Communication method and communication apparatus
By defining the security policy between the terminal device and the user plane function in the session management function, the problem of base station vulnerability to attack in the field environment is solved, end-to-end data transmission security protection is achieved, and the security of data transmission is improved and the latency is reduced.
Patent Information
- Application Number
- PCT/CN2025/103777
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-16
- Filing Date
- 2025-06-26
- Publication Date
- 2026-01-22
AI Technical Summary
In existing mobile communication networks, base stations deployed in the wild are vulnerable to near-end detection and physical attacks, resulting in weak data transmission security.
The session management function determines the security policy between the terminal device and the user plane function, including information on the service data flow (SDF) or quality of service flow (QoS) flow and its corresponding security processing methods, to achieve end-to-end security protection.
It improves the security of data transmission between terminal devices and user plane functions, provides fine-grained security policies and on-demand security protection, and reduces data transmission latency.
Smart Images

Figure CN2025103777_22012026_PF_FP_ABST
Abstract
Description
Communication methods and communication devices
[0001] This application claims priority to Chinese Patent Application No. 202410954279.0, filed on July 16, 2024, entitled "Communication Method and Communication Device", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of wireless communication, and more specifically, to a communication method and a communication device. Background Technology
[0003] In current mobile communication networks, user data is transmitted from base stations to user plane function (UPF) network elements. User plane data packets are protected during transmission through hop-by-hop security mechanisms. Specifically, on one hand, user data undergoes packet encryption and / or integrity protection between the terminal device and the base station (air interface). The terminal device and the base station use corresponding keys to verify and decrypt the data packets. On the other hand, the base station and UPF network elements protect the transmitted user data using Internet Protocol Security (IPsec). However, because base stations are deployed in outdoor environments, they are vulnerable to near-end probes and physical attacks. Therefore, the above scheme may offer relatively weak security for data transmission. Summary of the Invention
[0004] This application provides a communication method and a communication device that can achieve end-to-end security protection between terminal devices and user plane functions, thereby improving the security of data transmission between terminal devices and user plane functions.
[0005] Firstly, a communication method is provided. This method can be applied to the session management function side; that is, the method can be executed by the session management function or by its components (such as a chip, chip system, circuit, or communication module). This application does not limit this. The following description mainly uses the session management function as an example.
[0006] The method may include: determining a security policy for a terminal device's session, the security policy being used for secure processing of data transmission between the terminal device and the user plane function, the security policy including information of a Service Data Flow (SDF) and a security processing method corresponding to the SDF, or the security policy including information of a Quality of Service (QoS) flow and a security processing method corresponding to the QoS flow; and sending the security policy to the terminal device and the user plane function.
[0007] As an example, a security policy may include information about at least one SDF and a security processing method corresponding to each of the at least one SDF, that is, a security processing method at the SDF granularity. Alternatively, a security policy may include information about at least one QoS flow and a security processing method corresponding to each of the at least one QoS flow, that is, a security processing method at the QoS flow granularity.
[0008] As an example, SDF information is about packet filters.
[0009] As an example, the information for a QoS flow is the QoS flow identifier (QFI).
[0010] Based on the above technical solution, a security policy for data transmission between the terminal device and user plane functions is determined for the terminal device's session. This enables end-to-end security protection between the terminal device and user plane functions, improving the security of data transmission between them. Furthermore, this security policy includes SDF information and corresponding security processing methods; in other words, the security policy can be SDF-granular (or SDF-level). Alternatively, the security policy includes QoS flow information and corresponding security processing methods; in other words, the security policy can be QoS flow-granular (or QoS flow-level). Therefore, the above technical solution can also design different security processing methods based on different services or different QoS flows, thereby providing more granular security policies and protections, and thus providing on-demand security.
[0011] In conjunction with the first aspect, in some implementations of the first aspect, determining the security policy of the terminal device's session includes: determining the security policy of the terminal device's session during the session establishment process or the session modification process.
[0012] Based on the above technical solutions, a security policy can be determined for the terminal device's session during the session establishment process (e.g., when the session management function receives a session establishment request message), or during the session modification process (e.g., when the session management function receives a session modification request message). This allows the security policy to be determined during the session establishment or modification phase, enabling subsequent data transmissions to directly use this security policy, reducing data transmission latency and improving user experience.
[0013] In conjunction with the first aspect, in some implementations of the first aspect, the method further includes: sending a key corresponding to the security processing method to the user plane function; or, sending a first key to the user plane function, wherein the first key is used to determine the key corresponding to the security processing method.
[0014] Based on the above technical solution, different keys can be determined for different security processing methods and the user plane function can be notified. In this way, the user plane function can then perform encryption or decryption based on the security processing method used for the data.
[0015] In conjunction with the first aspect, in some implementations of the first aspect, sending the security policy to the terminal device includes: sending QoS rules to the terminal device, the QoS rules including the security policy.
[0016] As an example, an OoS rule includes information about at least one SDF and the security processing method corresponding to each SDF, or an OoS rule includes information about a QoS flow and the security processing method corresponding to the QoS flow.
[0017] Based on the above technical solution, the session management function can send security policies to the terminal device through QoS rules. In this way, when the terminal device needs to determine the security processing method of the data, it can find the security processing method in the corresponding QoS rule based on the QoS flow information of the data.
[0018] In conjunction with the first aspect, in some implementations of the first aspect, sending the security policy to the user plane function includes: sending an N4 rule to the user plane function, wherein the N4 rule includes the security policy.
[0019] As an example, an N4 rule includes information about at least one SDF and a security processing method corresponding to each of the at least one SDF; or, an N4 rule includes information about at least one QoS flow and a security processing method corresponding to each of the at least one QoS flow.
[0020] Based on the above technical solution, the session management function can send security policies to the user plane function through N4 rules. In this way, when the user plane function needs to determine the security processing method of the data, it can find the corresponding security processing method in the N4 rule based on the QoS of the data.
[0021] In conjunction with the first aspect, in some implementations of the first aspect, the security processing method includes one or more of the following: confidentiality processing, authentication and encryption processing of associated data, and integrity processing; or, the security processing method is: no processing.
[0022] Secondly, a communication method is provided. This method can be applied to the transmitting device side; that is, the method can be executed by the transmitting device. The transmitting device can be a terminal device, or a component of a terminal device (e.g., a chip, chip system, circuit, or communication module); or, the transmitting device can be a user plane function, or a component of a user plane function (e.g., a chip, chip system, circuit, or communication module), and this application does not limit this. The following description mainly uses a transmitting device as an example.
[0023] The method may include: protecting data with security based on a session security policy of the terminal device, wherein the security policy is used for secure processing of data transmission between the terminal device and the user plane function, and the security policy includes information of the Service Data Flow (SDF) and a security processing method corresponding to the SDF; or, the security policy includes information of the Quality of Service (QoS) flow and a security processing method corresponding to the QoS flow; and sending the protected data.
[0024] Based on the above technical solution, the transmitting device can provide security protection for data based on a security policy. This security policy is for data transmission between the terminal device and the user plane function, thus achieving end-to-end security protection between the terminal device and the user plane function and improving the security of data transmission between them. Furthermore, the security policy includes SDF information and the corresponding security processing method; in other words, the security policy can be SDF-granular (or SDF-level). Alternatively, the security policy includes QoS flow information and the corresponding security processing method; in other words, the security policy can be QoS flow-granular (or QoS flow-level). Therefore, the above technical solution can also design different security processing methods based on different services or different QoS flows, thereby providing more granular security policies and security protection, and thus providing on-demand security.
[0025] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes receiving the security policy before the data is securely protected by a security policy based on the terminal device's session.
[0026] In conjunction with the second aspect, in some implementations of the second aspect, the data matches the information of the SDF, and the security policy based on the terminal device's session protects the data, including: protecting the data based on the security processing method corresponding to the SDF.
[0027] Based on the above technical solution, the transmitting device can determine the security processing method corresponding to the SDF based on the data's SDF and security policy, and then protect the data based on the security processing method.
[0028] In conjunction with the second aspect, in some implementations of the second aspect, the data matches the information of the QoS stream; the security policy based on the terminal device's session protects the data, including: protecting the data based on a security processing method corresponding to the QoS stream.
[0029] Based on the above technical solution, the transmitting device can determine the security processing method corresponding to the QoS stream and security policy, and then protect the data based on the security processing method.
[0030] In conjunction with the second aspect, in some implementations of the second aspect, the information of the data matching the QoS flow includes: the data matching a packet filter; the security policy is included in the QoS rules corresponding to the QoS flow; and the security protection of the data based on the security processing method corresponding to the QoS flow includes: when the data matches the packet filter in the QoS rules, the data is protected based on the security processing method in the QoS rules.
[0031] In conjunction with the second aspect, in some implementations of the second aspect, the information of the data matching the QoS flow includes: the data matching a packet filter; the security policy is included in the N4 rule corresponding to the QoS flow; and the security protection of the data based on the security processing method corresponding to the QoS flow includes: when the data matches the packet filter in the N4 rule, the data is protected based on the security processing method in the N4 rule.
[0032] In conjunction with the second aspect, in some implementations of the second aspect, the securely protected data includes a security header that indicates the secure processing method of the data.
[0033] Based on the above technical solution, after determining the secure processing method for the data, the transmitting device can generate a security header based on that method and include it in the transmitted data. This allows the receiving device to efficiently and accurately determine the appropriate security processing method based on the data's security header, thereby reducing the latency caused by the receiving device determining the security processing method.
[0034] In conjunction with the second aspect, in some implementations of the second aspect, the secure data includes a message authentication code, which is constructed based on the security header and the key of the security header.
[0035] In conjunction with the second aspect, in some implementations of the second aspect, the security processing method includes one or more of the following: confidentiality processing, authentication and encryption processing of associated data, and integrity processing; or, the security processing method is: no processing.
[0036] Thirdly, a communication method is provided. This method can be applied to the receiving device side, that is, the method can be executed by the receiving device. The receiving device can be a terminal device, or a component of a terminal device (e.g., a chip, chip system, circuit, or communication module); or, the receiving device can be a user plane function, or a component of a user plane function (e.g., a chip, chip system, circuit, or communication module), and this application does not limit this. The following description mainly uses a receiving device as an example.
[0037] The method may include: receiving data; parsing the data based on a secure processing method, wherein the secure processing method is determined based on the security policy of the terminal device's session, and the security policy is used for secure processing of data transmission between the terminal device and the user plane function, wherein the security policy includes information of the Service Data Flow (SDF) and the security processing method corresponding to the SDF, or the security policy includes information of the Quality of Service (QoS) flow and the security processing method corresponding to the QoS flow.
[0038] In conjunction with the third aspect, in some implementations of the third aspect, before parsing the data based on the secure processing method of the data, the method further includes: receiving the security policy.
[0039] In conjunction with the third aspect, in some implementations of the third aspect, the data matches the information of the SDF, and the security processing method based on the data parses the data, including: parsing the data based on the security processing method corresponding to the SDF.
[0040] In conjunction with the third aspect, in some implementations of the third aspect, the data matches the information of the QoS stream; the security processing method based on the data parses the data, including: parsing the data based on the security processing method corresponding to the QoS stream.
[0041] In conjunction with the third aspect, in some implementations of the third aspect, the security policy is included in the QoS rules corresponding to the QoS flow, and parsing the data based on the security processing method corresponding to the QoS flow includes: parsing the data based on the security processing method in the QoS rules; or, the security policy is included in the N4 rules corresponding to the QoS flow, and parsing the data based on the security processing method corresponding to the QoS flow includes: parsing the data based on the security processing method in the N4 rules.
[0042] In conjunction with the third aspect, in some implementations of the third aspect, the data includes a security header indicating a secure processing method for the data; parsing the data based on the secure processing method includes: parsing the data based on the secure processing method indicated by the security header of the data.
[0043] In conjunction with the third aspect, in some implementations of the third aspect, the data includes a message authentication code, which is constructed based on the security header and the key of the security header.
[0044] In conjunction with the third aspect, in some implementations of the third aspect, the security policy is included in the QoS rules corresponding to the QoS flow, and the security processing method based on the data parses the data, including: parsing the data when the security processing method in the QoS rules is consistent with the security processing method of the data indicated by the security header.
[0045] In conjunction with the third aspect, in some implementations of the third aspect, the security policy is included in the N4 rule corresponding to the QoS flow, and the data parsing based on the data security processing method includes: parsing the data when the security processing method in the N4 rule is consistent with the security processing method of the data indicated by the security header.
[0046] In conjunction with the third aspect, in some implementations of the third aspect, the security processing method includes one or more of the following: confidentiality processing, authentication and encryption processing of associated data, and integrity processing; or, the security processing method is: no processing.
[0047] For possible implementation methods and effective effects of the third aspect, please refer to the relevant descriptions of the first and second aspects, which will not be elaborated here.
[0048] Fourthly, a communication method is provided. This method can be applied to the receiving device side, that is, the method can be executed by the receiving device. The receiving device can be a terminal device, or a component of a terminal device (e.g., a chip, chip system, circuit, or communication module); or, the receiving device can be a user plane function, or a component of a user plane function (e.g., a chip, chip system, circuit, or communication module), and this application does not limit this. The following description mainly uses a receiving device as an example.
[0049] The method may include: receiving data, the data including a security header indicating a secure processing method for the data; and parsing the data based on the secure processing method.
[0050] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the secure processing method of the data is determined based on the security policy of the terminal device's session. The security policy is used for secure processing of data transmission between the terminal device and the user plane function. The security policy includes information of the Service Data Flow (SDF) and the security processing method corresponding to the SDF. Alternatively, the security policy includes information of the Quality of Service (QoS) flow and the security processing method corresponding to the QoS flow.
[0051] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the method further includes: receiving the security policy.
[0052] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the data includes a message authentication code, which is constructed based on the security header and the key of the security header.
[0053] In conjunction with the fourth aspect, in some implementations of the fourth aspect, the security processing method includes one or more of the following: confidentiality processing, authentication and encryption processing of associated data, and integrity processing; or, the security processing method is: no processing.
[0054] Fifthly, a communication method is provided. This method can be applied to the core network element side; that is, the method can be executed by the core network element, or by a component of the core network element (such as a chip, chip system, circuit, or communication module). This application does not limit this. The following description mainly uses the core network element as an example.
[0055] The method may include: determining a security policy for a terminal device's session, the security policy being used for secure processing of data transmission between the terminal device and a user plane function, the security policy including information of a Service Data Flow (SDF) and a security processing method corresponding to the SDF, or the security policy including information of a Quality of Service (QoS) flow and a security processing method corresponding to the QoS flow; and sending the security policy to a session management function.
[0056] For the possible implementation methods and effective effects of the fourth and fifth aspects, please refer to the relevant descriptions of the first and second aspects above, which will not be repeated here.
[0057] Sixthly, a communication apparatus is provided for performing the methods of any one of the first to fifth aspects and any possible implementation thereof. Specifically, the apparatus may include units and / or modules for performing the methods of any one of the first to fifth aspects and any possible implementation thereof, such as processing units and / or communication units.
[0058] In one implementation, the device is a communication device (such as a terminal device, a user plane function, or a session management function). When the device is a communication device, the communication unit can be a transceiver or an input / output interface; the processing unit can be at least one processor. Optionally, the transceiver can be a transceiver circuit. Optionally, the input / output interface can be an input / output circuit.
[0059] In another implementation, the device is a chip, chip system, circuit, or communication module for communication equipment (such as terminal equipment, user plane functions, or session management functions). When the device is a chip, chip system, or circuit for communication equipment, the communication unit can be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip, chip system, or circuit; the processing unit can be at least one processor, processing circuit, or logic circuit.
[0060] A seventh aspect provides a communication device comprising: at least one processor configured to cause the device to perform any of the first to fifth aspects and any possible implementation thereof.
[0061] Optionally, the at least one processor is configured to execute computer programs or instructions to perform the methods of any of the first to fifth aspects and any possible implementation thereof.
[0062] Optionally, the device further includes a memory for storing the computer program or instructions.
[0063] Optionally, the at least one processor is coupled to a memory for storing the computer program or instructions. The memory may be located externally to the device.
