Communication method and device

The communication method and apparatus enable on-demand user plane integrity protection in 4G networks by using keys and algorithms from different standards, addressing the inflexibility of 4G security measures and reducing power consumption.

JP7862542B2Active Publication Date: 2026-05-19HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP Β· JP
Patent Type
Patents
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2022-09-28
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

The 4G network lacks the flexibility to implement on-demand user plane integrity protection, as it always enables user plane encryption protection but disables user plane integrity protection, leading to inflexible security measures.

Method used

A communication method and apparatus that enables on-demand user plane integrity protection by allowing access network devices to obtain and activate user plane integrity protection instructions and algorithms based on specific conditions, using keys and integrity protection algorithms from different network standards, thereby reducing changes and power consumption.

Benefits of technology

This approach allows for flexible implementation of user plane integrity protection in 4G networks, reducing power consumption and minimizing changes to existing devices while maintaining security standards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007862542000001
    Figure 0007862542000001
  • Figure 0007862542000002
    Figure 0007862542000002
  • Figure 0007862542000003
    Figure 0007862542000003
Patent Text Reader

Abstract

The present application provides a communication method and an apparatus for implementing on-demand user plane integrity protection in a fourth generation (4G) network. The method includes: when a first condition is met, an access network device of a first network standard obtains user plane integrity protection indication information and an integrity protection algorithm identifier of a second network standard, sends a first message to a terminal device, and activates user plane integrity protection of a first data radio bearer (DRB) based on a first key and an integrity protection algorithm of the second network standard. The first condition includes determining to establish a first DRB between the access network device of the first network standard and the terminal device, and determining to enable user plane integrity protection of the first DRB. The user plane integrity protection indication information indicates to enable user plane integrity protection of the first DRB. The first message includes user plane integrity protection indication information and an integrity protection algorithm identifier of the second network standard.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application claims the priority of Chinese Patent Application No. 202111155030.6, titled "Communication Method and Device", filed with the China National Intellectual Property Administration on September 29, 2021, the entire content of which is incorporated herein by reference.

[0002] This application relates to the field of communications, and in particular, to communication methods and devices.

Background Art

[0003] The on-demand user plane security protection mechanism is a security mechanism in the 5th generation (5G) network. The on-demand user plane security protection mechanism includes user plane encryption protection and user plane integrity protection. For example, in the on-demand user plane security protection mechanism, the access network device determines whether to enable user plane encryption protection and / or user plane integrity protection between the access network device and the terminal device according to the user plane security policy. In this way, the on-demand user plane security protection mechanism in the 5G network can provide more flexible user plane security protection for the terminal device.

[0004] In the existing 4th generation (4G) network, the user plane security between the access network device and the terminal device is fixed. Specifically, the user plane encryption protection is always enabled, and the user plane integrity protection is always disabled. That is, in the existing 4G network, the on-demand activation of user plane integrity protection is not supported, and the user plane security protection is not flexible. Therefore, how to implement on-demand user plane integrity protection in the 4G network has become an urgent problem to be solved. [Overview of the project] [Means for solving the problem]

[0005] Embodiments of this application provide a communication method and apparatus for implementing on-demand user plane integrity protection in a 4G network.

[0006] To achieve the aforementioned objectives, the following technical solutions are used in this application.

[0007] According to a first embodiment, a communication method is provided. The communication method includes, when a first condition is met, an access network device of a first network standard obtains user plane integrity protection instruction information and an integrity protection algorithm identifier of a second network standard, transmits a first message to a terminal device, and activates user plane integrity protection of a first data radio bearer (DRB) based on a first key and an integrity protection algorithm of a second network standard. The first condition includes deciding to establish a first DRB between the access network device of the first network standard and the terminal device, and deciding to enable user plane integrity protection of the first DRB. The user plane integrity protection instruction information indicates that user plane integrity protection of the first DRB should be enabled. The first message includes user plane integrity protection instruction information and an integrity protection algorithm identifier of a second network standard.

[0008] When it is decided to establish a first DRB based on the communication method of the first embodiment and to enable user plane integrity protection of the first DRB, the access network device of the first network standard obtains user plane integrity instruction information and an integrity algorithm identifier of the second network standard indicating that user plane integrity protection is enabled, and transmits the user plane integrity instruction information and the integrity algorithm identifier of the second network standard to the terminal device. In this way, both the access network device of the first network standard and the terminal device can activate user plane integrity protection of the first DRB based on the first key and the integrity algorithm of the second network standard, thereby applying the on-demand user plane integrity protection mode of the second network standard to user plane integrity protection between the terminal device and the access network device of the first network standard, and reducing the changes to the terminal device.

[0009] In a possible design, the first message may further include first directive information, which may indicate that the first key is determined using a master key. Optionally, the master key may be a KeNB key for an access network device of a first network standard. The first key may be a user plane integrity protection key, which may be used to perform integrity protection over user plane data between a terminal device and an access network device.

[0010] In a possible design, the first key may be determined based on a master key, a second network standard integrity protection algorithm identifier, and a first algorithm type distinguisher. Optionally, the value of the first algorithm type distinguisher may be 0x07. For example, the first algorithm type distinguisher may be N-UP-int-alg. In this way, user plane integrity protection of the first DRB may be activated based on the first key and the second network standard integrity protection algorithm, thereby applying the second network standard's on-demand user plane integrity protection mode to user plane integrity protection between terminal devices and access network devices of the first network standard.

[0011] In a possible design method, the integrity protection algorithm identifier of the second network standard may be determined based on the security capability of the terminal device to the second network standard. Optionally, the security capability of the second network standard may be a new radio (NR) security capability, where the NR security capability includes at least one integrity protection algorithm identifier, and the access network device of the first network standard may select one integrity protection algorithm identifier from at least one integrity protection algorithm identifier.

[0012] In possible design methods, the communication method provided in the first embodiment may further include an access network device of the first network standard receiving a second message from a core network element of the first network standard. The second message may include the security capabilities of the terminal device of the second network standard. In other words, the security capabilities of the second network standard may be received from a core network element of the first network standard.

[0013] In possible design methods, the integrity protection algorithm identifier of the second network standard may be determined based on the security capabilities of the first network standard. Optionally, the security capabilities of the second network standard may be determined based on the security capabilities of the first network standard, and the integrity protection algorithm identifier of the second network standard may be determined based on the security capabilities of the second network standard.

[0014] In possible design methods, the communication method provided in the first embodiment may further include, when the terminal device supports user plane integrity protection, an access network device of the first network standard determining an integrity protection algorithm identifier of the second network standard based on the security capabilities of the first network standard. In this way, wasted power consumption can be avoided.

[0015] In a possible design method, the security capability of the first network standard may include the integrity protection algorithm identifier of the first network standard, and the integrity protection algorithm identifier of the second network standard may be obtained by mapping the integrity protection algorithm identifier of the first network standard. In this way, the integrity protection algorithm identifier of the second network standard may be obtained by mapping.

[0016] In a possible design, the security capabilities of the first network standard can be received from the core network elements of the first network standard by the access network devices of the first network standard. In this way, the security capabilities of the first network standard can be obtained, and the integrity protection algorithm identifier of the second network standard can be obtained further.

[0017] In a possible design, the activation of user-plane integrity protection for a first DRB by an access network device of a first network standard based on a first key and an integrity protection algorithm of a second network standard may include the access network device of the first network standard configuring a first key and an integrity protection algorithm of a second network standard for a packet data convergence protocol (PDCP) entity of a second network standard corresponding to the first DRB. In this way, user-plane integrity protection can be activated using the PDCP of the second network standard.

[0018] In possible design methods, the first condition may further include that the terminal device supports user plane integrity protection. For support of user plane integrity protection, see the description of the embodiments below. After it is determined that the terminal device supports user plane integrity protection, a procedure is performed to flexibly enable user plane integrity protection (e.g., obtaining user plane integrity protection instruction information and integrity protection algorithm identifiers of a second network standard), which can reduce power consumption.

[0019] In possible design methods, the communication method provided in the first embodiment may further include an access network device of a first network standard receiving user plane directive information from a terminal device or a core network element of the first network standard. The user plane directive information may indicate whether the terminal device supports user plane integrity protection, and a first condition may be determined based on the user plane directive information. In this way, the access network device of the first network standard may determine, based on the user plane directive information, whether the terminal device supports user plane integrity protection.

[0020] In a possible design approach, user plane integrity protection instruction information, the integrity protection algorithm identifier of the second network standard, and the first instruction information can be encapsulated in the Radiobearerconfig information element of the first message. In this way, changes to the relevant standards for access network devices and terminal devices of the first network standard can be reduced.

[0021] In possible design approaches, the first network standard may include fourth-generation 4G, long-term evolution (LTE), or evolved packet system (EPS).

[0022] In possible design approaches, the second network standard could include fifth-generation 5G, new wireless NR, or fifth-generation system (5GS).

[0023] It should be noted that the first and second network standards are limited in this application on the condition that the first and second network standards are different network standards.

[0024] According to a second aspect, a communication method is provided. The communication method includes that when a terminal device receives a first message, the first message is from an access network device of a first network standard, and user plane integrity protection indication information indicates to enable user plane integrity protection of a first DRB, the terminal device activates user plane integrity protection of the first DRB based on a first key and an integrity protection algorithm of a second network standard. The first message includes user plane integrity protection indication information and an integrity protection algorithm identifier of the second network standard, and the user plane integrity protection indication information indicates to enable user plane integrity protection of a first data radio bearer (DRB) between the access network device of the first network standard and the terminal device.

[0025] In a possible design, the first message may further include first indication information, and the first indication information may indicate to determine the first key using a master key. The communication method provided in the second aspect may further include that the terminal device determines the first key using the master key based on the first indication information.

[0026] In a possible design, the first key may be determined based on a master key, an integrity protection algorithm identifier of the second network standard, and a first algorithm type discriminator.

[0027] In a possible design, the value of the first algorithm type discriminator may be 0x07. For example, the first algorithm type discriminator may be N-UP-int-alg.

[0028] In a possible design, the communication method provided in the second aspect may further include that when the terminal device supports user plane integrity protection, the terminal device transmits a third message to a core network element of the first network standard. The third message may include security capabilities of the second network standard.

[0029] In a possible design method, for the terminal device to activate user plane integrity protection for the first DRB based on the first key and the integrity protection algorithm of the second network standard, it may include that the terminal device can configure the first key and the integrity protection algorithm of the second network standard for the packet data convergence protocol (PDCP) entity of the second network standard corresponding to the first DRB.

[0030] In a possible design method, the communication method provided in the second aspect may further include that the terminal device determines whether the first message is from an access network device of the first network standard based on a public land mobile network identifier (PLMN ID), and the PLMN ID may further be from the access network device that sends the first message. For example, when the PLMN ID does not include 5G, the access network device that sends the first message is an access network device of the first network standard.

[0031] In a possible design method, the communication method provided in the second aspect may further include that the terminal device sends user plane indication information to an access network device of the first network standard or a core network element of the first network standard. The user plane indication information may indicate whether the terminal device supports user plane integrity protection.

[0032] In a possible design method, the user plane integrity protection indication information, the integrity protection algorithm identifier of the second network standard, and the first indication information may be encapsulated in the radio bearer configuration (Radiobearerconfig) information element of the first message.

[0033] In possible design approaches, the first network standard may include fourth-generation 4G, Long-Term Evolution LTE, or Advanced Packet System (EPS).

[0034] In possible design scenarios, the second network standard could include fifth-generation 5G, new wireless NR, or fifth-generation system 5GS.

[0035] Furthermore, for the technical effects of the communication method according to the second embodiment, please refer to the technical effects of the communication method in any one of the possible embodiments of the first embodiment. Details will not be explained again here.

[0036] According to a third aspect, a communication method is provided. The communication method includes, when a first condition is met, an access network device of a first network standard obtains user plane integrity protection instruction information and an integrity protection algorithm identifier of the first network standard, transmits a fourth message to a terminal device, and activates user plane integrity protection of the first DRB based on a first key and an integrity protection algorithm of the first network standard. The fourth message includes user plane integrity protection instruction information. The first condition includes deciding to establish a first data radio bearer DRB between the access network device of the first network standard and the terminal device, and deciding to enable user plane integrity protection of the first DRB. The user plane integrity protection instruction information indicates that user plane integrity protection of the first DRB is enabled.

[0037] When it is decided to establish a first DRB based on a communication method according to a third aspect, and it is decided to enable user plane integrity protection of the first DRB, the access network device of the first network standard obtains user plane integrity instruction information and an integrity algorithm identifier of the first network standard indicating that user plane integrity protection is enabled, and instructs the terminal device to activate integrity protection using the integrity algorithm of the first network standard. In this way, both the access network device of the first network standard and the terminal device can activate user plane integrity protection of the first DRB based on a first key and the integrity algorithm of the first network standard, thereby applying the on-demand user plane integrity protection mode of the second network standard to user plane integrity protection between the terminal device and the access network device of the first network standard, and the user plane integrity protection is activated using the integrity algorithm of the first network standard, resulting in the implementation of independent developments of user plane integrity protection of different network standards.

[0038] In a possible design, the fourth message may further include the first and / or second instruction information. The first instruction information may instruct the terminal device to determine the first key using the master key, and the second instruction information may indicate activating user-plane integrity protection of the first DRB based on the integrity protection algorithm identifier of the first network standard. Optionally, the second instruction information may indicate activating user-plane integrity protection based on the currently used integrity protection algorithm of the first network standard, or the second instruction information may include the integrity protection algorithm identifier of the first network standard. Thus, the second instruction information may indicate enabling user-plane integrity protection using the integrity protection algorithm in use.

[0039] Optionally, the master key may be a KeNB key for an access network device of a first network standard. The first key may be a user plane integrity protection key, which may be used to perform integrity protection on user plane data between a terminal device and an access network device.

[0040] In a possible design, the first key may be determined based on a master key, an integrity protection algorithm identifier of a first network standard, and a second algorithm type identifier. In this way, user plane integrity protection of the first DRB may be activated based on the first key and the integrity protection algorithm of the first network standard.

[0041] In a possible design, the first key is determined based on the master key, the integrity protection algorithm identifier of the second network standard, and the first algorithm type identifier, and the integrity protection algorithm identifier of the second network standard is determined based on the integrity protection algorithm identifier of the first network standard. In this way, user plane integrity protection of the first DRB can be activated based on the first key and the integrity protection algorithm of the second network standard, thereby applying the on-demand user plane integrity protection mode of the second network standard to user plane integrity protection between terminal devices and access network devices of the first network standard.

[0042] In possible design methods, the value of the first algorithm type distinguisher can be 0x07. For example, the first algorithm type distinguisher could be N-UP-int-alg.

[0043] In a possible design, the activation of user-plane integrity protection of the first DRB by an access network device of the first network standard based on a first key and the integrity protection algorithm of the first network standard may include the activation of user-plane integrity protection of the first DRB using the first key and the integrity protection algorithm of the first network standard based on second instruction information. In this way, the access network device of the first network standard may perform on-demand user-plane integrity protection using the integrity protection algorithm of the first network standard based on the instructions of the second instruction information.

[0044] In a possible design, the activation of user-plane integrity protection for a first DRB by an access network device of a first network standard based on a first key and an integrity protection algorithm of the first network standard may include the access network device of the first network standard configuring a first key and an integrity protection algorithm of the first network standard for a packet data convergence protocol (PDCP) entity of a second network standard corresponding to the first DRB. In this way, user-plane integrity protection can be activated using the PDCP of the second network standard.

[0045] In possible design methods, the first condition may further include that the terminal device supports user plane integrity protection. For support of user plane integrity protection, see the description of the embodiments below. After it is determined that the terminal device supports user plane integrity protection, a procedure is performed to flexibly enable user plane integrity protection (e.g., obtaining user plane integrity protection instruction information and integrity protection algorithm identifiers of the first network standard), which can reduce power consumption.

[0046] In possible design methods, the communication method provided in a third aspect may further include an access network device of a first network standard receiving user plane directive information from a terminal device or a core network element of the first network standard. The user plane directive information may indicate whether the terminal device supports user plane integrity protection, and the first condition may be determined based on the user plane directive information. In this way, the access network device of the first network standard may determine, based on the user plane directive information, whether the terminal device supports user plane integrity protection.

