Policy control method, device, and storage medium

By obtaining and implementing UP security policies through access network devices, the security protection problem of local data transmission by terminal devices on satellites in non-terrestrial network communication systems is solved, and a flexible and efficient UP data security mechanism is realized.

WO2025152007A1PCT designated stage expired Publication Date: 2025-07-24BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/072406
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-15
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

In non-terrestrial network communication systems, how to provide effective security protection for user plane data transmitted locally through access network devices on satellites, especially in UE-satellite-UE communications, the prior art lacks an effective UP security policy configuration mechanism.

Method used

The access network device obtains the UP security policy on the user plane and protects the locally transmitted UP data according to the policy, including integrity and confidentiality protection. Through the unified data management UDM and policy and billing function PCF sends UP security policy to the access network device during terminal device registration and service authorization.

Benefits of technology

It realizes flexible security protection of UP data between terminal equipment and access network equipment, improves the security and protection flexibility of data transmission, and avoids waste of resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024072406_24072025_PF_FP_ABST
    Figure CN2024072406_24072025_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a policy control method, a device, and a storage medium. The method comprises: acquiring a user plane (UP) security policy; and performing security protection on first UP data on the basis of the UP security policy, the first UP data being UP data locally transmitted by a terminal device by means of an access network device. In this way, the access network device can perform security protection on the locally transmitted UP data on the basis of the acquired UP security policy.
Need to check novelty before this filing date? Find Prior Art

Description

Policy control method, device and storage medium Technical Field

[0001] The present disclosure relates to the field of communication technologies, and in particular to a policy control method, device, and storage medium. Background Art

[0002] Non-terrestrial network (NTN) communication systems provide seamless coverage for user equipment (UE) by deploying access network equipment, or portions of it, on non-terrestrial equipment such as satellites. UE-satellite-UE communication occurs within the coverage area of ​​one or more serving satellites, using satellite-based access network equipment to communicate between UEs. User plane (UP) data is transmitted locally on the satellite's next-generation NodeB (gNB).

[0003] Summary of the Invention

[0004] The embodiments of the present disclosure provide a policy control method, device, and storage medium.

[0005] According to a first aspect of an embodiment of the present disclosure, a policy control method is proposed, which is performed by an access network device. The method includes:

[0006] Obtain the user plane UP security policy;

[0007] The first UP data is securely protected according to the UP security policy, where the first UP data is UP data that is locally transmitted by a terminal device through the access network device.

[0008] According to a second aspect of an embodiment of the present disclosure, a policy control method is proposed, which is executed by a unified data management (UDM). The method includes:

[0009] During the terminal device registration process, the user plane UP security policy is sent to the access network device through the access and mobility management function AMF. The UP security policy is used by the access network device to securely protect the first UP data. The first UP data is the UP data transmitted locally by the terminal device through the access network device.

[0010] According to a third aspect of an embodiment of the present disclosure, a policy control method is proposed, which is performed by a policy and charging function (PCF). The method includes:

[0011] During the service authorization and information configuration process of the terminal device, the user plane UP security policy is sent to the access network device through the access and mobility management function AMF. The UP security policy is used by the access network device to securely protect the first UP data. The first UP data is the UP data transmitted locally by the terminal device through the access network device.

[0012] According to a fourth aspect of an embodiment of the present disclosure, an access network device is provided, including:

[0013] a transceiver module configured to obtain a user plane UP security policy;

[0014] The processing module is configured to perform security protection on first UP data according to the UP security policy, where the first UP data is UP data locally transmitted by the terminal device through the access network device.

[0015] According to a fifth aspect of the embodiments of the present disclosure, a unified data management (UDM) is proposed, including:

[0016] The transceiver module is configured to send a user plane UP security policy to the access network device through the access and mobility management function AMF during the terminal device registration process. The UP security policy is used by the access network device to securely protect the first UP data. The first UP data is UP data transmitted locally by the terminal device through the access network device.

[0017] According to a sixth aspect of an embodiment of the present disclosure, a policy and charging function (PCF) is proposed, including:

[0018] The transceiver module is configured to send a user plane UP security policy to the access network device through the access and mobility management function AMF during the service authorization and information configuration process of the terminal device. The UP security policy is used by the access network device to securely protect the first UP data. The first UP data is UP data transmitted locally by the terminal device through the access network device.

[0019] According to a seventh aspect of an embodiment of the present disclosure, a communication device is proposed, comprising: one or more processors; wherein the communication device is used to execute an optional implementation of the first aspect, the second aspect, or the third aspect.

[0020] According to the eighth aspect of an embodiment of the present disclosure, a communication system is proposed, which may include: an access network device, a unified data management UDM, and a policy and charging function PCF; wherein, the access network device is configured to execute the method described in the optional implementation manner of the first aspect, the unified data management UDM is configured to execute the method described in the optional implementation manner of the second aspect, and the policy and charging function PCF is configured to execute the method described in the optional implementation manner of the third aspect.

[0021] According to the ninth aspect of an embodiment of the present disclosure, a storage medium is proposed, which stores instructions. When the instructions are executed on a communication device, the communication device executes the method described in the optional implementation of the first aspect, the second aspect, or the third aspect.

[0022] The technical solution provided by the embodiments of the present disclosure may have the following beneficial effects: obtaining a user plane UP security policy; and performing security protection on first UP data according to the UP security policy, where the first UP data is UP data transmitted locally by a terminal device through the access network device. In this way, the access network device can perform security protection on the locally transmitted UP data according to the obtained UP security policy.

[0023] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following drawings required for describing the embodiments are introduced. The following drawings are merely some embodiments of the present disclosure and do not impose specific limitations on the protection scope of the present disclosure.

[0025] FIG1A is a schematic diagram showing the architecture of a communication system according to an embodiment of the present disclosure.

[0026] FIG1B is a schematic diagram showing the architecture of a communication system according to an embodiment of the present disclosure.

[0027] FIG1C is a schematic diagram illustrating a UE-satellite-UE communication scenario according to an embodiment of the present disclosure.

[0028] FIG2A is an interactive schematic diagram illustrating a policy control method according to an embodiment of the present disclosure.

[0029] FIG2B is an interactive schematic diagram illustrating a policy control method according to an embodiment of the present disclosure.

[0030] FIG3A is a flow chart illustrating a policy control method according to an embodiment of the present disclosure.

[0031] FIG3B is a flow chart illustrating a policy control method according to an embodiment of the present disclosure.

[0032] FIG3C is a flow chart illustrating a policy control method according to an embodiment of the present disclosure.

[0033] FIG3D is a flow chart illustrating a policy control method according to an embodiment of the present disclosure.

[0034] FIG3E is a flow chart illustrating a policy control method according to an embodiment of the present disclosure.

[0035] FIG3F is a flow chart illustrating a policy control method according to an embodiment of the present disclosure.

[0036] FIG4A is a flow chart illustrating a policy control method according to an embodiment of the present disclosure.

[0037] FIG4B is a flow chart illustrating a policy control method according to an embodiment of the present disclosure.

[0038] FIG5 is a flow chart showing a policy control method according to an embodiment of the present disclosure.

[0039] FIG6A is an interactive schematic diagram illustrating a policy control method according to an embodiment of the present disclosure.

[0040] FIG6B is an interactive schematic diagram illustrating a policy control method according to an embodiment of the present disclosure.

[0041] FIG7A is a schematic structural diagram of an access network device proposed in an embodiment of the present disclosure.

[0042] FIG7B is a schematic diagram of the structure of a UDM proposed in an embodiment of the present disclosure.

[0043] FIG7C is a schematic diagram of the structure of a PCF proposed in an embodiment of the present disclosure.

[0044] FIG8A is a schematic structural diagram of a communication device proposed in an embodiment of the present disclosure.

[0045] FIG8B is a schematic diagram of the structure of the chip proposed in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0046] The embodiments of the present disclosure provide a policy control method, device, and storage medium.

[0047] In a first aspect, an embodiment of the present disclosure provides a policy control method, which is executed by an access network device. The method includes:

[0048] Obtain the user plane UP security policy;

[0049] The first UP data is securely protected according to the UP security policy, where the first UP data is UP data that is locally transmitted by a terminal device through the access network device.

[0050] In the above embodiment, the access network device can perform security protection on the locally transmitted UP data according to the acquired UP security policy.

[0051] In combination with some embodiments of the first aspect, in some embodiments, the terminal device includes a first terminal device and / or a second terminal device, and the UP security policy includes at least one of the following: a first UP security policy and a second UP security policy, the first UP security policy is the UP security policy corresponding to the first terminal device, the second UP security policy is the UP security policy corresponding to the second terminal device, and the first terminal device and the second terminal device perform local transmission of UP data through the access network device.

[0052] In the above embodiment, different UP security policies can be used to protect the UP data of different terminal devices, thereby improving the flexibility of security protection.

[0053] In conjunction with some embodiments of the first aspect, in some embodiments, obtaining the UP security policy includes at least one of the following:

[0054] During the registration process of the first terminal device, receiving the first UP security policy sent by the first unified data management UDM through the first access and mobility management function AMF;

[0055] During the registration process of the second terminal device, the second UP security policy sent by the second UDM through the second AMF is received.

[0056] In the above embodiment, the access network device can obtain the first UP security policy corresponding to the first terminal device from the first UDM, and obtain the second UP security policy corresponding to the second terminal device from the second UDM, so as to perform security protection on the UP data between the first terminal device and the access network device, and the UP data between the second terminal device and the access network device.

[0057] In conjunction with some embodiments of the first aspect, in some embodiments, obtaining the UP security policy includes at least one of the following:

[0058] During the service authorization and information configuration process of the first terminal device, receiving the first UP security policy sent by the first policy and charging function PCF through the first AMF;

[0059] During the service authorization and information configuration process of the second terminal device, the second UP security policy sent by the second PCF through the second AMF is received.

[0060] In the above embodiment, the access network device can obtain the first UP security policy corresponding to the first terminal device from the first PCF, and obtain the second UP security policy corresponding to the second terminal device from the second PCF, so as to perform security protection on the UP data between the first terminal device and the access network device, and the UP data between the second terminal device and the access network device.

[0061] In combination with some embodiments of the first aspect, in some embodiments, the first UP data includes at least one of the following: second UP data and third UP data, the second UP data is UP data protected by the first UP security policy, and the third UP data is UP data protected by the second UP security policy.

[0062] In the above embodiment, different UP security policies can protect different UP data, thereby improving the flexibility of security protection.

[0063] In conjunction with some embodiments of the first aspect, in some embodiments, performing security protection on the first UP data according to the UP security policy includes:

[0064] Receiving a first protocol data unit (PDU) session establishment request sent by the first terminal device;

[0065] Activate security protection for the second UP data according to the first UP security policy.

[0066] In the above embodiment, after receiving the PDU session establishment request sent by the first terminal device, the access network device can activate security protection for the second UP data corresponding to the first terminal device.

