Communication method and apparatus
The access network equipment determines the activation of user plane security protection based on the energy information of the terminal equipment, and solves the problem of increasing energy consumption of access network equipment and achieves the effect of energy saving and consumption reduction.
Patent Information
- Application Number
- PCT/CN2025/074785
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-09
- Filing Date
- 2025-01-24
- Publication Date
- 2025-08-14
AI Technical Summary
In the prior art, when access network equipment performs user surface security protection, energy consumption increases, operator operating costs increase and environmentally unfavorable.
The access network device receives the user plane security policy of the session management function network element and decides whether to activate the security protection of the data wireless bearer based on the energy information of the terminal device, including user plane encryption and/or integrity protection.
By combining the energy information of terminal equipment, security protection is reasonably activated, energy consumption of access network equipment is reduced, unnecessary security protection is avoided, and energy saving is achieved.
Smart Images

Figure CN2025074785_14082025_PF_FP_ABST
Abstract
Description
Communication method and device
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on February 9, 2024, with application number 202410179438.4 and application name "A Communication Method and Device", the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of communication technology, and in particular to a communication method and device. Background Art
[0004] Operators deploy access networks and core networks. After connecting to the core network via the access network, terminal devices can transmit data with various entities via access network equipment and core network elements. To improve the security of data transmitted over the air interface, terminal devices and access network equipment can implement user-plane security protection, such as encryption and / or integrity protection. However, implementing user-plane security protection increases energy consumption in access network equipment, leading to higher operating costs for operators and negatively impacting the environment. Summary of the Invention
[0005] The present application provides a communication method and apparatus that help reduce energy consumption of access network equipment for user plane security protection.
[0006] In a first aspect, an embodiment of the present application provides a communication method, comprising: an access network device in a network receives a user plane security policy from a session management function network element in the network, the user plane policy corresponding to a session of a terminal device; when the user plane security policy indicates priority, the access network device determines whether to activate security protection of the data wireless bearer of the session based on energy information corresponding to the terminal device; wherein the energy information corresponding to the terminal device is used to indicate the energy consumed by the network to transmit data of the terminal device, or the energy information corresponding to the terminal device is used to indicate the energy efficiency corresponding to the network transmitting data of the terminal device.
[0007] Based on the above method, the access network device determines whether to activate the security protection of the data wireless bearer in combination with the energy information corresponding to the terminal device, so that the decision on whether to activate the security protection is consistent with the energy consumption or energy efficiency corresponding to the network transmission of the data of the terminal device, which helps to avoid unnecessary security protection and reduce the energy consumption of the access network device for user plane security protection.
[0008] In one possible design, user plane security protection includes user plane encryption (UP confidentiality) and / or user plane integrity protection (UP integrity protection).
[0009] In one possible design, the energy information corresponding to the terminal device includes energy information corresponding to the session, the energy consumed by the network in transmitting the data of the terminal device includes energy consumed by the network in transmitting the session data of the terminal device, and the energy efficiency corresponding to the network transmitting the data of the terminal device includes energy efficiency corresponding to the network transmitting the session data of the terminal device. The energy information corresponding to the session helps to more accurately determine whether to activate security protection of the data radio bearer of the session.
[0010] In one possible design, the access network device receives energy information corresponding to the terminal device from the first network element. This design facilitates the access network device to quickly determine whether to activate security protection of the data radio bearer of the session based on the energy information corresponding to the terminal device.
[0011] In one possible design, the access network device determines whether to activate the security protection of the data radio bearer of the session based on the energy information corresponding to the terminal device, including: when the energy information corresponding to the terminal device meets the first condition, the access network device determines not to activate the security protection of the data radio bearer of the session; wherein, when the energy information corresponding to the terminal device indicates the energy consumed by the network to transmit the data of the terminal device, the first condition indicates that the difference between the energy and the energy quota is less than or equal to the first threshold; or, when the energy information corresponding to the terminal device indicates the energy consumed by the network to transmit the data of the terminal device, the first condition indicates that the ratio of the energy to the energy quota is greater than or equal to the second threshold; or, when the energy information corresponding to the terminal device indicates the energy consumed by the network to transmit the data of the terminal device, the first condition indicates that the energy is greater than or equal to the third threshold; or, when the energy information corresponding to the terminal device indicates the energy consumed by the network to transmit the data of the terminal device, the first condition indicates that the energy efficiency is less than or equal to the fourth threshold.
[0012] In the above design, when the energy information corresponding to the terminal device meets the set conditions, the access network device determines not to activate the security protection of the data radio bearer of the terminal device's session, thereby reducing network energy consumption and achieving energy conservation. Optionally, the energy quota involved in this design can be defined by the protocol, or configured by the access network device according to local policy, or the energy quota can be indicated to the access network device by other network elements. For example, the access network device can also receive first information from the session management function network element, where the first information is used to indicate the energy quota. This embodiment of the present application is not limited to this.
[0013] In a second aspect, an embodiment of the present application provides a communication method, including: a session management function network element in a network obtains energy information corresponding to a terminal device, the energy information corresponding to the terminal device is used to indicate the energy consumed by the network to transmit data of the terminal device, or the energy information corresponding to the terminal device is used to indicate the energy efficiency corresponding to the network transmitting data of the terminal device; the session management function network element sends a first message to an access network device in the network based on the energy information corresponding to the terminal device, and the first message is used by the access network device to determine whether to activate security protection of the data wireless bearer of the session of the terminal device.
[0014] In the above design, the session management function network element triggers the access network device to determine whether to activate the security protection of the data wireless bearer of the session of the terminal device based on the energy information corresponding to the terminal device. For example, triggering the access network device to determine not to activate the security protection of the data wireless bearer of the session of the terminal device can reduce the energy consumption of the access network device.
[0015] In one possible design, before a session management function network element in a network obtains energy information corresponding to a terminal device, the method further includes: the session management function network element receiving a first user plane security policy from a unified data management network element, the first user plane security policy corresponding to a session of the terminal device; and the session management function network element sending a first message to an access network device in the network based on the energy information corresponding to the terminal device, including: when the first user plane security policy indicates priority, the session management function network element sending the first message to the access network device in the network based on the energy information corresponding to the terminal device. When the user plane security policy indicates priority, the session management function network element triggers the access network device to change the security protection of the data radio bearer of the session based on the energy information corresponding to the terminal device, thereby helping to ensure data transmission security while reducing energy consumption of the access network device.
[0016] In one possible design, the session management function network element sends a first message to the access network device in the network based on the energy information, including: when the energy information meets a first condition, the session management function network element sends the first message to the access network device, and the first message is used to determine not to activate the security protection of the data radio bearer; wherein, the energy information indicates the energy consumed by the network to transmit data of the terminal device, the first condition indicates that the difference between the consumed energy and the energy quota is less than or equal to a first threshold, and the energy quota indicates the maximum value of the energy used to transmit the data of the terminal device on the network; or, the energy information indicates the energy consumed by the network to transmit data of the terminal device, and the first condition indicates that the ratio between the consumed energy and the energy quota is greater than or equal to a second threshold; or, the energy information indicates the energy consumed by the network to transmit data of the terminal device, and the first condition indicates that the consumed energy is greater than or equal to a third threshold; or, the energy information indicates the energy efficiency corresponding to the network transmitting data of the terminal device, and the first condition indicates that the energy efficiency is less than or equal to a fourth threshold. In the above design, when the session management function network element determines that the energy information corresponding to the terminal device meets the set conditions, it instructs the access network device not to activate the security protection of the data radio bearer of the session of the terminal device, which can reduce network energy consumption and achieve energy saving.
[0017] In one possible design, the first message includes a second user plane security policy corresponding to the session. The second user plane security policy indicates that it is not necessary, or can be replaced by a description that the second user plane security policy indicates that it is not necessary to activate security protection corresponding to the session. The security protection corresponding to the session can also be replaced by a description of user plane security protection corresponding to the session, including security protection of the data radio bearer of the session. In this design, the session management function network element changes the user plane security policy to trigger the access network device to change the security protection of the data radio bearer of the session, which can reduce energy consumption and indication overhead of the access network device.
[0018] In one possible design, the session management function network element determines whether security protection for the data radio bearer of the session is activated before sending the first message carrying the second user plane security policy. By simply sending an indication of the second user plane security policy, the access network device can be triggered to deactivate security protection for the data radio bearer of the session, thereby reducing energy consumption and indication overhead of the access network device.
[0019] In one possible design, the first message includes a first user plane security policy and third information, the third information indicating that the energy information corresponding to the terminal device meets the aforementioned first condition, the first user plane security policy is from a unified data management network element, and the first user plane security policy corresponds to the session of the terminal device. In such a design, the session management function network element does not change the user plane security policy, but triggers the access network device to change the security protection of the data radio bearer of the session by indicating that the energy information corresponding to the terminal device meets the first condition, thereby reducing energy consumption and indication overhead of the access network device.
[0020] In one possible design, the energy information corresponding to the terminal device includes the energy information corresponding to the session, the energy consumed by the network transmitting the data of the terminal device includes the energy consumed by the network transmitting the data of the session of the terminal device, and the energy efficiency corresponding to the network transmitting the data of the terminal device includes the energy efficiency corresponding to the network transmitting the data of the session of the terminal device.
[0021] In a third aspect, an embodiment of the present application provides a communication method, comprising: an access network device receiving a first message from a session management function network element, the first message including a first user plane security policy and third information; wherein the first user plane security policy corresponds to a session of a terminal device, the first user plane security policy indicates priority, and the third information indicates that the energy information corresponding to the terminal device meets the first condition; and the access network device determines, based on the first message, to deactivate security protection for a data radio bearer of the session of the terminal device. Through such a design, when the user plane policy indicates priority, the access network device can quickly determine security protection for the data radio bearer of the deactivated session without analysis or calculation, thereby reducing energy consumption of the access network device while ensuring data transmission security.
[0022] In a fourth aspect, an embodiment of the present application provides a communication method, including: a session management function network element in a network determines that the network adopts energy-saving mode to serve a terminal device; the session management function network element sends a first message to an access network device in the network, and the first message is used by the access network device to determine not to activate the security protection of the data radio bearer of the session of the terminal device. Wherein, the network adopts energy-saving mode to serve the terminal device, which can also be replaced by the description that the mode of the network serving the terminal device is energy-saving mode. In the case that the network adopts energy-saving mode to serve the terminal device, the session management function network element uses a simple indication to trigger the access network device to not activate the security protection of the data radio bearer of the session of the terminal device, which can reduce the energy consumption and indication overhead of the network.
[0023] In one possible design, the session management function network element in the network determines that the network adopts the energy-saving mode to serve the terminal device, including: the session management function network element receives fourth information, and determines that the network adopts the energy-saving mode to serve the terminal device based on the fourth information; wherein the fourth information indicates that the network slice enters the energy-saving state, and the network slice includes the session of the terminal device; or, the fourth information indicates that the session management function network element enters the energy-saving state, and the session managed by the session management function network element includes the session of the terminal device; or, the fourth information indicates that the access network device enters the energy-saving state, and the access network device serves the terminal device.
[0024] In one possible design, the first message includes a user plane security policy corresponding to the session of the terminal device and fifth information; wherein, the user plane security policy indicates priority, and the fifth information indicates that the network adopts energy-saving mode to serve the terminal device.
[0025] In a fifth aspect, an embodiment of the present application provides a communication method, comprising: an access network device in a network determines that the network adopts an energy-saving mode to serve a terminal device; when the user plane security policy corresponding to the session of the terminal device indicates priority, the access network device determines not to activate the security protection of the data radio bearer of the session. Wherein, the network adopts an energy-saving mode to serve the terminal device, which can also be replaced by the description that the mode of the network serving the terminal device is an energy-saving mode. When the network adopts an energy-saving mode to serve the terminal device, the access network device determines on its own not to activate the security protection of the data radio bearer of the session of the terminal device, which can reduce the energy consumption of the network.
[0026] In one possible design, the access network device in the network determines that the network adopts the energy-saving mode to serve the terminal device, including: the access network device receives fourth information, and determines that the network adopts the energy-saving mode to serve the terminal device based on the fourth information; wherein, the fourth information indicates that the network slice enters the energy-saving state, and the network slice includes the session of the terminal device; or, the fourth information indicates that the session management function network element enters the energy-saving state, and the session managed by the session management function network element includes the session of the terminal device; or, the fourth information indicates that the access network device enters the energy-saving state, and the access network device serves the terminal device.
[0027] In a sixth aspect, an embodiment of the present application provides a communication device, which may be an access network device, or a device, module or chip in the access network device, or a device that can be used in conjunction with the access network device. In one design, the communication device may include a module that corresponds one-to-one to the method / operation / step / action described in the first aspect, and the module may be a hardware circuit, or software, or a combination of a hardware circuit and software. In one design, the communication device may include a processing module and a communication module, and the communication module includes a sending unit and a receiving unit. Optionally, the processing module may also be replaced by the description of the processing unit.
