WO2022068474A1 - ProSe通信组的通信方法、装置及存储介质 - Google Patents

ProSe通信组的通信方法、装置及存储介质 Download PDF

Info

Publication number
WO2022068474A1
WO2022068474A1 PCT/CN2021/114506 CN2021114506W WO2022068474A1 WO 2022068474 A1 WO2022068474 A1 WO 2022068474A1 CN 2021114506 W CN2021114506 W CN 2021114506W WO 2022068474 A1 WO2022068474 A1 WO 2022068474A1
Authority
WO
WIPO (PCT)
Prior art keywords
group
communication
prose
key
information
Prior art date
Application number
PCT/CN2021/114506
Other languages
English (en)
French (fr)
Inventor
周巍
Original Assignee
大唐移动通信设备有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 大唐移动通信设备有限公司 filed Critical 大唐移动通信设备有限公司
Publication of WO2022068474A1 publication Critical patent/WO2022068474A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/041Key generation or derivation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/043Key management, e.g. using generic bootstrapping architecture [GBA] using a trusted network node as an anchor
    • H04W12/0433Key management protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/06Selective distribution of broadcast services, e.g. multimedia broadcast multicast service [MBMS]; Services to user groups; One-way selective calling services
    • H04W4/08User group management
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/80Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication

Definitions

  • the present application relates to the field of communication technologies, and in particular, to a communication method, device and storage medium for a ProSe communication group.
  • Proximity Services In the 4th generation mobile communication technology (4G), Proximity Services (ProSe) only supports public safety applications, while in the 5th generation mobile networks (5G) , ProSe will support public safety applications and commercial service applications.
  • public safety applications the establishment of the ProSe communication group is static, that is, the group is established in advance, and members are also added to the group in advance.
  • groups may be dynamically established, and group members may be dynamically added to or removed from the group. For example, an adjacent terminal (UE) establishes an interactive game group through a PC5 interface.
  • UE adjacent terminal
  • Embodiments of the present application provide a communication method, device, and storage medium for a ProSe communication group, so as to solve the problem of how to perform secure communication in a ProSe communication group.
  • an embodiment of the present application provides a communication method for a ProSe communication group, which is applied to a key management functional entity, including:
  • the first group of communication key request messages includes the first UE
  • the identity information of the first UE and the first authorization token issued by the application server for the first UE, or the first group communication key request message contains the identity information of the first UE and the ProSe communication group attribute information;
  • the identity information of the first UE and the first authorization token are included in the first group of communication key request messages, generating the identity information based on the identity information of the first UE and the first authorization token group communication key;
  • the identity information of the first UE and the attribute information of the ProSe communication group are included in the first group communication key request message, based on the identity information of the first UE and the attribute information Obtain the key generation authorization in the application server and generate the group communication key;
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the first authorization token includes: the identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the first The role information of the UE in the ProSe communication group, and the role information of the first UE is the group administrator.
  • an embodiment of the present application provides a communication method for a ProSe communication group, which is applied to a first user equipment UE, including:
  • the first UE When the first UE establishes a ProSe communication group under the proximity service ProSe application through the application server, it sends a first group of communication key request messages to the key management function entity; wherein the first group of communication key request messages includes There is the identity information of the first UE and the first authorization token issued by the application server for the first UE, so that the key management function entity is based on the identity information of the first UE and the first authorization token.
  • the first authorization token generates a group communication key, or the first group communication key request message contains the identity information of the first UE and the attribute information of the ProSe communication group, so that the key management
  • the functional entity obtains a key generation authorization from the application server based on the identity information of the first UE and the attribute information, and generates a group communication key;
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the first authorization token includes: the identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the first The role information of the UE in the ProSe communication group, and the role information of the first UE is the group administrator.
  • an embodiment of the present application provides a communication method for a ProSe communication group, which is applied to a second user equipment UE, including:
  • the second UE When the second UE joins the ProSe communication group under the proximity service ProSe application established by the first UE, it sends a second group of communication key request messages to the key management function entity; wherein the second group of communication key request messages contains the identity information of the second UE and the second authorization token issued by the application server for the second UE, so that the key management function entity is based on the identity information of the second UE and the The second authorization token obtains the group communication key of the ProSe communication group, or the group communication key request message contains the identity information of the second UE and the attribute information of the ProSe communication group, so that all The key management function entity obtains a key issuance authorization from the application server based on the identity information of the second UE and the attribute information and obtains the group communication key of the ProSe communication group;
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the second authorization token includes: the identity information of the second UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the second The role information of the UE in the ProSe communication group, and the role information of the second UE is a group member.
  • an embodiment of the present application provides a communication device for a ProSe communication group, including a memory, a transceiver, and a processor:
  • a memory for storing a computer program
  • a transceiver for sending and receiving data under the control of the processor
  • a processor for reading the computer program in the memory and performing the following operations:
  • the first group of communication key request messages includes the first UE
  • the identity information of the first UE and the first authorization token issued by the application server for the first UE, or the first group communication key request message contains the identity information of the first UE and the ProSe communication group attribute information;
  • the identity information of the first UE and the first authorization token are included in the first group of communication key request messages, generating the identity information based on the identity information of the first UE and the first authorization token group communication key;
  • the identity information of the first UE and the attribute information of the ProSe communication group are included in the first group communication key request message, based on the identity information of the first UE and the attribute information Obtain the key generation authorization in the application server and generate the group communication key;
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the first authorization token includes: the identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the first The role information of the UE in the ProSe communication group, and the role information of the first UE is the group administrator.
  • an embodiment of the present application provides a communication device for a ProSe communication group, including a memory, a transceiver, and a processor:
  • a memory for storing a computer program
  • a transceiver for sending and receiving data under the control of the processor
  • a processor for reading the computer program in the memory and performing the following operations:
  • the first UE When the first UE establishes a ProSe communication group under the proximity service ProSe application through the application server, it sends a first group of communication key request messages to the key management function entity; wherein the first group of communication key request messages includes There is the identity information of the first UE and the first authorization token issued by the application server for the first UE, so that the key management function entity is based on the identity information of the first UE and the first authorization token.
  • the first authorization token generates a group communication key, or the first group communication key request message contains the identity information of the first UE and the attribute information of the ProSe communication group, so that the key management
  • the functional entity obtains a key generation authorization from the application server based on the identity information of the first UE and the attribute information and generates a group communication key;
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the first authorization token includes: the identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the first The role information of the UE in the ProSe communication group, and the role information of the first UE is the group administrator.
  • an embodiment of the present application provides a communication device for a ProSe communication group, including a memory, a transceiver, and a processor:
  • a memory for storing a computer program
  • a transceiver for sending and receiving data under the control of the processor
  • a processor for reading the computer program in the memory and performing the following operations:
  • the second UE When the second UE joins the ProSe communication group under the proximity service ProSe application established by the first UE, it sends a second group of communication key request messages to the key management function entity; wherein the second group of communication key request messages contains the identity information of the second UE and the second authorization token issued by the application server for the second UE, so that the key management function entity is based on the identity information of the second UE and the The second authorization token obtains the group communication key of the ProSe communication group, or the group communication key request message contains the identity information of the second UE and the attribute information of the ProSe communication group, so that all The key management function entity obtains a key issuance authorization from the application server based on the identity information of the second UE and the attribute information and obtains the group communication key of the ProSe communication group;
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the second authorization token includes: the identity information of the second UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the second The role information of the UE in the ProSe communication group, and the role information of the second UE is a group member.
  • an embodiment of the present application provides a communication device for a ProSe communication group, which is applied to a key management functional entity, including:
  • the receiving module is configured to receive the first group of communication key request messages sent when the first user equipment UE establishes the ProSe communication group under the proximity service ProSe application through the application server, wherein the first group of communication key request messages Contains the identity information of the first UE and the first authorization token issued by the application server for the first UE, or the first group of communication key request messages contains the identity information of the first UE and attribute information of the ProSe communication group;
  • the first generation module is configured to, when the first group of communication key request messages contain the identity information of the first UE and the first authorization token, generate a method based on the identity information of the first UE and the first authorization token.
  • the first authorization token generates a group communication key
  • the second generating module is configured to, when the first group communication key request message contains the identity information of the first UE and the attribute information of the ProSe communication group, generate the information based on the identity information of the first UE and the attribute information of the ProSe communication group.
  • the attribute information obtains a key generation authorization from the application server and generates a group communication key;
  • a sending module configured to send a first group of communication key response messages to the first UE, wherein the first group of communication key response messages includes the group of communication keys;
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the first authorization token includes: the identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the first The role information of the UE in the ProSe communication group, and the role information of the first UE is the group administrator.
  • an embodiment of the present application provides a communication apparatus for a ProSe communication group, which is applied to a first user equipment UE, including:
  • the sending module is configured to send the first group of communication key request messages to the key management function entity when the first UE establishes a ProSe communication group under the ProSe application of the proximity service through the application server; wherein the first group of communication keys
  • the key request message contains the identity information of the first UE and the first authorization token issued by the application server for the first UE, so that the key management function entity is based on the first UE's identity information.
  • the identity information and the first authorization token generate a group communication key, or the first group communication key request message contains the identity information of the first UE and the attribute information of the ProSe communication group, so that the The key management function entity obtains a key generation authorization from the application server based on the identity information of the first UE and the attribute information, and generates a group communication key;
  • a receiving module configured to receive a first group of communication key response messages sent by the key management function entity, wherein the first group of communication key response messages includes the group of communication keys;
  • a communication module for communicating with a group member who subsequently joins the ProSe communication group based on the group communication key
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the first authorization token includes: the identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the first The role information of the UE in the ProSe communication group, and the role information of the first UE is the group administrator.
  • an embodiment of the present application provides a communication device for a ProSe communication group, which is applied to a second user equipment UE, including:
  • a sending module configured to send a second group of communication key request messages to the key management function entity when the second UE joins the ProSe communication group under the proximity service ProSe application established by the first UE; wherein the second group
  • the communication key request message contains the identity information of the second UE and the second authorization token issued by the application server for the second UE, so that the key management function entity is based on the second UE's identity information.
  • the identity information and the second authorization token obtain the group communication key of the ProSe communication group, or the group communication key request message contains the identity information of the second UE and the attribute of the ProSe communication group information, so that the key management function entity obtains key issuance authorization from the application server based on the identity information of the second UE and the attribute information and obtains the group communication key of the ProSe communication group;
  • a receiving module configured to receive a second group of communication key response messages sent by the key management function entity, wherein the second group of communication key response messages includes the group of communication keys;
  • a communication module for communicating with members in the ProSe communication group based on the group communication key
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the second authorization token includes: the identity information of the second UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the second The role information of the UE in the ProSe communication group, and the role information of the second UE is a group member.
  • an embodiment of the present application provides a processor-readable storage medium, where the processor-readable storage medium stores a computer program, and the computer program is used to cause a processor to execute the first aspect, the second aspect, or the first aspect.
  • the key management function entity receives the first group of communication key request messages sent by the first UE, and the first group of communication key request messages
  • the group communication key is directly generated based on the identity information of the first UE and the first authorization token
  • the first group communication key request message contains the
  • the key management function entity when the key management function entity generates the group communication key based on the first authorization token, the background interaction process between the application server and the key management function entity is avoided, and the ProSe communication group is guaranteed.
  • the key management function entity obtains the key generation authorization from the application server based on the attribute information of the ProSe communication group and then generates the group communication key, the application server does not need to issue an authorization token to the first UE, reducing the need for The transmission parameters between the UE and the network entity are reduced, that is, the UE overhead is reduced, and the secure communication of the ProSe communication group is guaranteed.
  • Fig. 1 is the step flow chart of the communication method that is applied to the ProSe communication group of key management functional entity in the embodiment of the application;
  • FIG. 2 is a flowchart of steps of a communication method applied to a ProSe communication group of a first UE in an embodiment of the present application
  • FIG. 3 is a flowchart of steps of a communication method applied to a ProSe communication group of a second UE in an embodiment of the present application;
  • FIG. 5 is the second schematic diagram of establishing ProSe communication group security communication in the embodiment of the application.
  • FIG. 6 is a block diagram of a module of a communication device applied to a ProSe communication group of a key management functional entity in an embodiment of the application;
  • FIG. 7 is a block diagram of a module of a communication device applied to a ProSe communication group of a first UE in an embodiment of the present application;
  • FIG. 8 is a block diagram of a module of a communication device applied to a ProSe communication group of a second UE in an embodiment of the present application;
  • FIG. 9 is one of the schematic structural diagrams of the communication device of the ProSe communication group in the embodiment of the application.
  • FIG. 10 is the second schematic structural diagram of the communication device of the ProSe communication group in the embodiment of the application.
  • FIG. 11 is a third schematic structural diagram of a communication device of a ProSe communication group in an embodiment of the present application.
  • the applicable system may be a global system of mobile communication (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (Wideband Code Division Multiple Access, WCDMA) general packet Wireless service (general packet radio service, GPRS) system, long term evolution (long term evolution, LTE) system, LTE frequency division duplex (frequency division duplex, FDD) system, LTE time division duplex (time division duplex, TDD) system, Long term evolution advanced (LTE-A) system, universal mobile telecommunication system (UMTS), worldwide interoperability for microwave access (WiMAX) system, 5G New Radio (New Radio, NR) system, etc.
  • GSM global system of mobile communication
  • CDMA code division multiple access
  • WCDMA wideband Code Division Multiple Access
  • general packet Wireless service general packet Radio service
  • GPRS general packet Wireless service
  • LTE long term evolution
  • LTE long term evolution
  • FDD frequency division duplex
  • FDD frequency division duplex
  • TDD time division duplex
  • the user equipment involved in the embodiments of the present application may be a device that provides voice and/or data connectivity to the user, a handheld device with a wireless connection function, or other processing devices connected to a wireless modem.
  • Wireless user equipment can communicate with one or more core networks (Core Network, CN) via a radio access network (Radio Access Network, RAN).
  • Core Network Core Network
  • RAN Radio Access Network
  • “telephone) and computers with mobile terminal equipment eg portable, pocket-sized, hand-held, computer-built or vehicle-mounted mobile devices, which exchange language and/or data with the radio access network.
  • PCS Personal Communication Service
  • SIP Session Initiated Protocol
  • WLL Wireless Local Loop
  • PDA Personal Digital Assistants
  • PDA Personal Digital Assistants
  • Wireless user equipment may also be referred to as system, subscriber unit, subscriber station, mobile station, mobile station, remote station, access point , a remote terminal device (remote terminal), an access terminal device (access terminal), a user terminal device (user terminal), a user agent (user agent), and a user device (user device), which are not limited in the embodiments of the present application.
  • the user equipment and other network equipment eg, core network equipment, access network equipment (ie, base station)
  • the user equipment is also regarded as a kind of network equipment.
  • Step 101 Receive a first group of communication key request messages sent by the first UE when the first UE establishes a ProSe communication group under the ProSe application through the application server.
  • the user equipment UE for short
  • the application server and the key management function entity are configured with parameters related to the dynamic ProSe communication group.
  • the UE is configured with the address information of the application server and the key management function entity.
  • the server is configured with UE subscription information related to ProSe communication group communication
  • the key management function entity is configured with key information for establishing a security association with the UE and security policies related to group communication security.
  • the first UE when the first UE wants to establish a ProSe communication group under a certain ProSe application, and establishes a ProSe communication group under the ProSe application through the application server, based on the need for secure communication in the communication group, the first UE can send The key management function entity sends the first group of communication key request messages, and at this time, the key management function entity receives the first group of communication key request messages sent by the first UE.
  • the first group of communication key request messages includes the identity information of the first UE and the first authorization token issued by the application server for the first UE, or the first group of communication key request messages includes the first UE identity information and attribute information of the ProSe communication group.
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the first authorization token includes: the identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the role information of the first UE in the ProSe communication group, and the first The role information of a UE is a group administrator, indicating that the ProSe communication group is established by the first UE.
  • the identity information of the UE refers to the identity information that uniquely identifies the communication members of the group in the ProSe communication group.
  • the identity information of the first UE can be the identity of the first UE or the user identity of the first UE in the ProSe application. This is not specifically limited.
  • the first authorization token may also include authorization information such as the validity period of the first authorization token and the token protection mechanism, which will not be specifically limited here.
  • both the key management function entity and the application server can pass the attribute information to the ProSe communication group.
  • the communication group is identified, and the duration of the ProSe communication group can be specified.
  • the key management function entity can verify whether the identity of the first UE is legal through the information in the first authorization token, and the role information of the first UE makes the key
  • the management function entity can determine whether the ProSe communication group is established by the first UE, so that the key management function entity can determine whether a group communication key of the ProSe communication group needs to be generated.
  • Step 102 When the first group communication key request message includes the identity information of the first UE and the first authorization token, generate a group communication key based on the identity information of the first UE and the first authorization token.
  • the key management function entity when the key management function entity detects that the first group of communication key request messages include the identity information of the first UE and the first authorization token, the key management function entity can verify the identity information of the first UE The identity of the first UE and the first authorization token are checked, that is, it can be directly combined with the identity information of the first UE and the first authorization token to check whether the first UE is a contracted UE of the application server, and when it is checked, it is based on the security policy. Generating the group communication key ensures the security of the group communication key generation process.
  • the key management function entity may also store the group identification information of the ProSe communication group obtained from the first authorization token, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the group communication key generated by itself, In order to provide the group communication key to the group members of the ProSe communication group who apply later.
  • Step 103 When the first group communication key request message contains the identity information of the first UE and the attribute information of the ProSe communication group, obtain the key generation authorization from the application server based on the identity information and attribute information of the first UE Generate group communication keys.
  • the key management function entity may determine the identity of the first UE from the application server based on the identity information of the first UE and the attribute information of the ProSe communication group and apply for a key generation authorization.
  • the group communication key is then generated when the identity information of a UE and the attribute information of the ProSe communication group are authorized by the application server to generate the key.
  • the key management function entity can determine whether to generate a group communication key through the interaction process with the application server in the background, so that the application server does not need to issue an authorization token to the first UE, and the transmission between the UE and the network entity is reduced.
  • the secure generation process of the group communication key is ensured, that is, the UE overhead is reduced and the secure communication of the ProSe communication group is guaranteed.
  • Step 104 Send a first set of communication key response messages to the first UE.
  • the first group communication key response message contains the group communication key, which enables the first UE to communicate with the group members in the ProSe communication group based on the group communication key after acquiring the group communication key, The communication security of the dynamic ProSe communication group established by the first UE is guaranteed.
  • the key management function entity in this embodiment receives the first set of communication key request messages sent by the first UE, and the first set of communication key request messages includes the identity information of the first UE and the first authorization
  • the group communication key is directly generated based on the identity information of the first UE and the first authorization token
  • the first group communication key request message contains the identity information of the first UE and the attribute information of the ProSe communication group.
  • the key generation authorization is obtained from the application server, the group communication key is generated, which realizes different group communication key generation processes for different information contained in the first group communication key request message.
  • the functional entity When the functional entity generates the group communication key based on the first authorization token, the background interaction process between the application server and the key management functional entity is avoided, and the secure communication of the ProSe communication group is ensured.
  • the key management functional entity based on ProSe communication When the attribute information of the group obtains the key generation authorization from the application server and then generates the group communication key, the application server does not need to issue an authorization token to the first UE, which reduces the transmission parameters between the UE and the network entity, that is, reduces the The UE overhead is reduced, and the secure communication of the ProSe communication group is guaranteed.
  • the The server sends a first authorization request message, wherein the first authorization request message includes the identity information of the first UE, the group identity information of the ProSe communication group, and the identity information of the ProSe application, so that the application server is based on the identity information of the first UE,
  • the group identification information of the ProSe communication group and the identification information of the ProSe application determine whether the first UE belongs to the ProSe communication group, and then receives the first authorization response message sent by the application server when it is determined that the first UE belongs to the ProSe communication group, wherein the first authorization The response message includes the identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the role information of the first UE in the Pro
  • the key management function entity when it obtains the key generation authorization, it can send the identity information of the first UE and the group identification information of the ProSe communication group and the identification information of the ProSe application included in the attribute information of the ProSe communication group to the application server.
  • the application server can send the first authorization request message
  • the identity information of the first UE, the group identification information of the ProSe communication group, and the identification information of the ProSe application are compared with the information recorded by itself, so as to determine whether the first UE belongs to the ProSe communication group, that is, to verify the legality of the identity of the first UE. sex.
  • the application server may send a first authorization response message to the key management function entity, and the first authorization response message It contains the identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the role information of the first UE in the ProSe communication group.
  • the key management function entity receives the first authorization response message, and determines the validity period of the ProSe communication group according to the validity period information of the ProSe communication group, and determines whether to generate a group communication key or directly search for the existing ProSe communication group according to the role information of the first UE.
  • the group communication key of the communication group of course, since the role information of the first UE is the group administrator, indicating that the ProSe communication group is newly created by the first UE, the key management function entity generates the group communication key.
  • the process of determining the key generation authorization from the application server to the key management function entity is realized, and the first UE is prevented from passing the authorization issued by the application server.
  • the problem of many interaction parameters between the first UE, the application server and the key management function entity reduces the number of communication between the first UE and the network entity.
  • the interaction parameter reduces the overhead of the first UE.
  • the application process may include the following steps:
  • Step A1 Receive a second group communication key request message sent by the second UE when it joins the ProSe communication group.
  • the second UE may send a second group of communication key request messages to the key management function entity.
  • the key management function The entity receives the second set of communication key request messages sent by the second UE.
  • the second set of communication key request messages includes the identity information of the second UE and the second authorization token issued by the application server for the second UE, or the second set of communication key request messages includes the second UE identity information and attribute information of the ProSe communication group.
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the second authorization token includes: the identity information of the second UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the role information of the second UE in the ProSe communication group, and the first The role information of the second UE is a group member.
  • the second authorization token may also include authorization information such as the validity period of the second authorization token and the token protection mechanism, which will not be specifically limited here.
  • the key management function entity can verify whether the second UE belongs to the ProSe communication group established by the application server through the information in the second authorization token, and the second The role information of the UE enables the key management function entity to determine whether the second UE is a group member that subsequently joins the ProSe communication group, thereby enabling the key management function entity to determine whether it is only necessary to obtain the generated group communication key of the ProSe communication group key.
  • Step A2 When the second group communication key request message contains the identity information of the second UE and the second authorization token, obtain the group of the ProSe communication group based on the identity information of the second UE and the second authorization token Communication key.
  • the key management function entity when the key management function entity detects that the second group of communication key request messages include the identity information of the second UE and the second authorization token, the key management function entity can verify the identity information of the second UE The identity of the second UE and the second authorization token are checked, that is, the identity information of the second UE and the second authorization token can be directly combined to check whether the second UE is a group member of the ProSe communication group, and when it is checked, according to the ProSe The communication group information retrieves the previously generated group communication key.
