Method for establishing secure connection, apparatus, and system

By sequentially requesting and forwarding security parameters through intermediate relays and U2N relays, the problem of secure connection between remote UEs and network devices in multi-hop relay scenarios is solved, and efficient and secure communication is achieved.

WO2025214103A9PCT designated stage Publication Date: 2026-03-26HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2026-03-26

Smart Images

  • Figure CN2025083323_26032026_PF_FP_ABST
    Figure CN2025083323_26032026_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a method for establishing a secure connection and a communication apparatus, which can be used in a multi-hop relay service. In one aspect, an intermediate relay uses the intermediate relay as a remote UE, requests to obtain a security parameter from a previous hop thereof to protect a secure connection between the intermediate relay and the previous hop, and in another aspect, uses the intermediate relay as an intermediate relay to request a security parameter for a next hop thereof (for example, another intermediate relay or a remote UE). The intermediate relay may obtain a security parameter for a downstream node thereof on the basis of the secure connection between the intermediate relay and the previous hop. In the multi-hop relay service, each intermediate relay can obtain the security parameter on the basis of the above process and request the security parameter for the next hop, so that viewed along the direction from a network device to the remote UE, a secure connection between adjacent nodes of every two hops in the multi-hop relay service is established in sequence, thus a secure connection between the remote UE and the network device is also established, and communication security can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Method, apparatus and system for establishing secure connection

[0001] The present application claims priority to the Chinese patent application No. 202410430869.3, filed on April 10, 2024, and entitled “Method, apparatus and system for establishing secure connection”, the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application relates to the field of communication, and in particular to a method, apparatus and system for establishing secure connection. BACKGROUND

[0003] Proximity based service (ProSe) communication is a kind of device to device (D2D) communication. User equipments (UEs) with ProSe communication function can communicate through PC5 interface.

[0004] When a certain UE is out of network coverage or has weak communication signal with a radio access network (RAN), the UE can perform assisted communication through a relay. The UE out of network coverage or having weak communication signal with the RAN can be referred to as a remote UE, and the relay can be a UE, which can be referred to as a relay UE. By establishing a communication mode of remote UE to relay UE to network, communication of the UE out of network coverage to the network can be extended. This communication scenario can be referred to as U2N communication, and the relay UE can also be referred to as UE-to-network relay (U2N relay).

[0005] In order to ensure communication security, the remote UE usually needs to obtain a security parameter (for example, a random number generated by the network side for deriving a PC5 root key) from the network device through the U2N relay, which can be used to determine a PC5 root key for protecting the secure connection (or link) between the remote UE and the U2N relay. Since the U2N relay can obtain the security parameter (for example, the PC5 root key) through the existing technology to protect the secure connection between the U2N relay and the network device, the secure connection between the remote UE and the network device can be established.

[0006] But in some cases, the remote UE can not be able to directly connect to the U2N relay, but need to find the U2N relay through one or more hops of relays, that is, need more relay UEs to assist communication. Among them, the relay UE between the remote UE and the U2N relay can be called an intermediate relay. For the scenario that the remote UE connects to the U2N relay through one or more hops of intermediate relays, there is no security solution. SUMMARY

[0007] The present application provides a method, device and system for establishing a secure connection, so as to establish a secure connection between a remote UE and a network device in the presence of multi-hop relays, and improve communication security.

[0008] In a first aspect, a method for establishing a secure connection is provided, which can be applied to a first communication device. The first communication device can be an intermediate relay, or can be a component (such as a circuit, a chip, a chip system or a processor, etc.) in the intermediate relay, or can be a logic module or software capable of realizing all or part of the functions of the intermediate relay, etc. The present application does not limit this.

[0009] In the following, in order to facilitate and illustrate, and to avoid the limitation on the number of hops of multi-hop relay services, the processing logic of the intermediate relay is described through the interaction process between the first communication device, the second communication device, the third communication device and the network device.

[0010] Exemplarily, the method comprises: receiving a first request message from a second communication device, the first request message carrying an identity corresponding to the second communication device; sending a second request message to a third communication device, the third communication device being an intermediate relay or a U2N relay, the second request message carrying an identity corresponding to the first communication device; receiving a first security parameter from the third communication device, the first security parameter being obtained based on the identity corresponding to the first communication device, the first security parameter being used to protect a first secure connection between the third communication device and the first communication device; sending the identity corresponding to the second communication device through the first secure connection, and receiving a second security parameter from the third communication device, the second security parameter being obtained based on the identity corresponding to the second communication device, the second security parameter being used to protect a second secure connection between the first communication device and the second communication device.

[0011] The first communication device corresponds to an intermediate relay; the second communication device is a next hop of the first communication device, which can correspond to a remote UE or another intermediate relay; and the third communication device is a previous hop of the first communication device, which can correspond to a U2N relay or another intermediate relay. In the case of multiple intermediate relays in a multi-hop relay service, each intermediate relay can perform the above scheme as the first communication device in turn, and the relative relationship between the first communication device, the second communication device, and the third communication device remains unchanged.

[0012] For example, the first communication device can correspond to an intermediate relay in FIG. 6 or FIG. 8 below; the second communication device can correspond to a remote UE in FIG. 6 or FIG. 8 below; the third communication device can correspond to a U2N relay in FIG. 6 or FIG. 8; the first security connection can correspond to security connection #1 in FIG. 6 or FIG. 8; the second security connection can correspond to security connection #0 in FIG. 6 or FIG. 8; the first security parameter can correspond to security parameter #1 in FIG. 6 or FIG. 8; and the second security parameter can correspond to security parameter #0 in FIG. 6 or FIG. 8.

[0013] For another example, the first communication device can correspond to an intermediate relay 1 in FIG. 7 below; the second communication device can correspond to a remote UE in FIG. 7; the third communication device can correspond to a U2N relay in FIG. 7; the first security connection can correspond to security connection #1 between the intermediate relay 1 and the intermediate relay 2 in FIG. 7; the second security connection can correspond to security connection #0 between the remote UE and the intermediate relay 1 in FIG. 7; the first security parameter can correspond to security parameter #1 in FIG. 7; and the second security parameter can correspond to security parameter #0 in FIG. 7.

[0014] For another example, the first communication device can correspond to an intermediate relay 1 in FIG. 7 below; the second communication device can correspond to a remote UE in FIG. 7; the third communication device can correspond to a U2N relay in FIG. 7; the first security connection can correspond to security connection #1 between the intermediate relay 1 and the intermediate relay 2 in FIG. 7; the second security connection can correspond to security connection #0 between the remote UE and the intermediate relay 1 in FIG. 7; the first security parameter can correspond to security parameter #1 in FIG. 7; and the second security parameter can correspond to security parameter #0 in FIG. 7.

[0015] Based on the above technical solutions, in the multi-hop relay service, each intermediate relay can establish a secure connection between itself as a remote UE and the network device, and then request security parameters for its downstream nodes as an intermediate relay. The U2N relay can obtain security parameters for each downstream node from the network device according to the identifiers corresponding to the plurality of nodes received, and forward the security parameters corresponding to each node in turn through the secure connection. In this way, the secure connection in the multi-hop relay service is established, and the remote UE can communicate securely with the network device.

[0016] With reference to the first aspect, in some possible implementation manners of the first aspect, the method further includes: sending the second security parameter to the second communication apparatus.

[0017] Forwarding the second security parameter to the second communication apparatus can facilitate the second communication apparatus to generate a session key based on the received second security parameter, so as to protect the second secure connection through the session key.

[0018] With reference to the first aspect, in some possible implementation manners of the first aspect, the first request message further carries a first relay service code (RSC), and the first RSC is used to indicate a relay service. Optionally, the first RSC can also be used to indicate a multi-hop relay service.

[0019] Optionally, the second RSC is also used to determine the first security parameter.

[0020] That is, the parameters used to determine the second security parameter are not limited to the identifier corresponding to the second communication apparatus, but can also include other parameters, such as the second RSC, and a random number 1 provided by the second communication apparatus, and the like.

[0021] With reference to the first aspect, in some possible implementation manners of the first aspect, the second request message further carries a second RSC, and the second RSC is used to indicate a relay service. Optionally, the second RSC is also used to indicate a multi-hop relay service.

[0022] Optionally, the second RSC is also used to determine the first security parameter.

[0023] Similar to the second security parameter, the parameters used to determine the first security parameter are not limited to the identifier corresponding to the first communication apparatus, but can also include other parameters, such as the first RSC, and a random number 1 provided by the first communication apparatus, and the like.

[0024] It should be understood that the first RSC and the second RSC can be the same or different, and the present application does not limit this.

[0025] With reference to the first aspect, in some possible implementation of the first aspect, the second request message is sent before the first request message is received.

[0026] In other words, receiving the first request message is a condition for triggering the first communication device to send the second request message. The first communication device can send the second request message in response to the first request message.

[0027] That is, in the multi-hop relay service, the operation of each intermediate relay requesting the network device to obtain the security parameter is triggered in response to the request of the next hop, and therefore the method can be referred to as a security establishment method triggered on demand along with the path, or the method can be referred to as a security establishment method triggered from downstream to upstream in sequence.

[0028] Optionally, before the second request message is sent to the third communication device, the method further includes: buffering the first request message, or buffering an information element in the first request message.

[0029] That is, the information element in the first request message is not sent to the third communication device immediately, but is sent after the first security connection is established.

[0030] With reference to the first aspect, in some possible implementation of the first aspect, the second request message is sent before the first request message is received.

[0031] In other words, the first communication device can request the first security parameter for the first security connection in advance through the second request message, to protect the first security connection. In the case of receiving the first request message, the second communication device can request the second security parameter through the first security connection.

[0032] In this way, in the multi-hop relay service, each intermediate relay can request the security parameter for the downstream node through the security connection that has been established in advance, and the establishment efficiency of the security connection between the remote UE and the network device is higher.

[0033] Optionally, before the second request message is sent to the third communication device, the method further includes: determining that the first communication device is an intermediate relay in the relay service.

[0034] The first communication device determines that it is an intermediate relay, and then can execute the processing logic of the intermediate relay.

[0035] In a possible implementation form of the first aspect, the first security parameter comprises a random number corresponding to the first secure connection, the random number corresponding to the first secure connection being used to derive a first session key, the first session key being used to protect the first secure connection; and the second security parameter comprises a random number corresponding to the second secure connection, the random number corresponding to the second secure connection being used to derive a second session key, the second session key being used to protect the first secure connection.

[0036] The random number is specifically a random number 2 from the network device. The random number 2 used to protect different secure connections can be generated based on the identifiers corresponding to the different communication apparatuses. For example, the first security parameter can be generated based on the identifier corresponding to the first communication apparatus, and the second security parameter can be generated based on the identifier corresponding to the first communication apparatus. Therefore, the random numbers 2 corresponding to different secure connections are different.

[0037] In a possible implementation form of the first aspect, the identifier corresponding to the second communication apparatus transmitted through the first secure connection is carried in an intermediate key request message, and the second security parameter received through the first secure connection is carried in an intermediate key reply message.

[0038] In a possible implementation form of the first aspect, the identifier corresponding to the second communication apparatus transmitted through the first secure connection is carried in a direct communication request message, and the second security parameter received through the first secure connection is carried in a direct communication consent message.

[0039] In a possible implementation form of the first aspect, the identifier corresponding to the second communication apparatus transmitted through the first secure connection and the second security parameter received through the first secure connection are both carried in a control plane message of a PC5 link.

[0040] In a possible implementation form of the first aspect, the identifier corresponding to the second communication apparatus transmitted through the first secure connection and the second security parameter received through the first secure connection are both carried in a user plane message of a PC5 link.

[0041] The messages transmitted and / or received by the first communication apparatus through the first secure connection listed above are only examples of several possible message types, and should not constitute any limitation on the present application. Since each message is transmitted or received through the first secure connection, the parameters in each message can be protected, and the communication can be safely performed.

[0042] In a second aspect, a method for establishing a secure connection is provided. The method can be applied to a fourth communication device, which can be a U2N relay, or a component (e.g., a circuit, a chip, a chip system, or a processor, etc.) in the U2N relay, or a logic module or software capable of implementing all or part of the functions of the U2N relay, etc. The present application does not limit this.

[0043] In the following, for the sake of convenience and illustration, and to avoid limiting the number of hops for the multi-hop relay service, the processing logic of the U2N relay is described through the interaction flows between the fourth communication device, the fifth communication device, the sixth communication device, and the network device.

[0044] Exemplarily, the method comprises: receiving a first security parameter from the network device, the first security parameter set being used to protect a third secure connection between the fourth communication device and a fifth communication device; receiving a second security parameter set from the network device, the second security parameter set being used to protect a fourth secure connection between the fifth communication device and a sixth communication device; and sending the second security parameter set to the fifth communication device through the fourth secure connection.

[0045] The fourth communication device can correspond to a U2N relay, the fifth communication device can be the next hop of the fourth communication device and can correspond to an intermediate relay, and the sixth communication device can be the next hop of the fifth communication device and can correspond to another intermediate relay or a remote UE. For example, the fourth communication device can correspond to the U2N relay in FIGS. 6-8, the fifth communication device can correspond to the intermediate relay in FIGS. 6 or 8, or the intermediate relay K in FIG. 7, the sixth communication device can correspond to the remote UE in FIGS. 6 or 8, or the intermediate relay K-1 in FIG. 7, the third secure connection can correspond to the secure connection #1 in FIGS. 6 or 8, or the secure connection #K in FIG. 7, and the fourth secure connection can correspond to the secure connection #0 in FIGS. 6 or 8, or the secure connection #K-1 in FIG. 7.

[0046] Based on the above technical solutions, the U2N relay can obtain security parameters for multiple communication devices from the network device according to the received identifiers corresponding to the multiple communication devices, and forward the security parameters corresponding to each communication device through a secure connection in turn. Thus, the establishment of a secure connection between each two adjacent nodes in the multi-hop relay service can be assisted, the secure connection in the multi-hop relay service is established, and the remote UE can perform secure communication with the network device.

[0047] In a possible implementation form of the second aspect, the second security parameter set is obtained based on an identifier of the sixth communication device; and the method further comprises: receiving the identifier of the sixth communication device from the fifth communication device; and sending, to the network device, a key request via the third secure connection, the key request carrying the identifier of the sixth communication device.

[0048] That is, the fourth communication device can receive the identifiers of the downstream communication devices via the third secure connection, and request the security parameters for the downstream communication devices. The messages received and sent by the fourth communication device are protected by the third secure connection, and the communication is safe.

[0049] In a possible implementation form of the second aspect, the identifier of the sixth communication device from the fifth communication device is carried in an intermediate key request message, and the second security parameter set sent to the fifth communication device is carried in an intermediate key reply message.

[0050] In a possible implementation form of the second aspect, the identifier of the sixth communication device from the fifth communication device is carried in a direct communication request message, and the second security parameter set sent to the fifth communication device is carried in a direct communication consent message.

[0051] In a possible implementation form of the second aspect, the identifier of the sixth communication device from the fifth communication device and the second security parameter set sent to the fifth communication device are both carried in a control plane message of a PC5 link.

[0052] In a possible implementation form of the second aspect, the identifier of the sixth communication device from the fifth communication device and the second security parameter set sent to the fifth communication device are both carried in a user plane message of a PC5 link.

[0053] The messages sent and / or received by the fifth communication device listed above are only examples of several possible message types, and should not constitute any limitation on the present application. The messages received from the fifth communication device are sent via the third secure connection, and the messages sent to the network device are sent via the secure connection established between the U2N relay and the network device, and the parameters in the messages are all securely protected, and the communication is safe.

[0054] With reference to the second aspect, in some possible implementation of the second aspect, before the sending, to the fifth communication apparatus, the second security parameter set via the third secure connection, the method further includes: determining to forward the second security parameter set via the third secure connection.

[0055] That is, the fourth communication apparatus can determine whether to forward the received security parameter set in the case of receiving a plurality of security parameter sets.

[0056] With reference to the second aspect, in some possible implementation of the second aspect, the first security parameter set includes a root key and a random number corresponding to the third secure connection, and the second security parameter set includes a root key and a random number corresponding to the fourth secure connection.

[0057] The random number is specifically a random number 2 from the network device. The random number 2 used for protecting different secure connections can be generated based on the identifiers corresponding to different communication apparatuses, for example, the random number 2 in the first security parameter set can be generated based on the identifier corresponding to the fifth communication apparatus, and the random number 2 in the second security parameter set can be generated based on the identifier corresponding to the sixth communication apparatus, so the random number 2 corresponding to different secure connections is different.

[0058] The third aspect provides a method for establishing a secure connection. The method can be applied to a first communication apparatus, which can be an intermediate relay, or can be a component (for example, a circuit, a chip, a chip system, or a processor, etc.) in the intermediate relay, or can also be a logic module or software capable of realizing all or part of the functions of the intermediate relay, etc. The present application does not limit this.

[0059] In the following, in order to facilitate and illustrate, and to avoid the limitation on the number of hops of the multi-hop relay service, the processing logic of the intermediate relay is described through the interaction process among the first communication apparatus, the second communication apparatus, the third communication apparatus and the network device.

[0060] Exemplarily, the method comprises: receiving a first message from a second communication device, the first message carrying an identity corresponding to N communication devices, the N communication devices comprising the second communication device, N being a positive integer; sending a second message to a third communication device, the second message carrying an identity corresponding to N+1 communication devices, the N+1 communication devices comprising the N communication devices and the first communication device; receiving a first security parameter from the third communication device, the first security parameter being obtained based on the identity corresponding to the first communication device, the first security parameter being used to protect a first secure connection between the first communication device and the third communication device; receiving a third message from the third communication device through the first secure connection, the third message carrying N security parameter groups corresponding to the N communication devices, the N security parameter groups being obtained based on the identities corresponding to the N communication devices, the N security parameter groups being used to protect secure connections between the N+1 communication devices.

[0061] In the case where there are multiple intermediate relays in the multi-hop relay service, each intermediate relay can perform the above scheme as the first communication device in turn, and the relative relationship between the first communication device, the second communication device and the third communication device remains unchanged. For example, the first communication device can correspond to the intermediate relay 1 in FIG. 9, the second communication device can correspond to the remote UE in FIG. 9, the third communication device can correspond to the intermediate relay 2 in FIG. 9, the first message can correspond to the request message #0 in FIG. 9, the second message can correspond to the request message #1 in FIG. 9, the first secure connection can correspond to the secure connection #1 in FIG. 9, the first security parameter can correspond to the security parameter #1 in FIG. 9, and the N security parameter groups can correspond to one security parameter group in the reply message #1 in FIG. 9; for another example, the first communication device can correspond to the intermediate relay 2 in FIG. 9, the second communication device can correspond to the intermediate relay 1 in FIG. 9, the third communication device can correspond to the U2N relay in FIG. 9, the first message can correspond to the request message #1 in FIG. 9, the second message can correspond to the request message #2 in FIG. 9, the first secure connection can correspond to the secure connection #2 in FIG. 9, the first security parameter can correspond to the security parameter #2 in FIG. 9, and the N security parameter groups can correspond to two security parameter groups in the reply message #2 in FIG. 9.

[0062] In the case where there are multiple intermediate relays in the multi-hop relay service, each intermediate relay can perform the above scheme as the first communication device in turn, and the relative relationship between the first communication device, the second communication device and the third communication device remains unchanged. For example, the first communication device can correspond to the intermediate relay 1 in FIG. 9, the second communication device can correspond to the remote UE in FIG. 9, the third communication device can correspond to the intermediate relay 2 in FIG. 9, the first message can correspond to the request message #0 in FIG. 9, the second message can correspond to the request message #1 in FIG. 9, the first secure connection can correspond to the secure connection #1 in FIG. 9, the first security parameter can correspond to the security parameter #1 in FIG. 9, and the N security parameter groups can correspond to one security parameter group in the reply message #1 in FIG. 9; for another example, the first communication device can correspond to the intermediate relay 2 in FIG. 9, the second communication device can correspond to the intermediate relay 1 in FIG. 9, the third communication device can correspond to the U2N relay in FIG. 9, the first message can correspond to the request message #1 in FIG. 9, the second message can correspond to the request message #2 in FIG. 9, the first secure connection can correspond to the secure connection #2 in FIG. 9, the first security parameter can correspond to the security parameter #2 in FIG. 9, and the N security parameter groups can correspond to two security parameter groups in the reply message #2 in FIG. 9.

[0063] Based on the above technical solution, in the multi-hop relay service, each intermediate relay can carry its own corresponding parameters (i.e., parameters for obtaining security parameters, such as but not limited to an identifier corresponding to a UE, etc.) and parameters from the next hop in the same request message to request multiple security parameter groups through the same request message in the case of receiving a request message from the next hop for requesting security parameters. The U2N relay can request security parameter groups for each downstream communication device according to the received message, and obtain and forward security parameter groups for each downstream node after establishing a secure connection between the U2N relay and the next hop. In this way, each intermediate relay in the downstream direction can first protect the secure connection between it and the next hop based on the received security parameter group, and then obtain and forward security parameters for downstream nodes through the secure connection. In this way, the secure connection between each two-hop adjacent node in the multi-hop relay service can be established in the downstream direction, and the remote UE can perform secure communication with the network device. Moreover, multiple security parameter groups that can be used to protect multiple secure connections are requested through the same request message, so that the establishment of the secure connection is more efficient.

[0064] In combination with the third aspect, in some possible implementation manners of the third aspect, the sorting rule of the identifiers corresponding to the N+1 communication devices in the second message is the same as the sorting rule of the identifiers corresponding to the N communication devices in the first message.

