Wireless communication method, terminal device, and network device
By dynamically adjusting the encryption and integrity protection of NAS messages based on message sensitivity in scenarios where multiple operators share network equipment, the problem of increased power consumption of terminal devices is solved, and power consumption optimization is achieved.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
- Filing Date
- 2024-10-15
- Publication Date
- 2026-04-23
AI Technical Summary
In scenarios where multiple operators share network equipment, NAS message transmission between terminal devices and session management network elements requires full encryption and/or integrity protection, which leads to increased power consumption of terminal devices.
The first network element indicates to the terminal device which NAS messages need encryption and/or integrity protection, and only encrypts and/or protects sensitive messages, rather than encrypting all messages, thereby reducing the power consumption of the terminal device.
By dynamically adjusting the encryption and integrity protection strategies for NAS messages, the power consumption of terminal devices is reduced and energy efficiency is improved.
Smart Images

Figure CN2024125054_23042026_PF_FP_ABST
Abstract
Description
Wireless communication methods, terminal devices, and network devices Technical Field
[0001] This application relates to the field of communication technology, and more specifically, to a wireless communication method, terminal device, and network device. Background Technology
[0002] To reduce network investment, multiple operators may share network equipment. In scenarios where multiple operators share network equipment, to ensure that non-access stratum (NAS) messages between the terminal device and the session management network element are not tampered with (e.g., added, deleted, or modified) by other devices (such as mobility management network elements), all messages between the terminal device and the session management network element need to be encrypted and / or protected for integrity. However, this leads to increased power consumption of the terminal device.
[0003] Summary of the Invention
[0004] This application provides a wireless communication method, terminal device, and network device. The various aspects covered by this application are described below.
[0005] In a first aspect, a wireless communication method is provided, comprising: a terminal device receiving a first message sent by a first network element, the first message including first information; wherein the first information is used to indicate whether a first NAS message needs encryption and / or integrity protection, and the first NAS message is used to carry session-related messages.
[0006] In a second aspect, a wireless communication method is provided, comprising: a first network element sending a first message to a terminal device, the first message including first information; wherein the first information is used to indicate whether a first NAS message needs encryption and / or integrity protection, and the first NAS message is used to carry session-related messages.
[0007] Thirdly, a wireless communication method is provided, comprising: a second network element receiving a second message sent by a terminal device, the second message being used to request the establishment of a first session; the second network element sending a response message of the second message to the terminal device, the response message being used to indicate the establishment result of the first session; wherein the establishment result of the first session is determined based on first information, the first information being used to indicate whether a first NAS message needs encryption and / or integrity protection, and the first NAS message being used to carry session-related messages.
[0008] Fourthly, a terminal device is provided, comprising: a first receiving module, configured to receive a first message sent by a first network element, the first message including first information; wherein the first information is used to indicate whether a first NAS message needs encryption and / or integrity protection, and the first NAS message is used to carry session-related messages.
[0009] Fifthly, a network device is provided, the network device being a first network element, the network device comprising: a sending module, configured to send a first message to a terminal device, the first message including first information; wherein the first information is used to indicate whether a first NAS message needs encryption and / or integrity protection, the first NAS message being used to carry session-related messages.
[0010] In a sixth aspect, a network device is provided, the network device being a second network element, the network device comprising: a first receiving module, configured to receive a second message sent by a terminal device, the second message being used to request the establishment of a first session; and a sending module, configured to send a response message of the second message to the terminal device, the response message being used to indicate the establishment result of the first session; wherein the establishment result of the first session is determined based on first information, the first information being used to indicate whether a first NAS message needs encryption and / or integrity protection, the first NAS message being used to carry session-related messages.
[0011] In a seventh aspect, a terminal device is provided, including a processor, a memory, and a communication interface, wherein the memory is used to store one or more computer programs, and the processor is used to invoke the computer programs in the memory to cause the terminal device to perform some or all of the steps in the method of the first aspect.
[0012] Eighthly, a network device is provided, including a processor, a memory, and a communication interface, wherein the memory is used to store one or more computer programs, and the processor is used to invoke the computer programs in the memory to cause the network device to perform some or all of the steps in the method of the second or third aspect.
[0013] Ninthly, embodiments of this application provide a communication system including the aforementioned terminal device and / or network device. In another possible design, the system may further include other devices that interact with the terminal device or network device as described in the embodiments of this application.
[0014] In a tenth aspect, embodiments of this application provide a computer-readable storage medium storing a computer program that causes a computer to perform some or all of the steps in the methods described above.
[0015] Eleventhly, embodiments of this application provide a computer program product, wherein the computer program product includes a non-transitory computer-readable storage medium storing a computer program operable to cause a computer to perform some or all of the steps in the methods described above. In some implementations, the computer program product may be a software installation package.
[0016] In a twelfth aspect, embodiments of this application provide a chip including a memory and a processor, the processor being able to call and run a computer program from the memory to implement some or all of the steps described in the methods of the foregoing aspects.
[0017] In this embodiment, the first network element can indicate to the terminal device whether the NAS message (i.e., the first NAS message) used to carry session-related messages needs encryption and / or integrity protection. Compared with the scheme where the terminal device directly encrypts and / or protects the integrity of all first NAS messages, the terminal device encrypts and / or protects the integrity of the first NAS message based on the first information, which helps to reduce the power consumption of the terminal device. Attached Figure Description
[0018] Figure 1 is an example diagram of the system architecture of a 5G system.
[0019] Figure 2 is another example diagram of the system architecture of a 5G system.
[0020] Figure 3 is an example of a scenario where operators share network equipment.
[0021] Figure 4 is a flowchart illustrating a wireless communication method provided in an embodiment of this application.
[0022] Figure 5 is a flowchart illustrating a wireless communication method provided in another embodiment of this application.
[0023] Figure 6 is a flowchart illustrating a wireless communication method provided in another embodiment of this application.
[0024] Figure 7 is a flowchart illustrating a wireless communication method provided in another embodiment of this application.
[0025] Figure 8 is a flowchart illustrating a wireless communication method provided in another embodiment of this application.
[0026] Figure 9 is a schematic diagram of the structure of the terminal device provided in the embodiment of this application.
[0027] Figure 10 is a schematic diagram of the structure of a network device provided in an embodiment of this application.
[0028] Figure 11 is a schematic diagram of the structure of a network device provided in another embodiment of this application.
[0029] Figure 12 is a schematic structural diagram of the communication device provided in an embodiment of this application. Detailed Implementation
[0030] The technical solutions in this application will now be described with reference to the accompanying drawings.
[0031] Figures 1 and 2 are schematic diagrams of the communication system architecture applicable to the embodiments of this application. The communication system may include terminal equipment, access network (AN) equipment, and network elements in the core network.
[0032] It should be understood that the technical solutions of the embodiments of this application can be applied to various communication systems, such as: 5th generation (5G) systems or new radio (NR), long term evolution (LTE) systems, LTE frequency division duplex (FDD) systems, LTE time division duplex (TDD) systems, etc. The technical solutions provided in this application can also be applied to future communication systems, such as 6th generation mobile communication systems, satellite communication systems, and so on.
[0033] The terminal device in this application embodiment can also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station (MS), MT, remote station, remote terminal, mobile device, user terminal, terminal, wireless terminal, user agent, or user device. The terminal device in this application embodiment can be a device that provides voice and / or data connectivity to a user, and can be used to connect people, objects, and machines, such as a handheld device with wireless connectivity, vehicle-mounted device, etc. The terminal devices in the embodiments of this application can be mobile phones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, etc. Optionally, the terminal device can be used to act as a base station. For example, the terminal device can act as a dispatching entity, providing sidelink signals between terminal devices in vehicle-to-everything (V2X) or device-to-device (D2D) communications. For example, cellular phones and cars communicate with each other using sidelink signals. Cellular phones and smart home devices communicate without relaying communication signals through base stations.
[0034] Access network equipment refers to devices that connect terminal devices to a wireless network. They are primarily responsible for air interface-side radio resource management, Quality of Service (QoS) management, data compression, and encryption. Access network equipment can also be called radio access network (RAN) equipment, such as a base station. A base station can broadly encompass, or be replaced by, various names including: NodeB, evolved NodeB (eNB), next-generation NodeB (gNB), relay station, access point, transmitting and receiving point (TRP), transmitting point (TP), master eNB (MeNB), secondary eNB (SeNB), multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. A base station can be a macro base station, micro base station, relay node, donor node, or similar entities, or combinations thereof. A base station can also refer to a communication module, modem, or chip installed within the aforementioned equipment or apparatus. A base station can also be a mobile switching center, a device that performs base station functions in D2D, V2X, and machine-to-machine (M2M) communications, a network-side device in a 6G network, or a device that performs base station functions in future communication systems. Base stations can support networks using the same or different access technologies. The embodiments of this application do not limit the specific technologies or device forms used in the access network equipment.
[0035] Base stations can be fixed or mobile. For example, a helicopter or drone can be configured to act as a mobile base station, and one or more cells can move depending on the location of the mobile base station. In other examples, a helicopter or drone can be configured as a device to communicate with another base station.
