Communication method and apparatus

By acquiring information related to the second node through the first node, determining its security level, and providing matching security resources, the problem of limited security resources is solved, and the rational allocation of security resources and the success rate of business execution are improved.

WO2026153523A1PCT designated stage Publication Date: 2026-07-23BEIJING SPREADTRUM HI TECH COMM TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
BEIJING SPREADTRUM HI TECH COMM TECH CO LTD
Filing Date
2026-01-16
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

Network devices have limited security resources with other devices or functional entities, making it impossible to meet the security needs of all devices or functional entities.

Method used

The first node obtains information related to the second node, determines its corresponding security level, and provides matching security resources. The second node then executes corresponding business operations based on the received information.

Benefits of technology

This enabled the rational allocation of security resources, met the security requirements of the second node, and increased the success rate of business execution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2026073229_23072026_PF_FP_ABST
    Figure CN2026073229_23072026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in embodiments of the present disclosure are a communication method and apparatus. The method is applied to a first node, and comprises: a first node acquires first information related to a second node, the first information being used for indicating at least one of the following: a security level requested by the second node, a security level supported by the second node, and an identity identifier of the second node; on the basis of the first information, the first node determines a first security level corresponding to the second node; and the first node provides second information, the second information being used for indicating a first security resource, and the first security resource being a security resource matching the first security level.
Need to check novelty before this filing date? Find Prior Art

Description

Communication methods and devices

[0001] This disclosure claims priority to Chinese patent application No. 202510080695.7, filed on January 17, 2025, the entire contents of which are incorporated herein by reference. Technical Field

[0002] This invention relates to the field of communication technology, and in particular to a communication method and apparatus. Background Technology

[0003] Network devices can provide security resources (such as algorithm resources) to each other with other devices or functional entities. However, security resources are limited and cannot meet the security needs of all devices or functional entities. Summary of the Invention

[0004] In a first aspect, embodiments of this disclosure provide a communication method applied to a first node, a chip within the first node, or a chip module. The method includes: the first node acquiring first information related to a second node, the first information indicating at least one of the following: a security level requested by the second node, a security level supported by the second node, or an identity identifier of the second node. The first node determines a first security level corresponding to the second node based on the first information. The first node provides second information indicating a first security resource, the first security resource being a security resource matching the first security level.

[0005] In one implementation, the first node acquires first information related to the second node, including: receiving the first information related to the second node.

[0006] In one embodiment, the first node receives first information related to the second node, including: receiving the first information related to the second node from the second node; the first node provides second information, including: sending the second information to the second node.

[0007] In one implementation, the first node determines the first security level corresponding to the second node based on first information, including: determining the first security level corresponding to the second node based on the first information and at least one of the following: the type of the first service, the security level supported by the first node, the security level information subscribed by the second node, and the load capacity information of the first node. Wherein, the first service is the service requested by the second node from the first node, and the security level information subscribed by the second node includes at least one of the following: security level, algorithm, identity identifier of the second node, data network name, identifier of the first service, and service type of the first service.

[0008] In one implementation, the first node further performs the following steps: obtaining the security level information of the second node's contract; and saving the security level information of the second node's contract.

[0009] In one embodiment, the second node is a terminal device, and the first node also sends third information to the terminal device. The third information is used to instruct the terminal device to access the third node, and the third node supports a first security level.

[0010] In one implementation, the second node is an application function (AF), and the first node also sends third information to the AF. The third information is used to instruct the AF to request the execution of services from the third node, and the third node supports the first security level.

[0011] In one implementation, the first node sends third information to the terminal device or AF, including: sending third information to the terminal device or AF when the first node does not support the first security level.

[0012] In one implementation, the third information is also used to indicate that the first node does not support a security level that matches the first security resource.

[0013] In one implementation, the first information is carried in any of the following: a non-access stratum message, a radio resource control message, a packet data convergence protocol message, a radio link control message, a media access control message, a physical layer message, a data processing message, or user plane data (i.e., data transmitted via the user plane). This method can save signaling overhead.

[0014] In one implementation, the non-access stratum message is any one of the following: registration message, session message, authentication message, or key negotiation message. The radio resource control message is any one of the following: radio link establishment message or radio link reconfiguration message.

[0015] In one implementation, the first security level is either quantum secure or non-quantum secure.

[0016] In one implementation, the first security resource includes at least one of the following: an algorithm, software resources, and hardware resources. The algorithm and / or software resources and / or hardware resources are used for at least one of the following: encryption, key generation or negotiation required for encryption, integrity protection, non-repudiation, and authentication.

[0017] Secondly, embodiments of this disclosure provide a communication method applied to a second node, a chip within the second node, or a chip module. The method includes: the second node sending first information, the first information indicating at least one of the following: a security level requested by the second node, a security level supported by the second node, or an identity identifier of the second node; the second node receiving second information, the second information indicating a first security resource, the first security resource matching a first security level, the first security level being determined based on the first information; and the second node performing a first service based on the first security resource.

[0018] In one implementation, the second node sending first information includes: sending first information to the first node; the second node receiving second information includes: receiving second information from the first node.

[0019] In one implementation, the second node performs a first service based on a first security resource, including: performing the first service based on the first security resource when the second node supports the first security resource.

[0020] In one embodiment, the second node is a terminal device, and the terminal device further performs the following steps: receiving third information from the first node, the third information being used to instruct the terminal device to access the third node, the third node supporting a security level matching the first security resource; and accessing the third node.

[0021] In one implementation, the second node is an application function (AF), which further performs the following steps: receiving third information from the first node, the third information being used to instruct the AF to request the execution of a service from the third node, the third node supporting a security level matching the first security resource; and sending fourth information to the third node, the fourth information being used to request the execution of the first service from the third node.

[0022] In one implementation, the third information is also used to indicate that the first node does not support a security level that matches the first security resource.

[0023] In one implementation, the first information is carried in any of the following: a non-access stratum message, a radio resource control message, a packet data convergence protocol message, a radio link control message, a media access control message, a physical layer message, a data processing message, or user plane data (i.e., data transmitted via the user plane). This method can save signaling overhead.

[0024] In one implementation, the non-access stratum message is any one of the following: registration message, session message, authentication message, key negotiation message; the radio resource control message is any one of the following: radio link establishment message, radio link reconfiguration message.

[0025] In one implementation, the first security level is either quantum secure or non-quantum secure.

[0026] In one embodiment, the first security resource includes at least one of the following: an algorithm, software resources, and hardware resources; wherein the algorithm and / or software resources and / or hardware resources are used for at least one of the following: encryption, key generation or negotiation required for encryption, integrity protection, non-repudiation, and authentication.

[0027] Thirdly, embodiments of this disclosure provide a communication method applied to a second node, a chip within the second node, or a chip module. The method includes: the second node receiving fifth information from at least one first node, the fifth information indicating a security level supported by the first node; the second node determining a fourth node based on the security level supported by the second node or a security level corresponding to a first service, and the security levels supported by at least one first node, the fourth node being a node among at least one first node that supports the security level supported by the second node, or supports the security level corresponding to the first service, the first service being a service to be executed by the second node; and the second node sending sixth information to the fourth node, the sixth information requesting the fourth node to execute the first service, the sixth information indicating the security level required for the first service.

[0028] In one implementation, when the second node is a terminal device, it also connects to a fourth node. This approach allows the second node to request the execution of the first service from the already connected fourth node.

[0029] In one implementation, the security level is quantum secure and / or non-quantum secure.

[0030] Fourthly, embodiments of this disclosure provide a communication method applied to a fourth node, a chip within the fourth node, or a chip module. The method includes: the fourth node sending fifth information to a second node, the fifth information indicating a security level supported by the fourth node; the fourth node receiving sixth information from the second node, the sixth information requesting the execution of a first service, the sixth information indicating a security level required for the first service; the security level supported by the fourth node being the same as the security level supported by the second node, or the security level supported by the fourth node being the same as the security level corresponding to the first service; and the fourth node executing the first service based on the security level indicated by the sixth information.

[0031] In one implementation, the security level is quantum secure and / or non-quantum secure.

[0032] Fifthly, embodiments of this disclosure provide a communication method applied to a first node, a chip within the first node, or a chip module. The method includes: the first node determining a target node to which the second node will connect, based on a security level corresponding to a second node or a security level corresponding to a first service, and security levels supported by multiple fifth nodes respectively; the target node being a node among the multiple fifth nodes that supports the security level corresponding to the second node or the security level corresponding to the first service; and the first node sending seventh information to the second node, the seventh information being used to instruct the second node to connect to the target node.

[0033] In one implementation, the security level is quantum secure and / or non-quantum secure.

[0034] Sixthly, embodiments of this disclosure provide a communication method applied to a second node, or a chip or chip module within the second node. The method includes: the second node receiving seventh information from a first node, the seventh information indicating that the second node accesses a target node, the target node supporting a security level corresponding to the second node or a security level corresponding to a first service, the first service being a service to be executed by the second node; and the second node accessing the target node.

[0035] In one implementation, the security level is quantum secure and / or non-quantum secure.

[0036] In a seventh aspect, embodiments of this disclosure provide a communication device, which includes a processing unit and a communication unit.

[0037] In one design, a processing unit is configured to acquire first information related to a second node, the first information indicating at least one of the following: a security level requested by the second node, a security level supported by the second node, or an identity identifier of the second node. The processing unit is also configured to determine a first security level corresponding to the second node based on the first information. The processing unit is further configured to provide second information indicating a first security resource, the first security resource being a security resource matching the first security level.

[0038] In addition, other embodiments of the communication device can be found in the relevant content of the first aspect above, and will not be described in detail here.