[0065] One example: in the first message, the parameter corresponding to the nth communication device in the N communication devices is located after the identifier corresponding to the (n-1)th communication device; in the second message, the parameter corresponding to the (n+1)th communication device in the N+1 communication devices is located after the identifier corresponding to the nth communication device, where the nth communication device is the nth hop in the N communication devices in the order starting from the remote UE (i.e., in the upstream order). That is, the identifier corresponding to the newly added communication device in the second message is located after the identifiers corresponding to the N communication devices in the first message. More simply, the sorting rule is that each newly added information element in the reconstructed message is placed after the information element in the received message.

[0066] Another example: in the first message, the parameter corresponding to the nth communication device in the N communication devices is located before the identifier corresponding to the (n-1)th communication device; in the second message, the parameter corresponding to the (n+1)th communication device in the N+1 communication devices is located before the identifier corresponding to the nth communication device, where the nth communication device is the nth hop in the N communication devices in the upstream order starting from the remote UE. That is, the identifier corresponding to the communication device newly added in the second message is located before the identifiers corresponding to the N communication devices in the first message. In other words, the rule is that the newly added information element in each reconstructed message is placed before the information element in the received message.

[0067] The rule for the ordering of the identifiers corresponding to the N+1 communication devices in the second message is the same as the rule for the ordering of the identifiers corresponding to the N communication devices in the first message, which enables the third communication device receiving the second message to identify the correspondence between the N identifiers in the second message and the N communication devices, and the hops at which the N communication devices are respectively located in the multi-hop relay service.

[0068] In combination with the third aspect, in some possible implementation manners of the third aspect, the rule for the ordering of the N security parameter groups in the third message is the same as the rule for the ordering of the identifiers corresponding to the N+1 communication devices in the second message.

[0069] The rule for the ordering is described above and will not be repeated here.

[0070] The rule for the ordering of the N security parameter groups in the third message is the same as the rule for the ordering of the identifiers corresponding to the N+1 communication devices in the second message, which enables the first communication device receiving the third message to correspond the N security parameter groups to the N communication devices, and further obtain the security parameter group for the secure connection between the first communication device and the next hop, and transmit the remaining N-1 security parameter groups.

[0071] In a fourth aspect, a method for establishing a secure connection is provided, which can be applied to a fourth communication device. The fourth communication device can be a U2N relay, or can be a component (such as a circuit, a chip, a chip system, or a processor, etc.) in the U2N relay, or can be a logic module or software, etc. capable of realizing all or part of the functions of the U2N relay. The present application does not limit this.

[0072] In the following, for the convenience and description, and to avoid limiting the number of hops in the multi-hop relay service, the processing logic of the U2N relay is described through the interaction process among the fourth communication device, the fifth communication device, and the network device.

[0073] Exemplarily, the method comprises: receiving a fourth message carrying the identities corresponding to the M communication devices; M is a positive integer greater than 1; sending M key requests through the secure connection between the fourth communication device and the network device, and receiving M key request replies; the M key requests carry the identities corresponding to the M communication devices, and the M key request replies carry M security parameter sets corresponding to the M communication devices, the M security parameter sets are obtained based on the identities corresponding to the M communication devices, and the M security parameter sets are used for secure connection between M+1 communication devices, the M+1 communication devices including the M communication devices and the fourth communication device.

[0074] The fourth communication device corresponds to an intermediate relay. For example, the fourth communication device can correspond to the U2N relay in FIG. 9.

[0075] M can represent the number of communication devices downstream of the U2N relay in the multi-hop relay service, and M is a positive integer greater than 1.

[0076] Based on the above technical solutions, in the multi-hop relay service, the U2N relay can receive a message carrying the identities corresponding to the M communication devices from the next hop, and then obtain security parameter sets for the M communication devices respectively, and after establishing a secure connection between the U2N relay and the next hop, the security parameter sets are forwarded to each communication device downstream in turn. In this way, the secure connection between every two adjacent nodes in the multi-hop relay service can be established in the downstream direction in turn, and the remote UE can perform secure communication with the network device. Moreover, multiple security parameter sets that can be used to protect multiple secure connections are requested through the same request message, so that the establishment efficiency of the secure connection is higher.

[0077] In combination with the fourth aspect, in some possible implementation manners of the fourth aspect, the same number is carried in the mth key request in the M key requests and the mth key request reply in the M key request replies, and the same number is determined based on m, m representing the mth hop of the M communication devices in the upstream direction or the mth hop of the M communication devices in the downstream direction; the M numbers carried in the M key requests are different from each other.

[0078] The upstream direction and the downstream direction are for each node in the multi-hop relay service. In the multi-hop relay service, the upstream direction can mean the direction from the remote UE to the network device, or the direction gradually away from the remote UE; the downstream direction can mean the direction opposite to the upstream direction, i.e., the direction from the network device to the remote UE, or the direction gradually close to the remote UE.

[0079] In addition, m can start from 0 or 1, and is not limited. As long as the M communication devices can be distinguished by different values.

[0080] The different numbers carried in the M key requests and the M key request replies can be used to distinguish the key requests and the key request replies corresponding to the identifiers of the different communication devices, thereby facilitating the U2N relay to correspond the M security parameter groups to the M communication devices in the case of receiving the M key request replies, to obtain the security parameter group for the secure connection between itself and the next hop, and to transmit the remaining M-1 security parameter groups.

[0081] In combination with the fourth aspect, in some possible implementation manners of the fourth aspect, the sending of the M key requests comprises: sending the M key requests in sequence according to the order of m from small to large, m representing the mth hop of the M communication devices in the upstream direction, or the M communication devices at the mth hop in the downstream direction.

[0082] The M key requests are sent in sequence according to the order of m from small to large, that is, the security parameter groups are requested for the secure connection between the mth communication device and its previous hop in the order of m from small to large.

[0083] Optionally, the sending of the M key requests and the receiving of the M key request replies comprise: performing the following operations in sequence according to the order of m from small to large until the value of m is traversed: sending an mth key request in the M key requests, and receiving an mth key request reply in the M key request replies.

[0084] That is, the sending of the mth key request and the receiving of the mth key request reply are taken as an obtaining operation of a security parameter group, and the M security parameter groups are obtained in sequence according to the order of m from small to large.

[0085] The M security parameter groups are obtained in sequence, and the M security parameter groups corresponding to the M communication devices are distinguished in the order of operation, thereby the fourth communication device can obtain the security parameter group for the secure connection between itself and the next hop from the M security parameter groups, and transmit the remaining M-1 security parameter groups.

[0086] In a possible implementation form of the fourth aspect, the method further comprises: sending, to the fifth communication device, a security parameter corresponding to the fifth communication device, the security parameter corresponding to the fifth communication device being used to protect a secure connection between the fifth communication device and the fourth communication device; and sending, through the secure connection, a fifth message, the fourth message carrying M-1 security parameter groups, the M-1 security parameter groups being security parameter groups other than the security parameter group corresponding to the fifth communication device among the M security parameter groups.

[0087] The fifth communication device is a next hop of the fourth communication device, and can correspond to an intermediate relay. For example, the fifth communication device can correspond to the intermediate relay 2 in FIG. 9.

[0088] The security parameter is sent to the fifth communication device, which can facilitate the fifth communication device to protect the secure connection with the fourth communication device based on the security parameter, and then forward the remaining M-1 security parameter groups through the established secure connection. Therefore, the M-1 security parameter groups can be securely protected, and the communication can be safely performed.

[0089] In a possible implementation form of the fourth aspect, the ordering rule of the M-1 security parameter groups in the fifth message is the same as the ordering rule of the identifiers corresponding to the M communication devices in the fourth message.

[0090] The ordering of the M-1 security parameter groups in the fifth message can be used to implicitly indicate the correspondence with the M-1 communication devices, and the fifth communication device receiving the M-1 security parameter groups can obtain the security parameter group for the secure connection between itself and the next hop, and forward the remaining M-2 security parameter groups.

[0091] In a fifth aspect, a communication device is provided, which can implement the method in the above first to fourth aspects and any possible implementation form of the first to fourth aspects. The device includes one or more functional units or modules for performing the above method. The functional units or modules included in the device can be implemented by software and / or hardware.

[0092] In a sixth aspect, a communication device is provided, which includes a processor configured to perform the method in the first to fourth aspects and any possible implementation form of the first to fourth aspects.

[0093] Optionally, the device can further include a memory configured to store instructions and data. The memory is coupled to the processor, and the processor can implement the method described in the above aspects when executing the instructions stored in the memory.

[0094] Optionally, the apparatus can further include a communication interface for the apparatus to communicate with other devices, which can be a transceiver, a circuit, a bus, a module or other type of communication interface.

[0095] In a seventh aspect, a chip system is provided, which includes at least one processor configured to support the functions described above in the first to fourth aspects and any possible implementation of the first to fourth aspects, such as receiving or processing data and / or information involved in the methods described above.

[0096] In a possible design, the chip system further includes a memory configured to store program instructions and data, which is located in or out of the processor.

[0097] In a possible design, the chip system further includes an interface circuit configured to transmit data and / or a power supply circuit configured to supply power to the chip system.

[0098] The chip system can be composed of a chip, or can include a chip and other discrete devices.

[0099] In an eighth aspect, a communication system is provided, which includes one or more of the following: a remote UE, at least one intermediate relay, a U2N relay or a network device. Each of the at least one intermediate relay can be configured to implement the functions described above in the first aspect and any possible implementation of the first aspect, and the U2N relay can be configured to implement the functions described above in the second aspect and any possible implementation of the second aspect; or each of the at least one intermediate relay can be configured to implement the functions described above in the third aspect and any possible implementation of the third aspect, and the U2N relay can be configured to implement the functions described above in the fourth aspect and any possible implementation of the fourth aspect.

[0100] In a ninth aspect, a computer-readable storage medium is provided, which includes a computer program, which, when executed on a computer, causes the computer to implement the methods in the first to fourth aspects and any possible implementation of the first to fourth aspects.

[0101] In a tenth aspect, a computer program product is provided, which includes a computer program (also referred to as code or instructions), which, when executed, causes a computer to perform the methods in the first to fourth aspects and any possible implementation of the first to fourth aspects.

[0102] It should be understood that the fifth aspect to the tenth aspect of the present application correspond to the technical solutions of the first aspect to the fourth aspect of the present application, and the beneficial effects achieved by each aspect and the corresponding feasible implementation manners are similar, which will not be described again. BRIEF DESCRIPTION OF DRAWINGS

[0103] FIG. 1 is a schematic diagram of ProSe signaling plane architecture in a 5G network;

[0104] FIG. 2 is a schematic diagram of a ProSe discovery procedure;

[0105] FIG. 3 is a schematic flow chart of establishing a secure connection based on a control plane (CP);

[0106] FIG. 4 is a schematic flow chart of establishing a secure connection based on a user plane (UP);

[0107] FIG. 5 is a schematic diagram of a multi-hop relay service;

[0108] FIG. 6 is a schematic flow chart of a method for establishing a secure connection according to an embodiment of the present application;

[0109] FIG. 7 is a schematic diagram of a method for establishing a secure connection according to an embodiment of the present application;

[0110] FIG. 8 is a schematic flow chart of a method for establishing a secure connection according to another embodiment of the present application;

[0111] FIG. 9 is a schematic flow chart of a method for establishing a secure connection according to yet another embodiment of the present application;

[0112] FIG. 10 and FIG. 11 are flow charts of two different implementations of steps 907 and 908 in the method of FIG. 9;

[0113] FIG. 12 and FIG. 13 are schematic block diagrams of possible communication devices according to embodiments of the present application. DETAILED DESCRIPTION

[0114] The technical solutions provided by the present application will be described below in conjunction with the accompanying drawings.

[0115] For the convenience of understanding the embodiments of the present application, the following points are first explained:

[0116] First, in the present application, indication includes explicit indication (also referred to as direct indication) and implicit indication (also referred to as indirect indication). Among them, the explicit indication information A means to include the information A; the implicit indication information A means to indicate the information A through the correspondence between the information A and the information B and the direct indication information B, and the correspondence between the information A and the information B can be predefined, pre-stored, pre-burned, or pre-configured; or it can also mean to indicate the information A through the information B and the preset rule.

[0117] Second, in the present application, the information C used for the determination of the information D includes that the information D is determined only based on the information C, and also includes that the information D is determined based on the information C and other information. In addition, the information C used for the determination of the information D can also be indirectly determined, such as the case that the information D is determined based on the information E, and the information E is determined based on the information C.

[0118] Third, in the present application, "at least one" means one or more, and "multiple" means two or more. The "and / or" describes the association relationship of the associated objects, which means that there can be three kinds of relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after it, but does not rule out the case that the associated objects before and after it represent an "and" relationship, and the meaning represented can be understood in combination with the context. "At least one of the following" or similar expressions means any combination of these items, including any combination of single item or multiple items. For example, at least one of a, b, or c can represent: a, b, c; a and b; a and c; b and c; or a and b and c. Where a, b, and c can be single or multiple.

[0119] Fourth, in the present application, the use of prefixes such as "first", "second", and the like is only for the convenience of distinguishing and describing different things belonging to the same name category, and does not constrain the order, size, or quantity of the things. For example, "first information" and "second information" are only different information, and there is no time sequence, size relationship or priority relationship between them.

[0120] Fifth, in the present application, "sending" and "receiving" represent the direction of signal transmission. For example, "sending a message to the U2N relay" can be understood as the destination of the message being the U2N relay, which can include direct transmission over the air interface, or indirect transmission over the air interface by other units or modules. "Receiving security parameters from the network device" can be understood as the source of the security parameters being the network device, which can include direct reception from the network device over the air interface, or indirect reception from the network device over the air interface from other units or modules. "Sending" can also be understood as the "output" of the chip interface, and "receiving" can also be understood as the "input" of the chip interface.

[0121] In other words, sending and receiving can be between devices, such as between the U2N relay and the network device, or within a device, such as between components, modules, chips, software modules or hardware modules within the device through a bus, wire or interface.

[0122] Sixth, in the embodiments of the present application, "when", "if" and "when" all refer to the device making corresponding processing under certain objective circumstances, and are not limited to time, and do not require the device to have a judgment action when implemented, nor does it mean that there are other limitations.

[0123] Seventh, in the present application, "example", "exemplarily", "for example" or "such as" are used to represent as an example, illustration or explanation. Any embodiment or design scheme described as "example", "exemplarily", "for example" or "such as" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the use of "example", "exemplarily", "for example" or "such as" is intended to present the relevant concept in a specific manner.

[0124] Under the control of a cell network, each communication device (such as a UE) can share spectrum resources and perform D2D communication to improve the utilization of spectrum resources, or can use unlicensed spectrum resources for communication without the control of a cell network. In D2D communication, communication devices can communicate through a PC5 interface, and UEs can transmit control plane and user plane information through a PC5 interface, including signaling and / or data. The link through which UEs directly communicate through a PC5 interface can be referred to as a sidelink (SL). It can include one-to-one communication and one-to-many communication. One-to-one communication can correspond to unicast communication, and one-to-many communication can correspond to groupcast communication and broadcast communication. In one-to-one communication, if the initiator and the receiver are within a short distance, they can communicate directly after discovering each other.

[0125] 2. ProSe communication: D2D communication has been widely discussed in LTE and 5G network standards, collectively referred to as ProSe communication. For example, in 5G, 5G ProSe direct communication (5G ProSe Direct Communication) is defined as: communicating between two or more ProSe communication-enabled UEs in proximity through a path that uses user plane transmission of NR technology without traversing any network node.

[0126] ProSe communication-enabled UEs can communicate through a PC5 interface, and control plane and user plane information, including signaling and / or data, can be transmitted between UEs through the PC5 interface. The link through which UEs directly communicate through the PC5 interface can also be referred to as a sidelink, or as a PC5 link. Unicast communication through a PC5 link can also be referred to as PC5 unicast communication, and a PC5 link used for unicast communication can also be referred to as a PC5 unicast link.

[0127] ProSe communication can include U2N communication and U2U communication.

[0128] In U2N communication, a remote UE can communicate through the assistance of a U2N relay, i.e., through remote UE-to-U2N relay communication and U2N relay-to-network communication, to achieve remote UE service. By establishing a communication mode from remote UE to U2N relay and from U2N relay to network, communication from UEs outside network coverage to the network can be extended.

[0129] U2U communication is for one-to-one communication scenarios, and the two UEs at the ends of the communication can be referred to as end UEs. When the two UEs at the ends of the communication (i.e., end UEs) are outside the signal coverage, the end UEs can communicate through the assistance of a relay UE with the other end UE, in which case the relay UE is referred to as a UE-to-UE relay (UE-to-UE relay or U2U relay).

[0130] Among them, the above-mentioned remote UE, U2N relay, end UE and U2U relay all belong to ProSe UE. ProSe UE is a UE with ProSe application function, or a UE capable of ProSe communication.

[0131] FIG. 1 exemplarily shows a ProSe signaling plane architecture in a 5G network. As shown in FIG. 1, a plurality of ProSe UEs (such as UE A, UE B, UE C and UE D in the figure) are shown in the signaling plane architecture, each of which has a ProSe application function and can be used for ProSe communication. The ProSe UEs can communicate with each other through a PC interface.

[0132] It should be understood that the UE in the present application can also be referred to as a terminal device, an access terminal, a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, a remote terminal, a mobile equipment (ME), a user terminal, a terminal, a wireless communication device, a user agent or a user device.

[0133] The UE can be a device that provides voice / data connectivity to a user, such as a handheld device with wireless connectivity, a vehicle-mounted device, etc. Currently, some examples of the UE can be a mobile phone, a pad, a computer (such as a notebook computer, a palm computer, etc.) with wireless transceiver function, a mobile internet device (MID), a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self driving, an uncrewed aerial vehicle (UAV), a wireless terminal in V2X, a wireless terminal in remote medical, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication function, a computing device or other processing device connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal device in a 5G network, or a terminal device in a future evolved public land mobile network (PLMN), etc.

[0134] Among them, the wearable device can also be called a wearable smart device, which is a general term of devices that can be worn, such as glasses, gloves, watches, clothing, and shoes, which are designed and developed by applying wearable technology to daily wear. The wearable device is a portable device that can be directly worn on the body or integrated into the user's clothes or accessories. The wearable device is not only a hardware device, but also a powerful function realized through software support and data interaction, cloud interaction. The general wearable smart device includes a full function, a large size, and can realize complete or partial functions without relying on a smart phone, such as a smart watch or smart glasses, and focuses on a certain application function and needs to cooperate with other devices such as a smart phone, such as various smart wristbands, smart jewelry, and the like.

[0135] In addition, the UE can also include a terminal device in an IoT system, which can also be called an IoT node. IoT is an important part of the future development of information technology, and its main technical features are that objects are connected to the network through communication technology, thereby realizing the interconnection of man and machine, and the intelligent network of interconnection of things. IoT technology can achieve mass connection, deep coverage, and terminal power saving through, for example, narrow band (NB) technology.

[0136] The UE can also include a smart printer, a train detector, a gas station sensor, and the like, and the main functions include collecting data (part of the terminal device), receiving control information and downlink data of the network device, and transmitting electromagnetic waves to transmit uplink data to the network device.

[0137] In the embodiment of the present application, the device for realizing the function of the UE can be the UE, or a device capable of supporting the UE to realize the function, such as a chip system, which can be installed in the UE or used with the UE. In the embodiment of the present application, the chip system can be composed of a chip, or include a chip and other discrete devices. In the embodiment of the present application, only the device for realizing the function of the UE is taken as an example for description, and the scheme of the embodiment of the present application is not limited.

[0138] The UE in the present application can be a hardware device, a software function running on a special hardware, or a software function running on a general hardware, and can also be a virtualized device, such as a general hardware and an instantiated virtualization function, or a special hardware and an instantiated virtualization function. Among them, the general hardware can be a server, such as a cloud server.

[0139] Corresponding to the ProSe application is a ProSe application server (ProSe Application Server). The ProSe application server can be an application function (AF) deployed in a data network. The AF with the ProSe application server function can have all the functions of the AF defined in the third generation partnership project (3 rd generation partnership project,3GPP) technical specification (TS) 23.501 version 15 (release 15,R15) version, as well as related functions for ProSe services. That is, in the signaling plane architecture, the ProSe application server can communicate with the UE through the UE-RAN-UPF-AF path in the user plane. The ProSe application server can also communicate with other network functions (NFs) in the 5G core network (5GC) through the network exposure function (NEF). For example, it communicates with the PCF through the NEF.

[0140] As shown in the figure, each ProSe UE can access the 5GC through the NG-RAN. The figure exemplarily shows the ProSe-related part of the network element in the 5GC, and each of the network elements is introduced as follows:

[0141] 5G direct discovery name management function (5G DDNMF): allocates and processes the mapping relationship between the ProSe application ID and the ProSe application code for open ProSe discovery.

[0142] ProSe key management function (PKMF): can be used to generate the key used by the PC5 link between the remote UE and the relay UE in the UE and network relay communication. The UE needs to interact with the PKMF through the user plane channel to obtain the PC5 key.

[0143] Access and mobility management function (AMF): used for non-access stratum (NAS) connection with the UE, and has the same 5G NAS security context as the UE. The 5G NAS security context includes K AMF , NAS-level keys and corresponding key identification information, UE security capabilities, uplink and downlink NAS count values. The NAS-level keys include NAS encryption keys and NAS integrity protection keys, which can be used for confidentiality protection and integrity protection of NAS messages, respectively.