[0047] In a possible design, the user plane integrity protection instruction information, the first instruction information, and the second instruction information can be encapsulated in the Radiobearerconfig information element of the fourth message. In this way, changes to the relevant standards for access network devices and terminal devices of the first network standard can be reduced.

[0048] In a possible design, the user plane integrity protection instruction information and the first instruction information may be encapsulated in the Radiobearerconfig information element of the fourth message.

[0049] In possible design approaches, the first network standard may include fourth-generation 4G, Long-Term Evolution LTE, or Advanced Packet System (EPS).

[0050] In possible design scenarios, the second network standard could include fifth-generation 5G, new wireless NR, or fifth-generation system 5GS.

[0051] It should be noted that the first and second network standards are limited in this application on the condition that the first and second network standards are different network standards.

[0052] According to a fourth aspect, a communication method is provided. The communication method includes a terminal device activating user plane integrity protection of a first DRB based on a first key and an integrity protection algorithm of a first network standard when the terminal device receives a fourth message and the fourth message is from an access network device of a first network standard and user plane integrity protection instruction information indicates that user plane integrity protection of a first DRB should be enabled. The fourth message includes user plane integrity protection instruction information, which indicates that user plane integrity protection of a first data radio bearer DRB should be enabled.

[0053] In a possible design, the fourth message may further include first instruction information, which may indicate determining the first key using the master key. The communication method provided in the fourth embodiment may further include the terminal device determining the first key using the master key based on the first instruction information.

[0054] In a possible design, the first key may be determined based on the master key, the integrity protection algorithm identifier of the first network standard, and the second algorithm type identifier.

[0055] In possible design methods, the first key may be determined based on the master key, the integrity protection algorithm identifier of the second network standard, and the first algorithm type identifier, and the integrity protection algorithm identifier of the second network standard is determined based on the integrity protection algorithm identifier of the first network standard.

[0056] In possible design methods, the value of the first algorithm type distinguisher can be 0x07. For example, the first algorithm type distinguisher could be N-UP-int-alg.

[0057] In possible design methods, the communication method provided in the fourth aspect may further include the terminal device obtaining an integrity protection algorithm of the first network standard from the access stratum (AS) security context based on user plane integrity protection instruction information.

[0058] In a possible design, the fourth message may further include second directive information indicating the activation of user-plane integrity protection of the first DRB based on the currently used integrity protection algorithm identifier of the first network standard. The communication method provided in the fourth aspect may further include the terminal device obtaining the integrity protection algorithm of the first network standard from the AS security context based on the second directive information.

[0059] In a possible design, the fourth message further includes second instruction information, the second instruction information includes an integrity protection algorithm identifier of the first network standard. The communication method provided in the fourth aspect may further include the terminal device obtaining the integrity protection algorithm of the first network standard based on the integrity protection algorithm identifier of the first network standard.

[0060] In a possible design, the activation of user-plane integrity protection of a first DRB by a terminal device based on a first key and an integrity protection algorithm of a first network standard may include the terminal device configuring a first key and an integrity protection algorithm of a first network standard for a packet data convergence protocol PDCP entity of a second network standard that corresponds to the first DRB.

[0061] In possible design methods, the communication method provided in the fourth aspect may further include the terminal device transmitting user plane instruction information to an access network device or core network element of the first network standard. The user plane instruction information may indicate whether the terminal device supports user plane integrity protection.

[0062] In possible design methods, the communication method provided in the fourth aspect may further include a terminal device determining, based on a public land mobile network identifier (PLMN) ID, whether the fourth message is from an access network device of the first network standard, and that the PLMN ID is from an access network device that transmits the fourth message.

[0063] In possible design methods, the user plane integrity protection instruction information, the first instruction information, and the second instruction information may be encapsulated in the Radiobearerconfig information element of the fourth message.

[0064] In a possible design, the user plane integrity protection instruction information and the first instruction information may be encapsulated in the Radiobearerconfig information element of the fourth message.

[0065] In possible design approaches, the first network standard may include fourth-generation 4G, Long-Term Evolution LTE, or Advanced Packet System (EPS).

[0066] In possible design scenarios, the second network standard could include fifth-generation 5G, new wireless NR, or fifth-generation system 5GS.

[0067] Furthermore, for the technical effects of the communication method according to the fourth embodiment, please refer to the technical effects of the communication method in any one of the possible embodiments of the third embodiment. Details will not be explained again here.

[0068] According to a fifth aspect, a communication device is provided. The communication device includes a processing module and a transceiver module. When a first condition is met, the processing module is configured to obtain user plane integrity protection instruction information and an integrity protection algorithm identifier of a second network standard. The transceiver module is configured to send a first message to a terminal device. The processing module is further configured to activate user plane integrity protection of a first DRB based on a first key and an integrity protection algorithm of a second network standard. The first condition includes deciding to establish a first DRB between the communication device and the terminal device and deciding to enable user plane integrity protection of the first DRB. The user plane integrity protection instruction information indicates that user plane integrity protection of the first DRB is enabled. The first message includes user plane integrity protection instruction information and an integrity protection algorithm identifier of a second network standard.

[0069] In a possible design, the first message may further contain first instruction information, which may indicate that the master key is used to determine the first key.

[0070] In a possible design, the first key may be determined based on the master key, the integrity protection algorithm identifier of the second network standard, and the first algorithm type identifier.

[0071] In a possible design, the value of the first algorithm type distinguisher may be 0x07. For example, the first algorithm type distinguisher may be N-UP-int-alg. In a possible design, the integrity protection algorithm identifier of the second network standard may be determined based on the security capability of the terminal device to the second network standard.

[0072] In a possible design, the transceiver module is further configured to receive a second message from the core network element of the first network standard. The second message may include the security capabilities of the terminal device according to the second network standard.

[0073] In a possible design approach, the integrity protection algorithm identifier of the second network standard may be determined based on the security capabilities of the first network standard.

[0074] In a possible design, when the terminal device supports user plane integrity protection, the processing module is further configured to determine the integrity protection algorithm identifier of a second network standard based on the security capabilities of a first network standard.

[0075] In a possible design method, the security capability of the first network standard may include the integrity protection algorithm identifier of the first network standard, and the integrity protection algorithm identifier of the second network standard may be obtained by mapping the integrity protection algorithm identifier of the first network standard.

[0076] In a possible design, the security capabilities of the first network standard can be received by the communication device from the core network elements of the first network standard.

[0077] In a possible design, the processing module is further configured to configure the first key and the integrity protection algorithm of the second network standard for the PDCP entity of the second network standard, corresponding to the first DRB.

[0078] In possible design methods, the first condition may further include that the terminal device supports user plane integrity protection.

[0079] In a possible design, the transceiver module is further configured to receive user plane instruction information from a terminal device or a core network element of a first network standard, the user plane instruction information may indicate whether the terminal device supports user plane integrity protection, and the first condition is determined based on the user plane instruction information.

[0080] In a possible design, user plane integrity protection instruction information, a second network standard integrity protection algorithm identifier, and first instruction information can be encapsulated in the Radiobearerconfig information element of the first message.

[0081] In possible design approaches, the first network standard may include fourth-generation 4G, Long-Term Evolution LTE, or Advanced Packet System (EPS).

[0082] In possible design scenarios, the second network standard could include fifth-generation 5G, new wireless NR, or fifth-generation system 5GS.

[0083] It should be noted that the transceiver module according to the fifth embodiment may include a receiving module and a transmitting module. The receiving module is configured to receive data and / or signaling from terminal devices and / or core network elements of the first network standard. The transmitting module is configured to transmit data and / or signaling to terminal devices and / or core network elements of the first network standard. Specific embodiments of the transceiver module are not specifically limited in this application.

[0084] Optionally, the communication device according to the fifth embodiment may further include a storage module that stores a program or instruction. When a processing module executes a program or instruction, the communication device according to the fifth embodiment is enabled to perform the method according to the first embodiment.

[0085] It should be noted that the communication device according to the fifth embodiment may be an access network device of the first network standard, or a chip (system) or other component or assembly that can be deployed in an access network device of the first network standard. This is not limited to the present application.

[0086] Furthermore, for the technical effects of the communication device according to the fifth embodiment, please refer to the technical effects of the communication method in any one of the possible embodiments of the first embodiment. Details will not be explained again here.

[0087] According to a sixth aspect, a communication device is provided. The communication device includes a processing module and a transceiver module. The transceiver module is configured to receive a first message. When the first message is from an access network device of a first network standard and user plane integrity protection instruction information indicates that user plane integrity protection of the first DRB should be enabled, the processing module is configured to activate user plane integrity protection of the first DRB based on a first key and an integrity protection algorithm of a second network standard. The first message includes user plane integrity protection instruction information and an integrity protection algorithm identifier of a second network standard, the user plane integrity protection instruction information indicating that user plane integrity protection of the first data radio bearer DRB should be enabled between the access network device of the first network standard and the communication device.

[0088] In a possible design, the first message may further contain first instruction information, which may indicate that the master key should be used to determine the first key. The processing module is further configured to determine the first key using the master key based on the first instruction information.

[0089] In a possible design, the first key may be determined based on the master key, the integrity protection algorithm identifier of the second network standard, and the first algorithm type identifier.

[0090] In possible design methods, the value of the first algorithm type distinguisher can be 0x07. For example, the first algorithm type distinguisher could be N-UP-int-alg.

[0091] In a possible design, when the communication device supports user plane integrity protection, the transceiver module is further configured to transmit a third message to the core network element of the first network standard. The third message may include security capabilities of the second network standard.

[0092] In a possible design, when the first message is from an access network device of a first network standard and the user plane integrity protection instruction information indicates that user plane integrity protection of the first DRB is enabled, the processing module is further configured to configure the first key and the integrity protection algorithm of the second network standard for the PDCP entity of the second network standard corresponding to the first DRB.

[0093] In a possible design, the processing module is further configured to determine, based on the PLMN ID, whether the first message is from an access network device of a first network standard, and the PLMN ID is from the access network device sending the first message.

[0094] In possible design configurations, the transceiver module is further configured to transmit user plane directive information to an access network device or core network element of a first network standard. The user plane directive information may indicate whether the communication device supports user plane integrity protection.

[0095] In a possible design, user plane integrity protection instruction information, a second network standard integrity protection algorithm identifier, and first instruction information can be encapsulated in the Radiobearerconfig information element of the first message.

[0096] In possible design approaches, the first network standard may include fourth-generation 4G, Long-Term Evolution LTE, or Advanced Packet System (EPS).

[0097] In possible design scenarios, the second network standard could include fifth-generation 5G, new wireless NR, or fifth-generation system 5GS.

[0098] It should be noted that the transceiver module according to the sixth aspect may include a receiving module and a transmitting module. The receiving module is configured to receive data and / or signaling from an access network device and / or a core network element of the first network standard. The transmitting module is configured to transmit data and / or signaling to an access network device and / or a core network element of the first network standard. Specific embodiments of the transceiver module are not specifically limited in this application.

[0099] Optionally, the communication device according to the sixth embodiment may further include a storage module that stores a program or instruction. When a processing module executes a program or instruction, the communication device according to the sixth embodiment is enabled to perform the method according to the second embodiment.

[0100] It should be noted that the communication device according to the sixth aspect may be a terminal device, or a chip (system) or other component or assembly that may be provided in a terminal device. This is not limited to the present application.

[0101] Furthermore, for the technical effects of the communication device according to the sixth embodiment, please refer to the technical effects of the communication method in any one of the possible embodiments of the second embodiment. Details will not be explained again here.

[0102] According to the seventh aspect, a communication device is provided. The communication device includes a processing module and a transceiver module. When a first condition is met, the processing module is configured to obtain user plane integrity protection instruction information and an integrity protection algorithm identifier of a first network standard. The transceiver module is configured to transmit a fourth message to a terminal device. The processing module is further configured to activate user plane integrity protection of a first DRB based on a first key and an integrity protection algorithm of a first network standard. The fourth message includes user plane integrity protection instruction information. The first condition includes deciding to establish a first data radio bearer DRB between the communication device and the terminal device and deciding to enable user plane integrity protection of the first DRB. The user plane integrity protection instruction information indicates that user plane integrity protection of the first DRB is enabled.

[0103] In a possible design, the fourth message may further include the first and / or second instruction information. The first instruction information may instruct the terminal device to determine the first key using the master key, and the second instruction information may indicate activating user-plane integrity protection of the first DRB based on the integrity protection algorithm identifier of the first network standard. Optionally, the second instruction information may indicate activating user-plane integrity protection based on the currently used integrity protection algorithm of the first network standard, or the second instruction information may include the integrity protection algorithm identifier of the first network standard.

[0104] In a possible design, the first key may be determined based on the master key, the integrity protection algorithm identifier of the first network standard, and the second algorithm type identifier.

[0105] In possible design methods, the first key may be determined based on the master key, the integrity protection algorithm identifier of the second network standard, and the first algorithm type identifier, and the integrity protection algorithm identifier of the second network standard is determined based on the integrity protection algorithm identifier of the first network standard.

[0106] In possible design methods, the value of the first algorithm type distinguisher can be 0x07. For example, the first algorithm type distinguisher could be N-UP-int-alg.

[0107] In a possible design, the processing module is further configured to activate user plane integrity protection of the first DRB using the integrity protection algorithm of the first key and the first network standard, based on the second instruction information.

[0108] In a possible design, the processing module is further configured to configure a first key and an integrity protection algorithm of the first network standard for packet data convergence protocol PDCP entities of the second network standard, corresponding to the first DRB.

[0109] In possible design methods, the first condition may further include that the terminal device supports user plane integrity protection.

[0110] In possible design configurations, the transceiver module is further configured to receive user plane directive information from a terminal device or a core network element of a first network standard. The user plane directive information may indicate whether the terminal device supports user plane integrity protection, and the first condition may be determined based on the user plane directive information.

[0111] In a possible design, the user plane integrity protection instruction information, the first instruction information, and the second instruction information may be encapsulated in the Radiobearerconfig information element of the fourth message.

[0112] In a possible design, the user plane integrity protection instruction information and the first instruction information may be encapsulated in the Radiobearerconfig information element of the fourth message.

[0113] In possible design approaches, the first network standard may include fourth-generation 4G, Long-Term Evolution LTE, or Advanced Packet System (EPS).

[0114] In possible design scenarios, the second network standard could include fifth-generation 5G, new wireless NR, or fifth-generation system 5GS.

[0115] It should be noted that the transceiver module according to the seventh aspect may include a receiving module and a transmitting module. The receiving module is configured to receive data and / or signaling from terminal devices and / or core network elements of the first network standard. The transmitting module is configured to transmit data and / or signaling to terminal devices and / or core network elements of the first network standard. Specific embodiments of the transceiver module are not specifically limited in this application.

[0116] Optionally, the communication device according to the seventh embodiment may further include a storage module that stores a program or instruction. When a processing module executes a program or instruction, the communication device according to the seventh embodiment is enabled to perform the method according to the third embodiment.

[0117] It should be noted that the communication device according to the seventh aspect may be an access network device of the first network standard, or a chip (system) or other component or assembly that can be deployed in an access network device of the first network standard. This is not limited to the present application.

[0118] Furthermore, for the technical effects of the communication device according to the seventh embodiment, please refer to the technical effects of the communication method in any one of the possible embodiments of the third embodiment. Details will not be explained again here.

[0119] According to the eighth aspect, a communication device is provided. The communication device includes a processing module and a transceiver module. The transceiver module is configured to receive a fourth message. When the fourth message is from an access network device of a first network standard and user plane integrity protection instruction information indicates that user plane integrity protection of the first DRB should be enabled, the processing module is configured to activate user plane integrity protection of the first DRB based on a first key and an integrity protection algorithm of the first network standard. The fourth message includes user plane integrity protection instruction information, which indicates that user plane integrity protection of the first data radio bearer DRB should be enabled.

[0120] In a possible design, the fourth message may further contain the first instruction information, which may indicate that the master key is used to determine the first key. The processing module is further configured to determine the first key using the master key based on the first instruction information.

[0121] In a possible design, the first key may be determined based on the master key, the integrity protection algorithm identifier of the first network standard, and the second algorithm type identifier.