[0039] In another design, a communication unit is configured to transmit first information, which indicates at least one of the following: a security level requested by the communication device, a security level supported by the communication device, and an identity identifier of the communication device. The communication unit is also configured to receive second information, which indicates a first security resource that matches a first security level, the first security level being determined based on the first information. A processing unit is configured to execute a first service based on the first security resource.

[0040] In addition, other embodiments of the communication device can be found in the relevant content of the second aspect above, and will not be described in detail here.

[0041] In another design, a communication unit is configured to receive fifth information from at least one first node, the fifth information indicating the security level supported by the first node. A processing unit is configured to determine a fourth node based on the security level supported by the communication device or the security level corresponding to a first service, and the security levels supported by the at least one first node; the fourth node is one of the at least one first node that supports the security level supported by the communication device or the security level corresponding to the first service, the first service being the service to be executed by the communication device. The communication unit is further configured to send sixth information to the fourth node, the sixth information requesting the fourth node to execute the first service, the sixth information indicating the security level required for the first service.

[0042] In addition, other embodiments of the communication device can be found in the relevant content of the third aspect above, and will not be described in detail here.

[0043] In another design, a communication unit is used to send fifth information to the second node, the fifth information indicating the security level supported by the communication device. The communication unit is also used to receive sixth information from the second node, the sixth information requesting the execution of a first service, the sixth information indicating the security level required for the first service; the security level supported by the communication device is the same as the security level supported by the second node, or the security level supported by the communication device is the same as the security level corresponding to the first service. A processing unit is used to execute the first service based on the security level indicated by the sixth information.

[0044] In addition, other embodiments of the communication device can be found in the relevant content of the fourth aspect above, and will not be described in detail here.

[0045] In another design, the processing unit is used to determine the target node to which the second node should connect, based on the security level corresponding to the second node or the security level corresponding to the first service, and the security levels supported by the multiple fifth nodes. The target node is the node among the multiple fifth nodes that supports the security level corresponding to the second node or the security level corresponding to the first service. The communication unit is used to send a seventh message to the second node, which instructs the second node to connect to the target node.

[0046] In addition, other embodiments of the communication device can be found in the relevant content of the fifth aspect above, and will not be described in detail here.

[0047] In another design, a communication unit receives seventh information from a first node, instructing the communication device to access a target node. The target node supports the security level corresponding to the communication device or the security level corresponding to a first service, where the first service is the service to be executed by the communication device. A processing unit is used to access the target node.

[0048] In addition, other embodiments of the communication device can be found in the relevant content of the sixth aspect above, and will not be described in detail here.

[0049] Eighthly, embodiments of this disclosure provide a communication device, the communication device including a memory and a processor; in some embodiments, the communication device further includes a communication interface;

[0050] Memory, used to store computer programs;

[0051] A communication interface used to receive or send data;

[0052] A processor is used to call program instructions stored in memory.

[0053] In one implementation, the processor invokes a computer program to perform the following operations:

[0054] Obtain first information related to the second node, the first information being used to indicate at least one of the following: the security level requested by the second node, the security level supported by the second node, and the identity identifier of the second node; determine the first security level corresponding to the second node based on the first information; provide second information, the second information being used to indicate a first security resource, the first security resource being a security resource that matches the first security level.

[0055] In addition, other implementations of the communication device can be found in the relevant content of the first aspect above, and will not be described in detail here.

[0056] In another implementation, the processor invokes a computer program to perform the following operations:

[0057] Send first information, which indicates at least one of the following: the security level requested by the communication device, the security level supported by the communication device, and the identity identifier of the communication device; receive second information, which indicates a first security resource, which matches a first security level, and the first security level is determined based on the first information; and perform a first service based on the first security resource.

[0058] In addition, other implementations of the communication device can be found in the relevant content of the second aspect above, and will not be described in detail here.

[0059] In another implementation, the processor invokes a computer program to perform the following operations:

[0060] The system receives fifth information from at least one first node, which indicates the security level supported by the first node. Based on the security level supported by the communication device or the security level corresponding to the first service, and the security levels supported by the at least one first node, a fourth node is determined. The fourth node is one of the at least one first node that supports the security level supported by the communication device or the security level corresponding to the first service, where the first service is the service to be executed by the communication device. A sixth message is sent to the fourth node, which requests the execution of the first service and indicates the required security level for the first service.

[0061] In addition, other implementations of the communication device can be found in the relevant content of the third aspect above, and will not be described in detail here.

[0062] In another implementation, the processor invokes a computer program to perform the following operations:

[0063] A fifth message is sent to the second node, indicating the security level supported by the communication equipment. A sixth message is received from the second node, requesting the execution of the first service. The sixth message indicates the security level required for the first service; the security level supported by the communication equipment is the same as the security level supported by the second node, or the security level supported by the communication equipment is the same as the security level corresponding to the first service. Based on the security level indicated by the sixth message, the first service is executed.

[0064] In addition, other implementation methods of the communication equipment can be found in the relevant content of the fourth aspect above, which will not be described in detail here.

[0065] In another implementation, the processor invokes a computer program to perform the following operations:

[0066] Based on the security level corresponding to the second node or the security level corresponding to the first service, and the security levels supported by the multiple fifth nodes, the target node to be connected by the second node is determined. The target node is the node among the multiple fifth nodes that supports the security level corresponding to the second node or the security level corresponding to the first service. A seventh message is sent to the second node, which instructs the second node to connect to the target node.

[0067] In addition, other implementation methods of the communication equipment can be found in the relevant content of the fifth aspect above, and will not be described in detail here.

[0068] In another implementation, the processor invokes a computer program to perform the following operations:

[0069] Receive the seventh message from the first node. The seventh message indicates that the communication device should connect to the target node. The target node supports the security level corresponding to the communication device or the security level corresponding to the first service. The first service is the service that the communication device is to execute. Connect to the target node.

[0070] In addition, other implementations of the communication device can be found in the relevant content of the sixth aspect above, and will not be described in detail here.

[0071] Ninthly, embodiments of this disclosure provide a chip, the chip including a processor and a communication interface, the communication interface being used to receive or transmit data; in one embodiment, the processor is configured to cause the chip to perform:

[0072] Obtain first information related to the second node, the first information being used to indicate at least one of the following: the security level requested by the second node, the security level supported by the second node, and the identity identifier of the second node; determine the first security level corresponding to the second node based on the first information; provide second information, the second information being used to indicate a first security resource, the first security resource being a security resource that matches the first security level.

[0073] In addition, other implementations of the chip can be found in the relevant content of the first aspect above, and will not be described in detail here.

[0074] In another embodiment, the processor is configured to cause the chip to perform:

[0075] Send first information, which indicates at least one of the following: the security level requested by the chip, the security level supported by the chip, and the chip's identity identifier; receive second information, which indicates a first security resource, which matches a first security level, and the first security level is determined based on the first information; and perform a first service based on the first security resource.

[0076] In addition, other implementation methods of the chip can be found in the relevant content of the second aspect above, which will not be described in detail here.

[0077] In another embodiment, the processor is configured to cause the chip to perform:

[0078] The system receives fifth information from at least one first node, indicating the security level supported by the first node. Based on the security level supported by the chip or the security level corresponding to the first service, and the security levels supported by the at least one first node, a fourth node is determined. The fourth node is one of the at least one first node that supports the security level supported by the chip or the security level corresponding to the first service, where the first service is the service to be executed by the chip. A sixth message is sent to the fourth node, requesting the execution of the first service and indicating the required security level for the first service.

[0079] In addition, other implementation methods of the chip can be found in the relevant content of the third aspect above, which will not be described in detail here.

[0080] In another embodiment, the processor is configured to cause the chip to perform:

[0081] The system sends a fifth message to the second node, indicating the security level supported by the chip. It receives a sixth message from the second node, requesting the execution of a first service. This sixth message indicates the required security level for the first service; either the chip's supported security level is the same as the second node's supported security level, or the chip's supported security level is the same as the security level corresponding to the first service. Based on the security level indicated by the sixth message, the system executes the first service.

[0082] In addition, other implementation methods of the chip can be found in the relevant content of the fourth aspect above, which will not be described in detail here.

[0083] In another embodiment, the processor is configured to cause the chip to perform:

[0084] Based on the security level corresponding to the second node or the security level corresponding to the first service, and the security levels supported by the multiple fifth nodes, the target node to be connected by the second node is determined. The target node is the node among the multiple fifth nodes that supports the security level corresponding to the second node or the security level corresponding to the first service. A seventh message is sent to the second node, which instructs the second node to connect to the target node.

[0085] In addition, other implementation methods of the chip can be found in the relevant content of the fifth aspect above, which will not be described in detail here.

[0086] In another embodiment, the processor is configured to cause the chip to perform:

[0087] Receive the seventh message from the first node. The seventh message indicates that the chip should connect to the target node. The target node supports the security level corresponding to the chip or the security level corresponding to the first service. The first service is the service that the chip is to execute. Connect to the target node.

[0088] In addition, other implementation methods of the chip can be found in the relevant content of the sixth aspect above, which will not be described in detail here.

[0089] In a tenth aspect, embodiments of this disclosure provide a computer-readable storage medium for storing computer software instructions used by the aforementioned terminal, including instructions for performing the methods described in any one of the first to sixth aspects.

[0090] Eleventhly, embodiments of this disclosure also provide a computer program product, which, when run on a processor, enables the implementation of the methods described in any one of the first to sixth aspects. Attached Figure Description

[0091] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.

[0092] Figure 1A is a schematic diagram of the architecture of a communication system.

[0093] Figure 1B is a schematic diagram of the architecture of a communication system.

[0094] Figure 2 is a flowchart illustrating a communication method according to an embodiment of this disclosure.