[0144] Policy control function (PCF) network element: mainly supports providing a unified policy framework to control network behavior, providing policy rules to control layer network functions, and being responsible for obtaining user subscription information related to policy decision.

[0145] Session management function (SMF): used for session management, terminal device internet protocol (IP) address allocation and management, selection and management of user plane functions, policy control, or termination of charging function interfaces, and downlink data notification, etc.

[0146] User plane function (UPF): can be used for packet routing and forwarding, or quality of service (QoS) processing of user plane data, etc.

[0147] Uniform data management (UDM): can be used to store user data such as subscription information, authentication / authorization information, etc.

[0148] Uniform data repository (UDR): can be used to store user data, including subscription data subscribed by UDM, policy data of PCF, structured data for capability exposure, application data invoked by NEF, etc.

[0149] NEF: can be used for interaction between the core network other internal network elements and the application function, AF network element corresponding to the core network external application server (application server, AS), to provide network exposure capabilities to AF, or provide information provided by AF to core network elements.

[0150] It should be understood that only some core network elements are exemplarily shown in the figure, and the core network can further include more other functional network elements, for example: an authentication server function (AUSF), which can be used for security authentication of a terminal when the UE accesses the network; a boostrapping server function (BSF), which can be used for session binding of N7 and N5 interfaces, and is used for supporting voice over NR (VoNR) service of a 5G network, so that a user selects the same PCF; a home subscriber server (HSS), which is used for storing user data of a VoLTE user in 2 / 3 / 4G and an IP multimedia system (IMS), processing data access of a user by a call control network element in 2 / 3 / 4G and the IMS, and receiving and responding to a service operation support system (BOSS) service opening instruction through an opening interface. For brevity, no further enumeration is made.

[0151] For the convenience of understanding the embodiments of the present application, the terms involved in the present application are first simply explained as follows.

[0152] 1. ProSe discovery procedure: Before the remote UE and the U2N relay perform ProSe communication, the ProSe discovery procedure is performed to determine the opposite end of the communication. At present, two discovery models are known: model A and model B. The UE can select one of the models to perform the discovery procedure. The two discovery models are simply explained in combination with FIG. 2 as follows.

[0153] FIG. 2 exemplarily shows the ProSe discovery procedure. Steps 210a and 220 in FIG. 2 show the ProSe discovery procedure using model A, and steps 210b, 210c and 220 in FIG. 2 show the ProSe discovery procedure using model B.

[0154] [Rule 91, 20.05.2025] In Model A: Two end UEs are announcing UE and monitoring UE respectively. After obtaining ProSe parameters, announcing UE can actively broadcast its interested proximity service. After obtaining ProSe parameters, monitoring UE can monitor its interested proximity service. In Model A ProSe discovery procedure, the first message can be initiated by announcing UE, as shown in step 210a in the figure, announcing UE can send discovery announcing, and monitoring UE can determine whether to continue the subsequent procedure according to whether it meets its service requirement after receiving the message of announcing UE, as shown in step 220 in the figure, to perform PC5 unicast establishment procedure.

[0155] In Model B: Two end UEs are discoverer UE and discoveree UE respectively. In Model B ProSe discovery procedure, the first message can be the message initiated by discoverer UE to request a service, as shown in step 210b in the figure, discoverer UE can send discovery solicitation, and discoveree UE can determine whether to reply to the request message according to whether it can provide service, as shown in step 210c in the figure, discoveree UE can send discovery response in the case that it can provide service, and discoverer UE can initiate the subsequent procedure after receiving the discovery response, as shown in step 220 in the figure, to perform PC5 unicast establishment procedure.

[0156] 3. Security establishment: To establish a secure connection between communication devices to ensure communication security. In ProSe communication, ProSe UE needs to perform security establishment in PC5 link establishment process. The existing security establishment methods include, for example, network side dependent security establishment, that is, security authentication, authorization and key establishment through network side. In other words, in the network side dependent security establishment scheme, security establishment needs to be completed by interacting with the network side. The network side dependent security establishment scheme can further include CP-based solution (hereinafter referred to as CP solution) and UP-based solution (hereinafter referred to as UP solution).

[0157] 4. CP solution: Solution to obtain the relay key through the control plane of the network. For the convenience of understanding, the flow of the CP solution is briefly described below in combination with FIG. 3.

[0158] In step 30a, the remote UE is registered, authenticated and authorized in the network. The remote UE can complete the registration at the AMF of the remote UE, and obtain the authentication and authorization for the U2N relay service.

[0159] In step 30b, the relay UE (specifically, the U2N relay) is registered, authenticated and authorized in the network. The relay UE can complete the registration, authentication and authorization at the AMF of the relay UE, and pass the authentication and authorization for the U2N relay service.

[0160] In step 31, the remote UE and / or the relay UE perform the ProSe discovery procedure to discover each other. Either of the remote UE and the relay UE can initiate the discovery procedure using Model A or Model B. For more detailed procedures of the ProSe discovery procedure, refer to the related description of FIG. 2 above, which will not be repeated here.

[0161] In step 32, the remote UE sends a DCR message to the relay UE, which can carry the identity corresponding to the remote UE, the RSC and the random number 1 (Nonce_1). The identity corresponding to the remote UE can be the device identity of the remote UE, such as the subscription concealed identifier (SUCI) of the remote UE, or can also be the key identity of the remote UE, such as the control plane ProSe remote user key identifier (CP-PRUK ID). The DCR message is used to request the establishment of a PC5 link.

[0162] In step 33, the relay UE sends a key acquisition request, such as a Relay Key Request, to the AMF of the relay UE, which carries the parameters in the DCR message, including: the identity corresponding to the remote UE, the RSC and the random number 1 (Nonce_1). The key acquisition request message is used to request the acquisition of the relay key and to verify whether the relay UE has the permission to use ProSe.

[0163] In step 34, the AMF of the relay UE verifies the relay UE to determine whether the relay UE has the permission to use ProSe. The specific way can be to interact with the UDM to determine whether the UE has the subscription information for using the ProSe service.

[0164] In step 35, the AMF of the relay UE sends an authentication request message, such as a Nausf_UEAuthentication_ProSeAuthenticate Request message, to the AUSF of the remote UE. The authentication request message carries the parameters in the DCR message: the identity of the remote UE, the RSC, and the random number 1 (Nonce_1).

[0165] If the identity of the remote UE in the parameters in the DCR message includes the SUCI of the remote UE, steps 36 to 39 are performed.

[0166] In step 36, the AUSF of the remote UE obtains a ProSe authorization vector (AV) from the UDM of the remote UE. The ProSe AV is used to perform ProSe authentication of the remote UE. Illustratively, the AUSF of the remote UE can request the ProSe AV from the UDM of the remote UE by sending a Nudm_UEAuthentication_GetProSeAuthorizationVector to the UDM of the remote UE.

[0167] In step 37, the AUSF of the remote UE performs a ProSe authentication procedure with the remote UE.

[0168] In steps 38a and 38b, the remote UE and the AUSF of the remote UE each generate a CP-PRUK and a CP-PRUK ID in case the ProSe authentication is passed. The CP-PRUK is a root key corresponding to the remote UE under the CP scheme, and the CP-PRUK ID is an identity of the CP-PRUK.

[0169] In steps 39a and 39b, the AUSF of the remote UE stores the generated CP-PRUK, CP-PRUK ID, and the corresponding RSC and SUPI into a ProSe anchor function (PAnF) of the remote UE. Illustratively, the AUSF of the remote UE can send a Npanf_ProSeKey_Register Request to the PAnF of the remote UE in step 39a, carrying the CP-PRUK, CP-PRUK ID, and the corresponding RSC and SUPI. The PAnF of the remote UE can send a Npanf_ProSeKey_Register Response to the AUSF of the remote UE in step 39b.

[0170] If the remote UE sends a DCR message to other UEs again. At this time, in the CP scheme, the identity corresponding to the remote UE in the parameters in the DCR message is the CP-PRUK ID, to indicate that the remote UE has performed the ProSe authentication process before, and the AUSF of the remote UE can directly obtain the corresponding CP-PRUK from the PAnF of the source UE according to the CP-PRUK ID and the RSC of the service, without the need to perform the ProSe authentication, the root key derivation corresponding to the remote UE and the process of storing the CP-PRUK to the PAnF in steps 36-39 again.

[0171] Steps 310a and 310b are performed in the case that the remote UE sends a DCR message in step 32 carrying the CP-PRUK ID, that is, the identity corresponding to the source UE in the DCR message is the CP-PRUK ID of the remote UE.

[0172] In steps 310a and 310b, the AUSF of the remote UE obtains the CP-PRUK of the remote UE from the PAnF of the remote UE. Exemplarily, the remote UE can determine that the remote UE has performed the ProSe authentication process according to the CP-PRUK ID carried in the above-mentioned DCR message, and thus can perform step 310a to send an Npanf_ProSeKey_get Request to the PAnF of the remote UE, carrying the CP-PRUK ID and the RSC. The PAnF of the remote UE can send an Npanf_ProSeKey_get Response to the AUSF of the remote UE, carrying the CP-PRUK.

[0173] In step 311, the AUSF of the remote UE generates a random number 2 (Nonce_2), and generates a root key (K NR_ProSe ) based on the CP-PRUK, the random number 1 (Nonce_1) and the random number 2 (Nonce_2), wherein the root key is a root key required for establishing a PC5 link between the remote UE and the relay UE.

[0174] In step 312, the AUSF of the remote UE sends the root key (K NR_ProSe ) and the random number 2 (Nonce_2) to the AMF of the relay UE. Exemplarily, the AUSF of the remote UE sends an Nausf_UE Authentication_ProSeAuthenticate Response message to the AMF of the relay UE, carrying the root key (K NR_ProSe) and a random number 2 (Nonce_2).

[0175] If the ProSe authentication of the remote UE is passed by the AUSF of the remote UE in step 37, the Nausf_UE_Authentication_ProSe_Authentication-Reply message also carries an extensible authentication protocol (EAP) success message.

[0176] In step 313, the AMF of the relay UE sends the root key (K NR_ProSe ) to the relay UE. Illustratively, the AMF of the relay UE sends a Relay Key Response to the relay UE, which carries the root key (K NR_ProSe ) and the random number 2 (Nonce_2), and optionally, an EAP success message.

[0177] In step 314, the relay UE sends a Direct Security Mode Command message to the remote UE, which carries the random number 2 (Nonce_2), and optionally, an EAP success message.

[0178] In step 315, the remote UE generates K NR_ProSe . Specifically, the remote UE generates the root key K NR_ProSe based on the CP-PRUK, the random number 1 (Nonce_1) and the random number 2 (Nonce_2).

[0179] So far, both the remote UE and the relay UE obtain the security parameters (the root key (K NR_ProSe ) and the random number 2 (Nonce2)), and the remote UE and the relay UE can establish a PC5 security connection based on the security parameters.

[0180] In step 316, the remote UE sends a Direct Security Complete message to the relay UE.

[0181] In step 317, the relay UE sends a Direct Communication Accept message to the remote UE.

[0182] It can be understood that the specific process of the CP scheme can also refer to the relevant introduction of the 3rd generation partnership project (3GPP) technical specification (TS) 33.503, which will not be described here.

[0183] 5. UP scheme: a scheme to obtain a relay key through a username of a network. For the convenience of understanding, the flow of the UP scheme is briefly explained below in conjunction with FIG. 4.

[0184] In step 40a, the remote UE obtains a PKMF address of the remote UE. Exemplarily, the remote UE can obtain the PKMF address of the remote UE from a 5G DDNMF of its HPLMN.

[0185] In step 40b, the remote UE obtains discovery security materials from the PKMF of the remote UE. The PKMF of the remote UE can send the discovery security materials to the remote UE after authenticating and authorizing the remote UE to use the ProSe service. The PKMF of the remote UE can also obtain the discovery security materials from the PKMF of a potential U2N relay. The potential U2N relay refers to a relay from which the remote UE can obtain a relay service.

[0186] In step 40c, the U2N relay obtains a PKMF address of the U2N relay. Exemplarily, the U2N relay can obtain the PKMF address of the U2N relay from a 5G DDNMF of its HPLMN.

[0187] In step 40d, the U2N relay obtains discovery configuration from the PKMF of the U2N relay. The PKMF of the U2N relay can send the discovery security materials to the U2N relay after authenticating and authorizing the U2N relay to use the ProSe service.

[0188] In step 41a, the remote UE sends a ProSe Remote User Key Request to the PKMF of the remote UE to request to obtain a user plane ProSe remote user key (UP-PRUK) of a PC5 link and a corresponding UP-PRUK identifier (UP-PRUK ID).

[0189] In step 41b, the PKMF of the remote UE sends a ProSe Remote User Key Response to the remote UE, carrying the UP-PRUK and the UP-PRUK ID.

[0190] In step 42, the remote UE determines the U2N relay through a discovery procedure. The remote UE and the U2N relay can perform the discovery procedure using the discovery security configuration obtained in step 40b and step 40d respectively. More detailed procedure of the ProSe discovery procedure can be referred to the related description in connection with FIG. 2 above, which will not be repeated here.

[0191] In step 43, the remote UE sends a DCR message to the U2N relay, which carries the identity corresponding to the remote UE, the RSC and the random number 1 (e.g. K NRP Freshness Parameter 1). The identity corresponding to the remote UE can be the device identity of the remote UE, such as SUCI, or can also be the key identity of the remote UE, such as UP-PRUK ID. The DCR message is used to request to establish the PC5 link.

[0192] In step 44a to 44e, the U2N relay obtains the security parameters, including the root key (e.g. K NRP ) and the random number 2 (e.g. K NRP Freshness Parameter 2) from the PKMF of the U2N relay. The root key is the root key required for establishing the PC5 link between the remote UE and the relay UE.

[0193] Exemplarily, the U2N relay sends a Key Request to the PKMF of the U2N relay in step 44a, and the PKMF of the relay UE forwards the Key Request to the PKMF of the remote UE in step 44b, which carries the parameters in the DCR message: the identity corresponding to the remote UE, the RSC and the random number. The Key Request message is used to request to obtain the security parameters.

[0194] In step 44c, if the PKMF of the remote UE determines that the UP-PRUK needs to be updated for the remote UE, the PKMF of the remote UE obtains the generic bootstrapping architecture (GBA) push information (GPI) or the authentication vector (AV) of the remote UE. Exemplarily, the PDMF of the remote UE can obtain the GPI or AV from the UDM, BSS or HSS of the remote UE, and determine the updated UP-PRUK according to the GPI or AV.

[0195] The PKMF of the remote UE sends a Key Response to the PKMF of the relay UE in step 44d, and the PKMF of the relay UE forwards the Key Response to the U2N relay in step 44e, which carries the root key (K NRP ), the random number 2 (K NRPFreshness Parameter 2). If the GPI was obtained in step 44c, then the GPI should also be included.

[0196] For example, the PKMF of the remote UE can generate random number 2(K) NRP Freshness Parameter 2), and based on the UP-PRUK corresponding to the UP-PRUK ID and the random number 1 (K NRP Freshness Parameter 1) and random number 2 (K NRP Freshness Parameter 2), obtain the root key (K) NRP The root key (K) of the remote UE's PKMF. NRP ), random number 2 (K) NRP Freshness Parameter 2) is carried in the key reply and sent to the U2N trunk via the PKMF of the trunk UE.

[0197] In step 45a, the U2N relay sends a Direct Security Mode Command message to the remote UE, which carries a random number 2(K). NRP Freshness Parameter 2). If the GPI was obtained in step 44c, then the GPI should also be included.

[0198] Remote UE determines K NRP Specifically, the remote UE is based on UP-PRUK and random number 1 (K NRP Freshness Parameter 1) and random number 2 (K NRP Freshness Parameter 2), generate root key K NRP .

[0199] At this point, both the remote UE and the U2N relay have obtained security parameters (including the root key (K)). NRP ) and random number 2 (K NRP Freshness Parameter 2) allows remote UEs and U2N relays to establish a PC5 secure connection based on security parameters.

[0200] In step 45b, the remote UE verifies that the U2N relay is authorized. The remote UE can verify the received direct communication mode command message to confirm that the U2N relay is an authorized UE providing relay services.

[0201] In step 45c, the remote UE sends a Direct Security Mode Complete message to the U2N relay.

[0202] In step 45d, the U2N relay verifies that the remote UE is authorized. The U2N relay can verify the received Direct Security Mode Complete message to confirm that the remote UE is an authorized UE to use the relay service.

[0203] In step 45e, the U2N relay sends a Direct Security Accept message to the remote UE.

[0204] In step 46, the remote UE and the U2N relay continue the relay service. The remote UE and the U2N relay can continue the subsequent relay service based on the PC5 security connection.

[0205] It should be understood that more detailed procedures related to the UP scheme can also be referred to the relevant introduction of 3GPP TS 33.503, which will not be repeated here.

[0206] The CP scheme and the UP scheme shown in FIGS. 3 and 4 above can be understood as the process of establishing a PC5 security connection between the remote UE and the relay UE. Therefore, the operations related to establishing a security connection in the following embodiments can be understood with reference to the above, which will not be repeated here.

[0207] [Rule 91, 05.11.2025] 6, ProSe UE-to-Network multi-hop relay service: hereinafter referred to as multi-hop relay service, refers to the ProSe UE finding a U2N relay through an intermediate relay, and then connecting to the network side.

[0208] FIGS. 5a) and b) show two examples of the multi-hop relay service. As shown in FIG. 5a), the remote UE connects to the network device through the intermediate relay and the U2N relay. In other words, the remote UE accesses the network device through a multi-hop relay link. FIG. 5a) is only an example, and it can be understood that the number of intermediate relays can be one or more, which is not limited.

[0209] As shown in FIG. 5b), the remote UE connects to the network device through the intermediate relay 1, the intermediate relay 2, …, the intermediate relay K-1, the intermediate relay K, and the U2N relay. The number of intermediate relays can be K, and K can be a positive integer. It can be understood that when K is 1, FIG. 5b) is the same as FIG. 5a).

[0210] The intermediate relay can search for the next-hop relay due to no network connection after receiving the discovery request of the remote UE, and the found next-hop relay can also search for its next-hop due to no network connection, and so on, until the U2N relay is found and accesses the network. Therefore, in the multi-hop relay service, the intermediate relay can not be within the range of network coverage.

[0211] In the embodiments of the present application, in order to distinguish and describe conveniently, the upstream and downstream in the multi-hop relay service can be distinguished according to the number of hops between the nodes and the network device, and the number of hops between the upstream nodes and the network device is less than that between the downstream nodes and the network device. Alternatively, the upstream and downstream directions in the multi-hop relay service can also be defined according to the direction of the signal. It should be understood that the direction of the signal is only a reference, and does not mean that there is signal transmission between the devices.

[0212] The first possible definition is that the direction from the network device to the UE is called downstream or downlink, and the direction from the UE to the network device is called upstream or uplink. For example, in the multi-hop relay service shown in a) of FIG. 5, the direction from the network device to the remote UE is called downstream or downlink, and the direction from the remote UE to the network device is called upstream or uplink. The relationship between adjacent nodes can also be defined based on the upstream and downstream or uplink and downlink directions. For example, in the multi-hop relay service shown in a) of FIG. 5, the U2N relay is the previous-hop node (or simply the previous-hop) of the intermediate relay, and the remote UE is the next-hop node (or simply the next-hop) of the intermediate relay. In this way, it is not listed. In the following, in order to distinguish and describe conveniently, the various embodiments are described based on this definition.

[0213] The second possible definition is that the direction from the network device to the UE is called upstream or uplink, and the direction from the UE to the network device is called downstream or downlink. For example, in the multi-hop relay service shown in a) of FIG. 5, the direction from the network device to the remote UE is called upstream or uplink, and the direction from the remote UE to the network device is called downstream or downlink. The relationship between adjacent nodes can also be defined based on the upstream and downstream directions. For example, in the multi-hop relay service shown in a) of FIG. 5, the U2N relay is the next-hop node (or simply the next-hop) of the intermediate relay, and the remote UE is the previous-hop node (or simply the previous-hop) of the intermediate relay. In this way, it is not listed. As can be seen, this definition is just the reverse of the first definition, and in this case, "downstream" in the various embodiments below can be replaced by "upstream", "upstream" can be replaced by "downstream", "previous-hop" can be replaced by "next-hop", and "next-hop" can be replaced by "previous-hop".

[0214] Of course, the upstream and downstream directions or the uplink and downlink directions can not be defined by the signal direction, and the previous hop or the next hop can not be distinguished by the upstream, downstream, uplink, downlink or other direction definitions. In the multi-hop relay service, the previous hop or the next hop is referred to as the adjacent hop or the next hop in the multi-hop relay service. In this case, the "previous hop" and "next hop" in each of the embodiments below can be replaced by "adjacent hop" or "next hop", and "upstream" and "downstream" are relative, which can be determined according to the number of hops between each node and the network device.

[0215] Since the intermediate relay itself is not within the network coverage, the intermediate relay cannot access the network, obtain security parameters from the network device, and thus cannot establish a secure connection. Therefore, how to establish a secure connection between the intermediate relay and the remote UE, between the intermediate relays (in the case of multiple intermediate relays), and between the intermediate relay and the U2N relay, becomes a technical problem to be solved.

