WO2023004656A1 - 一种直连通信方法、装置、用户设备及存储介质 - Google Patents

一种直连通信方法、装置、用户设备及存储介质 Download PDF

Info

Publication number
WO2023004656A1
WO2023004656A1 PCT/CN2021/109087 CN2021109087W WO2023004656A1 WO 2023004656 A1 WO2023004656 A1 WO 2023004656A1 CN 2021109087 W CN2021109087 W CN 2021109087W WO 2023004656 A1 WO2023004656 A1 WO 2023004656A1
Authority
WO
WIPO (PCT)
Prior art keywords
prose
security policy
initiating
signaling
strategy
Prior art date
Application number
PCT/CN2021/109087
Other languages
English (en)
French (fr)
Inventor
洪伟
Original Assignee
北京小米移动软件有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 北京小米移动软件有限公司 filed Critical 北京小米移动软件有限公司
Priority to CN202180002265.3A priority Critical patent/CN115885533A/zh
Priority to EP21951268.8A priority patent/EP4380294A1/en
Priority to PCT/CN2021/109087 priority patent/WO2023004656A1/zh
Publication of WO2023004656A1 publication Critical patent/WO2023004656A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • H04W76/14Direct-mode setup

Definitions

  • the present disclosure relates to the field of communication technologies, and in particular, to a direct connection communication method, device, user equipment, and storage medium.
  • Prose Proximity based Service, proximity communication service
  • UEs User Equipment, user equipment
  • the direct connection communication method, device, user equipment and storage medium proposed in the present disclosure are used to ensure the security of direct connection communication between UEs in the Prose service.
  • the direct connection communication method proposed by an embodiment of the present disclosure is applied to receive ProSe UE, including:
  • the direct connection communication method proposed by another embodiment of the present disclosure is applied to initiate ProSe UE, including:
  • the direct connection communication device proposed by the embodiment includes:
  • An acquisition module configured to acquire a security policy corresponding to the ProSe service
  • the communication module is used to establish direct communication security with the initiating ProSe UE based on the security policy.
  • the direct connection communication device proposed by the embodiment includes:
  • An acquisition module configured to acquire a security policy corresponding to the ProSe service
  • the communication module is used to establish direct communication security with the receiving ProSe UE based on the security policy.
  • a user equipment provided by an embodiment of another aspect of the present disclosure includes: a transceiver; a memory; and a processor, which are respectively connected to the transceiver and the memory, and configured to execute computer-executable instructions on the memory, The wireless signal transmission and reception of the transceiver is controlled, and the method provided in the embodiment of the above yet another aspect can be realized.
  • the computer storage medium provided by the embodiment, wherein the computer storage medium stores computer-executable instructions; after the computer-executable instructions are executed by a processor, the method as described above can be implemented.
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and based on the obtained security policy and the initiating ProSe UE Establish direct communication security. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 1 is a schematic flowchart of a direct communication method provided by an embodiment of the present disclosure
  • FIG. 2 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 3 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 4 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 5 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 6 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 7 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 8 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 9 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 10 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 11 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 12 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 13 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 14 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 15 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 16 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 17 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 18 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 19 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • FIG. 20 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure.
  • Fig. 21 is a schematic structural diagram of a direct communication device provided by an embodiment of the present disclosure.
  • Fig. 22 is a schematic structural diagram of a direct communication device provided by another embodiment of the present disclosure.
  • Fig. 23 is a block diagram of a user equipment provided by an embodiment of the present disclosure.
  • first, second, third, etc. may use the terms first, second, third, etc. to describe various information, the information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of the embodiments of the present disclosure, first information may also be called second information, and similarly, second information may also be called first information.
  • first information may also be called second information
  • second information may also be called first information.
  • the words "if” and "if” as used herein may be interpreted as “at” or "when” or "in response to a determination.”
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct connection communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 1 is a schematic flow diagram of a direct communication method provided by an embodiment of the present disclosure, which is applied to receive a ProSe UE. As shown in FIG. 1, the direct communication method may include the following steps:
  • Step 101 acquire the security policy corresponding to the ProSe service.
  • a UE may be a device that provides voice and/or data connectivity to a user.
  • UE can communicate with one or more core networks via RAN (Radio Access Network, wireless access network).
  • RAN Radio Access Network, wireless access network
  • UE can be an Internet of Things terminal, such as a sensor device, a mobile phone (or called a "cellular" phone) and a device with an Internet of Things
  • the computer of the terminal for example, may be a fixed, portable, pocket, hand-held, computer-built-in or vehicle-mounted device.
  • station Station, STA
  • subscriber unit subscriber unit
  • subscriber station subscriber station
  • mobile station mobile station
  • mobile station mobile
  • remote station remote station
  • access point remote terminal
  • user terminal or user agent.
  • the UE may also be a device of an unmanned aerial vehicle.
  • the UE may also be a vehicle-mounted device, for example, it may be a trip computer with a wireless communication function, or a wireless terminal connected externally to the trip computer.
  • the UE may also be a roadside device, for example, it may be a street lamp, a signal lamp, or other roadside devices with a wireless communication function.
  • a security policy corresponding to a ProSe service can be configured for each ProSe UE in advance, so that the ProSe UE can perform security protection on the PC5 interface of the ProSe UE based on the security policy.
  • the security policy corresponding to the ProSe service may specifically include the ProSe service to be protected and the security policy corresponding to the ProSe service to be protected.
  • the security policy may specifically include at least one of the following:
  • the security policy may be any one of the above-mentioned policies. In another embodiment of the present disclosure, the security policy may be any combination of the above policies.
  • the above-mentioned signaling integrity protection policy and signaling encryption protection policy belong to the signaling security policy; the above-mentioned UP integrity protection policy and UP encryption protection policy belong to the UP security strategy.
  • the security policy may include: REQUIRED (protection required); NOT NEEDED (protection not required); PREFERRED (optional protection).
  • the signaling integrity protection policy may include: REQUIRED; or, NOT NEEDED; or, PREFERRED.
  • the signaling encryption protection policy may include: REQUIRED; or, NOT NEEDED; or, PREFERRED.
  • the UP integrity protection policy may include: REQUIRED; or, NOT NEEDED; or, PREFERRED.
  • the UP encryption protection policy may include: REQUIRED; or, NOT NEEDED; or, PREFERRED.
  • REQUIRED may indicate that the ProSe UE needs security protection.
  • the security policy corresponding to the ProSe UE when the security policy corresponding to the ProSe UE is REQUIRED, the ProSe UE can only establish a secure connection with the ProSe UE whose security policy is also REQUIRED.
  • the security policy corresponding to the ProSe UE when the security policy corresponding to the ProSe UE is REQUIRED, the ProSe UE can only establish a connection with the ProSe UE using the non-NULL confidentiality algorithm or integrity algorithm.
  • NOT NEEDED can indicate that the ProSe UE does not need security protection, and, in one embodiment of the present disclosure, when the security policy corresponding to the ProSe UE is NOT NEEDED, the ProSe UE can only The ProSe UE with the same security policy as NOT NEEDED establishes a connection without security.
  • PREFERRED indicates that the ProSe UE may perform security protection, or may not perform security protection. And, in an embodiment of the present disclosure, when the security policy corresponding to the ProSe UE is PREFERRED, the ProSe UE can establish a secure connection with the ProSe UE whose security policy is REQUIRED, or with the ProSe UE whose security policy is NOT NEEDED ProSe UE establishes a connection without security.
  • the method for the ProSe UE to obtain the security policy corresponding to the ProSe service may include: obtaining the ProSe service and the protected ProSe service sent by the PCF (Policy Control Function, policy control function) The security policy corresponding to the ProSe service.
  • PCF Policy Control Function, policy control function
  • the method for the ProSe UE to obtain the security policy corresponding to the ProSe service may include: obtaining the ProSe service to be protected and the security policy corresponding to the ProSe service to be protected sent by the ProSe application server .
  • the ProSe application server may send the security policy corresponding to the ProSe service to the ProSe UE through the PCF.
  • the ProSe application server may send the security policy corresponding to the ProSe service to the ProSe UE through the PC1 interface.
  • the method for the ProSe UE to obtain the security policy corresponding to the ProSe service may include: obtaining the ProSe service configured on the UICC (Universal Integrated Circuit Card, embedded universal integrated circuit card) to be protected and Security policy corresponding to the ProSe service to be protected.
  • UICC Universal Integrated Circuit Card, embedded universal integrated circuit card
  • the security policy when the ProSe UE obtains the security policy corresponding to the ProSe service, the security policy can be protected through NAS (Non Access Stratum, non-access) signaling security.
  • NAS Non Access Stratum, non-access
  • the NAS security may be established after the ProSe UE registers the ProSe service.
  • Step 102 establish direct communication with the initiating ProSe UE based on the security policy.
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 2 is a schematic flowchart of a direct communication method provided by another embodiment of the present disclosure, which is applied to receive ProSeUE. As shown in FIG. 2, the direct communication method may include the following steps:
  • Step 201 acquire the security policy corresponding to the ProSe service.
  • step 201 for the detailed introduction of step 201, reference may be made to the relevant introduction in the foregoing embodiments, and the embodiments of the present disclosure will not repeat them here.
  • Step 202 obtain the Direct Communication Request (direct communication request) message sent by the initiating ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 203 determine whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition.
  • the first preset condition may include at least one of the following:
  • the strategy for initiating the signaling integrity protection of the ProSe UE is NOT NEEDED, and the strategy for receiving the signaling integrity protection of the ProSe UE is REQUIRED;
  • the strategy for initiating ProSe UE's signaling encryption protection is NOT NEEDED, and the strategy for receiving ProSe UE's signaling encryption protection is REQUIRED;
  • the strategy for initiating the signaling integrity protection of the ProSe UE is REQUIRED, and the strategy for receiving the signaling integrity protection of the ProSe UE is NOT NEEDED;
  • the signaling encryption protection policy of the initiating ProSe UE is REQUIRED, and the signaling encryption protection policy of the receiving ProSe UE is NOT NEEDED.
  • the first preset condition may be any one of the above preset conditions. In another embodiment of the present disclosure, the first preset condition may be any combination of the above preset conditions.
  • the first preset condition includes the above two or more preset conditions, if the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet Any one of the preset conditions in the first preset condition, it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition, otherwise it is determined that the signaling security policy of the ProSe UE is initiated and the signaling security policy of the receiving ProSe UE does not meet the first preset condition.
  • the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition it means that there is an existence between the initiating ProSe UE and the receiving ProSe UE. If the security policy conflicts, the two are not eligible for direct connection, go to step 204.
  • Step 204 Send a first rejection message to the initiating ProSe UE, where the first rejection message is used to reject the Direct Communication Request message sent by the initiating ProSe UE.
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • Fig. 3 is a schematic flowchart of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to receiving ProSeUE. As shown in Fig. 3, the direct connection communication method may include the following steps:
  • Step 301 acquire the security policy corresponding to the ProSe service.
  • Step 302 obtain the Direct Communication Request message sent by the initiating ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 303 determine whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition.
  • the process continues to step 304 .
  • Step 304 Determine the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE.
  • the negotiation result of the signaling security policy may include at least one of the following:
  • the negotiation result of the signaling security policy is determined, including:
  • the negotiation result of the signaling integrity protection strategy is determined to be NOT NEEDED . That is, when there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when there is a ProSe UE signaling integrity protection strategy of NOT NEEDED between the initiating ProSe UE and the receiving ProSe UE, The negotiation result of determining the signaling integrity protection policy is NOT NEEDED.
  • the negotiation result of the signaling integrity protection strategy is determined to be REQUIRED. That is, when there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when there is a ProSe UE whose signaling integrity protection strategy is REQUIRED between the initiating ProSe UE and the receiving ProSe UE, determine The negotiation result of the signaling integrity protection policy is REQUIRED.
  • the negotiation result of the signaling integrity protection strategy is determined to be REQUIRED or NOT NEEDED.
  • the negotiation result of the signaling encryption protection strategy is determined to be NOT NEEDED. That is, when there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when there is a ProSe UE whose signaling encryption protection policy is NOT NEEDED between the initiating ProSe UE and the receiving ProSe UE, determine The negotiation result of the signaling encryption protection policy is NOT NEEDED.
  • the negotiation result of the signaling encryption protection strategy is determined to be REQUIRED, that is, after receiving When there is no security policy conflict between the ProSe UE and the initiating ProSe UE, when there is a ProSe UE whose signaling encryption protection policy is REQUIRED between the initiating ProSe UE and the receiving ProSe UE, determine the policy of the signaling encryption protection
  • the negotiation result is REQUIRED.
  • the negotiation result of the signaling encryption protection strategy is determined to be REQUIRED or NOT NEEDED.
  • Step 305 Send a Direct Security Mode Command (direct security mode command) message to the initiating ProSe UE, wherein the Direct Security Mode Command message includes the negotiation result of the signaling security policy.
  • Direct Security Mode Command direct security mode command
  • the negotiation result of the signaling security policy included in the Direct Security Mode Command message may be the negotiation result determined in step 304 above.
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • Fig. 4 is a schematic flow diagram of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to receive a ProSe UE.
  • the direct connection communication method may include the following steps:
  • Step 401 acquire the security policy corresponding to the ProSe service.
  • Step 402 Obtain the Direct Communication Request message sent by the initiating ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 403 determine whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition.
  • step 404 if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the first preset condition, it means that the communication between the initiating ProSe UE and the receiving ProSe UE If there is no security policy conflict, the two are eligible for direct connection, and step 404 is performed.
  • Step 404 Determine the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE.
  • Step 405 Send a Direct Security Mode Command (direct security mode command) message to the initiating ProSe UE, wherein the Direct Security Mode Command message includes the negotiation result of the signaling security policy.
  • Direct Security Mode Command direct security mode command
  • Step 406 Receive the second rejection message sent by the initiating ProSe UE, where the second rejection message is used to refuse to receive the Direct Security Mode Command message sent by the ProSe UE.
  • the initiating ProSe UE when the initiating ProSe UE receives the Direct Security Mode Command message sent by the receiving ProSe UE, it will determine the security algorithm corresponding to the negotiation result of the signaling security policy included in the Direct Security Mode Command message Whether the security algorithm corresponding to the signaling security policy of the UE that initiates the ProSe is consistent.
  • the initiating ProSe UE when the initiating ProSe UE judges that the security algorithm corresponding to the negotiation result of the signaling security policy included in the Direct Security Mode Command message is inconsistent with the security algorithm corresponding to its own signaling security policy, It means that the receiving ProSe UE and the sending ProSe UE do not have the protection direct connection qualification, then the initiating ProSe UE sends a second rejection message to the receiving ProSe UE to refuse to receive the Direct Security Mode Command message sent by the ProSe UE.
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • Fig. 5 is a schematic flow diagram of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to receive a ProSe UE. As shown in Fig. 5, the direct connection communication method may include the following steps:
  • Step 501 acquire the security policy corresponding to the ProSe service.
  • Step 502 Obtain the Direct Communication Request message sent by the initiating ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 503 determine whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition.
  • step 504 if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the first preset condition, it means that the communication between the initiating ProSe UE and the receiving ProSe UE If there is no security policy conflict, the two are eligible for direct connection, and step 504 is performed.
  • Step 504 Determine the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE.
  • Step 505 Send a Direct Security Mode Command message to the initiating ProSe UE, wherein the Direct Security Mode Command message includes the negotiation result of the signaling security policy.
  • Step 506 judging whether the negotiation result of the signaling security policy is NOT NEEDED.
  • Step 507 Change the UP security policy of the receiving ProSe UE to NOT NEEDED.
  • the negotiation result of the signaling encryption protection strategy is NOT NEEDED, it means that the signaling between the initiating ProSe UE and the receiving ProSe UE does not need security protection and the negotiated encryption algorithm is NULL algorithm, at this time, the UP encryption protection policy of the receiving ProSe UE can also be changed to NOT NEEDED.
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 6 is a schematic flow diagram of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to receive a ProSe UE. As shown in FIG. 6, the direct connection communication method may include the following steps:
  • Step 601 acquire the security policy corresponding to the ProSe service.
  • Step 602 Obtain the Direct Communication Request message sent by the initiating ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 603 determine whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition.
  • step 604 if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the first preset condition, it means that the communication between the initiating ProSe UE and the receiving ProSe UE If there is no security policy conflict, the two are eligible for direct connection, and step 604 is performed.
  • Step 604 Determine the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE.
  • Step 605 Send a Direct Security Mode Command message to the initiating ProSe UE, wherein the Direct Security Mode Command message includes the negotiation result of the signaling security policy.
  • step 605 the signaling security policy negotiation between the receiving ProSe UE and the initiating ProSe UE is completed, and then the subsequent steps can be continued to negotiate between the receiving ProSe UE and the initiating ProSe UE.
  • UP security policy the signaling security policy negotiation between the receiving ProSe UE and the initiating ProSe UE is completed, and then the subsequent steps can be continued to negotiate between the receiving ProSe UE and the initiating ProSe UE.