[0095] Figure 3 is an interactive schematic diagram of a communication method according to an embodiment of this disclosure.

[0096] Figure 4 is an interactive schematic diagram of another communication method according to an embodiment of this disclosure.

[0097] Figure 5 is an interactive schematic diagram of another communication method according to an embodiment of this disclosure.

[0098] Figure 6 is a schematic diagram of the structure of a communication device according to an embodiment of the present disclosure.

[0099] Figure 7 is a schematic diagram of the structure of a communication device according to an embodiment of this disclosure. Detailed Implementation

[0100] The embodiments of this disclosure will now be described in conjunction with the accompanying drawings.

[0101] In this disclosure, the terms "first" and "second," etc., are used to distinguish different objects, not to describe a specific order. "First," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined with "first," "second," etc., may explicitly or implicitly include one or more of that feature. In the description of some embodiments of this disclosure, unless otherwise stated, "a plurality of" means two or more.

[0102] Furthermore, the terms “comprising” and “having”, and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but in some embodiments includes steps or units not listed, or in some embodiments includes other steps or units inherent to such processes, methods, products, or apparatus.

[0103] It should be understood that in this disclosure, "multiple" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously. A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects have an "or" relationship. "...when" and "if" both indicate that a corresponding action will be taken under certain objective circumstances; they are not time-limited, do not require a judgment action during implementation, and do not imply any other limitations.

[0104] In this disclosure, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" or "for example" in this disclosure should not be construed as being more preferred or advantageous than other embodiments or designs. Rather, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner to facilitate understanding.

[0105] To better understand the communication methods disclosed in the embodiments of this disclosure, the system architecture applicable to the embodiments of this disclosure is described.

[0106] This disclosure provides a communication system. Figure 1A is a schematic diagram of the architecture of the communication system. As shown in Figure 1A, the communication system may include, but is not limited to, terminal devices, networks, and application functions (AFs). The number and form of devices shown in Figure 1A are for illustrative purposes only and do not constitute a limitation on the embodiments of this disclosure. In practical applications, the devices shown in Figure 1A may include more than one terminal device, more than one network, and more than one AF. The network includes security function nodes that can provide security functions. The terminal devices and AFs can communicate with the network. For example, the terminal devices and AFs send service request information to the network to request the execution of a service.

[0107] This disclosure also provides a communication system. Figure 1B is a schematic diagram of the architecture of this communication system. As shown in Figure 1B, the communication system may include, but is not limited to, terminal devices and networks. The number and form of devices shown in Figure 1B are for illustrative purposes only and do not constitute a limitation on the embodiments of this disclosure. In practical applications, the devices shown in Figure 1B may include more than one terminal device and more than one network. The network includes an AF (Automatic Function) and security function nodes for providing security functions. The terminal device can communicate with the network. For example, the terminal device sends service request information to the network to request the execution of a service.

[0108] In addition, in the embodiments of this disclosure, AF in FIG1A and FIG1B can be replaced with server, network function (NF), etc.

[0109] In one embodiment, the first node in this disclosure is the network in FIG1A, and the second node is the terminal device or AF in FIG1A.

[0110] In another embodiment, the first node in this disclosure is the security function node in FIG1B that provides security functions, and the second node is a terminal device or AF.

[0111] The network in this embodiment can be a base station (BS) or a core network element.

[0112] The BS in this disclosure, also referred to as a base station device, is an apparatus deployed in a wireless access network (RAN) to provide wireless communication functions. For example, in a 2G network, devices providing base station functions include a base transceiver station (BTS). In a 3G network, devices providing base station functions include a Node B. In a 4G network, devices providing base station functions include an evolved Node B (eNB). In wireless local area networks (WLANs), devices providing base station functions are access points (APs). In 5G new radio (NR), devices providing base station functions include gNBs and further evolved Node Bs (ng-eNBs). In this embodiment, the gNB and the terminal device communicate using NR technology, while the ng-eNB and the terminal communicate using evolved universal terrestrial radio access (E-UTRA) technology. Both the gNB and ng-eNB can connect to the 5G core network. The base station in this embodiment also includes equipment that provides base station functionality in future new communication systems.

[0113] In this embodiment of the disclosure, the core network element refers to an entity or component in the core network responsible for a specific function. Core network elements may include authentication management function (AMF), session management function (SMF), and user plane function (UPF), etc.

[0114] The terminal device in this disclosure, also referred to as a terminal, can refer to various forms of user equipment (UE), access terminal, user unit, user station, mobile station, mobile station (MS), remote station, remote terminal, mobile device, user terminal, wireless communication device, user agent, or user device. The terminal device can also be a cellular phone, cordless phone, session initiation protocol (SIP) phone, wireless local loop (WLL) station, personal digital assistant (PDA), handheld device with wireless communication capabilities, computing device or other processing device connected to a wireless modem, vehicle-mounted device, or wearable device. The terminal device can also be a terminal device in a 5G network or a terminal device in a future public land mobile network (PLMN), etc. This disclosure does not limit this aspect.

[0115] The server in this embodiment can be a standalone physical server, a server cluster consisting of multiple physical servers, or a distributed system. The server in this embodiment can also be a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.

[0116] This disclosure is applicable to 5G communication systems, as well as 4G and 3G communication systems, and to various future communication systems. The embodiments disclosed herein are not limited thereto.

[0117] This disclosure provides a communication method 100. In this method 100, a first node acquires first information related to a second node, the first information indicating at least one of the following: a security level requested by the second node, a security level supported by the second node, or the identity identifier of the second node; the first node determines a first security level corresponding to the second node based on the first information; the first node provides second information indicating a first security resource, the first security resource being a security level matching the first security level. This method enables the first node to reasonably allocate security resources that meet the security needs of the second node based on the second node's security requirements, so that the second node can obtain the required security protection.

[0118] This disclosure also provides a communication method 200. In this communication method 200, a second node obtains the security levels supported by at least one first node. Then, the second node determines a fourth node based on the security level supported by the second node or the security level corresponding to a first service, and the security levels supported by the at least one first node. If the fourth node supports the security level supported by the second node or the security level corresponding to the first service, the second node can request the execution of the first service from the fourth node. Furthermore, the fourth node executes the first service for the second node based on the security level indicated by the second node, thereby increasing the probability of the first service being successfully executed.

[0119] This disclosure also provides a communication method 300. In this communication method 300, the node currently accessed by the terminal device determines the target node to be accessed from multiple service nodes based on the security level corresponding to the terminal device or the security level required for the first service to be executed by the terminal device, and the security levels supported by the multiple service nodes respectively. The node currently accessed by the terminal device also instructs the terminal device to access the target node. Thus, the target node that meets the security requirements of the terminal device executes the service for the terminal device, thereby enabling the terminal device to obtain security protection that meets its security requirements.

[0120] This disclosure provides a communication method 100. The communication method 100 is applied to a first node. The first node can also be a chip or chip module that supports the implementation of the corresponding method. Figure 2 is a flowchart of the communication method 100, which includes, but is not limited to:

[0121] S201, the first node obtains first information related to the second node, the first information being used to indicate at least one of the following: the security level requested by the second node, the security level supported by the second node, and the identity identifier of the second node.

[0122] In one implementation, the security level is either quantum safe or non-quantum safe, with quantum safe being a higher security level than non-quantum safe, or vice versa. In some embodiments, the second node requests one security level, such as quantum safe or non-quantum safe; the second node supports one or more security levels, including at least one of the following: quantum safe and non-quantum safe.

[0123] In some embodiments, the security level may also be other security levels besides quantum security and non-quantum security used to represent the level of security protection, and this disclosure does not limit this.

[0124] Additionally, the identity identifier of the second node is used to identify the second node. For example, when the second node is an AF (Application Function), the AF's identity identifier can be its address. For instance, the AF's identity identifier could be its Internet Protocol (IP) address or its Media Access Control (MAC) address. As another example, when the second node is a server, the server's identity identifier can be its address. For example, the server's identity identifier could be its IP address or its MAC address. Furthermore, when the second node is a terminal device, the terminal device's identity identifier is the UE ID.

[0125] In one implementation, the first node acquires first information related to the second node, including receiving the first information related to the second node. Correspondingly, the second node provides the first information, including sending the first information.

[0126] In some embodiments, the first node receives first information related to the second node, including receiving first information from the second node. Correspondingly, the second node provides the first information, including sending the first information to the first node. The first node and the second node can directly interact with the first information, or they can interact with the first information through an intermediate node. That is, the first information can be forwarded from the second node to the first node through an intermediate node.

[0127] As can be seen, the first node can receive at least one of the security level requested by the second node, the security level supported by the second node, and the identity identifier of the second node from the second node, thereby being able to determine the required security level of the second node based on this information.

[0128] In another implementation, nodes other than the first node and the second node store first information related to the second node. The first node obtains this first information by acquiring it from other nodes. For example, the first node receives first information related to the second node from other nodes. In some embodiments, the first node may receive the first information from other nodes via an intermediate node. That is, other nodes can send the first information related to the second node to the first node via an intermediate node.

[0129] In another implementation, the first node pre-stores first information related to the second node. Therefore, the first node obtaining the first information related to the second node includes: obtaining the first information related to the second node from within the first node itself. For example, the first node reads the first information related to the second node from a storage unit.

[0130] It is evident that the first node can flexibly acquire first information related to the second node through various implementation methods, which is beneficial for determining the required security level of the second node based on the first information.

[0131] In one implementation, the first information may indicate at least one of the following: the security level requested by the second node, the security level supported by the second node, and the identity identifier of the second node. For example, the first information may include the security level requested by the second node to directly indicate the security level requested by the second node. As another example, the first information may include both the security level requested by the second node and the identity identifier of the second node to directly indicate both the security level requested by the second node and the identity identifier of the second node.

