Secure communication method and apparatus, and communication system
By activating or closing integrity security protection in the communication system according to the session establishment process, the risk of DoS attack when the communication link is disconnected is solved, and the security and reliability guarantee of data transmission is achieved.
Patent Information
- Application Number
- PCT/CN2025/073066
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-19
- Filing Date
- 2025-01-17
- Publication Date
- 2025-07-24
AI Technical Summary
In communication systems, especially in 5G or satellite communication systems, when the communication link between the terminal device and the base station and the communication link between the base station and the core network are not in a connected state at the same time, there is a risk of a denied service (DoS) attack on the base station, resulting in the inability to guarantee network security.
During the session establishment process of the terminal device, the network device determines whether to activate the integrity security protection of the session based on the first information, and sends the integrity security protection instructions to the terminal device to indicate the activation result to maximize the integrity security protection of the session, ensuring that only user plane data that has passed the integrity verification is stored when the communication link is disconnected.
It effectively alleviates the potential risk of denial of service DoS attacks, ensures network communication security, and ensures the integrity and reliability of data transmission.
Smart Images

Figure CN2025073066_24072025_PF_FP_ABST
Abstract
Description
A secure communication method, device and communication system
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on January 19, 2024, with application number 202410083047.2, and invention name “A secure communication method, device and communication system”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communications, and more particularly, to a secure communication method, device, and communication system. Background Art
[0003] In a communication system, such as a fifth-generation (5G) communication system or a satellite communication system, a terminal device can communicate with a base station through a new radio (NR), and the base station can communicate with the core network through a ground gateway.
[0004] The uplink and downlink messages between the terminal device and the core network can be transmitted through the base station and the ground gateway station. At certain moments, the communication link between the terminal device and the base station, and the communication link between the base station and the core network may not be in a connected state at the same time. For example, when the communication link between the terminal device and the base station is in a connected state, and the communication link between the base station and the core network is in a disconnected state, the base station can perform a store and forward operation to store the uplink message from the terminal device, and after the communication link between the base station and the core network is restored, the stored uplink message is sent to the core network. In this case, if an attacker sends a large amount of malicious data or messages to the base station, network security may not be guaranteed, and there is a risk of denial of service (DoS) attacks on the base station. Therefore, additional measures are urgently needed to respond to reduce potential security risks. Summary of the Invention
[0005] The present application provides a secure communication method, device, and communication system that can reduce potential security risks and improve network communication security.
[0006] In the first aspect, a secure communication method is provided. The method is applied to the network device side. For example, the method can be executed by the network device, or it can also be executed by a chip or circuit in the network device, or it can also be executed by a functional module in the network device that can call and execute a program, or it can also be executed by a centralized unit (CU) or a distributed unit (DU) in the network device. This application is not limited to this. For ease of description, the following is an example of execution by a network device (such as a base station).
[0007] The method includes: during the session establishment process of the terminal device, the network device determines whether to activate the integrity security protection of the session based on first information, the first information is used to indicate whether the network device supports store-and-forward operations, and the session is used to transmit data between the terminal device and the core network; the network device sends first integrity security protection indication information to the terminal device, and the first integrity security protection indication information is used to indicate the activation result.
[0008] Exemplarily, the activation result is used to indicate whether to activate integrity security protection for the session, or in other words, the activation result is used to indicate whether to activate integrity security protection for one or more data radio bearers (DRBs) corresponding to the session. For example, the activation result includes activating integrity security protection for the session or not activating integrity security protection for the session.
[0009] Exemplarily, the first information may also be used to indicate whether the network device is configured to enable a store-and-forward operation, and / or the first information may also be used to indicate whether the network device is deployed on a satellite.
[0010] It should be understood that the deployment of network equipment on a satellite can be understood as the physical deployment of the network equipment (e.g., a base station) on the satellite, or the network equipment (e.g., a base station) and the satellite being co-located. In this case, the satellite has the capabilities of the network equipment, for example, the satellite supports store-and-forward operations of the network equipment.
[0011] According to the solution provided in the present application, taking the first information into consideration, the integrity security protection of the session is turned on or activated to the maximum extent possible, so that the data subsequently received by the network device is protected by integrity security as much as possible. This is convenient for the scenario where the communication link (such as the feeder link) between the network device and the core network is disconnected. The network device only stores the user plane data that has passed the integrity check, thereby alleviating the potential risk of denial of service DoS attacks and ensuring the security of network communications.
[0012] In some implementations, the network device determines whether to activate integrity security protection for the session based on first information, including: when the first information indicates that the network device supports store-and-forward operations, the network device determines to activate integrity security protection for the session; and / or when the first information indicates that the network device does not support store-and-forward operations, the network device determines not to activate integrity security protection for the session.
[0013] That is to say, when the network device supports store-and-forward operations, the network device activates the integrity security protection of the session; when the network device does not support store-and-forward operations, the network device does not activate the integrity security protection of the session, or may activate or not activate the integrity security protection of the session according to the user plane integrity security policy.
[0014] In some implementations, before a network device determines whether to activate integrity security protection for a session based on first information, the process includes: the network device obtains a user plane integrity security policy corresponding to the session, where the user plane integrity security policy is used to indicate whether integrity security protection is activated for the session; the network device determines whether to activate integrity security protection for the session based on the first information, including: the network device determines whether to activate integrity security protection for the session based on the first information and the user plane integrity security policy.
[0015] Based on the above scheme, the network device determines whether to activate the integrity security protection of the session based on the first information. In addition, the user plane integrity security policy can be considered to enable or activate the integrity security protection of the session as much as possible, so that the user plane data received by the network device is protected by integrity security to the greatest extent. In the scenario where the feeder link is disconnected, only the user plane data that has passed the integrity check is stored, which not only alleviates the potential risk of denial of service DoS attacks, but also ensures the security of network communications.
[0016] In certain implementations, the network device determines whether to activate integrity security protection for the session based on the first information and the user plane integrity security policy, including: when the first information indicates that the network device does not support store-and-forward operations and the user plane integrity security policy indicates that the session is activated or integrity security protection is optionally activated, the network device determines to activate integrity security protection for the session; and / or when the first information indicates that the network device does not support store-and-forward operations and the user plane integrity security policy indicates that integrity security protection is not activated for the session, the network device determines not to activate integrity security protection for the session.
[0017] Based on the above solution, when the network device does not support store-and-forward operations, the network device determines whether to activate the integrity security protection of the session. It can be based on the user plane integrity security policy, or it can be based on whether the network device supports store-and-forward operations. The integrity security protection of the session is turned on or activated to the maximum extent, so that the user plane data received by the network device is protected by integrity security to the greatest extent. In the scenario where the feeder link is disconnected, only the user plane data that has passed the integrity check is stored, which not only alleviates the potential risk of denial of service DoS attacks, but also ensures the security of network communications.
[0018] In certain implementations, the network device determines whether to activate integrity security protection for the session based on the first information and the user plane integrity security policy, including: when the first information indicates that the network device supports store-and-forward operations and the user plane integrity security policy indicates that the session is activated or integrity security protection is optionally activated, the network device determines to activate integrity security protection for the session; and / or, when the first information indicates that the network device supports store-and-forward operations and the user plane integrity security policy indicates that integrity security protection is not activated for the session, the network device determines to activate integrity security protection for the session.
[0019] Based on the above solution, when the network device supports store-and-forward operations, regardless of whether the user plane integrity security policy indicates that the session is active, optionally activated, or not activated, the network device determines to activate integrity security protection for the session. That is, the network device determines whether to activate integrity security protection for the session based on the first information, enabling or activating integrity security protection for the session to the greatest extent possible. This ensures that user plane data received by the network device undergoes integrity security protection to the greatest extent possible. This facilitates the storage of only user plane data that passes integrity verification in the event of a feeder link disconnection, mitigating potential denial-of-service (DoS) attack risks while also ensuring network communication security.
[0020] In a second aspect, a secure communication method is provided. The method is applied to a terminal device. For example, the method can be executed by the terminal device, or by a chip or circuit in the terminal device, or by a functional module in the terminal device that can call and execute a program. This application does not limit this. For ease of description, the following is an example of execution by a terminal device (e.g., user equipment (UE)).
[0021] The method includes: during the session establishment process of the terminal device, the terminal device receives first integrity security protection indication information from the network device, the first integrity security protection indication information is used to indicate whether to activate the integrity security protection of the session, the first integrity security protection indication information is determined based on the first information, and the first information is used to indicate whether the network device supports store-and-forward operations; the terminal device performs an integrity check on the first integrity security protection indication information, and the session is used to transmit data between the terminal device and the core network; if the integrity check passes, the terminal device determines whether to activate the integrity security protection of the session based on the first integrity security protection indication information.
[0022] Optionally, before the terminal device determines whether to activate integrity security protection for the session based on the first integrity security protection indication information, the method further includes: the terminal device performing an integrity check on the first integrity security protection indication information. Further, if the integrity check passes, the terminal device determines whether to activate integrity security protection for the session based on the first integrity security protection indication information.
[0023] Optionally, the first integrity security protection indication information is used to indicate whether to activate the integrity security protection of the session, which can be understood as: the first integrity security protection indication information is used to indicate the activation result, and the activation result is used to indicate whether to activate the integrity security protection of the session.
[0024] In some implementations, when the first information indicates that the network device supports store-and-forward operations, the first integrity security protection indication information is used to indicate that integrity security protection of the session is activated; and / or, when the first information indicates that the network device does not support store-and-forward operations, the first integrity security protection indication information is used to indicate that integrity security protection of the session is not activated.
[0025] In some implementations, the first integrity security protection indication information is determined according to the first information and a user plane integrity security policy, wherein the user plane integrity security policy is used to indicate whether integrity security protection is activated for the session.
[0026] In some implementations, when the first information indicates that the network device does not support store-and-forward operations and the user plane integrity security policy indicates session activation or optional activation of integrity security protection, the first integrity security protection indication information is used to indicate activation of integrity security protection for the session; and / or, when the first information indicates that the network device does not support store-and-forward operations and the user plane integrity security policy indicates inactivation of integrity security protection for the session, the first integrity security protection indication information is used to indicate inactivation of integrity security protection for the session.
[0027] In some implementations, when the first information indicates that the network device supports store-and-forward operations and the user plane integrity security policy indicates session activation or optional activation of integrity security protection, the first integrity security protection indication information is used to indicate the activation of integrity security protection for the session; and / or, when the first information indicates that the network device supports store-and-forward operations and the user plane integrity security policy indicates that integrity security protection is not activated for the session, the first integrity security protection indication information is used to indicate the activation of integrity security protection for the session.
[0028] The beneficial effects of the above-mentioned second aspect and certain implementation methods can be referred to the corresponding description of the first aspect, and will not be repeated here.
[0029] In a third aspect, a secure communication method is provided. The method is applied to the network device side. For example, the method can be executed by the network device, or it can also be executed by a chip or circuit in the network device, or it can also be executed by a functional module in the network device that can call and execute a program, or it can also be executed by a CU or DU in the network device. This application is not limited to this. For ease of description, the following is an example of execution by a network device (such as a base station).
[0030] The method includes: during the session establishment process of the terminal device, the network device obtains the user plane integrity security policy corresponding to the session, the user plane integrity security policy is used to indicate whether the session activates integrity security protection, and the session is used to transmit data between the terminal device and the core network; the network device determines the first integrity security protection indication information according to the user plane integrity security policy, the first integrity security protection indication information is used to indicate whether to activate the integrity security protection of the first DRB, the session corresponds to the first DRB, and the first DRB is used to carry data between the terminal device and the network device; the integrity security protection of the first DRB is activated or not according to the first integrity security protection indication information; in the case of a first link disconnection, the network device determines whether to release the first DRB according to whether the integrity security protection of the first DRB is activated, or the network device determines whether to modify the integrity security protection status of the first DRB according to whether the integrity security protection of the first DRB is activated, and the first link is the link between the network device and the core network; the network device sends a first message to the terminal device, and the first message is used to indicate the release result or modification result of the first DRB.
[0031] Exemplarily, in a satellite communication scenario, the first link may be a feeder link.
[0032] Optionally, when the first link is disconnected, the network device may also determine whether to release the first DRB based on the first integrity security protection indication information, or the network device may determine whether to modify the integrity security protection status of the first DRB based on the first integrity security protection indication information.
[0033] According to the solution provided in the present application, the network device determines whether to release the first DRB based on the user plane integrity security policy, or modifies the integrity security protection state of the first DRB to an activated state, so that the user plane data subsequently received by the network device are all protected by integrity security. In the scenario where the feeder link is disconnected, the satellite base station only stores the user plane data that has passed the integrity check, which can alleviate potential DoS risks and ensure network communication security.
[0034] In some implementations, the network device determines whether to release the first DRB based on whether the integrity security protection of the first DRB is activated, including: if the integrity security protection of the first DRB is not activated, the network device determines to release the first DRB.
[0035] In some implementations, the network device determines whether to modify the integrity security protection state of the first DRB based on whether the integrity security protection of the first DRB is activated, including: when the integrity security protection of the first DRB is not activated, the network device determines to modify the integrity security protection state of the first DRB to an activated state.
[0036] In some implementations, the method also includes: when the first link restores connection, the network device sends a second message to the terminal device, the second message is used to instruct the terminal device to establish a second DRB, the second message includes second integrity security protection indication information, the second integrity security protection indication information is used to instruct the second DRB not to activate integrity security protection, and the second DRB is used to carry data between the terminal device and the network device.
[0037] In some implementations, the second DRB is the first DRB. Before sending the second message to the terminal device, and / or after sending the first message to the terminal device, the method further includes: the network device stores the identifier of the first DRB; and / or the network device records that the integrity security protection status of the first DRB before modification is in an inactivated state; wherein the second message includes the identifier of the first DRB, and / or the second integrity security protection indication information carried in the second message is determined based on the integrity security protection status of the first DRB before modification being in an inactivated state.
[0038] Optionally, the second DRB can be a DRB re-established between the terminal device and the network device, or it can be the first DRB determined based on the identifier of the first DRB. In addition, the present application does not limit the storage of the identifier of the first DRB; and / or the timing when the network device records that the integrity security protection state of the first DRB before modification is in an inactive state. This implementation method is to facilitate normal communication between subsequent terminal devices and network devices.
[0039] That is to say, the network device can determine not to activate or enable the integrity security protection of the second DRB based on the record that the integrity security protection state of the first DRB before modification is in an inactive state. Optionally, the network device can also determine not to activate or enable the integrity security protection of the second DRB based on the user plane integrity security policy of the session, which is not limited in this application.
[0040] Based on this implementation method, after releasing the first DRB or modifying the integrity security protection state of the first DRB to an activated state, by recording the identifier of the first DRB, and / or recording the integrity security protection state of the first DRB before modification as an inactivated state, it is convenient to re-establish the first DRB (i.e., an example of the second DRB) based on the recorded first DRB identifier after the subsequent first link is restored.
[0041] In some implementations, the method also includes: the network device receives first data from the terminal device through the first DRB; when the first integrity security protection indication information indicates activation of the integrity security protection of the first DRB, the network device performs an integrity check on the first data; if the integrity check passes and the first link is disconnected, the network device stores the first data; or, if the integrity check fails, the network device does not store the first data, or the network device discards the first data.
[0042] In some implementations, before storing the first data, the method further includes: if the integrity check passes, determining whether the first link is disconnected.
[0043] In some implementations, before performing integrity checking on the first data, the method further includes: determining whether the first link is disconnected.
[0044] That is to say, the present application does not limit the execution order of determining whether the first link is disconnected and determining whether the integrity check of the first data needs to be performed. For example, the network device can determine whether the first link is disconnected by determining whether the communication between the network device and the core network is normal. For example, the network device flies to the side away from the ground gateway station, such as the ground gateway station cannot receive the signal transmitted by the network device; or the communication conditions between the network device and the core network deteriorate, such as encountering bad weather, or the signal quality is lower than a certain threshold;
[0045] In some implementations, the method also includes: the network device receives first data from the terminal device through the first DRB; when the first integrity security protection indication information indicates that the first DRB does not activate integrity security protection and the first link is disconnected, the network device does not perform integrity verification on the first data, or the network device discards the first data.
[0046] The beneficial effects of the third aspect and certain implementation methods mentioned above can be referred to the relevant description of the first aspect, and will not be repeated here.
[0047] In a fourth aspect, a secure communication method is provided. The method is applied to the terminal device side. For example, the method can be executed by the terminal device, or it can also be executed by a chip or circuit in the terminal device, or it can also be executed by a functional module in the terminal device that can call and execute a program. This application is not limited to this. For ease of description, the following is an example of execution by a terminal device (such as a UE).
[0048] The method includes: when the first link is disconnected, the terminal device receives a first message from the network device, the first message is used to indicate the release result or modification result of the first DRB, the release result is used to indicate whether to activate the first DRB, and the modification result is used to indicate whether to modify the integrity security protection status of the first DRB. The release result or the modification result is determined based on whether the integrity security protection of the first DRB is activated. The first DRB is used to carry data between the terminal device and the network device, and the first link is a link between the network device and the core network; the terminal device determines whether to release the first DRB based on the release result, or the terminal device determines whether to modify the integrity security protection status of the first DRB based on the modification result.
[0049] Exemplarily, whether the integrity security protection of the first DRB is activated is determined according to the user plane integrity security policy.
[0050] Optionally, before the terminal device determines whether to release the first DRB based on the release result, or before the terminal device determines whether to modify the integrity security protection state of the first DRB based on the modification result, the method further includes: the terminal device performs an integrity check on the first message. Furthermore, if the integrity check passes, the terminal device determines whether to release the first DRB based on the release result, or before the terminal device determines whether to modify the integrity security protection state of the first DRB based on the modification result.
[0051] In some implementations, when the first integrity security protection indication information indicates that integrity security protection is not activated for the first DRB, the release result indicates that the first DRB is released.
[0052] In some implementations, when the first integrity security protection indication information indicates that integrity security protection is not activated for the first DRB, the modification result indicates that the integrity security protection state of the first DRB is modified to an activated state.
[0053] In some implementations, the method also includes: when the first link restores connection, the terminal device receives a second message from the network device, the second message is used to indicate the establishment of a second DRB, the second message includes second integrity security protection indication information, the second integrity security protection indication information is used to indicate that the second DRB does not activate integrity security protection, the second DRB is used to carry data between the terminal device and the network device, and the first link is the link between the network device and the core network.
[0054] The beneficial effects of the fourth aspect and certain implementation methods mentioned above can be referred to the relevant description of the first aspect and will not be repeated here.
[0055] In a fifth aspect, a secure communication method is provided. This method can be executed by a session management network element, or by a chip or circuit within the session management network element, or by a functional module within the session management network element capable of calling and executing programs. This application is not limited to this. For ease of description, the following description uses execution by a session management network element as an example.
[0056] The method includes: during the session establishment process of the terminal device, the session management network element obtains indication information, the indication information is used to instruct the network device to be deployed on the satellite; the session management network element determines the user plane integrity security policy corresponding to the session based on the indication information, the user plane integrity security policy is used to instruct the session to activate or optionally activate integrity security protection; the session management network element sends the user plane integrity security policy to the network device.
[0057] In some implementations, the indication information is further used to indicate that the network device supports a store-and-forward operation.
[0058] In some implementations, the method also includes: the session management network element obtains contract information, and the contract information is used to indicate whether the terminal device has signed a contract for the store-and-forward operation service; the session management network element determines the user plane integrity security policy based on the indication information, including: the session management network element determines the user plane integrity security policy based on the indication information and the contract information.
[0059] Optionally, the session management network element determines a user plane integrity security policy according to the subscription information.
[0060] In some implementations, the session management network element determines a user plane integrity security policy based on the indication information and the contract information, including: when the contract information indicates that the terminal device has subscribed to the store-and-forward operation service, the session management network element determines the integrity security policy to indicate that the session activates integrity security protection.
