WO2025152190A1 - 信息处理方法、通信系统及存储介质 - Google Patents

信息处理方法、通信系统及存储介质

Info

Publication number
WO2025152190A1
WO2025152190A1 PCT/CN2024/073381 CN2024073381W WO2025152190A1 WO 2025152190 A1 WO2025152190 A1 WO 2025152190A1 CN 2024073381 W CN2024073381 W CN 2024073381W WO 2025152190 A1 WO2025152190 A1 WO 2025152190A1
Authority
WO
WIPO (PCT)
Prior art keywords
terminal
data
indication information
information
security
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/CN2024/073381
Other languages
English (en)
French (fr)
Inventor
陆伟
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Xiaomi Mobile Software Co Ltd
Original Assignee
Beijing Xiaomi Mobile Software Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Xiaomi Mobile Software Co Ltd filed Critical Beijing Xiaomi Mobile Software Co Ltd
Priority to CN202480005598.5A priority Critical patent/CN120677735A/zh
Priority to PCT/CN2024/073381 priority patent/WO2025152190A1/zh
Publication of WO2025152190A1 publication Critical patent/WO2025152190A1/zh
Anticipated expiration legal-status Critical
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/30Security of mobile devices; Security of mobile applications
    • H04W12/37Managing security policies for mobile devices or for controlling mobile applications

Definitions

  • an information processing method is proposed, which is executed by an access network device, including: determining the security protection of UP data of a first terminal and a second terminal based on first indication information and second indication information; wherein the first indication information is used to indicate the transmission mode and/or security policy of the UP data of the first terminal, and the second indication information is used to indicate the transmission mode and/or security policy of the UP data of the second terminal.
  • an information processing method is proposed, which is executed by a core network device, including: sending first information to an access network device, the first information including first indication information; the first indication information is used to indicate the transmission method and/or security policy of UP data of the first terminal; sending second information to the access network device, the second information including second indication information; the second indication information is used to indicate the transmission method and/or security policy of UP data of the second terminal; wherein the first indication information and the second indication information are used by the access network device to determine the security protection of UP data of the first terminal and the second terminal.
  • a core network device including: a second transceiver module, configured to send first information to an access network device, the first information including first indication information; the first indication information is used to indicate the transmission mode and/or security policy of UP data of the first terminal; the second transceiver module is also configured to send second information to the access network device, the second information including second indication information; the second indication information is used to indicate the transmission mode and/or security policy of UP data of the second terminal; wherein the first indication information and the second indication information are used by the access network device to determine the security protection of UP data of the first terminal and the second terminal.
  • a storage medium stores instructions.
  • the communication device executes the method described in the first aspect, the second aspect, or the optional implementation of the first and second aspects.
  • the disclosed embodiments can enable the access device to implement security protection for UP data of the first terminal and UP data of the second terminal in a communication scenario from the first terminal to the satellite to the second terminal (ie, UE-SAT-UE).
  • Fig. 1B is a schematic diagram showing a scenario in which UE-SAT-UE provides a service according to an exemplary embodiment.
  • FIG. 2 is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure.
  • FIG3A is a schematic flow chart of an information processing method according to an embodiment of the present disclosure.
  • FIG3B is a flowchart illustrating an information processing method according to an embodiment of the present disclosure.
  • FIG3C is a flow chart of an information processing method according to an embodiment of the present disclosure.
  • FIG3D is a flow chart of an information processing method according to an embodiment of the present disclosure.
  • FIG4A is a flow chart of an information processing method according to an embodiment of the present disclosure.
  • FIG4B is a flow chart of an information processing method according to an embodiment of the present disclosure.
  • FIG6A is a schematic diagram showing the structure of an access network device according to an embodiment of the present disclosure.
  • FIG. 7A is a schematic diagram of the structure of a communication device provided according to an embodiment of the present disclosure.
  • FIG. 7B is a schematic diagram of the structure of a chip provided according to an embodiment of the present disclosure.
  • an embodiment of the present disclosure proposes an information processing method, which is executed by an access network device, including: determining the security protection of UP data of a first terminal and a second terminal based on first indication information and second indication information; wherein the first indication information is used to indicate the transmission mode and/or security policy of the UP data of the first terminal, and the second indication information is used to indicate the transmission mode and/or security policy of the UP data of the second terminal.
  • the access network device can receive first information of the first terminal and second information of the second terminal from the core network device, so as to subsequently determine the security protection of the UP data based on the first indication information included in the first information and the second indication information included in the second information.
  • determining the security protection of the user plane UP data of the first terminal and the second terminal includes one of the following: when the transmission mode of the UP data indicated by the first indication information and the second indication information is both UE-SAT-UE local transmission, determining to enable consistency security protection for the UP data of the first terminal and the second terminal; when the security policies of the UP data indicated by the first indication information and the second indication information are the same and are the first type of security policies, determining to perform consistency security protection on the UP data of the first terminal and the second terminal; when the security policies of the UP data indicated by the first indication information and the second indication information are the same and are the second type of security policies, determining how to perform consistency security protection on the UP data based on the access network device; and when the security policies of the UP data indicated by the first indication information and the second indication information are different, determining whether to perform consistency protection on the UP data of the first terminal and the
  • the access network device can determine whether to enable consistency protection of the UP data of the first terminal and the second terminal based on the first indication information and the second indication information, or can accurately determine whether the UP data of the first terminal and the second terminal need to be consistently protected, and the specific security policy if consistency protection is required, etc. according to the security policy indicated by the first indication information and the second indication information.
  • the first type of security policy includes requiring protection or not requiring protection; and/or the second type of security policy includes preferred protection; wherein the preferred protection indicates the security protection selected by the preferred access network device.
  • the specific first-class security policy is defined as requiring protection or not requiring protection, and/or the specific second security policy is defined as including preferred protection, thereby facilitating the access network device to determine the security protection of UP data based on different types of security policies.