[0132] In some embodiments, the first information can also indirectly indicate the security level requested by the second node and the security level supported by the second node through other implementation methods (such as bitmaps). For example, the first node and the second node pre-agree on multiple bitmaps corresponding to different security levels. For instance, a quantum-safe bitmap is 01, and a non-quantum-safe bitmap is 11. Then, when the bit information in the first information used to indicate the security level requested by the second node is 01, it indirectly indicates that the security level requested by the second node is quantum-safe; when the bit information in the first information used to indicate the security level requested by the second node is 11, it indirectly indicates that the security level requested by the second node is non-quantum-safe.

[0133] In one implementation, when the first information is received by the first node, the first information can be carried in any of the following: a non-access stratum (NAS) message, a radio resource control (RRC) message, a packet data convergence protocol (PDCP) message, a radio link control (RLC) message, a media access control (Media Access Control) message, a physical layer (PHY) message, a data processing message, or user plane data (i.e., data transmitted via the user plane). The data processing message is used to process data plane information, which includes artificial intelligence information and sensory information. Therefore, the first information can be carried in existing messages between the first and second nodes, reducing signaling overhead compared to using a new message.

[0134] In some embodiments, the NAS message can be any of the following: registration message, session message (e.g., protocol data unit (PDU) session message), authentication message, key negotiation message, registration accept message, registration complete message, registration reject message, deregistration request message (created by the UE), deregistration accept message (originating by the UE), deregistration request message (terminated by the UE), deregistration accept message (terminated by the UE), service request message, service reject message, service accept message, control plane service request message, network slice message, network slice-specific authentication command message, network slice-specific authentication complete message, network slice-specific authentication result message, configuration update command message, configuration update message. The message types include: complete, authentication request, authentication response, authentication reject, authentication failure, authentication result, identity request, identity response, and security mode commands.The message types include command, security mode complete, security mode reject, 5G mobility management status (5G MM status), notification, notification response, uplink (UL) NAS transport, downlink (DL) NAS transport, relay key request, relay key accept, relay key reject, relay authentication request, and relay authentication response. In some embodiments, the NAS message may also be other messages. This disclosure does not limit the specific message type.

[0135] In some embodiments, the RRC message can be any of the following: a radio link establishment message, a radio link reconfiguration message, or a system message. In some embodiments, the system message can be a master information block (MIB) message, a system information block (SIB) message, an RRC reject message, or an RRC release message. In some embodiments, the RRC message can also be other messages, which are not limited in this disclosure.

[0136] In some embodiments, the registration message mentioned above may be a registration request message, the session message may be a session request message, and the wireless link establishment message may be a link establishment message.

[0137] In one implementation, the first information is carried in any of the aforementioned messages, which can be understood as: the first node receives any of the aforementioned messages, and this message carries the first information. For example, if the second node is a terminal device, the terminal device sends a registration message to the first node. This registration message is used to request network access from the first node, and the registration message carries the first information. As another example, if the second node is an AF (Application Firewall), the AF sends a service request message to the first node. This service request message carries the first information.

[0138] In some embodiments, when the second node is an AF and the terminal device communicates with the AF, the AF can obtain the security level supported by the terminal device from the terminal device. Therefore, the AF can also send the security level supported by the terminal device to the first node, so that when the first node allocates security resources to the second node, it can consider at least one of the security level supported by the AF, the security level requested by the AF, and the identity of the AF, as well as the security level supported by the terminal device, thereby improving the rationality of security resource allocation.

[0139] S202. The first node determines the first security level corresponding to the second node based on the first information.

[0140] In one implementation, the first security level corresponding to the second node can be understood as: the first security level required / needed / available for use by the second node; or it can be understood as: the first security level required / needed / available for use by the second node in requesting the execution of services from the first node. The first security level required / needed / available for use by the second node includes: the security level required / needed / available for use by the second node in executing all services.

[0141] In one implementation, when the first information indicates the security level requested by the second node, the first node determines the security level requested by the second node as a first security level, or determines the first security level based on the security level requested by the second node. Alternatively, when the first information indicates the security level requested by the second node, the first security level is the security level requested by the second node, or it is determined based on the security level requested by the second node.

[0142] In another implementation, if the first information indicates the security level supported by the second node, the first node determines one of the security levels supported by the second node as the first security level. That is, the first security level is one of the security levels supported by the second node.

[0143] In another implementation, when the first information indicates the identity of the second node, the first node determines a first security level based on the identity of the second node. That is, the first security level is a security level determined based on the identity of the second node.

[0144] For example, the first node determines that the second node requires a higher level of security protection based on the identity of the second node, and thus assigns a higher security level to the second node, such as determining the first security level as quantum security.

[0145] For example, the first node pre-stores the association between the identity identifier of the second node and the security level corresponding to the second node. Based on the identity identifier indicated by the first information, the first node determines one or more security levels corresponding to the second node. Then, the first node selects one security level from the one or more security levels corresponding to the second node as the first security level.

[0146] For example, the first node, based on the identity identifier indicated by the first information, obtains one or more security levels corresponding to the second node from other devices. These other devices store the association between the second node's identity identifier and its corresponding security level. The first node selects one of the obtained security levels corresponding to the second node as its first security level.

[0147] In another embodiment, when the first information indicates the security level requested by the second node and the identity of the second node: if one or more security levels corresponding to the identity of the second node include the security level requested by the second node, then the first node determines the security level requested by the second node as the first security level (i.e., the first security level is the security level requested by the second node); if one or more security levels corresponding to the identity of the second node do not include the security level requested by the second node, then the first node determines one of the one or more security levels corresponding to the identity of the second node as the first security level (i.e., the first security level is one of the one or more security levels corresponding to the identity of the second node). The one or more security levels corresponding to the identity of the second node may be pre-stored by the first node or may be obtained from other devices. This disclosure does not limit this aspect.

[0148] In another implementation, when the first information indicates the security level supported by the second node and the identity identifier of the second node, the first node determines one of the intersections of the security level supported by the second node and one or more security levels corresponding to the identity identifier of the second node as the first security level.

[0149] For example, if the security level supported by the AF indicated by the first information is quantum security and non-quantum security, and the security level corresponding to the identity identifier of the AF indicated by the first information is quantum security, then the first node determines the first security level as the intersection of the security level supported by the AF and the security level corresponding to the identity identifier of the AF, that is, the first security level is quantum security.

[0150] In some embodiments, when the first information indicates the security level supported by the second node and the identity of the second node, and there is no overlap between the security level supported by the second node and one or more security levels corresponding to the identity of the second node, the first node determines any one of the security levels supported by the second node and one or more security levels corresponding to the identity of the second node as the first security level. For example, the highest security level among one or more security levels can be determined as the first security level, or the lowest security level among one or more security levels can be determined as the first security level.

[0151] In another implementation, if the first information indicates the security level requested by the second node and the security level supported by the second node: if the security level supported by the second node includes the security level requested by the second node, then the first security level is the security level requested by the second node; if the security level supported by the second node does not include the security level requested by the second node, then the first security level is one of the security levels supported by the second node.

[0152] For example, if the first information indicates that the security level requested by the second node is quantum secure, and the security level supported by the second node is non-quantum secure, then the first node determines that the first security level is non-quantum secure.

[0153] In another implementation, when the first information indicates the security level requested by the second node, the security level supported by the second node, and the identity of the second node: if there is an intersection between the security level requested by the second node, the security level supported by the second node, and the security level corresponding to the identity of the second node, the first security level is the intersection of the security level requested by the second node, the security level supported by the second node, and the security level corresponding to the identity of the second node; if there is no intersection between the security level requested by the second node, the security level supported by the second node, and the security level corresponding to the identity of the second node, but there is an intersection between the security level supported by the second node and the security level corresponding to the identity of the second node, then the first security level is the intersection of the security level supported by the second node and the security level corresponding to the identity of the second node; if there is no intersection between the security level requested by the second node, the security level supported by the second node, and the security level corresponding to the identity of the second node, and there is no intersection between the security level supported by the second node and the security level corresponding to the identity of the second node, then the first security level is one of the security levels supported by the second node, or one of the security levels corresponding to the identity of the second node.

[0154] For example, if the first information indicates the identity of the terminal device, and indicates that the security level requested by the terminal device is quantum security, and the security levels supported by the terminal device are quantum security and non-quantum security, and the security level corresponding to the identity of the terminal device is quantum security, then the first node determines that the first security level is quantum security.

[0155] As can be seen, the first node can determine the first security level corresponding to the second node based on at least one of the following: the security level requested by the second node, the security level supported by the second node, and the identity identifier of the second node. Therefore, the determined first security level is the security level required by the second node, which allows the first node to rationally allocate security resources that match the security level required by the second node.

[0156] In one implementation, when the first node determines the first security level corresponding to the second node based on the first information, it also combines other information to determine the first security level. This disclosure does not limit the scope of the other information.

[0157] In one implementation, the first node determines the first security level corresponding to the second node based on first information, including: determining the first security level corresponding to the second node based on the first information and at least one of the following: the type of the first service, the security level supported by the first node, the security level information subscribed by the second node, and the load capacity information of the first node. The first service is the service that the second node requests to be executed by the first node. The security level information subscribed by the second node includes at least one of the following: security level, security resources, the identity identifier of the second node, data network name (DNN), the identifier of the first service, and the service type of the first service.

[0158] The first service is the task requested by the second node from the first node; that is, the service to be performed by the second node. The first service can be voice service, video service, file transfer service, SMS service, sensing service, or AIoT (Artificial Intelligence Internet of Things) service (time-sensitive service), etc. For example, in the case of the second node being AF (Analog-First Node), the first service is a sensing service. A sensing service is a service that requests the first node to perceive the surrounding environment (such as the number and speed of vehicles, rainfall).

