Communication method and apparatus, communication device, communication system, and storage medium

By introducing multiple network elements and devices into the 5G communication system to execute policy decisions and QoS processing for encrypted data streams, the QoS processing challenge of encrypted data streams in high-traffic applications is solved, and effective management and quality assurance of encrypted data streams are achieved.

WO2026020477A1PCT designated stage Publication Date: 2026-01-29BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/107953
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-26
Publication Date
2026-01-29

AI Technical Summary

Technical Problem

In 5G communication networks, how to effectively handle the Quality of Service (QoS) of encrypted data streams to meet different business needs, especially in high-traffic application scenarios such as mobile media services, online extended reality, and drone remote control, is a challenge that existing technologies struggle to achieve policy decisions and QoS processing for encrypted data streams.

Method used

By introducing multiple network elements and devices into the communication system, policy decisions and QoS processing for encrypted data streams are executed respectively. This includes receiving and sending relevant information to process the support characteristics, priorities, protocol descriptions, and address information of encrypted data streams, supporting the identification and mapping of encrypted data streams, and using encryption protocols such as MOQT, MASQUE, and extended UDP for transmission.

Benefits of technology

It achieves effective QoS processing for encrypted data streams, ensuring communication quality for different services, meeting the needs of high-traffic applications, and improving network flexibility and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024107953_29012026_PF_FP_ABST
    Figure CN2024107953_29012026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a communication method and apparatus, a communication device, a communication system, and a storage medium. The method comprises: receiving first information sent by a second network element, wherein the first information is used for implementing a policy decision for a first encrypted data flow of a first service. By means of the solution of the present disclosure, QoS processing for encrypted data flows can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and apparatus, communication device, communication system, and storage medium TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of communication, and in particular to a communication method and apparatus, a communication device, a communication system, and a storage medium. BACKGROUND

[0002] In communication technologies such as the 5th generation mobile networks (5G), mobile media services, online extended reality (XR), online games, video-based machine or drone remote control, etc. are expected to contribute more and more traffic to the communication network.

[0003] In actual network deployment and application, a large number of service data flows (SDFs) are encrypted data flows.

[0004] SUMMARY

[0005] The present disclosure provides a communication method and apparatus, a communication device, a communication system, and a storage medium.

[0006] According to a first aspect of the present disclosure, a communication method is provided. The communication method is performed by a first network element. The communication method comprises: receiving first information sent by a second network element, wherein the first information is used for policy decision of a first encrypted data flow of a first service.

[0007] According to a second aspect of the present disclosure, a communication method is provided. The communication method is performed by a second network element. The communication method comprises: sending first information to a first network element, wherein the first information is used for policy decision of a first encrypted data flow of a first service.

[0008] According to a third aspect of the present disclosure, a communication method is provided. The communication method is performed by a third network element. The communication method comprises: receiving second information sent by a first network element, wherein the second information is used for quality of service (QoS) processing of a first encrypted data flow of a first service.

[0009] According to a fourth aspect of the present disclosure, a communication method is provided. The communication method is performed by a fifth network element. The communication method comprises: receiving fourth information sent by a third network element, wherein the fourth information is used for QoS processing of a first encrypted data flow of a first service by the fifth network element.

[0010] According to a fifth aspect of the embodiments of the present disclosure, a communication method is provided. The communication method is performed by a first device. The communication method comprises: receiving fifth information sent by a fifth network element, wherein the fifth information is used for QoS processing of a first encrypted data flow of a first service by the first device.

[0011] According to a sixth aspect of the embodiments of the present disclosure, a communication method is provided. The communication method is performed by a core network. The core network comprises a first network element, a second network element, a third network element, and a fifth network element. The communication method comprises: the first network element performing the communication method according to the first aspect; the second network element performing the communication method according to the second aspect; the third network element performing the communication method according to the third aspect; the fifth network element performing the communication method according to the fourth aspect; and the first device performing the communication method according to the fifth aspect.

[0012] According to a seventh aspect of the embodiments of the present disclosure, a communication apparatus is provided. The communication apparatus is arranged in a first network element. The communication apparatus comprises a transceiver module. The transceiver module is configured to: receive first information sent by a second network element, wherein the first information is used for policy decision of a first encrypted data flow of a first service.

[0013] According to an eighth aspect of the embodiments of the present disclosure, a communication apparatus is provided. The communication apparatus is arranged in a second network element. The communication apparatus comprises a transceiver module. The transceiver module is configured to: send first information to a first network element, wherein the first information is used for policy decision of a first encrypted data flow of a first service.

[0014] According to a ninth aspect of the embodiments of the present disclosure, a communication apparatus is provided. The communication apparatus is arranged in a third network element. The communication apparatus comprises a transceiver module. The transceiver module is configured to: receive second information sent by a first network element, wherein the second information is used for QoS processing of a first encrypted data flow of a first service.

[0015] According to a tenth aspect of the embodiments of the present disclosure, a communication apparatus is provided. The communication apparatus is arranged in a fifth network element. The communication apparatus comprises a transceiver module. The transceiver module is configured to: receive fourth information sent by a third network element, wherein the fourth information is used for QoS processing of a first encrypted data flow of a first service by the fifth network element.

[0016] According to an eleventh aspect of the embodiments of the present disclosure, a communication apparatus is provided. The communication apparatus is arranged in a first device. The communication apparatus comprises a transceiver module. The transceiver module is configured to: receive fifth information sent by a fifth network element, wherein the fifth information is used for QoS processing of a first encrypted data flow of a first service by the first device.

[0017] According to a twelfth aspect of the embodiments of the present disclosure, a communication device is provided. The communication device includes one or more processors and a memory storing instructions. The instructions, when executed by the communication device, cause the communication device to implement the communication method according to the first aspect, the second aspect, the third aspect, the fourth aspect, or the fifth aspect.

[0018] According to a thirteenth aspect of the embodiments of the present disclosure, a communication system is provided. The communication system includes at least one of: a first network element configured to implement the communication method according to the first aspect; a second network element configured to implement the communication method according to the second aspect; a third network element configured to implement the communication method according to the third aspect; a fourth network element configured to implement the communication method according to the fourth aspect; a fifth network element configured to implement the communication method according to the fifth aspect; and a first device configured to implement the communication method according to the sixth aspect.

[0019] According to a fourteenth aspect of the embodiments of the present disclosure, a storage medium is provided. The storage medium stores instructions. The instructions, when executed on a communication device, cause the communication device to perform the communication method according to any one of the first aspect to the sixth aspect.

[0020] According to a fifteenth aspect of the embodiments of the present disclosure, a program product is provided. The program product, when executed by a communication device, causes the communication device to perform the communication method according to any one of the first aspect to the sixth aspect.

[0021] According to a sixteenth aspect of the embodiments of the present disclosure, a computer program is provided. The computer program, when executed on a computer, causes the computer to perform the communication method according to any one of the first aspect to the sixth aspect.

[0022] According to a seventeenth aspect of the embodiments of the present disclosure, a chip or chip system is provided. The chip or chip system includes processing circuitry. The processing circuitry is configured to perform the communication method according to any one of the first aspect to the sixth aspect.

[0023] By the embodiments of the present disclosure, the QoS processing on the encrypted data stream can be implemented.

[0024] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory and are not restrictive of the embodiments of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following introduces the drawings required for the embodiment description. The following drawings only constitute some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.

[0026] FIG. 1A is an architecture schematic diagram of a communication system according to an embodiment of the present disclosure.

[0027] FIG. 1B is a schematic diagram of an architecture of an implementation of a communication system, according to an embodiment of the present disclosure.

[0028] FIG. 1C is a schematic diagram of an architecture of another implementation of a communication system, according to an embodiment of the present disclosure.

[0029] FIG. 2A is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0030] FIG. 2B is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0031] FIG. 3A is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0032] FIG. 3B is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0033] FIG. 4A is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0034] FIG. 4B is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0035] FIG. 5A is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0036] FIG. 5B is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0037] FIG. 6A is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0038] FIG. 6B is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0039] FIG. 7 is a schematic diagram of a flow of a communication method, according to an embodiment of the present disclosure.

[0040] FIG. 8A is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0041] FIG. 8B is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0042] FIG. 8C is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0043] FIG. 8D is a schematic diagram of interactions of a communication method, according to an embodiment of the present disclosure.

[0044] FIG. 9A is a schematic diagram of interactions of an example implementation of a communication method, according to an embodiment of the present disclosure.

[0045] FIG. 9B is an interaction schematic diagram of an exemplary embodiment of a communication method according to an embodiment of the present disclosure.

[0046] FIG. 10 is a structural schematic diagram of a communication apparatus according to an embodiment of the present disclosure.

[0047] FIG. 11A is a structural schematic diagram of a communication device according to an embodiment of the present disclosure.

[0048] FIG. 11B is a structural schematic diagram of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0049] Embodiments of the present disclosure provide a communication method and apparatus, a communication device, a communication system, and a storage medium.

[0050] In a first aspect, embodiments of the present disclosure provide a communication method. The communication method is applied to a first network element. The communication method comprises: receiving first information sent by a second network element, wherein the first information is used for policy decision of a first encrypted data flow of a first service.

[0051] In some embodiments of the first aspect, the first information can comprise at least one of the following: first support information, used for indicating support characteristics of the encrypted data flow; priority information, used for determining a priority of the encrypted data flow; protocol description information, used for describing a related protocol of the first encrypted data flow.

[0052] In some embodiments of the first aspect, the first support information can be used for indicating at least one of the following: whether to support identification of the encrypted data flow; whether to support identification of PDU set information of the encrypted data flow; whether to support identification of a sub-flow in a multiplexed data flow; whether to support mapping from a sub-flow of an encrypted multiplexed data flow to a plurality of QoS flows; whether to support mapping from flow data of different media types of an encrypted multiplexed data flow to a plurality of QoS flows; whether to support mapping from flow data of different media components of an encrypted multiplexed data flow to a plurality of QoS flows; a supported encryption protocol; a supported transmission direction of the encrypted data flow.

[0053] In some embodiments of the first aspect, the encryption protocol can comprise at least one of the following: MOQT; MASQUE; extended UDP; N6 tunnel.

[0054] In some embodiments of the first aspect, the transmission direction can comprise one of the following: uplink; downlink; uplink and downlink.

[0055] In some embodiments of the first aspect, the priority information can be related to at least one of the following: an encryption protocol; a service; a network deployment; a network function.

[0056] In some embodiments of the first aspect, the method further comprises sending second information to the third network element, wherein the second information is used to implement the QoS processing of the first encrypted data flow.

[0057] In some embodiments of the first aspect, the second information comprises at least one of: second support information indicating support of encrypted data flow; priority information used to determine the priority of the encrypted data flow; protocol description information used to describe the related protocol of the first encrypted data flow; address information used to indicate the address of a fourth network element related to the first service.

[0058] In some embodiments of the first aspect, the second support information is used to indicate at least one of: support of identification of encrypted data flow; support of identification of PDU set information of encrypted data flow; support of identification of sub-flow in multiplexed data flow; support of mapping from sub-flow of encrypted multiplexed data flow to multiple QoS flows; support of mapping from flow data of different media types of encrypted multiplexed data flow to multiple QoS flows; support of mapping from flow data of different media components of encrypted multiplexed data flow to multiple QoS flows; supported encryption protocol; supported transmission direction of encrypted data flow.

[0059] In some embodiments of the first aspect, the method further comprises determining a first rule according to the first information, wherein the first rule comprises the second information.

[0060] In some embodiments of the first aspect, the second information further comprises subscription information used for event subscription related to the first encrypted data flow.

[0061] In some embodiments of the first aspect, the method further comprises receiving third information sent by a third network element, wherein the third information is used to indicate an event related to the first encrypted data flow.

[0062] In a second aspect, the embodiments of the present disclosure provide a communication method. The communication method is applied to a second network element. The communication method comprises: sending first information to a first network element, wherein the first information is used to implement policy decision of a first encrypted data flow of a first service.

[0063] In some embodiments of the second aspect, the first information comprises at least one of: first support information indicating support characteristics of encrypted data flow; priority information used to determine the priority of the encrypted data flow; protocol description information used to describe the related protocol of the first encrypted data flow.

[0064] In some embodiments in combination with the second aspect, in some embodiments, the first support information can be used to indicate at least one of: whether identification of encrypted data flow is supported; whether PDU set information of encrypted data flow is supported; whether identification of sub-flow in multiplexed data flow is supported; whether mapping from sub-flow of encrypted multiplexed data flow to multiple QoS flows is supported; whether mapping from flow data of different media types of encrypted multiplexed data flow to multiple QoS flows is supported; whether mapping from flow data of different media components of encrypted multiplexed data flow to multiple QoS flows is supported; supported encryption protocol; supported transmission direction of encrypted data flow.

[0065] In some embodiments in combination with the second aspect, in some embodiments, the encryption protocol can comprise at least one of: MOQT; MASQUE; extended UDP; N6 tunnel.

[0066] In some embodiments in combination with the second aspect, in some embodiments, the transmission direction can comprise one of: uplink; downlink; uplink and downlink.

[0067] In some embodiments in combination with the second aspect, in some embodiments, the priority information can be related to at least one of: encryption protocol; traffic; network deployment; network function.

[0068] In a third aspect, the embodiments of the present disclosure provide a communication method. The communication method is applied to a third network element. The communication method comprises: receiving second information sent by a first network element, wherein the second information is used to implement QoS processing on a first encrypted data flow of a first service.

[0069] In some embodiments in combination with the third aspect, in some embodiments, the second information can comprise at least one of: second support information used to indicate support of encrypted data flow; priority information used to determine priority of encrypted data flow; protocol description information used to describe related protocol of the first encrypted data flow; address information used to indicate address of a fourth network element related to the first service.

[0070] In some embodiments in combination with the third aspect, in some embodiments, the second support information can be used to indicate at least one of: support of identification of encrypted data flow; support of PDU set information of encrypted data flow; support of identification of sub-flow in multiplexed data flow; support of mapping from sub-flow of encrypted multiplexed data flow to multiple QoS flows; support of mapping from flow data of different media types of encrypted multiplexed data flow to multiple QoS flows; support of mapping from flow data of different media components of encrypted multiplexed data flow to multiple QoS flows; supported encryption protocol; supported transmission direction of encrypted data flow.

[0071] In some embodiments of the third aspect, in some embodiments, the encryption protocol can include at least one of: MOQT; MASQUE; extended UDP; N6 tunnel.

[0072] In some embodiments of the third aspect, in some embodiments, the transmission direction can include one of: uplink; downlink; uplink and downlink.

[0073] In some embodiments of the third aspect, in some embodiments, the priority information can be related to at least one of: the encryption protocol; the traffic; the network deployment; the network function.

[0074] In some embodiments of the third aspect, in some embodiments, the second information can be contained in the first rule, which is determined based on the first information.

[0075] In some embodiments of the third aspect, in some embodiments, the method can further include: sending fourth information to a fifth network element, wherein the fourth information is used for the fifth network element to perform QoS processing on the first encrypted data flow.

[0076] In some embodiments of the third aspect, in some embodiments, the fourth information can include at least one of: encryption protocol information, used to indicate at least one encryption protocol; policy information, used to indicate a QoS processing policy related to the first encrypted data flow; protocol description information, used to describe a related protocol of the first encrypted data flow; address information, used to indicate an address of the fourth network element related to the first traffic.

[0077] In some embodiments of the third aspect, in some embodiments, at least one of the encryption protocol information and the policy information can be determined based at least on the second information.

[0078] In some embodiments of the third aspect, in some embodiments, the second information and the fourth information can both further include subscription information, which is used for event subscription related to the first encrypted data flow.

[0079] In some embodiments of the third aspect, in some embodiments, the method can further include: receiving third information sent by the fifth network element, wherein the third information is used to indicate an event related to the first encrypted data flow; and sending the third information to the first network element.

[0080] In a fourth aspect, the embodiments of the present disclosure provide a communication method. The communication method is applied to a fifth network element. The communication method includes: receiving fourth information sent by a third network element, wherein the fourth information is used for the fifth network element to perform QoS processing on a first encrypted data flow of a first traffic.

[0081] In some embodiments of the fourth aspect, in some embodiments, the fourth information comprises at least one of: encryption protocol information, for indicating at least one encryption protocol; policy information, for indicating a QoS processing policy related to the first encrypted data flow; protocol description information, for describing a related protocol of the first encrypted data flow; address information, for indicating an address of the fourth network element related to the first service.

[0082] In some embodiments of the fourth aspect, in some embodiments, at least one of the encryption protocol information and the policy information can be determined based at least on the second information, the second information being used for implementing the QoS processing of the first encrypted data flow.

[0083] In some embodiments of the fourth aspect, in some embodiments, the second information can comprise at least one of: second support information, for indicating support of encrypted data flow; priority information, for determining a priority of encrypted data flow; protocol description information; address information.

[0084] In some embodiments of the fourth aspect, in some embodiments, the second support information can be used for indicating at least one of: support of identification of encrypted data flow; support of identification of PDU set information of encrypted data flow; support of identification of sub-flow in multiplexed data flow; support of mapping from sub-flow of encrypted multiplexed data flow to multiple QoS flows; support of mapping from flow data of different media types of encrypted multiplexed data flow to multiple QoS flows; support of mapping from flow data of different media components of encrypted multiplexed data flow to multiple QoS flows; supported encryption protocol; supported transmission direction of encrypted data flow.

[0085] In some embodiments of the fourth aspect, in some embodiments, the encryption protocol comprises at least one of: MOQT; MASQUE; extended UDP; N6 tunnel.

[0086] In some embodiments of the fourth aspect, in some embodiments, the transmission direction can comprise one of: uplink; downlink; uplink and downlink.

[0087] In some embodiments of the fourth aspect, in some embodiments, the priority information can be related to at least one of: encryption protocol; service; network deployment; network function.

[0088] In some embodiments of the fourth aspect, in some embodiments, the fourth information can comprise the address information; and the method can further comprise: establishing a connection with the fourth network element according to the address information.

[0089] In some embodiments of the fourth aspect, in some embodiments, the method can further comprise: performing mapping between the first encrypted data flow and the QoS flow according to the fourth information.

[0090] In some embodiments of the fourth aspect, in some embodiments, according to the fourth information, the operation of performing mapping between the first encrypted data stream and the QoS flow can comprise: according to the fourth information, determining an encryption protocol used for identifying the first encrypted data stream.

[0091] In some embodiments of the fourth aspect, in some embodiments, the method can further comprise: sending fifth information to the first device, wherein the fifth information is carried in a downlink data packet of the first encrypted data stream, and the fifth information is used by the first device for QoS processing of the first encrypted data stream.

[0092] In some embodiments of the fourth aspect, in some embodiments, the fifth information comprises at least one of: encryption protocol information used for indicating at least one encryption protocol; policy information used for indicating a QoS processing policy related to the first encrypted data stream; and protocol description information used for describing a related protocol of the first encrypted data stream.

[0093] In some embodiments of the fourth aspect, in some embodiments, the fourth information further comprises subscription information used for event subscription related to the first encrypted data stream.

[0094] In some embodiments of the fourth aspect, in some embodiments, the method can further comprise at least one of: sending third information to a third network element on a control plane; and sending the third information to a fourth network element on a user plane, wherein the third information is used for indicating an event related to the first encrypted data stream.

[0095] In a fifth aspect, the embodiments of the present disclosure provide a communication method. The communication method is applied to a first device. The communication method comprises: receiving fifth information sent by a fifth network element, wherein the fifth information is used for QoS processing of a first encrypted data stream of a first service by the first device.

[0096] In some embodiments of the fifth aspect, in some embodiments, the fifth information can comprise at least one of: encryption protocol information used for indicating at least one encryption protocol; policy information used for indicating a QoS processing policy related to the first encrypted data stream; and protocol description information used for describing a related protocol of the first encrypted data stream.

[0097] In some embodiments of the fifth aspect, in some embodiments, the fifth information is carried in a downlink data packet of the first encrypted data stream.

[0098] In some embodiments of the fifth aspect, in some embodiments, the fifth information can be determined based at least on fourth information used for QoS processing of the first encrypted data stream of the first service by the fifth network element.

[0099] In some embodiments of the fifth aspect, in some embodiments, the fourth information can comprise at least one of: encryption protocol information, for indicating at least one encryption protocol; policy information, for indicating a QoS processing policy related to the first encrypted data flow; protocol description information, for describing a related protocol of the first encrypted data flow; address information, for indicating an address of the fourth network element related to the first service.

[0100] In a sixth aspect, the embodiments of the present disclosure provide a communication method. The communication method is performed by a core network. The core network comprises a first network element, a second network element, a third network element, and a fifth network element. The communication method comprises: the first network element performing the communication method according to any one of the first aspect and possible implementation manners thereof; the second network element performing the communication method according to any one of the second aspect and possible implementation manners thereof; the third network element performing the communication method according to any one of the third aspect and possible implementation manners thereof; the fifth network element performing the communication method according to any one of the fourth aspect and possible implementation manners thereof; and the first device performing the communication method according to any one of the fifth aspect and possible implementation manners thereof.

[0101] In a seventh aspect, the embodiments of the present disclosure provide a communication apparatus. The communication apparatus is arranged in a first network element. The communication apparatus comprises a transceiver module. The transceiver module is configured to: receive first information sent by a second network element, wherein the first information is used for policy decision of a first encrypted data flow of a first service.

[0102] In some embodiments of the seventh aspect, in some embodiments, the first information can comprise at least one of: first support information, for indicating support characteristics of encrypted data flow; priority information, for determining a priority of encrypted data flow; protocol description information, for describing a related protocol of the first encrypted data flow.

[0103] In some embodiments of the seventh aspect, in some embodiments, the first support information can be used for indicating at least one of: whether to support identification of encrypted data flow; whether to support identification of PDU set information of encrypted data flow; whether to support identification of sub-flow in multiplexed data flow; whether to support mapping from sub-flow of encrypted multiplexed data flow to multiple QoS flows; whether to support mapping from flow data of different media types of encrypted multiplexed data flow to multiple QoS flows; whether to support mapping from flow data of different media components of encrypted multiplexed data flow to multiple QoS flows; supported encryption protocol; supported transmission direction of encrypted data flow.

[0104] In some embodiments of the seventh aspect, in some embodiments, the encryption protocol can comprise at least one of: MOQT; MASQUE; extended UDP; N6 tunnel.

[0105] In some embodiments of the seventh aspect, in some embodiments, the transmission direction can comprise one of: uplink; downlink; uplink and downlink.

[0106] In some embodiments of the seventh aspect, in some embodiments, the priority information can be related to at least one of: a ciphering protocol; a traffic; a network deployment; a network function.

[0107] In some embodiments of the seventh aspect, in some embodiments, the transceiver module can be further configured to: send second information to the third network element, wherein the second information is used to implement the QoS processing of the first ciphered data flow.

[0108] In some embodiments of the seventh aspect, in some embodiments, the second information can comprise at least one of: second support information, used to indicate support of the ciphered data flow; priority information, used to determine the priority of the ciphered data flow; protocol description information, used to describe a related protocol of the first ciphered data flow; address information, used to indicate an address of a fourth network element related to the first traffic.

