Information transmission method and apparatus, and related device
By receiving and processing the indication information from network nodes, generating or invalidating security parameters, and negotiating user plane security functions between the UE and UPF, the gap in the negotiation mechanism in the 6G user plane security scheme is filled, and flexible coordination of security processing is achieved.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-18
- Publication Date
- 2026-04-02
AI Technical Summary
In the 6G user plane security scheme, how to negotiate the security design between user equipment (UE) and user plane function (UPF), especially the negotiation mechanism when enabling or disabling user plane security functions, is not clear.
An information transmission method is provided, which generates or invalidates security parameters related to core network user plane functions by receiving and processing indication information sent by network nodes, and starts or stops security processing related to access network nodes, so as to negotiate user plane security functions between UE and UPF.
It enables negotiation of user plane security functions between the UE and core network functions, ensuring flexible activation or deactivation of security processing, and coordinating security collaborative processing between the terminal and access network nodes.
Smart Images

Figure CN2025122055_02042026_PF_FP_ABST
Abstract
Description
Information transmission method, apparatus and related device
[0001] Cross-reference to Related Applications
[0002] This application claims priority to Chinese Patent Application No. 202411344784.X, filed on September 25, 2024, the contents of which are incorporated herein by reference in its entirety. TECHNICAL FIELD
[0003] The present application belongs to the field of communication technology, and specifically relates to an information transmission method, apparatus and related device. BACKGROUND
[0004] In related technologies, in a Protocol Data Unit (PDU) session creation process, a Session Management Function (SMF) sends a user plane security policy (UP Security Policy) to a 5th Generation (5G) base station (the next generation Node B, gNB), the gNB decides whether to enable user plane security between a User Equipment (UE) and the gNB based on the policy, and if so, sends an enabling indication to the UE. In a 6th Generation (6G) user plane security scheme, while supporting UE-gNB inter-security design, UE-User Plane Function (UPF) inter-security design is also supported, and how to negotiate user plane security functions between the UE and the UPF is a technical problem to be solved. SUMMARY
[0005] Embodiments of the present application provide an information transmission method, apparatus and related device, which can solve the problem of how to negotiate user plane security functions between the UE and the UPF.
[0006] In a first aspect, an information transmission method is provided, executed by a terminal, and the method comprises:
[0007] receiving first indication information sent by a first network node;
[0008] performing at least one of a first operation and a second operation according to the first indication information;
[0009] The first operation comprises any one of the following:
[0010] generating a first security parameter;
[0011] invalidating the first security parameter;
[0012] generating the first security parameter and invalidating the second security parameter;
[0013] invalidating the first security parameter and generating the second security parameter;
[0014] The second operation includes any one of the following:
[0015] performing first security processing on the user plane data based on the first security parameter;
[0016] performing first security processing on the user plane data based on the first security parameter, and stopping second security processing on the user plane data based on the second security parameter;
[0017] performing first security processing on the user plane data based on the first security parameter, and performing third security processing on the user plane data based on the second security parameter;
[0018] stopping first security processing on the user plane data based on the first security parameter;
[0019] stopping first security processing on the user plane data based on the first security parameter, and performing second security processing on the user plane data based on the second security parameter;
[0020] stopping first security processing on the user plane data based on the first security parameter, and stopping third security processing on the user plane data based on the second security parameter;
[0021] The first security parameter is related to a core network user plane function;
[0022] The second security parameter is related to an access network node;
[0023] The first security processing includes at least one of confidentiality processing and integrity processing;
[0024] The second security processing includes at least one of confidentiality processing and integrity processing;
[0025] The third security processing includes at least one of integrity processing and confidentiality processing.
[0026] In a second aspect, a method for information transmission is provided, executed by a first network node, and the method includes:
[0027] performing a third operation, the third operation including at least one of the following:
[0028] sending first information to a core network user plane function;
[0029] sending first indication information to a terminal;
[0030] The first indication information is related to at least one of the following: the first security parameter, the second security parameter, user plane data, first security processing, second security processing, and third security processing.
[0031] The first information includes fourth indication information related to first security processing of user plane data.
[0032] The first security parameter is related to a core network user plane function.
[0033] The second security parameter is related to an access network node.
[0034] The first security processing includes at least one of confidentiality processing and integrity processing, and the first security processing is related to a core network user plane function.
[0035] The second security processing includes at least one of confidentiality processing and integrity processing, and the second security processing is related to an access network node.
[0036] The third security processing includes at least one of integrity processing and confidentiality processing, and the third security processing is related to an access network node.
[0037] In a third aspect, an information transmission apparatus is provided, comprising:
[0038] A first receiving module configured to receive first indication information sent by a first network node.
[0039] A processing module configured to perform at least one of a first operation and a second operation according to the first indication information.
[0040] The first operation includes any one of the following:
[0041] Generating a first security parameter.
[0042] Invalidating a first security parameter.
[0043] Generating a first security parameter and invalidating a second security parameter.
[0044] Invalidating a first security parameter and generating a second security parameter.
[0045] The second operation includes any one of the following:
[0046] Performing first security processing on user plane data based on a first security parameter.
[0047] Performing first security processing on user plane data based on a first security parameter, and stopping second security processing on user plane data based on a second security parameter.
[0048] performing first security processing on the user plane data based on the first security parameter, and performing third security processing on the user plane data based on the second security parameter;
[0049] stopping the first security processing on the user plane data based on the first security parameter;
[0050] stopping the first security processing on the user plane data based on the first security parameter, and performing second security processing on the user plane data based on the second security parameter;
[0051] stopping the first security processing on the user plane data based on the first security parameter, and stopping the third security processing on the user plane data based on the second security parameter;
[0052] wherein the first security parameter is related to a core network user plane function;
[0053] wherein the second security parameter is related to an access network node;
[0054] wherein the first security processing comprises at least one of confidentiality processing and integrity processing;
[0055] wherein the second security processing comprises at least one of confidentiality processing and integrity processing;
[0056] wherein the third security processing comprises at least one of integrity processing and confidentiality processing.
[0057] In a fourth aspect, an information transmission apparatus is provided, comprising:
[0058] a transceiver configured to perform a third operation, the third operation comprising at least one of:
[0059] sending first information to a core network user plane function;
[0060] sending first indication information to a terminal;
[0061] wherein the first indication information is related to at least one of: the first security parameter, the second security parameter, the user plane data, the first security processing, the second security processing, and the third security processing;
[0062] wherein the first information comprises fourth indication information, and the fourth indication information is related to the first security processing on the user plane data;
[0063] wherein the first security parameter is related to a core network user plane function;
[0064] wherein the second security parameter is related to an access network node;
[0065] The first security processing includes at least one of confidentiality processing and integrity processing, and the first security processing is related to a core network user plane function.
[0066] The second security processing includes at least one of confidentiality processing and integrity processing, and the second security processing is related to an access network node.
[0067] The third security processing includes at least one of integrity processing and confidentiality processing, and the third security processing is related to an access network node.
[0068] In a fifth aspect, an information transmission apparatus is provided, which is configured to perform the steps of the method according to the first aspect, or implement the steps of the method according to the second aspect.
[0069] In a sixth aspect, a terminal is provided, which includes a processor and a memory, the memory storing a program or instructions executable on the processor, and the program or instructions, when executed by the processor, implement the steps of the method according to the first aspect.
[0070] In a seventh aspect, a terminal is provided, which includes a processor and a communication interface, wherein the communication interface is configured to receive first indication information sent by a first network node; and the processor is configured to perform at least one of a first operation and a second operation according to the first indication information.
[0071] The first operation includes any one of the following:
[0072] generating a first security parameter;
[0073] invalidating the first security parameter;
[0074] generating the first security parameter and invalidating a second security parameter;
[0075] invalidating the first security parameter and generating the second security parameter;
[0076] The second operation includes any one of the following:
[0077] performing first security processing on user plane data based on a first security parameter;
[0078] performing first security processing on user plane data based on a first security parameter, and stopping second security processing on the user plane data based on a second security parameter;
[0079] performing first security processing on user plane data based on a first security parameter, and performing third security processing on the user plane data based on a second security parameter;
[0080] stopping first security processing on user plane data based on a first security parameter;
[0081] stopping the first security processing on the user plane data based on the first security parameter and performing a second security processing on the user plane data based on a second security parameter;
[0082] stopping the first security processing on the user plane data based on the first security parameter and stopping a third security processing on the user plane data based on the second security parameter;
[0083] wherein the first security parameter is related to a core network user plane function;
[0084] wherein the second security parameter is related to an access network node;
[0085] wherein the first security processing comprises at least one of a confidentiality processing and an integrity processing;
[0086] wherein the second security processing comprises at least one of a confidentiality processing and an integrity processing;
[0087] wherein the third security processing comprises at least one of an integrity processing and a confidentiality processing.
[0088] In an eighth aspect, a network-side device is provided, which comprises a processor and a memory, the memory storing programs or instructions executable on the processor, and the programs or instructions, when executed by the processor, implement the steps of the method according to the second aspect.
[0089] In a ninth aspect, a network-side device is provided, which comprises a processor and a communication interface, wherein the communication interface is configured to perform third operations, and the third operations comprise at least one of:
[0090] sending first information to a core network user plane function;
[0091] sending first indication information to a terminal;
[0092] wherein the first indication information is related to at least one of the first security parameter, the second security parameter, the user plane data, the first security processing, the second security processing and the third security processing;
[0093] wherein the first information comprises fourth indication information, and the fourth indication information is related to the first security processing on the user plane data;
[0094] wherein the first security parameter is related to a core network user plane function;
[0095] wherein the second security parameter is related to an access network node;
[0096] The first security processing includes at least one of confidentiality processing and integrity processing, and the first security processing is related to a core network user plane function.
[0097] The second security processing includes at least one of confidentiality processing and integrity processing, and the second security processing is related to an access network node.
[0098] The third security processing includes at least one of integrity processing and confidentiality processing, and the third security processing is related to an access network node.
[0099] The tenth aspect provides a readable storage medium, the readable storage medium storing a program or instructions, the program or instructions being executed by a processor to implement steps of the method according to the first aspect or implement steps of the method according to the second aspect.
[0100] The eleventh aspect provides a wireless communication system, including a terminal and a network side device, the terminal being configured to implement steps of the method according to the first aspect, and the network side device being configured to implement steps of the method according to the second aspect.
[0101] The twelfth aspect provides a chip, the chip including a processor and a communication interface, the communication interface being coupled to the processor, and the processor being configured to run a program or instructions to implement the method according to the first aspect or implement the method according to the second aspect.
[0102] The thirteenth aspect provides a computer program / program product, the computer program / program product being stored in a storage medium, and the computer program / program product being executed by at least one processor to implement steps of the method according to the first aspect or the second aspect.
