Communication method and device
By coordinating the access network equipment and core network equipment, the security protection of the sub-PDU at the MAC layer is activated, which solves the problem of lack of security protection at the MAC layer and improves the security of messages.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-29
- Publication Date
- 2026-04-02
AI Technical Summary
In existing 3GPP technologies, the MAC layer lacks security protection mechanisms, resulting in insufficient message security.
The core network equipment sends activation information to the terminal through the access network equipment to identify and activate the security protection of the MAC layer sub-PDUs. The core network equipment sends the terminal's MAC security policy to the access network equipment to identify the MAC layer sub-PDUs that need security protection.
A flexible security protection mechanism at the MAC layer has been implemented, which improves message security.
Smart Images

Figure CN2024122528_02042026_PF_FP_ABST
Abstract
Description
Communication method and device TECHNICAL FIELD
[0001] The present application relates to the field of communication, and more particularly, to a communication method and device. BACKGROUND
[0002] In the existing 3GPP technology, the encryption and integrity protection related processing is mainly performed in the NAS (Non-Access Stratum) and PDCP (Packet Data Convergence Protocol) layers. However, in the related technology, the MAC (Medium Access Control) layer is not provided with a corresponding security protection mechanism, and therefore, how to provide a corresponding security protection mechanism in the MAC layer to ensure the message security of the MAC layer becomes a problem to be solved.
[0003] SUMMARY
[0004] Embodiments of the present application provide a communication method and device.
[0005] Embodiments of the present application provide a communication method performed by a terminal, comprising:
[0006] receiving activation information from an access network device, wherein the activation information is used by the terminal to determine to activate security protection of at least one sub-PDU (Protocol Data Unit) of the MAC layer.
[0007] Embodiments of the present application provide a communication method performed by an access network device, comprising:
[0008] sending activation information to a terminal, wherein the activation information is used by the terminal to determine to activate security protection of at least one sub-PDU of the MAC layer.
[0009] Embodiments of the present application provide a communication method performed by a core network device, comprising:
[0010] sending a MAC security policy of a terminal to an access network device, wherein the MAC security policy of the terminal is used to determine at least one sub-PDU of the MAC layer that needs security protection.
[0011] Embodiments of the present application provide a terminal, comprising:
[0012] a first communication unit configured to receive activation information from an access network device, wherein the activation information is used by the terminal to determine to activate security protection of at least one sub-PDU of the MAC layer.
[0013] An access network device is provided in an embodiment of the present application, comprising:
[0014] A second communication unit is configured to send activation information to a terminal, wherein the activation information is used by the terminal to determine security protection of at least one sub-PDU of a MAC layer.
[0015] A core network device is provided in an embodiment of the present application, comprising:
[0016] A third communication unit is configured to send a MAC security policy of a terminal to an access network device, wherein the MAC security policy of the terminal is used to determine at least one sub-PDU of a MAC layer that needs security protection.
[0017] By using the above scheme, the access network device sends activation information to the terminal, so that the terminal determines security protection of a sub-PDU of a MAC layer. In this way, security protection mechanism can be flexibly added at the MAC layer, thereby ensuring the message security of the MAC layer. BRIEF DESCRIPTION OF DRAWINGS
[0018] FIG. 1 is a schematic diagram of an application scenario according to an embodiment of the present application.
[0019] FIG. 2 is a schematic flowchart of a communication method according to an embodiment of the present application.
[0020] FIG. 3 is a schematic flowchart of a communication method according to another embodiment of the present application.
[0021] FIG. 4 is a schematic flowchart of a communication method according to yet another embodiment of the present application.
[0022] FIG. 5 is a schematic flowchart of a process in which a core network device provides a MAC security policy of a terminal to an access network device according to an embodiment of the present application.
[0023] FIG. 6 is a schematic flowchart of a process in which an access network device provides a MAC security policy of a terminal to the terminal according to an embodiment of the present application.
[0024] FIG. 7 is a schematic flowchart of a process of configuring a MAC security policy of a UE in an AS SMC process according to an embodiment of the present application.
[0025] FIG. 8 is a schematic flowchart of a process of activating MAC security protection through an RRC connection reconfiguration process according to an embodiment of the present application.
[0026] FIG. 9 is a schematic flowchart of a process of adding activation information at a MAC layer in a switching execution process of an LTM according to an embodiment of the present application.
[0027] FIG. 10 is a schematic block diagram of a terminal according to an embodiment of the present application.
[0028] FIG. 11 is a schematic block diagram of an access network device according to an embodiment of the present application.
[0029] FIG. 12 is a schematic block diagram of a core network device according to an embodiment of the present application. DETAILED DESCRIPTION
[0030] The technical solutions of the embodiments of the present application can be applied to various communication systems, for example, LTE (Long Term Evolution), LTE-A (Long Term Evolution-Advanced), NR (New Radio), evolution of NR, WLAN (Wireless Local Area Network), WiFi (Wireless Fidelity), or other communication systems, etc.
[0031] The embodiments of the present application describe various embodiments in combination with network devices and terminals. The terminals can be mobile or fixed, and can also be referred to as mobile stations, user units, etc. The terminals can be stations in WLAN, and can be smart terminals, wireless modems, notebook computers, tablet computers, etc. In the embodiments of the present application, the terminals can be VR (Virtual Reality) terminals / AR (Augmented Reality) terminals, industrial control terminals, unmanned terminals, remote medical terminals, smart grid terminals, transportation safety terminals, smart city terminals, or wireless terminals of smart homes, etc. As an example but not limitation, in the embodiments of the present application, the terminals can also be wearable devices.
[0032] In the embodiments of the present application, the network devices can be devices for communicating with the terminals. The network devices can be access points in WLAN, can be evolved base stations in LTE, or relay stations, or network devices in vehicle-mounted devices, wearable devices, and NR networks (gNB, the next Generation Node B), or network devices in future evolved PLMN (Public Land Mobile Network), or network devices in non-ground networks, etc. As an example but not limitation, in the embodiments of the present application, the network devices can have mobile characteristics, for example, the network devices can be mobile devices.
[0033] In order to facilitate the understanding of the technical solutions of the embodiments of the present application, the related technologies of the embodiments of the present application are described as follows. The following related technologies can be combined with the technical solutions of the embodiments of the present application in any way, and all of them belong to the protection scope of the embodiments of the present application.
[0034] FIG. 1 illustrates a communication system 100. The communication system includes a network device 110 and a terminal 120. In a possible implementation, the communication system 100 can include a plurality of network devices 110, and each network device 110 can include a plurality of terminals 120 within a coverage range of the network device 110, which are not limited in the embodiments of the present application. In a possible implementation, the communication system 100 can further include a mobility management entity, an access and mobility management function, and other network entities, which are not limited in the embodiments of the present application. The network device can include an access network device and a core network device. That is, the communication system can include a plurality of core networks for communicating with the access network device. The access network device can be a base station of an LTE, LTE-A, or NR system. For example, the communication system shown in FIG. 1 can include network devices and terminals with communication functions, and can further include other devices in the communication system, such as a network controller, a mobility management entity, and other network entities, which are not limited in the embodiments of the present application.
[0035] FIG. 2 is a schematic flowchart of a communication method performed by a terminal according to an embodiment of the present application. The method includes at least part of the following contents.
[0036] S210, receiving activation information from an access network device, wherein the activation information is used by the terminal to determine to activate security protection of at least one subPDU of a MAC layer.
[0037] FIG. 3 is a schematic flowchart of a communication method performed by an access network device according to an embodiment of the present application. The method includes at least part of the following contents.
[0038] S310, sending activation information to a terminal, wherein the activation information is used by the terminal to determine to activate security protection of at least one subPDU of a MAC layer.
[0039] FIG. 4 is a schematic flowchart of a communication method performed by a core network device according to an embodiment of the present application. The method includes at least part of the following contents.
[0040] S410, sending a MAC security policy of a terminal to an access network device, wherein the MAC security policy of the terminal is used to determine at least one subPDU of a MAC layer that needs security protection.
[0041] Here, the subPDU of the MAC layer refers to a MAC subPDU. In the following, the subPDU can be replaced by the MAC subPDU, which is not repeated in the following.
[0042] The core network device can be a control plane network element on the core network side. In some possible examples, the core network device can include at least one of the following: an SMF (Session Management Function), a PCF (Policy Control function), and an AMF (Access and Mobility Management Function).
[0043] In some possible embodiments, the core network device provides the access network device with the MAC security policy of the terminal.
[0044] In an embodiment, the processing of the access network device can include sending a second security policy obtaining request to the core network device, where the second security policy obtaining request carries the identifier of the terminal. The processing of the core network device can include receiving the second security policy obtaining request from the access network device, where the second security policy obtaining request carries the identifier of the terminal.
