WO2025010609A1 - 通信处理方法、用户设备 - Google Patents

通信处理方法、用户设备 Download PDF

Info

Publication number
WO2025010609A1
WO2025010609A1 PCT/CN2023/106667 CN2023106667W WO2025010609A1 WO 2025010609 A1 WO2025010609 A1 WO 2025010609A1 CN 2023106667 W CN2023106667 W CN 2023106667W WO 2025010609 A1 WO2025010609 A1 WO 2025010609A1
Authority
WO
WIPO (PCT)
Prior art keywords
message
information
user equipment
verified
communication
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2023/106667
Other languages
English (en)
French (fr)
Inventor
陆伟
商正仪
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Xiaomi Mobile Software Co Ltd
Original Assignee
Beijing Xiaomi Mobile Software Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Xiaomi Mobile Software Co Ltd filed Critical Beijing Xiaomi Mobile Software Co Ltd
Priority to CN202380010065.1A priority Critical patent/CN117397209A/zh
Priority to PCT/CN2023/106667 priority patent/WO2025010609A1/zh
Publication of WO2025010609A1 publication Critical patent/WO2025010609A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols

Definitions

  • the present disclosure relates to the field of communication technology, and in particular to a communication processing method and a user equipment.
  • a terminal with vehicle-to-everything (V2X) capability often sends a request message containing V2X service information to establish a communication connection with a target terminal during the process of discovering and selecting a ranging/sidelink (SL) positioning terminal.
  • V2X vehicle-to-everything
  • the method disclosed in the present invention can be used to solve the technical problem that "the information in the request message is tampered with by an attacker, causing the subsequent process (such as ranging/SL positioning control) to fail or cause unexpected results.”
  • the embodiments of the present disclosure provide a communication processing method and a user equipment.
  • a communication processing method which is executed by a first user equipment and includes:
  • the second message includes information to be verified, and the information to be verified includes at least a portion of the unprotected content information
  • a fourth message sent by the second user equipment is received.
  • a communication processing method is proposed, which is executed by a second user equipment, including:
  • a fourth message is sent to the first user equipment according to the third message.
  • a first user equipment including:
  • a transceiver module configured to send a first message to a second user equipment, wherein the first message includes unprotected content information
  • the transceiver module is further configured to receive a second message sent by the second user equipment, wherein the second message includes information to be verified, and the information to be verified includes at least a portion of the unprotected content information;
  • a processing module used for verifying the information to be verified
  • the transceiver module is used to send a third message to the second user equipment, wherein the third message is used to indicate a verification result of the information to be verified;
  • the transceiver module is further used to receive a fourth message sent by the second user equipment.
  • a second user equipment including:
  • a transceiver module configured to receive a first message sent by a first user equipment, wherein the first message includes unprotected content information
  • the transceiver module is further configured to send a second message to the first user equipment, wherein the second message includes information to be verified, and the information to be verified includes at least a portion of the unprotected content information;
  • the transceiver module is further configured to receive a third message sent by the first user equipment, wherein the third message indicates a verification result of the information to be verified;
  • the transceiver module is further configured to send a fourth message to the first user equipment according to the third message.
  • a communication device including:
  • One or more processors are One or more processors;
  • the processor is used to call instructions so that the communication device executes the method described in any one of the first aspect and the second aspect.
  • a communication system including:
  • a first user equipment used to implement the communication processing method described in the first aspect
  • the second user equipment is used to implement the communication processing method described in the second aspect.
  • a storage medium stores instructions.
  • the instructions When the instructions are transmitted in a communication
  • the communication device When running on a device, the communication device is enabled to execute the communication processing method as described in any one of the first aspect and the second aspect.
  • the second user device that receives the first message can return a portion of the unprotected content information contained in the first message to the first user device, and the first user device verifies the returned information, thereby verifying the integrity of the unprotected content information received by the second user device, preventing the information in the first message received by the second user device from being tampered with, and further establishing a secure connection between the user devices.
  • FIG1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.
  • FIG2 is an interactive schematic diagram of a communication processing method according to an embodiment of the present disclosure
  • 3A-3B are flowchart diagrams of a communication processing method according to an embodiment of the present disclosure.
  • 4A-4B are flowchart diagrams of a communication processing method according to an embodiment of the present disclosure.
  • FIG5 is an interactive schematic diagram of a communication processing method according to an embodiment of the present disclosure.
  • FIG6A is a schematic diagram of the structure of a first user equipment proposed in an embodiment of the present disclosure.
  • FIG6B is a schematic diagram of the structure of a second user equipment proposed in an embodiment of the present disclosure.
  • FIG7A is a schematic diagram of the structure of a communication device provided in an embodiment of the present disclosure.
  • FIG. 7B is a schematic diagram of the structure of a chip proposed in an embodiment of the present disclosure.
  • the embodiments of the present disclosure provide a communication processing method and a user equipment.
  • an embodiment of the present disclosure provides a method for processing information, the method being executed by a first user equipment, including:
  • the second message includes information to be verified, and the information to be verified includes at least a portion of the unprotected content information
  • a fourth message sent by the second user equipment is received.
  • the second user device that receives the first message can return a part of the unprotected content information contained in the first message to the first user device, and the first user device verifies the returned information, thereby verifying the integrity of the unprotected content information received by the second user device, preventing the information in the received first message from being tampered with, and then a secure connection can be established between the user devices.
  • the first message is a direct communication request DCR message.
  • the unprotected content information is carried in the DCR message, which can reduce the overhead of communication resources.
  • the unprotected content information includes first information and second information of the first message, and the second information is security protection-related information.
  • the unprotected content information is divided into first information that can be used for verification and second information related to security protection, so that a part of the first information that can be used for verification can be carried in the second message, thereby saving the signaling overhead of transmitting the information to be verified and improving the verification efficiency.
  • the second message is a DSMC message.
  • the unprotected content information is divided into first information that can be used for verification and second information related to security protection, so that a part of the first information that can be used for verification can be carried in the second message, thereby saving the signaling overhead of transmitting the information to be verified and improving the verification efficiency.
  • verifying the information to be verified includes:
  • the information to be verified is verified according to the first information.
  • the information to be verified includes at least a portion of the first information
  • directly verifying the information to be verified based on the first information can improve verification efficiency.
  • the verification result is verification passed, and the third message is a direct security mode completion message; or, the verification result is verification failed, and the third message is a direct security mode rejection message.
  • the third message is determined according to the verification result of the information to be verified, so that the second user equipment can be accurately notified of the verification result of the information to be verified.
  • the direct communication connection when the fourth message is a direct communication acceptance message, the direct communication connection is successfully established; or, when the fourth message is a direct communication rejection message, the direct communication connection fails to be established.
  • the direct communication connection establishment result is indicated by the direct communication acceptance message and the direct communication rejection message, so that the communication resource overhead can be reduced.
  • the first information includes at least one of the following:
  • the second information includes at least one of PC5 security policy information of the first user device and security capability of the first user device.
  • an embodiment of the present disclosure provides a communication processing method, which is executed by a second user equipment, and the method includes:
  • a fourth message is sent to the first user equipment according to the third message.
  • the second user device that receives the first message can return a part of the unprotected content information contained in the first message to the first user device, and the first user device verifies the returned information, thereby verifying the integrity of the unprotected content information received by the second user device, preventing the information in the received first message from being tampered with, and then a secure connection can be established between the user devices.
  • the first message is a direct communication request DCR message.
  • the unprotected content information is carried in the DCR message, which can reduce the overhead of communication resources.
  • the unprotected content information includes first information and second information, and the second information is information related to security protection.
  • the unprotected content information is divided into first information that can be used for verification and second information related to security protection, so that a part of the first information that can be used for verification can be carried in the second message, thereby saving the signaling overhead of transmitting the information to be verified and improving the verification efficiency.
  • the second message is a direct safety mode command DSMC message.
  • the information to be verified is carried in the DSMC message, which can reduce the overhead of communication resources.
  • the verification result is verification passed, and the third message is a direct security mode completion message.
  • the verification result is verification failed, and the third message is a direct security mode rejection message.
  • different verification results can be indicated by a direct security mode completion message and a direct security mode rejection message, so that the second user equipment can accurately determine the verification result through different messages and reduce the overhead of communication resources.
  • the fourth message when the third message is a direct safety mode completion message, the fourth message is a direct communication acceptance message.
  • the third message is a direct safety mode rejection message, and the fourth message is a direct communication rejection message.
  • the fourth message may be sent to the first user equipment according to the third message, so that the sent fourth message may match the verification result, and then the two user equipments may accurately establish a communication connection.
  • the first information includes at least one of the following:
  • the second information includes at least one of PC5 security policy information of the first user device and security capabilities of the first user device.
  • an embodiment of the present disclosure provides a first user equipment, wherein the first user equipment includes at least one of a transceiver module and a processing module; wherein:
  • a transceiver module configured to send a first message to a second user equipment, wherein the first message includes unprotected content information
  • the transceiver module is further configured to receive a second message sent by the second user equipment, wherein the second message includes information to be verified, and the information to be verified includes at least a portion of the unprotected content information;
  • a processing module used for verifying the information to be verified
  • the transceiver module is used to send a third message to the second user equipment, wherein the third message is used to indicate a verification result of the information to be verified;
  • the transceiver module is further used to receive a fourth message sent by the second user equipment.
  • the first message is a direct communication request DCR message.
  • the unprotected content information includes first information and second information of the first message, and the second information is information related to security protection.
  • the second message is a DSMC message.
  • the processing module is used to:
  • the information to be verified is verified according to the first information.
  • the verification result is verification passed, and the third message is a direct security mode completion message; or, the verification result is verification failed, and the third message is a direct security mode rejection message.
  • the direct communication connection when the fourth message is a direct communication acceptance message, the direct communication connection is successfully established; or, when the fourth message is a direct communication rejection message, the direct communication connection fails to be established.
  • the first information includes at least one of the following:
  • the second information includes at least one of PC5 security policy information of the first user device and security capability of the first user device.
  • an embodiment of the present disclosure provides a second user equipment, wherein the second user equipment includes at least one of a transceiver module and a processing module; wherein:
  • a transceiver module configured to receive a first message sent by a first user equipment, wherein the first message includes unprotected content information
  • the transceiver module is further configured to send a second message to the first user equipment, wherein the second message includes information to be verified, and the information to be verified includes at least a portion of the unprotected content information;
  • the transceiver module is further configured to receive a third message sent by the first user equipment, wherein the third message indicates a verification result of the information to be verified;
  • the transceiver module is further configured to send a fourth message to the first user equipment according to the third message.
  • the first message is a direct communication request DCR message.
  • the unprotected content information includes first information and second information, and the second information is information related to security protection.
  • the second message is a direct safety mode command DSMC message.
  • the verification result is verification passed, and the third message is direct installation.
  • a full mode completion message; or, the verification result is that the verification failed, and the third message is a direct security mode rejection message.
  • the third message is a direct security mode completion message, and the fourth message is a direct communication acceptance message; or, the third message is a direct security mode rejection message, and the fourth message is a direct communication rejection message.
  • the first information includes at least one of the following:
  • the second information includes at least one of PC5 security policy information of the first user device and security capabilities of the first user device.
  • an embodiment of the present disclosure proposes a communication device, which includes: one or more processors; wherein the communication device is used to execute the first aspect and the optional implementation method of the first aspect.
  • an embodiment of the present disclosure proposes a communication device, wherein the communication device includes: one or more processors; wherein the communication device is used to execute the second aspect and the optional implementation method of the second aspect.
  • an embodiment of the present disclosure provides a communication system, wherein the communication system includes:
  • a first user equipment configured to implement the method as described in the first aspect and the optional implementation manner of the first aspect;
  • the second user equipment is used to implement the method described in the second aspect and the optional implementation manner of the second aspect.
  • an embodiment of the present disclosure proposes a storage medium, wherein the storage medium stores instructions.
  • the communication device executes the method described in the first aspect and the optional implementation of the first aspect, or executes the method described in the second aspect and the optional implementation of the second aspect.
  • an embodiment of the present disclosure proposes a program product.
  • the communication device executes the method described in the first aspect and the optional implementation of the first aspect, or executes the method described in the second aspect and the optional implementation of the second aspect.
  • an embodiment of the present disclosure proposes a computer program, which, when executed on a computer, enables the computer to execute the method described in the first aspect and the optional implementation of the first aspect, or execute the method described in the second aspect and the optional implementation of the second aspect.
  • an embodiment of the present disclosure provides a chip or a chip system.
  • the chip or chip system includes a processing circuit configured to execute the method described in the first aspect and the optional implementation of the first aspect, or to execute the method described in the second aspect and the optional implementation of the second aspect.
  • the embodiments of the present disclosure provide a communication processing method and a user device.
  • the terms such as communication processing method, information processing method, and communication method can be interchangeable, the terms such as information transmission device, information processing device, and communication device can be interchangeable, and the terms such as information processing system and communication system can be interchangeable.
  • each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined.
  • a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged.
  • the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined, for example, some or all of the steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
  • elements expressed in the singular form can mean “one and only one", or “one or more”, “at least one”, etc.
  • the noun after the article can be understood as a singular expression. It can also be understood as a plural expression.
  • plurality refers to two or more.
  • the terms "at least one of”, “one or more”, “a plurality of”, “multiple”, etc. can be used interchangeably.
  • "at least one of A and B", “A and/or B", “A in one case, B in another case”, “in response to one case A, in response to another case B”, etc. may include the following technical solutions according to the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). When there are more branches such as A, B, C, etc., the above is also similar.
  • the recording method of "A or B” may include the following technical solutions according to the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed).
  • A A is executed independently of B
  • B B is executed independently of A
  • execution is selected from A and B (A and B are selectively executed).
  • prefixes such as “first” and “second” in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute restrictions on the position, order, priority, quantity or content of the description objects.
  • the statement of the description object refers to the description in the context of the claims or embodiments, and should not constitute unnecessary restrictions due to the use of prefixes.
  • the description object is a "field”
  • the ordinal number before the "field” in the "first field” and the "second field” does not limit the position or order between the "fields”
  • the "first” and “second” do not limit whether the "fields” they modify are in the same message, nor do they limit the order of the "first field” and the "second field”.
  • the description object is a "level”
  • the ordinal number before the "level” in the “first level” and the “second level” does not limit the priority between the "levels”.
  • the number of description objects is not limited by the ordinal number, and can be one or more. Taking the "first device” as an example, the number of "devices” can be one or more.
  • the objects modified by different prefixes may be the same or different. For example, if the description object is "device”, then the “first device” and the “second device” may be the same device or different devices, and their types may be the same or different. For another example, if the description object is "information”, then the "first information” and the “second information” may be the same information or different information, and their contents may be the same or different.
  • “including A”, “comprising A”, “used to indicate A”, and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
  • devices, etc. can be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments.
  • Terms such as “device”, “equipment”, “device”, “circuit”, “network element”, “node”, “function”, “unit”, “section”, “system”, “network”, “chip”, “chip system”, “entity”, and “subject” can be used interchangeably.
  • terminal In some embodiments, the terms "terminal”, “terminal device”, “user equipment (UE)”, “user terminal” “mobile station (MS)”, “mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client and the like can be used interchangeably.
  • the access network device, the core network device, or the network device may be replaced with a terminal.
  • the various embodiments of the present disclosure may be applied to a structure in which the communication between an access network device, a core network device, or a network device and a terminal is replaced by a communication between multiple terminals (for example, it may also be referred to as a device-to-device (D2D), a vehicle-to-everything (V2X), etc.). In this case, it may also be a structure in which the terminal has all or part of the functions of the access network device.
  • the language such as "uplink” and "downlink” may also be replaced by a language corresponding to the communication between terminals (for example, "side”). For example, an uplink channel, a downlink channel, etc. may be replaced by a side channel, and an uplink, a downlink, etc. may be replaced by a side link.
  • the terminal may be replaced by an access network device, a core network device, or a network device.
