WO2022104617A1 - Communication method, apparatus and system - Google Patents

Communication method, apparatus and system Download PDF

Info

Publication number
WO2022104617A1
WO2022104617A1 PCT/CN2020/129914 CN2020129914W WO2022104617A1 WO 2022104617 A1 WO2022104617 A1 WO 2022104617A1 CN 2020129914 W CN2020129914 W CN 2020129914W WO 2022104617 A1 WO2022104617 A1 WO 2022104617A1
Authority
WO
WIPO (PCT)
Prior art keywords
user plane
security protection
session
plane security
terminal device
Prior art date
Application number
PCT/CN2020/129914
Other languages
French (fr)
Chinese (zh)
Inventor
雷骜
李�赫
吴义壮
吴�荣
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN202080107200.0A priority Critical patent/CN116671235A/en
Priority to PCT/CN2020/129914 priority patent/WO2022104617A1/en
Publication of WO2022104617A1 publication Critical patent/WO2022104617A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04BTRANSMISSION
    • H04B7/00Radio transmission systems, i.e. using radiation field
    • H04B7/14Relay systems
    • H04B7/15Active relay systems
    • H04B7/185Space-based or airborne stations; Stations for satellite systems
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup

Abstract

Embodiments of the present application provide a communication method, apparatus and system, for use in solving the problem that the consistency of the user plane security of C2 communication between a UAV and a UAVC cannot be guaranteed at present. The method comprises: a management device obtains a first user plane security protection enabling indication, the first user plane security protection enabling indication being used for indicating whether the user plane security protection of a first session is enabled, the first session being a session used by a first terminal device to carry C2 communication, the first terminal device being an initiating end device of the C2 communication, a second terminal device being a peer end device of the C2 communication, and the C2 communication being communication between the first terminal device and the second terminal device; and the management device triggers the second terminal device to initiate establishment of a second session, whether the user plane security protection of the second session is enabled being determined by the first user plane security protection enabling indication, and the second session being a session used by the second terminal device to carry the C2 communication.