[0122] In possible design methods, the first key may be determined based on the master key, the integrity protection algorithm identifier of the second network standard, and the first algorithm type identifier, and the integrity protection algorithm identifier of the second network standard is determined based on the integrity protection algorithm identifier of the first network standard.

[0123] In possible design methods, the value of the first algorithm type distinguisher can be 0x07. For example, the first algorithm type distinguisher could be N-UP-int-alg.

[0124] In a possible design, the processing module is further configured to retrieve the integrity protection algorithm of a first network standard from the access stratum (AS) security context based on user plane integrity protection instruction information.

[0125] In a possible design, the fourth message may further include second directive information, which indicates activating user-plane integrity protection of the first DRB based on the currently used integrity protection algorithm identifier of the first network standard. According to the communication method provided in the fourth aspect, the processing module is further configured to retrieve the integrity protection algorithm of the first network standard from the AS security context based on the second directive information.

[0126] In a possible design, the fourth message further includes second instruction information, the second instruction information includes an integrity protection algorithm identifier for the first network standard, and the processing module is further configured to obtain the integrity protection algorithm for the first network standard based on the integrity protection algorithm identifier for the first network standard.

[0127] In a possible design, the processing module is further configured to configure the first key and the integrity protection algorithm of the first network standard for the PDCP entities of the second network standard, corresponding to the first DRB.

[0128] In a possible design, the transmitting module may be further configured to transmit user plane directive information to an access network device or core network element of a first network standard. The user plane directive information may indicate whether the communication device supports user plane integrity protection.

[0129] In a possible design, the processing module is further configured to determine, based on the Public Land Mobile Network identifier (PLMN) ID, whether the fourth message is from an access network device of the first network standard, and the PLMN ID is from an access network device that sends the fourth message.

[0130] In possible design methods, the user plane integrity protection instruction information, the first instruction information, and the second instruction information may be encapsulated in the Radiobearerconfig information element of the fourth message.

[0131] In a possible design, the user plane integrity protection instruction information and the first instruction information may be encapsulated in the Radiobearerconfig information element of the fourth message.

[0132] In possible design approaches, the first network standard may include fourth-generation 4G, Long-Term Evolution LTE, or Advanced Packet System (EPS).

[0133] In possible design scenarios, the second network standard could include fifth-generation 5G, new wireless NR, or fifth-generation system 5GS.

[0134] It should be noted that the transceiver module according to the eighth aspect may include a receiving module and a transmitting module. The receiving module is configured to receive data and / or signaling from an access network device and / or a core network element of the first network standard. The transmitting module is configured to transmit data and / or signaling to an access network device and / or a core network element of the first network standard. Specific embodiments of the transceiver module are not specifically limited in this application.

[0135] Optionally, the communication device according to the eighth embodiment may further include a storage module. The storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device according to the eighth embodiment is enabled to perform the method according to the fourth embodiment.

[0136] It should be noted that the communication device according to the eighth aspect may be a terminal device, or a chip (system) or other component or assembly that may be placed in a terminal device. This is not limited to the present application.

[0137] Furthermore, for the technical effects of the communication device according to the eighth aspect, please refer to the technical effects of the communication method in any one of the possible embodiments of the fourth aspect. Details will not be explained again here.

[0138] According to the ninth aspect, a communication device is provided. The communication device includes a processor. The processor is coupled to memory, which is configured to store computer programs.

[0139] The processor is configured to execute a computer program stored in memory so that a communication method according to any one of the possible embodiments of the first to fourth embodiments is performed.

[0140] In possible designs, the communication device according to the ninth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an input / output port. The transceiver may be used by the communication device to communicate with another device.

[0141] It should be noted that the input port may be configured to perform a receiving function related to the first to fourth embodiments, and the output port may be configured to perform a transmitting function related to the first to fourth embodiments.

[0142] In this application, the communication device according to the ninth aspect may be an access network device, terminal device, or core network element of the first network standard, or a chip or chip system located inside an access network device, terminal device, or core network element of the first network standard.

[0143] Furthermore, for the technical effects of the communication device according to the ninth embodiment, please refer to the technical effects of the communication method in any one of the embodiments from the first to the fourth embodiment. Details will not be explained again here.

[0144] According to the tenth aspect, a communication system is provided. The communication system includes a communication device according to the fifth aspect and a communication device according to the sixth aspect. Alternatively, the communication system includes a communication device according to the seventh aspect and a communication device according to the eighth aspect.

[0145] Alternatively, the communication system includes a communication device according to a fifth embodiment configured to carry out the method according to the first embodiment, and a communication device according to a sixth embodiment configured to carry out the method according to the second embodiment. Alternatively, the communication system includes a communication device according to a seventh embodiment configured to carry out the method according to the third embodiment, and a communication device according to an eighth embodiment configured to carry out the method according to the fourth embodiment.

[0146] For example, a communication system may include access network devices and terminal devices of a first network standard, and may further include core network elements of a first network standard.

[0147] According to the eleventh aspect, a chip system is provided. The chip system includes logic circuits and input / output ports. The logic circuits are configured to perform processing functions related to the first to fourth aspects, and the input / output ports are configured to perform transceiver functions related to the first to fourth aspects. Specifically, the input ports may be configured to perform receiving functions related to the first to fourth aspects, and the output ports may be configured to perform transmitting functions related to the first to fourth aspects.

[0148] In possible designs, the chip system further includes memory. The memory is configured to store program instructions and data for performing the functions related to the first through fourth embodiments.

[0149] The chip system may include a chip, or it may include a chip and another discrete device.

[0150] According to the twelfth aspect, a computer-readable storage medium containing a computer program or instruction is provided. When the computer program or instruction is executed on the computer, a communication method according to any one of the possible embodiments of the first to fourth aspects is performed.

[0151] According to the 13th aspect, a computer program product is provided which includes a computer program or instructions. When the computer program or instructions are run on a computer, a communication method is performed according to any one of the possible embodiments of the first to fourth aspects. [Brief explanation of the drawing]

[0152] [Figure 1]This is a schematic diagram of the architecture of a communication system according to one embodiment of this application. [Figure 2] This is a schematic flowchart of a communication method according to one embodiment of this application. [Figure 3] This is a schematic flowchart of another communication method according to one embodiment of this application. [Figure 4] This is a schematic flowchart of yet another communication method according to one embodiment of this application. [Figure 5] This is a schematic diagram of the structure of a communication device according to one embodiment of this application. [Figure 6] This is a schematic diagram of the structure of another communication device according to one embodiment of this application. [Modes for carrying out the invention]

[0153] The technical solution of this application will be described below with reference to the attached drawings.

[0154] The technical solutions in the embodiments of this application can be applied to various communication systems, such as fourth-generation (4G) mobile communication systems including universal mobile telecommunications systems (UMTS), wireless local area networks (WLAN), wireless fidelity (Wi-Fi) systems, wired networks, vehicle-to-everything (V2X) communication systems, device-to-device (D2D) communication systems, vehicle internet communication systems, long-term evolution (LTE) systems, and worldwide interoperability for microwave access (WiMAX) communication systems; fifth-generation (5G) mobile communication systems including new radio (NR) systems; and sixth-generation (6G) mobile communication systems.

[0155] All aspects, embodiments, or features are presented in this application by describing systems that may include multiple devices, components, and modules, etc. It should be recognized and understood that each system may include other devices, components, and modules, etc., and / or may not include all of the devices, components, and modules, etc. described with reference to the accompanying drawings. In addition, combinations of these solutions may be used.

[0156] In addition, in the embodiments of this application, terms such as β€œexample” and β€œfor example” are used to indicate that an example, illustration, or explanation is being given. None of the embodiments or design solutions described as β€œexample” in this application are described as being more preferable or having more advantages than other embodiments or design solutions. More precisely, the term β€œexample” is used to present a concept in a specific way.

[0157] The terms "of," "corresponding" (or "relevant"), and "corresponding" (or "corresponding") can sometimes be used interchangeably. Note that the meanings expressed by these terms are equivalent when the differences between them are not emphasized.

[0158] In embodiments of this application, a subscript, such as W1, may sometimes be written in an incorrect form, such as W1. The meanings expressed are identical when the difference is not emphasized.

[0159] The network architectures and service scenarios described in the embodiments of this application are intended to more clearly illustrate the technical solutions in the embodiments of this application and do not constitute a limitation on the technical solutions provided in the embodiments of this application. Those skilled in the art will know that, with the development of network architectures and the emergence of new service scenarios, the technical solutions provided in the embodiments of this application may also be applicable to similar technical problems.

[0160] To facilitate understanding of the embodiments of this application, the communication system shown in Figure 1 is used first as an example to illustrate in detail a communication system applicable to the embodiments of this application. For example, Figure 1 is a schematic diagram of the architecture of a communication system to which a communication method according to one embodiment of this application is applicable.

[0161] As shown in Figure 1, the communication system includes terminal devices and access network devices. Optionally, the communication system may further include core network elements. The access network devices may communicate with terminal devices via a logical interface (e.g., a Uu interface), and the core network elements may communicate with the access network devices via a logical interface (e.g., an S1 interface).

[0162] A terminal device is a terminal device that accesses a communication system and has wireless transceiver functionality, or a chip or chip system that may be installed in a terminal device. A terminal device may also be called a sensing device, user equipment (UE), user device, access terminal, subscriber unit, subscriber station, mobile station (MS), remote station, remote terminal, mobile device, user terminal, terminal, terminal unit, terminal station, terminal device, wireless communication device, user agent, or user device.

[0163] For example, the terminal devices in the embodiments of this application may be customer premise equipment (CPE), mobile phones, wireless data cards, personal digital assistant (PDA) computers, laptop computers, tablet computers (Pads), computers with wireless receiver functionality, machine type communication (MTC) terminals, virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, Internet of Things (IoT) terminal devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical care, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes (such as game consoles, smart TVs, smart speakers, smart refrigerators, or health equipment), in-vehicle terminals, or RSUs with terminal functionality. Access terminals may include cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, handheld devices with wireless communication capabilities, computing devices, other processing devices connected to wireless modems, or wearable devices. Customer premises equipment is larger and more powerful than typical terminals and can receive signals transmitted by access network devices and then transmit signals to other terminal devices.This is equivalent to performing secondary relaying for signals transmitted by access network devices.

[0164] In other examples, the terminal device in the embodiments of this application may be a delivery terminal for smart logistics (e.g., a device capable of monitoring the location of a goods vehicle, or a device capable of monitoring the temperature and humidity of goods), a wireless terminal for smart agriculture (e.g., a wearable device capable of collecting relevant data on poultry and animals), a wireless terminal for smart buildings (e.g., a smart elevator, a fire monitoring device, and a smart meter), a wireless terminal for smart healthcare (e.g., a wearable device capable of monitoring the physiological status of a person or animal), a wireless terminal for smart transportation (e.g., a smart bus, a smart vehicle, a shared bike, a charging pile monitoring device, a smart traffic light, a train detector, or a sensor such as a gas station, or a smart monitoring device or a smart parking device), or a wireless terminal for smart retail (e.g., a vending machine, a self-service checkout machine, or an unmanned store). In other examples, the terminal device of this application may be an in-vehicle module, in-vehicle assembly, in-vehicle component, in-vehicle chip, or in-vehicle unit incorporated into a vehicle as one or more components or units. The vehicle uses an on-board module, on-board assembly, on-board component, on-board chip, or on-board unit incorporated into the vehicle to carry out the method provided in this application.

[0165] An access network device is a device or chip / chip system located on the network side of a communication system that has wireless transceiver functionality. Access network devices include, but are not limited to, access points (APs), evolved NodeBs (eNBs), radio network controllers (RNCs), NodeBs (NBs), base station controllers (BSCs), base transceiver stations (BTSs), home base stations (e.g., home evolved NodeBs or home NodeBs, HNBs), baseband units (BBUs), wireless relay nodes, wireless backhaul nodes, or transmission and reception points (TRPs or transmission points, TPs) in a wireless fidelity (Wi-Fi) system, such as home gateways, routers, servers, switches, and bridges. Alternatively, the access network device may be a gNB or transmission point (TRP or TP) in a 5G system, such as an NR system, or an antenna panel or group of antenna panels (including multiple antenna panels) of a base station in a 5G system, or a network node such as a baseband unit (BBU), distributed unit (DU), or roadside unit (RSU) having base station functionality that constitutes a gNB or transmission point. It should be noted that in this application, the access network device of the first network standard may be an access network device in an LTE system, such as an eNB, and the access network device of the second network standard may be an access network device in an NR system, such as a gNB or ng-eNB.

[0166] Core network elements are devices located on the network side of a communication system that provide network services to terminal devices, or chips (systems) or other components or assemblies that may be installed in such devices. In LTE systems, core network elements include, but are not limited to, a mobility management entity (MME). The mobility management entity manages and stores the mobility management context of terminal devices (e.g., terminal device identifier, mobility management state, and user security parameters), and may be responsible for processing non-access stratum (NAS) signaling (e.g., attach requests, update location requests, service requests, and packet data network (PDN) connectivity requests), and is responsible for NAS signaling security, etc. In 5G communication systems, the functions of the mobility management entity can be decomposed into an access and mobility management function (AMF) and a session management function (SMF). In future communication systems, the mobility management entity may still be MME, or AMF and SMF, or may have a different name. This is not limited to the present application. Optionally, the core network elements may further include a serving gateway (SGW) network element, a home subscriber server (HSS) + unified data management (UDM) network element, and a session management function (SMF) + packet data network gateway-control plane (PGW-C) network element.SGW network elements can perform user plane functions for user plane data transfer. HSS+UDM network elements can be configured to store user subscription data. In the interworking system architecture, network elements store both 4G subscription information and 5G subscription information for terminal devices. SMF+PGW-C network elements can be used for session establishment, deletion, and change management. In the interworking system architecture, network elements can provide both 4G session management functions and 5G session management functions.

[0167] It should be noted that the communication method provided in this embodiment of the present application is applicable to any two nodes shown in Figure 1, for example, a terminal device and an access network device, or an access network device and a core network element. For specific embodiments, please refer to the method embodiments described below. Details are not described again here.

[0168] It should be noted that the solutions in the embodiments of this application may also be used in other communication systems, and the corresponding names may also be replaced with the names of the corresponding functions in other communication systems.

[0169] Please understand that Figure 1 is merely a simplified schematic diagram of an example for ease of understanding. The communication system may further include other network devices and / or other terminal devices not shown in Figure 1.

[0170] To further clarify the embodiments of this application, the following summarizes some of the content and concepts related to the embodiments of this application.

[0171] First: User Plane Security Policy. User plane security policies are policies used to describe whether to enable security protection for user plane data. User plane security policies may include user plane cryptographic protection policies and user plane integrity protection policies.

[0172] The user plane encryption protection policy is a policy that can indicate whether or not to perform user plane encryption protection, and the user plane integrity protection policy is a policy that can indicate whether or not to enable user plane integrity protection.

[0173] User-plane encryption protection protects the confidentiality of user-plane data during transmission, while user-plane integrity protection protects the integrity of user-plane data during transmission. In embodiments of this application, integrity means that the acquired signaling or data matches the original signaling or data and has not been altered. Thus, integrity protection is used to prevent attackers from attacking the signaling or data. Confidentiality means that the actual content cannot be directly viewed. Thus, confidentiality protection is used to make it "unreadable" to attackers. In addition, encryption protection in embodiments of this application may also be called confidentiality protection. This is described uniformly here and will not be described in detail again below.

[0174] In embodiments of this application, there are a total of three protection policies: "required," "not needed," and "preferred." "Required" indicates that security must be enabled, "required" indicates that security does not need to be enabled, and "preferred" indicates that it is preferable to enable security, or is called optional enablement, i.e., security may be enabled or disabled. This is described here and is not described below in detail. The three possible values ​​of the protection policy mentioned above may be represented using two bits. For example, 00 indicates that security does not need to be enabled, 01 indicates that security may or may not be enabled, and 11 indicates that security must be enabled. The meanings indicated by the number and value of bits occupied by the protection policy are not limited in this application.

[0175] For example, a user plane integrity protection policy is used as an example. A user plane integrity protection policy may include enabling (required), disabling (not needed), or selecting (preferred) user plane integrity protection. For an example of a user plane cryptographic protection policy, see the example of a user plane integrity protection policy. Further details are not provided here.

