Communication method and apparatus

By setting MAC layer security policies for user plane control information in dual-connectivity scenarios, and either denying or performing security processing, the problem of insufficient MAC layer security processing in existing technologies is solved, thereby improving network security.

WO2025246501A1PCT designated stage Publication Date: 2025-12-04HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/079526
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-31
Filing Date
2025-02-27
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

In dual-connectivity scenarios, existing technologies have not yet proposed how to securely process user plane control PDUs at the Media Access Control (MAC) layer, resulting in insufficient network security.

Method used

The access network device determines the MAC layer security policy for user plane control information, and rejects or performs security processing to ensure the security of user plane control information at the MAC layer, including encryption and/or integrity protection.

Benefits of technology

It achieves secure protection of user plane control information in dual-connectivity scenarios, improves network security, and prevents information leakage and tampering.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025079526_04122025_PF_FP_ABST
    Figure CN2025079526_04122025_PF_FP_ABST
Patent Text Reader

Abstract

A communication method and apparatus. The method is applied to a scenario in which a terminal apparatus simultaneously accesses a first access network apparatus and a second access network apparatus. The method comprises: a first access network apparatus determining a security policy at a MAC layer for user-plane control information associated with a first PDU session of a terminal apparatus, and rejecting the establishment of the first PDU session on the basis of the security policy, or determining, on the basis of the security policy, whether to perform security processing on the user-plane control information at the MAC layer. In the method, a first access network apparatus can decide, on the basis of a security policy at a MAC layer for user-plane control information, whether to reject the establishment of a first PDU session, if the first PDU session is to be established, and determine, on the basis of the security policy, whether to perform security processing on the user-plane control information at the MAC layer, wherein the security policy is for the MAC layer. The method can realize security protection of user-plane control information in a dual-connectivity scenario, and can also realize security protection of user-plane control information above a MAC layer.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method and apparatus

[0001] Cross-reference to related applications

[0002] This application claims priority to Chinese Patent Application No. 202410708124.9, filed on May 31, 2024, entitled "A Communication Method and Apparatus", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of communication technology, and in particular to a communication method and apparatus. Background Technology

[0004] Wireless communication transmissions can be divided into control signaling and user plane data. Control signaling is transmitted on the control plane, while user plane data is transmitted on the user plane. User plane data can be carried in User Plane Data Units (PDUs) and User Plane Control PDUs. User plane data PDUs carry service data, while user plane control PDUs carry control information used to schedule or assist the transmission of service data. For security, the sending and receiving ends can perform security processing on user plane data and control plane signaling. For example, the sending end encrypts the data, and the receiving end decrypts it to prevent third parties from reading the data; the sending end performs integrity protection on the data, and the receiving end performs integrity verification to prevent third parties from tampering with the data.

[0005] While the paper proposes security processing at the media access control (MAC) layer for user plane control PDUs, it has not yet addressed how to implement MAC layer security processing for user plane control PDUs in dual-connectivity scenarios. Dual-connectivity refers to a terminal device simultaneously establishing connections with two network devices. Summary of the Invention

[0006] This application provides a communication method and apparatus for implementing security protection of user plane control information at the MAC layer in a dual-connectivity scenario, thereby improving network security.

[0007] To achieve the above objectives, the embodiments of this application adopt the following technical solutions:

[0008] Firstly, this application provides a communication method applied to the network side. For example, the method may be applied to an access network device or a component (e.g., a circuit, chip, or chip system) within the access network device; or, the method may be applied to a module or unit that performs some functions of the access network device, such as a central unit (CU), a distributed unit (DU), or a radio unit (RU); or, the method may be applied to a larger device including the access network device. For ease of description, the following example illustrates the method applied to a first access network device. This communication method is applied to a dual-connectivity scenario, i.e., a scenario where a terminal device simultaneously connects to two access network devices, for example, a terminal device simultaneously connects to both a first and a second access network device. The following example illustrates the first access network device as the primary node of the terminal device and the second access network device as the secondary node of the terminal device.

[0009] The communication method includes: a first access network device determining the security policy of the user plane control information associated with the first PDU session of the terminal device at the MAC layer, and rejecting the establishment of the first PDU session according to the security policy; or, determining whether to perform security processing on the user plane control information at the MAC layer according to the security policy.

[0010] The security processing includes encryption and / or integrity protection. When a terminal device is simultaneously connected to a first access network device and a second access network device, the first access network device can decide whether to reject the establishment of a first PDU session or determine whether to perform security processing on the user plane control information at the MAC layer based on the security policy of the user plane control information at the MAC layer. Since the security policy is applied at the MAC layer, this scheme can achieve security protection of user plane control information in dual-connectivity scenarios, as well as security protection of user plane control information above the MAC layer.

[0011] In one implementation, the method further includes: a first access network device receiving first capability information from a second access network device, the first capability information being used to indicate whether the second access network device supports MAC layer security processing.

[0012] Whether a second access network device supports secure MAC layer processing can be replaced with whether the second access network device has MAC security capabilities. During the process of one access network device requesting to establish an Xn link with another access network device, it can inform the other access network device whether it has MAC security capabilities. For example, during the process of a second access network device requesting to establish an Xn link with a first access network device, it can also inform the first access network device whether it has MAC security capabilities. Similarly, during the process of a first access network device requesting to establish an Xn link with a second access network device, it can also inform the second access network device whether it has MAC security capabilities. Through this scheme, the first access network device can clearly determine whether the second access network device has MAC security capabilities, which helps the first access network device decide whether to perform secure processing of user plane control information at the MAC layer, and control whether the second access network device performs secure processing of user plane control information at the MAC layer, thereby maximizing the consistency of the security policies for user plane control information between the first and second access network devices.

[0013] In one implementation, the security strategy includes: requiring security protection for user plane control information, preferably requiring security protection for user plane control information, or not requiring security protection for user plane control information.

[0014] In one implementation, the first access network device determines whether to perform secure processing on user plane control information at the MAC layer according to a security policy, including: the first access network device determines whether to perform secure processing on user plane control information at the MAC layer according to the security policy and whether the first access network device supports secure processing at the MAC layer.

[0015] Does the first access network device support secure processing at the MAC layer, that is, does the first access network device have MAC security capabilities? If the first access network device supports secure processing at the MAC layer, then the first access network device has MAC capabilities. In possible scenarios, in addition to considering the security policy for user plane control information, the first access network device must also determine whether to perform secure processing on user plane control information at the MAC layer based on its own actual capabilities to avoid invalid processing.

[0016] In one implementation, the first access network device determines whether to perform secure processing on user plane control information at the MAC layer according to a security policy, including: the first access network device determines whether to perform secure processing on user plane control information at the MAC layer according to the security policy, whether the first access network device supports secure processing at the MAC layer, and whether the second access network device supports secure processing at the MAC layer.

[0017] In a dual-connectivity scenario, the first access network device, in addition to considering the security policies for user plane control information and its own actual capabilities, must also determine whether to perform security processing on user plane control information at the MAC layer, based on whether the second access network device supports MAC layer security processing. This approach maximizes the security protection of user plane control information at the MAC layer, thereby improving its overall security.

[0018] In one implementation, the first access network device rejects the establishment of the first PDU session according to a security policy, including: if the security policy requires security protection for user plane control information and the first access network device does not support security protection for user plane control information at the MAC layer, then the first access network device rejects the establishment of the first PDU session.

[0019] Since the first access network device does not support security protection for user plane control information at the MAC layer, when the security policy of user plane control information requires security protection, the first access network device may refuse to establish the first PDU session in order to avoid unnecessary session establishment.

[0020] In one implementation, the method further includes: a first access network device sending a first reason value, the first reason value indicating a reason for rejecting the establishment of a first PDU session.

[0021] By reporting the first reason value, the core network can clearly understand why the first PDU session was refused to be established, which helps to prevent the core network from initiating a PDU session establishment request with the same security policy again.

[0022] In one implementation, the security policy requires security protection for user plane control information. The first access network device determines whether to perform security processing on the user plane control information at the MAC layer according to the security policy. This includes: if the first access network device supports security protection for user plane control information at the MAC layer, then the first access network device determines to perform security processing on the user plane control information at the MAC layer.

[0023] A condition under which the first access network device performs secure processing of user plane control information at the MAC layer is that the security policy requires security protection of user plane control information, and the first access network device supports security protection of user plane control information at the MAC layer. When this condition is met, the first access network device can perform secure processing of user plane control information at the MAC layer.

[0024] In one implementation, the second access network device supports security protection of user plane control information at the MAC layer. The method further includes: the first access network device sending a first indication message to the second access network device, the first indication message being used to instruct the second access network device to perform security processing on the user plane control information at the MAC layer.

[0025] When the security policy requires security protection for user plane control information, and both the first and second access network devices support security protection of user plane control information at the MAC layer, both devices can perform secure processing of user plane control information at the MAC layer. Specifically, the second access network device is instructed by the first access network device to perform secure processing of user plane control information at the MAC layer, thus ensuring consistency in the secure processing of user plane control information by both devices.

[0026] In one implementation, the second access network device does not support security protection of user plane control information at the MAC layer, and the method further includes: the first access network device does not send data of the first PUD session to the second access network device.

[0027] The first access network device not sending data of the first PUD session to the second access network device can be replaced by the first access network device refusing to send data of the first PUD session to the second access network device. The first access network device not sending data of the first PUD session to the second access network device can be understood as the first access network device not offloading data of the first PDU session. When the security policy requires security protection of user plane control information, and the first access network device supports security protection of user plane control information at the MAC layer, while the second access network device does not support security protection of user plane control information at the MAC layer, the first access network device can perform security processing of user plane control information at the MAC layer, while simultaneously not sending data of the first PUD session to the second access network device. This scheme avoids offloading data of the first PUD session to the second access network device, preventing leakage or tampering of the first PDU session data.

[0028] In one implementation, the security policy is to preferably protect the user plane control information. The first access network device determines whether to perform security processing on the user plane control information at the MAC layer according to the security policy, including the following three cases.

[0029] Case 1: The first access network device does not support security protection for user plane control information at the MAC layer, and the first access network device determines that it will not perform security processing on user plane control information at the MAC layer.

[0030] Case 1 can also be seen as a condition under which the first access network device determines not to perform security processing on user plane control information at the MAC layer: the security policy is to preferably perform security protection on user plane control information, and the first access network device does not support security protection on user plane control information at the MAC layer.

[0031] Scenario 2: The first access network device supports security protection of user plane control information at the MAC layer, and the first access network device determines to perform security processing on user plane control information at the MAC layer.

[0032] Scenario 2 can also be seen as a condition under which the first access network device determines to perform secure processing of user plane control information at the MAC layer: the security policy is to preferentially protect user plane control information, and the first access network device supports secure protection of user plane control information at the MAC layer. When the security policy is to preferentially protect user plane control information, in order to ensure the security of user plane control information, the first access network device can perform secure processing of user plane control information at the MAC layer.

[0033] Case 3: The first access network device supports security protection for user plane control information at the MAC layer, and the first access network device determines that it will not perform security processing on user plane control information at the MAC layer.

[0034] In one implementation, the first access network device supports security protection and secure processing of user plane control information at the MAC layer. The method further includes: the first access network device not sending data of the first PUD session to the second access network device. That is, in case 2, the first access network device does not send data of the first PUD session to the second access network device.

[0035] In one implementation, the first access network device supports security protection of user plane control information at the MAC layer, and does not perform security processing on user plane control information at the MAC layer. The method further includes: the first access network device sending data of a first PDU session to a second access network device, and the first access network device sending second indication information to the second access network device, the second indication information being used to instruct the second access network device not to perform security processing on user plane control information at the MAC layer.

[0036] In scenario 3, since the first access network device does not perform secure processing on user plane control information at the MAC layer, the first access network device does not perform secure processing on user plane control information at the MAC layer to the second access network device, and the first access network device does not send data of the first PUD session to the second access network device, so as to reduce unnecessary processing by the second access network device.

[0037] In one implementation, the method further includes: a first access network device sending a second reason value, the second reason value indicating the reason why user plane control information is not securely processed at the MAC layer.