Description

通信方法、装置及系统Communication method, device and system 技术领域technical field
本申请涉及通信技术领域,尤其涉及通信方法、装置及系统。The present application relates to the field of communication technologies, and in particular, to a communication method, device, and system.
背景技术Background technique
在目前第五代(5th generation,5G)无线通信网络使能无人机系统的讨论中,一个无人机系统(unmanned aerial system,UAS)包括一个无人机(unmanned aerial vehicle,UAV)和一个无人机控制器(UAV controller,UAVC)。UAV和UAVC之间通过命令与控制(command and control,C2)通信建立流程建立UAV用于承载C2通信的第一协议数据单元(protocol data unit,PDU)会话以及UAVC用于承载C2通信的第二PDU会话,UAS交通管理(UAS traffic management,UTM)/UAS服务供应商(UAS service supplier,USS)将第一PDU会话与第二PDU会话进行关联以实现UAV与UAVC之间的C2通信。当然,若UAV和UAVC中的其中一个已有用于承载UAS的非C2通信的PDU会话,则为其服务的会话管理功能(session management function,SMF)可对该用于承载UAS的非C2通信的PDU会话进行修改以满足C2通信的条件。In the current discussion of 5th generation (5G) wireless communication network-enabled unmanned aerial systems, an unmanned aerial system (UAS) includes an unmanned aerial vehicle (UAV) and an unmanned aerial vehicle (UAV) Unmanned aerial vehicle controller (UAV controller, UAVC). A first protocol data unit (PDU) session used by UAV to carry C2 communication and a second session of UAVC used to carry C2 communication are established between UAV and UAVC through a command and control (C2) communication establishment process In the PDU session, the UAS traffic management (UAS traffic management, UTM)/UAS service provider (UAS service supplier, USS) associates the first PDU session with the second PDU session to implement C2 communication between the UAV and the UAVC. Of course, if one of the UAV and UAVC already has a PDU session used for the non-C2 communication carrying the UAS, the session management function (SMF) serving it can be used for the non-C2 communication carrying the UAS. The PDU session is modified to meet the conditions of C2 communication.
目前的标准讨论中,暂未讨论UAV和UAVC之间的C2通信建立流程的安全问题。这样在UAVC对UAV进行飞行控制的场景中,将可能导致UAV段的用于C2通信的用户面安全保护开启方式与UAVC段的用于C2通信的用户面安全保护开启方式不一致。进而,在C2通信需要保证一定程度的安全性能的场景下,攻击者可以通过未开启安全保护的一端去干扰整条UAV和UAVC之间的C2通信,从而降低C2通信的安全性;或者,在C2通信需要保证传输效率的场景下,开启安全保护的一端会影响整条C2的传输效率。综上,如何保证UAV和UAVC之间的C2通信的用户面安全的一致性,是目前亟待解决的问题。In the current standard discussion, the security issue of the C2 communication establishment process between UAV and UAVC has not been discussed yet. In this way, in the scenario where the UAVC performs flight control on the UAV, the user plane security protection mode of the UAV segment for C2 communication may be inconsistent with the user plane security protection mode of the UAVC segment for C2 communication. Furthermore, in the scenario where the C2 communication needs to ensure a certain degree of security performance, the attacker can interfere with the C2 communication between the entire UAV and UAVC through the end without security protection, thereby reducing the security of the C2 communication; In the scenario where the C2 communication needs to ensure the transmission efficiency, the end with the security protection turned on will affect the transmission efficiency of the entire C2. In conclusion, how to ensure the consistency of user plane security of C2 communication between UAV and UAVC is an urgent problem to be solved at present.
发明内容SUMMARY OF THE INVENTION
本申请实施例提供通信方法、装置及系统,用于解决目前无法保证UAV和UAVC之间的C2通信的用户面安全的一致性的问题。The embodiments of the present application provide a communication method, apparatus and system, which are used to solve the problem that the consistency of user plane security of C2 communication between UAV and UAVC cannot be guaranteed at present.
为达到上述目的,本申请的实施例采用如下技术方案:To achieve the above object, the embodiments of the present application adopt the following technical solutions:
第一方面,提供了一种通信方法,执行该通信方法的通信装置可以为管理设备也可以为应用于管理设备中的模块,例如芯片或芯片系统。下面以执行主体为管理设备为例进行描述。管理设备获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,该第一会话为第一终端设备用于承载C2通信的会话,该第一终端设备为该C2通信的发起端设备,第二终端设备为该C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信;管理设备触发该第二终端设备发起第二会话的建立,其中,该第二会话的用户面安全保护是否开启由该第一用户面安全保护开启指示确定,该第二会话为该第二终端设备用于承载该C2通信的会话。该方案中,管理设备可以获取第一用户面安全保护开启指示,并触发第二终端设备发起第二会话的建立。其中,第二会话的用户面安全 保护是否开启由第一用户面安全保护开启指示确定,同时第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。换言之,第一会话的用户面安全保护是否开启以及第二会话的用户面安全保护是否开启均是由第一用户面安全保护开启指示确定的。由于第一会话为第一终端设备用于承载C2通信的会话,第二会话为第二终端设备用于承载C2通信的会话,该C2通信为第一终端设备与第二终端设备之间的通信,因此基于该方案,可以保证第一终端设备和第二终端设备之间的C2通信的用户面安全保护的一致性。In a first aspect, a communication method is provided, and a communication apparatus for executing the communication method may be a management device or a module applied in the management device, such as a chip or a chip system. The following description takes the execution subject as the management device as an example. The management device acquires a first user plane security protection enable instruction, where the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled; wherein the first session is the first terminal device used to bear the C2 communication session, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device; management The device triggers the second terminal device to initiate the establishment of a second session, wherein whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction, and the second session is used by the second terminal device. in the session that carries the C2 communication. In this solution, the management device may acquire the first user plane security protection opening instruction, and trigger the second terminal device to initiate the establishment of the second session. Wherein, whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled. In other words, whether the user plane security protection of the first session is enabled and whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction. Since the first session is a session used by the first terminal device to carry C2 communication, and the second session is a session used by the second terminal device to carry C2 communication, the C2 communication is the communication between the first terminal device and the second terminal device , so based on this solution, the consistency of user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
需要说明的是,本申请实施例中,第一用户面安全保护开启指示也可以理解为第一用户面安全保护开启结果指示。第一用户面安全保护开启结果指示例如可以包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示。其中,第一用户面机密性保护开启结果指示用于指示用户面机密性保护开启或不开启;第一用户面完整性保护开启结果指示用于指示用户面完整性保护开启或不开启。该说明适用于本申请所有实施例,在此统一说明,以下不再赘述。It should be noted that, in this embodiment of the present application, the first user plane security protection activation indication may also be understood as an indication of the first user plane security protection activation result. The first user plane security protection enabling result indication may include, for example, a first user plane confidentiality protection enabling result indication and a first user plane integrity protection enabling result indication. Wherein, the first user plane confidentiality protection enable result indication is used to indicate whether the user plane confidentiality protection is enabled or not; the first user plane integrity protection enable result indication is used to indicate whether the user plane integrity protection is enabled or disabled. This description is applicable to all the embodiments of the present application, and is uniformly described here, and will not be repeated below.
结合上述第一方面,在一种可能的实现方式中,管理设备触发该第二终端设备发起第二会话的建立,包括:管理设备向该第二终端设备发送第一消息,该第一消息用于触发该第二终端设备发起该第二会话的建立;以及,该管理设备向第二统一数据管理实体发送该第一用户面安全保护开启指示,其中,该第二统一数据管理实体是为该第二终端设备服务的统一数据管理实体。基于该方案,为第二终端设备服务的第二统一数据管理实体可以从管理设备获取第一用户面安全保护开启指示。进一步的,在第二会话的建立流程中,为第二终端设备服务的第二会话管理实体可以从第二统一数据管理实体获取第一用户面安全保护开启指示。其中,第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启。With reference to the above first aspect, in a possible implementation manner, the management device triggering the second terminal device to initiate the establishment of the second session includes: the management device sends a first message to the second terminal device, the first message using triggering the second terminal device to initiate the establishment of the second session; and, the management device sending the first user plane security protection opening instruction to a second unified data management entity, wherein the second unified data management entity is for the The unified data management entity served by the second terminal device. Based on this solution, the second unified data management entity serving the second terminal device can obtain the first user plane security protection opening instruction from the management device. Further, in the process of establishing the second session, the second session management entity serving the second terminal device may acquire the first user plane security protection enabling instruction from the second unified data management entity. The first user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled.
结合上述第一方面,在一种可能的实现方式中,管理设备触发该第二终端设备发起第二会话的建立,包括:管理设备向该第二终端设备发送第一消息,该第一消息用于触发该第二终端设备发起第二会话的建立;以及,该管理设备接收来自第二代理功能实体的第二消息,并向该第二代理功能实体发送该第一用户面安全保护开启指示;其中,该第二消息包括该第二终端设备的标识信息,该第二消息用于请求该第一用户面安全保护开启指示,该第二代理功能实体用于提供第二会话管理实体到该管理设备的接口,该第二会话管理实体是为该第二终端设备服务的会话管理实体。基于该方案,为第二终端设备服务的第二会话管理实体可以通过第二代理功能实体从管理设备获取第一用户面安全保护开启指示。其中,第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启。With reference to the above first aspect, in a possible implementation manner, the management device triggering the second terminal device to initiate the establishment of the second session includes: the management device sends a first message to the second terminal device, the first message using triggering the second terminal device to initiate the establishment of the second session; and the management device receives the second message from the second proxy function entity, and sends the first user plane security protection opening instruction to the second proxy function entity; Wherein, the second message includes the identification information of the second terminal device, the second message is used to request the first user plane security protection opening instruction, and the second proxy function entity is used to provide the second session management entity to the management The interface of the device, the second session management entity is a session management entity serving the second terminal device. Based on this solution, the second session management entity serving the second terminal device can obtain the first user plane security protection opening instruction from the management device through the second proxy function entity. The first user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled.
结合上述第一方面,在一种可能的实现方式中,管理设备获取第一用户面安全保护开启指示,包括:管理设备接收来自第一会话管理实体的该第一用户面安全保护开启指示,该第一会话管理实体是为该第一终端设备服务的会话管理实体。即,管理设备可以通过第一终端设备与管理设备之间的控制面获取第一用户面安全保护开启指示。With reference to the above-mentioned first aspect, in a possible implementation manner, obtaining the first user plane security protection enable instruction by the management device includes: the management device receiving the first user plane security protection enable instruction from the first session management entity, the The first session management entity is a session management entity serving the first terminal device. That is, the management device may obtain the first user plane security protection opening instruction through the control plane between the first terminal device and the management device.
结合上述第一方面,在一种可能的实现方式中,管理设备获取第一用户面安全保护开启指示,包括:管理设备接收来自该第一终端设备的该第一用户面安全保护开启指示。即,管理设备可以通过第一终端设备与管理设备之间的用户面获取第一用户面 安全保护开启指示。With reference to the above first aspect, in a possible implementation manner, acquiring the first user plane security protection opening instruction by the management device includes: the management device receiving the first user plane security protection opening instruction from the first terminal device. That is, the management device may obtain the first user plane security protection opening instruction through the user plane between the first terminal device and the management device.
结合上述第一方面,在一种可能的实现方式中,管理设备获取第一用户面安全保护开启指示,包括:管理设备接收来自第一代理功能实体的该第一用户面安全保护开启指示,该第一代理功能实体用于提供该第一会话管理实体到该管理设备的接口。即,管理设备可以从用于提供该第一会话管理实体到该管理设备的接口的第一代理功能实体获取第一用户面安全保护开启指示。With reference to the above-mentioned first aspect, in a possible implementation manner, obtaining the first user plane security protection opening instruction by the management device includes: the management device receiving the first user plane security protection opening instruction from the first proxy function entity, the The first proxy function entity is used to provide an interface from the first session management entity to the management device. That is, the management device may acquire the first user plane security protection opening instruction from the first proxy function entity for providing the interface of the first session management entity to the management device.
结合上述第一方面,在一种可能的实现方式中,管理设备获取第一用户面安全保护开启指示,包括:管理设备确定该第一终端设备与该第二终端设备配对授权成功;管理设备向第一代理功能实体发送第三消息,该第三消息包括该第一终端设备的标识信息,该第三消息用于请求该第一用户面安全保护开启指示;其中,该第一代理功能实体用于提供第一会话管理实体到该管理设备的接口,该第一会话管理实体是为该第一终端设备服务的会话管理实体;管理设备接收来自该第一代理功能实体的该第一用户面安全保护开启指示。即,管理设备可以基于配对授权流程的触发通过用于提供第一会话管理实体到该管理设备的接口的第一代理功能实体获取第一用户面安全保护开启指示。With reference to the above-mentioned first aspect, in a possible implementation manner, obtaining the first user plane security protection opening instruction by the management device includes: the management device determines that the pairing authorization between the first terminal device and the second terminal device is successful; The first proxy function entity sends a third message, where the third message includes the identification information of the first terminal device, and the third message is used to request the first user plane security protection opening instruction; wherein, the first proxy function entity uses for providing an interface from a first session management entity to the management device, where the first session management entity is a session management entity serving the first terminal device; the management device receives the first user plane security information from the first proxy function entity Protection on indication. That is, the management device may obtain the first user plane security protection opening instruction through the first proxy function entity for providing an interface of the first session management entity to the management device based on the triggering of the pairing authorization process.
第二方面,提供了一种通信方法,执行该通信方法的通信装置可以为第一会话管理实体也可以为应用于第一会话管理实体中的模块,例如芯片或芯片系统。下面以执行主体为第一会话管理实体为例进行描述。第一会话管理实体获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,该第一会话为第一终端设备用于承载C2通信的会话,该第一终端设备为该C2通信的发起端设备,第二终端设备为该C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信,该第一会话管理实体是为该第一终端设备服务的会话管理实体;第一会话管理实体发送该第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,该第二会话为该第二终端设备用于承载该C2通信的会话。该方案中,第一会话管理实体获取第一用户面安全保护开启指示,并发送第一用户面安全保护开启指示。其中,第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,同时第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。换言之,第一会话的用户面安全保护是否开启以及第二会话的用户面安全保护是否开启均是由第一用户面安全保护开启指示确定的。由于第一会话为第一终端设备用于承载C2通信的会话,第二会话为第二终端设备用于承载该C2通信的会话,该C2通信为第一终端设备与第二终端设备之间的通信,因此基于该方案,可以保证第一终端设备和第二终端设备之间的C2通信的用户面安全保护的一致性。In a second aspect, a communication method is provided, and a communication device executing the communication method may be a first session management entity or a module applied in the first session management entity, such as a chip or a chip system. The following description will be given by taking the execution subject as the first session management entity as an example. The first session management entity obtains a first user plane security protection opening instruction, and the first user plane security protection opening instruction is used to indicate whether the user plane security protection of the first session is enabled; wherein, the first session is used by the first terminal device. In a session carrying C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device. communication, the first session management entity is a session management entity serving the first terminal device; the first session management entity sends the first user plane security protection opening instruction, and the first user plane security protection opening instruction is used to determine the first Whether the user plane security protection of the second session is enabled, the second session is the session used by the second terminal device to carry the C2 communication. In this solution, the first session management entity acquires the first user plane security protection opening instruction, and sends the first user plane security protection opening instruction. The first user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled. In other words, whether the user plane security protection of the first session is enabled and whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction. Since the first session is a session used by the first terminal device to carry the C2 communication, the second session is a session used by the second terminal device to carry the C2 communication, and the C2 communication is a session between the first terminal device and the second terminal device. Therefore, based on this solution, the consistency of user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
结合上述第二方面,在一种可能的实现方式中,第一会话管理实体发送该第一用户面安全保护开启指示,包括:第一会话管理实体向管理设备发送该第一用户面安全保护开启指示。With reference to the above second aspect, in a possible implementation manner, sending the first user plane security protection opening instruction by the first session management entity includes: the first session management entity sending the first user plane security protection opening instruction to the management device instruct.
结合上述第二方面,在一种可能的实现方式中,该第一会话管理实体发送该第一用户面安全保护开启指示,包括:第一会话管理实体向第一代理功能实体发送该第一用户面安全保护开启指示;其中,该第一代理功能实体用于提供该第一会话管理实体 到该管理设备的接口。With reference to the above second aspect, in a possible implementation manner, sending the first user plane security protection enabling instruction by the first session management entity includes: the first session management entity sending the first user plane to the first proxy function entity A face security protection opening instruction; wherein, the first proxy function entity is used to provide an interface from the first session management entity to the management device.
结合上述第二方面,在一种可能的实现方式中,在第一会话管理实体向第一代理功能实体发送该第一用户面安全保护开启指示之前,该方法还包括:第一会话管理实体接收来自该第一代理功能实体的第四消息,该第四消息包括该第一终端设备的标识信息,该第四消息用于请求该第一用户面安全保护开启指示。With reference to the above second aspect, in a possible implementation manner, before the first session management entity sends the first user plane security protection opening instruction to the first proxy function entity, the method further includes: the first session management entity receives A fourth message from the first proxy function entity, where the fourth message includes identification information of the first terminal device, and the fourth message is used to request the first user plane security protection opening instruction.
结合上述第二方面,在一种可能的实现方式中,第一会话管理实体获取第一用户面安全保护开启指示,包括:第一会话管理实体从为该第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;第一会话管理实体向为该第一终端设备服务的第一接入网设备发送该第一用户面安全保护策略;第一会话管理实体接收来自该第一接入网设备的第一用户面安全保护开启指示,其中,第一用户面安全保护开启指示是根据第一用户面安全保护策略确定的。比如,当第一用户面安全保护策略为可选开启安全保护时,第一接入网设备可以根据第一用户面安全保护策略(可以结合其他信息,如第一接入网设备上资源的使用情况或第一终端设备可以支持的最大完整性保护速率),确定第一用户面安全保护开启指示并将第一用户面安全保护开启指示发送给第一会话管理实体。一种可能的实施例是,第一用户面安全保护策略包括用户面机密性保护为可选开启(PREFERRED)以及用户面完整性保护为可选开启;第一接入网设备当前比较空闲,有足够的资源为第一终端设备的用户面数据提供安全保护,则第一接入网设备可以开启用户面机密性保护和用户面完整性保护,并且向第一会话管理实体发送第一用户面安全保护开启指示,此时第一用户面安全保护开启指示用于指示开启用户面机密性保护和开启用户面完整性保护。With reference to the above-mentioned second aspect, in a possible implementation manner, the first session management entity obtains the first user plane security protection opening instruction, including: the first session management entity obtains the first unified data serving the first terminal device from the first unified data The management entity obtains the first user plane security protection policy; the first session management entity sends the first user plane security protection policy to the first access network device serving the first terminal device; the first session management entity receives information from the first user plane security protection policy; A first user plane security protection opening instruction of an access network device, wherein the first user plane security protection enabling instruction is determined according to a first user plane security protection policy. For example, when the first user plane security protection policy is optional to enable security protection, the first access network device can use the first user plane security protection policy (which may be combined with other information, such as the use of resources on the first access network device) situation or the maximum integrity protection rate that the first terminal device can support), determine the first user plane security protection enable instruction and send the first user plane security protection enable instruction to the first session management entity. A possible embodiment is that the first user plane security protection policy includes that the user plane confidentiality protection is optionally enabled (PREFERRED) and the user plane integrity protection is optionally enabled; the first access network device is currently idle, and there are If there are enough resources to provide security protection for the user plane data of the first terminal device, the first access network device can enable user plane confidentiality protection and user plane integrity protection, and send the first user plane security to the first session management entity. The protection enable instruction, at this time, the first user plane security protection enable instruction is used to instruct to enable the user plane confidentiality protection and the user plane integrity protection.
结合上述第二方面,在一种可能的实现方式中,第一会话管理实体获取第一用户面安全保护开启指示,包括:第一会话管理实体从为该第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;第一会话管理实体向为该第一终端设备服务的第一接入网设备发送该第一用户面安全保护策略;第一会话管理实体接收来自第一接入网设备的第七消息,第七消息用于指示第一接入网设备已经根据第一用户面安全保护策略建立第一会话;响应于第七消息,第一会话管理实体根据该第一用户面安全保护策略确定该第一用户面安全保护开启指示。比如,当第一用户面安全保护策略包括用户面机密性保护为强制开启(REQUIRED)/强制不开启(NOT NEEDED)以及用户面完整性保护为强制开启/强制不开启时,则当第一会话管理实体收到来自第一接入网设备的第七消息时,就可以根据第一用户面安全保护策略准确的确定用户面机密性保护和用户面完整性保护是否开启。例如第一用户面安全保护策略包括用户面机密性保护为强制开启以及用户面完整性保护为强制开启,则确定开启用户面机密性保护和开启用户面完整性保护。又例如,第一用户面安全保护策略包括用户面机密性保护为强制不开启以及用户面完整性保护为强制不开启,则确定不开启用户面机密性保护和不开启用户面完整性保护。其他情况类似,不再赘述。换句话说,第一用户面安全保护策略是确定性策略(例如用户面机密性保护为强制开启/强制不开启以及用户面完整性保护为强制开启/强制不开启)时,第一接入网设备可以不用明确的通知第一会话管理实体用户面安全的开启结果。当第一会话管理实体在确定会话已经建立的情况下,可以根据第一用户面安全保护策略自己确定用户面机密性保护和用户面完整性保 护是否开启。With reference to the above-mentioned second aspect, in a possible implementation manner, the first session management entity obtains the first user plane security protection opening instruction, including: the first session management entity obtains the first unified data serving the first terminal device from the first unified data The management entity obtains the first user plane security protection policy; the first session management entity sends the first user plane security protection policy to the first access network device serving the first terminal device; the first session management entity receives the The seventh message of the access network device, the seventh message is used to indicate that the first access network device has established the first session according to the first user plane security protection policy; in response to the seventh message, the first session management entity The user plane security protection policy determines the first user plane security protection opening instruction. For example, when the first user plane security protection policy includes that the user plane confidentiality protection is forcibly turned on (REQUIRED)/forcibly not turned on (NOT NEEDED) and the user plane integrity protection is forcibly turned on/forcibly not turned on, then when the first session When the management entity receives the seventh message from the first access network device, it can accurately determine whether user plane confidentiality protection and user plane integrity protection are enabled according to the first user plane security protection policy. For example, the first user plane security protection policy includes that the user plane confidentiality protection is forcibly turned on and the user plane integrity protection is forcibly turned on, and it is determined that the user plane confidentiality protection and the user plane integrity protection are turned on. For another example, if the first user plane security protection policy includes that the user plane confidentiality protection is forcibly disabled and the user plane integrity protection is forcibly disabled, it is determined that the user plane confidentiality protection and the user plane integrity protection are not enabled. Other situations are similar and will not be repeated here. In other words, when the first user plane security protection policy is a deterministic policy (for example, the user plane confidentiality protection is forcibly turned on/forcibly turned off and the user plane integrity protection is forcibly turned on/forcibly turned off), the first access network The device may not explicitly notify the first session management entity of the result of enabling user plane security. When the first session management entity determines that the session has been established, it can determine whether the user plane confidentiality protection and the user plane integrity protection are enabled according to the first user plane security protection policy.
第三方面,提供了一种通信方法,执行该通信方法的通信装置可以为第二会话管理实体也可以为应用于第二会话管理实体中的模块,例如芯片或芯片系统。下面以执行主体为第二会话管理实体为例进行描述。第二会话管理实体获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,该第一会话为第一终端设备用于承载C2通信的会话,该第一终端设备为该C2通信的发起端设备,第二终端设备为该C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信,该第二会话管理实体是为该第二终端设备服务的会话管理实体;第二会话管理实体向为该第二终端设备服务的第二接入网设备发送该第一用户面安全保护开启指示;其中,该第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,该第二会话为该第二终端设备用于承载该C2通信的会话。该方案中,第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,同时第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。换言之,第一会话的用户面安全保护是否开启以及第二会话的用户面安全保护是否开启均是由第一用户面安全保护开启指示确定的。由于第一会话为第一终端设备用于承载C2通信的会话,第二会话为第二终端设备用于承载该C2通信的会话,该C2通信为第一终端设备与第二终端设备之间的通信,因此基于该方案,可以保证第一终端设备和第二终端设备之间的C2通信的用户面安全保护的一致性。In a third aspect, a communication method is provided, and a communication device executing the communication method may be a second session management entity or a module applied in the second session management entity, such as a chip or a chip system. The following description will be given by taking the execution subject as the second session management entity as an example. The second session management entity obtains the first user plane security protection enable instruction, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled; wherein, the first session is used by the first terminal device In a session carrying C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device. communication, the second session management entity is a session management entity serving the second terminal device; the second session management entity sends the first user plane security protection enable to the second access network device serving the second terminal device wherein, the first user plane security protection opening instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is a session used by the second terminal device to carry the C2 communication. In this solution, the first user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled. In other words, whether the user plane security protection of the first session is enabled and whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction. Since the first session is a session used by the first terminal device to carry the C2 communication, the second session is a session used by the second terminal device to carry the C2 communication, and the C2 communication is a session between the first terminal device and the second terminal device. Therefore, based on this solution, the consistency of user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
第四方面,提供了一种通信方法,执行该通信方法的通信装置可以为第二会话管理实体也可以为应用于第二会话管理实体中的模块,例如芯片或芯片系统。下面以执行主体为第二会话管理实体为例进行描述。第二会话管理实体获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,该第一会话为第一终端设备用于承载C2通信的会话,该第一终端设备为该C2通信的发起端设备,第二终端设备为该C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信,该第二会话管理实体是为该第二终端设备服务的会话管理实体;第二会话管理实体根据该第一用户面安全保护开启指示确定第三用户面安全保护策略,该第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护;第二会话管理实体向为该第二终端设备服务的第二接入网设备发送该第三用户面安全保护策略;其中,该第三用户面安全保护策略用于确定第二用户面安全保护开启指示,该第二用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,该第二会话为该第二终端设备用于承载该C2通信的会话。该方案中,第三用户面安全保护策略用于确定指示第二会话的用户面安全保护是否开启的第二用户面安全保护开启指示,而第三用户面安全保护策略是由指示第一会话的用户面安全保护是否开启的第一用户面安全保护开启指示确定的,且第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护。换言之,第一会话的用户面安全保护是否开启以及第二会话的用户面安全保护是否开启均是由第一用户面安全保护开启指示确定的。由于第一会话为第一终端设备用于承载C2通信的会话,第二会话为第二终端设备用于承载该C2通信的会话,该C2通信为第一终端设备与第二终端设备之间的通信,因此基于该方案,可以保证第一终端设备和第二终端设备之间的C2通信的 用户面安全保护的一致性。In a fourth aspect, a communication method is provided, and a communication device for executing the communication method may be a second session management entity or a module applied in the second session management entity, such as a chip or a chip system. The following description will be given by taking the execution subject as the second session management entity as an example. The second session management entity obtains the first user plane security protection enable instruction, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled; wherein, the first session is used by the first terminal device In a session carrying C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device. communication, the second session management entity is a session management entity serving the second terminal device; the second session management entity determines a third user plane security protection policy according to the first user plane security protection opening instruction, and the third user plane The security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection; the second session management entity sends the third user plane security protection policy to the second access network device serving the second terminal device; The three user plane security protection policy is used to determine the second user plane security protection enable instruction, and the second user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is the second terminal The session used by the device to carry this C2 communication. In this solution, the third user plane security protection policy is used to determine the second user plane security protection enable instruction indicating whether the user plane security protection of the second session is enabled, and the third user plane security protection policy is used to indicate the first session. Whether the user plane security protection is enabled is determined by the first user plane security protection enable instruction, and the third user plane security protection policy only includes forcibly enabling the security protection or forcibly not enabling the security protection. In other words, whether the user plane security protection of the first session is enabled and whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction. Since the first session is a session used by the first terminal device to carry the C2 communication, the second session is a session used by the second terminal device to carry the C2 communication, and the C2 communication is a session between the first terminal device and the second terminal device. Therefore, based on this solution, the consistency of user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
需要说明的是,本申请实施例中,第二用户面安全保护开启指示也可以理解为第二用户面安全保护开启结果指示。第二用户面安全保护开启结果指示例如可以包括第二用户面机密性保护开启结果指示和第二用户面完整性保护开启结果指示。其中,第二用户面机密性保护开启结果指示用于指示用户面机密性保护开启或不开启;第二用户面完整性保护开启结果指示用于指示用户面完整性保护开启或不开启。该说明适用于本申请所有实施例,在此统一说明,以下不再赘述。It should be noted that, in the embodiment of the present application, the indication of enabling the security protection of the second user plane may also be understood as an indication of the result of enabling the security protection of the second user plane. The second user plane security protection enabling result indication may include, for example, a second user plane confidentiality protection enabling result indication and a second user plane integrity protection enabling result indication. Wherein, the second user plane confidentiality protection enable result indication is used to indicate whether the user plane confidentiality protection is enabled or not; the second user plane integrity protection enable result indication is used to indicate whether the user plane integrity protection is enabled or disabled. This description is applicable to all the embodiments of the present application, and is uniformly described here, and will not be repeated below.
结合上述第四方面,在一种可能的实现方式中,第二会话管理实体根据该第一用户面安全保护开启指示确定第三用户面安全保护策略,包括:当第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示,且第一用户面机密性保护开启结果指示用于指示用户面机密性保护开启,第一用户面完整性保护开启结果指示用于指示用户面完整性保护开启时,第二会话管理实体确定第三用户面安全保护策略包括用户面机密性保护为强制开启且用户面完整性保护为强制开启;或者,当第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示,且第一用户面机密性保护开启结果指示用于指示用户面机密性保护不开启,第一用户面完整性保护开启结果指示用于指示用户面完整性保护不开启时,第二会话管理实体确定所述第三用户面安全保护策略包括用户面机密性保护强制不开启且用户面完整性保护强制不开启。当第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示,且第一用户面机密性保护开启结果指示用于指示用户面机密性保护不开启,第一用户面完整性保护开启结果指示用于指示用户面完整性保护开启时,第二会话管理实体确定第三用户面安全保护策略包括用户面机密性保护强制不开启且用户面完整性保护强制开启;或者,当第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示,且第一用户面机密性保护开启结果指示用于指示用户面机密性保护开启,第一用户面完整性保护开启结果指示用于指示用户面完整性保护不开启时,第二会话管理实体确定所述第三用户面安全保护策略包括用户面机密性保护强制开启且用户面完整性保护强制不开启。With reference to the above fourth aspect, in a possible implementation manner, the second session management entity determines a third user plane security protection policy according to the first user plane security protection enabling instruction, including: when the first user plane security protection enabling instruction It includes the first user plane confidentiality protection opening result indication and the first user plane integrity protection opening result indication, and the first user plane confidentiality protection opening result indication is used to indicate that the user plane confidentiality protection is turned on, and the first user plane integrity protection is turned on. When the protection enable result indication is used to indicate that the user plane integrity protection is enabled, the second session management entity determines that the third user plane security protection policy includes that the user plane confidentiality protection is forcibly enabled and the user plane integrity protection is forcibly enabled; or, when The first user plane security protection enable instruction includes a first user plane confidentiality protection enable result instruction and a first user plane integrity protection enable result instruction, and the first user plane confidentiality protection enable result instruction is used to indicate the user plane confidentiality protection If it is not enabled, the first user plane integrity protection enable result indication is used to indicate that the user plane integrity protection is not enabled, and the second session management entity determines that the third user plane security protection policy includes that the user plane confidentiality protection is forcibly disabled and User plane integrity protection is forcibly disabled. When the first user plane security protection enable indication includes the first user plane confidentiality protection enable result indication and the first user plane integrity protection enable result indication, and the first user plane confidentiality protection enable result indication is used to indicate the user plane confidentiality When the protection is not enabled, the first user plane integrity protection enable result indication is used to indicate that the user plane integrity protection is enabled, the second session management entity determines that the third user plane security protection policy includes that the user plane confidentiality protection is forcibly disabled and the user plane Integrity protection is forcibly turned on; or, when the first user plane security protection turning on instruction includes the first user plane confidentiality protection turning on result indication and the first user plane integrity protection turning on result indication, and the first user plane confidentiality protection turning on result The indication is used to indicate that the user plane confidentiality protection is turned on, and the first user plane integrity protection turn-on result indication is used to indicate that the user plane integrity protection is not turned on, and the second session management entity determines that the third user plane security protection policy includes the user Face confidentiality protection is forcibly turned on and user face integrity protection is forcibly turned off.
结合上述第三方面或第四方面,在一种可能的实现方式中,第二会话管理实体获取第一用户面安全保护开启指示,包括:第二会话管理实体向为该第二终端设备服务的第二统一数据管理实体发送第五消息,该第五消息包括该第二终端设备的标识信息,该第五消息用于请求第二用户面安全保护策略;第二会话管理实体接收来自该第二统一数据管理实体的该第二用户面安全保护策略和该第一用户面安全保护开启指示。即,第二会话管理实体可以从为第二终端设备服务的第二统一数据管理实体获取第一用户面安全保护开启指示。With reference to the third aspect or the fourth aspect, in a possible implementation manner, the second session management entity acquiring the first user plane security protection opening instruction includes: The second unified data management entity sends a fifth message, where the fifth message includes the identification information of the second terminal device, and the fifth message is used to request the second user plane security protection policy; the second session management entity receives information from the second terminal device. The second user plane security protection policy and the first user plane security protection opening instruction of the unified data management entity are unified. That is, the second session management entity may acquire the first user plane security protection opening instruction from the second unified data management entity serving the second terminal device.
结合上述第三方面或第四方面,在一种可能的实现方式中,第二会话管理实体获取第一用户面安全保护开启指示,包括:第二会话管理实体向第二代理功能实体发送第六消息,该第六消息包括该第二终端设备的标识信息,该第六消息用于请求该第一用户面安全保护开启指示,该第二代理功能实体用于提供该第二会话管理实体到管理设备的接口;第二会话管理实体接收来自该第二代理功能实体的该第一用户面安全保 护开启指示。即,第二会话管理实体可以通过用于提供第二会话管理实体到该管理设备的接口的第二代理功能实体从管理设备获取第一用户面安全保护开启指示。With reference to the above third aspect or the fourth aspect, in a possible implementation manner, the second session management entity acquiring the first user plane security protection enable instruction includes: the second session management entity sends a sixth to the second proxy function entity. message, the sixth message includes the identification information of the second terminal device, the sixth message is used to request the first user plane security protection opening instruction, and the second proxy function entity is used to provide the second session management entity to the management The interface of the device; the second session management entity receives the first user plane security protection opening instruction from the second proxy function entity. That is, the second session management entity may obtain the first user plane security protection opening instruction from the management device through the second proxy function entity for providing an interface of the second session management entity to the management device.
结合上述第三方面或第四方面,在一种可能的实现方式中,在第二会话管理实体向第二代理功能实体发送第六消息之前,该方法还包括:第二会话管理实体接收来自该第二终端设备的指示信息,该指示信息指示该第二终端设备请求建立的该第二会话用于响应该第一终端设备发起的该C2通信。即,第二会话管理实体可以在获知第二终端设备请求建立的该第二会话用于响应该第一终端设备发起的该C2通信之后,直接通过用于提供第二会话管理实体到该管理设备的接口的第二代理功能实体从管理设备获取第一用户面安全保护开启指示。With reference to the third aspect or the fourth aspect, in a possible implementation manner, before the second session management entity sends the sixth message to the second proxy function entity, the method further includes: the second session management entity receives a message from the second session management entity. Indication information of the second terminal device, where the indication information indicates that the second session requested by the second terminal device to be established is used in response to the C2 communication initiated by the first terminal device. That is, the second session management entity can directly provide the second session management entity to the management device after learning that the second session requested by the second terminal device is used to respond to the C2 communication initiated by the first terminal device. The second proxy function entity of the interface obtains the first user plane security protection opening instruction from the management device.
第五方面,提供了一种通信装置用于执行上述第一方面或第一方面的任一可能的实现方式中的方法。该通信装置可以为上述第一方面或第一方面的任一可能的实现方式中的管理设备,或者应用于管理设备中的模块,例如芯片或芯片系统。其中,该通信装置包括实现上述方法相应的模块、单元、或手段(means),该模块、单元、或means可以通过硬件实现,软件实现,或者通过硬件执行相应的软件实现。该硬件或软件包括一个或多个与上述功能相对应的模块或单元。In a fifth aspect, a communication apparatus is provided for performing the above-mentioned first aspect or the method in any possible implementation manner of the first aspect. The communication apparatus may be the management device in the first aspect or any possible implementation manner of the first aspect, or a module applied in the management device, such as a chip or a chip system. Wherein, the communication device includes corresponding modules, units, or means (means) for implementing the above method, and the modules, units, or means may be implemented by hardware, software, or by executing corresponding software in hardware. The hardware or software includes one or more modules or units corresponding to the above functions.
结合上述第五方面,在一种可能的实现方式中,通信装置包括处理模块和收发模块;该处理模块,用于获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,该第一会话为第一终端设备用于承载C2通信的会话,该第一终端设备为该C2通信的发起端设备,第二终端设备为该C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信;该收发模块,用于触发该第二终端设备发起第二会话的建立,其中,该第二会话的用户面安全保护是否开启由该第一用户面安全保护开启指示确定,该第二会话为该第二终端设备用于承载该C2通信的会话。With reference to the fifth aspect, in a possible implementation manner, the communication device includes a processing module and a transceiver module; the processing module is used to obtain the first user plane security protection opening instruction, and the first user plane security protection opening instruction is used for Indicates whether the user plane security protection of the first session is enabled; wherein, the first session is a session used by the first terminal device to carry the C2 communication, the first terminal device is the initiating end device of the C2 communication, and the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device; the transceiver module is used to trigger the second terminal device to initiate the establishment of a second session, wherein the first terminal device Whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction, and the second session is a session used by the second terminal device to carry the C2 communication.
结合上述第五方面,在一种可能的实现方式中,该收发模块,用于触发该第二终端设备发起第二会话的建立,包括:向该第二终端设备发送第一消息,该第一消息用于触发该第二终端设备发起该第二会话的建立;以及,向第二统一数据管理实体发送该第一用户面安全保护开启指示,其中,该第二统一数据管理实体是为该第二终端设备服务的统一数据管理实体。With reference to the fifth aspect, in a possible implementation manner, the transceiver module, configured to trigger the second terminal device to initiate the establishment of the second session, includes: sending a first message to the second terminal device, the first The message is used to trigger the second terminal device to initiate the establishment of the second session; and send the first user plane security protection opening instruction to the second unified data management entity, wherein the second unified data management entity is for the first unified data management entity. Two unified data management entities served by terminal equipment.
结合上述第五方面,在一种可能的实现方式中,该收发模块,用于触发该第二终端设备发起第二会话的建立,包括:向该第二终端设备发送第一消息,该第一消息用于触发该第二终端设备发起第二会话的建立;以及,接收来自第二代理功能实体的第二消息,并向该第二代理功能实体发送该第一用户面安全保护开启指示;其中,该第二消息包括该第二终端设备的标识信息,该第二消息用于请求该第一用户面安全保护开启指示,该第二代理功能实体用于提供第二会话管理实体到该管理设备的接口,该第二会话管理实体是为该第二终端设备服务的会话管理实体。With reference to the fifth aspect, in a possible implementation manner, the transceiver module, configured to trigger the second terminal device to initiate the establishment of the second session, includes: sending a first message to the second terminal device, the first The message is used to trigger the second terminal device to initiate the establishment of the second session; and, receiving the second message from the second proxy function entity, and sending the first user plane security protection opening indication to the second proxy function entity; wherein , the second message includes the identification information of the second terminal device, the second message is used to request the first user plane security protection opening instruction, and the second proxy function entity is used to provide the second session management entity to the management device interface, the second session management entity is a session management entity serving the second terminal device.
结合上述第五方面,在一种可能的实现方式中,该处理模块具体用于:通过该收发模块接收来自第一会话管理实体的该第一用户面安全保护开启指示,该第一会话管理实体是为该第一终端设备服务的会话管理实体;或者,通过该收发模块接收来自该第一终端设备的该第一用户面安全保护开启指示;或者,通过该收发模块接收来自第 一代理功能实体的该第一用户面安全保护开启指示,该第一代理功能实体用于提供该第一会话管理实体到该管理设备的接口。With reference to the above fifth aspect, in a possible implementation manner, the processing module is specifically configured to: receive, through the transceiver module, an instruction to enable the first user plane security protection from a first session management entity, and the first session management entity is a session management entity serving the first terminal device; or, receives the first user plane security protection opening instruction from the first terminal device through the transceiver module; or, receives from the first proxy function entity through the transceiver module The first user plane security protection opening instruction of the first proxy function entity is used to provide an interface from the first session management entity to the management device.
结合上述第五方面,在一种可能的实现方式中,该处理模块具体用于:确定该第一终端设备与该第二终端设备配对授权成功;通过该收发模块向第一代理功能实体发送第三消息,该第三消息包括该第一终端设备的标识信息,该第三消息用于请求该第一用户面安全保护开启指示;其中,该第一代理功能实体用于提供第一会话管理实体到该管理设备的接口,该第一会话管理实体是为该第一终端设备服务的会话管理实体;通过该收发模块接收来自该第一代理功能实体的该第一用户面安全保护开启指示。With reference to the fifth aspect, in a possible implementation manner, the processing module is specifically configured to: determine that the first terminal device and the second terminal device are paired and authorized successfully; send the first proxy function entity through the transceiver module Three messages, the third message includes the identification information of the first terminal device, and the third message is used to request the first user plane security protection opening indication; wherein, the first proxy function entity is used to provide the first session management entity An interface to the management device, where the first session management entity is a session management entity serving the first terminal device; receiving the first user plane security protection opening instruction from the first proxy function entity through the transceiver module.
结合上述第五方面,在一种可能的实现方式中,通信装置包括处理器和收发器;该处理器,用于获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,该第一会话为第一终端设备用于承载C2通信的会话,该第一终端设备为该C2通信的发起端设备,第二终端设备为该C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信;该收发器,用于触发该第二终端设备发起第二会话的建立,其中,该第二会话的用户面安全保护是否开启由该第一用户面安全保护开启指示确定,该第二会话为该第二终端设备用于承载该C2通信的会话。With reference to the fifth aspect, in a possible implementation manner, the communication device includes a processor and a transceiver; the processor is used to obtain a first user plane security protection opening instruction, and the first user plane security protection opening instruction is used for Indicates whether the user plane security protection of the first session is enabled; wherein, the first session is a session used by the first terminal device to carry the C2 communication, the first terminal device is the initiating end device of the C2 communication, and the second terminal device is the peer device of the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device; the transceiver is used to trigger the second terminal device to initiate the establishment of the second session, wherein the first terminal device Whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction, and the second session is a session used by the second terminal device to carry the C2 communication.
结合上述第五方面,在一种可能的实现方式中,该收发器,用于触发该第二终端设备发起第二会话的建立,包括:向该第二终端设备发送第一消息,该第一消息用于触发该第二终端设备发起该第二会话的建立;以及,向第二统一数据管理实体发送该第一用户面安全保护开启指示,其中,该第二统一数据管理实体是为该第二终端设备服务的统一数据管理实体。With reference to the fifth aspect, in a possible implementation manner, the transceiver, configured to trigger the second terminal device to initiate the establishment of the second session, includes: sending a first message to the second terminal device, the first The message is used to trigger the second terminal device to initiate the establishment of the second session; and send the first user plane security protection opening instruction to the second unified data management entity, wherein the second unified data management entity is for the first unified data management entity. Two unified data management entities served by terminal equipment.
结合上述第五方面,在一种可能的实现方式中,该收发器,用于触发该第二终端设备发起第二会话的建立,包括:向该第二终端设备发送第一消息,该第一消息用于触发该第二终端设备发起第二会话的建立;以及,接收来自第二代理功能实体的第二消息,并向该第二代理功能实体发送该第一用户面安全保护开启指示;其中,该第二消息包括该第二终端设备的标识信息,该第二消息用于请求该第一用户面安全保护开启指示,该第二代理功能实体用于提供第二会话管理实体到该管理设备的接口,该第二会话管理实体是为该第二终端设备服务的会话管理实体。With reference to the fifth aspect, in a possible implementation manner, the transceiver, configured to trigger the second terminal device to initiate the establishment of the second session, includes: sending a first message to the second terminal device, the first The message is used to trigger the second terminal device to initiate the establishment of the second session; and, receiving the second message from the second proxy function entity, and sending the first user plane security protection opening indication to the second proxy function entity; wherein , the second message includes the identification information of the second terminal device, the second message is used to request the first user plane security protection opening instruction, and the second proxy function entity is used to provide the second session management entity to the management device interface, the second session management entity is a session management entity serving the second terminal device.
结合上述第五方面,在一种可能的实现方式中,该处理器具体用于:通过该收发器接收来自第一会话管理实体的该第一用户面安全保护开启指示,该第一会话管理实体是为该第一终端设备服务的会话管理实体;或者,通过该收发器接收来自该第一终端设备的该第一用户面安全保护开启指示;或者,通过该收发器接收来自第一代理功能实体的该第一用户面安全保护开启指示,该第一代理功能实体用于提供该第一会话管理实体到该管理设备的接口。With reference to the fifth aspect, in a possible implementation manner, the processor is specifically configured to: receive, through the transceiver, an instruction to enable the first user plane security protection from a first session management entity, and the first session management entity is a session management entity serving the first terminal device; or, receiving the first user plane security protection opening instruction from the first terminal device through the transceiver; or, receiving through the transceiver from the first proxy function entity The first user plane security protection opening instruction of the first proxy function entity is used to provide an interface from the first session management entity to the management device.
结合上述第五方面,在一种可能的实现方式中,该处理器具体用于:确定该第一终端设备与该第二终端设备配对授权成功;通过该收发器向第一代理功能实体发送第三消息,该第三消息包括该第一终端设备的标识信息,该第三消息用于请求该第一用户面安全保护开启指示;其中,该第一代理功能实体用于提供第一会话管理实体到该管理设备的接口,该第一会话管理实体是为该第一终端设备服务的会话管理实体;通 过该收发器接收来自该第一代理功能实体的该第一用户面安全保护开启指示。With reference to the fifth aspect, in a possible implementation manner, the processor is specifically configured to: determine that the first terminal device and the second terminal device are paired and authorized successfully; send the first proxy function entity through the transceiver Three messages, the third message includes the identification information of the first terminal device, and the third message is used to request the first user plane security protection opening indication; wherein, the first proxy function entity is used to provide the first session management entity An interface to the management device, the first session management entity is a session management entity serving the first terminal device; the transceiver receives the first user plane security protection opening instruction from the first proxy function entity through the transceiver.
其中,上述第五方面或第五方面的任一可能的实现方式的技术效果可参考上述第一方面,在此不再赘述。For the technical effect of the fifth aspect or any possible implementation manner of the fifth aspect, reference may be made to the first aspect, which will not be repeated here.
第六方面,提供了一种通信装置用于执行上述第二方面或第二方面的任一可能的实现方式中的方法。该通信装置可以为上述第二方面或第二方面的任一可能的实现方式中的第一会话管理实体,或者应用于第一会话管理实体中的模块,例如芯片或芯片系统。其中,该通信装置包括实现上述方法相应的模块、单元、或手段(means),该模块、单元、或means可以通过硬件实现,软件实现,或者通过硬件执行相应的软件实现。该硬件或软件包括一个或多个与上述功能相对应的模块或单元。In a sixth aspect, a communication apparatus is provided for performing the second aspect or the method in any possible implementation manner of the second aspect. The communication apparatus may be the first session management entity in the second aspect or any possible implementation manner of the second aspect, or a module applied in the first session management entity, such as a chip or a system of chips. Wherein, the communication device includes corresponding modules, units, or means (means) for implementing the above method, and the modules, units, or means may be implemented by hardware, software, or by executing corresponding software in hardware. The hardware or software includes one or more modules or units corresponding to the above functions.
结合上述第六方面,在一种可能的实现方式中,通信装置包括处理模块和收发模块;该处理模块,用于获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,该第一会话为第一终端设备用于承载C2通信的会话,该第一终端设备为该C2通信的发起端设备,第二终端设备为该C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信,该第一会话管理实体是为该第一终端设备服务的会话管理实体;该收发模块,用于发送该第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,该第二会话为该第二终端设备用于承载该C2通信的会话。With reference to the above sixth aspect, in a possible implementation manner, the communication device includes a processing module and a transceiver module; the processing module is used to obtain the first user plane security protection opening instruction, and the first user plane security protection opening instruction is used for Indicates whether the user plane security protection of the first session is enabled; wherein, the first session is a session used by the first terminal device to carry the C2 communication, the first terminal device is the initiating end device of the C2 communication, and the second terminal device is the peer device of the C2 communication, the C2 communication is the communication between the first terminal device and the second terminal device, and the first session management entity is a session management entity serving the first terminal device; the transceiver module, It is used to send the first user plane security protection opening instruction, and the first user plane security protection opening instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is used by the second terminal device to carry the Session for C2 communication.
结合上述第六方面,在一种可能的实现方式中,该收发模块具体用于:向管理设备发送该第一用户面安全保护开启指示。With reference to the sixth aspect, in a possible implementation manner, the transceiver module is specifically configured to: send the first user plane security protection opening instruction to the management device.
结合上述第六方面,在一种可能的实现方式中,该收发模块具体用于:向第一代理功能实体发送该第一用户面安全保护开启指示;其中,该第一代理功能实体用于提供该第一会话管理实体到该管理设备的接口。With reference to the above sixth aspect, in a possible implementation manner, the transceiver module is specifically configured to: send the first user plane security protection opening instruction to the first proxy function entity; wherein, the first proxy function entity is used to provide The interface of the first session management entity to the management device.
结合上述第六方面,在一种可能的实现方式中,该收发模块,还用于在该第一会话管理实体向第一代理功能实体发送该第一用户面安全保护开启指示之前,接收来自该第一代理功能实体的第四消息,该第四消息包括该第一终端设备的标识信息,该第四消息用于请求该第一用户面安全保护开启指示。With reference to the above sixth aspect, in a possible implementation manner, the transceiver module is further configured to receive a message from the first session management entity before the first session management entity sends the first user plane security protection opening instruction to the first proxy function entity. The fourth message of the first proxy function entity, where the fourth message includes the identification information of the first terminal device, and the fourth message is used to request the first user plane security protection opening instruction.
结合上述第六方面,在一种可能的实现方式中,该处理模块具体用于:从为该第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;通过该收发模块向为该第一终端设备服务的第一接入网设备发送该第一用户面安全保护策略;通过该收发模块接收来自该第一接入网设备的该第一用户面安全保护开启指示,其中,第一用户面安全保护开启指示是根据第一用户面安全保护策略确定的。With reference to the sixth aspect, in a possible implementation manner, the processing module is specifically configured to: obtain the first user plane security protection policy from the first unified data management entity serving the first terminal device; Send the first user plane security protection policy to the first access network device serving the first terminal device; receive the first user plane security protection opening instruction from the first access network device through the transceiver module, wherein , the first user plane security protection enabling instruction is determined according to the first user plane security protection policy.
结合上述第六方面,在一种可能的实现方式中,该处理模块具体用于:从为该第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;通过该收发模块向为该第一终端设备服务的第一接入网设备发送该第一用户面安全保护策略;通过该收发模块接收来自第一接入网设备的第七消息之后,响应于第七消息,根据第一用户面安全保护策略确定第一用户面安全保护开启指示,其中,第七消息用于指示第一接入网设备已经根据第一用户面安全保护策略建立第一会话。With reference to the sixth aspect, in a possible implementation manner, the processing module is specifically configured to: obtain the first user plane security protection policy from the first unified data management entity serving the first terminal device; Send the first user plane security protection policy to the first access network device serving the first terminal device; after receiving the seventh message from the first access network device through the transceiver module, in response to the seventh message, according to The first user plane security protection policy determines an indication that the first user plane security protection is enabled, wherein the seventh message is used to indicate that the first access network device has established the first session according to the first user plane security protection policy.
结合上述第六方面,在一种可能的实现方式中,通信装置包括处理器和收发器; 该处理器,用于获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,该第一会话为第一终端设备用于承载C2通信的会话,该第一终端设备为该C2通信的发起端设备,第二终端设备为该C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信,该第一会话管理实体是为该第一终端设备服务的会话管理实体;该收发器,用于发送该第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,该第二会话为该第二终端设备用于承载该C2通信的会话。With reference to the above sixth aspect, in a possible implementation manner, the communication device includes a processor and a transceiver; the processor is configured to obtain a first user plane security protection opening instruction, and the first user plane security protection opening instruction is used for Indicates whether the user plane security protection of the first session is enabled; wherein, the first session is a session used by the first terminal device to carry the C2 communication, the first terminal device is the initiating end device of the C2 communication, and the second terminal device is the opposite end device of the C2 communication, the C2 communication is the communication between the first terminal device and the second terminal device, and the first session management entity is a session management entity serving the first terminal device; the transceiver, It is used to send the first user plane security protection opening instruction, and the first user plane security protection opening instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is used by the second terminal device to carry the Session for C2 communication.
结合上述第六方面,在一种可能的实现方式中,该收发器具体用于:向管理设备发送该第一用户面安全保护开启指示。With reference to the above sixth aspect, in a possible implementation manner, the transceiver is specifically configured to: send the first user plane security protection opening indication to the management device.
结合上述第六方面,在一种可能的实现方式中,该收发器具体用于:向第一代理功能实体发送该第一用户面安全保护开启指示;其中,该第一代理功能实体用于提供该第一会话管理实体到该管理设备的接口。With reference to the above sixth aspect, in a possible implementation manner, the transceiver is specifically configured to: send the first user plane security protection opening instruction to the first proxy function entity; wherein the first proxy function entity is used to provide The interface of the first session management entity to the management device.
结合上述第六方面,在一种可能的实现方式中,该收发器,还用于在该第一会话管理实体向第一代理功能实体发送该第一用户面安全保护开启指示之前,接收来自该第一代理功能实体的第四消息,该第四消息包括该第一终端设备的标识信息,该第四消息用于请求该第一用户面安全保护开启指示。With reference to the above sixth aspect, in a possible implementation manner, the transceiver is further configured to receive a message from the first session management entity before the first session management entity sends the first user plane security protection opening instruction to the first proxy function entity The fourth message of the first proxy function entity, where the fourth message includes the identification information of the first terminal device, and the fourth message is used to request the first user plane security protection opening instruction.
结合上述第六方面,在一种可能的实现方式中,该处理器具体用于:从为该第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;通过该收发器向为该第一终端设备服务的第一接入网设备发送该第一用户面安全保护策略;通过该收发器接收来自该第一接入网设备的该第一用户面安全保护开启指示,其中,第一用户面安全保护开启指示是根据第一用户面安全保护策略确定的。With reference to the above sixth aspect, in a possible implementation manner, the processor is specifically configured to: obtain the first user plane security protection policy from the first unified data management entity serving the first terminal device; Sending the first user plane security protection policy to the first access network device serving the first terminal device; receiving the first user plane security protection opening instruction from the first access network device through the transceiver, wherein , the first user plane security protection enabling instruction is determined according to the first user plane security protection policy.