  • the negotiation result of the signaling security policy determined in step 604 is REQUIRED, it is considered that signaling security is established between the receiving ProSe UE and the initiating ProSe UE. protection, then in the subsequent process, when the receiving ProSe UE interacts with the initiating ProSe UE, the exchanged messages will be protected by signaling security, ensuring the security of signaling transmission.
  • Step 606 Receive the Direct Security Mode Complete message sent by the initiating ProSe UE, wherein the Direct Security Mode Complete message includes the UP security policy of the initiating ProSe UE.
  • Step 607 Determine whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition.
  • the second preset condition may include at least one of the following:
  • the strategy for initiating UP integrity protection of ProSe UE is NOT NEEDED, and the strategy for receiving UP integrity protection of ProSe UE is REQUIRED;
  • the strategy of initiating UP encryption protection of ProSe UE is NOT NEEDED, and the strategy of receiving UP encryption protection of ProSe UE is REQUIRED;
  • the strategy for initiating the UP integrity protection of the ProSe UE is REQUIRED, and the strategy for receiving the UP integrity protection of the ProSe UE is NOT NEEDED;
  • the strategy for initiating UP encryption protection of ProSe UE is REQUIRED, and the strategy for receiving UP encryption protection of ProSe UE is NOT NEEDED.
  • the second preset condition may be only any one of the above preset conditions. In another embodiment of the present disclosure, the second preset condition may be any combination of the above preset conditions.
  • the second preset condition includes the above two or more preset conditions, if the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE satisfy the second For any one of the preset conditions, it is determined that the UP security policy for initiating the ProSe UE and the UP security policy for receiving the ProSe UE meet the second preset condition, otherwise it is determined to determine the UP security policy for initiating the ProSe UE and receiving the ProSe UE The UP security policy does not meet the second preset condition.
  • the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition it means that there is security between the initiating ProSe UE and the receiving ProSe UE. Policy conflict, the two are not eligible for direct connection, go to step 608.
  • the receiving ProSe UE before determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition in step 607, the receiving ProSe UE will first Judging whether the negotiation result of the signaling security policy determined in the above step 605 is NOT NEEDED, when it is NOT NEEDED, the UP security policy of the receiving ProSe UE will also be changed to NOT NEEDED.
  • Step 608 Send a third rejection message to the initiating ProSe UE, where the third rejection message is used to reject the Direct Security Mode Complete message sent by the initiating ProSe UE.
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 7 is a schematic flowchart of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to receive ProSe UE. As shown in FIG. 7, the direct connection communication method may include the following steps:
  • Step 701 acquire the security policy corresponding to the ProSe service.
  • Step 702 Obtain the Direct Communication Request message sent by the initiating ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 703 determine whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition.
  • the process proceeds to step 704.
  • Step 704 Determine the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE.
  • Step 705 Send a Direct Security Mode Command message to the initiating ProSe UE, where the Direct Security Mode Command message includes the negotiation result of the signaling security policy.
  • Step 706 Receive the Direct Security Mode Complete message sent by the initiating ProSe UE, wherein the Direct Security Mode Complete message includes the UP security policy of the initiating ProSe UE.
  • Step 707 Determine whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition.
  • the process continues to step 708.
  • the receiving ProSe UE before determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition in step 707, the receiving ProSe UE will first Judging whether the negotiation result of the signaling security policy determined in the above step 705 is NOT NEEDED, when it is NOT NEEDED, the UP security policy of the receiving ProSe UE will also be changed to NOT NEEDED.
  • Step 708 Determine the negotiation result of the UP security policy based on the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE.
  • the negotiation result of the UP security policy may include at least one of the following:
  • the negotiation result of the UP security policy is determined based on the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE, including:
  • the negotiation result of the UP integrity protection policy is determined to be NOT NEEDED. That is, when there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when there is a ProSe UE whose UP integrity protection policy is NOT NEEDED between the initiating ProSe UE and the receiving ProSe UE, determine The negotiation result of the UP integrity protection policy is NOT NEEDED.
  • the UP integrity protection strategy of the initiating ProSe UE is REQUIRED, and/or, the UP integrity protection strategy of the receiving ProSe UE is REQUIRED, determine the negotiation result of the UP integrity protection strategy as REQUIRED. That is, when there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when there is a ProSe UE whose UP integrity protection policy is REQUIRED between the initiating ProSe UE and the receiving ProSe UE, determine the UP The negotiation result of the integrity protection policy is REQUIRED.
  • the UP integrity protection policy of the initiating ProSe UE is PREFERRED
  • the UP integrity protection policy of the receiving ProSe UE is PREFERRED
  • the UP encryption protection strategy of the initiating ProSe UE is NOT NEEDED, and/or, the UP encryption protection strategy of the receiving ProSe UE is NOT NEEDED, determine the negotiation result of the UP encryption protection strategy as NOT NEEDED. That is, when there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when there is a ProSe UE whose UP encryption protection policy is NOT NEEDED between the initiating ProSe UE and the receiving ProSe UE, determine the UP The negotiation result of encryption protection policy is NOT NEEDED.
  • the negotiation result of the UP encryption protection strategy is determined to be REQUIRED. That is, when there is no security policy conflict between the receiving ProSe UE and the initiating ProSe UE, when there is a ProSe UE whose UP encryption protection policy is REQUIRED between the initiating ProSe UE and the receiving ProSe UE, determine the UP encryption The negotiation result of the protected policy is REQUIRED.
  • the negotiation result of the UP encryption protection policy is REQUIRED or NOT NEEDED.
  • Step 709 Send a Direct Communication Accept message to the initiating ProSe UE, wherein the Direct Communication Accept message includes the negotiation result of the UP security policy.
  • the negotiation result of the UP security policy included in the Direct Communication Accept message may be the negotiation result determined in step 708 above.
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 8 is a schematic flowchart of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to receive ProSe UE. As shown in FIG. 8, the direct connection communication method may include the following steps:
  • Step 801 acquire the security policy corresponding to the ProSe service.
  • Step 802 obtain the Direct Communication Request message sent by the initiating ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 803 determine whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition.
  • step 804 if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the first preset condition, it means that the communication between the initiating ProSe UE and the receiving ProSe UE If there is no security policy conflict, the two are eligible for direct connection, and step 804 is performed.
  • Step 804 Determine the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE.
  • Step 805 Send a Direct Security Mode Command message to the initiating ProSe UE, wherein the Direct Security Mode Command message includes the negotiation result of the signaling security policy.
  • Step 806 Receive the Direct Security Mode Complete message sent by the initiating ProSe UE, wherein the Direct Security Mode Complete message includes the UP security policy of the initiating ProSe UE.
  • Step 807 determine whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition.
  • the process continues to step 808.
  • the receiving ProSe UE before determining whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition in step 807, the receiving ProSe UE will first Judging whether the negotiation result of the signaling security policy determined in the above step 804 is NOT NEEDED, when it is NOT NEEDED, the UP security policy of the receiving ProSe UE will also be changed to NOT NEEDED.
  • Step 808 Determine the negotiation result of the UP security policy based on the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE.
  • Step 809 Send a Direct Communication Accept message to the initiating ProSe UE, wherein the Direct Communication Accept message includes the negotiation result of the UP security policy.
  • Step 810 Perform direct communication with the initiating ProSe UE based on the negotiation result of the signaling security policy and the negotiation result of the UP security policy.
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 9 is a schematic flowchart of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to initiate a ProSe UE. As shown in FIG. 9, the direct connection communication method may include the following steps:
  • Step 901 acquire the security policy corresponding to the ProSe service.
  • Step 902 establish direct communication with the receiving ProSe UE based on the security policy.
  • the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 10 is a schematic flowchart of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to initiate a ProSe UE. As shown in FIG. 10 , the direct connection communication method may include the following steps:
  • Step 1001 acquire the security policy corresponding to the ProSe service.
  • step 1001 for a detailed introduction of step 1001, reference may be made to relevant introductions in the foregoing embodiments, and details are not described in this embodiment of the present disclosure.
  • Step 1002 Send a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 1003 Obtain and receive the first rejection message sent by the ProSe UE, where the first rejection message is used to reject the initiation of the Direct Communication Request message sent by the ProSe UE.
  • the receiving ProSe UE after the receiving ProSe UE obtains the Direct Communication Request message sent by the initiating ProSe UE, it will determine whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE satisfy the first preset conditions. And, in one embodiment of the present disclosure, if it is determined that the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE meet the first preset condition, it means that there is an existence between the initiating ProSe UE and the receiving ProSe UE. The security policy conflicts, and the two are not eligible for direct connection. The receiving ProSe UE will send the first rejection message to the initiating ProSe UE.
  • the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 11 is a schematic flowchart of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to initiate a ProSe UE. As shown in FIG. 11 , the direct connection communication method may include the following steps:
  • Step 1101 acquire the security policy corresponding to the ProSe service.
  • Step 1102 Send a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 1103 obtain and receive the Direct Security Mode Command message sent by the ProSe UE, and the Direct Security Mode Command includes the negotiation result of the signaling security policy.
  • the receiving ProSe UE after the receiving ProSe UE obtains the Direct Communication Request message sent by the initiating ProSe UE, it will determine whether the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE satisfy the first preset conditions.
  • the receiving ProSe UE will determine the negotiation result of the signaling security policy based on the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE. Afterwards, a Direct Security Mode Command message will be sent to the initiating ProSe UE, wherein the Direct Security Mode Command message includes the negotiation result of the signaling security policy.
  • the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 12 is a schematic flow diagram of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to initiate a ProSe UE. As shown in FIG. 12 , the direct connection communication method may include the following steps:
  • Step 1201 acquire the security policy corresponding to the ProSe service.
  • Step 1202 Send a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 1203 obtain and receive the Direct Security Mode Command message sent by the ProSe UE, and the Direct Security Mode Command includes the negotiation result of the signaling security policy.
  • Step 1204 judging whether the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE.
  • each signaling security policy has a corresponding security algorithm.
  • the security algorithm corresponding to the signaling security policy of the receiving ProSe UE may be consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE.
  • the security algorithm corresponding to the signaling security policy of the receiving ProSe UE may be inconsistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE.
  • the initiating ProSe UE judges that the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is inconsistent with the security algorithm corresponding to its own signaling security policy, it means that the receiving ProSe UE and The sending ProSe UEs are not eligible for protected direct connection, so continue to execute step 1205.
  • Step 1205 Send a second rejection message to the receiving ProSe UE, where the second rejection message is used to refuse to receive the Direct Security Mode Command message sent by the ProSe UE.
  • the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • Fig. 13 is a schematic flow diagram of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to initiate a ProSe UE. As shown in Fig. 13, the direct connection communication method may include the following steps:
  • Step 1301 acquire the security policy corresponding to the ProSe service.
  • Step 1302 Send a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 1303 obtain and receive the Direct Security Mode Command message sent by the ProSe UE, and the Direct Security Mode Command includes the negotiation result of the signaling security policy.
  • Step 1304 judging whether the negotiation result of the signaling security policy is NOT NEEDED.
  • Step 1305 change the UP security policy of the sending ProSe UE to NOT NEEDED.
  • the negotiation result of the signaling encryption protection policy is NOT NEEDED, it means that the signaling between the initiating ProSe UE and the receiving ProSe UE does not require security protection and the negotiated encryption algorithm is the NULL algorithm, at this time, the strategy for initiating the UP encryption protection of the ProSe UE can also be changed to NOT NEEDED.
  • the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 14 is a schematic flowchart of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to initiate a ProSe UE. As shown in FIG. 14 , the direct connection communication method may include the following steps:
  • Step 1401 acquire the security policy corresponding to the ProSe service.
  • Step 1402 Send a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 1403 obtain and receive the Direct Security Mode Command message sent by the ProSe UE, and the Direct Security Mode Command includes the negotiation result of the signaling security policy.
  • Step 1404 judging whether the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE.
  • the initiating ProSe UE judges that the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to its own signaling security policy, it means that the receiving ProSe UE is the same as the sending The ProSe UEs are eligible for protection direct connection, and proceed to step 1405.
  • Step 1405 Send a Direct Security Mode Complete message to the receiving ProSe UE, wherein the Direct Security Mode Complete message includes the UP security policy of the initiating ProSe UE.
  • the initiating ProSe UE before sending the Direct Security Mode Complete message to the receiving ProSe UE in step 1405, the initiating ProSe UE will first judge the signaling security policy received in the above step 1403 Whether the negotiation result is NOT NEEDED, if it is NOT NEEDED, the UP security policy of the initiating ProSe UE will also be changed to NOT NEEDED. And, later, when sending the Direct Security Mode Complete message to the receiving ProSe UE, the Direct Security Mode Complete message specifically includes the changed UP security policy of the initiating ProSe UE.
  • Step 1406 acquire and receive the third rejection message sent by the ProSe UE, the third rejection message is used to reject the Direct Security Mode Complete message sent by the initiating ProSe UE.
  • the receiving ProSe UE After the receiving ProSe UE acquires the Direct Security Mode Complete message sent by the initiating ProSe UE, it will determine whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second predetermined requirement. set conditions.
  • the receiving ProSe UE if it is determined that the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition, it means that there is a security policy between the initiating ProSe UE and the receiving ProSe UE conflict, the two are not eligible for direct connection, and the receiving ProSe UE will send a third rejection message to the initiating ProSe UE.
  • the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 15 is a schematic flowchart of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to initiate a ProSe UE. As shown in FIG. 15 , the direct connection communication method may include the following steps:
  • Step 1501 acquire the security policy corresponding to the ProSe service.
  • Step 1502 Send a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 1503 obtain and receive the Direct Security Mode Command message sent by the ProSe UE, and the Direct Security Mode Command includes the negotiation result of the signaling security policy.
  • Step 1504 judging whether the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE.
  • the initiating ProSe UE judges that the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to its own signaling security policy, it means that the receiving ProSe UE is the same as the sending The ProSe UEs are eligible for protected direct connection, and proceed to step 1505.
  • Step 1505 Send a Direct Security Mode Complete message to the receiving ProSe UE, and the Direct Security Mode Complete message includes the UP security policy of the initiating ProSe UE.
  • the initiating ProSe UE before sending the Direct Security Mode Complete message to the receiving ProSe UE in step 1405, the initiating ProSe UE will first judge the signaling security policy received in the above step 1403 Whether the negotiation result is NOT NEEDED, if it is NOT NEEDED, the UP security policy of the initiating ProSe UE will also be changed to NOT NEEDED. And, later, when sending the Direct Security Mode Complete message to the receiving ProSe UE, the Direct Security Mode Complete message specifically includes the changed UP security policy of the initiating ProSe UE.
  • Step 1506 obtain and receive the Direct Communication Accept message sent by the ProSe UE, the Direct Communication Accept message includes the negotiation result of the UP security policy.
  • the receiving ProSe UE after the receiving ProSe UE obtains the Direct Security Mode Complete message sent by the initiating ProSe UE, it will determine whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE satisfy the second predetermined condition. set conditions.
  • the receiving ProSe UE will determine the negotiation result of the UP security policy based on the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE. After that, send a Direct Communication Accept message to the initiating ProSe UE, wherein the Direct Communication Accept message includes the negotiation result of the UP security policy.
  • the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 16 is a schematic flowchart of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to initiate a ProSe UE. As shown in FIG. 16 , the direct connection communication method may include the following steps:
  • Step 1601 acquire the security policy corresponding to the ProSe service.
  • Step 1602 Send a Direct Communication Request message to the receiving ProSe UE, wherein the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE.
  • Step 1603 obtain and receive the Direct Security Mode Command message sent by the ProSe UE, and the Direct Security Mode Command includes the negotiation result of the signaling security policy.
  • Step 1604 judging whether the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to the signaling security policy of the initiating ProSe UE.
  • the initiating ProSe UE judges that the security algorithm corresponding to the signaling security policy of the receiving ProSe UE is consistent with the security algorithm corresponding to its own signaling security policy, it means that the receiving ProSe UE is the same as the sending The ProSe UEs are eligible for protected direct connection, and proceed to step 1605.
  • Step 1605 Send a Direct Security Mode Complete message to the receiving ProSe UE, and the Direct Security Mode Complete message includes the UP security policy of the initiating ProSe UE.
  • the initiating ProSe UE before sending the Direct Security Mode Complete message to the receiving ProSe UE in step 1605, the initiating ProSe UE will first judge the signaling security policy received in the above step 1603 Whether the negotiation result is NOT NEEDED, if it is NOT NEEDED, the UP security policy of the initiating ProSe UE will also be changed to NOT NEEDED. And, later, when sending the Direct Security Mode Complete message to the receiving ProSe UE, the Direct Security Mode Complete message specifically includes the changed UP security policy of the initiating ProSe UE.
  • Step 1606 obtain and receive the Direct Communication Accept message sent by the ProSe UE, and the Direct Communication Accept message includes the negotiation result of the UP security policy.
  • Step 1607 Perform direct communication with the ProSe UE based on the negotiation result of the signaling security policy and the negotiation result of the UP security policy.
  • the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 17 is a schematic flowchart of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to receive ProSe UE. As shown in FIG. 17, the direct connection communication method may include the following steps:
  • Step 1701 acquire the security policy corresponding to the ProSe service.
  • Step 1702 Receive the Direct Security Mode Complete message sent by the initiating ProSe UE, wherein the Direct Security Mode Complete message includes the UP security policy of the initiating ProSe UE.
  • Step 1703 determine whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition, and if the second preset condition is met, perform step 1704.
  • the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition it means that there is a security policy between the initiating ProSe UE and the receiving ProSe UE Conflict, the two are not qualified to protect the direct connection, go to step 1704.
  • Step 1704 Send a third rejection message to the initiating ProSe UE, where the third rejection message is used to reject the Direct Security Mode Complete message sent by the initiating ProSe UE.
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 18 is a schematic flowchart of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to receive ProSe UE. As shown in FIG. 18, the direct connection communication method may include the following steps:
  • Step 1801 acquire the security policy corresponding to the ProSe service.
  • Step 1802 Receive the Direct Security Mode Complete message sent by the initiating ProSe UE, wherein the Direct Security Mode Complete message includes the UP security policy of the initiating ProSe UE.
  • Step 1803 determine whether the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE meet the second preset condition, and if the second preset condition is not met, then perform step 1804.
  • the signaling security policy of the initiating ProSe UE and the signaling security policy of the receiving ProSe UE do not meet the second preset condition, it means that the communication between the initiating ProSe UE and the receiving ProSe UE If there is no security policy conflict, the two are qualified to protect the direct connection, and proceed to step 1804.
  • Step 1804 determine the negotiation result of the UP security policy based on the UP security policy of the initiating ProSe UE and the UP security policy of the receiving ProSe UE.
  • Step 1805 Send a Direct Communication Accept message to the initiating ProSe UE, wherein the Direct Communication Accept message includes the negotiation result of the UP security policy.
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 19 is a schematic flowchart of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to initiate a ProSe UE. As shown in FIG. 19, the direct connection communication method may include the following steps:
  • Step 1901 acquire the security policy corresponding to the ProSe service.
  • Step 1902 Send a Direct Security Mode Complete message to the receiving ProSe UE, wherein the Direct Security Mode Complete message includes the UP security policy of the initiating ProSe UE.
  • Step 1903 acquire and receive the third rejection message sent by the ProSe UE, the third rejection message is used to reject the Direct Security Mode Complete message sent by the initiating ProSe UE.
  • the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 20 is a schematic flowchart of a direct connection communication method provided by another embodiment of the present disclosure, which is applied to initiate a ProSe UE. As shown in FIG. 20 , the direct connection communication method may include the following steps:
  • Step 2001 acquire the security policy corresponding to the ProSe service.
  • Step 2002 Send a Direct Security Mode Complete message to the receiving ProSe UE, wherein the Direct Security Mode Complete message includes the UP security policy of the ProSe UE that initiated it.
  • Step 2003 obtain and receive the Direct Communication Accept message sent by the ProSe UE, and the Direct Communication Accept message includes the negotiation result of the UP security policy.
  • the initiating ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the receiving ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • FIG. 21 is a schematic structural diagram of a direct-connect communication device provided by an embodiment of the present disclosure. As shown in FIG. 21 , the device 2100 may include:
  • An acquisition module 2101 configured to acquire a security policy corresponding to the ProSe service
  • the communication module 2102 is configured to establish direct connection communication security with the initiating ProSe UE based on the security policy.
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • the security policy includes at least one of the following:
  • the security policy includes at least one of the following:
  • the security policy includes: REQUIRED; NOT NEEDED; PREFERRED.
  • the acquisition module is also used to:
  • the acquisition module is also used to:
  • the acquisition module is also used to:
  • the above-mentioned communication module 2102 is also used for:
  • the Direct Communication Request message sent by the initiating ProSe UE, and the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE;
  • the first preset condition includes at least one of the following:
  • the strategy for initiating the signaling integrity protection of the ProSe UE is NOT NEEDED, and the strategy for receiving the signaling integrity protection of the ProSe UE is REQUIRED;
  • the strategy for initiating ProSe UE's signaling encryption protection is NOT NEEDED, and the strategy for receiving ProSe UE's signaling encryption protection is REQUIRED;
  • the strategy for initiating the signaling integrity protection of the ProSe UE is REQUIRED, and the strategy for receiving the signaling integrity protection of the ProSe UE is NOT NEEDED;
  • the strategy for initiating ProSe UE's signaling encryption protection is REQUIRED, and the strategy for receiving ProSe UE's signaling encryption protection is NOT NEEDED;
  • a first rejection message is sent to the initiating ProSe UE, where the first rejection message is used to reject the Direct Communication Request message sent by the initiating ProSe UE.
  • the above-mentioned communication module 2102 is also used for:
  • the Direct Communication Request message sent by the initiating ProSe UE, and the Direct Communication Request message includes the signaling security policy of the initiating ProSe UE;
  • the first preset condition includes at least one of the following:
  • the strategy for initiating the signaling integrity protection of the ProSe UE is NOT NEEDED, and the strategy for receiving the signaling integrity protection of the ProSe UE is REQUIRED;
  • the strategy for initiating ProSe UE's signaling encryption protection is NOT NEEDED, and the strategy for receiving ProSe UE's signaling encryption protection is REQUIRED;
  • the strategy for initiating the signaling integrity protection of the ProSe UE is REQUIRED, and the strategy for receiving the signaling integrity protection of the ProSe UE is NOT NEEDED;
  • the strategy for initiating ProSe UE's signaling encryption protection is REQUIRED, and the strategy for receiving ProSe UE's signaling encryption protection is NOT NEEDED;
  • Direct Security Mode Command message Send a direct security mode command Direct Security Mode Command message to the initiating ProSe UE, and the Direct Security Mode Command message includes the negotiation result of the signaling security policy.
  • the negotiation result of the signaling security policy includes at least one of the following:
  • the communication module 2102 is also used for:
  • the signaling integrity protection strategy of the initiating ProSe UE is NOT NEEDED, and/or, the signaling integrity protection strategy of the receiving ProSe UE is NOT NEEDED, determine the negotiation result of the signaling integrity protection strategy as NOT NEEDED;
  • the signaling integrity protection strategy of the initiating ProSe UE is REQUIRED, and/or, the signaling integrity protection strategy of the receiving ProSe UE is REQUIRED, determine the negotiation result of the signaling integrity protection strategy as REQUIRED;
  • the signaling integrity protection strategy of the initiating ProSe UE is PREFERRED, and the signaling integrity protection strategy of the receiving ProSe UE is PREFERRED, determine the negotiation result of the signaling integrity protection strategy as REQUIRED or NOT NEEDED;
  • the signaling encryption protection strategy of the initiating ProSe UE is NOT NEEDED, and/or, the signaling encryption protection strategy of the receiving ProSe UE is NOT NEEDED, and the negotiation result of the signaling encryption protection strategy is determined to be NOT NEEDED;
  • the signaling encryption protection strategy of the initiating ProSe UE is REQUIRED, and/or, the signaling encryption protection strategy of the receiving ProSe UE is REQUIRED, and the negotiation result of the signaling encryption protection strategy is determined to be REQUIRED;
  • the signaling encryption protection strategy of the initiating ProSe UE is PREFERRED
  • the signaling encryption protection strategy of the receiving ProSe UE is PREFERRED
  • the above-mentioned device is also used for:
  • the above-mentioned device is also used for:
  • the above-mentioned device is also used for:
  • the second preset condition includes at least one of the following:
  • the strategy for initiating UP integrity protection of ProSe UE is NOT NEEDED, and the strategy for receiving UP integrity protection of ProSe UE is REQUIRED;
  • the strategy of initiating UP encryption protection of ProSe UE is NOT NEEDED, and the strategy of receiving UP encryption protection of ProSe UE is REQUIRED;
  • the strategy for initiating the UP integrity protection of the ProSe UE is REQUIRED, and the strategy for receiving the UP integrity protection of the ProSe UE is NOT NEEDED;
  • the strategy for initiating UP encryption protection of ProSe UE is REQUIRED, and the strategy for receiving UP encryption protection of ProSe UE is NOT NEEDED;
  • a third rejection message is sent to the initiating ProSe UE, where the third rejection message is used to reject the Direct Security Mode Complete message sent by the initiating ProSe UE.
  • the above-mentioned device is also used for:
  • the second preset condition includes at least one of the following:
  • the strategy for initiating UP integrity protection of ProSe UE is NOT NEEDED, and the strategy for receiving UP integrity protection of ProSe UE is REQUIRED;
  • the strategy of initiating UP encryption protection of ProSe UE is NOT NEEDED, and the strategy of receiving UP encryption protection of ProSe UE is REQUIRED;
  • the strategy for initiating the UP integrity protection of the ProSe UE is REQUIRED, and the strategy for receiving the UP integrity protection of the ProSe UE is NOT NEEDED;
  • the strategy for initiating UP encryption protection of ProSe UE is REQUIRED, and the strategy for receiving UP encryption protection of ProSe UE is NOT NEEDED;
  • the Direct Communication Accept message includes the negotiation result of the UP security policy.
  • the negotiation result of the UP security policy includes at least one of the following: the negotiation result of the UP integrity protection policy; the negotiation result of the UP encryption protection policy.
  • the above-mentioned device is also used for:
  • the UP integrity protection policy of the initiating ProSe UE is NOT NEEDED, and/or, the UP integrity protection policy of the receiving ProSe UE is NOT NEEDED, determine the negotiation result of the UP integrity protection policy as NOT NEEDED;
  • the negotiation result of the UP integrity protection strategy is determined to be REQUIRED;
  • the negotiation result of the UP integrity protection policy as REQUIRED or NOT NEEDED If the UP integrity protection policy of the initiating ProSe UE is PREFERRED, and the UP integrity protection policy of the receiving ProSe UE is PREFERRED, determine the negotiation result of the UP integrity protection policy as REQUIRED or NOT NEEDED;
  • the UP encryption protection policy of the ProSe UE is initiated as NOT NEEDED, and/or, the UP encryption protection policy of the receiving ProSe UE is NOT NEEDED, and the negotiation result of the UP encryption protection policy is determined to be NOT NEEDED;
  • the strategy for initiating the UP encryption protection of the ProSe UE is REQUIRED, and/or, the strategy for receiving the UP encryption protection of the ProSe UE is REQUIRED, determine that the negotiation result of the UP encryption protection strategy is REQUIRED;
  • the negotiation result of the UP encryption protection policy is REQUIRED or NOT NEEDED.
  • the above-mentioned device is also used for:
  • Fig. 22 is a schematic structural diagram of a direct connection communication provided by another embodiment of the present disclosure. As shown in Fig. 22, the device 2200 may include:
  • An acquisition module 2201 configured to acquire a security policy corresponding to the ProSe service
  • the communication module 2202 is configured to establish direct communication security with the receiving ProSe UE based on the security policy.
  • the receiving ProSe UE can obtain the security policy corresponding to the ProSe service, and establish direct communication security with the initiating ProSe UE based on the obtained security policy. Therefore, in the embodiment of the present disclosure, the security policy corresponding to the ProSe service can be configured for the UE, so that the receiving ProSe UE and the initiating ProSe UE can establish direct communication security based on the security policy. Therefore, the security of direct communication between UEs in the ProSe service is ensured, and the security of information transmission is improved.
  • the security policy includes at least one of the following:
  • the security policy includes at least one of the following:
  • the security policy includes: REQUIRED; NOT NEEDED; PREFERRED.
  • the acquisition module is also used to:
  • the acquisition module is also used to:
  • the acquisition module is also used to:
  • the above-mentioned communication module 2202 is also used for:
  • the Direct Communication Request message includes the signaling security policy of the ProSe UE that initiated it;
  • the ProSe UE Acquire and receive the first rejection message sent by the ProSe UE, where the first rejection message is used to reject the Direct Communication Request message sent by the ProSe UE.
  • the above-mentioned communication module 2202 is also used for:
  • the Direct Communication Request message includes the signaling security policy of the ProSe UE that initiated it;
  • the Direct Security Mode Command includes the negotiation result of the signaling security policy.
  • the above-mentioned communication module 2202 is also used for:
  • the negotiation result of the signaling security policy includes at least one of the following:
  • the above-mentioned device is also used for:
  • the above-mentioned device is also used for:
  • the Direct Security Mode Complete message includes the UP security policy of the ProSe UE that initiated it;
  • the above-mentioned device is also used for:
  • the Direct Security Mode Complete message includes the UP security policy of the ProSe UE that initiated it;
  • the Direct Communication Accept message includes the negotiation result of the UP security policy.
  • the above-mentioned device is also used for:
  • the computer storage medium provided by the embodiments of the present disclosure stores an executable program; after the executable program is executed by the processor, it can realize to any of the methods shown in Figure 20.
  • the present disclosure also proposes a computer program product, including a computer program.
  • a computer program product including a computer program.
  • the computer program When the computer program is executed by a processor, the computer program as shown in FIGS. 1 to 8, 17 to 18 or 9 to 16, The method shown in any one of Fig. 19 to Fig. 20.
  • the present disclosure also proposes a computer program.
  • the program When the program is executed by a processor, the computer program shown in FIG. 1 to FIG. 8 , FIG. 20 any one of the methods shown.
  • Fig. 19 is a block diagram of a user equipment UE1900 provided by an embodiment of the present disclosure.
  • the UE 1900 may be a mobile phone, a computer, a digital broadcasting terminal device, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, and the like.
  • UE2300 may include at least one of the following components: a processing component 2302, a memory 2304, a power supply component 2306, a multimedia component 2308, an audio component 2310, an input/output (I/O) interface 2312, a sensor component 2313, and a communication component 2316.
  • a processing component 2302 may include at least one of the following components: a processing component 2302, a memory 2304, a power supply component 2306, a multimedia component 2308, an audio component 2310, an input/output (I/O) interface 2312, a sensor component 2313, and a communication component 2316.
  • a processing component 2302 may include at least one of the following components: a processing component 2302, a memory 2304, a power supply component 2306, a multimedia component 2308, an audio component 2310, an input/output (I/O) interface 2312, a sensor component 2313, and a communication component 2316.
  • I/O input/output
  • the processing component 2302 generally controls the overall operations of the UE 2300, such as those associated with display, phone calls, data communications, camera operations, and recording operations.
  • the processing component 2302 may include at least one processor 2320 to execute instructions to complete all or part of the steps of the above-mentioned method.
  • processing component 2302 can include at least one module to facilitate interaction between processing component 2302 and other components.
  • processing component 2302 may include a multimedia module to facilitate interaction between multimedia component 2308 and processing component 2302 .
  • the memory 2304 is configured to store various types of data to support operations at the UE 2300 . Examples of such data include instructions for any application or method operating on the UE2300, contact data, phonebook data, messages, pictures, videos, etc.
  • the memory 2304 can be realized by any type of volatile or non-volatile storage device or their combination, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable Programmable Read Only Memory (EPROM), Programmable Read Only Memory (PROM), Read Only Memory (ROM), Magnetic Memory, Flash Memory, Magnetic or Optical Disk.
  • SRAM static random access memory
  • EEPROM electrically erasable programmable read-only memory
  • EPROM erasable Programmable Read Only Memory
  • PROM Programmable Read Only Memory
  • ROM Read Only Memory
  • Magnetic Memory Flash Memory
  • Magnetic or Optical Disk Magnetic Disk
  • the power supply component 2306 provides power to various components of the UE 2300.
  • Power component 2306 may include a power management system, at least one power supply, and other components associated with generating, managing, and distributing power for UE 2300 .
  • the multimedia component 2308 includes a screen providing an output interface between the UE 2300 and the user.
  • the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from a user.
  • the touch panel includes at least one touch sensor to sense touch, slide, and gestures on the touch panel. The touch sensor may not only sense a boundary of a touch or slide action, but also detect a wake-up time and pressure related to the touch or slide operation.
  • the multimedia component 2308 includes a front camera and/or a rear camera. When UE2300 is in operation mode, such as shooting mode or video mode, the front camera and/or rear camera can receive external multimedia data. Each front camera and rear camera can be a fixed optical lens system or have focal length and optical zoom capability.
  • the audio component 2310 is configured to output and/or input audio signals.
  • the audio component 2310 includes a microphone (MIC), which is configured to receive an external audio signal when the UE 2300 is in an operation mode, such as a call mode, a recording mode, and a voice recognition mode. Received audio signals may be further stored in memory 2304 or sent via communication component 2316 .
  • the audio component 2310 also includes a speaker for outputting audio signals.
  • the I/O interface 2312 provides an interface between the processing component 2302 and a peripheral interface module, which may be a keyboard, a click wheel, a button, and the like. These buttons may include, but are not limited to: a home button, volume buttons, start button, and lock button.
  • the sensor component 2313 includes at least one sensor, which is used to provide various aspects of state assessment for the UE 2300 .
  • the sensor component 2313 can detect the open/close state of the device 2300, the relative positioning of components, such as the display and the keypad of the UE2300, the sensor component 2313 can also detect the position change of the UE2300 or a component of the UE2300, and the user and Presence or absence of UE2300 contact, UE2300 orientation or acceleration/deceleration and temperature change of UE2300.
  • the sensor assembly 2313 may include a proximity sensor configured to detect the presence of nearby objects in the absence of any physical contact.
  • the sensor assembly 2313 may also include an optical sensor, such as a CMOS or CCD image sensor, for use in imaging applications.
  • the sensor component 2313 may also include an acceleration sensor, a gyro sensor, a magnetic sensor, a pressure sensor or a temperature sensor.
  • Communication component 2316 is configured to facilitate wired or wireless communications between UE 2300 and other devices.
  • UE2300 can access wireless networks based on communication standards, such as WiFi, 2G or 3G, or their combination.
  • the communication component 2316 receives broadcast signals or broadcast related information from an external broadcast management system via a broadcast channel.
  • the communication component 2316 also includes a near field communication (NFC) module to facilitate short-range communication.
  • NFC near field communication
  • the NFC module may be implemented based on Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, Ultra Wide Band (UWB) technology, Bluetooth (BT) technology and other technologies.
  • RFID Radio Frequency Identification
  • IrDA Infrared Data Association
  • UWB Ultra Wide Band
  • Bluetooth Bluetooth
  • UE2300 may be powered by at least one Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array ( FPGA), controller, microcontroller, microprocessor or other electronic components for implementing the above method.
  • ASIC Application Specific Integrated Circuit
  • DSP Digital Signal Processor
  • DSPD Digital Signal Processing Device
  • PLD Programmable Logic Device
  • FPGA Field Programmable Gate Array
  • controller microcontroller, microprocessor or other electronic components for implementing the above method.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本公开提出一种直连通信方法、装置、用户设备及存储介质,属于通信技术领域。其中,该方法包括:接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。