[0036] In some deployments, the access network device in this application embodiment may refer to a CU or a DU, or the access network device may include both a CU and a DU. The gNB may also include an AAU.
[0037] The types of network elements in the core network can include user plane function (UPF) network elements, access and mobility management function (AMF) network elements, session management function (SMF) network elements, policy control function (PCF) network elements, application function (AF), data network (DN), network slice selection function (NSSF), authentication server function (AUSF), unified data management (UDM), network exposure function (NEF), network repository function (NRF), and network slice-specific authentication and authorization function (NSSAAF). Among these, UPF network elements are primarily responsible for user data transmission. The other network elements, which can be referred to as control plane function network elements, are mainly responsible for authentication, authorization, registration management, session management, mobility management, and policy control to ensure reliable and stable transmission of user data.
[0038] UPF network elements can be used to forward and receive data from terminal devices. For example, a UPF network element can receive service data from the data network through the N6 interface and transmit it to the terminal device through the access network equipment. Data transmission between the UPF network element and the access network equipment can occur through the N3 interface. The UPF network element can also receive user data from the terminal device through the access network equipment and forward it to the data network. The transmission resources allocated and scheduled by the UPF network element for the terminal device are managed and controlled by the SMF network element. The bearer between the terminal device and the UPF network element can include: the user plane connection between the UPF network element and the access network equipment, and the channel established between the access network equipment and the terminal device. The user plane connection refers to the QoS flow of transmitted data that can be established between the UPF network element and the access network equipment.
[0039] The AMF (Active Network Provider) element can be used to manage terminal device access to the core network, such as location updates, network registration, access control, mobility management, and attachment / detachment. Besides mobility management, the AMF element is also responsible for forwarding session-related messages (such as session management messages) between the terminal device and the SMF element. In other words, the SMF sends session-related messages to the terminal device through the AMF, and the terminal device sends session-related messages to the SMF through the AMF. As one implementation, the terminal device can send an uplink NAS transport message to the AMF, carrying a payload container and payload type. The payload type indicates whether the payload container is a session management (SM) container or another type. If the payload type indicates that the payload container is an SM container, the AMF forwards the SM container to the SMF. Similarly, the SMF can send an SM container to the AMF, and the AMF can then carry the payload container and payload type in a downlink NAS transport message. It should be understood that the aforementioned session-related messages are carried within the SM container.
[0040] SMF network elements can be used to select user plane network elements for terminal devices, redirect user plane network elements for terminal devices, assign Internet Protocol (IP) addresses to terminal devices, establish bearers (also known as sessions) between terminal devices and UPF network elements, modify and release sessions, and control QoS. After a terminal device accesses the core network through the Uu port, it can establish Protocol Data Unit (PDU) sessions for data transmission under the control of the SMF.
[0041] PCF network elements are used to provide policies, such as QoS policies and slice selection policies, to AMF and SMF network elements. In other words, PCF network elements are responsible for formulating policies related to mobility management, session management, and billing of terminal devices.
[0042] AF network elements are used to interact with network elements in the 3GPP core network to support the routing of application-affected data, access network exposure functions, and interact with PCF network elements for policy control, etc.
[0043] A Data Network (DN) can provide data services to users for networks such as IP Multimedia Service (IMS) and the Internet. A DN can contain various application servers that provide different application services, such as carrier services, Internet access, or third-party services. These application servers can implement Application Server (AF) functionality.
[0044] NSSF is used for network slice selection and supports the following functions: selecting a set of network slice instance examples to serve the end device; determining allowed network slice selection assistance information (NSSAI), and, when necessary, determining the mapping to the subscribed single-network slice selection assistance information (S-NSSAI); determining the configured NSSAI, and, when necessary, determining the mapping to the subscribed S-NSSAI; determining the set of AMFs that may be used to query the end device, or determining a list of candidate AMFs based on the configuration.
[0045] AUSF is used to receive AMF requests for authentication of terminal devices. It requests a key from UDM and then forwards the issued key to AMF for authentication processing.
[0046] UDM includes functions such as generating and storing user subscription data and managing authentication data, and supports interaction with external third-party servers.
[0047] NEF is used for capability exposure, meaning that based on NEF, network capabilities can be exported to external networks. Untrusted external applications can access core network data through NEF to ensure network security. NEF can provide functions such as QoS capability exposure for external applications, event subscription, and AF request distribution.
[0048] The Network Request Forwarder (NRF) is used for the registration, management, and status monitoring of network elements in the core network, thereby achieving automated management of these elements. When a network element in the core network starts up, it must register with the NRF before it can provide services. Registration information may include, for example, the type, address, and service list of the network element.
[0049] In addition, some networks (such as 5G networks) have added network data analytics function (NWDAF) to the core network. Based on NWDAF, data can be collected from various network elements and network management systems in the core network, and big data statistics, analysis or intelligent data analysis can be performed to obtain network-side analysis or prediction data, thereby assisting various network elements to more effectively control terminal device access based on the data analysis results.
[0050] In some communication systems (such as 5G systems), network elements in the core network can also be called network functions (NFs).
[0051] In the communication systems shown in Figures 1 and 2, the terminal device can connect to the access network device via the Uu port to establish an access layer connection, exchanging access layer messages and wireless data. The terminal device can also connect to the AMF via the N1 interface to establish a NAS connection and exchange NAS messages.
[0052] The network elements in Figures 1 and 2 can be network components in hardware devices, software functions running on dedicated hardware, or virtualization functions implemented on a platform (e.g., a cloud platform). It should be noted that the network architectures shown in Figures 1 and 2 are merely illustrative examples of the network elements included in the overall network architecture. In this application embodiment, the network elements included in the overall network architecture are not limited.
[0053] Those skilled in the art will understand that the network architecture shown in Figures 1 and 2 does not constitute a limitation on the network architecture. In specific implementations, the network architecture may include more or fewer network elements than shown in the figures, or combine certain network elements, etc. It should be understood that AN or RAN is represented in Figures 1 and 2 as (R)AN.
[0054] In some scenarios, network devices and terminal devices can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; and they can also be deployed in the air on airplanes, balloons, and satellites. This application does not limit the scenarios in which the network devices and terminal devices are located.
[0055] By way of example and not limitation, in the embodiments of this application, the network device may have mobility characteristics; for example, the network device may be a mobile device. In some embodiments of this application, the network device may be a satellite or a balloon station. For example, the satellite may be a low Earth orbit (LEO) satellite, a medium Earth orbit (MEO) satellite, a geostationary earth orbit (GEO) satellite, a high elliptical orbit (HEO) satellite, etc. In some embodiments of this application, the network device may also be a base station located on land, water, or other similar locations.
[0056] Currently, in order to reduce investment in networks (such as 5G networks or future networks (such as 6G networks)), multiple operators may share network equipment. The following section, with reference to Figure 3, describes a scenario where multiple operators share network equipment.
[0057] As shown in Figure 3, operator X, acting as the hosting operator, will deploy NR base stations or 6G base stations, and deploy the AMF (Activity Management Function) in the 5G network or the centralized control point in the 6G network. The centralized control point in the 6G network can be, for example, a 6G control plane network element or a 6G mobility management network element (similar to the AMF in the 5G network). In some embodiments, the hosting operator may also be referred to as, or understood as, a shared operator.
[0058] In this way, the participating operator shown in Figure 3 can deploy network equipment other than NR base stations or AMFs in the 5G network only in a certain region, or the participating operator can deploy network equipment other than 6G base stations or 6G mobility management elements in the 6G network only in a certain region. The network jointly deployed by operator X and the participating operator can be called a shared network.
[0059] In scenarios where multiple operators share network equipment, NR or 6G base stations in the shared network need to broadcast the public land mobile network (PLMN) identifier of the participating operators so that the terminal equipment of the participating operators can select the network for access.
[0060] As mentioned above, NAS messages between the terminal device and the session management network element (such as the SMF or the session management network element in 6G) are transmitted through the mobility management network element (such as the AMF or the centralized control point in 6G). While the mobility management network element does not need to parse the SM container, it can tamper with (e.g., add, delete, or modify) the content of the SM container. Furthermore, neither the terminal device nor the session management network element can know whether the mobility management network element has tampered with the content of the SM container during transmission.
[0061] When the mobility management network element (MLE) and session management network element (SLE) belong to the same operator, a trust relationship can be considered to exist between them, as well as other network elements that need to send messages to the terminal device through the MLE. However, in scenarios where multiple operators share network equipment, the MLE and SLE may belong to different operators, and a trust relationship may not exist between them. To ensure that NAS messages between the terminal device and the SLE are not tampered with by other devices, one possible implementation is to encrypt and / or protect the integrity of all messages between the terminal device and the SLE. This means that the terminal device needs to encrypt and / or protect the integrity of all SM containers, which increases the power consumption of the terminal device.
[0062] To address the aforementioned issues, this application provides a wireless communication method, a terminal device, and a network device. In an embodiment of this application, a first network element can indicate to the terminal device via first information whether NAS messages used to carry session-related messages (i.e., the first NAS messages hereinafter) require encryption and / or integrity protection. Compared to a scheme where the terminal device directly encrypts and / or protects the integrity of all first NAS messages, encrypting and / or protecting the integrity of first NAS messages based on first information by the terminal device helps reduce the power consumption of the terminal device.