  • determining whether the UP data of the first terminal and the second terminal are to be consistently protected is performed according to the categories of security policies respectively indicated by the first indication information and the second indication information, including at least one of the following: when one of the first indication information and the second indication information indicates a first type of security policy and the other indicates a second type of security policy, determining that the UP data of the first terminal and the second terminal are to be consistently protected by the first type of security policy; wherein the first type of security policy includes whether protection is required or not required, and the second type of security policy includes preferred protection; and when both the first indication information and the second indication information indicate the first type of security policy, and the security policies indicated by the first indication information and the second indication information are different, determining that the UP data of the first terminal and the second terminal cannot be consistently protected.
  • the method also includes: when it is determined that the first terminal and the second terminal cannot be protected in consistency, refusing to establish a session with the first terminal and the second terminal; or, when it is determined that the first terminal and the second terminal cannot be protected in consistency, performing security protection on the UP data of the first terminal based on the security policy indicated by the first indication information, and/or, performing security protection on the UP data of the second terminal based on the security policy indicated by the second indication information.
  • the established session when consistent security protection cannot be performed, the established session can be rejected to reduce the possibility of data leakage caused by the inability to perform security protection in the communication between the first terminal, the satellite and the second terminal; or, when consistent security protection cannot be performed, the first terminal and the second terminal can be enabled to perform security protection according to their own security policies, thereby realizing communication between the first terminal, the satellite and the second terminal.
  • the method further includes: activating security protection of the UP data of the first terminal and/or the second terminal based on a security policy for the UP data of the first terminal and the second terminal.
  • the security policy after the security policy is configured, the security policy can be activated for security protection.
  • the method also includes: sending third information to the first terminal and/or the second terminal, wherein the third information is used to indicate the security protection of UP data of the first terminal and/or the second terminal determined by the access network device; the third information is used for the first terminal and/or the second terminal to perform security protection of UP data.
  • the third information may be sent to the first terminal and/or the second terminal, so that the first terminal and/or the second terminal performs security protection based on the security policy configured by the access network device.
  • the access network device includes a satellite base station; and/or the core network device includes: an access and mobility management function (Access and Mobility management Function, AMF), or a session management function (Session Management Function, SMF), or a policy control function (Policy Control Function, PCF).
  • AMF Access and Mobility management Function
  • SMF Session Management Function
  • PCF Policy Control Function
  • an embodiment of the present disclosure proposes an information processing method, which is executed by a core network device, including: sending first information to an access network device, the first information including first indication information; the first indication information is used to indicate the transmission method and/or security policy of UP data of the first terminal; sending second information to the access network device, the second information including second indication information; the second indication information is used to indicate the transmission method and/or security policy of UP data of the second terminal; wherein the first indication information and the second indication information are used by the access network device to determine the security protection of UP data of the first terminal and the second terminal.
  • the access network device includes a satellite base station; and/or the core network device includes an AMF or an SMF or a PCF.
  • an embodiment of the present disclosure proposes an access network device, including: a first transceiver module, configured to determine the security protection of UP data of a first terminal and a second terminal based on first indication information and second indication information; wherein the first indication information is used to indicate the transmission mode and/or security policy of the UP data of the first terminal, and the second indication information is used to indicate the transmission mode and/or security policy of the UP data of the second terminal.
  • an embodiment of the present disclosure proposes a core network device, comprising: a second transceiver module, configured to send first information to an access network device, the first information including first indication information; the first indication information is used to indicate the transmission mode and/or security policy of UP data of the first terminal; the second transceiver module is also configured to send second information to the access network device, the second information including second indication information; the second indication information is used to indicate the transmission mode and/or security policy of UP data of the second terminal; wherein the first indication information and the second indication information are used by the access network device to determine the security protection of UP data of the first terminal and the second terminal.
  • an embodiment of the present disclosure proposes a communication device, comprising one or more processors; wherein the above-mentioned communication device is used to execute optional implementation methods such as the first aspect, the second aspect, or the first aspect and the second aspect.
  • a communication system comprising: an access network device and a core network device; wherein the above-mentioned access network device is configured to execute the method described in the optional implementation manner of the first aspect, and the above-mentioned core network device is configured to execute the method described in the optional implementation manner of the second aspect.
  • an embodiment of the present disclosure proposes a storage medium, which stores instructions.
  • the communication device executes the method described in the first aspect, the second aspect, or the optional implementation of the first and second aspects.
  • an embodiment of the present disclosure proposes a program product.
  • the communication device executes the method described in the first aspect, the second aspect, or the optional implementation of the first and second aspects.
  • an embodiment of the present disclosure proposes a computer program, which, when executed on a computer, enables the computer to execute the information processing method as described in the first aspect, the second aspect, or the optional implementation of the first and second aspects.
  • an embodiment of the present disclosure proposes a chip or a chip system; the chip or chip system includes a processing circuit configured to execute the method described in accordance with the above-mentioned first aspect, second aspect, or optional implementation of the first and second aspects.
  • the embodiments of the present disclosure provide an information processing method, device, communication system and storage medium.
  • the terms information processing method and communication method are interchangeable, the terms information processing device and communication device are interchangeable, and the terms information processing system and communication system are interchangeable.
  • each step in a certain embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined.
  • a solution after removing some steps in a certain embodiment can also be implemented as an independent embodiment, and the order of the steps in a certain embodiment can be arbitrarily exchanged.
  • the optional implementation methods in a certain embodiment can be arbitrarily combined; in addition, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a certain embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
  • elements expressed in the singular form such as “a”, “an”, “the”, “above”, “said”, “aforementioned”, “this”, etc., may mean “one and only one", or “one or more”, “at least one”, etc.
  • the noun after the article may be understood as a singular expression or a plural expression.
  • plurality refers to two or more.
  • the terms "at least one of”, “one or more”, “a plurality of”, “multiple”, etc. can be used interchangeably.
  • "at least one of A and B", “A and/or B", “A in one case, B in another case”, “in response to one case A, in response to another case B”, etc. may include the following technical solutions according to the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). When there are more branches such as A, B, C, etc., the above is also similar.