[0045] Here, before sending the second security policy obtaining request to the core network device, the access network device can perform an access procedure with the terminal. Preferably, the access network device can send the second security policy obtaining request to the core network device after the terminal accesses the network (i.e., the terminal completes the access procedure). Alternatively, the access network device can send the second security policy obtaining request to the core network device during the process in which the terminal accesses the network.
[0046] The second security policy obtaining request can also be referred to as a second security policy request, or a second MAC security policy request, and the like, and here, all possible names thereof are not limited or exhausted.
[0047] In an embodiment, on the side of the core network device, after receiving the second security policy obtaining request, the MAC security policy of the terminal can be generated or obtained.
[0048] The MAC security policy of the terminal can also be referred to as a MAC layer security policy of the terminal; or the MAC security policy of the terminal can also be referred to as a MAC CE security policy of the terminal.
[0049] The MAC security policy of the terminal is used to determine at least one sub-PDU that needs to be secured.
[0050] At the MAC layer, a sub-PDU can be composed of a subheader (or subheader) corresponding to the sub-PDU and a payload (or content or data carried by the sub-PDU) of the sub-PDU. The payload of any one sub-PDU can be any one of the following: a MAC service data unit (SDU) and a MAC control element (CE).
[0051] The at least one sub-PDU that needs security protection can refer to at least one sub-PDU that needs security protection among all sub-PDUs belonging to the terminal.
[0052] The sub-PDU belonging to the terminal can refer to a sub-PDU sent by the terminal and / or a sub-PDU sent to the terminal.
[0053] Any one of the at least one sub-PDU that needs security protection among all sub-PDUs belonging to the terminal can refer to the following: the payload of the sub-PDU sent by the terminal needs security protection, or the payload of the sub-PDU sent by the terminal and the subheader corresponding to the sub-PDU need security protection; and / or, the payload of the sub-PDU sent to the terminal needs security protection, or the payload of the sub-PDU sent to the terminal and the subheader corresponding to the sub-PDU need security protection.
[0054] Since the sub-PDU that needs security protection must include the payload of the sub-PDU that needs security protection, in the following, the sub-PDU that needs security protection at least includes the payload (such as a MAC CE or a MAC SDU) of the sub-PDU that needs security protection, and the security protection of the sub-PDU is activated at least includes the security protection of the payload of the sub-PDU, and the following will not be repeated. The security protection can include integrity protection and / or confidentiality protection. The confidentiality protection can also be referred to as encryption protection, and the confidentiality protection and the encryption protection have the same meaning, and the following will not be repeated.
[0055] The MAC security policy of the terminal can be used to determine at least one of the following: whether there is at least one first sub-PDU that needs integrity protection among all sub-PDUs belonging to the terminal, and whether there is at least one second sub-PDU that needs confidentiality protection among all sub-PDUs belonging to the terminal.
[0056] The first sub-PDU and the second sub-PDU can be the same or different. The at least one first sub-PDU that needs integrity protection and the at least one second sub-PDU that needs confidentiality protection can be completely the same, or completely different, or partially the same.
[0057] The MAC security policy of the terminal comprises at least one of the following: identification information corresponding to at least one first sub-PDU requiring integrity protection, identification information corresponding to at least one second sub-PDU requiring confidentiality protection, a first bitmap used to indicate whether the at least one first sub-PDU requiring integrity protection exists, a second bitmap used to indicate whether the at least one second sub-PDU requiring confidentiality protection exists, and first indication information used to indicate whether the sub-PDUs constituting the MAC PDU require integrity protection and / or confidentiality protection.
[0058] In some possible examples, the MAC security policy of the terminal comprises identification information corresponding to each of the at least one first sub-PDU requiring integrity protection and / or identification information corresponding to each of the at least one second sub-PDU requiring confidentiality protection.
[0059] The identification information comprises at least one of the following: a logical channel identifier (LCID) and a number. The number can be a newly defined parameter capable of uniquely identifying a certain sub-PDU (or the payload of a certain sub-PDU), and the embodiment is not limited in terms of specific form or constituent structure.
[0060] For example, if there is at least one first sub-PDU requiring integrity protection among all the sub-PDUs belonging to the terminal, and all the sub-PDUs belonging to the terminal do not require confidentiality protection, the MAC security policy of the terminal can only comprise identification information corresponding to each of the first sub-PDUs requiring integrity protection. For example, if all the sub-PDUs belonging to the terminal do not require integrity protection, and there is at least one second sub-PDU requiring confidentiality protection among all the sub-PDUs belonging to the terminal, the MAC security policy of the terminal can only comprise identification information corresponding to each of the second sub-PDUs requiring confidentiality protection. For example, if there is at least one first sub-PDU requiring integrity protection among all the sub-PDUs belonging to the terminal, and there is at least one second sub-PDU requiring confidentiality protection, the MAC security policy of the terminal can comprise identification information corresponding to each of the second sub-PDUs requiring confidentiality protection and identification information corresponding to each of the second sub-PDUs requiring confidentiality protection.
[0061] In some possible examples, the MAC security policy of the terminal comprises a first bitmap and / or a second bitmap.
[0062] The first bitmap can include a plurality of bits, a number of bits included in the first bitmap can be equal to a number of all sub-PDUs belonging to the terminal, different bits correspond to different sub-PDUs, and a value of each bit is used to indicate whether the corresponding sub-PDU needs integrity protection. For example, in a case where a value of a bit i in the first bitmap is a first value, the value of the bit i is used to indicate that the sub-PDU corresponding to the bit i is a first sub-PDU which needs integrity protection; in a case where a value of a bit i in the first bitmap is a second value, the value of the bit i is used to indicate that the sub-PDU corresponding to the bit i is a sub-PDU which does not need integrity protection; i is a positive integer. The first value and the second value are different, and specific values of the first value and the second value can be configured according to actual conditions, for example, the first value can be 1 and the second value can be 0, or the first value can be 0 and the second value can be 1, and the embodiment does not limit or exhaust all possible values.
[0063] The second bitmap can include a plurality of bits, a number of bits included in the second bitmap can be equal to a number of all sub-PDUs belonging to the terminal, different bits correspond to different sub-PDUs, and a value of each bit is used to indicate whether the corresponding sub-PDU needs confidentiality protection. For example, in a case where a value of a bit j in the second bitmap is a third value, the value of the bit j is used to indicate that the sub-PDU corresponding to the bit j is a second sub-PDU which needs confidentiality protection; in a case where a value of a bit j in the second bitmap is a fourth value, the value of the bit j is used to indicate that the sub-PDU corresponding to the bit j is a sub-PDU which does not need confidentiality protection; j is a positive integer. The third value and the fourth value are different, and specific values of the third value and the fourth value can be configured according to actual conditions, for example, the third value can be 1 and the fourth value can be 0, or the third value can be 0 and the fourth value can be 1, and the embodiment does not limit or exhaust all possible values.
[0064] Optionally, the MAC security policy of the terminal includes the first bitmap and / or the second bitmap.
[0065] For example, there is at least one first sub-PDU which needs integrity protection in all sub-PDUs belonging to the terminal, and all sub-PDUs belonging to the terminal do not need confidentiality protection. In this case, the MAC security policy of the terminal can include the first bitmap and the second bitmap, each bit in the second bitmap takes the fourth value; or the MAC security policy of the terminal can only include the first bitmap.
[0066] For example, all the sub-PDUs belonging to the terminal do not need integrity protection, and there is at least one second sub-PDU belonging to the terminal that needs confidentiality protection. In this case, the MAC security policy of the terminal includes a first bitmap and a second bitmap, each bit in the first bitmap takes the second value; or the MAC security policy of the terminal can only include the second bitmap.
[0067] For example, there is at least one first sub-PDU among all the sub-PDUs belonging to the terminal that needs integrity protection, and there is at least one second sub-PDU that needs confidentiality protection; the MAC security policy of the terminal can include a first bitmap and a second bitmap.
[0068] In some possible examples, the MAC security policy of the terminal can include a security policy bitmap, which is obtained based on the first bitmap and the second bitmap.
[0069] The manner of obtaining the security policy bitmap based on the first bitmap and the second bitmap can be configured according to actual conditions.
[0070] For example, the security policy bitmap can include a plurality of bit groups, the number of bit groups included in the security policy bitmap can be equal to the number of all sub-PDUs belonging to the terminal, different bit groups correspond to different sub-PDUs, each bit group includes two consecutive bits, and the values of the two bits are respectively used to indicate whether the corresponding sub-PDU needs confidentiality protection and whether it needs integrity protection.