[0038] In both Case 1 and Case 3, the first access network device can indicate the reason why user plane control information is not processed securely at the MAC layer, which helps the core network to re-initiate a PDU session establishment request with the same security policy.

[0039] In one implementation, the security policy is that user plane control information does not need to be protected by security. The first access network device determines whether to perform security processing on the user plane control information at the MAC layer according to the security policy, including: the first access network device determines that the user plane control information is not processed by security at the MAC layer.

[0040] In one implementation, the method further includes: a first access network device sending a first key, which is generated based on a second key used by the first access network device.

[0041] When both the first access network device and the second access network device perform secure processing of user plane control information at the MAC layer, the first access network device can deduce the first key based on the second key and send the first key to the second access network device, so that the second access network device can use the first key to complete the secure processing at the MAC layer.

[0042] In one implementation, the method further includes: a first access network device sending second capability information, the second capability information being used to indicate whether the terminal device supports MAC layer security protection.

[0043] The first access network device can send second capability information to the core network element, which helps the core network to initiate a PDU session establishment request with appropriate security policy based on the MAC security capabilities of the terminal device.

[0044] In one implementation, the second capability information is included in the non-access stratum (NAS) PDU in the initial user equipment message.

[0045] Secondly, this application provides a communication method applied to a terminal side, for example, the method applied to a terminal device; or, the method applied to a larger device including the terminal device; or, the method applied to a module or unit that performs some functions of the terminal device, such as a circuit or chip / chip system (e.g., a modem chip, also known as a baseband chip, or a system-on-chip (SoC) chip containing a modem core, or a system-in-package (SIP) chip) or other functional module in the terminal device. For ease of description, the following example illustrates the application of this method to a terminal device. This scenario involves the terminal device simultaneously connecting to two access network devices, for example, the terminal device simultaneously connecting to a first access network device and a second access network device. The following example assumes that the first access network device is the master node of the terminal device, and the second access network device is the slave node of the terminal device.

[0046] The communication method includes: establishing a radio resource control (RRC) connection between the terminal device and the first access network device, and sending second capability information to the first access network device, wherein the second capability information is used to indicate whether the terminal device supports MAC layer security protection.

[0047] In the future, the network side may support secure processing of user plane control information at the MAC layer. If the network side decides to perform secure processing of user plane control information at the MAC layer, but the terminal device does not support MAC layer security protection, the terminal device may be unable to obtain the user plane control information. This solution allows the network side to clearly determine whether the terminal device supports MAC layer security protection, and adaptively choose whether to perform secure processing of user plane control information at the MAC layer.

[0048] In one implementation, the second capability information is included in message 5 during the random access process.

[0049] In one implementation, the method further includes: the terminal device receiving third indication information, which is used to indicate enabling the MAC protection function. The MAC protection function of the terminal device can be enabled by the network side.

[0050] Thirdly, embodiments of this application provide a communication method that can be executed by a first communication device and a second communication device. The first communication device has the function of implementing the behavior in the method example described in the first aspect. For example, the first communication device includes corresponding means, modules, or units for executing the method of the first aspect, which can be implemented by software and / or hardware. The first communication device can be the aforementioned first access network device. The second communication device can be the aforementioned second access network device. Hereinafter, the first communication device is taken as the first access network device and the second communication device as the second access network device, respectively.

[0051] The communication method includes: a first access network device acquiring first capability information of a second access network device, the first capability information being used to indicate whether the second access network device supports MAC layer security processing; the first access network device determining the security policy of user plane control information associated with a first PDU session of a terminal device at the MAC layer; the first access network device rejecting the establishment of the first PDU session according to the security policy, or the first access network device determining whether to perform security processing on the user plane control information at the MAC layer according to the security policy, the first capability information, and whether the first access network device supports MAC layer security processing.

[0052] For the beneficial effects of the third aspect, please refer to the beneficial effects of the first aspect and its various implementation methods, which will not be elaborated here.

[0053] Fourthly, embodiments of this application provide a communication device that has the functionality to implement the behavior in any of the method examples of the first or second aspect described above. The beneficial effects can be found in the relevant descriptions of the first or second aspect and will not be repeated here. For example, the communication device may be a first access network device in the first aspect, or it may be a device capable of supporting the access network device to implement the functions required by the method provided in the first aspect; for example, the communication device may be a chip or chip system in the access network device. As another example, the communication device may be a terminal device in the second aspect, or it may be a device capable of supporting the terminal device to implement the functions required by the method provided in the second aspect; for example, the communication device may be a chip or chip system in the terminal device.

[0054] In one possible design, the communication device includes a baseband device and a radio frequency device.

[0055] In one possible design, the communication device includes corresponding means, modules, or units for performing the methods of the first or second aspect. These modules, units, or means can be implemented in software, hardware, or a combination of both. For example, the communication device includes a processing unit (sometimes also called a processing module or processor) and / or a transceiver unit (sometimes also called a transceiver module or transceiver). The transceiver unit is capable of both sending and receiving functions. When the transceiver unit performs the sending function, it can be called a sending unit (sometimes also called a sending module), and when it performs the receiving function, it can be called a receiving unit (sometimes also called a receiving module). The sending unit and the receiving unit can be the same functional unit, referred to as the transceiver unit, which performs both sending and receiving functions; or, the sending unit and the receiving unit can be different functional units, with "transceiver unit" being a general term for these functional units. These units (modules) can perform the corresponding functions in the method examples of the first or second aspect described above, as detailed in the method examples, and will not be repeated here.

[0056] Fifthly, embodiments of this application provide a communication device, which can be the communication device in the fourth aspect of the above embodiments, or a chip or chip system disposed in the communication device in the fourth aspect. The communication device includes a communication interface and a processor, and optionally, a memory. The memory is used to store computer programs, instructions, or data, and the processor is coupled to the memory and the communication interface. When the processor reads the computer program, instructions, or data, it causes the communication device to execute the method executed by the first access network device in the above method embodiments. For example, the communication device can be the first access network device, a device including the first access network device, or a functional module in the first access network device, such as a baseband chip and a radio frequency chip. Alternatively, when the processor reads the computer program, instructions, or data, it causes the communication device to execute the method executed by the terminal device in the above method embodiments. For example, the communication device can be a terminal device, a device including the terminal device, or a functional module in the terminal device, such as a baseband chip and a radio frequency chip.

[0057] Sixthly, embodiments of this application provide a chip system including a processor and a communication interface for implementing the methods described in the first or second aspect. Optionally, the chip system further includes a memory. The memory stores computer programs (also referred to as code or instructions). The processor retrieves and executes the computer program from the memory, causing a device equipped with the chip system to perform the methods of the first or second aspect and any possible implementation thereof. The chip system may be composed of chips or may include chips and other discrete devices.

[0058] In a seventh aspect, embodiments of this application provide a communication device including an input / output interface and logic circuitry. The input / output interface is used for inputting and / or outputting information. The input / output interface may be an interface circuit, an output circuit, an input circuit, pins, or related circuitry, etc. The logic circuitry is used to execute the methods described in the first or second aspect.

[0059] In practical implementation, the aforementioned communication device can be a chip, the input circuit can be an input pin, the output circuit can be an output pin, and the logic circuit can be a transistor, gate circuit, flip-flop, and various other logic circuits. The input signal received by the input circuit can be received and input by, for example, but not limited to, a receiver, and the signal output by the output circuit can be, for example, but not limited to, output to and transmitted by a transmitter. Furthermore, the input circuit and the output circuit can be the same circuit, which is used as both the input circuit and the output circuit at different times. This application does not limit the specific implementation of the input / output interface and the logic circuit.

[0060] In one implementation, when the communication device is a wireless communication device, it can be a terminal device such as a mobile phone, or it can be an access network device such as a base station. The interface circuit can be a radio frequency processing chip in the wireless communication device, and the processing circuit can be a baseband processing chip in the wireless communication device.

[0061] Eighthly, embodiments of this application provide a communication system comprising a first access network device, a second access network device, and a terminal device. The terminal device is simultaneously connected to both the first access network device and the second access network device. The first access network device is used to implement the functions described in the first aspect, and the terminal device is used to implement the functions described in the second aspect.

[0062] Ninthly, embodiments of this application provide a computer-readable storage medium for storing a computer program or instructions that, when executed, cause the methods described in the first or second aspect and any of their implementations to be implemented.

[0063] In a tenth aspect, embodiments of this application also provide a computer program product containing instructions that, when run on a computer, cause the methods described in the first or second aspect and any of their implementations to be implemented.

[0064] The beneficial effects of the above-mentioned fourth to tenth aspects and their implementation methods can be referenced with the beneficial effects of the first aspect and any of its implementation methods. Attached Figure Description

[0065] Figure 1 is a schematic diagram of the architecture of the communication system provided in an embodiment of this application;

[0066] Figure 2 is a schematic diagram of the transmission of downlink data between layers provided in the embodiments of this application;

[0067] Figure 3 is a schematic diagram of the integrity protection / verification process based on NIA provided in an embodiment of this application;

[0068] Figure 4 is a schematic diagram of the encryption process based on NEA provided in an embodiment of this application;

[0069] Figure 5 is a schematic diagram of the EN-DC control plane architecture provided in an embodiment of this application;

[0070] Figure 6 is a schematic diagram of the EN-DC user plane architecture provided in an embodiment of this application;

[0071] Figure 7 is a flowchart illustrating the communication method 700 provided in an embodiment of this application;

[0072] Figure 8 is a schematic diagram of the process of generating a first key from a second key according to an embodiment of this application;

[0073] Figure 9 is a flowchart illustrating the communication method 900 provided in an embodiment of this application;

[0074] Figure 10 is a schematic diagram of a communication device provided in an embodiment of this application;

[0075] Figure 11 is a schematic diagram of another structure of the communication device provided in the embodiment of this application. Detailed Implementation

[0076] The method provided in this application embodiment can achieve security protection of user plane control information above the MAC layer in dual-connection scenarios, thereby preventing the leakage or tampering of user plane control information and improving communication security.

[0077] The technical solutions provided in the embodiments of this application can be applied to various communication systems, such as long term evolution (LTE) communication systems, the sixth generation (5G) mobile communication systems (also known as new radio (NR) communication systems), or they can also be applied to future communication networks or other similar communication systems. Other similar communication systems may include wireless fidelity (WIFI), vehicle-to-everything (V2X) systems, internet of things (IoT) systems, and so on.

[0078] Please refer to Figure 1, which illustrates a communication system applicable to an embodiment of this application. The communication system includes a radio access network (RAN) 100 and a core network (CN) 200. Optionally, the communication system may also include the Internet (Figure 1 uses this as an example). The RAN 100 may include at least one access network device and at least one terminal device. For example, the RAN 100 includes two access network devices, 110a and 110b, and terminal devices 120a to 120j, etc. The network architecture shown in Figure 1 is merely illustrative; the number of terminal devices and / or access network devices may be fewer or more. The communication system described in this application embodiment is for the purpose of more clearly illustrating the technical solutions of this application embodiment and does not constitute a limitation on the communication system applicable to the embodiments of this application. For example, the communication system may also include other devices, such as wireless relay devices and wireless backhaul devices, which are not shown in Figure 1. Those skilled in the art will understand that, with the evolution of network architecture, the technical solutions provided in this application embodiment are also applicable to similar technical problems. When applying the technical solutions of the embodiments of this application to other communication systems, the devices, components, modules, etc. in the embodiments can be replaced with corresponding devices, components, modules in other communication systems without limitation.

[0079] First, the access network equipment, terminal equipment, core network equipment, etc. involved in the embodiments of this application will be explained.

[0080] (1) Access network equipment refers to RAN equipment.

[0081] RAN can be a 3GPP-related cellular system, such as a 5G / new radio (NR) mobile communication system, or a future-oriented evolution system (such as a 6G mobile communication system). RAN can also be an open RAN (O-RAN or ORAN), a cloud radio access network (CRAN), or a virtualized RAN (vRAN). RAN can also be a communication system that integrates two or more of the above systems. RAN equipment can also be called a RAN node, RAN entity, or access node, etc.