[0103] In this embodiment, the terminal receives first indication information sent by a first network node; based on the first indication information, it performs at least one of a first operation and a second operation. The first operation can generate or invalidate a first security parameter related to the core network user plane function, or, based on the first operation, can generate or invalidate a second security parameter related to the access network node based on the generation or invalidation of the first security parameter related to the core network user plane function; the second operation can start or stop a first security process related to the core network user plane function, or, based on starting or stopping the first security process related to the core network user plane function, can start or stop a second or third security process related to the access network node. Therefore, based on at least one of the first and second operations, it can determine whether to enable the user plane security function between the terminal and the core network function, thus achieving the purpose of negotiating whether to enable the user plane security function between the terminal and the core network function, and also determining whether to enable or disable the user plane security function between the terminal and the access network node, thereby achieving the purpose of coordinating the user plane security functions between the terminal and the core network and between the terminal and the access network node. Attached Figure Description
[0104] Figure 1 shows a structural diagram of a communication system applicable to an embodiment of this application;
[0105] Figure 2 shows a flowchart of one of the information transmission methods according to an embodiment of this application;
[0106] Figure 3 shows a second schematic flowchart of the information transmission method according to an embodiment of this application;
[0107] Figure 4 shows one of the interactive schematic diagrams of the information transmission method according to an embodiment of this application;
[0108] Figure 5 shows a second interactive schematic diagram of the information transmission method according to an embodiment of this application;
[0109] Figure 6 shows a schematic diagram of one of the modules of the information transmission device according to an embodiment of this application;
[0110] Figure 7 shows a second schematic diagram of the information transmission device according to an embodiment of this application;
[0111] Figure 8 shows a structural block diagram of a communication device according to an embodiment of this application;
[0112] Figure 9 shows a structural block diagram of the terminal according to an embodiment of this application;
[0113] Figure 10 shows a structural block diagram of one of the network-side devices according to an embodiment of this application;
[0114] Figure 11 shows a second structural block diagram of the network-side device according to an embodiment of this application. DETAILED DESCRIPTION
[0115] The technical solutions in the embodiments of the present application will be clearly described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by those of ordinary skill in the art belong to the scope of protection of the present application.
[0116] The terms "first", "second", and the like in the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described herein, and the objects distinguished by "first", "second" are generally a category and do not limit the number of objects, for example, the first object can be one or more. In addition, "or" in the present application means at least one of the connected objects. For example, the protection scope of "A or B" at least covers three schemes, namely, scheme one: including A and not including B; scheme two: including B and not including A; scheme three: including A and including B. In addition, the terms "A and / or B", "at least one of A and B", "at least one of A or B" also at least cover the above three schemes, respectively. The character " / " generally represents that the objects before and after are in an "or" relationship.
[0117] The term "indicate" in the present application can be a direct indication (or explicit indication) or an indirect indication (or implicit indication). Among them, the direct indication can be understood as that the sender explicitly informs the receiver of the specific information, the operation to be performed or the request result, etc. in the sent indication; the indirect indication can be understood as that the receiver determines the corresponding information according to the indication sent by the sender, or judges and determines the operation to be performed or the request result, etc. according to the judgment result.
[0118] It is worth noting that the technology described in the embodiments of the present application is not limited to Long Term Evolution (LTE) / LTE-Advanced (LTE-A) systems, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency-Division Multiple Access (SC-FDMA) or other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the described technology can be used in the above-mentioned systems and radio technologies, as well as in other systems and radio technologies. The following description describes a New Radio (NR) system for example purposes, and NR terminology is used in most of the following description, but these technologies can also be applied to systems other than NR systems, such as 6th Generation (6G) communication systems. th
[0119] FIG. 1 shows a block diagram of a wireless communication system to which embodiments of the present application can be applied. The wireless communication system includes a terminal 11 and a network-side device 12. The terminal 11 can be a terminal-side device such as a mobile phone, a Tablet Personal Computer, a Laptop Computer, a notebook computer, a Personal Digital Assistant (PDA), a palmtop computer, a netbook, an Ultra-mobile Personal Computer (UMPC), a Mobile Internet Device (MID), an Augmented Reality (AR) device, a Virtual Reality (VR) device, a robot, a wearable device, a flight vehicle, a Vehicle User Equipment (VUE), a shipboard device, a Pedestrian User Equipment (PUE), a smart home (a home device with a wireless communication function such as a refrigerator, a television, a washing machine, or furniture), a game console, a Personal Computer (PC), a kiosk, or a self-service machine. The wearable device includes a smart watch, a smart bracelet, a smart earphone, smart glasses, smart jewelry (a smart bracelet, a smart necklace, a smart ring, a smart necklace, a smart anklet, a smart necklace, etc.), a smart wristband, smart clothes, etc. The vehicle-mounted device can also be referred to as a vehicle-mounted terminal, a vehicle-mounted controller, a vehicle-mounted module, a vehicle-mounted component, a vehicle-mounted chip, or a vehicle-mounted unit, etc. It should be noted that the specific type of the terminal 11 is not limited in the embodiments of the present application. The network-side device 12 can include an access network device or a core network device. The access network device can also be referred to as a Radio Access Network (RAN) device, a radio access network function, or a radio access network unit. The access network device can include a base station, a Wireless Local Area Network (WLAN) Access Point (AP), or a Wireless Fidelity (WiFi) node, etc.The base station can be referred to as a Node B (NB), an evolved Node B (eNB), a next generation Node B (gNB), a New Radio Node B (NR Node B), an access point, a relay station (RBS), a serving base station (SBS), a base transceiver station (BTS), a radio base station, a radio transceiver, a basic service set (BSS), an extended service set (ESS), a home Node B (HNB), a home evolved Node B, a transmit / receive point (TRP), or some other suitable terminology in the art, and is not limited to a particular technical terminology, provided that the same technical effect is achieved. It should be noted that in the embodiments of the present application, only the base station in the NR system is taken as an example for introduction, and the specific type of the base station is not limited.
[0120] The core network device can also be referred to as a core network node, a core network function, or a core network network element, etc., which includes but is not limited to at least one of the following: a mobility management entity (MME), an access and mobility management function (AMF), a session management function (SMF), a user plane function (UPF), a policy control function (PCF), a policy and charging rules function (PCRF), an edge application server discovery function (EASDF), a unified data management (UDM), a unified data repository (UDR), a home subscriber server (HSS), a centralized network configuration (CNC), a network repository function (NRF), a network exposure function (NEF), a local NEF (L-NEF), a binding support function (BSF), an application function (AF), a location management function (LMF), a gateway mobile location center (GMLC), a network data analytics function (NWDAF), etc. It should be noted that only the core network device in the NR system is taken as an example for introduction in the embodiments of the present application, and the specific type of the core network device is not limited. If the name of the core network device mentioned in the embodiments of the present application changes in the subsequent protocol version (for example, 6G), it is also within the protection scope of the present application.
[0121] Optionally, the core network device can be implemented by one or more function modules in one device, or can be implemented by multiple devices together, and the embodiments of the present application do not make a specific limitation in this regard. It can be understood that the above function modules can be network elements in a hardware device, can be software function modules running on a dedicated hardware, or can be virtualized function modules instantiated on a platform (for example, a cloud platform).
[0122] In order for those skilled in the art to better understand the embodiments of the present application, the following is first described.
[0123] 1. Key negotiation;
[0124] The UE and the AMF / Security Anchor Function (SEAF) learn the key K AMF / K SEAF In the PDU session creation procedure, the AMF / SEAF derives the key K SMF from the key K UPF-enc and K UPF-int are used for encryption and integrity protection respectively. In the PDU session creation procedure, the UE derives K UPF-enc and K UPF-int from the same derivation procedure in the core network, thus completing the key negotiation between the UE and the UPF.
[0125] 2. On-demand user plane security;
[0126] In the PDU session creation procedure, the SMF sends the user plane security policy (UP Security Policy) to the gNB, and the gNB decides whether to enable the UP security (between the UE and the gNB) based on the policy. If it is enabled, the gNB sends an enabling indication to the UE through a Radio Resource Control (RRC) message, including an indication of enabling confidentiality and / or an indication of enabling integrity. The UE Security Policy includes three types of policies, respectively for Confidentiality and Integrity, and specifically includes: Required—indicates to enable, Not needed—indicates to disable / not to enable, Preferred—indicates to prefer to enable, and whether to enable is decided by the gNB.
[0127] The information transmission method provided by the embodiments of the present application will be described in detail in combination with the accompanying drawings and some embodiments and application scenarios thereof.
[0128] As shown in FIG. 2, the embodiment of the present application provides an information transmission method, executed by a terminal, comprising:
[0129] Step 201: receiving first indication information sent by a first network node.
[0130] In the embodiment of the present application, the first network node can be a core network function or an access network node. For example, when the first network node is a core network function, the first network node can be MME, AMF, SMF, UPF, Serving Gateway (SGW), PDN Gateway (PGW), etc. When the first network node is an access network node, the first network node can be gNB, eNB, etc.
[0131] When the first network node is an access network node, the first indication information can be transparently transmitted to the terminal by the core network node through the access network node, for example, transparently transmitted to the terminal by the core network node through a Non-Access Stratum (NAS) message. The first indication information can also be non-transparently transmitted to the terminal by the core network node through the access network node, for example, sent by the core network node to the gNB through an N2 message, and then sent by the gNB to the terminal through a Radio Resource Control (RRC) message. The first indication information can also be partially transparently transmitted to the terminal by the access network node, and another part of the first indication information is non-transparently transmitted to the terminal by the access network node.
[0132] Optionally, the first indication information can indicate whether to perform the first operation and / or the second operation by direct indication or implicit indication.
[0133] For example, when the first indication information is used to indicate that the user plane security function between the terminal and the core network function is enabled, the terminal can perform the operations of the following A1, A3, B1, B2, and B3 items. For example, when the first indication information is used to indicate that the user plane security function between the terminal and the core network function is disabled, the terminal can perform the operations of the following A2, A4, B4, B5, and B6 items.
[0134] Step 202: performing at least one of the first operation and the second operation according to the first indication information.
[0135] The first operation includes any one of the following:
[0136] A1: generating a first security parameter.
[0137] In the embodiment of the present application, the first security parameter is related to the core network user plane function.
[0138] Optionally, the core network user plane function includes, but is not limited to, a UPF, an SGW, a PGW, and the like.
[0139] Optionally, the first security parameter includes at least one of the following: key information, count information.
[0140] The key information includes a key for confidentiality processing.
[0141] The count information is used as a parameter for security processing, which can ensure that different results are obtained each time security processing is performed, thereby avoiding a replay attack. For example, even if the contents of two times of encryption are the same, different results are obtained.