[0071] In this case, the first bitmap and the second bitmap can be fused to obtain the security policy bitmap. For example, the bit in the first bitmap corresponding to the nth sub-PDU is spliced with the bit in the second bitmap corresponding to the nth sub-PDU to obtain two consecutive bits corresponding to the nth sub-PDU, and the two consecutive bits are taken as a bit group corresponding to the nth sub-PDU in the security policy bitmap. The first bit in the bit group corresponding to the nth sub-PDU can be used to represent whether the nth sub-PDU needs confidentiality protection, and the second bit can be used to represent whether the nth sub-PDU needs integrity protection, or vice versa; wherein n is an integer greater than or equal to 1. Here, the manner of fusing the first bitmap and the second bitmap to obtain the security policy bitmap is not limited or exhausted.
[0072] For example, the security policy bitmap can include a plurality of bits, and the number of bits included in the security policy bitmap can be equal to twice the number of all sub-PDUs belonging to the terminal. In this case, the first bitmap and the second bitmap can be spliced in a specified order to obtain the security policy bitmap. The specified order can be that the first bitmap is in front and the second bitmap is behind, or vice versa. For example, the number of all sub-PDUs belonging to the terminal is M (M is an integer greater than or equal to 1), and the security policy bitmap can include 2M bits. The first M bits of the 2M bits can be the first bitmap, and the last M bits can be the second bitmap, or vice versa. The first M bits of the 2M bits can be the second bitmap, and the last M bits can be the first bitmap.
[0073] In some possible examples, the first indication information is included in the MAC security policy of the terminal.
[0074] Optionally, the first indication information can include an indication bit. When the value of the indication bit is a first indication value, the indication bit is used to indicate that the sub-PDUs constituting the MAC PDU need integrity protection and need confidentiality protection. When the value of the indication bit is a second indication value, the indication bit is used to indicate that the sub-PDUs constituting the MAC PDU do not need integrity protection and do not need confidentiality protection.
[0075] The sub-PDUs constituting the MAC PDU can include at least one of the following: all sub-PDUs that need to be assembled into any MAC PDU generated by the terminal, sub-PDUs of a specified type among all sub-PDUs that need to be assembled into any MAC PDU generated by the terminal, all sub-PDUs carried in any MAC PDU received by the terminal, and sub-PDUs of a specified type among all sub-PDUs carried in any MAC PDU received by the terminal.
[0076] The sub-PDUs of the specified type can be configured according to actual conditions, such as sub-PDUs carrying MAC CEs, or sub-PDUs carrying some MAC CEs for transmitting sensitive data, and the like. The specified type of sub-PDU is not limited or exhausted herein.
[0077] Optionally, the first indication information can include a first indication bit and a second indication bit, wherein the first indication bit is used to indicate that the sub-PDUs constituting the MAC PDU need integrity protection when the first indication bit takes a first indication value, and is used to indicate that the sub-PDUs constituting the MAC PDU do not need integrity protection when the first indication bit takes a second indication value; the second indication bit is used to indicate that the sub-PDUs constituting the MAC PDU need confidentiality protection when the second indication bit takes the first indication value, and is used to indicate that the sub-PDUs constituting the MAC PDU do not need confidentiality protection when the second indication bit takes the second indication value. The arrangement order of the first indication bit and the second indication bit is not limited in the embodiment.
[0078] The first indication value and the second indication value are different, and the first indication value and the second indication value can be configured according to actual conditions, for example, the first indication value can be 1, and the second indication value can be 0, or vice versa, and the first indication value and the second indication value are not limited or exhausted herein.
[0079] Optionally, the first indication information can include an indication field, and the content contained in the indication field is used to indicate that the sub-PDUs constituting the MAC PDU need integrity protection and need confidentiality protection when the indication field takes an open indication; and the content contained in the indication field is used to indicate that the sub-PDUs constituting the MAC PDU do not need integrity protection and do not need confidentiality protection when the indication field takes a non-open indication.
[0080] The open indication can be represented in any one of the following ways: enable, open, on, and the like. The non-open indication can be represented in any one of the following ways: disable, close, non-open, and the like.
[0081] Optionally, the first indication information can include a first indication field and a second indication field. The content contained in the first indication field is used to indicate that the sub-PDUs constituting the MAC PDU need integrity protection when the first indication field takes an open indication, and is used to indicate that the sub-PDUs constituting the MAC PDU do not need integrity protection when the first indication field takes a non-open indication; the content contained in the second indication field is used to indicate that the sub-PDUs constituting the MAC PDU need confidentiality protection when the second indication field takes the open indication, and is used to indicate that the sub-PDUs constituting the MAC PDU do not need confidentiality protection when the second indication field takes the non-open indication.
[0082] In an example, the core network device side can generate a MAC security policy of a terminal. The MAC security policy of the terminal is generated based on at least one of the following: the capability of the terminal, the capability of the access network device, the area where the terminal is located, and the subscription information of the terminal.
[0083] The terminal capability can include at least a security capability of the terminal, and the security capability of the terminal can be used to determine a security algorithm supported by the terminal. The terminal capability and the security capability of the terminal can include any content, which is not limited herein. The terminal capability can be reported by the terminal in advance and stored in a core network device. The core network device can obtain the terminal capability by locally searching the terminal capability or by obtaining the terminal capability from a device (such as a UDM (Unified Data Management)) that stores the terminal capability.
[0084] The access network device capability can include at least a security capability of the access network device, and the security capability of the access network device can be used to determine a security algorithm supported by the access network device. The access network device capability and the security capability of the access network device can include any content, which is not limited herein. The core network device can obtain the access network device capability in any manner, which is not limited herein.
[0085] The terminal area can be at least one of a cell where the terminal is located, a tracking area where the terminal is located, or a geographic area where the terminal is located. The cell where the terminal is located can be represented by a cell ID and / or a physical cell ID (PCI). The tracking area where the terminal is located can be represented by a tracking area identity (TAI) and / or a tracking area code (TAC). The geographic area where the terminal is located can be represented by geographic coordinates such as latitude and longitude.
[0086] The terminal area can be obtained in any manner, which is not limited herein.
[0087] The terminal subscription data can be stored locally by the core network device or obtained by the core network device from a device (such as a UDM) that stores the terminal subscription data. The terminal subscription data can include any content, which is not limited herein. For example, the terminal subscription data can include user identity information, subscription service information, and security credentials.
[0088] The manner in which the core network device generates the MAC security policy of the terminal can be configured according to actual conditions or actual requirements. For example, if the core network device determines, based on the capability of the terminal, that the terminal supports high computing capability or security capability, the core network device can determine that all sub-PDUs constituting the MAC PDU need to be integrity protected and / or need to be confidentiality protected, and then generate the MAC security policy of the terminal. For example, if the core network device determines, based on the capability of the terminal, that the terminal supports low computing capability or security capability, determines, based on the capability of the access network device, that the access network device supports high computing capability or security capability, and determines, based on the area in which the terminal is located, that integrity and encryption protection need to be performed, the core network device can determine that a part of the sub-PDUs of the terminal are first sub-PDUs that need to be integrity protected, and a part of the sub-PDUs of the terminal are second sub-PDUs that need to be confidentiality protected, and then generate the MAC security policy of the terminal. For example, if the core network device determines, based on the capability of the terminal, that the terminal supports low computing capability or security capability, determines, based on the capability of the access network device, that the access network device supports high computing capability or security capability, determines, based on the area in which the terminal is located, that integrity protection needs to be performed, and determines, based on the subscription information of the terminal, that the terminal allows security protection of the AS layer to be turned on, the core network device can determine that a part of the sub-PDUs of the terminal are first sub-PDUs that need to be integrity protected, and then generate the MAC security policy of the terminal.
[0089] In addition, the content or parameter used by the core network device to generate the MAC security policy of the terminal can include other content or parameters in addition to at least part of the capability of the terminal, the capability of the access network device, the area in which the terminal is located, and the subscription information of the terminal. For example, when generating the MAC security policy of the terminal, the core network device can also combine at least one of a UE Policy of a PCF (Policy Control Function), privacy of the terminal, user (user) consent, and the like. Accordingly, the manner in which the core network device generates the MAC security policy of the terminal can also be adjusted or increased according to the content or parameter added.
[0090] It should be noted that the above is only an exemplary description of the parameters and generation manner of the MAC security policy of the terminal generated by the core network device. The content or parameter used by the core network device to generate the MAC security policy of the terminal is not limited or exhausted, and the manner in which the core network device generates the MAC security policy of the terminal is not limited, as long as the core network device side can generate the MAC security policy of the terminal based on at least one of the above content or parameter.
[0091] It should also be noted that the timing of the core network device generating the MAC security policy of the terminal is not limited in the embodiment, as long as the core network device generates the MAC security policy of the terminal before sending the MAC security policy of the terminal to the access network device, which is within the protection scope of the embodiment.
[0092] For example, if the core network device has generated the MAC security policy of the terminal before receiving the second security policy acquisition request sent by the access network device, the core network device side can acquire the MAC security policy of the terminal locally. For example, the core network device can configure or generate the MAC security policy of the terminal in the registration process of the terminal.