结合上述第六方面,在一种可能的实现方式中,该处理器具体用于:从为该第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;通过该收发器向为该第一终端设备服务的第一接入网设备发送该第一用户面安全保护策略;通过该收发器接收来自第一接入网设备的第七消息之后,响应于第七消息,根据第一用户面安全保护策略确定第一用户面安全保护开启指示,其中,第七消息用于指示第一接入网设备已经根据第一用户面安全保护策略建立第一会话。With reference to the above sixth aspect, in a possible implementation manner, the processor is specifically configured to: obtain the first user plane security protection policy from the first unified data management entity serving the first terminal device; Send the first user plane security protection policy to the first access network device serving the first terminal device; after receiving the seventh message from the first access network device through the transceiver, in response to the seventh message, according to The first user plane security protection policy determines an indication that the first user plane security protection is enabled, wherein the seventh message is used to indicate that the first access network device has established the first session according to the first user plane security protection policy.
其中,上述第六方面或第六方面的任一可能的实现方式的技术效果可参考上述第二方面,在此不再赘述。For the technical effect of the sixth aspect or any possible implementation manner of the sixth aspect, reference may be made to the second aspect, which will not be repeated here.
第七方面,提供了一种通信装置用于执行上述第三方面或第三方面的任一可能的实现方式中的方法。该通信装置可以为上述第三方面或第三方面的任一可能的实现方式中的第二会话管理实体,或者应用于第二会话管理实体中的模块,例如芯片或芯片系统。其中,该通信装置包括实现上述方法相应的模块、单元、或手段(means),该模块、单元、或means可以通过硬件实现,软件实现,或者通过硬件执行相应的软件实现。该硬件或软件包括一个或多个与上述功能相对应的模块或单元。In a seventh aspect, a communication apparatus is provided for performing the third aspect or the method in any possible implementation manner of the third aspect. The communication apparatus may be the second session management entity in the third aspect or any possible implementation manner of the third aspect, or a module applied in the second session management entity, such as a chip or a system of chips. Wherein, the communication device includes corresponding modules, units, or means (means) for implementing the above method, and the modules, units, or means may be implemented by hardware, software, or by executing corresponding software in hardware. The hardware or software includes one or more modules or units corresponding to the above functions.
结合上述第七方面,在一种可能的实现方式中,通信装置包括处理模块和收发模块;该处理模块,用于获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,该第一会话为第一终端设备用于承载该第一终端设备与第二终端设备之间C2通信的会话,该第一终端设备 为该C2通信的发起端设备,该第二终端设备为该C2通信的对端设备,该第二会话管理实体是为该第二终端设备服务的会话管理实体;该收发模块,用于向为该第二终端设备服务的第二接入网设备发送该第一用户面安全保护开启指示;其中,该第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,该第二会话为该第二终端设备用于承载该C2通信的会话。With reference to the above seventh aspect, in a possible implementation manner, the communication device includes a processing module and a transceiver module; the processing module is used to obtain the first user plane security protection opening instruction, and the first user plane security protection opening instruction is used for Indicates whether the user plane security protection of the first session is enabled; wherein, the first session is a session used by the first terminal device to carry the C2 communication between the first terminal device and the second terminal device, and the first terminal device is The initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, the second session management entity is the session management entity serving the second terminal device; The second access network device served by the second terminal device sends the first user plane security protection enable instruction; wherein, the first user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the first user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled. The second session is a session used by the second terminal device to carry the C2 communication.
结合上述第七方面,在一种可能的实现方式中,通信装置包括处理器和收发器;该处理器,用于获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,该第一会话为第一终端设备用于承载C2通信的会话,该第一终端设备为该C2通信的发起端设备,第二终端设备为该C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信,该第二会话管理实体是为该第二终端设备服务的会话管理实体;该收发器,用于向为该第二终端设备服务的第二接入网设备发送该第一用户面安全保护开启指示;其中,该第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,该第二会话为该第二终端设备用于承载该C2通信的会话。With reference to the above seventh aspect, in a possible implementation manner, the communication device includes a processor and a transceiver; the processor is used to obtain the first user plane security protection opening instruction, and the first user plane security protection opening instruction is used for Indicates whether the user plane security protection of the first session is enabled; wherein, the first session is a session used by the first terminal device to carry the C2 communication, the first terminal device is the initiating end device of the C2 communication, and the second terminal device is the peer device of the C2 communication, the C2 communication is the communication between the first terminal device and the second terminal device, and the second session management entity is a session management entity serving the second terminal device; the transceiver, is used to send the first user plane security protection opening instruction to the second access network device serving the second terminal device; wherein the first user plane security protection opening instruction is used to determine the user plane security protection of the second session Whether it is enabled, the second session is a session used by the second terminal device to carry the C2 communication.
第八方面,提供了一种通信装置用于执行上述第四方面或第四方面的任一可能的实现方式中的方法。该通信装置可以为上述第四方面或第四方面的任一可能的实现方式中的第二会话管理实体,或者应用于第二会话管理实体中的模块,例如芯片或芯片系统。其中,该通信装置包括实现上述方法相应的模块、单元、或手段(means),该模块、单元、或means可以通过硬件实现,软件实现,或者通过硬件执行相应的软件实现。该硬件或软件包括一个或多个与上述功能相对应的模块或单元。In an eighth aspect, a communication apparatus is provided for performing the above fourth aspect or the method in any possible implementation manner of the fourth aspect. The communication apparatus may be the second session management entity in the fourth aspect or any possible implementation manner of the fourth aspect, or a module applied in the second session management entity, such as a chip or a system of chips. Wherein, the communication device includes corresponding modules, units, or means (means) for implementing the above method, and the modules, units, or means may be implemented by hardware, software, or by executing corresponding software in hardware. The hardware or software includes one or more modules or units corresponding to the above functions.
结合上述第八方面,在一种可能的实现方式中,通信装置包括处理模块和收发模块;该处理模块,用于获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,该第一会话为第一终端设备用于承载C2通信的会话,该第一终端设备为该C2通信的发起端设备,第二终端设备为该C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信,该第二会话管理实体是为该第二终端设备服务的会话管理实体;该处理模块,还用于根据该第一用户面安全保护开启指示确定第三用户面安全保护策略,该第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护;该收发模块,用于向为该第二终端设备服务的第二接入网设备发送该第三用户面安全保护策略;其中,该第三用户面安全保护策略用于确定第二用户面安全保护开启指示,该第二用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,该第二会话为该第二终端设备用于承载该C2通信的会话。With reference to the above eighth aspect, in a possible implementation manner, the communication device includes a processing module and a transceiver module; the processing module is used to obtain the first user plane security protection opening instruction, and the first user plane security protection opening instruction is used for Indicates whether the user plane security protection of the first session is enabled; wherein, the first session is a session used by the first terminal device to carry the C2 communication, the first terminal device is the initiating end device of the C2 communication, and the second terminal device is the peer device of the C2 communication, the C2 communication is the communication between the first terminal device and the second terminal device, and the second session management entity is the session management entity serving the second terminal device; the processing module, It is also used to determine a third user plane security protection policy according to the first user plane security protection opening instruction, and the third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection; the transceiver module is used to send The second access network device serving the second terminal device sends the third user plane security protection policy; wherein the third user plane security protection policy is used to determine the second user plane security protection opening instruction, and the second user The plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is a session used by the second terminal device to carry the C2 communication.
结合上述第八方面,在一种可能的实现方式中,该处理模块,用于根据该第一用户面安全保护开启指示确定第三用户面安全保护策略的方案可参考上述第四方面,在此不再赘述。With reference to the above-mentioned eighth aspect, in a possible implementation manner, for the solution of the processing module for determining the third user-plane security protection policy according to the first user-plane security protection opening instruction, reference may be made to the above-mentioned fourth aspect, and here No longer.
结合上述第八方面,在一种可能的实现方式中,通信装置包括处理器和收发器;该处理器,用于获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,该第一会话为第一终端设备用于承载C2通信的会话,该第一终端设备为该C2通信的发起端设备,第二终端设备为 该C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信,该第二会话管理实体是为该第二终端设备服务的会话管理实体;该处理器,还用于根据该第一用户面安全保护开启指示确定第三用户面安全保护策略,该第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护;该收发器,用于向为该第二终端设备服务的第二接入网设备发送该第三用户面安全保护策略;其中,该第三用户面安全保护策略用于确定第二用户面安全保护开启指示,该第二用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,该第二会话为该第二终端设备用于承载该C2通信的会话。With reference to the above-mentioned eighth aspect, in a possible implementation manner, the communication device includes a processor and a transceiver; the processor is used to obtain the first user plane security protection opening instruction, and the first user plane security protection opening instruction is used for Indicates whether the user plane security protection of the first session is enabled; wherein, the first session is a session used by the first terminal device to carry the C2 communication, the first terminal device is the initiating end device of the C2 communication, and the second terminal device is the peer device of the C2 communication, the C2 communication is the communication between the first terminal device and the second terminal device, and the second session management entity is a session management entity serving the second terminal device; the processor, It is also used for determining a third user plane security protection policy according to the first user plane security protection opening instruction, and the third user plane security protection policy only includes forcibly turning on the security protection or forcibly not turning on the security protection; the transceiver is used for sending The second access network device serving the second terminal device sends the third user plane security protection policy; wherein the third user plane security protection policy is used to determine the second user plane security protection opening instruction, and the second user The plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is a session used by the second terminal device to carry the C2 communication.
结合上述第八方面,在一种可能的实现方式中,该处理器,用于根据该第一用户面安全保护开启指示确定第三用户面安全保护策略的方案可参考上述第四方面,在此不再赘述。With reference to the above-mentioned eighth aspect, in a possible implementation manner, the processor for determining the third user-plane security protection policy according to the first user-plane security protection enabling instruction may refer to the above-mentioned fourth aspect, and here No longer.
结合上述第七方面或第八方面,在一种可能的实现方式中,该处理模块,用于获取第一用户面安全保护开启指示,包括:通过该收发模块向为该第二终端设备服务的第二统一数据管理实体发送第五消息,该第五消息包括该第二终端设备的标识信息,该第五消息用于请求第二用户面安全保护策略;通过该收发模块接收来自该第二统一数据管理实体的该第二用户面安全保护策略和该第一用户面安全保护开启指示。With reference to the above seventh aspect or the eighth aspect, in a possible implementation manner, the processing module, configured to obtain the first user plane security protection opening instruction, includes: sending the sending and receiving module to a server serving the second terminal device through the transceiver module. The second unified data management entity sends a fifth message, where the fifth message includes the identification information of the second terminal device, and the fifth message is used to request the second user plane security protection policy; The second user plane security protection policy and the first user plane security protection opening instruction of the data management entity.
结合上述第七方面或第八方面,在一种可能的实现方式中,该处理模块,用于获取第一用户面安全保护开启指示,包括:通过该收发模块向第二代理功能实体发送第六消息,该第六消息包括该第二终端设备的标识信息,该第六消息用于请求该第一用户面安全保护开启指示,该第二代理功能实体用于提供该第二会话管理实体到管理设备的接口;通过该收发模块接收来自该第二代理功能实体的该第一用户面安全保护开启指示。With reference to the above seventh aspect or the eighth aspect, in a possible implementation manner, the processing module, configured to obtain the first user plane security protection opening instruction, includes: sending a sixth to the second proxy function entity through the transceiver module. message, the sixth message includes the identification information of the second terminal device, the sixth message is used to request the first user plane security protection opening instruction, and the second proxy function entity is used to provide the second session management entity to the management The interface of the device; receiving the first user plane security protection opening instruction from the second proxy function entity through the transceiver module.
结合上述第七方面或第八方面,在一种可能的实现方式中,该收发模块,还用于在向第二代理功能实体发送第六消息之前,接收来自该第二终端设备的指示信息,该指示信息指示该第二终端设备请求建立的该第二会话用于响应该第一终端设备发起的该C2通信。With reference to the seventh aspect or the eighth aspect, in a possible implementation manner, the transceiver module is further configured to receive the indication information from the second terminal device before sending the sixth message to the second proxy function entity, The indication information indicates that the second session requested by the second terminal device to be established is used in response to the C2 communication initiated by the first terminal device.
结合上述第七方面或第八方面,在一种可能的实现方式中,该处理器,用于获取第一用户面安全保护开启指示,包括:通过该收发器向为该第二终端设备服务的第二统一数据管理实体发送第五消息,该第五消息包括该第二终端设备的标识信息,该第五消息用于请求第二用户面安全保护策略;通过该收发器接收来自该第二统一数据管理实体的该第二用户面安全保护策略和该第一用户面安全保护开启指示。With reference to the above seventh aspect or the eighth aspect, in a possible implementation manner, the processor, configured to obtain the first user plane security protection opening instruction, includes: sending a message to the server serving the second terminal device through the transceiver. The second unified data management entity sends a fifth message, where the fifth message includes the identification information of the second terminal device, and the fifth message is used to request the second user plane security protection policy; The second user plane security protection policy and the first user plane security protection opening instruction of the data management entity.
结合上述第七方面或第八方面,在一种可能的实现方式中,该处理器,用于获取第一用户面安全保护开启指示,包括:通过该收发器向第二代理功能实体发送第六消息,该第六消息包括该第二终端设备的标识信息,该第六消息用于请求该第一用户面安全保护开启指示,该第二代理功能实体用于提供该第二会话管理实体到管理设备的接口;通过该收发器接收来自该第二代理功能实体的该第一用户面安全保护开启指示。With reference to the seventh aspect or the eighth aspect, in a possible implementation manner, the processor, configured to obtain the first user plane security protection enabling instruction, includes: sending a sixth to the second proxy function entity through the transceiver message, the sixth message includes the identification information of the second terminal device, the sixth message is used to request the first user plane security protection opening instruction, and the second proxy function entity is used to provide the second session management entity to the management The interface of the device; receiving the first user plane security protection opening instruction from the second proxy function entity through the transceiver.
结合上述第七方面或第八方面,在一种可能的实现方式中,该收发器,还用于在向第二代理功能实体发送第六消息之前,接收来自该第二终端设备的指示信息,该指示信息指示该第二终端设备请求建立的该第二会话用于响应该第一终端设备发起的该 C2通信。With reference to the seventh aspect or the eighth aspect, in a possible implementation manner, the transceiver is further configured to receive the indication information from the second terminal device before sending the sixth message to the second proxy function entity, The indication information indicates that the second session requested by the second terminal device to be established is used in response to the C2 communication initiated by the first terminal device.
其中,上述第七方面或第七方面的任一可能的实现方式的技术效果可参考上述第三方面,在此不再赘述。For the technical effect of the seventh aspect or any possible implementation manner of the seventh aspect, reference may be made to the third aspect, which will not be repeated here.
其中,上述第八方面或第八方面的任一可能的实现方式的技术效果可参考上述第四方面,在此不再赘述。For the technical effect of the above-mentioned eighth aspect or any possible implementation manner of the eighth aspect, reference may be made to the above-mentioned fourth aspect, which will not be repeated here.
第九方面,提供了一种通信装置,包括:存储器以及与该存储器耦合的处理器,该存储器用于存储程序,该处理器用于执行该存储器存储的程序;当该通信装置运行时,该处理器运行该程序,使得该通信装置执行上述任一方面所述的方法。In a ninth aspect, a communication device is provided, comprising: a memory and a processor coupled with the memory, the memory is used for storing a program, and the processor is used for executing the program stored in the memory; when the communication device is running, the processing The computer runs the program, so that the communication device executes the method described in any one of the above-mentioned aspects.
结合上述第九方面,在一种可能的实现方式中,该通信装置可以是芯片或芯片系统。其中,当该通信装置是芯片系统时,该通信装置可以由芯片构成,也可以包含芯片和其他分立器件。With reference to the above ninth aspect, in a possible implementation manner, the communication device may be a chip or a chip system. Wherein, when the communication device is a chip system, the communication device may be constituted by a chip, or may include a chip and other discrete devices.
结合上述第九方面,在一种可能的实现方式中,当通信装置为芯片或芯片系统时,上述处理器也可以体现为处理电路或逻辑电路。With reference to the above ninth aspect, in a possible implementation manner, when the communication device is a chip or a chip system, the above-mentioned processor may also be embodied as a processing circuit or a logic circuit.
第十方面,提供了一种计算机可读存储介质,该计算机可读存储介质中存储有指令,当其在计算机上运行时,使得计算机可以执行上述任一方面所述的方法。In a tenth aspect, a computer-readable storage medium is provided, and instructions are stored in the computer-readable storage medium, which, when executed on a computer, enable the computer to execute the method described in any one of the above aspects.
第十一方面,提供了一种包含指令的计算机程序产品,当其在计算机上运行时,使得计算机可以执行上述任一方面所述的方法。In an eleventh aspect, there is provided a computer program product comprising instructions which, when run on a computer, enable the computer to perform the method of any of the preceding aspects.
其中,第九方面至第十一方面中任一种可能的实现方式所带来的技术效果可参见上述第一方面或第二方面或第三方面或第四方面中不同实现方式所带来的技术效果,此处不再赘述。Wherein, for the technical effects brought by any of the possible implementation manners of the ninth aspect to the eleventh aspect, reference may be made to the technical effects brought about by different implementation manners in the first aspect or the second aspect or the third aspect or the fourth aspect. The technical effect will not be repeated here.
第十二方面,提供一种通信系统,该通信系统包括上述第一方面所述的管理设备、以及上述第三方面或第四方面所述的第二会话管理实体。A twelfth aspect provides a communication system, which includes the management device described in the first aspect and the second session management entity described in the third aspect or the fourth aspect.
结合上述第十二方面,在一种可能的实现方式中,管理设备,用于获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;该第一会话为该第一终端设备用于承载C2通信的会话,该C2通信为第一终端设备与第二终端设备之间的通信;管理设备,还用于触发该第二终端设备发起第二会话的建立,该第二会话为该第二终端设备用于承载该C2通信的会话;第二会话管理实体,用于接收该管理设备获取的该第一用户面安全保护开启指示,并向为该第二终端设备服务的第二接入网设备发送该第一用户面安全保护开启指示;其中,该第一用户面安全保护开启指示用于确定该第二会话的用户面安全保护是否开启。With reference to the twelfth aspect above, in a possible implementation manner, the management device is configured to obtain a first user plane security protection enable instruction, where the first user plane security protection enable instruction is used to indicate the user plane security of the first session Whether the protection is enabled; the first session is a session used by the first terminal device to carry C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device; the management device is also used to trigger the second terminal device. The terminal device initiates establishment of a second session, and the second session is a session used by the second terminal device to carry the C2 communication; a second session management entity is configured to receive the first user plane security protection enabled by the management device. and send the first user plane security protection opening instruction to the second access network device serving the second terminal device; wherein, the first user plane security protection opening instruction is used to determine the user plane of the second session Whether security protection is enabled.
结合上述第十二方面,在另一种可能的实现方式中,管理设备,用于获取第一用户面安全保护开启指示,该第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;该第一会话为该第一终端设备用于承载C2通信的会话,该C2通信为第一终端设备与第二终端设备之间的通信;管理设备,还用于触发该第二终端设备发起第二会话的建立,该第二会话为该第二终端设备用于承载该C2通信的会话;第二会话管理实体,用于接收该管理设备获取的该第一用户面安全保护开启指示,并根据该第一用户面安全保护开启指示确定第三用户面安全保护策略之后,向为该第二终端设备服务的第二接入网设备发送该第三用户面安全保护策略;其中,该第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护;该第三用户面安全 保护策略用于确定第二用户面安全保护开启指示,该第二用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,该第二会话为该第二终端设备用于承载该C2通信的会话。With reference to the above twelfth aspect, in another possible implementation manner, the management device is configured to obtain a first user plane security protection enabling instruction, where the first user plane security protection enabling instruction is used to indicate the user plane of the first session Whether security protection is enabled; the first session is a session used by the first terminal device to carry the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device; the management device is also used to trigger the first terminal device. The second terminal device initiates the establishment of a second session, and the second session is the session used by the second terminal device to carry the C2 communication; the second session management entity is configured to receive the first user plane security protection obtained by the management device an enabling instruction, and after determining a third user plane security protection policy according to the first user plane security protection enabling instruction, send the third user plane security protection policy to the second access network device serving the second terminal device; wherein , the third user plane security protection policy only includes forcibly turning on the security protection or forcibly not turning on the security protection; the third user plane security protection policy is used to determine the second user plane security protection opening instruction, and the second user plane security protection is turned on Indicates whether the user plane security protection used for determining the second session is enabled, where the second session is a session used by the second terminal device to carry the C2 communication.
结合上述第十二方面,在另一种可能的实现方式中,该通信系统还包括上述第二方面所述的第一会话管理实体;其中,第一会话管理实体,用于向该管理设备发送该第一用户面安全保护开启指示;管理设备,用于获取第一用户面安全保护开启指示,包括:用于接收来自该第一会话管理实体的该第一用户面安全保护开启指示。With reference to the above twelfth aspect, in another possible implementation manner, the communication system further includes the first session management entity described in the above second aspect; wherein, the first session management entity is used to send to the management device The first user plane security protection opening instruction; the management device, configured to obtain the first user plane security protection opening instruction, includes: being used for receiving the first user plane security protection opening instruction from the first session management entity.
结合上述第十二方面,在另一种可能的实现方式中,通信系统还包括该第一终端设备;第一终端设备,用于向该管理设备发送该第一用户面安全保护开启指示;管理设备,用于获取第一用户面安全保护开启指示,包括:用于接收来自该第一终端设备的该第一用户面安全保护开启指示。With reference to the above twelfth aspect, in another possible implementation manner, the communication system further includes the first terminal device; the first terminal device is configured to send the first user plane security protection opening instruction to the management device; management The device, configured to acquire the first user plane security protection opening instruction, includes: being configured to receive the first user plane security protection opening instruction from the first terminal device.
其中,第十二方面的技术效果可参见上述第一方面或第二方面或第三方面或第四方面中不同实现方式所带来的技术效果,此处不再赘述。For the technical effects of the twelfth aspect, reference may be made to the technical effects brought about by different implementations in the first aspect or the second aspect or the third aspect or the fourth aspect, which will not be repeated here.
附图说明Description of drawings
图1为目前讨论的5G无线通信网络使能无人机系统的架构示意图;Figure 1 is a schematic diagram of the architecture of the currently discussed 5G wireless communication network-enabled UAV system;
图2a为本申请实施例提供的一种通信系统的架构示意图;2a is a schematic diagram of the architecture of a communication system provided by an embodiment of the present application;
图2b为本申请实施例提供的另一种通信系统的架构示意图;FIG. 2b is a schematic diagram of the architecture of another communication system provided by an embodiment of the present application;
图2c为本申请实施例提供的又一种通信系统的架构示意图;FIG. 2c is a schematic diagram of the architecture of another communication system provided by an embodiment of the present application;
图3为本申请实施例提供的通信系统应用于5G网络时的架构示意图;FIG. 3 is a schematic diagram of the architecture when the communication system provided by the embodiment of the present application is applied to a 5G network;
图4为本申请实施例提供的一种通信装置的结构示意图;FIG. 4 is a schematic structural diagram of a communication device according to an embodiment of the present application;
图5为本申请实施例提供的一种通信方法的流程示意图;FIG. 5 is a schematic flowchart of a communication method provided by an embodiment of the present application;
图6为本申请实施例提供的另一种通信方法的流程示意图;6 is a schematic flowchart of another communication method provided by an embodiment of the present application;
图7a为本申请实施例提供的又一种通信方法的流程示意图;FIG. 7a is a schematic flowchart of another communication method provided by an embodiment of the present application;
图7b为本申请实施例提供的又一种通信方法的流程示意图;FIG. 7b is a schematic flowchart of another communication method provided by an embodiment of the present application;
图8为本申请实施例提供的一种通信方法的交互示意图;FIG. 8 is an interactive schematic diagram of a communication method provided by an embodiment of the present application;
图9为本申请实施例提供的另一种通信方法的交互示意图;FIG. 9 is an interactive schematic diagram of another communication method provided by an embodiment of the present application;
图10为本申请实施例提供的又一种通信方法的交互示意图;FIG. 10 is an interactive schematic diagram of still another communication method provided by an embodiment of the present application;
图11为本申请实施例提供的又一种通信方法的交互示意图;FIG. 11 is an interactive schematic diagram of still another communication method provided by an embodiment of the present application;
图12为本申请实施例提供的另一种通信装置的结构示意图。FIG. 12 is a schematic structural diagram of another communication apparatus provided by an embodiment of the present application.
具体实施方式Detailed ways
为了方便理解本申请实施例的技术方案,首先给出本申请相关技术的简要介绍如下。In order to facilitate understanding of the technical solutions of the embodiments of the present application, a brief introduction of the related technologies of the present application is first given as follows.
第一,C2通信:First, C2 communication:
在第三代合作伙伴计划(3rd generation partnership project,3GPP)网络需求工作组(SA1)中,将C2通信定义为:UAVC或UTM/USS使用用户面连接向UAV传递命令与控制信令。其中,根据不同需求(例如信息交换频率,流量大小,端到端时延等),UAVC或UTM/USS对UAV有四种操作模式,包括航点转向、转向杆直接控制、自动飞行和靠近自动导航设施。由于本申请实施例不涉及具体的C2通信操作,因此本申请实施例对上述四种操作模式不进行详细阐述。In the 3rd generation partnership project (3GPP) network requirements working group (SA1), C2 communication is defined as: UAVC or UTM/USS uses user plane connection to transmit command and control signaling to UAV. Among them, according to different requirements (such as information exchange frequency, traffic size, end-to-end delay, etc.), UAVC or UTM/USS has four operation modes for UAV, including waypoint steering, direct control of steering stick, automatic flight and approaching automatic Navigation facilities. Since the embodiments of the present application do not involve specific C2 communication operations, the above-mentioned four operation modes are not described in detail in the embodiments of the present application.
在3GPP网络架构工作组(SA2)中,对于C2通信的定义新增加了一些描述,C2通信定义为:UAVC或UTM/USS使用用户面连接向UAV传递命令与控制信令,或者,UAV向UAVC或UTM/USS上报遥感监测信息。即,目前的C2通信包括UAVC与UAV之间的双向通信,以及UTM/USS与UAV之间的双向通信。In the 3GPP Network Architecture Working Group (SA2), some new descriptions have been added to the definition of C2 communication. C2 communication is defined as: UAVC or UTM/USS uses user plane connection to transmit command and control signaling to UAV, or UAV to UAVC Or UTM/USS to report remote sensing monitoring information. That is, current C2 communication includes bidirectional communication between UAVC and UAV, and bidirectional communication between UTM/USS and UAV.
需要说明的是,本申请实施例下述实施例中所指的C2通信仅涉及UAV与UAVC之间的C2通信,不涉及UAV与UTM/USS之间的C2通信,在此统一说明,以下不再赘述。It should be noted that the C2 communication referred to in the following embodiments of the embodiments of this application only involves the C2 communication between the UAV and the UAVC, and does not involve the C2 communication between the UAV and the UTM/USS. Repeat.
第二,5G网络使能无人机系统的架构:Second, the architecture of the 5G network-enabled UAS:
图1为目前讨论的5G无线通信网络使能无人机系统的架构示意图。如图1所示,一个UAS包括一个UAV和一个UAVC。在5G网络中,UAV被设计成可以通过3GPP网络与对端进行通信。其中,对端例如可以为UAVC;或者,对端例如可以为UTM/USS;或者,对端例如可以为授权的第三方实体(third party authorized entity,TPAE)。如图1所示,UAV或UAVC与3GPP网络用于UAS业务认证、授权、识别和跟踪的接口为UAV1;TPAE与3GPP网络用于远程识别(remote identification,Remote ID)和跟踪的接口为UAV2;UAV通过3GPP网络与UAVC之间进行C2通信时的接口为UAV3,UAV通过3GPP网络与UTM/USS之间通信时的接口为UAV9。此外,如图1所示,UAV可以通过UAV7与TPAE通信,UAV可以通过U2U与UAV所属的UAS之外的其他UAV通信;UAV可以通过UAV8与UAVC通信;UAV通过互联网与UAVC之间进行C2通信时的接口为UAV5。其中,UAV5、UAV7、UAV8和U2U接口不被3GPP网络控制,因此不在本申请实施例讨论的范围之内,在此统一说明,以下不再赘述。Figure 1 is a schematic diagram of the architecture of the currently discussed 5G wireless communication network-enabled unmanned aerial system. As shown in Figure 1, a UAS includes a UAV and a UAVC. In 5G networks, UAVs are designed to communicate with peers over 3GPP networks. Wherein, the opposite end may be, for example, UAVC; or, the opposite end may be, for example, UTM/USS; or, for example, the opposite end may be, for example, an authorized third party entity (third party authorized entity, TPAE). As shown in Figure 1, the interface between UAV or UAVC and 3GPP network for UAS service authentication, authorization, identification and tracking is UAV1; the interface between TPAE and 3GPP network for remote identification (Remote ID) and tracking is UAV2; The interface when UAV communicates with UAVC through C2 through 3GPP network is UAV3, and the interface when UAV communicates with UTM/USS through 3GPP network is UAV9. In addition, as shown in Figure 1, UAV can communicate with TPAE through UAV7, UAV can communicate with other UAVs other than UAS to which UAV belongs through U2U; UAV can communicate with UAVC through UAV8; UAV can communicate with UAVC through C2 through the Internet When the interface is UAV5. Among them, the UAV5, UAV7, UAV8 and U2U interfaces are not controlled by the 3GPP network, and therefore are not within the scope of the discussion of the embodiments of the present application, which are uniformly described here, and will not be repeated below.
本申请实施例中,UAV和UAVC均可被3GPP网络视为终端设备或称之为用户设备(user equipment,UE)。UTM负责无人机通信管理,USS为提供无人机业务的提供商。其中,UTM/USS的业务包括对UAV/UAVC是否可以使用无人机业务进行鉴权授权、以及对UAV与UAVC是否可以配对进行授权。TPAE是除了UAVC和UTM/USS之外的有监管需求的机构持有的设备(比如警察)。In the embodiments of the present application, both UAV and UAVC can be regarded as terminal equipment or called user equipment (user equipment, UE) by the 3GPP network. UTM is responsible for drone communication management, and USS is the provider of drone services. Among them, the services of UTM/USS include authentication and authorization of whether UAV/UAVC can use drone services, and authorization of whether UAV and UAVC can be paired. TPAEs are equipment held by agencies with regulatory needs other than UAVC and UTM/USS (such as police).
本申请实施例中,UAV通过3GPP网络与对端进行通信包括三种:In the embodiment of the present application, the communication between the UAV and the opposite end through the 3GPP network includes three types:
1、UAVC或UTM/USS对UAV进行C2通信,用作控制UAV飞行,或用作控制UAV向UAVC或UTM/USS发送测控数据。需要注意的是,UAV与UAVC在进行C2通信时,可以处于不同的公共陆地移动网(public land mobile network,PLMN)连接中,比如,图1中某个UAS中的UAV可以处于3GPP PLMN-a连接中,UAVC可以处于3GPP PLMN-b连接中,在此统一说明,以下不再赘述。1. UAVC or UTM/USS performs C2 communication with UAV, used to control UAV flight, or used to control UAV to send measurement and control data to UAVC or UTM/USS. It should be noted that when UAV and UAVC communicate in C2, they can be in different public land mobile network (PLMN) connections. For example, the UAV in a UAS in Figure 1 can be in 3GPP PLMN-a During the connection, the UAVC may be in the 3GPP PLMN-b connection, which is described in a unified manner here, and will not be repeated below.
2、UTM/USS或TPAE对UAV进行远程识别,由飞行中的UAV向UTM/USS或TPAE提供自己的识别信息,以辅助监管机构(例如UTM或民航局)及时识别无人机状态来填补安全隐患。2. UTM/USS or TPAE performs remote identification of UAV, and the UAV in flight provides its own identification information to UTM/USS or TPAE to assist regulatory agencies (such as UTM or Civil Aviation Administration) to identify the UAV status in time to fill in the safety hidden danger.
3、UAV与UTM/USS进行其他UAS业务,例如UAV从UTM/USS获取UAS服务参数,或者获取使用UAS服务的认证和授权等。3. The UAV performs other UAS services with the UTM/USS, for example, the UAV obtains UAS service parameters from the UTM/USS, or obtains the authentication and authorization for using the UAS service.
第三,用户面安全保护策略与用户面安全保护开启指示:Third, the user plane security protection policy and the user plane security protection enable instruction:
用户面安全保护策略是用于描述是否开启用户面安全保护的策略,可用于确定用 户面安全保护开启指示。本申请实施例中,用户面安全保护策略包括用户面机密性保护策略和/或用户面完整性保护策略。用户面机密性保护策略是用于描述是否开启用户面机密性保护的策略,可用于确定用户面机密性保护开启指示。用户面完整性保护策略是用于描述是否开启用户面完整性保护的策略,可用于确定用户面完整性保护开启指示。用户面机密性保护开启指示用于指示用户面机密性保护的开启结果,如用户面机密性保护的开启结果为用户面机密性保护开启(performed)或不开启(not performed)(例如取第一数值时,用户面机密性保护的开启结果为用户面机密性保护开启;取第二数值时,用户面机密性保护的开启结果为用户面机密性保护不开启)。用户面完整性保护开启指示用于指示用户面完整性保护的开启结果,如用户面完整性保护的开启结果为用户面完整性保护开启(performed)或不开启(not performed)(例如取第三数值时,用户面机密性保护的开启结果为用户面完整性保护开启;取第四数值时,用户面机密性保护的开启结果为用户面完整性保护不开启)。本申请实施例中,用户面机密性保护即保护用户面数据在传输过程中的机密性。用户面完整性保护即保护用户面数据在传输过程中的完整性。其中,完整性是指获取到的信令或数据与原始的信令或数据一致,没有被修改,因此,完整性保护是为了使得攻击者“攻击不成”。机密性是指无法被直接看出真实内容,因此机密性保护是为了使得攻击者“读不懂”。此外,本申请实施例中的机密性保护也可以称为加密保护,在此统一说明,以下不再赘述。The user plane security protection policy is a policy used to describe whether to enable the user plane security protection, and can be used to determine the instruction to enable the user plane security protection. In this embodiment of the present application, the user plane security protection policy includes a user plane confidentiality protection policy and/or a user plane integrity protection policy. The user plane confidentiality protection policy is a policy used to describe whether to enable the user plane confidentiality protection, and can be used to determine the user plane confidentiality protection enabling instruction. The user plane integrity protection policy is a policy used to describe whether to enable the user plane integrity protection, and can be used to determine the user plane integrity protection enable instruction. The user plane confidentiality protection enable instruction is used to indicate the enable result of the user plane confidentiality protection. When the value is set, the result of turning on the confidentiality protection of the user plane is that the confidentiality protection of the user plane is turned on; when the second value is taken, the result of turning on the confidentiality protection of the user plane is that the confidentiality protection of the user plane is not turned on). The user plane integrity protection enable instruction is used to indicate the result of enabling the user plane integrity protection. When the value is set, the result of turning on the confidentiality protection of the user plane is that the integrity protection of the user plane is turned on; when the fourth value is taken, the result of turning on the confidentiality protection of the user plane is that the integrity protection of the user plane is not turned on). In this embodiment of the present application, the user plane confidentiality protection is to protect the confidentiality of user plane data during transmission. User plane integrity protection protects the integrity of user plane data during transmission. The integrity means that the acquired signaling or data is consistent with the original signaling or data and has not been modified. Therefore, integrity protection is to prevent an attacker from "attacking". Confidentiality means that the real content cannot be seen directly, so confidentiality protection is to make the attacker "unreadable". In addition, the confidentiality protection in the embodiments of the present application may also be referred to as encryption protection, which is uniformly described here, and will not be repeated below.
本申请实施例中,用户面安全保护策略(包括用户面机密性保护策略与用户面完整性保护策略)可以有REQUIRED、NOT NEEDED和PREFERRED三种取值。REQUIRED表示需要强制开启安全保护,NOT NEEDED表示需要强制不开启安全保护,PREFERRED表示偏好开启或者称为可选开启,即可以开启安全保护但也可以不开启安全保护。In this embodiment of the present application, the user plane security protection policy (including the user plane confidentiality protection policy and the user plane integrity protection policy) may have three values: REQUIRED, NOT NEEDED, and PREFERRED. REQUIRED means that the security protection needs to be forced to be turned on, NOT NEEDED means that the security protection needs to be forced not to be turned on, and PREFERRED means that the security protection is preferably turned on or optional, that is, the security protection can be turned on but not turned on.
需要说明的是,本申请实施例中,用户面安全保护策略与用户面安全保护开启指示用于建立承载C2通信的会话或者用于建立承载非C2通信的会话,在此统一说明,以下不再赘述。It should be noted that, in this embodiment of the present application, the user plane security protection policy and the user plane security protection enable instruction are used to establish a session that bears C2 communication or a session that bears non-C2 communication. Repeat.
需要说明的是,本申请实施例中,用户面机密性保护策略或用户面完整性保护策略在被发送时,一般情况下只会选择三种(REQUIRED、NOT NEEDED和PREFERRED)取值中的一种发送,在某些特殊的场景下可能会选择至少2种发送,并且其中一个是PREFERRED。比如,在发送NOT NEEDED和PREFERRED时,代表倾向不开启安全保护;在发送REQUIRED和PREFERRED时,则代表倾向开启安全保护。It should be noted that, in this embodiment of the present application, when the user plane confidentiality protection policy or the user plane integrity protection policy is sent, generally only one of the three values (REQUIRED, NOT NEEDED, and PREFERRED) is selected. In some special scenarios, at least 2 types of transmissions may be selected, and one of them is PREFERRED. For example, when sending NOT NEEDED and PREFERRED, it means that the security protection is not turned on; when sending REQUIRED and PREFERRED, it means that the security protection is turned on.
需要说明的是,本申请实施例中,用户面机密性保护策略与用户面完整性保护策略可以相同,用户面机密性保护开启指示与用户面完整性保护开启指示可以相同,本申请实施例对此不做具体限定。It should be noted that, in this embodiment of the present application, the user plane confidentiality protection policy and the user plane integrity protection policy may be the same, and the user plane confidentiality protection enabling instruction and the user plane integrity protection enabling instruction may be the same. This is not specifically limited.
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行描述。其中,在本申请的描述中,除非另有说明,“/”表示前后关联的对象是一种“或”的关系,例如,A/B可以表示A或B;本申请中的“和/或”仅仅是一种描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况,其中A,B可以是单数或者复数。并且,在本申请的描述中,除非另有说明,“多个”是指两个或多于两个。“以下至少一项(个)”或其类似表达,是指 的这些项中的任意组合,包括单项(个)或复数项(个)的任意组合。例如,a,b,或c中的至少一项(个),可以表示:a,b,c,a-b,a-c,b-c,或a-b-c,其中a,b,c可以是单个,也可以是多个。另外,为了便于清楚描述本申请实施例的技术方案,在本申请的实施例中,采用了“第一”、“第二”等字样对功能和作用基本相同的相同项或相似项进行区分。本领域技术人员可以理解“第一”、“第二”等字样并不对数量和执行次序进行限定,并且“第一”、“第二”等字样也并不限定一定不同。同时,在本申请实施例中,“示例性的”或者“例如”等词用于表示作例子、例证或说明。本申请实施例中被描述为“示例性的”或者“例如”的任何实施例或设计方案不应被解释为比其它实施例或设计方案更优选或更具优势。确切而言,使用“示例性的”或者“例如”等词旨在以具体方式呈现相关概念,便于理解。The technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings in the embodiments of the present application. Wherein, in the description of this application, unless otherwise specified, "/" indicates that the objects associated before and after are an "or" relationship, for example, A/B can indicate A or B; in this application, "and/or" "It is only an association relationship that describes an associated object, which means that there can be three kinds of relationships, for example, A and/or B, which can mean: A alone exists, A and B exist at the same time, and B exists alone, where A exists , B can be singular or plural. Also, in the description of the present application, unless stated otherwise, "plurality" means two or more than two. "At least one item(s) below" or similar expressions refer to any combination of these items, including any combination of single item(s) or plural items(s). For example, at least one (a) of a, b, or c can represent: a, b, c, a-b, a-c, b-c, or a-b-c, where a, b, c may be single or multiple . In addition, in order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish the same or similar items with basically the same function and effect. Those skilled in the art can understand that the words "first", "second" and the like do not limit the quantity and execution order, and the words "first", "second" and the like are not necessarily different. Meanwhile, in the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or illustrations. Any embodiments or designs described in the embodiments of the present application as "exemplary" or "such as" should not be construed as preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "such as" is intended to present the related concepts in a specific manner to facilitate understanding.
此外,本申请实施例描述的网络架构以及业务场景是为了更加清楚的说明本申请实施例的技术方案,并不构成对于本申请实施例提供的技术方案的限定,本领域普通技术人员可知,随着网络架构的演变和新业务场景的出现,本申请实施例提供的技术方案对于类似的技术问题,同样适用。In addition, the network architecture and service scenarios described in the embodiments of the present application are for the purpose of illustrating the technical solutions of the embodiments of the present application more clearly, and do not constitute limitations on the technical solutions provided by the embodiments of the present application. With the evolution of the network architecture and the emergence of new service scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
如图2a所示,为本申请实施例提供的一种通信系统20。该通信系统20包括管理设备201和为第二终端设备服务的第二会话管理实体202。第二终端设备为C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信,第一终端设备为C2通信的发起端设备。其中,管理设备201和第二会话管理实体202之间可能直接通信,也可能通过其他设备(例如图2a中的第二代理功能实体203)的转发进行通信,本申请实施例对此不做具体限定。As shown in FIG. 2a, a communication system 20 is provided in an embodiment of the present application. The communication system 20 includes a management device 201 and a second session management entity 202 serving the second terminal device. The second terminal device is the opposite end device of the C2 communication, the C2 communication is the communication between the first terminal device and the second terminal device, and the first terminal device is the initiating end device of the C2 communication. Wherein, the management device 201 and the second session management entity 202 may communicate directly, or may communicate through the forwarding of other devices (for example, the second proxy function entity 203 in FIG. 2a ), which is not specifically described in this embodiment of the present application. limited.
一种可能的实现方式中,管理设备201,用于获取第一用户面安全保护开启指示,第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。其中,第一会话为第一终端设备用于承载C2通信的会话。管理设备201,还用于触发第二终端设备发起第二会话的建立,第二会话为第二终端设备用于承载C2通信的会话。第二会话管理实体202,用于接收管理设备201获取的第一用户面安全保护开启指示,并向为第二终端设备服务的第二接入网设备发送第一用户面安全保护开启指示。其中,第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启。该方案的具体实现可参考后续方法实施例,在此不再赘述。本申请实施例提供的通信系统中,第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,同时第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。换言之,第一会话的用户面安全保护是否开启以及第二会话的用户面安全保护是否开启均是由第一用户面安全保护开启指示确定的。由于第一会话为第一终端设备用于承载第一终端设备与第二终端设备之间C2通信的会话,第二会话为第二终端设备用于承载该C2通信的会话。因此基于该方案,可以保证第一终端设备和第二终端设备之间的C2通信的用户面安全保护的一致性。In a possible implementation manner, the management device 201 is configured to obtain the first user plane security protection enable instruction, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled. The first session is a session used by the first terminal device to carry C2 communication. The management device 201 is further configured to trigger the second terminal device to initiate establishment of a second session, where the second session is a session used by the second terminal device to carry C2 communication. The second session management entity 202 is configured to receive the first user plane security protection enable instruction obtained by the management device 201, and send the first user plane security protection enable instruction to the second access network device serving the second terminal device. The first user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled. For the specific implementation of this solution, reference may be made to subsequent method embodiments, which will not be repeated here. In the communication system provided by the embodiment of the present application, the first user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the first user plane security protection enable instruction is used to indicate the user plane of the first session. Whether security protection is enabled. In other words, whether the user plane security protection of the first session is enabled and whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction. Since the first session is a session used by the first terminal device to carry the C2 communication between the first terminal device and the second terminal device, the second session is a session used by the second terminal device to carry the C2 communication. Therefore, based on this solution, the consistency of user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
另一种可能的实现方式中,管理设备201,用于获取第一用户面安全保护开启指示,第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,第一会话为第一终端设备用于承载C2通信的会话。管理设备201,还用于触发第二终端设备发起第二会话的建立,第二会话为第二终端设备用于承载C2通信的会话。 第二会话管理实体202,用于接收管理设备201获取的第一用户面安全保护开启指示,并根据第一用户面安全保护开启指示确定第三用户面安全保护策略之后,向为第二终端设备服务的第二接入网设备发送第三用户面安全保护策略。其中,第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护。第三用户面安全保护策略用于确定第二用户面安全保护开启指示,第二用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,第二会话为第二终端设备用于承载C2通信的会话。该方案的具体实现可参考后续方法实施例,在此不再赘述。本申请实施例提供的通信系统中,第三用户面安全保护策略用于确定指示第二会话的用户面安全保护是否开启的第二用户面安全保护开启指示,而第三用户面安全保护策略是由指示第一会话的用户面安全保护是否开启的第一用户面安全保护开启指示确定的,且第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护。换言之,第一会话的用户面安全保护是否开启以及第二会话的用户面安全保护是否开启均是由第一用户面安全保护开启指示确定的。由于第一会话为第一终端设备用于承载C2通信的会话,第二会话为第二终端设备用于承载该C2通信的会话,该C2通信为第一终端设备与第二终端设备之间的通信,因此基于该方案,可以保证第一终端设备和第二终端设备之间的C2通信的用户面安全保护的一致性。In another possible implementation manner, the management device 201 is configured to obtain the first user plane security protection enable instruction, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled; A session is a session used by the first terminal device to carry the C2 communication. The management device 201 is further configured to trigger the second terminal device to initiate establishment of a second session, where the second session is a session used by the second terminal device to carry C2 communication. The second session management entity 202 is configured to receive the first user plane security protection enable instruction obtained by the management device 201, and after determining the third user plane security protection policy according to the first user plane security protection enable instruction, send a message to the second terminal device The serving second access network device sends the third user plane security protection policy. The third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection. The third user plane security protection policy is used to determine the second user plane security protection enable instruction, and the second user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is used by the second terminal device. for sessions that carry C2 communications. For the specific implementation of this solution, reference may be made to subsequent method embodiments, which will not be repeated here. In the communication system provided by the embodiment of the present application, the third user plane security protection policy is used to determine the second user plane security protection enable instruction indicating whether the user plane security protection of the second session is enabled, and the third user plane security protection policy is It is determined by the first user plane security protection enable instruction indicating whether the user plane security protection of the first session is enabled, and the third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection. In other words, whether the user plane security protection of the first session is enabled and whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction. Since the first session is a session used by the first terminal device to carry the C2 communication, the second session is a session used by the second terminal device to carry the C2 communication, and the C2 communication is a session between the first terminal device and the second terminal device. Therefore, based on this solution, the consistency of user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
可选的,如图2b所示,该通信系统20还可以包括为第一终端设备服务的第一会话管理实体204。其中,管理设备201和第一会话管理实体204之间可能直接通信,也可能通过其他设备(例如图2b中的第一代理功能实体205)的转发进行通信,本申请实施例对此不做具体限定。Optionally, as shown in FIG. 2b, the communication system 20 may further include a first session management entity 204 serving the first terminal device. Wherein, the management device 201 and the first session management entity 204 may communicate directly, or may communicate through the forwarding of other devices (for example, the first proxy function entity 205 in FIG. 2b ), which is not specifically described in this embodiment of the present application. limited.
第一会话管理实体204,用于向管理设备201发送第一用户面安全保护开启指示。相应的,管理设备201,用于获取第一用户面安全保护开启指示,包括:用于接收来自第一会话管理实体204的第一用户面安全保护开启指示。也就是说,本申请实施例中,管理设备可以通过第一终端设备与管理设备之间的控制面获得第一用户面安全保护开启指示。The first session management entity 204 is configured to send the first user plane security protection opening instruction to the management device 201 . Correspondingly, the management device 201, configured to obtain the first user plane security protection opening instruction, includes: being configured to receive the first user plane security protection opening instruction from the first session management entity 204. That is, in this embodiment of the present application, the management device may obtain the first user plane security protection opening instruction through the control plane between the first terminal device and the management device.
可选的,如图2c所示,该通信系统20还可以包括第一终端设备206。其中,管理设备201和第一终端设备206之间可能直接通信,也可能通过其他设备的转发进行通信,本申请实施例对此不做具体限定。Optionally, as shown in FIG. 2c , the communication system 20 may further include a first terminal device 206 . Wherein, the management device 201 and the first terminal device 206 may communicate directly or communicate through forwarding by other devices, which is not specifically limited in this embodiment of the present application.
第一终端设备206,用于向管理设备201发送第一用户面安全保护开启指示。相应的,管理设备201,用于获取第一用户面安全保护开启指示,包括:用于接收来自第一终端设备206的第一用户面安全保护开启指示。也就是说,本申请实施例中,管理设备可以通过第一终端设备与管理设备之间的用户面获得第一用户面安全保护开启指示。The first terminal device 206 is configured to send the first user plane security protection opening instruction to the management device 201 . Correspondingly, the management device 201 , configured to obtain the first user plane security protection opening instruction, includes: being configured to receive the first user plane security protection opening instruction from the first terminal device 206 . That is, in this embodiment of the present application, the management device may obtain the first user plane security protection opening instruction through the user plane between the first terminal device and the management device.
可选的,图2a至图2c所示的通信系统20可以适用于目前正在讨论的5G网络,也可以适用于未来的其他网络等,本申请实施例对此不做具体限定。Optionally, the communication system 20 shown in FIG. 2a to FIG. 2c may be applicable to the 5G network currently under discussion, and may also be applicable to other future networks, etc., which is not specifically limited in this embodiment of the present application.
示例性的,图2a至图2c所示的通信系统20应用于目前正在讨论的5G网络为例,则如图3所示,图2a至图2c所示的通信系统20中的第一会话管理实体或第二会话管理实体所对应的网元或者实体可以为5G网络的SMF;图2a至图2c所示的通信系统20中的管理设备例如可以为5G无线通信网络使能无人机系统的UTM/USS;图2a至 图2c所示的通信系统20中的第一代理功能实体或第二代理功能实体所对应的网元或者实体可以为用于提供3GPP网络到UTM/USS的接口的UAV飞行使能子系统(UAV flight enablement subsystem,UFES),这样可以减少对现有3GPP网络的影响。本申请实施例中,UFES的功能至少包括为3GPP网络提供UTM/USS选择寻址,终端设备(包括第一终端设备与第二终端设备)的外部UAV ID和3GPP标识的设备映射,以及代替UTM/USS向3GPP网络获取终端设备的签约和策略控制信息等,在此统一说明,以下不再赘述。Exemplarily, the communication system 20 shown in Fig. 2a to Fig. 2c is applied to the 5G network currently under discussion as an example, then as shown in Fig. 3, the first session management in the communication system 20 shown in Fig. 2a to Fig. 2c The network element or entity corresponding to the entity or the second session management entity may be the SMF of the 5G network; the management device in the communication system 20 shown in FIG. 2a to FIG. UTM/USS; the network element or entity corresponding to the first proxy functional entity or the second proxy functional entity in the communication system 20 shown in FIG. 2a to FIG. 2c may be a UAV for providing an interface from a 3GPP network to UTM/USS Flight enablement subsystem (UAV flight enablement subsystem, UFES), which can reduce the impact on the existing 3GPP network. In the embodiment of this application, the functions of UFES include at least providing UTM/USS selective addressing for 3GPP networks, mapping of external UAV IDs of terminal equipment (including the first terminal equipment and second terminal equipment) and 3GPP identifiers, and replacing UTM /USS obtains the subscription and policy control information of the terminal device from the 3GPP network, which is described here uniformly and will not be repeated below.
此外,如图3所示,5G网络还可以包括无线接入网(radio access network,RAN)设备、用户面功能(user plane function,UPF)、接入和移动性管理功能(core access and mobility management function,AMF)、认证服务器功能(authentication server function,AUSF)、网络切片选择功能(network slice selection function,NSSF)、网络开放功能(network exposure function,NEF)、网络功能存储功能(network exposure function Repository Function,NRF)、策略控制功能(policy control function,PCF)、统一数据管理(unified data management,UDM)、统一数据存储(unified data repository,UDR)、应用功能(application function,AF)或者计费功能(charging function,CHF)等。其中,终端设备通过RAN设备接入5G网络,终端设备通过N1接口(简称N1)与AMF通信;RAN设备通过N2接口(简称N2)与AMF通信;RAN设备通过N3接口(简称N3)与UPF通信;RAN设备还可以与UTM/USS通信;SMF通过N4接口(简称N4)与UP通信,UPF通过N6接口(简称N6)接入数据网络。此外,图3所示的AUSF、AMF、SMF、NSSF、NEF、NRF、PCF、UDM、UDR、CHF、UFES或者AF等控制面功能采用服务化接口进行交互。比如,AUSF对外提供的服务化接口为Nausf;AMF对外提供的服务化接口为Namf;SMF对外提供的服务化接口为Nsmf;NSSF对外提供的服务化接口为Nnssf;NEF对外提供的服务化接口为Nnef;NRF对外提供的服务化接口为Nnrf;PCF对外提供的服务化接口为Npcf;UDM对外提供的服务化接口为Nudm;UDR对外提供的服务化接口为Nudr;CHF对外提供的服务化接口为Nchf;UFES对外提供的服务化接口为Nufes;AF对外提供的服务化接口为Naf。相关功能描述以及接口描述可以参考23501标准中的5G系统架构(5G system architecture)图,在此不予赘述。In addition, as shown in Figure 3, a 5G network may also include radio access network (RAN) equipment, user plane functions (UPF), access and mobility management functions (core access and mobility management) function, AMF), authentication server function (AUSF), network slice selection function (NSSF), network exposure function (NEF), network exposure function (Repository Function) , NRF), policy control function (PCF), unified data management (UDM), unified data repository (UDR), application function (application function, AF) or billing function ( charging function, CHF), etc. The terminal device accesses the 5G network through the RAN device, and the terminal device communicates with the AMF through the N1 interface (N1 for short); the RAN device communicates with the AMF through the N2 interface (N2 for short); the RAN device communicates with the UPF through the N3 interface (N3 for short) RAN equipment can also communicate with UTM/USS; SMF communicates with UP through N4 interface (N4 for short), and UPF accesses data network through N6 interface (N6 for short). In addition, the control plane functions such as AUSF, AMF, SMF, NSSF, NEF, NRF, PCF, UDM, UDR, CHF, UFES or AF shown in FIG. 3 use service interfaces to interact. For example, the service interface provided by AUSF is Nausf; the service interface provided by AMF is Namf; the service interface provided by SMF is Nsmf; the service interface provided by NSSF is Nnssf; the service interface provided by NEF is Nnef; the service interface provided by NRF is Nnrf; the service interface provided by PCF is Npcf; the service interface provided by UDM is Nudm; the service interface provided by UDR is Nudr; the service interface provided by CHF is Nchf; the service interface provided by UFES is Nufes; the service interface provided by AF is Naf. For related function descriptions and interface descriptions, please refer to the 5G system architecture diagram in the 23501 standard, which will not be repeated here.
需要说明的是,本申请实施例中,UFES可以是独立于5G网络的网元部署的,也可以是部署在5G网络的网元上,如部署在NEF上,本申请实施例对此不做具体限定。It should be noted that, in the embodiment of the present application, the UFES may be deployed independently of the network element of the 5G network, or may be deployed on the network element of the 5G network, such as being deployed on the NEF, which is not done in the embodiment of the present application. Specific restrictions.
可选的,本申请实施例中的终端设备(包括上述第一终端设备或第二终端设备),可以是用于实现无线通信功能的设备,例如终端或者可用于终端中的芯片等,其可以部署在陆地上,包括室内或室外、手持或车载;也可以部署在水面上(如轮船等);还可以部署在空中(例如飞机、气球和卫星上等)。一种可能的实现方式中,上述的第一终端设备例如可以为5G无线通信网络使能无人机系统的UAV或可用于UAV上的芯片,上述的第二终端设备例如可以为5G无线通信网络使能无人机系统的UAVC或可用于UAVC上的芯片。另一种可能的实现方式中,上述的第一终端设备例如可以为5G无线通信网络使能无人机系统的UAVC或可用于UAVC上的芯片,上述的第二终端设备例如可以为5G无线通信网络使能无人机系统的UAV或可用于UAV上的芯 片。当然,上述的第一终端设备和第二终端设备还可以为能用于实现C2通信或者类似C2通信的其他终端设备,例如遥控汽车驾驶,遥控工业机械,监控回传等场景下的终端设备,本申请实施例对此不做具体限定。Optionally, the terminal device (including the above-mentioned first terminal device or the second terminal device) in this embodiment of the present application may be a device for implementing a wireless communication function, such as a terminal or a chip that can be used in the terminal, etc., which may be Deployed on land, including indoor or outdoor, handheld or vehicle; can also be deployed on water (such as ships, etc.); can also be deployed in the air (such as aircraft, balloons and satellites, etc.). In a possible implementation manner, the above-mentioned first terminal device may be, for example, a 5G wireless communication network-enabled UAV or a chip that can be used on the UAV, and the above-mentioned second terminal device may be, for example, a 5G wireless communication network. UAV-enabled UAVC or chip that can be used on UAVC. In another possible implementation manner, the above-mentioned first terminal device may be, for example, a UAVC of a 5G wireless communication network-enabled unmanned aerial vehicle system or a chip that can be used on a UAVC, and the above-mentioned second terminal device may be, for example, a 5G wireless communication Network-enabled UAVs for unmanned aerial systems or chips that can be used on UAVs. Of course, the above-mentioned first terminal device and second terminal device may also be other terminal devices that can be used to implement C2 communication or similar to C2 communication, such as terminal devices in scenarios such as remote control of car driving, remote control of industrial machinery, and monitoring backhaul. This embodiment of the present application does not specifically limit this.
可选的,本申请实施例中的RAN设备,是一种为终端设备提供无线通信功能的设备。接入网设备例如包括但不限于:5G中的下一代基站(gnodeB,gNB)、演进型节点B(evolved node B,eNB)、无线网络控制器(radio network controller,RNC)、节点B(node B,NB)、基站控制器(base station controller,BSC)、基站收发台(base transceiver station,BTS)、家庭基站(例如,home evolved nodeB,或home node B,HNB)、基带单元(baseBand unit,BBU)、传输点(transmitting and receiving point,TRP)、发射点(transmitting point,TP)、移动交换中心等。Optionally, the RAN device in this embodiment of the present application is a device that provides a wireless communication function for a terminal device. Access network equipment includes, but is not limited to, next-generation base stations (gnodeB, gNB), evolved node B (evolved node B, eNB), radio network controller (radio network controller, RNC), node B (node B) in 5G. B, NB), base station controller (BSC), base transceiver station (base transceiver station, BTS), home base station (for example, home evolved nodeB, or home node B, HNB), baseband unit (baseBand unit, BBU), transmission point (transmitting and receiving point, TRP), transmitting point (transmitting point, TP), mobile switching center, etc.
可选的,本申请实施例中的管理设备、第一会话管理实体或第二会话管理实体也可以称之为通信装置,其可以是一个通用设备或者是一个专用设备,本申请实施例对此不作具体限定。Optionally, the management device, the first session management entity, or the second session management entity in this embodiment of the present application may also be referred to as a communication device, which may be a general-purpose device or a dedicated device. There is no specific limitation.
可选的,本申请实施例中的管理设备、第一会话管理实体或第二会话管理实体的相关功能可以由一个设备实现,也可以由多个设备共同实现,还可以是由一个设备内的一个或多个功能模块实现,本申请实施例对此不作具体限定。可以理解的是,上述功能既可以是硬件设备中的网络元件,也可以是在专用硬件上运行的软件功能,或者是硬件与软件的结合,或者是平台(例如,云平台)上实例化的虚拟化功能。Optionally, the related functions of the management device, the first session management entity, or the second session management entity in this embodiment of the present application may be implemented by one device, may be implemented jointly by multiple devices, or may be implemented by a device within one device. One or more functional modules are implemented, which is not specifically limited in this embodiment of the present application. It is to be understood that the above-mentioned functions can be either network elements in hardware devices, or software functions running on dedicated hardware, or a combination of hardware and software, or instantiated on a platform (eg, a cloud platform). Virtualization capabilities.