[0061] The beneficial effects of the above-mentioned fifth aspect and certain implementation methods can be referred to the corresponding description of the first aspect and will not be repeated here.
[0062] In a sixth aspect, a communication device, such as a network device, is provided. The communication device includes: a processing unit configured to determine, during a session establishment process of a terminal device, whether to activate integrity security protection for the session based on first information, the first information being used to indicate whether the network device supports a store-and-forward operation; and a transceiver unit configured to send first integrity security protection indication information to the terminal device, the first integrity security protection indication information being used to indicate an activation result.
[0063] The transceiver unit can perform the reception and transmission processing in the aforementioned first aspect, and the processing unit can perform other processing except reception and transmission in the aforementioned first aspect.
[0064] In a seventh aspect, a communication device, such as a terminal device, is provided. The communication device includes: a transceiver unit configured to receive first integrity security protection indication information from a network device during a session establishment process of the terminal device, the first integrity security protection indication information being used to indicate whether integrity security protection for the session is activated, the first integrity security protection indication information being determined based on first information, the first information being used to indicate whether the network device supports a store-and-forward operation; a processing unit configured to perform an integrity check on the first integrity security protection indication information; and the processing unit further configured to determine, if the integrity check passes, whether to activate integrity security protection for the session based on the first integrity security protection indication information.
[0065] The transceiver unit can perform the reception and transmission processing in the aforementioned second aspect, and the processing unit can perform other processing except reception and transmission in the aforementioned second aspect.
[0066] In an eighth aspect, a communication device is provided, such as a network device. The communication device includes: a transceiver unit, configured to obtain a user plane integrity security policy corresponding to a session during a session establishment process of a terminal device, the user plane integrity security policy being used to indicate whether integrity security protection is activated for the session; a processing unit, configured to determine first integrity security protection indication information according to the user plane integrity security policy, the first integrity security protection indication information being used to indicate whether integrity security protection of a first DRB is activated, and the session corresponds to a first data radio bearer DRB; the processing unit is further configured to determine whether to release the first DRB according to whether the integrity security protection of the first DRB is activated, or to determine whether to modify the integrity security protection state of the first DRB according to whether the integrity security protection of the first DRB is activated, when a first link is disconnected, and the first link is a link between the network device and the core network; the transceiver unit is further configured to send a first message to the terminal device, the first message being used to indicate a release result or a modification result of the first DRB.
[0067] The transceiver unit can perform the receiving and sending processing in the aforementioned third aspect, and the processing unit can perform other processing except receiving and sending in the aforementioned third aspect.
[0068] In a ninth aspect, a communication device, such as a terminal device, is provided. The communication device includes: a transceiver unit, configured to receive a first message from a network device when a first link is disconnected, the first message being used to indicate a release result or a modification result of a first DRB, the first DRB being used to carry data between the terminal device and the network device, the release result being used to indicate whether to activate the first DRB, the modification result being used to indicate whether to modify the integrity security protection state of the first DRB, the release result or the modification result being determined based on whether the integrity security protection of the first DRB is activated; a processing unit, configured to perform an integrity check on the first message; and the processing unit, further configured to determine whether to release the first DRB based on the release result, or to determine whether to modify the integrity security protection state of the first DRB based on the modification result, if the integrity check passes.
[0069] Exemplarily, whether the integrity security protection of the first DRB is activated is determined according to the user plane integrity security policy.
[0070] The transceiver unit can perform the receiving and sending processing in the aforementioned fourth aspect, and the processing unit can perform other processing except receiving and sending in the aforementioned fourth aspect.
[0071] In a tenth aspect, a communication device, such as a session management network element, is provided. The communication device includes: a transceiver unit configured to receive indication information during a session establishment process of a terminal device, the indication information being used to instruct a network device to be deployed on a satellite; a processing unit configured to determine a user plane integrity security policy based on the indication information, the user plane integrity security policy being used to indicate session activation or optional activation of integrity security protection; and the transceiver unit further configured to send the user plane integrity security policy to the network device.
[0072] The transceiver unit can perform the reception and transmission processing in the aforementioned fifth aspect, and the processing unit can perform other processing except reception and transmission in the aforementioned fifth aspect.
[0073] In an eleventh aspect, a communication device is provided. The communication device includes a transceiver, a processor, and a memory, wherein the processor is configured to control the transceiver to transmit and receive signals, the memory is configured to store a computer program, and the processor is configured to retrieve and execute the computer program from the memory, so that the communication device performs the method of any possible implementation of the first to fifth aspects.
[0074] Optionally, there are one or more processors and one or more memories.
[0075] Optionally, the memory may be integrated with the processor, or the memory may be provided separately from the processor.
[0076] Optionally, the communication device further includes a transmitter (transmitter) and a receiver (receiver).
[0077] In a twelfth aspect, a communication system is provided. The communication system includes a network device and a session management network element, wherein the network device is configured to perform the method of the first aspect or the third aspect and any possible implementation thereof, and the session management network element is configured to perform the method of any possible implementation of the fifth aspect.
[0078] Optionally, the communication system further includes a terminal device, wherein the terminal device is used to execute the method in the above-mentioned second aspect or fourth aspect and any possible implementation manner thereof.
[0079] In a thirteenth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer program code instructions, and when the computer program code or instructions are executed, the method in any possible implementation of the first to fifth aspects is executed.
[0080] In a fourteenth aspect, a chip is provided. The chip includes at least one processor coupled to a memory, the memory being configured to store a computer program, and the processor being configured to retrieve and execute the computer program from the memory, so that a communication device equipped with the chip system performs the method of any possible implementation of the first to fifth aspects above.
[0081] The chip may include an input circuit or interface for sending information or data, and an output circuit or interface for receiving information or data.
[0082] In a fifteenth aspect, a computer program product is provided, comprising: computer program code, which, when executed, causes the method in any possible implementation of the first to fifth aspects to be executed.
[0083] In a sixteenth aspect, a computer program is provided, which, when executed, causes the method in any possible implementation of the first to fifth aspects to be executed.
[0084] Among them, the technical effects of the technical solutions of aspects 6 to 16 can refer to the description of the corresponding technical effects of aspects 1 to 5, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0085] FIG1 is a schematic diagram of a communication system applicable to an embodiment of the present application;
[0086] FIG2 is a schematic diagram of another communication system applicable to an embodiment of the present application;
[0087] FIG3 is a schematic flow chart of a method for establishing a session of a terminal device;
[0088] FIG4 is a schematic flow chart of a communication method provided in an embodiment of the present application;
[0089] FIG5 is a schematic flow chart of another communication method provided in an embodiment of the present application;
[0090] FIG6 is a schematic flow chart of another communication method provided in an embodiment of the present application;
[0091] FIG7 is a schematic flow chart of another communication method provided in an embodiment of the present application;
[0092] FIG8 is a schematic flow chart of another communication method provided in an embodiment of the present application;
[0093] FIG9 is a schematic flow chart of another communication method provided in an embodiment of the present application;
[0094] FIG10 is a schematic block diagram of a communication device provided in an embodiment of the present application;
[0095] FIG11 is a schematic block diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0096] The technical solution in this application will be described below with reference to the accompanying drawings.
[0097] The technical solution of the present application can be applied to non-terrestrial network (NTN) systems such as satellite communication systems and high altitude platform station (HAPS) communications, for example, integrated communication and navigation (ICaN) systems, global navigation satellite systems (GNSS), etc.
[0098] Satellite communication systems can be integrated with traditional mobile communication systems. Among them, the mobile communication system can be a 5G or NR system, a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD) system, a universal mobile telecommunication system (UMTS), etc. The technical solution provided in this application can also be applied to future communication systems, such as the sixth generation (6G) mobile communication system. The technical solution provided in this application can also be applied to device to device (D2D) communication, vehicle-to-everything (V2X) communication, machine to machine (M2M) communication, machine type communication (MTC), Internet of Things (IoT) communication system, non-terrestrial network (NTN) communication system or other communication systems.
[0099] Figure 1 is a schematic diagram of a communication system applicable to an embodiment of the present application. As shown in Figure 1 , the architecture 100 may include a terminal device 110, a network device 120, a core network (CN) 130, and an external network 140.
[0100] (1) The terminal device 110 may be referred to as a user equipment (UE). The terminal device 110 in this application is a device with wireless transceiver functions, which can communicate with one or more CNs 130 via the network device 120. The terminal device 110 may also be referred to as an access terminal, terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, user agent, or user device, etc. The terminal device 110 may be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; it may also be deployed on the water (e.g., a ship, etc.); it may also be deployed in the air (e.g., an airplane, a balloon, and a satellite, etc.). The terminal device 110 may be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a smart phone, a mobile phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), etc. Alternatively, the terminal device 110 may be a handheld device with wireless communication capabilities, a computing device, or other device connected to a wireless modem, an in-vehicle device, a wearable device, an unmanned aerial vehicle (UAV) device, or a terminal in the Internet of Things (IoT), the Internet of Vehicles (IoV), any terminal in a 5G network or future networks, a relay user device, or a terminal in a future evolving 6G network. The relay user device may be, for example, a 5G residential gateway (RG). For example, the terminal device 110 may be a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal in industrial control, a wireless terminal in unmanned driving, a wireless terminal in telemedicine, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, or a wireless terminal in a smart home. Alternatively, the terminal device 110 may be a logical entity, a smart device (such as a mobile phone), a smart terminal, or a communication device such as a server, gateway, base station, or controller, or an IoT device such as an IoT device, a sensor, an electricity meter, or a water meter. The embodiments of the present application do not limit the type or category of terminal devices.
[0101] In the embodiments of the present application, the device for implementing the function of the terminal device can be the terminal device, or it can be a device that can support the terminal device to implement the function, such as a chip system or chip, which can be installed in the terminal device. In the embodiments of the present application, the chip system can be composed of a chip, or it can include a chip and other discrete devices.
[0102] (2) The network device 120 can be any device with wireless transceiver functions for communicating with the terminal device. The network device can also be called an access network device or a wireless access network device, such as a base station. The network device in the embodiment of the present application can refer to a radio access network (RAN) node (or RAN device, or RAN entity) that connects the terminal device to the wireless network. (R)AN can be regarded as a subnetwork of the operator network, which is an implementation system between the service node in the operator network and the terminal device 110. For example, if the terminal device 110 wants to access the operator network, it first passes through the network device 120, and then can connect to the service node of the operator network through the network device 120. The above-mentioned RAN can be a cellular system related to the third generation partnership project (3GPP), such as a 5G mobile communication system, or a future-oriented evolution system (such as a 6G mobile communication system). RAN can also be an open radio access network (open RAN, O-RAN or ORAN), a cloud radio access network (CRAN), or a wireless fidelity (WiFi) system. RAN can also be a communication system that integrates two or more of the above systems. The network equipment 120 includes but is not limited to: the next generation node base station (gNB) in the 5G system, the evolved node B (eNB) in LTE, the radio network controller (RNC), the node B (NB), the base station controller (BSC), the base transceiver station (BTS), the home base station (for example, home evolved nodeB, or home nodeB, HNB), the base band unit (BBU), the transmission point (TRP), the transmitting point (TP), the small base station device (pico), the mobile switching center, or the network equipment in the future network. In systems using different wireless access technologies, the names of the devices with access network device functions may be different. For the convenience of description, in all embodiments of the present application, the above-mentioned devices that provide wireless communication functions for the terminal device 110 are collectively referred to as access network devices or simply referred to as RAN or AN.It should be understood that this document does not limit the specific type of access network equipment.
[0103] In some deployments, multiple RAN nodes collaborate to assist terminals in achieving wireless access, and different RAN nodes implement part of the functions of the base station. For example, the RAN node can be a CU, DU, central unit-control plane (CU-CP), central unit-user plane (CU-UP), or radio unit (RU). The CU and DU can be set separately, or they can also be included in the same network element, such as the BBU. The functions of the RU can be implemented by the radio frequency equipment of the base station. For example, the radio frequency equipment of the base station can be a remote radio unit (RRU), a pico remote radio unit (pRRU), an active antenna unit (AAU), or other units, modules or devices with radio frequency processing functions. The communication interface protocol between the BBU and the radio frequency equipment can be a common public radio interface (CPRI) interface protocol, an enhanced common public radio interface (eCPRI) interface protocol, or a fronthaul interface protocol between the DU and RU in the O-RAN system, etc., without limitation.
[0104] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application may be implemented by a software module, a hardware module, or a combination of a software module and a hardware module. For the convenience of description, this application takes CU, CU-CP, CU-UP, DU and RU as examples for description.
[0105] Network device 120 can be fixed or mobile. For example, a helicopter or drone can be configured to act as a mobile base station, and one or more cells can move based on the location of the mobile base station. In other examples, a helicopter or drone can be configured to act as a device that communicates with another base station.
[0106] In the embodiments of the present application, the device for implementing the functions of the access network device may be a network device, or a device capable of supporting the access network device in implementing the functions, such as a chip system or a chip, which may be installed in the access network device. In the embodiments of the present application, the chip system may be composed of a chip, or may include a chip and other discrete devices.
[0107] Network devices and terminal devices can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on the water surface; they can also be deployed on aircraft, balloons and satellites in the air. The embodiments of this application do not limit the scenarios in which network devices and terminal devices are located. In addition, terminal devices and network devices can be hardware devices, or they can be software functions running on dedicated hardware, software functions running on general-purpose hardware, such as virtualization functions instantiated on a platform (e.g., a cloud platform), or entities including dedicated or general-purpose hardware devices and software functions. This application does not limit the specific forms of terminal devices and network devices.
[0108] (3) The core network CN may include but is not limited to the following network functions (NF): user plane function (UPF), network exposure function (NEF), network function repository function (NRF), policy control function (PCF), unified data management function (UDM), unified data repository function (UDR), application function (AF), authentication server function (AUSF), access and mobility management function (AMF), and session management function (SMF).
[0109] The following is a brief description of the NF functions included in CN.
[0110] 1. The UPF is a gateway provided by the operator, serving as the gateway for communication between the operator network and the DN. It is primarily responsible for packet routing and transmission, packet detection, service usage reporting, Quality of Service (QoS) processing, lawful interception, uplink packet detection, and downlink packet storage. The UPF, also known as the user plane device, receives user data from the DN 240 and transmits it to the terminal device 110 via the network device 120. The UPF also receives user data from the terminal device 110 via the network device 120 and forwards it to the DN. The transmission resources and scheduling functions within the UPF that serve the terminal device 110 are managed and controlled by the SMF.
[0111] 2. NEF is a control plane function provided by operators. It primarily enables third parties to use network services. It supports network exposure, event and data analysis, provision of secure PLMN information from external applications, and conversion of information exchanged within and outside the PLMN. NEF, also known as network exposure equipment, can provide NNEF services.
[0112] 3. NRF is a control plane function provided by the operator, which can be used to maintain real-time information about network functions and services in the network. For example, it supports network service discovery, maintains the services supported by the NF profile of the NF instance, supports service discovery of the service communication proxy (SCP), maintains the SCP profile of the SCP instance, sends notifications about newly registered, deregistered, and updated NFs and SCPs, and maintains the health status of NF and SCP operations.
[0113] 4. PCF is a control plane function provided by the operator. It supports a unified policy framework to govern network behavior, provide policy rules to other control functions, and provide contract information related to policy decisions.
[0114] 5. UDM is a control plane function provided by the operator and is responsible for storing information such as the subscriber permanent identifier (SUPI), the generic public subscription identifier (GPSI), and credentials of subscribers in the operator's network. This information can be used to authenticate and authorize the terminal device 110 to access the operator's network. The SUPI is encrypted during transmission and is called a hidden subscriber subscription identifier (SUCI). UDM can also be referred to as a unified data management device, unified data management network element, data management device, or unified data management entity.
[0115] 6. The UDR is a control plane function provided by the operator. It provides storage and retrieval of subscription data for the UDM, storage and retrieval of policy data for the PCF, and storage and retrieval of user NF group ID information. The UDR can also be referred to as a user database device, user database entity, or user database network element. The user database primarily includes the following functions: storage and access of subscription data, policy data, application data, and other types of data.
[0116] 7. The AF is a control plane function provided by the operator. It interacts with other NFs in the PLMN to provide services such as providing roaming UEs with information on network selection, guiding data flow routing, and accessing NEFs. The AF can be deployed within the PLMN or outside the operator network.
[0117] 8. AUSF is a control plane function provided by the operator and is typically used for level 1 authentication, i.e., authentication between the terminal device 110 (subscriber) and the operator's network. After receiving an authentication request initiated by a subscriber, the AUSF may authenticate and / or authorize the subscriber using the authentication information and / or authorization information stored in the UDM, or generate authentication and / or authorization information for the subscriber through the UDM. The AUSF may feed back the authentication information and / or authorization information to the subscriber.
[0118] 9. The AMF is a control plane network function provided by the operator network. It is responsible for access control and mobility management of the terminal device 110 accessing the operator network, including, for example, mobility state management, allocation of temporary user identities, authentication and authorization of users, etc. For example, the AMF may also be referred to as an access and mobility management device, an access and mobility management function entity, an access and mobility management function network element, a mobility management device, a mobility management network element, a mobility management entity, etc., and may provide NAMF services.
[0119] 10. The SMF is a control plane network function provided by the operator network. It is responsible for managing the protocol data unit (PDU) session of the terminal device 110. The terminal device transmits PDUs to the DN through the PDU session. The SMF is responsible for establishing, maintaining, and deleting PDU sessions. The SMF includes session management (such as session establishment, modification, and release, including tunnel maintenance between the user plane function UPF and the network device 120), UPF selection and control, service and session continuity (SSC) mode selection, roaming, and other session-related functions. The SMF can also be called a session management device and can provide Nsmf services.
[0120] (4) External network 140 may be a data network (DN), also known as a packet data network (PDN), which is typically a network located outside the operator's network, such as a third-party network. In some implementations, the DN may also be deployed by the operator, i.e., the DN is part of a public land mobile network (PLMN). This application does not restrict whether the DN is part of a PLMN. A variety of services may be deployed on the DN, which may provide data and / or voice services to the terminal device 110.
[0121] It is understood that the above network elements or functions can be physical entities in hardware devices, software instances running on dedicated hardware, or virtualized functions instantiated on a shared platform (e.g., a cloud platform). Simply put, an NF can be implemented by hardware or software.
[0122] It should be understood that the above naming is defined only to facilitate the distinction between different functions and should not constitute any limitation to this application. This application does not exclude the possibility of adopting other naming in 5G networks and other future networks. For example, in a 6G network, some or all of the above network elements may continue to use the terminology used in 5G, or may adopt other names.
[0123] NTN communication systems include integrated communication and navigation (IcaN) systems, global navigation satellite systems (GNSS), and ultra-dense low-orbit satellite communication systems. For example, NTN communication systems, which include nodes such as satellite networks, high-altitude platforms, and drones, offer significant advantages, including global coverage, long-distance transmission, flexible networking, convenient deployment, and freedom from geographical restrictions. They have been widely used in a variety of fields, including maritime communications, positioning and navigation, disaster relief, scientific experiments, video broadcasting, and Earth observation. The integration of terrestrial communication networks (e.g., LTE networks, 5G communication networks, and future 6G communication networks) and satellite networks forms a global, seamless, integrated communication network covering land, sea, air, space, and ground, meeting the diverse service needs of users. Current 5G networks support the regenerative satellite model, in which the NTN communication system provides seamless coverage for terminal devices by deploying access network equipment or some of its functions on non-terrestrial platforms (e.g., high-altitude platforms or satellites). This can also be referred to as access network equipment providing satellite access to terminal devices using the New Radio (NR). For ease of description, in the embodiments of the present application, a satellite deployed with access network functions is referred to as a satellite access network device, or a base station deployed on a satellite is referred to as a satellite base station.