[0216] The present application provides a method, in which the intermediate relay can request security parameters from its previous hop as a remote UE to protect the secure connection between the intermediate relay and the previous hop, and request security parameters for its next hop (such as for the intermediate relay or the remote UE) as an intermediate relay. The intermediate relay can obtain security parameters for its downstream nodes based on the secure connection between the intermediate relay and the previous hop. Since each intermediate relay in the multi-hop relay service can obtain security parameters and request security parameters for the next hop based on the above process, the secure connection between each two-hop adjacent nodes in the multi-hop relay service is established in turn along the direction from the network device to the remote UE, so that the secure connection between the remote UE and the network device is also established, thereby improving communication security.

[0217] Based on the above idea, the present application provides two possible solutions:

[0218] The first possible solution is that the intermediate relay regards itself as a remote UE to request the security parameters. The parameters of the intermediate relay (i.e., parameters for requesting the security parameters, such as but not limited to an identifier corresponding to the UE, etc.) are carried in a request message to be forwarded to the network device by the upstream node to request the security parameters. If there is still an intermediate relay in the upstream node, the intermediate relay can also regard itself as a remote UE to request the security parameters by using the same method as described above. In this way, the next hop (i.e., the first hop in the intermediate relay) of the U2N relay can obtain the security parameters, and can protect the secure connection with the U2N relay based on the obtained security parameters, and then obtain and forward the security parameters of the downstream nodes through the secure connection. In this way, each intermediate relay along the downstream direction can first protect the secure connection with the previous hop based on the received security parameters, and then obtain and forward the security parameters of the downstream nodes through the secure connection.

[0219] The second possible solution is that each intermediate relay along the upstream direction can carry the parameters received from the next hop and the parameters of the intermediate relay in a request message, and forward the request message to the network device through the upstream node to request the security parameters of each node. Since the U2N relay is the last hop relay node along the upstream direction, the request message received by the U2N relay can include the parameters of each node downstream of the U2N relay. The U2N relay can send the parameters of each node downstream of the U2N relay to the network device to obtain the corresponding security parameters. After obtaining the security parameters corresponding to the next hop, the U2N relay can establish a secure connection with the next hop based on the security parameters, and then forward the security parameters of other downstream nodes through the secure connection. In this way, each intermediate relay along the downstream direction can first protect the secure connection with the previous hop based on the received security parameters, and then obtain and forward the security parameters of the downstream nodes through the secure connection.

[0220] The security parameter-based security connection protection specifically includes directly protecting the connection using part or all of the parameters in the security parameters, or further deriving parameters from part or all of the parameters in the security parameters to protect the connection. The protection of the connection can include confidentiality and / or integrity protection of the connection. The security parameter-based security connection protection can also be referred to as a secure connection accepting security parameter protection or a security parameter user protecting a secure connection.

[0221] The security parameters in the present application mainly refer to root keys and / or random numbers, such as the root key (K NR_ProSe ) and / or the random number (Nonce_2) under the CP scheme, the root key (K NPR ) and / or the random number 2 (K NRPfreshness parameter 2). For convenience of distinguishing and explaining, the root key (K NR_ProSe ) and the random number (Nonce_2) under the CP scheme, or the root key (K NPR ) and the random number 2 (K NRP freshness parameter 2) under the UP scheme are referred to as a security parameter group, and any one of the security parameter group (i.e., the root key (K NR_ProSe or K NPR ) or the random number 2 (Nonce_2 or K NRP freshness parameter 2)) is referred to as a security parameter.

[0222] [Rule 91, 05.11.2025] The above two processing methods will be described in detail below in conjunction with the accompanying drawings. FIGS. 6 and 8 below are two possible implementation processes of the first solution, and FIGS. 9 to 11 show possible implementation processes of the second solution. It should be noted that the possible implementation processes below take the U2N multi-hop relay scenario as an example, and the U2U multi-hop relay scenario is also used in actual use to establish a secure link between UEs using the CP or UP scheme. Therefore, the remote UE in the following text can be replaced by the end UE in the U2U multi-hop relay scenario, and the intermediate relay and U2N relay can be replaced by the U2U relay in the U2U multi-hop scenario.

[0223] First solution:

[0224] FIGS. 6 and 7 show one possible implementation process of the first solution. FIG. 8 shows another possible implementation process of the first solution. In the processes shown in FIGS. 6 and 7, for the convenience of understanding and explanation, the specific process of the method provided by the present application in the scenario including one intermediate relay (as shown in FIG. 5a) is first explained in conjunction with FIG. 6, and then how to apply the method to the scenario including more intermediate relays (as shown in FIG. 5b) is explained in conjunction with FIG. 7.

[0225] It should be understood that the embodiments shown in FIGS. 6 and 8 take the interaction between the remote UE, the intermediate relay, the U2N relay, and the network device as an example to describe the processing logic of the intermediate relay as an example of the first communication device, at this time, the remote UE is an example of the second communication device, and the U2N relay is an example of the third communication device. At the same time, FIGS. 6 and 8 also take the interaction between the remote UE, the intermediate relay, the U2N relay, and the network device as an example to describe the processing logic of the U2N relay as an example of the fourth communication device, at this time, the intermediate relay 1 is an example of the fifth communication device, and the remote UE is an example of the sixth communication device.

[0226] The first communication device to the sixth communication device are defined for distinguishing nodes in different positions. In the method embodiments shown in FIG. 6 and FIG. 8, the fourth communication device is a U2N relay, and the fifth communication device is a next hop of the U2N relay. Therefore, the definition of the first communication device to the sixth communication device herein should not constitute any limitation on the number of node hops in the multi-hop relay service. For example, in a multi-hop relay service including one intermediate relay, the intermediate relay is an example of the first communication device, and also an example of the fifth communication device, so the first communication device and the fifth communication device are the same communication device; accordingly, the U2N relay is an example of the third communication device, and also an example of the fourth communication device, so the third communication device and the fourth communication device are the same communication device; the remote UE is an example of the second communication device, and also an example of the sixth communication device, so the second communication device and the sixth communication device are the same communication device. As the number of node hops in the multi-hop relay service increases, the number of intermediate relays also increases, at this time, each intermediate relay and its previous hop and next hop can be regarded as an example of the first communication device, the third communication device and the second communication device.

[0227] In addition, for the convenience of distinguishing and description, the PC5 security connection between the first communication device and the third communication device is recorded as the first security connection, and the PC5 security connection between the first communication device and the second communication device is recorded as the second security connection, wherein the first security connection is protected by the first security parameter, or in other words, the first security parameter is used to protect the first security connection; the second security connection is protected by the second security parameter, or in other words, the second security parameter is used to protect the second security connection.

[0228] The PC5 security connection between the fourth communication device and the fifth communication device is recorded as the third security connection, and the security connection between the fifth communication device and the sixth communication device is recorded as the fourth security connection, wherein the third security connection is protected by the first security parameter set, or in other words, the first security parameter set is used to protect the third security connection; the fourth security connection is protected by the second security parameter set, or in other words, the second security parameter set is used to protect the fourth security connection.

[0229] In the embodiments shown in FIG. 6 and FIG. 8, the secure connection #1 between the intermediate relay and the U2N relay is an example of the first secure connection, and is also an example of the third secure connection; the secure connection #0 between the intermediate relay and the remote UE is an example of the second secure connection, and is also an example of the fourth secure connection. The security parameter #1 used to protect the secure connection #1 is an example of the first security parameter, and the security parameter set #1 used to protect the secure connection #1 is an example of the first security parameter set, wherein the security parameter #1 is from the security parameter set #1; the security parameter #0 used to protect the secure connection #0 is an example of the second security parameter, and the security parameter set #0 used to protect the secure connection #0 is an example of the second security parameter set, wherein the security parameter #0 is from the security parameter set #0.

[0230] The embodiments shown in FIG. 6 to FIG. 8 can be based on the following scenario: the remote UE, the intermediate relay and the U2N relay are all configured with U2N multi-hop discovery parameters. The remote UE and the intermediate relay can also respectively obtain parameters for establishing a secure connection in the identity of the remote UE, and the specific obtaining steps can refer to steps 30a in the CP scheme described above in combination with FIG. 3, and steps 41a and 41b in the UP scheme described in combination with FIG. 4, which will not be described again. The remote UE can discover the intermediate relay and the U2N relay through the U2N multi-hop discovery process.

[0231] Referring to FIG. 6, FIG. 6 is a schematic flowchart of a method 600 for establishing a secure connection according to an embodiment of the present application. The method 600 shown in FIG. 6 includes steps 601 to 614. Each step in the method 600 will be described in detail below.

[0232] In step 601, the remote UE performs a multi-hop discovery process to discover the intermediate relay and the U2N relay.

[0233] The remote UE can discover the last-hop node through the U2N multi-hop discovery process when it needs to access the network. In this embodiment, the last-hop of the remote UE is the intermediate relay.

[0234] Taking the ProSe discovery process of Model A as an example, the intermediate relay can send a discovery announcement (as shown in 601a in the figure). Optionally, the discovery announcement carries a multi-hop indication, which is used to indicate that the PC5 connection after discovery is used to carry U2N multi-hop relay services. The remote UE can determine that it meets its own service requirements after receiving the discovery announcement, and perform a PC5 unicast establishment process.

[0235] Taking the ProSe discovery procedure of Model B as an example, the remote UE can send a discovery request (as shown in 6011b in the figure). Optionally, the discovery request carries a multi-hop indication, which indicates that the PC5 connection after discovery is used to carry U2N multi-hop relay service. After receiving the discovery request, the intermediate relay determines that it can provide relay service, and sends a discovery reply (as shown in 6012b in the figure). After receiving the discovery reply, the remote UE can perform a PC5 unicast establishment procedure.

[0236] It should be noted that the above procedure takes the discovery procedure between the remote UE and the intermediate relay as an example, although it is not shown in the figure, it can be understood that the actual multi-hop discovery procedure can also involve the discovery procedure between multiple nodes upstream, including the discovery procedure between multiple intermediate relays and the discovery procedure between the intermediate relay and the U2N relay, so the above discovery procedure can be performed once or multiple times. For example, the intermediate relay can continue to discover its last hop, i.e., the U2N relay, as the remote UE in the case of no network coverage or the intermediate relay only as an intermediate relay. The process of the intermediate relay discovering the U2N relay is similar to the ProSe discovery procedure shown in Model A and Model B above, and can refer to the related description above, which will not be repeated here.

[0237] The related content of the U2N multi-hop discovery procedure can refer to the prior art, which will not be described in detail herein.

[0238] In step 602, the remote UE sends a first request message to the intermediate relay, and the first request message carries an identifier corresponding to the remote UE. Correspondingly, the intermediate relay receives the first request message from the remote UE.

[0239] Since the PC5 security connection between the remote UE and the intermediate relay has not been established, the remote UE can send the first request message to the intermediate relay to request to obtain a security parameter #0 for protecting the security connection #0 (i.e., an example of the second security connection) between the remote UE and the intermediate relay. The security parameter #0 is from a security parameter group #0. Therefore, the first request message sent by the remote UE is used to request the security parameter #0, and the first request message sent by the remote UE can also be called to request the security parameter group #0. In other words, the first request message sent by the remote UE can be used to request the security parameter #0, and can also be used to request other information in the security parameter group #0 except the security parameter #0.

[0240] For example, the security parameter group #0 can include a root key and a random number 2 based on the identifier corresponding to the remote UE, such as the root key (K NR_ProSe ) and the random number (Nonce_2) under the CP scheme, the root key (K NPR ) and the random number 2 (K NRPfreshness parameter 2), the security parameter #0 can be a random number 2 (Nonce_2 or K NRP freshness parameter 2).

[0241] The first request message carries an identifier corresponding to the remote UE. The identifier corresponding to the remote UE can be a device identifier for identifying the remote UE, such as the SUCI of the remote UE; the identifier corresponding to the remote UE can also be a key identifier of the remote UE, such as the CP-PRUK ID or the UP-PRUK ID of the remote UE. The identifier corresponding to the remote UE is used to obtain the security parameter group #0, or in other words, the identifier corresponding to the remote UE is a parameter required for obtaining the security parameter group #0.

[0242] It can be understood that the first request message is a message sent when the intermediate relay and the remote UE have not established a PC5 security connection. The first request message can be a message protected by a discovery security key, or a message sent without security protection.

[0243] Optionally, the first request message also carries a first RSC, which is used to indicate relay service. Optionally, the first RSC can also be used to determine the security parameter group #0.

[0244] Optionally, the first request message also carries a random number 1 (Nonce_1 or K NRP freshness parameter 1) provided by the remote UE, which can be used to determine the security parameter group #0.

[0245] In other words, the security parameter group #0 can be obtained based on the identifier corresponding to the remote UE, and the security parameter group #0 is not necessarily obtained based on only the identifier corresponding to the remote UE. As known from the flow examples in FIG. 3 and FIG. 4, the security parameter group #0 can be obtained based on the identifier corresponding to the remote UE, the first RSC, and the random number 1 provided by the remote UE, or in other words, the security parameter group #0 can be obtained based on the parameters in the first request message.

[0246] In one example, the first request message is a direct communication request (DCR) message, for example, denoted as a first DCR message.

[0247] The first DCR message can include parameters required for obtaining the security parameter #0, and the roles of the parameters under different security establishment schemes are shown in Table 1 as follows:

[0248] Table 1

[0249] Wherein, "UE ID" represents the device identity of the above-mentioned device identity, in the first DCR message, the UE ID can be the device identity of the UE corresponding to the remote UE; "User security key ID" represents the key identity of the above-mentioned key identity, in the first DCR message, the user security key ID can be the key identity corresponding to the remote UE. "Source L2 ID" refers to the source layer 2 (L2) identity, in the first DCR message, the source layer 2 identity can be the L2 identity of the remote UE; "Destination L2 ID" refers to the destination layer 2 identity, in the first DCR message, the destination layer 2 identity is the L2 identity of the U2N relay.

[0250] In step 603, the intermediate relay sends a second request message to the U2N relay, and the second request message carries the identity corresponding to the intermediate relay. Correspondingly, the U2N relay receives the second request message from the intermediate relay.

[0251] In the case that the intermediate relay receives the first request message from the next hop, since the intermediate relay is itself and also does not establish a secure connection with the previous hop (i.e. the U2N relay), it can send the second request message to its previous hop as the identity of the remote UE to request the security parameter #1 for protecting the secure connection #1 (i.e. an example of the first secure connection) between the intermediate relay and the U2N relay. Wherein, the security parameter #1 is from the security parameter group #1. Therefore, the second request message sent by the intermediate relay can be used to request the security parameter #1, and the second request message sent by the intermediate relay can also be used to request the security parameter group #1. In other words, the second request message sent by the intermediate relay can be used to request the security parameter #1, and can also be used to request other information in the security parameter group #1 except the security parameter #1.

[0252] Similar to the first request message, the second request message carries the identity corresponding to the intermediate relay. The identity corresponding to the intermediate relay can be a device identity for identifying the intermediate relay, such as the SUCI of the intermediate relay; the identity corresponding to the intermediate relay can also be a key identity of the intermediate relay, such as the CP-PRUK ID or the UP-PRUK ID. The identity corresponding to the intermediate relay is used to obtain the security parameter group #1, or in other words, the identity corresponding to the intermediate relay is a parameter required to obtain the security parameter group #1.

[0253] It can be understood that the second request message is a message sent in the case that the U2N relay and the intermediate relay have not established a PC5 secure connection. The second request message can be a message protected by a discovery security key, or a message sent without security protection.

[0254] Optionally, the second request message also carries a second RSC, where the second RSC is used to indicate the relay service. The second RSC can be the same as or different from the first RSC, which is not limited in the present application. A possible design is that the second RSC is the same as the first RSC, and is used to indicate the same relay service.

[0255] Optionally, the second request message also carries a random number 1 (Nonce_1 or K NRP freshness parameter 1) provided by the intermediate relay, where the random number 1 can be used to determine the security parameter group #1.

[0256] In other words, the security parameter group #1 can be obtained based on the identifier corresponding to the intermediate relay, and does not mean that the security parameter group #1 is only obtained based on the identifier corresponding to the intermediate relay. As known from the flow examples shown in FIG. 3 and FIG. 4, the security parameter group #1 can be obtained based on the identifier corresponding to the intermediate relay, the second RSC, and the random number 1 provided by the intermediate relay.

[0257] In one example, the second request message is another DCR message, for example, denoted as a second DCR message.

[0258] It can be understood that the second request message sent by the intermediate relay to the U2N relay is similar to the DCR message sent by the remote UE to the U2N relay in the CP scheme shown in FIG. 3 and the UP scheme shown in FIG. 4. That is, the intermediate relay can obtain the security parameter #1 from the network device by using the CP scheme or the UP scheme.

[0259] Further, before step 603, the method further includes step 604: determining, by the intermediate relay, that the intermediate relay is an intermediate relay in the multi-hop relay service.

[0260] In one possible implementation, the intermediate relay can determine that it is an intermediate relay in the multi-hop relay service based on the first RSC in the first request message. As described above, the first RSC can be used to indicate the relay service. Since the intermediate relay can determine that it is an intermediate relay in the discovery process, in combination with the corresponding relationship between the first RSC and the relay service, the intermediate relay can determine that it is an intermediate relay in the multi-hop relay service.

[0261] In another possible implementation, the intermediate relay can also determine that it is an intermediate relay in the multi-hop relay service based on the fact that the first request message has the same information as the discovery message in step 601. The fact that the first request message has the same information as the discovery message in step 601 can include one or more of the following: Source L2 ID, Destination L2 ID, or user information identifier (user info id).

[0262] The application does not limit the device to which the intermediate relay applies. The intermediate relay can apply to a UE, so the intermediate relay can perform step 603 after determining that it is an intermediate relay; the intermediate relay can also apply to a device dedicated to relay service, so the intermediate relay can directly perform step 603 after receiving the first request message, without having to perform step 604.

[0263] Optionally, the method further includes step 605: the intermediate relay caches the first request message; or, the intermediate relay caches the information element in the first request message. The information element includes the identifier corresponding to the remote UE, and optionally, the first RSC.

[0264] Since the intermediate relay does not forward the first request message after receiving the first request message because the security connection #1 is not established, the intermediate relay can first cache the first request message or the information element in the first request message locally. After the security connection #1 is established, the information element in the first request message is sent out, i.e., the action in step 609.

[0265] In step 606, the U2N relay sends a first key request to the network device, and the first key request carries the identifier corresponding to the intermediate relay. Correspondingly, the network device receives the first key request from the U2N relay.

[0266] The U2N relay can send the parameters in the second request message to the network device after receiving the second request message, to obtain the security parameter group #1 from the network device. It can be understood that the parameters in the second request message include the identifier corresponding to the intermediate relay, and optionally, the second RSC.

[0267] Exemplarily, the U2N relay can obtain the parameters in the second request message, construct a relay key request (corresponding to the CP scheme) or a key request (corresponding to the UP scheme), and send the relay key request or the key request to the network device, to obtain the security parameter group #1. The relay key request and the key request are two possible examples of the first key request.

[0268] In step 607, the network device sends the security parameter group #1 to the U2N relay.

[0269] The network device can send the security parameter group #1 to the U2N relay through a security connection (e.g., denoted as a U2N security connection) that has been established between the network device and the U2N relay. The security parameter group #1 is generated based on the parameters in the second request message, and can be used to protect the security connection #1 between the U2N relay and the intermediate relay.

[0270] As a reply to the first key request, the network device can send a first key reply to the U2N relay, which carries the security parameter set #1. Exemplarily, the network device can send a relay key reply (corresponding to the CP scheme) to the U2N relay, which carries a root key (K NR_ProSe ) and a random number 2 (Nonce_2) for protecting the secure connection #1; or the network device can send a key reply (corresponding to the UP scheme) to the U2N relay, which carries a root key (K NRP ) and a random number 2 (K NRP freshness parameter 2) for protecting the secure connection #1. The relay key reply and the key reply are two possible examples of the first key reply, respectively.

[0271] In step 608, the U2N relay sends the security parameter set #1 to the intermediate relay. Accordingly, the intermediate relay receives the security parameter set #1 from the U2N relay.

[0272] The U2N relay can send the random number 2 (Nonce_2 or K NRP freshness parameter 2) in the security parameter set #1 for protecting the secure connection #1 (i.e., the security parameter set #1) to the intermediate relay. In this way, the intermediate relay can generate the root key (K NR_ProSe or K NRP ) based on the received random number 2, and further obtain the session key for protecting the secure connection #1. For the sake of distinction and illustration, the session key for protecting the secure connection #1 is denoted as the first session key hereinafter.

[0273] On the other hand, the U2N relay can also generate the first session key based on the root key (K NR_ProSe or K NRP ) in the security parameter set #1. In this way, the U2N relay and the intermediate relay can protect the communication over the secure connection #1 based on the first session key.

[0274] It should be understood that the first session key is used for protecting the secure connection #1, and the first session key is obtained based on the parameters in the security parameter set #1, thus the security parameter set #1 can also be referred to as being used for protecting the secure connection #1.

[0275] It should also be understood that in the procedures shown in steps 603 and 606-608, the intermediate relay sends the second request message to the U2N relay in the identity of the remote UE, and obtains the security parameter set #1 from the network device, which is similar to the procedure in which the remote UE requests the network device to obtain the security parameter set through the U2N relay in the CP scheme or the UP scheme described above. Please refer to the CP scheme and the UP scheme exemplarily shown in FIG. 3 and FIG. 4 described above, which will not be described herein again.

[0276] In step 609, the intermediate relay sends the remote UE corresponding identity to the U2N relay over the secure connection #1.