[0176] The user plane security policy in the embodiments of this application primarily relates to a security policy used in the user plane between terminal devices and access network devices. For example, the user plane security policy may include at least one of the following: namely, a user plane encryption protection policy in Uu connections and a user plane integrity protection policy in Uu connections.

[0177] In this embodiment of the present application, for ease of explanation, unless otherwise specified, the user plane cryptographic protection policy in a Uu connection and the user plane integrity protection policy in a Uu connection will be briefly referred to as the user plane cryptographic protection policy and the user plane integrity protection policy, respectively.

[0178] In possible design methods, security protection directive information may be obtained in accordance with the user plane security policy. The user plane integrity protection policy is used as an example. If the user plane integrity protection policy is required, the access network device (terminal device) decides that the user plane integrity protection directive information for the corresponding user plane data will be enabled. If the user plane integrity protection policy is not needed, the access network device decides that the user plane integrity protection directive information for the corresponding user plane data will be disabled. If the user plane integrity protection policy is preferred, the access network device decides that the user plane integrity protection directive information for the corresponding user plane data may be enabled or disabled. For example, the access network device may decide whether to enable user plane integrity protection in accordance with local policies (such as the operational status of the access network device, control policies, or regulatory requirements). For an example of a user plane encryption protection policy, see the example of the user plane integrity protection policy. Further details are not provided here.

[0179] In embodiments of this application, it should be noted that when a user plane security policy is transmitted, typically only one of three types ("required," "not needed," and "preferred") is selected for transmission. In some special scenarios, at least two types may be selected for transmission, one of which is "preferred." For example, when "not needed" and "preferred" are transmitted, it indicates that it is preferable for security protection to be disabled. When "required" and "preferred" are transmitted, it indicates that it is preferable for security protection to be enabled.

[0180] Second: Security capabilities. Security capability refers to the security algorithms supported by the terminal device, and the security algorithms may include at least one of the following: one or more cryptographic protection algorithms and one or more integrity protection algorithms.

[0181] For example, security capabilities can differ across different network standards. For instance, in a 4G communication system, security capabilities might be EPS security capabilities, while in a 5G communication system, security capabilities might be NR security capabilities.

[0182] EPS security capability may include at least one of the following algorithm identifiers, namely EPS (or 4G) integrity algorithms (EIA) 0 to EIA7 and EPS (or 4G) encryption algorithms (EEA) 0 to EEA7. Optionally, algorithm identifier EIA7 may indicate that the terminal device supports user plane integrity protection (UPIP). NR security capability may include at least one of the following algorithm identifiers, namely 5G integrity algorithms (NIA) 0 to NIA7 and 5G encryption algorithms (NEA) NEA0 to NEA7. Algorithm identifiers identify algorithms. For example, algorithm identifier EIA1 corresponds to the SNOW 3G algorithm.

[0183] It should be noted that an integrity algorithm may also be called an integrity protection algorithm, and an encryption algorithm may also be called an encryption protection algorithm. In the embodiments of this application, an integrity protection algorithm and an encryption protection algorithm are used as illustrative examples.

[0184] Third: Network standards. Network standards refer to the type of network. In this application, network standards primarily refer to the type of mobile communication network. For example, network standards may include 2nd generation (2G), global system for mobile communications (GSM), 3rd generation (3G), code division multiple access (CMDA), 4G, LTE, EPS, 5G, NR, and 5GS.

[0185] It should be noted that the first and second network standards are limited in this application on the condition that the first and second network standards are different network standards.

[0186] For example, Figure 2 is a schematic flowchart of a communication method according to one embodiment of the present application. The communication method is applicable to communication between a terminal device and an access network device, and communication between an access network device and a core network element, as shown in Figure 1. The core network element may include an MME network element, an SGW network element, an HSS+UDM network element, and an SMF+PGW-C network element. In Figure 2, an initial access scenario is used as an example.

[0187] As shown in Figure 2, the communication method includes the following steps.

[0188] S201: The terminal device sends an attach request message to the MME network element. In response, the MME network element receives the attach request message from the terminal device.

[0189] For example, an attach request message includes the EPS security capability of the terminal device. EPS security capability includes EIA7, which may indicate that the terminal device supports user plane integrity protection.

[0190] S202: The MME network element sends a location update request message to the HSS+UDM network element. In response, the HSS+UDM network element receives a location update request message from the MME network element.

[0191] S203: The HSS+UDM network element sends a location update request acknowledgment (ACK) message to the MME network element. In response, the MME network element receives a location update request acknowledgment message from the HSS+UDM network element.

[0192] S204: The MME network element sends a create session request message to the SGW network element. In response, the SGW network element receives a create session request message from the MME network element.

[0193] S205: The SGW network element sends a session creation request message to the SMF+PGW-C network element. In response, the SMF+PGW-C network element receives a session creation request message from the SGW network element.

[0194] For specific embodiments of S202 to S205, please refer to the existing embodiments. Details will not be explained again here.

[0195] S206: The SMF+PGW-C network element retrieves the user plane security policy.

[0196] Optionally, the user plane security policy may include either User Plane Security Policy 1 or User Plane Security Policy 2.

[0197] For example, if an interface is defined between an SMF+PGW-C network element and an HSS+UDM network element, the SMF+PGW-C network element may obtain user plane security policy 1 from the HSS+UDM network element, or, if not, the SMF+PGW-C network element may use the default user plane security policy 2.

[0198] Optionally, whether MME network elements and SGW network elements support UPIP may be known according to the general packet radio service tunneling protocol-control plane (GTP-C) signaling compatibility principle. If MME network elements and SGW network elements support UPIP, the Create Session Response message in S207 may include the user plane security policy.

[0199] S207: The SMF+PGW-C network element sends a create session response message to the SGW network element. In response, the SGW network element receives a create session response message from the SMF+PGW-C network element.

[0200] Optionally, the creation session response message may include the bearer contexts to be created.

[0201] Optionally, the bearer context to be created may include user plane security policies, such as user plane integrity protection policies.

[0202] S208: The SGW network element sends the user plane security policy to the MME network element. In response, the MME network element receives the user plane security policy from the SGW.

[0203] For specific implementations of the user plane security policy, please refer to the above description of the user plane security policy. Further details will not be provided here.

[0204] S209: The MME network element decides to send the user plane security policy to the access network device.

[0205] For example, if the EPS security capability determines that the terminal device supports user plane integrity protection, the MME network element sends the user plane security policy to the access network device. For example, if the EPS security capability includes EIA7, the MME network element sends the user plane security policy to the access network device. If the EPS security capability determines that the terminal device does not support user plane integrity protection, the MME network element does not need to send the user plane security policy to the access network device.

[0206] S210: The MME network element sends an S1 message to the access network device. In response, the access network device receives an S1 message from the MME network element.

[0207] For example, an S1 message may include EPS security capabilities, where S1 is a logical interface between an MME network element and an access network device. Optionally, an S1 message may further include a user plane security policy.

[0208] For example, a user plane security policy may include a user plane integrity protection policy.

[0209] S211: The access network device determines the 4G algorithm identifier based on the terminal device's EPS security capability.

[0210] For example, EPS security capability includes one or more 4G integrity protection algorithm identifiers and one or more 4G encryption protection algorithm identifiers.

[0211] Optionally, an access network device may select a 4G encryption protection algorithm identifier from one or more 4G encryption protection algorithm identifiers based on a locally configured algorithm priority list and EPS security capabilities.

[0212] Optionally, an access network device may select a 4G integrity algorithm identifier from one or more 4G integrity algorithm identifiers based on a locally configured algorithm priority list and EPS security capabilities.

[0213] Furthermore, in some embodiments, the access network device derives the control plane cryptographic protection key Krrc-enc based on the access network device key KeNB, a selected 4G cryptographic protection algorithm identifier (e.g., EEA1, EEA2, or EEA3), and an algorithm type distinguisher (e.g., RRC-enc-alg, value 0x03). Krrc-enc is used to perform cryptographic protection on RRC messages from terminal devices and access network devices, i.e., to activate cryptographic protection for signaling radio bearers (SRBs).

[0214] Optionally, the access network device key KeNB may be obtained from the initial context setup request message.

[0215] In some embodiments, the access network device derives a control plane integrity protection key Krrc-int based on the access network device key KeNB, a selected 4G integrity protection algorithm identifier (e.g., EIA1, EIA2, or EIA3), and an algorithm type distinguisher (e.g., RRC-int-alg, value 0x04). Krrc-int is used to perform integrity protection on RRC messages from terminal devices and access network devices, i.e., to activate integrity protection for signaling radio bearers (SRBs).

[0216] In some embodiments, the access network device derives a user plane cryptographic protection key Kup-enc based on the access network device key KeNB, a selected 4G cryptographic protection algorithm identifier (e.g., EEA1, EEA2, or EEA3), and an algorithm type distinguisher (e.g., UP-enc-alg, value 0x05). Kup-enc is used to perform cryptographic protection on user plane data of terminal devices and access network devices.

[0217] Furthermore, the access network device may activate security protection between the access network device and the terminal device based on the derived key and the selected 4G security algorithm.

[0218] In some embodiments, the access network device may activate control plane encryption protection between the access network device and terminal devices based on Krrc-enc and a selected 4G encryption protection algorithm.

[0219] In some embodiments, the access network device may activate control plane integrity protection between the access network device and terminal devices based on Krrc-int and a selected 4G integrity protection algorithm (e.g., the SNOW 3G algorithm corresponding to EIA1), for example, by activating RRC integrity protection.

[0220] In some embodiments, the access network device may activate user plane encryption protection between the access network device and terminal devices based on Kup-enc and a selected 4G encryption protection algorithm.

[0221] For example, when an access network device activates integrity protection, it means that after activating integrity protection, the access network device will perform integrity protection on transmitted RRC messages or user plane messages using the 4G integrity protection algorithm and Krrc-int or Kup-int, and will perform integrity checks on received RRC messages or user plane messages using the 4G integrity protection algorithm and Krrc-int or Kup-int.

[0222] For example, when an access network device activates encryption protection, it means that RRC messages or user plane messages sent by the access network device after encryption protection is activated will be encrypted using the 4G encryption protection algorithm and Krrc-enc or Kup-enc, and that received RRC messages or user plane messages will be decrypted using the 4G encryption protection algorithm and Krrc-enc or Kup-enc.

[0223] Optionally, the access network device may store the EPS security capabilities, user plane security policy, Krrc-enc, Krrc-int, Kup-enc, selected 4G encryption protection algorithm, and selected 4G integrity protection algorithm as the AS security context for the terminal device.

[0224] S212: The access network device sends an AS security mode command (SMC) message to the terminal device. In response, the terminal device receives an AS SMC message from the access network device.

[0225] Optionally, security mode command messages may include a 4G encryption protection algorithm identifier, and may further include a 4G integrity protection algorithm identifier.

[0226] S213: The terminal device enables control plane security protection.

[0227] In some embodiments, the terminal device derives the control plane cryptographic protection key Krrc-enc based on the access network device key KeNB, the 4G cryptographic protection algorithm identifier, and the algorithm type distinguisher.

[0228] In some embodiments, the terminal device derives a control plane integrity key Krrc-int based on the access network device key KeNB, a selected 4G integrity protection algorithm identifier, and an algorithm type distinguisher.

[0229] In some embodiments, the terminal device derives the user plane cryptographic protection key Kup-enc based on the access network device key KeNB, the selected 4G cryptographic protection algorithm identifier, and the algorithm type distinguisher.

[0230] Furthermore, the terminal device may activate security protections between the access network device and the terminal device based on the derived key and 4G security algorithm.

[0231] In some embodiments, the terminal device may activate control plane encryption protection between the access network device and the terminal device based on Krrc-enc and 4G encryption protection algorithms.

[0232] In some embodiments, the terminal device may activate control plane integrity protection between the access network device and the terminal device based on Krrc-int and a selected 4G integrity protection algorithm, for example, by activating RRC integrity protection.

[0233] In some embodiments, the terminal device may activate user-plane encryption protection between the access network device and the terminal device based on Kup-enc and a selected 4G encryption protection algorithm. In other words, in addition to control-plane security protection, the terminal device may further activate user-plane encryption protection.

[0234] For example, when a terminal device activates integrity protection, it means that after activating integrity protection, the terminal device will use the 4G integrity protection algorithm and Krrc-int or Kup-int to perform integrity protection on transmitted RRC messages or user plane messages, and will use the 4G integrity protection algorithm and Krrc-int or Kup-int to perform integrity checks on received RRC messages or user plane messages.

[0235] For example, when a terminal device activates encryption protection, it means that RRC messages or user plane messages sent by the terminal device after encryption protection is activated will be encrypted using the 4G encryption protection algorithm and Krrc-enc or Kup-enc, and that received RRC messages or user plane messages will be decrypted using the 4G encryption protection algorithm and Krrc-enc or Kup-enc.

[0236] Optionally, the terminal device may store Krrc-enc, Krrc-int, Kup-enc, a selected 4G encryption protection algorithm, and a selected 4G integrity protection algorithm as the terminal device's AS security context.

[0237] S214: The terminal device sends an AS security mode complete (SMP) message to the access network device. In response, the access network device receives an AS SMP message from the terminal device.

[0238] S215: The access network device determines the user plane security activation instruction information.

[0239] Optionally, an access network device may determine user plane security activation directive information based on EPS security capabilities and / or user plane security policies.

[0240] For example, when obtaining a user plane security policy from an MME, the access network device determines user plane security activation instruction information according to the user plane security policy.

[0241] For example, if an access network device does not obtain a user plane security policy from the MME, but the EIA7 of the EPS security capability indicates that the terminal device supports user plane integrity protection, the access network device will determine user plane security activation instruction information according to the pre-configured user plane security policy.

[0242] If the user plane security activation instruction information indicates cipheringDisabled, it indicates that encryption protection will be disabled; otherwise, it indicates that encryption protection will be enabled. For example, if an access network device has enabled user plane encryption protection in S211, it may indicate that user plane encryption protection will be disabled in S215.

[0243] If the user plane integrity protection status indicates integrity protection, it means that integrity protection is enabled; otherwise, it means that integrity protection is disabled.

[0244] For example, an access network device may enable user plane encryption protection between the access network device and a terminal device, but not enable user plane integrity protection between the access network device and the terminal device, based on user plane security activation instruction information.

[0245] It should be noted that after determining the user plane security activation instruction information, the access network device may immediately activate user plane security protection, or it may activate user plane security protection before receiving user plane data. This is not limited to the present application.

[0246] S216: The access network device sends a first radio resource control (RRC) reconfiguration message to the terminal device. In response, the terminal device receives the first RRC reconfiguration message from the access network device.

[0247] Optionally, the first RRC reconfiguration message may include user plane security activation instruction information.

[0248] Optionally, the first RRC reconfiguration message may not carry user-plane security activation instruction information. This implicitly indicates that, by default, user-plane cryptographic protection is enabled and user-plane integrity protection is disabled.

[0249] For example, based on the user plane security activation instruction information carried in the first RRC reconfiguration message, the terminal device may decide to enable user plane security encryption protection between the terminal device and the access network device (or, if user plane security encryption protection is enabled in S213, not to re-enable user plane security encryption protection), and not to enable user plane integrity protection. Then, encryption protection is performed on the user plane data transmitted between the terminal device and the access network device, and integrity protection cannot be performed.

[0250] In a possible design, the terminal device may send an RRC connection reconfiguration complete message to the access network device. In response, the access network device receives the RRC connection reconfiguration complete message from the terminal device.

[0251] S217: The MME network element sends an attach accept message to the terminal device. In response, the terminal device receives an attach accept message from the MME network element.

[0252] Optionally, the attach authorization message may prompt the terminal device to complete the initial access.

[0253] In the communication method shown in Figure 2, user-plane encryption protection and integrity protection can be enabled, but the parameters obtained by the access network device and terminal device to activate user-plane integrity protection, and the solution for activating user-plane integrity protection are not provided.