  • Step A3 When the second group communication key request message contains the identity information of the second UE and the attribute information of the ProSe communication group, obtain the key issuance authorization from the application server based on the identity information and attribute information of the second UE Get the group communication key for the ProSe communication group.
  • the key management function entity may query the application server for the identity of the second UE based on the identity information of the second UE and the attribute information of the ProSe communication group and apply for key issuance authorization.
  • the key management function entity obtains the key issuance authorization from the application server, and retrieves and obtains the information of the previously generated ProSe communication group. Group communication key.
  • the key management function entity can determine whether to issue a group communication key to the second UE through the interaction process with the application server in the background, so that the application server does not need to issue an authorization token to the second UE, reducing the number of UE and network entities.
  • the safe distribution process of the group communication key is ensured, that is, the UE overhead is reduced and the safe communication of the ProSe communication group is guaranteed.
  • Step A4 Send a second set of communication key response messages to the second UE.
  • the second group communication key response message contains the group communication key, which enables the second UE to communicate with other members in the ProSe communication group based on the group communication key after acquiring the group communication key, The communication security of the ProSe communication group is guaranteed.
  • the key management function entity in this embodiment receives the second set of communication key request messages sent by the second UE, and the second set of communication key request messages includes the identity information of the second UE and the second authorization
  • the token is used, the previously generated group communication key is directly retrieved based on the identity information of the second UE and the second authorization token, and the second group communication key request message contains the identity information of the second UE and the ProSe communication group.
  • the attribute information is obtained from the application server, the key issuance authorization is obtained, and then the group communication key is retrieved and obtained.
  • the key management function entity obtains the group communication key based on the second authorization token
  • the background interaction process between the application server and the key management function entity is avoided, and the secure communication of the ProSe communication group is ensured
  • the key management function is
  • the entity obtains the key issuance authorization from the application server based on the attribute information of the ProSe communication group and then obtains the previously generated group communication key
  • the application server does not need to issue an authorization token to the second UE, which reduces the amount of communication between the UE and the network entity. , which reduces the UE overhead and ensures the secure communication of the ProSe communication group.
  • the key management function entity when it obtains the key issuance authorization from the application server based on the identity information and attribute information of the second UE, it may first send a second authorization request message to the application server, in which the first authorization request message is sent to the application server.
  • the second authorization request message contains the identity information of the second UE, the group identity information of the ProSe communication group, and the identity information of the ProSe application, so that the application server is based on the identity information of the second UE, the group identity information of the ProSe communication group, and the ProSe application.
  • the second authorization response message contains the identity of the second UE information, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the role information of the second UE in the ProSe communication group.
  • the key management function entity may send the identity information of the second UE and the group identification information of the ProSe communication group and the identification information of the ProSe application included in the attribute information of the ProSe communication group to the application server.
  • the application server can transfer the information in the second authorization request message
  • the identity information of the second UE, the group identity information of the ProSe communication group, and the identity information of the ProSe application are compared with the information recorded by itself to determine whether the second UE belongs to the ProSe communication group, that is, to verify the legitimacy of the identity of the second UE.
  • the application server may send a second authorization response message to the key management function entity, and
  • the second authorization response message includes the identity information of the second UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group and the role information of the second UE in the ProSe communication group.
  • the key management function entity receives the second authorization response message, and determines the validity period of the ProSe communication group according to the validity period information of the ProSe communication group, and determines whether to generate a group communication key or directly search for the existing ProSe communication group according to the role information of the second UE.
  • the group communication key of the communication group of course, since the role information of the second UE is a group member, indicating that the second UE is joining the established ProSe communication group, the key management function entity retrieves and obtains the previously generated group communication key.
  • the process of determining the key issuance authorization from the application server to the key management functional entity is realized, and the second UE is prevented from passing the key issued by the application server.
  • the second authorization token applies to the key management function entity for the group communication key
  • the problem of many interaction parameters between the second UE, the application server and the key management function entity reduces the number of communication between the second UE and the network entity.
  • the interaction parameter reduces the overhead of the second UE.
  • the first UE may update the group communication key as needed, and the process of updating the group communication key at this time may include the following steps:
  • the key management function entity receives the first group of communication key update request messages sent by the first UE, wherein the first group of communication key update request messages contains a list of group members of the ProSe communication group; and then based on the first group of communication keys
  • the key update request message sends the updated group communication key to the first UE; receives the second group communication key update request message sent by the second UE, and determines that the second UE is a group of the ProSe communication group based on the group member list member, send the updated group communication key to the second UE.
  • the first UE when it decides that the group communication key update needs to be performed, it may send a first group communication key update request message to the key management function entity, and the message includes a list of group members, so that the key management function An entity can store a list of group members and generate new group communication keys. Then, the key management function entity sends the updated group communication key to the first UE, and the first UE notifies the group members of the ProSe communication group that the group communication key needs to be updated. Then, the second UE, which is a group member, may send a second group communication key update request message to the key management function entity. At this time, the key management function entity determines that the second UE is a group of the ProSe communication group based on the group member list. When a member, the updated group communication key is sent to the second UE, thereby realizing the group communication key update process of the ProSe communication group, so that the members of the ProSe communication group can use the updated group communication key for security. group communication.
  • This embodiment implements the dynamic establishment process of the ProSe communication group through the above process, and ensures the secure communication between the ProSe communication groups through the group communication key.
  • FIG. 2 it is a flowchart of steps of a communication method applied to a ProSe communication group of a first UE according to an embodiment of the present application, and the method includes the following steps:
  • Step 201 When the first UE establishes a ProSe communication group under a ProSe application through the application server, it sends a first group communication key request message to the key management function entity.
  • the first group of communication key request messages includes the identity information of the first UE and the first authorization token issued by the application server for the first UE, so that the key management function entity is based on the first UE's identity information.
  • the identity information and the first authorization token generate a group communication key; or the first group communication key request message contains the identity information of the first UE and the attribute information of the ProSe communication group, so that the key management function entity is based on the The identity information and attribute information of the first UE obtain the key generation authorization from the application server and generate the group communication key.
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the first authorization token includes: the identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the role information of the first UE in the ProSe communication group, and the first The role information of a UE is a group administrator.
  • Step 202 Receive the first group of communication key response messages sent by the key management function entity.
  • the key management function entity may generate a group communication key after receiving the first group communication key request message, and send the first group communication key response message to the first UE. At this time, the first UE receives the first set of communication key response messages.
  • the first group communication key response message includes the group communication key, so that the first UE can perform secure communication within the group based on the group communication key.
  • Step 203 Communicate with group members who join the ProSe communication group subsequently based on the group communication key.
  • the first UE communicates with the group members who join the ProSe communication group subsequently based on the group communication key, which ensures the secure communication of the ProSe communication group.
  • the first UE in this embodiment establishes a ProSe communication group under the ProSe application through the application server, it sends the first group of communication key request messages to the key management function entity, and receives the key management function entity based on the first group of communication key request messages.
  • the group communication key sent by a group communication key request message enables the ProSe communication group to perform intra-group communication based on the group communication key, ensuring the security of the ProSe communication group.
  • the first UE when the first UE establishes a ProSe communication group under a ProSe application through the application server, the first UE may send a group message to the application server when the first UE needs to establish a ProSe communication group under the ProSe application.
  • a communication establishment request wherein the group communication establishment request contains the identity information of the first UE and the identification information of the ProSe application; then a group communication establishment response message sent by the application server based on the group communication establishment request is received, wherein the group communication establishment response message is Contains attribute information of the established ProSe communication group, or includes attribute information of the established ProSe communication group and the first authorization token.
  • the first UE when it wants to establish a ProSe communication group under a certain ProSe application, it can first send a group communication establishment request to the application server, and the request includes the identity information of the first UE and the identification information of the ProSe application .
  • the application server may detect whether the first UE can establish a ProSe communication group based on the subscription information, and if so, establish a ProSe communication group.
  • the ProSe communication group has a unique group identity of the ProSe communication group, the identity of the ProSe application, the group member list and the group validity period and other attributes, and the group members in the group member list include UE identity information and UE role information, etc.
  • the roles of group members include group administrator and group member, the role of the UE requesting to create a ProSe communication group is the group administrator, and the role of the UE that subsequently joins the ProSe communication group is the group member.
  • the application server may send the attribute information of the ProSe communication group and the first authorization token to the first UE, or only send the attribute information of the ProSe communication group to the first UE.
  • the first UE can use the first authorization token to apply to the key management function entity responsible for managing the group communication key for a group communication key for intra-group secure communication.
  • the key management function entity can parse the first A security mechanism for authorizing tokens, verifying that the token is correct and valid.
  • the first UE also needs to search for group members that can join the ProSe communication group.
  • the process of joining a group member may include the following steps:
  • Step B1 The first UE sends a group communication discovery request message in a broadcast manner, and the group communication discovery request message includes the identification information of the ProSe application and the identification information of the first UE.
  • the first UE can broadcast a group communication discovery request message through the PC5 interface, and the message includes the identity information of the ProSe application and the identity information of the first UE, so that other UEs can use the identity information of the first UE based on the identity information of the first UE.
  • the first UE is found, and whether to join the ProSe communication group is determined based on the identification information of the ProSe application.
  • Step B2 Receive a group communication discovery response message sent by the second UE based on the group communication discovery request message.
  • the second UE After receiving the group communication discovery request message of the first UE through the PC5 interface, if the second UE determines to join the ProSe communication group, it sends a group communication discovery response message to the first UE, where the group communication discovery response message contains There is the identity information of the ProSe application and the identity information of the second UE.
  • Step B3 Send a group communication discovery accept message to the second UE.
  • the group communication discovery accept message includes The identification information of the ProSe application and the group identification information of the ProSe communication group, so that the second UE joins the ProSe communication group based on the identification information of the ProSe application and the group identification information of the ProSe communication group.
  • Step B4 Receive a group communication discovery completion message sent by the second UE after joining the ProSe communication group.
  • the second UE may send a group communication discovery complete message to the first UE, so that the first UE can know that it can securely communicate with the second UE.
  • the first UE discovers the group members and adds the group members to the ProSe communication group, realizes the dynamic joining process of the members in the PorSe communication group, that is, realizes the dynamic establishment process of the ProSe communication group.
  • the above process can be performed after the first UE receives the first group communication key response message sent by the key management function entity, that is, the first UE establishes a ProSe communication group and obtains the group communication key After that, it is ensured that the intra-group communication can be performed after the subsequent UE joins.
  • step B1 and step B2 in the above process can also be performed before the first UE establishes a ProSe communication group under the ProSe application through the application server, and step B3 and step B4 are performed after the first UE establishes a ProSe communication group, that is, allowing the current
  • the group member discovery process is performed before the first UE finds that there are group members and can establish the ProSe communication group together, thereby avoiding the occurrence of no group members after the first UE establishes the ProSe communication group, and avoiding the generation of an invalid ProSe communication group.
  • the first UE may update the group communication key at any time as needed, and the update process of the group communication key initiated by the first UE at this time may include the following steps:
  • the first UE sends a first group of communication key update request messages to the key management function entity, wherein the first group of communication key update request messages contains the group member list of the ProSe communication group;
  • the updated group communication key sent by a group communication key update request message; and then a key update notification message is sent to the group members of the ProSe communication group, so that the group members of the ProSe communication group update the group communication key.
  • the present embodiment implements the dynamic establishment process of the ProSe communication group through the above process, and ensures that the ProSe communication groups can perform secure communication through the group communication key.
  • FIG. 3 it is a flowchart of steps of a communication method applied to a ProSe communication group of a second UE in an embodiment of the present application, and the method includes the following steps:
  • Step 301 When the second UE joins the ProSe communication group under the ProSe application established by the first UE, it sends a second group communication key request message to the key management function entity.
  • the second UE may send a second group of communication key request messages to the key management function entity based on the requirement for secure communication in the communication group.
  • the second group of communication key request messages includes the identity information of the second UE and the second authorization token issued by the application server for the second UE, so that the key management function entity is based on the identity information of the second UE and the second authorization token.
  • the second authorization token obtains the group communication key of the ProSe communication group; or the group communication key request message contains the identity information of the second UE and the attribute information of the ProSe communication group, so that the key management function entity is based on the second UE.
  • the identity information and attribute information obtained from the application server are authorized to issue the key and obtain the group communication key of the ProSe communication group.
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the second authorization token includes: the identity information of the second UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the role information of the second UE in the ProSe communication group, and the first The role information of the second UE is a group member.
  • Step 302 Receive the second group of communication key response messages sent by the key management function entity.
  • the key management function entity may obtain the group communication key after receiving the second group communication key request message, and send the second group communication key response message to the second UE. At this time, the second UE receives the second set of communication key response messages.
  • the second group communication key response message includes the group communication key, so that the second UE can perform secure communication within the group based on the group communication key.
  • Step 303 Communicate with members in the ProSe communication group based on the group communication key.
  • the second UE communicates with other members in the ProSe communication group based on the group communication key, which ensures the secure communication of the ProSe communication group.
  • the second UE in this embodiment sends a second set of communication key request messages to the key management function entity when joining the ProSe communication group, and receives the second set of communication key request messages from the key management function entity based on the second set of communication key request messages.
  • the sent group communication key enables the ProSe communication group to perform intra-group communication based on the group communication key, thereby ensuring the security of the ProSe communication group.
  • the second UE when it joins the ProSe communication group under the ProSe application established by the first UE, it may send a group communication join request to the application server, wherein the group communication join request includes the second UE. Identity information, the identification information of ProSe application and the identification information of the ProSe communication group; then receive the group communication joining response message sent by the application server based on the group communication joining request, wherein the group communication joining response message contains the attribute information of the ProSe communication group , or contains the attribute information of the ProSe communication group and the second authorization token.
  • the first UE also needs to search for group members that can join the ProSe communication group.
  • the discovery process of the second UE that is a group member may include the following steps:
  • the group communication discovery request message contains the identification information of the ProSe application and the identity information of the first UE; then send the group communication discovery request message to the first UE based on the group communication discovery request message.
  • a communication discovery response message wherein the group communication discovery response message includes the identification information of the ProSe application and the identity information of the second UE; and then receives the group communication discovery accept message sent by the first UE, wherein the group communication discovery accept message includes There are the identification information of the ProSe application and the group identification information of the ProSe communication group; finally, when joining the ProSe communication group based on the identification information of the ProSe application and the group identification information of the ProSe communication group, a group communication discovery complete message is sent to the first UE.
  • the second UE may also update the group communication key, and the update process may include the following steps:
  • the second UE receives the key update notification message sent by the first UE, then sends a second set of communication key update request messages to the key management function entity based on the key update notification message, and finally receives the key management function entity after determining the first 2.
  • this embodiment implements the process of joining the second UE to the ProSe communication group established by the first UE through the above process, and realizes the secure communication of the ProSe communication group.
  • Embodiment 1 As shown in Figure 4, one of the flow charts for establishing secure communication for the ProSe communication group, the process includes the following steps:
  • Parameters related to dynamic ProSe communication group communication are pre-configured in the UE, the application server and the key management functional entity.
  • the address information of the application server and the key management function entity is configured in the UE, and the key information for establishing a security association with the key management function entity is configured;
  • the UE subscription information related to the ProSe communication group communication is configured in the application server;
  • the key management function entity is configured with key information for establishing a security association with the UE and security policies related to group communication security.
  • the first UE is a UE that initiates a ProSe communication group.
  • the first UE needs to establish a ProSe communication group under a certain ProSe application, it sends a group communication establishment request to the application server, and the request contains the identity of the first UE. information and identification information of the ProSe application.
  • the application server checks whether the first UE can establish a ProSe communication group based on the subscription information. If possible, the application server establishes a ProSe communication group, sets a unique group identifier for the group, and generates an authorization token for the first UE. Then, the application server sends a group communication establishment response message to the first UE, wherein the group communication establishment response message includes attribute information of the established ProSe communication group and the first authorization token.
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the first authorization token includes: the identification information of the first UE, the group identification of the ProSe communication group information, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the role information of the first UE in the ProSe communication group, and the role information of the first UE is the group administrator.
  • the first authorization token may also include information such as token validity period and token protection mechanism.
  • the application server stores ProSe communication group creation information and group information for adding new group members in the future.
  • the first UE sends a first set of communication key request messages to the key management function entity, which contain the identity information of the first UE and the first authorization token.
  • the key management function entity authenticates the user identity, checks the authorization token, generates the group communication key based on the security policy, and provides the group communication key to the first UE through the first group communication key response message.
  • the key management function entity should store the identification information of the ProSe application, the identification information of the ProSe communication group, the generated group communication key and the group validity period, etc., so as to provide the group key to the group members who apply later.
  • the first UE sends a group communication discovery request message in a broadcast manner through the PC5 interface, where the request message includes the identification information of the ProSe application and the identity information of the first UE.
  • the second UE receives the group communication discovery request message of the first UE through the PC5 interface.
  • the second UE decides to join the group communication, and sends a group communication discovery response message to the first UE, where the response message includes the identity information of the ProSe application and the identity information of the second UE.
  • the first UE sends a discovery accept message to the second UE, which contains the identification information of the ProSe application and the identification information of the ProSe communication group.
  • the second UE sends a group communication join request message to the application server, which contains the identity information of the second UE, the identification information of the ProSe application and the identification information of the ProSe communication group.
  • the application server checks whether the second UE can be a member of the group, and if so, issues a second authorization token to the second UE.
  • the application server sends a group communication join response message to the second UE, which contains the attribute information of the ProSe communication group and the second authorization token.
  • the attribute information includes the identification information of the ProSe communication group, the identification information of the ProSe application and the validity period of the ProSe communication group, etc.;
  • the second authorization token includes the identification information of the second UE, the group identification information of the ProSe communication group, the identification information of the ProSe application
  • the identification information, the validity period information of the ProSe communication group, and the role information of the second UE in the ProSe communication group, and the role information of the second UE is the group administrator.
  • the second authorization token may also contain information such as token validity period and token protection mechanism.
  • the application server updates the stored group information.
  • the second UE sends a second set of communication key request messages to the key management function entity, which contain the identity information of the second UE and the second authorization token.
  • the key management function entity authenticates the user identity, checks the second authorization token, retrieves the previously generated group communication key according to the group information, and provides the group communication key to the second group communication key through the second group communication key response. UE.
  • the second UE sends a discovery complete message to the first UE.
  • group members in the ProSe communication group can perform secure group communication.
  • the first UE decides that the group communication key needs to be updated, the first UE sends a first group communication key update request to the key management function entity, and the request includes the group member list.
  • the key management function entity stores a list of group members and generates new group communication keys.
  • the first UE of the group administrator notifies the second UE of the group member that the key needs to be updated.
  • the second group member UE sends a second group communication key update request to the key management function entity.
  • the key management function entity provides a new group communication key to the group member second UE based on the group member list provided by the group administrator first UE.
  • the group members can use the new group communication key for secure group communication.
  • Embodiment 2 As shown in Figure 5, the second flow chart of establishing secure communication for the ProSe communication group, the process includes the following steps:
  • Parameters related to dynamic ProSe communication group communication are pre-configured in the UE, the application server and the key management functional entity.
  • the address information of the application server and the key management function entity is configured in the UE, and the key information for establishing a security association with the key management function entity is configured;
  • the UE subscription information related to the ProSe communication group communication is configured in the application server;
  • the key management function entity is configured with key information for establishing a security association with the UE and security policies related to group communication security.
  • the first UE is a UE that initiates a ProSe communication group.
  • the first UE needs to establish a ProSe communication group under a certain ProSe application, it sends a group communication establishment request to the application server, and the request contains the identity of the first UE. information and identification information of the ProSe application.
  • the application server checks whether the first UE can establish a ProSe communication group based on the subscription information. If possible, the application server establishes a ProSe communication group, and sets a unique group identifier for the group. Then, the application server sends a group communication establishment response message to the first UE, wherein the group communication establishment response message includes attribute information of the established ProSe communication group.
  • the attribute information of the ProSe communication group includes: group identification information of the ProSe communication group, identification information of the ProSe application, and validity period information of the ProSe communication group.
  • the application server stores ProSe communication group creation information and group information for adding new group members in the future.
  • the first UE sends a first group of communication key request messages to the key management function entity, which contains the identity information of the first UE and the attribute information of the ProSe communication group.
  • the key management function entity sends a first authorization request message to the application server, where the first authorization request message includes the identity information of the first UE, the group identification information of the ProSe communication group and the identification information of the ProSe application.
  • the application server uses the identity information of the first UE, the group identification information of the ProSe communication group and the identification information of the ProSe application to determine the role information of the first UE in the ProSe communication group, and sends the first authorization response to the key management function entity message, wherein the first authorization response message contains the identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group and the role information of the first UE in the ProSe communication group .
  • the key management function entity provides the group communication key to the first UE through the first group communication key response message.
  • the first UE sends a group communication discovery request message in a broadcast manner through the PC5 interface, where the request message includes the identity information of the ProSe application and the identity information of the first UE.
  • the second UE receives the group communication discovery request message of the first UE through the PC5 interface.
  • the second UE decides to join the group communication, and sends a group communication discovery response message to the first UE, where the response message includes the identity information of the ProSe application and the identity information of the second UE.
  • the first UE sends a discovery accept message to the second UE, which contains the identification information of the ProSe application and the identification information of the ProSe communication group.
  • the second UE sends a group communication join request message to the application server, which contains the identity information of the second UE, the identification information of the ProSe application, and the identification information of the ProSe communication group.
  • the application server checks whether the second UE can be a member of the group, and if so, sends a group communication join response message to the second UE, which contains the attribute information of the ProSe communication group.
  • the application server updates the stored group information.
  • the second UE sends a second group of communication key request messages to the key management function entity, which contains the identity information of the second UE and the attribute information of the ProSe communication group.
  • the key management function entity sends a second authorization request message to the application server, where the second authorization request message includes the identity information of the second UE, the group identification information of the ProSe communication group and the identification information of the ProSe application.
  • the application server uses the identity information of the second UE, the group identification information of the ProSe communication group and the identification information of the ProSe application to determine the role information of the second UE in the ProSe communication group, and sends the second authorization response to the key management function entity message, wherein the second authorization response message contains the identity information of the second UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group and the role information of the second UE in the ProSe communication group .