  • the recording method of "A or B” may include the following technical solutions according to the situation: in some embodiments, A (A is executed independently of B); in some embodiments, B (B is executed independently of A); in some embodiments, execution is selected from A and B (A and B are selectively executed).
  • A A is executed independently of B
  • B B is executed independently of A
  • execution is selected from A and B (A and B are selectively executed).
  • prefixes such as “first” and “second” in the embodiments of the present disclosure are only used to distinguish different description objects, and do not constitute restrictions on the position, order, priority, quantity or content of the description objects.
  • the statement of the description object refers to the description in the context of the claims or embodiments, and should not constitute unnecessary restrictions due to the use of prefixes.
  • the description object is a "field”
  • the ordinal number before the "field” in the "first field” and the "second field” does not limit the position or order between the "fields”
  • the "first” and “second” do not limit whether the "fields” they modify are in the same message, nor do they limit the order of the "first field” and the "second field”.
  • “including A”, “comprising A”, “used to indicate A”, and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
  • terms such as “greater than”, “greater than or equal to”, “not less than”, “more than”, “more than or equal to”, “not less than”, “higher than”, “higher than or equal to”, “not lower than”, and “above” can be replaced with each other, and terms such as “less than”, “less than or equal to”, “not greater than”, “less than”, “less than or equal to”, “no more than”, “lower than”, “lower than or equal to”, “not higher than”, and “below” can be replaced with each other.
  • network may be interpreted as devices included in the network (eg, access network equipment, core network equipment, etc.).
  • terminal In some embodiments, the terms "terminal”, “terminal device”, “user equipment (UE)”, “user terminal” “mobile station (MS)”, “mobile terminal (MT)", subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, handset, user agent, mobile client, client and the like can be used interchangeably.
  • the access network device, the core network device, or the network device can be replaced by a terminal.
  • the various embodiments of the present disclosure can also be applied to a structure in which the access network device, the core network device, or the network device and the communication between the terminals is replaced by the communication between multiple terminals (for example, it can also be referred to as device-to-device (D2D), vehicle-to-everything (V2X), etc.).
  • D2D device-to-device
  • V2X vehicle-to-everything
  • the language such as "uplink” and "downlink” can also be replaced by the language corresponding to the communication between the terminals (for example, "side”).
  • the uplink channel, the downlink channel, etc. can be replaced by the side channel
  • the uplink, the downlink, etc. can be replaced by the side link.
  • the terminal may be replaced by an access network device, a core network device, or a network device.
  • the access network device, the core network device, or the network device may also be configured to have a structure that has all or part of the functions of the terminal.
  • acquisition of data, information, etc. may comply with the laws and regulations of the country where the data is obtained.
  • data, information, etc. may be obtained with the user's consent.
  • each element, each row, or each column in the table of the embodiments of the present disclosure may be implemented as an independent embodiment, and the combination of any elements, any rows, or any columns may also be implemented as an independent embodiment.
  • FIG1A is a schematic diagram of a structure of an information processing system 100 according to an embodiment of the present disclosure.
  • the information processing system 100 may include: a terminal 101 and a network device 102 .
  • the network device 102 may include at least one of an access network device and a core network device.
  • the core network device may be a device, including a first device, a second device, etc., or may be a plurality of devices or a group of devices, including all or part of the first device and the second device mentioned above.
  • the first device and the second device may be network elements; the network element may be virtual or physical.
  • the core network may include, for example, at least one of an Evolved Packet Core (EPC), a 5G Core Network (5GCN), and a Next Generation Core (NGC).
  • EPC Evolved Packet Core
  • 5GCN 5G Core Network
  • NGC Next Generation Core
  • the information processing system described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution provided by the embodiment of the present disclosure.
  • a person skilled in the art can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solution provided by the embodiment of the present disclosure is also applicable to similar technical problems.
  • the following embodiments of the present disclosure may be applied to the information processing system 100 shown in FIG1A, or part of the main body, but are not limited thereto.
  • the main bodies shown in FIG1A are examples, and the information processing system may include all or part of the main bodies in FIG1A, or may include other main bodies other than FIG1A, and the number and form of the main bodies are arbitrary, and the connection relationship between the main bodies is an example, and the main bodies may be connected or disconnected, and the connection may be in any manner, which may be a direct connection or an indirect connection, and may be a wired connection or a wireless connection.
  • the present invention relates to wireless communication systems such as LTE, Wi-Fi (X), Global System for Mobile communications (GSM (registered trademark)), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi (registered trademark)), IEEE 802.16 (WiMAX (registered trademark)), IEEE 802.20, Ultra-WideBand (UWB), Bluetooth (registered trademark), Public Land Mobile Network (PLMN) network, Device to Device (D2D) system, Machine to Machine (M2M) system, Internet of Things (IoT) system, Vehicle to Everything (V2X), systems using other communication methods, and next-generation systems expanded based on them.
  • PLMN Public Land Mobile Network
  • D2D Device to Device
  • M2M Machine to Machine
  • IoT Internet of Things
  • V2X Vehicle to Everything
  • systems using other communication methods and next-generation systems expanded based on them.
  • next-generation systems expanded based on them.
  • a combination of multiple systems for example, a combination of
  • UE-to-satellite-to-UE (UE-SAT-UE) communication refers to communication between UEs under the coverage of one or more server satellites, where user plane (UP) data does not pass through a ground network but is exchanged locally.
  • the UE-to-satellite-to-UE communication may be terminal-to-satellite-to-terminal communication; for example, it may be first terminal-to-satellite-to-second terminal communication.
  • a scenario of UE-SAT-UE providing services is provided; the network system described in FIG. 1B supports UE-SAT-UE communication, and the network system may include UE x, UE y, and a base station (e.g., gNB) mounted on a satellite (Satellite, SAT) x.
  • a base station e.g., gNB
  • the gNB on satellite X forms a satellite cell A, and cell A can be adjacent to the ground cell.
  • security of user plane data on the Uu interface is activated based on a security policy (Security Policy) sent from the core network, which is set by Unified Data Management (UDM) or SMF based on a specific service requested by the UE.
