Communication method, apparatus, and system for mission session

A communication method with a configurable first protocol layer provides data plane security protection, addressing the need for flexible security measures in next-generation networks, ensuring secure and efficient data transmission and privacy for in-network data processing.

WO2026031382A1PCT designated stage Publication Date: 2026-02-12HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/131119
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-09
Filing Date
2024-11-08
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Existing communication systems lack flexible and dynamic security measures for data transmission between user equipment and network functions, particularly in next-generation networks supporting in-network data processing, which is crucial for ensuring the security and privacy of data handling.

Method used

A communication method involving a first protocol layer configured to provide data plane security protection, enabling encryption, privacy protection, and integrity protection based on packet identification and control information, allowing dynamic switching between protected and unprotected states.

Benefits of technology

Ensures secure and reliable data transmission by adapting to different security requirements, ensuring confidentiality and integrity of data, while allowing flexible involvement of intermediate network functions in data processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024131119_12022026_PF_FP_ABST
    Figure CN2024131119_12022026_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a communication method, apparatus, and system for a mission session. The method includes: receiving a message, where the message is used to configure a first protocol layer in a communication apparatus, the first protocol layer is to support data plane security protection on a first packet, and the protection is between a user equipment and a network function;and configuring the first protocol layer based on the message.
Need to check novelty before this filing date? Find Prior Art

Description

COMMUNICATION METHOD, APPARATUS, AND SYSTEM FOR MISSION SESSION

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to U.S. Provisional Application No. 63 / 681,280, filed on August 9, 2024. The disclosure of the above patent application is incorporated herein by reference in its entirety.TECHNICAL FIELD

[0003] The present disclosure relates to the field of communications technologies and, in particular, to a communication method, apparatus, and system for a mission session.BACKGROUND

[0004] Protocol data unit (PDU) connectivity service is provided by 5G network. PDU connectivity service is a service that provides exchange of PDUs between a user equipment (UE) and a Data Network (DN) . 5G network provides PDU connectivity service to a UE via one or more PDU sessions.

[0005] For a next generation (e.g. sixth generation (6G) or later) network, or a legacy (e.g. fifth generation (5G) , fourth generation (4G) ) network, e.g., in 6G era, the 6G network is expected to not only for connectivity, but also for data processing. In-network data processing (or termed as in-network computing interchangeably) is supported. The in-network data processing is for X as a service (XaaS) service (e.g., NET4AI, DAM, NET4DW, etc. ) , e.g., to execute AI model training or inferencing, ISAC data processing, data pre-processing (e.g., data normalization, data cleaning) . The specific design is needed to support the data processing.

[0006] This background information is provided to reveal information believed by the applicant to be of possible relevance to the present disclosure. No admission is necessarily intended, nor should be construed, that any of the preceding information constitutes prior art against the present disclosure.SUMMARY

[0007] In a first aspect, a communication method is provided in the present disclosure, including:

[0008] receiving a message, where the message is used to configure a first protocol layer in a communication apparatus, the first protocol layer is to support data plane security protection on a first packet, and the protection is between a user equipment (UE) and a network function; and

[0009] configuring the first protocol layer based on the message.

[0010] The method may be performed by a communication apparatus, such as a terminal device or a network function, on which the first protocol layer is to be configured. The communication apparatus can adapt to different security requirements by configuring the first protocol layer based on the received configuration message, allowing for flexible and dynamic security measures. Secure and reliable data transmission between the UE and network function can be enabled by establishing a robust security framework on the data plane. In addition, the establishment of the first protocol layer, which is to support data plane security protection on a first packet transmitted between the UE and the network function, can apply security protection measures, such as encryption, privacy protection and integrity protection, to the data packets that will be transmitted, ensuring the confidentiality and integrity of the data.

[0011] In a possible implementation of the first aspect, the first protocol layer is a lower layer of a second protocol layer which is used to provide a mission service, where the mission service is a service for both protocol data unit (PDU) connectivity and data processing and the first protocol layer is to protect at least one of security and privacy of data of the second protocol layer. The first protocol layer may act as a security layer that ensures the security and privacy of the data handled by the second  protocol layer. By structuring the protocol layers in this manner, the security and privacy of in-network processing (also termed as in-network computing) can be guaranteed for the mission service, such as a XaaS service.

[0012] In a possible implementation of the first aspect, the mission service is provided through at least one mission session, and each of the at least one mission session includes a data forwarding resource and a data processing resource for providing the mission service.

[0013] In a possible implementation of the first aspect, each of the at least one mission session includes at least one data session, and each of the at least one data session includes an association terminates at a second entity executing one or more computing blocks (CBs) of the mission service, where the second entity is on the second protocol layer, the mission service includes at least one CB, each of the at least one CB corresponds to a computational step toward achieving the mission service, and the at least one CB includes the one or more CBs.

[0014] In a possible implementation of the first aspect, the second protocol layer is an anything as a service (XaaS) service layer.

[0015] In a possible implementation of the first aspect, the second protocol layer is a processing service function (PSF) layer.

[0016] In a possible implementation of the first aspect, one or more first entities are established on the first protocol layer to perform the protection.

[0017] In a possible implementation of the first aspect, whether the protection should be performed on the first packet is determined based on at least one of:

[0018] identification information corresponding to the first packet, or

[0019] an indication on whether protection is performed or not, where the indication on whether protection is performed or not is included in a packet which includes the first packet, or is not included in a packet which includes the first packet.

[0020] By examining either or both of the identification information corresponding to the first packet and an indication within the packet including the first packet, the network can make decisions about whether to apply security protections such as encryption or integrity protection on a per-packet basis.

[0021] In a possible implementation of the first aspect, the identification information corresponding to the first packet includes at least one of:

[0022] a mission session identifier (ID) identifying a mission session to which the first packet belongs,

[0023] a mission session group ID identifying a mission session group to which the first packet belongs,

[0024] a data session ID identifying a data session to which the first packet belongs,

[0025] a data session group ID identifying a data session group to which the first packet belongs,

[0026] a computing block identifier (CBID) identifying a CB to which the first packet belongs,

[0027] a CB group ID identifying a CB group to which the first packet belongs,

[0028] a radio bearer ID identifying a radio bearer to which the first packet belongs,

[0029] a radio bearer group ID identifying a radio bearer group to which the first packet belongs,

[0030] a quality of service (QoS) flow ID identifying a QoS flow to which the first packet belongs, or

[0031] a QoS flow group ID identifying a QoS flow group to which the first packet belongs.

[0032] In a possible implementation of the first aspect, the message includes one or more of:

[0033] a mission session ID identifying a mission session on which the protection should be performed or not,

[0034] a mission session group ID identifying a mission session group on which the protection should be performed or not,

[0035] a data session ID identifying a data session on which the protection should be performed or not,

[0036] a data session group ID identifying a data session group on which the protection should be performed or not,

[0037] a CBID identifying a CB on which the protection should be performed or not,

[0038] a CB group ID identifying a CB group on which the protection should be performed or not,

[0039] a radio bearer ID identifying a radio bearer on which the protection should be performed or not,

[0040] a radio bearer group ID identifying a radio bearer group on which the protection should be performed or not,

[0041] a QoS flow ID identifying a QoS flow on which the protection should be performed or not, or

[0042] a QoS flow group ID identifying a QoS flow group on which the protection should be performed or not.

[0043] In a possible implementation of the first aspect, the method further includes:

[0044] determining, based on whether an intermediate network function between the user equipment and the network function should not be involved in data processing, whether the protection should be performed.

[0045] This approach can support dynamic switching between protected and unprotected states based on whether the intermediate network function should be involved in in-network data processing.

[0046] In a possible implementation of the first aspect, whether the protection should be performed is determined for at least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bears, or one or more QoS flows.

[0047] The determination on whether the protection should be performed may be made based on various granularities, such as, per mission session, per data session, per CB, per radio bearer, or per QoS flow, thereby providing more flexibility of data plane protection between the UE and the network function, accommodating various application scenarios, and adapting to different security requirements.

[0048] In a possible implementation of the first aspect, the determining, based on whether the intermediate network function between the user equipment and the network function should not be involved in data processing, whether the protection should be performed includes:

[0049] determining that the protection should be performed in a case that the intermediate network function between the UE and the network function should not be involved in data processing.

[0050] In a possible implementation of the first aspect, the determining, based on whether the intermediate network function between the user equipment and the network function should not be involved in data processing, whether the protection should be performed includes:

[0051] determining that the protection should not be performed in a case that the intermediate network function between the UE and the network function should be involved in data processing.

[0052] In a possible implementation of the first aspect, the method further includes:

[0053] determining, based on at least one of channel state information or processing payload, whether the intermediate network function between the UE and the network function should be involved in data processing.

[0054] By considering factors, such as, channel state information (CSI) and processing load, the communication apparatus can make a decision on whether to involve the intermediate network function in the data processing. This approach allows for a flexible and efficient management of network resources, optimizing both the performance of data processing and the security of data transmissions.

[0055] In a possible implementation of the first aspect, the method further includes:

[0056] sending or receiving control information which indicates:

[0057] that the protection should be performed; or

[0058] that the protection should not be performed.

[0059] In a possible implementation of the first aspect, the control information further indicates:

[0060] at least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bearers, or one or more QoS flows, where the protection should be performed on the first packet in a case that the first packet belongs to the one or more mission sessions, the one or more data sessions, the one or more CBs, the one or more radio bearers, or the one or more QoS flows; or

[0061] at least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bearers, or one or more QoS flows, where the protection should not be performed on the first packet in a case that the first packet belongs to the one or more mission sessions, the one or more data sessions, the one or more CBs, the one or more radio bearers, or the one or more QoS flows.

[0062] Control information may be exchanged to activate or deactivate the protection on packets transmitted between the UE and the network function. The control information may indicate the activation or deactivation based on various granularities, such as per mission session, per data session, per CB, per radio bearer, or per QoS flow, which can improve flexibility of data plane protection between the UE and the network function, accommodate various application scenarios, and adapt to different security requirements.

[0063] In a possible implementation of the first aspect, the control information is carried in a control PDU of the first protocol layer.

[0064] In a possible implementation of the first aspect, the control information includes one or more of:

[0065] an indication on whether the protection should be performed or not, or activated or deactivated,

[0066] a data session ID identifying a data session or a set of data session IDs identifying a set of data sessions,

[0067] a CBID identifying a CB or a set of CBIDs identifying a set of CBs,

[0068] a mission session ID identifying a mission session or a set of mission session IDs identifying a set of mission sessions,

[0069] a QoS flow ID identifying a QoS flow or a set of QoS flow IDs identifying a set of QoS flows,

[0070] one or more sequence numbers (SNs) , where a value of each SN is used for transmitting packet in order, and / or as material for at least one of ciphering or integrity protection, or

[0071] a reserved field.

[0072] The control information may be transmitted through a control PDU of the first protocol layer, which is a PDU on the data plane. The control PDU may include fields to indicate whether the protection should be performed or not, or activated or not, based on various granularities.

[0073] In a possible implementation of the first aspect, the first packet goes through the first protocol layer for the protection in a case that the protection should be performed.

[0074] When the protection should be performed, the first packet can be delivered to the first protocol layer so that the first packet can be performed with appropriate protection processing at the first protocol layer.

[0075] In a possible implementation of the first aspect, the first packet does not go through the first protocol layer, or goes through the first protocol layer without being performed with the protection in a case that the protection should not be performed.

[0076] When the protection should not be performed, the first packet may not be delivered to the first protocol layer, or the first packet may be delivered to the first protocol layer but protection is not performed for the first packet and in this case, it may be considered that the first protocol layer operates in a transparent mode. In this way, protection will not be performed on the first packet.

[0077] In a possible implementation of the first aspect, the communication apparatus is the UE.

[0078] In a possible implementation of the first aspect, the message is a radio resource control (RRC) message or a non-access stratum control plane (NAS-CP) message.

[0079] In a possible implementation of the first aspect, the first protocol layer is a lower layer of a second protocol layer providing a mission service.

[0080] In a possible implementation of the first aspect, there is one or more additional layers between the first protocol layer and the second protocol layer, and the one or more additional layers include at least one of: a PDU layer, an internet protocol (IP) layer, a user datagram protocol (UDP) layer, a transmission control protocol (TCP) layer, or a quick UDP internet connections (QUIC) layer.

[0081] For the UE, the first protocol layer may be a lower layer of the second protocol layer that provides a mission service, so that data of the second protocol layer can be protected by the first protocol layer. There may be no other layer between the first protocol layer and the second protocol layer, or there may be one or more other layers between the first protocol layer and the second protocol layer, which may depend on actual application scenarios, such as service or transmission requirements and the protocol stack of the UE.

[0082] In a possible implementation of the first aspect, the first protocol layer is an upper layer of a radio layer.

[0083] In a possible implementation of the first aspect, the radio layer includes a service data adaptation protocol (SDAP) layer.

[0084] In a possible implementation of the first aspect, there is one or more additional layers between the first protocol layer and the radio layer.

[0085] In a possible implementation of the first aspect, the one or more additional layers between the first protocol layer and the radio layer include at least one of: a PDU layer, an IP layer, a UDP layer, a TCP layer, or a QUIC layer.

[0086] For the UE, the first protocol layer may be an upper layer of a radio layer, which may be an SDAP layer, so that packets of the first protocol layer can be transmitted to the network function through the radio layer. There may be no other layer between the first protocol layer and the radio layer, or there may be one or more other layers between the first protocol layer and the radio protocol layer, which may depend on actual application scenarios, such as a protocol stack of the UE.

[0087] In a possible implementation of the first aspect, the method further includes:

[0088] determining, at a second protocol layer, based on identification information of the first packet, whether the protection should be performed on the first packet, where the second protocol layer is a higher layer of the first protocol layer.

[0089] For the UE, the first packet may be a packet that is generated by the second protocol layer based on uplink data or an uplink packet and to be delivered from the second protocol layer to a lower layer for transmission to the network side. When the second protocol layer has a first packet, whether the protection should be performed on the first packet can be determined so that the first packet can be delivered to an appropriate lower layer based on a result of the determination, thereby enabling appropriate handling and processing based on the security requirements and the network’s configuration. In addition, since devices not configured with the first protocol layer cannot get access to the protected data of the second protocol layer, e.g., protected data of the mission service (e.g. XaaS service) and cannot be involved in in-network data processing of such protected data, by determining whether protection should be performed and processing the packets accordingly, devices not configured with the first protocol layer but configured with the second protocol layer can be flexibly involved in in-network data processing based on security requirements and the network’s configuration.

[0090] In a possible implementation of the first aspect, the method further includes:

[0091] determining, at a second protocol layer, based on identification information of an uplink packet, whether the protection should be performed on the uplink packet, where the second protocol layer is a higher layer of the first protocol layer, and the uplink packet is included in the first packet.

[0092] The determination on whether the protection should be performed may also be performed before the first packet is generated. For example, uplink data or an uplink packet may be obtained at the second protocol layer, then whether the protection should be performed can be determined based on the identification information of the uplink data or uplink packet, and then the uplink data or uplink packet can be encapsulated in the first packet and delivered to an appropriate layer based on a result of the determination.

[0093] In a possible implementation of the first aspect, the first packet is delivered from the second protocol layer to the first protocol layer in a case that the protection should be performed, the method further including:

[0094] performing, at the first protocol layer, the protection on the first packet to obtain a processed first packet, and sending the processed first packet to a third protocol layer, where the third protocol layer is a lower layer of the first protocol layer.

[0095] When it is determined that the protection should be performed, the first packet can be delivered from the second protocol layer to the first protocol layer so that protection can be performed on the first packet by the first protocol layer to generate the processed first packet, which is then delivered to a lower layer for transmission to the network side. In this case, data of the second protocol layer is protected on the data plane, and devices not configured with the first protocol layer cannot get access to the data of the second protocol layer, e.g., data of the mission service (e.g., XaaS service) and is not involved in in-network data processing of such data, which can guarantee the security and privacy of in-network processing for the mission services e.g., XaaS service.

[0096] In a possible implementation of the first aspect, the protection on the first packet includes at least one of: ciphering, privacy protection, or integrity protection.

[0097] In a possible implementation of the first aspect, the processed first packet is included in a data PDU of the first protocol layer, and the data PDU includes one or more of:

[0098] a mission session ID identifying a mission session the data PDU belongs to,

[0099] a data session ID identifying the data session the DP-Sec data PDU belongs to,

[0100] a CBID identifying a CB the data PDU belongs to,

[0101] a QoS flow ID identifying the data PDU belongs to,

[0102] an indication on whether the protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated,

[0103] a length of the data PDU,

[0104] a sequence number of the data PDU,

[0105] a payload of the data PDU, or

[0106] a reserved field.

[0107] The processed first packet generated at the first protocol layer of the UE can be in a form of the data PDU of the first protocol layer which may include one or more fields listed above. The first packet may be included in the payload of the data PDU, and the PDU may also include IDs of various granularities, the length of the PDU, and / or the sequence number of the PDU, based on which the first protocol layer of the network function can perform suitable processing when receiving the processed first packet. This structured approach can allow for precise control over the security measures applied to each packet, optimizing both security and efficiency during data transmission.

[0108] In a possible implementation of the first aspect, the first packet is delivered from the second protocol layer to a third protocol layer in a case that the protection should not be performed, where the third protocol layer is a lower layer of the first protocol layer.

[0109] When it is determined that the protection should not be performed, the first packet can be delivered to a lower layer of the first protocol layer for transmission, without being processed by the first protocol layer. In this case, the first packet is not protected on the data plane, and devices not configured with the first protocol layer can still get access to the data of the first packet and be involved in in-network data processing if configured with the second protocol layer for data processing.

[0110] In a possible implementation of the first aspect, the method further includes:

[0111] receiving, at the third protocol layer, a packet from an upper layer, where the upper layer is the second protocol layer or the first protocol layer, and the received packet is the first packet from the second protocol layer or the processed first packet from the first protocol layer;

[0112] encapsulating, at the third protocol layer, the received packet and an indication on whether the protection is performed or not, to obtain a second packet of the third protocol layer for transmission;

[0113] where the indication on whether the protection is performed or not has a first value indicating the protection is performed in a case that the received packet is the processed first packet from the first protocol layer, or has a second value indicating the protection is not performed in a case that the received packet is the first packet from the second protocol layer.

[0114] The third protocol layer may receive the first packet from the second protocol layer or the processed first packet from the first protocol layer, and determine whether the protection is performed on a received packet based on the layer from which the packet is received, and then encapsulate the received packet and an indication with a corresponding value to obtain the second packet for transmission. In this way, the indication values can serve as a flag to indicate the protection state, and other device, such as the intermediate network function, which receives the second packet, can be aware of the protection state by checking the indication, which enables appropriate handling and processing based on the security requirements and the network’s configuration.

[0115] In a possible implementation of the first aspect, the indication on whether the protection is performed or not is encapsulated in a packet header or a payload of the second packet of the third protocol layer.

[0116] In a possible implementation of the first aspect, the method further includes:

[0117] determining, at a third protocol layer, whether the protection should be performed or not on the first packet, based on at least one of: identification information of the first packet or an indication on whether protection is performed or not, where the third protocol layer is a lower layer of the first protocol layer.

[0118] For the UE, the first packet may also be a packet that is obtained by the third protocol layer from a downlink packet and to be delivered from the third protocol layer to an upper layer. When the third protocol layer obtains the first packet, it may determine whether the protection should be performed on the first packet. By performing such determination, the first packet can be delivered to an appropriate upper layer based on a result of the determination, thereby enabling appropriate delivering and processing of packets based on the security requirements and the network’s configuration.

[0119] In a possible implementation of the first aspect, the method further includes:

[0120] determining, at a third protocol layer, whether the protection should be performed or not on a downlink packet, based on at least one of: identification information of the downlink packet or an indication on whether protection is performed or not, where the third protocol layer is a lower layer of the first protocol layer, and the first packet is included in the downlink packet.

[0121] The determination on whether the protection should be performed may also be performed before the first packet is obtained. For example, a downlink packet may be obtained by the third protocol layer of the UE from a lower layer, and then whether the protection should be performed can be determined based on the identification information of the downlink packet or an indication on whether protection is performed included in the downlink packet, and then the first packet is obtained from the downlink packet and delivered based on a result of the determination.

[0122] In a possible implementation of the first aspect, the first packet is delivered from the third protocol layer to the first protocol layer in a case that the protection should be performed, the method further including

[0123] performing, at the first protocol layer, the protection on the first packet to obtain a processed first packet and sending the processed first packet to a second protocol layer for data processing, where the second protocol layer is a higher layer of the first protocol layer.

[0124] When the UE determines that the protection should be performed, the first packet can be delivered from the third protocol layer to the first protocol layer so that protection can be performed by the first protocol layer on the first packet to obtain the processed first packet, which is then delivered to the second protocol layer for data processing. In this case, data of the second protocol layer is protected on the data plane, and devices not configured with the first protocol layer cannot get access to the data of the second protocol layer, e.g., data of the mission service (e.g. XaaS service) and are not involved in in-network data processing, which can guarantee the security and privacy of in-network processing for mission services, e.g., XaaS services.

[0125] In a possible implementation of the first aspect, the protection on the first packet includes at least one of: deciphering, privacy protection, or integrity verification.

[0126] In a possible implementation of the first aspect, the first packet is included in a data PDU of the first protocol layer, and the data PDU includes one or more of:

[0127] a mission session ID identifying a mission session the data PDU belongs to,

[0128] a data session ID identifying the data session the DP-Sec data PDU belongs to,

[0129] a CBID identifying a CB the data PDU belongs to,

[0130] a QoS flow ID identifying the data PDU belongs to,

[0131] an indication on whether protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated,

[0132] a length of the data PDU,

[0133] a sequence number of the data PDU,

[0134] a payload of the data PDU, or

[0135] a reserved field.

[0136] The first packet delivered from the third protocol layer of the UE to the first protocol layer of the UE can be in a form of the data PDU of the first protocol layer which may include one or more fields listed above. The processed first packet generated by the first protocol layer and delivered to the second protocol layer may be obtained from the payload of the data PDU, and the data PDU may also include IDs of various granularities, the length of the PDU, and / or the sequence number of the PDU, based on which the first protocol layer can perform processing to obtain the processed first packet. This structured approach can allow for precise control over the security measures applied to each packet, optimizing both security and efficiency during data transmission.

[0137] In a possible implementation of the first aspect, the first packet is delivered from the third protocol layer to a second protocol layer for data processing in a case that the protection should not be performed, and the second protocol layer is a higher layer of the first protocol layer.

[0138] When it is determined that the protection should not be performed, the first packet can be delivered to the second protocol layer for data processing, without being processed by the first protocol layer. In this case, the first packet is not protected on the data plane, and devices not configured with the first protocol layer can get access to the data of the first packet and be involved in in-network data processing if configured with the second protocol layer for data processing.

[0139] In a possible implementation of the first aspect, the third protocol layer is an SDAP layer.

[0140] In a possible implementation of the first aspect, the communication apparatus is the network function.

[0141] In a possible implementation of the first aspect, there is one or more layers above the first protocol layer.

[0142] In a possible implementation of the first aspect, the one or more layers above the first protocol layer include one or more of: a PDU layer, a second protocol layer providing a mission service, an IP layer, a UDP layer, a TCP layer, or a QUIC layer.

[0143] For the network function, there may be one or more other layers above the first protocol layer, which may depend on actual application scenarios. The network function may be or may not be configured with the second protocol layer which provides a mission service. When the network function is configured with the second protocol layer, it may be involved in the in-network data processing. When the network function is not configured with the second protocol layer, it may be connected with another network function which is configured with the second protocol layer for providing the mission service.

[0144] In a possible implementation of the first aspect, the first protocol layer is an upper layer of a transport network layer (TNL) . By this arrangement, transmission of data packets of the first protocol layer can be supported by the TNL

[0145] In a possible implementation of the first aspect, the TNL includes one or more of: a general packet radio service (GPRS) tunnelling protocol for user plane (GTP-U) layer, a UDP layer, a QUIC layer, or an IP layer.

[0146] In a possible implementation of the first aspect, there is one or more additional layers between the first protocol layer and the TNL layer.

[0147] In a possible implementation of the first aspect, the one or more additional layers between the first protocol layer and the TNL layer include at least one of: a PDU layer, an IP layer, a UDP layer, a TCP layer, or a QUIC layer.

[0148] In a possible implementation of the first aspect, the method further includes:

[0149] determining, at a third protocol layer in a first interface oriented to an intermediate function between the UE and the network function, whether the protection should be performed on the first packet, based on at least one of: identification information of the first packet or an indication on whether protection is performed or not, where the third protocol layer is a lower layer of the first protocol layer.

[0150] For the network function, the first packet may be a packet that is obtained from an uplink packet by the third protocol layer in the first interface oriented to the intermediate function, and to be delivered from the third protocol layer to another layer. When the third protocol layer in the first interface obtains the first packet, whether the protection should be performed on the first packet can be determined so that the first packet can be delivered to an appropriate layer based on a result of the determination, thereby enabling appropriate handling and processing based on the security requirements and the network’s configuration.

[0151] In a possible implementation of the first aspect, the method further includes:

[0152] determining, at a third protocol layer in a first interface oriented to an intermediate function between the UE and the network function, whether the protection should be performed on an uplink packet, based on at least one of: identification information of the uplink packet or an indication on whether protection is performed or not, where the third protocol layer is a lower layer of the first protocol layer, and the first packet is included in the uplink packet.

[0153] The determination on whether the protection should be performed may also be performed before the first packet is obtained. For example, an uplink packet may be obtained by the third protocol layer of the first interface from a lower layer, and then whether the protection should be performed can be determined based on the identification information of the uplink packet or an indication on whether protection is performed included in the uplink packet, and then the first packet is obtained from the uplink packet and delivered based on a result of the determination.

[0154] In a possible implementation of the first aspect, the first packet is delivered from the third protocol layer to the first protocol layer in a case that the protection should be performed, the method further including:

[0155] performing, at the first protocol layer, the protection on the first packet to obtain a processed first packet, and sending the processed first packet to a fourth protocol layer in a second interface oriented to another network function for data processing, or sending the processed first packet to a second protocol layer for data processing, where the fourth protocol layer is a lower layer of the first protocol layer, and the second protocol layer is a higher layer of the first protocol layer.

[0156] When the network function determines that the protection should be performed, the first packet can be delivered from the third protocol layer to the first protocol layer so that protection can be performed by the first protocol layer on the first packet to obtain the processed first packet. The processed first packet is then sent to the fourth protocol layer in the second interface so as to be sent to another network function for data processing, or sent to the second protocol layer configured in the network function for data processing. In this case, data of the second protocol layer is protected on the data plane, and devices not configured with the first protocol layer cannot get access to the data of the second protocol layer, e.g., data of the mission service (e.g. XaaS service) and are not involved in in-network data processing, which can guarantee the security and privacy of in-network processing for mission services, e.g., XaaS services.

[0157] In a possible implementation of the first aspect, the protection for the first packet includes at least one of: deciphering, privacy protection, or integrity verification.

[0158] In a possible implementation of the first aspect, the first packet is included in a data PDU of the first protocol layer, and the data PDU includes one or more of:

[0159] a mission session ID identifying a mission session the data PDU belongs to,

[0160] a data session ID identifying the data session the DP-Sec data PDU belongs to,

[0161] a CBID identifying a CB the data PDU belongs to,

[0162] a QoS flow ID identifying the data PDU belongs to,

[0163] an indication on whether protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated,

[0164] a length of the data PDU,

[0165] a sequence number of the data PDU,

[0166] a payload of the data PDU, or

[0167] a reserved field.

[0168] The first packet delivered from the third protocol layer of the first interface to the first protocol layer can be in a form of the data PDU of the first protocol layer which may include one or more fields listed above. The processed first packet generated by the first protocol layer and delivered to the fourth protocol layer of the second interface or the second protocol layer may be obtained from the payload of the data PDU, and the PDU may also include IDs of various granularities, the length of the PDU, and / or the sequence number of the PDU, based on which the first protocol layer can perform processing to obtain the processed first packet. This structured approach can allow for precise control over the security measures applied to each packet, optimizing both security and efficiency during data transmission.

[0169] In a possible implementation of the first aspect, the first packet is delivered from the third protocol layer to a fourth protocol layer in a second interface oriented to another network function for data processing, or delivered from the third protocol layer to a second protocol layer for data processing, in a case that the protection should not be performed, where the fourth protocol layer is a lower layer of the first protocol layer, and the second protocol layer is a higher layer of the first protocol layer.

[0170] When it is determined that the protection should not be performed, the first packet can be delivered to the fourth protocol layer or the second protocol layer for data processing, without being processed by the first protocol layer. In this case, the first packet is not protected on the data plane, and devices not configured with the first protocol layer can still get access to the data of the first packet and be involved in in-network data processing if configured with the second protocol layer for data processing.

[0171] In a possible implementation of the first aspect, the method further includes:

[0172] determining, at a fourth protocol layer in a second interface oriented to another network function, whether the protection should be performed or not on the first packet, based on at least one of: identification information of the first packet or an indication on whether the protection should be performed or not, where the fourth protocol layer is a lower layer of the first protocol layer.

[0173] For the network function, the first packet may also be a packet that is obtained by the fourth protocol layer in the second interface from a downlink packet, and to be delivered from the fourth protocol layer to another layer, e.g., the first protocol layer or the third protocol layer. The downlink packet is received from another network function, and the first packet obtained from the downlink packet may include, e.g., data of the mission service. When the fourth protocol layer obtains the first packet, it may determine whether the protection should be performed on the first packet. By performing such determination, the first packet can be delivered to an appropriate layer based on a result of the determination, thereby enabling appropriate delivering and processing of the packet based on the security requirements and the network’s configuration. In addition, since devices not configured with the first protocol layer cannot get access to the protected data of the mission service (e.g. XaaS service) and cannot be involved in in-network processing of protected data, by determining whether protection should be performed and processing packets accordingly, devices not configured with the first protocol layer but configured with the second protocol layer can be flexibly involved in in-network data processing based on security requirements and the network’s configuration.

[0174] In a possible implementation of the first aspect, the method further includes:

[0175] determining, at a fourth protocol layer in a second interface oriented to another network function, whether the protection should be performed or not on a downlink packet, based on at least one of: identification information of the downlink packet or an indication on whether the protection should be performed or not, where the fourth protocol layer is a lower layer of the first protocol layer, and the first packet is included in the downlink packet.

[0176] The determination on whether the protection should be performed may also be performed before the first packet is obtained. For example, a downlink packet may be obtained by the fourth protocol layer in the second interface from a lower layer, and then whether the protection should be performed can be determined based on the identification information of the downlink packet or an indication on whether the protection should be performed included in the downlink packet, and then the first packet is obtained from the downlink packet and delivered based on a result of the determination.

[0177] In a possible implementation of the first aspect, the first packet is delivered from the fourth protocol layer to the first protocol layer in a case that the protection should be performed, the method further including:

[0178] performing, at the first protocol layer, the protection on the first packet to obtain a processed first packet, and sending the processed first packet to a third protocol layer in a first interface oriented to an intermediate network function between the UE and the network function.

[0179] When the network function determines that the protection should be performed, the first packet can be delivered from the fourth protocol layer to the first protocol layer so that protection can be performed by the first protocol layer on the first packet to obtain the processed first packet, which is then delivered to the third protocol layer in the first interface for  transmission to the intermediate network function. In this case, data of the mission service, e.g., XaaS service, is protected on the data plane, and devices not configured with the first protocol layer cannot get access to the data of the mission service (e.g. XaaS service) and are not involved in in-network data processing, which can guarantee the security and privacy of in-network processing for mission services, e.g., XaaS services.

[0180] In a possible implementation of the first aspect, the protection on the first packet includes at least one of: ciphering, privacy protection, or integrity protection.