[0063] The first piece of information will be introduced below.
[0064] In some embodiments, considering that some session-related messages are not sensitive (e.g., do not contain privacy information and / or high-value information), it is not necessary to encrypt and / or protect the integrity of such session-related messages. In this case, the first network element may instruct, based on the first information, not to encrypt and / or protect the integrity of such session-related messages.
[0065] In some embodiments, considering that some session-related messages are sensitive, it is necessary to encrypt and / or protect their integrity. In this case, the first network element may instruct the encryption and / or integrity protection of such session-related messages based on the first information instruction.
[0066] In some embodiments, the first information can be carried separately in a NAS container. Alternatively, the first information can be a single information element (IE). For example, the first information can be carried separately in a 6G session policy container.
[0067] In some embodiments, the first information may be carried together with other information in a NAS container. For example, the first information may be carried together with other information in a terminal device policy container. Alternatively, the first information may be carried together with other information in a 6G session policy container.
[0068] This application does not specifically limit the implementation of the first information indicating whether a first NAS message needs encryption and / or integrity protection. As one possible implementation, the first information can indicate whether different types of first NAS messages require encryption and / or integrity protection respectively. For example, the first information can indicate that PDU session establishment request messages and PDU session modification request messages require encryption and / or integrity protection, while PDU session modification confirmation messages and PDU session deletion request messages do not require encryption and / or integrity protection, etc. As another possible implementation, the first information can indicate whether a first NAS message needs encryption and / or integrity protection through a first mapping relationship. That is, the first information can include a first mapping relationship, which can be used to indicate whether a first NAS message needs encryption and / or integrity protection. The first mapping relationship is described below.
[0069] In some embodiments, the first mapping relationship can be used to indicate the mapping relationship between a first attribute and whether a first NAS message requires encryption and / or integrity protection. The first attribute can be used to indicate the session attributes of the first NAS message. It should be noted that the session attributes of the first NAS message can be understood as the first NAS message indicating one or more of these session attributes, and the values of the session attributes indicated in different first NAS messages may be the same or different.
[0070] This application does not specifically limit the first attribute, as long as it can indicate the session attribute of the first NAS message. For example, the first attribute may include one or more of the following attributes: network slice identifier, data network name, session and service continuity mode, and session type.
[0071] In some embodiments, a network slice identifier can be used to identify the network slice associated with a PDU session. For example, the network slice identifier can be single network slice selection assistance information (S-NSSAI).
[0072] In some embodiments, the data network name (DNN) can be used to identify the data network to which the PDU session is connected.
[0073] In some embodiments, session and service continuity (SSC) modes can be used to define how to maintain the continuity of a PDU session during a mobility event. For example, SSC modes can include SSC mode 1, SSC mode 2, and SSC mode 3. For a PDU session in SSC mode 1, the network maintains the UPF that acted as the PDU session anchor at the time the PDU session was established. For a PDU session in SSC mode 2, if the network needs to migrate the anchor UPF and service SMF, to maintain service continuity, the network will allow the terminal device to release the PDU session and immediately initiate a new PDU session establishment process; both PDU sessions will connect to the same data network. For a PDU session in SSC mode 3, the network allows a connection to be established through a new PDU session anchor before the connection between the terminal device and the previous PDU session anchor is released.
[0074] In some embodiments, the session type can be used to indicate the session type of a PDU session. This application does not limit the session type of a PDU session. Exemplarily, the session type of a PDU session may include one or more of the following: a session for transmitting IP data, a session for transmitting unstructured data, and a session for transmitting Ethernet frames.
[0075] In some embodiments, a session for transmitting IP data can be indicated by the field "PDU session type-IP". In some embodiments, a session for transmitting IP data can also include multiple session types. For example, a session for transmitting IP data can include one or more of the following session types: Internet Protocol version 4 (IPv4) PDU session, Internet Protocol version 6 (IPv6) PDU session, and IPv4v6 PDU session. Specifically, an IPv4 PDU session supports only IPv4 data transmission, an IPv6 PDU session supports IPv6 data transmission, and an IPv4v6 PDU session supports both IPv4 and IPv6 data transmission.
[0076] In some embodiments, a session for transmitting unstructured data can be indicated by the field "Unstructure".
[0077] In some embodiments, a session for transmitting Ethernet frames can be indicated by the field "Ethernet".
[0078] In some embodiments, the first attribute may include multiple values. In this case, the first information can be used to indicate whether the first NAS message corresponding to each of the multiple values requires encryption and / or integrity protection. For example, the multiple values may include a first value and / or a second value, where the first value corresponds to a first NAS message that requires encryption and / or integrity protection, and the second value corresponds to a first NAS message that does not require encryption and / or integrity protection.
[0079] As an example, the above multiple values include the first value, and the first NAS message corresponding to the first value needs to be encrypted and protected for integrity.
[0080] As another example, the above multiple values include a second value, and the first NAS message corresponding to the second value does not require encryption and integrity protection.
[0081] As yet another example, the above multiple values include a first value (or a second value), and the first NAS message corresponding to the first value (or the second value) needs to be encrypted, but does not need to be protected for integrity.
[0082] As another example, the above multiple values include the first value (or the second value). The first NAS message corresponding to the first value (or the second value) does not need to be encrypted, but it does need to be protected for integrity.
[0083] As another example, the above multiple values include a first value and a second value. The first NAS message corresponding to the first value needs to be encrypted, while the first NAS message corresponding to the second value does not need to be encrypted.
[0084] As another example, the above multiple values include a first value and a second value. The first NAS message corresponding to the first value needs integrity protection, while the first NAS message corresponding to the second value does not need integrity protection.
[0085] As another example, the above multiple values include a first value and a second value. The first NAS message corresponding to the first value needs to be encrypted and protected for integrity, while the first NAS message corresponding to the second value does not need to be encrypted and protected for integrity.
[0086] Taking a network slice identifier as an example, the first NAS message corresponding to network slice identifier 1 may require encryption and / or integrity protection, while the first NAS messages corresponding to network slice identifiers 2 and 3 may not require encryption and / or integrity protection. Alternatively, the first NAS messages corresponding to network slice identifiers 1 and 3 may require encryption and / or integrity protection, while the first NAS message corresponding to network slice identifier 2 may not require encryption and / or integrity protection, and so on.
[0087] Taking a first attribute including a DNN as an example, the first NAS message corresponding to DNN 1 may require encryption and / or integrity protection, while the first NAS messages corresponding to DNN 2 and DNN 3 may not require encryption and / or integrity protection. Alternatively, the first NAS messages corresponding to DNN 1 and DNN 3 may require encryption and / or integrity protection, while the first NAS message corresponding to DNN 2 may not require encryption and / or integrity protection, and so on.
[0088] Taking the first attribute including SSC mode as an example, the first NAS message corresponding to SSC mode 1 may require encryption and / or integrity protection, while the first NAS messages corresponding to SSC mode 2 and SSC mode 3 may not require encryption and / or integrity protection. Alternatively, the first NAS messages corresponding to SSC mode 1 and SSC mode 2 may require encryption and / or integrity protection, while the first NAS message corresponding to SSC mode 3 may not require encryption and / or integrity protection, and so on.
[0089] Taking session type as an example, the first NAS message corresponding to session type 1 may require encryption and / or integrity protection, while the first NAS messages corresponding to session types 2 and 3 may not require encryption and / or integrity protection. Alternatively, the first NAS messages corresponding to session types 1 and 3 may require encryption and / or integrity protection, while the first NAS message corresponding to session type 2 may not require encryption and / or integrity protection, and so on.
[0090] As an example, the first NAS message corresponding to a session used to transmit IP data may require encryption and / or integrity protection, while the first NAS message corresponding to a session used to transmit unstructured data and a session used to transmit Ethernet frames may not require encryption and / or integrity protection.
[0091] As another example, sessions used to transmit IP data and sessions used to transmit unstructured data may require encryption and / or integrity protection, while the first NAS message corresponding to a session used to transmit Ethernet frames may not require encryption and / or integrity protection.
[0092] As yet another example, IPv4 PDU sessions may not require encryption and / or integrity protection, while IPv6 PDU sessions and IPv4v6 PDU sessions may require encryption and / or integrity protection.
[0093] As another example, if the first NAS message includes the field "unstructured", then the first NAS message requires encryption and / or integrity protection; if the first NAS message does not include the field "unstructured", then the first NAS message does not require encryption and / or integrity protection. Alternatively, if the first NAS message includes the field "unstructured", then the first NAS message does not require encryption and / or integrity protection; if the first NAS message does not include the field "unstructured", then the first NAS message requires encryption and / or integrity protection.
[0094] As another example, if the first NAS message includes the field "Ethernet", then the first NAS message requires encryption and / or integrity protection; if the first NAS message does not include the field "Ethernet", then the first NAS message does not require encryption and / or integrity protection. Alternatively, if the first NAS message includes the field "Ethernet", then the first NAS message does not require encryption and / or integrity protection; if the first NAS message does not include the field "Ethernet", then the first NAS message requires encryption and / or integrity protection.