Description

一种直连通信方法、装置、用户设备及存储介质 技术领域
本公开涉及通信技术领域,尤其涉及一种直连通信方法、装置、用户设备及存储介质。
背景技术
在5G通信系统中,引入了Prose(Proximity based Service,邻近通信服务),以实现UE(User Equipment,用户设备)之间的直连通信(direct communication)。
但是,如何在Prose服务中确保UE之间的直连通信安全是亟需解决的问题。
发明内容
本公开提出的直连通信方法、装置、用户设备及存储介质,以在Prose服务中确保UE之间的直连通信安全。
本公开一方面实施例提出的直连通信方法,应用于接收ProSe UE,包括:
获取ProSe业务对应的安全策略;
基于所述安全策略与发起ProSe UE建立直连通信安全。
本公开另一方面实施例提出的直连通信方法,应用于发起ProSe UE,包括:
获取ProSe业务对应的安全策略;
基于安全策略与接收ProSe UE建立直连通信安全。
本公开又一方面实施例提出的直连通信装置,包括:
获取模块,用于获取ProSe业务对应的安全策略;
通信模块,用于基于安全策略与发起ProSe UE建立直连通信安全。
本公开又一方面实施例提出的直连通信装置,包括:
获取模块,用于获取ProSe业务对应的安全策略;
通信模块,用于基于安全策略与接收ProSe UE建立直连通信安全。
本公开又一方面实施例提出的一种用户设备,包括:收发器;存储器;处理器,分别与所述收发器及所述存储器连接,配置为通过执行所述存储器上的计算机可执行指令,控制所述收发器的无线信号收发,并能够实现如上又一方面实施例提出的方法。
本公开又一方面实施例提出的计算机存储介质,其中,所述计算机存储介质存储有计 算机可执行指令;所述计算机可执行指令被处理器执行后,能够实现如上所述的方法。
综上所述,在本公开实施例提供的直连通信方法、装置、用户设备及存储介质之中,接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
本公开附加的方面和优点将在下面的描述中部分给出,部分将从下面的描述中变得明显,或通过本公开的实践了解到。
附图说明
本公开上述的和/或附加的方面和优点从下面结合附图对实施例的描述中将变得明显和容易理解,其中:
图1为本公开一个实施例所提供的直连通信方法的流程示意图;
图2为本公开另一个实施例所提供的直连通信方法的流程示意图;
图3为本公开再一个实施例所提供的直连通信方法的流程示意图;
图4为本公开又一个实施例所提供的直连通信方法的流程示意图;
图5为本公开又一个实施例所提供的直连通信方法的流程示意图;
图6为本公开又一个实施例所提供的直连通信方法的流程示意图;
图7为本公开又一个实施例所提供的直连通信方法的流程示意图;
图8为本公开又一个实施例所提供的直连通信方法的流程示意图;
图9为本公开又一个实施例所提供的直连通信方法的流程示意图;
图10为本公开又一个实施例所提供的直连通信方法的流程示意图;
图11为本公开又一个实施例所提供的直连通信方法的流程示意图;
图12为本公开又一个实施例所提供的直连通信方法的流程示意图;
图13为本公开又一个实施例所提供的直连通信方法的流程示意图;
图14为本公开又一个实施例所提供的直连通信方法的流程示意图;
图15为本公开又一个实施例所提供的直连通信方法的流程示意图;
图16为本公开又一个实施例所提供的直连通信方法的流程示意图;
图17为本公开又一个实施例所提供的直连通信方法的流程示意图;
图18为本公开又一个实施例所提供的直连通信方法的流程示意图;
图19为本公开又一个实施例所提供的直连通信方法的流程示意图;
图20为本公开又一个实施例所提供的直连通信方法的流程示意图;
图21为本公开一个实施例所提供的直连通信装置的结构示意图;
图22为本公开另一个实施例所提供的直连通信装置的结构示意图;
图23是本公开一个实施例所提供的一种用户设备的框图。
具体实施方式
这里将详细地对示例性实施例进行说明,其示例表示在附图中。下面的描述涉及附图时,除非另有表示,不同附图中的相同数字表示相同或相似的要素。以下示例性实施例中所描述的实施方式并不代表与本公开实施例相一致的所有实施方式。相反,它们仅是与如所附权利要求书中所详述的、本公开实施例的一些方面相一致的装置和方法的例子。
在本公开实施例使用的术语是仅仅出于描述特定实施例的目的,而非旨在限制本公开实施例。在本公开实施例和所附权利要求书中所使用的单数形式的“一种”和“该”也旨在包括多数形式,除非上下文清楚地表示其他含义。还应当理解,本文中使用的术语“和/或”是指并包含一个或多个相关联的列出项目的任何或所有可能组合。
应当理解,尽管在本公开实施例可能采用术语第一、第二、第三等来描述各种信息,但这些信息不应限于这些术语。这些术语仅用来将同一类型的信息彼此区分开。例如,在不脱离本公开实施例范围的情况下,第一信息也可以被称为第二信息,类似地,第二信息也可以被称为第一信息。取决于语境,如在此所使用的词语“如果”及“若”可以被解释成为“在……时”或“当……时”或“响应于确定”。
下面详细描述本公开的实施例,所述实施例的示例在附图中示出,其中自始至终相同或类似的标号表示相同或类似的要素。下面通过参考附图描述的实施例是示例性的,旨在用于解释本公开,而不能理解为对本公开的限制。
其中,在本公开实施例提供的直连通信方法之中,接收ProSe UE可以获取ProSe业务 对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
下面参考附图对本公开提供的直连通信方法、装置、用户设备及存储介质进行详细描述。
图1为本公开实施例所提供的一种直连通信方法的流程示意图,应用于接收ProSe UE,如图1所示,该直连通信方法可以包括以下步骤:
步骤101、获取ProSe业务对应的安全策略。
需要说明的是,本公开实施例的指示方法可以应用在任意的UE中。UE可以是指向用户提供语音和/或数据连通性的设备。UE可以经RAN(Radio Access Network,无线接入网)与一个或多个核心网进行通信,UE可以是物联网终端,如传感器设备、移动电话(或称为“蜂窝”电话)和具有物联网终端的计算机,例如,可以是固定式、便携式、袖珍式、手持式、计算机内置的或者车载的装置。例如,站(Station,STA)、订户单元(subscriber unit)、订户站(subscriber station),移动站(mobile station)、移动台(mobile)、远程站(remote station)、接入点、远程终端(remoteterminal)、接入终端(access terminal)、用户装置(user terminal)或用户代理(useragent)。或者,UE也可以是无人飞行器的设备。或者,UE也可以是车载设备,比如,可以是具有无线通信功能的行车电脑,或者是外接行车电脑的无线终端。或者,UE也可以是路边设备,比如,可以是具有无线通信功能的路灯、信号灯或者其它路边设备等。
其中,在本公开的一个实施例之中,可以预先为每个ProSe UE配置ProSe业务对应的安全策略,以使得ProSe UE可以基于安全策略对ProSe UE的PC5接口进行安全保护。
以及,在本公开的一个实施例之中,ProSe业务对应的安全策略具体可以包括需被保护的ProSe业务及该需被保护的ProSe业务对应的安全策略。
其中,在本公开的一个实施例之中,安全策略具体可以包括以下的至少一种:
信令完整性保护的策略;
信令加密保护的策略;
UP(User Plane,用户面)完整性保护的策略;
UP加密保护的策略。
其中,在本公开的一个实施例之中,安全策略可以为上述策略中的任意一种。在本公开的另一个实施例之中,安全策略可以为上述策略的任意组合。
以及,在本公开的一个实施例之中,上述的信令完整性保护的策略和信令加密保护的策略属于信令安全策略;上述的UP完整性保护的策略和UP加密保护的策略属于UP安全策略。
进一步地,在本公开的一个实施例之中,安全策略可以包括:REQUIRED(需要保护);NOT NEEDED(不需要保护);PREFERRED(可选性保护)。
具体的,在本公开的一个实施例之中,信令完整性保护的策略可以包括:REQUIRED;或者,NOT NEEDED;或者,PREFERRED。
以及,在本公开的一个实施例之中,信令加密保护的策略可以包括:REQUIRED;或者,NOT NEEDED;或者,PREFERRED。
其中,在本公开的一个实施例之中,UP完整性保护的策略可以包括:REQUIRED;或者,NOT NEEDED;或者,PREFERRED。
以及,在本公开的一个实施例之中,UP加密保护的策略可以包括:REQUIRED;或者,NOT NEEDED;或者,PREFERRED。
需要说明的是,在本公开的一个实施例之中,REQUIRED可以指示ProSe UE需要安全保护。以及,在本公开的一个实施例之中,当ProSe UE对应的安全策略为REQUIRED时,该ProSe UE仅能与安全策略同样为REQUIRED的ProSe UE建立安全性的连接。进一步示例的,当ProSe UE对应的安全策略为REQUIRED时,ProSe UE仅能与使用非NULL机密性算法或完整性算法的ProSe UE建立连接。
在本公开的一个实施例之中,NOT NEEDED可以指示ProSe UE不需要安全保护,以及,在本公开的一个实施例之中,当ProSe UE对应的安全策略为NOT NEEDED时,该ProSe UE仅能与安全策略同样为NOT NEEDED的ProSe UE建立没有安全性的连接。
在本公开的一个实施例之中,PREFERRED指示ProSe UE可以进行安全保护,或者,也可以不进行安全保护。以及,在本公开的一个实施例之中,当ProSe UE对应的安全策略 为PREFERRED时,该ProSe UE可以与安全策略为REQUIRED的ProSe UE建立安全性的连接,也可以与安全策略为NOT NEEDED的ProSe UE建立没有安全性的连接。
以及,需要说明的是,在本公开的一个实施例之中,安全策略为REQUIRED的ProSe UE与安全策略为NOT NEEDED的ProSe UE之间具备安全策略冲突,使得该两个ProSe UE不具备直连资格。
进一步地,在本公开的一个实施例之中,ProSe UE获取ProSe业务对应的安全策略的方法可以包括:获取PCF(Policy Control Function,策略控制功能)发送的需被保护的ProSe业务及需被保护的ProSe业务对应的安全策略。
以及,在本公开的另一个实施例之中,ProSe UE获取ProSe业务对应的安全策略的方法可以包括:获取ProSe应用服务器发送的需被保护的ProSe业务及需被保护的ProSe业务对应的安全策略。其中,在本公开的一个实施例之中,ProSe应用服务器可以通过PCF向ProSe UE发送ProSe业务对应的安全策略。在本公开的另一个实施例之中,ProSe应用服务器可以通过PC1接口向ProSe UE发送ProSe业务对应的安全策略。
在本公开的又一个实施例之中,ProSe UE获取ProSe业务对应的安全策略的方法可以包括:获取UICC(Universal Integrated Circuit Card,嵌入式通用集成电路卡)上配置的需被保护的ProSe业务及需被保护的ProSe业务对应的安全策略。
需要说明的是,在本公开的一个实施例之中,ProSe UE获取ProSe业务对应的安全策略时,该安全策略可以通过NAS(Non Access Stratum,非接入)信令安全进行保护。其中,在本公开的一个实施例之中,该NAS安全可以是ProSe UE在注册ProSe业务后所建立的。
步骤102、基于安全策略与发起ProSe UE建立直连通信。
其中,关于基于安全策略与发起ProSe UE建立直连通信的具体方法在后续实施例会进行详细介绍。
综上所述,在本公开实施例提供的直连通信方法之中,接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图2为本公开另一个实施例所提供的一种直连通信方法的流程示意图,应用于接收ProSeUE,如图2所示,该直连通信方法可以包括以下步骤:
步骤201、获取ProSe业务对应的安全策略。
其中,关于步骤201的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
步骤202、获取发起ProSe UE发送的Direct Communication Request(直连通信请求)消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
步骤203、确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略是否满足第一预设条件。
其中,在本公开的一个实施例之中,第一预设条件可以包括以下的至少一种:
发起ProSe UE的信令完整性保护的策略为NOT NEEDED,接收ProSe UE的信令完整性保护的策略为REQUIRED;
发起ProSe UE的信令加密保护的策略为NOT NEEDED,接收ProSe UE的信令加密保护的策略为REQUIRED;
发起ProSe UE的信令完整性保护的策略为REQUIRED,接收ProSe UE的信令完整性保护的策略为NOT NEEDED;
发起ProSe UE的信令加密保护的策略为REQUIRED,接收ProSe UE的信令加密保护的策略为NOT NEEDED。
以及,需要说明的是,在公开的一个实施例之中,第一预设条件可以仅为上述预设条件中的任意一种。在本公开的另一个实施例之中,第一预设条件可以为上述预设条件中的任意组合。其中,在本公开的一个实施例之中,当第一预设条件包含上述两种或两种以上预设条件时,若发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略满足第一预设条件中的任意一种预设条件,则确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略满足第一预设条件,否则确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略不满足第一预设条件。
其中,在本公开的一个实施例之中,若确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略满足第一预设条件,则说明发起ProSe UE与接收ProSe UE之间存在 安全策略冲突,两者不具备直连的资格,继续执行步骤204。
步骤204、向发起ProSe UE发送第一拒绝消息,第一拒绝消息用于拒绝发起ProSe UE发送的Direct Communication Request消息。
综上所述,在本公开实施例提供的直连通信方法之中,接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图3为本公开再一个实施例所提供的一种直连通信方法的流程示意图,应用于接收ProSeUE,如图3所示,该直连通信方法可以包括以下步骤:
步骤301、获取ProSe业务对应的安全策略。
步骤302、获取发起ProSe UE发送的Direct Communication Request消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
步骤303、确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略是否满足第一预设条件。
其中,关于步骤301~步骤303的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
以及,在本公开的一个实施例之中,若确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略不满足第一预设条件,则说明发起ProSe UE与接收ProSe UE之间不存在安全策略冲突,两者具备直连的资格,继续执行步骤304。
步骤304、基于发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略确定信令安全策略的协商结果。
其中,在本公开的一个实施例之中,信令安全策略的协商结果可以包括以下的至少一种:
信令完整性保护的策略的协商结果;
信令加密保护的策略的协商结果。
以及,在本公开的一个实施例之中,基于发起ProSe UE的信令安全策略和接收ProSe  UE的信令安全策略确定信令安全策略的协商结果,包括:
若发起ProSe UE的信令完整性保护的策略为NOT NEEDED,和/或,接收ProSe UE的信令完整性保护的策略为NOT NEEDED,则确定信令完整性保护的策略的协商结果为NOT NEEDED。也即是,在接收ProSe UE和发起ProSe UE之间不具备安全策略冲突的情况下,当发起ProSe UE与接收ProSe UE之间有一个ProSe UE的信令完整性保护的策略为NOT NEEDED时,确定信令完整性保护的策略的协商结果为NOT NEEDED。
若发起ProSe UE的信令完整性保护的策略为REQUIRED,和/或,接收ProSe UE的信令完整性保护的策略为REQUIRED,则确定信令完整性保护的策略的协商结果为REQUIRED。也即是,在接收ProSe UE和发起ProSe UE之间不具备安全策略冲突的情况下,当发起ProSe UE与接收ProSe UE之间有一个ProSe UE的信令完整性保护的策略为REQUIRED时,确定信令完整性保护的策略的协商结果为REQUIRED。
若发起ProSe UE的信令完整性保护的策略为PREFERRED,且接收ProSe UE的信令完整性保护的策略为PREFERRED,则确定信令完整性保护的策略的协商结果为REQUIRED或NOT NEEDED。
若发起ProSe UE的信令加密保护的策略为NOT NEEDED,和/或,接收ProSe UE的信令加密保护的策略为NOT NEEDED,则确定信令加密保护的策略的协商结果为NOT NEEDED。也即是,在接收ProSe UE和发起ProSe UE之间不具备安全策略冲突的情况下,当发起ProSe UE与接收ProSe UE之间有一个ProSe UE的信令加密保护的策略为NOT NEEDED时,确定信令加密保护的策略的协商结果为NOT NEEDED。
若发起ProSe UE的信令加密保护的策略为REQUIRED,和/或,接收ProSe UE的信令加密保护的策略为REQUIRED,则确定信令加密保护的策略的协商结果为REQUIRED也即是,在接收ProSe UE和发起ProSe UE之间不具备安全策略冲突的情况下,当发起ProSe UE与接收ProSe UE之间有一个ProSe UE的信令加密保护的策略为REQUIRED时,确定信令加密保护的策略的协商结果为REQUIRED。
若发起ProSe UE的信令加密保护的策略为PREFERRED,且接收ProSe UE的信令加密保护的策略为PREFERRED,则确定信令加密保护的策略的协商结果为REQUIRED或NOT NEEDED。
步骤305、向发起ProSe UE发送Direct Security Mode Command(直接安全模式命令)消息,其中,Direct Security Mode Command消息包括信令安全策略的协商结果。
其中,在本公开的一个实施例之中,Direct Security Mode Command消息中包括信令安全策略的协商结果可以是上述步骤304确定的协商结果。
综上所述,在本公开实施例提供的直连通信方法之中,接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图4为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于接收ProSe UE,如图4所示,该直连通信方法可以包括以下步骤:
步骤401、获取ProSe业务对应的安全策略。
步骤402、获取发起ProSe UE发送的Direct Communication Request消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
步骤403、确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略是否满足第一预设条件。
以及,在本公开的一个实施例之中,若确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略不满足第一预设条件,则说明发起ProSe UE与接收ProSe UE之间不存在安全策略冲突,两者具备直连的资格,继续执行步骤404。
步骤404、基于发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略确定信令安全策略的协商结果。
步骤405、向发起ProSe UE发送Direct Security Mode Command(直接安全模式命令)消息,其中,Direct Security Mode Command消息包括信令安全策略的协商结果。
其中,关于步骤401~步骤405的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
步骤406、接收发起ProSe UE发送的第二拒绝消息,第二拒绝消息用于拒绝接收ProSe UE发送的Direct Security Mode Command消息。
其中,在本公开的一个实施例之中,当发起ProSe UE收到接收ProSeUE发送的Direct Security Mode Command消息后,会判断Direct Security Mode Command消息中包括的信令安全策略的协商结果对应的安全算法与发起ProSe UE的信令安全策略对应的安全算法是否一致。以及,在本公开的一个实施例之中,当发起ProSe UE判断Direct Security Mode Command消息中包括的信令安全策略的协商结果对应的安全算法与自身的信令安全策略对应的安全算法不一致时,说明接收ProSe UE与发送ProSe UE之间也不具备保护直连资格,则发起ProSe UE向接收ProSe UE发送第二拒绝消息,以拒绝接收ProSe UE发送的Direct Security Mode Command消息。
综上所述,在本公开实施例提供的直连通信方法之中,接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图5为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于接收ProSe UE,如图5所示,该直连通信方法可以包括以下步骤:
步骤501、获取ProSe业务对应的安全策略。
步骤502、获取发起ProSe UE发送的Direct Communication Request消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
步骤503、确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略是否满足第一预设条件。
以及,在本公开的一个实施例之中,若确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略不满足第一预设条件,则说明发起ProSe UE与接收ProSe UE之间不存在安全策略冲突,两者具备直连的资格,继续执行步骤504。
步骤504、基于发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略确定信令安全策略的协商结果。
步骤505、向发起ProSe UE发送Direct Security Mode Command消息,其中,Direct Security Mode Command消息包括信令安全策略的协商结果。
其中,关于步骤501~步骤505的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
步骤506、判断信令安全策略的协商结果是否为NOT NEEDED。
其中,在本公开的一个实施例之中,当信令安全策略的协商结果为NOT NEEDED时,继续执行步骤507。
步骤507、将接收ProSe UE的UP安全策略更改为NOT NEEDED。
其中,在本公开的一个实施例之中,当信令加密保护的策略的协商结果为NOT NEEDED时,说明发起ProSe UE与接收ProSe UE之间的信令不需要安全保护且协商的加密算法为NULL算法,此时,可以将接收ProSe UE的UP加密保护的策略也更改为NOT NEEDED。
综上所述,在本公开实施例提供的直连通信方法之中,接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图6为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于接收ProSe UE,如图6所示,该直连通信方法可以包括以下步骤:
步骤601、获取ProSe业务对应的安全策略。
步骤602、获取发起ProSe UE发送的Direct Communication Request消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
步骤603、确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略是否满足第一预设条件。
以及,在本公开的一个实施例之中,若确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略不满足第一预设条件,则说明发起ProSe UE与接收ProSe UE之间不存在安全策略冲突,两者具备直连的资格,继续执行步骤604。
步骤604、基于发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略确定信令安全策略的协商结果。
步骤605、向发起ProSe UE发送Direct Security Mode Command消息,其中,Direct Security Mode Command消息包括信令安全策略的协商结果。
其中,关于步骤601~步骤605的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
以及,在本公开的一个实施例之中,至此步骤605,接收ProSe UE与发起ProSe UE之间的信令安全策略协商完毕,进而可以继续执行后续步骤以协商接收ProSe UE与发起ProSe UE之间的UP安全策略。
还需要说明的是,在本公开的一个实施例之中,若步骤604中确定出的信令安全策略的协商结果为REQUIRED,则认为在接收ProSe UE与发起ProSe UE之间建立了信令安全保护,则后续过程中,接收ProSe UE与发起ProSe UE进行交互时,所交互的消息会受到信令安全保护,确保了信令传输的安全性。
步骤606、接收发起ProSe UE发送的Direct Security Mode Complete消息,其中,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略。
步骤607、确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件。
其中,在本公开的一个实施例之中,第二预设条件可以包括以下的至少一种:
发起ProSe UE的UP完整性保护的策略为NOT NEEDED,接收ProSe UE的UP完整性保护的策略为REQUIRED;
发起ProSe UE的UP加密保护的策略为NOT NEEDED,接收ProSe UE的UP加密保护的策略为REQUIRED;
发起ProSe UE的UP完整性保护的策略为REQUIRED,接收ProSe UE的UP完整性保护的策略为NOT NEEDED;
发起ProSe UE的UP加密保护的策略为REQUIRED,接收ProSe UE的UP加密保护的策略为NOT NEEDED。
以及,需要说明的是,在公开的一个实施例之中,第二预设条件可以仅为上述预设条件中的任意一种。在本公开的另一个实施例之中,第二预设条件可以为上述预设条件中的任意组合。其中,在本公开的一个实施例之中,当第二预设条件包含上述两种或两种以上 预设条件时,若发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略满足第二预设条件中的任意一种预设条件,则确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略满足第二预设条件,否则确定确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略不满足第二预设条件。