[0181] In a possible implementation of the first aspect, the processed first packet is included in a data PDU of the first protocol layer, and the data PDU includes one or more of:

[0182] a mission session ID identifying a mission session the data PDU belongs to,

[0183] a data session ID identifying the data session the DP-Sec data PDU belongs to,

[0184] a CBID identifying a CB the data PDU belongs to,

[0185] a QoS flow ID identifying the data PDU belongs to,

[0186] an indication on whether the protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated,

[0187] a length of the data PDU,

[0188] a sequence number of the data PDU,

[0189] a payload of the data PDU, or

[0190] a reserved field.

[0191] The processed first packet generated at the first protocol layer of the network function and delivered to the third protocol layer in the first interface can be in a form of the data PDU of the first protocol layer which may include one or more fields listed above. The first packet may be included in the payload of the data PDU, and the PDU may also include IDs of various granularities, the length of the PDU, and / or the sequence number of the PDU, based on which the first protocol layer of the UE can perform suitable processing when receiving the processed first packet. This structured approach can allow for precise control over the security measures applied to each packet, optimizing both security and efficiency during data transmission.

[0192] In a possible implementation of the first aspect, the first packet is delivered from the fourth protocol layer to a third protocol layer in a first interface oriented to an intermediate network function between the UE and the network function, in a case that the protection should not be performed, where the third protocol layer is a lower layer of the first protocol layer.

[0193] When it is determined that the protection should not be performed, the first packet can be delivered to the third protocol layer in the first interface for transmission to the intermediate network function, without being processed by the first protocol layer. In this case, the first packet is not protected on the data plane, and devices not configured with the first protocol layer can still get access to the data of the first packet and be involved in in-network data processing if configured with the second protocol layer for data processing.

[0194] In a possible implementation of the first aspect, the method further includes:

[0195] receiving, at the third protocol layer, a packet to be relayed, where the packet to be relayed is the first packet from the fourth protocol layer or the processed first packet from the first protocol layer;

[0196] encapsulating, at the third protocol layer, the packet to be relayed and an indication on whether the protection is performed or not to obtain a second packet of the third protocol layer for transmission;

[0197] where the indication on whether the protection is performed or not has a first value indicating the protection is performed in a case that the packet to be relayed is the processed first packet from the first protocol layer, or has a second value indicating the protection is not performed in a case that the packet to be relayed is the first packet from the fourth protocol layer.

[0198] The third protocol layer in the first interface may receive the first packet from the fourth protocol layer or the processed first packet from the first protocol layer, and determine whether the protection is performed on a received packet based on the layer from which the packet is received, and then encapsulate the received packet and an indication with a  corresponding value to obtain the second packet for transmission. In this way, the indication values can serve as a flag to indicate the protection state, and other device, such as the intermediate network function, which receives the second packet, can be aware of the protection state by checking the indication, which enables appropriate handling and processing based on the security requirements and the network’s configuration.

[0199] In a possible implementation of the first aspect, the indication on whether the protection is performed or not is encapsulated in a packet header or a payload of the second packet of the third protocol layer.

[0200] In a possible implementation of the first aspect, the fourth protocol layer is a GTP-U layer, a UDP layer, a QUIC layer, or an IP layer.

[0201] In a possible implementation of the first aspect, the third protocol layer is a GTP-U layer, a UDP layer, a QUIC layer, or an IP layer

[0202] In a possible implementation of the first aspect, the payload of the data PDU of the first protocol layer is encrypted in a case that the protection is performed.

[0203] In a possible implementation of the first aspect, the protection is performed on the first packet by using at least one of:a mission session ID, a data session ID, a CBID, or a QoS ID of the first packet as one or more of: a ciphering material, a privacy protection material, or an integrity protection material. When the protection is applied using the identifiers as materials, the packet can be ready for transmission over the network, with the appropriate security measures in place to safeguard the data.

[0204] In a possible implementation of the first aspect, the network function is in a core network.

[0205] In a possible implementation of the first aspect, the network function includes a data trustworthy gateway (Data-TW-GW) , or a user plane function (UPF) .

[0206] In a possible implementation of the first aspect, the intermediate network function includes a radio access network (RAN) node.

[0207] In a second aspect, a communication method is provided in the present disclosure, including:

[0208] receiving a message, where the message is used to configure a first protocol layer in a communication apparatus, the first protocol layer is to support data plane security protection, and a data protocol data unit (PDU) of the first protocol layer includes one or more of:

[0209] a mission session identifier (ID) identifying a mission session the data PDU belongs to,

[0210] a data session ID identifying the data session the DP-Sec data PDU belongs to,

[0211] a computing block identifier (CBID) identifying a computing block (CB) the data PDU belongs to,

[0212] a quality of service (QoS) flow ID identifying the data PDU belongs to,

[0213] an indication on whether the protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated,

[0214] a length of the data PDU,

[0215] a sequence number of the data PDU,

[0216] a payload of the data PDU, or

[0217] a reserved field; and

[0218] configuring the first protocol layer based on the message.

[0219] This configuration ensures that the data plane security protection is set up as specified, with the appropriate parameters and settings for identifiers, protection indications, and other relevant data for the PDU. Configuring the first protocol layer enables establishing a secure communication channel that protects the data as it is transmitted between the UE and the network function. The communication system can adapt to different security requirements by configuring the first protocol layer based on the received configuration messages, allowing for flexible and dynamic security measures. Secure and reliable data transmission between the UE and network functions can be enabled by establishing a robust security framework on the data plane.

[0220] In a third aspect, a communication method is provided in the present disclosure, including:

[0221] obtaining a first message, where the first message includes information for configuring a first protocol layer in a user equipment (UE) , the first protocol layer is to support data plane security protection on a first packet, and the protection is between the UE and a network function; and

[0222] sending the first message to the UE.

[0223] The method may be performed by an intermediate network function between the UE and the network function, such as a RAN. By configuring the first protocol layer in the UE, the UE can adapt to different security requirements, allowing for flexible and dynamic security measures. Secure and reliable data transmission between the UE and network functions can be enabled by establishing a robust security framework on the data plane. In addition, the establishment of the first protocol layer, which is to support data plane security protection on a first packet transmitted between the UE and the network function, can apply security protection measures, such as encryption, privacy protection and integrity protection, to the data packets that will be transmitted, ensuring the confidentiality and integrity of the data. The information for configuring the first protocol layer in the UE, included in the first message, may be generated by the intermediate network function, or received by the intermediate network function from another network function, e.g., a C / M plane function.

[0224] In a possible implementation of the third aspect, the network function is in a core network.

[0225] In a possible implementation of the third aspect, the first protocol layer is a lower layer of a second protocol layer, where the second protocol layer is used to provide a mission service, where the mission service is a service for both protocol data unit (PDU) connectivity and data processing and the first protocol layer is to protect at least one of security and privacy of the second protocol layer. The first protocol layer may act as a security layer that ensures the security and privacy of the data handled by the second protocol layer. By structuring the protocol layers in this manner, the security and privacy of in-network processing (also termed as in-network computing) can be guaranteed for mission service, such as a XaaS service.

[0226] In a possible implementation of the third aspect, the second protocol layer is an anything as a service (XaaS) service layer.

[0227] In a possible implementation of the third aspect, the second protocol layer is a processing service function (PSF) layer.

[0228] In a possible implementation of the third aspect, the method further includes:

[0229] receiving a second message from a further network function, where the second message includes information for configuring the first protocol layer in the UE.

[0230] The information for configuring the first protocol layer in the UE may be received from a further network function through the second message. The further network function may be a C / M plane function, such as a C / M-TW-GW, a SCP+, an AMF+, an SMF+, etc.

[0231] In a possible implementation of the third aspect, the information for configuring the first protocol layer in the UE includes information indicating one or more identifiers (IDs) on which the protection should be performed or not.

[0232] In a possible implementation of the third aspect, the method further includes:

[0233] sending assistance information to the further network function, where the assistance information includes the information indicating one or more IDs on which the protection should be performed or not.

[0234] The collaborative approach between the RAN and the further network function can ensure that the security configuration is aligned with the specific needs of the packet transmission, optimizing both security and network performance.

[0235] In a possible implementation of the third aspect, the information indicating one or more identifiers on which the protection should be performed or not includes one or more of:

[0236] a mission session ID identifying a mission session on which the protection should be performed or not,

[0237] a mission session group ID identifying a mission session group on which the protection should be performed or not,

[0238] a data session ID identifying a data session on which the protection should be performed or not,

[0239] a data session group ID identifying a data session group on which the protection should be performed or not,

[0240] a computing block identifier (CBID) identifying a computing block (CB) on which the protection should be performed or not,

[0241] a CB group ID identifying a CB group on which the protection should be performed or not,

[0242] a radio bearer ID identifying a radio bearer on which the protection should be performed or not,

[0243] a radio bearer group ID identifying a radio bearer group on which the protection should be performed or not,

[0244] a quality of service (QoS) flow ID identifying a QoS flow on which the protection should be performed or not, or

[0245] a QoS flow group ID identifying a QoS flow group on which the protection should be performed or not.

[0246] In a possible implementation of the third aspect, where the second message and the first message are to send non-access stratum information between the further network function and the UE, or the second message is a message on an interface with an application protocol between the further network function and an intermediate network function, and the first message is a radio resource control (RRC) message. The information for configuring the first protocol layer may be sent to the UE in various ways, which can provides more flexibility for the transmission of configuration information, and accommodate more application scenarios.

[0247] In a possible implementation of the third aspect, the intermediate network function is in a radio access network (RAN) , the second protocol layer is in the intermediate network function and above a radio layer in a first interface oriented to the UE, where the first interface is a radio interface.

[0248] In a possible implementation of the third aspect, the radio layer includes a service data adaptation protocol (SDAP) layer.

[0249] In a possible implementation of the third aspect, there is one or more additional layers between the second protocol layer and the radio layer.

[0250] In a possible implementation of the third aspect, the intermediate network function is in a RAN, the second protocol layer is in the intermediate network function and above a transport network layer (TNL) in a second interface oriented to the network function.

[0251] In a possible implementation of the third aspect, the TNL layer includes one or more of: a general packet radio service (GPRS) tunnelling protocol for user plane (GTP-U) layer, a user datagram protocol (UDP) layer, a quick UDP internet connections (QUIC) layer, or an internet protocol (IP) layer.

[0252] In a possible implementation of the third aspect, there is one or more additional layers between the second protocol layer and the TNL layer.

[0253] In a possible implementation of the third aspect, the one or more additional layers include one or more of: a protocol data unit (PDU) layer, an IP layer, a UDP layer, a transmission control protocol (TCP) layer, or a QUIC layer.

[0254] In a possible implementation of the third aspect, whether the protection is performed on the first packet is determined based on at least one of :

[0255] identification information corresponding to the first packet, or

[0256] an indication on whether the protection is performed or not, where the indication on whether the protection is performed or not is included in a packet which includes the first packet, or is not included in a packet which includes the first packet.

[0257] By examining either or both of the identification information and an indication within the packet, the network can make decisions about whether to apply security protections such as encryption or integrity protection on a per-packet basis.

[0258] In a possible implementation of the third aspect, the identification information corresponding to the first packet includes at least one of:

[0259] a mission session ID identifying a mission session to which the first packet belongs,

[0260] a mission session group ID identifying a mission session group to which the first packet belongs,

[0261] a data session ID identifying a data session to which the first packet belongs,

[0262] a data session group ID identifying a data session group to which the first packet belongs,

[0263] a CBID identifying a CB to which the first packet belongs,

[0264] a CB group ID identifying a CB group to which the first packet belongs,

[0265] a radio bearer ID identifying a radio bearer to which the first packet belongs,

[0266] a radio bearer group ID identifying a radio bearer group to which the first packet belongs,

[0267] a QoS flow ID identifying a QoS flow to which the first packet belongs, or

[0268] a QoS flow group ID identifying a QoS flow group to which the first packet belongs.

[0269] In a possible implementation of the third aspect, the method further includes:

[0270] determining, based on whether an intermediate network function between the user equipment and the network function should not be involved in data processing, whether the protection should be performed.

[0271] The intermediate network function may assess whether it needs to participate in data processing, and then determine whether the protection should be performed accordingly, enabling dynamic switch of the protection.

[0272] In a possible implementation of the third aspect, whether the protection should be performed is determined for at least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bears, or one or more QoS flows.

[0273] The determination on whether the protection should be performed may be made based on various granularities, such as, per mission session, per data session, per CB, per radio bearer, or per QoS flow, thereby providing more flexibility of data plane protection between the UE and the network function, accommodating various application scenarios, and adapting to different security requirements.

[0274] In a possible implementation of the third aspect, the determining, based on whether the intermediate network function between the user equipment and the network function should not be involved in data processing, whether the protection should be performed includes:

[0275] determining that the protection should be performed in a case that an intermediate network function between the UE and the network function should not be involved in data processing.

[0276] In a possible implementation of the third aspect, the determining, based on whether the intermediate network function between the user equipment and the network function should not be involved in data processing, whether the protection should be performed includes:

[0277] determining that the protection should not be performed in a case that an intermediate network function between the UE and the network function should be involved in data processing.

[0278] In a possible implementation of the third aspect, the method further includes:

[0279] determining, based on at least one of: channel state information or processing payload, whether an intermediate network function between the UE and the network function should be involved in data processing.

[0280] By considering factors, such as, CSI and processing load, the intermediate network function can make a decision on whether the intermediate network function should be involved in the data processing. This approach allows for a flexible and efficient management of network resources, optimizing both the performance of data processing and the security of data transmissions.

[0281] In a possible implementation of the third aspect, the method further includes:

[0282] sending or receiving control information which indicates:

[0283] that the protection should be performed; or

[0284] that the protection should not be performed.

[0285] In a possible implementation of the third aspect, the control information further indicates

[0286] at least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bearers, or one or more QoS flows, where the protection should be performed on the first packet in a case that the first packet belongs to the one or more mission sessions, the one or more data sessions, the one or more CBs, the one or more radio bearers, or the one or more QoS flows; or

[0287] at least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bearers, or one or more QoS flows, where the protection should not be performed on the first packet in a case that the first packet belongs to the one or more mission sessions, the one or more data sessions, the one or more CBs, the one or more radio bearers, or the one or more QoS flows.

[0288] Control information may be exchanged to activate or deactivate the protection on packets transmitted between the UE and the network function. The control information may indicate the activation or deactivation based on various granularities, such as per mission session, per data session, per CB, per radio bearer, or per QoS flow, which can improve flexibility of data plane protection between the UE and the network function, accommodate various application scenarios, and adapt to different security requirements.

[0289] In a possible implementation of the third aspect, the first packet goes through a second protocol layer for data processing in a case that the protection is not performed, and the second protocol layer is a higher layer of the first protocol layer.

[0290] In a possible implementation of the third aspect, the first packet does not go through a second protocol layer for data processing in a case that the protection is performed, and the second protocol layer is a higher layer of the first protocol layer.

[0291] Whether or not the first packet goes through the second protocol layer for data processing may depend on whether the first packet is protected. If the first packet is protected, the intermediate network function cannot parse the data in the first packet and cannot perform data processing, and in this case, the first packet would not be delivered to the second protocol layer. If the first packet is not protected, the intermediate network function can parse the data of the first packet, and the first packet can be delivered to the second protocol layer for data processing.

[0292] In a possible implementation of the third aspect, the method further includes:

[0293] determining, at a third protocol layer in a first interface oriented to the UE, whether the protection is performed or not on the first packet, based on at least one of identification information of the first packet or an indication on whether the protection is performed or not, where the third protocol layer is a lower layer of the first protocol layer.

[0294] The first packet may be a packet that is obtained from an uplink packet by the third protocol layer in the first interface of the intermediate network function, and to be delivered from the third protocol layer to another layer. The third protocol layer may operate within the first interface that is oriented to the UE. The intermediate network function may determine whether the protection is applied to the first packet at the third protocol layer, so that the first packet can be delivered to an appropriate layer based on a result of the determination accordingly.

[0295] In a possible implementation of the third aspect, the method further includes:

[0296] determining, at a third protocol layer in a first interface oriented to the UE, whether the protection is performed or not on an uplink packet, based on at least one of identification information of the uplink packet or an indication on whether the protection is performed or not, where the third protocol layer is a lower layer of the first protocol layer, and the first packet is included in the uplink packet.

[0297] The determination on whether the protection is performed may also be performed before the first packet is obtained. For example, an uplink packet may be obtained by the third protocol layer of the first interface from a lower layer, and then whether the protection is performed can be determined based on the identification information of the uplink packet or an indication on whether the protection is performed included in the uplink packet, and then the first packet is obtained from the uplink packet and delivered based on a result of the determination.

[0298] In a possible implementation of the third aspect, the first packet is delivered from the third protocol layer to a fourth protocol layer in a second interface oriented to the network function in a case that the protection is performed, where the fourth protocol layer is a lower layer of the first protocol layer.

[0299] When it is determined that the protection is performed, the intermediate network function cannot parse the data in the first packet, and may deliver the first packet from the third protocol layer to the fourth protocol layer in the second interface to forward to the network function.

[0300] In a possible implementation of the third aspect, the first packet is delivered from the third protocol layer to a second protocol layer for data processing in a case that the protection is not performed, the second protocol layer is a higher layer of the first protocol layer, and the method further includes:

[0301] performing, at the second protocol layer, data processing on the first packet to obtain a processed first packet containing a processing result of the first packet, and sending the processed first packet to a fourth protocol layer in a second interface oriented to the network function, where the fourth protocol layer is a lower layer of the first protocol layer.

[0302] When it is determined that the protection is not performed, the intermediate network function may deliver the first packet from the third protocol layer to the second protocol layer for data processing. In this case, the first packet is not protected on the data plane, and the intermediate network function can parse and process the data of the first packet.

[0303] In a possible implementation of the third aspect, the method further includes:

[0304] receiving, at the fourth protocol layer, a packet to be relayed, where the packet to be relayed is the first packet from the third protocol layer or the processed first packet from the second protocol layer;

[0305] encapsulating, at the fourth protocol layer, the packet to be relayed and an indication on whether the protection is performed or not to obtain a second packet of the fourth protocol layer for transmission;

[0306] where the indication on whether the protection is performed or not has a first value indicating the protection is performed in a case that the packet to be relayed is the first packet from the third protocol layer, or has a second value indicating the protection is not performed in a case that the packet to be relayed is the processed first packet from the second protocol layer.

[0307] In this way, the indication values can serve as a flag to indicate the protection state, and other device, such as the network function, which receives the second packet, can be aware of the protection state by checking the indication, which enables appropriate handling and processing based on the security requirements and the network’s configuration.

[0308] In a possible implementation of the third aspect, the indication on whether the protection is performed or not is encapsulated in a packet header or a payload of the second packet of the fourth protocol layer.

[0309] In a possible implementation of the third aspect, the method further includes:

[0310] determining, at a fourth protocol layer in a second interface oriented to the network function, whether the protection is performed or not on the first packet, based on at least one of: identification information of the first packet or an indication on whether the protection is performed or not, where the fourth protocol layer is a lower layer of the first protocol layer.

[0311] The first packet may be a packet that is obtained from a downlink packet by the fourth protocol layer in the second interface of the intermediate network function, and to be delivered from the fourth protocol layer to another layer. The fourth protocol layer may operate within the second interface that is oriented towards the network function. The intermediate network function may determine whether the protection is performed on the first packet at the fourth protocol layer, so that the first packet can be delivered to an appropriate layer based on a result of the determination.

[0312] In a possible implementation of the third aspect, the method further includes:

[0313] determining, at a fourth protocol layer in a second interface oriented to the network function, whether the protection is performed or not on a downlink packet, based on at least one of: identification information of the downlink packet or an indication on whether the protection is performed or not, where the fourth protocol layer is a lower layer of the first protocol layer, and the first packet is included in the downlink packet.

[0314] The determination on whether the protection is performed may also be performed before the first packet is obtained. For example, a downlink packet may be obtained by the fourth protocol layer of the second interface from a lower layer, and then whether the protection is performed can be determined based on the identification information of the downlink packet or an indication on whether the protection is performed included in the downlink packet, and then the first packet is obtained from the downlink packet and delivered based on a result of the determination.

[0315] In a possible implementation of the third aspect, the first packet is delivered from the fourth protocol layer to a third protocol layer in a first interface oriented to the UE in a case that the protection is performed, where the third protocol layer is a lower layer of the first protocol layer.

[0316] When it is determine that the protection is performed, the intermediate network function cannot parse the data in the first packet, and may deliver the first packet from the fourth protocol layer to the third protocol layer in the second interface to forward to the UE.

[0317] In a possible implementation of the third aspect, the first packet is delivered from the fourth protocol layer to a second protocol layer for data processing in a case that the protection is not performed, the second protocol layer is a higher layer of the first protocol layer, and the method further includes:

[0318] performing, at the second protocol layer, data processing on the first packet to obtain a processed first packet containing a processing result of the first packet, and sending the processed first packet to a third protocol layer in a first interface oriented to the UE, where the third protocol layer is a lower layer of the first protocol layer.

[0319] When it is determined that the protection is not performed, the intermediate network function may deliver the first packet from the fourth protocol layer to the second protocol layer for data processing. In this case, the first packet is not protected on the data plane, and the intermediate network function can parse and process the data of the first packet.

[0320] In a possible implementation of the third aspect, the method further includes:

[0321] receiving, at the third protocol layer, a packet to be relayed, where the packet to be relayed is the first packet from the fourth protocol layer or the processed first packet from the second protocol layer;

[0322] encapsulating, at the third protocol layer, the packet to be relayed and an indication on whether the protection is performed or not to obtain a second packet of the third protocol layer for transmission;

[0323] where the indication on whether the protection is performed or not has a first value indicating the protection is performed in a case that the packet to be relayed is the first packet from the fourth protocol layer, or has a second value indicating the protection is not performed in a case that the packet to be relayed is the processed first packet from the second protocol layer.

[0324] In this way, the indication values can serve as a flag to indicate the protection state of the packet, the UE can be aware of the protection state of each packet through checking the indication when receiving the second packet, which enables appropriate handling and processing based on the security requirements and the network’s configuration.

[0325] In a possible implementation of the third aspect, the indication on whether the protection is performed or not is encapsulated in a packet header or a payload of the second packet of the third protocol layer.

[0326] In a possible implementation of the third aspect, when it is determine that the protection is performed, the first packet is included in a data PDU of the first protocol layer, and the data PDU includes one or more of:

[0327] a mission session ID identifying a mission session the data PDU belongs to,

[0328] a data session ID identifying the data session the DP-Sec data PDU belongs to,

[0329] a CBID identifying a CB the data PDU belongs to,

[0330] a QoS flow ID identifying the data PDU belongs to,

[0331] an indication on whether the protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated,

[0332] a length of the data PDU,

[0333] a sequence number of the data PDU,

[0334] a payload of the data PDU, or

[0335] a reserved field.

[0336] In a possible implementation of the third aspect, the payload of the data PDU of the first protocol layer is encrypted in a case that the protection is performed.

[0337] In a possible implementation of the third aspect, the third protocol layer is an SDAP layer.

[0338] In a possible implementation of the third aspect, the fourth protocol layer is a GTP-U layer, a UDP layer, an IP layer, or a QUIC layer.

[0339] In a possible implementation of the third aspect, the protection is performed on the first packet by using at least one of:a mission session ID, a data session ID, a CBID, or a QoS ID of the first packet as one or more of: a ciphering material, a privacy protection material, or an integrity protection material.

[0340] In a fourth aspect, a communication apparatus is provided in the present disclosure, configured to perform the method according to the first aspect or any possible implementations of the first aspect or the second aspect or any possible implementations of the second aspect or the third aspect.

[0341] In a possible implementation of the fourth aspect, the apparatus includes:

[0342] a receiving unit, configured to receive a message, where the message is used to configure a first protocol layer in the communication apparatus, and the first protocol layer is to support data plane security protection on a first packet, and the protection is between a user equipment (UE) and a network function; and

[0343] a processing unit, configured to configure the first protocol layer based on the message.

[0344] In a possible implementation of the fourth aspect, the apparatus includes:

[0345] an obtaining unit, configured to obtain a first message, where the first message includes information for configuring a first protocol layer in a UE, and the first protocol layer is to support data plane security protection on a first packet, and the protection is between the UE and a network function; and

[0346] a sending unit, configured to send the first message to the UE.

[0347] In a possible implementation of the fourth aspect, the apparatus includes:

[0348] an interface circuit, configured to receive a message, where the message is used to configure a first protocol layer in the communication apparatus, the first protocol layer is to support data plane security protection on a first packet, and the protection is between a UE and a network function; and

[0349] one or more processors, configured to configure the first protocol layer based on the message.

[0350] In a possible implementation of the fourth aspect, the apparatus includes:

[0351] one or more processors, configured to obtain a first message, where the first message includes information for configuring a first protocol layer in a UE, the first protocol layer is to support data plane security protection between the UE and a network function; and

[0352] an interface circuit, configured to send the first message to the UE.

[0353] In a possible implementation of the fourth aspect, the communication apparatus is the UE.

[0354] In a possible implementation of the fourth aspect, the communication apparatus is the network function.

[0355] In a fifth aspect, a communication system is provided in the present disclosure, the communication system including: the communication apparatus according to the fourth aspect or any possible implementations of the fourth aspect.

[0356] In a sixth aspect, a computer-readable storage medium is provided in the present disclosure, the computer-readable storage medium having instructions stored thereon which, when executed by an apparatus, cause the apparatus to perform the method of the first aspect or the second aspect or any possible implementations of the first aspect or the second aspect or any possible implementations of the second aspect or the third aspect.

[0357] In a seventh aspect, a computer program product is provided in the present disclosure, the computer program product storing instructions which, when executed, cause an apparatus to perform the method of the first aspect or the second aspect or any possible implementations of the first aspect or the second aspect or any possible implementations of the second aspect or the third aspect.

[0358] In an eighth aspect, a communication apparatus is provided in the present disclosure, the communication apparatus including one or more processors, the one or more processors is configured to execute instructions stored in one or more memories to implement the method of the first aspect or the second aspect or any possible implementations of the first aspect or the second aspect or any possible implementations of the second aspect or the third aspect.BRIEF DESCRIPTION OF THE DRAWINGS

[0359] The accompanying drawings are used to provide a further understanding of the present disclosure, constitute a part of the specification, and are used to explain the present disclosure together with the following specific example embodiments, but should not be construed as limiting the present disclosure.

[0360] FIG. 1 is a simplified schematic illustration of a communication system according to one or more embodiments of the present disclosure.

[0361] FIG. 2 is a schematic illustration of another example communication system according to one or more embodiments of the present disclosure.

[0362] FIG. 3A is a schematic illustration of an apparatus in a communication system according to one or more embodiments of the present disclosure.

[0363] FIG. 3B is a schematic illustration of another apparatus in a communication system according to one or more embodiments of the present disclosure.

[0364] FIG. 4 is a schematic illustration an apparatus in a communication system according to one or more embodiments of the present disclosure.

[0365] FIG. 5 is a schematic illustration an apparatus in a communication system according to one or more embodiments of the present disclosure.

[0366] FIG. 6 is a schematic illustration of 5G PDU session according to one or more embodiments of the present disclosure.

[0367] FIG. 7 illustrates a 5G user plane protocol stack between UE and gNB.

[0368] FIG. 8 is a schematic illustration of a mission service provided by a 6G network according to one or more embodiments of the present disclosure.

[0369] FIG. 9 is a schematic illustration of a mission session for a mission service according to one or more embodiments of the present disclosure.

[0370] FIG. 10 illustrates a mission session for mission service according to one or more embodiments of the present disclosure.

[0371] FIG. 11 is a schematic illustration of tunnels configured per mission session according to one or more embodiments of the present disclosure.

[0372] FIG. 12 is a schematic illustration of tunnels configured per network entity according to one or more embodiments of the present disclosure.

[0373] FIG. 13 illustrates a protocol stack on data plane to support XaaS service according to one or more embodiments of the present disclosure.

[0374] FIG. 14 illustrates a protocol stack on data plane to support XaaS service according to one or more embodiments of the present disclosure.

[0375] FIG. 15 illustrates a protocol stack between XaaS layer and TNL or radio layer according to one or more embodiments of the present disclosure.

[0376] FIG. 16 illustrates another protocol stack on data plane to support XaaS service according to one or more embodiments of the present disclosure.

[0377] FIG. 17 illustrates traffic between XaaS functions according to one or more embodiments of the present disclosure.

[0378] FIG. 18 is a schematic illustration of a 6G System conceptual structure according to one or more embodiments of the present disclosure.

[0379] FIG. 19 illustrates a block diagram of 6G System conceptual structure according to one or more embodiments of the present disclosure.

[0380] FIG. 20 illustrates a data plane security (DP-Sec) layer according to one or more embodiments of the present disclosure.

[0381] FIG. 21 illustrates a traffic flow when RAN-PSF layer is involved or not according to one or more embodiments of the present disclosure.

[0382] FIG. 22 illustrates a dynamic switch for DP-Sec protection according to one or more embodiments of the present disclosure.

[0383] FIG. 23 shows a schematic flowchart of a communication method according to one or more embodiments of the present disclosure.

[0384] FIG. 24 shows a schematic flowchart of a communication method according to one or more embodiments of the present disclosure.

[0385] FIG. 25 illustrates an evolved GTP-U header according to one or more embodiments of the present disclosure.

[0386] FIG. 26 illustrates an SDAP header according to one or more embodiments of the present disclosure.

[0387] FIG. 27 illustrates a flowchart for configuration on DP-Sec protection according to one or more embodiments of the present disclosure.

[0388] FIG. 28 shows a schematic flowchart of a communication method according to one or more embodiments of the present disclosure.

[0389] FIG. 29 illustrates a format of a DP-Sec data PDU according to one or more embodiments of the present disclosure.

[0390] FIG. 30 illustrates a format of a DP-Sec control PDU according to one or more embodiments of the present disclosure.

[0391] FIG. 31 illustrates a DP-Sec layer for security protection according to one or more embodiments of the present disclosure.

[0392] FIG. 32 illustrates other layers for security protection according to one or more embodiments of the present disclosure.

[0393] FIG. 33 shows a schematic structural diagram of a communication apparatus according to one or more example embodiments of the present disclosure.

[0394] FIG. 34 shows a schematic structural diagram of a communication apparatus according to one or more example embodiments of the present disclosure.DETAILED DESCRIPTION

[0395] In the following description, reference is made to the accompanying figures, which form part of the present disclosure, and which show, by way of illustration, specific aspects of examples of the present disclosure or specific aspects in which examples of the present disclosure may be used. It is understood that examples of the present disclosure may be used in other aspects and include structural or logical changes not depicted in the figures. The following detailed description, therefore, is not to be taken in a limiting sense, and the scope of the present disclosure is defined by the appended claims.

[0396] To assist in understanding the present disclosure, examples of wireless communication systems and devices are described below.

[0397] FIG. 1 is a simplified schematic illustration of a communication system according to one or more embodiments of the present disclosure. Referring to FIG. 1, as an illustrative example, a simplified schematic illustration of a communication system is provided. The communication system 100 may comprise a radio access network 120. The radio access network (RAN) 120 may be a next generation (e.g. 6th generation (6G) or later) radio access network, or a legacy (e.g. 5th generation (5G) , 4th generation (4G) ) radio access network. In some implementations, 6G radio access refers to a next generation air interface of standards which may comprise both terrestrial networks (TNs) and non-terrestrial networks (NTNs) , and more details will be described below. One or more communication electronic device (ED) 110a, 110b, 110c, 110d, 110e, 110f, 110g, 110h, 110i, 110j (generically referred to as 110) may be interconnected to one another or connected to one or more network nodes 170a, 170b (generically referred to as 170) in the RAN 120. A core network (CN) 130 may be a part of the communication system and may be dependent or independent of the radio access technology used in the communication system 100. The communication system 100 may also comprise a public switched telephone network (PSTN) 140, the internet 150, and other networks 160.