[0109] In some embodiments of the seventh aspect, in some embodiments, the second support information can be used to indicate at least one of: support of identification of the ciphered data flow; support of identification of PDU set information of the ciphered data flow; support of identification of sub-flows in a multiplexed data flow; support of mapping from sub-flows of a ciphered multiplexed data flow to a plurality of QoS flows; support of mapping from flow data of different media types of a ciphered multiplexed data flow to a plurality of QoS flows; support of mapping from flow data of different media components of a ciphered multiplexed data flow to a plurality of QoS flows; supported ciphering protocol; supported transmission direction of the ciphered data flow.

[0110] In some embodiments of the seventh aspect, in some embodiments, the apparatus can further comprise a processing module. The processing module is configured to: determine, according to the first information, a first rule, wherein the first rule comprises the second information.

[0111] In some embodiments of the seventh aspect, in some embodiments, the second information can further comprise subscription information, used for event subscription related to the first ciphered data flow.

[0112] In some embodiments of the seventh aspect, in some embodiments, the transceiver module can be further configured to: receive third information sent by a third network element, wherein the third information is used to indicate an event related to the first ciphered data flow.

[0113] In an eighth aspect, the embodiments of the present disclosure provide a communication apparatus. The communication apparatus is arranged in a second network element. The communication apparatus comprises a transceiver. The transceiver is configured to send first information to a first network element, wherein the first information is used for policy decision of a first encrypted data flow of a first service.

[0114] In some embodiments of the eighth aspect, the first information can comprise at least one of: first support information, used for indicating support characteristics of the encrypted data flow; priority information, used for determining a priority of the encrypted data flow; protocol description information, used for describing a related protocol of the first encrypted data flow.

[0115] In some embodiments of the eighth aspect, the first support information can be used for indicating at least one of: whether to support identification of the encrypted data flow; whether to support identification of PDU set information of the encrypted data flow; whether to support identification of sub-flows in a multiplexed data flow; whether to support mapping from a sub-flow of the encrypted multiplexed data flow to a plurality of QoS flows; whether to support mapping from flow data of different media types of the encrypted multiplexed data flow to the plurality of QoS flows; whether to support mapping from flow data of different media components of the encrypted multiplexed data flow to the plurality of QoS flows; a supported encryption protocol; a supported transmission direction of the encrypted data flow.

[0116] In some embodiments of the eighth aspect, the encryption protocol can comprise at least one of: MOQT; MASQUE; extended UDP; N6 tunnel.

[0117] In some embodiments of the eighth aspect, the transmission direction can comprise one of: uplink; downlink; uplink and downlink.

[0118] In some embodiments of the eighth aspect, the priority information can be related to at least one of: an encryption protocol; a service; a network deployment; a network function.

[0119] In a ninth aspect, the embodiments of the present disclosure provide a communication apparatus. The communication apparatus is arranged in a third network element. The communication apparatus comprises a transceiver. The transceiver is configured to receive second information sent by a first network element, wherein the second information is used for QoS processing of a first encrypted data flow of a first service.

[0120] In some embodiments of the ninth aspect, the second information can comprise at least one of: second support information, used for indicating support of the encrypted data flow; priority information, used for determining a priority of the encrypted data flow; protocol description information, used for describing a related protocol of the first encrypted data flow; address information, used for indicating an address of a fourth network element related to the first service.

[0121] In some embodiments in combination with the ninth aspect, in some embodiments, the second support information can be used to indicate at least one of: support for identification of encrypted data flows; support for identification of PDU set information of encrypted data flows; support for identification of sub-flows in multiplexed data flows; support for mapping from sub-flows of encrypted multiplexed data flows to multiple QoS flows; support for mapping from flow data of different media types of encrypted multiplexed data flows to multiple QoS flows; support for mapping from flow data of different media components of encrypted multiplexed data flows to multiple QoS flows; supported encryption protocols; supported transmission direction of encrypted data flows.

[0122] In some embodiments in combination with the ninth aspect, in some embodiments, the encryption protocols can comprise at least one of: MOQT; MASQUE; extended UDP; N6 tunnel.

[0123] In some embodiments in combination with the ninth aspect, in some embodiments, the transmission direction can comprise one of: uplink; downlink; uplink and downlink.

[0124] In some embodiments in combination with the ninth aspect, in some embodiments, the priority information can be related to at least one of: encryption protocols; traffic; network deployment; network functions.

[0125] In some embodiments in combination with the ninth aspect, in some embodiments, the second information can be contained in a first rule, which is determined based on the first information.

[0126] In some embodiments in combination with the ninth aspect, in some embodiments, the transceiver module can be further configured to: send fourth information to a fifth network element, wherein the fourth information is used for QoS processing of the first encrypted data flow by the fifth network element.

[0127] In some embodiments in combination with the ninth aspect, in some embodiments, the fourth information can comprise at least one of: encryption protocol information, used to indicate at least one encryption protocol; policy information, used to indicate a QoS processing policy related to the first encrypted data flow; protocol description information, used to describe a related protocol of the first encrypted data flow; address information, used to indicate an address of the fourth network element related to the first traffic.

[0128] In some embodiments in combination with the ninth aspect, in some embodiments, at least one of the encryption protocol information and the policy information can be determined based at least on the second information.

[0129] In some embodiments in combination with the ninth aspect, in some embodiments, both the second information and the fourth information can further comprise subscription information, which is used for event subscription related to the first encrypted data flow.

[0130] In some embodiments of the ninth aspect, in some embodiments, the transceiver module is further configured to: receive third information sent by the fifth network element, wherein the third information is used to indicate the event related to the first encrypted data flow; and send the third information to the first network element.

[0131] In a tenth aspect, the embodiments of the present disclosure provide a communication device. The communication device is arranged in the fifth network element. The communication device comprises a transceiver module. The transceiver module is configured to: receive fourth information sent by the third network element, wherein the fourth information is used for QoS processing of the first encrypted data flow of the first service by the fifth network element.

[0132] In some embodiments of the tenth aspect, in some embodiments, the fourth information comprises at least one of: encryption protocol information used to indicate at least one encryption protocol; policy information used to indicate a QoS processing policy related to the first encrypted data flow; protocol description information used to describe a related protocol of the first encrypted data flow; and address information used to indicate an address of the fourth network element related to the first service.

[0133] In some embodiments of the tenth aspect, in some embodiments, at least one of the encryption protocol information and the policy information can be determined based at least on the second information, the second information being used to implement the QoS processing of the first encrypted data flow.

[0134] In some embodiments of the tenth aspect, in some embodiments, the second information comprises at least one of: second support information used to indicate support of encrypted data flow; priority information used to determine a priority of the encrypted data flow; protocol description information; and address information.

[0135] In some embodiments of the tenth aspect, in some embodiments, the second support information can be used to indicate at least one of: support of identification of encrypted data flow; support of identification of PDU set information of encrypted data flow; support of identification of sub-flow in multiplexed data flow; support of mapping from sub-flow of encrypted multiplexed data flow to multiple QoS flows; support of mapping from flow data of different media types of encrypted multiplexed data flow to multiple QoS flows; support of mapping from flow data of different media components of encrypted multiplexed data flow to multiple QoS flows; supported encryption protocol; and supported transmission direction of encrypted data flow.

[0136] In some embodiments of the tenth aspect, in some embodiments, the encryption protocol comprises at least one of: MOQT; MASQUE; extended UDP; and N6 tunnel.

[0137] In some embodiments of the tenth aspect, in some embodiments, the transmission direction comprises one of: uplink; downlink; and uplink and downlink.

[0138] In some embodiments of the tenth aspect, in some embodiments, the priority information can be related to at least one of: a ciphering protocol; a service; a network deployment; a network function.

[0139] In some embodiments of the tenth aspect, in some embodiments, the fourth information can comprise address information; and the transceiver module can be further configured to establish a connection with the fourth network element according to the address information.

[0140] In some embodiments of the tenth aspect, in some embodiments, the apparatus can further comprise a processing module configured to perform the mapping between the first ciphering data flow and the QoS flow according to the fourth information.

[0141] In some embodiments of the tenth aspect, in some embodiments, performing the mapping between the first ciphering data flow and the QoS flow according to the fourth information can comprise determining a ciphering protocol used for identifying the first ciphering data flow according to the fourth information.

[0142] In some embodiments of the tenth aspect, in some embodiments, the transceiver module can be further configured to send fifth information to the first device, wherein the fifth information is carried in a downlink packet of the first ciphering data flow, and the fifth information is used for QoS processing of the first ciphering data flow by the first device.

[0143] In some embodiments of the tenth aspect, in some embodiments, the fifth information comprises at least one of: ciphering protocol information used for indicating at least one ciphering protocol; policy information used for indicating a QoS processing policy related to the first ciphering data flow; and protocol description information used for describing a related protocol of the first ciphering data flow.

[0144] In some embodiments of the tenth aspect, in some embodiments, the fourth information further comprises subscription information used for event subscription related to the first ciphering data flow.

[0145] In some embodiments of the tenth aspect, in some embodiments, the transceiver module can be further configured to perform at least one of: sending third information to the third network element on a control plane; and sending the third information to the fourth network element on a user plane, wherein the third information is used for indicating an event related to the first ciphering data flow.

[0146] In an eleventh aspect, the embodiments of the present disclosure provide a communication apparatus. The communication apparatus is arranged in a first device. The communication apparatus comprises a transceiver module. The transceiver module is configured to receive fifth information sent by a fifth network element, wherein the fifth information is used for QoS processing of a first ciphering data flow of a first service by the first device.

[0147] In some embodiments of the eleventh aspect, in some embodiments, the fifth information can comprise at least one of: encryption protocol information, for indicating at least one encryption protocol; policy information, for indicating a QoS processing policy related to the first encrypted data flow; protocol description information, for describing a related protocol of the first encrypted data flow.

[0148] In some embodiments of the eleventh aspect, in some embodiments, the fifth information is carried in a downlink data packet of the first encrypted data flow.

[0149] In some embodiments of the eleventh aspect, in some embodiments, the fifth information can be determined based at least on the fourth information, the fourth information being used for the fifth network element to process the QoS of the first encrypted data flow of the first service.

[0150] In some embodiments of the eleventh aspect, in some embodiments, the fourth information can comprise at least one of: encryption protocol information, for indicating at least one encryption protocol; policy information, for indicating a QoS processing policy related to the first encrypted data flow; protocol description information, for describing a related protocol of the first encrypted data flow; address information, for indicating an address of the fourth network element related to the first service.

[0151] In a twelfth aspect, the embodiments of the present disclosure provide a communication device. The communication device comprises one or more processors, and a memory storing instructions. The instructions, when executed by the communication device, cause the communication device to implement the communication method according to any one of the first aspect, the second aspect, the third aspect, the fourth aspect, the fifth aspect, and possible implementation manners thereof.

[0152] In a thirteenth aspect, the embodiments of the present disclosure provide a communication system. The communication system comprises at least one of: a first network element configured to implement the communication method according to any one of the first aspect and possible implementation manners thereof; a second network element configured to implement the communication method according to any one of the second aspect and possible implementation manners thereof; a third network element configured to implement the communication method according to any one of the third aspect and possible implementation manners thereof; a fourth network element configured to implement the communication method according to any one of the fourth aspect and possible implementation manners thereof; a fifth network element configured to implement the communication method according to any one of the fifth aspect and possible implementation manners thereof; and a first device configured to implement the communication method according to any one of the sixth aspect and possible implementation manners thereof.

[0153] In a fourteenth aspect, the embodiments of the present disclosure provide a storage medium. The storage medium stores instructions. The instructions, when executed on a communication device, cause the communication device to perform the communication method according to any one of the first aspect to the sixth aspect, and possible implementation manners thereof.

[0154] In a fifteenth aspect, an embodiment of the present disclosure provides a program product. The program product, when executed by a communication device, causes the communication device to perform the communication method according to any one of the first aspect to the sixth aspect and possible implementation manners thereof.

[0155] In a sixteenth aspect, an embodiment of the present disclosure provides a computer program. The computer program, when running on a computer, causes the computer to perform the communication method according to any one of the first aspect to the sixth aspect and possible implementation manners thereof.

[0156] In a seventeenth aspect, an embodiment of the present disclosure provides a chip or chip system. The chip or chip system includes processing circuitry. The processing circuitry is configured to perform the communication method according to any one of the first aspect to the sixth aspect and possible implementation manners thereof.

[0157] It can be understood that the above communication apparatus, communication device, communication system, storage medium, program product, computer program, chip, and chip system are all used to perform the communication method provided by the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved thereby can refer to the beneficial effects in the corresponding method, which will not be described here again.

[0158] Embodiments of the present disclosure provide a communication method and apparatus, a communication device, a communication system, and a storage medium. In some embodiments, the terms of the communication method and the information processing method can be replaced with each other, the terms of the network element and the information processing apparatus, the communication apparatus can be replaced with each other, and the terms of the information processing system and the communication system can be replaced with each other.

[0159] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily. For example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be arbitrarily exchanged. In addition, the optional implementation manners in an embodiment can be combined arbitrarily. In addition, the embodiments can be combined arbitrarily. For example, part or all steps of different embodiments can be combined arbitrarily. For another example, an embodiment can be combined with the optional implementation manners of other embodiments.

[0160] In each embodiment of the present disclosure, the terms and / or descriptions between the embodiments are consistent if there is no special description and logical conflict, and can be referred to each other. The technical features in different embodiments can be combined to form a new embodiment according to their inherent logical relationship.

[0161] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and not as a limitation on the present disclosure.

[0162] In the embodiments of the present disclosure, an element expressed in singular form, such as "a", "an", "the", "said", "the aforementioned", "the foregoing", "this", and the like, unless otherwise specified, can represent "one and only one", or can represent "one or more", "at least one", and the like. For example, in the case of using an article such as "a", "an", "the" in English, the noun after the article can be understood as a singular expression, or can be understood as a plural expression.

[0163] In the embodiments of the present disclosure, "plurality" refers to two or more.

[0164] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple", and the like can be replaced with each other.

[0165] In some embodiments, the description manner such as "at least one of A, B", "A and / or B", "A in one case and B in another case", "A in response to one case and B in response to another case", and the like, according to the case, can include the following technical solutions: A in some embodiments (A is executed regardless of B); B in some embodiments (B is executed regardless of A); A and B are selectively executed in some embodiments (A and B are selected from A and B); A and B are executed in some embodiments (A and B are executed). When there are more branches such as A, B, C, and the like, it is similar to the above.

[0166] In some embodiments, the description manner such as "A or B", and the like, according to the case, can include the following technical solutions: A in some embodiments (A is executed regardless of B); B in some embodiments (B is executed regardless of A); A and B are selectively executed in some embodiments (A and B are selected from A and B). When there are more branches such as A, B, C, and the like, it is similar to the above.

[0167] The prefix words of "first", "second" and the like in the embodiments of the present disclosure are merely used to distinguish different description objects, and do not constitute limitation on the position, order, priority, quantity or content of the description objects. The description objects are described in the claims or embodiments, and should not be construed as redundant limitation because of the use of the prefix words. For example, the description object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified thereby are in the same message or not, nor limit the order of "first field" and "second field". For another example, the description object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the quantity of the description object is not limited by the ordinal words, and can be one or more. For example, "first device", wherein the quantity of "device" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the description object is "device", and "first device" and "second device" can be the same device or different devices, and the types thereof can be the same or different. For another example, the description object is "information", and "first information" and "second information" can be the same information or different information, and the contents thereof can be the same or different.

[0168] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.

[0169] In some embodiments, the terms of "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.

[0170] In some embodiments, the terms of "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms of "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.

[0171] In some embodiments, an apparatus or the like can be interpreted as an entity, and can also be interpreted as virtual, and the name thereof is not limited to the name described in the embodiments. The terms "apparatus", "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject" and the like can be replaced with each other.

[0172] In some embodiments, a "network" can be interpreted as an apparatus (for example, an access network device, a core network device, and the like) included in the network.

[0173] In some embodiments, the terms "access network device (AN device)", "radio access network device (RAN device)", "base station (BS)", "radio base station", "fixed station", "node", "access point", "transmission point (TP)", "reception point (RP)", "transmission / reception point (TRP)", "panel", "antenna panel", "antenna array", "cell", "macro cell", "small cell", "femto cell", "pico cell", "sector", "cell group", "serving cell", "carrier", "component carrier", "bandwidth part (BWP)" and the like can be replaced with each other.

[0174] In some embodiments, the terms "terminal," "terminal device," "user equipment (UE)," "user terminal," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," and so on can be replaced with each other.

[0175] In some embodiments, the access network device, the core network device, or the network device can be replaced with a terminal. For example, the embodiments of the present disclosure can also be applied to a structure in which communication between the access network device, the core network device, or the network device and the terminal is replaced with communication between a plurality of terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the terminal can also be configured to have all or part of the functions of the access network device. In addition, the terms "uplink," "downlink," and the like can also be replaced with terms corresponding to the inter-terminal communication (e.g., "side"). For example, the uplink channel, the downlink channel, and the like can be replaced with the side channel, and the uplink, the downlink, and the like can be replaced with the sidelink.

[0176] In some embodiments, the terminal can be replaced with the access network device, the core network device, or the network device. In this case, the access network device, the core network device, or the network device can also be configured to have all or part of the functions of the terminal.

[0177] In some embodiments, the data, information, etc. can be obtained in compliance with the laws and regulations of the country where the location is situated.

[0178] In some embodiments, the data, information, etc. can be obtained after obtaining the consent of the user.

[0179] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0180] FIG. 1A is a schematic diagram of an architecture of a communication system according to an embodiment of the present disclosure. As shown in FIG. 1A, the communication system 100 includes a terminal 101, a first device 102, and a core network 103.

[0181] In some embodiments, the terminal 101 includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable automobile, a smart automobile, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, and the like, but is not limited thereto.

[0182] In some embodiments, the first device 102 can be an access network device. In some embodiments, the first device 102 can be a wireless access network device. In some embodiments, the first device 102 can be an access network device using other technologies. For example, the first device 102 can be a non-3GPP interworking function (N3IWF), a trusted non-3GPP gateway function (TNGF), a wireline access gateway function (W-AGF).

[0183] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network, and the access network device can include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.

[0184] In some embodiments, the technical solutions of the present disclosure can be applicable to an open radio access network (Open RAN) architecture, at this time, the interfaces between or within the access network devices involved in the embodiments of the present disclosure can become internal interfaces of the Open RAN, and the processes and information interactions between these internal interfaces can be realized through software or programs.

[0185] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), wherein the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and the functions of part of the protocol layers are controlled by the CU, and the functions of the remaining part or all of the protocol layers are distributed in the DU and controlled by the CU, but the present disclosure is not limited thereto.

[0186] In some embodiments, the core network 103 can be one device including the first network element 1031, the second network element 1032, the third network element 1033, the fourth network element 1034, the fifth network element 1035, the sixth network element 1036, the seventh network element 1037, etc., or can be multiple devices or device groups including all or part of the first network element 1031, the second network element 1032, the third network element 1033, the fourth network element 1034, the fifth network element 1035, the sixth network element 1036, the seventh network element 1037, etc., respectively. The network element can be virtual or physical. The core network includes, for example, at least one of an evolved packet core (EPC), a 5G core network (5GCN), a next generation core (NGC).

[0187] In some embodiments, the first network element 1031 can be, for example, a control plane network element.

[0188] In some embodiments, the first network element 1031 can be, for example, a policy control function (PCF).

[0189] In some embodiments, the first network element 1031 can be used to support a unified policy framework and provide policy rules, the name of which is not limited thereto.

[0190] In some embodiments, the second network element 1032 can be a control plane network element.

[0191] In some embodiments, the second network element 1032 can include, for example, an application function (AF).

[0192] In some embodiments, the second network element 1032 can be implemented by an application server and used to provide application services, the name of which is not limited thereto.

[0193] In some embodiments, the third network element 1033 can be, for example, a control plane network element.

[0194] In some embodiments, the third network element 1033 can be, for example, a policy control function (SMF).

[0195] In some embodiments, the third network element 1033 can be used for session management, execution of control policies issued by the PCF, selection of the UPF, allocation of an internet protocol (IP) address of the UE, and the like, the name of which is not limited thereto.

[0196] In some embodiments, the fourth network element 1034 can be a user plane network element.

[0197] In some embodiments, the fourth network element 1034 can include, for example, an application server (AS).

[0198] In some embodiments, the fourth network element 1034 can be used to provide application services and support.

[0199] In some embodiments, the fifth network element 1035 can be, for example, a user plane network element.

[0200] In some embodiments, the fifth network element 1035 can be, for example, a user plane function (UPF).

[0201] In some embodiments, the fifth network element 1035 can be used to implement user plane (UP) data forwarding, session / flow level based charging statistics, bandwidth limitation, QoS processing for UP, and the like, without limitation.

[0202] In some embodiments, the sixth network element 1036 can be, for example, a network exposure function (NEF).

[0203] In some embodiments, the sixth network element 1036 can be, for example, a common API framework (CAPIF).

[0204] In some embodiments, the sixth network element 1036 can be used to secure external applications to the 3GPP network, provide QoS customization capability exposure for external applications, mobility state time subscription, AF request distribution, and the like, without limitation.

[0205] In some embodiments, the seventh network element 1037 can be, for example, a control plane network element.

[0206] In some embodiments, the seventh network element 1037 can be, for example, an access and mobility management function (AMF).

[0207] In some embodiments, the seventh network element 1037 can be used to complete mobility management, non-access stratummobility management (NAS MM) signaling processing, NAS session management (SM) signaling routing, security anchor point and security context management, and the like, without limitation.

[0208] In some embodiments, the second network element 1032 can be located outside the core network 103, or can be located inside the core network 103, and the embodiments of the present disclosure do not make specific limitations in this regard.

[0209] In some embodiments, the fourth network element 1034 can be located outside the core network 103, or can be located inside the core network 103, and the embodiments of the present disclosure do not make specific limitations in this regard.

[0210] In some embodiments, the second network element 1032 and the fourth network element 1034 can be deployed centrally or independently, and the embodiments of the present disclosure do not make specific limitations in this regard.

[0211] In some embodiments, the above-mentioned communication system 100 can be a 5G communication system. It should be noted that the communication system 100 can also be other communication systems, such as a 4G communication system, a 6G communication system, and the embodiments of the present disclosure do not make specific limitations in this regard.

[0212] In some embodiments, one or more of the first network element 1031, the second network element 1032, the third network element 1033, the fourth network element 1034, the fifth network element 1035, the sixth network element 1036, and the seventh network element 1037 in the above-mentioned communication system 100 can also be a data plane network element.

[0213] In FIGS. 1B and 1C, the architecture of the communication system is exemplarily explained by taking the 5G communication system as an example. Here, the terminal 101 can be a UE, and the first device 102 can be a RAN.

[0214] FIG. 1B is a schematic diagram of an architecture of an implementation of a communication system according to an embodiment of the present disclosure. As shown in FIG. 1B, the architecture of the 5G communication system is presented in the form of reference points. N1 is a reference point between the UE and the AMF. N2 is a reference point between the RAN and the AMF. N3 is a reference point between the RAN and the UPF. N4 is a reference point between the SMF and the UPF. N5 is a reference point between the PCF and the AF. N6 is a reference point between the UPF and the data network (DN). N7 is a reference point between the SMF and the PCF. N11 is a reference point between the AMF and the SMF. N15 is a reference point between the SMF and the PCF. Uu is an interface between the UE and the RAN. It should be noted that the NEF is not shown in FIG. 1B. However, each network element in the communication system can interact with the NEF.