[0028] Among them, the communication module is used to receive a user plane security policy from a session management function network element in the network, and the user plane policy corresponds to the session of the terminal device; the processing module is used to determine whether to activate the security protection of the data wireless bearer of the session according to the energy information corresponding to the terminal device when the user plane security policy indicates priority; wherein the energy information corresponding to the terminal device is used to indicate the energy consumed by the network to transmit the data of the terminal device, or the energy information corresponding to the terminal device is used to indicate the energy efficiency corresponding to the network transmitting the data of the terminal device.
[0029] In one possible design, user plane security protection includes user plane encryption (UP confidentiality) and / or user plane integrity protection (UP integrity protection).
[0030] In one possible design, the energy information corresponding to the terminal device includes the energy information corresponding to the session, the energy consumed by the network transmitting the data of the terminal device includes the energy consumed by the network transmitting the session data of the terminal device, and the energy efficiency corresponding to the network transmitting the data of the terminal device includes the energy efficiency corresponding to the network transmitting the session data of the terminal device.
[0031] In one possible design, the communication module is further used to receive energy information corresponding to the terminal device from the first network element.
[0032] In one possible design, the processing module is specifically used to determine not to activate the security protection of the data wireless bearer of the session when the energy information corresponding to the terminal device meets the first condition; wherein, when the energy information corresponding to the terminal device indicates the energy consumed by the network to transmit the data of the terminal device, the first condition indicates that the difference between the energy and the energy quota is less than or equal to the first threshold; or, when the energy information corresponding to the terminal device indicates the energy consumed by the network to transmit the data of the terminal device, the first condition indicates that the ratio of the energy to the energy quota is greater than or equal to the second threshold; or, when the energy information corresponding to the terminal device indicates the energy consumed by the network to transmit the data of the terminal device, the first condition indicates that the energy is greater than or equal to the third threshold; or, when the energy information corresponding to the terminal device indicates the energy consumed by the network to transmit the data of the terminal device, the first condition indicates that the energy is greater than or equal to the third threshold; or, when the energy information corresponding to the terminal device indicates the energy efficiency corresponding to the network transmitting the data of the terminal device, the first condition indicates that the energy efficiency is less than or equal to the fourth threshold.
[0033] Optionally, the energy quota involved in this design may be defined by a protocol, or configured by the access network device according to a local policy, or the energy quota may be indicated to the access network device by other network elements. For example, the access network device may also receive first information from the session management function network element, and the first information is used to indicate the energy quota. This embodiment of the present application is not limited to this.
[0034] In the seventh aspect, an embodiment of the present application provides a communication device, which may be a member management function network element, or a device, module or chip in the member management function network element, or a device that can be used in combination with the member management function network element. In one design, the communication device may include a module that corresponds one-to-one to the execution of the method / operation / step / action described in the second aspect, and the module may be a hardware circuit, or software, or a combination of a hardware circuit and software. In one design, the communication device may include a processing module and a communication module, and the communication module includes a sending unit and a receiving unit. Optionally, the processing module may also be replaced by the description of the processing unit.
[0035] A communication module is used to obtain energy information corresponding to a terminal device, where the energy information corresponding to the terminal device is used to indicate the energy consumed by the network in transmitting data of the terminal device, or the energy information corresponding to the terminal device is used to indicate the energy efficiency corresponding to the network in transmitting data of the terminal device; a processing module is used to send a first message to an access network device in the network through the communication module based on the energy information corresponding to the terminal device, where the first message is used by the access network device to determine whether to activate security protection of the data wireless bearer of the session of the terminal device.
[0036] In one possible design, the communication module is also used to receive a first user plane security policy from a unified data management network element before obtaining the energy information corresponding to the terminal device, where the first user plane security policy corresponds to the session of the terminal device; the processing module is specifically used to send a first message to the access network device in the network through the communication module according to the energy information corresponding to the terminal device when the first user plane security policy indicates priority.
[0037] In one possible design, the processing module is specifically used to send the first message to the access network device through the communication module when the energy information meets the first condition, and the first message is used to determine not to activate the security protection of the data wireless bearer; wherein, the energy information indicates the energy consumed by the network to transmit the data of the terminal device, the first condition indicates that the difference between the consumed energy and the energy quota is less than or equal to the first threshold, and the energy quota indicates the maximum value of the energy used to transmit the data of the terminal device to the network; or, the energy information indicates the energy consumed by the network to transmit the data of the terminal device, and the first condition indicates that the ratio between the consumed energy and the energy quota is greater than or equal to the second threshold; or, the energy information indicates the energy consumed by the network to transmit the data of the terminal device, and the first condition indicates that the consumed energy is greater than or equal to a third threshold; or, the energy information indicates the energy efficiency corresponding to the network transmitting the data of the terminal device, and the first condition indicates that the energy efficiency is less than or equal to a fourth threshold.
[0038] In one possible design, the first message includes a second user plane security policy corresponding to the session. The second user plane security policy indicates that it is not necessary, or it can also be replaced by a description that the second user plane security policy indicates that it is not necessary to activate the security protection corresponding to the session. The security protection corresponding to the session can also be replaced by a description that the user plane security protection corresponding to the session includes security protection of the data radio bearer of the session.
[0039] In one possible design, before the communication module sends the first message carrying the second user plane security policy, the processing module is further used to determine whether security protection of the data radio bearer of the session is activated.
[0040] In one possible design, the first message includes a first user plane security policy and third information, the third information indicates that the energy information corresponding to the terminal device meets the aforementioned first condition, the first user plane security policy comes from a unified data management network element, and the first user plane security policy corresponds to the session of the terminal device.
[0041] In one possible design, the energy information corresponding to the terminal device includes the energy information corresponding to the session, the energy consumed by the network transmitting the data of the terminal device includes the energy consumed by the network transmitting the data of the session of the terminal device, and the energy efficiency corresponding to the network transmitting the data of the terminal device includes the energy efficiency corresponding to the network transmitting the data of the session of the terminal device.
[0042] In an eighth aspect, an embodiment of the present application provides a communication method, wherein the communication device may be an access network device, or a device, module or chip in the access network device, or a device that can be used in conjunction with the access network device. In one design, the communication device may include a module that corresponds one-to-one to the execution of the method / operation / step / action described in the third aspect, and the module may be a hardware circuit, or software, or a combination of a hardware circuit and software. In one design, the communication device may include a processing module and a communication module, and the communication module includes a sending unit and a receiving unit. Optionally, the processing module may also be replaced by the description of the processing unit.
[0043] A communication module is used to receive a first message from a session management function network element, where the first message includes a first user plane security policy and third information; wherein the first user plane security policy corresponds to a session of a terminal device, the first user plane security policy indicates priority, and the third information indicates that the energy information corresponding to the terminal device meets the first condition; a processing module is used to determine, based on the first message, whether to activate the security protection of the data radio bearer of the session of the terminal device.
[0044] In the ninth aspect, an embodiment of the present application provides a communication device, which may be a member management function network element, or a device, module or chip in the member management function network element, or a device that can be used in combination with the member management function network element. In one design, the communication device may include a module that corresponds one-to-one to the method / operation / step / action described in the fourth aspect, and the module may be a hardware circuit, or software, or a combination of a hardware circuit and software. In one design, the communication device may include a processing module and a communication module, and the communication module includes a sending unit and a receiving unit. Optionally, the processing module may also be replaced by the description of the processing unit.
[0045] A processing module is used to determine that the network adopts energy-saving mode to serve the terminal device; a communication module is used to send a first message to an access network device in the network, and the first message is used by the access network device to determine not to activate the security protection of the data wireless bearer of the session of the terminal device.
[0046] In one possible design, the communication module is further used to receive fourth information; the processing module is further used to determine, based on the fourth information, that the network adopts the energy-saving mode to serve the terminal device; wherein, the fourth information indicates that the network slice enters an energy-saving state, and the network slice includes the session of the terminal device; or, the fourth information indicates that the session management function network element enters an energy-saving state, and the session managed by the session management function network element includes the session of the terminal device; or, the fourth information indicates that the access network device enters an energy-saving state, and the access network device serves the terminal device.
[0047] In one possible design, the first message includes a user plane security policy corresponding to the session of the terminal device and fifth information; wherein, the user plane security policy indicates priority, and the fifth information indicates that the network adopts energy-saving mode to serve the terminal device.
[0048] In the tenth aspect, an embodiment of the present application provides a communication device, which may be an access network device, or a device, module or chip in the access network device, or a device that can be used in conjunction with the access network device. In one design, the communication device may include a module that corresponds one-to-one to the execution of the method / operation / step / action described in the fifth aspect, and the module may be a hardware circuit, or software, or a combination of a hardware circuit and software. In one design, the communication device may include a processing module and a communication module, and the communication module includes a sending unit and a receiving unit. Optionally, the processing module may also be replaced by the description of the processing unit.
[0049] The processing module is used to determine that the network adopts energy-saving mode to serve the terminal device; and when the user plane security policy corresponding to the session of the terminal device indicates priority, determine not to activate the security protection of the data radio bearer of the session.
[0050] In one possible design, the communication module is further used to receive fourth information; the processing module is further used to determine, based on the fourth information, that the network adopts the energy-saving mode to serve the terminal device; wherein, the fourth information indicates that the network slice enters an energy-saving state, and the network slice includes the session of the terminal device; or, the fourth information indicates that the session management function network element enters an energy-saving state, and the session managed by the session management function network element includes the session of the terminal device; or, the fourth information indicates that the access network device enters an energy-saving state, and the access network device serves the terminal device.
[0051] In an eleventh aspect, an embodiment of the present application provides a communication device, comprising a processor configured to implement the method described in any one of the first to fifth aspects above. The processor is coupled to a memory configured to store instructions and data. When the processor executes the instructions stored in the memory, the method described in the first aspect can be implemented. Optionally, the communication device may further comprise a memory; the communication device may further comprise a communication interface configured to enable the communication device to communicate with other devices. Exemplarily, the communication interface may be a transceiver, circuit, bus, module, pin, or other type of communication interface.
[0052] In the twelfth aspect, an embodiment of the present application provides a communication device, comprising a logic circuit and an interface circuit; the interface circuit is used to communicate with a module outside the communication device; the logic circuit is used to execute a computer program so that the communication device executes the method provided in any one of the above-mentioned first to fifth aspects.
[0053] In a thirteenth aspect, an embodiment of the present application provides a communication method, which is applied to a communication system including a session management function network element and an access network device.
[0054] In one possible design, the communication method includes: a session management function network element in a network sends a user plane security policy to an access network device in the network, wherein the user plane policy corresponds to a session of a terminal device; the access network device receives the user plane security policy from the session management function network element, and when the user plane security policy indicates priority, the access network device determines whether to activate security protection of the data wireless bearer of the session based on energy information corresponding to the terminal device; wherein the energy information corresponding to the terminal device is used to indicate the energy consumed by the network to transmit data of the terminal device, or the energy information corresponding to the terminal device is used to indicate the energy efficiency corresponding to the network transmitting data of the terminal device.
[0055] In one possible design, the communication method includes: a session management function network element in the network obtains energy information corresponding to the terminal device, where the energy information corresponding to the terminal device is used to indicate the energy consumed by the network to transmit data of the terminal device, or the energy information corresponding to the terminal device is used to indicate the energy efficiency corresponding to the network transmitting data of the terminal device; the session management function network element sends a first message to an access network device in the network based on the energy information corresponding to the terminal device, and the first message is used by the access network device to determine whether to activate security protection of the data wireless bearer of the session of the terminal device.
[0056] In one possible design, the communication method includes: a session management function network element in the network determines that the network adopts an energy-saving mode to serve the terminal device; the session management function network element sends a first message to an access network device in the network, and the first message is used by the access network device to determine not to activate the security protection of the data wireless bearer of the session of the terminal device.
[0057] In a fourteenth aspect, an embodiment of the present application provides a communication system, including an access network device and a session management function network element.
[0058] In one possible design, the access network device is used to implement the method described in the above first aspect or any possible design thereof; the session management function network element is used to: send a user plane security policy to the access network device.
[0059] In another possible design, the session management function network element is used to implement the method described in the above second aspect or any possible design thereof, and the access network device is used to implement the method described in the above third aspect or any possible design thereof.
[0060] In another possible design, the session management function network element is used to implement the method described in the above second aspect, fourth aspect or any possible design thereof, and the access network device is used to implement the method described in the above third aspect or any possible design thereof.
[0061] In one possible design, the access network device is used to implement the method described in the above-mentioned fifth aspect or any possible design thereof; the session management function network element is used to: send a user plane security policy to the access network device.
[0062] In the fifteenth aspect, an embodiment of the present application further provides a computer program, which, when executed on a computer, enables the computer to execute the method provided in any one of the first to fifth aspects above.