[0398] In general, the communication system 100 enables communication of multiple wireless or wired elements. The communication system 100 may provide content, such as voice, data, video, and / or text, via broadcast, multicast, groupcast, unicast, etc. The communication system 100 may operate by sharing resources, such as carrier spectrum bandwidth, among its constituent elements.

[0399] The communication system 100 may provide a wide range of communication services and applications including enhanced Mobile Broadband (eMBB) services, ultra-reliable low-latency communication (URLLC) services, massive machine  type communication (mMTC) services, integrated sensing and communication (ISAC) , immersive communication, massive communication, Hyper reliable and low-latency communication, ubiquitous connectivity, integrated AI and communication, and other services that can be provided by a future generation communication system. The communication system 100 may provide other services and applications such as earth monitoring, remote sensing, passive sensing and positioning, navigation and tracking, autonomous delivery and mobility, etc.

[0400] FIG. 2 is a schematic illustration of another example communication system according to one or more embodiments of the present disclosure. As described earlier, the communication system 100 may include ED 110a, 110b, 110c, 110d (generically referred to as ED 110) , RAN 120a, 120b, and one or more of a CN 130, a PSTN 140, the internet 150, and other networks 160. In addition, the communication system 100 may also include a non-terrestrial network (NTN) 120c. The RANs 120a, 120b may include respective network nodes 170a, 170b such as base stations 170a, 170b, which may be generically referred to as terrestrial network (TN) devices or terrestrial transmit and receive points (T-TRPs) 170a, 170b (generically referred to as 170) . As referred to herein, the terms “TRP” and “base station” may be used interchangeably unless explicitly noted otherwise in a given example or section. For brevity, this disclosure may primarily refer to base station; however, absent an explicit limitation, references to TRP are merely non-limiting instances of interchangeable use. The T-TRPs 170a, 170b may be base stations mounted on a building or tower. In one implementation, the NTN 120c includes a RAN node such as base station 172, which may be generically referred to as an NTN device, a non-terrestrial node, a non-terrestrial network device, a non-terrestrial base station, or a non-terrestrial transmit and receive point (NT-TRP) 172.

[0401] A base station (also referred to TRP as stated above) 170 may be a network element in radio access network responsible for radio transmission and reception in one or more cells to or from the user equipment. Base station 170 may be known by other names in some implementations, such as a base transceiver station (BTS) , a radio base station, a network node, a network device, a device on the network side, a transmit / receive node, a Node B, an evolved NodeB (eNodeB or eNB) , a Home eNodeB, a next Generation NodeB (gNB) , a transmission point (TP) , a site controller, an access point (AP) , a wireless router, a relay station, a terrestrial node, a terrestrial network device, a terrestrial base station, a positioning node, among other possibilities. The base station 170 may be a macro base station (BS) , a pico BS, a relay node, a donor node, or the like, or combinations thereof. When a base station 170 performs (or is configured to perform) a method described herein, it may be interpreted as the base station, one or more modules (or units) in the base station, a circuit or chip, or a combination thereof, may perform the method. For example, the circuit or chip may include a modem chip, also referred to as a baseband chip, a system on chip (SoC) including a modem core, system in package (SIP) ) , and the like, and may be responsible for one or more communication functions in the base station.

[0402] Any base station may be a single element, as shown, or multiple elements, distributed in the corresponding RAN, or otherwise. In some implementations, a plurality of RAN nodes coordinate to assist the ED 110 in implementing radio access, and different RAN nodes separately implement different functions of the base station. For example, the RAN node may be a central unit (CU) , a distributed unit (DU) , a CU-control plane (CP) , a CU-user plane (UP) , or a radio unit (RU) etc. The CU and the DU may be separately deployed, or may be included in a same element (i.e., a baseband unit (BBU) ) . The RU may be included in a radio frequency device or a radio frequency unit (i.e., a remote radio unit (RRU) , an active antenna unit (AAU) , or a remote radio head (RRH) ) .

[0403] The ED 110 is used to connect persons, objects, machines, etc. The ED 110 may be widely used in various scenarios including, for example, cellular communications, device-to-device (D2D) , vehicle to everything (V2X) , peer-to-peer (P2P) , machine-to-machine (M2M) , MTC, internet of things (IoT) , virtual reality (VR) , augmented reality (AR) , mixed reality (MR) , metaverse, digital twin, industrial control, self-driving, remote medical, smart grid, smart furniture, smart office, smart wearable, smart transportation, smart city, drones, robots, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery and mobility, etc.

[0404] Each ED 110 represents any suitable end user device for wireless operation and may include such devices (or may be referred to but not limited to) as a user equipment (UE) or a user device or a terminal device, a wireless transmit / receive unit (WTRU) , a mobile station, a fixed or mobile subscriber unit, a cellular telephone, a station (STA) , a MTC device, a  personal digital assistant (PDA) , a smartphone, a laptop, a computer, a tablet, a wireless sensor, a consumer electronics device, a smart book, a vehicle, a car, a truck, a bus, a train, or an IoT device, wearable devices (such as a watch, a pair of glasses, head mounted equipment, etc. ) , an industrial device, or an apparatus in (e.g. module, modem, or chip) or comprising the forgoing devices, among other possibilities. Future generation EDs 110 may be referred to using other terms. When an ED 110 performs (or is configured to perform) a method described herein, it may be interpreted as the ED, one or more module (or units) in the ED, a circuit or chip, or a combination thereof, may perform the method. For example, the circuit or chip may include a modem chip, also referred to as a baseband chip, a system on chip (SoC) including a modem core, or system in package (SIP) ) , and the like, and may be responsible for one or more communication functions in the ED.

[0405] An air interface (e.g., 190a, 190b, 190c) generally includes a number of components and associated parameters that collectively specify how a transmission is to be sent and / or received over a wireless communications link between two or more communicating devices such as ED and base station. For example, an air interface may include one or more components defining the waveform (s) , frame structure (s) , multiple access scheme (s) , protocol (s) , coding scheme (s) and / or modulation scheme (s) for conveying information (e.g., data) over a wireless communications link. The air interfaces 190a and 190b may use similar communication technology, such as any suitable radio access technology.

[0406] The RANs 120a and 120b are in communication with the CN 130 to provide the EDs 110a 110b, and 110c with various services such as voice, data, and other services. The RANs 120a and 120b and / or the CN 130 may be in direct or indirect communication with one or more other RANs (not shown) , which may or may not be directly served by CN 130, and may or may not employ the same radio access technology as RAN 120a, RAN 120b or both. The CN 130 may also serve as a gateway access between (i) the RANs 120a and 120b or EDs 110a 110b, and 110c or both, and (ii) other networks (such as the PSTN 140, the Internet 150, and the other networks 160) . In addition, some or all of the EDs 110a 110b, and 110c may include functionality for communicating with different wireless networks over different wireless links using different wireless technologies and / or protocols. Instead of wireless communication (or in addition thereto) , the EDs 110a 110b, and 110c may communicate via wired communication channels to a service provider or switch (not shown) , and to the Internet 150. PSTN 140 may include circuit switched telephone networks for providing plain old telephone service (POTS) . Internet 150 may include a network of computers and subnets (intranets) or both, and incorporate protocols, such as internet protocol (IP) , transmission control protocol (TCP) , user datagram protocol (UDP) . EDs 110a 110b, and 110c may be multimode devices capable of operation according to multiple radio access technologies, and incorporate multiple transceivers necessary to support such.

[0407] In addition, the communication system 100 may comprise a sensing agent (not shown) to manage the sensed data from ED 110 and / or any one of TRPs 170 a-170b, 172. In one implementation, the sensing agent may be part of any one of TRPs 170 a-b, 172. In another implementation, the sensing agent is a separate node that can communicate with the CN 130 and / or the RAN 120 (e.g., any one of TRPs 170 a-b, 172) .

[0408] FIG. 3A illustrates an example of an apparatus 310 wirelessly communicating with an apparatus 320 in a communication system (e.g., the communication system 100) . The apparatus 310 may be an electronic device (e.g. ED 110) . The apparatus 320 may be a network node (e.g. network node 170) such as T-TRP 170 or a NT-TRP 172. Although there is only one apparatus 310, and one apparatus 320 shown in the figure, the number of apparatus 310 and / or 320 could be one or more. For example, one ED 110 may be served by only one T-TRP 170 (or one NT-TRP 172) , by more than one T-TRP 170 (or more than one NT-TRP 172) . One ED 110 may be served by one or more T-TRP 170 and one or more NT-TRP172. Similarly, one T-TRP 170 (or one NT-TRP172) may serve one or more ED 110.

[0409] Apparatus 310 includes at least one processor 210. Only one processor 210 is illustrated to avoid congestion in the drawing. The apparatus 310 may further include a transmitter 201 and a receiver 203 coupled to one or more antennas 204. Only one antenna 204 is illustrated to avoid congestion in the drawing. One, some, or all of the antennas 204 may alternatively be panels. The transmitter 201 and the receiver 203 may be integrated, e.g. as a transceiver. The transceiver is configured to modulate data or other content for transmission by at least one antenna 204 or network interface controller (NIC) . The transceiver is also configured to demodulate data or other content received by the at least one antenna 204. Each transceiver  includes any suitable structure for generating signals for wireless or wired transmission and / or processing signals received wirelessly or by wire. Each antenna 204 includes any suitable structure for transmitting and / or receiving wireless or wired signals. The apparatus 310 may include at least one memory 208. Only the transmitter 201, receiver 203, processor 210, memory 208, and antenna 204 is illustrated for simplicity, but the apparatus 310 may include one or more other components. In present disclosure, the transceiver (or transmitter 201 and / or receiver 203) may be viewed as an interface circuit.

[0410] The apparatus 310 may include at least one memory 208. The memory 208 stores instructions used to perform operations described herein. The memory 208 may also stores data used, generated, or collected by the apparatus 310. For example, the memory 208 could store software instructions or modules configured to implement some or all of the functionality and / or embodiments described herein and that are executed by one or more processors 210.

[0411] The apparatus 310 may further include one or more input / output devices (not shown) or interfaces. The input / output devices or interfaces permit interaction with a user or other devices in the network. Each input / output device or interface includes any suitable structure for providing information to or receiving information from a user, and / or for network interface communications. Suitable structures include, for example, a speaker, microphone, keypad, keyboard, display, touch screen, etc.

[0412] The processor 210 may perform (or control the apparatus 310 to perform) operations (or methods) described herein as being performed by the apparatus 310.

[0413] Although not illustrated, the processor 210 may form part of the transmitter 201 and / or part of the receiver 203. Although not illustrated, the memory 208 may form part of the processor 210.

[0414] The processor 210, the processing components of the transmitter 201, and the processing components of the receiver 203 may each be implemented by the same or different one or more processors that are configured to execute instructions stored in a memory (e.g. in the memory 208) .

[0415] The apparatus 320 includes one or more processors 260 (only one processor 260 is illustrated to in the figure) . The apparatus 320 may further include at least one transmitter 252 and at least one receiver 254 coupled to one or more antennas 256. Only one antenna 256 is illustrated to avoid congestion in the drawing. One, some, or all of the antennas 256 may alternatively be panels. The transmitter 252 and the receiver 254 may be integrated as a transceiver. The apparatus 320 may further include at least one memory 258. The apparatus 320 may further include scheduler 253. Only the transmitter 252, receiver 254, processor 260, memory 258, antenna 256 and scheduler 253 are illustrated for simplicity, but the apparatus 320 may include one or more other components. In present disclosure, the transceiver (or transmitter 252 and / or receiver254) may be viewed as an interface circuit.

[0416] In some implementations, the parts of the apparatus 320 may be distributed. For example, some of the modules of the apparatus 320 may be located remote from the equipment that houses the antennas 256 for the apparatus 320 (thereby also can be viewed as one of more nodes) , and may be coupled to the equipment that houses the antennas 256 over a communication link (not shown) sometimes known as front haul, such as common public radio interface (CPRI) . Therefore, in some implementations, the term apparatus 320 may also refer to nodes on the network side that perform processing operations, such as determining the location of the apparatus 310, resource allocation (scheduling) , message generation, and encoding / decoding, and that are not necessarily part of the equipment that houses the antennas 256 of the apparatus 320. The nodes may also be coupled to other apparatus 320s. In some implementations, the apparatus 320 may actually be a plurality of nodes that are operating together to serve the apparatus 310, e.g. through the use of coordinated multipoint transmissions, or the use of ORAN system as described above in the application.

[0417] The apparatus 320a may further includes a memory 258 storing instructions used to perform operations described herein. The memory 258 may also stores data used, generated, or collected by the apparatus 320a. For example, the memory 258 could store software instructions or modules configured to implement some or all of the functionality and / or embodiments described herein and that are executed by the processor 260.

[0418] Although not illustrated, the processor 260 may form part of the transmitter 252 and / or part of the receiver 254. Also, although not illustrated, the processor 260 may implement the scheduler 253. Although not illustrated, the memory 258 may form part of the processor 260.

[0419] The processor 260, the scheduler 253, the processing components of the transmitter 252, and the processing components of the receiver 254 may each be implemented by the same or different one or more processors that are configured to execute instructions stored in a memory, e.g. in the memory 258.

[0420] The apparatus 320 and / or the apparatus 310 may include other components, but these have been omitted for the sake of clarity.

[0421] FIG. 3B illustrates an example of an apparatus 330 in a communication system (e.g., the communication system 100) . The apparatus 330 may be CN, any components in CN or any Network Function of CN. As shown in FIG. 3B, the apparatus 330 may include at least one processor 331. Only one processor 331 is illustrated to avoid congestion in the drawing. The processor 331 may perform (or control the apparatus 330 to perform) operations (or methods) described herein as being performed by the apparatus 330. The apparatus 330 may further include a transmitter 332, a receiver 333, and at least one memory 334. One or more network functions of the CN can be distributed across one or more devices, such as X86 servers.

[0422] It should be noted that in present application, “information” , when different from “message” , may be carried in one single message, or be carried in more than one separate message.

[0423] FIG. 4 is a schematic illustration an apparatus in a communication system according to one or more embodiments of the present disclosure. FIG. 4 illustrates an example of an apparatus 410. The apparatus 410 may be a communication device or an apparatus implemented in a communication device such as ED 110 or TRPs 170a-170b, 172. For example, the apparatus implemented in a communication device may be an integrated circuit, which in some contexts may be known by other colloquial names, such as chip, modem, modem chip, baseband chip, or baseband processor. In some implementations, one or more integrated circuits can be packaged into a system-on-chip, a system-in-package, or a multi-chip module. The apparatus may comprise one or more integrated circuits or comprise one or more integrated circuits and other discrete components. In some implementations, the apparatus 410 may be a module in ED 110, or apparatus 320. In some implementations, the apparatus 410 may be a module in one of TRPs 170a-170b, 172, or apparatus 320.

[0424] In an example, the apparatus 410 may include one or more processors / processor cores 411, and an interface circuit 412. The apparatus 410 may further include a memory 413. The one or more processors / processor cores 411 are configured to process signals and execute one or more communication protocols. The memory 413 is configured to store at least a part of corresponding computer program instructions and / or data. In an example, the one or more processors (or processor cores) 411 execute the computer program instructions stored in the memory 413 to implement related operations (for example, inputting, outputting, receiving, and transmitting) in the foregoing method embodiments. In some implementations, the memory 413 being configured to store the corresponding computer program instructions and / or data may mean that the memory 413 is configured to store all of the corresponding computer program instructions and / or data for execution by the one or more processors / processor cores 411. In some implementations, the memory 413 being configured to store the corresponding computer program instructions and / or data may mean that the memory 413 is configured to store a part of the corresponding computer program instructions and / or data. For example, the part of the corresponding computer program instructions and / or data include computer program instructions and / or data that need to be currently executed by the one or more processors / processor cores 411. Thus, the memory 413 may store different parts of computer program instructions and / or data for a plurality times for the one or more processors (or processor cores) 411 to perform related operations in the foregoing method embodiments. As a communication interface, the interface circuit 412 is configured to implement communication with another component. For example, the interface circuit 412 may communicate a signal with other apparatus / system such as a radio frequency processing apparatus, or processor system. Optionally, to reduce a load of the processor core, a baseband signal processing circuit 414 may be also disposed to implement processing of at least a part of baseband signals, including signal demodulation, modulation, encoding, decoding, or the like.

[0425] Apparatus 410 may be processor 210 (or 260) in apparatus 320, in some scenario, or included in processor 210 (or 260) in apparatus 320 in some scenario. Apparatus 410 may be or include a baseband chip. In some implementations, the apparatus 410 may be independently packaged into a chip. In some implementations, the apparatus 320 includes different types of chips. The apparatus 410 may be packaged into a processor chip (for example, a SoC chip or an SIP chip) with the different types of chips. In some implementations, the apparatus 410 may be packaged into a chip with some or all of circuits of a radio frequency processing system that may further included in the apparatus 320.

[0426] FIG. 5 is a schematic illustration of an apparatus in a communication system according to one or more embodiments of the present disclosure. FIG. 5 illustrates an example of apparatus 510. Apparatus 510 may include corresponding modules or units configured to implement methods and / or embodiments described herein. In some implementations, the apparatus 510 includes a processing unit 512 and a communication unit 513. Optionally, the apparatus 510 may further include a storage unit 514 configured to store apparatus program code (or instructions) and / or data.

[0427] The apparatus 510 may be an ED side apparatus, for example, an ED or a module in an ED, or a circuit or a chip responsible for a communication function in an ED. In some implementations, apparatus 510 may be implemented as apparatus 320, accordingly, the processing unit 512 is implemented as processor 210, the communication unit 513 is implemented as transmitter 201 and / or receiver 203, and the storage unit 511 is implemented as memory 208.

[0428] The apparatus 510 may be a CN side apparatus or a base station side apparatus, for example, a base station or a module in a base station, or a circuit or a chip responsible for a communication function in a base station. In some implementations, apparatus 510 may be implemented as apparatus 320, accordingly, the processing unit 512 is implemented as processor 260 (the scheduler 253 may also be included) , the communication unit 513 is implemented as transmitter 252 and / or receiver 254, and the storage unit 511 is implemented as memory 258.

[0429] In some implementations, when the apparatus 510 is an ED 110 or a module in an ED 110, a function of the apparatus 510 may be implemented by one or more processors. Specifically, the processor may include a modem chip, or a system on chip SoC chip or an SIP chip that includes a modem core. A function of the communication unit 513 may be implemented by a transceiver circuit.

[0430] In some implementations, when the apparatus 510 is a circuit or a chip that is responsible for a communication function in a ED 110, for example, a modem chip, a system on chip SoC chip or an SIP chip that includes a modem core, a function of the processing unit 512 may be implemented by a circuit system that is in the chip and that includes one or more processors or processor cores. A function of the communication unit 513 may be implemented by an interface circuit or a data transceiver circuit on the foregoing chip.

[0431] It may be understood that division into the units in the foregoing apparatus is merely logical function division. Each function may correspond to one functional unit, or two or more functions may be integrated into one functional unit. In actual implementation, all or some of the units may be integrated into one physical entity, or may be distributed in different physical entities. In addition, the foregoing functional units may be implemented in a form of hardware, may be implemented in a form of software, or may be implemented in a form of a combination of hardware and software. Whether a function is performed in a form of hardware or software depends on particular applications and design constraint conditions of the technical solutions. A person skilled in the art may use different methods to implement the described functions for each particular application, but it should not be considered that the implementation goes beyond the scope of this application.

[0432] In an example, a functional unit in any one of the foregoing apparatuses may be configured as one or more integrated circuits for implementing the foregoing methods, for example, one or more application-specific integrated circuits (application-specific integrated circuits, ASICs) , one or more central processing units (central processing units, CPUs) , one or more microprocessors (microcontroller units, MCUs) , one or more digital signal processors (digital signal processors, DSP) , one or more field programmable gate arrays (field programmable gate arrays, FPGAs) , or a combination of at least two of these integrated circuit forms.

[0433] In an example, the storage unit 901 may include a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, and / or a register.

[0434] A processor, a processor system, an application processor, a baseband processor, a processor circuit, or a processor core may be collectively referred to as a processor. The processor may include one or a combination of a central processing unit (central processing unit, CPU) , a digital signal processor (digital signal processor, DSP) , a microprocessor (microprocessor unit, MPU) , a microcontroller (microcontroller unit, MCU) , a graphics processing unit (graphics processing unit, GPU) , a field programmable gate array (field programmable gate array, FPGA) , an artificial intelligence processor (artificial intelligence processor, AI processor) , or a neural network processing unit (neural network processing unit, NPU) .

[0435] The memory may include one or more of the following storage media: a random access memory (random access memory, RAM) , a static random access memory (static RAM, SRAM) , a dynamic random access memory (dynamic RAM, DRAM) , a phase-change memory (phase-change memory, PCM) , a resistive random access memory (resistive RAM, ReRAM) , a magnetoresistive random access memory (magnetoresistive RAM, MRAM) , a ferroelectric random access memory (ferroelectric RAM, FRAM) , a cache (cache) , a register (register) , a read-only memory (read-only memory, ROM) , a flash memory (flash memory) , an erasable programmable read-only memory (erasable programmable ROM, EPROM) , a hard disk (hard disk) , and the like. In an example, the computer program instructions used to execute the foregoing embodiments may be stored in a non-volatile memory, for example, at least a part of the memory 1060 (for example, one or more of a ROM, a flash memory, an EPROM, or a hard disk) . When the terminal runs, a part or all of corresponding computer program instructions may be loaded to a memory that has a higher transmission speed with the processor, for example, at least a part of the memory 1036 and / or the memory 10312 (for example, one or more of a RAM, an SRAM, a DRAM, a PCM, a RERAM, an MRAM, a FRAM, a cache (cache) , or a register) , so that the processor executes the computer program instructions to perform the steps in the foregoing method embodiments.

[0436] The solution described in the present disclosure may be applicable to a next generation (e.g. sixth generation (6G) or later) network, or a legacy (e.g. 5G, 4G) network.

[0437] PDU connectivity service is provided by 5G network. PDU connectivity service is a service that provides exchange of PDUs between a UE and a Data Network (DN) . 5G network provides PDU connectivity service to a UE via one or more PDU sessions. FIG. 6 is a schematic illustration of 5G PDU session according to one or more embodiments of the present disclosure. As in FIG. 6, for a PDU session, it is an association between the UE and a Data Network (DN) that provides a PDU connectivity service. There are intermediate network nodes (e.g., RAN node gNB, UPF) in the PDU session between UE and DN. One or more QoS flows may be transmitted via a PDU session. The QoS Flow is the finest granularity of QoS differentiation in the PDU Session. User Plane traffic within a QoS flow of a PDU Session receives the same traffic forwarding treatment (e.g. scheduling, admission threshold, delay, loss rate) .

[0438] On network side, user plane tunnels (e.g., GTP-U tunnel) are established to deliver the data of a PDU session. For example, there are NG-U tunnel (e.g., N3 tunnel) between RAN and UPF, tunnel (e.g., N9 tunnel) between two UPFs, and tunnel (e.g., N6 tunnel) between UPF and DN, etc. The data of a PDU session is delivered via the tunnels on network side.

[0439] Over the air, data radio bearer is established between UE and RAN. The data radio bearer transports the packets of a PDU session over the air. There is a one-to-multiple mapping between the PDU session and the data radio bearer. The data of a PDU session is mapped to one or more data radio bearers by RAN. For example, one QoS flow of a PDU session is mapped to one data radio bearer, and different QoS flows of the PDU session can be mapped to the same or different data radio bearers.

[0440] To establish a PDU session for data forwarding, the 5G control plane functions (e.g., AMF, SMF, RAN CP) configures the user plane functions (e.g., UPF, RAN UP) to establish the resources for the PDU session, e.g., to establish the tunnels (e.g., GTP-U tunnel) on the network side and data radio bearers over the air. For example, GTP-U tunnel (e.g., for N3 tunnel, N9 tunnel) is established per PDU session, and a GTP-U tunnel is dedicated to a PDU session. One or multiple data radio bearers are established over the air for a PDU session. Packet detection rule and forwarding action rule are configured to user plane function when the PDU session resource is setup under the control of control plane function. For example, the mapping between GTP-U tunnel and PDU session is configured to user plane function to enable data forwarding.

[0441] The QoS Flow is the finest granularity of QoS differentiation in the PDU Session. A QoS Flow ID (QFI) is used to identify a QoS Flow in the 5G System. User Plane traffic with the same QFI within a PDU Session receives the same traffic forwarding treatment (e.g. scheduling, admission threshold) . The QFI is carried in an encapsulation header on N3 (and N9) i.e. without any changes to the end to end packet header. QFI shall be used for all PDU Session Types. The QFI shall be unique within a PDU Session. The QFI may be dynamically assigned or may be equal to the 5QI. A QoS Flow is associated with QoS requirements as specified by QoS parameters and QoS characteristics.

[0442] User plane functions (e.g., UPF, RAN UP) performs suitable actions to deliver uplink and / or downlink data. For example, UPF classifies PDU layer packets for QoS flow marking (e.g., based on packet detection rule) and maps the QoS flows to GTP-U tunnels. And other user plane function (e.g., UPF, RAN) decides the QoS flow that a received packet belongs to based on the QoS flow identifier marked in the packet header, and decides the PDU session that a received packet belongs to, based on the tunnel via which the packet is delivered. RAN maps QoS flows of a PDU session received in a specific GTP-U tunnel to data radio bearers.

[0443] 5G user plane protocol stack between UE and gNB is depicted in FIG. 7. Data radio bearer (DRB) is configured with Service Data Adaptation Protocol (SDAP) sublayer, Packet Data Convergence Protocol (PDCP) sublayer, Radio Link Control (RLC) sublayer, Medium Access Control (MAC) sublayer and Physical Layer (PHY) .

[0444] User plane functions (e.g., UPF, RAN UP) performs suitable actions to deliver uplink and / or downlink data. For example, UPF classifies PDU layer packets for QoS flow marking (e.g., based on packet detection rule) and maps the QoS flows to GTP-U tunnels. And other user plane function (e.g., UPF, RAN) decides the QoS flow a received packet belongs to, based on the QoS flow identifier marked in the packet header, and decides the PDU session that a received packet belongs to, based on the tunnel via which the packet is delivered. RAN (i.e., SDAP) maps QoS flows of a PDU session received in a specific GTP-U tunnel to data radio bearers.

[0445] As described in 3GPP TS 37.324, the SDAP entities are located in the SDAP sublayer. Several SDAP entities may be defined for a UE. There is an SDAP entity configured for each individual PDU session for NR Uu. SDAP entity is per PDU session.

[0446] However, for a next generation (e.g. sixth generation (6G) or later) network, or a legacy (e.g. 5G, 4G, 3G or 2G) network, e.g., in 6G era, the 6G network is expected to not only for connectivity, but also for data processing. In-network data processing (or termed as in-network computing interchangeably) is supported. The in-network data processing is for XaaS service (e.g., NET4AI, DAM, NET4DW, etc. ) , e.g., to execute AI model training or inferencing, ISAC data processing, data pre-processing (e.g., data normalization, data cleaning) .

[0447] FIG. 8 is a schematic illustration of a mission service provided by a 6G network according to one or more embodiments of the present disclosure. As in FIG. 8, mission service is expected to be provided by 6G network. A mission is to achieve a designated goal, known as mission goal, which includes (1) providing PDU connectivity and optionally (2) providing data processing. Mission service is a service that provides achieving of a mission goal (i.e., PDU connectivity and / or data processing) . When the mission goal includes providing data processing, the mission goal is associated with specific computational problem (s) , and providing data processing refers to solving the specific computational problem (s) . In this case, the mission includes one or multiple computing blocks (CBs) and is associated with a networking procedure among the CBs for solving the specific computational problem (s) . A CB within the mission corresponds to a defined computational step toward the mission goal (i.e. solving the specific computational problem (s) ) and may be supported by a XaaS service (in the form of a task) , a data network (DN) , or another mission service; accordingly, the CB is referred to as a task CB, an external CB or a sub-mission CB. A CB corresponds to a particular action of data processing, e.g., AI training, AI inference, data pre-processing, data de-privatization, data cleaning, data collection, data analytics, sensing, etc. Different CBs of a mission may be executed in sequence or parallel. When the mission goal only includes providing PDU connectivity, the mission service is reduced to the 5G PDU connectivity service.

[0448] When the mission goal includes providing data processing, the data is forwarded to one or more CB entities and processed by the CB entities, then the processed data is forwarded to next-hop one or more CB entities, until the mission goal  is completed. Each of the CB entities executing one or more CBs. The CB entities are supported by XaaS services and / or DN. The CB entities can be deployed in device (e.g., UE, vehicle, radar, sensor, drone, and actuator) , RAN, CN, and even in third parties. In some cases, the mission service including the CB entities are configured and under the control of C / M plane functions, e.g., a mission management function (MM) . As in FIG. 8, devices deploying CB entities and other CB entities provided by XaaS services and / or DN are involved in a mission service to perform data processing in parallel and / or sequence. For example, CB entities 1, 2, 3 and 4 are provided by XaaS services 1, 2, 3 and 4, respectively, and the two devices may also provide other CB entities (not illustrated in the figure) or not. In some cases, the CB entities 1, 2, 3 and 4 may be provided by a same XaaS service instead of 4 different XaaS services. The CB entities and devices are connected via data trustworthy gateway (Data-TW-GW) . In some cases, the CB entity, Data-TW-GW are deployed on 6G data plane, and the data plane may be also termed as user plane, or enhanced user plane, etc. In some cases, the Data-TW-GW could be UPF, or enhanced UPF. CB DP entities (e.g., deployed in device, RAN, CN and DN) are connected via Data-TW-GW. The Data-TW-GW is helpful to get rid of mesh topology among CBs and to support anonymous communication among CBs.

[0449] For the data processing (computing) procedure within the mission service:

[0450] the two devices may deliver data (non-processed or processed data by CB entities in the devices) to CB entity 1 being provided by XaaS service 1 (e.g., DAM service) ;

[0451] CB entity 1 delivers the data directly or deliver the data after processing to CB entity 2 being provided by XaaS service 2 (e.g., NET4AI service) , via Data-TW-GW 1;

[0452] in parallel, CB entity 2 receives data from CB entity 4 being provided by XaaS service 4 (e.g., NET4DW service) , via Data-TW-GW1 and Data-TW-GW2;

[0453] and the data received by CB entity 2 from CB entity 4 is the processed results of the data received by CB entity 4 from CB entity 3 being provided by XaaS service 3 (e.g., NET4Data) , via Data-TW-GW2;

[0454] then CB entity 2 performs data processing of AI training (or AI inference, etc. ) using all the received data from CB entities 1, 3 and 4, and sends the processed results to CB entity 4;

[0455] CB entity 4 perform data processing using the data sent by CB entity 2 and the data from CB entity 3, and sends the processed results to CB entity 2; and then, back and forth data processing and forwarding are performed among CB entities 2, 3 and 4 until the mission goal is completed.

[0456] In some case, a mission corresponds to a service function chain as defined by IETF, e.g., in in RFC 7665. A service function chain is defined as a logical representation of an ordered set (sequence) of service functions that need to successively handle some traffic, e.g. traffic is first handled by service function1 (e.g. Deep Packet Inspection) , then service function 2 (e.g. TCP / IP optimization) and lastly by Service function 3 (e.g. Firewall) .

[0457] FIG. 9 is a schematic illustration of a mission session for a mission service according to one or more embodiments of the present disclosure. As in FIG. 9, mission service subscriber (e.g., 6G device, AS) accesses mission service via one or multiple mission sessions.

[0458] A mission session is an association between a network entity (e.g. a UE, a NF, and an AS) and a Data Network (DN) , providing a mission service. And the DN may be virtual and dummy DN. A mission session includes the data forwarding and data processing resources to execute a mission. A mission session includes a collection (group) of data sessions and optional inter-GW sessions.