[0095] Taking the first attribute including DNN and SSC modes as an example, the first NAS message corresponding to DNN 1 and SSC mode 1 may require encryption and / or integrity protection, while the first NAS message corresponding to DNN 1 and SSC mode 2 may not require encryption and / or integrity protection. The first NAS message corresponding to DNN 2 and SSC mode 1 may not require encryption and / or integrity protection, and so on.
[0096] Taking the first attribute including network slice identifier, DNN, and SSC mode as an example, the first NAS message corresponding to network slice identifier 1, DNN 1, and SSC mode 1 may require encryption and / or integrity protection, the first NAS message corresponding to network slice identifier 1, DNN 1, and SSC mode 2 may not require encryption and / or integrity protection, and the first NAS message corresponding to network slice identifier 1, DNN 2, and SSC mode 1 may require encryption and / or integrity protection, etc.
[0097] It should be noted that the first attribute can include any one or more combinations of attributes such as network slice identifier, DNN, SSC mode, and session type. For the sake of brevity, other combinations will not be listed.
[0098] In some embodiments, after the terminal device obtains the first mapping relationship (i.e., the first information), when the terminal device needs to send a first NAS message, it can determine whether to encrypt and / or protect the integrity of the first NAS message based on the first attribute carried in the first NAS message to be sent. For example, if the first attribute includes a network slice identifier, and assuming the network slice identifier carried in the first NAS message to be sent is network slice identifier 1, the terminal device can determine whether the first NAS message corresponding to network slice identifier 1 needs to be encrypted and / or protected for integrity based on the first mapping relationship. If so, the terminal device encrypts and / or protects the integrity of the first NAS message before sending it to the second network element. Similarly, if the first attribute includes a network slice identifier and an SSC mode, and assuming the network slice identifier carried in the first NAS message to be sent is network slice identifier 1 and the SSC mode is SSC mode 1, the terminal device can determine whether the first NAS message corresponding to network slice identifier 1 and SSC mode 1 needs to be encrypted and / or protected for integrity based on the first mapping relationship. If so, the terminal device encrypts and / or protects the integrity of the first NAS message before sending it to the second network element.
[0099] In some embodiments, the first information is sent to the terminal device by the first network element after the terminal device registers. Taking the first network element as a policy control network element as an example, after the terminal device registers, the mobility management network element can select the policy control network element and send a policy control creation request message (such as an Npcf_Policy Control_Create Request message) to the policy control network element. Subsequently, the policy control network element can carry the first information in a policy control creation response message (such as an Npcf_Policy Control_Create Response message). Taking the first network element as a unified data management network element as an example, after the terminal device registers, the mobility management network element can select the unified data management network element and send a message (such as a Nudm_UECM_Registration message) to the unified data management network element to request the protection of the terminal device's context management message. Subsequently, the unified data management network element can send a Nudm_SDM_Notification message to the terminal device, which can carry the first information. Taking the first network element as the session management network element as an example, after the terminal device registers, it can send a PDU session establishment request message (such as Nsmf_PDU session_create SM content_request message) to the session management network element to request the establishment of the first session. After that, the session management network element can carry the first information in the PDU session establishment response message (such as Nsmf_PDU session_create SM content_response message).
[0100] The first piece of information has been introduced above. The following section describes the process steps involved in the embodiments of this application.
[0101] Figure 4 is a schematic flowchart of a wireless communication method provided in an embodiment of this application. The method shown in Figure 4 is described from the perspective of the interaction between a terminal device and a first network element and a second network element. The terminal device can be, for example, the terminal device shown in Figure 1 or Figure 2. For ease of understanding, the first network element and the second network element will be described below first.
[0102] In this embodiment, the first network element is a network element used to indicate to the terminal device whether the first NAS message needs encryption and / or integrity protection. This embodiment does not specifically limit the first network element, as long as it can indicate to the terminal device whether the first NAS message needs encryption and / or integrity protection.
[0103] In some embodiments, the first network element can be a network element in the core network.
[0104] In some embodiments, the first network element may include one or more of the following: a policy control network element, a unified data management network element, and a session management network element.
[0105] As an example, the first network element can be a policy control network element. For instance, the first network element can be a PCF network element or a network element in a future communication system that has the same or similar functions as a PCF network element.
[0106] As another example, the first network element can be a unified data management network element. For instance, the first network element can be a UDM network element or a network element in a future communication system that has the same or similar functions as a UDM network element.
[0107] As another example, the first network element can be a session management network element. For example, the first network element can be an SMF network element or a network element in a future communication system that has the same or similar functions as an SMF network element. In some embodiments, when the first network element is a session management network element, the session management network element can first obtain first information from other network elements (such as policy control network elements or unified data management network elements), and then send the first information to the terminal device.
[0108] As another example, the first network element may include a policy control network element and a session management network element. That is, both the policy control network element and the session management network element can indicate to the terminal device whether the first NAS message needs encryption and / or integrity protection.
[0109] As another example, the first network element may include a unified data management network element and a session management network element. That is, both the unified data management network element and the session management network element can indicate to the terminal device whether the first NAS message needs encryption and / or integrity protection.
[0110] In this embodiment, the second network element is the recipient of the first NAS message. Alternatively, the second network element is the recipient of session-related messages.
[0111] In some embodiments, the second network element can be a network element in the core network. For example, the second network element can be a session management network element, such as an SMF, or a network element in a future communication system that has the same or similar functions as an SMF network element.
[0112] In some embodiments, the first network element and the second network element are different network elements. For example, the first network element is a policy control network element, and the second network element is a session management network element. Another example is that the first network element is a unified data management network element, and the second network element is a session management network element.
[0113] In some embodiments, the first network element and the second network element can be the same network element. For example, the first network element and the second network element are the same session management network element.
[0114] The method shown in Figure 4 may include step S410, which will be described below.
[0115] In step S410, the first network element sends a first message to the terminal device. Correspondingly, the terminal device receives the first message sent by the first network element. The first message includes first information. In this way, the terminal device can determine whether to encrypt and / or protect the integrity of the first NAS message based on the first information.
[0116] In this embodiment, the first message may differ depending on the first network element. Taking a policy control network element as an example, the first message can be any type of message sent by the policy control network element to the terminal device, such as an Npcf_Policy Control_Create Response message. Taking a unified data management network element as an example, the first message can be any type of message sent by the unified data management network element to the terminal device, such as a Nudm_SDM_Notification message. Taking a session management network element as an example, the first message can be any type of message sent by the session management network element to the terminal device, such as an Nsmf_PDU session_CreateSMContext_Response message.
[0117] In some embodiments, the first network element can directly send the first message to the terminal device. For example, the first network element can call the service interface of the terminal device to send the first message to the terminal device.
[0118] In some embodiments, the first network element can send a first message to the terminal device through other network elements. For example, the first network element can send the first message to the mobility management network element, and then the mobility management network element sends the first message to the terminal device. It should be noted that the "mobility management network element" in the embodiments of this application can be, for example, an AMF or a centralized control point in a future communication system, that is, the "mobility management network element" can be a network element in a future communication system with the same or similar functions as the AMF.
[0119] In one implementation, when the first network element sends the first message to the terminal device through other network elements, the other network elements can directly forward all the contents of the first message to the terminal device. In another implementation, when the first network element sends the first message to the terminal device through other network elements, the other network elements can forward only a portion of the information in the first message (such as the first information) to the terminal device.
[0120] In some embodiments, when the first network element sends a first message to the terminal device through other network elements, the other network element may carry the first message in a downlink NAS transmission message to send it to the terminal device.
[0121] In the embodiments of this application, the first message includes first information, or in other words, the first message carries first information. The first information can be used to indicate whether the first NAS message needs encryption and / or integrity protection. That is, the first information can be used for the security protection of the first NAS message; therefore, in some embodiments, the first information can also be called or understood as session security information.
[0122] In some embodiments, the first NAS message can be used to carry session-related messages (or session management-related messages, session management messages, etc.). However, the embodiments of this application are not limited to this. For example, the first NAS message can also be used to carry policy control-related messages or other types of messages. As an example, when the first NAS message is a message between the terminal device and the policy control network element, the first NAS message can carry policy control-related messages.
[0123] In some embodiments, the first NAS message may be carried in a NAS container. For example, the first NAS message may be carried in a first NAS container used for session management, i.e., the first NAS container is an SM container. As another example, the first NAS message may be carried in a second NAS container used for policy control, i.e., the second NAS container is a terminal device policy container.
[0124] This application does not specifically limit the first NAS message. Taking the first NAS message as carrying session-related messages as an example, the first NAS message may include one or more of the following: PDU session establishment request message, PDU session modification request message, PDU session modification confirmation message, and PDU session deletion request message.
[0125] In some embodiments, the first message may include other information besides the first information. For example, if the first network element is a policy control network element, the first message may include a terminal device policy container in addition to the first information. If the first network element is a unified data management network element, the first message may include a terminal device parameter container in addition to the first information. If the first network element is a session management network element, the first message may include an SM container and / or a PDU session ID in addition to the first information.