[0142] The first security parameter is generated, so that subsequent first security processing is performed on user plane data based on the first security parameter.
[0143] A2: invalidating the first security parameter.
[0144] The first security parameter is invalidated, so that subsequent first security processing based on the first security parameter on user plane data is stopped.
[0145] A3: generating the first security parameter and invalidating the second security parameter.
[0146] In an embodiment of the present application, the second security parameter is related to the access network node.
[0147] Optionally, the second security parameter includes at least one of the following: key information, count information.
[0148] The key information includes a key for confidentiality processing.
[0149] The count information is used as a parameter for security processing, which can ensure that different results are obtained each time security processing is performed, thereby avoiding a replay attack. For example, even if the contents of two times of encryption are the same, different results are obtained.
[0150] The key information included in the first security parameter and the second security parameter can be different, and the count information included in the first security parameter and the second security parameter can be the same or different.
[0151] Here, by generating the first security parameter and invalidating the second security parameter, it is determined to enable the user plane security function between the terminal and the core network function, and to disable the user plane security function between the terminal and the access network node, thereby achieving the purpose of coordinating the user plane security function between the terminal and the core network and the user plane security function between the terminal and the access network node.
[0152] A4: invalidating the first security parameter and generating the second security parameter.
[0153] Here, by invalidating the first security parameter and generating the second security parameter, i.e., determining to close the user plane security function between the terminal and the core network function, and enabling the user plane security function between the terminal and the access network node, the purpose of coordinating the user plane security function between the terminal and the core network and the user plane security function between the terminal and the access network node is achieved.
[0154] The second operation includes any one of the following:
[0155] B1: performing first security processing on the user plane data based on the first security parameter.
[0156] In the embodiments of the present application, the first security processing includes at least one of confidentiality processing and integrity processing.
[0157] B2: performing first security processing on the user plane data based on the first security parameter, and stopping second security processing on the user plane data based on the second security parameter.
[0158] Optionally, the second security processing includes at least one of confidentiality processing and integrity processing.
[0159] Optionally, the first security processing is the same as or different from the second security processing.
[0160] For example, first confidentiality processing or first integrity processing is performed based on the first security parameter, and second confidentiality processing and second integrity processing based on the second security parameter are stopped; or first confidentiality processing and first integrity processing are performed based on the first security parameter, and second confidentiality processing and second integrity processing based on the second security parameter are stopped; or first confidentiality processing is performed based on the first security parameter, and second confidentiality processing based on the second security parameter is stopped; or first integrity processing is performed based on the first security parameter, and second integrity processing based on the second security parameter is stopped; and the like.
[0161] B3: performing first security processing on the user plane data based on the first security parameter, and performing third security processing on the user plane data based on the second security parameter.
[0162] Optionally, the third security processing includes at least one of integrity processing and confidentiality processing.
[0163] Optionally, the first security processing is different from the third security processing.
[0164] For example, first confidentiality processing is performed based on the first security parameter, and third integrity processing is performed based on the second security parameter; or first integrity processing is performed based on the first security parameter, and third confidentiality processing is performed based on the second security parameter; and the like.
[0165] B4: stop the first security processing on the user plane data based on the first security parameter.
[0166] For example, when the first indication information is used to instruct to disable the user plane security function between the terminal and the core network function, the terminal stops the first security processing on the user plane data based on the first security parameter.
[0167] B5: stop the first security processing on the user plane data based on the first security parameter, and perform the second security processing on the user plane data based on the second security parameter.
[0168] For example, stop the first confidentiality processing or the first integrity processing based on the first security parameter, and perform the second confidentiality processing and the second integrity processing based on the second security parameter; or, stop the first confidentiality processing and the first integrity processing based on the first security parameter, and perform the second confidentiality processing and the second integrity processing based on the second security parameter; or, stop the first confidentiality processing based on the first security parameter, and perform the second confidentiality processing based on the second security parameter; or, stop the first integrity processing based on the first security parameter, and perform the second integrity processing based on the second security parameter; and the like.
[0169] B6: stop the first security processing on the user plane data based on the first security parameter, and stop the third security processing on the user plane data based on the second security parameter.
[0170] Optionally, the first security processing is different from the third security processing.
[0171] For example, stop the first confidentiality processing based on the first security parameter, and perform the third integrity processing based on the second security parameter; or, stop the first integrity processing based on the first security parameter, and perform the third confidentiality processing based on the second security parameter; and the like.
[0172] In the embodiments of the present application, the first security processing is performed on the user plane based on the first security parameter, the user plane security function between the terminal and the UPF is enabled, that is, the security processing is performed on the user plane data between the terminal and the UPF, without the security processing of the gNB, so that the purpose of bypassing the security processing of the gNB on the user plane data is achieved.
[0173] In the embodiments of the present application, the terminal receives first indication information sent by the first network node; and at least one of a first operation and a second operation is performed according to the first indication information. Based on the first operation, the first security parameter related to the core network user plane function can be generated or invalidated, or based on the first operation, the second security parameter related to the access network node can be generated or invalidated on the basis of generating or invalidating the first security parameter related to the core network user plane function; based on the second operation, the first security processing related to the core network user plane function can be started or stopped, or the second security processing or the third security processing related to the access network node can be started or stopped on the basis of starting or stopping the first security processing related to the core network user plane function, so that based on at least one of the first operation and the second operation, it can be determined whether to enable the user plane security function between the terminal and the core network function, that is, the purpose of negotiating whether to enable the user plane security function between the terminal and the core network function is achieved, and it can also be determined whether to enable or close the user plane security function between the terminal and the access network node, so that the purpose of coordinating the user plane security function between the terminal and the core network and the user plane security function between the terminal and the access network node is achieved.
[0174] Optionally, before the receiving the first indication information sent by the first network node, the method further comprises:
[0175] sending second indication information to the first network node, the second indication information being related to at least one of the first security parameter, the core network user plane function, the first security processing of the user plane data, the security coordination processing of the user plane data, the coordination processing of the security parameter, the capability of the terminal, and the expectation or request of the terminal;
[0176] wherein the capability of the terminal is related to at least one of the security coordination processing of the user plane data, the coordination processing of the security parameter, the first security parameter, the core network user plane function, and the first security processing;
[0177] the expectation or request of the terminal is related to at least one of the security coordination processing of the user plane data, the coordination processing of the security parameter, the first security parameter, the core network user plane function, and the first security processing.
[0178] In some embodiments of the present application, the second indication information is used to indicate at least one of the following: support for generating or using the first security parameter, support for the user plane data security processing of the UPF, support for using the first security parameter, support for using the user plane data security processing of the UPF, etc.
[0179] In the embodiments of the present application, after receiving the second indication information, the first network node determines that the terminal supports the user plane security function between the terminal and the core network function based on the second indication information, and then sends the first indication information to the terminal based on the second indication information.
[0180] Optionally, in the embodiments of the present application, at least one of the first indication information or the second indication information further comprises:
[0181] Third indication information, the third indication information is used to indicate at least one of confidentiality processing and integrity processing.
[0182] It should be noted that the content indicated by the third indication information included in the first indication information and the second indication information can be the same or different, for example, the third indication information in the first indication information is used to indicate confidentiality processing and integrity processing, the third indication information in the second indication information is used to indicate confidentiality processing or integrity processing, or the third indication information in the first indication information is used to indicate confidentiality processing or integrity processing, the third indication information in the second indication information is used to indicate confidentiality processing and integrity processing, or the third indication information in the first indication information is used to indicate confidentiality processing, the third indication information in the second indication information is used to indicate integrity processing, or the third indication information in the second indication information is used to indicate confidentiality processing, and the third indication information in the third indication information is used to indicate integrity processing.
[0183] Based on the third indication information, the terminal can determine to perform confidentiality processing, or integrity processing, or confidentiality processing and integrity processing on the user plane data.
[0184] Optionally, the first indication information comprises:
[0185] First protocol data unit (PDU) session information, wherein the user plane data is related to a PDU session indicated by the first PDU session information.
[0186] Optionally, the first PDU session information includes but is not limited to PDU session identification (PDU Session ID), data network name (Data Network Name, DNN), single network slice selection assistance information (Single Network Slice Selection Assistance Information, S-NSSAI).
[0187] Based on the first PDU session information, the terminal can determine the PDU session to be processed securely. In a case where the first indication information includes the first PDU session information, the terminal performs corresponding security processing on the PDU session associated with the first PDU session information, otherwise, performs corresponding security processing on all user plane data.
[0188] In the embodiments of the present application, the terminal receives first indication information sent by the first network node; and performs at least one of a first operation and a second operation according to the first indication information. Based on the first operation, a first security parameter related to a core network user plane function can be generated or invalidated, or based on the first operation, a second security parameter related to an access network node can be generated or invalidated on the basis of generating or invalidating the first security parameter related to the core network user plane function; based on the second operation, a first security processing related to the core network user plane function can be started or stopped, or a second security processing or a third security processing related to the access network node can be started or stopped on the basis of starting or stopping the first security processing related to the core network user plane function, so that based on at least one of the first operation and the second operation, it can be determined whether to enable the user plane security function between the terminal and the core network function, that is, the purpose of negotiating whether to enable the user plane security function between the terminal and the core network function is achieved, and it can also be determined whether to enable or disable the user plane security function between the terminal and the access network node, so that the purpose of coordinating the user plane security function between the terminal and the core network and the user plane security function between the terminal and the access network node is achieved.
[0189] As shown in FIG. 3, the embodiments of the present application also provide an information transmission method, which is executed by a first network node, and the method comprises:
[0190] Step 301: performing a third operation, the third operation comprising at least one of:
[0191] sending first information to a core network user plane function;
[0192] sending first indication information to a terminal;
[0193] The first indication information is related to at least one of: a first security parameter, a second security parameter, user plane data, a first security processing, a second security processing and a third security processing.
[0194] The first information comprises fourth indication information, and the fourth indication information is related to a first security processing of the user plane data.
[0195] The first security parameter is related to the core network user plane function; optionally, the core network user plane function comprises but is not limited to a UPF, an SGW, a PGW, etc.
[0196] The second security parameter is related to the access network node.
[0197] The first security processing includes at least one of confidentiality processing and integrity processing, and the first security processing is related to the core network user plane function.
[0198] The second security processing includes at least one of confidentiality processing and integrity processing, and the second security processing is related to the access network node.
[0199] The third security processing includes at least one of integrity processing and confidentiality processing, and the third security processing is related to the access network node.
[0200] Optionally, the first security processing is the same as or different from the second security processing.
[0201] Optionally, the first security processing is different from the third security processing.
[0202] Optionally, the first security parameter includes at least one of key information and count information.