[0124] Figure 2 is a schematic diagram of a network architecture applicable to an embodiment of the present application. The satellite communication system includes a satellite base station 201 and a satellite base station 202. Each satellite base station can provide services to terminal devices through multiple beams, such as communication services, navigation services, and positioning services. The satellite in this scenario can be a low earth orbit (LEO) satellite, a medium earth orbit (MEO) satellite, a high elliptical orbit (HEO) satellite, a geostationary earth orbit (GEO) satellite, etc., and the embodiment of the present application does not specifically limit this. The satellite base station 202 is connected to a ground gateway station (such as NTN Gateway), which can also be called a gateway station, a signal gateway station, a ground station device, etc. The satellite uses multiple beams to cover the service area, and different beams can communicate through one or more of time division, frequency division, and space division.
[0125] As shown in Figure 2, taking the 5G network as an example, ground terminal devices can use the 5G new air interface to communicate with satellite base stations. For example, satellite base stations can communicate wirelessly with terminal devices through broadcast communication signals and navigation signals. The connection between the terminal device and the satellite base station can be called a service link. The satellite base station can communicate wirelessly with a ground station (also known as a gateway station, ground gateway station, signal gateway station, etc.) through the NG interface (for example, for signaling such as NAS for interaction with the core network, and user service data). The satellite base station can also communicate with the core network through the ground gateway station. The ground station is mainly responsible for forwarding signaling and service data between the satellite base station and the core network. The connection between the satellite base station and the ground station can be called a feeder link. At the same time, there is an inter-satellite link (ISL) between satellites for completing signaling interaction and user data transmission between 5G access network devices. For example, satellite base station 201 can communicate wirelessly with satellite base station 202 through the Xn interface (for example, for signaling interaction such as handover).
[0126] It should be noted that the communication system shown in Figure 2 is illustrated by taking the satellite communication system combined with the 5G system as an example. When the satellite communication system is combined with other terrestrial communication systems, the network elements and interfaces involved may have other names, and the embodiments of the present application do not specifically limit this.
[0127] Typically, the service link between a terminal device and a satellite base station, and the feeder link between the satellite base station and the ground station, are connected. This means that uplink and downlink messages between the terminal device and the core network can be transmitted via the satellite base station and the ground station. The following describes session establishment between a terminal device and the core network, using Figure 3.
[0128] Figure 3 is a schematic flow diagram of a method for establishing a session on a terminal device. This method 300 is applicable to the network architectures of Figures 1 and 2 , and primarily addresses the user plane session establishment process in a satellite communication system, as well as the user plane security protection policy indicated between the terminal device and the satellite base station during the user plane session establishment process. As shown in Figure 3 , assuming the terminal device is a UE, the access network device is a satellite base station, and the core network element is a session management element, such as an AMF or SMF, the method includes the following steps. For portions not fully described, reference may be made to existing protocols.
[0129] S301, UE registers to the network.
[0130] Exemplarily, the UE registers with the network, completes authentication, and activates non-access stratum (NAS) and access stratum (AS) layer security.
[0131] For example, the UE sends a registration request message to the network to request registration to the network, and the registration request message includes the UE ID. Furthermore, the UE and the network perform authentication, including: AMF triggering authentication of the UE. For example, the AMF sends an authentication request #1 to the AUSF, and the AUSF sends an authentication request #2 to the UDM. The authentication request #1 and the authentication request #2 are used to request authentication of the UE. The UDM generates an authentication vector and sends an authentication response #1 to the AUSF. The AUSF sends an authentication response #2 to the AMF. The authentication response #1 and the authentication response #2 include an authentication vector, such as an authentication vector of 5G-AKA or an authentication vector of EAP-AKA'. Among them, the authentication method includes but is not limited to: 5G Authentication and Key Agreement (5G-AKA) authentication method, Extensible Authentication Protocol-Authentication and Key Agreement (EAP-AKA') authentication method. Taking the authentication vector of EAP-AKA' as an example, the AMF sends an EAP Request / AKA'-Challenge message to the UE through a NAS message. After the UE completes authentication and authentication of the network, it sends an EAP-Response / AKA'-Challenge message to the AMF through a NAS message. The AMF then sends a Nausf_UE Authentication_Authenticate Request message to the AUSF, carrying the EAP-Response / AKA'-Challenge message. The AUSF verifies the EAP-Response / AKA'-Challenge message. If the verification is successful, the UE is authenticated, and an EAP Success message is sent to the UE through the AMF to indicate that the authentication is successful. For the specific authentication implementation method, please refer to the relevant description of the existing protocol TS 33.501.
[0132] It should be understood that after the above-mentioned authentication process, the UE and the AMF side usually generate or obtain a new NAS layer key (such as KAMF), wherein the NAS layer key (such as KAMF subkey) is activated for use by triggering the NAS SMC process, that is, the AMF sends a NAS SMC message to the UE, and the UE sends a NAS SMP message to the AMF. Among them, the NAS SMC message includes but is not limited to: integrity security protection algorithm identifier and / or confidentiality security protection algorithm identifier, ngKSI, replayed UE security capability, MAC#1. The NAS SMP message includes MAC#2. Among them, ngKSI is used to identify a specific NAS security context, and the NAS security context includes: one or more of: key identifier, UE security capability, uplink and downlink NAS count value, confidentiality security protection key, integrity security protection key, selected integrity security protection algorithm identifier, and confidentiality security protection algorithm identifier.
[0133] S302: The UE sends a session establishment request message to the AMF. Correspondingly, the AMF receives the session establishment request message from the UE.
[0134] The session establishment request message includes a session identifier, which is used to identify the UE's session. Optionally, it may also carry information such as the session type and / or slice. Exemplarily, the UE initiates a PDU session establishment request message, such as a PDU Session Establishment Request message, to the AMF via a satellite base station. It should be understood that the session request message is a NAS message, which is transparently transmitted by the satellite base station. The satellite base station does not parse the session establishment request message.
[0135] S303, AMF sends a session creation context request message to SMF, and correspondingly, SMF receives the session creation context request message from AMF.
[0136] The session creation context request message includes a session identifier, and the session creation context request message may be an Nsmf_PDUSession_createSMContext Request message. Correspondingly, the SMF may search for a corresponding user plane security policy (which may be referred to as a security protection policy or user plane security protection policy) from the UDM, PCF, or network management function element based on the session identifier to indicate whether security protection is required at the transport layer.
[0137] Exemplarily, the user plane security policy includes a confidentiality security policy and / or an integrity security policy, wherein the confidentiality security policy is used to indicate whether the transport layer requires confidentiality security protection, and the integrity security policy is used to indicate whether the transport layer requires integrity security protection.
[0138] In one implementation, the security policy values include required, preferred, and not needed. For example, if the security policy value is required, it indicates that the sender needs to perform security protection on the message and / or data to be sent; if the security policy value is not needed, it indicates that the sender does not need to perform security protection on the message and / or data to be sent; if the security policy value is preferred, it indicates that the sender needs to perform optional security protection on the message and / or data to be sent, that is, the sender can perform security protection on the message and / or data to be sent, or can perform no security protection on the message and / or data to be sent, where security protection includes confidentiality security protection and / or integrity security protection. For example, when the value of the integrity security policy is required, it means that integrity security protection is required for the messages and / or data to be sent; when the value of the integrity security policy is not needed, it means that integrity security protection is not required for the messages and / or data to be sent; when the value of the integrity security policy is preferred, it means that integrity security protection is optional for the messages and / or data to be sent, that is, integrity security protection can be performed on the messages and / or data to be sent, or integrity security protection can be omitted. For another example, when the value of the confidentiality security policy is required, it means that confidentiality security protection is required for the messages and / or data to be sent; when the value of the confidentiality security policy is not needed, it means that confidentiality security protection is not required for the messages and / or data to be sent; when the value of the confidentiality security policy is preferred, it means that confidentiality security protection is optional for the messages and / or data to be sent, that is, confidentiality security protection can be performed on the messages and / or data to be sent, or confidentiality security protection can be omitted.
[0139] It should be understood that integrity protection can be achieved by physical means or cryptographic methods to ensure that information and / or data are not tampered with or modified without authorization during the generation, transmission, storage process, and thereafter. There are many ways to perform integrity protection on information through cryptographic methods, such as using a one-way function (such as a hash function), with a symmetric key (integrity security protection key) and a message as input parameters to generate a message authentication code (MAC) to achieve integrity security protection of the message and / or data. Exemplarily, integrity security protection can refer to performing integrity security protection on the message to be sent based on the selected integrity security protection algorithm and integrity security protection key. For example, for NAS messages, the integrity security protection key may be a NAS integrity key (NAS Integrity Key, Knasint), and Knasint is used to perform integrity security protection on messages to be sent; for RRC messages, the integrity security protection key may be an RRC integrity key (RRC Integrity Key, Krrcint), and Krrcint is used to perform integrity security protection on messages to be sent; for user plane messages and / or data, the integrity security protection key may be an integrity key (UP Integrity Key, Kupint), and Kupint is used to perform integrity security protection on messages to be sent.
[0140] It should also be understood that confidentiality security protection may refer to encrypting messages and / or data to be sent according to a confidentiality security protection algorithm and a confidentiality security protection key.
[0141] Optionally, the security policy may be explicitly indicated, for example, using an independent information element (IE). For example, by indicating with 2 bits of indication information, "00" indicates that the value of the security policy is required, "01" indicates that the value of the security policy is not needed, and "10" indicates that the value of the security policy is preferred; or, "true" indicates that the value of the security policy is required, and "false" indicates that the value of the security policy is not needed. This application does not limit this.
[0142] Exemplarily, the security algorithm includes an integrity security algorithm and / or a confidentiality security protection algorithm. The integrity security algorithm includes one or more of the following: an AES integrity security protection algorithm, a SNOW integrity security protection algorithm, a ZUC integrity security protection algorithm, or a null integrity security protection algorithm; and the confidentiality security protection algorithm includes one or more of the following: a ZUC confidentiality security protection algorithm, an AES confidentiality security protection algorithm, a SNOW confidentiality security protection algorithm, or a null integrity security protection algorithm.
[0143] S304, SMF sends a session creation context response message to AMF, and correspondingly, AMF receives the session creation context response message from SMF.
[0144] The session creation context response message includes a session identifier, a user plane security policy, and a session acceptance message. For example, the session creation context response message may be an Nsmf_PDUSession_createSMContext Response message. The session acceptance message is carried in an N1 container.
[0145] S305, AMF sends a session resource establishment request message to the satellite base station, and correspondingly, the satellite base station receives the session resource establishment request message from AMF.
[0146] The session resource establishment request message includes a session identifier, a user plane security policy, and a session acceptance message. The session resource establishment request message may be a PDU Session Resource Setup Request message.
[0147] S306: The satellite base station determines whether to activate security protection of the DRB corresponding to the session according to the user plane security policy.
[0148] Among them, a session corresponds to one or more DRBs. In other words, one or more data #1 transmitted by a session can be carried by the one or more DRBs respectively, and usually one DRB carries one data #1. It should be noted that the user plane security policy is used to indicate whether to enable security protection of the DRB corresponding to the session.
[0149] Exemplarily, when the value of the user plane security policy is required, the satellite base station determines that the security protection of the DRB needs to be activated, that is, the security protection of the DRB is configured to be enabled; when the value of the user plane security policy is not needed, the satellite base station determines that the security protection of the DRB does not need to be activated, that is, the security protection of the DRB is configured to be disabled; when the value of the user plane security policy is preferred, the satellite base station can determine whether to activate the security protection of the DRB according to the local policy, that is, determine whether to enable the security protection according to the local policy. For example, the local policy indicates that when the value of the user plane security policy is preferred, the satellite base station can choose to enable security protection, or the local policy indicates that when the value of the user plane security policy is preferred, the satellite base station can choose to enable or not enable security protection according to its own load situation.
[0150] In one implementation, when the value of the integrity security policy is required, the satellite base station activates the integrity security protection of the DRB corresponding to the session; when the value of the integrity security policy is not needed, the satellite base station activates the integrity security protection of the DRB corresponding to the session; when the value of the integrity security policy is preferred, the satellite base station activates or does not activate the integrity security protection of the DRB corresponding to the session according to the local policy.
[0151] In another implementation, when the value of the confidentiality security policy is required, the satellite base station activates the confidentiality security protection of the DRB corresponding to the session; when the value of the confidentiality security policy is not needed, the satellite base station activates the confidentiality security protection of the DRB corresponding to the session; when the value of the confidentiality security policy is preferred, the satellite base station activates or does not activate the confidentiality security protection of the DRB corresponding to the session according to the local policy.
[0152] It should be noted that if the user plane security policy indicates that the integrity security protection of the DRB does not need to be activated (or turned on), the satellite base station and the UE can set the MAC to all 0s, which means that the satellite base station and the UE do not perform integrity security protection on the user plane messages and / or data carried by the DRB, and do not need to perform integrity verification on the user plane messages and / or data carried by the DRB. Optionally, the MAC may not be included in the Packet Data Convergence Protocol (PDCP) data packet.
[0153] S307: The satellite base station sends an RRC reconfiguration message to the UE. Correspondingly, the UE receives the RRC reconfiguration message from the satellite base station.
[0154] Exemplarily, the RRC reconfiguration message may be an RRC Reconfiguration message.
[0155] Among them, the RRC reconfiguration message includes a DRB identifier (such as DRB ID) and its corresponding user plane security indication (UP sec indication), such as an integrity security protection indication and / or a confidentiality security protection indication. The integrity security protection indication is used to indicate whether the integrity security protection of the DRB is enabled, or whether the integrity security protection of the DRB needs to be activated. The confidentiality security protection indication is used to indicate whether the confidentiality security protection of the DRB is enabled, or whether the confidentiality security protection of the DRB needs to be activated.
[0156] In addition, the RRC reconfiguration message also includes the session acceptance message.
[0157] Optionally, the size of the integrity security protection indication and / or confidentiality security protection indication may be 1 bit. For example, a value of "1" for the confidentiality indication information indicates that the confidentiality security protection of the DRB is enabled; a value of "0" for the confidentiality indication information indicates that the confidentiality security protection of the DRB is not enabled. For another example, a value of "1" for the integrity indication information indicates that the integrity security protection of the DRB is enabled; a value of "0" for the integrity indication information indicates that the integrity security protection of the DRB is not enabled.
[0158] Optionally, the values of the integrity security protection indicator and the confidentiality security protection indicator may be determined according to a user plane security policy received by the satellite base station.
[0159] For example, if the UE's session corresponds to two DRBs (e.g., DRB#1 and DRB#2), the data used for transmission in the session is carried in DRB#1 and DRB#2, for example, data#1 is carried in DRB#1, and data#2 is carried in DRB#2. If the user plane security policy indicates that integrity security protection is activated but confidentiality security protection is not activated, the satellite base station can set the value of the integrity security protection indicator corresponding to DRB#1 and DRB#2 to "1" and the value of the confidentiality security protection indicator to "0", and carry them in the RRC reconfiguration message of step S307.
[0160] Optionally, after determining whether to activate security protection for the DRB, or after determining the user plane security protection policy, the satellite base station configures the PDCP entity of the DRB corresponding to the session. For example, if the user plane security policy indicates activation of integrity security protection and deactivation of confidentiality security protection, the user plane security indication in the RRC reconfiguration message is used to instruct DRB#1 and DRB#2 to enable integrity security protection and deactivate confidentiality security protection. Correspondingly, the satellite base station configures the integrity security protection key and integrity security protection algorithm corresponding to DRB#1 and DRB#2 in the PDCP entity, and activates the integrity check of the uplink user plane messages and / or data on the DRB#1 and DRB#2, and activates the integrity security protection of the downlink user plane messages and / or data on the DRB#1 and DRB#2.
[0161] S308: The UE performs an integrity check on the RRC reconfiguration message.
[0162] Exemplarily, the UE performs an integrity check on the received RRC reconfiguration message. For example, the UE compares the MAC#3 value carried in the RRC reconfiguration message with the MAC#4 calculated locally by the UE. If the two are the same, it can be considered that the integrity check has passed; otherwise, the integrity check has failed.
[0163] Furthermore, when the integrity verification is successful, the UE configures the PDCP entity corresponding to the DRB. For example, if integrity security protection is activated for DRB#1 indicated in the RRC reconfiguration message, the UE configures the integrity security protection key and integrity security protection algorithm corresponding to DRB#1 in the PDCP entity, and activates the integrity security protection of the uplink user plane message on the DRB#1, and activates the integrity check of the downlink user plane message on the DRB#1. If confidentiality security protection is activated for DRB#2 indicated in the RRC reconfiguration message, the UE configures the confidentiality security protection key and confidentiality security protection algorithm corresponding to DRB#2 in the PDCP entity, and activates the confidentiality security protection of the uplink user plane message on the DRB#2, and activates the decryption operation of the downlink user plane message on the DRB#2.
[0164] S309 , the UE sends an RRC reconfiguration completion message to the satellite base station, and correspondingly, the satellite base station receives the RRC reconfiguration completion message from the UE.
[0165] Exemplarily, if the UE successfully verifies the integrity of the RRC reconfiguration message in step S309, the UE sends an RRC reconfiguration complete message to the satellite base station. For example, the RRC reconfiguration complete message may be an RRC Reconfiguration Complete message. Alternatively, if the UE fails to successfully activate DRB security protection, or if the UE fails to configure the PDCP entity for the DRB, the UE may send a failure cause value to the satellite base station. The failure cause value may indicate that the integrity check of the RRC reconfiguration message failed.
[0166] S310, the satellite base station sends a session resource establishment response message to the AMF, and correspondingly, the AMF receives the session resource establishment response message from the satellite base station.
[0167] The session resource setup response message is used to inform the session resource setup result, such as whether the setup is successful or failed. Exemplarily, the session resource setup response message can be a PDU Session Resource Setup Response message. It should be understood that the technical solution of the present application is based on the successful establishment of the session resource.
[0168] Optionally, in an LTE network, the core network element in the above method 300 may be a Mobility Management Entity (MME), a Serving GateWays (S-GWs), or a Public Data Network (PDN GWs or P-GWs). The specific implementation method is similar and will not be described here.
[0169] Since the ground coverage range of the satellite is limited, at certain moments, the service link and the feeder link may not be in a connected state at the same time. For example, when the satellite moves over geographical location A, it can establish a service link with the UE in geographical location B, but at this time it may not be able to establish a feeder link with the ground gateway station in geographical location C. At this time, the satellite base station can perform a store and forward operation (Store and Forward), that is, the satellite base station can store the received uplink message, that is, cache the uplink message on the satellite base station, and then forward the stored uplink information to the ground network after the feeder link is restored. It should be understood that the store and forward operation is mainly suitable for delay-insensitive or non-real-time IoT satellite services. The object of the store and forward operation can be signaling plane data or user plane data. For the convenience of description and understanding, this application takes user plane data as an example for illustration.
[0170] In store-and-forward scenarios, if an attacker sends a large amount of malicious data or messages to a satellite base station, the satellite base station's storage area may become full, making it unable to cache control plane data and / or user plane data for legitimate UEs. This poses a risk of malicious attacks on the satellite base station and compromises network security. Therefore, additional measures are urgently needed to mitigate potential security risks.
[0171] In view of this, the present application provides a secure communication method and communication device, which can reduce the risk of satellite base stations being maliciously attacked and improve network communication security.
[0172] The communication method provided by the embodiment of the present application will be described in detail below with reference to the accompanying drawings. The embodiment provided by the present application can be applied to a communication scenario where a transmitting device and a receiving device communicate, such as the communication system shown in Figures 1 and 2 above.
[0173] Figure 4 is a flow chart of the communication method provided by an embodiment of the present application. The method 400 can be executed by the terminal device side, the network device side, and the core network side. For example, the method can be executed by the terminal device, the network device, and the core network element (such as the session management element), or it can also be executed by the chip or circuit of the terminal device, the network device, and the core network element (such as the session management element), or it can also be implemented by a logic module or software that can realize all or part of the functions of the communication device. This application does not limit this. The following is an example of the execution subject being the terminal device, the network device, and the session management element. As shown in Figure 4, the method includes the following multiple steps. For the part not fully described, please refer to the above method 300 or the existing protocol.