[0126] In some embodiments, after receiving the first message, the terminal device may also send a response message to the first network element to confirm receipt of the first message. Taking the first network element as a unified data management network element as an example, the terminal device may send a transparent container to the unified data management network element to indicate that the terminal device has confirmed receipt of the first message.
[0127] In some embodiments, the method of FIG4 may further include step S420. In step S420, the terminal device sends a first NAS message to the second network element.
[0128] In some embodiments, the first NAS message sent by the terminal device to the second network element may be encrypted and / or protected for integrity based on the first information.
[0129] In some embodiments, when both the first network element and the second network element are session management network elements, the first network element (i.e., the second network element) can indicate the first information during the session establishment process. This will be described below with reference to Figure 5.
[0130] Figure 5 is a flowchart illustrating a wireless communication method according to another embodiment of this application. The method shown in Figure 5 may include steps S510 and S520.
[0131] In step S510, the terminal device sends a second message to the second network element, the second message being used to request the establishment of a first session.
[0132] In some embodiments, the second message may be a NAS message. For example, the second message may be a PDU session establishment request message.
[0133] In some embodiments, the second message may be carried in an SM container.
[0134] In some embodiments, the second message may carry one or more of the following: PDU session identifier, PDU session establishment type, PDU session session type, network slice identifier, DNN, etc.
[0135] In some embodiments, the second message is sent by the terminal device to the second network element through the mobility management network element. For example, the terminal device may send an uplink NAS transmission message to the mobility management network element, which may carry a PDU session identifier, a network slice identifier, a DNN, and the second message. The mobility management network element can then send the second message to the second network element, carrying the second message within an SM container.
[0136] In step S520, the second network element sends a response message of the second message to the terminal device. This response message can be used to indicate the establishment result of the first session. For example, the response message can indicate whether the first session was successfully established or failed to establish.
[0137] In some embodiments, the response message may also carry a reason for the failure when the first session establishment fails. That is, if the second network element refuses to establish the first session, the second network element may carry a reason for refusal (such as carrying a reason value) in the response message of the second message.
[0138] In some embodiments, the establishment result of the first session is determined based on the first information. For example, if the second network element determines that the second message is not encrypted and / or protected for integrity in accordance with the first information, the second network element may refuse to establish the first session.
[0139] In some embodiments, if the second network element refuses to establish the first session, the reason for refusal carried by the second network element in the corresponding message may include "the encryption and / or integrity protection methods corresponding to the second message do not match" or "the encryption and / or integrity protection methods corresponding to the second message are incorrect," meaning the security attributes of the first session do not match. It should be understood that a mismatch in the encryption and / or integrity protection methods corresponding to the second message means that the encryption and / or integrity protection methods corresponding to the second message sent by the terminal device do not match the encryption and / or integrity protection methods corresponding to the second message determined based on the first information. For example, the first information determines that the second message requires encryption and / or integrity protection, but the second message sent by the terminal device does not. Another example is that the first information determines that the second message does not require encryption and / or integrity protection, but the second message sent by the terminal device does.
[0140] In some embodiments, if the encryption and / or integrity protection method corresponding to the second message is incorrect, the rejection reason value carried in the above response message may be "the encryption and / or integrity protection method corresponding to the second message does not match", or it may be an existing rejection reason value. This application embodiment does not limit this.
[0141] In some embodiments, if the encryption and / or integrity protection method corresponding to the second message is incorrect, the above response message may be used to indicate that the second message needs to be encrypted and / or protected based on the first information.
[0142] In some embodiments, the second network element may carry first information in the response message described above. A description of the first information can be found above and will not be repeated here.
[0143] For ease of understanding, the following description uses policy control network element, unified data management network element, and session management network element as examples to illustrate the process of the method in this application. The relevant descriptions of the content involved in the embodiments below (such as the first information) can be found above and will not be repeated hereafter.
[0144] Example 1: The first network element is a policy control network element
[0145] Figure 6 is a flowchart illustrating a wireless communication method according to another embodiment of this application. The method shown in Figure 6 includes steps S601 to S607.
[0146] In step S601, the terminal device sends a registration request message to the mobility management network element.
[0147] In some embodiments, the registration request message may carry one or more of the following information: the identifier of the terminal device, the registration type, and the security capabilities of the terminal device.
[0148] This application does not limit the identifier of the terminal device. For example, the identifier of the terminal device may include one or more of the following: a subscription concealed identifier (SUCI) and a globally unique temporary UE identity (GUTI). As an example, the identifier of the terminal device may be a SUCI. As another example, the identifier of the terminal device may be a 6G-GUTI.
[0149] In step S602, after receiving the registration request, the mobility management network element triggers the authentication process.
[0150] After the authentication process is completed, the mobility management network element can send a security mode command message to the terminal device. This message may carry one or more of the following information: NAS key set identifier (KSI), replayable terminal device security capabilities, integrity algorithm, ciphering algorithm, and a request indication for a complete initial NAS message. Afterwards, the terminal device can send a security mode complete message to the mobility management network element. This message may carry a complete registration request message, which, in addition to the content from step S601, may also include requested slice information, terminal device capability information, etc.
[0151] In step S603, the mobility management network element returns a registration acceptance message to the terminal device. The registration acceptance message may carry a new GUTI (such as 6G-GUTI) and a registration area.
[0152] In step S604, the terminal device sends a registration completion message to the mobility management network element to confirm that the new GUTI has taken effect.
[0153] In step S605, the mobility management network element selects the policy control network element and sends an Npcf_policy control_creation request message to the policy control network element.
[0154] In step S606, the policy control network element returns an Npcf_policy control_creation response message to the mobility management network element. This message may carry the terminal device policy container and the first information.
[0155] In some embodiments, the first information may be a separate IE or part of a terminal device policy container.
[0156] In step S607, the mobility management network element sends a downlink NAS transmission message to the terminal device. This message carries the terminal device's policy container and first information.
[0157] Subsequently, when the terminal device sends the first NAS message to the second network element, it can determine whether the first NAS message needs to be encrypted and / or protected for integrity based on the first information.
[0158] Example 2: The first network element is a unified data management network element.
[0159] Figure 7 is a schematic flowchart of a wireless communication method provided in another embodiment of this application. The method shown in Figure 7 includes steps S701 to S710.
[0160] For details regarding steps S701 to S704, please refer to the above description of steps S601 to S604; they will not be repeated here.
[0161] In step S705, the mobility management network element selects the unified data management network element and sends a Nudm_UECM_registration message to the unified data management network element. This message may carry the identifier of the terminal device and the identifier of the mobility management network element. In some embodiments, the identifier of the terminal device carried in this message may be, for example, a subscription permanent identifier (SUPI).
[0162] In step S706, the unified data management network element returns a Nudm_UECM_registration confirmation message to the mobility management network element.
[0163] In step S707, the unified data management network element sends a Nudm_SDM_notification message to the terminal device. This message may carry the terminal device parameter container and the first information.
[0164] In some embodiments, the first information may be a separate IE or part of a terminal device policy container.
[0165] In step S708, the mobility management network element sends a downlink NAS transmission message to the terminal device. This message carries a terminal device parameter container and first information.
[0166] In step S709, the terminal device sends an uplink NAS transmission message to the mobility management network element. This message carries a transparent container, which contains a positive acknowledgment message from the terminal device.
[0167] In step S710, the mobility management network element sends a Nudm_SDM_info request message to the unified data management network element, which carries the aforementioned transparent container.
[0168] Subsequently, when the terminal device sends the first NAS message to the second network element, it can determine whether the first NAS message needs to be encrypted and / or protected for integrity based on the first information.
[0169] Example 3: The first network element is a session management network element.
[0170] Figure 8 is a flowchart illustrating a wireless communication method according to another embodiment of this application. The method shown in Figure 8 includes steps S701 to S708.
[0171] For details regarding steps S801 to S804, please refer to the above description of steps S601 to S604; they will not be repeated here.
[0172] In step S805, the terminal device sends an uplink NAS transmission message to the mobility management network element. This message carries a PDU session identifier, a network slice identifier, a DNN, and a PDU session establishment request message. The PDU session establishment request message may carry one or more of the following: PDU session identifier, PDU session establishment type, PDU session session type, network slice identifier, and DNN.
[0173] In some embodiments, the PDU session establishment request message is carried through the SM container.
[0174] In step S806, the mobility management network element sends an Nsmf_PDU session_create SM content_request message to the session management network element. This message may carry a PDU session identifier, a network slice identifier, and an SM container. The SM container carries a PDU session establishment request message.
[0175] In step S807, the session management network element sends an Nsmf_PDU session_create SM content_response message to the mobility management network element.
[0176] In some embodiments, if the SM container in step S806 does not perform encryption and / or integrity protection based on the first information, the session management network element may refuse to establish the PDU session and reply with a rejection reason value (the rejection reason value here may be a mismatch between the encryption and / or integrity protection methods corresponding to the SM container, or it may be an existing rejection reason value).
[0177] In some embodiments, the rejection reason value sent by the session management network element to the mobility management network element is used to indicate that the second message needs to be encrypted and / or protected for integrity based on the first information.