[0064] Optionally, the device also includes a communication interface through which the processor reads instructions from memory. This can be understood as the communication interface being coupled to the processor and used to input computer programs or instructions to the processor, or to output information from the processor.
[0065] Unless otherwise specified, or if the transmission and acquisition / reception operations involved do not contradict their actual function or internal logic in the relevant description, they can be understood as output, input, or other operations, or as transmission and reception operations performed by radio frequency circuits and antennas. This application does not limit them in this regard.
[0066] In one implementation, the device is a communication device (such as a terminal device, a user plane function, or a session management function).
[0067] In another implementation, the device is a chip, chip system, circuit, or communication module for communication equipment (such as terminal equipment, user plane functions, or session management functions). Optionally, the chip is a modem chip, also known as a baseband chip, or a system-on-chip (SoC) chip containing a modem core, or a system-in-package (SIP) chip.
[0068] Eighthly, a computer-readable storage medium is provided that stores a computer program (e.g., program code) or instructions that, when executed on a communication device, cause the communication device to perform the methods of any one of the first to fifth aspects and any possible implementation thereof.
[0069] Ninth aspect, a computer program product containing instructions is provided, which, when run on a computer, causes the computer to perform the methods of any one of the first to fifth aspects and any possible implementation thereof.
[0070] A tenth aspect provides a communication system comprising at least one of the following: a terminal device, a user plane function, and a session management function. The session management function is used to execute the method provided in any implementation of the first aspect. The terminal device is used to execute the method provided in any implementation of the second aspect, and the user plane function is used to execute the method provided in any implementation of the third or fourth aspect; or, the user plane function is used to execute the method provided in any implementation of the second aspect, and the terminal device is used to execute the method provided in any implementation of the third or fourth aspect. Attached Figure Description
[0071] Figure 1 is a schematic diagram of a network architecture applicable to an embodiment of this application.
[0072] Figure 2 is a schematic diagram of a communication method 200 provided in an embodiment of this application.
[0073] Figure 3 is a schematic diagram of a communication method 300 provided in an embodiment of this application.
[0074] Figure 4 is a schematic diagram of key deduction.
[0075] Figure 5 is a schematic diagram of a communication method 500 provided in an embodiment of this application.
[0076] Figure 6 is a schematic diagram of a communication method 600 provided in an embodiment of this application.
[0077] Figure 7 is a schematic diagram of QoS rules.
[0078] Figure 8 is a schematic diagram of a communication method 800 provided in an embodiment of this application.
[0079] Figure 9 is a schematic diagram of a communication method 900 provided in an embodiment of this application.
[0080] Figure 10 is a schematic diagram of a communication device 1000 provided in an embodiment of this application.
[0081] Figure 11 is a schematic diagram of another communication device 1100 provided in an embodiment of this application.
[0082] Figure 12 is a schematic diagram of a chip system 1200 provided in an embodiment of this application. Detailed Implementation
[0083] The technical solutions in this application will now be described with reference to the accompanying drawings.
[0084] Before introducing the scheme of this application, the following points should be noted.
[0085] (1) In this application, "instruction" can include direct instruction, indirect instruction, explicit instruction, implicit instruction, etc. When describing an instruction information as indicating A, it can be understood that the instruction information carries A, carries the identifier of A, carries B which is associated with A, carries the identifier of B which is associated with A, etc. In other words, if the receiving side of an instruction information can determine A based on the instruction information, it can be described as the instruction information indicating A, and the specific method of determination is not limited. When it is understood that the instruction information carries A, "instruction" can be replaced with "includes". In this case, a statement such as "send / receive instruction information, the instruction information indicates A" can be replaced with "send / receive A".
[0086] In this application, the information indicated by the instruction information is called the information to be instructed. In specific implementations, there are many ways to indicate the information to be instructed, such as, but not limited to, directly indicating the information to be instructed, such as the information to be instructed itself or its index. It can also indirectly indicate the information to be instructed by indicating other information, where there is a relationship between the other information and the information to be instructed. It can also indicate only a part of the information to be instructed, while the other parts are known or pre-agreed upon. For example, the instruction of specific information can be achieved by using a pre-agreed (e.g., protocol-defined) arrangement of various pieces of information, thereby reducing instruction overhead to some extent. Furthermore, the information to be instructed can be sent as a whole or divided into multiple sub-information pieces, and the sending period and / or timing of these sub-information pieces can be the same or different.
[0087] (2) In this application, the expression " / " is used to indicate that the objects before and after are in an "or" relationship; for example, A / B can mean: A or B. The expression "and / or" is used to indicate that the objects before and after are in a relationship of either "and" or "or"; for example, A and / or B can mean the following: A exists alone, B exists alone, A and B exist simultaneously, where A and B can be single or multiple. "At least one of the following" or similar expressions are used to indicate any combination of the listed items; for example, at least one of A, B and / or C can mean the following: A exists alone, B exists alone, C exists alone, A and B exist simultaneously, B and C exist simultaneously, A and C exist simultaneously, A, B and C exist simultaneously, where A, B, and C can be single or multiple.
[0088] (3) In this application, "send" and "receive" indicate the direction of signal transmission. For example, "send information to XX" can be understood as the destination of the information being XX, which may include direct transmission via the air interface or indirect transmission by other units or modules via the air interface. "Receive information from YY" can be understood as the source of the information being YY, which may include direct reception from YY via the air interface or indirect reception from YY by other units or modules via the air interface. "Send" can also be understood as the "output" of the chip interface, and "receive" can also be understood as the "input" of the chip interface. In other words, sending and receiving can occur between devices, such as between network devices and terminal devices, or within a device, such as between components, modules, chips, software modules, or hardware modules within the device via a bus, wiring, or interface.
[0089] (4) In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terms and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0090] (5) In this application, "first," "second," and "#1," "#2," and "#A" are merely for descriptive convenience and are used to distinguish objects, and are not intended to limit the scope of the embodiments of this application. They are not used to describe the order or sequence of features. It should be understood that such described objects can be interchanged where appropriate so as to describe solutions other than those in the embodiments of this application.
[0091] (6) In this application, "predefined" can mean a standard protocol predefined, or it can mean a pre-agreed or pre-negotiated agreement between devices. Here, "protocol" can refer to a standard protocol in the field of communications, for example, it may include fourth-generation (4G) protocols. thGeneration 4G network, fifth generation (5G) network th This application does not limit the scope to network protocols such as 5G (generation, 5G), New Radio (NR) protocols, 5.5G network protocols, and related protocols applied in future communication systems.
[0092] (7) In this application, the words “exemplary,” “for example,” etc., are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as an “example” in this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the word “example” is intended to present the concept in a concrete manner. In the embodiments of this application, “of,” “corresponding, relevant,” and “corresponding” may sometimes be used interchangeably, and it should be noted that their intended meanings are consistent unless their distinction is emphasized.
[0093] First, let me introduce the communication system to which this application applies.
[0094] The technical solutions provided in this application can be applied to various communication systems, such as 5th generation (5G) or new radio (NR) systems, long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, and LTE time division duplex (TDD) systems. The technical solutions provided in this application can also be applied to future communication systems. Furthermore, the technical solutions provided in this application can be applied to device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, machine-to-machine (M2M) communication, machine-type communication (MTC), and Internet of Things (IoT) communication systems. The technical solutions provided in this application can also be applied to non-terrestrial network (NTN) systems such as inter-satellite communication and satellite communication.
[0095] As an example, a satellite communication system includes a satellite base station and terminal equipment. The satellite base station provides communication services to the terminal equipment. Satellite base stations can also communicate with each other. A satellite can act as a base station or as a terminal device. Here, "satellite" can refer to drones, hot air balloons, low-Earth orbit satellites, medium-Earth orbit satellites, high-Earth orbit satellites, etc. "Satellite" can also refer to non-terrestrial base stations or non-terrestrial equipment.
[0096] As an example, V2X communication can include: vehicle-to-vehicle (V2V) communication, vehicle-to-infrastructure (V2I) communication, vehicle-to-pedestrian (V2P) communication, and vehicle-to-network (V2N) communication.
[0097] In communication systems, the portion operated by the operator can be referred to as a public land mobile network (PLMN), or operator network, etc. A PLMN is a network established and operated by the government or its approved operators for the purpose of providing terrestrial mobile communication services to the public. It is primarily a public network where mobile network operators (MNOs) provide mobile broadband access services to users. The PLMN described in this application embodiment can specifically be a network conforming to the 3rd Generation Partnership Project (3GPP) standards, or simply a 3GPP network. 3GPP networks typically include, but are not limited to, 5G networks, 4th-generation (4G) networks, and other future communication systems.
[0098] In a communication system, a device can send signals to or receive signals from another device. These signals can include information, signaling, or data. The device can also be replaced by an entity, network entity, communication equipment, communication module, node, communication node, etc. This application uses a device as an example for description.
[0099] To make it easier to understand, let's first introduce a few concepts.
[0100] 1. Protocol Data Unit (PDU) Session: An association between user equipment (UE) and data network (DN) used to provide a PDU connection service, or in other words, to provide the UE with a user plane connection to the DN. The network (such as a 5G network) provides data exchange services between the UE and the DN, which may be referred to as the PDU connection service. The UE obtains the PDU connection service by initiating a PDU session establishment request to the network. The network provides the PDU connection service by maintaining the PDU session for the UE.
[0101] A PDU session can be identified by a PDU session identifier (PDU session ID). Since the PDU session is at the UE level, each PDU session identifier can also correspond to a terminal device.
[0102] 2. Quality of Service (QoS) Flow: A QoS flow is the finest granularity of QoS differentiation within a PDU session. A specific QoS flow generally has specific parameter specifications corresponding to its requirements, and the network side can provide corresponding QoS for the data needs (or data requirements) of a specific QoS flow. In a 5G system, a QoS flow identifier (QFI) can be used to identify a QoS flow. A PDU session can include multiple QoS flows, but each QoS flow has a different QFI. In other words, a QFI is unique within a PDU session.
[0103] In the following embodiments, QFI is used as an example to illustrate the QoS flow information, but this is not a limitation. For example, the QoS flow information can also be a 5G QoS identifier (5QI).
[0104] 3. Packet Filtering and Identification for Service Data Flow (SDF): In the current network, the user plane function (UPF) network element responsible for transmitting user data mainly identifies whether packets belong to a specific session or service data flow through traffic monitoring. Specifically, the session management function (SMF) network element is responsible for instructing the UPF network element on how to determine whether user data traffic belongs to a certain packet detection rule (PDR). Other parameters provided in the PDR describe how the UPF network element processes packets that match this detection information.
[0105] For example, the SMF controls traffic detection of UPF network elements by providing detection information corresponding to each PDR. As an example, the detection information may include one or more of the following: CN tunnel information, network instance, QFI, IP packet filter set, application identifier, and full qualified domain name (FQDN) filter for DNS query messages. As an example, the IP packet filter set may include one or more of the following: source / destination IP address or IPv6 prefix, source / destination port number, protocol ID of IP upper / lower layer header type, service type (IPv4) / traffic type (IPv6) and MASK, flow label (IPv6), security parameter index, and packet filtering direction.
[0106] UPF identifies which session a specific packet belongs to based on the above information. Specifically, on a 3GPP connection, by using the IP address assigned to each session of the UE by UPF and the source / destination IP address or IPv6 prefix in the IP packet filter set mentioned above, it can identify which specific session the corresponding packet belongs to.
[0107] For example, if the UPF assigns IP address 1 to a session 1 of a UE, then the source address of packets sent by the UE to the UPF is IP address 1. By filtering the source address of the packets, the corresponding traffic packets can be mapped to session 1 of the UE. Furthermore, based on the IP address to which the data packet is sent to the DN, the corresponding service can be identified. Traffic packets coming from the DN, if filtered by their destination address (e.g., IP address 1), indicate that the traffic corresponds to session 1.
[0108] The network architecture is described below.
[0109] Referring to Figure 1, as an example, Figure 1 is a schematic diagram of a network architecture applicable to an embodiment of this application. As shown in Figure 1, this network architecture takes the 5th generation system (5GS) as an example. As an example, this network architecture includes three parts: a terminal device part, a data network (DN) part, and an operator network PLMN part. The operator network PLMN part may include, but is not limited to, a radio access network (RAN) and a core network (CN) part.
[0110] The following is a brief introduction to the network elements of each part.
[0111] 1. Terminal equipment, including user equipment (UE). UE: Also known as a terminal or terminal device, it can be a device or module that accesses the aforementioned communication system and has corresponding communication functions. UE can include various devices with wireless communication capabilities, which can be used to connect people, objects, machines, etc. Terminal devices can be widely used in various scenarios, such as: cellular communication, D2D, V2X, peer-to-peer, M2M, MTC, IoT, virtual reality (VR), augmented reality (AR), industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, smart cities, drones, robots, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery, etc. Terminal devices can be terminals in any of the above scenarios, such as MTC terminals, IoT terminals, etc. Terminal devices can be UEs (User Equipment), terminals, fixed equipment, mobile station equipment or mobile devices, subscriber units, handheld devices, vehicle-mounted equipment, wearable devices, cellular phones, smartphones, session initiation protocol (SIP) phones, wireless data cards, personal digital assistants (PDAs), computers, tablets, laptops, wireless modems, handsets, laptop computers, computers with wireless transceiver capabilities, smart books, vehicles, satellites, global positioning system (GPS) devices, target tracking devices, aircraft (e.g., drones, helicopters, multiple helicopters, four helicopters, or airplanes), ships, remote control devices, smart home devices, industrial equipment, transportation vehicles with wireless communication capabilities, communication modules, and roadside units with terminal functions, all conforming to the 3GPP (3rd Generation Partnership Project) standard. The device may be a wireless communication unit (RSU), or a device built into the aforementioned device (e.g., a communication module, modem, or chip in the aforementioned device), or other processing devices connected to the wireless modem.
[0112] In addition, the UE can store a long-term key K and related functions. During two-way authentication, the UE can use K and related functions to verify the authenticity of the network.
[0113] It should be understood that in certain scenarios, a UE can also be used as a base station. For example, a UE can act as a scheduling entity, providing sidelink signaling between UEs in scenarios such as V2X, D2D, or end-to-end.
[0114] In this embodiment, the device for implementing the functions of a terminal device, i.e., the terminal device, can be the terminal device itself, or it can be any device capable of supporting the terminal device in implementing the functions, such as a chip system, chip, circuit, or communication module (i.e., a communication module that performs communication functions). This device can be installed in the terminal device. In this embodiment, the chip system can be composed of chips, or it can include chips and other discrete devices. Furthermore, the device can also be configured with program instructions for performing corresponding communication functions.
[0115] 2. The data network portion can include a Data Network (DN), which provides the network for transmitting data. Examples include carrier service networks (such as IP Multimedia Subsystem (IMS)), the Internet, and third-party service networks. A DN can also be called a Packet Data Network (PDN), and is typically a network located outside the carrier network, such as a third-party network.
[0116] 3. The (R)AN portion may include one or more access network elements or access network devices. The access network provides network access functionality to authorized users in a specific area and includes radio access network (RAN) devices and AN devices. RAN devices are primarily radio network devices within the 3GPP network, while AN devices may be access network devices not defined by 3GPP.
[0117] Access networks can be those employing different access technologies. Currently, there are two types of wireless access technologies: 3GPP access technologies (such as those used in 3G, 4G, or 5G systems) and non-3GPP access technologies.
[0118] Among them, 3GPP access technology refers to access technology that conforms to 3GPP standards and specifications. For example, the access network equipment in a 5G system is called a next-generation NodeB (gNB) or RAN.
[0119] Non-3GPP access technologies refer to access technologies that do not conform to 3GPP standards and specifications. Examples include air interface technologies such as access points (APs) in Wireless Fidelity (WiFi), Worldwide Interoperability for Microwave Access (WiMAX), and Code Division Multiple Access (CDMA) networks. Access network equipment (AN equipment) allows terminal equipment and the 3GPP core network to interconnect using non-3GPP technologies.
