Communication method and communication apparatus
By generating privacy computation rules in the communication system, user plane network elements, access network equipment, and terminals are instructed to perform privacy computations, which solves the problem of ensuring user data privacy and security in existing user plane protocols and reduces the computational burden on terminals and application servers.
Patent Information
- Application Number
- PCT/CN2025/101199
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-24
- Filing Date
- 2025-06-16
- Publication Date
- 2026-01-02
AI Technical Summary
How can privacy computing be applied to communication systems to ensure the privacy and security of user data, especially by reducing the computational performance requirements of terminals and application servers in existing user plane protocols?
By generating privacy computation rules in the session management network element on the network side, user plane network elements, access network devices and terminals are instructed to perform privacy computation and/or privacy computation marking. By utilizing the packet detection rules and QoS configuration in the existing user plane protocol, the computational requirements of terminals and application servers are reduced.
It enables privacy-preserving computation of user data in communication systems, ensuring user data privacy and security, while reducing the computational performance requirements of terminals and application servers and adapting to existing user plane protocols.
Smart Images

Figure CN2025101199_02012026_PF_FP_ABST
Abstract
Description
Communication method and communication apparatus
[0001] Cross-reference to Related Applications
[0002] This application claims priority to the Chinese Patent Application No. 202410823768.2, filed on June 24, 2024, and entitled "A Communication Method and Communication Apparatus", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0003] The present application relates to the field of communication technology, and in particular to a communication method and communication apparatus. BACKGROUND
[0004] With the progress of society and the increasing awareness of data ownership, the requirement for data privacy protection is also increasing. In the process of data processing and use, if it suffers from various security and privacy attacks from internal and external entities of the network, it will cause serious hidden troubles.
[0005] Privacy computing technology refers to a technical system that realizes data analysis and calculation under the premise of protecting data from being leaked to the outside. It involves cryptography, distributed computing, artificial intelligence, data science and many other fields. Compared with the traditional way of using data, privacy computing focuses more on the protection of data use process and calculation results, and its goal is to maximize the value of data under the premise of ensuring data security.
[0006] However, how to apply privacy computing to the communication system to protect the privacy and security of user data remains to be studied. SUMMARY
[0007] The embodiments of the present application provide a communication method and communication apparatus to protect the privacy and security of user data.
[0008] In a first aspect, an embodiment of the present application provides a communication method, which can be applied to a network side, such as a session management network element, a module (such as a circuit, a chip or a chip system, etc.) in the session management network element, or a logic node, a logic module or software capable of implementing all or part of the functions of the session management network element. The method comprises: obtaining a first privacy computing context, the first privacy computing context being used to indicate a data flow with a privacy computing requirement; determining a privacy computing rule according to the first privacy computing context, the privacy computing rule comprising at least one of a first privacy computing rule, a second privacy computing rule or a third privacy computing rule; wherein the first privacy computing rule is used to instruct a user plane network element to perform privacy computation and / or privacy computation marking on a data flow matching a packet detection rule in the first privacy computing rule, the second privacy computing rule is used to instruct an access network device to perform privacy computation and / or privacy computation marking on a data flow matching a quality of service (QoS) configuration in the second privacy computing rule, and the third privacy computing rule is used to instruct a terminal to perform privacy computation marking on a data flow matching a QoS rule in the third privacy computing rule.
[0009] Based on the above scheme, the session management network element generates at least one of the first privacy computing rule, the second privacy computing rule or the third privacy computing rule, wherein the first privacy computing rule instructs the user plane network element to perform privacy computation and / or privacy computation marking, the second privacy computing rule instructs the access network device to perform privacy computation and / or privacy computation marking, and the third privacy computing rule instructs the terminal to perform privacy computation marking. The method can implement privacy computation in a communication system, perform privacy computation on user data, and protect the privacy and security of user data. Moreover, when the generated privacy computing rule instructs the user plane network element and / or the access network device to perform privacy computation, the terminal and / or the application server do not need to perform privacy computation, and thus the demand for the computing performance of the terminal and / or the application server can be reduced.
[0010] In a possible design, the method further comprises: sending the first privacy computing rule to the user plane network element.
[0011] Based on the above scheme, the user plane network element can perform privacy calculation and / or privacy calculation marking on the data flow matched with the packet detection rule in the first privacy calculation rule according to the first privacy calculation rule, which can apply privacy calculation to the communication system, perform privacy calculation on user data, and protect user data privacy and security. Moreover, when the first privacy calculation rule instructs the user plane network element to perform privacy calculation, the terminal and / or the application server do not need to perform privacy calculation, thereby reducing the requirement for the computing performance of the terminal and / or the application server. In addition, since the first privacy calculation rule contains the packet detection rule in the existing user plane protocol, the existing user plane protocol is adapted, and the change to the existing user plane protocol is small.
[0012] In a possible design, the first privacy calculation rule includes the packet detection rule and first indication information; or the first privacy calculation rule includes the packet detection rule, and the packet detection rule includes the first indication information; where the first indication information is used to instruct the user plane network element to perform privacy calculation and / or privacy calculation marking on the data flow matched with the packet detection rule.
[0013] Based on the above scheme, by adding the first indication information, the user plane network element can be accurately instructed to perform privacy calculation and / or privacy calculation marking on the data flow matched with the packet detection rule. Moreover, the first indication information can be used to perform privacy calculation only on the data flow that needs to perform privacy calculation, thereby providing differentiated services for users.
[0014] In a possible design, the method further includes: sending the second privacy calculation rule to the access network device.
[0015] Based on the above scheme, the access network device can perform privacy calculation and / or privacy calculation marking on the data flow matched with the QoS configuration in the second privacy calculation rule according to the second privacy calculation rule, which can apply privacy calculation to the communication system, perform privacy calculation on user data, and protect user data privacy and security. Moreover, when the second privacy calculation rule instructs the access network device to perform privacy calculation, the terminal and / or the application server do not need to perform privacy calculation, thereby reducing the requirement for the computing performance of the terminal and / or the application server. In addition, since the second privacy calculation rule contains the QoS configuration in the existing user plane protocol, the existing user plane protocol is adapted, and the change to the existing user plane protocol is small.
[0016] In a possible design, the second privacy calculation rule includes the QoS configuration and second indication information; or the second privacy calculation rule includes the QoS configuration, and the QoS configuration includes the second indication information; where the second indication information is used to instruct the access network device to perform privacy calculation and / or privacy calculation marking on the data flow matched with the QoS configuration.
[0017] Based on the above scheme, by adding the second indication information, the access network device can be accurately instructed to perform privacy computation and / or privacy computation marking on the data flow matching the QoS configuration. Moreover, the second indication information can be used to perform privacy computation only on the data flow that needs to perform privacy computation, thereby providing differentiated services for users.
[0018] In a possible design, the method further includes: sending the third privacy computation rule to the terminal.
[0019] Based on the above scheme, the terminal can perform privacy computation marking on the data flow matching the QoS rule in the third privacy computation rule according to the third privacy computation rule, which can implement application of privacy computation to the communication system and privacy computation on user data, thereby protecting user data privacy and security. Moreover, the third privacy computation rule instructs the terminal to perform privacy computation marking, without the need for the terminal and / or the application server to perform privacy computation, thereby reducing the requirement for the computing performance of the terminal and / or the application server. In addition, since the third privacy computation rule includes the QoS rule in the existing user plane protocol, the existing user plane protocol is adapted, and the change to the existing user plane protocol is small.
[0020] In a possible design, the third privacy computation rule includes the QoS rule and third indication information; or the third privacy computation rule includes the QoS rule, and the QoS rule includes the third indication information; where the third indication information is used to instruct the terminal to perform privacy computation marking on the data flow matching the QoS rule.
[0021] Based on the above scheme, by adding the third indication information, the terminal can be accurately instructed to perform privacy computation marking on the data flow matching the QoS rule. Moreover, the third indication information can be used to perform privacy computation only on the data flow that needs to perform privacy computation, thereby providing differentiated services for users.
[0022] In a possible design, the first privacy computation context includes any one or more of the following: a user identifier, a service identifier, a ciphertext computation function enabling indication, or a privacy computation algorithm identifier; where the service identifier is used to indicate the data flow.
[0023] Based on the above scheme, by the first privacy computation context, information related to privacy computation of the user can be accurately indicated, which is helpful for the session management network element to accurately determine the privacy computation rule, and further helpful for implementing privacy computation on user data, thereby protecting user data privacy and security.
[0024] In a second aspect, an embodiment of the present application provides a communication method, which can be applied to a user plane network element on a network side, a module (such as a circuit, a chip or a chip system, etc.) in the user plane network element, or a logic node, a logic module or software capable of realizing all or part of the functions of the user plane network element. Alternatively, the method can also be applied to an access network device on the network side, a module (such as a circuit, a chip or a chip system, etc.) in the access network device, or a logic node, a logic module or software capable of realizing all or part of the functions of the access network device. Alternatively, the method can also be applied to a terminal or a communication module in the terminal, or a circuit or a chip (such as a modem chip, also known as a baseband chip, or a SoC chip or a SIP chip containing a modem core) responsible for communication functions in the terminal. The method comprises: obtaining an encrypted data stream; processing the encrypted data stream according to a privacy calculation rule matched with the encrypted data stream to obtain a processed encrypted data stream; and sending the processed encrypted data stream; wherein the privacy calculation rule comprises one of a first privacy calculation rule, a second privacy calculation rule or a third privacy calculation rule; wherein the first privacy calculation rule is used to instruct the user plane network element to perform privacy calculation and / or privacy calculation marking on a data stream matched with a packet detection rule in the first privacy calculation rule, the second privacy calculation rule is used to instruct the access network device to perform privacy calculation and / or privacy calculation marking on a data stream matched with a QoS configuration in the second privacy calculation rule, and the third privacy calculation rule is used to instruct the terminal to perform privacy calculation marking on a data stream matched with a QoS rule in the third privacy calculation rule.
[0025] Based on the above scheme, the user plane network element can perform privacy calculation and / or privacy calculation marking on a data stream matched with a packet detection rule in the first privacy calculation rule according to the first privacy calculation rule, which can realize application of privacy calculation to a communication system and privacy calculation on user data, thereby ensuring the privacy and security of user data. Moreover, when the first privacy calculation rule instructs the user plane network element to perform privacy calculation, the terminal and / or the application server do not need to perform privacy calculation, thereby reducing the demand for the calculation performance of the terminal and / or the application server. In addition, since the first privacy calculation rule contains a packet detection rule in an existing user plane protocol, it is adapted to the existing user plane protocol and has little change to the existing user plane protocol.
[0026] The access network device can perform privacy computation and / or privacy computation marking on a data flow matching the QoS configuration in the second privacy computation rule according to the second privacy computation rule, can implement application of privacy computation to the communication system, and implement privacy computation on user data to protect the privacy and security of the user data. Moreover, when the second privacy computation rule instructs the access network device to perform privacy computation, the terminal and / or the application server do not need to perform privacy computation, and thus the requirement on the computing performance of the terminal and / or the application server can be reduced. In addition, since the second privacy computation rule contains the QoS configuration in the existing user plane protocol, the existing user plane protocol is adapted, and the existing user plane protocol is changed little.
[0027] The terminal can perform privacy computation marking on a data flow matching the QoS rule in the third privacy computation rule according to the third privacy computation rule, can implement application of privacy computation to the communication system, and implement privacy computation on user data to protect the privacy and security of the user data. Moreover, since the third privacy computation rule instructs the terminal to perform privacy computation marking, the terminal and / or the application server do not need to perform privacy computation, and thus the requirement on the computing performance of the terminal and / or the application server can be reduced. In addition, since the third privacy computation rule contains the QoS rule in the existing user plane protocol, the existing user plane protocol is adapted, and the existing user plane protocol is changed little.
[0028] In a possible design, the obtaining the encrypted data stream includes: receiving a first encrypted data stream; the processing the encrypted data stream according to the privacy computation rule matched with the encrypted data stream to obtain a processed encrypted data stream includes: when the first privacy computation rule is used to instruct the user plane network element to perform privacy computation on a data flow matched with the packet detection rule, performing privacy computation on the first encrypted data stream according to the first privacy computation rule matched with the first encrypted data stream to obtain a second encrypted data stream; and the sending the processed encrypted data stream includes: sending the second encrypted data stream.
[0029] Based on the foregoing scheme, the privacy computation is performed by the user plane network element instead of the terminal or the application server in the data network, and thus the requirement on the computing performance of the terminal and / or the application server can be reduced.
[0030] In a possible design, the first privacy computation rule further includes a second privacy computation context; and the performing privacy computation on the first encrypted data stream according to the first privacy computation rule to obtain a second encrypted data stream includes: performing privacy computation on the first encrypted data stream according to the second privacy computation context to obtain the second encrypted data stream.
[0031] Based on the above scheme, the first encrypted data stream is processed according to the privacy computing rule matched with the encrypted data stream to obtain a processed encrypted data stream, and the processed encrypted data stream is sent, thereby realizing correct privacy computation of the first encrypted data stream and helping to protect user data privacy and security.
[0032] In a possible design, the second privacy computing context includes any one or more of the following: a service identifier, a ciphertext computing function enabling indication, or a privacy computing algorithm identifier; wherein the service identifier is used to indicate the first encrypted data stream.
[0033] Based on the above scheme, the second privacy computing context can accurately indicate information related to privacy computation of the user, helping to realize correct privacy computation of the encrypted data stream and protect user data privacy and security.
[0034] In a possible design, the first privacy computing rule includes the packet detection rule and first indication information; or the first privacy computing rule includes the packet detection rule, and the packet detection rule includes the first indication information; wherein the first indication information is used to indicate that the user plane network element performs privacy computation on a data stream matched with the packet detection rule.
[0035] Based on the above scheme, the first indication information can be used to accurately indicate that the user plane network element performs privacy computation on a data stream matched with the packet detection rule. Moreover, only a data stream that needs to perform privacy computation can be subjected to privacy computation by using the first indication information, thereby providing differentiated services for users.
[0036] In a possible design, the obtaining of the encrypted data stream includes: receiving the first encrypted data stream; and processing the encrypted data stream according to a privacy computing rule matched with the encrypted data stream to obtain a processed encrypted data stream, including: when the first privacy computing rule is used to indicate that the user plane network element performs privacy computation on a data stream matched with the packet detection rule, adding privacy computation marking information in each data packet of the first encrypted data stream according to the first privacy computing rule matched with the first encrypted data stream to obtain a second encrypted data stream; wherein the privacy computation marking information is used to indicate that the first encrypted data stream is subjected to privacy computation; and the sending of the processed encrypted data stream includes: sending the second encrypted data stream.
[0037] Based on the above scheme, the user plane network element does not perform privacy computation on the first encrypted data stream, but adds privacy computation marking information in each data packet of the first encrypted data stream to indicate that other devices receiving the second encrypted data stream perform privacy computation on the first encrypted data stream or the second encrypted data stream, thereby reducing the requirement for computing performance of the user plane network element.
[0038] In a possible design, the first privacy computation rule includes the packet detection rule and first indication information; or the first privacy computation rule includes the packet detection rule, and the packet detection rule includes the first indication information; where the first indication information is used to instruct the user plane network element to perform privacy computation marking on a data flow matching the packet detection rule.
[0039] Based on the above scheme, by adding the first indication information, the user plane network element can be accurately instructed to perform privacy computation marking on a data flow matching the packet detection rule. Moreover, by using the first indication information, only the data flow that needs to perform privacy computation can be marked, thereby providing differentiated services for users.
[0040] In a possible design, the method further includes: receiving the first privacy computation rule from the session management network element.
[0041] In a possible design, the obtaining the encrypted data flow includes: receiving a third encrypted data flow; and the processing the encrypted data flow according to the privacy computation rule matching the encrypted data flow to obtain a processed encrypted data flow includes: when the second privacy computation rule is used to instruct the access network device to perform privacy computation on a data flow matching the QoS configuration, performing privacy computation on the third encrypted data flow according to the second privacy computation rule matching the third encrypted data flow to obtain a fourth encrypted data flow; and the sending the processed encrypted data flow includes: sending the fourth encrypted data flow.