[0067] In conjunction with some embodiments of the first aspect, in some embodiments, performing security protection on the first UP data according to the UP security policy includes:

[0068] Receiving a second PDU session establishment request sent by the second terminal device;

[0069] Activate security protection for the third UP data according to the second UP security policy.

[0070] In the above embodiment, after receiving the PDU session establishment request sent by the second terminal device, the access network device can activate security protection for the third UP data corresponding to the second terminal device.

[0071] In combination with some embodiments of the first aspect, in some embodiments, the first UP security policy includes a third UP security policy, and the third UP security policy is used to securely protect UP data transmitted locally by the access network device.

[0072] With reference to some embodiments of the first aspect, in some embodiments, obtaining the UP security policy includes:

[0073] Obtain first configuration information, where the first configuration information is used to indicate the third UP security policy.

[0074] In the above embodiment, the access network device can obtain the third UP security policy through the first configuration information to implement security protection for locally transmitted UP data.

[0075] In conjunction with some embodiments of the first aspect, in some embodiments, performing security protection on the first UP data according to the UP security policy includes:

[0076] According to the first configuration information, security protection of the first UP data corresponding to the third UP security policy is activated.

[0077] In the above embodiment, the access network device may activate security protection for UP data according to the third UP security policy.

[0078] In conjunction with some embodiments of the first aspect, in some embodiments, the UP security policy is used to indicate any one of the following:

[0079] activating security protection for the first UP data;

[0080] deactivating security protection for the first UP data;

[0081] First indication information, where the first indication information is used to instruct the access network device to determine whether to activate security protection for the first UP data.

[0082] In the above embodiment, whether to perform security protection on UP data may be determined according to the instruction of the UP security policy.

[0083] In combination with some embodiments of the first aspect, in some embodiments, the security protection includes at least one of the following: integrity protection and confidentiality protection.

[0084] In the above embodiment, security protection may include at least one of integrity protection and confidentiality protection, making the security protection method more flexible.

[0085] In a second aspect, an embodiment of the present disclosure proposes a policy control method, which is executed by a unified data management (UDM). The method includes:

[0086] During the terminal device registration process, the user plane UP security policy is sent to the access network device through the access and mobility management function AMF. The UP security policy is used by the access network device to securely protect the first UP data. The first UP data is the UP data transmitted locally by the terminal device through the access network device.

[0087] In conjunction with some embodiments of the second aspect, in some embodiments,

[0088] Sending the UP security policy to the access network device through the AMF includes:

[0089] Determine sending the UP security policy according to the contract information of the terminal device;

[0090] The UP security policy is sent to the access network device through the AMF.

[0091] In the above embodiment, the UDM can determine whether to send the UP security policy to the access network device according to the contract information of the terminal device, so that the UP protection policy can be sent when the terminal device needs security protection, thereby avoiding resource waste.

[0092] In conjunction with some embodiments of the second aspect, in some embodiments,

[0093] The determining and sending the UP security policy according to the contract information of the terminal device includes:

[0094] Determining local transmission of UP data signed by the terminal device according to the contract information of the terminal device;

[0095] Determine to send the UP security policy.

[0096] In the above embodiment, when the UDM determines that the terminal device has signed a contract for local transmission of UP data, it sends the UP security policy to the access network device to avoid wasting resources.

[0097] In combination with some embodiments of the second aspect, in some embodiments, the terminal device includes a first terminal device and / or a second terminal device, and the UP security policy includes at least one of the following: a first UP security policy and a second UP security policy, the first UP security policy is the UP security policy corresponding to the first terminal device, the second UP security policy is the UP security policy corresponding to the second terminal device, and the first terminal device and the second terminal device perform local transmission of UP data through the access network device.

[0098] In combination with some embodiments of the second aspect, in some embodiments, the UDM includes at least one of the following: a first UDM and a second UDM, wherein the first UDM is used to send the first UP security policy to the access network device through the first AMF during the registration process of the first terminal device, and the second UDM is used to send the second UP security policy to the access network device through the second AMF during the registration process of the second terminal device.

[0099] In conjunction with some embodiments of the second aspect, in some embodiments, the UP security policy is used to indicate any one of the following:

[0100] activating security protection for the first UP data;

[0101] deactivating security protection for the first UP data;

[0102] First indication information, where the first indication information is used to instruct the access network device to determine whether to activate security protection for the first UP data.

[0103] In combination with some embodiments of the second aspect, in some embodiments, the security protection includes at least one of the following: integrity protection and confidentiality protection.

[0104] In a third aspect, an embodiment of the present disclosure proposes a policy control method, which is executed by a policy and charging function (PCF). The method includes:

[0105] During the service authorization and information configuration process of the terminal device, the user plane UP security policy is sent to the access network device through the access and mobility management function AMF. The UP security policy is used by the access network device to securely protect the first UP data. The first UP data is the UP data transmitted locally by the terminal device through the access network device.

[0106] In combination with some embodiments of the third aspect, in some embodiments, the terminal device includes a first terminal device and / or a second terminal device, and the UP security policy includes at least one of the following: a first UP security policy and a second UP security policy, the first UP security policy is the UP security policy corresponding to the first terminal device, the second UP security policy is the UP security policy corresponding to the second terminal device, and the first terminal device and the second terminal device perform local transmission of UP data through the access network device.

[0107] In combination with some embodiments of the third aspect, in some embodiments, the PCF includes at least one of the following: a first PCF and a second PCF, wherein the first PCF is used to send the first UP security policy to the access network device through the first AMF during the service authorization and information configuration process of the first terminal device, and the second PCF is used to send the second UP security policy to the access network device through the second AMF during the service authorization and information configuration process of the second terminal device.

[0108] In conjunction with some embodiments of the third aspect, in some embodiments, the method further includes:

[0109] Determine the UP security policy corresponding to the terminal device from the unified data repository UDR.

[0110] In the above embodiment, the PCF can retrieve the UP security policy from the UDR, which improves the flexibility of obtaining the UP security policy.

[0111] In conjunction with some embodiments of the third aspect, in some embodiments, the UP security policy is used to indicate any one of the following:

[0112] activating security protection for the first UP data;

[0113] deactivating security protection for the first UP data;

[0114] First indication information, where the first indication information is used to instruct the access network device to determine whether to activate security protection for the first UP data.

[0115] In combination with some embodiments of the third aspect, in some embodiments, the security protection includes at least one of the following: integrity protection and confidentiality protection.

[0116] In a fourth aspect, an embodiment of the present disclosure proposes an access network device, which may include at least one of a transceiver module and a processing module; wherein the access network device may be used to execute the optional implementation method of the first aspect.

[0117] In a fifth aspect, an embodiment of the present disclosure proposes a unified data management (UDM), which may include at least one of a transceiver module and a processing module; wherein the UDM may be used to execute the optional implementation of the second aspect.

[0118] In a sixth aspect, an embodiment of the present disclosure proposes a policy and charging function (PCF), which may include at least one of a transceiver module and a processing module; wherein, the PCF may be used to execute the optional implementation method of the third aspect.

[0119] In a seventh aspect, an embodiment of the present disclosure proposes an access network device, which may include: one or more processors; wherein, the access network device can be used to execute the optional implementation method of the first aspect.

[0120] In an eighth aspect, an embodiment of the present disclosure proposes a unified data management (UDM), which may include: one or more processors; wherein, the UDM may be used to execute the optional implementation of the second aspect.

[0121] In a ninth aspect, an embodiment of the present disclosure proposes a policy and charging function (PCF), which may include: one or more processors; wherein, the PCF may be used to execute the optional implementation method of the third aspect.

[0122] In the tenth aspect, an embodiment of the present disclosure proposes a communication device, which may include: one or more processors; wherein the communication device can be used to execute an optional implementation method of the first aspect, the second aspect, or the third aspect.

[0123] In the eleventh aspect, an embodiment of the present disclosure proposes a communication system, which may include: an access network device, a UDM and a PCF; wherein, the access network device is configured to execute the method described in the optional implementation manner of the first aspect, the UDM is configured to execute the method described in the optional implementation manner of the second aspect, and the PCF is configured to execute the method described in the optional implementation manner of the third aspect.

[0124] In the twelfth aspect, an embodiment of the present disclosure proposes a storage medium storing instructions, which, when executed on a communication device, enables the communication device to execute the method described in the optional implementation of the first aspect, the second aspect, or the third aspect.

[0125] In a thirteenth aspect, an embodiment of the present disclosure proposes a program product, which, when executed by a communication device, enables the communication device to execute the method described in the optional implementation manner of the first aspect, the second aspect, or the third aspect.

[0126] In a fourteenth aspect, an embodiment of the present disclosure proposes a computer program, which, when executed on a computer, enables the computer to execute the method described in the optional implementation of the first aspect, the second aspect, or the third aspect.

[0127] In a fifteenth aspect, an embodiment of the present disclosure provides a chip or a chip system, wherein the chip or chip system includes a processing circuit configured to execute the method described in the optional implementation of the first aspect, the second aspect, or the third aspect.

[0128] It is understandable that the aforementioned access network devices, UDMs, PCFs, communication devices, communication systems, storage media, program products, computer programs, chips, or chip systems can all be used to perform the methods proposed in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved can be referenced to the beneficial effects of the corresponding methods and will not be further elaborated here.

[0129] The present disclosure provides a policy control method, device, and storage medium. In some embodiments, the terms "policy control method" and "information processing method" and "communication method" are interchangeable; the terms "policy control device" and "information processing device" and "communication device" are interchangeable; and the terms "policy control system" and "communication system" are interchangeable.

[0130] The embodiments of the present disclosure are not exhaustive and are merely illustrative of some embodiments, and are not intended to be a specific limitation on the scope of protection of the present disclosure. In the absence of contradiction, each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged. In addition, the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined. For example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0131] In each embodiment of the present disclosure, unless otherwise specified or provided for by logic, the terms and / or descriptions between the embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form a new embodiment based on their inherent logical relationships.

[0132] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure.

[0133] In the embodiments of the present disclosure, unless otherwise specified, elements expressed in the singular, such as "a", "an", "the", "above", "said", "the", "the", etc., may mean "one and only one", or "one or more", "at least one", etc. For example, when using articles such as "a", "an", "the" in English in translation, the noun following the article may be understood as a singular expression or a plural expression.

[0134] In some embodiments, "plurality" may refer to two or more.

[0135] In some embodiments, the terms "at least one," "one or more," "a plurality of," "multiple," etc. may be used interchangeably.

[0136] In some embodiments, descriptions such as "at least one of A and B," "A and / or B," "A in one case, B in another case," or "in response to one case A, in response to another case B" may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); and in some embodiments, A and B (both A and B are executed). The above is also applicable when there are more branches such as A, B, and C.