[0063] In the sixteenth aspect, an embodiment of the present application further provides a computer program product, comprising instructions, which, when executed on a computer, enable the computer to execute the method provided in any one of the first to fifth aspects above.
[0064] In the seventeenth aspect, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program or instruction is stored. When the computer program or instruction is run on a computer, the computer executes the method provided in any one of the first to fifth aspects above.
[0065] In the eighteenth aspect, an embodiment of the present application further provides a chip, which is used to read a computer program stored in a memory and execute the method provided in any one of the first to fifth aspects above.
[0066] In a nineteenth aspect, an embodiment of the present application further provides a chip system, which includes a processor for supporting a computer device to implement the method provided in any one of the first to fifth aspects above. In one possible design, the chip system also includes a memory for storing the necessary programs and data for the computer device. The chip system can be composed of a chip, or it can include a chip and other discrete devices.
[0067] The effects of the solutions provided in any of the sixth to nineteenth aspects above can be referred to the corresponding descriptions in the first to fifth aspects. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] FIG1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present application;
[0069] FIG2 is a schematic diagram of a network architecture according to an embodiment of the present application;
[0070] 3 to 7 are flowcharts of several communication methods in embodiments of the present application;
[0071] FIG8 is a schematic diagram of a structure of a communication device according to an embodiment of the present application;
[0072] FIG9 is one of the structural diagrams of the communication device in the embodiment of the present application. DETAILED DESCRIPTION
[0073] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.
[0074] The at least one (item) involved in the embodiments of the present application as follows indicates one (item) or more (items). More (items) refers to two (items) or more than two (items). "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. In addition, it should be understood that although the terms first, second, etc. may be used to describe each object in the embodiments of the present application, these objects should not be limited to these terms. These terms are only used to distinguish each object from each other.
[0075] The terms "including" and "having" and any variations thereof mentioned in the following description of the embodiments of the present application are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes other steps or units that are not listed, or optionally includes other steps or units that are inherent to these processes, methods, products or devices. It should be noted that, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any method or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other methods or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way.
[0076] The technical solutions provided in this application can be applied to various communication systems, such as: fifth generation (5G) or new radio (NR) systems, long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, wireless local area networks (WLAN) systems, satellite communication systems, future communication systems, such as sixth generation (6G) mobile communication systems, or a fusion system of multiple systems. The technical solutions provided in this application can also be applied to device to device (D2D) communication, vehicle-to-everything (V2X) communication, machine to machine (M2M) communication, machine type communication (MTC), and Internet of Things (IoT) communication systems or other communication systems.
[0077] A network element in a communication system can send a signal to another network element or receive a signal from another network element. The signal may include information, signaling, or data, etc. The network element can also be replaced by an entity, a network entity, a device, a communication device, a communication module, a node, a communication node, etc. The embodiments of the present application are described using a network element as an example. For example, a communication system may include at least one terminal device and at least one access network device. The access network device can send a downlink signal to the terminal device, and / or the terminal device can send an uplink signal to the access network device. In addition, it can be understood that if the communication system includes multiple terminal devices, multiple terminal devices can also send signals to each other, that is, the signal sending network element and the signal receiving network element can both be terminal devices.
[0078] The communication method provided in the embodiment of the present application can be applied to wireless communication systems such as 5G, 6G, and satellite communication. Referring to Figure 1, Figure 1 is a simplified schematic diagram of the wireless communication system provided in the embodiment of the present application. As shown in Figure 1, the wireless communication system includes a wireless access network 100. The wireless access network 100 can be a next-generation (e.g., 6G or higher) wireless access network, or a traditional (e.g., 5G, 4G, 3G, or 2G) wireless access network. One or more communication devices (120a-120j, collectively referred to as 120) can be connected to each other or to one or more access network devices (110a, 110b, collectively referred to as 110) in the wireless access network 100.
[0079] Optionally, in actual applications, the wireless communication system may include multiple access network devices (also called network devices) or multiple communication devices. An access network device may serve one or more communication devices simultaneously. A communication device may also access one or more access network devices simultaneously. The embodiments of the present application do not limit the number of communication devices and access network devices included in the wireless communication system.
[0080] The access network device may be an entity on the network side for transmitting or receiving signals. The access network device may be an access device for a communication device to access the wireless communication system in a wireless manner, such as a base station. A base station can broadly cover various names as follows, or be replaced with the following names, such as: radio access network (RAN) equipment, RAN node, NodeB, evolved NodeB (eNB), next generation NodeB (gNB), access network equipment in an open radio access network (O-RAN), relay station, access point, transmission point (TRP), transmitting point (TP), master station MeNB, secondary station SeNB, multi-standard radio (MSR) node, home base station, network controller, access node, radio node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), radio head (RRH), central unit (CU), distributed unit (DU), radio unit (RU), centralized unit control plane (CU-CP) node, centralized unit user plane (CU-UP) node, positioning node, etc. The base station can be a macro base station, a micro base station, a relay node, a donor node or the like, or a combination thereof. The access network device can also refer to a communication module, a modem or a chip that is provided in the aforementioned device or apparatus. The access network device can also be a mobile switching center and a device to device (Device-to-Device, D2D), vehicle-to-everything (V2X), machine-to-machine (machine-to-machine, M2M) communication device that performs the base station function, a network side device in a 6G network, a device that performs the base station function in a future communication system, etc. The access network device can support networks with the same or different access technologies. The embodiments of the present application do not limit the specific technology and specific device form adopted by the access network device.
[0081] In some deployments, a gNB may include a centralized unit (CU) and a distributed unit (DU). The gNB may also include an active antenna unit (AAU). The CU may implement some gNB functions, while the DU may implement other gNB functions. For example, the CU is responsible for processing non-real-time protocols and services, implementing the functions of the radio resource control (RRC) and packet data convergence protocol (PDCP) layers. The DU is responsible for processing physical layer protocols and real-time services, implementing the functions of the radio link control (RLC), media access control (MAC), and physical (PHY) layers. The AAU implements some physical layer processing functions, RF processing, and active antenna-related functions. RRC layer information is generated by the CU and ultimately encapsulated by the DU's PHY layer into PHY layer information, or is converted from PHY layer information. Therefore, in this architecture, higher-layer signaling, such as RRC layer signaling, can also be considered to be sent by the DU, or by a combination of the DU and the AAU. It is understood that the access network device may include one or more of a CU node, a DU node, and an AAU node. In addition, the CU may be classified as an access network device in the access network, or as an access network device in the CN, which is not limited in this application.
[0082] Access network equipment can be fixed or mobile. For example, base stations 110a and 110b are stationary and are responsible for wireless transmission and reception in one or more cells from the communication device 120. The helicopter or drone 120i shown in Figure 1 can be configured to act as a mobile base station, and one or more cells can move according to the location of the mobile base station 120i. In other examples, the helicopter or drone (120i) can be configured to serve as a communication device that communicates with the base station 110b.
[0083] In the embodiments of the present application, the communication device used to implement the above-mentioned access network function can be an access network device, or an access network device with partial access network functions, or a device capable of supporting the implementation of the access network function, such as a chip system, a hardware circuit, a software module, or a hardware circuit and a software module. The device can be installed in the access network device or used in conjunction with the access network device. In the method of the embodiments of the present application, the communication device used to implement the access network device function is described as an access network device or a RAN device.
[0084] A communication device can be an entity on the user side that receives or transmits signals, such as a mobile phone. A communication device can be used to connect people, objects, and machines. A communication device can communicate with one or more core networks via access network equipment. Communication devices include handheld devices with wireless connectivity, other processing devices connected to a wireless modem, or in-vehicle devices. A communication device can be portable, pocket-sized, handheld, built into a computer, or in-vehicle. The communication device 120 can be widely used in various scenarios, such as cellular communications, device-to-device (D2D), vehicle-to-everything (V2X), end-to-end (P2P), machine-to-machine (M2M), machine-type communications (MTC), the Internet of Things (IoT), virtual reality (VR), augmented reality (AR), industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, smart cities, drones, robots, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery and mobility, and the like. Some examples of the communication device 120 include: user equipment (UE) of the 3GPP standard, fixed equipment, mobile equipment, handheld equipment, wearable equipment, cellular phones, smart phones, session initiation protocol (SIP) phones, laptops, personal computers, smart books, vehicles, satellites, global positioning system (GPS) devices, target tracking equipment, drones, helicopters, aircraft, ships, remote control equipment, smart home devices, industrial equipment, personal communication service (PCS) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), wireless network cameras, tablet computers, handheld computers, mobile internet devices (MIDs), wearable devices such as smart watches, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, terminals in vehicle networking systems, wireless terminals in self-driving cars, wireless terminals in smart grids, wireless terminals in transportation safety, and smart cities. The communication device 120 may be a wireless device in the above scenarios or a device configured in a wireless device, such as a communication module, modem, or chip in the above devices.A communication device may also be referred to as a terminal, terminal device, user equipment (UE), mobile station (MS), mobile terminal (MT), etc. A communication device may also be a communication device in a future wireless communication system. A communication device may be used in a dedicated network device or a general-purpose device. The embodiments of the present application do not limit the specific technology and specific device form used by the communication device.
[0085] Alternatively, a communication device can function as a base station. For example, a UE can function as a dispatching entity, providing sidelink signals between UEs in V2X, D2D, or P2P scenarios. As shown in Figure 1 , a cell phone 120a and a car 120b communicate with each other using sidelink signals. Cell phone 120a and smart home device 120e communicate without relaying the communication signals through base station 110b.
[0086] In the embodiment of the present application, the communication device for realizing the functions of the communication device may be a terminal device, or a terminal device having some of the functions of the above communication devices, or a device capable of supporting the functions of the above communication devices, such as a chip system, which can be installed in the terminal device or used in combination with the terminal device. In the embodiment of the present application, the chip system may be composed of chips, or may include chips and other discrete devices. In the technical solution provided in the embodiment of the present application, the communication device is described as a terminal device or UE as an example.
[0087] The communication between the access network device and the terminal device follows a certain protocol layer structure. The protocol layer structure may include a control plane protocol layer structure and a user plane protocol layer structure. For example, the control plane protocol layer structure may include the functions of protocol layers such as the radio resource control (RRC) layer, the packet data convergence protocol (PDCP) layer, the radio link control (RLC) layer, the medium access control (MAC) layer, and the physical layer. For example, the user plane protocol layer structure may include the functions of protocol layers such as the PDCP layer, the RLC layer, the MAC layer, and the physical layer. In one possible implementation, a service data adaptation protocol (SDAP) layer may also be included above the PDCP layer.
[0088] Taking data transmission between access network equipment and terminal devices as an example, data transmission needs to pass through the user plane protocol layers, such as the SDAP layer, PDCP layer, RLC layer, MAC layer, and physical layer. The SDAP layer, PDCP layer, RLC layer, MAC layer, and physical layer can also be collectively referred to as the access layer. Data transmission is divided into sending or receiving based on the direction of transmission, and each of these layers is further divided into a sending part and a receiving part. Taking downlink data transmission as an example, after the PDCP layer obtains data from the upper layer, it transmits the data to the RLC layer and MAC layer. The MAC layer then generates a transport block, which is then wirelessly transmitted through the physical layer. Data is encapsulated accordingly in each layer. For example, data received by a layer from the layer above it is considered a service data unit (SDU) of that layer. After encapsulation by that layer, it becomes a protocol data unit (PDU) and is then passed to the next layer.
[0089] For example, a terminal device may also have an application layer and a non-access layer. The application layer can be used to provide services to applications installed in the terminal device. For example, downlink data received by the terminal device can be sequentially transmitted from the physical layer to the application layer, and then provided by the application layer to the application. For another example, the application layer can obtain data generated by the application and sequentially transmit the data to the physical layer for transmission to other communication devices. The non-access layer can be used to forward user data, such as forwarding uplink data received from the application layer to the SDAP layer, or forwarding downlink data received from the SDAP layer to the application layer.
[0090] It should be understood that the number and type of each device in the communication system shown in Figure 1 are for illustration only, and the embodiments of the present application are not limited thereto. In actual applications, the communication system may also include more terminal devices, more access network devices, and other network elements, such as core network devices, network management and / or network elements for implementing artificial intelligence functions. Among them, the network management can also be called operation administration and maintenance (OAM) network element, referred to as OAM. Operations mainly complete the analysis, prediction, planning and configuration of daily network and business operations; maintenance mainly involves daily operational activities such as testing and fault management of the network and its services. The network management can detect the network operation status, optimize network connections and performance, improve network operation stability, and reduce network maintenance costs.
[0091] For ease of understanding, Figure 2 shows a network architecture applicable to the communication method provided in an embodiment of the present application. The network architecture may include an access network and a core network, and the terminal device accesses the data network (DN) through the access network and the core network.