  • the key management function entity acquires the previously generated group communication key according to the group information, and provides the acquired group communication key to the second UE through the second group communication key response message.
  • the second UE sends a discovery complete message to the first UE.
  • group members in the ProSe communication group can perform secure group communication.
  • the first UE decides that the group communication key update needs to be performed, the first UE sends a first group communication key update request to the key management function entity, and the request includes the group member list.
  • the key management function entity stores a list of group members and generates new group communication keys.
  • the first UE of the group administrator notifies the second UE of the group member that the key needs to be updated.
  • the second group member UE sends a second group communication key update request to the key management function entity.
  • the key management function entity provides a new group communication key to the group member second UE based on the group member list provided by the group administrator first UE.
  • the group members can use the new group communication key for secure group communication.
  • the present application implements the secure communication of the ProSe communication group through any of the above-mentioned embodiments.
  • FIG. 6 is a block diagram of a module of a communication device applied to a ProSe communication group of a key communication functional entity in an embodiment of the present application, and the device includes:
  • a receiving module 601 configured to receive a first group of communication key request messages sent by the first user equipment UE when establishing a ProSe communication group under the proximity service ProSe application through an application server, wherein the first group of communication key request messages contains the identity information of the first UE and the first authorization token issued by the application server for the first UE, or the first group communication key request message contains the identity of the first UE information and attribute information of the ProSe communication group;
  • the first generating module 602 is configured to, when the first group of communication key request messages contain the identity information of the first UE and the first authorization token, generate a method based on the identity information of the first UE and the first authorization token.
  • the first authorization token generates a group communication key;
  • the second generation module 603 is configured to, when the first group communication key request message contains the identity information of the first UE and the attribute information of the ProSe communication group, generate the information based on the identity information of the first UE and the attribute information obtains a key generation authorization from the application server and generates a group communication key;
  • a sending module 604 configured to send a first group communication key response message to the first UE, wherein the first group communication key response message includes the group communication key;
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the first authorization token includes: the identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the first The role information of the UE in the ProSe communication group, and the role information of the first UE is the group administrator.
  • the second generation module 603 is specifically configured to: send a first authorization request message to the application server, wherein the first authorization request message includes the identity information of the first UE, the ProSe communication group group identification information and the identification information of the ProSe application, so that the application server determines the first UE based on the identification information of the first UE, the group identification information of the ProSe communication group and the identification information of the ProSe application. Whether a UE belongs to the ProSe communication group;
  • the first authorization response message includes the identity information of the first UE, the The group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the role information of the first UE in the ProSe communication group.
  • the receiving module 601 is further configured to receive a second group of communication key request messages sent by the second UE when joining the ProSe communication group, wherein the second group of communication key request messages includes The identity information of the second UE and the second authorization token issued by the application server for the second UE, or the second set of communication key request messages contain the identity information of the second UE and the second authorization token. Attribute information of the ProSe communication group;
  • the first generating module 602 is further configured to, when the second group of communication key request messages contain the identity information of the second UE and the second authorization token, generate the second UE based on the identity information of the second UE Obtain the group communication key of the ProSe communication group with the second authorization token;
  • the second generation module 603 is further configured to: when the second group communication key request message contains the identity information of the second UE and the attribute information of the ProSe communication group, generate the information based on the identity of the second UE Information and described attribute information obtain key issuance authorization from described application server and obtain the group communication key of described ProSe communication group;
  • the sending module 604 is further configured to send a second group communication key response message to the second UE, wherein the second group communication key response message includes the group communication key;
  • the second authorization token includes: the identity information of the second UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the Role information of the second UE in the ProSe communication group, and the role information of the second UE is a group member.
  • the second generation module 603 is further configured to send a second authorization request message to the application server, wherein the second authorization request message contains the identity information of the second UE, the ProSe communication group group identification information and the identification information of the ProSe application, so that the application server determines the first 2. Whether the UE belongs to the ProSe communication group;
  • the second authorization response message includes the identity information of the second UE, the The group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the role information of the second UE in the ProSe communication group.
  • the apparatus further includes a key update module (not shown in the figure), configured to receive a first set of communication key update request messages sent by the first UE, wherein the first set of communication key update The request message contains the group member list of the ProSe communication group;
  • a key update module (not shown in the figure), configured to receive a first set of communication key update request messages sent by the first UE, wherein the first set of communication key update The request message contains the group member list of the ProSe communication group;
  • FIG. 7 is a block diagram of a module of a communication apparatus applied to a ProSe communication group of a first UE in an embodiment of the present application, and the apparatus includes:
  • the sending module 701 is configured to send a first group of communication key request messages to the key management function entity when the first UE establishes a ProSe communication group under the ProSe application of the proximity service through the application server; wherein the first group of communication
  • the key request message contains the identity information of the first UE and the first authorization token issued by the application server for the first UE, so that the key management function entity is based on the first UE
  • the identity information and the first authorization token to generate a group communication key
  • the first group communication key request message contains the identity information of the first UE and the attribute information of the ProSe communication group, to causing the key management function entity to obtain a key generation authorization from the application server based on the identity information of the first UE and the attribute information and generate a group communication key;
  • a receiving module 702 configured to receive a first group of communication key response messages sent by the key management function entity, wherein the first group of communication key response messages includes the group of communication keys;
  • a communication module 703, configured to communicate with a group member who subsequently joins the ProSe communication group based on the group communication key;
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the first authorization token includes: the identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the first The role information of the UE in the ProSe communication group, and the role information of the first UE is the group administrator.
  • the first UE establishes a ProSe communication group under a proximity service ProSe application through an application server, including:
  • the first UE When the first UE needs to establish a ProSe communication group under the ProSe application, it sends a group communication establishment request to the application server, wherein the group communication establishment request includes the identity information of the first UE and all The identification information of the above ProSe application;
  • the group communication establishment response message includes attribute information of the established ProSe communication group, or includes the established ProSe communication attribute information of the group and the first authorization token.
  • the device also includes a terminal discovery module (not shown in the figure) for sending a group communication discovery request message by broadcasting, and the group communication discovery request message contains the identification information of the ProSe application and the described ProSe application. identity information of the first UE;
  • the group communication discovery response message includes the identification information of the ProSe application and the identity information of the second UE;
  • the group communication discovery accept message includes the identification information of the ProSe application and the group identification information of the ProSe communication group, so that the second UE is based on The identification information of the described ProSe application and the group identification information of the described ProSe communication group join the described ProSe communication group;
  • a group communication discovery complete message sent by the second UE after joining the ProSe communication group is received.
  • the apparatus further includes a key update module (not shown in the figure), configured to send a first group of communication key update request messages to the key management function entity, wherein the first group of communication key update The request message contains the group member list of the ProSe communication group;
  • a key update module (not shown in the figure), configured to send a first group of communication key update request messages to the key management function entity, wherein the first group of communication key update The request message contains the group member list of the ProSe communication group;
  • a key update notification message is sent to the group members of the ProSe communication group, so that the group members of the ProSe communication group update the group communication key.
  • Fig. 8 is the module block diagram of the communication device of the ProSe communication group applied to the second UE in the embodiment of the present application, and this device comprises:
  • the sending module 801 is configured to send a second group of communication key request messages to the key management function entity when the second UE joins the ProSe communication group under the proximity service ProSe application established by the first UE; wherein the second The group communication key request message contains the identity information of the second UE and the second authorization token issued by the application server for the second UE, so that the key management function entity is based on the second UE.
  • the identity information and the second authorization token obtain the group communication key of the ProSe communication group, or the group communication key request message contains the identity information of the second UE and the identity information of the ProSe communication group. attribute information, so that the key management function entity obtains a key issuance authorization from the application server based on the identity information of the second UE and the attribute information and obtains the group communication key of the ProSe communication group;
  • a receiving module 802 configured to receive a second group of communication key response messages sent by the key management function entity, wherein the second group of communication key response messages includes the group of communication keys;
  • a communication module 803, configured to communicate with members in the ProSe communication group based on the group communication key;
  • the attribute information of the ProSe communication group includes: the group identification information of the ProSe communication group, the identification information of the ProSe application and the validity period information of the ProSe communication group;
  • the second authorization token includes: the identity information of the second UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the second The role information of the UE in the ProSe communication group, and the role information of the second UE is a group member.
  • the second UE joins the ProSe communication group under the proximity service ProSe application established by the first UE, including:
  • the group communication join request includes the identity information of the second UE, the identification information of the ProSe application and the identification information of the ProSe communication group;
  • the apparatus further includes a terminal joining module (not shown in the figure), configured to receive a group communication discovery request message sent by the first UE in a broadcast manner, where the group communication discovery request message includes the The identity information of the ProSe application and the identity information of the first UE;
  • a terminal joining module (not shown in the figure), configured to receive a group communication discovery request message sent by the first UE in a broadcast manner, where the group communication discovery request message includes the The identity information of the ProSe application and the identity information of the first UE;
  • the group communication discovery response message includes the identity information of the ProSe application and the identity information of the second UE;
  • the group communication discovery accept message includes the identification information of the ProSe application and the group identification information of the ProSe communication group;
  • a group communication discovery complete message is sent to the first UE.
  • the apparatus further includes a key update module (not shown in the figure), configured to receive a key update notification message sent by the first UE;
  • FIG. 9 is a schematic structural diagram of a communication device of a ProSe communication group provided by an embodiment of the present application, including a transceiver 900 , a processor 910 , and a memory 920 .
  • the bus architecture may include any number of interconnected buses and bridges, specifically one or more processors represented by processor 910 and various circuits of memory represented by memory 920 are linked together.
  • the bus architecture may also link together various other circuits, such as peripherals, voltage regulators, and power management circuits, which are well known in the art and, therefore, will not be described further herein.
  • the bus interface provides the interface.
  • Transceiver 900 may be multiple elements, including a transmitter and a receiver, providing means for communicating with various other devices over transmission media including wireless channels, wired channels, fiber optic cables, and the like.
  • the processor 910 is responsible for managing the bus architecture and general processing, and the memory 920 may store data used by the processor 910 in performing operations.
  • the processor 910 may be a central processor (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or a complex programmable logic device (Complex Programmable Logic Device). , CPLD), the processor can also use a multi-core architecture.
  • CPU central processor
  • ASIC application specific integrated circuit
  • FPGA field programmable gate array
  • CPLD complex programmable logic device
  • the memory 920 is used to store computer programs; the transceiver 900 is used to send and receive data under the control of the processor; the processor 910 is used to read the computer programs in the memory and perform the following operations:
  • the first group of communication key request messages includes the first UE
  • the identity information of the first UE and the first authorization token issued by the application server for the first UE, or the first group communication key request message contains the identity information of the first UE and the ProSe communication attribute information of the group; when the first group communication key request message contains the identity information of the first UE and the first authorization token, based on the identity information of the first UE and the first authorization token an authorization token to generate a group communication key; when the first group communication key request message contains the identity information of the first UE and the attribute information of the ProSe communication group, based on the first UE's identity information The identity information and the attribute information obtain the key generation authorization from the application server and generate a group communication key; send a first group communication key response message to the first UE, wherein the first group communication key The response message contains the group communication key;
  • the attribute information of the ProSe communication group includes: group identification information of the ProSe communication group, identification information of the ProSe application, and validity period information of the ProSe communication group;
  • the first authorization token includes: The identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the role information of the first UE in the ProSe communication group , and the role information of the first UE is the group administrator.
  • obtaining a key generation authorization from the application server based on the identity information of the first UE and the attribute information includes:
  • the application server sends a first authorization request message to the application server, wherein the first authorization request message contains the identity information of the first UE, the group identification information of the ProSe communication group and the identification information of the ProSe application, so that the application server determines whether the first UE belongs to the ProSe communication group based on the identity information of the first UE, the group identification information of the ProSe communication group and the identification information of the ProSe application; receiving the A first authorization response message sent by the application server when determining that the first UE belongs to the ProSe communication group, wherein the first authorization response message includes the identity information of the first UE, the ProSe communication group group identification information, identification information of the ProSe application, validity period information of the ProSe communication group, and role information of the first UE in the ProSe communication group.
  • the processor 910 is further configured to perform the following operation: receive a second group of communication key request messages sent by the second UE when joining the ProSe communication group, wherein the second group of communication key request messages It contains the identity information of the second UE and the second authorization token issued by the application server for the second UE, or the second group of communication key request messages contains the identity information of the second UE.
  • identity information and attribute information of the ProSe communication group when the second group communication key request message contains the identity information of the second UE and the second authorization token, based on the second UE The identity information and the second authorization token obtain the group communication key of the ProSe communication group; when the second group communication key request message contains the identity information of the second UE and the ProSe communication
  • the attribute information of the group is obtained, obtain the key issuance authorization from the application server based on the identity information of the second UE and the attribute information, and obtain the group communication key of the ProSe communication group; to the second UE sending a second group of communication key response messages, wherein the second group of communication key response messages includes the group of communication keys;
  • the second authorization token includes: the identity information of the second UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the Role information of the second UE in the ProSe communication group, and the role information of the second UE is a group member.
  • obtaining the key issuance authorization from the application server based on the identity information of the second UE and the attribute information including:
  • the second authorization request message contains the identity information of the second UE, the group identification information of the ProSe communication group and the identification information of the ProSe application, so that the application server determines whether the second UE belongs to the ProSe communication group based on the identity information of the second UE, the group identification information of the ProSe communication group and the identification information of the ProSe application; receiving the A second authorization response message sent by the application server when determining that the second UE belongs to the ProSe communication group, wherein the second authorization response message includes the identity information of the second UE, the ProSe communication group group identification information, identification information of the ProSe application, validity period information of the ProSe communication group, and role information of the second UE in the ProSe communication group.
  • the processor 910 is further configured to perform the following operation: receive a first set of communication key update request messages sent by the first UE, wherein the first set of communication key update request messages includes the The group member list of the ProSe communication group; send the updated group communication key to the first UE based on the first group communication key update request message; receive the second group communication key update request sent by the second UE message, and send the updated group communication key to the second UE when it is determined that the second UE is a group member of the ProSe communication group based on the group member list.
  • FIG. 10 is a second schematic structural diagram of a communication device of a ProSe communication group provided by an embodiment of the present application, including a transceiver 1000 , a processor 1010 , and a memory 1020 .
  • the bus architecture may include any number of interconnected buses and bridges, specifically one or more processors represented by processor 1010 and various circuits of memory represented by memory 1020 are linked together.
  • the bus architecture may also link together various other circuits, such as peripherals, voltage regulators, and power management circuits, which are well known in the art and, therefore, will not be described further herein.
  • the bus interface provides the interface.
  • Transceiver 1000 may be multiple elements, including a transmitter and a receiver, providing means for communicating with various other devices over transmission media including wireless channels, wired channels, fiber optic cables, and the like.
  • the processor 1010 is responsible for managing the bus architecture and general processing, and the memory 1020 may store data used by the processor 1010 in performing operations.
  • the processor 1010 can be a central processor (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or a complex programmable logic device (Complex Programmable Logic Device). , CPLD), the processor can also use a multi-core architecture.
  • CPU central processor
  • ASIC application specific integrated circuit
  • FPGA field programmable gate array
  • CPLD complex programmable logic device
  • the memory 1020 is used to store computer programs; the transceiver 1000 is used to send and receive data under the control of the processor; the processor 1010 is used to read the computer programs in the memory and perform the following operations:
  • the first UE When the first UE establishes a ProSe communication group under the proximity service ProSe application through the application server, it sends a first group of communication key request messages to the key management function entity; wherein the first group of communication key request messages includes: There is the identity information of the first UE and the first authorization token issued by the application server for the first UE, so that the key management function entity is based on the identity information of the first UE and the first authorization token.
  • the first authorization token generates a group communication key, or the first group communication key request message contains the identity information of the first UE and the attribute information of the ProSe communication group, so that the key management
  • the functional entity obtains a key generation authorization from the application server based on the identity information of the first UE and the attribute information, and generates a group communication key;
  • the attribute information of the ProSe communication group includes: group identification information of the ProSe communication group, identification information of the ProSe application, and validity period information of the ProSe communication group;
  • the first authorization token includes: The identity information of the first UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the role information of the first UE in the ProSe communication group , and the role information of the first UE is the group administrator.
  • the first UE establishes a ProSe communication group under the proximity service ProSe application through the application server, including:
  • the first UE When the first UE needs to establish a ProSe communication group under the ProSe application, it sends a group communication establishment request to the application server, wherein the group communication establishment request includes the identity information of the first UE and all The identification information of the described ProSe application; Receive the group communication establishment response message sent by the application server based on the group communication establishment request, wherein the group communication establishment response message includes the attribute information of the established ProSe communication group, or Contains attribute information of the established ProSe communication group and the first authorization token.
  • processor 1010 is further configured to perform the following operations:
  • processor 1010 is further configured to perform the following operations:
  • the foregoing embodiment can implement all steps on the first UE side and can achieve the same technical effect, which will not be repeated here.
  • FIG. 11 is a third schematic structural diagram of a communication device of a ProSe communication group provided by an embodiment of the present application, including a transceiver 1100 , a processor 1110 , and a memory 1120 .
  • the bus architecture may include any number of interconnected buses and bridges, specifically one or more processors represented by processor 1110 and various circuits of memory represented by memory 1120 are linked together.
  • the bus architecture may also link together various other circuits, such as peripherals, voltage regulators, and power management circuits, which are well known in the art and, therefore, will not be described further herein.
  • the bus interface provides the interface.
  • Transceiver 1100 may be multiple elements, ie, including transmitters and receivers, providing means for communicating with various other devices over transmission media including wireless channels, wired channels, fiber optic cables, and the like.
  • the processor 1110 is responsible for managing the bus architecture and general processing, and the memory 1120 may store data used by the processor 1110 in performing operations.
  • the processor 1110 may be a central processor (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or a complex programmable logic device (Complex Programmable Logic Device). , CPLD), the processor can also use a multi-core architecture.
  • CPU central processor
  • ASIC application specific integrated circuit
  • FPGA field programmable gate array
  • CPLD complex programmable logic device
  • the memory 1120 is used to store computer programs; the transceiver 1100 is used to send and receive data under the control of the processor; the processor 1110 is used to read the computer program in the memory and perform the following operations:
  • the second UE When the second UE joins the ProSe communication group under the proximity service ProSe application established by the first UE, it sends a second group of communication key request messages to the key management function entity; wherein the second group of communication key request messages contains the identity information of the second UE and the second authorization token issued by the application server for the second UE, so that the key management function entity is based on the identity information of the second UE and the The second authorization token obtains the group communication key of the ProSe communication group, or the group communication key request message contains the identity information of the second UE and the attribute information of the ProSe communication group, so that all The key management function entity obtains a key issuance authorization from the application server based on the identity information of the second UE and the attribute information and obtains the group communication key of the ProSe communication group;
  • the attribute information of the ProSe communication group includes: group identification information of the ProSe communication group, identification information of the ProSe application, and validity period information of the ProSe communication group;
  • the second authorization token includes: The identity information of the second UE, the group identification information of the ProSe communication group, the identification information of the ProSe application, the validity period information of the ProSe communication group, and the role information of the second UE in the ProSe communication group , and the role information of the second UE is a group member.
  • the second UE joins the ProSe communication group under the proximity service ProSe application established by the first UE, including:
  • the group communication joining request includes the identity information of the second UE, the identification information of the ProSe application and the identification information of the ProSe communication group; receive the application server A group communication join response message sent based on the group communication join request, wherein the group communication join response message includes attribute information of the ProSe communication group, or includes attribute information of the ProSe communication group and the The second authorization token.
  • processor 1110 is further configured to perform the following operations:
  • a group communication discovery request message sent by the first UE in a broadcast manner, where the group communication discovery request message includes the identification information of the ProSe application and the identity information of the first UE; based on the group communication
  • the discovery request message sends a group communication discovery response message to the first UE, wherein the group communication discovery response message contains the identification information of the ProSe application and the identity information of the second UE; receiving the first UE
  • the sent group communication discovery accept message wherein the group communication discovery accept message contains the identification information of the ProSe application and the group identification information of the ProSe communication group; when based on the identification information of the ProSe application and the When the group identification information of the ProSe communication group joins the ProSe communication group, a group communication discovery complete message is sent to the first UE.
  • processor 1110 is further configured to perform the following operations:
  • the above embodiment can implement all the steps on the second UE side and can achieve the same technical effect, which will not be repeated here.
  • each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit.
  • the above-mentioned integrated units may be implemented in the form of hardware, or may be implemented in the form of software functional units.
  • the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a processor-readable storage medium.
  • the technical solutions of the present application can be embodied in the form of software products in essence, or the parts that contribute to the prior art, or all or part of the technical solutions, and the computer software products are stored in a storage medium , including several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor (processor) to execute all or part of the steps of the methods described in the various embodiments of the present application.
  • the aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk and other media that can store program codes .
  • an embodiment of the present application further provides a processor-readable storage medium, where a computer program is stored in the processor-readable storage medium, and the computer program is used to cause the processor to execute the processes described in the foregoing embodiments.
  • the method can achieve the same technical effect, and will not be repeated here.
  • the processor-readable storage medium can be any available medium or data storage device that can be accessed by a processor, including, but not limited to, magnetic storage (eg, floppy disk, hard disk, magnetic tape, magneto-optical disk (MO), etc.), optical storage (eg, CD, DVD, BD, HVD, etc.), and semiconductor memory (eg, ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state disk (SSD)), and the like.
  • magnetic storage eg, floppy disk, hard disk, magnetic tape, magneto-optical disk (MO), etc.
  • optical storage eg, CD, DVD, BD, HVD, etc.
  • semiconductor memory eg, ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state disk (SSD)
  • the processor-readable storage medium stores a computer program, and the computer program is used to cause the processor to execute the above-mentioned communication method of the ProSe communication group.
  • the embodiments of the present application may be provided as a method, a system, or a computer program product. Accordingly, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present application may take the form of a computer program product embodied on one or more computer-usable storage media having computer-usable program code embodied therein, including but not limited to disk storage, optical storage, and the like.
  • processor-executable instructions may also be stored in a processor-readable memory capable of directing a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the processor-readable memory result in the manufacture of means including the instructions product, the instruction means implements the functions specified in the flow or flow of the flowchart and/or the block or blocks of the block diagram.
  • processor-executable instructions can also be loaded onto a computer or other programmable data processing device to cause a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process that Execution of the instructions provides steps for implementing the functions specified in the flowchart or blocks and/or the block or blocks of the block diagrams.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Multimedia (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请实施例提供一种ProSe通信组的通信方法、装置及存储介质,方法包括:接收第一UE通过应用服务器建立ProSe应用下的ProSe通信组时所发送的第一组通信密钥请求消息;当第一组通信密钥请求消息中包含有第一UE的身份信息和第一授权令牌时,基于第一UE的身份信息和第一授权令牌生成组通信密钥;当第一组通信密钥请求消息中包含有第一UE的身份信息和ProSe通信组的属性信息时,基于第一UE的身份信息和属性信息从应用服务器中得到密钥生成授权并生成组通信密钥;向第一UE发送第一组通信密钥响应消息,其中第一组通信密钥响应消息中包含有组通信密钥。本申请实施例实现了ProSe通信组的安全通信。