进一步地,在本公开的一个实施例之中,若确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略满足第二预设条件,则说明发起ProSe UE与接收ProSe UE之间存在安全策略冲突,两者不具备直连的资格,继续执行步骤608。
此外,需要说明的是,在本公开的一个实施例之中,在步骤607确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件之前,接收ProSe UE会先判断上述步骤605所确定出的信令安全策略的协商结果是否为NOT NEEDED,当为NOT NEEDED时,会将接收ProSe UE的UP安全策略也更改为NOT NEEDED。以及,之后,在确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件时,具体是确定发起ProSe UE的UP安全策略和接收ProSe UE的更改后的UP安全策略是否满足第二预设条件。
步骤608、向发起ProSe UE发送第三拒绝消息,其中,第三拒绝消息用于拒绝发起ProSe UE发送的Direct Security Mode Complete消息。
综上所述,在本公开实施例提供的直连通信方法之中,接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图7为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于接收ProSe UE,如图7所示,该直连通信方法可以包括以下步骤:
步骤701、获取ProSe业务对应的安全策略。
步骤702、获取发起ProSe UE发送的Direct Communication Request消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
步骤703、确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略是否 满足第一预设条件。
以及,在本公开的一个实施例之中,若确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略不满足第一预设条件,则说明发起ProSe UE与接收ProSe UE之间不存在安全策略冲突,两者具备直连的资格,继续执行步骤704。
步骤704、基于发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略确定信令安全策略的协商结果。
步骤705、向发起ProSe UE发送Direct Security Mode Command消息,其中,Direct Security Mode Command消息包括信令安全策略的协商结果。
步骤706、接收发起ProSe UE发送的Direct Security Mode Complete消息,其中,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略。
步骤707、确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件。
其中,关于步骤701~步骤707的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
以及,在本公开的一个实施例之中,若确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略不满足第二预设条件,则说明发起ProSe UE与接收ProSe UE之间不存在安全策略冲突,两者具备直连的资格,继续执行步骤708。
此外,需要说明的是,在本公开的一个实施例之中,在步骤707确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件之前,接收ProSe UE会先判断上述步骤705所确定出的信令安全策略的协商结果是否为NOT NEEDED,当为NOT NEEDED时,会将接收ProSe UE的UP安全策略也更改为NOT NEEDED。以及,之后,在确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件时,具体是确定发起ProSe UE的UP安全策略和接收ProSe UE的更改后的UP安全策略是否满足第二预设条件。
步骤708、基于发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略确定UP安全策略的协商结果。
其中,在本公开的一个实施例之中,UP安全策略的协商结果可以包括以下的至少一 种:
UP完整性保护的策略的协商结果;
UP加密保护的策略的协商结果。
以及,在本公开的一个实施例之中,基于发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略确定UP安全策略的协商结果,包括:
若发起ProSe UE的UP完整性保护的策略为NOT NEEDED,和/或,接收ProSe UE的UP完整性保护的策略为NOT NEEDED,确定UP完整性保护的策略的协商结果为NOT NEEDED。也即是,在接收ProSe UE和发起ProSe UE之间不具备安全策略冲突的情况下,当发起ProSe UE与接收ProSe UE之间有一个ProSe UE的UP完整性保护的策略为NOT NEEDED时,确定UP完整性保护的策略的协商结果为NOT NEEDED。
若发起ProSe UE的UP完整性保护的策略为REQUIRED,和/或,接收ProSe UE的UP完整性保护的策略为REQUIRED,确定UP完整性保护的策略的协商结果为REQUIRED。也即是,在接收ProSe UE和发起ProSe UE之间不具备安全策略冲突的情况下,当发起ProSe UE与接收ProSe UE之间有一个ProSe UE的UP完整性保护的策略为REQUIRED时,确定UP完整性保护的策略的协商结果为REQUIRED。
若发起ProSe UE的UP完整性保护的策略为PREFERRED,且接收ProSe UE的UP完整性保护的策略为PREFERRED,确定UP完整性保护的策略的协商结果为REQUIRED或NOT NEEDED。
若发起ProSe UE的UP加密保护的策略为NOT NEEDED,和/或,接收ProSe UE的UP加密保护的策略为NOT NEEDED,确定UP加密保护的策略的协商结果为NOT NEEDED。也即是,在接收ProSe UE和发起ProSe UE之间不具备安全策略冲突的情况下,当发起ProSe UE与接收ProSe UE之间有一个ProSe UE的UP加密保护的策略为NOT NEEDED时,确定UP加密保护的策略的协商结果为NOT NEEDED。
若发起ProSe UE的UP加密保护的策略为REQUIRED,和/或,接收ProSe UE的UP加密保护的策略为REQUIRED,确定UP加密保护的策略的协商结果为REQUIRED。也即是,在接收ProSe UE和发起ProSe UE之间不具备安全策略冲突的情况下,当发起ProSe UE与接收ProSe UE之间有一个ProSe UE的UP加密保护的策略为REQUIRED时,确定UP 加密保护的策略的协商结果为REQUIRED。
若发起ProSe UE的UP加密保护的策略为PREFERRED,且接收ProSe UE的UP加密保护的策略为PREFERRED,确定UP加密保护的策略的协商结果为REQUIRED或NOT NEEDED。
步骤709、向发起ProSe UE发送Direct Communication Accept消息,其中,Direct Communication Accept消息包括UP安全策略的协商结果。
其中,在本公开的一个实施例之中,Direct Communication Accept消息中包括UP安全策略的协商结果可以是上述步骤708确定的协商结果。
综上所述,在本公开实施例提供的直连通信方法之中,接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图8为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于接收ProSe UE,如图8所示,该直连通信方法可以包括以下步骤:
步骤801、获取ProSe业务对应的安全策略。
步骤802、获取发起ProSe UE发送的Direct Communication Request消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
步骤803、确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略是否满足第一预设条件。
以及,在本公开的一个实施例之中,若确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略不满足第一预设条件,则说明发起ProSe UE与接收ProSe UE之间不存在安全策略冲突,两者具备直连的资格,继续执行步骤804。
步骤804、基于发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略确定信令安全策略的协商结果。
步骤805、向发起ProSe UE发送Direct Security Mode Command消息,其中,Direct Security Mode Command消息包括信令安全策略的协商结果。
步骤806、接收发起ProSe UE发送的Direct Security Mode Complete消息,其中,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略。
步骤807、确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件。
其中,在本公开的一个实施例之中,若确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略不满足第二预设条件,则说明发起ProSe UE与接收ProSe UE之间不存在安全策略冲突,两者具备直连的资格,继续执行步骤808。
此外,需要说明的是,在本公开的一个实施例之中,在步骤807确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件之前,接收ProSe UE会先判断上述步骤804所确定出的信令安全策略的协商结果是否为NOT NEEDED,当为NOT NEEDED时,会将接收ProSe UE的UP安全策略也更改为NOT NEEDED。以及,之后,在确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件时,具体是确定发起ProSe UE的UP安全策略和接收ProSe UE的更改后的UP安全策略是否满足第二预设条件。
步骤808、基于发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略确定UP安全策略的协商结果。
步骤809、向发起ProSe UE发送Direct Communication Accept消息,其中,Direct Communication Accept消息包括UP安全策略的协商结果。
其中,关于步骤801~步骤809的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
步骤810、基于信令安全策略的协商结果和UP安全策略的协商结果与发起ProSe UE进行直连通信。
综上所述,在本公开实施例提供的直连通信方法之中,接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图9为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于发起ProSe UE,如图9所示,该直连通信方法可以包括以下步骤:
步骤901、获取ProSe业务对应的安全策略。
步骤902、基于安全策略与接收ProSe UE建立直连通信。
其中,关于步骤901~902的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
综上所述,在本公开实施例提供的直连通信方法之中,发起ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与接收ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图10为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于发起ProSe UE,如图10所示,该直连通信方法可以包括以下步骤:
步骤1001、获取ProSe业务对应的安全策略。
其中,关于步骤1001的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
步骤1002、向接收ProSe UE发送Direct Communication Request消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
步骤1003、获取接收ProSe UE发送的第一拒绝消息,第一拒绝消息用于拒绝发起ProSe UE发送的Direct Communication Request消息。
其中,在本公开的一个实施例之中,接收ProSe UE获取发起ProSe UE发送的Direct Communication Request消息后,会确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略是否满足第一预设条件。以及,在本公开的一个实施例之中,若确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略满足第一预设条件,则说明发起ProSe UE与接收ProSe UE之间存在安全策略冲突,两者不具备直连的资格,接收ProSe UE会向发起ProSe UE发送第一拒绝消息。
综上所述,在本公开实施例提供的直连通信方法之中,发起ProSe UE可以获取ProSe 业务对应的安全策略,并基于获取到的安全策略与接收ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图11为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于发起ProSe UE,如图11所示,该直连通信方法可以包括以下步骤:
步骤1101、获取ProSe业务对应的安全策略。
步骤1102、向接收ProSe UE发送Direct Communication Request消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
其中,关于步骤1101~1102的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
步骤1103、获取接收ProSe UE发送的Direct Security Mode Command消息,Direct Security Mode Command包括信令安全策略的协商结果。
其中,在本公开的一个实施例之中,接收ProSe UE获取发起ProSe UE发送的Direct Communication Request消息后,会确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略是否满足第一预设条件。
以及,在本公开的一个实施例之中,若确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略不满足第一预设条件,则说明发起ProSe UE与接收ProSe UE之间不存在安全策略冲突,两者具备直连的资格,接收ProSe UE会基于发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略确定信令安全策略的协商结果。之后,会向发起ProSe UE发送Direct Security Mode Command消息,其中,Direct Security Mode Command消息中包括信令安全策略的协商结果。
综上所述,在本公开实施例提供的直连通信方法之中,发起ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与接收ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图12为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于发起ProSe UE,如图12所示,该直连通信方法可以包括以下步骤:
步骤1201、获取ProSe业务对应的安全策略。
步骤1202、向接收ProSe UE发送Direct Communication Request消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
步骤1203、获取接收ProSe UE发送的Direct Security Mode Command消息,Direct Security Mode Command包括信令安全策略的协商结果。
其中,关于步骤1201~1203的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
步骤1204、判断接收ProSe UE的信令安全策略对应的安全算法与发起ProSe UE的信令安全策略对应的安全算法是否一致。
其中,在本公开的一个实施例之中,信令安全策略均有与之对应的安全算法。以及,在本公开的一个实施例之中,接收ProSe UE的信令安全策略对应的安全算法与发起ProSe UE的信令安全策略对应的安全算法可以一致。以及,在本公开的一个实施例之中,接收ProSe UE的信令安全策略对应的安全算法与发起ProSe UE的信令安全策略对应的安全算法可以不一致。
具体的,在本公开的一个实施例之中,当发起ProSe UE判断接收ProSe UE的信令安全策略对应的安全算法与自身的信令安全策略对应的安全算法不一致时,则说明接收ProSe UE与发送ProSe UE之间也不具备保护直连资格,继续执行步骤1205。
步骤1205、向接收ProSe UE发送第二拒绝消息,第二拒绝消息用于拒绝接收ProSe UE发送的Direct Security Mode Command消息。
综上所述,在本公开实施例提供的直连通信方法之中,发起ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与接收ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图13为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于发起 ProSe UE,如图13所示,该直连通信方法可以包括以下步骤:
步骤1301、获取ProSe业务对应的安全策略。
步骤1302、向接收ProSe UE发送Direct Communication Request消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
步骤1303、获取接收ProSe UE发送的Direct Security Mode Command消息,Direct Security Mode Command包括信令安全策略的协商结果。
其中,关于步骤1301~1303的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
步骤1304、判断信令安全策略的协商结果是否为NOT NEEDED。
其中,在本公开的一个实施例之中,当信令安全策略的协商结果为NOT NEEDED时,继续执行步骤1305。
步骤1305、将发送ProSe UE的UP安全策略更改为NOT NEEDED。
其中,在本公开的另一个实施例之中,当信令加密保护的策略的协商结果为NOT NEEDED时,说明发起ProSe UE与接收ProSe UE之间的信令不需要安全保护且协商的加密算法为NULL算法,此时,可以将发起ProSe UE的UP加密保护的策略也更改为NOT NEEDED。
综上所述,在本公开实施例提供的直连通信方法之中,发起ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与接收ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图14为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于发起ProSe UE,如图14所示,该直连通信方法可以包括以下步骤:
步骤1401、获取ProSe业务对应的安全策略。
步骤1402、向接收ProSe UE发送Direct Communication Request消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
步骤1403、获取接收ProSe UE发送的Direct Security Mode Command消息,Direct  Security Mode Command包括信令安全策略的协商结果。
其中,关于步骤1401~1403的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
步骤1404、判断接收ProSe UE的信令安全策略对应的安全算法与发起ProSe UE的信令安全策略对应的安全算法是否一致。
其中,在本公开的一个实施例之中,当发起ProSe UE判断接收ProSe UE的信令安全策略对应的安全算法与自身的信令安全策略对应的安全算法一致时,则说明接收ProSe UE与发送ProSe UE之间具备保护直连资格,继续执行步骤1405。
步骤1405、向接收ProSe UE发送Direct Security Mode Complete消息,其中,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略。
其中,需要说明的是,在本公开的一个实施例之中,在步骤1405向接收ProSe UE发送Direct Security Mode Complete消息之前,发起ProSe UE会先判断上述步骤1403中接收到的信令安全策略的协商结果是否为NOT NEEDED,当为NOT NEEDED时,会将发起ProSe UE的UP安全策略也更改为NOT NEEDED。以及,之后,向接收ProSe UE发送Direct Security Mode Complete消息时,Direct Security Mode Complete消息中具体包含的是发起ProSe UE的更改后的UP安全策略。
步骤1406、获取接收ProSe UE发送的第三拒绝消息,第三拒绝消息用于拒绝发起ProSe UE发送的Direct Security Mode Complete消息。
其中,在本公开的一个实施例之中,接收ProSe UE获取发起ProSe UE发送的Direct Security Mode Complete消息后,会确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件。以及,在本公开的一个实施例之中,若确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略满足第二预设条件,则说明发起ProSe UE与接收ProSe UE之间存在安全策略冲突,两者不具备直连的资格,接收ProSe UE会向发起ProSe UE发送第三拒绝消息。
综上所述,在本公开实施例提供的直连通信方法之中,发起ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与接收ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起 ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图15为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于发起ProSe UE,如图15所示,该直连通信方法可以包括以下步骤:
步骤1501、获取ProSe业务对应的安全策略。
步骤1502、向接收ProSe UE发送Direct Communication Request消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
步骤1503、获取接收ProSe UE发送的Direct Security Mode Command消息,Direct Security Mode Command包括信令安全策略的协商结果。
步骤1504、判断接收ProSe UE的信令安全策略对应的安全算法与发起ProSe UE的信令安全策略对应的安全算法是否一致。
其中,在本公开的一个实施例之中,当发起ProSe UE判断接收ProSe UE的信令安全策略对应的安全算法与自身的信令安全策略对应的安全算法一致时,则说明接收ProSe UE与发送ProSe UE之间具备保护直连资格,继续执行步骤1505。
步骤1505、向接收ProSe UE发送Direct Security Mode Complete消息,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略。
其中,关于步骤1501~1505的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
其中,需要说明的是,在本公开的一个实施例之中,在步骤1405向接收ProSe UE发送Direct Security Mode Complete消息之前,发起ProSe UE会先判断上述步骤1403中接收到的信令安全策略的协商结果是否为NOT NEEDED,当为NOT NEEDED时,会将发起ProSe UE的UP安全策略也更改为NOT NEEDED。以及,之后,向接收ProSe UE发送Direct Security Mode Complete消息时,Direct Security Mode Complete消息中具体包含的是发起ProSe UE的更改后的UP安全策略。
步骤1506、获取接收ProSe UE发送的Direct Communication Accept消息,Direct Communication Accept消息包括UP安全策略的协商结果。
其中,在本公开的一个实施例之中,接收ProSe UE获取发起ProSe UE发送的Direct  Security Mode Complete消息后,会确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件。
以及,在本公开的一个实施例之中,若确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略不满足第二预设条件,则说明发起ProSe UE与接收ProSe UE之间不存在安全策略冲突,两者具备保护直连的资格,接收ProSe UE会基于发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略确定UP安全策略的协商结果。之后,向发起ProSe UE发送Direct Communication Accept消息,其中,Direct Communication Accept消息中包括UP安全策略的协商结果。
综上所述,在本公开实施例提供的直连通信方法之中,发起ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与接收ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图16为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于发起ProSe UE,如图16所示,该直连通信方法可以包括以下步骤:
步骤1601、获取ProSe业务对应的安全策略。
步骤1602、向接收ProSe UE发送Direct Communication Request消息,其中,Direct Communication Request消息中包含发起ProSe UE的信令安全策略。
步骤1603、获取接收ProSe UE发送的Direct Security Mode Command消息,Direct Security Mode Command包括信令安全策略的协商结果。