[0120] The access network device in this application embodiment can be a device or module with corresponding communication functions. The access network device can be a device used to communicate with terminal devices; it can also be called a network device or a wireless access network device, such as a base station. In this application embodiment, the access network device can refer to a RAN node (or device) that connects terminal devices to a wireless network. A base station can broadly encompass, or be replaced by, various names including: NodeB, evolved NodeB (eNB), gNB, relay station, access point, transmitting and receiving point (TRP), transmitter, master station, auxiliary station, multiple standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. A base station can be a macro base station, micro base station, relay node, donor node, or similar entities, or combinations thereof. A base station can also refer to a communication module, modem, or chip installed within the aforementioned equipment or apparatus. A base station can also be a mobile switching center, a device that performs base station functions in D2D, V2X, and M2M communications, or a device that performs base station functions in future communication systems. A base station can support networks using the same or different access technologies. The embodiments of this application do not limit the specific technologies or device forms used in the network equipment.
[0121] Base stations can be fixed or mobile. For example, a helicopter or drone can be configured to act as a mobile base station, and one or more cells can move depending on the location of the mobile base station. In other examples, a helicopter or drone can be configured as a device to communicate with another base station.
[0122] In some deployments, the access network equipment mentioned in the embodiments of this application may be a device including a CU, or a DU, or a device including both a CU and a DU, or a device with a control plane CU node (central unit-control plane (CU-CP)) and a user plane CU node (central unit-user plane (CU-UP)) and a DU node.
[0123] In some deployments, multiple RAN nodes collaborate to assist terminal devices in achieving wireless access, with different RAN nodes each implementing some of the base station's functions. For example, RAN nodes can be CUs, DUs, CU-CPs, CU-UPs, or radio units (RUs). CUs and DUs can be configured separately or included in the same network element, such as a BBU. RUs can be included in radio equipment or radio units, such as RRUs, AAUs, or RRHs.
[0124] In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, a radio access network can also be an open radio access network (O-RAN) architecture. In an O-RAN system, CU can also be called an open CU (open CU, O-CU), DU can also be called an open DU (open DU, O-DU), CU-CP can also be called an open CU-CP (O-CU-CP), CU-UP can also be called an open CU-UP (O-CU-UP), and RU can also be called an open RU (open RU, O-RU). Any of the units among CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented through software modules, hardware modules, or a combination of software modules and hardware modules.
[0125] In this embodiment, the device for implementing the functions of the access network device can be the access network device itself, or it can be any device capable of supporting the access network device in implementing these functions, such as a chip system, chip, circuit, or communication module (i.e., a communication module that performs communication functions). This device can be installed within the access network device. In this embodiment, the chip system can be composed of chips, or it can include chips and other discrete devices. Furthermore, the device can be configured with program instructions for performing corresponding communication functions. This embodiment only uses the access network device as an example to illustrate the device for implementing the functions of the access network device, and does not limit the solution of this embodiment.
[0126] Access network equipment and terminal equipment can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; and they can also be deployed in the air on airplanes, balloons, and satellites. This application embodiment does not limit the scenario in which the access network equipment and terminal equipment are located.
[0127] 4. The CN component may include, but is not limited to, the following network functions (NFs): network slice selection function (NSSF), network slice specific authentication and authorization function (NSSAAF), authentication server function (AUSF), unified data management (UDM), network exposure function (NEF), network repository function (NRF), policy control function (PCF), application function (AF), access and mobility management function (AMF), session management function (SMF), user plane function (UPF), and signaling control point (SCP). A brief introduction to each network element follows.
[0128] 1) UPF network element: Used for packet routing and forwarding, as well as quality of service (QoS) processing of user plane data. User data can access the DN through this network element. In the embodiments of this application, it can be used to implement user plane functions.
[0129] 2) AMF network element: mainly used for mobility management and access management, and can be used to implement other functions of the mobility management entity (MME) other than session management, such as access authorization / authentication.
[0130] AMF network elements may include security anchor function (SEAF) network elements. SEAF network elements are primarily used to initiate authentication requests to AFS and complete network-side authentication of the UE during the Evolved Packet System Authentication and Key Agreement (EPS-AKA) authentication process. It can be understood that SEAF network elements can also function as independent network elements, i.e., network elements independent of AMF network elements; this is not a limitation.
[0131] 3) SMF network elements: mainly used for session management, allocation and management of Internet Protocol (IP) addresses for terminal devices, selection and management of user plane functions, endpoints of policy control and billing function interfaces, and downlink data notification, etc.
[0132] 4) PCF network element: A unified policy framework used to guide network behavior, providing policy rule information to network elements (such as AMF, SMF, etc.) or terminal devices.
[0133] In addition, PCF internally stores QoS rules. Furthermore, PCF can generate corresponding QoS rules as required to ensure that the services provided by the network meet the requirements of third parties.
[0134] 5) NRF network element: Used to store network function entities and their description information, as well as support functions such as service discovery and network element entity discovery.
[0135] 6) NEF network element: used to enable third parties to use the services provided by the network, support the network to open its capabilities, events and data analysis, provide security configuration information to the PLMN from external applications, and convert information exchanged between the PLMN and external networks.
[0136] 7) UDM network element: used for unified data management, 5G user data management, processing user identification, access authentication, registration, or mobility management, etc.
[0137] 8) UDR network element: Used to provide UDM with the function of saving and retrieving subscription data, PCF with the function of saving and retrieving policy data, and saving and retrieving user NF group ID information, etc.
[0138] 9) AF element: Used to provide corresponding services by interacting with other NFs in the PLMN, such as providing network selection information for roaming UE visits, routing data flows, and accessing NEFs.
[0139] 10) AUSF network element: used for Level 1 authentication, i.e. authentication between UE (subscribed user) and operator network.
[0140] In addition, the architecture may include other network elements, such as the authentication repository and processing function (ARPF) network element, which is mainly used to store the long-term key K; receive authentication vector requests from AUSF; calculate the authentication vector using K; and send the authentication vector to AUSF.
[0141] In Figure 1, Nnssf, Nnef, Nnrf, Npcf, Nudm, Nudr, Naf, Nausf, Namf, Nsmf, Neasdf, Nnssaaf, Nnsacf, N1, N2, N3, N4, and N6 are interface sequence numbers. For example, the meanings of these interface sequence numbers can be found in the 3GPP standard protocols, and this application does not limit the meaning of these interface sequence numbers. It should be noted that the interface names between the various network functions in Figure 1 are merely examples; in specific implementations, the interface names of this system architecture may be other names, and this application does not limit them. Furthermore, the names of the messages (or signaling) transmitted between the various network elements are also merely examples and do not constitute any limitation on the function of the messages themselves.
[0142] It should be noted that in the architecture shown in Figure 1, the interface between (R)AN and CN can also be called the NG interface (not shown in the figure). (R)AN and CN are connected through the NG interface. The NG interface can include the NG-C interface and the NG-U interface. The NG-C interface is the control plane interface, connecting (R)AN and AMF, and is used to transmit control plane data. The NG-U interface is the user plane interface, connecting (R)AN and UPF, and is used to transmit user plane data.
[0143] The network elements shown in Figure 1, such as AMF, SMF, UPF, NEF, AUSF, NRF, PCF, and UDM, can be understood as network elements in the core network used to implement different functions, for example, they can be combined into network slices as needed. These core network elements can be independent devices or integrated into the same device to implement different functions. This application does not limit the specific form of the above network elements. In addition, the above network elements or functions can be physical entities in hardware devices, software instances running on dedicated hardware, or virtualized functions instantiated on a shared platform (e.g., a cloud platform). Simply put, an NF can be implemented by hardware or by software.
[0144] Furthermore, the aforementioned naming is defined solely for the purpose of distinguishing different functions and should not constitute any limitation on this application. This application does not preclude the possibility of using other naming conventions in 5G networks and other future networks. For example, in future communication networks, some or all of the aforementioned network elements may retain the terminology used in 5G, or they may adopt other names, etc.
[0145] With the development of communications, two main needs have emerged: end-to-end encryption from the UE to the core network and fine-grained security protection. These will be discussed in detail below.
[0146] 1. End-to-end encryption requirements from UE to core network
[0147] In current mobile communication networks, user data is transmitted to UPF network elements via base stations, and this user data is protected during transmission through a hop-by-hop security mechanism. Specifically:
[0148] (1) User data is encrypted and / or protected for integrity by Packet Data Convergence Protocol (PDCP) between the UE and the base station, i.e., on the air interface side. The UE and the base station use the corresponding keys to perform integrity verification and decryption of PDCP data packets.
[0149] (2) The base station and the UPF (or UPF front-end security gateway) establish a corresponding SA through IPsec to protect the user data transmitted in the GTP-U tunnel. The base station and the UPF (or UPF front-end security gateway) use the corresponding key in IPsec to perform integrity verification and decryption of the protected traffic.
[0150] As can be seen from the above, there is a period when user data appears in plaintext on the base station side.
[0151] Because base stations are deployed in outdoor environments, they are more susceptible to near-end detection and physical attacks. In many scenarios, users and upper-layer services prefer to establish end-to-end security protection directly between the UE and UPF. The base station can only forward encrypted data and cannot obtain the data transmitted within it.
[0152] 2. Fine-grained safety protection requirements
[0153] With the continuous development of mobile communication services, the types of services are increasing. In addition to traditional services such as making calls, sending text messages, and data traffic, new types of services may have different security requirements, and security protection mechanisms may also differ in different service scenarios. Several examples are given below.
[0154] For example, applications that use TLS or QUIC protocols and have enabled security protection mechanisms at the upper layer may not have high requirements for the underlying security protection mechanisms, or may even not need to enable security protection at all.
[0155] For example, some applications may only need to enable integrity protection and not encryption protection in order to reduce performance consumption (such as IoT applications).
[0156] For example, in certain scenarios, such as high-definition live streaming, integrity protection does not need to be enabled; otherwise, packet loss retransmission will affect the smoothness of the video.
[0157] For example, in certain scenarios, where security requirements are high, it is necessary to provide both confidentiality and integrity protection.
[0158] If a user uses the aforementioned different types of applications simultaneously, according to the current security policy, different sessions need to be created for different service data streams (SDFs). As the number of applications increases, a single user unit (UE) may need to establish many sessions. Moreover, since these SDFs all use the same key for encryption and integrity protection, secure isolation between different services may not be possible.
[0159] Furthermore, current PDU session creation primarily considers DN and slice information, without taking into account security requirements at different service granularities. To achieve fine-grained security, the services carried in the PDU session need to be considered during session creation. Therefore, from a network perspective, this allows for more granular security policies and protections to be provided to users, thus offering on-demand security.
[0160] In view of this, this application proposes to design security policies with SDF granularity or QoS granularity to achieve fine-grained security protection. Furthermore, the terminal device sends data based on this security policy, and the user plane function parses the data based on this security policy; or, the user plane function sends data based on this security policy, and the terminal device parses the data based on this security policy, thereby achieving end-to-end security protection.
[0161] The methods provided by the embodiments of this application will be described in detail below with reference to the accompanying drawings. The embodiments provided by this application can be applied to the architecture shown in the above figures, and are not limited thereto.
[0162] Referring to Figure 2, as an example, Figure 2 is a schematic diagram of a communication method 200 provided in an embodiment of this application. The method 200 shown in Figure 2 may include the following steps.
[0163] 210. The transmitting device protects the data based on a security policy.
[0164] Specifically, the transmitting device first determines the secure processing method for the data based on a security policy, and then protects the data based on this secure processing method. The determination of the secure processing method by the transmitting device will be explained in detail later in conjunction with aspect 1.
[0165] The security policy refers to the security policy for the terminal device's session. This policy can be used for secure data transmission between the terminal device and the user plane function. The session, for example, is a PDU session. The user plane function, for example, is a UPF network element.
[0166] The security policy includes SDF information and the corresponding security processing method, or the security policy includes QoS flow information and the corresponding security processing method. In other words, the security policy includes N security processing methods, where N is an integer greater than or equal to 1. Different security processing methods among the N security processing methods correspond to different SDFs, or different security processing methods among the N security processing methods correspond to different QoS flows, where N is an integer greater than 1.
[0167] Optionally, the security processing method includes at least one of the following: no processing, confidentiality processing, integrity processing, and authenticated encryption with associated data (AEAD) processing. The security processing method can be any one of the above; or it can be a combination of the above processing methods, for example, the security processing method is confidentiality processing and integrity processing, such as simply confidentiality + integrity processing (or simply: confidentiality and integrity processing).
[0168] The following sections will detail the relevant security strategies in conjunction with aspect 1, and the relevant security handling methods in conjunction with aspect 2.
[0169] 220, The transmitting device sends securely protected data to the receiving device.
[0170] For example, if the security processing mode is no processing, then in step 220, the transmitting device sends unprotected data to the receiving device.
[0171] For example, if the security processing method is confidentiality processing, then in step 220, the sending device sends encrypted (or confidentiality protected) data to the receiving device.
[0172] For example, if the security processing method is AEAD processing, then in step 220, the transmitting device sends the data protected by AEAD to the receiving device.
[0173] For example, if the security processing method is confidentiality + integrity processing, then in step 220, the sending device sends encrypted and integrity-protected data to the receiving device.
[0174] In one possible scenario, the transmitting device is a terminal device, and the receiving device is a user plane function (i.e., a user plane function network element, such as a UPF).
[0175] Another possible scenario is that the transmitting device is a user plane function (i.e., a user plane function network element, such as a UPF), and the receiving device is a terminal device.
[0176] The terminal device can be replaced by its components, such as a chip, chip system, circuit, or communication module. The user plane function can be replaced by its components, such as a chip, chip system, circuit, or communication module. For simplicity and ease of description, this application uses a terminal device and user plane function as examples for illustration.
[0177] Optionally, method 200 further includes step 230, in which the receiving device parses the data based on a secure data processing method. Parsing the data can also be referred to as processing the data.
[0178] Specifically, the receiving device first determines the secure processing method for the data, and then parses the data based on that secure processing method.
[0179] For example, if the data security processing method is encryption and integrity processing, the receiving device parses the data based on the data security processing method, including: the receiving device performing integrity verification and decryption processing on the data.
[0180] For example, if the data is processed in a confidential manner, the receiving device will parse the data based on the data's security processing method, including: the receiving device decrypting the data.
[0181] For example, if the data security processing method is integrity processing, the receiving device parses the data based on the data security processing method, including: the receiving device performing integrity verification on the data.
[0182] The implementation of the secure data processing method determined by the receiving device will be explained in detail later in conjunction with aspect 2.
[0183] For ease of description, embodiments of this application are described below in conjunction with several aspects. It is understood that although the following description is divided into several aspects, the content of each aspect can be used in combination and referenced interchangeably, and will not be elaborated further thereafter.
[0184] Aspect 1: Security Strategy Plan
[0185] Optionally, the security policy can be at the SDF granularity or SDF level; or, the security policy can be at the QoS flow granularity or QoS flow level. These two implementation methods are described below.
[0186] One possible implementation is that the security policy is at the SDF (Security Component Document) granularity. Based on this, the security policy includes SDF information and corresponding security processing methods. For example, the security policy includes information about at least one SDF and corresponding security processing methods for each of those at least one SDF. This application's embodiments primarily illustrate the example of a security policy including information about at least one SDF and corresponding security processing methods for each of those at least one SDF, and are not intended to limit the scope. For example, in some cases, the security policy may also include information about at least one SDF and corresponding security processing methods for some of those at least one SDF.
[0187] Optionally, if the security policy is at the SDF granularity, the sending device in step 210 performs security protection on the data based on the security policy, including: if the data matches the information of the SDF, such as the data matching a specific packet filter, the sending device determines the security processing method corresponding to the packet filter according to the packet filter and the security policy, and performs security protection on the data based on the security processing method.
[0188] The SDF information represents information that can identify the SDF. For example, the SDF information is a packet filter. In this case, the security policy may include the packet filter and the corresponding security processing method. The correspondence (or mapping rule) between the security processing method and the packet filter can be stored or transmitted in the form of a table, function, text, or string. Taking a table as an example, the correspondence between the security processing method and the packet filter is shown in Table 1.
[0189] Table 1
[0190] If the security policy is at the SDF granularity, the transmitting device determines the secure processing method for the data, including: based on the SDF information (such as packet filter) matched by the data and the security policy, the transmitting device determines the secure processing method corresponding to the packet filter as the secure processing method for the data. This is explained in detail below with reference to Table 1.