  • the access network device, the core network device, or the network device may also be configured to have a structure that has all or part of the functions of the terminal.
  • acquisition of data, information, etc. may comply with the laws and regulations of the country where the data is obtained.
  • data, information, etc. may be obtained with the user's consent.
  • FIG1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.
  • the communication system 100 may include a first user equipment (terminal) 101 and a second user equipment 102.
  • a communication connection may be established between the first user equipment 101 and the second user equipment 102.
  • SL communication may be performed between the first user equipment 101 and the second user equipment 102.
  • the communication system 100 may also include a network device, which may include at least one of an access network device and a core network device.
  • the first user device 101 or the second user device 102 includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control (industrial control), a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid (smart grid), a wireless terminal device in transportation safety (transportation safety), a wireless terminal device in a smart city (smart city), and at least one of a wireless terminal device in a smart home (smart home), but is not limited to these.
  • a mobile phone a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (
  • the access network device is, for example, a node or device that accesses a terminal to a wireless network.
  • the access network device may include an evolved Node B (eNB), a next generation evolved Node B (ng-eNB), a next generation Node B (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a WiFi system, but is not limited thereto.
  • eNB evolved Node B
  • ng-eNB next generation evolved Node B
  • gNB next generation Node B
  • NB node B
  • the technical solution of the present disclosure may be applicable to the Open RAN architecture.
  • the interfaces between access network devices or within access network devices involved in the embodiments of the present disclosure may become internal interfaces of Open RAN, and the processes and information interactions between these internal interfaces may be implemented through software or programs.
  • the access network device may be composed of a centralized unit (central unit, CU) and a distributed unit (distributed unit, DU), wherein the CU may also be called a control unit (control unit).
  • the CU-DU structure may be used to split the protocol layer of the access network device, with some functions of the protocol layer being centrally controlled by the CU, and the remaining part or all of the functions of the protocol layer being distributed in the DU, and the DU being centrally controlled by the CU, but not limited to this.
  • the core network device may be a device including one or more network elements, or may be multiple devices or device groups, each including all or part of one or more network elements.
  • the network element may be virtual or physical.
  • the core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).
  • EPC Evolved Packet Core
  • 5GCN 5G Core Network
  • NGC Next Generation Core
  • the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution proposed in the embodiment of the present disclosure.
  • a person of ordinary skill in the art can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution proposed in the embodiment of the present disclosure is also applicable to similar technical problems.
  • the following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1 , or part of the subject, but are not limited thereto.
  • the subjects shown in FIG1 are examples, and the communication system may include all or part of the subjects in FIG1 , or may include other subjects other than FIG1 , and the number and form of the subjects are arbitrary, and the connection relationship between the subjects is an example, and the subjects may be connected or disconnected, and the connection may be in any manner, which may be a direct connection or an indirect connection, and may be a wired connection or a wireless connection.
  • LTE Long Term Evolution
  • LTE-A LTE-Advanced
  • LTE-B LTE-Beyond
  • SUPER 3G IMT-Advanced
  • 4G the fourth generation mobile communication system
  • 5G 5G new radio
  • FAA Future Radio Access
  • RAT New Radio
  • NR New Radio
  • NX New radio access
  • the present invention relates to wireless communication systems such as LTE, Wi-Fi (X), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) network, Device to Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle to Everything (V2X), systems using other communication methods, and next-generation systems expanded based on them.
  • PLMN Public Land Mobile Network
  • D2D Device to Device
  • M2M Machine to Machine
  • IoT Internet of Things
  • V2X Vehicle to Everything
  • systems using other communication methods and next-generation systems expanded based on them.
  • next-generation systems expanded based on them.
  • a combination of multiple systems for example, a combination of
  • the ranging/SL positioning UE discovery and selection process of the UE with V2X capability, or sending a direct communication request (DCR) message includes V2X service information indicating "ranging/sidelink positioning", source user information (e.g., application layer ID of the source UE, serving public land mobile network (Public Land Mobile Network, PLMN) of the source UE), target user information (e.g., application layer ID of the target UE), ranging and sidelink positioning protocol (ranging and sidelink positioning protocol, RSPP) metadata information, application layer group ID, etc. All of this information is critical to the success of ranging/SL positioning communication. If any information (e.g., source user information, target user information, RSPP metadata including UE role) is tampered with by an attacker, subsequent processes (e.g., ranging/SL positioning control) will fail or lead to unexpected consequences.
  • V2X service information indicating "ranging/sidelink positioning”
  • source user information e.g., application layer ID of the source UE, serving public land mobile network (Public Land
  • the DCR messages constructed by the network layer of the UE are not protected by the UE at the network layer, that is, the integrity of the DCR message is not protected by the UE at the network layer, making it impossible for the V2X UE that receives the DCR message to verify whether the information in the received DCR message has been tampered with.
  • FIG2 is an interactive schematic diagram of a communication processing method according to an embodiment of the present disclosure. As shown in FIG2 , the present disclosure embodiment relates to a communication processing method, which is used in a communication system 100, and the method includes:
  • Step S2101 A first user equipment sends a first message to a second user equipment.
  • the first message includes unprotected content information.
  • unprotected content information is information for which protection is to be applied.
  • the unprotected content information may include first information and second information, where the second information is information related to security protection.
  • the first information includes at least one of the following:
  • the RSPP metadata may be data used for RSPP control operations on the short range direct communication interface (PC5).
  • the target user information may be an application layer ID of the target UE, etc. This disclosure does not limit this.
  • the source user information may be an application layer ID of the source UE, a serving PLMN of the source UE, etc. This disclosure does not limit this.
  • the group identifier (Identity document, ID) can be an application layer group ID.
  • the service information may be specific information of a service that the first user equipment wants to implement, for example, the service may be a ranging/SL positioning related service.
  • the second information may include at least one of PC5 security policy information of the first user device and security capability information of the first user device.
  • the PC5 security policy information of the first user device may be security-related information for protecting the PC5 of the first user device.
  • the first user equipment security capability information may be information related to the security capability of the first user equipment, such as the security algorithms it supports.
  • the first message may further include authentication information.
  • the authentication information may include information required for authentication and security establishment between the first user equipment and the second user equipment.
  • the authentication information may include at least one of a key, a random number, and key establishment information key_Est_info.
  • the key is a set of parameters or codes used in the encryption and decryption process to encrypt and decrypt information.
  • the key is usually a long string or number (such as 128 bits or 256 bits) generated by a random number generator. Or it is a set of unique numbers or codes assigned by the first user device and the second user device after negotiation.
  • the random number may be a set of seemingly random numbers or characters generated by a random number generator, the generation process of which is not subject to human interference or control, and the result of each generation is different. Random numbers can be used to generate encryption keys or ensure the security of one-time passwords in communications.
  • the key establishment information key_Est_info may be related information for indicating the creation of keys required for authentication and security establishment between terminals.
  • terms such as “certain”, “preset”, “preset”, “set”, “indicated”, “some”, “arbitrary”, “any”, “first”, etc. can be interchangeable, and "specific A”, “preset A”, “preset A”, “set A”, “indicated A”, “some A”, “any A”, “any A”, “first A” can be interpreted as A pre-defined in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., and can also be interpreted as specific A, some A, arbitrary A, any A or first A, etc., but not limited to this.
  • obtain can be interchangeable, and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from high levels, obtaining by self-processing, autonomous implementation, etc.
  • the names of information, etc. are not limited to the names recorded in the embodiments, and terms such as “information”, “message”, “signal”, “signaling”, “report”, “configuration”, “indication”, “instruction”, “command”, and “parameter” can be used interchangeably.
  • Step S2102 The second user equipment establishes security authentication with the first user equipment according to the authentication information in the first message.
  • the second user equipment may parse the first message to obtain authentication information contained in the first message, and then establish security authentication with the first user equipment based on the authentication information.
  • the second user equipment may use the information exchanged in Key_Est_Info to initiate a direct authentication and key establishment procedure with the first user equipment for mutual authentication between UEs.
  • Step S2103 The second user equipment sends a second message to the first user equipment.
  • the second message includes information to be verified, and the information to be verified includes at least a portion of unprotected content information in the first message.
  • the second message may be a Direct Security Mode Command (DSMC) message.
  • DSMC Direct Security Mode Command
  • the DSMC message may be a message sent by the second user equipment to the first user equipment for requesting to establish a communication connection with the first user equipment.
  • the second message may be a direct safety mode command DSMC message, or may be other messages, which is not limited in the present disclosure.
  • the information to be verified may be information whose security is to be verified by the first user equipment.
  • the information to be verified may include at least a portion of the first information.
  • the information to be verified may include one or more of ranging and sidelink positioning protocol RSPP metadata, target user information, source user information, group ID, and service information.
  • an intermediate key between the first user device and the second user device may be generated based on the authentication information, and then a security context may be generated using a random number and the intermediate key to perform integrity protection on the second message through the security context.
  • an intermediate key can be derived based on a random number in the authentication information through a key derivation function (KDF).
  • KDF key derivation function
  • the second message also includes the encryption algorithm and key derivation information used by the second user equipment.
  • the encryption algorithm may be a symmetric key encryption algorithm, such as a Data Encryption Standard (DES) algorithm, an Advanced Encryption Standard (AES) algorithm, etc. It may also be an asymmetric key encryption algorithm, such as a Digital Signature Algorithm (DSA), etc. This disclosure does not limit this.
  • DES Data Encryption Standard
  • AES Advanced Encryption Standard
  • DSA Digital Signature Algorithm
  • the key derivation information may include a random number used by the first user equipment for key derivation, etc.
  • Step S2104 The first user equipment verifies the information to be verified in the second message.
  • the first user equipment may verify the information to be verified using the unprotected content information included in the first message.
  • the unprotected content information may be matched with the information to be verified. If the unprotected content information contains information that matches the information to be verified, the information to be verified passes verification. If any information in the information to be verified does not match the information in the unprotected content information, the information to be verified fails verification.
  • the first user equipment may also use the first information to verify the information to be verified.
  • the first information may be matched with the information to be verified. If the first information contains information that matches the information to be verified, the information to be verified is verified successfully. If any information in the information to be verified does not match the information in the first information, the information to be verified is not verified successfully.
  • the first user equipment may first verify the integrity of the second message, and then verify the information to be verified if the integrity of the second message passes the verification.
  • a security context may be generated using a random number and an intermediate key, and the integrity of the second message may be verified using the security context.
  • the second message may further include an encryption algorithm and key derivation information, so that the first user equipment may also parse the second message according to the encryption algorithm and key derivation information to obtain the information to be verified.
  • Step S2105 The first user equipment sends a third message to the second user equipment.
  • the third message indicates a verification result of the information to be verified.
  • the first user equipment may send a third message to the second user equipment according to the verification result of the information to be verified.
  • the third message is used to indicate that the verification result is passed. If the verification result is that the verification is not passed, the third message is used to indicate that the verification result is not passed.
  • the verification result is verification passed
  • the third message is a direct security mode completion message. That is, in the case of verification passed, the first user equipment can send a direct security mode completion message to the second user equipment.
  • the verification result is that the verification fails, and the third message is a direct safety mode rejection message. That is, in the case of verification failure, the first user equipment can send a direct safety mode rejection message to the second user equipment.
  • the first user equipment may generate a security context using the generated intermediate key and the key derivation information included in the second message, and perform security protection on the third message based on the security context.
  • Step S2106 The second user equipment sends a fourth message to the first user equipment according to the third message.
  • the fourth message is a direct communication acceptance message, that is, when the second user equipment receives the direct safety mode completion message, it sends a direct communication acceptance message to the first user equipment.
  • the fourth message is a direct communication rejection message, that is, when the second user equipment receives the direct safety mode rejection message, it sends a direct communication rejection message to the first user equipment.
  • a fourth message is sent to the first user equipment according to the verification result indicated by the third message.
  • the fourth message is determined to be a direct communication acceptance message, that is, the direct communication acceptance message is sent to a user equipment.
  • the fourth message is determined to be a direct communication rejection message, that is, when the verification result indicated by the third message is failure to pass the verification, the second user equipment sends a direct communication rejection message to the first user equipment.
  • the fourth message is a direct communication acceptance message
  • the direct communication connection is established successfully
  • the second user equipment may send a direct communication acceptance message to the first user equipment to inform the first user equipment that the communication connection is successfully established.
  • the fourth message is a direct communication rejection message
  • the establishment of the direct communication connection fails, that is, the second user equipment may send a direct communication rejection message to the first user equipment to tell the first user equipment to reject the establishment of the communication connection.
  • the second user device when the second user device receives the direct security mode completion message sent by the first user device, the second user device can determine that the information to be verified received and returned to the first user device is the real information in the first message and has not been tampered with. And the security connection between the first user device and the second user device has been established.
  • the second user device can send a security-protected direct communication acceptance message to the first user device.
  • the communication method involved in the embodiments of the present disclosure may include at least one of steps S2101 to S2106.
  • step S2103 may be implemented as an independent embodiment
  • step S2104 may be implemented as an independent embodiment
  • steps S2103+S2104 may be implemented as an independent embodiment
  • steps S2101+S2102+S2103+S2104+S2105 may be implemented as an independent embodiment, but are not limited thereto.
  • steps S2101, S2102, S2103, S2104, and S2106 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
  • steps S2101, S2103, S2104, S2105, and S2106 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
  • each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other implementation modes or other examples.
  • FIG3A is a flow chart of a communication processing method according to an embodiment of the present disclosure. As shown in FIG3A , the present disclosure embodiment relates to a communication processing method, which is used for a first user device 101, and the method includes:
  • Step S3101 sending the first message.
  • step S3101 can refer to step S2101 in FIG. 2 , and other related parts in the embodiments involved in FIG. 2 and FIG. 3A , which will not be described in detail here.
  • the first user equipment 101 may send the first message to the second user equipment 102.
  • the present invention is not limited thereto, and the first message may also be sent to other user equipments, for example, by broadcasting the first message.
  • the first message includes unprotected content information.
  • Step S3102 Establish security authentication with the second user equipment.
  • step S3102 can refer to step S2102 of FIG. 2 and other related parts of the embodiment involved in FIG. 2 , which will not be described in detail here.
  • the second user equipment 102 may be a user equipment that receives the first message sent by the first user equipment 102 .
  • Step S3103 obtain the second message.
  • step S3103 can refer to step S2103 of FIG. 2 and other related parts of the embodiment involved in FIG. 2 , which will not be described in detail here.
  • the second message includes information to be verified, and the information to be verified includes at least a portion of the unprotected content information in the first message.
  • the first user equipment 101 receives the second message sent by the second user equipment 102.
  • this is not limited thereto, and the second message sent by other user equipment may also be received.
  • Step S3104 verify the information to be verified contained in the second message.
  • step S3104 can refer to step S2104 of FIG. 2 and other related parts of the embodiment involved in FIG. 2 , which will not be described in detail here.
  • Step S3105 Send a third message to the second user equipment.
  • step S3105 can refer to step S2105 of FIG. 2 and other related parts of the embodiment involved in FIG. 2 , which will not be described in detail here.
  • Step S3106 obtain the fourth message.
  • step S3106 can refer to step S2106 of FIG. 2 and other related parts of the embodiment involved in FIG. 2 , which will not be described in detail here.
  • the first user equipment 101 receives the second message sent by the second user equipment 102.
  • this is not limited thereto, and the second message sent by other user equipment may also be received.
  • the method involved in the embodiment of the present disclosure may include at least one of steps S3101 to S3106.
  • steps S3101+S3103+S3104 may be implemented as an independent embodiment
  • steps S3103+S3104 may be implemented as an independent embodiment
  • steps S3103+S3104+S3105 may be implemented as an independent embodiment
  • steps S3101+S3103+S3104+S3105 may be implemented as an independent embodiment, but are not limited thereto.
  • steps S3102, S3103, S3104, S3105, and S3106 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
  • each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other implementation modes or other examples.
  • FIG3B is a flow chart of a communication processing method according to an embodiment of the present disclosure. As shown in FIG3B , the present disclosure embodiment relates to a communication processing method, which is used for a first user device 101, and the method includes:
  • Step S3201 Send a first message to a second user equipment.
  • the first message includes unprotected content information.
  • the first message is a direct communication request DCR message.
  • the unprotected content information includes first information and second information of the first message, and the second information is information related to security protection.
  • the first information includes at least one of the following:
  • the second information includes at least one of PC5 security policy information of the first user device and security capability of the first user device.
  • Step S3202 Receive a second message sent by a second user equipment.
  • the second message includes information to be verified, and the information to be verified includes at least a portion of unprotected content information in the first message.
  • the second message is a DSMC message.
  • Step S3203 verify the information to be verified.
  • verifying the information to be verified includes:
  • the information to be verified is verified according to the first information.
  • Step S3204 Send a third message to the second user equipment.
  • the third message is used to indicate the verification result of the information to be verified.
  • the third message is a direct security mode completion message. If the verification result is verification failed, the third message is a direct security mode rejection message.