[0159] Furthermore, the security level information of the second node refers to the security level information pre-agreed upon by the first and second nodes. The load capacity information of the first node refers to the maximum amount of communication tasks that the first node can handle, including the number of users it can support, data transmission rate, signal coverage, etc. The identifier of the first service can be an application ID. Security resources include at least one of the following: algorithms, software resources, and hardware resources. Algorithms and / or software resources and / or hardware resources are used for at least one of the following: encryption, key generation or negotiation required for encryption, integrity protection, non-repudiation, and authentication. Alternatively, the algorithm may include authentication algorithms, encryption algorithms, integrity protection algorithms, etc.

[0160] It is evident that the first node can determine the first security level corresponding to the second node based on at least one of the following: the first information, the type of the first service, the security level supported by the first node, the security level information of the second node's contract, and the load capacity information of the first node. This helps to improve the accuracy of the first security level.

[0161] In one implementation, the first node may further perform the following steps: obtain the security level information of the second node's contract; and save the security level information of the second node's contract.

[0162] In one implementation, the first node obtains the security level information signed by the second node, including: receiving the security level information signed by the second node from the second node. Specifically, the first node can receive the security level information signed by the second node from the second node through an intermediate node. That is, the second node can send the security level information signed by the second node to the first node through an intermediate node. Therefore, the first node can obtain and store the security level information signed by the second node from the second node.

[0163] In some embodiments, the second node may send the signed security level information to the first node after connecting to or establishing a connection with the first node. The first node then receives and stores the signed security level information from the second node.

[0164] In another implementation, the first node obtains the security level information of the second node's contract, including receiving the security level information of the second node's contract from other nodes besides the second node. In this method, the other nodes pre-store the security level information of the second node's contract. Therefore, these other nodes can send the security level information of the second node's contract to the first node.

[0165] In some embodiments, the security level information signed by the second node can be maintained (e.g., updated, deleted, or determined) within the unified data management (UDM) function or in the first node. For example, the first node can update the security level information signed by the second node.

[0166] As can be seen, the first node can manage the security level information signed by the second node. Therefore, when determining the first security level corresponding to the second node, the first node can combine the security level information signed by the second node to make the determination, thereby improving the accuracy of the first security level.

[0167] S203. The first node provides second information, which is used to indicate the first security resource, which is a security resource that matches the first security level.

[0168] In one embodiment, the first security resource includes at least one of the following: an algorithm, software resources, and hardware resources. The algorithm and / or software resources and / or hardware resources are used for at least one of the following: encryption, key generation or negotiation required for encryption, integrity protection, non-repudiation, and authentication. In some embodiments, the first security resource may further include UPF resources, network element (such as data plane network element) resources, etc.

[0169] Alternatively, the first security resource includes at least one of the following: the algorithm required for encryption, the algorithm for key generation or negotiation required for encryption, the algorithm for integrity protection, the algorithm for non-repudiation, the algorithm for authentication, the software or hardware resources corresponding to the algorithm required for encryption, the software or hardware resources corresponding to the algorithm for key generation or negotiation required for encryption, the software or hardware resources corresponding to the algorithm for integrity protection, the software or hardware resources corresponding to the algorithm for non-repudiation, and the software or hardware resources corresponding to the algorithm for authentication.

[0170] The encryption algorithm refers to the algorithm that encrypts the communicated information using a key. The key generation or negotiation algorithm is used to generate or negotiate the key. The authentication algorithm is a technology that verifies the user's identity through methods such as passwords and digital signatures.

[0171] Integrity protection algorithms prevent key tampering by sending the entire combination of a random number generated before key encryption and the MAC information. The MAC information is generated from the random number. Specifically, if the random number is tampered with, the receiver will receive the altered random number and will be unable to generate the correct MAC information from it. Correct MAC information is generated from an untampered random number.

[0172] Non-repudiation algorithms are techniques that ensure information cannot be denied or repudiated. These algorithms are implemented using digital signature technology. For example, a sender sends a message containing a digital signature. The receiver then tampers with the message. The digital signature on the tampered message is different from the digital signature in the original message sent by the sender. Therefore, the digital signature in the message sent by the sender is a technique used to ensure non-repudiation.

[0173] In some embodiments, the first security resource is a security resource that matches the first security level. This can be understood as: the first security resource is the security resource required when the security requirement is the first security level; or it can be understood as: the first security resource is the security resource required when performing the business corresponding to the first security level.

[0174] In one implementation, before providing the second information, the first node may also determine a first security resource that matches the first security level. Thus, the first node is able to provide the first security resource that matches the first security level.

[0175] In one implementation, the first node provides the second information by sending the second information to the second node. Correspondingly, the second node receives the second information from the first node. In some embodiments, the first node may send the second information to the second node through an intermediate node.

[0176] As can be seen, the first node can directly provide the second node with a first security resource that matches the second node's security requirements. Therefore, the second node can execute business operations based on this first security resource, thereby satisfying its required security protection.

[0177] In one implementation, the second node performs a first service based on the first security resource, including: when the second node supports the first security resource, performing the first service based on the first security resource, thereby facilitating the successful execution of the first service.

[0178] In some embodiments, before executing the first service based on the first security resource, the second node may request the execution of the first service from the first node. Therefore, the second node executing the first service based on the first security resource may be: executing the first service together with the first node based on the first security resource.

[0179] For example, if the first security resource is encryption algorithm a, and the first service is the transmission of data a from the first node to the second node, then the second node uses encryption algorithm a to encrypt the data a and sends the encrypted data to the first node. Correspondingly, the first node can use decryption algorithm a corresponding to encryption algorithm a to decrypt the encrypted data and obtain the data a.

[0180] In one embodiment, where the first node obtains first information related to the second node from the second node, and the first node provides the second node with first security resources, the interaction diagram between the first node and the second node can be seen in Figure 3. As shown in Figure 3, the interaction process includes, but is not limited to, the following steps: S301, the second node sends first information to the first node, the first information indicating at least one of the following: the security level requested by the second node, the security level supported by the second node, and the identity identifier of the second node; S302, the first node determines the first security level corresponding to the second node based on the first information; S303, the first node sends second information to the second node, the second information indicating the first security resource, the first security resource being a security resource matching the first security level; S304, the second node executes a first service based on the first security resource. Specific implementations of S301 to S304 can be found above and will not be repeated here.

[0181] In another implementation, the first node provides the second information by sending the second information to other nodes besides the second node. These other nodes may be nodes participating in the second node's tasks. In some embodiments, the first node may send the second information to other nodes through an intermediary node. This allows other nodes participating in the second node's tasks to obtain security resources matching the security level required by the second node. Furthermore, this facilitates the other nodes in assisting in the execution of the second node's tasks based on security resources matching the second node's required security level (e.g., other nodes determine which security resources to provide to the second node based on security resources obtained from the first node), thereby satisfying the security protection required by the second node.

[0182] For example, if the first node is node a, the second node is node b, and nodes c and d will work with node b to execute task 1, then node a can send second information to nodes b, c, and d respectively, so that nodes b, c, and d can all assist in executing task 1 based on security resources that match the security level required by node b, thereby satisfying the security protection required by node b.

[0183] As can be seen, after determining the first security level corresponding to the second node based on the second node's security requirements, the first node allocates the first security resources that match the first security level, so that the first security level can meet the security needs of the second node and enable the second node to obtain the required security protection.

[0184] In some embodiments, the second information further indicates a first security level to inform the second node or other nodes of the determined first security level. When the first node informs the second node of the first security level via the second information, this allows the second node to reconfirm whether the first security level is the required security level. Then, the second node determines whether to use the first security resource to perform the first task. When the first node informs other nodes of the first security level via the second information, this allows other nodes to confirm whether they support the first security level. Then, other nodes determine whether they can assist in performing the second node's task based on the first security resource.

[0185] In one implementation, when the second node is a terminal device, the first node can also send third information to the terminal device. The third information instructs the terminal device to access the third node, which supports a first security level. Accordingly, the terminal device performs the following steps: receiving the third information from the first node; and accessing the third node based on the third information. The third node can be considered as the target node to which the terminal device is to access.

[0186] In some embodiments, the third information includes the identification information of the third node (such as the ID of the third node), so that the second node can determine the third node based on the third information.

[0187] It is evident that the first node can instruct the terminal device to access the third node that supports the first security level, which is beneficial for the terminal device to request the execution of services from the third node, thereby increasing the probability that the services will be successfully executed.

[0188] In some embodiments, the third information used to instruct the terminal device to access the third node can be replaced by: the third information used to instruct the terminal device to access the first cell, the first cell supporting the first security level. Here, the first cell can be considered as the cell (cell) to which the terminal device is to access.

[0189] It is evident that the cell where the first node is located can instruct the second node to switch to the first cell that supports the first security level. This is beneficial for the second node to request the execution of the first service from the first cell, thereby increasing the probability that the first service will be successfully executed.

[0190] In another implementation, when the second node is an AF (Automatic Service Provider), the first node can also send a third message to the AF. This third message instructs the AF to request the execution of a service from the third node, whereby the third node supports a first security level. Accordingly, the AF performs the following steps: receiving the third message from the first node, which instructs the AF to request the execution of a service from the third node, whereby the third node supports a security level matching the first security resource; and sending a fourth message to the third node, which requests the execution of the first service from the third node.

[0191] Optionally, the third information is used to instruct the AF to request the execution of services from the third node, which can be replaced with: the third information is used to instruct the AF to request the execution of services from the first cell, and the first cell supports the first security level.