[0459] Mission service is a service that provides achieving of a mission goal (i.e., PDU connectivity and / or data processing) . When the mission goal includes providing data processing, the mission goal is associated with specific computational problem (s) , and providing data processing refers to solving the specific computational problem (s) . In this case, the mission includes one or multiple computing blocks (CBs) and is associated with a networking procedure among the CBs for solving the specific computational problem (s) . A CB within the mission corresponds to a defined computational step toward the mission goal (i.e. solving the specific computational problem (s) ) and may be supported by a XaaS service (in the form of a task) , a data network (DN) , or another mission service; accordingly, the CB is referred to as a task CB, an external CB or a sub-mission CB. A CB corresponds to a particular action of data processing, e.g., AI training, AI inference, data pre-processing,  data de-privatization, data cleaning, data collection, data analytics, sensing, etc. Different CBs of a mission may be executed in sequence or parallel.

[0460] A Data Session is an association at least terminates at a Computing Block (CB) entity to execute one or more CBs of a mission. The CB entity is an entity to execute the actions corresponding to the one or more CBs. Particular data transmission and / or data processing are executed among the CB entities in specific order (e.g., in sequence and / or parallel) to complete the mission. The CB entity is supported by XaaS service and / or DN. The CB entity is a network entity which can be deployed in: device (e.g., UE, vehicle, radar, sensor, drone, and actuator) , RAN, CN, DN, and even in third parties. In some cases, the CB entity is deployed on 6G data plane. In some cases, the CB entity is supported by a XaaS service, e.g., by a processing service function (PSF) of the XaaS service. Different CB entities may execute the same or different CBs. In some cases, a data session corresponds to one CB of a mission. In some cases, a data session corresponds to multiple CBs of a mission.

[0461] In some cases, the data session may be regarded as only including the data forwarding resource to execute one or more CBs of a mission, i.e., a pipe to connect a CB entity with another network entity, and the data processing resources configured in the CB entity do not belong to the data session.

[0462] In some cases, the data session may be regarded as including both the data forwarding and data processing resources to execute one or more CBs of a mission, i.e., the data processing resources configured in the CB entity also belongs to the data session.

[0463] In some cases, a data session is an association between a CB entity and a Data-TW-GW.

[0464] In some cases, a data session is an association between a CB entity and another CB entity.

[0465] In some cases, for implementation, a data session is an association between a device (e.g., UE, vehicle, radar, sensor, drone, and actuator) and a Data-TW-GW. The Data-TW-GW may be deployed in RAN or CN.

[0466] In some cases, for implementation, a data session is an association between a Data-TW-GW and a processing service function (PSF) provided by a XaaS service. The Data-TW-GW may be deployed in RAN or CN. The PSF may be deployed in RAN or CN.

[0467] In some cases, for implementation, a data session is an association between a device and a PSF provided by a XaaS service. The PSF may be deployed in RAN or CN.

[0468] In some cases, for implementation, a data session is an association between a PSF and another PSF, and the two PSFs may be provided by a same or different XaaS services. Both or either of the two PSFs may be deployed in RAN or CN.

[0469] In some cases, for implementation, a data session is an association between a DN and a PSF provided by a XaaS service. The PSF may be deployed in RAN or CN.

[0470] In some cases, for implementation, a data session is an association between a DN and a Data-TW-GW. The Data-TW-GW may be deployed in RAN or CN.

[0471] In some cases, for implementation, a data session is an association between two devices.

[0472] In some cases, for implementation, a data session is an association between two DNs.

[0473] In some cases, for implementation, a data session is an association between a device and a DN.

[0474] An Inter-GW Session is an association between two Data-TW-GW for data forwarding. In some cases, the Data-TW-GW could be UPF, or enhanced UPF. CB DP entities (e.g., deployed in device, RAN, CN and DN) are connected via Data-TW-GW. The Data-TW-GW is helpful to get rid of mesh topology among CBs and to support anonymous communication among CBs.

[0475] A CB entity (deployed in device, RAN, CN or DN) may participate into one or multiple Mission Sessions. A CB entity may participate into one or multiple Data Sessions.

[0476] A mission session can be identified by a mission session ID or a session group ID. A data session can be identified by a data session ID or a session group ID.

[0477] As in FIG. 9, a mission session consists of one or multiple Data Sessions. There are two CB entities deployed in RAN, two CB entities deployed in core network functions (NFs) or DN. Devices may also deploy CB entities or be active as  CB entities not illustrated in the figure. The CB entity may be supported by XaaS service. Over the air, radio bearer is established between device and 6G RAN node. Data session is established between device deploying CB entity and a Data-TW-GW. Each device establishes one or multiple data sessions belongs to a mission session. On or multiple devices are involved in a mission session. Flexible mapping are enabled between radio bearer and Data Session. On network side, data session is established between a CB entity and a Data-TW-GW. There could be one or multiple Data Sessions between a CB entity and a Data-TW-GW, and a CB entity (e.g., deployed in PSF of XaaS) could belong to one or multiple Data Sessions. A CB entity (e.g., deployed in PSF of XaaS) could belong to one or multiple Mission Sessions. One or multiple Inter-GW sessions are established between Data-TW-GWs. FIG. 10 illustrates a mission session for mission service according to one or more embodiments of the present disclosure. As in FIG. 10, two devices are involved in a mission session, and each device establishes two data sessions. A data session may be mapped to a radio bearer, or multiple data sessions are mapped to a radio bearer. It does not rule out the possibility that a data session is mapped to multiple radio bearers. One of the two CB entities in RAN establishes 2 data sessions illustrated as small rectangular boxes, another one of the two CB entities in RAN establishes 1 data session. One CB entity in NFs or DN establishes 2 data sessions, and one CB entity in NFs or DN establishes 1 data session. Two Inter-GW sessions are established between the two Data-TW-GWs.

[0478] A mission includes no CBs (i.e. no computing-related functionalities) when its goal is only to provide PDU connectivity. In this case, A Mission Session is reduced to a PDU Session. Different Mission Session Types can be defined: PDU connectivity only type, and both data connectivity and processing type (i.e., non PDU connectivity only type) . The PDU connectivity only type indicates that no CB entity is involved in the mission session, i.e., the mission session is reduced to PDU session in this case. The both data connectivity and processing type (i.e., non PDU connectivity only type) indicates that there is CB entity involved in the mission session, both data forwarding and processing are supported via the mission session, e.g., to support 6G services of data processing (e.g., AI, sensing, data service) .

[0479] In some cases, the CB entity of a mission session is a virtual and dummy entity, e.g., for a mission session of PDU connectivity only type.

[0480] In this application, the terms forward (forwarding) , transmit (transmission) and deliver (delivery) are used interchangeably. Data connectivity and data forwarding are used interchangeably.

[0481] In some cases, a mission session consists of one or more data sessions.

[0482] In some cases, a data session corresponds to one or more CBs.

[0483] In some cases, one or multiple QoS flows are delivered in a data session. QoS flow is the finest granularity of QoS differentiation in the mission service. Traffic within the same QoS flow receives the same data processing treatment and data forwarding treatment. In some cases, a data session is implemented as a QoS flow.

[0484] New radio bearers dedicated for mission service may be established over the air on C / M plane and data plane to provide service with particular QoS. For example, new data radio bearer dedicated for a mission session is established over the air on data plane to provide service with particular QoS.

[0485] Different data sessions of a mission session may be mapped and connected via one or more Data-TW-GWs, e.g., depending on whether, and how many Data-TW-GWs are deployed.

[0486] Different data sessions of a mission session may be mapped and connected internally within a CB entity.

[0487] FIG. 10 is a schematic illustration of tunnels configured per data (inter-GW) session according to one or more embodiments of the present disclosure. As an example, for FIG. 10, a rectangular represents a data session or an inter-GW session of a mission session, and a cylindrical represents a tunnel dedicatedly configured for a data session or an inter-GW of the mission session. The tunnel is configured per data session for a mission session and cannot be shared by different data sessions or inter-GW sessions between two network entities. The type of the tunnel is not limited to GTP-U tunnel, QUIC connection, etc. CB entity 1 establishes data sessions 1 and 2 with Data-TW-GW 1. CB entity 2 establishes data sessions 3, 4 and 5 with Data-TW-GW 1. CB entity 3 establishes data sessions 1 and 2 with Data-TW-GW 2. There are inter-GW sessions 1 and 2 established between Data-TW-GW1 and Data-TW-GW2.7 tunnels are established each of which is dedicated for a data session, and 2 tunnels are established each of which is dedicated for an inter-GW session. As illustrated by the dash line,  data sessions 1 and 2 of CB entity 1 are mapped to data session 3 of CB entity 2 via Data-TW-GW 1, data session 3 of CB entity 2 is mapped to data session 4 of CB entity 2 within CB entity 2, data session 4 of CB entity 2 is mapped to inter-GW session 1 via Data-TW-GW 1, inter-GW session 1 is mapped to data session 2 of CB entity 3 via Data-TW-GW2, data session 2 of CB entity 3 is mapped to data session 1 of CB entity 3 within CB entity 3, data session 1 of CB entity 3 is mapped to inter-GW session 2 via Data-TW-GW2. For example, CB entity 1 executes two CB 1 and CB 2 corresponding to data session 1 and data session 2, respectively. CB entity 1 sends the data processing results of CBs 1 and 2 (corresponding to data sessions 1 and 2, respectively) to data session 3 of CB entity 2 via Data-TW-GW 1. CB entity 2 executes CB 3 to using the received data from CB entity 1 and then sends the new data processing results to CB entity 1. Back and forth data forwarding and data processing are performed between CB entity 1 and CB entity 2 until they are completed. Then CB entity 2 sends the final data processing results of CB 3 to data session 4 of CB entity 2. CB entity 2 executes CB 4 corresponding to data session 4 and sends data processing results to data session 2 of CB entity 3 via Data-TW-GW1 and Data-TW-GW2 through inter-GW session 1. CB entity 3 executes CB 6 corresponding to data session 2. Back and forth data forwarding and data processing are performed between CB entity 2 and CB entity 3 until CB 4 of CB entity 2 and CB 6 of CB entity 3 are completed. Then CB entity 3 sends the final data processing results of CB 6 to data session 1 of CB entity 3. CB entity 3 executes CB 7 corresponding to data session 1 and sends data processing results to data session 5 of CB entity 2 via Data-TW-GW2 and Data-TW-GW1 through inter-GW session 2. CB entity 2 executes CB 5 corresponding to data session 5. Back and forth data forwarding and data processing are performed between CB entity 3 and CB entity 2 until CB 5 of CB entity 2 and CB 7 of CB entity 3 are completed. Then the mission may be completed. It can be observed that, some data from CB entity 2 should be sent to CB entity 1 via Data-TW-GW1, and some data from CB entity 2 should be sent to CB entity 3 via Data-TW-GW1. In order to enable the CB entities and the Data-TW-GWs to deliver data in specific sequence of CBs of a mission via suitable tunnel, and to enable them to detect and recognize the packet received via a tunnel, data forwarding information, e.g., data mapping information and tunnel information, should be configured to the CB entities and Data-TW-GWs, and data processing information, e.g., CB sequence, should be configured to the CB entities.

[0488] In some cases, CB entity 1, CB entity 2 and Data-TW-GW1 are in network domain 1, CB entity 3 and Data-TW-GW 2 are in network domain 2. Network domain 1 and Network domain 2 can be the same or not. The network domain can be RAN, CN, DN and terminal device. For example, network domain 1 is RAN and network domain 2 is CN, and vice versa. Network domain 1 is RAN and network domain 2 is DN, and vice versa. Network domain 1 is CN and network domain 2 is DN, and vice versa. Network domain 1 is RAN and network domain 2 is device, and vice versa.

[0489] In some cases, one or more of the CB entities are in the DN. For example, the CB entity 1, CB entity 2, Data-TW-GW 1 and Data-TW-GW2 are in CN, and CB entity 3 is in DN. As another example, the CB entity 1, CB entity 2 and Data-TW-GW 1 are in RAN, Data-TW-GW2 is in CN, and CB entity 3 is in DN. As another example, Data-TW-GW2 and CB entity 3 are in RAN, Data-TW-GW1 is in CN, and CB entity 1 and CB entity 2 are in DN. As another example, Data-TW-GW2, CB entity 3 and Data-TW-GW1 are in CN, and CB entity 1 and CB entity 2 are in DN.

[0490] FIG. 11 is a schematic illustration of tunnels configured per mission session according to one or more embodiments of the present disclosure. As an example, for FIG. 11, compared with FIG. 11, a rectangular represents a data session or an inter-GW session of a mission session, and the difference is that a cylindrical represents a tunnel configured for the mission session between two network entities. The tunnel is configured per mission session and can be shared by different data sessions or inter-GW sessions between two network entities. The type of the tunnel is not limited to GTP-U tunnel, QUIC connection, etc. Tunnel 1 between CB entity 1 and Data-TW-GW 1 for the mission session is established, Tunnel 2 between CB entity 2 and Data-TW-GW 1 for the mission session is established, Tunnel 3 between CB entity 3 and Data-TW-GW 2 for the mission session is established, and Tunnel 4 between Data-TW-GW 1 and Data-TW-GW 2 for the mission session is established. For example, some packets (e.g., packets of data session 3) received from Tunnel 2 should be forwarded by Data-TW-GW 1 to CB entity 1, but some packets (e.g., packets of data session 4) received from Tunnel 2 should be forwarded by Data-TW-GW 1 to Data-TW-GW2 then to CB entity 3. Different from the case where a dedicated tunnel is configured per data session, when tunnel is configured per mission session, additional information should be configured to enable CB entity and Data-TW-GW  to detect, recognize and deliver packet, and necessary information should be encapsulated into packet (e.g., packet header or payload) .

[0491] FIG. 12 is a schematic illustration of tunnels configured per network entity according to one or more embodiments of the present disclosure. As an example, for FIG. 12, compared with FIG. 10 and FIG. 11, there are two mission sessions illustrated in the figure respectively represented by the dash line and the solid line, a rectangular represents a data session or an inter-GW session of a mission session, and a cylindrical represents a tunnel shared by the two mission sessions between the network entities. Three data sessions 1, 2 and 3 are established between CB entity 1 and Data-TW-GW1, four data sessions 4, 5, 6 and 7 are established between CB entity 2 and Data-TW-GW1, and two data sessions 1 and 2 are established between CB entity 3 and Data-TW-GW2. Data sessions 1 and 2 of CB entity 1, data sessions 4 and 5, and data session 2 of CB entity 3 belongs to mission session 1. Data sessions 3, data sessions 6 and 7 and data session 1 of CB entity 3 belongs to mission session 2. The tunnel is configured per network entity. It means the tunnel can be shared by different mission sessions of the network entity. The type of the tunnel is not limited to GTP-U tunnel, QUIC connection, etc. Tunnel 1 between CB entity 1 and Data-TW-GW 1 for the two mission sessions is established, Tunnel 2 between CB entity 2 and Data-TW-GW 1 for the two mission sessions is established, Tunnel 3 between CB entity 3 and Data-TW-GW 2 for the two mission sessions is established, and Tunnel 4 between Data-TW-GW 1 and Data-TW-GW 2 for the two mission sessions is established. For example, some packets (e.g., packets of data session 4) received from Tunnel 2 should be forwarded by Data-TW-GW 1 to CB entity 1, but some packets (e.g., packets of data session 5) received from Tunnel 2 should be forwarded by Data-TW-GW 1 to Data-TW-GW2 then to CB entity 3. Different from the cases where a tunnel is configured per data session or mission session, when tunnel is configured per network entity, additional information should be configured to enable CB entity and Data-TW-GW to detect, recognize and deliver packet, and necessary information should be encapsulated into packet (e.g., packet header or payload) .

[0492] As described above, over the air, radio bearer is established between device and 6G RAN node. Radio bearers dedicated for mission service may be established over the air on data plane to provide service with particular QoS. For example, data radio bearer dedicated for a mission session is established over the air on data plane to provide service with particular QoS. On or multiple devices are involved in a mission session. Each device establishes one or multiple data radio bears corresponding to a mission session. As in FIG. 9, two devices are involved in a mission session, and each device establishes two data sessions. Flexible mapping are enabled between radio bearer and Data Session. A data session may be mapped to a radio bearer (one-to-one mapping) , or multiple data sessions are mapped to a radio bearer (multiple-to-one mapping) . It does not rule out the possibility that a data session is mapped to multiple radio bearers (one-to-multiple mapping) .

[0493] FIG. 13 illustrates a protocol stack on data plane to support XaaS service according to one or more embodiments of the present disclosure. As in FIG. 13, XaaS service layer is deployed to support XaaS service. On data plane, the XaaS service layer (e.g., PSF layer) is the upper layer of Transport Network Layer (TNL) or radio layer (e.g., SDAP layer) . For example, for the protocol stack on the network side (e.g., the protocol stack for the core network (CN) interface, or the protocol stack for the interface between RAN and CN) , the XaaS service layer (e.g., PSF layer) is the upper layer of TNL (e.g., GTP-U, UDP, IP, L2 and L1 in sequence) . In some cases, the GTP-U protocol can be replaced by QUIC. In some cases, the IP layer can based on IPv4, IPv6, or SRv6. For the protocol stack over the air (e.g., the protocol stack on UE, protocol stack for the air interface between UE and RAN) , the XaaS service layer (e.g., PSF layer) is the upper layer of SDAP (e.g., SDAP, PDCP, RLC, MAC and PHY in sequence) .

[0494] FIG. 14 illustrates a protocol stack on data plane to support XaaS service according to one or more embodiments of the present disclosure. As in FIG. 14, on UE side, the PSF layer is the upper layer of SDAP layer. The PSF layer is the upper layer of SDAP layer on RAN side for radio interface. In core network, there is PSF network function (CN-PSF) , and the CN-PSF network function is implemented via deploying PSF layer as the upper layer of TNL. For the protocol stack on the RAN side for the interface oriented to CN-PSF, the PSF layer is the upper layer of TNL. In some case, as in Figure 9, there is intermediate data plane functions between RAN and CN-PSF, e.g., a Data-TW-GW or a UPF+ for data forwarding. In some  case, there is not intermediate data plane functions between RAN and CN-PSF, they are connected with each other via direct interface.

[0495] The XaaS layer can be deployed PSF layer within 3GPP network (e.g., 3GPP defines PSF layer functionality or PDU format) , it has the advantage that 3GPP network can have strong control of XaaS service, e.g., the C / M plane of the 3GPP network can configure the data plane XaaS layer (e.g., PSF layer) . For example, the C / M plane can configure QoS parameters, data processing parameters to XaaS service layer (e.g., PSF layer) .

[0496] In some cases, PSF layer is directly above TNL.

[0497] In some cases, as in FIG. 15, there are other layers between XaaS service layer and TNL or SDAP layer, e.g., TCP layer, QUIC layer, UDP layer, IP layer. FIG. 15 illustrates a protocol stack between XaaS layer and TNL or radio layer according to one or more embodiments of the present disclosure. For example, there are TCP and IP layers in sequence between PSF layer and SDAP layer. For example, there are UDP and IP layers in sequence between PSF layer and SDAP layer. For example, there are QUIC, UDP and IP layers in sequence between PSF layer and SDAP layer.

[0498] In some cases, there is PDU layer between XaaS layer and TNL or SDAP layer.

[0499] In some cases, there is data plane security protection (DP-Sec) layer between XaaS layer and TNL or SDAP layer.

[0500] In some cases, some of layers TNL are not deployed, e.g., GTP-U layer, UDP layer.

[0501] In some cases some of layers of radio layer are not deployed, e.g., SDAP layer.

[0502] FIG. 16 illustrates another protocol stack on data plane to support XaaS service according to one or more embodiments of the present disclosure. As in FIG. 16, compared with FIG. 14, there are other layers between PSF layer and TNL or radio layer (e.g., SDAP layer) , e.g., TCP and IP layers in sequence, UDP and IP layers in sequence, QUIC, UDP and IP layers in sequence.

[0503] In some cases, if there are other layer deployed between XaaS service layer and TNL or radio layer (e.g., SDAP layer) . XaaS service layer may be considered to be out of the scope of 3GPP, and 3GPP network may have relatively fewer control on XaaS service (e.g., PSF layer) .

[0504] PSF entity can be established in the PSF layer. In some cases, a CB entity is implemented as a PSF entity. A PSF entity executes one or more CBs.

[0505] In some cases, the PSF entity can be configured per mission session, per mission session, per data session (group) , per CB (group) , or per network function.

[0506] For a PSF entity per mission session in a network function, the PSF entity is dedicated for a mission session. The network function corresponds to one or more data sessions of the mission session, and the PSF entity is shared by the one or more data sessions. The network function should execute one or more CBs corresponding to the mission session, and the PSF entity executes the one or more CBs. Each data session of the mission session corresponds to a number of CBs. Different PSF entities should be established for different mission sessions.

[0507] For a PSF entity per data session (group) in a network function, the PSF entity is dedicated for a data session (group) of a mission session. The network function corresponds to one or more data sessions of the mission session, the one or more data sessions includes the data session (group) , and the PSF entity corresponds to the data session (group) and is not shared by the other data sessions of the one or more data sessions. The network function should execute one or more CBs corresponding to the data session (group) , and the PSF entity executes the one or more CBs. Each data session (group) of the mission session corresponds to a number of CBs. Different PSF entities should be established for different data sessions (groups) of the mission session.

[0508] For a PSF entity per CB (group) in a network function, the PSF entity is dedicated for a CB (group) of a mission session. The network function should execute one or more CBs of the mission session, the one or more CBs includes the CB (group) , and the PSF entity corresponds to the CB (group) and is not shared by the other CBs of the one or more CBs. Different PSF entities should be established for different CBs (groups) of the mission session.

[0509] For a PSF entity per network function, the PSF entity is established in a network function. The network function corresponds to one or more mission sessions, and the PSF entity is shared by the one or more mission sessions. The PSF entity is established for all the different mission sessions corresponding to the network function.

[0510] In some cases, the PSF entity can be established per mission session group in a network function, the PSF entity is dedicated for a mission session group. The network function corresponds to one or more mission sessions, and the PSF entity is shared by the mission session group and is not shared by the other mission sessions of the one or more mission sessions. If the mission session group comprises all the one or more mission sessions, the PSF entity can be also considered as being established per network function.

[0511] In some cases, a data session comprise a number of QoS flows, or is implemented with a QoS flow.

[0512] Similarly, entities of other layers (e.g., SDAP entity, PDCP entity, RLC entity, MAC entity, PHY entity, GTP-U layer entity, UDP layer entity, IP layer entity) can be configured per mission session, per data session (group) , per CB (group) , or per network function. Taking an SDAP entity as an example:

[0513] For an SDAP entity per mission session in a network function, the SDAP entity is dedicated for a mission session. The network function corresponds to one or more data sessions of the mission session, and the SDAP entity is shared by the one or more data sessions. The network function should execute one or more CBs corresponding to the mission session, and the SDAP entity executes the one or more CBs. Each data session of the mission session corresponds to a number of CBs. Different SDAP entities should be established for different mission sessions.

[0514] For an SDAP entity per data session (group) in a network function, the SDAP entity is dedicated for a data session (group) of a mission session. The network function corresponds to one or more data sessions of the mission session, the one or more data sessions includes the data session (group) , and the SDAP entity corresponds to the data session (group) and is not shared by the other data sessions of the one or more data sessions. The network function should execute one or more CBs corresponding to the data session (group) , and the SDAP entity executes the one or more CBs. Each data session (group) of the mission session corresponds to a number of CBs. Different SDAP entities should be established for different data sessions (groups) of the mission session.

[0515] For an SDAP entity per CB (group) in a network function, the SDAP entity is dedicated for a CB (group) of a mission session. The network function should execute one or more CBs of the mission session, the one or more CBs includes the CB (group) , and the SDAP entity corresponds to the CB (group) and is not shared by the other CBs of the one or more CBs. Different SDAP entities should be established for different CBs (groups) of the mission session.

[0516] For an SDAP entity per network function, the SDAP entity is established in a network function. The network function corresponds to one or more mission sessions, and the SDAP entity is shared by the one or more mission sessions. The SDAP entity is established for all the different mission sessions corresponding to the network function.

[0517] In some cases, the SDAP entity can be established per mission session group in a network function, the SDAP entity is dedicated for a mission session group. The network function corresponds to one or more mission sessions, and the SDAP entity is shared by the mission session group and is not shared by the other mission sessions of the one or more mission sessions. If the mission session group comprises all the one or more mission sessions, the SDAP entity can be also considered as being established per network function.

[0518] FIG. 17 illustrates traffic between XaaS functions according to one or more embodiments of the present disclosure. As in FIG. 17, there may be multiple XaaS service functions deployed on data plane, e.g., XaaS PSF network function. And the PSF network function can be deployed in RAN and / or CN (e.g., CN-PSF) . For the multiple PSF network functions (e.g., CN-PSFs) , they can be connected to each other via direct interface, as illustrated by dashed line in Figure 12, or they are connected via intermediate data plane function, e.g., a Data-TW-GW or a UPF+.

[0519] For example, the interface between XaaS PSFs (e.g., CN-PSF#1, CN-PSF#2, and CN-PSF#3) can be IP-based interface. The traffic between the XaaS PSFs (e.g., CN-PSFs) can be exchanged as in the dashed line via the IP-based interface. Segment Routing over IPv6 (SRv6) or other segment routing (SR) schemes for the traffic path among XaaS PSFs can be applied. For example, for the IP-based interface, there is not GTP-U or UDP layers deployed above IP layer. If the traffic is  delivered among multiple XaaS PSFs (e.g., CN-PSFs) , only the XaaS PSFs in the first-hop (e.g., for the traffic going into RAN) or in the last-hop (e.g., for the traffic going out from RAN) needs to connect to an intermediate data plane function, e.g., a Data-TW-GW or a UPF+. Traffic between other XaaS PSFs does not pass through the intermediate data plane function (e.g., Data-TW-GW or UPF+) . Then the traffic can be forwarded by the Data-TW-GW or the UPF+ to / from the RAN. The interface between the intermediate data plane function (e.g., Data-TW-GW or UPF+) and the XaaS PSF can be IP-based interface. In some cases, there is not transport layer (e.g., GTP-U or UDP layer) deployed above IP layer. In some cases, for the IP-based interface, the traffic between the intermediate data plane function (e.g., Data-TWGW or UPF+) and the (first-hop or last-hop) XaaS PSF is in the granularity of XaaS service data flow.

[0520] For example, the interface between XaaS PSFs (e.g., CN-PSF#1, CN-PSF#2, and CN-PSF#3) can be connected via an intermediate data plane function (e.g., Data-TWGW or UPF+) . The traffic between the CN-PSFs can be exchanged as in the solid line. For the interface between XaaS PSF and the intermediate data plane function, transport layer (e.g., GTP-U layer, UDP layer or QUIC layer) can be deployed as the upper layer of IP layer. Segment Routing over IPv6 (SRv6) or other segment routing (SR) schemes can be applied for the IP layer. Traffics between XaaS PSFs can be configure to steer to GW / UPF+. Each XaaS PSF needs to connect to the intermediate data plane function. If the traffic is delivered among multiple XaaS PSFs (e.g., CN-PSFs) , the traffic between XaaS PSFs needs to pass through the intermediate data plane function. The traffic among the XaaS PSFs can be forwarded by the Data-TW-GW or the UPF+. In some cases, the traffic between the intermediate data plane function (e.g., Data-TW-GW or UPF+) and XaaS PSF is in the granularity of quality of service (QoS) flow. In some cases, the network (e.g., network control function) can program data plane tunnels (e.g., GTP-U tunnel, QUIC connection) for the traffic path among XaaS PSFs.

[0521] In comparison, if the XaaS PSFs connect with each other via direct interface (e.g., IP-based interface) without going through the intermediate data plane function (e.g., Data-TW-GW, or UPF+) , XaaS PSFs directly see and connect to each other without the intermediate log or supervision of the intermediate data plane function, it may lead to trustworthiness problem (e.g., security problem or privacy problem) . QoS management on the segment between the intermediate data plane function and XaaS PSF is not feasible. The interactions of XaaS PSFs may be left to external implementation out of 3GPP network. It leaves fewer spaces for 3GPP network to control and program the XaaS services.

[0522] There are challenges on the security and privacy issues of RAN node, e.g., on data plane security and privacy. Security and privacy should be guaranteed from architecture and protocol to prevent RAN to parse the data going through it, e.g., when the RAN is not involved in data processing and the data should be parsed by the RAN, especially when XaaS service layer (e.g., PSF layer) does not perform encryption. Some information in upper-layer (e.g., PSF layer) packet header or payload is private. Security and privacy should be natively supported by network, and should not depend on the XaaS service layer’s ability of performing encryption. Security and privacy protections between UE and XaaS service function (e.g., CN-PSFs) needs the UE to perform multiple / duplicated encryption operations, it is necessary to reduce encryption operations of the UE.

[0523] User plane security (UP-Sec) protection has been discussed in 5G (e.g., 3GPP document S3-170296) , the UP-Sec layer is proposed to be deployed to protect the UP security between UE and UPF. For the first option, the UP security is implemented right above the PDCP layer. The UP security requires a new security header that includes. If ciphering is turned on, the SDU received from the upper-layer (excluding the UP security header) is encrypted based on the ciphering algorithm. If integrity protection is turned on, the SDU received from the upper-layer and the UP security header are integrity protected based on the integrity protection algorithm. In this option, the UP security can be implemented regardless of the upper layer protocol, i.e., IP or non-IP. For the second option, the UP security is implemented above the TCP (UDP)  / IP layer. The UP security header is placed right above the transport header (e.g., TCP / UDP) . If ciphering is turned on, the application payload is identified (excluding the transport and IP header) and encrypted based on the ciphering algorithm. If integrity protection is turned on, the application payload is identified (excluding the transport and IP header) and the UP security header are integrity protected based on the integrity protection algorithm. In case of UL transfer, the UPF processes the UP security (e.g., decrypts the packet or verifies the integrity of the packet) based on the UP security header and removes the UP security header before further forwarding the packet to the next hop. In case of DL transfer, the 5G-UE processes the UP security (e.g., decrypts the  packet or verifies integrity of the packet) based on the UP security header and removes the UP security header before further forwarding the packet to the upper-layer.

[0524] In the prior art, in 5G, user plane security protection (UP-Sec) has been discussed. However, in 5G, RAN is a pipe for connectivity service, there is no other upper-layers above radio layer (e.g., SDAP / GTP-U layer) of RAN. In future network (e.g., 5.5G, and 6G) , as explained above, XaaS service layer (e.g., PSF layer) is proposed to support XaaS service (e.g., mission service) on data plane. RAN is not only a pipe, upper-layer (e.g., PSF layer) will be established above SDAP / GTP-U layer, if the RAN should be involved in XaaS service (e.g., Sensing service) for in-network processing. Moreover, in prior art, UP security is discussed to be configured in a bearer basis, e.g., per-bearer security configuration. In future network (e.g., 5.5G, and 6G) , for the XaaS service, the configuration can be per mission session (group) , per data session (group) , per CB (group) , etc.

[0525] Overall, in prior art, how to perform data plane security (DP-Sec) protection is not discussed, e.g., how to perform the security protection between UE and Data-TW-GW / UPF+.

[0526] In view of the above, embodiments of the present disclosure provide a communication solution which aims to perform DP-security protection between UE and Data-TW-GW (UPF+) in future network where there is new upper-layer of RAN for in-network processing. Solutions according to some embodiments of the present disclosure introduce a new layer (DP-Sec layer) to perform the security protections between device and serving Data-TW-GW. Solutions according to some embodiments of the present disclosure provides dynamic switch of DP-Sec protection to enable the flexible involvement of RAN for in-network data processing. Solutions according to some embodiments of the present disclosure further provide new actions of PSF layer, SDAP layer, and GTP-U layer. Moreover, solutions according to some embodiments of the present disclosure introduce new fields in GTP-U header and SDAP header, and the formats of new DP-Sec data PDU and DP-Sec control PDU. Solutions according to some embodiments of the present disclosure further provide the call flow between device, RAN and C / M-TW-GW for DP-Sec protection configuration and the corresponding configuration information.