[0174] S410, during the session establishment process of the terminal device, the network device determines whether to activate integrity security protection of the session based on first information, where the first information is used to indicate whether the network device supports a store-and-forward operation (which may be referred to as capability information).
[0175] It should be understood that the session is used to transmit data between the terminal device and the core network. For example, a session corresponds to one or more DRBs, which means that one or more data transmitted by a session can be carried by the one or more DRBs respectively. Typically, one DRB carries one data, and the DRB is used to carry data between the terminal device and the network device.
[0176] It should be noted that whether to activate the integrity security protection of the session can be understood as: whether to activate the integrity security protection of one or more DRBs corresponding to the session, or whether to enable integrity security protection for the data transmitted between the terminal device and the network device.
[0177] The specific implementation of the session establishment process of the terminal device and the meaning of the store and forward operation (Store and Forward) can be referred to the relevant description of the above method 300 and will not be explained here.
[0178] Optionally, before executing step S410, the method further includes: the network device obtains first information.
[0179] For example, the first information may be predefined, configured via signaling, or preconfigured. Predefinition may include predefinition, such as protocol definition. Preconfiguration may be implemented by pre-saving corresponding codes, tables, strings, or other methods that can be used to indicate the first information in the network device. This application does not limit the specific implementation method.
[0180] Optionally, the first information may also be used to indicate whether the network device is configured to enable a store-and-forward operation (which may be referred to as configuration information), and / or the first information may also be used to indicate whether the network device is deployed on a satellite (which may be referred to as location information). For ease of description, this application may refer to a network device deployed on a satellite as a satellite base station, and a network device not deployed on a satellite as a ground base station.
[0181] That is, the first information in this application may include one or more of capability information, configuration information, or location information of the network device.
[0182] Below, an example is given of a network device determining whether to activate integrity security protection of a session based on the first information, or a satellite base station activating or not activating integrity security protection of a session based on the first message, including one or more of the following.
[0183] (1) The network device determines whether to activate the integrity security protection of the session based on the capability information. In other words, the network device determines whether to activate or not activate the integrity security protection of the session based on the capability information.
[0184] For example, if the capability information indicates that the network device supports store-and-forward operations, the network device determines to activate integrity security protection for the session, i.e., the integrity security protection for the session can be directly activated without considering the integrity security policy. For another example, if the capability information indicates that the network device does not support store-and-forward operations, the network device determines not to activate integrity security protection for the session. Alternatively, the network device can determine whether to activate integrity security protection for the session based on the user plane integrity security policy obtained in step S403.
[0185] That is to say, when the network device supports store-and-forward operations, the network device activates the integrity security protection of the session; when the network device does not support store-and-forward operations, the network device does not activate the integrity security protection of the session, or may activate or not activate the integrity security protection of the session according to the user plane integrity security policy.
[0186] (2) The network device determines whether to activate the integrity security protection of the session based on the configuration information, or in other words, the network device activates or does not activate the integrity security protection of the session based on the configuration information.
[0187] For example, if the configuration information instructs the network device to enable the store-and-forward operation, the network device determines to activate integrity security protection for the session, i.e., it can directly activate integrity security protection for the session without considering the integrity security policy. For another example, if the configuration information instructs the network device not to enable the store-and-forward operation, the network device determines not to activate integrity security protection for the session. Alternatively, the network device can determine whether to activate integrity security protection for the session based on the user plane integrity security policy obtained in step S403.
[0188] It can be understood that when the network device is configured to enable the store-and-forward operation, the network device activates the integrity security protection of the session; when the network device is configured not to enable the store-and-forward operation, the network device does not activate the integrity security protection of the session, or can activate or not activate the integrity security protection of the session based on the user plane integrity security policy.
[0189] (3) The network device determines whether to activate the integrity security protection of the session based on the location information, or in other words, the network device activates or does not activate the integrity security protection of the session based on the location information.
[0190] For example, when the location information indicates that the network device is deployed on a satellite, that is, the network device is a satellite base station, the network device determines to activate the integrity security protection of the session, that is, there is no need to consider the integrity security policy, and the integrity security protection of the session can be directly activated; for another example, when the location information indicates that the network device is deployed on a non-satellite, for example, the network device is a ground base station, the network device does not activate the integrity security protection of the session, or can determine whether to activate the integrity security protection of the session based on the user plane integrity security policy obtained in step S403.
[0191] It can be understood that when the network device is deployed on a satellite, the network device activates the integrity security protection of the session; when the network device is deployed on the ground, the network device does not activate the integrity security protection of the session, or can activate or not activate the integrity security protection of the session according to the user plane integrity security policy.
[0192] It should be understood that in the above (1)-(3), the network device determines whether to activate the integrity security protection of the session based on the first information, or in other words, the network device activates or deactivates the integrity security protection of the session based on the first information. The technical logic of the above (1)-(3) is the same, that is, the network device can activate or deactivate the integrity security protection of the session based on the first information without considering the user plane integrity security policy. This method allows the user plane data to have integrity security protection as much as possible, making it easier for the subsequent network device to perform integrity verification on the received uplink message and / or data, thereby ensuring network communication security and reducing the risk of denial of service attacks.
[0193] Optionally, when determining whether to activate the integrity security protection of the session, the network device may also consider the user plane integrity security policy corresponding to the session, that is, the network device may determine whether to activate the integrity security protection of the session based on the first information and the user plane integrity security policy. At this time, the method also includes the following step S404.
[0194] S404: The network device determines whether to activate integrity security protection of the session according to the first information and the user plane integrity security policy.
[0195] The user plane integrity security policy is used to indicate whether to activate the integrity security protection of the session. For a specific interpretation, please refer to the relevant description of the above step S410 and the above method 300.
[0196] Optionally, before executing step S404, the session management network element obtains a user plane integrity security policy for the session, for example, see the following step S403.
[0197] S403: The network device obtains a user plane integrity security policy corresponding to the session.
[0198] Exemplarily, the values of the user plane integrity security policy include required, preferred, and not needed. For example, if the value of the user plane integrity security policy is required, it indicates that integrity security protection is enabled for the session; if the value of the user plane integrity security policy is not needed, it indicates that integrity security protection is not enabled for the session; and if the value of the user plane integrity security policy is preferred, it indicates that integrity security protection is optionally enabled for the session.
[0199] Optionally, the user plane integrity security policy can be explicitly indicated, for example, using an independent information element (IE). For example, through 2 bits of indication information, "00" indicates that the value of the user plane integrity security policy is required, "01" indicates that the value of the user plane integrity security policy is not needed, and "10" indicates that the value of the user plane integrity security policy is preferred; or, "true" indicates that the value of the user plane integrity security policy is required, and "false" indicates that the value of the user plane integrity security policy is not needed. This application does not limit its expression.
[0200] In one implementation, the network device obtains the user plane integrity security policy corresponding to the session from the session management network element, for example, see the following step S402.
[0201] S402 , the session management network element sends a user plane integrity security policy corresponding to the session to the network device. Correspondingly, the network device receives the user plane integrity security policy corresponding to the session from the session management network element.
[0202] In one example, the session management network element sends the user plane integrity security policy to the mobile access management network element (such as AMF), and the mobile access management network element then sends the user plane integrity security policy to the network device.
[0203] Optionally, the session management network element may proactively send the user plane integrity security policy corresponding to the session to the network device, or may send the policy based on a request from the network device. For example, the network device may send a request message to the session management network element, where the request message is used to obtain the user plane integrity security policy corresponding to the session. In response, the session management network element may send the user plane integrity security policy corresponding to the session to the network device after receiving the request message.
[0204] Optionally, before executing step S402, the session management network element determines the user plane integrity security policy of the session. For example, the session management network element may determine the user plane integrity security policy of the session based on the acquired indication information, for example, see the following step S401.
[0205] S401: The session management network element obtains instruction information.
[0206] The indication information is used to indicate that the network device is deployed on a satellite. Optionally, the indication information is also used to indicate that the network device supports store-and-forward operations, and / or that the network device is configured to enable store-and-forward features.
[0207] It should be understood that the deployment of network equipment on a satellite can be understood as the physical deployment of the network equipment (e.g., a base station) on the satellite, or the network equipment (e.g., a base station) and the satellite being co-located. In this case, the satellite has the capabilities of the network equipment, for example, the satellite supports store-and-forward operations of the network equipment.
[0208] In one example, the session management element receives indication information from the mobile access management element (e.g., AMF). For example, during the session establishment process of the terminal device, the mobile access management element sends a session creation context request message to the session management element, and the session creation context request message carries the indication information.
[0209] In another example, the session management network element obtains indication information from Operation Administration and Maintenance (OAM) or UDM. For example, the session management network element sends a query message to the OAM or UDM to obtain one or more of the network device's capability information, location information, or configuration information. In response, the OAM or UDM sends the indication information to the session management network element. The specific definitions of capability information, location information, and configuration information can be found in the relevant descriptions above and are not further explained here.
[0210] Exemplarily, the user plane integrity security policy corresponding to the session is determined based on the indication information, or in other words, the session management network element can determine the user plane integrity security policy corresponding to the session based on the indication information. For example, when the indication information determines that the network device is deployed on a satellite, or that the network device supports store-and-forward operations, or that the network device is configured to enable store-and-forward features, then considering the limited storage resources of the network device and to avoid potential DoS risks, the session management network element can set the value of the user integrity security policy to required. In other words, the session management network element can determine to enable or activate integrity security protection based on the indication information, that is, all subsequent data transmitted between the terminal device and the network device are integrity-protected, that is, all data transmitted between the terminal device and the network device are required to undergo integrity verification, and then the data that passes the integrity verification is stored and forwarded.
[0211] Optionally, the user plane integrity security policy corresponding to the session can also be determined based on the subscription information, or in other words, the session management network element can determine the user plane integrity security policy corresponding to the session based on the subscription information. The subscription information is used to indicate whether the terminal device has subscribed to the store-and-forward operation service. For example, if the subscription information indicates that the terminal device has subscribed to the store-and-forward operation service, the session management network element can set the value of the user plane integrity security policy corresponding to the session to required. In other words, the session management network element can enable integrity security protection for the session based on the subscription information, that is, all subsequent uplink and downlink data transmitted between the terminal device and the network device are integrity-protected, that is, the terminal device and the network device need to perform integrity verification on the received user plane data. For another example, if the subscription information indicates that the terminal device has not subscribed to the store-and-forward operation service, the session management network element can set the value of the user plane integrity security policy corresponding to the session to preferred. In other words, the session management network element can determine the optional activation of integrity security protection for the session based on the subscription information, and then the network device determines whether to enable integrity security protection for the session based on the local policy.
[0212] Optionally, the user plane integrity security policy corresponding to the session can also be determined based on the contract information and the indication information, or in other words, the session management network element can determine the user plane integrity security policy corresponding to the session based on the indication information and the contract information. For example, if the indication information determines that the network device is deployed on a satellite, or the network device supports store-and-forward operations, or the network device is configured to enable the store-and-forward feature, and at the same time, the contract information indicates that the terminal device has signed a contract for the store-and-forward operation service, then the session management network element can set the value of the user plane integrity security policy corresponding to the session to required, indicating that the integrity security protection of the session is enabled; for another example, if the indication information determines that the network device is not deployed on a satellite, or the network device does not support store-and-forward operations, or the network device is configured not to enable the store-and-forward feature, and the contract information indicates that the terminal device has not signed a contract for the store-and-forward operation service, then the session management network element can set the value of the user plane integrity security policy corresponding to the session to not needed, indicating that the integrity security protection of the session is not enabled; for example, if the indication information determines that the network device is not deployed on a satellite, or the network device does not support store-and-forward operations, or the network device configuration does not enable the store-and-forward feature, or the contract information indicates that the terminal device has not signed a contract for the store-and-forward operation service, then the session management network element can set the user plane integrity security policy corresponding to the session to the value of preferred, indicating that the integrity security protection of the session can be enabled optionally, and then the network device determines whether to enable or not the integrity security protection of the session according to the local policy.
[0213] In one implementation, the session management element may obtain the subscription information from the UDM or PCF. For example, the session management element sends a query message to the UDM or PCF to obtain the subscription information of the terminal device. In response, the UDM or PCF sends the subscription information of the terminal device to the session management element.
[0214] Optionally, this application does not limit the order in which the session management network element obtains the above-mentioned contract information and indication information.
[0215] Below, an example is given of the network device determining whether to activate the integrity security protection of the session based on the first information and the user plane integrity security policy in the above step S404, or the satellite base station activating or not activating the integrity security protection of the session based on the first message and the user plane integrity security policy, including one or more of the following.
[0216] (1) The network device determines whether to activate the integrity security protection of the session based on the capability information and the user plane integrity security policy. In other words, the network device activates or deactivates the integrity security protection of the session based on the capability information and the user plane integrity security policy.
[0217] For example, when the capability information indicates that the network device supports store-and-forward operations and the value of the user-plane integrity security policy is required or preferred, the network device determines to activate the integrity security protection of the session; for another example, when the capability information indicates that the network device supports store-and-forward operations and the value of the user-plane integrity security policy is not needed, the network device determines not to activate the integrity security protection of the session. In this implementation, the network device determines whether to activate the integrity security protection of the session mainly based on the user-plane integrity security policy; for another example, when the capability information indicates that the network device supports store-and-forward operations and the value of the user-plane integrity security policy is not needed, the network device determines to activate the integrity security protection of the session. In this implementation, the network device determines whether to activate the integrity security protection of the session mainly based on whether the network device supports store-and-forward operations; for another example, when the capability information indicates that the network device does not support store-and-forward operations, regardless of the value of the user-plane integrity security policy is required, preferred or not needed, the network device determines not to activate the integrity security protection of the session.
[0218] (2) The network device determines whether to activate the integrity security protection of the session based on the configuration information of the network device and the user plane integrity security policy. In other words, the network device activates or does not activate the integrity security protection of the session based on the configuration information of the network device and the integrity security policy.
[0219] For example, when the configuration information indicates that the network device is configured to enable the store-and-forward operation and the value of the user-plane integrity security policy is required or preferred, the network device determines to activate the integrity security protection of the session; for another example, when the configuration information indicates that the network device is configured to enable the store-and-forward operation and the value of the user-plane integrity security policy is not needed, the network device determines not to activate the integrity security protection of the session. In this implementation, the network device determines whether to activate the integrity security protection of the session mainly based on the user-plane integrity security policy; for another example, when the configuration information indicates that the network device is configured to enable the store-and-forward operation and the value of the user-plane integrity security policy is not needed, the network device determines to activate the integrity security protection of the session. In this implementation, the network device determines whether to activate the integrity security protection of the session mainly based on whether the network device is configured to enable the store-and-forward operation; for another example, when the configuration information indicates that the network device is configured not to enable the store-and-forward operation, regardless of the value of the user-plane integrity security policy is required, preferred or not needed, the network device determines not to activate the integrity security protection of the session.
[0220] (3) The network device determines whether to activate the integrity security protection of the session based on the location information and the user plane integrity security policy. In other words, the network device activates or does not activate the integrity security protection of the session based on the location information and the user plane integrity security policy.
[0221] For example, when the location information indicates that the network device is deployed on a satellite (for example, the network device is a satellite base station) and the value of the user plane integrity security policy is required or preferred, the network device determines to activate the integrity security protection of the session; for another example, when the location information indicates that the network device is deployed on a satellite and the value of the user plane integrity security policy is not needed, the network device determines not to activate the integrity security protection of the session. In this implementation, the network device determines whether to activate the integrity security protection of the session mainly based on the user plane integrity security policy; for another example, when the location information indicates that the network device is deployed on a satellite and the value of the user plane integrity security policy is not needed, the network device determines not to activate the integrity security protection of the session. In this implementation, the network device determines whether to activate the integrity security protection of the session mainly based on whether the network device is a satellite base station; for another example, when the location information indicates that the network device is deployed on a non-satellite (for example, the network device is a ground base station), regardless of the value of the user plane integrity security policy is required, preferred, or not needed, the network device determines not to activate the integrity security protection of the session.
[0222] It should be understood that in (4)-(6) above, the network device determines whether to activate the integrity security protection of the session based on the first information user plane integrity security policy, or in other words, the network device activates or does not activate the integrity security protection of the session based on the first information user plane integrity security policy. The technical logic of (4)-(6) above is the same, that is, the network device supports maximizing the activation of the integrity security protection of the session, ensuring that the integrity security protection of the user plane data is activated to the maximum extent, facilitating the subsequent network device to perform integrity verification on the received uplink messages and / or data, thereby ensuring network communication security and reducing the risk of denial of service attacks.
[0223] It should be noted that this application does not impose any specific restrictions on the order in which steps S401-S404 are executed. For example, steps S401-S404 may be executed before step S410, or after step S410, or steps S401-S403 may be executed before step S410 and step S404 may be completed after step S410, as long as steps S401-S404 are executed before step S420.
[0224] S420, the network device sends first integrity security protection indication information to the terminal device, and correspondingly, the terminal device receives the first integrity security protection indication information from the network device.
[0225] The first integrity security protection indication information is used to indicate an activation result. Exemplarily, the activation result is used to indicate whether integrity security protection for the session is activated, or in other words, the activation result is used to indicate whether integrity security protection for one or more DRBs corresponding to the session is activated. For example, the activation result includes activating integrity security protection for the session or deactivating integrity security protection for the session.
[0226] Optionally, the network device sends an RRC reconfiguration message to the terminal device, such as an RRC Reconfiguration message, where the RRC reconfiguration message carries first integrity security protection indication information.
[0227] Optionally, the first integrity security protection indication information may be explicitly indicated, for example, using an independent information element (IE). For example, it may be indicated by a 1-bit indication information, where "1" indicates that integrity security protection for the session is activated, and "0" indicates that integrity security protection for the session is not activated; or, alternatively, "true" indicates that integrity security protection for the session is activated, and "false" indicates that integrity security protection for the session is not activated. This application does not limit the form of its expression.
[0228] In one implementation, the first integrity security protection indication information is determined based on the first information. For example, based on the above step S410, if the network device determines to activate integrity security protection for the session based on the first information, the first integrity security protection indication information is used to indicate that integrity security protection for the session is activated; if the network device determines not to activate integrity security protection for the session based on the first information, the first integrity security protection indication information is used to indicate that integrity security protection for the session is not activated.
[0229] In another implementation, the first integrity security protection indication information is determined based on the first information and the user plane security protection policy. For example, based on step S404 above, if the network device determines to activate integrity security protection for the session based on the first information and the user plane security protection policy, the first integrity security protection indication information is used to indicate that integrity security protection for the session is activated; if the network device determines not to activate integrity security protection for the session based on the first information and the user plane security protection policy, the first integrity security protection indication information is used to indicate that integrity security protection for the session is not activated.
[0230] Optionally, the size of the first integrity security protection indication information can be 1 bit. For example, the value of the first integrity security protection indication information is "1", indicating that the integrity security protection corresponding to the session is enabled, or in other words, one or more DRBs corresponding to the session have integrity security protection enabled, that is, one or more data carried on the one or more DRBs between the terminal device and the network device are integrity-secured, and the terminal device or the network device needs to perform an integrity check after receiving the one or more data; for another example, the value of the first integrity security protection indication information is "0", indicating that the integrity security protection corresponding to the session is not enabled, or in other words, one or more DRBs corresponding to the session do not have integrity security protection enabled, that is, one or more data carried on the one or more DRBs between the terminal device and the network device are not integrity-secured, and the terminal device or the network device does not need to perform an integrity check after receiving the one or more data.