[0093] For another example, if the core network device has not generated the MAC security policy of the terminal before receiving the second security policy acquisition request sent by the access network device, the core network device side can generate the MAC security policy of the terminal locally after receiving the second security policy acquisition request sent by the access network device.
[0094] In an example, the core network device side can acquire the MAC security policy of the terminal from other information or other device side.
[0095] For example, the core network device can acquire the MAC security policy from the NAS context of the terminal. The NAS context of the terminal can be stored in the core network device or other network device (such as AMF), and accordingly, the core network device can acquire the MAC security policy of the terminal from the NAS context of the terminal stored by itself, or the core network device can acquire the MAC security policy of the terminal from the NAS context of the terminal stored by the AMF.
[0096] In an embodiment, after the core network device side generates or acquires the MAC security policy of the terminal, the core network device side can send the MAC security policy of the terminal to the access network device. After sending the second security policy acquisition request, the access network device can further include receiving the MAC security policy of the terminal from the core network device.
[0097] The MAC security policy of the terminal can be carried by the second security policy acquisition response, for example, the core network device can encapsulate the MAC security policy of the terminal in a container, and then add the container in the second security policy acquisition response.
[0098] Optionally, the second security policy acquisition response can carry the identifier of the terminal in addition to the MAC security policy of the terminal. The second security policy acquisition response can also be referred to as a second security policy response, or a second MAC security policy (Security Policy) response, etc., and here the possible names thereof are not limited or exhausted.
[0099] After the access network device receives the MAC security policy of the terminal, the access network device and the terminal can activate the MAC security protection. Specifically, the processing after the access network device receives the MAC security policy of the terminal can include: activating the MAC security protection of the terminal by using an RRC message.
[0100] Optionally, the core network device can also send second indication information or third indication information to the access network device; specifically, if at least part of the sub-PDUs belonging to the terminal need security protection, the core network device can send second indication information to the access network device to indicate that the MAC security protection of the terminal is required, for example, the second indication information can be “Required”; if all sub-PDUs belonging to the terminal do not need security protection, the core network device can send third indication information to the access network device to indicate that the MAC security protection of the terminal is not required, for example, the third indication information can be “Not need”.
[0101] The second indication information or the third indication information can be sent to the access network device at the same time as the MAC security policy of the terminal. For example, the second indication information (or the third indication information) and the MAC security policy of the terminal can be carried in the second security policy acquisition response, or the second indication information (or the third indication information) can be included in the MAC security policy of the terminal. Alternatively, the core network device can only send the third indication information to the access network device.
[0102] On the side of the access network device, if the second indication information (such as “Required”) is received, the access network device will not reject or change the MAC security policy of the terminal provided by the core network device; but in the case that the access network device cannot activate the MAC security protection of the terminal, the access network device can reject to send the MAC security policy to the terminal, and send the rejection reason to the core network device. The reasons why the access network device cannot activate the MAC security protection of the terminal can be various, such as the access network device cannot activate the MAC security protection of the terminal due to network connection and the like, and the like, which are not limited or enumerated here.
[0103] At the access network device side, if the third indication information (such as "Not need") is received, the access network device can perform transmission of MAC layer messages or information with the terminal according to the relevant protocol (such as TS 38.321). The MAC security policy of the terminal provided by the core network device will not be rejected or changed; but the access network device can reject to send the MAC security policy to the terminal in the case that the access network device cannot activate the MAC security protection of the terminal, and send the rejection reason to the core network device. The reason why the access network device cannot activate the MAC security protection of the terminal can be various, such as the access network device cannot activate the MAC security protection of the terminal due to network connection and the like, and the like, which are not limited or enumerated here.
[0104] Next, taking the terminal as UE and the access network device as gNB as an example, the processing of the core network device providing the MAC security policy of the terminal to the access network device is exemplarily described below with reference to FIG. 5, which specifically includes:
[0105] Step 501: The UE and the gNB perform an access procedure (i.e., the UE accesses the network).
[0106] Step 502: The gNB sends a MAC security policy request message (or can be referred to as a MAC CE security policy request message) (i.e., the second security policy acquisition request in the foregoing embodiment) to the core network device (such as SMF), and the MAC security policy request message includes the UE ID.
[0107] Step 503: The core network device (such as SMF) acquires the MAC security policy of the UE according to the UE ID.
[0108] Step 503 is optional, which can be that the core network device itself has the MAC security policy of the UE, can also be that the core network device acquires the MAC security policy of the UE from the NAS context of the UE, and can also be that the MAC security policy of the UE is configured in the registration procedure.
[0109] It should be pointed out that the MAC security policy of the UE can be generated based at least in part on at least one of the following: the (security) capability of the UE, the (security) capability of the gNB, the network area (i.e., the area where the UE is located), the UE policy of the PCF, the UE privacy, the user consent, and the like.
[0110] Step 504: The core network device (e.g., SMF) sends a MAC security policy response message (or can be referred to as a MAC CE security policy response message) (i.e., the second security policy acquisition response of the foregoing embodiment) to the gNB, which contains the UE ID and a container containing the MAC security policy of the UE.
[0111] That is, the core network device (e.g., SMF) should provide the MAC security policy of the UE to the gNB (or an access network device such as ng-eNB, etc.). The MAC security policy of the UE should indicate whether to activate confidentiality and / or integrity protection for all MAC CEs belonging to the UE.
[0112] Step 505: The gNB and the UE activate the MAC security protection.
[0113] In step 505, the gNB (or an access network device such as ng-eNB, etc.) should activate the confidentiality and / or integrity protection of each sub-PDU (such as a sub-PDU including a MAC CE, a sub-PDU including a MAC SDU, etc.) using RRC signaling according to the received MAC security policy of the UE. If the MAC security policy of the UE is “Required” or “Not need”, the gNB will not Overrule the MAC CE security policy provided by the core network device (e.g., SMF). If the gNB cannot activate the MAC CE confidentiality and / or MAC CE integrity protection when the received MAC security policy of the UE is “Required”, the gNB should exchange MAC CE control information with the UE and indicate the reason for rejection to the SMF. If the received MAC security policy of the UE is “Not need”, the transmission of the MAC layer message is performed as described in TS 38.321.
[0114] In some possible implementation manners, the MAC security policy of the terminal is provided by the access network device for the terminal.
[0115] In an embodiment, the MAC security policy of the terminal is requested by the terminal from the access network device.
[0116] The processing on the terminal side can include: sending a first security policy acquisition request to the access network device, wherein the first security policy acquisition request carries the identity of the terminal. The processing of the access network device can include: receiving the first security policy acquisition request from the terminal, wherein the first security policy acquisition request carries the identity of the terminal.
[0117] The terminal can send the first security policy obtaining request to the access network device in a process of starting to perform an access procedure to access the network, or the terminal can send the first security policy obtaining request to the access network device after completing the access procedure (i.e., has accessed the network).
[0118] The first security policy obtaining request can be carried by any type of uplink access stratum (AS) message between the terminal and the access network device. The embodiment does not limit the specific type of the AS message carrying the first security policy obtaining request.
[0119] The first security policy obtaining request can also be referred to as a first security policy request, or a first MAC security policy (Security Policy) request, and the like. Here, all possible names thereof are not limited or exhausted.
[0120] After the access network device receives the first security policy obtaining request, the MAC security policy of the terminal can be obtained. The MAC security policy of the terminal is described as in the foregoing embodiments, and details are not repeated.
[0121] For example, the access network device obtaining the MAC security policy of the terminal can include: checking whether the MAC security policy of the terminal is locally saved based on the identifier of the terminal; if the MAC security policy of the terminal is saved, directly obtaining the locally saved MAC security policy of the terminal; if the MAC security policy of the terminal is not saved, generating the MAC security policy of the terminal. The MAC security policy of the terminal is obtained based on the identifier of the terminal.
[0122] If the access network device saves the MAC security policy of the terminal, the access network device can have previously generated the MAC security policy of the terminal and locally saved the MAC security policy of the terminal in association with the identifier of the terminal. The timing of the access network device generating the MAC security policy of the terminal is not limited.
[0123] The MAC security policy of the terminal is generated based on at least one of the following: the capability of the terminal, the capability of the access network device, the area where the terminal is located, and the subscription information of the terminal.
[0124] The access network device can obtain the capability of the terminal by locally searching for the capability of the terminal, or by obtaining the capability of the terminal from a device (such as a UDM (Unified Data Management)) that saves the capability of the terminal on the core network side. The specific manner of the access network device obtaining the capability of the terminal is not limited. The capability of the terminal is described as in the foregoing embodiments, and details are not repeated.
[0125] The subscription data of the terminal can be acquired by the access network device from a device on the core network side that stores the subscription data of the terminal, such as a UDM and the like.
[0126] In addition, the access network device generates the content or parameters used by the MAC security policy of the terminal, in addition to at least part of the above-mentioned capabilities of the terminal, the capabilities of the access network device, the area where the terminal is located, and the subscription information of the terminal, can also include other content or parameters, such as the access network device can also acquire and use at least one of the UE Policy of the PCF, the privacy of the terminal, and the user consent from the device processing on the core network side to generate the MAC security policy of the terminal.
[0127] The way in which the access network device generates the MAC security policy of the terminal is similar to the way in which the core network device generates the MAC security policy of the terminal, and will not be described in detail.
[0128] After the access network device acquires the MAC security policy of the terminal, it also includes sending the MAC security policy of the terminal to the terminal. The processing of the terminal can also include receiving the MAC security policy of the terminal from the access network device.
[0129] The MAC security policy of the terminal can be carried by the first security policy acquisition response, for example, the access network device can encapsulate the MAC security policy of the terminal in a container, and then add the container in the first security policy acquisition response.
[0130] Optionally, in addition to carrying the MAC security policy of the terminal, the first security policy acquisition response can also carry the identifier of the terminal. The first security policy acquisition response can also be referred to as a first security policy response, or a first MAC security policy response, and the like, and here it is not limited or exhaustive to all possible names.
[0131] After the terminal receives the MAC security policy of the terminal, the access network device and the terminal can activate the MAC security protection. Specifically, the processing of the access network device after receiving the MAC security policy of the terminal can include activating the MAC security protection of the terminal using an RRC message.
[0132] Next, taking the terminal as UE and the access network device as gNB as an example, the processing of the access network device providing the MAC security policy of the terminal to the terminal will be described in detail with reference to FIG. 6, which includes the following steps.
[0133] Step 601: The UE and the gNB perform an access process (i.e., the UE accesses the network).
[0134] Step 602: The UE sends a MAC security policy request message (or can be referred to as a MAC CE security policy request message) (i.e., the first security policy acquisition request of the foregoing embodiment) to the gNB, the MAC security policy request message including a UE ID.
[0135] Step 603: The gNB acquires the MAC security policy of the UE according to the UE ID. The MAC security policy of the UE can be generated based at least in part on at least one of the following: (security) capability of the UE, (security) capability of the gNB, network area (i.e., area where the UE is located), etc.
[0136] Step 604: The gNB sends a MAC security policy response message (or can be referred to as a MAC CE security policy response message) (i.e., the first security policy acquisition response of the foregoing embodiment) to the UE, the MAC security policy response message containing the UE ID and a container, the container containing the MAC security policy of the UE.
[0137] That is, the gNB directly provides the MAC security policy of the UE to the UE. The MAC security policy of the UE should indicate whether to activate confidentiality and / or integrity protection for all MAC CEs belonging to the UE.
[0138] Step 605: The gNB and the UE activate the MAC security protection.
[0139] In step 605, the gNB (or an access network device such as an ng-eNB, etc.) should activate the confidentiality and / or integrity protection of each sub-PDU (such as a sub-PDU including a MAC CE, a sub-PDU including a MAC SDU, etc.) using RRC signaling according to the MAC security policy of the UE.
[0140] In an embodiment, the access network device provides the MAC security policy of the terminal to the terminal in the AS SMC procedure.
[0141] The processing of the access network device further includes sending the MAC security policy of the terminal to the terminal. The processing of the terminal can further include receiving the MAC security policy of the terminal from the access network device.
[0142] In the embodiment, the MAC security policy of the terminal is carried by a security mode command (SMC) message. The SMC message is an access stratum (AS) SMC message.
[0143] Specifically, the MAC security policy of the terminal can be transmitted in an AS security establishment procedure (or referred to as an AS SMC procedure or an AS SMC process) when the terminal and the access network device establish an RRC connection, and the AS SMC procedure is used for RRC, UP, MAC security algorithm negotiation, and RRC (Radio Resource Control) security activation. In the AS SMC procedure, an AS SMC message sent by the access network device to the terminal carries the MAC security policy of the terminal. It should be pointed out that the AS SMC message can carry, in addition to the MAC security policy of the terminal, RRC, UP (user plane), MAC encryption and integrity algorithms selected by the access network device, and the like, and the entire content that can be carried by the AS SMC message is not limited or enumerated here.
[0144] Optionally, the AS SMC message can be integrity protected using an RRC integrity key (which can be denoted as K RRCint ). That is, the AS SMC message can also carry a first integrity check code. Specifically, the processing of the access network device can include: starting or enabling RRC integrity protection, calculating the first integrity check code based on an RRC integrity algorithm and an RRC integrity key (which can be denoted as K RRCint ), and sending the AS SMC message carrying the MAC security policy of the terminal, the first integrity check code, the integrity protection algorithm, and the encryption algorithm (i.e., the RRC, UP (user plane), and MAC encryption and integrity algorithms selected by the access network device). In addition, the AS SMC message can also carry other content as specified by the relevant protocol, which is not limited by the present embodiment.
[0145] Correspondingly, the processing of the terminal can be: receiving the AS SMC message, calculating the first integrity check code based on the RRC integrity key and the content carried by the AS SMC message other than the first integrity check code; and in the case that the first integrity check code is the same as the first integrity check code, determining that the integrity verification of the AS SMC message is successful, and extracting the MAC security policy of the terminal, the first integrity check code, the integrity protection algorithm, and the encryption algorithm from the AS SMC message.
[0146] In addition, the processing of the terminal can also include: in the case that the integrity verification of the AS SMC message is successful, enabling RRC integrity protection and RRC downlink message decryption (or referred to as RRC downlink decryption).
[0147] The processing of the access network device can also include: after sending the AS SMC message, enabling or starting RRC downlink message encryption (or referred to as RRC downlink encryption).
[0148] Further, the processing of the terminal can further include: sending an AS security mode complete message to the access network device, and starting RRC uplink message encryption (or referred to as RRC uplink encryption). The AS security mode complete message can be based on the RRC integrity algorithm and K RRCint is integrity protected, that is, the AS security mode complete message can carry a second integrity check code. The processing of the access network device can further include: receiving the AS security mode complete message, calculating the second integrity verification code, determining that the integrity check is successful in a case where the second integrity check code and the second integrity verification code are the same, and starting or enabling RRC uplink message decryption (or referred to as RRC uplink decryption). RRCint is integrity protected, that is, the AS security mode complete message can carry a second integrity check code. The processing of the access network device can further include: receiving the AS security mode complete message, calculating the second integrity verification code, determining that the integrity check is successful in a case where the second integrity check code and the second integrity verification code are the same, and starting or enabling RRC uplink message decryption (or referred to as RRC uplink decryption).
[0149] It should be further noted that if the processing of the terminal on the AS SMC message is unsuccessful (such as integrity verification failure), the terminal will reply to the access network device with an unprotected security mode failure message.
[0150] In combination with FIG. 7, taking the terminal as a UE and the access network device as a gNB as an example, the processing of configuring the MAC security policy of the UE in the AS SMC process is exemplarily described:
[0151] Step 701, the gNB enables RRC integrity protection.
[0152] Step 702, the gNB sends an AS SMC to the UE, wherein the AS SMC can carry the MAC security policy of the UE, and in addition, can carry an integrity algorithm, an encryption algorithm, a first integrity check code, and the like, and here, the content that can be carried by the AS SMC is not limited or exhausted.
[0153] Step 703, the gNB enables RRC downlink encryption.
[0154] Step 704, the UE verifies the integrity of the AS SMC, and if the integrity check is successful, the MAC security policy of the UE is acquired, and RRC integrity protection and RRC downlink decryption are enabled.
[0155] Step 705, the UE feeds back an AS security mode complete message to the gNB, and the AS security mode complete message can also be integrity protected by using an RRC integrity key.
[0156] Step 706, the UE enables RRC uplink encryption.
[0157] Step 707, the gNB enables RRC uplink decryption.
[0158] Here, the execution order of step 703 and step 704 is not limited, as long as both are after step 702 and before step 705, which is within the protection scope of the present example. The execution order of step 706 and step 707 is not limited, as long as both are after step 705, which is within the protection scope of the present example.
[0159] In some possible embodiments, the access network device activates the MAC security policy of the terminal through an RRC message.
[0160] The processing of the access network device can include determining the activation information based on the MAC security policy of the terminal, wherein the MAC security policy of the terminal is used to determine at least one sub-PDU that needs security protection.
[0161] After the access network device determines the activation information, the activation information can be sent to the terminal, wherein the activation information is used by the terminal to determine to activate security protection of at least one medium access control sub-PDU. Correspondingly, the terminal receives the activation information from the access network device.
[0162] In an embodiment, the access network device can receive the MAC security policy of the terminal from the core network device. The activation information is used to determine at least one of the following: to activate integrity protection of at least one first sub-PDU, and to activate confidentiality protection of at least one second sub-PDU.
[0163] In some possible examples, the access network device can determine, based on the MAC security policy of the terminal, whether encryption protection and / or integrity protection is activated for each sub-PDU belonging to the terminal, generate an activation indication corresponding to each sub-PDU based on whether encryption protection and / or integrity protection is activated for each sub-PDU belonging to the terminal, and take the activation indications corresponding to all sub-PDUs belonging to the terminal as the activation information, wherein the activation indication corresponding to each sub-PDU of all sub-PDUs belonging to the terminal can be used to indicate whether encryption protection and / or integrity protection is activated for the sub-PDU.
[0164] In this example, the activation indication of each sub-PDU in the activation information is used by the terminal to determine which sub-PDUs are at least one first sub-PDU that needs integrity protection, and / or which sub-PDUs are at least one second sub-PDU that needs confidentiality protection.
[0165] In some possible examples, the MAC security policy of the terminal includes identification information corresponding to each first sub-PDU of at least one first sub-PDU that needs integrity protection, and / or identification information corresponding to each second sub-PDU of at least one second sub-PDU that needs confidentiality protection.
[0166] The access network device determines the activation information based on the MAC security policy of the terminal. The determination can include: adding identification information corresponding to the at least one first sub-PDU in the activation information as an indication of activating integrity protection of the at least one first sub-PDU; and / or adding identification information corresponding to the at least one second sub-PDU in the activation information as an indication of activating confidentiality protection of the at least one second sub-PDU.
[0167] In some possible examples, the MAC security policy of the terminal includes a first bitmap and / or a second bitmap.
[0168] The access network device determines the activation information based on the MAC security policy of the terminal. The determination can include: generating a first activation bitmap based on the first bitmap, and adding the first activation bitmap in the activation information as an indication of activating integrity protection of the at least one first sub-PDU; and / or generating a second activation bitmap based on the second bitmap, and adding the second activation bitmap in the activation information as an indication of activating confidentiality protection of the at least one second sub-PDU.
[0169] The first activation bitmap and the bits and related meanings included in the first bitmap can be the same, and different names are used to refer to them because their functions are different, and no repeated description is given herein. The second activation bitmap and the bits and related meanings included in the second bitmap can be the same, and different names are used to refer to them because their functions are different, and no repeated description is given herein.
[0170] In some possible examples, the MAC security policy of the terminal can include a security policy bitmap.
[0171] The access network device determines the activation information based on the MAC security policy of the terminal. The determination can include: generating an activation indication bitmap based on the security policy bitmap, and adding the activation indication bitmap in the activation information as an indication of activating integrity protection of the at least one first sub-PDU and / or an indication of activating confidentiality protection of the at least one second sub-PDU. In this example, the activation indication bitmap included in the activation information can be the same as the security policy bitmap in terms of bits and related meanings, and no repeated description is given herein. In this example, different bits in the activation indication bitmap can be used to indicate whether a sub-PDU is a first sub-PDU for which integrity protection is activated or a second sub-PDU for which confidentiality protection is activated.
[0172] In this embodiment, the activation information can be carried by an RRC message. For example, the RRC message can be an RRC connection reconfiguration (RRC Connection Reconfiguration) message or other RRC message of the UE, and the type of the RRC message is not limited in this embodiment.
[0173] Next, an example is described below by taking the RRC connection reconfiguration message as an example to carry the activation information:
[0174] The RRC connection reconfiguration message includes an RRC connection reconfiguration IE (Information Element), and the activation information (or activation information for MAC security) can be added in the RRC connection reconfiguration IE.
[0175] Further, for example, the activation information includes an activation indication indicating whether each MAC CE activates encryption protection and / or integrity protection, and the RRC message syntax specified by ASN.1 can be used to carry the activation indication corresponding to each MAC CE, for example, RRC message>DL-DCCH-Message>rrcReconfiguration>MACCEConfig>{cipheringDisabled, integrityProtection}. That is, the RRC message includes a DL-DCCH-Message, the DL-DCCH-Message includes an rrcReconfiguration, the UL-DCCH-Message includes an rrcReconfiguration, the rrcReconfiguration includes a MACCEConfig, and the MACCEConfig specifically includes the activation indication corresponding to the MAC CE, and the activation indication is “cipheringDisabled, integrityProtection”. The field of “{cipheringDisabled, integrityProtection}” can have the following format:
[0176] “cipheringDisabled ENUMERATED{true}OPTIONAL,
[0177] integrityProtection ENUMERATED{enabled}OPTIONAL”
[0178] If a MAC CE configuration contains "cipheringDisabled", ciphering of this MAC CE is prohibited regardless of which ciphering algorithm is configured for the MAC CE. If a MAC CE configuration contains "integrityProtection", it is used to indicate whether integrity protection is configured for this MAC CE.
[0179] In some possible examples, the first indication information is included in the MAC security policy of the terminal. The access network device determines the activation information based on the MAC security policy of the terminal. The activation information can be the first indication information.
[0180] In an embodiment, the access network device provides the terminal with the MAC security policy of the terminal. The activation information is used to indicate that the security protection of at least one sub-PDU is activated based on the MAC security policy of the terminal. The MAC security policy of the terminal is used to determine the at least one sub-PDU (i.e., at least one sub-PDU of the MAC layer) that needs security protection.
[0181] In this embodiment, the activation information can only include one field, which can simply indicate opening or activation. Correspondingly, since the terminal has saved its own MAC security policy, the terminal only needs to determine whether each sub-PDU belonging to the terminal activates encryption protection and / or integrity protection based on the saved MAC security policy when receiving the activation information indicating opening or activation, and then activate the encryption protection of the second sub-PDU that needs encryption protection and / or activate the integrity protection of the first sub-PDU that needs integrity protection.
[0182] In this embodiment, the activation information can also be carried by an RRC message. For example, the RRC message can be an RRC connection reconfiguration message or other RRC message of the UE, and the type of the RRC message is not limited in this embodiment.
[0183] With reference to FIG. 8, the processing of activating the MAC security protection through the RRC connection reconfiguration process is exemplarily explained by taking the terminal as the UE and the access network device as the gNB, specifically including the following steps.
[0184] In step 811, the UE and the gNB activate RRC security. That is, the RRC connection reconfiguration process is performed only after the RRC security is activated.
[0185] Step 812: The gNB shall send a RRC connection reconfiguration message to the UE for activating the MAC CE security, wherein the RRC connection reconfiguration message contains the activation information determined according to the MAC security policy of the UE, the activation information includes an indication of activating the integrity protection of at least one first MAC CE and / or an indication of activating the confidentiality protection of at least one second MAC CE.
[0186] Herein, the at least one first MAC CE can include at least one first MAC CE for uplink and / or at least one first MAC CE; and the at least one second MAC CE can include at least one second MAC CE for uplink and / or at least one second MAC CE.
[0187] Step 813: After the gNB sends the activation information through the RRC connection reconfiguration message, the gNB starts the integrity verification of the at least one first MAC CE for uplink and the integrity protection of the at least one first MAC CE for downlink; and / or starts the deciphering of the at least one second MAC CE for uplink and the encryption protection of the at least one second MAC CE for downlink.
[0188] Herein, if the gNB does not have the MAC integrity key K MACint , the gNB shall generate K MACint for the integrity protection and the integrity verification, and / or, if the gNB does not have the MAC confidentiality key K MACenc , the gNB shall generate K MACenc for the encryption protection and the deciphering. The way of deriving K MACint and K MACin by the gNB is not limited in the present example.
[0189] Step 821: The UE verifies the RRC connection reconfiguration message, if the verification is successful, the UE activates the MAC CE integrity protection according to the activation information in the RRC connection reconfiguration message, and then starts the integrity protection of the at least one first MAC CE for uplink and the integrity verification of the at least one first MAC CE for downlink; and / or the UE activates the MAC CE encryption according to the activation information in the RRC connection reconfiguration message, and then starts the encryption protection of the at least one second MAC CE for uplink and the deciphering of the at least one second MAC CE for downlink.
[0190] Herein, if the UE does not have K MACint , the UE shall generate K MACint for the integrity protection and the integrity verification, and / or, if the UE does not have K MACenc , the UE shall generate K MACenc for the encryption protection and the deciphering. The way of deriving K MACint and K MACinIn this example, no limitation is made.
[0191] Step 822: The UE sends an RRC connection reconfiguration complete message to the gNB.
[0192] In some possible implementation, the activation information is carried by a third sub-PDU, wherein the activation information is used to indicate that the integrity protection and / or the confidentiality protection of the third sub-PDU is activated.
[0193] This embodiment is particularly suitable for the case where the number of sub-PDUs that need security protection is small.
[0194] The third sub-PDU can refer to a sub-PDU carrying a specified type of payload, and / or a sub-PDU carrying sensitive data in the payload.
[0195] The specified type of payload can be a MAC CE; the sensitive data can refer to at least one of the following configured according to actual conditions: an identifier of a terminal, a next hop chaining counter (NCC), a timing advance (TA) amount, etc.
[0196] Optionally, the activation information carried by the third sub-PDU can include an activation indication bit, wherein when the activation indication bit takes a third indication value, it is used to indicate that the third sub-PDU activates the integrity protection and needs the confidentiality protection; and when the activation indication bit takes a fourth indication value, it is used to indicate that the third sub-PDU does not activate the integrity protection and needs the confidentiality protection.
[0197] Optionally, the activation information carried by the third sub-PDU can include a first activation indication bit and a second activation indication bit, wherein when the first activation indication bit takes a third indication value, it is used to indicate that the third sub-PDU activates the integrity protection; and when the first activation indication bit takes a fourth indication value, it is used to indicate that the third sub-PDU does not activate the integrity protection; and when the second activation indication bit takes the third indication value, it is used to indicate that the third sub-PDU activates the confidentiality protection; and when the second activation indication bit takes the fourth indication value, it is used to indicate that the third sub-PDU does not activate the confidentiality protection. The arrangement order of the first activation indication bit and the second activation indication bit is not limited in this embodiment.
[0198] The third indication value is different from the fourth indication value, and both the third indication value and the fourth indication value can be configured according to actual conditions, such as the third indication value can be 1 and the fourth indication value can be 0, or vice versa. Here, the third indication value and the fourth indication value are not limited or exhausted.
[0199] The activation information can be carried by a subheader corresponding to the third sub-PDU, or the activation information can be carried by the payload of the third sub-PDU.
[0200] Preferably, the activation information can be carried by the subheader corresponding to the third subPDU. For example, the indication field for carrying the activation information in the subheader corresponding to the third subPDU can be R (Reserved bit). It should be pointed out that this is only an example and the indication field in the subheader corresponding to the third subPDU for carrying the activation information is not limited or exhaustive.
[0201] For example, the load of the third subPDU is a MAC CE carrying a cell handover command message, and the cell handover command message contains sensitive data NCC, so the MAC CE (or the third subPDU) needs to activate security protection. In this case, the activation information can be carried in the subheader corresponding to the third subPDU, and the activation information is only used to indicate whether the integrity protection and / or confidentiality protection is activated.
[0202] For another example, after receiving the third subPDU, the terminal can determine whether the integrity protection and / or encryption protection of the third subPDU is activated or determine to activate the integrity protection and / or encryption protection of the third subPDU based on the activation information carried in the subheader corresponding to the third subPDU. Further, in the case of activating the integrity protection of the third subPDU, the terminal can verify the integrity of the third subPDU by using the MAC integrity key; in the case of activating the encryption protection and integrity protection of the third subPDU, the terminal can first decrypt the data carried by the load of the subPDU by using the MAC confidentiality key, and then verify the integrity of the third subPDU by using the MAC integrity key.
[0203] In combination with FIG. 9, the processing of adding activation information at the MAC layer in the handover execution process of LTM (L1 / L2-Triggered Mobility) is exemplarily illustrated by taking the terminal as UE and the access network device as gNB, and specifically includes:
[0204] Step 901: The UE reports an L1 (Layer 1) measurement report to the gNB; the gNB can be a source gNB of the UE.
[0205] Step 902: The gNB sends a MAC CE (or the gNB sends a subPDU in which the MAC CE is located) to the UE, the MAC CE carries a cell handover command, and the subheader corresponding to the MAC CE carries activation information. The subheader corresponding to the MAC CE and the subheader corresponding to the subPDU where the MAC CE is located have the same meaning and are not repeated.
[0206] Step 903: The UE activates the integrity protection and / or the confidentiality protection of the MAC CE (or the sub-PDU in which the MAC CE is located) based on the activation information. The UE can also perform a process of using the configuration of the target gNB separate from (or disconnected from) the source gNB, which is not limited here.
[0207] By adopting the above scheme, the MAC key can be generated by the device in the communication network, so that the MAC layer message received or sent by the device can be securely protected or verified by the MAC key, thereby making up for the lack of MAC layer security mechanism and ensuring the security of the MAC layer transmission message. Further, the above scheme can enhance the existing AS security mode negotiation, and the MAC security algorithm negotiation can be implemented in the device in the communication network, and the lack of MAC layer security negotiation mechanism is also made up.
[0208] In combination with the related art, there are many MAC CEs threatened in the 6G era, and the existing 3GPP encryption and integrity protection is at the NAS layer and the PDCP layer, which cannot provide security protection for the MAC layer. In addition, considering that not all MAC CEs need security protection in the 6G era, a flexible on-demand MAC CE protection mechanism needs to be designed. Based on this, the above scheme provided by the present application can send activation information for the terminal by the access network device, so that the terminal determines to activate the security protection of the sub-PDU of the MAC layer. In this way, the security protection mechanism can be flexibly added at the MAC layer, thereby ensuring the message security of the MAC layer.
[0209] FIG. 10 is a schematic diagram of the composition structure of a terminal according to an embodiment of the present application, which includes:
[0210] The first communication unit 1001 is configured to receive activation information from an access network device, wherein the activation information is used by the terminal to determine to activate the security protection of at least one sub-PDU of the MAC layer.
[0211] The activation information is used to determine at least one of the following: to activate the integrity protection of at least one first sub-PDU, and to activate the confidentiality protection of at least one second sub-PDU.
[0212] The activation information is used to indicate to activate the security protection of at least one sub-PDU based on the MAC security policy of the terminal, wherein the MAC security policy of the terminal is used to determine at least one sub-PDU that needs security protection.
[0213] The MAC security policy of the terminal comprises at least one of the following: identification information corresponding to at least one first sub-PDU requiring integrity protection, identification information corresponding to at least one second sub-PDU requiring confidentiality protection, a first bitmap indicating whether the at least one first sub-PDU requiring integrity protection exists, a second bitmap indicating whether the at least one second sub-PDU requiring confidentiality protection exists, and first indication information indicating whether the sub-PDU constituting the MAC PDU requires integrity protection and / or confidentiality protection.
[0214] The identification information comprises at least one of the following: a logical channel identifier (LCID) and a number.
[0215] The first communication unit is configured to receive the MAC security policy of the terminal from the access network device.
[0216] The first communication unit is configured to send a first security policy acquisition request to the access network device, wherein the first security policy acquisition request carries the identifier of the terminal.
[0217] The MAC security policy of the terminal is carried by a security mode command (SMC) message.
[0218] The activation information is carried by a radio resource control (RRC) message.
[0219] The activation information is carried by a third sub-PDU, wherein the activation information is used to indicate that the integrity protection and / or the confidentiality protection of the third sub-PDU is activated.
[0220] FIG. 11 is a schematic diagram of the composition structure of an access network device according to an embodiment of the present application, comprising:
[0221] The second communication unit 1101 is configured to send activation information to the terminal, wherein the activation information is used by the terminal to determine the security protection of at least one sub-PDU of the MAC layer.
[0222] As shown in FIG. 11, the access network device further comprises a second processing unit 1102 configured to determine the activation information based on the MAC security policy of the terminal, wherein the MAC security policy of the terminal is used to determine at least one sub-PDU requiring security protection.
[0223] The MAC security policy of the terminal comprises at least one of the following: identification information corresponding to at least one first sub-PDU requiring integrity protection, identification information corresponding to at least one second sub-PDU requiring confidentiality protection, a first bitmap indicating whether the at least one first sub-PDU requiring integrity protection exists, a second bitmap indicating whether the at least one second sub-PDU requiring confidentiality protection exists, and first indication information indicating whether the sub-PDU constituting the MAC PDU requires integrity protection and / or confidentiality protection.
[0224] The identification information comprises at least one of the following: a logical channel identifier (LCID) and a number.
[0225] The second communication unit is configured to receive the MAC security policy of the terminal from a core network device.
[0226] The second communication unit is configured to send a second security policy acquisition request to the core network device, wherein the second security policy acquisition request carries the identifier of the terminal.
[0227] The second communication unit is configured to send the MAC security policy of the terminal to the terminal.
[0228] The second communication unit is configured to receive a first security policy acquisition request from the terminal, wherein the first security policy acquisition request carries the identifier of the terminal.
[0229] The MAC security policy of the terminal is carried by a security mode command (SMC) message.
[0230] The MAC security policy of the terminal is generated based on at least one of the following: the capability of the terminal, the capability of the access network device, the area where the terminal is located, and the subscription information of the terminal.
[0231] The activation information is used to determine at least one of the following: activation of integrity protection of at least one first sub-PDU and activation of confidentiality protection of at least one second sub-PDU.