[0191] For example, assuming the sending device is a terminal device, the terminal device can match data to a specific packet filter (for distinction, this packet filter is called the target packet filter). Based on Table 1, the security processing method corresponding to the target packet filter can be determined, and then the data can be protected based on this security processing method. Taking Table 1 as an example, if the target packet filter is packet filter #1, the terminal device will protect the data based on security processing method #1. If security processing method #1 is confidentiality processing, the terminal device will encrypt the data. If the target packet filter is packet filter #2, the terminal device will protect the data based on security processing method #2. If security processing method #1 is integrity processing, the terminal device will protect the data integrity, and so on. In addition, the terminal device can also generate a security header for the data based on the data's security processing method. In this way, the receiving device (such as the user plane function) can determine the data's security processing method based on the data's security header. The security header scheme will be described in detail later.
[0192] For another example, assuming the transmitting device is a user plane function, it can match data to a specific packet filter (for distinction, this packet filter will be called the target packet filter). Based on Table 1, the security processing method corresponding to the target packet filter can be determined, and then the data can be protected based on this security processing method. Taking Table 1 as an example, if the target packet filter is packet filter #1, the user plane function will protect the data based on security processing method #1. If security processing method #1 is confidentiality processing, the terminal device will encrypt the data. If the target packet filter is packet filter #2, the user plane function will protect the data based on security processing method #2. If security processing method #1 is integrity processing, the terminal device will protect the data integrity, and so on. Furthermore, the terminal device can also generate a security header for the data based on the data's security processing method. Thus, the receiving device (such as the user plane function) can determine the data's security processing method based on the data's security header. The security header scheme will be discussed in detail later.
[0193] Table 1 above is an illustrative example, and the embodiments of this application are not limited thereto. Any variations of Table 1 are applicable to the embodiments of this application. For example, the packet filter in Table 1 can also be replaced with a packet filter set, that is, one packet filter set corresponds to one security processing method. In other words, the security policy can be at the granularity of a packet filter set. As another example, there may be multiple packet filters in Table 1 corresponding to the same security processing method. In other words, one security processing method can correspond to multiple packet filters.
[0194] A second possible implementation involves a security policy at the QoS flow granularity. Based on this, the security policy includes QoS flow information and corresponding security processing methods. For example, the security policy includes information on at least one QoS flow and a corresponding security processing method for each of those at least one QoS flow. This application's embodiments primarily illustrate the example of a security policy including information on at least one QoS flow and a corresponding security processing method for each of those at least one QoS flow, and are not intended to limit the scope. For example, in some cases, a security policy may also include information on at least one QoS flow and corresponding security processing methods for some of those at least one QoS flow.
[0195] Optionally, if the security policy is at the QoS flow level, the sending device performs security protection on the data based on the security policy in step 210, including: the sending device determines the security processing method corresponding to the QoS flow according to the QoS flow corresponding to the data and the security policy, and performs security protection on the data based on the security processing method.
[0196] The QoS flow information represents information that identifies the QoS flow. For example, the QoS flow information is the QFI. In this case, the security policy may include the QFI and the corresponding security processing method. The correspondence (or mapping rule) between the security processing method and the QFI can be stored or transmitted in the form of a table, function, text, or string. For example, the correspondence between the security processing method and the QFI is shown in Table 2.
[0197] Table 2
[0198] If the security policy is at the QoS flow level, the transmitting device determines the secure processing method for the data, including: based on the QoS flow information (QFI) matched by the data and the security policy, the transmitting device determines the secure processing method corresponding to the QoS flow as the secure processing method for the data. This is explained in detail below with reference to Table 2.
[0199] For example, suppose the sending device is a terminal device. The terminal device matches data to a specific QoS stream (referred to as the target QoS stream for distinction) based on QoS rules. Based on the target QoS stream and Table 2, the corresponding security processing method can be determined, and the data can then be protected based on this method. Optionally, this security policy can be included in the QoS rules on the terminal device side. The terminal device matches data to a specific QoS stream (referred to as the target QoS stream for distinction) based on the QoS rules. Based on the target QoS stream and the security processing method in the corresponding QoS rules, the corresponding security processing method can be determined, and the data can then be protected based on this method. Taking Table 2 as an example, if the QFI of the target QoS stream is QFI#1, the terminal device protects the data based on security processing method #1; if the QFI of the target QoS stream is QFI#2, the terminal device protects the data based on security processing method #2, and so on.
[0200] For another example, suppose the transmitting device is a user plane function. The user plane function can match data to a specific packet filter set of a Packet Detection Rule (PDR) based on the Packet Detection Rule (PDR). Then, based on the QFI (referred to as the target QFI) in that PDR and Table 2, it can determine the corresponding security processing method and protect the data based on that method. Alternatively, the user plane function can match data to a specific FAR based on the Forwarding Action Rule (FAR). Then, based on the QFI (referred to as the target QFI) in that FAR and Table 2, it can determine the corresponding security processing method and protect the data based on that method. Taking Table 2 as an example, if the QFI of the target QoS flow is QFI#1, the user plane function protects the data based on security processing method #1; if the QFI of the target QoS flow is QFI#2, the user plane function protects the data based on security processing method #2, and so on. Optionally, the security policy may be included in rule #A, which represents a rule sent to the user plane function for transmitting session data. As an example, rule #A may be an N4 rule, or rule #A may be a rule contained within an N4 rule. One possible implementation is that rule #A is at least one of the following: Packet Inspection Rule (PDR) or Forwarding Operation Rule (FAR). This will be explained in detail later.
[0201] Table 2 above is an illustrative example, and the embodiments of this application are not limited thereto. Any variations of Table 2 are applicable to the embodiments of this application. For example, there may be multiple QFIs corresponding to the same security processing method in Table 2; in other words, one security processing method may correspond to multiple QFIs.
[0202] Optionally, the method further includes: the transmitting device and / or the receiving device receiving a security policy. Based on this, the receiving device can parse the data based on the security policy; the transmitting device can determine what kind of security protection the data should be protected based on the security policy, and then apply the corresponding security processing method to protect the data.
[0203] As an example, the sending device and / or receiving device receive a security policy from the session management function. Based on this, the session management function determines the security policy and then sends the security policy to the sending device and / or receiving device. For example, the session management function sends the security policy to both the sending device and the receiving device. Another example is that the session management function sends the security policy to the sending device, and the sending device sends the security policy to the receiving device. Yet another example is that the session management function sends the security policy to the receiving device, and the receiving device sends the security policy to the sending device.
[0204] It is understood that the session management function sends security policies to the sending and receiving devices, but this does not mean that the session management function sends security policies to the sending and receiving devices through the same signaling. Rather, it means that the session management function provides the sending and receiving devices with SDF information and the corresponding security processing method, or QoS flow information and the corresponding security processing method, respectively.
[0205] Taking the transmitting device as the terminal equipment and the receiving device as the user plane function as an example, the session management function can send the security policy to the user plane function through rule #A, and also send the security policy to the user plane function through QoS rules. These will be explained separately below.
[0206] 1) The session management function can send security policies to the user plane function through rule #A. Specifically, the session management function sends rule #A to the user plane function. Rule #A includes security policies, that is, rule #A includes information on at least one SDF and the security processing method corresponding to each SDF, or rule #A includes information on at least one QoS flow and the security processing method corresponding to each QoS flow.
[0207] Here, rule #A represents a rule sent by the session management function to the user plane function for transmitting session data. As an example, rule #A is an N4 rule, or rule #A is a rule contained within an N4 rule. One possible implementation is that rule #A is at least one of the following: a packet inspection rule, or a forwarding operation rule.
[0208] 2) The session management function can send security policies to the terminal device through QoS rules. Specifically, the session management function sends at least one QoS rule to the terminal device. This at least one QoS rule includes a security policy. For example, a QoS rule may include information about at least one SDF (such as a packet filter set) and a security processing method corresponding to each SDF. Alternatively, a QoS rule may include information about a QoS flow and a security processing method corresponding to that QoS flow. It is understood that the QoS rule here can also be replaced with other names; in other words, the naming of the QoS rule does not limit the scope of protection of the embodiments of this application. For example, a QoS rule can be replaced with rule #B, where rule #B represents the rule sent by the session management function to the terminal device for transmitting session data.
[0209] The above are illustrative examples, and the embodiments of this application are not limited thereto. For example, when a transmitting device wants to transmit data, it requests a security policy from the session management function; the session management function sends the security policy to the transmitting device based on the request. As another example, after receiving data, a receiving device requests a security policy from the session management function; the session management function sends the security policy to the receiving device based on the request. The aforementioned session management function can also be replaced by other functional network elements (such as PCF, UDM, etc.).
[0210] The session management function determines the security policy and may include at least any of the following implementation methods.
[0211] One possible implementation is to configure security policies locally for the session management function.
[0212] Another possible implementation is that the session management function receives security policies from other network elements. For example, these other network elements could be a PCF or UDM. Specifically, the session management function sends a request message to other network elements to request the security policy for the session; upon receiving the request message, the other network elements send the security policy corresponding to that session back to the session management function.
[0213] As an example, the session management function determines security policies, including any of the following scenarios.
[0214] In one possible scenario, during the session establishment process, the session management function determines the security policy. Specifically, after receiving a session establishment request message from the terminal device, the session management function determines the security policy for that session.
[0215] Another possible scenario is that during the session modification process, the session management function determines or updates the security policy. Specifically, after receiving a session modification request message, the session management function determines or updates the security policy for that session.
[0216] As an example, after receiving a session modification request message, the session management function determines a security policy for the session. Based on this, the session management function can determine a security policy for the session during the session modification process.
[0217] In another example, after receiving a session modification request message, the session management function updates the security policy for that session. Based on this, the session management function can determine the security policy for a session before the session modification process begins; and update the security policy for that session during the session modification process.
[0218] The session management function updates the security policy for sessions. For example, it may include: adjusting the correspondence between packet filters (or packet filter sets) and security processing methods; adjusting the correspondence between QoS flows and security processing methods; adding a new correspondence between packet filters (or packet filter sets) and security processing methods; or adding a new correspondence between QoS flows and security processing methods.
[0219] The session establishment process can be initiated by the terminal device, in other words, the session management function receives session modification request messages from the terminal device; or, the session establishment process can be initiated by a core network element (such as UPF, PCF, etc.), in other words, the session management function can receive session modification request messages from a core network element (such as UPF, PCF, etc.).
[0220] Optionally, the session modification request message includes a security handling method (referred to as security handling method #B for distinction), which is the requested (or expected) security handling method.
[0221] The above section introduced relevant security strategy solutions in conjunction with aspect 1. The following section introduces relevant solutions for security handling methods.
[0222] Aspect 2, Security Handling Methods
[0223] The security processing method, also known as the security protection type or security type, indicates what kind of security processing or security protection is applied to the data; and / or, what kind of de-security processing or de-security protection is applied to the data.
[0224] Specifically, with the continuous development of mobile communication services, the types of services are increasing. In addition to traditional services such as making calls, sending text messages, and data traffic, new types of services may have different security requirements, and security protection mechanisms may also differ in different service scenarios. Therefore, different security processing methods can be designed for the same session (such as a PDU session). For example, different security processing methods can be designed for different services within the same session.
[0225] As mentioned above, optionally, the security processing methods include at least one of the following: no processing, confidentiality processing, integrity processing, and AEAD processing. Confidentiality processing includes: encryption protection (or confidentiality protection) and / or decryption processing. Integrity processing includes: integrity protection and / or integrity verification. AEAD processing includes: AEAD protection and / or AEAD decryption (or AEAD deprotection, or AEAD desecurity). The above security processing methods can also be combined; for example, the security processing method may be confidentiality processing and integrity processing, such as simply confidentiality + integrity processing. Confidentiality + integrity processing includes: encryption and integrity protection, and / or decryption and integrity verification.
[0226] For example, if the security processing mode is no processing, it means that no security protection is required for the data, that is, in step 220, the transmitting device sends data without security protection to the receiving device; accordingly, in step 230, the receiving device parses the data based on the data security processing mode, including: the receiving device directly processes the data.
[0227] For example, for some applications, if the upper layer uses Transport Layer Security (TLS) or Quick UDP Internet Connection (QUIC) protocols and has security protection mechanisms enabled, the requirements for the underlying security protection mechanisms may not be so high, so security protection may not be enabled.
[0228] In another example, if the security processing method is confidentiality processing, then in step 210, the sending device protects the data based on a security policy, including: the sending device encrypts the data based on the security policy; correspondingly, in step 230, the receiving device parses the data based on the data security processing method, including: the receiving device decrypts the received data.
[0229] For example, for some applications, such as high-definition live streaming, integrity protection may not need to be enabled, otherwise packet loss and retransmission will affect the smoothness of the video. For such applications, encryption is sufficient.
[0230] In another example, if the security processing method is integrity processing, then in step 210, the sending device performs security protection on the data based on the security policy, including: the sending device performs integrity protection processing on the data based on the security policy; correspondingly, in step 230, the receiving device parses the data based on the data security processing method, including: the receiving device performs integrity verification on the received data.
[0231] For example, for some applications, such as IoT applications, in order to reduce performance consumption, integrity protection can be enabled, that is, encryption protection is not required.
[0232] In another example, if the security processing method is confidentiality + integrity processing, then in step 210, the sending device performs security protection on the data based on the security policy, including: the sending device performs encryption and integrity protection processing on the data based on the security policy; correspondingly, in step 230, the receiving device parses the data based on the data security processing method, including: the receiving device performs integrity verification and decryption processing on the received data.
[0233] For example, for certain applications, such as those with high security requirements, it may be necessary to provide both encryption and integrity protection to improve security.
[0234] The above is an illustrative example, and the embodiments of this application do not limit which security processing method is used for which business.
[0235] For the transmitting device, as described in section 1 above, the appropriate security processing method can be determined based on packet filtering or QoS flow of the data. Optionally, the receiving device determines the data security processing method based on one or more of the following methods:
[0236] One possible implementation is that the receiving device determines the secure processing method for the data based on the data's security header;
[0237] Another possible implementation is that the receiving device determines the secure processing method for the data based on rules.
[0238] The two implementation methods are described in detail below.
[0239] 1) The receiving device determines the data security processing method based on the data security header.
[0240] Optionally, the data in step 220 includes a security header. This security header indicates the secure processing method for the data. Based on this, the receiving device can determine the secure processing method used for the data based on the security header of the received data.
[0241] Specifically, the transmitting device generates a security header for the data based on the data's security processing method; the receiving device determines the data's security processing method based on the received data's security header.
[0242] Taking a security policy at the SDF granularity as an example, specifically, the transmitting device determines the data security processing method based on the data packet filter and the security policy, as shown in Table 1 above; then, the transmitting device generates a security header based on this data security processing method. Alternatively, taking a security policy at the QoS flow granularity as an example, specifically, the transmitting device determines the data security processing method based on the QoS flow to which the data packet filter belongs and the security policy, as shown in Table 2 above; then, the transmitting device generates a security header based on this data security processing method.
[0243] The specific content of the safety head indicator is not limited. Several possible implementation methods are described below.
[0244] The first possible implementation is a secure header indicating the secure processing method for data.
[0245] For example, the security header indicates that the data is processed in a confidential manner. In this case, the receiving device knows from the security header that the data is encrypted, or the receiving device knows from the security header that the data needs to be decrypted. In this case, step 230, where the receiving device parses the data based on the data's security processing method, includes: the receiving device decrypting the data.
[0246] For example, the security header indicates that the data is processed for integrity. In this case, the receiving device knows from the security header that the data has undergone integrity protection, or the receiving device knows from the security header that the data needs to be verified for integrity. In this case, in step 230, the receiving device parses the data based on the data's security processing method, including: the receiving device performing integrity verification on the data.
[0247] The above are examples. As mentioned earlier, security processing methods can also include no processing, AEAD processing, or confidentiality + integrity processing, etc.
[0248] The second possible implementation involves a security header indicating what kind of security protection the data has undergone. In other words, the transmitting device uses the security header to indicate to the receiving device what security processing methods the transmitting device has used to protect the data.