[0231] Optionally, after determining whether to activate the integrity security protection of the session, or after determining the first integrity security protection indication information, or after sending the first integrity security protection indication information to the terminal device, the network device may configure the PDCP entity of one or more DRBs corresponding to the session. Exemplarily, if it is determined to activate the integrity security protection of the session, the network device configures the integrity security protection key and integrity security protection algorithm of the one or more DRBs in the PDCP entity, and activates the integrity check of the uplink user plane messages and / or data carried by the one or more DRBs, and activates the integrity security protection of the downlink user plane messages and / or data carried by the one or more DRBs; if it is determined not to activate the integrity security protection of the session, the network device does not need to configure the integrity security protection key and integrity security protection algorithm of the one or more DRBs in the PDCP entity, and does not need to activate the integrity check of the uplink user plane messages and / or data carried by the one or more DRBs, and does not need to activate the integrity security protection of the downlink user plane messages and / or data carried by the one or more DRBs.
[0232] S430, the terminal device performs integrity verification on the first integrity security protection indication information.
[0233] Exemplarily, the terminal device may determine whether the integrity check passes by comparing MAC values. For specific implementations, reference may be made to the relevant description of the above method 300 and will not be described again here.
[0234] S440: When the integrity check passes, the terminal device determines whether to activate the integrity security protection of the session according to the first integrity security protection indication information.
[0235] That is to say, after the terminal device receives the first integrity security protection indication information, when the integrity check of the first integrity security protection indication information passes, the terminal device can further determine whether to enable or disable integrity security protection for the session. For example, if the first integrity security protection indication information indicates to activate integrity security protection for the session, the terminal device enables integrity security protection for the session, which means that all subsequent uplink messages and / or data sent by the terminal device to the network device need to undergo integrity security protection, and all subsequent uplink messages and / or data received by the terminal device from the network device need to undergo integrity verification; for another example, if the first integrity security protection indication information indicates not to activate integrity security protection for the session, the terminal device does not enable integrity security protection for the session, which means that all subsequent uplink messages and / or data sent by the terminal device to the network device do not need to undergo integrity security protection, and all subsequent uplink messages and / or data received by the terminal device from the network device do not need to undergo integrity verification.
[0236] Optionally, when the integrity verification passes, after determining whether to activate the integrity security protection of the session, the terminal device can configure the PDCP entity of one or more DRBs corresponding to the session. For example, if the first integrity security protection indication information indicates to activate the integrity security protection of the session, the terminal device configures the integrity security protection key and integrity security protection algorithm of the one or more DRBs corresponding to the session in the PDCP entity, and activates the integrity security protection of the uplink user plane messages and / or data carried by the one or more DRBs, and activates the integrity check of the downlink user plane messages and / or data carried by the one or more DRBs; if the first integrity security protection indication information indicates not to activate the integrity security protection of the session, the terminal device does not need to configure the integrity security protection key and integrity security protection algorithm of the one or more DRBs corresponding to the session in the PDCP entity, and does not need to activate the integrity security protection of the uplink user plane messages and / or data carried by the one or more DRBs, and does not need to activate the integrity check of the downlink user plane messages and / or data carried by the one or more DRBs.
[0237] Optionally, the terminal device may send a response message to the network device to indicate whether the terminal device has successfully activated the integrity security protection of the session. For example, if the terminal device successfully activates the integrity security protection of the session, the terminal device sends a response message #1 to the network device to indicate that the terminal device has successfully activated the integrity security protection of the session. Optionally, if the first integrity security protection indication information of the above step S420 is carried in the RRC reconfiguration message, the terminal device may send an RRC reconfiguration completion message to the network device to indicate that the terminal device has successfully activated the integrity security protection of the session, or in other words, to indicate that the terminal device has successfully configured the PDCP entity of one or more DRBs corresponding to the session. For another example, if the terminal device has not successfully activated the integrity security protection of the session, the terminal device sends a response message #2 to the network device to indicate that the terminal device has not successfully activated the integrity security protection of the session. Optionally, the response message #2 may carry a failure reason value, for example, the failure reason value may be used to indicate that the verification of the first integrity security protection indication information has failed.
[0238] Optionally, in the scenario where the connection between the network device and the ground core network is disconnected, the network device performs integrity check on the received uplink message and / or data, and stores the uplink data if the integrity check passes. If the integrity check fails, the uplink data is not stored or is discarded. This can ensure network communication security while reducing the risk of DoS attacks. For the specific implementation method, please refer to the relevant description of the following method 500, which will not be explained here.
[0239] It should be noted that the above method 300 is described using user plane integrity security protection, user plane integrity security policy, or integrity verification as an example. This is merely an example for ease of understanding and does not limit the technical solution of the present application. Optionally, the technical solution of the present application is also applicable to user plane confidentiality security protection, user plane confidentiality security policy, or decryption operations. For specific implementation methods, please refer to the relevant description above and will not be described here.
[0240] In the solution provided above in the present application, the network device determines whether to activate the integrity security protection of the session based on the first information. In addition, the user plane integrity security policy and / or the local policy of the network device can be considered to enable or activate the integrity security protection of the session as much as possible, so that the user plane data received by the network device is protected by integrity security to the greatest extent. In the scenario where the feeder link is disconnected, only the user plane data that has passed the integrity check is stored, which not only alleviates the potential risk of denial of service DoS attacks, but also ensures the security of network communications.
[0241] FIG5 is a flow chart of a communication method 500 provided in an embodiment of the present application. As shown in FIG5 , the terminal device is a UE, the network device is a base station, and the core network element is an AMF or SMF as the execution subject to interact. For the convenience of description, the present application may refer to a base station deployed on a satellite as a satellite base station, and a base station deployed on a non-satellite, such as a base station deployed on the ground, as a ground base station. This method can be regarded as a further refinement of the above-mentioned method 400. It should be understood that the embodiment shown in FIG5 and the embodiment shown in FIG4 can be coupled with each other and can refer to each other. Therefore, the relevant description in the above-mentioned method 400 is also applicable to this implementation method. The same or similar technical means may exist between the two. The content described in the embodiment shown in FIG4 will not be repeated. The method includes the following multiple steps. The part not fully described can refer to the above-mentioned method 400 or the existing protocol.
[0242] S501: UE registers with the network.
[0243] Optionally, the embodiments of the present application do not limit the number of UEs registered to the same network. It should be understood that for scenarios where multiple UEs are registered to the network, the process for each UE to establish a session, and the specific implementation of activating or deactivating user plane integrity security protection for the session are similar. For ease of description, this implementation is described using an example of a UE registering to the network, establishing a session, and determining whether to activate or deactivate user plane integrity security protection for the session.
[0244] S502: The UE sends a session establishment request message to the AMF. Correspondingly, the AMF receives the session establishment request message from the UE.
[0245] Among them, a session can correspond to one or more DRBs. It should be understood that the session is used to transmit data between the UE and the core network. For example, a session is used to transmit one or more data. The one or more data can be carried by the one or more DRBs respectively. Usually, one DRB carries one data.
[0246] S503, AMF sends a session creation context request message to SMF, and correspondingly, SMF receives the session creation context request message from AMF.
[0247] S504, SMF sends a session creation context response message to AMF, and correspondingly, AMF receives the session creation context response message from SMF.
[0248] S505, AMF sends a session resource establishment request message to the satellite base station, and correspondingly, the satellite base station receives the session resource establishment request message from AMF.
[0249] The specific implementation of steps S501 to S505 may refer to the relevant description of the method 300.
[0250] S506: The satellite base station determines whether to activate the integrity security protection of the session according to the first information. In other words, the satellite base station activates or does not activate the integrity security protection of the session according to the first information.
[0251] It should be understood that whether to activate the integrity security protection of the session can be understood as whether to activate the integrity security protection of one or more DRBs corresponding to the session, or whether integrity security protection is enabled for the data transmitted between the terminal device and the network device.
[0252] Optionally, before executing step S506, the satellite base station obtains first information. For example, the first information includes one or more of capability information, configuration information, or location information of the network device. For the specific implementation of obtaining the first information and the meaning of the first information, refer to the description of step S410 of method 400 above.
[0253] Below, an example is given of a satellite base station determining whether to activate the integrity security protection of a session based on the first information, or in other words, a satellite base station activating or not activating the integrity security protection of a session based on the first information, including one or more of the following. For specific implementation methods, please refer to the relevant description of the above method 400.
[0254] (1) The satellite base station determines whether to activate the integrity security protection of the session based on the capability information. In other words, the satellite base station determines whether to activate or not activate the integrity security protection of the session based on the capability information.
[0255] (2) The satellite base station determines whether to activate the integrity security protection of the session according to the configuration information, or in other words, the satellite base station activates or does not activate the integrity security protection of the session according to the configuration information.
[0256] (3) The base station determines whether to activate the integrity security protection of the session based on the location information. In other words, the base station activates or does not activate the integrity security protection of the session based on the location information.
[0257] Optionally, the satellite base station can determine whether to activate the integrity security protection of the session based on the first information and the user plane integrity security policy carried in the above step S505, or in other words, the satellite base station activates or does not activate the integrity security protection of the session based on the first information and the user plane integrity security policy. An example illustration includes one or more of the following. The specific implementation method can refer to the relevant description of step S404 of the above method 400.
[0258] (1) The satellite base station determines whether to activate the integrity security protection of the session based on the capability information and the user plane integrity security policy. In other words, the satellite base station activates or does not activate the integrity security protection of the session based on the capability information and the user plane integrity security policy.
[0259] (2) The satellite base station determines whether to activate the integrity security protection of the session based on the configuration information and the user plane integrity security policy. In other words, the satellite base station activates or does not activate the integrity security protection of the session based on the base station configuration information and the user plane integrity security policy.
[0260] (3) The base station determines whether to activate the integrity security protection of the session based on the location information and the user plane integrity security policy. In other words, the satellite base station activates or does not activate the integrity security protection of the session based on the location information and the user plane integrity security policy.
[0261] S507 , the satellite base station sends an RRC reconfiguration message to the UE. Correspondingly, the UE receives the RRC reconfiguration message from the satellite base station.
[0262] Exemplarily, the RRC reconfiguration message may be an RRC Reconfiguration message.
[0263] The RRC reconfiguration message includes one or more DRB identifiers (e.g., DRB IDs) corresponding to the session, and an integrity security protection indication of the one or more DRBs, wherein the integrity security protection indication is used to indicate whether integrity security protection is enabled for the one or more DRBs, or whether integrity security protection needs to be activated for the one or more DRBs.
[0264] In addition, the RRC reconfiguration message may also include the session acceptance message carried in step S505.
[0265] S508: The UE performs an integrity check on the RRC reconfiguration message.
[0266] Optionally, if the integrity check passes, the UE configures the PDCP entity of the one or more DRBs.
[0267] S509 , the UE sends an RRC reconfiguration completion message to the satellite base station. Correspondingly, the satellite base station receives the RRC reconfiguration completion message from the UE.
[0268] Exemplarily, the RRC reconfiguration completion message may be an RRC Reconfiguration Complete message.
[0269] S510, the satellite base station sends a session resource establishment response message to the AMF, and correspondingly, the AMF receives the session resource establishment response message from the satellite base station.
[0270] The specific implementation of steps S509 to S510 may refer to the relevant description of the method 300.
[0271] In the following steps S511-S514, in the scenario where the connection between the satellite base station and the ground core network is disconnected, the satellite base station performs integrity check on the received uplink data to determine whether to store the uplink data, thereby reducing the risk of DoS attacks while ensuring network communication security.
[0272] S511, the connection between the satellite base station and the ground core network is disconnected, such as the feeder link is disconnected.
[0273] Exemplarily, the triggering conditions for feeder link disconnection include one or more of the following:
[0274] (1) The satellite base station flies to the side away from the ground gateway station, that is, the ground gateway station cannot receive the signal transmitted by the satellite base station;
[0275] (2) The communication conditions between the satellite base station and the ground gateway station deteriorate, such as encountering bad weather or the signal quality falling below a certain threshold;
[0276] (3)Other conditions.
[0277] S512: The UE sends uplink data to the satellite base station. Correspondingly, the satellite base station receives the uplink data from the UE.
[0278] It should be noted that if the integrity security protection indication carried in the RRC reconfiguration message of the above step S507 is used to indicate that one or more DRBs corresponding to the session have integrity security protection enabled, the UE needs to perform integrity security protection on the uplink data before sending the uplink data; or, if the integrity security protection indication carried in the RRC reconfiguration message is used to indicate that one or more DRBs corresponding to the session do not have integrity security protection enabled, the UE does not need to perform integrity security protection on the uplink data before sending the uplink data.
[0279] S513: The satellite base station performs integrity check on the uplink data.
[0280] Exemplarily, the triggering conditions for the satellite base station to perform integrity check on uplink data include one or more of the following:
[0281] (1) The satellite base station supports store-and-forward operation and the feeder link is disconnected;
[0282] (2) The satellite base station starts the store-and-forward operation and the feeder link is disconnected.
[0283] Optionally, the triggering conditions may also include:
[0284] (3) The load of the satellite base station is greater than a first threshold. The first threshold may be predefined, such as defined by a protocol, or the first threshold may be configured or preconfigured, which is not limited in this application.
[0285] The specific implementation methods of integrity verification include any of the following:
[0286] (1) The satellite base station performs integrity check on all received uplink data;
[0287] (2) The satellite base station determines whether to perform integrity check on the received uplink data based on the session granularity.
[0288] Exemplarily, if the satellite base station determines in step S506 to activate the user plane integrity security protection of the session, the satellite base station needs to perform integrity verification on the one or more uplink data received by the satellite base station through one or more DRBs corresponding to the session; or, if the satellite base station determines in step S506 not to activate the user plane integrity security protection of the session, the satellite base station does not need to perform integrity verification on the one or more uplink data received by the satellite base station through one or more DRBs corresponding to the session, and optionally, the satellite base station can directly discard the one or more uplink data.
[0289] (3) The satellite base station determines whether to perform integrity check on the received uplink data based on the DRB granularity.
[0290] Exemplarily, if the satellite base station determines in step S506 that the user plane integrity security protection of the session can be optionally activated, the satellite base station can further determine whether to activate the user plane integrity security protection of the one or more DRBs based on local policies, such as its own load conditions. Assuming that the session corresponds to two DRBs (such as DRB#1 and DRB#2), when it is determined according to the first information and / or the user plane integrity security policy that the user plane integrity security protection of the session can be optionally enabled, the satellite base station determines according to its own load that DRB#1 enables user plane integrity security protection, and DRB#2 does not enable user plane integrity security protection. Then, for the uplink data #1 received by the satellite base station through the DRB#1, the satellite base station needs to perform integrity verification on the uplink data #1. For the uplink data #2 received by the satellite base station through the DRB#2, the satellite base station does not need to perform integrity verification on the uplink data #2. Optionally, the satellite base station can directly discard the uplink data #2.
[0291] Among them, the MAC value calculation and judgment method involved in the integrity verification process can refer to the relevant description of the above method 300, which will not be repeated here.
[0292] S514: The satellite base station determines whether to store the uplink data according to the verification result.
[0293] The check result is used to indicate whether the satellite base station passes the integrity check of the received uplink data in the above step S513, including whether the check is successful (passed) or failed (failed).
[0294] Exemplarily, the satellite base station stores uplink data that passes the integrity check, does not store or discards uplink data without integrity security protection, or does not store or discards uplink data that fails the integrity check.
[0295] Based on the solution provided above, the satellite base station determines whether to activate the integrity security protection of the session based on one or more of the user plane integrity security policy, local policy, satellite base station capability information, configuration information, or location information, and turns on the session integrity security protection as much as possible, so that the user plane data received by the satellite base station is protected by integrity security to the greatest extent. In the scenario where the feeder link is disconnected, the satellite base station only stores data that has passed the integrity check, which can alleviate potential DoS risks and ensure network communication security.
[0296] It should be understood that the above Figures 4 and 5 show that during the session establishment process of the terminal device, the satellite base station activates the integrity security protection of the session to the maximum extent according to the first information, thereby mitigating potential DoS risks and ensuring network communication security. Compared with Figures 4 and 5, the schemes shown in Figures 6 and 7 below reduce the processing load of the UE and the satellite base station by releasing the session and / or DRB for which integrity security protection is not activated, or by modifying the integrity security protection state of the session and / or DRB to an activated state, when the feeder link is disconnected, thereby avoiding potential DoS risks and ensuring network communication security.
[0297] Figure 6 is a flow chart of a communication method provided by an embodiment of the present application. This method 600 can be executed by a terminal device, a network device, and a core network element (e.g., a session management element), or it can also be executed by a chip or circuit of the terminal device, the network device, and the core network element (e.g., a session management element), or it can also be implemented by a logic module or software that can implement all or part of the functions of the communication device, and this application does not limit this. The following is an example of the execution subject being a terminal device, a network device, and a session management element. As shown in Figure 6, the method includes the following multiple steps. For the parts not described in detail, please refer to the above methods 300-500 or existing protocols.
[0298] S610: The network device obtains a user plane integrity security policy corresponding to the session.
[0299] Among them, the user plane integrity security policy is used to indicate whether integrity security protection is activated for the session, or whether the data transmitted by the session needs to have integrity security protection enabled. For the value of the user plane integrity security policy and its specific meaning, as well as its expression, please refer to the relevant description of the above method 300 or 400, which will not be repeated here.
[0300] In one implementation, the network device obtains the user plane integrity security policy corresponding to the session from the session management network element, for example, see the following step S602.
[0301] S602: The session management network element sends a user plane integrity security policy corresponding to the session to the network device. Correspondingly, the network device receives the user plane integrity security policy corresponding to the session from the session management network element.
[0302] The specific implementation method may refer to the relevant description of step S402 of the above method 400, which will not be described again here.
[0303] Optionally, before executing step S602, the session management network element determines the user plane integrity security policy of the session. For example, the session management network element may determine the user plane integrity security policy of the session based on the acquired indication information, for example, see the following step S601.
[0304] S601: The session management network element obtains instruction information.
[0305] The specific meaning of the indication information and the specific implementation method of obtaining the indication information can be referred to the relevant description of step S402 of the above method 400, which will not be described again here.
[0306] In a first implementation manner, the session management network element may determine the user plane integrity security policy corresponding to the session according to the indication information.
[0307] In the second implementation, the session management network element may enable session integrity security protection based on the contract information of the terminal device.
[0308] In a third implementation manner, the session management network element may determine the user plane integrity security policy corresponding to the session based on the indication information and the subscription information of the terminal device.
[0309] Among them, the specific meaning of the contract information, the method of obtaining the contract information, and examples of the above three implementation methods can refer to the relevant description of step S401 of method 400.
[0310] S620: The network device determines first integrity security protection indication information according to the user plane integrity security policy.
[0311] The first integrity security protection indication information is used to indicate whether to activate integrity security protection for the first DRB, that is, the first integrity security protection indication information is used to indicate whether to turn on integrity security protection for the session. The first DRB corresponds to the session in step S610 above. It should be understood that the session is used to transmit data between the terminal device and the core network, and the first DRB is used to transmit data between the terminal device and the network device.
[0312] Exemplarily, the values of the user plane integrity security policy include required, preferred, and not needed. For example, when the value of the user plane integrity security policy is required, the network device can determine that the first integrity security protection indication information is used to indicate that the session turns on integrity security protection; when the value of the user plane integrity security policy is not needed, the network device can determine that the first integrity security protection indication information is used to indicate that the session does not turn on integrity security protection; when the value of the user plane integrity security policy is preferred, the network device can determine that the first integrity security protection indication information is used to indicate that the session optionally turns on integrity security protection. For specific implementation methods, please refer to the relevant description of the above method 300.
[0313] Optionally, the present application does not specifically limit the form of expression of the first integrity security protection indication information. For details, please refer to the relevant description of step S420 of the above method 400.
[0314] S621: The network device activates or deactivates the integrity security protection of the first DRB according to the first integrity security protection indication information.
