Data transmission method, communication apparatus, and storage medium
By using different keys and parameter information in different sessions between the terminal device and the user plane network element to perform end-to-end user plane security protection, the problems of data transmission delay and low efficiency are solved, and efficient data transmission is achieved.
Patent Information
- Application Number
- PCT/CN2025/108540
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-29
- Filing Date
- 2025-07-15
- Publication Date
- 2026-02-05
AI Technical Summary
In mobile communication network systems, data transmission between terminal devices and user plane network elements requires multiple user plane security protection processes, resulting in data transmission delays and low efficiency.
By using different keys for different sessions between the terminal device and the user plane network element, end-to-end user plane security protection is achieved, including encryption and integrity protection. The parameter information corresponding to the session is used to indicate the data transmission parameters, thereby reducing replay attacks.
It effectively prevents replay attacks, reduces data transmission latency, and improves data transmission efficiency.
Smart Images

Figure CN2025108540_05022026_PF_FP_ABST
Abstract
Description
A data transmission method, a communication device, and a storage medium
[0001] This application claims priority to Chinese Patent Application No. 202411027475X, filed on July 29, 2024, entitled "A Data Transmission Method, Communication Device and Storage Medium", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of communication technology, specifically to a data transmission method, a communication device, and a storage medium. Background Technology
[0003] In mobile communication network systems, after a terminal device accesses the core network through a wireless network device, it can transmit data with user plane network elements in the core network via the wireless network device. In existing technologies, the data transmitted between the terminal device and the user plane network elements requires hop-by-hop user plane security protection (such as confidentiality protection and / or integrity protection). Taking the transmission of uplink data with confidentiality protection as an example, the terminal device uses a user plane encryption key (such as K... UPenc After encrypting the uplink data, the encrypted data is sent to the wireless network device. Upon receiving the encrypted data from the terminal device, the wireless network device decrypts the data using the same user plane encryption key. Next, the wireless network device uses the key of the Internet Protocol Security (IPsec) tunnel to encrypt the decrypted data again and sends the encrypted data to the user plane network element. Correspondingly, the user plane network element uses the key of the IPsec tunnel to decrypt the received data, thus obtaining the original uplink data.
[0004] However, in the above process, the data needs to undergo multiple user plane security protections during transmission, which leads to longer data transmission time and lower efficiency. Summary of the Invention
[0005] This application provides a data transmission method, a communication device, and a storage medium to achieve end-to-end user plane security protection between a terminal device and a user plane network element, thereby improving data transmission efficiency.
[0006] To address the aforementioned technical problems, this application provides the following technical solutions:
[0007] In a first aspect, embodiments of this application provide a data transmission method, the method comprising:
[0008] The terminal device obtains the first key based on the identifier of the first session between the terminal device and the user plane network element;
[0009] The terminal device performs user plane security protection on the first data based on the first key to obtain the second data;
[0010] The terminal device sends the second data through the first session;
[0011] The user plane network element receives the second data through the first session;
[0012] The user plane network element performs user plane security processing on the second data according to the first key to obtain the first data.
[0013] In the above implementation scheme, different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, different keys can be used to protect the user plane data of different sessions, realize end-to-end user plane security protection between the terminal device and the user plane network element, effectively prevent replay attacks, reduce data transmission latency, and improve data transmission efficiency.
[0014] Secondly, embodiments of this application provide a data transmission method, the method being applied to a terminal device, the method comprising:
[0015] The first key is obtained based on the identifier of the first session between the terminal device and the user plane network element;
[0016] The first data is protected with user plane security based on the first key to obtain the second data;
[0017] The second data is sent through the first session.
[0018] In the above implementation scheme, different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, different keys can be used to protect the user plane data of different sessions, realize end-to-end user plane security protection between the terminal device and the user plane network element, effectively prevent replay attacks, reduce data transmission latency, and improve data transmission efficiency.
[0019] In one possible implementation of the first or second aspect, the step of providing user plane security protection for the first data based on the first key includes:
[0020] User plane security protection is applied to the first data based on the first key and the parameter information corresponding to the first session. The parameter information corresponding to the first session is used to indicate the transmission parameters of the first data.
[0021] In the above implementation scheme, when the terminal device performs security protection, in addition to using the first key, it can also use the parameter information corresponding to the first session. The parameter information corresponding to the first session is used to indicate the transmission parameters of the first data. Different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, by using different keys and the parameter information corresponding to the first session, the user plane data of different sessions can be protected, thereby realizing end-to-end user plane security protection between the terminal device and the user plane network element.
[0022] In one possible implementation of the first or second aspect, the parameter information corresponding to the first session includes, but is not limited to, one or more of the following:
[0023] The first parameter is used to indicate the first quality of service flow in the first session, and the first quality of service flow is used for the transmission of the first data.
[0024] The second parameter indicates the value of a counter corresponding to the data packet carrying the first data, the counter being used to count data packets in the first session.
[0025] In the above implementation, the first parameter is defined at the granularity of a first quality of service (QoS) flow, which is used for the transmission of first data. Therefore, the first parameter can be determined through the first QoS flow. The second parameter indicates the value of a counter used to carry the first data of the first session. Therefore, the second parameter can be determined through the value of the counter corresponding to the data packet carrying the first data. In this application embodiment, the parameter information corresponding to the first session may include the first parameter or the second parameter. The parameter information corresponding to the first session can be determined through the first parameter and / or the second parameter.
[0026] In one possible implementation of the first or second aspect, the first parameter includes an identifier of the first quality of service flow.
[0027] In the above implementation scheme, the first parameter is based on the first quality of service flow. For example, the first parameter includes the identifier of the first quality of service flow, so the first parameter can be determined through the first quality of service flow.
[0028] In one possible implementation of the first or second aspect, obtaining the first key based on the identifier of the first session between the terminal device and the user plane network element includes:
[0029] The first key is obtained based on the identifier of the first session and the identifier of the first quality of service flow in the first session.
[0030] In the above implementation scheme, after the terminal device obtains the identifier of the first session, it obtains the first key based on the identifier of the first session and the identifier of the first quality of service flow. For example, the identifier of the first quality of service flow can be the first quality of service flow identifier. Therefore, in this embodiment, the first key can correspond to the first session and the first quality of service flow to realize different keys corresponding to different sessions between the terminal device and the user plane network element.
[0031] In one possible implementation of the first or second aspect, the step of providing user plane security protection for the first data based on the first key includes:
[0032] User plane security protection is applied to the first data based on the first key and the third parameter, wherein the third parameter indicates the value of a counter corresponding to the data packet carrying the first data, and the counter is used to count the data packets corresponding to the first quality of service stream.
[0033] In the above scheme, when the terminal device performs security protection, in addition to using the first key, it can also use a third parameter. The third parameter is used to indicate the value of the counter used to carry the first data. The data packet is used to carry the first data of the first session. Therefore, the third parameter can be determined by the value of the counter corresponding to the data packet carrying the first data. Different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, by using different keys and the third parameter, the user plane data of different sessions can be protected, realizing end-to-end user plane security protection between the terminal device and the user plane network element.
[0034] In one possible implementation of the first or second aspect, user plane security protection includes encryption, and the terminal device performs user plane security protection on the first data according to the first key, including:
[0035] The terminal device obtains the first confidentiality protection key based on the first key;
[0036] The terminal device obtains the first key stream based on the first confidentiality protection key;
[0037] The terminal device encrypts the first data according to the first key stream to obtain the first ciphertext, and the second data includes the first ciphertext.
[0038] In the above scheme, the terminal device can obtain the first confidentiality protection key through the first key. The first confidentiality protection key is used to encrypt the first data, thereby realizing end-to-end confidentiality protection of the first data between the terminal device and the user plane network element.
[0039] In one possible implementation of the first or second aspect, user plane security protection includes integrity protection, and the terminal device performs user plane security protection on the first data according to the first key, including:
[0040] The terminal device obtains the first integrity protection key based on the first key;
[0041] The terminal device obtains a first message authentication code based on a first integrity protection key and first data, and the second data includes the first message authentication code.
[0042] In the above scheme, the terminal device can obtain the first integrity protection key through the first key. The first integrity protection key is used to protect the integrity of the first data, thereby realizing end-to-end integrity protection of the first data between the terminal device and the user plane network element.
[0043] In one possible implementation of the first or second aspect, user plane security protection includes encryption and integrity protection, and the terminal device performs user plane security protection on the first data according to the first key, including:
[0044] The terminal device obtains a second key stream based on the first key, and encrypts the first data based on the second key stream to obtain the second ciphertext;
[0045] The terminal device obtains the second message authentication code based on the first key and the first data;
[0046] The second data includes the second ciphertext and the second message authentication code.
[0047] In the above scheme, the terminal device can protect the confidentiality and integrity of the first data through the first key, thereby achieving end-to-end confidentiality and integrity protection of the first data between the terminal device and the user plane network element.
[0048] In one possible implementation of the first or second aspect, the data transmission method executed by the terminal device, in addition to performing the foregoing steps, further includes:
[0049] The terminal device obtains parameter information corresponding to the first session, and the parameter information is used to indicate the transmission parameters of the first data.
[0050] In the above implementation scheme, when the terminal device performs security protection, in addition to using the first key, it can also use the parameter information corresponding to the first session. The parameter information corresponding to the first session is used to indicate the transmission parameters of the first data. For example, before using the first key and the parameter information corresponding to the first session to perform user plane security protection, the terminal device can obtain the parameter information corresponding to the first session, thereby realizing the use of the parameter information corresponding to the first session to perform user plane security protection.
[0051] Thirdly, embodiments of this application also provide a data transmission method, the method being applied to a user plane network element, the method comprising:
[0052] The second data is received through a first session between the user plane network element and the terminal device. The second data is data after the first data has been protected with user plane security according to the first key corresponding to the first session.
[0053] The second data is processed using the first key to obtain the first data.
[0054] In the above implementation scheme, the first session corresponds to the first key, and different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, user plane data of different sessions can be securely processed through different keys, realizing end-to-end user plane security processing between the terminal device and the user plane network element, effectively preventing replay attacks, reducing data transmission latency, and improving data transmission efficiency.
[0055] In one possible implementation of the first or third aspect, the user-plane security processing of the second data based on the first key includes:
[0056] The second data is processed for user plane security based on the first key and the parameter information corresponding to the first session. The parameter information corresponding to the first session is used to indicate the transmission parameters of the second data.
[0057] In the above implementation scheme, when the user plane network element performs security processing, in addition to using the first key, it can also use the parameter information corresponding to the first session. The parameter information corresponding to the first session is used to indicate the transmission parameters of the first data of the first session. Different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, by using different keys and the parameter information corresponding to the first session, the user plane data of different sessions can be securely protected, and end-to-end user plane security processing between the terminal device and the user plane network element can be realized.
[0058] In one possible implementation of the first or third aspect, the parameter information corresponding to the first session includes, but is not limited to, one or more of the following:
[0059] The first parameter is used to indicate the first quality of service flow in the first session, and the first quality of service flow is used for the transmission of the second data.
[0060] The second parameter indicates the value of a counter corresponding to the data packet carrying the first data, the counter being used to count data packets in the first session.
[0061] In the above implementation, the first parameter is defined at the granularity of a first quality of service (QoS) flow, which is used for the transmission of first data. Therefore, the first parameter can be determined through the first QoS flow. The second parameter indicates the value of a counter used to carry the first data of the first session. Therefore, the second parameter can be determined through the value of the counter corresponding to the data packet carrying the first data. In this application embodiment, the parameter information corresponding to the first session may include the first parameter or the second parameter. The parameter information corresponding to the first session can be determined through the first parameter and / or the second parameter.
[0062] In one possible implementation of the first or third aspect, the first parameter includes an identifier of the first quality of service flow.
[0063] In the above implementation scheme, the first parameter is based on the first quality of service flow. For example, the first parameter includes the identifier of the first quality of service flow, so the first parameter can be determined through the first quality of service flow.
[0064] In one possible implementation of the first or third aspect, the user-plane security processing of the second data based on the first key includes:
[0065] The second data is processed for user plane security based on the first key and the third parameter, wherein the third parameter indicates the value of the counter corresponding to the data packet carrying the second data, and the counter is used to count the data packets corresponding to the first quality of service flow in the first session.
[0066] In the above scheme, when the terminal device performs security protection, in addition to using the first key, it can also use a third parameter. The third parameter is used to indicate the value of the counter of the data packet used to carry the first data. The data packet is used to carry the first data of the first session. Therefore, the third parameter can be determined by the value of the counter corresponding to the data packet carrying the first data. Different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, the user plane data of different sessions can be securely processed by using different keys and the third parameter, realizing end-to-end user plane security processing between the terminal device and the user plane network element.
[0067] In one possible implementation of the first or third aspect, the second data includes the first ciphertext, and the user plane network element performs user plane security processing on the second data according to the first key, including:
[0068] The user plane network element obtains the first confidentiality protection key based on the first key;
[0069] The user plane network element obtains the first key stream based on the first confidentiality protection key;
[0070] The user plane network element decrypts the first ciphertext according to the first key stream to obtain the first plaintext.
[0071] In the above scheme, the user plane network element can obtain the first confidentiality protection key through the first key. The first confidentiality protection key is used to decrypt the first ciphertext, thereby realizing end-to-end confidentiality protection of the first data between the terminal device and the user plane network element.
[0072] In one possible implementation of the first or third aspect, the second data includes a first message authentication code, and the user plane network element performs user plane security processing on the second data based on the first key, including:
[0073] The user plane network element obtains the first integrity protection key based on the first key;
[0074] The user plane network element obtains the third message authentication code based on the first integrity protection key;
[0075] The user plane network element obtains the first message authentication code from the second data, and obtains the integrity verification result based on the first message authentication code and the third message authentication code.
[0076] In the above scheme, the user plane network element can obtain the first integrity protection key through the first key. The first integrity protection key is used to obtain the third message verification code. Integrity verification can be performed through the first message authentication code and the third message authentication code in the second data, thereby realizing end-to-end integrity protection of the first data between the terminal device and the user plane network element.
[0077] In one possible implementation of the first or third aspect, the second data includes a second ciphertext and a second message authentication code. The user plane network element performs user plane security processing on the second data based on the first key, including:
[0078] The user plane network element obtains the second key stream based on the first key, and decrypts the second ciphertext based on the second key stream to obtain the second plaintext;
[0079] The user plane network element obtains the fourth message authentication code based on the first key;
[0080] The user plane network element obtains the integrity verification result based on the second and fourth message authentication codes.
[0081] In the above scheme, the user plane network element can protect the confidentiality and integrity of the first data through the first key, thereby achieving end-to-end confidentiality and integrity protection of the first data between the terminal device and the user plane network element.
[0082] In one possible implementation of the first or third aspect, the data transmission method performed by the user plane network element, in addition to performing the aforementioned steps, further includes:
[0083] The user plane network element obtains the parameter information corresponding to the first session, and the parameter information is used to indicate the transmission parameters of the first data.
[0084] In the above implementation scheme, when the user plane network element performs security processing, in addition to using the first key, it can also use the parameter information corresponding to the first session. The parameter information corresponding to the first session is used to indicate the transmission parameters of the first data. For example, before using the first key and the parameter information corresponding to the first session to perform user plane security processing, the user plane network element can obtain the parameter information corresponding to the first session, thereby realizing the use of the parameter information corresponding to the first session to perform user plane security processing.
[0085] Fourthly, embodiments of this application also provide a data transmission method, the method comprising:
[0086] The terminal device obtains the first key corresponding to the terminal device;
[0087] The terminal device performs user plane security protection on the first data according to the first key and the first parameter to obtain the second data. The first parameter is used to indicate the first session, or the first parameter is used to indicate the first quality of service flow in the first session. The first session is a session between the terminal device and the user plane network element.
[0088] The terminal device sends the second data through the first session;
[0089] The user plane network element receives the second data through the first session;
[0090] The user plane network element performs user plane security processing on the second data based on the first key and the first parameters to obtain the first data.
[0091] In the above implementation scheme, different sessions between the terminal device and the user plane network element correspond to different first parameters, or different quality of service flows of different sessions correspond to different first parameters. Therefore, the user plane data of different sessions can be securely protected by the first key and different first parameters, realizing end-to-end user plane security protection between the terminal device and the user plane network element, effectively preventing replay attacks, reducing data transmission latency, and improving data transmission efficiency.
[0092] Fifthly, embodiments of this application also provide a data transmission method, the method being applied to a terminal device, the method comprising:
[0093] Obtain the first key corresponding to the terminal device;
[0094] User plane security protection is applied to the first data based on the first key and the first parameter to obtain the second data. The first parameter is used to indicate the first session between the terminal device and the user plane network element, or the first parameter is used to indicate the first quality of service flow in the first session. The first session is the session between the terminal device and the user plane network element.
[0095] The second data is sent through the first session.
[0096] In the above implementation scheme, different sessions between the terminal device and the user plane network element correspond to different first parameters, or the quality of service flow of different sessions corresponds to different first parameters. Therefore, the user plane data of different sessions can be securely protected by the first key and different first parameters, realizing end-to-end user plane security protection between the terminal device and the user plane network element, effectively preventing replay attacks, reducing data transmission latency, and improving data transmission efficiency.
[0097] In one possible implementation of the fourth or fifth aspect, the step of providing user plane security protection for the first data based on the first key and the first parameters includes:
[0098] User plane security protection is applied to the first data based on the first key, the first parameter, and the second parameter. The second parameter indicates the value of a counter corresponding to the data packet carrying the first data, and the counter is used to count data packets in the first session.
[0099] In the above implementation scheme, when the terminal device performs security protection, in addition to using the first key, it can also use a first parameter and a second parameter. The first parameter is at the granularity of the first session or the first quality of service flow. The first quality of service flow is used for the transmission of the first data, so the first parameter can be determined through the first session or the first quality of service flow. The second parameter is used to indicate the value of the counter for the data packet used to carry the first data. The data packet is used to carry the first data of the first session, so the second parameter can be determined through the value of the counter corresponding to the data packet carrying the first data. Therefore, by using the first key and different first and second parameters, security protection can be provided for user plane data of different sessions, realizing end-to-end user plane security protection between the terminal device and the user plane network element.
[0100] In one possible implementation of the fourth or fifth aspect, the first parameter is used to indicate a first session between the terminal device and the user plane network element, including: the first parameter includes an identifier of the first session;
[0101] or,
[0102] The first parameter is used to indicate a first quality of service flow in the first session, including: the first parameter includes an identifier of the first quality of service flow and an identifier of the first session.
[0103] In the above scheme, the first parameter is at the level of the first session or at the level of the first quality of service flow. The first quality of service flow is used for the transmission of the first data. Therefore, the first parameter can be determined by the identifier of the first session, or by the identifier of the first session and the identifier of the first quality of service flow.
[0104] In one possible implementation of the fourth or fifth aspect, user plane security protection includes encryption, and the terminal device performs user plane security protection on the first data according to the first key, including:
[0105] The terminal device obtains the first confidentiality protection key based on the first key;
[0106] The terminal device obtains the first key stream based on the first confidentiality protection key;
[0107] The terminal device encrypts the first data according to the first key stream to obtain the first ciphertext, and the second data includes the first ciphertext.
[0108] In the above scheme, the terminal device can obtain the first confidentiality protection key through the first key. The first confidentiality protection key is used to encrypt the first data, thereby realizing end-to-end confidentiality protection of the first data between the terminal device and the user plane network element.
[0109] In one possible implementation of the fourth or fifth aspect, user plane security protection includes integrity protection, and the terminal device performs user plane security protection on the first data based on the first key, including:
[0110] The terminal device obtains the first integrity protection key based on the first key;
[0111] The terminal device obtains a first message authentication code based on a first integrity protection key and first data, and the second data includes the first message authentication code.
[0112] In the above scheme, the terminal device can obtain the first integrity protection key through the first key. The first integrity protection key is used to protect the integrity of the first data, thereby realizing end-to-end integrity protection of the first data between the terminal device and the user plane network element.
[0113] In one possible implementation of the fourth or fifth aspect, user plane security protection includes encryption and integrity protection. The terminal device performs user plane security protection on the first data based on the first key, including:
[0114] The terminal device obtains a second key stream based on the first key, and encrypts the first data based on the second key stream to obtain the second ciphertext;
[0115] The terminal device obtains the second message authentication code based on the first key and the first data;
[0116] The second data includes the second ciphertext and the second message authentication code.
[0117] In the above scheme, the terminal device can protect the confidentiality and integrity of the first data through the first key, thereby achieving end-to-end confidentiality and integrity protection of the first data between the terminal device and the user plane network element.
[0118] Sixthly, embodiments of this application also provide a data transmission method, the method being applied to a user plane network element, the method comprising:
[0119] The second data is received through a first session between the user plane network element and the terminal device. The second data is data after user plane security protection of the first data is performed according to the first key and first parameters corresponding to the terminal device. The first parameters are used to indicate the first session, or the first parameters are used to indicate the first quality of service flow in the first session.
[0120] The second data is processed using the first key and the first parameters corresponding to the terminal device to obtain the first data.
[0121] In the above implementation scheme, different sessions between the terminal device and the user plane network element correspond to different first parameters, or different quality of service flows of different sessions correspond to different first parameters. Therefore, the user plane data of different sessions can be securely protected by the first key and different first parameters, realizing end-to-end user plane security protection between the terminal device and the user plane network element, effectively preventing replay attacks, reducing data transmission latency, and improving data transmission efficiency.
[0122] In one possible implementation of the fourth or sixth aspect, the step of performing user plane security processing on the first data based on the first key and first parameters corresponding to the terminal device includes:
[0123] The second data is processed for user plane security based on the first key, the first parameter, and the second parameter. The second parameter indicates the value of a counter corresponding to the data packet carrying the second data. The counter is used to count data packets in the first session.
[0124] In the above implementation scheme, when the terminal device performs security protection, in addition to using the first key, it can also use a first parameter and a second parameter. The first parameter is at the granularity of the first session or the first quality of service flow. The first quality of service flow is used for the transmission of the first data, so the first parameter can be determined through the first session or the first quality of service flow. The second parameter is used to indicate the value of the counter for the data packet used to carry the first data. The data packet is used to carry the first data of the first session, so the second parameter can be determined through the value of the counter corresponding to the data packet carrying the first data. Therefore, by using the first key and different first and second parameters, security protection can be provided for user plane data of different sessions, realizing end-to-end user plane security protection between the terminal device and the user plane network element.