[0249] For example, a security header indicates confidentiality protection. In this case, the receiving device knows from the security header that the data is encrypted. Therefore, in step 230, the receiving device parses the data based on the data's security processing method, including: the receiving device decrypts the data.
[0250] For example, a security header indicates integrity protection. In this case, the receiving device knows from the security header that the data has undergone integrity protection. Therefore, in step 230, the receiving device parses the data based on the data's security processing method, including: the receiving device performing integrity verification on the data.
[0251] The above are examples. As mentioned earlier, security processing methods can also include no processing, AEAD processing, or confidentiality + integrity processing, etc.
[0252] The third possible implementation involves a security header indicating how the data should be parsed. In other words, the transmitting device uses the security header to instruct the receiving device on the appropriate security processing method to parse the data.
[0253] For example, the security header indicates decryption processing (or decryption). In this case, the receiving device knows from the security header that data decryption processing is required. Therefore, in step 230, the receiving device parses the data based on the data's secure processing method, including: the receiving device decrypting the data.
[0254] For example, a security header indicates integrity verification. In this case, the receiving device knows from the security header that integrity verification of the data is required. Therefore, in step 230, the receiving device parses the data based on the data's security processing method, including: the receiving device performing integrity verification on the data.
[0255] The above are examples. As mentioned earlier, security processing methods can also include no processing, AEAD processing, or confidentiality + integrity processing, etc.
[0256] The above describes three implementation methods, and the embodiments of this application are not limited to these. In the following embodiments, the first possible implementation method is mainly used as an example for illustration.
[0257] The form of the security header is not limited. Two implementation methods are listed below.
[0258] One possible implementation is that the security header is implemented using at least 1 bit.
[0259] Taking four security processing methods as an example, they are: confidentiality processing, integrity processing, AEAD processing, and confidentiality + integrity processing. The security header can be represented by 2 bits. If the value of these 2 bits is "00", it indicates that the security processing method is confidentiality processing; if the value of these 2 bits is "01", it indicates that the security processing method is integrity processing; if the value of these 2 bits is "10", it indicates that the security processing method is AEAD processing; and if the value of these 2 bits is "11", it indicates that the security processing method is confidentiality + integrity processing.
[0260] Taking five security processing methods as an example, they are: no processing, confidentiality processing, integrity processing, AEAD processing, and confidentiality + integrity processing. The security header can be represented by 3 bits. If the value of these 3 bits is "000", it means that the security processing method is no processing; if the value of these 3 bits is "001", it means that the security processing method is confidentiality processing; if the value of these 3 bits is "010", it means that the security processing method is integrity processing; if the value of these 3 bits is "011", it means that the security processing method is AEAD processing; and if the value of these 3 bits is "100", it means that the security processing method is confidentiality + integrity processing.
[0261] The above examples illustrating the correspondence between bits and security processing methods are merely illustrative, and the embodiments of this application are not limited thereto.
[0262] Another possible implementation is that the security header is implemented using a bitmap, with each bit corresponding to a security processing method.
[0263] Taking four security processing methods as an example, they are: confidentiality processing, integrity processing, AEAD processing, and confidentiality + integrity processing. The security header can be represented by a 4-bit bitmap. If the 4-bit bitmap value is "1000", it indicates that the security processing method is confidentiality processing; if the 4-bit bitmap value is "0100", it indicates that the security processing method is integrity processing; if the 4-bit bitmap value is "0010", it indicates that the security processing method is AEAD processing; and if the 4-bit bitmap value is "0001", it indicates that the security processing method is confidentiality + integrity processing.
[0264] Taking five security processing methods as an example, they are: no processing, confidentiality processing, integrity processing, AEAD processing, and confidentiality + integrity processing. The security header can be represented by a 5-bit bitmap. If the 5-bit bitmap value is "10000", it indicates that the security processing method is no processing; if the 5-bit bitmap value is "01000", it indicates that the security processing method is confidentiality processing; if the 5-bit bitmap value is "00100", it indicates that the security processing method is integrity processing; if the 5-bit bitmap value is "00010", it indicates that the security processing method is AEAD processing; and if the 5-bit bitmap value is "00001", it indicates that the security processing method is confidentiality + integrity processing.
[0265] The correspondence between bits and security processing methods can be predefined, indicated, or pre-configured, and is not limited in this respect. Furthermore, the use of a bit value of "1" to indicate the application of that security processing method and a bit value of "0" to indicate the non-application of that security processing method is not limited in this respect. For example, a bit value of "0" indicates the application of that security processing method, and a bit value of "1" indicates the non-application of that security processing method.
[0266] The above is an illustrative example, and the embodiments of this application are not limited thereto. For example, if the data does not carry a security header, the security processing of the data can be assumed to be no processing. Specifically, taking the five security processing methods as an example, if the data does not carry a security header, the security processing of the data can be assumed to be no processing; if the data carries a security header, the security processing of the data can be determined based on the bit values in the security header (such as the value of 2 bits), specifically confidentiality processing, integrity processing, AEAD processing, or confidentiality + integrity processing; or, if the data carries a security header, the security processing of the data can be determined based on the bitmap in the security header (such as a 4-bit bitmap), specifically confidentiality processing, integrity processing, AEAD processing, or confidentiality + integrity processing.
[0267] Optionally, the data includes a message authentication code (MAC), which is constructed based on a security header and its key. Specifically, the sending device constructs the MAC based on the security header and its key; after receiving the MAC, the receiving device verifies it using information used to verify the MAC (such as the security header key). If the verification is successful, the security header can be obtained. This method improves the security of the security header.
[0268] As an example, the MAC can be a 32-bit or 64-bit bit string. There is no limit to the length of the bit string.
[0269] The position of the MAC address is not limited. For example, the MAC address may be placed before the security header; after the security header; or at the end of the data.
[0270] Here, the security header key represents the key used to protect the security header. As an example, the security header key includes the following possible implementations.
[0271] One possible implementation is that the security header key is a key specifically used for the security protection of the session's security header. Based on this, the security header key can be a unique key used specifically to derive or generate the security header key (such as the key for security header integrity protection).
[0272] Another possible implementation is that the security header key is the session key. Based on this, the security header key can be derived or generated from the session key.
[0273] Optionally, the receiving device can verify the security processing method indicated by the security header based on the security processing method in the security policy. Specifically, after receiving data, the receiving device determines the security processing method corresponding to the packet filter based on the packet filter matched by the data and the security policy; if the security processing method corresponding to the packet filter is consistent with the security processing method indicated by the security header, the receiving device continues to parse the received data; if the security processing method corresponding to the packet filter is inconsistent with the security processing method indicated by the security header, the receiving device discards, ignores, or rejects the received data.
[0274] 2) The receiving device determines the secure processing method for the data based on rules. As an example, this method can be applied to scenarios where the security policy is at the QoS stream granularity.
[0275] Optionally, the method further includes: the sending device and / or receiving device receiving a rule (such as the QoS rule or rule #A described above) from the session management function, which includes a security policy. For example, the rule includes identification information of the QoS flow (such as QFI) and the security processing method corresponding to the QoS flow. Based on this, the session management function can send the rule to the terminal device and / or user plane function, which can be used by the terminal device and / or user plane function to transmit data. Several scenarios are described below.
[0276] The first possible scenario is that the rule is a QoS rule. In this case, the session management function sends at least one QoS rule to the terminal device.
[0277] As an example, each QoS rule includes information about a QoS flow (such as QFI) and the corresponding security handling method. In addition to including information about a QoS flow (such as QFI) and the corresponding security handling method, a QoS rule may also include other information, such as at least one of the following: a QoS rule identifier, a packet filter set, and a QoS rule precedence.
[0278] The above examples primarily illustrate scenarios where the security policy is at the QoS flow granularity. However, the embodiments of this application are not limited to this. For instance, if the security policy is at the SDF granularity, each QoS rule includes information about at least one SDF (such as a packet filter set) and a security processing method corresponding to each SDF. Furthermore, in addition to including information about at least one SDF (such as a packet filter set) and a security processing method corresponding to each SDF, the QoS rule may also include other parameters. For example, the QoS rule may also include at least one of the following parameters: QoS rule identifier, QFI, and QoS rule priority.
[0279] The second possible scenario is rule #A. In this case, the session management function sends rule #A to the user plane function. Rule #A includes information about the QoS flow (such as QFI) and the security processing method corresponding to the QoS flow.
[0280] As mentioned earlier, rule #A represents a rule issued by the session management function to the user plane function for transmitting session data. As an example, rule #A is at least one of the following: Packet Inspection Rule (PDR) or Forwarding Operation Rule (FAR). Several examples are described below.
[0281] For example, rule #A is a PDR. Each PDR includes information about a QoS flow (such as QFI) and the security handling method corresponding to that QoS flow. In addition, the PDR also includes other information, such as at least one of the following: CN tunnel information, network instance, IP packet filter set, application identifier, and FQDN filter for DNS query messages.
[0282] Another example is rule #A, which is a FAR. Each FAR includes information about a QoS flow (such as QFI) and the security handling method corresponding to that QoS flow.
[0283] Another example is rule #A, which includes a PDR and a FAR. For instance, the PDR includes information about a QoS flow (such as QFI), and the FAR includes the security handling method corresponding to that QoS flow. Furthermore, the PDR and FAR may also include other information. For example, the PDR may include at least one of the following: CN tunnel information, network instance, QFI, IP packet filter set, application identifier, and FQDN filter for DNS query messages; and the FAR may also include QFI, etc.
[0284] The following two examples illustrate the specific application of the above rules.
[0285] In one possible scenario, the transmitting device is a terminal device, and the receiving device is a user plane function.
[0286] In this scenario, for the sending terminal device, if the data hits the packet filter in the QoS rule (referred to as QoS rule #1 for distinction) (in other words, the data's packet filter is the packet filter in QoS rule #1), then the terminal device will protect the data based on the security processing method in QoS rule #1.
[0287] In this scenario, for the receiving end user plane function, after receiving data, it determines the QFI of the data. For example, the user plane function determines the session ID, such as based on the tunnel ID or the user plane function's IP address, and then determines the QFI in the PDR corresponding to that session ID; or, it determines the QFI corresponding to the data packet transmitted in the tunnel (e.g., the header of the data packet transmitted in the NG-U tunnel contains QFI information). The user plane function can then determine the security processing method for the data based on the QFI in the PDR corresponding to the session of the terminal device, and then parse the data based on that security processing method. Alternatively, for the receiving end user plane function, after determining the QFI using the aforementioned methods, the user plane function performs security parsing on the data based on the security processing method in the FAR corresponding to the QoS flow.
[0288] Another possible scenario is that the transmitting device is a user plane function, and the receiving device is a terminal device.
[0289] In this scenario, for the user plane function at the sending end, if the data hits the packet filter set in the PDR (referred to as PDR#1 for distinction) (in other words, the data's packet filter belongs to the packet filter set in PDR#1), then the user plane function will protect the data based on the security processing method in PDR#1.
[0290] Alternatively, for the user plane function at the sending end, if the data hits the QoS flow in the PDR (referred to as PDR#1 for distinction), the user plane function will protect the data based on the security processing method in the FAR corresponding to the QoS flow.
[0291] In this scenario, for the receiving terminal device, after receiving data, the terminal device determines the QFI of the data based on the packet filter set in the QoS rules; alternatively, after receiving data from a data radio bearer (DRB), the terminal device determines the QFI of the data based on the mapping relationship between the DRB and the QFI. The terminal device then determines the security processing method for the data based on the security parameters in the QoS rules corresponding to the QFI, and subsequently parses the data based on this security processing method.
[0292] The above describes two methods, which can be understood to be used in combination. For example, the receiving device can verify the security processing method indicated in the security header of the data based on the security processing method in a rule (such as rule #A, or a QoS rule). Specifically, the receiving device can determine the security processing method of the received data as security processing method #1 based on the rule (such as rule #A, or a QoS rule) corresponding to the received data, and the security processing method indicated in the security header of the received data as security processing method #2. The receiving device can compare security processing method #1 and security processing method #2, that is, verify security processing method #2 based on security processing method #1. If security processing method #1 and security processing method #2 are consistent, the receiving device continues to parse the received data; if security processing method #1 and security processing method #2 are inconsistent, the receiving device discards, ignores, or rejects the received data.
[0293] Optionally, different security processing methods correspond to different keys.
[0294] If a security policy includes N security processing methods, then keys can be assigned to each of these N methods. For example, N keys can be assigned, each used for one of the N security processing methods.
[0295] One possible implementation involves a receiving device and / or a transmitting device receiving the keys for the N secure processing methods.
[0296] For example, the session management function determines the key for each of the N security processing methods and sends the key for each security processing method to the receiving device and / or the sending device. For instance, the session management function sends the key for each security processing method to both the sending and receiving devices. Another example is that the session management function sends the key for each security processing method to the sending device. Yet another example is that the session management function sends the key for each security processing method to the receiving device.
[0297] Another possible implementation is that the receiving and / or transmitting device determines the keys for N secure processing methods.
[0298] For example, the receiving device and / or transmitting device can determine the key for each of the N security processing methods based on the session key. The session key can be provided by the session management function, meaning the session management function sends the session key to the receiving device and / or transmitting device.
[0299] For ease of understanding, the specific processes applicable to the embodiments of this application are described below in conjunction with different scenarios. In the examples below, the session is a PDU session, the terminal device is a UE, the session management function is SMF, and the user plane function is UPF. It should be understood that the processes described below are merely illustrative examples, and the embodiments of this application are not limited thereto. Content not described in detail below can be referred to the description in method 200, and will not be repeated hereafter.
[0300] Referring to Figure 3, as an example, Figure 3 is a schematic diagram of a communication method 300 provided in an embodiment of this application. Method 300 can be used in scenarios where the security policy is at the SDF granularity. The following describes the steps that 300 may include, in conjunction with two stages.
[0301] Phase 1: Session Establishment Phase.
[0302] 301. The UE sends a PDU session establishment request message to the SMF.
[0303] For example, the UE sends a PDU session establishment request message to the SMF through intermediate network elements, such as the RAN and / or AMF.
[0304] 302, SMF determines the security policy for PDU sessions.
[0305] For brevity, the security policy for PDU sessions will be referred to simply as security policy.
[0306] Specifically, after receiving the UE's PDU session establishment request message, the SMF determines the security policy for the PDU session.
[0307] One possible implementation is to configure security policies locally in the SMF.
[0308] Another possible implementation is that the SMF receives the security policy from other network elements. For example, these other network elements could be the PCF or UDM. The SMF sends a request message to these other network elements to request the security policy for the PDU session; upon receiving the request message, the other network elements configure the security policy and then send it back to the SMF.
[0309] Security policies can be at the SDF granularity. For example, a security policy might take the form of (packet filters, security processing methods), as shown in Table 1. For details on the form of security policies, please refer to the preceding descriptions; they will not be repeated here.
[0310] 303, SMF determines the key for N secure processing methods.
[0311] Where N is an integer greater than or equal to 1. The keys for the N security processing methods include the key for each of the N security processing methods. Specifically, the SMF determines what type of key to obtain based on the security policy, and then obtains the corresponding type of key. In other words, the SMF obtains the keys for each security processing method in the security policy. The keys for different security processing methods can be different.
[0312] Further, optionally, the SMF also determines the session key for the PDU session.
[0313] Referring to Figure 4, which serves as an example, Figure 4 is a schematic diagram of key derivation. Assume that the security processing methods in the security policy include: no processing, confidentiality processing, integrity processing, AEAD processing, and confidentiality + integrity processing. As shown in Figure 4, after the SMF performs primary authentication on the UE, the anchor key K can be derived from CK and IK in the primary authentication process. AUSF Then through K AUSF Derive K SEAF Through K SEAF Derive K NASenc (NAS confidentiality protection key) and K NASint (NAS integrity protection key), and the session key K for the PDU session. PDUsession Then SMF can use the session key K of the PDU session. PDUsession Derive the keys for various security processing methods, such as the key K for confidentiality processing. enc AEAD processing key K AEAD Integrity processing key K int Key K for confidentiality and integrity processing enc+int .
[0314] Alternatively, the SMF may also determine the UPF.
[0315] 304. The SMF sends the security policy and keys for N security processing methods to the UPF.