[0315] Exemplarily, when the first integrity security protection indication information indicates that integrity security protection is enabled for the session, the network device activates the integrity security protection of the first DRB; when the first integrity security protection indication information indicates that integrity security protection is not enabled for the session, the network device does not activate the integrity security protection of the first DRB; when the first integrity security protection indication information indicates that integrity security protection is optionally enabled for the session, the network device may activate the integrity security protection of the first DRB according to local policies. For specific implementation methods, please refer to the relevant description of the above method 300.
[0316] Among them, activating the integrity security protection of the first DRB can be understood as: the network device configures the PDCP entity of the first DRB, configures the integrity security protection key and integrity security protection algorithm of the first DRB in the PDCP entity, and activates the integrity verification of the uplink user plane messages and / or data carried by the first DRB, and activates the integrity security protection of the downlink user plane messages and / or data carried by the first DRB; not activating the integrity security protection of the first DRB can be understood as: the network device configures the PDCP entity of the first DRB, but there is no need to configure the integrity security protection key and integrity security protection algorithm of the first DRB in the PDCP entity, nor is there any need to activate the integrity verification of the uplink user plane messages and / or data carried by the first DRB, and there is no need to activate the integrity security protection of the downlink user plane messages and / or data carried by the first DRB.
[0317] S630, when the first link is disconnected, the network device determines whether to release the first DRB according to whether the integrity security protection of the first DRB is activated, or the network device determines whether to modify the integrity security protection status of the first DRB according to whether the integrity security protection of the first DRB is activated.
[0318] Exemplarily, when the integrity security protection of the first DRB is activated or turned on, the network device determines that there is no need to release the session and / or the first DRB.
[0319] Exemplarily, when the integrity security protection of the first DRB is not activated or turned on, the network device determines to release the session and / or the first DRB.
[0320] Exemplarily, when the integrity security protection of the first DRB is activated or turned on, the network device determines that there is no need to modify the integrity security protection status of the session and / or the first DRB, that is, at this time the integrity security protection status of the session and / or the first DRB is activated.
[0321] Exemplarily, when the integrity security protection activated by the first DRB is not activated or turned on, the network device determines to modify the integrity security protection state of the session and / or the first DRB, that is, to change it from an inactivated state to an activated state.
[0322] Among them, the first link is a link between the network device and the core network. For example, the first link can be a feeder link. The triggering condition for disconnection of the first link can refer to the relevant description of step S511 of the above method 500 and will not be explained here.
[0323] Optionally, when the first link is disconnected, the network device determines whether to release the first DRB based on the first integrity security protection indication information, or the network device determines whether to modify the integrity security protection status of the first DRB based on the first integrity security protection indication information.
[0324] In other words, when the first link is disconnected, the network device determines whether to release the first DRB based on the first integrity security protection indication information, or the network device determines whether to modify the integrity security protection status of the first DRB based on the first integrity security protection indication information.
[0325] Exemplarily, when the first integrity security protection indication information indicates that the integrity security protection of the first DRB is not activated or turned on, the network device determines to release the session and / or the first DRB.
[0326] Exemplarily, when the first integrity security protection indication information indicates to activate or turn on the integrity security protection of the first DRB, the network device determines not to release the session and / or the first DRB.
[0327] Exemplarily, when the first integrity security protection indication information indicates that the integrity security protection of the first DRB is not activated or turned on, the network device determines to modify the integrity security protection state of the session and / or the first DRB to an activated state.
[0328] Exemplarily, when the first integrity security protection indication information indicates to activate or turn on the integrity security protection of the first DRB, the network device determines to keep the integrity security protection state of the session and / or the first DRB as activated.
[0329] For the above-mentioned network device, releasing the session and / or the first DRB for which integrity security protection is not activated or optionally activated, or the network device modifies the integrity security protection state of the session and / or the first DRB to an activated state, the corresponding triggering conditions may include one or more of the following:
[0330] (1) The network device supports store-and-forward operations and the feeder link is disconnected;
[0331] (2) The network device starts the store-and-forward operation and the feeder link is disconnected.
[0332] (3) The load of the network device is greater than a first threshold. The first threshold may be predefined, such as a protocol definition, or the first threshold may be configured or preconfigured, which is not limited in this application.
[0333] (4) The value of the user plane integrity security policy obtained by the satellite base station is preferred.
[0334] Optionally, the network device may store the identifier of the session and / or the first DRB; and / or record that the integrity security protection state of the session and / or the first DRB before modification is in an inactivated state, for subsequent targeted restoration of the session and / or the first DRB and its integrity security protection state before modification.
[0335] Optionally, the present application does not limit the storage of the identifier of the session and / or the first DRB; and / or, the timing of recording the integrity security protection status of the session and / or the first DRB as inactive before modification. For example, the network device may do so after sending the first message to the terminal device, that is, after step S640, and / or, the network device may do so before sending the second message to the terminal device. The specific implementation method can refer to the relevant description of the following step S660, which will not be explained here.
[0336] S640, the network device sends a first message to the terminal device, and correspondingly, the terminal device receives the first message from the network device.
[0337] The first message is used to indicate a release result or a modification result of the session and / or the first DRB. Optionally, the first message may be an RRC reconfiguration message, such as an RRC Reconfiguration message.
[0338] Exemplarily, when the first integrity security protection indication information indicates that the first DRB does not activate integrity security protection, the release result indicates the release of the session and / or the first DRB.
[0339] Exemplarily, when the first integrity security protection indication information indicates that the first DRB activates integrity security protection, the release result indicates that the session and / or the first DRB is not released.
[0340] Exemplarily, when the first integrity security protection indication information indicates that the integrity security protection of the first DRB is not activated, the modification result indicates that the integrity security protection state of the session and / or the first DRB is modified to an activated state.
[0341] Exemplarily, when the first integrity security protection indication information indicates that the first DRB activates integrity security protection, the modification result indicates that the integrity security protection state of the first DRB is kept activated.
[0342] S650: The terminal device performs an integrity check on the first message.
[0343] Exemplarily, the terminal device may determine whether the integrity check passes by comparing MAC values. For specific implementations, reference may be made to the relevant description of the above method 300 and will not be described again here.
[0344] S660: When the integrity check passes, the terminal device determines whether to release the first DRB based on the release result, or determines whether to modify the integrity security protection status of the first DRB based on the modification result.
[0345] That is to say, after the terminal device receives the first message, when the integrity check of the first message passes, the terminal device can further determine whether to release the session and / or the first DRB, or whether to modify the integrity security protection status of the session and / or the first DRB.
[0346] For example, if the first message indicates to release the first DRB, the terminal device releases the session and / or the first DRB, and the subsequent terminal device cannot send uplink data through the session and / or the first DRB, and cannot receive downlink data through the session and / or the first DRB; for another example, if the first message indicates not to release the first DRB, the terminal device does not release the session and / or the first DRB, and the subsequent terminal device can still send uplink data through the session and / or the first DRB, and receive downlink data through the session and / or the first DRB. At the same time, whether integrity security protection is enabled for the session and / or the first DRB depends on the user plane integrity security policy. For specific implementation methods, please refer to the relevant description of the above method 300.
[0347] For example, if the first message indicates that the integrity security protection state of the first DRB is modified to be activated, the terminal device modifies the integrity security protection state of the session and / or the first DRB to be activated; for another example, if the first message indicates that the integrity security protection state of the first DRB is kept activated, the terminal device does not need to modify the integrity security protection state of the session and / or the first DRB. The terminal device can subsequently send uplink data through the session and / or the first DRB, and receive downlink data through the session and / or the first DRB. It should be noted that the uplink and downlink data carried on the first DRB are integrity security protected and need to be integrity checked.
[0348] Optionally, if the integrity verification passes, the terminal device can reconfigure the PDCP entity of the first DRB. For example, if the first message indicates the release of the first DRB, the terminal device deletes the PDCP entity of the first DRB, including deleting the integrity security protection key and integrity security protection algorithm of the first DRB; if the first message indicates the modification of the integrity security protection state of the first DRB to the activated state, the terminal device configures the integrity security protection key and integrity security protection algorithm in the PDCP entity corresponding to the first DRB, which means that it is necessary to activate the integrity security protection of the uplink user plane messages and / or data carried by the first DRB, and activate the integrity check of the downlink user plane messages and / or data carried by the first DRB.
[0349] Optionally, the terminal device may send a response message #1 to the network device, indicating that the terminal device has successfully released the first DRB, or indicating that the terminal device has successfully modified the integrity security protection state of the first DRB to an activated state. Optionally, if the first message of the above step S640 is carried in the RRC reconfiguration message, the terminal device may send an RRC reconfiguration completion message to the network device. If the terminal device fails to successfully release the first DRB, or the terminal device fails to successfully modify the integrity security protection state of the first DRB to an activated state, the terminal device may send a response message #2 to the network device. Optionally, the response message #2 may carry a failure reason value, for example, the failure reason value may be used to indicate that the verification of the first integrity security protection indication information has failed, etc.
[0350] Optionally, in the scenario where the connection between the network device and the ground core network is disconnected, the network device performs an integrity check on the received uplink message and / or data, and stores the uplink data if the integrity check passes. If the integrity check fails, the uplink data is not stored or is discarded. This can ensure the security of network communications while reducing the risk of DoS attacks. For the specific implementation method, please refer to the relevant description of the following method 700 or 800, which will not be explained here.
[0351] Optionally, in one implementation, when the first link restores connection, the network device may send a second message to the terminal device, where the second message is used to indicate the establishment of a second DRB, and the second message includes second integrity security protection indication information, where the second integrity security protection indication information is used to indicate that the second DRB does not activate integrity security protection, and the second DRB is used to carry data between the terminal device and the network device.
[0352] Optionally, the second DRB can be a DRB re-established between the terminal device and the network device, or it can be the first DRB released as determined in the above step S630, or the first DRB whose integrity security protection state is modified to an activated state. This application does not limit this. This implementation method is to facilitate normal communication between subsequent terminal devices and network devices.
[0353] Optionally, the second message includes an identifier of the first DRB, and / or the second integrity security protection indication information is determined based on the fact that the integrity security protection state of the first DRB before modification is in an inactivated state. That is, the network device may determine that the integrity security protection of the re-established second DRB is inactivated or not enabled based on the fact that the integrity security protection state of the first DRB before modification recorded in the above step S630 is inactivated. Optionally, the network device may also determine not to activate or enable the integrity security protection of the second DRB based on the user plane integrity security policy of the session, which is not limited in this application.
[0354] It should be noted that the above method 600 is described using user plane integrity security protection, user plane integrity security policy, or integrity verification as an example. This is merely an example for ease of understanding and does not limit the technical solution of the present application. Optionally, the technical solution of the present application is also applicable to user plane confidentiality security protection, user plane confidentiality security policy, or decryption operations. For specific implementation methods, please refer to the relevant description above and will not be described here.
[0355] Based on the solution provided above, the network device determines whether to release the first DRB based on the user plane integrity security policy, or changes the integrity security protection state of the first DRB to an activated state, so that the user plane data subsequently received by the network device are all protected by integrity security. In the scenario where the feeder link is disconnected, the satellite base station only stores the user plane data that has passed the integrity check, which can alleviate potential DoS risks and ensure network communication security.
[0356] Figure 7 is a flow chart of a communication method 700 provided in an embodiment of the present application. As shown in Figure 7, the terminal device is the UE, the core network element is the AMF, and the SMF is the execution subject for interaction. This method can be regarded as a further refinement of the above-mentioned method 600, and is mainly used for explaining the release of sessions and / or DRBs for which integrity security protection is not activated by satellite base stations and UEs. It should be understood that the embodiment shown in Figure 7 and the embodiment shown in Figure 6 can be coupled with each other and can be used as references to each other. Therefore, the relevant descriptions in the above-mentioned method 600 are also applicable to this implementation method. The same or similar technical means may exist between the two, and the contents described in the embodiment shown in Figure 6 will not be repeated. The method includes the following multiple steps, and the parts that are not fully described can refer to the above-mentioned method 600 or the existing protocol.
[0357] S701, UE1 and UE2 register with the network.
[0358] Optionally, the embodiments of the present application do not limit the number of UEs registered to the same network. For ease of description, this implementation is described using an example in which two UEs (e.g., UE1 and UE2) register with the network, establish a session, and determine whether to activate or deactivate user plane integrity security protection for the session. The process for establishing a session between UE1 and UE2, as well as the specific implementation of activating or deactivating user plane integrity security protection for the session, are similar, and the repeated parts will not be repeated below.
[0359] S702, UE1 sends a session establishment request message to AMF, and correspondingly, AMF receives the session establishment request message from UE1.
[0360] S703, AMF sends a session creation context request message to SMF, and correspondingly, SMF receives the session creation context request message from AMF.
[0361] S704, SMF sends a session creation context response message to AMF, and correspondingly, AMF receives the session creation context response message from SMF.
[0362] S705, AMF sends a session resource establishment request message to the satellite base station, and correspondingly, the satellite base station receives the session resource establishment request message from the AMF.
[0363] S706 , the satellite base station sends an RRC reconfiguration message # 1 to UE1 , and correspondingly, UE1 receives the RRC reconfiguration message # 1 from the satellite base station.
[0364] S707, UE1 performs integrity check on RRC reconfiguration message #1.
[0365] S708 , UE1 sends an RRC reconfiguration complete message # 1 to the satellite base station. Correspondingly, the satellite base station receives the RRC reconfiguration complete message # 1 from UE1.
[0366] S709, the satellite base station sends a session resource establishment response message to the AMF, and correspondingly, the AMF receives the session resource establishment response message from the satellite base station.
[0367] The specific implementation of the above steps S701 to S709 can refer to the relevant description of the above method 300.
[0368] The following steps address the potential DoS risk after the feeder link is disconnected. The satellite base station releases the non-integrity security-protected sessions and / or DRBs between it and UE2, reducing the processing load on both UE2 and the satellite base station. Furthermore, after the feeder link is reconnected, the satellite base station triggers the addition of the previously released non-integrity security-protected sessions and / or DRBs to ensure communication between UE2 and the satellite base station.
[0369] S710, the connection between the satellite base station and the ground core network is disconnected, such as the feeder link is disconnected, wherein the triggering condition of the feeder link disconnection can refer to the relevant description of step S511 of the above method 500.
[0370] S711: The satellite base station releases the session and / or DRB for which integrity security protection is not activated.
[0371] It should be understood that a session and / or DRB without activated integrity security protection means that the integrity security protection of the session and / or DRB is not turned on, or in other words, the user plane data carried on the session and / or DRB is not security protected and does not require integrity verification.
[0372] Among them, the triggering conditions for the satellite base station to release the session and / or DRB for which integrity security protection is not activated can refer to the relevant description of the above method 600 and will not be explained here.
[0373] Exemplarily, the satellite base station may determine the session and / or DRB that needs to be released based on the user plane integrity security policy received in step S705. For example, if the user plane integrity security policy indicates that integrity security protection is enabled for session #1 (or one or more DRB #1s corresponding to the session) between UE1 and the satellite base station, the satellite base station does not release the session #1 or the one or more DRB #1s; for another example, if the user plane integrity security policy indicates that integrity security protection is not enabled or can be optionally enabled for session #2 (or one or more DRB #2s corresponding to the session) between UE2 and the satellite base station, the satellite base station releases the session #2 or the one or more DRB #2s.
[0374] Furthermore, after determining that one or more DRB#2s need to be released, the satellite base station can release the PDCP entities corresponding to the one or more DRB#2s. In other words, all uplink data subsequently received by the satellite base station is integrity-protected, such as uplink data received through one or more DRB#1s. Therefore, it is necessary to perform integrity checks on all received uplink data.
[0375] S712: The satellite base station sends an RRC reconfiguration message #2 to UE2. Correspondingly, UE2 receives the RRC reconfiguration message #2 from the satellite base station.
[0376] In one example, the RRC reconfiguration message #2 includes a session ID and / or a DRB ID, for example, for identifying the session #2 or the one or more DRBs #2 for which integrity security protection is not activated in step S711. For example, the RRC reconfiguration message #2 may carry a drb-ToReleaseList information element, which includes the ID of the DRB for which integrity security protection is not activated, for example, the DRB #2 ID.
[0377] It should be understood that before releasing the session #2 or the one or more DRB#2s, the integrity security protection activation status of the session #2 or the one or more DRB#2s is in an inactive state, or in other words, the integrity security protection of the session #2 or the one or more DRB#2s is not enabled, indicating that the user plane data carried on the session #2 or the one or more DRB#2s has not been integrity-secured and no integrity check is required.
[0378] Optionally, the satellite base station stores the released Session#2ID and / or DRB#2ID. Optionally, the stored Session#2ID and / or DRB#2ID can be used to restore Session#2 and / or DRB#2 in the subsequent step S720.
[0379] S713: UE2 releases the session and / or DRB for which integrity security protection is not activated.
[0380] In one example, the UE releases the corresponding Session #2 and / or DRB #2 based on the Session #2 ID and / or DRB #2 ID. For example, UE2 releases the PDCP entity corresponding to DRB #2. In other words, UE2 cannot transmit user plane data with the satellite base station via Session #2 and / or DRB #2.
[0381] It should be noted that since the user plane integrity security protection of session #2 and / or DRB #2 is not enabled before releasing session #2 and / or DRB #2, the RRC reconfiguration message #2 in the above step S712 does not need to undergo integrity security protection. Correspondingly, UE2 does not need to perform integrity verification on RRC reconfiguration message #2.
[0382] S714, UE2 sends an RRC reconfiguration complete message #2 to the satellite base station. Correspondingly, the satellite base station receives the RRC reconfiguration complete message #2 from the UE.
[0383] Exemplarily, the RRC reconfiguration complete message #2 is used to indicate that UE2 has released session #2 and / or DRB #2.
[0384] S715 , UE1 sends uplink data to the satellite base station, and correspondingly, the satellite base station receives the uplink data from UE1.
[0385] It should be noted that since integrity security protection is enabled for session #1 or DRB #1 between UE1 and the satellite base station, UE1 needs to perform integrity security protection on the uplink data before sending it. For the specific implementation method, please refer to the relevant description of the above method 300.
[0386] S716: The satellite base station performs integrity check on the uplink data.
[0387] Exemplarily, the triggering conditions for the satellite base station to perform integrity check on uplink data include one or more of the following:
[0388] (1) The satellite base station supports store-and-forward operation and the feeder link is disconnected;
[0389] (2) The satellite base station starts the store-and-forward operation and the feeder link is disconnected.
[0390] (3) The load of the satellite base station is greater than a first threshold. The first threshold may be predefined, such as a protocol definition, or the first threshold may be configured or preconfigured, which is not limited in this application.
[0391] (4) The value of the integrity security policy received by the satellite base station is "preferred".
[0392] It should be noted that, based on the above steps S711 and S713, the satellite base station and the UE have released the session and / or DRB for which integrity security protection has not been activated, indicating that the uplink data sent by the UE is integrity security protected, which also means that the satellite base station needs to perform integrity verification on all uplink data received in the above step S715. The specific implementation method of the integrity verification can refer to the relevant description of the above method 300, which will not be repeated here.
[0393] S717: The satellite base station determines whether to store the uplink data based on the verification result.
[0394] The verification result includes verification success (pass) or verification failure (failure). It should be understood that the satellite base station stores uplink data that passes the integrity verification and discards uplink data that fails the integrity security protection verification.
[0395] S718, the connection between the satellite base station and the ground core network is restored, such as the feeder link is restored.
[0396] The triggering conditions for feeder link recovery include one or more of the following:
[0397] (1) The satellite base station flies to the side close to the ground gateway station, that is, the ground gateway station can receive the signal transmitted by the satellite base station;
[0398] (2) The communication conditions between the satellite base station and the ground gateway station are good.
[0399] S719 , the satellite base station sends an RRC reconfiguration message #3 to UE2. Correspondingly, UE2 receives the RRC reconfiguration message #3 from the satellite base station.