[0178] As one implementation, the Nsmf_PDU Session_CreateSMContent_Response message can carry an SM container and a PDU session identifier. The SM container carried in the Nsmf_PDU Session_CreateSMContent_Response message can include a PDU session establishment rejection message. This PDU session establishment rejection message can carry a rejection reason value.
[0179] In some embodiments, the Nsmf_PDU session_create SM content_response message may also carry first information.
[0180] In some embodiments, the session management network element can first obtain the first information from other network elements (such as the policy control network element and the unified data management network element), and then carry the first information in the Nsmf_PDU session_create SM content_response message.
[0181] In step S808, the mobility management network element sends a downlink NAS transmission message to the terminal device. This message carries an SM container and a PDU session identifier. The SM container carries a PDU session establishment rejection message, which contains the reason for the rejection.
[0182] In some embodiments, the PDU session establishment rejection message carries first information.
[0183] Subsequently, when the terminal device sends the first NAS message to the second network element, it can determine whether the first NAS message needs to be encrypted and / or protected for integrity based on the first information.
[0184] The method embodiments of this application have been described in detail above with reference to Figures 1 to 8. The apparatus embodiments of this application will be described in detail below with reference to Figures 9 to 12. It should be understood that the descriptions of the method embodiments correspond to the descriptions of the apparatus embodiments; therefore, any parts not described in detail can be referred to the foregoing method embodiments.
[0185] Figure 9 is a schematic diagram of the structure of a terminal device provided in an embodiment of this application. The terminal device 900 shown in Figure 9 includes a first receiving module 910. The first receiving module 910 can be used to receive a first message sent by a first network element, the first message including first information; wherein, the first information is used to indicate whether a first NAS message needs encryption and / or integrity protection, and the first NAS message is used to carry session-related messages.
[0186] In some embodiments, the first information includes a first mapping relationship, which indicates a mapping relationship between a first attribute and whether the first NAS message requires encryption and / or integrity protection, and the first attribute indicates a session attribute of the first NAS message.
[0187] In some embodiments, the first attribute includes multiple values, and the first information is used to indicate whether the first NAS message corresponding to each of the multiple values needs encryption and / or integrity protection.
[0188] In some embodiments, the plurality of values includes a first value and / or a second value, wherein the first NAS message corresponding to the first value requires encryption and / or integrity protection, and the first NAS message corresponding to the second value does not require encryption and / or integrity protection.
[0189] In some embodiments, the first attribute includes one or more of the following attributes: network slice identifier; data network name; session and service continuity mode; session type.
[0190] In some embodiments, the session type includes one or more of the following types: a session for transmitting IP data; a session for transmitting unstructured data; and a session for transmitting Ethernet frames.
[0191] In some embodiments, the first information is carried in a single NAS container, or the first information is carried together with other information in a single NAS container.
[0192] In some embodiments, the terminal device further includes: a first sending module 920, configured to send a second message to a second network element, the second message being used to request the establishment of a first session; and a second receiving module 930, configured to receive a response message to the second message sent by the second network element, the response message being used to indicate the establishment result of the first session; wherein the establishment result of the first session is determined based on the first information.
[0193] In some embodiments, the establishment result of the first session includes: the encryption and / or integrity protection methods corresponding to the second message do not match.
[0194] In some embodiments, the response message includes the first information.
[0195] In some embodiments, the terminal device further includes: a second sending module, configured to send the first NAS message to a second network element, wherein the first NAS message is encrypted and / or protected for integrity based on the first information.
[0196] In some embodiments, the first network element includes one or more of the following: a policy control network element, a unified data management network element, and a session management network element.
[0197] In some embodiments, the first NAS message includes one or more of the following: a PDU session establishment request message; a PDU session modification request message; a PDU session modification confirmation message; and a PDU session deletion request message.
[0198] In some embodiments, the first NAS message may be carried in a first NAS container, which is used for session management.
[0199] In some embodiments, the first receiving module 910 may be a transceiver 1230. The terminal device 900 may also include a processor 1210 and a memory 1220, as shown in FIG12.
[0200] Figure 10 is a schematic diagram of the structure of a network device provided in an embodiment of this application. The network device 1000 shown in Figure 10 can be any of the first network elements described above. The network device 1000 may include a sending module 1010. The sending module 1010 can be used to send a first message to a terminal device, the first message including first information; wherein, the first information is used to indicate whether a first NAS message needs encryption and / or integrity protection, and the first NAS message is used to carry session-related messages.
[0201] In some embodiments, the first information includes a first mapping relationship, which indicates a mapping relationship between a first attribute and whether the first NAS message requires encryption and / or integrity protection, and the first attribute indicates a session attribute of the first NAS message.
[0202] In some embodiments, the first attribute includes multiple values, and the first information is used to indicate whether the first NAS message corresponding to each of the multiple values needs encryption and / or integrity protection.
[0203] In some embodiments, the plurality of values includes a first value and / or a second value, wherein the first NAS message corresponding to the first value requires encryption and / or integrity protection, and the first NAS message corresponding to the second value does not require encryption and / or integrity protection.
[0204] In some embodiments, the first attribute includes one or more of the following attributes: network slice identifier; data network name; session and service continuity mode; session type.
[0205] In some embodiments, the session type includes one or more of the following types: a session for transmitting IP data; a session for transmitting unstructured data; and a session for transmitting Ethernet frames.
[0206] In some embodiments, the first information is carried in a single NAS container, or the first information is carried together with other information in a single NAS container.
[0207] In some embodiments, the first network element includes one or more of the following: a policy control network element, a unified data management network element, and a session management network element.
[0208] In some embodiments, the first NAS message includes one or more of the following: a PDU session establishment request message; a PDU session modification request message; a PDU session modification confirmation message; and a PDU session deletion request message.
[0209] In some embodiments, the first NAS message may be carried in a first NAS container, which is used for session management.
[0210] In some embodiments, the transmitting module 1010 may be a transceiver 1230. The network device 1000 may also include a processor 1210 and a memory 1220, as shown in FIG12.
[0211] Figure 11 is a schematic diagram of a network device according to another embodiment of this application. The network device 1100 shown in Figure 11 can be any of the second network elements described above. The network device 1100 may include a first receiving module 1110 and a sending module 1120. The first receiving module 1110 can be used to receive a second message sent by a terminal device, the second message being used to request the establishment of a first session. The sending module 1120 can be used to send a response message of the second message to the terminal device, the response message being used to indicate the establishment result of the first session. The establishment result of the first session is determined based on first information, the first information being used to indicate whether a first NAS message needs encryption and / or integrity protection, the first NAS message being used to carry session-related messages.
[0212] In some embodiments, the first information includes a first mapping relationship, which indicates a mapping relationship between a first attribute and whether the first NAS message requires encryption and / or integrity protection, and the first attribute indicates a session attribute of the first NAS message.
[0213] In some embodiments, the first attribute includes multiple values, and the first information is used to indicate whether the first NAS message corresponding to each of the multiple values needs encryption and / or integrity protection.
[0214] In some embodiments, the plurality of values includes a first value and / or a second value, wherein the first NAS message corresponding to the first value requires encryption and / or integrity protection, and the first NAS message corresponding to the second value does not require encryption and / or integrity protection.
[0215] In some embodiments, the first attribute includes one or more of the following attributes: network slice identifier; data network name; session and service continuity mode; session type.
[0216] In some embodiments, the session type includes one or more of the following types: a session for transmitting IP data; a session for transmitting unstructured data; and a session for transmitting Ethernet frames.
[0217] In some embodiments, the first information is carried in a single NAS container, or the first information is carried together with other information in a single NAS container.
[0218] In some embodiments, the establishment result of the first session includes: the encryption and / or integrity protection methods corresponding to the second message do not match.
[0219] In some embodiments, the response message includes the first information.
[0220] In some embodiments, the network device further includes: a second receiving module, configured to receive the first NAS message sent by the terminal device, wherein the first NAS message is encrypted and / or protected for integrity based on the first information.
[0221] In some embodiments, the first NAS message includes one or more of the following: a PDU session establishment request message; a PDU session modification request message; a PDU session modification confirmation message; and a PDU session deletion request message.
[0222] In some embodiments, the first NAS message may be carried in a first NAS container, which is used for session management.
[0223] In some embodiments, the first receiving module 1110 and the transmitting module 1120 may be a transceiver 1230. The network device 1100 may also include a processor 1210 and a memory 1220, as shown in FIG12.
[0224] Figure 12 is a schematic structural diagram of a communication device according to an embodiment of this application. The dashed lines in Figure 12 indicate that the unit or module is optional. This device 1200 can be used to implement the methods described in the above method embodiments. Device 1200 can be a chip, a terminal device, or a network device.
[0225] Apparatus 1200 may include one or more processors 1210. The processor 1210 may support apparatus 1200 in implementing the methods described in the preceding method embodiments. The processor 1210 may be a general-purpose processor or a special-purpose processor. For example, the processor may be a central processing unit (CPU). Alternatively, the processor may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0226] The apparatus 1200 may further include one or more memories 1220. The memories 1220 store a program that can be executed by the processor 1210, causing the processor 1210 to perform the methods described in the preceding method embodiments. The memories 1220 may be independent of the processor 1210 or integrated within the processor 1210.