[0316] Specifically, the SMF sends an N4 session establishment request message to the UPF and establishes an N4 session. During the N4 session establishment process, the SMF sends the security policy and keys for N security processing methods to the UPF. In addition, the SMF also sends the PDU session identifier (PDU session ID) to the UPF.
[0317] It is understandable that Method 300 uses the example of the SMF determining the keys for N security processing methods as an illustration, and is not intended to limit the scope of the method. As described in Method 200 above, the UPF can also determine the keys for N security processing methods itself. For example, the SMF sends the session key of the PDU session to the UPF, and the UPF determines the keys for N security processing methods based on the session key of the PDU session.
[0318] 305, SMF sends security policy to UE.
[0319] After receiving the security policy, the UE can store it.
[0320] Furthermore, in Phase 1 (i.e., the session establishment phase), the network side can establish corresponding QoS for the PDU session, and the RAN side can allocate corresponding DRBs, thereby completing the PDU session establishment. Additionally, subsequent new services may trigger PDU session updates, initiating the establishment of new QoS, which is not limited to this. The specific process for PDU session establishment can refer to existing methods. This application's embodiments mainly focus on completing key deduction for different security processing methods and distributing security policies during the PDU session establishment process.
[0321] Phase Two: Data Transmission Phase.
[0322] During the data transmission phase, the transmitting device may be either a UE or a UPF; there is no limitation on this. For ease of explanation, Method 300 uses a UE as an example for illustration. Regarding the case where the transmitting device is a UPF, please refer to the description in the preceding method embodiments; it will not be repeated here.
[0323] 306. The UE protects the data according to the security policy.
[0324] Specifically, the UE initiates a new service and, based on the security policy received in 305 (i.e., the service-level security policy), performs security protection on the data to be transmitted (i.e., the data of the service).
[0325] For example, the UE determines which security processing method to apply to the data based on the security policy. Suppose the UE determines to use security processing method #A in the security policy for data security protection, then the UE can use the key for security processing method #A to protect the data.
[0326] Optionally, the data includes a security header that indicates the secure processing method for the data (i.e., security processing method #A). Specifically, during the packet construction process, the UE constructs the security header based on the security processing method mapped to the packet traffic.
[0327] Optionally, the data includes a MAC, which is determined based on the security header and the security header key.
[0328] For details regarding the safety head solution, please refer to the description in the previous method embodiments; it will not be repeated here.
[0329] 307, the UE sends securely protected data to the UPF.
[0330] Specifically, the UE protects the data and sends the protected data.
[0331] As an example, the UE sends data to the UPF through the RAN. Specifically, the UE sends a PDCP data packet to the RAN, which carries the corresponding security header information. After receiving the PDCP data packet, the RAN puts the security header information in the PDCP data packet into the GTP-U header and sends the data to the UPF through the GTP-U tunnel.
[0332] 308, UPF uses a secure data processing method to parse data.
[0333] Specifically, the UPF locates the corresponding PDU session and UE based on the tunnel ID or the UPF's IP address; and the UPF determines that the data uses security processing mode #A based on the data's security header; the UPF can then perform integrity verification and / or decryption on the data using the key for security processing mode #A received in 304, thus allowing it to continue processing.
[0334] Alternatively, if the security header in the data is protected for integrity, such as if the data includes a MAC constructed based on the security header and its key, the UPF can first verify the integrity protection of the security header. If the verification passes, the security processing method #A is then determined based on the security header.
[0335] Optionally, the UPF performs double verification. Specifically, after parsing the security header, the UPF can obtain the security processing method for the data based on the security header; further, the UPF can determine the security processing method corresponding to the packet filter based on the packet filter (or packet filter set) matched by the data and the security policy received in step 304. If the security processing method corresponding to the packet filter is consistent with the security processing method indicated by the security header, the data is parsed based on the security processing method indicated by the security header; if the security processing method corresponding to the packet filter is inconsistent with the security processing method indicated by the security header, the data is directly rejected or dropped.
[0336] Phase Two is illustrated using the UE as the transmitting device and the UPF as the receiving device as an example, but the embodiments of this application are not limited to this. For example, when the UE is the receiving device and the UPF is the transmitting device, the operation of the UPF can be referred to in steps 306 and 307, and the operation of the UE can be referred to in step 308. The difference is that if the UE is the receiving device, the UE can determine the security processing method corresponding to the packet filter through the packet filter (or packet filter set) matched by the data and the security policy received in step 305, and then verify the security processing method indicated by the security header based on the security processing method corresponding to the packet filter. If the security processing method corresponding to the packet filter is consistent with the security processing method indicated by the security header, the data is parsed based on the security processing method indicated by the security header; if the security processing method corresponding to the packet filter is inconsistent with the security processing method indicated by the security header, the data is directly rejected or dropped.
[0337] The above description, with reference to Figure 3, illustrates a possible process. The steps described above are merely illustrative and are not intended to be strictly limited. Furthermore, the sequence numbers of the processes do not imply a specific order of execution; the execution order should be determined by their function and internal logic, and should not constitute any limitation on the implementation process of this application's embodiments. For example, steps 302 and 303 can be performed simultaneously. As another example, steps 304 and 305 can be performed simultaneously; or, step 305 can be executed first, followed by step 304.
[0338] Based on the above embodiments, security policies can be determined and issued during session establishment. Furthermore, by deriving different keys for different security processing methods, finer-grained (i.e., SDF-level) security protection and end-to-end security protection between the UE and UPF can be achieved. Additionally, by adding security header information to data packets, SDF-level security control can be implemented without changing existing QoS rules.
[0339] Referring to Figure 5, as an example, Figure 5 is a schematic diagram of a communication method 500 provided in an embodiment of this application. Method 500 can be used in scenarios where the security policy is at the SDF granularity. The steps that 500 may include are described below in conjunction with three stages.
[0340] Phase 1: Session Establishment Phase.
[0341] 501, PDU session established.
[0342] The PDU session establishment process can be found in Phase 1 of 300, and will not be elaborated here.
[0343] Phase Two: Session Modification Phase.
[0344] This application's embodiments mainly use the UE initiating session modification as an example for illustration. However, this application's embodiments are not limited to this. For example, core network elements, such as UPF, can also initiate session modification.
[0345] 502, the UE sends a PDU session modification request message to the SMF.
[0346] For example, the UE sends a PDU session modification request message to the SMF through intermediate network elements, such as the RAN and / or AMF.
[0347] Optionally, the PDU session modification request message carries a security processing method (referred to as security processing method #B for distinction), which is the security processing method requested (or desired) by the UE.
[0348] 503, SMF updates security policy for PDU sessions.
[0349] Specifically, after receiving a PDU session modification request message, the SMF updates the security policy of the PDU session. For example, the SMF can adjust or add the correspondence between packet filters and security handling methods.
[0350] Alternatively, if a new security processing method is added, the key for that new security processing method can also be determined.
[0351] 504, SMF sends an updated security policy to UPF.
[0352] Optionally, if a new security processing method is added in 503 and the key for the new security processing method is determined, then in 504, the SMF also sends the key to the UPF.
[0353] 505, SMF sends an updated security policy to UE.
[0354] For example, the SMF sends the updated complete security policy to the UE, such as the SMF sending the UE the mapping between all packet filters and security processing methods; another example is that the SMF sends the UE the updated part, such as the SMF sending the UE the mapping between newly added packet filters and security processing methods.
[0355] Furthermore, in Phase Two (i.e., the session modification phase), the network side can also establish corresponding QoS for the PDU session. The specific process for session updates can be found in existing methods; this application's embodiments primarily focus on updating and distributing security policies during the session update process.
[0356] Phase 3, data transmission phase.
[0357] 506, The UE protects the data according to the updated security policy.
[0358] 507, the UE sends securely protected data to the UPF.
[0359] 508, UPF uses a secure data processing method to parse data.
[0360] Regarding the data transmission phase in 500, please refer to the data transmission phase in 300; it will not be elaborated here.
[0361] The above description, in conjunction with Figure 5, illustrates a possible process. The steps described above are merely illustrative and are not intended to be strictly limited. Furthermore, the sequence numbers of the processes do not imply a specific order of execution; the execution order should be determined by their function and internal logic, and should not constitute any limitation on the implementation process of this application's embodiments. For example, steps 504 and 505 can be performed simultaneously; or, step 505 can be executed first, followed by step 504.
[0362] Based on the above embodiments, security policies can be determined and issued during session establishment, and updated and issued during session modification. Furthermore, by deriving different keys for different security processing methods, finer-grained (i.e., SDF-level) security protection and end-to-end security protection between the UE and UPF can be achieved. Additionally, by adding security header information to data packets, SDF-level security control can be implemented without changing existing QoS mapping rules.
[0363] Referring to Figure 6, as an example, Figure 6 is a schematic diagram of a communication method 600 provided in an embodiment of this application. Method 600 can be used in a scenario where the receiving device determines the secure processing method of data based on rules in method 200. The method 600 shown in Figure 6 may include the following steps.
[0364] Phase 1: Session Establishment Phase.
[0365] 601, the UE sends a PDU session establishment request message to the SMF.
[0366] 602, SMF determines the security policy of the PDU session and the keys for N security processing methods.
[0367] Optionally, the security policy is at the SDF granularity or SDF level; or, the security policy is at the QoS flow granularity or QoS flow level.
[0368] For 601-602, please refer to 301-303; they will not be elaborated upon here.
[0369] 603. SMF determines QoS rules and N4 rules, which include security handling methods.
[0370] 1) QoS rules
[0371] As an example, each QoS rule includes information about a QoS flow (such as QFI) and the corresponding security handling method. In addition to including information about a QoS flow (such as QFI) and the corresponding security handling method, a QoS rule may also include other information, such as at least one of the following: QoS rule identifier, packet filter set, and QoS rule priority.
[0372] 2) N4 rule
[0373] As an example, an N4 rule includes at least one PDR, and each PDR includes information about a QoS flow (such as QFI) and the security handling method corresponding to that QoS flow. In addition, the PDR also includes other information, such as at least one of the following: CN tunnel information, network instance, QFI, IP packet filter set, application identifier, and FQDN filter for DNS query messages.
[0374] Another example is that the N4 rule includes at least one FAR, and each FAR includes information about a QoS flow (such as QFI) and the security processing method corresponding to that QoS flow.
[0375] Another example is that an N4 rule includes at least one PDR and at least one FAR. A PDR includes information about a QoS flow (such as QFI), and a FAR includes the security handling method corresponding to that QoS flow.
[0376] As mentioned above, the naming of the N4 rule does not limit the scope of protection of the embodiments of this application.
[0377] 604, SMF sends the keys for N security processing methods and the N4 rule to UPF.
[0378] Specifically, the SMF sends the security policy of the PDU session to the UE, as well as the N4 rule defined in S603.
[0379] It is understandable that Method 600 uses the example of the SMF determining the keys for N security processing methods as an illustration, and is not intended to limit the scope of the method. As described in Method 200 above, the UPF can also determine the keys for N security processing methods itself. For example, the SMF sends the session key of the PDU session to the UPF, and the UPF determines the keys for N security processing methods based on the session key of the PDU session.
[0380] 605, SMF sends security policies and QoS rules to UE.
[0381] Specifically, the SMF sends the security policy of the PDU session to the UE, as well as the QoS rules determined in S603.
[0382] In addition, during Phase 1 (i.e., the session establishment phase), the network side can also establish a corresponding number of QoS (e.g., N QoS) for the PDU session. Different QoS have different security handling methods, and the RAN side allocates the corresponding DRB to complete the PDU session establishment.
[0383] Phase Two: Data Transmission Phase.
[0384] During the data transmission phase, the transmitting device may be either a UE or a UPF; there is no limitation on this. For ease of explanation, Method 300 uses a UE as an example for illustration. Regarding the case where the transmitting device is a UPF, please refer to the description in the preceding method embodiments; it will not be repeated here.
[0385] 606, The UE protects the data according to the security policy.
[0386] Specifically, the UE initiates a new service and protects the data of that service according to the security policy received in 305 (i.e., the security policy at the service granularity).
[0387] For example, the UE filters traffic according to the packet filter set in the QoS rules to distinguish different SDFs; then the UE uses different security processing methods and keys to protect the corresponding traffic according to the security policy; after security protection, it maps the QFI to the corresponding QoS flow according to the QoS rules.
[0388] Referring to Figure 7, which is a schematic diagram of QoS rules as an example, let's assume the four QoS flows are named QoS#1, QoS#2, QoS#3, and QoS#4, respectively. The security processing method corresponding to QoS#1 is Security Processing Method #1, QoS#2 is Security Processing Method #2, QoS#3 is Security Processing Method #3, and QoS#4 is Security Processing Method #4. As shown in Figure 7, security protection can be applied to data mapped to (or matched to) QoS#1 according to Security Processing Method #1; to data mapped to (or matched to) QoS#2 according to Security Processing Method #2; to data mapped to (or matched to) QoS#3 according to Security Processing Method #3; and to data mapped to (or matched to) QoS#4 according to Security Processing Method #4.
[0389] 607, the UE sends securely protected data to the UPF.
[0390] 608, UPF uses a secure data processing method to parse data.
[0391] Specifically, the UPF determines the PDU session ID based on the tunnel ID or the UPF's IP address, and then determines the QFI in the PDR corresponding to that session ID. For example, the UPF determines the QFI corresponding to a data packet transmitted in the tunnel (e.g., the header of a data packet transmitted in an NG-U tunnel contains QFI information). The UPF can determine the security processing method for the data based on the QFI in the PDR corresponding to the PDU session and the corresponding security parameters, and then parse the data based on the security processing method.
[0392] Optionally, this data includes a security header. See section 308 for a detailed description, which will not be repeated here.
[0393] Phase Two primarily uses the UE as the transmitting device and the UPF as the receiving device as an example for illustration, but the embodiments of this application are not limited to this. For example, when the UE is the receiving device and the UPF is the transmitting device, the operation of the UPF can be referred to 606 and 607, and the operation of the UE can be referred to 608. The difference is that if the UE is the receiving device, after receiving data, the UE determines the QFI of the data according to the packet filter set in the QoS rule, and then determines the security processing method (i.e., the data security processing method) in the QoS rule corresponding to the QFI, and then parses the data based on the security processing method; or, after receiving data from a DRB, the UE determines the QFI of the data according to the mapping relationship between the DRB and the QFI, and then determines the security processing method (i.e., the data security processing method) in the QoS rule corresponding to the QFI, and then parses the data based on the security processing method.
[0394] The above description, with reference to Figure 6, illustrates a possible process. The steps described above are merely illustrative and are not intended to be strictly limited. Furthermore, the sequence numbers of the processes do not imply a specific order of execution; the execution order should be determined by their function and internal logic, and should not constitute any limitation on the implementation process of this application's embodiments. For example, steps 602 and 603 can be performed simultaneously. As another example, steps 604 and 605 can be performed simultaneously; or, step 605 can be executed first, followed by step 604.
[0395] Based on the above embodiments, security policies can be determined and issued during session establishment. Furthermore, by adding security policies to QoS rules and N4 rules, and by deriving different keys for different security processing methods, finer-grained (i.e., SDF-level) security protection, as well as end-to-end security protection between the UE and UPF, can be achieved.
[0396] Referring to Figure 8, as an example, Figure 8 is a schematic diagram of a communication method 800 provided in an embodiment of this application. Method 800 can be used in a scenario where the receiving device determines the secure processing method of data based on rules in method 200, and the UE initiates session modification. The method 800 shown in Figure 8 may include the following steps.
[0397] Phase 1: Session Establishment Phase.
[0398] 801, PDU session established.
[0399] The PDU session establishment process can be found in Phase 1 of 600, and will not be elaborated here.
[0400] Phase Two: Session Modification Phase.
[0401] In this embodiment of the application, it is assumed that the UE initiates a session modification.
[0402] 802, the UE sends a PDU session modification request message to the SMF.
[0403] For example, the UE sends a PDU session modification request message to the SMF through intermediate network elements, such as the RAN and / or AMF.
[0404] Optionally, the PDU session modification request message carries a security processing method (referred to as security processing method #B for distinction), which is the security processing method requested (or desired) by the UE. For example, the PDU session modification request may include QoS, which includes the security processing method.