[0215] FIG. 1C is a schematic diagram of another implementation of a communication system according to an embodiment of the present disclosure. As shown in FIG. 1C, the architecture of the 5G communication system is presented in a manner of service-based interface. Namf is a service-based interface provided by the AMF. Nsmf is a service-based interface provided by the SMF. Nnef is a service-based interface provided by the NEF. Npcf is a service-based interface provided by the PCF. Naf is a service-based interface provided by the AF.

[0216] It can be understood that the communication system described in the embodiments of the present disclosure is for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and does not constitute a limitation on the technical solutions proposed by the embodiments of the present disclosure. It can be known by those skilled in the art that, with the evolution of system architecture and the appearance of new business scenarios, the technical solutions proposed by the embodiments of the present disclosure are also applicable to similar technical problems.

[0217] The following embodiments of the present disclosure can be applied to the communication system 100 shown in FIG. 1A or part of the subjects in the communication system 100, but are not limited thereto. The subjects shown in FIG. 1A are exemplary, the communication system 100 can include all or part of the subjects in FIG. 1A, or other subjects other than FIG. 1A, the number and form of each subject is arbitrary, each subject can be real or virtual, the connection relationship between each subject is exemplary, each subject can not be connected or can be connected, the connection can be in any way, can be direct connection or indirect connection, can be wired connection or wireless connection.

[0218] Embodiments of the present disclosure can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (Bluetooth (registered trademark)), Public Land Mobile Network (PLMN) network, Device-to-Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle-to-Everything (V2X), system using other communication methods, next-generation system expanded based thereon, and the like. Further, a plurality of systems can be applied in combination (for example, combination of LTE or LTE-A and 5G, and the like).

[0219] In some cases, mobile media type services, XR services such as online AR / VR, online games, video-based machine or drone remote control, etc. are expected to contribute to an increasingly high traffic for the communication network. XR services involve multi-modal data flows. Multi-modal data is data input from the same device or different devices (including sensors) describing the same service / application, which can be output to one or more destination device terminals. Each data flow in multi-modal data often has certain or even strong correlation, such as synchronization of audio and video streams, synchronization of haptics and vision, etc. There are some common characteristics in the data flow of such media services, between the data flows, and the requirements of these service data flows for network transmission. Effective identification and utilization of these characteristics will be more helpful for network and service transmission, control, and also for service guarantee and user experience.

[0220] In further cases, eXtended reality and interactive media services require the communication system to comprehensively consider the QoS characteristics of service data flows. The QoS characteristics include, for example, at least one of the following: whether delay-sensitive guaranteed bit rate (GBR) data flows, guaranteed flow bit rate (GFBR), packet delay budget (PDB), default maximum data burst volume (MDBV), etc. can be simultaneously satisfied and consistently coordinated. The consistency of QoS authorization and execution of each other for multiple XRM data flows involving one terminal and multiple terminals.

[0221] In some embodiments, the SDF of extended reality multimedia (XRM) can support PDU set-based processing, thereby enhancing QoS awareness and guarantee of the SDF, and enhancing the quality of experience (QoE) of users.

[0222] In some embodiments, in a system such as 4G, 5G, 6G, V2X, an AF can provide PDU set QoS parameters and protocol description. In some embodiments, the PDU set QoS parameters can include at least one of: PDU set delay budget (PSDB), PDU set error rate (PSER), PDU Set Integrated Handling Information (PSIHI). Then, the SMF and UPF can extend the header of the PDU in the PDU set of the SDF in combination with the protocol description and protocol header extension provided by the AF, to carry the PDU set information. The carried PDU information can be used by the access network for PDU set based QoS control.

[0223] In some embodiments, the above-mentioned PDU set information can include at least one of: PDU set sequence number, start PDU or end PDU of the PDU set, PDU sequence number within the PDU set, number of PDUs within the PDU set, PDU set importance, PDU set size. Here, the PDU set importance is used to represent the importance of a PDU set relative to other PDU sets in the same QoS flow.

[0224] It can be understood that the UPF performs SDF to QoS flow mapping based on the PDR, and maps (also can be called encapsulates) the mutually associated PDUs into a PDU set. In addition, the UPF can apply the same QoS policy to all PDU sets within the QoS flow. For example, the UPF can apply the same PDU set QoS parameters to all PDU sets within the QoS flow. In an example, the UPF can map an application flow to a QoS flow based on the packet detection information in the PDR. Some PDUs in the QoS flow can be associated with media components (e.g., intra-coded frames and predicted frames), and the UPF classifies these PDUs as belonging to a PDU set and performs corresponding control.

[0225] In some embodiments, the RAN can implement PDU set based QoS processing according to the PDU set QoS characteristics and protocol description provided by the 5GC and AF, and the enhanced header identified and marked by the UPF.

[0226] In some embodiments, a large number of application corresponding SDFs can be encrypted. For these encrypted SDFs, it is required that the communication network can identify the PDU set information and the like therein, so as to ensure the QoS processing of these encrypted data streams.

[0227] FIG. 2A is an interaction diagram of a communication method according to an embodiment of the present disclosure. The communication method according to an embodiment of the present disclosure can be applied to the communication system 100. As shown in FIG. 2A, the communication method according to an embodiment of the present disclosure includes steps S2101-S2128.

[0228] In step S2101, the second network element 1032 sends first information to the sixth network element 1036.

[0229] In some embodiments, the second network element 1032 can send the first information.

[0230] In some embodiments, the sixth network element 1036 can receive the first information.

[0231] In some embodiments, the first information can be used to determine a QoS policy of a first encrypted data flow of a first service.

[0232] In some embodiments, the first information can be used for a policy decision corresponding to the first encrypted data flow of the first service.

[0233] In some embodiments, the first information can be used to indicate a processing requirement for the first encrypted data flow of the first service.

[0234] In some embodiments, the first information can be irrelevant to the terminal 101. In some embodiments, the first information sent by the second network element 1032 can be irrelevant to a specific terminal (e.g., the terminal 101). In an example, the first information can be irrelevant to the service of the terminal 101.

[0235] In some embodiments, the first information can be used to determine a QoS policy of a first encrypted data flow of a first task. In an example, the first task can correspond to one or more terminals. In an example, the first task can correspond to a terminal group. In some embodiments, the first encrypted data flow of the first task can be general data.

[0236] In some embodiments, the name of the first information is not limited, which can be, for example, requirement information, indication information, encrypted flow information, encrypted flow requirement information, etc.

[0237] In some embodiments, the first information can include at least one of the following: first support information, priority information, protocol description information. It can be understood that the first information can also include other information, which is not specifically limited in the embodiments of the present disclosure.

[0238] In some embodiments, the first support information can be used to indicate support characteristics for encrypted data flows. In some embodiments, the support characteristics can include support or not, and / or support manner. In some embodiments, the first support information can be used to determine whether support for identification of encrypted data flows is supported. In some embodiments, the first support information can be used to determine support manner for encrypted data flows.

[0239] In some embodiments, the first support information can be used to indicate at least one of: whether support for identification of encrypted data flows is supported; whether support for identification of PDU set information of encrypted data flows is supported; whether support for identification of subflows in multiplexed data flows is supported; whether support for mapping from subflows of encrypted multiplexed data flows to multiple QoS flows is supported; whether support for mapping from subflows of different media types of encrypted multiplexed data flows to multiple QoS flows is supported; whether support for mapping from subflows of different media components of encrypted multiplexed data flows to multiple QoS flows is supported; supported encryption protocols; supported transmission direction of encrypted data flows.

[0240] In some embodiments, the first support information can be used to indicate whether support for identification of encrypted data flows is supported. In some embodiments, the first support information can be used to indicate whether support for identification of encrypted data flows is required. In some embodiments, the first support information can be used to indicate support for identification of encrypted data flows. In some embodiments, support for identification of encrypted data flows can mean support for identification of encrypted data flows using at least one encryption protocol. In some embodiments, the first support information can be used to indicate no support for identification of encrypted data flows. In some embodiments, no support for identification of encrypted data flows can mean no support for identification of encrypted data flows using any encryption protocol.

[0241] In some embodiments, the first support information can use at least one bit to indicate whether support for identification of encrypted data flows is supported. In an example, one bit in the first support information can be used to indicate whether support for identification of encrypted data flows is supported. For example, a first value of the bit can indicate support for identification of encrypted data flows. For example, a second value of the bit can indicate no support for identification of encrypted data flows. In some embodiments, the first support information can use a specific field to indicate whether support for identification of encrypted data flows is supported. In an example, whether support for identification of encrypted data flows is supported can be identified by the presence or absence of the specific field. For example, the presence of the field in the first support information means support for identification of encrypted data flows. For example, the absence of the field in the first support information means no support for identification of encrypted data flows.

[0242] In some embodiments, the first support information can be used to indicate whether support of identification of PDU set information for an encrypted data flow is supported. In some embodiments, the first support information can be used to indicate whether support of identification of PDU set information for an encrypted data flow is required. In some embodiments, the first support information can be used to indicate support of identification of PDU set information for an encrypted data flow. In some embodiments, the first support information can be used to indicate no support of identification of PDU set information for an encrypted data flow.

[0243] In some embodiments, the first support information can indicate whether support of identification of PDU set information for an encrypted data flow using at least one bit. In an example, one bit in the first support information can be used to indicate whether support of identification of PDU set information for an encrypted data flow is supported. For example, a first value of the bit can indicate support of identification of PDU set information for an encrypted data flow. For example, a second value of the bit can indicate no support of identification of PDU set information for an encrypted data flow. In some embodiments, the first support information can indicate whether support of identification of PDU set information for an encrypted data flow using a specific field. In an example, whether support of identification of PDU set information for an encrypted data flow can be identified by the presence or absence of the specific field. For example, the inclusion of the field in the first support information means that support of identification of PDU set information for an encrypted data flow is supported. For example, the absence of the field in the first support information means that no support of identification of PDU set information for an encrypted data flow is supported.

[0244] In some embodiments, the first support information can be used to indicate whether support of identification of subflows in a multiplexed data flow is supported. In some embodiments, the first support information can be used to indicate whether support of identification of subflows in a multiplexed data flow is required. In some embodiments, a multiplexed data flow can include one or more subflows. The subflows in the multiplexed data flow can be multiplexed in the same five-tuple for transmission. Different subflows can have the same or different QoS requirements. In some embodiments, the first support information can be used to indicate support of identification of subflows in a multiplexed data flow. In some embodiments, the first support information can be used to indicate no support of identification of subflows in a multiplexed data flow.

[0245] In some embodiments, the first support information can be used to indicate whether support of identification of sub-streams in multiplexed data streams is required. In an example, a bit in the first support information can be used to indicate whether support of identification of sub-streams in multiplexed data streams is required. For example, a first value of the bit can indicate that support of identification of sub-streams in multiplexed data streams is required. For example, a second value of the bit can indicate that support of identification of sub-streams in multiplexed data streams is not required.

[0246] In some embodiments, support of identification of encrypted data streams and support of identification of sub-streams in multiplexed data streams can be indicated separately. In an example, in the first support information, information used to indicate whether support of identification of encrypted data streams is independent of information used to indicate whether support of identification of sub-streams in multiplexed data streams. In some embodiments, a combination of the two information can be used to indicate whether support of identification of encrypted multiplexed data streams is required.

[0247] In some embodiments, the first support information can be used to indicate whether support of identification of sub-streams in encrypted multiplexed data streams is required. In some embodiments, the first support information can be used to indicate whether support of identification of sub-streams in encrypted multiplexed data streams is required. In some embodiments, the first support information can be used to indicate whether support of identification of sub-streams in encrypted multiplexed data streams is required. In an example, a bit in the first support information can be used to indicate whether support of identification of sub-streams in encrypted multiplexed data streams is required. For example, a first value of the bit can indicate that support of identification of sub-streams in encrypted multiplexed data streams is required. For example, a second value of the bit can indicate that support of identification of sub-streams in encrypted multiplexed data streams is not required. In some embodiments, the first support information can be used to indicate whether support of identification of sub-streams in encrypted multiplexed data streams is required. In an example, a presence or absence of a specific field in the first support information can be used to indicate whether support of identification of sub-streams in encrypted multiplexed data streams is required. For example, inclusion of the field in the first support information can mean that support of identification of sub-streams in encrypted multiplexed data streams is required. For example, absence of the field in the first support information can mean that support of identification of sub-streams in encrypted multiplexed data streams is not required.

[0248] In some embodiments, the first support information can be used to indicate whether mapping of substreams of an encrypted multiplexed data stream to multiple QoS streams is supported. In some embodiments, the first support information can be used to indicate whether mapping of substreams of an encrypted multiplexed data stream to multiple QoS streams is required to be supported. In some embodiments, the mapping of substreams of an encrypted multiplexed data stream to multiple QoS streams can refer to mapping different substreams in the encrypted multiplexed data stream to multiple QoS streams. In some embodiments, the first support information can be used to indicate that mapping of substreams of an encrypted multiplexed data stream to multiple QoS streams is supported. In some embodiments, the first support information can be used to indicate that mapping of substreams of an encrypted multiplexed data stream to multiple QoS streams is not supported.

[0249] In some embodiments, the first support information can use at least one bit to indicate whether mapping of substreams of an encrypted multiplexed data stream to multiple QoS streams is supported. In an example, one bit in the first support information can be used to indicate whether mapping of substreams of an encrypted multiplexed data stream to multiple QoS streams is supported. For example, a first value of the bit can indicate that mapping of substreams of an encrypted multiplexed data stream to multiple QoS streams is supported. For example, a second value of the bit can indicate that mapping of substreams of an encrypted multiplexed data stream to multiple QoS streams is not supported. In some embodiments, the first support information can use a specific field to indicate whether mapping of substreams of an encrypted multiplexed data stream to multiple QoS streams is supported. In an example, whether mapping of substreams of an encrypted multiplexed data stream to multiple QoS streams is supported can be identified by the presence or absence of the specific field. For example, the presence of the field in the first support information means that mapping of substreams of an encrypted multiplexed data stream to multiple QoS streams is supported. For example, the absence of the field in the first support information means that mapping of substreams of an encrypted multiplexed data stream to multiple QoS streams is not supported.

[0250] In some embodiments, the first support information can be used to indicate whether mapping of stream data of different media types of an encrypted multiplexed data stream to multiple QoS streams is supported. In some embodiments, the first support information can be used to indicate whether mapping of stream data of different media types of an encrypted multiplexed data stream to multiple QoS streams is required to be supported. In some embodiments, the first support information can be used to indicate that mapping of stream data of different media types of an encrypted multiplexed data stream to multiple QoS streams is supported. In some embodiments, the first support information can be used to indicate that mapping of stream data of different media types of an encrypted multiplexed data stream to multiple QoS streams is not supported.

[0251] In some embodiments, the media types can include, but are not limited to, video, audio, haptic feedback. In an example, the media types of the stream data in the encrypted multiplexed data stream can be one or more of video, audio, haptic feedback, respectively. The sub-streams with media type of video can carry video data. The sub-streams with media type of audio can carry audio data. The sub-streams with media type of haptic feedback can carry haptic data. In an example, the stream data in the encrypted multiplexed data stream can include at least one of video data, audio data, haptic data.

[0252] In some embodiments, in the encrypted multiplexed data stream, the stream data of different media types can be mixed transmission. For example, the encrypted multiplexed data stream can not be divided into sub-streams.

[0253] In some embodiments, in the encrypted multiplexed data stream, the stream data of different media types can be independently transmitted. For example, the stream data of different media types can be carried in different sub-streams. In this case, the encrypted multiplexed data stream can include sub-streams of different media types.

[0254] In some embodiments, the first support information can be used to indicate whether the mapping from the sub-streams of different media types of the encrypted multiplexed data stream to the plurality of QoS streams is supported. In some embodiments, the first support information can be used to indicate whether the mapping from the sub-streams of different media types of the encrypted multiplexed data stream to the plurality of QoS streams is required to be supported. In some embodiments, the first support information can be used to indicate that the mapping from the sub-streams of different media types of the encrypted multiplexed data stream to the plurality of QoS streams is supported. In some embodiments, the first support information can be used to indicate that the mapping from the sub-streams of different media types of the encrypted multiplexed data stream to the plurality of QoS streams is not supported.

[0255] In some embodiments, the first support information can employ at least one bit to indicate whether the mapping from the sub-streams of different media types of the encrypted multiplexed data stream to the plurality of QoS streams is supported. In some embodiments, the first support information can employ a specific field to indicate whether the mapping from the sub-streams of different media types of the encrypted multiplexed data stream to the plurality of QoS streams is supported.

[0256] In some embodiments, the first support information can be used to indicate whether the mapping from the stream data of different media components of the encrypted multiplexed data stream to the plurality of QoS streams is supported. In some embodiments, the first support information can be used to indicate whether the mapping from the stream data of different media components of the encrypted multiplexed data stream to the plurality of QoS streams is required to be supported. In some embodiments, the first support information can be used to indicate that the mapping from the stream data of different media components of the encrypted multiplexed data stream to the plurality of QoS streams is supported. In some embodiments, the first support information can be used to indicate that the mapping from the stream data of different media components of the encrypted multiplexed data stream to the plurality of QoS streams is not supported.

[0257] In some embodiments, for the same media type, the corresponding stream data can include one or more media components (or simply components). In some embodiments, the stream data of video type can include one or more components. In an example, three-dimensional video data can include two components, i.e., data of a first channel and data of a second channel, and the data of each channel is a video component. The data of the first channel can be, for example, data corresponding to the left eye. The data of the second channel can be, for example, data corresponding to the right eye. In some embodiments, the stream data of audio type can include one or more components. In an example, the audio data can include data of multiple audio channels, and the data of each channel is an audio component.

[0258] In some embodiments, in the encrypted multiplexed data stream, the stream data of different media components can be mixed transmission. For example, the encrypted multiplexed data stream can not be divided into sub-streams.

[0259] In some embodiments, in the encrypted multiplexed data stream, the stream data of different media components can be independently transmitted. For example, the stream data of different media types can be carried in different sub-streams. In this case, the encrypted multiplexed data stream can include sub-streams carrying different media components.

[0260] In some embodiments, the first support information can be used to indicate whether the mapping from the sub-streams of different media components of the encrypted multiplexed data stream to the multiple QoS streams is supported. In some embodiments, the first support information can be used to indicate whether the mapping from the sub-streams of different media components of the encrypted multiplexed data stream to the multiple QoS streams is required to be supported. In some embodiments, the first support information can be used to indicate that the mapping from the sub-streams of different media components of the encrypted multiplexed data stream to the multiple QoS streams is supported. In some embodiments, the first support information can be used to indicate that the mapping from the sub-streams of different media components of the encrypted multiplexed data stream to the multiple QoS streams is not supported.

[0261] In some embodiments, the plurality of sub-streams in the encrypted multiplexed data stream can correspond to different media components. In some embodiments, two or more sub-streams in the encrypted multiplexed data stream can correspond to different components of a video. In an example, three-dimensional video data can include data of a first channel and data of a second channel. The data of the first channel may, for example, be data corresponding to a left eye. The data of the second channel may, for example, be data corresponding to a right eye. The data of the first channel and the data of the second channel can be respectively carried in different sub-streams of the encrypted multiplexed data stream. In some embodiments, two or more sub-streams in the encrypted multiplexed data stream can correspond to different components of audio. In an example, audio data can include data of a plurality of channels, and data of each channel is an audio component. The data of different channels can be respectively carried in different sub-streams of the encrypted multiplexed data stream.

[0262] In some embodiments, the first support information can indicate, using at least one bit, whether mapping from sub-streams of different media types of the encrypted multiplexed data stream to the plurality of QoS streams is supported. In some embodiments, the first support information can indicate, using a specific field, whether mapping from sub-streams of different media types of the encrypted multiplexed data stream to the plurality of QoS streams is supported.

[0263] In some embodiments, the first support information can be used to indicate a supported encryption protocol. In some embodiments, the first support information can be used to indicate a required encryption protocol. In some embodiments, the first support information can indicate one or more encryption protocols.

[0264] In some embodiments, the encryption protocol can include at least one of: media over QUIC transport (MOQT) based on quick UDP internet connections (QUIC), multiplexed application substrate over QUIC encryption (MASQUE) based on QUIC, extended user datagram protocol (UDP), N6 tunnel. It can be understood that the encrypted data stream can also use other encryption protocols, which are not specifically limited by the embodiments of the present disclosure.

[0265] In some embodiments, the MASQUE protocol can include Proxy-UDP-in-HTTP / 3.

[0266] In some embodiments, the MASQUE protocol can include QUIC proxying. In an example, the MASQUE protocol can be QUIC-aware proxying.

[0267] In some embodiments, the extended UDP can be a UDP option. In an example, the extended UDP can include RTP over QUIC (RoQ). Here, RTP is real-time transport protocol. In an example, the extended UDP can include obfuscated (OFC) metadata.

[0268] In some embodiments, the N6 tunnel can be pre-configured. In an example, the pre-configured N6 tunnel can employ a user plane part of general packet radio service tunneling protocol (GTP-U) protocol.

[0269] In some embodiments, the first support information can be used to indicate a transmission direction of the supported encrypted data flow. In some embodiments, the transmission direction can include uplink and downlink. In an example, the first support information can be used to indicate an identification of the encrypted data flow that supports uplink. In an example, the first support information can be used to indicate an identification of the encrypted data flow that supports downlink. In an example, the first support information can be used to indicate an identification of the encrypted data flow that supports uplink and downlink.

[0270] It should be noted that the first support information can further include other information, which is not limited in the embodiments of the present disclosure.

[0271] In some embodiments, the priority information can be used to determine a priority of the encrypted data flow.

[0272] In some embodiments, the priority information can be related to at least one of the following: an encryption protocol, a service, a network deployment, a network function.

[0273] In some embodiments, the priority information can be used to indicate a priority between encrypted data flows that employ different encryption protocols. In other words, the priority information can be used to indicate a priority between different encryption protocols.

[0274] In some embodiments, the priority information can be used to indicate a priority of all possible encryption protocols.

[0275] In some embodiments, the priority information can be used to indicate the priority of the supported encryption protocol indicated by the first support information.

[0276] In some embodiments, the priority between different encryption protocols can be the same or different.

[0277] In some embodiments, the priority information can be used to indicate the priority between MOQT, MASQUE, extended UDP, N6 tunnel. In an example, in order of priority from high to low, it can be MOQT, MASQUE protocol, extended UDP, N6 tunnel. It can be understood that different encryption protocols can also have other priority orders, and the embodiments of the present disclosure do not make specific limitations thereto.

[0278] In some embodiments, the priority information can be related to the service. In some embodiments, the priority of the encryption protocol can be related to the service. In some embodiments, the priority of the encryption protocol can be different for different service scenarios.

[0279] In some embodiments, the priority information can be related to the network deployment. In some embodiments, the priority of the encryption protocol can be related to the network deployment. In some embodiments, the priority of the encryption protocol can be different for different network deployment scenarios.