[0192] As can be seen, the first node can instruct the AF to request the execution of the first service from the third node / first cell that supports the first security level, thereby increasing the probability that the first service is successfully executed.

[0193] In some embodiments, the first node sends third information to the terminal device or AF, including: sending third information to the terminal device or AF when the first node does not support the first security level.

[0194] Therefore, even if the first node does not support the first security level, it can instruct the terminal device to access a third node that supports the first security level. This increases the probability of the terminal device requesting service execution from the third node that supports the first security level, thus improving the success rate of service execution. Alternatively, even if the first node does not support the first security level, it can instruct the AF to request service execution from a third node that supports the first security level. This also increases the probability of service execution.

[0195] In some embodiments, regardless of whether the second node is a terminal device or an AF, the third information is also used to indicate that the first node does not support the security level that matches the first security resource, which is beneficial for the terminal device or AF not to request the execution of services from the first node, thereby reducing the probability that the services cannot be successfully executed.

[0196] As can be seen, the first security resource provided by the first node matches the first security level, and the first security level is determined based on at least one of the security level requested by the second node, the security level supported by the second node, and the identity identifier of the second node. This facilitates ensuring that the first security resource meets the security needs of the second node. This method allows the first node to reasonably allocate security resources that meet the security needs of the second node, so that the second node can obtain the required security protection.

[0197] This disclosure provides a communication method 200. The communication method 200 is applied to a first node and a second node. The first node can also be a chip or chip module that supports the implementation of the corresponding method, and the second node can also be a chip or chip module that supports the implementation of the corresponding method. Figure 4 is an interactive schematic diagram of the communication method 200, which includes, but is not limited to:

[0198] S401, one or more first nodes send a fifth message to a second node, the fifth message indicating the security level supported by the first node. Correspondingly, the second node receives the fifth message from at least one first node.

[0199] In some embodiments, the first node can send the fifth message to the second node through an intermediate node. Alternatively, the second node can receive the fifth message from the first node through an intermediate node.

[0200] In one implementation, the fifth information can be carried in a NAS message or an RRC message. Alternatively, a NAS message or an RRC message can carry the fifth information. The NAS message and RRC message are as described in the communication method 100 above, and will not be repeated here.

[0201] In addition, the first node supports one or more security levels. In one embodiment, the first node supports quantum security and / or non-quantum security. Quantum security and non-quantum security are described in the communication method 100 above and will not be repeated here.

[0202] It is evident that when one or more first nodes indicate the security level they support to the second nodes, the second nodes can determine which first node to request the execution of their business based on the security level supported by each first node, so that the business can obtain the necessary security protection.

[0203] In some embodiments, the fifth information may also indicate the security resources supported by the first node, so that the second node can also determine the node requesting to perform the service by combining the security resources supported by each of the first nodes in at least one of the first nodes.

[0204] S402. The second node determines the fourth node based on the security level supported by the second node or the security level corresponding to the first service, and the security level supported by at least one first node.

[0205] The second node supports one or more security levels. For example, the second node supports quantum security and / or non-quantum security. The first service is the service to be executed by the second node; the service type can be found in the communication method 100 above, and will not be repeated here. The security level corresponding to the first service can be understood as: the security level / security protection level required by the first service.

[0206] Furthermore, the fourth node is a node among at least one of the first nodes that supports the security level supported by the second node, or supports the security level corresponding to the first service, where the first service is the service to be executed by the second node. For example, if at least one first node includes first node a and first node b, first node a supports quantum security, first node b supports non-quantum security, and the second node supports quantum security, then the fourth node is first node a.

[0207] For example, if at least one first node includes first node a and first node b, first node a supports quantum security, first node b supports non-quantum security, and the security level required for the business #1 to be executed by the second node is non-quantum security, then the fourth node is first node b.

[0208] It is evident that the second node can determine a fourth node that supports the security level supported by the second node from at least one first node, or it can determine a fourth node that supports the security level corresponding to the first service from at least one first node, so that the second node can request the execution of the first service from the fourth node.

[0209] In one implementation, the fifth information can also be used to indicate the security resources supported by the first node, so that the second node can also determine the fourth node capable of performing the first service by combining the security resources supported by the first node.

[0210] S403. The second node sends a sixth message to the fourth node. The sixth message requests the fourth node to execute the first service, and indicates the security level required for the first service. Correspondingly, the fourth node receives the sixth message from the second node.

[0211] The security level required for the first service can be determined based on the security level of the second node, or it can be determined based on the security level of the first service.

[0212] Understandably, since the fourth node supports the security level supported by the second node, or supports the security level corresponding to the first service, the second node can request the execution of the first service from the fourth node through the sixth information, thereby enabling the first service to be successfully executed by the fourth node.

[0213] In some embodiments, the second node can send the sixth message to the fourth node through an intermediate node. Alternatively, the fourth node can receive the sixth message from the second node through an intermediate node.

[0214] In one implementation, if the second node is a terminal device, the terminal device can also connect to a fourth node. Therefore, after connecting to the fourth node, the terminal device can request the execution of the first task from the fourth node via the sixth information.

[0215] S404, the fourth node executes the first service based on the security level indicated by the sixth information.

[0216] In some embodiments, the fourth node performs a first service based on the security level indicated by the sixth information, including: determining security resources that match the security level indicated by the sixth information; and performing the first service based on the determined security resources. The implementation method for the fourth node to perform the first service based on the determined security resources can be referred to the implementation method in S304, and will not be repeated here.

[0217] As can be seen, the second node obtains at least one security level supported by the first node, and thus determines the fourth node based on the security level supported by the second node or the security level corresponding to the first service, as well as the security level supported by at least one first node. The fourth node is a node that supports the security level supported by the second node, or supports the security level corresponding to the first service. Therefore, the second node can request the execution of the first service from the fourth node, and the fourth node executes the first service for the second node based on the security level indicated by the second node, thereby increasing the probability that the first service is successfully executed.

[0218] This disclosure provides a communication method 300. The communication method 300 is applied to a first node and a second node, where the first node is a network, such as a base station or CN, and the second node is a terminal device. The first node can also be a chip or chip module that supports the implementation of the corresponding method, and the second node can also be a chip or chip module that supports the implementation of the corresponding method. Figure 5 is an interactive schematic diagram of the communication method 300, which includes, but is not limited to:

[0219] S501. The first node determines the target node to be accessed by the second node based on the security level corresponding to the second node or the security level corresponding to the first service, as well as the security levels supported by multiple fifth nodes.

[0220] The security level corresponding to the second node can be understood as the required security level / security protection level for the second node; the security level corresponding to the first service can be understood as the required security level / security protection level for the first service. The first service is the service to be executed by the second node. The type of the first service can be found in the communication method 100 above, and will not be repeated here. For example, the security level corresponding to the second node may be quantum-safe and / or non-quantum-safe, the security level corresponding to the first service may be quantum-safe and / or non-quantum-safe, and the security level supported by the fifth node may include at least one of the following: quantum-safe or non-quantum-safe.

[0221] Additionally, the first node is the node currently connected to the second node, meaning the first node is the service node of the second node; the multiple fifth nodes are nodes that the second node can switch between, meaning the multiple fifth nodes are the neighbor nodes of the second node. The target node is either the fifth node that supports the security level corresponding to the second node, or the fifth node that supports the security level corresponding to the first service.

[0222] As can be seen, the first node can determine the target node to be accessed / switched from multiple neighboring nodes based on the security level corresponding to the terminal device or the security level corresponding to the first service to be executed by the terminal device, as well as the security levels supported by multiple neighboring nodes of the terminal device. This enables the terminal device to access neighboring nodes that meet the security requirements, thereby facilitating the execution of the first service by the neighboring node for the terminal device.

[0223] In some embodiments, S501 can be replaced by: the first node determining the target cell to which the second node should access based on the security level corresponding to the second node or the security level corresponding to the first service, and the security levels supported by the multiple second cells respectively. Here, the second cell is a neighboring cell of the second node, and the first node, the first cell, the multiple fifth nodes, and the multiple second cells can all provide a public land mobile network (PLMN) for the terminal device.

[0224] As can be seen, the first node can determine the target cell for the terminal device to access / handover from multiple neighboring cells based on the security level corresponding to the terminal device or the security level corresponding to the first service to be executed by the terminal device, as well as the security levels supported by the multiple neighboring cells of the terminal device. Thus, the terminal device can access a neighboring cell that meets the security requirements, which is beneficial for that neighboring cell to execute the first service for the terminal device.

[0225] In some embodiments, the first node may also determine the tracking area (TA) and selective optimal routing (SOR) of the second node based on the security level corresponding to the second node or the security level corresponding to the first service, as well as the security levels supported by the multiple fifth nodes respectively.

[0226] S502, the first node sends a seventh message to the second node, the seventh message being used to instruct the second node to connect to the target node. Correspondingly, the second node receives the seventh message from the first node.

[0227] In some embodiments, the first node can send the seventh message to the second node through an intermediate node. Alternatively, the second node can receive the seventh message from the first node through an intermediate node.

[0228] In some embodiments, the seventh information includes the identity identifier of the target node, so that the second node can determine the target node based on the identity identifier of the target node.

[0229] As can be seen, the first node can use the seventh information to instruct the terminal device to access / switch to the target node that meets the terminal device's perception requirements, so that it can request the execution of services from the target node, enabling the second node to obtain the required security protection.

[0230] In some embodiments, the seventh information is used to instruct the second node to access the target node, which can be replaced by: the seventh information being used to instruct the second node to access / handover to the target cell, so that the second node can access the target cell that meets the sensing requirements. In some embodiments, the seventh information includes the cell identifier of the target cell, so that the second node can determine the target cell based on the cell identifier of the target cell.