例如,本申请实施例中的管理设备、第一会话管理实体或第二会话管理实体的相关功能可以通过图4中的通信装置400来实现。图4所示为本申请实施例提供的通信装置400的结构示意图。该通信装置400包括一个或多个处理器401,通信线路402,以及至少一个通信接口(图4中仅是示例性的以包括通信接口404,以及一个处理器401为例进行说明),可选的还可以包括存储器403。For example, the related functions of the management device, the first session management entity, or the second session management entity in the embodiment of the present application may be implemented by the communication apparatus 400 in FIG. 4 . FIG. 4 is a schematic structural diagram of a communication apparatus 400 according to an embodiment of the present application. The communication device 400 includes one or more processors 401, a communication line 402, and at least one communication interface (in FIG. 4, the communication interface 404 and one processor 401 are used as an example for illustration only), optional may also include memory 403 .
处理器401可以是一个通用中央处理器(central processing unit,CPU),微处理器,特定应用集成电路(application-specific integrated circuit,ASIC),或一个或多个用于控制本申请方案程序执行的集成电路。The processor 401 may be a general-purpose central processing unit (central processing unit, CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more processors for controlling the execution of the programs of the present application. integrated circuit.
通信线路402可包括一通路,用于连接不同组件之间。 Communication line 402 may include a path for connecting the various components.
通信接口404,可以是收发模块用于与其他设备或通信网络通信,如以太网,RAN,无线局域网(wireless local area networks,WLAN)等。例如,所述收发模块可以是收发器、收发机一类的装置。可选的,所述通信接口404也可以是位于处理器401内的收发电路,用以实现处理器的信号输入和信号输出。The communication interface 404 can be a transceiver module for communicating with other devices or communication networks, such as Ethernet, RAN, wireless local area networks (wireless local area networks, WLAN) and the like. For example, the transceiver module may be a device such as a transceiver or a transceiver. Optionally, the communication interface 404 may also be a transceiver circuit located in the processor 401 to implement signal input and signal output of the processor.
存储器403可以是具有存储功能的装置。例如可以是只读存储器(read-only memory,ROM)或可存储静态信息和指令的其他类型的静态存储设备,随机存取存储器(random access memory,RAM)或者可存储信息和指令的其他类型的动态存储设备,也可以是电可擦可编程只读存储器(electrically erasable programmable read-only memory,EEPROM)、只读光盘(compact disc read-only memory,CD-ROM)或其他光盘存储、光碟存储(包括压缩光碟、激光碟、光碟、数字通用光碟、蓝光光碟等)、磁盘存储介质或者其他磁存储设备、或者能够用于携带或存储具有指令或数据结构形式的期望的程序代码并能够由计算机存取的任何其他介质,但不限于此。存储器可以 是独立存在,通过通信线路402与处理器相连接。存储器也可以和处理器集成在一起。The memory 403 may be a device having a storage function. For example, it may be read-only memory (ROM) or other types of static storage devices that can store static information and instructions, random access memory (RAM) or other types of storage devices that can store information and instructions The dynamic storage device can also be electrically erasable programmable read-only memory (electrically erasable programmable read-only memory, EEPROM), compact disc read-only memory (CD-ROM) or other optical disk storage, optical disk storage ( including compact discs, laser discs, compact discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or capable of carrying or storing desired program code in the form of instructions or data structures and capable of being stored by a computer any other medium taken, but not limited to this. The memory may be separate and connected to the processor through communication line 402. The memory can also be integrated with the processor.
其中,存储器403用于存储执行本申请方案的计算机执行指令,并由处理器401来控制执行。处理器401用于执行存储器403中存储的计算机执行指令,从而实现本申请实施例中提供的通信方法。The memory 403 is used for storing computer-executed instructions for executing the solution of the present application, and the execution is controlled by the processor 401 . The processor 401 is configured to execute the computer-executed instructions stored in the memory 403, so as to implement the communication method provided in the embodiments of the present application.
或者,可选的,本申请实施例中,也可以是处理器401执行本申请下述实施例提供的通信方法中的处理相关的功能,通信接口404负责与其他设备或通信网络通信,本申请实施例对此不作具体限定。Or, optionally, in this embodiment of the present application, the processor 401 may also perform processing-related functions in the communication methods provided in the following embodiments of the present application, and the communication interface 404 is responsible for communicating with other devices or communication networks. The embodiment does not specifically limit this.
可选的,本申请实施例中的计算机执行指令也可以称之为应用程序代码,本申请实施例对此不作具体限定。Optionally, the computer-executed instructions in the embodiment of the present application may also be referred to as application code, which is not specifically limited in the embodiment of the present application.
在具体实现中,作为一种实施例,处理器401可以包括一个或多个CPU,例如图4中的CPU0和CPU1。In a specific implementation, as an embodiment, the processor 401 may include one or more CPUs, such as CPU0 and CPU1 in FIG. 4 .
在具体实现中,作为一种实施例,通信装置400可以包括多个处理器,例如图4中的处理器401和处理器408。这些处理器中的每一个可以是一个单核(single-core)处理器,也可以是一个多核(multi-core)处理器。这里的处理器可以包括但不限于以下至少一种:中央处理单元(central processing unit,CPU)、微处理器、数字信号处理器(DSP)、微控制器(microcontroller unit,MCU)、或人工智能处理器等各类运行软件的计算设备,每种计算设备可包括一个或多个用于执行软件指令以进行运算或处理的核。In a specific implementation, as an embodiment, the communication apparatus 400 may include multiple processors, such as the processor 401 and the processor 408 in FIG. 4 . Each of these processors can be a single-core processor or a multi-core processor. The processor here may include, but is not limited to, at least one of the following: a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), a microcontroller (MCU), or artificial intelligence Processors and other types of computing devices that run software, each computing device may include one or more cores for executing software instructions to perform operations or processing.
在具体实现中,作为一种实施例,通信装置400还可以包括输出设备405和输入设备406。输出设备405和处理器401通信,可以以多种方式来显示信息。例如,输出设备405可以是液晶显示器(liquid crystal display,LCD),发光二级管(light emitting diode,LED)显示设备,阴极射线管(cathode ray tube,CRT)显示设备,或投影仪(projector)等。输入设备406和处理器401通信,可以以多种方式接收用户的输入。例如,输入设备406可以是鼠标、键盘、触摸屏设备或传感设备等。In a specific implementation, as an embodiment, the communication apparatus 400 may further include an output device 405 and an input device 406 . The output device 405 is in communication with the processor 401 and can display information in a variety of ways. For example, the output device 405 may be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector (projector) Wait. Input device 406 is in communication with processor 401 and can receive user input in a variety of ways. For example, the input device 406 may be a mouse, a keyboard, a touch screen device, a sensor device, or the like.
上述的通信装置400有时也可以称为通信装置,其可以是一个通用设备或者是一个专用设备。例如通信装置400可以是台式机、便携式电脑、网络服务器、掌上电脑(personal digital assistant,PDA)、移动手机、平板电脑、无线终端设备、嵌入式设备、上述终端设备,上述网络设备、或具有图4中类似结构的设备。本申请实施例不限定通信装置400的类型。The above-mentioned communication apparatus 400 may also be sometimes referred to as a communication apparatus, which may be a general-purpose device or a dedicated device. For example, the communication device 400 may be a desktop computer, a portable computer, a network server, a personal digital assistant (PDA), a mobile phone, a tablet computer, a wireless terminal device, an embedded device, the above-mentioned terminal device, the above-mentioned network device, or a 4 devices of similar structure. This embodiment of the present application does not limit the type of the communication apparatus 400 .
下面将结合附图,对本申请实施例提供的通信方法进行说明。The communication method provided by the embodiments of the present application will be described below with reference to the accompanying drawings.
如图5所示,为本申请实施例提供的一种通信方法,包括如下步骤:As shown in FIG. 5, a communication method provided by an embodiment of the present application includes the following steps:
S501、管理设备获取第一用户面安全保护开启指示,第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。其中,第一会话为第一终端设备用于承载C2通信的会话,第一终端设备为C2通信的发起端设备,第二终端设备为C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信。S501. The management device acquires a first user plane security protection enable instruction, where the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled. The first session is a session used by the first terminal device to carry the C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the first terminal device Communication with the second terminal device.
本申请实施例以及下述各实施例中,第一用户面安全保护开启指示的相关描述可参考发明内容部分,在此不再赘述。In the embodiments of the present application and the following embodiments, reference may be made to the content of the invention for a description of the first user plane security protection enabling indication, which will not be repeated here.
一种可能的实现方式中,管理设备获取第一用户面安全保护开启指示,包括:管理设备接收来自第一会话管理实体的第一用户面安全保护开启指示,第一会话管理实 体是为第一终端设备服务的会话管理实体。该方案的具体实现可参考图8或图9所示的实施例,在此不予赘述。In a possible implementation manner, obtaining the first user plane security protection opening instruction by the management device includes: the management device receiving the first user plane security protection opening instruction from the first session management entity, where the first session management entity is the first session management entity. The session management entity served by the terminal device. For the specific implementation of this solution, reference may be made to the embodiment shown in FIG. 8 or FIG. 9 , which will not be repeated here.
另一种可能的实现方式中,管理设备获取第一用户面安全保护开启指示,包括:管理设备接收来自第一终端设备的第一用户面安全保护开启指示。该方案的具体实现可参考图9所示的实施例,在此不予赘述。In another possible implementation manner, acquiring the first user plane security protection opening instruction by the management device includes: the management device receiving the first user plane security protection opening instruction from the first terminal device. For the specific implementation of this solution, reference may be made to the embodiment shown in FIG. 9 , which will not be repeated here.
又一种可能的实现方式中,管理设备获取第一用户面安全保护开启指示,包括:管理设备接收来自第一代理功能实体的第一用户面安全保护开启指示,第一代理功能实体用于提供第一会话管理实体到管理设备的接口。该方案的具体实现可参考图11所示的实施例,在此不予赘述。In another possible implementation manner, the obtaining of the first user plane security protection opening instruction by the management device includes: the management device receiving the first user plane security protection opening instruction from the first proxy function entity, and the first proxy function entity is used to provide The interface of the first session management entity to the management device. For the specific implementation of this solution, reference may be made to the embodiment shown in FIG. 11 , which will not be repeated here.
又一种可能的实现方式中,管理设备获取第一用户面安全保护开启指示,包括:管理设备确定第一终端设备与第二终端设备配对授权成功;管理设备向第一代理功能实体发送第三消息,第三消息包括第一终端设备的标识信息,第三消息用于请求第一用户面安全保护开启指示。其中,第一代理功能实体用于提供第一会话管理实体到管理设备的接口,第一会话管理实体是为第一终端设备服务的会话管理实体。管理设备接收来自第一代理功能实体的第一用户面安全保护开启指示。该方案的具体实现可参考图10或图11所示的实施例,在此不予赘述。In another possible implementation manner, the management device acquiring the first user plane security protection opening instruction includes: the management device determining that the pairing authorization between the first terminal device and the second terminal device is successful; the management device sending a third message, the third message includes identification information of the first terminal device, and the third message is used to request the first user plane security protection opening instruction. The first proxy function entity is used to provide an interface from the first session management entity to the management device, and the first session management entity is a session management entity serving the first terminal device. The management device receives the first user plane security protection opening instruction from the first proxy function entity. For the specific implementation of this solution, reference may be made to the embodiment shown in FIG. 10 or FIG. 11 , which will not be repeated here.
S502、管理设备触发第二终端设备发起第二会话的建立。其中,第二会话的用户面安全保护是否开启由第一用户面安全保护开启指示确定,第二会话为第二终端设备用于承载C2通信的会话。S502. The management device triggers the second terminal device to initiate the establishment of the second session. Wherein, whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction, and the second session is a session used by the second terminal device to carry the C2 communication.
一种可能的实现方式中,管理设备触发第二终端设备发起第二会话的建立,包括:管理设备向第二终端设备发送第一消息,第一消息用于触发第二终端设备发起第二会话的建立;以及,管理设备向第二统一数据管理实体发送第一用户面安全保护开启指示,其中,第二统一数据管理实体是为第二终端设备服务的统一数据管理实体。具体实现可参考图8所示的实施例,在此不予赘述。In a possible implementation manner, the management device triggering the second terminal device to initiate the establishment of the second session includes: the management device sends a first message to the second terminal device, where the first message is used to trigger the second terminal device to initiate the second session. and, the management device sends the first user plane security protection opening indication to the second unified data management entity, where the second unified data management entity is a unified data management entity serving the second terminal device. For specific implementation, reference may be made to the embodiment shown in FIG. 8 , which will not be repeated here.
另一种可能的实现方式中,管理设备触发第二终端设备发起第二会话的建立,包括:管理设备向第二终端设备发送第一消息,第一消息用于触发第二终端设备发起第二会话的建立;以及,管理设备接收来自第二代理功能实体的第二消息,并向第二代理功能实体发送第一用户面安全保护开启指示;其中,第二消息包括第二终端设备的标识信息,第二消息用于请求第一用户面安全保护开启指示,第二代理功能实体用于提供第二会话管理实体到管理设备的接口,第二会话管理实体是为第二终端设备服务的会话管理实体。具体实现可参考图8所示的实施例,在此不予赘述。In another possible implementation manner, the management device triggering the second terminal device to initiate the establishment of the second session includes: the management device sends a first message to the second terminal device, where the first message is used to trigger the second terminal device to initiate the second session. establishing a session; and, the management device receives a second message from the second proxy function entity, and sends the first user plane security protection opening instruction to the second proxy function entity; wherein, the second message includes the identification information of the second terminal device , the second message is used to request the first user plane security protection opening instruction, the second proxy function entity is used to provide the interface of the second session management entity to the management device, and the second session management entity is the session management for the second terminal device. entity. For specific implementation, reference may be made to the embodiment shown in FIG. 8 , which will not be repeated here.
本申请实施例提供的通信方法中,管理设备可以获取第一用户面安全保护开启指示,并触发第二终端设备发起第二会话的建立。其中,第二会话的用户面安全保护是否开启由第一用户面安全保护开启指示确定,同时第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。换言之,第一会话的用户面安全保护是否开启以及第二会话的用户面安全保护是否开启均是由第一用户面安全保护开启指示确定的。由于第一会话为第一终端设备用于承载第一终端设备与第二终端设备之间C2通信的会话,第二会话为第二终端设备用于承载该C2通信的会话。因此基于该方案,可以保证第一终端设备和第二终端设备之间的C2通信的用户面安全保护的一致性。In the communication method provided by the embodiment of the present application, the management device may acquire the first user plane security protection opening instruction, and trigger the second terminal device to initiate the establishment of the second session. Wherein, whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled. In other words, whether the user plane security protection of the first session is enabled and whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction. Since the first session is a session used by the first terminal device to carry the C2 communication between the first terminal device and the second terminal device, the second session is a session used by the second terminal device to carry the C2 communication. Therefore, based on this solution, the consistency of user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
其中,上述步骤S501至S502中管理设备的动作可以由图4所示的通信装置400中的处理器401调用存储器403中存储的应用程序代码以指令管理设备执行,本实施例对此不作任何限制。Wherein, the actions of the management device in the above steps S501 to S502 may be executed by the processor 401 in the communication apparatus 400 shown in FIG. 4 calling the application code stored in the memory 403 to instruct the management device to execute, which is not limited in this embodiment. .
如图6所示,为本申请实施例提供的一种通信方法,包括如下步骤:As shown in FIG. 6 , a communication method provided by an embodiment of the present application includes the following steps:
S601、第一会话管理实体获取第一用户面安全保护开启指示,第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。其中,第一会话为第一终端设备用于承载C2通信的会话,第一终端设备为C2通信的发起端设备,第二终端设备为C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信,第一会话管理实体是为第一终端设备服务的会话管理实体。S601. The first session management entity acquires a first user plane security protection enable instruction, where the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled. The first session is a session used by the first terminal device to carry the C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the first terminal device In the communication with the second terminal device, the first session management entity is a session management entity serving the first terminal device.
一种可能的实现方式中,第一会话管理实体获取第一用户面安全保护开启指示,包括:第一会话管理实体从为第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;第一会话管理实体向为第一终端设备服务的第一接入网设备发送第一用户面安全保护策略;第一会话管理实体接收来自第一接入网设备的第一用户面安全保护开启指示,其中,第一用户面安全保护开启指示是根据第一用户面安全保护策略确定的。In a possible implementation manner, obtaining the first user plane security protection enabling instruction by the first session management entity includes: the first session management entity obtains the first user plane security protection from a first unified data management entity serving the first terminal device. protection policy; the first session management entity sends the first user plane security protection policy to the first access network device serving the first terminal device; the first session management entity receives the first user plane security protection policy from the first access network device A protection opening instruction, wherein the first user plane security protection opening instruction is determined according to a first user plane security protection policy.
另一种可能的实现方式中,第一会话管理实体获取第一用户面安全保护开启指示,包括:第一会话管理实体从为第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;第一会话管理实体向为第一终端设备服务的第一接入网设备发送第一用户面安全保护策略;第一会话管理实体接收来自第一接入网设备的第七消息,第七消息用于指示第一接入网设备已经根据第一用户面安全保护策略建立第一会话;响应于第七消息,第一会话管理实体根据第一用户面安全保护策略确定该第一用户面安全保护开启指示。In another possible implementation manner, acquiring the first user plane security protection enabling instruction by the first session management entity includes: the first session management entity acquires the first user plane from a first unified data management entity serving the first terminal device a security protection policy; the first session management entity sends a first user plane security protection policy to the first access network device serving the first terminal device; the first session management entity receives the seventh message from the first access network device, The seventh message is used to indicate that the first access network device has established the first session according to the first user plane security protection policy; in response to the seventh message, the first session management entity determines the first user according to the first user plane security protection policy Face safety protection on instruction.
上述方案的具体实现可参考图8所示的实施例,在此不予赘述。For the specific implementation of the above solution, reference may be made to the embodiment shown in FIG. 8 , which will not be repeated here.
S602、第一会话管理实体发送第一用户面安全保护开启指示。第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,第二会话为第二终端设备用于承载C2通信的会话。S602. The first session management entity sends a first user plane security protection enabling instruction. The first user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is a session used by the second terminal device to carry the C2 communication.
一种可能的实现方式中,第一会话管理实体发送第一用户面安全保护开启指示,包括:第一会话管理实体向管理设备发送第一用户面安全保护开启指示。该方案的具体实现可参考图8或图9所示的实施例,在此不予赘述。In a possible implementation manner, sending the first user plane security protection opening instruction by the first session management entity includes: the first session management entity sending the first user plane security protection opening instruction to the management device. For the specific implementation of this solution, reference may be made to the embodiment shown in FIG. 8 or FIG. 9 , which will not be repeated here.
另一种可能的实现方式中,第一会话管理实体发送第一用户面安全保护开启指示,包括:第一会话管理实体向第一代理功能实体发送第一用户面安全保护开启指示;其中,第一代理功能实体用于提供第一会话管理实体到管理设备的接口。该方案的具体实现可参考图10或图11所示的实施例,在此不予赘述。可选的,在第一会话管理实体向第一代理功能实体发送第一用户面安全保护开启指示之前,该方法还包括:第一会话管理实体接收来自第一代理功能实体的第四消息,第四消息包括第一终端设备的标识信息,第四消息用于请求第一用户面安全保护开启指示。该方案的具体实现可参考图10所示的实施例,在此不予赘述。In another possible implementation manner, sending the first user plane security protection opening instruction by the first session management entity includes: the first session management entity sending the first user plane security protection opening instruction to the first proxy function entity; A proxy function entity is used to provide an interface from the first session management entity to the management device. For the specific implementation of this solution, reference may be made to the embodiment shown in FIG. 10 or FIG. 11 , which will not be repeated here. Optionally, before the first session management entity sends the first user plane security protection opening indication to the first proxy functional entity, the method further includes: the first session management entity receives a fourth message from the first proxy functional entity, and the first session management entity receives a fourth message from the first proxy functional entity. The fourth message includes identification information of the first terminal device, and the fourth message is used to request the first user plane security protection opening instruction. For the specific implementation of this solution, reference may be made to the embodiment shown in FIG. 10 , which will not be repeated here.
本申请实施例提供的通信方法中,第一会话管理实体获取第一用户面安全保护开启指示,并发送第一用户面安全保护开启指示。其中,第一用户面安全保护开启指示 用于确定第二会话的用户面安全保护是否开启,同时第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。换言之,第一会话的用户面安全保护是否开启以及第二会话的用户面安全保护是否开启均是由第一用户面安全保护开启指示确定的。由于第一会话为第一终端设备用于承载第一终端设备与第二终端设备之间C2通信的会话,第二会话为第二终端设备用于承载该C2通信的会话。因此基于该方案,可以保证第一终端设备和第二终端设备之间的C2通信的用户面安全保护的一致性。In the communication method provided by the embodiment of the present application, the first session management entity acquires the first user plane security protection opening instruction, and sends the first user plane security protection opening instruction. The first user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled. In other words, whether the user plane security protection of the first session is enabled and whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction. Since the first session is a session used by the first terminal device to carry the C2 communication between the first terminal device and the second terminal device, the second session is a session used by the second terminal device to carry the C2 communication. Therefore, based on this solution, the consistency of user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
其中,上述步骤S601至S602中第一会话管理实体的动作可以由图4所示的通信装置400中的处理器401调用存储器403中存储的应用程序代码以指令第一会话管理实体执行,本实施例对此不作任何限制。Wherein, the actions of the first session management entity in the above steps S601 to S602 may be executed by the processor 401 in the communication device 400 shown in FIG. 4 calling the application code stored in the memory 403 to instruct the first session management entity to execute. The example does not impose any restrictions on this.
如图7a所示,为本申请实施例提供的一种通信方法,包括如下步骤:As shown in FIG. 7a, a communication method provided by an embodiment of the present application includes the following steps:
S701a、第二会话管理实体获取第一用户面安全保护开启指示,第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,第一会话为第一终端设备用于承载C2通信的会话,第一终端设备为C2通信的发起端设备,第二终端设备为C2通信的对端设备,该C2通信为第一终端设备与第二终端设备之间的通信,第二会话管理实体是为第二终端设备服务的会话管理实体。S701a, the second session management entity acquires the first user plane security protection enable instruction, where the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled; wherein, the first session is used by the first terminal device For a session carrying C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the second terminal device, and the second terminal device is the peer device of the C2 communication. The second session management entity is a session management entity serving the second terminal device.
一种可能的实现方式中,第二会话管理实体获取第一用户面安全保护开启指示,包括:第二会话管理实体向为第二终端设备服务的第二统一数据管理实体发送第五消息,第五消息包括第二终端设备的标识信息,第五消息用于请求第二用户面安全保护策略;第二会话管理实体接收来自第二统一数据管理实体的第二用户面安全保护策略和第一用户面安全保护开启指示。该方案的具体实现可参考图8所示的实施例,在此不予赘述。In a possible implementation manner, the second session management entity acquiring the first user plane security protection opening instruction includes: the second session management entity sends a fifth message to the second unified data management entity serving the second terminal device, the first The fifth message includes the identification information of the second terminal device, and the fifth message is used to request the second user plane security protection policy; the second session management entity receives the second user plane security protection policy from the second unified data management entity and the first user Face safety protection on instruction. For the specific implementation of this solution, reference may be made to the embodiment shown in FIG. 8 , which will not be repeated here.
另一种可能的实现方式中,第二会话管理实体获取第一用户面安全保护开启指示,包括:第二会话管理实体向第二代理功能实体发送第六消息,第六消息包括第二终端设备的标识信息,第六消息用于请求第一用户面安全保护开启指示,第二代理功能实体用于提供第二会话管理实体到管理设备的接口。第二会话管理实体接收来自第二代理功能实体的第一用户面安全保护开启指示。可选的,在第二会话管理实体向第二代理功能实体发送第六消息之前,该方法还包括:第二会话管理实体接收来自第二终端设备的指示信息,指示信息指示第二终端设备请求建立的第二会话用于响应第一终端设备发起的C2通信。该方案的具体实现可参考图8所示的实施例,在此不予赘述。In another possible implementation manner, the second session management entity acquiring the first user plane security protection enabling instruction includes: the second session management entity sends a sixth message to the second proxy function entity, where the sixth message includes the second terminal device The sixth message is used to request the first user plane security protection opening instruction, and the second proxy function entity is used to provide an interface from the second session management entity to the management device. The second session management entity receives the first user plane security protection opening instruction from the second proxy function entity. Optionally, before the second session management entity sends the sixth message to the second proxy function entity, the method further includes: the second session management entity receives indication information from the second terminal device, where the indication information indicates that the second terminal device requests The established second session is used to respond to the C2 communication initiated by the first terminal device. For the specific implementation of this solution, reference may be made to the embodiment shown in FIG. 8 , which will not be repeated here.
S702a、第二会话管理实体向为第二终端设备服务的第二接入网设备发送第一用户面安全保护开启指示;其中,第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,第二会话为第二终端设备用于承载C2通信的会话。S702a. The second session management entity sends a first user plane security protection enable instruction to the second access network device serving the second terminal device; wherein the first user plane security protection enable instruction is used to determine the user plane of the second session Whether security protection is enabled, the second session is a session used by the second terminal device to carry C2 communication.
本申请实施例提供的通信方法中,第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,同时第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。换言之,第一会话的用户面安全保护是否开启以及第二会话的用户面安全保护是否开启均是由第一用户面安全保护开启指示确定的。由于第一会话为第一终端设备用于承载第一终端设备与第二终端设备之间C2通信的会话,第二会话为第二终端设备用于承载该C2通信的会话。因此基于该方案,可以保证第一终端设备和第二终端设备之间的C2通信的用户面安全保护的一致性。In the communication method provided by the embodiment of the present application, the first user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the first user plane security protection enable instruction is used to indicate the user plane of the first session. Whether security protection is enabled. In other words, whether the user plane security protection of the first session is enabled and whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction. Since the first session is a session used by the first terminal device to carry the C2 communication between the first terminal device and the second terminal device, the second session is a session used by the second terminal device to carry the C2 communication. Therefore, based on this solution, the consistency of user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
其中,上述步骤S701a至S702a中第二会话管理实体的动作可以由图4所示的通信装置400中的处理器401调用存储器403中存储的应用程序代码以指令第二会话管理实体执行,本实施例对此不作任何限制。Wherein, the actions of the second session management entity in the above steps S701a to S702a may be performed by the processor 401 in the communication device 400 shown in FIG. 4 calling the application code stored in the memory 403 to instruct the second session management entity to execute. The example does not impose any restrictions on this.
如图7b所示,为本申请实施例提供的一种通信方法,包括如下步骤:As shown in FIG. 7b, a communication method provided by an embodiment of the present application includes the following steps:
S701b、同步骤S701a,相关描述可参考图7a所示的实施例,在此不再赘述。S701b is the same as step S701a, and the related description may refer to the embodiment shown in FIG. 7a, which will not be repeated here.
S702b、第二会话管理实体根据第一用户面安全保护开启指示确定第三用户面安全保护策略,第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护。S702b, the second session management entity determines a third user plane security protection policy according to the first user plane security protection enabling instruction, and the third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection.
一种可能的实现方式中,本申请实施例中,第二会话管理实体根据第一用户面安全保护开启指示确定第三用户面安全保护策略的方案可参考前述发明内容部分,在此不再赘述。In a possible implementation manner, in this embodiment of the present application, for the solution in which the second session management entity determines the third user plane security protection policy according to the first user plane security protection enable instruction, reference may be made to the foregoing section of the content of the invention, and details are not repeated here. .
S703b、第二会话管理实体向为第二终端设备服务的第二接入网设备发送第三用户面安全保护策略。其中,第三用户面安全保护策略用于确定第二用户面安全保护开启指示,第二用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,第二会话为第二终端设备用于承载C2通信的会话。S703b: The second session management entity sends a third user plane security protection policy to the second access network device serving the second terminal device. The third user plane security protection policy is used to determine the second user plane security protection enable instruction, and the second user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is the second terminal A session used by the device to carry C2 communications.
本申请实施例以及下述各实施例中,第二用户面安全保护开启指示的相关描述可参考发明内容部分,在此不再赘述。In the embodiments of the present application and the following embodiments, reference may be made to the content of the invention for the relevant description of the indication of enabling the security protection of the second user plane, which will not be repeated here.
本申请实施例提供的通信方法中,第三用户面安全保护策略用于确定指示第二会话的用户面安全保护是否开启的第二用户面安全保护开启指示,而第三用户面安全保护策略是由指示第一会话的用户面安全保护是否开启的第一用户面安全保护开启指示确定的,且第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护。换言之,第一会话的用户面安全保护是否开启以及第二会话的用户面安全保护是否开启均是由第一用户面安全保护开启指示确定的。由于第一会话为第一终端设备用于承载第一终端设备与第二终端设备之间C2通信的会话,第二会话为第二终端设备用于承载该C2通信的会话。因此基于该方案,可以保证第一终端设备和第二终端设备之间的C2通信的用户面安全保护的一致性。In the communication method provided by the embodiment of the present application, the third user plane security protection policy is used to determine the second user plane security protection enable instruction indicating whether the user plane security protection of the second session is enabled, and the third user plane security protection policy is It is determined by the first user plane security protection enable instruction indicating whether the user plane security protection of the first session is enabled, and the third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection. In other words, whether the user plane security protection of the first session is enabled and whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction. Since the first session is a session used by the first terminal device to carry the C2 communication between the first terminal device and the second terminal device, the second session is a session used by the second terminal device to carry the C2 communication. Therefore, based on this solution, the consistency of user plane security protection of the C2 communication between the first terminal device and the second terminal device can be guaranteed.
其中,上述步骤S701b至S703b中第二会话管理实体的动作可以由图4所示的通信装置400中的处理器401调用存储器403中存储的应用程序代码以指令第二会话管理实体执行,本实施例对此不作任何限制。Wherein, the actions of the second session management entity in the above steps S701b to S703b may be executed by the processor 401 in the communication device 400 shown in FIG. 4 calling the application code stored in the memory 403 to instruct the second session management entity to execute. The example does not impose any restrictions on this.
下面以图2a至图2c所述的通信系统应用于如图3所示的5G网络,第一终端设备为UAV,第二终端设备为UAVC,管理设备为UTM/USS,为第一终端设备服务的第一接入网设备为RAN设备1,为第二终端设备服务的第二接入网设备为RAN设备2,为第一终端设备服务的第一会话管理实体为SMF1,为第二终端设备服务的第二会话管理实体为SMF2,为第一终端设备服务的第一统一数据管理实体为UDM1,为第二终端设备服务的第二统一数据管理实体为UDM2,为第一终端设备服务的第一代理功能实体为UFES1,为第二终端设备服务的第二代理功能实体为UFES2为例,对本申请实施例提供的通信方法进行详细阐述。当然,本申请实施例中,也可以是第一终端设备为UAVC,第二终端设备为UAV,此时仅需将下述实施例中的UAV和UAVC的操作调换而已,在此统一说明,以下不再赘述。The communication system described in Figures 2a to 2c is applied to the 5G network shown in Figure 3 below. The first terminal device is UAV, the second terminal device is UAVC, and the management device is UTM/USS, serving the first terminal device. The first access network device is RAN device 1, the second access network device serving the second terminal device is RAN device 2, and the first session management entity serving the first terminal device is SMF1, which is the second terminal device. The second session management entity serving is SMF2, the first unified data management entity serving the first terminal device is UDM1, the second unified data management entity serving the second terminal device is UDM2, and the first unified data management entity serving the first terminal device is UDM2. The first proxy function entity is UFES1, and the second proxy function entity serving the second terminal device is UFES2 as an example, and the communication method provided by the embodiment of the present application is described in detail. Of course, in the embodiment of the present application, the first terminal device may also be a UAVC, and the second terminal device may be a UAV. In this case, the operations of the UAV and UAVC in the following embodiments only need to be exchanged. No longer.
需要说明的是,本申请下述实施例中各个网元之间的消息名字或消息中各参数的 名字等只是一个示例,具体实现中也可以是其他的名字,本申请实施例对此不作具体限定。It should be noted that the names of messages between network elements or the names of parameters in the messages in the following embodiments of the present application are just an example, and other names may also be used in specific implementations, which are not specified in the embodiments of the present application. limited.
需要说明的是,本申请下述示例均以3GPP网络和UTM/USS之间存在UFES,UFES为独立的网元为例进行说明。当然,UFES也可以为现有3GPP网元的一部分功能(例如NEF的一部分功能),此时下述示例中UFES与3GPP网络或UTM/USS交互的流程可以替换为该3GPP网元(例如NEF)与3GPP网络或UTM/USS交互,在此统一说明,以下不再赘述。It should be noted that, the following examples of this application are all described by taking the UFES existing between the 3GPP network and the UTM/USS, and the UFES being an independent network element as an example. Of course, the UFES can also be a part of the functions of the existing 3GPP network element (for example, a part of the functions of the NEF). In this case, in the following example, the process of the interaction between the UFES and the 3GPP network or the UTM/USS can be replaced by the 3GPP network element (for example, NEF) and the The 3GPP network or UTM/USS interaction is described in a unified manner here, and will not be repeated below.
一种可能的实现方式中,UTM/USS可以在UAV建立用于承载UAV与UAVC之间的C2通信(以下将UAV与UAVC之间的C2通信简称C2通信)的第一PDU会话的过程中获取用于指示第一PDU会话的用户面安全保护是否开启的第一用户面安全保护开启指示。进一步的,为UAVC服务的SMF2可以在UAVC建立用于承载C2通信的第二PDU会话的过程中获取该第一用户面安全保护开启指示。示例性的,如图8所示,为本申请实施例提供的一种通信方法,该通信方法包括UAV和UAVC在3GPP网络的注册流程,如下述步骤S801a与步骤S801b:In a possible implementation manner, the UTM/USS may be acquired during the process of the UAV establishing the first PDU session for carrying the C2 communication between the UAV and the UAVC (hereinafter referred to as the C2 communication between the UAV and the UAVC). The first user plane security protection enable indication is used to indicate whether the user plane security protection of the first PDU session is enabled. Further, the SMF2 serving the UAVC may acquire the first user plane security protection opening indication during the process of establishing the second PDU session for carrying the C2 communication by the UAVC. Exemplarily, as shown in FIG. 8 , a communication method is provided in an embodiment of the present application. The communication method includes a registration process of UAV and UAVC in a 3GPP network, such as the following steps S801a and S801b:
S801a、UAV注册到3GPP网络,具体注册过程可参考现有技术,在此不再赘述。S801a, the UAV is registered to the 3GPP network, and the specific registration process may refer to the prior art, which will not be repeated here.
其中,在本申请实施例中,UAV可以在注册到3GPP网络的过程中获取3GPP网络为UAV分配的3GPP设备ID(后续简称3GPP UAV ID),该3GPP UAV ID用于在UAV注册的3GPP网络唯一标识该UAV。示例性的,该3GPP UAV ID例如可以为签约永久标识(subscription permanent identifier,SUPI)或者签约隐藏标识(subscription concealed identifier,SUCI)。Wherein, in the embodiment of the present application, the UAV can obtain the 3GPP device ID (hereinafter referred to as 3GPP UAV ID) allocated by the 3GPP network for the UAV during the process of registering with the 3GPP network, and the 3GPP UAV ID is used for the unique 3GPP network registered in the UAV. Identifies this UAV. Exemplarily, the 3GPP UAV ID may be, for example, a subscription permanent identifier (SUPI) or a subscription concealed identifier (SUCI).
S801b、UAVC注册到3GPP网络,具体注册过程可参考现有技术,在此不再赘述。S801b and UAVC are registered to the 3GPP network, and the specific registration process may refer to the prior art, which will not be repeated here.
其中,在本申请实施例中,UAVC可以在注册到3GPP网络的过程中获取3GPP网络为UAVC分配的3GPP设备ID(后续简称3GPP UAVC ID),该3GPP UAVC ID用于在UAVC注册的3GPP网络唯一标识该UAVC。示例性的,该3GPP UAVC ID例如可以为SUPI或者SUCI。Wherein, in the embodiment of the present application, the UAVC can obtain the 3GPP device ID (hereinafter referred to as the 3GPP UAVC ID) allocated by the 3GPP network for the UAVC during the process of registering with the 3GPP network, and the 3GPP UAVC ID is used for the unique 3GPP network registered in the UAVC. Identifies this UAVC. Exemplarily, the 3GPP UAVC ID may be, for example, SUPI or SUCI.
需要说明的是,本申请实施例中,UAV注册的3GPP网络与UAVC注册的3GPP网络可能是相同的3GPP网络,也可能是不同的3GPP网络,本申请实施例对此不做具体限定。It should be noted that, in the embodiment of the present application, the 3GPP network registered by the UAV and the 3GPP network registered by the UAVC may be the same 3GPP network or different 3GPP networks, which are not specifically limited in the embodiment of the present application.
需要说明的是,本申请实施例中的UAV和UAVC除了可以获取上述各自的3GPP设备ID之外,UAV和UAVC还分别预配置有外部UAV ID。这里的外部UAV ID是由非3GPP网络分配的,例如民航局(civil aviation authority,CAA)为UAV或UAVC分配的UAV ID。It should be noted that, in addition to the above-mentioned respective 3GPP device IDs, the UAVs and UAVCs in the embodiments of the present application are also preconfigured with external UAV IDs, respectively. The external UAV ID here is assigned by a non-3GPP network, such as the UAV ID assigned by the Civil Aviation Authority (CAA) for UAV or UAVC.
进一步的,本申请实施例提供的通信方法还包括UAV触发建立第一PDU会话的流程,如下述步骤S802-S813:Further, the communication method provided by the embodiment of the present application further includes a process of triggering the establishment of a first PDU session by the UAV, as follows in steps S802-S813:
S802、UAV向3GPP网络中的SMF1发送会话建立请求1。相应的,SMF1接收来自UAV的会话建立请求1。该会话建立请求1包括3GPP UAV ID和指示信息1,指示信息1用于指示UAV请求建立的第一PDU会话用于承载C2通信。S802, the UAV sends a session establishment request 1 to the SMF1 in the 3GPP network. Accordingly, SMF1 receives session establishment request 1 from the UAV. The session establishment request 1 includes a 3GPP UAV ID and indication information 1, where the indication information 1 is used to indicate that the first PDU session that the UAV requests to establish is used to bear C2 communication.
一种可能的实现方式中,指示信息1可以为显示指示。比如,指示信息1可以为 UAS操作请求指示(UAS operation request indication),该UAS操作请求指示为C2请求,用于显示指示UAV请求建立的第一PDU会话用于承载C2通信。可选的,本申请实施例中,UAS操作请求指示还可以指示该C2请求为主动C2请求。In a possible implementation manner, the indication information 1 may be a display indication. For example, the indication information 1 may be a UAS operation request indication (UAS operation request indication), and the UAS operation request indication is a C2 request, which is used to display and indicate that the first PDU session established by the UAV request is used to carry the C2 communication. Optionally, in this embodiment of the present application, the UAS operation request indication may further indicate that the C2 request is an active C2 request.
另一种可能的实现方式中,指示信息1可以为隐式指示。比如,指示信息1可以为专用于C2通信的数据网络名称(data network name,DNN)信息,或者专用于C2通信的DNN和切片组合信息等。In another possible implementation manner, the indication information 1 may be an implicit indication. For example, the indication information 1 may be data network name (data network name, DNN) information dedicated to C2 communication, or DNN and slice combination information dedicated to C2 communication, and the like.
当然,若在步骤S802之前,UAV和UAVC已经线下通过非3GPP方式配对(例如两设备通过蓝牙配对)或者通过其他方式配对,则UAV可以获取与其配对的UAVC的配对标识。进一步的,会话建立请求1中可以包括UAVC的配对标识,UAVC的配对标识可以用来隐式指示UAV请求建立的第一PDU会话用于承载C2通信。示例性的,UAVC的配对标识例如可以为3GPP UAVC ID或者UAVC的外部UAV ID。Of course, if the UAV and the UAVC have been paired offline in a non-3GPP manner (for example, the two devices are paired via Bluetooth) or in other manners before step S802, the UAV can obtain the pairing identifier of the UAVC paired with it. Further, the session establishment request 1 may include the pairing identifier of the UAVC, and the pairing identifier of the UAVC may be used to implicitly indicate that the first PDU session established by the UAV request is used to carry the C2 communication. Exemplarily, the pairing identifier of the UAVC may be, for example, the 3GPP UAVC ID or the external UAV ID of the UAVC.
可选的,本申请实施例中,当UAVC的配对标识为UAVC的外部UAV ID时,UAVC的外部UAV ID可以包括在会话建立请求1的容器(container)中。这样,一方面,由于中间节点透传container不篡改container中内容,因此可以保证上述参数的安全性;另一方面,由于中间节点可以不解析上述参数,因此可以节省中间节点的处理资源,以及提高中间节点的处理效率。Optionally, in this embodiment of the present application, when the pairing identifier of the UAVC is the external UAV ID of the UAVC, the external UAV ID of the UAVC may be included in the container (container) of the session establishment request 1. In this way, on the one hand, since the intermediate node transparently transmits the container without tampering with the contents in the container, the security of the above parameters can be guaranteed; Processing efficiency of intermediate nodes.
S803、SMF1根据指示信息1,确定UAV请求建立的第一PDU会话用于承载C2通信之后,从UDM1获取第一用户面安全保护策略,该第一用户面安全保护策略用于建立第一PDU会话。S803. After determining that the first PDU session requested to be established by the UAV is used to carry the C2 communication according to the indication information 1, the SMF1 obtains the first user plane security protection policy from the UDM1, where the first user plane security protection policy is used to establish the first PDU session .
本申请实施例中,第一用户面安全保护策略的相关描述可参考具体实施方式前序部分“用户面安全保护策略”的描述,在此不再赘述。In this embodiment of the present application, for the relevant description of the first user plane security protection policy, reference may be made to the description of the "user plane security protection policy" in the preamble of the specific implementation manner, and details are not repeated here.
一种可能的实现方式中,SMF1根据指示信息1,确定UAV请求建立的第一PDU会话用于C2通信之后,向UDM1发送请求消息。该请求消息包括3GPP UAV ID,该请求消息用于请求第一用户面安全保护策略。UDM1接收该请求消息之后,根据3GPP UAV ID确定第一用户面安全保护策略,并在向SMF1发送的响应消息中携带第一用户面安全保护策略。In a possible implementation manner, the SMF1 sends a request message to the UDM1 after determining, according to the indication information 1, that the first PDU session requested by the UAV is used for the C2 communication. The request message includes the 3GPP UAV ID, and the request message is used to request the first user plane security protection policy. After receiving the request message, UDM1 determines the first user plane security protection policy according to the 3GPP UAV ID, and carries the first user plane security protection policy in the response message sent to SMF1.
S804、SMF1向RAN设备1发送第一用户面安全保护策略。相应的,RAN设备1接收来自SMF1的第一用户面安全保护策略。S804 , the SMF1 sends the first user plane security protection policy to the RAN device 1 . Correspondingly, the RAN device 1 receives the first user plane security protection policy from the SMF1.
S805、RAN设备1根据第一用户面安全保护策略确定第一用户面安全保护开启指示,第一用户面安全保护开启指示用于指示第一PDU会话的用户面安全保护是否开启。S805. The RAN device 1 determines the first user plane security protection enable instruction according to the first user plane security protection policy, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first PDU session is enabled.
本申请实施例中,RAN设备1根据第一用户面安全保护策略确定第一用户面安全保护开启指示时,可以结合其他信息(如第一接入网设备上资源的使用情况或第一终端设备可以支持的最大完整性保护速率)确定。In the embodiment of the present application, when the RAN device 1 determines the first user plane security protection enable instruction according to the first user plane security protection policy, it may combine other information (such as the usage of resources on the first access network device or the first terminal device The maximum integrity protection rate that can be supported) is determined.
比如,当第一用户面安全保护策略包括用户面机密性保护为可选开启以及用户面完整性保护为可选开启;RAN设备1当前比较空闲,有足够的资源为UAV的用户面数据提供安全保护,则RAN设备1可以确定开启用户面机密性保护和用户面完整性保护,即第一用户面安全保护开启指示用于指示用户面机密性保护开启且用户面完整性保护开启。又比如,当第一用户面安全保护策略包括用户面机密性保护为可选开启以及用户面完整性保护为可选开启;RAN设备1当前没有足够的资源为UAV的用户面 数据提供安全保护,则RAN设备1可以确定不开启用户面机密性保护和用户面完整性保护,即第一用户面安全保护开启指示用于指示用户面机密性保护不开启且用户面完整性保护不开启。For example, when the first user plane security protection policy includes that user plane confidentiality protection is optionally enabled and user plane integrity protection is optionally enabled; RAN device 1 is currently idle and has sufficient resources to provide security for UAV user plane data protection, the RAN device 1 may determine to enable user plane confidentiality protection and user plane integrity protection, that is, the first user plane security protection enable instruction is used to indicate that user plane confidentiality protection and user plane integrity protection are enabled. For another example, when the first user plane security protection policy includes that the user plane confidentiality protection is optionally enabled and the user plane integrity protection is optionally enabled; the RAN device 1 currently does not have enough resources to provide security protection for the user plane data of the UAV, Then the RAN device 1 may determine not to enable the user plane confidentiality protection and the user plane integrity protection, that is, the first user plane security protection enable instruction is used to indicate that the user plane confidentiality protection and the user plane integrity protection are not enabled.
比如,本申请实施例中,当第一用户面安全保护策略包括用户面机密性保护为强制开启以及用户面完整性保护为强制开启,且RAN设备1当前比较空闲,有足够的资源为UAV的用户面数据提供安全保护,则RAN设备1可以确定开启用户面机密性保护和开启用户面完整性保护,即第一用户面安全保护开启指示用于指示用户面机密性保护开启且用户面完整性保护开启。又比如,第一用户面安全保护策略包括用户面机密性保护为强制不开启以及用户面完整性保护为强制不开启,则RAN设备1可以确定不开启用户面机密性保护和不开启用户面完整性保护,即第一用户面安全保护开启指示用于指示用户面机密性保护不开启且用户面完整性保护不开启,其他情况类似,不再赘述。For example, in the embodiment of the present application, when the first user plane security protection policy includes that the user plane confidentiality protection is forcibly turned on and the user plane integrity protection is forcibly turned on, and the RAN device 1 is currently idle, there are enough resources for UAV The user plane data provides security protection, then the RAN device 1 can determine to enable the user plane confidentiality protection and the user plane integrity protection, that is, the first user plane security protection enable instruction is used to indicate that the user plane confidentiality protection is enabled and the user plane integrity protection is enabled. Protection is on. For another example, the first user plane security protection policy includes that the user plane confidentiality protection is forcibly disabled and the user plane integrity protection is forcibly disabled, then the RAN device 1 may determine that the user plane confidentiality protection is not enabled and the user plane integrity protection is disabled. The security protection of the first user plane is used to indicate that the confidentiality protection of the user plane is not enabled and the integrity protection of the user plane is not enabled. The other situations are similar and will not be repeated here.
当然,本申请实施例中,当第一用户面安全保护策略包括用户面机密性保护为强制开启以及用户面完整性保护为强制开启,但是RAN设备1当前没有足够的资源为UAV的用户面数据提供安全保护时,RAN设备1可以确定拒绝第一PDU会话的建立,进而RAN设备可以向SMF1发送拒绝第一PDU会话建立的指示,以终止后续流程,本申请实施例对该情况不做具体阐述。这样可以保证UAV侧的承载C2通信的路径上所有节点均可以支持第一用户面安全保护开启指示,从而保证UAV与UAVC之间的正常C2通信。Of course, in the embodiment of the present application, when the first user plane security protection policy includes that the user plane confidentiality protection is forcibly turned on and the user plane integrity protection is forcibly turned on, but the RAN device 1 currently does not have enough resources for the user plane data of the UAV When providing security protection, the RAN device 1 may determine to reject the establishment of the first PDU session, and then the RAN device may send an indication of rejecting the establishment of the first PDU session to the SMF1 to terminate the subsequent process, which is not specifically described in this embodiment of the present application . In this way, it can be ensured that all nodes on the path carrying the C2 communication on the UAV side can support the first user plane security protection opening instruction, thereby ensuring normal C2 communication between the UAV and the UAVC.
进一步的,在RAN设备1未拒绝第一PDU会话的建立的情况下,本申请实施例提供的通信方法还包括如下步骤S806:Further, in the case that the establishment of the first PDU session is not rejected by the RAN device 1, the communication method provided by the embodiment of the present application further includes the following step S806:
S806、RAN设备1向SMF1发送PDU会话资源建立响应传输(PDU session resource setup response transfer)消息。相应的,SMF1接收来自RAN设备1的PDU会话资源建立响应传输消息。该PDU会话资源建立响应传输消息用于指示RAN设备1已经根据第一用户面安全保护策略建立第一PDU会话。S806, RAN device 1 sends a PDU session resource setup response transfer (PDU session resource setup response transfer) message to SMF1. Correspondingly, the SMF1 receives the PDU session resource establishment response transmission message from the RAN device 1 . The PDU session resource establishment response transmission message is used to indicate that the RAN device 1 has established the first PDU session according to the first user plane security protection policy.
需要说明的是,本申请实施例中,RAN设备1向SMF1发送的PDU会话资源建立响应传输消息仅是图6所示的实施例中第七消息的一种示例,第七消息还可以为其他,本申请实施例对此不做具体限定。It should be noted that, in the embodiment of the present application, the PDU session resource establishment response transmission message sent by the RAN device 1 to the SMF1 is only an example of the seventh message in the embodiment shown in FIG. 6 , and the seventh message may also be other , which is not specifically limited in the embodiments of the present application.
在本申请实施例中,在第一用户面安全保护策略为可选开启安全保护的情况下,上述PDU会话资源建立响应传输消息包括第一用户面安全保护开启指示。当上述PDU会话资源建立响应传输消息不包括第一用户面安全保护开启指示时(即第一用户面安全保护策略为强制开启安全保护或强制不开启安全保护的情况下),本申请实施例提供的通信方法还包括如下步骤S807:In the embodiment of the present application, in the case that the first user plane security protection policy is optional to enable security protection, the above-mentioned PDU session resource establishment response transmission message includes the first user plane security protection enable instruction. When the above-mentioned PDU session resource establishment response transmission message does not include the first user plane security protection opening indication (that is, when the first user plane security protection policy is forcibly enabling security protection or forcibly not enabling security protection), the embodiments of the present application provide The communication method further includes the following steps S807:
S807、响应于PDU会话资源建立响应传输消息,SMF1根据第一用户面安全保护策略确定第一用户面安全保护开启指示。S807. In response to the PDU session resource establishment response transmission message, the SMF1 determines the first user plane security protection opening instruction according to the first user plane security protection policy.
即,本申请实施例中,第一用户面安全保护策略是确定性策略(例如第一用户面安全保护策略包括用户面机密性保护为强制开启/强制不开启以及用户面完整性保护为强制开启/强制不开启)时,RAN设备1可以不用明确的通知SMF1用户面安全保护的开启结果。当SMF1在确定第一会话已经建立的情况下,可以根据第一用户面安全 保护策略自己确定用户面机密性保护和用户面完整性保护是否开启。That is, in this embodiment of the present application, the first user plane security protection policy is a deterministic policy (for example, the first user plane security protection policy includes that the user plane confidentiality protection is forcibly turned on/not turned on and the user plane integrity protection is forcibly turned on /Forcibly disabled), the RAN device 1 may not explicitly notify the SMF1 of the result of enabling the security protection on the user plane. When SMF1 determines that the first session has been established, it can determine whether user plane confidentiality protection and user plane integrity protection are enabled according to the first user plane security protection policy.
基于上述步骤S806或步骤S807,SMF1可以获取第一用户面安全保护开启指示。进而,第一PDU会话建立流程还包括如下步骤:Based on the above step S806 or step S807, the SMF1 may acquire the first user plane security protection opening instruction. Furthermore, the first PDU session establishment process further includes the following steps:
S808、SMF1向UFES1发送消息1。相应的,UFES1接收来自SMF1的消息1。该消息1包括3GPP UAV ID和第一用户面安全保护开启指示。S808, SMF1 sends message 1 to UFES1. Correspondingly, UFES1 receives message 1 from SMF1. The message 1 includes the 3GPP UAV ID and the first user plane security protection opening indication.
S809、UFES1向UTM/USS发送消息2。相应的,UTM/USS接收来自UFES1的消息2。该消息2包括UAV的外部UAV ID和第一用户面安全保护开启指示。S809, UFES1 sends message 2 to the UTM/USS. Correspondingly, UTM/USS receives message 2 from UFES1. The message 2 includes the external UAV ID of the UAV and the first user plane security protection opening indication.
对于上述步骤S808-S809:For the above steps S808-S809:
一种可能的实现方式中,上述消息1和消息2可以为会话建立流程中用于配对授权的消息(如C2配对请求);或者上述消息1和消息2可以为会话建立流程中用于二次认证的消息,可选的,UAV可以借助该二次认证流程完成USS UAV认证授权(USS UAV authorization/authentication,UUAA)和/或配对授权;或者上述消息1和消息2可以为会话建立流程中用于UUAA的消息;或者上述消息1和消息2可以为会话建立流程中的其他现有消息或者新定义的消息,本申请实施例对此不做具体限定。In a possible implementation manner, the above message 1 and message 2 may be messages used for pairing authorization in the session establishment process (such as a C2 pairing request); or the above message 1 and message 2 may be used in the session establishment process for the second time. Authentication message, optionally, UAV can use this secondary authentication process to complete USS UAV authentication and authorization (USS UAV authorization/authentication, UUAA) and/or pairing authorization; or the above message 1 and message 2 can be used in the session establishment process. message for UUAA; or the above message 1 and message 2 may be other existing messages or newly defined messages in the session establishment process, which are not specifically limited in this embodiment of the present application.
另一种可能的实现方式中,在SMF1向UFES1发送消息1之前,SMF1向UFES1发送消息a。UFES1接收到来自SMF1的消息a之后,根据消息a确定UAV请求建立的第一PDU会话用于承载C2通信之后,向SMF1请求获取第一用户面安全保护开启指示。进而,SMF1向UFES1发送消息1。该场景下,消息a和消息2可以为会话建立流程中用于配对授权的消息(如C2配对请求);或者消息a和消息2可以为会话建立流程中用于二次认证的消息,可选的,UAV可以借助该二次认证流程完成UUAA和/或配对授权;或者消息a和消息2可以为会话建立流程中用于UUAA的消息;或者上述消息a和消息2可以为会话建立流程中的其他消息,本申请实施例对此不做具体限定。In another possible implementation manner, before SMF1 sends message 1 to UFES1, SMF1 sends message a to UFES1. After receiving message a from SMF1, UFES1 determines, according to message a, that the first PDU session requested by the UAV is used to carry C2 communication, and then requests SMF1 to obtain the first user plane security protection opening indication. Further, SMF1 sends message 1 to UFES1. In this scenario, message a and message 2 can be messages used for pairing authorization in the session establishment process (such as a C2 pairing request); or message a and message 2 can be messages used for secondary authentication in the session establishment process, optional Yes, UAV can complete UUAA and/or pairing authorization with the help of this secondary authentication process; or message a and message 2 can be the messages used for UUAA in the session establishment process; or the above message a and message 2 can be the messages in the session establishment process Other information is not specifically limited in this embodiment of the present application.
本申请实施例中,UFES1从3GPP网络获取3GPP UAV ID之后,可以根据存储的3GPP UAV ID与UAV的外部UAV ID的映射关系,将3GPP UAV ID“翻译”转化为UTM/USS能够识别的UAV的外部UAV ID,并将UAV的外部UAV ID发送给UTM/USS,在此统一说明,以下不再赘述。In the embodiment of this application, after UFES1 obtains the 3GPP UAV ID from the 3GPP network, it can “translate” the 3GPP UAV ID into a UAV ID that can be identified by UTM/USS according to the stored mapping relationship between the 3GPP UAV ID and the external UAV ID of the UAV. The external UAV ID, and the external UAV ID of the UAV is sent to the UTM/USS, which is explained here and will not be repeated below.
本申请实施例中,若上述会话建立请求1中包括UAVC的配对标识,则上述消息1和消息2中还包括该UAVC的配对标识。其中,当UAVC的配对标识为3GPP UAVC ID时,UFES1从3GPP网络获取3GPP UAVC ID之后,可以根据存储的3GPP UAVC ID与UAVC的外部UAV ID的映射关系,将3GPP UAVC ID“翻译”转化为UTM/USS能够识别的UAVC的外部UAV ID,并将UAVC的外部UAV ID发送给UTM/USS,在此统一说明,以下不再赘述。In this embodiment of the present application, if the above session establishment request 1 includes the pairing identifier of the UAVC, the above message 1 and message 2 also include the pairing identifier of the UAVC. Among them, when the pairing identifier of UAVC is 3GPP UAVC ID, after UFES1 obtains the 3GPP UAVC ID from the 3GPP network, it can “translate” the 3GPP UAVC ID into UTM according to the stored mapping relationship between the 3GPP UAVC ID and the external UAV ID of UAVC. /The external UAV ID of the UAVC that the USS can identify, and sends the external UAV ID of the UAVC to the UTM/USS, which is described here uniformly and will not be repeated below.
基于上述步骤S808或步骤S809,UTM/USS可以获取第一用户面安全保护开启指示。可选的,本申请实施例中,若C2配对授权是在第一PDU会话建立流程中实现的,则本申请实施例提供的通信方法还包括如下步骤S810:Based on the foregoing step S808 or step S809, the UTM/USS may acquire the first user plane security protection opening instruction. Optionally, in the embodiment of the present application, if the C2 pairing authorization is implemented in the first PDU session establishment process, the communication method provided by the embodiment of the present application further includes the following step S810:
S810、UTM/USS确定与UAV配对的UAVC在网后,对C2配对请求进行授权。S810: After the UTM/USS determines that the UAVC paired with the UAV is on the network, it authorizes the C2 pairing request.
需要说明的是,本申请实施例中,UAVC在网可以是UAVC与UTM/USS通过3GPP方式连接,进而使用3GPP接入方式执行UUAA流程以获得UTM/USS的认证授权; 或者,本申请实施例中,UAVC在网可以是UAVC与UTM/USS通过非3GPP方式连接,进而使用非3GPP接入方式获得UTM/USS的认证授权,本申请实施例对此不做具体限定。It should be noted that, in the embodiment of the present application, the UAVC on the network may be the UAVC and the UTM/USS connected through 3GPP, and then the 3GPP access method is used to execute the UUAA process to obtain the authentication and authorization of the UTM/USS; or, the embodiment of the present application In the UAVC network, the UAVC may be connected to the UTM/USS in a non-3GPP manner, and then use a non-3GPP access manner to obtain the authentication and authorization of the UTM/USS, which is not specifically limited in this embodiment of the present application.
一种可能的实现方式中,若在步骤S802之前,UAV和UAVC已经线下通过非3GPP方式配对(例如两设备通过蓝牙配对)或者通过其他方式配对,UTM/USS可以从接收到的消息中获得UAVC的外部UAV ID,并根据UAVC的外部UAV ID确定UAVC是否已经获得UTM/USS的认证授权。如果UAVC已经获得UTM/USS的认证授权,则UTM/USS可以确定UAVC在网。其中,UTM/USS从接收到的消息中获得UAVC的外部UAV ID的方式包括:解析接收到的消息中的container,获得container中包含的UAVC的外部UAV ID;或者,从接收到的消息中直接获得UAVC的外部UAV ID。In a possible implementation manner, if before step S802, UAV and UAVC have been paired offline in a non-3GPP manner (for example, two devices are paired via Bluetooth) or paired in other manners, UTM/USS can obtain from the received message. The external UAV ID of the UAVC, and according to the external UAV ID of the UAVC, determine whether the UAVC has been authorized by the UTM/USS. If the UAVC has been authorized by the UTM/USS, the UTM/USS can determine that the UAVC is on the network. Wherein, the way that the UTM/USS obtains the external UAV ID of the UAVC from the received message includes: parsing the container in the received message, and obtaining the external UAV ID of the UAVC contained in the container; or, directly from the received message Get the external UAV ID of the UAVC.
另一种可能的实现方式中,UAV和UAVC的配对关系可以存储在UTM/USS中(例如UAV和UAVC的生产商在设备出厂时将UAV和UAVC配对好,并将配对关系注册到UTM/USS中)。其中,该配对关系可以通过UAV的外部UAV ID和UAVC的外部UAV ID的映射关系进行表征。进而,UTM/USS根据接收到的UAV的外部UAV ID,以及UAV和UAVC的配对关系确定UAVC的外部UAV ID后,根据UAVC的外部UAV ID确定UAVC是否已经获得UTM/USS的认证授权。如果UAVC已经获得UTM/USS的认证授权,则UTM/USS可以确定UAVC在网。In another possible implementation, the pairing relationship between UAV and UAVC can be stored in UTM/USS (for example, the manufacturer of UAV and UAVC pairs UAV and UAVC when the device leaves the factory, and registers the pairing relationship in UTM/USS middle). The pairing relationship can be characterized by the mapping relationship between the external UAV ID of the UAV and the external UAV ID of the UAVC. Further, after the UTM/USS determines the external UAV ID of the UAVC according to the received external UAV ID of the UAV and the pairing relationship between the UAV and the UAVC, it determines whether the UAVC has obtained the authentication authorization of the UTM/USS according to the external UAV ID of the UAVC. If the UAVC has been authorized by the UTM/USS, the UTM/USS can determine that the UAVC is on the network.
本申请实施例中,UTM/USS对C2配对请求进行授权包括:UTM/USS根据获得UAVC的外部UAV ID和的UAV的外部UAV ID,确定UAV和UAVC是否匹配。In the embodiment of the present application, the UTM/USS authorizing the C2 pairing request includes: the UTM/USS determines whether the UAV and the UAVC match according to the obtained external UAV ID of the UAVC and the external UAV ID of the UAV.
本申请实施例中,UTM/USS确定UAV与UAVC的C2配对授权成功后,可以存储UAV的外部UAV ID、UAVC的外部UAV ID以及第一用户面安全保护开启指示的映射关系,以备后续使用。In the embodiment of the present application, after the UTM/USS determines that the C2 pairing authorization between the UAV and the UAVC is successful, it can store the mapping relationship between the external UAV ID of the UAV, the external UAV ID of the UAVC, and the first user plane security protection opening instruction for subsequent use. .
进一步的,本申请实施例提供的第一PDU会话建立流程还包括如下步骤:Further, the first PDU session establishment process provided by the embodiment of the present application further includes the following steps:
S811、第一PDU会话在3GPP网络与UTM/USS之间的其他建立流程,具体可参考现有技术,在此不再赘述。S811 . Other procedures for establishing the first PDU session between the 3GPP network and the UTM/USS may refer to the prior art for details, which will not be repeated here.
需要说明的是,本申请实施例中,若执行上述步骤S810,则第一PDU会话在3GPP网络与UTM/USS之间的其他建立流程中,UTM/USS需要通过UFES1向SMF1发送UAV与UAVC的C2配对授权成功的指示信息,进而SMF1可以获知UAV与UAVC的C2配对授权成功。当然,UAV与UAVC之间的C2配对授权也可以是在步骤S801a与步骤S801b中的注册流程中完成的。该场景下,在UAV与UAVC之间的C2配对授权成功的情况下,SMF1也可以获得UAV与UAVC的C2配对授权成功的指示信息,从而可以获知UAV与UAVC的C2配对授权成功。It should be noted that, in this embodiment of the present application, if the above step S810 is executed, in other establishment procedures between the 3GPP network and the UTM/USS for the first PDU session, the UTM/USS needs to send the UAV and UAVC information to the SMF1 through the UFES1. The indication information that the C2 pairing authorization is successful, and then the SMF1 can learn that the C2 pairing authorization of the UAV and the UAVC is successful. Of course, the C2 pairing authorization between the UAV and the UAVC may also be completed in the registration process in steps S801a and S801b. In this scenario, when the C2 pairing authorization between the UAV and the UAVC is successful, the SMF1 can also obtain the indication information that the C2 pairing authorization of the UAV and the UAVC is successful, so as to know that the C2 pairing authorization of the UAV and the UAVC is successful.
S812、SMF1确定第一PDU会话建立成功后,向RAN设备1发送会话建立接受消息1。相应的,RAN设备1接收来自SMF1的会话建立接受消息1。该会话建立接受消息1包括SMF1发送给UAV的N1会话管理容器(N1 session management container)以及SMF1发送给RAN设备1的和N2会话管理信息(N2 Session Management Information)。其中,N2会话管理信息包含第一PDU会话的会话标识信息、配置N3隧道的核心网隧道信息(CN Tunnel Info)、和/或QoS配置文件(QoS Profile)等信息,具体信息可参考现有技术,此处不再赘述。S812 , after determining that the first PDU session is successfully established, the SMF1 sends a session establishment acceptance message 1 to the RAN device 1 . Correspondingly, the RAN device 1 receives the session establishment accept message 1 from the SMF1. The session establishment accept message 1 includes the N1 session management container (N1 session management container) sent by SMF1 to the UAV and the N2 session management information (N2 Session Management Information) sent by SMF1 to the RAN device 1. Wherein, the N2 session management information includes the session identification information of the first PDU session, the core network tunnel information (CN Tunnel Info) for configuring the N3 tunnel, and/or the QoS profile (QoS Profile) and other information. For specific information, please refer to the prior art , and will not be repeated here.
S813、RAN设备1向UAV发送会话建立接受消息2。相应的,UAV接收SMF1的会话建立接受消息2。该会话建立接受消息2包括第一用户面安全保护开启指示、N1会话管理容器以及第一PDU会话的会话标识信息。当然,该会话建立接受消息2还可以包括一些其他的参数,本申请实施例对此不做具体限定。S813 , the RAN device 1 sends a session establishment accept message 2 to the UAV. Correspondingly, the UAV receives the session establishment accept message 2 of SMF1. The session establishment accept message 2 includes the first user plane security protection opening indication, the N1 session management container, and the session identification information of the first PDU session. Certainly, the session establishment acceptance message 2 may also include some other parameters, which are not specifically limited in this embodiment of the present application.
由于UAV与RAN设备1均可以获得第一用户面安全保护开启指示,因此后续UAV与UAVC之间进行C2通信时,UAV与RAN设备1之间可以根据第一用户面安全保护开启指示进行UAV侧的用户面安全保护。Since both the UAV and the RAN device 1 can obtain the first user plane security protection enable instruction, during subsequent C2 communication between the UAV and the UAVC, the UAV and the RAN device 1 can perform the UAV side according to the first user plane security protection enable instruction. user plane security protection.
进一步的,本申请实施例提供的通信方法还包括为UAVC服务的SMF2在建立第二PDU会话时获取第一用户面安全保护开启指示的流程,如下述步骤S814-S818所示的方式A或步骤S819-S821所示的方式B。Further, the communication method provided by the embodiment of the present application further includes a process of obtaining the first user plane security protection opening indication when the SMF2 serving the UAVC establishes the second PDU session, as shown in the following steps S814-S818. Mode B shown in S819-S821.
方式A如下:Method A is as follows:
S814、UTM/USS向为UAVC服务的UFES2发送消息3。相应的,UFES2接收来自UTM/USS的消息3。消息3包括UAVC的外部UAV ID以及第一用户面安全保护开启指示。S814, UTM/USS sends message 3 to UFES2 serving UAVC. Correspondingly, UFES2 receives message 3 from UTM/USS. Message 3 includes the external UAV ID of the UAVC and the first user plane security protection opening indication.
S815、UFES2向为UAVC服务的UDM2发送消息4。相应的,UDM2接收来自UFES2的消息4。消息4包括3GPP UAVC ID以及第一用户面安全保护开启指示。S815. UFES2 sends message 4 to UDM2 serving UAVC. Correspondingly, UDM2 receives message 4 from UFES2. Message 4 includes the 3GPP UAVC ID and the first user plane security protection opening indication.
示例性的,本申请实施例中的消息3例如可以为UTM/USS用于更新UFES2中UAS业务相关参数的消息,消息4例如可以为UFES2用于更新UDM2中UAS业务相关参数的消息。Exemplarily, message 3 in this embodiment of the present application may be, for example, a message used by UTM/USS to update UAS service-related parameters in UFES2, and message 4 may be, for example, a message used by UFES2 to update UAS service-related parameters in UDM2.
可选的,本申请实施例中,UDM2获取3GPP UAVC ID以及第一用户面安全保护开启指示之后,可以存储3GPP UAVC ID以及第一用户面安全保护开启指示的映射关系,以备后续使用。可选的,本申请实施例中,UDM2存储3GPP UAVC ID以及第一用户面安全保护开启指示的映射关系之前,可以根据3GPP UAVC ID确定UDM2中存储的UAVC对应的第二用户面安全保护策略是否满足UDM2从UTM/USS获取的第一用户面安全保护开启指示。若UDM2确定第二用户面安全保护策略满足第一用户面安全保护开启指示,则UDM2可以存储3GPP UAVC ID以及第一用户面安全保护开启指示的映射关系。若UDM2确定第二用户面安全保护策略不满足第一用户面安全保护开启指示,则UDM2可以通过UFES2向UTM/USS发送拒绝指示,该拒绝指示用于指示拒绝UAVC建立承载C2通信的PDU会话。当然,若UDM2确定第二用户面安全保护策略满足第一用户面安全保护开启指示,UDM2也可以通过UFES2向UTM/USS发送允许UAVC建立承载C2通信的PDU会话的指示信息,本申请实施例对此不做具体限定。基于该方案,一方面,可以避免后续由于第二用户面安全保护策略不满足第一用户面安全保护开启指示时可能导致的C2通信失败的问题。另一方面,在第二用户面安全保护策略不满足第一用户面安全保护开启指示时,可以及时终止UAVC发起建立第二PDU会话的流程,避免了过多的信令浪费。Optionally, in the embodiment of this application, after the UDM2 obtains the 3GPP UAVC ID and the first user plane security protection opening instruction, it can store the mapping relationship between the 3GPP UAVC ID and the first user plane security protection opening instruction for subsequent use. Optionally, in this embodiment of the present application, before the UDM2 stores the mapping relationship between the 3GPP UAVC ID and the first user plane security protection opening indication, it may be determined whether the second user plane security protection policy corresponding to the UAVC stored in the UDM2 is based on the 3GPP UAVC ID. The first user plane security protection activation instruction obtained by UDM2 from the UTM/USS is satisfied. If UDM2 determines that the second user plane security protection policy satisfies the first user plane security protection opening instruction, UDM2 may store the mapping relationship between the 3GPP UAVC ID and the first user plane security protection opening instruction. If UDM2 determines that the second user plane security protection policy does not satisfy the first user plane security protection opening indication, UDM2 may send a rejection indication to UTM/USS through UFES2, where the rejection indication is used to instruct UAVC to reject the establishment of a PDU session carrying C2 communication. Of course, if UDM2 determines that the second user plane security protection policy satisfies the first user plane security protection opening instruction, UDM2 may also send instruction information to UTM/USS through UFES2 to allow UAVC to establish a PDU session carrying C2 communication. This is not specifically limited. Based on this solution, on the one hand, the subsequent problem of C2 communication failure that may be caused when the second user plane security protection policy does not satisfy the first user plane security protection opening instruction can be avoided. On the other hand, when the second user plane security protection policy does not satisfy the first user plane security protection enable instruction, the process of initiating the establishment of the second PDU session by the UAVC can be terminated in time to avoid excessive signaling waste.
示例性的,假设第一用户面安全保护开启指示指示用户面机密性保护开启且用户面完整性保护开启,第二用户面安全保护策略包括用户面机密性保护为强制开启且用户面完整性保护为强制开启,则UDM2可以确定第二用户面安全保护策略满足第一用户面安全保护开启指示;或者,假设第一用户面安全保护开启指示指示用户面机密性 保护开启且用户面完整性保护开启,第二用户面安全保护策略包括用户面机密性保护为强制不开启且用户面完整性保护为强制不开启,则UDM2可以确定第二用户面安全保护策略不满足第一用户面安全保护开启指示;或者,假设第一用户面安全保护开启指示指示用户面机密性保护开启且用户面完整性保护开启,第二用户面安全保护策略包括用户面机密性保护为可选开启且用户面完整性保护为可选开启,则UDM2可以确定第二用户面安全保护策略满足第一用户面安全保护开启指示。其他情况类似,不再赘述。Exemplarily, it is assumed that the first user plane security protection enable instruction indicates that the user plane confidentiality protection is enabled and the user plane integrity protection is enabled, and the second user plane security protection policy includes that the user plane confidentiality protection is forcibly enabled and the user plane integrity protection is enabled. For forced opening, UDM2 may determine that the second user plane security protection policy satisfies the first user plane security protection opening instruction; or, it is assumed that the first user plane security protection opening instruction indicates that the user plane confidentiality protection is enabled and the user plane integrity protection is enabled. , the second user plane security protection policy includes that the user plane confidentiality protection is forcibly disabled and the user plane integrity protection is forcibly disabled, then UDM2 may determine that the second user plane security protection policy does not satisfy the first user plane security protection opening instruction Or, assuming that the first user plane security protection opening instruction indicates that the user plane confidentiality protection is enabled and the user plane integrity protection is enabled, the second user plane security protection policy includes that the user plane confidentiality protection is optional and the user plane integrity protection is enabled. For optional activation, UDM2 may determine that the second user plane security protection policy satisfies the first user plane security protection activation instruction. Other situations are similar and will not be repeated here.
S816、UTM/USS向UAVC发送消息5。相应的,UAVC接收来自UTM/USS的消息5。该消息5用于触发UAVC发起第二PDU会话的建立流程。S816, the UTM/USS sends message 5 to the UAVC. Correspondingly, the UAVC receives the message 5 from the UTM/USS. The message 5 is used to trigger the UAVC to initiate the establishment process of the second PDU session.
本申请实施例中,消息5可以通过3GPP网络的控制面或用户面发送,也可通过非3GPP网络发送,本申请实施例对此不做具体限定。In the embodiment of the present application, the message 5 may be sent through the control plane or the user plane of the 3GPP network, or may be sent through the non-3GPP network, which is not specifically limited in the embodiment of the present application.
示例性的,本申请实施例中的消息5例如可以为UTM/USS通过3GPP网络控制面或用户面发送的C2通信触发请求;或者,本申请实施例中的消息5例如可以为UTM/USS通过非3GPP网络发送的C2通信触发请求,该C2通信触发请求用于请求UAVC通过3GPP网络响应UAV的C2通信请求。Exemplarily, message 5 in this embodiment of the present application may be, for example, a C2 communication trigger request sent by UTM/USS through a 3GPP network control plane or user plane; or, message 5 in this embodiment of the present application may be, for example, a UTM/USS passing through The C2 communication trigger request sent by the non-3GPP network, the C2 communication trigger request is used to request the UAVC to respond to the C2 communication request of the UAV through the 3GPP network.
需要说明的是,本申请实施例中,UTM/USS向UAVC发送的消息5仅是图5所示的实施例中第一消息的一种示例,第一消息还可以为其他,本申请实施例对此不做具体限定。It should be noted that, in the embodiment of the present application, the message 5 sent by the UTM/USS to the UAVC is only an example of the first message in the embodiment shown in FIG. 5 , and the first message may also be other. This embodiment of the present application There is no specific limitation on this.
S817、UAVC向3GPP网络中的SMF2发送会话建立请求2。相应的,SMF2接收来自UAVC的会话建立请求2。该会话建立请求2包括3GPP UAVC ID和指示信息2,指示信息2用于指示UAVC请求建立的第二PDU会话用于承载C2通信。S817. The UAVC sends a session establishment request 2 to the SMF2 in the 3GPP network. Correspondingly, SMF2 receives session establishment request 2 from UAVC. The session establishment request 2 includes the 3GPP UAVC ID and indication information 2, where the indication information 2 is used to indicate that the second PDU session requested by the UAVC to be established is used to bear C2 communication.
一种可能的实现方式中,指示信息2可以为显示指示。比如,指示信息2可以为UAS操作请求指示(UAS operation request indication),该UAS操作请求指示为C2请求,用于显示指示UAVC请求建立的第二PDU会话用于承载C2通信。可选的,本申请实施例中,UAS操作请求指示还可以指示该C2请求为被动C2请求。In a possible implementation manner, the indication information 2 may be a display indication. For example, the indication information 2 may be a UAS operation request indication (UAS operation request indication), and the UAS operation request indication is a C2 request, which is used to display and indicate that the second PDU session established by the UAVC request is used to carry the C2 communication. Optionally, in this embodiment of the present application, the UAS operation request indication may further indicate that the C2 request is a passive C2 request.
另一种可能的实现方式中,指示信息2可以为隐式指示。比如,指示信息2可以为专用于C2通信的DNN信息,或者专用于C2通信的DNN和切片组合信息。In another possible implementation manner, the indication information 2 may be an implicit indication. For example, the indication information 2 may be DNN information dedicated to C2 communication, or DNN and slice combination information dedicated to C2 communication.
当然,若在步骤S802之前,UAV和UAVC已经线下通过非3GPP方式配对(例如两设备通过蓝牙配对)或者通过其他方式配对,则UAVC可以获取与其配对的UAV的配对标识。进一步的,会话建立请求2中可以包括UAV的配对标识,UAV的配对标识隐式指示UAVC请求建立的第二PDU会话用于承载C2通信。示例性的,UAV的配对标识例如可以为3GPP UAV ID或者UAV的外部UAV ID。Of course, if the UAV and the UAVC have been paired offline in a non-3GPP manner (eg, the two devices are paired via Bluetooth) or in other manners before step S802, the UAVC can obtain the pairing identifier of the UAV paired with it. Further, the session establishment request 2 may include the pairing identifier of the UAV, and the pairing identifier of the UAV implicitly indicates that the second PDU session requested by the UAVC to be established is used to carry the C2 communication. Exemplarily, the pairing identifier of the UAV may be, for example, a 3GPP UAV ID or an external UAV ID of the UAV.
S818、SMF2根据指示信息2,确定UAVC请求建立的第二PDU会话用于承载C2通信之后,从UDM2获取第一用户面安全保护开启指示。S818. After determining that the second PDU session requested by the UAVC to be established is used to carry the C2 communication according to the indication information 2, the SMF2 obtains the first user plane security protection opening indication from the UDM2.
一种可能的实现方式中,SMF2根据指示信息2,确定UAVC请求建立的第二PDU会话用于承载C2通信之后,向UDM2发送请求消息。该请求消息包括3GPP UAVC ID,该请求消息用于请求UAVC对应的第二用户面安全保护策略。UDM2接收该请求消息之后,根据3GPP UAVC ID确定UAVC对应的第二用户面安全保护策略,并在向SMF2发送的响应消息中携带UAVC对应的第二用户面安全保护策略。本申请实施例中,第 二用户面安全保护策略的相关描述可参考具体实施方式前序部分“用户面安全保护策略”的描述,在此不再赘述。此外,本申请实施例中,由于UDM2中存储有第一用户面安全保护开启指示,因此该响应消息还可以包括第一用户面安全保护开启指示。In a possible implementation manner, the SMF2 sends a request message to the UDM2 after determining, according to the indication information 2, that the second PDU session requested by the UAVC to be established is used to carry the C2 communication. The request message includes the 3GPP UAVC ID, and the request message is used to request the second user plane security protection policy corresponding to the UAVC. After receiving the request message, UDM2 determines the second user plane security protection policy corresponding to UAVC according to the 3GPP UAVC ID, and carries the second user plane security protection policy corresponding to UAVC in the response message sent to SMF2. In this embodiment of the present application, for the relevant description of the second user plane security protection policy, reference may be made to the description of the "user plane security protection policy" in the preamble of the specific implementation manner, which will not be repeated here. In addition, in this embodiment of the present application, since the UDM2 stores the first user plane security protection opening indication, the response message may further include the first user plane security protection opening indication.
需要说明的是,本申请实施例中,SMF2向UDM2发送的请求消息仅是图7a所示的实施例中第五消息的一种示例,第五消息还可以为其他,本申请实施例对此不做具体限定。It should be noted that, in the embodiment of the present application, the request message sent by the SMF2 to the UDM2 is only an example of the fifth message in the embodiment shown in FIG. 7a, and the fifth message may also be other, which the embodiment of the present application does not No specific limitation is made.
需要说明的是,本申请实施例中,若步骤S815中UDM2根据3GPP UAVC ID确定UDM2中存储的UAVC对应的第二用户面安全保护策略满足UDM2从UTM/USS获取的第一用户面安全保护开启指示,则UTM/USS可以在接收来自UDM2的允许UAVC建立承载C2通信的PDU会话的指示信息之后,向UAVC发送消息5(执行步骤S816)。当然,UDM2也可以直接默认UAVC对应的第二用户面安全保护策略满足UDM2从UTM/USS获取的第一用户面安全保护开启指示。此时,步骤S814与步骤S816没有必然的执行先后顺序,可以先执行步骤S814,再执行步骤S816;也可以先执行步骤S816,再执行步骤S814;还可以同时执行步骤S814和S816,本申请实施例对此不做具体限定。It should be noted that, in this embodiment of the present application, if the UDM2 determines the second user plane security protection policy corresponding to the UAVC stored in the UDM2 according to the 3GPP UAVC ID in step S815, the security protection policy of the first user plane obtained by the UDM2 from the UTM/USS is enabled. indication, the UTM/USS may send message 5 to the UAVC after receiving the indication information from the UDM2 that allows the UAVC to establish a PDU session carrying the C2 communication (step S816 is executed). Of course, the UDM2 may also directly default the second user plane security protection policy corresponding to the UAVC to satisfy the first user plane security protection activation instruction obtained by the UDM2 from the UTM/USS. At this time, steps S814 and S816 do not have a necessary order of execution. Step S814 may be executed first, and then step S816 may be executed; or step S816 may be executed first, and then step S814 may be executed; steps S814 and S816 may also be executed simultaneously, and this application implements The example does not specifically limit this.
方式B如下:Method B is as follows:
S819、同步骤S816,相关描述可参考上述步骤S816,在此不再赘述。S819, the same as step S816, the related description can refer to the above-mentioned step S816, which will not be repeated here.
S820、UAVC向3GPP网络中的SMF2发送会话建立请求2。相应的,SMF2接收来自UAVC的会话建立请求2。该会话建立请求2包括3GPP UAVC ID和指示信息3,指示信息3用于指示UAVC请求建立的第二PDU会话用于响应UAV发起的C2通信。S820. The UAVC sends a session establishment request 2 to the SMF2 in the 3GPP network. Correspondingly, SMF2 receives session establishment request 2 from UAVC. The session establishment request 2 includes the 3GPP UAVC ID and indication information 3, where the indication information 3 is used to indicate that the second PDU session requested by the UAVC to be established is used in response to the C2 communication initiated by the UAV.
一种可能的实现方式中,指示信息3可以为显示指示。比如,指示信息3可以为UAS操作请求指示(UAS operation request indication),该UAS操作请求指示为被动C2请求,用于显示指示UAVC请求建立的第二PDU会话用于响应UAV发起的C2通信。In a possible implementation manner, the indication information 3 may be a display indication. For example, the indication information 3 may be a UAS operation request indication (UAS operation request indication), the UAS operation request indication is a passive C2 request, which is used to display and indicate that the second PDU session established by the UAVC request is used to respond to the C2 communication initiated by the UAV.
S821、SMF2根据指示信息3,确定UAVC请求建立的第二PDU会话用于响应UAV发起的C2通信之后,通过UFES2从UTM/USS获取第一用户面安全保护开启指示。S821. After determining that the second PDU session requested by the UAVC to be established is used to respond to the C2 communication initiated by the UAV according to the indication information 3, the SMF2 obtains the first user plane security protection opening indication from the UTM/USS through the UFES2.
一种可能的实现方式中,SMF2根据指示信息3,确定UAVC请求建立的第二PDU会话用于响应UAV发起的C2通信之后,向UFES2发送请求消息,该请求消息包括3GPP UAVC ID,该请求消息用于请求第一用户面安全保护开启指示。进而,UFES2向UTM/USS发送请求消息,该请求消息包括UAVC的外部UAV ID,该请求消息用于请求第一用户面安全保护开启指示。UTM/USS接收该请求消息之后,可以根据UAVC的外部UAV ID、以及UAV的外部UAV ID、UAVC的外部UAV ID以及第一用户面安全保护开启指示的映射关系,确定第一用户面安全保护开启指示,并向SMF2发送第一用户面安全保护开启指示。In a possible implementation manner, after determining that the second PDU session requested by UAVC to be established is used to respond to the C2 communication initiated by UAV according to the indication information 3, SMF2 sends a request message to UFES2, the request message including the 3GPP UAVC ID, the request message. It is used to request the first user plane security protection on instruction. Further, UFES2 sends a request message to the UTM/USS, where the request message includes the external UAV ID of the UAVC, and the request message is used to request the first user plane security protection opening indication. After the UTM/USS receives the request message, it can determine that the first user plane security protection is enabled according to the external UAV ID of the UAVC, and the mapping relationship between the external UAV ID of the UAV, the external UAV ID of the UAVC, and the first user plane security protection opening instruction instruction, and send the first user plane security protection opening instruction to the SMF2.
需要说明的是,本申请实施例中,UFES2向UTM/USS发送的请求消息仅是图5所示的实施例中第二消息的一种示例,第二消息还可以为其他,本申请实施例对此不做具体限定。It should be noted that, in the embodiment of the present application, the request message sent by the UFES2 to the UTM/USS is only an example of the second message in the embodiment shown in FIG. 5 , and the second message may also be other, the embodiment of the present application There is no specific limitation on this.
需要说明的是,本申请实施例中,SMF2向UFES2发送的请求消息仅是图7a所示 的实施例中第六消息的一种示例,第六消息还可以为其他,本申请实施例对此不做具体限定。It should be noted that, in the embodiment of the present application, the request message sent by the SMF2 to the UFES2 is only an example of the sixth message in the embodiment shown in FIG. 7a, and the sixth message may also be other, and the embodiment of the present application is for this No specific limitation is made.
本申请实施例中,UFES2从3GPP网络获取3GPP UAVC ID之后,可以根据存储的3GPP UAVC ID与UAVC的外部UAV ID的映射关系,将3GPP UAVC ID“翻译”转化为UTM/USS能够识别的UAVC的外部UAV ID,并将UAVC的外部UAV ID发送给UTM/USS,在此统一说明,以下不再赘述。In the embodiment of this application, after UFES2 obtains the 3GPP UAVC ID from the 3GPP network, it can “translate” the 3GPP UAVC ID into a UAVC ID that can be identified by UTM/USS according to the stored mapping relationship between the 3GPP UAVC ID and the external UAV ID of the UAVC. The external UAV ID, and the external UAV ID of the UAVC is sent to the UTM/USS, which is described in a unified manner here, and will not be repeated below.
可选的,本申请实施例中,SMF2根据指示信息3,确定UAVC请求建立的第二PDU会话用于响应UAV发起的C2通信之后,还可以从UDM2获取UAVC对应的第二用户面安全保护策略,本申请实施例对此不作具体限定。其中,当SMF2同时从UDM2获取UAVC对应的第二用户面安全保护策略以及第一用户面安全保护开启指示的情况下,SMF2可以确定第二用户面安全保护策略是否满足第一用户面安全保护开启指示,在SMF2确定第二用户面安全保护策略是否满足第一用户面安全保护开启指示的情况下,SMF2继续第二PDU会话建立流程;或者,在SMF2确定第二用户面安全保护策略不满足第一用户面安全保护开启指示的情况下,SMF2拒绝第二PDU会话的建立。SMF2确定第二用户面安全保护策略是否满足第一用户面安全保护开启指示的方式可参考上述UDM2确定第二用户面安全保护策略是否满足第一用户面安全保护开启指示的方式,在此不再赘述。当然,当SMF2同时从UDM2获取UAVC对应的第二用户面安全保护策略以及第一用户面安全保护开启指示的情况下,SMF2也可以默认使用第一用户面安全保护开启指示,忽略第二用户面安全保护策略,本申请实施例对此不做具体限定。Optionally, in this embodiment of the present application, after determining that the second PDU session requested by the UAVC to be established is used to respond to the C2 communication initiated by the UAV according to the indication information 3, the SMF2 may also obtain the second user plane security protection policy corresponding to the UAVC from the UDM2. , which is not specifically limited in the embodiments of the present application. Wherein, when SMF2 obtains the second user plane security protection policy corresponding to UAVC and the first user plane security protection enable instruction from UDM2 at the same time, SMF2 may determine whether the second user plane security protection policy satisfies the first user plane security protection enablement indicates that, in the case where SMF2 determines whether the second user plane security protection policy satisfies the first user plane security protection opening instruction, SMF2 continues the second PDU session establishment process; or, when SMF2 determines that the second user plane security protection policy does not satisfy the first user plane security protection In the case of a user plane security protection open indication, the SMF2 rejects the establishment of the second PDU session. The method for SMF2 to determine whether the second user plane security protection policy satisfies the first user plane security protection enable instruction can refer to the above-mentioned method of UDM2 for determining whether the second user plane security protection policy meets the first user plane security protection enable instruction, which is not repeated here. Repeat. Of course, when SMF2 obtains the second user plane security protection policy corresponding to UAVC and the first user plane security protection enable instruction from UDM2 at the same time, SMF2 can also use the first user plane security protection enable instruction by default, ignoring the second user plane The security protection policy is not specifically limited in this embodiment of the present application.
进一步的,本申请实施例提供的通信方法还可以包括第二PDU会话建立的其他流程,如下述步骤S822-S825所示的方式一或步骤S826-S827所示的方式二。Further, the communication method provided by the embodiment of the present application may further include other procedures for establishing a second PDU session, such as the first manner shown in the following steps S822-S825 or the second manner shown in the steps S826-S827.
方式一如下:The first method is as follows:
S822、SMF2根据第一用户面安全保护开启指示,确定第三用户面安全保护策略。第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护。其中,步骤S822的具体实现可参考前述发明内容部分,在此不再赘述。S822, SMF2 determines a third user plane security protection policy according to the first user plane security protection enabling instruction. The third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection. For the specific implementation of step S822, reference may be made to the foregoing summary of the invention, which will not be repeated here.
S823、SMF2向RAN设备2发送第三用户面安全保护策略。相应的,RAN设备2接收来自SMF2的第三用户面安全保护策略。S823 , the SMF2 sends the third user plane security protection policy to the RAN device 2 . Correspondingly, the RAN device 2 receives the third user plane security protection policy from the SMF2.
S824、RAN设备2根据第三用户面安全保护策略,确定第二用户面安全保护开启指示,第二用户面安全保护开启指示用于指示第二PDU会话的用户面安全保护是否开启。S824. The RAN device 2 determines the second user plane security protection enable instruction according to the third user plane security protection policy, and the second user plane security protection enable instruction is used to indicate whether the user plane security protection of the second PDU session is enabled.
本申请实施例中,RAN设备2根据第三用户面安全保护策略,确定第二用户面安全保护开启指示的相关示例可参考步骤S805中RAN设备1根据第一用户面安全保护策略确定第一用户面安全保护开启指示的方式,在此不再赘述。In this embodiment of the present application, the RAN device 2 determines a related example of the indication of enabling the second user plane security protection according to the third user plane security protection policy, please refer to step S805 in which the RAN device 1 determines the first user according to the first user plane security protection policy The method of instructing the face security protection on is not repeated here.
当然,本申请实施例中,当第三用户面安全保护策略包括用户面机密性保护为强制开启以及用户面完整性保护为强制开启,但是RAN设备2当前没有足够的资源为UAVC的用户面数据提供安全保护时,RAN设备2可以确定拒绝第二PDU会话的建立,进而RAN设备可以向SMF2发送拒绝第二PDU会话建立的指示,以终止后续流程,本申请实施例对该情况不做具体阐述。这样可以保证UAVC侧的承载C2通信的 路径上所有节点均可以支持第二用户面安全保护开启指示,从而保证UAV与UAVC之间的正常C2通信。Of course, in the embodiment of the present application, when the third user plane security protection policy includes that the user plane confidentiality protection is forcibly turned on and the user plane integrity protection is forcibly turned on, but the RAN device 2 currently does not have enough resources for the user plane data of UAVC When providing security protection, the RAN device 2 may determine to reject the establishment of the second PDU session, and then the RAN device may send an indication of rejecting the establishment of the second PDU session to the SMF2 to terminate the subsequent process, which is not specifically described in this embodiment of the present application . In this way, it can be ensured that all nodes on the path carrying the C2 communication on the UAVC side can support the second user plane security protection opening instruction, thereby ensuring the normal C2 communication between the UAV and the UAVC.
S825、第二PDU会话建立的其他流程,具体可参考现有技术,在此不再赘述。其中,在第二PDU会话建立的其他流程中,RAN设备2可以向UAVC发送第二用户面安全保护开启指示。由于RAN设备2和UAVC均可以获得第二用户面安全保护开启指示,因此后续UAV与UAVC之间进行C2通信时,UAVC与RAN设备2之间可以根据第二用户面安全保护开启指示进行UAVC侧的用户面安全保护。S825. For other procedures of establishing the second PDU session, reference may be made to the prior art for details, and details are not described herein again. Wherein, in other procedures of establishing the second PDU session, the RAN device 2 may send the second user plane security protection opening indication to the UAVC. Since both RAN device 2 and UAVC can obtain the second user plane security protection enable instruction, during subsequent C2 communication between UAV and UAVC, UAVC and RAN device 2 can perform the UAVC side according to the second user plane security protection enable instruction. user plane security protection.
该方式一中,由于第二用户面安全保护开启指示指示的用户面安全保护的开启方式与第三用户面安全保护策略指示的用户面安全保护的开启方式相同,第三用户面安全保护策略指示的用户面安全保护的开启方式与第一用户面安全保护开启指示指示的用户面安全保护的开启方式相同,因此第一用户面安全保护开启指示指示的用户面安全保护的开启方式与第二用户面安全保护开启指示指示的用户面安全保护的开启方式相同。由于第一用户面安全保护开启指示指示的用户面安全保护的开启方式为UAV侧的用于承载C2通信的第一PDU会话的用户面安全保护的开启方式,第二用户面安全保护开启指示指示的用户面安全保护的开启方式为UAVC侧的用于承载C2通信的第二PDU会话的用户面安全保护的开启方式,因此基于该方案,可以保证UAV和UAVC之间的C2通信的用户面安全保护的一致性。In the first method, since the method of enabling the user plane security protection indicated by the second user plane security protection enabling instruction is the same as the enabling manner of the user plane security protection indicated by the third user plane security protection policy, the third user plane security protection policy instruction The way of opening the user plane security protection of the first user plane security protection is the same as that of the user plane security protection indicated by the first user plane security protection opening instruction, so the way of opening the user plane security protection indicated by the first user plane security protection opening instruction The method of turning on the user face security protection indicated by the face security protection turning on instruction is the same. Since the first user plane security protection enable instruction indicates that the user plane security protection is enabled in the manner in which the user plane security protection is enabled on the UAV side for the first PDU session carrying the C2 communication, the second user plane security protection enable instruction indicates The user plane security protection is enabled on the UAVC side for the second PDU session carrying the C2 communication. Therefore, based on this solution, the user plane security of the C2 communication between the UAV and the UAVC can be guaranteed. Consistency of protection.
方式二如下:The second way is as follows:
S826、SMF2向RAN设备2发送第一用户面安全保护开启指示。相应的,RAN设备2接收来自SMF2的第一用户面安全保护开启指示。S826. The SMF2 sends the first user plane security protection opening instruction to the RAN device 2. Correspondingly, the RAN device 2 receives the first user plane security protection opening instruction from the SMF2.
S827、第二PDU会话建立的其他流程,具体可参考现有技术,在此不再赘述。其中,在第二PDU会话建立的其他流程中,RAN设备2可以向UAVC发送第二用户面安全保护开启指示。由于RAN设备2和UAVC均可以获得第二用户面安全保护开启指示,因此后续UAV与UAVC之间进行C2通信时,UAVC与RAN设备2之间可以根据第二用户面安全保护开启指示进行UAVC侧的用户面安全保护。S827. For other procedures of establishing the second PDU session, reference may be made to the prior art for details, and details are not described herein again. Wherein, in other procedures of establishing the second PDU session, the RAN device 2 may send the second user plane security protection opening indication to the UAVC. Since both RAN device 2 and UAVC can obtain the second user plane security protection enable instruction, during subsequent C2 communication between UAV and UAVC, UAVC and RAN device 2 can perform the UAVC side according to the second user plane security protection enable instruction. user plane security protection.
该方式二中,由于UAV侧的用于承载C2通信的第一PDU会话的用户面安全保护的开启方式和UAVC侧的用于承载C2通信的第二PDU会话的用户面安全保护的开启方式均由第一用户面安全保护开启指示指示。因此基于该方案,可以保证UAV和UAVC之间的C2通信的用户面安全保护的一致性。In the second method, since the method of enabling the user plane security protection of the first PDU session for carrying the C2 communication on the UAV side and the method of enabling the user plane security protection of the second PDU session for carrying the C2 communication on the UAVC side are both Indicated by the first user plane security protection on instruction. Therefore, based on this scheme, the consistency of user plane security protection of C2 communication between UAV and UAVC can be guaranteed.
可选的,作为一种替换方案,本申请实施例中,上述步骤S815之后,UDM2还可以根据从UTM/USS获取的第一用户面安全保护开启指示更新UDM2中存储的UAVC对应的第二用户面安全保护策略。其中,更新后的第二用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护。具体地,UDM根据第一用户面安全保护开启指示确定更新后的第二用户面安全保护策略的方案与步骤S822中SMF2根据第一用户面安全保护开启指示,确定第三用户面安全保护策略的示例类似,在此不再赘述。进而,当SMF2接收来自UAVC的会话建立请求2,并根据指示信息2确定UAVC请求建立的第二PDU会话用于承载C2通信之后或者根据指示信息3确定UAVC请求建立的第二PDU会话用于响应UAV发起的C2通信之后,可以向UDM2发送请求消息。该请求消息包括3GPP UAVC ID,该请求消息用于请求UAVC对应的第二用户面安全 保护策略。UDM2接收该请求消息之后,根据3GPP UAVC ID确定UAVC对应的第二用户面安全保护策略,并在向SMF2发送的响应消息中携带UAVC对应的第二用户面安全保护策略。进一步的,SMF2可以向RAN设备2发送第二用户面安全保护策略。相应的,RAN设备2接收来自SMF2的第二用户面安全保护策略,并根据第二用户面安全保护策略确定第二用户面安全保护开启指示,第二用户面安全保护开启指示用于指示第二PDU会话的用户面安全保护是否开启。基于该方案,由于第二用户面安全保护开启指示指示的用户面安全保护的开启方式与第二用户面安全保护策略指示的用户面安全保护的开启方式相同,第二用户面安全保护策略指示的用户面安全保护的开启方式与第一用户面安全保护开启指示指示的用户面安全保护的开启方式相同,因此第一用户面安全保护开启指示指示的用户面安全保护的开启方式与第二用户面安全保护开启指示指示的用户面安全保护的开启方式相同。由于第一用户面安全保护开启指示指示的用户面安全保护的开启方式为UAV侧的用于承载C2通信的第一PDU会话的用户面安全保护的开启方式,第二用户面安全保护开启指示指示的用户面安全保护的开启方式为UAVC侧的用于承载C2通信的第二PDU会话的用户面安全保护的开启方式,因此基于该方案,可以保证UAV和UAVC之间的C2通信的用户面安全保护的一致性。Optionally, as an alternative solution, in this embodiment of the present application, after the above step S815, the UDM2 may also update the second user corresponding to the UAVC stored in the UDM2 according to the first user plane security protection opening instruction obtained from the UTM/USS. face security protection strategy. Wherein, the updated second user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection. Specifically, the UDM determines the updated second user plane security protection policy according to the first user plane security protection opening instruction and the SMF2 in step S822 determines the third user plane security protection policy according to the first user plane security protection opening instruction. The examples are similar and will not be repeated here. Further, when the SMF2 receives the session establishment request 2 from the UAVC, and determines according to the indication information 2 that the second PDU session established by the UAVC request is used to carry the C2 communication, or determines that the second PDU session established by the UAVC request is used for the response according to the indication information 3 After the C2 communication initiated by the UAV, a request message may be sent to the UDM2. The request message includes the 3GPP UAVC ID, and the request message is used to request the second user plane security protection policy corresponding to the UAVC. After receiving the request message, UDM2 determines the second user plane security protection policy corresponding to UAVC according to the 3GPP UAVC ID, and carries the second user plane security protection policy corresponding to UAVC in the response message sent to SMF2. Further, the SMF2 may send the second user plane security protection policy to the RAN device 2 . Correspondingly, the RAN device 2 receives the second user plane security protection policy from the SMF2, and determines the second user plane security protection enable instruction according to the second user plane security protection policy, and the second user plane security protection enable instruction is used to indicate the second user plane. Whether the user plane security protection of the PDU session is enabled. Based on this solution, since the method of enabling the user plane security protection indicated by the second user plane security protection enabling instruction is the same as the enabling manner of the user plane security protection indicated by the second user plane security protection policy, the second user plane security protection policy indicates The way to turn on the security protection of the user plane is the same as the way of turning on the security protection of the user plane indicated by the first user plane security protection turning on instruction. The security protection of the user plane indicated by the security protection opening instruction is activated in the same manner. Since the first user plane security protection enable instruction indicates that the user plane security protection is enabled in the manner in which the user plane security protection is enabled on the UAV side for the first PDU session carrying the C2 communication, the second user plane security protection enable instruction indicates The user plane security protection is enabled on the UAVC side for the second PDU session carrying the C2 communication. Therefore, based on this solution, the user plane security of the C2 communication between the UAV and the UAVC can be guaranteed. Consistency of protection.
可选的,作为一种替换方案,SMF2获得第一用户面安全保护开启指示之后,还可以将第一用户面安全保护开启指示发送给其他网元(如PCF),由其他网元根据第一用户面安全保护开启指示确定上述第三用户面安全保护策略之后,将第三用户面安全保护策略发送给SMF2,本申请实施例对此不做具体限定。Optionally, as an alternative solution, after the SMF2 obtains the first user plane security protection opening instruction, it can also send the first user plane security protection opening instruction to other network elements (such as PCF), and the other network elements are based on the first user plane. After the user plane security protection enable instruction determines the third user plane security protection policy, the third user plane security protection policy is sent to the SMF2, which is not specifically limited in this embodiment of the present application.
进一步的,本申请实施例提供的通信方法还可以包括如下步骤S828:Further, the communication method provided by the embodiment of the present application may further include the following step S828:
S828、第二PDU会话建立完成后,UAV注册的3GPP网络与UAVC注册的3GPP网络进行会话所用信息的配置,并建立UAV和UAVC之间的C2通信通道后开始后续C2通信流程。其中,会话所用信息的配置包括路由信息配置,PDU会话修改等流程,相关实现可参考现有技术,在此不再赘述。S828. After the establishment of the second PDU session is completed, the 3GPP network registered by the UAV and the 3GPP network registered by the UAVC configure the information used for the session, and the subsequent C2 communication process starts after establishing the C2 communication channel between the UAV and the UAVC. The configuration of the information used in the session includes routing information configuration, PDU session modification and other processes, and related implementations may refer to the prior art, which will not be repeated here.
基于本申请实施例提供的通信方法,由于UTM/USS可以在UAV建立用于承载C2通信的第一PDU会话的过程中获取用于指示第一PDU会话的用户面安全保护是否开启的第一用户面安全保护开启指示,并且为UAVC服务的SMF2可以在UAVC建立用于承载C2通信的第二PDU会话的过程中获取该第一用户面安全保护开启指示或者获取根据该第一用户面安全保护开启指示更新的UAVC对应的第二用户面安全保护策略。其中,第二PDU会话的用户面安全保护是否开启由第一用户面安全保护开启指示确定或者第二用户面安全保护策略确定。因此基于该方案,可以保证UAV侧的用于承载C2通信的第一PDU会话的用户面安全保护的开启方式和UAVC侧的用于承载C2通信的第二PDU会话的用户面安全保护的开启方式相同,从而可以保证UAV和UAVC之间的C2通信的用户面安全保护的一致性。Based on the communication method provided by the embodiment of the present application, since the UTM/USS can obtain the first user used to indicate whether the user plane security protection of the first PDU session is enabled during the process of establishing the first PDU session for carrying the C2 communication by the UAV and the SMF2 serving the UAVC can obtain the first user plane security protection enable instruction or obtain the first user plane security protection enable instruction during the process of establishing the second PDU session for carrying the C2 communication by the UAVC. Indicates the second user plane security protection policy corresponding to the updated UAVC. Wherein, whether the user plane security protection of the second PDU session is enabled is determined by the first user plane security protection enable instruction or the second user plane security protection policy. Therefore, based on this solution, it is possible to ensure the enabling method of the user plane security protection on the UAV side for carrying the first PDU session of the C2 communication and the enabling method of the user plane security protection on the UAVC side for carrying the second PDU session of the C2 communication. The same, so that the consistency of the user plane security protection of the C2 communication between the UAV and the UAVC can be guaranteed.
其中,上述步骤S801a至S828中SMF1、UTM/USS、SMF2、UFES1或者UFES2的动作可以由图4所示的通信装置400中的处理器401调用存储器403中存储的应用程序代码以指令SMF1、UTM/USS、SMF2、UFES1或者UFES2执行,本实施例对此不作任何限制。Wherein, the actions of SMF1, UTM/USS, SMF2, UFES1 or UFES2 in the above steps S801a to S828 can be performed by the processor 401 in the communication device 400 shown in FIG. 4 calling the application code stored in the memory 403 to instruct SMF1, UTM /USS, SMF2, UFES1, or UFES2 is executed, which is not limited in this embodiment.
另一种可能的实现方式中,UTM/USS可以在UAV建立用于承载UAV与UAVC之间的C2通信(以下将UAV与UAVC之间的C2通信简称C2通信)的第一PDU会话的过程结束后通过用户面或者控制面获取用于指示第一PDU会话的用户面安全保护是否开启的第一用户面安全保护开启指示。进一步的,为UAVC服务的SMF2可以在UAVC建立用于承载C2通信的第二PDU会话的过程中获取该第一用户面安全保护开启指示或者获取根据该第一用户面安全保护开启指示更新的UAVC对应的第二用户面安全保护策略。示例性的,如图9所示,为本申请实施例提供的一种通信方法,该通信方法包括UAV和UAVC在3GPP网络的注册流程,如下述步骤S901a与步骤S901b:In another possible implementation manner, the UTM/USS may end the process of establishing the first PDU session in the UAV for carrying the C2 communication between the UAV and the UAVC (hereinafter referred to as the C2 communication between the UAV and the UAVC) Afterwards, a first user plane security protection enable instruction for indicating whether the user plane security protection of the first PDU session is enabled is obtained through the user plane or the control plane. Further, the SMF2 serving the UAVC may acquire the first user plane security protection enable instruction or acquire the UAVC updated according to the first user plane security protection enable instruction during the process of establishing the second PDU session for carrying the C2 communication by the UAVC. The corresponding second user plane security protection policy. Exemplarily, as shown in FIG. 9 , a communication method is provided in an embodiment of the present application. The communication method includes a registration process of UAV and UAVC in a 3GPP network, such as the following steps S901a and S901b:
S901a、UAV注册到3GPP网络,具体注册过程可参考现有技术,在此不再赘述。S901a, the UAV is registered to the 3GPP network, and the specific registration process may refer to the prior art, which will not be repeated here.
S901b、UAVC注册到3GPP网络,具体注册过程可参考现有技术,在此不再赘述。S901b, the UAVC is registered to the 3GPP network, and the specific registration process may refer to the prior art, which will not be repeated here.
步骤S901a和步骤S901b的具体实现可分别参考图8所示的实施例中的步骤S801a和S801b,在此不再赘述。For the specific implementation of step S901a and step S901b, reference may be made to steps S801a and S801b in the embodiment shown in FIG. 8 respectively, and details are not repeated here.
进一步的,本申请实施例提供的通信方法还包括UAV触发建立第一PDU会话的流程,如下述步骤S902:Further, the communication method provided by the embodiment of the present application further includes a process of triggering the establishment of a first PDU session by the UAV, such as the following step S902:
S902、UAV触发建立第一PDU会话的流程,具体可参考现有技术,在此不再赘述。S902 , the UAV triggers the process of establishing the first PDU session, for details, reference may be made to the prior art, which will not be repeated here.
其中,第一PDU会话建立完成后,UAV、RAN设备1和SMF1均可以获知第一用户面安全保护开启指示。进一步的,本申请实施例提供的通信方法还包括UTM/USS获取第一用户面安全保护开启指示的流程,如下述步骤S903所示的方式M或步骤S904-S905所示的方式N。Wherein, after the establishment of the first PDU session is completed, the UAV, the RAN device 1 and the SMF1 can all learn the first user plane security protection opening instruction. Further, the communication method provided by the embodiment of the present application further includes a process for the UTM/USS to obtain the first user plane security protection opening instruction, such as the following way M shown in step S903 or way N shown in steps S904-S905.
方式M如下:The way M is as follows:
S903、UAV通过已经建立的第一PDU会话的用户面向UTM/USS发送UAV的外部UAV ID和第一用户面安全保护开启指示。相应的,UTM/USS接收来自UAV的UAV的外部UAV ID和第一用户面安全保护开启指示。S903, the UAV sends the UAV's external UAV ID and the first user plane security protection opening indication to the UTM/USS through the user of the already established first PDU session. Correspondingly, the UTM/USS receives the UAV's external UAV ID and the first user plane security protection opening instruction from the UAV.
方式N如下:The way N is as follows:
S904、SMF1确定第一PDU会话建立完成后,向UFES1发送消息6。相应的,UFES1接收来自SMF1的消息6。该消息6包括3GPP UAV ID和第一用户面安全保护开启指示。S904. After determining that the establishment of the first PDU session is completed, the SMF1 sends a message 6 to the UFES1. Accordingly, UFES1 receives message 6 from SMF1. The message 6 includes the 3GPP UAV ID and the first user plane security protection opening indication.
S905、UFES1向UTM/USS发送消息7。相应的,UTM/USS接收来自UFES1的消息7。该消息7包括UAV的外部UAV ID和第一用户面安全保护开启指示。S905, UFES1 sends message 7 to the UTM/USS. Accordingly, UTM/USS receives message 7 from UFES1. The message 7 includes the external UAV ID of the UAV and the first user plane security protection opening indication.
对于上述步骤S904-S905:For the above steps S904-S905:
上述消息6和消息7可以为会话建立流程结束后SMF1将UAV侧C2通信所用的会话参数(例如UAV用于C2通信的IP地址)通知给UTM/USS的消息;或者上述消息6和消息7可以为会话建立流程结束后的其他现有控制面消息或者新定义的控制面消息,本申请实施例对此不做具体限定。The above message 6 and message 7 can be the messages that SMF1 notifies the UTM/USS of the session parameters (such as the IP address used by the UAV for C2 communication) used for C2 communication on the UAV side after the session establishment process ends; or the above messages 6 and 7 can be It is other existing control plane messages or newly defined control plane messages after the session establishment process ends, which is not specifically limited in this embodiment of the present application.
本申请实施例中,UFES1从3GPP网络获取3GPP UAV ID之后,可以根据存储的3GPP UAV ID与UAV的外部UAV ID的映射关系,将3GPP UAV ID“翻译”转化为UTM/USS能够识别的UAV的外部UAV ID,并将UAV的外部UAV ID发送给 UTM/USS,在此统一说明,以下不再赘述。In the embodiment of this application, after UFES1 obtains the 3GPP UAV ID from the 3GPP network, it can “translate” the 3GPP UAV ID into a UAV ID that can be identified by UTM/USS according to the stored mapping relationship between the 3GPP UAV ID and the external UAV ID of the UAV. The external UAV ID, and the external UAV ID of the UAV is sent to the UTM/USS, which is explained here and will not be repeated below.
基于上述方式M或方式N,UTM/USS可以获取第一用户面安全保护开启指示。进一步的,为UAVC服务的SMF2可以在UAVC建立用于承载C2通信的第二PDU会话的过程中获取该第一用户面安全保护开启指示或者获取根据该第一用户面安全保护开启指示更新的UAVC对应的第二用户面安全保护策略。其中,第二PDU会话的用户面安全保护是否开启由第一用户面安全保护开启指示确定或者第二用户面安全保护策略确定。相关实现可参考图8所示的实施例中的步骤S814-S828,在此不再赘述。Based on the foregoing manner M or manner N, the UTM/USS may acquire the first user plane security protection opening instruction. Further, the SMF2 serving the UAVC may acquire the first user plane security protection enable instruction or acquire the UAVC updated according to the first user plane security protection enable instruction during the process of establishing the second PDU session for carrying the C2 communication by the UAVC. The corresponding second user plane security protection policy. Wherein, whether the user plane security protection of the second PDU session is enabled is determined by the first user plane security protection enable instruction or the second user plane security protection policy. For related implementation, reference may be made to steps S814-S828 in the embodiment shown in FIG. 8 , and details are not described herein again.
基于本申请实施例提供的通信方法,由于UTM/USS可以在UAV建立用于承载C2通信的第一PDU会话的流程结束之后获取用于指示第一PDU会话的用户面安全保护是否开启的第一用户面安全保护开启指示,并且为UAVC服务的SMF2可以在UAVC建立用于承载C2通信的第二PDU会话的过程中获取该第一用户面安全保护开启指示或者获取根据该第一用户面安全保护开启指示更新的UAVC对应的第二用户面安全保护策略。其中,第二PDU会话的用户面安全保护是否开启由第一用户面安全保护开启指示确定或者第二用户面安全保护策略确定。因此基于该方案,可以保证UAV侧的用于承载C2通信的第一PDU会话的用户面安全保护的开启方式和UAVC侧的用于承载C2通信的第二PDU会话的用户面安全保护的开启方式相同,从而可以保证UAV和UAVC之间的C2通信的用户面安全保护的一致性。Based on the communication method provided by the embodiments of the present application, since the UTM/USS can obtain the first information indicating whether the user plane security protection of the first PDU session is enabled after the process of establishing the first PDU session for carrying the C2 communication by the UAV ends The user plane security protection enable instruction, and the SMF2 serving the UAVC can obtain the first user plane security protection enable instruction during the process of UAVC establishing the second PDU session for carrying the C2 communication or obtain the first user plane security protection according to the first user plane. Enable the second user plane security protection policy corresponding to the updated UAVC. Wherein, whether the user plane security protection of the second PDU session is enabled is determined by the first user plane security protection enable instruction or the second user plane security protection policy. Therefore, based on this solution, it is possible to ensure the enabling method of the user plane security protection on the UAV side for carrying the first PDU session of the C2 communication and the enabling method of the user plane security protection on the UAVC side for carrying the second PDU session of the C2 communication. The same, so that the consistency of the user plane security protection of the C2 communication between the UAV and the UAVC can be guaranteed.
其中,上述步骤S901a至S905中SMF1、UTM/USS、SMF2、UFES1或者UFES2的动作可以由图4所示的通信装置400中的处理器401调用存储器403中存储的应用程序代码以指令SMF1、UTM/USS、SMF2、UFES1或者UFES2执行,本实施例对此不作任何限制。Wherein, the actions of SMF1, UTM/USS, SMF2, UFES1 or UFES2 in the above steps S901a to S905 can be performed by the processor 401 in the communication device 400 shown in FIG. 4 calling the application code stored in the memory 403 to instruct SMF1, UTM /USS, SMF2, UFES1, or UFES2 is executed, which is not limited in this embodiment.
又一种可能的实现方式中,UTM/USS可以基于配对授权流程的触发,通过为UAV服务的UFES1获取用于指示第一PDU会话(即UAV用于承载UAV与UAVC之间的C2通信(以下将UAV与UAVC之间的C2通信简称C2通信)的会话)的用户面安全保护是否开启的第一用户面安全保护开启指示。进一步的,为UAVC服务的SMF2可以在UAVC建立用于承载C2通信的第二PDU会话的过程中获取该第一用户面安全保护开启指示或者获取根据该第一用户面安全保护开启指示更新的UAVC对应的第二用户面安全保护策略。示例性的,如图10所示,为本申请实施例提供的一种通信方法,该通信方法包括UAV和UAVC在3GPP网络的注册流程,如下述步骤S1001a与步骤S1001b:In another possible implementation manner, the UTM/USS may, based on the triggering of the pairing authorization process, obtain through the UFES1 serving the UAV to indicate the first PDU session (that is, the UAV is used to carry the C2 communication between the UAV and the UAVC (below). The C2 communication between the UAV and the UAVC is referred to as the C2 communication session) of the user plane security protection is the first user plane security protection open indication. Further, the SMF2 serving the UAVC may acquire the first user plane security protection enable instruction or acquire the UAVC updated according to the first user plane security protection enable instruction during the process of establishing the second PDU session for carrying the C2 communication by the UAVC. The corresponding second user plane security protection policy. Exemplarily, as shown in FIG. 10 , a communication method is provided in an embodiment of the present application. The communication method includes a registration process of UAV and UAVC in a 3GPP network, such as the following steps S1001a and S1001b:
S1001a、UAV注册到3GPP网络,具体注册过程可参考现有技术,在此不再赘述。S1001a, the UAV is registered to the 3GPP network, and the specific registration process may refer to the prior art, which will not be repeated here.
S1001b、UAVC注册到3GPP网络,具体注册过程可参考现有技术,在此不再赘述。S1001b, the UAVC is registered to the 3GPP network, and the specific registration process may refer to the prior art, which will not be repeated here.
步骤S1001a和步骤S1001b的具体实现可分别参考图8所示的实施例中的步骤S801a和S801b,在此不再赘述。For the specific implementation of steps S1001a and S1001b, reference may be made to steps S801a and S801b in the embodiment shown in FIG. 8 respectively, and details are not repeated here.
进一步的,本申请实施例提供的通信方法还包括UAV触发建立非C2通信使用的PDU会话(记为第三PDU会话)的流程,如下述步骤S1002:Further, the communication method provided by the embodiment of the present application further includes a process in which the UAV triggers the establishment of a PDU session (referred to as the third PDU session) used for non-C2 communication, as shown in the following step S1002:
S1002、UAV触发建立第三PDU会话的流程,具体可参考现有技术,在此不再赘述。S1002 , the UAV triggers the process of establishing the third PDU session. For details, reference may be made to the prior art, which will not be repeated here.
进一步的,本申请实施例提供的通信方法还包括配对授权流程,如下述步骤S1003-S1004所示:Further, the communication method provided by the embodiment of the present application further includes a pairing authorization process, as shown in the following steps S1003-S1004:
S1003、UAV通过已经建立的第三PDU会话的用户面向UTM/USS发送C2配对请求1。相应的,UTM/USS接收来自UAV的C2配对请求1。该C2配对请求1中包括UAV的外部UAV ID。S1003 , the UAV sends a C2 pairing request 1 to the UTM/USS through the user of the established third PDU session. Accordingly, the UTM/USS receives the C2 pairing request 1 from the UAV. The C2 pairing request 1 includes the UAV's external UAV ID.
当然,若在步骤S1003之前,UAV和UAVC已经线下通过非3GPP方式配对(例如两设备通过蓝牙配对)或者通过其他方式配对,则UAV可以获取与其配对的UAVC的配对标识。进一步的,C2配对请求1中可以包括UAVC的配对标识。示例性的,UAVC的配对标识例如可以为3GPP UAVC ID或者UAVC的外部UAV ID。Of course, if before step S1003, the UAV and the UAVC have been paired offline in a non-3GPP manner (for example, the two devices are paired via Bluetooth) or in other ways, the UAV can obtain the pairing identifier of the UAVC paired with it. Further, the C2 pairing request 1 may include the pairing identifier of the UAVC. Exemplarily, the pairing identifier of the UAVC may be, for example, the 3GPP UAVC ID or the external UAV ID of the UAVC.
可选的,本申请实施例中,当UAVC的配对标识为UAVC的外部UAV ID时,UAVC的外部UAV ID可以包括在C2配对请求1的容器(container)中。这样,一方面,由于中间节点透传container不篡改container中内容,因此可以保证上述参数的安全性;另一方面,由于中间节点可以不解析上述参数,因此可以节省中间节点的处理资源,以及提高中间节点的处理效率。Optionally, in this embodiment of the present application, when the pairing identifier of the UAVC is the external UAV ID of the UAVC, the external UAV ID of the UAVC may be included in the container (container) of the C2 pairing request 1. In this way, on the one hand, since the intermediate node transparently transmits the container without tampering with the contents in the container, the security of the above parameters can be guaranteed; Processing efficiency of intermediate nodes.
S1004、UTM/USS确定与UAV配对的UAVC在网后,对C2配对请求进行授权。S1004: After the UTM/USS determines that the UAVC paired with the UAV is on the network, it authorizes the C2 pairing request.
其中,UAVC在网以及UTM/USS对C2配对请求进行授权的相关描述可参考图8所示的实施例步骤S810,在此不再赘述。For the relevant description of the authorization of the C2 pairing request by the UAVC on the network and the UTM/USS, reference may be made to step S810 of the embodiment shown in FIG. 8 , which will not be repeated here.
一种可能的实现方式中,若C2配对请求1中包括UAVC的外部UAV ID,则UTM/USS可以根据UAVC的外部UAV ID确定UAVC是否已经获得UTM/USS的认证授权。如果UAVC已经获得UTM/USS的认证授权,则UTM/USS可以确定UAVC在网。其中,UTM/USS从接收到的C2配对请求1中获得UAVC的外部UAV ID的方式包括:解析接收到的C2配对请求1中的container,获得container中包含的UAVC的外部UAV ID;或者,从接收到的C2配对请求1中直接获得UAVC的外部UAV ID。In a possible implementation manner, if the C2 pairing request 1 includes the external UAV ID of the UAVC, the UTM/USS can determine whether the UAVC has obtained the authentication and authorization of the UTM/USS according to the external UAV ID of the UAVC. If the UAVC has been authorized by the UTM/USS, the UTM/USS can determine that the UAVC is on the network. The manner in which the UTM/USS obtains the external UAV ID of the UAVC from the received C2 pairing request 1 includes: parsing the container in the received C2 pairing request 1, and obtaining the external UAV ID of the UAVC contained in the container; or, from The external UAV ID of the UAVC is directly obtained from the received C2 pairing request 1.
另一种可能的实现方式中,UAV和UAVC的配对关系可以存储在UTM/USS中(例如UAV和UAVC的生产商在设备出厂时将UAV和UAVC配对好,并将配对关系注册到UTM/USS中)。其中,该配对关系可以通过UAV的外部UAV ID和UAVC的外部UAV ID的映射关系进行表征。进而,UTM/USS根据接收到的UAV的外部UAV ID,以及UAV和UAVC的配对关系确定UAVC的外部UAV ID后,根据UAVC的外部UAV ID确定UAVC是否已经获得UTM/USS的认证授权。如果UAVC已经获得UTM/USS的认证授权,则UTM/USS可以确定UAVC在网。In another possible implementation, the pairing relationship between UAV and UAVC can be stored in UTM/USS (for example, the manufacturer of UAV and UAVC pairs UAV and UAVC when the device leaves the factory, and registers the pairing relationship in UTM/USS middle). The pairing relationship can be characterized by the mapping relationship between the external UAV ID of the UAV and the external UAV ID of the UAVC. Further, after the UTM/USS determines the external UAV ID of the UAVC according to the received external UAV ID of the UAV and the pairing relationship between the UAV and the UAVC, it determines whether the UAVC has obtained the authentication authorization of the UTM/USS according to the external UAV ID of the UAVC. If the UAVC has been authorized by the UTM/USS, the UTM/USS can determine that the UAVC is on the network.
需要说明的时,本申请实施例以UAV通过3GPP接入的用户面向UTM/USS发送C2配对请求为例进行说明。可选的,UAV也可以通过非3GPP接入向UTM/USS发送C2配对请求,该C2配对请求中包括UAV的外部UAV ID,本申请实施例对此不做具体限定。When it needs to be explained, the embodiment of the present application is described by taking an example that a user accessing the UAV through 3GPP sends a C2 pairing request to the UTM/USS. Optionally, the UAV may also send a C2 pairing request to the UTM/USS through a non-3GPP access, where the C2 pairing request includes an external UAV ID of the UAV, which is not specifically limited in this embodiment of the present application.
进一步的,本申请实施例提供的通信方法还包括UTM/USS基于配对授权流程的触发获取用于指示第一PDU会话的用户面安全保护是否开启的第一用户面安全保护开启指示的流程,如下述步骤S1005-S1013所示:Further, the communication method provided by the embodiment of the present application further includes a process in which the UTM/USS obtains a first user plane security protection opening instruction for indicating whether the user plane security protection of the first PDU session is enabled based on the triggering of the pairing authorization process, as follows: The above steps S1005-S1013 are shown:
S1005、配对授权完成后,UTM/USS向UFES1发送请求消息1。相应的,UFES1接收来自UTM/USS的请求消息1。该请求消息1包括UAV的外部UAV ID,该请求 消息1用于请求第一用户面安全保护开启指示,第一用户面安全保护开启指示用于指示第一PDU会话的用户面安全保护是否开启。S1005. After the pairing authorization is completed, the UTM/USS sends a request message 1 to the UFES1. Correspondingly, UFES1 receives request message 1 from UTM/USS. The request message 1 includes the external UAV ID of the UAV, and the request message 1 is used to request the first user plane security protection opening instruction, and the first user plane security protection opening instruction is used to indicate whether the user plane security protection of the first PDU session is enabled.
其中,第一用户面安全保护开启指示的相关描述可参考具体实施方式前序部分“用户面安全保护开启指示”的描述,在此不再赘述。For the relevant description of the first user plane security protection opening instruction, reference may be made to the description of the "user plane security protection opening instruction" in the preamble of the specific implementation manner, which will not be repeated here.
需要说明的是,本申请实施例中,UTM/USS向UFES1发送的请求消息1仅是图5所示的实施例第三消息的一种示例,第三消息还可以为其他,本申请实施例对此不做具体限定。It should be noted that, in the embodiment of the present application, the request message 1 sent by the UTM/USS to the UFES1 is only an example of the third message in the embodiment shown in FIG. 5 , and the third message may also be other. There is no specific limitation on this.
一种可能的实现方式中,本申请实施例中,该请求消息1可以包括指示信息4,指示信息4用于指示该请求消息1用于请求第一用户面安全保护开启指示。In a possible implementation manner, in this embodiment of the present application, the request message 1 may include indication information 4, where the indication information 4 is used to indicate that the request message 1 is used to request an indication of enabling the security protection of the first user plane.
另一种可能的实现方式中,请求消息1本身可以指示该请求消息1用于请求第一用户面安全保护开启指示。比如,该请求消息1可以为用户面安全保护开启指示请求消息,本申请实施例对此不做具体限定。In another possible implementation manner, the request message 1 itself may indicate that the request message 1 is used to request the first user plane security protection opening instruction. For example, the request message 1 may be a user plane security protection opening indication request message, which is not specifically limited in this embodiment of the present application.
S1006、UFES1向SMF1发送请求消息2。相应的,SMF1接收来自UFES1的请求消息2。该请求消息2包括3GPP UAV ID,该请求消息2用于请求第一用户面安全保护开启指示。S1006, UFES1 sends request message 2 to SMF1. Correspondingly, SMF1 receives request message 2 from UFES1. The request message 2 includes the 3GPP UAV ID, and the request message 2 is used to request the first user plane security protection opening instruction.
需要说明的是,本申请实施例中,UFES1向SMF1发送的请求消息2仅是图6所示的实施例中第四消息的一种示例,第四消息还可以为其他,本申请实施例对此不做具体限定。It should be noted that, in this embodiment of the present application, the request message 2 sent by UFES1 to SMF1 is only an example of the fourth message in the embodiment shown in FIG. 6 , and the fourth message may also be other. This is not specifically limited.
本申请实施例中,UFES1获取UAV的外部UAV ID之后,可以根据存储的3GPP UAV ID与UAV的外部UAV ID的映射关系,将请求消息1中的UAV的外部UAV ID“翻译”转化为3GPP网络能够识别的3GPP UAV ID,并通过请求消息2将3GPP UAV ID发送给SMF1,在此统一说明,以下不再赘述。In the embodiment of the present application, after UFES1 obtains the external UAV ID of the UAV, it can "translate" the external UAV ID of the UAV in the request message 1 into a 3GPP network according to the stored mapping relationship between the 3GPP UAV ID and the external UAV ID of the UAV The 3GPP UAV ID that can be identified, and the 3GPP UAV ID is sent to the SMF1 through the request message 2, which is described here uniformly and will not be repeated below.
一种可能的实现方式中,本申请实施例中,该请求消息2可以包括指示信息5,指示信息5用于指示该请求消息2用于请求第一用户面安全保护开启指示。In a possible implementation manner, in this embodiment of the present application, the request message 2 may include indication information 5, where the indication information 5 is used to indicate that the request message 2 is used to request an indication of enabling the security protection of the first user plane.
另一种可能的实现方式中,请求消息2本身可以指示该请求消息2用于请求第一用户面安全保护开启指示。比如,该请求消息2可以为用户面安全保护开启指示请求消息,本申请实施例对此不做具体限定。In another possible implementation manner, the request message 2 itself may indicate that the request message 2 is used to request the first user plane security protection opening instruction. For example, the request message 2 may be a user plane security protection opening indication request message, which is not specifically limited in this embodiment of the present application.
S1007-S1011、同图8所示的实施例中的S803-S807,相关描述可参考图8所示的实施例,在此不再赘述。S1007-S1011 are the same as S803-S807 in the embodiment shown in FIG. 8 , and the related description may refer to the embodiment shown in FIG. 8 , which will not be repeated here.
S1012、SMF1向UFES1发送响应消息2。相应的,UFES1接收来自SMF1的响应消息2。该响应消息2包括3GPP UAV ID以及第一用户面安全保护开启指示。S1012, SMF1 sends response message 2 to UFES1. Correspondingly, UFES1 receives response message 2 from SMF1. The response message 2 includes the 3GPP UAV ID and the first user plane security protection opening indication.
S1013、UFES1向UTM/USS发送响应消息1。相应的,UTM/USS接收来自UFES1的响应消息1。该响应消息1包括UAV的外部UAV ID以及第一用户面安全保护开启指示。S1013. UFES1 sends response message 1 to UTM/USS. Correspondingly, UTM/USS receives response message 1 from UFES1. The response message 1 includes the external UAV ID of the UAV and the first user plane security protection opening indication.
本申请实施例中,响应消息1中UAV的外部UAV ID是根据响应消息2中的3GPP UAV ID“翻译”转化得到的,转化方式可参考上述步骤S809,在此不再赘述。In the embodiment of the present application, the external UAV ID of the UAV in the response message 1 is obtained by "translation" of the 3GPP UAV ID in the response message 2, and the conversion method can refer to the above-mentioned step S809, which is not repeated here.
本申请实施例中,SMF1获知第一用户面安全保护开启指示之后,还可以执行如下步骤S1014:In this embodiment of the present application, after learning the first user plane security protection opening instruction, the SMF1 may further perform the following step S1014:
S1014、SMF1触发建立第一PDU会话的流程。其中,本申请实施例中的第一PDU 会话可以是修改上述第三PDU会话得到的,也可以是SMF触发UAV新建得到的,本申请实施例对此不做具体限定。基于第三PDU会话修改得到第一PDU会话的流程以及新建第一PDU会话的流程均可参考现有技术,在此不再赘述。S1014. The SMF1 triggers the process of establishing the first PDU session. The first PDU session in the embodiment of the present application may be obtained by modifying the above-mentioned third PDU session, or may be obtained by creating a new UAV triggered by the SMF, which is not specifically limited in the embodiment of the present application. The process of modifying and obtaining the first PDU session based on the third PDU session and the process of creating the first PDU session can refer to the prior art, and details are not repeated here.
基于上述方式方案,UTM/USS可以获取第一用户面安全保护开启指示。进一步的,为UAVC服务的SMF2可以在UAVC建立用于承载C2通信的第二PDU会话的过程中获取该第一用户面安全保护开启指示或者获取根据该第一用户面安全保护开启指示更新的UAVC对应的第二用户面安全保护策略。其中,第二PDU会话的用户面安全保护是否开启由第一用户面安全保护开启指示确定或者第二用户面安全保护策略确定。相关实现可参考图8所示的实施例中的步骤S814-S828,在此不再赘述。Based on the above solutions, the UTM/USS can obtain the first user plane security protection opening instruction. Further, the SMF2 serving the UAVC may acquire the first user plane security protection enable instruction or acquire the UAVC updated according to the first user plane security protection enable instruction during the process of establishing the second PDU session for carrying the C2 communication by the UAVC. The corresponding second user plane security protection policy. Wherein, whether the user plane security protection of the second PDU session is enabled is determined by the first user plane security protection enable instruction or the second user plane security protection policy. For related implementation, reference may be made to steps S814-S828 in the embodiment shown in FIG. 8 , and details are not described herein again.
基于本申请实施例提供的通信方法,由于UTM/USS可以基于配对授权流程的触发,通过为UAV服务的UFES1获取用于指示承载C2通信的第一PDU会话的用户面安全保护是否开启的第一用户面安全保护开启指示,并且为UAVC服务的SMF2可以在UAVC建立承载C2通信的第二PDU会话的过程中获取该第一用户面安全保护开启指示或者获取根据该第一用户面安全保护开启指示更新的UAVC对应的第二用户面安全保护策略。其中,第二PDU会话的用户面安全保护是否开启由第一用户面安全保护开启指示确定或者第二用户面安全保护策略确定。因此基于该方案,可以保证UAV侧的用于承载C2通信的第一PDU会话的用户面安全保护的开启方式和UAVC侧的用于承载C2通信的第二PDU会话的用户面安全保护的开启方式相同,从而可以保证UAV和UAVC之间的C2通信的用户面安全保护的一致性。Based on the communication method provided by the embodiment of the present application, since the UTM/USS can be triggered based on the pairing authorization process, the UFES1 serving the UAV can obtain the first information for indicating whether the user plane security protection of the first PDU session carrying the C2 communication is enabled or not. The user plane security protection enable instruction, and the SMF2 serving the UAVC can obtain the first user plane security protection enable instruction or obtain the first user plane security protection enable instruction in the process of establishing the second PDU session carrying the C2 communication in the UAVC The second user plane security protection policy corresponding to the updated UAVC. Wherein, whether the user plane security protection of the second PDU session is enabled is determined by the first user plane security protection enable instruction or the second user plane security protection policy. Therefore, based on this solution, it is possible to ensure the enabling method of the user plane security protection on the UAV side for carrying the first PDU session of the C2 communication and the enabling method of the user plane security protection on the UAVC side for carrying the second PDU session of the C2 communication. The same, so that the consistency of the user plane security protection of the C2 communication between the UAV and the UAVC can be guaranteed.
其中,上述步骤S1001a至S1014中SMF1、UTM/USS、SMF2、UFES1或者UFES2的动作可以由图4所示的通信装置400中的处理器401调用存储器403中存储的应用程序代码以指令SMF1、UTM/USS、SMF2、UFES1或者UFES2执行,本实施例对此不作任何限制。Wherein, the actions of SMF1, UTM/USS, SMF2, UFES1 or UFES2 in the above steps S1001a to S1014 can be performed by the processor 401 in the communication device 400 shown in FIG. 4 calling the application code stored in the memory 403 to instruct SMF1, UTM /USS, SMF2, UFES1, or UFES2 is executed, which is not limited in this embodiment.
又一种可能的实现方式中,可以由为UAV的UFES1在UUAA流程或基于UUAA流程的触发获取用于指示第一PDU会话(即UAV用于承载UAV与UAVC之间的C2通信(以下将UAV与UAVC之间的C2通信简称C2通信)的会话)的用户面安全保护是否开启的第一用户面安全保护开启指示,并维护第一用户面安全保护开启指示和UAV的外部UAV ID的映射关系。进而,在UAV触发的配对授权流程中,为UAV服务的UFES1可以将该第一用户面安全保护开启指示发送给UTM/USS。进一步的,为UAVC服务的SMF2可以在UAVC建立用于承载C2通信的第二PDU会话的过程中获取该第一用户面安全保护开启指示或者获取根据该第一用户面安全保护开启指示更新的UAVC对应的第二用户面安全保护策略。示例性的,如图11所示,为本申请实施例提供的一种通信方法,该通信方法包括UAV和UAVC在3GPP网络的注册流程,如下述步骤S1101a与步骤S1101b:In yet another possible implementation, the UFES1, which is a UAV, can be acquired in the UUAA process or triggered by the UUAA process to indicate the first PDU session (that is, the UAV is used to carry the C2 communication between the UAV and the UAVC (hereinafter referred to as the UAV). The C2 communication with the UAVC (referred to as the session of C2 communication) is the first user plane security protection opening instruction indicating whether the user plane security protection is enabled, and the mapping relationship between the first user plane security protection opening instruction and the external UAV ID of the UAV is maintained. . Furthermore, in the pairing authorization process triggered by the UAV, the UFES1 serving the UAV may send the first user plane security protection activation instruction to the UTM/USS. Further, the SMF2 serving the UAVC may acquire the first user plane security protection enable instruction or acquire the UAVC updated according to the first user plane security protection enable instruction during the process of establishing the second PDU session for carrying the C2 communication by the UAVC. The corresponding second user plane security protection policy. Exemplarily, as shown in FIG. 11 , a communication method is provided in an embodiment of the present application. The communication method includes a registration process of UAV and UAVC in a 3GPP network, such as the following steps S1101a and S1101b:
S1101a、UAV注册到3GPP网络,具体注册过程可参考现有技术,在此不再赘述。S1101a, the UAV is registered to the 3GPP network, and the specific registration process may refer to the prior art, which will not be repeated here.
S1101b、UAVC注册到3GPP网络,具体注册过程可参考现有技术,在此不再赘述。S1101b, the UAVC is registered to the 3GPP network, and the specific registration process may refer to the prior art, which will not be repeated here.
步骤S1101a和步骤S1101b的具体实现可分别参考图8所示的实施例中的步骤S801a和S801b,在此不再赘述。For the specific implementation of step S1101a and step S1101b, reference may be made to steps S801a and S801b in the embodiment shown in FIG. 8 respectively, and details are not repeated here.
进一步的,本申请实施例提供的通信方法还包括UAV触发建立非C2通信使用的PDU会话(记为第三PDU会话)的流程,如下述步骤S1102-S1112:Further, the communication method provided by the embodiment of the present application also includes a process in which the UAV triggers the establishment of a PDU session (referred to as the third PDU session) used for non-C2 communication, as follows in steps S1102-S1112:
S1102、UAV向3GPP网络中的SMF1发送会话建立请求3。相应的,SMF1接收来自UAV的会话建立请求3。该会话建立请求3包括3GPP UAV ID和指示信息6,指示信息6用于指示UAV请求建立的第三PDU会话用于UAS的非C2通信。S1102, the UAV sends a session establishment request 3 to the SMF1 in the 3GPP network. Correspondingly, SMF1 receives the session establishment request 3 from the UAV. The session establishment request 3 includes the 3GPP UAV ID and indication information 6, where the indication information 6 is used to indicate that the third PDU session that the UAV requests to establish is used for the non-C2 communication of the UAS.
一种可能的实现方式中,指示信息6可以为显示指示。比如,指示信息6可以为UAS操作请求指示(UAS operation request indication),该UAS操作请求指示为C2请求之外的其他请求。In a possible implementation manner, the indication information 6 may be a display indication. For example, the indication information 6 may be a UAS operation request indication (UAS operation request indication), and the UAS operation request indication is a request other than the C2 request.
另一种可能的实现方式中,指示信息6可以为隐式指示。比如,指示信息6可以为专用于UAS的非C2通信的DNN信息,或者专用于UAS的非C2通信的DNN和切片组合信息等。In another possible implementation manner, the indication information 6 may be an implicit indication. For example, the indication information 6 may be DNN information dedicated to the non-C2 communication of the UAS, or DNN and slice combination information dedicated to the non-C2 communication of the UAS, or the like.
S1103、SMF1根据指示信息6,确定UAV请求建立的第三PDU会话用于UAS的非C2通信之后,从UDM1获取第一用户面安全保护策略和第四用户面安全保护策略,该第一用户面安全保护策略用于建立第一PDU会话,该第四用户面安全保护策略用于建立第三PDU会话。S1103. After determining that the third PDU session requested to be established by the UAV is used for the non-C2 communication of the UAS according to the instruction information 6, the SMF1 obtains the first user plane security protection policy and the fourth user plane security protection policy from the UDM1. The security protection policy is used to establish the first PDU session, and the fourth user plane security protection policy is used to establish the third PDU session.
本申请实施例中,第一用户面安全保护策略和第四用户面安全保护策略的相关描述可参考具体实施方式前序部分“用户面安全保护策略”的描述,在此不再赘述。In the embodiment of the present application, for the related descriptions of the first user plane security protection policy and the fourth user plane security protection policy, reference may be made to the description of the "user plane security protection policy" in the preamble of the specific implementation manner, which will not be repeated here.
一种可能的实现方式中,SMF1向UDM1发送请求消息,该请求消息包括3GPP UAV ID,该请求消息用于请求第三PDU会话的用户面安全策略。UDM1接收该请求消息之后,根据3GPP UAV ID确定UAV的签约信息。UAV的签约信息中包括第一用户面安全保护策略和第四用户面安全保护策略。进而,UDM1可以在向SMF1发送的响应消息中携带第一用户面安全保护策略和第四用户面安全保护策略。In a possible implementation manner, SMF1 sends a request message to UDM1, where the request message includes a 3GPP UAV ID, and the request message is used to request the user plane security policy of the third PDU session. After receiving the request message, UDM1 determines the subscription information of the UAV according to the 3GPP UAV ID. The subscription information of the UAV includes a first user plane security protection policy and a fourth user plane security protection policy. Furthermore, the UDM1 may carry the first user plane security protection policy and the fourth user plane security protection policy in the response message sent to the SMF1.
另一种可能的实现方式中,SMF1可以根据会话建立请求3中的信息确定请求建立会话的节点为UAV,进而SMF1向UDM1发送请求消息,该请求消息包括3GPP UAV ID,该请求消息用于请求第一用户面安全保护策略和第四用户面安全保护策略。UDM1接收该请求消息之后,根据3GPP UAV ID从UAV的签约信息中获取第一用户面安全保护策略和第四用户面安全保护策略。进而,UDM1可以在向SMF1发送的响应消息中携带第一用户面安全保护策略和第四用户面安全保护策略。In another possible implementation manner, SMF1 may determine, according to the information in session establishment request 3, that the node requesting session establishment is a UAV, and then SMF1 sends a request message to UDM1, where the request message includes a 3GPP UAV ID, and the request message is used to request The first user plane security protection policy and the fourth user plane security protection policy. After receiving the request message, UDM1 obtains the first user plane security protection policy and the fourth user plane security protection policy from the subscription information of the UAV according to the 3GPP UAV ID. Furthermore, the UDM1 may carry the first user plane security protection policy and the fourth user plane security protection policy in the response message sent to the SMF1.
需要说明的是,本申请实施例中,第一用户面安全保护策略和第四用户面安全保护策略可以是相同的用户面安全保护策略,本申请实施例对此不做具体限定。It should be noted that, in this embodiment of the present application, the first user plane security protection policy and the fourth user plane security protection policy may be the same user plane security protection policy, which is not specifically limited in this embodiment of the present application.
需要说明的是,本申请实施例以UDM2针对不同类型的PDU会话分别存储对应的用户面安全保护策略为例进行说明。当然,UDM2中存储的UAV对应的用户面安全保护策略也可以为一个,该用户面安全保护策略既可以用于建立第一PDU会话,也可以用于建立第三PDU会话,此时SMF1从UDM1获取的UAV对应的用户面安全保护策略也为一个,本申请实施例对此不做具体限定。It should be noted that the embodiments of the present application are described by taking the UDM2 separately storing corresponding user plane security protection policies for different types of PDU sessions as an example. Of course, the user plane security protection policy corresponding to the UAV stored in UDM2 can also be one, and the user plane security protection policy can be used to establish the first PDU session or the third PDU session. The obtained user plane security protection policy corresponding to the UAV is also one, which is not specifically limited in this embodiment of the present application.
S1104、SMF1向RAN设备1发送第一用户面安全保护策略和第四用户面安全保护策略。相应的,RAN设备1接收来自SMF1的第一用户面安全保护策略和第四用户面安全保护策略。S1104 , the SMF1 sends the first user plane security protection policy and the fourth user plane security protection policy to the RAN device 1 . Correspondingly, the RAN device 1 receives the first user plane security protection policy and the fourth user plane security protection policy from the SMF1.
S1105、RAN设备1根据第四用户面安全保护策略确定第四用户面安全保护开启 指示,第四用户面安全保护开启指示用于指示第三PDU会话的用户面安全保护是否开启。S1105. The RAN device 1 determines a fourth user plane security protection enable instruction according to the fourth user plane security protection policy, and the fourth user plane security protection enable instruction is used to indicate whether the user plane security protection of the third PDU session is enabled.
其中,第四用户面安全保护开启指示的相关描述可参考具体实施方式前序部分“用户面安全保护开启指示”的描述,在此不再赘述。此外,RAN设备1根据第四用户面安全保护策略确定第四用户面安全保护开启指示的方式可参考图8所示的实施例中RAN设备1根据第一用户面安全保护策略确定第一用户面安全保护开启指示的方式,在此不再赘述。For the relevant description of the fourth user plane security protection enable instruction, reference may be made to the description of the "user plane security protection enable instruction" in the preamble of the specific implementation manner, and details are not repeated here. In addition, for the manner in which the RAN device 1 determines the fourth user plane security protection enable instruction according to the fourth user plane security protection policy, reference may be made to the RAN device 1 determining the first user plane according to the first user plane security protection policy in the embodiment shown in FIG. 8 . The manner of the security protection opening instruction will not be repeated here.
S1106-S1108、同图8所示的实施例中的S805-S807,相关描述可参考图8所示的实施例,在此不再赘述。S1106-S1108 are the same as S805-S807 in the embodiment shown in FIG. 8 , and the related description can refer to the embodiment shown in FIG. 8 , and details are not repeated here.
进一步的,UFES1可以在第三PDU会话建立流程中通过步骤S1109的方式P或者步骤S1110-S1111的方式获取第一用户面安全保护开启指示。Further, the UFES1 may obtain the first user plane security protection opening instruction by means of step S1109 or steps S1110-S1111 in the third PDU session establishment process.
方式P如下:The way P is as follows:
S1109、SMF1向UFES1发送UUAA请求1。相应的,UFES1接收来自SMF1的UUAA请求1。该UUAA请求1包括3GPP UAV ID和第一用户面安全保护开启指示。S1109, SMF1 sends UUAA request 1 to UFES1. Correspondingly, UFES1 receives UUAA request 1 from SMF1. The UUAA request 1 includes the 3GPP UAV ID and the first user plane security protection opening indication.
即,本申请实施例中,SMF1依赖会话建立过程中的UUAA请求1将3GPP UAV ID和第一用户面安全保护开启指示发送给UFES1。That is, in the embodiment of the present application, the SMF1 relies on the UUAA request 1 in the session establishment process to send the 3GPP UAV ID and the first user plane security protection opening instruction to the UFES1.
方式Q如下:The way Q is as follows:
S1110、SMF1向UFES1发送UUAA请求2。相应的,UFES1接收来自SMF1的UUAA请求2。该UUAA请求2包括3GPP UAV ID。S1110, SMF1 sends UUAA request 2 to UFES1. Correspondingly, UFES1 receives UUAA request 2 from SMF1. The UUAA Request 2 includes the 3GPP UAV ID.
S1111、UFES1从SMF1获取第一用户面安全保护开启指示。S1111. UFES1 obtains the first user plane security protection enabling instruction from SMF1.
一种可能的实现方式中,UFES1向SMF1发送请求消息,该请求消息包括3GPP UAV ID,该请求消息用于请求第一用户面安全保护开启指示。SMF1接收该请求消息之后,向UFES 1发送响应消息,该响应消息包括第一用户面安全保护开启指示。In a possible implementation manner, UFES1 sends a request message to SMF1, where the request message includes a 3GPP UAV ID, and the request message is used to request a first user plane security protection opening indication. After receiving the request message, SMF1 sends a response message to UFES 1, where the response message includes the first user plane security protection opening indication.
进一步的,本申请实施例提供的第三PDU会话建立流程还包括如下步骤:Further, the third PDU session establishment process provided by the embodiment of the present application further includes the following steps:
S1112、第三PDU会话建立的其他流程,如UFES1向UTM/USS发送包括UAV的外部UAV ID的UUAA请求3。UTM/USS接收来自UFES1的UUAA请求3之后,根据UAV的外部UAV ID对UAV进行UUAA。相关实现可参考现有技术具体可参考现有技术,在此不再赘述。S1112. Other procedures for establishing a third PDU session, such as UFES1 sending a UUAA request 3 including the external UAV ID of the UAV to the UTM/USS. After the UTM/USS receives the UUAA request 3 from UFES1, it performs UUAA on the UAV according to the UAV's external UAV ID. For related implementation, reference may be made to the prior art, and specific reference may be made to the prior art, which will not be repeated here.
进一步的,本申请实施例提供的通信方法还可以包括如下步骤S511:Further, the communication method provided by the embodiment of the present application may further include the following step S511:
S1113、UFES1存储UAV的外部UAV ID和第一用户面安全保护开启指示的映射关系。S1113. UFES1 stores the mapping relationship between the external UAV ID of the UAV and the first user plane security protection opening indication.
本申请实施例中,UFES1获取3GPP UAV ID之后,可以根据存储的3GPP UAV ID与UAV的外部UAV ID的映射关系,确定与3GPP UAV ID对应的UAV的外部UAV ID。进而存储UAV的外部UAV ID和第一用户面安全保护开启指示的映射关系。当然,本申请实施例中,UFES1可以存储UAV的外部UAV ID、3GPP UAV ID以及第一用户面安全保护开启指示的映射关系,本申请实施例对此不做具体限定。In the embodiment of the present application, after the UFES1 obtains the 3GPP UAV ID, the external UAV ID of the UAV corresponding to the 3GPP UAV ID can be determined according to the stored mapping relationship between the 3GPP UAV ID and the external UAV ID of the UAV. Then, the mapping relationship between the external UAV ID of the UAV and the first user plane security protection opening instruction is stored. Of course, in the embodiment of the present application, the UFES1 may store the mapping relationship between the external UAV ID of the UAV, the 3GPP UAV ID, and the first user plane security protection opening instruction, which is not specifically limited in the embodiment of the present application.
进一步的,本申请实施例提供的通信方法还包括UTM/USS通过配对授权流程获取第一用户面安全保护开启指示的流程,如下述步骤S1114-S1116所示的方式X或步骤S1117-S1119所示的方式Y。Further, the communication method provided by the embodiment of the present application further includes a process in which the UTM/USS obtains the first user plane security protection opening instruction through the pairing authorization process, as shown in the following steps S1114-S1116 in manner X or steps S1117-S1119. way Y.
方式X如下:The way X is as follows:
S1114、UAV通过SMF1向UFES1发送C2配对请求2。相应的,UFES1接收来自UAV的C2配对请求2。该C2配对请求2中包括3GPP UAV ID。S1114. The UAV sends a C2 pairing request 2 to the UFES1 through the SMF1. Correspondingly, UFES1 receives C2 pairing request 2 from UAV. The C2 pairing request 2 includes the 3GPP UAV ID.
当然,若在步骤S1114之前,UAV和UAVC已经线下通过非3GPP方式配对(例如两设备通过蓝牙配对)或者通过其他方式配对,则UAV可以获取与其配对的UAVC的配对标识。进一步的,C2配对请求2中可以包括UAVC的配对标识。示例性的,UAVC的配对标识例如可以为3GPP UAVC ID或者UAVC的外部UAV ID。Of course, if the UAV and the UAVC have been paired offline in a non-3GPP manner (for example, the two devices are paired via Bluetooth) or in other manners before step S1114, the UAV can obtain the pairing identifier of the UAVC paired with it. Further, the C2 pairing request 2 may include the pairing identifier of the UAVC. Exemplarily, the pairing identifier of the UAVC may be, for example, the 3GPP UAVC ID or the external UAV ID of the UAVC.
可选的,本申请实施例中,当UAVC的配对标识为UAVC的外部UAV ID时,UAVC的外部UAV ID可以包括在C2配对请求2的容器(container)中。这样,一方面,由于中间节点透传container不篡改container中内容,因此可以保证上述参数的安全性;另一方面,由于中间节点可以不解析上述参数,因此可以节省中间节点的处理资源,以及提高中间节点的处理效率。Optionally, in this embodiment of the present application, when the pairing identifier of the UAVC is the external UAV ID of the UAVC, the external UAV ID of the UAVC may be included in the container (container) of the C2 pairing request 2. In this way, on the one hand, since the intermediate node transparently transmits the container without tampering with the contents in the container, the security of the above parameters can be guaranteed; Processing efficiency of intermediate nodes.
S1115、UFES1向UTM/USS发送C2配对请求3。相应的,UTM/USS接收来自UFES1的C2配对请求3。该C2配对请求3包括UAV的外部UAV ID和第一用户面安全保护开启指示。S1115. UFES1 sends C2 pairing request 3 to UTM/USS. Correspondingly, UTM/USS receives C2 pairing request 3 from UFES1. The C2 pairing request 3 includes the external UAV ID of the UAV and the first user plane security protection opening instruction.
本申请实施例中,C2配对请求3中UAV的外部UAV ID是根据C2配对请求2中的3GPP UAV ID“翻译”转化得到的,转化方式可参考上述步骤S809,在此不再赘述。In the embodiment of the present application, the external UAV ID of the UAV in the C2 pairing request 3 is obtained by "translation" of the 3GPP UAV ID in the C2 pairing request 2, and the conversion method can refer to the above step S809, which will not be repeated here.
此外,本申请实施例中,UFES1获取UAV的外部UAV ID之后,可以根据存储的UAV的外部UAV ID和第一用户面安全保护开启指示的映射关系,确定第一用户面安全保护开启指示,并通过C2配对请求3发送给UTM/USS。In addition, in the embodiment of the present application, after the UFES1 obtains the external UAV ID of the UAV, it can determine the first user plane security protection opening instruction according to the stored mapping relationship between the external UAV ID of the UAV and the first user plane security protection opening instruction, and Sent to UTM/USS via C2 pairing request 3.
本申请实施例中,若上述C2配对请求2中包括UAVC的配对标识,则上述C2配对请求3中还包括UAVC的配对标识。其中,当UAVC的配对标识为3GPP UAVC ID时,UFES1还需要将3GPP UAVC ID“翻译”转化为UTM/USS能够识别的UAVC的外部UAV ID,并将UAVC的外部UAV ID发送给UTM/USS,转化方式可参考上述步骤S809,在此不再赘述。In the embodiment of the present application, if the above-mentioned C2 pairing request 2 includes the pairing identifier of the UAVC, the above-mentioned C2 pairing request 3 also includes the pairing identifier of the UAVC. Among them, when the pairing identifier of UAVC is 3GPP UAVC ID, UFES1 also needs to "translate" the 3GPP UAVC ID into the external UAV ID of UAVC that can be recognized by UTM/USS, and send the external UAV ID of UAVC to UTM/USS, For the conversion method, reference may be made to the above-mentioned step S809, which will not be repeated here.
S1116、UTM/USS确定与UAV配对的UAVC在网后,对C2配对请求进行授权。S1116: After the UTM/USS determines that the UAVC paired with the UAV is on the network, it authorizes the C2 pairing request.
步骤S1116的相关实现可参考图10所示的实施例中步骤S1004的描述,区别比如在于将步骤S1004中的C2配对请求1替换为本申请实施例中的C2配对请求3,在此不再赘述。For the related implementation of step S1116, reference may be made to the description of step S1004 in the embodiment shown in FIG. 10 . The difference is, for example, that the C2 pairing request 1 in step S1004 is replaced with the C2 pairing request 3 in this embodiment of the present application, which will not be repeated here. .
方式Y如下:The way Y is as follows:
S1117、UAV通过已经建立的第三PDU会话的用户面向UTM/USS发送C2配对请求1。相应的,UTM/USS接收来自UAV的C2配对请求1。该C2配对请求中包括UAV的外部UAV ID。S1117: The UAV sends a C2 pairing request 1 to the UTM/USS through the user of the established third PDU session. Accordingly, the UTM/USS receives the C2 pairing request 1 from the UAV. The C2 pairing request includes the UAV's external UAV ID.
步骤S1117的相关实现可参考图10所示的实施例中步骤S1003的描述,在此不再赘述。For the related implementation of step S1117, reference may be made to the description of step S1003 in the embodiment shown in FIG. 10, and details are not repeated here.
S1118、UTM/USS确定与UAV配对的UAVC在网后,对C2配对请求进行授权。S1118: After the UTM/USS determines that the UAVC paired with the UAV is on the network, it authorizes the C2 pairing request.
步骤S1118的具体实现可参考上述步骤S1116,区别比如在于将步骤S1116中的C2配对请求3替换为步骤S1118中的C2配对请求1,在此不再赘述。The specific implementation of step S1118 can refer to the above-mentioned step S1116. The difference is, for example, that the C2 pairing request 3 in step S1116 is replaced with the C2 pairing request 1 in step S1118, which will not be repeated here.
S1119、配对授权完成后,UTM/USS从UFES1获取第一用户面安全保护开启指示。S1119. After the pairing authorization is completed, the UTM/USS obtains the first user plane security protection opening instruction from the UFES1.
一种可能的实现方式中,UTM/USS向UFES1发送请求消息。该请求消息包括UAV的外部UAV ID,该请求消息用于请求第一用户面安全保护开启指示。UFES1接收该请求消息之后,可以根据存储的UAV的外部UAV ID和第一用户面安全保护开启指示的映射关系,确定第一用户面安全保护开启指示,并在向UTM/USS发送的响应消息中携带第一用户面安全保护开启指示。In a possible implementation manner, UTM/USS sends a request message to UFES1. The request message includes the external UAV ID of the UAV, and the request message is used to request the first user plane security protection opening instruction. After UFES1 receives the request message, it can determine the first user plane security protection opening instruction according to the stored mapping relationship between the external UAV ID of the UAV and the first user plane security protection opening instruction, and send it to the UTM/USS in the response message. Carry the first user plane security protection opening instruction.
需要说明的是,本申请实施例中,UTM/USS向UFES1发送的请求消息仅是图5所示的实施例第三消息的一种示例,第三消息还可以为其他,本申请实施例对此不做具体限定。It should be noted that, in the embodiment of the present application, the request message sent by the UTM/USS to the UFES1 is only an example of the third message in the embodiment shown in FIG. 5 , and the third message may also be other. This is not specifically limited.
需要说明的时,上述方式X或方式Y以UAV通过3GPP接入向UTM/USS发送C2配对请求为例进行说明。可选的,UAV也可以通过非3GPP接入向UTM/USS发送C2配对请求,该C2配对请求中包括UAV的外部UAV ID。UTM/USS接收C2配对请求之后,可以按照上述步骤S1118-S1119的方式获取第一用户面安全保护开启指示,在此不再赘述。When it needs to be explained, the foregoing manner X or manner Y is described by taking the UAV sending a C2 pairing request to the UTM/USS through 3GPP access as an example for description. Optionally, the UAV may also send a C2 pairing request to the UTM/USS through a non-3GPP access, where the C2 pairing request includes the UAV's external UAV ID. After the UTM/USS receives the C2 pairing request, it can obtain the first user plane security protection opening instruction in the manner of the above steps S1118-S1119, which will not be repeated here.
基于上述方式X或方式Y,UTM/USS可以通过配对授权流程获取第一用户面安全保护开启指示。进一步的,本申请实施例提供的通信方法还包括如下步骤S1120-S1121:Based on the foregoing manner X or manner Y, the UTM/USS may obtain the first user plane security protection activation instruction through the pairing authorization process. Further, the communication method provided by the embodiment of the present application further includes the following steps S1120-S1121:
S1120、配对授权完成后,UTM/USS通过UFES1向SMF1发送指示信息7。相应的,SMF1接收来自UTM/USS的指示信息7。指示信息7用于指示UAV与UAVC之间的C2配对授权成功。S1120. After the pairing authorization is completed, the UTM/USS sends the indication information 7 to the SMF1 through the UFES1. Correspondingly, the SMF1 receives the indication information 7 from the UTM/USS. The indication information 7 is used to indicate that the C2 pairing authorization between the UAV and the UAVC is successful.
S1121、SMF1触发建立第一PDU会话的流程。其中,本申请实施例中的第一PDU会话可以是修改上述第三PDU会话得到的,也可以是SMF触发UAV新建得到的,本申请实施例对此不做具体限定。基于第三PDU会话修改得到第一PDU会话的流程以及新建第一PDU会话的流程均可参考现有技术,在此不再赘述。S1121. SMF1 triggers the process of establishing the first PDU session. The first PDU session in the embodiment of the present application may be obtained by modifying the third PDU session, or may be obtained by creating a new UAV triggered by the SMF, which is not specifically limited in the embodiment of the present application. The process of modifying and obtaining the first PDU session based on the third PDU session and the process of creating the first PDU session can refer to the prior art, and details are not repeated here.
基于上述方式方案,UTM/USS可以获取第一用户面安全保护开启指示。进一步的,为UAVC服务的SMF2可以在UAVC建立用于承载C2通信的第二PDU会话的过程中获取该第一用户面安全保护开启指示或者获取根据该第一用户面安全保护开启指示更新的UAVC对应的第二用户面安全保护策略。其中,第二PDU会话的用户面安全保护是否开启由第一用户面安全保护开启指示确定或者第二用户面安全保护策略确定。相关实现可参考图8所示的实施例中的步骤S814-S828,在此不再赘述。Based on the above solutions, the UTM/USS can obtain the first user plane security protection opening instruction. Further, the SMF2 serving the UAVC may acquire the first user plane security protection enable instruction or acquire the UAVC updated according to the first user plane security protection enable instruction during the process of establishing the second PDU session for carrying the C2 communication by the UAVC. The corresponding second user plane security protection policy. Wherein, whether the user plane security protection of the second PDU session is enabled is determined by the first user plane security protection enable instruction or the second user plane security protection policy. For related implementation, reference may be made to steps S814-S828 in the embodiment shown in FIG. 8 , and details are not described herein again.
基于本申请实施例提供的通信方法,由于UTM/USS可以基于配对授权流程的触发,通过为UAV服务的UFES1获取用于指示承载C2通信的第一PDU会话的用户面安全保护是否开启的第一用户面安全保护开启指示,并且为UAVC服务的SMF2可以在UAVC建立承载C2通信的第二PDU会话的过程中获取该第一用户面安全保护开启指示或者获取根据该第一用户面安全保护开启指示更新的UAVC对应的第二用户面安全保护策略。其中,第二PDU会话的用户面安全保护是否开启由第一用户面安全保护开启指示确定或者第二用户面安全保护策略确定。因此基于该方案,可以保证UAV侧的用于承载C2通信的第一PDU会话的用户面安全保护的开启方式和UAVC侧的用于承载C2通信的第二PDU会话的用户面安全保护的开启方式相同,从而可以保证UAV和UAVC之间的C2通信的用户面安全保护的一致性。Based on the communication method provided by the embodiment of the present application, since the UTM/USS can be triggered based on the pairing authorization process, the UFES1 serving the UAV can obtain the first information for indicating whether the user plane security protection of the first PDU session carrying the C2 communication is enabled or not. The user plane security protection enable instruction, and the SMF2 serving the UAVC can obtain the first user plane security protection enable instruction or obtain the first user plane security protection enable instruction in the process of establishing the second PDU session carrying the C2 communication in the UAVC The second user plane security protection policy corresponding to the updated UAVC. Wherein, whether the user plane security protection of the second PDU session is enabled is determined by the first user plane security protection enable instruction or the second user plane security protection policy. Therefore, based on this solution, it is possible to ensure the enabling method of the user plane security protection on the UAV side for carrying the first PDU session of the C2 communication and the enabling method of the user plane security protection on the UAVC side for carrying the second PDU session of the C2 communication. The same, so that the consistency of the user plane security protection of the C2 communication between the UAV and the UAVC can be guaranteed.
其中,上述步骤S1101a至S1121中SMF1、UTM/USS、SMF2、UFES1或者UFES2的动作可以由图4所示的通信装置400中的处理器401调用存储器403中存储的应用程序代码以指令SMF1、UTM/USS、SMF2、UFES1或者UFES2执行,本实施例对此不作任何限制。Wherein, the actions of SMF1, UTM/USS, SMF2, UFES1 or UFES2 in the above steps S1101a to S1121 can be performed by the processor 401 in the communication device 400 shown in FIG. 4 calling the application code stored in the memory 403 to instruct SMF1, UTM /USS, SMF2, UFES1, or UFES2 is executed, which is not limited in this embodiment.
作为一种替代方案,图11所示的实施例中,UFES1在第三PDU会话建立的流程中获取第一用户面安全保护开启指示之后,可以在步骤S1112所述的第三PDU会话建立的其他流程向UTM/USS发送第一用户面安全保护开启指示。比如,UFES1可以通过上述的UUAA请求3向UTM/USS发送第一用户面安全保护开启指示。这样,UFES1接收到UUAA请求3之后,即可获取第一用户面安全保护开启指示,不需要通过图11所示的实施例中的方式X或方式Y获取第一用户面安全保护开启指示,本申请实施例对该方案不再详细具体阐述,具体可参考图11所示的实施例中的相关步骤。As an alternative, in the embodiment shown in FIG. 11 , after the UFES1 obtains the first user plane security protection opening instruction in the process of establishing the third PDU session, it can establish other other functions in the third PDU session described in step S1112. The process sends the first user plane security protection opening indication to the UTM/USS. For example, the UFES1 may send the first user plane security protection opening indication to the UTM/USS through the above-mentioned UUAA request 3. In this way, after receiving the UUAA request 3, UFES1 can obtain the first user plane security protection opening instruction, and does not need to obtain the first user plane security protection opening instruction through the mode X or mode Y in the embodiment shown in FIG. 11 . This solution is not described in detail in the application examples, and for details, reference may be made to the relevant steps in the embodiment shown in FIG. 11 .
可以理解的是,以上各个实施例中,由管理设备实现的方法和/或步骤,也可以由可用于管理设备的部件(例如芯片或者电路)实现;由会话管理实体(包括第一会话管理实体或第二会话管理实体)实现的方法和/或步骤,也可以由可用于会话管理实体的部件(例如芯片或者电路)实现。It can be understood that, in the above embodiments, the methods and/or steps implemented by the management device may also be implemented by a component (such as a chip or circuit) that can be used to manage the device; the session management entity (including the first session management entity) or the second session management entity), the methods and/or steps implemented by the session management entity may also be implemented by components (eg, chips or circuits) available for the session management entity.
上述主要从各个网元之间交互的角度对本申请实施例提供的方案进行了介绍。相应的,本申请实施例还提供了通信装置,该通信装置用于实现上述各种方法。该通信装置可以为上述方法实施例中的管理设备,或者包含上述管理设备的装置,或者为可用于管理设备的部件;或者,该通信装置可以为上述方法实施例中的会话管理实体(包括第一会话管理实体或第二会话管理实体),或者包含上述会话管理实体的装置,或者为可用于会话管理实体的部件。可以理解的是,该通信装置为了实现上述功能,其包含了执行各个功能相应的硬件结构和/或软件模块。本领域技术人员应该很容易意识到,结合本文中所公开的实施例描述的各示例的单元及算法步骤,本申请能够以硬件或硬件和计算机软件的结合形式来实现。某个功能究竟以硬件还是计算机软件驱动硬件的方式来执行,取决于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本申请的范围。The foregoing mainly introduces the solutions provided by the embodiments of the present application from the perspective of interaction between various network elements. Correspondingly, an embodiment of the present application further provides a communication device, where the communication device is used to implement the above-mentioned various methods. The communication device may be the management device in the above method embodiment, or a device including the above management device, or a component that can be used to manage the device; or, the communication device may be the session management entity in the above method embodiment (including the first A session management entity or a second session management entity), or a device including the above session management entity, or a component available for the session management entity. It can be understood that, in order to realize the above-mentioned functions, the communication apparatus includes corresponding hardware structures and/or software modules for executing each function. Those skilled in the art should easily realize that the present application can be implemented in hardware or a combination of hardware and computer software with the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein. Whether a function is performed by hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Skilled artisans may implement the described functionality using different methods for each particular application, but such implementations should not be considered beyond the scope of this application.
本申请实施例可以根据上述方法实施例中对通信装置进行功能模块的划分,例如,可以对应各个功能划分各个功能模块,也可以将两个或两个以上的功能集成在一个处理模块中。上述集成的模块既可以采用硬件的形式实现,也可以采用软件功能模块的形式实现。需要说明的是,本申请实施例中对模块的划分是示意性的,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式。In this embodiment of the present application, the communication device may be divided into functional modules according to the above method embodiments. For example, each functional module may be divided corresponding to each function, or two or more functions may be integrated into one processing module. The above-mentioned integrated modules can be implemented in the form of hardware, and can also be implemented in the form of software function modules. It should be noted that, the division of modules in the embodiments of the present application is schematic, and is only a logical function division, and there may be other division manners in actual implementation.
图12示出了一种通信装置120的结构示意图。该通信装置120包括收发模块1201和处理模块1202。所述收发模块1201,也可以称为收发单元用以实现收发功能,例如可以是收发电路,收发机,收发器或者通信接口。FIG. 12 shows a schematic structural diagram of a communication device 120 . The communication device 120 includes a transceiver module 1201 and a processing module 1202 . The transceiver module 1201 may also be called a transceiver unit to implement a transceiver function, for example, a transceiver circuit, a transceiver, a transceiver or a communication interface.
其中,以通信装置120为上述方法实施例中的管理设备为例:Wherein, take the communication device 120 as the management device in the above method embodiment as an example:
一种可能的实现方式中,处理模块1202,用于获取第一用户面安全保护开启指示,第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。其中,第一会话为第一终端设备用于承载C2通信的会话,第一终端设备为C2通信的发起端 设备,第二终端设备为C2通信的对端设备,C2通信为第一终端设备与第二终端设备之间的通信。收发模块1201,用于触发第二终端设备发起第二会话的建立,其中,第二会话的用户面安全保护是否开启由第一用户面安全保护开启指示确定,第二会话为第二终端设备用于承载C2通信的会话。In a possible implementation manner, the processing module 1202 is configured to obtain the first user plane security protection enable instruction, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled. The first session is a session used by the first terminal device to carry the C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the C2 communication device. Communication between second terminal devices. The transceiver module 1201 is configured to trigger the second terminal device to initiate the establishment of a second session, wherein whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction, and the second session is used by the second terminal device. for sessions that carry C2 communications.
一种可能的实现方式中,收发模块1201,用于触发第二终端设备发起第二会话的建立,包括:向第二终端设备发送第一消息,第一消息用于触发第二终端设备发起第二会话的建立;以及,向第二统一数据管理实体发送第一用户面安全保护开启指示,其中,第二统一数据管理实体是为第二终端设备服务的统一数据管理实体。In a possible implementation manner, the transceiver module 1201, configured to trigger the second terminal device to initiate the establishment of the second session, includes: sending a first message to the second terminal device, where the first message is used to trigger the second terminal device to initiate the second session. Two sessions are established; and sending a first user plane security protection opening indication to a second unified data management entity, where the second unified data management entity is a unified data management entity serving the second terminal device.
另一种可能的实现方式中,收发模块1201,用于触发第二终端设备发起第二会话的建立,包括:向第二终端设备发送第一消息,第一消息用于触发第二终端设备发起第二会话的建立;以及,接收来自第二代理功能实体的第二消息,并向第二代理功能实体发送第一用户面安全保护开启指示;其中,第二消息包括第二终端设备的标识信息,第二消息用于请求第一用户面安全保护开启指示,第二代理功能实体用于提供第二会话管理实体到管理设备的接口,第二会话管理实体是为第二终端设备服务的会话管理实体。In another possible implementation manner, the transceiver module 1201, configured to trigger the second terminal device to initiate the establishment of the second session, includes: sending a first message to the second terminal device, where the first message is used to trigger the second terminal device to initiate the establishment of the second session establishment of a second session; and, receiving a second message from the second proxy function entity, and sending a first user plane security protection opening indication to the second proxy function entity; wherein the second message includes the identification information of the second terminal device , the second message is used to request the first user plane security protection opening instruction, the second proxy function entity is used to provide the interface of the second session management entity to the management device, and the second session management entity is the session management for the second terminal device. entity.
一种可能的实现方式中,处理模块1202具体用于:通过收发模块1201接收来自第一会话管理实体的第一用户面安全保护开启指示,第一会话管理实体是为第一终端设备服务的会话管理实体;或者,通过收发模块1201接收来自第一终端设备的第一用户面安全保护开启指示;或者,通过收发模块1201接收来自第一代理功能实体的第一用户面安全保护开启指示,第一代理功能实体用于提供第一会话管理实体到管理设备的接口。In a possible implementation manner, the processing module 1202 is specifically configured to: receive, through the transceiver module 1201, a first user plane security protection opening instruction from a first session management entity, where the first session management entity is a session serving the first terminal device. management entity; or, receive the first user plane security protection opening instruction from the first terminal device through the transceiver module 1201; or, receive the first user plane security protection opening instruction from the first proxy function entity through the transceiver module 1201, the first The proxy function entity is used to provide an interface from the first session management entity to the management device.
另一种可能的实现方式中,处理模块1202具体用于:确定第一终端设备与第二终端设备配对授权成功;通过收发模块1201向第一代理功能实体发送第三消息,第三消息包括第一终端设备的标识信息,第三消息用于请求第一用户面安全保护开启指示;其中,第一代理功能实体用于提供第一会话管理实体到管理设备的接口,第一会话管理实体是为第一终端设备服务的会话管理实体;通过收发模块1201接收来自第一代理功能实体的第一用户面安全保护开启指示。In another possible implementation manner, the processing module 1202 is specifically configured to: determine that the pairing authorization between the first terminal device and the second terminal device is successful; send a third message to the first proxy function entity through the transceiver module 1201, where the third message includes the first The identification information of the terminal device, and the third message is used to request the first user plane security protection opening instruction; wherein, the first proxy function entity is used to provide the interface from the first session management entity to the management device, and the first session management entity is for The session management entity served by the first terminal device; the receiving and sending module 1201 receives the first user plane security protection opening instruction from the first proxy function entity.
以通信装置120为上述方法实施例中的第一会话管理实体为例:Taking the communication device 120 as the first session management entity in the above method embodiment as an example:
一种可能的实现方式中,处理模块1202,用于获取第一用户面安全保护开启指示,第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。其中,第一会话为第一终端设备用于承载C2通信的会话,第一终端设备为C2通信的发起端设备,第二终端设备为C2通信的对端设备,C2通信为第一终端设备与第二终端设备之间的通信,第一会话管理实体是为第一终端设备服务的会话管理实体。收发模块1201,用于发送第一用户面安全保护开启指示,第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,第二会话为第二终端设备用于承载C2通信的会话。In a possible implementation manner, the processing module 1202 is configured to obtain the first user plane security protection enable instruction, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled. The first session is a session used by the first terminal device to carry the C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the C2 communication device. In the communication between the second terminal devices, the first session management entity is a session management entity serving the first terminal device. The transceiver module 1201 is configured to send a first user plane security protection enable instruction, the first user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is the second terminal device for carrying C2 communication session.
一种可能的实现方式中,收发模块1201具体用于:向管理设备发送第一用户面安全保护开启指示。In a possible implementation manner, the transceiver module 1201 is specifically configured to: send the first user plane security protection opening instruction to the management device.
另一种可能的实现方式中,收发模块1201具体用于:向第一代理功能实体发送第 一用户面安全保护开启指示;其中,第一代理功能实体用于提供第一会话管理实体到管理设备的接口。In another possible implementation manner, the transceiver module 1201 is specifically configured to: send the first user plane security protection enabling instruction to the first proxy function entity; wherein the first proxy function entity is configured to provide the first session management entity to the management device Interface.
可选的,本申请实施例中,收发模块1201,还用于在第一会话管理实体向第一代理功能实体发送第一用户面安全保护开启指示之前,接收来自第一代理功能实体的第四消息,第四消息包括第一终端设备的标识信息,第四消息用于请求第一用户面安全保护开启指示。Optionally, in this embodiment of the present application, the transceiver module 1201 is further configured to receive a fourth message from the first proxy functional entity before the first session management entity sends the first user plane security protection opening instruction to the first proxy functional entity. message, the fourth message includes identification information of the first terminal device, and the fourth message is used to request the first user plane security protection opening instruction.
一种可能的实现方式中,处理模块1202具体用于:从为第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;通过收发模块1201向为第一终端设备服务的第一接入网设备发送第一用户面安全保护策略;通过收发模块1201接收来自第一接入网设备的第一用户面安全保护开启指示,其中,第一用户面安全保护开启指示是根据第一用户面安全保护策略确定的。In a possible implementation manner, the processing module 1202 is specifically configured to: obtain the first user plane security protection policy from the first unified data management entity serving the first terminal device; The first access network device sends the first user plane security protection policy; the transceiver module 1201 receives the first user plane security protection enable instruction from the first access network device, wherein the first user plane security protection enable instruction is based on the first user plane security protection enable instruction. A user plane security protection policy is determined.
一种可能的实现方式中,处理模块1202具体用于:从为第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;通过收发模块1201向为第一终端设备服务的第一接入网设备发送第一用户面安全保护策略;通过收发模块1201接收来自第一接入网设备的第七消息,第七消息用于指示第一接入网设备已经根据第一用户面安全保护策略建立第一会话;响应于第七消息,根据所述第一用户面安全保护策略确定所述第一用户面安全保护开启指示。In a possible implementation manner, the processing module 1202 is specifically configured to: obtain the first user plane security protection policy from the first unified data management entity serving the first terminal device; The first access network device sends the first user plane security protection policy; the transceiver module 1201 receives a seventh message from the first access network device, where the seventh message is used to indicate that the first access network device has The security protection policy establishes a first session; and in response to the seventh message, the first user plane security protection opening indication is determined according to the first user plane security protection policy.
以通信装置120为上述方法实施例中的第二会话管理实体为例:Taking the communication device 120 as the second session management entity in the above method embodiment as an example:
一种可能的实现方式中,处理模块1202,用于获取第一用户面安全保护开启指示,第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。其中,第一会话为第一终端设备用于承载C2通信的会话,第一终端设备为C2通信的发起端设备,第二终端设备为C2通信的对端设备,C2通信为第一终端设备与第二终端设备之间的通信,第二会话管理实体是为第二终端设备服务的会话管理实体。收发模块1201,用于向为第二终端设备服务的第二接入网设备发送第一用户面安全保护开启指示;其中,第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,第二会话为第二终端设备用于承载C2通信的会话。In a possible implementation manner, the processing module 1202 is configured to obtain the first user plane security protection enable instruction, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled. The first session is a session used by the first terminal device to carry the C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the C2 communication device. For communication between second terminal devices, the second session management entity is a session management entity serving the second terminal device. The transceiver module 1201 is configured to send a first user plane security protection opening instruction to a second access network device serving the second terminal device; wherein the first user plane security protection opening instruction is used to determine the user plane security of the second session Whether protection is enabled, the second session is a session used by the second terminal device to carry C2 communication.
以通信装置120为上述方法实施例中的第二会话管理实体为例:Taking the communication device 120 as the second session management entity in the above method embodiment as an example:
一种可能的实现方式中,处理模块1202,用于获取第一用户面安全保护开启指示,第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启。其中,第一会话为第一终端设备用于承载C2通信的会话,第一终端设备为C2通信的发起端设备,第二终端设备为C2通信的对端设备,C2通信为第一终端设备与第二终端设备之间的通信,第二会话管理实体是为第二终端设备服务的会话管理实体。处理模块1202,还用于根据第一用户面安全保护开启指示确定第三用户面安全保护策略,第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护。收发模块1201,用于向为第二终端设备服务的第二接入网设备发送第三用户面安全保护策略;其中,第三用户面安全保护策略用于确定第二用户面安全保护开启指示,第二用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,第二会话为第二终端设备用于承载C2通信的会话。In a possible implementation manner, the processing module 1202 is configured to obtain the first user plane security protection enable instruction, and the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled. The first session is a session used by the first terminal device to carry the C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the C2 communication device. For communication between second terminal devices, the second session management entity is a session management entity serving the second terminal device. The processing module 1202 is further configured to determine a third user plane security protection policy according to the first user plane security protection enabling instruction, where the third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection. The transceiver module 1201 is configured to send a third user plane security protection policy to a second access network device serving the second terminal device; wherein, the third user plane security protection policy is used to determine an instruction to enable the second user plane security protection, The second user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is a session used by the second terminal device to carry C2 communication.
本申请实施例中,处理模块1202,用于根据第一用户面安全保护开启指示确定第 三用户面安全保护策略的方案可参考前述发明内容部分,在此不再赘述。In this embodiment of the present application, for the solution of the processing module 1202 for determining the third user plane security protection policy according to the first user plane security protection enable instruction, reference may be made to the foregoing summary of the invention, which will not be repeated here.
一种可能的实现方式中,处理模块1202,用于获取第一用户面安全保护开启指示,包括:通过收发模块1201向为第二终端设备服务的第二统一数据管理实体发送第五消息,第五消息包括第二终端设备的标识信息,第五消息用于请求第二用户面安全保护策略;通过收发模块1201接收来自第二统一数据管理实体的第二用户面安全保护策略和第一用户面安全保护开启指示。In a possible implementation manner, the processing module 1202, configured to obtain the first user plane security protection opening instruction, includes: sending a fifth message to the second unified data management entity serving the second terminal device through the transceiver module 1201, the first The fifth message includes the identification information of the second terminal device, and the fifth message is used to request the second user plane security protection policy; the second user plane security protection policy and the first user plane security protection policy from the second unified data management entity are received through the transceiver module 1201 Safety protection on indication.
另一种可能的实现方式中,处理模块1202,用于获取第一用户面安全保护开启指示,包括:通过收发模块1201向第二代理功能实体发送第六消息,第六消息包括第二终端设备的标识信息,第六消息用于请求第一用户面安全保护开启指示,第二代理功能实体用于提供第二会话管理实体到管理设备的接口;通过收发模块1201接收来自第二代理功能实体的第一用户面安全保护开启指示。In another possible implementation manner, the processing module 1202, configured to obtain the first user plane security protection enabling indication, includes: sending a sixth message to the second proxy function entity through the transceiver module 1201, where the sixth message includes the second terminal device The sixth message is used to request the first user plane security protection opening instruction, and the second proxy function entity is used to provide the interface from the second session management entity to the management device; The first user plane security protection activation instruction.
可选的,本申请实施例中,收发模块1201,还用于在向第二代理功能实体发送第六消息之前,接收来自第二终端设备的指示信息,指示信息指示第二终端设备请求建立的第二会话用于响应第一终端设备发起的C2通信。Optionally, in this embodiment of the present application, the transceiver module 1201 is further configured to receive indication information from the second terminal device before sending the sixth message to the second proxy function entity, where the indication information indicates that the second terminal device requests to establish a The second session is used to respond to the C2 communication initiated by the first terminal device.
其中,上述方法实施例涉及的各步骤的所有相关内容均可以援引到对应功能模块的功能描述,在此不再赘述。Wherein, all relevant contents of the steps involved in the above method embodiments can be cited in the functional descriptions of the corresponding functional modules, which will not be repeated here.
在本实施例中,该通信装置120以采用集成的方式划分各个功能模块的形式来呈现。这里的“模块”可以指特定ASIC,电路,执行一个或多个软件或固件程序的处理器和存储器,集成逻辑电路,和/或其他可以提供上述功能的器件。在一个简单的实施例中,本领域的技术人员可以想到该通信装置120可以采用图4所示的通信装置400的形式。In this embodiment, the communication apparatus 120 is presented in the form of dividing each functional module in an integrated manner. "Module" herein may refer to a specific ASIC, circuit, processor and memory executing one or more software or firmware programs, integrated logic circuit, and/or other device that may provide the functions described above. In a simple embodiment, those skilled in the art can imagine that the communication device 120 may take the form of the communication device 400 shown in FIG. 4 .
比如,图4所示的通信装置400中的处理器401可以通过调用存储器403中存储的计算机执行指令,使得通信装置400执行上述方法实施例中的通信方法。For example, the processor 401 in the communication apparatus 400 shown in FIG. 4 may execute the instructions by calling the computer stored in the memory 403, so that the communication apparatus 400 executes the communication method in the above method embodiment.
具体的,图12中的收发模块1201和处理模块1202的功能/实现过程可以通过图4所示的通信装置400中的处理器401调用存储器403中存储的计算机执行指令来实现。或者,图12中的处理模块1202的功能/实现过程可以通过图4所示的通信装置400中的处理器401调用存储器403中存储的计算机执行指令来实现,图12中的收发模块1201的功能/实现过程可以通过图4中所示的通信装置400中的通信接口404来实现。Specifically, the functions/implementation process of the transceiver module 1201 and the processing module 1202 in FIG. 12 can be implemented by the processor 401 in the communication apparatus 400 shown in FIG. 4 calling the computer execution instructions stored in the memory 403 . Alternatively, the function/implementation process of the processing module 1202 in FIG. 12 can be implemented by the processor 401 in the communication device 400 shown in FIG. 4 calling the computer execution instructions stored in the memory 403, and the function of the transceiver module 1201 in FIG. 12 can be implemented. The implementation process can be implemented through the communication interface 404 in the communication device 400 shown in FIG. 4 .
由于本实施例提供的通信装置120可执行上述通信方法,因此其所能获得的技术效果可参考上述方法实施例,在此不再赘述。Since the communication apparatus 120 provided in this embodiment can execute the above communication method, the technical effects that can be obtained by the communication apparatus 120 may refer to the above method embodiments, which will not be repeated here.
需要说明的是,以上模块或单元的一个或多个可以软件、硬件或二者结合来实现。当以上任一模块或单元以软件实现的时候,所述软件以计算机程序指令的方式存在,并被存储在存储器中,处理器可以用于执行所述程序指令并实现以上方法流程。该处理器可以内置于SoC(片上系统)或ASIC,也可是一个独立的半导体芯片。该处理器内处理用于执行软件指令以进行运算或处理的核外,还可进一步包括必要的硬件加速器,如现场可编程门阵列(field programmable gate array,FPGA)、PLD(可编程逻辑器件)、或者实现专用逻辑运算的逻辑电路。It should be noted that, one or more of the above modules or units may be implemented by software, hardware or a combination of both. When any of the above modules or units are implemented in software, the software exists in the form of computer program instructions and is stored in the memory, and the processor can be used to execute the program instructions and implement the above method flow. The processor can be built into a SoC (system on chip) or an ASIC, or it can be an independent semiconductor chip. In addition to the core for executing software instructions for operation or processing, the internal processing of the processor may further include necessary hardware accelerators, such as field programmable gate array (FPGA), PLD (Programmable Logic Device) , or a logic circuit that implements dedicated logic operations.
当以上模块或单元以硬件实现的时候,该硬件可以是CPU、微处理器、数字信号处理(digital signal processing,DSP)芯片、微控制单元(microcontroller unit,MCU)、人工智能处理器、ASIC、SoC、FPGA、PLD、专用数字电路、硬件加速器或非集成的分立器件中 的任一个或任一组合,其可以运行必要的软件或不依赖于软件以执行以上方法流程。When the above modules or units are implemented in hardware, the hardware can be CPU, microprocessor, digital signal processing (DSP) chip, microcontroller unit (MCU), artificial intelligence processor, ASIC, Any or any combination of SoCs, FPGAs, PLDs, dedicated digital circuits, hardware accelerators, or non-integrated discrete devices that may or may not run the necessary software to perform the above method flows.
可选的,本申请实施例还提供了一种芯片系统,包括:至少一个处理器和接口,该至少一个处理器通过接口与存储器耦合,当该至少一个处理器执行存储器中的计算机程序或指令时,使得上述任一方法实施例中的方法被执行。在一种可能的实现方式中,该通信装置还包括存储器。可选的,该芯片系统可以由芯片构成,也可以包含芯片和其他分立器件,本申请实施例对此不作具体限定。Optionally, an embodiment of the present application further provides a chip system, including: at least one processor and an interface, the at least one processor is coupled to the memory through the interface, and when the at least one processor executes the computer program or instructions in the memory , the method in any of the above method embodiments is executed. In a possible implementation, the communication device further includes a memory. Optionally, the chip system may be composed of chips, or may include chips and other discrete devices, which are not specifically limited in this embodiment of the present application.
在上述实施例中,可以全部或部分地通过软件、硬件、固件或者其任意组合来实现。当使用软件程序实现时,可以全部或部分地以计算机程序产品的形式来实现。该计算机程序产品包括一个或多个计算机指令。在计算机上加载和执行计算机程序指令时,全部或部分地产生按照本申请实施例所述的流程或功能。所述计算机可以是通用计算机、专用计算机、计算机网络、或者其他可编程装置。所述计算机指令可以存储在计算机可读存储介质中,或者从一个计算机可读存储介质向另一个计算机可读存储介质传输,例如,所述计算机指令可以从一个网站站点、计算机、服务器或者数据中心通过有线(例如同轴电缆、光纤、数字用户线(digital subscriber line,DSL))或无线(例如红外、无线、微波等)方式向另一个网站站点、计算机、服务器或数据中心进行传输。所述计算机可读存储介质可以是计算机能够存取的任何可用介质或者是包含一个或多个可以用介质集成的服务器、数据中心等数据存储设备。所述可用介质可以是磁性介质(例如,软盘、硬盘、磁带),光介质(例如,DVD)、或者半导体介质(例如固态硬盘(solid state disk,SSD))等。In the above-mentioned embodiments, it may be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on the computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer may be a general purpose computer, special purpose computer, computer network, or other programmable device. The computer instructions may be stored in or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions may be downloaded from a website site, computer, server, or data center Transmission to another website site, computer, server, or data center by wire (eg, coaxial cable, optical fiber, digital subscriber line, DSL) or wireless (eg, infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or data storage devices including one or more servers, data centers, etc. that can be integrated with the medium. The usable media may be magnetic media (eg, floppy disks, hard disks, magnetic tapes), optical media (eg, DVDs), or semiconductor media (eg, solid state disks (SSDs)), and the like.
尽管在此结合各实施例对本申请进行了描述,然而,在实施所要求保护的本申请过程中,本领域技术人员通过查看所述附图、公开内容、以及所附权利要求书,可理解并实现所述公开实施例的其他变化。在权利要求中,“包括”(comprising)一词不排除其他组成部分或步骤,“一”或“一个”不排除多个的情况。单个处理器或其他单元可以实现权利要求中列举的若干项功能。相互不同的从属权利要求中记载了某些措施,但这并不表示这些措施不能组合起来产生良好的效果。Although the application is described herein in conjunction with the various embodiments, those skilled in the art will understand and understand from a review of the drawings, the disclosure, and the appended claims in practicing the claimed application. Other variations of the disclosed embodiments are implemented. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude a plurality. A single processor or other unit may fulfill the functions of several items recited in the claims. The mere fact that certain measures are recited in mutually different dependent claims does not indicate that these measures cannot be combined to advantage.
尽管结合具体特征及其实施例对本申请进行了描述,显而易见的,在不脱离本申请的精神和范围的情况下,可对其进行各种修改和组合。相应地,本说明书和附图仅仅是所附权利要求所界定的本申请的示例性说明,且视为已覆盖本申请范围内的任意和所有修改、变化、组合或等同物。显然,本领域的技术人员可以对本申请进行各种改动和变型而不脱离本申请的精神和范围。这样,倘若本申请的这些修改和变型属于本申请权利要求及其等同技术的范围之内,则本申请也意图包含这些改动和变型在内。Although the application has been described in conjunction with specific features and embodiments thereof, it will be apparent that various modifications and combinations can be made therein without departing from the spirit and scope of the application. Accordingly, this specification and drawings are merely exemplary illustrations of the application as defined by the appended claims, and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of this application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

Claims (46)

  1. 一种通信方法,其特征在于,所述方法包括:A communication method, characterized in that the method comprises:
    管理设备获取第一用户面安全保护开启指示,所述第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,所述第一会话为第一终端设备用于承载C2通信的会话,所述第一终端设备为所述C2通信的发起端设备,第二终端设备为所述C2通信的对端设备,所述C2通信为所述第一终端设备与所述第二终端设备之间的通信;The management device acquires a first user plane security protection opening instruction, and the first user plane security protection opening instruction is used to indicate whether the user plane security protection of the first session is enabled; wherein, the first session is used by the first terminal device for A session carrying C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the communication between the first terminal device and the C2 communication. communication between second terminal devices;
    所述管理设备触发所述第二终端设备发起第二会话的建立,其中,所述第二会话的用户面安全保护是否开启由所述第一用户面安全保护开启指示确定,所述第二会话为所述第二终端设备用于承载所述C2通信的会话。The management device triggers the second terminal device to initiate the establishment of a second session, wherein whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction, and the second session is the session used by the second terminal device to carry the C2 communication.
  2. 根据权利要求1所述的方法,其特征在于,所述管理设备触发所述第二终端设备发起第二会话的建立,包括:The method according to claim 1, wherein the management device triggering the second terminal device to initiate the establishment of the second session comprises:
    所述管理设备向所述第二终端设备发送第一消息,所述第一消息用于触发所述第二终端设备发起所述第二会话的建立;sending, by the management device, a first message to the second terminal device, where the first message is used to trigger the second terminal device to initiate establishment of the second session;
    以及,所述管理设备向第二统一数据管理实体发送所述第一用户面安全保护开启指示,其中,所述第二统一数据管理实体是为所述第二终端设备服务的统一数据管理实体。And, the management device sends the first user plane security protection opening indication to a second unified data management entity, where the second unified data management entity is a unified data management entity serving the second terminal device.
  3. 根据权利要求1所述的方法,其特征在于,所述管理设备触发所述第二终端设备发起第二会话的建立,包括:The method according to claim 1, wherein the management device triggering the second terminal device to initiate the establishment of the second session comprises:
    所述管理设备向所述第二终端设备发送第一消息,所述第一消息用于触发所述第二终端设备发起第二会话的建立;sending, by the management device, a first message to the second terminal device, where the first message is used to trigger the second terminal device to initiate establishment of a second session;
    以及,所述管理设备接收来自第二代理功能实体的第二消息,并向所述第二代理功能实体发送所述第一用户面安全保护开启指示;其中,所述第二消息包括所述第二终端设备的标识信息,所述第二消息用于请求所述第一用户面安全保护开启指示,所述第二代理功能实体用于提供第二会话管理实体到所述管理设备的接口,所述第二会话管理实体是为所述第二终端设备服务的会话管理实体。And, the management device receives the second message from the second proxy function entity, and sends the first user plane security protection opening indication to the second proxy function entity; wherein, the second message includes the first The identification information of the second terminal device, the second message is used to request the first user plane security protection opening instruction, the second proxy function entity is used to provide the interface from the second session management entity to the management device, so The second session management entity is a session management entity serving the second terminal device.
  4. 根据权利要求1-3任一项所述的方法,其特征在于,所述管理设备获取第一用户面安全保护开启指示,包括:The method according to any one of claims 1-3, wherein the obtaining, by the management device, the first user plane security protection enabling instruction, comprises:
    所述管理设备接收来自第一会话管理实体的所述第一用户面安全保护开启指示,所述第一会话管理实体是为所述第一终端设备服务的会话管理实体;receiving, by the management device, an indication of enabling the security protection of the first user plane from a first session management entity, where the first session management entity is a session management entity serving the first terminal device;
    或者,所述管理设备接收来自所述第一终端设备的所述第一用户面安全保护开启指示;Or, the management device receives the first user plane security protection opening instruction from the first terminal device;
    或者,所述管理设备接收来自第一代理功能实体的所述第一用户面安全保护开启指示,所述第一代理功能实体用于提供所述第一会话管理实体到所述管理设备的接口。Alternatively, the management device receives the first user plane security protection opening instruction from a first proxy function entity, where the first proxy function entity is configured to provide an interface from the first session management entity to the management device.
  5. 根据权利要求1-3任一项所述的方法,其特征在于,所述管理设备获取第一用户面安全保护开启指示,包括:The method according to any one of claims 1-3, wherein the obtaining, by the management device, the first user plane security protection enabling instruction, comprises:
    所述管理设备确定所述第一终端设备与所述第二终端设备配对授权成功;The management device determines that the pairing authorization between the first terminal device and the second terminal device is successful;
    所述管理设备向第一代理功能实体发送第三消息,所述第三消息包括所述第一终端设备的标识信息,所述第三消息用于请求所述第一用户面安全保护开启指示;其中, 所述第一代理功能实体用于提供第一会话管理实体到所述管理设备的接口,所述第一会话管理实体是为所述第一终端设备服务的会话管理实体;The management device sends a third message to the first proxy function entity, where the third message includes identification information of the first terminal device, and the third message is used to request the first user plane security protection opening instruction; wherein, the first proxy function entity is used to provide an interface from a first session management entity to the management device, where the first session management entity is a session management entity serving the first terminal device;
    所述管理设备接收来自所述第一代理功能实体的所述第一用户面安全保护开启指示。The management device receives the first user plane security protection opening instruction from the first proxy function entity.
  6. 根据权利要求1-5任一项所述的方法,其特征在于,所述第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示;所述第一用户面机密性保护开启结果指示用于指示用户面机密性保护开启或不开启;所述第一用户面完整性保护开启结果指示用于指示用户面完整性保护开启或不开启。The method according to any one of claims 1-5, wherein the first user plane security protection enabling indication comprises a first user plane confidentiality protection enabling result indication and a first user plane integrity protection enabling result indication The first user plane confidentiality protection opening result indication is used to indicate that the user plane confidentiality protection is turned on or not turned on; the first user plane integrity protection turning on result indication is used to indicate that the user plane integrity protection is turned on or not turned on .
  7. 一种通信方法,其特征在于,所述方法包括:A communication method, characterized in that the method comprises:
    第一会话管理实体获取第一用户面安全保护开启指示,所述第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,所述第一会话为第一终端设备用于承载C2通信的会话,所述第一终端设备为所述C2通信的发起端设备,第二终端设备为所述C2通信的对端设备,所述C2通信为所述第一终端设备与所述第二终端设备之间的通信,所述第一会话管理实体是为所述第一终端设备服务的会话管理实体;The first session management entity obtains a first user plane security protection enable instruction, where the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled; wherein the first session is a first terminal The device is used to carry the session of C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the first terminal device Communication with the second terminal device, the first session management entity is a session management entity serving the first terminal device;
    所述第一会话管理实体发送所述第一用户面安全保护开启指示,所述第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,所述第二会话为所述第二终端设备用于承载所述C2通信的会话。The first session management entity sends the first user plane security protection enable instruction, and the first user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is all The second terminal device is used to carry the session of the C2 communication.
  8. 根据权利要求7所述的方法,其特征在于,所述第一会话管理实体发送所述第一用户面安全保护开启指示,包括:The method according to claim 7, wherein the sending, by the first session management entity, the first user plane security protection enabling instruction comprises:
    所述第一会话管理实体向管理设备发送所述第一用户面安全保护开启指示。The first session management entity sends the first user plane security protection opening instruction to the management device.
  9. 根据权利要求7所述的方法,其特征在于,所述第一会话管理实体发送所述第一用户面安全保护开启指示,包括:The method according to claim 7, wherein the sending, by the first session management entity, the first user plane security protection enabling instruction comprises:
    所述第一会话管理实体向第一代理功能实体发送所述第一用户面安全保护开启指示;其中,所述第一代理功能实体用于提供所述第一会话管理实体到所述管理设备的接口。The first session management entity sends the first user plane security protection opening instruction to the first proxy function entity; wherein the first proxy function entity is used to provide the first session management entity to the management device. interface.
  10. 根据权利要求9所述的方法,其特征在于,在所述第一会话管理实体向第一代理功能实体发送所述第一用户面安全保护开启指示之前,所述方法还包括:The method according to claim 9, wherein before the first session management entity sends the first user plane security protection opening instruction to the first proxy function entity, the method further comprises:
    所述第一会话管理实体接收来自所述第一代理功能实体的第四消息,所述第四消息包括所述第一终端设备的标识信息,所述第四消息用于请求所述第一用户面安全保护开启指示。The first session management entity receives a fourth message from the first proxy function entity, where the fourth message includes identification information of the first terminal device, and the fourth message is used to request the first user Face safety protection on instruction.
  11. 根据权利要求7-10任一项所述的方法,其特征在于,所述第一会话管理实体获取第一用户面安全保护开启指示,包括:The method according to any one of claims 7-10, wherein the obtaining, by the first session management entity, the first user plane security protection enabling instruction comprises:
    所述第一会话管理实体从为所述第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;obtaining, by the first session management entity, a first user plane security protection policy from a first unified data management entity serving the first terminal device;
    所述第一会话管理实体向为所述第一终端设备服务的第一接入网设备发送所述第一用户面安全保护策略;sending, by the first session management entity, the first user plane security protection policy to a first access network device serving the first terminal device;
    所述第一会话管理实体接收来自所述第一接入网设备的所述第一用户面安全保护 开启指示,其中,所述第一用户面安全保护开启指示是根据所述第一用户面安全保护策略确定的。The first session management entity receives the first user plane security protection opening instruction from the first access network device, wherein the first user plane security protection enabling instruction is based on the first user plane security The protection strategy is determined.
  12. 根据权利要求7-10任一项所述的方法,其特征在于,所述第一会话管理实体获取第一用户面安全保护开启指示,包括:The method according to any one of claims 7-10, wherein the obtaining, by the first session management entity, the first user plane security protection enabling instruction comprises:
    所述第一会话管理实体从为所述第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;obtaining, by the first session management entity, a first user plane security protection policy from a first unified data management entity serving the first terminal device;
    所述第一会话管理实体向为所述第一终端设备服务的第一接入网设备发送所述第一用户面安全保护策略;sending, by the first session management entity, the first user plane security protection policy to a first access network device serving the first terminal device;
    所述第一会话管理实体接收来自所述第一接入网设备的第七消息,所述第七消息用于指示所述第一接入网设备已经根据所述第一用户面安全保护策略建立所述第一会话;The first session management entity receives a seventh message from the first access network device, where the seventh message is used to indicate that the first access network device has established a security protection policy according to the first user plane the first session;
    响应于所述第七消息,所述第一会话管理实体根据所述第一用户面安全保护策略确定所述第一用户面安全保护开启指示。In response to the seventh message, the first session management entity determines the first user plane security protection opening indication according to the first user plane security protection policy.
  13. 根据权利要求7-12任一项所述的方法,其特征在于,所述第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示;所述第一用户面机密性保护开启结果指示用于指示用户面机密性保护开启或不开启;所述第一用户面完整性保护开启结果指示用于指示用户面完整性保护开启或不开启。The method according to any one of claims 7-12, wherein the first user plane security protection enabling indication comprises a first user plane confidentiality protection enabling result indication and a first user plane integrity protection enabling result indication The first user plane confidentiality protection opening result indication is used to indicate that the user plane confidentiality protection is turned on or not turned on; the first user plane integrity protection turning on result indication is used to indicate that the user plane integrity protection is turned on or not turned on .
  14. 一种通信方法,其特征在于,所述方法包括:A communication method, characterized in that the method comprises:
    第二会话管理实体获取第一用户面安全保护开启指示,所述第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,所述第一会话为第一终端设备用于承载C2通信的会话,所述第一终端设备为所述C2通信的发起端设备,第二终端设备为所述C2通信的对端设备,所述C2通信为所述第一终端设备与所述第二终端设备之间的通信,所述第二会话管理实体是为所述第二终端设备服务的会话管理实体;The second session management entity obtains the first user plane security protection enable instruction, where the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled; wherein the first session is the first terminal The device is used to carry the session of C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the first terminal device communication with the second terminal device, the second session management entity is a session management entity serving the second terminal device;
    所述第二会话管理实体向为所述第二终端设备服务的第二接入网设备发送所述第一用户面安全保护开启指示;其中,所述第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,所述第二会话为所述第二终端设备用于承载所述C2通信的会话。The second session management entity sends the first user plane security protection opening instruction to the second access network device serving the second terminal device; wherein the first user plane security protection opening instruction is used to determine Whether the user plane security protection of the second session is enabled, where the second session is a session used by the second terminal device to carry the C2 communication.
  15. 一种通信方法,其特征在于,所述方法包括:A communication method, characterized in that the method comprises:
    第二会话管理实体获取第一用户面安全保护开启指示,所述第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,所述第一会话为第一终端设备用于承载C2通信的会话,所述第一终端设备为所述C2通信的发起端设备,第二终端设备为所述C2通信的对端设备,所述C2通信为所述第一终端设备与所述第二终端设备之间的通信,所述第二会话管理实体是为所述第二终端设备服务的会话管理实体;The second session management entity obtains the first user plane security protection enable instruction, where the first user plane security protection enable instruction is used to indicate whether the user plane security protection of the first session is enabled; wherein the first session is the first terminal The device is used to carry the session of C2 communication, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the first terminal device communication with the second terminal device, the second session management entity is a session management entity serving the second terminal device;
    所述第二会话管理实体根据所述第一用户面安全保护开启指示确定第三用户面安全保护策略,所述第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护;determining, by the second session management entity, a third user plane security protection policy according to the first user plane security protection enabling instruction, where the third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection;
    所述第二会话管理实体向为所述第二终端设备服务的第二接入网设备发送所述第三用户面安全保护策略;其中,所述第三用户面安全保护策略用于确定第二用户面安全保护开启指示,所述第二用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,所述第二会话为所述第二终端设备用于承载所述C2通信的会话。The second session management entity sends the third user plane security protection policy to the second access network device serving the second terminal device; wherein the third user plane security protection policy is used to determine the second User plane security protection enable instruction, the second user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is used by the second terminal device to carry the C2 communication session.
  16. 根据权利要求15所述的方法,其特征在于,所述第二会话管理实体根据所述第一用户面安全保护开启指示确定第三用户面安全保护策略,包括:The method according to claim 15, wherein the second session management entity determines a third user plane security protection policy according to the first user plane security protection enable instruction, comprising:
    当所述第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示,且所述第一用户面机密性保护开启结果指示用于指示用户面机密性保护开启,所述第一用户面完整性保护开启结果指示用于指示用户面完整性保护开启时,所述第二会话管理实体确定所述第三用户面安全保护策略为用户面机密性保护强制开启且用户面完整性保护强制开启;When the first user plane security protection enabling indication includes a first user plane confidentiality protection enabling result indication and a first user plane integrity protection enabling result indication, and the first user plane confidentiality protection enabling result indication is used to indicate When user plane confidentiality protection is enabled, and the first user plane integrity protection enable result indication is used to indicate that user plane integrity protection is enabled, the second session management entity determines that the third user plane security protection policy is the user plane. Confidentiality protection is forced to be turned on and user plane integrity protection is forced to be turned on;
    或者,当所述第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示,且所述第一用户面机密性保护开启结果指示用于指示用户面机密性保护不开启,所述第一用户面完整性保护开启结果指示用于指示用户面完整性保护不开启时,所述第二会话管理实体确定所述第三用户面安全保护策略为用户面机密性保护强制不开启且用户面完整性保护强制不开启;Or, when the first user plane security protection enable instruction includes the first user plane confidentiality protection enable result instruction and the first user plane integrity protection enable result instruction, and the first user plane confidentiality protection enable result instruction is used. When indicating that the user plane confidentiality protection is not enabled, and the first user plane integrity protection enabling result indication is used to indicate that the user plane integrity protection is not enabled, the second session management entity determines the third user plane security protection. The policy is that the user plane confidentiality protection is forcibly disabled and the user plane integrity protection is forcibly disabled;
    或者,当所述第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示,且所述第一用户面机密性保护开启结果指示用于指示用户面机密性保护不开启,所述第一用户面完整性保护开启结果指示用于指示用户面完整性保护开启时,所述第二会话管理实体确定所述第三用户面安全保护策略为用户面机密性保护强制不开启且用户面完整性保护强制开启;Or, when the first user plane security protection enable instruction includes the first user plane confidentiality protection enable result instruction and the first user plane integrity protection enable result instruction, and the first user plane confidentiality protection enable result instruction is used. When indicating that the user plane confidentiality protection is not turned on, and the first user plane integrity protection turning on result indication is used to indicate that the user plane integrity protection is turned on, the second session management entity determines the third user plane security protection policy It is mandatory to disable user plane confidentiality protection and mandatory enable user plane integrity protection;
    或者,当所述第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示,且所述第一用户面机密性保护开启结果指示用于指示用户面机密性保护开启,所述第一用户面完整性保护开启结果指示用于指示用户面完整性保护不开启时,所述第二会话管理实体确定所述第三用户面安全保护策略为用户面机密性保护强制开启且用户面完整性保护强制不开启。Or, when the first user plane security protection enable instruction includes the first user plane confidentiality protection enable result instruction and the first user plane integrity protection enable result instruction, and the first user plane confidentiality protection enable result instruction is used. When indicating that the user plane confidentiality protection is turned on, and the first user plane integrity protection turning on result indication is used to indicate that the user plane integrity protection is not turned on, the second session management entity determines the third user plane security protection policy It is mandatory to enable user plane confidentiality protection and mandatory to disable user plane integrity protection.
  17. 根据权利要求14-16任一项所述的方法,其特征在于,所述第二会话管理实体获取第一用户面安全保护开启指示,包括:The method according to any one of claims 14-16, wherein the obtaining, by the second session management entity, the first user plane security protection enabling instruction comprises:
    所述第二会话管理实体向为所述第二终端设备服务的第二统一数据管理实体发送第五消息,所述第五消息包括所述第二终端设备的标识信息,所述第五消息用于请求第二用户面安全保护策略;The second session management entity sends a fifth message to the second unified data management entity serving the second terminal device, the fifth message includes the identification information of the second terminal device, and the fifth message uses for requesting the second user plane security protection policy;
    所述第二会话管理实体接收来自所述第二统一数据管理实体的所述第二用户面安全保护策略和所述第一用户面安全保护开启指示。The second session management entity receives the second user plane security protection policy and the first user plane security protection opening instruction from the second unified data management entity.
  18. 根据权利要求14-16任一项所述的方法,其特征在于,所述第二会话管理实体获取第一用户面安全保护开启指示,包括:The method according to any one of claims 14-16, wherein the obtaining, by the second session management entity, the first user plane security protection enabling instruction comprises:
    所述第二会话管理实体向第二代理功能实体发送第六消息,所述第六消息包括所述第二终端设备的标识信息,所述第六消息用于请求所述第一用户面安全保护开启指示,所述第二代理功能实体用于提供所述第二会话管理实体到管理设备的接口;The second session management entity sends a sixth message to the second proxy function entity, where the sixth message includes identification information of the second terminal device, and the sixth message is used to request security protection of the first user plane an opening instruction, the second proxy function entity is used to provide an interface from the second session management entity to a management device;
    所述第二会话管理实体接收来自所述第二代理功能实体的所述第一用户面安全保 护开启指示。The second session management entity receives the first user plane security protection opening instruction from the second proxy function entity.
  19. 根据权利要求18所述的方法,其特征在于,在所述第二会话管理实体向第二代理功能实体发送第六消息之前,所述方法还包括:The method according to claim 18, wherein before the second session management entity sends the sixth message to the second proxy function entity, the method further comprises:
    所述第二会话管理实体接收来自所述第二终端设备的指示信息,所述指示信息指示所述第二终端设备请求建立的所述第二会话用于响应所述第一终端设备发起的所述C2通信。The second session management entity receives indication information from the second terminal device, where the indication information indicates that the second session requested by the second terminal device to be established is used to respond to all requests initiated by the first terminal device. C2 communication described above.
  20. 一种管理设备,其特征在于,所述管理设备包括:处理模块和收发模块;A management device, characterized in that the management device comprises: a processing module and a transceiver module;
    所述处理模块,用于获取第一用户面安全保护开启指示,所述第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,所述第一会话为第一终端设备用于承载C2通信的会话,所述第一终端设备为所述C2通信的发起端设备,第二终端设备为所述C2通信的对端设备,所述C2通信为所述第一终端设备与所述第二终端设备之间的通信;The processing module is configured to obtain a first user plane security protection opening instruction, and the first user plane security protection opening instruction is used to indicate whether the user plane security protection of the first session is enabled; wherein, the first session is the first session. A terminal device is used to carry a C2 communication session, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the first terminal device communication between the terminal device and the second terminal device;
    所述收发模块,用于触发所述第二终端设备发起第二会话的建立,其中,所述第二会话的用户面安全保护是否开启由所述第一用户面安全保护开启指示确定,所述第二会话为所述第二终端设备用于承载所述C2通信的会话。The transceiver module is configured to trigger the second terminal device to initiate the establishment of a second session, wherein whether the user plane security protection of the second session is enabled is determined by the first user plane security protection enable instruction, and the The second session is a session used by the second terminal device to carry the C2 communication.
  21. 根据权利要求20所述的管理设备,其特征在于,所述收发模块,用于触发所述第二终端设备发起第二会话的建立,包括:The management device according to claim 20, wherein the transceiver module is configured to trigger the second terminal device to initiate the establishment of the second session, comprising:
    向所述第二终端设备发送第一消息,所述第一消息用于触发所述第二终端设备发起所述第二会话的建立;以及,向第二统一数据管理实体发送所述第一用户面安全保护开启指示,其中,所述第二统一数据管理实体是为所述第二终端设备服务的统一数据管理实体。sending a first message to the second terminal device, where the first message is used to trigger the second terminal device to initiate the establishment of the second session; and sending the first user to a second unified data management entity A face security protection opening instruction, wherein the second unified data management entity is a unified data management entity serving the second terminal device.
  22. 根据权利要求20所述的管理设备,其特征在于,所述收发模块,用于触发所述第二终端设备发起第二会话的建立,包括:The management device according to claim 20, wherein the transceiver module is configured to trigger the second terminal device to initiate the establishment of the second session, comprising:
    向所述第二终端设备发送第一消息,所述第一消息用于触发所述第二终端设备发起第二会话的建立;以及,接收来自第二代理功能实体的第二消息,并向所述第二代理功能实体发送所述第一用户面安全保护开启指示;其中,所述第二消息包括所述第二终端设备的标识信息,所述第二消息用于请求所述第一用户面安全保护开启指示,所述第二代理功能实体用于提供第二会话管理实体到所述管理设备的接口,所述第二会话管理实体是为所述第二终端设备服务的会话管理实体。Sending a first message to the second terminal device, where the first message is used to trigger the second terminal device to initiate the establishment of a second session; and, receiving the second message from the second proxy function entity, and sending the second message to all The second proxy function entity sends the first user plane security protection opening instruction; wherein, the second message includes the identification information of the second terminal device, and the second message is used to request the first user plane. The security protection opening indication, the second proxy function entity is used to provide an interface from a second session management entity to the management device, where the second session management entity is a session management entity serving the second terminal device.
  23. 根据权利要求20-22任一项所述的管理设备,其特征在于,所述处理模块具体用于:The management device according to any one of claims 20-22, wherein the processing module is specifically configured to:
    通过所述收发模块接收来自第一会话管理实体的所述第一用户面安全保护开启指示,所述第一会话管理实体是为所述第一终端设备服务的会话管理实体;receiving, by the transceiver module, the first user plane security protection opening instruction from a first session management entity, where the first session management entity is a session management entity serving the first terminal device;
    或者,通过所述收发模块接收来自所述第一终端设备的所述第一用户面安全保护开启指示;Or, receiving, by the transceiver module, the first user plane security protection opening instruction from the first terminal device;
    或者,通过所述收发模块接收来自第一代理功能实体的所述第一用户面安全保护开启指示,所述第一代理功能实体用于提供所述第一会话管理实体到所述管理设备的接口。Or, receive, through the transceiver module, the first user plane security protection enabling instruction from a first proxy function entity, where the first proxy function entity is configured to provide an interface from the first session management entity to the management device .
  24. 根据权利要求20-22任一项所述的管理设备,其特征在于,所述处理模块具 体用于:The management device according to any one of claims 20-22, wherein the processing module is specifically configured to:
    确定所述第一终端设备与所述第二终端设备配对授权成功;通过所述收发模块向第一代理功能实体发送第三消息,所述第三消息包括所述第一终端设备的标识信息,所述第三消息用于请求所述第一用户面安全保护开启指示;其中,所述第一代理功能实体用于提供第一会话管理实体到所述管理设备的接口,所述第一会话管理实体是为所述第一终端设备服务的会话管理实体;通过所述收发模块接收来自所述第一代理功能实体的所述第一用户面安全保护开启指示。Determine that the pairing authorization of the first terminal device and the second terminal device is successful; send a third message to the first proxy function entity through the transceiver module, where the third message includes the identification information of the first terminal device, The third message is used to request the first user plane security protection opening instruction; wherein, the first proxy function entity is used to provide an interface from a first session management entity to the management device, and the first session management entity The entity is a session management entity serving the first terminal device; receiving the first user plane security protection opening instruction from the first proxy function entity through the transceiver module.
  25. 根据权利要求20-24任一项所述的管理设备,其特征在于,所述第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示;所述第一用户面机密性保护开启结果指示用于指示用户面机密性保护开启或不开启;所述第一用户面完整性保护开启结果指示用于指示用户面完整性保护开启或不开启。The management device according to any one of claims 20 to 24, wherein the first user plane security protection enabling indication comprises a first user plane confidentiality protection enabling result indication and a first user plane integrity protection enabling result instruction; the first user plane confidentiality protection enable result indication is used to indicate whether the user plane confidentiality protection is enabled or disabled; the first user plane integrity protection enable result indication is used to indicate whether the user plane integrity protection is enabled or disabled on.
  26. 一种第一会话管理实体,其特征在于,所述第一会话管理实体包括:处理模块和收发模块;A first session management entity, characterized in that the first session management entity comprises: a processing module and a transceiver module;
    所述处理模块,用于获取第一用户面安全保护开启指示,所述第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,所述第一会话为第一终端设备用于承载C2通信的会话,所述第一终端设备为所述C2通信的发起端设备,第二终端设备为所述C2通信的对端设备,所述C2通信为所述第一终端设备与所述第二终端设备之间的通信,所述第一会话管理实体是为所述第一终端设备服务的会话管理实体;The processing module is configured to obtain a first user plane security protection opening instruction, and the first user plane security protection enabling instruction is used to indicate whether the user plane security protection of the first session is enabled; wherein, the first session is the first session. A terminal device is used to carry a C2 communication session, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the first terminal device communication between a terminal device and the second terminal device, the first session management entity is a session management entity serving the first terminal device;
    所述收发模块,用于发送所述第一用户面安全保护开启指示,所述第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,所述第二会话为所述第二终端设备用于承载所述C2通信的会话。The transceiver module is configured to send the first user plane security protection opening instruction, and the first user plane security protection opening instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is all The second terminal device is used to carry the C2 communication session.
  27. 根据权利要求26所述的第一会话管理实体,其特征在于,所述收发模块具体用于:The first session management entity according to claim 26, wherein the transceiver module is specifically configured to:
    向管理设备发送所述第一用户面安全保护开启指示。Send the first user plane security protection opening instruction to the management device.
  28. 根据权利要求26所述的第一会话管理实体,其特征在于,所述收发模块具体用于:The first session management entity according to claim 26, wherein the transceiver module is specifically configured to:
    向第一代理功能实体发送所述第一用户面安全保护开启指示;其中,所述第一代理功能实体用于提供所述第一会话管理实体到所述管理设备的接口。Sending the first user plane security protection opening indication to a first proxy function entity; wherein the first proxy function entity is configured to provide an interface from the first session management entity to the management device.
  29. 根据权利要求28所述的第一会话管理实体,其特征在于,The first session management entity according to claim 28, wherein,
    所述收发模块,还用于在所述第一会话管理实体向第一代理功能实体发送所述第一用户面安全保护开启指示之前,接收来自所述第一代理功能实体的第四消息,所述第四消息包括所述第一终端设备的标识信息,所述第四消息用于请求所述第一用户面安全保护开启指示。The transceiver module is further configured to receive a fourth message from the first proxy functional entity before the first session management entity sends the first user plane security protection opening instruction to the first proxy functional entity, where the The fourth message includes identification information of the first terminal device, and the fourth message is used to request the first user plane security protection opening instruction.
  30. 根据权利要求26-29任一项所述的第一会话管理实体,其特征在于,所述处理模块具体用于:The first session management entity according to any one of claims 26-29, wherein the processing module is specifically configured to:
    从为所述第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;通过所述收发模块向为所述第一终端设备服务的第一接入网设备发送所述第一用 户面安全保护策略;通过所述收发模块接收来自所述第一接入网设备的所述第一用户面安全保护开启指示,其中,所述第一用户面安全保护开启指示是根据所述第一用户面安全保护策略确定的。Obtain the first user plane security protection policy from the first unified data management entity serving the first terminal device; send the first user plane security protection policy to the first access network device serving the first terminal device through the transceiver module; a user plane security protection policy; the first user plane security protection enabling instruction from the first access network device is received by the transceiver module, wherein the first user plane security protection enabling instruction is based on the The first user plane security protection policy is determined.
  31. 根据权利要求26-29任一项所述的第一会话管理实体,其特征在于,所述处理模块具体用于:The first session management entity according to any one of claims 26-29, wherein the processing module is specifically configured to:
    从为所述第一终端设备服务的第一统一数据管理实体获取第一用户面安全保护策略;通过所述收发模块向为所述第一终端设备服务的第一接入网设备发送所述第一用户面安全保护策略;通过所述收发模块接收来自所述第一接入网设备的第七消息之后,响应于所述第七消息,根据所述第一用户面安全保护策略确定所述第一用户面安全保护开启指示,其中,所述第七消息用于指示所述第一接入网设备已经根据所述第一用户面安全保护策略建立所述第一会话。Obtain the first user plane security protection policy from the first unified data management entity serving the first terminal device; send the first user plane security protection policy to the first access network device serving the first terminal device through the transceiver module; a user plane security protection policy; after receiving the seventh message from the first access network device through the transceiver module, in response to the seventh message, determine the first user plane security protection policy according to the first user plane security protection policy A user plane security protection enable instruction, wherein the seventh message is used to indicate that the first access network device has established the first session according to the first user plane security protection policy.
  32. 根据权利要求26-31任一项所述的第一会话管理实体,其特征在于,所述第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示;所述第一用户面机密性保护开启结果指示用于指示用户面机密性保护开启或不开启;所述第一用户面完整性保护开启结果指示用于指示用户面完整性保护开启或不开启。The first session management entity according to any one of claims 26 to 31, wherein the first user plane security protection enabling indication comprises a first user plane confidentiality protection enabling result indication and a first user plane integrity protection enable result indication; the first user plane confidentiality protection enable result indication is used to indicate whether user plane confidentiality protection is enabled or not enabled; the first user plane integrity protection enable result indication is used to indicate user plane integrity protection On or off.
  33. 一种第二会话管理实体,其特征在于,所述第二会话管理实体包括:处理模块和收发模块;A second session management entity, characterized in that the second session management entity comprises: a processing module and a transceiver module;
    所述处理模块,用于获取第一用户面安全保护开启指示,所述第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,所述第一会话为第一终端设备用于承载C2通信的会话,所述第一终端设备为所述C2通信的发起端设备,第二终端设备为所述C2通信的对端设备,所述C2通信为所述第一终端设备与所述第二终端设备之间的通信,所述第二会话管理实体是为所述第二终端设备服务的会话管理实体;The processing module is configured to obtain a first user plane security protection opening instruction, and the first user plane security protection opening instruction is used to indicate whether the user plane security protection of the first session is enabled; wherein, the first session is the first session. A terminal device is used to carry a C2 communication session, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the first terminal device communication between a terminal device and the second terminal device, where the second session management entity is a session management entity serving the second terminal device;
    所述收发模块,用于向为所述第二终端设备服务的第二接入网设备发送所述第一用户面安全保护开启指示;其中,所述第一用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,所述第二会话为所述第二终端设备用于承载所述C2通信的会话。The transceiver module is configured to send the first user plane security protection opening instruction to a second access network device serving the second terminal device; wherein the first user plane security protection opening instruction is used to determine Whether the user plane security protection of the second session is enabled, where the second session is a session used by the second terminal device to carry the C2 communication.
  34. 一种第二会话管理实体,其特征在于,所述第二会话管理实体包括:处理模块和收发模块;A second session management entity, characterized in that the second session management entity comprises: a processing module and a transceiver module;
    所述处理模块,用于获取第一用户面安全保护开启指示,所述第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;其中,所述第一会话为第一终端设备用于承载C2通信的会话,所述第一终端设备为所述C2通信的发起端设备,第二终端设备为所述C2通信的对端设备,所述C2通信为所述第一终端设备与所述第二终端设备之间的通信,所述第二会话管理实体是为所述第二终端设备服务的会话管理实体;The processing module is configured to obtain a first user plane security protection opening instruction, and the first user plane security protection opening instruction is used to indicate whether the user plane security protection of the first session is enabled; wherein, the first session is the first session. A terminal device is used to carry a C2 communication session, the first terminal device is the initiating end device of the C2 communication, the second terminal device is the opposite end device of the C2 communication, and the C2 communication is the first terminal device communication between a terminal device and the second terminal device, where the second session management entity is a session management entity serving the second terminal device;
    所述处理模块,还用于根据所述第一用户面安全保护开启指示确定第三用户面安全保护策略,所述第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护;The processing module is further configured to determine a third user plane security protection policy according to the first user plane security protection opening instruction, where the third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection;
    所述收发模块,用于向为所述第二终端设备服务的第二接入网设备发送所述第三用户面安全保护策略;其中,所述第三用户面安全保护策略用于确定第二用户面安全保护开启指示,所述第二用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,所述第二会话为所述第二终端设备用于承载所述C2通信的会话。The transceiver module is configured to send the third user plane security protection policy to the second access network device serving the second terminal device; wherein the third user plane security protection policy is used to determine the second User plane security protection enable instruction, the second user plane security protection enable instruction is used to determine whether the user plane security protection of the second session is enabled, and the second session is used by the second terminal device to carry the C2 communication session.
  35. 根据权利要求34所述的第二会话管理实体,其特征在于,所述处理模块,用于根据所述第一用户面安全保护开启指示确定第三用户面安全保护策略,包括:The second session management entity according to claim 34, wherein the processing module, configured to determine a third user plane security protection policy according to the first user plane security protection enable instruction, comprises:
    当所述第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示,且所述第一用户面机密性保护开启结果指示用于指示用户面机密性保护开启,所述第一用户面完整性保护开启结果指示用于指示用户面完整性保护开启时,确定所述第三用户面安全保护策略为用户面机密性保护强制开启且用户面完整性保护强制开启;When the first user plane security protection enabling indication includes a first user plane confidentiality protection enabling result indication and a first user plane integrity protection enabling result indication, and the first user plane confidentiality protection enabling result indication is used to indicate The user plane confidentiality protection is turned on, and the first user plane integrity protection turning on result indication is used to indicate that when the user plane integrity protection is turned on, it is determined that the third user plane security protection policy is that the user plane confidentiality protection is forcibly turned on and the user Face integrity protection is forced to be turned on;
    或者,当所述第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示,且所述第一用户面机密性保护开启结果指示用于指示用户面机密性保护不开启,所述第一用户面完整性保护开启结果指示用于指示用户面完整性保护不开启时,确定所述第三用户面安全保护策略为用户面机密性保护强制不开启且用户面完整性保护强制不开启;Or, when the first user plane security protection enable instruction includes the first user plane confidentiality protection enable result instruction and the first user plane integrity protection enable result instruction, and the first user plane confidentiality protection enable result instruction is used. When indicating that the user plane confidentiality protection is not turned on, and the first user plane integrity protection turning on result indication is used to indicate that the user plane integrity protection is not turned on, it is determined that the third user plane security protection policy is user plane confidentiality protection Mandatory not to open and user plane integrity protection mandatory to not open;
    或者,当所述第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示,且所述第一用户面机密性保护开启结果指示用于指示用户面机密性保护不开启,所述第一用户面完整性保护开启结果指示用于指示用户面完整性保护开启时,确定所述第三用户面安全保护策略为用户面机密性保护强制不开启且用户面完整性保护强制开启;Or, when the first user plane security protection enable instruction includes the first user plane confidentiality protection enable result instruction and the first user plane integrity protection enable result instruction, and the first user plane confidentiality protection enable result instruction is used. When indicating that the user plane confidentiality protection is not turned on, and the first user plane integrity protection turning on result indication is used to indicate that the user plane integrity protection is turned on, it is determined that the third user plane security protection policy is user plane confidentiality protection mandatory It is not turned on and the user plane integrity protection is forced to be turned on;
    或者,当所述第一用户面安全保护开启指示包括第一用户面机密性保护开启结果指示和第一用户面完整性保护开启结果指示,且所述第一用户面机密性保护开启结果指示用于指示用户面机密性保护开启,所述第一用户面完整性保护开启结果指示用于指示用户面完整性保护不开启时,确定所述第三用户面安全保护策略为用户面机密性保护强制开启且用户面完整性保护强制不开启。Or, when the first user plane security protection enable instruction includes the first user plane confidentiality protection enable result instruction and the first user plane integrity protection enable result instruction, and the first user plane confidentiality protection enable result instruction is used. When indicating that the user plane confidentiality protection is turned on, and the first user plane integrity protection turning on result indication is used to indicate that the user plane integrity protection is not turned on, it is determined that the third user plane security protection policy is user plane confidentiality protection mandatory It is enabled and the user plane integrity protection is forcibly disabled.
  36. 根据权利要求33-35任一项所述的第二会话管理实体,其特征在于,所述处理模块,用于获取第一用户面安全保护开启指示,包括:The second session management entity according to any one of claims 33 to 35, wherein the processing module, configured to obtain the first user plane security protection opening instruction, includes:
    通过所述收发模块向为所述第二终端设备服务的第二统一数据管理实体发送第五消息,所述第五消息包括所述第二终端设备的标识信息,所述第五消息用于请求第二用户面安全保护策略;通过所述收发模块接收来自所述第二统一数据管理实体的所述第二用户面安全保护策略和所述第一用户面安全保护开启指示。A fifth message is sent to the second unified data management entity serving the second terminal device through the transceiver module, where the fifth message includes identification information of the second terminal device, and the fifth message is used to request The second user plane security protection policy; the second user plane security protection policy and the first user plane security protection enabling instruction from the second unified data management entity are received by the transceiver module.
  37. 根据权利要求33-35任一项所述的第二会话管理实体,其特征在于,所述处理模块,用于获取第一用户面安全保护开启指示,包括:The second session management entity according to any one of claims 33 to 35, wherein the processing module, configured to obtain the first user plane security protection opening instruction, includes:
    通过所述收发模块向第二代理功能实体发送第六消息,所述第六消息包括所述第二终端设备的标识信息,所述第六消息用于请求所述第一用户面安全保护开启指示,所述第二代理功能实体用于提供所述第二会话管理实体到管理设备的接口;通过所述收发模块接收来自所述第二代理功能实体的所述第一用户面安全保护开启指示。A sixth message is sent to the second proxy function entity through the transceiver module, where the sixth message includes the identification information of the second terminal device, and the sixth message is used to request the first user plane security protection opening instruction , the second proxy function entity is configured to provide an interface from the second session management entity to a management device; and receive the first user plane security protection opening instruction from the second proxy function entity through the transceiver module.
  38. 根据权利要求37所述的第二会话管理实体,其特征在于,The second session management entity according to claim 37, wherein,
    所述收发模块,还用于在向第二代理功能实体发送第六消息之前,接收来自所述第二终端设备的指示信息,所述指示信息指示所述第二终端设备请求建立的所述第二会话用于响应所述第一终端设备发起的所述C2通信。The transceiver module is further configured to receive indication information from the second terminal device before sending the sixth message to the second proxy function entity, where the indication information indicates that the second terminal device requests the establishment of the first message. The second session is used to respond to the C2 communication initiated by the first terminal device.
  39. 一种通信装置,其特征在于,包括:A communication device, comprising:
    存储器以及与所述存储器耦合的处理器,所述存储器用于存储程序,所述处理器用于执行所述存储器存储的所述程序;当所述通信装置运行时,所述处理器运行所述程序,使得所述通信装置执行上述权利要求1-6或7-13或14-19中任一项所述的方法。a memory and a processor coupled to the memory, the memory for storing a program, the processor for executing the program stored in the memory; the processor executes the program when the communication device operates , so that the communication device performs the method of any one of the above claims 1-6 or 7-13 or 14-19.
  40. 根据权利要求39所述的通信装置,其特征在于,所述通信装置为芯片或芯片系统。The communication device according to claim 39, wherein the communication device is a chip or a chip system.
  41. 一种计算机可读存储介质,其特征在于,其上存储有计算机程序,当所述计算机程序被计算机执行时使得所述计算机执行权利要求1-6或7-13或14-19中任一项所述的方法。A computer-readable storage medium, characterized in that a computer program is stored thereon, and when the computer program is executed by a computer, the computer is made to execute any one of claims 1-6 or 7-13 or 14-19 the method described.
  42. 一种计算机程序产品,其特征在于,包括:指令,当所述计算机程序产品在计算机上运行时,使得计算机执行权利要求1-6或7-13或14-19中任一项所述的方法。A computer program product, characterized by comprising: instructions, when the computer program product runs on a computer, causing the computer to execute the method of any one of claims 1-6 or 7-13 or 14-19 .
  43. 一种通信系统,其特征在于,所述通信系统包括管理设备和为第二终端设备服务的第二会话管理实体,所述第二终端设备为C2通信的对端设备,所述C2通信为第一终端设备与所述第二终端设备之间的通信,所述第一终端设备为所述C2通信的发起端设备;A communication system, characterized in that the communication system includes a management device and a second session management entity serving a second terminal device, the second terminal device is a peer device of C2 communication, and the C2 communication is a second session management entity. Communication between a terminal device and the second terminal device, where the first terminal device is the initiating end device of the C2 communication;
    所述管理设备,用于获取第一用户面安全保护开启指示,所述第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;所述第一会话为所述第一终端设备用于承载所述C2通信的会话;The management device is configured to obtain a first user plane security protection opening instruction, and the first user plane security protection enabling instruction is used to indicate whether the user plane security protection of the first session is enabled; the first session is the first session. A terminal device is used to carry the C2 communication session;
    所述管理设备,还用于触发所述第二终端设备发起第二会话的建立,所述第二会话为所述第二终端设备用于承载所述C2通信的会话;The management device is further configured to trigger the second terminal device to initiate establishment of a second session, where the second session is a session used by the second terminal device to carry the C2 communication;
    所述第二会话管理实体,用于接收所述管理设备获取的所述第一用户面安全保护开启指示,并向为所述第二终端设备服务的第二接入网设备发送所述第一用户面安全保护开启指示;其中,所述第一用户面安全保护开启指示用于确定所述第二会话的用户面安全保护是否开启。The second session management entity is configured to receive the first user plane security protection opening indication obtained by the management device, and send the first access network device serving the second terminal device to the second access network device. A user plane security protection opening instruction; wherein the first user plane security protection enabling instruction is used to determine whether the user plane security protection of the second session is enabled.
  44. 一种通信系统,其特征在于,所述通信系统包括管理设备和为第二终端设备服务的第二会话管理实体,所述第二终端设备为C2通信的对端设备,所述C2通信为第一终端设备与所述第二终端设备之间的通信,所述第一终端设备为所述C2通信的发起端设备;A communication system, characterized in that the communication system includes a management device and a second session management entity serving a second terminal device, the second terminal device is a peer device of C2 communication, and the C2 communication is a second session management entity. Communication between a terminal device and the second terminal device, where the first terminal device is the initiating end device of the C2 communication;
    所述管理设备,用于获取第一用户面安全保护开启指示,所述第一用户面安全保护开启指示用于指示第一会话的用户面安全保护是否开启;所述第一会话为所述第一终端设备用于承载所述C2通信的会话;The management device is configured to obtain a first user plane security protection opening instruction, and the first user plane security protection enabling instruction is used to indicate whether the user plane security protection of the first session is enabled; the first session is the first session. A terminal device is used to carry the C2 communication session;
    所述管理设备,还用于触发所述第二终端设备发起第二会话的建立,所述第二会话为所述第二终端设备用于承载所述C2通信的会话;The management device is further configured to trigger the second terminal device to initiate establishment of a second session, where the second session is a session used by the second terminal device to carry the C2 communication;
    所述第二会话管理实体,用于接收所述管理设备获取的所述第一用户面安全保护开启指示,并根据所述第一用户面安全保护开启指示确定第三用户面安全保护策略之后,向为所述第二终端设备服务的第二接入网设备发送所述第三用户面安全保护策略; 其中,所述第三用户面安全保护策略仅包括强制开启安全保护或强制不开启安全保护;所述第三用户面安全保护策略用于确定第二用户面安全保护开启指示,所述第二用户面安全保护开启指示用于确定第二会话的用户面安全保护是否开启,所述第二会话为所述第二终端设备用于承载所述C2通信的会话。The second session management entity is configured to receive the first user plane security protection enable instruction obtained by the management device, and after determining a third user plane security protection policy according to the first user plane security protection enable instruction, sending the third user plane security protection policy to the second access network device serving the second terminal device; wherein the third user plane security protection policy only includes forcibly enabling security protection or forcibly not enabling security protection ; The third user plane security protection policy is used to determine the second user plane security protection opening instruction, and the second user plane security protection opening instruction is used to determine whether the user plane security protection of the second session is enabled, and the second user plane security protection opening instruction is used to determine whether the second session is enabled. The session is a session used by the second terminal device to carry the C2 communication.
  45. 根据权利要求43或44所述的通信系统,其特征在于,所述通信系统还包括为所述第一终端设备服务的第一会话管理实体;The communication system according to claim 43 or 44, wherein the communication system further comprises a first session management entity serving the first terminal device;
    所述第一会话管理实体,用于向所述管理设备发送所述第一用户面安全保护开启指示;the first session management entity, configured to send the first user plane security protection opening indication to the management device;
    所述管理设备,用于获取第一用户面安全保护开启指示,包括:用于接收来自所述第一会话管理实体的所述第一用户面安全保护开启指示。The management device, configured to obtain the first user plane security protection opening instruction, includes: receiving the first user plane security protection opening instruction from the first session management entity.
  46. 根据权利要求43或44所述的通信系统,其特征在于,所述通信系统还包括所述第一终端设备;The communication system according to claim 43 or 44, wherein the communication system further comprises the first terminal device;
    所述第一终端设备,用于向所述管理设备发送所述第一用户面安全保护开启指示;the first terminal device, configured to send the first user plane security protection opening instruction to the management device;
    所述管理设备,用于获取第一用户面安全保护开启指示,包括:用于接收来自所述第一终端设备的所述第一用户面安全保护开启指示。The management device, configured to obtain the first user plane security protection opening instruction, includes: receiving the first user plane security protection opening instruction from the first terminal device.
PCT/CN2020/129914 2020-11-18 2020-11-18 Communication method, apparatus and system WO2022104617A1 (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN202080107200.0A CN116671235A (en) 2020-11-18 2020-11-18 Communication method, device and system
PCT/CN2020/129914 WO2022104617A1 (en) 2020-11-18 2020-11-18 Communication method, apparatus and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2020/129914 WO2022104617A1 (en) 2020-11-18 2020-11-18 Communication method, apparatus and system