[0280] In some embodiments, the priority information can be related to the network function. In some embodiments, the priority of the encryption protocol can be related to the network deployment. In some embodiments, the priority of the encryption protocol can be different for different network functions. In some embodiments, different network functions can have different support capabilities for encryption protocols. In an example, the priority information can be related to the support capability of the fifth network element 1035 for the encryption protocol. For example, the fifth network element 1035 can only support one encryption protocol, and the supported encryption protocol can have the highest priority. For example, the fifth network element 1035 can support at least two encryption protocols, and the supported encryption protocol can have a higher priority.

[0281] In some embodiments, the priority information can also include other information, and the embodiments of the present disclosure do not make specific limitations thereto.

[0282] In some embodiments, the protocol description information can be used to describe the related protocol of the first encrypted data flow.

[0283] In some embodiments, the protocol description information can be referred to as protocol description.

[0284] In some embodiments, the protocol description information can be used to describe an encryption protocol and / or a transmission protocol related to the first encrypted data stream.

[0285] In some embodiments, the protocol description information can comprise at least one of the following: a protocol type, a codec type, a media type.

[0286] In some embodiments, the first information can be sent by the second network element 1032 to the sixth network element 1036 through a service-based interface Nnef.

[0287] In some embodiments, the first information can be carried in a request message.

[0288] In some embodiments, the request message carrying the first information can be a message in an Nnef_AFsessionWithQoS service. In an example, the request message can be a message in an Nnef_AFsessionWithQoS_Create service operation (or procedure). In an example, the request message can be a message in an Nnef_AFsessionWithQoS_Update service operation (or procedure).

[0289] In some embodiments, the request message can be an AF session resource request message. In an example, the AF session resource request message can be an Nnef_AFSessionWithQoS_Create request message or an Nnef_AFSessionWithQoS_Update request message.

[0290] In some embodiments, the request message can further comprise service information of the first service.

[0291] In some embodiments, the first service can be an XRM service, an interactive media type service, etc. It can be understood that the first service can also be other services, which are not limited specifically in the embodiments of the present disclosure.

[0292] In some embodiments, the service information of the first service can comprise at least one of the following: an identifier of the first service, an address and / or an identifier of the terminal 101, an identifier of the second network element 1032, an AF service identifier, an external application identifier, a flow description, a data network name (DNN), single network slice selection assistance information (S-NSSAI), a QoS parameter. It can be understood that the service information of the first service can also comprise other information, which is not limited specifically in the embodiments of the present disclosure.

[0293] In some embodiments, the first service ID can be used to identify a data flow or a group of data flows of the first service. In some embodiments, the first service ID can be a multi-modal service ID, and the multi-modal service ID can be used to identify all data flows in a group of services. In some embodiments, the data flow or the group of data flows of the first service can be a service data flow or a group of service data flows.

[0294] In step S2102, the sixth network element 1036 performs authorization.

[0295] In some embodiments, the sixth network element 1036 can authorize the request message from the second network element 1032.

[0296] In some embodiments, the second network element 1032 can be untrusted. In this case, the request message can be sent by the sixth network element 1036 to the first network element 1031.

[0297] In some embodiments, the sixth network element 1036 can perform mapping.

[0298] In some embodiments, the sixth network element 1036 can implement mapping between the first service and the DNN and / or S-NSSAI. In an example, the sixth network element 1036 can map the AF service ID of the first service to the DNN and / or S-NSSAI. In an example, the sixth network element 1036 can map the external application ID to the application ID known in the core network.

[0299] In some embodiments, the sixth network element 1036 can implement mapping between the external ID and the internal ID of the terminal 101. In an example, the sixth network element 1036 can map the ID of the terminal 101 outside the core network to the ID of the terminal 101 inside the core network based on subscription information. In an example, the subscription information can be obtained from a unified data management (UDM).

[0300] In some embodiments, the sixth network element 1036 can implement mapping between the external group ID and the internal group ID of the first service. In an example, the sixth network element 1036 can map the group ID of the first service outside the core network to the group ID of the first service inside the core network based on subscription information. In an example, the subscription information can be obtained from a UDM.

[0301] In step S2103, the sixth network element 1036 sends the first information to the first network element 1031.

[0302] In some embodiments, the sixth network element 1036 can send the first information received from the second network element 1032 to the first network element 1031.

[0303] In some embodiments, the first network element 1031 can receive the first information.

[0304] In some embodiments, the sixth network element 1036 can send the first information in different ways. In some embodiments, the sixth network element 1036 can determine the way of sending the first information according to the information and / or parameters received from the second network element 1032.

[0305] In some embodiments, the way of the sixth network element 1036 sending the first information can include sending through a time sensitive communication and time synchronization function (TSCTSF), sending directly.

[0306] In some embodiments, the sixth network element 1036 can determine to send the first information to the first network element 1031 through the TSCTSF. In some embodiments, the sixth network element 1036 can send the first information to the TSCTSF through a service-based interface Ntsftsf, and then the TSCTSF can send the first information to the first network element 1031 through a service-based interface Npcf. In an example, the sixth network element 1036 can send the first information to the TSCTSF through a Ntsctsf_QoSandTSCAssistance_Create request message or a Ntsctsf_QoSandTSCAssistance_Update request message, and then the TSCTSF can send the first information to the first network element 1031 through a Npcf_PolicyAuthorization_Create request message or a Npcf_PolicyAuthorization_Update request message.

[0307] In some embodiments, the sixth network element 1036 can determine to send the first information to the first network element 1031 directly. In some embodiments, the sixth network element 1036 can send the first information to the first network element 1031 through a service-based interface Npcf. In an example, the sixth network element 1036 can send the first information to the first network element 1031 through a Npcf_PolicyAuthorization_Create request message or a Npcf_PolicyAuthorization_Update request message.

[0308] It can be understood that, through steps S2101 to S2103, the first network element 1031 can obtain the first information from the fourth network element 1034. In some embodiments, the first network element 1031 can obtain the first information through other manners. At this time, steps S2101 to S2103 can be omitted. For example, the first network element 1031 can determine the first information based on operator operation and management configuration and / or local configuration.

[0309] In step S2104, the first network element 1031 performs a policy decision.

[0310] In some embodiments, the first network element 1031 can perform the policy decision to determine the first rule.

[0311] In some embodiments, step S2104 can include that the first network element 1031 authorizes the first information. In some embodiments, the first network element 1031 can authorize the first information sent by the fourth network element 1034 received through the sixth network element 1036.

[0312] In some embodiments, after authorization through, the first network element 1031 can determine the first rule.

[0313] In some embodiments, the first rule can be used for traffic mapping of an encrypted data flow of the first service.

[0314] In some embodiments, the first rule can be a policy and charging control (PCC) rule. In some embodiments, the first rule can belong to the PCC rule.

[0315] In some embodiments, the first rule can be a new rule.

[0316] In some embodiments, the first rule can be an updated rule.

[0317] In some embodiments, in the process of determining the first rule, the first network element 1031 can consider the first information.

[0318] In some embodiments, the first information can be determined on the basis of considering the first information.

[0319] In some embodiments, the name of the first rule is not limited, which can be, for example, a traffic mapping policy, a traffic mapping rule, a traffic mapping relationship.

[0320] In some embodiments, in step S2104, the first network element 1031 can determine second information.

[0321] In some embodiments, the second information can be used to implement QoS processing on the first encrypted data flow.

[0322] In some embodiments, the name of the second information is not limited, which can be, for example, policy information, rule information, etc.

[0323] In some embodiments, the second information can be contained in the first rule. It can be understood that in some cases, the second information can be independent of the first rule.

[0324] In some embodiments, the second information can include at least one of the following: second support information, priority information, protocol description information, address information.

[0325] In some embodiments, the second support information can be used to indicate support for encrypted data flow.

[0326] In some embodiments, the second support information can be used to indicate at least one of the following: support for identification of encrypted data flow; support for identification of packet data unit (PDU) set information of encrypted data flow; support for identification of sub-flow in multiplexed data flow; support for mapping from sub-flow of encrypted multiplexed data flow to multiple QoS flows; support for mapping from flow data of different media types of encrypted multiplexed data flow to multiple QoS flows; support for mapping from flow data of different media components of encrypted multiplexed data flow to multiple QoS flows; supported encryption protocol; supported transmission direction of encrypted data flow.

[0327] In some embodiments, the second support information can be used to indicate support for identification of encrypted data flow. In some embodiments, the second support information can be used to indicate the need to support identification of encrypted data flow.

[0328] In some embodiments, the second support information can be used to indicate support for identification of packet data unit (PDU) set information of encrypted data flow. In some embodiments, the second support information can be used to indicate the need to support identification of packet data unit (PDU) set information of encrypted data flow.

[0329] In some embodiments, the second support information can be used to indicate support for identification of sub-flow in multiplexed data flow. In some embodiments, the second support information can be used to indicate the need to support identification of sub-flow in multiplexed data flow.

[0330] In some embodiments, the second support information can be used to indicate support for mapping from sub-flow of encrypted multiplexed data flow to multiple QoS flows. In some embodiments, the second support information can be used to indicate the need to support mapping from sub-flow of encrypted multiplexed data flow to multiple QoS flows.

[0331] In some embodiments, the second support information can be used to indicate support of mapping of stream data from different media types of the encrypted multiplexed data stream to the plurality of QoS flows. In some embodiments, the second support information can be used to indicate need of support of mapping of stream data from different media types of the encrypted multiplexed data stream to the plurality of QoS flows.

[0332] In some embodiments, the second support information can be used to indicate support of mapping of stream data from different media components of the encrypted multiplexed data stream to the plurality of QoS flows. In some embodiments, the second support information can be used to indicate need of support of mapping of stream data from different media components of the encrypted multiplexed data stream to the plurality of QoS flows.

[0333] In some embodiments, the second support information can be used to indicate supported encryption protocols. In an example, the second support information can be used to indicate one or more encryption protocols supported. For example, the second support information can be used to indicate at least one of MOQT, MASQUE, extended UDP, N6 tunnel.

[0334] In some embodiments, the second support information can be used to indicate supported transmission direction of encrypted data stream. In some embodiments, the transmission direction indicated by the second support information can comprise one of: uplink, downlink, uplink and downlink.

[0335] In some embodiments, the priority information in the second information can be the same as or different from the priority information in the first information. For example, the priority information in the second information can be exactly the same as the priority information in the first information. For example, the priority information in the second information can be different from the priority information in the first information. For example, the priority information in the second information can be determined based on the priority information in the first information. For example, the priority information in the second information can be determined based on the priority information in the first information, and taking into account at least one of network deployment, network function, operator configuration, local configuration.

[0336] In some embodiments, the protocol description information in the second information can be the same as or different from the protocol description information in the first information.

[0337] In some embodiments, the address information can be used to indicate an address of the fourth network element 1034 related to the first service. Through the address information, communication can be performed with the fourth network element 1034. In an example, the fourth network element 1034 can be an AS, and the address information can be an AS address.

[0338] It can be understood that the second information can further include other information, which is not specifically limited in the embodiments of the present disclosure.

[0339] In some embodiments, the second information can further include subscription information.

[0340] In some embodiments, the subscription information can be used for event subscription related to the first encrypted data flow.

[0341] In some embodiments, the subscription information can be used for requesting reporting or notification for the event.

[0342] In some embodiments, the event subscribed by the subscription information can comprise at least one of: data flow change, data flow parameter change.

[0343] In some embodiments, the data flow change can comprise increase, decrease, etc. of the data flow.

[0344] In some embodiments, the data flow parameter change can comprise change of parameter value of the data flow.

[0345] In step S2105, the first network element 1031 sends a response message to the sixth network element 1036.

[0346] In some embodiments, the sixth network element 1036 can receive the response message.

[0347] In some embodiments, the first network element 1031 can send the response message after receiving the first information.

[0348] In some embodiments, the response message can carry authorization result of the first network element 1031 on the first information. In an example, the response message can indicate that the first information passes the authorization or fails the authorization.

[0349] In some embodiments, the response message can be a Npcf_PolicyAuthorization_Create response message or a Npcf_PolicyAuthorization_Update response message.

[0350] In step S2106, the sixth network element 1036 sends a response message to the second network element 1032.

[0351] In some embodiments, the second network element 1032 can receive the response message.

[0352] In some embodiments, the sixth network element 1036 can send the response message to the second network element 1032 after receiving the response message from the first network element 1031.

[0353] In some embodiments, the response message can carry authorization result of the first network element 1031 on the first information. In an example, the response message can indicate that the first information passes the authorization or fails the authorization.

[0354] In some embodiments, the response message can be an Nnef_AFSessionWithQoS_Create response message or an Nnef_AFSessionWithQoS_Update response message.

[0355] In step S2107, the first network element 1031 sends second information to the third network element 1033.

[0356] In some embodiments, the third network element 1033 can receive the second information.

[0357] In some embodiments, the second information can be used by the third network element 1033 to determine a second rule.

[0358] In some embodiments, the second information can be sent to the third network element 1033 through a service-based interface Npcf.

[0359] In some embodiments, the first network element 1031 can initiate an SM policy association modification (SM Policy Association Modification) procedure to send the second information. In some embodiments, the second information can be carried in an Npcf_SMPolicyControl_UpdateNotify request message.

[0360] In step S2108, the third network element 1033 determines a QoS rule.

[0361] In some embodiments, the third network element 1033 can determine the second rule after receiving the second information.

[0362] In some embodiments, the second rule can be determined based on the second information.

[0363] In some embodiments, the second rule can be QoS rules. In some embodiments, the second rule can belong to QoS rules.

[0364] In some embodiments, the second rule can include N4 rules. In some embodiments, the second rule can include a packet detection rule (PDR).

[0365] In some embodiments, in step S2108, the third network element 1033 can determine fourth information.

[0366] In some embodiments, the fourth information can be used by the fifth network element 1035 for QoS processing of the first encrypted data stream.

[0367] In some embodiments, the name of the fourth information is not limited, which can be, for example, rule information, indication information, configuration information, and the like.

[0368] In some embodiments, the fourth information can include at least one of the following: encryption protocol information, policy information, protocol description information, address information.

[0369] In some embodiments, the encryption protocol information can be used to indicate at least one encryption protocol. The encryption protocol indicated by the encryption protocol information can be an encryption protocol processed by the fifth network element 1035. In other words, the encryption protocol information can be used for the fifth network element 1035 to process the first encrypted data stream of the indicated encryption protocol.

[0370] In some embodiments, the encryption protocol information can indicate at least one of the following: MOQT, MASQUE, extended UDP, N6 tunnel.

[0371] In some embodiments, the policy information can be used to indicate a QoS processing policy related to the first encrypted data stream.

[0372] In some embodiments, the encryption protocol information and / or the policy information can be determined based at least on the second information. In an example, the encryption protocol information and / or the policy information can be determined based on the second information, and in consideration of the S-NSSAI and / or the DNN.

[0373] In some embodiments, the protocol description information and the address information can be obtained from the second information. In an example, the protocol description information and the address information in the fourth information can be the same as the protocol description information and the address information in the second information.

[0374] In some embodiments, the second information can not contain the address information. In this case, the third network element 1033 can obtain the address information in other ways. In some embodiments, the address information can be pre-configured in the third network element 1033. In some embodiments, the address information can be contained in the operation administration and management (OAM) configuration of the third network element 1033.

[0375] It can be understood that the fourth information can also include other information, which is not specifically limited in the embodiments of the present disclosure.

[0376] In some embodiments, the fourth information can also include subscription information. In an example, the subscription information in the fourth information can be the same as the subscription information in the second information. In an example, the subscription information in the fourth information can be determined based on the subscription information in the second information.

[0377] In some embodiments, the fourth information can further comprise a QoS parameter.

[0378] In some embodiments, the fourth information can be carried in the second rule. In some embodiments, the fourth information can be independent of the second rule.

[0379] In step S2109, the third network element 1033 sends a response message to the first network element 1031.

[0380] In some embodiments, the first network element 1031 can receive the response message.

[0381] In some embodiments, the third network element 1033 can send the response message after receiving the second information.

[0382] In some embodiments, the third network element 1033 can send the response message after determining the QoS rule.

[0383] In some embodiments, the response message can be an Npcf_SMPolicyControl_UpdateNotify response message.

[0384] In step S2110, the third network element 1033 sends fourth information to the fifth network element 1035.

[0385] In some embodiments, the fifth network element 1035 can receive the fourth information.

[0386] In some embodiments, the third network element 1033 can send the second rule to the fifth network element 1035. The second rule can contain the fourth information.

[0387] In some embodiments, the third network element 1033 can send the fourth information and the second rule to the fifth network element 1035. The fourth information can be independent of the second rule, for example.

[0388] In some embodiments, the third network element 1033 can send the fourth information through an N4 session.

[0389] In some embodiments, the fourth information can be carried in an N4 Session Modification request message.

[0390] In step S2111, the fifth network element 1035 sends a response message to the third network element 1033.

[0391] In some embodiments, the third network element 1033 can receive the response message.

[0392] In some embodiments, after receiving the fourth message, the fifth network element 1035 can send a response message.

[0393] In some embodiments, the response message can be an N4 Session Modification response message.

[0394] In step S2112, the third network element 1033 sends sixth information to the seventh network element 1037.

[0395] In some embodiments, the seventh network element 1037 can receive the sixth information.

[0396] In some embodiments, the sixth information can be used to indicate QoS related information.

[0397] In some embodiments, the sixth information can be used for QoS processing of the first encrypted data flow of the first service by the first device 102.

[0398] In some embodiments, the sixth information can include at least one of: encryption protocol information, policy information, protocol description information. The description of the sixth information can refer to the fourth information, which is not repeated here.

[0399] In some embodiments, the third network element 1033 can send the sixth information to the fifth network element 1035 through the Namf_Communication_N1N2MessageTransfer service operation.

[0400] In some embodiments, in the Namf_Communication_N1N2MessageTransfer service operation, the third network element 1033 can send a Namf_Communication_N1N2MessageTransfer request message to the fifth network element 1035, and the fifth network element 1035 can send a Namf_Communication_N1N2MessageTransfer response message to the third network element 1033. The sixth information can be carried in the Namf_Communication_N1N2MessageTransfer request message.

[0401] In some embodiments, through the Namf_Communication_N1N2MessageTransfer service operation, the third network element 1033 can also send at least one of: N2SM information, PDU session identifier, QoS flow identifier (QFI), QoS profile, N1SM container.

[0402] In step S2113, the seventh network element 1037 sends sixth information to the first device 102.

[0403] In some embodiments, the first device 102 can receive the sixth information.

[0404] In some embodiments, the fifth network element 1035 can send the sixth information to the first device 102 through an N2 message.

[0405] In some embodiments, the N2 message can be an N2 PDU session request message.

[0406] In some embodiments, the N2 message can further include at least one of: an N2 SM information, a NAS message.

[0407] In some embodiments, the NAS message can include at least one of: a PDU session identifier, an N1 SM container.

[0408] In some embodiments, the N1 SM container can include a PDU Session Modification Command.

[0409] In step S2114, the first device 102 interacts with the terminal 101.

[0410] In some embodiments, the first device 102 can establish wireless resources with the terminal 101.

[0411] In some embodiments, the first device 102 can send AN dedicated signaling to exchange information with the terminal 101.

[0412] In some embodiments, the first device 102 can send the received sixth information to the terminal 101 for the terminal 101 to process the QoS of the first encrypted data stream of the first service.

[0413] In some embodiments, the first device 102 can further send the received N2 SM information and / or NAS message to the terminal 101.

[0414] In some embodiments, the sixth information enables the terminal 101 and the first device 102 to establish wireless resources associated with the QoS rule.

[0415] In step S2115, the first device 102 sends an N2 message to the seventh network element 1037.

[0416] In some embodiments, the fifth network element 1035 can receive an acknowledgement (ACK) message.

[0417] In some embodiments, the first device can send an acknowledgment message to the fifth network element 1035 through an N2 message.

[0418] In some embodiments, the acknowledgment message can be used to indicate an acknowledgment of the N2 PDU session request message.

[0419] In some embodiments, the acknowledgment message can be an N2 PDU session acknowledgment message.

[0420] In some embodiments, the N2 SM information can be carried in the acknowledgment message.

[0421] In step S2116, the seventh network element 1037 sends a request message to the third network element 1033.

[0422] In some embodiments, the third network element 1033 can receive the request message.

[0423] In some embodiments, the request message can include N2 SM information.

[0424] In some embodiments, the fifth network element 1035 can send the request message to the third network element 1033 through an Nsmf_PDUSession_UpdateSMContext service operation.

[0425] In some embodiments, the request message can be an Nsmf_PDUSession_UpdateSMContext request message.

[0426] In step S2117, the third network element 1033 sends a response message to the seventh network element 1037.

[0427] In some embodiments, the seventh network element 1037 can receive the response message.

[0428] In some embodiments, the response message can be an Nsmf_PDUSession_UpdateSMContext response message.

[0429] In step S2118, the third network element 1033 sends a request message to the fifth network element 1035.

[0430] In some embodiments, the fifth network element 1035 can receive the request message.

[0431] In some embodiments, the third network element 1033 can send the request message to the fifth network element 1035 through an N4 session modification service operation.

[0432] In some embodiments, the request message can be an N4 session modification request message.

[0433] In some embodiments, the request can be for updating the N4 session of the fifth network element 1035.

[0434] In step S2119, the fifth network element 1035 sends a response message to the third network element 1033.

[0435] In some embodiments, the third network element 1033 can receive the response message.

[0436] In some embodiments, the response message can be an N4 session modification response message.

[0437] In step S2120, the fourth network element 1034 sends downlink data to the fifth network element 1035.

[0438] In some embodiments, the downlink data sent by the fourth network element 1034 to the fifth network element 1035 can be a first encrypted data stream of the first service.

[0439] In some embodiments, the first encrypted data stream can be a data stream in downlink direction.

[0440] In some embodiments, the first encrypted data stream can be transmitted over user plane.

[0441] In some embodiments, the first encrypted data stream can employ one or more encryption protocols. In an example, the first encrypted data stream can employ at least one of the following encryption protocols: MOQT, MASQUE, extended UDP, N6 tunnel.

[0442] In some embodiments, the first encrypted data stream can be a multiplexed data stream.

[0443] In some embodiments, the first encrypted data stream can comprise one or more sub-streams.

[0444] In some embodiments, the first encrypted data stream can carry data of one or more media types.

[0445] In some embodiments, the first encrypted data stream can carry data of one or more media components.

[0446] In some embodiments, the first encrypted data stream can arrive at the fifth network element 1035 from the fourth network element 1034 via the sixth network element 1036.

[0447] In step S2121, the fifth network element 1035 performs QoS processing on the downlink data.

[0448] In some embodiments, the fifth network element 1035 can perform QoS processing on the first encrypted data stream of the downlink.

[0449] In some embodiments, the fifth network element 1035 can perform traffic mapping on the first encrypted data stream. In some embodiments, the first encrypted data stream can be mapped into one or more QoS flows.

[0450] In some embodiments, the fifth network element 1035 can identify the first encrypted data stream.

[0451] In some embodiments, the fifth network element 1035 can identify the PDU set information of the first encrypted data stream.

[0452] In some embodiments, the first encrypted data stream can be a multiplexed data stream, and include one or more sub-streams. The fifth network element 1035 can identify the sub-streams in the first encrypted data stream.

[0453] In some embodiments, the fifth network element 1035 can map different sub-streams in the first encrypted data stream to multiple QoS flows.