[0082] In one possible scenario, a RAN node can be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next-generation NodeB (gNB), or a base station in a future communication network. RAN nodes can also be macro base stations, micro base stations, indoor stations, relay nodes, donor / host nodes, or radio controllers. RAN nodes can also be servers, wearable devices, vehicles, or in-vehicle equipment. For example, in V2X technology, the RAN node can be a roadside unit (RSU).

[0083] In another possible scenario, a RAN node can be a module or unit that performs some of the functions of a base station; or multiple RAN nodes can collaborate to assist terminal devices in achieving wireless access, with different RAN nodes each performing some of the functions of a base station. For example, a RAN node can be a CU, DU, or RU that performs some of the functions of a base station. Any of the CU, DU, and RU units can be implemented through software modules, hardware modules, or a combination of software and hardware modules.

[0084] The CU and DU can be configured according to the protocol layer functions of the wireless network they implement: for example, the CU can be configured to implement the functions of the Packet Data Convergence Protocol (PDCP) layer and above (such as the RRC layer and / or the Service Data Adaptation Protocol (SDAP) layer); the DU can be configured to implement the functions of protocol layers below the PDCP layer (such as the Radio Link Control (RLC) layer, the MAC layer, and / or the Physical (PHY) layer). For specific descriptions of the above protocol layers, please refer to the relevant 3GPP technical specifications or the technical specifications of other applicable communication protocols.

[0085] When the RAN is O-RAN, it can also have artificial intelligence (AI) capabilities. For example, O-RAN includes an intelligent controller. The intelligent controller can be a non-real-time RAN intelligent controller (RIC / non-RT RIC / NRT RIC) or a near-real-time RAN intelligent controller (RIC / near-RT RIC / nRT RIC). A non-real-time RIC can be used to implement non-real-time intelligent management of RAN functions, enabling workflows including model training and model updates, and guiding applications / functions in the nRT RIC based on policies. A near-real-time RIC can be used to implement near-real-time intelligent management of the RAN. Through data collection and related operations on the E2 interface, near-real-time control and optimization of O-RAN modules and resources are achieved.

[0086] In the embodiments of this application, the device used to implement the function of the access network device can be the access network device itself, or it can be a device that supports the access network device in implementing the function, such as a chip system or a combination device or component that can implement the function of the access network device. The device can be installed in the access network device. The embodiments of this application do not limit the specific technology or specific device form used in the access network device.

[0087] (2) Terminal equipment

[0088] Any device capable of communicating with a base station can be considered a terminal device. Terminal devices are also called terminals, terminal equipment, user equipment (UE), mobile stations, or mobile terminals. Terminal devices can be widely used in various scenarios. For example, terminal devices can be: mobile phones, computers, mobile internet devices (MID), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, stations (STA), robotic arms, cameras, robots, vehicles, drones, helicopters, airplanes, ships, or smart home devices (such as televisions, air conditioners, robot vacuums, speakers, set-top boxes), relays, customer premises equipment (CPE), or terminal devices in IoT systems, such as water meters and electricity meters.

[0089] When the terminal device is applied to V2X, it can also be called a V2X device, such as a smart car, digital car, unmanned car, driverless car, pilotless car, autonomous car, pure electric vehicle, hybrid electric vehicle (HEV), range-extended electric vehicle (REEV), plug-in hybrid electric vehicle (PHEV), new energy vehicle, and RSU.

[0090] The various terminal devices described above, if located on a vehicle (e.g., placed / installed inside the vehicle), can all be considered in-vehicle terminal devices. In-vehicle terminal devices can be built into a vehicle's in-vehicle module, in-vehicle component, in-vehicle chip, or in-vehicle unit as one or more components or units. The vehicle can implement the methods of this application through the built-in in-vehicle module, in-vehicle component, in-vehicle chip, or in-vehicle unit. In-vehicle terminal devices can be vehicle equipment, in-vehicle modules, vehicles, in-vehicle units (on-board units, OBUs), remote sensing units (RSUs), in-vehicle infotainment systems (or in-vehicle transmission units) (telematics boxes, T-boxes), chips, or system-on-chips (SoCs), etc. These chips or SoCs can be installed in the vehicle, OBU, RSU, or T-box.

[0091] In the embodiments of this application, the device for implementing the functions of the terminal device can be the terminal device itself, or a device capable of supporting the terminal device in implementing the functions, such as a chip system or a combination of devices or components capable of implementing the functions of the terminal device. This device can be installed in the terminal device. The embodiments of this application do not limit the specific technology or specific device form used in the terminal device.

[0092] The roles of base station and UE can be relative. For example, the helicopter or drone 120i in Figure 1 can be configured as a mobile base station. For UEs 120j that access the radio access network 100 through 120i, UE 120i is a base station; however, for base station 110a, 120i is a UE, meaning that 110a and 120i communicate via a radio interface protocol. Of course, 110a and 120i can also communicate via a base station-to-base station interface protocol. In this case, relative to 110a, 120i is also a base station. Therefore, both base station and UE can be collectively referred to as communication devices. 110a and 110b in Figure 1 can be called communication devices with base station functions, and 120a-120j in Figure 1 can be called communication devices with UE functions.

[0093] (3) Protocol layer structure between access network equipment and terminal equipment

[0094] Communication between access network equipment and terminal equipment follows a specific protocol layer structure. For example, the control plane protocol layer structure may include the RRC layer, PDCP layer, RLC layer, MAC layer, and PHY layer; the user plane protocol layer structure may include the PDCP layer, RLC layer, MAC layer, and PHY layer. In one possible implementation, an SDAP layer may also be included above the PDCP layer. The SDAP layer, PDCP layer, RLC layer, MAC layer, and PHY layer can all be collectively referred to as the access layer. For detailed descriptions of each of these protocol layers, please refer to the relevant technical specifications of the 3GPP (Third Generation Partnership Project).

[0095] Taking data transmission between access network devices and terminal devices as an example, data transmission needs to pass through user plane protocol layers, such as SDAP, PDCP, RLC, MAC, and PHY layers. For example, please refer to Figure 2, which illustrates the transmission of downlink data between these layers. Downlink data refers to the data sent from the access network device to the terminal device. In Figure 2, downward arrows represent data transmission, and upward arrows represent data reception.

[0096] After receiving data from the upper layer, the SDAP layer entity maps the data to the corresponding PDCP layer entity. The PDCP layer entity then delivers the data to at least one RLC layer entity corresponding to that PDCP layer entity. This RLC layer entity then delivers the data to the corresponding MAC layer entity, which generates a transport block (TB) and transmits it wirelessly through the corresponding PHY layer entity. Data is encapsulated at each layer. Data received by a layer from its upper layer is considered a Service Data Unit (SDU) for that layer. After layer encapsulation, it becomes a PDU and is then passed to the next layer. For example, data received by a PDCP layer entity from its upper layer is called a PDCP SDU, and data sent by the PDCP layer entity to its lower layer is called a PDCP PDU; similarly, data received by an RLC layer entity from its upper layer is called an RLC SDU, and data sent by the RLC layer entity to its lower layer is called an RLC PDU. Different layers can transmit data through corresponding channels. For instance, RLC layer entities and MAC layer entities can transmit data through a logical channel (LCH), and MAC layer entities and physical layer entities can transmit data through a transport channel.

[0097] Similar to access network equipment, terminal equipment also has an access layer comprising SDAP, PDCP, RLC, MAC, and physical layers. Terminal equipment also has an application layer and a non-access layer. The application layer provides services to applications installed on the terminal equipment. For example, downlink data received by the terminal equipment can be sequentially transmitted from the physical layer to the application layer, and then provided to the application by the application layer. Alternatively, the application layer can acquire data generated by applications (such as videos recorded by users using the application) and sequentially transmit the data to the physical layer for transmission to other communication devices. The non-access layer forwards user data, such as forwarding uplink data received from the application layer to the SDAP layer or forwarding downlink data received from the SDAP layer to the application layer.

[0098] (4) Core network equipment, also known as core network elements

[0099] The core network 200 includes one or more core network devices, such as authentication server function (AUSF) network elements, unified data management (UDM) network elements, unified data repository (UDR) network elements, access and mobility management function (AMF) network elements, and session management function (SMF) network elements. The core network devices mentioned above are just examples; other devices exist, but will not be detailed here. Among them, the AMF network element performs mobility management and access authentication / authorization functions. The SMF network element can be used to perform session management and Internet Protocol (IP) address allocation for terminal devices. The AUSF network element is responsible for authenticating users to determine whether to allow users or devices to access the network. The UDM network element performs functions such as managing subscription data and authorizing user access. The UDR can perform data access functions for subscription data, policy data, application data, and other types of data.

[0100] The communication system applicable to the embodiments of this application has been described above. The related technologies involved in the embodiments of this application, such as user plane transmission and security processing, are described below.

[0101] 1) User plane transmission

[0102] Wireless communication transmission is divided into user plane transmission and control plane transmission. User plane transmission can be used to transmit user plane data and user plane control information, while control plane transmission can be used to transmit control plane signaling, which may include RRC signaling, etc.

[0103] User plane data refers to user plane data PDUs, which are used to carry communication content data. User plane data PDUs can include data PDUs from various protocol layers, such as SDAP data PDUs, PDCP data PDUs, RLC data PDUs, etc.

[0104] User plane control information refers to user plane control PDUs, which carry control information to support the transmission of user plane data PDUs, such as status reports, robust header compression (RoHC) feedback, and Ethernet header compression (EHC) feedback. User plane control PDUs can include control PDUs from various protocol layers, such as SDAP control PDUs, PDCP control PDUs, and RLC control PDUs. Besides the user plane control PDUs mentioned above, other control information exists, such as MAC control element (CE) PDUs and control PDUs for new protocol layers that may be defined in future communication systems.

[0105] 2) Security processing, also known as security protection, includes encryption processing and / or integrity protection processing.

[0106] For security during communication, the sending and receiving ends can perform security processing on user plane data and control plane signaling. Currently, access layer security processing can be performed at the PDCP layer. That is, the sending end performs security processing on user plane data or control plane signaling at the PDCP layer, such as encryption and / or integrity protection; the receiving end also performs corresponding security processing on user plane data or control plane signaling at the PDCP layer, such as decryption and / or integrity verification. Integrity verification can also be called integrity check. In the embodiments of this application, "integrity protection" can also be called integrity verification, or simply integrity protection verification / integrity check / integrity protection. "Encryption" and "integrity protection" can be independent algorithms. Alternatively, "encryption" may also include "integrity protection." In other words, "encryption" includes both encryption and integrity protection.

[0107] Encryption refers to the process by which the sending end uses an algorithm to convert plaintext data into ciphertext based on input parameters such as a key. Decryption refers to the process by which the receiving end uses an algorithm to convert the ciphertext back into plaintext based on input parameters such as a key. When the input parameters used by the sending end and the receiving end are the same, it is possible for information encrypted at the sending end to be successfully decrypted at the receiving end.

[0108] Integrity protection processing refers to the sending end calculating integrity protection parameters (e.g., parameter A) using an algorithm based on input parameters such as data packets and keys. Integrity verification refers to the receiving end calculating parameter B using an algorithm based on input parameters such as data packets and keys. If parameters A and B match, integrity verification succeeds; otherwise, it fails. When the input parameters used by the sending end and the receiving end are the same, information that has undergone integrity protection at the sending end can be successfully verified for integrity by the receiving end.

[0109] For example, please refer to Figure 3, which illustrates the process of integrity protection / authentication using the integrity algorithm for 5G (NIA). As shown in Figure 3, the input parameters for integrity protection / authentication include a count, a key, a message (such as the message itself to be protected / authenticated), a transmission direction (such as uplink or downlink transmission), and a bearer identifier. The output parameters obtained from the integrity protection process (i.e., parameter A) include the message authentication code-integrity (MAC-I), and the output parameters obtained from the integrity authentication process (i.e., parameter B) include the expected message authentication code-integrity (XMAC-I). If parameters MAC-I and XMAC-I match, the integrity authentication is successful; if parameters MAC-I and XMAC-I do not match, the integrity authentication fails.

[0110] The encryption protection process for the air interface is similar to the integrity protection process for the air interface. For example, please refer to Figure 4, which illustrates the encryption process using the 5G encryption algorithm (NEA). As shown in Figure 4, the input parameters for air interface encryption include the key, counter value, radio bearer identifier, transmission direction, and key stream length. When the transmitting end performs encryption, it generates a key stream (KEYSTREAMBLOCK) based on the input parameters. This key stream is XORed with the input plaintext (PLAINTEXTBLOCK) to generate the ciphertext (CIPHERTEXTBLOCK). At the receiving end, the same key stream is generated using the same input parameters, and the plaintext is XORed with the ciphertext to recover the plaintext.

[0111] It should be noted that the above integrity protection is based on MAC-I. This application does not limit the means of integrity protection employed. For example, cyclic redundancy check (CRC), hash function (HASH), or digital signature can also be used to implement integrity protection. MAC-I can be considered a keyed hash function. Taking integrity protection through CRC as an example, the sending and receiving ends can agree on the CRC generator polynomial P before communication. The length of P is R+1. The sending end adds R zeros to the original K-bit data, which is equivalent to shifting the original K-bit data left by R bits, resulting in K+R bits of data. Then, it performs modulo-2 division (i.e., XOR operation), dividing the K+R bits of data by P, and repeating the calculation until the order of the remainder is less than R. This remainder has a length of R and is an additional CRC checksum. If the length is less than R bits, it is padded with leading zeros. The sending end appends the R-bit checksum to the original K-bit data and sends it to the receiving end. After receiving the data, the receiving end divides the data by the divisor P using modulo-2 division. If there is no remainder, it means that no error occurred during transmission; otherwise, it means that an error occurred.

[0112] 3) Dual connectivity (DC)

[0113] DC refers to a terminal device simultaneously accessing two network devices. One network device is the master node (MN), and the other network device is the secondary node (SN). The one or more cells provided by the MN to the terminal device are called the master cell group (MCG), while the one or more cells provided by the SN to the terminal device are called the secondary cell group (SCG).

[0114] In the evolution of wireless communication systems, both NR and LTE systems are deployed simultaneously. In one scenario, terminal devices support simultaneous access to both LTE and NR network devices. Because LTE is also known as Evolved Universal Terrestrial Radio Access (E-UTRA), this access method is called E-UTRA NR dual connectivity (EN-DC). In EN-DC mode, the LTE network device is the MN, and the NR network device is the SN. In another scenario, terminal devices can also support NR and E-UTRA dual connectivity (NE-DC). In NE-DC mode, the NR network device is the MN, and the LTE network device is the SN. Since terminals in EN-DC and NE-DC access two different radio access technologies, these DC modes can also be collectively referred to as Multi-RAT Dual Connectivity (MR-DC). Furthermore, when the core network connected to the MN and SN is a 5G core network, EN-DC is also called NGEN-DC.

[0115] Wireless communication transmission is divided into control plane transmission and user plane transmission. User plane transmission is mainly used to transmit user plane data, while control plane transmission is mainly used to transmit control signaling. User plane data can be carried on user plane data PDUs and user plane control PDUs. User plane data PDUs are used to carry service data, while user plane control PDUs are used to carry control information, which is used to schedule or assist the transmission of service data.

[0116] The following section uses EN-DC as an example, and introduces the control plane transmission and user plane transmission of DC in conjunction with Figures 5 and 6.

[0117] Please refer to Figure 5, which is a schematic diagram of the EN-DC control plane architecture provided in an embodiment of this application.

[0118] In Figure 5, the UE can connect to both the MN and SN simultaneously. Communication between the UE and the MN / SN is via the Uu interface, while communication between the MN and SN is via the X2-C interface. However, the UE has only one RRC state and only one control plane connection to the core network; that is, there is only one control plane connection. For example, for the UE, the control plane connection is from the MN to the core network, but there is no control plane connection from the SN to the core network.

[0119] Both the MN and SN have RRC entities that can create RRC PDUs for the UE. RRC PDUs created by the SN can be transmitted to the UE via the MN. The MN sends the initial RRC configuration of the SN to the UE via the MCG's signaling radio bearer (SRB) (e.g., SRB1). Subsequent RRC configurations of the SN can be sent by either the MN or the SN. When transmitting RRC PDUs from the SN, the MN does not modify the UE configuration information provided by the SN.

[0120] During the initial connection establishment of SRB1, E-UTRA's PDCP is used. After the initial connection is established, the MCG SRBs (SRB1 and SRB2) can be configured by the network to use either E-UTRA's PDCP or NR's PDCP. PDCP version changes for SRBs can be supported through handover procedures or non-mobility reconfiguration. For UEs supporting EN-DC, NR PDCP can be configured for both the data radio bearer (DRB) and SRB before EN-DC configuration.

[0121] The UE can be configured to establish an SRB (SRB3) with the SN to enable the SN to directly send RRC PDUs to the UE. Only RRC PDUs configured for the SN and not requiring negotiation with the MN can be directly sent from the SN to the UE. If SRB3 is already configured, mobility measurements within the SN can be performed directly between the SN and the UE.

[0122] Please refer to Figure 6, which is a schematic diagram of the EN-DC user plane architecture provided in an embodiment of this application.

[0123] In EN-DC, MN and SN are connected via the EN-DC X2 interface. As shown in Figure 6, under the user plane architecture, there are three bearer modes: SCG Bearer, Split Bearer, and MCG Bearer. From the network side, MCG Bearer and split bearer (including MCG Split Bearer and SCG Split Bearer) are generally used, and the specific bearer used is determined by the MN configuration. In MCG Bearer, PDCP can be configured as E-UTRA PDCP or NR PDCP. In EN-DC, the PDCP carried by MCG Split Bearer supports LTE communication technology / is configured as E-UTRA PDCP, or the PDCP carried by MCG Split Bearer supports NR communication technology / is configured as NR PDCP (Figure 6 uses this as an example). In other DC scenarios, the PDCP carried by MCG Split Bearer is configured as NR PDCP. The PDCP carried by SCG Split Bearer is configured as NR PDCP, and the "split" of the data flow is completed by the PDCP.

[0124] From the terminal / UE side, there are MCG Bearer and Split Bearer in EN-DC. The PDCP in MCG Bearer can be configured as E-UTRA PDCP or NR PDCP, while the PDCP in Split Bearer is configured as NR PDCP.

[0125] 4) In the embodiments of this application, "send" and "receive" indicate the direction of signal transmission. For example, "send information to XX" can be understood as the destination of the information being XX, which may include direct transmission via the air interface or indirect transmission by other units or modules via the air interface. "Receive information from YY" can be understood as the source of the information being YY, which may include direct reception from YY via the air interface or indirect reception from YY by other units or modules via the air interface. "Send" can also be understood as the "output" of the chip interface, and "receive" can also be understood as the "input" of the chip interface. In other words, sending and receiving can occur between devices, such as between access network devices and terminal devices, or within a device, such as between components, modules, chips, software modules, or hardware modules within the device via a bus, wiring, or interface.

[0126] In this application embodiment, the number of nouns, unless otherwise specified, refers to "singular nouns or plural nouns," that is, "one or more." "At least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, or B exists alone, where A / B can be singular or plural. The character " / " generally indicates that the related objects before and after are in an "or" relationship. For example, A / B means: A or B. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c means: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c can be single or multiple.

[0127] In the embodiments of this application, "when," "if," and "if" all refer to the device taking corresponding actions under certain objective circumstances, and are not time-limited, nor do they require the device to perform a judgment action, nor do they imply any other limitations. Unless otherwise specified, "if" and "if" can be substituted, and "when" and "in the case of" can be substituted. "When" and "if" / "if" can be substituted.

[0128] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the terms "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0129] In this application's embodiments, ordinal numbers such as "first" and "second" are used to distinguish multiple objects, and are not used to limit the size, content, order, timing, priority, or importance of the multiple objects. For example, "first instruction information" and "second instruction information" refer to two different pieces of information, and do not indicate a difference in priority or importance between the two pieces of information.

[0130] During wireless communication, data leakage or tampering can occur, leading to adverse consequences. For example, critical user plane control information can be exploited by malicious base stations or terminal devices to forge or monitor this information, posing a significant security risk to wireless communication. For instance, the MAC CE (Control Entity Controller) might be used to control terminal devices during cell handover; if a fake base station impersonates MAC layer handover signaling, it can cause incorrect handovers. Therefore, for security, both the transmitting and receiving ends can implement security measures for user plane data and control plane signaling. For example, the transmitting end can encrypt the data, and the receiving end can decrypt it to prevent third-party access; the transmitting end can perform integrity protection on the data, and the receiving end can perform integrity verification to prevent tampering.

[0131] For user plane data PDUs, security processing is introduced at the PDCP layer, and it is proposed to migrate the security processing at the PDCP layer to the MAC layer, thereby achieving security above the MAC layer. However, no security processing strategy has been proposed for user plane control PDUs. Similar to user plane data PDUs, security processing could also be performed at the MAC layer for user plane control PDUs to achieve security. However, for specific scenarios, how to implement security processing of user plane control PDUs at the MAC layer is currently not proposed.

[0132] For example, in a dual-connectivity scenario, since the terminal device only has one control plane connection to the core network, there may be a misalignment in the security processing of user plane control PDUs between the MN and SN. This could result in the user plane control PDUs not being properly secured at the SN side, leading to security vulnerabilities. For instance, if the control plane connection runs from the MN to the core network, the MN can perform security processing on the user plane control PDUs at the MAC layer, but the SN is unaware that the MN will perform this processing, potentially resulting in the SN not performing security processing on the user plane control PDUs at the MAC layer.

[0133] In view of this, the solution of this application embodiment is proposed. In this application embodiment, the MN side can determine the security policy of user plane control information at the MAC layer. The security policy includes whether it is necessary to protect the user plane control information at the MAC layer, or to prioritize the protection of the user plane control information at the MAC layer. Further, the MN side decides whether to protect the user plane control information at the MAC layer based on the determined security policy and whether the MN and SN support the protection of the user plane control information at the MAC layer, and decides whether to allow the SN to protect the user plane control information at the MAC layer. If the MN allows the SN to protect the user plane control information at the MAC layer, it can instruct the SN to protect the user plane control information at the MAC layer through signaling. Correspondingly, the SN protects the user plane control information at the MAC layer based on the MN's instruction. If the SN does not receive the MN's instruction, then it does not protect the user plane control information at the MAC layer. Through the solution provided by this application embodiment, in a dual-connectivity scenario, the SN and MN can maintain consistency on whether to protect the user plane control information at the MAC layer, thereby achieving secure processing of the user plane control information and improving the security of the user plane control information.

[0134] The solutions provided in the embodiments of this application are described below with reference to the accompanying drawings.

[0135] In the following description, taking the communication method provided in the embodiments of this application applied to the network architecture shown in Figures 1, 2, 5, or 6 as an example, the communication method provided in the embodiments of this application can be executed by a first access network device and a second access network device. The steps executed by the first access network device can be implemented by the first access network device itself, or by components within the first access network device (such as a baseband chip, or other processing units or processor modules), or by a device or apparatus that performs some functions of the first access network device. For example, the first access network device can be a CU, DU, or RU that performs some functions of the first access network device. The steps executed by the second access network device can be implemented by the second access network device itself, or by components within the second access network device (such as a baseband chip, or other processing units or processor modules), or by a device or apparatus that includes some functions of the second access network device. For example, the second access network device can be a CU, DU, or RU that performs some functions of the second access network device. There are no restrictions on the specific form of the first access network device and the second access network device. For example, the first access network device can be a chip and the second access network device can be a device; or, both the first access network device and the second access network device can be chips or devices.

[0136] In this embodiment, the terminal device can simultaneously access a first access network device and a second access network device. Relatively speaking, the first access network device is the master node / MN, and the second access network device is the slave node / SN. "Perform secure processing of user plane control information at the MAC layer" can be replaced with "enable security processing function," "enable MAC security processing function," "enable security policy," or "enable security policy at the MAC layer." "The data transmission of the first PDU session should not be migrated to the second access network device" can mean that the data of the first PDU session should not be sent to the second access network device, or that the split PDU session function should not be enabled, or that the split DRB function should not be enabled. Conversely, "migrating the data transmission of the first PDU session to the second access network device" can mean sending the data of the first PDU session to the second access network device, or enabling the split PDU session function, or enabling the split DRB function.

[0137] The following describes the solutions provided by the embodiments of this application in conjunction with Figures 1 to 6.

[0138] Please refer to Figure 7, which is a flowchart illustrating the communication method 700 provided in an embodiment of this application. Figure 7 describes the communication method 700 from the perspective of the interaction between the first access network device and the second access network device. As shown in Figure 7, the communication method 700 provided in this embodiment includes the following steps.

[0139] S701. The first access network device determines the security policy of the user plane control information associated with the first PDU session at the MAC layer.

[0140] The first access network device is the MN (Mean Access Network) in a dual-connectivity scenario. The terminal device establishes an RRC (Relational Resource Control) connection with the first access network device and initiates a PDU (Programmable Dedicated Unit) session establishment request to the core network through the first access network device. For example, the terminal device can initiate the establishment of a PDU session to the first access network device through the core network. For example, the core network sends a first request message to the first access network device, which is used to request the establishment of a first PDU session. This application embodiment does not limit the specific name of the first request message; for example, the first request message can be called a session establishment request message or a session creation request message.

[0141] Considering the security of user plane control information associated with the first PDU session, the core network can also instruct the first access network device on the security policy of the user plane control information at the MAC layer, so as to achieve the security of user plane control information above the MAC layer.

[0142] For example, considering that user plane control information may carry important content, security processing of the user plane control information is required at the MAC layer to prevent such content from being leaked or tampered with. In this case, the security strategy could be either to provide security protection for the user plane control information at the MAC layer, or to provide security protection for the user plane control information at the MAC layer.

[0143] For example, even if the content carried by the user plane control information is leaked or tampered with, the impact is not significant, so no security processing is needed for the user plane control information at the MAC layer. In this case, the security policy can be either not to protect the user plane control information or not to protect the user plane control information at the MAC layer.

[0144] Alternatively, user plane control information can be protected at the MAC layer, or it can be left unprotected. In either case, the security policy can be to prioritize / prefer security protection for user plane control information, or to prioritize / prefer security protection for user plane control information at the MAC layer.

[0145] In possible implementations, the security policy may be carried in a first field included in the first request message. The first access network device receives the first request message and determines the security policy based on the first field. The specific name of the first field is not limited in this application embodiment. For example, the first field may be called the MAC security policy indication field, or the first field may be called the User Plane Control Unit (PDU) security policy indication field, or the first field may also be called the security policy indication field.

[0146] In some embodiments, the first field is information of an enumeration type. When the value is required, it indicates that the security policy requires security processing of user plane control information at the MAC layer; when the value is preferred, it indicates that the security policy prioritizes security processing of user plane control information at the MAC layer; when the value is not needed, it indicates that the security policy does not require security processing of user plane control information at the MAC layer.

[0147] In other embodiments, the first field may also be an enumerated type of information. When the value is "required," it indicates that security processing of the user plane control information is required; when the value is "preferred," it indicates that security processing of the user plane control information is prioritized; and when the value is "not needed," it indicates that security processing of the user plane control information is not required. In this case, it can be assumed that security processing of the user plane control information refers to security processing of the user plane control information at the MAC layer. Alternatively, the core network may additionally indicate that the user plane control information is MAC layer user plane control information, so that the first access network device can determine the security policy based on the first field and the additional indication from the core network. For example, if the value of the first field is "required," and the core network additionally indicates that the user plane control information is MAC layer user plane control information, then the security policy is that security processing of the user plane control information is required at the MAC layer.

[0148] In possible implementations, the security policy of the user plane control information associated with the first PDU session at the MAC layer is determined by the first access network device itself. For example, to ensure the security of the user plane control information, the default security policy can be that the user plane control information needs to be protected at the MAC layer.

[0149] Understandably, due to capability limitations, the first access network device may or may not support secure processing of user plane control information at the MAC layer. Therefore, if the first access network device supports secure processing of user plane control information at the MAC layer, it can determine that the security policy requires or preferably requires secure protection of user plane control information at the MAC layer. However, if the first access network device does not support secure processing of user plane control information at the MAC layer, even though secure protection of user plane control information at the MAC layer is required, the first access network device cannot perform secure processing of user plane control information at the MAC layer. In this case, the first access network device can determine that the security policy does not require secure protection of user plane control information at the MAC layer.

[0150] S702. The first access network device, according to the security policy, refuses to establish the first PDU session.

[0151] After determining the security policy, the first access network device can decide whether to establish or refuse the establishment of the first PDU session based on its own capabilities. Here, the capabilities of the first access network device include whether it supports secure processing of user plane control information at the MAC layer. If the security policy requires secure processing of user plane control information at the MAC layer, but the first access network device does not support such processing, then it can refuse the establishment of the first PDU session. If the first access network device supports secure processing of user plane control information at the MAC layer, it can establish the first PDU session, and then execute S703. Alternatively, S702 can be replaced with: The first access network device determines whether to establish the first PDU session based on the security policy. If the security policy requires secure processing of user plane control information at the MAC layer, but the first access network device does not support secure processing of user plane control information at the MAC layer, then the first access network device will refuse to establish the first PDU session. Conversely, if the security policy requires secure processing of user plane control information at the MAC layer, and the first access network device supports secure processing of user plane control information at the MAC layer, then the first access network device may establish the first PDU session and subsequently execute S703.

[0152] Optionally, when the first access network device refuses to establish a first PDU session, the first access network device can also inform the core network of the reason for refusing to establish the first PDU session. For example, the first access network device can send a first reason value to the core network, which indicates the reason for refusing to establish the first PDU session. For example, the first reason value is that the first access network device does not support security protection for user plane control information at the MAC layer. The first reason value can be included in the session establishment response message.

[0153] S703. The first access network device determines, according to the security policy, whether to perform security processing on user plane control information at the MAC layer.

[0154] The first access network device can determine whether to perform secure processing of user plane control information at the MAC layer based on a security policy and its own capabilities. Alternatively, in a dual-connectivity scenario, the first access network device can determine whether to perform secure processing of user plane control information at the MAC layer based on a security policy and the capabilities of both the first and second access network devices. Here, the capabilities of the second access network device include whether it supports secure processing of user plane control information at the MAC layer.

[0155] It should be noted that the two access network devices can exchange capabilities when establishing an Xn link. For example, when access network device A requests to establish an Xn link with access network device B, access network device A can send its capability information to access network device B. This capability information indicates whether access network device A supports secure processing of user plane control information at the MAC layer. Similarly, before S701, during the establishment of an Xn link between the first and second access network devices, the second access network device can send first capability information to the first access network device. This first capability information indicates whether the second access network device supports secure processing of user plane control information at the MAC layer (Figure 7 uses this as an example). Of course, if the first access network device requests to establish an Xn link with the second access network device, the first access network device can also send its own capability information to the second access network device. This capability information indicates whether the first access network device supports secure processing of user plane control information at the MAC layer.

[0156] Depending on the security policy, the capabilities of the first access network device and the second access network device, the result of the first access network device determining whether to perform secure processing on user plane control information at the MAC layer will also differ, or the behavior of the first access network device after receiving the first establishment request will also differ. Specifically, there are several possible subsequent behaviors of the first access network device, which are described below in conjunction with situations A to C.

[0157] Scenario A: The security policy requires security protection for user plane control information.

[0158] In scenario A, if the first access network device supports security protection of user plane control information at the MAC layer, then the first access network device can determine to perform secure processing of the user plane control information at the MAC layer. The condition that "the security policy requires security protection of user plane control information, and the first access network device supports security protection of user plane control information at the MAC layer" can be considered a condition for the first access network device to perform secure processing of user plane control information at the MAC layer (for example, referred to as condition 1). If condition 1 is met, the first access network device can perform secure processing of user plane control information at the MAC layer. If the first access network device determines to perform secure processing of user plane control information at the MAC layer, the first access network device can enable the security processing function, or enable the MAC security processing function, or enable the security policy, or enable the security policy at the MAC layer.

[0159] Furthermore, in a dual-connectivity scenario, if the second access network device supports security protection of user plane control information at the MAC layer, it can also perform secure processing of the user plane control information at the MAC layer to ensure its security. The condition that "the security policy requires security protection of user plane control information, and both the first and second access network devices support security protection of user plane control information at the MAC layer" can be considered a condition for the first access network device to perform secure processing of user plane control information at the MAC layer (for example, referred to as condition 2).

[0160] For the second access network device, it is unaware whether the first access network device performs security processing on user plane control information at the MAC layer. If the second access network device makes its own decision on whether to perform security processing on user plane control information at the MAC layer, there may be inconsistencies in the security policies of the first and second access network devices. For example, the first access network device may perform security processing on user plane control information at the MAC layer, while the second access network device may not, thus failing to guarantee the security of the user plane control information. Therefore, the first access network device performs security processing on user plane control information at the MAC layer, and the second access network device supports security protection for user plane control information at the MAC layer. The first access network device can instruct the second access network device to perform security processing on user plane control information at the MAC layer. For example, the first access network device can send a first indication message to the second access network device, which can be used to instruct the second access network device to perform security protection for user plane control information at the MAC layer. Accordingly, the second access network device determines, based on the first instruction information, to perform secure processing of user plane control information at the MAC layer. This ensures that both the first and second access network devices perform secure processing of user plane control information at the MAC layer, thereby reducing the risk of user plane control information being leaked or tampered with.

[0161] It is understandable that the second access network device supports secure processing of user plane control information at the MAC layer. Therefore, the second access network device can securely process user plane control signaling associated with the data of the first PDU session from the first access network device, thereby ensuring the secure transmission of the first PDU session's data in the second access network device. Thus, when the first access network device performs secure processing of user plane control information at the MAC layer and instructs the second access network device to do the same, the first access network device can migrate the data transmission of the first PDU session to the second access network device. This ensures the secure transmission of the first PDU session's data while reducing the load on the first access network device. Migrating the data transmission of the first PDU session to the second access network device can also be understood as offloading the data of the first PDU session to the second access network device.

[0162] In scenario A, if the first access network device supports security protection of user plane control information at the MAC layer, but the second access network device does not, the first access network device can determine that it should perform secure processing of the user plane control information at the MAC layer and should not send the data of the first PDU session to the second access network device. Since the second access network device does not support secure processing of user plane control information at the MAC layer, it cannot perform secure processing of the user plane control signaling associated with the data of the first PDU session from the first access network device. Therefore, it cannot guarantee the secure transmission of the first PDU session data to the second access network device. Thus, to ensure the secure transmission of the first PDU session data, the first access network device should not send the first PDU session data to the second access network device. This can be replaced by saying that the data transmission of the first PDU session should not be migrated / distributed to the second access network device.

[0163] The condition that "the security policy requires security protection for user plane control information, the first access network device supports security protection of user plane control information at the MAC layer, and the second access network device does not support security protection of user plane control information at the MAC layer" can be used as a condition for the first access network device to perform secure processing of user plane control information at the MAC layer (for example, referred to as condition 3). When condition 3 is met, the first access network device performs secure processing of user plane control information at the MAC layer and does not send the data of the first PDU session to the second access network device. In this way, the data of the first PDU session can be avoided from being diverted to the second access network device, which could lead to the leakage or tampering of the data of the first PDU session because the second access network device does not support secure processing of user plane control information at the MAC layer.

[0164] Scenario B: The preferred security strategy is to protect user plane control information.

[0165] In scenario B, if the first access network device does not support security protection for user plane control information at the MAC layer, then the first access network device determines that it can forgo security processing of user plane control information at the MAC layer. In other words, one condition (for example, referred to as condition 4) under which the first access network device determines that it will not perform security processing on user plane control information at the MAC layer is: the security policy is to preferentially protect user plane control information, and the first access network device does not support security protection for user plane control information at the MAC layer.

[0166] When condition 4 is met, the first access network device determines that it can disable security processing of user plane control information at the MAC layer, or the first access network device disables security processing functionality, or disables MAC security processing functionality. In this case, the first access network device can also send a second indication message to the second access network device, which indicates that the second access network device can disable security processing of user plane control information at the MAC layer. Accordingly, the second access network device receives the second indication message and will not perform security processing of user plane control information at the MAC layer. The second access network device receives the second indication message and disables security processing functionality, or disables MAC security processing functionality. Additionally, the first access network device can inform the core network of the reason for not performing security processing of user plane control information at the MAC layer. For example, the first access network device can send a second reason value to the core network, which indicates the reason for not performing security processing of user plane control information at the MAC layer.

[0167] Alternatively, if the first access network device supports security protection of user plane control information at the MAC layer, then for the security of user plane control information, the first access network device can perform secure processing on the user plane control information at the MAC layer. One condition for the first access network device to perform secure processing of user plane control information at the MAC layer (for example, referred to as condition 5) can be: the security strategy is to preferentially protect user plane control information, and the first access network device supports security protection of user plane control information at the MAC layer.

[0168] When condition 5 is met, the first access network device can determine that user plane control information can be securely processed at the MAC layer. In this case, if the second access network device supports security protection of user plane control information at the MAC layer, the first access network device can also instruct the second access network device to perform secure processing of user plane control information at the MAC layer. Accordingly, the second access network device enables the security processing function / MAC security processing function according to the instruction of the first access network device. In addition, the first access network device can also inform the core network that the first access network device has enabled the security processing function. Optionally, the first access network device can also send the data of the first PDU session to the second access network device, which can reduce the load of the first access network device while ensuring the secure transmission of the data of the first PDU session.

[0169] If the second access network device does not support security protection for user plane control information at the MAC layer, the first access network device should not send data of the first PDU session to the second access network device. This is to avoid leakage or tampering of the first PDU session data due to the second access network device's lack of support for secure processing of user plane control information at the MAC layer. Additionally, the first access network device can also inform the core network that it has not enabled security processing functionality.

[0170] Alternatively, if the first access network device supports security protection of user plane control information at the MAC layer, it may choose not to perform security processing on the user plane control information at the MAC layer to reduce processing complexity. One condition (e.g., referred to as condition 6) for the first access network device not to perform security processing on user plane control information at the MAC layer can be considered as follows: the security policy preferentially prioritizes security protection of user plane control information, and the first access network device supports security protection of user plane control information at the MAC layer.

[0171] When condition 6 is met, the first access network device can refrain from performing security processing on user plane control information at the MAC layer. In this case, the first access network device can also send a second indication message to the second access network device, which instructs the second access network device to refrain from performing security processing on user plane control information at the MAC layer. Furthermore, since the security strategy preferentially involves performing security processing on user plane control information—that is, whether or not security processing is performed—to reduce the load on the first access network device, it can migrate the data of the first PDU session to the second access network device. For example, the first access network device sends the data of the first PDU session to the second access network device. It should be noted that the order in which the first access network device sends the data of the first PDU session and the second indication message to the second access network device is not limited in this embodiment.

[0172] Case C: The security policy is that the user plane control information does not require security protection.

[0173] When the security policy stipulates that user plane control information does not require security protection, the first access network device determines that it will not perform security protection on user plane control information at the MAC layer. It can be considered that a condition (e.g., condition 7) under which the first access network device does not perform security processing on user plane control information at the MAC layer is: the security policy stipulates that user plane control information does not require security protection. When condition 7 is met, the first access network device can determine that it can perform no security processing on user plane control information at the MAC layer. That is, when the security policy stipulates that user plane control information does not require security protection, regardless of whether the first access network device supports security processing of user plane control information at the MAC layer, the first access network device will not enable the security processing function, or will not enable the MAC security processing function. Correspondingly, the first access network device can instruct the second access network device not to perform security processing on user plane control information at the MAC layer. For example, the first access network device can send a second indication message to the second access network device. The second access network device receives the second indication message and either does not enable the security processing function, or does not enable the MAC security processing function.

[0174] When both the first access network device and the second access network device perform secure processing of user plane control information at the MAC layer, the key used by the second access network device can originate from the first access network device. For example, the first access network device can send a first key to the second access network device, which is generated based on the second key used by the first access network device.

[0175] For ease of understanding, please refer to Figure 8, which illustrates the process of generating the first key from the second key. In Figure 8, S-K_gNB is the first key, and K_gNB is the second key. It can be understood that the first access network device can derive K_MACint and K_MACenc from K_gNB. K_MACint is used to protect user plane control information at the MAC layer using a specific integrity algorithm; K_MACint can be called the MAC integrity protection key. K_MACenc is used to protect user plane control information at the MAC layer using a specific encryption algorithm; K_MACenc is also called the MAC encryption key. It should be noted that there are no restrictions on the specific names of K_MACint and K_MACenc; for example, K_MACint can be K_RRCint, and K_MACenc can be K_RRCenc.

[0176] The first access network device generates an S-K_gNB based on the K_gNB. For example, the first access network device derives the S-K_gNB using the K_gNB and SN counter. The first access network device sends the S-K_gNB to the second access network device, which uses the K_MACint and K_MACenc derived from the S-K_gNB to perform secure processing of user plane control information at the MAC layer.

[0177] In communication method 700, the MN side determines the security policy for user plane control information at the MAC layer. Based on the determined security policy and whether the MN and SN support security protection of user plane control information at the MAC layer, it decides whether to perform secure processing of user plane control information at the MAC layer and whether to allow the SN to perform security protection of user plane control information at the MAC layer. If the MN allows the SN to perform security protection of user plane control information at the MAC layer, it can instruct the SN to perform security protection of user plane control information at the MAC layer via signaling. Accordingly, the SN performs security protection of user plane control information at the MAC layer based on the MN's instruction. If the SN does not receive the MN's instruction, then it does not perform security protection of user plane control information at the MAC layer. In this way, the SN and MN can maintain consistency on whether to perform security protection of user plane control information at the MAC layer, thereby achieving secure processing of user plane control information and improving the security of user plane control information.

[0178] Considering the capabilities of different terminal devices, some devices may support MAC layer security protection for user plane control information, while others may not. If a terminal device supports MAC layer security protection for user plane control information, it can be considered to have MAC layer security capabilities. Furthermore, even if a terminal device supports MAC layer security protection for user plane control information, the network side may not perform security processing on the user plane control information at the MAC layer. In this case, it is unnecessary for the terminal device to enable MAC security processing, or the terminal device's MAC layer security capability may be optional and not mandatory.

[0179] From the network side's perspective, it is unaware of whether the terminal device possesses MAC security capabilities, and therefore cannot adaptively enable MAC security functions on the terminal device. To address this, the terminal device can also report to the network side whether it possesses MAC security capabilities, allowing the network side to determine whether the terminal device has such capabilities.

[0180] For example, please refer to Figure 9, which is a flowchart illustrating the communication method 900 provided in an embodiment of this application. Figure 9 describes the communication method 900 from the perspective of interaction between the terminal device, the first access network device, and the core network. As shown in Figure 9, the flowchart of the communication method 900 provided in an embodiment of this application includes the following steps.

[0181] S901. The terminal device establishes an RRC connection with the first access network device.

[0182] During the process of establishing an RRC connection between the terminal device and the first access network device, the terminal device may send second capability information to the first access network device. The second capability information is used to indicate whether the terminal device supports MAC layer security processing, or to indicate whether the terminal device has MAC security capabilities.

[0183] In possible implementations, the first capability information may be included in message 5 (Msg5) during the random access procedure. For example, the first capability information may be included in the NAS PDU in Msg5; or, the first capability information may be included in the UE capability information element in Msg5.

[0184] S902, The first access network device sends the first capability information to the AMF.

[0185] Accordingly, the AMF receives the first capability information. This first capability information may be included in an Initial UE message. For example, the first access network device sends an Initial UE message to the AMF, which includes a NAS PDU, and the NAS PDU includes the first capability information.

[0186] S903, AMF, AUSF, and UDM perform user authentication for terminal devices.

[0187] User authentication refers to verifying the legitimacy of a user. The AMF can request authentication of the user's legitimacy from both the AMF and the UDM. The user authentication process will not be described in detail here. The UDM stores the user's subscription information, which includes primary capability information. Therefore, the AMF can determine whether the terminal device has MAC security capabilities based on the subscription information provided by the UDM.

[0188] S904. The terminal device receives third instruction information, which is used to enable the terminal device to enable MAC security capabilities.

[0189] If the terminal device has MAC security capabilities, the core network can instruct the network side to enable MAC security capabilities. For example, when an SMF network element requests to establish a first PDU session, it can instruct a security policy that requires secure processing of user plane control information at the MAC layer. If the first access network device determines that secure processing of user plane control information is required at the MAC layer, it can enable the terminal device to enable MAC security capabilities. For example, the first access network device can send a third instruction message to the terminal device, which enables the terminal device to enable MAC security capabilities. The first access network device can send the third instruction message to the terminal device in various possible ways, such as through a configuration message, which can be an RRC reconfiguration message.

[0190] Communication method 700 and communication method 900 can be combined with each other. For example, when a terminal device requests to establish a first PDU session, it can use communication method 900 to report the second capability information to the first access network device or the core network.

[0191] In the embodiments provided above, the methods provided by the embodiments of this application are described using a first access network device, a second access network device, or a terminal device as examples. In this application, each embodiment can be implemented independently or in combination based on certain inherent connections; in each embodiment, different implementation methods can be implemented in combination or independently. To achieve the functions in the methods provided by the embodiments of this application above, the steps executed by the terminal device can be implemented by the terminal device itself or by different functional entities constituting the terminal device. The steps executed by the first access network device can be implemented by the first access network device itself or by different functional entities constituting the first access network device. For example, the first access network device is an access network device, which can be a CU-DU architecture, where the CU can generate first indication information and the DU can send the first indication information. To achieve the functions in the methods provided by the embodiments of this application above, the terminal device and network device can include hardware structures and / or software modules, implementing the above functions in the form of hardware structures, software modules, or hardware structures plus software modules. Whether a certain function is executed in the form of hardware structures, software modules, or hardware structures plus software modules depends on the specific application and design constraints of the technical solution.

[0192] Based on the same inventive concept as the method embodiments, this application provides a communication device. The communication device used to implement the above method in the embodiments of this application is described below with reference to the accompanying drawings. The content above can be used in subsequent embodiments, and repeated content will not be repeated.

[0193] Figure 10 is a schematic block diagram of a communication device 1000 provided in an embodiment of this application. The communication device 1000 can be a first access network device or a terminal device in the above embodiments. For example, the communication device 1000 can be the terminal device in Figure 1; or, the communication device 1000 can be a chip (system) in the terminal device; or, the communication device 1000 can be a software module of the terminal device. The communication device 1000 can correspondingly implement the functions or steps implemented by the terminal device in the above method embodiments. For another example, the communication device 1000 can be the access network device in Figure 1; or, the communication device 1000 can be a chip (system) in the access network device; or, the communication device 1000 can be a software module of the access network device. The communication device 1000 can correspondingly implement the functions or steps implemented by the access network device in the above method embodiments. The communication device 1000 may include a processing module 1010 and a transceiver module 1020. Optionally, it may also include a storage module, which can be used to store instructions (code or program) and / or data. The storage module may be, for example, a memory. The processing module 1010 and the transceiver module 1020 can be coupled to the storage module. For example, the processing module 1010 can read instructions (code or program) and / or data from the storage module to implement the corresponding method. When the communication device 1000 is a chip in a terminal device or network device, the storage module can be a storage module within the chip, such as a register or cache. For example, the storage module can also be a storage module located outside the chip in the terminal device or network device, such as a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, such as random access memory (RAM). The above-mentioned units can be set independently or partially or completely integrated.

[0194] Processing module 1010 may be a processor or controller, such as a general-purpose central processing unit (CPU), a general-purpose processor, a digital signal processing unit (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc. Transceiver module 1020 is a transceiver, interface circuit, bus, pin, or other possible communication interface for receiving signals from other devices. For example, when the device is implemented as a chip, transceiver module 1020 is an interface circuit for the chip to receive signals from other chips or devices, or an interface circuit for the chip to send signals to other chips or devices.

[0195] In one implementation, the communication device 1000 can correspondingly implement the behavior and functions of the first access network device in the above method embodiments. The communication device 1000 can be an access network device, a component (e.g., a chip or circuit) within the access network device, a part of a chip or chipset in the access network device used to execute the relevant method functions, or a software module in the access network device capable of implementing the above communication method; no limitation is imposed. For details, please refer to the relevant content of the foregoing method embodiments, which will not be repeated here.

[0196] For example, the processing module 1010 is used to determine the security policy of the user plane control information associated with the first PDU session of the terminal device at the MAC layer; according to the security policy, it rejects the establishment of the first PDU session, or, according to the security policy, determines whether to perform security processing on the user plane control information at the MAC layer.

[0197] As an optional implementation, the transceiver module 1020 is used to receive first capability information from the second access network device, which is used to indicate whether the second access network device supports MAC layer security processing.

[0198] As an optional implementation approach, security strategies include: requiring security protection for user plane control information, preferably requiring security protection for user plane control information, or not requiring security protection for user plane control information.

[0199] As an optional implementation, the processing module 1010 is specifically used to: determine whether to perform security processing on user plane control information at the MAC layer based on the security policy and whether the first access network device supports MAC layer security processing; or, determine whether to perform security processing on user plane control information at the MAC layer based on the security policy, whether the first access network device supports MAC layer security processing, and whether the second access network device supports MAC layer security processing.

[0200] As an optional implementation, the processing module 1010 is specifically used to: if the security policy requires security protection for user plane control information, and the first access network device does not support security protection for user plane control information at the MAC layer, then the establishment of the first PDU session is rejected.

[0201] As an optional implementation, the transceiver module 1020 is also used to send a first reason value, which indicates the reason for rejecting the establishment of the first PDU session.

[0202] As an optional implementation, the security strategy requires security protection for user plane control information. Specifically, the processing module 1010 is used to: if the first access network device supports security protection for user plane control information at the MAC layer, then determine to perform security processing on the user plane control information at the MAC layer.

[0203] As an optional implementation, the second access network device supports security protection of user plane control information at the MAC layer. The transceiver module 1020 is also used to: send a first indication message to the second access network device, which is used to instruct the second access network device to perform security processing on user plane control information at the MAC layer.

[0204] As an optional implementation, the second access network device does not support security protection of user plane control information at the MAC layer, and the transceiver module 1020 is also used to: not send the data of the first PUD session to the second access network device.

[0205] As an optional implementation, the preferred security strategy is to provide security protection for user plane control information. The processing module 1010 is specifically used for: the first access network device does not support security protection for user plane control information at the MAC layer, and determines that no security processing is performed on user plane control information at the MAC layer; or, the first access network device supports security protection for user plane control information at the MAC layer, and determines that security processing is performed on user plane control information at the MAC layer; or, the first access network device supports security protection for user plane control information at the MAC layer, and determines that no security processing is performed on user plane control information at the MAC layer.

[0206] As an optional implementation, the first access network device supports security protection of user plane control information at the MAC layer and security processing of user plane control information at the MAC layer. The transceiver module 1020 is also used to: not send the data of the first PUD session to the second access network device.

[0207] As an optional implementation, the first access network device supports security protection of user plane control information at the MAC layer, and does not perform security processing on user plane control information at the MAC layer. The transceiver module 1020 is also used to: send data of the first PDU session to the second access network device, and the first access network device sends second indication information to the second access network device, the second indication information being used to instruct the second access network device not to perform security processing on user plane control information at the MAC layer.

[0208] As an optional implementation, the transceiver module 1020 is also used to: send a second reason value, which indicates the reason why user plane control information is not securely processed at the MAC layer.

[0209] As an optional implementation, the security strategy is to not require security protection for user plane control information. Specifically, the processing module 1010 is used to: determine that no security processing is performed on user plane control information at the MAC layer.

[0210] As an optional implementation, the transceiver module 1020 is also used to: send a first key, which is generated based on a second key used by the first access network device.

[0211] As an optional implementation, the transceiver module 1020 is also used to: send second capability information, which is used to indicate whether the terminal device supports MAC layer security protection.

[0212] As an optional implementation, the second capability information is included in the NAS PDU in the initial user equipment message.

[0213] In one implementation, the communication device 1000 can correspondingly implement the behavior and functions of the terminal device in the above method embodiments. The communication device 1000 can be a terminal device, a component (e.g., a chip or circuit) within the terminal device, a part of a chip or chipset in the terminal device used to execute the relevant method functions, or a software module in the terminal device capable of implementing the above communication method; no limitation is imposed. For details, please refer to the relevant content of the foregoing method embodiments, which will not be repeated here.

[0214] For example, processing module 1010 and / or transceiver module 1020 are used to establish an RRC connection with the first access network device. Transceiver module 1020 is also used to send second capability information to the first access network device, which is used to indicate whether the terminal device supports MAC layer security protection.

[0215] As an optional implementation, the second capability information is included in message 5 during the random access process.

[0216] As an optional implementation, the transceiver module 1020 is also used to receive third indication information, which is used to indicate that the MAC protection function is enabled.

[0217] When the communication device 1000 is a chip-based device or circuit, the transceiver module can be an input / output circuit and / or a communication interface; the processing module is an integrated processor, microprocessor, or integrated circuit.

[0218] Figure 11 is a schematic block diagram of a communication device 1100 provided in an embodiment of this application. The communication device 1100 can be a terminal device or a first access network device as described in the above embodiments. For example, the communication device 1100 can be a terminal device in Figure 1 or a chip (system) within a terminal device. In this embodiment, the chip system can be composed of chips or may include chips and other discrete devices. Specific functions can be found in the descriptions of the above method embodiments. As another example, the communication device 1100 can be an access network device in Figure 1 or a chip (system) within an access network device. In this embodiment, the chip system can be composed of chips or may include chips and other discrete devices. Specific functions can be found in the descriptions of the above method embodiments.

[0219] The communication device 1100 includes one or more processors 1101, used to implement or support the communication device 1100 in implementing the functions of the terminal device or the first access network device in the methods provided in the embodiments of this application. For details, please refer to the detailed description in the method examples, which will not be repeated here. The processor 1101 can also be called a processing unit or processing module, and can implement certain control functions. The processor 1101 can be a general-purpose processor or a dedicated processor, etc. For example, it includes: a baseband processor, a central processing unit, an application processor, a modem processor, a graphics processor, an image signal processor, a digital signal processor, a video codec processor, a controller, a memory, and / or a neural network processor, etc. The baseband processor can be used to process communication protocols and communication data. The central processing unit can be used to control the communication device 1100 (e.g., a network device or a terminal device), execute software programs and / or process data. Different processors can be independent devices or integrated into one or more processors, for example, integrated on one or more application-specific integrated circuits.

[0220] In one design, processor 1101 may include program 1103 (sometimes referred to as code or instructions) that can be executed on processor 1101 to cause communication device 1100 to perform the methods described in the embodiments below. In yet another possible design, communication device 1100 includes circuitry (not shown in FIG11) for implementing the functions of the terminal device or the first access network device in the above embodiments.

[0221] In one design, the communication device 1100 may include one or more memories 1102 storing a program 1104 (sometimes referred to as code or instructions), which can be run on the processor 1101 to cause the communication device 1100 to perform the methods described in the above method embodiments.

[0222] In one design, the processor 1101 and / or memory 1102 may include an artificial intelligence (AI) module 1107 and an AI module 1108, which are used to implement AI-related functions. The AI ​​modules may be implemented through software, hardware, or a combination of both. For example, the AI ​​module may include a RAN intelligent controller (RIC) module. For example, the AI ​​module may be a near real-time RIC or a non-real-time RIC.

[0223] In one possible design, the processor 1101 and / or memory 1102 may also store data. The processor and memory may be configured separately or integrated together.

[0224] In one possible design, the communication device 1100 may further include a transceiver 1105 and / or an antenna 1106. The processor 1101, sometimes referred to as a processing unit, controls the communication device 1100. The transceiver 1105, sometimes referred to as a transceiver unit, transceiver, transceiver circuit, or transceiver, is used to realize the transmission and reception functions of the communication device 1100 through the antenna 1106.

[0225] In one possible design, the communication device 1100 may further include one or more of the following components: a wireless communication module, an audio module, an external memory interface, internal memory, a universal serial bus (USB) interface, a power management module, an antenna, a speaker, a microphone, an input / output module, a sensor module, a motor, a camera, or a display screen, etc. It is understood that in some embodiments, the communication device 1100 may include more or fewer components, or some components may be integrated, or some components may be separated. These components may be implemented in hardware, software, or a combination of software and hardware.

[0226] The communication device in the above embodiments can be a terminal device, a circuit, a chip applied in a terminal device, or other combined devices or components having the aforementioned terminal device. Alternatively, the communication device in the above embodiments can be a network device, a circuit, a chip applied in a network device, or other combined devices or components having the aforementioned network device. When the communication device is a terminal device or a network device, the transceiver module can be a transceiver, which may include an antenna and radio frequency circuits, etc., and the processing module can be a processor, such as a CPU. When the communication device is a chip system, the communication device can be an FPGA, a dedicated ASIC, a system-on-chip (SoC), a CPU, a network processor (NP), a DSP, a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips. The processing module can be the processor of the chip system. The transceiver module or communication interface can be the input / output interface or interface circuit of the chip system. For example, the interface circuit can be a code / data read / write interface circuit. The interface circuit can be used to receive code instructions (the code instructions are stored in memory and can be read directly from memory or through other devices) and transmit them to the processor; the processor can then execute the code instructions to perform the methods described in the above method embodiments. Alternatively, the interface circuit can also be a signal transmission interface circuit between a communication processor and a transceiver.

[0227] This application also provides a communication system comprising at least one terminal device and at least two access network devices, wherein the at least two access networks include a first access network device and a second access network device. The terminal device is a terminal apparatus for implementing functions related to the aforementioned communication method, and the first access network device is an access network device for implementing functions related to the aforementioned communication method. This application also provides a computer-readable storage medium including instructions that, when executed on a computer, cause the computer to perform the method executed by the terminal device or the first access network device in the aforementioned communication method.

[0228] This application also provides a computer program product, including computer program code, which, when executed, causes a computer to perform the method executed by the terminal device or the first access network device in the above-described communication method.

[0229] This application provides a chip system including a processor and potentially a memory, for implementing the functions of a terminal device or a first access network device in the aforementioned communication method. The chip system may be composed of a chip or may include chips and other discrete components.

[0230] To achieve the functions of the communication devices shown in Figures 10 and 11, this application embodiment also provides a chip, including a processor, for supporting the communication device in implementing the functions involved in the terminal device or the first access network device in the above method embodiments. In one possible design, the chip is connected to a memory or the chip includes a memory for storing necessary computer programs, instructions, and data for the communication device.

[0231] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0232] Those skilled in the art will recognize that the various illustrative logical blocks and steps described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.

[0233] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0234] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0235] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0236] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the essential contributing part of the technical solution of this application, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, external hard drives, ROM, RAM, magnetic disks, or optical disks.

[0237] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A communication method, characterized in that, The method is applied to a first access network device, and the method includes: The security policy of the user plane control information associated with the first protocol data unit (PDU) session of the terminal device in the media access control (MAC) layer is determined, and the first access network device is the master node of the terminal device. According to the security policy, the establishment of the first PDU session is rejected; or, according to the security policy, it is determined whether the user plane control information should be processed securely at the MAC layer.

2. The method as described in claim 1, characterized in that, The method further includes: The device receives first capability information from a second access network device, the first capability information being used to indicate whether the second access network device supports MAC layer security processing.

3. The method as described in claim 1 or 2, characterized in that, The security policy includes: The user plane control information needs to be securely protected; or, Preferably, the user plane control information is protected with security; or, There is no need to provide security protection for the user plane control information.

4. The method as described in claim 2 or 3, characterized in that, Based on the security policy, determining whether to perform security processing on the user plane control information at the MAC layer includes: Based on the security policy and whether the first access network device supports MAC layer security processing, determine whether to perform security processing on the user plane control information at the MAC layer; or... Based on the security policy, whether the first access network device supports MAC layer security processing, and whether the second access network device supports MAC layer security processing, it is determined whether to perform security processing on the user plane control information at the MAC layer, wherein the second access network device is an auxiliary node of the terminal device.

5. The method as described in claim 3, characterized in that, According to the security policy, denying the establishment of the first PDU session includes: The security policy requires that the user plane control information be protected, and if the first access network device does not support the protection of user plane control information at the MAC layer, then the establishment of the first PDU session will be rejected.

6. The method as described in claim 5, characterized in that, The method further includes: Send a first reason value, which indicates the reason for rejecting the establishment of the first PDU session.

7. The method as described in claim 4, characterized in that, The security policy requires security protection for the user plane control information. Based on the security policy, determining whether to perform security processing on the user plane control information at the MAC layer includes: If the first access network device supports security protection of user plane control information at the MAC layer, then it is determined that the user plane control information will be processed securely at the MAC layer.

8. The method as described in claim 7, characterized in that, The second access network device supports security protection of user plane control information at the MAC layer, and the method further includes: Send a first instruction message to the second access network device, the first instruction message being used to instruct the second access network device to perform secure processing of the user plane control information at the MAC layer.

9. The method as described in claim 7, characterized in that, The second access network device does not support security protection for user plane control information at the MAC layer, and the method further includes: The data of the first PUD session is not sent to the second access network device.

10. The method as described in claim 4, characterized in that, The security policy preferably protects the user plane control information. Based on the security policy, determining whether to perform security processing on the user plane control information at the MAC layer includes: The first access network device does not support security protection for user plane control information at the MAC layer, therefore it is determined that no security processing will be performed on the user plane control information at the MAC layer; or... The first access network device supports security protection for user plane control information at the MAC layer, and determines that the user plane control information is processed securely at the MAC layer; or, The first access network device supports security protection for user plane control information at the MAC layer, and determines that no security processing is performed on the user plane control information at the MAC layer.

11. The method as described in claim 10, characterized in that, The first access network device supports security protection of user plane control information at the MAC layer and security processing of the user plane control information at the MAC layer. The method further includes: The data of the first PUD session is not sent to the second access network device.

12. The method as described in claim 10, characterized in that, The first access network device supports security protection for user plane control information at the MAC layer, but does not perform security processing on the user plane control information at the MAC layer. The method further includes: Send the data of the first PDU session to the second access network device; Send a second indication message to the second access network device, the second indication message being used to instruct the second access network device not to perform security processing on the user plane control information at the MAC layer.

13. The method as described in claim 10, characterized in that, The method further includes: Send a second reason value, which indicates the reason why the user plane control information is not securely processed at the MAC layer.

14. The method as described in claim 4, characterized in that, The security policy stipulates that no security protection is required for the user plane control information. Based on this security policy, determining whether to perform security processing on the user plane control information at the MAC layer includes: It is determined that the user plane control information will not be processed securely at the MAC layer.

15. The method as described in claim 8, characterized in that, The method further includes: Send a first key, which is generated based on a second key used by the first access network device.

16. The method according to any one of claims 1-15, characterized in that, The method further includes: Send a second capability information, which is used to indicate whether the terminal device supports MAC layer security protection.

17. The method as described in claim 16, characterized in that, The second capability information is contained in the non-access stratum NAS PDU in the initial user equipment message.

18. A communication method, characterized in that, include: A Radio Resource Control (RRC) connection is established with a first access network device, which is the master node of the terminal device, and the terminal device is simultaneously connected to the first access network device and a second access network device. Send second capability information to the first access network device, the second capability information being used to indicate whether the terminal device supports security protection of the Media Access Control (MAC) layer.

19. The method as described in claim 18, characterized in that, The second capability information is included in message 5 during the random access process.

20. The method as described in claim 19, characterized in that, The method further includes: Receive a third instruction message, which is used to instruct the MAC protection function to be enabled.

21. A communication method, characterized in that, include: The first access network device obtains first capability information of the second access network device, the first capability information being used to indicate whether the second access network device supports secure processing of the Media Access Control (MAC) layer. The first access network device determines the security policy of the user plane control information associated with the first protocol data unit (PDU) session of the terminal device at the MAC layer. The first access network device is the master node of the terminal device, and the second access network device is the auxiliary node of the terminal device. The first access network device rejects the establishment of the first PDU session according to the security policy; or, the first access network device determines whether to perform security processing on the user plane control information at the MAC layer according to the security policy, the first capability information, and whether the first access network device supports MAC layer security processing.

22. A communication device, characterized in that, The communication device is the master node of the terminal device, and the communication device includes: The transceiver module is used to receive the establishment request of the first protocol data unit (PDU) session of the terminal device; The processing module is configured to determine the security policy of the user plane control information associated with the first PDU session at the Media Access Control (MAC) layer; and, based on the security policy, refuse the establishment of the first PDU session, or, based on the security policy, determine whether to perform security processing on the user plane control information at the MAC layer.

23. The apparatus as claimed in claim 22, characterized in that, The transceiver module is also used for: The device receives first capability information from a second access network device, the first capability information being used to indicate whether the second access network device supports MAC layer security processing.

24. The apparatus as claimed in claim 22 or 23, characterized in that, The security policy includes: The user plane control information needs to be securely protected; or, Preferably, the user plane control information is protected with security; or, There is no need to provide security protection for the user plane control information.

25. The apparatus as claimed in claim 23 or 24, characterized in that, The processing module is specifically used for: Based on the security policy and whether the first access network device supports MAC layer security processing, determine whether to perform security processing on the user plane control information at the MAC layer. or, Based on the security policy, whether the first access network device supports MAC layer security processing, and whether the second access network device supports MAC layer security processing, it is determined whether to perform security processing on the user plane control information at the MAC layer, wherein the second access network device is an auxiliary node of the terminal device.

26. The apparatus as claimed in claim 24, characterized in that, The processing module is specifically used for: The security policy requires that the user plane control information be protected, and if the first access network device does not support the protection of user plane control information at the MAC layer, then the establishment of the first PDU session will be rejected.

27. The apparatus as claimed in claim 26, characterized in that, The transceiver module is also used for: Send a first reason value, which indicates the reason for rejecting the establishment of the first PDU session.

28. The apparatus as claimed in claim 25, characterized in that, The processing module is specifically used for: If the first access network device supports security protection of user plane control information at the MAC layer, then it is determined that the user plane control information will be processed securely at the MAC layer.

29. The apparatus as claimed in claim 28, characterized in that, The second access network device supports security protection of user plane control information at the MAC layer, and the transceiver module is further used for: Send a first instruction message to the second access network device, the first instruction message being used to instruct the second access network device to perform secure processing of the user plane control information at the MAC layer.

30. The apparatus as claimed in claim 28, characterized in that, The second access network device does not support security protection for user plane control information at the MAC layer, and the transceiver module is further used for: The data of the first PUD session is not sent to the second access network device.

31. The apparatus as claimed in claim 25, characterized in that, The processing module is specifically used for: The first access network device does not support security protection for user plane control information at the MAC layer, therefore it is determined that no security processing will be performed on the user plane control information at the MAC layer; or... The first access network device supports security protection of user plane control information at the MAC layer, and determines that the user plane control information is processed securely at the MAC layer; or, The first access network device supports security protection for user plane control information at the MAC layer, and determines that no security processing is performed on the user plane control information at the MAC layer.

32. The apparatus as claimed in claim 31, characterized in that, The first access network device supports security protection of user plane control information at the MAC layer and security processing of the user plane control information at the MAC layer. The transceiver module is further configured to: The data of the first PUD session is not sent to the second access network device.

33. The apparatus as claimed in claim 31, characterized in that, The first access network device supports security protection for user plane control information at the MAC layer, but does not perform security processing on the user plane control information at the MAC layer. The transceiver module is further configured to: Send the data of the first PDU session to the second access network device; Send a second indication message to the second access network device, the second indication message being used to instruct the second access network device not to perform security processing on the user plane control information at the MAC layer.

34. The apparatus as claimed in claim 31, characterized in that, The transceiver module is also used for: Send a second reason value, which indicates the reason why the user plane control information is not securely processed at the MAC layer.

35. The apparatus as claimed in claim 25, characterized in that, The security policy stipulates that no security protection is required for the user plane control information. Based on this security policy, determining whether to perform security processing on the user plane control information at the MAC layer includes: It is determined that the user plane control information will not be processed securely at the MAC layer.

36. The apparatus as claimed in claim 29, characterized in that, The transceiver module is also used for: Send a first key, which is generated based on a second key used by the first access network device.

37. The apparatus as claimed in any one of claims 22-36, characterized in that, The transceiver module is also used for: Send a second capability information, which is used to indicate whether the terminal device supports MAC layer security protection.

38. The apparatus as claimed in claim 37, characterized in that, The second capability information is contained in the non-access stratum NAS PDU in the initial user equipment message.

39. A communication device, characterized in that, include: The processing module is used to determine the second capability information, which is used to indicate whether the communication device supports security protection of the Media Access Control (MAC) layer. The transceiver module is used to send the second capability information to a first access network device, the first access network device being the master node of the communication device, and the communication device being connected to both the first access network device and the second access network device.

40. The apparatus as claimed in claim 39, characterized in that, The second capability information is included in message 5 during the random access process.

41. The apparatus as claimed in claim 40, characterized in that, The transceiver module is also used for: Receive a third instruction message, which is used to instruct the MAC protection function to be enabled.

42. A communication device, characterized in that, The communication device includes at least one processor and at least one memory, the at least one memory being used to store a computer program, and the at least one processor being used to execute the computer program stored in the memory, causing the communication device to perform the method as claimed in any one of claims 1 to 17, or causing the communication device to perform the method as claimed in any one of claims 18 to 20.

43. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program that, when run on a computer, causes the computer to perform the method as described in any one of claims 1 to 17, or causes the computer to perform the method as described in any one of claims 18 to 20.

44. A computer program product, characterized in that, The computer program product includes a computer program that, when run on a computer, causes the computer to perform the method as described in any one of claims 1 to 17, or causes the computer to perform the method as described in any one of claims 18 to 20.

45. A chip or chip system, characterized in that, The chip or chip system includes: At least one processor and an interface, the at least one processor being configured to call and execute instructions from the interface, wherein when the at least one processor executes the instructions, it implements the method as described in any one of claims 1 to 17, or implements the method as described in any one of claims 18 to 20.

46. ​​A communication system, characterized in that, The communication system includes: a first access network device, a second access network device, and a terminal device, wherein the first access network device is the master node of the terminal device, and the second access network device is the auxiliary node of the terminal device; wherein, the first access network device is used for: Receive the request to establish a first Protocol Data Unit (PDU) session from the terminal device; Determine the security policy of the user plane control information associated with the first PDU session at the MAC layer; Obtain first capability information of the second access network device, wherein the first capability information is used to indicate whether the second access network device supports secure processing of the Media Access Control (MAC) layer. According to the security policy, the establishment of the first PDU session is rejected; or, according to the security policy, the user plane control information is determined to be subject to security processing at the MAC layer based on whether the first capability information and the first access network device support MAC layer security processing.

Citation Information

Patent Citations

  • Security protection method and device and access network equipment

    CN110167018A

  • Security activation method and communication device

    CN115396884A

  • User plane security policy configuration method and related equipment

    CN115696385A

  • Method and device for controlling security function

    US20210092612A1