[0254] For example, Figure 3 is a schematic flowchart of another communication method according to one embodiment of the present application. The communication method is applicable to communication between a terminal device and an access network device, and communication between an access network device and a core network element, as shown in Figure 1. The method shown in Figure 3 is applicable to any scenario in which user plane integrity protection needs to be flexibly enabled, such as multiple scenarios in which the DRB is established or re-established, including initial access, PDN session establishment, dedicated bearer activation, X2 handover (where X2 is a communication interface between access network devices), and S1 handover, and illustrates a solution for activating user plane integrity protection.

[0255] As shown in Figure 3, the communication method includes the following steps.

[0256] S301: When the first condition is met, the access network device of the first network standard obtains user plane integrity protection instruction information and integrity protection algorithm identifier of the second network standard.

[0257] For example, the first network standard may include 4G, LTE, or EPS.

[0258] For example, the second network standard could include 5G, NR, or 5GS.

[0259] In some embodiments, the first condition includes deciding to establish a first DRB between an access network device and a terminal device of a first network standard, and deciding to enable user plane integrity protection for the first DRB.

[0260] For example, an access network device of a first network standard may decide to establish a DRB for a terminal device in an attach procedure to establish a default EPS bearer, or it may decide to establish a DRB in a PDN connection establishment process or a dedicated bearer activation process to establish a dedicated EPS bearer, or it may restore a DRB on a new access network device in a mobility process, for example, by performing a handover or re-establishment.

[0261] In some embodiments, the first condition may further include that the terminal device supports user plane integrity protection.

[0262] Note that terminal devices may support User Plane Integrity Protection (UPIP) in multiple ways.

[0263] For example, "supports user plane integrity protection" or "supports UPIP" may have an object-based description method, and features may be described, for example, as "supports the feature of object (which can be replaced by one of the following features 1 to 3)" or "supports the feature (which can be replaced by one of the following features 1 to 3)".

[0264] For example, an object may include (1) evolved packet core (EPC), (2) eNB, (3) LTE, (4) E-UTRA with EPC, (5) EPC based Dual Connectivity of E-UTRA and NR radio access technology (RAT), and (6) EPS.

[0265] For example, features may include (1) user plane integrity protection, (2) user plane security protection, and (3) on-demand user plane protection (whether to enable user plane cryptographic protection and / or user plane integrity protection may be determined according to the user plane security policy).

[0266] For example, referring to object (1) and feature (1), "The terminal device supports user plane integrity protection" can be expressed as "The terminal device supports user plane integrity protection with EPC."

[0267] For example, referring to object (2) and feature (1), "The terminal device supports user plane integrity protection" can be expressed as "The terminal device supports user plane integrity protection with the eNB." The eNB may be an access network device of the first network standard. That is, the terminal device supports user plane integrity protection with the access network device of the first network standard.

[0268] In some embodiments, if the object is optional, this can be expressed as β€œthe terminal device supports user plane integrity protection” with reference to feature (1).

[0269] Please note that similar descriptions of "supports user plane integrity protection" or "supports UPIP" used below may be replaced with "supports an object feature (which can be replaced by one of the aforementioned features 1 through 3)" or "supports a feature (which can be replaced by one of the aforementioned features 1 through 3)."

[0270] In some embodiments, whether a terminal device supports user plane integrity protection can be determined by an access network device of a first network standard based on user plane instruction information.

[0271] For example, user plane instruction information may indicate whether the terminal device supports user plane integrity protection.

[0272] In some embodiments, an access network device of the first network standard may acquire user plane instruction information by the following steps 1a and 2a, or step 1b.

[0273] Step 1a: The terminal device transmits user plane instruction information to the core network element of the first network standard. In response, the core network element of the first network standard receives user plane instruction information from the terminal device.

[0274] Optionally, user plane instruction information may be transmitted using NAS signaling.

[0275] For example, user plane instruction information can be encapsulated in terminal device capability information, such as the terminal device's EPS security capability.

[0276] Step 2a: The core network element of the first network standard transmits user plane instruction information to the access network device of the first network standard. In response, the access network device of the first network standard receives user plane instruction information from the core network element of the first network standard.

[0277] Optionally, user plane instruction information may be transmitted using S1 signaling.

[0278] In other words, an access network device of the first network standard can obtain user plane instruction information from a terminal device via the core network elements of the first network standard.

[0279] Step 1b: The terminal device transmits user plane instruction information to an access network device of the first network standard. In response, the access network device of the first network standard receives user plane instruction information from the terminal device.

[0280] Optionally, user plane instruction information may be transmitted using RRC signaling.

[0281] For example, user plane instruction information can be encapsulated in the terminal device's radio capability information, such as the terminal device's evolved UMTS terrestrial radio access network (E-UTRAN) wireless capability.

[0282] In other words, an access network device of the first network standard can directly obtain user plane instruction information from a terminal device.

[0283] In this way, an access network device of the first network standard can determine, based on user plane instruction information, whether a terminal device supports user plane integrity protection. If the user plane instruction information indicates that the terminal device supports user plane integrity protection, the access network device of the first network standard can know that the terminal device supports user plane integrity protection; otherwise, the terminal device does not support user plane integrity protection.

[0284] In a possible design, user plane integrity protection instruction information may indicate that user plane integrity protection for the first DRB is enabled.

[0285] In other words, in order to implement on-demand user plane integrity protection, user plane integrity protection corresponding to the first DRB may be activated.

[0286] Optionally, user plane integrity protection instruction information may be determined by an access network device of the first network standard in accordance with the user plane integrity protection policy.

[0287] For example, if a user plane integrity protection policy includes enabling user plane integrity protection, the user plane integrity protection instruction information indicates enabling user plane integrity protection for the first DRB, or if a user plane integrity protection policy includes disabling user plane integrity protection, the user plane integrity protection instruction information indicates disabling user plane integrity protection for the first DRB.

[0288] In some embodiments, user plane integrity protection instruction information may be determined by an access network device of a first network standard in accordance with the received user plane integrity protection policy.

[0289] Optionally, an access network device of a first network standard may obtain a user plane integrity protection policy from an external network element.

[0290] For example, an access network device of a first network standard receives a user plane integrity protection policy from an MME network element. Naturally, the access network device of the first network standard may further receive a user plane encryption protection policy. This is not limited in this application. For specific embodiments, refer to S210 shown in FIG. 2. For the process by which the MME network element obtains a user plane integrity protection policy, refer to S204 to S208.

[0291] In another example, an access network device of a first network standard receives a user plane integrity protection policy from another access network device. The other access network device may be a source access network device in a mobility scenario such as handover or re-establishment.

[0292] In some other embodiments, the user plane integrity protection indication information may be determined by an access network device of a first network standard according to a pre-configured user plane integrity protection policy.

[0293] For example, an access network device of a first network standard pre-configures a user plane integrity protection policy. Naturally, the access network device of the first network standard may further pre-configure a user plane encryption protection policy. This is not limited in this application.

[0294] Optionally, the integrity protection algorithm identifier of a second network standard may be a 5G integrity protection algorithm identifier, such as NIA0 to NIA7.

[0295] In a possible design method, the integrity protection algorithm identifier of the second network standard may be determined based on the security capabilities of the terminal device to the second network standard.

[0296] For example, the security capability of the second network standard may be an NR security capability, which includes at least one algorithm identifier, and an access network device of the first network standard may select one integrity protection algorithm identifier from at least one algorithm identifier.

[0297] Optionally, an access network device of the first network standard may select an integrity protection algorithm identifier of the second network standard based on the terminal device's NR security capabilities and a locally configured algorithm priority list.

[0298] For example, if the NR security capability reported by a terminal device indicates that the terminal device supports NIA1 and NIA2, and the priority in the algorithm priority list is NIA3 > NIA2 > NIA1, then an access network device of the first network standard may, after considering the two, select NIA2 as the chosen integrity protection algorithm identifier for the second network standard.

[0299] For a detailed explanation of NR security capabilities, please refer to the previously mentioned explanation of security capabilities. Further details will not be provided here.

[0300] Optionally, an access network device of the first network standard may acquire the security capabilities of a terminal device of the second network standard in multiple ways.

[0301] In a possible design method, the integrity protection algorithm identifier of the second network standard is determined based on the security capabilities of the first network standard.

[0302] For example, an access network device of a first network standard may determine the security capabilities of a second network standard based on the security capabilities of the first network standard, and determine the integrity protection algorithm identifier of the second network standard based on the security capabilities of the second network standard.

[0303] Optionally, when a terminal device supports user plane integrity protection, an access network device of the first network standard determines the security capability of the second network standard based on the security capability of the first network standard, and the security capability of the second network standard includes the integrity protection algorithm identifier of the second network standard. In this way, wasted power consumption can be avoided. Specifically, the security capability of the second network standard is determined when the terminal device does not support user plane integrity protection, but user plane integrity protection cannot be implemented. This results in meaningless operation and wasted power consumption.

[0304] In some embodiments, the security capability of a first network standard includes an integrity protection algorithm identifier for the first network standard, and the security capability of a second network standard includes an integrity protection algorithm identifier for the second network standard, the integrity protection algorithm identifier for the second network standard is obtained by mapping the integrity protection algorithm identifier for the first network standard.

[0305] Assuming that EPS security capabilities include EEA1, EEA2, EIA1, and EIA2, the mapped NR security capabilities include NEA1, NEA2, NIA1, and NIA2. Specifically, NEA1 is obtained by mapping based on EEA1, NEA2 by mapping based on EEA2, NIA1 by mapping based on EIA1, and NIA2 by mapping based on EIA2. This mapping method is also applicable to EIA3 through EIA7 and EEA3 through EEA7.

[0306] For example, the integrity algorithm (SNOW 3G algorithm) identified by the 4G integrity algorithm identifier EIA1 and the 5G integrity algorithm identifier NIA1 is the same. Similarly, the integrity algorithm (advanced encryption standard (AES) algorithm) identified by EIA2 and NIA2 is the same, and the integrity algorithm (ZUC algorithm) identified by EIA3 and NIA3 is the same, and so on. In this way, the integrity algorithm identifier of a second network standard can be obtained by mapping it to the integrity algorithm identifier of a first network standard.

[0307] In some embodiments, the communication method shown in Figure 3 may further include S305: the core network element of the first network standard transmits a second message to an access network device of the first network standard. Correspondingly, the access network device of the first network standard receives the second message from the core network element of the first network standard.

[0308] Optionally, the second message may include the security capabilities of the terminal device in accordance with the first network standard.

[0309] For example, the second message may be an initial context setup request message.

[0310] Optionally, the access network device of the first network standard may store the security capabilities of the terminal device for the first network standard as the AS security context of the terminal device.

[0311] In another possible design method, the security capabilities of the second network standard may be received by the access network device of the first network standard from the core network element of the first network standard.

[0312] For example, the second message may further include the security capabilities of the terminal device for the second network standard.

[0313] Optionally, the access network device of the first network standard may store the NR security capabilities of the terminal device in the AS security context of the terminal device.

[0314] When the core network element of the first network standard is a conventional MME network element, the second message may not include the security capabilities of the second network standard. This is because when the MME network element is a conventional MME network element, the MME network element cannot correctly identify the security capabilities of the second network standard, and thus cannot send the security capabilities to the access network device. When the MME network element is not a conventional MME network element, for example, an MME network element that supports UPIP, the MME network element can identify the security capabilities of the terminal device for the second network standard. In this case, the second message may include the security capabilities of the terminal device for the second network standard.

[0315] In some embodiments, the communication method shown in Figure 3 may further include S306: the terminal device transmits a third message to a core network element of the first network standard. Correspondingly, the core network element of the first network standard receives the third message from the terminal device.

[0316] Optionally, the third message may include the security capabilities of the first network standard.

[0317] Optionally, S306 may include, when the terminal device supports user plane integrity protection, the terminal device transmitting security capabilities of a second network standard to the core network elements of the first network standard. That is, the third message may further include security capabilities of a second network standard.

[0318] For example, the third message could be an attach request message or a tracking area update (TAU) request message.

[0319] S302: An access network device of the first network standard sends a first message to a terminal device. In response, the terminal device receives the first message.

[0320] For example, the first message may include user plane integrity protection instruction information and a second network standard integrity protection algorithm identifier.

[0321] In some embodiments, the first message may further include first instruction information.

[0322] Optionally, the first instruction information may indicate that the master key is used to determine the first key.

[0323] For example, the master key could be a KeNB (Key of Access Network Device) for a first network standard.

[0324] When the communication method shown in Figure 3 is applied to a dual connectivity scenario, the key of the access network device of the first network standard may be called the master key, and the key of the access network device of the second network standard may be called the secondary key.

[0325] For example, the first key could be a user plane integrity protection key, which could be used to perform integrity protection on user plane data between a terminal device and an access network device. For example, the first key could be a Kup-int.

[0326] For example, the first message could be an RRC connection reconfiguration message.

[0327] In possible design methods, user plane integrity protection instruction information and the integrity protection algorithm identifier of the second network standard may be encapsulated in the Radiobearerconfig information element of the first message. Optionally, the first instruction information may also be encapsulated in the Radiobearerconfig information element of the first message.

[0328] For example, user plane integrity protection instruction information is encapsulated in the PDCP configuration (PDCP-config) of the Radiobearerconfig information element. For example, integrity protection information elements are encapsulated in PDCP-config.

[0329] In some embodiments, when user plane integrity protection instruction information indicates that user plane integrity protection is not enabled (or will be disabled), the information element does not need to be encapsulated in PDCP-config. In this case, integrity protection is disabled by default.

[0330] For example, the integrity protection algorithm identifier of the second network standard can be encapsulated in the securityAlgorithmConfig information element of the Radiobearerconfig information element.

[0331] For example, the first instruction information may be encapsulated in a key (keyToUse) information element used in the Radiobearerconfig information element.

[0332] For example, an access network device of a first network standard may set keyToUse as the master key, thereby allowing terminal devices to generate user plane keys using the master key based on the keyToUse instruction. For example, the first key is determined based on the master key, the integrity protection algorithm identifier of a second network standard, and the first algorithm type distinguisher (e.g., N-UP-int-alg, value 0x07).

[0333] Alternatively, for example, the first instruction information may be implicitly indicated. The first message does not carry the keyToUse information element, which indicates that, by default, the user plane key is derived using the master key.

[0334] S303: An access network device of the first network standard activates user plane integrity protection of the first DRB based on the first key and the integrity protection algorithm of the second network standard.

[0335] It should be noted that the order of S302 and S303 is not limited to this embodiment of the present application.

[0336] Optionally, the first key may be determined by the access network device of the first network standard based on the master key, the integrity protection algorithm identifier of the second network standard, and the first algorithm type identifier. For example, the first key is the user plane integrity protection key Kup-int.

[0337] For example, the value of the first algorithm type distinguisher could be 0x07. For example, the first algorithm type distinguisher is N-UP-int-alg.

[0338] For example, the master key can be obtained from the AS security context of the terminal device.

[0339] Alternatively, the access network device of the first network standard may optionally obtain the first key, for example, a pre-derived Kup-int, directly from the AS security context of the terminal device.

[0340] In this way, an access network device of the first network standard can activate user plane integrity protection of the first DRB based on Kup-int and the integrity protection algorithm of the second network standard. Therefore, after the access network device of the first network standard activates user plane integrity protection, integrity protection is performed on transmitted user plane data using the integrity protection algorithm of the second network standard and Kup-int, and integrity checks are performed on received user plane data packets using the integrity protection algorithm of the second network standard and Kup-int.

[0341] Optionally, S303 may include the configuration of a first network standard access network device with respect to a second network standard PDCP entity corresponding to a first DRB, and an integrity protection algorithm of the second network standard.

[0342] For example, a PDCP entity of a second network standard could be an NR PDCP entity.

[0343] In this way, the access network device of the first network standard activates user plane integrity protection to implement on-demand user plane integrity protection.

[0344] S304: When the first message is from an access network device of the first network standard and the user plane integrity protection instruction information indicates that user plane integrity protection of the first DRB should be enabled, the terminal device activates user plane integrity protection of the first DRB based on the first key and the integrity protection algorithm of the second network standard.

[0345] Optionally, the terminal device may determine whether the terminal device is connected to a network of a first network standard.

[0346] For example, a terminal device may determine whether it is currently connected to E-UTRA / EPC based on a Public Land Mobile Network Identifier (PLMN) ID broadcast by an access network device of a first network standard. For example, if the PLMN ID broadcast by an access network device of a first network standard does not include 5G, the terminal device may determine that it is connected to E-UTRA / EPC.