[0092] Among them, the definition and examples of terminal equipment and the introduction to the terminal equipment in the communication system shown in Figure 1 are understood, and the embodiments of the present application will not go into details. The access network is used to implement access-related functions, and can provide network access functions for authorized users in a specific area, and can determine transmission links of different qualities to transmit user data based on the user's level, business requirements, etc. The access network forwards control signals and user data between the UE and the core network. The access network may include the access network device as shown in Figure 1, and the access network device provides access services for the terminal device. For example, the access network device may be responsible for wireless resource management, quality of service (QoS) management, data compression and encryption and other functions on the air interface side.
[0093] The core network is responsible for maintaining subscription data in the mobile network and providing terminal devices with functions such as session management, mobility management, policy management, and security authentication. The core network includes but is not limited to one or more of the following network elements: application function (AF) network element, unified data management (UDM) network element, unified data repository (UDR) network element, policy control function (PCF) network element, session management function (SMF) network element, access and mobility management function (AMF) network element, network repository function (NRF) network element, authentication server function (AUSF) network element, network exposure function (NEF) network element, user plane function (UPF) network element, and network data analytics function (NWDAF) network element.
[0094] The access and mobility management function network element is mainly responsible for mobility management in the mobile network, such as user location update, user registration network, user switching, allocation of user temporary identity, authentication and authorization of users, etc. In 5G, the access and mobility management function network element can be an AMF network element. In future communications such as the 6th generation (6G), the mobility management network element can still be an AMF network element or have other names, which are not limited in this application.
[0095] The session management function network element is responsible for managing the protocol data unit (PDU) session of the terminal device. The PDU session is a channel for transmitting PDUs, and the terminal device needs to transmit PDUs to each other with the DN through the PDU session. The SMF network element is responsible for establishing, maintaining and deleting PDU sessions. The session management function network element includes session management (such as session establishment, modification and release, including tunnel maintenance between user plane network elements and access network equipment), selection and control of user plane network elements, service and session continuity (SSC) mode selection, roaming and other session-related functions. In 5G, the session management function network element can be an SMF network element. In future communications such as 6G, the session management function network element can still be an SMF network element, or have other names, which are not limited in this application.
[0096] The user plane function network element is the gateway for communication between the mobile network and the data network (DN). It is mainly responsible for forwarding and receiving user data. For example, it can receive user data from the data network and transmit it to the UE through the access network equipment; it can also receive user data from the UE through the access network equipment and forward it to the data network. In addition, the user plane function network element also includes user-plane related functions such as data packet detection, service usage reporting, quality of service (QoS) processing, legal monitoring, uplink data packet detection, downlink data packet storage, etc. In 5G, the user plane function network element can be a UPF network element. In future communications such as 6G, the user plane function network element can still be a UPF network element, or have other names, which are not limited in this application.
[0097] The unified data management network element is responsible for storing information such as the subscriber's subscriber permanent identifier (SUPI), credentials, security context, and subscription information. The information stored by the unified data management network element can be used for authentication and authorization of terminal devices to access the mobile network. The above-mentioned subscribers can specifically be users who use services provided by the mobile network, such as users who use China Telecom's mobile phone SIM cards, or users who use China Mobile's mobile phone SIM cards, etc. The subscriber's permanent subscription identifier (SUPI) can be the number of the mobile phone SIM card, etc. The subscriber's credentials and security context can be small files storing the encryption key of the mobile phone SIM card or information related to the encryption of the mobile phone SIM card, which are used for authentication and / or authorization. The above-mentioned security context can be data (cookie) or token stored on the user's local terminal (such as a mobile phone). The subscription data of the subscriber can be the supporting services of the mobile phone SIM card, such as the data package of the mobile phone SIM card or the network used. It should be noted that permanent identifiers, credentials, security contexts, authentication data (cookies), and tokens are equivalent to authentication and authorization-related information. In this application document, for the sake of convenience of description, no distinction or restriction is made. Unless otherwise specified, the embodiments of this application will be described using security context as an example, but the embodiments of this application are also applicable to authentication and / or authorization information expressed in other ways. In 5G, the unified data management network element can be a UDM network element. In future communications such as 6G, the unified data management network element can still be a UDM network element, or have other names, which are not limited in this application.
[0098] The network open network element opens the external interface of the mobile network to a third party in a secure manner. When the session management function network element needs to communicate with the network element of a third party, the network open network element can serve as a relay for the communication between the session management function network element and the network element of the third party. When the network open network element acts as a relay, it can translate the identification information of the subscriber, as well as the identification information of the third-party network element. For example, when the network open network element sends the SUPI of the subscriber from the mobile network to a third party, the SUPI can be translated into its corresponding external identity (identity, ID). Conversely, when the network open network element sends the external ID (third-party network element ID) to the mobile network, it can translate it into SUPI. In 5G, the network open network element can be a NEF network element. In future communications such as 6G, the network open network element can still be a NEF network element, or have other names, which are not limited in this application.
[0099] The application function network element is used to convey the requirements of the application side to the network side, such as QoS requirements or user status event subscriptions. The application function network element can be a third-party functional entity or an application server deployed by the operator, such as the IP multimedia subsystem (IMS) voice call service. In 5G, the application function network element can be an AF network element. In future communications such as 6G, the application function network element can still be an AF network element or have other names, which are not limited in this application.
[0100] The policy control network element is used to provide PDU session policies to the session management function network element. Policies may include billing-related policies, QoS-related policies, and authorization-related policies. In 5G, the policy control network element may be a PCF network element. In future communications such as 6G, the policy control network element may still be a PCF network element or have other names, which are not limited in this application.
[0101] The network data analysis function network element provides functions such as network data collection and analysis based on technologies such as big data and artificial intelligence. In 5G, the network data analysis function network element can be an NWDAF network element. In future communications such as 6G, the network data analysis function network element can still be an NWDAF network element or have other names, which are not limited in this application.
[0102] The above-mentioned AF network element, UDM network element, UDR network element, PCF network element, SMF network element, AMF network element, NRF network element, AUSF network element, NEF network element, UPF network element, and NWDAF network element can also be referred to as AF, UDM, UDR, PCF, SMF, AMF, NRF, AUSF, NEF, UPF, and NWDAF, respectively, as shown in Figure 1.
[0103] In Figure 2, Nausf, Nnef, Nnrf, Namf, Npcf, Nsmf, Nudm, Nudr, Naf, and Nnwdaf are service-oriented interfaces provided by the aforementioned AUSF, NEF, NRF, AMF, PCF, SMF, UDM, UDR, AF, and NWDAF, respectively, and are used to invoke corresponding service-oriented operations. N1, N2, N3, N4, and N6 are interface serial numbers, and their meanings are as follows:
[0104] 1) N1: The interface between AMF and terminal devices, which can be used to deliver non-access stratum (NAS) signaling (such as QoS rules from AMF) to terminal devices.
[0105] 2) N2: The interface between AMF and access network equipment, which can be used to transmit radio bearer control information from the core network side to the access network equipment.
[0106] 3) N3: The interface between the access network equipment and UPF, mainly used to transmit uplink and downlink user plane data between the access network equipment and UPF.
[0107] 4) N4: The interface between SMF and UPF can be used to transmit information between the control plane and the user plane, including controlling the issuance of forwarding rules, QoS rules, traffic statistics rules, etc. for the user plane and reporting information on the user plane.
[0108] 5) N6: Interface between UPF and DN, used to transmit uplink and downlink user data flows between UPF and DN.
[0109] It is understandable that one or more of the above-mentioned terminal devices, access network devices, or core network devices can be network elements in hardware devices, or can be software functions running on dedicated hardware (such as a proprietary processor or a general-purpose processor), or all or part of the functions implemented by these devices can be virtualized. For example, one or more functions of the virtualized terminal device, access network device, or core network device can be implemented by a cloud device, such as a cloud device in an over-the-top (OTT) system. Because the terminal device and the access network device involve an interface for air interface transmission, the transceiver function of the interface can be implemented by hardware.
[0110] The technical terms involved in the embodiments of this application are described in detail below.
[0111] (1) User plane security policy (UP security policy)
[0112] The UP security policy is used to control the user plane security protection of the DRB of the terminal device's session. Currently, UP security policies are divided into the following three types: UP security policy indicates required (required), which indicates that the security protection of the DRB of the terminal device's session needs to be activated; UP security policy indicates not needed (not needed), which indicates that the security protection of the DRB of the terminal device's session does not need to be activated; UP security policy indicates preferred (preferred), which indicates that the security protection of the DRB of the terminal device's session is activated first or the security protection of the DRB of the terminal device's session is not activated first. Taking the session as a PDU session as an example, the security protection of the DRB of the PDU session includes UP confidentiality and / or UP integrity protection.
[0113] Normally, the SMF can provide the access network device with the UP security policy corresponding to the PDU session of the terminal device during the PDU session establishment process. The access network device determines whether to activate the user plane security protection of the DRB belonging to the PDU session based on the received UP security policy. For example, when the UP security policy indicates that it is required, the access network device activates the user plane security protection of the DRB of the PDU session; or, when the UP security policy indicates that it is required but the access network device cannot activate the user plane security protection of the DRB of the PDU session, the access network device should refuse to establish user plane resources for the PDU session and indicate the reason for the refusal to the SMF; or, when the UP security policy indicates that it is not needed, the access network device does not activate the user plane security protection of the DRB of the PDU session; or, when the UP security policy indicates priority, the access network device can determine whether to activate the user plane security protection of the DRB of the PDU session based on the local policy; or, when the UP security policy indicates priority, the access network device can dynamically change the activation or deactivation of the user plane security protection of the DRB of the PDU session. Optionally, in the embodiment of the present application, activation (activate) can also be replaced by the description of opening, deactivation (de-activate) can also be replaced by the description of not opening, and deactivation (de-activate) can also be replaced by the description of closing.
[0114] Among them, when the UP security policy is configured in the contract information of the terminal device's session, SMF can obtain the contract information of the terminal device's session from UDM to obtain the aforementioned UP security policy. When the UP security policy is not configured in the contract information of the terminal device's session, SMF can configure the same user plane security policy for all sessions corresponding to the same granularity according to the granularity of data network, network slice, access network device, etc.
[0115] (2) Energy information
[0116] Energy information can also be replaced by energy data, energy parameters, energy information or other names. In the embodiments of the present application, energy information is used as an example for explanation. Energy information can be energy consumption information (or energy consumption), indicating the energy consumed by the data transmitted by the network terminal device, such as the energy consumed by the session data of the network terminal device; or energy information can be energy efficiency information, indicating the energy efficiency corresponding to the network transmission terminal device, such as the energy efficiency corresponding to the session data of the network terminal device. It can be understood that for the same amount of data transmitted over the network: the higher the energy efficiency, the less energy is consumed; or the lower the energy efficiency, the more energy is consumed.
[0117] Among them, the energy can be electricity, and the unit of electricity can be kilowatt / hour (kw / h), watt / hour (w / h), or joule, etc.; or, the energy is related to renewable energy, such as carbon emission data, green energy amount, which is not limited in the embodiments of the present application.
[0118] In some possible designs, energy quotas (or energy consumption quotas) can be configured for various granularities. For example, the energy quota for a network slice can be configured to indicate the maximum amount of energy that the network slice is allowed to consume; the energy quota for a terminal device (or energy consumption quota) can be configured to indicate the maximum amount of energy that the network is allowed to consume when transmitting data from the terminal device; or the energy quota for a session can be configured to indicate the maximum amount of energy that the network is allowed to consume when transmitting session data from the terminal device.
[0119] The embodiment of the present application introduces consideration of energy information corresponding to terminal devices during the process of controlling user plane security protection on the network side to reduce network energy consumption and achieve energy saving.
[0120] Option 1
[0121] FIG3 illustrates a communication method, which mainly includes the following steps:
[0122] S301: The session management function network element sends a user plane security policy corresponding to a session of a terminal device to an access network device.
[0123] The user plane security policy indication corresponding to the session is preferred; or a new user plane security policy indication a can be added based on whether the user plane security policy indication is required, not required, or preferred. For example, the new user plane security policy indication a can be preferred according to energy state. Based on this, the user plane security policy indication corresponding to the session is preferred based on energy state to indicate the security protection of the DRB for the session of the terminal device based on energy priority activation or the security protection of the DRB for the session of the terminal device based on energy priority deactivation.
[0124] Accordingly, when the user plane security policy indicates priority or priority based on energy status, the access network device can control the security protection of the data radio bearer for the terminal device's session based on the energy consumed by the network transmission terminal device or the energy efficiency corresponding to the network transmission terminal device. It is understood that the network refers to the network where the access network device and the session management function network element are located. S301 can also be alternatively described as the session management function network element in the network sending the user plane security policy corresponding to the terminal device's session to the access network device in the network.