  • a fourth message sent by the second user equipment is received, wherein the fourth message indicates a direct communication connection establishment result.
  • the direct communication connection when the fourth message is a direct communication acceptance message, the direct communication connection is established successfully.
  • the fourth message is a direct communication rejection message, the direct communication connection is established unsuccessfully.
  • steps S3201 - S3205 please refer to the above embodiment description.
  • the communication processing method involved in the embodiment of the present disclosure may include at least one of steps S3201 to S3205.
  • step S3201 may be implemented as an independent embodiment
  • step S3202 may be implemented as an independent embodiment
  • step S3203 may be implemented as an independent embodiment
  • step S3202+step S3203+step S3204 may be implemented as an independent embodiment, but is not limited thereto.
  • step S3201 and step S3205 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
  • each step can be independent, combined arbitrarily or exchanged in order, and the optional methods or optional examples can be combined arbitrarily.
  • FIG4A is a flow chart of a communication processing method according to an embodiment of the present disclosure. As shown in FIG4A , the present disclosure embodiment relates to a communication processing method for a second user device 102, the method comprising:
  • Step S4101 obtain the first message.
  • step S4101 can refer to the optional implementation of step S2101 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
  • the second user equipment 102 receives the first message sent by the first user equipment 101. However, this is not limited thereto, and the second user equipment 102 may also receive the first message sent by other user equipment.
  • the first message includes unprotected content information.
  • unprotected content information is obtained according to a protocol agreement.
  • Step S4102 Establish security authentication with the first user equipment according to the authentication information in the first message.
  • step S4102 can refer to the optional implementation of step S2102 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
  • Step S4103 Send a second message to the first user equipment.
  • step S4103 can refer to the optional implementation of step S2103 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
  • Step S4104 obtain the third message.
  • the third message indicates a verification result of the information to be verified.
  • step S4104 can refer to the optional implementation of step S2105 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
  • the second user equipment 102 receives the third message sent by the first user equipment 101. However, this is not limited thereto, and the third message sent by other user equipment may also be received.
  • Step S4105 Send a fourth message to the first user equipment according to the third message.
  • step 4105 can refer to step S2106 of FIG. 2 and other related parts of the embodiment involved in FIG. 2 , which will not be described in detail here.
  • step S4101+S4102 may be implemented as an independent embodiment
  • step S4103+S4104 may be implemented as an independent embodiment
  • step S4103+S4104+S4105 may be implemented as an independent embodiment
  • step S4101+S4103+S4104+S4105 may be implemented as an independent embodiment, but is not limited thereto.
  • steps S4102, S4103, S4104, and S4105 are optional, and one or more of these steps may be omitted or replaced in different embodiments.
  • FIG4B is a flow chart of a communication processing method according to an embodiment of the present disclosure. As shown in FIG4B , the present disclosure embodiment relates to a communication processing method for a second user device 102, the method comprising:
  • Step S4201 receiving a first message sent by a first user equipment.
  • step S4201 can refer to step S2101 in FIG. 2 , the optional implementation of step S4101 in FIG. 3A , and other related parts in the embodiments involved in FIG. 2 and FIG. 3A , which will not be described in detail here.
  • the first message includes unprotected content information.
  • the first message is a direct communication request DCR message.
  • the unprotected content information includes first information and second information of the first message, and the second information is security protection related information.
  • the first information includes at least one of the following:
  • the second information includes at least one of PC5 security policy information of the first user device and security capability of the first user device.
  • Step S4202 Send a second message to the first user equipment.
  • step S4202 can refer to step S2103 of FIG. 2 , the optional implementation of step S4103 of FIG. 3A , and other related parts in the embodiments involved in FIG. 2 and FIG. 3A , which will not be described in detail here.
  • the second message includes information to be verified, and the information to be verified includes at least a portion of the unprotected content information.
  • the second message is a Direct Safety Mode Command DSMC message.
  • Step S4203 Receive a third message sent by the first user equipment.
  • step S4203 can refer to the optional implementation of step S2105 in Figure 2, step S4104 in Figure 3A, and other related parts in the embodiments involved in Figures 2 and 3A, which will not be repeated here.
  • the third message indicates a verification result of the information to be verified.
  • the third message is a direct security mode completion message. If the verification result is verification failed, the third message is a direct security mode rejection message.
  • Step S4204 Send a fourth message to the first user equipment according to the third message.
  • step S4204 can refer to the optional implementation of step S2106 in FIG. 2 , step S4105 in FIG. 3A , and other related parts in the embodiments involved in FIG. 2 and FIG. 3A , which will not be described in detail here.
  • a fourth message is sent to the first user equipment according to the verification result indicated by the third message.
  • the fourth message when the third message is a direct safety mode completion message, the fourth message is a direct communication acceptance message.
  • the third message is a direct safety mode rejection message
  • the fourth message is a direct communication rejection message.
  • the communication processing method involved in the embodiment of the present disclosure may include at least one of step S4201 to step S4204.
  • step S4201 may be implemented as an independent embodiment
  • step S4202 may be implemented as an independent embodiment
  • step S4203 may be implemented as an independent embodiment
  • step S4201+step S4202+step S4203 may be implemented as independent embodiments, but are not limited thereto.
  • S4201 is optional, and one or more of these steps may be omitted or replaced in different embodiments.
  • each step can be independent, combined arbitrarily or exchanged in order, and the optional methods or optional examples can be combined arbitrarily.
  • FIG5 is a flow chart of a communication processing method according to an embodiment of the present disclosure.
  • the present disclosure embodiment relates to a communication processing method, which is used in a communication system 100, and the communication system 100 includes a first user device 101 and a second user device 102.
  • the method includes:
  • Step S5101 A first user equipment sends a first message.
  • the first message includes unprotected content information.
  • Step S5102 The second user equipment sends a second message to the first user equipment.
  • the second message includes information to be verified, and the information to be verified includes at least a portion of unprotected content information in the first message.
  • Step S5103 The first user equipment verifies the information to be verified.
  • Step S5104 Send a third message to the second user equipment.
  • the third message is used to indicate the verification result of the information to be verified.
  • Step S5105 The second user equipment sends a fourth message to the first user equipment.
  • steps S5101 to S5105 may refer to the description of the above embodiment.
  • the above method may include the method of the above-mentioned communication system side, the first user equipment side, the second user equipment side, etc., which will not be repeated here.
  • the processing method involved in the embodiment of the present disclosure may include at least one of steps S5101 to S5105.
  • steps S5102+S5103 may be implemented as an independent embodiment
  • steps S5101+S5102+S5103+S5104 may be implemented as an independent embodiment, but are not limited thereto.
  • each step can be independent, arbitrarily combined or exchanged in order, the optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other implementation modes or other examples.
  • Step 1 The first user equipment sends a direct communication request DCR message to the second user equipment.
  • the message includes all the information that needs to be included in the DCR message, such as RSPP metadata (for RSPP control operations on PC5), target user information, group ID (for SLPP signaling multicast), PC5 signaling security policy of the first user equipment, etc.
  • the message also includes information required for authentication and security establishment between terminals (such as keys, random numbers, key_Est_info).
  • Step 2 The second user equipment uses the information exchanged in Key_Est_Info to initiate a direct authentication and key establishment process with the first user equipment for mutual authentication between UEs.
  • Step 3 The second user device sends a direct security mode command DSMC message to the first user device, wherein the second user device shall return specific information (such as RSPP metadata, target user information, group ID) contained in the received DCR message to be verified by the first user device.
  • the DSMC message is integrity protected using the security context derived from the random number and intermediate key generated by the second user device in step 2.
  • the encryption algorithm used and the random number to be used by the first user device for key derivation are also included in the DSMC message.
  • Step 4 When the first user device receives the DSMC message, the first user device shall first check the integrity protection on the DSMC message. If the integrity of the DSMC message is verified, the DSMC checks whether the returned specific information matches the information sent in the DCR message. If the returned information does not match, the second user device sends a rejection message indicating the reason for the failure to the first user device. Only when all the returned information in the DSMC message matches the original sent information in the DCR message, the second user device sends a direct security mode completion message to the first user device, and the first user device optionally uses the intermediate key generated in step 2 and the security context derived from the random number received from the second user device to perform integrity protection on the direct security mode completion message.
  • Step 5 When the second user equipment receives the integrity-protected direct security mode completion message, the second user equipment can verify that the information received and returned to the first user equipment is the real information in the DCR message and will not be tampered with, and the security between the first user equipment and the second user equipment is now established. The second user equipment should send a protected direct communication acceptance message to the first user equipment.
  • part or all of the steps and their optional implementations may be arbitrarily combined with part or all of the steps in other embodiments, or may be arbitrarily combined with optional implementations of other embodiments.
  • the embodiments of the present disclosure also propose a device for implementing any of the above methods, for example, a device is proposed, the above device includes a unit or module for implementing each step performed by the terminal in any of the above methods.
  • a device is also proposed, including a unit or module for implementing each step performed by a network device (such as an access network device, a core network function node, a core network device, etc.) in any of the above methods.
  • a network device such as an access network device, a core network function node, a core network device, etc.
  • the division of the units or modules in the above device is only a division of logical functions, and in actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated.
  • the units or modules in the device can be implemented in the form of a processor calling software: for example, the device includes a processor, the processor is connected to a memory, and instructions are stored in the memory.
  • the processor calls the instructions stored in the memory to implement any of the above methods or implement the functions of the units or modules of the above device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory inside the device or a memory outside the device.
  • CPU central processing unit
  • microprocessor a microprocessor
  • the units or modules in the device may be implemented in the form of hardware circuits, and the functions of some or all of the units or modules may be implemented by designing the hardware circuits.
  • the hardware circuits may be understood as one or more processors.
  • the hardware circuits are application-specific integrated circuits (ASICs), and the functions of some or all of the above units or modules may be implemented by designing the logical relationship of components within the circuits.
  • the hardware circuits may be implemented by programmable logic devices (PLDs).
  • field programmable gate arrays may include a large number of logic gate circuits, and the connection relationship between the logic gate circuits may be configured by configuration files, thereby implementing the functions of some or all of the above units or modules. All units or modules of the above devices may be implemented entirely in the form of software called by a processor, or entirely in the form of hardware circuits, or partially in the form of software called by a processor and the rest in the form of hardware circuits.
  • the processor is a circuit with signal processing capability.
  • the processor may be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which may be understood as a microprocessor), or a digital signal processor (DSP); in another implementation, the processor may implement certain functions through the logical relationship of a hardware circuit, and the logical relationship of the above hardware circuit may be fixed or reconfigurable, such as a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA.
  • ASIC application-specific integrated circuit
  • PLD programmable logic device
  • the process of the processor loading a configuration document to implement the hardware circuit configuration may be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules.
  • it can also be a hardware circuit designed for artificial intelligence, which can be understood as ASIC, such as Neural Network Processing Unit (NPU), Tensor Processing Unit (TPU), Deep Learning Processing Unit (DPU), etc.
  • ASIC Neural Network Processing Unit
  • NPU Neural Network Processing Unit
  • TPU Tensor Processing Unit
  • DPU Deep Learning Processing Unit
  • FIG6A is a schematic diagram of the structure of the first user device proposed in an embodiment of the present disclosure.
  • the first user device 6100 may include: at least one of a transceiver module 6101, a processing module 6102, etc.
  • the transceiver module is used to send a first message to a second user device, wherein the first message includes unprotected content information; the transceiver module is also used to receive a second message sent by the second user device, wherein the second message includes information to be verified, and the information to be verified includes at least a part of the unprotected content information; the processing module is used to verify the information to be verified; the transceiver module is used to send a third message to the second user device, wherein the third message is used to indicate the verification result of the information to be verified; the transceiver module is also used to receive a fourth message sent by the second user device.
  • the above-mentioned processing module is used to execute at least one of the communication steps such as sending and/or receiving performed by the first user device 101 in any of the above methods (for example, step S2101, but not limited thereto), which will not be repeated here.
  • the processing module is used to execute at least one of the other steps (such as step S2104, but not limited to this) performed by the first user equipment 101 in any of the above methods, which will not be repeated here.
  • FIG6B is a schematic diagram of the structure of the second user device proposed in an embodiment of the present disclosure.
  • the second user device 6200 may include: at least one of a transceiver module 6201, a processing module 6202, etc.
  • the transceiver module is used to receive a first message sent by the first user device, wherein the first message includes unprotected content information; the transceiver module is also used to send a second message to the first user device, wherein the second message includes information to be verified, and the information to be verified includes at least a part of the unprotected content information; the transceiver module is also used to receive a third message sent by the first user device, wherein the third message indicates the verification result of the information to be verified; the transceiver module is also used to send a fourth message to the first user device according to the third message.
  • the transceiver module is used to execute at least one of the communication steps such as sending and/or receiving (such as step S2103, but not limited to this) performed by the second user device 102 in any of the above methods, which will not be repeated here.
  • the processing module is used to execute at least one of the other steps (such as step S2102, but not limited to this) performed by the second user equipment 101 in any of the above methods, which will not be repeated here.
  • the transceiver module may include a sending module and/or a receiving module, and the sending module and the receiving module may be separate or integrated.
  • the transceiver module may be interchangeable with the transceiver.
  • the processing module can be a module or include multiple submodules.
  • the multiple submodules respectively execute all or part of the steps required to be executed by the processing module.
  • the processing module can be replaced with the processor.
  • FIG7A is a schematic diagram of the structure of a communication device 7100 proposed in an embodiment of the present disclosure.
  • the communication device 7100 may be a network device (e.g., an access network device, a core network device, etc.), or a terminal (e.g., a user device, etc.), or a chip, a chip system, or a processor that supports a network device to implement any of the above methods, or a chip, a chip system, or a processor that supports a terminal to implement any of the above methods.
  • the communication device 7100 may be used to implement the method described in the above method embodiment, and the details may refer to the description in the above method embodiment.
  • the communication device 7100 includes one or more processors 7101.
  • the processor 7101 may be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit.
  • the baseband processor may be used to process the communication protocol and the communication data
  • the central processing unit may be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute a program, and process the data of the program.
  • the communication device 7100 is used to execute any of the above methods.
  • the communication device 7100 further includes one or more memories 7102 for storing instructions.
  • the memory 7102 may also be outside the communication device 7100.
  • the communication device 7100 further includes one or more transceivers 7103.
  • the transceiver 7103 performs the communication steps such as sending and/or receiving in the above method (for example, step S2102, but not limited thereto).
  • the processor 7101 executes at least one of the other steps (such as step S2101, but not limited to this).
  • the transceiver may include a receiver and/or a transmitter, and the receiver and the transmitter may be separate or integrated.
  • the terms such as transceiver, transceiver unit, transceiver, transceiver circuit, etc. may be replaced with each other, the terms such as transmitter, transmission unit, transmitter, transmission circuit, etc. may be replaced with each other, and the terms such as receiver, receiving unit, receiver, receiving circuit, etc. may be replaced with each other.
  • the communication device 7100 may include one or more interface circuits 7104.
  • the interface circuit 7104 is connected to the memory 7102, and the interface circuit 7104 may be used to receive signals from the memory 7102 or other devices, and may be used to send signals to the memory 7102 or other devices.
  • the interface circuit 7104 may read instructions stored in the memory 7102 and send the instructions to the processor 7101.
  • the communication device 7100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 7100 described in the present disclosure is not limited thereto, and the structure of the communication device 7100 may not be limited by FIG. 7A.
  • the communication device may be an independent device or may be part of a larger device.
  • the communication device may be: 1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.
  • FIG. 7B is a schematic diagram of the structure of a chip 7200 provided in an embodiment of the present disclosure.
  • the communication device 7200 may be a chip or a chip system
  • the chip 7200 includes one or more processors 7201, and the chip 8200 is used to execute any of the above methods.
  • the chip 7200 further includes one or more interface circuits 7202.
  • the interface circuit 7202 is connected to the memory 7203.
  • the interface circuit 7202 can be used to receive signals from the memory 7203 or other devices, and the interface circuit 7202 can be used to send signals to the memory 7203 or other devices.
  • the interface circuit 7202 can read instructions stored in the memory 7203 and send the instructions to the processor 7201.
  • the interface circuit 7202 performs at least one of the communication steps such as sending and/or receiving in the above method (for example, step S2102, but not limited to this), and the processor 7201 performs at least one of the other steps (for example, step S2101, but not limited to this).
  • interface circuit interface circuit
  • transceiver pin transceiver
  • the chip 7200 further includes one or more memories 7203 for storing instructions.
  • the memory 7203 may be outside the chip 7200.
  • the present disclosure also proposes a storage medium, on which instructions are stored, and when the instructions are executed on the communication device 7100, the communication device 7100 executes any of the above methods.
  • the storage medium is an electronic storage medium.
  • the storage medium is a computer-readable storage medium, but is not limited to this, and it can also be a storage medium readable by other devices.
  • the storage medium can be a non-transitory storage medium, but is not limited to this, and it can also be a temporary storage medium.
  • the present disclosure also proposes a program product, which, when executed by the communication device 7100, enables the communication device 7100 to execute any of the above methods.
  • the program product is a computer program product.
  • the present disclosure also proposes a computer program, which, when executed on a computer, causes the computer to execute any one of the above methods.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本公开涉及通信处理方法,包括:向第二用户设备发送第一消息,其中,第一消息包括未受保护内容信息;接收第二用户设备发送的第二消息,其中,第二消息包括待验证信息,待验证信息包括未受保护内容信息的至少一部分;验证待验证信息;向第二用户设备发送第三消息,其中,第三消息用于指示待验证信息的验证结果;接收第二用户设备发送的第四消息。由此,第一用户设备可以对第二用户设备返回的信息进行验证,从而可以验证第二用户设备接收到的未受保护内容信息的完整性,避免接收到的第一消息中的信息被篡改,进而用户设备之间可以建立安全连接。