[0125] In one possible implementation of the fourth or sixth aspect, the first parameter is used to indicate the first session, including: the first parameter includes an identifier of the first session;
[0126] or,
[0127] The first parameter is used to indicate a first quality of service flow in the first session, including: the first parameter includes an identifier of the first quality of service flow and an identifier of the first session.
[0128] In the above scheme, the first parameter is at the level of the first session or at the level of the first quality of service flow. The first quality of service flow is used for the transmission of the first data. Therefore, the first parameter can be determined by the identifier of the first session, or by the identifier of the first session and the identifier of the first quality of service flow.
[0129] In one possible implementation of the fourth or sixth aspect, the second data includes the first ciphertext, and the user plane network element performs user plane security processing on the second data according to the first key, including:
[0130] The user plane network element obtains the first confidentiality protection key based on the first key;
[0131] The user plane network element obtains the first key stream based on the first confidentiality protection key;
[0132] The user plane network element decrypts the first ciphertext according to the first key stream to obtain the first plaintext.
[0133] In the above scheme, the user plane network element can obtain the first confidentiality protection key through the first key. The first confidentiality protection key is used to decrypt the first ciphertext, thereby realizing end-to-end confidentiality protection of the first data between the terminal device and the user plane network element.
[0134] In one possible implementation of the fourth or sixth aspect, the second data includes a first message authentication code, and the user plane network element performs user plane security processing on the second data based on the first key, including:
[0135] The user plane network element obtains the first integrity protection key based on the first key;
[0136] The user plane network element obtains the third message authentication code based on the first integrity protection key;
[0137] The user plane network element obtains the first message authentication code from the second data, and obtains the integrity verification result based on the first message authentication code and the third message authentication code.
[0138] In the above scheme, the user plane network element can obtain the first integrity protection key through the first key. The first integrity protection key is used to obtain the third message verification code. Integrity verification can be performed through the first message authentication code and the third message authentication code in the second data, thereby realizing end-to-end integrity protection of the first data between the terminal device and the user plane network element.
[0139] In one possible implementation of the fourth or sixth aspect, the second data includes a second ciphertext and a second message authentication code. The user plane network element performs user plane security processing on the second data based on the first key, including:
[0140] The user plane network element obtains the second key stream based on the first key, and decrypts the second ciphertext based on the second key stream to obtain the second plaintext;
[0141] The user plane network element obtains the fourth message authentication code based on the first key;
[0142] The user plane network element obtains the integrity verification result based on the second and fourth message authentication codes.
[0143] In the above scheme, the user plane network element can protect the confidentiality and integrity of the first data through the first key, thereby achieving end-to-end confidentiality and integrity protection of the first data between the terminal device and the user plane network element.
[0144] Seventhly, embodiments of this application provide a data transmission method, including:
[0145] The user plane network element obtains the second key based on the identifier of the second session between the user plane network element and the terminal device;
[0146] The user plane network element performs user plane security protection on the third data based on the second key, and obtains the fourth data.
[0147] The user plane network element sends the fourth data through the second session;
[0148] The terminal device receives the fourth data through a second session between the terminal device and the user plane network element;
[0149] The terminal device performs user plane security processing on the fourth data based on the second key to obtain the third data.
[0150] In the above implementation scheme, different sessions between user plane network elements and terminal devices correspond to different keys. Therefore, different keys can be used to protect the user plane data of different sessions, realize end-to-end user plane security protection between user plane network elements and terminal devices, effectively prevent replay attacks, reduce data transmission latency, and improve data transmission efficiency.
[0151] Eighthly, embodiments of this application provide a data transmission method, the method being applied to a user plane network element, including:
[0152] The second key is obtained based on the identifier of the second session between the user plane network element and the terminal device;
[0153] The third data is protected with user plane security based on the second key to obtain the fourth data;
[0154] The fourth data is sent through the second session.
[0155] In the above implementation scheme, different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, different keys can be used to protect the user plane data of different sessions, realize end-to-end user plane security protection between the terminal device and the user plane network element, effectively prevent replay attacks, reduce data transmission latency, and improve data transmission efficiency.
[0156] In one possible implementation of the seventh or eighth aspect, the second key is obtained based on the identifier of the second session between the user plane network element and the terminal device, including:
[0157] The second key is obtained based on the identifier of the second session and the identifier of the second quality of service flow in the second session.
[0158] In the above implementation scheme, after the user plane network element obtains the identifier of the second session, it obtains the second key based on the identifier of the second session and the identifier of the second quality of service flow. For example, the identifier of the second quality of service flow can be the second quality of service flow identifier. Therefore, in this embodiment, the second key can correspond to the second session and the second quality of service flow to realize different keys corresponding to different sessions between the terminal device and the user plane network element.
[0159] In one possible implementation of the seventh or eighth aspect, user plane security protection is applied to the third data based on the second key to obtain the fourth data, which includes:
[0160] User plane security protection is applied to the third data based on the parameter information corresponding to the second key and the second session. The parameter information corresponding to the second session is used to indicate the transmission parameters of the third data.
[0161] In the above implementation scheme, when the user plane network element performs security protection, in addition to using the second key, it can also use the parameter information corresponding to the second session. The parameter information corresponding to the second session is used to indicate the transmission parameters of the third data. Different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, by using different keys and the parameter information corresponding to the second session, the user plane data of different sessions can be protected, thereby realizing end-to-end user plane security protection between the terminal device and the user plane network element.
[0162] In one possible implementation of the seventh or eighth aspect, the parameter information corresponding to the second session includes, but is not limited to, one or more of the following:
[0163] The fourth parameter is used to indicate the second quality of service flow in the second session, which is used for the transmission of the third data.
[0164] The fifth parameter indicates the value of the counter corresponding to the data packet carrying the third data, and the counter is used to count data packets in the second session.
[0165] In the above implementation, the fourth parameter is at the granularity of the second quality of service flow, which is used for the transmission of the third data. Therefore, the fourth parameter can be determined through the second quality of service flow. The fifth parameter is used to indicate the value of the counter for the data packet used to carry the third data of the second session. Therefore, the fifth parameter can be determined through the value of the counter corresponding to the data packet carrying the third data. The parameter information corresponding to the second session in this application embodiment may include the fourth parameter or the fifth parameter. The parameter information corresponding to the second session can be determined through the fourth parameter and / or the fifth parameter.
[0166] In one possible implementation of the seventh or eighth aspect, user plane security protection includes encryption, and the user plane network element performs user plane security protection on the third data based on a second key, including:
[0167] The user plane network element obtains the second confidentiality protection key based on the second key;
[0168] User plane network elements obtain the third key stream based on the second confidentiality protection key;
[0169] The user plane network element encrypts the third data according to the third key stream to obtain the third ciphertext, and the fourth data includes the third ciphertext.
[0170] In the above scheme, the user plane network element can obtain the second confidentiality protection key through the second key. The second confidentiality protection key is used to encrypt the third data, thereby realizing end-to-end confidentiality protection of the third data between the terminal device and the user plane network element.
[0171] In one possible implementation of the seventh or eighth aspect, user plane security protection includes integrity protection, whereby the user plane network element performs user plane security protection on the third data based on the second key, including:
[0172] The user plane network element obtains the second integrity protection key based on the second key;
[0173] The user plane network element obtains the fifth message authentication code based on the second integrity protection key and the third data, and the fourth data includes the fifth message authentication code.
[0174] In the above scheme, the user plane network element can obtain the second integrity protection key through the second key. The second integrity protection key is used to protect the integrity of the third data, thereby realizing end-to-end integrity protection of the third data between the terminal device and the user plane network element.
[0175] In one possible implementation of the seventh or eighth aspect, user plane security protection includes encryption and integrity protection, and the user plane network element performs user plane security protection on the third data based on the second key, including:
[0176] The user plane network element obtains the fourth key stream based on the second key, and encrypts the third data based on the fourth key stream to obtain the fourth ciphertext;
[0177] The user plane network element obtains the sixth message authentication code based on the second key and the third data;
[0178] The third data includes the fourth ciphertext and the sixth message authentication code.
[0179] In the above scheme, the user plane network element can use the second key to protect the confidentiality and integrity of the third data, thereby achieving end-to-end confidentiality and integrity protection of the third data between the terminal device and the user plane network element.
[0180] Ninthly, embodiments of this application provide a data transmission method, the method being applied to a terminal device, including:
[0181] The fourth data is received through a second session between the terminal device and the user plane network element. The fourth data is data after the third data has been protected with user plane security according to the second key corresponding to the second session.
[0182] The fourth data is processed using the second key to obtain the third data.
[0183] In one possible implementation of the seventh or ninth aspect, the fourth data is subjected to user-plane security processing based on the second key to obtain the third data, which includes:
[0184] The fourth data is processed for user plane security based on the second key and the parameter information corresponding to the second session. The parameter information corresponding to the second session is used to indicate the transmission parameters of the fourth data.
[0185] In one possible implementation of the seventh or ninth aspect, the parameter information corresponding to the second session includes, but is not limited to, one or more of the following:
[0186] The fourth parameter is used to indicate the second quality of service flow in the second session, which is used for the transmission of the fourth data.
[0187] The fifth parameter indicates the value of the counter corresponding to the data packet carrying the third data, and the counter is used to count data packets in the second session.
[0188] In one possible implementation of the seventh or ninth aspect, the fourth data includes the third ciphertext, and the terminal device performs user plane security processing on the fourth data according to the second key, including:
[0189] The terminal device obtains the second confidentiality protection key based on the second key;
[0190] The terminal device obtains the third key stream based on the second confidentiality protection key;
[0191] The terminal device decrypts the third ciphertext based on the third key stream to obtain the third plaintext.
[0192] In the above scheme, the terminal device can obtain the second confidentiality protection key through the second key. The second confidentiality protection key is used to decrypt the third ciphertext, thereby realizing the confidentiality protection of the third data between the terminal device and the user plane network element.
[0193] In one possible implementation of the seventh or ninth aspect, the fourth data includes a fifth message authentication code, and the terminal device performs user plane security processing on the fourth data based on the second key, including:
[0194] The terminal device obtains the second integrity protection key based on the second key;
[0195] The terminal device obtains the seventh message authentication code based on the second integrity protection key;
[0196] The terminal device obtains the fifth message authentication code from the fourth data, and obtains the integrity verification result based on the fifth message authentication code and the seventh message authentication code.
[0197] In the above scheme, the terminal device can obtain the second integrity protection key through the second key. The second integrity protection key is used to obtain the seventh message verification code. Integrity verification can be performed through the fifth message authentication code and the seventh message authentication code in the fourth data, thereby realizing the integrity protection of the third data between the terminal device and the user plane network element.
[0198] In one possible implementation of the seventh or ninth aspect, the fourth data includes a fourth ciphertext and a sixth message authentication code, and the terminal device performs user plane security processing on the fourth data based on the second key, including:
[0199] The terminal device obtains a fourth key stream based on the second key, and decrypts the fourth ciphertext based on the fourth key stream to obtain the fourth plaintext;
[0200] The terminal device obtains the eighth message authentication code based on the second key;
[0201] The terminal device obtains the integrity verification result based on the sixth and eighth message authentication codes.
[0202] In the above scheme, the terminal device can protect the confidentiality and integrity of the third data through the second key, thereby achieving end-to-end confidentiality and integrity protection of the third data between the terminal device and the user plane network element.
[0203] In a tenth aspect, embodiments of this application provide a data transmission method, including:
[0204] The user plane network element obtains the second key corresponding to the terminal device;
[0205] The user plane network element performs user plane security protection on the third data according to the second key and the fourth parameter to obtain the fourth data. The fourth parameter is used to indicate the second session, or the fourth parameter is used to indicate the second quality of service flow in the second session. The second session is a session between the user plane network element and the terminal device.
[0206] The user plane network element sends the fourth data through the second session;
[0207] The terminal device receives the fourth data through a second session between the terminal device and the user plane network element;
[0208] The terminal device performs user plane security processing on the fourth data based on the second key and the fourth parameter corresponding to the terminal device to obtain the third data.
[0209] Eleventhly, embodiments of this application provide a data transmission method, the method being applied to a user plane network element, including:
[0210] The user plane network element obtains the second key corresponding to the terminal device;
[0211] The user plane network element performs user plane security protection on the third data according to the second key and the fourth parameter to obtain the fourth data. The fourth parameter is used to indicate the second session, or the fourth parameter is used to indicate the second quality of service flow in the second session. The second session is a session between the user plane network element and the terminal device.
[0212] The user plane network element sends the fourth data through the second session.
[0213] In one possible implementation of the tenth or eleventh aspect, the step of providing user plane security protection for the first data based on the first key and the first parameters includes:
[0214] User plane security protection is applied to the third data based on the second key, the fourth parameter, and the fifth parameter. The fifth parameter indicates the value of a counter corresponding to the data packet carrying the third data, and the counter is used to count data packets in the second session.
[0215] In one possible implementation of the tenth or eleventh aspect, the fourth parameter is used to indicate a second session between the terminal device and the user plane network element, including: the fourth parameter includes an identifier of the second session;
[0216] or,
[0217] The fourth parameter is used to indicate the second quality of service flow in the second session, and includes: the fourth parameter includes the identifier of the second quality of service flow and the identifier of the second session.
[0218] In a twelfth aspect, embodiments of this application provide a data transmission method, the method being applied to a terminal device, including:
[0219] The terminal device receives fourth data through a second session between the terminal device and the user plane network element. The fourth data is data after the third data has been protected by user plane security according to the second key and the fourth parameter corresponding to the terminal device. The fourth parameter is used to indicate the second session, or the fourth parameter is used to indicate the second quality of service flow in the second session. The second session is a session between the user plane network element and the terminal device.
[0220] The terminal device performs user plane security processing on the fourth data based on the second key and the fourth parameter corresponding to the terminal device to obtain the third data.
[0221] In one possible implementation of the tenth or twelfth aspect, the step of performing user plane security processing on the fourth data based on the second key and the fourth parameter corresponding to the terminal device includes:
[0222] User plane security processing is performed on the fourth data according to the second key, the fourth parameter, and the fifth parameter. The fifth parameter is used to indicate the value of the counter corresponding to the data packet carrying the fourth data, and the counter is used to count data packets in the second session.
[0223] In one possible implementation of the tenth or twelfth aspect, the fourth parameter is used to indicate a second session between the terminal device and the user plane network element, including: the fourth parameter includes an identifier of the second session;
[0224] or,
[0225] The fourth parameter is used to indicate the second quality of service flow in the second session, and includes: the fourth parameter includes the identifier of the second quality of service flow and the identifier of the second session.
[0226] In a thirteenth aspect, embodiments of this application provide a data transmission system, the data transmission system comprising: a terminal device and a user plane network element;
[0227] The terminal device is configured to obtain a first key based on the identifier of a first session between the terminal device and a user plane network element; perform user plane security protection on first data based on the first key to obtain second data; and send the second data through the first session.
[0228] The user plane network element is used to receive the second data through the first session; and to perform user plane security processing on the second data according to the first key to obtain the first data.
[0229] In the above implementation scheme, different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, different keys can be used to protect the user plane data of different sessions, realize end-to-end user plane security protection between the terminal device and the user plane network element, effectively prevent replay attacks, reduce data transmission latency, and improve data transmission efficiency.
[0230] In a fourteenth aspect, embodiments of this application also provide a data transmission system, the system comprising:
[0231] A terminal device, used to obtain a first key corresponding to the terminal device;
[0232] The terminal device is used to perform user plane security protection on the first data according to the first key and the first parameter to obtain the second data. The first parameter is used to indicate the first session, or the first parameter is used to indicate the first quality of service flow in the first session. The first session is a session between the terminal device and the user plane network element.
[0233] The terminal device is used to send the second data through the first session;
[0234] The user plane network element is used to receive the second data through the first session;
[0235] The user plane network element is used to perform user plane security processing on the second data according to the first key and the first parameters to obtain the first data.
[0236] In a fifteenth aspect, embodiments of this application provide a data transmission system, the system comprising:
[0237] User plane network element, used to obtain second key based on the identifier of the second session between user plane network element and terminal device;
[0238] User plane network elements are used to perform user plane security protection on the third data based on the second key, and obtain the fourth data.
[0239] User plane network element, used to send the fourth data through the second session;
[0240] A terminal device is used to receive fourth data through a second session between the terminal device and a user plane network element;
[0241] A terminal device is configured to perform user plane security processing on the fourth data according to the second key to obtain the third data.
[0242] In a sixteenth aspect, embodiments of this application provide a data transmission system, the system comprising:
[0243] User plane network elements are used to obtain the second key corresponding to the terminal device;
[0244] The user plane network element is used to perform user plane security protection on the third data according to the second key and the fourth parameter to obtain the fourth data. The fourth parameter is used to indicate the second session, or the fourth parameter is used to indicate the second quality of service flow in the second session. The second session is a session between the user plane network element and the terminal device.
[0245] User plane network element, used to send the fourth data through the second session;
[0246] A terminal device is configured to receive the fourth data through a second session between the terminal device and a user plane network element;
[0247] A terminal device is used to perform user plane security processing on the fourth data according to the second key and the fourth parameter corresponding to the terminal device to obtain the third data.
[0248] In a seventeenth aspect, embodiments of this application provide a communication device including a processor and a memory, the memory and the processor being coupled together, the processor being configured to execute the method described in any one of the first to twelfth aspects.
[0249] In the seventeenth aspect of this application, the constituent modules of the communication device may also perform the steps described in the foregoing first to twelfth aspects and various possible implementations, as detailed in the foregoing descriptions of the first to twelfth aspects and various possible implementations.
[0250] Eighteenthly, embodiments of this application provide a communication device, the communication device comprising: a transmitting module, a receiving module, and a processing module;
[0251] The processing module is configured to execute the method described in any one of the first to twelfth aspects.
[0252] In a nineteenth aspect, embodiments of this application provide a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the methods described in the first to twelfth aspects.
[0253] In a twentieth aspect, embodiments of this application provide a computer program product containing instructions that, when run on a computer, cause the computer to perform the methods described in the first to twelfth aspects.
[0254] In a twentieth aspect, embodiments of this application provide a communication device, which may include entities such as terminal devices or chips. The communication device includes: a processor and a memory; the memory is used to store instructions; the processor is used to execute the instructions in the memory, causing the communication device to perform the method as described in any one of the first or twelfth aspects above.
[0255] In a twenty-second aspect, this application provides a chip system including a processor for supporting a terminal device or user plane network element in implementing the functions involved in the above aspects, such as transmitting or processing data and / or information involved in the above methods. In one possible design, the chip system further includes a memory for storing program instructions and data necessary for the terminal device or user plane network element. This chip system may be composed of chips or may include chips and other discrete devices.
[0256] In a twentieth aspect, embodiments of this application provide a chip including one or more interface circuits and one or more processors; the interface circuits are configured to receive signals from the memory of an electronic device and send signals to the processors, the signals including computer instructions stored in the memory; when the processor executes the computer instructions, it causes the electronic device to perform any possible implementation of the methods in the first to twelfth aspects. Attached Figure Description
[0257] Figure 1 is a network architecture diagram of a communication system applicable to an embodiment of this application;
[0258] Figure 2 is a schematic diagram of a key deduction architecture for a 5G communication system provided in an embodiment of this application;
[0259] Figure 3 is a schematic diagram of hop-by-hop data transmission between the terminal device and the wireless network device, and between the wireless network device and the user plane network element, provided in an embodiment of this application.
[0260] Figure 4a is a schematic diagram of the uplink data transmission process from the terminal device to the user plane network element provided in the embodiment of this application;
[0261] Figure 4b is a schematic diagram of the downlink data transmission process from the user plane network element to the terminal device provided in an embodiment of this application;
[0262] Figure 5 is a schematic diagram of the data transmission process between a terminal device and a user plane network element provided in an embodiment of this application;
[0263] Figure 6 is a schematic diagram of the data transmission process between a terminal device and a user plane network element according to an embodiment of this application;
[0264] Figure 7 is a schematic diagram of the data transmission process between a terminal device and a user plane network element provided in an embodiment of this application;
[0265] Figure 8 is a schematic diagram of the data transmission process between a terminal device and a user plane network element according to an embodiment of this application;
[0266] Figure 9a is a schematic diagram of a key deduction process provided in an embodiment of this application;
[0267] Figure 9b is a schematic diagram of the data transmission process between a terminal device and a user plane network element according to an embodiment of this application;
[0268] Figure 9c is a schematic diagram of the data transmission process between a terminal device and a user plane network element according to an embodiment of this application;
[0269] Figure 10a is a schematic diagram of a key deduction process provided in an embodiment of this application;
[0270] Figure 10b is a schematic diagram of the data transmission process between a terminal device and a user plane network element according to an embodiment of this application;
[0271] Figure 10c is a schematic diagram of the data transmission process between a terminal device and a user plane network element according to an embodiment of this application;
[0272] Figure 11a is a schematic diagram of a key deduction process provided in an embodiment of this application;
[0273] Figure 11b is a schematic diagram of another key deduction process provided in an embodiment of this application;
[0274] Figure 11c is a schematic diagram of the data transmission process between a terminal device and a user plane network element provided in an embodiment of this application;
[0275] Figure 11d is a schematic diagram of the data transmission process between a terminal device and a user plane network element according to an embodiment of this application;
[0276] Figure 12 is a schematic diagram of the composition structure of a communication device provided in an embodiment of this application;
[0277] Figure 13 is a schematic diagram of the composition structure of a communication device provided in an embodiment of this application. Detailed Implementation
[0278] The embodiments of this application will now be described with reference to the accompanying drawings.
[0279] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such terms are interchangeable where appropriate; this is merely a way of distinguishing objects with the same attributes in the embodiments of this application. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion, so that a process, method, system, product, or apparatus that comprises a series of elements is not necessarily limited to those elements, but may include other elements not explicitly listed or inherent to those processes, methods, products, or apparatuses.