[0400] Exemplarily, RRC reconfiguration message #3 is used to instruct UE2 to add (or reestablish) session #3 and / or DRB #3, which are used to transmit data between UE2 and the satellite base station. Optionally, session #3 and / or DRB #3 may be the same as or different from the released session #2 and / or DRB #2, and this application does not limit this. For example, RRC reconfiguration message #3 carries a drb-ToAddModList information element, which includes session #3 ID and / or DRB #3 ID and its corresponding integrity security protection indication.
[0401] Optionally, DRB#3ID can be the released DRB ID (for example, DRB#2ID) stored by the satellite base station in the above step S712. At this time, the RRC reconfiguration message #3 is used to instruct UE2 to re-establish the previously released session #2 and / or DRB#2, and according to the integrity security protection indication carried in the RRC reconfiguration message #3, the integrity security protection of the session #2 and / or DRB#2 is not enabled.
[0402] Exemplarily, the triggering condition for the satellite base station to send the RRC reconfiguration message #3 includes one or more of the following:
[0403] (1) Feeder link restoration;
[0404] (2) The load of the satellite base station itself is lower than a second threshold. The second threshold may be predefined, such as defined by a protocol, or the second threshold may be configured or preconfigured.
[0405] Optionally, the second threshold value may be the same as or different from the first threshold value in the above step S716, and this application does not limit this.
[0406] S720, UE2 establishes a session and / or DRB according to the session ID and / or DRB ID.
[0407] Exemplarily, UE2 re-establishes session #3 based on session #3ID, and determines that the integrity security protection of session #3 is not enabled based on the integrity security protection indication corresponding to session #3; in other words, UE2 re-establishes DRB #3 based on DRB #3ID, and determines that the integrity security protection of DRB #3 is not enabled based on the integrity security protection indication corresponding to DRB #3, that is, UE2 configures the PDCP entity corresponding to DRB #3. Since the integrity security protection of DRB #3 is not activated, UE2 does not need to configure the integrity security protection key and integrity security protection algorithm in the PDCP entity.
[0408] It should be noted that in the above steps S718-S720, in the case of feeder link recovery, it is an optional operation for the UE and the satellite base station to re-establish the above-mentioned released session and / or DRB with inactivated integrity security protection. Whether the satellite base station and the UE rebuild the session and / or DRB depends on the satellite base station policy, which is not limited in this application.
[0409] It should be noted that in the above examples, whether the user plane integrity security protection of one or more DRBs corresponding to the session is enabled is consistent. Optionally, whether the user plane integrity security protection of multiple DRBs corresponding to the session is enabled may be different. For example, if the value of the integrity security policy corresponding to session #a established between the satellite base station and UE1 is preferred, it means that the integrity security protection of session #a is optionally enabled, which means that the user plane integrity security protection of DRB#a and DRB#b corresponding to session #a is optionally enabled. Furthermore, the satellite base station can determine to enable the user plane integrity security protection of DRB#a based on local policies or its own load conditions, and not to enable the user plane integrity security protection of DRB#b, that is, the satellite base station determines that DRB#b needs to be released. Furthermore, the satellite base station can notify UE1 to release DRB#b through an RRC reconfiguration message, and subsequently UE1 and the satellite base station can transmit data through DRB#a, and the transmitted data is integrity security protected, and DRB#b cannot be used to transmit data between UE1 and the satellite base station. Furthermore, when the feeder link is restored, the satellite base station may instruct UE1 to add (or re-establish) DRB#c without enabling user plane integrity security protection for the DRB#c. Optionally, the DRB#c may be the same as or different from DRB#b. For a specific implementation, reference may be made to steps S710 to S714 of method 700, and the description of steps S718 to S720. For the sake of brevity, these descriptions are omitted here.
[0410] The solution provided by this application is that, in the scenario where the feeder link is disconnected, the satellite base station releases the session and / or DRB without integrity security protection, so that the uplink data subsequently received by the satellite base station is integrity security protected. The satellite base station also avoids receiving uplink data without integrity security protection, alleviates the potential DoS risk, and reduces the processing load of the UE and the satellite base station. In addition, after the feeder link is restored, the satellite base station triggers the addition of a session and / or DRB without integrity security protection to ensure normal communication between the UE and the satellite base station.
[0411] Compared with the solution shown in Figure 7 above, in combination with Figure 8 below, when the feeder link between the satellite base station and the UE is disconnected, the satellite base station and the UE will change the integrity security protection status of the inactivated integrity security protected session and / or DRB to an activated state, so that the uplink data transmitted between the UE and the satellite base station are all securely protected, avoiding potential DoS risks, while ensuring normal communication between the UE and the satellite base station.
[0412] Figure 8 is a flow chart of a communication method 800 provided in an embodiment of the present application. As shown in Figure 8, the terminal device is the UE and the session management network element is the SMF as the execution body to interact. This method can be regarded as a further refinement of the above-mentioned method 400. It should be understood that the embodiment shown in Figure 8 and the embodiment shown in Figure 6 can be coupled with each other and can refer to each other. Therefore, the relevant description in the above-mentioned method 600 is also applicable to this implementation. The same or similar technical means may exist between the two. The content described in the embodiment shown in Figure 6 or Figure 7 will not be repeated. The method includes the following multiple steps. For the parts not described in detail, please refer to the above-mentioned methods 600-700 or existing protocols.
[0413] S801: UE registers with the network.
[0414] S802: The UE sends a session establishment request message to the AMF. Correspondingly, the AMF receives the session establishment request message from the UE.
[0415] S803, AMF sends a session creation context request message to SMF, and correspondingly, SMF receives the session creation context request message from AMF.
[0416] S804, SMF sends a session creation context response message to AMF, and correspondingly, AMF receives the session creation context response message from SMF.
[0417] S805, AMF sends a session resource establishment request message to the satellite base station, and correspondingly, the satellite base station receives the session resource establishment request message from the AMF.
[0418] S806 , the satellite base station sends an RRC reconfiguration message # 1 to the UE. Correspondingly, the UE receives the RRC reconfiguration message # 1 from the satellite base station.
[0419] S807: The UE performs an integrity check on the RRC reconfiguration message #1.
[0420] S808 , the UE sends an RRC reconfiguration complete message # 1 to the satellite base station. Correspondingly, the satellite base station receives the RRC reconfiguration complete message # 1 from the UE.
[0421] S809, the satellite base station sends a session resource establishment response message to the AMF, and correspondingly, the AMF receives the session resource establishment response message from the satellite base station.
[0422] For the specific implementation of steps S801 to S809 , reference may be made to the description of steps S701 to S709 of method 700 .
[0423] The following steps address the situation where, after the feeder link is disconnected, the satellite base station modifies the non-integrity-security protected sessions and / or DRBs to activate integrity security, mitigating potential DoS risks and reducing the processing load on the UE and satellite base station. Furthermore, after the feeder link is reconnected, the satellite base station triggers the previously activated DRBs to revert to their previous non-integrity-security state, ensuring communication between the UE and the satellite base station.
[0424] S810, the connection between the satellite base station and the ground core network is disconnected, such as the feeder link is disconnected, wherein the triggering condition of the feeder link disconnection can refer to the relevant description of step S511 of the above method 500.
[0425] S811, the satellite base station changes the integrity security protection state of the session and / or DRB for which integrity security protection is not activated to an activated state.
[0426] It should be understood that a session and / or DRB without activated integrity security protection means that the integrity security protection of the session and / or DRB is not turned on, or in other words, the user plane data carried on the session and / or DRB is not security protected and does not require integrity verification.
[0427] Among them, the triggering conditions for the satellite base station to modify the integrity security protection status of the session and / or DRB that has not activated integrity security protection to the activated state can refer to the relevant description of the above method 600 and will not be explained here.
[0428] Exemplarily, the satellite base station may determine the session and / or DRB whose integrity security protection state needs to be modified based on the user plane integrity security policy received in step S805. For example, if the user plane integrity security policy indicates that integrity security protection is enabled for the session between the UE and the satellite base station (or one or more DRBs corresponding to the session), the satellite base station does not need to modify the integrity security protection state of the session or the one or more DRBs; for another example, if the user plane integrity security policy indicates that integrity security protection is not enabled or can be optionally enabled for the session between the UE and the satellite base station (or one or more DRBs corresponding to the session), the satellite base station may modify the integrity security protection state of the session or the one or more DRBs to be activated.
[0429] Furthermore, after determining that the session and / or DRB in the integrity security protection state needs to be modified, the satellite base station modifies the PDCP entity corresponding to the DRB accordingly. For example, the satellite base station configures the integrity security protection key and integrity security protection algorithm in the PDCP entity. At the same time, the satellite base station activates the integrity security protection of the downlink data on the DRB, and activates the integrity check of the uplink data on the DRB. In other words, all uplink data subsequently received by the satellite base station through the DRB is integrity security protected, so it is necessary to perform integrity check on the uplink data received through the DRB.
[0430] S812: The satellite base station sends an RRC reconfiguration message #2 to the UE. Correspondingly, the UE receives the RRC reconfiguration message #2 from the satellite base station.
[0431] In one example, the RRC reconfiguration message #2 includes a session ID and / or a DRB ID, and the integrity security protection activation state of the session and / or DRB corresponding to the session ID and / or DRB ID is an inactive state. In addition, the RRC reconfiguration message #2 also includes an integrity security protection indication corresponding to the session and / or DRB, and the integrity security protection indication is used to instruct the UE to activate (or turn on) the integrity security protection of the session and / or DRB. That is, the RRC reconfiguration message #2 is used to instruct the UE to modify the integrity security protection state of the session and / or DRB, that is, to change it from an inactive state to an active state. For example, the RRC reconfiguration message #2 carries a drb-ToAddModList information element, which includes a session ID and / or DRB ID for which integrity security protection is not activated.
[0432] Optionally, the satellite base station records the session ID and / or DRB ID whose integrity security protection state has been modified, or records that the integrity security protection state of the session and / or DRB before the modification is in an inactive state, or records that the integrity security policy of the session and / or DRB before the modification indicates that integrity security protection is not enabled, etc. Optionally, the recorded session ID and / or DRB ID is used to restore the integrity security protection state of the session and / or DRB to an inactive state in the subsequent step S820.
[0433] S813, the UE changes the integrity security protection state of the session and / or DRB to an activated state.
[0434] That is to say, the integrity security protection state of the session / DRB before the modification is in an inactive state, and the integrity security protection state of the session / DRB after the modification is in an active state.
[0435] In one example, the UE modifies the integrity security protection state of the corresponding session and / or DRB to an activated state according to the session ID and / or DRB ID. For example, the UE modifies the PDCP entity corresponding to the DRB, including: configuring the integrity security protection key and the integrity security protection algorithm in the PDCP entity. At the same time, the UE activates the integrity security protection of the uplink data on the DRB, and activates the integrity check of the downlink data on the DRB. In other words, all uplink data subsequently sent by the UE through the session and / or DRB are integrity-secured, so the satellite base station also needs to perform integrity check on the uplink data received through the session and / or DRB.
[0436] S814, the UE sends an RRC reconfiguration complete message #2 to the satellite base station. Correspondingly, the satellite base station receives the RRC reconfiguration complete message #2 from the UE.
[0437] Exemplarily, the RRC reconfiguration complete message #2 is used to indicate that the UE has modified the integrity security protection state of the session and / or DRB to an activated state.
[0438] S815, the UE sends uplink data to the satellite base station, and correspondingly, the satellite base station receives the uplink data from the UE.
[0439] It should be noted that since the UE has modified the integrity security protection status of the session and / or DRB that has not activated integrity security protection to an activated state, the UE needs to perform integrity security protection on the uplink data before sending the uplink data. For the specific implementation method, please refer to the relevant description of the above method 300.
[0440] S816: The satellite base station performs integrity check on the uplink data.
[0441] S817: The satellite base station determines whether to store the uplink data based on the verification result.
[0442] S818, the connection between the satellite base station and the ground core network is restored, such as the feeder link is restored.
[0443] Among them, the specific implementation method of the above steps S816-S818, the triggering conditions of the integrity check, and the triggering conditions of the feeder link recovery can refer to the relevant description of steps S716-S718 of the above method 700.
[0444] S819 , the satellite base station sends an RRC reconfiguration message #3 to the UE. Correspondingly, the UE receives the RRC reconfiguration message #3 from the satellite base station.
[0445] The triggering condition for the satellite base station to send the RRC reconfiguration message #3 may refer to the relevant description of step S719 of the above method 700.
[0446] Exemplarily, RRC reconfiguration message #3 is used to instruct the UE to add (or reestablish) a session and / or DRB, and the added or reestablished session and / or DRB is used for subsequent data transmission between the UE and the satellite base station. Optionally, the added or reestablished session and / or DRB may be the same as or different from the above-mentioned session and / or DRB whose user plane integrity security protection state is modified to an activated state, and this application does not limit this. For example, the RRC reconfiguration message #3 carries a drb-ToAddModList information element, which includes a session ID and / or DRB ID, and its corresponding integrity security protection indication.
[0447] Optionally, the session ID is the session ID whose integrity security protection status has been modified as recorded by the satellite base station in the above step S812. At this time, the RRC reconfiguration message #3 is used to instruct the UE to modify the integrity security protection status of the session and / or DRB, that is, from an activated state to an inactivated state. The integrity security protection indication is used to indicate that the integrity security protection of the session and / or DRB is not enabled.
[0448] S820, the UE modifies the integrity security protection state of the session and / or DRB to an inactive state according to the session ID and / or DRB ID.
[0449] Exemplarily, the UE modifies the integrity security protection state of the corresponding session and / or DRB according to the session ID and / or DRB ID to an inactive state, that is, the integrity security protection of the session and / or DRB is not enabled. For example, the UE modifies the PDCP entity corresponding to the DRB. Since the integrity security protection of the DRB is not enabled, the UE does not need to configure the integrity security protection key and integrity security protection algorithm in the PDCP entity. For example, the satellite base station deletes the integrity security protection key and integrity security protection algorithm corresponding to the PDCP entity.
[0450] It should be noted that in the above steps S818-S820, in the case of feeder link recovery, it is optional for the UE and the satellite base station to modify the integrity security protection state of the session and / or DRB. Whether the satellite base station and the UE modify the integrity security protection state of the session and / or DRB to the inactive state depends on the satellite base station policy, which is not limited in this application.
[0451] It should be noted that in the above examples, whether the user plane integrity security protection of one or more DRBs corresponding to the session is enabled is consistent. Optionally, whether the user plane integrity security protection of multiple DRBs corresponding to the session is enabled may be different. For example, if the value of the integrity security policy corresponding to session #a established between the satellite base station and the UE is preferred, it means that the integrity security protection of session #a is optionally enabled, which also means that the integrity security protection of DRB#a and DRB#b corresponding to session #a is optionally enabled. Further, the satellite base station can determine to activate the integrity security protection of DRB#a based on local policies or its own load conditions, and not to activate the integrity security protection of DRB#b, that is, the satellite base station determines that the integrity security protection state of DRB#b needs to be modified to an activated state, that is, the modified DRB#b turns on integrity security protection. Further, the satellite base station can notify the UE through an RRC reconfiguration message to modify the integrity security protection state of DRB#b to an activated state. Subsequently, the UE and the satellite base station can transmit data through DRB#a and DRB#b, and the transmitted data is integrity security protected. Furthermore, when the feeder link is restored, the satellite base station can instruct the UE to modify the integrity security protection status of the DRB#b to an inactivated state. The specific implementation method can refer to steps S810 to S814 of method 800 and the relevant descriptions of steps S818 to S820. For the sake of brevity, they will not be repeated here.
[0452] The solution provided by this application is that, in the scenario where the feeder link is disconnected, the satellite base station modifies the integrity security protection status of the session without integrity security protection and / or DRB to the activated state, so that all uplink data subsequently received by the satellite base station is integrity security protected. The satellite base station also avoids receiving uplink data without integrity security protection, mitigating the potential DoS risk. In addition, after the feeder link is restored, the satellite base station triggers the restoration of the session and / or DRB that were modified to enable integrity security protection to the inactivated state, ensuring the communication connection between the UE and the satellite base station.
[0453] Figure 9 is a flow chart of a communication method 900 provided in an embodiment of the present application. As shown in Figure 9, the terminal device is the UE, the core network element is the AMF, and the SMF is the execution subject for interaction. This method can be regarded as a further refinement of the above-mentioned method 400 or 600, and is mainly explained for SMF to determine the user plane integrity security policy based on the indication information and / or contract information. It should be understood that the embodiment shown in Figure 9 and the embodiments shown in Figures 4 to 8 can be coupled with each other and can refer to each other. Therefore, the relevant descriptions in the above-mentioned methods 400 to 800 are also applicable to this implementation method. The same or similar technical means may exist between the two, and the contents described in the embodiments shown in Figures 4 to 8 will not be repeated. The method includes the following multiple steps, and the parts that are not fully described can refer to the existing protocol.
[0454] S901, UE registers to the network.
[0455] S902, the UE sends a session establishment request message to the AMF, and correspondingly, the AMF receives the session establishment request message from the UE.
[0456] The specific implementation of the above steps S901 and S902 can refer to the relevant description of the above method 300.
[0457] S903, AMF sends a session creation context request message to SMF, and correspondingly, SMF receives the session creation context request message from AMF.
[0458] The session creation context request message carries indication information, where the indication information is used to indicate that the base station is deployed on a satellite (referred to as a satellite base station for short). Optionally, the indication information is also used to indicate that the satellite base station supports a store-and-forward feature.
[0459] Optionally, the AMF obtains one or more of the capability information, configuration information, or location information of the base station through a local query or by sending a query message to the OAM or UDM. For specific explanations, refer to the relevant description of the above method 500. The AMF can determine through the query that the base station is deployed on a satellite. Optionally, the AMF can also determine that the satellite base station supports the store-and-forward feature.
[0460] S904, SMF determines the user plane integrity security policy of the session based on the indication information and / or contract information.
[0461] Optionally, the indication information can be obtained by SMF from AMF, or by SMF from OAM or UDM.
[0462] Optionally, the contract information can be obtained by SMF from UDM or PCF.
[0463] In the first example, the SMF determines the user plane integrity security policy of the session according to the indication information.
[0464] In the second example, the SMF determines the user plane integrity security policy based on the subscription information.
[0465] The UE's subscription information is used to indicate whether the UE has subscribed to the store-and-forward operation service.
[0466] Optionally, this application does not limit the order in which the SMF obtains the contract information and indication information.
[0467] In the third example, the SMF determines the user plane integrity security policy based on the indication information and the subscription information.
[0468] For the specific implementation in the above example, reference may be made to the relevant description of step S401 of the above method 400 .
[0469] S905, SMF sends a session creation context response message to AMF, and correspondingly, AMF receives the session creation context response message from SMF.
[0470] S906, AMF sends a session resource establishment request message to the satellite base station, and correspondingly, the satellite base station receives the session resource establishment request message from the AMF.
[0471] S907 , the satellite base station sends an RRC reconfiguration message to the UE. Correspondingly, the UE receives the RRC reconfiguration message from the satellite base station.
[0472] It should be noted that, for the integrity security policy value determined in the above step S904 to be preferred, the satellite base station can further determine whether the integrity security policy is required or not needed based on the local policy. For specific implementation methods, please refer to the relevant description of the above method 300.
[0473] S908: The UE performs an integrity check on the RRC reconfiguration message.
[0474] S909 , the UE sends an RRC reconfiguration completion message to the satellite base station. Correspondingly, the satellite base station receives the RRC reconfiguration completion message from the UE.
[0475] The specific implementation of steps S905 to S909 may refer to the relevant description of the method 300.
[0476] S910, the satellite base station sends a session resource establishment response message to the AMF, and correspondingly, the AMF receives the session resource establishment response message from the satellite base station.
[0477] S911, the connection between the satellite base station and the ground core network is disconnected, such as the feeder link is disconnected, wherein the triggering condition of the feeder link disconnection can refer to the relevant description of step S511 of the above method 500.