Description

通信处理方法、用户设备 技术领域
本公开涉及通信技术领域,尤其涉及通信处理方法、用户设备。
背景技术
在通信系统中,具有车联网(Vehicle-to-everything,V2X)能力的终端在进行测距/侧行链路(sidelink,SL)定位终端的发现和选择的过程中,往往会发送包含V2X服务信息的请求消息,以与目标终端建立通信连接。
发明内容
本公开的方法可以用于解决“请求消息中的信息被攻击者篡改,而导致后续过程(例如测距/SL定位控制)失败或导致意外结果”这一技术问题。
本公开实施例提出了一种通信处理方法、用户设备。
根据本公开实施例的第一方面,提出了一种通信处理方法,由第一用户设备执行,包括:
向第二用户设备发送第一消息,其中,所述第一消息包括未受保护内容信息;
接收所述第二用户设备发送的第二消息,其中,所述第二消息包括待验证信息,所述待验证信息包括所述未受保护内容信息的至少一部分;
验证所述待验证信息;
向所述第二用户设备发送第三消息,其中,第三消息用于指示所述待验证信息的验证结果;
接收所述第二用户设备发送的第四消息。
根据本公开实施例的第二方面,提出了一种通信处理方法,由第二用户设备执行,包括:
接收第一用户设备发送的第一消息,其中,所述第一消息包括未受保护内容信息;
向所述第一用户设备发送第二消息,其中,所述第二消息包括待验证信息,所述待验证信息包括所述未受保护内容信息的至少一部分;
接收所述第一用户设备发送的第三消息,其中,所述第三消息指示所述待验证信息的验证结果;
根据所述第三消息向所述第一用户设备发送第四消息。
根据本公开实施例的第三方面,提出了一种第一用户设备,包括:
收发模块,用于向第二用户设备发送第一消息,其中,所述第一消息包括未受保护内容信息;
所述收发模块,还用于接收所述第二用户设备发送的第二消息,其中,所述第二消息包括待验证信息,所述待验证信息包括所述未受保护内容信息的至少一部分;
处理模块,用于验证所述待验证信息;
所述收发模块,用于向所述第二用户设备发送第三消息,其中,第三消息用于指示所述待验证信息的验证结果;
所述收发模块,还用于接收所述第二用户设备发送的第四消息。
根据本公开实施例的第四方面,提出了一种第二用户设备,包括:
收发模块,用于接收第一用户设备发送的第一消息,其中,所述第一消息包括未受保护内容信息;
所述收发模块,还用于向所述第一用户设备发送第二消息,其中,所述第二消息包括待验证信息,所述待验证信息包括所述未受保护内容信息的至少一部分;
所述收发模块,还用于接收所述第一用户设备发送的第三消息,其中,所述第三消息指示所述待验证信息的验证结果;
所述收发模块,还用于根据所述第三消息向所述第一用户设备发送第四消息。
根据本公开实施例的第五方面,提出了一种通信设备,包括:
一个或多处理器;
其中,所述处理器用于调用指令以使得所述通信设备执行第一方面、第二方面中任一方面所述的方法。
根据本公开实施例的第六方面,提出了一种通信系统,包括:
第一用户设备,用于实现第一方面中所述的通信处理方法;
第二用户设备,用于实现第二方面中所述的通信处理方法。
根据本公开实施例的第七方面,提出了一种存储介质,所述存储介质存储有指令,当所述指令在通信 设备上运行时,使得所述通信设备执行如第一方面、第二方面中任一方面所述的通信处理方法。
本公开实施例中,接收到第一消息的第二用户设备,可以将第一消息中包含的未受保护内容信息中的一部分返回给第一用户设备,由第一用户设备对返回的信息进行验证,从而可以验证第二用户设备接收到的未受保护内容信息的完整性,避免第二用户设备接收到的第一消息中的信息被篡改,进而用户设备之间可以建立安全连接。
附图说明
本公开上述的和/或附加的方面和优点从下面结合附图对实施例的描述中将变得明显和容易理解,其中:
图1是根据本公开实施例示出的通信系统的架构示意图;
图2是根据本公开实施例示出的通信处理方法的交互示意图;
图3A-3B是根据本公开实施例示出的通信处理方法的流程示意图;
图4A-4B是根据本公开实施例示出的通信处理方法的流程示意图;
图5是根据本公开实施例示出的通信处理方法的交互示意图;
图6A是本公开实施例提出的第一用户设备的结构示意图;
图6B是本公开实施例提出的第二用户设备的结构示意图;
图7A是本公开实施例提出的通信设备的结构示意图;
图7B是本公开实施例提出的芯片的结构示意图。
具体实施方式
本公开实施例提出了通信处理方法、用户设备。
第一方面,本公开实施例提出了一种信息的处理方法,所述方法由第一用户设备执行,包括:
向第二用户设备发送第一消息,其中,所述第一消息包括未受保护内容信息;
接收所述第二用户设备发送的第二消息,其中,所述第二消息包括待验证信息,所述待验证信息包括所述未受保护内容信息的至少一部分;
验证所述待验证信息;
在接收所述第二消息之后,验证所述待验证信息,向所述第二用户设备发送第三消息,其中,第三消息用于指示所述待验证信息的验证结果;
接收所述第二用户设备发送的第四消息。
在上述实施例中,接收到第一消息的第二用户设备,可以将第一消息中包含的未受保护内容信息中的一部分返回给第一用户设备,由第一用户设备对返回的信息进行验证,从而可以验证第二用户设备接收到的未受保护内容信息的完整性,避免接收到的第一消息中的信息被篡改,进而用户设备之间可以建立安全连接。
结合第一方面的一些实施例,在一些实施例中,所述第一消息为直接通信请求DCR消息。
在上述实施例中,在DCR消息中携带未受保护内容信息,可以减少通信资源的开销。
结合第一方面的一些实施例,在一些实施例中,所述未受保护内容信息包括所述第一消息的第一信息和第二信息,所述第二信息为安全保护相关的信息。
在上述实施例中,将未受保护的内容信息划分为可用于验证的第一信息,和与安全保护相关的第二信息,从而可以在第二消息中携带可用于验证的第一信息的一部分,进行可以节省传输待验证信息的信令开销,提高验证效率。
结合第一方面的一些实施例,在一些实施例中,所述第二消息为DSMC消息。
在上述实施例中,将未受保护的内容信息划分为可用于验证的第一信息,和与安全保护相关的第二信息,从而可以在第二消息中携带可用于验证的第一信息的一部分,进行可以节省传输待验证信息的信令开销,提高验证效率。
结合第一方面的一些实施例,在一些实施例中,所述验证所述待验证信息,包括:
根据所述第一信息对所述待验证信息进行验证。
在上述实施例中,由于待验证信息包括所述第一信息的至少一部分,因此,直接基于第一信息对所述待验证信息进行验证,可以提高验证效率。
结合第一方面的一些实施例,在一些实施例中,所述验证结果为验证通过,所述第三消息为直接安全模式完成消息;或者,所述验证结果为验证未通过,所述第三消息为直接安全模式拒绝消息。
在上述实施例中,根据所述待验证信息的验证结果,确定第三消息,从而可以准确地通知第二用户设备待验证信息的验证结果。
结合第一方面的一些实施例,在一些实施例中,所述第四消息为直接通信接受消息时,直接通信连接建立成功;或者,所述第四消息为直接通信拒绝消息时,直接通信连接建立失败。
在上述实施例中,通过直接通信接受消息及直接通信拒绝消息指示直接通信连接建立结果,可以减少通信资源的开销。
结合第一方面的一些实施例,在一些实施例中,所述第一信息包括以下至少一项:
测距与侧行链路定位协议RSPP元数据;
目标用户信息;
源用户信息;
组标识ID;
业务信息。
结合第一方面的一些实施例,在一些实施例中,所述第二信息包括所述第一用户设备的PC5安全策略信息、第一用户设备安全能力的至少一项。
第二方面,本公开实施例提出了一种通信处理方法,所述方法由第二用户设备执行,该方法包括:
接收第一用户设备发送的第一消息,其中,所述第一消息包括未受保护内容信息;
向所述第一用户设备发送第二消息,其中,所述第二消息包括待验证信息,所述待验证信息包括所述未受保护内容信息的至少一部分;
接收所述第一用户设备发送的第三消息,其中,所述第三消息指示所述待验证信息的验证结果;
根据所述第三消息向所述第一用户设备发送第四消息。
上述实施例中,接收到第一消息的第二用户设备,可以将第一消息中包含的未受保护内容信息中的一部分返回给第一用户设备,由第一用户设备对返回的信息进行验证,从而可以验证第二用户设备接收到的未受保护内容信息的完整性,避免接收到的第一消息中的信息被篡改,进而用户设备之间可以建立安全连接。
结合第二方面的一些实施例,在一些实施例中,所述第一消息为直接通信请求DCR消息。
在上述实施例中,在DCR消息中携带未受保护内容信息,可以减少通信资源的开销。
结合第二方面的一些实施例,在一些实施例中,所述未受保护内容信息包括第一信息和第二信息,所述第二信息为安全保护相关的信息。
在上述实施例中,将未受保护的内容信息划分为可用于验证的第一信息,和与安全保护相关的第二信息,从而可以在第二消息中携带可用于验证的第一信息的一部分,进行可以节省传输待验证信息的信令开销,提高验证效率。
结合第二方面的一些实施例,在一些实施例中,所述第二消息为直接安全模式命令DSMC消息。
在上述实施例中,在DSMC消息中携带待验证信息,可以减少通信资源的开销。
结合第二方面的一些实施例,在一些实施例中,所述验证结果为验证通过,所述第三消息为直接安全模式完成消息。或者,所述验证结果为验证未通过,所述第三消息为直接安全模式拒绝消息。
在上述实施例中,可以通过直接安全模式完成消息及直接安全模式拒绝消息指示不同的验证结果,从而第二用户设备可以通过不同的消息,准确地确定验证结果,而且可以减少通信资源的开销。
结合第二方面的一些实施例,在一些实施例中,所述第三消息为直接安全模式完成消息时,所述第四消息为直接通信接受消息。或者,所述第三消息为直接安全模式拒绝消息,所述第四消息为直接通信拒绝消息。
在上述实施例中,可以根据第三消息向所述第一用户设备发送第四消息,从而使发送的第四消息可以与验证结果相匹配,进而两个用户设备可以准确地建立通信连接。
结合第二方面的一些实施例,在一些实施例中,所述第一信息包括以下至少一项:
测距与侧行链路定位协议RSPP元数据;
目标用户信息;
源用户信息;
组标识ID;
业务信息。
结合第二方面的一些实施例,在一些实施例中,所述第二信息包括所述第一用户设备的PC5安全策略信息、第一用户设备安全能力中的至少一项。
第三方面,本公开实施例提出了第一用户设备,上述第一用户设备包括收发模块、处理模块中的至少一者;其中,
收发模块,用于向第二用户设备发送第一消息,其中,所述第一消息包括未受保护内容信息;
所述收发模块,还用于接收所述第二用户设备发送的第二消息,其中,所述第二消息包括待验证信息,所述待验证信息包括所述未受保护内容信息的至少一部分;
处理模块,用于验证所述待验证信息;
所述收发模块,用于向所述第二用户设备发送第三消息,其中,第三消息用于指示所述待验证信息的验证结果;
所述收发模块,还用于接收所述第二用户设备发送的第四消息。
结合第三方面的一些实施例,在一些实施例中,所述第一消息为直接通信请求DCR消息。
结合第三方面的一些实施例,在一些实施例中,所述未受保护内容信息包括所述第一消息的第一信息和第二信息,所述第二信息为安全保护相关的信息。
结合第三方面的一些实施例,在一些实施例中,所述第二消息为DSMC消息。
结合第三方面的一些实施例,在一些实施例中,所述处理模块,用于:
根据所述第一信息对所述待验证信息进行验证。
结合第三方面的一些实施例,在一些实施例中,所述验证结果为验证通过,所述第三消息为直接安全模式完成消息;或者,所述验证结果为验证未通过,所述第三消息为直接安全模式拒绝消息。
结合第三方面的一些实施例,在一些实施例中,所述第四消息为直接通信接受消息时,直接通信连接建立成功;或者,所述第四消息为直接通信拒绝消息时,直接通信连接建立失败。
结合第三方面的一些实施例,在一些实施例中,所述第一信息包括以下至少一项:
测距与侧行链路定位协议RSPP元数据;
目标用户信息;
源用户信息;
组标识ID;
业务信息。
结合第三方面的一些实施例,在一些实施例中,所述第二信息包括所述第一用户设备的PC5安全策略信息、第一用户设备安全能力的至少一项。
第四方面,本公开实施例提出了第二用户设备,上述第二用户设备包括收发模块、处理模块中的至少一者;其中,
收发模块,用于接收第一用户设备发送的第一消息,其中,所述第一消息包括未受保护内容信息;
所述收发模块,还用于向所述第一用户设备发送第二消息,其中,所述第二消息包括待验证信息,所述待验证信息包括所述未受保护内容信息的至少一部分;
所述收发模块,还用于接收所述第一用户设备发送的第三消息,其中,所述第三消息指示所述待验证信息的验证结果;
所述收发模块,还用于根据所述第三消息向所述第一用户设备发送第四消息。
结合第四方面的一些实施例,在一些实施例中,所述第一消息为直接通信请求DCR消息。
结合第四方面的一些实施例,在一些实施例中,所述未受保护内容信息包括第一信息和第二信息,所述第二信息为安全保护相关的信息。
结合第四方面的一些实施例,在一些实施例中,所述第二消息为直接安全模式命令DSMC消息。
结合第四方面的一些实施例,在一些实施例中,所述验证结果为验证通过,所述第三消息为直接安 全模式完成消息;或者,所述验证结果为验证未通过,所述第三消息为直接安全模式拒绝消息。
结合第四方面的一些实施例,在一些实施例中,所述第三消息为直接安全模式完成消息,所述第四消息为直接通信接受消息;或者,所述第三消息为直接安全模式拒绝消息,所述第四消息为直接通信拒绝消息。
结合第四方面的一些实施例,在一些实施例中,所述第一信息包括以下至少一项:
测距与侧行链路定位协议RSPP元数据;
目标用户信息;
源用户信息;
组标识ID;
业务信息。
结合第四方面的一些实施例,在一些实施例中,所述第二信息包括所述第一用户设备的PC5安全策略信息、第一用户设备安全能力的至少一项。
第五方面,本公开实施例提出了通信设备,上述通信设备包括:一个或多个处理器;其中,上述通信设备用于执行第一方面和第一方面的可选实现方式。
第六方面,本公开实施例提出了通信设备,上述通信设备包括:一个或多个处理器;其中,上述通信设备用于执行第二方面和第二方面的可选实现方式。
第七方面,本公开实施例提出了通信系统,上述通信系统包括:
第一用户设备,用于实现如第一方面和第一方面的可选实现方式所描述的方法;
第二用户设备,用于实现如第二方面和第二方面的可选实现方式所描述的方法。
第八方面,本公开实施例提出了存储介质,上述存储介质存储有指令,当上述指令在通信设备上运行时,使得上述通信设备执行如第一方面和第一方面的可选实现方式所描述的方法、或执行如第二方面和第二方面的可选实现方式所描述的方法。
第九方面,本公开实施例提出了程序产品,上述程序产品被通信设备执行时,使得上述通信设备执行如第一方面和第一方面的可选实现方式所描述的方法、或执行如第二方面和第二方面的可选实现方式所描述的方法。
第十方面,本公开实施例提出了计算机程序,当其在计算机上运行时,使得计算机执行如第一方面和第一方面的可选实现方式所描述的方法、或执行如第二方面和第二方面的可选实现方式所描述的方法。
第十一方面,本公开实施例提供了一种芯片或芯片系统。该芯片或芯片系统包括处理电路,被配置为执行第一方面和第一方面的可选实现方式所描述的方法、或执行如第二方面和第二方面的可选实现方式所描述的方法。
可以理解地,上述用户设备、通信系统、存储介质、程序产品、计算机程序、芯片或芯片系统均用于执行本公开实施例所提出的方法。因此,其所能达到的有益效果可以参考对应方法中的有益效果,此处不再赘述。
本公开实施例提出了通信处理方法、用户设备。在一些实施例中,通信处理方法与信息处理方法、通信方法等术语可以相互替换,信息传输装置与信息处理装置、通信装置等术语可以相互替换,信息处理系统、通信系统等术语可以相互替换。
本公开实施例并非穷举,仅为部分实施例的示意,不作为对本公开保护范围的具体限制。在不矛盾的情况下,某一实施例中的每个步骤均可以作为独立实施例来实施,且各步骤之间可以任意组合,例如,在某一实施例中去除部分步骤后的方案也可以作为独立实施例来实施,且在某一实施例中各步骤的顺序可以任意交换,另外,某一实施例中的可选实现方式可以任意组合;此外,各实施例之间可以任意组合,例如,不同实施例的部分或全部步骤可以任意组合,某一实施例可以与其他实施例的可选实现方式任意组合。
在各本公开实施例中,如果没有特殊说明以及逻辑冲突,各实施例之间的术语和/或描述具有一致性,且可以互相引用,不同实施例中的技术特征根据其内在的逻辑关系可以组合形成新的实施例。
本公开实施例中所使用的术语只是为了描述特定实施例的目的,而并非作为对本公开的限制。
在本公开实施例中,除非另有说明,以单数形式表示的元素,如“一个”、“一种”、“该”、“上述”、“所述”、“前述”、“这一”等,可以表示“一个且只有一个”,也可以表示“一个或多个”、“至少一个”等。例如,在翻译中使用如英语中的“a”、“an”、“the”等冠词(article)的情况下,冠词之后的名词可以理解为单数表 达形式,也可以理解为复数表达形式。