步骤1604、判断接收ProSe UE的信令安全策略对应的安全算法与发起ProSe UE的信令安全策略对应的安全算法是否一致。
其中,在本公开的一个实施例之中,当发起ProSe UE判断接收ProSe UE的信令安全策略对应的安全算法与自身的信令安全策略对应的安全算法一致时,则说明接收ProSe UE与发送ProSe UE之间具备保护直连资格,继续执行步骤1605。
步骤1605、向接收ProSe UE发送Direct Security Mode Complete消息,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略。
其中,需要说明的是,在本公开的一个实施例之中,在步骤1605向接收ProSe UE发送Direct Security Mode Complete消息之前,发起ProSe UE会先判断上述步骤1603中接收到的信令安全策略的协商结果是否为NOT NEEDED,当为NOT NEEDED时,会将发起ProSe UE的UP安全策略也更改为NOT NEEDED。以及,之后,向接收ProSe UE发送Direct Security Mode Complete消息时,Direct Security Mode Complete消息中具体包含的是发起ProSe UE的更改后的UP安全策略。
步骤1606、获取接收ProSe UE发送的Direct Communication Accept消息,Direct Communication Accept消息包括UP安全策略的协商结果。
其中,关于步骤1601~1606的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
步骤1607、基于信令安全策略的协商结果和UP安全策略的协商结果与ProSe UE进行直连通信。
综上所述,在本公开实施例提供的直连通信方法之中,发起ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与接收ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图17为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于接收ProSe UE,如图17所示,该直连通信方法可以包括以下步骤:
步骤1701、获取ProSe业务对应的安全策略。
步骤1702、接收发起ProSe UE发送的Direct Security Mode Complete消息,其中,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略。
步骤1703、确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件,若满足第二预设条件,则执行步骤1704。
其中,在本公开的一个实施例之中,若确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略满足第二预设条件,则说明发起ProSe UE与接收ProSe UE之间存在安全策略冲突,两者不具备保护直连的资格,继续执行步骤1704。
步骤1704、向发起ProSe UE发送第三拒绝消息,其中,第三拒绝消息用于拒绝发起ProSe UE发送的Direct Security Mode Complete消息。
其中,关于步骤1701~1704的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
综上所述,在本公开实施例提供的直连通信方法之中,接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图18为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于接收ProSe UE,如图18所示,该直连通信方法可以包括以下步骤:
步骤1801、获取ProSe业务对应的安全策略。
步骤1802、接收发起ProSe UE发送的Direct Security Mode Complete消息,其中,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略。
步骤1803、确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件,若不满足第二预设条件,则执行步骤1804。
其中,在本公开的一个实施例之中,若确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略不满足第二预设条件,则说明发起ProSe UE与接收ProSe UE之间不存在安全策略冲突,两者具备保护直连的资格,继续执行步骤1804。
步骤1804、基于发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略确定UP安全策略的协商结果。
步骤1805、向发起ProSe UE发送Direct Communication Accept消息,其中,Direct Communication Accept消息包括UP安全策略的协商结果。
其中,关于步骤1801~1805的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
综上所述,在本公开实施例提供的直连通信方法之中,接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此, 本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图19为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于发起ProSe UE,如图19所示,该直连通信方法可以包括以下步骤:
步骤1901、获取ProSe业务对应的安全策略。
步骤1902、向接收ProSe UE发送Direct Security Mode Complete消息,其中,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略。
步骤1903、获取接收ProSe UE发送的第三拒绝消息,第三拒绝消息用于拒绝发起ProSe UE发送的Direct Security Mode Complete消息。
其中,关于步骤1901~1903的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
综上所述,在本公开实施例提供的直连通信方法之中,发起ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与接收ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图20为本公开又一个实施例所提供的一种直连通信方法的流程示意图,应用于发起ProSe UE,如图20所示,该直连通信方法可以包括以下步骤:
步骤2001、获取ProSe业务对应的安全策略。
步骤2002、向接收ProSe UE发送Direct Security Mode Complete消息,其中,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略。
步骤2003、获取接收ProSe UE发送的Direct Communication Accept消息,Direct Communication Accept消息包括UP安全策略的协商结果。
其中,关于步骤2001~2003的详细介绍可以参考上述实施例中的相关介绍,本公开实施例在此不做赘述。
综上所述,在本公开实施例提供的直连通信方法之中,发起ProSe UE可以获取ProSe 业务对应的安全策略,并基于获取到的安全策略与接收ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
图21为本公开一个实施例所提供的一种直连通信装置的结构示意图,如图21所示,装置2100可以包括:
获取模块2101,用于获取ProSe业务对应的安全策略;
通信模块2102,用于基于所述安全策略与发起ProSe UE建立直连通信安全。
综上所述,在本公开实施例提供的直连通信装置之中,接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
在本公开一个实施例之中,安全策略包括以下的至少一种:
信令安全策略;
用户面UP安全策略。
进一步地,在本公开另一个实施例之中,安全策略包括以下的至少一种:
信令完整性保护的策略;
信令加密保护的策略;
UP完整性保护的策略;
UP加密保护的策略。
进一步地,在本公开另一个实施例之中,所述安全策略包括:REQUIRED;NOT NEEDED;PREFERRED。
进一步地,在本公开另一个实施例之中,获取模块,还用于:
获取PCF发送的需被保护的ProSe业务及需被保护的ProSe业务对应的安全策略。
进一步地,在本公开另一个实施例之中,获取模块,还用于:
获取ProSe应用服务器发送的需被保护的ProSe业务及需被保护的ProSe业务对应的 安全策略。
进一步地,在本公开另一个实施例之中,获取模块,还用于:
获取UICC上配置的需被保护的ProSe业务及需被保护的ProSe业务对应的安全策略。
进一步地,在本公开另一个实施例之中,上述通信模块2102,还用于:
获取发起ProSe UE发送的直接通信请求Direct Communication Request消息,Direct Communication Request消息中包含发起ProSe UE的信令安全策略;
确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略是否满足第一预设条件;
第一预设条件包括以下的至少一种:
发起ProSe UE的信令完整性保护的策略为NOT NEEDED,接收ProSe UE的信令完整性保护的策略为REQUIRED;
发起ProSe UE的信令加密保护的策略为NOT NEEDED,接收ProSe UE的信令加密保护的策略为REQUIRED;
发起ProSe UE的信令完整性保护的策略为REQUIRED,接收ProSe UE的信令完整性保护的策略为NOT NEEDED;
发起ProSe UE的信令加密保护的策略为REQUIRED,接收ProSe UE的信令加密保护的策略为NOT NEEDED;
当满足第一预设条件,向发起ProSe UE发送第一拒绝消息,第一拒绝消息用于拒绝发起ProSe UE发送的Direct Communication Request消息。
进一步地,在本公开另一个实施例之中,上述通信模块2102,还用于:
获取发起ProSe UE发送的Direct Communication Request消息,Direct Communication Request消息中包含发起ProSe UE的信令安全策略;
确定发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略是否满足第一预设条件;
第一预设条件包括以下的至少一种:
发起ProSe UE的信令完整性保护的策略为NOT NEEDED,接收ProSe UE的信令完整性保护的策略为REQUIRED;
发起ProSe UE的信令加密保护的策略为NOT NEEDED,接收ProSe UE的信令加密保护的策略为REQUIRED;
发起ProSe UE的信令完整性保护的策略为REQUIRED,接收ProSe UE的信令完整性保护的策略为NOT NEEDED;
发起ProSe UE的信令加密保护的策略为REQUIRED,接收ProSe UE的信令加密保护的策略为NOT NEEDED;
当不满足第一预设条件,基于发起ProSe UE的信令安全策略和接收ProSe UE的信令安全策略确定信令安全策略的协商结果;
向发起ProSe UE发送直接安全模式命令Direct Security Mode Command消息,Direct Security Mode Command消息包括所述信令安全策略的协商结果。
进一步地,在本公开另一个实施例之中,信令安全策略的协商结果包括以下的至少一种:
信令完整性保护的策略的协商结果;
信令加密保护的策略的协商结果;
进一步地,在本公开一个实施例之中,通信模块2102,还用于:
若发起ProSe UE的信令完整性保护的策略为NOT NEEDED,和/或,接收ProSe UE的信令完整性保护的策略为NOT NEEDED,确定信令完整性保护的策略的协商结果为NOT NEEDED;
若发起ProSe UE的信令完整性保护的策略为REQUIRED,和/或,接收ProSe UE的信令完整性保护的策略为REQUIRED,确定信令完整性保护的策略的协商结果为REQUIRED;
若发起ProSe UE的信令完整性保护的策略为PREFERRED,且接收ProSe UE的信令完整性保护的策略为PREFERRED,确定信令完整性保护的策略的协商结果为REQUIRED或NOT NEEDED;
若发起ProSe UE的信令加密保护的策略为NOT NEEDED,和/或,接收ProSe UE的信令加密保护的策略为NOT NEEDED,确定信令加密保护的策略的协商结果为NOT NEEDED;
若发起ProSe UE的信令加密保护的策略为REQUIRED,和/或,接收ProSe UE的信令加密保护的策略为REQUIRED,确定信令加密保护的策略的协商结果为REQUIRED;
若发起ProSe UE的信令加密保护的策略为PREFERRED,且接收ProSe UE的信令加密保护的策略为PREFERRED,确定信令加密保护的策略的协商结果为REQUIRED或NOT NEEDED。
进一步地,在本公开另一个实施例之中,上述装置还用于:
接收发起ProSe UE发送的第二拒绝消息,第二拒绝消息用于拒绝所述接收ProSe UE发送的Direct Security Mode Command消息。
进一步地,在本公开另一个实施例之中,上述装置还用于:
当信令加密保护的策略的协商结果为NOT NEEDED,将接收ProSe UE的UP加密保护的策略更改为NOT NEEDED。
进一步地,在本公开另一个实施例之中,上述装置还用于:
接收发起ProSe UE发送的直接安全模式完成Direct Security Mode Complete消息,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略;
确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件;
第二预设条件包括以下的至少一种:
发起ProSe UE的UP完整性保护的策略为NOT NEEDED,接收ProSe UE的UP完整性保护的策略为REQUIRED;
发起ProSe UE的UP加密保护的策略为NOT NEEDED,接收ProSe UE的UP加密保护的策略为REQUIRED;
发起ProSe UE的UP完整性保护的策略为REQUIRED,接收ProSe UE的UP完整性保护的策略为NOT NEEDED;
发起ProSe UE的UP加密保护的策略为REQUIRED,接收ProSe UE的UP加密保护的策略为NOT NEEDED;
当满足第二预设条件,向发起ProSe UE发送第三拒绝消息,第三拒绝消息用于拒绝发起ProSe UE发送的Direct Security Mode Complete消息。
进一步地,在本公开另一个实施例之中,上述装置还用于:
接收发起ProSe UE发送的Direct Security Mode Complete消息,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略;
确定发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略是否满足第二预设条件;
第二预设条件包括以下的至少一种:
发起ProSe UE的UP完整性保护的策略为NOT NEEDED,接收ProSe UE的UP完整性保护的策略为REQUIRED;
发起ProSe UE的UP加密保护的策略为NOT NEEDED,接收ProSe UE的UP加密保护的策略为REQUIRED;
发起ProSe UE的UP完整性保护的策略为REQUIRED,接收ProSe UE的UP完整性保护的策略为NOT NEEDED;
发起ProSe UE的UP加密保护的策略为REQUIRED,接收ProSe UE的UP加密保护的策略为NOT NEEDED;
当不满足第二预设条件,基于发起ProSe UE的UP安全策略和接收ProSe UE的UP安全策略确定UP安全策略的协商结果;
向发起ProSe UE发送直接通信接受Direct Communication Accept消息,Direct Communication Accept消息包括UP安全策略的协商结果。
进一步地,在本公开另一个实施例之中,UP安全策略的协商结果包括以下的至少一种:UP完整性保护的策略的协商结果;UP加密保护的策略的协商结果。
进一步地,在本公开另一个实施例之中,上述装置还用于:
若发起ProSe UE的UP完整性保护的策略为NOT NEEDED,和/或,接收ProSe UE的UP完整性保护的策略为NOT NEEDED,确定UP完整性保护的策略的协商结果为NOT NEEDED;
若发起ProSe UE的UP完整性保护的策略为REQUIRED,和/或,接收ProSe UE的UP完整性保护的策略为REQUIRED,确定UP完整性保护的策略的协商结果为REQUIRED;
若发起ProSe UE的UP完整性保护的策略为PREFERRED,且接收ProSe UE的UP 完整性保护的策略为PREFERRED,确定UP完整性保护的策略的协商结果为REQUIRED或NOT NEEDED;
若发起ProSe UE的UP加密保护的策略为NOT NEEDED,和/或,接收ProSe UE的UP加密保护的策略为NOT NEEDED,确定UP加密保护的策略的协商结果为NOT NEEDED;
若发起ProSe UE的UP加密保护的策略为REQUIRED,和/或,接收ProSe UE的UP加密保护的策略为REQUIRED,确定UP加密保护的策略的协商结果为REQUIRED;
若发起ProSe UE的UP加密保护的策略为PREFERRED,且接收ProSe UE的UP加密保护的策略为PREFERRED,确定UP加密保护的策略的协商结果为REQUIRED或NOT NEEDED。
进一步地,在本公开另一个实施例之中,上述装置还用于:
基于信令安全策略的协商结果和UP安全策略的协商结果与发起ProSe UE进行直连通信。
图22为本公开另一个实施例所提供的一种直连通信的结构示意图,如图22所示,装置2200可以包括:
获取模块2201,用于获取ProSe业务对应的安全策略;
通信模块2202,用于基于所述安全策略与接收ProSe UE建立直连通信安全。
综上所述,在本公开实施例提供的直连通信装置之中,接收ProSe UE可以获取ProSe业务对应的安全策略,并基于获取到的安全策略与发起ProSe UE建立直连通信安全。由此,本公开实施例中,可以为UE配置ProSe业务对应的安全策略,使得接收ProSe UE和发起ProSe UE可以基于安全策略建立直连通信安全。从而保证了ProSe服务中UE之间的直连通信安全,提高了信息传输的安全性。
在本公开一个实施例之中,安全策略包括以下的至少一种:
信令安全策略;
UP安全策略。
进一步地,在本公开另一个实施例之中,所述安全策略包括以下的至少一种:
信令完整性保护的策略;
信令加密保护的策略;
UP完整性保护的策略;
UP加密保护的策略。
进一步地,在本公开另一个实施例之中,所述安全策略包括:REQUIRED;NOT NEEDED;PREFERRED。
进一步地,在本公开另一个实施例之中,获取模块,还用于:
获取PCF发送的需保护的ProSe业务及需保护的ProSe业务对应的安全策略。
进一步地,在本公开另一个实施例之中,获取模块,还用于:
获取ProSe应用服务器发送的需保护的ProSe业务及需保护的ProSe业务对应的安全策略。
进一步地,在本公开另一个实施例之中,获取模块,还用于:
获取UICC上配置的需保护的ProSe业务及需保护的ProSe业务对应的安全策略。
进一步地,在本公开另一个实施例之中,上述通信模块2202还用于:
向接收ProSe UE发送Direct Communication Request消息,Direct Communication Request消息中包含发起ProSe UE的信令安全策略;
获取接收ProSe UE发送的第一拒绝消息,第一拒绝消息用于拒绝发起ProSe UE发送的Direct Communication Request消息。
进一步地,在本公开另一个实施例之中,上述通信模块2202还用于:
向接收ProSe UE发送Direct Communication Request消息,Direct Communication Request消息中包含发起ProSe UE的信令安全策略;
获取接收ProSe UE发送的Direct Security Mode Command消息,Direct Security Mode Command包括信令安全策略的协商结果。
进一步地,在本公开另一个实施例之中,上述通信模块2202还用于:
判断接收ProSe UE的信令安全策略对应的安全算法与发起ProSe UE的信令安全策略对应的安全算法是否一致;
当不一致,向接收ProSe UE发送第二拒绝消息,第二拒绝消息用于拒绝所述接收ProSe UE发送的Direct Security Mode Command消息。
进一步地,在本公开另一个实施例之中,信令安全策略的协商结果包括以下的至少一种:
信令完整性保护的策略的协商结果;
信令加密保护的策略的协商结果。
进一步地,在本公开另一个实施例之中,上述装置还用于:
当信令加密保护的策略的协商结果为NOT NEEDED,将发起ProSe UE的UP加密保护的策略更改为NOT NEEDED。
进一步地,在本公开另一个实施例之中,上述装置还用于:
向接收ProSe UE发送Direct Security Mode Complete消息,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略;
获取接收ProSe UE发送的第三拒绝消息,第三拒绝消息用于拒绝发起ProSe UE发送的Direct Security Mode Complete消息。
进一步地,在本公开另一个实施例之中,上述装置还用于:
向接收ProSe UE发送Direct Security Mode Complete消息,Direct Security Mode Complete消息中包含发起ProSe UE的UP安全策略;
获取接收ProSe UE发送的Direct Communication Accept消息,Direct Communication Accept消息包括UP安全策略的协商结果。
进一步地,在本公开另一个实施例之中,上述装置还用于:
基于信令安全策略的协商结果和UP安全策略的协商结果与ProSe UE进行直连通信。
本公开实施例提供的计算机存储介质,存储有可执行程序;所述可执行程序被处理器执行后,能够实现如图1至图8、图17至图18或图9至图16、图19至图20任一所示的方法。
为了实现上述实施例,本公开还提出一种计算机程序产品,包括计算机程序,所述计算机程序在被处理器执行时实现如图1至图8、图17至图18或图9至图16、图19至图20任一所示的方法。
此外,为了实现上述实施例,本公开还提出一种计算机程序,该程序被处理器执行时,以实现如图1至图8、图17至图18或图9至图16、图19至图20任一所示的方法。
图19是本公开一个实施例所提供的一种用户设备UE1900的框图。例如,UE1900可以是移动电话,计算机,数字广播终端设备,消息收发设备,游戏控制台,平板设备,医疗设备,健身设备,个人数字助理等。
参照图23,UE2300可以包括以下至少一个组件:处理组件2302,存储器2304,电源组件2306,多媒体组件2308,音频组件2310,输入/输出(I/O)的接口2312,传感器组件2313,以及通信组件2316。
处理组件2302通常控制UE2300的整体操作,诸如与显示,电话呼叫,数据通信,相机操作和记录操作相关联的操作。处理组件2302可以包括至少一个处理器2320来执行指令,以完成上述的方法的全部或部分步骤。此外,处理组件2302可以包括至少一个模块,便于处理组件2302和其他组件之间的交互。例如,处理组件2302可以包括多媒体模块,以方便多媒体组件2308和处理组件2302之间的交互。
存储器2304被配置为存储各种类型的数据以支持在UE2300的操作。这些数据的示例包括用于在UE2300上操作的任何应用程序或方法的指令,联系人数据,电话簿数据,消息,图片,视频等。存储器2304可以由任何类型的易失性或非易失性存储设备或者它们的组合实现,如静态随机存取存储器(SRAM),电可擦除可编程只读存储器(EEPROM),可擦除可编程只读存储器(EPROM),可编程只读存储器(PROM),只读存储器(ROM),磁存储器,快闪存储器,磁盘或光盘。
电源组件2306为UE2300的各种组件提供电力。电源组件2306可以包括电源管理系统,至少一个电源,及其他与为UE2300生成、管理和分配电力相关联的组件。
多媒体组件2308包括在所述UE2300和用户之间的提供一个输出接口的屏幕。在一些实施例中,屏幕可以包括液晶显示器(LCD)和触摸面板(TP)。如果屏幕包括触摸面板,屏幕可以被实现为触摸屏,以接收来自用户的输入信号。触摸面板包括至少一个触摸传感器以感测触摸、滑动和触摸面板上的手势。所述触摸传感器可以不仅感测触摸或滑动动作的边界,而且还检测与所述触摸或滑动操作相关的唤醒时间和压力。在一些实施例中,多媒体组件2308包括一个前置摄像头和/或后置摄像头。当UE2300处于操作模式,如拍摄模式或视频模式时,前置摄像头和/或后置摄像头可以接收外部的多媒体数据。每个前置摄像头和后置摄像头可以是一个固定的光学透镜系统或具有焦距和光学变焦能力。
音频组件2310被配置为输出和/或输入音频信号。例如,音频组件2310包括一个麦克风(MIC),当UE2300处于操作模式,如呼叫模式、记录模式和语音识别模式时,麦克风被配置为接收外部音频信号。所接收的音频信号可以被进一步存储在存储器2304或经由通信组件2316发送。在一些实施例中,音频组件2310还包括一个扬声器,用于输出音频信号。
I/O接口2312为处理组件2302和外围接口模块之间提供接口,上述外围接口模块可以是键盘,点击轮,按钮等。这些按钮可包括但不限于:主页按钮、音量按钮、启动按钮和锁定按钮。
传感器组件2313包括至少一个传感器,用于为UE2300提供各个方面的状态评估。例如,传感器组件2313可以检测到设备2300的打开/关闭状态,组件的相对定位,例如所述组件为UE2300的显示器和小键盘,传感器组件2313还可以检测UE2300或UE2300一个组件的位置改变,用户与UE2300接触的存在或不存在,UE2300方位或加速/减速和UE2300的温度变化。传感器组件2313可以包括接近传感器,被配置用来在没有任何的物理接触时检测附近物体的存在。传感器组件2313还可以包括光传感器,如CMOS或CCD图像传感器,用于在成像应用中使用。在一些实施例中,该传感器组件2313还可以包括加速度传感器,陀螺仪传感器,磁传感器,压力传感器或温度传感器。
通信组件2316被配置为便于UE2300和其他设备之间有线或无线方式的通信。UE2300可以接入基于通信标准的无线网络,如WiFi,2G或3G,或它们的组合。在一个示例性实施例中,通信组件2316经由广播信道接收来自外部广播管理系统的广播信号或广播相关信息。在一个示例性实施例中,所述通信组件2316还包括近场通信(NFC)模块,以促进短程通信。例如,在NFC模块可基于射频识别(RFID)技术,红外数据协会(IrDA)技术,超宽带(UWB)技术,蓝牙(BT)技术和其他技术来实现。
在示例性实施例中,UE2300可以被至少一个应用专用集成电路(ASIC)、数字信号处理器(DSP)、数字信号处理设备(DSPD)、可编程逻辑器件(PLD)、现场可编程门阵列(FPGA)、控制器、微控制器、微处理器或其他电子元件实现,用于执行上述方法。
本领域技术人员在考虑说明书及实践这里公开的发明后,将容易想到本发明的其它实施方案。本公开旨在涵盖本发明的任何变型、用途或者适应性变化,这些变型、用途或者 适应性变化遵循本发明的一般性原理并包括本公开未公开的本技术领域中的公知常识或惯用技术手段。说明书和实施例仅被视为示例性的,本公开的真正范围和精神由下面的权利要求指出。
应当理解的是,本公开并不局限于上面已经描述并在附图中示出的精确结构,并且可以在不脱离其范围进行各种修改和改变。本公开的范围仅由所附的权利要求来限制。