[0227] The device 1200 may also include a transceiver 1230. The processor 1210 can communicate with other devices or chips via the transceiver 1230. For example, the processor 1210 can send and receive data with other devices or chips via the transceiver 1230.
[0228] This application also provides a computer-readable storage medium for storing a program. This computer-readable storage medium can be applied to a terminal device or network device provided in this application, and the program causes a computer to execute the methods performed by the terminal device or network device in various embodiments of this application.
[0229] This application also provides a computer program product. The computer program product includes a program. This computer program product can be applied to a terminal device or network device provided in this application embodiment, and the program causes a computer to execute the methods performed by the terminal device or network device in the various embodiments of this application.
[0230] This application also provides a computer program. This computer program can be applied to the terminal device or network device provided in this application, and the computer program causes the computer to execute the methods performed by the terminal device or network device in various embodiments of this application.
[0231] It should be understood that the terms "system" and "network" in this application can be used interchangeably. Furthermore, the terminology used in this application is only for explaining specific embodiments of the application and is not intended to limit the application. The terms "first," "second," "third," and "fourth," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish different objects, not to describe a specific order. In addition, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion.
[0232] In the embodiments of this application, the term "instruction" can be a direct instruction, an indirect instruction, or an indication of a relationship. For example, A instructing B can mean that A directly instructs B, such as B being able to obtain information through A; it can also mean that A indirectly instructs B, such as A instructing C, so B can obtain information through C; or it can mean that there is a relationship between A and B.
[0233] In the embodiments of this application, "B corresponding to A" means that B is associated with A, and B can be determined based on A. However, it should also be understood that determining B based on A does not mean that B is determined solely based on A; B can also be determined based on A and / or other information.
[0234] In the embodiments of this application, the term "correspondence" can indicate a direct or indirect correspondence between two things, or an association between two things, or a relationship such as instruction and being instructed, configuration and being configured.
[0235] In the embodiments of this application, the term "comprising" can refer to direct inclusion or indirect inclusion. Optionally, "comprising" in the embodiments of this application can be replaced with "instructing" or "used to determine". For example, "A includes B" can be replaced with "A instructs B" or "A is used to determine B".
[0236] In this application embodiment, "predefined" or "preconfigured" can be implemented by pre-storing corresponding codes, tables, or other means that can be used to indicate relevant information in the device (e.g., including terminal devices and network devices). This application does not limit the specific implementation method. For example, predefined can refer to what is defined in the protocol.
[0237] In this application embodiment, the "protocol" may refer to a standard protocol in the field of communication, such as the LTE protocol, the NR protocol, and related protocols applied to future communication systems. This application does not limit this.
[0238] In the embodiments of this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0239] In the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0240] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0241] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0242] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0243] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can read or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., digital video discs, DVDs) or semiconductor media (e.g., solid-state disks, SSDs), etc.
[0244] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for wireless communication, characterized in that, include: The terminal device receives a first message sent by a first network element, the first message including first information; The first information is used to indicate whether the first non-access stratum NAS message needs encryption and / or integrity protection, and the first NAS message is used to carry session-related messages.
2. The method according to claim 1, characterized in that, The first information includes a first mapping relationship, which indicates the mapping relationship between a first attribute and whether the first NAS message needs encryption and / or integrity protection. The first attribute indicates the session attribute of the first NAS message.
3. The method according to claim 2, characterized in that, The first attribute includes multiple values, and the first information is used to indicate whether the first NAS message corresponding to each of the multiple values needs encryption and / or integrity protection.
4. The method according to claim 3, characterized in that, The plurality of values includes a first value and / or a second value. The first NAS message corresponding to the first value needs to be encrypted and / or protected for integrity, while the first NAS message corresponding to the second value does not need to be encrypted and / or protected for integrity.
5. The method according to any one of claims 2-4, characterized in that, The first attribute includes one or more of the following attributes: Network slice identifier; Data network name; Session and service continuity mode; Session type.
6. The method according to claim 5, characterized in that, The session type includes one or more of the following types: A session used for transmitting IP data; Sessions used for transmitting unstructured data; A session used to transmit Ethernet frames.
7. The method according to any one of claims 1-6, characterized in that, The first information is stored in a separate NAS container, or the first information is stored together with other information in a NAS container.
8. The method according to any one of claims 1-7, characterized in that, The method further includes: The terminal device sends a second message to the second network element, the second message being used to request the establishment of a first session; The terminal device receives a response message to the second message sent by the second network element, and the response message is used to indicate the establishment result of the first session; The establishment result of the first session is determined based on the first information.
9. The method according to claim 8, characterized in that, The establishment result of the first session includes: the encryption and / or integrity protection methods corresponding to the second message do not match.
10. The method according to claim 8 or 9, characterized in that, The response message includes the first information.
11. The method according to any one of claims 1-10, characterized in that, The method further includes: The terminal device sends the first NAS message to the second network element, and the first NAS message is encrypted and / or protected for integrity based on the first information.
12. The method according to any one of claims 1-11, characterized in that, The first network element includes one or more of the following: policy control network element, unified data management network element, and session management network element.
13. The method according to any one of claims 1-12, characterized in that, The first NAS message includes one or more of the following: PDU session establishment request message; PDU Session Modification Request Message; PDU session modification confirmation message; PDU session deletion request message.
14. The method according to any one of claims 1-13, characterized in that, The first NAS message is carried in a first NAS container, which is used for session management.
15. A method for wireless communication, characterized in that, include: The first network element sends a first message to the terminal device, the first message including first information; The first information is used to indicate whether the first non-access stratum NAS message needs encryption and / or integrity protection, and the first NAS message is used to carry session-related messages.
16. The method according to claim 15, characterized in that, The first information includes a first mapping relationship, which indicates the mapping relationship between a first attribute and whether the first NAS message needs encryption and / or integrity protection. The first attribute indicates the session attribute of the first NAS message.
17. The method according to claim 16, characterized in that, The first attribute includes multiple values, and the first information is used to indicate whether the first NAS message corresponding to each of the multiple values needs encryption and / or integrity protection.
18. The method according to claim 17, characterized in that, The plurality of values includes a first value and / or a second value. The first NAS message corresponding to the first value needs to be encrypted and / or protected for integrity, while the first NAS message corresponding to the second value does not need to be encrypted and / or protected for integrity.
19. The method according to any one of claims 16-18, characterized in that, The first attribute includes one or more of the following attributes: Network slice identifier; Data network name; Session and service continuity mode; Session type.
20. The method according to claim 19, characterized in that, The session type includes one or more of the following types: A session used for transmitting IP data; Sessions used for transmitting unstructured data; A session used to transmit Ethernet frames.
21. The method according to any one of claims 15-20, characterized in that, The first information is stored in a separate NAS container, or the first information is stored together with other information in a NAS container.
22. The method according to any one of claims 15-21, characterized in that, The first network element includes one or more of the following: policy control network element, unified data management network element, and session management network element.
23. The method according to any one of claims 15-22, characterized in that, The first NAS message includes one or more of the following: PDU session establishment request message; PDU Session Modification Request Message; PDU session modification confirmation message; PDU session deletion request message.
24. The method according to any one of claims 15-23, characterized in that, The first NAS message is carried in a first NAS container, which is used for session management.
25. A method for wireless communication, characterized in that, include: The second network element receives a second message sent by the terminal device, the second message being used to request the establishment of a first session; The second network element sends a response message of the second message to the terminal device, the response message being used to indicate the establishment result of the first session; The establishment result of the first session is determined based on the first information, which is used to indicate whether the first non-access stratum (NAS) message needs encryption and / or integrity protection, and the first NAS message is used to carry session-related messages.
26. The method according to claim 25, characterized in that, The first information includes a first mapping relationship, which indicates the mapping relationship between a first attribute and whether the first NAS message needs encryption and / or integrity protection. The first attribute indicates the session attribute of the first NAS message.
27. The method according to claim 26, characterized in that, The first attribute includes multiple values, and the first information is used to indicate whether the first NAS message corresponding to each of the multiple values needs encryption and / or integrity protection.
28. The method according to claim 27, characterized in that, The plurality of values includes a first value and / or a second value. The first NAS message corresponding to the first value needs to be encrypted and / or protected for integrity, while the first NAS message corresponding to the second value does not need to be encrypted and / or protected for integrity.
29. The method according to any one of claims 26-28, characterized in that, The first attribute includes one or more of the following attributes: Network slice identifier; Data network name; Session and service continuity mode; Session type.
30. The method according to claim 29, characterized in that, The session type includes one or more of the following types: A session used for transmitting IP data; Sessions used for transmitting unstructured data; A session used to transmit Ethernet frames.
31. The method according to any one of claims 25-30, characterized in that, The first information is stored in a separate NAS container, or the first information is stored together with other information in a NAS container.
32. The method according to any one of claims 25-31, characterized in that, The establishment result of the first session includes: the encryption and / or integrity protection methods corresponding to the second message do not match.