[0137] In some embodiments, "A or B" and other descriptions may include the following technical solutions depending on the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The above is also applicable when there are more branches such as A, B, C, etc.

[0138] The prefixes such as "first" and "second" in the embodiments of the present disclosure are only used to distinguish different description objects and do not constitute any restriction on the position, order, priority, quantity or content of the description objects. For the statement of the description object, please refer to the description in the context of the claims or embodiments, and no unnecessary restriction should be constituted due to the use of prefixes. For example, if the description object is a "field", the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields". "First" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the description object is a "level", the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of description objects is not limited by the ordinal number and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the description object is "device", then the "first device" and the "second device" can be the same device or different devices, and their types can be the same or different; for another example, if the description object is "information", then the "first information" and the "second information" can be the same information or different information, and their contents can be the same or different.

[0139] In some embodiments, “including A,” “comprising A,” “used to indicate A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0140] In some embodiments, terms such as "in response to...", "in response to determining...", "in the case of...", "at the time of...", "when...", "if...", "if...", etc. can be used interchangeably.

[0141] In some embodiments, terms such as "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not less than", and "above" can be replaced with each other, and terms such as "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", and "below" can be replaced with each other.

[0142] In some embodiments, devices and the like can be interpreted as physical or virtual, and their names are not limited to those described in the embodiments. Terms such as "device," "equipment," "device," "circuit," "network element," "node," "function," "unit," "section," "system," "network," "chip," "chip system," "entity," and "subject" can be used interchangeably.

[0143] In some embodiments, "network" can be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).

[0144] In some embodiments, the terms "Access Network Device (AN Device)", "Radio Access Network Device (RAN Device)", "Base Station (BS)", "Radio Base Station (Radio Base Station)", "Fixed Station (Fixed Station)", "Node (Node)", "Access Point (Access Point)", "Transmission Point (TP)", "Reception Point (RP)", "Transmission and / or Reception Point (TRP))", "Panel (Panel)", "Antenna Panel (Antenna Panel)", "Antenna Array (Antenna Array)" "Cell (Cell)", "Macro Cell (Macro Cell)", "Small Cell (Small Cell)", "Femto Cell (Femto Cell)", "Pico Cell (Pico Cell)" "Sector (Sector)", "Cell Group (Cell Group)", "Serving Cell", "Carrier (Carrier)", "Component Carrier (Component Carrier)", "Bandwidth Part (BWP)" and the like can be used interchangeably.

[0145] In some embodiments, the terms "terminal", "terminal device", "user equipment (UE)", "user terminal" "mobile station (MS)", "mobile terminal (MT)", subscriber station (Subscriber Station), mobile unit (Mobile Unit), subscriber unit (Subscriber Unit), wireless unit (Wireless Unit), remote unit (Remote Unit), mobile device (Mobile Device), wireless device (Wireless Device), wireless communication device (Wireless Communication Device), remote device (Remote Device), mobile subscriber station (Mobile Subscriber Station), access terminal (Access Terminal), mobile terminal (Mobile Terminal), wireless terminal (Wireless Terminal), remote terminal (Remote Terminal), handset (Handset), user agent (User Agent), mobile client (Mobile Client), client (Client) and the like can be used interchangeably.

[0146] In some embodiments, the access network device, the core network device, or the network device can be replaced by a terminal. For example, the various embodiments of the present disclosure can also be applied to a structure in which the communication between the access network device, the core network device, or the network device and the terminal is replaced by communication between multiple terminals (for example, device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, it is also possible to set the structure in which the terminal has all or part of the functions of the access network device. In addition, terms such as "uplink" and "downlink" can also be replaced by terms corresponding to communication between terminals (for example, "side"). For example, uplink channels, downlink channels, etc. can be replaced by side channels or direct channels, and uplinks, downlinks, etc. can be replaced by side links or direct links.

[0147] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, the core network device, or the network device may have a structure that has all or part of the functions of the terminal.

[0148] In some embodiments, obtaining data, information, etc. may comply with the laws and regulations of the country where the data is obtained.

[0149] In some embodiments, data, information, etc. may be obtained with the user's consent.

[0150] In addition, each element, each row, or each column in the table of the embodiment of the present disclosure can be implemented as an independent embodiment, and the combination of any elements, any rows, and any columns can also be implemented as an independent embodiment.

[0151] FIG1A is a schematic diagram illustrating an architecture of a communication system according to an embodiment of the present disclosure. As shown in FIG1A , the communication system 100 may include a terminal device 150 , an access network device 160 , and a core network device 170 .

[0152] In some embodiments, the terminal device 150 may include at least one of a mobile phone, a wearable device, an Internet of Things device, a car with communication capabilities, a smart car, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, and a wireless terminal device in smart home, but is not limited thereto.

[0153] In some embodiments, the access network device 160 may be a node or device that accesses a terminal device to a wireless network. The access network device 160 may include an evolved NodeB (eNB), a next generation evolved NodeB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved nodeB (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a Wi-Fi system, but is not limited thereto.

[0154] In some embodiments, the technical solution of the present disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can be transformed into internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be implemented through software or programs.

[0155] In some embodiments, the access network device 160 can be composed of a centralized unit (CU) and a distributed unit (DU), where the CU can also be called a control unit (Control Unit). The CU-DU structure can be used to split the protocol layer of the access network device, with the functions of some protocol layers centrally controlled by the CU, and the functions of the remaining part or all of the protocol layers distributed in the DU, which is centrally controlled by the CU, but is not limited to this.

[0156] In some embodiments, the access network device 160 may be an access network device on a satellite in an NTN communication system.

[0157] In some embodiments, the terminal device 150 may include a first terminal device and / or a second terminal device, and the first terminal device and the second terminal device communicate via an access network device 160 on a satellite.

[0158] In some embodiments, the core network device 170 may be a single device, or may be multiple devices or a group of devices. The core network may include at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).

[0159] Figure 1B is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure. As shown in Figure 1B, the core network device 170 in the communication system 100 may include multiple functions, entities or network elements. For example, the core network device 170 may include at least one of Unified Data Management (UDM) 171, Policy Control Function (PCF) 172 and Access and Mobility Management Function (AMF) 173. It should be noted that the specific functions, connection relationships and implementation methods of the above-mentioned AMF, PCF and UDM can be referred to the relevant descriptions in the relevant technologies (such as the 3GPP protocol), and this disclosure will not go into details.

[0160] It can be understood that the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution proposed in the embodiment of the present disclosure. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution proposed in the embodiment of the present disclosure is also applicable to similar technical problems.

[0161] The following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1B , or a portion thereof, but are not limited thereto. The entities shown in FIG1B are examples. The communication system may include all or part of the entities shown in FIG1B , or may include other entities outside of FIG1B . The number and form of the entities are arbitrary. The entities may be physical or virtual. The connection relationship between the entities is an example. The entities may be connected or disconnected. The connection may be in any manner, directly or indirectly, and wired or wireless.

[0162] The embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G New Radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New Radio Access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X), systems utilizing other communication methods, and next-generation systems based on and extending these methods. Furthermore, multiple systems may be combined (for example, a combination of LTE or LTE-A with 5G).

[0163] In some embodiments, the embodiments of the present disclosure may be applied in a UE-satellite-UE communication scenario.

[0164] In some embodiments, it is necessary to support UE-satellite-UE communication. UE-satellite-UE communication refers to communication between UEs through access network equipment on a satellite within the coverage area of ​​one or more serving satellites, without switching user plane (UP) data through a terrestrial network.

[0165] FIG1C is a schematic diagram illustrating a UE-satellite-UE communication scenario according to an embodiment of the present disclosure. As shown in FIG1C , UEx and UEy communicate via a gNB on a satellite.

[0166] In some embodiments, the security of UP data on the Uu interface is activated based on a security policy sent from the core network. This policy is set by the Unified Data Management (UDM) or Session Management Function (SMF) based on the specific service requested by the UE. The SMF determines the UP security enforcement information for the Protocol Data Unit (PDU) session when the PDU session is established based on the following information:

[0167] (1) a subscribed UP security policy, which is part of the service module (SM) subscription information received from the UDM; or

[0168] (2) When UDM does not provide UP security policy information, the UP security policy configured locally in SMF based on (Data Network Name (DNN) and Single Network Slice Selection Assistance Information (S-NSSAI)) will be used.

[0169] In some embodiments, the UP security policy indicates whether UP security protection of the PDU session should be activated on the Uu interface, which is used to activate UP confidentiality and / or UP integrity of the PDU session.

[0170] In some embodiments, since UE-satellite-UE communication transmits UP data locally on the gNB on the satellite, rather than through the terrestrial network on the core network function (e.g., SMF), providing UP security policy configuration to the gNB becomes a pressing issue.

[0171] FIG2A is an interactive diagram illustrating a policy control method according to an embodiment of the present disclosure. The method may be executed by the above-mentioned communication system. As shown in FIG2A , the method may include:

[0172] Step S2101: During the registration process of the first terminal device, the first UDM determines to send a first UP security policy to the access network device based on the contract information of the first terminal device.

[0173] In some embodiments, the first terminal device may be a terminal device that communicates with the second terminal device via a satellite.

[0174] In some embodiments, the first terminal device may be a UE in a UE-satellite-UE communication scenario.

[0175] In some embodiments, the access network device may be an access network device on a satellite.

[0176] In some embodiments, the contract information can be used to indicate whether the first terminal device has signed a contract for local transmission of UP data.

[0177] In some embodiments, "local transmission of UP data" can be understood as "local transmission of UP data on the gNB on the satellite during communication between the first terminal device and the second terminal device, without passing through the ground network on the core network function side."

[0178] For example, the first terminal device and the second terminal device do not switch local UP data through SMF.

[0179] In some embodiments, the first UP security policy may be used to indicate any of the following:

[0180] Activate security protection for the second UP data;

[0181] Do not activate security protection for the second UP data;

[0182] The first indication information is used to instruct the access network device to determine whether to activate security protection for the second UP data.

[0183] The second UP data may be UP data between the first terminal device and the access network device.

[0184] In one implementation, if the first UP security policy indicates the first indication information, the access network device can independently determine whether to activate security protection for the second UP data.

[0185] In some embodiments, the first UDM may be any UDM in the core network, which is not limited in the embodiments of the present disclosure.

[0186] In some embodiments, during the registration process of the first terminal device with the core network, the first UDM can obtain the contract information of the first terminal device and determine whether to send the first UP security policy based on the contract information.

[0187] In some embodiments, it is determined based on the contract information of the first terminal device whether the first terminal device has signed a contract for local transmission of UP data, and it is determined to send a first UP security policy.

[0188] For example, if it is determined based on the contract information of the first terminal device that the first terminal device has signed a contract for local transmission of UP data, it is determined to send the first UP security policy to the access network device; if it is determined based on the contract information of the first terminal device that the first terminal device has not signed a contract for local transmission of UP data, it is determined not to send the first UP security policy to the access network device.