[0125] In one possible implementation, the contract information of the terminal device stored in the unified data management network element includes the user plane security policy corresponding to the session of the terminal device. The session management function network element can obtain the user plane security policy corresponding to the session of the terminal device from the unified data management network element, and then forward it to the access network device. For example, during the session establishment process, the terminal device initiates a session establishment request (session establishment request) to the session management function network element through the access network device; the session management function network element can query the contract information of the terminal device from the unified data management network element during the session establishment process, or the session management function network element can query the contract information of the terminal device from the unified data management network element after the session is established. The session involved in the embodiment of the present application can be a PDU session or other session, and the PDU session can be used as an example of a session.
[0126] It is understandable that the control of user plane security protection for a session in the embodiment of the present application may occur during the session establishment process, or may be sent after the session is established, or in the session modification process after the session is established, or in the subsequent re-establishment of a new session, and the embodiment of the present application is not limited to this. As an example, FIG3 also illustrates an optional step with a dotted line before S301: S300a: The terminal device initiates a session establishment request to the session management function network element through the access network device, S300b, the session management function network element obtains the contract information of the terminal device from the unified data management network element, and the contract information includes the user plane security policy corresponding to the session of the terminal device.
[0127] Additionally, optionally, the contract information of the terminal device may further include indication information for instructing the session management function network element to perform energy information statistics, where the energy information statistics may include energy consumption statistics and / or energy efficiency statistics. The indication information may be explicitly indicated in the contract information of the terminal device, for example, the contract information of the terminal device includes a separate field for instructing the session management function network element to perform energy information statistics; or the indication information may be implicitly indicated in the contract information of the terminal device, for example, when a specific bit in the ID of the terminal device is 1, indicating that the indication information exists, or may be a message name indication.
[0128] Accordingly, the session management function network element can obtain the energy quota corresponding to the terminal device or the energy quota corresponding to the session of the terminal device in response to the indication information. The energy quota corresponding to the terminal device refers to the maximum value of energy used for network transmission of the data of the terminal device, or can also be understood as the maximum value of energy allowed to be consumed by the network to transmit the data of the terminal device, or the maximum amount of energy that can be consumed by the network to transmit the data of the terminal device. The energy quota of a session refers to the maximum value of energy used for network transmission of the data of the session, or can also be understood as the maximum value of energy allowed to be consumed by the network to transmit the data of the session, or the maximum amount of energy that can be consumed by the network to transmit the data of the session. Optionally, the energy quota of the terminal device can also be replaced by the total energy quota corresponding to the terminal device, and the energy quota of the terminal device includes the energy quota of each session of the terminal device. For example, the energy quota of the terminal device or the energy quota of the session of the terminal device is configured in the contract information of the terminal device, and the session management function network element can obtain the energy quota of the terminal device or the energy quota of the session of the terminal device based on the contract information of the terminal device. For example, the session management function network element can send an energy quota query request to the network data analysis function (charging function, CHF) network element, the NWDAF network element, or an independently set energy information network element, and receive an energy quota query response. The energy quota query response may include one or more of the following: the energy quota of the network slice, the energy quota of the terminal device, and the energy quota of the session of the terminal device.
[0129] S302: The access network device determines whether to activate security protection of the data radio bearer of the session of the terminal device according to the energy information corresponding to the terminal device.
[0130] In a possible implementation, this step can be divided into the following two steps S3021 and S3022:
[0131] S3021: The access network device determines whether the energy information corresponding to the terminal device meets the first condition.
[0132] The energy information corresponding to the terminal device is used to indicate the energy consumed by the network corresponding to the access network device when transmitting the data of the terminal device, or the energy information corresponding to the terminal device is used to indicate the energy efficiency corresponding to the network corresponding to the access network device when transmitting the data of the terminal device. It is understandable that the energy information corresponding to the terminal device includes the energy information corresponding to the session of the terminal device, the energy consumed by the network transmitting the data of the terminal device includes the energy consumed by the network transmitting the data of the session of the terminal device, and the energy efficiency corresponding to the network transmitting the data of the terminal device includes the energy efficiency corresponding to the network transmitting the data of the session of the terminal device.
[0133] First, the access network device can obtain energy information corresponding to the terminal device. For example, the access network device obtains energy information corresponding to the terminal device from a first network element; the first network element can be used to count (store) the energy currently consumed by the network transmission of the terminal device's data. The first network element can be an OAM, AMF, NWDAF, or a separately configured energy information network element. Taking the first network element as an example, the access network device can send an energy data query request to the OAM, and the OAM sends an energy data query response to the access network device. The energy data query response includes the energy consumed by the network transmission of the terminal device's data (e.g., 1000 joules) or the energy efficiency level corresponding to the network transmission of the terminal device's data (e.g., level 1, 2, or 3). Optionally, the energy data query response can also include the energy consumption corresponding to the access network device. If the access network device manages multiple terminal devices, the energy consumption corresponding to the access network devices can be averaged to the energy consumption corresponding to each terminal device. For example, if the access network device manages three terminal devices, the access network device obtains the energy consumption corresponding to the access network device from the OAM and divides it by 3 to obtain the energy consumed by the network transmission of the terminal device's data. For example, if the first network element is OAM, the access network device can send an energy data subscription request to OAM, and the energy data subscription request includes subscription cycle information. OAM can periodically send an energy data subscription response to the access network device according to the subscription cycle information. The energy data subscription response includes the energy currently consumed by the data of the network transmission terminal device (for example, 1000 joules of electricity), or includes the energy efficiency level corresponding to the data of the network transmission terminal device (for example, level one, level two or level three).
[0134] Then, the access network device determines whether the energy information corresponding to the terminal device meets the first condition based on the received energy information.
[0135] The following are some examples to illustrate the definitions of the first condition.
[0136] Example 1: The energy information corresponding to the terminal device indicates the energy consumed by the network to transmit data of the terminal device, and the first condition indicates that the difference between the energy and the energy quota is less than or equal to a first threshold.
[0137] It can be understood that the energy quota corresponds to the aforementioned terminal device, for example, it can be the energy quota of the terminal device; or, in the case where the energy consumed by the network transmitting the data of the terminal device is the energy consumed by the network transmitting the session data of the terminal device, the energy quota can be the energy quota of the terminal device's session. In one possible design, the energy quota described in Example 1 can be indicated to the terminal device by the session management function network element via second information. For example, as described in S301, the session management function network element obtains the energy quota of the terminal device, and the session management function network element can send second information to the access network device, the second information being used to indicate the energy quota of the terminal device; or, the session management function network element can determine the energy quota of the terminal device's session based on the terminal device's energy quota. For example, if the terminal device corresponds to 5 sessions, the energy quota of the terminal device's session can be 20% of the terminal device's energy quota; then, the session management function network element sends second information to the access network device, the second information indicating the energy quota of the terminal device's session. It is understood that the session management function network element can send the user plane security policy and the second information as described in S301 simultaneously, or can send the user plane security policy and the second information in a time-sharing manner, that is, at different times, and this embodiment of the present application is not limited to this. For example, the SMF first sends the user plane security policy during the PDU session establishment process, and then sends the second information during the PDU session update process. In another possible design, the aforementioned energy quota is determined by the access network device according to local policy.
[0138] Based on this, if the access network device determines that the difference between the energy consumed by the received network transmission of the terminal device's data and the energy quota is less than or equal to the first threshold, then the energy information corresponding to the terminal device is determined to meet the first condition; alternatively, if the access network device determines that the difference between the energy consumed by the received network transmission of the terminal device's data and the energy quota is greater than the first threshold, then the energy information corresponding to the terminal device is determined to not meet the first condition. Optionally, the second threshold in Example 1 can be predefined by the protocol, locally preconfigured by the access network device, or indicated to the access network device by OAM.
[0139] Example 2: The energy information corresponding to the terminal device indicates the energy consumed by the network to transmit data of the terminal device, and the first condition indicates that the ratio of the energy to the energy quota is greater than or equal to a second threshold.
[0140] The definition of energy quota can be understood with reference to Example 1, and will not be elaborated in detail in the embodiment of the present application.
[0141] Based on this, if the access network device determines that the ratio of energy consumed by the received network transmission of the terminal device's data to the energy quota is greater than or equal to the second threshold, then the energy information corresponding to the terminal device is determined to meet the first condition; alternatively, if the access network device determines that the ratio of energy consumed by the received network transmission of the terminal device's data to the energy quota is less than the second threshold, then the energy information corresponding to the terminal device is determined to not meet the first condition. Optionally, the second threshold in Example 2 can be predefined by the protocol, locally preconfigured by the access network device, or indicated to the access network device by OAM.
[0142] Example 3, the energy information corresponding to the terminal device indicates the energy consumed by the network to transmit the data of the terminal device, and the first condition indicates that the consumed energy is greater than or equal to a third threshold. Based on this, if the access network device determines that the energy consumed by the received network to transmit the data of the terminal device is greater than or equal to the third threshold, it is determined that the energy information corresponding to the terminal device meets the first condition; or, if the access network device determines that the energy consumed by the received network to transmit the data of the terminal device is less than the third threshold, it is determined that the energy information corresponding to the terminal device does not meet the first condition. Optionally, the third threshold in Example 3 can be predefined by the protocol, or locally preconfigured by the access network device, or indicated to the access network device by OAM.
[0143] Example 4: The energy information corresponding to the terminal device indicates the energy efficiency corresponding to the network transmission of the data of the terminal device, and the first condition indicates that the energy efficiency is less than or equal to a fourth threshold. Based on this, if the access network device determines that the energy efficiency corresponding to the received network transmission of the data of the terminal device is less than or equal to the fourth threshold, it is determined that the energy information corresponding to the terminal device meets the first condition; or, if the access network device determines that the energy efficiency corresponding to the received network transmission of the data of the terminal device is greater than the fourth threshold, it is determined that the energy information corresponding to the terminal device does not meet the first condition. Optionally, the fourth threshold in this example can be predefined by the protocol, or locally preconfigured by the access network device, or indicated to the access network device by OAM.
[0144] S3022: If the energy information corresponding to the terminal device meets the first condition, the access network device determines not to activate security protection of the data radio bearer of the session.
[0145] In one possible implementation, if, before executing S302, the access network device determines that security protection for the data radio bearer of the session of the terminal device is activated, then after executing S3022 to determine not to activate security protection for the data radio bearer of the session, the access network device may further deactivate security protection for the data radio bearer of the session. For example, the access network device may deactivate security protection for the data radio bearer of the session by sending an RRC connection reconfiguration.
[0146] In another possible implementation, if before executing S302, the access network device determines that the security protection of the data radio bearer of the session of the terminal device is not configured, or the security protection of the data radio bearer of the session of the terminal device is not activated, then after the access network device executes S3022 to determine not to activate the security protection of the data radio bearer of the session, there is no need to perform configuration related to the security protection of the data radio bearer of the session.
[0147] In addition, if the energy information corresponding to the terminal device does not meet the first condition, the access network device determines whether to activate the security protection of the data wireless bearer of the session according to the existing protocol or technical design solution, and the embodiment of the present application is not limited to this.
[0148] In the above-mentioned solution 1, when the user plane security policy indication corresponding to the session of the terminal device takes priority, the access network device determines whether to activate the security protection of the data wireless bearer of the terminal device's session based on the energy information corresponding to the terminal device. For example, when the energy information corresponding to the terminal device meets the set conditions, it is determined not to activate the security protection of the data wireless bearer of the terminal device's session, which can reduce network energy consumption and achieve energy saving.
[0149] It should be understood that in the above embodiments, the size of the sequence number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0150] Option 2
[0151] FIG4 illustrates a communication method, which mainly includes the following steps:
[0152] S401: The unified data management network element sends a first user plane security policy corresponding to a session of a terminal device to a session management function network element.
[0153] Among them, the first user plane security policy indication corresponding to the session is preferred; or a new user plane security policy indication a can be added based on whether the first user plane security policy indication is required, not required, or preferred. For example, the newly added user plane security policy indication a can be preferred according to energy state. Based on this, the first user plane security policy indication corresponding to the session is based on energy state priority, which can also be understood as indicating the security protection of the DRB for the session of the terminal device based on energy priority activation or the security protection of the DRB for the session of the terminal device based on energy priority deactivation.
[0154] In one possible implementation, the subscription information of the terminal device stored in the unified data management network element includes the first user plane security policy corresponding to the session of the terminal device, and the unified data management network element can send the subscription information of the terminal device to the session management function network element. For example, during the session establishment process, the terminal device initiates a session establishment request (session establishment request) to the session management function network element through the access network device; the session management function network element can query the subscription information of the terminal device from the unified data management network element during the session establishment process, or the session management function network element can query the subscription information of the terminal device from the unified data management network element after the session is established. It is understandable that the control of user plane security protection for the session in the embodiment of the present application can occur during the session establishment process or after the session is established. For example, the control of user plane security protection for the session can occur in the session modification process triggered by the change of energy consumption status after the session is established, and the embodiment of the present application is not limited to this. As an example, in Figure 4, an optional step is also indicated by a dotted line before S401: S400: The terminal device initiates a session establishment request to the session management function network element through the access network device.