[0203] Optionally, the second security parameter includes at least one of key information and count information.
[0204] The key information includes a key for confidentiality processing.
[0205] The count information is used as a parameter for security processing, so that different results can be obtained each time the security processing is performed, and replay attacks can be avoided. For example, even if the contents of two encryptions are the same, different results can be obtained.
[0206] In the embodiments of the present application, the first network node can be a core network function or an access network node. For example, when the first network node is a core network function, the first network node can be an MME, an AMF, an SMF, a UPF, a serving gateway (SGW), a PDN gateway (PGW), etc. When the first network node is an access network node, the first network node can be a gNB, an eNB, etc.
[0207] When the first network node is an access network node, the first indication information can be transparently transmitted by the core network node to the terminal through the access network node, for example, transparently transmitted to the terminal by the core network node through a Non-Access Stratum (NAS) message. The first indication information can also be non-transparently transmitted by the core network node to the terminal through the access network node, for example, transmitted by the core network node to the gNB through an N2 message, and then transmitted by the gNB to the terminal through a Radio Resource Control (RRC) message. The first indication information can also be partially transparently transmitted by the access network node to the terminal, and another part of the first indication information is non-transparently transmitted by the access network node to the terminal.
[0208] Optionally, the fourth indication information is used to indicate that the UPF security (i.e., the user plane security between the UE and the UPF) is enabled, or to indicate auxiliary information for enabling the UPF security, for example, the auxiliary information is expected to enable the UPF security.
[0209] Optionally, the first information further includes a first key or a second key, for example, the first key can be K SMF , K UPF。 K SMF It can be understood that the key K UPF can be understood as a key of the SMF, and the key K UPF can be a key derived from the key K SMF . After receiving the first key, the UFP derives the key K UPF-enc , K UPF-int based on the first key. The second key can be K UPF-enc , K UPF-int .
[0210] In the embodiments of the present application, the first network node performs sending the first information to the core network user plane function or sending the first indication information to the terminal, so that the core network user plane function and the terminal can determine whether to enable the user plane security function between the terminal and the core network function, thereby achieving the purpose of negotiating whether to enable the user plane security function between the terminal and the core network function.
[0211] Optionally, the first information further includes a third security parameter, and the first security processing of the core network user plane function is based on the third security parameter.
[0212] Optionally, the third security parameter includes at least one of the following: key information, count information.
[0213] The key information includes a key for confidentiality processing.
[0214] The count information can be used as a parameter of security processing, so that different results can be obtained each time security processing is performed, and replay attacks can be avoided. For example, even if the encrypted content is the same twice, different results can be obtained. In an embodiment of the present application, in a case where the fourth indication information is used to indicate that the first security processing is performed, the UPF performs the first security processing based on the third security parameter.
[0215] Optionally, the fourth indication information is used for at least one of the following:
[0216] indicating that the first security processing is performed;
[0217] indicating that the first security processing is stopped;
[0218] indicating that the first security processing is expected to be performed;
[0219] indicating that the first security processing is expected to be stopped.
[0220] Optionally, the performing the third operation comprises:
[0221] obtaining or receiving subscription information from a unified data management entity (UDM);
[0222] performing the third operation based on the subscription information.
[0223] For example, if the UDM subscription indicates that UPF security is required, the UPF security is enabled and the gNB security is disabled; if the UDM subscription indicates that UPF security is preferred, the AMF / SMF autonomously decides whether to enable the UPF security and disable the gNB security; if the UDM subscription indicates that gNB security is preferred, the AMF / SMF autonomously decides whether to enable the gNB security and disable the UPF security; if the UDM subscription indicates that gNB security is not needed, the AMF / SMF disables the gNB security and autonomously decides whether to enable the UPF security; if the UDM subscription indicates that UPF security is not needed, the UPF security is disabled; and if the UDM subscription indicates that gNB security is required, the AMF / SMF enables the gNB security and disables the UPF security.
[0224] Optionally, the performing the third operation comprises:
[0225] receiving second indication information from a terminal;
[0226] performing the third operation based on the second indication information;
[0227] The second indication information is related to at least one of the following: security coordination processing of user plane data, coordination processing of security parameters, the first security parameter, a core network user plane function, first security processing of user plane data, a capability of the terminal, and an expectation or request of the terminal.
[0228] The capability of the terminal is related to at least one of the following: security coordination processing of user plane data, coordination processing of security parameters, the first security parameter, a core network user plane function, and the first security processing.
[0229] The expectation or request of the terminal is related to at least one of the following: security coordination processing of user plane data, coordination processing of security parameters, the first security parameter, a core network user plane function, and the first security processing.
[0230] In some embodiments of the present application, the second indication information is used to indicate at least one of the following: support for generating or using the first security parameter, support for user plane data security processing of the UPF, support for using the first security parameter, support for using the user plane data security processing of the UPF, and the like.
[0231] In the embodiments of the present application, after the first network node receives the second indication information, the terminal supports the user plane security function between the terminal and the core network function based on the second indication information, and then the first indication information is sent to the terminal based on the second indication information.
[0232] Optionally, the sending of the first indication information to the terminal comprises:
[0233] receiving fifth indication information from the core network user plane function, the fifth indication information being used to indicate that the core network user plane function performs or stops the first security processing;
[0234] based on the fifth indication information, performing the sending of the first indication information to the terminal.
[0235] In the embodiments of the present application, in the case that the fourth indication information is used to indicate that the first security processing is expected to be performed, or to indicate that the first security processing is expected to be stopped, the fifth indication information is received from the core network user plane function, and the first indication information is sent to the terminal based on the fifth indication information.
[0236] Optionally, the method of the embodiments of the present application further comprises:
[0237] based on at least one of the first indication information, the fourth indication information, and the fifth indication information, sending second information to the access network node, the second information comprising sixth indication information, the sixth indication information being used to indicate any one of the following:
[0238] performing the second security processing;
[0239] indicate to stop the second security processing;
[0240] indicate to perform the third security processing;
[0241] indicate to stop the third security processing.
[0242] Optionally, in a case where at least one of the first indication information, the fourth indication information and the fifth indication information is used to indicate that the first security processing on the user plane data based on the first security parameter is performed, the sixth indication information is used to indicate to stop the second security processing on the user plane data based on the second security parameter, or is used to indicate to perform the third security processing on the user plane data based on the second security parameter.
[0243] Or, in a case where at least one of the first indication information, the fourth indication information and the fifth indication information is used to indicate to stop the first security processing on the user plane data based on the first security parameter, the sixth indication information is used to indicate to perform the second security processing on the user plane data based on the second security parameter, or is used to indicate to stop the third security processing on the user plane data based on the second security parameter.
[0244] Optionally, the second information further comprises:
[0245] second PDU session information, the sixth indication information is related to a PDU session indicated by the second PDU session information.
[0246] Optionally, the second PDU session information comprises but is not limited to a PDU session identifier (PDU Session ID), a data network name (Data Network Name, DNN) and single network slice selection assistance information (Single Network Slice Selection Assistance Information, S-NSSAI).
[0247] Based on the above-mentioned second PDU session information, the access network node is enabled to determine the PDU session on which the security processing is performed. In a case where the sixth indication information comprises the above-mentioned first PDU session information, the access network performs the corresponding security processing on the PDU session associated with the first PDU session information, otherwise, performs the corresponding security processing on all user plane data.
[0248] Optionally, the sixth indication information further comprises:
[0249] seventh indication information, the seventh indication information is used to indicate at least one of confidentiality processing and integrity processing.
[0250] Based on the seventh indication information, the access network node can determine that the security processing performed on the user plane data is confidentiality processing, or is integrity processing, or is both confidentiality processing and integrity processing.
[0251] Optionally, the method of the embodiments of the present application further comprises:
[0252] Optionally, the method of the embodiments of the present application further comprises:
[0253] In the case that the first network node is an access network node, the first indication information is received from a second network node, which can be a core network function such as MME, AMF, SMF, etc.
[0254] Optionally, the first indication information comprises:
[0255] Optionally, the first indication information comprises:
[0256] Optionally, the first PDU session information comprises but is not limited to PDU session identification (PDU Session ID), data network name (Data Network Name, DNN), single network slice selection assistance information (Single Network Slice Selection Assistance Information, S-NSSAI).
[0257] Based on the above-mentioned first PDU session information, the terminal can determine the PDU session to be processed for security. In the case that the first indication information comprises the above-mentioned first PDU session information, the terminal performs corresponding security processing on the PDU session associated with the first PDU session information, otherwise, performs corresponding security processing on all user plane data.
[0258] Optionally, at least one of the first indication information, the second indication information, the fourth indication information and the fifth indication information further comprises:
[0259] The third indication information is used to indicate at least one of confidentiality processing and integrity processing.
[0260] It should be noted that in the embodiments of the present application, the third indication information contained in the first indication information, the second indication information, the fourth indication information and the fifth indication information indicates the same or different content.
[0261] In the embodiments of the present application, the first network node sends the first information to the core network user plane function or sends the first indication information to the terminal, so that the core network user plane function and the terminal can determine whether to enable the user plane security function between the terminal and the core network function, thereby achieving the purpose of negotiating whether to enable the user plane security function between the terminal and the core network function.
[0262] The information transmission method of the present application will be described below in conjunction with embodiments.
[0263] As shown in FIG. 4, in an embodiment of the present application, the information transmission method comprises:
[0264] Step 401: The UE initiates a PDU session establishment procedure or a service request procedure.
[0265] For example, the terminal initiates the PDU session establishment procedure by sending a PDU session establishment request (PDU Session Establishment Request) message. Alternatively, the service request procedure is initiated by sending a service request (Service Request) message.
[0266] After receiving the PDU session establishment request message, the AMF forwards the received message to the SMF.
[0267] The AMF receives the Service Request and invokes the Nsmf_PDUSession_UpdateSMContext operation.
[0268] Optionally, the PDU session establishment request message or the service request message carries the second indication information, which can be used to indicate that the terminal supports UPF security, the UE supports user plane security, or the opposite end of the UE supporting user plane security is UPF, etc. Optionally, the AMF forwards the indication to the SMF, such as including the second indication information in the parameters of the Nsmf_PDUSession_UpdateSMContext operation.
[0269] Optionally, the second indication information can further include third indication information, which is used to indicate at least one of confidentiality processing and integrity processing, indicating that the confidentiality processing supports UPF security, the integrity processing supports UPF security, or indicating that both the confidentiality processing and the integrity processing support UPF security.
[0270] Step 402: Optionally, the AMF / SMF determines whether to perform UPF security for the PDU session based on at least one of the UDM subscription or the local policy and the second indication information.
[0271] The step 402 is an optional step. The UPF security can be understood as a user plane security function between the UE and the UPF.