[0189] It should be noted that the registration process of the first terminal device can refer to the provisions of the existing protocol and will not be repeated here.

[0190] Step S2102: The first UDM sends the first UP security policy to the access network device through the first AMF.

[0191] In some embodiments, if it is determined to send a first UP security policy to the access network device, the first UP security policy can be sent to the access network device through the first AMF.

[0192] In some embodiments, the first AMF can be any AMF in the core network, which is not limited in the embodiments of the present disclosure.

[0193] Step S2103: During the registration process of the second terminal device, the second UDM determines to send the second UP security policy to the access network device based on the contract information of the second terminal device.

[0194] In some embodiments, the contract information of the second terminal device may be the same as the contract information of the first terminal device, or the contract information of the second terminal device may be different from the contract information of the first terminal device. This is not limited in the embodiments of the present disclosure.

[0195] In some embodiments, the second UP security policy may be used to indicate any of the following:

[0196] Activate security protection for third-party UP data;

[0197] Do not activate security protection for third-party UP data;

[0198] The first indication information is used to instruct the access network device to determine whether to activate security protection for the third UP data.

[0199] The third UP data may be UP data between the second terminal device and the access network device.

[0200] In one implementation, if the second UP security policy indicates the first indication information, the access network device can independently determine whether to activate security protection for the third UP data.

[0201] In some embodiments, the second UDM may be any UDM in the core network, which is not limited in the embodiments of the present disclosure.

[0202] In some embodiments, the second UDM may be different from the first UDM.

[0203] In some embodiments, during the registration process of the second terminal device with the core network, the second UDM can obtain the contract information of the second terminal device and determine whether to send the second UP security policy based on the contract information.

[0204] In some embodiments, the second UDM determines that the second terminal device has signed a contract for local transmission of UP data based on the contract information of the second terminal device, and determines to send a second UP security policy.

[0205] For example, if it is determined based on the contract information of the second terminal device that the second terminal device has signed a contract for local transmission of UP data, it is determined to send the second UP security policy to the access network device; if it is determined based on the contract information of the second terminal device that the second terminal device has not signed a contract for local transmission of UP data, it is determined not to send the second UP security policy to the access network device.

[0206] It should be noted that the registration process of the second terminal device can refer to the provisions of the existing protocol and will not be repeated here.

[0207] Step S2104: The second UDM sends the second UP security policy to the access network device through the second AMF.

[0208] In some embodiments, if it is determined to send a second UP security policy to the access network device, the second UP security policy can be sent to the access network device through the second AMF.

[0209] In some embodiments, the second AMF can be any AMF in the core network, which is not limited in the embodiments of the present disclosure.

[0210] In some embodiments, the second AMF may be different from the first AMF.

[0211] Step S2105: The first terminal device sends a first PDU session establishment request to the access network device.

[0212] In some embodiments, after registration is completed, the first terminal device may send a first PDU session establishment request to the access network device.

[0213] It should be noted that the content and sending method of the first PDU session request can refer to the existing protocol and will not be repeated here.

[0214] Step S2106: The access network device activates security protection for the second UP data according to the first UP security policy.

[0215] In some embodiments, security protection may include at least one of the following: integrity protection and confidentiality protection.

[0216] In one implementation, if the first UP security policy indicates "activate security protection for the second UP data" and the security protection includes integrity protection, the access network device can activate the integrity protection of the second UP data; if the first UP security policy indicates "activate security protection for the second UP data" and the security protection includes confidentiality protection, the access network device can activate the confidentiality protection of the second UP data; if the first UP security policy indicates "activate security protection for the second UP data" and the security protection includes integrity protection and confidentiality protection, the access network device can activate the integrity protection and confidentiality protection of the second UP data.

[0217] In another implementation, if the first UP security policy indicates "not activating security protection for the second UP data", the access network device may not activate security protection for the second UP data.

[0218] In another implementation, if the first UP security policy indicates the first indication information, the access network device may activate the security protection for the second UP data or may not activate the security protection for the second UP data.

[0219] It should be noted that when the first UP security policy indicates the first indication information, the access network device can determine whether to activate the security protection of the second UP data according to the protocol agreement, and the embodiment of the present disclosure does not limit this.

[0220] Step S2107: The second terminal device sends a second PDU session establishment request to the access network device.

[0221] In some embodiments, after registration is completed, the second terminal device may send a second PDU session establishment request to the access network device.

[0222] It should be noted that the content and sending method of the second PDU session request can refer to the existing protocol and will not be repeated here.

[0223] Step S2108: The access network device activates security protection for the third UP data according to the second UP security policy.

[0224] In one implementation, if the second UP security policy indicates "activate security protection for the third UP data" and the security protection includes integrity protection, the access network device can activate the integrity protection of the third UP data; if the second UP security policy indicates "activate security protection for the third UP data" and the security protection includes confidentiality protection, the access network device can activate the confidentiality protection of the third UP data; if the second UP security policy indicates "activate security protection for the third UP data" and the security protection includes integrity protection and confidentiality protection, the access network device can activate the integrity protection and confidentiality protection of the third UP data.

[0225] In another implementation, if the second UP security policy indicates "not activating security protection for the third UP data", the access network device may not activate security protection for the third UP data.

[0226] In another implementation, if the second UP security policy indicates the first indication information, the access network device may activate security protection for the third UP data or may not activate security protection for the third UP data.

[0227] It should be noted that when the second UP security policy indicates the first indication information, the access network device can determine whether to activate the security protection of the third UP data according to the protocol agreement, and the embodiment of the present disclosure is not limited to this.

[0228] The method involved in the embodiments of the present disclosure may include at least one of the above steps S2101 to S2108. For example, step S2101 and step S2102 can be implemented as independent embodiments, step S2103 and step S2104 can be implemented as independent embodiments, step S2105 and step S2106 can be implemented as independent embodiments, step S2107 and step S2108 can be implemented as independent embodiments, step S2101, step S2102, step S2105, and step S2106 can be implemented as independent embodiments, and step S2103, step S2104, step S2107, and step S2108 can be implemented as independent embodiments.

[0229] In some embodiments, steps S2101 to S2108 can be executed in a swapped order or simultaneously. For example, steps S2101 and S2103 can be executed in a swapped order or simultaneously, steps S2102 and S2104 can be executed in a swapped order or simultaneously, steps S2105 and S2107 can be executed in a swapped order or simultaneously, and steps S2106 and S2108 can be executed in a swapped order or simultaneously.

[0230] In some embodiments, the above steps S2101 to S2108 are all optional steps.

[0231] In some embodiments, reference may be made to other optional implementations described before or after the description corresponding to FIG. 2A .

[0232] Using the above method, the access network device can receive the first UP security policy sent by the first UDM during the registration process of the first terminal device, and after receiving the first PDU session request sent by the first terminal device, activate security protection for the second UP data according to the first UP security policy. During the registration process of the second terminal device, the access network device can receive the second UP security policy sent by the second UDM, and after receiving the second PDU session request sent by the second terminal device, activate security protection for the third UP data according to the second UP security policy. In this way, the access network device can implement security protection for locally transmitted UP data through the UDM.

[0233] In some embodiments, the names of information, etc. are not limited to the names described in the embodiments, and terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codeword", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.

[0234] In some embodiments, "obtain", "get", "get", "receive", "transmit", "bidirectional transmission", "send and / or receive" can be interchangeable, and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining by self-processing, autonomous implementation, etc.

[0235] In some embodiments, terms such as "send", "transmit", "report", "download", "transmit", "bidirectional transmission", "send and / or receive" can be used interchangeably.

[0236] In some embodiments, terms such as "certain", "preset", "preset", "setting", "indicated", "a certain", "any", and "first" can be interchangeable. "Specific A", "preset A", "preset A", "setting A", "indicated A", "a certain A", "any A", and "first A" can be interpreted as A pre-specified in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., or as specific A, a certain A, any A, or first A, etc., but not limited to this.

[0237] FIG2B is an interactive diagram illustrating a policy control method according to an embodiment of the present disclosure. The method may be executed by the above-mentioned communication system. As shown in FIG2B , the method may include:

[0238] Step S2201: During the service authorization and information configuration process of the first terminal device, the first PCF sends the first UP security policy to the access network device through the first AMF.

[0239] It should be noted that the explanation of the first terminal device, access network device, first UP security policy, and second UP data in step S2201 can refer to step S2101 and will not be repeated here.

[0240] In some embodiments, the first PCF may be any PCF in the core network, which is not limited in the embodiments of the present disclosure.

[0241] In some embodiments, during the service authorization and information configuration process of the first terminal device, the first PCF can send the first UP security policy to the access network device through the first AMF.

[0242] In some embodiments, the PCF may determine the UP security policy corresponding to the terminal device from a unified data repository (UDR).

[0243] For example, the PCF may retrieve the first UP security policy corresponding to the first terminal device from the UDR.

[0244] In some embodiments, the first AMF can be any AMF in the core network, which is not limited in the embodiments of the present disclosure.

[0245] It should be noted that the service authorization and information configuration process of the first terminal device can refer to the provisions of the existing protocol and will not be repeated here.

[0246] Step S2202: During the service authorization and information configuration process of the second terminal device, the second PCF sends the second UP security policy to the access network device through the second AMF.

[0247] In some embodiments, the second PCF may be any PCF in the core network, which is not limited in the embodiments of the present disclosure.

[0248] In some embodiments, the second PCF may be different from the first PCF.

[0249] In some embodiments, the contract information of the second terminal device may be the same as the contract information of the first terminal device, or the contract information of the second terminal device may be different from the contract information of the first terminal device. This is not limited in the embodiments of the present disclosure.

[0250] In some embodiments, during the service authorization and information configuration process of the second terminal device, the second PCF can send the second UP security policy to the access network device through the second AMF.

[0251] In some embodiments, the PCF may retrieve the second UP security policy corresponding to the second terminal device from the UDR.

[0252] In some embodiments, the second AMF can be any AMF in the core network, which is not limited in the embodiments of the present disclosure.

[0253] In some embodiments, the second AMF may be different from the first AMF.

[0254] It should be noted that the service authorization and information configuration process of the second terminal device can refer to the provisions of the existing protocol and will not be repeated here.

[0255] Step S2203: The first terminal device sends a first PDU session establishment request to the access network device.

[0256] The optional implementation of step S2203 can refer to the optional implementation of step S2105 in FIG2A and other related parts in the embodiment involved in FIG2A , which will not be described in detail here.

[0257] Step S2204: The access network device activates security protection for the second UP data according to the first UP security policy.

[0258] The optional implementation of step S2204 can refer to the optional implementation of step S2106 in FIG2A and other related parts in the embodiment involved in FIG2A , which will not be described in detail here.

[0259] Step S2205: The second terminal device sends a second PDU session establishment request to the access network device.