[0280] The technical solutions of this application can be applied to various data processing communication systems, such as 5th generation (5G) communication systems, new radio (NR), long term evolution (LTE), code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal frequency-division multiple access (OFDMA), single carrier frequency division multiple access (SC-FDMA), and other systems. The term "system" can be used interchangeably with "network." CDMA systems can implement wireless technologies such as Universal Terrestrial Radio Access (UTRA) and CDMA2000. UTRA can include wideband CDMA (WCDMA) technology and other CDMA variants. CDMA2000 can cover interim standard (IS) 2000 (IS-2000), IS-95, and IS-856 standards. TDMA systems can implement wireless technologies such as the Global System for Mobile Communication (GSM). OFDMA systems can implement wireless technologies such as evolved Universal Radio Terrestrial Access (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, and Flash OFDMA. UTRA and E-UTRA are UMTS and its evolved versions, respectively. Furthermore, the technical solutions provided in this application can also be applied to future communication systems. The system architecture and service scenarios described in this application are for the purpose of more clearly illustrating the technical solutions of this application and do not constitute a limitation on the technical solutions provided in this application. Those skilled in the art will understand that with the evolution of network architecture and the emergence of new service scenarios, the technical solutions provided in this application are also applicable to similar technical problems.
[0281] Figure 1 is a schematic diagram of a network architecture for a communication system applicable to an embodiment of this application. The network architecture includes: a terminal device, an access network, user plane network elements, access and mobility management network elements, and session management network elements. It should be noted that this network architecture is merely an exemplary system architecture applicable to an embodiment of this application and is not intended to limit the scope of the embodiments. The following is a description of each part in Figure 1:
[0282] A terminal device can be a terminal equipment, or a module, unit, or chip within a terminal equipment. Terminal equipment can also be called user equipment (UE), mobile station (MS), mobile terminal (MT), or terminal, and provides voice and / or data connectivity to users. Examples of terminal equipment include: mobile phones, tablets, laptops, PDAs, mobile internet devices (MID), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving cars, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, handheld devices with wireless connectivity, and in-vehicle equipment.
[0283] There are two types of access networks (ANs). One type is the radio access network (RAN), representing air interface access technology, known as 3rd Generation Partnership Project (3GPP) access. This includes the air interface access technologies for 3G, 4G, and 5G networks. For example, the air interface in a 5G network is called a next-generation node base station (gNB). The other type is non-3GPP access. This refers to any air interface technology that is not defined by the 3GPP standard, such as air interface technologies like wireless fidelity (Wi-Fi) access points (APs).
[0284] For example, the RAN can be a base station access system for a 2G network (i.e., the RAN includes base stations and base station controllers), or a base station access system for a 3G network (i.e., the RAN includes base stations and radio network controllers (RNCs)), or a base station access system for a 4G network (i.e., the RAN includes eNBs and RNCs), or a base station access system for a 5G network, or an access system for a future network.
[0285] The access network includes one or more network devices, which can also be called access network devices. A network device can be any device with wireless transceiver capabilities, or it can be a chip embedded within a device with wireless transceiver capabilities. A network device can also be called a wireless network device; in the following examples of this application, they are collectively referred to as wireless network devices. Wireless network devices include, but are not limited to: base stations (e.g., base stations BS, NodeB, evolved NodeB or eNB, gNodeB or gNB in fifth-generation communication systems, base stations in future communication systems, access nodes in WiFi systems, wireless relay nodes, wireless backhaul nodes, etc.). Base stations can be: macro base stations, micro base stations, pico base stations, small cells, relay stations, etc. Multiple base stations can support networks using one or more of the technologies mentioned above, or future evolved networks. The core network can support networks using one or more of the technologies mentioned above, or future evolved networks. A base station can contain one or more co-located or non-co-located transmission receiving points (TRPs). Wireless network devices can also be radio controllers, centralized unit (CU) nodes, or distributed unit (DU) nodes in cloud radio access network (CRAN) scenarios, or RAN devices including both CU and DU nodes. Wireless network devices can also be servers, wearable devices, or vehicle-mounted devices. Wireless network devices can communicate with terminal devices or via relay stations. Terminal devices can support communication with multiple wireless network devices using different technologies. For example, a terminal device can support communication with wireless network devices supporting LTE networks, 5G networks, dual connectivity with both LTE and 5G networks, and communication with wireless network devices for future communication networks.
[0286] The user plane network element, access and mobility management network element, and session management network element in Figure 1 are network elements in the core network. The functions of each network element are briefly introduced below.
[0287] User plane network elements are the exit points for user plane data, used to connect to external data networks. For example, in a 5G communication system, a user plane network element can be a user plane function (UPF) network element. This application does not limit the name and function of user plane network elements in different network standards. The terminal device and the user plane network element interact through a wireless network device. For example, the terminal device's user plane data is sent to the user plane network element through the wireless network device, and the user plane network element then sends the user plane data to the external data network. Alternatively, the user plane network element may be located in a specific campus, or the user plane network element may be co-located with the wireless network device, implemented through the same physical entity; this application does not impose any limitations on this.
[0288] Access and mobility management network elements are responsible for access control and mobility management of terminal devices accessing the network. Access and mobility management network elements can be access and mobility management function (AMF) network elements in 5G communication systems.
[0289] Session management network elements are used to manage terminal device sessions (such as protocol data unit (PDU) sessions), including session establishment, modification, and release. Session management network elements can be session management function (SMF) network elements in 5G communication systems.
[0290] The core network may also include one or more of the following network elements: security anchor function (SEAF) network element, authentication server function (AUSF) network element, authentication repository and processing function (ARPF) network element, unified data management (UDM) network element, policy control function (PCF) network element, and network exposure function (NEF) network element.
[0291] The network architecture shown in Figure 1 can also include other devices and network elements, which are not limited in this embodiment. It is understood that a network element can also be called a network function (NF). A network element can be a physical entity in a hardware device, a software instance running on dedicated hardware, or a virtualized function instantiated on a shared platform (e.g., a cloud platform). That is, a network element can be implemented in hardware or software. In the architecture shown in Figure 1, the terminal device can transmit data with the user plane network element via the wireless network device. In the prior art, the data transmitted between the terminal device and the user plane network element needs to be protected by user plane security (such as confidentiality protection and / or integrity protection) hop-by-hop. Taking uplink data transmission with confidentiality protection as an example, the terminal device encrypts the uplink data using a user plane encryption key (such as KUPenc) and sends the encrypted data to the wireless network device. After receiving the encrypted data from the terminal device, the wireless network device decrypts the data using the same user plane encryption key. Next, the wireless network device uses the key of the Internet Protocol Security (IPsec) protocol tunnel to re-encrypt the decrypted data and sends the encrypted data to the user plane network element. Correspondingly, the user plane network element uses the key of the IPsec protocol tunnel to decrypt the received data, thereby obtaining the original uplink data.
[0292] However, in the aforementioned process, data needs to undergo multiple user plane security protections during transmission, which leads to prolonged data transmission time and low efficiency. Furthermore, during the data transmission process, the wireless network device needs to decrypt and re-encrypt the data, resulting in high computational overhead for the wireless network device. This makes it unsuitable for application scenarios such as satellite communication, and the wireless network device is vulnerable to physical attacks. Once subjected to a physical attack, the decrypted data of the wireless network device may be exposed to the attacker, posing a security risk.
[0293] The following is an explanation of the technologies that may be involved in the embodiments of this application:
[0294] First, the key derivation process used in 5G communication systems for user plane security protection and processing of user plane data is explained. User plane data can be simply referred to as data, and it can include uplink data from a terminal device to a user plane network element, or downlink data from a user plane network element to a terminal device. User plane security protection can be simply referred to as security protection, and user plane security processing can be simply referred to as security processing. In this embodiment, user plane security processing is the reverse process of user plane security protection. For example, if a 5G communication system includes a transmitter and a receiver, and the transmitter performs user plane security protection on user plane data, the receiver can perform user plane security processing on the received user plane data from the terminal device, as detailed in the following description.
[0295] In 5G communication systems, keys are required as input for user plane security protection. Please refer to Figure 2 for an explanation of the key derivation process in a 5G communication system. Optionally, the terminal device can be user equipment (UE), which includes mobile equipment (ME) and a universal subscriber identity module (USIM), or the UE includes a mobile equipment and a subscriber identification module (SIM). A long-term key can be stored in the UE's USIM and SIM. This long-term key is part of the user's subscription data and is used for authentication when the terminal device accesses the network. Additionally, the long-term key K is stored in the UDM or ARPF network elements on the network side. The length of the long-term key K can be 128 bits or 256 bits. Optionally, during key derivation, a 256-bit key can be derived first, and then truncated to a 128-bit key when needed. As security technologies evolve, the cryptographic algorithms used in future mobile communication systems may not be limited to algorithms using 128-bit keys, but may also use 256-bit keys. In this case, if the derived key length is 256 bits, it does not need to be truncated and can be used directly. If the derived key length is greater than 256 bits, it needs to be truncated to 256 bits before using the truncated key.
[0296] When a terminal device registers with the network, it needs to undergo identity authentication, also known as master authentication. The master authentication process generates intermediate keys CK and IK, which in turn yield the corresponding anchor keys KAUSF and KSEAF. During the derivation of the intermediate keys CK and IK, the network sends a challenge random number (RAND) and an authentication vector (AUTH) to the terminal device in plaintext. The terminal device and the network generate the intermediate keys CK and IK based on the long-term key K and the challenge random number, and verify the authentication vector using these keys.
[0297] After obtaining KSEAF, KAMF is derived from KSEAF. KAMF is used to generate the Non-Access Stratum (NAS) key for the control plane. The NAS key includes the NAS integrity protection key (KNASint) and the NAS confidentiality protection key (KNASenc). For example, based on KSEAF, with the algorithm type and algorithm identifier as input, the NAS integrity protection key (KNASint) and the NAS confidentiality protection key (KNASenc) can be derived. This algorithm type can include NAS encryption and NAS integrity protection.
[0298] In addition, KAMF is also used to generate the base station key KgNB and the next hop parameter (NH). The base station key KgNB is used to generate the RRC key and the user plane key. The next hop parameter is the input parameter for the base station to perform key deduction during the base station handover process.
[0299] For non-3GPP access processes, KN3IWF can also be derived through KAMF. KN3IWF is used to protect data traffic from non-3GPP access.
[0300] After obtaining the base station key KgNB, the base station key KgNB can also be used to generate the RRC integrity protection key (KRRCint) and the RRC confidentiality protection key (KRRCenc), the user plane (UP) integrity protection key (KUPint) and the UP confidentiality protection key (KUPenc).
[0301] In a 5G communication system, the process by which the terminal device and the network side negotiate security protection algorithms is as follows:
[0302] The terminal device sends a registration request to the network side. The registration request includes the terminal device's security capability information (UE security capability), which carries information about the security protection algorithms supported by the terminal device.
[0303] Based on the security capabilities of the terminal device and the priority list of security protection algorithms configured on the network side, the network side can negotiate the security protection algorithm to be used by the terminal device and the network side. Optionally, a security protection algorithm supported by both the network side and the terminal device with higher priority can be selected. The network side locally configures the list of security protection algorithms supported by the network and their priorities; optionally, the network can be an AMF (Advanced Security Functions) or a wireless network device. The AMF can decrypt encrypted NAS messages, and the wireless network device can decrypt encrypted RRC signaling and user plane data.
[0304] After the network side determines the security protection algorithm to be used, it sends the selected security protection algorithm to the terminal device during the security activation process. The terminal device can receive the security protection algorithm indicated by the network side.
[0305] After introducing the key derivation process and the security protection algorithm negotiation process, the following describes the data security protection in the 5G communication system. In this embodiment, the 5G communication system provides mechanisms to protect the confidentiality and integrity of signaling and user plane data. For example, the signaling may include radio resource control (RRC) signaling and non-access stratum (NAS) signaling. Data transmission in the 5G communication system can include a transmitting end and a receiving end according to the data transmission direction. For example, the transmitting end may include a terminal device, and the receiving end may include a wireless network device. Alternatively, the transmitting end may include a wireless network device, and the receiving end may include a terminal device.
[0306] Confidentiality protection refers to using confidentiality protection algorithms to securely protect signaling and user plane data. For example, the sending end uses a confidentiality protection algorithm to encrypt the signaling and user plane data, obtaining encrypted signaling and user plane data, and then sends the encrypted signaling and user plane data to the receiving end. After receiving the encrypted signaling and user plane data, the receiving end can decrypt the encrypted signaling and user plane data according to the confidentiality protection algorithm, obtaining the decrypted signaling and user plane data. Furthermore, confidentiality protection can include both encryption and decryption.
[0307] For example, confidentiality protection refers to encrypting data, obtaining ciphertext, and then outputting that ciphertext. An attacker who obtains the ciphertext cannot deduce the corresponding plaintext information. In the encryption process defined by 3GPP, the sending end inputs the key, first parameter, second parameter, transmission direction parameter, and length parameter into the confidentiality protection algorithm (e.g., encryption algorithm NEA), outputting a keystream (KEYSTREAM). Then, the output keystream is XORed with the plaintext (PLAINTEXT) to output the corresponding ciphertext (CIPHERTEXT). The sending end sends this ciphertext to the receiving end. The decryption process is the reverse of the encryption process. The receiving end inputs the key, first parameter, second parameter, transmission direction parameter, and length parameter into the confidentiality protection algorithm (e.g., encryption algorithm NEA), outputting a keystream (KEYSTREAM). Then, the ciphertext (CIPHERTEXT) is XORed with the keystream (KEYSTREAM) to output the corresponding plaintext (PLAINTEXT).
[0308] Integrity protection refers to the use of integrity protection algorithms to secure signaling and user plane data. For example, the sending end uses an integrity protection algorithm to calculate a message authentication code (MAC) for the signaling and user plane data and sends this MAC to the receiving end. After receiving the MAC, the receiving end can calculate its own MAC based on the integrity protection algorithm and compare the received MAC with the one calculated by the receiving end. Integrity protection can also be abbreviated as "integrity protection".
[0309] For example, during the integrity protection process, the sending end inputs the key, first parameter, second parameter, message, and direction into the integrity protection algorithm (NIA), and outputs the corresponding message authentication code (MAC) value. During the integrity verification process, the receiving end uses the key, first parameter, second parameter, message, and direction into the integrity protection algorithm (NIA) to calculate the MAC value and compares the received MAC value with the MAC value calculated by the receiving end.
[0310] The following explanation is provided regarding the parameters input for safety protection:
[0311] The key can be 128 bits, 256 bits, or other lengths. The key corresponds to the terminal device, meaning different terminal devices correspond to different keys. The key can be derived from KgNB.
[0312] The first parameter can be used to indicate the quality of service flow. For example, the first parameter can indicate the value of the bearer. The bearer value can be the NAS connection identifier used in Non-access stratum (NAS) protection, or the bearer value can be the data radio bearer (DRB) identity (ID) used in AS protection.
[0313] The second parameter can be used to indicate a counter (COUNT). For example, the second parameter can indicate the value of a counter used in NAS protection, which refers to the security protection of NAS messages. The initial value of the counter should be zero (0), and the value of the NAS counter is incremented by one after each encryption and integrity protection process for a NAS message. Alternatively, the counter can be a Packet Data Convergence Protocol (PDCP) counter used in AS protection, which refers to RRC signaling protection and user plane data protection. The initial value of the counter should be zero (0), and the value of the PDCP counter is incremented by one after each encryption and integrity protection process for an AS message. The sending and receiving ends each maintain the value of the counter. Optionally, the counter is further divided into an uplink counter and a downlink counter. If the data is sent from the terminal device to the network side (such as wireless network equipment or core network), it is an uplink message, and the second parameter uses the count value of the uplink counter. If the data is sent from the network side to the terminal device, it is a downlink message, and the second parameter uses the count value of the downlink counter.
[0314] The Non-Access Layer (NAS) is a functional layer in the wireless communication protocol stack between the core network and user equipment, mainly used for the transmission of control plane signaling. The Access Layer (AS) refers to the RRC layer and below in the control plane protocol stack between user equipment and wireless network equipment (i.e., base station). The AS has the function of handling the communication between the wireless access network and terminal devices, and is mainly used for the transmission of RRC signaling and user plane data.
[0315] The transmission direction (DIRECTION) parameter is used to indicate the transmission direction of the link. The transmission direction parameter can include the uplink direction and the downlink direction.
[0316] The length parameter indicates the length of the plaintext to be transmitted.
[0317] A message is the content of a message used for integrity protection. The length of a message is its length.
[0318] It is understandable that the input parameters for both confidentiality and integrity protection mentioned above include: key, first parameter, second parameter, transmission direction, and the corresponding message to be protected. The definitions of these input parameters differ in different scenarios. Specifically, the input parameters for confidentiality and integrity protection differ: the confidentiality protection algorithm requires the length of the key stream as input, while the integrity protection algorithm does not.
[0319] In a 5G communication system, please refer to Figure 3, which illustrates the hop-by-hop data transmission between a terminal device and a wireless network device (i.e., a base station), and between a wireless network device and a user plane network element. There is a session between the terminal device and the user plane network element. Optionally, a protocol data unit (PDU) session is used as an example for illustration. The type of session is not limited in this application embodiment. In a 5G communication system, a terminal device supports multiple PDU sessions. Each PDU session can contain multiple quality of service (QoS) streams to achieve differentiated services. A QoS stream is called a data path. All data streams on the same data path receive the same QoS guarantee; different QoS guarantees require different data paths. Optionally, QoS guarantee can refer to scheduling policies and buffer queue management methods. Under limited bandwidth resources, bandwidth can be allocated to various services or users through QoS rules to provide end-to-end QoS guarantees for services or users. End-to-end refers to the flow from the terminal device to the user plane network element, or from the user plane network element to the terminal device. For example, terminal devices or user plane network elements can configure QoS priorities for voice, video, and important data applications, and transmit data according to these QoS priorities.
[0320] Multiple QoS flows can exist between the terminal device and the user plane network element, and these flows are distinguished by their respective QoS Flow Identifiers (QFIs). A QFI is unique within a PDU session. Alternatively, the QFI can be dynamically assigned, or it can be equal to 5QI (5G QoS identity).
[0321] A PDU session's transmission channel consists of an NG-U tunnel and several radio bearers (RBs), including data radio bearers (DRBs). Wireless network devices need to map QoS flows to DRBs. The mapping between QoS flows and DRBs can be many-to-one or one-to-one. The wireless network device configures DRBs and NG-U tunnels for QoS flows according to session requirements.
[0322] In 5G communication systems, NG-U tunnels exist between wireless network devices and user plane network elements. Control plane data and user plane data are separated starting from the network device side. Control plane data connects to the core network via the NG-C interface, while user plane data connects to the core network via the NG-U interface. For example, NG-U tunnels exist between wireless network devices and user plane network elements via the General Packet Radio Service (GPRS) Tunneling Protocol (GTP-U). Data from different PDU sessions is transmitted in different NG-U tunnels. The tunnel header of the NG-U tunnel carries a QFI (Quick Information Framework), which indicates different data streams.
[0323] Based on the network architecture shown in Figure 3, the uplink data transmission process from the terminal device to the user plane network element will be described next, referring to Figure 4a, including the following process:
[0324] Step 11: The terminal device sends uplink data packets to the wireless network device.
[0325] After identifying the uplink data packet, the terminal device determines the mapping of the uplink data packet to the corresponding QoS flow based on the packet filter set (PFS) in the terminal device's QoS rules. The packet filter set should support packet filtering based on any combination of the following items: source / destination IP address or IPv6 address prefix, source / destination port number, protocol identifier above the IP / next header type, service type / traffic classification and mask, flow label, security parameter index, packet filtering direction, etc.
[0326] For example, a terminal device can identify a service flow by whether an uplink data packet matches a specific IP 5-tuple. Matching an uplink data packet with an IP 5-tuple means that the source IP address, source device port number, destination address, destination device port number, and upper-layer protocol of the uplink data packet are the same as or match the corresponding content in the IP 5-tuple.
[0327] The terminal device maps uplink data packets to the corresponding QoS stream according to its own QoS rules, and then maps them to the corresponding DRB according to the air interface mapping rules. The corresponding uplink data packets are then sent to the wireless network device on the corresponding DRB. The terminal device can maintain the mapping relationship between QoS and DRB locally, that is, maintain the air interface mapping rules. This mapping relationship can be assigned and sent to the terminal device by the wireless network device.
[0328] Among them, the QoS rules are sent to the terminal device by the session management network element during the PDU session. The QoS rules include the QoS rule identifier, the QoS flow identifier QFI, the packet filtering set used to filter uplink packets and the optional downlink packet filtering set, optional QoS parameters, etc., so that the terminal device can filter the data to be sent according to the packet filtering set and map it to the corresponding QoS flow according to the QFI in the corresponding QoS rule.
[0329] Before sending the corresponding uplink data packet according to the above process, the terminal device will use the user plane protection key corresponding to the terminal device to negotiate and determine the security protection algorithm according to the security policy of the session, and perform security protection on the uplink data packet. The security protection process is described in the above introduction to data security protection in the 5G communication system, and will not be repeated here.
[0330] The security policy for this session is sent to the wireless network device by the session management network element during the session establishment process. After determining the corresponding security protection algorithm, the wireless network device sends the selected security protection algorithm and security policy to the terminal device through an RRC reconfiguration message.
[0331] Step 12: The wireless network device receives the uplink data packet and sends the uplink data packet to the user plane network element through the NG-U tunnel.
[0332] Before the aforementioned wireless network device sends uplink data packets to the user plane network element, the wireless network device receives uplink data packets through DRB, obtains the QFI corresponding to the uplink data packet according to the mapping relationship between DRB and QFI corresponding to different sessions stored locally in the wireless network device, and then carries the corresponding QFI in the tunnel header of the NG-U tunnel sent to the user plane network element.
[0333] Optionally, before the aforementioned wireless network device sends uplink data packets to the user plane network element, the wireless network device performs security processing on the received uplink data packets according to the key corresponding to the terminal device and the selected security protection algorithm to obtain the security-processed data. Then, according to the above description, it maps to the corresponding QFI and sends the security-processed data in the corresponding NG-U tunnel. Optionally, the data transmitted in the NG-U can be securely transmitted again through the IPsec protocol between the wireless network device and the user plane network element / security gateway.
[0334] Step 13: The user plane network element receives the uplink data packet through the NG-U tunnel.
[0335] Before receiving uplink data packets through the NG-U tunnel, the user plane network element can perform secure processing on the securely transmitted data using the key corresponding to the IPsec protocol to obtain the original data packets. Then, the user plane network element identifies the QoS flow to which the uplink data packets belong through the QFI carried in the tunnel header of the NG-U tunnel. After receiving the corresponding uplink data packets through the NG-U tunnel, the user plane network element forwards the corresponding uplink data packets to the data network (DN).
[0336] Next, referring to Figure 4b, the downlink data transmission process between the terminal device and the user plane network element includes the following steps:
[0337] Step 21: The user plane network element obtains the tunnel ID and QFI of the NG-U tunnel to which the downlink data packet is mapped.
[0338] The user plane network element receives downlink data packets from the DN and maps the corresponding data packets to the corresponding NG-U tunnel and QFI according to the packet detection rule (PDR).
[0339] Optionally, during PDU session establishment, the session management network element can instruct the user plane network element on packet detection rules. These rules describe how the user plane network element processes packets that have been detected. For example, the detection information may include a combination of the following: core network (CN) tunnel information, network instance, QFI, packet filter set, application identifier, etc. The packet filter set may include the following parameters: source / destination IP address or IPv6 prefix, source / destination port number, protocol ID of the IP upper / lower header type, service type (IPv4) / traffic type (IPv6) and mask, flow label (IPv6), security parameter index, and packet filtering direction.
[0340] After receiving a downlink data packet, the user plane network element can map it to the corresponding data packet detection rule based on the data packet filtering set in the data packet detection rule, thereby determining the core network tunnel information (i.e., NG-U tunnel information) and QFI corresponding to the downlink data packet.
[0341] Step 22: The user plane network element sends downlink data packets on the corresponding NG-U tunnel. The header of the downlink data packet includes QFI.
[0342] Before sending the corresponding downlink data packet according to the above process, the user plane network element will use the user plane protection key corresponding to the downlink data packet to negotiate and determine the security protection algorithm according to the security policy of the PDU session, and perform security protection on the downlink data packet. The security protection process is described in the above introduction to data security protection in the 5G communication system, and will not be repeated here.
[0343] Among them, the security policy of PDU session is sent by the session management network element to the user plane network element during the session establishment process.
[0344] Step 23: The wireless network device receives the corresponding downlink data packet through the NG-U tunnel, maps it to the corresponding DRB according to the NG-U tunnel and QFI, and sends the corresponding downlink data packet in the corresponding DRB.
[0345] Specifically, the wireless network device obtains the DRB corresponding to the QFI in the downlink data packet based on the mapping relationship between DRB and QFI stored locally in the wireless network device, and then sends the corresponding downlink data packet in the corresponding DRB.
[0346] Optionally, before the aforementioned wireless network device sends downlink data packets to the terminal device, the wireless network device performs security processing on the received downlink data packets according to the key corresponding to the terminal device and the selected security protection algorithm to obtain the security-processed downlink data packets. Then, according to the above description, it is mapped to the corresponding DRB.
[0347] The corresponding mapping process is described in step 12, and will not be repeated here.
[0348] Step 24: The terminal device receives the corresponding downlink data packet.
[0349] After receiving downlink data packets through the DRB, the terminal device can perform secure processing on the securely transmitted data using the key corresponding to the terminal device, and obtain the downlink data sent by the user plane network element.
[0350] This application proposes a data transmission method for end-to-end user plane security protection of data transmission between a terminal device and a user plane network element, thereby reducing data transmission latency and improving data transmission efficiency.
[0351] Figure 5 is a flowchart illustrating a data transmission method provided in an embodiment of this application. Taking the transmission of uplink data between a terminal device and a user plane network element as an example, the method includes the following steps:
[0352] 501. The terminal device obtains the first key based on the identifier of the first session between the terminal device and the user plane network element.
[0353] There can be multiple sessions between the terminal device and the user plane network element. For example, the multiple sessions include the first session. In this embodiment, there is a correspondence between the session and the key. Different sessions of the terminal device correspond to different keys. Therefore, the corresponding key can be obtained through the identifier of the session. For example, the terminal device can obtain the first key according to the identifier of the first session. The first key corresponds to the first session.
[0354] Optionally, the terminal device obtains the first key based on the identifier of the first session between the terminal device and the user plane network element, including: the terminal device obtaining the first key based on the terminal device's long-term key and the identifier of the first session.
[0355] For example, the USIM of the terminal device can store a long-term key, which is part of the user's subscription data and is used for authentication when the terminal device accesses the network. After obtaining the identifier of the first session, the terminal device obtains a first key based on the terminal device's long-term key and the identifier of the first session, for example, by using the key derivation process shown in Figure 2. Optionally, this first key can be a user plane key. In this embodiment, different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, different keys can be used to protect the user plane data of different sessions, and there is no reuse of key streams or message authentication codes. By using different keys to protect the user plane data, replay attacks are effectively prevented.
[0356] In some embodiments of this application, the terminal device obtains the first key based on the terminal device's long-term key and the identifier of the first session. This may include: the terminal device obtaining an intermediate key based on the terminal device's long-term key, and then the terminal device obtaining the first key based on the intermediate key and the identifier of the first session. Optionally, the intermediate key is obtained based on the long-term key. For example, referring to the description of key deduction on the terminal device side shown in Figure 2 above, the terminal device can obtain the intermediate key based on the long-term key K. For example, the intermediate key may include at least one of the following: CK, IK, KAUSF, KSEAF, KAMF, Knasint, Knasenc, Kn3iwf, KgNB. The first key deduced based on the intermediate key and the identifier of the first session may include, for example, KPDUsession. Not limited, in the embodiments of this application, a confidentiality protection key and an integrity protection key may also be deduced based on the first key; this is not limited here.
[0357] For example, the terminal device obtains intermediate keys CK and IK based on the long-term key K stored in the USIM, and then obtains the corresponding anchor keys KAUSF and KSEAF based on the intermediate keys CK and IK. Then, KSM is derived from KSEAF, and the first key is derived from KSM and the identifier of the first session. Optionally, the first key can be a user plane key or a session key. For example, KSM is derived from KAUSF, or KAMF is derived from KSEAF, and then KSM is derived from KAMF and the identifier of the first session. KSM is the first key.
[0358] Optionally, the first session can be a PDU session. The identifier of the first session can be a PDU session identifier (session ID). For example, the first key corresponds to the PDU session granularity, and this first key can be a session key KPDUsession. Different session keys KPDUsession can be determined for different PDU sessions.
[0359] 502. The terminal device performs user plane security protection on the first data according to the first key, and obtains the second data.
[0360] In this embodiment, after obtaining the first key, the terminal device can perform user plane security protection on the first data based on the first key. User plane security protection can be simply referred to as security protection. The first data can be first uplink data, which refers to user plane data sent by the terminal device to the user plane network element on the network side.
[0361] User plane security protection may include confidentiality protection and / or integrity protection. For example, in confidentiality protection, the terminal device can generate a key stream based on a first key, and then encrypt the first data based on the key stream. For example, in integrity protection, the terminal device can generate a message authentication code based on the first key. Optionally, the terminal device can deduce a first encryption key and a first integrity protection key based on the first key. In confidentiality protection, the terminal device can generate a key stream based on the first encryption key, and then encrypt the first data based on the key stream; in integrity protection, the terminal device can generate a message authentication code based on the first integrity protection key.
[0362] For example, the terminal device can perform user plane security protection on the first data according to the first key and the security policy corresponding to the first session. The security policy corresponding to the first session indicates whether confidentiality protection and / or integrity protection are required for the data in the first session. For instance, when the security policy corresponding to the first session indicates that confidentiality protection is required for the data in the first session, the terminal device performs confidentiality protection on the first data according to the first key; when the security policy corresponding to the first session indicates that integrity protection is required for the data in the first session, the terminal device performs integrity protection on the first data according to the first key; when the security policy corresponding to the first session indicates that both confidentiality and integrity protection are required for the data in the first session, the terminal device performs both confidentiality and integrity protection on the first data according to the first key.
[0363] 503. The terminal device sends the second data through the first session.
[0364] For example, a terminal device can send second data to a user plane network element through a first session. For instance, the terminal device can send second data to a wireless network device through the first session, and the wireless network device can then send the second data to the user plane network element.
[0365] For example, the terminal device maps the second data to the first Quality of Service (QoS) flow in the first session according to QoS rules, then maps the first QoS flow to the corresponding DRB according to the air interface mapping rules, and then sends it to the wireless network device through the DRB. The air interface mapping rules can include the correspondence between QoS flows and DRBs. The wireless network device receives the second data carried on the DRB and, according to the mapping relationship between DRBs and QoS flows stored locally in the wireless network device, sends the second data to the user plane network element through the QoS flow corresponding to the DRB. The data packet carrying the second data may carry the identifier of the QoS flow.
[0366] Steps 501 to 503 above are executed by the terminal device. After the terminal device sends the second data through the first session, the user plane network element can execute the following steps 504 to 505.
[0367] 504. The user plane network element receives the second data through the first session between the user plane network element and the terminal device.
[0368] In this setup, a first session exists between the user plane network element and the terminal device. The user plane network element can receive second data from the terminal device through this first session. This second data may be the second data sent by the terminal device in step 503. Optionally, the user plane network element can receive the second data sent by the terminal device through a wireless network device. Optionally, the first data may be first uplink data.
[0369] 505. The user plane network element performs user plane security processing on the second data according to the first key to obtain the first data.
[0370] In this embodiment of the application, the user plane network element can store keys corresponding to multiple sessions, wherein the multiple sessions include a first session, and the key corresponding to the first session is a first key. For example, the user plane network element can store the correspondence between the identifier of the first session and the first key.
[0371] For example, after receiving the second data through the first session, the user plane network element determines the first key corresponding to the first session, and then uses the first key to perform user plane security processing on the second data. For instance, the user plane network element determines the first key based on the identifier of the first session and the correspondence between the identifier of the first session and the first key.
[0372] For example, a core network element can deduce the keys corresponding to multiple sessions. See Figure 2 for a description of the key deduction process. After obtaining multiple keys, the core network element sends the keys corresponding to multiple sessions to the user plane network element. Optionally, the core network element can be an SMF, an AMF, a SEAF, or an AUSF. This application embodiment does not limit the type of core network element that provides keys to the user plane network element.
[0373] Optionally, the user plane network element may use any of the following examples to determine the identifier of the first session.
[0374] Example 1: The user plane network element can determine the corresponding terminal device identifier and the corresponding first session identifier through the tunnel identifier of the NG-U tunnel. The user plane network element obtains the first key corresponding to the first session based on the identifier of the first session of the terminal device. Since different sessions correspond to different keys, there is a one-to-one correspondence between different sessions and keys of different terminal devices. Therefore, the first key can be obtained through the identifier of the first session of the terminal device.
[0375] Example 2: The user plane network element can also determine the identifier of the sending terminal device corresponding to the data packet by the source IP address of the data packet, determine the identifier of the first session according to the NG-U tunnel identifier, and thus obtain the first key corresponding to the first session. Since different sessions correspond to different keys, there is a one-to-one correspondence between different sessions and keys of different terminal devices. Therefore, the first key can be obtained by the identifier of the first session of the terminal device.
[0376] Optionally, user plane security processing may refer to decryption and / or integrity verification. It should be understood that user plane security processing is the reverse process of user plane security protection. When user plane security protection includes confidentiality protection, then user plane security processing includes decryption; when user plane security protection includes integrity protection, then user plane security processing includes integrity verification. After obtaining the first data through user plane security processing, the user plane network element can forward the first data to the data network.
[0377] In one possible implementation (denoted as implementation A), step 502, the terminal device performs user plane security protection on the first data according to the first key, including: the terminal device performs user plane security protection on the first data according to the first key and parameter information corresponding to the first session, wherein the parameter information corresponding to the first session is used to indicate the transmission parameters of the first data.
[0378] Correspondingly, in step 505, the user plane network element performs user plane security processing on the second data according to the first key, including: the user plane network element performs user plane security processing on the first data according to the first key and the parameter information corresponding to the first session, wherein the parameter information corresponding to the first session is used to indicate the first data transmission parameters.
[0379] It should be understood that the parameter information corresponding to the first session used by the user plane network element in step 505 is the same as the parameter information corresponding to the first session used by the terminal device in step 502.
[0380] The parameter information corresponding to the first session is used to indicate the transmission parameters of the first data in the first session, and can also be regarded as the configuration parameters for transmitting user plane data through the first session.
[0381] The parameter information corresponding to the first session may include, but is not limited to, one or more of the following:
[0382] The first parameter is used to indicate the first quality of service flow in the first session, and the first quality of service flow is used for the transmission of the first data.
[0383] The second parameter indicates the value of the counter corresponding to the data packet carrying the first data. The counter is used to count the data packets in the first session.
[0384] The first parameter is used to indicate the first Quality of Service (QoS) flow in the first session. The first session corresponds to multiple QoS flows, and the multiple QoS flows include the first QoS flow. For example, the first parameter can be implemented in various ways; any parameter that can indicate the first QoS flow in the first session can be used as the first parameter. In one example, the first parameter is at the QoS flow granularity, for example, the first parameter includes the identifier of the first QoS flow. In this embodiment, the first parameter is not limited to being at the QoS flow granularity; for example, the first parameter can also be at the DRB granularity, and the implementation method of the first parameter is not limited.
[0385] The first data packet carries the first data of the first session. The second parameter indicates the value of the counter corresponding to this data packet. For example, the terminal device and the user plane network element maintain two counters for a session of the terminal device: an uplink counter and a downlink counter. The uplink counter counts uplink data packets in the first session, and the downlink counter counts downlink data packets in the first session. Uplink data packets refer to data packets sent from the terminal device to the user plane network element, and downlink data packets refer to data packets sent from the user plane network element to the terminal device. The uplink counter of the terminal device and the user plane network element increments according to the number of uplink data packets, and the downlink counter of the user plane network element and the terminal device increments according to the number of downlink data packets. The counting methods of the counters on both sides of the terminal device and the user plane network element are kept synchronized. Asynchronous counters due to packet loss are prevented by sending check bits and other means. For example, the value of the counter indicated by the second parameter here is the value of the uplink counter.
[0386] For example, the second parameter is at the session level. Therefore, by using session-level keys and counters, different keys and counters can be used to securely protect user plane data for different sessions, preventing the reuse of keystreams or message authentication codes. Protecting user plane data with different keys effectively prevents replay attacks.
[0387] Furthermore, in some embodiments of this application, the parameter information corresponding to the first session includes, in addition to the aforementioned first and second parameters, one or more of the following information:
[0388] The transmission direction parameter indicates that the transmission direction of the first data is uplink.
[0389] The length parameter indicates the length of the key stream used for confidentiality protection, which can be the same as the length of the first data.
[0390] The composition of the parameter information corresponding to the first session is not limited here. For example, the parameter information corresponding to the first session may include a first parameter, or it may include a second parameter, or it may include a transmission direction parameter, or it may include a length parameter. Alternatively, the parameter information corresponding to the first session may include both a first parameter and a second parameter, or it may include a first parameter, a second parameter, a transmission direction parameter, and a length parameter. Optionally, in some embodiments of this application, the first parameter includes a first quality of service (QoS) flow identifier corresponding to the first QoS flow. For example, the first parameter is at the QoS flow identifier granularity; therefore, different keys and different first parameters can be used to securely protect user plane data for different sessions, preventing the reuse of keystreams or message authentication codes. Using different keys to securely protect user plane data effectively prevents replay attacks.
[0391] For example, the length of the first parameter can be determined based on the length of the first quality of service flow identifier, and / or the length of the first parameter is greater than or equal to 6 bits. The length of the first parameter is not limited in the embodiments of this application.
[0392] Optionally, the second parameter corresponds to the first session, that is, different sessions correspond to different counters, meaning the terminal device uses different counters to count data packets for different sessions.
[0393] Optionally, the second parameter corresponds to the first quality of service flow of the first session. That is, different quality of service flows correspond to different counters, meaning that the terminal device uses different counters to count data packets transmitted based on different quality of service flows.
[0394] Therefore, by using different keys and different second parameters, user plane data for different sessions can be securely protected, and there is no reuse of key streams or message authentication codes.
[0395] In another possible implementation (referred to as implementation B), step 501, the terminal device obtains the first key based on the identifier of the first session between the terminal device and the user plane network element, including: the terminal device obtains the first key based on the identifier of the first session and the identifier of the first quality of service flow in the first session.
[0396] In this implementation, different quality of service streams between the terminal device and the user plane network element correspond to different keys. Therefore, user plane data transmitted based on different quality of service streams can be securely protected by different keys. There is no reuse of key streams or message authentication codes, which can effectively prevent replay attacks.
[0397] The identifier of the first quality of service flow can be the QFI of the first quality of service flow.
[0398] For example, the terminal device obtains the first key based on the terminal device's long-term key, the identifier of the first session, and the identifier of the first quality of service flow. The long-term key is a key stored in the terminal device; for example, it could be a key stored in the terminal device's USIM.
[0399] For example, the terminal device obtains a session key based on its long-term key and the identifier of the first session, and then obtains a first key based on the session key and the identifier of the first quality of service flow corresponding to the first quality of service flow. The actions of the terminal device obtaining the session key based on its long-term key and the identifier of the first session, and obtaining the first key based on the session key and the identifier of the first quality of service flow corresponding to the first quality of service flow, can be continuous or discontinuous; they can be completed in one process or in different processes. For instance, the terminal device can first deduce the session key during session creation, and then deduce the first key during the creation of the quality of service flow.
[0400] Taking the key derivation process shown in Figure 2 as an example, the terminal device can obtain intermediate keys CK and IK based on the long-term key K stored in the USIM. Then, based on the intermediate keys CK and IK, it can obtain the corresponding anchor keys KAUSF and KSEAF. KSM is then derived through KSEAF, and the first key is derived based on KSM, the identifier of the first session, and the identifier of the first quality of service flow in the first session. Alternatively, the terminal device can derive KSM based on KAUSF, or KAMF through KSEAF, and then derive the first key through KAMF, the identifier of the first session, and the identifier of the first quality of service flow in the first session. The derivation method for the user plane key or session key is not limited here.
[0401] It should be understood that in implementation method B, the derivation process of the first key used by the user plane network element to perform user plane security processing on the second data in step 505 is the same as the method by which the terminal device derives the first key. For example, the core network element can derive the first key according to the method by which the terminal device derives the first key and send the first key to the user plane network element.
[0402] Based on the above implementation method B, step 502, where the terminal device performs user plane security protection on the first data according to the first key, may include: the terminal device performs user plane security protection on the first data according to the first key and a third parameter, wherein the third parameter is used to indicate the value of the counter corresponding to the data packet carrying the first data / second data, and the counter is used to count the data packets corresponding to the first quality of service flow in the first session.
[0403] Correspondingly, step 505 involves the user plane network element performing user plane security processing on the second data based on the first key, including: the user plane network element performing user plane security processing on the first data based on the first key and the third parameter.
[0404] The third parameter indicates the value of the counter corresponding to the data packet carrying the first data / second data. This counter can be used to count data packets corresponding to the first quality of service flow in the first session. Different quality of service flows correspond to different counter values. For example, the terminal device and the user plane network element maintain two counter values for a session of the terminal device: an uplink counter and a downlink counter. The uplink counter is used to count uplink data packets in the first session, and the downlink counter is used to count downlink data packets in the first session. The value of the counter indicated by the third parameter is the value of the uplink counter.
[0405] For example, the terminal device and the user plane network element maintain uplink counter A and uplink counter B, respectively. The terminal device sequentially sends data packet #1 and data packet #2 based on the first quality of service flow. Data packet #2 is a data packet carrying first data / second data. After sending data packet #1, the terminal device updates the value of uplink counter A, such as by incrementing it by 1, and uses this updated value as a third parameter for user plane security protection of the first data. After sending data packet #2, the terminal device updates the value of uplink counter A again. Correspondingly, after receiving data packet #2, the user plane network element updates the value of uplink counter B, such as by incrementing it by 1, and uses this updated value as a third parameter for user plane security processing of the second data.
[0406] Next, the process of user plane security protection and user plane security processing will be described. When user plane security protection includes confidentiality protection, the aforementioned step 502, where the terminal device performs user plane security protection on the first data based on the first key, may include:
[0407] G1. The terminal device obtains the first confidentiality protection key based on the first key;
[0408] G2. The terminal device obtains the first key stream based on the first confidentiality protection key;
[0409] G3. The terminal device encrypts the first data according to the first key stream to obtain the first ciphertext, and the second data includes the first ciphertext.
[0410] The terminal device obtains the first confidentiality protection key based on the first key. Here, it is not limited that the terminal device can also use other input parameters besides the first key to obtain the first confidentiality protection key. For example, other input parameters may include at least one of the following: cryptographic algorithm identifier, security protection / processing method indication (e.g., indicating different security protection / security processing methods such as encryption, integrity protection, encryption and integrity protection, AEAD, etc.).
[0411] The terminal device obtains a first key stream based on a first confidentiality protection key. Since the first key corresponds to a first session, different keys can be obtained through different sessions, thereby generating different key streams and ensuring that the key streams are not reused. The first key stream is used to encrypt the first data, thereby achieving confidentiality protection for the first data.
[0412] For example, the terminal device inputs a first key (key), a first parameter, a second parameter, a transmission direction parameter, and a length parameter into the encryption algorithm NEA, outputs a first key stream, and then performs an XOR operation between the output first key stream and first data. Through a first session, the corresponding first ciphertext can be output. The user plane network element receives this first ciphertext through the first session between the user plane network element and the terminal device. For example, the first key (key) is a session-level key, the first parameter is the QoS flow identifier (QFI), and the second parameter is the value of the uplink data packet counter corresponding to the session.
[0413] Accordingly, when the terminal device executes steps G1 to G3, for example, the second data includes: the first ciphertext, and the aforementioned step 505, where the user plane network element performs user plane security processing on the second data according to the first key, may include:
[0414] H1. The user plane network element obtains the first confidentiality protection key based on the first key;
[0415] H2. The user plane network element obtains the first key stream based on the first confidentiality protection key;
[0416] H3. The user plane network element decrypts the first ciphertext according to the first key stream to obtain the first data.
[0417] The user plane network element obtains the first confidentiality protection key based on the first key. Here, it is not limited that the user plane network element can also use other input parameters besides the first key to obtain the first confidentiality protection key. For example, other input parameters may include at least one of the following: cryptographic algorithm identifier, security protection / processing method indication (e.g., indicating different security protection / security processing methods such as encryption, integrity protection, encryption and integrity protection, AEAD, etc.).
[0418] In this case, the first confidentiality protection key obtained by the terminal device in G1 is the same as the first confidentiality protection key obtained by the user plane network element in H1. The parameters used by the terminal device in G1 to obtain the first confidentiality protection key can be the same as the parameters used by the user plane network element in H1 to obtain the first confidentiality protection key.
[0419] The user plane network element obtains a first key stream based on the first confidentiality protection key. Since the first key corresponds to the first session, different keys can be obtained through different sessions, thus generating different key streams and ensuring that the key stream is not reused. The first key stream is used to decrypt the first ciphertext, for example, by performing an XOR operation on the first key stream and the first ciphertext, thereby obtaining the first data through decryption.
[0420] For example, the user plane network element inputs a first key (key), a first parameter, a second parameter, a transmission direction parameter, and a length parameter into the encryption algorithm NEA, outputs a first key stream, and then performs an XOR operation between the output first key stream and the first ciphertext to output the corresponding first data to the data network. For example, the first key (key) can be a session-level key, the first parameter can be the QoS flow identifier (QFI), and the second parameter can be the value of the uplink packet counter corresponding to the session.
[0421] When user plane security protection includes integrity protection, the aforementioned step 502, where the terminal device performs user plane security protection on the first data based on the first key, may include:
[0422] I1. The terminal device obtains the first integrity protection key based on the first key;
[0423] I2. The terminal device obtains a first message authentication code based on the first integrity protection key and the first data, and the second data includes the first message authentication code.
[0424] The terminal device obtains the first integrity protection key based on the first key. This is not limited to the terminal device using other input parameters besides the first key to obtain the first integrity protection key. For example, other input parameters may include at least one of the following: cryptographic algorithm identifier, security protection / processing method indication (e.g., indicating different security protection / processing methods such as encryption, integrity protection, encryption and integrity protection, AEAD, etc.).
[0425] The terminal device obtains a first message authentication code based on a first integrity protection key and first data. Since the first key corresponds to a first session, different keys can be obtained through different sessions, thereby generating different message authentication codes and ensuring that the message authentication code is not reused. The first integrity protection key is used to protect the integrity of the first data, thus achieving integrity protection for the first data.
[0426] For example, during integrity protection, the terminal device inputs a first key, a first parameter, a second parameter, a message, and a transmission direction parameter into the integrity protection algorithm (NIA). It then outputs a corresponding first message authentication code through a first session. The user plane network element receives this first message authentication code through the first session between the user plane network element and the terminal device. For instance, the first key is a session-level key, the first parameter is the QoS flow identifier (QFI), and the second parameter is the value of the uplink data packet counter corresponding to the session.
[0427] Accordingly, when the terminal device executes the aforementioned steps I1 and I2, for example, the second data includes: a first message authentication code, and the aforementioned step 505, where the user plane network element performs user plane security processing on the second data based on the first key, may include:
[0428] J1. The user plane network element obtains the first integrity protection key based on the first key;
[0429] J2. The user plane network element obtains the third message authentication code based on the first integrity protection key;
[0430] J3. The user plane network element obtains the first message authentication code from the second data, and obtains the integrity verification result based on the first message authentication code and the third message authentication code received by the user plane network element from the terminal device.
[0431] The user plane network element obtains the first integrity protection key based on the first key. Here, it is not limited that the user plane network element can also use other input parameters besides the first key to obtain the first integrity protection key. Other input parameters may include at least one of the following: cryptographic algorithm identifier, security protection / processing method indication (e.g., indicating different security protection / security processing methods such as encryption, integrity protection, encryption and integrity protection, AEAD, etc.).
[0432] The first integrity protection key obtained by the terminal device in I1 is the same as the first integrity protection key obtained by the user plane network element in J1. The parameters used by the terminal device in I1 to obtain the first integrity protection key can be the same as the parameters used by the user plane network element in J1 to obtain the first integrity protection key.
[0433] For example, during integrity verification, the user plane network element inputs a first key (key), a first parameter, a second parameter, a message (MESSAGE), and a transmission direction parameter into the Integrity Protection Algorithm (NIA) to calculate a third message authentication code. For instance, the first key (key) is a session-level key, the first parameter is the QoS Flow Identifier (QFI), and the second parameter is the value of the uplink packet counter corresponding to the session. After calculating the third message authentication code, the user plane network element compares the first message authentication code received from the terminal device with the third message authentication code calculated by the user plane network element. If the first message authentication code and the third message authentication code are the same, the integrity verification is successful; if they are different, the integrity verification fails.
[0434] When user plane security protection includes encryption and integrity protection, the aforementioned step 502, where the terminal device performs user plane security protection on the first data based on the first key, may include:
[0435] K1. The terminal device obtains a second key stream based on the first key, and encrypts the first data based on the second key stream to obtain the second ciphertext;
[0436] K2. The terminal device obtains the second message authentication code based on the first key and the first data;
[0437] The second data includes the second ciphertext and the second message authentication code.
[0438] It is understood that there is no agreed-upon execution order between steps K2 and K1. Step K2 can be executed before or after K1, or both can be executed simultaneously, depending on the application scenario. No specific restrictions are imposed here. In the scenario where K2 is executed before K1, the terminal device may also obtain a second message authentication code based on the first key and the second ciphertext in step K2. In this case, the terminal device uses the Authenticated Encryption Associated Data (AEAD) algorithm to protect the data. It is not limited here whether the input for obtaining the message authentication code is the first data or the second ciphertext.
[0439] The terminal device obtains the second key stream based on the first key. Here, it is not limited that the terminal device can also use other input parameters besides the first key to generate the second key stream. Other input parameters include: cryptographic algorithm identifier, security protection / processing method indication (e.g., indicating different security protection / security processing methods such as encryption, integrity protection, encryption and integrity protection, AEAD, etc.).
[0440] Since the first key corresponds to the first session, different keys can be obtained through different sessions, thus generating different keystreams. This ensures that the keystreams are not reused. The second keystream is used to encrypt the first data, thereby protecting the confidentiality of the first data. Similarly, since the first key corresponds to the first session, different keys can be obtained through different sessions, thus generating different message authentication codes. This ensures that the message authentication codes are not reused. The first key is used to protect the integrity of the first data, thereby achieving integrity protection for the first data.
[0441] When the terminal device executes the aforementioned steps K1 and K2, the first data includes: the second ciphertext and the second message authentication code; correspondingly, the aforementioned step 505, where the user plane network element performs user plane security processing on the second data based on the first key, may include:
[0442] L1. The user plane network element obtains the second key stream based on the first key, and decrypts the second ciphertext based on the second key stream to obtain the second plaintext;
[0443] L2. The user plane network element obtains the fourth message authentication code based on the first key;
[0444] L3. The user plane network element obtains the integrity verification result based on the second message authentication code and the fourth message authentication code.
[0445] It is understood that there is no agreed-upon execution order between steps L1 and L2-L3. Step L1 can be executed first, followed by steps L2 and L3; steps L2-L3 can be executed first, followed by step L1; or steps L1 and L2-L3 can be executed simultaneously, depending on the application scenario. No specific restrictions are imposed here. In the scenario where L1 is executed first, followed by L2 and L3, the user plane network element in step L2 may also obtain the fourth message authentication code based on the first key and the second ciphertext. In this case, the user plane network element uses the AEAD algorithm to verify the data integrity. Here, it is not limited whether the input for obtaining the message authentication code is the first data or the second ciphertext.
[0446] In this process, since the first key corresponds to the first session, different keys can be obtained through different sessions, thus generating different keystreams. This ensures that the keystreams are not reused. The second keystream is used to decrypt the first data, thereby protecting the confidentiality of the first data. The user plane network element obtains the fourth message authentication code based on the first key. Since the first key corresponds to the first session, different keys can be obtained through different sessions, thus generating different message authentication codes. This ensures that the message authentication codes are not reused. The first key is used to protect the integrity of the first data, thereby achieving the integrity protection of the first data.
[0447] The following example illustrates the security protection process for the terminal device. For instance, the terminal device inputs a first key (key), a first parameter, a second parameter, a transmission direction parameter, a length parameter, and a message (MESSAGE) into the AEAD algorithm to obtain the second ciphertext and the second message authentication code. The terminal device then sends second data through the first session. This second data includes the second ciphertext and the second message authentication code. For example, the first key (key) is a session-level key, the first parameter is the QoS flow identifier (QFI), and the second parameter is the value of the uplink data packet counter corresponding to the session.
[0448] Accordingly, the process of security protection for user plane network elements is illustrated with an example. For instance, the user plane network element inputs a first key (key), a first parameter, a second parameter, a transmission direction parameter, a length parameter, and a message (MESSAGE) into the AEAD algorithm to obtain a second plaintext and a fourth message authentication code. The user plane network element can obtain the integrity verification result based on the second message authentication code received from the terminal device and the fourth message authentication code calculated by the user plane network element. For example, the first key (key) is a session-level key, the first parameter is the QoS flow identifier (QFI), and the second parameter is the value of the uplink data packet counter corresponding to the session.
[0449] In some embodiments of this application, confidentiality protection and integrity protection can be two separate security measures, and they can also be related. For example, the terminal device first performs confidentiality protection on the first data to obtain the first ciphertext, and then performs integrity protection on the first ciphertext, outputting the first message authentication code. Correspondingly, after receiving the first message authentication code, the user plane network element first uses the received first ciphertext to perform integrity verification. After passing the integrity verification, it then decrypts the received first ciphertext to obtain the first data.
[0450] In some embodiments of this application, in addition to performing the aforementioned steps, the data transmission method performed by the user plane network element also includes:
[0451] M1, the user plane network element obtains the parameter information corresponding to the first session, and the parameter information is used to indicate the transmission parameters of the first data.
[0452] When user plane network elements perform security protection, in addition to using the first key, they can also use the parameter information corresponding to the first session. The parameter information is used to indicate the transmission parameters of the first data. These transmission parameters are the parameters configured by the terminal device when sending user plane data through the first session.
[0453] Furthermore, in some embodiments of this application, step M1, where the user plane network element obtains parameter information corresponding to the first session, includes:
[0454] M11. The user plane network element obtains the second information, which is used to indicate the parameter information corresponding to the first session.
[0455] M12, the user plane network element obtains the parameter information corresponding to the first session based on the second information.
[0456] In this embodiment, the core network element can obtain the second information and then send it to the user plane network element. The user plane network element then obtains the parameter information corresponding to the first session based on the second information. For example, the core network element can be an SMF network element, an AMF network element, a SEAF network element, or an AUSF network element. This application embodiment does not limit the core network element that provides the parameter information corresponding to the first session to the user plane network element. For example, the second information sent by the core network element to the SMF network element can be one or more of the following: the identifier of the terminal device sent through the N4 session, the identifier of the first session, packet detection rule information, and packet forwarding rule information. The parameter information corresponding to the first session includes a first parameter and / or a second parameter. For example, the second information obtained by the user plane network element is the identifier of the receiving terminal device and the identifier of the first session. Based on the identifier, the user plane network element can obtain the information of the corresponding first session associated with the COUNT value, that is, obtain the information of the second parameter. Another example is that the second information obtained by the user plane network element is the packet detection rule corresponding to the received uplink data packet. Based on the packet detection rule, the QoS flow information corresponding to the uplink data packet can be determined, thereby obtaining the QFI information of the QoS flow, that is, the information of the first parameter. Yet another example is that the second information received by the user plane network element can be information carried in the uplink data packet itself, such as the QFI information carried in the header of the uplink data packet sent by the wireless network device, thereby obtaining the information of the first parameter.
[0457] Furthermore, in some embodiments of this application, in addition to performing the aforementioned steps, the data transmission method executed by the terminal device further includes:
[0458] N1. The terminal device obtains the parameter information corresponding to the first session. The parameter information is used to indicate the transmission parameters of the first data.
[0459] Furthermore, in some embodiments of this application, the parameter information corresponding to the first session includes, but is not limited to, one or more of the following:
[0460] The first parameter corresponds to the first session; and / or, the first parameter corresponds to the first quality of service flow identifier, which is the identifier of the first quality of service flow; and / or, the first parameter corresponds to the first data radio bearer, which is used to carry the first data transmitted over the air interface of the first session; and / or, the first parameter corresponds to the first Internet Protocol (IP) address of the terminal device.
[0461] The third parameter indicates the value of the counter corresponding to the data packet carrying the first data. The counter is used to count the data packets corresponding to the first quality of service flow.
[0462] Transmission direction parameter: The transmission direction parameter is used to indicate whether the transmission direction is uplink or downlink;
[0463] The length parameter indicates the length of the key stream used for confidentiality protection, which can be the same as the length of the first data.
[0464] Since different Quality of Service (QoS) flows between the terminal device and the user plane network element correspond to different keys, different keys can be used to protect the user plane data of different sessions. When the input for security protection is the first parameter, the granularity of the first parameter can be various, such as the granularity of the first parameter corresponding to the session, or the granularity of the QoS flow identifier, or the granularity of the data radio bearer, or the granularity of the terminal device. There are multiple ways to implement the first parameter, and the first parameter can be flexibly selected according to the application scenario.
[0465] The third parameter, transmission direction parameter, and length parameter are similar to those in the previous embodiments, and will not be repeated here.
[0466] Please refer to Figure 6, which is a flowchart illustrating a data transmission method provided in an embodiment of this application. The difference between Figure 6 and Figure 5 is that Figure 5 uses uplink data transmission between a terminal device and a user plane network element as an example, while Figure 6 uses downlink data transmission between a user plane network element and a terminal device as an example. The data transmission method provided in this embodiment mainly includes the following steps:
[0467] 601. The user plane network element obtains the second key based on the identifier of the second session between the user plane network element and the terminal device.
[0468] In this embodiment, user plane network elements can store keys corresponding to multiple sessions. For example, core network elements can deduce the keys corresponding to multiple sessions.
[0469] 602. The user plane network element performs user plane security protection on the third data based on the second key, and obtains the fourth data.
[0470] In this embodiment, after obtaining the second key, the user plane network element performs user plane security protection on the third data based on the second key to obtain the fourth data. This user plane security protection can be simply referred to as security protection. In this embodiment, user plane security protection may include confidentiality protection and / or integrity protection.
[0471] 603. The user plane network element sends the fourth data through the second session.
[0472] In this embodiment, the user plane network element can obtain the fourth data by performing step 602. The user plane network element can send the fourth data through a second session. For example, the user plane network element can send the fourth data to the terminal device through the second session.
[0473] 604. The terminal device receives the fourth data through a second session between the terminal device and the user plane network element.
[0474] There is a second session between the user plane network element and the terminal device. The terminal device can receive fourth data from the user plane network element through the second session. The fourth data can be the fourth data sent by the user plane network element in step 603.
[0475] 605. The terminal device performs user plane security processing on the fourth data according to the second key to obtain the third data.
[0476] In this embodiment of the application, the terminal device can store keys corresponding to multiple sessions. For example, the terminal device can deduce the keys corresponding to multiple sessions.
[0477] The following example illustrates the implementation of steps 601 to 605 as shown in Figure 6.
[0478] In step 602, referring to the key derivation process described in Figure 2, after the core network element obtains multiple keys, it sends the keys corresponding to multiple sessions to the user plane network element. In this embodiment, the third data corresponds to the second key, and it is necessary to ensure that different sessions correspond to different keys.
[0479] In some embodiments of this application, step 601, in which the user plane network element obtains the second key based on the identifier of the second session between the user plane network element and the terminal device, includes:
[0480] The user plane network element obtains the second key based on the identifier of the second session and the identifier of the second quality of service flow in the second session.
[0481] After obtaining the identifier of the second session, the user plane network element obtains the second key based on the identifier of the second session and the identifier of the second quality of service flow. For example, the identifier of the second quality of service flow can be a second quality of service flow identifier. The second key can be obtained by using the key derivation process shown in Figure 2. Optionally, the second key can be a user plane key or a session key. The derivation method of the user plane key or the session key is not limited here.
[0482] In this embodiment, different Quality of Service (QoS) streams between the terminal device and the user plane network element correspond to different keys. Therefore, different keys can be used to protect user plane data for different sessions, preventing the reuse of key streams or message authentication codes. Protecting user plane data with different keys effectively prevents replay attacks.
[0483] In step 602, the terminal device performs security protection on the third data according to the second key and the security policy corresponding to the second session. This protection can include confidentiality protection and / or integrity protection based on the security policy. For example, in confidentiality protection, the user plane network element can generate a key stream based on the second key and then encrypt the third data based on the key stream. Similarly, in integrity protection, the user plane network element can generate a message authentication code based on the second key. Optionally, the user plane network element can deduce a second encryption key and a second integrity protection key based on the second key. In confidentiality protection, the user plane network element can generate a key stream based on the second encryption key and then encrypt the third data based on the key stream; in integrity protection, the terminal device can generate a message authentication code based on the second integrity protection key.
[0484] In some embodiments of this application, in step 602, the user plane network element performs user plane security protection on the third data according to the second key to obtain the fourth data, including:
[0485] The user plane network element performs user plane security protection on the third data based on the second key and the parameter information corresponding to the second session. The parameter information corresponding to the second session is used to indicate the transmission parameters of the third data.
[0486] When user plane network elements perform security protection, in addition to using the second key, they can also use the parameter information corresponding to the second session. This parameter information is used to indicate the transmission parameters of the third data. These transmission parameters are the parameters configured by the user plane network element when sending user plane data through the second session. There are several ways to implement these transmission parameters; for example, the transmission parameters can be configuration parameters for transmitting user plane data through the second session.
[0487] In some embodiments of this application, the parameter information corresponding to the second session includes, but is not limited to, one or more of the following:
[0488] The fourth parameter is used to indicate the second quality of service flow in the second session, which is used for the transmission of the third data.
[0489] The fifth parameter indicates the value of the counter corresponding to the data packet carrying the third data. The counter is used to count data packets in the second session.
[0490] The fourth parameter indicates the second Quality of Service (QoS) flow corresponding to the second session. The second session corresponds to multiple QoS flows, including the second QoS flow. For example, the fourth parameter can be implemented in various ways; any parameter capable of indicating the second QoS flow corresponding to the second session can be used as the fourth parameter. In one example, the fourth parameter can be a bearer; however, its implementation is not limited to bearers, and it is implemented at the QoS flow granularity. In this embodiment, the fourth parameter is not limited to QoS flow granularity; for example, it can also be implemented at the DRB granularity. The implementation method of the fourth parameter is not limited.
[0491] For example, the fifth parameter is used to indicate the value of the downlink counter corresponding to the downlink data packet used to carry the third data. The downlink counter is used to count downlink data packets in the second session. For example, the terminal device and the user plane network element maintain the values of two counters for a session of the terminal device, namely the values of the uplink counter and the downlink counter. Optionally, when the user plane network element sends a downlink data packet, the fifth parameter is used to indicate the value of the downlink counter.
[0492] For example, the fifth parameter is at the PDU session level. Therefore, by using different keys and counters at the PDU session level, user plane data for different sessions can be securely protected, preventing the reuse of keystreams or message authentication codes. Using different keys to secure user plane data effectively prevents replay attacks. Optionally, the fifth parameter can be a counter maintained on the user plane network element side.
[0493] The transmission direction parameter indicates whether the transmission direction is uplink or downlink. In this embodiment, the value of the transmission direction parameter is not limited. For example, when the transmission direction is uplink, the value of the transmission direction parameter can be 1; when the transmission direction is downlink, the value of the transmission direction parameter can be 0. Furthermore, the transmission direction parameter must correspond to the uplink counter or downlink counter in the fourth parameter. In this embodiment, the value of the transmission direction is not limited.
[0494] The length parameter indicates the length of the key stream used for confidentiality protection, which can be the same as the length of the first data.
[0495] Optionally, in some embodiments of this application, the fourth parameter includes an identifier of the second Quality of Service (QoS) flow. For example, the fourth parameter is at the granularity of a QoS flow identifier, so different keys and different fourth parameters can be used to securely protect user plane data for different sessions, without reusing keystreams or message authentication codes. Using different keys to securely protect user plane data effectively prevents replay attacks.
[0496] In this embodiment, the user plane network element can obtain the fourth data by performing step 602. In step 603, the user plane network element can send the fourth data through a second session. For example, the user plane network element can send the fourth data to the terminal device through the second session. In this embodiment, different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, different keys can be used to protect the user plane data of different sessions, preventing key stream reuse or message authentication code duplication. By using different keys to protect the user plane data, key stream reuse and replay attacks are effectively prevented.
[0497] In step 604, a second session exists between the user plane network element and the terminal device. The terminal device can receive fourth data from the user plane network element through this second session. This fourth data may be the fourth data sent by the user plane network element in step 603. Optionally, the terminal device can receive the fourth data sent by the user plane network element through a wireless network device. Optionally, the fourth data may be second downlink data, which refers to user plane data sent by the user plane network element to the terminal device.
[0498] In step 605, the terminal device can store keys corresponding to multiple sessions. For example, the terminal device can deduce keys corresponding to multiple sessions, as detailed in the key deduction process in Figure 2. The terminal device obtains multiple keys, such as a second key corresponding to the second session. Different keys correspond to different sessions between the terminal device and the user plane network element, thereby avoiding key duplication.
[0499] For example, the terminal device obtains the downlink data packet of the third data from the DRB. Based on the session information corresponding to the DRB, it can determine the corresponding second session, and thus determine the second key corresponding to the second session.
[0500] In some embodiments of this application, step 605, the terminal device performs user plane security processing on the fourth data based on the second key, including:
[0501] The terminal device performs user plane security processing on the fourth data based on the second key and the parameter information corresponding to the second session. The parameter information corresponding to the second session is used to indicate the parameters for transmitting the fourth data.
[0502] When the terminal device performs security protection, in addition to using the second key, it can also use the parameter information corresponding to the second session. The parameter information corresponding to the second session is used to indicate the transmission parameters of the fourth data. These transmission parameters are the parameters configured by the user plane network element when sending user plane data through the second session.
[0503] For example, after receiving third data from a user plane network element, the terminal device obtains the second key and corresponding parameter information for the second session. This second session parameter information may include parameters for the fourth data transmission. The terminal device then uses the second key and this parameter information to decrypt and / or verify the integrity of the fourth data to obtain the third data. Optionally, the terminal device determines the QFI (Quality Filter Information) corresponding to the downlink data packet based on the DRB (Diagram Block Designation) and the correspondence between the DRB and QoS (Quality of Service). Based on the second session corresponding to the downlink data packet, the terminal device can obtain the value of the downlink counter maintained by the terminal device for the second session, i.e., the fifth parameter information.
[0504] In some embodiments of this application, in step 602, the user plane network element performs user plane security protection on the third data according to the second key to obtain the fourth data, including:
[0505] The user plane network element performs user plane security protection on the third data based on the second key and the sixth parameter. The sixth parameter is used to indicate the value of the counter corresponding to the data packet used to carry the third data. The counter is used to count the data packets corresponding to the second quality of service flow.
[0506] Optionally, the user plane network element obtains a sixth parameter, which indicates the value of a counter corresponding to the data packet carrying the third data. This counter can be used to count downlink data packets corresponding to the second quality of service flow in the second session. Different quality of service flows correspond to different counter values. For example, the terminal device and the user plane network element maintain two counter values for a session of the terminal device: an uplink counter and a downlink counter. Optionally, when the user plane network element sends a downlink data packet, the sixth parameter indicates the value of the downlink counter. The user plane network element performs user plane security protection on the third data based on the second key and the sixth parameter. Therefore, different keys can be used to protect user plane data in different sessions, preventing the reuse of key streams or message authentication codes. Using different keys to protect user plane data effectively prevents replay attacks.
[0507] In some embodiments of this application, step 605, the terminal device performs user plane security processing on the third data based on the second key, including:
[0508] The terminal device performs user plane security processing on the third data based on the second key and the sixth parameter. The sixth parameter is used to indicate the value of the counter corresponding to the data packet carrying the third data. The counter is used to count the data packets corresponding to the second quality of service flow in the second session.
[0509] Optionally, the terminal device obtains a sixth parameter, which indicates the value of a counter corresponding to the data packet carrying the third data. This counter can be used to count downlink data packets corresponding to the second quality of service flow in the second session. Different quality of service flows correspond to different counter values. For example, the terminal device and the user plane network element maintain two counter values for one session of the terminal device: an uplink counter and a downlink counter. Optionally, when the terminal device receives a downlink data packet, the sixth parameter indicates the value of the downlink counter. The user plane network element performs user plane security protection on the third data based on the second key and the sixth parameter. Therefore, different keys can be used to protect user plane data in different sessions, preventing the reuse of key streams or message authentication codes. Using different keys to protect user plane data effectively prevents replay attacks.
[0510] Optionally, user plane security protection includes encryption, whereby the user plane network element performs user plane security protection on the third data based on the second key, including:
[0511] The user plane network element obtains the second confidentiality protection key based on the second key;
[0512] User plane network elements obtain the third key stream based on the second confidentiality protection key;
[0513] The user plane network element encrypts the third data according to the third key stream to obtain the third ciphertext, and the fourth data includes the third ciphertext.
[0514] In the above scheme, the user plane network element can obtain the second confidentiality protection key through the second key. The second confidentiality protection key is used to encrypt the third data, thereby realizing end-to-end confidentiality protection of the third data between the terminal device and the user plane network element.
[0515] Optionally, the fourth data includes the third ciphertext, and the terminal device performs user plane security processing on the fourth data based on the second key, including:
[0516] The terminal device obtains the second confidentiality protection key based on the second key;
[0517] The terminal device obtains the third key stream based on the second confidentiality protection key;
[0518] The terminal device decrypts the third ciphertext based on the third key stream to obtain the third plaintext.
[0519] In the above scheme, the terminal device can obtain the second confidentiality protection key through the second key. The second confidentiality protection key is used to decrypt the third ciphertext, thereby realizing the confidentiality protection of the third data between the terminal device and the user plane network element.
[0520] Optionally, user plane security protection includes integrity protection. The user plane network element performs user plane security protection on the third data based on the second key, including:
[0521] The user plane network element obtains the second integrity protection key based on the second key;
[0522] The user plane network element obtains the fifth message authentication code based on the second integrity protection key and the third data, and the fourth data includes the fifth message authentication code.
[0523] In the above scheme, the user plane network element can obtain the second integrity protection key through the second key. The second integrity protection key is used to protect the integrity of the third data, thereby realizing end-to-end integrity protection of the third data between the terminal device and the user plane network element.
[0524] Optionally, the fourth data includes a fifth message authentication code. The terminal device performs user plane security processing on the fourth data based on the second key, including:
[0525] The terminal device obtains the second integrity protection key based on the second key;
[0526] The terminal device obtains the seventh message authentication code based on the second integrity protection key;
[0527] The terminal device obtains the fifth message authentication code from the fourth data, and obtains the integrity verification result based on the fifth message authentication code and the seventh message authentication code.
[0528] In the above scheme, the terminal device can obtain the second integrity protection key through the second key. The second integrity protection key is used to obtain the seventh message verification code. Integrity verification can be performed through the fifth message authentication code and the seventh message authentication code in the fourth data, thereby realizing the integrity protection of the third data between the terminal device and the user plane network element.
[0529] Optionally, user plane security protection includes encryption and integrity protection. The user plane network element performs user plane security protection on the third data based on the second key, including:
[0530] The user plane network element obtains the fourth key stream based on the second key, and encrypts the third data based on the fourth key stream to obtain the fourth ciphertext;
[0531] The user plane network element obtains the sixth message authentication code based on the second key and the third data;
[0532] The third data includes the fourth ciphertext and the sixth message authentication code.
[0533] In the above scheme, the user plane network element can use the second key to protect the confidentiality and integrity of the third data, thereby achieving end-to-end confidentiality and integrity protection of the third data between the terminal device and the user plane network element.
[0534] Optionally, the fourth data includes a fourth ciphertext and a sixth message authentication code. The terminal device performs user plane security processing on the fourth data based on the second key, including:
[0535] The terminal device obtains a fourth key stream based on the second key, and decrypts the fourth ciphertext based on the fourth key stream to obtain the fourth plaintext;
[0536] The terminal device obtains the eighth message authentication code based on the second key;
[0537] The terminal device obtains the integrity verification result based on the sixth and eighth message authentication codes.
[0538] In the above scheme, the terminal device can protect the confidentiality and integrity of the third data through the second key, thereby achieving end-to-end confidentiality and integrity protection of the third data between the terminal device and the user plane network element.
[0539] As illustrated by the foregoing embodiments, in this application, different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, different keys can be used to protect the user plane data of different sessions, preventing the reuse of key streams or message authentication codes. Protecting user plane data with different keys effectively prevents replay attacks.
[0540] Please refer to Figure 7, which is a flowchart illustrating a data transmission method provided in an embodiment of this application. Taking the transmission of uplink data between a terminal device and a user plane network element as an example, the data transmission method provided in this embodiment mainly includes the following steps:
[0541] 701. The terminal device obtains the first key corresponding to the terminal device.
[0542] In this embodiment, the terminal device and the first key correspond. For example, the first key can be obtained using the key derivation process shown in Figure 2. Optionally, the first key can be a user plane key or a session key. The derivation method for the user plane key or session key is not limited here.
[0543] 702. The terminal device performs user plane security protection on the first data according to the first key and the first parameter to obtain the second data. The first parameter is used to indicate the first session, or the first parameter is used to indicate the first quality of service flow in the first session. The first session is a session between the terminal device and the user plane network element.
[0544] 703. The terminal device sends the second data through the first session.
[0545] In this embodiment, the terminal device can obtain the second data by executing step 702. The terminal device can send the second data through the first session. In this embodiment, different terminal devices correspond to different keys. Therefore, by using different keys and the first parameter, user plane data of different sessions can be securely protected, preventing key stream reuse or message authentication code duplication. By using different keys and the first parameter to securely protect user plane data, key stream reuse and replay attacks are effectively prevented.
[0546] 704. The user plane network element receives the second data through the first session.
[0547] The second data is data after user plane security protection of the first data according to the first key and first parameters corresponding to the terminal device. The first parameters are used to indicate the first session, or the first parameters are used to indicate the first quality of service flow in the first session.
[0548] There is a first session between the user plane network element and the terminal device. The user plane network element can receive second data from the terminal device through the first session. The second data can be the second data sent by the terminal device in step 703.
[0549] 705. The user plane network element performs user plane security processing on the first data according to the first key and the first parameters to obtain the first data.
[0550] In this embodiment, the user plane network element can store keys corresponding to multiple terminal devices. For example, the core network element can deduce the keys corresponding to multiple terminal devices, as detailed in Figure 2. After obtaining multiple keys, the core network element sends the keys corresponding to the multiple terminal devices to the user plane network element. In this embodiment, the terminal device sending the first data corresponds to the first key, and different terminal devices correspond to different keys, thereby avoiding key duplication.
[0551] The user plane network element performs user plane security processing on the first data based on the first key and the first parameters, which is the reverse process of user plane security protection performed by the terminal device. Optionally, user plane security processing may refer to decryption and / or integrity verification.
[0552] The following example illustrates the implementation of steps 701 to 705 as shown in Figure 7.
[0553] In step 702, there can be multiple sessions between the terminal device and the user plane network element. For example, the multiple sessions may include a first session. The first parameter is used to indicate the first session between the terminal device and the user plane network element. For example, the first parameter includes the identifier of the first session. Alternatively, the first session may correspond to multiple Quality of Service (QoS) flows, and the multiple QoS flows may include the first QoS flow. The first parameter is used to indicate the first QoS flow in the first session. For example, the first parameter includes both the identifier of the first session and the identifier of the first QoS flow. In the embodiments of this application, the first parameter can be implemented in various ways. Any parameter that can indicate the first session or the first QoS flow can be used as the first parameter. In one example, the first parameter can be a bearer. However, it is not limited to the implementation of the first parameter as a bearer.
[0554] For an explanation of the first key and user plane security protection, please refer to the explanation of step 502 in the embodiment shown in Figure 5 above, which will not be repeated here.
[0555] In some embodiments of this application, step 702, where the terminal device performs user plane security protection on the first data based on the first key and the first parameters, includes:
[0556] The terminal device performs user plane security protection on the first data based on the first key, the first parameter, and the second parameter. The second parameter is used to indicate the value of the counter corresponding to the data packet carrying the first data. The counter is used to count the data packets in the first session.
[0557] In addition to the first key and the first parameter, the terminal device also needs to use a second parameter when performing user plane security protection. The second parameter indicates the value of a counter used to carry the first data packet for the first session. When the terminal device sends the uplink data packet, the second parameter corresponds to the uplink counter.
[0558] In some embodiments of this application, step 705, where the user plane network element performs user plane security processing on the first data based on the first key and first parameters corresponding to the terminal device, includes:
[0559] The user plane network element performs user plane security processing on the second data according to the first key, the first parameter, and the second parameter. The second parameter is used to indicate the value of the counter corresponding to the data packet carrying the second data. The counter is used to count the data packets in the first session.
[0560] In addition to the first key and the first parameter, the user plane network element also needs to use a second parameter when performing user plane security processing. The second parameter indicates the value of a counter used to carry the first data packet for the first session. For example, when the user plane network element receives an uplink data packet, the second parameter here corresponds to the uplink counter.
[0561] Optionally, the first parameter is used to indicate the first session between the terminal device and the user plane network element, including: the first parameter includes an identifier of the first session;
[0562] or,
[0563] The first parameter is used to indicate a first quality of service flow in the first session, including: the first parameter includes an identifier of the first quality of service flow and an identifier of the first session.
[0564] In the above scheme, the first parameter is at the level of the first session or at the level of the first quality of service flow. The first quality of service flow is used for the transmission of the first data. Therefore, the first parameter can be determined by the identifier of the first session, or by the identifier of the first session and the identifier of the first quality of service flow.
[0565] In this embodiment, different terminal devices correspond to different keys between the terminal device and the user plane network element. The first parameter indicates the first session between the terminal device and the user plane network element, or the first parameter is used to indicate the first quality of service flow in the first session. Therefore, by using different keys and the first parameter, user plane data in different sessions can be securely protected, preventing key stream reuse or message authentication code duplication. By using different keys to securely protect user plane data, key stream reuse and replay attacks are effectively prevented.
[0566] Please refer to Figure 8, which is a flowchart illustrating a data transmission method provided in an embodiment of this application. Taking downlink data transmission between a user plane network element and a terminal device as an example, the data transmission method provided in this embodiment mainly includes the following steps:
[0567] 801. The user plane network element obtains the second key corresponding to the terminal device.
[0568] In this embodiment, the user plane network element can store keys corresponding to multiple terminal devices. For example, the core network element can deduce the keys corresponding to multiple terminal devices, as detailed in Figure 2. After obtaining multiple keys, the core network element sends the keys corresponding to the multiple terminal devices to the user plane network element. In this embodiment, the second data corresponds to the second key, and it is necessary to ensure that different sessions correspond to different keys.
[0569] 802. The user plane network element performs user plane security protection on the third data according to the second key and the fourth parameter to obtain the fourth data. The fourth parameter is used to indicate the second session, or the fourth parameter is used to indicate the second quality of service flow in the second session. The fourth session is a session between the user plane network element and the terminal device.
[0570] There can be multiple sessions between the terminal device and the user plane network element. For example, the multiple sessions may include a second session, and the fourth parameter is used to indicate the second session. Alternatively, the second session may correspond to multiple Quality of Service (QoS) flows, and the multiple QoS flows may include the second QoS flow. The fourth parameter is used to indicate the second QoS flow in the second session. For example, the fourth parameter can be implemented in various ways; any parameter that can indicate the second session or the second QoS flow can be used as the fourth parameter. In one example, the fourth parameter can be a bearer, but it is not limited to the implementation of the fourth parameter as a bearer.
[0571] 803. The user plane network element sends the fourth data through the second session.
[0572] In this embodiment, the user plane network element can obtain the fourth data by executing step 802. The user plane network element can send the fourth data through a second session. For example, the user plane network element can send the fourth data to the terminal device through the second session. In this embodiment, different sessions between the terminal device and the user plane network element correspond to different keys. Therefore, different keys can be used to protect the user plane data of different sessions, preventing key stream reuse or message authentication code duplication. By using different keys to protect the user plane data, key stream reuse and replay attacks are effectively prevented.
[0573] 804. The terminal device receives the fourth data through a second session between the terminal device and the user plane network element.
[0574] There is a second session between the user plane network element and the terminal device. The terminal device can receive fourth data from the user plane network element through the second session. The fourth data can be the fourth data sent by the user plane network element in step 803.
[0575] 805. The terminal device performs user plane security processing on the fourth data based on the second key and the fourth parameter corresponding to the terminal device to obtain the third data.
[0576] The following example illustrates the implementation of steps 801 to 805 as shown in Figure 8.
[0577] In some embodiments of this application, the fourth parameter is used to indicate a second session between the terminal device and the user plane network element, including: the fourth parameter includes an identifier of the second session;
[0578] or,
[0579] The fourth parameter is used to indicate the second quality of service flow in the second session, and includes: the fourth parameter includes the identifier of the second quality of service flow and the identifier of the second session.
[0580] The fourth parameter is granular at the session level, for example, it includes the identifier of the second session; or it is granular at the session and quality of service flow level, for example, it includes the identifier of the second session and the identifier of the second quality of service flow. In this embodiment, different keys and the fourth parameter can be used to securely protect user plane data, thereby achieving key stream isolation and effectively preventing replay attacks.
[0581] For an explanation of the second key, the fourth parameter, and user plane security protection, please refer to the explanation of step 602 in the embodiment shown in Figure 6 above, which will not be repeated here.
[0582] In some embodiments of this application, step 802, the terminal device performs user plane security processing on the second data based on the second key and the fourth parameter corresponding to the terminal device, including:
[0583] The user plane network element performs user plane security protection on the second data based on the second key, the fourth parameter, and the fifth parameter. The fifth parameter is used to indicate the value of the counter corresponding to the data packet used to carry the third data. The counter is used to count the data packets in the second session.
[0584] In addition to the second key and the fourth parameter, the user plane network element also needs to use a fifth parameter when performing user plane security protection. The fifth parameter indicates the value of the counter corresponding to the data packet carrying the third data. This counter is used to count data packets in the second session. For example, the terminal device and the user plane network element maintain two counter values for a session of the terminal device: an uplink counter and a downlink counter. Optionally, when the user plane network element sends a downlink data packet, the fifth parameter indicates the value of the downlink counter.
[0585] In this embodiment, there can be multiple sessions between the terminal device and the user plane network element. For example, the multiple sessions may include a second session, and the fourth parameter is used to indicate the second session between the terminal device and the user plane network element. Alternatively, the second session may correspond to multiple Quality of Service (QoS) flows, and the multiple QoS flows may include the second QoS flow. The fourth parameter is used to indicate the second QoS flow in the second session. For example, the fourth parameter can be implemented in various ways; any parameter that can indicate the second session or the second QoS flow can be used as the fourth parameter. In one example, the fourth parameter can be a bearer, but it is not limited to the implementation of the fourth parameter as a bearer.
[0586] The methods for obtaining the second key and the fourth parameter can be found in step 605 above, and will not be repeated here.
[0587] In some embodiments of this application, step 805, the terminal device performs user plane security processing on the second data based on the second key and the fourth parameter corresponding to the terminal device, including:
[0588] The terminal device performs user plane security processing on the second data based on the second key, the fourth parameter, and the fifth parameter. The fifth parameter is used to indicate the value of the counter corresponding to the data packet carrying the fourth data. The counter is used to count data packets in the second session.
[0589] In addition to the second key and the fourth parameter, the terminal device also needs to use a fifth parameter when performing user plane security processing. The fifth parameter indicates the value of the counter corresponding to the data packet carrying the fourth data. This counter is used to count data packets in the second session. For example, the terminal device and the user plane network element maintain two counter values for a session of the terminal device: an uplink counter and a downlink counter. Optionally, when the terminal device receives a downlink data packet, the fifth parameter indicates the value of the downlink counter.
[0590] The method for obtaining the fifth parameter can be found in step 602 above, and will not be repeated here.
[0591] In this embodiment, different terminal devices correspond to different keys between the terminal device and the user plane network element. The fourth parameter indicates the second session between the terminal device and the user plane network element, or the fourth parameter is used to indicate the second quality of service flow in the second session. Therefore, by using different keys and the fourth parameter, user plane data in different sessions can be securely protected, preventing key stream reuse or message authentication code duplication. Using different keys to securely protect user plane data effectively prevents key stream reuse and replay attacks.
[0592] The embodiments of this application will now be described with detailed application scenario examples.
[0593] In this embodiment, confidentiality and integrity protection input parameters can be used to achieve security protection at the PDU session and QoS stream granularity.
[0594] In one implementation of this application, as shown in FIG9a, the first key corresponds to the identifier of the PDU session (PDU session ID), and the first parameter corresponds to the identifier of the QoS flow (QFI).
[0595] The following example illustrates the confidentiality and integrity protection of user plane data using the key deduction method shown in Figure 9a. Figure 9b shows a schematic diagram of key generation provided in an embodiment of this application; the main process includes:
[0596] S901. A PDU session is established between the terminal device and the user plane network element.
[0597] A PDU session is established between the terminal device and the user plane network element, and the terminal device performs security activation of the access layer (AS).
[0598] S902, the terminal device and the user plane network element respectively obtain the first key, the first parameter and the second parameter corresponding to the first session.
[0599] (1) First key.
[0600] In one embodiment of this application, the introduction of the first key will be illustrated below with reference to Figure 9a. Taking the first key corresponding to the identifier of a PDU session as an example, during the PDU session establishment process, the core network element performs key deduction to maintain a key for each PDU session of each terminal device. Additionally, the core network element can also send the key corresponding to each PDU session of each terminal device to the corresponding user plane network element. The terminal device obtains the first key through the same deduction rules.
[0601] In the key deduction process shown in Figure 9a, the arrows indicate that the upper key is used to deduce the lower key. The formula for key deduction can include:
[0602] newkey=KDF(oldkey, parameters, length of parameters);
[0603] Where oldkey represents the key above, newkey represents the key below derived from it, parameters represent the input parameters, and length of parameters represents the length parameter.
[0604] For example, as shown in Figure 2, the terminal device's USIM and UDM / ARPF sides store the terminal device's long-term key K. The terminal device registers with the network and performs identity authentication, i.e., primary authentication. After the primary authentication process, the corresponding anchor keys KAUSF and KSEAF can be derived using the intermediate keys CK and IK in the primary authentication process. The SEAF network element uses the key KSEAF to derive KSM, for example, KSM = KDF(KSEAF, session management). The SEAF network element sends KSM to the SMF network element. The SMF network element uses KSM to derive KPDUsession, for example, KPDUsession = KDF(KSM, PDUsession ID). The SMF network element sends KPDUsession to the user plane network element. Alternatively, the SEAF network element uses the key KSEAF to derive KSM and sends KSM to the SMF network element. The SMF network element directly uses KSM as the session key KPDUsession and sends it to the user plane network element. User plane network elements use KPDUsession to derive the user plane confidentiality key KUPenc and the user plane integrity key KUPint, for example, KUPenc = KDF(KPDUsession, confidentiality protection identifier), KUPint = KDF(KPDUsession, integrity protection identifier).
[0605] (2) First parameter.
[0606] The first parameter indicates the QoS flow in the PDU session, the first key corresponds to the PDU session granularity, and the first parameter is the QFI. Alternatively, not for security reasons, the first parameter is the DRB ID.
[0607] (3) Second parameter.
[0608] The second parameter indicates the value of the counter (COUNT).
[0609] In this application embodiment, the COUNT value can correspond to a PDU session, or the COUNT value can correspond to a QoS flow, as explained below:
[0610] For the COUNT corresponding to a PDU session, two COUNT values are maintained for each PDU session, one for counting uplink packets and the other for counting downlink packets. For example, the uplink COUNT is used to count uplink packets, and the downlink COUNT is used to count downlink packets. The COUNT value can be 32 bits or other bit types; there is no limitation here. When the COUNT value reaches its maximum value, the counter is toggled, and the key update process is triggered simultaneously. In the case of the COUNT corresponding to the PDU session, setting the first parameter to QFI is an optional scheme.
[0611] For the COUNT corresponding to a QoS flow, two COUNT values are maintained for each QFI in each session, counting uplink and downlink packets for that QoS flow respectively. For example, the uplink COUNT is used to count uplink packets, and the downlink COUNT is used to count downlink packets. The COUNT value can be 32 bits or other bit types, which are not limited here. When the COUNT value reaches its maximum value, it triggers a counter flip and simultaneously triggers a key update process. In the case of the COUNT corresponding to a QoS flow, the first parameter is the QFI. Therefore, when using the COUNT at the QoS flow granularity, the input parameter of the first parameter needs to include the QFI to distinguish different COUNTs.
[0612] In this embodiment of the application, in addition to the aforementioned first key, first parameter, and second parameter, the input for security protection may also include the following parameters:
[0613] (3) Transmission direction (DIRECTION) parameter.
[0614] The length of the transmission direction can be 1 bit, and the value of the transmission direction can be 0 or 1, representing the transmission direction as uplink and downlink, respectively.
[0615] (4) Length parameter.
[0616] Length refers to the length of the plaintext.
[0617] S903. The terminal device performs user plane security protection based on the first key, first parameter and second parameter corresponding to the first session, and sends uplink data after user plane security protection.
[0618] For example, the terminal device uses the first key as input for user plane security protection, such as as input parameters for user plane encryption and integrity protection algorithms. User plane security protection may include confidentiality protection and / or integrity protection.
[0619] Taking the transmission process of uplink data from a terminal device to a user plane network element as an example, the terminal device protects the confidentiality of the uplink data by generating ciphertext using a first key, first parameters, second parameters, length parameters, and transmission direction parameters. The terminal device then sends the ciphertext to the wireless network device, which in turn sends it to the user plane network element. Alternatively, the terminal device protects the integrity of the uplink data by generating a message authentication code using a first key, first parameters, second parameters, transmission direction parameters, and the message itself. The terminal device then sends the message authentication code to the wireless network device, which in turn sends it to the user plane network element.
[0620] S904. The user plane network element receives uplink data from the terminal device after user plane security protection, and performs user plane security processing according to the first key, first parameter and second parameter corresponding to the first session.
[0621] After the core network element derives the first key corresponding to the first session, it sends the corresponding first key to the corresponding user plane network element. The user plane network element can obtain the first key from the SMF network element. In addition to obtaining the first key corresponding to the first session, the user plane network element can also obtain the first parameter and the second parameter. The user plane network element performs user plane security processing based on the first key, the first parameter, and the second parameter. User plane security processing may include decryption and / or integrity verification.
[0622] Based on the example of step S903 above, it can be seen that the second parameter for user plane security protection by the terminal device can indicate the COUNT value. There are two ways to implement the COUNT value, and correspondingly, the user plane security processing performed by the user plane network element includes the following two types:
[0623] (1) If it is a COUNT corresponding to a PDU session, decryption and / or integrity verification are performed at the anchor user plane network element.
[0624] The terminal device identifier can be mapped to its IP address, and the PDU session identifier can be obtained through the tunnel ID. The tunnel ID corresponds to a specific session on a terminal device. The QFI can be obtained from the packet header. The terminal device and the anchor user plane network element maintain the same COUNT value for each PDU session. The anchor user plane network element refers to the user plane network element that processes data last when there are multiple user plane network elements. The anchor user plane network element decrypts and / or verifies the integrity of the received user plane security-protected data.
[0625] (2) If it is a COUNT corresponding to a QoS flow, it can be decrypted and / or its integrity verified directly at the corresponding user plane network element.
[0626] The terminal device identifier can be mapped to its IP address, the PDU session identifier can be obtained through the Tunnel ID, and the QFI can be obtained from the packet header. The terminal device and the user plane network element maintain the same COUNT value for a specific QoS flow in each PDU session. The user plane network element decrypts and / or verifies the integrity of the received user plane security-protected data.
[0627] Step S904 above describes the uplink transmission process of the terminal device. Next, referring to Figure 9c, taking the user plane network element as the sender and the terminal device as the receiver as an example, the downlink data transmission process is described. The methods by which the user plane network element and the terminal device obtain the first key, first parameter, and second parameter are similar to those in the previous embodiments, and will not be described in detail here.
[0628] S911. The user plane network element receives downlink data from the DN and performs user plane security protection on the downlink data according to the first key, first parameter and second parameter corresponding to the first session.
[0629] When a user plane network element receives downlink data, it maps the downlink data to the corresponding tunnel identifier (Tunnel ID) and QFI according to the PDR rules. The PDR rules may include a set of packet filtering rules. Based on the Tunnel ID, the user plane network element can find the first key and the COUNT value at the PDU session granularity. Then, based on the first key and the security policy corresponding to the session or the QFI, the user plane network element performs user plane security protection on the downlink data. User plane security protection may include encryption and / or integrity protection.
[0630] It is understandable that, assuming that during the PDU session establishment process, the user plane network element receives the key of the corresponding session of the corresponding terminal device sent by other core network elements (such as SMF network elements), and associates the key with the N4 session, after the user plane network element allocates user plane resources and configures the NG-U tunnel for the session, it can bind the key with the TunnelID. Correspondingly, the COUNT value of the PDU session granularity corresponds to the TunnelID.
[0631] S912, the user plane network element sends the corresponding downlink data on the corresponding tunnel, and the header of the downlink data packet includes QFI.
[0632] The user plane network element sends downlink data to the wireless network device. The wireless network device receives the corresponding downlink data, maps it to the corresponding DRB ID based on the Tunnel ID and QFI, and then sends the corresponding downlink data to the terminal device in the corresponding DRB ID.
[0633] S913. The terminal device receives the corresponding downlink data and performs user plane security processing on the downlink data according to the first key, first parameter and second parameter corresponding to the first session.
[0634] Optionally, the terminal device can find the corresponding QFI based on the mapping relationship between DRB ID and QFI, determine the PDU session to which the downlink data belongs based on the destination IP address of the downlink data, determine the corresponding key based on the PDU session, find the COUNT value corresponding to the PDU session, and thus perform user plane security processing on the downlink data. User plane security processing includes: integrity verification and / or decryption operations.
[0635] As illustrated by the foregoing examples, the embodiments of this application can input different keys and parameters for confidentiality protection and integrity protection, ensuring that the key stream is not reused and preventing replay attacks.
[0636] In another implementation of this application, as shown in FIG10a, the first key corresponds to the terminal device, and the first parameter corresponds to the identifier of the PDU session and the identifier of the QoS stream, QFI.
[0637] The following section provides examples illustrating the confidentiality and integrity protection of user plane data based on the aforementioned key derivation method.
[0638] Figure 10b shows a schematic diagram of the key generation process provided in this embodiment of the application. The main process includes:
[0639] S1001. A PDU session is established between the terminal device and the user plane network element.
[0640] A PDU session is established between the terminal device and the user plane network element, and the terminal device performs security activation of the access layer.
[0641] S1002, the terminal device and the user plane network element respectively obtain the first key, first parameter and second parameter corresponding to the terminal device.
[0642] (1) First key.
[0643] In one embodiment of this application, the introduction of the first key will be illustrated below with reference to Figure 10a. Taking a terminal device as an example, during the PDU session establishment process, the core network element performs key deduction and maintains a key for each terminal device. Additionally, the core network element can also send the key corresponding to each terminal device to the corresponding user plane network element. The terminal device obtains the first key through the same deduction rules. When performing confidentiality and integrity protection on user plane data, the first key is implemented at the terminal device level.
[0644] For example, the terminal device's USIM and UDM / ARPF sides store the terminal device's long-term key K. The terminal device registers with the network and performs identity authentication, i.e., primary authentication. After the primary authentication process, the corresponding anchor keys KAUSF and KSEAF can be derived from the intermediate keys CK and IK in the primary authentication process. For example, the SEAF network element uses the key KSEAF to derive KSM, such as KSM = KDF(KSEAF, session management). The SEAF network element sends KSM to the SMF network element, and the SMF network element sends KSM to the user plane network element. The user plane network element uses KSM to derive the user plane confidentiality key KUPenc and the user plane integrity key KUPint, such as KUPenc = KDF(KPDUsession, confidentiality protection identifier) and KUPint = KDF(KPDUsession, integrity protection identifier).
[0645] (2) First parameter.
[0646] The first parameter indicates the QoS stream in the PDU session. The first parameter can indicate the PDU session identifier and QFI of the current user plane data. The length of the first parameter is determined by the length of the PDU session identifier and the length of the QFI. For example, if the length of the PDU session identifier is 8 bits and the length of the QFI is 6 bits, the length of the first parameter can be 8 + 6 = 14 bits. Alternatively, the first parameter can indicate the PDU session identifier of the current user plane data. The length of the first parameter is the length of the PDU session identifier. For example, if the length of the PDU session identifier is 8 bits, the length of the first parameter is 8 bits.
[0647] (3) Second parameter.
[0648] The second parameter indicates the value of the counter (COUNT).
[0649] In this application embodiment, the COUNT value can correspond to a PDU session, or the COUNT value can correspond to a QoS flow, as explained below:
[0650] For the COUNT corresponding to a PDU session, two COUNT values are maintained for each PDU session. The uplink and downlink data packets of that PDU session are counted separately; for example, the uplink COUNT is used to count uplink data packets, and the downlink COUNT is used to count downlink data packets. When the COUNT value reaches its maximum value, the counter is toggled, simultaneously triggering the key update process. In the case of the COUNT corresponding to a PDU session, setting the first parameter to QFI is an optional scheme.
[0651] For the COUNT corresponding to a QoS flow, two COUNT values are maintained for each QFI in each session, counting uplink and downlink packets for that QoS flow respectively. For example, the uplink COUNT is used to count uplink packets, and the downlink COUNT is used to count downlink packets. The COUNT value can be 32 bits or other bit types, which are not limited here. When the COUNT value reaches its maximum value, it triggers a counter flip and simultaneously triggers a key update process. In the case of the COUNT corresponding to a QoS flow, the input parameter of the first parameter is the QFI. Therefore, when using the COUNT at the QoS flow granularity, the input parameter of the first parameter needs to include the QFI to distinguish different COUNTs.
[0652] In this embodiment of the application, in addition to the aforementioned first key, first parameter, and second parameter, the input for security protection may also include the following parameters:
[0653] (3) Transmission direction (DIRECTION) parameter.
[0654] The length of the transmission direction can be 1 bit, and the value of the transmission direction can be 0 or 1, representing the transmission direction as uplink and downlink, respectively.
[0655] (4) Length parameter.
[0656] Length refers to the length of the plaintext.
[0657] S1003. The terminal device performs user plane security protection based on the first key, first parameter and second parameter corresponding to the terminal device, and sends uplink data after user plane security protection.
[0658] For example, the terminal device uses the first key as input for user plane security protection, such as as input parameters for user plane encryption and integrity protection algorithms. User plane security protection may include confidentiality protection and / or integrity protection.
[0659] Taking the transmission process of uplink data from a terminal device to a user plane network element as an example, the terminal device protects the confidentiality of the uplink data by generating ciphertext using a first key, first parameter, second parameter, length parameter, and transmission direction parameter. The terminal device then sends the ciphertext to the wireless network device, which in turn sends it to the user plane network element. Alternatively, the terminal device protects the integrity of the uplink data by generating a message authentication code using a first key, first parameter, second parameter, transmission direction parameter, and message. The terminal device then sends the message authentication code to the wireless network device, which in turn sends it to the user plane network element.
[0660] S1004. The user plane network element receives uplink data from the terminal device after user plane security protection, and performs user plane security processing according to the first key, first parameter and second parameter corresponding to the terminal device.
[0661] After the core network element derives the first key corresponding to the first session, it sends the corresponding first key to the corresponding user plane network element. The user plane network element can obtain the first key from the SMF network element. In addition to obtaining the first key corresponding to the first session, the user plane network element can also obtain the first parameter and the second parameter. The user plane network element performs user plane security processing based on the first key, the first parameter, and the second parameter. User plane security processing may include decryption and / or integrity verification.
[0662] Based on the example of step S1003 above, it can be seen that the second parameter for user plane security protection of the terminal device can indicate the COUNT value. There are two ways to implement the COUNT value, and correspondingly, the user plane security processing performed by the user plane network element includes the following two types:
[0663] (1) If it is a COUNT corresponding to a PDU session, decryption and / or integrity verification are performed at the anchor user plane network element.
[0664] The terminal device identifier can be mapped through the IP address, and the PDU session identifier can be obtained through the tunnel ID. The tunnel ID can be mapped to a specific session of a terminal device. The QFI can be obtained from the packet header. The terminal device and the anchor user plane network element maintain the same COUNT value for each PDU session. The anchor user plane network element refers to the user plane network element that processes the data last when there are multiple user plane network elements. The anchor user plane network element decrypts and / or verifies the integrity of the received user plane security-protected data.
[0665] (2) If it is a COUNT corresponding to a QoS flow, it can be decrypted and / or its integrity verified directly at the corresponding user plane network element.
[0666] The terminal device identifier can be mapped to its IP address, the PDU session identifier can be obtained through the Tunnel ID, and the QFI can be obtained from the packet header. The terminal device and the user plane network element maintain the same COUNT value for a specific QoS flow in each PDU session. The user plane network element decrypts and / or verifies the integrity of the received user plane security-protected data.
[0667] Step S1004 above describes the uplink transmission process of the terminal device. Next, referring to Figure 10c, taking the user plane network element as the sender and the terminal device as the receiver as an example, the downlink data transmission process is described. The methods by which the user plane network element and the terminal device obtain the first key, first parameter, and second parameter are similar to those in the previous embodiments, and will not be described in detail here.
[0668] S1011. The user plane network element receives downlink data from the DN and performs user plane security protection on the downlink data according to the first key, first parameter and second parameter corresponding to the terminal device.
[0669] When a user plane network element receives downlink data, it maps the downlink data to the corresponding tunnel identifier (Tunnel ID) and QFI according to the PDR rules. The PDR rules may include a set of packet filtering rules. Based on the Tunnel ID, the user plane network element can find the first key and the COUNT value at the PDU session granularity. Then, based on the first key and the security policy corresponding to the session or the QFI, the user plane network element performs user plane security protection on the downlink data. User plane security protection may include encryption and / or integrity protection.
[0670] It is understandable that, assuming that during the PDU session establishment process, the user plane network element receives the key of the corresponding session of the corresponding terminal device sent by other core network elements (such as SMF network elements), and associates the key with the N4 session, after the user plane network element allocates user plane resources and configures the NG-U tunnel for the session, it can bind the key with the Tunnel ID. Correspondingly, the COUNT value of the PDU session granularity corresponds to the Tunnel ID.
[0671] S1012. The user plane network element sends the corresponding downlink data on the corresponding tunnel, and the header of the downlink data packet includes QFI.
[0672] The user plane network element sends downlink data to the wireless network device. The wireless network device receives the corresponding downlink data, maps it to the corresponding DRB ID based on the Tunnel ID and QFI, and then sends the corresponding downlink data to the terminal device in the corresponding DRB ID.
[0673] S1013. The terminal device receives the corresponding downlink data and performs user plane security processing on the downlink data according to the first key, first parameter and second parameter corresponding to the terminal device.
[0674] Optionally, the terminal device can find the corresponding QFI based on the mapping relationship between DRB ID and QFI, determine the PDU session to which the downlink data belongs based on the destination IP address of the downlink data, determine the corresponding key based on the PDU session, find the COUNT value corresponding to the PDU session, and thus perform user plane security processing on the downlink data. User plane security processing includes: integrity verification and / or decryption operations.
[0675] As illustrated by the foregoing examples, the embodiments of this application can input different keys and parameters for confidentiality protection and integrity protection, ensuring that the key stream is not reused and preventing replay attacks.
[0676] In another implementation of this application, as shown in Figures 11a and 11b, the first key corresponds to the identifier of the PDU session and the identifier of the QoS flow, QFI, and the first parameter corresponds to the identifier of the PDU session, the identifier of the QoS flow, QFI, the identifier of the DRB, DRBID, or other parameters shared by the terminal device and the user plane network element.
[0677] The following examples illustrate the confidentiality and integrity protection of user plane data using the key deduction methods shown in Figures 11a and 11b. Figure 11c shows a schematic diagram of key generation provided in an embodiment of this application; the main process includes:
[0678] S1101. A PDU session is established between the terminal device and the user plane network element.
[0679] A PDU session is established between the terminal device and the user plane network element, and the terminal device performs security activation of the access layer (AS).
[0680] S1102, the terminal device and the user plane network element respectively obtain the first key, the first parameter and the second parameter corresponding to the identifier of the first session and the first quality of service flow.
[0681] (1) First key.
[0682] As shown in Figures 11a and 11b, taking the PDU session identifier and QFI as an example, during the PDU session establishment process, the core network element performs key deduction to maintain a key for each QFI of each session for each terminal device. Additionally, the core network element can also send the key corresponding to each QFI of each session for each terminal device to the corresponding user plane network element. The terminal device obtains the first key through the same deduction rules. When protecting the confidentiality and integrity of user plane data, the first key can be more granular, i.e., the first key can be at the PDU session identifier and QFI granularity.
[0683] The terminal device's USIM and UDM / ARPF sides store the terminal device's long-term key K. The terminal device registers with the network and performs identity authentication, i.e., primary authentication. After the primary authentication process, the corresponding anchor keys KAUSF and KSEAF can be derived from the intermediate keys CK and IK in the primary authentication process. The SEAF network element uses the key KSEAF to derive KSM. The SEAF network element sends KSM to the SMF network element, as shown in Figure 11a. The SMF network element uses KSM to directly derive KPDUsession+QFI. For example, KPDUsession+QFI = KDF(KSM, PDUsession ID+QFI). The SMF network element sends KPDUsession+QFI to the user plane network element. The user plane network element uses KPDUsession+QFI to derive the user plane confidentiality key KUPenc and the user plane integrity key KUPint. For example, KUPenc = KDF(KPDUsession, confidentiality protection identifier) and KUPint = KDF(KPDUsession, integrity protection identifier).
[0684] In another implementation, as shown in Figure 11b, the SMF network element uses KSM to deduce KPDUsession, and then uses KPDUsession to deduce KQFI. The KQFI is then sent to the user plane network element, which uses KQFI to deduce the user plane confidentiality key KUPenc and the user plane integrity key KUPint. For example, KUPenc = KDF(KPDUsession, confidentiality protection identifier) and KUPint = KDF(KPDUsession, integrity protection identifier).
[0685] (2) First parameter.
[0686] In this embodiment, the key corresponds to the PDU session identifier and the QFI granularity. By using the COUNT value of the PDU session identifier and the QFI granularity, it can be ensured that the key stream is not reused. The first parameter can use multiple granularities. The first parameter indicates the PDU session identifier, QFI ID, DRB ID, or other parameters shared by the terminal device and the user plane network element. The parameters shared by the terminal device and the user plane network element include the IP address of the terminal device.
[0687] (3) Second parameter.
[0688] The second parameter indicates the value of the counter (COUNT).
[0689] In this embodiment, the COUNT value can correspond to a QoS flow, as explained below: For the COUNT corresponding to a QoS flow, two COUNT values are maintained for each QFI of each session, counting the uplink and downlink data packets of that QoS flow respectively. For example, the uplink COUNT is used to count uplink data packets, and the downlink COUNT is used to count downlink data packets. The COUNT value can be 32 bits or other bits, which is not limited here. When the COUNT value reaches its maximum value, the counter will be toggled, and the key update process will be triggered simultaneously. In the case of the COUNT corresponding to a QoS flow, the first parameter is the QFI. Therefore, when using the COUNT at the QoS flow granularity, the input parameter of the first parameter needs to carry the QFI to distinguish different COUNTs.
[0690] In this embodiment of the application, in addition to the aforementioned first key, first parameter, and second parameter, the input for security protection may also include the following parameters:
[0691] (3) Transmission direction (DIRECTION) parameter.
[0692] The length of the transmission direction can be 1 bit, and the value of the transmission direction can be 0 or 1, representing the transmission direction as uplink and downlink, respectively.
[0693] (4) Length parameter.
[0694] Length refers to the length of the plaintext.
[0695] S1103. The terminal device performs user plane security protection based on the first key, first parameter and second parameter corresponding to the identifier of the first session and the first quality of service flow, and sends uplink data after user plane security protection.
[0696] For example, the terminal device uses the first key as input for user plane security protection, such as as input parameters for user plane encryption and integrity protection algorithms. User plane security protection may include confidentiality protection and / or integrity protection.
[0697] Taking the transmission process of uplink data from a terminal device to a user plane network element as an example, the terminal device protects the confidentiality of the uplink data by generating ciphertext using a first key, first parameter, second parameter, length parameter, and transmission direction parameter. The terminal device then sends the ciphertext to the wireless network device, which in turn sends it to the user plane network element. Alternatively, the terminal device protects the integrity of the uplink data by generating a message authentication code using a first key, first parameter, second parameter, transmission direction parameter, and message. The terminal device then sends the message authentication code to the wireless network device, which in turn sends it to the user plane network element.
[0698] S1104. The user plane network element receives uplink data from the terminal device after user plane security protection, and performs user plane security processing according to the first key, first parameter and second parameter corresponding to the identifier of the first session and the first quality of service flow.
[0699] After the core network element derives the first key corresponding to the first session, it sends the corresponding first key to the corresponding user plane network element. The user plane network element can obtain the first key from the SMF network element. In addition to obtaining the first key corresponding to the first session, the user plane network element can also obtain the first parameter and the second parameter. The user plane network element performs user plane security processing based on the first key, the first parameter, and the second parameter. User plane security processing may include decryption and / or integrity verification.
[0700] Based on the example of step S1003 above, the second parameter for user plane security protection performed by the terminal device can indicate the COUNT value. Correspondingly, the user plane security processing performed by the user plane network element includes: if the COUNT corresponds to a QoS flow, decryption and / or integrity verification can be performed directly at the corresponding user plane network element. The terminal device's identifier can be obtained through its IP address, the PDU session identifier through the Tunnel ID, and the QFI from the packet header. The terminal device and the user plane network element maintain the same COUNT value for a specific QoS flow in each PDU session. The user plane network element decrypts and / or verifies the integrity of the received user plane security protected data.
[0701] Step S1104 above describes the uplink transmission process of the terminal device. Next, referring to Figure 11d, taking the user plane network element as the sender and the terminal device as the receiver as an example, the downlink data transmission process is described. The methods by which the user plane network element and the terminal device obtain the first key, first parameter, and second parameter are similar to those in the previous embodiments, and will not be described in detail here.
[0702] S1111 The user plane network element receives downlink data from the DN and performs user plane security protection on the downlink data according to the first key, first parameter and second parameter corresponding to the identifier of the first session and the first quality of service flow.
[0703] When a user plane network element receives downlink data, it maps the downlink data to the corresponding tunnel identifier (Tunnel ID) and QFI according to the PDR rules. The PDR rules may include a set of packet filtering rules. Based on the Tunnel ID, the user plane network element can find the first key and the COUNT value at the PDU session granularity. Then, based on the first key and the security policy corresponding to the session or the QFI, the user plane network element performs user plane security protection on the downlink data. User plane security protection may include encryption and / or integrity protection.
[0704] It is understandable that, assuming that during the PDU session establishment process, the user plane network element receives the key of the corresponding session of the corresponding terminal device sent by other core network elements (such as SMF network elements), and associates the key with the N4 session, after the user plane network element allocates user plane resources and configures the NG-U tunnel for the session, it can bind the key with the Tunnel ID. Correspondingly, the COUNT value of the PDU session granularity corresponds to the Tunnel ID.
[0705] S1112. The user plane network element sends the corresponding downlink data on the corresponding tunnel, and the header of the downlink data packet includes QFI.
[0706] The user plane network element sends downlink data to the wireless network device. The wireless network device receives the corresponding downlink data, maps it to the corresponding DRB ID based on the Tunnel ID and QFI, and then sends the corresponding downlink data to the terminal device in the corresponding DRB ID.
[0707] S1113. The terminal device receives the corresponding downlink data and performs user plane security processing on the downlink data according to the first key, first parameter and second parameter corresponding to the identifier of the first session and the first quality of service flow.
[0708] Optionally, the terminal device can find the corresponding QFI based on the mapping relationship between DRB ID and QFI, determine the PDU session to which the downlink data belongs based on the destination IP address of the downlink data, determine the corresponding key based on the PDU session, find the COUNT value corresponding to the PDU session, and thus perform user plane security processing on the downlink data. User plane security processing includes: integrity verification and / or decryption operations.
[0709] As illustrated by the foregoing examples, the embodiments of this application can input different keys and parameters for confidentiality protection and integrity protection, ensuring that the key stream is not reused and preventing replay attacks.
[0710] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0711] To facilitate better implementation of the above-described solutions in the embodiments of this application, related apparatus for implementing the above-described solutions is also provided below.
[0712] Please refer to Figure 12. A communication device 1200 provided in this application embodiment may include: a transmitting module 1201, a receiving module 1202, and a processing module 1203.
[0713] Optionally, the communication device can be a terminal device as shown in Figures 5-8, or a user plane network element. The function of the processing module 1303 can be found in the method flow executed by the terminal device or user plane network element in Figures 5-8.
[0714] It should be noted that the information interaction and execution process between the modules / units of the above-mentioned device are based on the same concept as the method embodiments of this application, and the resulting technical effects are the same as those of the method embodiments of this application. The details can be found in the descriptions of the method embodiments shown above in this application, and will not be repeated here.
[0715] This application also provides a computer storage medium storing a program that performs some or all of the steps described in the above method embodiments.
[0716] Next, another communication device provided in the embodiments of this application will be introduced. Please refer to FIG13. The communication device 1300 includes:
[0717] The communication device 1300 includes a receiver 1301, a transmitter 1302, a processor 1303, and a memory 1304 (the number of processors 1303 in the communication device 1300 can be one or more; Figure 13 shows an example of one processor). In some embodiments of this application, the receiver 1301, transmitter 1302, processor 1303, and memory 1304 can be connected via a bus or other means; Figure 13 shows an example of connection via a bus.
[0718] Memory 1304 may include read-only memory and random access memory, and provides instructions and data to processor 1303. A portion of memory 1304 may also include non-volatile random access memory (NVRAM). Memory 1304 stores operating system and operation instructions, executable modules or data structures, or subsets thereof, or extended sets thereof, wherein the operation instructions may include various operation instructions for implementing various operations. The operating system may include various system programs for implementing various basic business functions and handling hardware-based tasks.
[0719] Processor 1303 controls the operation of the communication device. Processor 1303 can also be called a central processing unit (CPU). Optionally, in practical applications, the various components of the communication device are coupled together through a bus system. This bus system may include not only a data bus but also a power bus, control bus, and status signal bus. However, for clarity, all buses are referred to as a bus system in the diagram.
[0720] The methods disclosed in the embodiments of this application can be applied to or implemented by the processor 1303. The processor 1303 can be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in the processor 1303 or by instructions in the form of software. The processor 1303 can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software modules can be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 1304. Processor 1303 reads the information in memory 1304 and, in conjunction with its hardware, completes the steps of the above method.
[0721] The receiver 1301 can be used to receive input digital or character information and generate signal inputs related to the settings and function control of the communication device. The transmitter 1302 may include a display device such as a display screen and can be used to output digital or character information through an external interface.
[0722] In this embodiment of the application, the processor 1303 is used to execute the method flow executed by the terminal device or user plane network element in the aforementioned Figures 5-8.
[0723] In another possible design, when the communication device is a terminal device or a chip within a user plane network element, the chip includes a processing unit and a communication unit. The processing unit may be, for example, a processor, and the communication unit may be, for example, an input / output interface, pins, or circuits. The processing unit can execute computer-executable instructions stored in a storage unit to cause the chip within the terminal to perform any of the methods described in the first aspect above. Optionally, the storage unit may be a storage unit within the chip, such as a register or cache. Alternatively, the storage unit may be a storage unit located outside the chip within the terminal, such as read-only memory (ROM) or other types of static storage devices capable of storing static information and instructions, such as random access memory (RAM).
[0724] The processor mentioned above can be a general-purpose central processing unit, a microprocessor, an ASIC, or one or more integrated circuits used to control the execution of programs for the aforementioned data transmission methods.
[0725] It should also be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. In addition, in the device embodiment drawings provided in this application, the connection relationship between modules indicates that they have a communication connection, which can optionally be implemented as one or more communication buses or signal lines.
[0726] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general-purpose hardware, or it can be implemented by special-purpose hardware including application-specific integrated circuits, special-purpose CPUs, special-purpose memory, special-purpose components, etc. Generally, any function performed by a computer program can be easily implemented by corresponding hardware, and the hardware structure used to implement the same function can also be diverse, such as analog circuits, digital circuits, or special-purpose circuits. However, for this application, software program implementation is more often the preferred implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium, such as a computer floppy disk, USB flash drive, mobile hard disk, ROM, RAM, magnetic disk, or optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0727] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product.
[0728] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).
Claims
1. A data transmission method, characterized by, The method comprises: The terminal device obtains a first key according to an identifier of a first session between the terminal device and a user plane network element; The terminal device performs user plane security protection on first data according to the first key, to obtain second data; The terminal device sends the second data through the first session; The user plane network element receives the second data through the first session; The user plane network element performs user plane security processing on the second data according to the first key, to obtain the first data.
2. A data transmission method, characterized by, The method is applied to a terminal device, and the method comprises: A first key is obtained according to an identifier of a first session between the terminal device and a user plane network element; First data is subjected to user plane security protection according to the first key, to obtain second data; The second data is sent through the first session.
3. The method according to claim 1 or 2, characterized in that, The first data is subjected to user plane security protection according to the first key and parameter information corresponding to the first session, wherein the parameter information corresponding to the first session is used to indicate transmission parameters of the first data. The parameter information corresponding to the first session comprises, but is not limited to, one or more of the following information:
4. The method of claim 3, wherein, A first parameter is used to indicate a first quality of service flow in the first session, and the first quality of service flow is used for transmission of the first data; A second parameter is used to indicate a value of a counter corresponding to a data packet used to carry the first data, and the counter is used to count data packets in the first session. The first parameter comprises an identifier of the first quality of service flow.
5. The method of claim 4, wherein, The first key is obtained according to the identifier of the first session and an identifier of a first quality of service flow in the first session.
6. The method of claim 1 or 2, wherein, The first data is subjected to user plane security protection according to the first key and a third parameter, wherein the third parameter is used to indicate a value of a counter corresponding to a data packet used to carry the first data, and the counter is used to count data packets corresponding to the first quality of service flow. The method is applied to a user plane network element, and the method comprises:
7. The method of claim 6, wherein, Second data is received through a first session between the user plane network element and a terminal device, wherein the second data is data subjected to user plane security protection on first data according to a first key corresponding to the first session; The first data is obtained by performing user plane security processing on the second data according to the first key.
8. A data transmission method, characterized by, The second data is subjected to user plane security processing according to the first key and parameter information corresponding to the first session, wherein the parameter information corresponding to the first session is used to indicate transmission parameters of the second data. The parameter information corresponding to the first session comprises, but is not limited to, one or more of the following information: 9. The method according to claim 1 or 8, characterized in that, 10. The method of claim 9, wherein, a first parameter, the first parameter being used to indicate a first quality of service flow in the first session, the first quality of service flow being used for transmission of the second data; a second parameter, the second parameter being used to indicate a value of a counter corresponding to a data packet carrying the second data, the counter being used to count data packets in the first session.
11. The method of claim 10, wherein, The first parameter comprises an identifier of the first quality of service flow.
12. The method of claim 1 or 8, wherein, The user plane security processing of the second data according to the first key comprises: user plane security processing of the second data according to the first key and a third parameter, the third parameter being used to indicate a value of a counter corresponding to a data packet carrying the second data, the counter being used to count data packets corresponding to the first quality of service flow in the first session.
13. A data transmission method, characterized by, The method comprises: a terminal device acquires a first key corresponding to the terminal device; the terminal device performs user plane security protection on first data according to the first key and a first parameter to obtain second data, the first parameter being used to indicate a first session or the first parameter being used to indicate a first quality of service flow in the first session, the first session being a session between the terminal device and a user plane network element; the terminal device transmits the second data through the first session; the user plane network element receives the second data through the first session; the user plane network element performs user plane security processing on the second data according to the first key and the first parameter to obtain the first data.
14. A data transmission method, characterized by, The method is applied to a terminal device, and the method comprises: acquiring a first key corresponding to the terminal device; performing user plane security protection on first data according to the first key and a first parameter to obtain second data, the first parameter being used to indicate a first session or the first parameter being used to indicate a first quality of service flow in the first session, the first session being a session between the terminal device and a user plane network element; transmitting the second data through the first session.
15. The method according to claim 13 or 14, characterized in that, The user plane security protection on the first data according to the first key and the first parameter comprises: user plane security protection on the first data according to the first key, the first parameter and a second parameter, the second parameter being used to indicate a value of a counter corresponding to a data packet carrying the first data, the counter being used to count data packets in the first session.
16. The method of any of claims 13 to 15, wherein the first parameter is used to indicate a first session, and the first parameter comprises an identifier of the first session; or the first parameter is used to indicate a first quality of service flow in a first session, and the first parameter comprises an identifier of the first quality of service flow and an identifier of the first session. The method is applied to a user plane network element, and the method comprises:
17. A data transmission method, characterized by, receive, by the user plane network element, second data through a first session between the user plane network element and a terminal device, the second data being first data after user plane security protection according to a first key corresponding to the terminal device and a first parameter, the first parameter being used for indicating the first session, or the first parameter being used for indicating a first quality of service flow in the first session; perform, according to the first key and the first parameter, user plane security processing on the second data to obtain the first data.
18. The method of claim 13 or 17, wherein, The performing, according to the first key and the first parameter, user plane security processing on the second data comprises: performing, according to the first key, the first parameter and a second parameter, user plane security processing on the second data, the second parameter being used for indicating a value of a counter corresponding to a data packet carrying the second data, the counter being used for counting data packets in the first session.
19. The method of claim 18, wherein the first parameter being used for indicating the first session comprises that the first parameter comprises an identifier of the first session; or the first parameter being used for indicating the first quality of service flow in the first session comprises that the first parameter comprises an identifier of the first quality of service flow and an identifier of the first session. The method comprises:
20. A data transmission method, characterized by, obtaining, by a user plane network element, a second key according to an identifier of a second session between the user plane network element and a terminal device; performing, by the user plane network element, user plane security protection on third data according to the second key to obtain fourth data; sending, by the user plane network element, the fourth data through the second session; receiving, by the terminal device, the fourth data through a second session between the terminal device and the user plane network element; performing, by the terminal device, user plane security processing on the fourth data according to the second key to obtain the third data. The method is applied to a user plane network element, and the method comprises:
21. A data transmission method, characterized by, obtaining a second key according to an identifier of a second session between the user plane network element and a terminal device; performing user plane security protection on third data according to the second key to obtain fourth data; sending the fourth data through the second session. The obtaining, according to an identifier of a second session between the user plane network element and a terminal device, a second key comprises:
22. The method of claim 20 or 21, wherein, obtaining the second key according to the identifier of the second session and an identifier of a second quality of service flow in the second session. The performing, according to the second key, user plane security protection on third data to obtain fourth data comprises:
23. The method of any one of claims 20-22, wherein, performing, according to the second key and parameter information corresponding to the second session, user plane security protection on the third data, the parameter information corresponding to the second session being used for indicating a transmission parameter of the third data. The parameter information corresponding to the second session comprises one or more of the following information:
24. The method of claim 23, wherein, a fourth parameter, the fourth parameter being used for indicating a second quality of service flow in the second session, the second quality of service flow being used for transmission of the third data; a fifth parameter, the fifth parameter being used for indicating a value of a counter corresponding to a data packet carrying the third data, the counter being used for counting data packets in the second session. 25. The method of any one of claims 20-24, wherein, The user plane security protection includes encryption, and the user plane network element performs user plane security protection on the third data according to the second key, including: The user plane network element obtains a second confidentiality protection key according to the second key; The user plane network element obtains a third key stream according to the second confidentiality protection key; The user plane network element encrypts the third data according to the third key stream to obtain third ciphertext, and the fourth data includes the third ciphertext.
26. The method of any one of claims 20-25, wherein, The user plane security protection includes integrity protection, and the user plane network element performs user plane security protection on the third data according to the second key, including: The user plane network element obtains a second integrity protection key according to the second key; The user plane network element obtains a fifth message authentication code according to the second integrity protection key and the third data, and the fourth data includes the fifth message authentication code.
27. The method of any one of claims 20-24, wherein, The user plane security protection includes encryption and integrity protection, and the user plane network element performs user plane security protection on the third data according to the second key, including: The user plane network element obtains a fourth key stream according to the second key, and encrypts the third data according to the fourth key stream to obtain fourth ciphertext; The user plane network element obtains a sixth message authentication code according to the second key and the third data; The third data includes the fourth ciphertext and the sixth message authentication code.
28. A method of data transmission, characterized by The method is applied to a terminal device, and the method includes: Receiving fourth data through a second session between the terminal device and a user plane network element, the fourth data being data obtained by performing user plane security protection on third data according to a second key corresponding to the second session; Performing user plane security processing on the fourth data according to the second key to obtain the third data.
29. The method of claim 28, wherein, Performing user plane security processing on the fourth data according to the second key to obtain the third data includes: Performing user plane security processing on the fourth data according to the second key and parameter information corresponding to the second session, the parameter information corresponding to the second session being used to indicate transmission parameters of the fourth data.
30. The method of claim 28 or 29, wherein, The parameter information corresponding to the second session includes one or more of the following information: A fourth parameter, the fourth parameter being used to indicate a second quality of service flow in the second session, the second quality of service flow being used for transmission of the fourth data; A fifth parameter, the fifth parameter being used to indicate a value of a counter corresponding to a data packet carrying the third data, the counter being used to count data packets in the second session.
31. The method of any one of claims 28-30, wherein, The fourth data includes third ciphertext, and the terminal device performs user plane security processing on the fourth data according to the second key, including: The terminal device obtains a second confidentiality protection key according to the second key; The terminal device obtains a third key stream according to the second confidentiality protection key; The terminal device decrypts the third ciphertext according to the third key stream to obtain third plaintext.
32. The method of any one of claims 28-31, wherein, The fourth data includes a fifth message authentication code, and the terminal device performs user plane security processing on the fourth data according to the second key, including: The terminal device obtains a second integrity protection key according to the second key; The terminal device derives a seventh message authentication code from the second integrity protection key; The terminal device derives the fifth message authentication code from the fourth data; An integrity verification result is derived from the fifth message authentication code and the seventh message authentication code.
33. The method of any one of claims 28-30, wherein, The fourth data comprises fourth cipher text and a sixth message authentication code, and the terminal device performs user plane security processing on the fourth data according to the second key, comprising: The terminal device derives a fourth key stream from the second key, and decrypts the fourth cipher text according to the fourth key stream to obtain fourth plaintext; The terminal device derives an eighth message authentication code from the second key; The terminal device derives an integrity verification result from the sixth message authentication code and the eighth message authentication code.
34. A method of data transmission, characterized by The method: The user plane network element obtains a second key corresponding to the terminal device; The user plane network element performs user plane security protection on the third data according to the second key and a fourth parameter to obtain fourth data, and the fourth parameter is used to indicate a second session, or the fourth parameter is used to indicate a second quality of service flow in the second session, the second session being a session between the user plane network element and the terminal device; The user plane network element sends the fourth data through the second session; The terminal device receives the fourth data through a second session between the terminal device and the user plane network element; The terminal device performs user plane security processing on the fourth data according to the second key corresponding to the terminal device and the fourth parameter to obtain the third data.
35. A method of data transmission, characterized by The method is applied to a user plane network element, comprising: The user plane network element obtains a second key corresponding to the terminal device; The user plane network element performs user plane security protection on the third data according to the second key and a fourth parameter to obtain fourth data, and the fourth parameter is used to indicate a second session, or the fourth parameter is used to indicate a second quality of service flow in the second session, the second session being a session between the user plane network element and the terminal device; The user plane network element sends the fourth data through the second session.
36. The method of claim 34 or 35, wherein, Performing user plane security protection on the third data according to the second key and the fourth parameter, comprising: Performing user plane security protection on the third data according to the second key, the fourth parameter and a fifth parameter, and the fifth parameter is used to indicate a value of a counter corresponding to a data packet used to carry the third data, the counter being used to count data packets in the second session.
37. The method of any one of claims 34-36, wherein, The fourth parameter is used to indicate the second session between the terminal device and the user plane network element, comprising: the fourth parameter comprises an identifier of the second session; Or, The fourth parameter is used to indicate the second quality of service flow in the second session, comprising: the fourth parameter comprises an identifier of the second quality of service flow and an identifier of the second session.
38. A data transmission method, characterized by, The method is applied to a terminal device, comprising: The terminal device receives fourth data through a second session between the terminal device and a user plane network element, the fourth data being third data after user plane security protection according to a second key corresponding to the terminal device and a fourth parameter, the fourth parameter being used for indicating the second session, or the fourth parameter being used for indicating a second quality of service flow in the second session, the second session being a session between the user plane network element and the terminal device; The terminal device performs user plane security processing on the fourth data according to the second key corresponding to the terminal device and the fourth parameter, to obtain the third data.
39. The method of claim 38, wherein, The user plane security processing on the fourth data according to the second key corresponding to the terminal device and the fourth parameter comprises: The user plane security processing on the fourth data according to the second key, the fourth parameter and a fifth parameter, the fifth parameter being used for indicating a value of a counter corresponding to a data packet carrying the fourth data, the counter being used for counting data packets in the second session.
40. The method of claim 38 or 39, wherein, The fourth parameter is used for indicating the second session between the terminal device and the user plane network element, comprising that the fourth parameter comprises an identifier of the second session. Or, The fourth parameter is used for indicating the second quality of service flow in the second session, comprising that the fourth parameter comprises an identifier of the second quality of service flow and an identifier of the second session. 41.A communication device comprising a processor and a memory, the memory and the processor being coupled, the processor being configured to perform the method of any one of claims 2 to 12, or the processor being configured to perform the method of any one of claims 14 to 19, or the processor being configured to perform the method of any one of claims 21 to 33, or the processor being configured to perform the method of any one of claims 35 to 40.
42. A communications device, characterized by The communication device comprises a sending module, a receiving module and a processing module; The processing module is configured to perform the method of any one of claims 2 to 12, or the processing module is configured to perform the method of any one of claims 14 to 19, or the processing module is configured to perform the method of any one of claims 21 to 33, or the processing module is configured to perform the method of any one of claims 35 to 40. 43.A computer readable storage medium comprising instructions which, when executed on a computer, cause the computer to perform the method of any one of claims 2 to 12, or cause the computer to perform the method of any one of claims 14 to 19, or cause the processor to perform the method of any one of claims 21 to 33, or cause the processor to perform the method of any one of claims 35 to 40.
44. A computer program product comprising instructions which, when executed on a computer, cause the computer to carry out the method of any one of claims 2 to 12, or cause the computer to carry out the method of any one of claims 14 to 19, or the processor is configured to carry out the method of any one of claims 21 to 33, or the processor is configured to carry out the method of any one of claims 35 to 40.
Citation Information
Patent Citations
Security realization method, equipment and system
CN108347410A
Data protection method, device and system
CN110891269A
Methods and systems for deriving CU-up security keys for disaggregated gnb architecture
US20220030425A1