在本公开实施例中,“多个”是指两个或两个以上。
在一些实施例中,“至少一者(至少一项、至少一个)(at least one of)”、“一个或多个(one ormore)”、“多个(a plurality of)”、“多个(multiple)等术语可以相互替换。
在一些实施例中,“A、B中的至少一者”、“A和/或B”、“在一情况下A,在另一情况下B”、“响应于一情况A,响应于另一情况B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择执行(A和B被选择性执行);在一些实施例中A和B(A和B都被执行)。当有A、B、C等更多分支时也类似上述。
在一些实施例中,“A或B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择执行(A和B被选择性执行)。当有A、B、C等更多分支时也类似上述。
本公开实施例中的“第一”、“第二”等前缀词,仅仅为了区分不同的描述对象,不对描述对象的位置、顺序、优先级、数量或内容等构成限制,对描述对象的陈述参见权利要求或实施例中上下文的描述,不应因为使用前缀词而构成多余的限制。例如,描述对象为“字段”,则“第一字段”和“第二字段”中“字段”之前的序数词并不限制“字段”之间的位置或顺序,“第一”和“第二”并不限制其修饰的“字段”是否在同一个消息中,也不限制“第一字段”和“第二字段”的先后顺序。再如,描述对象为“等级”,则“第一等级”和“第二等级”中“等级”之前的序数词并不限制“等级”之间的优先级。再如,描述对象的数量并不受序数词的限制,可以是一个或者多个,以“第一装置”为例,其中“装置”的数量可以是一个或者多个。此外,不同前缀词修饰的对象可以相同或不同,例如,描述对象为“装置”,则“第一装置”和“第二装置”可以是相同的装置或者不同的装置,其类型可以相同或不同;再如,描述对象为“信息”,则“第一信息”和“第二信息”可以是相同的信息或者不同的信息,其内容可以相同或不同。
在一些实施例中,“包括A”、“包含A”、“用于指示A”、“携带A”,可以解释为直接携带A,也可以解释为间接指示A。
在一些实施例中,“响应于……”、“响应于确定……”、“在……的情况下”、“在……时”、“当……时”、“若……”、“如果……”等术语可以相互替换。
在一些实施例中,装置等可以解释为实体的、也可以解释为虚拟的,其名称不限定于实施例中所记载的名称,“装置”、“设备(equipment)”、“设备(device)”、“电路”、“网元”、“节点”、“功能”、“单元”、“部件(section)”、“系统”、“网络”、“芯片”、“芯片系统”、“实体”、“主体”等术语可以相互替换。
在一些实施例中,“接入网设备(access network device,AN device)”、“无线接入网设备(radio access network device,RAN device)”、“基站(base station,BS)”、“无线基站(radio base station)”、“固定台(fixed station)”、“节点(node)”、“接入点(access point)”、“发送点(transmission point,TP)”、“接收点(reception point,RP)”、“发送接收点(transmission/reception point,TRP)”、“面板(panel)”、“天线面板(antenna panel)”、“天线阵列(antenna array)”、“小区(cell)”、“宏小区(macro cell)”、“小型小区(small cell)”、“毫微微小区(femto cell)”、“微微小区(pico cell)”、“扇区(sector)”、“小区组(cell group)”、“载波(carrier)”、“分量载波(component carrier)”、“带宽部分(bandwidth part,BWP)”等术语可以相互替换。
在一些实施例中,“终端(terminal)”、“终端设备(terminal device)”、“用户设备(user equipment,UE)”、“用户终端(user terminal)”、“移动台(mobile station,MS)”、“移动终端(mobile terminal,MT)”、订户站(subscriber station)、移动单元(mobile unit)、订户单元(subscriber unit)、无线单元(wireless unit)、远程单元(remote unit)、移动设备(mobile device)、无线设备(wireless device)、无线通信设备(wireless communication device)、远程设备(remote device)、移动订户站(mobile subscriber station)、接入终端(access terminal)、移动终端(mobile terminal)、无线终端(wireless terminal)、远程终端(remote terminal)、手持设备(handset)、用户代理(user agent)、移动客户端(mobile client)、客户端(client)等术语可以相互替换。
在一些实施例中,接入网设备、核心网设备、或网络设备可以被替换为终端。例如,针对将接入网设 备、核心网设备、或网络设备以及终端间的通信置换为多个终端间的通信(例如,也可以被称为设备对设备(device-to-device,D2D)、车联网(vehicle-to-everything,V2X)等)的结构,也可以应用本公开的各实施例。在该情况下,也可以设为终端具有接入网设备所具有的全部或部分功能的结构。此外,“上行”、“下行”等语言也可以被替换为与终端间通信对应的语言(例如,“侧行(side)”)。例如,上行信道、下行信道等可以被替换为侧行信道,上行链路、下行链路等可以被替换为侧行链路。
在一些实施例中,终端可以被替换为接入网设备、核心网设备、或网络设备。在该情况下,也可以设为接入网设备、核心网设备、或网络设备具有终端所具有的全部或部分功能的结构。
在一些实施例中,获取数据、信息等可以遵照所在地国家的法律法规。
在一些实施例中,可以在得到用户同意后获取数据、信息等。
图1是根据本公开实施例示出的通信系统的架构示意图。如图1所示,通信系统100可以包括第一用户设备(terminal)101、第二用户设备102。第一用户设备101与第二用户设备102之间可以建立有通信连接。第一用户设备101与第二用户设备102之间可以进行SL通信。
在一些实施例中,通信系统100还可以包括网络设备,网络设备可以包括接入网设备和核心网设备(core network device)的至少一者。
在一些实施例中,第一用户设备101或第二用户设备102例如包括手机(mobile phone)、可穿戴设备、物联网设备、具备通信功能的汽车、智能汽车、平板电脑(Pad)、带无线收发功能的电脑、虚拟现实(virtual reality,VR)终端设备、增强现实(augmented reality,AR)终端设备、工业控制(industrial control)中的无线终端设备、无人驾驶(self-driving)中的无线终端设备、远程手术(remote medical surgery)中的无线终端设备、智能电网(smart grid)中的无线终端设备、运输安全(transportation safety)中的无线终端设备、智慧城市(smart city)中的无线终端设备、智慧家庭(smart home)中的无线终端设备中的至少一者,但不限于此。
在一些实施例中,接入网设备例如是将终端接入到无线网络的节点或设备,接入网设备可以包括5G通信系统中的演进节点B(evolved NodeB,eNB)、下一代演进节点B(next generation eNB,ng-eNB)、下一代节点B(next generation NodeB,gNB)、节点B(node B,NB)、家庭节点B(home node B,HNB)、家庭演进节点B(home evolved nodeB,HeNB)、无线回传设备、无线网络控制器(radio network controller,RNC)、基站控制器(base station controller,BSC)、基站收发台(base transceiver station,BTS)、基带单元(base band unit,BBU)、移动交换中心、6G通信系统中的基站、开放型基站(Open RAN)、云基站(Cloud RAN)、其他通信系统中的基站、WiFi系统中的接入节点中的至少一者,但不限于此。
在一些实施例中,本公开的技术方案可适用于Open RAN架构,此时,本公开实施例所涉及的接入网设备间或者接入网设备内的接口可变为Open RAN的内部接口,这些内部接口之间的流程和信息交互可以通过软件或者程序实现。
在一些实施例中,接入网设备可以由集中单元(central unit,CU)与分布式单元(distributed unit,DU)组成的,其中,CU也可以称为控制单元(control unit),采用CU-DU的结构可以将接入网设备的协议层拆分开,部分协议层的功能放在CU集中控制,剩下部分或全部协议层的功能分布在DU中,由CU集中控制DU,但不限于此。
在一些实施例中,核心网设备可以是一个设备,包括一个或多个网元,也可以是多个设备或设备群,分别包括一个或多个网元中的全部或部分。网元可以是虚拟的,也可以是实体的。核心网例如包括演进分组核心(Evolved Packet Core,EPC)、5G核心网络(5G Core Network,5GCN)、下一代核心(Next Generation Core,NGC)中的至少一者。
可以理解的是,本公开实施例描述的通信系统是为了更加清楚的说明本公开实施例的技术方案,并不构成对于本公开实施例提出的技术方案的限定,本领域普通技术人员可知,随着系统架构的演变和新业务场景的出现,本公开实施例提出的技术方案对于类似的技术问题同样适用。
下述本公开实施例可以应用于图1所示的通信系统100、或部分主体,但不限于此。图1所示的各主体是例示,通信系统可以包括图1中的全部或部分主体,也可以包括图1以外的其他主体,各主体数量和形态为任意,各主体之间的连接关系是例示,各主体之间可以不连接也可以连接,其连接可以是任意方式,可以是直接连接也可以是间接连接,可以是有线连接也可以是无线连接。
本公开各实施例可以应用于长期演进(Long Term Evolution,LTE)、LTE-Advanced(LTE-A)、LTE-Beyond(LTE-B)、SUPER 3G、IMT-Advanced、第四代移动通信系统(4th generation mobile communication system,4G)、)、第五代移动通信系统(5th generation mobile communication system,5G)、5G新空口(new radio,NR)、未来无线接入(Future Radio Access,FRA)、新无线接入技术(New-Radio Access Technology,RAT)、新无线(New Radio,NR)、新无线接入(New radio access,NX)、未来一代无线接入(Future generation radio access,FX)、Global System for Mobile communications(GSM(注册商标))、CDMA2000、超移动宽带(Ultra Mobile Broadband,UMB)、IEEE 802.11(Wi-Fi(注册商标))、IEEE 802.16(WiMAX(注册商标))、IEEE 802.20、超宽带(Ultra-WideBand,UWB)、蓝牙(Bluetooth(注册商标))、陆上公用移动通信网(Public Land Mobile Network,PLMN)网络、设备到设备(Device-to-Device,D2D)系统、机器到机器(Machine to Machine,M2M)系统、物联网(Internet of Things,IoT)系统、车联网(Vehicle-to-Everything,V2X)、利用其他通信方法的系统、基于它们而扩展的下一代系统等。此外,也可以将多个系统组合(例如,LTE或者LTE-A与5G的组合等)应用。
本公开实施例中,具有V2X能力的UE的测距/SL定位UE发现和选择的过程,或发送直接通信请求(Direct Communication Request,DCR)消息,DCR消息中包含指示“测距/侧链定位”的V2X服务信息,源用户信息(例如,源UE的应用层ID、源UE的服务公共陆地移动网(Public Land Mobile Network,PLMN))、目标用户信息(如,目标UE的应用层层ID)、测距与侧行链路定位协议(ranging and sidelink positioning protocol,RSPP)元数据信息、应用层组ID等。所有这些信息对于测距/SL定位通信的成功至关重要。如果任何信息(例如源用户信息、目标用户信息、包括UE角色的RSPP元数据)被攻击者篡改,则后续过程(例如测距/SL定位控制)将失败或导致意外后果。
相关技术中,对于用于具有V2X能力的UE的DCR消息的安全保护,由UE的网络层构建的DCR消息在网络层不受UE的保护,即DCR消息完整性在网络层没有受到UE的保护,使得接收到DCR消息的V2X UE无法验证接收到的DCR消息中的信息是否被篡改。
目前没有现有的方法来验证测距/SL定位服务的DCR消息中包含的任何特定信息(例如,RSPP元数据、组ID等)的完整性。因此,需要研究V2X UE接收DCR消息以验证DCR消息中包含的特定信息的完整性的方法。
图2是根据本公开实施例示出的通信处理方法的交互示意图。如图2所示,本公开实施例涉及通信处理方法,用于通信系统100,上述方法包括:
步骤S2101,第一用户设备向第二用户设备发送第一消息。
在一些实施例中,所述第一消息之中包括未受保护内容信息。
在一些实施例中,第一消息可以为直接通信请求DCR消息。也可以为其他可以携带未保护内容信息的消息,本公开对此不做限定。
在一些实施例中,未受保护内容信息为待对其进行保护的信息。
在一些实施例中,对未受保护内容信息的名称不做限定,比如,特定信息,指定信息等等。
在一些实施例中,所述未受保护内容信息可以包括第一信息和第二信息,所述第二信息为与安全保护相关的信息。
在一些实施例中,第一信息包括以下至少一项:
测距与侧行链路定位协议RSPP元数据;
目标用户信息;
源用户信息;
组标识ID;
业务信息。
在一些实施例中,RSPP元数据可以为用于短距离直接通信接口(PC5)上的RSPP控制操作的数据。
在一些实施例中,目标用户信息可以为目标UE的应用层层ID等。本公开对此不做限定。
在一些实施例中,源用户信息可以为源UE的应用层ID、源UE的服务PLMN等。本公开对此不做限定。
在一些实施例中,组标识(Identity document,ID)可以为应用层组ID。
在一些实施例中,业务信息可以为第一用户设备想要实现的业务的具体信息,比如,业务可以为测距/SL定位相关的业务。
在一些实施例中,第二信息可以包括第一用户设备的PC5安全策略信息、第一用户设备安全能力信息中的至少一项。
在一些实施例中,第一用户设备的PC5安全策略信息可以为用于保护第一用户设备的PC5的安全相关的信息。
在一些实施例中,第一用户设备安全能力信息可以为第一用户设备安全能力相关的信息。比如,其支持的安全算法等。
在一些实施例中,第一消息中还可以包括认证信息。认证信息可以包括第一用户设备与第二用户设备之间的认证和安全建立所需的信息。
在一些实施例中,认证信息可以包括密钥、随机数和密钥建立信息key_Est_info中的至少一项。
在一些实施例中,密钥是在加密和解密过程中使用的一组参数或代码,用于对信息进行加密和解密。密钥通常是一个长字符串或数(比如128位或256位),由随机数生成器生成。或者是由第一用户设备和第二用户设备协商后分配的一组唯一的数字或代码。
在一些实施例中,随机数可以为由随机数生成器生成的一组看似随机的数字或字符,其生成过程不受人为的干扰或控制,且每次生成的结果都是不同的。随机数可以用来产生加密密钥或确保通信中的一次性密码的安全性。
在一些实施例中,密钥建立信息key_Est_info可以为用于指示创建终端之间认证和安全建立所需的密钥的相关信息。