[0260] The optional implementation of step S2205 can refer to the optional implementation of step S2107 in FIG2A and other related parts in the embodiment involved in FIG2A , which will not be described in detail here.

[0261] Step S2206: The access network device activates security protection for the third UP data according to the second UP security policy.

[0262] The optional implementation of step S2206 can refer to the optional implementation of step S2108 in FIG2A and other related parts in the embodiment involved in FIG2A , which will not be described in detail here.

[0263] The method involved in the embodiments of the present disclosure may include at least one of the above steps S2201 to S2206. For example, step S2201 can be implemented as an independent embodiment, step S2202 can be implemented as an independent embodiment, step S2203 + step S2204 can be implemented as an independent embodiment, step S2205 + step S2206 can be implemented as an independent embodiment, step S2201 + step S2203 + step S2204 can be implemented as an independent embodiment, and step S2202 + step S2205 + step S2206 can be implemented as an independent embodiment.

[0264] In some embodiments, steps S2201 to S2206 can be executed in a swapped order or simultaneously. For example, steps S2201 and S2202 can be executed in a swapped order or simultaneously, steps S2203 and S2205 can be executed in a swapped order or simultaneously, and steps S2204 and S2206 can be executed in a swapped order or simultaneously.

[0265] In some embodiments, the above steps S2201 to S2206 are all optional steps.

[0266] Using the above method, the access network device can receive a first UP security policy sent by a first PCF during the service authorization and information configuration process of a first terminal device, and upon receiving a first PDU session request from the first terminal device, activate security protection for the second UP data according to the first UP security policy. Furthermore, during the service authorization and information configuration process of a second terminal device, the access network device can receive a second UP security policy sent by a second PCF, and upon receiving a second PDU session request from the second terminal device, activate security protection for the third UP data according to the second UP security policy. In this way, the access network device can implement security protection for locally transmitted UP data through the PCF.

[0267] FIG3A is a flow chart of a policy control method according to an embodiment of the present disclosure. As shown in FIG3A , the embodiment of the present disclosure relates to a policy control method, which can be executed by an access network device. The method may include:

[0268] Step S3101: During the registration process of the first terminal device, obtain the first UP security policy.

[0269] The optional implementation of step S3101 can refer to the optional implementation of step S2101 and step S2102 in Figure 2A, and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.

[0270] Step S3102: During the registration process of the second terminal device, obtain the second UP security policy.

[0271] The optional implementation of step S3102 can refer to the optional implementation of step S2103 and step S2104 in Figure 2A, and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.

[0272] Step S3103: Obtain a first PDU session establishment request.

[0273] The optional implementation of step S3103 can refer to the optional implementation of step S2105 in FIG2A and other related parts in the embodiment involved in FIG2A , which will not be described in detail here.

[0274] Step S3104: Activate security protection for the second UP data according to the first UP security policy.

[0275] The optional implementation of step S3104 can refer to the optional implementation of step S2106 in FIG2A and other related parts in the embodiment involved in FIG2A , which will not be described in detail here.

[0276] Step S3105: Get the second PDU session establishment request

[0277] The optional implementation of step S3105 can refer to the optional implementation of step S2107 in FIG2A and other related parts in the embodiment involved in FIG2A , which will not be described in detail here.

[0278] Step S3106: Activate security protection for the third UP data according to the second UP security policy.

[0279] The optional implementation of step S3106 can refer to the optional implementation of step S2108 in FIG2A and other related parts in the embodiment involved in FIG2A , which will not be described in detail here.

[0280] The method involved in the embodiments of the present disclosure may include at least one of the above steps S3101 to S3106. For example, step S3101 can be implemented as an independent embodiment, step S3102 can be implemented as an independent embodiment, step S3103 + step S3104 can be implemented as an independent embodiment, step S3105 + step S3106 can be implemented as an independent embodiment, step S3101 + step S3103 + step S3104 can be implemented as an independent embodiment, and step S3102 + step S3105 + step S3106 can be implemented as an independent embodiment.

[0281] In some embodiments, steps S3101 to S3106 can be executed in a swapped order or simultaneously. For example, steps S3101 and S3102 can be executed in a swapped order or simultaneously, steps S3103 and S3105 can be executed in a swapped order or simultaneously, and steps S3104 and S3106 can be executed in a swapped order or simultaneously.

[0282] In some embodiments, the above steps S3101 to S3106 are all optional steps.

[0283] FIG3B is a flow chart of a policy control method according to an embodiment of the present disclosure. As shown in FIG3B , the embodiment of the present disclosure relates to a policy control method, which can be executed by an access network device. The method may include:

[0284] Step S3201: During the service authorization and information configuration process on the first terminal device, obtain the first UP security policy.

[0285] The optional implementation of step S3201 can refer to the optional implementation of step S220 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.

[0286] Step S3202: During the service authorization and information configuration process on the second terminal device, obtain the second UP security policy.

[0287] The optional implementation of step S3202 can refer to the optional implementation of step S2202 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.

[0288] Step S3203: Obtain a first PDU session establishment request.

[0289] The optional implementation of step S3203 can refer to the optional implementation of step S2203 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.

[0290] Step S3204: Activate security protection for the second UP data according to the first UP security policy.

[0291] The optional implementation of step S3204 can refer to the optional implementation of step S2204 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.

[0292] Step S3205: Get the second PDU session establishment request

[0293] The optional implementation of step S3205 can refer to the optional implementation of step S2205 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.

[0294] Step S3206: Activate security protection for the third UP data according to the second UP security policy.

[0295] The optional implementation of step S3206 can refer to the optional implementation of step S2206 in Figure 2B and other related parts in the embodiment involved in Figure 2B, which will not be repeated here.

[0296] The method involved in the embodiments of the present disclosure may include at least one of the above steps S3201 to S3206. For example, step S3201 can be implemented as an independent embodiment, step S3202 can be implemented as an independent embodiment, step S3203 + step S3204 can be implemented as an independent embodiment, step S3205 + step S3206 can be implemented as an independent embodiment, step S3201 + step S3203 + step S3204 can be implemented as an independent embodiment, and step S3202 + step S3205 + step S3206 can be implemented as an independent embodiment.

[0297] In some embodiments, steps S3201 to S3206 can be executed in a swapped order or simultaneously. For example, steps S3201 and S3202 can be executed in a swapped order or simultaneously, steps S3203 and S3205 can be executed in a swapped order or simultaneously, and steps S3204 and S3206 can be executed in a swapped order or simultaneously.

[0298] In some embodiments, the above steps S3201 to S3206 are all optional steps.

[0299] FIG3C is a flow chart of a policy control method according to an embodiment of the present disclosure. As shown in FIG3C , the embodiment of the present disclosure relates to a policy control method, which can be executed by an access network device. The method may include:

[0300] Step S3301: During the terminal device registration process, obtain the UP security policy.

[0301] The optional implementation of step S3301 can be found in steps S2101 to S2104 of FIG. 2A , the optional implementation of steps S3101 and S3102 of FIG. 3A , and other related parts in the embodiments involved in FIG. 2A and FIG. 3A , which will not be repeated here.

[0302] In some embodiments, the UP security policy includes at least one of the following: a first UP security policy and a second UP security policy, the first UP security policy is the UP security policy corresponding to the first terminal device, the second UP security policy is the UP security policy corresponding to the second terminal device, and the first terminal device and the second terminal device perform local transmission of UP data through the access network device.

[0303] In some embodiments, the UP security policy is used to indicate any of the following:

[0304] activating security protection for the first UP data;

[0305] Not activating security protection for the first UP data;

[0306] The first indication information is used to instruct the access network device to determine whether to activate security protection for the first UP data.

[0307] Step S3302: Obtain a PDU session establishment request.

[0308] The optional implementation of step S3302 can be found in step S2105 of FIG. 2A , the optional implementation of step S3103 of FIG. 3A , and other related parts in the embodiments involved in FIG. 2A and FIG. 3A , which will not be described in detail here.

[0309] Step S3303: Activate security protection for the first UP data according to the UP security policy.

[0310] The optional implementation of step S3303 can be found in step S2106 and step S2108 of FIG. 2A , the optional implementation of step S3104 and step S3106 of FIG. 3A , and other related parts in the embodiments involved in FIG. 2A and FIG. 3A , which will not be repeated here.

[0311] In some embodiments, the first UP data includes at least one of the following: second UP data and third UP data, the second UP data is UP data protected by the first UP security policy, and the third UP data is UP data protected by the second UP security policy.

[0312] In some embodiments, the above steps are all optional steps.

[0313] FIG3D is a flow chart of a policy control method according to an embodiment of the present disclosure. As shown in FIG3D , the embodiment of the present disclosure relates to a policy control method, which can be executed by an access network device. The method may include:

[0314] Step S3401: During the service authorization and information configuration process of the terminal device, obtain the UP security policy.

[0315] The optional implementation of step S3401 can be found in steps S2201 and S2202 of FIG. 2B , the optional implementation of steps S3201 and S3202 of FIG. 3B , and other related parts in the embodiments involved in FIG. 2B and FIG. 3B , which will not be repeated here.

[0316] Step S3402: Obtain a PDU session establishment request.

[0317] The optional implementation of step S3402 can be found in step S2203 and step S2205 of FIG. 2B , the optional implementation of step S3203 and step S3205 of FIG. 3B , and other related parts in the embodiments involved in FIG. 2B and FIG. 3B , which will not be repeated here.

[0318] Step S3403: Activate security protection for the first UP data according to the UP security policy.

[0319] The optional implementation of step S3403 can be found in steps S2204 and S2206 of FIG. 2B , the optional implementation of steps S3204 and S3206 of FIG. 3B , and other related parts in the embodiments involved in FIG. 2B and FIG. 3B , which will not be repeated here.

[0320] In some embodiments, the above steps are all optional steps.

[0321] FIG3E is a flow chart of a policy control method according to an embodiment of the present disclosure. As shown in FIG3E , an embodiment of the present disclosure relates to a policy control method, which can be executed by an access network device. The method may include:

[0322] Step S3501: Obtain first configuration information.

[0323] In some embodiments, the UP security policy may include a third UP security policy, where the third UP security policy is used to securely protect the first UP data transmitted locally by the access network device.

[0324] In some embodiments, the third UP security policy can provide security protection for each first UP data transmitted locally through the access network device.

[0325] For example, the first terminal device and the second terminal device communicate through the access network device. The third UP security policy can provide security protection for the second UP data between the first terminal device and the access network device, and can also provide security protection for the third UP data between the second terminal device and the access network device.

[0326] In some embodiments, the first configuration information may be used to indicate the third UP security policy.

[0327] In some embodiments, the first configuration information may be specified by a protocol or may be predefined, which is not limited in the embodiments of the present disclosure.

[0328] In some embodiments, the third UP security policy may include activating security protection for the first UP data, or not activating security protection for the first UP data.