[0405] Optionally, the PDU session modification request may also include a packet filter.
[0406] 803, SMF updates security policy for PDU sessions.
[0407] For 803, please refer to 503; details will not be elaborated here.
[0408] 804, SMF establishes or modifies QoS rules and N4 rules.
[0409] As an example, the QoS rule and N4 rule include newly added security handling methods. Specifically, if the SMF establishes or modifies QoS, security handling methods are added or modified in the corresponding QoS rule and N4 rule.
[0410] 805, SMF sends the updated security policy and the PDR corresponding to the new packet filter to UPF.
[0411] 806, SMF sends updated security policies and QoS rules to UE.
[0412] Furthermore, in Phase Two (i.e., the session modification phase), the UE, RAN, and UPF establish or modify the corresponding QoS. The specific process for session updates can be found in existing methods. This application's embodiments primarily focus on updating and distributing security policies, QoS rules, and N4 rules during the session update process.
[0413] Phase 3, data transmission phase.
[0414] 807, The UE protects the data according to the updated security policy.
[0415] 808, the UE sends securely protected data to the UPF.
[0416] 809, UPF uses a secure data processing method to parse data.
[0417] For the data transmission phase in 800, please refer to the data transmission phase in 600; it will not be elaborated here.
[0418] The above description, with reference to Figure 8, illustrates a possible process. The steps described above are merely illustrative and are not intended to be strictly limited. Furthermore, the sequence numbers of the processes do not imply a specific order of execution; the execution order should be determined by their function and internal logic, and should not constitute any limitation on the implementation process of this application's embodiments. For example, steps 803 and 804 can be performed simultaneously. As another example, steps 805 and 806 can be performed simultaneously; or, step 806 can be executed first, followed by step 805.
[0419] Based on the above embodiments, security policies, QoS rules, and N4 rules can be updated and distributed during the session modification process initiated by the UE. Furthermore, by adding security policies to QoS rules and N4 rules, and by deriving different keys for different security processing methods, finer-grained (i.e., SDF-level) security protection and end-to-end security protection between the UE and UPF can be achieved.
[0420] Referring to Figure 9, as an example, Figure 9 is a schematic diagram of a communication method 900 provided in an embodiment of this application. Method 900 can be used in a scenario where the receiving device determines the secure processing method of data based on rules in method 200, and the PCF initiates session modification. The method 900 shown in Figure 9 may include the following steps.
[0421] Phase 1: Session Establishment Phase.
[0422] 901, PDU session established.
[0423] The PDU session establishment process can be found in Phase 1 of 600, and will not be elaborated here.
[0424] Phase Two: Session Modification Phase.
[0425] In this embodiment, it is assumed that the PCF initiates the session modification. That is, the PDU session modification is triggered by the PCF, rather than requested by the UE. The PCF carries the policy control and charging (PCC) rules in the PCF initiated SM Policy Association Modification message, which includes the relevant content of the requested QoS.
[0426] 902, PCF sends an SM policy association modification message to SMF.
[0427] Optionally, the SM policy association modification carries QoS, which includes security processing requirements.
[0428] One possible scenario is that the PCF triggers a PCF-initiated SM policy association modification process to notify the SMF of changes to the relevant session policies. This could be triggered by a policy decision or an AF request. In this case, as an example, the QoS carried in the SM policy association modification is obtained based on the QoS parameter information carried in the AF trigger request.
[0429] Another possible scenario is that the UDM updates the SMF's subscription data via a Nudm_SDM_Notification, such as if the Nudm_SDM_Notification includes SUPI and session management subscription data. In this case, the QoS carried in the SM policy association modification may trigger a modification of the QoS already created for that PDU session.
[0430] Another possible scenario is triggering by SMF local configuration or RAN-side policies. This could also be triggered if the user plane (UP) connection is active and the SMF has marked one or more QoS Flow states as deleted in 5GC, but these haven't been synchronized with the UE. In this case, it might not involve modification of security parameters; it could simply be releasing QoS.
[0431] 903, SMF updates security policy for PDU sessions.
[0432] 904, SMF establishes or modifies QoS rules and N4 rules.
[0433] 905, SMF sends the updated security policy and the PDR corresponding to the new packet filter to UPF.
[0434] 906, SMF sends updated security policies and QoS rules to UE.
[0435] Furthermore, in Phase Two (i.e., the session modification phase), the UE, RAN, and UPF establish or modify the corresponding QoS. The specific process for session updates can be found in existing methods. This application's embodiments primarily focus on updating and distributing security policies, QoS rules, and N4 rules during the session update process.
[0436] Phase 3, data transmission phase.
[0437] 907. The UE protects the data according to the updated security policy.
[0438] 908, the UE sends securely protected data to the UPF.
[0439] 909, UPF uses a secure data processing method to parse data.
[0440] Regarding the data transmission phase in 900, please refer to the data transmission phase in 600; it will not be elaborated here.
[0441] The above description, with reference to Figure 9, illustrates a possible process. The steps described above are merely illustrative and are not intended to be strictly limited. Furthermore, the sequence numbers of the processes do not imply a specific order of execution; the execution order should be determined by their function and internal logic, and should not constitute any limitation on the implementation process of this application's embodiments. For example, steps 903 and 904 can be performed simultaneously. As another example, steps 905 and 906 can be performed simultaneously; or, step 906 can be executed first, followed by step 905.
[0442] Based on the above embodiments, security policies, QoS rules, and N4 rules can be updated and distributed during the session modification process initiated by the PCF. Furthermore, by adding security policies to the QoS and N4 rules, and by deriving different keys for different security processing methods, finer-grained (i.e., SDF-level) security protection and end-to-end security protection between the UE and UPF can be achieved.
[0443] The methods described above (300-900) mainly introduce the case where the security policy is at the SDF granularity. As mentioned earlier, in the embodiments of this application, the security policy can also be at the QoS flow granularity. For the determination and distribution of the QoS flow granularity security policy, please refer to the relevant descriptions in the preceding sections (300-500). Here, we mainly introduce the use of the security policy during the data transmission phase in two scenarios.
[0444] Scenario 1: UE sends data to UPF.
[0445] 1) UE side
[0446] Specifically, the SMF sends QoS rules to the UE, and the UE can map these QoS rules to the corresponding service data streams. When the UE wants to send data for a certain service, it can map the data to the corresponding QoS stream according to the QoS rules, and then map the QoS stream to the corresponding DRB. After identifying the QFI according to the QoS rules, the UE can perform mapping in the following three ways.
[0447] One possible implementation is that the UE performs mapping based on radio resource control (RRC) signaling configuration. Specifically, the RAN can directly indicate the correspondence between QFI and DRB through RRC configuration messages.
[0448] Another possible implementation is that the UE performs reflection QoS mapping, specifically, the UE performs reflection mapping based on downlink rules.
[0449] Another possible implementation is that the UE maps based on the default DRB configuration. For example, if neither of the above two implementations can be obtained, and the default DRB parameter of a certain DRB configured by the RAN is true, then the UE can use the default DRB to send all uplink QoS flows.
[0450] The above-mentioned implementation methods are illustrative examples and are not limited to the embodiments of this application.
[0451] Based on the above mapping, it becomes clear which DRB (Device Regulator) the corresponding QoS flow data packet should be sent in. During this process, the data packet can be protected according to the QoS flow's security policy. As an example, a security header can be added to the packet header to indicate which security processing method was used for protection.
[0452] After receiving a data packet from the UE, the RAN can put the security header information, the QFI mapped according to the DRB from which the data packet came, and other information into the GTP-U packet header and send it.
[0453] 2) UPF side
[0454] During PDU session establishment or session modification, the UPF receives a QoS flow-level security policy from the SMF. The UPF receives data from the UE and, based on the GTP-U packet header information, can determine the security header and QFI information. Based on the security header, the UPF knows which security processing method is used to protect the data. The UPF can find the corresponding UE and PDU session based on the tunnel ID, and thus find the corresponding key based on the security processing method. Optionally, the UPF can verify the security processing method. Specifically, the UPF can also obtain the corresponding security processing method based on the QFI and the QoS flow security policy in the UPF's N4 rules. Therefore, the UPF can verify whether the security processing method indicated by the security header is consistent with the security policy; if consistent, the data is processed; otherwise, the data is rejected or discarded.
[0455] Scenario 2: UPF sends data to UE.
[0456] 1) UPF side
[0457] When a UPF receives a data packet from a DN, it can map it to the corresponding QoS based on the PDR. The UPF can then apply appropriate security protection to the data packet according to the security handling method specified in the PDR. Optionally, the UPF can add a security header to the packet header indicating which security handling method was used for security protection.
[0458] 2) UE side
[0459] After receiving a data packet from the UPF, the UE can determine the corresponding QoS according to the QoS rules, and then determine which security processing method is used to protect the data packet based on the QoS flow-level security policy. Furthermore, if the data packet also includes a security header, the UE can also verify the security processing method. Specifically, the UE verifies whether the security processing method indicated by the security header is consistent with the security policy; if consistent, the data is processed; otherwise, the data is rejected or discarded.
[0460] It is understood that the embodiments shown in Figures 3 to 9 above are illustrated using UE, SMF, UPF, etc. as examples. This application does not exclude the possibility of using other names in other networks in the future. For example, in future communication networks, some or all of the above network elements may use the terminology from 5G, or they may use other names, etc.
[0461] The methods provided by the embodiments of this application have been described in detail above with reference to Figures 2 to 9. The apparatus provided by the embodiments of this application will be described in detail below with reference to Figures 10 to 12. It should be understood that the descriptions of the apparatus embodiments correspond to the descriptions of the method embodiments; therefore, any content not described in detail can be referred to the method embodiments above, and for the sake of brevity, will not be repeated here.
[0462] Referring to Figure 10, as an example, Figure 10 is a schematic diagram of a communication device 1000 provided in an embodiment of this application. The communication device 1000 includes a transceiver unit 1010 and a processing unit 1020. The transceiver unit 1010 can be used to implement corresponding communication functions. The transceiver unit 1010 can also be referred to as a communication interface or a communication unit. The processing unit 1020 can be used to perform processing, such as determining security policies, using security processing methods to protect data, and using security processing methods to parse data, etc.
[0463] Optionally, the device 1000 may further include a storage unit, which can be used to store instructions and / or data, and the processing unit 1020 can read the instructions and / or data in the storage unit to enable the device to implement the aforementioned method embodiments.
[0464] In a first possible design, the device 1000 can be the session management function in the foregoing embodiments. The device 1000 can implement the steps or processes corresponding to the session management function in the above method embodiments. Specifically, the transceiver unit 1010 can be used to perform transceiver-related operations (such as sending and / or receiving data or messages) of the session management function in the above method embodiments, and the processing unit 1020 can be used to perform processing-related operations of the session management function in the above method embodiments, or operations other than transceiver operations (such as operations other than sending and / or receiving data or messages).
[0465] One possible implementation is that the processing unit 1020 is used to determine the security policy of the terminal device's session. The security policy is used for the secure processing of data transmission between the terminal device and the user plane function. The security policy includes information of the Service Data Flow (SDF) and the security processing method corresponding to the SDF. Alternatively, the security policy includes information of the Quality of Service (QoS) flow and the security processing method corresponding to the QoS flow. The transceiver unit 1010 is used to send the security policy to the terminal device and the user plane function.
[0466] Optionally, the processing unit 1020 is used to determine the security policy of the terminal device's session, including: the processing unit 1020 is used to determine the security policy of the terminal device's session during the session establishment process or the session modification process.
[0467] Optionally, the transceiver unit 1010 is further configured to send a key corresponding to the security processing method to the user plane function; or, send a first key to the user plane function, the first key being used to determine the key corresponding to the security processing method.
[0468] Optionally, the transceiver unit 1010 is used to send a security policy to the terminal device, including: the transceiver unit 1010 is used to send QoS rules to the terminal device, the QoS rules including the security policy.
[0469] Optionally, the transceiver unit 1010 is used to send a security policy to the user plane function, including: the transceiver unit 1010 is used to send an N4 rule to the user plane function, the N4 rule including the security policy.
[0470] Optionally, the security processing method includes one or more of the following: confidentiality processing, authentication and encryption processing of associated data, and integrity processing; or, the security processing method is: no processing.
[0471] In a second possible design, the device 1000 can be the transmitting device in the aforementioned embodiments, such as the transmitting device in the embodiment shown in FIG2, and the UE in the embodiments shown in FIG3-9. The device 1000 can implement the steps or processes corresponding to those performed by the transmitting device in the above method embodiments. Specifically, the transceiver unit 1010 can be used to perform transceiver-related operations (such as sending and / or receiving data or messages) of the transmitting device in the above method embodiments, and the processing unit 1020 can be used to perform processing-related operations of the transmitting device in the above method embodiments, or operations other than transceiver (such as operations other than sending and / or receiving data or messages).
[0472] One possible implementation is that the processing unit 1020 is used to protect the data based on the security policy of the terminal device's session. The security policy is used for the secure processing of data transmission between the terminal device and the user plane function. The security policy includes information of the service data stream SDF and the security processing method corresponding to the SDF. Alternatively, the security policy includes information of the quality of service (QoS) stream and the security processing method corresponding to the QoS stream. The transceiver unit 1010 is used to send the protected data.
[0473] Optionally, the transceiver unit 1010 is also used to receive security policies.
[0474] Optionally, the data matching SDF information, the processing unit 1020, is used to protect the data security based on the security policy of the terminal device's session, including: the processing unit 1020 is used to protect the data security based on the security processing method corresponding to the SDF.
[0475] Optionally, the data matches QoS stream information; the processing unit 1020 is used to protect the data based on the security policy of the terminal device's session, including: the processing unit 1020 is used to protect the data based on the security processing method corresponding to the QoS stream.
[0476] Optionally, the information of the data matching the QoS flow includes: the data matching packet filter; the security policy is included in the QoS rules corresponding to the QoS flow, and the processing unit 1020 is used to perform security protection on the data based on the security processing method corresponding to the QoS flow, including: when the data matches the packet filter in the QoS rules, the processing unit 1020 is used to perform security protection on the data based on the security processing method in the QoS rules; the security policy is included in the N4 rules corresponding to the QoS flow, and the processing unit 1020 is used to perform security protection on the data based on the security processing method corresponding to the QoS flow, including: when the data matches the packet filter in the N4 rules, the processing unit 1020 is used to perform security protection on the data based on the security processing method in the N4 rules.
[0477] Optionally, the protected data includes a security header that indicates how the data should be handled securely.
[0478] Optionally, the secure data includes a message authentication code, which is constructed based on a security header and a security header key.
[0479] Optionally, the security processing method includes one or more of the following: confidentiality processing, authentication and encryption processing of associated data, and integrity processing; or, the security processing method is: no processing.
[0480] In a third possible design, the device 1000 can be the receiving device in the aforementioned embodiments, such as the receiving device in the embodiment shown in FIG2, and the UPF in the embodiments shown in FIG3-9. The device 1000 can implement the steps or processes corresponding to those performed by the receiving device in the above method embodiments. Specifically, the transceiver unit 1010 can be used to perform transceiver-related operations (such as sending and / or receiving data or messages) of the receiving device in the above method embodiments, and the processing unit 1020 can be used to perform processing-related operations of the receiving device in the above method embodiments, or operations other than transceiver (such as operations other than sending and / or receiving data or messages).
[0481] One possible implementation is a transceiver unit 1010 for receiving data; and a processing unit 1020 for parsing data based on a secure data processing method. The secure data processing method is determined based on the security policy of the terminal device's session. The security policy is used for secure data transmission between the terminal device and the user plane function. The security policy includes information about the Service Data Flow (SDF) and the corresponding secure processing method. Alternatively, the security policy includes information about the Quality of Service (QoS) flow and the corresponding secure processing method.
[0482] Optionally, the transceiver unit 1010 is also used to receive security policies.
[0483] Optionally, the data matching SDF information, the processing unit 1020, is used to parse the data based on the data security processing method, including: the processing unit 1020, used to parse the data based on the security processing method corresponding to the SDF.