[0042] Based on the above scheme, the privacy computation is performed by the access network device instead of the terminal or the application server in the data network, thereby reducing the requirement on the computing performance of the terminal and / or the application server.
[0043] In a possible design, the second privacy computation rule further includes a third privacy computation context; and the performing privacy computation on the third encrypted data flow according to the second privacy computation rule to obtain a fourth encrypted data flow includes: performing privacy computation on the third encrypted data flow according to the third privacy computation context to obtain the fourth encrypted data flow.
[0044] Based on the above scheme, by using the third privacy computation context to perform privacy computation on the third encrypted data flow, the third encrypted data flow can be correctly computed, thereby helping to protect the privacy and security of user data.
[0045] In a possible design, the third privacy computation context includes any one or more of the following: a service identifier, a ciphertext computation function enabling indication, or a privacy computation algorithm identifier; where the service identifier is used to indicate the third encrypted data flow.
[0046] Based on the above scheme, the third privacy computing context can accurately indicate information related to privacy computing of the user, which helps to correctly perform privacy computing on the encrypted data stream and protect the privacy and security of the user data.
[0047] In a possible design, the second privacy computing rule includes the QoS configuration and second indication information; or the second privacy computing rule includes the QoS configuration, and the QoS configuration includes the second indication information; where the second indication information is used to indicate that the access network device performs privacy computing on the data stream matching the QoS configuration.
[0048] Based on the above scheme, by adding the second indication information, the access network device performing privacy computing on the data stream matching the QoS configuration can be accurately indicated. Moreover, the second indication information can be used to perform privacy computing only on the data stream that needs to perform privacy computing, thereby providing differentiated services for users.
[0049] In a possible design, the obtaining the encrypted data stream includes receiving a third encrypted data stream; and the processing the encrypted data stream according to the privacy computing rule matching the encrypted data stream to obtain a processed encrypted data stream includes: when the second privacy computing rule is used to indicate that the access network device performs privacy computing marking on the data stream matching the QoS configuration, adding privacy computing marking information in each data packet of the third encrypted data stream according to the second privacy computing rule matching the third encrypted data stream to obtain a fourth encrypted data stream; where the privacy computing marking information is used to indicate that the third encrypted data stream is subjected to privacy computing; and the sending the processed encrypted data stream includes sending the fourth encrypted data stream.
[0050] Based on the above scheme, the access network device does not perform privacy computing on the third encrypted data stream, but adds privacy computing marking information in each data packet of the third encrypted data stream to indicate that other devices receiving the fourth encrypted data stream perform privacy computing on the third encrypted data stream or the fourth encrypted data stream, which can reduce the demand for computing performance of the access network device.
[0051] In a possible design, the second privacy computing rule includes the QoS configuration and second indication information; or the second privacy computing rule includes the QoS configuration, and the QoS configuration includes the second indication information; where the second indication information is used to indicate that the access network device performs privacy computing marking on the data stream matching the QoS configuration.
[0052] Based on the above scheme, by adding the second indication information, the access network device can be accurately instructed to mark the data flow matching the QoS configuration for privacy calculation. Moreover, the first indication information can be used to perform privacy calculation on only the data flow that needs to perform privacy calculation, thereby providing differentiated services for users.
[0053] In a possible design, the method further includes receiving the second privacy calculation rule from the session management network element.
[0054] In a possible design, the obtaining the encrypted data stream includes generating a fifth encrypted data stream; and the processing the encrypted data stream according to the privacy calculation rule matching the encrypted data stream to obtain a processed encrypted data stream includes: adding, according to a third privacy calculation rule matching the fifth encrypted data stream, privacy calculation marking information in each data packet of the fifth encrypted data stream to obtain a sixth encrypted data stream; the third privacy calculation rule is used to instruct the terminal to mark the data flow matching a quality of service (QoS) rule in the third privacy calculation rule for privacy calculation, and the privacy calculation marking information is used to instruct the fifth encrypted data stream for privacy calculation; and the sending the processed encrypted data stream includes sending the sixth encrypted data stream.
[0055] Based on the above scheme, the terminal can mark the data flow matching the QoS rule in the third privacy calculation rule for privacy calculation according to the third privacy calculation rule, which can apply privacy calculation to the communication system and implement privacy calculation on user data to protect the privacy of user data. Moreover, since the third privacy calculation rule instructs the terminal to perform privacy calculation, the terminal and / or the application server do not need to perform privacy calculation, thereby reducing the requirement on the computing performance of the terminal and / or the application server. In addition, since the third privacy calculation rule includes the QoS rule in the existing user plane protocol, the existing user plane protocol can be adapted with less modification.
[0056] In a possible design, the third privacy calculation rule includes the QoS rule and third indication information; or the third privacy calculation rule includes the QoS rule, and the QoS rule includes the third indication information; the third indication information is used to instruct the terminal to mark the data flow matching the QoS rule for privacy calculation.
[0057] Based on the above scheme, by adding the third indication information, the terminal can be accurately instructed to mark the data flow matching the QoS rule for privacy calculation. Moreover, the first indication information can be used to perform privacy calculation on only the data flow that needs to perform privacy calculation, thereby providing differentiated services for users.
[0058] In a possible design, the third privacy computation rule is received from a session management network element.
[0059] In a third aspect, an embodiment of the present application provides a communication method. The method can be applied to a network side, for example, a user plane network element of the network side, a module (for example, a circuit, a chip, or a chip system, etc.) in the user plane network element, or a logic node, a logic module, or software capable of realizing all or part of the function of the user plane network element. The method comprises: receiving a first encrypted data stream; processing the first encrypted data stream according to a first privacy computation rule matched with the first encrypted data stream to obtain a second encrypted data stream; wherein the first privacy computation rule is used to instruct the user plane network element to perform privacy computation and / or privacy computation marking on a data stream matched with a packet detection rule in the first privacy computation rule; and sending the second encrypted data stream.
[0060] Based on the above scheme, the user plane network element can perform privacy computation and / or privacy computation marking on a data stream matched with a packet detection rule in the first privacy computation rule according to the first privacy computation rule, and can realize application of privacy computation to a communication system and privacy computation on user data to protect the privacy and security of user data. Moreover, when the first privacy computation rule instructs the user plane network element to perform privacy computation, the terminal and / or the application server do not need to perform privacy computation, and thus the demand for the computing performance of the terminal and / or the application server can be reduced. In addition, since the first privacy computation rule contains a packet detection rule in an existing user plane protocol, the existing user plane protocol can be adapted and the change to the existing user plane protocol is small.
[0061] In a possible design, the processing of the first encrypted data stream according to the first privacy computation rule matched with the first encrypted data stream to obtain the second encrypted data stream comprises: when the first privacy computation rule is used to instruct the user plane network element to perform privacy computation on a data stream matched with the packet detection rule, performing privacy computation on the first encrypted data stream according to the first privacy computation rule to obtain the second encrypted data stream.
[0062] Based on the above scheme, the privacy computation is performed by the user plane network element instead of the terminal or the application server in the data network, and thus the demand for the computing performance of the terminal and / or the application server can be reduced.
[0063] In a possible design, the first privacy computation rule further comprises a second privacy computation context; and the performing of privacy computation on the first encrypted data stream according to the first privacy computation rule to obtain the second encrypted data stream comprises: performing privacy computation on the first encrypted data stream according to the second privacy computation context to obtain the second encrypted data stream.
[0064] Based on the above scheme, the first encrypted data stream is processed according to the first privacy computing rule matched with the first encrypted data stream, and the second encrypted data stream is obtained, which can correctly perform privacy computation on the first encrypted data stream, and helps to protect user data privacy and security.
[0065] In a possible design, the second privacy computing context includes any one or more of the following: a service identifier, a ciphertext computing function enabling indication, or a privacy computing algorithm identifier; and the service identifier is used to indicate the first encrypted data stream.
[0066] Based on the above scheme, the second privacy computing context can accurately indicate information related to the privacy computation of the user, which helps to correctly perform privacy computation on the encrypted data stream and protect the privacy and security of the user data.
[0067] In a possible design, the processing of the first encrypted data stream according to the first privacy computing rule matched with the first encrypted data stream to obtain the second encrypted data stream includes: when the first privacy computing rule is used to indicate that the user plane network element performs privacy computation marking on the data stream matched with the packet detection rule, adding privacy computation marking information in each data packet of the first encrypted data stream according to the first privacy computing rule to obtain the second encrypted data stream; and the privacy computation marking information is used to indicate that the first encrypted data stream is subjected to privacy computation.
[0068] Based on the above scheme, the user plane network element does not perform privacy computation on the first encrypted data stream, but adds privacy computation marking information in each data packet of the first encrypted data stream to indicate that other devices receiving the second encrypted data stream perform privacy computation on the first encrypted data stream or the second encrypted data stream. The method can reduce the demand for the computing performance of the user plane network element.
[0069] In a possible design, the method further includes: receiving the first privacy computing rule from the session management network element.
[0070] In a possible design, the first privacy computing rule includes the packet detection rule and first indication information; or the first privacy computing rule includes the packet detection rule, and the packet detection rule includes the first indication information; and the first indication information is used to indicate that the user plane network element performs privacy computation and / or privacy computation marking on the data stream matched with the packet detection rule.
[0071] Based on the above scheme, by adding the first indication information, the user plane network element can be accurately indicated to perform privacy computation and / or privacy computation marking on the data stream matched with the packet detection rule. Moreover, only the data stream that needs to perform privacy computation can be subjected to privacy computation through the first indication information, so as to provide differentiated services for users.
[0072] In a fourth aspect, an embodiment of the present application provides a communication method, which can be applied to a network side, for example, an access network device of the network side, a module (for example, a circuit, a chip or a chip system, etc.) in the access network device, or a logic node, a logic module or software capable of realizing all or part of the function of the access network device. The method comprises: receiving a third encrypted data stream; processing the third encrypted data stream according to a second privacy calculation rule matched with the third encrypted data stream to obtain a fourth encrypted data stream; wherein the second privacy calculation rule is used to instruct the access network device to perform privacy calculation and / or privacy calculation marking on a data stream matched with a QoS configuration in the second privacy calculation rule; and sending the fourth encrypted data stream.
[0073] Based on the above scheme, the access network device can perform privacy calculation and / or privacy calculation marking on a data stream matched with the QoS configuration in the second privacy calculation rule according to the second privacy calculation rule, which can realize application of privacy calculation to a communication system and privacy calculation on user data to protect the privacy and security of user data. Moreover, when the second privacy calculation rule instructs the access network device to perform privacy calculation, the terminal and / or the application server do not need to perform privacy calculation, so the demand for the computing performance of the terminal and / or the application server can be reduced. In addition, since the second privacy calculation rule contains the QoS configuration in the existing user plane protocol, it is adapted to the existing user plane protocol and has little change to the existing user plane protocol.
[0074] In a possible design, the processing of the third encrypted data stream according to the second privacy calculation rule matched with the third encrypted data stream to obtain the fourth encrypted data stream comprises: when the second privacy calculation rule is used to instruct the access network device to perform privacy calculation on a data stream matched with the QoS configuration, performing privacy calculation on the third encrypted data stream according to the second privacy calculation rule to obtain the fourth encrypted data stream.
[0075] Based on the above scheme, the privacy calculation is performed by the access network device instead of the terminal or the application server in the data network, so the demand for the computing performance of the terminal and / or the application server can be reduced.
[0076] In a possible design, the second privacy calculation rule further comprises a third privacy calculation context; and the performing of privacy calculation on the third encrypted data stream according to the second privacy calculation rule to obtain the fourth encrypted data stream comprises: performing privacy calculation on the third encrypted data stream according to the third privacy calculation context to obtain the fourth encrypted data stream.
[0077] Based on the above scheme, the third encrypted data stream is subjected to privacy calculation through the third privacy calculation context, which can realize correct privacy calculation on the third encrypted data stream and help to protect the privacy and security of user data.
[0078] In a possible design, the third privacy computation context includes any one or more of the following: a service identifier, a ciphertext computation function enabling indication, or a privacy computation algorithm identifier; where the service identifier is used to indicate the third encrypted data stream.
[0079] Based on the above scheme, the third privacy computation context can accurately indicate information related to privacy computation of the user, which helps to correctly perform privacy computation on the encrypted data stream and protect the privacy and security of the user data.
[0080] In a possible design, the processing of the third encrypted data stream according to the second privacy computation rule matched with the third encrypted data stream to obtain a fourth encrypted data stream includes: when the second privacy computation rule is used to instruct the access network device to perform privacy computation marking on a data stream matching the QoS configuration, adding privacy computation marking information in each data packet of the third encrypted data stream according to the second privacy computation rule to obtain the fourth encrypted data stream; where the privacy computation marking information is used to indicate that the third encrypted data stream is subjected to privacy computation.
[0081] Based on the above scheme, the access network device does not perform privacy computation on the third encrypted data stream, but adds privacy computation marking information in each data packet of the third encrypted data stream to instruct other devices receiving the fourth encrypted data stream to perform privacy computation on the third encrypted data stream or the fourth encrypted data stream, which can reduce the requirement on the computing performance of the access network device.
[0082] In a possible design, the method further includes: receiving the second privacy computation rule from a session management network element.
[0083] In a possible design, the second privacy computation rule includes the QoS configuration and second indication information; or the second privacy computation rule includes the QoS configuration, and the QoS configuration includes the second indication information; where the second indication information is used to instruct the access network device to perform privacy computation and / or privacy computation marking on a data stream matching the QoS configuration.
[0084] Based on the above scheme, by adding the second indication information, the access network device can be accurately instructed to perform privacy computation and / or privacy computation marking on a data stream matching the QoS configuration. Moreover, only data streams requiring privacy computation can be subjected to privacy computation through the second indication information, so that differentiated services can be provided for users.
[0085] In a fifth aspect, an embodiment of the present application provides a communication method, which can be applied to a terminal side, for example, a terminal or a communication module in the terminal, or a circuit or chip (such as a modem chip, also known as a baseband chip, or a system on chip (SoC) chip or a system in package (SIP) chip containing a modem core) responsible for a communication function in the terminal. The method comprises: generating a fifth encrypted data stream; adding privacy calculation marking information in each data packet of the fifth encrypted data stream according to a third privacy calculation rule matched with the fifth encrypted data stream, to obtain a sixth encrypted data stream; wherein the third privacy calculation rule is used to instruct the terminal to perform privacy calculation marking on a data stream matched with a QoS rule in the third privacy calculation rule, and the privacy calculation marking information is used to instruct to perform privacy calculation on the fifth encrypted data stream; and sending the sixth encrypted data stream.
[0086] Based on the above scheme, the terminal can perform privacy calculation marking on a data stream matched with a QoS rule in the third privacy calculation rule according to the third privacy calculation rule, which can realize application of privacy calculation to a communication system, and realize privacy calculation on user data to protect the privacy and security of the user data. Moreover, since the third privacy calculation rule instructs the terminal to perform privacy calculation marking, the terminal and / or the application server do not need to perform privacy calculation, so that the demand for the calculation performance of the terminal and / or the application server can be reduced. In addition, since the third privacy calculation rule contains a QoS rule in an existing user plane protocol, it is adapted to the existing user plane protocol, and the change to the existing user plane protocol is small.
[0087] In a possible design, the third privacy calculation rule is received from a session management network element.
[0088] In a possible design, the third privacy calculation rule comprises the QoS rule and third indication information; or the third privacy calculation rule comprises the QoS rule, and the QoS rule comprises third indication information; wherein the third indication information is used to instruct the terminal to perform privacy calculation marking on a data stream matched with the QoS rule.
[0089] Based on the above scheme, by adding the third indication information, accurate instruction of the terminal to perform privacy calculation marking on a data stream matched with the QoS rule can be realized. Moreover, only a data stream needing to perform privacy calculation can be marked by the third indication information, so that differentiated services can be provided for users.