  • the SMF determines the UP security implementation information of the Protocol Data Unit (PDU) session when the PDU session is established based on the following factors: the subscribed security policy is part of the session management subscription information received from the UDM; or, the UP security policy locally configured in the SMF by (Single Data Network Name (DNN) or Single Network Slice Selection AssiSATnce Information (S-NSSAI)) is used when the UDM does not provide the UP security policy.
  • the Uu interface is the cellular communication interface between the UE and the base station.
  • the UP security policy indicates whether security protection of UP data should be activated on the Uu interface of the PDU session.
  • the UP security policy is used to activate security protection of confidentiality and/or integrity of the PDU session.
  • the UP security policy provided by the SMF, if the If the UP security policy indicates "Required", the gNB activates Uu UP security protection for each Data Radio Bearer (DRB) using RRC signaling; or, if the UP security policy indicates "Not Needed", the establishment of the PDU session will proceed without protection; or, if the UP security policy indicates "Preferred", the gNB can decide whether to activate Uu UP security protection. However, when the UP security policy shows "Required” or "Not Needed", the gNB cannot overrule the UP security policy received from the SMF.
  • the UP data can be UP service data or UP traffic, etc.
  • the UE for UE-to-UE communication through the 5G network, the UE establishes separate PDU sessions with the core network device via possibly independent base stations.
  • the gNB applies possibly different UP security policies corresponding to the UE to the separate PDU sessions of the UE.
  • the first information includes first indication information.
  • the first information may include information related to the UP security policy.
  • the first information may include at least one of the following: session management information, a first identifier of the first terminal, a service identifier of UE-SAT-UE communication, a data network name used for UE-SAT-UE communication, and auxiliary information for selecting a network slice used for UE-SAT-UE communication.
  • the first identifier may be any number or character string used to indicate the first terminal.
  • the first identifier may be a user information identifier (User Info), a subscription concealed identifier (SUCI), a user permanent identifier (SUPI), or a globally unique temporary identifier (GUTI), etc. of the first terminal.
  • User Info user information identifier
  • SUCI subscription concealed identifier
  • SUPI user permanent identifier
  • GUI globally unique temporary identifier
  • the first indication information is used to indicate a transmission mode and/or security policy of UP data of the first terminal.
  • the UP data may be replaced by UP traffic, UP service, UP service data or UP service traffic.
  • the security policy may include requiring protection, not requiring protection, and/or prioritizing protection.
  • the name of the first indication information may not be limited, and it may be, for example, UE-SAT-UE communication indication or security policy indication.
  • the access network device receives the second information sent by the core network device.
  • the second indication information is used to indicate a security policy of UP data of the second terminal in a UE-SAT-UE communication situation.
  • the access network device determines that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and may also determine that the security policies of the UP data of the first terminal and the second terminal both do not require protection.
  • the security policies of the UP data indicated by the first indication information and the second indication information both do not require integrity protection, it is determined that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal both do not require integrity protection.
  • the security policies of the UP data indicated by the first indication information and the second indication information both do not require confidentiality protection, it is determined that the UP data of the first terminal and the second terminal are subjected to consistent security protection; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal both do not require confidentiality protection.
  • the first indication information indicates that protection is required and the second indication information indicates preferred protection
  • the first indication information indicates preferred protection and the second indication information indicates required protection, it is determined that the UP data of the first terminal and the second terminal are consistently protected; and it can also be determined that the security policies of the UP data of the first terminal and the second terminal both require protection.
  • the access network device determines that the UP data of the first terminal and the second terminal cannot be consistently and securely protected.
  • the access network device activates security protection of the UP data of the first terminal and/or the second terminal based on a security policy for the UP data of the first terminal and the second terminal.
  • the UP data of the first terminal and the second terminal both need to be protected, the UP data of the first terminal and the second terminal are activated or determined to be securely protected.
  • the UP data of the first terminal and the second terminal do not need to be protected, it is activated or determined that the UP data of the first terminal and the second terminal are not to be protected by security.
  • the UP data of the first terminal does not need protection and the UP data of the second terminal needs protection, it is activated or determined that the UP data of the first terminal does not need security protection and the UP data of the second terminal needs security protection.
  • requiring protection includes requiring confidentiality protection and/or requiring integrity protection; not requiring protection includes not requiring confidentiality protection and/or not requiring integrity protection.
  • Step S2104 The access network device sends third information to the first terminal and/or the second terminal.
  • the first terminal and/or the second terminal receives third information sent by the access network device.
  • the third information is used to indicate security protection of UP data of the first terminal and/or the second terminal determined by the access network device; the third information is used for security protection of UP data of the first terminal and/or the second terminal.
  • the security protection of the UP data of the first terminal and/or the second terminal determined by the access network device may include: the security protection of the UP data of the first terminal and/or the second terminal determined by the access network device itself, or the access network device determines the security protection of the UP data of the first terminal and/or the second terminal based on the first indication information and the second indication information.
  • the security protection may refer to a security policy; the security protection may refer to the need for protection or the need for protection, etc.
  • the name of the third information is not limited, and it can be, for example, security policy information, UP security policy information, or security policy indicator. Display information, etc.
  • the names of information, etc. are not limited to the names recorded in the embodiments, and terms such as “information”, “message”, “signal”, “signaling”, “report”, “configuration”, “indication”, “instruction”, “command”, “channel”, “parameter”, “domain”, “field”, “symbol”, “symbol”, “code element”, “codebook”, “codeword”, “codepoint”, “bit”, “data”, “program”, and “chip” can be used interchangeably.
  • obtain can be interchangeable, and can be interpreted as receiving from other entities, obtaining from protocols, obtaining from high levels, obtaining by self-processing, autonomous implementation, etc.
  • terms such as “certain”, “preset”, “preset”, “setting”, “indicated”, “some”, “any”, and “first” can be interchangeable, and "specific A”, “preset A”, “preset A”, “setting A”, “indicated A”, “some A”, “any A”, and “first A” can be interpreted as A pre-defined in a protocol, etc., or as A obtained through setting, configuration, or indication, etc., and can also be interpreted as specific A, some A, any A, or first A, etc., but is not limited to this.