[0347] For example, if user plane integrity protection instruction information indicates that user plane integrity protection should be enabled, and the terminal device is connected to E-UTRAN / EPC, the terminal device may activate user plane integrity protection of the first DRB based on the integrity protection algorithm of the first key and the second network standard.

[0348] In some embodiments, a terminal device may determine, based on a PLMN ID, whether a first message originates from an access network device of a first network standard, where the PLMN ID is from the access network device sending the first message. For example, access network device 1 broadcasts a PLMN ID and sends a first message to the terminal device. If the PLMN ID does not contain 5G, then access network device 1 is an access network device of a first network standard, and the first message originates from an access network device of a first network standard.

[0349] Optionally, the first key may be determined by the terminal device based on the master key, the integrity protection algorithm identifier of the second network standard, and the first algorithm type distinguisher (e.g., N-UP-int-alg, value 0x07). For example, the first key may be the user plane integrity protection key Kup-int.

[0350] For example, the master key may be obtained by the terminal device from the terminal device's AS security context based on the first instruction information.

[0351] Alternatively, the terminal device may optionally obtain the first key, for example, a pre-derived Kup-int, directly from the terminal device's AS security context.

[0352] In this way, the terminal device can activate user plane integrity protection of the first DRB based on Kup-int and the integrity protection algorithm of the second network standard. Therefore, after activating user plane integrity protection, the terminal device uses the integrity protection algorithm of the second network standard and Kup-int to perform integrity protection on transmitted user plane data and uses the integrity protection algorithm of the second network standard and Kup-int to perform integrity checks on received user plane data packets.

[0353] Optionally, S304 may include, when the first message is from an access network device of a first network standard and the user plane integrity protection instruction information indicates that user plane integrity protection for the first DRB should be enabled, the terminal device configuring a first key and a second network standard integrity protection algorithm for a PDCP entity of a second network standard corresponding to the first DRB, based on the user plane integrity protection instruction information.

[0354] For example, the RRC layer of a terminal device may configure an integrity protection algorithm for a first key and a second network standard for an NR PDCP entity corresponding to a first DRB.

[0355] In this way, the terminal device activates user plane integrity protection to implement on-demand user plane integrity protection.

[0356] In possible design methods, the communication method shown in Figure 3 may further include S307. The terminal device sends an RRC reconfiguration complete message to the access network device of the first network standard. In response, the access network device of the first network standard receives the RRC reconfiguration complete message from the terminal device.

[0357] It should be noted that in this embodiment of the present application, the order of S303 and S307 is not limited, and the order of S304 and S307 is not limited.

[0358] In possible design methods, the communication method shown in Figure 3 may further include S308 to S311. For embodiments of S308 to S311, please refer to S211 to S214, respectively. The main difference is that "4G" is replaced with "first network standard" and "access network device" is replaced with "access network device of the first network standard". In this way, the communication method shown in Figure 3 may further implement on-demand user plane encryption protection. Note that S308 to S311 may be performed before S301. This is not limited to the present application.

[0359] S308: The access network device of the first network standard determines the 4G algorithm identifier based on the EPS security capability of the terminal device.

[0360] In a possible design, an access network device of the first network standard derives a first key, for example, a user plane integrity protection key Kup-int, based on a master key and an integrity protection algorithm identifier of the first network standard. Kup-int is used to perform integrity protection on user plane data between a terminal device and the access network device of the first network standard.

[0361] In other words, in the process of deriving the control plane key and user plane encryption key, the access network device of the first network standard can derive a Kup-int based on the master key KeNB and the 4G integrity protection algorithm identifier. Therefore, in S303, the access network device of the first network standard can directly obtain the first key from the AS security context of the terminal device. In S304, the terminal device can directly obtain the first key from the AS security context of the terminal device.

[0362] Note that access network devices of the first network standard may activate user-plane encryption protection in S308, but do not activate user-plane encryption protection in S303.

[0363] For example, the first message in S301 may further include user plane cryptographic protection status indicator information to indicate whether user plane cryptographic protection is enabled or disabled. If S308 through S311 are executed before S301, and an access network device of the first network standard activates user plane cryptographic protection in S308, the access network device of the first network standard may disable the enabled user plane cryptographic protection in S303 in order to further implement on-demand user plane cryptographic protection.

[0364] S309: An access network device of the first network standard sends an AS SMC message to a terminal device. In response, the terminal device receives an AS SMC message from the access network device of the first network standard.

[0365] S310: The terminal device enables control plane security protection.

[0366] It should be noted that in this embodiment of the present application, the order of enabling security protection by the terminal device, deriving the key by the access network device of the first network standard, and activating security protection in S308 is not limited.

[0367] Note that the terminal device may activate user-plane encryption protection at S310, but will not activate user-plane encryption protection at S304.

[0368] For example, the first message in S301 may further include user plane cryptographic protection status indicator information to indicate whether user plane cryptographic protection is enabled or disabled. If S308 through S311 are executed before S301 and the terminal device activates user plane cryptographic protection in S310, the terminal device may disable the enabled user plane cryptographic protection in S304 in order to further implement on-demand user plane cryptographic protection.

[0369] S311: The terminal device sends an AS SMP message to an access network device of the first network standard. In response, the access network device of the first network standard receives an AS SMP message from the terminal device.

[0370] Based on the communication method shown in Figure 3, when it is decided to establish a first DRB and to enable user plane integrity protection for the first DRB, the access network device of the first network standard obtains user plane integrity instruction information and an integrity algorithm identifier of the second network standard indicating that user plane integrity protection is enabled, and transmits the user plane integrity instruction information and the integrity algorithm identifier of the second network standard to the terminal device. In this way, both the access network device of the first network standard and the terminal device can activate user plane integrity protection for the first DRB based on the first key and the integrity algorithm of the second network standard, thereby applying the on-demand user plane integrity protection mode of the second network standard to user plane integrity protection between the terminal device and the access network device of the first network standard, and reducing the changes to the terminal device.

[0371] For example, Figure 4 is a schematic flowchart of yet another communication method according to one embodiment of the present application. The communication method is applicable to communication between a terminal device and an access network device, and communication between an access network device and a core network element, as shown in Figure 1. The method shown in Figure 4 is applicable to any scenario in which user plane integrity protection needs to be flexibly enabled, such as multiple scenarios in which the DRB is established or re-established, including initial access, PDN session establishment, dedicated bearer activation, X2 handover (where X2 is an interface between access network devices), and S1 handover, and illustrates a solution for activating user plane integrity protection.

[0372] As shown in Figure 4, the communication method includes the following steps.

[0373] S401: When the first condition is met, the access network device of the first network standard obtains user plane integrity protection instruction information and integrity protection algorithm identifier of the first network standard.

[0374] Similar to the communication method shown in Figure 3, the first network standard may include 4G, LTE, or EPS, and the second network standard may include 5G, NR, or 5GS.

[0375] In some embodiments, the first condition includes deciding to establish a first DRB between an access network device and a terminal device of a first network standard, and deciding to enable user plane integrity protection for the first DRB. Optionally, the first condition may further include that the terminal device supports user plane integrity protection. For specific embodiments of the first condition, see the corresponding embodiments in S301, which are not described in detail here again.

[0376] In some embodiments, whether a terminal device supports user plane integrity protection can be determined by an access network device of a first network standard based on user plane instruction information. For specific embodiments, see the corresponding embodiments in S301, which are not described in detail here again.

[0377] For specific embodiments of how an access network device of the first network standard acquires user plane instruction information, see steps 1a and 2a or step 1b of S301. Further details are not provided here.

[0378] In possible design methods, user plane integrity protection instruction information may indicate that user plane integrity protection for the first DRB is enabled. For specific embodiments, see the corresponding embodiments in S301, which are not described in detail here again.

[0379] Optionally, the integrity protection algorithm of the first network standard may be the 4G integrity protection algorithm. For details, please refer to the corresponding description of security capabilities above.

[0380] In a possible design method, the integrity protection algorithm identifier of the first network standard may be determined based on the security capabilities of the terminal device to the first network standard.

[0381] For example, the security capability of a first network standard may be an EPS security capability, which includes at least one algorithm identifier, and an access network device of the first network standard may select an integrity protection algorithm identifier, such as EIA1, from the at least one algorithm identifier.

[0382] Optionally, an access network device of the first network standard may select an integrity protection algorithm identifier of the first network standard based on the terminal device's EPS security capabilities and a locally configured algorithm priority list. A specific embodiment is similar to the embodiment of S301, in which the integrity protection algorithm identifier of the second network standard is selected based on the terminal device's NR security capabilities and a locally configured algorithm priority list. Further details are not described here.

[0383] Optionally, the integrity protection algorithm identifier of the first network standard may be the currently used integrity protection algorithm identifier of the first network standard between the access network device and the terminal device of the first network standard.

[0384] For example, an access network device of the first network standard obtains the currently used integrity protection algorithm identifier of the first network standard from the AS security context of the terminal device.

[0385] In some embodiments, the communication method shown in Figure 4 may further include S405: the core network element of the first network standard transmits a fifth message to an access network device of the first network standard. Correspondingly, the access network device of the first network standard receives the fifth message from the core network element of the first network standard.

[0386] Optionally, the fifth message may include the security capabilities of the terminal device in accordance with the first network standard.

[0387] For example, the fifth message could be an initial context setup request message.

[0388] Optionally, an access network device of the first network standard may store the terminal device's security capabilities of the first network standard as the terminal device's AS security context.

[0389] In some embodiments, the communication method shown in Figure 4 may further include S406: the terminal device transmits a sixth message to the core network element of the first network standard. Correspondingly, the core network element of the first network standard receives the sixth message from the terminal device.

[0390] Optionally, the sixth message may include the security capabilities of the first network standard.

[0391] For example, the sixth message could be an attach request message or a tracking area update request message.

[0392] S402: An access network device of the first network standard sends the fourth message to a terminal device. In response, the terminal device receives the fourth message.

[0393] For example, the fourth message includes user plane integrity protection instruction information.

[0394] In some embodiments, the fourth message may further include the first instruction information and / or the second instruction information.

[0395] Optionally, the first instruction information may indicate that the first key is determined using the master key. For specific embodiments of the first instruction information, the master key, and the first key, see the corresponding description in S302. Further details are not provided here.

[0396] Optionally, the second instruction information may indicate activating user-plane integrity protection of the first DRB using the integrity protection algorithm of the first network standard.

[0397] For example, the second instruction information may include an integrity protection algorithm identifier of the first network standard, or the second instruction information may indicate that user plane integrity protection should be activated using the currently used integrity protection algorithm of the first network standard.

[0398] In this way, the second instruction information may indicate that user plane integrity protection should be enabled using the integrity protection algorithm being used, i.e., the integrity protection algorithm of the first network standard.

[0399] Alternatively, in some embodiments, the fourth message may include user plane integrity protection instruction information, which indicates enabling user plane integrity protection for the first DRB and implicitly indicates activating user plane integrity protection using the integrity protection algorithm of the first network standard.

[0400] In other words, user plane integrity protection instruction information may not only indicate that user plane integrity protection should be enabled, but also that user plane integrity protection should be activated using the integrity protection algorithm of the first network standard.

[0401] For example, the fourth message could be an RRC connection reconfiguration message.

[0402] In possible design methods, user plane integrity protection instruction information may be encapsulated in the Radiobearerconfig information element of the fourth message. Optionally, the first instruction information may be encapsulated in the Radiobearerconfig information element of the fourth message. Optionally, the second instruction information may be encapsulated in the Radiobearerconfig information element of the fourth message, or it may be encapsulated in a different information element of the fourth message, distinct from the Radiobearerconfig information element.

[0403] For embodiments that encapsulate user plane integrity protection instruction information in a Radiobearerconfig information element, see the corresponding embodiment in S302. Further details are not provided here.

[0404] For embodiments in which the first instruction information is encapsulated in the Radiobearerconfig information element, please refer to the corresponding embodiment in S302. Further details are not provided here.

[0405] For example, the second instruction information may include the integrity protection algorithm identifier of the first network standard. With respect to the second instruction information, the Radiobearerconfig information element may carry the algorithm configuration information element of the first network standard within securityAlgorithmConfig. This differs from the method shown in Figure 3.

[0406] For example, an algorithm configuration information element of the first network standard may be used to encapsulate an integrity protection algorithm identifier of the first network standard, indicating that the user plane integrity protection of the first DRB is activated using the integrity protection algorithm of the first network standard.

[0407] Optionally, the second instruction information may indicate activating user plane integrity protection using the currently used integrity protection algorithm of the first network standard. With respect to the second instruction information, the fourth message may carry the second instruction information element, but the second instruction information element does not have to be encapsulated in the Radiobearerconfig information element. This differs from the method shown in Figure 3.

[0408] It should be noted that the names of the information elements for encapsulating the integrity protection algorithm identifier of the first network standard are not limited in this application.

[0409] S403: An access network device of the first network standard activates user plane integrity protection of the first DRB based on the first key and the integrity protection algorithm of the first network standard.

[0410] It should be noted that the order of S402 and S403 is not limited to this embodiment of the present application.

[0411] In some embodiments, the first key may be determined by an access network device of the first network standard based on a master key, an integrity protection algorithm identifier of the first network standard, and a second algorithm type distinguisher (e.g., UP-int-alg, value 0x06). For example, the first key is the user plane integrity protection key Kup-int.

[0412] For example, the master key can be obtained from the AS security context of the terminal device.

[0413] Alternatively, the access network device of the first network standard may optionally obtain the first key, for example, a pre-derived Kup-int, directly from the AS security context of the terminal device.

[0414] For example, if the integrity protection algorithm identifier of the first network standard determined in S401 or S408 is EIA1, the access network device of the first network standard may determine the first key Kup-int-E based on the master key and the integrity protection algorithm identifier EIA1 of the first network standard.

[0415] In this way, an access network device of the first network standard can activate user plane integrity protection of the first DRB based on Kup-int-E and the integrity protection algorithm of the first network standard. Therefore, after activating user plane integrity protection, the access network device of the first network standard performs integrity protection on transmitted user plane data using the integrity protection algorithm of the first network standard and Kup-int-E, and performs integrity checks on received user plane data packets using the integrity protection algorithm of the first network standard and Kup-int-E.

[0416] In some embodiments, the first key may be determined by the access network device of the first network standard based on a master key, an integrity protection algorithm identifier of the second network standard, and a first algorithm type identifier (e.g., N-UP-int-alg, value 0x07), and the integrity protection algorithm identifier of the second network standard is determined based on the integrity protection algorithm identifier of the first network standard.

[0417] For example, the integrity protection algorithm identifier for the second network standard could be the 5G integrity protection algorithm identifier, such as NIA1.

[0418] Optionally, the integrity protection algorithm identifier of the second network standard is obtained by mapping the integrity protection algorithm identifier of the first network standard to the access network device of the first network standard.

[0419] For example, if the integrity protection algorithm identifier for the first network standard determined in S401 above or S408 below is EIA1, the integrity protection algorithm identifier NIA1 for the second network standard is obtained by mapping EIA1. In this way, the access network device for the first network standard can determine the first key Kup-int-N based on the master key, the integrity protection algorithm identifier NIA1 for the second network standard, and the first algorithm type distinguisher (e.g., N-UP-int-alg, value 0x07).

[0420] Note that while the algorithms identified by the integrity protection algorithm identifiers of the first and second network standards, which can be mapped to each other, may be the same, the first key used to determine them may be different.

[0421] For example, both EIA1 and NIA1 identify the SNOW 3G algorithm, but the first key Kup-int-E determined based on EIA1 and KeNB is different from the first key Kup-int-N determined based on NIA1 and KeNB. The first keys determined are different because the values ​​of the information elements corresponding to the integrity protection algorithm identifier of the first network standard and the integrity protection algorithm identifier of the second network standard are different.

[0422] In this way, an access network device of the first network standard may activate user plane integrity protection of the first DRB based on Kup-int-N and an algorithm identified by the integrity protection algorithm identifier of the second network standard (which may be called the integrity protection algorithm of the first network standard or the integrity protection algorithm of the second network standard, for example, the SNOW 3G algorithm).