[0454] In some embodiments, the fifth network element 1035 can map stream data of different media types in the first encrypted data stream to multiple QoS flows.

[0455] In some embodiments, the fifth network element 1035 can map stream data of different media components in the first encrypted data stream to multiple QoS flows.

[0456] In some embodiments, through detection and identification of the first encrypted data stream, the fifth network element 1035 can identify (and determine) the PDU set information in the first encrypted data stream.

[0457] In some embodiments, the fifth network element 1035 can determine a priority usage encryption protocol according to the priority information. In an example, the fifth network element 1035 can determine to use a highest priority encryption protocol to identify the first encrypted data stream. For example, MOQT can have the highest priority, then the fifth network element 1035 can preferentially use MOQT to identify the first encrypted data stream. In an example, in a case that the highest priority encryption protocol is invalid, the fifth network element 1035 can determine to use a second highest priority encryption protocol to identify the first encrypted data stream. For example, in a case that MOQT identification fails, the fifth network element 1035 can determine to use MASQUE as the second highest priority encryption protocol to identify the first encrypted data stream. In an example, the fifth network element 1035 can determine a priority usage encryption protocol according to its own support of different encryption protocols. For example, in a case that MOQT has a higher priority than MASQUE, the fifth network element 1035 does not support MOQT, then the fifth network element 1035 can determine MASQUE as the priority usage encryption protocol.

[0458] In some embodiments, the fifth network element 1035 can identify the PDU set information in the first encrypted data flow according to the fourth information.

[0459] In some embodiments, the fifth network element 1035 can identify the PDU set information in the first encrypted data flow according to the OAM configuration and / or operator policy. In an example, the fifth network element 1035 can identify the PDU set information in the first encrypted data flow according to the OAM configuration and / or operator policy without receiving the fourth information. In an example, the fifth network element 1035 can identify the PDU set information in the first encrypted data flow according to the fourth information and the OAM configuration and / or operator policy.

[0460] In some embodiments, the fifth network element 1035 can add the determined PDU set information to the header of the downlink data packet of the first encrypted data flow. In an example, the fifth network element 1035 can add the determined PDU set information to the extension header of the data packet of the first encrypted data flow. In an example, the fifth network element 1035 can add the determined PDU set information to the GTP-U header of the data packet of the first encrypted data flow.

[0461] In some embodiments, the fifth network element 1035 can add the fifth information in the downlink data packet of the first encrypted data flow.

[0462] In some embodiments, the fifth information can be used for the QoS processing of the first encrypted data flow by the first device 102.

[0463] In some embodiments, the fifth information can include at least one of the following: encryption protocol information, policy information, protocol description information.

[0464] In some embodiments, the fifth information can be determined based on the fourth information. In an example, the fifth network element 1035 can determine the fifth information according to the received fourth information.

[0465] In step S2122, the fifth network element 1035 sends the downlink data to the first device 102.

[0466] In some embodiments, the fifth network element 1035 can send the first encrypted data flow to the first device 102.

[0467] In some embodiments, the fifth network element 1035 can send the data packet corresponding to the first encrypted data flow to the first device 102.

[0468] In some embodiments, through step S2122, the fifth network element 1035 can send the fifth information to the first device 102.

[0469] In some embodiments, the data packet corresponding to the first encrypted data stream sent by the fifth network element 1035 can carry the fifth information.

[0470] In some embodiments, the data packet corresponding to the first encrypted data stream sent by the fifth network element 1035 can carry the PDU set information.

[0471] In some embodiments, the first data stream can be sent to the first device 102 using the GTP-U protocol. In an example, the fifth network element 1035 can carry the fifth information in the GTP-U header. In an example, the fifth network element 1035 can carry the PDU set information in the GTP-U header.

[0472] In some embodiments, the PDU information can include at least one of the following: PDU set sequence number, start / end PDU of the PDU set, PDU sequence number within the PDU set, number of PDUs within the PDU set, PDU set importance, PDU set size, end of data burst.

[0473] In step S2123, the first device 102 performs QoS processing on the downlink data.

[0474] In some embodiments, after receiving the first encrypted data stream, the first device 102 can perform QoS processing on the first encrypted data stream.

[0475] In some embodiments, the first device 102 can perform QoS processing according to the fifth information and / or the PDU set information carried in the header of the data packet of the first encrypted data stream.

[0476] In some embodiments, the first device 102 can adjust the QoS parameter according to the fifth information and / or the PDU set information carried in the header of the data packet of the first encrypted data stream.

[0477] In step S2124, the first device 102 sends the downlink data to the terminal 101.

[0478] In some embodiments, the first device 102 can send the first encrypted data stream to the terminal 101 through a radio bearer.

[0479] In step S2125, the terminal 101 performs QoS processing on the uplink data.

[0480] In some embodiments, the terminal 101 can perform QoS processing on the uplink first encrypted data stream.

[0481] In some embodiments, the terminal 101 can perform QoS processing on the uplink data packet of the first encrypted data stream of the first service according to the sixth information.

[0482] In some embodiments, the terminal 101 can perform traffic mapping for the first encrypted data stream. In some embodiments, the first encrypted data stream can be mapped into one or more QoS flows.

[0483] In some embodiments, the terminal 101 can map different sub-streams in the first encrypted data stream to multiple QoS flows.

[0484] In some embodiments, the terminal 101 can map stream data of different media types in the first encrypted data stream to multiple QoS flows.

[0485] In some embodiments, the terminal 101 can map stream data of different media components in the first encrypted data stream to multiple QoS flows.

[0486] In step S2126, the terminal 101 sends uplink data to the fourth network element 1034.

[0487] In some embodiments, the terminal 101 can send the first encrypted data stream to the fourth network element 1034.

[0488] In some embodiments, the terminal can send data packets corresponding to the first encrypted data stream to the fourth network element 1034.

[0489] In some embodiments, the terminal 101 can send data packets of the first encrypted data stream to the fourth network element 1034 via the first device 102 and the fifth network element 1035.

[0490] In some embodiments, the terminal 101 can send the first encrypted data stream to the first device 102 via a radio bearer.

[0491] In step S2127, the fifth network element 1035 performs monitoring.

[0492] In some embodiments, the fifth network element 1035 can perform monitoring for the first encrypted data stream according to the subscription information.

[0493] In some embodiments, the fifth network element 1035 can monitor data stream changes of the first encrypted data stream. In an example, the fifth network element 1035 can monitor an increase of data streams and / or sub-streams in the first encrypted data stream. In an example, the fifth network element 1035 can monitor a decrease of data streams and / or sub-streams in the first encrypted data stream.

[0494] In some embodiments, the fifth network element 1035 can monitor data stream parameter changes of the first encrypted data stream. In an example, the fifth network element 1035 can monitor parameter changes of data streams and / or sub-streams in the first encrypted data stream.

[0495] In some embodiments, the fifth network element 1035 can obtain a monitoring result by monitoring the first encrypted data stream.

[0496] In some embodiments, the monitoring result can include at least one of a measurement value, an event.

[0497] In some embodiments, the measurement value can be a measurement value in the process of the fifth network element 1035 monitoring the first encrypted data stream.

[0498] In some embodiments, the event can be an event determined by the fifth network element 1035 through monitoring.

[0499] In step S2128, the fifth network element 1035 sends third information to the fourth network element 1034.

[0500] In some embodiments, the fourth network element 1034 can receive the third information.

[0501] In some embodiments, the third information can be used to indicate an event related to the first encrypted data stream.

[0502] In some embodiments, the third information can be used to indicate a monitoring result of monitoring the first encrypted data stream.

[0503] In some embodiments, the name of the third information is not limited, which can be, for example, event notification information, reporting information, monitoring information, etc.

[0504] In some embodiments, the third information can be sent in at least one of the following ways: periodically, event triggered.

[0505] In some embodiments, the event triggering the sending of the third information can include at least one of the following: a measurement value meeting a preset threshold, receiving trigger information for the third information.

[0506] In some embodiments, the fifth network element 1035 can send the third information to the fourth network element 1034 in the user plane.

[0507] In some embodiments, the fifth network element 1035 can send the third information to the fourth network element 1034 through the N6 interface.

[0508] Through the above steps S2101 to S2128, the communication method of the embodiments of the present disclosure can be implemented.

[0509] The communication method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2128. For example, step S2101 may be implemented as a standalone embodiment. For example, step S2103 may be implemented as a standalone embodiment. For example, step S2107 may be implemented as a standalone embodiment. For example, step S2109 may be implemented as a standalone embodiment. For example, step S2122 may be implemented as a standalone embodiment. For example, steps S2101 and S2103 may be implemented as standalone embodiments. For example, a combination of steps S2107 and S2109 may be implemented as a standalone embodiment. For example, a combination of steps S2109 and S2122 may be implemented as a standalone embodiment. It should be noted that the possible standalone embodiments consisting of one or more steps S2101 to S2128 are not limited thereto.

[0510] In some embodiments, at least two of steps S2101 to S2128 may be executed in an interchangeable order or simultaneously. For example, steps S2112 and S2121 may be executed in an interchangeable order or simultaneously. For example, steps S2120 and S2126 may be executed in an interchangeable order or simultaneously. For example, steps S2120 and S2127 may be executed in an interchangeable order or simultaneously.

[0511] In some embodiments, steps S2102 to S2128 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0512] In some embodiments, steps S2101, S2102, S2104 to S2128 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0513] In some embodiments, steps S2101 to S2106 and S2108 to S2128 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0514] In some embodiments, steps S2101 to S2108 and S2110 to S2128 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0515] In some embodiments, steps S2101 to S2121 and S2123 to S2128 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0516] In some embodiments, other alternative implementations may be described before or after the specification corresponding to FIG2A.

[0517] Figure 2B is an interactive schematic diagram of the communication method provided according to an embodiment of the present disclosure. The communication method involved in the embodiment of the present disclosure can be applied to the communication system 100. As shown in Figure 2B, the communication method of the embodiment of the present disclosure includes steps S2201 to S2222.

[0518] In step S2201, the second network element 1032 sends the first information to the first network element 1031.

[0519] The optional implementations of step S2201 can be found in the optional implementations of steps S2101, S2102, and S2103 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0520] In some embodiments, the second network element 1032 can send the first information to the first network element 1031 through the sixth network element 1036.

[0521] In some embodiments, the first information may be carried in the request message.

[0522] In some embodiments, the request message carrying the first information may be a message from the Nnef_AFsessionWithQoS service.

[0523] In some embodiments, the request message may also include QoS parameters for the PDU set.

[0524] In some embodiments, the request message may further include protocol description information. In some embodiments, the protocol description information may include information related to the encapsulation protocol between the fifth network element 1035 and the fourth network element 1034. In some embodiments, this information enables the encapsulation protocol connection between the fifth network element 1035 and the fourth network element 1034.

[0525] In some embodiments, protocol description information may be included in the first information.

[0526] In some embodiments, the request message may further include address information of the fourth network element 1034. This address information can be used by the fifth network element 1035 to establish an encapsulation protocol session with the fourth network element 1034.

[0527] In some embodiments, the address information may be included in the first information or may be independent of the first information; this disclosure does not specifically limit this.

[0528] In step S2202, the first network element 1031 sends the second information to the third network element 1033.

[0529] The optional implementation of step S2202 can be found in the optional implementation of step S2107 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0530] In some embodiments, the second information may be carried within the first rule. In one example, the first rule may be a PCC rule.

[0531] In some embodiments, the first rule may be determined at least based on first information.

[0532] In some embodiments, the first rule may be determined taking into account the QoS parameters of the PDU set.

[0533] In some embodiments, the first rule may further include at least one of the following: protocol description information and address information.

[0534] In some embodiments, protocol description information and / or address information may be included in the second information. It is understood that the protocol description information and / or address information may be independent of the second information, and this disclosure does not specifically limit this aspect.

[0535] In step S2203, the third network element 1033 determines the QoS rules.

[0536] The optional implementation of step S2203 can be found in the optional implementation of step S2108 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0537] In some embodiments, the third network element 1033 may determine the second rule after receiving the second information.

[0538] In some embodiments, the second rule may include packet detection rules (PDR). In some embodiments, the second rule may be an N4 rule.

[0539] In some embodiments, packet detection rules may include uplink packet detection rules and downlink packet detection rules.

[0540] In some embodiments, the uplink packet detection rule may include first indication information.

[0541] In some embodiments, the first indication information can be used to instruct the fifth network element 1035 to establish an encapsulation protocol session. The encapsulation protocol session is used for transmitting uplink data of the first encrypted data stream between the fifth network element 1035 and the fourth network element 1034.

[0542] In some embodiments, downlink packet detection rules may include first configuration information.

[0543] In some embodiments, the first configuration information can be used by the fifth network element 1035 to perform PDU set monitoring and extract PDU set information.

[0544] In step S2204, the third network element 1033 sends the fourth information to the fifth network element 1035.

[0545] The optional implementation of step S2204 can be found in the optional implementation of step S2110 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0546] In some embodiments, the third network element 1033 can send fourth information through an N4 session.

[0547] In some embodiments, the third network element 1033 can send a second rule through an N4 session, and the second rule can carry fourth information.

[0548] In some embodiments, the second rule may further include packet detection rules.

[0549] In step S2205, terminal 101 triggers the establishment of a connection.

[0550] In some embodiments, terminal 101 may trigger the establishment of a connection to the fourth network element 1034.

[0551] In some embodiments, an application on terminal 101 is triggered to connect to the corresponding fourth network element 1034. The fourth network element 1034 can provide a first service corresponding to the application.

[0552] In step S2206, terminal 101 sends uplink data to the fifth network element 1035.

[0553] In some embodiments, the fifth network element 1035 can receive uplink data.

[0554] In some embodiments, terminal 101 may send uplink data of the first encrypted data stream of the first service to fifth network element 1035 via first device 102.

[0555] In some embodiments, terminal 101 may send a first encrypted data stream to first device 102 via a wireless bearer.

[0556] In some embodiments, terminal 101 may perform traffic mapping on the first encrypted data stream. In some embodiments, the first encrypted data stream may be mapped to one or more QoS streams.

[0557] In some embodiments, terminal 101 can map different sub-streams in the first encrypted data stream to multiple QoS streams.

[0558] In some embodiments, terminal 101 can map streaming data of different media types in the first encrypted data stream to multiple QoS streams.

[0559] In some embodiments, terminal 101 can map streaming data of different media components in a first encrypted data stream to multiple QoS streams.

[0560] In step S2207, the fifth network element 1035 determines to establish a session.

[0561] In some embodiments, upon receiving an uplink data packet from a first encrypted data stream from terminal 101, the fifth network element 1035 may determine that a session has been established with the fourth network element 1034.

[0562] In some embodiments, the fourth network element 1034 may be a network device for providing a first service corresponding to the first encrypted data stream.

[0563] In some embodiments, the fifth network element 1035 may determine to establish a session with the fourth network element 1034 based on the first indication information in the uplink packet detection rules and the address information.

[0564] In step S2208, the fifth network element 1035 sends a request message to the fourth network element 1034.

[0565] In some embodiments, the fourth network element 1034 may receive request messages.

[0566] In some embodiments, the request message can be used to request the establishment of a session connection from the fourth network element 1034.

[0567] In some embodiments, the request message can be sent via an encapsulation protocol procedure.

[0568] In step S2209, the fourth network element 1034 sends an acknowledgment message to the fifth network element 1035.

[0569] In some embodiments, the fifth network element 1035 can receive confirmation messages.

[0570] In some embodiments, an acknowledgment message may be used to determine that a session connection has been established.

[0571] In step S2210, the fifth network element 1035 processes the uplink data.

[0572] In some embodiments, after receiving the confirmation message, the fifth network element 1035 may encapsulate the uplink data packets of the first encrypted data stream.

[0573] In some embodiments, the fifth network element 1035 can encapsulate uplink data packets within the data packets of the established session connection.

[0574] In step S2211, the fifth network element 1035 sends uplink data to the fourth network element 1034.

[0575] In some embodiments, the fifth network element 1035 can send uplink data of the first encrypted data stream to the fourth network element 1034 through an established session connection.

[0576] In step S2212, data transmission is performed between terminal 101 and the fourth network element 1034.

[0577] In some embodiments, the terminal 101 and the fourth network element 1034 may continue to perform uplink and / or downlink transmission of the first encrypted data stream.

[0578] In some embodiments, the transmission of the first encrypted data stream between terminal 101 and fourth network element 1034 may pass through first device 102 and fifth network element 1035.

[0579] In some embodiments, the fifth network element 1035 can implement QoS mapping of data.

[0580] In step S2213, the fourth network element 1034 determines the PDU set information.

[0581] In some embodiments, the fourth network element 1034 can determine one or more PDUs belonging to the PDU set in the downlink data of the first encrypted data stream, and add the PDU set information to the encapsulation protocol header of the PDU.

[0582] In step S2214, the fourth network element 1034 sends downlink data to the fifth network element 1035.

[0583] The optional implementation of step S2214 can be found in the optional implementation of step S2120 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0584] In step S2215, the fifth network element 1035 performs QoS processing on the downlink data.

[0585] The optional implementation of step S2215 can be found in the optional implementation of step S2121 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0586] In step S2216, the fifth network element 1035 sends the fifth information to the first device 102.

[0587] The optional implementation of step S2216 can be found in the optional implementation of step S2122 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0588] In step S2217, the first device 102 performs QoS processing on the downlink data.

[0589] The optional implementation of step S2217 can be found in the optional implementation of step S2123 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0590] In step S2218, the first device 102 sends downlink data to the terminal 101.

[0591] The optional implementation of step S2218 can be found in the optional implementation of step S2124 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0592] In step S2219, the fifth network element 1035 performs monitoring.

[0593] The optional implementation of step S2219 can be found in the optional implementation of step S2127 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0594] In step S2220, the fifth network element 1035 sends third information to the third network element 1033.

[0595] In some embodiments, the third network element 1033 may receive third information.

[0596] In some embodiments, third information may be used to indicate events associated with the first encrypted data stream.

[0597] In some embodiments, the third information may be used to indicate the monitoring results of monitoring the first encrypted data stream.

[0598] In some embodiments, the name of the third information is not limited, and it may be, for example, event notification information, reporting information, monitoring information, etc.

[0599] In some embodiments, the third information may be sent in at least one of the following ways: periodic sending, event-triggered sending.

[0600] In some embodiments, the event that triggers the transmission of third information may include at least one of the following: the measured value meets a preset threshold, or a trigger message for third information is received.

[0601] In some embodiments, the fifth network element 1035 controls the transmission of third information to the third network element 1033.

[0602] In some embodiments, the fifth network element 1035 can send third information to the third network element 1033 via the N4 interface. In some embodiments, the fifth network element 1035 can send third information to the third network element 1033 via the N4 session.

[0603] In some embodiments, third information can be sent via the service-based interface Nupf.

[0604] In some embodiments, the fifth network element 1035 can trigger an event exposure notification. In some embodiments, the fifth network element 1035 can send a Nupf_EventExposure_Notify message, carrying third information therein.

[0605] In step S2221, the third network element 1033 sends third information to the first network element 1031.

[0606] In some embodiments, the first network element 1031 may receive third information.

[0607] In some embodiments, the third network element 1033 can send third information from the fifth network element 1035 to the first network element 1031.

[0608] In some embodiments, the third network element 1033 can send third information to the first network element 1031 through the N7 interface.

[0609] In step S2222, the first network element 1031 sends third information to the second network element 1032.

[0610] In some embodiments, the second network element 1032 may receive third information.

[0611] In some embodiments, the first network element 1031 can send third information from the third network element 1033 to the second network element 1032.

[0612] In some embodiments, the first network element 1031 can send third information to the second network element 1032 through the sixth network element 1036.

[0613] In some embodiments, the first network element 1031 may send a Nupf_EventExposure_Notify message to the sixth network element 1036, and carry third information therein.

[0614] In some embodiments, the sixth network element 1036 may send an Nnef_EventExposure_Notify message to the second network element 1032, and carry third information therein.

[0615] The communication method of this embodiment can be realized through the above steps S2201 to S2222.

[0616] The communication method involved in the embodiments of this disclosure may include at least one of steps S2201 to S2222. For example, step S2201 may be implemented as a standalone embodiment. For example, step S2202 may be implemented as a standalone embodiment. For example, step S2204 may be implemented as a standalone embodiment. For example, step S2216 may be implemented as a standalone embodiment. For example, steps S2202 and S2204 may be implemented as standalone embodiments. For example, a combination of steps S2204 and S2216 may be implemented as a standalone embodiment. It should be noted that the possible standalone embodiments consisting of one or more steps S2201 to S2222 are not limited thereto.

[0617] In some embodiments, at least two of steps S2201 to S2222 may be executed in an alternate order or simultaneously. For example, steps S2214 and S2219 may be executed in an alternate order or simultaneously.

[0618] In some embodiments, steps S2202 to S2222 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0619] In some embodiments, steps S2201, S2203 to S2222 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0620] In some embodiments, steps S2201 to S2203, S2205 to S2215, and S2217 to S2222 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0621] In some embodiments, other optional implementations may be described before or after the specification corresponding to FIG2B.

[0622] In some embodiments, the names of information, etc., are not limited to the names described in the embodiments. Terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.

[0623] In some embodiments, the terms "uplink", "uplink", and "physical uplink" can be used interchangeably, as can the terms "downlink", "downlink", and "physical downlink", as well as the terms "sidelink", "sidelink", "sidelink communication", "sidelink communication", "direct connection", "direct link", "direct communication", and "direct link communication".

[0624] In some embodiments, the terms “radio”, “wireless”, “radio access network (RAN)”, “access network (AN)”, and “RAN-based” can be used interchangeably.

[0625] In some embodiments, terms such as “moment,” “point in time,” “time,” and “time location” can be used interchangeably, as can terms such as “duration,” “segment,” “time window,” “window,” and “time.”

[0626] In some embodiments, “get,” “obtain,” “receive,” “transmit,” “bidirectional transmission,” and “send and / or receive” can be used interchangeably and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from higher layers, obtaining through self-processing, or autonomous implementation, among other meanings.

[0627] In some embodiments, terms such as “send,” “transmit,” “report,” “distribute,” “transfer,” “bidirectional transmission,” “send and / or receive” can be used interchangeably.

[0628] In some embodiments, terms such as "certain", "preset", "default", "set", "indicated", "a certain", "any", and "first" can be used interchangeably. "Certain A", "preset A", "default A", "set A", "indicated A", "a certain A", "any A", and "first A" can be interpreted as A pre-defined in a protocol or the like, or as A obtained through setting, configuration, or instruction, or as specific A, a certain A, any A, or first A, but are not limited thereto.

[0629] In some embodiments, the determination or judgment can be made by a value represented by 1 bit (0 or 1), or by a true or false value (boolean), or by a comparison of numerical values ​​(e.g., a comparison with a predetermined value), but is not limited thereto.

[0630] In some embodiments, the terms “traffic”, “flow”, “stream”, “sub-stream”, and “data stream” can be used interchangeably.

[0631] In some embodiments, terms such as "service," "business," and "traffic" can be used interchangeably.

[0632] Figure 3A is a schematic flowchart of a communication method provided according to an embodiment of the present disclosure. This disclosure relates to a communication method. The communication method is executed by a first network element 1031. As shown in Figure 3A, the method includes steps S3101 to S3105.

[0633] In step S3101, first information is obtained.