在一些实施例中,“特定(certain)”、“预定(preseted)”、“预设”、“设定”、“指示(indicated)”“某一”、“任意”、“任一”、“第一”等术语可以相互替换,“特定A”、“预定A”、“预设A”、“设定A”、“指示A”、“某一A”、“任意A”、“任一A”“第一A”可以解释为在协议等中预先规定的A,也可以解释为通过设定、配置、或指示等得到的A,也可以解释为特定A、某一A、任意A、任一A或第一A等,但不限于此。
在一些实施例中,“发送”、“发射”、“上报”、“下发”、“传输”、“双向传输”、“发送和/或接收”等术语可以相互替换。
在一些实施例中,“获取”、“获得”、“得到”、“接收”、“传输”、“双向传输”、“发送和/或接收”可以相互替换,其可以解释为从其他主体接收,从协议中获取,从高层获取,自身处理得到、自主实现等多种含义。
在一些实施例中,信息等的名称不限定于实施例中所记载的名称,“信息(information)”、“消息(message)”、“信号(signal)”、“信令(signaling)”、“报告(report)”、“配置(configuration)”、“指示(indication)”、“指令(instruction)”、“命令(command)”、“参数(parameter)”等术语可以相互替换。
步骤S2102,第二用户设备根据第一消息中的认证信息建立与第一用户设备的安全认证。
在一些实施例中,第二用户设备可以对第一消息进行解析,以获取第一消息中包含的认证信息,进而基于认证信息,与第一用户设备的建立安全认证。
在一些实施例中,第二用户设备可以使用在Key_Est_Info中交换的信息来发起与第一用户设备之间的的直接认证和密钥建立过程,以用于UE之间的相互认证。
步骤S2103,第二用户设备向第一用户设备发送第二消息。
其中,第二消息包括待验证信息,待验证信息包括第一消息中未受保护内容信息的至少一部分。
在一些实施例中,第二消息可以为直接安全模式命令(Direct Security Mode Command,DSMC)消息。
在一些实施例中,DSMC消息可以为第二用户设备向第一用户设备发送的,用于请求与第一用户设备建立通信连接的消息。
在一些实施例中,第二消息可以为直接安全模式命令DSMC消息,也可以为其他消息。本公开对此不做限定。
在一些实施例中,待验证信息可以为待第一用户设备对其安全性进行验证的信息。
在一些实施例中,待验证信息可以包括第一信息的至少一部分。比如,待验证信息可以包括测距与侧行链路定位协议RSPP元数据、目标用户信息、源用户信息、组ID、业务信息中的一项或多项。
在一些实施例中,在获取了认证信息之后,还可以根据认证信息生成第一用户设备和第二用户设备之间的中间密钥,进而使用随机数和中间密钥生成安全上下文,以通过安全上下文对第二消息进行完整性保护。
在一些实施例中,可以通过密钥派生函数(Key Derivation Function,KDF),根据认证信息中的随机数派生中间密钥。
在一些实施例中,第二消息还包括第二用户设备所使用的加密算法和密钥推导信息。
在一些实施例中,加密算法可以为对称密钥加密算法,比如数据加密标准(Data Encryption Standard,DES)算法、高级加密标准(Advanced Encryption Standard,AES)算法等。也可以为非对称密钥加密算法,比如数字签名算法(Digital Signature Algorithm,DSA)等。本公开对此不做限定。
在一些实施例中,密钥推导信息可以包括第一用户设备用于密钥推导的随机数等。
步骤S2104,第一用户设备验证第二消息中的待验证信息。
在一些实施例中,第一用户设备可以使用第一消息中包含的未受保护内容信息对待验证信息进行验证。
在一些实施例中,可以将未受保护内容信息与待验证信息进行匹配,若未受保护内容信息中包含与待验证信息相匹配的信息,则待验证信息验证通过。若待验证信息中的任一信息与未受保护内容信息中的信息不匹配,则待验证信息未通过验证。
在一些实施例中,第一用户设备也可以使用第一信息对待验证信息进行验证。
在一些实施例中,可以将第一信息与待验证信息进行匹配,若第一信息中包含与待验证信息相匹配的信息,则待验证信息验证通过。若待验证信息中的任一信息与第一信息中的信息不匹配,则待验证信息为未通过验证。
在一些实施例中,第一用户设备在接收到第二消息之后,可以先对第二消息的完整性进行验证,在第二消息的完整性通过验证的情况下,再对待验证信息进行验证。
在一些实施例中,可以使用随机数和中间密钥生成安全上下文,并通过安全上下文对第二消息进行完整性验证。
在一些实施例中,第二消息中还可以包括加密算法和密钥推导信息。从而第一用户设备还可以根据加密算法和密钥推导信息从第二消息之中解析获得待验证信息。
步骤S2105,第一用户设备向第二用户设备发送第三消息。
在一些实施例中,第三消息指示待验证信息的验证结果。
在一些实施例中,第一用户设备可以根据待验证信息的验证结果,向第二用户设备发送第三消息。
在一些实施例中,若验证结果为验证通过,则第三消息用于指示验证结果为验证通过。若验证结果为未验证通过,则第三消息用于指示验证结果为验证未通过。
在一些实施例中,验证结果为验证通过,第三消息为直接安全模式完成消息。即在验证通过的情况下,第一用户设备可以向第二用户设备发送直接安全模式完成消息。
在一些实施例中,验证结果为验证未通过,第三消息为直接安全模式拒绝消息。即在验证未通过的情况下,第一用户设备可以向第二用户设备发送直接安全模式拒绝消息。
在一些实施例中,第一用户设备可以通过生成的中间密钥及第二消息中包含的密钥推导信息,生成安全上下文,基于安全上下文对第三消息进行安全性保护。
步骤S2106,第二用户设备根据第三消息向第一用户设备发送第四消息。
在一些实施例中,第三消息为直接安全模式完成消息时,第四消息为直接通信接受消息。即第二用户设备在接收到直接安全模式完成消息时,向第一用户设备发送直接通信接受消息。
在一些实施例中,第三消息为直接安全模式拒绝消息时,第四消息为直接通信拒绝消息。即第二用户设备在接收到直接安全模式拒绝消息时,向第一用户设备发送直接通信拒绝消息。
在一些实施例中,根据第三消息指示的验证结果,向第一用户设备发送第四消息。
在一些实施例中,若第三消息指示的验证结果为通过验证,确定第四消息为直接通信接受消息,即向一用户设备发送直接通信接受消息。
在一些实施例中,若第三消息指示的验证结果为未通过验证,确定第四消息为直接通信拒绝消息,即在第三消息指示的验证结果为未通过验证时,第二用户设备向第一用户设备发送直接通信拒绝消息。
在一些实施例中,第四消息为直接通信接受消息时,直接通信连接建立成功。即第二用户设备可以向第一用户设备发送直接通信接受消息,以告诉第一用户设备成功建立通信连接。
在一些实施例中,第四消息为直接通信拒绝消息时,直接通信连接建立失败。即第二用户设备可以向第一用户设备发送直接通信拒绝消息,以告诉第一用户设备拒绝建立通信连接。
在一些实施例中,第二用户设备在接收到第一用户设备发送的直接安全模式完成消息的情况下,第二用户设备可以确定接收到并返回给第一用户设备的待验证信息是第一消息中的真实信息,没有被篡改。且第一用户设备和第二用户设备之间的安全性连接已经建立。可选地,第二用户设备可以向第一用户设备发送受安全保护的直接通信接受消息。
本公开实施例所涉及的通信方法可以包括步骤S2101~步骤S2106中的至少一者。例如,步骤S2103可以作为独立实施例来实施,步骤S2104可以作为独立实施例来实施,步骤S2103+S2104可以作为独立实施例来实施,步骤S2101+S2102+S2103+S2104+S2105可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S2101、S2102、S2103、S2104、S2106是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
在一些实施例中,步骤S2101、S2103、S2104、S2105、S2106是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
在本实施方式或实施例中,在不矛盾的情况下,各步骤可以独立、任意组合或交换顺序,可选方式或可选例可以任意组合,且可以与其他实施方式或其他实施例的任意步骤之间进行任意组合。
图3A是根据本公开实施例示出的通信处理方法的流程示意图。如图3A所示,本公开实施例涉及通信处理方法,用于第一用户设备101,上述方法包括:
步骤S3101,发送第一消息。
步骤S3101的可选实现方式可以参见图2的步骤S2101、及图2、图3A所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,第一用户设备101可以向第二用户设备102发送第一消息。但不限于此,也可以向其他用户设备发送的第一信息,比如,广播第一消息。
在一些实施例中,第一消息包括未受保护内容信息。
步骤S3102,建立与第二用户设备的安全认证。
步骤S3102的可选实现方式可以参见图2的步骤S2102、及图2所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,第二用户设备102可以为接收到第一用户设备102发送第一消息的用户设备。
步骤S3103,获取第二消息。
步骤S3103的可选实现方式可以参见图2的步骤S2103、及图2所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,第二消息包括待验证信息,待验证信息包括第一消息中未受保护内容信息的至少一部分。
在一些实施例中,第一用户设备101接收第二用户设备102发送的第二消息。但不限于此,也可以接收由其他用户设备发送的第二消息。
步骤S3104,验证第二消息中包含的待验证信息。
步骤S3104的可选实现方式可以参见图2的步骤S2104、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S3105,向第二用户设备发送第三消息。
步骤S3105的可选实现方式可以参见图2的步骤S2105、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S3106,获取第四消息。
步骤S3106的可选实现方式可以参见图2的步骤S2106、及图2所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,第一用户设备101接收第二用户设备102发送的第二消息。但不限于此,也可以接收由其他用户设备发送的第二消息。
本公开实施例所涉及的方法可以包括步骤S3101~步骤S3106中的至少一者。例如,步骤S3101+S3103+S3104可以作为独立实施例来实施,步骤S3103+S3104可以作为独立实施例来实施,步骤S3103+S3104+S3105可以作为独立实施例来实施,步骤S3101+S3103+S3104+S3105可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S3102、S3103、S3104、S3105、S3105是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
在本实施方式或实施例中,在不矛盾的情况下,各步骤可以独立、任意组合或交换顺序,可选方式或可选例可以任意组合,且可以与其他实施方式或其他实施例的任意步骤之间进行任意组合。
图3B是根据本公开实施例示出的通信处理方法的流程示意图。如图3B所示,本公开实施例涉及通信处理方法,用于第一用户设备101,上述方法包括:
步骤S3201,向第二用户设备发送第一消息。
其中,第一消息包括未受保护内容信息。
在一些实施例中,第一消息为直接通信请求DCR消息。
在一些实施例中,未受保护内容信息包括第一消息的第一信息和第二信息,第二信息为与安全保护相关的信息。
在一些实施例中,第一信息包括以下至少一项:
测距与侧行链路定位协议RSPP元数据;
目标用户信息;
源用户信息;
组标识ID;
业务信息。
在一些实施例中,第二信息包括第一用户设备的PC5安全策略信息、第一用户设备安全能力的至少一项。
步骤S3202,接收第二用户设备发送的第二消息。
其中,第二消息包括待验证信息,待验证信息包括第一消息中未受保护内容信息的至少一部分。
在一些实施例中,第二消息为DSMC消息。
步骤S3203,.验证待验证信息。
在一些实施例中,验证待验证信息,包括:
根据第一信息对待验证信息进行验证。
步骤S3204,向第二用户设备发送第三消息。
其中,第三消息用于指示待验证信息的验证结果。
在一些实施例中,验证结果为验证通过,第三消息为直接安全模式完成消息。验证结果为验证未通过,第三消息为直接安全模式拒绝消息。
步骤S3205,接收第二用户设备发送的第四消息。
在一些实施例中,接收第二用户设备发送的第四消息,其中,第四消息指示直接通信连接建立结果。
在一些实施例中,第四消息为直接通信接受消息时,直接通信连接建立成功。第四消息为直接通信拒绝消息时,直接通信连接建立失败。
关于步骤S3201-S3205的详细介绍可以参考上述实施例描述。
本公开实施例所涉及的通信处理方法可以包括步骤S3201~步骤S3205中的至少一者。例如,步骤S3201可以作为独立实施例来实施,步骤S3202可以作为独立实施例来实施,步骤S3203可以作为独立实施例来实施,步骤S3202+步骤S3203+步骤S3204可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S3201、步骤S3205是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
在本实施方式或实施例中,在不矛盾的情况下,各步骤可以独立、任意组合或交换顺序,可选方式或可选例可以任意组合。
在本实施方式或实施例中,在不矛盾的情况下,可选方式或可选例可以任意组合。
图4A是根据本公开实施例示出的通信处理方法的流程示意图。如图4A所示,本公开实施例涉及通信处理方法,用于第二用户设备102,上述方法包括:
步骤S4101,获取第一消息。
步骤S4101的可选实现方式可以参见图2的步骤S2101的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,第二用户设备102接收第一用户设备101发送的第一消息。但不限于此,也可以接收由其他用户设备发送的第一消息。
在一些实施例中,第一消息包括未受保护内容信息。
在一些实施例中,根据协议约定,获取未受保护的内容信息。
步骤S4102,根据第一消息中的认证信息建立与第一用户设备的安全认证。
步骤S4102的可选实现方式可以参见图2的步骤S2102的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4103,向第一用户设备发送第二消息。
步骤S4103的可选实现方式可以参见图2的步骤S2103的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4104,获取第三消息。
在一些实施例中,第三消息指示待验证信息的验证结果。
步骤S4104的可选实现方式可以参见图2的步骤S2105的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,第二用户设备102接收第一用户设备101发送的第三消息。但不限于此,也可以接收由其他用户设备发送的第三消息。
步骤S4105,根据第三消息向第一用户设备发送第四消息。
步骤4105的可选实现方式可以参见图2的步骤S2106、及图2所涉及的实施例中其他关联部分,此处不再赘述。
本公开实施例所涉及的方法可以包括步骤S4101~步骤S4105中的至少一者。例如,步骤S4101+S4102可以作为独立实施例来实施,步骤S4103+S4104可以作为独立实施例来实施,步骤S4103+S4104+S4105可以作为独立实施例来实施,步骤S4101+S4103+S4104+S4105可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S4102、S4103、S4104、S4105是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
在本实施方式或实施例中,在不矛盾的情况下,各步骤可以独立、任意组合或交换顺序,可选方式或可选例可以任意组合,且可以与其他实施方式或其他实施例的任意步骤之间进行任意组合。