[0231] For example, the terminal device is currently camped in cell 1, and is also covered by cells 2 and 3, meaning cells 2 and 3 are neighboring cells of the terminal device. If the signal quality of the cell where the terminal device is currently camped deteriorates, base station 1, located in cell 1, determines cell 2 as the target cell for the terminal device to access / handover, based on the security level required by the terminal device (quantum security), the security level supported by cell 1 (non-quantum security), and the security level supported by cell 2 (quantum security). Therefore, base station 1 instructs the terminal device to access / handover to cell 2 via the seventh information.

[0232] S503, The second node connects to the target node.

[0233] Understandably, after receiving the seventh information from the first node, the second node connects to the target node based on the seventh information. For example, the second node determines the target node based on the target node's identity identifier in the seventh information, and then connects to / switches to that target node.

[0234] In some embodiments, S503 can be replaced by: the second node accessing the target cell. In some embodiments, the second node determines the target cell based on the identity identifier of the target cell in the seventh information, and then accesses / handovers to the target cell.

[0235] In some embodiments, the second node may send a request message to the target node requesting the execution of a first service, and the request message includes the security level required for the first service. Correspondingly, the target node receives the request message from the second node requesting the execution of a first task; based on the security level required for the first service, the target node executes the first task for the second node, enabling the second node to obtain the necessary security protection.

[0236] As can be seen, in this embodiment of the present disclosure, the node currently accessed by the terminal device determines the target node to be accessed by the terminal device from multiple neighboring nodes based on the security level corresponding to the terminal device or the security level required for the first service to be executed by the terminal device, as well as the security levels supported by multiple service nodes respectively, and instructs the terminal device to access the target node. This is beneficial for the target node that meets the security requirements of the terminal device to execute the service for the terminal device, so that the terminal device can obtain security protection that meets the security requirements.

[0237] Please refer to Figure 6, which is a schematic diagram of a communication device provided in an embodiment of the present invention. The communication device can be a first node, a chip in the first node, or a chip module. Specifically, as shown in Figure 6, the communication device 600 may include a processing unit 601 and a communication unit 602.

[0238] In one embodiment, the communication device 600 is applied in a first node, wherein:

[0239] The processing unit 601 is configured to acquire first information related to the second node, the first information being used to indicate at least one of the following: the security level requested by the second node, the security level supported by the second node, or the identity identifier of the second node.

[0240] The processing unit 601 is also configured to determine the first security level corresponding to the second node based on the first information.

[0241] The processing unit 601 is also configured to provide second information, which is used to indicate a first security resource, the first security resource being a security resource that matches a first security level.

[0242] In one embodiment, the processing unit 601 is used to obtain first information related to the second node, including receiving the first information related to the second node through the communication unit 602.

[0243] In one embodiment, the communication unit 602 receives first information related to the second node, including receiving first information related to the second node from the second node; the processing unit 601 provides second information, including sending the second information to the second node.

[0244] In one embodiment, the processing unit 601 determines the first security level corresponding to the second node based on first information and at least one of the following: the type of the first service, the security level supported by the communication device, the security level information subscribed by the second node, or the load capacity information of the communication device. The first service is the service that the second node requests to be executed by the first node, and the security level information subscribed by the second node includes at least one of the following: security level, algorithm, identity of the second node, data network name, identifier of the first service, and service type of the first service.

[0245] In one embodiment, the processing unit 601 further performs the following steps: obtaining the security level information of the second node's contract; and saving the security level information of the second node's contract.

[0246] In one embodiment, the second node is a terminal device, and the communication unit 602 sends third information to the terminal device. The third information is used to instruct the terminal device to access the third node, and the third node supports a first security level.

[0247] In one embodiment, the second node is an application function (AF), and the communication unit 602 sends third information to the AF. The third information is used to instruct the AF to request the execution of services from the third node, and the third node supports the first security level.

[0248] In one embodiment, the communication unit 602 sends third information to the terminal device or AF when the communication device does not support the first security level.

[0249] In one embodiment, the third information is further used to indicate that the communication device does not support a security level that matches the first security resource.

[0250] In one implementation, the first information is carried in any of the following: a non-access stratum message, a radio resource control message, a packet data convergence protocol message, a radio link control message, a media access control message, a physical layer message, a data processing message, or user plane data.

[0251] In one implementation, the non-access stratum message is any one of the following: registration message, session message, authentication message, key negotiation message; the radio resource control message is any one of the following: radio link establishment message, radio link reconfiguration message.

[0252] In one implementation, the first security level is either quantum secure or non-quantum secure.

[0253] In one embodiment, the first security resource includes at least one of the following: an algorithm, a software resource, or a hardware resource; wherein the algorithm and / or the software resource and / or the hardware resource are used for at least one of the following: encryption, key generation or negotiation required for encryption, integrity protection, non-repudiation, or authentication.

[0254] In another embodiment, the communication device 600 is applied in a second node, wherein:

[0255] The communication unit 602 is configured to send first information, which indicates at least one of the following: the security level requested by the communication device, the security level supported by the communication device, or the identity identifier of the communication device.

[0256] The communication unit 602 is also used to receive second information, which is used to indicate a first security resource, the first security resource being matched with a first security level, and the first security level being determined based on the first information.

[0257] Processing unit 601 is used to execute a first service based on a first security resource.

[0258] In one embodiment, the communication unit 602 sends first information, including sending the first information to a first node; the communication unit 602 receives second information, including receiving second information from the first node.

[0259] In one embodiment, the processing unit 601 executes a first service based on the first security resource, provided that the communication device supports the first security resource.

[0260] In one embodiment, the second node is a terminal device, and the communication unit 601 receives third information from the first node. The third information is used to instruct the terminal device to access the third node, and the third node supports a security level that matches the first security resource; access the third node.

[0261] In one embodiment, the communication device is an application function (AF). The communication unit 601 receives third information from a first node, which instructs the AF to request the execution of a service from the third node. The third node supports a security level that matches the first security resource. The communication unit 601 then sends fourth information to the third node, which in turn requests the execution of the first service from the third node.

[0262] In one implementation, the third information is also used to indicate that the first node does not support a security level that matches the first security resource.

[0263] In one implementation, the first information is carried in any of the following: a non-access stratum message, a radio resource control message, a packet data convergence protocol message, a radio link control message, a media access control message, a physical layer message, a data processing message, or user plane data.

[0264] In one implementation, the non-access stratum message is any one of the following: registration message, session message, authentication message, or key negotiation message; the radio resource control message is any one of the following: radio link establishment message or radio link reconfiguration message.

[0265] In one implementation, the first security level is either quantum secure or non-quantum secure.

[0266] In one embodiment, the first security resource includes at least one of the following: an algorithm, a software resource, or a hardware resource; wherein the algorithm and / or the software resource and / or the hardware resource are used for at least one of the following: encryption, key generation or negotiation required for encryption, integrity protection, non-repudiation, or authentication.

[0267] In another embodiment, the communication device 600 is applied in a second node, wherein:

[0268] The communication unit 602 is used to receive fifth information from at least one first node, the fifth information being used to indicate the security level supported by the first node.

[0269] Processing unit 601 is configured to determine a fourth node based on the security level supported by the communication device or the security level corresponding to the first service, and the security levels supported by at least one first node. The fourth node is one of the at least one first node that supports the security level supported by the communication device or the security level corresponding to the first service, where the first service is the service to be executed by the communication device.

[0270] The communication unit 602 is also used to send a sixth message to the fourth node, the sixth message being used to request the fourth node to execute the first service, and the sixth message indicating the security level required for the first service.

[0271] In one embodiment, the processing unit 601 is also used to access the fourth node.

[0272] In one implementation, the security level is quantum secure and / or non-quantum secure.

[0273] In another embodiment, the communication device 600 is applied in a fourth node, wherein:

[0274] The communication unit 602 is used to send fifth information to the second node, the fifth information being used to indicate the security level supported by the communication device.

[0275] The communication unit 602 is also configured to receive sixth information from the second node, the sixth information being used to request the execution of the first service, the sixth information indicating the security level required for the first service; the security level supported by the communication device is the same as the security level supported by the second node, or the security level supported by the communication device is the same as the security level corresponding to the first service.

[0276] Processing unit 601 is used to perform first business based on the security level indicated by the sixth information.

[0277] In one implementation, the security level is quantum secure and / or non-quantum secure.

[0278] In another embodiment, the communication device 600 is applied in the first node, wherein:

[0279] The processing unit 601 is used to determine the target node to be accessed by the second node based on the security level corresponding to the second node or the security level corresponding to the first service, and the security levels supported by the multiple fifth nodes respectively. The target node is the node among the multiple fifth nodes that supports the security level corresponding to the second node or the security level corresponding to the first service.

[0280] The communication unit 602 is used to send a seventh message to the second node, which instructs the second node to access the target node.

[0281] In one implementation, the security level is quantum secure and / or non-quantum secure.

[0282] In another embodiment, the communication device 600 is applied in a second node, wherein:

[0283] The communication unit 602 is used to receive seventh information from the first node. The seventh information is used to instruct the communication device to access the target node. The target node supports the security level corresponding to the communication device or the security level corresponding to the first service. The first service is the service to be executed by the second node.

[0284] Processing unit 601 is used to access the target node.

[0285] In one implementation, the security level is quantum secure and / or non-quantum secure.

[0286] For a more detailed description of the communication device 600 and its technical effects, please refer to the relevant descriptions in the above method embodiments, which will not be repeated here.

[0287] Please refer to Figure 7, which is a schematic diagram of the structure of a communication device provided in an embodiment of this disclosure. The communication device 700 may include a memory 701 and a processor 702. In some embodiments, the communication device 700 further includes a communication interface 703. The memory 701, processor 702, and communication interface 703 are connected via one or more communication buses. The communication interface 703 is controlled by the processor 702 and is used for sending and receiving information.