[0329] The first UP data may include at least one of the second UP data and the third UP data.

[0330] Step S3502: Activate security protection of the first UP data corresponding to the third UP security policy according to the first configuration information.

[0331] In some embodiments, if the third UP security policy is to activate protection of the first UP data, the access network device may start security protection for the first UP data.

[0332] In some embodiments, if the third UP security policy is to not activate protection of the first UP data, the access network device may not start security protection for the first UP data.

[0333] By adopting the above method, the third UP security policy can be configured in advance in the access network device to implement security protection for UP data transmitted locally by the access network device.

[0334] FIG3F is a flow chart of a policy control method according to an embodiment of the present disclosure. As shown in FIG3F , the embodiment of the present disclosure relates to a policy control method, which can be executed by an access network device. The method may include:

[0335] Step S3601: Obtain UP security policy.

[0336] For the optional implementation of step S3601, please refer to steps S2101 to S2104 of Figure 2A, steps S2201 to S2202 of Figure 2B, steps S3101 to S3102 of Figure 3A, steps S3201 to S3202 of Figure 3B, and the optional implementation of step S3501 of Figure 3E, as well as other related parts in the embodiments involved in Figures 2A, 2B, 3A, 3B, and 3E, which will not be repeated here.

[0337] Step S3602: Perform security protection on the first UP data according to the UP security policy.

[0338] For the optional implementation of step S3602, please refer to steps S2105 to S2108 of Figure 2A, steps S2203 to S2206 of Figure 2B, steps S3103 to S3106 of Figure 3A, steps S3203 to S3206 of Figure 3B, the optional implementation of step S3502 of Figure 3E, and other related parts in the embodiments involved in Figures 2A, 2B, 3A, 3B, and 3E, which will not be repeated here.

[0339] The first UP data is UP data that is locally transmitted by the terminal device through the access network device.

[0340] In some embodiments, the terminal device includes a first terminal device and / or a second terminal device, and the UP security policy may include at least one of the following: a first UP security policy and a second UP security policy, the first UP security policy is the UP security policy corresponding to the first terminal device, the second UP security policy is the UP security policy corresponding to the second terminal device, and the first terminal device and the second terminal device perform local transmission of UP data through the access network device.

[0341] In some embodiments, obtaining the UP security policy includes at least one of the following:

[0342] During the registration process of the first terminal device, receiving the first UP security policy sent by the first unified data management UDM through the first access and mobility management function AMF;

[0343] During the registration process of the second terminal device, the second UP security policy sent by the second UDM through the second AMF is received.

[0344] In some embodiments, obtaining the UP security policy includes at least one of the following:

[0345] During the service authorization and information configuration process of the first terminal device, receiving the first UP security policy sent by the first policy and charging function PCF through the first AMF;

[0346] During the service authorization and information configuration process of the second terminal device, the second UP security policy sent by the second PCF through the second AMF is received.

[0347] In some embodiments, the first UP data includes at least one of the following: second UP data and third UP data, the second UP data is UP data protected by the first UP security policy, and the third UP data is UP data protected by the second UP security policy.

[0348] In some embodiments, the performing security protection on the first UP data according to the UP security policy includes:

[0349] Receiving a first protocol data unit (PDU) session establishment request sent by the first terminal device;

[0350] Activate security protection for the second UP data according to the first UP security policy.

[0351] In some embodiments, the performing security protection on the first UP data according to the UP security policy includes:

[0352] Receiving a second PDU session establishment request sent by the second terminal device;

[0353] Activate security protection for the third UP data according to the second UP security policy.

[0354] In some embodiments, the first UP security policy includes a third UP security policy, and the third UP security policy is used to securely protect UP data transmitted locally by the access network device.

[0355] In some embodiments, obtaining the UP security policy includes:

[0356] Obtain first configuration information, where the first configuration information is used to indicate the third UP security policy.

[0357] In some embodiments, the performing security protection on the first UP data according to the UP security policy includes:

[0358] According to the first configuration information, security protection of UP data corresponding to the third UP security policy is activated.

[0359] In some embodiments, the UP security policy is used to indicate any of the following:

[0360] activating security protection for the first UP data;

[0361] deactivating security protection for the first UP data;

[0362] First indication information, where the first indication information is used to instruct the access network device to determine whether to activate security protection for the first UP data.

[0363] In some embodiments, the security protection includes at least one of the following: integrity protection and confidentiality protection.

[0364] FIG4A is a flow chart of a policy control method according to an embodiment of the present disclosure. As shown in FIG4A , an embodiment of the present disclosure relates to a policy control method, which can be executed by a UDM. The method may include:

[0365] Step S4101: During the terminal device registration process, determine to send the UP security policy to the access network device based on the contract information of the terminal device.

[0366] The optional implementation of step S4101 can refer to the optional implementation of step S2101 and step S2103 in Figure 2A, and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.

[0367] In some embodiments, the UDM includes at least one of the following: a first UDM and a second UDM, wherein the first UDM is used to send the first UP security policy to the access network device through the first AMF during the registration process of the first terminal device, and the second UDM is used to send the second UP security policy to the access network device through the second AMF during the registration process of the second terminal device.

[0368] Step S4102: Send the UP security policy to the access network device through AMF.

[0369] The optional implementation of step S4102 can refer to the optional implementation of step S2102 and step S2104 in Figure 2A, and other related parts in the embodiment involved in Figure 2A, which will not be repeated here.

[0370] In some embodiments, the AMF may include a first AMF and / or a second AMF.

[0371] For example, in the case where the terminal device includes a first terminal device, the AMF may include a first AMF, in the case where the terminal device includes a second terminal device, the AMF includes a second AMF, and in the case where the terminal device includes a first terminal device and a second terminal device, the AMF includes a first AMF and a second AMF.

[0372] In some embodiments, the above steps are all optional steps.

[0373] FIG4B is a flow chart of a policy control method according to an embodiment of the present disclosure. As shown in FIG4B , an embodiment of the present disclosure relates to a policy control method, which can be executed by a network device. The method may include:

[0374] Step S4201: During the terminal device registration process, the UP security policy is sent to the access network device through AMF.

[0375] The optional implementation of step S4201 can refer to steps S2101 to S2104 in FIG. 2A , the optional implementation of step S4102 in FIG. 4A , and other related parts in the embodiments involved in FIG. 2A and FIG. 4A , which will not be repeated here.

[0376] In some embodiments, sending the UP security policy to the access network device through the AMF includes:

[0377] Determine sending the UP security policy according to the contract information of the terminal device;

[0378] The UP security policy is sent to the access network device via the AMF. In some embodiments,

[0379] In some embodiments, determining to send the UP security policy according to the contract information of the terminal device includes:

[0380] Determining local transmission of UP data signed by the terminal device according to the contract information of the terminal device;

[0381] Determine to send the UP security policy.

[0382] In some embodiments, the terminal device includes a first terminal device and / or a second terminal device, and the UP security policy includes at least one of the following: a first UP security policy and a second UP security policy, the first UP security policy is the UP security policy corresponding to the first terminal device, and the second UP security policy is the UP security policy corresponding to the second terminal device, and the first terminal device and the second terminal device perform local transmission of UP data through the access network device.

[0383] In some embodiments, the UDM includes at least one of the following: a first UDM and a second UDM, wherein the first UDM is used to send the first UP security policy to the access network device through the first AMF during the registration process of the first terminal device, and the second UDM is used to send the second UP security policy to the access network device through the second AMF during the registration process of the second terminal device.

[0384] In some embodiments, the UP security policy is used to indicate any of the following:

[0385] activating security protection for the first UP data;

[0386] deactivating security protection for the first UP data;

[0387] First indication information, where the first indication information is used to instruct the access network device to determine whether to activate security protection for the first UP data.

[0388] In some embodiments, the security protection includes at least one of the following: integrity protection and confidentiality protection.

[0389] FIG5 is a flow chart of a policy control method according to an embodiment of the present disclosure. As shown in FIG5 , the embodiment of the present disclosure relates to a policy control method, which can be executed by a PCF. The method may include:

[0390] Step S5101: During the service authorization and information configuration process of the first terminal device, the UP security policy is sent to the access network device through AMF.

[0391] The optional implementation of step S5201 can refer to the optional implementation of steps S2201 to S2202 in FIG. 2B , and other related parts in the embodiment involved in FIG. 2B , which will not be described in detail here.

[0392] In some embodiments, the AMF may include a first AMF and / or a second AMF.

[0393] For example, in the case where the terminal device includes a first terminal device, the AMF may include a first AMF, in the case where the terminal device includes a second terminal device, the AMF includes a second AMF, and in the case where the terminal device includes a first terminal device and a second terminal device, the AMF includes a first AMF and a second AMF.

[0394] In some embodiments, the terminal device includes a first terminal device and / or a second terminal device, and the UP security policy includes at least one of the following: a first UP security policy and a second UP security policy, the first UP security policy is the UP security policy corresponding to the first terminal device, and the second UP security policy is the UP security policy corresponding to the second terminal device, and the first terminal device and the second terminal device perform local transmission of UP data through the access network device.

[0395] In some embodiments, the PCF includes at least one of the following: a first PCF and a second PCF, wherein the first PCF is used to send the first UP security policy to the access network device through the first AMF during the service authorization and information configuration process of the first terminal device, and the second PCF is used to send the second UP security policy to the access network device through the second AMF during the service authorization and information configuration process of the second terminal device.

[0396] In some embodiments, the method further comprises:

[0397] Determine the UP security policy corresponding to the terminal device from the unified data repository UDR.

[0398] In some embodiments, the UP security policy is used to indicate any of the following:

[0399] activating security protection for the first UP data;

[0400] deactivating security protection for the first UP data;

[0401] First indication information, where the first indication information is used to instruct the access network device to determine whether to activate security protection for the first UP data.

[0402] In some embodiments, the security protection includes at least one of the following: integrity protection and confidentiality protection.

[0403] In some embodiments, in UE-satellite-UE communication, the UP security policy is configured on the gNB without the core network functions of the terrestrial network participating in the communication process.

[0404] In some embodiments, the architecture of UE-satellite-UE communication may include:

[0405] (1) To use the UE-satellite-UE communication feature, the UE needs to subscribe to the feature from the operator. Once the UE subscribes to the feature, the UP security policy for UE-satellite-UE communication will be configured as part of the UE subscription information, which can be stored in the UDM or UDR.

[0406] (2) In the UE-satellite-UE communication scenario, the existing registration procedures of all involved UEs, including relevant core network functions (such as UDM, PCF, AMF), as well as service authorization and information configuration procedures can be reused.

[0407] (3) In the UE-satellite-UE communication scenario, the core network functions (including SMF) in the terrestrial network may not participate in the PDU session establishment process (for example, due to the unavailability of the feeder link), or only the minimum set of SMF functions required for PDU session establishment are moved to the gNB on the satellite.