图4B是根据本公开实施例示出的通信处理方法的流程示意图。如图4B所示,本公开实施例涉及通信处理方法,用于第二用户设备102,上述方法包括:
步骤S4201,接收第一用户设备发送的第一消息。
步骤S4201的可选实现方式可以参见图2的步骤S2101、图3A的步骤S4101的可选实现方式、及图2、图3A所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,第一消息包括未受保护内容信息。
在一些实施例中,第一消息为直接通信请求DCR消息。
在一些实施例中,未受保护内容信息包括第一消息的第一信息和第二信息,第二信息为安全保护相关的信息。
在一些实施例中,第一信息包括以下至少一项:
测距与侧行链路定位协议RSPP元数据;
目标用户信息;
源用户信息;
组标识ID;
业务信息。
在一些实施例中,第二信息包括第一用户设备的PC5安全策略信息、第一用户设备安全能力中的至少一项。
步骤S4202,向第一用户设备发送第二消息。
步骤S4202的可选实现方式可以参见图2的步骤S2103、图3A的步骤S4103的可选实现方式、及图2、图3A所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,第二消息包括待验证信息,待验证信息包括未受保护内容信息的至少一部分。
在一些实施例中,第二消息为直接安全模式命令DSMC消息。
步骤S4203,接收第一用户设备发送的第三消息。
步骤S4203的可选实现方式可以参见图2的步骤S2105、图3A的步骤S4104的可选实现方式、及图2、图3A所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,第三消息指示待验证信息的验证结果。
在一些实施例中,验证结果为验证通过,第三消息为直接安全模式完成消息。验证结果为验证未通过,第三消息为直接安全模式拒绝消息。
步骤S4204,根据第三消息向第一用户设备发送第四消息。
步骤S4204的可选实现方式可以参见图2的步骤S2106、图3A的步骤S4105的可选实现方式、及图2、图3A所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,根据第三消息指示的验证结果向第一用户设备发送第四消息。
在一些实施例中,第三消息为直接安全模式完成消息时,第四消息为直接通信接受消息。第三消息为直接安全模式拒绝消息时,第四消息为直接通信拒绝消息。
本公开实施例所涉及的通信处理方法可以包括步骤S4201~步骤S4204中的至少一者。例如,步骤S4201可以作为独立实施例来实施,步骤S4202可以作为独立实施例来实施,步骤S4203可以作为独立实施例来实施,步骤S4201+步骤S4202+步骤S4203可以作为独立实施例来实施,但不限于此。
在一些实施例中,S4201是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。
在本实施方式或实施例中,在不矛盾的情况下,各步骤可以独立、任意组合或交换顺序,可选方式或可选例可以任意组合。
在本实施方式或实施例中,在不矛盾的情况下,可选方式或可选例可以任意组合。
图5是根据本公开实施例示出的通信处理方法的流程示意图。如图5所示,本公开实施例涉及通信处理方法,用于通信系统100,通信系统100包括第一用户设备101和第二用户设备102,上述方法包括:
步骤S5101,第一用户设备发送第一消息。
其中,第一消息包括未受保护内容信息。
步骤S5102,第二用户设备向第一用户设备发送第二消息。
其中,第二消息包括待验证信息,待验证信息包括第一消息中未受保护内容信息的至少一部分。
步骤S5103,第一用户设备验证待验证信息。
步骤S5104,向第二用户设备发送第三消息。
其中,第三消息用于指示待验证信息的验证结果。
步骤S5105,第二用户设备向第一用户设备发送第四消息。
步骤S5101-步骤S5105的可选实现方式可以参见上述实施例描述。
在一些实施例中,上述方法可以包括上述通信系统侧、第一用户设备侧、第二用户设备侧等的实施例的方法,此处不再赘述。
本公开实施例所涉及的处理方法可以包括步骤S5101~步骤S5105中的至少一者。例如,步骤S5102+S5103可以作为独立实施例来实施,步骤S5101+S5102+S5103+S5104可以作为独立实施例来实施,但不限于此。
在本实施方式或实施例中,在不矛盾的情况下,各步骤可以独立、任意组合或交换顺序,可选方式或可选例可以任意组合,且可以与其他实施方式或其他实施例的任意步骤之间进行任意组合。
以下为对上述方法的示例性介绍。
步骤1、第一用户设备向第二用户设备发送直接通信请求DCR消息。该消息包括需要包含在DCR消息中的所有信息,例如RSPP元数据(用于PC5上的RSPP控制操作)、目标用户信息、组ID(用于SLPP信令群播)、第一用户设备的PC5信令安全策略等。该消息还包括终端之间的认证和安全建立所需的信息(例如密钥、随机数、key_Est_info)。
步骤2、第二用户设备使用在Key_Est_Info中交换的信息来发起与第一用户设备的直接认证和密钥建立过程以用于UE之间的相互认证。
步骤3、第二用户设备向第一用户设备发送直接安全模式命令DSMC消息,其中第二用户设备应返回接收到的DCR消息中包含的待第一用户设备验证的特定信息(如RSPP元数据、目标用户信息、组ID)。使用第二用户设备从步骤2中生成的随机数和中间密钥导出的安全上下文来对DSMC消息进行完整性保护。可选地,所使用的加密算法和将由第一用户设备用于密钥推导的随机数也包括在DSMC消息中。
步骤4、第一用户设备在接收到DSMC消息时,第一用户设备应首先检查DSMC消息上的完整性保护。如果DSMC消息的完整性得到验证,则DSMC检查返回的特定信息是否与其在DCR消息中发送的信息相匹配。如果返回的信息不匹配,则第二用户设备向第一用户设备发送指示失败原因的拒绝消息。只有当DSMC消息中的所有返回信息与DCR消息中的原始发送信息相匹配时,第二用户设备才向第一用户设备发送直接安全模式完成消息,可选的第一用户设备使用从步骤2中生成的中间密钥和从第二用户设备接收的随机数导出的安全上下文对直接安全模式完成消息进行完整性保护。
步骤5、第二用户设备在接收到完整性保护的直接安全模式完成消息时,第二用户设备可以验证接收到并返回给第一用户设备的信息是DCR消息中的真实信息,而不会被篡改,并且第一用户设备和第二用户设备之间的安全性现在已经建立。第二用户设备应向第一用户设备发送受保护的直接通信接受消息。
在本公开实施例中,部分或全部步骤、其可选实现方式可以与其他实施例中的部分或全部步骤任意组合,也可以与其他实施例的可选实现方式任意组合。
本公开实施例还提出用于实现以上任一方法的装置,例如,提出一装置,上述装置包括用以实现以上任一方法中终端所执行的各步骤的单元或模块。再如,还提出另一装置,包括用以实现以上任一方法中网络设备(例如接入网设备、核心网功能节点、核心网设备等)所执行的各步骤的单元或模块。
应理解以上装置中各单元或模块的划分仅是一种逻辑功能的划分,在实际实现时可以全部或部分集成到一个物理实体上,也可以物理上分开。此外,装置中的单元或模块可以以处理器调用软件的形式实现:例如装置包括处理器,处理器与存储器连接,存储器中存储有指令,处理器调用存储器中存储的指令,以实现以上任一方法或实现上述装置各单元或模块的功能,其中处理器例如为通用处理器,例如中央处理单元(Central Processing Unit,CPU)或微处理器,存储器为装置内的存储器或装置外的存储器。或者,装置中的单元或模块可以以硬件电路的形式实现,可以通过对硬件电路的设计实现部分或全部单元或模块的功能,上述硬件电路可以理解为一个或多个处理器;例如,在一种实现中,上述硬件电路为专用集成电路(application-specific integrated circuit,ASIC),通过对电路内元件逻辑关系的设计,实现以上部分或全部单元或模块的功能;再如,在另一种实现中,上述硬件电路为可以通过可编程逻辑器件(programmable logic device,PLD)实现,以现场可编程门阵列(Field Programmable Gate Array,FPGA)为例,其可以包括大量逻辑门电路,通过配置文件来配置逻辑门电路之间的连接关系,从而实现以上部分或全部单元或模块的功 能。以上装置的所有单元或模块可以全部通过处理器调用软件的形式实现,或全部通过硬件电路的形式实现,或部分通过处理器调用软件的形式实现,剩余部分通过硬件电路的形式实现。
在本公开实施例中,处理器是具有信号处理能力的电路,在一种实现中,处理器可以是具有指令读取与运行能力的电路,例如中央处理单元(Central Processing Unit,CPU)、微处理器、图形处理器(graphics processing unit,GPU)(可以理解为微处理器)、或数字信号处理器(digital signal processor,DSP)等;在另一种实现中,处理器可以通过硬件电路的逻辑关系实现一定功能,上述硬件电路的逻辑关系是固定的或可以重构的,例如处理器为专用集成电路(application-specific integrated circuit,ASIC)或可编程逻辑器件(programmable logic device,PLD)实现的硬件电路,例如FPGA。在可重构的硬件电路中,处理器加载配置文档,实现硬件电路配置的过程,可以理解为处理器加载指令,以实现以上部分或全部单元或模块的功能的过程。此外,还可以是针对人工智能设计的硬件电路,其可以理解为ASIC,例如神经网络处理单元(Neural Network Processing Unit,NPU)、张量处理单元(Tensor Processing Unit,TPU)、深度学习处理单元(Deep learning Processing Unit,DPU)等。
图6A是本公开实施例提出的第一用户设备的结构示意图。如图6A所示,第一用户设备6100可以包括:收发模块6101、处理模块6102等中的至少一者。在一些实施例中,收发模块,用于向第二用户设备发送第一消息,其中,第一消息包括未受保护内容信息;收发模块,还用于接收第二用户设备发送的第二消息,其中,第二消息包括待验证信息,待验证信息包括未受保护内容信息的至少一部分;处理模块,用于验证待验证信息;收发模块,用于向第二用户设备发送第三消息,其中,第三消息用于指示待验证信息的验证结果;收发模块,还用于接收第二用户设备发送的第四消息。可选地,上述处理模块用于执行以上任一方法中第一用户设备101执行的发送和/或接收等通信步骤(例如步骤S2101,但不限于此)中的至少一者,此处不再赘述。可选地,上述处理模块用于执行以上任一方法中第一用户设备101执行的其他步骤(例如步骤S2104,但不限于此)中的至少一者,此处不再赘述。
图6B是本公开实施例提出的第二用户设备的结构示意图。如图6B所示,第二用户设备6200可以包括:收发模块6201、处理模块6202等中的至少一者。在一些实施例中,上述收发模块,用于接收第一用户设备发送的第一消息,其中,第一消息包括未受保护内容信息;收发模块,还用于向第一用户设备发送第二消息,其中,第二消息包括待验证信息,待验证信息包括未受保护内容信息的至少一部分;收发模块,还用于接收第一用户设备发送的第三消息,其中,第三消息指示待验证信息的验证结果;收发模块,还用于根据第三消息向第一用户设备发送第四消息。可选地,上述收发模块用于执行以上任一方法中第二用户设备102执行的发送和/或接收等通信步骤(例如步骤S2103,但不限于此)中的至少一者,此处不再赘述。可选地,上述处理模块用于执行以上任一方法中第二用户设备101执行的其他步骤(例如步骤S2102,但不限于此)中的至少一者,此处不再赘述。
在一些实施例中,收发模块可以包括发送模块和/或接收模块,发送模块和接收模块可以是分离的,也可以集成在一起。可选地,收发模块可以与收发器相互替换。
在一些实施例中,处理模块可以是一个模块,也可以包括多个子模块。可选地,上述多个子模块分别执行处理模块所需执行的全部或部分步骤。可选地,处理模块可以与处理器相互替换。
图7A是本公开实施例提出的通信设备7100的结构示意图。通信设备7100可以是网络设备(例如接入网设备、核心网设备等),也可以是终端(例如用户设备等),也可以是支持网络设备实现以上任一方法的芯片、芯片系统、或处理器等,还可以是支持终端实现以上任一方法的芯片、芯片系统、或处理器等。通信设备7100可用于实现上述方法实施例中描述的方法,具体可以参见上述方法实施例中的说明。
如图7A所示,通信设备7100包括一个或多个处理器7101。处理器7101可以是通用处理器或者专用处理器等,例如可以是基带处理器或中央处理器。基带处理器可以用于对通信协议以及通信数据进行处理,中央处理器可以用于对通信装置(如,基站、基带芯片,终端设备、终端设备芯片,DU或CU等)进行控制,执行程序,处理程序的数据。通信设备7100用于执行以上任一方法。
在一些实施例中,通信设备7100还包括用于存储指令的一个或多个存储器7102。可选地,全部或部分存储器7102也可以处于通信设备7100之外。
在一些实施例中,通信设备7100还包括一个或多个收发器7103。在通信设备7100包括一个或多个收发器7103时,收发器7103执行上述方法中的发送和/或接收等通信步骤(例如步骤S2102,但不限于此) 中的至少一者,处理器7101执行其他步骤(例如步骤S2101,但不限于此)中的至少一者。
在一些实施例中,收发器可以包括接收器和/或发送器,接收器和发送器可以是分离的,也可以集成在一起。可选地,收发器、收发单元、收发机、收发电路等术语可以相互替换,发送器、发送单元、发送机、发送电路等术语可以相互替换,接收器、接收单元、接收机、接收电路等术语可以相互替换。
在一些实施例中,通信设备7100可以包括一个或多个接口电路7104。可选地,接口电路7104与存储器7102连接,接口电路7104可用于从存储器7102或其他装置接收信号,可用于向存储器7102或其他装置发送信号。例如,接口电路7104可读取存储器7102中存储的指令,并将该指令发送给处理器7101。
以上实施例描述中的通信设备7100可以是网络设备或者终端,但本公开中描述的通信设备7100的范围并不限于此,通信设备7100的结构可以不受图7A的限制。通信设备可以是独立的设备或者可以是较大设备的一部分。例如所述通信设备可以是:1)独立的集成电路IC,或芯片,或,芯片系统或子系统;(2)具有一个或多个IC的集合,可选地,上述IC集合也可以包括用于存储数据,程序的存储部件;(3)ASIC,例如调制解调器(Modem);(4)可嵌入在其他设备内的模块;(5)接收机、终端设备、智能终端设备、蜂窝电话、无线设备、手持机、移动单元、车载设备、网络设备、云设备、人工智能设备等等;(6)其他等等。
图7B是本公开实施例提出的芯片7200的结构示意图。对于通信设备7200可以是芯片或芯片系统的情况,可以参见图7B所示的芯片7200的结构示意图,但不限于此。
芯片7200包括一个或多个处理器7201,芯片8200用于执行以上任一方法。
在一些实施例中,芯片7200还包括一个或多个接口电路7202。可选地,接口电路7202与存储器7203连接,接口电路7202可以用于从存储器7203或其他装置接收信号,接口电路7202可用于向存储器7203或其他装置发送信号。例如,接口电路7202可读取存储器7203中存储的指令,并将该指令发送给处理器7201。
在一些实施例中,接口电路7202执行上述方法中的发送和/或接收等通信步骤(例如步骤S2102,但不限于此)中的至少一者,处理器7201执行其他步骤(例如步骤S2101,但不限于此)中的至少一者。
在一些实施例中,接口电路、接口、收发管脚、收发器等术语可以相互替换。
在一些实施例中,芯片7200还包括用于存储指令的一个或多个存储器7203。可选地,全部或部分存储器7203可以处于芯片7200之外。
本公开还提出存储介质,上述存储介质上存储有指令,当上述指令在通信设备7100上运行时,使得通信设备7100执行以上任一方法。可选地,上述存储介质是电子存储介质。可选地,上述存储介质是计算机可读存储介质,但不限于此,其也可以是其他装置可读的存储介质。可选地,上述存储介质可以是非暂时性(non-transitory)存储介质,但不限于此,其也可以是暂时性存储介质。
本公开还提出程序产品,上述程序产品被通信设备7100执行时,使得通信设备7100执行以上任一方法。可选地,上述程序产品是计算机程序产品。
本公开还提出计算机程序,当其在计算机上运行时,使得计算机执行以上任一方法。