Publications (1)

Publication Number Publication Date
WO2022104617A1 true WO2022104617A1 (en) 2022-05-27

Family

ID=81708149

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/129914 WO2022104617A1 (en) 2020-11-18 2020-11-18 Communication method, apparatus and system

Country Status (2)

Country Link
CN (1) CN116671235A (en)
WO (1) WO2022104617A1 (en)

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20190104015A (en) * 2019-08-16 2019-09-05 엘지전자 주식회사 A method for photographing an unmanned aerial robot and a device for supporting the same in an unmanned aerial vehicle system
CN111867142A (en) * 2019-04-29 2020-10-30 华为技术有限公司 Method, equipment and system for establishing communication bearer

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111867142A (en) * 2019-04-29 2020-10-30 华为技术有限公司 Method, equipment and system for establishing communication bearer
KR20190104015A (en) * 2019-08-16 2019-09-05 엘지전자 주식회사 A method for photographing an unmanned aerial robot and a device for supporting the same in an unmanned aerial vehicle system

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
"3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of Unmanned Aerial Systems (UAS) (Release 17)", 3GPP STANDARD; TECHNICAL REPORT; 3GPP TR 33.854, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, no. V0.3.0, 20 November 2020 (2020-11-20), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , pages 1 - 40, XP051961656 *
SAMSUNG: "Updates to KI#6", 3GPP DRAFT; S3-202610, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG3, no. e-meeting; 20201012 - 20201016, 2 October 2020 (2020-10-02), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051937911 *

Also Published As

Publication number Publication date
CN116671235A (en) 2023-08-29

Similar Documents

Publication Publication Date Title
US20220116814A1 (en) Meeting strict qos requirements through network control of device route and location
US11812496B2 (en) User group session management method and apparatus
KR20200139771A (en) Methods of managing access to local area data network (LADN) in 5G network
JP2021518075A (en) Service subscription method and equipment
JP2021524209A (en) Session management methods, equipment, and systems
JP2023510191A (en) Edge service configuration
US20230397145A1 (en) Mobility in Non-Public Networks
WO2019076275A1 (en) Communication method and device
WO2020220820A1 (en) Method for establishing communication bearer, device and system
WO2020199991A1 (en) Communication method, device and system
KR20210024160A (en) Communication method and device
EP3952213B1 (en) Communication method, apparatus, and system
WO2019024744A1 (en) Method and device for acquiring identifier of terminal device
WO2021227871A1 (en) Method for handling unmanned aerial vehicle having abnormal behavior, network element, system, and storage medium
US20230328821A1 (en) Modifying PDU Sessions In Underlay Networks
WO2020001319A1 (en) Dynamic networking method, device and system
WO2020192622A1 (en) Terminal management and control method, apparatus and system
EP4243463A2 (en) Charging method and device
WO2022104617A1 (en) Communication method, apparatus and system
WO2022155853A1 (en) Wireless communication method, communication apparatus and communication system
WO2021254116A1 (en) Communication method and apparatus
WO2018191867A1 (en) Synchronization method, apparatus, and system for terminal monitoring information
EP4099758A1 (en) Communication method and device
WO2021218244A1 (en) Communication method, apparatus and system
WO2023246427A1 (en) Ranging method and communication device

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20961908

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 202080107200.0

Country of ref document: CN

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 20961908

Country of ref document: EP

Kind code of ref document: A1