[0288] Memory 701 may include read-only memory and random access memory, and provides instructions and data to processor 702. A portion of memory 701 may also include non-volatile random access memory.

[0289] The communication interface 703 is used to receive or send data.

[0290] Processor 702 can be a central processing unit (CPU). The processor 702 can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor; in some embodiments, the processor 702 can also be any conventional processor. Wherein:

[0291] Memory 701 is used to store program instructions.

[0292] Processor 702 is used to call program instructions stored in memory 701.

[0293] The processor 702 calls the program instructions stored in the memory 701, causing the communication device 700 to execute the method performed by the first node or the second node in the above method embodiment.

[0294] This disclosure also provides a computer-readable storage medium (including non-transient computer-readable storage media). This computer-readable storage medium stores instructions that, when executed on a processor, enable the implementation of the method flow described in the above method embodiments.

[0295] This disclosure also provides a computer program product. When the computer program product is run on a processor, the method flow of the above-described method embodiments is implemented.

[0296] Regarding the modules / units included in the various devices and products described in the above embodiments, these modules / units can be software modules / units, hardware modules / units, or a combination of both. For example, for various devices and products applied to or integrated into a chip, all of their included modules / units can be implemented using hardware methods such as circuits, or at least some modules / units can be implemented using software programs that run on the integrated processor within the chip, while the remaining (if any) modules / units can be implemented using hardware methods such as circuits. For various devices and products applied to or integrated into a chip module, all of their included modules / units can be implemented using hardware methods such as circuits. Different modules / units can be located in the same piece (e.g., chip, circuit module, etc.) or different components of the chip module, or at least some modules / units can be implemented using software programs that run on the integrated processor within the chip module, while the remaining (if any) modules / units can be implemented using hardware methods such as circuits. For various devices and products applied to or integrated into the terminal, the modules / units contained therein can all be implemented in hardware such as circuits. Different modules / units can be located in the same component (e.g., chip, circuit module, etc.) or different components within the terminal. Alternatively, at least some modules / units can be implemented in software programs that run on the processor integrated inside the terminal, while the remaining (if any) modules / units can be implemented in hardware such as circuits.

[0297] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this disclosure is not limited to the described order of actions. This is because, according to this disclosure, some operations can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this disclosure.

[0298] The descriptions of the various embodiments provided in this disclosure can be referenced mutually. Each embodiment has its own emphasis; parts not detailed in a particular embodiment can be found in the relevant descriptions of other embodiments. For ease of description and brevity, for example, regarding the functions and operations of the various devices and equipment provided in the embodiments of this disclosure, reference can be made to the relevant descriptions of the method embodiments of this disclosure. The method embodiments and device embodiments can also be referenced, combined, or cited mutually. All embodiments of this disclosure can be performed individually or in combination with other embodiments, and all are considered to be within the scope of protection claimed by this disclosure.

[0299] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this disclosure, and not to limit them. Although this disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features. These modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this disclosure.

Claims

1. A communication method, wherein, The method is executed by the first node, and the method includes: Obtain first information related to the second node, the first information being used to indicate at least one of the following: the security level requested by the second node, the security level supported by the second node, and the identity identifier of the second node; Based on the first information, determine the first security level corresponding to the second node; Provide second information, which is used to indicate a first security resource, the first security resource being a security resource that matches the first security level.

2. The method according to claim 1, wherein, The acquisition of the first information related to the second node includes: Receive first information related to the second node.

3. The method according to claim 2, wherein, Receiving the first information related to the second node includes: receiving the first information related to the second node from the second node; Providing the second information includes sending the second information to the second node.

4. The method according to any one of claims 1 to 3, wherein, The step of determining the first security level corresponding to the second node based on the first information includes: Based on the first information and at least one of the following: the type of the first service, the security level supported by the first node, the security level information of the second node's contract, or the load capacity information of the first node, the first security level corresponding to the second node is determined. Wherein, the first service is the service that the second node requests to be executed by the first node, and the security level information signed by the second node includes at least one of the following: security level, security resources, identity identifier of the second node, data network name, identifier of the first service, or service type of the first service.

5. The method according to claim 4, wherein, The method further includes: Obtain the security level information of the second node's contract; Save the security level information of the second node's contract.

6. The method according to any one of claims 1 to 5, wherein, The second node is a terminal device, and the method further includes: A third message is sent to the terminal device, the third message being used to instruct the terminal device to access a third node, the third node supporting the first security level.

7. The method according to any one of claims 1 to 5, wherein, The second node is the application function AF, and the method further includes: The third information is sent to the AF, which instructs the AF to request the execution of a service from a third node, wherein the third node supports the first security level.

8. The method according to claim 6 or 7, wherein, Sending third information to the terminal device or the AF includes: If the first node does not support the first security level, it sends the third information to the terminal device or the AF.

9. The method according to any one of claims 6 to 8, wherein, The third piece of information is also used to indicate that the first node does not support a security level that matches the first security resource.

10. The method according to any one of claims 1 to 9, wherein, The first information is carried in any of the following: non-access stratum message, radio resource control message, packet data convergence protocol message, radio link control message, media access control message, physical layer message, data processing message, or user plane data.

11. The method according to claim 10, wherein, in, The non-access stratum message is any one of the following: registration message, session message, authentication message, or key negotiation message; The radio resource control message is any one of the following: radio link establishment message or radio link reconfiguration message.

12. The method according to any one of claims 1 to 11, wherein, The first security level is either quantum secure or non-quantum secure.

13. The method according to any one of claims 1 to 12, wherein, The first security resource includes at least one of the following: an algorithm, a software resource, or a hardware resource; The algorithm and / or the software resources and / or the hardware resources are used for at least one of the following: encryption, key generation or negotiation required for encryption, integrity protection, non-repudiation, or authentication.

14. A communication method, wherein, The method is applied to the second node, and the method includes: Send a first message, the first message being used to indicate at least one of the following: the security level requested by the second node, the security level supported by the second node, or the identity identifier of the second node; Receive second information, the second information being used to indicate a first security resource, the first security resource being matched with a first security level, the first security level being determined based on the first information; Based on the first security resource, execute the first service.

15. The method according to claim 14, wherein, Sending the first information includes: sending the first information to the first node; Receiving the second information includes receiving second information from the first node.

16. The method according to claim 14 or 15, wherein, The execution of the first service based on the first security resource includes: If the second node supports the first security resource, the first service is executed based on the first security resource.

17. The method according to any one of claims 14 to 16, wherein, The second node is a terminal device, and the method further includes: Receive third information from the first node, the third information being used to instruct the terminal device to access the third node, the third node supporting a security level matching the first security resource; Connect to the third node.

18. The method according to any one of claims 14 to 16, wherein, The second node is the application function AF, and the method further includes: The third information is received from the first node, which instructs the AF to request the execution of a service from the third node, wherein the third node supports a security level that matches the first security resource. Send a fourth message to the third node, the fourth message being used to request the third node to execute the first service.

19. The method according to claim 17 or 18, wherein, The third piece of information is also used to indicate that the first node does not support a security level that matches the first security resource.

20. The method according to any one of claims 14 to 19, wherein, The first information is carried in any of the following: non-access stratum message, radio resource control message, packet data convergence protocol message, radio link control message, media access control message, physical layer message, data processing message, or user plane data.

21. The method according to claim 20, wherein, in, The non-access stratum message is any one of the following: registration message, session message, authentication message, or key negotiation message; The radio resource control message is any one of the following: radio link establishment message or radio link reconfiguration message.

22. The method according to any one of claims 14 to 21, wherein, The first security level is either quantum secure or non-quantum secure.

23. The method according to any one of claims 14 to 22, wherein, The first security resource includes at least one of the following: algorithm, software resource, and hardware resource; The algorithm and / or the software resources and / or the hardware resources are used for at least one of the following: encryption, key generation or negotiation required for encryption, integrity protection, non-repudiation, and authentication.

24. A communication device, wherein, The device includes a processing unit and a communication unit, the communication unit being used to send and receive signals / signaling. The processing unit is configured to acquire first information related to the second node, wherein the first information is used to indicate at least one of the following: the security level requested by the second node, the security level supported by the second node, or the identity identifier of the second node; The processing unit is configured to determine the first security level corresponding to the second node based on the first information; The processing unit is further configured to provide second information, which indicates a first security resource, the first security resource being a security resource that matches the first security level.

25. A communication device, wherein, The device includes a processing unit and a communication unit. The communication unit is configured to send first information, the first information being configured to indicate at least one of the following: the security level requested by the device, the security level supported by the device, or the identity identifier of the device; The communication unit is further configured to receive second information, the second information being used to indicate a first security resource, the first security resource being matched with a first security level, the first security level being determined based on the first information; The processing unit is used to execute a first service based on the first security resource.

26. A communication device, wherein, The communication device includes a processor and a memory interconnected thereto. The memory is used to store a computer program, the computer program including program instructions. The processor is configured to invoke the program instructions to perform the method as described in any one of claims 1 to 13, or to perform the method as described in any one of claims 14 to 23.

27. A chip, wherein, The chip includes at least one processor and an interface circuit, the interface circuit being connected to the at least one processor, the processor executing program instructions to perform the method as described in any one of claims 1 to 13, or to perform the method as described in any one of claims 14 to 23.

28. A non-transient computer-readable storage medium, wherein, The computer-readable storage medium stores computer-readable instructions that, when executed on a communication device, cause the communication device to perform the method as described in any one of claims 1 to 13, or the method as described in any one of claims 14 to 23.