Description

ProSe通信组的通信方法、装置及存储介质
交叉引用
本申请引用于2020年09月29日提交的专利名称为“一种ProSe通信组的通信方法、装置及存储介质”的第2020110525800号中国专利申请。该专利申请通过引用被全部并入本申请。
技术领域
本申请涉及通信技术领域,具体涉及一种ProSe通信组的通信方法、装置及存储介质。
背景技术
在第四代移动通信技术(4th generation mobile communication technology,4G)中,近距离服务(Proximity Services,ProSe)仅支持公共安全应用,而在第五代移动通信技术(5th generation mobile networks,5G)中,ProSe将支持公共安全应用和商业服务应用。在公共安全应用中,ProSe通信组的建立是静态的,也就是组是事先建立的,成员也是事先就加入组中。而在商业应用中,组可能是动态建立的,组成员也可能是动态加入组或从组中移除,例如,临近的终端(UE)通过PC5接口建立一个互动游戏组。
目前正在进行5G ProSe架构和5G ProSe安全的研究工作,但是还没有提出关于ProSe通信组的安全通信的技术方案。
发明内容
本申请实施例提供一种ProSe通信组的通信方法、装置及存储介质,以解决ProSe通信组如何进行安全通信的问题。
第一方面,本申请实施例提供一种ProSe通信组的通信方法,应用于密钥管理功能实体,包括:
接收第一用户设备UE通过应用服务器建立近距离服务ProSe应用下的ProSe通信组时所发送的第一组通信密钥请求消息,其中所述第一组通信密钥请求消息中包含有第一UE的身份信息和所述应用服务器为所述第 一UE所颁发的第一授权令牌,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息;
当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述第一授权令牌时,基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥;
当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息时,基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
向所述第一UE发送第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
第二方面,本申请实施例提供一种ProSe通信组的通信方法,应用于第一用户设备UE,包括:
当第一UE通过应用服务器建立一近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第一组通信密钥请求消息;其中所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
接收所述密钥管理功能实体所发送的第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
基于所述组通信密钥与后续加入所述ProSe通信组的组成员进行通信;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
第三方面,本申请实施例提供一种ProSe通信组的通信方法,应用于第二用户设备UE,包括:
当第二UE加入第一UE所建立的近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第二组通信密钥请求消息;其中所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和应用服务器为所述第二UE所颁发的第二授权令牌,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述第二授权令牌获取所述ProSe通信组的组通信密钥,或者所述组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权并获取所述ProSe通信组的组通信密钥;
接收所述密钥管理功能实体所发送的第二组通信密钥响应消息,其中所述第二组通信密钥响应消息中包含有所述组通信密钥;
基于所述组通信密钥与所述ProSe通信组中的成员进行通信;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
所述第二授权令牌中包括:所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息,且所述第二UE的角色信息为组成员。
第四方面,本申请实施例提供一种ProSe通信组的通信装置,包括存储器,收发机,处理器:
存储器,用于存储计算机程序;收发机,用于在所述处理器的控制下收发数据;处理器,用于读取所述存储器中的计算机程序并执行以下操作:
接收第一用户设备UE通过应用服务器建立近距离服务ProSe应用下的ProSe通信组时所发送的第一组通信密钥请求消息,其中所述第一组通信密钥请求消息中包含有第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息;
当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述第一授权令牌时,基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥;
当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息时,基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
向所述第一UE发送第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
第五方面,本申请实施例提供一种ProSe通信组的通信装置,包括存储器,收发机,处理器:
存储器,用于存储计算机程序;收发机,用于在所述处理器的控制下收发数据;处理器,用于读取所述存储器中的计算机程序并执行以下操作:
当第一UE通过应用服务器建立一近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第一组通信密钥请求消息;其中所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第一UE 的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
接收所述密钥管理功能实体所发送的第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
基于所述组通信密钥与后续加入所述ProSe通信组的组成员进行通信;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
第六方面,本申请实施例提供一种ProSe通信组的通信装置,包括存储器,收发机,处理器:
存储器,用于存储计算机程序;收发机,用于在所述处理器的控制下收发数据;处理器,用于读取所述存储器中的计算机程序并执行以下操作:
当第二UE加入第一UE所建立的近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第二组通信密钥请求消息;其中所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和应用服务器为所述第二UE所颁发的第二授权令牌,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述第二授权令牌获取所述ProSe通信组的组通信密钥,或者所述组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权并获取所述ProSe通信组的组通信密钥;
接收所述密钥管理功能实体所发送的第二组通信密钥响应消息,其中所述第二组通信密钥响应消息中包含有所述组通信密钥;
基于所述组通信密钥与所述ProSe通信组中的成员进行通信;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
所述第二授权令牌中包括:所述第二UE的身份信息、所述ProSe通 信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息,且所述第二UE的角色信息为组成员。
第七方面,本申请实施例提供一种ProSe通信组的通信装置,应用于密钥管理功能实体,包括:
接收模块,用于接收第一用户设备UE通过应用服务器建立近距离服务ProSe应用下的ProSe通信组时所发送的第一组通信密钥请求消息,其中所述第一组通信密钥请求消息中包含有第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息;
第一生成模块,用于当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述第一授权令牌时,基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥;
第二生成模块,用于当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息时,基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
发送模块,用于向所述第一UE发送第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
第八方面,本申请实施例提供一种ProSe通信组的通信装置,应用于第一用户设备UE,包括:
发送模块,用于当第一UE通过应用服务器建立一近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第一组通信密钥请求 消息;其中所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
接收模块,用于接收所述密钥管理功能实体所发送的第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
通信模块,用于基于所述组通信密钥与后续加入所述ProSe通信组的组成员进行通信;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
第九方面,本申请实施例提供一种ProSe通信组的通信装置,应用于第二用户设备UE,包括:
发送模块,用于当第二UE加入第一UE所建立的近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第二组通信密钥请求消息;其中所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和应用服务器为所述第二UE所颁发的第二授权令牌,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述第二授权令牌获取所述ProSe通信组的组通信密钥,或者所述组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权并获取所述ProSe通信组的组通信密钥;
接收模块,用于接收所述密钥管理功能实体所发送的第二组通信密钥响应消息,其中所述第二组通信密钥响应消息中包含有所述组通信密钥;
通信模块,用于基于所述组通信密钥与所述ProSe通信组中的成员进行通信;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
所述第二授权令牌中包括:所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息,且所述第二UE的角色信息为组成员。
第十方面,本申请实施例提供一种处理器可读存储介质,所述处理器可读存储介质存储有计算机程序,所述计算机程序用于使处理器执行第一方面、第二方面或第三方面所述的方法。
本申请实施例提供的ProSe通信组的通信方法、装置及存储介质,密钥管理功能实体通过接收第一UE所发送的第一组通信密钥请求消息,且在第一组通信密钥请求消息中包含有第一UE的身份信息和第一授权令牌时,直接基于第一UE的身份信息和第一授权令牌生成组通信密钥,并在第一组通信密钥请求消息中包含有第一UE的身份信息和ProSe通信组的属性信息时从应用服务器中得到密钥生成授权后再生成组通信密钥,实现了针对第一组通信密钥请求消息中所包含的不同信息进行不同的组通信密钥生成过程,从而在密钥管理功能实体基于第一授权令牌生成组通信密钥时避免了应用服务器与密钥管理功能实体之间的后台交互过程,且保证了ProSe通信组的安全通信,在密钥管理功能实体基于ProSe通信组的属性信息从应用服务器中得到密钥生成授权后再生成组通信密钥时,使得应用服务器不必再向第一UE颁发授权令牌,减少了UE与网络实体之间的传输参数,即减少了UE开销,并保证了ProSe通信组的安全通信。
附图说明
为了更清楚地说明本申请实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作一简单地介绍,显而易见地,下面描述中的附图是本申请的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本申请实施例中应用于密钥管理功能实体的ProSe通信组的通 信方法的步骤流程图;
图2为本申请实施例中应用于第一UE的ProSe通信组的通信方法的步骤流程图;
图3为本申请实施例中应用于第二UE的ProSe通信组的通信方法的步骤流程图;
图4为本申请实施例中建立ProSe通信组安全通信的示意图之一;
图5为本申请实施例中建立ProSe通信组安全通信的示意图之二;
图6为本申请实施例中应用于密钥管理功能实体的ProSe通信组的通信装置的模块框图;
图7为本申请实施例中应用于第一UE的ProSe通信组的通信装置的模块框图;
图8为本申请实施例中应用于第二UE的ProSe通信组的通信装置的模块框图;
图9为本申请实施例中ProSe通信组的通信装置的结构示意图之一;
图10为本申请实施例中ProSe通信组的通信装置的结构示意图之二;
图11为本申请实施例中ProSe通信组的通信装置的结构示意图之三。
具体实施方式
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分实施例,并不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
本申请实施例提供的技术方案可以适用于多种系统,例如5G系统。例如适用的系统可以是全球移动通讯(global system of mobile communication,GSM)系统、码分多址(code division multiple access,CDMA)系统、宽带码分多址(Wideband Code Division Multiple Access,WCDMA)通用分组无线业务(general packet radio service,GPRS)系统、长期演进(long term evolution,LTE)系统、LTE频分双工(frequency division duplex,FDD)系统、LTE时分双工(time division duplex,TDD)系统、高级长期演进(long term evolution advanced,LTE-A)系统、通用移动系 统(universal mobile telecommunication system,UMTS)、全球互联微波接入(worldwide interoperability for microwave access,WiMAX)系统、5G新空口(New Radio,NR)系统等。这多种系统中均包括终端设备和网络设备。系统中还可以包括核心网部分,例如演进的分组系统(Evloved Packet System,EPS)、5G系统(5GS)等。
本申请实施例涉及的用户设备,可以是指向用户提供语音和/或数据连通性的设备,具有无线连接功能的手持式设备、或连接到无线调制解调器的其他处理设备等。无线用户设备可以经无线接入网(Radio Access Network,RAN)与一个或多个核心网(Core Network,CN)进行通信,无线用户设备可以是移动终端设备,如移动电话(或称为“蜂窝”电话)和具有移动终端设备的计算机,例如,可以是便携式、袖珍式、手持式、计算机内置的或者车载的移动装置,它们与无线接入网交换语言和/或数据。例如,个人通信业务(Personal Communication Service,PCS)电话、无绳电话、会话发起协议(Session Initiated Protocol,SIP)话机、无线本地环路(Wireless Local Loop,WLL)站、个人数字助理(Personal Digital Assistant,PDA)等设备。无线用户设备也可以称为系统、订户单元(subscriber unit)、订户站(subscriber station),移动站(mobile station)、移动台(mobile)、远程站(remote station)、接入点(access point)、远程终端设备(remote terminal)、接入终端设备(access terminal)、用户终端设备(user terminal)、用户代理(user agent)、用户装置(user device),本申请实施例中并不限定。由于用户设备与其它网络设备(例如核心网设备、接入网设备(即基站))一起构成一个可支持通信的网络,在本申请中,用户设备也视为一种网络设备。
此外,应理解,说明书通篇中提到的“一个实施例”或“一实施例”意味着与实施例有关的特定特征、结构或特性包括在本申请的至少一个实施例中。因此,在整个说明书各处出现的“在一个实施例中”或“在一实施例中”未必一定指相同的实施例。此外,这些特定的特征、结构或特性可以任意适合的方式结合在一个或多个实施例中。
下面对本申请进行具体说明。
如图1所示,为本申请实施例中应用于密钥管理功能实体的ProSe通 信组的通信方法的步骤流程图,该方法包括如下步骤:
步骤101:接收第一UE通过应用服务器建立ProSe应用下的ProSe通信组时所发送的第一组通信密钥请求消息。
具体的,在用户设备(简称UE)、应用服务器和密钥管理功能实体中配置有与动态的ProSe通信组相关的参数,例如UE中配置有应用服务器和密钥管理功能实体的地址信息,应用服务器中配置有与ProSe通信组通信相关的UE签约信息,密钥管理功能实体中配置有与UE建立安全关联的密钥信息和组通信安全相关的安全策略。
具体的,当第一UE想要在某个ProSe应用下建立一个ProSe通信组,且通过应用服务器建立ProSe应用下的ProSe通信组时,基于通信组内需要安全通信的需求,第一UE可以向密钥管理功能实体发送第一组通信密钥请求消息,此时密钥管理功能实体接收第一UE所发送的第一组通信密钥请求消息。
其中,第一组通信密钥请求消息中包含有第一UE的身份信息和应用服务器为第一UE所颁发的第一授权令牌,或者第一组通信密钥请求消息中包含有第一UE的身份信息和ProSe通信组的属性信息。
具体的,ProSe通信组的属性信息包括:ProSe通信组的组标识信息、ProSe应用的标识信息和ProSe通信组的有效期信息;
第一授权令牌中包括:第一UE的身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息、ProSe通信组的有效期信息和第一UE在ProSe通信组中的角色信息,且第一UE的角色信息为组管理员,表示该ProSe通信组由第一UE建立。
UE的身份信息指在ProSe通信组中唯一标识组通信成员的标识信息,例如第一UE的身份信息可以为第一UE的标识,也可以是该第一UE在ProSe应用中的用户标识,在此不对此进行具体限定。
当然,在此需要说明的是,第一授权令牌中还可以包括第一授权令牌的有效期和令牌保护机制等授权信息,在此不再进行具体限定。
这样,通过在ProSe通信组的属性信息中包括ProSe通信组的组标识信息、ProSe应用的标识信息和ProSe通信组的有效期信息,使得密钥管理功能实体和应用服务器均能够通过该属性信息对ProSe通信组进行识别, 且能够明确ProSe通信组的期限。此外,通过在第一授权令牌中包括上述信息,使得密钥管理功能实体能够通过该第一授权令牌中的信息验证第一UE的身份是否合法,且第一UE的角色信息使得密钥管理功能实体能够确定该ProSe通信组是否由第一UE建立,从而使得密钥管理功能实体能够确定是否需要生成该ProSe通信组的组通信密钥。
步骤102:当第一组通信密钥请求消息中包含有第一UE的身份信息和第一授权令牌时,基于第一UE的身份信息和第一授权令牌生成组通信密钥。
具体的,当密钥管理功能实体检测到第一组通信密钥请求消息中包括第一UE的身份信息和第一授权令牌时,密钥管理功能实体可以通过该第一UE的身份信息验证第一UE的身份且检查第一授权令牌,即可以直接结合第一UE的身份信息和第一授权令牌检查第一UE是否为应用服务器的签约UE,并在检查到是时基于安全策略生成组通信密钥,保证了组通信密钥生成过程的安全性。
具体的,密钥管理功能实体还可以存储由第一授权令牌中得到的ProSe通信组的组标识信息、ProSe应用的标识信息、ProSe通信组的有效期信息以及自身所生成的组通信密钥,以便将组通信密钥提供给后续来申请的ProSe通信组的组成员。
步骤103:当第一组通信密钥请求消息中包含有第一UE的身份信息和ProSe通信组的属性信息时,基于第一UE的身份信息和属性信息从应用服务器中得到密钥生成授权并生成组通信密钥。
具体的,当密钥管理功能实体检测到第一组通信密钥请求消息中包括第一UE的身份信息和ProSe通信组的属性信息时,由于ProSe通信组的属性信息并不是应用服务器颁发的能够证明第一UE合法身份的证明信息,因此密钥管理功能实体并不能直接通过第一UE的身份信息和ProSe通信组的属性信息判断第一UE是否为应用服务器的签约UE。此时,密钥管理功能实体可以基于该第一UE的身份信息和ProSe通信组的属性信息向应用服务器确定该第一UE的身份并申请密钥生成授权,当密钥管理功能实体基于该第一UE的身份信息和ProSe通信组的属性信息从应用服务器中得到密钥生成授权时再生成组通信密钥。
这样,密钥管理功能实体可以在后台通过与应用服务器的交互过程确定是否生成组通信密钥,从而使得应用服务器不必再向第一UE颁发授权令牌,减少了UE与网络实体之间的传输参数的同时,保证了组通信密钥的安全生成过程,即减少了UE开销且保证了ProSe通信组的安全通信。
步骤104:向第一UE发送第一组通信密钥响应消息。
具体的,第一组通信密钥响应消息中包含有组通信密钥,这使得第一UE在获取到组通信密钥后能够基于该组通信密钥与ProSe通信组中的组成员进行通信,保证了第一UE所建立的动态ProSe通信组的通信安全。
本实施例中的密钥管理功能实体通过接收第一UE所发送的第一组通信密钥请求消息,且在第一组通信密钥请求消息中包含有第一UE的身份信息和第一授权令牌时,直接基于第一UE的身份信息和第一授权令牌生成组通信密钥,并在第一组通信密钥请求消息中包含有第一UE的身份信息和ProSe通信组的属性信息时从应用服务器中得到密钥生成授权后再生成组通信密钥,实现了针对第一组通信密钥请求消息中所包含的不同信息进行不同的组通信密钥生成过程,从而在密钥管理功能实体基于第一授权令牌生成组通信密钥时避免了应用服务器与密钥管理功能实体之间的后台交互过程,且保证了ProSe通信组的安全通信,在密钥管理功能实体基于ProSe通信组的属性信息从应用服务器中得到密钥生成授权后再生成组通信密钥时,使得应用服务器不必再向第一UE颁发授权令牌,减少了UE与网络实体之间的传输参数,即减少了UE开销,并保证了ProSe通信组的安全通信。
可选地,在本实施例中,密钥管理功能实体基于第一UE的身份信息和ProSe通信组的属性信息从应用服务器中得到密钥生成授权并生成组通信密钥时,可以先向应用服务器发送第一授权请求消息,其中第一授权请求消息中包含有第一UE的身份信息、ProSe通信组的组标识信息和ProSe应用的标识信息,以使应用服务器基于第一UE的身份信息、ProSe通信组的组标识信息和ProSe应用的标识信息确定第一UE是否属于ProSe通信组,然后接收应用服务器在确定第一UE属于ProSe通信组时所发送的第一授权响应消息,其中第一授权响应消息中包含有第一UE的身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息、ProSe通信组的有效 期信息和第一UE在ProSe通信组中的角色信息。
具体的,密钥管理功能实体在获取密钥生成授权时,可以将第一UE的身份信息以及ProSe通信组的属性信息中所包括的ProSe通信组的组标识信息和ProSe应用的标识信息发送给应用服务器。此时由于第一UE为通过应用服务器建立ProSe通信组,应用服务器中记录有第一UE所建立的ProSe通信组的属性信息以及第一UE的身份信息,因此应用服务器可以将第一授权请求消息中的第一UE身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息与自身所记录的信息进行对比,从而确定第一UE是否属于该ProSe通信组,即验证第一UE身份的合法性。然后,当应用服务器基于该第一授权请求消息中所包含的信息确定第一UE属于所述ProSe通信组时,可以向密钥管理功能实体发送第一授权响应消息,且该第一授权响应消息中包含第一UE的身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息、ProSe通信组的有效期信息和第一UE在ProSe通信组中的角色信息。此时密钥管理功能实体接收该第一授权响应消息,并通过ProSe通信组的有效期信息确定ProSe通信组的有效期,通过第一UE的角色信息确定是生成组通信密钥还是直接查找已有ProSe通信组的组通信密钥,当然由于第一UE的角色信息为组管理员,说明该ProSe通信组是由第一UE新建的,因此密钥管理功能实体生成组通信密钥。
这样,通过上述密钥管理功能实体和应用服务器之间的后台交互过程,实现了由应用服务器向密钥管理功能实体确定密钥生成授权的过程,避免了第一UE通过由应用服务器所颁发的第一授权令牌向密钥管理功能实体申请组通信密钥时,第一UE与应用服务器以及密钥管理功能实体之间交互参数较多的问题,减少了第一UE与网络实体之间的交互参数,减少了第一UE的开销。
另外,可选地,在本实施例中,在存在第二UE加入第一UE所建立的ProSe通信组时,同样需要向密钥管理功能实体申请组通信密钥以进行ProSe通信组内的安全通信,此时该申请过程可以包括如下步骤:
步骤A1:接收第二UE在加入ProSe通信组时所发送的第二组通信密钥请求消息。
具体的,当第二UE在加入ProSe通信组后,基于通信组内需要安全 通信的需求,第二UE可以向密钥管理功能实体发送第二组通信密钥请求消息,此时密钥管理功能实体接收第二UE所发送的第二组通信密钥请求消息。
其中,第二组通信密钥请求消息中包含有第二UE的身份信息和应用服务器为第二UE所颁发的第二授权令牌,或者第二组通信密钥请求消息中包含有第二UE的身份信息和ProSe通信组的属性信息。
具体的,ProSe通信组的属性信息包括:ProSe通信组的组标识信息、ProSe应用的标识信息和ProSe通信组的有效期信息;
第二授权令牌中包括:第二UE的身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息、ProSe通信组的有效期信息和第二UE在ProSe通信组中的角色信息,且第二UE的角色信息为组成员。
当然,在此需要说明的是,第二授权令牌中还可以包括第二授权令牌的有效期和令牌保护机制等授权信息,在此不再进行具体限定。