Claims (34)

  1. 一种直连通信方法,其特征在于,应用于接收基于邻近业务通信ProSe用户设备UE,包括:
    获取ProSe业务对应的安全策略;以及
    基于所述安全策略与发起ProSe UE建立直连通信安全。
  2. 如权利要求1所述的方法,其特征在于,所述安全策略包括以下的至少一种:
    信令安全策略;
    用户面UP安全策略。
  3. 如权利要求2所述的方法,其特征在于,所述安全策略包括以下至少一种:
    信令完整性保护的策略;
    信令加密保护的策略;
    UP完整性保护的策略;
    UP加密保护的策略。
  4. 如权利要求3所述的方法,其特征在于,所述安全策略包括:需要保护REQUIRED;不需要保护NOT NEEDED;可选性保护PREFERRED。
  5. 如权利要求1-4任一所述的方法,其特征在于,所述获取ProSe业务对应的安全策略,包括:
    获取策略控制功能PCF发送的需被保护的ProSe业务及所述需被保护的ProSe业务对应的安全策略。
  6. 如权利要求1-4任一所述的方法,其特征在于,所述获取ProSe业务对应的安全策略,包括:
    获取ProSe应用服务器发送的需被保护的ProSe业务及所述需被保护的ProSe业务对 应的安全策略。
  7. 如权利要求1-4任一所述的方法,其特征在于,所述获取ProSe业务对应的安全策略,包括:
    获取嵌入式通用集成电路卡UICC上配置的需被保护的ProSe业务及所述需被保护的ProSe业务对应的安全策略。
  8. 如权利要求4所述的方法,其特征在于,所述基于所述安全策略与发起ProSe UE建立直连通信安全,包括:
    获取所述发起ProSe UE发送的直接通信请求Direct Communication Request消息,所述Direct Communication Request消息中包含所述发起ProSe UE的信令安全策略;
    确定所述发起ProSe UE的信令安全策略和所述接收ProSe UE的信令安全策略是否满足第一预设条件;
    所述第一预设条件包括以下的至少一种:
    所述发起ProSe UE的信令完整性保护的策略为NOT NEEDED,所述接收ProSe UE的信令完整性保护的策略为REQUIRED;
    所述发起ProSe UE的信令加密保护的策略为NOT NEEDED,所述接收ProSe UE的信令加密保护的策略为REQUIRED;
    所述发起ProSe UE的信令完整性保护的策略为REQUIRED,所述接收ProSe UE的信令完整性保护的策略为NOT NEEDED;
    所述发起ProSe UE的信令加密保护的策略为REQUIRED,所述接收ProSe UE的信令加密保护的策略为NOT NEEDED;
    当满足所述第一预设条件时,向所述发起ProSe UE发送第一拒绝消息,所述第一拒绝消息用于拒绝所述发起ProSe UE发送的Direct Communication Request消息。
  9. 如权利要求4所述的方法,其特征在于,所述基于所述安全策略与接收ProSe UE建立直连通信安全,包括:
    获取发起ProSe UE发送的Direct Communication Request消息,所述Direct Communication Request消息中包含所述发起ProSe UE的信令安全策略;
    确定所述发起ProSe UE的信令安全策略和所述接收ProSe UE的信令安全策略是否满足第一预设条件;
    所述第一预设条件包括以下的至少一种:
    所述发起ProSe UE的信令完整性保护的策略为NOT NEEDED,所述接收ProSe UE的信令完整性保护的策略为REQUIRED;
    所述发起ProSe UE的信令加密保护的策略为NOT NEEDED,所述接收ProSe UE的信令加密保护的策略为REQUIRED;
    所述发起ProSe UE的信令完整性保护的策略为REQUIRED,所述接收ProSe UE的信令完整性保护的策略为NOT NEEDED;
    所述发起ProSe UE的信令加密保护的策略为REQUIRED,所述接收ProSe UE的信令加密保护的策略为NOT NEEDED;
    当不满足所述第一预设条件时,基于所述发起ProSe UE的信令安全策略和所述接收ProSe UE的信令安全策略确定所述信令安全策略的协商结果;
    向所述发起ProSe UE发送直接安全模式命令Direct Security Mode Command消息,所述Direct Security Mode Command消息包括所述信令安全策略的协商结果。
  10. 如权利要求9所述的方法,其特征在于,所述信令安全策略的协商结果包括以下的至少一种:所述信令完整性保护的策略的协商结果;所述信令加密保护的策略的协商结果;
    所述基于所述发起ProSe UE的信令安全策略和所述接收ProSe UE的信令安全策略确定所述信令安全策略的协商结果,包括:
    当所述发起ProSe UE的信令完整性保护的策略为NOT NEEDED,和/或,所述接收ProSe UE的信令完整性保护的策略为NOT NEEDED时,确定所述信令完整性保护的策略的协商结果为NOT NEEDED;
    当所述发起ProSe UE的信令完整性保护的策略为REQUIRED,和/或,所述接收ProSe  UE的信令完整性保护的策略为REQUIRED时,确定所述信令完整性保护的策略的协商结果为REQUIRED;
    当所述发起ProSe UE的信令完整性保护的策略为PREFERRED,且所述接收ProSe UE的信令完整性保护的策略为PREFERRED时,确定所述信令完整性保护的策略的协商结果为REQUIRED或NOT NEEDED;
    当所述发起ProSe UE的信令加密保护的策略为NOT NEEDED,和/或,所述接收ProSe UE的信令加密保护的策略为NOT NEEDED时,确定所述信令加密保护的策略的协商结果为NOT NEEDED;
    当所述发起ProSe UE的信令加密保护的策略为REQUIRED,和/或,所述接收ProSe UE的信令加密保护的策略为REQUIRED时,确定所述信令加密保护的策略的协商结果为REQUIRED;
    当所述发起ProSe UE的信令加密保护的策略为PREFERRED,且所述接收ProSe UE的信令加密保护的策略为PREFERRED时,确定所述信令加密保护的策略的协商结果为REQUIRED或NOT NEEDED。
  11. 如权利要求9所述的方法,其特征在于,所述方法还包括:
    接收所述发起ProSe UE发送的第二拒绝消息,所述第二拒绝消息用于拒绝所述接收ProSe UE发送的Direct Security Mode Command消息。
  12. 如权利要求10所述的方法,其特征在于,所述方法还包括:
    当所述信令完整性保护的策略的协商结果为NOT NEEDED时,将所述接收ProSe UE的UP完整性保护的策略更改为NOT NEEDED;
    当所述信令加密保护的策略的协商结果为NOT NEEDED时,将所述接收ProSe UE的UP加密保护的策略更改为NOT NEEDED。
  13. 如权利要求12所述的方法,其特征在于,所述方法还包括:
    接收所述发起ProSe UE发送的直接安全模式完成Direct Security Mode Complete消息, 所述Direct Security Mode Complete消息中包含所述发起ProSe UE的UP安全策略;以及
    确定所述发起ProSe UE的UP安全策略和所述接收ProSe UE的UP安全策略是否满足第二预设条件;
    其中,所述第二预设条件包括以下的至少一种:
    所述发起ProSe UE的UP完整性保护的策略为NOT NEEDED,所述接收ProSe UE的UP完整性保护的策略为REQUIRED;
    所述发起ProSe UE的UP加密保护的策略为NOT NEEDED,所述接收ProSe UE的UP加密保护的策略为REQUIRED;
    所述发起ProSe UE的UP完整性保护的策略为REQUIRED,所述接收ProSe UE的UP完整性保护的策略为NOT NEEDED;
    所述发起ProSe UE的UP加密保护的策略为REQUIRED,所述接收ProSe UE的UP加密保护的策略为NOT NEEDED;
    当满足所述第二预设条件时,向所述发起ProSe UE发送第三拒绝消息,所述第三拒绝消息用于拒绝所述发起ProSe UE发送的Direct Security Mode Complete消息。
  14. 如权利要求12所述的方法,其特征在于,所述方法还包括:
    接收所述发起ProSe UE发送的Direct Security Mode Complete消息,所述Direct Security Mode Complete消息中包含所述发起ProSe UE的UP安全策略;以及
    确定所述发起ProSe UE的UP安全策略和所述接收ProSe UE的UP安全策略是否满足第二预设条件;
    所述第二预设条件包括以下的至少一种:
    所述发起ProSe UE的UP完整性保护的策略为NOT NEEDED,所述接收ProSe UE的UP完整性保护的策略为REQUIRED;
    所述发起ProSe UE的UP加密保护的策略为NOT NEEDED,所述接收ProSe UE的UP加密保护的策略为REQUIRED;
    所述发起ProSe UE的UP完整性保护的策略为REQUIRED,所述接收ProSe UE的UP完整性保护的策略为NOT NEEDED;
    所述发起ProSe UE的UP加密保护的策略为REQUIRED,所述接收ProSe UE的UP加密保护的策略为NOT NEEDED;
    当不满足所述第二预设条件时,基于所述发起ProSe UE的UP安全策略和所述接收ProSe UE的UP安全策略确定所述UP安全策略的协商结果;
    向所述发起ProSe UE发送直接通信接受Direct Communication Accept消息,所述Direct Communication Accept消息包括所述UP安全策略的协商结果。
  15. 如权利要求14所述的方法,其特征在于,所述UP安全策略的协商结果包括以下的至少一种:所述UP完整性保护的策略的协商结果;所述UP加密保护的策略的协商结果;
    所述基于所述发起ProSe UE的UP安全策略和所述接收ProSe UE的UP安全策略确定所述UP安全策略的协商结果,包括:
    当所述发起ProSe UE的UP完整性保护的策略为NOT NEEDED,和/或,所述接收ProSe UE的UP完整性保护的策略为NOT NEEDED时,确定所述UP完整性保护的策略的协商结果为NOT NEEDED;
    当所述发起ProSe UE的UP完整性保护的策略为REQUIRED,和/或,所述接收ProSe UE的UP完整性保护的策略为REQUIRED时,确定所述UP完整性保护的策略的协商结果为REQUIRED;
    当所述发起ProSe UE的UP完整性保护的策略为PREFERRED,且所述接收ProSe UE的UP完整性保护的策略为PREFERRED时,确定所述UP完整性保护的策略的协商结果为REQUIRED或NOT NEEDED;
    当所述发起ProSe UE的UP加密保护的策略为NOT NEEDED,和/或,所述接收ProSe UE的UP加密保护的策略为NOT NEEDED时,确定所述UP加密保护的策略的协商结果为NOT NEEDED;
    当所述发起ProSe UE的UP加密保护的策略为REQUIRED,和/或,所述接收ProSe UE的UP加密保护的策略为REQUIRED时,确定所述UP加密保护的策略的协商结果为REQUIRED;
    当所述发起ProSe UE的UP加密保护的策略为PREFERRED,且所述接收ProSe UE的UP加密保护的策略为PREFERRED时,确定所述UP加密保护的策略的协商结果为REQUIRED或NOT NEEDED。
  16. 如权利要求14所述的方法,其特征在于,所述方法还包括:
    基于所述信令安全策略的协商结果和所述UP安全策略的协商结果与所述发起ProSe UE进行直连通信保护。
  17. 一种直连通信方法,其特征在于,应用于发起ProSe UE,包括:
    获取ProSe业务对应的安全策略;
    基于所述安全策略与接收ProSe UE建立直连通信安全。
  18. 如权利要求17所述的方法,其特征在于,所述安全策略包括以下的至少一种:
    信令安全策略;
    UP安全策略。
  19. 如权利要求18所述的方法,其特征在于,所述安全策略包括以下的至少一种:
    信令完整性保护的策略;
    信令加密保护的策略;
    UP完整性保护的策略;
    UP加密保护的策略。
  20. 如权利要求19所述的方法,其特征在于,所述安全策略包括:REQUIRED;NOT NEEDED;PREFERRED。
  21. 如权利要求17-20任一所述的方法,其特征在于,所述获取ProSe业务对应的安全策略,包括:
    获取PCF发送的需保护的ProSe业务及所述需保护的ProSe业务对应的安全策略。
  22. 如权利要求17-20任一所述的方法,其特征在于,所述获取ProSe业务对应的安全策略,包括:
    获取ProSe应用服务器发送的需保护的ProSe业务及所述需保护的ProSe业务对应的安全策略。
  23. 如权利要求17-20任一所述的方法,其特征在于,所述获取ProSe业务对应的安全策略,包括:
    获取UICC上配置的需保护的ProSe业务及所述需保护的ProSe业务对应的安全策略。
  24. 如权利要求20所述的方法,其特征在于,所述基于所述安全策略与接收ProSe UE建立直连通信安全,包括:
    向所述接收ProSe UE发送Direct Communication Request消息,所述Direct Communication Request消息中包含所述发起ProSe UE的信令安全策略;
    获取所述接收ProSe UE发送的第一拒绝消息,所述第一拒绝消息用于拒绝所述发起ProSe UE发送的Direct Communication Request消息。
  25. 如权利要求20所述的方法,其特征在于,所述基于所述安全策略与接收ProSe UE建立直连通信安全,包括:
    向所述接收ProSe UE发送Direct Communication Request消息,所述Direct Communication Request消息中包含所述发起ProSe UE的信令安全策略;
    获取所述接收ProSe UE发送的Direct Security Mode Command消息,所述Direct Security Mode Command包括所述信令安全策略的协商结果。
  26. 如权利要求25所述的方法,其特征在于,所述方法还包括:
    判断所述接收ProSe UE的信令安全策略对应的安全算法与所述发起ProSe UE的信令 安全策略对应的安全算法是否一致;
    当不一致,向所述接收ProSe UE发送第二拒绝消息,所述第二拒绝消息用于拒绝所述接收ProSe UE发送的Direct Security Mode Command消息。
  27. 如权利要求25所述的方法,其特征在于,所述信令安全策略的协商结果包括以下的至少一种:所述信令完整性保护的策略的协商结果;所述信令加密保护的策略的协商结果;
    所述方法还包括:
    当所述信令完整性保护的策略的协商结果为NOT NEEDED,将所述发起ProSe UE的UP完整性保护的策略更改为NOT NEEDED;
    当所述信令加密保护的策略的协商结果为NOT NEEDED,将所述发起ProSe UE的UP加密保护的策略更改为NOT NEEDED。
  28. 如权利要求27所述的方法,其特征在于,所述方法还包括:
    向所述接收ProSe UE发送Direct Security Mode Complete消息,所述Direct Security Mode Complete消息中包含所述发起ProSe UE的UP安全策略;
    获取所述接收ProSe UE发送的第三拒绝消息,所述第三拒绝消息用于拒绝所述发起ProSe UE发送的Direct Security Mode Complete消息。
  29. 如权利要求27所述的方法,其特征在于,所述方法还包括:
    向所述接收ProSe UE发送Direct Security Mode Complete消息,所述Direct Security Mode Complete消息中包含所述发起ProSe UE的UP安全策略;
    获取所述接收ProSe UE发送的Direct Communication Accept消息,所述Direct Communication Accept消息包括所述UP安全策略的协商结果。
  30. 如权利要求29所述的方法,其特征在于,所述方法还包括:
    基于所述信令安全策略的协商结果和所述UP安全策略的协商结果与所述ProSe UE进 行直连通信。
  31. 一种直连通信装置,其特征在于,包括:
    获取模块,用于获取ProSe业务对应的安全策略;
    通信模块,用于基于所述安全策略与发起ProSe UE建立直连通信安全。
  32. 一种直连通信装置,其特征在于,包括:
    获取模块,用于获取ProSe业务对应的安全策略;
    通信模块,用于基于所述安全策略与接收ProSe UE建立直连通信安全。
  33. 一种用户设备,其特征在于,包括:收发器;存储器;处理器,分别与所述收发器及所述存储器连接,配置为通过执行所述存储器上的计算机可执行指令,控制所述收发器的无线信号收发,并能够实现权利要求1至30任一项所述的方法。
  34. 一种计算机存储介质,其中,所述计算机存储介质存储有计算机可执行指令;所述计算机可执行指令被处理器执行后,能够实现权利要求1至16或17至30任一项所述的方法。
PCT/CN2021/109087 2021-07-28 2021-07-28 一种直连通信方法、装置、用户设备及存储介质 WO2023004656A1 (zh)