33. The method according to any one of claims 25-32, characterized in that, The response message includes the first information.
34. The method according to any one of claims 25-33, characterized in that, The method further includes: The second network element receives the first NAS message sent by the terminal device, the first NAS message being encrypted and / or protected for integrity based on the first information.
35. The method according to any one of claims 25-34, characterized in that, The first NAS message includes one or more of the following: PDU session establishment request message; PDU Session Modification Request Message; PDU session modification confirmation message; PDU session deletion request message.
36. The method according to any one of claims 25-35, characterized in that, The first NAS message is carried in a first NAS container, which is used for session management.
37. A terminal device, characterized in that, include: The first receiving module is configured to receive a first message sent by a first network element, wherein the first message includes first information; The first information is used to indicate whether the first non-access stratum NAS message needs encryption and / or integrity protection, and the first NAS message is used to carry session-related messages.
38. The terminal device according to claim 37, characterized in that, The first information includes a first mapping relationship, which indicates the mapping relationship between a first attribute and whether the first NAS message needs encryption and / or integrity protection. The first attribute indicates the session attribute of the first NAS message.
39. The terminal device according to claim 38, characterized in that, The first attribute includes multiple values, and the first information is used to indicate whether the first NAS message corresponding to each of the multiple values needs encryption and / or integrity protection.
40. The terminal device according to claim 39, characterized in that, The plurality of values includes a first value and / or a second value. The first NAS message corresponding to the first value needs to be encrypted and / or protected for integrity, while the first NAS message corresponding to the second value does not need to be encrypted and / or protected for integrity.
41. The terminal device according to any one of claims 38-40, characterized in that, The first attribute includes one or more of the following attributes: Network slice identifier; Data network name; Session and service continuity mode; Session type.
42. The terminal device according to claim 41, characterized in that, The session type includes one or more of the following types: A session used for transmitting IP data; Sessions used for transmitting unstructured data; A session used to transmit Ethernet frames.
43. The terminal device according to any one of claims 37-42, characterized in that, The first information is stored in a separate NAS container, or the first information is stored together with other information in a NAS container.
44. The terminal device according to any one of claims 37-43, characterized in that, The terminal device also includes: The first sending module is used to send a second message to the second network element, the second message being used to request the establishment of a first session; The second receiving module is used to receive a response message to the second message sent by the second network element, the response message being used to indicate the establishment result of the first session; The establishment result of the first session is determined based on the first information.
45. The terminal device according to claim 44, characterized in that, The establishment result of the first session includes: the encryption and / or integrity protection methods corresponding to the second message do not match.
46. The terminal device according to claim 44 or 45, characterized in that, The response message includes the first information.
47. The terminal device according to any one of claims 37-46, characterized in that, The terminal device also includes: The second sending module is used to send the first NAS message to the second network element, wherein the first NAS message is encrypted and / or protected for integrity based on the first information.
48. The terminal device according to any one of claims 37-47, characterized in that, The first network element includes one or more of the following: policy control network element, unified data management network element, and session management network element.
49. The terminal device according to any one of claims 37-48, characterized in that, The first NAS message includes one or more of the following: PDU session establishment request message; PDU Session Modification Request Message; PDU session modification confirmation message; PDU session deletion request message.
50. The terminal device according to any one of claims 37-49, characterized in that, The first NAS message is carried in a first NAS container, which is used for session management.
51. A network device, characterized in that, The network device is a first network element, and the network device includes: A sending module is used to send a first message to a terminal device, the first message including first information; The first information is used to indicate whether the first non-access stratum NAS message needs encryption and / or integrity protection, and the first NAS message is used to carry session-related messages.
52. The network device according to claim 51, characterized in that, The first information includes a first mapping relationship, which indicates the mapping relationship between a first attribute and whether the first NAS message needs encryption and / or integrity protection. The first attribute indicates the session attribute of the first NAS message.
53. The network device according to claim 52, characterized in that, The first attribute includes multiple values, and the first information is used to indicate whether the first NAS message corresponding to each of the multiple values needs encryption and / or integrity protection.
54. The network device according to claim 53, characterized in that, The plurality of values includes a first value and / or a second value. The first NAS message corresponding to the first value needs to be encrypted and / or protected for integrity, while the first NAS message corresponding to the second value does not need to be encrypted and / or protected for integrity.
55. The network device according to any one of claims 52-54, characterized in that, The first attribute includes one or more of the following attributes: Network slice identifier; Data network name; Session and service continuity mode; Session type.
56. The network device according to claim 55, characterized in that, The session type includes one or more of the following types: A session used for transmitting IP data; Sessions used for transmitting unstructured data; A session used to transmit Ethernet frames.
57. The network device according to any one of claims 51-56, characterized in that, The first information is stored in a separate NAS container, or the first information is stored together with other information in a NAS container.
58. The network device according to any one of claims 51-57, characterized in that, The first network element includes one or more of the following: policy control network element, unified data management network element, and session management network element.
59. The network device according to any one of claims 51-58, characterized in that, The first NAS message includes one or more of the following: PDU session establishment request message; PDU Session Modification Request Message; PDU session modification confirmation message; PDU session deletion request message.
60. The network device according to any one of claims 51-59, characterized in that, The first NAS message is carried in a first NAS container, which is used for session management.
61. A network device, characterized in that, The network device is a second network element, and the network device includes: The first receiving module is used to receive a second message sent by the terminal device, the second message being used to request the establishment of a first session; A sending module is used to send a response message of the second message to the terminal device, the response message being used to indicate the establishment result of the first session; The establishment result of the first session is determined based on the first information, which is used to indicate whether the first non-access stratum (NAS) message needs encryption and / or integrity protection, and the first NAS message is used to carry session-related messages.
62. The network device according to claim 61, characterized in that, The first information includes a first mapping relationship, which indicates the mapping relationship between a first attribute and whether the first NAS message needs encryption and / or integrity protection. The first attribute indicates the session attribute of the first NAS message.
63. The network device according to claim 62, characterized in that, The first attribute includes multiple values, and the first information is used to indicate whether the first NAS message corresponding to each of the multiple values needs encryption and / or integrity protection.
64. The network device according to claim 63, characterized in that, The plurality of values includes a first value and / or a second value. The first NAS message corresponding to the first value needs to be encrypted and / or protected for integrity, while the first NAS message corresponding to the second value does not need to be encrypted and / or protected for integrity.
65. The network device according to any one of claims 62-64, characterized in that, The first attribute includes one or more of the following attributes: Network slice identifier; Data network name; Session and service continuity mode; Session type.
66. The network device according to claim 65, characterized in that, The session type includes one or more of the following types: A session used for transmitting IP data; Sessions used for transmitting unstructured data; A session used to transmit Ethernet frames.
67. The network device according to any one of claims 61-66, characterized in that, The first information is stored in a separate NAS container, or the first information is stored together with other information in a NAS container.
68. The network device according to any one of claims 61-67, characterized in that, The establishment result of the first session includes: the encryption and / or integrity protection methods corresponding to the second message do not match.
69. The network device according to any one of claims 61-68, characterized in that, The response message includes the first information.
70. The network device according to any one of claims 61-69, characterized in that, The network device also includes: The second receiving module is used to receive the first NAS message sent by the terminal device, wherein the first NAS message is encrypted and / or protected for integrity based on the first information.
71. The network device according to any one of claims 61-70, characterized in that, The first NAS message includes one or more of the following: PDU session establishment request message; PDU Session Modification Request Message; PDU session modification confirmation message; PDU session deletion request message.
72. The network device according to any one of claims 61-71, characterized in that, The first NAS message is carried in a first NAS container, which is used for session management.
73. A terminal device, characterized in that, The device includes a transceiver, a memory, and a processor. The memory stores a program, and the processor invokes the program in the memory and controls the transceiver to receive or send signals so that the terminal device performs the method as described in any one of claims 1-14.
74. A network device, characterized in that, The device includes a transceiver, a memory, and a processor. The memory stores a program, and the processor invokes the program in the memory and controls the transceiver to receive or transmit signals to cause the network device to perform the method as described in any one of claims 15-24 or 25-36.
75. An apparatus, characterized in that, Includes a processor for calling a program from memory to cause the apparatus to perform the method as described in any one of claims 1-14, 15-24, or 25-36.
76. A chip, characterized in that, Includes a processor for calling a program from memory, causing a device on which the chip is mounted to perform the method as described in any one of claims 1-14, 15-24, or 25-36.
77. A computer-readable storage medium, characterized in that, It contains a program that causes a computer to perform the method as described in any one of claims 1-14, 15-24, or 25-36.
78. A computer program product, characterized in that, Includes a program that causes a computer to perform the method as described in any one of claims 1-14, 15-24, or 25-36.
79. A computer program, characterized in that, The computer program causes the computer to perform the method as described in any one of claims 1-14, 15-24, or 25-36.
Citation Information
Patent Citations
Security solution for switching on and off security for up data between UE and ran in 5g
CN110447252A
UE controlled handling of the security policy for user plane protection in 5g systems
CN111937425A
Communication method and communication device
CN118488604A
Communication method and communication apparatus
US20230397008A1