这样,通过在第二授权令牌中包括上述信息,使得密钥管理功能实体能够通过该第二授权令牌中的信息验证第二UE是否属于通过应用服务器所建立的ProSe通信组,且第二UE的角色信息使得密钥管理功能实体能够确定第二UE是否为后续加入ProSe通信组的组成员,从而使得密钥管理功能实体能够确定是否仅需要获取已生成的该ProSe通信组的组通信密钥。
步骤A2:当第二组通信密钥请求消息中包含有第二UE的身份信息和第二授权令牌时,基于第二UE的身份信息和第二授权令牌获取所述ProSe通信组的组通信密钥。
具体的,当密钥管理功能实体检测到第二组通信密钥请求消息中包括第二UE的身份信息和第二授权令牌时,密钥管理功能实体可以通过该第二UE的身份信息验证第二UE的身份且检查第二授权令牌,即可以直接结合第二UE的身份信息和第二授权令牌检查第二UE是否为ProSe通信组的组成员,并在检查到是时根据ProSe通信组信息检索到之前生成的组通信密钥。
步骤A3:当第二组通信密钥请求消息中包含有第二UE的身份信息和ProSe通信组的属性信息时,基于第二UE的身份信息和属性信息从应用 服务器中得到密钥颁发授权并获取ProSe通信组的组通信密钥。
具体的,当密钥管理功能实体检测到第二组通信密钥请求消息中包括第二UE的身份信息和ProSe通信组的属性信息时,由于ProSe通信组的属性信息并不是应用服务器颁发的能够证明第二UE合法身份的证明信息,因此密钥管理功能实体并不能直接通过第二UE的身份信息和ProSe通信组的属性信息判断第二UE是否为应用服务器的签约UE。此时,密钥管理功能实体可以基于该第二UE的身份信息和ProSe通信组的属性信息向应用服务器查询该第二UE的身份并申请密钥颁发授权,当应用服务器基于该第二UE的身份信息和ProSe通信组的属性信息确定第二UE属于之前建立的ProSe通信组的组成员时,密钥管理功能实体从应用服务器中得到密钥颁发授权,并检索获取之前生成的ProSe通信组的组通信密钥。
这样,密钥管理功能实体可以在后台通过与应用服务器的交互过程确定是否向第二UE颁发组通信密钥,从而使得应用服务器不必再向第二UE颁发授权令牌,减少了UE与网络实体之间的传输参数的同时,保证了组通信密钥的安全分发过程,即减少了UE开销且保证了ProSe通信组的安全通信。
步骤A4:向第二UE发送第二组通信密钥响应消息。
具体的,第二组通信密钥响应消息中包含有组通信密钥,这使得第二UE在获取到组通信密钥后能够基于该组通信密钥与ProSe通信组中的其他成员进行通信,保证了ProSe通信组的通信安全。
本实施例中的密钥管理功能实体通过接收第二UE所发送的第二组通信密钥请求消息,且在第二组通信密钥请求消息中包含有第二UE的身份信息和第二授权令牌时,直接基于第二UE的身份信息和第二授权令牌检索之前生成的组通信密钥,并在第二组通信密钥请求消息中包含有第二UE的身份信息和ProSe通信组的属性信息时从应用服务器中得到密钥颁发授权后再检索获取组通信密钥,实现了针对第而组通信密钥请求消息中所包含的不同信息进行不同的组通信密钥获取过程,使得密钥管理功能实体基于第二授权令牌获取组通信密钥时避免了应用服务器与密钥管理功能实体之间的后台交互过程,且保证了ProSe通信组的安全通信,并使得密钥管理功能实体基于ProSe通信组的属性信息从应用服务器中得到密钥 颁发授权后再获取之前生成的组通信密钥时,应用服务器不必再向第二UE颁发授权令牌,减少了UE与网络实体之间的传输参数,即减少了UE开销,并保证了ProSe通信组的安全通信。
可选地,在本实施例中,密钥管理功能实体基于第二UE的身份信息和属性信息从应用服务器中得到密钥颁发授权时,可以先向应用服务器发送第二授权请求消息,其中第二授权请求消息中包含有第二UE的身份信息、ProSe通信组的组标识信息和ProSe应用的标识信息,以使应用服务器基于第二UE的身份信息、ProSe通信组的组标识信息和ProSe应用的标识信息确定第二UE是否属于ProSe通信组,然后接收应用服务器在确定第二UE属于ProSe通信组时所发送的第二授权响应消息,其中第二授权响应消息中包含有第二UE的身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息、ProSe通信组的有效期信息和第二UE在ProSe通信组中的角色信息。
具体的,密钥管理功能实体在获取密钥颁发授权时,可以将第二UE的身份信息以及ProSe通信组的属性信息中所包括的ProSe通信组的组标识信息和ProSe应用的标识信息发送给应用服务器。此时由于第二UE为通过应用服务器加入的ProSe通信组,应用服务器中记录有第二UE的身份信息以及第二UE所加入的ProSe通信组,因此应用服务器可以将第二授权请求消息中的第二UE身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息与自身所记录的信息进行对比,从而确定第二UE是否属于该ProSe通信组,即验证第二UE身份的合法性。然后,当应用服务器基于该第二授权请求消息中所包含的信息确定第二UE属于所述ProSe通信组且角色信息为组成员时,可以向密钥管理功能实体发送第二授权响应消息,且该第二授权响应消息中包含第二UE的身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息、ProSe通信组的有效期信息和第二UE在ProSe通信组中的角色信息。此时密钥管理功能实体接收该第二授权响应消息,并通过ProSe通信组的有效期信息确定ProSe通信组的有效期,通过第二UE的角色信息确定是生成组通信密钥还是直接查找已有ProSe通信组的组通信密钥,当然由于第二UE的角色信息为组成员,说明第二UE是加入已建立的ProSe通信组,因此密钥管理功能实体检索并 获取之前生成的组通信密钥。
这样,通过上述密钥管理功能实体和应用服务器之间的后台交互过程,实现了由应用服务器向密钥管理功能实体确定密钥颁发授权的过程,避免了第二UE通过由应用服务器所颁发的第二授权令牌向密钥管理功能实体申请组通信密钥时,第二UE与应用服务器以及密钥管理功能实体之间交互参数较多的问题,减少了第二UE与网络实体之间的交互参数,减少了第二UE的开销。
另外,可选地,在本实施例中,第一UE可以根据需要进行组通信密钥的更新,此时组通信密钥的更新过程可以包括如下步骤:
密钥管理功能实体接收第一UE所发送的第一组通信密钥更新请求消息,其中第一组通信密钥更新请求消息中包含有ProSe通信组的组成员列表;然后基于第一组通信密钥更新请求消息向第一UE发送更新后的组通信密钥;接收第二UE所发送的第二组通信密钥更新请求消息,并在基于组成员列表确定第二UE为ProSe通信组的组成员时,向第二UE发送更新后的组通信密钥。
具体的,当第一UE决定需要进行组通信密钥更新时,可以向密钥管理功能实体发送第一组通信密钥更新请求消息,该消息中包含有组成员列表,从而使得密钥管理功能实体能够存储组成员列表并生成新的组通信密钥。然后密钥管理功能实体将更新后的组通信密钥发送给第一UE,且第一UE将需要更新组通信密钥的信息通知给ProSe通信组的组成员。再然后,作为组成员的第二UE可以向密钥管理功能实体发送第二组通信密钥更新请求消息,此时密钥管理功能实体在基于组成员列表确定第二UE为ProSe通信组的组成员时,将更新后的组通信密钥发送给第二UE,从而实现了ProSe通信组的组通信密钥更新过程,使得ProSe通信组的成员之间可以使用更新后的组通信密钥进行安全的组通信。
本实施例通过上述过程实现了ProSe通信组的动态建立过程,且保证了ProSe通信组之间通过组通信密钥进行安全通信。
此外,如图2所示,为本申请实施例应用于第一UE的ProSe通信组的通信方法的步骤流程图,该方法包括如下步骤:
步骤201:当第一UE通过应用服务器建立一ProSe应用下的ProSe 通信组时,向密钥管理功能实体发送第一组通信密钥请求消息。
具体的,第一组通信密钥请求消息中包含有第一UE的身份信息和应用服务器为第一UE所颁发的第一授权令牌,以使密钥管理功能实体基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥;或者第一组通信密钥请求消息中包含有第一UE的身份信息和ProSe通信组的属性信息,以使密钥管理功能实体基于第一UE的身份信息和属性信息从应用服务器中得到密钥生成授权并生成组通信密钥。
此外,具体的,ProSe通信组的属性信息包括:ProSe通信组的组标识信息、ProSe应用的标识信息和ProSe通信组的有效期信息;
第一授权令牌中包括:第一UE的身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息、ProSe通信组的有效期信息和第一UE在ProSe通信组中的角色信息,且第一UE的角色信息为组管理员。
在此需要说明的是,上述过程可以参见密钥功能实体侧接收第一组通信密钥请求消息的过程,在此不再进行赘述。
步骤202:接收密钥管理功能实体所发送的第一组通信密钥响应消息。
具体的,密钥管理功能实体在接收到第一组通信密钥请求消息后可以生成组通信密钥,并向第一UE发送第一组通信密钥响应消息。此时,第一UE接收该第一组通信密钥响应消息。
具体的,第一组通信密钥响应消息中包含有组通信密钥,从而使得第一UE能够基于该组通信密钥进行组内的安全通信。
步骤203:基于组通信密钥与后续加入ProSe通信组的组成员进行通信。
具体的,第一UE基于组通信密钥与后续加入ProSe通信组的组成员进行通信,保证了ProSe通信组的安全通信。
这样,本实施例中的第一UE在通过应用服务器建立ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第一组通信密钥请求消息,并接收密钥管理功能实体基于该第一组通信密钥请求消息所发送的组通信密钥,使得ProSe通信组能够基于该组通信密钥进行组内通信,保证了ProSe通信组的安全性。
此外,可选地,在本实施例中,第一UE通过应用服务器建立一ProSe 应用下的ProSe通信组时,可以当第一UE需要在ProSe应用下建立ProSe通信组时,向应用服务器发送组通信建立请求,其中组通信建立请求中包含有第一UE的身份信息和ProSe应用的标识信息;然后接收应用服务器基于组通信建立请求所发送的组通信建立响应消息,其中组通信建立响应消息中包含有所建立的ProSe通信组的属性信息,或者包含有所建立的ProSe通信组的属性信息和第一授权令牌。
具体的,第一UE想要在某个ProSe应用下建立一个ProSe通信组时,可以先向应用服务器发送组通信建立请求,且该请求中包含有第一UE的身份信息和ProSe应用的标识信息。应用服务器可以基于签约信息检测第一UE是否可以建立一个ProSe通信组,若可以则建立一个ProSe通信组。具体的,该ProSe通信组具有唯一的一个ProSe通信组的组标识、ProSe应用的标识、组成员列表和组有效期等属性,组成员列表中的组成员包含有UE身份信息和UE的角色信息等属性,组成员的角色有组管理员和组成员,请求创建ProSe通信组的UE的角色为组管理员,后续加入ProSe通信组的UE的角色为组成员。
然后,应用服务器可以将ProSe通信组的属性信息和第一授权令牌发送给第一UE,或者仅将ProSe通信组的属性信息发送给第一UE。具体的,第一UE可以使用该第一授权令牌向负责管理组通信密钥的密钥管理功能实体申请用于组内安全通信的组通信密钥,当然密钥管理功能实体能够解析第一授权令牌的安全机制,验证令牌是否正确和有效。
这样,通过上述过程实现了ProSe通信组的建立过程。
此外,可选地,在本实施例中,第一UE还需要查找能够加入至ProSe通信组的组成员。此时,组成员加入的过程可以包括如下步骤:
步骤B1:第一UE通过广播方式发送组通信发现请求消息,组通信发现请求消息中包含有ProSe应用的标识信息和第一UE的身份信息。
具体的,第一UE可以通过PC5接口以广播方式发送组通信发现请求消息,并该消息中包含ProSe应用的标识信息和第一UE的身份信息,从而使得其他UE能够基于第一UE的身份信息查找到第一UE,并基于ProSe应用的标识信息确定是否加入ProSe通信组。
步骤B2:接收第二UE基于组通信发现请求消息所发送的组通信发现 响应消息。
具体的,第二UE通过PC5接口接收到第一UE的组通信发现请求消息之后,若确定加入ProSe通信组,则向第一UE发送组通信发现响应消息,其中该组通信发现响应消息中包含有ProSe应用的标识信息和第二UE的身份信息。
步骤B3:向第二UE发送组通信发现接受消息。
具体的,第一UE接收到第二UE的组通信发现响应消息之后,若同意第二UE加入ProSe通信组,则向第二UE发送组通信发现接受消息,且组通信发现接受消息中包含有ProSe应用的标识信息和ProSe通信组的组标识信息,以使第二UE基于ProSe应用的标识信息和ProSe通信组的组标识信息加入ProSe通信组。
步骤B4:接收第二UE在加入ProSe通信组后所发送的组通信发现完成消息。
具体的,当第二UE加入ProSe通信组且获得组通信密钥之后,可以向第一UE发送组通信发现完成消息,从而使得第一UE能够获知可以与第二UE进行安全通信。
这样,通过上述过程实现了第一UE发现组成员以及将组成员加入至ProSe通信组的过程,实现了PorSe通信组中的成员的动态加入过程,即实现了ProSe通信组的动态建立过程。
在此需要说明的是,上述过程可以在第一UE接收密钥管理功能实体所发送的第一组通信密钥响应消息之后执行,即在第一UE建立起ProSe通信组且得到组通信密钥之后进行,从而保证了在后续UE加入后即可进行组内通信。此外,上述过程中的步骤B1和步骤B2也可以在第一UE通过应用服务器建立ProSe应用下的ProSe通信组之前进行,步骤B3和步骤B4在第一UE建立ProSe通信组之后进行,即允许当第一UE发现有组成员可以一起建立ProSe通信组之前进行组成员发现过程,从而避免了在第一UE建立ProSe通信组后但无组员情况的发生,避免了无效ProSe通信组的产生。
另外,可选地,在本实施例中,第一UE可以根据需要随时进行组通信密钥的更新,此时第一UE发起的组通信密钥的更新过程可以包括如下 步骤:
第一UE向密钥管理功能实体发送第一组通信密钥更新请求消息,其中第一组通信密钥更新请求消息中包含有ProSe通信组的组成员列表;然后接收密钥管理功能实体基于第一组通信密钥更新请求消息所发送的更新后的组通信密钥;再然后向ProSe通信组的组成员发送密钥更新通知消息,以使ProSe通信组的组成员更新组通信密钥。
在此需要说明的是,上述组通信密钥的更新过程可以参见密钥管理功能实体侧的相关内容,在此不再进行赘述。
这样,本实施例通过上述过程实现了ProSe通信组的动态建立过程,且保证了ProSe通信组之间能够通过组通信密钥进行安全通信。
此外,如图3所示,为本申请实施例中应用于第二UE的ProSe通信组的通信方法的步骤流程图,该方法包括如下步骤:
步骤301:当第二UE加入第一UE所建立的ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第二组通信密钥请求消息。
具体的,当第二UE在加入ProSe通信组后,基于通信组内需要安全通信的需求,第二UE可以向密钥管理功能实体发送第二组通信密钥请求消息。
其中,第二组通信密钥请求消息中包含有第二UE的身份信息和应用服务器为第二UE所颁发的第二授权令牌,以使密钥管理功能实体基于第二UE的身份信息和第二授权令牌获取ProSe通信组的组通信密钥;或者组通信密钥请求消息中包含有第二UE的身份信息和ProSe通信组的属性信息,以使密钥管理功能实体基于第二UE的身份信息和属性信息从应用服务器中得到密钥颁发授权并获取ProSe通信组的组通信密钥。
具体的,ProSe通信组的属性信息包括:ProSe通信组的组标识信息、ProSe应用的标识信息和ProSe通信组的有效期信息;
第二授权令牌中包括:第二UE的身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息、ProSe通信组的有效期信息和第二UE在ProSe通信组中的角色信息,且第二UE的角色信息为组成员。
在此需要说明的是,上述过程可以参见密钥功能实体侧接收第二组通信密钥请求消息的过程,在此不再进行赘述。
步骤302:接收密钥管理功能实体所发送的第二组通信密钥响应消息。
具体的,密钥管理功能实体在接收到第二组通信密钥请求消息后可以获取组通信密钥,并向第二UE发送第二组通信密钥响应消息。此时,第二UE接收该第二组通信密钥响应消息。
具体的,第二组通信密钥响应消息中包含有组通信密钥,从而使得第二UE能够基于该组通信密钥进行组内的安全通信。
步骤303:基于组通信密钥与ProSe通信组中的成员进行通信。
具体的,第二UE基于组通信密钥与ProSe通信组中的其他成员进行通信,保证了ProSe通信组的安全通信。
这样,本实施例中的第二UE在加入到ProSe通信组时向密钥管理功能实体发送第二组通信密钥请求消息,并接收密钥管理功能实体基于该第二组通信密钥请求消息所发送的组通信密钥,使得ProSe通信组能够基于该组通信密钥进行组内通信,保证了ProSe通信组的安全性。
可选地,在本实施例中,第二UE加入第一UE所建立的ProSe应用下的ProSe通信组时,可以向应用服务器发送组通信加入请求,其中组通信加入请求中包含有第二UE的身份信息、ProSe应用的标识信息和ProSe通信组的标识信息;然后接收应用服务器基于组通信加入请求所发送的组通信加入响应消息,其中组通信加入响应消息中包含有ProSe通信组的属性信息,或者包含有ProSe通信组的属性信息和第二授权令牌。
在此需要说明的是,上述第二UE加入ProSe通信组的过程可以参见第一UE侧方法实施例的相关内容,在此不再进行赘述。
此外,可选地,本实施例中第一UE还需要查找能够加入至ProSe通信组的组成员。此时,作为组成员的第二UE的发现过程可以包括如下步骤:
接收第一UE通过广播方式所发送的组通信发现请求消息,组通信发现请求消息中包含有ProSe应用的标识信息和第一UE的身份信息;然后基于组通信发现请求消息向第一UE发送组通信发现响应消息,其中组通信发现响应消息中包含有ProSe应用的标识信息和第二UE的身份信息;再然后接收第一UE所发送的组通信发现接受消息,其中组通信发现接受消息中包含有ProSe应用的标识信息和ProSe通信组的组标识信息;最后 当基于ProSe应用的标识信息和ProSe通信组的组标识信息加入ProSe通信组时向第一UE发送组通信发现完成消息。
在此需要说明的是,上述过程可以参见第一UE侧方法实施例的相关内容,在此不再进行赘述。
另外,可选地,第二UE还可以更新组通信密钥,此时更新过程可以包括如下步骤:
第二UE接收第一UE所发送的密钥更新通知消息,然后基于密钥更新通知消息向密钥管理功能实体发送第二组通信密钥更新请求消息,最后接收密钥管理功能实体在确定第二UE为ProSe通信组的组成员时所发送的更新后的组通信密钥。
在此需要说明的是,上述第二UE的组通信密钥更新过程可以参见密钥管理功能实体侧和第一UE侧的相关内容,在此不再进行赘述。
这样本实施例通过上述过程实现了第二UE加入第一UE所建立的ProSe通信组的过程,并且实现了ProSe通信组的安全通信。
下面通过具体实施例对本申请进行具体说明。
实施例一:如图4所示,为ProSe通信组建立安全通信的流程图之一,该过程包括如下步骤:
在UE、应用服务器和密钥管理功能实体中预配置与动态ProSe通信组通信相关的参数。例如,在UE中配置应用服务器和密钥管理功能实体的地址信息,与密钥管理功能实体建立安全关联的密钥信息;在应用服务器中配置与ProSe通信组通信相关的UE签约信息;在密钥管理功能实体中配置与UE建立安全关联的密钥信息和组通信安全相关的安全策略。
1、第一UE为发起ProSe通信组的UE,当第一UE需要在某个ProSe应用下建立一个ProSe通信组时,向应用服务器发送组通信建立请求,该请求中包含有第一UE的身份信息和ProSe应用的标识信息。
2、应用服务器基于签约信息检查第一UE是否可以建立一个ProSe通信组。若可以,则应用服务器建立一个ProSe通信组,为该组设置一个唯一的组标识,并为第一UE生成授权令牌。然后,应用服务器向第一UE发送组通信建立响应消息,其中组通信建立响应消息中包含有所建立的ProSe通信组的属性信息和第一授权令牌。ProSe通信组的属性信息包括: ProSe通信组的组标识信息、ProSe应用的标识信息和ProSe通信组的有效期信息;第一授权令牌中包括:第一UE的身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息、ProSe通信组的有效期信息和第一UE在ProSe通信组中的角色信息,且第一UE的角色信息为组管理员。此外,第一授权令牌中还可以包含令牌有效期和令牌保护机制等信息。应用服务器存储ProSe通信组的创建信息和组的信息,以便将来加入新的组成员。
3、第一UE向密钥管理功能实体发送第一组通信密钥请求消息,其中包含有第一UE的身份信息和第一授权令牌。
4、密钥管理功能实体认证用户身份,检查授权令牌,基于安全策略生成组通信密钥,并将组通信密钥通过第一组通信密钥响应消息提供给第一UE。密钥管理功能实体应存储ProSe应用的标识信息、ProSe通信组的标识信息、生成的组通信密钥和组有效期等,以便将组密钥提供给之后来申请的组成员。
5、第一UE通过PC5接口以广播方式发送组通信发现请求消息,该请求消息中包含有ProSe应用的标识信息和第一UE的身份信息。
6、第二UE通过PC5接口接收到第一UE的组通信发现请求消息。第二UE决定加入该组通信,且向第一UE发送组通信发现响应消息,该响应消息中包含有ProSe应用的标识信息和第二UE的身份信息。
7、第一UE向第二UE发送发现接受消息,其中包含有ProSe应用的标识信息和ProSe通信组的标识信息。
8、第二UE向应用服务器发送组通信加入请求消息,其中包含有第二UE的身份信息、ProSe应用的标识信息和ProSe通信组的标识信息。
9、应用服务器检查第二UE是否可以作为组的成员,若可以则向第二UE颁发第二授权令牌。应用服务器向第二UE发送组通信加入响应消息,其中包含有ProSe通信组的属性信息和第二授权令牌。其中属性信息包括ProSe通信组的标识信息、ProSe应用的标识信息和ProSe通信组的有效期等;第二授权令牌中包含有第二UE的身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息、ProSe通信组的有效期信息和第二UE在所述ProSe通信组中的角色信息,且第二UE的角色信息为组管理员。此外,第二授权令牌还可以包含令牌有效期和令牌保护机制等信息。应用服务器 更新存储的组的信息。
10、第二UE向密钥管理功能实体发送第二组通信密钥请求消息,其中包含有第二UE的身份信息和第二授权令牌。
11、密钥管理功能实体认证用户身份,检查第二授权令牌,根据组信息检索到之前生成的的组通信密钥,并将组通信密钥通过第二组通信密钥响应提供给第二UE。
12、第二UE向第一UE发送发现完成消息。
13、此时ProSe通信组中的组成员之间可以进行安全的组通信。
14、当组管理员第一UE决定需要进行组通信密钥更新时,第一UE向密钥管理功能实体发送第一组通信密钥更新请求,请求中包含组成员列表。密钥管理功能实体存储组成员列表,并生成新的组通信密钥。
15、组管理员第一UE将需要更新密钥的信息通知组成员第二UE。
16、组成员第二UE向密钥管理功能实体发送第二组通信密钥更新请求。密钥管理功能实体基于组管理员第一UE提供的组成员列表向组成员第二UE提供新的组通信密钥。
17、等组通信密钥更新完成后,组成员之间可以使用新的组通信密钥进行安全的组通信。
实施例二:如图5所示,为ProSe通信组建立安全通信的流程图之二,该过程包括如下步骤:
在UE、应用服务器和密钥管理功能实体中预配置与动态ProSe通信组通信相关的参数。例如,在UE中配置应用服务器和密钥管理功能实体的地址信息,与密钥管理功能实体建立安全关联的密钥信息;在应用服务器中配置与ProSe通信组通信相关的UE签约信息;在密钥管理功能实体中配置与UE建立安全关联的密钥信息和组通信安全相关的安全策略。
1、第一UE为发起ProSe通信组的UE,当第一UE需要在某个ProSe应用下建立一个ProSe通信组时,向应用服务器发送组通信建立请求,该请求中包含有第一UE的身份信息和ProSe应用的标识信息。
2、应用服务器基于签约信息检查第一UE是否可以建立一个ProSe通信组。若可以,则应用服务器建立一个ProSe通信组,为该组设置一个唯一的组标识。然后,应用服务器向第一UE发送组通信建立响应消息, 其中组通信建立响应消息中包含有所建立的ProSe通信组的属性信息。ProSe通信组的属性信息包括:ProSe通信组的组标识信息、ProSe应用的标识信息和ProSe通信组的有效期信息。应用服务器存储ProSe通信组的创建信息和组的信息,以便将来加入新的组成员。
3、第一UE向密钥管理功能实体发送第一组通信密钥请求消息,其中包含有第一UE的身份信息和ProSe通信组的属性信息。
4、密钥管理功能实体向应用服务器发送第一授权请求消息,其中第一授权请求消息中包含有第一UE的身份信息、ProSe通信组的组标识信息和ProSe应用的标识信息。
5、应用服务器利用第一UE的身份信息、ProSe通信组的组标识信息和ProSe应用的标识信息确定第一UE在ProSe通信组中的角色信息,并向密钥管理功能实体发送第一授权响应消息,其中第一授权响应消息中包含有第一UE的身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息、ProSe通信组的有效期信息和第一UE在ProSe通信组中的角色信息。
6、密钥管理功能实体将组通信密钥通过第一组通信密钥响应消息提供给第一UE。
7、第一UE通过PC5接口以广播方式发送组通信发现请求消息,该请求消息中包含有ProSe应用的标识信息和第一UE的身份信息。
8、第二UE通过PC5接口接收到第一UE的组通信发现请求消息。第二UE决定加入该组通信,且向第一UE发送组通信发现响应消息,该响应消息中包含有ProSe应用的标识信息和第二UE的身份信息。
9、第一UE向第二UE发送发现接受消息,其中包含有ProSe应用的标识信息和ProSe通信组的标识信息。
10、第二UE向应用服务器发送组通信加入请求消息,其中包含有第二UE的身份信息、ProSe应用的标识信息和ProSe通信组的标识信息。
11、应用服务器检查第二UE是否可以作为组的成员,若可以则向第二UE发送组通信加入响应消息,其中包含有ProSe通信组的属性信息。应用服务器更新存储的组的信息。
12、第二UE向密钥管理功能实体发送第二组通信密钥请求消息,其 中包含有第二UE的身份信息和ProSe通信组的属性信息。
13、密钥管理功能实体向应用服务器发送第二授权请求消息,其中第二授权请求消息中包含有第二UE的身份信息、ProSe通信组的组标识信息和ProSe应用的标识信息。
14、应用服务器利用第二UE的身份信息、ProSe通信组的组标识信息和ProSe应用的标识信息确定第二UE在ProSe通信组中的角色信息,并向密钥管理功能实体发送第二授权响应消息,其中第二授权响应消息中包含有第二UE的身份信息、ProSe通信组的组标识信息、ProSe应用的标识信息、ProSe通信组的有效期信息和第二UE在ProSe通信组中的角色信息。
15、密钥管理功能实体根据组信息获取之前生成的组通信密钥,并将获取的组通信密钥通过第二组通信密钥响应消息提供给第二UE。
16、第二UE向第一UE发送发现完成消息。
17、此时ProSe通信组中的组成员之间可以进行安全的组通信。
18、当组管理员第一UE决定需要进行组通信密钥更新时,第一UE向密钥管理功能实体发送第一组通信密钥更新请求,请求中包含组成员列表。密钥管理功能实体存储组成员列表,并生成新的组通信密钥。
19、组管理员第一UE将需要更新密钥的信息通知组成员第二UE。
20、组成员第二UE向密钥管理功能实体发送第二组通信密钥更新请求。密钥管理功能实体基于组管理员第一UE提供的组成员列表向组成员第二UE提供新的组通信密钥。
21、等组通信密钥更新完成后,组成员之间可以使用新的组通信密钥进行安全的组通信。
这样,本申请通过上述任一实施例均实现了ProSe通信组的安全通信。