[0478] S912, the UE sends uplink data to the satellite base station, and correspondingly, the satellite base station receives the uplink data from the UE.
[0479] S913: The satellite base station performs integrity check on the uplink data.
[0480] Among them, the triggering conditions for the satellite base station to perform integrity check on the uplink data, and the specific implementation method of the satellite base station to perform integrity check on the uplink data can refer to the relevant description of step S513 of the above method 500, which will not be repeated here.
[0481] S914: The satellite base station determines whether to store the uplink data based on the verification result.
[0482] For the specific implementation, please refer to the relevant description of step S514 of the above method 500.
[0483] The solution provided by this application uses an integrity security policy set by indication information to ensure that user plane data subsequently received by the satellite base station undergoes integrity security protection to the greatest extent possible, mitigating potential DoS risks and reducing the processing load on the UE and base station. In the event of a feeder link disconnection, the satellite base station can only store data that passes the integrity check to ensure network security.
[0484] The communication method embodiment of the present application is described in detail above with reference to Figures 1 to 9 . The communication device embodiment of the present application will be described in detail below with reference to Figures 10 and 11 . It should be understood that the description of the device embodiment corresponds to the description of the method embodiment. Therefore, for portions not described in detail, reference can be made to the aforementioned method embodiment.
[0485] Figure 10 is a schematic diagram of a communication device provided in accordance with an embodiment of the present application. As shown in Figure 10, the communication device 1000 includes a processing module 1010 and a communication module 1020. The communication device 1000 may be a terminal device, or a communication device applied to or used in conjunction with a terminal device and capable of implementing a method executed by the terminal device, such as a chip, a chip system, or a circuit; or the communication device 1000 may be a network device, or a communication device applied to or used in conjunction with a network device and capable of implementing a method executed by the network device, such as a chip, a chip system, or a circuit; or the communication device 1000 may be a session management network element, or a communication device applied to or used in conjunction with a session management network element and capable of implementing a method executed by the session management network element, such as a chip, a chip system, or a circuit.
[0486] The communication module may also be referred to as a transceiver module, transceiver, transceiver, or transceiver device. The processing module may also be referred to as a processor, processing board, processing unit, or processing device. Optionally, the communication module is used to perform the sending and receiving operations of the terminal device and network device in the above method. The device used to implement the receiving function in the communication module can be considered a receiving unit, and the device used to implement the sending function in the communication module can be considered a sending unit. That is, the communication module includes a receiving unit and a sending unit.
[0487] When the communication apparatus 1000 is applied to a terminal device, the processing module 1010 may be used to implement the processing functions of the terminal device in the above embodiments, and the communication module 1020 may be used to implement the transceiver functions of the terminal device in the above embodiments.
[0488] When the communication device 1000 is applied to a network device, the processing module 1010 may be used to implement the processing functions of the network device in the above embodiments, and the communication module 1020 may be used to implement the transceiver functions of the network device in the above embodiments.
[0489] When the communication device 1000 is applied to a session management network element, the processing module 1010 can be used to implement the processing functions of the session management network element in the above embodiments, and the communication module 1020 can be used to implement the sending and receiving functions of the session management network element in the above embodiments.
[0490] In addition, it should be noted that the aforementioned communication module and / or processing module can be implemented by a virtual module, for example, the processing module can be implemented by a software functional unit or a virtual device, and the communication module can be implemented by a software function or a virtual device. Alternatively, the processing module or the communication module can also be implemented by a physical device, for example, if the device is implemented using a chip / circuit (such as an integrated circuit or a logic circuit, etc.). The communication module can be an input and output circuit and / or a communication interface, performing input operations (corresponding to the aforementioned receiving operations) and output operations (corresponding to the aforementioned sending operations); the processing module is an integrated processor or microprocessor or circuit (such as an integrated circuit or a logic circuit, etc.).
[0491] The division of modules in this application is illustrative and represents only a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the examples of this application may be integrated into a single processor, exist physically as separate modules, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in either hardware or software functional modules.
[0492] Figure 11 is a schematic diagram of another communication device provided in an embodiment of the present application. As shown in Figure 11, communication device 2000 can optionally be the aforementioned terminal device, network device, or session management network element, or a chip or chip system for the aforementioned terminal device, network device, or session management network element. Optionally, in the present application, the chip system can be composed of a chip, or can include a chip and other discrete components.
[0493] The communication device 2000 can be used to implement the functions of any device (e.g., a terminal device, a network device, or a session management network element) in the communication system described in the above examples. The communication device 2000 may include at least one processing circuit 2010. Optionally, the processing circuit 2010 is coupled to a memory, and the memory may be located within the device, or the memory may be integrated with the processor, or the memory may be located outside the device. For example, the communication device 2000 may also include at least one memory 2020. The memory 2020 stores the necessary computer programs, computer programs or instructions and / or data for implementing any of the above examples; the processing circuit 2010 may execute the computer program stored in the memory 2020 to complete the method in any of the above examples.
[0494] The communication device 2000 may also include a transceiver circuit 2030, and the communication device 2000 can exchange information with other devices through the transceiver circuit 2030. Exemplarily, the transceiver circuit 2030 can be a transceiver, circuit, bus, module, pin or other type of communication interface. When the communication device 2000 is a chip-type device or circuit, the transceiver circuit 2030 in the device 2000 can also be an input-output circuit, or an interface circuit, which can input information (or receive information) and output information (or send information). When the communication device 2000 is a network device or terminal device, the transceiver circuit 2030 can be a transmitter, a receiver or a transceiver, or a communication interface, which is not limited here.
[0495] The processing circuit 2010 may be one or more processors, or all or part of the processing circuits in one or more processors. The processing circuit 2010 may be an integrated processor, microprocessor, integrated circuit, or logic circuit, and the processor may determine output information based on input information.
[0496] Coupling in this application refers to an indirect coupling or communication connection between devices, units, or modules, and can be electrical, mechanical, or other forms, used for information exchange between devices, units, or modules. Processing circuit 2010 may operate in conjunction with memory 2020 and transceiver circuit 2030. This application does not limit the specific connection medium between the processing circuit 2010, memory 2020, and transceiver circuit 2030.
[0497] Optionally, as shown in FIG11 , the processing circuit 2010, the memory 2020, and the transceiver circuit 2030 are interconnected via a bus 2040. Optionally, the bus may include an address bus, a data bus, a control bus, or other types of buses. Furthermore, for ease of illustration, FIG11 shows one bus 2040, but this does not mean that there is only one bus or only one type of bus.
[0498] It should be understood that the processors mentioned in the embodiments of the present application may be the following devices or the circuit portions of the following devices used for processing functions: a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0499] It should also be understood that the memory mentioned in the embodiments of the present application may be a volatile memory and / or a non-volatile memory. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM includes the following forms: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0500] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, the memory (storage module) can be integrated into the processor.
[0501] It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0502] An embodiment of the present application also provides a computer-readable storage medium on which computer instructions are stored for implementing the methods executed by at least one of a terminal device, a network device, or a session management network element in the above-mentioned method embodiments.
[0503] An embodiment of the present application also provides a computer program product comprising code or instructions, which, when executed by a computer, implements the method performed by at least one of a terminal device, a network device, or a session management network element in the above-mentioned method embodiments.
[0504] An embodiment of the present application also provides a communication system, which includes at least one of the core network element, session management network element, or network device in the above embodiments.
[0505] Optionally, the communication system further includes the terminal device in the above embodiments.
[0506] The explanation of the relevant contents and beneficial effects of any of the above-mentioned devices can be referred to the corresponding method embodiments provided above and will not be described again here.
[0507] To facilitate understanding of the above embodiments provided in this application, the following points are explained:
[0508] 1) In this application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0509] 2) In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b and c can mean: a, or b, or c, or a and b, or a and c, or b and c, or a, b and c. Where a, b and c can be single or multiple, respectively.
[0510] 3) Throughout this application, the terms "first," "second," and various numerical references (e.g., #1, #2, etc.) are used to distinguish between different messages for ease of description and are not intended to limit the scope of the embodiments of this application. For example, they are used to distinguish between different messages, rather than to describe a specific order or precedence. It should be understood that such references are interchangeable, where appropriate, to allow for the description of scenarios beyond the embodiments of this application.
[0511] 4) In this application, descriptions such as "when...", "in the case of...", and "if" all mean that the device will perform corresponding processing under certain objective circumstances. They do not limit the time, nor do they require the device to perform judgment actions when implementing them, nor do they mean that there are other limitations.
[0512] 5) In this application, "indicate" or "used to indicate" can include being used for direct indication and being used for indirect indication. When describing that a certain indication information is used to indicate A, it can include that the indication information directly indicates A or indirectly indicates A, and does not necessarily mean that the indication information carries A.
[0513] The indication methods involved in the embodiments of this application should be understood to encompass various methods that enable the party to be indicated to obtain information about the information to be indicated. The information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately. The transmission period and / or timing of these sub-information can be the same or different. This application does not limit the transmission method, for example.
[0514] In the embodiments of the present application, the "indication information" may be an explicit indication, i.e., a direct indication via signaling, or may be obtained based on parameters indicated by the signaling, in combination with other rules, other parameters, or by deduction. It may also be an implicit indication, i.e., based on a rule or relationship, or based on other parameters, or by deduction. This application does not impose specific limitations on this.
[0515] 6) In this application, "protocol" may refer to a standard protocol in the field of communications, such as 5G protocol, NR protocol, and related protocols used in future communication systems, which is not limited in this application. "Predefined" may include pre-definition. For example, protocol definition. "Preconfiguration" can be implemented by pre-saving corresponding codes, tables, or other methods that can be used to indicate relevant information in the device, and this application does not limit its implementation method.
[0516] 7) In this application, "communication" may also be described as "data transmission", "information transmission", "data processing", etc. "Transmission" includes "sending" and "receiving".
[0517] 8) In this application, "sending information to XX (device)" can be understood as the destination of the information being the device. This can include sending information directly or indirectly to the device. "Receiving information from XX (device)" can be understood as the source of the information being the device, which can include receiving information directly or indirectly from the device. The information may undergo necessary processing between the source and destination, such as format changes, but the destination can still understand the valid information from the source.
[0518] In various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0519] In this application, under the premise of no logical contradiction, the examples can reference each other, for example, the methods and / or terms between method embodiments can reference each other, for example, the functions and / or terms between device embodiments can reference each other, for example, the functions and / or terms between device examples and method examples can reference each other.
[0520] It should be understood that in some of the above embodiments, the devices in the existing network architecture are mainly used as examples for illustrative description, and the specific form of the devices is not limited in the embodiments of the present application. For example, devices that can achieve the same functions in the future are applicable to the embodiments of the present application.
[0521] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0522] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be described again here.
[0523] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0524] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0525] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0526] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disk.
[0527] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A secure communication method, which is applied to a network device or a chip in the network device, characterized in that, including: During the session establishment process of the terminal device, determine whether to activate the integrity security protection of the session according to the first information, where the first information is used to indicate whether the network device supports the store-and-forward operation, and the session is used to transmit data between the terminal device and the core network; Send the first integrity security protection indication information to the terminal device, where the first integrity security protection indication information is used to indicate the activation result.
2. The method according to claim 1, characterized in that The determining whether to activate the integrity security protection of the session according to the first information includes: When the first information indicates that the network device supports the store-and-forward operation, determine to activate the integrity security protection of the session; and / or, When the first information indicates that the network device does not support the store-and-forward operation, determine not to activate the integrity security protection of the session.
3. The method according to claim 1 or 2, characterized in that, Before determining whether to activate the integrity security protection of the session according to the first information, it includes: Obtain the user plane integrity security policy corresponding to the session, where the user plane integrity security policy is used to indicate whether to activate the integrity security protection of the session; The determining whether to activate the integrity security protection of the session according to the first information includes: Determine whether to activate the integrity security protection of the session according to the first information and the user plane integrity security policy.
4. The method according to claim 3, wherein The determining whether to activate the integrity security protection of the session according to the first information and the user plane integrity security policy includes: When the first information indicates that the network device does not support the store-and-forward operation, and the user plane integrity security policy indicates that the session activates or optionally activates the integrity security protection, determine to activate the integrity security protection of the session; and / or, When the first information indicates that the network device does not support the store-and-forward operation, and the user plane integrity security policy indicates that the session does not activate the integrity security protection, determine not to activate the integrity security protection of the session.
5. The method according to claim 3 or 4, characterized in that, The determining whether to activate the integrity security protection of the session according to the first information and the user plane integrity security policy includes: When the first information indicates that the network device supports the store-and-forward operation, and the user plane integrity security policy indicates that the session activates or optionally activates the integrity security protection, determine to activate the integrity security protection of the session; and / or, When the first information indicates that the network device supports the store-and-forward operation, and the user plane integrity security policy indicates that the session does not activate the integrity security protection, determine to activate the integrity security protection of the session.
6. A secure communication method, characterized in that, The method is applied to a terminal device or a chip in the terminal device, and includes: During the session establishment process of the terminal device, receive the first integrity security protection indication information from the network device, where the first integrity security protection indication information is used to indicate whether to activate the integrity security protection of the session, and the first integrity security protection indication information is determined according to the first information, and the first information is used to indicate whether the network device supports the store-and-forward operation; Determine whether to activate the integrity security protection of the session according to the first integrity security protection indication information.
7. The method according to claim 6, wherein when the first information indicates that the network device supports the store-and-forward operation, the first integrity security protection indication information is used to indicate activating the integrity security protection of the session; and / or when the first information indicates that the network device does not support the store-and-forward operation, the first integrity security protection indication information is used to indicate not activating the integrity security protection of the session.
8. A secure communication method, which is applied to a network device or a chip in a network device, characterized in that, including: During the session establishment process of the terminal device, obtain the user plane integrity security policy corresponding to the session, where the user plane integrity security policy is used to indicate whether to activate the integrity security protection of the session, and the session is used to transmit data between the terminal device and the core network; Determine the first integrity security protection indication information according to the user plane integrity security policy, where the first integrity security protection indication information is used to indicate whether to activate the integrity security protection of the first data radio bearer (DRB), the session corresponds to the first DRB, and the first DRB is used to carry data between the terminal device and the network device; Activate or deactivate the integrity security protection of the first DRB according to the first integrity security protection indication information; When the first link is disconnected, determine whether to release the first DRB according to whether the integrity security protection of the first DRB is activated, or determine whether to modify the integrity security protection state of the first DRB according to whether the integrity security protection of the first DRB is activated, where the first link is the link between the network device and the core network; Send a first message to the terminal device, where the first message is used to indicate the release result or modification result of the first DRB.
9. The method according to claim 8, wherein The determining whether to release the first DRB according to whether the integrity security protection of the first DRB is activated includes: When the integrity security protection of the first DRB is not activated, determine to release the first DRB.
10. The method according to claim 8, characterized in that, The determining whether to modify the integrity security protection state of the first DRB according to whether the integrity security protection of the first DRB is activated includes: When the integrity security protection of the first DRB is not activated, determine to modify the integrity security protection state of the first DRB to the activated state.
11. The method according to any one of claims 1 to 10, characterized in that, The method further includes: When the first link is restored, send a second message to the terminal device, where the second message is used to indicate that the terminal device establishes a second DRB, the second message includes second integrity security protection indication information, and the second integrity security protection indication information is used to indicate that the second DRB does not activate the integrity security protection, and the second DRB is used to carry data between the terminal device and the network device.
12. The method according to claim 11, wherein The second DRB is the first DRB; Before sending the second message to the terminal device, and / or after sending the first message to the terminal device, the method further includes: Store the identifier of the first DRB; and / or, record that the integrity security protection status of the first DRB before modification is the inactive state; Wherein, the second message includes the identifier of the first DRB, and / or, the second integrity security protection indication information is determined according to the integrity security protection status of the first DRB before modification being the inactive state.
13. The method according to any one of claims 8 to 12, characterized in that, The method further includes: Receive first data from the terminal device through the first DRB; When the first integrity security protection indication information indicates to activate the integrity security protection of the first DRB, perform integrity verification on the first data; When the integrity verification passes and the first link is disconnected, store the first data.
14. The method according to claim 13, wherein Before storing the first data, the method further includes: When the integrity verification passes, determine whether the first link is disconnected.
15. The method according to claim 13, characterized in that, Before performing integrity verification on the first data, the method further includes: Determine whether the first link is disconnected.
16. A secure communication method, characterized in that, The method is applied to a terminal device or a chip in the terminal device, and includes: When the first link is disconnected, receive a first message from the network device, where the first message is used to indicate the release result or modification result of the first data radio bearer (DRB), the release result is used to indicate whether to activate the first DRB, the modification result is used to indicate whether to modify the integrity security protection status of the first DRB, the release result or the modification result is determined according to whether the integrity security protection of the first DRB is activated, the first DRB is used to carry data between the terminal device and the network device, and the first link is the link between the network device and the core network; Determine whether to release the first DRB according to the release result, or determine whether to modify the integrity security protection status of the first DRB according to the modification result.
17. The method according to claim 16, wherein, When the first DRB does not activate integrity security protection, the release result indicates to release the first DRB.
18. The method according to claim 16, wherein, When the first DRB does not activate integrity security protection, the modification result indicates to modify the integrity security protection status of the first DRB to the active state.
19. A secure communication method, characterized in that, The method is applied to a session management network element or a chip in the session management network element, and includes: During the session establishment process of the terminal device, obtain indication information, where the indication information is used to indicate that the network device is deployed on a satellite; Determine the user plane integrity security policy corresponding to the session according to the indication information, where the user plane integrity security policy is used to indicate to activate or optionally activate integrity security protection for the session; Send the user plane integrity security policy to the network device.
20. The method according to claim 19, characterized in that, The indication information is further used to indicate that the network device supports store-and-forward operations.
21. The method according to claim 19 or 20, characterized in that The method further includes: Obtain subscription information, where the subscription information is used to indicate whether the terminal device subscribes to the store-and-forward operation service; Determining the user plane integrity security policy according to the indication information includes: Determine the user plane integrity security policy according to the indication information and the subscription information.
22. The method according to claim 21, wherein The determining of the user plane integrity security policy according to the indication information and the subscription information includes: When the subscription information indicates that the terminal device subscribes to the store-and-forward operation service, determine that the integrity security policy is used to indicate session activation integrity security protection.
23. A communication device, characterized in that, Comprising at least one module, where the at least one module is used to execute the method according to any one of claims 1 to 22.
24. A communication device, characterized in that, Comprising: At least one processor, where the at least one processor is used to execute a computer program or instruction so that the method according to any one of claims 1 to 22 is executed.
25. The communication device according to claim 24, wherein The communication device further comprises a memory, where the memory is used to store the computer program or instruction; and / or The communication device further comprises a communication interface, where the communication interface is coupled to the at least one processor, and the communication interface is used to input and / or output information.
26. The communication device according to claim 24 or 25, characterized in that, The communication device is a chip or a chip system.
27. A communication system, characterized in that, Comprising: At least one of a network device, a terminal device, or a session management network element, where the network device is used to execute the method according to any one of claims 1 to 5, 8 to 15, the terminal device is used to execute the method according to any one of claims 6 or 7, 16 to 18, and the session management network element is used to execute the method according to any one of claims 19 to 22.
28. A computer-readable storage medium, characterized in that, Computer program code or instruction is stored on the computer-readable storage medium, and when the computer program code or instruction runs on a computer, the method according to any one of claims 1 to 22 is executed.
29. A computer program product, characterized in that, Containing instructions, when the instructions are run, the method according to any one of claims 1 to 22 is executed.
Citation Information
Patent Citations
Data processing method and device
CN110830993A
Safety protection method and device
CN111641582A
Internet of Things information transmission method, terminal and system in low earth orbit satellite Internet of Things
CN113271558A
Certificate transmission method and device, communication equipment and storage medium
CN115868188A
Communication method and device, equipment and storage medium
CN116830627A