[0155] Optionally, the contract information of the terminal device stored in the unified data management network element may further include indication information for instructing the session management function network element to perform energy consumption statistics. The indication information may be explicitly indicated in the contract information of the terminal device, for example, the contract information of the terminal device includes a separate field for instructing the session management function network element to perform energy consumption statistics; or, the indication information may be implicitly indicated in the contract information of the terminal device, for example, when a specific bit in the ID of the terminal device is 1, it indicates that the indication information exists, or it may be a message name indication. Accordingly, the session management function network element may obtain the energy quota of the terminal device or the energy quota of the session of the terminal device in response to the indication information. For example, the energy quota of the terminal device or the energy quota of the session of the terminal device is configured in the contract information of the terminal device stored in the unified data management network element, and the session management function network element may obtain the energy quota of the terminal device or the energy quota of the session of the terminal device based on the contract information of the terminal device. For example, the session management function network element can send an energy quota query request to the CHF, NWDAF, or an independently set energy information network element, and receive an energy quota query response, which may include one or more of the following: the energy quota of the network slice, the energy quota of the terminal device, and the energy quota of the session of the terminal device.
[0156] It is understandable that S401 is illustrated in FIG4 as an optional step, that is, when implementing this solution, S401 can be skipped and execution can be started from S402 , which is not limited in this embodiment of the present application.
[0157] S402: The session management function network element obtains energy information corresponding to the terminal device.
[0158] It is understood that the energy information corresponding to the terminal device is used to indicate the energy consumed by the network when transmitting the data of the terminal device, or the energy information corresponding to the terminal device is used to indicate the energy efficiency corresponding to the network when transmitting the data of the terminal device. It is understood that the energy information corresponding to the terminal device includes the energy information corresponding to the session of the terminal device, the energy consumed by the network when transmitting the data of the terminal device includes the energy consumed by the network when transmitting the session data of the terminal device, and the energy efficiency corresponding to the network when transmitting the data of the terminal device includes the energy efficiency corresponding to the network when transmitting the session data of the terminal device. The "network" here refers to the network where the session management function network element, access network equipment, and terminal devices are located.
[0159] In one possible design, the session management function network element may receive energy information corresponding to the terminal device from the first network element. For example, the first network element may be an OAM. The manner in which the session management function network element obtains energy information from the OAM can be understood with reference to the description in S3021 and will not be further described in this embodiment of the present application. In another possible design, the session management function network element may independently calculate the energy consumed by the network in transmitting the session data of the terminal device and / or the energy efficiency corresponding to the network in transmitting the data of the terminal device.
[0160] S403: The session management function network element sends a first message to the access network device according to the energy information corresponding to the terminal device.
[0161] The first message is used by the access network device to determine whether to activate the security protection of the data radio bearer of the session of the terminal device.
[0162] When S401 is executed, step S403 may also be replaced by the description that when the first user plane security policy indicates priority, the session management function network element sends the first message to the access network device according to the energy information.
[0163] Exemplarily, this step can be divided into the following two steps S4031 and S4032a, or two steps S4031 and S4032b:
[0164] S4031, the session management function network element determines whether the energy information corresponding to the terminal device meets the first condition.
[0165] Among them, when the energy information corresponding to the terminal device indicates the energy consumed by the network to transmit the data of the terminal device, the first condition indicates that the difference between the energy and the energy quota is less than or equal to the first threshold; or, when the energy information corresponding to the terminal device indicates the energy consumed by the network to transmit the data of the terminal device, the first condition indicates that the ratio of the energy to the energy quota is greater than or equal to the second threshold; or, when the energy information corresponding to the terminal device indicates the energy consumed by the network to transmit the data of the terminal device, the first condition indicates that the energy is greater than or equal to the third threshold; or, when the energy information corresponding to the terminal device indicates the energy efficiency corresponding to the network transmitting the data of the terminal device, the first condition indicates that the energy efficiency is less than or equal to the fourth threshold.
[0166] In one possible design, the session management function network element can independently determine whether the energy information corresponding to the terminal device meets the first condition. In another possible design, after receiving the energy information corresponding to the terminal device from the first network element, the session management function network element can request the CHF to statistically analyze the energy information. The session management function network element then determines whether the energy information corresponding to the terminal device meets the first condition based on the feedback information from the CHF. For example, the session management function network element can periodically or pre-configuredly send an energy usage report to the CHF. The energy usage report includes the energy consumed by the network transmission of the terminal device's data, as summarized by the session management function network element. The CHF checks whether the energy consumed by the network transmission of the terminal device's data meets the first condition based on the energy usage report sent by the session management function network element. If so, the CHF sends a second message to the SMF. The second message may include the ID of the target session and / or the ID of the terminal device. It is understood that the second message is used to indicate that the energy information corresponding to the terminal device meets the first condition. The second message is also used to instruct the deactivation or inactivation of security protection for the data radio bearer of the target session of the terminal device.
[0167] Furthermore, when the session management function network element determines that the energy information corresponding to the terminal device meets the first condition, it executes S4032a or S4032b.
[0168] S4032a, the session management function network element sends a first message to the access network device, where the first message includes a second user plane security policy corresponding to the session of the terminal device.
[0169] If the energy information corresponding to the terminal device meets the first condition, the second user plane security policy indicates that it is not required, or alternatively, the second user plane security policy indicates that it is not required to activate security protection corresponding to the session. The security protection corresponding to the session may be user plane security protection corresponding to the session, such as security protection for the data radio bearer of the session. Accordingly, the access network device determines not to activate security protection for the data radio bearer of the session of the terminal device based on the second user plane security policy. For example, in a roaming scenario, the session management function network element may modify the user plane security policy in the terminal device's subscription information from indicating priority to not requiring based on local policies related to energy consumption.
[0170] In one possible design, if the session management function network element determines that security protection of the data radio bearer of the session of the terminal device is activated before sending the second user plane security policy, then the second user plane security policy included in the first message sent by the session management function network element can be understood as triggering the access network device to deactivate the security protection of the data radio bearer of the session of the terminal device. Accordingly, after receiving the second user plane security policy, the access network device can implement the security protection of the data radio bearer of the deactivated session by sending RRC connection reconfiguration.
[0171] For example, the session management function network element may determine whether the security protection of the radio bearer of the session of the terminal device is activated in one or more of the following ways: the session management function network element receives a user plane enforcement policy notification from the access network device, where the user plane enforcement policy notification indicates that the security protection of the radio bearer of the session of the terminal device is activated; or, the session management function network element queries historical session records from the unified data management network element based on the identifier of the terminal device; or, the session management function network element may locally store the user plane security policy indicated to the access network device, and based on this, the session management function network element determines whether the security protection of the radio bearer of the session of the terminal device is activated based on the local historical records.
[0172] S4032b: The session management function network element sends a first message to the access network device, where the first message includes the first user plane security policy and third information.
[0173] The first user plane security policy is derived from a unified data management network element, corresponds to a session of a terminal device, and takes precedence over the first user plane security policy. The third information indicates that the energy information corresponding to the terminal device meets the first condition, and the third information is used to trigger the access network device to determine not to activate security protection for the data radio bearer of the session of the terminal device. Optionally, the third information may be replaced with an energy reason indication or another name, which is not limited in this embodiment of the present application.
[0174] S404: The access network device determines, based on the first message, to deactivate security protection of the radio bearer of the session data of the terminal device.
[0175] In the above-mentioned solution 2, when the user plane security policy indication corresponding to the session of the terminal device takes precedence, the session management function network element updates the user plane security policy indication to the access network device based on the energy information corresponding to the terminal device, so that the access network device can quickly determine the security protection of the data wireless bearer of the session of the inactivated terminal device, which can reduce network energy consumption and achieve energy saving.
[0176] It should be understood that in the above embodiments, the size of the sequence number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0177] Option 3
[0178] FIG5 illustrates a communication method, which can be applied before establishing a session (such as a PDU session) of a terminal device, during establishing a session (such as a PDU session) of a terminal device, after establishing a session (such as a PDU session) of a terminal device, or during modifying a session (such as a PDU session) of a terminal device. Exemplarily, the method mainly includes the following steps.
[0179] S501: The session management function network element determines that the network adopts energy-saving mode to serve the terminal device.
[0180] The network adopts energy-saving mode to serve the terminal device, which can also be replaced by the description that: the mode of the network serving the terminal device is energy-saving mode.
[0181] In one possible design, the session management function network element may determine, under the triggering of other network elements, that the network adopts an energy-saving mode to serve the terminal device. It is understandable that the network is the network where the session management function network element is located. For example, the session management function network element receives fourth information, which indicates that the specified network granularity enters an energy-saving state (or energy-saving mode), or alternatively, it may be described as: the fourth information is used to request or trigger the session management function network element to control the energy consumption of all sessions of the specified network granularity. If all sessions corresponding to the specified network granularity include the session of the aforementioned terminal device, the session management function network element may determine that the network adopts an energy-saving mode to serve the terminal device.
[0182] Exemplarily, the designated network granularity can also be replaced by the designated level. The designated network granularity can be at least one of the node level, slice level, or application level. As shown in Figure 5, S500 can also be performed before S501: the session management function network element receives fourth information from a second network element, where the second network element can be an OAM, NWDAF, PCF, AF, NEF, or an independently configured energy information network element. In the case where the fourth information comes from OAM, the aforementioned designated network granularity is the entire current network or a specific node. For example, the fourth information indicates that an access network device has entered an energy-saving state. The access network device serves (or manages) a terminal device, and all sessions of the terminal device served by the access network device include the session of the terminal device described in S501. For another example, the fourth information indicates that the session management function network element has entered an energy-saving state, and the sessions managed by the session management function network element include the session of the terminal device described in S501. In the case where the fourth information comes from NWDAF, the aforementioned designated network granularity is a network slice or a specific node. The fourth information indicates that a network slice has entered an energy-saving state. The network slice includes the session of the terminal device described in S501. In the case where the fourth information comes from AF or NEF, the aforementioned designated network granularity is at the application level, and the fourth information indicates that the application enters an energy-saving state, and all sessions related to the application include the session of the terminal device described in S501. In the case where the fourth information comes from an independently set energy information network element: the aforementioned designated network granularity is at the terminal level, and the fourth information indicates that the network adopts an energy-saving mode to serve the terminal device; or, the aforementioned designated network granularity is at the node level (such as an access network device), and the fourth information indicates that the access network device enters an energy-saving state. In the case where the fourth information comes from PCF: the aforementioned designated network granularity is at the terminal level, and the fourth information indicates that the network adopts an energy-saving mode to serve the terminal device; or, the aforementioned designated network granularity is at the session level, and the fourth information indicates that the service mode for the session enters an energy-saving state.
[0183] Furthermore, S502 illustrates that after determining that the network adopts the energy-saving mode to serve the terminal device, the session management function network element triggers the access network device to determine not to activate the security protection of the data radio bearer of the session.
[0184] S502: The session management function network element sends a first message to the access network device.
[0185] The first message is used by the access network device to determine not to activate security protection of the data radio bearer of the session.
[0186] In one possible design, the first message includes a user plane security policy corresponding to the session of the terminal device and fifth information; wherein the user plane security policy corresponding to the session of the terminal device indicates priority, and the fifth information instructs the network to serve the terminal device in energy-saving mode. The method for determining the user plane security policy can be understood with reference to the description in S301, and is not further described in this embodiment of the application.
[0187] In another possible design, the first message includes a user plane security policy of the terminal device, and the user plane security policy indicates that it is not needed, that is, there is no need to activate security protection corresponding to the session of the terminal device.
[0188] Accordingly, after receiving the first message, the access network device may execute the following step S503.
[0189] S503: The access network device determines not to activate security protection of the data radio bearer of the session according to the first message.
[0190] Alternatively, if user plane security protection for a session of a terminal device is activated and the session management function network element determines that the network uses energy-saving mode to serve the terminal device, step S502 may be replaced with S504 as shown in FIG5 : the session management function network element may only send fifth information to the access network device, where the fifth information is used to instruct the network to use energy-saving mode to serve the terminal device, thereby triggering the access network device to execute S505: deactivate security protection for the data radio bearer of the session. For example, the access network device may deactivate security protection for the data radio bearer of the session by sending an RRC connection reconfiguration.
[0191] It should be understood that in the above embodiments, the size of the sequence number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0192] Option 4
[0193] FIG6 illustrates a communication method, which can be applied before establishing a session (such as a PDU session) of a terminal device, during establishing a session (such as a PDU session) of a terminal device, after establishing a session (such as a PDU session) of a terminal device, or during modifying a session (such as a PDU session) of a terminal device. Exemplarily, the method mainly includes the following steps.
[0194] S601: The access network device determines that the network uses the energy-saving mode to serve the terminal device. The network uses the energy-saving mode to serve the terminal device, which can also be replaced by: the mode of the network serving the terminal device is the energy-saving mode.
[0195] In one possible design, the access network device may determine, triggered by other network elements, that the network adopts an energy-saving mode to serve the terminal device. For example, the access network device receives fourth information indicating that a specified network granularity enters an energy-saving state (or energy-saving mode), or alternatively, the fourth information is used to request or trigger a session management function network element to perform energy consumption control for all sessions at the specified network granularity. If all sessions corresponding to the specified network granularity include the session of the aforementioned terminal device, the session management function network element may determine that the network adopts an energy-saving mode to serve the terminal device.
[0196] Exemplarily, the designated network granularity can also be replaced by the description of the designated level, and the designated network granularity can be at least one of the node level, slice level, or application level. As shown in Figure 6, S600 can also be executed before S601: the access network device receives fourth information, and the fourth information can come from a second network element. The second network element can be OAM, NWDAF, PCF, AF, NEF, or an independently set energy information network element. In the case where the fourth information comes from OAM, the aforementioned designated network granularity is the current entire network or a specific node. For example, the fourth information indicates that the access network device enters an energy-saving state, and all sessions of the terminal device managed by the access network device include the session of the terminal device described in S601; for another example, the fourth information indicates that the session management function network element enters an energy-saving state, and all sessions managed by the session management function network element include the session of the terminal device described in S601. In the case where the fourth information comes from NWDAF, the aforementioned designated network granularity is a network slice or a specific node, and the fourth information indicates that the network slice enters an energy-saving state, and the network slice includes the session of the terminal device described in S601. In the case where the fourth information comes from AF or NEF, the aforementioned designated network granularity is at the application level, and the fourth information indicates that the application enters an energy-saving state, and all sessions related to the application include the session of the terminal device described in S601. In the case where the fourth information comes from an independently set energy information network element: the aforementioned designated network granularity is at the terminal level, and the fourth information indicates that the network adopts an energy-saving mode to serve the terminal device; or, the aforementioned designated network granularity is at the node level (such as an access network device), and the fourth information indicates that the access network device enters an energy-saving state. In the case where the fourth information comes from PCF: the aforementioned designated network granularity is at the terminal level, and the fourth information indicates that the network adopts an energy-saving mode to serve the terminal device; or, the aforementioned designated network granularity is at the session level, and the fourth information indicates that the service mode for the session enters an energy-saving state.
[0197] S602: The access network device determines not to activate security protection of the data radio bearer of the session of the terminal device.
[0198] Optionally, the access network device can also obtain the user plane security policy corresponding to the session of the terminal device from the session management network element, or the user plane security policy corresponding to the session of the terminal device according to the historical records. When the user plane security policy indicates priority, the access network device does not activate the security protection of the data wireless bearer of the session of the terminal device.
[0199] In the above-mentioned schemes 3 and 4, by configuring the specified network granularity to enter the energy-saving state and not activating or deactivating (de-activating) the security protection of the data wireless bearer of the session of the terminal device corresponding to the specified network granularity, network energy consumption can be reduced and energy saving can be achieved.
[0200] It should be understood that in the above embodiments, the size of the sequence number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0201] Plan 5
[0202] FIG7 illustrates a communication method, which includes the following steps.
[0203] S701: The session management function network element obtains the contract information of the terminal device from the unified data management network element.
[0204] The contract information includes a first user plane security policy corresponding to the session of the terminal device and an energy quota of the terminal device, and the first user plane security policy indicates "priority".
[0205] S702, the session management function network element establishes a first PDU session with the terminal device.
[0206] After the session is successfully established, the security protection of the data radio bearer of the first PDU session is activated.
[0207] S703, the terminal device initiates a session establishment request for the second PDU session to the session management function network element through the access network device.
[0208] S704: The session management function network element sends an energy data subscription request to the first network element. The energy data subscription request is used to subscribe to energy information corresponding to the terminal device.
[0209] The energy information corresponding to the terminal device indicates the energy consumed by the network for transmitting the data of the terminal device, and / or includes the energy efficiency corresponding to the network for transmitting the data of the terminal device.
[0210] The first network element may be an OAM, NWDAF, PCF or a separately set energy information network element.
[0211] S705: The first network element sends an energy data subscription response to the session management function network element. The energy data subscription response includes energy information corresponding to the terminal device.
[0212] The energy information corresponding to the terminal device indicates the value of energy currently consumed by the network transmitting the data of the terminal device, and / or includes the energy efficiency level corresponding to the network transmitting the data of the terminal device.
[0213] Optionally, the energy data subscription request can be used to periodically subscribe to the energy information corresponding to the terminal device. Accordingly, the first network element can periodically send an energy data subscription response to the session management function network element, that is, the first network element sends an energy data subscription response once every specific time (such as 1 hour). Each energy data subscription response sent includes the latest data, such as the energy currently consumed by the network transmission terminal device's data, and / or the current energy efficiency corresponding to the network transmission terminal device's data.
[0214] Optionally, the session function network element can also automatically count the energy currently consumed by the terminal device and then determine the energy information corresponding to the terminal device. In this case, S704 and S705 do not need to be executed, that is, S704 and S705 are optional steps, which are indicated by dotted lines in Figure 7.
[0215] S706: When the session management function network element determines that the energy information corresponding to the terminal device meets the first condition, it sends a first message to the access network device.
[0216] The first message is used to trigger the access network device to determine not to activate the security protection of the data radio bearer of the second PDU session of the terminal device. Optionally, the first message is also used to trigger the access network device to deactivate the security protection of the data radio bearer of the first PDU session. The definition of the first condition can be understood with reference to the description in S3021 and S4031, and this step can be implemented with reference to the description in S402.
[0217] In one possible implementation, the first message includes a second user plane security policy corresponding to a session of the terminal device, and the second user plane security policy indicates that it is not required. In another possible implementation, the first message includes the first user plane security policy corresponding to the session of the terminal device and the third information indicating that the energy information corresponding to the terminal device meets the first condition.
[0218] S707: The access network device determines not to activate security protection of the data radio bearer of the second PDU session according to the first message.
[0219] Optionally, the access network device may further execute S708.
[0220] S708: The access network device determines to deactivate security protection of the data radio bearer of the first PDU session according to the first message.
[0221] For example, the access network device can implement security protection for the data radio bearer of a deactivated session by sending an RRC connection reconfiguration. In the aforementioned solution five, when establishing a new PDU session, the energy consumption corresponding to an already established PDU session is referenced. If the energy consumption corresponding to the already established PDU session meets the first condition of exceeding the standard, the security protection for the data radio bearer of the new PDU session is not activated, thereby reducing network energy consumption and achieving energy conservation.
[0222] Based on the same concept, referring to FIG8 , an embodiment of the present application provides a communication device 800, which includes a processing module 801 and a communication module 802. The communication device 800 can be a terminal device, or a communication device applied to a terminal device or used in conjunction with a terminal device, capable of implementing a communication method executed on the terminal device side; or the communication device 800 can be an access network device, or a communication device applied to an access network device or used in conjunction with an access network device, capable of implementing a communication method executed on the access network device side; or the communication device 800 can be a core network element, or a communication device applied to a core network element or used in conjunction with a core network element, capable of implementing a communication method executed on the core network element side.
[0223] The communication module may also be referred to as a transceiver module, transceiver, transceiver, or transceiver device. The processing module may also be referred to as a processor, processing board, processing unit, or processing device. Optionally, the communication module is used to perform the sending and receiving operations on the terminal device side or the access network device side in the above method. The device in the communication module that implements the receiving function can be considered a receiving unit, and the device in the communication module that implements the sending function can be considered a sending unit. That is, the communication module includes a receiving unit and a sending unit.
[0224] When the communication device 800 is applied to a terminal device, the processing module 801 can be used to implement the processing function of the terminal device described in the embodiments shown in Figures 3 to 7, and the communication module 802 can be used to implement the transceiver function of the terminal device described in the embodiments shown in Figures 3 to 7.
[0225] When the communication device 800 is applied to an access network device, the processing module 801 can be used to implement the processing function of the access network device described in the embodiments shown in Figures 3 to 7, and the communication module 802 can be used to implement the transceiver function of the access network device described in the embodiments shown in Figures 3 to 7.
[0226] When the communication device 800 is applied to a core network element, the processing module 801 can be used to implement the processing function of the core network element in the embodiments shown in Figures 3 to 7, and the communication module 802 can be used to implement the sending and receiving functions of the core network element in the embodiments shown in Figures 3 to 7.
[0227] In addition, it should be noted that the aforementioned communication module and / or processing module can be implemented through virtual modules, for example, the processing module can be implemented through a software functional unit or a virtual device, and the communication module can be implemented through a software function or a virtual device. Alternatively, the processing module or the communication module can also be implemented through a physical device. For example, if the communication device is implemented using a chip / chip circuit, the communication module can be an input / output circuit and / or a communication interface that performs input operations (corresponding to the aforementioned receiving operations) and output operations (corresponding to the aforementioned sending operations); the processing module is an integrated processor, microprocessor, or integrated circuit.
[0228] The division of modules in the embodiments of the present application is illustrative and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of the present application may be integrated into a single processor, or may exist physically separately, or two or more modules may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or software functional modules.
[0229] Based on the same technical concept, the embodiment of the present application further provides a communication device 900. For example, the communication device 900 can be a chip or a chip system. Optionally, in the embodiment of the present application, the chip system can be composed of a chip, or can include a chip and other discrete devices.
[0230] The communication device 900 can be used to implement the functions of any network element in the communication system described in the aforementioned embodiments. The communication device 900 may include at least one processor 910, which is coupled to a memory. Optionally, the memory may be located within the communication device, the memory may be integrated with the processor, or the memory may be located outside the communication device. For example, the communication device 900 may also include at least one memory 920. The memory 920 stores the necessary computer programs, computer programs or instructions and / or data for implementing any of the aforementioned embodiments; the processor 910 may execute the computer program stored in the memory 920 to complete the method in any of the aforementioned embodiments.
[0231] The communication device 900 may also include a communication interface 930, and the communication device 900 can exchange information with other devices through the communication interface 930. Exemplarily, the communication interface 930 can be a transceiver, a circuit, a bus, a module, a pin, or other types of communication interfaces. When the communication device 900 is a chip-type device or circuit, the communication interface 930 in the communication device 900 can also be an input-output circuit that can input information (or receive information) and output information (or send information). The processor is an integrated processor or microprocessor or integrated circuit or logic circuit, and the processor can determine output information based on the input information.
[0232] The coupling in the embodiments of the present application is an indirect coupling or communication connection between devices, units, or modules, which can be electrical, mechanical, or other forms, and is used for information exchange between devices, units, or modules. The processor 910 may operate in conjunction with the memory 920 and the communication interface 930. The specific connection medium between the processor 910, memory 920, and communication interface 930 is not limited in the embodiments of the present application.
[0233] Optionally, referring to FIG9 , the processor 910, the memory 920, and the communication interface 930 are interconnected via a bus 940. The bus 940 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus may be classified as an address bus, a data bus, a control bus, etc. For ease of illustration, FIG9 shows only one thick line, but this does not mean that there is only one bus or only one type of bus.
[0234] In the embodiments of the present application, the processor may be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the present application may be directly implemented as being executed by a hardware processor, or may be executed by a combination of hardware and software modules in the processor.
[0235] In an embodiment of the present application, the memory may be a non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), etc., or a volatile memory (volatile memory), such as a random-access memory (RAM). The memory is any other medium that can be used to carry or store a desired program code in the form of an instruction or data structure and can be accessed by a computer, but is not limited thereto. The memory in the embodiment of the present application may also be a circuit or any other device that can implement a storage function, for storing program instructions and / or data.
[0236] In one possible implementation, the communication device 900 can be applied to an access network device. The communication device 900 can be an access network device, or a device that can support the access network device and implement the functions of the access network device in any of the above-mentioned embodiments. The memory 920 stores computer programs (or instructions) and / or data that implement the functions of the access network device in any of the above-mentioned embodiments. The processor 910 can execute the computer program stored in the memory 920 to complete the method performed by the access network device in any of the above-mentioned embodiments. Applied to an access network device, the communication interface in the communication device 900 can be used to interact with a terminal device, send information to the terminal device, or receive information from the terminal device.
[0237] In one possible implementation, the communication device 900 can be applied to a core network network element (such as SMF, UDM, etc.). For example, the communication device 900 can be a core network network element, or it can be a device that can support a core network network element and implement the functions of the core network element in any of the above-mentioned embodiments. The memory 920 stores a computer program (or instruction) and / or data that implements the functions of the core network element in any of the above-mentioned embodiments. The processor 910 can execute the computer program stored in the memory 920 to complete the method executed by the core network element in any of the above-mentioned embodiments. Applied to a core network network element, the communication interface in the communication device 900 can be used to interact with an access network device and other core network network elements, send information to an access network device and other core network elements, or receive information from an access network device and other core network elements.