[0634] The optional implementation of step S3101 can be found in the optional implementation of step S2103 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0635] In some embodiments, the first network element 1031 may receive first information sent by the sixth network element 1036, but is not limited thereto, and may also receive first information sent by other entities.

[0636] In step S3102, a strategy decision is made.

[0637] The optional implementation of step S3102 can be found in the optional implementation of step S2104 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0638] In step S3103, a response message is sent.

[0639] The optional implementation of step S3103 can be found in the optional implementation of step S2105 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0640] In some embodiments, the first network element 1031 may send a response message to the sixth network element 1036, but is not limited thereto; it may also send a response message to other entities.

[0641] In step S3104, the second information is sent.

[0642] The optional implementation of step S3104 can be found in the optional implementation of step S2107 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0643] In some embodiments, the first network element 1031 may send second information to the third network element 1033, but is not limited thereto, and may also send second information to other entities.

[0644] In step S3105, a response message is obtained.

[0645] The optional implementation of step S3105 can be found in the optional implementation of step S2108 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0646] In some embodiments, the first network element 1031 may receive a response message sent by the third network element 1033, but is not limited thereto, and may also receive a response message sent by other entities.

[0647] The communication method involved in the embodiments of this disclosure may include at least one of steps S3101 to S3105. For example, step S3101 may be implemented as a standalone embodiment. For example, step S3104 may be implemented as a standalone embodiment. For example, a combination of steps S3101 and S3104 may be implemented as a standalone embodiment. It should be noted that the possible standalone embodiments consisting of one or more steps S3101 to S3105 are not limited thereto.

[0648] In some embodiments, at least two of steps S3101 to S3105 may be executed in an interchangeable order or simultaneously. For example, steps S3103 and S3104 may be executed in an interchangeable order or simultaneously.

[0649] In some embodiments, steps S3102, S3103, S3104, and S3105 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0650] In some embodiments, steps S3101, S3102, S3103, and S3105 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0651] Figure 3B is a schematic flowchart of a communication method provided according to an embodiment of the present disclosure. This disclosure relates to a communication method. The communication method is executed by a first network element 1031. As shown in Figure 3B, the method includes steps S3201 to S3204.

[0652] In step S3201, first information is obtained.

[0653] The optional implementation of step S3201 can be found in the optional implementation of step S2201 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0654] In some embodiments, the first network element 1031 may receive first information sent by the second network element 1032, but is not limited thereto, and may also receive first information sent by other entities.

[0655] In step S3202, the second information is sent.

[0656] The optional implementation of step S3202 can be found in the optional implementation of step S2202 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0657] In some embodiments, the first network element 1031 may send second information to the third network element 1033, but is not limited thereto, and may also send second information to other entities.

[0658] In step S3203, third information is obtained.

[0659] The optional implementation of step S3203 can be found in the optional implementation of step S2221 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0660] In some embodiments, the first network element 1031 may receive third information sent by the third network element 1033, but is not limited thereto, and may also receive third information sent by other entities.

[0661] In step S3204, the third message is sent.

[0662] The optional implementation of step S3204 can be found in the optional implementation of step S2222 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0663] In some embodiments, the first network element 1031 may send third information to the second network element 1032, but is not limited thereto; it may also send third information to other entities.

[0664] The communication method involved in the embodiments of this disclosure may include at least one of steps S3201 to S3204. For example, step S3201 may be implemented as a standalone embodiment. For example, step S3202 may be implemented as a standalone embodiment. For example, a combination of steps S3201 and S3202 may be implemented as a standalone embodiment. It should be noted that the possible standalone embodiments consisting of one or more steps S3201 to S3204 are not limited thereto.

[0665] In some embodiments, steps S3202, S3203, and S3204 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0666] In some embodiments, steps S3201, S3203, and S3204 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0667] Figure 4A is a schematic flowchart of a communication method provided according to an embodiment of the present disclosure. This disclosure relates to a communication method. The communication method is executed by a second network element 1032. As shown in Figure 4A, the method includes steps S4101 to S4102.

[0668] In step S4101, the first information is sent.

[0669] The optional implementation of step S4101 can be found in the optional implementation of step S2101 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0670] In some embodiments, the second network element 1032 may send the first information to the sixth network element 1036, but is not limited thereto; it may also send the first information to other entities.

[0671] In step S4102, a response message is obtained.

[0672] The optional implementation of step S4102 can be found in the optional implementation of step S2106 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0673] In some embodiments, the second network element 1032 may receive a response message sent by the sixth network element 1036, but is not limited thereto, and may also receive a response message sent by other entities.

[0674] The communication method involved in the embodiments of this disclosure may include at least one of steps S4101 to S4102. For example, step S4101 may be implemented as a standalone embodiment. It should be noted that the possible standalone embodiments consisting of one or more steps S4101 to S4102 are not limited thereto.

[0675] In some embodiments, step S4102 is optional and may be omitted or replaced in different embodiments.

[0676] Figure 4B is a schematic flowchart of a communication method provided according to an embodiment of the present disclosure. This disclosure relates to a communication method. The communication method is executed by a second network element 1032. As shown in Figure 4B, the method includes steps S4201 to S4202.

[0677] In step S4201, the first information is sent.

[0678] The optional implementation of step S4201 can be found in the optional implementation of step S2201 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0679] In some embodiments, the second network element 1032 may send first information to the first network element 1031, but is not limited thereto, and may also send first information to other entities.

[0680] In step S4202, third information is obtained.

[0681] The optional implementation of step S4202 can be found in the optional implementation of step S2222 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0682] In some embodiments, the second network element 1032 may receive third information sent by the first network element 1031, but is not limited thereto, and may also receive third information sent by other entities.

[0683] The communication method involved in the embodiments of this disclosure may include at least one of steps S4201 to S4202. For example, step S4201 may be implemented as a standalone embodiment. It should be noted that the possible standalone embodiments consisting of one or more steps S4201 to S4202 are not limited thereto.

[0684] In some embodiments, step S4202 is optional and may be omitted or replaced in different embodiments.

[0685] Figure 5A is a schematic flowchart of a communication method provided according to an embodiment of the present disclosure. This disclosure relates to a communication method. The communication method is executed by a third network element 1033. As shown in Figure 5A, the method includes steps S5101 to S5110.

[0686] In step S5101, the second information is obtained.

[0687] The optional implementation of step S5101 can be found in the optional implementation of step S2107 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0688] In some embodiments, the third network element 1033 may receive second information sent by the first network element 1031, but is not limited thereto, and may also receive second information sent by other entities.

[0689] In step S5102, QoS rules are determined.

[0690] The optional implementation of step S5102 can be found in the optional implementation of step S2108 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0691] In step S5103, a response message is sent.

[0692] The optional implementation of step S5103 can be found in the optional implementation of step S2109 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0693] In some embodiments, the third network element 1033 may send a response message to the first network element 1031, but is not limited thereto; it may also send a response message to other entities.

[0694] In step S5104, the fourth message is sent.

[0695] The optional implementation of step S5104 can be found in the optional implementation of step S2110 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0696] In some embodiments, the third network element 1033 may send fourth information to the fifth network element 1035, but is not limited thereto; it may also send fourth information to other entities.

[0697] In step S5105, a response message is obtained.

[0698] The optional implementation of step S5105 can be found in the optional implementation of step S2111 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0699] In some embodiments, the third network element 1033 may receive a response message sent by the fifth network element 1035, but is not limited thereto, and may also receive a response message sent by other entities.

[0700] In step S5106, the sixth message is sent.

[0701] The optional implementation of step S5106 can be found in the optional implementation of step S2112 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0702] In some embodiments, the third network element 1033 may send the sixth information to the seventh network element 1037, but is not limited thereto; it may also send the sixth information to other entities.

[0703] In step S5107, a request message is obtained.

[0704] The optional implementation of step S5107 can be found in the optional implementation of step S2116 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0705] In some embodiments, the third network element 1033 may receive request messages sent by the seventh network element 1037, but is not limited thereto, and may also receive request messages sent by other entities.

[0706] In step S5108, a response message is sent.

[0707] The optional implementation of step S5108 can be found in the optional implementation of step S2117 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0708] In some embodiments, the third network element 1033 may send a response message to the seventh network element 1037, but is not limited thereto; it may also send a response message to other entities.

[0709] In step S5109, a request message is sent.

[0710] The optional implementation of step S5109 can be found in the optional implementation of step S2118 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0711] In some embodiments, the third network element 1033 may send a request message to the fifth network element 1035, but is not limited thereto; it may also send request messages to other entities.

[0712] In step S5110, a response message is obtained.

[0713] The optional implementation of step S5110 can be found in the optional implementation of step S2119 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0714] The communication method involved in the embodiments of this disclosure may include at least one of steps S5101 to S5110. For example, step S5101 may be implemented as a standalone embodiment. For example, step S5104 may be implemented as a standalone embodiment. For example, a combination of steps S5101 and S5104 may be implemented as a standalone embodiment. It should be noted that the possible standalone embodiments consisting of one or more steps S5101 to S5110 are not limited thereto.

[0715] In some embodiments, steps S5102 to S5110 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0716] In some embodiments, steps S5101 to S5103 and S5104 to S5110 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0717] Figure 5B is a schematic flowchart of a communication method provided according to an embodiment of the present disclosure. This disclosure relates to a communication method. The communication method is executed by a third network element 1033. As shown in Figure 5B, the method includes steps S5201 to S5205.

[0718] In step S5201, the second information is obtained.

[0719] The optional implementation of step S5201 can be found in the optional implementation of step S2202 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0720] In some embodiments, the third network element 1033 may receive second information sent by the first network element 1031, but is not limited thereto, and may also receive second information sent by other entities.

[0721] In step S5202, QoS rules are determined.

[0722] The optional implementation of step S5202 can be found in the optional implementation of step S2203 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0723] In step S5203, the fourth message is sent.

[0724] The optional implementation of step S5203 can be found in the optional implementation of step S2204 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0725] In some embodiments, the third network element 1033 may send fourth information to the fifth network element 1035, but is not limited thereto; it may also send fourth information to other entities.

[0726] In step S5204, third information is obtained.

[0727] The optional implementation of step S5204 can be found in the optional implementation of step S2220 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0728] In some embodiments, the third network element 1033 may receive third information sent by the fifth network element 1035, but is not limited thereto, and may also receive third information sent by other entities.

[0729] In step S5205, the third message is sent.

[0730] The optional implementation of step S5205 can be found in the optional implementation of step S2221 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0731] In some embodiments, the third network element 1033 may send third information to the first network element 1031, but is not limited thereto; it may also send third information to other entities.

[0732] The communication method involved in the embodiments of this disclosure may include at least one of steps S5201 to S5205. For example, step S5201 may be implemented as a standalone embodiment. For example, step S5203 may be implemented as a standalone embodiment. For example, step S5204 may be implemented as a standalone embodiment. For example, step S5205 may be implemented as a standalone embodiment. For example, a combination of steps S5201 and S5203 may be implemented as a standalone embodiment. For example, a combination of steps S5204 and S5205 may be implemented as a standalone embodiment. It should be noted that the possible standalone embodiments consisting of one or more steps S5201 to S5205 are not limited thereto.

[0733] In some embodiments, steps S5202, S5203, S5204, and S5205 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0734] In some embodiments, steps S5201, S5202, S5204, and S5205 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0735] In some embodiments, steps S5201, S5202, S5203, and S5205 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0736] In some embodiments, steps S5201, S5202, S5203, and S5204 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0737] Figure 6A is a schematic flowchart of a communication method provided according to an embodiment of the present disclosure. This disclosure relates to a communication method. The communication method is executed by a fifth network element 1035. As shown in Figure 6A, the method includes steps S6101 to S6110.

[0738] In step S6101, the fourth information is obtained.

[0739] The optional implementation of step S6101 can be found in the optional implementation of step S2110 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0740] In some embodiments, the fifth network element 1035 may receive fourth information sent by the third network element 1033, but is not limited thereto, and may also receive fourth information sent by other entities.

[0741] In step S6102, a response message is sent.

[0742] The optional implementation of step S6102 can be found in the optional implementation of step S2111 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0743] In some embodiments, the fifth network element 1035 may send a response message to the third network element 1033, but is not limited thereto, and may also receive response messages sent by other entities.

[0744] In step S6103, a request message is obtained.

[0745] The optional implementation of step S6103 can be found in the optional implementation of step S2118 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0746] In some embodiments, the fifth network element 1035 may receive request information sent by the third network element 1033, but is not limited thereto, and may also receive fourth information sent by other entities.

[0747] In step S6104, a response message is sent.

[0748] The optional implementation of step S6104 can be found in the optional implementation of step S2119 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0749] In some embodiments, the fifth network element 1035 may send a response message to the third network element 1033, but is not limited thereto, and may also receive response messages sent by other entities.

[0750] In step S6105, downlink data is acquired.

[0751] The optional implementation of step S6105 can be found in the optional implementation of step S2120 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0752] In some embodiments, the fifth network element 1035 may receive downlink data sent by the fourth network element 1034, but is not limited thereto, and may also receive downlink data sent by other entities.

[0753] In step S6106, QoS processing is performed.

[0754] The optional implementation of step S6106 can be found in the optional implementation of step S2121 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0755] In step S6107, the fifth message is sent.

[0756] The optional implementation of step S6107 can be found in the optional implementation of step S2122 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0757] In some embodiments, the fifth network element 1035 may send downlink data to the first device 102, but is not limited thereto, and may also send downlink data to other entities.

[0758] In step S6108, the uplink data is forwarded.

[0759] The optional implementation of step S6108 can be found in the optional implementation of step S2126 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0760] In some embodiments, the fifth network element 1035 may forward uplink data from the first device 102, but is not limited thereto, and may also forward uplink data from other entities.

[0761] In step S6109, monitoring is performed.

[0762] The optional implementation of step S6109 can be found in the optional implementation of step S2127 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0763] In step S6110, the third information is sent.

[0764] The optional implementation of step S6110 can be found in the optional implementation of step S2128 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0765] In some embodiments, the fifth network element 1035 may send third information to the fourth network element 1034, but is not limited thereto; it may also send third information to other entities.

[0766] The communication method involved in the embodiments of this disclosure may include at least one of steps S6101 to S6110. For example, step S6101 may be implemented as a standalone embodiment. For example, step S6107 may be implemented as a standalone embodiment. For example, a combination of steps S6101 and S6107 may be implemented as a standalone embodiment. It should be noted that the possible standalone embodiments consisting of one or more steps S6101 to S6110 are not limited thereto.

[0767] In some embodiments, steps S6102 to S6110 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0768] In some embodiments, steps S6101 to S6106 and S6108 to S6110 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0769] Figure 6B is a schematic flowchart of a communication method provided according to an embodiment of the present disclosure. This disclosure relates to a communication method. This communication method is executed by a fifth network element 1035. As shown in Figure 6B, the method includes steps S6201 to S6213.

[0770] In step S6201, the fourth information is obtained.

[0771] The optional implementation of step S6201 can be found in the optional implementation of step S2204 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0772] In some embodiments, the fifth network element 1035 may receive fourth information sent by the third network element 1033, but is not limited thereto, and may also receive fourth information sent by other entities.

[0773] In step S6202, upstream data is acquired.

[0774] The optional implementation of step S6202 can be found in the optional implementation of step S2206 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0775] In some embodiments, the fifth network element 1035 may receive uplink data sent by the terminal 101, but is not limited thereto, and may also receive uplink data sent by other entities.

[0776] In step S6203, it is determined that a session will be established.

[0777] The optional implementation of step S6203 can be found in the optional implementation of step S2207 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0778] In step S6204, a request message is sent.

[0779] The optional implementation of step S6204 can be found in the optional implementation of step S2208 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0780] In some embodiments, the fifth network element 1035 may send a request message to the fourth network element 1034, but is not limited thereto; it may also send request messages to other entities.

[0781] In step S6205, a confirmation message is obtained.

[0782] The optional implementation of step S6205 can be found in the optional implementation of step S2209 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0783] In some embodiments, the fifth network element 1035 may receive an acknowledgment message sent by the fourth network element 1034, but is not limited thereto, and may also receive an acknowledgment message sent by other entities.

[0784] In step S6206, the upstream data is processed.

[0785] The optional implementation of step S6206 can be found in the optional implementation of step S2210 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0786] In step S6207, uplink data is sent.

[0787] The optional implementation of step S6207 can be found in the optional implementation of step S2211 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0788] In some embodiments, the fifth network element 1035 may send uplink data to the fourth network element 1034, but is not limited thereto, and may also send uplink data to other entities.

[0789] In step S6208, data transmission is performed.

[0790] The optional implementation of step S6208 can be found in the optional implementation of step S2212 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0791] In step S6209, downlink data is acquired.

[0792] The optional implementation of step S6209 can be found in the optional implementation of step S2214 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0793] In some embodiments, the fifth network element 1035 may receive downlink data sent by the fourth network element 1034, but is not limited thereto, and may also receive downlink data sent by other entities.

[0794] In step S6210, QoS processing is performed.

[0795] The optional implementation of step S6210 can be found in the optional implementation of step S2215 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0796] In step S6211, the fifth message is sent.

[0797] The optional implementation of step S6211 can be found in the optional implementation of step S2216 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0798] In some embodiments, the fifth network element 1035 may send fifth information to the first device 102, but is not limited thereto; it may also send fifth information to other entities.

[0799] In step S6212, monitoring is performed.

[0800] The optional implementation of step S6212 can be found in the optional implementation of step S2219 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0801] In step S6213, the third message is sent.

[0802] The optional implementation of step S6213 can be found in the optional implementation of step S2220 in Figure 2B, as well as other related parts in the embodiments involved in Figure 2B, which will not be repeated here.

[0803] In some embodiments, the fifth network element 1035 may send third information to the third network element 1033, but is not limited thereto; it may also send third information to other entities.

[0804] The communication method involved in the embodiments of this disclosure may include at least one of steps S6201 to S6213. For example, step S6201 may be implemented as a standalone embodiment. For example, step S6211 may be implemented as a standalone embodiment. For example, step S6212 may be implemented as a standalone embodiment. For example, step S6213 may be implemented as a standalone embodiment. For example, a combination of steps S6212 and S6213 may be implemented as a standalone embodiment. It should be noted that the possible standalone embodiments consisting of one or more steps S6201 to S6213 are not limited thereto.

[0805] In some embodiments, steps S6202 to S6213 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0806] In some embodiments, steps S6201 to S6210, S6212, and S6213 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0807] In some embodiments, steps S6201 to S6211 and S6213 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0808] In some embodiments, steps S6201 to S6212 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0809] Figure 7 is a flowchart illustrating a communication method provided according to an embodiment of the present disclosure. This disclosure relates to a communication method. The communication method is executed by a first device 102. As shown in Figure 7, the method includes steps S701 to S706.

[0810] In step S701, the sixth information is obtained.

[0811] The optional implementation of step S701 can be found in the optional implementation of step S2113 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0812] In some embodiments, the first device 102 may receive the sixth information sent by the seventh network element 1037, but is not limited thereto, and may also receive the sixth information sent by other entities.

[0813] In step S702, interaction is performed with terminal 101.

[0814] The optional implementation of step S702 can be found in the optional implementation of step S2114 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0815] In step S703, the N2 message is sent.

[0816] The optional implementation of step S703 can be found in the optional implementation of step S2115 in Figure 2A, as well as other related parts in the embodiments involved in Figure 2A, which will not be repeated here.

[0817] In some embodiments, the first device 102 may send an N2 message to the seventh network element 1037, but is not limited thereto; it may also send an N2 message to other entities.

[0818] In step S704, the fifth piece of information is obtained.

[0819] The optional implementation of step S704 can be found in the optional implementation of step S2122 in Figure 2A, step S2216 in Figure 2B, and other related parts in the embodiments involved in Figures 2A and 2B, which will not be repeated here.

[0820] In some embodiments, the first device 102 may receive fifth information sent by the fifth network element 1035, but is not limited thereto, and may also receive fifth information sent by other entities.

[0821] In step S705, QoS processing is performed.

[0822] The optional implementation of step S705 can be found in the optional implementation of step S2123 in Figure 2A, step S2217 in Figure 2B, and other related parts in the embodiments involved in Figures 2A and 2B, which will not be repeated here.

[0823] In step S706, downlink data is sent.

[0824] Optional implementations of step S706 can be found in optional implementations of step S2124 in Figure 2A, step S2218 in Figure 2B, and other related parts in the embodiments involved in Figures 2A and 2B, which will not be repeated here.

[0825] In some embodiments, the first device 102 may send downlink data to the terminal 101, but is not limited thereto, and may also send downlink data to other entities.

[0826] The communication method involved in the embodiments of this disclosure may include at least one of steps S701 to S706. For example, step S7104 may be implemented as a standalone embodiment. It should be noted that the possible standalone embodiments consisting of one or more steps S701 to S706 are not limited thereto.

[0827] In some embodiments, steps S701, S702, S703, S705, and S706 are optional, and one or more of these steps may be omitted or substituted in different embodiments.

[0828] Figure 8A is an interactive schematic diagram of a communication method provided according to an embodiment of the present disclosure. As shown in Figure 8A, the present disclosure relates to a communication method. The communication method includes step S8101.

[0829] In step S8101, the second network element 1032 sends the first information to the first network element 1031.

[0830] Optional implementations of step S8101 can be found in steps S2101 and S2103 of FIG2A, optional implementations of step S2201 of FIG2B, and other related parts in the embodiments involved in FIG2A and FIG2B, which will not be repeated here.

[0831] Figure 8B is an interactive schematic diagram of a communication method provided according to an embodiment of the present disclosure. As shown in Figure 8B, the present disclosure relates to a communication method. The communication method includes step S8201.

[0832] In step S8201, the first network element 1031 sends the second information to the third network element 1033.

[0833] Optional implementations of step S8201 can be found in optional implementations of step S2107 in FIG2A, step S2202 in FIG2B, and other related parts in the embodiments involved in FIG2A and FIG2B, which will not be repeated here.

[0834] Figure 8C is an interactive schematic diagram of a communication method provided according to an embodiment of the present disclosure. As shown in Figure 8C, the present disclosure relates to a communication method. The communication method includes step S8301.

[0835] In step S8301, the third network element 1033 sends the fourth information to the fifth network element 1035.

[0836] Optional implementations of step S8301 can be found in step S2110 of FIG2A, optional implementations of step S2204 of FIG2B, and other related parts in the embodiments involved in FIG2A and FIG2B, which will not be repeated here.

[0837] Figure 8D is an interactive schematic diagram of a communication method provided according to an embodiment of the present disclosure. As shown in Figure 8D, the present disclosure relates to a communication method. The communication method includes step S8401.

[0838] In step S8401, the fifth network element 1035 sends the fifth information to the first device 102.

[0839] Optional implementations of step S8401 can be found in step S2122 of FIG2A, optional implementations of step S2216 of FIG2B, and other related parts in the embodiments involved in FIG2A and FIG2B, which will not be repeated here.

[0840] In the following, specific embodiments of the present disclosure will be described by way of example.

[0841] Figure 9A is an interactive schematic diagram of an exemplary implementation of a communication method provided according to embodiments of the present disclosure. As shown in Figure 9A, the communication method involves an AF session establishment process with a desired QoS and includes multiple steps.