[0527] Non-access stratum (NAS) layer security protection on control plane has been deployed in 5G. NAS security protection between UE and CN control plane function (e.g., AMF) is supported.

[0528] An evolutionary solution of a 6G system architecture design and procedure design are described in the present application. The evolutionary solution is designed by enhancement of 5G system.

[0529] The proposed 6G network architecture has been designed with a few important principles and requirements: openness, trustworthiness, simplicity in standardization, scalability, rapid deployment of 6G networks and future-proofing.

[0530] The proposed 6G network architecture design applies modularization strategy, utilizes service-based (XaaS) concepts and network virtualization techniques.

[0531] For all of the procedure designs, we are trying modularization of procedures. A procedure of the 6G System may include some procedures that can be reused by other procedures. Such a reusable procedure is defined as a basic procedure.

[0532] A complex procedure can, thus, include multiple sequential or parallel basic procedures. It is expected that such methodology can simplify designs of procedures.

[0533] The 6G System leverages service-based architecture and XaaS concept. XaaS services in the 6G System are categorized into three layers. The 6G System conceptual structure is shown in FIG. 13.

[0534] Infrastructure Layer includes infrastructures supporting 6G services. Among them are wireless networks (Radio Access Network (RAN) , Core Network (CN) ) infrastructures, Cloud / data center infrastructures, satellite networks, storage / database infrastructures, and sensing networks, and etc. These infrastructures can be provided by a single provider or by multiple providers.

[0535] FIG. 18 is a schematic illustration of a 6G System conceptual structure according to one or more embodiments of the present disclosure. In FIG. 18, each XaaS service is provided by identified 5G logical functions. In the evolutionary solution, a XaaS service can be provided with 5G enhancement by more than one approaches. The figure above is only an example.

[0536] In the 6G System conceptual structure:

[0537] -Network for AI (NET4AI) is a new type of service in 6G CN / RAN which enables network with the capability to conduct / execute AI training / inferencing task (s) . i.e., AI task (s) , by network-based computing and communication resources. In this application, the evolutionary solution to support NET4AI service by enhancing the network data analytics function (NWDAF) in 5G system are described.

[0538] -A NET4Data service provides a decentralized architecture for data stakeholders to collaboratively manage data lifecycle events. These data lifecycle events include data storage and data sharing. The data could be public, private, sensitive, confidential. In the present application, the NET4Data service could be integrated into the 5GS, or could be enhanced by the 5GS.

[0539] -Data analysis and management (DAM) focus on different types of data: network data (e.g., data collected from network functions, XaaS service) , ISAC data (3GPP-based sensing data (e.g., from UE and RAN) , Non-3GPP-based sensing data (e.g., from Radar, LiDAR, WiFi Sensing) ) , sensor data (e.g., data from camera sensor, video sensor) , and other data (e.g., Digital user data, 3rd party data, synthetization data, and AI data) . DAM provides services for a variety of data consumers, e.g., XaaS service, 3rd party, NF, UE, etc. 5G system logical functions for example: NWDAF, DCCF, and MFAF of control plane can be enhanced to support DAM service in an evolutionary solution.

[0540] -Network for Digital World (NET4DW) as a service provides the capability of intelligent integration / synthesis of information from the physical world and digital world (DW) . Customers of NET4DW can be individuals, industries, governments. The customers can have the capability of creation, control, and management of a variety of applications running in the DW such as virtual reality applications. DW services can be supported by enhancing 5G functions and adding new functions (e.g., an evolutionary solution) where necessary.

[0541] -Network for connectivity (NET4CON) as a service provides a capability to support exchange of messages and data among new 6G services. The basic capabilities of NET4CON include to manage logical topology among XaaS services and between 6G XaaS services and all types of 6G system customers, to introduce intelligent GWs for controlling dynamic forwarding based on configured procedure principle and to support anonymous interactions among these XaaS services and customers by the introduced intelligent GWs. The NET4CON service is provided by enhancement of 5G system.

[0542] -Mission Management (MM) as a Service provides a capability to program provisioning of XaaS services at Service Layer to provide mission services. A mission is to achieve a designated goal, known as mission goal, which includes providing PDU connectivity and optionally providing data processing. The MM services include the following: mission information management service, mission session management service, mission execution and access management service.

[0543] -Resource Management (RM) as a Service provides a capability of life-cycle management of a variety of slices and over-the-air resource assignment to wireless devices.

[0544] -Service Provisioning Management (SPM) as a Service provides a capability of control and management of 6G service access by customers and provisioning of requested services. The capability is provided by ID management, unified authentication, anonymous service authorization and key management.

[0545] -Connectivity Management (CM) as a service provides a capability of reachability management of 6G wireless devices and D-users in NET4DW in order to support connectivity establishment between wireless devices / D-Users and XaaS services of 6G System. Note that physical locations of D-Users can be changed. A CM service can be deployed across multiple BAS domains.

[0546] -Protocol as a Service provides a capability to design service customized protocol stacks for identified interfaces.

[0547] FIG. 19 illustrates a block diagram of 6G System conceptual structure according to one or more embodiments of the present disclosure. FIG. 19 is used to show one example of deployment of the 6G system in evolutionary solution.

[0548] The “+” represents “enhanced” , for example, the 5G AMF-Mobility function is enhanced, denoted as AMF-Mobility+, the 5G RRC function is enhanced, denoted as RRC+, the 5G Network Repository Function (NRF) is enhanced, denoted as NRF+, the 5G Session Management Function (SMF) is enhanced, denoted as SMF+, the 5G Network Exposure Function (NEF) is enhanced, denoted as NEF+, the 5G Authentication Server Function (AUSF) is enhanced, denoted as AUSF+, other enhanced functions are not described in detail herein.

[0549] C / M Radio Bearer (C / M RB) of a 6G device: over-the-air connection for carrying control signaling for over-the-air interface management and C / M plane messages. A 6G device can have multiple C / M RBs.

[0550] Data Radio Bearer (Data RB) of a 6G device: over-the-air connection for carrying Data plane traffic. A 6G device can have multiple Data RBs.

[0551] RB endpoint: endpoint of an RB at network side. An endpoint of an RB protocol stack (e.g., PDCP) can be in, e.g., a RAN BAS domain, but not limited to. In other words, an RB endpoint can be flexibly deployed / selected for a device.

[0552] RB handler: over-the-air interface protocol stack handler. An RB handler is defined as a logical function which perform RB protocol stack operations after getting configurations. A protocol handler is PDCP-only handler or whole protocol stack handler. An RB handler accepts RB configuration from Connectivity Management (CM) service. An RB handler also accepts security configuration, e.g., keying material, from Service Provisioning Management (SPM) service.

[0553] The NET4CON service which is main service impacting on 6G system architecture is implemented by enhanced 5G Service Communication Proxy (SCP+) as C / M plane GW and enhanced 5G User Plane Function (UPF+) as data plane GW. Proposed per device / D-User C / M session and data session are defined as logical connection between a device / D-User and its serving SCP+ (C / M-TW-GW) and serving UPF+ (Data-TW-GW) . All XaaS services are deployed across multiple BAS / clouds.

[0554] The 6G customer can be of various types, including a device (e.g., electronic device ED, terminal device) , apparatus, a chip, an equipment (e.g., user equipment) etc. For example, the customer may be an individual customer, a business customer, etc. The 6G customer is used to connect persons, objects, machines, etc. The 6G customer may be widely used in various scenarios including, for example, cellular communications, device-to-device (D2D) , vehicle to everything (V2X) , peer-to-peer (P2P) , machine-to-machine (M2M) , MTC, internet of things (IoT) , virtual reality (VR) , augmented reality (AR) , mixed reality (MR) , metaverse, digital twin, industrial control, self-driving, remote medical, smart grid, smart furniture, smart office, smart wearable, smart transportation, smart city, drones, robots, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery and mobility, etc.

[0555] Each 6G customer represents any suitable end user device for wireless operation and may include such devices (or may be referred to but not limited to) as a user equipment (UE) or a user device or a terminal device, a wireless transmit / receive unit (WTRU) , a mobile station, a fixed or mobile subscriber unit, a cellular telephone, a station (STA) , a MTC device, a personal digital assistant (PDA) , a smartphone, a laptop, a computer, a tablet, a wireless sensor, a consumer electronics device, a smart book, a vehicle, a car, a truck, a bus, a train, or an IoT device, wearable devices (such as a watch, a pair of glasses, head mounted equipment, etc. ) , an industrial device, or an apparatus in (e.g. module, modem, or chip) or comprising the forgoing devices, among other possibilities. Future generation 6G customer may be referred to using other terms. When a 6G customer performs (or is configured to perform) a method described herein, it may be interpreted as the ED, one or more module (or units) in the ED, a circuit or chip, or a combination thereof, may perform the method. For example, the circuit or chip may include a modem chip, also referred to as a baseband chip, a system on chip (SoC) including a modem core, or system in package (SIP) ) , and the like, and may be responsible for one or more communication functions in the ED.

[0556] A person skilled in the art should understand that embodiments of this application may be provided as a method, an apparatus (or system) , computer-readable storage medium, or a computer program product. Therefore, this application may use a form of a hardware-only embodiment, a software-only embodiment, or an embodiment with a combination of software and hardware. Moreover, this application may use a form of a computer program product that is implemented on one or more computer-usable storage media (including but not limited to a disk memory, an optical memory, and the like) that include computer-usable program code.

[0557] FIG. 20 illustrates a data plane security (DP-Sec) layer according to one or more embodiments of the present disclosure. As in FIG. 20, data plane security (DP-Sec) layer is deployed to support data plane security protection between UE and Data-TW-GW (or UPF+) . On data plane, the DP-Sec layer is the upper layer of Transport Network Layer (TNL) or radio layer (e.g., SDAP layer) . For example, for the protocol stack on the network side (e.g., the protocol stack on Data-TW-GW or UPF+) , the DP-Sec is the upper layer of TNL (e.g., GTP-U, UDP, IP, L2 and L1 in sequence) . In some cases, the GTP-U  protocol can be replaced by QUIC. In some cases, the IP layer can based on IPv4, IPv6, or SRv6. For the protocol stack on UE, the DP-Sec layer is the upper layer of radio layer (e.g., SDAP, PDCP, RLC, MAC and PHY in sequence) .

[0558] As in FIG. 20, on UE side, the PSF layer is the upper layer of SDAP layer. The PSF layer is the upper layer of SDAP layer on RAN side for radio interface. In core network, there is PSF network function (CN-PSF) , and the CN-PSF network function is implemented via deploying PSF layer as the upper layer of TNL. For the protocol stack on the RAN side for the interface oriented to CN-PSF, the PSF layer is the upper layer of TNL. As in FIG. 20, there is intermediate data plane functions between RAN and CN-PSF, e.g., a Data-TW-GW or a UPF+ for data forwarding.

[0559] In some cases, the PSF layers on RAN are not established.

[0560] In some cases, on UE side, there are other layers between XaaS service layer (e.g., PSF layer) and DP-Sec layer, e.g., TCP layer, QUIC layer, UDP layer, IP layer, which are not illustrated in FIG. 20. For example, there are TCP and IP layers in sequence between PSF layer and DP-Sec layer. For example, there are UDP and IP layers in sequence between PSF layer and DP-Sec layer. For example, there are QUIC, UDP and IP layers in sequence between PSF layer and DP-Sec layer.

[0561] In some cases, on UE side, there are other layers between DP-Sec layer and radio layer (e.g., SDAP layer) , e.g., TCP layer, QUIC layer, UDP layer, IP layer, which are not illustrated in FIG. 20. For example, there are TCP and IP layers in sequence between DP-Sec layer and radio layer. For example, there are UDP and IP layers in sequence between DP-Sec layer and radio layer. For example, there are QUIC, UDP and IP layers in sequence between DP-Sec layer and radio layer.

[0562] In some cases, on Data-TW-GW / UPF+ side, there are other layers above DP-Sec layer, e.g., TCP layer, QUIC layer, UDP layer, IP layer, which are not illustrated in FIG. 20. For example, there are TCP and IP layers above DP-Sec layer. For example, there are UDP and IP layers above DP-Sec layer. For example, there are QUIC, UDP and IP layers above DP-Sec layer.

[0563] In some cases, on Data-TW-GW / UPF+ side, there are other layers between DP-Sec layer and TNL (e.g., GTP-U layer) , e.g., TCP layer, QUIC layer, UDP layer, IP layer, which are not illustrated in FIG. 20. For example, there are TCP and IP layers in sequence between DP-Sec layer and TNL. For example, there are UDP and IP layers in sequence between DP-Sec layer and TNL. For example, there are QUIC, UDP and IP layers in sequence between DP-Sec layer and TNL.

[0564] In some cases, there is PDU layer between XaaS layer and DP-Sec layer. In some cases, there is PDU layer between DP-Sec layer and radio layer (e.g., SDAP layer) or TNL.

[0565] In some cases, some of layers TNL are not deployed, e.g., GTP-U layer, UDP layer.

[0566] In some cases, some of layers of radio layer are not deployed, e.g., SDAP layer.

[0567] In some cases, the connection from the UE to the Data-TW-GW / UPF+ on data plane is termed as data session. The DP-Sec layer is used to perform security protection on data session.

[0568] In the following, we take the DP-Sec layer between XaaS service layer (e.g., PSF layer) and radio layer on UE side as an example to describe, and the other possible layers between XaaS service layer (e.g., PSF layer) and radio layer are not illustrated.

[0569] In the following, we take the DP-Sec layer above TNL on Data-TW-GW / UPF+ side as an example to describe, and the other possible layers between DP-Sec layer and TNL are not illustrated.

[0570] FIG. 21 illustrates a traffic flow when RAN-PSF layer is involved or not according to one or more embodiments of the present disclosure. As illustrated by the dashed line in FIG. 21, RAN solely acts as a pipe to relay traffic and the traffic does not go through RAN-PSF layer. In this case, the data plane security protection can be performed on UE and Data-TW-GW / UPF+ side. As illustrated by the solid line in FIG. 21, traffic goes through RAN-PSF layer for in-network processing. In this case, the data plane security protection is not performed on UE and GW / UPF+ side, otherwise, the RAN-PSF layer cannot parse the payload (e.g., PSF layer PDU sent by UE to RAN) .

[0571] As in FIG. 21, the dashed line traffic and the solid line traffic share a PSF entity of the PSF layer and lower layer entities (e.g., SDAP entity) . For example, the PSF entity may be configured per mission session (group) , per data session (group) or per CB (group) . The DP-Sec entities of DP-Sec layer are established respectively in UE and Data-TW-GW / UPF+. The dashed line traffic goes through the DP-Sec entities, but solid line traffic does not. For example, in different data processing  step, UE decides whether RAN should be involved in a mission (e.g., for in-network data processing) based on channel state information (CSI) and processing load. If the RAN should be involved, the traffic goes through as the solid line (i.e., goes through RAN-PSF layer, but does not go through UE DP-Sec layer or Data-TW-GW / UPF+ DP-Sec layer) , otherwise, the traffic goes through as the dashed line (i.e., does not go through RAN-PSF layer, but can go through UE DP-Sec layer or Data-TW-GW / UPF+ DP-Sec layer) . For example, one UE participates in multiple data sessions or CBs of a mission session, and processing results of some data sessions or CBs need further processing by RAN-PSF layer, but processing results of some data sessions or CBs does not need. The traffic of former processing results goes through as the solid line (i.e., goes through RAN-PSF layer, but does not go through UE DP-Sec layer or Data-TW-GW / UPF+ DP-Sec layer) , and the traffic of latter processing results goes through as the dashed line (i.e., does not go through RAN-PSF layer, but can go through UE DP-Sec layer or Data-TW-GW / UPF+ DP-Sec layer) .

[0572] As explained above, in some cases, traffic of a mission session is not always protected by DP-Sec, not always unprotected by DP-Sec, either. Traffic of a mission session can go through the DP-Sec layer or not dynamically. Dynamic switch is needed.

[0573] In some cases, if separated entities (e.g., PSF entity, DP-Sec entity, SDAP entity) for different traffics (e.g., solid line traffic, dashed line traffic) are established, i.e., an entity is not shared by multiple traffics, the dynamic switch is not need. In this case, fixed binding relationship between entities of different layers can be configured.

[0574] FIG. 22 illustrates a dynamic switch for DP-Sec protection according to one or more embodiments of the present disclosure. As in FIG. 22, UE-PSF layer on UE side should perform traffic dynamic switch to enable RAN-PSF layer to be involved in processing (solid line) or not (dashed line) . The PSF entity of the UE-PSF layer dynamically decides whether to deliver packet through DP-Sec layer, e.g., based on whether the packet should be DP-Sec protected (e.g., corresponding to whether RAN-PSF layer is involved or not) . Whether packet should be DP-Sec protected can be decided based on which data session or CB the packet belongs to. For example, if a data session or CB is configured to be DP-Sec protected or not, then the corresponding packets should be DP-Sec protected or not.

[0575] If DP-Sec protection is needed, the UE-PSF entity sends packets to a DP-Sec entity, then the DP-Sec entity performs security protection (e.g., ciphering, integrity protection) before forwarding the packet to a lower layer entity (e.g., SDAP entity) . It does not rule out other possibilities that there are other layer entities between the UE-PSF entity, the DP-Sec entity, and the SDAP entity.

[0576] If DP-Sec protection is not needed, the UE-PSF entity sends packets to an SDAP entity directly without going through a DP-Sec entity. It can be also considered as that the UE-PSF entity sends packets to an SDAP entity with going through a DP-Sec entity which is in transparent mode (TM) .

[0577] As in FIG. 22, RAN radio layer (e.g., RAN-SDAP layer) should perform traffic dynamic switch to enable RAN-PSF layer to be involved in processing (solid line) or not (dashed line) . The RAN-SDAP entity dynamically decides to submit a packet (e.g., uplink packet) to a upper-layer PSF entity or to relay the packet to a GTP-U entity, e.g., based on whether the packet is DP-Sec protected (e.g., corresponding to whether RAN-PSF layer is involved or not) . Whether the packet is DP-Sec protected can be decided based on which data session or CB the packet belongs to. For example, if a data session or CB is configured to be DP-Sec protected or not, then the corresponding packets is DP-Sec protected or not.

[0578] If DP-Sec protection is performed on the packet, the RAN radio layer entity (e.g., RAN SDAP entity) relays the packet to a GTP-U entity, then the GTP-U entity forwards the packet to next-hop (e.g., to a Data-TW-GW / UPF+) . It can be also considered as that the RAN-SDAP entity relays the packet to the GTP-U entity with going through RAN PSF layer which is in transparent mode (TM) .

[0579] If DP-Sec protection is not performed, the RAN radio layer entity (e.g., RAN SDAP entity) submits the packet to a RAN-PSF entity, then the RAN-PSF entity performs processing on the packet and sends the processing result to next-hop (e.g., to a RAN-PSF entity oriented to CN-PSF) . It does not rule out other possibilities that there are other layer entities between the RAN-PSF entity and the RAN-SDAP entity.

[0580] As in FIG. 22, TNL (e.g., GTP-U layer, QUIC layer) of Data-TW-GW / UPF+ should perform traffic dynamic switch when DP-Sec protection is performed (dashed line) or not (solid line) . The TNL entity (e.g., GTP-U entity oriented to RAN) dynamically decides to submit a packet (e.g., uplink packet) to an upper-layer DP-Sec entity or to relay the packet to another TNL entity (e.g., GTP-U entity) , e.g., based on whether the packet is DP-Sec protected (e.g., corresponding to whether RAN-PSF layer is involved or not) . Whether the packet is DP-Sec protected can be decided based on which data session or CB the packet belongs to. For example, if a data session or CB is configured to be DP-Sec protected or not, then the corresponding packets is DP-Sec protected or not.

[0581] If DP-Sec protection is not performed on the packet, a first TNL entity (e.g., GTP-U entity oriented to RAN) relays the packet to a second TNL entity (e.g., a GTP-U entity oriented to CN-PSF) , then the second TNL entity forwards the packet to next-hop (e.g., to a CN-PSF) . It can be also considered as that the first TNL entity relays the packet to the second TNL entity with going through DP-Sec layer which is in transparent mode (TM) .

[0582] If DP-Sec protection is performed, the TNL entity (e.g., GTP-U entity) submits the packet to an upper-layer DP-Sec entity, then the DP-Sec entity performs security protection (e.g., deciphering, integrity verification) before forwarding the packet to a lower layer entity (e.g., GTP-U entity) . It does not rule out other possibilities that there are other layer entities between the DP-Sec entity and the TNL entity (e.g., GTP-U entity) .

[0583] Similarly, for downlink transmission, new actions should be performed by TNL layer (e.g., GTP-U layer) , radio layer (e.g., SDAP layer) to perform traffic dynamic switch.

[0584] TNL (e.g., GTP-U layer, QUIC layer) of Data-TW-GW / UPF+ should perform traffic dynamic switch (e.g., for downlink) when DP-Sec protection is performed or not. The TNL entity (e.g., GTP-U entity oriented to CN-PSF) dynamically decides to submit a packet (e.g., uplink packet) to an upper-layer DP-Sec entity or to relay the packet to another TNL entity (e.g., GTP-U entity) , e.g., based on whether the packet should be DP-Sec protected (e.g., corresponding to whether RAN-PSF layer is involved or not) . Whether the packet should be DP-Sec protected can be decided based on which data session or CB the packet belongs to. For example, if a data session or CB is configured to be DP-Sec protected or not, then the corresponding packets should be DP-Sec protected or not.

[0585] If DP-Sec protection should not be performed on the packet, a first TNL entity (e.g., a GTP-U entity oriented to CN-PSF) relays the packet to a second TNL entity (e.g., a GTP-U entity oriented to RAN) , then the second TNL entity forwards the packet to next-hop (e.g., to a RAN) . It can be also considered as that the first TNL entity relays the packet to the second TNL entity with going through DP-Sec layer which is in transparent mode (TM) .

[0586] If DP-Sec protection should be performed, the TNL entity (e.g., a GTP-U entity oriented to CN-PSF) submits the packet to an upper-layer DP-Sec entity, then the DP-Sec entity performs security protection (e.g., ciphering, integrity protection) before forwarding the packet to a lower layer entity (e.g., a GTP-U entity) . It does not rule out other possibilities that there are other layer entities between the DP-Sec entity and the TNL entity (e.g., GTP-U entity) .

[0587] RAN TNL (e.g., GTP-U layer oriented to Data-TW-GW / UPF+) should perform traffic dynamic switch to enable RAN-PSF layer to be involved in processing or not. The RAN TNL entity dynamically decides to submit a packet (e.g., downlink packet) to an upper-layer PSF entity or to relay the packet to a radio layer entity (e.g., SDAP entity) , e.g., based on whether the packet is DP-Sec protected (e.g., corresponding to whether RAN-PSF layer is involved or not) . Whether the packet is DP-Sec protected can be decided based on which data session or CB the packet belongs to. For example, if a data session or CB is configured to be DP-Sec protected, then the corresponding packets is DP-Sec protected.

[0588] If DP-Sec protection is performed on the packet, the RAN TNL entity (e.g., RAN GTP-U entity oriented to Data-TW-GW / UPF+) relays the packet to an SDAP entity, then the SDAP entity forwards the packet to next-hop (e.g., to a UE over the air) . It can be also considered as that the RAN TNL entity relays the packet to the SDAP entity with going through RAN PSF layer which is in transparent mode (TM) .

[0589] If DP-Sec protection is not performed, the TNL entity (e.g., GTP-U entity) submits the packet to a RAN-PSF entity, then the RAN-PSF entity performs processing on the packet and sends the processing result to next-hop (e.g., to a RAN-PSF  entity oriented to UE) . It does not rule out other possibilities that there are other layer entities between the RAN TNL entity and the RAN-PSF entity.

[0590] UE radio layer (e.g., UE-SDAP layer) should perform traffic dynamic switch when DP-Sec protection is performed or not. The UE radio layer (e.g., UE-SDAP layer) entity dynamically decides to submit a packet (e.g., uplink packet) to a upper-layer PSF entity or to a upper layer DP-Sec entity, e.g., based on whether the packet is DP-Sec protected (e.g., corresponding to whether RAN-PSF layer is involved or not) . Whether the packet is DP-Sec protected can be decided based on which data session or CB the packet belongs to. For example, if a data session or CB is configured to be DP-Sec protected or not, then the corresponding packets is DP-Sec protected or not.

[0591] If DP-Sec protection is performed on the packet, the UE radio layer entity (e.g., UE SDAP entity) submits the packet to a DP-Sec entity, then the DP-Sec entity performs security protection (e.g., deciphering, integrity verification) before forwarding the packet to a PSF entity. It does not rule out other possibilities that there are other layer entities between the radio layer entity (e.g., SDAP entity) , the DP-Sec entity and the PSF entity.

[0592] If DP-Sec protection is not performed, the UE radio layer entity (e.g., UE SDAP entity) submits the packet to a PSF entity directly without going through a DP-Sec entity. It does not rule out other possibilities that there are other layer entities between the radio layer entity (e.g., SDAP entity) and the PSF entity. It can be also considered as that the radio layer entity (e.g., UE SDAP entity) submits the packet to the PSF entity with going through DP-Sec layer which is in transparent mode (TM) .

[0593] FIG. 23 shows a schematic flowchart of a communication method according to one or more embodiments of the present disclosure. The method can be implemented by a communication apparatus, and the communication apparatus may be a user equipment (e.g., the apparatus 310 as shown in FIG. 3A) or a network function (e.g. the apparatus 320 as shown in FIG. 3A, the component in the apparatus 320 as shown in FIG. 3A, the apparatus 330 as shown in FIG. 3B or the component in the apparatus 330 as shown in FIG. 3B) . The detailed procedures are as the following steps. As shown in FIG. 23, the method can include the following steps.

[0594] S2310, the communication apparatus receives a message, where the message is used to configure a first protocol layer in a communication apparatus, the first protocol layer is to support data plane security protection on a first packet, and the protection is between a UE and a network function.

[0595] S2320, the communication apparatus configures the first protocol layer based on the message.

[0596] In the embodiment, the communication apparatus, which could be either a UE or a network function, receives a configuration message. The network function may be in a core network. For example, the network function can be a data trustworthy gateway (Data-TW-GW) , or a user plane function (UPF) .

[0597] The message is used to set up the first protocol layer to support data plane security protection for some packets. The first protocol layer may be, e.g., the DP-Sec layer described above, or some other layers with the same or similar function. The protection is designed to secure the data transmission between the UE and a network function, ensuring the confidentiality and integrity of the data as it travels across the network.

[0598] The message may include essential configuration information that the communication apparatus needs to establish the first protocol layer effectively. For example, the message may include information for the communication apparatus to determine whether the protection (e.g., DP-Sec protection) should be performed on the first packet. The message information might include security parameters, encryption algorithms, keying material, and other relevant settings that define the security requirements for the first packet. After receiving the message, the communication apparatus proceeds to configure the first protocol layer based on the message.

[0599] The communication apparatus can adapt to different security requirements by configuring the first protocol layer based on the received configuration message, allowing for flexible and dynamic security measures. Secure and reliable data transmission between the UE and network functions can be enabled by establishing a robust security framework on the data plane. In addition, the establishment of the first protocol layer, which is to support data plane security protection on a first  packet, can apply security measures, such as encryption, privacy protection and integrity protection, to the data packets that will be transmitted, ensuring the confidentiality and integrity of the data.

[0600] In a possible implementation, one or more first entities, e.g., DP-Sec entities, are established on the first protocol layer to perform the protection. The first protocol layer, which is configured for data plane security protection (DP-Sec) , may establish one or more first entities. These first entities could be software modules, logical components, or service instances that are designed to operate within the protocol layer. Depending on the network conditions, security requirements, or mission service needs, these first entities can be dynamically configured or reconfigured. This allows the network to adapt to changing security environment and to provide the necessary level of protection for different types of data and services.

[0601] In a possible implementation, the first protocol layer may be a lower layer of a second protocol layer which is used to provide a mission service, where the mission service is a service for both PDU connectivity and data processing and the first protocol layer is to protect at least one of security and privacy of data of the second protocol layer. In a possible implementation, the second protocol layer may be an anything as a XaaS service layer or a PSF layer. The first protocol layer may act as a security layer that ensures the security and privacy of the data handled by the second protocol layer. By structuring the protocol layers in this manner, the security and privacy of in-network processing (also termed as in-network computing) can be guaranteed for the mission service, such as a XaaS service.

[0602] In a possible implementation, the mission service is provided through at least one mission session, and each of the at least one mission session may include a data forwarding resource and a data processing resource for providing the mission service. The mission service may be facilitated through one or more mission sessions.

[0603] In a possible implementation, each of the at least one mission session may include at least one data session, and each of the at least one data session includes an association terminates at a second entity executing one or more computing blocks (CBs) of the mission service, where the second entity is on the second protocol layer, the mission service includes at least one CB, each of the at least one CB corresponds to a computational step toward achieving the mission service, and the at least one CB includes the one or more CBs. The computational step toward achieving the mission service can also be referred to as the computational step toward the mission goal cited above. The computational step toward achieving the mission service may include one or more of: artificial intelligence (AI) training, AI inference, data pre-processing, data privacy protection, data cleaning, data collection, data analytics, sensing, data sanitization, data management, data normalization, data aggregation, data splitting, useless data filtering, data formatting, data adaptation, data feature engineering, data compression, data embedding, data representation learning, or data feature extraction. A CB within the mission service corresponds to a defined computational step toward a mission goal of the mission service. The second protocol layer can be used to execute the mission service by executing the at least one CB of the mission service through the at least one second entity on the second protocol layer. When the second protocol layer is a XaaS layer, the second entity is a XaaS entity. When the second protocol layer is a PSF layer, the second entity is a PSF entity.

[0604] In a possible implementation, the communication apparatus is the UE. The message can be sent to the UE in multiple ways. In a possible implementation, the message may be an access stratum (AS) message, e.g., an RRC message, which may be sent from a RAN to the UE. In a possible implementation, the message may be a non-access stratum control plane (NAS-CP) message, which may be sent from a C / M plane function (e.g., C / M-TW-GW, SCP+, AMF+, or SMF+) to the UE.

[0605] When the communication apparatus is a UE, the first protocol layer may be a lower layer of a second protocol layer providing a mission service. The first protocol layer, which is responsible for DP-Sec protections, may be a lower layer supporting protection on a second protocol layer that provides the mission service. The second protocol layer could be a PSF layer, which handles tasks related to the mission service.

[0606] In a possible implementation, there may be no additional layer between the first protocol layer and the second protocol layer. In a possible implementation, there may be one or more additional layers between the first protocol layer and the second protocol layer, and the one or more additional layers include at least one of: a PDU layer, an IP layer, a UDP layer, a TCP layer, or a QUIC layer. Whether there is one or more additional layers and what the one or more additional layers are may depend on actual application scenarios, such as service or transmission requirements and the protocol stack of the UE.

[0607] In a possible implementation, the first protocol layer may be an upper layer of a radio layer. In a possible implementation, the radio layer may include an SDAP layer. The SDAP layer is responsible for adapting service data units to fit the requirements of the radio bearer. In a possible implementation, there may be no additional layers between the first protocol layer and the radio layer. In a possible implementation, there may be one or more additional layers between the first protocol layer and the radio layer. In a possible implementation, the one or more additional layers between the first protocol layer and the radio layer include at least one of: a PDU layer, an IP layer, a UDP layer, a TCP layer, or a QUIC layer. Whether there is one or more additional layers and what the one or more additional layers are may depend on actual application scenarios, such as service or transmission requirements and the protocol stack of the UE.

[0608] In a possible implementation, the communication apparatus may be the network function. The network function may be a Data Trustworthy Gateway (Data-TW-GW) or an enhanced User Plane Function (UPF+) . In a possible implementation, there may no other layers above the first protocol layer. In a possible implementation, there may be one or more layers above the first protocol layer. The one or more layers above the first protocol layer may include one or more of: a PDU layer, a second protocol layer providing a mission service, an IP layer, a UDP layer, a TCP layer, or a QUIC layer. The network function may be or may not be configured with the second protocol layer which provides the mission service. When the network function is configured with the second protocol layer, it may be involved in the in-network data processing. When the network function is not configured with the second protocol layer, it may be connected with another network function which is configured with the second protocol layer for providing the mission service.

[0609] In a possible implementation, in the network function, the first protocol layer may be an upper layer of a transport network layer (TNL) . By this arrangement, transmission of data packet of the first protocol layer, e.g., the DP-Sec layer, can be supported by the TNL. In a possible implementation, the TNL may include one or more of: a general packet radio service (GPRS) tunnelling protocol for user plane (GTP-U) layer, a UDP layer, a QUIC layer, or an IP layer.

[0610] In a possible implementation, there may be one or more additional layers between the first protocol layer and the TNL layer. The one or more additional layers between the first protocol layer and the TNL layer may include at least one of: a PDU layer, an IP layer, a UDP layer, a TCP layer, or a QUIC layer.

[0611] In a possible implementation, whether the protection should be performed on the first packet may be determined based on at least one of: identification information corresponding to the first packet, or an indication on whether protection is performed or not, where the indication on whether protection is performed or not is included in a packet which includes the first packet, or is not included in a packet which includes the first packet.

[0612] Whether the protection should be performed on the first packet may rely on identification information that is associated with the first packet. In a possible implementation, the identification information corresponding to the first packet may include at least one of: a mission session identifier (ID) identifying a mission session to which the first packet belongs, a mission session group ID identifying a mission session group to which the first packet belongs, a data session ID identifying a data session to which the first packet belongs, a data session group ID identifying a data session group to which the first packet belongs, a computing block identifier (CBID) identifying a CB to which the first packet belongs, a CB group ID identifying a CB group to which the first packet belongs, a radio bearer ID identifying a radio bearer to which the first packet belongs, a radio bearer group ID identifying a radio bearer group to which the first packet belongs, a quality of service (QoS) flow ID identifying a QoS flow to which the first packet belongs, or a QoS flow group ID identifying a QoS flow group to which the first packet belongs. The Mission session ID can identify a mission session to which the first packet belongs. In some cases, the above mentioned IDs can be used as ciphering and integrity material. The mission session group ID can identify a group of mission sessions to which the first packet belongs. The data session ID can identify a specific data session to which the first packet belongs. A data session typically involves the exchange of data between communication devices. The data session group ID can identify a group of data sessions to which the first packet belongs. The CBID can identify a specific computing block, which represents a defined computational step within a mission, to which the first packet belongs. The CB group ID can identify a group of computing blocks, allowing for the application of security protections across a set of related computational steps. The radio bearer ID can identify a specific radio bearer, which is a logical connection between the UE  and the network for the transfer of user data, to which the first packet belongs. The radio bearer group ID can identify a group of radio bearers to which the first packet belongs, enabling the network to apply security measures to multiple logical connections at once. The QoS flow ID can identify a specific QoS flow, which is a logical channel that carries user data with specific quality requirements, to which the first packet belongs. The QoS flow group ID can identify a group of QoS flows to which the first packet belongs. Identifiers of various granularities may be considered in the determination on whether the protection should be performed, thereby providing more flexibility of data plane protection between the UE and the network function, accommodating various application scenarios, and adapting to different security requirements.

[0613] The indication on whether protection is performed or not may be an indication flag or field included within the packet header or payload of a packet of a lower layer of the first protocol layer, e.g., an SDAP packet or a GTP-U packet, and be used to explicitly indicate whether the protection should be applied to the first packet. This indication can be used to determine whether the protection should be performed for a packet received from other devices. For example, the UE may receive a packet, the packet may include an indication field to indicate whether protection is performed or not, in other words, to indicate whether data in the packet is protected. When the indication indicates that protection is performed, then the received packet is protected, then the protection on the first protocol layer should be performed, the protection action at the first protocol layer for example can be deciphering the protected packet.

[0614] In a possible implementation, the communication apparatus may determine whether the protection should be performed based on both the identification information and the indication.

[0615] When determination is made based on both the identification information and the indication, the determination result based on the identification information may be different from the determination result based on the indication. For example, based on the identification information, it may be determined that the protection should not be performed while based on the indication, it may be determined that the protection should be performed. The inconsistency may be caused, e.g., by different configurations on the transmitting side and the receiving side. For example, the configuration of the first protocol layer is reconfigured or updated for a mission service, and the network function has completed the reconfiguration, while the UE has not completed the reconfiguration.

[0616] In such a case, the determination result based on the indication may prevail since it represents the protection state of the packet. For example, it is determined based on the identification information that the protection should not be performed, but it is determined based on the indication in the packet that the protection should be performed. Since the indication in the packet represents the protection state of the packet, that is, data in the packet is protected (e.g., encrypted, etc. ) , the protection (e.g., deciphering) should be applied to get the data from the packet.

[0617] These approaches can allow the communication apparatus to dynamically decide whether to apply data plane security (DP-Sec) protections based on the content of these packets.

[0618] In a possible implementation, there may be no such indication in the packet including the first packet. The determination on whether the protection should be performed may be determined based on the identification information corresponding to the first packet as described above.

[0619] In a possible implementation, the absence of such an indication within a packet that includes the first packet may indicate a default protection state, which may be that the protection is performed, or that the protection is not performed, and whether the protection should be performed can be determined based on the default protection state.

[0620] Various methods for determining whether the protection should be performed are described above. These approaches can allow for flexible and dynamic security management on the data plane.

[0621] By examining either or both of the identification information and an indication within the packet, the network can make decisions about whether to apply security protections such as encryption or integrity checks on a per-packet basis.

[0622] In a possible implementation, the message may include one or more of: a mission session ID identifying a mission session on which the protection should be performed or not, a mission session group ID identifying a mission session group on which the protection should be performed or not, a data session ID identifying a data session on which the protection should be performed or not, a data session group ID identifying a data session group on which the protection should be performed or  not, a CBID identifying a CB on which the protection should be performed or not, a CB group ID identifying a CB group on which the protection should be performed or not, a radio bearer ID identifying a radio bearer on which the protection should be performed or not, a radio bearer group ID identifying a radio bearer group on which the protection should be performed or not, a QoS flow ID identifying a QoS flow on which the protection should be performed or not, or a QoS flow group ID identifying a QoS flow group on which the protection should be performed or not. The message sent to configure the DP-Sec protection may include one or more of the identifiers. These identifiers instruct the communication apparatus (such as UE or network functions) on which sessions, groups, or flows the protection should be applied or skipped. For example, if the message includes a mission session ID identifying a mission session on which the protection should be performed, the communication apparatus can determine whether the protection should be performed on the first packet by determining whether the mission session ID to which the first packet belongs is included in the mission session ID identifying a mission session on which the protection should be performed.

[0623] In a possible implementation, the communication apparatus may determine, based on whether an intermediate network function between the user equipment and the network function should not be involved in data processing, whether the protection should be performed. The communication apparatus may assess whether an intermediate network function, situated between the UE and the final network function, needs to participate in the processing of the data. Intermediate network functions could include elements like RAN node or other apparatus that facilitates data transmission. In a possible implementation, the communication apparatus may determine that the protection should be performed in a case that the intermediate network function between the UE and the network function should not be involved in data processing. In a possible implementation, the communication apparatus may determine that the protection should not be performed in a case that the intermediate network function between the UE and the network function should be involved in data processing. If the intermediate network function is not required to perform in-network data processing, the communication apparatus may decide that DP-Sec protection should be applied. If the intermediate network function needs to be involved in data processing, the communication apparatus may decide not to apply DP-Sec protection. This approach can support dynamic switching between protected and unprotected states based on, for example, actual network conditions, such as, conditions of channels for transmission, and processing load of relevant devices.

[0624] In a possible implementation, whether the protection should be performed is determined for at least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bears, or one or more QoS flows. The decision to apply DP-Sec protection may be made on a granular level, targeting specific entities that are involved in data transmission and processing. The entities for which protection may be determined include: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bears, or one or more QoS flows. Protection decisions may be made at various granularities, such as per mission session, per data session, per CB, per radio bearer, or per QoS flow, thereby providing more flexibility of data plane protection between the UE and the network function. In addition, the network can optimize the use of security resources, applying protections only where they are needed. This approach can balance the need for security with the requirements for performance and efficiency, ensuring that the network can deliver a wide range of services while maintaining a high level of security, thereby accommodating various application scenarios, and adapting to different security requirements.

[0625] In a possible implementation, the communication apparatus may determine whether the intermediate network function between the UE and the network function should be involved in data processing based on at least one of CSI or processing payload. The communication apparatus may make the decision on whether an intermediate network function should participate in the data processing based on at least one of channel state information or processing payload. The channel state information may refer to the status and quality of the communication channel between the UE and the network. The CSI can include data on signal strength, interference levels, channel capacity, and other relevant metrics that affect the transmission of data. For example, if the CSI indicates that the channel quality is good and stable and it allows the UE and the intermediate network to exchange data in a required delay budget for data processing, the UE may offload parts of processing workload to the intermediate network function and parts of processing workload to the network function, and the intermediate network  function may need to process the data. The processing payload may refer to the computational or processing requirements associated with the data being transmitted. If the processing payload of the UE is large or complex, which would require significant processing power or specialized capabilities, the intermediate network function may need to be involved in processing the data. By considering these factors, the communication apparatus can make a decision on whether to involve the intermediate network function in the data processing. This approach allows for a flexible and efficient management of network resources, optimizing both the performance of data processing and the security of data transmissions.

[0626] In a possible implementation, the communication apparatus may send or receive control information which indicates: that the protection should be performed; or that the protection should not be performed. The control information might be an indicator field that is communicated via messages and embedded in packet headers to signal whether DP-Sec protection is required. In a possible implementation, the control information may be carried in a control PDU of the first protocol layer. The control information may be used to manage the operation of the data plane, specifically related to the DP-Sec layer. By carrying the control information in a control PDU, the system can dynamically adjust the security measures applied to the data packets, ensuring flexibility and adaptability to various network conditions and security requirements.

[0627] In a possible implementation, the control information may further indicate: at least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bearers, or one or more QoS flows, where the protection should be performed on the first packet in a case that the first packet belongs to the one or more mission sessions, the one or more data sessions, the one or more CBs, the one or more radio bearers, or the one or more QoS flows; or at least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bearers, or one or more QoS flows, where the protection should not be performed on the first packet in a case that the first packet belongs to the one or more mission sessions, the one or more data sessions, the one or more CBs, the one or more radio bearers, or the one or more QoS flows. The control information might specify one or more mission sessions, data sessions, CBs, radio bearers, or QoS flows, indicating that protection should be applied to the first packet if it belongs to any of these designated categories. Alternatively, the control information could identify one or more mission sessions, data sessions, CBs, radio bearers, or QoS flows for which protection should not be applied to the first packet if it belongs to any of these specified categories. The control information can indicate whether the protection should be performed or not with various granularities, which can allow for a highly tailored approach to data plane security protection, enabling protection to be applied on a per-session or per-flow basis or other granularities as needed, depending on the security requirements of the data or other criteria. It also provides the flexibility to exempt certain types of traffic from protection, which could be important in scenarios where performance or compatibility considerations take precedence over security for specific data packets.

[0628] In a possible implementation, the control information may include one or more of: an indication on whether the protection should be performed or not, or activated or deactivated, a data session ID identifying a data session or a set of data session IDs identifying a set of data sessions, a CBID identifying a CB or a set of CBIDs identifying a set of CBs, a mission session ID identifying a mission session or a set of mission session IDs identifying a set of mission sessions, a QoS flow ID identifying a QoS flow or a set of QoS flow IDs identifying a set of QoS flows, one or more sequence numbers (SNs) . A value of each SN may be used for transmitting packet in order, and / or as material for at least one of ciphering or integrity protection, or a reserved field. The reserved field is a field reserved for future use or additional information that may be required for the control PDU. The control information may be transmitted through the control PDU of the first protocol layer, which is a PDU on the data plane. The control PDU may include fields to indicate whether the protection should be performed or not, or activated or not, based on various granularities.

[0629] In a possible implementation, the first packet would go through the first protocol layer for the protection in a case that the protection should be performed. Alternatively, the first packet would not go through the first protocol layer, or would through the first protocol layer without being performed with the protection in a case that the protection should not be performed. The handling of the first packet related to the first protocol layer would be determined based on the message for configuring the first protocol layer and / or the control information indicating whether protection should be performed or not. If protection should be performed, the first packet would need to go through the first protocol layer (DP-Sec layer) to receive  the necessary security protection. This could involve processes such as encryption for confidentiality, integrity protection, etc. to ensure that the intermediate network function cannot parse the data of the packet, the packet has not been tampered with, or involve other security measures deemed necessary for the protection of the data. If protection should not be performed, the first packet would either not pass through the DP-Sec layer at all, or it would pass through the first protocol layer without receiving any security protection measures.

[0630] In a possible implementation, when the communication apparatus is the UE, the UE has uplink data to be transmitted to the network function, the UE may determine, at a second protocol layer, based on identification information of the first packet, whether the protection should be performed on the first packet, where the second protocol layer is a higher layer of the first protocol layer. The first packet may be a packet that is generated by the second protocol layer, e.g., PSF layer, based on uplink data or an uplink packet and to be delivered from the second protocol layer to a lower layer for transmission to the network side. When the second protocol layer is a PSF layer, the first packet may be a PSF packet. The second protocol layer may determine whether the protection should be performed on the first packet based on identification information of the first packet so that the first packet can be delivered to an appropriate lower layer based on a result of the determination, enabling appropriate handling and processing based on the security requirements and the network’s configuration. In addition, devices not configured with the first protocol layer cannot get access to the protected data of the second protocol layer, e.g., the protected data of the mission service (e.g. XaaS service) and cannot be involved in in-network data processing of such protected data. By determining whether protection should be performed and processing the packets accordingly, devices not configured with the first protocol layer but configured with the second protocol layer can be flexibly involved in in-network data processing based on security requirements and the network’s configuration.

[0631] In a possible implementation, when the communication apparatus is the UE, the UE has uplink data to be transmitted to the network function, the UE may determine, at a second protocol layer, based on identification information of an uplink packet, whether the protection should be performed on the uplink packet, where the second protocol layer is a higher layer of the first protocol layer, and the uplink packet is included in the first packet. The determination on whether the protection should be performed may also be performed before the first packet is generated. For example, uplink data or an uplink packet may be obtained at the second protocol layer, e.g., PSF layer. Then, the second protocol layer may determine whether the protection should be performed, based on identification information of the uplink data or uplink packet, and then the uplink data or uplink packet can be encapsulated in the first packet and delivered to an appropriate layer based on a result of the determination.

[0632] For example, the UE has uplink data to be transmitted to the network function, the data will be carried on an uplink packet, when the packet arrives at the PSF layer, the PSF layer will perform processing on the uplink packet and determine whether the protection should be performed. The UE can make the determination in either of the following cases:

[0633] Case 1: the UE will perform the processing on the uplink packet at the PSF layer to obtain the first packet, the uplink packet is included in the first packet, before the first packet is sent out of the PSF layer, the UE will determine whether the protection should be performed on the first packet at the first protocol layer, if the protection should be performed, then the first packet will be delivered to the first protocol layer, the protection will be performed on the first packet at the first protocol layer. If the protection should not be performed on the first packet, the UE will either send the first packet to a third protocol layer below the PSF layer or send the first packet to the first protocol layer without performing the protection at the first protocol layer.

[0634] Case 2: the UE will determine whether the protection should be performed on the uplink packet, then the UE will perform processing on the uplink packet at the PSF layer to obtain the first packet, the uplink packet is included in the first packet. If the protection should be performed, then the first packet will be delivered to the first protocol layer, the protection will be performed on the first packet at the first protocol layer. If the protection should not be performed on the first packet, the UE will either send the first packet to a third protocol layer below the PSF layer or send the first packet to the first protocol layer without performing the protection at the first protocol layer.

[0635] In a possible implementation, the first packet may be delivered from the second protocol layer to the first protocol layer in a case that the protection should be performed, the UE may perform, at the first protocol layer, the protection on the  first packet to obtain a processed first packet, and may send the processed first packet to a third protocol layer, where the third protocol layer is a lower layer of the first protocol layer. In a case that the second protocol layer determines that the protection should be performed on the first packet, the first packet would be delivered to the first protocol layer (DP-Sec layer) , and the necessary protection would be applied to the first packet to obtain a processed first packet. After the protection has been applied, the processed first packet would be then sent from the first protocol layer to a third protocol layer. The third protocol layer is used for data adaptation and transmission, for example, the third protocol layer may be an SDAP layer. In this case, data of the second protocol layer is protected on the data plane, and devices not configured with the first protocol layer cannot get access to the data of the second protocol layer, e.g., data of the mission service (e.g., XaaS service) and is not involved in in-network data processing of such data, which can guarantee the security and privacy of in-network processing for the mission services e.g., XaaS service. In a possible implementation, the protection on the first packet may include at least one of: ciphering, privacy protection, or integrity protection.

[0636] In a possible implementation, the processed first packet may be included in a data PDU of the first protocol layer, and the data PDU includes one or more of: a mission session ID identifying a mission session the data PDU belongs to, a data session ID identifying the data session the DP-Sec data PDU belongs to, a CBID identifying a CB the data PDU belongs to, a QoS flow ID identifying the data PDU belongs to, an indication on whether the protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated, a length of the data PDU, a sequence number of the data PDU, a payload of the data PDU, or a reserved field. The processed first packet generated at the first protocol layer of the UE can be in a form of the data PDU of the first protocol layer which may include one or more fields listed above. The first packet may be included in the payload of the data PDU, and the PDU may also include IDs of various granularities, the length of the PDU, and / or the sequence number of the PDU, based on which the first protocol layer of the network function can perform suitable processing when receiving the processed first packet. This structured approach can allow for precise control over the security measures applied to each packet, optimizing both security and efficiency during data transmission.

[0637] In a possible implementation, the first packet may be delivered from the second protocol layer to a third protocol layer in a case that the protection should not be performed, where the third protocol layer is a lower layer of the first protocol layer. In a case that the second protocol layer determines that the protection should not be performed on the first packet, the first packet would be delivered from the second protocol layer to a third protocol layer, skipping the first protocol layer. In this case, the first packet is not protected on the data plane, and devices not configured with the first protocol layer can still parse the data of the first packet and be involved in in-network data processing if configured with the second protocol layer for data processing.

[0638] In a possible implementation, the UE may receive, at the third protocol layer, a packet from an upper layer, where the upper layer is the second protocol layer or the first protocol layer, and the received packet is the first packet from the second protocol layer or the processed first packet from the first protocol layer. The UE may then encapsulate, at the third protocol layer, the received packet and an indication on whether the protection is performed or not, to obtain a second packet of the third protocol layer for transmission. The indication on whether the protection is performed or not has a first value indicating the protection is performed in a case that the received packet is the processed first packet from the first protocol layer, or has a second value indicating the protection is not performed in a case that the received packet is the first packet from the second protocol layer. The UE receives a packet at the third protocol layer. The packet could be the original first packet coming from the second protocol layer (which made the decision on whether protection should be performed) , or it could be the processed first packet from the first protocol layer (DP-Sec layer) that has already undergone security protection measures at the first protocol layer. After receiving the first packet or the processed first packet, the communication apparatus may encapsulate the received packet along with an indication that signals whether protection is performed or not. If the received packet is the processed first packet from the first protocol layer, the indication may take on a first value signifying that protection is performed. If the received packet is the original first packet from the second protocol layer and has not undergone protection at the first protocol layer, the indication may take on a second value indicating that protection is not performed. In this way, the indication values can serve as a flag to indicate the protection state, and other device, such as the intermediate  network function, which receives the second packet, can be aware of the protection state by checking the indication, which enables appropriate handling and processing based on the security requirements and the network’s configuration. In a possible implementation, the indication on whether the protection is performed or not is encapsulated in a packet header or a payload of the second packet of the third protocol layer, which may be the packet header or payload of an SDAP packet.

[0639] In a possible implementation, when the communication apparatus is the UE, the UE receives downlink data from the network function, the UE may determine, at a third protocol layer, whether the protection should be performed or not on the first packet, based on at least one of: identification information of the first packet or an indication on whether protection is performed or not, where the third protocol layer is a lower layer of the first protocol layer. The first packet may also be a packet that is obtained by the third protocol layer, e.g., SDAP layer, from a downlink packet and be delivered from the third protocol layer to an upper layer, which may be the first protocol layer, e.g., the DP-Sec layer, or the second protocol layer, e.g., the PSF layer. When the third protocol layer obtains the first packet, it may determine whether the protection should be performed on the first packet. By performing such determination, the first packet can be delivered to an appropriate upper layer based on a result of the determination, thereby enabling appropriate delivering and processing of packets based on the security requirements and the network’s configuration.

[0640] In a possible implementation, when the communication apparatus is the UE, the UE receives downlink data from the network function, the UE may determine, at a third protocol layer, whether the protection should be performed or not on a downlink packet, based on at least one of: identification information of the downlink packet or an indication on whether protection is performed or not, where the third protocol layer is a lower layer of the first protocol layer, and the first packet is included in the downlink packet. For downlink transmission, the determination on whether the protection should be performed may also be performed before the first packet is obtained. For example, a downlink packet, e.g., SDAP layer, may be obtained by the third protocol layer, e.g., SDAP layer, from a lower layer, and then whether the protection should be performed can be determined based on the identification information of the downlink packet or an indication on whether protection is performed included in the downlink packet, and then the first packet is obtained from the downlink packet and delivered based on a result of the determination.

[0641] For example, the UE receives the downlink data from the network function, the data will be carried on a downlink packet, when the packet arrives at the SDAP layer, the SDAP layer will perform processing on the downlink packet and determine whether the protection should be performed. The UE can make the determination in either of the following cases:

[0642] Case 1: the UE will perform the processing on the downlink packet at the SDAP layer to obtain the first packet, the first packet is included in the downlink packet, before the first packet is sent out of the SDAP layer, the UE will determine whether the protection should be performed on the first packet at the first protocol layer, if the protection should be performed, then the first packet will be delivered to the first protocol layer, the protection will be performed on the first packet at the first protocol layer. If the protection should not be performed on the first packet, the UE will either send the first packet to a second protocol layer above the third protocol layer or send the first packet to the first protocol layer without performing the protection at the first protocol layer.

[0643] Case 2: the UE will determine whether the protection should be performed on the downlink packet, then the UE will perform processing on the downlink packet at the SDAP layer to obtain the first packet, the first packet is included in the downlink packet. If the protection should be performed, then the first packet will be delivered to the first protocol layer, the protection will be performed on the first packet at the first protocol layer. If the protection should not be performed on the first packet, the UE will either send the first packet to a second protocol layer above the third protocol layer or send the first packet to the first protocol layer without performing the protection at the first protocol layer.

[0644] In a possible implementation, the first packet is delivered from the third protocol layer to the first protocol layer in a case that the protection should be performed, the UE may perform, at the first protocol layer, the protection on the first packet to obtain a processed first packet and send the processed first packet to a second protocol layer for data processing. When the UE determines that the protection should be performed, the first packet can be delivered from the third protocol layer to the first protocol layer so that protection can be performed by the first protocol layer on the first packet to obtain the processed  first packet, which is then delivered to the second protocol layer for data processing. In this case, the first data is a packet of the first protocol layer, e.g., DP-Sec packet, and data of the second protocol layer, e.g., PSF layer, is protected on the data plane, and devices not configured with the first protocol layer cannot get access to the protected data of the second protocol layer, e.g., protected data of the mission service (e.g. XaaS service) and are not involved in in-network data processing, which can guarantee the security and privacy of in-network processing for mission services, e.g., XaaS services. In a possible implementation, the protection on the first packet may include at least one of: deciphering, privacy protection, or integrity verification.

[0645] In a possible implementation, the first packet delivered from the third protocol layer to the first protocol layer may be included in a data PDU of the first protocol layer, and the data PDU includes one or more of: a mission session ID identifying a mission session the data PDU belongs to, a data session ID identifying the data session the DP-Sec data PDU belongs to, a CBID identifying a CB the data PDU belongs to, a QoS flow ID identifying the data PDU belongs to, an indication on whether protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated, a length of the data PDU, a sequence number of the data PDU, a payload of the data PDU, or a reserved field. By incorporating these components into the data PDU, the communication apparatus can effectively manage the security and processing of the packet. The processed first packet generated by the first protocol layer and delivered to the second protocol layer may be obtained from the payload of the data PDU, and the data PDU may also include IDs of various granularities, the length of the PDU, and / or the sequence number of the PDU, based on which the first protocol layer can perform processing to obtain the processed first packet. This structured approach can allow for precise control over the security measures applied to each packet, optimizing both security and efficiency during data transmission.

[0646] In a possible implementation, the first packet may be delivered from the third protocol layer to a second protocol layer for data processing in a case that the protection should not be performed. The second protocol layer is a higher layer of the first protocol layer. When it is determined that the protection should not be performed, the first packet can be delivered to the second protocol layer, e.g., PSF layer, for data processing, without being processed by the first protocol layer, e.g., DP-Sec layer. In this case, the first packet is a packet of the second protocol layer, e.g., a PSF packet, and the first packet is not protected on the data plane, and devices not configured with the first protocol layer can get access to the data of the first packet and be involved in in-network data processing if configured with the second protocol layer for data processing.

[0647] In a possible implementation, when the communication apparatus is the network function, the network function receives uplink data from the UE, the network function may determine, at a third protocol layer in a first interface oriented to an intermediate function between the UE and the network function, whether the protection should be performed on the first packet, based on at least one of: identification information of the first packet or an indication on whether protection is performed or not, where the third protocol layer is a lower layer of the first protocol layer. For uplink transmission, the first packet may be a packet that is obtained from an uplink packet by the third protocol layer of the network function, and to be delivered from the third protocol layer to another layer. The third protocol layer may operate within the first interface that is oriented towards an intermediate network function, which facilitates communication between the UE and the network function. The network function may determine whether security protection should be applied to the first packet at the third protocol layer, so that the first packet can be delivered to an appropriate layer based on a result of the determination. The first interface may be an interface established for data transmission between the network function and an intermediate network function. The third protocol layer may be a GTP-U layer, a UDP layer, a QUIC layer, or an IP layer. In a possible implementation, the protection for the first packet may include at least one of: deciphering, privacy protection, or integrity verification.

[0648] In a possible implementation, when the communication apparatus is the network function, the network function receives uplink data from the UE, the network function may determine, at a third protocol layer in a first interface oriented to an intermediate function between the UE and the network function, whether the protection should be performed on an uplink packet, based on at least one of: identification information of the uplink packet or an indication on whether protection is performed or not, where the third protocol layer is a lower layer of the first protocol layer, and the first packet is included in the uplink packet. The determination on whether the protection should be performed may also be performed before the first  packet is obtained. For example, an uplink packet may be obtained by the third protocol layer, e.g., GTP-U layer, of the first interface from a lower layer, and then whether the protection should be performed can be determined based on the identification information of the uplink packet or an indication on whether protection is performed included in the uplink packet, and then the first packet is obtained from the uplink packet and delivered based on a result of the determination.

[0649] For example, the network function receives the uplink data from the UE, the data will be carried on an uplink packet, when the packet arrives at the GTP-U layer in the first interface oriented to the intermediate network function, the GTP-U layer in the first interface will perform processing on the uplink packet and determine whether the protection should be performed. The network function can make the determination in either of the following cases:

[0650] Case 1: the network function will perform the processing on the uplink packet at the GTP-U layer in the first interface to obtain the first packet, the first packet is included in the uplink layer. Before the first packet is sent out of the GTP-U layer in the first interface, the network function will determine whether the protection should be performed on the first packet at the first protocol layer. If the protection should be performed, then the first packet will be delivered to the first protocol layer, and the protection will be performed on the first packet at the first protocol layer. If the protection should not be performed on the first packet, the network function will either send the first packet to a second protocol layer above the GTP-U layer, or a fourth protocol layer in a second interface oriented to another network function for data processing, or send the first packet to the first protocol layer without performing the protection at the first protocol layer.

[0651] Case 2: the network function will determine whether the protection should be performed on the uplink packet, then the network function will perform processing on the uplink packet at the GTP-U layer in the first interface to obtain the first packet, the first packet is included in the uplink packet. If the protection should be performed, then the first packet will be delivered to the first protocol layer, and the protection will be performed on the first packet at the first protocol layer. If the protection should not be performed on the first packet, the network function will either send the first packet to a second protocol layer above the GTP-U layer, or a fourth protocol layer in a second interface oriented to another network function for data processing, or send the first packet to the first protocol layer without performing the protection at the first protocol layer.

[0652] In a possible implementation, the first packet is delivered from the third protocol layer to the first protocol layer in a case that the protection should be performed, the network function may perform, at the first protocol layer, the protection on the first packet to obtain a processed first packet, and send the processed first packet to a fourth protocol layer in a second interface oriented to another network function for data processing, or may send the processed first packet to a second protocol layer for data processing, where the fourth protocol layer is a lower layer of the first protocol layer, and the second protocol layer is a higher layer of the first protocol layer. In this case, data of the second protocol layer is protected on the data plane, and devices not configured with the first protocol layer cannot get access to the protected data of the second protocol layer, e.g., protected data of the mission service (e.g. XaaS service) and are not involved in in-network data processing, which can guarantee the security and privacy of in-network processing for mission services, e.g., XaaS services. In a possible implementation, the fourth protocol layer is a GTP-U layer, a UDP layer, a QUIC layer, or an IP layer. The third protocol layer may be a GTP-U layer, a UDP layer, a QUIC layer, or an IP layer. The second interface oriented to another network function for data processing may be an interface allowing data to be transmitted between the network function to another network function (for example, a CN-PSF network function) . For example, the first packet is delivered from a GTP-U layer (the third protocol layer) to the first protocol layer in a case that the protection should be performed, the network function may perform the protection on the first packet to obtain a processed first packet at the first protocol layer, and then the processed first packet would be sent to a GTP-U layer (the fourth protocol layer) in a second interface oriented to CN-PSF function.

[0653] In a possible implementation, the first packet may be included in a data PDU of the first protocol layer, and the data PDU may include one or more of: a mission session ID identifying a mission session the data PDU belongs to, a data session ID identifying the data session the DP-Sec data PDU belongs to, a CBID identifying a CB the data PDU belongs to, a QoS flow ID identifying the data PDU belongs to, an indication on whether protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated, a length of the data PDU, a sequence number of the data PDU, a payload of the data PDU, or a reserved field. The first packet delivered from the third protocol layer of the first interface  to the first protocol layer can be in a form of the data PDU of the first protocol layer which may include one or more fields listed above. The processed first packet generated by the first protocol layer and delivered to the fourth protocol layer of the second interface or the second protocol layer may be obtained from the payload of the data PDU, and the PDU may also include IDs of various granularities, the length of the PDU, and / or the sequence number of the PDU, based on which the first protocol layer can perform processing to obtain the processed first packet. This structured approach can allow for precise control over the security measures applied to each packet, optimizing both security and efficiency during data transmission.

[0654] In a possible implementation, the first packet may be delivered from the third protocol layer to a fourth protocol layer in a second interface oriented to another network function for data processing, or delivered from the third protocol layer to a second protocol layer for data processing, in a case that the protection should not be performed, where the fourth protocol layer is a lower layer of the first protocol layer, and the second protocol layer is a higher layer of the first protocol layer. In a case that the protection should not be performed, the network function may deliver the first packet from the third protocol layer to the fourth protocol layer, or deliver the first packet from the third protocol layer to a second protocol layer, without being processed by the first protocol layer. In this case, the first packet is not protected on the data plane, and devices not configured with the first protocol layer can still get access to the data of the first packet and be involved in in-network data processing if configured with the second protocol layer for data processing. In a possible implementation, the fourth protocol layer is a GTP-U layer, a UDP layer, a QUIC layer, or an IP layer. The second protocol layer may be a PSF layer.

[0655] In a possible implementation, when the communication apparatus is the network function, the network function receives, from another network function, downlink data to be transmitted to the UE, the network function may determine, at a fourth protocol layer in a second interface oriented to the another network function, whether the protection should be performed or not on the first packet, based on at least one of: identification information of the first packet or an indication on whether the protection should be performed or not, where the fourth protocol layer is a lower layer of the first protocol layer. For downlink transmission, the network function may determine whether the protection should be performed or not on the first packet at a fourth protocol layer (e.g. a GTP-U layer) in a second interface oriented to another network function (e.g. the CN-PSF network function) . The downlink packet may be received from another network function, and the first packet obtained from the downlink packet may include, e.g., data of the mission service. By performing such determination, the first packet can be delivered to an appropriate layer based on a result of the determination, thereby enabling appropriate delivering and processing of the packet based on the security requirements and the network’s configuration. In addition, since devices not configured with the first protocol layer cannot get access to the protected data of the mission service (e.g. XaaS service) and cannot be involved in in-network processing of protected data, by determining whether protection should be performed and processing packets accordingly, devices not configured with the first protocol layer but configured with the second protocol layer can be flexibly involved in in-network data processing based on security requirements and the network’s configuration.

[0656] In a possible implementation, when the communication apparatus is the network function, the network function receives, from another network function, downlink data to be transmitted to the UE, the network function may determine, at a fourth protocol layer in a second interface oriented to the another network function, whether the protection should be performed or not on a downlink packet, based on at least one of: identification information of the downlink packet or an indication on whether the protection should be performed or not, where the fourth protocol layer is a lower layer of the first protocol layer, and the first packet is included in the downlink packet. The determination on whether the protection should be performed may also be performed before the first packet is obtained. For example, a downlink packet may be obtained by the fourth protocol layer in the second interface from a lower layer, and then whether the protection should be performed can be determined based on the identification information of the downlink packet or an indication on whether the protection is performed included in the downlink packet, and then the first packet is obtained from the downlink packet and delivered based on a result of the determination.

[0657] For example, the network function receives the downlink data from another network function, the data will be carried on a downlink packet and the data is to be transmitted to the UE. When the packet arrives at the GTP-U layer in the second interface oriented to the another network function, the GTP-U layer in the second interface will perform processing on the  downlink packet and determine whether the protection should be performed. The network function can make the determination in either of the following cases:

[0658] Case 1: the network function will perform the processing on the downlink packet at the GTP-U layer in the second interface to obtain the first packet, where the first packet is included in the downlink packet. Before the first packet is sent out of the GTP-U layer in the second interface, the network function will determine whether the protection should be performed on the first packet at the first protocol layer. If the protection should be performed, then the first packet will be delivered to the first protocol layer, and the protection will be performed on the first packet at the first protocol layer. If the protection should not be performed on the first packet, the network function will either send the first packet to a third protocol layer in a first interface oriented to the UE or send the first packet to the first protocol layer without performing the protection at the first protocol layer.

[0659] Case 2: the network function will determine whether the protection should be performed on the downlink packet, then the network function will perform processing on the downlink packet at the GTP-U layer in the second interface to obtain the first packet, where the first packet is included in the downlink packet. If the protection should be performed, then the first packet will be delivered to the first protocol layer, and the protection will be performed on the first packet at the first protocol layer. If the protection should not be performed on the first packet, the network function will either send the first packet to a third protocol layer in a first interface oriented to the UE, or send the first packet to the first protocol layer without performing the protection at the first protocol layer.

[0660] In a possible implementation, the first packet may be delivered from the fourth protocol layer to the first protocol layer in a case that the protection should be performed, the network function may perform, at the first protocol layer, the protection on the first packet to obtain a processed first packet, and the network function may send the processed first packet to a third protocol layer in a first interface oriented to an intermediate network function between the UE and the network function. In this case, data of the mission service, e.g., XaaS service, can be protected on the data plane, and devices not configured with the first protocol layer cannot get access to the data of the mission service (e.g. XaaS service) and are not involved in in-network data processing, which can guarantee the security and privacy of in-network processing for mission services, e.g., XaaS services. In a possible implementation, the protection on the first packet may include at least one of: ciphering, privacy protection, or integrity protection. The intermediate network function may include a RAN node.

[0661] In a possible implementation, the processed first packet may be included in a data PDU of the first protocol layer, and the data PDU may include one or more of: a mission session ID identifying a mission session the data PDU belongs to, a data session ID identifying the data session the DP-Sec data PDU belongs to, a CBID identifying a CB the data PDU belongs to, a QoS flow ID identifying the data PDU belongs to, an indication on whether the protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated, a length of the data PDU, a sequence number of the data PDU, a payload of the data PDU, or a reserved field. The processed first packet generated at the first protocol layer of the network function and delivered to the third protocol layer in the first interface can be in a form of the data PDU of the first protocol layer which may include one or more fields listed above. The first packet may be included in the payload of the data PDU, and the PDU may also include IDs of various granularities, the length of the PDU, and / or the sequence number of the PDU, based on which the first protocol layer of the UE can perform suitable processing when receiving the processed first packet. This structured approach can allow for precise control over the security measures applied to each packet, optimizing both security and efficiency during data transmission.

[0662] In a possible implementation, the first packet may be delivered from the fourth protocol layer to a third protocol layer in a first interface oriented to an intermediate network function between the UE and the network function, in a case that the protection should not be performed, where the third protocol layer is a lower layer of the first protocol layer. When the protection should not be performed, the network function can pass the first packet from the fourth protocol layer to the third protocol layer, skipping the first protocol layer. In this case, the first packet is not protected on the data plane, and devices not configured with the first protocol layer can still get access to the data of the first packet and be involved in in-network data processing if configured with the second protocol layer for data processing.

[0663] In a possible implementation, the network function may receive, at the third protocol layer, a packet to be relayed, where the packet to be relayed is the first packet from the fourth protocol layer or the processed first packet from the first protocol layer, and the network function may encapsulate, at the third protocol layer, the packet to be relayed and an indication on whether the protection is performed or not to obtain a second packet of the third protocol layer for transmission. The indication on whether the protection is performed or not has a first value indicating the protection is performed in a case that the packet to be relayed is the processed first packet from the first protocol layer, or has a second value indicating the protection is not performed in a case that the packet to be relayed is the first packet from the fourth protocol layer. The packet to be relayed received by the network function at the third protocol layer could be the original first packet coming from the fourth protocol layer, or could be the processed first packet that has already undergone security protection measures at the first protocol layer. At the third protocol layer, the network function may encapsulate the packet to be relayed along with an indication that signals whether protection has been applied to the packet or not. The protection indication can have two distinct values, i.e. first value or second value. The value may take 1 bit. The first value may indicate that protection has been performed. The first value is used when the packet to be relayed is the processed first packet from the first protocol layer, meaning it has already undergone security measures. The second value may indicate that protection has not been performed. The second value is used when the packet to be relayed is the original first packet from the fourth protocol layer. In this way, the indication values can serve as a flag to indicate the protection state, and other device, e.g., the intermediate network function, which receives the second packet, can be aware of the protection state through checking the indication, which enables appropriate handling and processing based on the security requirements and the network’s configuration.

[0664] In a possible implementation, the network function may be configured with the second protocol layer for providing a mission service, where the second protocol layer is a higher layer of the first protocol layer. The first packet may be a packet that is generated by the second protocol layer, e.g., PSF layer, based on downlink data and to be delivered from the second protocol layer to a lower layer in the first interface oriented to the intermediate network function, for transmission to the UE via the intermediate network function.

[0665] Similar to the UE, the network function may determine, at the second protocol layer, based on identification information of the first packet or downlink data, whether the protection should be performed. When the second protocol layer is a PSF layer, the first packet may be a PSF packet. The second protocol layer may determine whether the protection should be performed on the first packet based on identification information of the first packet so that the first packet can be delivered to an appropriate lower layer based on a result of the determination.

[0666] In a case that the second protocol layer determines that the protection should be performed, the first packet would be delivered to the first protocol layer, e.g., DP-Sec layer, in the network function, and the necessary protection would be applied to the first packet to obtain a processed first packet. After the protection has been applied, the processed first packet would be then sent from the first protocol layer to the third protocol layer in the first interface oriented to the intermediate network function.

[0667] In a case that the second protocol layer determines that the protection should not be performed, the first packet may be delivered from the second protocol layer to the third protocol layer in the first interface, without being processed by the first protocol layer.

[0668] The network function may receive, at the third protocol layer in the first interface, a packet from an upper layer, where the upper layer is the second protocol layer or the first protocol layer, and the received packet is the first packet from the second protocol layer or the processed first packet from the first protocol layer. The network function may then encapsulate, at the third protocol layer, the received packet and an indication on whether the protection is performed or not, to obtain a second packet of the third protocol layer for transmission. The indication on whether the protection is performed or not has a first value indicating the protection is performed in a case that the received packet is the processed first packet from the first protocol layer, or has a second value indicating the protection is not performed in a case that the received packet is the first packet from the second protocol layer.

[0669] In a possible implementation, the indication on whether the protection is performed or not is encapsulated in a packet header or a payload of the second packet of the third protocol layer.

[0670] In a possible implementation, the payload of the data PDU of the first protocol layer may be encrypted in a case that the protection is performed. If it is determined that protection should be performed, the payload may be encrypted using an encryption algorithm.

[0671] In a possible implementation, the protection may be performed on the first packet by using at least one of: a mission session ID, a data session ID, a CBID, or a QoS ID of the first packet as one or more of: a ciphering material, a privacy protection material, or an integrity protection material. For example, for uplink transmission, these IDs can be used by the UE to generate or select an encryption key (ciphering material) used to encrypt the payload of the data PDU, ensuring that only authorized recipients can decrypt and access the data. These IDs can be employed to anonymize or pseudonymize the data within the packet, thereby protecting the privacy of the users or the content of the communication. These IDs can also be used to generate or select the parameters for creating a message authentication code or a digital signature, which verifies that the packet has not been altered during transit. When the protection is applied using the identifiers as materials, the packet can be ready for transmission over the network, with the appropriate security measures in place to safeguard the data.

[0672] FIG. 24 shows a schematic flowchart of a communication method according to one or more embodiments of the present disclosure. The method can be implemented by an intermediate network function (e.g., the apparatus 320 as shown in FIG. 3A) between a UE and a network function, and the intermediate network function may be e.g., in a RAN. The detailed procedures are as the following steps by taking RAN as an example. As shown in FIG. 24, the method can include the following steps.

[0673] S2410, the intermediate network function obtains a first message, where the first message includes information for configuring a first protocol layer in a UE, the first protocol layer is to support data plane security protection on a first packet, and the protection is between the UE and a network function.

[0674] S2420, the intermediate network function sends the first message to the UE.

[0675] In the embodiment, the intermediate network function can obtain the first message and send it to the UE, where the first message includes information which is used to set up the first protocol layer in a UE to support data plane security protection for some packets. The first protocol layer may be, e.g., the DP-Sec layer described above, or some other layers with the same or similar functions. The protection is designed to secure the data transmission between the UE and a network function, ensuring the confidentiality and integrity of the data as it travels across the network. The information for configuring the first protocol layer in the UE, included in the first message, may be generated by the intermediate network function, or received by the intermediate network function from another network function, e.g., a C / M plane function. The network function may be in a core network. For example, the network function can be a data trustworthy gateway (Data-TW-GW) , or a user plane function (UPF) .

[0676] The message may include essential information that the UE needs to establish the first protocol layer effectively. For example, the message may include information for the UE to determine whether the protection (e.g., DP-Sec protection) should be performed on a packet. The message might include security parameters, encryption algorithms, keying material, and other relevant settings that define the security requirements for the first packet.

[0677] By configuring the first protocol layer in the UE, the UE can adapt to different security requirements, allowing for flexible and dynamic security measures. Secure and reliable data transmission between the UE and network functions can be enabled by establishing a robust security framework on the data plane. In addition, the establishment of the first protocol layer, which is to support data plane security protection on a first packet, can apply security protection measures to the data packets that will be transmitted, ensuring the confidentiality and integrity of the data.

[0678] In a possible implementation, the first protocol layer may be a lower layer of a second protocol layer, where the second protocol layer is used to provide a mission service, where the mission service is a service for both PDU connectivity and data processing and the first protocol layer is to protect at least one of security and privacy of the second protocol layer.

[0679] In a possible implementation, the second protocol layer may be a XaaS service layer or a PSF layer.

[0680] In a possible implementation, the intermediate network function may receive a second message from a further network function, where the second message includes information for configuring the first protocol layer in the UE. The further network function may be a C / M plane function, such as a C / M-TW-GW, a SCP+, an AMF+, an SMF+, etc.

[0681] In a possible implementation, the information for configuring the first protocol layer in the UE may include information indicating one or more identifiers on which the protection should be performed or not.

[0682] In a possible implementation, the intermediate network function may send assistance information to the further network function, where the assistance information includes the information indicating one or more IDs on which the protection should be performed or not. The intermediate network function may play an active role in the security configuration process by providing assistance information to a further network function, such as the C / M-TW-GW. The assistance information may be used for determining the information for configuring the first protocol layer. In a possible implementation, the intermediate network function may receive configurations from a C / M plane function, e.g., a mission control function (MCF) . The intermediate network function can know one or more of: a mission session (group) , a data session (group) , a CB (group) , a radio bearer (group) , and a QoS flow (group) , that the second protocol layer, e.g., PSF layer in intermediate network function should be involved in. The assistance information sent by the intermediate network function to the further network function may include details that indicate one or more IDs. These IDs could be related to various aspects of the packet transmission including one or more of mission session ID, data session ID, CBID, QoS flow ID. The information indicating whether protection should be performed or not on these IDs helps the further network function to make decisions on whether to apply security measures such as encryption, integrity protections, or privacy protections to the packets associated with these IDs. The collaborative approach between the intermediate network function and the further network function can ensure that the security configuration is aligned with the specific needs of the packet transmission, optimizing both security and network performance.

[0683] In a possible implementation, the information indicating one or more identifiers on which the protection should be performed or not may include one or more of: a mission session ID identifying a mission session on which the protection should be performed or not, a mission session group ID identifying a mission session group on which the protection should be performed or not, a data session ID identifying a data session on which the protection should be performed or not, a data session group ID identifying a data session group on which the protection should be performed or not, a computing block identifier (CBID) identifying a computing block (CB) on which the protection should be performed or not, a CB group ID identifying a CB group on which the protection should be performed or not, a radio bearer ID identifying a radio bearer on which the protection should be performed or not, a radio bearer group ID identifying a radio bearer group on which the protection should be performed or not, a quality of service (QoS) flow ID identifying a QoS flow on which the protection should be performed or not, or a QoS flow group ID identifying a QoS flow group on which the protection should be performed or not.

[0684] In a possible implementation, the second message received from the further network function and the first message sent to the UE may be to send non-access stratum information between the further network function and the UE, or the second message may be a message on an interface with an application protocol between the further network function and the intermediate network function, e.g., RAN, and the first message is an RRC message. The second message could also be an application protocol message exchanged over an interface between the further network function and the intermediate network function. The application protocol would provide signaling service between the further network function and the intermediate network function, e.g., application layer signaling protocol, or NG application protocol (NGAP) . In some cases, the application protocol supports the functions of the control plane interface between the further network function and the intermediate network function by signaling defined messages. The first message, in this case, is identified as an RRC message. The RRC message may be used for establish and maintain the connection and can also be used to configure security parameters for the data plane. The information for configuring the first protocol layer may be sent to the UE in various ways, which can provide more flexibility for the transmission of configuration information, and accommodate more application scenarios.

[0685] In a possible implementation, the intermediate network function may be in a RAN. The intermediate network function may have a first interface oriented to the UE, which is a radio interface, and a second interface oriented to the network function. In a case that the intermediate network function is configured with the second protocol layer, e.g., PSF layer, the second protocol layer may be above a radio layer in the first interface oriented to the UE. In a possible implementation, the radio layer may include an SDAP layer.

[0686] In a possible implementation, there may be one or more additional layers between the second protocol layer and the radio layer. In a possible implementation, the one or more additional layers may include one or more of: a PDU layer, an IP layer, a UDP layer, a TCP layer, or a QUIC layer.

[0687] In a possible implementation, the second protocol layer may be above a transport network layer (TNL) in the second interface oriented to the network function. In a possible implementation, the TNL layer may include one or more of: a GTP-U layer, a UDP layer, a QUIC layer, or an IP layer.

[0688] In a possible implementation, there may be one or more additional layers between the second protocol layer and the TNL layer. In a possible implementation, the one or more additional layers may include one or more of: a PDU layer, an IP layer, a UDP layer, a TCP layer, or a QUIC layer.

[0689] In a possible implementation, whether the protection is performed on the first packet may be determined based on at least one of: identification information corresponding to the first packet, or an indication on whether the protection is performed or not, where the indication on whether the protection is performed or not is included in a packet which includes the first packet, or is not included in a packet which includes the first packet.

[0690] In a possible implementation, the identification information corresponding to the first packet may include at least one of: a mission session ID identifying a mission session to which the first packet belongs, a mission session group ID identifying a mission session group to which the first packet belongs, a data session ID identifying a data session to which the first packet belongs, a data session group ID identifying a data session group to which the first packet belongs, a CBID identifying a CB to which the first packet belongs, a CB group ID identifying a CB group to which the first packet belongs, a radio bearer ID identifying a radio bearer to which the first packet belongs, a radio bearer group ID identifying a radio bearer group to which the first packet belongs, a QoS flow ID identifying a QoS flow to which the first packet belongs, or a QoS flow group ID identifying a QoS flow group to which the first packet belongs.

[0691] In a possible implementation, the intermediate network function may determine, based on whether the intermediate network function between the UE and the network function should not be involved in data processing, whether the protection should be performed. The intermediate network function may assess whether it needs to participate in data processing, and then determine whether the protection should be performed accordingly, enabling dynamic switch of the protection.

[0692] In a possible implementation, whether the protection should be performed may be determined for at least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bears, or one or more QoS flows.

[0693] In a possible implementation, the intermediate network function may determine that the protection should be performed in a case that the intermediate network function between the UE and the network function should not be involved in data processing. In a possible implementation, the intermediate network function may determine that the protection should not be performed in a case that the intermediate network function between the UE and the network function should be involved in data processing.

[0694] In a possible implementation, the intermediate network function may determine, based on at least one of: channel state information or processing payload, whether an intermediate network function between the UE and the network function should be involved in data processing.

[0695] In a possible implementation, the intermediate network function may send or receive control information which indicates: that the protection should be performed; or that the protection should not be performed. In a possible implementation, the control information may further indicate at least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bearers, or one or more QoS flows, where the protection should be performed on the first packet in a case that the first packet belongs to the one or more mission sessions, the one or more data sessions, the one or more CBs,  the one or more radio bearers, or the one or more QoS flows; or at least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bearers, or one or more QoS flows, where the protection should not be performed on the first packet in a case that the first packet belongs to the one or more mission sessions, the one or more data sessions, the one or more CBs, the one or more radio bearers, or the one or more QoS flows. By exchanging control information with other devices, the security measures applied to the data packets can be dynamically adjusted, enabling flexible involvement of the intermediate network function for in-network processing and ensuring flexibility and adaptability to various network conditions and security requirements.

[0696] In a possible implementation, the first packet may go through a second protocol layer for data processing in a case that the protection is not performed, and the second protocol layer is a higher layer of the first protocol layer.

[0697] In a possible implementation, the first packet may not go through a second protocol layer for data processing in a case that the protection is performed, and the second protocol layer is a higher layer of the first protocol layer.

[0698] Whether or not the first packet goes through the second protocol layer for data processing may depend on whether the first packet is protected. If the first packet is protected, i.e., the protection is performed, the intermediate network function cannot parse the data in the first packet and cannot perform data processing, and in this case, the first packet would not be delivered to the second protocol layer, e.g., PSF layer. If the first packet is not protected, i.e., the protection is not performed, the intermediate network function can parse the data of the first packet, and the first packet can be delivered to the second protocol layer for data processing.

[0699] In a possible implementation, the intermediate function may determine, at a third protocol layer in a first interface oriented to the UE, whether the protection is performed or not on the first packet, based on at least one of identification information of the first packet or an indication on whether the protection is performed or not, where the third protocol layer is a lower layer of the first protocol layer. For uplink transmission, the first packet may be a packet that is obtained from an uplink packet by the third protocol layer, e.g., SDAP layer, in the first interface of the intermediate network function, and to be delivered from the third protocol layer to another layer. The third protocol layer may operate within the first interface that is oriented towards the UE. The intermediate network function may determine whether the protection is applied to the first packet at the third protocol layer, so that the first packet can be delivered to an appropriate layer based on a result of the determination.

[0700] In a possible implementation, the intermediate network function may determine, at a third protocol layer in a first interface oriented to the UE, whether the protection is performed or not on an uplink packet, based on at least one of identification information of the uplink packet or an indication on whether the protection is performed or not, where the third protocol layer is a lower layer of the first protocol layer, and the first packet is included in the uplink packet. The determination on whether the protection is performed may also be performed before the first packet is obtained. For example, an uplink packet may be obtained by the third protocol layer, e.g., SDAP layer, of the first interface from a lower layer, and then whether the protection is performed can be determined based on the identification information of the uplink packet or an indication on whether the protection is performed included in the uplink packet, and then the first packet is obtained from the uplink packet and delivered based on a result of the determination.

[0701] For example, the RAN receives, from the UE, uplink data to be transmitted to the network function, the data will be carried on an uplink packet, when the uplink packet arrives at the SDAP layer in the first interface oriented to the UE, the SDAP layer will perform processing on the uplink packet and determine whether the protection is performed. The RAN can make the determination in either of the following cases:

[0702] Case 1: the RAN will perform processing on the uplink packet at the SDAP layer in the first interface to obtain the first packet, the first packet is included in the uplink packet. Before the first packet is sent out of the SDAP layer, the RAN will determine whether the protection is performed on the first packet. If the RAN determines that the protection is performed on the first packet, then the first packet will be delivered to a fourth protocol layer in a second interface oriented to the network function. If the RAN determines that the protection is not performed on the first packet, then the first packet will be delivered to a second protocol layer, e.g., PSF layer, for data processing.

[0703] Case 2: the RAN will determine whether the protection is performed on the uplink packet, then the RAN will perform processing on the uplink packet at the SDAP layer in the first interface to obtain the first packet, the first packet is included in the uplink packet. If the RAN determines that the protection is performed on the uplink packet, then the first packet will be delivered to a fourth protocol layer in a second interface oriented to the network function. If the RAN determines that the protection is not performed on the uplink packet, then the first packet will be delivered to a second protocol layer, e.g., PSF layer, for data processing.

[0704] In a possible implementation, the first packet may be delivered from the third protocol layer to a fourth protocol layer in the second interface oriented to the network function in a case that the protection is performed, where the fourth protocol layer is a lower layer of the first protocol layer. If the protection is performed, the intermediate network function cannot parse the data in the first packet, and may deliver the first packet from the third protocol layer to the fourth protocol layer in the second interface to forward to the network function.

[0705] In a possible implementation, the first packet may be delivered from the third protocol layer to a second protocol layer for data processing in a case that the protection is not performed, the second protocol layer is a higher layer of the first protocol layer, the intermediate network function may perform, at the second protocol layer, data processing on the first packet to obtain a processed first packet containing a processing result of the first packet, and send the processed first packet to the fourth protocol layer in the second interface oriented to the network function, where the fourth protocol layer is a lower layer of the first protocol layer. If the protection is not performed, the intermediate network function may deliver the first packet from the third protocol layer to the second protocol layer for data processing. In this case, the first packet is not protected on the data plane, and the intermediate network function can parse and process the data of the first packet.

[0706] In a possible implementation, the intermediate network function may receive, at the fourth protocol layer, a packet to be relayed, where the packet to be relayed is the first packet from the third protocol layer or the processed first packet from the second protocol layer. The intermediate network function may then encapsulate, at the fourth protocol layer, the packet to be relayed and an indication on whether the protection is performed or not to obtain a second packet of the fourth protocol layer for transmission. The indication on whether the protection is performed or not has a first value indicating the protection is performed in a case that the packet to be relayed is the first packet from the third protocol layer, or has a second value indicating the protection is not performed in a case that the packet to be relayed is the processed first packet from the second protocol layer. In this way, the indication values can serve as a flag to indicate the protection state, and other device, such as the network function, which receives the second packet, can be aware of the protection state by checking the indication, which enables appropriate handling and processing based on the security requirements and the network’s configuration.

[0707] In a possible implementation, the indication on whether the protection is performed or not may be encapsulated in a packet header or a payload of the second packet of the fourth protocol layer.

[0708] In a possible implementation, the intermediate network function may determine, at a fourth protocol layer in a second interface oriented to the network function, whether the protection is performed or not on the first packet, based on at least one of:identification information of the first packet or an indication on whether the protection is performed or not, where the fourth protocol layer is a lower layer of the first protocol layer. For downlink transmission, the first packet may be a packet that is obtained from a downlink packet by the fourth protocol layer, e.g., GTP-U layer, in the second interface of the intermediate network function, and to be delivered from the fourth protocol layer to another layer. The fourth protocol layer may operate within the second interface that is oriented towards the network function. The intermediate network function may determine whether the protection is performed on the first packet at the fourth protocol layer, so that the first packet can be delivered to an appropriate layer based on a result of the determination.

[0709] In a possible implementation, the RAN may determine, at a fourth protocol layer in a second interface oriented to the network function, whether the protection is performed or not on a downlink packet, based on at least one of: identification information of the downlink packet or an indication on whether the protection is performed or not, where the fourth protocol layer is a lower layer of the first protocol layer, and the first packet is included in the downlink packet. The determination on whether the protection is performed may also be performed before the first packet is obtained. For example, a downlink packet  may be obtained by the fourth protocol layer, e.g., GTP-U layer, of the second interface from a lower layer, and then whether the protection is performed can be determined based on the identification information of the downlink packet or an indication on whether the protection is performed included in the downlink packet, and then the first packet is obtained from the downlink packet and delivered based on a result of the determination.

[0710] For example, the RAN receives, from the network function, downlink data to be transmitted to the UE, the data will be carried on a downlink packet, when the downlink packet arrives at the GTP-U layer in the second interface oriented to the network function, the GTP-U layer will perform processing on the downlink packet and determine whether the protection is performed. The RAN can make the determination in either of the following cases:

[0711] Case 1: the RAN will perform processing on the downlink packet at the GTP-U layer in the second interface to obtain the first packet, the first packet is included in the downlink packet. Before the first packet is sent out of the GTP-U layer in the second interface, the RAN will determine whether the protection is performed on the first packet. If the RAN determines that the protection is performed on the first packet, then the first packet will be delivered to a third protocol layer in a first interface oriented to the UE. If the RAN determines that the protection is not performed on the first packet, then the first packet will be delivered to a second protocol layer, e.g., PSF layer, for data processing.

[0712] Case 2: the RAN will determine whether the protection is performed on the downlink packet, then the RAN will perform processing on the downlink packet at the GTP-U layer in the second interface to obtain the first packet, the first packet is included in the downlink packet. If the RAN determines that the protection is performed on the downlink packet, then the first packet will be delivered to a third protocol layer in a first interface oriented to the UE. If the RAN determines that the protection is not performed on the downlink packet, then the first packet will be delivered to a second protocol layer, e.g., PSF layer, for data processing.

[0713] In a possible implementation, the first packet may be delivered from the fourth protocol layer to a third protocol layer in a first interface oriented to the UE in a case that the protection is performed, where the third protocol layer is a lower layer of the first protocol layer. If the protection is performed, the intermediate network function cannot parse the data in the first packet, and may deliver the first packet from the fourth protocol layer to the third protocol layer in the second interface to forward to the UE.

[0714] In a possible implementation, the first packet may be delivered from the fourth protocol layer to a second protocol layer for data processing in a case that the protection is not performed, the second protocol layer is a higher layer of the first protocol layer, and the RAN may perform, at the second protocol layer, data processing on the first packet to obtain a processed first packet containing a processing result of the first packet, and sending the processed first packet to a third protocol layer in a first interface oriented to the UE, where the third protocol layer is a lower layer of the first protocol layer. If the protection is not performed, the intermediate network function may deliver the first packet from the fourth protocol layer to the second protocol layer for data processing. In this case, the first packet is not protected on the data plane, and the intermediate network function can parse and process the data of the first packet.

[0715] In a possible implementation, the intermediate network function may receive, at the third protocol layer, a packet to be relayed, where the packet to be relayed is the first packet from the fourth protocol layer or the processed first packet from the second protocol layer, and may encapsulate, at the third protocol layer, the packet to be relayed and an indication on whether the protection is performed or not to obtain a second packet of the third protocol layer for transmission. The indication on whether the protection is performed or not has a first value indicating the protection is performed in a case that the packet to be relayed is the first packet from the fourth protocol layer, or has a second value indicating the protection is not performed in a case that the packet to be relayed is the processed first packet from the second protocol layer. In this way, the indication values can serve as a flag to indicate the protection state of the packet, the UE can be aware of the protection state through checking the indication, which enables appropriate handling and processing based on the security requirements and the network’s configuration.

[0716] In a possible implementation, the indication on whether the protection is performed or not is encapsulated in a packet header or a payload of the second packet of the third protocol layer.

[0717] In a possible implementation, in a case that the protection is performed, the first packet to be delivered from the third protocol layer to the fourth protocol layer may be included in a data PDU of the first protocol layer, and the data PDU includes one or more of: a mission session ID identifying a mission session the data PDU belongs to, a data session ID identifying the data session the DP-Sec data PDU belongs to, a CBID identifying a CB the data PDU belongs to, a QoS flow ID identifying the data PDU belongs to, an indication on whether the protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated, a length of the data PDU, a sequence number of the data PDU, a payload of the data PDU, or a reserved field.

[0718] In a possible implementation, the payload of the data PDU of the first protocol layer may be encrypted in a case that the protection is performed.

[0719] In a possible implementation, the third protocol layer of the intermediate network function may be an SDAP layer.

[0720] In a possible implementation, the fourth protocol layer of the intermediate network function may be a GTP-U layer, a UDP layer, an IP layer, or a QUIC layer.

[0721] In a possible implementation, the protection is performed on the first packet by using at least one of: a mission session ID, a data session ID, a CBID, or a QoS ID of the first packet as one or more of: a ciphering material, a privacy protection material, or an integrity protection material.

[0722] As discussed above, a packet of a layer lower than the first protocol layer may have a field to indicate whether the protection is performed, so that other devices receiving the packet can be aware of the protection state of the packet and operate accordingly. The packet may be a packet of a TNL layer, e.g., a GTP-U packet, or a QUIC packet, or a packet of a radio layer, e.g., an SDAP packet.

[0723] For example, for the UE, in uplink transmission, by taking the first protocol layer being DP-Sec layer, the second protocol layer being PSF layer and the third protocol layer being SDAP layer as an exampl...

Claims

1.A communication method, comprising:receiving a message, wherein the message is used to configure a first protocol layer in a communication apparatus, the first protocol layer is to support data plane security protection on a first packet, and the protection is between a user equipment (UE) and a network function; andconfiguring the first protocol layer based on the message.2.The method according to claim 1, wherein the first protocol layer is a lower layer of a second protocol layer which is used to provide a mission service, wherein the mission service is a service for both protocol data unit (PDU) connectivity and data processing and the first protocol layer is to protect at least one of security and privacy of data of the second protocol layer.3.The method according to claim 2, wherein the mission service is provided through at least one mission session, and each of the at least one mission session comprises a data forwarding resource and a data processing resource for providing the mission service.4.The method according to claim 3, wherein each of the at least one mission session comprises at least one data session, and each of the at least one data session comprises an association terminates at a second entity executing one or more computing blocks (CBs) of the mission service, wherein the second entity is on the second protocol layer, the mission service comprises at least one CB, each of the at least one CB corresponds to a computational step toward achieving the mission service, and the at least one CB comprises the one or more CBs.5.The method according to any one of claims 2 to 4, wherein the second protocol layer is an anything as a service (XaaS) service layer.6.The method according to any one of claims 2 to 5, wherein the second protocol layer is a processing service function (PSF) layer.7.The method according to any one of claims 1 to 6, wherein one or more first entities are established on the first protocol layer to perform the protection.8.The method according to any one of claims 1 to 7, wherein whether the protection should be performed on the first packet is determined based on at least one of:identification information corresponding to the first packet, oran indication on whether protection is performed or not, wherein the indication on whether protection is performed or not is comprised in a packet which comprises the first packet, or is not comprised in a packet which comprises the first packet.9.The method according to claim 8, wherein the identification information corresponding to the first packet comprises at least one of:a mission session identifier (ID) identifying a mission session to which the first packet belongs,a mission session group ID identifying a mission session group to which the first packet belongs,a data session ID identifying a data session to which the first packet belongs,a data session group ID identifying a data session group to which the first packet belongs,a computing block identifier (CBID) identifying a CB to which the first packet belongs,a CB group ID identifying a CB group to which the first packet belongs,a radio bearer ID identifying a radio bearer to which the first packet belongs,a radio bearer group ID identifying a radio bearer group to which the first packet belongs,a quality of service (QoS) flow ID identifying a QoS flow to which the first packet belongs, ora QoS flow group ID identifying a QoS flow group to which the first packet belongs.10.The method according to any one of claims 1 to 9, wherein the message comprises one or more of:a mission session ID identifying a mission session on which the protection should be performed or not,a mission session group ID identifying a mission session group on which the protection should be performed or not,a data session ID identifying a data session on which the protection should be performed or not,a data session group ID identifying a data session group on which the protection should be performed or not,a CBID identifying a CB on which the protection should be performed or not,a CB group ID identifying a CB group on which the protection should be performed or not,a radio bearer ID identifying a radio bearer on which the protection should be performed or not,a radio bearer group ID identifying a radio bearer group on which the protection should be performed or not,a QoS flow ID identifying a QoS flow on which the protection should be performed or not, ora QoS flow group ID identifying a QoS flow group on which the protection should be performed or not.11.The method according to any one of claim 1 to 10, further comprising:determining, based on whether an intermediate network function between the user equipment and the network function should not be involved in data processing, whether the protection should be performed.12.The method according to claim 11, wherein whether the protection should be performed is determined for at least one of:one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bears, or one or more QoS flows.13.The method according to claim 11 or 12, wherein the determining, based on whether the intermediate network function between the user equipment and the network function should not be involved in data processing, whether the protection should be performed comprises:determining that the protection should be performed in a case that the intermediate network function between the UE and the network function should not be involved in data processing.14.The method according to any one of claims 11 to 13, wherein the determining, based on whether the intermediate network function between the user equipment and the network function should not be involved in data processing, whether the protection should be performed comprises:determining that the protection should not be performed in a case that the intermediate network function between the UE and the network function should be involved in data processing.15.The method according to any one of claims 11 to 14, further comprising:determining, based on at least one of channel state information or processing payload, whether the intermediate network function between the UE and the network function should be involved in data processing.16.The method according to any one of claims 1 to 15, further comprising:sending or receiving control information which indicates:that the protection should be performed; orthat the protection should not be performed.17.The method according to claim 16, wherein the control information further indicatesat least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bearers, or one or more QoS flows, wherein the protection should be performed on the first packet in a case that the first packet belongs to the one or more mission sessions, the one or more data sessions, the one or more CBs, the one or more radio bearers, or the one or more QoS flows; orat least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bearers, or one or more QoS flows, wherein the protection should not be performed on the first packet in a case that the first packet belongs to the one or more mission sessions, the one or more data sessions, the one or more CBs, the one or more radio bearers, or the one or more QoS flows.18.The method according to claim 16 or 17, wherein the control information is carried in a control PDU of the first protocol layer.19.The method according to claim 18, wherein the control information comprises one or more of:an indication on whether the protection should be performed or not, or activated or deactivated,a data session ID identifying a data session or a set of data session IDs identifying a set of data sessions,a CBID identifying a CB or a set of CBIDs identifying a set of CBs,a mission session ID identifying a mission session or a set of mission session IDs identifying a set of mission sessions,a QoS flow ID identifying a QoS flow or a set of QoS flow IDs identifying a set of QoS flows,one or more sequence numbers (SNs) , wherein a value of each SN is used for transmitting packet in order, and / or as material for at least one of ciphering or integrity protection, ora reserved field.20.The method according to any one of claims 1 to 19, wherein the first packet goes through the first protocol layer for the protection in a case that the protection should be performed.21.The method according to any one of claims 1 to 20, wherein the first packet does not go through the first protocol layer, or goes through the first protocol layer without being performed with the protection in a case that the protection should not be performed.22.The method according to any one of claims 1 to 21, wherein the communication apparatus is the UE.23.The method according to claim 22, wherein the message is a radio resource control (RRC) message or a non-access stratum control plane (NAS-CP) message.24.The method according to claim 22 or 23, wherein the first protocol layer is a lower layer of a second protocol layer providing a mission service.25.The method according to claim 24, wherein there is one or more additional layers between the first protocol layer and the second protocol layer, and the one or more additional layers comprise at least one of: a PDU layer, an internet protocol (IP) layer, a user datagram protocol (UDP) layer, a transmission control protocol (TCP) layer, or a quick UDP internet connections (QUIC) layer.26.The method according to any one of claims 22 to 25, wherein the first protocol layer is an upper layer of a radio layer.27.The method according to claim 26, wherein the radio layer comprises a service data adaptation protocol (SDAP) layer.28.The method according to claim 26 or 27, wherein there is one or more additional layers between the first protocol layer and the radio layer.29.The method according to claim 28, wherein the one or more additional layers between the first protocol layer and the radio layer comprise at least one of: a PDU layer, an IP layer, a UDP layer, a TCP layer, or a QUIC layer.30.The method according to any one of claims 22 to 29, further comprising:determining, at a second protocol layer, based on identification information of the first packet, whether the protection should be performed on the first packet, wherein the second protocol layer is a higher layer of the first protocol layer.31.The method according to any one of claims 22 to 29, further comprising:determining, at a second protocol layer, based on identification information of an uplink packet, whether the protection should be performed on the uplink packet, wherein the second protocol layer is a higher layer of the first protocol layer, and the uplink packet is comprised in the first packet.32.The method according to claim 30 or 31, wherein the first packet is delivered from the second protocol layer to the first protocol layer in a case that the protection should be performed, the method further comprising:performing, at the first protocol layer, the protection on the first packet to obtain a processed first packet, and sending the processed first packet to a third protocol layer, wherein the third protocol layer is a lower layer of the first protocol layer.33.The method according to claim 32, wherein the protection on the first packet comprises at least one of: ciphering, privacy protection, or integrity protection.34.The method according to claim 32 or 33, wherein the processed first packet is comprised in a data PDU of the first protocol layer, and the data PDU comprises one or more of:a mission session ID identifying a mission session the data PDU belongs to,a data session ID identifying the data session the DP-Sec data PDU belongs to,a CBID identifying a CB the data PDU belongs to,a QoS flow ID identifying the data PDU belongs to,an indication on whether the protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated,a length of the data PDU,a sequence number of the data PDU,a payload of the data PDU, ora reserved field.35.The method according to claim 30 or 31, wherein:the first packet is delivered from the second protocol layer to a third protocol layer in a case that the protection should not be performed, wherein the third protocol layer is a lower layer of the first protocol layer.36.The method according to any one of claims 32 to 35, further comprising:receiving, at the third protocol layer, a packet from an upper layer, wherein the upper layer is the second protocol layer or the first protocol layer, and the received packet is the first packet from the second protocol layer or the processed first packet from the first protocol layer;encapsulating, at the third protocol layer, the received packet and an indication on whether the protection is performed or not, to obtain a second packet of the third protocol layer for transmission;wherein the indication on whether the protection is performed or not has a first value indicating the protection is performed in a case that the received packet is the processed first packet from the first protocol layer, or has a second value indicating the protection is not performed in a case that the received packet is the first packet from the second protocol layer.37.The method according to claim 36, wherein the indication on whether the protection is performed or not is encapsulated in a packet header or a payload of the second packet of the third protocol layer.38.The method according to any one of claims 22 to 29, further comprising:determining, at a third protocol layer, whether the protection should be performed or not on the first packet, based on at least one of: identification information of the first packet or an indication on whether protection is performed or not, wherein the third protocol layer is a lower layer of the first protocol layer.39.The method according to any one of claims 22 to 29, further comprising:determining, at a third protocol layer, whether the protection should be performed or not on a downlink packet, based on at least one of: identification information of the downlink packet or an indication on whether protection is performed or not, wherein the third protocol layer is a lower layer of the first protocol layer, and the first packet is comprised in the downlink packet.40.The method according to claim 38 or 39, wherein the first packet is delivered from the third protocol layer to the first protocol layer in a case that the protection should be performed, the method further comprising:performing, at the first protocol layer, the protection on the first packet to obtain a processed first packet and sending the processed first packet to a second protocol layer for data processing, wherein the second protocol layer is a higher layer of the first protocol layer.41.The method according to claim 40, wherein the protection on the first packet comprises at least one of: deciphering, privacy protection, or integrity verification.42.The method according to claim 40 or 41, wherein the first packet is comprised in a data PDU of the first protocol layer, and the data PDU comprises one or more of:a mission session ID identifying a mission session the data PDU belongs to,a data session ID identifying the data session the DP-Sec data PDU belongs to,a CBID identifying a CB the data PDU belongs to,a QoS flow ID identifying the data PDU belongs to,an indication on whether protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated,a length of the data PDU,a sequence number of the data PDU,a payload of the data PDU, ora reserved field.43.The method according to claim 38 or 39, wherein the first packet is delivered from the third protocol layer to a second protocol layer for data processing in a case that the protection should not be performed, and the second protocol layer is a higher layer of the first protocol layer.44.The method according to any one of claims 32 to 43, wherein the third protocol layer is an SDAP layer.45.The method according to any one of claims 1 to 21, wherein the communication apparatus is the network function.46.The method according to claim 45, wherein there is one or more layers above the first protocol layer.47.The method according to claim 46, wherein the one or more layers above the first protocol layer comprise one or more of: a PDU layer, a second protocol layer providing a mission service, an IP layer, a UDP layer, a TCP layer, or a QUIC layer.48.The method according to any one of claims 45 to 47, wherein the first protocol layer is an upper layer of a transport network layer (TNL) .49.The method according to claim 48, wherein the TNL comprises one or more of: a general packet radio service (GPRS) tunnelling protocol for user plane (GTP-U) layer, a UDP layer, a QUIC layer, or an IP layer.50.The method according to claim 48 or 49, wherein there is one or more additional layers between the first protocol layer and the TNL layer.51.The method according to claim 50, wherein the one or more additional layers between the first protocol layer and the TNL layer comprise at least one of: a PDU layer, an IP layer, a UDP layer, a TCP layer, or a QUIC layer.52.The method according to any one of claims 45 to 51, further comprising:determining, at a third protocol layer in a first interface oriented to an intermediate function between the UE and the network function, whether the protection should be performed on the first packet, based on at least one of: identification information of the first packet or an indication on whether protection is performed or not, wherein the third protocol layer is a lower layer of the first protocol layer.53.The method according to any one of claims 45 to 51, further comprising:determining, at a third protocol layer in a first interface oriented to an intermediate function between the UE and the network function, whether the protection should be performed on an uplink packet, based on at least one of: identification information of the uplink packet or an indication on whether protection is performed or not, wherein the third protocol layer is a lower layer of the first protocol layer, and the first packet is comprised in the uplink packet.54.The method according to claim 52 or 53, wherein the first packet is delivered from the third protocol layer to the first protocol layer in a case that the protection should be performed, the method further comprising:performing, at the first protocol layer, the protection on the first packet to obtain a processed first packet, and sending the processed first packet to a fourth protocol layer in a second interface oriented to another network function for data processing, or sending the processed first packet to a second protocol layer for data processing, wherein the fourth protocol layer is a lower layer of the first protocol layer, and the second protocol layer is a higher layer of the first protocol layer.55.The method according to claim 54, wherein the protection for the first packet comprises at least one of: deciphering, privacy protection, or integrity verification.56.The method according to claim 54 or 55, wherein the first packet is comprised in a data PDU of the first protocol layer, and the data PDU comprises one or more of:a mission session ID identifying a mission session the data PDU belongs to,a data session ID identifying the data session the DP-Sec data PDU belongs to,a CBID identifying a CB the data PDU belongs to,a QoS flow ID identifying the data PDU belongs to,an indication on whether protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated,a length of the data PDU,a sequence number of the data PDU,a payload of the data PDU, ora reserved field.57.The method according to claim 52 or 53, wherein the first packet is delivered from the third protocol layer to a fourth protocol layer in a second interface oriented to another network function for data processing, or delivered from the third protocol layer to a second protocol layer for data processing, in a case that the protection should not be performed, wherein the fourth protocol layer is a lower layer of the first protocol layer, and the second protocol layer is a higher layer of the first protocol layer.58.The method according to any one of claims 45 to 51, further comprising:determining, at a fourth protocol layer in a second interface oriented to another network function, whether the protection should be performed or not on the first packet, based on at least one of: identification information of the first packet or an indication on whether the protection should be performed or not, wherein the fourth protocol layer is a lower layer of the first protocol layer.59.The method according to any one of claims 45 to 51, further comprising:determining, at a fourth protocol layer in a second interface oriented to another network function, whether the protection should be performed or not on a downlink packet, based on at least one of: identification information of the downlink packet or an indication on whether the protection should be performed or not, wherein the fourth protocol layer is a lower layer of the first protocol layer, and the first packet is comprised in the downlink packet.60.The method according to claim 58 or 59, wherein the first packet is delivered from the fourth protocol layer to the first protocol layer in a case that the protection should be performed, the method further comprising:performing, at the first protocol layer, the protection on the first packet to obtain a processed first packet, and sending the processed first packet to a third protocol layer in a first interface oriented to an intermediate network function between the UE and the network function.61.The method according to claim 60, wherein the protection on the first packet comprises at least one of: ciphering, privacy protection, or integrity protection.62.The method according to claim 60 or 61, wherein the processed first packet is comprised in a data PDU of the first protocol layer, and the data PDU comprises one or more of:a mission session ID identifying a mission session the data PDU belongs to,a data session ID identifying the data session the DP-Sec data PDU belongs to,a CBID identifying a CB the data PDU belongs to,a QoS flow ID identifying the data PDU belongs to,an indication on whether the protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated,a length of the data PDU,a sequence number of the data PDU,a payload of the data PDU, ora reserved field.63.The method according to claim 58 or 59, wherein the first packet is delivered from the fourth protocol layer to a third protocol layer in a first interface oriented to an intermediate network function between the UE and the network function, in a case that the protection should not be performed, wherein the third protocol layer is a lower layer of the first protocol layer.64.The method according to any one of claims 60 to 63, further comprising:receiving, at the third protocol layer, a packet to be relayed, wherein the packet to be relayed is the first packet from the fourth protocol layer or the processed first packet from the first protocol layer;encapsulating, at the third protocol layer, the packet to be relayed and an indication on whether the protection is performed or not to obtain a second packet of the third protocol layer for transmission;wherein the indication on whether the protection is performed or not has a first value indicating the protection is performed in a case that the packet to be relayed is the processed first packet from the first protocol layer, or has a second value indicating the protection is not performed in a case that the packet to be relayed is the first packet from the fourth protocol layer.65.The method according to claim 64, wherein the indication on whether the protection is performed or not is encapsulated in a packet header or a payload of the second packet of the third protocol layer.66.The method according to any one of claims 54 to 65, wherein the fourth protocol layer is a GTP-U layer, a UDP layer, a QUIC layer, or an IP layer.67.The method according to any one of claims 52 to 57 and claims 60 to 65, wherein the third protocol layer is a GTP-U layer, a UDP layer, a QUIC layer, or an IP layer.68.The method according to any of claims 34, 42, 56, and 62, wherein the payload of the data PDU of the first protocol layer is encrypted in a case that the protection is performed.69.The method according to any one of claims 1 to 68, wherein the protection is performed on the first packet by using at least one of: a mission session ID, a data session ID, a CBID, or a QoS ID of the first packet as one or more of: a ciphering material, a privacy protection material, or an integrity protection material.70.The method according to any one of claims 1 to 69, wherein the network function is in a core network.71.The method according to claim 70, wherein the network function comprises a data trustworthy gateway (Data-TW-GW) , or a user plane function (UPF) .72.The method according to any one of claims 11 to 15, claims 52 to 57, and claims 60 to 65, wherein the intermediate network function comprises a radio access network (RAN) node.73.A communication method, comprising:receiving a message, wherein the message is used to configure a first protocol layer in a communication apparatus, the first protocol layer is to support data plane security protection, and a data protocol data unit (PDU) of the first protocol layer comprises one or more of:a mission session identifier (ID) identifying a mission session the data PDU belongs to,a data session ID identifying the data session the DP-Sec data PDU belongs to,a computing block identifier (CBID) identifying a computing block (CB) the data PDU belongs to,a quality of service (QoS) flow ID identifying the data PDU belongs to,an indication on whether the protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated,a length of the data PDU,a sequence number of the data PDU,a payload of the data PDU, ora reserved field; andconfiguring the first protocol layer based on the message.74.A communication method, comprising:obtaining a first message, wherein the first message comprises information for configuring a first protocol layer in a user equipment (UE) , the first protocol layer is to support data plane security protection on a first packet, and the protection is between the UE and a network function; andsending the first message to the UE.75.The method according to claim 74, wherein the network function is in a core network.76.The method according to claim 74 or 75, wherein the first protocol layer is a lower layer of a second protocol layer, wherein the second protocol layer is used to provide a mission service, wherein the mission service is a service for both protocol data unit (PDU) connectivity and data processing and the first protocol layer is to protect at least one of security and privacy of the second protocol layer.77.The method according to claim 76, wherein the second protocol layer is an anything as a service (XaaS) service layer.78.The method according to claim 76 or 77, wherein the second protocol layer is a processing service function (PSF) layer.79.The method according to any one of claims 76 to 78, further comprises:receiving a second message from a further network function, wherein the second message comprises information for configuring the first protocol layer in the UE.80.The method according to claim 79, wherein the information for configuring the first protocol layer in the UE comprises information indicating one or more identifiers (IDs) on which the protection should be performed or not.81.The method according to claim 79 or 80, further comprising:sending assistance information to the further network function, wherein the assistance information comprises the information indicating one or more IDs on which the protection should be performed or not.82.The method according to claim 80 or 81, wherein the information indicating one or more identifiers on which the protection should be performed or not comprises one or more of:a mission session ID identifying a mission session on which the protection should be performed or not,a mission session group ID identifying a mission session group on which the protection should be performed or not,a data session ID identifying a data session on which the protection should be performed or not,a data session group ID identifying a data session group on which the protection should be performed or not,a computing block identifier (CBID) identifying a computing block (CB) on which the protection should be performed or not,a CB group ID identifying a CB group on which the protection should be performed or not,a radio bearer ID identifying a radio bearer on which the protection should be performed or not,a radio bearer group ID identifying a radio bearer group on which the protection should be performed or not, a quality of service (QoS) flow ID identifying a QoS flow on which the protection should be performed or not, ora QoS flow group ID identifying a QoS flow group on which the protection should be performed or not.83.The method according to any one of claims 79 to 82, wherein the second message and the first message are to send non-access stratum information between the further network function and the UE, orthe second message is a message on an interface with an application protocol between the further network function and an intermediate network function, and the first message is a radio resource control (RRC) message.84.The method according to claim 83, wherein the intermediate network function is in a radio access network (RAN) , the second protocol layer is in the intermediate network function and above a radio layer in a first interface oriented to the UE, wherein the first interface is a radio interface.85.The method according to claim 84, wherein the radio layer comprises a service data adaptation protocol (SDAP) layer.86.The method according to claim 84 or 85, wherein there is one or more additional layers between the second protocol layer and the radio layer.87.The method according to claim 83, wherein the intermediate network function is in a RAN, the second protocol layer is in the intermediate network function and above a transport network layer (TNL) in a second interface oriented to the network function.88.The method according to claim 87, wherein the TNL layer comprises one or more of: a general packet radio service (GPRS) tunnelling protocol for user plane (GTP-U) layer, a user datagram protocol (UDP) layer, a quick UDP internet connections (QUIC) layer, or an internet protocol (IP) layer.89.The method according to claim 87 or 88, wherein there is one or more additional layers between the second protocol layer and the TNL layer.90.The method according to claim 86 or 89, wherein the one or more additional layers comprise one or more of: a protocol data unit (PDU) layer, an IP layer, a UDP layer, a transmission control protocol (TCP) layer, or a QUIC layer.91.The method according to any one of claims 74 to 90 wherein whether the protection is performed on the first packet is determined based on at least one of:identification information corresponding to the first packet, oran indication on whether the protection is performed or not, wherein the indication on whether the protection is performed or not is comprised in a packet which comprises the first packet, or is not comprised in a packet which comprises the first packet.92.The method according to claim 91, wherein the identification information corresponding to the first packet comprises at least one of:a mission session ID identifying a mission session to which the first packet belongs,a mission session group ID identifying a mission session group to which the first packet belongs,a data session ID identifying a data session to which the first packet belongs,a data session group ID identifying a data session group to which the first packet belongs,a CBID identifying a CB to which the first packet belongs,a CB group ID identifying a CB group to which the first packet belongs,a radio bearer ID identifying a radio bearer to which the first packet belongs,a radio bearer group ID identifying a radio bearer group to which the first packet belongs,a QoS flow ID identifying a QoS flow to which the first packet belongs, ora QoS flow group ID identifying a QoS flow group to which the first packet belongs.93.The method according to any one of claims 74 to 92, further comprising:determining, based on whether an intermediate network function between the user equipment and the network function should not be involved in data processing, whether the protection should be performed.94.The method according to claim 93, wherein whether the protection should be performed is determined for at least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bears, or one or more QoS flows.95.The method according to claim 93 or 94, wherein the determining, based on whether the intermediate network function between the user equipment and the network function should not be involved in data processing, whether the protection should be performed comprises:determining that the protection should be performed in a case that an intermediate network function between the UE and the network function should not be involved in data processing.96.The method according to any one of claims 93 to 95, wherein the determining, based on whether the intermediate network function between the user equipment and the network function should not be involved in data processing, whether the protection should be performed comprises:determining that the protection should not be performed in a case that an intermediate network function between the UE and the network function should be involved in data processing.97.The method according to any one of claims 93 to 96, further comprising:determining, based on at least one of: channel state information or processing payload, whether an intermediate network function between the UE and the network function should be involved in data processing.98.The method according to any one of claims 76 to 97, further comprising:sending or receiving control information which indicates:that the protection should be performed; orthat the protection should not be performed.99.The method according to claim 98, wherein the control information further indicatesat least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bearers, or one or more QoS flows, wherein the protection should be performed on the first packet in a case that the first packet belongs to the one or more mission sessions, the one or more data sessions, the one or more CBs, the one or more radio bearers, or the one or more QoS flows; orat least one of: one or more mission sessions, one or more data sessions, one or more CBs, one or more radio bearers, or one or more QoS flows, wherein the protection should not be performed on the first packet in a case that the first packet belongs to the one or more mission sessions, the one or more data sessions, the one or more CBs, the one or more radio bearers, or the one or more QoS flows.100.The method according to any one of claims 74 to 99, wherein the first packet goes through a second protocol layer for data processing in a case that the protection is not performed, and the second protocol layer is a higher layer of the first protocol layer.101.The method according to any one of claims 74 to 100, wherein the first packet does not go through a second protocol layer for data processing in a case that the protection is performed, and the second protocol layer is a higher layer of the first protocol layer.102.The method according to any one of claims 74 to 101, further comprising:determining, at a third protocol layer in a first interface oriented to the UE, whether the protection is performed or not on the first packet, based on at least one of identification information of the first packet or an indication on whether the protection is performed or not, wherein the third protocol layer is a lower layer of the first protocol layer.103.The method according to any one of claims 74 to 101, further comprising:determining, at a third protocol layer in a first interface oriented to the UE, whether the protection is performed or not on an uplink packet, based on at least one of identification information of the uplink packet or an indication on whether the protection is performed or not, wherein the third protocol layer is a lower layer of the first protocol layer, and the first packet is comprised in the uplink packet.104.The method according to claim 102 or 103, wherein the first packet is delivered from the third protocol layer to a fourth protocol layer in a second interface oriented to the network function in a case that the protection is performed, wherein the fourth protocol layer is a lower layer of the first protocol layer.105.The method according to any one of claims 102 to 104, wherein the first packet is delivered from the third protocol layer to a second protocol layer for data processing in a case that the protection is not performed, the second protocol layer is a higher layer of the first protocol layer, and the method further comprises:performing, at the second protocol layer, data processing on the first packet to obtain a processed first packet containing a processing result of the first packet, and sending the processed first packet to a fourth protocol layer in a second interface oriented to the network function, wherein the fourth protocol layer is a lower layer of the first protocol layer.106.The method according to claim 104 or 105, further comprising:receiving, at the fourth protocol layer, a packet to be relayed, wherein the packet to be relayed is the first packet from the third protocol layer or the processed first packet from the second protocol layer;encapsulating, at the fourth protocol layer, the packet to be relayed and an indication on whether the protection is performed or not to obtain a second packet of the fourth protocol layer for transmission;wherein the indication on whether the protection is performed or not has a first value indicating the protection is performed in a case that the packet to be relayed is the first packet from the third protocol layer, or has a second value indicating the protection is not performed in a case that the packet to be relayed is the processed first packet from the second protocol layer.107.The method according to claim 106, wherein the indication on whether the protection is performed or not is encapsulated in a packet header or a payload of the second packet of the fourth protocol layer.108.The method according to any one of claims 74 to 101, further comprising:determining, at a fourth protocol layer in a second interface oriented to the network function, whether the protection is performed or not on the first packet, based on at least one of: identification information of the first packet or an indication on whether the protection is performed or not, wherein the fourth protocol layer is a lower layer of the first protocol layer.109.The method according to any one of claims 74 to 101, further comprising:determining, at a fourth protocol layer in a second interface oriented to the network function, whether the protection is performed or not on a downlink packet, based on at least one of: identification information of the downlink packet or an indication on whether the protection is performed or not, wherein the fourth protocol layer is a lower layer of the first protocol layer, and the first packet is comprised in the downlink packet.110.The method according to claim 108 or 109, wherein the first packet is delivered from the fourth protocol layer to a third protocol layer in a first interface oriented to the UE in a case that the protection is performed, wherein the third protocol layer is a lower layer of the first protocol layer.111.The method according to any one of claims 108 to 110, wherein the first packet is delivered from the fourth protocol layer to a second protocol layer for data processing in a case that the protection is not performed, the second protocol layer is a higher layer of the first protocol layer, and the method further comprises:performing, at the second protocol layer, data processing on the first packet to obtain a processed first packet containing a processing result of the first packet, and sending the processed first packet to a third protocol layer in a first interface oriented to the UE, wherein the third protocol layer is a lower layer of the first protocol layer.112.The method according to claim 110 or 111, further comprising:receiving, at the third protocol layer, a packet to be relayed, wherein the packet to be relayed is the first packet from the fourth protocol layer or the processed first packet from the second protocol layer;encapsulating, at the third protocol layer, the packet to be relayed and an indication on whether the protection is performed or not to obtain a second packet of the third protocol layer for transmission;wherein the indication on whether the protection is performed or not has a first value indicating the protection is performed in a case that the packet to be relayed is the first packet from the fourth protocol layer, or has a second value indicating the protection is not performed in a case that the packet to be relayed is the processed first packet from the second protocol layer.113.The method according to claim 112, wherein the indication on whether the protection is performed or not is encapsulated in a packet header or a payload of the second packet of the third protocol layer.114.The method according to claim 104 or 110, wherein the first packet is comprised in a data PDU of the first protocol layer, and the data PDU comprises one or more of:a mission session ID identifying a mission session the data PDU belongs to,a data session ID identifying the data session the DP-Sec data PDU belongs to,a CBID identifying a CB the data PDU belongs to,a QoS flow ID identifying the data PDU belongs to,an indication on whether the protection is performed or not on the data PDU, or whether the protection of the data PDU is activated or deactivated,a length of the data PDU,a sequence number of the data PDU,a payload of the data PDU, ora reserved field.115.The method according to claim 114, wherein the payload of the data PDU of the first protocol layer is encrypted in a case that the protection is performed.116.The method according to any one of claims 102 to 107 and claims 110 to 115, wherein the third protocol layer is an SDAP layer.117.The method according to any one of claims 104 to 115, wherein the fourth protocol layer is a GTP-U layer, a UDP layer, an IP layer, or a QUIC layer.118.The method according to any one of claims 74 to 117, wherein the protection is performed on the first packet by using at least one of: a mission session ID, a data session ID, a CBID, or a QoS ID of the first packet as one or more of: a ciphering material, a privacy protection material, or an integrity protection material.119.A communication apparatus, configured to perform the method according to any one of claims 1 to 118.120.The communication apparatus according to claim 119, comprising:a receiving unit, configured to receive a message, wherein the message is used to configure a first protocol layer in the communication apparatus, and the first protocol layer is to support data plane security protection on a first packet, and the protection is between a user equipment (UE) and a network function; anda processing unit, configured to configure the first protocol layer based on the message.121.The communication apparatus according to claim 119, comprising:an obtaining unit, configured to obtain a first message, wherein the first message comprises information for configuring a first protocol layer in a UE, and the first protocol layer is to support data plane security protection on a first packet, and the protection is between the UE and a network function; anda sending unit, configured to send the first message to the UE.122.The communication apparatus according to claim 119, comprising:an interface circuit, configured to receive a message, wherein the message is used to configure a first protocol layer in the communication apparatus, the first protocol layer is to support data plane security protection on a first packet, and the protection is between a UE and a network function; andone or more processors, configured to configure the first protocol layer based on the message.123.The communication apparatus according to claim 119, comprising:one or more processors, configured to obtain a first message, wherein the first message comprises information for configuring a first protocol layer in a UE, the first protocol layer is to support data plane security protection between the UE and a network function; andan interface circuit, configured to send the first message to the UE.124.The communication apparatus according to claim 120 or 122, wherein the communication apparatus is the UE.125.The communication apparatus according to claim 120 or 122, wherein the communication apparatus is the network function.126.A communication system, comprising: the communication apparatus according to claim 124, the communication apparatus according to claim 125 and the communication apparatus according to claim 121 or 123.127.A computer-readable storage medium having instructions stored thereon which, when executed by an apparatus, cause the apparatus to perform the method of any one of claims 1 to 118.128.A computer program product storing instructions which, when executed, cause an apparatus to perform the method of any one of claims 1 to 118.129.A communication apparatus, comprising one or more processors, the one or more processors is configured to execute instructions stored in one or more memories to implement the method of any one of claims 1 to 118.

Citation Information

Patent Citations

  • Interface security protection method and device

    CN114362984A

  • Quantum resistant ledger for secure communications

    US20240048369A1

  • Wireless communications

    WO2017076891A1

  • Communication method, apparatus and system

    WO2021196051A1