此外,图6是本申请实施例中应用于密钥通信功能实体的ProSe通信组的通信装置的模块框图,该装置包括:
接收模块601,用于接收第一用户设备UE通过应用服务器建立近距离服务ProSe应用下的ProSe通信组时所发送的第一组通信密钥请求消息,其中所述第一组通信密钥请求消息中包含有第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,或者所述第一组通信密 钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息;
第一生成模块602,用于当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述第一授权令牌时,基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥;
第二生成模块603,用于当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息时,基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
发送模块604,用于向所述第一UE发送第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
可选地,第二生成模块603具体用于:向所述应用服务器发送第一授权请求消息,其中所述第一授权请求消息中包含有所述第一UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息,以使所述应用服务器基于所述第一UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息确定所述第一UE是否属于所述ProSe通信组;
接收所述应用服务器在确定所述第一UE属于所述ProSe通信组时所发送的第一授权响应消息,其中所述第一授权响应消息中包含有所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息。
可选地,接收模块601还用于,接收第二UE在加入所述ProSe通信组时所发送的第二组通信密钥请求消息,其中所述第二组通信密钥请求消 息中包含有所述第二UE的身份信息和所述应用服务器为所述第二UE所颁发的第二授权令牌,或者所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息;
第一生成模块602还用于,当所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述第二授权令牌时,基于所述第二UE的身份信息和所述第二授权令牌获取所述ProSe通信组的组通信密钥;
第二生成模块603还用于,当所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息时,基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权并获取所述ProSe通信组的组通信密钥;
发送模块604还用于,向所述第二UE发送第二组通信密钥响应消息,其中所述第二组通信密钥响应消息中包含有所述组通信密钥;
其中,所述第二授权令牌中包括:所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息,且所述第二UE的角色信息为组成员。
可选地,第二生成模块603还用于,向所述应用服务器发送第二授权请求消息,其中所述第二授权请求消息中包含有所述第二UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息,以使所述应用服务器基于所述第二UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息确定所述第二UE是否属于所述ProSe通信组;
接收所述应用服务器在确定所述第二UE属于所述ProSe通信组时所发送的第二授权响应消息,其中所述第二授权响应消息中包含有所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息。
可选地,装置还包括密钥更新模块(图中未示出),用于接收所述第一UE所发送的第一组通信密钥更新请求消息,其中所述第一组通信密钥更新请求消息中包含有所述ProSe通信组的组成员列表;
基于所述第一组通信密钥更新请求消息向所述第一UE发送更新后的组通信密钥;
接收第二UE所发送的第二组通信密钥更新请求消息,并在基于所述组成员列表确定所述第二UE为所述ProSe通信组的组成员时,向所述第二UE发送更新后的组通信密钥。
在此需要说明的是,上述装置能够实现密钥管理功能实体侧方法实施例的所有步骤并能够达到相同的有益效果,在此不再进行赘述。
此外,图7是本申请实施例中应用于第一UE的ProSe通信组的通信装置的模块框图,该装置包括:
发送模块701,用于当第一UE通过应用服务器建立一近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第一组通信密钥请求消息;其中所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
接收模块702,用于接收所述密钥管理功能实体所发送的第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
通信模块703,用于基于所述组通信密钥与后续加入所述ProSe通信组的组成员进行通信;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
可选地,所述第一UE通过应用服务器建立一近距离服务ProSe应用 下的ProSe通信组,包括:
当所述第一UE需要在所述ProSe应用下建立ProSe通信组时,向所述应用服务器发送组通信建立请求,其中所述组通信建立请求中包含有所述第一UE的身份信息和所述ProSe应用的标识信息;
接收所述应用服务器基于所述组通信建立请求所发送的组通信建立响应消息,其中所述组通信建立响应消息中包含有所建立的ProSe通信组的属性信息,或者包含有所建立的ProSe通信组的属性信息和所述第一授权令牌。
可选地,装置还包括终端发现模块(图中未示出),用于通过广播方式发送组通信发现请求消息,所述组通信发现请求消息中包含有所述ProSe应用的标识信息和所述第一UE的身份信息;
接收第二UE基于所述组通信发现请求消息所发送的组通信发现响应消息,其中所述组通信发现响应消息中包含有所述ProSe应用的标识信息和所述第二UE的身份信息;
向所述第二UE发送组通信发现接受消息,其中所述组通信发现接受消息中包含有所述ProSe应用的标识信息和所述ProSe通信组的组标识信息,以使所述第二UE基于所述ProSe应用的标识信息和所述ProSe通信组的组标识信息加入所述ProSe通信组;
接收所述第二UE在加入所述ProSe通信组后所发送的组通信发现完成消息。
可选地,装置还包括密钥更新模块(图中未示出),用于向所述密钥管理功能实体发送第一组通信密钥更新请求消息,其中所述第一组通信密钥更新请求消息中包含有所述ProSe通信组的组成员列表;
接收所述密钥管理功能实体基于所述第一组通信密钥更新请求消息所发送的更新后的组通信密钥;
向所述ProSe通信组的组成员发送密钥更新通知消息,以使所述ProSe通信组的组成员更新组通信密钥。
在此需要说明的是,上述装置能够实现第一UE侧方法实施例的所有步骤并能够达到相同的有益效果,在此不再进行赘述。
此外,图8是本申请实施例中应用于第二UE的ProSe通信组的通信 装置的模块框图,该装置包括:
发送模块801,用于当第二UE加入第一UE所建立的近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第二组通信密钥请求消息;其中所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和应用服务器为所述第二UE所颁发的第二授权令牌,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述第二授权令牌获取所述ProSe通信组的组通信密钥,或者所述组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权并获取所述ProSe通信组的组通信密钥;
接收模块802,用于接收所述密钥管理功能实体所发送的第二组通信密钥响应消息,其中所述第二组通信密钥响应消息中包含有所述组通信密钥;
通信模块803,用于基于所述组通信密钥与所述ProSe通信组中的成员进行通信;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
所述第二授权令牌中包括:所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息,且所述第二UE的角色信息为组成员。
可选地,所述第二UE加入第一UE所建立的近距离服务ProSe应用下的ProSe通信组,包括:
向所述应用服务器发送组通信加入请求,其中所述组通信加入请求中包含有所述第二UE的身份信息、ProSe应用的标识信息和所述ProSe通信组的标识信息;
接收所述应用服务器基于所述组通信加入请求所发送的组通信加入响应消息,其中所述组通信加入响应消息中包含有所述ProSe通信组的属性信息,或者包含有所述ProSe通信组的属性信息和所述第二授权令牌。
可选地,装置还包括终端加入模块(图中未示出),用于接收所述第 一UE通过广播方式所发送的组通信发现请求消息,所述组通信发现请求消息中包含有所述ProSe应用的标识信息和所述第一UE的身份信息;
基于所述组通信发现请求消息向所述第一UE发送组通信发现响应消息,其中所述组通信发现响应消息中包含有所述ProSe应用的标识信息和所述第二UE的身份信息;
接收所述第一UE所发送的组通信发现接受消息,其中所述组通信发现接受消息中包含有所述ProSe应用的标识信息和所述ProSe通信组的组标识信息;
当基于所述ProSe应用的标识信息和所述ProSe通信组的组标识信息加入所述ProSe通信组时向所述第一UE发送组通信发现完成消息。
可选地,装置还包括密钥更新模块(图中未示出),用于接收所述第一UE所发送的密钥更新通知消息;
基于所述密钥更新通知消息向所述密钥管理功能实体发送第二组通信密钥更新请求消息;
接收所述密钥管理功能实体在确定所述第二UE为所述ProSe通信组的组成员时所发送的更新后的组通信密钥。
在此需要说明的是,上述装置能够实现第二UE侧方法实施例的所有步骤并能够达到相同的有益效果,在此不再进行赘述。
图9是本申请实施例提供的一种ProSe通信组的通信装置的结构示意图之一,包括收发机900,处理器910,存储器920。
其中,在图9中,总线架构可以包括任意数量的互联的总线和桥,具体由处理器910代表的一个或多个处理器和存储器920代表的存储器的各种电路链接在一起。总线架构还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口提供接口。收发机900可以是多个元件,即包括发送机和接收机,提供用于在传输介质上与各种其他装置通信的单元,这些传输介质包括无线信道、有线信道、光缆等传输介质。处理器910负责管理总线架构和通常的处理,存储器920可以存储处理器910在执行操作时所使用的数据。
处理器910可以是中央处埋器(CPU)、专用集成电路(Application  Specific Integrated Circuit,ASIC)、现场可编程门阵列(Field-Programmable Gate Array,FPGA)或复杂可编程逻辑器件(Complex Programmable Logic Device,CPLD),处理器也可以采用多核架构。
存储器920,用于存储计算机程序;收发机900,用于在所述处理器的控制下收发数据;处理器910,用于读取所述存储器中的计算机程序并执行以下操作:
接收第一用户设备UE通过应用服务器建立近距离服务ProSe应用下的ProSe通信组时所发送的第一组通信密钥请求消息,其中所述第一组通信密钥请求消息中包含有第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息;当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述第一授权令牌时,基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥;当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息时,基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;向所述第一UE发送第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
可选地,所述基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权,包括:
向所述应用服务器发送第一授权请求消息,其中所述第一授权请求消息中包含有所述第一UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息,以使所述应用服务器基于所述第一UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息确 定所述第一UE是否属于所述ProSe通信组;接收所述应用服务器在确定所述第一UE属于所述ProSe通信组时所发送的第一授权响应消息,其中所述第一授权响应消息中包含有所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息。
可选地,处理器910还用于执行以下操作:接收第二UE在加入所述ProSe通信组时所发送的第二组通信密钥请求消息,其中所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述应用服务器为所述第二UE所颁发的第二授权令牌,或者所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息;当所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述第二授权令牌时,基于所述第二UE的身份信息和所述第二授权令牌获取所述ProSe通信组的组通信密钥;当所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息时,基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权并获取所述ProSe通信组的组通信密钥;向所述第二UE发送第二组通信密钥响应消息,其中所述第二组通信密钥响应消息中包含有所述组通信密钥;
其中,所述第二授权令牌中包括:所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息,且所述第二UE的角色信息为组成员。
可选地,所述基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权,包括:
向所述应用服务器发送第二授权请求消息,其中所述第二授权请求消息中包含有所述第二UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息,以使所述应用服务器基于所述第二UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息确定所述第二UE是否属于所述ProSe通信组;接收所述应用服务器在确定所述第二UE属于所述ProSe通信组时所发送的第二授权响应消息,其中所述第二授权响应消息中包含有所述第二UE的身份信息、所述ProSe通 信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息。
可选地,处理器910还用于执行以下操作:接收所述第一UE所发送的第一组通信密钥更新请求消息,其中所述第一组通信密钥更新请求消息中包含有所述ProSe通信组的组成员列表;基于所述第一组通信密钥更新请求消息向所述第一UE发送更新后的组通信密钥;接收第二UE所发送的第二组通信密钥更新请求消息,并在基于所述组成员列表确定所述第二UE为所述ProSe通信组的组成员时,向所述第二UE发送更新后的组通信密钥。
上述实施例能够实现密钥管理功能实体侧的所有步骤并能够达到相同的技术效果,在此不再进行赘述。
图10是本申请实施例提供的一种ProSe通信组的通信装置的结构示意图之二,包括收发机1000,处理器1010,存储器1020。
其中,在图10中,总线架构可以包括任意数量的互联的总线和桥,具体由处理器1010代表的一个或多个处理器和存储器1020代表的存储器的各种电路链接在一起。总线架构还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口提供接口。收发机1000可以是多个元件,即包括发送机和接收机,提供用于在传输介质上与各种其他装置通信的单元,这些传输介质包括无线信道、有线信道、光缆等传输介质。处理器1010负责管理总线架构和通常的处理,存储器1020可以存储处理器1010在执行操作时所使用的数据。
处理器1010可以是中央处埋器(CPU)、专用集成电路(Application Specific Integrated Circuit,ASIC)、现场可编程门阵列(Field-Programmable Gate Array,FPGA)或复杂可编程逻辑器件(Complex Programmable Logic Device,CPLD),处理器也可以采用多核架构。
存储器1020,用于存储计算机程序;收发机1000,用于在所述处理器的控制下收发数据;处理器1010,用于读取所述存储器中的计算机程序并执行以下操作:
当第一UE通过应用服务器建立一近距离服务ProSe应用下的ProSe 通信组时,向密钥管理功能实体发送第一组通信密钥请求消息;其中所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
接收所述密钥管理功能实体所发送的第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;基于所述组通信密钥与后续加入所述ProSe通信组的组成员进行通信;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
可选地,所述第一UE通过应用服务器建立一近距离服务ProSe应用下的ProSe通信组,包括:
当所述第一UE需要在所述ProSe应用下建立ProSe通信组时,向所述应用服务器发送组通信建立请求,其中所述组通信建立请求中包含有所述第一UE的身份信息和所述ProSe应用的标识信息;接收所述应用服务器基于所述组通信建立请求所发送的组通信建立响应消息,其中所述组通信建立响应消息中包含有所建立的ProSe通信组的属性信息,或者包含有所建立的ProSe通信组的属性信息和所述第一授权令牌。
可选地,处理器1010还用于执行以下操作:
通过广播方式发送组通信发现请求消息,所述组通信发现请求消息中包含有所述ProSe应用的标识信息和所述第一UE的身份信息;接收第二UE基于所述组通信发现请求消息所发送的组通信发现响应消息,其中所述组通信发现响应消息中包含有所述ProSe应用的标识信息和所述第二 UE的身份信息;向所述第二UE发送组通信发现接受消息,其中所述组通信发现接受消息中包含有所述ProSe应用的标识信息和所述ProSe通信组的组标识信息,以使所述第二UE基于所述ProSe应用的标识信息和所述ProSe通信组的组标识信息加入所述ProSe通信组;接收所述第二UE在加入所述ProSe通信组后所发送的组通信发现完成消息。
可选地,处理器1010还用于执行以下操作:
向所述密钥管理功能实体发送第一组通信密钥更新请求消息,其中所述第一组通信密钥更新请求消息中包含有所述ProSe通信组的组成员列表;接收所述密钥管理功能实体基于所述第一组通信密钥更新请求消息所发送的更新后的组通信密钥;向所述ProSe通信组的组成员发送密钥更新通知消息,以使所述ProSe通信组的组成员更新组通信密钥。
上述实施例能够实现第一UE侧的所有步骤并能够达到相同的技术效果,在此不再进行赘述。
图11是本申请实施例提供的一种ProSe通信组的通信装置的结构示意图之三,包括收发机1100,处理器1110,存储器1120。
其中,在图11中,总线架构可以包括任意数量的互联的总线和桥,具体由处理器1110代表的一个或多个处理器和存储器1120代表的存储器的各种电路链接在一起。总线架构还可以将诸如外围设备、稳压器和功率管理电路等之类的各种其他电路链接在一起,这些都是本领域所公知的,因此,本文不再对其进行进一步描述。总线接口提供接口。收发机1100可以是多个元件,即包括发送机和接收机,提供用于在传输介质上与各种其他装置通信的单元,这些传输介质包括无线信道、有线信道、光缆等传输介质。处理器1110负责管理总线架构和通常的处理,存储器1120可以存储处理器1110在执行操作时所使用的数据。
处理器1110可以是中央处埋器(CPU)、专用集成电路(Application Specific Integrated Circuit,ASIC)、现场可编程门阵列(Field-Programmable Gate Array,FPGA)或复杂可编程逻辑器件(Complex Programmable Logic Device,CPLD),处理器也可以采用多核架构。
存储器1120,用于存储计算机程序;收发机1100,用于在所述处理器的控制下收发数据;处理器1110,用于读取所述存储器中的计算机程序 并执行以下操作:
当第二UE加入第一UE所建立的近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第二组通信密钥请求消息;其中所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和应用服务器为所述第二UE所颁发的第二授权令牌,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述第二授权令牌获取所述ProSe通信组的组通信密钥,或者所述组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权并获取所述ProSe通信组的组通信密钥;
接收所述密钥管理功能实体所发送的第二组通信密钥响应消息,其中所述第二组通信密钥响应消息中包含有所述组通信密钥;基于所述组通信密钥与所述ProSe通信组中的成员进行通信;
其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;所述第二授权令牌中包括:所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息,且所述第二UE的角色信息为组成员。
可选地,所述第二UE加入第一UE所建立的近距离服务ProSe应用下的ProSe通信组,包括:
向所述应用服务器发送组通信加入请求,其中所述组通信加入请求中包含有所述第二UE的身份信息、ProSe应用的标识信息和所述ProSe通信组的标识信息;接收所述应用服务器基于所述组通信加入请求所发送的组通信加入响应消息,其中所述组通信加入响应消息中包含有所述ProSe通信组的属性信息,或者包含有所述ProSe通信组的属性信息和所述第二授权令牌。
可选地,处理器1110还用于执行以下操作:
接收所述第一UE通过广播方式所发送的组通信发现请求消息,所述组通信发现请求消息中包含有所述ProSe应用的标识信息和所述第一UE 的身份信息;基于所述组通信发现请求消息向所述第一UE发送组通信发现响应消息,其中所述组通信发现响应消息中包含有所述ProSe应用的标识信息和所述第二UE的身份信息;接收所述第一UE所发送的组通信发现接受消息,其中所述组通信发现接受消息中包含有所述ProSe应用的标识信息和所述ProSe通信组的组标识信息;当基于所述ProSe应用的标识信息和所述ProSe通信组的组标识信息加入所述ProSe通信组时向所述第一UE发送组通信发现完成消息。
可选地,处理器1110还用于执行以下操作:
接收所述第一UE所发送的密钥更新通知消息;基于所述密钥更新通知消息向所述密钥管理功能实体发送第二组通信密钥更新请求消息;接收所述密钥管理功能实体在确定所述第二UE为所述ProSe通信组的组成员时所发送的更新后的组通信密钥。
上述实施例能够实现第二UE侧的所有步骤并能够达到相同的技术效果,在此不再进行赘述。
需要说明的是,本申请实施例中对单元的划分是示意性的,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式。另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个处理器可读取存储介质中。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)或处理器(processor)执行本申请各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、磁碟或者光盘等各种可以存储程序代码的介质。
在此需要说明的是,本申请实施例提供的上述装置,能够实现上述方 法实施例所实现的所有方法步骤,且能够达到相同的技术效果,在此不再对本实施例中与方法实施例相同的部分及有益效果进行具体赘述。
另一方面,本申请实施例还提供一种处理器可读存储介质,所述处理器可读存储介质存储有计算机程序,所述计算机程序用于使所述处理器执行上述实施例中所述的方法并能达到相同的技术效果,在此不再进行赘述。
所述处理器可读存储介质可以是处理器能够存取的任何可用介质或数据存储设备,包括但不限于磁性存储器(例如软盘、硬盘、磁带、磁光盘(MO)等)、光学存储器(例如CD、DVD、BD、HVD等)、和半导体存储器(例如ROM、EPROM、EEPROM、非易失性存储器(NAND FLASH)、固态硬盘(SSD))等。
由上述实施例可见,处理器可读存储介质存储有计算机程序,所述计算机程序用于使所述处理器执行上述ProSe通信组的通信方法。
本领域内的技术人员应明白,本申请的实施例可提供为方法、系统、或计算机程序产品。因此,本申请可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本申请可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器和光学存储器等)上实施的计算机程序产品的形式。
本申请是参照根据本申请实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机可执行指令实现流程图和/或方框图中的每一流程和/或方框、和流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机可执行指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。
这些处理器可执行指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的处理器可读存储器中,使得存储在该处理器可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。
这些处理器可执行指令也可装载到计算机或其他可编程数据处理设 备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。
显然,本领域的技术人员可以对本申请进行各种改动和变型而不脱离本申请的精神和范围。这样,倘若本申请的这些修改和变型属于本申请权利要求及其等同技术的范围之内,则本申请也意图包含这些改动和变型在内。