[0408] In some embodiments, according to existing specifications, the UP security policy is configured by the SMF to the gNB during the PDU session establishment process. If the terrestrial SMF is not used for UE-satellite-UE communication establishment on the ground (assuming (3) above), it is recommended that the UP security policy be configured by the UDM to the gNB on the satellite during the registration process, which is supported by (1) and (2) above.

[0409] In some embodiments, FIG6A is an interactive diagram illustrating a policy control method according to an embodiment of the present disclosure. As shown in FIG6A , the method may include:

[0410] 1a. UE1 initiates the registration process with the core network. During this period, UDM1 sends UE1's UP security policy to gNB through AMF1.

[0411] 1b. UE2 initiates the registration process with the core network. During this period, UDM2 sends UE2's UP security policy to gNB via AMF2.

[0412] 2. UE1 / UE2 respectively initiates the PDU session establishment process to the network (i.e., the gNB on the satellite) (e.g., 2a and 2b in Figure 6A).

[0413] 3. The gNB on the satellite activates the UP security state of UE1 / UE2 respectively according to the UP security policy received from the UDM.

[0414] In some embodiments, if the security policy indicates "Required," the gNB activates Uu UP security protection for each DRB via Radio Resource Control (RRC) signaling. If the security policy indicates "Not Needed," the gNB does not activate Uu UP security protection for PDU session establishment. If the security policy indicates "Preferred," the gNB may decide whether to activate Uu UP security protection. However, when the policy indicates "Required" or "Not Needed," the gNB cannot overrule the UP security policy received from the UDM.

[0415] It should be noted that the UP security policy of UE2 may be different from the UP security policy of UE1, so the security state of the activated UE1 may be different from the security state of the activated UE2.

[0416] 4. UP data between UE1 and UE2 transmitted via gNB is protected by the activated security method.

[0417] It should be noted that if the security state of the activated UE1 is different from the security state of the activated UE2, then the protection applied to the UP data between UE1 and the gNB may be different from the protection applied to the UP data between UE2 and the gNB.

[0418] In some embodiments, it is recommended that the PCF configure the UP security policy to the gNB on the satellite during the service authorization and information configuration process, which is supported by (1) and (2) above.

[0419] FIG6B is an interactive diagram illustrating a policy control method according to an embodiment of the present disclosure. As shown in FIG6B , the method may include:

[0420] 1a. UE1 initiates the service authorization and configuration process to the core network. During this process, PCF1 sends UE1's UP security policy to the gNB through AMF1. The PCF can retrieve the UP security policy from the UDR.

[0421] 1b. UE2 initiates the service authorization and configuration process to the core network. During this process, PCF2 sends UE2's UP security policy to the gNB via AMF2. The PCF can retrieve the UP security policy from the UDR.

[0422] 2. UE1 / UE2 respectively initiates the PDU session establishment process to the network (i.e., the gNB on the satellite) (e.g., 2a and 2b in Figure 6B).

[0423] 3. The gNB on the satellite activates the Uu UP security state for UE1 / UE2 respectively according to the UP security policy received from the PCF.

[0424] In some embodiments, if the security policy indicates "Required," the gNB activates Uu UP security protection for each DRB via RRC signaling. If the security policy indicates "Not Needed," the gNB does not activate Uu UP security protection for PDU session establishment. If the security policy indicates "Preferred," the gNB may decide whether to activate Uu UP security protection. However, when the policy indicates "Required" or "Not Needed," the gNB cannot overrule the UP security policy received from the UDM.

[0425] 4. UP data between UE1 and UE2 transmitted via gNB is protected by the activated security method.

[0426] In some embodiments, for PDU session establishment for UE-satellite-UE communications, it is recommended that UP security policies can also be pre-configured on the gNB on the satellite, i.e., the gNB can determine how to activate Uu UP security if no security policy is configured in the core network. For example, the gNB can determine:

[0427] (a) Integrity protection of UP data on the Uu interface for UE-satellite-UE communications shall always be enabled.

[0428] (b) Confidentiality protection of UP data for UE-satellite-UE communications on the Uu interface shall always be activated.

[0429] (c) The integrity and confidentiality protection of UP data on the Uu interface for UE-satellite-UE communications shall always be activated.

[0430] In some embodiments, for the UDM side, during the registration process based on UE subscription data, the UDM should be able to provide the UP security policy to the gNB through the AMF.

[0431] In some embodiments, for the PCF side, during the service authorization and information configuration process, the PCF should be able to provide UP security policies to the gNB through the AMF.

[0432] In some embodiments, for the gNB side, the gNB should be able to receive the UP security policy from the UDM via the AMF during the UE's registration process.

[0433] In some embodiments, for the gNB side, the gNB should be able to receive the UP security policy from the PCF via the AMF during the UE's service authorization and information configuration process.

[0434] In some embodiments, for the gNB side, the gNB should be able to determine how to activate Uu UP security when the core network has not configured UP security policy.

[0435] In some embodiments of the present disclosure, a communication system is provided, which may include an access network device, a UDM and a PCF, wherein the access network device can execute the policy control method executed by the access network device in the aforementioned embodiment of the present disclosure; the UDM can execute the policy control method executed by the UDM in the aforementioned embodiment of the present disclosure; and the PCF can execute the policy control method executed by the PCF in the aforementioned embodiment of the present disclosure.

[0436] The embodiments of the present disclosure also provide apparatuses for implementing any of the above methods. For example, an apparatus is provided that includes units or modules for implementing each step performed by an access network device in any of the above methods. For another example, another apparatus is provided that includes units or modules for implementing each step performed by a UDM in any of the above methods. For another example, another apparatus is provided that includes units or modules for implementing each step performed by a PCF in any of the above methods.

[0437] It should be understood that the division of the various units or modules in the above device is only a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. In addition, the units or modules in the device can be implemented in the form of a processor calling software: For example, the device includes a processor, the processor is connected to a memory, and the memory stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the various units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits, and the functions of some or all of the units or modules can be realized by designing the hardware circuits. The above-mentioned hardware circuits can be understood as one or more processors; for example, in one implementation, the above-mentioned hardware circuit is an application-specific integrated circuit (ASIC), and the functions of some or all of the above units or modules are realized by designing the logical relationship of the components in the circuit; for example, in another implementation, the above-mentioned hardware circuit can be realized by a programmable logic device (PLD). Taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by configuring the configuration file, thereby realizing the functions of some or all of the above units or modules. All units or modules of the above devices can be realized in the form of software called by the processor, or in the form of hardware circuits, or in part by the form of software called by the processor, and the rest by hardware circuits.

[0438] In the embodiments of the present disclosure, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction reading and execution capabilities, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of a hardware circuit. The logical relationship of the above-mentioned hardware circuit is fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.

[0439] Figure 7A is a schematic diagram of the structure of an access network device proposed in an embodiment of the present disclosure. As shown in Figure 7A, the access network device 160 may include at least one of a transceiver module 7101, a processing module 7102, etc. In some embodiments, the transceiver module 7101 is configured to obtain a user plane UP security policy; the processing module 7102 is configured to perform security protection on the first UP data according to the UP security policy, where the first UP data is UP data transmitted locally by the terminal device through the access network device. Optionally, the transceiver module 7101 can be used to execute at least one of the communication steps such as sending and / or receiving (for example, step S2102, but not limited thereto) performed by the access network device 160 in any of the above methods, which will not be repeated here. Optionally, the processing module 7102 can be used to execute at least one of the other steps (for example, step S2106, but not limited thereto) performed by the access network device 160 in any of the above methods, which will not be repeated here.

[0440] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module, and the transmitting module and the receiving module may be separate or integrated. Optionally, the transceiver module may be interchangeable with the transceiver.

[0441] In some embodiments, the processing module can be a single module or can include multiple submodules. Optionally, the multiple submodules respectively execute all or part of the steps required to be executed by the processing module. Optionally, the processing module can be interchangeable with the processor.

[0442] Figure 7B is a structural diagram of a UDM proposed in an embodiment of the present disclosure. As shown in Figure 7B, the UDM 171 may include: at least one of a transceiver module 7201, a processing module 7202, etc. In some embodiments, the transceiver module 7201 is configured to send a user plane UP security policy to the access network device through the access and mobility management function AMF during the terminal device registration process. The UP security policy is used by the access network device to perform security protection on the first UP data. The first UP data is the UP data that the terminal device transmits locally through the access network device. Optionally, the transceiver module 7201 can be used to execute at least one of the communication steps such as sending and / or receiving (for example, step S2102, but not limited to this) performed by the UDM 171 in any of the above methods, which will not be repeated here.

[0443] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module, and the transmitting module and the receiving module may be separate or integrated. Optionally, the transceiver module may be interchangeable with the transceiver.

[0444] Figure 7C is a structural diagram of a PCF proposed in an embodiment of the present disclosure. As shown in Figure 7C, the PCF 172 may include: at least one of a transceiver module 7301, a processing module 7302, etc. In some embodiments, the transceiver module 7301 is configured to send a user plane UP security policy to the access network device through the access and mobility management function AMF during the service authorization and information configuration process of the terminal device. The UP security policy is used by the access network device to perform security protection on the first UP data. The first UP data is the UP data transmitted locally by the terminal device through the access network device. Optionally, the transceiver module 7301 can be used to execute at least one of the communication steps such as sending and / or receiving (such as step S2201, but not limited to this) performed by the PCF 172 in any of the above methods, which will not be repeated here.

[0445] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module, and the transmitting module and the receiving module may be separate or integrated. Optionally, the transceiver module may be interchangeable with the transceiver.

[0446] Figure 8A is a schematic diagram of the structure of a communication device 8100 proposed in an embodiment of the present disclosure. Communication device 8100 can be a network device (e.g., an access network device, a core network device, etc.), a terminal (e.g., a user device, etc.), a chip, a chip system, or a processor that supports a first device to implement any of the above methods, or a chip, a chip system, or a processor that supports a terminal to implement any of the above methods. Communication device 8100 can be used to implement the methods described in the above method embodiments. For details, please refer to the description of the above method embodiments.

[0447] As shown in Figure 8A, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, an IoT device, an IoT device chip, a DU or CU, etc.), execute programs, and process program data. The communication device 8100 is used to perform any of the above methods.

[0448] In some embodiments, the communication device 8100 further includes one or more memories 8102 for storing instructions. Optionally, all or part of the memories 8102 may be located outside the communication device 8100.

[0449] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the transceiver 8103 performs at least one of the communication steps such as sending and / or receiving in the above method (for example, step S2102 and step S2104, but not limited thereto), and the processor 8101 performs at least one of the other steps (for example, step S2101, but not limited thereto).

[0450] In some embodiments, a transceiver may include a receiver and / or a transmitter. The receiver and transmitter may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, and transceiver circuit may be used interchangeably; the terms transmitter, transmitting unit, transmitter, and transmitting circuit may be used interchangeably; and the terms receiver, receiving unit, receiver, and receiving circuit may be used interchangeably.