[0272] For example, if the UDM subscription indicates that the UPF security is Required, the steps 403-406 are performed, i.e., the UPF security is enabled and the gNB security is disabled; if the UDM subscription indicates that the UPF security is Preferred, the AMF / SMF autonomously decides whether to perform the steps 403-406, i.e., autonomously decides whether to enable the UPF security and disable the gNB security; if the UDM subscription indicates that the gNB security is Preferred, the AMF / SMF autonomously decides whether to perform the steps 403-406, i.e., autonomously decides whether to enable the gNB security and disable the UPF security; if the UDM subscription indicates that the gNB security is Not needed, the AMF / SMF disables the gNB security and autonomously decides whether to perform the steps 403-406 to enable the UPF security; if the UDM subscription indicates that the UPF security is Not needed, the steps 403-406 are not performed, i.e., the UPF security is disabled; if the UDM subscription indicates that the gNB security is Required, the AMF / SMF enables the gNB security and disables the UPF security.
[0273] The gNB security can be understood as a user plane security function between the UE and the gNB.
[0274] The step 403: the AMF sends first information to the SMF based on the result of the step 402, including fourth indication information, used to indicate to enable the UPF security (i.e., the user plane security is between the UE and the UPF) or to indicate auxiliary information of the UPF security to be enabled.
[0275] For example, the auxiliary information is to enable the UPF security.
[0276] Optionally, the first information further includes a first key, for example, the first key can be K SMF , K UPF .
[0277] Optionally, the AMF derives the first key based on the result of the step 402. The SMF sends the fourth indication information to the UPF and sends a first key or a second key to the UPF, the second key being derived from the first key. For example, the second key can be K UPF , K UPF-enc , K UPF-int .
[0278] Alternatively, the step 403 can also be that the SMF sends the first information to the UPF based on the result of the step 402.
[0279] Optionally, the SMF derives a third key based on the result of the step 402 and sends it to the UPF, such as KUPF , K UPF-enc , K UPF-int , the third key being received from the AMF or derived from a key received from the AMF.
[0280] Step 404: Optionally, the UPF decides to enable or disable UPF security, and decides to disable or enable gNB security.
[0281] Optionally, the UPF receives key information, and derives a first security handling key based on the received key information, e.g., K UPF- enc , K UPF-int , the first security handling key being used for UPF security handling data interacting with the UE, including confidentiality and / or integrity handling. Optionally, the UPF performs the above key derivation operation based on the decision result. For example, in the case of deciding to enable UPF security, the operation of deriving the above first security handling key is performed.
[0282] Step 405: The UPF responds to the SMF.
[0283] Optionally, the UPF sends fifth indication information to the SMF, the fifth indication information being used to indicate whether the first security function is enabled by the UPF.
[0284] Optionally, in the case that the above fourth indication information is used to indicate the assistance information of enabling UPF security, the UPF sends the above fifth indication information.
[0285] Step 406: The SMF sends first indication information to the UE or the AMF based on the result of step 402 or based on the indication of step 405, and the SMF can also send sixth indication information to the gNB.
[0286] Or, the step 406 can also be that the AMF sends first indication information to the UE based on the result of step 402, and the AMF can also send sixth indication information to the gNB.
[0287] Optionally, the first indication information can be used to indicate that UPF security is enabled, or the two ends of user plane security are UE and UPF, or the security termination point is UPF, or the security protocol is Internet Protocol Security (IPSec) and other non-Packet Data Convergence Protocol (PDCP) protocols; the sixth indication information can be used to indicate that the user plane disables the base station security or disables the Access Stratum (AS) security, or stops using the user plane security between the UE and the base station (such as indicating Not Needed in the UP Security Policy), such as the SMF invoking the Namf_Communication_N1N2MessageTransfer operation of the AMF, including the PDU session establishment command (Session Establishment Command) message sent to the UE in the operation parameter, the message includes the first indication information, the operation can also include N2 session management information (N2 SM Information), which includes the sixth indication information, or the first indication information is also included in the N2 SM Information, which is transmitted to the UE by the gNB through the RRC message.
[0288] Alternatively, the SMF includes the first indication information in the result returned to the AMF in the Nsmf_PDUSession_UpdateSMContext operation based on the result of step 402, and can also include the sixth indication information sent to the gNB (such as included in the N2 SM Information parameter), the AMF sends the eighth indication information to the UE based on the first indication information, which includes the first indication information and the first PDU session information to indicate that the corresponding PDU session uses the UPF security. Optionally, the AMF sends the ninth indication information to the gNB based on the first indication information, which includes the first PDU session information and the corresponding UP Security Policy, wherein the UP Security Policy indicates Not Needed. The above-mentioned eighth indication information and ninth indication information can also be transparently transmitted by the SMF through the AMF and sent to the UE and gNB respectively.
[0289] Optionally, the first indication information and the fourth indication information can further comprise second indication information, indicating that the confidentiality processing uses UPF security, the integrity processing uses UPF security, or both. Optionally, the sixth indication information comprises the corresponding second indication information in the first indication information, implementing the coordinated handling of user plane security (i.e. if the user plane confidentiality processing uses UPF security, deactivating the AS security for the user plane confidentiality processing, if the user plane integrity processing uses UPF security, deactivating the AS security for the user plane confidentiality processing, if the user plane confidentiality and integrity processing uses UPF security, deactivating the AS security for the user plane confidentiality and integrity processing). The above-mentioned coordinated handling can be implemented by the SMF (i.e. the SMF sends the first indication information comprising the second indication information to the UE and sends the sixth indication information comprising the corresponding second indication information to the gNB), or by the AMF (i.e. the AMF sends the first indication information comprising the second indication information to the UE and sends the sixth indication information comprising the corresponding second indication information to the gNB). Similarly, the eighth indication information can also comprise the second indication information, and the ninth indication information comprises the corresponding second indication information in the eighth indication information. In the case that the fourth, first, sixth, eighth, and ninth indication information do not comprise the second indication information, it is equivalent to indicating the confidentiality and integrity.
[0290] The first indication information and the sixth indication information can be used to indicate that all PDU sessions of the UE enable UPF security, such as in the embodiment that the AMF performs the above-mentioned procedure based on the result of step 402, such as in the PDU Session Establishment procedure, the first indication information and the sixth indication information sent by the SMF can be for the created PDU session.
[0291] The UE receives the first indication information or the eighth indication information, and derives the same key as used by the UPF.
[0292] Step 407: The gNB generates the tenth indication information based on the sixth indication information or the ninth indication information and sends it to the UE, the tenth indication information is used to indicate deactivating the AS security.
[0293] Step 408: the UE bases on the first indication information or the eighth indication information, and the UPF bases on the fourth indication information, both of them use the same key to process the data exchanged between the UE and the UPF, including Confidentiality processing, Integrity processing, Confidentiality and Integrity processing on the data.
[0294] As shown in FIG. 5, in an embodiment of the present application, the information transmission method comprises:
[0295] Step 501: the UE initiates a registration procedure.
[0296] For example, the UE sends a Registration Request message carrying the second indication information.
[0297] Step 502: the AMF decides whether to use UPF security for the PDU session of the UE based on at least one of the UDM subscription, the local policy and the second indication information.
[0298] Step 503: the AMF sends a registration response to the UE, and the registration response carries the first indication information.
[0299] For example, the registration response is a Registration Accept message.
[0300] Optionally, the AMF sends sixth indication information to the gNB, and the gNB keeps the sixth indication information and judges whether to enable or disable the gNB security for all PDU sessions of the UE based on the sixth indication information, i.e., the indication in step 510 is sent in advance, and step 510 can not be sent.
[0301] Step 504: the UE initiates a PDU session establishment procedure.
[0302] For example, the UE sends a PDU Session Establishment Request message.
[0303] Step 505: the AMF sends fourth indication information to the SMF when forwarding the PDU Session Establishment Request message based on the result of step 502.
[0304] Step 506: the SMF sends the fourth indication information and related key information to the UPF.
[0305] Optionally, the above-mentioned related key information includes a first key or a second key derived from the first key, for example, the second key is K UPF , KUPF-enc , K UPF-int The first key can be K SMF , K UPF .
[0306] Step 507: Optionally, the UPF decides to enable or disable UPF security, and decides to disable or enable gNB security.
[0307] This step is the same as step 404 described above.
[0308] Step 508: The UPF responds to the SMF.
[0309] This step is the same as step 405 described above.
[0310] Step 509: The SMF invokes the Namf_Communication_N1N2MessageTransfer operation of the AMF, including sending the PDU Session Establishment Command message to the UE.
[0311] Step 510: The AMF receives the invocation of step 509, and based on the result of step 502, sends the sixth indication information or the ninth indication information to the gNB.
[0312] Step 511: The UE derives the user plane key related to UPF security based on the first indication information, and no longer derives the user plane key related to gNB security.
[0313] Step 512: The gNB generates the tenth indication information based on the sixth indication information or the ninth indication information and sends it to the UE, the tenth indication information being used to indicate to disable AS security.
[0314] This step is the same as step 407.
[0315] Step 513: The UE and the UPF use the same key to process the data between the UE and the UPF based on the first indication information or the eighth indication information and the fourth indication information, including Confidentiality processing, Integrity processing, Confidentiality and Integrity processing on the data.
[0316] This step is the same as step 408.
[0317] The above scheme of the embodiments of the present application achieves the purpose of negotiating whether to enable the user plane security function between the terminal and the core network function, and can also determine whether to enable or disable the user plane security function between the terminal and the access network node, thereby achieving the purpose of coordinating the processing of the user plane security function between the terminal and the core network and the user plane security function between the terminal and the access network node.
[0318] The information transmission method provided by the embodiments of the present application can be executed by an information transmission device. The embodiments of the present application take the information transmission device as an example to illustrate the information transmission device provided by the embodiments of the present application.
[0319] The embodiments of the present application provide an information transmission device. As an example, the information transmission device can be a communication device or a component in the communication device, such as a chip. The communication device can be a terminal, a network side device or a server, etc. For example, the terminal can include but is not limited to the types of the terminal 11 listed above, the network side device can include but is not limited to the types of the network side device 12 listed above, and the embodiments of the present application do not make specific limitations.
[0320] The information transmission device includes a receiving module, a sending module and a processing module. The receiving module, the sending module and the processing module can be implemented by software or by hardware. When implemented by hardware, the processing module can be implemented by a processor, which can include a general purpose processor, a special purpose processor, etc., such as a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), an artificial intelligent (AI) processor, a graphics processing unit (GPU), an application specific integrated circuit (ASIC), a network processor (NP), a field programmable gate array (FPGA) or other programmable logic devices, a gate circuit, a transistor, a discrete hardware component, etc. The receiving module and the sending module can be implemented by a communication interface, which can include one or more of a transceiver, a pin, a circuit, a bus, a radio frequency unit, etc.