Claims (40)

  1. 一种ProSe通信组的通信方法,应用于密钥管理功能实体,其特征在于,包括:
    接收第一用户设备UE通过应用服务器建立近距离服务ProSe应用下的ProSe通信组时所发送的第一组通信密钥请求消息,其中所述第一组通信密钥请求消息中包含有第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息;
    当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述第一授权令牌时,基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥;
    当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息时,基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
    向所述第一UE发送第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
    其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
    所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
  2. 根据权利要求1所述的ProSe通信组的通信方法,其特征在于,所述基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权,包括:
    向所述应用服务器发送第一授权请求消息,其中所述第一授权请求消息中包含有所述第一UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息,以使所述应用服务器基于所述第一UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息确定所述第一UE是否属于所述ProSe通信组;
    接收所述应用服务器在确定所述第一UE属于所述ProSe通信组时所发送的第一授权响应消息,其中所述第一授权响应消息中包含有所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息。
  3. 根据权利要求1所述的ProSe通信组的通信方法,其特征在于,还包括:
    接收第二UE在加入所述ProSe通信组时所发送的第二组通信密钥请求消息,其中所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述应用服务器为所述第二UE所颁发的第二授权令牌,或者所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息;
    当所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述第二授权令牌时,基于所述第二UE的身份信息和所述第二授权令牌获取所述ProSe通信组的组通信密钥;
    当所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息时,基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权并获取所述ProSe通信组的组通信密钥;
    向所述第二UE发送第二组通信密钥响应消息,其中所述第二组通信密钥响应消息中包含有所述组通信密钥;
    其中,所述第二授权令牌中包括:所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息,且所述第二UE的角色信息为组成员。
  4. 根据权利要求3所述的ProSe通信组的通信方法,其特征在于,所述基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权,包括:
    向所述应用服务器发送第二授权请求消息,其中所述第二授权请求消息中包含有所述第二UE的身份信息、所述ProSe通信组的组标识信息和 所述ProSe应用的标识信息,以使所述应用服务器基于所述第二UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息确定所述第二UE是否属于所述ProSe通信组;
    接收所述应用服务器在确定所述第二UE属于所述ProSe通信组时所发送的第二授权响应消息,其中所述第二授权响应消息中包含有所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息。
  5. 根据权利要求1所述的ProSe通信组的通信方法,其特征在于,还包括:
    接收所述第一UE所发送的第一组通信密钥更新请求消息,其中所述第一组通信密钥更新请求消息中包含有所述ProSe通信组的组成员列表;
    基于所述第一组通信密钥更新请求消息向所述第一UE发送更新后的组通信密钥;
    接收第二UE所发送的第二组通信密钥更新请求消息,并在基于所述组成员列表确定所述第二UE为所述ProSe通信组的组成员时,向所述第二UE发送更新后的组通信密钥。
  6. 一种ProSe通信组的通信方法,应用于第一用户设备UE,其特征在于,包括:
    当第一UE通过应用服务器建立一近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第一组通信密钥请求消息;其中所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
    接收所述密钥管理功能实体所发送的第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
    基于所述组通信密钥与后续加入所述ProSe通信组的组成员进行通信;
    其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
    所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
  7. 根据权利要求6所述的ProSe通信组的通信方法,其特征在于,所述第一UE通过应用服务器建立一近距离服务ProSe应用下的ProSe通信组,包括:
    当所述第一UE需要在所述ProSe应用下建立ProSe通信组时,向所述应用服务器发送组通信建立请求,其中所述组通信建立请求中包含有所述第一UE的身份信息和所述ProSe应用的标识信息;
    接收所述应用服务器基于所述组通信建立请求所发送的组通信建立响应消息,其中所述组通信建立响应消息中包含有所建立的ProSe通信组的属性信息,或者包含有所建立的ProSe通信组的属性信息和所述第一授权令牌。
  8. 根据权利要求6所述的ProSe通信组的通信方法,其特征在于,还包括:
    通过广播方式发送组通信发现请求消息,所述组通信发现请求消息中包含有所述ProSe应用的标识信息和所述第一UE的身份信息;
    接收第二UE基于所述组通信发现请求消息所发送的组通信发现响应消息,其中所述组通信发现响应消息中包含有所述ProSe应用的标识信息和所述第二UE的身份信息;
    向所述第二UE发送组通信发现接受消息,其中所述组通信发现接受消息中包含有所述ProSe应用的标识信息和所述ProSe通信组的组标识信息,以使所述第二UE基于所述ProSe应用的标识信息和所述ProSe通信组的组标识信息加入所述ProSe通信组;
    接收所述第二UE在加入所述ProSe通信组后所发送的组通信发现完成消息。
  9. 根据权利要求6所述的ProSe通信组的通信方法,其特征在于,还包括:
    向所述密钥管理功能实体发送第一组通信密钥更新请求消息,其中所述第一组通信密钥更新请求消息中包含有所述ProSe通信组的组成员列表;
    接收所述密钥管理功能实体基于所述第一组通信密钥更新请求消息所发送的更新后的组通信密钥;
    向所述ProSe通信组的组成员发送密钥更新通知消息,以使所述ProSe通信组的组成员更新组通信密钥。
  10. 一种ProSe通信组的通信方法,应用于第二用户设备UE,其特征在于,包括:
    当第二UE加入第一UE所建立的近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第二组通信密钥请求消息;其中所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和应用服务器为所述第二UE所颁发的第二授权令牌,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述第二授权令牌获取所述ProSe通信组的组通信密钥,或者所述组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权并获取所述ProSe通信组的组通信密钥;
    接收所述密钥管理功能实体所发送的第二组通信密钥响应消息,其中所述第二组通信密钥响应消息中包含有所述组通信密钥;
    基于所述组通信密钥与所述ProSe通信组中的成员进行通信;
    其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
    所述第二授权令牌中包括:所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息,且所述第二UE的角色信息为组成员。
  11. 根据权利要求10所述的ProSe通信组的通信方法,其特征在于,所述第二UE加入第一UE所建立的近距离服务ProSe应用下的ProSe通 信组,包括:
    向所述应用服务器发送组通信加入请求,其中所述组通信加入请求中包含有所述第二UE的身份信息、ProSe应用的标识信息和所述ProSe通信组的标识信息;
    接收所述应用服务器基于所述组通信加入请求所发送的组通信加入响应消息,其中所述组通信加入响应消息中包含有所述ProSe通信组的属性信息,或者包含有所述ProSe通信组的属性信息和所述第二授权令牌。
  12. 根据权利要求10所述的ProSe通信组的通信方法,其特征在于,还包括:
    接收所述第一UE通过广播方式所发送的组通信发现请求消息,所述组通信发现请求消息中包含有所述ProSe应用的标识信息和所述第一UE的身份信息;
    基于所述组通信发现请求消息向所述第一UE发送组通信发现响应消息,其中所述组通信发现响应消息中包含有所述ProSe应用的标识信息和所述第二UE的身份信息;
    接收所述第一UE所发送的组通信发现接受消息,其中所述组通信发现接受消息中包含有所述ProSe应用的标识信息和所述ProSe通信组的组标识信息;
    当基于所述ProSe应用的标识信息和所述ProSe通信组的组标识信息加入所述ProSe通信组时向所述第一UE发送组通信发现完成消息。
  13. 根据权利要求10所述的ProSe通信组的通信方法,其特征在于,还包括:
    接收所述第一UE所发送的密钥更新通知消息;
    基于所述密钥更新通知消息向所述密钥管理功能实体发送第二组通信密钥更新请求消息;
    接收所述密钥管理功能实体在确定所述第二UE为所述ProSe通信组的组成员时所发送的更新后的组通信密钥。
  14. 一种ProSe通信组的通信装置,其特征在于,包括存储器,收发机,处理器:
    存储器,用于存储计算机程序;收发机,用于在所述处理器的控制下 收发数据;处理器,用于读取所述存储器中的计算机程序并执行以下操作:
    接收第一用户设备UE通过应用服务器建立近距离服务ProSe应用下的ProSe通信组时所发送的第一组通信密钥请求消息,其中所述第一组通信密钥请求消息中包含有第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息;
    当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述第一授权令牌时,基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥;
    当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息时,基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
    向所述第一UE发送第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
    其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
    所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
  15. 根据权利要求14所述的ProSe通信组的通信装置,其特征在于,所述基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权,包括:
    向所述应用服务器发送第一授权请求消息,其中所述第一授权请求消息中包含有所述第一UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息,以使所述应用服务器基于所述第一UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息确定所述第一UE是否属于所述ProSe通信组;
    接收所述应用服务器在确定所述第一UE属于所述ProSe通信组时所发送的第一授权响应消息,其中所述第一授权响应消息中包含有所述第一 UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息。
  16. 根据权利要求14所述的ProSe通信组的通信装置,其特征在于,还包括:
    接收第二UE在加入所述ProSe通信组时所发送的第二组通信密钥请求消息,其中所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述应用服务器为所述第二UE所颁发的第二授权令牌,或者所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息;
    当所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述第二授权令牌时,基于所述第二UE的身份信息和所述第二授权令牌获取所述ProSe通信组的组通信密钥;
    当所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息时,基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权并获取所述ProSe通信组的组通信密钥;
    向所述第二UE发送第二组通信密钥响应消息,其中所述第二组通信密钥响应消息中包含有所述组通信密钥;
    其中,所述第二授权令牌中包括:所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息,且所述第二UE的角色信息为组成员。
  17. 根据权利要求16所述的ProSe通信组的通信装置,其特征在于,所述基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权,包括:
    向所述应用服务器发送第二授权请求消息,其中所述第二授权请求消息中包含有所述第二UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息,以使所述应用服务器基于所述第二UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息确 定所述第二UE是否属于所述ProSe通信组;
    接收所述应用服务器在确定所述第二UE属于所述ProSe通信组时所发送的第二授权响应消息,其中所述第二授权响应消息中包含有所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息。
  18. 根据权利要求14所述的ProSe通信组的通信装置,其特征在于,还包括:
    接收所述第一UE所发送的第一组通信密钥更新请求消息,其中所述第一组通信密钥更新请求消息中包含有所述ProSe通信组的组成员列表;
    基于所述第一组通信密钥更新请求消息向所述第一UE发送更新后的组通信密钥;
    接收第二UE所发送的第二组通信密钥更新请求消息,并在基于所述组成员列表确定所述第二UE为所述ProSe通信组的组成员时,向所述第二UE发送更新后的组通信密钥。
  19. 一种ProSe通信组的通信装置,其特征在于,包括存储器,收发机,处理器:
    存储器,用于存储计算机程序;收发机,用于在所述处理器的控制下收发数据;处理器,用于读取所述存储器中的计算机程序并执行以下操作:
    当第一UE通过应用服务器建立一近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第一组通信密钥请求消息;其中所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
    接收所述密钥管理功能实体所发送的第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
    基于所述组通信密钥与后续加入所述ProSe通信组的组成员进行通信;
    其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
    所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
  20. 根据权利要求19所述的ProSe通信组的通信装置,其特征在于,所述第一UE通过应用服务器建立一近距离服务ProSe应用下的ProSe通信组,包括:
    当所述第一UE需要在所述ProSe应用下建立ProSe通信组时,向所述应用服务器发送组通信建立请求,其中所述组通信建立请求中包含有所述第一UE的身份信息和所述ProSe应用的标识信息;
    接收所述应用服务器基于所述组通信建立请求所发送的组通信建立响应消息,其中所述组通信建立响应消息中包含有所建立的ProSe通信组的属性信息,或者包含有所建立的ProSe通信组的属性信息和所述第一授权令牌。
  21. 根据权利要求19所述的ProSe通信组的通信装置,其特征在于,还包括:
    通过广播方式发送组通信发现请求消息,所述组通信发现请求消息中包含有所述ProSe应用的标识信息和所述第一UE的身份信息;
    接收第二UE基于所述组通信发现请求消息所发送的组通信发现响应消息,其中所述组通信发现响应消息中包含有所述ProSe应用的标识信息和所述第二UE的身份信息;
    向所述第二UE发送组通信发现接受消息,其中所述组通信发现接受消息中包含有所述ProSe应用的标识信息和所述ProSe通信组的组标识信息,以使所述第二UE基于所述ProSe应用的标识信息和所述ProSe通信组的组标识信息加入所述ProSe通信组;
    接收所述第二UE在加入所述ProSe通信组后所发送的组通信发现完成消息。
  22. 根据权利要求19所述的ProSe通信组的通信装置,其特征在于,还包括:
    向所述密钥管理功能实体发送第一组通信密钥更新请求消息,其中所述第一组通信密钥更新请求消息中包含有所述ProSe通信组的组成员列表;
    接收所述密钥管理功能实体基于所述第一组通信密钥更新请求消息所发送的更新后的组通信密钥;
    向所述ProSe通信组的组成员发送密钥更新通知消息,以使所述ProSe通信组的组成员更新组通信密钥。
  23. 一种ProSe通信组的通信装置,其特征在于,包括存储器,收发机,处理器:
    存储器,用于存储计算机程序;收发机,用于在所述处理器的控制下收发数据;处理器,用于读取所述存储器中的计算机程序并执行以下操作:
    当第二UE加入第一UE所建立的近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第二组通信密钥请求消息;其中所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和应用服务器为所述第二UE所颁发的第二授权令牌,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述第二授权令牌获取所述ProSe通信组的组通信密钥,或者所述组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权并获取所述ProSe通信组的组通信密钥;
    接收所述密钥管理功能实体所发送的第二组通信密钥响应消息,其中所述第二组通信密钥响应消息中包含有所述组通信密钥;
    基于所述组通信密钥与所述ProSe通信组中的成员进行通信;
    其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
    所述第二授权令牌中包括:所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息,且所述第二UE的角色信息为组成员。
  24. 根据权利要求23所述的ProSe通信组的通信装置,其特征在于,所述第二UE加入第一UE所建立的近距离服务ProSe应用下的ProSe通信组,包括:
    向所述应用服务器发送组通信加入请求,其中所述组通信加入请求中包含有所述第二UE的身份信息、ProSe应用的标识信息和所述ProSe通信组的标识信息;
    接收所述应用服务器基于所述组通信加入请求所发送的组通信加入响应消息,其中所述组通信加入响应消息中包含有所述ProSe通信组的属性信息,或者包含有所述ProSe通信组的属性信息和所述第二授权令牌。
  25. 根据权利要求23所述的ProSe通信组的通信装置,其特征在于,还包括:
    接收所述第一UE通过广播方式所发送的组通信发现请求消息,所述组通信发现请求消息中包含有所述ProSe应用的标识信息和所述第一UE的身份信息;
    基于所述组通信发现请求消息向所述第一UE发送组通信发现响应消息,其中所述组通信发现响应消息中包含有所述ProSe应用的标识信息和所述第二UE的身份信息;
    接收所述第一UE所发送的组通信发现接受消息,其中所述组通信发现接受消息中包含有所述ProSe应用的标识信息和所述ProSe通信组的组标识信息;
    当基于所述ProSe应用的标识信息和所述ProSe通信组的组标识信息加入所述ProSe通信组时向所述第一UE发送组通信发现完成消息。
  26. 根据权利要求23所述的ProSe通信组的通信装置,其特征在于,还包括:
    接收所述第一UE所发送的密钥更新通知消息;
    基于所述密钥更新通知消息向所述密钥管理功能实体发送第二组通信密钥更新请求消息;
    接收所述密钥管理功能实体在确定所述第二UE为所述ProSe通信组的组成员时所发送的更新后的组通信密钥。
  27. 一种ProSe通信组的通信装置,应用于密钥管理功能实体,其特 征在于,包括:
    接收模块,用于接收第一用户设备UE通过应用服务器建立近距离服务ProSe应用下的ProSe通信组时所发送的第一组通信密钥请求消息,其中所述第一组通信密钥请求消息中包含有第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息;
    第一生成模块,用于当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述第一授权令牌时,基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥;
    第二生成模块,用于当所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息时,基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
    发送模块,用于向所述第一UE发送第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
    其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
    所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
  28. 根据权利要求27所述的ProSe通信组的通信装置,其特征在于,所述第二生成模块具体用于:
    向所述应用服务器发送第一授权请求消息,其中所述第一授权请求消息中包含有所述第一UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息,以使所述应用服务器基于所述第一UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息确定所述第一UE是否属于所述ProSe通信组;
    接收所述应用服务器在确定所述第一UE属于所述ProSe通信组时所 发送的第一授权响应消息,其中所述第一授权响应消息中包含有所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息。
  29. 根据权利要求27所述的ProSe通信组的通信装置,其特征在于,所述接收模块还用于:接收第二UE在加入所述ProSe通信组时所发送的第二组通信密钥请求消息,其中所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述应用服务器为所述第二UE所颁发的第二授权令牌,或者所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息;
    所述第一生成模块还用于:当所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述第二授权令牌时,基于所述第二UE的身份信息和所述第二授权令牌获取所述ProSe通信组的组通信密钥;
    所述第二生成模块还用于:当所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息时,基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权并获取所述ProSe通信组的组通信密钥;
    所述发送模块还用于:向所述第二UE发送第二组通信密钥响应消息,其中所述第二组通信密钥响应消息中包含有所述组通信密钥;
    其中,所述第二授权令牌中包括:所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息,且所述第二UE的角色信息为组成员。
  30. 根据权利要求29所述的ProSe通信组的通信装置,其特征在于,所述第二生成模块还用于:
    向所述应用服务器发送第二授权请求消息,其中所述第二授权请求消息中包含有所述第二UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息,以使所述应用服务器基于所述第二UE的身份信息、所述ProSe通信组的组标识信息和所述ProSe应用的标识信息确定所述第二UE是否属于所述ProSe通信组;
    接收所述应用服务器在确定所述第二UE属于所述ProSe通信组时所发送的第二授权响应消息,其中所述第二授权响应消息中包含有所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息。
  31. 根据权利要求27所述的ProSe通信组的通信装置,其特征在于,还包括密钥更新模块,用于:
    接收所述第一UE所发送的第一组通信密钥更新请求消息,其中所述第一组通信密钥更新请求消息中包含有所述ProSe通信组的组成员列表;
    基于所述第一组通信密钥更新请求消息向所述第一UE发送更新后的组通信密钥;
    接收第二UE所发送的第二组通信密钥更新请求消息,并在基于所述组成员列表确定所述第二UE为所述ProSe通信组的组成员时,向所述第二UE发送更新后的组通信密钥。
  32. 一种ProSe通信组的通信装置,应用于第一用户设备UE,其特征在于,包括:
    发送模块,用于当第一UE通过应用服务器建立一近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第一组通信密钥请求消息;其中所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述应用服务器为所述第一UE所颁发的第一授权令牌,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述第一授权令牌生成组通信密钥,或者所述第一组通信密钥请求消息中包含有所述第一UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第一UE的身份信息和所述属性信息从所述应用服务器中得到密钥生成授权并生成组通信密钥;
    接收模块,用于接收所述密钥管理功能实体所发送的第一组通信密钥响应消息,其中所述第一组通信密钥响应消息中包含有所述组通信密钥;
    通信模块,用于基于所述组通信密钥与后续加入所述ProSe通信组的组成员进行通信;
    其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标 识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
    所述第一授权令牌中包括:所述第一UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第一UE在所述ProSe通信组中的角色信息,且所述第一UE的角色信息为组管理员。
  33. 根据权利要求32所述的ProSe通信组的通信装置,其特征在于,所述第一UE通过应用服务器建立一近距离服务ProSe应用下的ProSe通信组,包括:
    当所述第一UE需要在所述ProSe应用下建立ProSe通信组时,向所述应用服务器发送组通信建立请求,其中所述组通信建立请求中包含有所述第一UE的身份信息和所述ProSe应用的标识信息;
    接收所述应用服务器基于所述组通信建立请求所发送的组通信建立响应消息,其中所述组通信建立响应消息中包含有所建立的ProSe通信组的属性信息,或者包含有所建立的ProSe通信组的属性信息和所述第一授权令牌。
  34. 根据权利要求32所述的ProSe通信组的通信装置,其特征在于,还包括终端发现模块,用于:
    通过广播方式发送组通信发现请求消息,所述组通信发现请求消息中包含有所述ProSe应用的标识信息和所述第一UE的身份信息;接收第二UE基于所述组通信发现请求消息所发送的组通信发现响应消息,其中所述组通信发现响应消息中包含有所述ProSe应用的标识信息和所述第二UE的身份信息;
    向所述第二UE发送组通信发现接受消息,其中所述组通信发现接受消息中包含有所述ProSe应用的标识信息和所述ProSe通信组的组标识信息,以使所述第二UE基于所述ProSe应用的标识信息和所述ProSe通信组的组标识信息加入所述ProSe通信组;接收所述第二UE在加入所述ProSe通信组后所发送的组通信发现完成消息。
  35. 根据权利要求32所述的ProSe通信组的通信装置,其特征在于,还包括密钥更新模块,用于:
    向所述密钥管理功能实体发送第一组通信密钥更新请求消息,其中所 述第一组通信密钥更新请求消息中包含有所述ProSe通信组的组成员列表;
    接收所述密钥管理功能实体基于所述第一组通信密钥更新请求消息所发送的更新后的组通信密钥;
    向所述ProSe通信组的组成员发送密钥更新通知消息,以使所述ProSe通信组的组成员更新组通信密钥。
  36. 一种ProSe通信组的通信装置,应用于第二用户设备UE,其特征在于,包括:
    发送模块,用于当第二UE加入第一UE所建立的近距离服务ProSe应用下的ProSe通信组时,向密钥管理功能实体发送第二组通信密钥请求消息;其中所述第二组通信密钥请求消息中包含有所述第二UE的身份信息和应用服务器为所述第二UE所颁发的第二授权令牌,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述第二授权令牌获取所述ProSe通信组的组通信密钥,或者所述组通信密钥请求消息中包含有所述第二UE的身份信息和所述ProSe通信组的属性信息,以使所述密钥管理功能实体基于所述第二UE的身份信息和所述属性信息从所述应用服务器中得到密钥颁发授权并获取所述ProSe通信组的组通信密钥;
    接收模块,用于接收所述密钥管理功能实体所发送的第二组通信密钥响应消息,其中所述第二组通信密钥响应消息中包含有所述组通信密钥;
    通信模块,用于基于所述组通信密钥与所述ProSe通信组中的成员进行通信;
    其中,所述ProSe通信组的属性信息包括:所述ProSe通信组的组标识信息、所述ProSe应用的标识信息和所述ProSe通信组的有效期信息;
    所述第二授权令牌中包括:所述第二UE的身份信息、所述ProSe通信组的组标识信息、所述ProSe应用的标识信息、所述ProSe通信组的有效期信息和所述第二UE在所述ProSe通信组中的角色信息,且所述第二UE的角色信息为组成员。
  37. 根据权利要求36所述的ProSe通信组的通信装置,其特征在于,所述第二UE加入第一UE所建立的近距离服务ProSe应用下的ProSe通信组,包括:
    向所述应用服务器发送组通信加入请求,其中所述组通信加入请求中 包含有所述第二UE的身份信息、ProSe应用的标识信息和所述ProSe通信组的标识信息;
    接收所述应用服务器基于所述组通信加入请求所发送的组通信加入响应消息,其中所述组通信加入响应消息中包含有所述ProSe通信组的属性信息,或者包含有所述ProSe通信组的属性信息和所述第二授权令牌。
  38. 根据权利要求36所述的ProSe通信组的通信装置,其特征在于,还包括终端加入模块,用于:
    接收所述第一UE通过广播方式所发送的组通信发现请求消息,所述组通信发现请求消息中包含有所述ProSe应用的标识信息和所述第一UE的身份信息;基于所述组通信发现请求消息向所述第一UE发送组通信发发现响应消息,其中所述组通信发现响应消息中包含有所述ProSe应用的标识信息和所述第二UE的身份信息;
    接收所述第一UE所发送的组通信发现接受消息,其中所述组通信发现接受消息中包含有所述ProSe应用的标识信息和所述ProSe通信组的组标识信息;当基于所述ProSe应用的标识信息和所述ProSe通信组的组标识信息加入所述ProSe通信组时向所述第一UE发送组通信发现完成消息。
  39. 根据权利要求36所述的ProSe通信组的通信装置,其特征在于,还包括密钥更新模块,用于:
    接收所述第一UE所发送的密钥更新通知消息;
    基于所述密钥更新通知消息向所述密钥管理功能实体发送第二组通信密钥更新请求消息;
    接收所述密钥管理功能实体在确定所述第二UE为所述ProSe通信组的组成员时所发送的更新后的组通信密钥。
  40. 一种处理器可读存储介质,其特征在于,所述处理器可读存储介质存储有计算机程序,所述计算机程序用于使处理器执行权利要求1至5任一项所述的ProSe通信组的通信方法,或执行权利要求6至9任一项所述的ProSe通信组的通信方法,或执行权利要求10至13任一项所述的ProSe通信组的通信方法。
PCT/CN2021/114506 2020-09-29 2021-08-25 ProSe通信组的通信方法、装置及存储介质 WO2022068474A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202011052580.0A CN114339622B (zh) 2020-09-29 2020-09-29 一种ProSe通信组的通信方法、装置及存储介质
CN202011052580.0 2020-09-29