[0277] After the intermediate relay establishes the secure connection #1 with the U2N relay, the intermediate relay can send the parameters in the first request message to the network device over the secure connection #1 to request the security parameter set #0. As mentioned before, the parameters in the first request message include the remote UE corresponding identity, and optionally, the first RSC. One possible implementation for the intermediate relay to send the parameters in the first request message over the secure connection #1 is to encrypt the parameters in the first request message based on the first session key.

[0278] The following exemplary shows several possible message types that can be used to carry the parameters in the first request message sent by the intermediate relay to the U2N relay.

[0279] Optionally, the parameters in the first request message sent by the intermediate relay over the secure connection #1 are carried in an intermediate key request message. That is, the remote UE corresponding identity sent over the secure connection #1 is carried in the intermediate key request message. Optionally, the first RSC sent over the secure connection #1 is also carried in the intermediate key request message.

[0280] Optionally, the parameters in the first request message sent by the intermediate relay over the secure connection #1 are carried in a DCR message (e.g., denoted as a third DCR message). That is, the remote UE corresponding identity sent over the secure connection #1 is carried in the third DCR message. Optionally, the first RSC sent over the secure connection #1 is also carried in the third DCR message.

[0281] It should be understood that, unlike the first DCR message and the second DCR message described before, the third DCR message is a DCR message protected based on the first session key.

[0282] Optionally, the parameters in the first request message sent over the secure connection #1 are carried in a control plane message of the PC5 link. That is, the remote UE corresponding identity sent over the secure connection #1 is carried in the control plane message of the PC5 link. Optionally, the first RSC sent over the secure connection #1 is also carried in the control plane message of the PC5 link. Exemplarily, the control plane message of the PC5 link is a link modification request message.

[0283] Optionally, the parameters in the first request message sent over the secure connection #1 are carried in the user plane message of the PC5 link. That is, the identity of the remote UE corresponding to the first request message sent over the secure connection #1 is carried in the user plane message of the PC5 link. Optionally, the first RSC sent over the secure connection #1 is also carried in the user plane message of the PC5 link.

[0284] In a possible design, the intermediate relay carries a message container in the above-mentioned control plane message or user plane message of the PC5 link sent over the secure connection #1, where the message container contains the parameters in the first request message. It should be noted that the message container can be predefined, and the message container can be used to carry one or more information elements. For example, if the message container is used to carry a DCR message (i.e., the DCR message is carried in the message container as an information element, or the parameters in the DCR message are carried in the message container as information elements), the message container includes the parameters carried in the DCR message, and the message container can also be referred to as a DCR container.

[0285] In step 610, the U2N relay sends a second key request to the network device, where the second key request carries the identity of the remote UE. Accordingly, the network device receives the second key request from the U2N relay.

[0286] The U2N relay can request the network device to obtain the security parameters again after receiving the identity of the remote UE from the intermediate relay. The U2N relay can send a second key request to the network device, where the second key request carries the parameters in the first request message. It should be understood that the parameters in the first request message include the identity of the remote UE, and optionally, the first RSC.

[0287] It should be understood that step 610 is similar to step 606, and details are referable to the description of step 606.

[0288] In step 611, the network device sends the security parameter set #0 to the U2N relay. Accordingly, the U2N relay receives the security parameter set #0 from the network device.

[0289] The network device can send the security parameter set #0 to the U2N relay over the U2N secure connection. The security parameter set #0 is generated based on the parameters in the first request message, and can be used to protect the secure connection #0 between the intermediate relay and the remote UE.

[0290] As a reply to the second key request, the network device can send a second key reply to the U2N relay, where the second key reply carries the security parameter set #0.

[0291] It should be understood that step 611 is similar to step 607, and reference can be made to the relevant description of step 607, which will not be repeated here.

[0292] It should be noted that, since different UEs correspond to different HPLMNs, after the U2N relay sends the second key request to the network device, the network device can obtain the security parameter set #0 by interacting with a network element in the HPLMN of the remote UE. The specific obtaining steps can be referred to the steps 35 to 312 in the CP scheme of FIG. 3 and the steps 44b to 44e in the UP scheme of FIG. 4, which will not be repeated here. It can be understood that in different security establishment schemes, the above network device can refer to different network elements in the HPLMN of the U2N relay or the serving PLMN (serving PLMN), which is not limited in the present application.

[0293] In step 612, the U2N relay sends the security parameter set #0 to the intermediate relay through the secure connection #1. Correspondingly, the intermediate relay receives the security parameter set #0 from the U2N relay through the secure connection #1.

[0294] After receiving the security parameter set #0, the U2N relay can send the security parameter set #0 to the intermediate relay through the secure connection #1.

[0295] The message type used by the U2N relay to send the security parameter set #0 to the intermediate relay through the secure connection #1 in step 612 can correspond to the message type used by the intermediate relay to send the parameters in the first request message through the secure connection #1 in step 609.

[0296] Optionally, the security parameter set #0 sent by the U2N relay through the secure connection #1 (or received by the intermediate relay through the secure connection #1) is carried in an intermediate key response message.

[0297] Correspondingly, the parameters in the first request message sent by the intermediate relay through the secure connection #1 in step 609 are carried in an intermediate key request message.

[0298] Optionally, the security parameter set #0 sent by the U2N relay through the secure connection #1 (or received by the intermediate relay through the secure connection #1) is carried in a direct communication accept (DCA) message.

[0299] Correspondingly, the parameters in the first request message sent by the intermediate relay through the secure connection #1 in step 609 are carried in a third DCR message.

[0300] Optionally, the security parameter group #0 sent by the U2N relay over the secure connection #1 (or, in other words, received by the intermediate relay over the secure connection #1) is carried in a control plane message of the PC5 link.

[0301] Correspondingly, the parameters in the first request message sent by the intermediate relay over the secure connection #1 in step 609 are carried in a control plane message of the PC5 link.

[0302] Optionally, the security parameter group #0 sent by the U2N relay over the secure connection #1 (or, in other words, received by the intermediate relay over the secure connection #1) is carried in a user plane message of the PC5 link.

[0303] Correspondingly, the parameters in the first request message sent by the intermediate relay over the secure connection #1 in step 609 are carried in a user plane message of the PC5 link.

[0304] In a possible design, the U2N relay carries a message container in the control plane message or the user plane message of the PC5 link sent over the secure connection #1, where the message container contains the security parameter group #0.

[0305] As can be seen from steps 603 and 606 and steps 609 and 610 above, the U2N relay receives, from the same intermediate relay (i.e., the intermediate relay), twice in succession, the identity corresponding to the communication apparatus (i.e., the identity corresponding to the intermediate relay and the identity corresponding to the remote UE), and receives, from the network device, twice in succession, the security parameter group (i.e., the security parameter group #1 and the security parameter group #0). The U2N relay can determine, according to the order in which the security parameter group #1 and the security parameter group #0 are received, whether the received security parameter group is used to protect the secure connection of the U2N relay and the next hop, or is used to protect the secure connection between downstream nodes, i.e., whether to forward the received security parameter group to the next hop.

[0306] Optionally, before step 612, the method further includes step 613: the U2N relay determines to forward the security parameter group #0 over the secure connection #0.

[0307] In one possible implementation, the U2N relay can determine that the security parameters requested from the network device this time are for protecting the secure connection between downstream nodes, e.g., according to the message type received in step 609. For example, the protocol can predefine that the intermediate relay sends a second key request using a predefined message type after the secure connection #1 between the U2N relay and the intermediate relay is established. If the message type received by the U2N relay in step 609 belongs to the predefined message type, it can be determined that the security parameters requested from the network device this time are for protecting the secure connection between downstream nodes, and thus it can be determined to forward the security parameter set #0. Since the U2N relay needs to determine to forward the security parameter set #0 according to the message type received in step 609, this step can be performed after step 609 and before step 613.

[0308] In another possible implementation, the U2N relay can determine that the security parameters requested from the network device this time are for protecting the secure connection between downstream nodes, according to the message received in step 609 and the message received in step 603 being from the same node. It can be understood that when the same node sends two messages for obtaining security parameters to the U2N relay successively, the node can be requesting security parameters for its downstream nodes. For example, in this embodiment, the U2N relay receives messages from the intermediate relay in both steps 609 and 603, and thus it can be determined that the security parameters requested from the network device this time are for protecting the secure connection between downstream nodes, and thus it can be determined to forward the security parameter set #0. Since the U2N relay needs to determine to forward the security parameter set #0 according to the message type received in step 609, this step can be performed after step 609 and before step 613. Specifically, the U2N relay can determine that the two messages are from the same node according to the message received in step 609 and the message received in step 603 carrying the same information, which can include one or more of the following: Source L2 ID, Destination L2 ID, RSC or user info id.

[0309] In yet another possible implementation, the U2N relay can determine that the current traffic is multi-hop relay traffic in combination with the previous discovery procedure, and thus the U2N relay can forward the security parameter set received again in the case that it receives the security parameter set #1 again (such as the security parameter set #0 shown in the foregoing embodiment). Since the U2N relay does not need to determine to forward the security parameter set #0 according to the message type received in step 609, this step can also be performed before step 609, without limitation.

[0310] It should be understood that the processing logic of the U2N relay is described in detail in connection with steps 603 to 610, at which time the U2N relay is an example of the fourth communication device, the intermediate relay is an example of the fifth communication device, the remote UE is an example of the sixth communication device, the secure connection #1 is an example of the third secure connection, the security parameter set #1 is an example of the third security parameter, the secure connection #0 is an example of the fourth secure connection, and the security parameter set #0 is an example of the fourth security parameter set.

[0311] Optionally, the method further includes step 614: the intermediate relay sends the security parameter #0 to the remote UE. Accordingly, the remote UE receives the security parameter #0 from the intermediate relay.

[0312] Similar to step 608, the intermediate relay can send the random number 2 (Nonce_2 or K NRP freshness parameter 2) in the security parameter set #0 to the remote UE for protecting the secure connection #0 (i.e., the security parameter #0). In this way, the remote UE can determine the session key for protecting the secure connection #0 based on the local root key and the received random number. For the convenience of distinguishing the description, the session key for protecting the secure connection #0 is referred to as the second session key hereinafter.

[0313] It should be understood that the random number 2 in step 608 and the random number 2 in step 614 are random numbers 2 from different security parameter sets, generated based on different parameters, and used for protecting different secure connections, which are examples of the security parameter #1 and the security parameter #0 respectively in the embodiment, and are different from each other.

[0314] On the other hand, the intermediate relay can also generate the second session key based on the root key (K NR_ProSe or K NRP ) in the security parameter set #0. In this way, the intermediate relay and the remote UE can protect the communication through the secure connection #0 based on the second session key.

[0315] It should be understood that the second session key is used for protecting the secure connection #0, and the second session key is based on the parameters in the security parameter set #0, so the security parameter set #0 can also be referred to as being used for protecting the secure connection #0.

[0316] So far, the remote UE can securely communicate with the network device through the intermediate relay and the U2N relay.

[0317] It is not difficult to see that in the above process, the secure connection #1 is triggered to be established after the secure connection #0, and is completed before the secure connection #0. That is, the completion of the security establishment can be completed in turn along the downstream direction of the multi-hop relay service.

[0318] The above is just for easy understanding, and shows the security establishment procedure of the multi-hop relay service including one intermediate relay. The method can also be applied to a scenario including more intermediate relays, such as the scenario shown in Figure 5b.

[0319] Figure 7 shows a scenario including K intermediate relays, in the downstream direction: a network device, a U2N relay, an intermediate relay K, an intermediate relay K-1, …, an intermediate relay 2, an intermediate relay 1, and a remote UE. That is, in addition to the network device, there are K+2 communication devices. In this case, the above method 600 can still be applied.

[0320] Exemplarily, the remote UE (i.e., an example of the second communication device) can send a request message #0 (i.e., an example of the first request message) to the upper one hop (i.e., the intermediate relay 1, an example of the first communication device) to request to obtain a security parameter #0 (i.e., an example of the second security parameter); the intermediate relay 1, in response to the request message #0, can send a request message #1 (i.e., an example of the second request message) to the upper one hop (i.e., the intermediate relay 2, an example of the third communication device) to request to obtain a security parameter #1 (i.e., an example of the first security parameter).

[0321] The intermediate relay 2, after receiving the request message #2, can regard itself as the first communication device, regard the request message #1 as the first request message, and send a request message #2 (i.e., another example of the second request message) to the upper one hop (i.e., the intermediate relay 3, another example of the third communication device) to request to obtain a security parameter #3 (i.e., another example of the first security parameter). At this time, the intermediate relay 1 from which the request message #2 comes is another example of the second communication device.

[0322] By analogy, until the U2N relay receives the request message #K from the intermediate relay K. Therefore, in the multi-hop node, starting from the remote UE and ending at the U2N relay, every three-hop adjacent node in the upstream direction can respectively serve as the first communication device, the second communication device, and the third communication device, and perform the steps performed by the remote UE (corresponding to the second communication device), the intermediate relay 1 (corresponding to the first communication device), and the U2N relay (corresponding to the third communication device) respectively in the above method 600 once.

[0323] After the U2N relay (i.e., an example of the fourth communication device) receives the request message #K from the intermediate relay K (i.e., an example of the fifth communication device), the U2N relay can first perform steps 603 and steps 606 to 608 to establish the secure connection #K (i.e., an example of the third secure connection) between the U2N relay and the next hop, and then perform steps 609 to 613 to obtain the security parameters #K-1 (i.e., an example of the second security parameter set) for the intermediate relay K, for protecting the secure connection #K-1 (i.e., an example of the fourth secure connection) between the intermediate relay K and the intermediate relay K-1. Thereafter, the U2N relay can request the security parameter set for each of the downstream nodes (including the intermediate relay K-2, the intermediate relay K-3, …, the intermediate relay 1, and the remote UE) in sequence, in the same way as the processing of steps 606 to 609, for protecting the secure connection between each two-hop adjacent nodes downstream.

[0324] wherein the number #0 corresponds to the remote UE, the numbers #1 to #K correspond to the K intermediate relays, and the number #K+1 corresponds to the U2N relay. The request message #k carries an identity corresponding to the node with the number #k, and the security parameters #k are obtained based on the identity corresponding to the node with the number #k carried in the request message #k, and can be used to protect the secure connection #k between the node with the number #k and the previous hop (or the node with the number #k+1). k can be a positive integer in 0 to K.

[0325] Based on the above technical solution, in the multi-hop relay service, each intermediate relay can request to obtain the security parameters by taking itself as the remote UE when receiving the request message from the next hop for requesting to obtain the security parameters. The parameters of the intermediate relay (i.e., the parameters for obtaining the security parameters, such as but not limited to the identity corresponding to the UE, etc.) are carried in the request message to be forwarded to the network device by the upstream node, for requesting to obtain the security parameters. The U2N relay can request the security parameter set for each of the downstream nodes according to the received multiple request messages, and obtain and forward the security parameter set for each of the downstream nodes in sequence after establishing the secure connection between the U2N relay and the next hop. In this way, each intermediate relay in the downstream direction can first protect the secure connection between itself and the next hop based on the received security parameter set, and then obtain and forward the security parameters for the downstream nodes in sequence through the secure connection. In this way, the secure connection between each two-hop adjacent nodes in the multi-hop relay service can be established in sequence in the downstream direction, and the remote UE can perform secure communication with the network device.

[0326] It should be understood that in the flow shown in method 600, each intermediate relay requests the network device for security parameters upon receiving a request message from the next hop for requesting security parameters, in other words, the operation of each intermediate relay requesting the network device for security parameters is triggered in response to the request from the next hop, thus the method can be referred to as a security establishment method triggered on-demand along with the route, or the method can be referred to as a security establishment method triggered sequentially from downstream to upstream.

[0327] Method 600 shown in FIG. 6 only shows one possible implementation, in another implementation, the intermediate relay can also establish a security connection with the previous hop in advance, and upon receiving the request message from the next hop, the intermediate relay can use the security connection already established in advance to request security parameters for the next hop. This implementation will be described below in conjunction with FIG. 8.

[0328] It should be understood that method 800 shown in FIG. 8 and method 600 shown in FIG. 6 are two different implementations based on the same processing logic (i.e., the first processing logic described above). Some steps in the two methods are the same or similar, and the description of the steps in method 800 below that are the same or similar to the steps in method 600, as well as the terms in method 800 that are the same or similar to the terms in method 600, can be referred to the description of the steps in method 600 above, and will not be described again.

[0329] [Rule 91, 05.11.2025] Referring to FIG. 8, FIG. 8 is a schematic flow chart of a method 800 for establishing a security connection according to another embodiment of the present application. Method 800 shown in FIG. 8 includes steps 801 to 814. Each step in method 800 will be described in detail below.

[0330] In step 801, the intermediate relay determines that it is an intermediate relay in a multi-hop relay service.

[0331] The intermediate relay determines that it can be an intermediate relay in a U2N multi-hop relay service, and triggers a discovery procedure to discover the next hop. In this embodiment, the previous hop of the intermediate relay is a U2N relay.

[0332] In one implementation, the intermediate relay determines that it can be an intermediate relay in a U2N multi-hop relay service after performing a multi-hop discovery procedure such as step 601, according to the fact that there are still relay nodes other than network devices in the previous hop of the intermediate relay.

[0333] In another implementation, the intermediate relay is locally pre-configured with a ProSe U2N multi-hop relay service policy, which indicates that the intermediate relay is an intermediate relay in a U2N multi-hop relay service.

[0334] In step 802, the intermediate relay detects the U2N relay.

[0335] The process of discovering U2N relays through the intermediate relay discovery process is similar to step 601 in method 600, for example, it can be achieved through the ProSe discovery process of model A or model B.

[0336] [Detailed Rules 91, 30.01.2026] Taking the ProSe discovery process of Model A as an example, a U2N relay can send a discovery broadcast (as shown in Figure 802a). Optionally, this discovery broadcast carries a multi-hop indicator, which is used to indicate that the PC5 connection after discovery is used to carry U2N multi-hop relay services. After receiving the discovery broadcast, the intermediate relay can determine whether it meets its own service requirements and execute the PC5 unicast establishment process.

[0337] [Detailed Rule 91, 30.01.2026] Taking the ProSe discovery process of Model B as an example, an intermediate relay can send a discovery request (as shown in Figure 8021b). Optionally, the discovery request carries a multi-hop indicator, which is used to indicate that the discovered PC5 connection is used to carry U2N multi-hop relay services. After receiving the discovery request, the U2N relay determines that it can provide relay services and can send a discovery reply (as shown in Figure 8022b). After receiving the discovery reply, the intermediate relay can execute the PC5 unicast establishment process.

[0338] It should be noted that the above process uses the discovery process between an intermediate relay and a U2N as an example. Although not shown in the diagram, it can be understood that the actual multi-hop discovery process may also involve discovery processes between multiple upstream nodes, including discovery processes between multiple intermediate relays and between intermediate relays and U2N relays. Therefore, the above discovery process can be executed once or multiple times. For example, an intermediate relay can continue to discover its previous hop, i.e., the U2N relay, as a remote UE even in the absence of network coverage or when it is only acting as an intermediate relay. The discovery process between multiple upstream nodes described above is detailed in conjunction with the ProSe discovery process shown in Model A and Model B above, and will not be repeated here.

[0339] For details regarding the U2N multi-hop discovery process, please refer to existing technologies; this article will not elaborate further.

[0340] In step 803, the intermediate relay sends a second request message to the U2N relay, which carries the identifier corresponding to the intermediate relay.

[0341] In step 804, the U2N relay sends a first key request to the network device, the first key request carrying an identifier corresponding to the intermediate relay. Accordingly, the network device receives the first key request from the U2N relay.

[0342] In step 805, the network device sends a security parameter set #1 to the U2N relay.

[0343] In step 806, the U2N relay sends the security parameter #1 to the intermediate relay. Accordingly, the intermediate relay receives the security parameter #1 from the U2N relay.

[0344] It should be understood that steps 803 to 806 show the establishment procedure of the security connection #1, which is similar to the specific procedures of steps 603 and 606 to 608 in method 600. For details, refer to the related description in method 600, which will not be repeated here.

[0345] In step 807, the remote UE discovers the intermediate relay.

[0346] Similar to step 802, the remote UE can discover its last hop through the discovery procedure. In this embodiment, the last hop of the remote UE is the intermediate relay.

[0347] For details of the specific procedure in which the remote UE discovers the intermediate relay through the discovery procedure, refer to the related description in step 601 of method 600, which will not be repeated here.

[0348] In step 808, the remote UE sends a first request message to the intermediate relay, where the first request message carries an identifier corresponding to the remote UE. Accordingly, the intermediate relay receives the first request message from the remote UE.

[0349] In step 809, the intermediate relay sends the identifier corresponding to the remote UE to the U2N relay through the security connection #1.

[0350] In step 810, the U2N relay sends a second key request to the network device, where the second key request carries the identifier corresponding to the remote UE. Accordingly, the network device receives the second key request from the U2N relay.

[0351] In step 811, the network device sends a security parameter set #0 to the U2N relay. Accordingly, the U2N relay receives the security parameter set #0 from the network device.

[0352] In step 812, the U2N relay determines to forward the security parameter set #0 through the security connection #0.

[0353] In step 813, the U2N relay sends the security parameter set #0 to the intermediate relay through the security connection #1. Accordingly, the intermediate relay receives the security parameter set #0 from the U2N relay through the security connection #1.