[0423] In a possible design, S403 may include the access network device of the first network standard activating user plane integrity protection of the first DRB using the first key and the integrity protection algorithm of the first network standard based on the second instruction information. In this way, the access network device of the first network standard can perform on-demand user plane integrity protection using the integrity protection algorithm of the first network standard based on the instructions of the second instruction information.

[0424] In a possible design, S403 may include a first network standard access network device configuring a first key and a first network standard integrity protection algorithm for a second network standard PDCP entity corresponding to a first DRB.

[0425] In this way, the access network device of the first network standard activates user plane integrity protection to implement on-demand user plane integrity protection.

[0426] S404: When the fourth message is from an access network device of the first network standard and the user plane integrity protection instruction information indicates that user plane integrity protection of the first DRB should be enabled, the terminal device activates user plane integrity protection of the first DRB based on the first key and the integrity protection algorithm of the first network standard.

[0427] Optionally, the terminal device may determine whether the terminal device is connected to a network of a first network standard.

[0428] For example, a terminal device may determine whether it is currently connected to E-UTRA / EPC based on a PLMN ID broadcast by an access network device of a first network standard. For example, if the PLMN ID broadcast by an access network device of a first network standard does not include 5G, the terminal device may determine that it is connected to E-UTRA / EPC.

[0429] For example, if user plane integrity protection instruction information indicates that user plane integrity protection should be enabled, and the terminal device is connected to E-UTRAN / EPC, the terminal device may activate user plane integrity protection of the first DRB based on the first key and the integrity protection algorithm of the first network standard.

[0430] In some embodiments, a terminal device may determine, based on a PLMN ID, whether the fourth message originates from an access network device of a first network standard, where the PLMN ID is from the access network device sending the fourth message. For example, access network device 2 broadcasts a PLMN ID and sends the fourth message to the terminal device. If the PLMN ID does not contain 5G, then access network device 2 is an access network device of a first network standard, and the fourth message originates from an access network device of a first network standard.

[0431] In some embodiments, the integrity protection algorithm of the first network standard may be received by a terminal device from an access network device of the first network standard, or obtained by a terminal device from the AS security context of the terminal device.

[0432] Optionally, when user plane integrity protection instruction information indicates that user plane integrity protection for the first DRB should be enabled, the terminal device may retrieve the currently used integrity protection algorithm for the first network standard from the terminal device's AS security context.

[0433] Optionally, if the second instruction information indicates activating user plane integrity protection based on the currently used integrity protection algorithm of the first network standard, the terminal device may retrieve the currently used integrity protection algorithm of the first network standard from the terminal device's AS security context based on the second instruction information.

[0434] Optionally, the second instruction information may include an integrity protection algorithm identifier for the first network standard. In this case, the terminal device obtains the integrity protection algorithm for the first network standard based on the integrity protection algorithm identifier for the first network standard.

[0435] In some embodiments, the first key may be determined by the terminal device based on a master key, an integrity protection algorithm identifier of a first network standard, and a second algorithm type identifier (e.g., UP-int-alg, value 0x06). For example, the first key may be the user plane integrity protection key Kup-int.

[0436] For example, the master key may be obtained by the terminal device from the terminal device's AS security context based on the first instruction information.

[0437] Alternatively, the terminal device may optionally obtain the first key, for example, a pre-derived Kup-int, directly from the terminal device's AS security context.

[0438] For example, if the integrity protection algorithm identifier of the received first network standard is EIA1, the terminal device may determine the first key Kup-int-E based on the master key KeNB and the integrity protection algorithm identifier EIA1 of the first network standard.

[0439] In this way, the terminal device can activate the user plane integrity protection of the first DRB based on Kup-int-E and the integrity protection algorithm of the first network standard. Therefore, after activating user plane integrity protection, the terminal device uses the integrity protection algorithm of the first network standard and Kup-int-E to perform integrity protection on transmitted user plane data and uses the integrity protection algorithm of the first network standard and Kup-int-E to perform integrity checks on received user plane data packets.

[0440] In some embodiments, the first key may be determined by a terminal device based on a master key, a second network standard integrity protection algorithm identifier, and a first algorithm type identifier (e.g., N-UP-int-alg, value 0x07), and the second network standard integrity protection algorithm identifier is determined based on the first network standard integrity protection algorithm identifier.

[0441] For example, the integrity protection algorithm identifier for the second network standard could be the 5G integrity protection algorithm identifier, such as NIA1.

[0442] Optionally, the integrity protection algorithm identifier of the second network standard may be obtained by mapping the integrity protection algorithm identifier of the first network standard to the terminal device.

[0443] Optionally, the first key may be determined by a terminal device based on the second instruction information, using a master key, a second network standard integrity algorithm identifier, and a first algorithm type identifier (e.g., N-UP-int-alg, value 0x07), the second network standard integrity algorithm identifier being obtained by mapping the first network standard integrity algorithm identifier. For specific embodiments, see S403 above, in which the second network standard integrity algorithm identifier is obtained by a first network standard access network device by mapping the first network standard integrity algorithm identifier. Further details are not provided here.

[0444] For example, the integrity protection algorithm, master key, and first key of the first network standard within the AS security context of the terminal device can all be obtained in step S410 below.

[0445] In a possible design, in S404, the activation of user plane integrity protection of the first DRB by a terminal device based on a first key and an integrity protection algorithm of the first network standard may include the terminal device configuring the first key and the integrity protection algorithm of the first network standard for a PDCP entity of the second network standard corresponding to the first DRB.

[0446] For example, the RRC layer of a terminal device may configure an integrity protection algorithm for a first key and a first network standard for an NR PDCP entity corresponding to a first DRB.

[0447] In this way, the terminal device activates user plane integrity protection to implement on-demand user plane integrity protection.

[0448] In possible design methods, the communication method shown in Figure 4 may further include S407 to S411. For specific embodiments of S407 to S411, please refer to S307 to S311. Details are not described again here. The main difference is that S301 is replaced by S401, S303 is replaced by S403, and S304 is replaced by S404.

[0449] It should be noted that in this embodiment of the present application, the order of S403 and S407 is not limited, and the order of S404 and S407 is not limited.

[0450] Based on the communication method shown in Figure 4, when it is decided to establish a first DRB and to enable user plane integrity protection for the first DRB, the access network device of the first network standard obtains user plane integrity instruction information and an integrity algorithm identifier of the first network standard indicating that user plane integrity protection is enabled, and instructs the terminal device to activate integrity protection using the integrity algorithm of the first network standard. In this way, both the access network device of the first network standard and the terminal device can activate user plane integrity protection for the first DRB based on the first key and the integrity algorithm of the first network standard, thereby applying the on-demand user plane integrity protection mode of the second network standard to user plane integrity protection between the terminal device and the access network device of the first network standard, and the user plane integrity protection is activated using the integrity algorithm of the first network standard, resulting in the implementation of independent developments of user plane integrity protection for different network standards.

[0451] In this application, unless otherwise specified, the same or similar parts of the embodiments should be referenced to one another. In the embodiments and embodiments / methods of the embodiments of this application, unless otherwise specified or unless a logical inconsistency arises, the terminology and / or descriptions are consistent and can be referenced to one another between different embodiments and embodiments / methods of the embodiments. Technical features in different embodiments and embodiments / methods of the embodiments may be combined to form new embodiments, embodiments, or methods of implementation based on their internal logical relationships. The following embodiments of this application are not intended to limit the scope of protection of this application.

[0452] The communication method provided in the embodiments of this application is described in detail above with reference to Figures 2 to 4. The communication device provided in the embodiments of this application is described in detail below with reference to Figures 5 and 6.

[0453] Figure 5 is a schematic diagram of the structure of a communication device that may be configured to perform a communication method according to one embodiment of the present application. The communication device 500 may be an access network device, terminal device, or core network element of a first network standard, or it may be a chip or other component having the corresponding function used in an access network device, terminal device, or core network element of a first network standard. As shown in Figure 5, the communication device 500 may include a processor 501. Optionally, the communication device 500 may further include one or more of a memory 502 and a transceiver 503. The processor 501 may be coupled to one or more of the memory 502 and the transceiver 503, for example, connected via a communication bus, or the processor 501 may be used independently.

[0454] Each component of the communication device 500 will be described in detail below with reference to Figure 5.

[0455] The processor 501 is the control center of the communication device 500 and may be a single processor or a collective term for multiple processing elements. For example, the processor 501 may be one or more central processing units (CPUs), or application-specific integrated circuits (ASICs), or one or more integrated circuits that implement embodiments of this application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).

[0456] The processor 501 can perform various functions of the communication device 500 by operating or executing software programs stored in memory 502 and by retrieving data stored in memory 502.

[0457] In a specific implementation, in one embodiment, the processor 501 may include one or more CPUs, for example, CPU0 and CPU1 shown in Figure 5.

[0458] In a specific implementation, in one embodiment, the communication device 500 may include a plurality of processors, for example, processors 501 and 504 shown in Figure 5. Each of the processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processors here may be one or more communication devices, circuits, and / or processing cores configured to process data (e.g., computer program instructions).

[0459] Optionally, memory 502 may be read-only memory (ROM) or another type of static storage communication device capable of storing static information and instructions, or random access memory (RAM) or another type of dynamic storage communication device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or another compact disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital multipurpose discs, and Blu-ray discs, etc.), magnetic disk storage medium or another magnetic storage communication device, or any other computer-accessible medium that can be used to hold or store appropriate program code in the form of instructions or data structures. However, it is not limited to these. Memory 502 may be integrated with processor 501 or may exist independently and be coupled to processor 501 via input / output ports of communication device 500 (not shown in Figure 5). This is not specifically limited to this embodiment of the present application.

[0460] For example, an input port may be configured to perform a receiving function performed by an access network device, terminal device, or core network element of the first network standard in any of the method embodiments described above, and an output port may be configured to perform a transmitting function performed by an access network device, terminal device, or core network element of the first network standard in any of the method embodiments described above.

[0461] Memory 502 may be configured to store a software program for executing the solution of this application, and processor 501 controls the execution. For specific embodiments described above, please refer to the method embodiments below, which will not be described in detail again here.

[0462] Optionally, the transceiver 503 may be configured to communicate with another communication device. For example, when the communication device 500 is an access network device of a first network standard, the transceiver 503 may be configured to communicate with a terminal device and a core network element of the first network standard. In another example, when the communication device 500 is a terminal device, the transceiver 503 may be configured to communicate with an access network device and a core network element of the first network standard. In yet another example, when the communication device 500 is a core network element of the first network standard, the transceiver 503 may be configured to communicate with an access network device and a terminal device of the first network standard. In addition, the transceiver 503 may include a receiver and a transmitter (not shown separately in Figure 5). The receiver is configured to perform a receiving function, and the transmitter is configured to perform a transmitting function. The transceiver 503 may be integrated with the processor 501 or may exist independently, and may be coupled to the processor 501 via the input / output ports of the communication device 500 (not shown in Figure 5). This is not specifically limited to this embodiment of the present application.

[0463] It should be noted that the structure of the communication device 500 shown in Figure 5 does not constitute a limitation on communication devices. Actual communication devices may include more or fewer components than those shown in the figure, may combine several components, or may have a different arrangement of components.

[0464] Actions performed by the access network devices of the first network standard shown in Figures 2 to 4 may be performed by the processor 501 of the communication device 500 shown in Figure 5 by calling application program code stored in memory 502 to instruct the access network devices of the first network standard to perform the actions.

[0465] Actions performed by the terminal devices in Figures 2 to 4 may be executed by the processor 501 of the communication device 500 shown in Figure 5 by calling application program code stored in memory 502 to instruct the terminal devices to perform the actions. This is not limited to this embodiment.

[0466] Actions performed by the core network elements of the first network standard in Figures 2 to 4 may be executed by the processor 501 of the communication device 500 shown in Figure 5 by calling application program code stored in memory 502 to instruct the core network elements to perform the actions. This is not limited to this embodiment.

[0467] When the communication device is an access network device of the first network standard, the communication device 500 may implement any one or more possible design methods related to an access network device of the first network standard in the method embodiment described above. When the communication device is a terminal device, the communication device 500 may implement any one or more possible design methods related to a terminal device in the method embodiment described above. When the communication device is a core network element of the first network standard, the communication device 500 may implement any one or more possible design methods related to a core network element of the first network standard in the method embodiment described above.

[0468] It should be noted that all relevant details of the steps in the aforementioned method embodiment may be referenced in the functional description of the corresponding functional module. Further details will not be provided here.

[0469] Figure 6 is a schematic diagram of the structure of another communication device according to one embodiment of this application. For the sake of clarity, Figure 6 shows only the main components of the communication device.

[0470] The communication device 600 includes a transceiver module 601 and a processing module 602. The communication device 600 may be an access network device, terminal device, or core network element of the first network standard in the method embodiments described above. The transceiver module 601 may also be called a transceiver unit and is configured to perform transceiver functions performed by an access network device, terminal device, or core network element of the first network standard in any one of the method embodiments described above.

[0471] It should be noted that the transceiver module 601 may include a receiving module and a transmitting module (not shown in Figure 6). The receiving module is configured to receive data and / or signaling from another device, and the transmitting module is configured to transmit data and / or signaling to another device. Specific embodiments of the transceiver module are not specifically limited in this application. The transceiver module may include transceiver circuitry, a transceiver machine, a transceiver, or a communication interface.

[0472] The processing module 602 may be configured to perform processing functions that are executed by an access network device, terminal device, or core network element of the first network standard in any one of the method embodiments described above. The processing module 602 may be a processor.

[0473] In this embodiment, the communication device 600 is presented in the form of a functional module obtained by division in an integrated manner. Here, β€œmodule” may be a specific ASIC, circuit, processor running one or more software or firmware programs, memory, integrated logic circuit, and / or other components capable of providing the aforementioned functions. In a simple embodiment, those skilled in the art will understand that the communication device 600 may be in the form of the communication device 500 shown in Figure 5.

[0474] For example, the processor 501 of the communication device 500 shown in Figure 5 can call computer executable instructions stored in memory 502 so that the communication method in the above-described embodiment is executed.

[0475] Specifically, the functions / implementation processes of the transceiver module 601 and processing module 602 in Figure 6 may be performed by the processor 501 of the communication device 500 shown in Figure 5 by calling computer-executable instructions stored in memory 502. Alternatively, the functions / implementation processes of the processing module 602 in Figure 6 may be performed by the processor 501 of the communication device 500 shown in Figure 5 by calling computer-executable instructions stored in memory 502, and the functions / implementation processes of the transceiver module 601 in Figure 6 may be performed by the transceiver 503 of the communication device 500 shown in Figure 5.

[0476] The communication device 600 provided in this embodiment can perform the communication method described above. Therefore, please refer to the method embodiment described above for the technical effects that can be achieved by the communication device 600. Details will not be described again here.

[0477] In a possible design solution, the communication device 600 shown in Figure 6 may be used in the communication system shown in Figure 1 and perform the function of an access network device of the first network standard in the communication method shown in Figure 3.

[0478] When the first condition is met, the processing module 602 is configured to obtain user plane integrity protection instruction information and an integrity protection algorithm identifier for a second network standard. The first condition includes deciding to establish a first data radio bearer DRB between the communication device 600 and the terminal device, and deciding to enable user plane integrity protection for the first DRB. The user plane integrity protection instruction information indicates that user plane integrity protection for the first DRB is enabled.

[0479] The transceiver module 601 is configured to send a first message to a terminal device. The first message includes user plane integrity protection instruction information and an integrity protection algorithm identifier for a second network standard.

[0480] The processing module 602 is further configured to activate user plane integrity protection of the first DRB based on the integrity protection algorithm of the first key and the second network standard.

[0481] Optionally, the communication device 600 may further include a storage module (not shown in Figure 6). The storage module stores a program or instruction. When the processing module 602 executes the program or instruction, the communication device 600 is enabled to perform the functions of an access network device of the first network standard in the communication method shown in Figure 3.

[0482] It should be noted that the communication device 600 may be an access network device of the first network standard, or a chip (system) or other component or assembly that can be deployed in an access network device of the first network standard. This is not limited to the present application.