Publications (1)

Publication Number Publication Date
WO2022068474A1 true WO2022068474A1 (zh) 2022-04-07

Family

ID=80949603

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/114506 WO2022068474A1 (zh) 2020-09-29 2021-08-25 ProSe通信组的通信方法、装置及存储介质

Country Status (2)

Country Link
CN (1) CN114339622B (zh)
WO (1) WO2022068474A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114866964B (zh) * 2022-04-13 2024-02-23 中国电信股份有限公司 基于邻近服务的消息传输方法、装置、电子设备及介质
WO2024065334A1 (zh) * 2022-09-28 2024-04-04 北京小米移动软件有限公司 一种用户设备ue的授权令牌的生成方法/装置/设备及存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105025478A (zh) * 2014-04-30 2015-11-04 中兴通讯股份有限公司 D2D通信安全配置方法、ProSe密钥管理功能实体、终端及系统
US20160219437A1 (en) * 2013-10-11 2016-07-28 Samsung Electronics Co., Ltd. Method and system for supporting security and information for proximity based service in mobile communication system environment
CN106162618A (zh) * 2015-04-23 2016-11-23 中兴通讯股份有限公司 一种d2d业务组播的认证方法、装置和系统
WO2018164552A1 (ko) * 2017-03-10 2018-09-13 엘지전자(주) 무선 통신 시스템에서 릴레이를 통한 데이터 송수신 방법 및 이를 위한 장치

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20160149876A1 (en) * 2013-06-28 2016-05-26 Nec Corporation Security for prose group communication
KR102100159B1 (ko) * 2014-01-13 2020-04-13 삼성전자 주식회사 이동 통신 시스템에서 서비스 발견 및 그룹 통신을 위한 보안 지원 방법 및 시스템
KR102088848B1 (ko) * 2014-01-13 2020-03-13 삼성전자 주식회사 이동 통신에서 ProSe그룹 통신 또는 공공 안전을 지원하기 위한 보안 방안 및 시스템
WO2016021981A1 (en) * 2014-08-08 2016-02-11 Samsung Electronics Co., Ltd. System and method of counter management and security key update for device-to-device group communication
BR112018003168A2 (pt) * 2015-08-17 2018-09-25 Telefonaktiebolaget Lm Ericsson (Publ) métodos e aparelho para estabelecimento de chave de comunicação direta
WO2019051776A1 (zh) * 2017-09-15 2019-03-21 华为技术有限公司 密钥的传输方法及设备

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20160219437A1 (en) * 2013-10-11 2016-07-28 Samsung Electronics Co., Ltd. Method and system for supporting security and information for proximity based service in mobile communication system environment
CN105025478A (zh) * 2014-04-30 2015-11-04 中兴通讯股份有限公司 D2D通信安全配置方法、ProSe密钥管理功能实体、终端及系统
CN106162618A (zh) * 2015-04-23 2016-11-23 中兴通讯股份有限公司 一种d2d业务组播的认证方法、装置和系统
WO2018164552A1 (ko) * 2017-03-10 2018-09-13 엘지전자(주) 무선 통신 시스템에서 릴레이를 통한 데이터 송수신 방법 및 이를 위한 장치

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
"3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Proximity-based Services (ProSe); Security aspects (Release 15)", 3GPP STANDARD; TECHNICAL SPECIFICATION; 3GPP TS 33.303, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG3, no. V15.0.0, 22 June 2018 (2018-06-22), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , pages 1 - 90, XP051473401 *
HUAWEI, HISILICON: "Security for PrSe UE communication in group owner mode", 3GPP DRAFT; S3-130973- SECURITY FOR PROSE COMMUNICATIONS IN GROUP OWNER MODE, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG3, no. San Francisco; 20131111 - 20131115, 12 November 2013 (2013-11-12), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP050745005 *

Also Published As

Publication number Publication date
CN114339622A (zh) 2022-04-12
CN114339622B (zh) 2022-09-23

Similar Documents

Publication Publication Date Title
US11296877B2 (en) Discovery method and apparatus based on service-based architecture
US11956361B2 (en) Network function service invocation method, apparatus, and system
US20230076628A1 (en) Network security management method, and apparatus
CN111670587B (zh) 用于多个注册的方法和设备
US11496320B2 (en) Registration method and apparatus based on service-based architecture
WO2021037175A1 (zh) 一种网络切片的管理方法及相关装置
WO2022170994A1 (zh) Pc5根密钥处理方法、装置、ausf及远程终端
WO2022068474A1 (zh) ProSe通信组的通信方法、装置及存储介质
WO2009030164A1 (fr) Procédé, système et dispositif pour empêcher l'attaque par dégradation pendant qu'un terminal se déplace
CN113541925B (zh) 通信系统、方法及装置
US20230188997A1 (en) Secure communication method and apparatus
US20230096402A1 (en) Service obtaining method and apparatus, and communication device and readable storage medium
WO2013152740A1 (zh) 用户设备的认证方法、装置及系统
US20240089728A1 (en) Communication method and apparatus
WO2018170703A1 (zh) 一种连接建立方法及装置
WO2022027505A1 (en) User equipment authentication and authorization procedure for edge data network
JP2021524167A (ja) 複数の登録のための方法および装置
WO2023011107A1 (zh) 会话策略控制方法、网元、存储介质和电子设备
WO2016197630A1 (zh) 一种无线接入方法及路由装置
WO2024021580A1 (zh) 用户终端接入网络的安全认证方法、装置及电子设备
WO2017101627A1 (zh) 一种内容访问控制方法及相关设备
WO2022147838A1 (zh) 无线通信的方法和装置
US20230354028A1 (en) Method, system, and apparatus for generating key for inter-device communication
US20230231708A1 (en) Method and apparatus for multiple registrations
WO2023016451A1 (zh) 更新方法、网络侧设备、终端和计算机可读存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21874135

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 21874135

Country of ref document: EP

Kind code of ref document: A1