[0842] In some embodiments, the interaction process in FIG9A involves the UE, consumer, first control plane (CP) network function (NF), second CP NF, third CP NF, first user plane (UP) NF, NEF, and DN / AF.

[0843] In some embodiments, the consumer in this embodiment may be the RAN. In some embodiments, the consumer may refer to the object to which the service is targeted. For example, in a service-based scenario, the service may be provided to the consumer. In some embodiments, monitoring and / or reporting information and / or parameters for a first parameter provided by the AF and / or PCF may be provided to the RAN. In this case, the RAN may be considered the consumer. It is understood that the consumer may be device-independent. The object to which the service is provided is the consumer.

[0844] In some embodiments, the first CP NF can be a PCF. In some embodiments, the second CP NF can be an SMF. In some embodiments, the third CP NF can be an AMF. In some embodiments, the first UP NF can be a UPF.

[0845] In step 1, the AF (i.e., the second network element) sends an AF session resource request, for example, by creating an AF request through the Nnef_AFsessionWithQoS_Create request. The AF carries the QoS requirements of XRM service and interactive media service data streams in the request message.

[0846] In some embodiments, the request sent by the AF may be independent of a specific UE. For example, the request sent by the AF may be independent of the service corresponding to the UE. In some embodiments, the request sent by the AF may be a task-based request. In some embodiments, the data that may be included in the task is not only based on a specific UE or a specific service session of the UE, but may be based on a group of UEs, or UE-independent general data used for network functions as consumers.

[0847] In some embodiments, the request and data processing flow may include not only interactions between the control plane and the user plane, but also business processes that include interactions between the data plane.

[0848] In some embodiments, the AF sends an encrypted traffic processing request (i.e., first information) to a network function (e.g., NEF, CAPIF, PCF), which includes a traffic processing support instruction and encrypted traffic assistance information. In some embodiments, the AF may provide an encryption protocol description.

[0849] In some embodiments, the traffic processing support indication and encrypted traffic assistance information include at least one of the following:

[0850] - Does it support the recognition of encrypted streams?

[0851] - Does it support PDU set information identification for encrypted streams?

[0852] - Does it support sub-stream identification of encrypted multiplexed streams? If so, does it further support mapping of sub-streams of encrypted multiplexed streams to multi-QoS streams?

[0853] - Does it support sub-stream identification of encrypted multiplexed streams? If so, does it further support mapping different media types or media components of encrypted multiplexed streams to multiple QoS streams?

[0854] - Does it support multiple encrypted stream recognition mechanisms? Among them, encrypted stream mechanisms include, but are not limited to: Media-over-QUIC; extended UDP, such as RTP-over-QUIC, OFC (similar to hash); MASQUE, such as Proxy-UDP-in-HTTP / 3, QUIC-aware proxying; pre-configured N6 tunnel (GTP-U);

[0855] - When multiple encrypted stream identification mechanisms are supported, the priority of the corresponding encrypted stream mechanism is as follows: for example, Media over QUIC has the highest priority, MASQUE has the second highest priority, extended UDP has the third highest priority, and the pre-configured N6 tunnel has the fourth highest priority.

[0856] - When multiple encrypted stream identification mechanisms are supported, the priority of encrypted stream identification mechanisms for different encryption protocols may be different;

[0857] - When multiple encrypted stream identification mechanisms are supported, the priority of the encrypted stream identification mechanism may be different for different business scenarios;

[0858] - When multiple encrypted stream identification mechanisms are supported, the priority of the encrypted stream identification mechanisms may differ in different network deployment scenarios;

[0859] - When multiple encrypted stream identification mechanisms are supported, the priority of the encrypted stream identification mechanisms for network functions supported by different capabilities may be different; for example, UPF may only support one encrypted stream identification mechanism, or only support one or more low-priority identification mechanisms among multiple encrypted stream identification mechanisms.

[0860] -Supports encrypted stream flow information (DL, UL, DL and UL);

[0861] - When multiple encrypted stream identification directions are supported, and multiple encrypted stream identification mechanisms are used, the selection of encrypted stream mechanisms and priorities for different stream directions are determined.

[0862] In some embodiments, during the AF QoS request / update process, the AF may provide encrypted traffic processing requirements to the NEF / CAPIF (i.e., the sixth network element) / PCF (i.e., the first network element), including traffic processing support instructions and encrypted traffic auxiliary information.

[0863] In some embodiments, XRM service information may be carried, identifying the XRM service data flow or data flow group (e.g., multimodal service ID), UE address / UE identifier, AF identifier, application ID, flow description, DNN, S-NSSAI, QoS parameters, and other corresponding information. Here, the multimodal service ID can be used to identify all flows in the XRM service group.

[0864] In step 2, the NEF authorizes the AF request. If it is an untrusted AF, the NEF sends the AF request to the PCF. (Optionally, the NEF performs relevant mappings, including mapping the XRM service identifier (AF service identifier) ​​to the DNN and S-NSSAI, mapping the external application to the core network application identifier; and mapping the external UE identifier to the core network UE identifier (such as SUPI) based on UDM subscription information, and performing the mapping of the external to internal XRM service group identifier based on the UDM subscription information).

[0865] In step 3, the NEF authorizes the AF request and determines whether to trigger the TSCTSF or directly contact the PCF based on the parameters provided by the AF. These signaling steps can be found in the AF session with required QoS procedure. The PCF receives the attributes provided by the AF from the NEF or TSCTSF. The NEF triggers Npcf_PolicyAuthorization_Create, sending the AF request to the PCF, carrying QoS requirement information for the PCF to make policy decisions.

[0866] In some embodiments, the message sent by the NEF to the PCF carries the encrypted traffic processing requirements of the corresponding SDF, including traffic processing support instructions and encrypted traffic assistance information.

[0867] In step 4, the PCF makes policy decisions. The PCF can determine whether updated or new policy information needs to be sent to the SMF (i.e., the third-party network element).

[0868] In some embodiments, the PCF may determine the PCC rule (i.e., the first rule) taking into account the encrypted traffic processing requirements provided by the AF (including traffic processing support indications and encrypted traffic auxiliary information).

[0869] In some embodiments, the PCF sends authorized encrypted traffic processing information to the SMF via PCC rules. In some embodiments, the authorized encrypted traffic processing information can be sent to the SMF within PCC rules.

[0870] In some embodiments, the authorized encrypted traffic processing information (i.e., the second information) includes at least one of the following:

[0871] -Supports recognition of encrypted streams;

[0872] -Supports identification of PDU set information in encrypted streams;

[0873] - Supports sub-stream identification of encrypted multiplexed streams; if supported, further support for mapping sub-streams of encrypted multiplexed streams to multi-QoS streams;

[0874] - Supports sub-stream identification of encrypted multiplexed streams; if supported, further supports mapping of different media types or media components of encrypted multiplexed streams to multiple QoS streams;

[0875] - Supports multiple encryption stream recognition mechanisms; among which, encryption stream mechanisms include but are not limited to: Media-over-QUIC; extended UDP, such as RTP-over-QUIC, OFC (similar to hash); MASQUE, such as Proxy-UDP-in-HTTP / 3, QUIC-aware proxying; pre-configured N6 tunnel (GTP-U);

[0876] - When multiple encrypted stream identification mechanisms are supported, the priority of the corresponding encrypted stream mechanism is as follows: for example, Media over QUIC has the highest priority, MASQUE has the second highest priority, extended UDP has the third highest priority, and the pre-configured N6 tunnel has the fourth highest priority.

[0877] - When multiple encrypted stream identification mechanisms are supported, the priority of encrypted stream identification mechanisms for different encryption protocols may be different;

[0878] - When multiple encrypted stream identification mechanisms are supported, the priority of the encrypted stream identification mechanism may be different for different business scenarios;

[0879] - When multiple encrypted stream identification mechanisms are supported, the priority of the encrypted stream identification mechanisms may differ in different network deployment scenarios;

[0880] - When multiple encrypted stream identification mechanisms are supported, the priority of the encrypted stream identification mechanisms for network functions supported by different capabilities may be different; for example, UPF may only support one encrypted stream identification mechanism, or only support one or more low-priority identification mechanisms among multiple encrypted stream identification mechanisms.

[0881] -Supports encrypted stream flow information (DL, UL, DL and UL);

[0882] - When multiple encrypted stream identification directions are supported, and multiple encrypted stream identification mechanisms are used, the selection of encrypted stream mechanisms and priorities for different stream directions are determined.

[0883] In some embodiments, the PCF authorizes encrypted traffic processing information, taking into account the encrypted traffic processing requirements provided by the AF, the information stored in the UDR / UDM, operator policies, and received network status information.

[0884] In step 5, in response, PCF sends an Npcf_Policy Authorization_Create response to NEF.

[0885] In step 6, NEF sends an Nnef_AFsessionWithQoS_Create response message to AF, which carries the result to indicate whether the request has been authorized.

[0886] In step 7, the PCF initiates an SM Policy Association Modification request to the SMF, which carries the PCC rules.

[0887] In some embodiments, upon receiving PCC rules, the SMF determines QoS rules and QoS set parameters, taking into account authorized encrypted traffic processing information, to configure and / or activate rules for the UPF (i.e., the fifth network element), for example (via an N4 session).

[0888] In some embodiments, taking into account the indications of S-NSSAI, DNN, and PCF, the SMF determines the encrypted stream identification mechanism (e.g., Media-over-QUIC; Extended UDP; MASQUE; Pre-configured N6 tunnel) and encrypted stream processing policy information (e.g., encrypted traffic processing information). The SMF (e.g., via an N4 session) sends the determined encrypted stream identification mechanism and / or encrypted stream processing policy information to the UPF.

[0889] In some embodiments, the SMF sends the AS address received from the PCF (or configured locally or in OAM) to the UPF, thereby triggering the establishment of a connection with the AS (i.e., the fourth network element) for encrypted traffic processing.

[0890] In step 8, the SMF responds to the PCF with an SM policy association modification response.

[0891] In step 9, the SMF initiates an N4 session modification request to the UPF, which includes: encrypted stream identification mechanism (e.g., Media-over-QUIC; Extended UDP; MASQUE; Pre-configured N6 tunnel), encrypted stream processing policy information (e.g., encrypted traffic processing information), and AS address.

[0892] In step 10, the UPF responds to the SMF.

[0893] In some embodiments, taking into account authorized encrypted traffic processing information (e.g., encrypted flow identification mechanism, encrypted flow processing policy information, encrypted protocol description), the UPF identifies and determines PDU set information (e.g., from metadata) and sends it to the NG-RAN (i.e., the first device) (e.g., in the extended header, GTP-U header). In some embodiments, the UPF sends encrypted traffic processing information (e.g., encrypted flow identification mechanism, encrypted flow processing policy information, encrypted protocol description) to the NG-RAN (e.g., in the extended header, GTP-U header).

[0894] In some embodiments, the UPF determines the encrypted data stream processing category (i.e., encryption protocol) by taking into account encrypted traffic processing information (e.g., encrypted stream identification mechanism, encrypted stream processing policy information, encryption protocol description). In some embodiments, the UPF triggers a connection with the AS using an AS address (e.g., a URI) for the determined encrypted traffic processing. The UPF receives connection establishment from the UE.

[0895] In some embodiments, UPF configuration may be employed. In some embodiments, based on OAM configuration and / or operator policies, and taking into account authorized encrypted traffic processing information and encryption protocol descriptions, the UPF identifies and determines PDU set information and sends it to NG-RAN in an extended header (e.g., in a GTP-U header).

[0896] In step 11, for the modification of the SMF request, the SMF triggers Namf_Communication_N1N2MessageTransfer(N2SM information (PDU session ID, QFI, QoS configuration, N1SM container)).

[0897] In step 12, the AMF (i.e., the seventh network element) can send N2 messages (N2SM information received from the SMF, NAS messages (PDU session ID, N1SM container (PDU session modification command))) to the RAN.

[0898] In step 14, the RAN can acknowledge the N2PDU session request by sending an N2PDU session acknowledgment message to the AMF.

[0899] In step 15, the AMF forwards the N2SM information from the access network to the SMF through the Nsmf_PDUSession_UpdateSMContext service operation.

[0900] In step 16, SMF responds with the Nsmf_PDUSession_UpdateSMContext response.

[0901] In steps 17 and 18, the SMF can update the N4 session of the UPF involved in the PDU session modification by sending an N4 session modification request to the UPF.

[0902] Figure 9B is an interactive schematic diagram of an exemplary implementation of a communication method provided according to embodiments of the present disclosure. As shown in Figure 9B, the communication method involves a general flow for encrypted media data packets supporting PDU set identification and includes multiple steps.

[0903] In step 1, by triggering the Nnef_AfsessionWithQoS_Create service operation, which includes the QoS parameters of the PDU set for XR services, the AF requests the establishment of an AF session with the required QoS.

[0904] In some embodiments, AF may also include the following information: information that enables the UPF and AS to establish an encapsulation protocol connection, and the address of the server that enables the UPF to establish an encapsulation protocol session with.

[0905] In some embodiments, the AF sends encrypted traffic processing requests to network functions (e.g., NEF, PCF), including traffic processing support instructions and encrypted traffic assistance information. In some embodiments, the AF may provide an encryption protocol description.

[0906] In some embodiments, the traffic processing support indication and encrypted traffic assistance information include at least one of the following:

[0907] - Does it support the recognition of encrypted streams?

[0908] - Does it support PDU set information identification for encrypted streams?

[0909] - Does it support sub-stream identification of encrypted multiplexed streams? If so, does it further support mapping of sub-streams of encrypted multiplexed streams to multi-QoS streams?

[0910] - Does it support sub-stream identification of encrypted multiplexed streams? If so, does it further support mapping different media types or media components of encrypted multiplexed streams to multiple QoS streams?

[0911] - Does it support multiple encrypted stream recognition mechanisms? Among them, encrypted stream mechanisms include, but are not limited to: Media-over-QUIC; extended UDP, such as RTP-over-QUIC, OFC (similar to hash); MASQUE, such as Proxy-UDP-in-HTTP / 3, QUIC-aware proxying; pre-configured N6 tunnel (GTP-U);

[0912] - When multiple encrypted stream identification mechanisms are supported, the priority of the corresponding encrypted stream mechanism is as follows: for example, Media over QUIC has the highest priority, MASQUE has the second highest priority, extended UDP has the third highest priority, and the pre-configured N6 tunnel has the fourth highest priority.

[0913] - When multiple encrypted stream identification mechanisms are supported, the priority of encrypted stream identification mechanisms for different encryption protocols may be different;

[0914] - When multiple encrypted stream identification mechanisms are supported, the priority of the encrypted stream identification mechanism may be different for different business scenarios;

[0915] - When multiple encrypted stream identification mechanisms are supported, the priority of the encrypted stream identification mechanisms may differ in different network deployment scenarios;

[0916] - When multiple encrypted stream identification mechanisms are supported, the priority of the encrypted stream identification mechanisms for network functions supported by different capabilities may be different; for example, UPF may only support one encrypted stream identification mechanism, or only support one or more low-priority identification mechanisms among multiple encrypted stream identification mechanisms.

[0917] -Supports encrypted stream flow information (DL, UL, DL and UL);

[0918] - When multiple encrypted stream identification directions are supported, and multiple encrypted stream identification mechanisms are used, the selection of encrypted stream mechanisms and priorities for different stream directions can be considered. For example, the supported mechanisms for uplink and downlink encrypted streams can be the same or different; the priorities of the supported mechanisms for uplink and downlink encrypted streams can be the same or different.

[0919] In step 2, PCF creates PCC rules taking into account the QoS parameters of the PDU set. The PCC rules also include encapsulation protocol details and server addresses.

[0920] In some embodiments, the PCF may determine PCC rules taking into account the encrypted traffic processing requirements provided by the AF (including traffic processing support indications and encrypted traffic auxiliary information).

[0921] In some embodiments, the PCF sends authorized encrypted traffic processing information to the SMF via PCC rules. In some embodiments, the authorized encrypted traffic processing information can be sent to the SMF within PCC rules.

[0922] In some embodiments, the authorized encrypted traffic processing information (i.e., the second information) includes at least one of the following:

[0923] -Supports recognition of encrypted streams;

[0924] -Supports identification of PDU set information in encrypted streams;

[0925] - Supports sub-stream identification of encrypted multiplexed streams; if supported, further support for mapping sub-streams of encrypted multiplexed streams to multi-QoS streams;

[0926] - Supports sub-stream identification of encrypted multiplexed streams; if supported, further supports mapping of different media types or media components of encrypted multiplexed streams to multiple QoS streams;

[0927] - Supports multiple encryption stream recognition mechanisms; among which, encryption stream mechanisms include but are not limited to: Media-over-QUIC; extended UDP, such as RTP-over-QUIC, OFC (similar to hash); MASQUE, such as Proxy-UDP-in-HTTP / 3, QUIC-aware proxying; pre-configured N6 tunnel (GTP-U);

[0928] - When multiple encrypted stream identification mechanisms are supported, the priority of the corresponding encrypted stream mechanism is as follows: for example, Media over QUIC has the highest priority, MASQUE has the second highest priority, extended UDP has the third highest priority, and the pre-configured N6 tunnel has the fourth highest priority.

[0929] - When multiple encrypted stream identification mechanisms are supported, the priority of encrypted stream identification mechanisms for different encryption protocols may be different;

[0930] - When multiple encrypted stream identification mechanisms are supported, the priority of the encrypted stream identification mechanism may be different for different business scenarios;

[0931] - When multiple encrypted stream identification mechanisms are supported, the priority of the encrypted stream identification mechanisms may differ in different network deployment scenarios;

[0932] - When multiple encrypted stream identification mechanisms are supported, the priority of the encrypted stream identification mechanisms for network functions supported by different capabilities may be different; for example, UPF may only support one encrypted stream identification mechanism, or only support one or more low-priority identification mechanisms among multiple encrypted stream identification mechanisms.

[0933] -Supports encrypted stream flow information (DL, UL, DL and UL);

[0934] - When multiple encrypted stream identification directions are supported, and multiple encrypted stream identification mechanisms are used, the selection of encrypted stream mechanisms and priorities for different stream directions are determined.

[0935] In some embodiments, the PCF authorizes encrypted traffic processing information, taking into account the encrypted traffic processing requirements provided by the AF, the information stored in the UDR / UDM, operator policies, and received network status information.

[0936] In step 3, the SMF creates packet detection rules (N4 rules) for the UPF. The uplink packet detection rule includes an instruction to the UPF to establish an encapsulation protocol session based on the server address (provided by the AF) upon detecting that a packet is being sent to a server address. The downlink packet detection rule includes configuration information to enable PDU set probing and to extract PDU set information from the information contained in the encapsulation protocol.

[0937] In some embodiments, upon receiving a PCC rule, the SMF determines QoS rules and QoS set parameters, taking into account authorized encrypted traffic processing information, to configure and / or activate the rules for the UPF (e.g., via an N4 session).

[0938] In some embodiments, taking into account the indications of S-NSSAI, DNN, and PCF, the SMF determines the encrypted stream identification mechanism (e.g., Media-over-QUIC; Extended UDP; MASQUE; Pre-configured N6 tunnel) and encrypted stream processing policy information (e.g., encrypted traffic processing information). The SMF (e.g., via an N4 session) sends the determined encrypted stream identification mechanism and / or encrypted stream processing policy information to the UPF.

[0939] In some embodiments, the SMF sends the AS address received from the PCF (or configured locally or in OAM) to the UPF, thereby triggering the establishment of a connection with the AS for encrypted traffic processing.

[0940] In step 4, the N4 rule is sent to the UPF.

[0941] In some embodiments, taking into account authorized encrypted traffic processing information (e.g., encrypted flow identification mechanism, encrypted flow processing policy information, encrypted protocol description), the UPF identifies and determines PDU set information (e.g., from metadata) and sends it to the NG-RAN (e.g., in the extended header or GTP-U header). In some embodiments, the UPF sends encrypted traffic processing information (e.g., encrypted flow identification mechanism, encrypted flow processing policy information, encrypted protocol description) to the NG-RAN (e.g., in the extended header or GTP-U header).

[0942] In some embodiments, the UPF determines the encrypted data stream processing category by taking into account encrypted traffic processing information (e.g., encrypted stream identification mechanism, encrypted stream processing policy information, encryption protocol description). In some embodiments, the UPF triggers a connection with the AS using an AS address (e.g., a URI) for the determined encrypted traffic processing. The UPF receives connection establishment from the UE.

[0943] In some embodiments, UPF configuration may be employed. In some embodiments, based on OAM configuration and / or operator policies, and taking into account authorized encrypted traffic processing information and encryption protocol descriptions, the UPF identifies and determines PDU set information and sends it to NG-RAN in an extended header (e.g., in a GTP-U header).

[0944] In step 5, the application in the UE (i.e., the terminal) is triggered to connect to the AS.

[0945] In step 6, the application sends application data packets via the uplink on the 3GPP network.

[0946] In step 7, the UPF probes data packets, determines the packet detection rules that indicate the establishment of an encapsulation protocol session to the server address, and routes the uplink data packets through the encapsulation protocol.

[0947] In step 8, the UPF sends a session request to establish a connection using the encapsulation protocol procedure.

[0948] In step 9, the server confirms.

[0949] In step 10, the UPF encapsulates the uplink data packet in the header of the encapsulation protocol.

[0950] In step 11, the session data packet is sent to the AS via N6.

[0951] In step 12, subsequent downlink and uplink data packets can be routed, and the connection between the UE and AS is fully encrypted.

[0952] In step 13, AS determines the PDUs belonging to the PDU set and adds the PDU set information to the header of the encapsulation protocol.

[0953] In step 14, the UDP packet is sent to the UPF via an encapsulation protocol.

[0954] In step 15, the UPF extracts UDP packets and uses the PDU set information provided in the encapsulation protocol as described in step 4 to determine the PDU set information.

[0955] In some embodiments, the flow of the communication method according to the present disclosure (e.g., the flow shown in Figures 9A and 9B) may involve at least one of the following: control plane, user plane, and data plane. In some embodiments, the flow of the communication method according to the present disclosure may include at least one of the following: interaction within the control plane, interaction within the user plane, interaction between the control plane and the user plane, interaction within the data plane, interaction between the control plane and the data plane, and interaction between the user plane and the data plane. It should be noted that the flow of the communication method according to the present disclosure may also involve the computation plane or other planes, which are not specifically limited in this regard. In some embodiments, the network elements and devices within the communication system of the present disclosure may be located on one or more planes, including the control plane, user plane, data plane, and computation plane. These network elements and devices may implement request and data processing flows on one or more planes.

[0956] In the embodiments disclosed herein, some or all of the steps and their optional implementations may be arbitrarily combined with some or all of the steps in other embodiments, or may be arbitrarily combined with the optional implementations in other embodiments.

[0957] This disclosure also provides a communication apparatus for implementing any of the above methods. For example, this disclosure also provides another communication apparatus, including units or modules for implementing the steps performed by the network device (network element, first device) in any of the above methods.

[0958] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.

[0959] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a central processing unit, microprocessor, graphics processing unit (GPU) (which can be understood as a type of microprocessor), or digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device, such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), tensor processing unit (TPU), deep learning processing unit (DPU), etc.

[0960] Figure 10 is a schematic diagram of the structure of a communication device provided according to an embodiment of the present disclosure. As shown in Figure 10, the communication device 1000 may include at least one of the following: a transceiver module 1001 and a processing module 1002.