[0451] In some embodiments, the communication device 8100 may include one or more interface circuits. Optionally, the interface circuits are connected to the memory 8102 and may be used to receive signals from the memory 8102 or other devices, or to send signals to the memory 8102 or other devices. For example, the interface circuits may read instructions stored in the memory 8102 and send the instructions to the processor 8101.

[0452] The communication device 8100 described in the above embodiments may be a first device or an IoT device, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG. 8A. The communication device may be an independent device or may be part of a larger device. For example, the communication device may be: 1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data or programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, an IoT device, an intelligent IoT device, a cellular phone, a wireless device, a handheld device, a mobile unit, an in-vehicle device, a first device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.

[0453] FIG8B is a schematic diagram of the structure of a chip 8200 according to an embodiment of the present disclosure. If the communication device 8100 can be a chip or a chip system, please refer to the schematic diagram of the structure of the chip 8200 shown in FIG8B , but the present disclosure is not limited thereto.

[0454] The chip 8200 includes one or more processors 8201 , and the chip 8200 is configured to execute any of the above methods.

[0455] In some embodiments, the chip 8200 further includes one or more interface circuits 8203. Optionally, the interface circuit 8203 is connected to the memory 8202. The interface circuit 8203 can be used to receive signals from the memory 8202 or other devices, and can be used to send signals to the memory 8202 or other devices. For example, the interface circuit 8203 can read instructions stored in the memory 8202 and send the instructions to the processor 8201.

[0456] In some embodiments, the interface circuit 8203 executes at least one of the communication steps such as sending and / or receiving in the above method (for example, step S2102, step S2104, but not limited to this), and the processor 8201 executes at least one of the other steps (for example, step S2101, but not limited to this).

[0457] In some embodiments, terms such as interface circuit, interface, transceiver pin, and transceiver may be used interchangeably.

[0458] In some embodiments, the chip 8200 further includes one or more memories 8202 for storing instructions. Alternatively, all or part of the memory 8202 may be located outside the chip 8200.

[0459] The embodiments of the present disclosure further provide a storage medium having instructions stored thereon. When the instructions are executed on the communication device 8100, the communication device 8100 executes any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto and may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but is not limited thereto and may also be a temporary storage medium.

[0460] The present disclosure also provides a program product, which, when executed by the communication device 8100, enables the communication device 8100 to perform any of the above methods. Optionally, the program product may be a computer program product.

[0461] The embodiments of the present disclosure also provide a computer program, which, when executed on a computer, enables the computer to execute any one of the above methods.

Claims

1. A policy control method, characterized in that, Performed by an access network device, the method includes: Obtain a user plane (UP) security policy; Perform security protection on first UP data according to the UP security policy, where the first UP data is UP data locally transmitted by a terminal device through the access network device.

2. The method according to claim 1, characterized in that The terminal device includes a first terminal device and / or a second terminal device, and the UP security policy includes at least one of the following: a first UP security policy, a second UP security policy. The first UP security policy is the UP security policy corresponding to the first terminal device, and the second UP security policy is the UP security policy corresponding to the second terminal device. The first terminal device and the second terminal device perform local transmission of UP data through the access network device.

3. The method according to claim 2, wherein The obtaining of the UP security policy includes at least one of the following: During the registration process of the first terminal device, receive the first UP security policy sent by a first unified data management (UDM) through a first access and mobility management function (AMF); During the registration process of the second terminal device, receive the second UP security policy sent by a second UDM through a second AMF.

4. The method according to claim 2, characterized in that The obtaining of the UP security policy includes at least one of the following: During the service authorization and information configuration process of the first terminal device, receive the first UP security policy sent by a first policy and charging function (PCF) through a first AMF; During the service authorization and information configuration process of the second terminal device, receive the second UP security policy sent by a second PCF through a second AMF.

5. The method according to any one of claims 2 to 4, characterized in that, The first UP data includes at least one of the following: second UP data, third UP data. The second UP data is the UP data protected by the first UP security policy, and the third UP data is the UP data protected by the second UP security policy.

6. The method according to claim 5, characterized in that, The performing of security protection on the first UP data according to the UP security policy includes: Receive a first protocol data unit (PDU) session establishment request sent by the first terminal device; Activate security protection for the second UP data according to the first UP security policy.

7. The method according to claim 5 or 6, characterized in that, The performing of security protection on the first UP data according to the UP security policy includes: Receive a second PDU session establishment request sent by the second terminal device; Activate security protection for the third UP data according to the second UP security policy.

8. The method according to claim 1, wherein The first UP security policy includes a third UP security policy, and the third UP security policy is used to perform security protection on UP data locally transmitted by the access network device.

9. The method according to claim 8, characterized in that The obtaining of the UP security policy includes: Obtain first configuration information, where the first configuration information is used to indicate the third UP security policy.

10. The method according to claim 9, wherein The performing of security protection on the first UP data according to the UP security policy includes: Activate security protection for the first UP data corresponding to the third UP security policy according to the first configuration information.

11. The method according to any one of claims 1 to 10, characterized in that, The UP security policy is used to indicate any one of the following: Activate security protection for the first UP data; Do not activate security protection for the first UP data; The first indication information, which is used to instruct the access network device to determine whether to activate the security protection for the first UP data.

12. The method according to any one of claims 1-11, characterized in that, The security protection includes at least one of the following: integrity protection, confidentiality protection.

13. A policy control method, characterized in that, Executed by the Unified Data Management (UDM), the method includes: During the registration process of the terminal device, the User Plane (UP) security policy is sent to the access network device through the Access and Mobility Management Function (AMF). The UP security policy is used for the access network device to perform security protection on the first UP data, and the first UP data is the UP data locally transmitted by the terminal device through the access network device.

14. The method according to claim 13, characterized in that The sending of the UP security policy to the access network device through the AMF includes: Determining to send the UP security policy according to the subscription information of the terminal device; Sending the UP security policy to the access network device through the AMF.

15. The method according to claim 14, wherein The determining to send the UP security policy according to the subscription information of the terminal device includes: Determining that the terminal device subscribes to local transmission of UP data according to the subscription information of the terminal device; Determining to send the UP security policy.

16. The method according to any one of claims 13-15, characterized in that The terminal device includes a first terminal device and / or a second terminal device. The UP security policy includes at least one of the following: a first UP security policy, a second UP security policy. The first UP security policy is the UP security policy corresponding to the first terminal device, and the second UP security policy is the UP security policy corresponding to the second terminal device. The first terminal device and the second terminal device perform local transmission of UP data through the access network device.

17. The method according to claim 16, characterized in that, The UDM includes at least one of the following: a first UDM, a second UDM. The first UDM is used to send the first UP security policy to the access network device through the first AMF during the registration process of the first terminal device, and the second UDM is used to send the second UP security policy to the access network device through the second AMF during the registration process of the second terminal device.

18. The method according to any one of claims 13-17, characterized in that, The UP security policy is used to indicate any one of the following: Activating the security protection for the first UP data; Not activating the security protection for the first UP data; The first indication information, which is used to instruct the access network device to determine whether to activate the security protection for the first UP data.

19. The method according to any one of claims 13 - 18, characterized in that The security protection includes at least one of the following: integrity protection, confidentiality protection.

20. A policy control method, characterized in that, Executed by the Policy and Charging Function (PCF), the method includes: During the service authorization and information configuration process of the terminal device, the User Plane (UP) security policy is sent to the access network device through the Access and Mobility Management Function (AMF). The UP security policy is used for the access network device to perform security protection on the first UP data, and the first UP data is the UP data locally transmitted by the terminal device through the access network device.

21. The method according to claim 20, wherein The terminal device includes a first terminal device and / or a second terminal device. The UP security policy includes at least one of the following: a first UP security policy and a second UP security policy. The first UP security policy is the UP security policy corresponding to the first terminal device, and the second UP security policy is the UP security policy corresponding to the second terminal device. The first terminal device and the second terminal device perform local UP data transmission through the access network device.

22. The method according to claim 21, wherein The PCF includes at least one of the following: a first PCF and a second PCF. The first PCF is used to send the first UP security policy to the access network device through the first AMF during the service authorization and information configuration process of the first terminal device. The second PCF is used to send the second UP security policy to the access network device through the second AMF during the service authorization and information configuration process of the second terminal device.

23. The method according to any one of claims 20 - 22, characterized in that, The method further includes: Determining the UP security policy corresponding to the terminal device from the unified data repository UDR.

24. The method according to any one of claims 20-23, characterized in that, The UP security policy is used to indicate any one of the following: Activating security protection for the first UP data; Not activating security protection for the first UP data; A first indication message, which is used to indicate whether the access network device determines to activate security protection for the first UP data.

25. The method according to any one of claims 20 - 24, characterized in that, The security protection includes at least one of the following: integrity protection and confidentiality protection.

26. An access network device, characterized in that, It includes: A transceiver module, configured to obtain a user plane (UP) security policy; A processing module, configured to perform security protection on first UP data according to the UP security policy. The first UP data is the UP data locally transmitted by the terminal device through the access network device.

27. A unified data management UDM, characterized in that, It includes: A transceiver module, configured to send a user plane (UP) security policy to the access network device through an access and mobility management function (AMF) during the registration process of the terminal device. The UP security policy is used for the access network device to perform security protection on first UP data. The first UP data is the UP data locally transmitted by the terminal device through the access network device.

28. A Policy and Charging Function PCF, characterized in that, It includes: A transceiver module, configured to send a user plane (UP) security policy to the access network device through an access and mobility management function (AMF) during the service authorization and information configuration process of the terminal device. The UP security policy is used for the access network device to perform security protection on first UP data. The first UP data is the UP data locally transmitted by the terminal device through the access network device.

29. A communication device, characterized in that, It is characterized by including: One or more processors; Wherein, the communication device is used to execute the policy control method described in any one of claims 1 to 12 or claims 13 to 19 or claims 20 to 25.

30. A communication system, characterized in that, The communication system includes an access network device, a unified data management UDM, and a policy and charging function PCF. Among them, the access network device is configured to implement the policy control method described in any one of claims 1 to 12, the UDM is configured to implement the policy control method described in any one of claims 13 to 19, and the PCF is configured to implement the policy control method described in any one of claims 20 to 25.

31. A storage medium, the storage medium stores instructions, characterized in that, When the instruction runs on the communication device, the communication device is caused to execute the policy control method described in any one of claims 1 to 12 or claims 13 to 19 or claims 20 to 25.

Citation Information

Patent Citations

  • Security policy processing method and communication device

    CN115396879A

  • Communication method and device

    CN115706998A

  • Communication method, device and equipment

    CN115843438A

  • Method and apparatus for handling security policies in v2x communication system

    US20210258793A1