Priority Applications (3)

Application Number Priority Date Filing Date Title
CN202180002265.3A CN115885533A (zh) 2021-07-28 2021-07-28 一种直连通信方法、装置、用户设备及存储介质
EP21951268.8A EP4380294A1 (en) 2021-07-28 2021-07-28 Direct communication method and apparatus, user equipment, and storage medium
PCT/CN2021/109087 WO2023004656A1 (zh) 2021-07-28 2021-07-28 一种直连通信方法、装置、用户设备及存储介质

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2021/109087 WO2023004656A1 (zh) 2021-07-28 2021-07-28 一种直连通信方法、装置、用户设备及存储介质

Publications (1)

Publication Number Publication Date
WO2023004656A1 true WO2023004656A1 (zh) 2023-02-02

Family

ID=85086006

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/109087 WO2023004656A1 (zh) 2021-07-28 2021-07-28 一种直连通信方法、装置、用户设备及存储介质

Country Status (3)

Country Link
EP (1) EP4380294A1 (zh)
CN (1) CN115885533A (zh)
WO (1) WO2023004656A1 (zh)

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105264816A (zh) * 2013-05-16 2016-01-20 三星电子株式会社 执行用于设备对设备通信的发现的方法和装置
US20180375647A1 (en) * 2015-12-22 2018-12-27 Nokia Technologies Oy Flexible security channel establishment in d2d communications

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105264816A (zh) * 2013-05-16 2016-01-20 三星电子株式会社 执行用于设备对设备通信的发现的方法和装置
US20180375647A1 (en) * 2015-12-22 2018-12-27 Nokia Technologies Oy Flexible security channel establishment in d2d communications

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
"3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of 3GPP support for advanced Vehicle-to-Everything (V2X) services (Release 16)", 3GPP STANDARD; TECHNICAL SPECIFICATION; 3GPP TR 33.836, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, no. V16.1.0, 25 September 2020 (2020-09-25), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , pages 1 - 51, XP051961170 *
QUALCOMM INCORPORATED: "Proposed text for security establishment clause of NR PC5 unicast security", 3GPP DRAFT; S3-200347, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), MOBILE COMPETENCE CENTRE ; 650, ROUTE DES LUCIOLES ; F-06921 SOPHIA-ANTIPOLIS CEDEX ; FRANCE, vol. SA WG3, no. e-meeting; 20200302 - 20200306, 21 February 2020 (2020-02-21), Mobile Competence Centre ; 650, route des Lucioles ; F-06921 Sophia-Antipolis Cedex ; France , XP051855082 *

Also Published As

Publication number Publication date
EP4380294A1 (en) 2024-06-05
CN115885533A (zh) 2023-03-31

Similar Documents

Publication Publication Date Title
WO2018129940A1 (zh) 用户设备的状态控制方法、装置、用户设备和基站
US20220295590A1 (en) Inactivity timer control method and device
US11805562B2 (en) User device pairing method and apparatus
WO2021081796A1 (zh) 寻呼信令接收方法和装置、寻呼信令发送方法和装置
WO2023004656A1 (zh) 一种直连通信方法、装置、用户设备及存储介质
CN113170474B (zh) 资源配置方法、装置、终端设备、接入网设备及存储介质
WO2023245354A1 (zh) 安全保护方法、装置、通信设备及存储介质
WO2023004655A1 (zh) 一种通信方法、装置、用户设备、基站、核心网设备及存储介质
WO2024055329A1 (zh) 邻近服务ProSe的无线通信方法、装置、通信设备及存储介质
WO2019153236A1 (zh) 将终端与待接入的核心网建立连接的的方法、装置和系统
WO2022236627A1 (zh) 指示方法、装置、用户设备、基站、核心网设备及存储介质
WO2022222086A1 (zh) 信息传输方法、装置、用户设备、接入网设备、核心网及存储介质
WO2023070685A1 (zh) 中继通信的方法、装置、通信设备及存储介质
WO2022165633A1 (zh) 用户寻呼分组的确定方法、装置、用户设备及存储介质
WO2023220893A1 (zh) 中继通信方法、装置、通信设备及存储介质
WO2023070560A1 (zh) 信息传输方法、装置、通信设备和存储介质
WO2024031390A1 (zh) 个人物联网信息更新方法、装置、通信设备及存储介质
WO2018184170A1 (zh) 实现物联网设备引导的方法、装置、设备及基站
WO2023070509A1 (zh) 信息处理方法及装置、通信设备及存储介质
US20230254758A1 (en) Access control method and communication device, and storage medium
WO2022257144A1 (zh) 信息配置方法、装置、用户设备、基站及存储介质
WO2024016349A1 (zh) 提供感知服务的方法、装置、通信设备及存储介质
WO2024044916A1 (zh) 上报bsr的方法、装置、通信设备及存储介质
WO2024036495A1 (zh) 信息处理方法及装置、通信设备及存储介质
WO2023141771A1 (zh) 提供感知服务的方法、装置、通信设备及存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21951268

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2021951268

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2021951268

Country of ref document: EP

Effective date: 20240228