[0961] In some embodiments, the communication device 1000 may be a first network element 1031. In some embodiments, the transceiver module 1001 may be configured to receive first information sent by a second network element, wherein the first information is used for policy decision-making regarding the first encrypted data stream of a first service. Optionally, the transceiver module 1001 may be configured to perform at least one of the communication steps (e.g., steps S2103, S2105, S2107, S2109, S2201, S2202, S2221, S2222) performed by the first network element 1031 in any of the above methods, which will not be elaborated here. Optionally, the processing module 1002 may be configured to perform at least one of other steps (e.g., step S2104) besides the communication steps (e.g., step S2104) performed by the first network element 1031 in any of the above methods, which will not be elaborated here.

[0962] In some embodiments, the communication device 1000 may be a second network element 1032. In some embodiments, the transceiver module 1001 may be configured to send first information to a first network element, wherein the first information is used to make a policy decision for implementing a first encrypted data stream of a first service. Optionally, the transceiver module 1001 may be configured to perform at least one of the communication steps (e.g., steps S2101, S2106, S2201, S2202, S2222) performed by the second network element 1032 in any of the above methods, which will not be described in detail here.

[0963] In some embodiments, the communication device 1000 may be a third network element 1033. In some embodiments, the transceiver module 1001 may be configured to receive second information sent by a first network element, wherein the second information is used to implement QoS processing of a first encrypted data stream of a first service. Optionally, the transceiver module 1001 may be configured to perform at least one of the communication steps such as sending and / or receiving performed by the third network element 1033 in any of the above methods (e.g., steps S2107, S2109, S2110, S2111, S2112, S2116, S2117, S2118, S2119, S2120, S2122, S2128, S2202, S2204, S2220, S2221), which will not be elaborated here. Optionally, the processing module 1002 may be configured to perform at least one of the other steps (e.g., steps S2108, S2203) besides the communication steps such as sending and / or receiving performed by the third network element 1033 in any of the above methods, which will not be described in detail here.

[0964] In some embodiments, the communication device 1000 may be a fifth network element 1035. In some embodiments, the transceiver module 1001 may be configured to receive fourth information sent by a third network element, wherein the fourth information is used by the fifth network element for QoS processing of the first encrypted data stream of the first service. Optionally, the transceiver module 1001 may be configured to perform at least one of the communication steps such as sending and / or receiving performed by the fifth network element 1035 in any of the above methods (e.g., steps S2110, S2111, S2118, S2119, S2120, S2122, S2128, S2204, S2206, S2208, S2209, S2211, S2216, S2220), which will not be elaborated here. Optionally, the processing module 1002 may be configured to perform at least one of the following steps other than the communication steps such as sending and / or receiving performed by the fifth network element 1035 in any of the above methods (e.g., steps S2121, S2127, S2207, S2210, S2215, S2219), which will not be described in detail here.

[0965] In some embodiments, the communication device 1000 may be the first device 102. In some embodiments, the transceiver module 1001 may be configured to receive fifth information sent by a fifth network element, wherein the fifth information is used by the first device for QoS processing of the first encrypted data stream of the first service. Optionally, the transceiver module 1001 may be configured to perform at least one of the communication steps (e.g., steps S2113, S2114, S2115, S2122, S2124, S2218) performed by the first device 102 in any of the above methods, which will not be elaborated here. Optionally, the processing module 1002 may be configured to perform at least one of other steps (e.g., steps S2123, S2217) besides the communication steps (e.g., steps S2123, S2217) performed by the first device 102 in any of the above methods, which will not be elaborated here.

[0966] In some embodiments, the transceiver module may include a transmitting module and / or a receiving module. The transmitting and receiving modules may be separate or integrated. Optionally, the transceiver module may be interchangeable with a transceiver.

[0967] In some embodiments, the processing module may be a single module or may include multiple sub-modules. Optionally, the multiple sub-modules may each perform all or part of the steps required by the processing module. Optionally, the processing module may be interchangeable with a processor.

[0968] Figure 11A is a schematic diagram of the structure of a communication device provided according to an embodiment of the present disclosure. The communication device 11100 can be a network device (e.g., access network device, core network device, etc.), a terminal (e.g., user equipment, etc.), a chip, chip system, or processor that supports the network device in implementing any of the above methods, or a chip, chip system, or processor that supports the terminal in implementing any of the above methods. The communication device 11100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.

[0969] As shown in Figure 11A, the communication device 11100 includes one or more processors 11101. The processor 11101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. Optionally, the communication device 11100 can be used to execute any of the above methods. Optionally, one or more processors 11101 can be used to invoke instructions to cause the communication device 11100 to execute any of the above methods.

[0970] In some embodiments, the communication device 11100 further includes one or more transceivers 11102. When the communication device 11100 includes one or more transceivers 11102, the transceivers 11102 perform communication steps such as sending and / or receiving in the above method (e.g., steps S2101, S2103, S2105, S2106, S2107, S2109, S2110, S2111, S2112, S2113, S2114, S2115, S2116, S2117, S2118, S2119, S2120, S2122, S2124, S2126, S2128, S2201, S2202, S2202, S2103, S2104, S2105, S2106, S2107, S2109, S2110, S2111, S2112, S2113, S2114, S2115, S2116, S2117, S2118, S2119, S2120, S2122, S2124, S2126, S2128, S2201, S2202, S2103, S2104, S2105, S2106, S2107, S2109, S2110, S21106, S2107, S2109, S2110, S21106, S2107, S2108, S2109, S2101, S2102, S2104, S2105, S2106, S2107, S2108, S2109, S21 At least one of S2204, S2206, S2208, S2209, S2211, S2212, S2214, S2216, S2218, S2220, S2221, S2222, but not limited thereto, is performed by processor 11101, which executes at least one of other steps (e.g., steps S2102, S2104, S2108, S2121, S2123, S2125, S2127, S2203, S2207, S2210, S2213, S2215, S2217, S2219, but not limited thereto). In optional embodiments, the transceiver may include a receiver and / or a transmitter, which may be separate or integrated together. Optionally, terms such as transceiver, transceiver unit, transceiver, transceiver circuit, interface circuit, and interface can be used interchangeably; terms such as transmitter, transmitting unit, transmitter, and transmitting circuit can be used interchangeably; and terms such as receiver, receiving unit, receiver, and receiving circuit can be used interchangeably.

[0971] In some embodiments, the communication device 11100 further includes one or more memories 11103 for storing data. Optionally, all or part of the memories 11103 may be located outside the communication device 11100. In optional embodiments, the communication device 11100 may include one or more interface circuits 11104. Optionally, the interface circuits 11104 are connected to the memories 11103 and can be used to receive data from the memories 11103 or other devices, and can be used to send data to the memories 11103 or other devices. For example, the interface circuits 11104 can read data stored in the memories 11103 and send the data to the processor 11101.

[0972] The communication device 11100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 11100 described in this disclosure is not limited thereto, and the structure of the communication device 11100 may not be limited by FIG11A. The communication device may be a standalone device or may be part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.

[0973] Figure 11B is a schematic diagram of the structure of a chip provided according to an embodiment of the present disclosure. For cases where the communication device 11100 can be a chip or a chip system, please refer to the schematic diagram of the structure of the chip 11200 shown in Figure 11B, but it is not limited thereto.

[0974] Chip 11200 includes one or more processors 11201. Chip 11200 is used to perform any of the methods described above.

[0975] In some embodiments, chip 11200 further includes one or more interface circuits 11202. Optionally, terms such as interface circuit, interface, and transceiver pin can be used interchangeably. In some embodiments, chip 11200 further includes one or more memories 11203 for storing data. Optionally, all or part of the memories 11203 may be located outside of chip 11200. Optionally, interface circuit 11202 is connected to memory 11203, and interface circuit 11202 can be used to receive data from memory 11203 or other devices, and interface circuit 11202 can be used to send data to memory 11203 or other devices. For example, interface circuit 11202 can read data stored in memory 11203 and send the data to processor 11201.

[0976] In some embodiments, the interface circuit 11202 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps S2101, S2103, S2105, S2106, S2107, S2109, S2110, S2111, S2112, S2113, S2114, S2115, S2116, S2117, S2118, S2119, S2120, S2122, S2124, S2126, S2128, S2201, S2202, S2204, S2206, S2208, S2209, S2211, S2212, S2214, S2216, S2218, S2220, S2221, S2222, but not limited thereto). The interface circuit 11202 performing the communication steps such as sending and / or receiving in the above method refers to, for example, the interface circuit 11202 performing data interaction between the processor 11201, the chip 11200, the memory 11203, or the transceiver device. In some embodiments, the processor 11201 performs at least one of other steps (e.g., steps S2102, S2104, S2108, S2121, S2123, S2125, S2127, S2203, S2207, S2210, S2213, S2215, S2217, S2219, but is not limited thereto).

[0977] The modules and / or devices described in the various embodiments, such as virtual devices, physical devices, and chips, can be combined or separated arbitrarily as needed. Optionally, some or all steps can also be performed collaboratively by multiple modules and / or devices, which is not limited here.

[0978] This disclosure also proposes a storage medium storing instructions that, when executed on a communication device 11100, cause the communication device 11100 to perform any of the methods described above. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but is not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but is not limited thereto; it may also be a temporary storage medium.

[0979] This disclosure also proposes a program product that, when executed by the communication device 11100, causes the communication device 11100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0980] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.

[0981] Other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of the invention are indicated by the following claims.

[0982] It should be understood that the present invention is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. A communication method performed by a first network element, wherein, The method comprises: receiving first information sent by a second network element, wherein the first information is used for implementing policy decision of a first encrypted data flow of a first service.

2. The method of claim 1, wherein, The first information comprises at least one of: first support information used for indicating support characteristics of encrypted data flow; priority information used for determining priority of encrypted data flow; protocol description information used for describing related protocol of the first encrypted data flow.

3. The method of claim 2, wherein, The first support information is used for indicating at least one of: whether to support identification of encrypted data flow; whether to support identification of packet data unit (PDU) set information of encrypted data flow; whether to support identification of sub-flow in multiplexed data flow; whether to support mapping from sub-flow of encrypted multiplexed data flow to multiple quality of service (QoS) flows; whether to support mapping from flow data of different media types of encrypted multiplexed data flow to multiple QoS flows; whether to support mapping from flow data of different media components of encrypted multiplexed data flow to multiple QoS flows; supported encryption protocol; supported transmission direction of encrypted data flow.

4. The method of claim 3, wherein, The encryption protocol comprises at least one of: media over quick user datagram protocol internet connection (QUIC) (MOQT); multiplexed application over QUIC encrypted (MASQUE); extended user datagram protocol (UDP); N6 tunnel.

5. The method of claim 3 or 4, wherein, The transmission direction comprises one of: uplink; downlink; uplink and downlink.

6. The method of any one of claims 2 to 5, wherein, The priority information is related to at least one of: encryption protocol; service; network deployment; network function.

7. The method of any one of claims 1 to 6, wherein, The method further comprises: sending second information to a third network element, wherein the second information is used for implementing QoS processing on the first encrypted data flow.

8. The method of claim 7, wherein, The second information comprises at least one of: second support information used for indicating support of encrypted data flow; priority information used for determining priority of encrypted data flow; protocol description information used for describing related protocol of the first encrypted data flow; address information used for indicating address of a fourth network element related to the first service.

9. The method of claim 8, wherein, The second support information is used for indicating at least one of: support of identification of encrypted data flow; support of identification of packet data unit (PDU) set information of encrypted data flow; support of identification of sub-flow in multiplexed data flow; support of mapping from sub-flow of encrypted multiplexed data flow to multiple quality of service (QoS) flows; support of mapping from flow data of different media types of encrypted multiplexed data flow to multiple QoS flows; support of mapping from flow data of different media components of encrypted multiplexed data flow to multiple QoS flows; supported encryption protocol; supported transmission direction of encrypted data flow.

10. The method of any one of claims 7 to 9, wherein, The method further comprises: determining first rule according to the first information, wherein the first rule comprises the second information.

11. The method of any one of claims 7 to 10, wherein, The second information further comprises subscription information used for event subscription related to the first encrypted data flow.

12. The method of claim 11, wherein, The method further comprises: receiving third information sent by a third network element, wherein the third information is used for indicating event related to the first encrypted data flow.

13. A method of communication performed by a second network element, comprising: The method comprises: sending first information to a first network element, wherein the first information is used for implementing policy decision of a first encrypted data flow of a first service.

14. The method of claim 13, wherein, The first information comprises at least one of: first support information for indicating support characteristics of encrypted data flow; priority information for determining priority of encrypted data flow; protocol description information for describing related protocol of the first encrypted data flow.

15. The method of claim 14, wherein, The first support information is used for indicating at least one of: whether to support identification of encrypted data flow; whether to support identification of packet data unit (PDU) set information of encrypted data flow; whether to support identification of sub-flow in multiplexed data flow; whether to support mapping from sub-flow of encrypted multiplexed data flow to multiple QoS flows; whether to support mapping from flow data of different media types of encrypted multiplexed data flow to multiple QoS flows; whether to support mapping from flow data of different media components of encrypted multiplexed data flow to multiple QoS flows; supported encryption protocol; supported transmission direction of encrypted data flow.

16. The method of claim 15, wherein, The encryption protocol comprises at least one of: media over quick user datagram protocol internet connections (QUIC) (MOQT); multipath application base protocol over QUIC encryption (MASQUE); extended user datagram protocol (UDP); N6 tunnel.

17. The method of claim 15 or 16, wherein, The transmission direction comprises one of: uplink; downlink; uplink and downlink.

18. The method of any one of claims 14 to 17, wherein, The priority information is related to at least one of: encryption protocol; service; network deployment; network function.

19. A communication method performed by a third network element, wherein, The method comprises: receiving second information sent by a first network element, wherein the second information is used for implementing quality of service (QoS) processing of a first encrypted data flow of a first service.

20. The method of claim 19, wherein, The second information comprises at least one of: second support information for indicating support of encrypted data flow; priority information for determining priority of encrypted data flow; protocol description information for describing related protocol of the first encrypted data flow; address information for indicating address of a fourth network element related to the first service.

21. The method of claim 20, wherein, The second support information is used for indicating at least one of: support of identification of encrypted data flow; support of identification of packet data unit (PDU) set information of encrypted data flow; support of identification of sub-flow in multiplexed data flow; support of mapping from sub-flow of encrypted multiplexed data flow to multiple QoS flows; support of mapping from flow data of different media types of encrypted multiplexed data flow to multiple QoS flows; support of mapping from flow data of different media components of encrypted multiplexed data flow to multiple QoS flows; supported encryption protocol; supported transmission direction of encrypted data flow.

22. The method of claim 21, wherein, The encryption protocol comprises at least one of: media over quick user datagram protocol internet connections (QUIC) (MOQT); multipath application base protocol over QUIC encryption (MASQUE); extended user datagram protocol (UDP); N6 tunnel.

23. The method of claim 21 or 22, wherein, The transmission direction comprises one of: uplink; downlink; uplink and downlink.

24. The method of any one of claims 20-23, wherein, The priority information is related to at least one of: encryption protocol; service; network deployment; network function.

25. The method of any one of claims 19 to 24, wherein, The second information is contained in a first rule, which is determined based on the first information.

26. The method of any one of claims 19 to 25, wherein, The method further includes: sending fourth information to a fifth network element, wherein the fourth information is used for the fifth network element to process QoS of the first encrypted data flow.

27. The method of claim 26, wherein, The fourth information includes at least one of: encryption protocol information, used to indicate at least one encryption protocol; policy information, used to indicate a QoS processing policy related to the first encrypted data flow; protocol description information, used to describe a related protocol of the first encrypted data flow; address information, used to indicate an address of a fourth network element related to the first service.

28. The method of claim 27, wherein, At least one of the encryption protocol information and the policy information is determined based at least on the second information.

29. The method of any one of claims 26-28, wherein, The second information and the fourth information both further include subscription information, used for event subscription related to the first encrypted data flow.

30. The method of claim 29, wherein, The method further includes: receiving third information sent by a fifth network element, wherein the third information is used to indicate an event related to the first encrypted data flow; sending the third information to the first network element.

31. A communication method performed by a fifth network element, wherein, The method includes: receiving fourth information sent by a third network element, wherein the fourth information is used for a fifth network element to process quality of service (QoS) of a first encrypted data flow of a first service.

32. The method of claim 31, wherein, The fourth information includes at least one of: encryption protocol information, used to indicate at least one encryption protocol; policy information, used to indicate a QoS processing policy related to the first encrypted data flow; protocol description information, used to describe a related protocol of the first encrypted data flow; address information, used to indicate an address of a fourth network element related to the first service.

33. The method of claim 32, wherein, At least one of the encryption protocol information and the policy information is determined based at least on second information used to implement the QoS processing of the first encrypted data flow.

34. The method of claim 33, wherein, The second information includes at least one of: second support information, used to indicate support of encrypted data flow; priority information, used to determine a priority of encrypted data flow; the protocol description information; the address information.

35. The method of claim 34, wherein, The second support information is used to indicate at least one of: support of identification of encrypted data flow; support of identification of packet data unit (PDU) set information of encrypted data flow; support of identification of subflow in multiplexed data flow; support of mapping from subflow of encrypted multiplexed data flow to multiple QoS flows; support of mapping from flow data of different media types of encrypted multiplexed data flow to multiple QoS flows; support of mapping from flow data of different media components of encrypted multiplexed data flow to multiple QoS flows; supported encryption protocol; supported transmission direction of encrypted data flow.

36. The method of claim 35, wherein, The encryption protocol includes at least one of: QUIC-based media transport (MOQT); QUIC-encrypted multiplexed application base protocol (MASQUE); extended user datagram protocol (UDP); N6 tunnel.

37. The method of claim 35 or 36, wherein, The transmission direction includes one of: uplink; downlink; uplink and downlink.

38. The method of any one of claims 34-37, wherein, The priority information is related to at least one of: encryption protocol; service; network deployment; network function.

39. The method of any one of claims 32 to 38, wherein, The fourth information includes the address information; wherein the method further includes: According to the address information, a connection is established with the fourth network element.

40. The method of any one of claims 31 to 39, wherein, The method further comprises: According to the fourth information, mapping between the first encrypted data flow and a QoS flow is performed.

41. The method of claim 40, wherein, According to the fourth information, mapping between the first encrypted data flow and a QoS flow is performed. According to the fourth information, an encryption protocol used for identifying the first encrypted data flow is determined.

42. The method of any one of claims 31 to 41, wherein, The method further comprises: The fifth information is carried in a downlink data packet of the first encrypted data flow, and is used for QoS processing of the first encrypted data flow by the first device.

43. The method of claim 42, wherein, The fifth information comprises at least one of: Encryption protocol information used for indicating at least one encryption protocol; Policy information used for indicating a QoS processing policy related to the first encrypted data flow; Protocol description information used for describing a related protocol of the first encrypted data flow.

44. The method of any one of claims 31 to 43, wherein, The fourth information further comprises subscription information used for event subscription related to the first encrypted data flow.

45. The method of claim 44, wherein, The method further comprises at least one of: Sending third information to a third network element on a control plane; Sending third information to a fourth network element on a user plane; The third information is used for indicating an event related to the first encrypted data flow.

46. A communication method performed by a first device, wherein, The method comprises: Receiving fifth information sent by a fifth network element, wherein the fifth information is used for quality of service (QoS) processing of a first encrypted data flow of a first service by the first device.

47. The method of claim 46, wherein, The fifth information comprises at least one of: Encryption protocol information used for indicating at least one encryption protocol; Policy information used for indicating a QoS processing policy related to the first encrypted data flow; Protocol description information used for describing a related protocol of the first encrypted data flow.

48. The method of claim 46 or 47, wherein, The fifth information is carried in a downlink data packet of the first encrypted data flow.

49. The method of any one of claims 46-48, wherein, The fifth information is determined based on at least fourth information used for QoS processing of the first encrypted data flow of the first service by the fifth network element.

50. The method of claim 49, wherein, The fourth information comprises at least one of: Encryption protocol information used for indicating at least one encryption protocol; Policy information used for indicating a QoS processing policy related to the first encrypted data flow; Protocol description information used for describing a related protocol of the first encrypted data flow; Address information used for indicating an address of a fourth network element related to the first service.

51. A communication method performed by a core network, wherein, The core network comprises a first network element, a second network element, a third network element, and a fifth network element. The method comprises: The first network element performs the communication method according to any one of claims 1 to 12; The second network element performs the communication method according to any one of claims 13 to 18; The third network element performs the communication method according to any one of claims 19 to 30; The fifth network element performs the communication method according to any one of claims 31 to 45.

52. A communications device arranged at a first network element, wherein The communication device comprises: A transceiver module configured to receive first information sent by a second network element, wherein the first information is used for policy decision of a first encrypted data flow of a first service.

53. A communications device configured to be located at a second network element, wherein, The communication device comprises: The transceiver is configured to send first information to the first network element, wherein the first information is used to implement policy decision of the first encrypted data flow of the first service.

54. A communications device arranged at a third network element, wherein The communication device comprises: The transceiver is configured to receive second information sent by the first network element, wherein the second information is used to implement quality of service (QoS) processing of the first encrypted data flow of the first service.

55. A communications device configured to be located at a fifth network element, wherein, The communication device comprises: The transceiver is configured to receive second information sent by the first network element, wherein the second information is used to implement quality of service (QoS) processing of the first encrypted data flow of the first service.

56. A communication device configured to be disposed at a first facility, wherein, The communication device comprises: The transceiver is configured to receive fifth information sent by the fifth network element, wherein the fifth information is used for quality of service (QoS) processing of the first encrypted data flow of the first service by the first device.

57. A communication device comprising: one or more processors; a memory storing instructions; wherein the instructions, when executed on the communication device, cause the communication device to implement at least one of: the communication method of any of claims 1-12; the communication method of any of claims 13-18; the communication method of any of claims 19-30; the communication method of any of claims 31-45; the communication method of any of claims 46-50.

58. A communication system comprising at least one of: a first network element configured to implement the communication method of any of claims 1-12; a second network element configured to implement the communication method of any of claims 13-18; a third network element configured to implement the communication method of any of claims 19-30; a fifth network element configured to implement the communication method of any of claims 31-45; a first device configured to implement the communication method of any of claims 46-50.

59. A storage medium storing instructions, wherein, when executed on a communication device, cause the communication device to implement at least one of: the communication method of any of claims 1-12; the communication method of any of claims 13-18; the communication method of any of claims 19-30; the communication method of any of claims 31-45; the communication method of any of claims 46-50.

60. A computer program product comprising instructions, wherein when executed on a communication device, cause the communication device to implement at least one of: the communication method of any of claims 1-12; the communication method of any of claims 13-18; the communication method of any of claims 19-30; the communication method of any of claims 31-45; the communication method of any of claims 46-50.

Citation Information

Patent Citations

  • Method, device and system for updating security policy

    CN112788593A

  • A first node, second node, third node for handling encrypted traffic in communication network and methods performed by same

    CN117083893A

  • Information processing method, network element, system and storage medium

    CN117546452A

  • Service data flow processing method, network equipment, communication equipment and storage medium

    CN117546519A

  • Communicating PDU sets in a wireless communication system

    WO2023215918A1