[0238] In another possible implementation, the communication device 900 can be applied to a terminal device. For example, the communication device 900 can be a terminal device, or a device that can support a terminal device and implement the functions of the terminal device in any of the above-mentioned embodiments. The memory 920 stores a computer program (or instruction) and / or data that implements the functions of the terminal device in any of the above-mentioned embodiments. The processor 910 can execute the computer program stored in the memory 920 to complete the method executed by the terminal device in any of the above-mentioned embodiments. Applied to a terminal device, the communication interface in the communication device 900 can be used to interact with an access network device, send information to the access network device, or receive information from the access network device.
[0239] Since the communication device 900 provided in this embodiment can be applied to an access network device to implement the method executed by the access network device, or applied to a terminal device to implement the method executed by the terminal device, the technical effects that can be achieved can be referred to the above method examples and will not be repeated here.
[0240] Based on the above embodiments, an embodiment of the present application provides a communication system, including an access network device and a terminal device, wherein the access network device and the terminal device can implement the methods provided in the embodiments shown in Figures 3 to 7.
[0241] The technical solutions provided in the embodiments of the present application can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, they can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a terminal device, an access network device, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital video disc (DVD)), or a semiconductor medium.
[0242] In the embodiments of the present application, under the premise that there is no logical contradiction, the embodiments may reference each other, for example, the methods and / or terms between method embodiments may reference each other, for example, the functions and / or terms between device embodiments may reference each other, for example, the functions and / or terms between device embodiments and method embodiments may reference each other.
[0243] Obviously, those skilled in the art may make various changes and modifications to the embodiments of the present application without departing from the scope of the embodiments of the present application. Thus, if these modifications and variations of the embodiments of the present application fall within the scope of the claims of the embodiments of the present application and their equivalents, the embodiments of the present application are intended to include these modifications and variations.
Claims
1. A communication method, characterized in that: include: An access network device in the network receives a user plane security policy from a session management function network element in the network, where the user plane security policy corresponds to a session of the terminal device; In a case where the user plane security policy indicates priority, the access network device determines, based on the energy information corresponding to the terminal device, whether to activate security protection for a data radio bearer, the data radio bearer belonging to the session; The energy information is used to indicate the energy consumed by the network in transmitting the data of the terminal device, or the energy information is used to indicate the energy efficiency corresponding to the network in transmitting the data of the terminal device.
2. The method according to claim 1, wherein The energy information includes the energy information corresponding to the session, the energy consumed by the network to transmit the data of the terminal device includes the energy consumed by the network to transmit the data of the session, and the energy efficiency corresponding to the network transmitting the data of the terminal device includes the energy efficiency corresponding to the network transmitting the data of the session.
3. The method according to claim 1 or 2, wherein: Also includes: The access network device receives the energy information from the first network element.
4. The method according to any one of claims 1 to 3, wherein The access network device determines, according to the energy information corresponding to the terminal device, whether to activate security protection of the data radio bearer, including: When the energy information meets the first condition, the access network device determines not to activate the security protection of the data radio bearer; wherein, The energy information indicates energy consumed by the network to transmit data of the terminal device, the first condition indicates that a difference between the consumed energy and the energy quota is less than or equal to a first threshold, and the energy quota indicates a maximum value of energy used by the network to transmit data of the terminal device; or The energy information indicates the energy consumed by the network to transmit data of the terminal device, and the first condition indicates that the ratio between the consumed energy and the energy quota is greater than or equal to a second threshold; or The energy information indicates the energy consumed by the network to transmit data of the terminal device, and the first condition indicates that the consumed energy is greater than or equal to a third threshold; or The energy information indicates the energy efficiency corresponding to the network transmitting the data of the terminal device, and the first condition indicates that the energy efficiency is less than or equal to a fourth threshold.
5. The method according to claim 4, wherein Also includes: First information is received from the session management function network element, where the first information is used to indicate the energy quota.
6. A communication method, characterized in that: include: A session management function network element in the network obtains energy information corresponding to the terminal device, where the energy information is used to indicate energy consumed by the network in transmitting data of the terminal device, or the energy information is used to indicate energy efficiency corresponding to the network in transmitting data of the terminal device; The session management function network element sends a first message to an access network device in the network based on the energy information, where the first message is used to determine whether to activate security protection of a data radio bearer, where the data radio bearer belongs to a session of the terminal device.
7. The method according to claim 6, wherein Before the session management function network element in the network obtains the energy information corresponding to the terminal device, the method further includes: The session management function network element receives a first user plane security policy from the unified data management network element, where the first user plane security policy corresponds to the session of the terminal device; The session management function network element sends a first message to an access network device in the network according to the energy information corresponding to the terminal device, including: In a case where the first user plane security policy indicates priority, the session management function network element sends the first message to the access network device according to the energy information.
8. The method according to claim 6 or 7, wherein: The session management function network element sends a first message to an access network device in the network according to the energy information, including: When the energy information meets the first condition, the session management function network element sends the first message to the access network device, where the first message is used to determine not to activate security protection of the data radio bearer; wherein, The energy information indicates energy consumed by the network to transmit data of the terminal device, the first condition indicates that a difference between the consumed energy and the energy quota is less than or equal to a first threshold, and the energy quota indicates a maximum value of energy used by the network to transmit data of the terminal device; or The energy information indicates the energy consumed by the network to transmit data of the terminal device, and the first condition indicates that the ratio between the consumed energy and the energy quota is greater than or equal to a second threshold; or The energy information indicates the energy consumed by the network to transmit data of the terminal device, and the first condition indicates that the consumed energy is greater than or equal to a third threshold; or The energy information indicates the energy efficiency corresponding to the network transmitting the data of the terminal device, and the first condition indicates that the energy efficiency is less than or equal to a fourth threshold.
9. The method according to claim 8, wherein The first message includes a second user plane security policy, and the second user plane security policy indicates that security protection corresponding to the session does not need to be activated.
10. The method according to claim 9, wherein Before the session management function network element sends the first message, the method further includes: The session management function network element determines that security protection of the data radio bearer is activated.
11. The method according to claim 8, wherein The first message includes a first user plane security policy and third information, the third information indicating that the energy information corresponding to the terminal device meets the first condition, the first user plane security policy comes from a unified data management network element, and the first user plane security policy corresponds to the session of the terminal device.
12. The method according to any one of claims 6 to 10, characterized in that The energy information includes the energy information corresponding to the session, the energy consumed by the network to transmit the data of the terminal device includes the energy consumed by the network to transmit the data of the session, and the energy efficiency corresponding to the network transmitting the data of the terminal device includes the energy efficiency corresponding to the network transmitting the data of the session.
13. A communication method, characterized in that: include: An access network device in a network receives a first message from a session management function network element in the network, the first message including a first user plane security policy and third information; wherein the first user plane security policy corresponds to a session of a terminal device, the first user plane security policy indicates priority, and the third information indicates that energy information corresponding to the terminal device meets a first condition; wherein, The energy information indicates energy consumed by the network to transmit data of the terminal device, the first condition indicates that a difference between the consumed energy and the energy quota is less than or equal to a first threshold, and the energy quota indicates a maximum value of energy used by the network to transmit data of the terminal device; or The energy information indicates the energy consumed by the network to transmit data of the terminal device, and the first condition indicates that the ratio between the consumed energy and the energy quota is greater than or equal to a second threshold; or The energy information indicates the energy consumed by the network to transmit data of the terminal device, and the first condition indicates that the consumed energy is greater than or equal to a third threshold; or The energy information indicates energy efficiency corresponding to network transmission of data of the terminal device, and the first condition indicates that the energy efficiency is less than or equal to a fourth threshold; The access network device determines, based on the first message, to deactivate security protection of a data radio bearer, where the data radio bearer belongs to the session.
14. A communication method, characterized in that: include: A session management function network element in the network determines that the network adopts an energy-saving mode to serve the terminal device; The session management function network element sends a first message to an access network device in the network, where the first message is used by the access network device to determine not to activate security protection of a data radio bearer, where the data radio bearer belongs to a session of the terminal device.
15. The method according to claim 14, wherein The session management function network element in the network determines that the network adopts the energy-saving mode to serve the terminal device, including: The session management function network element receives the fourth information, and determines, according to the fourth information, that the network adopts the energy-saving mode to serve the terminal device; The fourth information indicates that the network slice enters an energy-saving state, and the network slice includes the session of the terminal device; or, the fourth information indicates that the session management function network element enters an energy-saving state, and the sessions managed by the session management function network element include the session of the terminal device; or, the fourth information indicates that the access network device enters an energy-saving state, and the access network device serves the terminal device.
16. The method according to claim 14 or 15, characterized in that The first message includes a user plane security policy corresponding to the session of the terminal device and fifth information; wherein, the user plane security policy indicates priority, and the fifth information indicates that the network adopts energy-saving mode to serve the terminal device.
17. A communication method, characterized in that: include: An access network device in the network determines that the network adopts an energy-saving mode to serve the terminal device; In a case where the user plane security policy indication corresponding to the session of the terminal device takes priority, the access network device determines not to activate security protection of the data radio bearer, and the data radio bearer belongs to the session.
18. The method according to claim 17, wherein The access network device in the network determines that the network adopts the energy-saving mode to serve the terminal device, including: The access network device receives the fourth information, and determines, based on the fourth information, that the network adopts the energy-saving mode to serve the terminal device; The fourth information indicates that the network slice enters an energy-saving state, and the network slice includes the session of the terminal device; or, the fourth information indicates that the session management function network element enters an energy-saving state, and the sessions managed by the session management function network element include the session of the terminal device; or, the fourth information indicates that the access network device enters an energy-saving state, and the access network device serves the terminal device.
19. A communication method, characterized in that: include: A session management function network element in the network sends a user plane security policy to an access network device in the network, where the user plane policy corresponds to a session of the terminal device; The access network device receives the user plane security policy from the session management function network element, and when the user plane security policy indicates priority, the access network device determines whether to activate security protection of the data radio bearer of the session according to the energy information corresponding to the terminal device; The energy information corresponding to the terminal device is used to indicate the energy consumed by the network in transmitting the data of the terminal device, or the energy information corresponding to the terminal device is used to indicate the energy efficiency corresponding to the network in transmitting the data of the terminal device.
20. A communication method, characterized in that: include: A session management function network element in the network obtains energy information corresponding to the terminal device, where the energy information is used to indicate energy consumed by the network in transmitting data of the terminal device, or the energy information is used to indicate energy efficiency corresponding to the network in transmitting data of the terminal device; The session management function network element sends a first message to an access network device in the network according to the energy information; The access network device determines whether to activate security protection of a data radio bearer according to the first message, where the data radio bearer belongs to a session of the terminal device.
21. A communication method, characterized in that: include: A session management function network element in the network determines that the network adopts an energy-saving mode to serve the terminal device; The session management function network element sends a first message to an access network device in the network; The access network device determines not to activate security protection of a data radio bearer according to the first message, and the data radio bearer belongs to a session of the terminal device.
22. A communication system, characterized in that: Including access network equipment and session management function network elements, The access network device is used to perform the method according to any one of claims 1 to 5; The session management function network element is used to send a user plane security policy to the access network device.
23. A communication system, characterized in that: Including access network equipment and session management function network elements, The session management function network element is configured to perform the method according to any one of claims 6 to 12; The access network device is used to determine whether to activate security protection of a data radio bearer according to the first message, where the data radio bearer belongs to a session of a terminal device.
24. A communication system, characterized in that: Including access network equipment and session management function network elements, The session management function network element is configured to perform the method according to any one of claims 14 to 16; The access network device is used to determine, according to the first message, to deactivate security protection of a data radio bearer, where the data radio bearer belongs to a session of a terminal device.
25. A communication device, characterized in that: Comprising a module for executing the method according to any one of claims 1 to 5, or a module for executing the method according to any one of claims 6 to 12, or a module for executing the method according to claim 13, or a module for executing the method according to any one of claims 14 to 16, or a module for executing the method according to claim 17 or 18.
26. A communication device, characterized in that: include: A processor, the processor being coupled to a memory, and the processor being configured to call computer program instructions stored in the memory to execute the method according to any one of claims 1 to 18.
27. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions, and when the instructions are executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 18.
28. A computer program product, characterized in that The method comprises instructions, which, when executed on a computer, cause the computer to execute the method according to any one of claims 1 to 18.
Citation Information
Patent Citations
Access stratum security in a wireless communication system
CN111149379A
Communications device, infrastructure equipment, core network equipment and methods
CN113557699A
Integrity protection processing method and device, related equipment and storage medium
CN113596843A
A conveyer transportation apparatus
KR1020230030301A