  • the determination or judgment can be performed by a value represented by 1 bit (0 or 1), by a true or false value (Boolean value) represented by true or false, or by comparison of numerical values (for example, comparison with a predetermined value), but is not limited to this.
  • step S2101 may be implemented as an independent embodiment
  • step S2102 may be implemented as an independent embodiment
  • step S2103 may be implemented as an independent embodiment
  • step S2104 may be implemented as an independent embodiment
  • the combination of step S2101 and step S2102 may be implemented as an independent embodiment
  • the combination of step S2101 and step S2103 may be implemented as an independent embodiment
  • the combination of step S2102 and step S2103 may be implemented as an independent embodiment
  • the combination of step S2101, step S2102 and step S2103 may be implemented as an independent embodiment
  • the combination of step S2103 and step S2104 may be implemented as an independent embodiment
  • the combination of step S2101 to step S2104 may be implemented as an independent embodiment.
  • step S2101, step S2102, and step S2104 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.
  • step S2101 and step S2102 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.
  • step S2104 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.
  • each embodiment may be implemented individually or in combination with each other, and the steps in each embodiment may be distinguished in order.
  • step S3101 can refer to the optional implementation of step S2101 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
  • the access network device receives the first information sent by the core network device, but is not limited thereto, and may also receive the first information sent by other entities.
  • the access network device obtains the first information from an upper layer(s).
  • the access network device performs processing to obtain the first information.
  • step S3101 is omitted, and the access network device autonomously implements the function indicated by the first information, or the above function is missing. Default or default.
  • step S3102 can refer to the optional implementation of step S2102 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
  • the access network device receives the second information sent by the core network device, but is not limited thereto, and may also receive the second information sent by other entities.
  • the access network device obtains second information specified by the protocol.
  • the access network device obtains the second information from an upper layer(s).
  • Step S3103 Determine security protection of UP data of the first terminal and the second terminal.
  • step S3103 can refer to the optional implementation of step S2103 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
  • FIG3B is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG3B , the present disclosure embodiment relates to an information processing method, which is executed by an access network device, and the method includes:
  • step S3201 can refer to step S2103 in Figure 2, or the optional implementation of step S3103 in Figure 3A, and other related parts in the embodiments involved in Figures 2 and 3A, which will not be repeated here.
  • the first indication information is used to indicate the transmission mode and/or security policy of UP data of the first terminal
  • the second indication information is used to indicate the transmission mode and/or security policy of UP data of the second terminal.
  • the method further includes: receiving first information sent by a core network device, wherein the first information includes first indication information; and receiving second information sent by the core network device, wherein the second information includes second indication information.
  • the method also includes: when it is determined that the first terminal and the second terminal cannot be consistently protected, refusing to establish a session with the first terminal and the second terminal; or, when it is determined that the first terminal and the second terminal cannot be consistently protected, performing security protection on the UP data of the first terminal based on the security policy indicated by the first indication information, and/or, performing security protection on the UP data of the second terminal based on the security policy indicated by the second indication information.
  • the method also includes: sending third information to the first terminal and/or the second terminal, wherein the third information is used to indicate the security protection of UP data of the first terminal and/or the second terminal determined by the access network device; the third information is used for the first terminal and/or the second terminal to perform security protection of UP data.
  • FIG3C is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG3C , the present disclosure embodiment relates to an information processing method, which is executed by an access network device, and the method includes:
  • Step S3301 receiving first information.
  • step S3302 can refer to step S2102 in Figure 2, or the optional implementation of step S3102 in Figure 3A, and other related parts in the embodiments involved in Figures 2 and 3A, which will not be repeated here.
  • the first information includes first indication information; and the second information includes second indication information.
  • step S3303 can refer to step S2103 in Figure 2, or the optional implementation of step S3103 in Figure 3A, and other related parts in the embodiments involved in Figures 2 and 3A, which will not be repeated here.
  • FIG3D is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG3D , the present disclosure embodiment relates to an information processing method, which is executed by an access network device, and the method includes:
  • Step S3401 determine the security protection of UP data of the first terminal and the second terminal.
  • the third information is used to indicate security protection of UP data of the first terminal and/or the second terminal determined by the access network device.
  • FIG4A is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG4A , the present disclosure embodiment relates to an information processing method, which is executed by a core network device, and the method includes:
  • Step S4101 sending the first information.
  • step S4101 can refer to the optional implementation of step S2101 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
  • step S4102 can refer to the optional implementation of step S2102 in FIG. 2 and other related parts in the embodiment involved in FIG. 2 , which will not be described in detail here.
  • the core network device sends the second information to the access network device, but is not limited to this, and the second information may also be sent to other entities.
  • the core network device before step S4101, the core network device obtains the first information.
  • the core network device receives the second information sent by the second terminal, but is not limited thereto, and may also receive the second information sent by other entities.
  • the core network device obtains the second information specified by the protocol.
  • the core network device obtains the second information from an upper layer(s).
  • the core network device performs processing to obtain the second information.
  • the core network device receives the third information sent by the access network device, but is not limited to this, and can also receive the third information sent by other entities.
  • the core network device obtains the third information from the upper layer(s).
  • the first device sends the measurement result to the network device, but is not limited thereto, and the measurement result may also be sent to other entities.
  • step S4101 may be implemented as an independent embodiment
  • step S4102 may be implemented as an independent embodiment
  • step S4101 and step S4102 may be implemented as independent embodiments.
  • step S4101 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.
  • step S4102 may be optional, and one or more of these steps may be omitted or replaced in different embodiments.
  • Step S4201 Send first information and second information to an access network device.
  • the method further includes: receiving first information sent by a first terminal; and/or receiving second information sent by a second terminal.
  • the access network equipment includes a satellite base station; and/or, the core network equipment includes an AMF or an SMF or a PCF.
  • FIG5 is a flow chart of an information processing method according to an embodiment of the present disclosure. As shown in FIG5 , the present disclosure embodiment relates to an information processing method, and the method includes:
  • the above method may include CASE1 or CASE2;
  • CASE1 represents a hypothetical procedure of reusing an existing mechanism;
  • CASE2 represents the enhanced degree of consistency protection for the entire UP data.