[0483] Furthermore, for the technical effects of the communication device 600, please refer to the technical effects of the communication method shown in Figure 3. Further details will not be explained here.

[0484] In another possible design solution, the communication device 600 shown in Figure 6 may be used in the communication system shown in Figure 1 and perform the function of a terminal device in the communication method shown in Figure 3.

[0485] The transceiver module 601 is configured to receive a first message. The first message includes user plane integrity protection instruction information and an integrity protection algorithm identifier for a second network standard, the user plane integrity protection instruction information indicating that user plane integrity protection of the first data radio bearer DRB between the access network device of the first network standard and the communication device 600 is enabled.

[0486] When the first message is from an access network device of a first network standard and the user plane integrity protection instruction information indicates that user plane integrity protection for the first DRB should be enabled, the processing module 602 is configured to activate user plane integrity protection for the first DRB based on the first key and the integrity protection algorithm of the second network standard.

[0487] It should be noted that all relevant details of the steps in the aforementioned method embodiment may be referenced in the functional description of the corresponding functional module. Further details will not be provided here.

[0488] Optionally, the communication device 600 may further include a storage module (not shown in Figure 6). The storage module stores a program or instruction. When the processing module 602 executes the program or instruction, the communication device 600 is enabled to perform the functions of a terminal device in the communication method shown in Figure 3.

[0489] It should be noted that the communication device 600 may be a terminal device, or a chip (system), another component, or assembly that can be placed in a terminal device. This is not limited to the present application.

[0490] Furthermore, for the technical effects of the communication device 600, please refer to the technical effects of the communication method shown in Figure 3. Further details will not be explained here.

[0491] In yet another possible design solution, the communication device 600 shown in Figure 6 may be used in the communication system shown in Figure 1 and perform the function of an access network device of the first network standard in the communication method shown in Figure 4.

[0492] When the first condition is met, the processing module 602 is configured to obtain user plane integrity protection instruction information and an integrity protection algorithm identifier for the first network standard. The first condition includes deciding to establish a first data radio bearer DRB between the communication device 600 and the terminal device, and deciding to enable user plane integrity protection for the first DRB. The user plane integrity protection instruction information indicates that user plane integrity protection for the first DRB is enabled.

[0493] The transceiver module 601 is configured to send a fourth message to a terminal device. The fourth message includes user plane integrity protection instruction information and an integrity protection algorithm identifier for the first network standard.

[0494] The processing module 602 is further configured to activate user plane integrity protection of the first DRB based on the integrity protection algorithm of the first key and the first network standard.

[0495] It should be noted that all relevant details of the steps in the aforementioned method embodiment may be referenced in the functional description of the corresponding functional module. Further details will not be provided here.

[0496] Optionally, the communication device 600 may further include a storage module (not shown in Figure 6). The storage module stores a program or instruction. When the processing module 602 executes the program or instruction, the communication device 600 is enabled to perform the functions of an access network device of the first network standard in the communication method shown in Figure 4.

[0497] It should be noted that the communication device 600 may be an access network device of the first network standard, or a chip (system) or other component or assembly that can be deployed in an access network device of the first network standard. This is not limited to the present application.

[0498] Furthermore, for the technical effects of the communication device 600, please refer to the technical effects of the communication method shown in Figure 4. Further details will not be explained here.

[0499] In another possible design solution, the communication device 600 shown in Figure 6 may be used in the communication system shown in Figure 1 and perform the function of a terminal device in the communication method shown in Figure 4.

[0500] The transceiver module 601 is configured to receive a fourth message. The fourth message includes user plane integrity protection instruction information and an integrity protection algorithm identifier for the first network standard, the user plane integrity protection instruction information indicating that user plane integrity protection for the first data radio bearer DRB is enabled.

[0501] When the fourth message is from an access network device of the first network standard and the user plane integrity protection instruction information indicates that user plane integrity protection for the first DRB should be enabled, the processing module 602 is configured to activate user plane integrity protection for the first DRB based on the first key and the integrity protection algorithm of the first network standard.

[0502] It should be noted that all relevant details of the steps in the aforementioned method embodiment may be referenced in the functional description of the corresponding functional module. Further details will not be provided here.

[0503] Optionally, the communication device 600 may further include a storage module (not shown in Figure 6). The storage module stores a program or instruction. When the processing module 602 executes the program or instruction, the communication device 600 is enabled to perform the functions of a terminal device in the communication method shown in Figure 4.

[0504] It should be noted that the communication device 600 may be a terminal device, or a chip (system), another component, or assembly that can be placed in a terminal device. This is not limited to the present application.

[0505] Furthermore, for the technical effects of the communication device 600, please refer to the technical effects of the communication method shown in Figure 4. Further details will not be explained here.

[0506] One embodiment of this application provides a communication system. The communication system includes access network devices and terminal devices of a first network standard. Optionally, the communication system may further include core network elements of the first network standard.

[0507] The access network device of the first network standard is configured to perform the actions performed by the access network device of the first network standard in the method embodiment described above. For specific methods and processes of execution, please refer to the method embodiment described above. Details will not be described again here.

[0508] The terminal device is configured to perform the actions performed by the terminal device in the method embodiment described above. For specific execution methods and processes, please refer to the method embodiment described above. Further details are not provided here.

[0509] The core network element of the first network standard is configured to perform the actions performed by the core network element of the first network standard in the method embodiment described above. For specific execution methods and processes, please refer to the method embodiment described above. Details will not be described again here.

[0510] One embodiment of this application provides a chip system, which includes logic circuits and input / output ports. The logic circuits may be configured to perform processing functions related to the communication method provided in the embodiment of this application, and the input / output ports may be configured to perform transceiver functions related to the communication method provided in the embodiment of this application.

[0511] For example, an input port may be configured to perform a receiving function related to the communication method provided in the embodiments of this application, and an output port may be configured to perform a transmitting function related to the communication method provided in the embodiments of this application.

[0512] For example, the processor of the communication device 500 may be configured to perform baseband-related processing, for example, but not limited to this, and the transceiver of the communication device 500 may be configured to perform radio frequency transmission and reception, for example, but not limited to this. The aforementioned devices may be arranged separately on independent chips, or at least some or all of the devices may be arranged on the same chip. For example, the processor may be further divided into an analog baseband processor and a digital baseband processor. The analog baseband processor and transceiver may be integrated on the same chip, or the digital baseband processor may be arranged on a separate chip. With the continued development of integrated circuit technology, more and more devices may be integrated on the same chip. For example, the digital baseband processor may be integrated on the same chip as multiple application processors (e.g., graphics processors and multimedia processors, but not limited to these). The chip may be called a system on a chip. Whether devices are arranged independently on different chips or integrated on one or more chips usually depends on the specific requirements of the product design. In this embodiment of the present application, the specific embodiments of the devices are not limited.

[0513] In possible designs, the chip system further includes memory. The memory is configured to store program instructions and data for performing functions related to the communication method provided in embodiments of this application.

[0514] The chip system may include a chip, or it may include a chip and another discrete device.

[0515] One embodiment of this application provides a computer-readable storage medium. The computer-readable storage medium includes a computer program or instructions. When the computer program or instructions are executed on a computer, a communication method provided in the embodiment of this application is performed.

[0516] One embodiment of this application provides a computer program product. The computer program product includes a computer program or instructions. When the computer program or instructions are run on a computer, the communication method provided in the embodiment of this application is executed.

[0517] It should be understood that the processor in the embodiments of this application may be a central processing unit (CPU), or the processor may be another general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or another programmable logic device, discrete gate or transistor logic device, or discrete hardware component. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor.

[0518] It should be further understood that the memory in the embodiments of this application may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM) used as an external cache. Many forms of random access memory (RAM), such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM), may be used, but not as an example.

[0519] All or part of the embodiments described above may be implemented using software, hardware (e.g., circuitry), firmware, or any combination thereof. When software is used to implement the embodiments, all or part of the embodiments described above may be implemented in the form of a computer program product. A computer program product includes one or more computer instructions or computer programs. When the program instructions or computer programs are loaded and executed on a computer, the procedures or functions according to the embodiments of this application are generated in whole or in part. The computer may be a general-purpose computer, a dedicated computer, a computer network, or other programmable device. Computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions may be transmitted by wired means (e.g., infrared, wireless, and microwave) from one website, computer, server, or data center to another website, computer, server, or data center. The computer-readable storage medium may be any available medium accessible by a computer, or a data storage device such as a server or data center incorporating one or more available media. The usable media may be magnetic media (e.g., floppy disks, hard disks, or magnetic tapes), optical media (e.g., DVDs), or semiconductor media. Semiconductor media may include solid-state drives.

[0520] In this specification, the term "and / or" describes only the relational relationship between the related objects, and it should be understood that three relationships are possible. For example, A and / or B can represent the following three cases: A exists only, both A and B exist, and B exists only. A and B may be singular or plural. In addition, the symbol " / " in this specification usually indicates an "or" relationship between related objects, but it can also indicate an "and / or" relationship. For further details, please refer to the context for understanding.

[0521] In this application, "at least one" means "one or more," and "multiple" means "two or more." "At least one of the following (elements)" or similar expressions refer to any combination of these, including any single (element) or any combination of multiple (elements). For example, at least one of a, b, or c could refer to a, b, c, ab, ac, bc, or abc, where a, b, and c may be singular or plural.

[0522] It should be understood that the sequential numbering of the processes described above does not imply the order of execution in the various embodiments of this application. The order of execution of the processes should be determined based on the function and internal logic of the processes and should not be construed as any limitation to the implementation processes of the embodiments of this application.

[0523] Those skilled in the art will recognize, in combination with the examples described in the embodiments disclosed herein, that the units and algorithmic steps may be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether the function is performed by hardware or by software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but the embodiments should not be considered to exceed the scope of this application.

[0524] For the sake of brevity, it will be readily apparent to those skilled in the art that the detailed operating processes of the aforementioned systems, apparatus, and units can be described by referring to the corresponding processes in the method embodiments described above. Further details are not provided here.

[0525] In some embodiments provided in this application, it should be understood that the disclosed systems, apparatus, and methods may be implemented in other ways. For example, the apparatus embodiments described are merely illustrative. For example, the division into units is merely a division of logical functions, and other divisions may be used in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not performed. In addition, the interconnections or direct connections or communication connections presented or described may be implemented through some interfaces. Indirect connections or communication connections between apparatus or units may be implemented electronically, mechanically, or in other forms.

[0526] Units described as separate components may or may not be physically separate, and components presented as units may or may not be physical units, may be located in one location, or may be distributed across multiple network units. Some or all of the units may be selected based on actual requirements to achieve the objectives of the solution of the embodiment.

[0527] In addition, the functional units in the embodiments of this application may be integrated into a single processing unit, each unit may exist physically independently, or two or more units may be integrated into a single unit.

[0528] When a function is implemented in the form of a software function unit and sold or used as an independent product, the function may be stored on a computer-readable storage medium. Based on this understanding, the technical solution of this application may be implemented in the form of a software product, either in essence, in part with respect to the prior art, or in part with respect to the technical solution. The software product includes several instructions stored on a storage medium for instructing a computer device (which may be a personal computer, server, or network device) to perform all or part of the steps of the method described in the embodiments of this application. The aforementioned storage medium includes any medium capable of storing program code, such as a USB flash drive, removable hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.

[0529] The foregoing description is merely a specific embodiment of the present application and is not intended to limit the scope of protection of this application. Any modifications or substitutions that are readily conceivable by a person skilled in the art within the scope of the art disclosed herein shall also fall within the scope of protection of this application. Accordingly, the scope of protection of this application shall be subject to the scope of protection of the claims. [Explanation of symbols]

[0530] 500 Communication devices 501 Processor 502 memory 503 Transceiver 504 Processors 600 Communication devices 601 Transceiver Module 602 Processing Module

Claims

1. A method of communication, When deciding to establish a first data radio bearer DRB between an access network device of a first network standard and a terminal device, and to enable user plane integrity protection of the first DRB, the access network device of the first network standard obtains user plane integrity instruction information and an integrity algorithm identifier of a second network standard, wherein the integrity algorithm identifier of the second network standard is obtained by mapping the integrity algorithm identifier of the first network standard, and the user plane integrity instruction information indicates that the user plane integrity protection of the first DRB is enabled. A step of transmitting a first message to the terminal device by the access network device of the first network standard, wherein the first message includes the user plane integrity protection instruction information and the integrity protection algorithm identifier of the second network standard. The steps include: activating the user plane integrity protection of the first DRB using the access network device of the first network standard, based on the first key and the integrity protection algorithm of the second network standard; A communication method that includes this.

2. The communication method according to claim 1, wherein the first message further includes first instruction information, the first instruction information indicating that the first key is determined using a master key.

3. The communication method according to claim 1, wherein the security capability of the first network standard includes the integrity protection algorithm identifier of the first network standard, and the integrity protection algorithm identifier of the second network standard is determined based on the security capability of the first network standard.

4. The communication method according to claim 3, wherein the security capability of the first network standard is received by the access network device of the first network standard from the core network element of the first network standard.

5. The step of activating the user plane integrity protection of the first DRB based on the first key and the integrity protection algorithm of the second network standard by the access network device of the first network standard is: The steps of configuring the first key and the integrity protection algorithm of the second network standard for a packet data convergence protocol PDCP entity of the second network standard, which corresponds to the first DRB, using the access network device of the first network standard. The communication method according to claim 1, including the method described in claim 1.

6. The communication method according to claim 2, wherein the user plane integrity protection instruction information, the integrity protection algorithm identifier of the second network standard, and the first instruction information are encapsulated in the Radiobearerconfig information element of the first message.

7. A method of communication, A communication device receives a first message from an access network device of a first network standard, wherein the first message includes user plane integrity protection instruction information and an integrity protection algorithm identifier of a second network standard, the integrity protection algorithm identifier of the second network standard maps to a corresponding integrity protection algorithm identifier of the first network standard, and the user plane integrity protection instruction information indicates that user plane integrity protection of a first data radio bearer DRB between the access network device of the first network standard and the communication device is enabled. The communication device performs the steps of activating the user plane integrity protection of the first DRB based on the first key and the integrity protection algorithm of the second network standard. A communication method including, A communication method wherein the communication device is a terminal device or a chip placed in the terminal device.

8. The first message further includes first instruction information, the first instruction information indicates that the first key is determined using the master key, and the communication method is The communication device determines the first key using the master key based on the first instruction information. The communication method according to claim 7, further comprising:

9. The communication method is: Steps include: when the communication device supports user plane integrity protection, the communication device transmits a third message to a core network element of the first network standard, wherein the third message includes the security capability of the second network standard, which includes the integrity protection algorithm identifier of the second network standard; The communication method according to claim 7, further comprising:

10. The step of activating the user plane integrity protection of the first DRB based on the first key and the integrity protection algorithm of the second network standard by the communication device is: The communication device configures the first key and the integrity protection algorithm of the second network standard for a packet data convergence protocol PDCP entity of the second network standard that corresponds to the first DRB. The communication method according to claim 7, including the method described in claim 7.

11. The communication method according to claim 8, wherein the user plane integrity protection instruction information, the integrity protection algorithm identifier of the second network standard, and the first instruction information are encapsulated in the Radiobearerconfig information element of the first message.

12. The communication method according to claim 7, wherein the first network standard includes fourth-generation 4G, Long-Term Evolution LTE, or Advanced Packet System EPS, and the second network standard includes fifth-generation 5G, New Wireless NR, or fifth-generation System 5GS.

13. A communication device comprising a unit or module configured to perform the communication method described in any one of claims 1 to 6.

14. A communication device comprising a unit or module configured to perform the communication method described in any one of claims 7 to 12.

15. A computer-readable storage medium, wherein the computer-readable storage medium includes a computer program or instructions, and when the computer program or instructions are run on a computer, the communication method described in any one of claims 1 to 6 is executed.

16. A computer-readable storage medium, wherein the computer-readable storage medium includes a computer program or instructions, and when the computer program or instructions are run on a computer, the communication method described in any one of claims 7 to 12 is executed.

17. A computer program comprising instructions, wherein when the instructions are executed on a computer, the communication method described in any one of claims 1 to 6 is executed.

18. A computer program comprising instructions, wherein when the instructions are executed on a computer, the communication method described in any one of claims 7 to 12 is executed.