[0090] In a sixth aspect, the present application provides a communication apparatus, which has the functions of the first aspect, e.g., the communication apparatus includes modules, units or means for performing the operations of the first aspect, which can be implemented in software, or in hardware, or in a combination of software and hardware.
[0091] In a seventh aspect, the present application provides a communication apparatus, which has the functions of the second aspect, e.g., the communication apparatus includes modules, units or means for performing the operations of the second aspect, which can be implemented in software, or in hardware, or in a combination of software and hardware.
[0092] In an eighth aspect, the present application provides a communication apparatus, which has the functions of the third aspect, e.g., the communication apparatus includes modules, units or means for performing the operations of the third aspect, which can be implemented in software, or in hardware, or in a combination of software and hardware.
[0093] In a ninth aspect, the present application provides a communication apparatus, which has the functions of the fourth aspect, e.g., the communication apparatus includes modules, units or means for performing the operations of the fourth aspect, which can be implemented in software, or in hardware, or in a combination of software and hardware.
[0094] In a tenth aspect, the present application provides a communication apparatus, which has the functions of the fifth aspect, e.g., the communication apparatus includes modules, units or means for performing the operations of the fifth aspect, which can be implemented in software, or in hardware, or in a combination of software and hardware.
[0095] In an eleventh aspect, the present application provides a communication apparatus, which includes an interface circuit and one or more processors. The one or more processors are coupled to a memory. The memory is used to store computer programs or instructions for implementing the functions of the first aspect. The one or more processors can execute the computer programs or instructions, which, when executed, cause the communication apparatus to implement the method in any possible design or implementation manner of the first aspect. The interface circuit is used to implement the communication function within the communication apparatus and / or the communication function of the communication apparatus with other apparatuses or components.
[0096] In a possible design, the one or more processors are configured to communicate with other apparatuses or components via the interface circuit.
[0097] In a possible design, the communication apparatus further includes the memory. Optionally, the memory and the processor are integrated together.
[0098] In a possible design, the memory is independent of the communication apparatus and located outside the communication apparatus.
[0099] The communication apparatus described above can be a session management network element, a module (for example, a circuit, a chip, or a chip system, etc.) in the session management network element, or a logic node, a logic module, or software capable of implementing all or part of the functions of the session management network element.
[0100] In a possible design, the communication apparatus includes an interface circuit and one or more processors. The one or more processors are coupled with a memory. The memory is configured to store a computer program or instructions for implementing the functions described in the second aspect above. The one or more processors are configured to execute the computer program or instructions, and when the computer program or instructions are executed, the one or more processors cause the communication apparatus to implement the method in any possible design or implementation manner of the second aspect above. The interface circuit is configured to implement the communication function within the communication apparatus and / or the communication function between the communication apparatus and other apparatuses or components.
[0101] In a possible design, the one or more processors are configured to communicate with other apparatuses or components via the interface circuit.
[0102] In a possible design, the communication apparatus further includes the memory. Optionally, the memory and the processor are integrated together.
[0103] In a possible design, the memory is independent of the communication apparatus and located outside the communication apparatus.
[0104] The communication apparatus described above can be a user plane network element, a module (for example, a circuit, a chip, or a chip system, etc.) in the user plane network element, or a logic node, a logic module, or software capable of implementing all or part of the functions of the user plane network element.
[0105] The communication apparatus described above can be an access network device, a module (for example, a circuit, a chip, or a chip system, etc.) in the access network device, or a logic node, a logic module, or software capable of implementing all or part of the functions of the access network device.
[0106] The communication apparatus described above can be a terminal, or a communication module in the terminal, or a chip responsible for the communication function in the terminal, such as a modem chip (also known as a baseband chip) or an SoC or SIP chip containing a modem module.
[0107] In a thirteenth aspect, the present application provides a communication apparatus, which comprises an interface circuit and one or more processors. The one or more processors are coupled to a memory. The memory is used to store part or all of the necessary computer programs or instructions for implementing the functions related to the third aspect described above. The one or more processors can execute the computer programs or instructions, which, when executed, cause the communication apparatus to implement the method in any possible design or implementation manner of the third aspect described above. The interface circuit is used to implement the communication function within the communication apparatus and / or the communication function of the communication apparatus with other apparatuses or components.
[0108] In a possible design, the one or more processors are configured to communicate with other apparatuses or components via the interface circuit.
[0109] In a possible design, the communication apparatus can further include the memory. Alternatively, the memory and the processor are integrated together.
[0110] In a possible design, the memory is independent of the communication apparatus and located outside the communication apparatus.
[0111] The communication apparatus described above can be a user plane network element, a module (for example, a circuit, a chip or a chip system, etc.) in the user plane network element, or a logic node, a logic module or software capable of implementing all or part of the functions of the user plane network element.
[0112] In a fourteenth aspect, the present application provides a communication apparatus, which comprises an interface circuit and one or more processors. The one or more processors are coupled to a memory. The memory is used to store part or all of the necessary computer programs or instructions for implementing the functions related to the fourth aspect described above. The one or more processors can execute the computer programs or instructions, which, when executed, cause the communication apparatus to implement the method in any possible design or implementation manner of the fourth aspect described above. The interface circuit is used to implement the communication function within the communication apparatus and / or the communication function of the communication apparatus with other apparatuses or components.
[0113] In a possible design, the one or more processors are configured to communicate with other apparatuses or components via the interface circuit.
[0114] In a possible design, the communication apparatus can further include the memory. Alternatively, the memory and the processor are integrated together.
[0115] In a possible design, the memory is independent of the communication apparatus and located outside the communication apparatus.
[0116] The communication device can be an access network device, a module (e.g., a circuit, a chip or a chip system, etc.) in the access network device, or a logic node, a logic module or software capable of implementing all or part of the functions of the access network device.
[0117] In a fifteenth aspect, a communication device is provided. The communication device includes an interface circuit and one or more processors. The one or more processors are coupled to a memory. The memory is configured to store part or all of the computer programs or instructions necessary to implement the functions related to the fifth aspect. The one or more processors are configured to execute the computer programs or instructions, which when executed cause the communication device to implement the method in any possible design or implementation manner of the fifth aspect. The interface circuit is configured to implement the communication function within the communication device and / or the communication function between the communication device and other devices or components.
[0118] In a possible design, the one or more processors are configured to communicate with other devices or components via the interface circuit.
[0119] In a possible design, the communication device further includes the memory. Optionally, the memory and the processor are integrated together.
[0120] In a possible design, the memory is independent of the communication device and located outside the communication device.
[0121] The communication device can be a terminal, or a communication module in the terminal, or a chip responsible for the communication function such as a modem chip (also referred to as a baseband chip) or a SoC or SIP chip including a modem module in the terminal.
[0122] In a sixteenth aspect, a computer readable storage medium is provided. The computer readable storage medium stores instructions. The instructions, when executed, implement the method in any possible design of the first aspect to the fifth aspect.
[0123] In a seventeenth aspect, a computer program product is provided. The computer program product includes instructions or computer programs. The instructions or computer programs, when executed, implement the method in any possible design of the first aspect to the fifth aspect.
[0124] In an eighteenth aspect, a communication system is provided. The communication system includes a session management network element configured to perform the method in any possible design of the first aspect.
[0125] In a possible design, the communication system further includes a user plane network element configured to perform the method in any possible design of the third aspect. For example, the user plane network element is configured to receive the first privacy computation rule from the session management network element.
[0126] In one possible design, the communication system further includes an access network device configured to perform the method of any of the fourth aspects. For example, the access network device is configured to receive the second privacy computation rule from the session management network element.
[0127] In one possible design, the communication system further includes a terminal configured to perform the method of any of the fifth aspects. For example, the terminal is configured to receive the third privacy computation rule from the session management network element. BRIEF DESCRIPTION OF DRAWINGS
[0128] FIG. 1 is an illustration of a network architecture based on a service-oriented architecture;
[0129] FIG. 2(a) is an illustration of a flowchart of a communication method according to an embodiment of the present application;
[0130] FIG. 2(b) is an illustration of a flowchart of a communication method according to an embodiment of the present application;
[0131] FIG. 3 is an illustration of a flowchart of a communication method according to an embodiment of the present application;
[0132] FIG. 4 is an illustration of a flowchart of a communication method according to an embodiment of the present application;
[0133] FIG. 5 is an illustration of a flowchart of a communication method according to an embodiment of the present application;
[0134] FIG. 6 is an illustration of a flowchart of a communication method according to an embodiment of the present application;
[0135] FIG. 7 is an illustration of a flowchart of a communication method according to an embodiment of the present application;
[0136] FIG. 8 is an illustration of a flowchart of a communication method according to an embodiment of the present application;
[0137] FIG. 9 is a possible exemplary block diagram of a communication device according to an embodiment of the present application;
[0138] FIG. 10 is an illustration of a structure of a terminal according to an embodiment of the present application;
[0139] FIG. 11 is a possible exemplary block diagram of a communication device according to an embodiment of the present application. DETAILED DESCRIPTION
[0140] To cope with the challenge of wireless broadband technology, maintain the leading advantage of the 3rd generation partnership project (3GPP) network, the 5th generation (5G) network architecture is formulated by the 3GPP standard group. The architecture not only supports the wireless access technology defined by the 3GPP standard group (such as long term evolution (LTE) access technology, 5G radio access network (RAN) access technology, etc.) to access the 5G core network (CN), but also supports the use of non-3GPP (non-3GPP) access technology to access the core network through non-3GPP interworking function (N3IWF) or next generation packet data gateway (ngPDG).
[0141] FIG. 1 is a schematic diagram of a network architecture based on a service-oriented architecture. The network architecture shown in FIG. 1 can include access network devices and core network devices. A terminal accesses a data network (DN) through the access network devices and the core network devices. The core network devices include, but are not limited to, some or all of the following network elements: authentication server function (AUSF), unified data management (UDM), unified data repository (UDR), network repository function (NRF), network exposure function (NEF), application function (AF), policy control function (PCF), access and mobility management function (AMF), session management function (SMF), and user plane function (UPF).
[0142] The access network device, which can also be referred to as a RAN node, a RAN entity, or an access node, etc., is used to help the terminal to realize wireless access.
[0143] In a possible scenario, the access network device can be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next generation NodeB (gNB), a base station in a future mobile communication system, or an access node in a wireless fidelity (WiFi) system, etc. The access network device can be a macro base station, a micro base station, or an indoor station, a relay node or a donor node. Optionally, the access network device can also be a server, a wearable device, a vehicle or a vehicle-mounted device, etc. For example, the access network device in vehicle to everything (V2X) technology can be a road side unit (RSU). All or part of the functions of the access network device in the present application can also be implemented by software functions running on hardware, or by virtualized functions instantiated on a platform (such as a cloud platform). The access network device can also be provided with a communication module, circuit or chip for performing corresponding communication functions, and program instructions for performing corresponding communication functions. The access network device in the present application can also be a logic node, logic module or software that can implement all or part of the functions of the access network device.
[0144] In another possible scenario, multiple access network devices cooperate to assist a terminal to implement wireless access, and different access network devices respectively implement part of the functions of a base station. For example, the access network device can be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU), etc. The CU and the DU can be separately arranged, or can be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or a radio frequency unit, such as a remote radio unit (RRU), an active antenna processing unit (AAU), or a remote radio head (RRH).
[0145] In different systems, the CU (or CU-CP and CU-UP), DU or RU can also have different names, but those skilled in the art can understand their meanings. For example, in an open radio access network (ORAN) system, the CU can also be referred to as an O-CU (open CU), the DU can also be referred to as an O-DU, the CU-CP can also be referred to as an O-CU-CP, the CU-UP can also be referred to as an O-CU-UP, and the RU can also be referred to as an O-RU. For the convenience of description, the CU, CU-CP, CU-UP, DU and RU are taken as examples for description in this application. Any one of the CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0146] The terminal can also be referred to as a terminal device, user equipment (UE), mobile station, mobile terminal, etc. The terminal can be widely applied to various scenarios, such as device-to-device (D2D), vehicle to everything (V2X) communication, machine-type communication (MTC), internet of things (IOT), virtual reality, augmented reality, industrial control, automatic driving, remote medical treatment, smart power grid, smart furniture, smart office, smart wear, smart transportation, smart city, etc. The terminal can be a mobile phone, tablet computer, computer with wireless transceiver function, wearable device (such as smart watch, smart bracelet, pedometer, smart glasses, ring, etc.), vehicle device (such as whole vehicle device, vehicle-mounted module, vehicle-mounted chip, on board unit (OBU) or telematics box (T-BOX)), flight device (such as unmanned aerial vehicle, helicopter, airplane, hot air balloon), ship, robot, mechanical arm, smart home device, transport vehicle with wireless communication function, communication module, smart point of sale (POS) machine, customer-premises equipment (CPE), light UE, reduced capability UE (REDCAP UE), etc. Embodiments of the present application do not limit the device form of the terminal. The terminal is usually provided with a communication module, circuit or chip for executing corresponding communication functions. The terminal is also configured with program instructions for executing corresponding communication functions.
[0147] The access network device and the terminal can be fixed in position or mobile. The access network device and the terminal can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can be deployed on water; and can be deployed on aircraft, balloons and satellites in the air. Embodiments of the present application do not limit the application scenarios of the access network device and the terminal.
[0148] The AMF includes functions such as performing mobility management, or access authentication / authorization. In addition, it is also responsible for delivering user policies between the terminal and the PCF.
[0149] The SMF includes functions such as performing session management, performing control policies issued by the PCF, selecting a UPF, or allocating an internet protocol (IP) address of the terminal.
[0150] The UPF includes functions such as completing user plane data forwarding, session / stream level-based charging statistics, or bandwidth limitation.
[0151] The UDM includes functions such as performing management of subscription data, or user access authorization.
[0152] The UDR includes functions such as accessing different types of data such as subscription data, policy data, or application data.
[0153] The NEF is used to support the opening of capabilities and events.
[0154] The AF delivers application-side requirements for the network side, such as quality of service (QoS) requirements or user state event subscriptions. The AF can be a third-party functional entity, or an application service deployed by the operator, such as an IP Multimedia Subsystem (IMS) voice call service. Among them, the AF includes an AF within the core network (namely, the AF of the operator) and a third-party AF (such as an application server of a certain enterprise).
[0155] PCF, including policy control functions responsible for charging, QoS bandwidth guarantee and mobility management at session, service flow level, or terminal policy decision, etc. The PCF includes access and mobility management policy control function (AM PCF) and session management policy control function (SM PCF). Among them, the AM PCF network element is used to formulate AM policy and user policy for the terminal, and the AM PCF can also be called PCF for a UE (PCF for a UE). The SM PCF formulates session management policy (SM policy) for the session, and the SM PCF can also be called PCF for a PDU session (PCF for a PDU session).
[0156] NRF, which can be used to provide a network element discovery function, and provide network element information corresponding to a network element type based on a request of another network element. The NRF also provides network element management services, such as network element registration, update, deregistration, or network element state subscription and push, etc.
[0157] AUSF, responsible for authenticating a user to determine whether to allow the user or device to access the network.
[0158] DN, a network located outside the operator network, the operator network can access multiple DNs, and multiple services can be deployed on the DN to provide data and / or voice services for terminals. For example, the DN is a private network of a smart factory, and the sensors installed in the workshop of the smart factory can be terminals, and the control server of the sensors is deployed in the DN, and the control server can provide services for the sensors. The sensor can communicate with the control server, obtain the instruction of the control server, and transmit the collected sensor data to the control server according to the instruction, etc. For example, the DN is an internal office network of a company, and the mobile phone or computer of the employee of the company can be a terminal, and the mobile phone or computer of the employee can access information and data resources on the internal office network of the company.
[0159] Nausf, Npcf, Nudr, Nudm, Naf, Namf, Nsmf, Nnef, Nnrf in FIG. 1 are service-based interfaces (SBI) provided by the above-mentioned AUSF, PCF, UDR, UDM, AF, AMF, SMF, NEF, NRF, respectively, for calling corresponding service-based operations. N1, N2, N3, N4 and N6 are interface sequence numbers, and the meanings of these interface sequence numbers are as follows:
[0160] 1), N1: the interface between the AMF and the terminal, which can be used to deliver non access stratum (NAS) signaling (such as including the QoS rule from the AMF) to the terminal and the like.
[0161] 2), N2: the interface between the AMF and the access network device, which can be used to deliver the radio bearer control information from the core network side to the access network device and the like.
[0162] 3), N3: the interface between the access network device and the UPF, which is mainly used to deliver the uplink and downlink user plane data between the access network device and the UPF.
[0163] 4), N4: the interface between the SMF and the UPF, which can be used to deliver information between the control plane and the user plane, including the delivery of the forwarding rule, the QoS rule, the traffic statistics rule and the like from the control plane to the user plane, and the information reporting of the user plane.
[0164] 5), N6: the interface between the UPF and the DN, which is used to deliver the uplink and downlink user data flow between the UPF and the DN.
[0165] The various network function network elements in the architecture shown in FIG. 1 are connected through a service bus and interact through a service interface. The service bus has the advantages of improving the flexibility, openness, expansibility and intelligentization of the network, and can support diversified business scenarios and requirements. The service bus can be used to transmit various types of data and signaling, such as real-time signaling (for example, service interface calling signaling between network element function network elements) sensitive to delay, real-time data (for example, real-time artificial intelligence reasoning data) sensitive to delay, and non-real-time data (for example, data for offline artificial intelligence training). Moreover, when the service bus transmits these data or signaling, the data or signaling are coupled together, that is, the service bus can be used to transmit real-time signaling, real-time data and non-real-time data at the same time.
[0166] It can be understood that the above network element or function can be a network element in a hardware device, or a software function running on a dedicated hardware, or a virtualized function instantiated on a platform (for example, a cloud platform). Optionally, the above network element or function can be implemented by one device, or can be implemented by multiple devices together, or can be a functional module in one device, and the embodiments of the present application do not make specific limitations in this regard.
[0167] The session management network element and the user plane network element in the present application can be the SMF and the UPF in FIG. 1, or can be network elements having the functions of the above SMF and UPF in future communication networks, and the present application does not make limitations in this regard.
[0168] With the progress of society and the increasing awareness of data ownership, the requirement for data privacy protection is also increasing. In the process of data processing and use, it is necessary to meet the regulatory requirements of regulations, and if it is subject to various security and privacy attacks from internal and external entities of the network, it will cause serious hidden dangers.
[0169] Privacy computing technology refers to a technical system that realizes data analysis and calculation while protecting data from being leaked. It involves cryptography, distributed computing, artificial intelligence, data science and many other fields. Compared with the traditional use of data, privacy computing focuses more on the protection of data use process and calculation results, and its goal is to maximize data value while ensuring data security.
[0170] However, how to apply privacy computing to the communication system to protect the privacy and security of user data and reduce the demand for computing performance of the terminal and / or application server needs to be studied.
[0171] The communication method and device will be further described below with reference to the accompanying drawings. It can be understood that the session management network element, user plane network element, access network device and terminal are taken as examples in this application as the execution subject, but the application is not limited to the execution subject. For example, the method executed by the session management network element in this application can also be implemented by a module (such as a circuit, a chip or a chip system, etc.) in the session management network element, or a logical node, a logical module or software capable of realizing all or part of the functions of the session management network element; the method executed by the user plane network element in this application can also be implemented by a module (such as a circuit, a chip or a chip system, etc.) in the user plane network element, or a logical node, a logical module or software capable of realizing all or part of the functions of the user plane network element; the method executed by the access network device in this application can also be implemented by a module (such as a circuit, a chip or a chip system, etc.) in the access network device, or a logical node, a logical module or software capable of realizing all or part of the functions of the access network device; the method executed by the terminal in this application can also be implemented by a communication module in the terminal or a circuit or chip (such as a modem chip (also known as a baseband chip), or a SoC chip containing a modem core, or a SIP chip) responsible for communication functions in the terminal.
[0172] FIG. 2(a) is a flowchart of a communication method provided by an embodiment of the application. The method includes the following steps:
[0173] Step 201a, the session management network element acquires a first privacy computing context.
[0174] The first privacy computing context is used to indicate a data flow with privacy computing requirements. Here, the data flow can be a data network (DN) data flow, an application (APP) data flow or a QoS flow, etc.
[0175] Exemplarily, the session management network element can obtain the first privacy computation context from a private computation management function (PCMF) network element, a UDM, or a PCF.
[0176] Exemplarily, the first privacy computation context includes one or more of the following information: a user identity, a service identity, a ciphertext computation function enabling indication, or a privacy computation algorithm identity.
[0177] The user identity can be a terminal identity. The service identity is used to indicate a data flow, and the service identity can be a data network name (DNN), an application identity (APP ID), or a QoS flow identity (QFI), etc. For example, when the service identity is a DNN, it indicates that the data flow in the DN indicated by the DNN has a privacy computation requirement. When the service identity is an APP ID, it indicates that the data flow in the APP indicated by the APP ID has a privacy computation requirement. When the service identity is a QFI, it indicates that the QoS flow indicated by the QFI has a privacy computation requirement.
[0178] The ciphertext computation function enabling indication is used to indicate that the ciphertext computation function or the privacy computation function is enabled. The privacy computation algorithm identity is used to indicate the algorithm used by the privacy computation. For example, the privacy computation algorithm includes a homomorphic encryption algorithm, a federated encryption algorithm, etc.
[0179] In a possible design, before step 201a, the terminal sends a session establishment request to the session management network element, and the session establishment request carries indication information used to indicate privacy computation, which triggers the session management network element to perform step 201a and step 202a.
[0180] In step 202a, the session management network element determines a privacy computation rule according to the first privacy computation context, and the privacy computation rule includes at least one of a first privacy computation rule, a second privacy computation rule, or a third privacy computation rule.
[0181] The first privacy computation rule is used to instruct the user plane network element to perform privacy computation and / or privacy computation marking on a data flow matching a packet detection rule (PDR) in the first privacy computation rule. Exemplarily, the first privacy computation rule includes a packet detection rule and first indication information, or the first privacy computation rule includes a packet detection rule and the packet detection rule includes first indication information. The first indication information is used to instruct the user plane network element to perform privacy computation and / or privacy computation marking on a data flow matching the packet detection rule.
[0182] Exemplarily, the packet detection rule includes a QFI and a QoS enforcement rule (QER). Optionally, the packet detection rule can further include an application identifier and / or a DNN.
[0183] Exemplarily, the first privacy computation rule can further include a second privacy computation context, which is determined according to the first privacy computation context. The second privacy computation context includes one or more of the following information: a service identifier, a ciphertext computation function enabling indication, or a privacy computation algorithm identifier.
[0184] Exemplarily, after determining the first privacy computation rule, the session management network element can further send the first privacy computation rule to the user plane network element.
[0185] The second privacy computation rule is used to instruct the access network device to perform privacy computation and / or privacy computation marking on a data flow matching a QoS profile in the second privacy computation rule. Exemplarily, the second privacy computation rule includes the QoS profile and second indication information, or the second privacy computation rule includes the QoS profile and the QoS profile includes the second indication information. The second indication information is used to instruct the access network device to perform privacy computation and / or privacy computation marking on the data flow matching the QoS profile.
[0186] Exemplarily, the QoS profile includes a QFI and a series of QoS parameters. Optionally, the QoS profile can further include an application identifier and / or a DNN.
[0187] Exemplarily, the second privacy computation rule can further include a third privacy computation context, which is determined according to the first privacy computation context. The third privacy computation context includes one or more of the following information: a service identifier, a ciphertext computation function enabling indication, or a privacy computation algorithm identifier.
[0188] Exemplarily, after determining the second privacy computation rule, the session management network element can further send the second privacy computation rule to the access network device.
[0189] The third privacy computation rule is used to instruct the terminal to perform privacy computation marking on a data flow matching a QoS rule in the third privacy computation rule. Exemplarily, the third privacy computation rule includes the QoS rule and third indication information, or the third privacy computation rule includes the QoS rule and the QoS rule includes the third indication information. The third indication information is used to instruct the terminal to perform privacy computation marking on the data flow matching the QoS rule.
[0190] Exemplarily, the QoS rule includes a series of QoS parameters, such as QFI, a packet filter set, and the like. Optionally, the QoS rule can also include an application identifier and / or a DNN.
[0191] Exemplarily, the session management network element can also send the third privacy computing rule to the terminal after determining the second privacy computing rule.
[0192] The names of the above-mentioned first indication information, second indication information, and third indication information are not limited in the present application, and in actual applications, other names can also be used, for example, all of them can be referred to as privacy computing data flow identifiers / indexes (PCI).
[0193] Based on the above scheme, the session management network element generates at least one of the first privacy computing rule, the second privacy computing rule, or the third privacy computing rule, wherein the first privacy computing rule indicates the user plane network element to perform privacy computing and / or privacy computing marking, the second privacy computing rule indicates the access network device to perform privacy computing and / or privacy computing marking, and the third privacy computing rule indicates the terminal to perform privacy computing marking. The method can implement the application of privacy computing to the communication system, implement privacy computing on user data, and protect the privacy and security of user data. Moreover, since the generated privacy computing rule indicates the user plane network element and / or the access network device to perform privacy computing, the terminal and / or the application server do not need to perform privacy computing, and thus the demand for the computing performance of the terminal and / or the application server can be reduced.
[0194] FIG. 2(b) is a flow diagram of a communication method provided by an embodiment of the present application. The method includes the following steps:
[0195] Step 201b: Obtain encrypted data flow.
[0196] Step 202b: Process the encrypted data flow according to the privacy computing rule matched with the encrypted data flow to obtain processed encrypted data flow.
[0197] The privacy computing rule includes one of the first privacy computing rule, the second privacy computing rule, or the third privacy computing rule.
[0198] The first privacy computing rule is used to indicate the user plane network element to perform privacy computing and / or privacy computing marking on the data flow matched with the packet detection rule in the first privacy computing rule.
[0199] The second privacy computing rule is used to indicate the access network device to perform privacy computing and / or privacy computing marking on the data flow matched with the QoS configuration in the second privacy computing rule.
[0200] The third privacy computation rule is used to instruct the terminal to perform privacy computation marking on a data flow matching a QoS rule in the third privacy computation rule.
[0201] In step 203b, the processed encrypted data flow is sent.
[0202] Based on the above scheme, the user plane network element can perform privacy computation and / or privacy computation marking on a data flow matching a packet detection rule in the first privacy computation rule according to the first privacy computation rule, and can implement application of privacy computation to the communication system and implementation of privacy computation on user data, thereby guaranteeing privacy and security of the user data. Moreover, when the first privacy computation rule instructs the user plane network element to perform privacy computation, the terminal and / or the application server do not need to perform privacy computation, and thus the requirement for the computing performance of the terminal and / or the application server can be reduced. In addition, since the packet detection rule in the first privacy computation rule is included in the existing user plane protocol, the existing user plane protocol is adapted, and changes to the existing user plane protocol are small.
[0203] The access network device can perform privacy computation and / or privacy computation marking on a data flow matching a QoS configuration in the second privacy computation rule according to the second privacy computation rule, and can implement application of privacy computation to the communication system and implementation of privacy computation on user data, thereby guaranteeing privacy and security of the user data. Moreover, when the second privacy computation rule instructs the access network device to perform privacy computation, the terminal and / or the application server do not need to perform privacy computation, and thus the requirement for the computing performance of the terminal and / or the application server can be reduced. In addition, since the QoS configuration in the second privacy computation rule is included in the existing user plane protocol, the existing user plane protocol is adapted, and changes to the existing user plane protocol are small.
[0204] The terminal can perform privacy computation marking on a data flow matching a QoS rule in the third privacy computation rule according to the third privacy computation rule, and can implement application of privacy computation to the communication system and implementation of privacy computation on user data, thereby guaranteeing privacy and security of the user data. Moreover, since the third privacy computation rule instructs the terminal to perform privacy computation marking, the terminal and / or the application server do not need to perform privacy computation, and thus the requirement for the computing performance of the terminal and / or the application server can be reduced. In addition, since the QoS rule in the third privacy computation rule is included in the existing user plane protocol, the existing user plane protocol is adapted, and changes to the existing user plane protocol are small.
[0205] The implementation method of the user plane network element for performing privacy computation and / or privacy computation marking according to the first privacy computation rule is introduced below (see FIG. 3, FIG. 7, and FIG. 8), the implementation method of the access network device for performing privacy computation and / or privacy computation marking according to the second privacy computation rule is introduced below (see FIG. 4, FIG. 7, and FIG. 8), and the implementation method of the terminal for performing privacy computation marking according to the third privacy computation rule is introduced below (see FIG. 5 and FIG. 8).
[0206] The implementation method of the user plane network element for performing privacy computation and / or privacy computation marking according to the first privacy computation rule is introduced below.
[0207] FIG. 3 is a flow diagram of a communication method provided by an embodiment of the present application. The method includes the following steps:
[0208] In step 301, the user plane network element receives a first encrypted data stream.
[0209] The first encrypted data stream can be an uplink encrypted data stream, for example, an encrypted data stream generated by a terminal or an access network device, or a data stream processed (for example, privacy computation or privacy computation marking) by an access device. Alternatively, the first encrypted data stream can be a downlink encrypted data stream, for example, an encrypted data stream generated by an application server.
[0210] In step 302, the user plane network element processes the first encrypted data stream according to a first privacy computation rule matched with the first encrypted data stream, to obtain a second encrypted data stream.
[0211] The first privacy computation rule comes from the session management network element. In one possible implementation, the user plane network element receives the first privacy computation rule from the session management network element.
[0212] The first privacy computation rule is used to instruct the user plane network element to perform privacy computation and / or privacy computation marking on a data stream matched with a packet detection rule in the first privacy computation rule. Exemplarily, the first privacy computation rule includes a packet detection rule and first indication information, or the first privacy computation rule includes a packet detection rule and the packet detection rule includes first indication information. The first indication information is used to instruct the user plane network element to perform privacy computation and / or privacy computation marking on a data stream matched with the packet detection rule.
[0213] Exemplarily, the first privacy computing rule can further include a second privacy computing context, which is determined according to the first privacy computing context. The second privacy computing context includes one or more of the following information: a service identifier, a ciphertext computing function enabling indication, or a privacy computing algorithm identifier. The service identifier is used to indicate the first encrypted data stream, and the service identifier can be a triple information (source IP address, target IP address, protocol), a quintuple information (source IP address, target IP address, source port number, destination port number, protocol), a DNN, an APP ID, or a QFI, etc. The ciphertext computing function enabling indication is used to indicate that the ciphertext computing function or the privacy computing function is enabled. The privacy computing algorithm identifier is used to indicate the algorithm used by the privacy computing.
[0214] In a possible design, when the first privacy computation rule is used to instruct the user plane network element to perform privacy computation on a data flow matching a packet detection rule, the step 302 specifically includes: determining, by the user plane network element, that the first encrypted data flow matches the packet detection rule in the first privacy computation rule according to the first privacy computation rule, and then performing privacy computation on the first encrypted data flow to obtain a second encrypted data flow. For example, if the first privacy computation rule includes first indication information or the packet detection rule in the first privacy computation rule includes first indication information, and the first indication information instructs the user plane network element to perform privacy computation on a data flow matching the packet detection rule, the user plane network element performs privacy computation on the first encrypted data flow based on the first indication information after determining the first encrypted data flow matching the packet detection rule. It should be noted that if the data packet of the first encrypted data flow matching the packet detection rule carries privacy computation marking information in the packet header, the user plane network element can also perform privacy computation on the first encrypted data flow based on the privacy computation marking information or based on the privacy computation marking information and the first indication information after determining the first encrypted data flow matching the packet detection rule. For example, the user plane network element determines that the first encrypted data flow matches the packet detection rule in the first privacy computation rule, for example, by obtaining the three-tuple information, five-tuple information, DNN, APP ID, or QFI from the packet header of the data packet of the first encrypted data flow, and determining that the three-tuple information matches the three-tuple information in the packet detection rule, or the five-tuple information matches the five-tuple information in the packet detection rule, or the DNN matches the DNN in the packet detection rule, or the APP ID matches the APP ID in the packet detection rule, or the QFI matches the QFI in the packet detection rule, and then determining that the data packet matches the packet detection rule in the first privacy computation rule. For example, the user plane network element performs privacy computation on the first encrypted data flow to obtain the second encrypted data flow, for example, by performing privacy computation on the first encrypted data flow according to the privacy computation algorithm identifier in the second privacy computation context and according to the privacy computation algorithm corresponding to the privacy computation algorithm identifier to obtain the second encrypted data flow. According to this method, the privacy computation is performed by the user plane network element instead of the terminal or the application server in the DN, which can reduce the requirement on the computing performance of the terminal and / or the application server.
[0215] In another possible design, when the first privacy computation rule is used to instruct the user plane network element to mark the data flow matching the packet detection rule for privacy computation, the step 302 specifically includes: the user plane network element determines, according to the first privacy computation rule, that the first encrypted data flow matches the packet detection rule in the first privacy computation rule, and then adds privacy computation marking information in each data packet of the first encrypted data flow, for example, adds the privacy computation marking information in the packet header of each data packet to obtain a second encrypted data flow. The privacy computation marking information is used to instruct privacy computation on the first encrypted data flow. For example, if the first privacy computation rule includes first indication information or the packet detection rule in the first privacy computation rule includes the first indication information, and the first indication information instructs the user plane network element to mark the data flow matching the packet detection rule for privacy computation, the user plane network element marks the first encrypted data flow for privacy computation based on the first indication information after determining that the first encrypted data flow matches the packet detection rule. It should be noted that if the packet header of the data packet of the first encrypted data flow matching the packet detection rule carries the privacy computation marking information, the user plane network element can also mark the first encrypted data flow for privacy computation based on the privacy computation marking information or based on the privacy computation marking information and the first indication information after determining that the first encrypted data flow matches the packet detection rule. Based on this method, the user plane network element does not perform privacy computation on the first encrypted data flow, but adds the privacy computation marking information in each data packet of the first encrypted data flow to instruct other devices (for example, an access network device or another user plane network element) receiving the second encrypted data flow to perform privacy computation on the first encrypted data flow or the second encrypted data flow. This method can reduce the demand for the computing performance of the user plane network element.
[0216] In step 303, the user plane network element sends the second encrypted data flow.
[0217] In step 303, the user plane network element sends the second encrypted data flow.
[0218] In one possible design, the terminal sends the first encrypted data flow to the user plane network element, the user plane network element performs privacy computation, and then returns the second encrypted data flow to the terminal, and the terminal decrypts the second encrypted data flow.
[0219] In another possible design, the terminal and the application server can complete the key negotiation for data encryption and decryption before step 301. Therefore, the terminal sends the first encrypted data stream to the user plane network element, and the second encrypted data stream is sent to the application server after the user plane network element performs the privacy calculation, and the application server can decrypt the received encrypted data stream according to the decryption key to obtain the data information. Alternatively, the application server sends the first encrypted data stream to the user plane network element, and the second encrypted data stream is sent to the terminal after the user plane network element performs the privacy calculation, and the terminal can decrypt the received encrypted data stream according to the decryption key to obtain the data information.
[0220] Based on the above scheme, the user plane network element can perform privacy calculation and / or privacy calculation marking on the data stream matching the packet detection rule in the first privacy calculation rule according to the first privacy calculation rule, which can implement application of privacy calculation to the communication system and privacy calculation on user data, and guarantee the privacy and security of user data. Moreover, when the first privacy calculation rule instructs the user plane network element to perform privacy calculation, the terminal and / or the application server do not need to perform privacy calculation, and thus the demand for the calculation performance of the terminal and / or the application server can be reduced. In addition, since the first privacy calculation rule contains the packet detection rule in the existing user plane protocol, the existing user plane protocol can be adapted, and the change to the existing user plane protocol is small.
[0221] The implementation method of the access network device for performing privacy calculation and / or privacy calculation marking according to the second privacy calculation rule is introduced below.
[0222] FIG. 4 is a flow diagram of a communication method according to an embodiment of the present application. The method includes the following steps:
[0223] In step 401, the access network device receives a third encrypted data stream.
[0224] The third encrypted data stream can be an uplink encrypted data stream, for example, an encrypted data stream generated by the terminal, or the third encrypted data stream can be a downlink encrypted data stream, for example, an encrypted data stream generated by the application server, or a data stream processed (for example, privacy calculation or privacy calculation marking) by the user plane network element.
[0225] In step 402, the access network device processes the third encrypted data stream according to the second privacy calculation rule matching the third encrypted data stream to obtain a fourth encrypted data stream.
[0226] The second privacy calculation rule comes from the session management network element. In one possible implementation, the user plane network element receives the second privacy calculation rule from the session management network element.
[0227] The second privacy computation rule is used to instruct the access network device to perform privacy computation and / or privacy computation marking on a data flow matching the QoS configuration in the second privacy computation rule. Illustratively, the second privacy computation rule includes the QoS configuration and second indication information, or the second privacy computation rule includes the QoS configuration and the QoS configuration includes the second indication information. The second indication information is used to instruct the access network device to perform privacy computation and / or privacy computation marking on the data flow matching the QoS configuration.
[0228] Illustratively, the second privacy computation rule can further include a third privacy computation context determined according to the first privacy computation context. The third privacy computation context includes one or more of the following information: a service identity, a ciphertext computation function enabling indication, or a privacy computation algorithm identity. The service identity is used to indicate a third encrypted data flow, and the service identity can be a three-tuple information (source IP address, target IP address, protocol), a five-tuple information (source IP address, target IP address, source port number, destination port number, protocol), a DNN, an APP ID, or a QFI, etc. The ciphertext computation function enabling indication is used to indicate enabling of a ciphertext computation function or a privacy computation function. The privacy computation algorithm identity is used to indicate an algorithm used for privacy computation.
[0229] In a possible design, when the second privacy calculation rule is used to instruct the access network device to perform privacy calculation on a data flow matching the QoS configuration, the step 402 specifically includes: determining, by the access network device, that the third encrypted data flow matches the QoS configuration in the second privacy calculation rule according to the second privacy calculation rule, and performing privacy calculation on the third encrypted data flow to obtain a fourth encrypted data flow. For example, if the second privacy calculation rule includes second indication information or the QoS configuration in the second privacy calculation rule includes second indication information, and the second indication information instructs the access network device to perform privacy calculation on a data flow matching the QoS configuration, the access network device performs privacy calculation on the third encrypted data flow based on the second indication information after determining that the third encrypted data flow matches the QoS configuration. It should be noted that if the packet header of the data packet of the third encrypted data flow matching the QoS configuration carries privacy calculation marking information, the access network device can also perform privacy calculation on the third encrypted data flow based on the privacy calculation marking information or based on the privacy calculation marking information and the second indication information after determining that the third encrypted data flow matches the QoS configuration. For example, the access network device can obtain the three-tuple information, five-tuple information, DNN, APP ID, or QFI from the packet header of the data packet of the third encrypted data flow, and determine that the three-tuple information matches the three-tuple information in the QoS configuration, or the five-tuple information matches the five-tuple information in the QoS configuration, or the DNN matches the DNN in the QoS configuration, or the APP ID matches the APP ID in the QoS configuration, or the QFI matches the QFI in the QoS configuration, and then determine that the data packet matches the QoS configuration in the second privacy calculation rule. For example, the access network device can perform privacy calculation on the third encrypted data flow according to the privacy calculation algorithm identifier in the third privacy calculation context, and according to the privacy calculation algorithm corresponding to the privacy calculation algorithm identifier to obtain the fourth encrypted data flow. According to the method, the privacy calculation is performed by the access network device rather than by the terminal or the application server in the DN, which can reduce the requirement on the computing performance of the terminal and / or the application server.
[0230] In another possible design, when the second privacy calculation rule is used to instruct the access network device to perform privacy calculation marking on the data flow matching the QoS configuration, the step 402 specifically includes: the access network device determines, according to the second privacy calculation rule, that the third encrypted data flow matches the QoS configuration in the second privacy calculation rule, and then adds privacy calculation marking information in each data packet of the third encrypted data flow, for example, adds the privacy calculation marking information in the packet header of each data packet, to obtain a fourth encrypted data flow. The privacy calculation marking information is used to instruct to perform privacy calculation on the third encrypted data flow. For example, if the second privacy calculation rule includes second indication information or the QoS configuration in the second privacy calculation rule includes second indication information, and the second indication information instructs the access network device to perform privacy calculation marking on the data flow matching the QoS configuration, the access network device performs privacy calculation marking on the third encrypted data flow matching the QoS configuration based on the second indication information after determining the third encrypted data flow matching the QoS configuration. It should be noted that if the packet header of the data packet of the third encrypted data flow matching the QoS configuration carries the privacy calculation marking information, the access network device can also perform privacy calculation marking on the third encrypted data flow based on the privacy calculation marking information or based on the privacy calculation marking information and the second indication information after determining the third encrypted data flow matching the QoS configuration. Based on this method, the access network device does not perform privacy calculation on the third encrypted data flow, but adds the privacy calculation marking information in each data packet of the third encrypted data flow to instruct other devices (for example, a user plane network element) receiving the fourth encrypted data flow to perform privacy calculation on the third encrypted data flow or the fourth encrypted data flow. This method can reduce the requirement for the calculation performance of the access network device.
[0231] In step 403, the access network device sends the fourth encrypted data flow.
[0232] In the uplink direction, the access network device sends the fourth encrypted data flow to the user plane network element or the application server. In the downlink direction, the access network device sends the fourth encrypted data flow to the terminal.
[0233] In a possible design, the terminal and the application server can complete the key negotiation for data encryption and decryption before step 401. Therefore, when the terminal or the application server receives the fourth encrypted data flow or receives other encrypted data flows calculated based on the fourth encrypted data flow, the terminal or the application server can decrypt the received encrypted data flow to obtain data information according to the decryption key.
[0234] Based on the above scheme, the access network device can perform privacy computation and / or privacy computation marking on the data flow matching the QoS configuration in the second privacy computation rule according to the second privacy computation rule, which can implement application of privacy computation to the communication system and privacy computation on user data to protect user data privacy and security. Moreover, when the second privacy computation rule instructs the access network device to perform privacy computation, the terminal and / or the application server do not need to perform privacy computation, thereby reducing the requirement for the computing performance of the terminal and / or the application server. In addition, since the second privacy computation rule contains the QoS configuration in the existing user plane protocol, the existing user plane protocol is adapted, and the change to the existing user plane protocol is small.
[0235] The implementation method of the terminal performing privacy computation marking according to the third privacy computation rule is introduced below.
[0236] FIG. 5 is a flow diagram of a communication method provided by an embodiment of the present application. The method includes the following steps:
[0237] Step 501: The terminal generates a fifth encrypted data flow.
[0238] The terminal encrypts the data flow to be sent according to the encryption algorithm to obtain the fifth encrypted data flow.
[0239] Step 502: The terminal adds privacy computation marking information in each data packet of the fifth encrypted data flow according to the third privacy computation rule matching the fifth encrypted data flow to obtain a sixth encrypted data flow.
[0240] The third privacy computation rule comes from a session management network element.
[0241] The third privacy computation rule is used to instruct the terminal to perform privacy computation marking on the data flow matching the QoS rule in the third privacy computation rule. Exemplarily, the third privacy computation rule includes the QoS rule and third indication information, or the third privacy computation rule includes the QoS rule and the QoS rule includes the third indication information. The third indication information is used to instruct the terminal to perform privacy computation marking on the data flow matching the QoS rule.
[0242] Exemplarily, the terminal determines, according to the third privacy calculation rule, that the fifth encrypted data stream matches the QoS rule in the third privacy calculation rule, and further adds privacy calculation mark information in each data packet of the fifth encrypted data stream, for example, adds the privacy calculation mark information in the packet header of each data packet, to obtain a sixth encrypted data stream. The privacy calculation mark information is used to indicate that privacy calculation is performed on the fifth encrypted data stream. Exemplarily, if the third privacy calculation rule includes third indication information or the QoS rule in the third privacy calculation rule includes the third indication information, and the third indication information indicates that the terminal performs privacy calculation marking on the data stream matching the QoS rule, the terminal performs privacy calculation marking on the fifth encrypted data stream based on the third indication information after determining that the fifth encrypted data stream matches the QoS rule. For example, the terminal can obtain the three-tuple information (source IP address, target IP address, and protocol), five-tuple information (source IP address, target IP address, source port number, destination port number, and protocol), DNN, APP ID, or QFI from the packet header of the data packet of the fifth encrypted data stream, and determine that the three-tuple information matches the three-tuple information in the QoS rule, or the five-tuple information matches the five-tuple information in the QoS rule, or the DNN matches the DNN in the QoS rule, or the APP ID matches the APP ID in the QoS rule, or the QFI matches the QFI in the QoS rule, to determine that the data packet matches the QoS rule in the third privacy calculation rule. Based on this method, the access network device does not perform privacy calculation on the fifth encrypted data stream, but adds privacy calculation mark information in each data packet of the fifth encrypted data stream to indicate that other devices (for example, user plane network elements) receiving the sixth encrypted data stream perform privacy calculation on the fifth encrypted data stream or the sixth encrypted data stream.
[0243] In step 503, the terminal sends the sixth encrypted data stream.
[0244] Exemplarily, the terminal sends the sixth encrypted data stream to the access network device or the user plane network element.
[0245] In a possible design, the terminal and the application server can complete key negotiation for data encryption and decryption before step 501, so that when the application server receives the sixth encrypted data stream or receives other encrypted data streams calculated based on the sixth encrypted data stream, the application server can decrypt the received encrypted data stream to obtain data information according to a decryption key. In an implementation, the application server maintains a correspondence between an encrypted data stream (i.e., an encrypted data stream before privacy calculation is performed) and an encrypted data stream after privacy calculation is performed, and performs a corresponding decryption algorithm on the encrypted data stream after privacy calculation is performed, so as to complete decryption.
[0246] In another possible design, after receiving the sixth encrypted data stream, the access network device or the user plane network element can perform privacy computation on the sixth encrypted data stream to obtain a seventh encrypted data stream, and send the seventh encrypted data stream to the terminal. Optionally, after receiving the seventh encrypted data stream, the terminal can perform decryption on the seventh encrypted data stream to obtain a decrypted data stream. Based on this method, the terminal can use the high computing capability of the access network device or the user plane network element to complete the computation on the data stream, thereby saving the power consumption of the terminal; and the data stream is encrypted and will not be exposed in the network, thereby achieving privacy protection of the data.
[0247] Based on the foregoing scheme, the terminal can perform privacy computation marking on the data stream matching the QoS rule in the third privacy computation rule according to the third privacy computation rule, and can apply privacy computation to the communication system, perform privacy computation on user data, and guarantee the privacy security of the user data. In addition, since the third privacy computation rule instructs the terminal to perform privacy computation marking, the terminal and / or the application server do not need to perform privacy computation, and thus the requirement on the computing performance of the terminal and / or the application server can be reduced. Moreover, since the third privacy computation rule contains the QoS rule in the existing user plane protocol, the existing user plane protocol can be adapted, and the change to the existing user plane protocol is small.
[0248] FIG. 6 is a flow diagram of a communication method provided by an embodiment of the present application. The method includes the following steps:
[0249] In step 601, a privacy computation management function network element determines a first privacy computation context.
[0250] The content of the first privacy computation context can refer to the description of step 201.
[0251] In step 602, a terminal sends a session establishment request or a privacy computation request to a session management network element. Correspondingly, the session management network element receives the session establishment request or the privacy computation request.