  • CASE1 may include steps S5101 to S5103; wherein step S5101 may include step S5101A and/or step S5101B; step S5102 may include step S5102A and/or step S5102B.
  • CASE2 may include steps S5104 to S5108.
  • Step S5101A the PDU session of UE1 is established.
  • Step S5101B the base station activates Uu UP security protection.
  • the base station activates Uu UP security protection according to the received security policy of UE1.
  • Uu UP security protection may be security protection of UP data of a Uu interface; the Uu interface is a communication interface between UE1 and the base station.
  • Step S5102A the PDU session of UE2 is established.
  • UE2 when the network triggers UE1's request for communication, UE2 sends a PDU session establishment process to the core network device; during this process, the core network device sends UE2's UP security policy to the base station.
  • UE2 may be the second terminal in the previous embodiment.
  • the core network device may be the AMF or SMF in the previous embodiment; the AMF of UE2 may be AMF2; and the SMF of UE2 may be SMF2.
  • Step S5102B the base station activates Uu UP security protection.
  • Step S5103 UP data between UE1 and the base station and UP data between UE2 and the base station are securely protected.
  • UP data between UE1 and the base station is protected by the activated security policy of UE1, and UP data between UE2 and the base station is protected by the activated security policy of UE2.
  • the security protection applied to UP data between UE1 and the base station may be different from the protection applied to UP data between UE2 and the base station.
  • Step S5104 The PDU session of UE1 is established.
  • UE1 initiates a PDU session establishment process to the core network, indicating UE2 as the target UE for communication.
  • the core network sends the UP security policy of UE1 to the base station (e.g., eNB).
  • the UP security policy of UE1 may include a UE1-SAT-UE2 communication indication; the UE1-SAT-UE2 communication indication is also sent to the base station by the core network (e.g., SMF1 or AMF1), and the UE1-SAT-UE2 communication indication is used as part of the session management subscription data or session management information.
  • the base station should not immediately activate the Uu UP security policy for UE1, but will wait to receive the UP security policy of UE2 during the PDU session establishment process of UE2.
  • the UP security policy of UE1 may be the first information in the previous embodiment; and the UE1-SAT-UE2 communication indication of UE1 may be the first indication information in the previous embodiment.
  • Step S5105 The PDU session of UE2 is established.
  • UE2 initiates a PDU session establishment process to the core network, indicating UE2 as the target UE for communication.
  • the core network sends the UP security policy of UE2 to the base station (e.g., eNB).
  • the UP security policy of UE2 may include a UE1-SAT-UE2 communication indication; the UE1-SAT-UE2 communication indication is also sent by the core network (e.g., SMF2 or AMF2) sends to the base station, and the UE1-SAT-UE2 communication indication is a part of the session management subscription data or the session management information.
  • the UP security policy of UE2 may be the second information in the previous embodiment; and the UE1-SAT-UE2 communication indication of UE2 may be the second indication information in the previous embodiment.
  • the UP security policy of UE1 (UE1UP security policy) may be different from the UP security policy of UE2 (UE2UP security policy). Therefore, the Uu UP security protection activated for UE1 may be different from the Uu UP security protection activated for UE2.
  • Step S5106 The base station determines how to activate security protection for UE1 and UE2.
  • the base station determines how to consistently activate UP security on two Uu interfaces with UE1 and UE2 based on the received UE1 UP security policy and UE2 UP security policy; this may be as follows:
  • Example 1 If the UE1UP security policy and the UE2UP security policy are consistent (for example, both indicate “needed” or both indicate “not required"), the base station adopts the received UE1UP security policy and UE2UP security policy ("needed" or "not required") to perform consistent security protection on the UP data.
  • performing consistent security protection can be understood as the same security protection for the UP data of the first terminal and the UP data of the second terminal; for example, using the same security policy.
  • Example 2 If both the UE1 UP security policy and the UE2 UP security policy indicate "preferred", the base station determines the UP security policy by itself.
  • Example 3 If one of the UE1 UP security policy and the UE2 UP security policy indicates “need” and the other indicates “preferred", the base station uses "need” as the consistency security protection for UP data.
  • Example 5 If one of the UE1UP security policy and the UE2UP security policy indicates “needed” and the other indicates “not needed”, this means that consistent security protection cannot be performed on the UP data. Then the base station can decide to: refuse to establish a PDU session with UE1 and UE2; or continue to activate Uu UP security protection for UE1 and UE2 respectively based on different security policies, that is, activate inconsistent security protection for UP data.
  • the inability to perform consistent security protection can be understood as different security protection for the UP data of the first terminal and the UP data of the second terminal; for example, using different security policies.
  • Step S5107 the base station activates Uu UP security protection for UE1 and UE2.
  • the gNB activates the Uu UP security protection of UE1 and UE2 based on the UP security policy determined in step S5106; this may also refer to the security state in which the base station activates the security protection of UE1 and UE2, and the security state refers to a state in which protection is required or not required.
  • step S5108 the UP data exchanged between UE1 and UE2 and the base station are securely protected.
  • UP data exchanged between UE1 and UE2 through the base station is always protected by the activated UP security policy.
  • requiring protection includes requiring confidentiality protection and/or requiring integrity protection; not requiring protection includes not requiring confidentiality protection and/or not requiring integrity protection.
  • each embodiment may be implemented individually or in combination with each other, and the steps in each embodiment may be distinguished in order.
  • the disclosed embodiment relates to an information processing method, the method comprising:
  • the base station should be able to receive UE (eg, UE1, UE2) UE1-SAT-UE2 communication indication from the core network device.
  • UE eg, UE1, UE2
  • the base station should be able to determine how to handle the UP security policy of the UEs involved (eg, UE1, UE2) based on the UE1-SAT-UE2 indication from the core network device.
  • the base station should be able to determine a consistent UP security policy for UP data of UE-SAT-UE communication based on the UP security policies of the involved UEs (eg, UE1, UE2).