[0354] In step 814, the intermediate relay sends a security parameter #0 to the remote UE. Accordingly, the remote UE receives the security parameter #0 from the intermediate relay.

[0355] It should be understood that steps 808 to 814 show the establishment procedure of the secure connection #0, which is similar to the specific procedures of steps 601 and 609 to 614 in method 600. For details, please refer to the related description in method 600, which will not be repeated here.

[0356] So far, the remote UE can perform secure communication with the network device through the intermediate relay and the U2N relay.

[0357] As can be seen, in the above procedure, the secure connection #1 is established before the secure connection #0, in other words, the secure connection #1 is not established due to the establishment requirement of the secure connection #0.

[0358] The above is only for the convenience of understanding, and shows the secure establishment procedure of the multi-hop relay service including one intermediate relay. The method can also be applied to a scenario including more intermediate relays, for example, the scenario shown in b) of FIG. 5.

[0359] Exemplarily, the intermediate relay K (i.e., an example of the first communication device) can send a request message #K (i.e., an example of the second request message) to the U2N relay (i.e., an example of the third communication device) in the identity of the remote UE, and obtain a security parameter #K (i.e., an example of the first security parameter), and then establish a secure connection #K (i.e., an example of the first secure connection) with the U2N relay; the intermediate relay K-1 (i.e., an example of the second communication device) can send a request message #K-1 (i.e., an example of the first request message) to the intermediate relay K in the identity of the remote UE after finding the intermediate relay K, and obtain a security parameter #K-1 (i.e., an example of the second security parameter), and then establish a secure connection #K-1 (i.e., an example of the second secure connection) with the intermediate relay K.

[0360] The intermediate relay K-2 can also perform similar operations to the intermediate relay K-1 in the identity of the remote UE after finding the intermediate relay K-1. At this time, the intermediate relay K-2 is another example of the second communication device, the intermediate relay K-1 is another example of the first communication device, and the intermediate relay K is another example of the third communication device. The above request message #K-1 can be regarded as another example of the second request message, and the secure connection #K-1 between the intermediate relay K-2 and the intermediate relay K-1 is another example of the first secure connection. The intermediate relay K-2 can send a request message #K-2 (i.e., another example of the first request message) to the intermediate relay K-1, and obtain a security parameter #K-2 (i.e., another example of the second security parameter), and then establish a secure connection #K-2 (i.e., another example of the second secure connection) with the intermediate relay #K-1.

[0361] By analogy, until the far-end UE (i.e., another example of the second communication apparatus) finds the intermediate relay 1 (i.e., another example of the first communication apparatus), and sends the request message #0 (i.e., another example of the first request message) to the intermediate relay 1, and obtains the security parameter #0 (i.e., another example of the second security parameter), and further establishes the secure connection #0 (i.e., another example of the second secure connection) with the intermediate relay 1.

[0362] After the U2N relay (i.e., an example of the fourth communication apparatus) receives the request message #K from the intermediate relay K (i.e., an example of the fifth communication apparatus), it can first perform 804 to 806 to establish the secure connection #K (i.e., an example of the third secure connection) between the U2N relay and the next hop, and after receiving the corresponding parameters from the intermediate relay K-1 (i.e., an example of the sixth communication apparatus) through the secure connection #K, it can perform steps 810 to 813 to obtain the security parameter set #K-1 (i.e., an example of the second security parameter set) for the intermediate relay K-1, for protecting the secure connection #K-1 (i.e., an example of the fourth secure connection) between the intermediate relay K and the intermediate relay K-1. Thereafter, the U2N relay can request security parameters for its downstream nodes (including the intermediate relay K-2, the intermediate relay K-3, …, the intermediate relay 1 and the far-end UE) in sequence according to the processing manner of steps 810 to 813, for protecting the security parameters between every two-hop adjacent nodes downstream thereof.

[0363] wherein the number #0 corresponds to the far-end UE, the numbers #1 to #K correspond to the K intermediate relays, and the number #K+1 corresponds to the U2N relay. The request message #k carries an identity corresponding to the node with the number #k, the security parameter #k is obtained based on the identity corresponding to the node with the number #k carried in the request message #k, and can be used to protect the secure connection #k, the secure connection #k is the secure connection between the node with the number #k and the previous hop (or the node with the number #k+1), and k can be a positive integer in 0 to K.

[0364] Based on the above technical solution, in the multi-hop relay service, each node can establish a secure connection with the previous hop in advance when determining to serve as an intermediate relay, that is, the secure connection between the node and the network device is established. Therefore, in the case where the next hop receives a request message for requesting security parameters, the parameters in the request message can be forwarded to the network device through the secure connection via the upstream node to request security parameters. The U2N relay can request security parameters for each downstream node according to the received identifiers corresponding to the plurality of nodes, and sequentially forward the security parameters corresponding to each node through the secure connection. In this way, each intermediate relay along the downstream direction can first protect the secure connection between itself and the next hop based on the received security parameter group, and then sequentially acquire and forward security parameters for downstream nodes through the secure connection. In this way, the remote UE can perform secure communication with the network device. Moreover, since each node can establish a secure connection with the network device in advance, the intermediate relay does not need to request security parameters for itself in response to the request message from the next hop, and the establishment of the secure connection between the remote UE and the network device is more efficient.

[0365] It should be understood that in the flow shown in the method 800, the intermediate relay does not need to request security parameters for itself in response to the request message from the next hop because the secure connection with the network device is established in advance, that is, the implementation mode shown in the method 800 is not a security establishment method triggered on demand along the way.

[0366] The second solution:

[0367] In the following, the specific flow of the method provided by the present application in the scenario including two intermediate relays is described in combination with FIG. 9. It should be understood that in the multi-hop relay service including two intermediate relays, the upstream direction is sequentially: the remote UE, the intermediate relay 1, the intermediate relay 2, the U2N relay, and the network device. In the following, the processing logic of the intermediate relay 1 as an example of the first communication device is described by taking the interaction among the remote UE, the intermediate relay 1, and the intermediate relay 2 as an example, at this time the remote UE is an example of the second communication device, and the intermediate relay 2 is an example of the third communication device; the processing logic of the intermediate relay 2 as another example of the first communication device is described by taking the interaction among the intermediate relay 1, the intermediate relay 2, and the U2N relay as an example, at this time the intermediate relay 1 is another example of the second communication device, and the U2N relay is another example of the third communication device. In addition, the processing logic of the U2N relay as an example of the fourth communication device is described by taking the interaction among the intermediate relay 2, the U2N relay, and the network device as an example, at this time the intermediate relay 2 is an example of the fifth communication device.

[0368] The first communication device to the fifth communication device are defined for distinguishing nodes in different positions, for example, the first communication device is a next hop of the third communication device and is a previous hop of the second communication device; the fifth communication device is a next hop of the fourth communication device, and the definition of the first communication device to the fifth communication device in the present document should not constitute any limitation on the number of node hops in the multi-hop relay service.

[0369] The embodiment shown in FIG. 9 can be based on the following scenario: the remote UE, the intermediate relay 1, the intermediate relay 2 and the U2N relay are all configured with U2N multi-hop discovery parameters. The remote UE, the intermediate relay 1 and the intermediate relay 2 can also respectively acquire parameters for establishing a secure connection in the identity of the remote UE, and the specific acquisition steps can refer to steps 30a in the CP scheme described above in combination with FIG. 3, and steps 41a and 41b in the UP scheme described in combination with FIG. 4, which will not be described again. The remote UE can discover the intermediate relay and the U2N relay through the U2N multi-hop discovery process.

[0370] Referring to FIG. 9, FIG. 9 is a schematic flowchart of a method for establishing a secure connection according to another embodiment of the present application. The method 900 shown in FIG. 9 includes steps 901 to 914.

[0371] In step 901, the remote UE performs a multi-hop discovery process to discover the intermediate relay 1, the intermediate relay 2 and the U2N relay.

[0372] The remote UE can discover the previous hop node through the U2N multi-hop discovery process when it needs to access the network. In the present embodiment, the previous hop of the remote UE is the intermediate relay 1.

[0373] Taking the ProSe discovery process of Model A as an example, the intermediate relay can send a discovery announcement (as shown in 901a in the figure). Optionally, the discovery announcement carries a multi-hop indication, which is used to indicate that the PC5 connection after discovery is used to carry the U2N multi-hop relay service. The remote UE can determine that it meets its own service requirements after receiving the discovery announcement, and perform a PC5 unicast establishment process.

[0374] Taking the ProSe discovery process of Model B as an example, the remote UE can send a discovery request (as shown in 9011b in the figure). Optionally, the discovery request carries a multi-hop indication, which is used to indicate that the PC5 connection after discovery is used to carry the U2N multi-hop relay service. The intermediate relay can send a discovery reply (as shown in 9012b in the figure) after receiving the discovery request and determining that it can provide relay service. The remote UE can receive the discovery reply and perform a PC5 unicast establishment process.

[0375] It is to be noted that the above procedure takes the discovery procedure between the remote UE and the intermediate relay 1 as an example, although not shown in the figure, it can be understood that the actual multi-hop discovery procedure can also involve the discovery procedure between multiple nodes upstream, including the discovery procedure between multiple intermediate relays (such as the intermediate relay 1 and the intermediate relay 2), the discovery procedure between the intermediate relay and the U2N relay (such as the intermediate relay 2 and the U2N relay), and thus the above discovery procedure can be performed once or multiple times. For example, the intermediate relay can continue to discover its last hop, i.e., the U2N relay, as the remote UE in the case of no network coverage or the intermediate relay only as an intermediate relay. The process of the intermediate relay discovering the U2N relay is similar to the ProSe discovery procedure shown in the above models A and B, and can refer to the related description in the above, which will not be described in detail.

[0376] In step 902, the remote UE sends a request message #0 to the intermediate relay 1, and the request message #0 carries an identity corresponding to the remote UE. Correspondingly, the intermediate relay 1 receives the request message #0 from the remote UE.

[0377] The identity corresponding to the remote UE can be a device identity of the remote UE, such as the SUCI of the remote UE; the identity corresponding to the remote UE can also be a key identity of the remote UE, such as the CP-PRUK ID or the UP-PRUK ID of the remote UE. The identity corresponding to the remote UE is used to obtain a security parameter #0, or in other words, the identity corresponding to the remote UE is a parameter required to obtain the security parameter #0. In other words, the request message #0 can be used to request to obtain the security parameter #0. Wherein, the security parameter #0 is from a security parameter group #0. Therefore, the request message #0 sent by the remote UE is used to request the security parameter #0, and can also be called that the request message #0 sent by the remote UE is used to request the security parameter group #0. In other words, the request message #0 sent by the remote UE can be used to request the security parameter #0, and can also be used to request other information in the security parameter group #0 except the security parameter #0.

[0378] The security parameter group #0 (or the security parameter #0) can be used to protect a secure connection #0 between the remote UE and the intermediate relay 1.

[0379] For more detailed description of the security parameter group #0, the security parameter #0 and the secure connection #0, please refer to the related description in the above method 600, which will not be described in detail.

[0380] Optionally, the request message #0 also carries an RSC #0, and the RSC #0 is used to indicate a relay service. Optionally, the RSC #0 can be used to determine the security parameter group #0.

[0381] Optionally, the request message #0 also carries a random number 1 (Nonce_1 or KNRP The random number 1 can be used to determine the security parameter group #0.

[0382] It should be understood that the parameters in the request message #0 are all provided by the remote UE.

[0383] In other words, the security parameter group #0 can be based on the identity corresponding to the remote UE, and does not mean that the security parameter group #0 is only based on the identity corresponding to the remote UE. As known from the flow examples shown in FIG. 3 and FIG. 4, the security parameter group #0 can be based on the identity corresponding to the remote UE, the first RSC and the random number 1 provided by the remote UE, or in other words, the security parameter group #0 can be based on the parameters in the request message #0.

[0384] In a possible design, the request message #0 is a DCR message. The DCR message can include parameters for obtaining the security parameter group #0. The parameters for obtaining the security parameter group #0, and the roles of the parameters in different security establishment schemes are shown in Table 1 in the method 600, and will not be repeated here.

[0385] In step 903, the intermediate relay 1 sends a request message #1 to the intermediate relay 2, and the request message #1 carries the identity corresponding to the remote UE and the identity corresponding to the intermediate relay 1.

[0386] Similar to the identity corresponding to the remote UE, the identity corresponding to the intermediate relay 1 can be a device identity of the intermediate relay 1, for example, a SUCI of the intermediate relay 1; the identity corresponding to the intermediate relay 1 can be a key identity of the intermediate relay 1, for example, a CP-PRUK ID or a UP-PRUK ID of the intermediate relay 1.

[0387] After receiving the request message #0, the intermediate relay 1 constructs another message, i.e., the request message #1, based on the parameters in the request message #1 and the parameters corresponding to the intermediate relay 1, and sends the request message #1 to the previous hop, which is the intermediate relay 2 in this embodiment.

[0388] The parameters corresponding to the intermediate relay 1 are used to obtain the security parameter #1, and the security parameter #1 is used to protect the security connection #1 between the intermediate relay 1 and the intermediate relay 2. The security parameter #1 is from the security parameter group #1. Therefore, the request message #1 sent by the intermediate relay 1 is used to request the security parameter #1, and the request message #1 sent by the intermediate relay 1 can also be used to request the security parameter group #1. In other words, the request message #1 sent by the intermediate relay 1 can be used to request the security parameter #1, and can also be used to request other information in the security parameter group #1 except the security parameter #1.

[0389] Exemplarily, the parameters corresponding to the intermediate relay 1 comprise an identity corresponding to the intermediate relay 1. Optionally, the parameters corresponding to the intermediate relay 1 further comprise an RSC#1, which is used to indicate a relay service. Optionally, the RSC#1 can be used to obtain a security parameter group #1. Optionally, the parameters corresponding to the intermediate relay 1 further comprise a random number 1 used to obtain the security parameter group #1.

[0390] Therefore, the request message #1 carries the identity corresponding to the remote UE and the identity corresponding to the intermediate relay 1. Optionally, the request message #1 further carries the RSC#0 and the RSC#1. Optionally, the request message #1 further carries the random number 1 provided by the remote UE and the random number 1 provided by the intermediate relay 1. The RSC#1 and the random number 1 provided by the intermediate relay 1 can be used to determine the security parameter group #1. The RSC#0 and the RSC#1 can be the same or different. In the case that the RSC#0 and the RSC#1 are the same, the request message #1 can only carry any one of the RSC#0 or the RSC#1.

[0391] It can be seen that the parameters in the request message #1 comprise the parameters provided by the remote UE and the parameters provided by the intermediate relay 1, i.e., the request message #1 carries the parameters corresponding to two communication apparatuses, in other words, the request message #1 carries the parameters corresponding to multiple communication apparatuses.

[0392] In a possible design, the order of the parameters corresponding to the multiple communication apparatuses in the request message #1 is determined according to a predefined order rule.

[0393] One possible example of the order rule is that the parameters corresponding to the n+1th communication apparatus are located after the identity corresponding to the nth communication apparatus, where the nth communication apparatus is the nth hop in the order (i.e., in the upstream order) starting from the remote UE among the N communication apparatuses. For example, the remote UE is the 1st hop, the intermediate relay 1 of the last hop of the remote UE is the 2nd hop, and so on. In other words, the parameters corresponding to the communication apparatuses are arranged in the request message #1 in the upstream order, i.e., in the order starting from the remote UE. The order rule is denoted as rule one for example. According to rule one, for the request message #1, the parameters corresponding to the communication apparatuses in the order determined according to the order rule in the request message #1 are, in sequence, the parameters corresponding to the remote UE and the parameters corresponding to the intermediate relay 1.

[0394] Another possible example of the ordering rule is that the parameter corresponding to the nth+1th communication apparatus is located before the parameter corresponding to the nth communication apparatus, where the nth communication apparatus is the nth hop in the ordering (i.e., in the upstream order) from the remote UE among the N communication apparatuses. For example, the remote UE is the 1st hop, the intermediate relay 1 of the previous hop of the remote UE is the 2nd hop, and so on. In other words, the parameters corresponding to the communication apparatuses are arranged in the request message #1 in the downstream order, i.e., sequentially ordered from the network device. This ordering rule is, for example, denoted as rule two. Based on rule two, for the request message #1, the parameters corresponding to the communication apparatuses determined based on the ordering rule are sequentially arranged in the request message #1 in the following order: the parameter corresponding to the intermediate relay 1, the parameter corresponding to the remote UE.

[0395] In another possible implementation, the parameters from the request message #0 can be carried in a container of the request message #1, or can be directly carried in the request message #1.

[0396] One example, the request message #1 carries: {the parameter corresponding to the remote UE}, the parameter of the intermediate relay 1, where the container is denoted by {}. That is, sequentially arranged in the upstream order, and the parameters from the request message #0 are carried in the container of the request message #1.

[0397] Another example, the request message #1 carries: the parameter of the intermediate relay 1, {the parameter corresponding to the remote UE}. That is, sequentially arranged in the downstream order, and the parameters from the request message #0 are carried in the container of the request message #1.

[0398] Yet another example, the request message #1 carries: the parameter corresponding to the remote UE, the parameter corresponding to the intermediate relay 1. That is, sequentially arranged in the upstream order, and the parameters from the request message #0 are directly carried in the request message #1.

[0399] Still another example, the request message #1 carries: the parameter corresponding to the intermediate relay 1, the parameter corresponding to the remote UE. That is, sequentially arranged in the downstream order, and the parameters from the request message #0 are directly carried in the request message #1.

[0400] In a possible design, the request message #1 is a DCR message. The DCR message includes the parameters for obtaining the security parameter group #0 and the parameters for obtaining the security parameter group #1.

[0401] As can be seen, the DCR message in the method 900 is different from the first DCR message, the second DCR message, and the third DCR message exemplified in the foregoing methods 600 and 800, and in fact, is also different from the DCR message in the prior art. The DCR message can carry the parameters corresponding to the plurality of communication apparatuses, for obtaining the plurality of security parameter groups, to protect the plurality of security connections.

[0402] It should be understood that in step 902 to step 903, the intermediate relay 1 is an example of the first communication device, the request message #0 is an example of the first message, and the request message #1 is an example of the second message. The first message at this time carries parameters corresponding to 1 (i.e., N = 1) communication devices (including the identifiers corresponding to the 1 communication devices), and the second message at this time carries parameters corresponding to 2 (i.e., N + 1 = 2) communication devices (including the identifiers corresponding to the 2 communication devices). Wherein, N represents the number of nodes downstream of the first communication device, and N is a positive integer.

[0403] Optionally, before step 903, the method further includes step 904: the intermediate relay 1 determines to be an intermediate relay in the multi-hop relay service.

[0404] As described above, the RSC #0 can be used to indicate the relay service. Since the intermediate relay 1 can determine itself to be an intermediate relay in the discovery process, in combination with the corresponding relationship between the RSC #0 and the relay service, the intermediate relay 1 can determine itself to be an intermediate relay in the multi-hop relay service.

[0405] The application does not limit the device to which the intermediate relay is applied. The intermediate relay 1 can be applied to a UE, so that the intermediate relay 1 can perform step 903 after determining itself to be an intermediate relay; the intermediate relay 1 can also be applied to a device dedicated to the relay service, so that the intermediate relay 1 can also directly perform step 903 after receiving the request message #0, without having to perform step 904.

[0406] In step 905, the intermediate relay 2 sends a request message #2 to the U2N relay, and the request message #2 carries the identifier corresponding to the remote UE, the identifier corresponding to the intermediate relay 1, and the identifier corresponding to the intermediate relay 2.

[0407] After receiving the request message #1, the intermediate relay 2 can perform similar operations as the intermediate relay 1, i.e., based on the parameters in the request message #1 and the parameters corresponding to itself, to construct another message, i.e., the request message #2, and send it to the previous hop. In this embodiment, the previous hop of the intermediate relay 2 is the U2N relay. For more detailed description of step 905, please refer to the related description of step 903, which will not be repeated here.

[0408] It can be understood that, since step 905, the intermediate relay 2 is an example of the first communication device, the intermediate relay 1 is an example of the second communication device, the U2N relay is an example of the third communication device, the request message #1 is an example of the first message, and the request message #2 is an example of the second message. At this time, the first message carries parameters corresponding to 2 (i.e., N = 2) communication devices (including the identifiers corresponding to the 2 communication devices), and the second message carries parameters corresponding to 3 (i.e., N + 1 = 3) communication devices (including the identifiers corresponding to the 3 communication devices).

[0409] In a possible design, the sorting rule of the parameters corresponding to the N + 1 communication devices in the second message is the same as the sorting rule of the parameters corresponding to the N communication devices in the first message.

[0410] An example of the sorting rule is that, in the first message, the parameter corresponding to the n + 1 communication device is located after the identifier corresponding to the n communication device; and in the second message, the identifier corresponding to the first communication device is located after the identifiers corresponding to the N communication devices in the first message, where the first communication device is the N + 1 hop. Here, the n communication device is the n hop in the sorting (i.e., in the upstream order) of the N communication devices from the remote UE. The sorting rule corresponds to the first rule in step 903.

[0411] Taking the remote UE, the intermediate relay 1, and the intermediate relay 2 in this embodiment as an example (i.e., N = 2 and N + 1 = 3), the parameters carried in the request message #1 (i.e., an example of the first message) are {the parameter corresponding to the remote UE}, and the parameter of the intermediate relay 1 in sequence; the parameters carried in the request message #2 (i.e., an example of the second message) are {the parameter corresponding to the remote UE}, {the parameter corresponding to the intermediate relay 1}, and the parameter corresponding to the intermediate relay 2 in sequence; or the parameters carried in the request message #1 (i.e., an example of the first message) are the parameter corresponding to the remote UE and the parameter of the intermediate relay 1 in sequence; and the parameters carried in the request message #2 (i.e., an example of the second message) are the parameter corresponding to the remote UE, the parameter corresponding to the intermediate relay 1, and the parameter corresponding to the intermediate relay 2 in sequence.

[0412] Another example of the sorting rule is that, in the first message, the parameter corresponding to the n + 1 communication device is located before the identifier corresponding to the n communication device; and in the second message, the identifier corresponding to the first communication device is located before the identifiers corresponding to the N communication devices in the first message, where the first communication device is the N + 1 hop. Here, the n communication device is the n hop in the sorting (i.e., in the upstream order) of the N communication devices from the remote UE. The sorting rule corresponds to the second rule in step 903.

[0413] Taking the remote UE, the intermediate relay 1 and the intermediate relay 2 in the embodiment as an example (i.e., N = 2, N + 1 = 3). The parameters carried in the request message #1 (i.e., an example of the first message) are in turn: the parameters corresponding to the intermediate relay 1, {the parameters corresponding to the remote UE}; the parameters carried in the request message #2 (i.e., an example of the second message) are in turn: the parameters corresponding to the intermediate relay 2, {the parameters corresponding to the intermediate relay 1}, {the parameters corresponding to the remote UE}; or, the parameters carried in the request message #1 (i.e., an example of the first message) are in turn: the parameters corresponding to the intermediate relay 1, the parameters corresponding to the remote UE; the parameters carried in the request message #2 (i.e., an example of the second message) are in turn: the parameters corresponding to the intermediate relay 2, the parameters corresponding to the intermediate relay 1, the parameters corresponding to the remote UE.

[0414] Table 2 below shows the arrangement of N communication devices in the first message and the arrangement of N + 1 communication devices in the second message under different rules:

[0415] Table 2

[0416] Based on the above ordering rules, each communication device receiving the request message can determine the relative positions of the nodes in each hop in the multi-hop relay service, thereby facilitating the acquisition of the security parameters corresponding to itself from the security parameters corresponding to multiple communication devices in the subsequent received forwarding of the upstream node.

[0417] In addition, in the embodiment, since the intermediate relay 2 is the next hop of the U2N relay, the U2N relay is an example of the fourth communication device, and the intermediate relay 2 is an example of the fifth communication device, the above request message #2 is an example of the fourth message. The fourth message carries the parameters (including the identifiers corresponding to the three communication devices) corresponding to the three communication devices (i.e., M = 3).

[0418] It can be understood that the request message #2 is an example of the fourth message, and the arrangement of the parameters corresponding to the N + 1 communication devices in the request message #2 itself satisfies the above rule one or rule two, so the arrangement of the parameters corresponding to the M communication devices in the fourth message also satisfies the rule one or rule two. It should be noted that the M communication devices refer to the number of downstream nodes of the U2N relay in the multi-hop relay service, which can be equal to the number of intermediate relays plus one, so M is a positive integer greater than 1.

[0419] It should also be understood that, since the request message #2 as an example of the fourth message is described in the embodiment with M = 3, from the perspective of the U2N relay, in the case of M being other values, the fourth message can also be other request messages, for example, the request message #M. In other words, the request message #2 is also an example of the request message #M.

[0420] Optionally, before step 905, the method further comprises step 906: the intermediate relay 2 determines itself as an intermediate relay in the multi-hop relay service.

[0421] Similar to step 904, since RSC#1 can be used to indicate relay service, the intermediate relay 2 can determine itself as an intermediate relay in the discovery procedure, and in combination with the correspondence between the RSC#1 and the relay service, the intermediate relay 2 can determine itself as an intermediate relay in the multi-hop relay service.

[0422] The application does not limit the device to which the intermediate relay is applied. The intermediate relay 1 can be applied to a UE, so that the intermediate relay 2 can perform step 905 after determining to perform step 906 to determine itself as an intermediate relay; the intermediate relay 2 can also be applied to a device dedicated to relay service, so that the intermediate relay 2 can directly perform step 905 after receiving the request message #1, without having to perform step 906.

[0423] In step 907, the U2N relay sends three key requests to the network device, and the three key requests carry the identifiers corresponding to the three communication devices. Correspondingly, the network device receives the three key requests from the U2N relay.

[0424] After receiving the fourth message, the U2N relay can obtain the parameters corresponding to the M communication devices (i.e., the M nodes downstream of the U2N relay) from the fourth message. The U2N relay can send M key requests to the network device through the U2N security connection previously established with the network device. The M key requests correspond one-to-one to the M communication devices. The M key requests carry the parameters corresponding to the M communication devices, including the identifiers corresponding to the M communication devices. Each key request carries the parameters corresponding to one communication device. The parameters corresponding to each communication device can be used to obtain a corresponding security parameter set for protecting the security connection between each communication device and its previous hop.

[0425] Taking the mth key request in the M key requests as an example, the mth key request corresponds to the mth communication device in the M communication devices, and carries the parameters corresponding to the mth communication device, which are used to obtain a security parameter set of the mth communication device for protecting the security connection between the mth communication device and its previous hop, i.e., the security connection #m.

[0426] It should be understood that in this embodiment, M is 3, so step 907 shows an example in which the U2N relay sends three key requests to the network device.

[0427] In step 908, the network device sends 3 key request replies to the U2N relay, and the 3 key request replies carry 3 security parameter groups. Correspondingly, the U2N relay receives the 3 key request replies from the network device.

[0428] The M key request replies can be replies to the M key requests. The M key request replies correspond to the M communication devices one by one. Each of the M key request replies carries a security parameter group, which can be used to protect the secure connection between the corresponding communication device and its previous hop.

[0429] Taking the mth key request reply in the M key request replies as an example, the mth key request corresponds to the mth communication device in the M communication devices, and the mth key request carries the security parameter group corresponding to the mth communication device, which is used to protect the secure connection between the mth communication device and its previous hop, i.e., the secure connection #m.

[0430] In this embodiment, the above-mentioned M security parameter groups include three security parameter groups corresponding to the intermediate relay 2, the intermediate relay 1 and the remote UE respectively. Each security parameter group includes a root key (K NR_ProSe ) and a random number 2 (Nonce_2), or includes a root key (K NPR ) and a random number 2 (K NRP freshness parameter 2).

[0431] It should be understood that in this embodiment, M is 3, so step 908 shows an example in which the network device sends 3 key request replies.

[0432] It should be noted that since different UEs correspond to different HPLMNs, after the U2N relay sends the M key requests to the network device, the network device can obtain the corresponding security parameter groups by interacting with the network element in the HPLMN of each UE. For specific obtaining steps, please refer to steps 35 to 312 in the CP scheme of FIG. 3 and steps 44b to 44e in the UP scheme of FIG. 4, which will not be described here. It can be understood that in different security establishment schemes, the above-mentioned network device can refer to different network elements in the HPLMN or the serving PLMN of the U2N relay, which is not limited in the present application.

[0433] Since FIG. 10 and FIG. 11 below show two different implementations for steps 907 and 908, the implementation process of steps 907 and 908 will not be described here.

[0434] Optionally, after step 905 and before step 907, the method further includes step 909: the U2N relay determines to request security parameters for the plurality of communication devices.

[0435] After receiving the fourth message in step 905, the U2N relay can determine that the fourth message is used to request security parameters for the M communication devices according to the parameters corresponding to the M communication devices carried in the fourth message.

[0436] The U2N relay can also be pre-configured as the U2N relay in the multi-hop relay service, in which case, the U2N relay can not need to perform step 909, but directly perform step 907 and the subsequent steps.

[0437] In step 910, the U2N relay sends the security parameter #2 to the intermediate relay 2. Accordingly, the intermediate relay 2 receives the security parameter #2 from the U2N relay.

[0438] The security parameter #2 is a random number 2 (Nonce_2 or K NRP freshness parameter 2) in the security parameter group #2 corresponding to the intermediate relay 2. The random number 2 can be used to protect the security connection #2 (i.e., an example of the first security connection) between the intermediate relay 2 and the U2N relay. The intermediate relay 2 can generate a session key for protecting the security connection #2 based on the received random number 2 and a locally generated root key (K NR_ProSe or K NPR ).

[0439] In step 910, the intermediate relay 2 is an example of the first communication device, which protects the security connection #2 based on the received security parameter #2, which is an example of the first security parameter, and the security connection #2 is an example of the first security connection.

[0440] On the other hand, the U2N relay can generate a session key for protecting the security connection #2 based on a root key (K NR_ProSe or K NRP ) in the security parameter group #2 corresponding to the intermediate relay 2.

[0441] Thus, the security connection #2 between the U2N relay and the intermediate relay 2 is established. The U2N relay and the intermediate relay 2 can protect when communicating through the security connection #2 based on the session key.

[0442] It should also be understood that the security connection #2 is described from the perspective of the position of the intermediate relay 2 in the multi-hop relay service. Since M = 3 is taken as an example in the embodiment, from the perspective of the U2N relay, the security connection #2 can also be replaced by the security connection #M in the case of other values of M.

[0443] In step 911, the U2N relay sends a reply message #2 to the intermediate relay 2 through the secure connection #2, and the reply message #2 carries 2 security parameter sets. Correspondingly, the intermediate relay 2 receives the reply message #2 from the U2N relay.

[0444] The reply message #2 is a reply message corresponding to the request message #2 in the foregoing step 905. The reply message #2 carries 2 security parameter sets, which are respectively based on the parameters corresponding to the remote UE and the parameters corresponding to the intermediate relay 1, and are respectively used to protect the secure connection #0 between the remote UE and the intermediate relay 1 and the secure connection #1 between the intermediate relay 1 and the intermediate relay 2.

[0445] It can be understood that in step 911, the intermediate relay 2 is an example of the first communication device, and the reply message #2 received by the intermediate relay 2 is an example of the third message, which carries 2 (N=2) security parameter sets. The 2 security parameter sets can be used to protect 2 secure connections between 2 nodes downstream of the intermediate relay 2 and the intermediate relay 2, that is, the secure connection #1 between the intermediate relay 2 and the intermediate relay 1 and the secure connection #0 between the intermediate relay 1 and the remote UE.

[0446] As described above, the request message #2 is also an example of the request message #M, and correspondingly, the reply message #2 is also an example of the reply message #M. From the perspective of the U2N relay, in the case where M is other values, the reply message #2 can be replaced by the reply message #M, which carries M security parameter sets.

[0447] In this embodiment, since the intermediate relay 2 is the next hop of the U2N relay, and the U2N relay is an example of the fourth communication device, the intermediate relay 2 is also an example of the fifth communication device, and the above-mentioned reply message #2 is also an example of the fifth message. The fifth message carries 2 (that is, M-1=2) security parameter sets.

[0448] Since the intermediate relay 2 receives 2 security parameter sets, the intermediate relay 2 can obtain the root key (K NR_ProSe or K NRP ) in the security parameter set #1 for protecting the secure connection #1 from the 2 security parameter sets, and further generate a session key for protecting the secure connection #1. Therefore, the intermediate relay 2 needs to be able to identify the security parameter set #1 in the 2 security parameter sets.

[0449] In one possible design, the ordering rule of the M security parameter groups in the fifth message is the same as that of the M communication devices' corresponding parameters (including the identities) in the fourth message. Alternatively, for any intermediate relay after the intermediate relay 2, the ordering rule of the N security parameter groups in the third message is the same as that of the N communication devices' corresponding parameters (including the identities) in the second message.

[0450] That is, the correspondence between each security parameter group and each communication device or each security connection is implicitly indicated by the ordering rule of the M security parameter groups. For example, if the ordering rule of the M communication devices' corresponding parameters (including the identities) in the fourth message is rule two, and the ordering rule of the M security parameter groups in the fifth message is also rule two, then the intermediate relay 2 can determine that the leftmost security parameter group in the fourth message is the security parameter group #1.

[0451] In another possible design, the fifth message also carries the M communication devices' corresponding identities, one-to-one corresponding to the M security parameter groups. Each security parameter group can be marked by the corresponding communication device's corresponding identity, so that the intermediate relay 2 can determine the security parameter group #1 from the two security parameter groups in the fifth message according to the intermediate relay 1's corresponding identity.

[0452] In step 912, the intermediate relay 2 sends the security parameter #2 to the intermediate relay 1, and accordingly, the intermediate relay 1 receives the security parameter #2 of the intermediate relay 2.

[0453] The security parameter #1 is a random number 2 (Nonce_2 or K NRP freshness parameter 2) in the security parameter group #1 based on the intermediate relay 1's corresponding parameters. The random number 2 can be used to protect the security connection #1 between the intermediate relay 1 and the intermediate relay 2. The intermediate relay 1 can generate a session key for protecting the security connection #1 based on the received random number 2 and a locally generated root key (K NR_ProSe or K NPR ).

[0454] In step 912, the intermediate relay 1 is an example of the first communication device, which protects the security connection #1 based on the received security parameter #1, which is another example of the first security parameter, and the security connection #1 is another example of the first security connection.

[0455] On the other hand, the intermediate relay 2 can generate a session key for protecting the security connection #1 based on the root key (K NR_ProSe or K NRP ) in the security parameter group #1 corresponding to the intermediate relay 1.

[0456] Thus, the secure connection #1 between the intermediate relay 1 and the intermediate relay 2 is established. The intermediate relay 2 and the intermediate relay 1 can protect when communicating via the secure connection #1 based on the session key.

[0457] In step 913, the intermediate relay 2 sends a reply message #1 to the intermediate relay 1 via the secure connection #1, and the reply message #1 carries one security parameter set. Accordingly, the intermediate relay 1 receives the reply message #1 from the intermediate relay 2.

[0458] The reply message #1 is a reply message corresponding to the request message #1 in the previous step 905. The reply message #2 carries one security parameter set, which is obtained based on the parameters corresponding to the remote UE, and is used to protect the secure connection #0 between the remote UE and the intermediate relay 1.

[0459] In step 914, the intermediate relay 1 sends the security parameter #0 to the remote UE. Accordingly, the remote UE receives the security parameter #0 from the intermediate relay 1.

[0460] The security parameter #0 is the random number 2 (Nonce_2 or K NRP freshness parameter 2) in the security parameter set #0 obtained based on the parameters corresponding to the remote UE. The random number 2 can be used to protect the secure connection #0 between the remote UE and the intermediate relay 1. The remote UE can generate a session key for protecting the secure connection #1 based on the received random number 2 and the locally generated root key (K NR_ProSe or K NPR ).

[0461] On the other hand, the intermediate relay 1 can generate a session key for protecting the secure connection #0 based on the root key (K NR_ProSe or K NRP ) in the security parameter set #0 corresponding to the remote UE.

[0462] Thus, the secure connection #0 between the intermediate relay 1 and the remote UE is established. The intermediate relay 1 and the remote UE can protect when communicating via the secure connection #0 based on the session key.

[0463] In step 907, after receiving the fourth message, the U2N relay can obtain the parameters corresponding to the M communication devices (i.e., the M nodes downstream of the U2N relay) from the fourth message. In order to obtain the corresponding security parameter set for different communication devices, the U2N relay can use different implementation manners to perform step 907.

[0464] The two different implementation manners will be described below in combination with FIG. 10 and FIG. 11.

[0465] In a first possible implementation, the U2N relay can assign a number to each of the parameters corresponding to the M communication devices, each number corresponding to a key request, and each number being carried in the corresponding key request for identifying the corresponding key request. Therefore, the M key requests sent by the U2N in step 907 can carry M numbers. The network device can also carry the corresponding numbers in the M key request replies for the M key requests based on the numbers carried in the M key requests respectively, so as to distinguish the security parameter groups corresponding to different communication devices.

[0466] Exemplarily, FIG. 10 shows the flow of this implementation when M is 3. The flow can include the following steps:

[0467] Step 9070: The U2N relay assigns a number to each of the identifiers corresponding to the M communication devices, or assigns a number to each of the key requests corresponding to the M communication devices. It should be noted that the numbers assigned by the U2N relay to the identifiers corresponding to different communication devices or to the key requests corresponding to different communication devices are different.

[0468] Exemplarily, the number assigned by the U2N relay can be a transaction ID.

[0469] Step 9071: The U2N relay sends a key request #0 to the network device, and the key request #0 carries the identifier corresponding to the remote UE and the number 0.

[0470] Step 9072: The U2N relay sends a key request #1 to the network device, and the key request #1 carries the identifier corresponding to the remote UE and the number 1.

[0471] Step 9073: The U2N relay sends a key request #2 to the network device, and the key request #2 carries the identifier corresponding to the remote UE and the number 2.

[0472] Step 9081: The network device sends a key request reply #0 to the U2N relay, and the key request reply #0 carries the security parameter group #0 and the number #0.

[0473] Step 9082: The network device sends a key request reply #1 to the U2N relay, and the key request reply #1 carries the security parameter group #1 and the number #1.

[0474] Step 9083: The network device sends a key request reply #2 to the U2N relay, and the key request reply #2 carries the security parameter group #2 and the number #2.

[0475] In step 9070, the U2N relay can assign a number to the parameter corresponding to each of the M communication devices according to the order of the parameter (including the identifier) in the fourth message. The number assigned to the key request #m in the M key requests is determined by m, which can be m, or a value obtained by performing mathematical transformation on m, and the mathematical transformation can include at least one or more of the following linear transformations: adding an arbitrary value, subtracting an arbitrary value, multiplying an arbitrary value, or dividing an arbitrary value. As long as the M numbers obtained by performing mathematical transformation on different values of m are different, the M numbers are different. Wherein, m can represent the mth hop of the M communication devices in the multi-hop relay service starting from the remote UE (i.e., in the upstream direction), or the mth hop of the M communication devices in the multi-hop relay service starting from the next hop of the U2N relay (i.e., in the downstream direction). The number carried in the key request #m in the M key requests is the same as the number carried in the key request reply #m in the M key request reply.

[0476] Steps 9071, 9072, and 9073 can be executed synchronously or asynchronously, and the present application does not limit this.

[0477] Steps 9081, 9082, and 9083 can be executed synchronously or asynchronously, and the present application does not limit this. It can be understood that step 9081 is executed after step 9071, step 9082 is executed after step 9072, and step 9083 is executed after step 9073.

[0478] It should be understood that in the above-mentioned steps 9071 to 9073 and steps 9081 to 9083, the number carried in the key request #m and the key request reply #m is m, as described above, which can be replaced by other values determined by m, which will not be listed.

[0479] In addition, since M can be other values, the implementation process of the above implementation mode can further include more steps, for example, it can include M key request sending steps and M key request reply receiving steps, and the specific implementation details can be referred to the above, and will not be repeated. The M key request sending steps can be executed synchronously or asynchronously, and the present application does not limit this. It can be understood that the synchronous execution of the M key request sending steps can enable the network device to obtain M security parameter groups for M communication devices in parallel, thereby improving the efficiency of establishing a secure connection.

[0480] In the second possible implementation, the M key requests are sent in sequence in ascending order of m, where m can represent the mth hop of the M communication devices in the multi-hop relay service starting from the remote UE (i.e., in the upstream direction) or the mth hop of the M communication devices in the multi-hop relay service starting from the next hop of the U2N relay (i.e., in the downstream direction).

[0481] Exemplarily, FIG. 11 shows a possible flow of this implementation. The flow includes the following steps:

[0482] At step 9074, the U2N relay sends a key request #0 to the network device, where the key request #0 carries an identifier corresponding to the remote UE.

[0483] At step 9084, the network device sends a key request reply #0 to the U2N relay, where the key request reply #0 carries a security parameter group #0.

[0484] At step 9075, the U2N relay sends a key request #1 to the network device, where the key request #1 carries an identifier corresponding to the remote UE.

[0485] At step 9085, the network device sends a key request reply #1 to the U2N relay, where the key request reply #1 carries a security parameter group #1.

[0486] At step 9076, the U2N relay sends a key request #2 to the network device, where the key request #2 carries an identifier corresponding to the remote UE.

[0487] At step 9086, the network device sends a key request reply #2 to the U2N relay, where the key request reply #2 carries a security parameter group #2.

[0488] Different from the first implementation, the steps 9074, 9084, 9075, 9085, 9076 and 9086 in the second implementation are executed in sequence, and in this embodiment, step 9075 is executed after step 9084; step 9076 is executed after step 9085, while step 9084 itself is executed after step 9074, step 9085 itself is executed after step 9075, and step 9086 itself is executed after step 9076, so the above-mentioned steps are executed in sequence in ascending order of m, with one key request sent and one key request reply received as a group. In other words, steps 907 and 908 can also be replaced by that the U2N relay obtains M security parameter groups from the network device in sequence in ascending order of m.

[0489] It should be understood that the steps 9074, 9075, 9076 and the steps 9084, 9085, 9086 exemplified above are all based on the assumption that m represents the mth hop in the multi-hop relay service starting from the next hop of the U2N relay (i.e., in the downstream direction). If the mth hop in the multi-hop relay service starts from the remote UE (i.e., in the upstream direction), the execution order of the above steps is as follows: first, steps 9076 and 9086 are executed, then steps 9075 and 9085 are executed, and finally, steps 9074 and 9084 are executed.

[0490] It should also be understood that the two implementations shown in FIGS. 10 and 11 are only examples, and the two implementations can also be used alone or in combination. For example, after steps 9074 and 9084 are executed, steps 9075 and 9076 are executed in parallel. At this time, the key requests in steps 9075 and 9085 can be distinguished by the aforementioned numbering, and the network device carries the same number in the corresponding key request reply based on the number in each key request. The specific implementation process can be referred to the description above, and will not be repeated here.

[0491] Based on the above technical solutions, in the multi-hop relay service, each intermediate relay can carry its own parameters (i.e., parameters for obtaining security parameters, such as but not limited to the identifier corresponding to the UE, etc.) and the parameters from the next hop in the same request message to request multiple security parameter groups through the same request message when receiving the request message from the next hop for requesting security parameters. The U2N relay can request security parameter groups for each node downstream according to the received request message, and obtain and forward the security parameter groups for each node downstream in turn after establishing the secure connection between the U2N relay and the next hop. In this way, each intermediate relay in the downstream direction can first protect the secure connection between it and the next hop based on the received security parameter group, and then obtain and forward the security parameters for the downstream nodes through the secure connection. In this way, the secure connection between each two-hop adjacent nodes in the multi-hop relay service can be established in turn in the downstream direction, and the remote UE can securely communicate with the network device. Moreover, multiple security parameter groups that can be used to protect multiple secure connections are requested through the same request message, so that the establishment of the secure connection is more efficient.

[0492] The above describes in detail the method provided by the embodiments of the present application in combination with FIGS. 6 to 11. The following describes in detail the apparatus provided by the embodiments of the present application in combination with the accompanying drawings.

[0493] FIG. 12 to FIG. 13 are schematic block diagrams of possible communication devices provided by embodiments of the present application. These communication devices can be used to implement the functions of the first communication device (e.g., an intermediate relay) or the fourth communication device (e.g., a U2N relay) in the above-mentioned method embodiments, and thus can also achieve the beneficial effects possessed by the above-mentioned method embodiments.

[0494] In embodiments of the present application, the communication device can be an intermediate relay or a U2N relay in the method embodiments shown in FIG. 6 to FIG. 11, or can be a component (e.g., a chip, a chip system, a processor, etc.) configured in the intermediate relay or the U2N relay, or can be a logic module or software capable of implementing part or all of the functions of the intermediate relay or the U2N relay.

[0495] One of the communication devices provided by the present application is shown in FIG. 12. The communication device 1200 includes a transceiver unit 1210. Optionally, the communication device 1200 further includes a processing unit 1220.

[0496] One possible design is that the communication device 1200 is used to implement the functions of the intermediate relay in the above-mentioned method embodiments shown in FIG. 6 to FIG. 11.

[0497] In one embodiment, the transceiver unit 1210 can be used to: receive a first request message from a second communication device, the first request message carrying an identity corresponding to the second communication device; send a second request message to a third communication device, the third communication device being an intermediate relay or a user equipment (UE) to network (U2N) relay, the second request message carrying an identity corresponding to the first communication device; receive a first security parameter from the third communication device, the first security parameter being obtained based on the identity corresponding to the first communication device, the first security parameter being used to protect a first secure connection between the third communication device and the first communication device; and send the identity corresponding to the second communication device through the first secure connection, and receive a second security parameter from the third communication device, the second security parameter being obtained based on the identity corresponding to the second communication device, the second security parameter being used to protect a second secure connection between the first communication device and the second communication device.

[0498] Optionally, the transceiver unit 1210 can also be used to send the second security parameter to the second communication device.

[0499] Optionally, the processing unit 1220 can be used to determine that the first communication device is an intermediate relay in the relay service.

[0500] Optionally, the processing unit 1220 can also be used to cache the first request message.

[0501] More details of the transceiver unit 1210 and the processing unit 1220 can be found in the description of the intermediate relay in the method embodiments shown in FIGS. 6-8, which are incorporated herein by reference.

[0502] In another embodiment, the transceiver unit 1210 can be configured to receive a first message from a second communication device, the first message carrying identities of N communication devices, the N communication devices including the second communication device, N being a positive integer; send a second message to a third communication device, the second message carrying identities of N+1 communication devices, the N+1 communication devices including the N communication devices and the first communication device; receive a first security parameter from the third communication device, the first security parameter being based on the identity of the first communication device, the first security parameter being used to protect a first secure connection between the first communication device and the third communication device; and receive a third message from the third communication device via the first secure connection, the third message carrying N security parameter sets corresponding to the N communication devices, the N security parameter sets being based on the identities of the N communication devices, the N security parameter sets being used to protect secure connections among the N+1 communication devices.

[0503] More details of the transceiver unit 1210 and the processing unit 1220 can be found in the description of the intermediate relay in the method embodiments shown in FIGS. 9-11, which are incorporated herein by reference.

[0504] In another possible design, the communication device 1200 can be configured to implement the functions of the U2N relay in the method embodiments shown in FIGS. 6-11.

[0505] In one embodiment, the transceiver unit 1210 can be configured to receive a first security parameter set from the network device, the first security parameter set being used to protect a third secure connection between the fourth communication device and a fifth communication device; receive a second security parameter set from the network device, the second security parameter set being used to protect a fourth secure connection between the fifth communication device and a sixth communication device; and send the second security parameter set to the fifth communication device via the third secure connection.

[0506] Optionally, the transceiver unit 1210 can be further configured to receive an identity of the sixth communication device from the fifth communication device via the third secure connection; and send a key request to the network device, the key request carrying the identity of the sixth communication device.

[0507] Optionally, the processing unit 1220 can be configured to determine to forward the second security parameter set via the third secure connection.

[0508] More detailed description of the transceiver unit 1210 and the processing unit 1220 can be directly obtained by referring to the description of the U2N relay in the method embodiments shown in FIGS. 6-8, which will not be repeated here.

[0509] In another embodiment, the transceiver unit 1210 can be configured to receive a fourth message carrying the identities of the M communication devices, where M is a positive integer greater than 1; send M key requests to the network device via a secure connection between the fourth communication device and the network device, and receive M key request replies; the M key requests carry the identities of the M communication devices, and the M key request replies carry M security parameter sets corresponding to the M communication devices, which are obtained based on the identities of the M communication devices, and are used for secure connection between M+1 communication devices including the M communication devices and the fourth communication device.

[0510] Optionally, when sending the M key requests, the transceiver unit 1210 is configured to send the M key requests in ascending order of m, where m represents the mth hop of the M communication devices in an upstream direction, or the mth hop of the M communication devices in a downstream direction.

[0511] Optionally, the transceiver unit 1210 can also be configured to send a security parameter corresponding to the fifth communication device to the fifth communication device, where the security parameter is used to protect the secure connection between the fifth communication device and the fourth communication device; and send a fifth message via the secure connection, where the fourth message carries M-1 security parameter sets, which are the security parameter sets in the M security parameter sets except for the security parameter set corresponding to the fifth communication device.

[0512] More detailed description of the transceiver unit 1210 and the processing unit 1220 can be directly obtained by referring to the description of the U2N relay in the method embodiments shown in FIGS. 9-11, which will not be repeated here.

[0513] It should be noted that the transceiver unit can also be referred to as a transceiver module, a transceiver, a transceiver device, or the like. The processing unit can also be referred to as a processor, a processing board, a processing module, or the like. Optionally, the transceiver unit is configured to perform the sending and receiving operations of the intermediate relay or the U2N relay in the above methods, and the devices in the communication module for implementing the receiving function can be regarded as a receiving unit, and the devices in the communication module for implementing the sending function can be regarded as a sending unit, i.e., the transceiver unit includes a receiving unit and a sending unit.

[0514] It should be noted that in a possible design, the foregoing transceiver unit and / or processing unit can be implemented by a virtual module, for example, the processing unit can be implemented by a software function unit or a virtual device, and the transceiver unit can be implemented by a software function or a virtual device. In another possible design, the processing unit or the transceiver unit can also be implemented by a physical device, for example, if the device is implemented by a chip / chip circuit, the transceiver unit can be an input / output circuit and / or a communication interface, which performs an input operation (corresponding to the foregoing receiving operation) and an output operation (corresponding to the foregoing sending operation); and the processing unit is an integrated processor or a microprocessor or an integrated circuit.

[0515] The division of units in the embodiments of the present application is illustrative, and is merely a logical function division. In actual implementation, another division manner can be used. In addition, each function module in each example in the embodiments of the present application can be integrated in one processor, or can be physically separated, or two or more modules can be integrated in one module. The integrated module can be implemented in the form of hardware or in the form of a software function module.

[0516] Another communication device provided in the present application is shown in FIG. 13. The communication device 1300 includes at least one processor 1310. The at least one processor 1310 can be used to execute computer programs or instructions in the memory, to implement the steps performed by each intermediate relay or the steps performed by the U2N relay in the method embodiments shown in FIGS. 9 to 11.

[0517] Optionally, the communication device 1300 can further include at least one memory 1320, used to store instructions executed by the processor 1310 or to store input data required by the processor 1310 to run instructions or to store data generated after the processor 1310 runs instructions. The at least one processor 1310 and the at least one memory 1320 can be separately arranged. For example, each memory can be connected with one or more processors, so that the connected processor can read information from the memory, store and / or write information in the memory. Alternatively, the at least one processor 1310 and the at least one memory 1320 can be integrated together, for example, one or more memories can be integrated in one processor.

[0518] Optionally, the communication device 1300 further includes an interface circuit 1330, which can be used to transmit data and / or signaling. The at least one processor 1310 and the interface circuit 1330 are mutually coupled. It can be understood that the interface circuit 1330 can be a transceiver, an input / output circuit, a bus, a module, a pin or other types of communication interfaces, wherein the input circuit in the input / output circuit can be used for receiving, and the output interface can be used for sending.

[0519] When the communication apparatus 1300 is used to implement the methods shown in FIGS. 6-11, the processor 1313 is configured to perform the functions of the processing units described above, and the interface circuit 1330 is configured to perform the functions of the transceiving units described above. The interface circuit 1330 is configured to transmit or receive, depending on whether the communication apparatus 1300 is performing a scheme in which the transmitting action or the receiving action is performed.

[0520] It can be understood that when the communication apparatus 1300 is a communication device (such as an intermediate relay or a U2N relay), the interface circuit 1330 can be a transceiver, which can specifically include a transmitter and a receiver, the transmitter being configured to transmit signals, and the receiver being configured to receive signals. When the communication apparatus 1300 is a chip applied to a communication device, the interface circuit 1330 can be an input / output circuit, a bus, a module, a pin, or other types of communication interfaces, wherein the input circuit in the input / output circuit can be configured to receive, and the output interface can be configured to transmit.

[0521] It should be understood that in the communication apparatus 1300 shown in FIG. 13, the processor 1310 can correspond to the processing unit 1220 in the communication apparatus 1200 described above, and the interface circuit 1330 can correspond to the transceiving unit 1210 in the communication apparatus 1200 described above.

[0522] It should also be understood that the coupling in the embodiments of the present application is an indirect coupling or communication connection between devices, units or modules, which can be electrical, mechanical or other forms, for information interaction between devices, units or modules. The specific connection medium between the at least one processor 1310, the at least one memory 1320, the interface circuit 1330 and the power supply circuit 1340 in the embodiments of the present application is not limited. In FIG. 13, the processor 1310, the memory 1320, the interface circuit 1330 and the power supply circuit 1340 are connected through the bus 1350. The bus 1350 is represented by a thick line in FIG. 13, and the connection mode between other components is only schematically illustrated and is not limited. The bus can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For convenience of representation, only one thick line is used to represent the bus in FIG. 13, but it does not mean that there is only one bus or only one type of bus.

[0523] It can be appreciated that the processor in the embodiments of the present application can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.

[0524] The memory in the embodiments of the present application can be a volatile memory or a nonvolatile memory, or can include both volatile and nonvolatile memory. Among them, the nonvolatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically EPROM (EEPROM) or a flash memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example, and not limitation, many forms of RAM can be used, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM) and direct rambus RAM (DR RAM). It should be noted that the memory of the system and method described herein is intended to include, but not be limited to, these and any other suitable types of memory.

[0525] The present application also provides a communication system, which includes a remote UE, at least one intermediate relay, a U2N relay and a network device.

[0526] The application further provides a computer program product, which comprises a computer program (also referred to as code or instruction), which, when executed, causes a computer to perform the method executed by each intermediate relay or the method executed by the U2N relay in the embodiments shown in FIG. 9 to FIG. 11.

[0527] The application further provides a computer readable storage medium, which stores a computer program (also referred to as code or instruction). When the computer program is executed, it causes a computer to perform the method executed by each intermediate relay or the method executed by the U2N relay in the embodiments shown in FIG. 9 to FIG. 11.

[0528] The terms "unit", "module" and the like used in the specification can be used to represent computer-related entities, hardware, combinations of hardware and software, software, or software in execution.

[0529] Those of ordinary skill in the art can realize that the various illustrative logical blocks and steps described in connection with the embodiments disclosed herein can be implemented or performed with electronic hardware, or a combination of computer software and electronic hardware. The choice of hardware or software implementation depends on the specific application and design constraints of the technical solution. A skilled person can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the application. In several embodiments provided in the application, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the above-described device embodiments are only illustrative, for example, the division of the unit is only a logical functional division, and actual implementation can have another division, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0530] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, i.e. they can be located in one place or distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.

[0531] In addition, the functional units in each embodiment of the application can be integrated into one processing unit, or each unit can exist physically, or two or more units can be integrated into one unit.

[0532] In the above embodiments, the functions of the various functional units can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented in software, the functions can be implemented in the form of one or more computer programs that run on a computer. When the computer programs are loaded and executed on the computer, the whole or part of the flow or function described in the embodiments of the present application is produced. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable apparatus. The computer programs can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer programs can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server, data center, etc. that includes one or more available media sets. The available medium can be a magnetic medium (for example, floppy disk, hard disk, magnetic tape), an optical medium (for example, digital video disc (DVD)), or a semiconductor medium (for example, solid state disk (SSD)) and the like.

[0533] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, ROM, RAM, magnetic disk or optical disk, and various media that can store program codes.

[0534] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for establishing a secure connection, characterized by, The method applied to a first communication device comprises: receiving a first request message from a second communication device, the first request message carrying an identity corresponding to the second communication device; sending a second request message to a third communication device, the third communication device being an intermediate relay or a user equipment (UE) to network (U2N) relay, the second request message carrying an identity corresponding to the first communication device; receiving a first security parameter from the third communication device, the first security parameter being derived based on the identity corresponding to the first communication device, the first security parameter being used to protect a first secure connection between the third communication device and the first communication device; sending the identity corresponding to the second communication device through the first secure connection and receiving a second security parameter from the third communication device, the second security parameter being derived based on the identity corresponding to the second communication device, the second security parameter being used to protect a second secure connection between the first communication device and the second communication device.

2. The method of claim 1, wherein, The method further comprises: sending the second security parameter to the second communication device.

3. The method according to claim 1 or 2, c h a r a c t e r i z e d in that, The first request message further carries a relay service code (RSC), the RSC being used to indicate a relay service; and Before the sending of the second request message to the third communication device, the method further comprises: based on the RSC, determining that the first communication device is an intermediate relay in the relay service.

4. The method of any one of claims 1 to 3, wherein, The first security parameter comprises a random number corresponding to the first secure connection, the random number corresponding to the first secure connection being used to derive a first session key, the first session key being used to protect the first secure connection; The second security parameter comprises a random number corresponding to the second secure connection, the random number corresponding to the second secure connection being used to derive a second session key, the second session key being used to protect the first secure connection.

5. The method of any one of claims 1 to 4, wherein, The second request message is sent after the receiving of the first request message.

6. The method of claim 5, wherein, The method further comprises: buffering the first request message.

7. The method of any one of claims 1 to 6, wherein, The identity corresponding to the second communication device sent through the first secure connection is carried in an intermediate key request message, and the second security parameter received through the first secure connection is carried in an intermediate key reply message; or The identity corresponding to the second communication device sent through the first secure connection is carried in a direct communication request message, and the second security parameter received through the first secure connection is carried in a direct communication consent message; or The identity corresponding to the second communication device sent through the first secure connection and the second security parameter received through the first secure connection are both carried in a control plane message of a PC5 link, or The identity corresponding to the second communication device sent through the first secure connection and the second security parameter received through the first secure connection are both carried in a user plane message of a PC5 link.

8. A method for establishing a secure connection, characterized by, The method applied to a fourth communication device comprises: receiving a first security parameter set from a network device, the first security parameter set being used to protect a third secure connection between the fourth communication apparatus and a fifth communication apparatus; receiving a second security parameter set from the network device, the second security parameter set being used to protect a fourth secure connection between the fifth communication apparatus and a sixth communication apparatus; sending the second security parameter set to the fifth communication apparatus through the third secure connection.

9. The method of claim 8, wherein, The second security parameter set is obtained based on an identity of the sixth communication apparatus; the method further comprises: receiving the identity of the sixth communication apparatus from the fifth communication apparatus through the third secure connection; sending a key request to the network device, the key request carrying the identity of the sixth communication apparatus.

10. The method of claim 9, wherein, The identity of the sixth communication apparatus from the fifth communication apparatus is carried in an intermediate key request message, and the second security parameter set sent to the fifth communication apparatus is carried in an intermediate key reply message; Or The identity of the sixth communication apparatus from the fifth communication apparatus is carried in a direct communication request message, and the second security parameter set sent to the fifth communication apparatus is carried in a direct communication agreement message; Or The identity of the sixth communication apparatus from the fifth communication apparatus and the second security parameter set sent to the fifth communication apparatus are both carried in a control plane message of a PC5 link, or The identity of the sixth communication apparatus from the fifth communication apparatus and the second security parameter set sent to the fifth communication apparatus are both carried in a user plane message of a PC5 link.

11. The method of any one of claims 8 to 10, wherein, Before the step of sending the second security parameter set to the fifth communication apparatus through the third secure connection, the method further comprises: determining to forward the second security parameter set through the third secure connection.

12. The method of any one of claims 8 to 11, wherein, The first security parameter set comprises a root key and a random number corresponding to the third secure connection, and the second security parameter set comprises a root key and a random number corresponding to the fourth secure connection.

13. A method for establishing a secure connection, characterized by The method applied to a first communication apparatus, the method comprises: receiving a first message from a second communication apparatus, the first message carrying identities of N communication apparatuses, the N communication apparatuses including the second communication apparatus, N being a positive integer; sending a second message to a third communication apparatus, the second message carrying identities of N+1 communication apparatuses, the N+1 communication apparatuses including the N communication apparatuses and the first communication apparatus; receiving a first security parameter from the third communication apparatus, the first security parameter being obtained based on the identity of the first communication apparatus, the first security parameter being used to protect a first secure connection between the first communication apparatus and the third communication apparatus; The third message is received from the third communication device through the first secure connection, and the third message carries N security parameter groups corresponding to the N communication devices, the N security parameter groups are obtained based on the identifiers corresponding to the N communication devices, and the N security parameter groups are used to protect the secure connection between the N+1 communication devices.

14. The method of claim 13, wherein, The sorting rule of the identifiers corresponding to the N+1 communication devices in the second message is the same as the sorting rule of the identifiers corresponding to the N communication devices in the first message.

15. The method of claim 14, wherein, The sorting rule of the N security parameter groups in the third message is the same as the sorting rule of the identifiers corresponding to the N+1 communication devices in the second message.

16. A method for establishing a secure connection, characterized by The method is applied to a fourth communication device, and the method comprises: A fourth message is received, and the fourth message carries identifiers corresponding to M communication devices; M is a positive integer greater than 1; M key requests are sent through a secure connection between the fourth communication device and a network device, and M key request replies are received; the M key requests carry the identifiers corresponding to the M communication devices, and the M key request replies carry M security parameter groups corresponding to the M communication devices, the M security parameter groups are obtained based on the identifiers corresponding to the M communication devices, and the M security parameter groups are used to protect secure connections between M+1 communication devices, the M+1 communication devices including the M communication devices and the fourth communication device.

17. The method of claim 16, wherein, The same number is carried in the mth key request in the M key requests and the mth key request reply in the M key request replies, and the same number is determined based on m, m representing the mth hop in an upstream direction of the M communication devices or the mth hop in a downstream direction of the M communication devices; the M numbers carried in the M key requests are different from each other.

18. The method of claim 16 or 17, wherein, The M key requests are sent in the following manner: The M key requests are sent in an order from small to large of m, m representing the mth hop in an upstream direction of the M communication devices or the mth hop in a downstream direction of the M communication devices.

19. The method of any one of claims 16 to 18, wherein, The method further comprises: A security parameter corresponding to a fifth communication device is sent to the fifth communication device, and the security parameter corresponding to the fifth communication device is used to protect a secure connection between the fifth communication device and the fourth communication device; A fifth message is sent through the secure connection, and the fourth message carries M-1 security parameter groups, the M-1 security parameter groups being security parameter groups in the M security parameter groups except for a security parameter group corresponding to the fifth communication device.

20. The method of claim 19, wherein, The sorting rule of the M-1 security parameter groups in the fifth message is the same as the sorting rule of the identifiers corresponding to the M communication devices in the fourth message.

21. A communications device, characterized by One or more functional units are included to implement the method in any of claims 1 to 20.

22. A communications device, characterized by A processor is included to execute program code to enable the communication device to implement the method in any of claims 1 to 20.

23. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program, which when executed by a processor, causes the method of any one of claims 1 to 20 to be performed.

24. A computer program product, characterised in that, A computer program product comprising a computer program which, when executed by a processor, causes the method of any one of claims 1 to 20 to be performed.