[0232] The activation information is used to indicate activation of security protection of at least one sub-PDU based on the MAC security policy of the terminal.
[0233] The activation information is carried by an RRC message.
[0234] The activation information is carried by a third sub-PDU, wherein the activation information is used to indicate activation of integrity protection and / or confidentiality protection of the third sub-PDU.
[0235] Fig. 12 is a schematic diagram of a constituent structure of a core network device according to an embodiment of the present application, comprising:
[0236] The third communication unit 1201 is configured to send a MAC security policy of the terminal to the access network device, wherein the MAC security policy of the terminal is used to determine at least one sub-PDU of the MAC layer that needs security protection.
[0237] The MAC security policy of the terminal comprises at least one of the following: identification information corresponding to at least one first sub-PDU that needs integrity protection, identification information corresponding to at least one second sub-PDU that needs confidentiality protection, a first bitmap used to indicate whether the at least one first sub-PDU that needs integrity protection exists, a second bitmap used to indicate whether the at least one second sub-PDU that needs confidentiality protection exists, and first indication information used to indicate whether the sub-PDU constituting the MAC PDU needs integrity protection and / or needs confidentiality protection.
[0238] The identification information comprises at least one of the following: a logical channel identifier (LCID) and a number.
[0239] The MAC security policy of the terminal is generated based on at least one of the following: a capability of the terminal, a capability of the access network device, a region where the terminal is located, and subscription information of the terminal.
[0240] The third communication unit is configured to receive a second security policy acquisition request from the access network device, wherein the second security policy acquisition request carries an identifier of the terminal.
[0241] The device according to the embodiments of the present application can realize the corresponding functions of each device in the communication method embodiments described above. The processes, functions, implementation manners and advantages of each module (sub-module, unit or component, etc.) in the device can be referred to the corresponding description in the method embodiments, which will not be described here. It should be noted that the functions described with respect to each module (sub-module, unit or component, etc.) in the device can be realized by different modules (sub-modules, units or components, etc.), or by the same module (sub-module, unit or component, etc.).
[0242] It should be understood that the magnitude of the serial number of each process in various embodiments of the present application does not mean the order of execution, the execution order of each process should be determined by its function and inherent logic. Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiment, which will not be repeated here. The above is only a specific embodiment of the present application, and the protection scope of the present application is not limited to this. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A communication method performed by a terminal, comprising: receiving activation information from an access network device, wherein the activation information is used by the terminal to determine to activate security protection of at least one sub-protocol data unit (PDU) of a medium access control (MAC) layer.
2. The method of claim 1, wherein, The activation information is used to determine at least one of: to activate integrity protection of at least one first sub-PDU, to activate confidentiality protection of at least one second sub-PDU.
3. The method of claim 1, wherein, The activation information is used to indicate to activate security protection of at least one sub-PDU based on a MAC security policy of the terminal, wherein the MAC security policy of the terminal is used to determine at least one sub-PDU that needs security protection.
4. The method of claim 3, wherein, The MAC security policy of the terminal comprises at least one of: identification information corresponding to the at least one first sub-PDU that needs integrity protection, identification information corresponding to the at least one second sub-PDU that needs confidentiality protection, a first bitmap used to indicate whether the at least one first sub-PDU that needs integrity protection exists, a second bitmap used to indicate whether the at least one second sub-PDU that needs confidentiality protection exists, and first indication information used to indicate whether a sub-PDU constituting a MAC PDU needs integrity protection and / or needs confidentiality protection.
5. The method of claim 4, wherein, The identification information comprises at least one of: a logical channel identifier (LCID), and a number. 6.The method of any one of claims 3-5, further comprising: receiving a MAC security policy of the terminal from the access network device. 7.The method of claim 6, further comprising: sending a first security policy acquisition request to the access network device, wherein the first security policy acquisition request carries an identity of the terminal.
8. The method of claim 6, wherein, The MAC security policy of the terminal is carried by a security mode command (SMC) message.
9. The method of any one of claims 1-8, wherein, The activation information is carried by a radio resource control (RRC) message.
10. The method of claim 1, wherein, The activation information is carried by a third sub-PDU, wherein the activation information is used to indicate to activate integrity protection and / or confidentiality protection of the third sub-PDU. 11.A communication method performed by an access network device, comprising: sending activation information to a terminal, wherein the activation information is used by the terminal to determine to activate security protection of at least one sub-protocol data unit (PDU) of a medium access control (MAC) layer. 12.The method of claim 11, further comprising: determining the activation information based on a MAC security policy of the terminal, wherein the MAC security policy of the terminal is used to determine at least one sub-PDU that needs security protection.
13. The method of claim 12, wherein, The MAC security policy of the terminal comprises at least one of the following: identification information corresponding to at least one first sub-PDU requiring integrity protection, identification information corresponding to at least one second sub-PDU requiring confidentiality protection, a first bitmap indicating whether the at least one first sub-PDU requiring integrity protection exists, a second bitmap indicating whether the at least one second sub-PDU requiring confidentiality protection exists, and first indication information indicating whether the sub-PDUs constituting a MAC protocol data unit (PDU) require integrity protection and / or confidentiality protection.
14. The method of claim 13, wherein, The identification information comprises at least one of the following: a logical channel identifier (LCID) and a number.
15. The method of any one of claims 11-14, further comprising: receiving, from a core network device, a MAC security policy of the terminal.
16. The method of claim 15, further comprising: sending, to the core network device, a second security policy acquisition request, wherein the second security policy acquisition request carries an identifier of the terminal.
17. The method of any one of claims 11-14, further comprising: sending, to the terminal, a MAC security policy of the terminal.
18. The method of claim 17, further comprising: receiving, from the terminal, a first security policy acquisition request, wherein the first security policy acquisition request carries an identifier of the terminal.
19. The method of claim 17, wherein, The MAC security policy of the terminal is carried by a security mode command (SMC) message.
20. The method of any one of claims 17-19, wherein, The MAC security policy of the terminal is generated based on at least one of the following: a capability of the terminal, a capability of the access network device, a region where the terminal is located, and subscription information of the terminal.
21. The method of any one of claims 11-20, wherein, The activation information is used to determine at least one of the following: activation of integrity protection of at least one first sub-PDU, and activation of confidentiality protection of at least one second sub-PDU.
22. The method of any one of claims 11-14, 17-20, wherein, The activation information is used to indicate activation of security protection of at least one sub-PDU based on the MAC security policy of the terminal.
23. The method of any one of claims 11-22, wherein, The activation information is carried by an RRC message.
24. The method of any one of claims 11-20, wherein, The activation information is carried by a third sub-PDU, and the activation information is used to indicate activation of integrity protection and / or confidentiality protection of the third sub-PDU.
25. A communication method performed by a core network device, comprising: sending, to an access network device, a MAC security policy of a terminal, wherein the MAC security policy of the terminal is used to determine at least one sub-protocol data unit (PDU) of a media access control (MAC) layer requiring security protection.
26. The method of claim 25, wherein, The MAC security policy of the terminal comprises at least one of the following: identification information corresponding to at least one first sub-PDU requiring integrity protection, identification information corresponding to at least one second sub-PDU requiring confidentiality protection, a first bitmap indicating whether the at least one first sub-PDU requiring integrity protection exists, a second bitmap indicating whether the at least one second sub-PDU requiring confidentiality protection exists, and first indication information, wherein the first indication information is used to indicate whether the sub-PDU constituting a MAC protocol data unit (PDU) requires integrity protection and / or confidentiality protection.
27. The method of claim 26, wherein, The identification information comprises at least one of the following: a logical channel identifier (LCID) and a number.
28. The method of any one of claims 25-27, wherein, The MAC security policy of the terminal is generated based on at least one of the following: a capability of the terminal, a capability of the access network device, a region where the terminal is located, and subscription information of the terminal.
29. The method of any one of claims 25-28, further comprising: receiving a second security policy acquisition request from the access network device, wherein the second security policy acquisition request carries an identifier of the terminal.
30. A terminal, comprising: a first communication unit configured to receive activation information from an access network device, wherein the activation information is used by the terminal to determine to activate security protection of at least one sub-protocol data unit (PDU) of a medium access control (MAC) layer.
31. An access network device, comprising: a second communication unit configured to send activation information to a terminal, wherein the activation information is used by the terminal to determine to activate security protection of at least one sub-protocol data unit (PDU) of a medium access control (MAC) layer.
32. A core network device, comprising: a third communication unit configured to send a MAC security policy of a terminal to an access network device, wherein the MAC security policy of the terminal is used to determine at least one sub-protocol data unit (PDU) of a medium access control (MAC) layer requiring security protection.
Citation Information
Patent Citations
Communication method and device
CN115696319A
Data transmission method and terminal equipment
CN116210322A
Message transmission method, device and equipment
CN118368616A
Methods, infrastructure equipment and communications devices
US20240305994A1