  • the base station should be able to activate consistent Uu UP security protection for UP data in UE-SAT-UE communication based on its own determined UP security policy.
  • the core network device should be able to send the UE1-SAT-UE2 communication indication as part of the session management subscription data or session management information.
  • part or all of the steps and their optional implementations may be arbitrarily combined with part or all of the steps in other embodiments, and may also be arbitrarily combined with optional implementations of other embodiments.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本公开实施例提出了一种信息处理方法、通信系统及存储介质;信息处理方法,由接入网设备执行,包括:基于第一指示信息和第二指示信息,确定第一终端和第二终端的UP数据的安全保护;其中,第一指示信息用于指示第一终端的UP数据的传输方式和/或安全策略,第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略;如此接入网设备可以确定第一终端和第二终端UP数据的安全保护,可以提升第一终端到卫星到第二终端之间通信的安全性。

Description

信息处理方法、通信系统及存储介质 技术领域
本公开涉及通信技术领域,尤其涉及一种信息处理方法、通信系统及存储介质。
背景技术
在通信技术领域中,引入了卫星通信技术,即用户设备(User Equipment)可以通过卫星接入网络进行通信。其中,UE到卫星到UE(UE—SAT-UE)通信是指一个或多个服务器卫星覆盖下,用户面(User Plane,UP)数据不经过地面网络而通过本地交换在UE之间进行的通信;可选地,UE可以为终端。
发明内容
本公开实施例需要解决如何处理第一终端到卫星到第二终端(即UE-SAT-UE)通信场景下第一终端的UP数据与第二终端的UP数据安全保护的问题。
根据本公开实施例的第一方面,提出了一种信息处理方法,由接入网设备执行,包括:基于第一指示信息和第二指示信息,确定第一终端和第二终端的UP数据的安全保护;其中,第一指示信息用于指示第一终端的UP数据的传输方式和/或安全策略,第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略。
根据本公开实施例的第二方面,提出了一种信息处理方法,由核心网设备执行,包括:向接入网设备发送第一信息,第一信息包括第一指示信息;第一指示信息用于指示第一终端的UP数据的传输方式和/或安全策略;向接入网设备发送第二信息,第二信息包括第二指示信息;第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略;其中,第一指示信息和第二指示信息用于接入网设备确定第一终端和第二终端的UP数据的安全保护。
根据本公开实施例的第三方面,提出了一种接入网设备,包括:第一收发模块,被配置为基于第一指示信息和第二指示信息,确定第一终端和第二终端的UP数据的安全保护;其中,第一指示信息用于指示第一终端的UP数据的传输方式和/或安全策略,第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略。
根据本公开实施例的第四方面,提出了一种核心网设备,包括:第二收发模块,被配置为向接入网设备发送第一信息,第一信息包括第一指示信息;第一指示信息用于指示第一终端的UP数据的传输方式和/或安全策略;第二收发模块,还被配置为向接入网设备发送第二信息,第二信息包括第二指示信息;第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略;其中,第一指示信息和第二指示信息用于接入网设备确定第一终端和第二终端的UP数据的安全保护。
根据本公开实施例的第五方面,提出了一种通信设备,包括一个或多个处理器;其中,上述通信设备用于执行如第一方面、第二方面、或者第一方面和第二方面的可选实现方式。
根据本公开实施例第六方面,提出了一种通信系统,包括:接入网设备和核心网设备;其中,上述接入网设备被配置为执行如第一方面的可选实现方式所描述的方法、上述核心网设备被配置为执行如第二方面的可选实现方式所描述的方法。
根据本公开实施例的第七方面,提出了一种存储介质,上述存储介质存储有指令,当上述指令在通信设备上运行时,使得上述通信设备执行如第一方面、第二方面、或者第一方面和第二方面的可选实现方式所描述的方法。
本公开实施例可以使得接入设备实现对第一终端到卫星到第二终端(即UE-SAT-UE)通信场景下第一终端的UP数据与第二终端的UP数据的安全保护。
附图说明
为了更清楚地说明本公开实施例中的技术方案,以下对实施例描述所需的附图进行介绍,以下附图仅仅是本公开的一些实施例,不对本公开的保护范围造成具体限制。
图1A是根据本公开实施例示出的一种信息处理系统的结构示意图。
图1B是根据一示例性实施例示出的一种UE-SAT-UE提供服务的场景的示意图。
图2是根据本公开实施例示出的一种信息处理方法的交互示意图。
图3A是根据本公开实施例示出的一种信息处理方法的流程示意图。
图3B是根据本公开实施例示出的一种信息处理方法的流程示意图。
图3C是根据本公开实施例示出的一种信息处理方法的流程示意图。
图3D是根据本公开实施例示出的一种信息处理方法的流程示意图。
图4A是根据本公开实施例示出的一种信息处理方法的流程示意图。
图4B是根据本公开实施例示出的一种信息处理方法的流程示意图。
图5是根据本公开实施例示出的一种信息处理方法的流程示意图。
图6A是根据本公开实施例示出的一种接入网设备的结构示意图。
图6B是根据本公开实施例示出的一种核心网设备的结构示意图。
图7A是根据本公开实施例提供的通信设备的结构示意图。
图7B是根据本公开实施例提供的芯片的结构示意图。
具体实施方式
本公开实施例提出了一种信息处理方法、通信系统及存储介质。