Claims (22)

  1. 一种通信处理方法,其特征在于,所述方法由第一用户设备执行,所述方法包括:
    向第二用户设备发送第一消息,其中,所述第一消息包括未受保护内容信息;
    接收所述第二用户设备发送的第二消息,其中,所述第二消息包括待验证信息,所述待验证信息包括所述未受保护内容信息的至少一部分;
    验证所述待验证信息;
    向所述第二用户设备发送第三消息,其中,第三消息用于指示所述待验证信息的验证结果;
    接收所述第二用户设备发送的第四消息。
  2. 如权利要求1所述的方法,其特征在于,所述第一消息为直接通信请求DCR消息。
  3. 如权利要求1或2所述的方法,其特征在于,所述未受保护内容信息包括第一信息和第二信息,所述第二信息为安全保护相关的信息。
  4. 如权利要求1-3任一所述的方法,其特征在于,所述第二消息为DSMC消息。
  5. 如权利要求3所述的方法,其特征在于,所述验证所述待验证信息,包括:
    根据所述第一信息对所述待验证信息进行验证。
  6. 如权利要求1-5所述的方法,其特征在于,所述验证结果为验证通过,所述第三消息为直接安全模式完成消息;或者,所述验证结果为验证未通过,所述第三消息为直接安全模式拒绝消息。
  7. 如权利要求6所述的方法,其特征在于,所述第四消息为直接通信接受消息时,直接通信连接建立成功;或者,所述第四消息为直接通信拒绝消息时,直接通信连接建立失败。
  8. 如权利要求3所述的方法,其特征在于,所述第一信息包括以下至少一项:
    测距与侧行链路定位协议RSPP元数据;
    目标用户信息;
    源用户信息;
    组标识ID;
    业务信息。
  9. 如权利要求3所述的方法,其特征在于,所述第二信息包括所述第一用户设备的PC5安全策略信息、第一用户设备安全能力的至少一项。
  10. 一种通信处理方法,其特征在于,所述方法由第二用户设备执行,所述方法包括:
    接收第一用户设备发送的第一消息,其中,所述第一消息包括未受保护内容信息;
    向所述第一用户设备发送第二消息,其中,所述第二消息包括待验证信息,所述待验证信息包括所述未受保护内容信息的至少一部分;
    接收所述第一用户设备发送的第三消息,其中,所述第三消息指示所述待验证信息的验证结果;
    根据所述第三消息向所述第一用户设备发送第四消息。
  11. 如权利要求10所述的方法,其特征在于,所述第一消息为直接通信请求DCR消息。
  12. 如权利要求10或11所述的方法,其特征在于,所述未受保护内容信息包括第一信息和第二信息,所述第二信息为安全保护相关的信息。
  13. 如权利要求10-12任一所述的方法,其特征在于,所述第二消息为直接安全模式命令DSMC消息。
  14. 如权利要求10-13任一所述的方法,其特征在于,
    所述验证结果为验证通过,所述第三消息为直接安全模式完成消息;或者,
    所述验证结果为验证未通过,所述第三消息为直接安全模式拒绝消息。
  15. 如权利要求14所述的方法,其特征在于,
    所述第三消息为直接安全模式完成消息,所述第四消息为直接通信接受消息;或者,
    所述第三消息为直接安全模式拒绝消息,所述第四消息为直接通信拒绝消息。
  16. 如权利要求12所述的方法,其特征在于,所述第一信息包括以下至少一项:
    测距与侧行链路定位协议RSPP元数据;
    目标用户信息;
    源用户信息;
    组标识ID;
    业务信息。
  17. 如权利要求12所述的方法,其特征在于,所述第二信息包括所述第一用户设备的PC5安全策略信息、第一用户设备安全能力的至少一项。
  18. 一种第一用户设备,其特征在于,包括:
    收发模块,用于向第二用户设备发送第一消息,其中,所述第一消息包括未受保护内容信息;
    所述收发模块,还用于接收所述第二用户设备发送的第二消息,其中,所述第二消息包括待验证信息,所述待验证信息包括所述未受保护内容信息的至少一部分;
    处理模块,用于验证所述待验证信息;
    所述收发模块,用于向所述第二用户设备发送第三消息,其中,第三消息用于指示所述待验证信息的验证结果;
    所述收发模块,还用于接收所述第二用户设备发送的第四消息。
  19. 一种第二用户设备,其特征在于,包括:
    收发模块,用于接收第一用户设备发送的第一消息,其中,所述第一消息包括未受保护内容信息;
    所述收发模块,还用于向所述第一用户设备发送第二消息,其中,所述第二消息包括待验证信息,所述待验证信息包括所述未受保护内容信息的至少一部分;
    所述收发模块,还用于接收所述第一用户设备发送的第三消息,其中,所述第三消息指示所述待验证信息的验证结果;
    所述收发模块,还用于根据所述第三消息向所述第一用户设备发送第四消息。
  20. 一种通信设备,其特征在于,包括:
    一个或多处理器;
    其中,所述处理器用于调用指令以使得所述通信设备执行权利要求1-9、10-17中任一项所述的方法。
  21. 一种通信系统,其特征在于,包括:
    第一用户设备,用于实现权利要求1-9中任一项所述的通信处理方法;
    第二用户设备,用于实现权利要求10-17中任一项所述的通信处理方法。
  22. 一种存储介质,所述存储介质存储有指令,其特征在于,当所述指令在通信设备上运行时,使得所述通信设备执行如权利要求1-9、10-17中任一项所述的通信处理方法。
PCT/CN2023/106667 2023-07-10 2023-07-10 通信处理方法、用户设备 Ceased WO2025010609A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN202380010065.1A CN117397209A (zh) 2023-07-10 2023-07-10 通信处理方法、用户设备
PCT/CN2023/106667 WO2025010609A1 (zh) 2023-07-10 2023-07-10 通信处理方法、用户设备

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2023/106667 WO2025010609A1 (zh) 2023-07-10 2023-07-10 通信处理方法、用户设备

Publications (1)

Publication Number Publication Date
WO2025010609A1 true WO2025010609A1 (zh) 2025-01-16

Family

ID=89465361

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/106667 Ceased WO2025010609A1 (zh) 2023-07-10 2023-07-10 通信处理方法、用户设备

Country Status (2)

Country Link
CN (1) CN117397209A (zh)
WO (1) WO2025010609A1 (zh)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113676898A (zh) * 2020-04-30 2021-11-19 华为技术有限公司 确定安全保护方法、系统及装置
US20220360966A1 (en) * 2021-05-07 2022-11-10 Qualcomm Incorporated Secure link establishment
CN115836539A (zh) * 2020-08-14 2023-03-21 华为技术有限公司 通信方法、装置及系统
CN116325845A (zh) * 2020-10-01 2023-06-23 华为技术有限公司 一种安全通信方法、装置及系统

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113676898A (zh) * 2020-04-30 2021-11-19 华为技术有限公司 确定安全保护方法、系统及装置
CN115836539A (zh) * 2020-08-14 2023-03-21 华为技术有限公司 通信方法、装置及系统
CN116325845A (zh) * 2020-10-01 2023-06-23 华为技术有限公司 一种安全通信方法、装置及系统
US20220360966A1 (en) * 2021-05-07 2022-11-10 Qualcomm Incorporated Secure link establishment

Also Published As

Publication number Publication date
CN117397209A (zh) 2024-01-12

Similar Documents

Publication Publication Date Title
WO2025010741A1 (zh) 信息处理方法、设备、通信系统及存储介质
WO2024234313A1 (zh) 信息处理方法及装置、通信设备、通信系统、存储介质
WO2025035417A1 (zh) 信息处理方法、装置及存储介质
US20230189135A1 (en) Cell access selection method, terminal device, and network device
WO2025030300A1 (zh) 信息指示方法、第一api调用者、第一网络功能和存储介质
WO2025015513A1 (zh) 信息处理方法、终端、通信系统及存储介质
WO2025043723A1 (zh) 一种信息处理方法及其装置
WO2025010609A1 (zh) 通信处理方法、用户设备
WO2025010608A1 (zh) 通信处理方法、终端
WO2026073452A1 (zh) 通信方法、api调用者、rof、ccf、通信系统及存储介质
WO2026007146A1 (zh) 信息处理方法、通信系统及存储介质
WO2025213303A1 (zh) 信息处理方法、网络设备、终端、通信系统及存储介质
WO2026036328A1 (zh) 信息处理方法、通信设备及存储介质
WO2026060719A1 (zh) 密钥处理方法、通信设备及存储介质
WO2025054998A1 (zh) 信息处理方法、终端、通信系统及存储介质
WO2026085823A1 (zh) 数据安全处理方法、通信设备、通信系统、存储介质及程序产品
WO2026036237A1 (zh) 信息处理方法、设备、通信系统及存储介质
WO2026007409A1 (zh) 通信方法、第一网络设备、终端、通信系统和存储介质
WO2025236133A1 (zh) 用户认证方法、通信设备及存储介质
WO2025152183A1 (zh) 数据安全处理方法及通信设备、通信系统及存储介质
WO2026073453A1 (zh) 通信方法、api调用者、rof、ccf、通信系统及存储介质
WO2025091186A1 (zh) 密钥处理方法、通信设备、及存储介质
WO2026055947A1 (zh) 数据安全处理方法、通信设备、通信系统、存储介质及程序产品
WO2025236135A1 (zh) 用户认证方法、通信设备及存储介质
WO2026065134A1 (zh) 通信方法、网元、终端、设备及存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23944632

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE