WO2025152183A1 - 数据安全处理方法及通信设备、通信系统及存储介质 - Google Patents
数据安全处理方法及通信设备、通信系统及存储介质Info
- Publication number
- WO2025152183A1 WO2025152183A1 PCT/CN2024/073360 CN2024073360W WO2025152183A1 WO 2025152183 A1 WO2025152183 A1 WO 2025152183A1 CN 2024073360 W CN2024073360 W CN 2024073360W WO 2025152183 A1 WO2025152183 A1 WO 2025152183A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- key
- communication
- network device
- information
- sat
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
Definitions
- the present disclosure relates to the field of communication technology, and in particular to a data security processing method, communication equipment, communication system and storage medium.
- UE User Equipment
- UE-satellite-UE User Equipment
- UE-SAT-UE User Equipment
- UPF User Plane Function
- the embodiments of the present disclosure provide a data security processing method, a communication device, a communication system and a storage medium.
- a data security processing method is provided, wherein the method is performed by a first network device, and the method includes:
- the first key is used for a first user equipment UE and a second UE to determine a second key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE;
- the first key is sent to the first UE and the second UE.
- a data security processing method is provided, wherein the method is executed by a first terminal, and the method includes:
- a second key is determined based on the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
- a data security processing method is provided, wherein the method is performed by a core network function, and the method includes:
- First information is sent to a first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
- a data security processing method is provided, wherein the method is performed by a communication system, and the method includes:
- the core network function sends first information to the first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection;
- the first network device determines a first key; and sends the first key to the first UE and the second UE;
- the first UE and the second UE determine a second key based on the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
- a first network device wherein the first network device includes:
- a determination module is configured to determine a first key; the first key is used for a first user equipment UE and a second UE to determine a second key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE;
- a sending module is configured to send the first key to the first UE and the second UE.
- a first UE is provided, wherein the first UE includes:
- a receiving module configured to receive a first key sent by a first network device
- the determination module is configured to determine a second key according to the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
- a core network function includes:
- the sending module is configured to send first information to the first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
- a communication system including a first terminal, a first network device and a core network function, the first network device is configured to implement the data security processing method provided by the first aspect, the first terminal is configured to implement the data security processing method provided by the second aspect, and the core network function is configured to implement the data security processing method provided by the third aspect.
- a communication device wherein the communication device includes:
- a storage medium stores instructions, and when the instructions are executed on a communication device, the communication device executes the data security processing method provided by the first aspect, the second aspect or the third aspect.
- FIG1A is a schematic diagram showing an architecture of a communication system according to an exemplary embodiment
- FIG1B is a schematic diagram 1 showing a UE-SAT-UE communication scenario according to an exemplary embodiment
- FIG1C is a second schematic diagram showing a UE-SAT-UE communication scenario according to an exemplary embodiment
- FIG2 is an interactive schematic diagram showing a data security processing method according to an exemplary embodiment
- FIG3A is a schematic flow chart of a data security processing method according to an exemplary embodiment
- FIG3B is a schematic flow chart of a data security processing method according to an exemplary embodiment
- FIG4A is a schematic flow chart of a data security processing method according to an exemplary embodiment
- FIG4B is a schematic flow chart of a data security processing method according to an exemplary embodiment
- FIG4C is a schematic flow chart of a data security processing method according to an exemplary embodiment
- FIG4D is a schematic flow chart of a data security processing method according to an exemplary embodiment
- FIG5 is an interactive schematic diagram showing a data security processing method according to an exemplary embodiment
- FIG6 is a schematic diagram of a process flow of end-to-end protection of UE-SAT-UE communication according to an exemplary embodiment
- FIG7A is a schematic diagram showing the structure of a first network device according to an exemplary embodiment
- FIG7B is a schematic structural diagram of a first UE according to an exemplary embodiment
- FIG7C is a schematic diagram showing the structure of a core network function according to an exemplary embodiment
- FIG8A is a schematic diagram showing the structure of a communication device according to an exemplary embodiment
- FIG. 8B is a schematic structural diagram of a chip according to an exemplary embodiment.
- the embodiments of the present disclosure provide a data security processing method, a communication device, a communication system and a storage medium.
- the first key is used for a first user equipment UE and a second UE to determine a second key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE;
- the first key is sent to the first UE and the second UE.
- the first network device determines the first key and sends the first key to the first UE and the second UE, so that the first UE and the second UE can determine the second key based on the same first key, thereby using the same second key to achieve end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE; so that the user plane service used for UE-SAT-UE communication between the first UE and the second UE can be consistently protected on the two Uu interfaces and/or inter-satellite links of UE-SAT-UE communication, thereby reducing the situation where the first UE and the second UE cannot communicate securely due to inconsistent security protection.
- determining the first key includes:
- the first network device may use the AS layer intermediate key of the first UE and/or the AS layer intermediate key of the second UE as the third key to generate the first key based on the third key, thereby realizing the reuse of the AS layer intermediate key of the first UE and/or the second UE and reducing the number of keys that the first network device needs to store.
- the first key is determined according to the fourth key.
- the first network device can generate the fourth key according to the AS layer intermediate key of the first UE and/or the AS layer intermediate key of the second UE, and then generate the first key based on the fourth key. In this way, by introducing the fourth key, it is possible to generate a first key applicable to the UEs at both ends of the communication (the first terminal and the second terminal), ensuring the applicability of the first key.
- the first information is sent to the first UE and the second UE.
- the first information includes at least one of the following:
- the security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
- the method further includes:
- the first information sent by the first network device is received.
- the second key includes at least one of the following:
- an embodiment of the present disclosure provides a data security processing method, wherein the method is performed by a core network function, and the method includes:
- First information is sent to a first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
- the core network function may send the first information to the first network device to inform the first network device of the configuration of the core network function for the end-to-end security protection policy of the UE-SAT-UE communication between the first UE and the second UE, so that the first network device determines whether to activate or deactivate the end-to-end security protection for the UE-SAT-UE communication between the first UE and the second UE and determines whether to generate the first key.
- the core network function may send the first information to the first network device to inform the first network device of the configuration of the core network function for the end-to-end security protection policy of the UE-SAT-UE communication between the first UE and the second UE, so that the first network device determines whether to activate or deactivate the end-to-end security protection for the UE-SAT-UE communication between the first UE and the second UE and determines whether to generate the first key.
- the first information includes at least one of the following:
- the security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit PDU session between the first UE and the first network device providing service requires end-to-end security protection;
- the security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
- the method further includes:
- the first information is determined according to the session management information of the PDU session of the first UE and/or the second UE.
- an embodiment of the present disclosure provides a data security processing method, which is executed by a communication system, and the method includes:
- the core network function sends first information to the first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection;
- the first network device determines a first key; and sends the first key to the first UE and the second UE;
- the first UE and the second UE determine a second key based on the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
- an embodiment of the present disclosure provides a first network device, comprising:
- a determination module is configured to determine a first key; the first key is used for a first user equipment UE and a second UE to determine a second key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE;
- a sending module is configured to send the first key to the first UE and the second UE.
- a receiving module configured to receive a first key sent by a first network device
- the determination module is configured to determine a second key according to the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
- an embodiment of the present disclosure provides a core network function, including:
- the sending module is configured to send first information to the first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
- an embodiment of the present disclosure provides a communication system, wherein the communication system includes a first terminal, a first network device and a core network function, the first network device is configured to implement the data security processing method provided by the first aspect, the first terminal is configured to implement the data security processing method provided by the second aspect, and the core network function is configured to implement the data security processing method provided by the third aspect.
- each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined.
- a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged.
- the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined, for example, some or all of the steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
- prefixes such as “first” and “second” in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute restrictions on the position, order, priority, quantity or content of the description objects.
- the statement of the description object refers to the description in the context of the claims or embodiments, and should not constitute unnecessary restrictions due to the use of prefixes.
- the description object is a "field”
- the ordinal number before the "field” in the "first field” and the "second field” does not limit the position or order between the "fields”
- the "first” and “second” do not limit whether the "fields” they modify are in the same message, nor do they limit the order of the "first field” and the "second field”.
- the terminal may be replaced by an access network device, a core network device, or a network device.
- the access network device, the core network device, or the network device may also be configured to have a structure that has all or part of the functions of the terminal.
- acquisition of data, information, etc. may comply with the laws and regulations of the country where the data is obtained.
- Fig. 1A is a schematic diagram showing the architecture of a communication system according to an exemplary embodiment.
- the user equipment 101 may include: a first user equipment 1011 and a second user equipment 1012 .
- the user device 101 includes, for example, a mobile phone, a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control (industrial control), a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid (smart grid), a wireless terminal device in transportation safety (transportation safety), a wireless terminal device in a smart city (smart city), and at least one of a wireless terminal device in a smart home (smart home), but is not limited to these.
- a mobile phone a wearable device, an Internet of Things device, a car with communication function, a smart car, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless
- the access network device 102 can be, for example, a node or device that accesses a terminal to a wireless network.
- the access network device can include an evolved Node B (eNB), a next generation evolved Node B (ng-eNB), a next generation Node B (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, and at least one of an access node in a Wi-Fi system, but is not limited thereto.
- eNB evolved Node B
- ng-eNB next generation evolved Node B
- gNB next generation Node B
- the technical solution of the present disclosure may be applicable to the Open RAN architecture.
- the interfaces between access network devices or within access network devices involved in the embodiments of the present disclosure may become internal interfaces of Open RAN, and the processes and information interactions between these internal interfaces may be implemented through software or programs.
- the access network device may be composed of a centralized unit (central unit, CU) and a distributed unit (distributed unit, DU), wherein the CU may also be called a control unit (control unit).
- the CU-DU structure may be used to split the protocol layer of the access network device, with some functions of the protocol layer being centrally controlled by the CU, and the remaining part or all of the functions of the protocol layer being distributed in the DU, and the DU being centrally controlled by the CU, but not limited to this.
- the access network device 102 includes a first network device 1021 and/or a second network device 1022 .
- the core network device 103 may be a device including one or more core network functions 1031, etc., or may be a plurality of devices or a group of devices, each including one or more core network functions 1031.
- the core network function may be virtual or physical.
- the core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).
- EPC Evolved Packet Core
- 5GCN 5G Core Network
- NGC Next Generation Core
- the core network function 1031 is, for example, a session management function (SMF).
- SMS session management function
- the core network function 1031 is, for example, an access and mobility management function (AMF).
- AMF access and mobility management function
- the communication system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution provided by the embodiment of the present disclosure.
- a person skilled in the art can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution provided by the embodiment of the present disclosure is also applicable to similar technical problems.
- the following embodiments of the present disclosure may be applied to the communication system 100 shown in FIG1A, or part of the subject, but are not limited thereto.
- the subjects shown in FIG1A are examples, and the communication system may include all or part of the subjects in FIG1A, or may include other subjects other than FIG1A, and the number and form of the subjects are arbitrary, and the connection relationship between the subjects is an example, and the subjects may be connected or disconnected, and the connection may be in any manner, which may be a direct connection or an indirect connection, and may be a wired connection or a wireless connection.
- the embodiments of the present disclosure may be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), future radio access (FRA), new radio access technology (RAT), new radio (NR), new radio access (NX), future generation radio access (FX), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Communications Network (PLMN)
- the 5G network includes a plurality of systems, such as a 5G network, ...
- UE User Equipment
- UE-satellite-UE User Equipment
- UE-SAT-UE User Equipment
- UP user plane
- FIG. 1C is a schematic diagram 2 of a UE-SAT-UE communication scenario according to an exemplary embodiment.
- the inter-satellite link ISL
- the UE-SAT-UE communication can be extended to the coverage of more than one satellite, and the ISL can ensure that the ground connection is always available.
- the security of the uplink service carried by the Uu interface is activated based on the security policy sent from the core network equipment, which is set by the Unified Data Management (UDM) or SMF according to the specific service requested by the UE.
- the SMF determines the UP security mandatory information for the PDU session based on the following when the PDU session is established:
- the UP traffic may be at risk of being tampered with by malicious/misbehaving entities (e.g., entities between inter-satellite links), and the confidential part of the UP traffic may be at risk of being exposed to another entity (e.g., entities between inter-satellite links).
- malicious/misbehaving entities e.g., entities between inter-satellite links
- confidential part of the UP traffic may be at risk of being exposed to another entity (e.g., entities between inter-satellite links).
- the PDU session of the first UE is a PDU session transmitted locally between the first UE and the first network device providing services
- the PDU session of the second UE is a PDU session transmitted locally between the second UE and the first network device providing services.
- the first network device and the second network device may be deployed in the air, for example, on an airplane, a drone, or a satellite.
- the PDU sessions for UE-SAT-UE communication between the first UE and the second UE are two separate PDU sessions. If the first UE and the second UE have different user plane security policies, the security protection on the Uu interface of the two PDU sessions for UE-SAT-UE communication may be inconsistent.
- the protection of the user plane service carried by the ISL can only depend on the security protection of the ISL; thereby making the security protection on the Uu interface and the ISL of the two PDU sessions for UE-SAT-UE communication inconsistent.
- end-to-end security protection for UE-SAT-UE communication can be applied between the first UE and the second UE.
- the core network function determines whether the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection based on the subscription data of the first UE, the subscription data of the second UE and/or the security requirements of the services involved in the UE-SAT-UE communication between the first UE and the second UE, obtains a determination result, and sets the first information based on the determination result.
- the first information indicates that the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection, otherwise the first information indicates that the UE-SAT-UE communication between the first UE and the second UE does not require end-to-end security protection.
- the first level is higher than the second level.
- the first information includes at least one of the following:
- the core network device sends the first information to the first network device and/or the second network device.
- the first network device may determine to terminate the UE-SAT-UE communication between the first UE and the second UE; alternatively, the first network device may also determine, based on the security policy indication of the first UE or the security policy indication of the second UE, whether the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
- the first network device can re-determine whether the UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection, so that the first UE and the second UE can reach an agreement on the user plane security policy.
- the first network device when the security policy indication of the first UE is different from the security policy indication of the second UE, the first network device sends third information to the second network device; the third information is used to indicate the re-determined security policy indication of the second UE.
- the first network device may send fourth information to the second network device and the core network function; the fourth information indicates the termination of UE-SAT-UE communication between the first UE and the second UE.
- the first network device can determine to terminate the UE-SAT-UE communication between the first UE and the second UE, and inform the second network device and the core network function through the fourth information.
- the first network device activates security protection for the user plane service carried by the Uu interface of the PDU session of the first UE.
- the first network device activates security protection for the user plane service carried by the Uu interface of the PDU session of the second UE.
- the Uu interface is an interface for communication between the UE and the network device providing services.
- security protection of user plane services carried by the Uu interface of the PDU session may include at least one of the following:
- the first network device sends first information to the first UE and the second UE.
- the first network device can send the first information to the first UE and the second UE; so that the first UE and the second UE can determine whether end-to-end security protection is required for the data of UE-SAT-UE communication.
- Step S2103 The first network device determines a first key.
- the first key can be a root key used to generate the second key.
- the first information indicates that end-to-end security protection of UE-SAT-UE communication between the first UE and the second UE is not activated, and the first network device does not need to determine the first key.
- the first network device When the first UE and the second UE are served by the same network device, the first network device stores the AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE. The first network device can generate the first key according to the AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE.
- the first network device of the first UE requesting to initiate the PDU session establishment process can obtain the AS layer intermediate key of the second UE from the second network device, and generate a first key based on the AS layer intermediate key of the first UE and the AS layer intermediate key of the second UE.
- the first network device sends the first key to the second network device.
- generating the first key based on the third key includes one of the following:
- the second key comprises at least one of: an integrity key; a confidentiality key.
- the integrity key can be used to perform integrity protection on the UP service used for UE-SAT-UE communication between the first UE and the second UE to ensure that the UP service is not tampered with or damaged during transmission.
- the confidentiality key can be used to protect the confidentiality of the UP service used for UE-SAT-UE communication between the first UE and the second UE to ensure that the UP service will not be leaked to third-party devices other than the first UE and the second UE.
- the first UE determines the second key based on the first key.
- the first UE and the second UE can generate a second key based on the first key, so that the first UE and the second UE can achieve end-to-end security protection of UE-SAT-UE communication between the first UE and the second UE based on the second key.
- the first information indicates activation of user plane confidentiality protection for UE-SAT-UE communication between the first UE and the second UE, and generates a confidentiality key based on the first key.
- the first UE and the second UE receive the first information sent by the first network device to indicate the activation of the user plane confidentiality protection of the UE-SAT-UE communication between the first UE and the second UE, it means that the first network device has activated the user plane confidentiality protection of the Uu interface of the PDU session used by the first UE and the second UE for UE-SAT-UE communication; the first UE and the second UE can generate a confidentiality key based on the first key, so as to use the confidentiality key to perform confidentiality protection on the UP service used for UE-SAT-UE communication between the first UE and the second UE.
- the first information indicates activation of user plane integrity protection of UE-SAT-UE communication between the first UE and the second UE, and generates an integrity key based on the first key.
- the first UE and the second UE receive the first information sent by the first network device to indicate the activation of the user plane integrity protection of the UE-SAT-UE communication between the first UE and the second UE, it means that the first network device has activated the user plane integrity protection of the Uu interface of the PDU session used by the first UE and the second UE for UE-SAT-UE communication; the first UE and the second UE can generate an integrity key based on the first key, so as to use the integrity key to perform integrity protection on the UP service used for UE-SAT-UE communication between the first UE and the second UE.
- the second UE can generate a second key based on the first key when receiving the UP data sent by the first UE for UE-SAT-UE communication to decrypt the received UP data for UE-SAT-UE communication.
- Step S2106 The first UE and the second UE perform end-to-end security protection for the UP service used for UE-SAT-UE communication based on the second key.
- the first UE and the second UE perform integrity protection on UP traffic for UE-SAT-UE communication between the first UE and the second UE based on a confidentiality key.
- the data security processing method involved in the embodiment of the present disclosure may include at least one of steps S2101 to S2106.
- steps S2103 to S2106 may be implemented as independent embodiments
- steps S2103 to S2105 may be implemented as independent embodiments
- steps S2101 to S2105 may be implemented as independent embodiments
- steps S2101 and S2102 may be implemented as independent embodiments.
- the present invention is implemented as an independent embodiment, but is not limited thereto.
- step S2106 is optional, and one or more of these steps may be omitted or replaced in different embodiments. It is understood that, when the UP service of UE-SAT-UE communication between the first UE and the second UE does not require end-to-end security protection, the first UE and the second UE do not need to use the second key to perform security protection on the UP service of UE-SAT-UE communication.
- FIG3A is a flow chart of a data security processing method according to an exemplary embodiment. As shown in FIG3a, the embodiment of the present disclosure relates to a data security processing method, which is executed by a first network device, and the method includes:
- step S3101 can refer to the optional implementation of step S2102 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.
- step S3103 can refer to the optional implementation of step S2104 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.
- the data security processing method involved in the embodiment of the present disclosure may include at least one of steps S3101 to S3103.
- steps S3102 to S3103 may be implemented as independent embodiments
- step S3101 may be implemented as an independent embodiment, but is not limited thereto.
- step S3101 is optional, and one or more of these steps may be omitted or replaced in different embodiments.
- the first network device can generate a first key for the first UE and the second UE performing UE-SAT-UE communication, and send it to the first UE and the second UE, so that the first UE and the second UE generate a second key based on the first key; the generation process of the first key does not need to consider the first information, so the core network function does not need to send the first information to the first network device.
- step S3102 and step S3103 are optional, and one or more of these steps may be omitted or replaced in different embodiments. It is understandable that, when the first information indicates that the UE-SAT-UE communication between the first UE and the second UE does not require end-to-end security protection, the first network device does not need to determine the first key, and further does not need to send the first key to the first UE and the second UE.
- FIG3B is a flow chart of a data security processing method according to an exemplary embodiment. As shown in FIG3B , the embodiment of the present disclosure relates to a data security processing method, which is executed by a first network device, and the method includes:
- Step S3201 Determine the first key
- the first key is used by the first user equipment UE and the second UE to determine the second key.
- the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
- Step S3202 Send the first key to the first UE and the second UE.
- determining the first key comprises:
- the first key is generated according to a third key; the third key includes: an access layer AS intermediate key of the first UE and/or an AS layer intermediate key of the second UE.
- generating the first key according to the third key includes:
- the first key is determined according to the fourth key.
- the AS intermediate key of the access layer of the first UE and/or the AS intermediate key of the second UE key determining that the fourth key includes one of the following:
- the access layer AS intermediate key of the first UE and the AS layer intermediate key of the second UE are cascaded to obtain the fourth key.
- the method further comprises:
- first information sent by a core network function, where the first information is used to indicate whether to activate end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE;
- the determining of the first key comprises:
- the first information indicates activation of end-to-end security protection of UE-SAT-UE communication between the first UE and the second UE, and determination of the first key.
- the method further comprises:
- the first information is sent to the first UE and the second UE.
- the first information includes at least one of the following:
- the security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit PDU session between the first UE and the first network device providing service requires end-to-end security protection;
- the security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
- generating the first key according to the third key includes one of the following:
- a first key is generated according to the first information, the length of the first information and the third key.
- the second key includes at least one of the following:
- FIG4A is a flow chart of a data security processing method according to an exemplary embodiment. As shown in FIG4A , the embodiment of the present disclosure relates to a data security processing method, which is executed by a first UE, and the method includes:
- Step S4101 Receive a first key sent by a first network device.
- step S4101 can refer to the optional implementation of step S2104 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.
- the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
- the security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit PDU session between the first UE and the first network device providing service requires end-to-end security protection;
- the second key includes at least one of the following:
- FIG4C is a flow chart of a data security processing method according to an exemplary embodiment. As shown in FIG4C , the embodiment of the present disclosure relates to a data security processing method, which is executed by a core network function, and the method includes:
- Step S4301 Determine the first information.
- step S4301 can refer to the optional implementation of step S2101 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.
- step S4302 can refer to the optional implementation of step S2102 in Figure 2 and other related parts of the embodiment involved in Figure 2, which will not be repeated here.
- Step S4401 Send first information to a first network device.
- the security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit PDU session between the first UE and the first network device providing service requires end-to-end security protection;
- the method further comprises:
- the first information is determined according to the session management information of the PDU session of the first UE and/or the second UE.
- the first information is used to indicate whether to activate end-to-end security protection for UE-SAT-UE communication.
- Step S5104 The first UE and the second UE determine the second key based on the first key.
- the above method may include the methods of the above-mentioned communication system side, user equipment side, access network equipment side, core network equipment side, etc., which will not be repeated here.
- end-to-end protection is applied between two communicating UEs, consistent protection of UP traffic for UE-SAT-UE communication carried on two UU interfaces and ISL can be achieved.
- E2E end-to-end
- FIG. 6 is a schematic diagram of a process of end-to-end protection of UE-SAT-UE communication according to an exemplary embodiment.
- Step 1 PDU session establishment process of UE1.
- UE1 sends a PDU session establishment request to the core network device and indicates UE2 as the target UE for communication.
- the E2E security indication for UE-SAT-UE communication is sent by the core network function (such as SMF) to the access network device of UE1.
- SMF E2E security protection for UE-SAT-UE communication is determined based on session management subscription data or session management information.
- the access network device When receiving the E2E security indication, the access network device should not understand the activation of the UP security protection of the Uu interface of UE1, but will wait to receive the UP security policy during the PDU session establishment of UE2.
- Step 2 PDU session establishment process of UE1.
- the network triggers the communication requested by UE1, and UE2 initiates PDU session establishment to the core network device.
- the E2E security indication for UE-SAT-UE communication is sent by the core network function (such as SMF) to the access network device of UE2.
- SMF determines the E2E security protection for UE-SAT-UE communication based on the session management subscription data or session management information.
- the access network device determines a root key K E2E for E2E security of UE-SAT-UE communication based on the E2E security indication.
- Step 4 While activating UP security of the Uu interface for UE1 and UE2 respectively, the access network device sends an E2E security indication and a root key K E2E for UE-SAT-UE communication to UE1 and UE2.
- Step 5 UE1 and UE2 respectively determine an E2E key K UP-E2E for the UP service based on the root key received from the access network device.
- the E2E key K UP-E2E for the UP service may include a confidentiality key K UP-E2E-enc and an integrity key K UP-E2E-int .
- step 6 UE1 and UE2 use the E2E key K UP-E2E for UP services to protect the UP services exchanged between UE1 and UE2 through the access network device.
- step 5b in FIG. 6 may occur after step 6.
- KDF Key Derivation Function
- L0 length of the E2E security indication for UE-SAT-UE communication
- the access network device When UE1 and UE2 are served by the same access network device, the access network device has both the access stratum key K gNB of UE1 and the access stratum key K gNB of UE2.
- gNB1 When UE1 and UE2 are served by different access network devices (e.g., gNB1 and gNB2), gNB1 needs to send UE1's access stratum key K gNB to gNB2 so that both gNBs can calculate the concatenation or exclusive OR of UE1's access stratum key K gNB and UE2's access stratum key K gNB .
- the units or modules in the device may be implemented in the form of hardware circuits, and the functions of some or all of the units or modules may be implemented by designing the hardware circuits.
- the hardware circuits may be understood as one or more processors; for example, in one implementation, the hardware circuits are application-specific integrated circuits (ASICs), and the functions of some or all of the above units or modules may be implemented by designing the logical relationship of the components in the circuits; for another example, in another implementation, the hardware circuits may be implemented by programmable logic devices (PLDs), and Field Programmable Gate Arrays (FPGAs) may be used as an example, which may include a large number of logic gate circuits, and the connection relationship between the logic gate circuits may be configured by configuring the configuration files, thereby implementing the functions of some or all of the above units or modules. All units or modules of the above devices may be implemented in the form of software called by the processor, or in the form of hardware circuits, or in the form of software called by the processor, and the remaining part may be implemented in
- the process of the processor loading a configuration document to implement the hardware circuit configuration can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules.
- it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.
- NPU neural network processing unit
- TPU tensor processing unit
- DPU deep learning processing unit
- the determination module 7101 is configured to determine a first key; the first key is used for a first user equipment UE and a second UE to determine a second key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE;
- the sending module 7102 is configured to send the first key to the first UE and the second UE.
- the determination module may be used by the first network device to execute information determination-related steps in any data security processing method.
- the sending module can be used by the first network device to execute steps related to information sending in any data security processing method.
- the first network device may further include: a receiving module.
- the receiving module may correspond to a network interface and/or a transceiver antenna of the first network device.
- the receiving module may be used by the first network device to execute steps related to information reception in any data security processing method.
- the determination module is configured to generate the first key according to a third key; the third key includes: an access layer AS intermediate key of the first UE and/or an AS layer intermediate key of the second UE.
- the determination module is configured to determine a fourth key based on an access layer AS intermediate key of the first UE and/or an AS layer intermediate key of the second UE; and determine the first key based on the fourth key.
- the determination module is configured to perform one of the following:
- the access layer AS intermediate key of the first UE and the AS layer intermediate key of the second UE are cascaded to obtain the fourth key.
- the receiving module is configured to receive first information sent by a core network function, where the first information is used to indicate whether to activate end-to-end security protection for UE-SAT-UE communication between the first UE and the second UE;
- the determination module is configured to determine the first key based on the first information indication to activate end-to-end security protection of UE-SAT-UE communication between the first UE and the second UE.
- the sending module is configured to send the first information to the first UE and the second UE.
- the first information includes at least one of the following:
- the security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit PDU session between the first UE and the first network device providing service requires end-to-end security protection;
- the security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
- the determination module is configured to perform one of the following:
- a first key is generated according to the first information, the length of the first information and the third key.
- the second key includes at least one of the following:
- FIG7B is a schematic diagram of a structure of a first UE device according to an exemplary embodiment. As shown in FIG7B , the first UE includes:
- the receiving module 7201 is configured to receive a first key sent by a first network device
- the determination module 7202 is configured to determine a second key based on the first key; the second key is used for end-to-end security protection of user equipment to satellite to user equipment UE-SAT-UE communication between the first UE and the second UE.
- the receiving module may be used by the first UE to perform steps related to information reception in any data security processing method.
- the receiving module may correspond to a network interface and/or a transceiver antenna of the first UE.
- the determination module may be used by the first UE to perform information determination-related steps in any data security processing method.
- the first UE may further include: a sending module.
- the sending module can be used by the first network device to execute steps related to information sending in any data security processing method.
- the first key is generated according to the third key; the third key includes: an access layer AS intermediate key of the first UE and/or an AS layer intermediate key of the second UE.
- the first key is generated according to the first information and the third key; or,
- the first key is generated according to the first information, the length of the first information and the third key; the first information is used to indicate whether to activate end-to-end security protection of UE-SAT-UE communication.
- the first information includes at least one of the following:
- the security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit PDU session between the first UE and the first network device providing service requires end-to-end security protection;
- the security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
- the receiving module is configured to receive the first information sent by the first network device.
- the second key includes at least one of the following:
- FIG7C is a schematic diagram of a structure of a core network function according to an exemplary embodiment.
- the core network function includes:
- the sending module 7301 is configured to send first information to the first network device, where the first information is used to indicate whether UE-SAT-UE communication between the first UE and the second UE requires end-to-end security protection.
- the sending module can be used by the core network function to execute steps related to information sending in any data security processing method.
- the core network function may also include: a receiving module and/or a determining module.
- the receiving module can be used by the core network function to execute steps related to information reception in any data security processing method.
- the determination module may be used by the core network function to execute information determination-related steps in any data security processing method.
- the first information includes at least one of the following:
- the security policy indication of the first UE is used to indicate whether a user plane of a locally transmitted protocol data unit PDU session between the first UE and the first network device providing service requires end-to-end security protection;
- the security policy indication of the second UE is used to indicate whether the user plane of the PDU session locally transmitted between the second UE and the first network device providing service requires end-to-end security protection.
- the determination module is configured to determine the first information based on session management information of the PDU session of the first UE and/or the second UE.
- the communication device 8100 may be a network device (e.g., an access network device or a core network device, etc.), or a terminal (e.g., a user device, etc.), or a chip, a chip system, or a processor that supports the network device to implement any of the above methods, or a chip, a chip system, or a processor that supports the terminal to implement any of the above data security processing methods.
- the communication device 8100 may be used to implement the data security processing method described in the above method embodiment, and the details may refer to the description in the above method embodiment.
- the communication device 8100 includes one or more processors 8101.
- the processor 8101 may be a general-purpose processor or a dedicated processor, for example, a baseband processor or a central processing unit.
- the baseband processor may be used to process the communication protocol and the communication data
- the central processing unit may be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute a program, and process the data of the program.
- the processor 8101 is used to call instructions to enable the communication device 8100 executes any of the above communication methods.
- the communication device 8100 further includes one or more memories 8102 for storing instructions.
- the memory 8102 may also be outside the communication device 8100.
- the communication device 8100 further includes one or more transceivers 8103.
- the communication steps such as sending and receiving in the above method are executed by the transceiver 8103, and the other steps are executed by the processor 8101.
- the transceiver may include a receiver and a transmitter, and the receiver and the transmitter may be separate or integrated.
- the terms such as transceiver, transceiver unit, transceiver, transceiver circuit, etc. may be replaced with each other, the terms such as transmitter, transmission unit, transmitter, transmission circuit, etc. may be replaced with each other, and the terms such as receiver, receiving unit, receiver, receiving circuit, etc. may be replaced with each other.
- the communication device 8100 further includes one or more interface circuits 8104, which are connected to the memory 8102.
- the interface circuit 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices.
- the interface circuit 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
- the communication device 8100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 may not be limited by FIG. 8A.
- the communication device may be an independent device or may be part of a larger device.
- the communication device may be: (1) an independent integrated circuit IC, or a chip, or a chip system or subsystem; (2) a collection of one or more ICs, optionally, the above IC collection may also include a storage component for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, an intelligent terminal device, a cellular phone, a wireless device, a handheld device, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.
- Fig. 8B is a schematic diagram of the structure of a chip 8200 according to an exemplary embodiment.
- the communication device 8100 may be a chip or a chip system
- the chip 8200 includes one or more processors 8201, and the processor 8201 is used to call instructions so that the chip 8200 executes any of the above communication methods.
- the chip 8200 further includes one or more interface circuits 8202, which are connected to the memory 8203.
- the interface circuit 8202 can be used to receive signals from the memory 8203 or other devices, and the interface circuit 8202 can be used to send signals to the memory 8203 or other devices.
- the interface circuit 8202 can read the instructions stored in the memory 8203 and send the instructions to the processor 8201.
- the terms such as interface circuit, interface, transceiver pin, and transceiver can be replaced with each other.
- the chip 8200 further includes one or more memories 8203 for storing instructions.
- the memory 8203 may be outside the chip 8200.
- the present disclosure also provides a storage medium, on which instructions are stored, and when the instructions are executed on the communication device 8100, the communication device 8100 executes any of the above methods.
- the storage medium is an electronic storage medium.
- the storage medium is a computer-readable storage medium, but it can also be a storage medium readable by other devices.
- the storage medium can be a non-transitory storage medium, but it can also be a temporary storage medium.
- the present disclosure also provides a program product, and when the program product is executed by the communication device 8100, the communication device 8100 executes any one of the above communication methods.
- the program product is a computer program product.
- the present disclosure also provides a computer program, which, when executed on a computer, enables the computer to execute any one of the above communication methods.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本公开实施例提供一种数据安全处理方法及通信设备、通信系统及存储介质。所述方法由第一网络设备执行,所述方法包括:确定第一密钥;所述第一密钥用于第一用户设备UE和第二UE确定第二密钥;所述第二密钥,用于所述第一UE和所述第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护;将所述第一密钥发送给所述第一UE和所述第二UE。本公开实施例有利于实现对第一UE和第二UE之间的UE-SAT-UE通信进行端到端安全保护;使得第一UE和第二UE之间用于UE-SAT-UE通信的用户面业务能够在UE-SAT-UE通信的两个Uu接口和/或星间链路上得到一致性保护,减少出现由于安全保护不一致而导致第一UE和第二UE之间无法安全通信的情况。
Description
本公开涉及通信技术领域,尤其涉及数据安全处理方法及通信设备、通信系统及存储介质。
用户设备(User Equipment,UE)到卫星到用户设备(UE-satellite-UE,UE-SAT-UE)通信是指一个或多个服务卫星覆盖下的两个UE之间通过本地交换传输用户面(User Plane,UP)业务,而不需要经过地面网络的用户面功能(User Plane Function,UPF)。
发明内容
本公开实施例提供一种数据安全处理方法及通信设备、通信系统及存储介质。
根据本公开实施例的第一方面,提供一种数据安全处理方法,其中,所述方法由第一网络设备执行,所述方法包括:
确定第一密钥;所述第一密钥用于第一用户设备UE和第二UE确定第二密钥;所述第二密钥,用于所述第一UE和所述第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护;
将所述第一密钥发送给所述第一UE和所述第二UE。
根据本公开实施例的第二方面,提供一种数据安全处理方法,其中,所述方法由第一终端执行,所述方法包括:
接收第一网络设备发送的第一密钥;
根据所述第一密钥,确定第二密钥;所述第二密钥,用于第一UE和第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
根据本公开实施例的第三方面,提供一种数据安全处理方法,其中,所述方法由核心网功能执行,所述方法包括:
向第一网络设备发送第一信息,所述第一信息用于指示第一UE和所述第二UE之间的UE-SAT-UE通信是否需要端到端安全保护。
根据本公开实施例的第四方面,提供一种数据安全处理方法,其中,由通信系统执行,所述方法包括:
核心网功能向第一网络设备发送第一信息,所述第一信息用于指示第一UE和所述第二UE之间的UE-SAT-UE通信是否需要端到端安全保护;
所述第一网络设备确定第一密钥;将所述第一密钥发送给所述第一UE和所述第二UE;
所述第一UE和所述第二UE根据所述第一密钥,确定第二密钥;所述第二密钥,用于第一UE和第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
根据本公开实施例的第五方面,提供一种第一网络设备,其中,所述第一网络设备包括:
确定模块,被配置为确定第一密钥;所述第一密钥用于第一用户设备UE和第二UE确定第二密钥;所述第二密钥,用于所述第一UE和所述第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护;
发送模块,被配置为将所述第一密钥发送给所述第一UE和所述第二UE。
根据本公开实施例的第六方面,提供一种第一UE,其中,所述第一UE包括:
接收模块,被配置为接收第一网络设备发送的第一密钥;
确定模块,被配置为根据所述第一密钥,确定第二密钥;所述第二密钥,用于第一UE和第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
根据本公开实施例的第七方面,提供一种核心网功能,其中,所述核心网功能包括:
发送模块,被配置为向第一网络设备发送第一信息,所述第一信息用于指示第一UE和所述第二UE之间的UE-SAT-UE通信是否需要端到端安全保护。
根据本公开实施例的第八方面,提供一种通信系统,其中,所述通信系统包括第一终端、第一网络设备和核心网功能,所述第一网络设备被配置为实现第一方面提供的数据安全处理方法,所述第一终端被配置为实现第二方面提供的数据安全处理方法,所述核心网功能被配置为实现第三方面提供的数据安全处理方法。
根据本公开实施例的第九方面,提供一种通信设备,其中,所述通信设备包括:
一个或多个处理器;
其中,所述处理器用于调用指令以使得所述通信设备执行第一方面、第二方面或第三方面提供的数据安全处理方法。
根据本公开实施例的第十方面,提供一种存储介质,其中,所述存储介质存储有指令,当所述指令在通信设备上运行时,使得所述通信设备执行第一方面、第二方面或第三方面提供的数据安全处理方法。
本公开实施例提供的技术方案通过确定第一密钥,以便于第一UE和第二UE能够基于相同的第一密钥确定第二密钥;如此,在第一UE和第二UE进行UE-SAT-UE通信时,第一UE和第二UE能够使用相同的第二密钥对用户面业务进行端到端安全保护,从而使得第一UE和第二UE之间用于UE-SAT-UE通信的用户面业务能够在UE-SAT-UE通信的两个Uu接口和/或星间链路上得到一致性保护;减少出现由于安全保护不一致而导致第一UE和第二UE之间无法通信的情况。
应当理解的是,以上的一般描述和后文的细节描述仅是示例性和解释性的,并不能限制本公开实施例。
此处的附图被并入说明书中并构成本说明书的一部分,示出了符合本发明实施例,并与说明书一起用于解释本发明实施例的原理。
图1A是根据一示例性实施例示出的一种通信系统的架构示意图;
图1B是根据一示例性实施例示出的一种UE-SAT-UE通信场景的示意图一;
图1C是根据一示例性实施例示出的一种UE-SAT-UE通信场景的示意图二;
图2是根据一示例性实施例示出的一种数据安全处理方法的交互示意图;
图3A是根据一示例性实施例示出的一种数据安全处理方法的流程示意图;
图3B是根据一示例性实施例示出的一种数据安全处理方法的流程示意图;
图4A是根据一示例性实施例示出的一种数据安全处理方法的流程示意图;
图4B是根据一示例性实施例示出的一种数据安全处理方法的流程示意图;
图4C是根据一示例性实施例示出的一种数据安全处理方法的流程示意图;
图4D是根据一示例性实施例示出的一种数据安全处理方法的流程示意图;
图5是根据一示例性实施例示出的一种数据安全处理方法的交互示意图;
图6是根据一示例性实施例示出的一种UE-SAT-UE通信的端到端保护的流程示意图;
图7A是根据一示例性实施例示出的一种第一网络设备的结构示意图;
图7B是根据一示例性实施例示出的一种第一UE的结构示意图;
图7C是根据一示例性实施例示出的一种核心网功能的结构示意图;
图8A是根据一示例性实施例示出的一种通信设备的结构示意图;
图8B是根据一示例性实施例示出的一种芯片的结构示意图。
本公开实施例提供一种数据安全处理方法及通信设备、通信系统及存储介质。
第一方面,本公开实施例提供了一种数据安全处理方法,其中,所述方法由第一网络设备执行,所述方法包括:
确定第一密钥;所述第一密钥用于第一用户设备UE和第二UE确定第二密钥;所述第二密钥,用于所述第一UE和所述第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护;
将所述第一密钥发送给所述第一UE和所述第二UE。
在上述实施例中,第一网络设备通过确定第一密钥,并将第一密钥发送给第一UE和第二UE,使得第一UE和第二UE能够基于相同的第一密钥确定第二密钥,从而利用相同的第二密钥实现对第一UE和第二UE之间的UE-SAT-UE通信进行端到端安全保护;使得第一UE和第二UE之间用于UE-SAT-UE通信的用户面业务能够在UE-SAT-UE通信的两个Uu接口和/或星间链路上得到一致性保护,减少出现由于安全保护不一致而导致第一UE和第二UE之间无法安全通信的情况。
结合第一方面的一些实施例,在一些实施例中,所述确定第一密钥包括:
根据第三密钥生成所述第一密钥;所述第三密钥包括:所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥。
在上述实施例中,第一网络设备可以将第一UE的AS层中间密钥和/或第二UE的AS层中间密钥作为第三密钥,以根据第三密钥生成第一密钥,从而实现对第一UE和/或第二UE的AS层中间密钥的复用,减少第一网络设备需要存储的密钥数量。
结合第一方面的一些实施例,在一些实施例中,所述根据第三密钥生成所述第一密钥,包括:
根据所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥,确定第四密钥;
根据所述第四密钥,确定所述第一密钥。
在上述实施例中,第一网络设备可根据第一UE的AS层中间密钥和/或第二UE的AS层中间密钥,生成第四密钥,然后基于第四密钥,生成第一密钥。如此,通过引入第四密钥,使得能够生成适用于通信两端UE(第一终端、第二终端)的第一密钥;确保第一密钥的适用性。
结合第一方面的一些实施例,在一些实施例中,所述根据所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥,确定第四密钥包括以下之一:
进行所述第一UE的接入层AS中间密钥和所述第二UE的AS层中间密钥异或,得到所述第四密钥;
级联所述第一UE的接入层AS中间密钥和所述第二UE的AS层中间密钥,得到所述第四密钥。
在上述实施例中,可以通过对第一UE的AS层中间密钥和第二UE的AS层中间密钥进行级联或异或,得到能够用于生成第一密钥的第四密钥,提高生成的第四密钥的多样化。
结合第一方面的一些实施例,在一些实施例中,所述方法还包括:
接收核心网功能发送的第一信息,所述第一信息用于指示是否激活所述第一UE与所述第二UE的UE-SAT-UE通信的端到端安全保护;
所述确定第一密钥,包括:
所述第一信息指示激活所述第一UE与所述第二UE的UE-SAT-UE通信的端到端安全保护,确定所述第一密钥。
在上述实施例中,第一网络设备可接收核心网功能发送的第一信息,以根据第一信息获知核心网功能对第一UE和第二UE之间的UE-SAT-UE通信的端到端安全保护策略的配置。并在第一信息指示所述第一UE与所述第二UE的UE-SAT-UE通信需要端到端安全保护,生成所述第一密钥;在第一信息指示所述第一UE与所述第二UE的UE-SAT-UE通信不需要端到端安全保护,不生成第一密钥。如此,减少第一网络设备生成不必要的第一密钥的情况,降低功耗。
结合第一方面的一些实施例,在一些实施例中,所述方法还包括:
向所述第一UE和所述第二UE发送所述第一信息。
在上述实施例中,第一网络设备可将核心网功能发送的第一信息,发送给第一UE和第二UE,使得第一UE和第二UE获知核心网功能对第一UE和第二UE之间的UE-SAT-UE通信的端到端安全保护策略的配置;以便于第一UE和第二UE确定是否需要对UE-SAT-UE通信的数据执行端到端安全保护的操作。
结合第一方面的一些实施例,在一些实施例中,所述第一信息,包括以下至少之一:
所述第一UE的安全策略指示,用于指示所述第一UE与提供服务的第一网络设备之间本地传输的协议数据单元PDU会话的用户面是否需要端到端安全保护;
所述第二UE的安全策略指示,用于指示所述第二UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面是否需要端到端安全保护。
在上述实施例中,第一信息可包括第一UE的安全策略指示和/或第二UE的安全策略指示,从而实现以UE为粒度进行安全策略指示;使得为第一UE和/或第二UE提供服务的第一网络设备能够获知第一UE和/或第二UE与第一网络设备之间本地传输的PDU会话的用户面是否需要端到端安全保护,从而确定是否需要激活第一UE和/或第二UE的PDU会话的用户面端到端安全保护。
结合第一方面的一些实施例,在一些实施例中,所述根据第三密钥生成所述第一密钥,包括以下之一:
根据所述第一信息以及所述第三密钥生成第一密钥;
根据第一信息、第一信息的长度以及第三密钥,生成第一密钥。
在上述实施例中,第一网络设备可根据第三密钥和核心网功能发送的第一信息,生成第一密钥;或者根据第三密钥和所述第一信息以及所述第一信息的长度,生成第一密钥,从而提高生成的第一密钥的多样化。
结合第一方面的一些实施例,在一些实施例中,所述第二密钥,包括以下至少之一:
完整性密钥;
机密性密钥。
在上述实施例中,第二密钥可包括完整性密钥和/或机密性密钥,以便通过完整性密钥实现对第一UE和第二UE之间用于进行UE-SAT-UE的用户面业务的完整性保护,以降低所述用户面业务出现被篡改的风险。通过机密性密钥实现对第一UE和第二UE之间用于进行UE-SAT-UE的用户面业务的机密性保护,以降低所述用户面业务暴露的风险,提高通信的安全性。
第二方面,本公开实施例提供了一种数据安全处理方法,其中,所述方法由第一UE执行,所述方法包括:
接收第一网络设备发送的第一密钥;
根据所述第一密钥,确定第二密钥;所述第二密钥,用于第一UE和第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
在上述实施例中,第一UE可接收第一网络设备发送的第一密钥,并根据第一密钥确定第二密钥,从而利用第二密钥实现对第一UE和第二UE之间的UE-SAT-UE通信进行端到端安全保护;使得第一UE和第二UE之间用于UE-SAT-UE通信的用户面业务能够在UE-SAT-UE通信的两个Uu接口和/或星间链路上得到一致性保护,提高通信安全性。
结合第二方面的一些实施例,在一些实施例中,所述第一密钥是根据所述第三密钥生成的;所述第三密钥包括:所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥。
结合第二方面的一些实施例,在一些实施例中,所述第一密钥是根据第一信息以及所述第三密钥生成的;或者,所述第一密钥是根据所述第一信息、第一信息的长度以及第三密钥生成的;所述第一信息用于指示是否激活UE-SAT-UE通信的端到端安全保护。
结合第二方面的一些实施例,在一些实施例中,所述第一信息,包括以下至少之一:
所述第一UE的安全策略指示,用于指示所述第一UE与提供服务的第一网络设备之间本地传输的协议数据单元PDU会话的用户面是否需要端到端安全保护;
所述第二UE的安全策略指示,用于指示所述第二UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面是否需要端到端安全保护。
结合第二方面的一些实施例,在一些实施例中,所述方法还包括:
接收第一网络设备发送的所述第一信息。
结合第二方面的一些实施例,在一些实施例中,所述第二密钥,包括以下至少之一:
完整性密钥;
机密性密钥。
第三方面,本公开实施例提供了一种数据安全处理方法,其中,所述方法由核心网功能执行,所述方法包括:
向第一网络设备发送第一信息,所述第一信息用于指示第一UE和所述第二UE之间的UE-SAT-UE通信是否需要端到端安全保护。
在上述实施例中,核心网功能可向第一网络设备发送第一信息,以将核心网功能对第一UE和第二UE之间的UE-SAT-UE通信的端到端安全保护策略的配置告知给第一网络设备,使得第一网络设备确定是否激活或去激活第一UE和第二UE用于UE-SAT-UE通信的端到端安全保护以及确定是否生成第一密钥。如此,减少第一网络设备生成不必要的第一密钥的情况,降低功耗。
结合第三方面的一些实施例,在一些实施例中,所述第一信息,包括以下至少之一:
所述第一UE的安全策略指示,用于指示所述第一UE与提供服务的第一网络设备之间本地传输的协议数据单元PDU会话的用户面是否需要端到端安全保护;
所述第二UE的安全策略指示,用于指示所述第二UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面是否需要端到端安全保护。
结合第三方面的一些实施例,在一些实施例中,所述方法还包括:
根据所述第一UE和/或所述第二UE的所述PDU会话的会话管理信息,确定所述第一信息。
第四方面,本公开实施例提供了一种数据安全处理方法,其中,由通信系统执行,所述方法包括:
核心网功能向第一网络设备发送第一信息,所述第一信息用于指示第一UE和所述第二UE之间的UE-SAT-UE通信是否需要端到端安全保护;
所述第一网络设备确定第一密钥;将所述第一密钥发送给所述第一UE和所述第二UE;
所述第一UE和所述第二UE根据所述第一密钥,确定第二密钥;所述第二密钥,用于第一UE和第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
第五方面,本公开实施例提供了一种第一网络设备,其中,包括:
确定模块,被配置为确定第一密钥;所述第一密钥用于第一用户设备UE和第二UE确定第二密钥;所述第二密钥,用于所述第一UE和所述第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护;
发送模块,被配置为将所述第一密钥发送给所述第一UE和所述第二UE。
第六方面,本公开实施例提供了一种第一UE,其中,包括:
接收模块,被配置为接收第一网络设备发送的第一密钥;
确定模块,被配置为根据所述第一密钥,确定第二密钥;所述第二密钥,用于第一UE和第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
第七方面,本公开实施例提供了一种核心网功能,其中,包括:
发送模块,被配置为向第一网络设备发送第一信息,所述第一信息用于指示第一UE和所述第二UE之间的UE-SAT-UE通信是否需要端到端安全保护。
第八方面,本公开实施例提供了一种通信系统,其中,所述通信系统包括第一终端、第一网络设备和核心网功能,所述第一网络设备被配置为实现第一方面提供的数据安全处理方法,所述第一终端被配置为实现第二方面提供的数据安全处理方法,所述核心网功能被配置为实现第三方面提供的数据安全处理方法。
第九方面,本公开实施例提供了一种通信设备,所述通信设备包括:
一个或多个处理器;
其中,所述处理器用于调用指令以使得所述通信设备执行第一方面、第二方面或第三方面的可选实现方式所描述的数据安全处理方法。
第十方面,本公开实施例提供了一种存储介质,其中,所述存储介质存储有指令,当所述指令在通信设备上运行时,使得所述通信设备执行第一方面、第二方面或第三方面的可选实现方式所描述的数据安全处理方法。
第十一方面,本公开实施例提供了一种程序产品,所述程序产品被通信设备执行时,使得所述通设备执行第一方面或第二方面或第三方面的可选实现方式所描述的数据安全处理方法。
第十二方面,本公开实施例提供了一种计算机程序,当其在计算机上运行时,使得计算机执行第一方面或第二方面或第三方面的可选实现方式所描述的数据安全处理方法。
可以理解地,上述第一网络设备、第一UE、核心网功能、通信设备、通信系统、存储介质、程序产品、计算机程序均用于执行本公开实施例所提供的方法。因此,其所能达到的有益效果可以参考对应方法中的有益效果,此处不再赘述。
本公开实施例提出了一种数据安全处理方法及装置、通信设备、通信系统及存储介质。在一些实施例中,数据安全处理方法与信息处理方法、信息传输方法等术语可以相互替换,通信系统、信息处理系统等术语可以相互替换。
本公开实施例并非穷举,仅为部分实施例的示意,不作为对本公开保护范围的具体限制。在不矛盾的情况下,某一实施例中的每个步骤均可以作为独立实施例来实施,且各步骤之间可以任意组合,例如,在某一实施例中去除部分步骤后的方案也可以作为独立实施例来实施,且在某一实施例中各步骤的顺序可以任意交换,另外,某一实施例中的可选实现方式可以任意组合;此外,各实施例之间可以任意组合,例如,不同实施例的部分或全部步骤可以任意组合,某一实施例可以与其他实施例的可选实现方式任意组合。
在各本公开实施例中,如果没有特殊说明以及逻辑冲突,各实施例之间的术语和/或描述具有一致性,且可以互相引用,不同实施例中的技术特征根据其内在的逻辑关系可以组合形成新的实施例。
本公开实施例中所使用的术语只是为了描述特定实施例的目的,而并非作为对本公开的限制。
在本公开实施例中,除非另有说明,以单数形式表示的元素,如“一个”、“一种”、“该”、“上述”、“所述”、“前述”、“这一”等,可以表示“一个且只有一个”,也可以表示“一个或多个”、“至少一个”等。例如,在翻译中使用如英语中的“a”、“an”、“the”等冠词(article)的情况下,冠词之后的名词可以理解为单数表达形式,也可以理解为复数表达形式。
在本公开实施例中,“多个”是指两个或两个以上。
在一些实施例中,“至少一者(至少之一、至少一项、至少一个)(at least one of)”、“一个或多个(one or more)”、“多个(a plurality of)”、“多个(multiple)等术语可以相互替换。
在一些实施例中,“A、B中的至少一者”、“A和/或B”、“在一情况下A,在另一情况下B”、“一情况A,另一情况B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择执行(A和B被选择性执行);在一些实施例中A和B(A和B都被执行)。当有A、B、C等更多分支时也类似上述。
在一些实施例中,“A或B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择
执行(A和B被选择性执行)。当有A、B、C等更多分支时也类似上述。
本公开实施例中的“第一”、“第二”等前缀词,仅仅为了区分不同的描述对象,不对描述对象的位置、顺序、优先级、数量或内容等构成限制,对描述对象的陈述参见权利要求或实施例中上下文的描述,不应因为使用前缀词而构成多余的限制。例如,描述对象为“字段”,则“第一字段”和“第二字段”中“字段”之前的序数词并不限制“字段”之间的位置或顺序,“第一”和“第二”并不限制其修饰的“字段”是否在同一个消息中,也不限制“第一字段”和“第二字段”的先后顺序。再如,描述对象为“等级”,则“第一等级”和“第二等级”中“等级”之前的序数词并不限制“等级”之间的优先级。再如,描述对象的数量并不受序数词的限制,可以是一个或者多个,以“第一装置”为例,其中“装置”的数量可以是一个或者多个。此外,不同前缀词修饰的对象可以相同或不同,例如,描述对象为“装置”,则“第一装置”和“第二装置”可以是相同的装置或者不同的装置,其类型可以相同或不同;再如,描述对象为“信息”,则“第一信息”和“第二信息”可以是相同的信息或者不同的信息,其内容可以相同或不同。
在一些实施例中,“包括A”、“包含A”、“用于指示A”、“携带A”,可以解释为直接携带A,也可以解释为间接指示A。
在一些实施例中,“……”、“确定……”、“在……的情况下”、“在……时”、“当……时”、“若……”、“如果……”等术语可以相互替换。
在一些实施例中,“大于”、“大于或等于”、“不小于”、“多于”、“多于或等于”、“不少于”、“高于”、“高于或等于”、“不低于”、“以上”等术语可以相互替换,“小于”、“小于或等于”、“不大于”、“少于”、“少于或等于”、“不多于”、“低于”、“低于或等于”、“不高于”、“以下”等术语可以相互替换。
在一些实施例中,装置等可以解释为实体的、也可以解释为虚拟的,其名称不限定于实施例中所记载的名称,“装置”、“设备(equipment)”、“设备(device)”、“电路”、“网元”、“节点”、“功能”、“单元”、“部件(section)”、“系统”、“网络”、“芯片”、“芯片系统”、“实体”、“主体”等术语可以相互替换。
在一些实施例中,“网络”可以解释为网络中包含的装置(例如,接入网设备、核心网设备等)。
在一些实施例中,“接入网设备(access network device,AN device)”、“无线接入网设备(radio access network device,RAN device)”、“基站(base station,BS)”、“无线基站(radio base station)”、“固定台(fixed station)”、“节点(node)”、“接入点(access point)”、“发送点(transmission point,TP)”、“接收点(reception point,RP)”、“发送接收点(transmission/reception point,TRP)”、“面板(panel)”、“天线面板(antenna panel)”、“天线阵列(antenna array)”、“小区(cell)”、“宏小区(macro cell)”、“小型小区(small cell)”、“毫微微小区(femto cell)”、“微微小区(pico cell)”、“扇区(sector)”、“小区组(cell group)”、“服务小区”、“载波(carrier)”、“分量载波(component carrier)”、“带宽部分(bandwidth part,BWP)”等术语可以相互替换。
在一些实施例中,“终端(terminal)”、“终端设备(terminal device)”、“用户设备(user equipment,UE)”、“用户终端(user terminal)”、“移动台(mobile station,MS)”、“移动终端(mobile terminal,MT)”、订户站(subscriber station)、移动单元(mobile unit)、订户单元(subscriber unit)、无线单元(wireless unit)、远程单元(remote unit)、移动设备(mobile device)、无线设备(wireless device)、无线通信设备(wireless communication device)、远程设备(remote device)、移动订户站(mobile subscriber station)、接入终端(access terminal)、移动终端(mobile terminal)、无线终端(wireless terminal)、远程终端(remote terminal)、手持设备(handset)、用户代理(user agent)、移动客户端(mobile client)、客户端(client)等术语可以相互替换。
在一些实施例中,接入网设备、核心网设备、或网络设备可以被替换为终端。例如,针对将接入网设备、核心网设备、或网络设备以及终端间的通信置换为多个终端间的通信(例如,设备对设备(device-to-device,D2D)、车联网(vehicle-to-everything,V2X)等)的结构,也可以应用本公开的各实施例。在该情况下,也可以设为终端具有接入网设备所具有的全部或部分功能的结构。此外,“上行”、“下行”等术语也可以被替换为与终端间通信对应的术语(例如,“侧行(side)”)。例如,上行信道、下行信道等可以被替换为侧行信道,上行链路、下行链路等可以被替换为侧行链路。
在一些实施例中,终端可以被替换为接入网设备、核心网设备、或网络设备。在该情况下,也可以设为接入网设备、核心网设备、或网络设备具有终端所具有的全部或部分功能的结构。
在一些实施例中,获取数据、信息等可以遵照所在地国家的法律法规。
在一些实施例中,可以在得到用户同意后获取数据、信息等。
此外,本公开实施例的表格中的每一元素、每一行、或每一列均可以作为独立实施例来实施,任意元素、任意行、任意列的组合也可以作为独立实施例来实施。
图1A是根据一示例性实施例示出的一种通信系统的架构示意图。
如图1A所示,通信系统100包括用户设备(user equipment,UE)101、接入网设备102和核心网设备103。
在一些实施例中,用户设备101可包括:第一用户设备1011和第二用户设备1012。
在一些实施例中,用户设备101例如包括手机(mobile phone)、可穿戴设备、物联网设备、具备通信功能的汽车、智能汽车、平板电脑(Pad)、带无线收发功能的电脑、虚拟现实(virtual reality,VR)终端设备、增强现实(augmented reality,AR)终端设备、工业控制(industrial control)中的无线终端设备、无人驾驶(self-driving)中的无线终端设备、远程手术(remote medical surgery)中的无线终端设备、智能电网(smart grid)中的无线终端设备、运输安全(transportation safety)中的无线终端设备、智慧城市(smart city)中的无线终端设备、智慧家庭(smart home)中的无线终端设备中的至少一者,但不限于此。
在一些实施例中,接入网设备102例如可以是将终端接入到无线网络的节点或设备,接入网设备可以包括5G通信系统中的演进节点B(evolved NodeB,eNB)、下一代演进节点B(next generation eNB,ng-eNB)、下一代节点B(next generation NodeB,gNB)、节点B(node B,NB)、家庭节点B(home node B,HNB)、家庭演进节点B(home evolved nodeB,HeNB)、无线回传设备、无线网络控制器(radio network controller,RNC)、基站控制器(base station controller,BSC)、基站收发台(base transceiver station,BTS)、基带单元(base band unit,BBU)、移动交换中心、6G通信系统中的基站、开放型基站(Open RAN)、云基站(Cloud RAN)、其他通信系统中的基站、Wi-Fi系统中的接入节点中的至少一者,但不限于此。
在一些实施例中,本公开的技术方案可适用于Open RAN架构,此时,本公开实施例所涉及的接入网设备间或者接入网设备内的接口可变为Open RAN的内部接口,这些内部接口之间的流程和信息交互可以通过软件或者程序实现。
在一些实施例中,接入网设备可以由集中单元(central unit,CU)与分布式单元(distributed unit,DU)组成的,其中,CU也可以称为控制单元(control unit),采用CU-DU的结构可以将接入网设备的协议层拆分开,部分协议层的功能放在CU集中控制,剩下部分或全部协议层的功能分布在DU中,由CU集中控制DU,但不限于此。
在一些实施例中,接入网设备102包括第一网络设备1021和/或第二网络设备1022。
在一些实施例中,核心网设备103可以是一个设备,包括一个或多个核心网功能1031等,也可以是多个设备或设备群,分别包括一个或多个核心网功能1031。核心网功能可以是虚拟的,也可以是实体的。核心网例如包括演进分组核心(Evolved Packet Core,EPC)、5G核心网络(5G Core Network,5GCN)、下一代核心(Next Generation Core,NGC)中的至少一者。
在一些实施例中,核心网功能1031例如是会话管理功能(Session Management Function,SMF)。
在一些实施例中,核心网功能1031例如是接入与移动性管理功能(Access and Mobility Management Function,AMF)。
可以理解的是,本公开实施例描述的通信系统是为了更加清楚的说明本公开实施例的技术方案,并不构成对于本公开实施例提供的技术方案的限定,本领域普通技术人员可知,随着系统架构的演变和新业务场景的出现,本公开实施例提供的技术方案对于类似的技术问题同样适用。
下述本公开实施例可以应用于图1A所示的通信系统100、或部分主体,但不限于此。图1A所示的各主体是例示,通信系统可以包括图1A中的全部或部分主体,也可以包括图1A以外的其他主体,各主体数量和形态为任意,各主体之间的连接关系是例示,各主体之间可以不连接也可以连接,其连接可以是任意方式,可以是直接连接也可以是间接连接,可以是有线连接也可以是无线连接。
本公开各实施例可以应用于长期演进(Long Term Evolution,LTE)、LTE-Advanced(LTE-A)、LTE-Beyond(LTE-B)、SUPER 3G、IMT-Advanced、第四代移动通信系统(4th generation mobile communication system,4G)、)、第五代移动通信系统(5th generation mobile communication system,5G)、5G新空口(new radio,NR)、未来无线接入(Future Radio Access,FRA)、新无线接入技术(New-Radio Access Technology,RAT)、新无线(New Radio,NR)、新无线接入(New radio access,NX)、未来一代无线接入(Future generation radio access,FX)、Global System for Mobile communications(GSM(注册商标))、CDMA2000、超移动宽带(Ultra Mobile Broadband,UMB)、IEEE 802.11(Wi-Fi(注册商标))、IEEE 802.16(WiMAX(注册商标))、IEEE 802.20、超宽带(Ultra-WideBand,UWB)、蓝牙(Bluetooth(注册商标))、陆上公用移动通信网(Public Land Mobile
Network,PLMN)网络、设备到设备(Device-to-Device,D2D)系统、机器到机器(Machine to Machine,M2M)系统、物联网(Internet of Things,IoT)系统、车联网(Vehicle-to-Everything,V2X)、利用其他通信方法的系统、基于它们而扩展的下一代系统等。此外,也可以将多个系统组合(例如,LTE或者LTE-A与5G的组合等)应用。
用户设备(User Equipment,UE)到卫星到用户设备(UE-satellite-UE,UE-SAT-UE)通信是在没有用户面(User Plane,UP)业务通过地面网络的情况下,一个或多个服务卫星的覆盖下的UE之间经由本地交换的通信。
如图1B所示,图1B是根据一示例性实施例示出的一种UE-SAT-UE通信场景的示意图一。其中,图1B中两个UE处于通信中。但通信会话可以涉及2个以上的UE。
在卫星服务于一个以上小区的情况下,图1B中两个UE的服务小区可以不同。接入和移动性管理功能(Access and Mobility Management Function,AMF)是5GC唯一代表的网络功能(Network Function,NF),但可能隐含其他NF,例如会话管理功能(Session Management Function,SMF)。
如图1C所示,图1C是根据一示例性实施例示出的一种UE-SAT-UE通信场景的示意图二。如果卫星与卫星间链路连通,星间链路(Inter-Satellite Link,ISL)可以确保地面连接始终可用。在本地交换能力分布在一个以上卫星的情况下,UE-SAT-UE通信可以扩展到一个以上卫星的覆盖范围内,并且ISL可以确保地面连接始终可用。
Uu接口承载的上行业务的安全性基于从核心网设备发送的安全性策略来激活,该安全性策略由统一数据管理(Unified Data Management,UDM)或SMF根据UE请求的特定服务来设置。SMF在PDU会话建立时基于以下内容来确定用于PDU会话的UP安全性强制信息:
订阅的UP安全性策略,它是从UDM接收的会话管理(Session Management,SM)订阅消息的一部分;或者,当UDM不提供UP安全性策略时使用SMF中根据(数据网络名称(Data Network Name,DNN),单个网络切片选择辅助信息(Single Network Slice Selection Assistance Information,S-NSSAI))本地配置的UP安全性策略。
UP安全性策略指示是否应在PDU会话的UU接口处激活UP安全性保护;用于激活PDU会话的UP机密性和/或UP完整性。
根据SMF提供的UP安全性策略,如果UP安全性策略指示“必需(Required)”,接入网设备使用RRC信令为每一个数据无线承载(Data Radio Bearer,DRB)激活Uu接口的UP安全性保护。
如果UP安全性策略指示“不需要(Not needed)”,PDU会话的建立将在没有保护的情况下进行。
如果UP安全性策略指示“首选(Perferred)”,接入网设备可以决定是否激活Uu接口的UP安全性保护。但是在UP安全性策略指示“Required”或“Not needed”时,接入网设备遵循从SMF接收到的UP安全性策略。
对于使用5G网络的UE到UE通信,UE通过接入网设备与核心网设备建立单独的PDU会话,接入网设备将UE对应的UP安全性策略应用于UE单独的PDU会话,不同UE对应的UP安全性策略可以是不同的。
对于UE-SAT-UE通信,可以建立两个单独的用于UE-SAT-UE通信的PDU会话。然而如果通信的两个UE具有不同的UP安全性策略,可能导致单个UE-SAT-UE通信会话的两个Uu接口应用不同的安全性保护。在这种情况下,两个Uu接口上的安全性保护可能不一致。一个Uu接口上的较高安全性保护(例如完整性保护和机密性保护)可能会被另一个Uu接口上的较低安全性保护(例如仅完整性保护或仅机密性保护或无保护)所拒绝。
值的注意的是,Uu接口上的安全性保护终止于接入网设备,即发送UE的接入网设备对发送UE发送的上行链路UP业务进行解码,接收UE的接入网设备对发送到接收UE的下行链路UP业务进行编码。当UP业务需要在发送UE的接入网设备和接收UE的接入网设备之间的卫星间链路上传输时,通过ISL对UP业务的保护只能依赖于ISL的安全性。该安全性可能不受运营商的控制。因此,通过两个Uu接口和ISL承载的UP业务可能不会得到一致性的保护,在这种情况下,UP流量可能有被恶意/行为不端的实体(例如,卫星间链路之间的实体)篡改的风险,并且UP流量的机密部分可能有暴露给另一个实体(例如,卫星间链路之间的实体)的风险。
UE-SAT-UE通信的两个UE之间传输的UP业务缺少一致性的安全保护,存在很大的安全隐患。
图2是根据一示例性实施例示出的一种数据安全处理方法的交互示意图。如图2所示,本公开实施例涉及数据安全处理方法,用于通信系统100,方法包括:
步骤S2101:核心网功能确定第一信息。
在一些实施例中,核心网功能可以是核心网设备的网络功能。例如,核心网功能可以是SMF或
UDM。
在一些实施例中,核心网功能根据第一UE和/或第二UE的PDU会话的会话管理信息,确定第一信息。
PDU会话可以是用于第一UE和第二UE之间进行UE-SAT-UE通信的PDU会话。
这里,第一UE和第二UE是由同一个网络设备提供服务时,第一UE的PDU会话是第一UE与提供服务的第一网络设备之间本地传输的PDU会话;第二UE的PDU会话是第二UE与提供服务的第一网络设备之间本地传输的PDU会话。
需要说明的是,第一网络设备可以是为第一UE和第二UE接入网络的接入设备。
第一UE和第二UE是由不同网络设备提供服务时,第一UE的PDU会话是第一UE与提供服务的第一网络设备之间本地传输的PDU会话;第二UE的PDU会话是第二UE与提供服务的第二网络设备之间本地传输的PDU会话。
需要说明的是,第一网络设备可以是为第一UE接入网络的接入设备,第二网络设备可以是为第二UE接入网络的接入设备。
本公开实施例所涉及的第一UE和第二UE可以是但不限于是手机、可穿戴设备、车载终端、路侧单元(Road Side Unit,RSU)和/或智能家居终端。
第一网络设备和第二网络设备可以被部署在空中。例如,第一网络设备和第二网络设备被部署在飞机、无人机或卫星上。
在一些实施例中,PDU会话的会话管理信息可以用于指示PDU会话的用户面资源建立的相关参数。例如,会话管理信息可以指示PDU会话的用户面路径。
核心网功能可根据第一UE和/或第二UE的PDU会话的会话管理信息所指示的PDU会话的用户面资源建立的相关参数,确定第一信息。
在一些实施例中,核心网功能接收到第二信息,核心网功能确定第一信息;第二信息用于请求建立第一UE和第二UE进行UE-SAT-UE通信的PDU会话。
需要说明的是,第二信息可以是第一UE发送的,并经由第一网络设备转发给核心网功能。第一UE可以是发起PDU会话建立流程的发起设备。
在一些实施例中,第二信息可以是PDU会话建立请求或PDU会话更新请求。
在一些实施例中,第一信息用于指示是否激活第一UE和第二UE的UE-SAT-UE通信的端到端安全保护。
在一些实施例中,第一信息用于指示第一UE和第二UE的UE-SAT-UE通信是否需要端到端安全保护。
值的注意的是,第一UE和第二UE之间进行UE-SAT-UE通信的PDU会话是两个单独的PDU会话。如果第一UE和第二UE具有不同的用户面安全策略,可以会使得进行UE-SAT-UE通信的两个PDU会话的Uu接口上的安全保护不一致。
核心网功能通过确定第一信息,以便于第一UE和第二UE能够基于相同的第一信息,确定第一UE和第二UE之间的UE-SAT-UE通信是否需要端到端安全保护,从而使得第一UE和第二UE在用户面安全策略上达成一致;减少出现由于UE-SAT-UE通信的两个PDU会话的Uu接口上的安全保护不一致而导致无法安全通信的情况。
并且,当第一UE和第二UE是由不同网络设备提供服务时,即第一UE和第二UE之间进行UE-SAT-UE通信的用户面业务需要在第一网络设备和第二网络设备之间的ISL上传输时,ISL承载的用户面业务的保护只能取决于ISL的安全保护;从而使得进行UE-SAT-UE通信的两个PDU会话的Uu接口和ISL上的安全保护不一致。
为了实现对UE-SAT-UE通信的两个PDU会话的Uu接口和/或ISL上承载的用户面业务的一致性保护,可通过在第一UE和第二UE之间应用用于UE-SAT-UE通信的端到端安全保护。
在一些实施例中,第一信息包括安全策略指示。该安全策略指示,用于指示第一UE和第二UE之间的UE-SAT-UE通信是否需要端到端安全保护。
示例性地,该安全策略指示可包括一个或多个比特。该一个或多个比特具有第一取值,用于指示第一UE和第二UE之间的UE-SAT-UE通信需要端到端安全保护。该一个或多个比特具有第二取值,用于指示第一UE和第二UE之间的UE-SAT-UE通信无需端到端安全保护。
在一些实施例中,核心网功能根据第一UE的签约数据、第二UE的签约数据和/或第一UE和第二UE之间UE-SAT-UE通信涉及的业务的安全需求,确定第一UE和第二UE之间的UE-SAT-UE通信是否需要端到端安全保护,得到确定结果,并根据确定结果设置第一信息。
在一些实施例中,根据第一UE的签约数据和第二UE的签约数据中任意一个,确定第一UE和第二UE之间的UE-SAT-UE通信需要端到端安全保护,则第一信息指示第一UE和第二UE之间的UE-SAT-UE通信需要端到端安全保护,否则第一信息示第一UE和第二UE之间的UE-SAT-UE通信无需端到端安全保护。
在一些实施例中,根据第一UE和第二UE之间UE-SAT-UE通信涉及的业务的安全需求为第一等级,则第一信息指示第一UE和第二UE之间的UE-SAT-UE通信需要端到端安全保护。
在一些实施例中,根据第一UE和第二UE之间UE-SAT-UE通信涉及的业务的安全需求为第二等级,则第一信息指示第一UE和第二UE之间的UE-SAT-UE通信无需端到端安全保护。
第一等级高于第二等级。
在一些实施例中,第一信息包括以下至少之一:
第一UE的安全策略指示,用于指示第一UE与提供服务的第一网络设备之间本地传输的协议数据单元PDU会话的用户面是否需要端到端安全保护;
第二UE的安全策略指示,用于指示第二UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面是否需要端到端安全保护。
值的注意的是,第一UE的安全策略指示应当与第二UE的安全策略指示相同,如此才能够使得第一UE和第二UE之间进行UE-SAT-UE通信的两个PDU会话的Uu接口的安全保护一致。
在一些实施例中,所述第一信息内携带的第一UE的安全策略指示与第二UE的安全策略指示不同时,可由第一网络设备确定中止第一UE和第二UE之间进行UE-SAT-UE通信。
在一些实施例中,所述第一信息内携带的第一UE的安全策略指示与第二UE的安全策略指示不同时,也可由第一网络设备根据第一UE的安全策略指示和第一UE的安全策略指示自行确定激活或去激活第一UE和第二UE之间进行UE-SAT-UE通信的端到端安全保护。
示例性地,第一网络设备根据第一UE的安全策略指示和第一UE的安全策略确定激活或去激活第一UE和第二UE之间进行UE-SAT-UE通信的端到端安全保护可包括以下至少之一:
第一UE的安全策略指示和第二UE的安全策略中任意一个指示第一UE和第二UE之间的UE-SAT-UE通信需要端到端安全保护,确定需要指示第一UE和第二UE之间的UE-SAT-UE通信需要端到端安全保护;
第一UE的安全策略指示和第二UE的安全策略均指示第一UE和第二UE之间的UE-SAT-UE通信无需端到端安全保护,确定无需指示第一UE和第二UE之间的UE-SAT-UE通信需要端到端安全保护。
步骤S2102:核心网功能发送第一信息。
在一些实施例中,核心网功能可以是核心网设备的网络功能。例如,核心网功能可以是SMF或UDM。
在一些实施例中,核心网设备向第一网络设备和/或第二网络设备发送第一信息。
在一些实施例中,第一UE和第二UE是由同一网络设备提供服务时,核心网功能向第一网络设备发送第一信息。
在一些实施例中,第一UE和第二UE是由不同网络设备提供服务时,核心网功能向第一网络设备和第二网络设备发送第一信息。
在一些实施例中,在PDU会话建立的过程中,核心网功能向第一网络设备发送第一信息。
在一些实施例中,第一UE和第二UE是由同一个网络设备提供服务时,核心网功能向第一网络设备发送第一UE的安全策略指示和第二UE的安全策略指示。
在一些实施例中,第一网络设备接收到的第一信息携带的第一UE的安全策略指示和第二UE的安全策略指示不同时,第一网络设备可确定中止第一UE和第二UE的UE-SAT-UE通信;或者,第一网络设备也可根据第一UE的安全策略指示或第二UE的安全策略指示,自行确定第一UE和第二UE的UE-SAT-UE通信是否需要端到端安全保护。
需要说明的是,在第一信息中的第一UE的安全策略指示和第二UE的安全策略指示不一致的情况下,第一网络设备可确定中止第一UE和第二UE的UE-SAT-UE通信。或者,可由第一网络设备来确定第一UE和第二UE的UE-SAT-UE通信是否需要端到端安全保护,从而使得第一UE和第二UE在用户面安全策略上达成一致。
例如,第一网络设备可从第一UE的安全策略指示和第二UE的安全策略指示中确定出安全保护要求更高的目标指示;以便按照所述目标指示确定是否需要对第一UE和第二UE的UE-SAT-UE通信进行端到端安全保护。
又例如,第一网络设备可从第一UE的安全策略指示和第二UE的安全策略指示中确定出安全保护要求更低的目标指示;以便按照所述目标指示确定是否需要对第一UE和第二UE的UE-SAT-UE通信进行端到端安全保护。
在一些实施例中,第一UE和第二UE是由不同网络设备提供服务时,核心网功能分别向第一网络设备和第二网络设备发送第一信息。
可以理解的是,由于第一UE和第二UE分别由不同的网络设备提供服务,为了实现第一UE和第二UE进行UE-SAT-UE通信的两个PDU会话的Uu接口上的安全保护达成一致,核心网功能可分别向第一网络设备和第二网络设备发送第一信息,使得第一网络设备和第二网络设备能够基于相同的第一信息,确定第一UE和第二UE之间的UE-SAT-UE通信是否需要端到端安全保护。
在一些实施例中,第一UE和第二UE是由不同网络设备提供服务时,核心网功能向第一网络设备发送第一UE的安全策略指示,向第二网络设备发送第二UE的安全策略指示。
值的注意的是,第一网络设备在接收到第一UE的安全策略指示后,可从第二网络设备获取第二UE的安全策略指示,以便于确定第一UE的安全策略指示和第一UE的安全策略指示是否一致。
在第一UE的安全策略指示和第二UE的安全策略指示不同时,第一网络设备可确定中止第一UE和第二UE的UE-SAT-UE通信;或者,第一网络设备也可根据第一UE的安全策略指示或第二UE的安全策略指示,自行确定第一UE和第二UE的UE-SAT-UE通信是否需要端到端安全保护。
需要说明的是,在核心网功能确定出的第一UE的安全策略指示和第二UE的安全策略指示不一致的情况下,可由第一网络设备来重新确定第一UE和第二UE的UE-SAT-UE通信是否需要端到端安全保护,从而使得第一UE和第二UE在用户面安全策略上达成一致。
在一些实施例中,第一UE的安全策略指示与第二UE的安全策略指示不同时,第一网络设备向第二网络设备发送第三信息;第三信息用于指示重新确定的第二UE的安全策略指示。
可以理解的是,第一UE的安全策略指示和第二UE的安全策略指示不一致的情况下,由第一网络设备来重新确定第一UE的安全策略指示与第二UE的安全策略指示,以统一第一UE和第二UE的用户面安全策略;并通过向第二网络设备发送第三信息,以将重新确定后的第二UE的安全策略指示告知第二网络设备。
在一些实施例中,第一UE的安全策略指示与第二UE的安全策略指示不同时,第一网络设备可向第二网络设备和核心网功能发送第四信息;所述第四信息指示中止第一UE和第二UE的UE-SAT-UE通信。
可以理解的是,第一UE的安全策略指示和第二UE的安全策略指示不一致的情况下,第一网络设备可确定中止第一UE和第二UE的UE-SAT-UE通信,并通过第四信息告知第二网络设备和核心网功能。
在一些实施例中,第一UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面需要端到端安全保护时,第一网络设备激活第一UE的PDU会话的Uu接口承载的用户面业务的安全保护。
在一些实施例中,第二UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面需要端到端安全保护时,第一网络设备激活第二UE的PDU会话的Uu接口承载的用户面业务的安全保护。
需要说明的是,Uu接口是UE与提供服务的网络设备之间进行通信的接口。
在一些实施例中,PDU会话的Uu接口承载的用户面业务的安全保护,可包括以下至少之一:
PDU会话的Uu接口的用户面机密性保护;
PDU会话的Uu接口的用户面完整性保护。
在一些实施例中,第一网络设备向第一UE和第二UE发送第一信息。
可以理解的是,第一网络设备接收到核心网功能发送的第一信息后,可向第一UE和第二UE发送第一信息;以便第一UE和第二UE确定是否需要对UE-SAT-UE通信的数据进行端到端安全保护。
步骤S2103:第一网络设备确定第一密钥。
在一些实施例中,第一密钥用于第一UE和第二UE确定第二密钥;第二密钥用于第一UE和第二UE之间进行UE-SAT-UE通信的端到端安全保护。
可以理解的是,第一密钥可以是用于生成第二密钥的根密钥。
在一些实施例中,所述第一信息指示激活第一UE和第二UE的UE-SAT-UE通信的端到端安全保护,第一网络设备确定第一密钥。
需要说明的是,在第一信息指示激活第一UE和第二UE的UE-SAT-UE通信的端到端安全保护的情况下,说明第一UE和第二UE之间的UE-SAT-UE通信需要端到端安全保护,第一网络设备应生成第一密钥,发送给第一UE和第二UE。从而使得第一UE和第二UE能够基于第一密钥,生成第二密钥。如此,使得第一UE和第二UE在进行UE-SAT-UE通信时能够利用相同的第二密钥实现对用户面业务的安全保护,从而实现第一UE和第二UE的UE-SAT-UE通信的端到端安全保护。
在一些实施例中,第一信息指示不激活第一UE和第二UE的UE-SAT-UE通信的端到端安全保护,第一网络设备不需要确定第一密钥。
在第一信息指示不激活第一UE和第二UE的UA-SAT-UE通信的端到端安全保护的情况下,说明第一UE和第二UE之间的UE-SAT-UE通信不需要端到端安全保护,第一网络设备不需要生成第一密钥。如此,在不需要对第一UE和第二UE进行UE-SAT-UE通信的端到端安全保护的情况下,减少第一网络设备生成不必要的第一密钥的情况。
在一些实施例中,第一信息指示优先激活第一UE和第二UE的UE-SAT-UE通信的端到端安全保护,第一网络设备自行确定是否生成第一密钥。
值的注意的是,在第一信息指示优先激活第一UE和第二UE的UE-SAT--UE通信的端到端安全保护的情况下,说明第一UE和第二UE之间的UE-SAT-UE通信可以进行端到端安全保护,也可以不进行端到端安全保护;第一网络设备可以根据某些条件确定是否生成第一密钥。例如,第一网络设备的资源充足的情况下,第一网络设备可生成第一密钥;在第一网络设备的资源不充足的情况下,第一网络设备可不生成第一密钥。
在一些实施例中,第一网络设备可根据第三密钥生成第一密钥。
这里,第三密钥可包括:第一UE的接入层(Access Stratum,AS)中间密钥和/或第二UE的AS层中间密钥。
AS层中间密钥为用户设备与接入网设备之间进行安全保护的中间密钥。
需要说明的是,对于AS层密钥,接入与移动性管理功能(Access and Mobility Management Function,AMF)首先生成AS层中间密钥,所述AS层中间密钥为在接入网设备侧使用的中间密钥,AS层中间密钥用于在接入网设备侧生成RRC密钥(例如RRC机密性密钥KRRC_enc和/或RRC完整性密钥KRRC_int)和用户面安全密钥(例如用户面机密性密钥KUP_enc和/或用户面完整性密钥KUP_int)等AS层相关的密钥。
第一UE和第二UE是由同一个网络设备提供服务时,第一网络设备存储有第一UE的AS层中间密钥和第二UE的AS层中间密钥。第一网络设备可根据第一UE的AS层中间密钥和第二UE的AS层中间密钥,生成第一密钥。
第一UE和第二UE是由不同网络设备提供服务(例如第一网络设备和第二网络设备)时,请求发起PDU会话建立流程的第一UE的第一网络设备可从第二网络设备获取第二UE的AS层中间密钥,并根据第一UE的AS层中间密钥和第二UE的AS层中间密钥,生成第一密钥。第一网络设备将第一密钥发送给第二网络设备。
或者,第一网络设备可将第一UE的AS层中间密钥发送给第二网络设备,由第二网络设备根据第一UE的AS层中间密钥和第二UE的AS层中间密钥,生成第一密钥;并将生成的第一密钥发送给第一网络设备。
又或者,第一网络设备可将第一UE的AS层中间密钥发送给第二网络设备,第二网络设备可将第二UE的AS层中间密钥发送给第一网络设备,如此,两个网络设备均可以根据第一UE的AS层中间密钥和第二UE的AS层中间密钥,生成第一密钥。
在一些实施例中,根据第三密钥生成第一密钥,包括:
根据第一UE的AS层中间密钥和/或第二UE的AS层中间密钥,确定第四密钥;
根据第四密钥,确定第一密钥。
可以理解的是,第一网络设备可以根据第四密钥推导出第一密钥。例如,可将第四密钥作为输入密钥,基于密钥推导功能(Key Derivation Function,KDF)推导出第一密钥。
在一些实施例中,根据第一UE的AS层中间密钥和/或第二UE的AS层中间密钥,确定第四密钥,包括以下至少之一:
对第一UE的AS层中间密钥和第二UE的AS层中间密钥进行异或,得到第四密钥;
级联第一UE的AS层中间密钥和第二UE的AS层中间密钥,得到第四密钥。
通过级联第一UE的AS层中间密钥和第二UE的AS层中间密钥,得到级联结果;可将整个级联结果确定为第四密钥;或者,从级联结果中选取部分字符串作为第四密钥。
在一些实施例中,AS层中间密钥包括:第一子密钥段和第二子密钥段;其中,所述第一子密钥段内的每一个比特位高于第二子密钥段内的每一个比特位;
所述级联第一UE的AS层中间密钥和第二UE的AS层中间密钥,得到第四密钥,包括以下之一:
级联第一UE的AS层中间密钥内的第一子密钥段和第二UE的AS层中间密钥内的第一子密钥段,得到第四密钥;
级联第一UE的AS层中间密钥内的第二子密钥段和第二UE的AS层中间密钥内的第二子密钥段,得到第四密钥;
级联第一UE的AS层中间密钥内的第一子密钥段和第二UE的AS层中间密钥内的第二子密钥段,得到第四密钥;
级联第一UE的AS层中间密钥内的第二子密钥段和第二UE的AS层中间密钥内的第一子密钥段,得到第四密钥。
需要说明的是,AS层中间密钥中第一子密钥段内包含的比特位的数量与第二子密钥段内包含的比特位的数量相同。
通过将第一UE的第一子密钥段或第二子密钥段,与第二UE的第一子密钥段或第二子密钥段进行级联,使得级联得到的第四密钥的长度与AS层中间密钥的长度相同,有利于后续可以直接基于第四密钥进行密钥推导,以得到第一密钥。
在一些实施例中,所述级联第一UE的AS层中间密钥和第二UE的AS层中间密钥,得到第四密钥,包括:
将所述第一UE的AS层中间密钥分别映射到第五密钥中的奇数比特位;
将所述第二UE的AS层中间密钥分别映射到第五密钥中的偶数比特位;
基于所述第五密钥确定第四密钥。
需要说明的是,可以通过在第五密钥的多个比特位中选取预设数量的比特位,并基于预设数量的比特位确定第四密钥。这里,预设数量可以根据实际需求进行设置。例如,预设数量是由AS层中间密钥的比特位数量确定的。如此,使得级联得到的第四密钥的长度与AS层中间密钥的长度相同,有利于后续可以直接基于第四密钥进行密钥推导,以得到第一密钥。
在一些实施例中,根据第三密钥生成第一密钥包括以下之一:
根据第一信息以及第三密钥生成第一密钥;
根据第一信息、第一信息的长度以及第三密钥,生成第一密钥。
需要说明的是,第一网络设备可根据第三密钥确定第四密钥,并基于第四密钥和第一信息,生成第一密钥;或者基于第一密钥和第一信息以及第一信息的长度,生成第一密钥。
可以将第四密钥作为KDF的输入密钥,将第一信息和/或第一信息的长度作为KDF的参数,以推导出第一密钥。
步骤S2104:第一网络设备将第一密钥发送给第一UE和第二UE。
在一些实施例中,第一UE和第二UE是由同一个网络设备提供服务时,第一网络设备将第一密钥发送给第一UE和第二UE。
在一些实施例中,第一UE和第二UE是由不同网络设备提供服务时,第一网络设备将第一密钥发送给第一UE,并通过第二网络设备发送给第二UE。
需要说明的是,第一UE和第二UE是由不同网络设备提供服务时,第一密钥可以是由第一网络设备生成的;第一网络设备可将生成的第一密钥发送给第二网络设备,再由第二网络设备发送给第二UE。
在一些实施例中,第一UE和第二UE是由不同网络设备提供服务时,第一网络设备将第一密钥发送给第一UE,第二网络设备将第一密钥发送给第二UE。
需要说明的是,第一UE和第二UE是由不同网络设备提供服务时,第一网络设备和第二网络设备均可以生成第一密钥,如此,由第一网络设备将生成的第一密钥发送给第一UE,由第二网络设备将生成的第一密钥发送给第二UE。
在一些实施例中,第一网络设备激活第一UE和第二UE的PDU会话的Uu接口承载的用户面业务的安全保护时,向第一UE和第二UE发送第一密钥。
在一些实施例中,所述将第一密钥发送给第一UE和第二UE包括:
将第一信息和第一密钥发送给第一UE和第二UE。
可以理解的是,第一网络设备可以将第一密钥和第一信息一起发送给第一UE和第二UE,以减
少第一网络设备和第一UE、第二UE之间的信息交互次数,节省传输资源。
步骤S2105:第一UE根据第一密钥确定第二密钥。
在一些实施例中,第二UE根据第一密钥确定第二密钥。
可以理解的是,第一UE可以根据第一密钥推导出第二密钥。例如,可将第一密钥作为KDF的输入密钥,以推导出第二密钥。
在一些实施例中,第二密钥包括以下至少之一:完整性密钥;机密性密钥。
需要说明的是,完整性密钥可以用于对第一UE和第二UE之间用于UE-SAT-UE通信的UP业务进行完整性保护,以确保UP业务在传输过程中不被篡改或损坏。
机密性密钥可以用于对第一UE和第二UE之间用于UE-SAT-UE通信的UP业务进行机密性保护,以确保UP业务不会被泄露给除第一UE和第二UE以外的第三方设备。
在一些实施例中,第一信息指示激活第一UE和第二UE的UE-SAT-UE通信的端到端安全保护时,第一UE根据第一密钥确定第二密钥。
需要说明的是,在第一信息指示激活第一UE和第二UE的UA-SAT-UE通信的端到端安全保护时,第一UE和第二UE可以基于第一密钥生成第二密钥,以便于第一UE和第二UE能够基于第二密钥,实现第一UE和第二UE之间进行UE-SAT-UE通信的端到端安全保护。
在未接收到用于指示激活第一UE和第二UE的UA-SAT-UE通信的端到端安全保护的第一信息时,第一UE和第二UE可以不基于第一密钥生成第二密钥。如此,在不需要对第一UE和第二UE进行UE-SAT-UE通信的端到端安全保护的情况下,减少第一UE和第二UE生成不必要的第一密钥的情况。
在一些实施例中,第一信息指示激活第一UE和第二UE的UE-SAT-UE通信的用户面机密性保护,根据第一密钥生成机密性密钥。
若第一UE和第二UE接收到第一网络设备发送的用于指示激活第一UE和第二UE的UE-SAT-UE通信的用户面机密性保护的第一信息,说明第一网络设备已经激活第一UE和第二UE用于进行UE-SAT-UE通信的PDU会话的Uu接口的用户面机密性保护;第一UE和第二UE可根据第一密钥生成机密性密钥,以便利用机密性密钥对第一UE和第二UE之间用于UE-SAT-UE通信的UP业务进行机密性保护。
在一些实施例中,第一信息指示激活第一UE和第二UE的UE-SAT-UE通信的用户面完整性保护,根据第一密钥生成完整性密钥。
若第一UE和第二UE接收到第一网络设备发送的用于指示激活第一UE和第二UE的UE-SAT-UE通信的用户面完整性保护的第一信息,说明第一网络设备已经激活第一UE和第二UE用于进行UE-SAT-UE通信的PDU会话的Uu接口的用户面完整性保护;第一UE和第二UE可根据第一密钥生成完整性密钥,以便利用完整性密钥对第一UE和第二UE之间用于UE-SAT-UE通信的UP业务进行完整性保护。
在一些实施例中,第二UE可在接收到第一UE发送的用于UE-SAT-UE通信的UP数据的情况下,根据第一密钥生成第二密钥。
需要说明的是,由于第一UE发送的用于UE-SAT-UE通信的UP数据是基于第二密钥进行加密后的数据;因而第二UE可以在接收到第一UE发送的用于UE-SAT-UE通信的UP数据时,根据第一密钥生成第二密钥,以对接收的用于UE-SAT-UE通信的UP数据进行解密。
步骤S2106:第一UE和第二UE基于第二密钥对用于UE-SAT-UE通信的UP业务进行端到端安全保护。
在一些实施例中,第一UE和第二UE基于完整性密钥对第一UE和第二UE之间用于UE-SAT-UE通信的UP业务进行完整性保护。
在一些实施例中,第一UE和第二UE基于机密性密钥对第一UE和第二UE之间用于UE-SAT-UE通信的UP业务进行完整性保护。
在一些实施例中,术语“信息”可以与“消息(message)”、“信号(signal)”、“信令(signaling)”、“报告(report)”、“配置(configuration)”、“指示(indication)”、“指令(instruction)”、“命令(command)”、“信道”、“参数(parameter)”、“字段”、“数据(data)”等术语可以相互替换。
在一些实施例中,术语“发送”可以与“发射”、“上报”、“传输”等术语相互替换。
本公开实施例所涉及的数据安全处理方法可以包括步骤S2101至步骤S2106中的至少一者。例如,步骤S2103至步骤S2106可以作为独立实施例来实施,步骤S2103至步骤S2105可以作为独立实施例来实施,步骤S2101至步骤S2105可以作为独立实施例来实施,步骤S2101和步骤S2102可
以作为独立实施例来实施。但不限于此。
在一些实施例中,步骤S2101和步骤S2102是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。可以理解的是,第一网络设备可以自行为进行UE-SAT-UE通信的第一UE和第二UE,生成第一密钥,并发送给第一UE和第二UE,以便于第一UE和第二UE基于第一密钥生成第二密钥;第一密钥的生成过程无需考虑第一信息,从而核心网功能无需向第一网络设备发送第一信息。
在一些实施例中,步骤S2106是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。可以理解的是,在第一UE和第二UE之间进行UE-SAT-UE通信的UP业务不需要端到端安全保护的情况下,第一UE和第二UE不需要使用第二密钥对UE-SAT-UE通信的UP业务进行安全保护。
在一些实施例中,步骤S2103、步骤S2104、步骤S2105和步骤S2106是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。可以理解的是,在第一信息指示第一UE和第二UE之间的UE-SAT-UE通信不需要端到端安全保护的情况下,第一网络设备不需要确定第一密钥,进而也不需要向第一UE和第二UE发送第一密钥。
图3A是根据一示例性实施例示出的一种数据安全处理方法的流程示意图。如图3a所示,本公开实施例涉及数据安全处理方法,由第一网络设备执行,上述方法包括:
步骤S3101:接收核心网功能发送的第一信息。
在一些实施例中,步骤S3101的可选实现方式可以参见图2的步骤S2102的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S3102:确定第一密钥。
在一些实施例中,步骤S3102的可选实现方式可以参见图2的步骤S2103的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S3103:将第一密钥发送给第一UE和第二UE。
在一些实施例中,步骤S3103的可选实现方式可以参见图2的步骤S2104的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
本公开实施例所涉及的数据安全处理方法可以包括步骤S3101至步骤S3103中的至少一者。例如,步骤S3102至步骤S3103可以作为独立实施例来实施,步骤S3101可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S3101是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。可以理解的是,第一网络设备可以自行为进行UE-SAT-UE通信的第一UE和第二UE,生成第一密钥,并发送给第一UE和第二UE,以便于第一UE和第二UE基于第一密钥生成第二密钥;第一密钥的生成过程无需考虑第一信息,从而核心网功能无需向第一网络设备发送第一信息。
在一些实施例中,步骤S3102和步骤S3103是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。可以理解的是,在第一信息指示第一UE和第二UE之间的UE-SAT-UE通信不需要端到端安全保护的情况下,第一网络设备不需要确定第一密钥,进而也不需要向第一UE和第二UE发送第一密钥。
图3B是根据一示例性实施例示出的一种数据安全处理方法的流程示意图。如图3B所示,本公开实施例涉及数据安全处理方法,由第一网络设备执行,上述方法包括:
步骤S3201:确定第一密钥;
在一些实施例中,所述第一密钥用于第一用户设备UE和第二UE确定第二密钥。
在一些实施例中,所述第二密钥,用于所述第一UE和所述第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
步骤S3202:将第一密钥发送给第一UE和第二UE。
在一些实施例中,所述确定第一密钥包括:
根据第三密钥生成所述第一密钥;所述第三密钥包括:所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥。
在一些实施例中,所述根据第三密钥生成所述第一密钥,包括:
根据所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥,确定第四密钥;
根据所述第四密钥,确定所述第一密钥。
在一些实施例中,所述根据所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间
密钥,确定第四密钥包括以下之一:
进行所述第一UE的接入层AS中间密钥和所述第二UE的AS层中间密钥异或,得到所述第四密钥;
级联所述第一UE的接入层AS中间密钥和所述第二UE的AS层中间密钥,得到所述第四密钥。
在一些实施例中,所述方法还包括:
接收核心网功能发送的第一信息,所述第一信息用于指示是否激活所述第一UE与所述第二UE的UE-SAT-UE通信的端到端安全保护;
所述确定第一密钥,包括:
所述第一信息指示激活所述第一UE与所述第二UE的UE-SAT-UE通信的端到端安全保护,确定所述第一密钥。
在一些实施例中,所述方法还包括:
向所述第一UE和所述第二UE发送所述第一信息。
在一些实施例中,所述第一信息,包括以下至少之一:
所述第一UE的安全策略指示,用于指示所述第一UE与提供服务的第一网络设备之间本地传输的协议数据单元PDU会话的用户面是否需要端到端安全保护;
所述第二UE的安全策略指示,用于指示所述第二UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面是否需要端到端安全保护。
在一些实施例中,所述根据第三密钥生成所述第一密钥,包括以下之一:
根据所述第一信息以及所述第三密钥生成第一密钥;
根据第一信息、第一信息的长度以及第三密钥,生成第一密钥。
在一些实施例中,所述第二密钥,包括以下至少之一:
完整性密钥;
机密性密钥。
图4A是根据一示例性实施例示出的一种数据安全处理方法的流程示意图。如图4A所示,本公开实施例涉及数据安全处理方法,由第一UE执行,上述方法包括:
步骤S4101:接收第一网络设备发送的第一密钥。
在一些实施例中,步骤S4101的可选实现方式可以参见图2的步骤S2104的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4102:根据第一密钥确定第二密钥。
在一些实施例中,步骤S4102的可选实现方式可以参见图2的步骤S2105的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4103:基于第二密钥对用于UE-SAT-UE通信的的UP业务进行端到端安全保护。
在一些实施例中,步骤S4103的可选实现方式可以参见图2的步骤S2106的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
本公开实施例所涉及的数据安全处理方法可以包括步骤S4101至步骤S4103中的至少一者。例如,步骤S4101至步骤S4102可以作为独立实施例来实施,但不限于此。
在一些实施例中,步骤S4103是可选的,在不同实施例中可以对这些步骤中的一个或多个步骤进行省略或替代。可以理解的是,在第一UE和第二UE之间进行UE-SAT-UE通信的UP业务不需要端到端安全保护的情况下,第一UE和第二UE不需要使用第二密钥对UE-SAT-UE通信的UP业务进行安全保护。
图4B是根据一示例性实施例示出的一种数据安全处理方法的流程示意图。如图4B所示,本公开实施例涉及数据安全处理方法,由第一UE执行,上述方法包括:
步骤S4201:接收第一网络设备发送的第一密钥。
步骤S4202:根据所述第一密钥,确定第二密钥。
在一些实施例中,所述第二密钥,用于第一UE和第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
在一些实施例中,所述第一密钥是根据所述第三密钥生成的;所述第三密钥包括:所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥。
在一些实施例中,所述第一密钥是根据第一信息以及所述第三密钥生成的;或者,所述第一密钥是根据所述第一信息、第一信息的长度以及第三密钥生成的;所述第一信息用于指示是否激活UE-SAT-UE通信的端到端安全保护。
在一些实施例中,所述第一信息,包括以下至少之一:
所述第一UE的安全策略指示,用于指示所述第一UE与提供服务的第一网络设备之间本地传输的协议数据单元PDU会话的用户面是否需要端到端安全保护;
所述第二UE的安全策略指示,用于指示所述第二UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面是否需要端到端安全保护。
在一些实施例中,所述方法还包括:
接收第一网络设备发送的所述第一信息。
结合第二方面的一些实施例,在一些实施例中,所述第二密钥,包括以下至少之一:
完整性密钥;
机密性密钥。
图4C是根据一示例性实施例示出的一种数据安全处理方法的流程示意图。如图4C所示,本公开实施例涉及数据安全处理方法,由核心网功能执行,上述方法包括:
步骤S4301:确定第一信息。
在一些实施例中,步骤S4301的可选实现方式可以参见图2的步骤S2101的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S4302:向第一网络设备发送第一信息。
在一些实施例中,步骤S4302的可选实现方式可以参见图2的步骤S2102的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
图4D是根据一示例性实施例示出的一种数据安全处理方法的流程示意图。如图4D所示,本公开实施例涉及数据安全处理方法,由核心网功能执行,上述方法包括:
步骤S4401:向第一网络设备发送第一信息。
在一些实施例中,所述第一信息用于指示第一UE和所述第二UE之间的UE-SAT-UE通信是否需要端到端安全保护。
在一些实施例中,所述第一信息,包括以下至少之一:
所述第一UE的安全策略指示,用于指示所述第一UE与提供服务的第一网络设备之间本地传输的协议数据单元PDU会话的用户面是否需要端到端安全保护;
所述第二UE的安全策略指示,用于指示所述第二UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面是否需要端到端安全保护。
在一些实施例中,所述方法还包括:
根据所述第一UE和/或所述第二UE的所述PDU会话的会话管理信息,确定所述第一信息。
图5是根据一示例性实施例示出的一种数据安全处理方法的交互示意图。如图5所示,本公开实施例涉及数据安全处理方法,用于通信系统100,方法包括以下步骤之一:
步骤S5101:核心网功能向第一网络设备发送第一信息。
在一些实施例中,所述第一信息用于指示是否激活UE-SAT-UE通信的端到端安全保护。
步骤S5102:第一网络设备确定第一密钥。
在一些实施例中,所述第一信息指示激活UE-SAT-UE通信的端到端安全保护,确定所述第一密钥。
步骤S5103:第一网络设备将第一密钥发送给第一UE和第二UE。
步骤S5104:第一UE和第二UE根据第一密钥确定第二密钥。
在一些实施例中,所述第二密钥,用于第一UE和第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
在一些实施例中,上述方法可以包括上述通信系统侧、用户设备侧、接入网设备侧、核心网设备侧等实施例的方法,此处不再赘述。
在一些实施例中,如果在两个通信UE之间应用端到端保护,可以实现对在两个UU接口和ISL承载的用于UE-SAT-UE通信的UP业务的一致性保护。目前还没有对UE-SAT-UE通信的UP流量进行端到端(End-to-End,E2E)保护的解决方案。
如图6所示,图6是根据一示例性实施例示出的一种UE-SAT-UE通信的端到端保护的流程示意图。
步骤1,UE1的PDU会话建立过程。
UE1向核心网设备发送PDU会话建立请求,并将UE2指示为用于通信的目标UE。在该过程中,用于UE-SAT-UE通信的E2E安全性指示由核心网功能(例如SMF)发送到UE1的接入网设备。SMF
根据会话管理订阅数据或会话管理信息来确定用于UE-SAT-UE通信的E2E安全性保护。
接入网设备在接收到E2E安全性指示时,不应理解激活UE1的Uu接口的UP安全性保护,而是将在UE2的PDU会话建立期间等待接收到UP安全性策略。
步骤2,UE1的PDU会话建立过程。
由网络触发进行UE1请求的通信,UE2向核心网设备发起PDU会话建立。在该过程中,用于UE-SAT-UE通信的E2E安全性指示由核心网功能(例如SMF)发送到UE2的接入网设备。SMF根据会话管理订阅数据或会话管理信息来确定用于UE-SAT-UE通信的E2E安全性保护。
步骤3,接入网设备确定用于UE-SAT-UE通信的E2E安全性的根密钥KE2E。
接入网设备基于E2E安全性指示确定用于UE-SAT-UE通信的E2E安全性的根密钥KE2E。
步骤4,在分别为UE1和UE2激活Uu接口的UP安全性的同时,接入网设备向UE1和UE2发送用于UE-SAT-UE通信的E2E安全性指示和根密钥KE2E。
步骤5,UE1和UE2基于从接入网设备接收的根密钥,分别确定出用于UP业务的E2E密钥KUP-E2E。
这里,用于UP业务的E2E密钥KUP-E2E可包括机密性密钥KUP-E2E-enc和完整性密钥KUP-E2E-int。
步骤6,UE1和UE2使用用于UP业务的E2E密钥KUP-E2E保护通过接入网设备在UE1和UE2之间交换的UP业务。
值的注意的是,图6中的步骤5b可以是发生在步骤6之后。
对于E2E安全性的根密钥KE2E的确定。
当接入网设备推导根密钥KE2E时,应使用以下参数形成密钥推导功能(Key Derivation Function,KDF)的输入参数:
FC=TBD;
P0=用于UE-SAT-UE通信的E2E安全性指示;
L0=用于UE-SAT-UE通信的E2E安全性指示的长度;
输入密钥可以是:
UE1的接入层密钥KgNB和UE2的接入层密钥KgNB的级联;例如,KgNB(UE1)||KgNB(UE2);或者,
UE1的接入层密钥KgNB和UE2的接入层密钥KgNB的异或;例如
当UE1和UE2由同一接入网设备提供服务时,该接入网设备同时具有UE1的接入层密钥KgNB和UE2的接入层密钥KgNB。
当UE1和UE2由不同接入网设备提供服务(例如gNB1和gNB2)时,gNB1需要向gNB2发送UE1的接入层密钥KgNB,使得两个gNB都可以计算UE1的接入层密钥KgNB和UE2的接入层密钥KgNB的级联或异或。
本公开实施例还提供用于实现以上任一方法的装置,例如,提供一种装置,上述装置包括用以实现以上任一种方法中终端所执行的各步骤的单元或模块。再如,还提供另一种装置,包括用以实现以上任一种方法中网络设备(例如,接入网设备、或者核心网设备等)所执行的各步骤的单元或模块。
应理解以上装置中各单元或模块的划分仅是一种逻辑功能的划分,在实际实现时可以全部或部分集成到一个物理实体上,也可以物理上分开。此外,装置中的单元或模块可以以处理器调用软件的形式实现:例如装置包括处理器,处理器与存储器连接,存储器中存储有指令,处理器调用存储器中存储的指令,以实现以上任一种方法或实现上述装置各单元或模块的功能,其中处理器例如为通用处理器,例如中央处理单元(Central Processing Unit,CPU)或微处理器,存储器为装置内的存储器或装置外的存储器。或者,装置中的单元或模块可以以硬件电路的形式实现,可以通过对硬件电路的设计实现部分或全部单元或模块的功能,上述硬件电路可以理解为一个或多个处理器;例如,在一种实现中,上述硬件电路为专用集成电路(application-specific integrated circuit,ASIC),通过对电路内元件逻辑关系的设计,实现以上部分或全部单元或模块的功能;再如,在另一种实现中,上述硬件电路为可以通过可编程逻辑器件(programmable logic device,PLD)实现,以现场可编程门阵列(Field Programmable Gate Array,FPGA)为例,其可以包括大量逻辑门电路,通过配置文件来配置逻辑门电路之间的连接关系,从而实现以上部分或全部单元或模块的功能。以上装置的所有单元或模块可以全部通过处理器调用软件的形式实现,或全部通过硬件电路的形式实现,或部分通过处理器调用软件的形式实现,剩余部分通过硬件电路的形式实现。
在本公开实施例中,处理器是一种具有信号处理能力的电路,在一种实现中,处理器可以是具
有指令读取与运行能力的电路,例如中央处理单元(Central Processing Unit,CPU)、微处理器、图形处理器(graphics processing unit,GPU)(可以理解为一种微处理器)、或数字信号处理器(digital signal processor,DSP)等;在另一种实现中,处理器可以通过硬件电路的逻辑关系实现一定功能,上述硬件电路的逻辑关系是固定的或可以重构的,例如处理器为专用集成电路(application-specific integrated circuit,ASIC)或可编程逻辑器件(programmable logic device,PLD)实现的硬件电路,例如FPGA。在可重构的硬件电路中,处理器加载配置文档,实现硬件电路配置的过程,可以理解为处理器加载指令,以实现以上部分或全部单元或模块的功能的过程。此外,还可以是针对人工智能设计的硬件电路,其可以理解为一种ASIC,例如神经网络处理单元(Neural Network Processing Unit,NPU)、张量处理单元(Tensor Processing Unit,TPU)、深度学习处理单元(Deep learning Processing Unit,DPU)等。
图7A是根据一示例性实施例示出的一种第一网络设备的结构示意图。如图7A所示,第一网络设备包括:
确定模块7101,被配置为确定第一密钥;所述第一密钥用于第一用户设备UE和第二UE确定第二密钥;所述第二密钥,用于所述第一UE和所述第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护;
发送模块7102,被配置为将所述第一密钥发送给所述第一UE和所述第二UE。
在一些实施例中,该确定模块可用于第一网络设备执行任意一个数据安全处理方法中的信息确定相关的步骤。
在一些实施例中,该发送模块可用于第一网络设备执行任意一个数据安全处理方法中的信息发送相关的步骤。
在一些实施例中,该第一网络设备还可包括:接收模块。
在一些实施例中,该接收模块可对应于第一网络设备的网络接口和/或收发天线。
在一些实施例中,该接收模块可用于第一网络设备执行任意一个数据安全处理方法中的信息接收相关的步骤。
在一些实施例中,确定模块被配置为根据第三密钥生成所述第一密钥;所述第三密钥包括:所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥。
在一些实施例中,确定模块被配置为根据所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥,确定第四密钥;根据所述第四密钥,确定所述第一密钥。
在一些实施例中,确定模块被配置为执行以下之一:
进行所述第一UE的接入层AS中间密钥和所述第二UE的AS层中间密钥异或,得到所述第四密钥;
级联所述第一UE的接入层AS中间密钥和所述第二UE的AS层中间密钥,得到所述第四密钥。
在一些实施例中,接收模块被配置为接收核心网功能发送的第一信息,所述第一信息用于指示是否激活所述第一UE与所述第二UE的UE-SAT-UE通信的端到端安全保护;
确定模块被配置为所述第一信息指示激活所述第一UE与所述第二UE的UE-SAT-UE通信的端到端安全保护,确定所述第一密钥。
在一些实施例中,发送模块被配置为向所述第一UE和所述第二UE发送所述第一信息。
在一些实施例中,所述第一信息,包括以下至少之一:
所述第一UE的安全策略指示,用于指示所述第一UE与提供服务的第一网络设备之间本地传输的协议数据单元PDU会话的用户面是否需要端到端安全保护;
所述第二UE的安全策略指示,用于指示所述第二UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面是否需要端到端安全保护。
在一些实施例中,确定模块被配置为执行以下之一:
根据所述第一信息以及所述第三密钥生成第一密钥;
根据第一信息、第一信息的长度以及第三密钥,生成第一密钥。
在一些实施例中,所述第二密钥,包括以下至少之一:
完整性密钥;
机密性密钥。
图7B是根据一示例性实施例示出的一种第一UE装置的结构示意图。如图7B所示,第一UE包括:
接收模块7201,被配置为接收第一网络设备发送的第一密钥;
确定模块7202,被配置为根据所述第一密钥,确定第二密钥;所述第二密钥,用于第一UE和第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
在一些实施例中,该接收模块可用于第一UE执行任意一个数据安全处理方法中的信息接收相关的步骤。
在一些实施例中,该接收模块可对应于第一UE的网络接口和/或收发天线。
在一些实施例中,该确定模块可用于第一UE执行任意一个数据安全处理方法中的信息确定相关的步骤。
在一些实施例中,该第一UE还可包括:发送模块。
在一些实施例中,该发送模块可用于第一网络设备执行任意一个数据安全处理方法中的信息发送相关的步骤。
在一些实施例中,所述第一密钥是根据所述第三密钥生成的;所述第三密钥包括:所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥。
在一些实施例中,所述第一密钥是根据第一信息以及所述第三密钥生成的;或者,
所述第一密钥是根据所述第一信息、第一信息的长度以及第三密钥生成的;所述第一信息用于指示是否激活UE-SAT-UE通信的端到端安全保护。
在一些实施例中,所述第一信息,包括以下至少之一:
所述第一UE的安全策略指示,用于指示所述第一UE与提供服务的第一网络设备之间本地传输的协议数据单元PDU会话的用户面是否需要端到端安全保护;
所述第二UE的安全策略指示,用于指示所述第二UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面是否需要端到端安全保护。
在一些实施例中,接收模块被配置为接收第一网络设备发送的所述第一信息。
在一些实施例中,所述第二密钥,包括以下至少之一:
完整性密钥;
机密性密钥。
图7C是根据一示例性实施例示出的一种核心网功能的结构示意图。如图7C所示,核心网功能包括:
发送模块7301,被配置为向第一网络设备发送第一信息,所述第一信息用于指示第一UE和所述第二UE之间的UE-SAT-UE通信是否需要端到端安全保护。
在一些实施例中,该发送模块可用于核心网功能执行任意一个数据安全处理方法中的信息发送相关的步骤。
在一些实施例中,该核心网功能还可包括:接收模块和/或确定模块。
在一些实施例中,该接收模块可用于核心网功能执行任意一个数据安全处理方法中的信息接收相关的步骤。
在一些实施例中,该确定模块可用于核心网功能执行任意一个数据安全处理方法中的信息确定相关的步骤。
在一些实施例中,所述第一信息,包括以下至少之一:
所述第一UE的安全策略指示,用于指示所述第一UE与提供服务的第一网络设备之间本地传输的协议数据单元PDU会话的用户面是否需要端到端安全保护;
所述第二UE的安全策略指示,用于指示所述第二UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面是否需要端到端安全保护。
在一些实施例中,确定模块被配置为根据所述第一UE和/或所述第二UE的所述PDU会话的会话管理信息,确定所述第一信息。
图8A是根据一示例性实施例示出的一种通信设备的结构示意图。通信设备8100可以是网络设备(例如,接入网设备或核心网设备等),也可以是终端(例如用户设备等),也可以是支持网络设备实现以上任一种方法的芯片、芯片系统、或处理器等,还可以是支持终端实现以上任一种数据安全处理方法的芯片、芯片系统、或处理器等。通信设备8100可用于实现上述方法实施例中描述的数据安全处理方法,具体可以参见上述方法实施例中的说明。
如图8A所示,通信设备8100包括一个或多个处理器8101。处理器8101可以是通用处理器或者专用处理器等,例如可以是基带处理器或中央处理器。基带处理器可以用于对通信协议以及通信数据进行处理,中央处理器可以用于对通信装置(如,基站、基带芯片,终端设备、终端设备芯片,DU或CU等)进行控制,执行程序,处理程序的数据。处理器8101用于调用指令以使得通信设备
8100执行以上任一种通信方法。
在一些实施例中,通信设备8100还包括用于存储指令的一个或多个存储器8102。可选地,全部或部分存储器8102也可以处于通信设备8100之外。
在一些实施例中,通信设备8100还包括一个或多个收发器8103。在通信设备8100包括一个或多个收发器8103时,上述方法中的发送接收等通信步骤由收发器8103执行,其他步骤由处理器8101执行。
在一些实施例中,收发器可以包括接收器和发送器,接收器和发送器可以是分离的,也可以集成在一起。可选地,收发器、收发单元、收发机、收发电路等术语可以相互替换,发送器、发送单元、发送机、发送电路等术语可以相互替换,接收器、接收单元、接收机、接收电路等术语可以相互替换。
可选地,通信设备8100还包括一个或多个接口电路8104,接口电路8104与存储器8102连接,接口电路8104可用于从存储器8102或其他装置接收信号,可用于向存储器8102或其他装置发送信号。例如,接口电路8104可读取存储器8102中存储的指令,并将该指令发送给处理器8101。
以上实施例描述中的通信设备8100可以是网络设备或者终端,但本公开中描述的通信设备8100的范围并不限于此,通信设备8100的结构可以不受图8A的限制。通信设备可以是独立的设备或者可以是较大设备的一部分。例如所述通信设备可以是:(1)独立的集成电路IC,或芯片,或,芯片系统或子系统;(2)具有一个或多个IC的集合,可选地,上述IC集合也可以包括用于存储数据,程序的存储部件;(3)ASIC,例如调制解调器(Modem);(4)可嵌入在其他设备内的模块;(5)接收机、终端设备、智能终端设备、蜂窝电话、无线设备、手持机、移动单元、车载设备、网络设备、云设备、人工智能设备等等;(6)其他等等。
图8B是根据一示例性实施例示出的一种芯片8200的结构示意图。对于通信设备8100可以是芯片或芯片系统的情况,可以参见图8B所示的芯片8200的结构示意图,但不限于此。
芯片8200包括一个或多个处理器8201,处理器8201用于调用指令以使得芯片8200执行以上任一种通信方法。
在一些实施例中,芯片8200还包括一个或多个接口电路8202,接口电路8202与存储器8203连接,接口电路8202可以用于从存储器8203或其他装置接收信号,接口电路8202可用于向存储器8203或其他装置发送信号。例如,接口电路8202可读取存储器8203中存储的指令,并将该指令发送给处理器8201。可选地,接口电路、接口、收发管脚、收发器等术语可以相互替换。
在一些实施例中,芯片8200还包括用于存储指令的一个或多个存储器8203。可选地,全部或部分存储器8203可以处于芯片8200之外。
本公开还提供一种存储介质,上述存储介质上存储有指令,当上述指令在通信设备8100上运行时,使得通信设备8100执行以上任一种方法。可选地,上述存储介质是电子存储介质。可选地,上述存储介质是计算机可读存储介质,但也可以是其他装置可读的存储介质。可选地,上述存储介质可以是非暂时性(non-transitory)存储介质,但也可以是暂时性存储介质。
本公开还提供一种程序产品,上述程序产品被通信设备8100执行时,使得通信设备8100执行以上任一种通信方法。可选地,上述程序产品是计算机程序产品。
本公开还提供一种计算机程序,当其在计算机上运行时,使得计算机执行以上任一种通信方法。
本领域技术人员在考虑说明书及实践这里公开的发明后,将容易想到本发明的其它实施方案。本公开旨在涵盖本发明的任何变型、用途或者适应性变化,这些变型、用途或者适应性变化遵循本发明的一般性原理并包括本公开未公开的本技术领域中的公知常识或惯用技术手段。说明书和实施例仅被视为示例性的,本发明的真正范围和精神由下面的权利要求指出。
应当理解的是,本发明并不局限于上面已经描述并在附图中示出的精确结构,并且可以在不脱离其范围进行各种修改和改变。本发明的范围仅由所附的权利要求来限制。
Claims (25)
- 一种数据安全处理方法,其中,由第一网络设备执行,所述方法包括:确定第一密钥;所述第一密钥用于第一用户设备UE和第二UE确定第二密钥;所述第二密钥,用于所述第一UE和所述第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护;将所述第一密钥发送给所述第一UE和所述第二UE。
- 根据权利要求1所述的方法,其中,所述确定第一密钥包括:根据第三密钥生成所述第一密钥;所述第三密钥包括:所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥。
- 根据权利要求2所述的方法,其中,所述根据第三密钥生成所述第一密钥,包括:根据所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥,确定第四密钥;根据所述第四密钥,确定所述第一密钥。
- 根据权利要求3所述的方法,其中,所述根据所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥,确定第四密钥包括以下之一:进行所述第一UE的接入层AS中间密钥和所述第二UE的AS层中间密钥异或,得到所述第四密钥;级联所述第一UE的接入层AS中间密钥和所述第二UE的AS层中间密钥,得到所述第四密钥。
- 根据权利要求1至4任一项所述的方法,其中,所述方法还包括:接收核心网功能发送的第一信息,所述第一信息用于指示是否激活所述第一UE与所述第二UE的UE-SAT-UE通信的端到端安全保护;所述确定第一密钥,包括:所述第一信息指示激活所述第一UE与所述第二UE的UE-SAT-UE通信的端到端安全保护,确定所述第一密钥。
- 根据权利要求5所述的方法,其中,所述方法还包括:向所述第一UE和所述第二UE发送所述第一信息。
- 根据权利要求5或6所述的方法,其中,所述第一信息,包括以下至少之一:所述第一UE的安全策略指示,用于指示所述第一UE与提供服务的第一网络设备之间本地传输的协议数据单元PDU会话的用户面是否需要端到端安全保护;所述第二UE的安全策略指示,用于指示所述第二UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面是否需要端到端安全保护。
- 根据权利要求5至7任一项所述的方法,其中,所述根据第三密钥生成所述第一密钥,包括以下之一:根据所述第一信息以及所述第三密钥生成第一密钥;根据第一信息、第一信息的长度以及第三密钥,生成第一密钥。
- 根据权利要求1至8任一项所述的方法,其中,所述第二密钥,包括以下至少之一:完整性密钥;机密性密钥。
- 一种数据安全处理方法,其中,由第一UE执行,所述方法包括:接收第一网络设备发送的第一密钥;根据所述第一密钥,确定第二密钥;所述第二密钥,用于第一UE和第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
- 根据权利要求10所述的方法,其中,所述第一密钥是根据第三密钥生成的;所述第三密钥包括:所述第一UE的接入层AS中间密钥和/或所述第二UE的AS层中间密钥。
- 根据权利要求11所述的方法,其中,所述第一密钥是根据第一信息以及所述第三密钥生成的;或者,所述第一密钥是根据所述第一信息、第一信息的长度以及第三密钥生成的;所述第一信息用于指示是否激活UE-SAT-UE通信的端到端安全保护。
- 根据权利要求12所述的方法,其中,所述第一信息,包括以下至少之一:所述第一UE的安全策略指示,用于指示所述第一UE与提供服务的第一网络设备之间本地传输的协议数据单元PDU会话的用户面是否需要端到端安全保护;所述第二UE的安全策略指示,用于指示所述第二UE与提供服务的第一网络设备之间本地传输 的PDU会话的用户面是否需要端到端安全保护。
- 根据权利要求12或13所述的方法,其中,所述方法还包括:接收第一网络设备发送的所述第一信息。
- 根据权利要求10至14任一项所述的方法,其中,所述第二密钥,包括以下至少之一:完整性密钥;机密性密钥。
- 一种数据安全处理方法,其中,由核心网功能执行,所述方法包括:向第一网络设备发送第一信息,所述第一信息用于指示第一UE和第二UE之间的UE-SAT-UE通信是否需要端到端安全保护。
- 根据权利要求16所述的方法,其中,所述第一信息,包括以下至少之一:所述第一UE的安全策略指示,用于指示所述第一UE与提供服务的第一网络设备之间本地传输的协议数据单元PDU会话的用户面是否需要端到端安全保护;所述第二UE的安全策略指示,用于指示所述第二UE与提供服务的第一网络设备之间本地传输的PDU会话的用户面是否需要端到端安全保护。
- 根据权利要求16或17所述的方法,其中,所述方法还包括:根据所述第一UE和/或所述第二UE的PDU会话的会话管理信息,确定所述第一信息。
- 一种数据安全处理方法,其中,由通信系统执行,所述方法包括:核心网功能向第一网络设备发送第一信息,所述第一信息用于指示第一UE和第二UE之间的UE-SAT-UE通信是否需要端到端安全保护;所述第一网络设备确定第一密钥;将所述第一密钥发送给所述第一UE和所述第二UE;所述第一UE和所述第二UE根据所述第一密钥,确定第二密钥;所述第二密钥,用于第一UE和第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
- 一种第一网络设备,其中,包括:确定模块,被配置为确定第一密钥;所述第一密钥用于第一用户设备UE和第二UE确定第二密钥;所述第二密钥,用于所述第一UE和所述第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护;发送模块,被配置为将所述第一密钥发送给所述第一UE和所述第二UE。
- 一种第一UE,其中,包括:接收模块,被配置为接收第一网络设备发送的第一密钥;确定模块,被配置为根据所述第一密钥,确定第二密钥;所述第二密钥,用于第一UE和第二UE之间进行用户设备到卫星到用户设备UE-SAT-UE通信的端到端安全保护。
- 一种核心网功能,其中,包括:发送模块,被配置为向第一网络设备发送第一信息,所述第一信息用于指示第一UE和第二UE之间的UE-SAT-UE通信是否需要端到端安全保护。
- 一种通信系统,其中,所述通信系统包括第一终端、第一网络设备和核心网功能;所述第一网络设备被配置为实现权利要求1至9中任一项所述的数据安全处理方法,所述第一终端被配置为实现权利要求10至15中任一项所述的数据安全处理方法,所述核心网功能被配置为实现权利要求16至19中任一项所述的数据安全处理方法。
- 一种通信设备,其中,所述通信设备包括:一个或多个处理器;其中,所述处理器用于调用指令以使得所述通信设备执行权利要求1至9、权利要求10至15、权利要求16至19中任一项所述的数据安全处理方法。
- 一种存储介质,其中,所述存储介质存储有指令,当所述指令在通信设备上运行时,使得所述通信设备执行权利要求1至9、权利要求10至15、权利要求16至19中任一项所述的数据安全处理方法。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2024/073360 WO2025152183A1 (zh) | 2024-01-19 | 2024-01-19 | 数据安全处理方法及通信设备、通信系统及存储介质 |
| CN202480005619.3A CN120677733A (zh) | 2024-01-19 | 2024-01-19 | 数据安全处理方法及通信设备、通信系统及存储介质 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/CN2024/073360 WO2025152183A1 (zh) | 2024-01-19 | 2024-01-19 | 数据安全处理方法及通信设备、通信系统及存储介质 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025152183A1 true WO2025152183A1 (zh) | 2025-07-24 |
Family
ID=96470483
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2024/073360 Pending WO2025152183A1 (zh) | 2024-01-19 | 2024-01-19 | 数据安全处理方法及通信设备、通信系统及存储介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN120677733A (zh) |
| WO (1) | WO2025152183A1 (zh) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107241137A (zh) * | 2017-07-25 | 2017-10-10 | 芯盾(北京)信息技术有限公司 | 一种基于卫星服务的智能终端通讯加密系统 |
| US20210051005A1 (en) * | 2019-08-16 | 2021-02-18 | Lenovo (Singapore) Pte. Ltd. | Security capabilities in an encryption key request |
| CN114338005A (zh) * | 2021-12-24 | 2022-04-12 | 北京海泰方圆科技股份有限公司 | 一种数据传输加密方法、装置、电子设备及存储介质 |
| CN114785399A (zh) * | 2022-03-22 | 2022-07-22 | 南京熊猫汉达科技有限公司 | 一种低轨卫星通信网络系统的端到端通信方法 |
| CN115334497A (zh) * | 2022-08-01 | 2022-11-11 | 中电信量子科技有限公司 | 卫星终端密钥分发方法、装置及系统 |
-
2024
- 2024-01-19 CN CN202480005619.3A patent/CN120677733A/zh active Pending
- 2024-01-19 WO PCT/CN2024/073360 patent/WO2025152183A1/zh active Pending
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107241137A (zh) * | 2017-07-25 | 2017-10-10 | 芯盾(北京)信息技术有限公司 | 一种基于卫星服务的智能终端通讯加密系统 |
| US20210051005A1 (en) * | 2019-08-16 | 2021-02-18 | Lenovo (Singapore) Pte. Ltd. | Security capabilities in an encryption key request |
| CN114338005A (zh) * | 2021-12-24 | 2022-04-12 | 北京海泰方圆科技股份有限公司 | 一种数据传输加密方法、装置、电子设备及存储介质 |
| CN114785399A (zh) * | 2022-03-22 | 2022-07-22 | 南京熊猫汉达科技有限公司 | 一种低轨卫星通信网络系统的端到端通信方法 |
| CN115334497A (zh) * | 2022-08-01 | 2022-11-11 | 中电信量子科技有限公司 | 卫星终端密钥分发方法、装置及系统 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN120677733A (zh) | 2025-09-19 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2025015580A1 (zh) | 信息处理方法、终端、通信系统及存储介质 | |
| US20220217538A1 (en) | Communication Method And Communication Apparatus | |
| WO2025035417A1 (zh) | 信息处理方法、装置及存储介质 | |
| WO2025152183A1 (zh) | 数据安全处理方法及通信设备、通信系统及存储介质 | |
| WO2025030300A1 (zh) | 信息指示方法、第一api调用者、第一网络功能和存储介质 | |
| WO2025152184A1 (zh) | 密钥处理方法、通信设备及存储介质 | |
| WO2026007146A1 (zh) | 信息处理方法、通信系统及存储介质 | |
| WO2025152190A1 (zh) | 信息处理方法、通信系统及存储介质 | |
| WO2025010609A1 (zh) | 通信处理方法、用户设备 | |
| WO2026036328A1 (zh) | 信息处理方法、通信设备及存储介质 | |
| WO2025189403A1 (zh) | 信息处理方法、装置及存储介质 | |
| WO2026065134A1 (zh) | 通信方法、网元、终端、设备及存储介质 | |
| WO2025217856A1 (zh) | 数据传输通道建立方法、网络设备、终端、通信系统及介质 | |
| WO2025000394A9 (zh) | 建立用户面连接的方法及装置、存储介质 | |
| WO2025010573A1 (zh) | 基于ntn的通信方法和装置、通信设备、通信系统及存储介质 | |
| WO2025091186A1 (zh) | 密钥处理方法、通信设备、及存储介质 | |
| WO2025213303A1 (zh) | 信息处理方法、网络设备、终端、通信系统及存储介质 | |
| WO2025179499A1 (zh) | 通信方法、第一设备、网络功能、通信系统和存储介质 | |
| WO2025213308A1 (zh) | 通信方法、通信设备、通信系统及存储介质 | |
| WO2025166651A1 (zh) | 信息处理方法、网元、接入网设备、通信系统及存储介质 | |
| WO2026036326A1 (zh) | 信息处理方法、通信设备及存储介质 | |
| WO2026065155A1 (zh) | 通信方法、终端、网元、系统及介质 | |
| WO2026065156A1 (zh) | 通信方法、终端、网元、系统及介质 | |
| WO2025091380A1 (zh) | 指示方法、装置以及存储介质 | |
| WO2025025026A1 (zh) | 信息处理方法、网络设备、终端、通信系统及存储介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| WWE | Wipo information: entry into national phase |
Ref document number: 202480005619.3 Country of ref document: CN |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24917806 Country of ref document: EP Kind code of ref document: A1 |
|
| WWP | Wipo information: published in national office |
Ref document number: 202480005619.3 Country of ref document: CN |