[0321] Specifically, referring to FIG. 6, when the information transmission device is a terminal or a component in the terminal, the information transmission device 600 includes a first receiving module 601 configured to receive first indication information sent by a first network node; and a processing module 602 configured to perform at least one of a first operation and a second operation according to the first indication information.
[0322] The first operation includes any one of the following:
[0323] generating a first security parameter;
[0324] invalidating the first security parameter;
[0325] generating the first security parameter and invalidating the second security parameter;
[0326] invalidating the first security parameter and generating the second security parameter;
[0327] The second operation includes any one of the following:
[0328] performing first security processing on the user plane data based on the first security parameter;
[0329] performing first security processing on the user plane data based on the first security parameter, and stopping second security processing on the user plane data based on the second security parameter;
[0330] performing first security processing on the user plane data based on the first security parameter, and performing third security processing on the user plane data based on the second security parameter;
[0331] stopping first security processing on the user plane data based on the first security parameter;
[0332] stopping first security processing on the user plane data based on the first security parameter, and performing second security processing on the user plane data based on the second security parameter;
[0333] stopping first security processing on the user plane data based on the first security parameter, and stopping third security processing on the user plane data based on the second security parameter;
[0334] The first security parameter is related to a core network user plane function;
[0335] The second security parameter is related to an access network node;
[0336] The first security processing includes at least one of confidentiality processing and integrity processing;
[0337] The second security processing includes at least one of confidentiality processing and integrity processing;
[0338] The third security processing includes at least one of integrity processing and confidentiality processing.
[0339] Optionally, the apparatus of the embodiment of the application further includes:
[0340] The first sending module is configured to send second indication information to the first network node, the second indication information being related to at least one of the first security parameter, a core network user plane function, first security processing of user plane data, security collaborative processing of user plane data, collaborative processing of security parameters, a capability of the terminal, and an expectation or request of the terminal.
[0341] wherein the capability of the terminal is related to at least one of security coordination processing of user plane data, security parameter coordination processing, the first security parameter, core network user plane function and the first security processing.
[0342] the expectation or request of the terminal is related to at least one of security coordination processing of user plane data, security parameter coordination processing, the first security parameter, core network user plane function and the first security processing.
[0343] Optionally, at least one of the first indication information or the second indication information further comprises:
[0344] third indication information, the third indication information being used for indicating at least one of confidentiality processing and integrity processing.
[0345] Optionally, the first indication information comprises:
[0346] first protocol data unit (PDU) session information, wherein the user plane data is related to a PDU session indicated by the first PDU session information.
[0347] Optionally, the first security parameter or the second security parameter respectively comprises at least one of:
[0348] key information, count information.
[0349] Referring to FIG. 7, when the information transmission apparatus is a network side device or a component in the network side device, the information transmission apparatus 700 comprises a transceiver module 701, configured to perform a third operation, the third operation comprising at least one of:
[0350] sending first information to a core network user plane function;
[0351] sending first indication information to a terminal;
[0352] wherein the first indication information is related to at least one of the first security parameter, the second security parameter, the user plane data, the first security processing, the second security processing and the third security processing.
[0353] wherein the first information comprises fourth indication information, the fourth indication information being related to the first security processing of the user plane data.
[0354] wherein the first security parameter is related to the core network user plane function.
[0355] wherein the second security parameter is related to an access network node.
[0356] The first security processing includes at least one of confidentiality processing and integrity processing, and the first security processing is related to a core network user plane function.
[0357] The second security processing includes at least one of confidentiality processing and integrity processing, and the second security processing is related to an access network node.
[0358] The third security processing includes at least one of integrity processing and confidentiality processing, and the third security processing is related to an access network node.
[0359] The transceiver module can be understood as including a receiving module and a sending module.
[0360] Optionally, the first information further includes a third security parameter, and the first security processing of the core network user plane function is based on the third security parameter.
[0361] Optionally, the fourth indication information is used for at least one of:
[0362] Indicating to perform the first security processing;
[0363] Indicating to stop the first security processing;
[0364] Indicating to expect to perform the first security processing;
[0365] Indicating to expect to stop the first security processing.
[0366] Optionally, the transceiver module is used for:
[0367] Obtaining or receiving subscription information from a unified data management entity (UDM);
[0368] Performing the third operation based on the subscription information.
[0369] Optionally, the transceiver module is used for:
[0370] Receiving second indication information from a terminal;
[0371] Performing the third operation based on the second indication information;
[0372] The second indication information is related to at least one of security collaborative processing of user plane data, collaborative processing of security parameters, the first security parameter, a core network user plane function, first security processing of user plane data, a capability of a terminal, and an expectation or request of the terminal.
[0373] The capability of the terminal is related to at least one of security collaborative processing of user plane data, collaborative processing of security parameters, the first security parameter, a core network user plane function, and the first security processing.
[0374] The expectation or request of the terminal is related to at least one of a security coordination process of user plane data, a security parameter coordination process, the first security parameter, a core network user plane function, and the first security process.
[0375] Optionally, the receiving module is configured to:
[0376] receive fifth indication information from the core network user plane function, the fifth indication information being used to indicate that the core network user plane function performs or stops the first security process;
[0377] based on the fifth indication information, perform the sending of the first indication information to the terminal.
[0378] Optionally, the apparatus of the embodiment of the present application further includes:
[0379] a second sending module configured to send second information to an access network node based on at least one of the first indication information, the fourth indication information, and the fifth indication information, the second information including sixth indication information, the sixth indication information being used to indicate any one of the following:
[0380] to perform a second security process;
[0381] to stop the second security process;
[0382] to perform a third security process;
[0383] to stop the third security process.
[0384] Optionally, in a case where at least one of the first indication information, the fourth indication information, and the fifth indication information is used to indicate that the user plane data is subjected to the first security process based on the first security parameter, the sixth indication information is used to indicate that the user plane data is subjected to the second security process based on a second security parameter, or is used to indicate that the user plane data is subjected to the third security process based on the second security parameter.
[0385] Or, in a case where at least one of the first indication information, the fourth indication information, and the fifth indication information is used to indicate that the user plane data is subjected to the first security process based on the first security parameter, the sixth indication information is used to indicate that the user plane data is subjected to the second security process based on the second security parameter, or is used to indicate that the user plane data is subjected to the third security process based on the second security parameter.
[0386] Optionally, the second information further includes:
[0387] second PDU session information, the sixth indication information being related to a PDU session indicated by the second PDU session information.
[0388] Optionally, the sixth indication information further comprises:
[0389] Seventh indication information, the seventh indication information is used for indicating at least one of confidentiality processing and integrity processing.
[0390] Optionally, the apparatus further comprises:
[0391] A second receiving module, configured to receive the first indication information from a second network node.
[0392] Optionally, the first indication information comprises:
[0393] First protocol data unit (PDU) session information, the user plane data is related to a PDU session indicated by the first PDU session information.
[0394] Optionally, at least one of the first indication information, the second indication information, the fourth indication information and the fifth indication information further comprises:
[0395] Third indication information, the third indication information is used for indicating at least one of confidentiality processing and integrity processing.
[0396] The above scheme of the embodiments of the present application achieves the purpose of negotiating whether to enable the user plane security function between the terminal and the core network function, and can also determine whether to enable or close the user plane security function between the terminal and the access network node, thereby achieving the purpose of coordinating the user plane security function between the terminal and the core network and the user plane security function between the terminal and the access network node.
[0397] The information transmission apparatus provided by the embodiments of the present application can implement each process implemented by the method embodiments of FIGS. 2 to 5 and achieve the same technical effects. To avoid repetition, details are not described herein.
[0398] As shown in FIG. 8, the embodiments of the present application further provide a communication device 800, which comprises a processor 801 and a memory 802, and the memory 802 stores programs or instructions executable on the processor 801. For example, when the communication device 800 is a terminal, the programs or instructions are executed by the processor 801 to implement each step of the information transmission method embodiments performed by the terminal described above, and the same technical effects can be achieved. When the communication device 800 is a network side device, the programs or instructions are executed by the processor 801 to implement each step of the information transmission method embodiments performed by the first network node described above, and the same technical effects can be achieved. To avoid repetition, details are not described herein.
[0399] The embodiment of the present application further provides a terminal comprising a processor and a communication interface, wherein the communication interface is coupled with the processor, and the processor is used to run programs or instructions to realize the steps in the method embodiment shown in FIG. 2. The terminal embodiment corresponds to the terminal-side method embodiment described above, and each implementation process and implementation manner of the method embodiment can be applied to the terminal embodiment, and the same technical effects can be achieved. The terminal can be the information transmission device shown in FIG. 6. Specifically, FIG. 9 is a schematic diagram of the hardware structure of a terminal for implementing the embodiment of the present application.
[0400] The terminal 900 includes, but is not limited to, at least part of components such as a radio frequency unit 901, a network module 902, an audio output unit 903, an input unit 904, a sensor 905, a display unit 906, a user input unit 907, an interface unit 908, a memory 909, and a processor 910.
[0401] Those skilled in the art can understand that the terminal 900 can further include a power supply (such as a battery) for supplying power to each component, and the power supply can be logically connected with the processor 910 through a power management system, so as to realize functions such as management of charging, discharging, and power consumption management through the power management system. The terminal structure shown in FIG. 9 does not constitute a limitation on the terminal, and the terminal can include more or fewer components than those shown, or combine certain components, or different component arrangements, which will not be described here.
[0402] It should be understood that in the embodiment of the present application, the input unit 904 can include a graphics processor 9041 and a microphone 9042, and the graphics processor 9041 processes image data of a still picture or a video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 906 can include a display panel 9061, which can be configured in the form of a liquid crystal display, an organic light-emitting diode, etc. The user input unit 907 includes at least one of a touch panel 9071 and other input devices 9072. The touch panel 9071 is also called a touch screen. The touch panel 9071 can include two parts of a touch detection device and a touch controller. The other input devices 9072 can include, but are not limited to, a physical keyboard, function keys (such as volume control keys, on-off keys, etc.), a trackball, a mouse, a joystick, etc., which will not be described here.
[0403] In the embodiment of the present application, the radio frequency unit 901 can transmit downlink data from the network side device to the processor 910 for processing, and can send uplink data to the network side device. Generally, the radio frequency unit 901 includes, but is not limited to, an antenna, an amplifier, a transceiver, a coupler, a low-noise amplifier, a duplexer, etc.
[0404] The memory 909 can be used to store software programs or instructions and various data. The memory 909 can mainly include a first storage area storing programs or instructions and a second storage area storing data, wherein the first storage area can store an operating system, application programs or instructions required by at least one function (such as a sound playing function, an image playing function, etc.), and the like. In addition, the memory 909 can include a volatile memory or a non-volatile memory. The non-volatile memory can be a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable PROM (EPROM), an Electrically EPROM (EEPROM), or a flash memory. The volatile memory can be a Random Access Memory (RAM), a Static RAM (SRAM), a Dynamic RAM (DRAM), a Synchronous DRAM (SDRAM), a Double Data Rate SDRAM (DDR SDRAM), an Enhanced SDRAM (ESDRAM), a Synch link DRAM (SLDRAM), and a Direct Rambus RAM (DRRAM). The memory 909 in the embodiments of the present application includes but is not limited to these and any other suitable types of memory.
[0405] The processor 910 can include one or more processing units; optionally, the processor 910 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and an application program, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It can be understood that the above-mentioned modem processor can also not be integrated into the processor 910.
[0406] The radio frequency unit 901 is configured to receive first indication information sent by a first network node.
[0407] The processor 910 is configured to perform at least one of a first operation and a second operation according to the first indication information.
[0408] The first operation includes any one of the following:
[0409] Generating a first security parameter;
[0410] invalidating the first security parameter;
[0411] generating the first security parameter and invalidating the second security parameter;
[0412] invalidating the first security parameter and generating the second security parameter;
[0413] The second operation comprises any one of the following:
[0414] performing first security processing on the user plane data based on the first security parameter;
[0415] performing first security processing on the user plane data based on the first security parameter, and stopping second security processing on the user plane data based on the second security parameter;
[0416] performing first security processing on the user plane data based on the first security parameter, and performing third security processing on the user plane data based on the second security parameter;
[0417] stopping first security processing on the user plane data based on the first security parameter;
[0418] stopping first security processing on the user plane data based on the first security parameter, and performing second security processing on the user plane data based on the second security parameter;
[0419] stopping first security processing on the user plane data based on the first security parameter, and stopping third security processing on the user plane data based on the second security parameter;
[0420] The first security parameter is related to a core network user plane function.
[0421] The second security parameter is related to an access network node.
[0422] The first security processing comprises at least one of confidentiality processing and integrity processing.
[0423] The second security processing comprises at least one of confidentiality processing and integrity processing.
[0424] The third security processing comprises at least one of integrity processing and confidentiality processing.
[0425] In the embodiments of the present application, a terminal receives first indication information sent by a first network node; and at least one of a first operation and a second operation is performed according to the first indication information. Based on the first operation, a first security parameter related to a core network user plane function can be generated or invalidated, or based on the first operation, a second security parameter related to an access network node can be generated or invalidated on the basis of generating or invalidating the first security parameter related to the core network user plane function; based on the second operation, a first security processing related to the core network user plane function can be started or stopped, or a second security processing or a third security processing related to the access network node can be started or stopped on the basis of starting or stopping the first security processing related to the core network user plane function, so that based on at least one of the first operation and the second operation, it can be determined whether to enable a user plane security function between the terminal and the core network function, that is, the purpose of negotiating whether to enable the user plane security function between the terminal and the core network function is achieved, and it can also be determined whether to enable or disable a user plane security function between the terminal and the access network node, so that the purpose of coordinating the user plane security function between the terminal and the core network and the user plane security function between the terminal and the access network node is achieved.
[0426] Optionally, before the receiving of the first indication information sent by the first network node, the method further includes:
[0427] sending, to the first network node, second indication information, the second indication information being related to at least one of the first security parameter, the core network user plane function, the first security processing of the user plane data, the security coordination processing of the user plane data, the coordination processing of the security parameter, the capability of the terminal, and the expectation or request of the terminal;
[0428] wherein the capability of the terminal is related to at least one of the security coordination processing of the user plane data, the coordination processing of the security parameter, the first security parameter, the core network user plane function, and the first security processing;
[0429] the expectation or request of the terminal is related to at least one of the security coordination processing of the user plane data, the coordination processing of the security parameter, the first security parameter, the core network user plane function, and the first security processing.
[0430] Optionally, at least one of the first indication information or the second indication information further includes:
[0431] third indication information, the third indication information being used to indicate at least one of a confidentiality processing and an integrity processing.
[0432] Optionally, the first indication information includes:
[0433] First protocol data unit (PDU) session information, wherein the user plane data is related to a PDU session indicated by the first PDU session information.
[0434] Optionally, the first security parameter or the second security parameter respectively comprises at least one of:
[0435] Key information, count information.
[0436] It can be understood that the implementation processes of the implementation manners mentioned in the embodiments can refer to the related descriptions of the method embodiments and achieve the same or corresponding technical effects. To avoid repetition, they will not be described here again.
[0437] The embodiments of the application further provide a network side device, comprising a processor and a communication interface, the communication interface and the processor are coupled, the processor is used to run programs or instructions, and the steps of the method embodiments shown in FIG. 3 are realized. The network side device embodiment corresponds to the network side device method embodiment described above, and each implementation process and implementation manner of the above method embodiments can be applied to the network side device embodiment, and the same technical effects can be achieved.
[0438] Specifically, the embodiments of the application further provide a network side device, which can be the information transmission apparatus shown in FIG. 7. As shown in FIG. 10, the network side device 1000 comprises an antenna 101, a radio frequency device 102, a baseband device 103, a processor 104 and a memory 105. The antenna 101 is connected with the radio frequency device 102. In the uplink direction, the radio frequency device 102 receives information through the antenna 101, and sends the received information to the baseband device 103 for processing. In the downlink direction, the baseband device 103 processes the information to be sent and sends it to the radio frequency device 102, and the radio frequency device 102 processes the received information and sends it out through the antenna 101.
[0439] The method performed by the network side device in the above embodiments can be implemented in the baseband device 103, which comprises a baseband processor.
[0440] The baseband device 103 may, for example, comprise at least one baseband board, and a plurality of chips are arranged on the baseband board, as shown in FIG. 10. One of the chips is, for example, a baseband processor, which is connected with the memory 105 through a bus interface to call the programs in the memory 105 and perform the network device operations shown in the above method embodiments.
[0441] The network side device can further comprise a network interface 106, which is, for example, a common public radio interface (Common Public Radio Interface, CPRI).
[0442] Specifically, the network side device 1000 of the embodiment of the present application further includes instructions or programs stored on the storage 105 and executable on the processor 104, the processor 104 invokes the instructions or programs in the storage 105 to execute the method performed by each module shown in FIG. 7 and achieve the same technical effects, to avoid repetition, and thus will not be described here.
[0443] Specifically, the embodiment of the present application further provides a network side device. As shown in FIG. 11, the network side device 1100 includes a processor 1101, a network interface 1102 and a storage 1103. The network side device can be the information transmission apparatus shown in FIG. 7. Wherein, the network interface 1102 is, for example, a common public radio interface (common public radio interface, CPRI).
[0444] Specifically, the network side device 1100 of the embodiment of the present application further includes instructions or programs stored on the storage 1103 and executable on the processor 1101, the processor 1101 invokes the instructions or programs in the storage 1103 to execute the method performed by each module shown in FIG. 7 and achieve the same technical effects, to avoid repetition, and thus will not be described here.
[0445] The embodiment of the present application further provides a readable storage medium, the readable storage medium stores programs or instructions, the programs or instructions are executed by the processor to realize each process of the above-mentioned information transmission method embodiment, and the same technical effects can be achieved, to avoid repetition, which will not be described here.
[0446] The processor is the processor in the terminal in the above-mentioned embodiments. The readable storage medium includes a computer readable storage medium, such as a computer readable only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc. In some examples, the readable storage medium can be a non-transitory readable storage medium.
[0447] The embodiment of the present application further provides a chip, the chip includes a processor and a communication interface, the communication interface and the processor are coupled, the processor is used to run programs or instructions, realizes each process of the above-mentioned information transmission method embodiment, and the same technical effects can be achieved, to avoid repetition, which will not be described here.
[0448] It should be understood that the chip mentioned in the embodiment of the present application can also be referred to as a system chip, a system chip, a chip system or a system on chip, etc.
[0449] The embodiment of the present application further provides a computer program / program product stored in a storage medium, which is executed by at least one processor to implement the processes of the above information transmission method embodiment, and can achieve the same technical effects. To avoid repetition, details are not described herein.
[0450] The embodiment of the present application further provides an information transmission system, comprising: a terminal and a network side device, wherein the terminal can be used to execute the steps of the information transmission method executed by the terminal as described above, and the network side device can be used to execute the steps of the information transmission method executed by the first network node as described above.
[0451] It should be noted that, in this document, the terms "comprising", "including", or any other variant thereof are intended to cover non-exclusive inclusions, so that processes, methods, articles, or devices that include a series of elements not only include those elements, but also include other elements not explicitly listed, or include elements inherent to such processes, methods, articles, or devices. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of another identical element in the process, method, article, or device comprising the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, but can also include performing functions in a substantially simultaneous manner or in reverse order, for example, the described method can be performed in an order different from that described, and various steps can also be added, omitted or combined. In addition, the features described with reference to certain examples can be combined in other examples.
[0452] From the above description of the embodiments, those skilled in the art can clearly understand that the above embodiment method can be realized by means of computer software product and general hardware platform, of course, it can also be realized by hardware. The computer software product is stored in a storage medium (such as ROM, RAM, magnetic disc, optical disc, etc.), which includes a plurality of instructions for making the terminal or network side device execute the method described in each embodiment of the present application.
[0453] The embodiments of the present application are described above in combination with the drawings, but the present application is not limited to the above specific embodiments, the above specific embodiments are only illustrative, not restrictive, and those skilled in the art can make many forms of embodiments under the inspiration of the present application without departing from the scope of the present application and the protection scope of the claims, and these embodiments all belong to the protection scope of the present application.
Claims
1. A method for information transmission, the method comprising: receiving, by a terminal, first indication information transmitted by a first network node; performing, by the terminal, at least one of a first operation and a second operation according to the first indication information; wherein the first operation comprises any one of: generating a first security parameter; invalidating the first security parameter; generating the first security parameter and invalidating a second security parameter; invalidating the first security parameter and generating the second security parameter; the second operation comprises any one of: performing first security processing on user plane data based on the first security parameter; performing the first security processing on the user plane data based on the first security parameter and stopping second security processing on the user plane data based on a second security parameter; performing the first security processing on the user plane data based on the first security parameter and performing third security processing on the user plane data based on the second security parameter; stopping the first security processing on the user plane data based on the first security parameter; stopping the first security processing on the user plane data based on the first security parameter and performing the second security processing on the user plane data based on the second security parameter; stopping the first security processing on the user plane data based on the first security parameter and stopping the third security processing on the user plane data based on the second security parameter; wherein the first security parameter is related to a core network user plane function; wherein the second security parameter is related to an access network node; wherein the first security processing comprises at least one of confidentiality processing and integrity processing; wherein the second security processing comprises at least one of confidentiality processing and integrity processing; wherein the third security processing comprises at least one of integrity processing and confidentiality processing.
2. The method of claim 1, wherein, before the receiving, by the terminal, the first indication information transmitted by the first network node, the method further comprising: transmitting, by the terminal, second indication information to the first network node, the second indication information being related to at least one of the first security parameter, the core network user plane function, first security processing on user plane data, security coordination processing on user plane data, coordination processing on security parameters, a capability of the terminal, and an expectation or request of the terminal; wherein the capability of the terminal is related to at least one of the security coordination processing on user plane data, the coordination processing on security parameters, the first security parameter, the core network user plane function, and the first security processing; wherein the expectation or request of the terminal is related to at least one of the security coordination processing on user plane data, the coordination processing on security parameters, the first security parameter, the core network user plane function, and the first security processing.
3. The method of claim 1 or 2, wherein, at least one of the first indication information or the second indication information further comprises: third indication information, the third indication information being used to indicate at least one of confidentiality processing and integrity processing.
4. The method according to any one of claims 1 to 3, wherein, the first indication information comprises: first protocol data unit (PDU) session information, wherein the user plane data is related to a PDU session indicated by the first PDU session information.
5. The method according to any one of claims 1 to 4, wherein, the first security parameter or the second security parameter respectively comprises at least one of: key information, and count information.
6. A method for information transmission, the method comprising: The first network node performs a third operation, the third operation comprising at least one of: sending first information to a core network user plane function; sending first indication information to a terminal; wherein the first indication information is related to at least one of: first security parameters, second security parameters, user plane data, first security processing, second security processing, and third security processing; wherein the first information comprises fourth indication information, the fourth indication information being related to first security processing of user plane data; wherein the first security parameters are related to the core network user plane function; wherein the second security parameters are related to an access network node; wherein the first security processing comprises at least one of confidentiality processing and integrity processing, the first security processing being related to the core network user plane function; wherein the second security processing comprises at least one of confidentiality processing and integrity processing, the second security processing being related to the access network node; wherein the third security processing comprises at least one of integrity processing and confidentiality processing, the third security processing being related to the access network node.
7. The method of claim 6, wherein, The first information further comprises third security parameters, and the first security processing is based on the third security parameters.
8. The method of claim 6 or 7, wherein, The fourth indication information is used for at least one of: indicating to perform the first security processing; indicating to stop the first security processing; indicating to expect to perform first security processing; indicating to expect to stop the first security processing.
9. The method according to any one of claims 6 to 8, wherein, The performing the third operation comprises: obtaining or receiving subscription information from a unified data management entity (UDM); performing the third operation based on the subscription information.
10. The method according to any one of claims 6 to 9, wherein, The performing the third operation comprises: receiving second indication information from a terminal; performing the third operation based on the second indication information; wherein the second indication information is related to at least one of: security coordination processing of user plane data, coordination processing of security parameters, the first security parameters, the core network user plane function, the first security processing of user plane data, a capability of the terminal, an expectation or request of the terminal; wherein the capability of the terminal is related to at least one of: security coordination processing of user plane data, coordination processing of security parameters, the first security parameters, the core network user plane function, and the first security processing; wherein the expectation or request of the terminal is related to at least one of: security coordination processing of user plane data, coordination processing of security parameters, the first security parameters, the core network user plane function, and the first security processing.
11. The method according to any one of claims 6-10, wherein, The sending first indication information to a terminal comprises: receiving fifth indication information from the core network user plane function, the fifth indication information being used to indicate the core network user plane function to perform or stop the first security processing; performing the sending first indication information to a terminal based on the fifth indication information.
12. The method according to any one of claims 6 to 11, wherein, Further comprising: sending second information to an access network node based on at least one of the first indication information, the fourth indication information, and the fifth indication information, the second information comprising sixth indication information, the sixth indication information being used for any one of: indicating to perform second security processing; indicating to stop second security processing; indicating to perform third security processing; indicating to stop third security processing.
13. The method of claim 12, wherein, In a case that the at least one of the first indication information, the fourth indication information and the fifth indication information indicates to perform the first security processing on the user plane data based on the first security parameter, the sixth indication information is used to indicate to stop performing the second security processing on the user plane data based on the second security parameter, or is used to indicate to perform the third security processing on the user plane data based on the second security parameter. Or, in a case that the at least one of the first indication information, the fourth indication information and the fifth indication information indicates to stop performing the first security processing on the user plane data based on the first security parameter, the sixth indication information is used to indicate to perform the second security processing on the user plane data based on the second security parameter, or is used to indicate to stop performing the third security processing on the user plane data based on the second security parameter.
14. The method of claim 12 or 13, wherein, The second information further includes: Second PDU session information, the sixth indication information is related to a PDU session indicated by the second PDU session information.
15. The method according to any one of claims 12 to 14, wherein, The sixth indication information further includes: Seventh indication information, the seventh indication information is used to indicate at least one of the confidentiality processing and the integrity processing.
16. The method of claim 6, wherein, The method further includes: Receiving the first indication information from a second network node.
17. The method of any one of claims 6 to 16, wherein, The first indication information includes: First protocol data unit (PDU) session information, the user plane data is related to a PDU session indicated by the first PDU session information.
18. The method of any one of claims 6 to 17, wherein, At least one of the first indication information, the second indication information, the fourth indication information and the fifth indication information further includes: Third indication information, the third indication information is used to indicate at least one of the confidentiality processing and the integrity processing. 19.An information transmission apparatus, comprising: a first receiving module, configured to receive first indication information sent by a first network node; a processing module, configured to perform at least one of a first operation and a second operation according to the first indication information; wherein the first operation includes any one of: generating a first security parameter; invalidating the first security parameter; generating the first security parameter and invalidating a second security parameter; invalidating the first security parameter and generating the second security parameter; the second operation includes any one of: performing first security processing on user plane data based on the first security parameter; performing the first security processing on the user plane data based on the first security parameter and stopping performing second security processing on the user plane data based on a second security parameter; performing the first security processing on the user plane data based on the first security parameter and performing third security processing on the user plane data based on the second security parameter; stopping performing the first security processing on the user plane data based on the first security parameter; stopping performing the first security processing on the user plane data based on the first security parameter and performing the second security processing on the user plane data based on the second security parameter; stopping performing the first security processing on the user plane data based on the first security parameter and stopping performing the third security processing on the user plane data based on the second security parameter; wherein the first security parameter is related to a core network user plane function; wherein the second security parameter is related to an access network node; The first security processing includes at least one of confidentiality processing and integrity processing. The second security processing includes at least one of confidentiality processing and integrity processing. The third security processing includes at least one of integrity processing and confidentiality processing.
20. The apparatus of claim 19, wherein, Further comprising: The first sending module is configured to send second indication information to the first network node, the second indication information being related to at least one of the first security parameter, the core network user plane function, the first security processing of the user plane data, the security collaborative processing of the user plane data, the collaborative processing of the security parameter, the capability of the terminal, and the expectation or request of the terminal. The capability of the terminal is related to at least one of the security collaborative processing of the user plane data, the collaborative processing of the security parameter, the first security parameter, the core network user plane function, and the first security processing. The expectation or request of the terminal is related to at least one of the security collaborative processing of the user plane data, the collaborative processing of the security parameter, the first security parameter, the core network user plane function, and the first security processing. 21.An information transmission apparatus, comprising: a transceiver configured to perform a third operation, the third operation comprising at least one of: sending first information to a core network user plane function; sending first indication information to a terminal; wherein the first indication information is related to at least one of: a first security parameter, a second security parameter, user plane data, first security processing, second security processing, and third security processing; wherein the first information comprises fourth indication information, the fourth indication information being related to the first security processing of the user plane data; wherein the first security parameter is related to the core network user plane function; wherein the second security parameter is related to an access network node; wherein the first security processing comprises at least one of confidentiality processing and integrity processing, the first security processing being related to the core network user plane function; wherein the second security processing comprises at least one of confidentiality processing and integrity processing, the second security processing being related to the access network node; wherein the third security processing comprises at least one of integrity processing and confidentiality processing, the third security processing being related to the access network node.
22. The apparatus of claim 21, wherein, The first information further comprises a third security parameter, and the first security processing is based on the third security parameter.
23. The apparatus of claim 21 or 22, wherein, The fourth indication information is used for at least one of: indicating to perform the first security processing; indicating to stop the first security processing; indicating to expect to perform the first security processing; indicating to expect to stop the first security processing.
24. The apparatus of any one of claims 21 to 23, wherein, The transceiver is configured to: obtain or receive subscription information from a unified data management entity (UDM); perform the third operation based on the subscription information.
25. The apparatus of any one of claims 21 to 24, wherein, The transceiver is configured to: receive second indication information from a terminal; perform the third operation based on the second indication information; wherein the second indication information is related to at least one of the security collaborative processing of the user plane data, the collaborative processing of the security parameter, the first security parameter, the core network user plane function, the first security processing of the user plane data, the capability of the terminal, and the expectation or request of the terminal. The capability of the terminal is related to at least one of security coordination processing of user plane data, security parameter coordination processing, the first security parameter, core network user plane function, and the first security processing. The expectation or request of the terminal is related to at least one of security coordination processing of user plane data, security parameter coordination processing, the first security parameter, core network user plane function, and the first security processing. 26.A terminal comprising a processor and a memory, the memory storing programs or instructions executable on the processor, the programs or instructions, when executed by the processor, implement the steps of the information transmission method according to any one of claims 1 to 5. 27.A network side device comprising a processor and a memory, the memory storing programs or instructions executable on the processor, the programs or instructions, when executed by the processor, implement the steps of the information transmission method according to any one of claims 6 to 18. 28.A readable storage medium, the readable storage medium storing programs or instructions, the programs or instructions, when executed by a processor, implement the steps of the information transmission method according to any one of claims 1 to 5, or implement the steps of the information transmission method according to any one of claims 6 to 18. 29.A computer program product comprising computer instructions, the computer instructions, when executed by a processor, implement the steps of the information transmission method according to any one of claims 1 to 5, or implement the steps of the information transmission method according to any one of claims 6 to 18.
Citation Information
Patent Citations
Encryption mode negotiation method, encryption mode negotiation device and system
CN107396366A
Security protection negotiation method and network element
CN108347416A
Data processing method and device
CN110830993A
Security solution for switching on and off security for up data between UE and ran in 5g
US20200100101A1
Secure Session Method And Apparatus
US20210168594A1