[0484] Optionally, the data matches QoS flow information; the processing unit 1020 is used to parse the data based on the data's security processing method, including: the processing unit 1020 is used to parse the data based on the security processing method corresponding to the QoS flow.
[0485] Optionally, the security policy is included in the QoS rules corresponding to the QoS flow, and the processing unit 1020 is used to parse the data based on the security processing method corresponding to the QoS flow, including: the processing unit 1020 is used to parse the data based on the security processing method in the QoS rules; or, the security policy is included in the N4 rules corresponding to the QoS flow, and the processing unit 1020 is used to parse the data based on the security processing method corresponding to the QoS flow, including: the processing unit 1020 is used to parse the data based on the security processing method in the N4 rules.
[0486] Optionally, the data includes a security header indicating a secure processing method for the data; the processing unit 1020 is used to parse the data based on the secure processing method, including: the processing unit 1020 is used to parse the data based on the secure processing method indicated by the security header.
[0487] Optionally, the data includes a message authentication code, which is constructed based on a security header and a key to the security header.
[0488] Optionally, the security policy is included in the QoS rules corresponding to the QoS flow. The processing unit 1020 is used to parse the data based on the data's security processing method, including: the processing unit 1020 is used to parse the data when the security processing method in the QoS rules is consistent with the security processing method of the data indicated by the security header; or, the security policy is included in the N4 rules corresponding to the QoS flow. The processing unit 1020 is used to parse the data based on the data's security processing method, including: the processing unit 1020 is used to parse the data when the security processing method in the N4 rules is consistent with the security processing method of the data indicated by the security header.
[0489] Optionally, the security processing method includes one or more of the following: confidentiality processing, authentication and encryption processing of associated data, and integrity processing; or, the security processing method is: no processing.
[0490] It should be understood that the specific process of each unit performing the above-mentioned corresponding steps has been described in detail in the above method embodiments, and will not be repeated here for the sake of brevity.
[0491] It should also be understood that the device 1000 here is embodied in the form of a functional unit. The term "unit" here can refer to an application-specific integrated circuit (ASIC), electronic circuitry, a processor (e.g., a shared processor, a proprietary processor, or a group processor, etc.) and memory for executing one or more software or firmware programs, integrated logic circuitry, and / or other suitable components supporting the described functions. In an alternative example, those skilled in the art will understand that the device 1000 can be specifically the communication device in the above embodiments, and can be used to execute the various processes and / or steps corresponding to the communication device in the above method embodiments; to avoid repetition, these will not be described again here.
[0492] The apparatus 1000 of each of the above-described schemes has the function of implementing the corresponding steps performed by the communication device (such as a terminal device, user plane function, or session management function) in the above-described methods. The functions can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions; for example, a transceiver unit can be replaced by a transceiver (e.g., the sending unit in the transceiver unit can be replaced by a transmitter, and the receiving unit in the transceiver unit can be replaced by a receiver), and other units, such as processing units, can be replaced by processors, each performing the transmission and reception operations and related processing operations in the respective method embodiments.
[0493] In addition, the transceiver unit 1010 may also be a transceiver circuit (for example, it may include a receiving circuit and a transmitting circuit), and the processing unit may be a processing circuit.
[0494] It should be noted that the device in Figure 10 can be the communication device in the aforementioned embodiments (such as a terminal device, a session management function, or a user plane function), or it can be a chip or a chip system, such as a system on a chip (SoC). The transceiver unit can be an input / output circuit or a communication interface; the processing unit is a processor, microprocessor, or integrated circuit integrated on the chip. No limitations are imposed here.
[0495] Referring to Figure 11, as an example, Figure 11 is a schematic diagram of another communication device 1100 provided in an embodiment of this application. The device 1100 includes a processor 1110, which is coupled to a memory 1120. The memory 1120 is used to store computer programs or instructions and / or data. The processor 1110 is used to execute the computer programs or instructions stored in the memory 1120, or to read the data stored in the memory 1120, in order to execute the methods in the above method embodiments.
[0496] Optionally, there may be one or more processors 1110.
[0497] Optionally, the memory 1120 may be one or more.
[0498] Alternatively, the memory 1120 can be integrated with the processor 1110, or it can be set separately.
[0499] Optionally, as shown in FIG11, the device 1100 further includes a transceiver 1130 for receiving and / or transmitting signals. For example, the processor 1110 is used to control the transceiver 1130 to receive and / or transmit signals.
[0500] As an example, processor 1110 may have the functions of processing unit 1020 shown in FIG10, memory 1120 may have the functions of storage unit, and transceiver 1130 may have the functions of transceiver unit 1010 shown in FIG10.
[0501] As one approach, the device 1100 is used to implement the operations performed by the communication device (such as a terminal device, a user plane function, or a session management function) in the various method embodiments described above.
[0502] For example, processor 1110 is used to execute computer programs or instructions stored in memory 1120 to implement the relevant operations of the communication device in the various method embodiments described above.
[0503] It should be understood that the processor mentioned in the embodiments of this application can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.
[0504] It should also be understood that the memory mentioned in the embodiments of this application can be volatile memory and / or non-volatile memory. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM). For example, RAM can be used as an external cache. By way of example and not limitation, RAM includes the following forms: static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0505] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) can be integrated into the processor.
[0506] It should also be noted that the memory described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0507] Referring to Figure 12, as an example, Figure 12 is a schematic diagram of a chip system 1200 provided in an embodiment of this application. The chip system 1200 (or may also be referred to as a processing system) includes logic circuitry 1210 and an input / output interface 1220.
[0508] The logic circuit 1210 can be a processing circuit in the chip system 1200. The logic circuit 1210 can be coupled to a memory unit, calling instructions from the memory unit, enabling the chip system 1200 to implement the methods and functions of the embodiments of this application. The input / output interface 1220 can be an input / output circuit in the chip system 1200, outputting processed information from the chip system 1200, or inputting data or signaling information to be processed into the chip system 1200 for processing.
[0509] As one approach, the chip system 1200 is used to implement operations performed by communication devices (such as terminal devices, user plane functions, or session management functions) in the various method embodiments described above.
[0510] For example, logic circuit 1210 is used to implement processing-related operations performed by communication devices (such as terminal devices, user plane functions, or session management functions) in the above method embodiments; input / output interface 1220 is used to implement sending and / or receiving-related operations performed by communication devices (such as terminal devices, user plane functions, or session management functions) in the above method embodiments.
[0511] This application also provides a computer-readable storage medium storing a computer program or instructions for implementing the methods executed by a communication device (such as a terminal device, a user plane function, or a session management function) in the above-described method embodiments.
[0512] For example, when a computer program or instruction is executed on a communication device, the communication device (such as a terminal device, a user plane function, or a session management function) performs the above-described methods (such as method 200, method 300-900).
[0513] This application also provides a computer program product comprising instructions which, when executed by a computer, implement the methods described above as being performed by a communication device (such as a terminal device, a user plane function, or a session management function).
[0514] For example, when a computer program or instruction is run on a communication device, it causes the communication device (such as a terminal device, a user plane function, or a session management function) to execute the above methods (such as method 200, method 300-900).
[0515] This application also provides a communication system, which includes at least one of the following in the above embodiments: terminal device, user plane function, and session management function. For example, the system includes the transmitting device and receiving device in the embodiment of FIG2. As another example, at least one of UPF, SMF, and UE in FIG3-FIG9. Optionally, the communication system also includes other devices or network elements, such as other core network elements.
[0516] The explanations and beneficial effects of the relevant contents in any of the devices provided above can be found in the corresponding method embodiments provided above, and will not be repeated here.
[0517] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of apparatus or units may be electrical, mechanical, or other forms.
[0518] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. For example, the computer can be a personal computer, a server, or a network device, etc. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks, SSDs). For example, the aforementioned available media include, but are not limited to, USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks, and other media capable of storing program code.
[0519] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A communication method characterized by comprising: The method comprises: determining a security policy of a session of a terminal device, the security policy being used for security processing of data transmission between the terminal device and a user plane function, the security policy comprising information of a service data flow (SDF) and a security processing manner corresponding to the SDF, or the security policy comprising information of a quality of service (QoS) flow and a security processing manner corresponding to the QoS flow; sending the security policy to the terminal device and the user plane function.
2. The method of claim 1, wherein, The determining of the security policy of the session of the terminal device comprises: determining the security policy of the session of the terminal device in a session establishment process or a session modification process.
3. The method according to claim 1 or 2, characterized in that, The method further comprises: sending a key corresponding to the security processing manner to the user plane function; or sending a first key to the user plane function, the first key being used for determining the key corresponding to the security processing manner.
4. The method according to any one of claims 1 to 3, characterized in that, The sending of the security policy to the terminal device comprises: sending a QoS rule to the terminal device, the QoS rule comprising the security policy.
5. The method according to any one of claims 1 to 4, characterized in that, The sending of the security policy to the user plane function comprises: sending an N4 rule to the user plane function, the N4 rule comprising the security policy.
6. A communication method characterized by comprising: The method comprises: performing security protection on data based on a security policy of a session of a terminal device, the security policy being used for security processing of data transmission between the terminal device and a user plane function, the security policy comprising information of a service data flow (SDF) and a security processing manner corresponding to the SDF, or the security policy comprising information of a quality of service (QoS) flow and a security processing manner corresponding to the QoS flow; sending the data that has been security protected.
7. The method of claim 6, wherein, Before the performing of the security protection on the data based on the security policy of the session of the terminal device, the method further comprises: receiving the security policy.
8. The method according to claim 6 or 7, characterized in that, The data matches the information of the SDF, The performing of the security protection on the data based on the security policy of the session of the terminal device comprises: performing the security protection on the data based on the security processing manner corresponding to the SDF.
9. The method according to claim 6 or 7, characterized in that, The data matches the information of the QoS flow; The performing of the security protection on the data based on the security policy of the session of the terminal device comprises: performing the security protection on the data based on the security processing manner corresponding to the QoS flow.
10. The method of claim 9, wherein, The data matches the information of the QoS flow comprises that the data matches a packet filter; The security policy is contained in a QoS rule corresponding to the QoS flow, and the performing of the security protection on the data based on the security processing manner corresponding to the QoS flow comprises: performing the security protection on the data based on the security processing manner in the QoS rule in a case where the data matches the packet filter in the QoS rule; or The security policy is contained in an N4 rule corresponding to the QoS flow, and the performing of the security protection on the data based on the security processing manner corresponding to the QoS flow comprises: In a case where the data matches a packet filter in the N4 rule, the data is security protected based on a security processing manner in the N4 rule.
11. The method according to any one of claims 6 to 10, characterized in that, The security protected data includes a security header, and the security header indicates the security processing manner of the data.
12. The method of claim 11, wherein, The security protected data includes a message authentication code, and the message authentication code is constructed based on the security header and a key of the security header.
13. A method of communication, comprising: The method comprises: receiving data; parsing the data based on a security processing manner of the data, the security processing manner of the data being determined based on a security policy of a session of a terminal device, the security policy being used for security processing of data transmission between the terminal device and a user plane function, the security policy including information of a service data flow (SDF) and a security processing manner corresponding to the SDF, or the security policy including information of a quality of service (QoS) flow and a security processing manner corresponding to the QoS flow.
14. The method of claim 13, wherein, Before parsing the data based on the security processing manner of the data, the method further comprises: receiving the security policy.
15. The method according to claim 13 or 14, characterized in that, The data matches the information of the SDF, The parsing of the data based on the security processing manner of the data comprises: parsing the data based on the security processing manner corresponding to the SDF.
16. The method according to claim 13 or 14, characterized in that The data matches the information of the QoS flow. The parsing of the data based on the security processing manner of the data comprises: parsing the data based on the security processing manner corresponding to the QoS flow.
17. The method of claim 16, wherein the security policy is contained in a QoS rule corresponding to the QoS flow, and the parsing of the data based on the security processing manner corresponding to the QoS flow comprises: parsing the data based on the security processing manner in the QoS rule; or the security policy is contained in an N4 rule corresponding to the QoS flow, and the parsing of the data based on the security processing manner corresponding to the QoS flow comprises: parsing the data based on the security processing manner in the N4 rule. The data includes a security header, and the security header indicates the security processing manner of the data.
18. The method according to any one of claims 13 to 17, characterized in that, The parsing of the data based on the security processing manner of the data comprises: parsing the data based on the security processing manner indicated by the security header of the data. The data includes a message authentication code, and the message authentication code is constructed based on the security header and a key of the security header.
19. The method of claim 18, wherein, 20. The method of claim 18 or 19, wherein the security policy is contained in a QoS rule corresponding to the QoS flow, and the parsing of the data based on the security processing manner of the data comprises: parsing the data in a case where the security processing manner in the QoS rule is consistent with the security processing manner of the data indicated by the security header; or the security policy is contained in an N4 rule corresponding to the QoS flow, and the parsing of the data based on the security processing manner of the data comprises: In a case where the security processing manner in the N4 rule is consistent with the security processing manner of the data indicated by the security header, the data is parsed.
21. The method of any one of claims 1 to 20, wherein, The security processing manner includes one or more of the following: confidentiality processing, authentication encryption processing of associated data, and integrity processing; or the security processing manner is no processing.
22. A method of communication, comprising: The method includes: receiving data, the data including a security header, the security header indicating a security processing manner of the data; parsing the data based on the security processing manner of the data.
23. The method of claim 22, wherein, The security processing manner of the data is determined based on a security policy of a session of a terminal device, the security policy being used for security processing of data transmission between the terminal device and a user plane function, the security policy including information of a service data flow (SDF) and a security processing manner corresponding to the SDF, or the security policy including information of a quality of service (QoS) flow and a security processing manner corresponding to the QoS flow.
24. The method of claim 23, wherein, The method further includes: receiving the security policy.
25. The method of any one of claims 22-24, wherein, The data includes a message authentication code, the message authentication code being constructed based on the security header and a key of the security header.
26. The method of any one of claims 22-25, wherein, The security processing manner includes one or more of the following: confidentiality processing, authentication encryption processing of associated data, and integrity processing; or the security processing manner is no processing.
27. A communication system, characterized by including at least one of the following: a user plane function, a session management function, and a terminal device; The session management function is configured to perform the method in any one of claims 1 to 5; The user plane function is configured to perform the method in any one of claims 6 to 12, and the terminal device is configured to perform the method in any one of claims 13 to 21; or The user plane function is configured to perform the method in any one of claims 13 to 21, and the terminal device is configured to perform the method in any one of claims 6 to 12.
28. A communications device, characterized by including a module or unit for performing the method in any one of claims 1 to 5; or including a module or unit for performing the method in any one of claims 6 to 12; or including a module or unit for performing the method in any one of claims 13 to 21; or including a module or unit for performing the method in any one of claims 22 to 26.
29. A communications device, characterized by including a processor configured to cause the communication apparatus to perform the method in any one of claims 1 to 5; or configured to cause the communication apparatus to perform the method in any one of claims 6 to 12; or configured to cause the communication apparatus to perform the method in any one of claims 13 to 21; or configured to cause the communication apparatus to perform the method in any one of claims 22 to 26.
30. The apparatus of claim 29, wherein, The apparatus further includes a memory and / or a communication interface, The memory, coupled to the processor, is configured to store computer programs or instructions; The communication interface, coupled to the processor, is configured to input and / or output information.
31. A computer readable storage medium, characterized in that, The computer readable storage medium stores computer programs or instructions which, when running on the communication device, cause the communication device to perform the method of any one of claims 1 to 5; or cause the communication device to perform the method of any one of claims 6 to 12; or cause the communication device to perform the method of any one of claims 13 to 21; or cause the communication device to perform the method of any one of claims 22 to 26.
32. A computer program product, characterised in that, The computer program product comprises computer programs or instructions which, when running on the communication device, cause the communication device to perform the method of any one of claims 1 to 5; or cause the communication device to perform the method of any one of claims 6 to 12; or cause the communication device to perform the method of any one of claims 13 to 21; or cause the communication device to perform the method of any one of claims 22 to 26.
Citation Information
Patent Citations
Data protection method, device and system
CN110891269A
Secure communication method and communication device
CN115706973A
Communication method and device
CN117376900A
Communication method, communication device and communication system
CN117440366A