[0252] The session establishment request is used to request establishment of a session. Optionally, the session establishment request contains indication information, which is used to indicate privacy computation.
[0253] The privacy computation request is used to request privacy computation.
[0254] In step 603, the session management network element obtains the first privacy computation context.
[0255] Exemplarily, the session management network element can obtain the first privacy computation context from the privacy computation management function network element. Alternatively, if the privacy computation management function network element stores the first privacy computation context to the UDM or the PCF, the privacy computation management function network element can also obtain the first privacy computation context from the UDM or the PCF.
[0256] In one implementation method, if the terminal sends the session establishment request in step 602, the session management network element determines that privacy computation needs to be performed for the terminal based on a local policy, and then triggers step 603 to be performed.
[0257] In another implementation method, if the terminal sends the session establishment request in step 602, and the session establishment request carries the indication information, the session management network element determines that privacy computation needs to be performed for the terminal based on the indication information, and then triggers step 603 to be performed.
[0258] In another implementation method, if the terminal sends the privacy computation request in step 602, the session management network element determines that privacy computation needs to be performed for the terminal based on the privacy computation request, and then triggers step 603 to be performed.
[0259] In step 604, the session management network element determines a privacy computation rule according to the first privacy computation context, and the privacy computation rule includes a first privacy computation rule, a second privacy computation rule, and a third privacy computation rule.
[0260] This step 604 is similar to the aforementioned step 202a, and reference can be made to the foregoing description.
[0261] In step 605, the session management network element sends the first privacy computation rule to the user plane network element. Correspondingly, the user plane network element receives the first privacy computation rule.
[0262] In step 606, the session management network element sends the second privacy computation rule to the access network device. Correspondingly, the access network device receives the second privacy computation rule.
[0263] In step 607, the session management network element sends the third privacy computation rule to the terminal. Correspondingly, the terminal receives the third privacy computation rule.
[0264] The execution sequence of the above steps 605 to 607 is not limited.
[0265] Based on the above scheme, the session management network element generates at least one of the first privacy calculation rule, the second privacy calculation rule, or the third privacy calculation rule, wherein the first privacy calculation rule indicates the user plane network element to perform privacy calculation and / or privacy calculation marking, the second privacy calculation rule indicates the access network device to perform privacy calculation and / or privacy calculation marking, and the third privacy calculation rule indicates the terminal to perform privacy calculation marking. This method can implement privacy calculation in a communication system, implement privacy calculation on user data, and protect user data privacy and security. Moreover, since the generated privacy calculation rule instructs the user plane network element and / or the access network device to perform privacy calculation, the terminal and / or the application server do not need to perform privacy calculation, and thus the demand for the computing performance of the terminal and / or the application server can be reduced.
[0266] FIG. 7 is a flow diagram of a communication method provided by an embodiment of the present application. The method is for sending a downlink data stream. The method includes the following steps:
[0267] Step 701: A user plane network element receives an encrypted data stream #1.
[0268] The encrypted data stream #1 is a downlink encrypted data stream, which can be an encrypted data stream generated by an application server, for example.
[0269] Step 702: The user plane network element performs privacy calculation or privacy calculation marking on the encrypted data stream #1 according to a first privacy calculation rule, to obtain an encrypted data stream #2.
[0270] For the specific implementation method of performing privacy calculation or privacy calculation marking on the encrypted data stream #1 according to the first privacy calculation rule to obtain the encrypted data stream #2, reference can be made to the description of the aforementioned step 302, which will not be repeated here.
[0271] Step 703: The user plane network element sends the encrypted data stream #2. Correspondingly, an access network device receives the encrypted data stream #2.
[0272] Step 704: The access network device performs privacy calculation or privacy calculation marking on the encrypted data stream #2 according to a second privacy calculation rule, to obtain an encrypted data stream #3.
[0273] For the specific implementation method of performing privacy calculation or privacy calculation marking on the encrypted data stream #2 according to the second privacy calculation rule to obtain the encrypted data stream #3, reference can be made to the description of the aforementioned step 402, which will not be repeated here.
[0274] Step 705: The access network device sends the encrypted data stream #3. Correspondingly, a terminal receives the encrypted data stream #3.
[0275] Step 706, the terminal decrypts the encrypted data stream #3 to obtain plaintext.
[0276] Based on the above scheme, the user plane network element can perform privacy calculation and / or privacy calculation marking on the data stream matched with the packet detection rule in the first privacy calculation rule according to the first privacy calculation rule, which can apply privacy calculation to the communication system and perform privacy calculation on user data, thereby protecting the privacy and security of user data. Moreover, when the first privacy calculation rule instructs the user plane network element to perform privacy calculation, the terminal and / or the application server do not need to perform privacy calculation, thereby reducing the requirement for the computing performance of the terminal and / or the application server. In addition, since the first privacy calculation rule contains the packet detection rule in the existing user plane protocol, the existing user plane protocol is adapted, and the change to the existing user plane protocol is small.
[0277] The access network device can perform privacy calculation and / or privacy calculation marking on the data stream matched with the QoS configuration in the second privacy calculation rule according to the second privacy calculation rule, which can apply privacy calculation to the communication system and perform privacy calculation on user data, thereby protecting the privacy and security of user data. Moreover, when the second privacy calculation rule instructs the access network device to perform privacy calculation, the terminal and / or the application server do not need to perform privacy calculation, thereby reducing the requirement for the computing performance of the terminal and / or the application server. In addition, since the second privacy calculation rule contains the QoS configuration in the existing user plane protocol, the existing user plane protocol is adapted, and the change to the existing user plane protocol is small.
[0278] FIG. 8 is a flow diagram of a communication method provided by an embodiment of the present application. The method is for the sending of an uplink data stream. The method includes the following steps:
[0279] Step 801, the terminal generates an encrypted data stream #4.
[0280] Step 802, the terminal performs privacy calculation marking on the encrypted data stream #4 according to the third privacy calculation rule to obtain an encrypted data stream #5.
[0281] For the specific implementation method of performing privacy calculation marking on the encrypted data stream #4 according to the third privacy calculation rule to obtain the encrypted data stream #5 by the terminal, reference can be made to the description of the aforementioned step 502, which will not be described herein again.
[0282] Step 803, the terminal sends the encrypted data stream #5. Correspondingly, the access network device receives the encrypted data stream #5.
[0283] Step 804, the access network device performs privacy calculation or privacy calculation marking on the encrypted data stream #5 according to the second privacy calculation rule to obtain an encrypted data stream #6.
[0284] The specific implementation method of the access network device performing privacy computation or privacy computation marking on the encrypted data stream #5 according to the second privacy computation rule to obtain the encrypted data stream #6 can refer to the description of the foregoing step 402, and details are not described herein again.
[0285] In step 805, the access network device sends the encrypted data stream #6. Correspondingly, the user plane network element receives the encrypted data stream #6.
[0286] In step 806, the user plane network element performs privacy computation or privacy computation marking on the encrypted data stream #6 according to the first privacy computation rule to obtain an encrypted data stream #7.
[0287] The specific implementation method of the user plane network element performing privacy computation or privacy computation marking on the encrypted data stream #6 according to the first privacy computation rule to obtain the encrypted data stream #7 can refer to the description of the foregoing step 302, and details are not described herein again.
[0288] In step 807, the user plane network element sends the encrypted data stream #7. Correspondingly, the application server receives the encrypted data stream #7.
[0289] In step 808, the application server decrypts the encrypted data stream #7 to obtain plaintext.
[0290] Based on the foregoing scheme, the user plane network element can perform privacy computation and / or privacy computation marking on a data stream matched with a packet detection rule in the first privacy computation rule according to the first privacy computation rule, and can implement application of privacy computation to a communication system and implementation of privacy computation on user data to protect user data privacy and security. Moreover, when the first privacy computation rule indicates the user plane network element to perform privacy computation, the terminal and / or the application server do not need to perform privacy computation, and thus the demand for the computing performance of the terminal and / or the application server can be reduced. In addition, since the first privacy computation rule contains a packet detection rule in an existing user plane protocol, the existing user plane protocol is adapted, and changes to the existing user plane protocol are small.
[0291] The access network device can perform privacy computation and / or privacy computation marking on a data stream matched with a QoS configuration in the second privacy computation rule according to the second privacy computation rule, and can implement application of privacy computation to a communication system and implementation of privacy computation on user data to protect user data privacy and security. Moreover, when the second privacy computation rule indicates the access network device to perform privacy computation, the terminal and / or the application server do not need to perform privacy computation, and thus the demand for the computing performance of the terminal and / or the application server can be reduced. In addition, since the second privacy computation rule contains a QoS configuration in an existing user plane protocol, the existing user plane protocol is adapted, and changes to the existing user plane protocol are small.
[0292] The terminal can perform privacy computation marking on a data flow matching a QoS rule in the third privacy computation rule according to the third privacy computation rule, can implement application of privacy computation to a communication system, and can implement privacy computation on user data to protect privacy and security of the user data. In addition, since the third privacy computation rule instructs the terminal to perform privacy computation marking, the terminal and / or the application server do not need to perform privacy computation, and thus the requirement for computing performance of the terminal and / or the application server can be reduced. In addition, since the third privacy computation rule contains a QoS rule in an existing user plane protocol, the third privacy computation rule adapts to the existing user plane protocol and has small changes to the existing user plane protocol.
[0293] FIG. 9 shows a possible exemplary block diagram of a communication apparatus involved in an embodiment of the present application. As shown in FIG. 9, the communication apparatus 900 can include modules or units for implementing the method embodiments described above. In a possible design, the communication apparatus 900 includes a processing unit 902 and a communication unit 903. Optionally, the communication apparatus 900 can further include a storage unit 901, which is configured to store apparatus program code and / or data.
[0294] The communication apparatus 900 can also be a network side apparatus in the embodiments described above, for example, a network side session management network element, a module (for example, a circuit, a chip or a chip system, etc.) in the session management network element, or a logic node, a logic module or software capable of implementing all or part of the functions of the session management network element.
[0295] For example, in an embodiment, the processing unit 902 is configured to obtain a first privacy computation context, where the first privacy computation context is used to indicate a data flow having a privacy computation requirement; and determine at least one of a first privacy computation rule, a second privacy computation rule or a third privacy computation rule according to the first privacy computation context, where the first privacy computation rule is used to instruct a user plane network element to perform privacy computation and / or privacy computation marking on a data flow matching a packet detection rule in the first privacy computation rule, the second privacy computation rule is used to instruct an access network device to perform privacy computation and / or privacy computation marking on a data flow matching a QoS configuration in the second privacy computation rule, and the third privacy computation rule is used to instruct a terminal to perform privacy computation marking on a data flow matching a QoS rule in the third privacy computation rule.
[0296] In a possible design, the communication unit 903 is configured to send the first privacy computation rule to the user plane network element.
[0297] In a possible design, the first privacy calculation rule includes the packet detection rule and first indication information; or the first privacy calculation rule includes the packet detection rule, and the packet detection rule includes the first indication information; where the first indication information is used to instruct the user plane network element to perform privacy calculation and / or privacy calculation marking on a data flow matching the packet detection rule.
[0298] In a possible design, the communication unit 903 is configured to send the second privacy calculation rule to the access network device.
[0299] In a possible design, the second privacy calculation rule includes the QoS configuration and second indication information; or the second privacy calculation rule includes the QoS configuration, and the QoS configuration includes the second indication information; where the second indication information is used to instruct the access network device to perform privacy calculation and / or privacy calculation marking on a data flow matching the QoS configuration.
[0300] In a possible design, the communication unit 903 is configured to send the third privacy calculation rule to the terminal.
[0301] In a possible design, the third privacy calculation rule includes the QoS rule and third indication information; or the third privacy calculation rule includes the QoS rule, and the QoS rule includes the third indication information; where the third indication information is used to instruct the terminal to perform privacy calculation marking on a data flow matching the QoS rule.
[0302] In a possible design, the first privacy calculation context includes any one or more of the following: a user identifier, a service identifier, a cipher calculation function enabling indication, or a privacy calculation algorithm identifier; where the service identifier is used to indicate the data flow.
[0303] The communication apparatus 900 can also be a network side device in the above-described embodiments, for example, a network side user plane network element, a module (for example, a circuit, a chip or a chip system, etc.) in the user plane network element, or a logic node, a logic module or software capable of realizing all or part of the functions of the user plane network element.
[0304] For example, in an embodiment, the communication unit 903 is configured to receive a first encrypted data flow; the processing unit 902 is configured to process the first encrypted data flow according to a first privacy calculation rule matching the first encrypted data flow, to obtain a second encrypted data flow; where the first privacy calculation rule is used to instruct a user plane network element to perform privacy calculation and / or privacy calculation marking on a data flow matching a packet detection rule in the first privacy calculation rule; and the communication unit 903 is further configured to send the second encrypted data flow.
[0305] In a possible design, the processing unit 902 is configured to process the first encrypted data stream according to the first privacy computation rule matched by the first encrypted data stream to obtain a second encrypted data stream, including: when the first privacy computation rule is used to instruct the user plane network element to perform privacy computation on a data stream matched by the packet detection rule, performing privacy computation on the first encrypted data stream according to the first privacy computation rule to obtain the second encrypted data stream.
[0306] In a possible design, the first privacy computation rule further includes a second privacy computation context; and the processing unit 902 is configured to perform privacy computation on the first encrypted data stream according to the first privacy computation rule to obtain the second encrypted data stream, including: performing privacy computation on the first encrypted data stream according to the second privacy computation context to obtain the second encrypted data stream.
[0307] In a possible design, the second privacy computation context includes any one or more of the following: a service identifier, a ciphertext computation function enabling indication, or a privacy computation algorithm identifier; and the service identifier is used to indicate the first encrypted data stream.
[0308] In a possible design, the processing unit 902 is configured to process the first encrypted data stream according to the first privacy computation rule matched by the first encrypted data stream to obtain a second encrypted data stream, including: when the first privacy computation rule is used to instruct the user plane network element to perform privacy computation marking on a data stream matched by the packet detection rule, adding privacy computation marking information in each data packet of the first encrypted data stream according to the first privacy computation rule to obtain the second encrypted data stream; and the privacy computation marking information is used to indicate that privacy computation is performed on the first encrypted data stream.
[0309] In a possible design, the communication unit 903 is further configured to receive the first privacy computation rule from a session management network element.
[0310] In a possible design, the first privacy computation rule includes the packet detection rule and first indication information; or the first privacy computation rule includes the packet detection rule, and the packet detection rule includes the first indication information; and the first indication information is used to instruct the user plane network element to perform privacy computation and / or privacy computation marking on a data stream matched by the packet detection rule.
[0311] The communication apparatus 900 can also be the network side device in the above-described embodiments, for example, an access network device on the network side, a module (for example, a circuit, a chip or a chip system, etc.) in the access network device, or a logic node, a logic module or software capable of realizing all or part of the functions of the access network device.
[0312] For example, in an embodiment, the communication unit 903 is configured to receive a third encrypted data stream; the processing unit 902 is configured to process the third encrypted data stream according to a second privacy computation rule matched with the third encrypted data stream to obtain a fourth encrypted data stream; the second privacy computation rule is configured to instruct the access network device to perform privacy computation and / or privacy computation marking on a data stream matched with a QoS configuration in the second privacy computation rule; and the communication unit 903 is configured to send the fourth encrypted data stream.
[0313] In a possible design, the processing unit 902 is configured to process the third encrypted data stream according to the second privacy computation rule to obtain the fourth encrypted data stream, including: when the second privacy computation rule is configured to instruct the access network device to perform privacy computation on a data stream matched with the QoS configuration, performing privacy computation on the third encrypted data stream according to the second privacy computation rule to obtain the fourth encrypted data stream.
[0314] In a possible design, the second privacy computation rule further includes a third privacy computation context; and the processing unit 902 is configured to perform privacy computation on the third encrypted data stream according to the second privacy computation rule to obtain the fourth encrypted data stream, including: performing privacy computation on the third encrypted data stream according to the third privacy computation context to obtain the fourth encrypted data stream.
[0315] In a possible design, the third privacy computation context includes any one or more of a service identifier, a cipher computation function enabling indication, or a privacy computation algorithm identifier; and the service identifier is configured to indicate the third encrypted data stream.
[0316] In a possible design, the processing unit 902 is configured to process the third encrypted data stream according to the second privacy computation rule to obtain the fourth encrypted data stream, including: when the second privacy computation rule is configured to instruct the access network device to perform privacy computation marking on a data stream matched with the QoS configuration, adding privacy computation marking information in each data packet of the third encrypted data stream according to the second privacy computation rule to obtain the fourth encrypted data stream; and the privacy computation marking information is configured to indicate that the third encrypted data stream is subjected to privacy computation.
[0317] In a possible design, the communication unit 903 is further configured to receive the second privacy computation rule from a session management network element.
[0318] In a possible design, the second privacy calculation rule includes the QoS configuration and second indication information; or the second privacy calculation rule includes the QoS configuration, and the QoS configuration includes second indication information; where the second indication information is used to instruct the access network device to perform privacy calculation and / or privacy calculation marking on a data flow matching the QoS configuration.
[0319] The communication apparatus 900 can be a terminal-side apparatus in the above-described embodiments, for example, a terminal or a communication module in the terminal, or a circuit or chip responsible for communication functions in the terminal. In a possible design, when the communication apparatus 900 is a terminal or a communication module in the terminal, the function of the processing unit 902 can be implemented by one or more processors. Specifically, the processor can include a modem chip, or a system on chip (SoC) chip or a SIP chip including a modem core. The function of the communication unit 903 can be implemented by transceiver circuitry.
[0320] In a possible design, when the communication apparatus 900 is a circuit or chip responsible for communication functions in the terminal, such as a modem chip or a system on chip (SoC) chip or a SIP chip including a modem core, the function of the processing unit 902 can be implemented by circuitry including one or more processors or processor cores in the above-described chip. The function of the communication unit 903 can be implemented by interface circuitry or data transceiver circuitry on the above-described chip.
[0321] For example, in an embodiment, the processing unit 902 is configured to generate a fifth encrypted data flow, and add, according to a third privacy calculation rule matching the fifth encrypted data flow, privacy calculation marking information in each data packet of the fifth encrypted data flow to obtain a sixth encrypted data flow, where the third privacy calculation rule is used to instruct a terminal to perform privacy calculation marking on a data flow matching a QoS rule in the third privacy calculation rule, and the privacy calculation marking information is used to instruct to perform privacy calculation on the fifth encrypted data flow. The communication unit 903 is configured to send the sixth encrypted data flow.
[0322] In a possible design, the communication unit 903 is further configured to receive the third privacy calculation rule from a session management network element.
[0323] In a possible design, the third privacy calculation rule includes the QoS rule and third indication information; or the third privacy calculation rule includes the QoS rule, and the QoS rule includes third indication information; where the third indication information is used to instruct the terminal to perform privacy calculation marking on a data flow matching the QoS rule.
[0324] The communication apparatus 900 can also be a network side device in the above embodiments, for example, a user plane network element on the network side, a module (such as a circuit, a chip or a chip system, etc.) in the user plane network element, or a logic node, a logic module or software capable of realizing all or part of the functions of the user plane network element. Alternatively, the communication apparatus 900 can also be a network side device in the above embodiments, for example, an access network device on the network side, a module (such as a circuit, a chip or a chip system, etc.) in the access network device, or a logic node, a logic module or software capable of realizing all or part of the functions of the access network device. Alternatively, the communication apparatus 900 can be a terminal side device in the above embodiments, for example, a terminal or a communication module in the terminal, or a circuit or a chip responsible for communication functions in the terminal. In a possible design, when the communication apparatus 900 is a terminal or a communication module in the terminal, the functions of the processing unit 902 can be realized by one or more processors. Specifically, the processor can include a modem chip, or a system on chip (SoC) chip or a SIP chip containing a modem core. The functions of the communication unit 903 can be realized by a transceiver circuit.
[0325] For example, in an embodiment, the processing unit 902 is configured to obtain an encrypted data stream, and perform processing on the encrypted data stream according to a privacy calculation rule matched with the encrypted data stream to obtain a processed encrypted data stream; and the communication unit 903 is configured to send the processed encrypted data stream; where the privacy calculation rule includes one of a first privacy calculation rule, a second privacy calculation rule or a third privacy calculation rule; where the first privacy calculation rule is used to instruct the user plane network element to perform privacy calculation and / or privacy calculation marking on a data stream matched with a packet detection rule in the first privacy calculation rule, the second privacy calculation rule is used to instruct the access network device to perform privacy calculation and / or privacy calculation marking on a data stream matched with a QoS configuration in the second privacy calculation rule, and the third privacy calculation rule is used to instruct the terminal to perform privacy calculation marking on a data stream matched with a QoS rule in the third privacy calculation rule.
[0326] In a possible design, the processing unit 902 is configured to obtain an encrypted data stream, including being configured to receive a first encrypted data stream through the communication unit 903; and the processing unit 902 is configured to perform processing on the encrypted data stream according to a privacy calculation rule matched with the encrypted data stream to obtain a processed encrypted data stream, including being configured to, when the first privacy calculation rule is used to instruct the user plane network element to perform privacy calculation on a data stream matched with the packet detection rule, perform privacy calculation on the first encrypted data stream according to the first privacy calculation rule matched with the first encrypted data stream to obtain a second encrypted data stream; and the communication unit 903 is configured to send the processed encrypted data stream, including being configured to send the second encrypted data stream.
[0327] In a possible design, the first privacy computation rule further includes a second privacy computation context; and the processing unit 902 is configured to perform privacy computation on the first encrypted data flow according to the first privacy computation rule to obtain a second encrypted data flow, including performing privacy computation on the first encrypted data flow according to the second privacy computation context to obtain the second encrypted data flow.
[0328] In a possible design, the second privacy computation context includes any one or more of a service identifier, a ciphertext computation function enabling indication, or a privacy computation algorithm identifier; and the service identifier is used to indicate the first encrypted data flow.
[0329] In a possible design, the first privacy computation rule includes the packet detection rule and first indication information, or the first privacy computation rule includes the packet detection rule, and the packet detection rule includes the first indication information; and the first indication information is used to indicate that the user plane network element performs privacy computation on a data flow matching the packet detection rule.
[0330] In a possible design, the processing unit 902 is configured to obtain the encrypted data flow, including receiving the first encrypted data flow through the communication unit 903; and the processing unit 902 is configured to perform processing on the encrypted data flow according to a privacy computation rule matching the encrypted data flow to obtain a processed encrypted data flow, including: when the first privacy computation rule is used to indicate that the user plane network element performs privacy computation marking on a data flow matching the packet detection rule, adding privacy computation marking information in each data packet of the first encrypted data flow according to the first privacy computation rule matching the first encrypted data flow to obtain a second encrypted data flow; and the privacy computation marking information is used to indicate that privacy computation is performed on the first encrypted data flow; and the communication unit 903 is configured to send the processed encrypted data flow, including sending the second encrypted data flow.
[0331] In a possible design, the first privacy computation rule includes the packet detection rule and first indication information, or the first privacy computation rule includes the packet detection rule, and the packet detection rule includes the first indication information; and the first indication information is used to indicate that the user plane network element performs privacy computation marking on a data flow matching the packet detection rule.
[0332] In a possible design, the communication unit 903 is further configured to receive the first privacy computation rule from a session management network element.
[0333] In a possible design, the processing unit 902, configured to obtain the encrypted data stream, includes: a communication unit 903, configured to receive a third encrypted data stream; and the processing unit 902, configured to process the third encrypted data stream according to a privacy computation rule matched with the encrypted data stream to obtain a processed encrypted data stream, including: when the second privacy computation rule is used to instruct the access network device to perform privacy computation on a data stream matched with the QoS configuration, performing privacy computation on the third encrypted data stream according to the second privacy computation rule matched with the third encrypted data stream to obtain a fourth encrypted data stream; and the communication unit 903, configured to send the processed encrypted data stream, including: sending the fourth encrypted data stream.
[0334] In a possible design, the second privacy computation rule further includes a third privacy computation context; and the processing unit 902, configured to perform privacy computation on the third encrypted data stream according to the second privacy computation rule to obtain a fourth encrypted data stream, includes: performing privacy computation on the third encrypted data stream according to the third privacy computation context to obtain the fourth encrypted data stream.
[0335] In a possible design, the third privacy computation context includes any one or more of the following: a service identifier, a ciphertext computation function enabling instruction or a privacy computation algorithm identifier; and the service identifier is used to indicate the third encrypted data stream.
[0336] In a possible design, the second privacy computation rule includes the QoS configuration and second indication information; or the second privacy computation rule includes the QoS configuration, and the QoS configuration includes the second indication information; and the second indication information is used to instruct the access network device to perform privacy computation on a data stream matched with the QoS configuration.
[0337] In a possible design, the processing unit 902, configured to obtain the encrypted data stream, includes: a communication unit 903, configured to receive a third encrypted data stream; and the processing unit 902, configured to process the third encrypted data stream according to a privacy computation rule matched with the encrypted data stream to obtain a processed encrypted data stream, including: when the second privacy computation rule is used to instruct the access network device to perform privacy computation on a data stream matched with the QoS configuration, adding privacy computation mark information in each data packet of the third encrypted data stream according to the second privacy computation rule matched with the third encrypted data stream to obtain a fourth encrypted data stream; and the privacy computation mark information is used to indicate that privacy computation is performed on the third encrypted data stream; and the communication unit 903, configured to send the processed encrypted data stream, including: sending the fourth encrypted data stream.
[0338] In a possible design, the second privacy calculation rule includes the QoS configuration and second indication information; or the second privacy calculation rule includes the QoS configuration, and the QoS configuration includes second indication information; where the second indication information is used to instruct the access network device to perform privacy calculation marking on a data flow matching the QoS configuration.
[0339] In a possible design, the communication unit 903 is further configured to receive the second privacy calculation rule from the session management network element.
[0340] In a possible design, the processing unit 902 configured to obtain the encrypted data stream includes: a fifth encrypted data stream generator; the processing unit 902 configured to process the encrypted data stream according to a privacy calculation rule matching the encrypted data stream to obtain a processed encrypted data stream includes: a third privacy calculation rule, where the third privacy calculation rule is used to instruct a terminal to perform privacy calculation marking on a data flow matching a quality of service (QoS) rule in the third privacy calculation rule, and the third privacy calculation rule is used to instruct the terminal to perform privacy calculation marking on the fifth encrypted data stream; and a sixth encrypted data stream generator configured to add privacy calculation marking information in each data packet of the fifth encrypted data stream according to the third privacy calculation rule to obtain the sixth encrypted data stream; and the communication unit 903 configured to send the processed encrypted data stream includes: a sixth encrypted data stream transmitter.
[0341] In a possible design, the third privacy calculation rule includes the QoS rule and third indication information; or the third privacy calculation rule includes the QoS rule, and the QoS rule includes third indication information; where the third indication information is used to instruct the terminal to perform privacy calculation marking on a data flow matching the QoS rule.
[0342] In a possible design, the communication unit 903 is further configured to receive the third privacy calculation rule from the session management network element.
[0343] It can be understood that the division of units in the above apparatus is merely a logical function division, and one function can correspond to one functional unit, or two or more functions can be integrated into one functional unit. In actual implementation, all or part of the units can be integrated into one physical entity, or distributed on different physical entities. In addition, the above functional units can be implemented in the form of hardware, software, or a combination of hardware and software. Whether a certain function is implemented in hardware or software depends on specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for specific applications, but such implementation should not be considered beyond the scope of the present application.
[0344] FIG. 10 is a structural schematic diagram of a terminal 1000 provided in an embodiment of the present application. The terminal 1000 can correspond to the terminal shown in FIG. 1, and is used to implement the operations of the terminal in the above embodiments. As shown in FIG. 10, the terminal includes one or more antennas 1010, a radio frequency processing system 1020, and a processor system 1030.
[0345] In the downlink or sidelink direction, the radio frequency processing system 1020 receives radio frequency signals through the antenna 1010, and sends the signals processed by radio frequency to the processor system 1030 for further processing. In the uplink or sidelink direction, the processor system 1030 performs signal processing on the information at the terminal side, and sends the signal to the radio frequency processing system 1020, which performs radio frequency processing on the signal and transmits it through the antenna 1010.
[0346] In one example, the radio frequency processing system 1020, as a communication interface of the terminal for external communication, can include a radio frequency front end 1021 (RFFE) and a radio frequency transceiver 1022 (RF transceiver). The RFFE 1021 is mainly used for one or more of shaping, passband selection, or gain processing of RF signals received by the antenna or RF signals to be sent through the antenna, and can include one or more of radio frequency switches, duplexers, filters, power amplifiers, antenna tuning, and low-noise amplifiers. The RFFE 1021 can be a circuit system composed of multiple discrete devices, or can be integrated and packaged in one or more chips. The radio frequency transceiver 1022 is used to process the RF signals received by the RFFE 1021 into baseband / intermediate frequency signals for the processor system 1030 to perform the next step of processing, and to process the baseband / intermediate frequency signals provided by the processor system 1030 into RF signals for sending to the RFFE 1021. The baseband / intermediate frequency signals transmitted between the radio frequency transceiver 1022 and the processor system 1030 can be digital signals or analog signals. The radio frequency transceiver 1022 can be implemented by one or more chips, which are usually referred to as radio frequency integrated circuits (RFICs).
[0347] In one example, the processor system 1030 can include one or more processors for processing signals and for executing appropriate instructions to carry out one or more communication protocols. Optionally, the processor system 1030 can further include a memory 1036. In one example, the one or more processors include at least one baseband processor 1031 (also referred to as a modem processor). The memory 1036 is used for storing data and / or computer program instructions. Optionally, the processor system 1030 can further include one or more application processors 1032 for implementing processing for an operating system of the terminal and for application layers. Optionally, the processor system 1030 can further include one or more of a voice subsystem 1033, a multimedia subsystem 1034, or an interface circuit 1035. The voice subsystem 1033 is used for processing voice signals, the multimedia subsystem 1034 is used for processing multimedia related operations, such as video codec, image processing, etc., and the interface circuit 1035 is used for communicating with other terminal components, such as a display 1040, input devices 1050, a memory 1060, etc. The above components in the processor system 1030 can communicate with each other through a bus or a communication interface circuit.
[0348] In one example, the processor system 1030 can be packaged as a processor chip, such as a SoC chip or a SIP chip. In one example, the processor system 1030 can be a system of multiple chips, for example, the baseband processor 1031 can be packaged separately as a chip, or packaged with part or all of the circuitry of a radio frequency processing system as a chip.
[0349] In one example, the memory 1036 can be an on-chip memory, i.e., located on the chip of the processor system 1030. In one example, the memory 1060 can be an off-chip memory, i.e., located off the chip of the processor system 1030.
[0350] In one example, the baseband processor 1031 can include one or more processor cores 10311 and interface circuit 10314. The one or more processor cores 10311 are configured to process signals and perform one or more communication protocols. Optionally, the baseband processor 1031 can also include a memory 10312 configured to store at least part of corresponding computer program instructions and / or data. In one example, the one or more processor cores 10311 implement the above-mentioned operations (e.g., perform the above-mentioned steps 501-503, steps 602, steps 607, steps 705-706, steps 801-803) by executing the computer program instructions stored in the memory 10312. In this application, the memory 10312 configured to store corresponding computer program instructions and / or data can mean that the memory 10312 is configured to store all corresponding computer program instructions and / or data for execution by the processor core 10311; or can mean that the memory 10312 is configured to store part of corresponding computer program instructions and / or data, which includes computer program instructions and / or data currently needed for execution by the processor core 10311, and the memory 10312 can store different parts of computer program instructions and / or data for execution by the processor core 10311 multiple times to implement the above-mentioned operations. The interface circuit 10314 is configured as a communication interface to communicate with other components, such as transmitting signals with the radio frequency processing system 1020, communicating with other subsystems and related components of the processor system 1030 through a bus, such as transmitting data control signals with the application processor 1032, and transmitting data or computer program instructions with the memory 1036 or the memory 1060. Optionally, in order to reduce the load of the processor core, the baseband signal processing circuit 10313 can be configured to perform at least part of the processing of the baseband signal, including one or more of demodulation, modulation, encoding or decoding of the signal.
[0351] In one example, the communication device provided in the present application can be a terminal 1000, including a processor system 1030 and a communication module of a radio frequency system 1020, the processor system 1030, or the baseband processor 1031.
[0352] In one example, the functional units in any of the above apparatuses can be one or more integrated circuits configured to implement the above methods, such as one or more application specific integrated circuits (ASICs), one or more central processing units (CPUs), one or more microprocessor units (MPUs), one or more microcontroller units (MCUs), one or more graphics processing units (GPUs), one or more artificial intelligence (AI) processors, one or more neural processing units (NPUs), one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms.
[0353] The processing units, processors, processor systems, application processors, baseband processors, processor circuits, or processor cores described above can be collectively referred to as processors, which can include one or a combination of CPUs, DSPs, MPUs, MCUs, GPUs, FPGAs, AI processors, or NPUs.
[0354] The storage unit and the memory can include one or more of the following storage media: random access memory (RAM), static RAM (SRAM), dynamic RAM (DRAM), phase-change memory (PCM), resistive RAM (ReRAM), magneto resistive RAM (MRAM), ferroelectric RAM (FRAM), cache, register, read-only memory (ROM), flash memory, erasable programmable ROM (EPROM), hard disk, etc. In one example, the computer program instructions for implementing the above embodiments can be stored on a non-volatile memory, such as at least part of the storage unit 901 and the memory 1060 (e.g., one or more of ROM, flash memory, EPROM, or hard disk).
[0355] In one example, the radio frequency transceiver 1022 and the radio frequency front end 1021 can also be packaged in one chip. In one example, the radio frequency transceiver 1022, the radio frequency front end 1021, and the baseband processor 1031 can also be packaged in one chip.
[0356] The terms "system" and "network" in the embodiments of the present application can be used interchangeably. "At least one" means one or more, and "multiple" means two or more. The "and / or" describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the cases of A alone, A and B together, and B alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the front and rear associated objects. "At least one of the following" or the like means any combination of these items, including any combination of single or multiple items. For example, "at least one of A, B, or C" includes A, B, C, AB, AC, BC, or ABC, and "at least one of A, B, and C" can also be understood to include A, B, C, AB, AC, BC, or ABC. In addition, unless otherwise specified, the ordinal numbers "first", "second", etc. mentioned in the embodiments of the present application are used to distinguish a plurality of objects, and are not used to limit the order, time sequence, priority or importance of the plurality of objects.
[0357] FIG. 11 is an example diagram of a communication apparatus 1100 provided by embodiments of the present application, which includes a communication interface 1120 and one or more processors 1110. The one or more processors 1110 are coupled with a memory 1130. The memory 1130 is used to store computer programs or instructions for implementing functions involved in various method embodiments. The one or more processors 1110 can execute the computer programs or instructions, which, when executed, cause the communication apparatus 1100 to implement various method embodiments described above. The communication interface 1120 is used to implement communication functions within the communication apparatus 1100 and / or communication functions of the communication apparatus 1100 with other apparatuses or components.
[0358] In a possible design, the one or more processors 1110 are used to communicate with other apparatuses or components via the communication interface 1120.
[0359] In a possible design, the communication apparatus 1100 can further include the memory 1130. Optionally, the memory 1130 and the processor 1110 are integrated together.
[0360] In a possible design, the memory 1130 is independent of the communication apparatus 1100 and located outside the communication apparatus 1100.
[0361] The communication apparatus 1100 described above can be a user plane network element, a module (for example, a circuit, a chip, or a chip system, etc.) in the user plane network element, or a logic node, a logic module, or software capable of implementing all or part of the functions of the user plane network element.
[0362] The communication apparatus 1100 described above can be an access network device, a module (for example, a circuit, a chip, or a chip system, etc.) in the access network device, or a logic node, a logic module, or software capable of implementing all or part of the functions of the access network device.
[0363] The communication apparatus 1100 described above can be a terminal, or a communication module in the terminal, or a chip responsible for communication functions such as a modem chip (also known as a baseband chip) or an SoC or SIP chip containing a modem module in the terminal.
[0364] The present application provides a computer-readable storage medium, which stores instructions, when the instructions are executed, implementing various method embodiments described above.
[0365] The present application provides a computer program product, which includes instructions or computer programs, when the instructions or computer programs are executed, implementing various method embodiments described above.
[0366] Those skilled in the art will appreciate that embodiments of the present application can be readily used as software, hardware, or a combination of software and hardware. In a software embodiment, various software modules are stored in memory (such as RAM, ROM, etc.) and executed by one or more general-purpose or special-purpose processors. In a hardware embodiment, various functions are performed by various hardware components. In an embodiment that is a combination of software and hardware, various functions are performed by a combination of software and hardware.
[0367] The present application is described in reference to the flow diagrams and / or block diagrams of the methods, apparatus (systems) and computer program products according to this application. It will be understood that each block of the flow diagrams and / or block diagrams, and combinations of blocks in the flow diagrams and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks.
[0368] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flow diagrams and / or block diagrams block or blocks.
[0369] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks.
[0370] Obviously, numerous modifications and variations of the present application are possible in light of the above teachings. It is therefore to be understood that within the scope of the claims and their equivalents, the application can be practiced otherwise than as specifically described.
Claims
1. A communication method, characterized in that, include: Obtain a first privacy computing context, which is used to indicate a data flow with privacy computing requirements; Based on the first privacy computing context, a privacy computing rule is determined, wherein the privacy computing rule includes at least one of a first privacy computing rule, a second privacy computing rule, or a third privacy computing rule; Wherein, the first privacy calculation rule is used to instruct the user plane network element to perform privacy calculation and / or privacy calculation marking on the data flow that matches the packet detection rule in the first privacy calculation rule; the second privacy calculation rule is used to instruct the access network device to perform privacy calculation and / or privacy calculation marking on the data flow that matches the QoS configuration in the second privacy calculation rule; and the third privacy calculation rule is used to instruct the terminal to perform privacy calculation marking on the data flow that matches the QoS rule in the third privacy calculation rule.
2. The method as described in claim 1, characterized in that, Also includes: The first privacy calculation rule is sent to the user plane network element.
3. The method as described in claim 1 or 2, characterized in that, The first privacy calculation rule includes the packet detection rule and the first indication information; or, The first privacy calculation rule includes the packet detection rule, and the packet detection rule includes first indication information; The first indication information is used to instruct the user plane network element to perform privacy calculations and / or privacy calculation markings on the data stream that matches the packet detection rule.
4. The method according to any one of claims 1 to 3, characterized in that, Also includes: The second privacy calculation rule is sent to the access network device.
5. The method according to any one of claims 1 to 4, characterized in that, The second privacy calculation rule includes the QoS configuration and the second indication information; or, The second privacy calculation rule includes the QoS configuration, and the QoS configuration includes second indication information; The second indication information is used to instruct the access network device to perform privacy calculations and / or privacy calculation markings on data streams that match the QoS configuration.
6. The method according to any one of claims 1 to 5, characterized in that, Also includes: The third privacy calculation rule is sent to the terminal.
7. The method according to any one of claims 1 to 6, characterized in that, The third privacy calculation rule includes the QoS rule and the third indication information; or, The third privacy calculation rule includes the QoS rule, and the QoS rule includes third indication information; The third indication information is used to instruct the terminal to perform privacy calculation marking on the data stream that matches the QoS rule.
8. The method according to any one of claims 1 to 7, characterized in that, The first privacy computation context includes any one or more of the following: User identifier, service identifier, encrypted computation function enable instruction or privacy computation algorithm identifier; The service identifier is used to indicate the data flow.
9. A communication method, characterized in that, include: Obtain the encrypted data stream; The encrypted data stream is processed according to privacy computation rules that match the encrypted data stream to obtain a processed encrypted data stream. Send the processed encrypted data stream; The privacy calculation rules include one of a first privacy calculation rule, a second privacy calculation rule, or a third privacy calculation rule; wherein the first privacy calculation rule is used to instruct user plane network elements to perform privacy calculation and / or privacy calculation marking on data flows that match the packet detection rule in the first privacy calculation rule; the second privacy calculation rule is used to instruct access network devices to perform privacy calculation and / or privacy calculation marking on data flows that match the Quality of Service (QoS) configuration in the second privacy calculation rule; and the third privacy calculation rule is used to instruct terminals to perform privacy calculation marking on data flows that match the QoS rule in the third privacy calculation rule.
10. The method as described in claim 9, characterized in that, The acquisition of the encrypted data stream includes: Receive the first encrypted data stream; The step of processing the encrypted data stream according to a privacy computation rule matching the encrypted data stream to obtain a processed encrypted data stream includes: When the first privacy calculation rule is used to instruct the user plane network element to perform privacy calculation on the data stream that matches the packet detection rule, the first encrypted data stream is subjected to privacy calculation according to the first privacy calculation rule that matches the first encrypted data stream to obtain the second encrypted data stream; Sending the processed encrypted data stream includes: Send the second encrypted data stream.
11. The method as described in claim 10, characterized in that, The first privacy computation rule also includes a second privacy computation context; The step of performing privacy calculations on the first encrypted data stream according to the first privacy calculation rule to obtain the second encrypted data stream includes: Based on the second privacy computation context, privacy computation is performed on the first encrypted data stream to obtain the second encrypted data stream.
12. The method as described in claim 11, characterized in that, The second privacy computation context includes any one or more of the following: Service identifier, encrypted computation function enablement indicator, or privacy computation algorithm identifier; The service identifier is used to indicate the first encrypted data stream.
13. The method according to any one of claims 10 to 12, characterized in that, The first privacy calculation rule includes the packet detection rule and the first indication information; or, The first privacy calculation rule includes the packet detection rule, and the packet detection rule includes first indication information; The first indication information is used to instruct the user plane network element to perform privacy calculations on the data stream that matches the packet detection rule.
14. The method as described in claim 9, characterized in that, The acquisition of the encrypted data stream includes: Receive the first encrypted data stream; The step of processing the encrypted data stream according to a privacy computation rule matching the encrypted data stream to obtain a processed encrypted data stream includes: When the first privacy calculation rule is used to instruct the user plane network element to perform privacy calculation marking on the data stream that matches the packet detection rule, privacy calculation marking information is added to each data packet of the first encrypted data stream according to the first privacy calculation rule that matches the first encrypted data stream to obtain the second encrypted data stream; wherein, the privacy calculation marking information is used to instruct privacy calculation to be performed on the first encrypted data stream; Sending the processed encrypted data stream includes: Send the second encrypted data stream.
15. The method as described in claim 14, characterized in that, The first privacy calculation rule includes the packet detection rule and the first indication information; or, The first privacy calculation rule includes the packet detection rule, and the packet detection rule includes first indication information; The first indication information is used to instruct the user plane network element to perform privacy calculation and labeling on the data stream that matches the packet detection rule.
16. The method according to any one of claims 10 to 15, characterized in that, Also includes: Receive the first privacy calculation rule from the session management network element.
17. The method as described in claim 9, characterized in that, The acquisition of the encrypted data stream includes: Receive a third encrypted data stream; The step of processing the encrypted data stream according to a privacy computation rule matching the encrypted data stream to obtain a processed encrypted data stream includes: When the second privacy calculation rule is used to instruct the access network device to perform privacy calculation on the data stream that matches the QoS configuration, the third encrypted data stream is subjected to privacy calculation according to the second privacy calculation rule that matches the third encrypted data stream to obtain the fourth encrypted data stream; Sending the processed encrypted data stream includes: Send the fourth encrypted data stream.
18. The method as described in claim 17, characterized in that, The second privacy computation rule also includes a third privacy computation context; The step of performing privacy calculations on the third encrypted data stream according to the second privacy calculation rule to obtain the fourth encrypted data stream includes: Based on the third privacy computation context, privacy computation is performed on the third encrypted data stream to obtain the fourth encrypted data stream.
19. The method as described in claim 18, characterized in that, The third privacy computation context includes any one or more of the following: Service identifier, encrypted computation function enablement indicator, or privacy computation algorithm identifier; The service identifier is used to indicate the third encrypted data stream.
20. The method according to any one of claims 17 to 19, characterized in that, The second privacy calculation rule includes the QoS configuration and the second indication information; or, The second privacy calculation rule includes the QoS configuration, and the QoS configuration includes second indication information; The second indication information is used to instruct the access network device to perform privacy calculations on data streams that match the QoS configuration.
21. The method as described in claim 9, characterized in that, The acquisition of the encrypted data stream includes: Receive a third encrypted data stream; The step of processing the encrypted data stream according to a privacy computation rule matching the encrypted data stream to obtain a processed encrypted data stream includes: When the second privacy calculation rule is used to instruct the access network device to perform privacy calculation marking on the data stream that matches the QoS configuration, privacy calculation marking information is added to each data packet of the third encrypted data stream according to the second privacy calculation rule that matches the third encrypted data stream to obtain a fourth encrypted data stream; wherein, the privacy calculation marking information is used to instruct privacy calculation to be performed on the third encrypted data stream; Sending the processed encrypted data stream includes: Send the fourth encrypted data stream.
22. The method as described in claim 21, characterized in that, The second privacy calculation rule includes the QoS configuration and the second indication information; or, The second privacy calculation rule includes the QoS configuration, and the QoS configuration includes second indication information; The second indication information is used to instruct the access network device to perform privacy calculation and labeling on data streams that match the QoS configuration.
23. The method according to any one of claims 17 to 21, characterized in that, Also includes: Receive the second privacy calculation rule from the session management network element.
24. The method as described in claim 9, characterized in that, The acquisition of the encrypted data stream includes: Generate a fifth encrypted data stream; The step of processing the encrypted data stream according to a privacy computation rule matching the encrypted data stream to obtain a processed encrypted data stream includes: According to the third privacy calculation rule matching the fifth encrypted data stream, privacy calculation tag information is added to each data packet of the fifth encrypted data stream to obtain a sixth encrypted data stream; wherein, the third privacy calculation rule is used to instruct the terminal to perform privacy calculation tagging on the data stream matching the Quality of Service (QoS) rule in the third privacy calculation rule, and the privacy calculation tag information is used to instruct privacy calculation to be performed on the fifth encrypted data stream; Sending the processed encrypted data stream includes: Send the sixth encrypted data stream.
25. The method as described in claim 24, characterized in that, The third privacy calculation rule includes the QoS rule and the third indication information; or, The third privacy calculation rule includes the QoS rule, and the QoS rule includes third indication information; The third indication information is used to instruct the terminal to perform privacy calculation marking on the data stream that matches the QoS rule.
26. The method as described in claim 24 or 25, characterized in that, Receive the third privacy computation rule from the session management network element.
27. A communication device, characterized in that, Includes modules for performing the method of any one of claims 1 to 8, or the method of any one of claims 9 to 26.
28. A communication device, characterized in that, It includes a processor and an interface circuit, the processor being configured to communicate with other devices via the interface circuit to implement the method of any one of claims 1 to 8, or to implement the method of any one of claims 9 to 26.
29. A computer program product, characterized in that, The computer program product includes instructions that, when executed, implement the method of any one of claims 1 to 8, or the method of any one of claims 9 to 26.
30. A computer-readable storage medium, characterized in that, The storage medium stores a computer program or instructions, which, when executed, implement the method of any one of claims 1 to 8, or the method of any one of claims 9 to 26.
Citation Information
Patent Citations
Information processing method and device based on implicit indication encryption
CN114640988A
Information privacy protection method and device, equipment and storage medium
CN114692194A
Data transmission method and communication apparatus
WO2024092399A1