第一方面,本公开实施例提出了一种信息处理方法,由接入网设备执行,包括:基于第一指示信息和第二指示信息,确定第一终端和第二终端的UP数据的安全保护;其中,第一指示信息用于指示第一终端的UP数据的传输方式和/或安全策略,第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略。
在上述实施例中,接入网设备可以确定(UE-SAT-UE通信情况下)第一终端和第二终端UP数据的安全保护,可以提升第一终端到卫星到第二终端之间通信的安全性。
结合第一方面的一些实施例,在一些实施例中,确定第一终端和第二终端的UP数据的安全保护,包括以下至少之一:确定第一终端和第二终端的UP数据是否需要进行安全保护;确定第一终端和第二终端的UP数据是否进行一致性安全保护;以及确定第一终端和/或第二终端的UP数据进行安全保护的安全策略。
在上述实施例中,接入网设备可以确定第一终端和第二终端是否进行安全保护、是否进行一致性安全保护和/或进行安全保护的安全策略,从而便于对于第一终端到卫星到第二终端通信时UP数据的统一安全保护等。
结合第一方面的一些实施例,在一些实施例中,方法还包括:接收核心网设备发送的第一信息,其中,第一信息包括第一指示信息;接收核心网设备发送的第二信息,其中,第二信息包括第二指示信息。
在上述实施例中,接入网设备可以从核心网设备接收到第一终端的第一信息和第二终端的第二信息,便于后续基于该第一信息中包括的第一指示信息和第二信息中包括的第二指示信息确定对UP数据的安全保护。
结合第一方面的一些实施例,在一些实施例中,基于第一指示信息和第二指示信息,确定第一终端和第二终端的用户面UP数据的安全保护,包括以下之一:在第一指示信息和第二指示信息指示的UP数据的传输方式均为UE-SAT-UE本地传输的情况下,确定对第一终端和第二终端的UP数据启用一致性安全保护的判断;在第一指示信息和第二指示信息指示的UP数据的安全策略相同且为第一类安全策略的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;在第一指示信息和第二指示信息指示的UP数据的安全策略相同且为第二类安全策略的情况下,确定基于接入网设备确定如何对UP数据进行一致性安全保护;以及在第一指示信息和第二指示信息指示的UP数据的安全策略不同的情况下,根据第一指示信息和第二指示信息分别指示的安全策略的类别,确定第一终端和第二终端的UP数据是否进行一致性保护。
在上述实施例中,接入网设备可以基于第一指示信息和第二指示信息确定是否启用对第一终端和第二终端的UP数据的一致性保护,或者,可以根据第一指示信息和第二指示信息所指示的安全策略,准确确定第一终端和第二终端的UP数据是否需要进行一致性安全保护,以及若需要进行一致性安全保护时具体的安全策略等。
结合第一方面的一些实施例,在一些实施例中,第一类安全策略包括需要保护或者不需要保护;和/或,第二类安全策略包括优选保护;其中,优选保护指示优选接入网设备选择的安全保护。
在上述实施例中,限定了具体的第一类安全策略可以为需要保护或者不需要保护,和/或限定了具体的第二安全策略包括优选保护,从而便于接入网设备基于不同类别的安全策略确定UP数据的安全保护。
结合第一方面的一些实施例,在一些实施例中,根据第一指示信息和第二指示信息分别指示的安全策略的类别,确定第一终端和第二终端的UP数据是否进行一致性保护,包括以下至少之一:在第一指示信息和第二指示信息中一个指示第一类安全策略及另一个指示第二类安全策略的情况下,确定第一终端和第二终端的UP数据进行第一类安全策略的一致性保护;其中,第一类安全策略包括需要保护或者不需要保护,第二类安全策略包括优选保护;以及在第一指示信息和第二指示信息均指示第一类安全策略、且第一指示信息和第二指示信息指示的安全策略不同的情况下,确定第一终端和第二终端的UP数据无法进行一致性保护。
在上述实施例中,若第一终端和第二终端中安全策略一个为需要或者不需要安全保护以及另一个为优选保护时,可以确定出第一终端和第二终端需要进行一致性保护;或者,若第一终端和第二终端中安全策 略一个为需要保护以及另一个为不需要保护时,则确定无法进行一致性安全保护;如此可以这对不同的应用场景确定合适的且准确的安全保护。
结合第一方面的一些实施例,在一些实施例中,方法还包括:在确定第一终端与第二终端无法进行一致性保护的情况下,拒绝与第一终端和第二终端建立会话;或者,在确定第一终端与第二终端无法进行一致性保护的情况下,基于第一指示信息指示的安全策略对第一终端的UP数据进行安全保护,和/或,基于第二指示信息指示的安全策略对第二终端的UP数据进行安全保护。
在上述实施例中,在无法进行一致性安全保护的情况下,可以通过拒接建立的会话,以降低第一终端到卫星到第二终端之间的通信中因无法进行安全保护而带来数据泄露的情况;或者,在无法进行一致性安全保护的情况下,也可以使得第一终端和第二终端按照自身的安全策略进行安全保护,从而可以实现第一终端到卫星到第二终端之间的通信。
结合第一方面的一些实施例,在一些实施例中,方法还包括:基于针对第一终端和第二终端的UP数据的安全策略,激活第一终端和/或第二终端的UP数据的安全保护。
在上述实施例中,可以配置好了安全策略后,激活安全策略进行安全保护。
结合第一方面的一些实施例,在一些实施例中,方法还包括:向第一终端和/或第二终端发送第三信息,其中,第三信息用于指示接入网设备确定的第一终端和/第二终端的UP数据的安全保护;第三信息用于第一终端和/或第二终端进行UP数据的安全保护。
在上述实施例中,可以向第一终端和/或第二终端发送第三信息,以使得第一终端和/或第二终端基于接入网设备配置的安全策略进行安全保护。
结合第一方面的一些实施例,在一些实施例中,接入网设备包括卫星基站;和/或,核心网设备包括:接入和移动性管理功能(Access and Mobility management Function,AMF),或者,会话管理功能(Session Management Function,SMF),或者,策略控制功能(Policy Control Function,PCF)。
第二方面,本公开实施例提出了一种信息处理方法,由核心网设备执行,包括:向接入网设备发送第一信息,第一信息包括第一指示信息;第一指示信息用于指示第一终端的UP数据的传输方式和/或安全策略;向接入网设备发送第二信息,第二信息包括第二指示信息;第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略;其中,第一指示信息和第二指示信息用于接入网设备确定第一终端和第二终端的UP数据的安全保护。
结合第二方面的一些实施例,在一些实施例中,方法还包括:接收第一终端发送的第一信息;和/或,接收第二终端发送的第二信息。
结合第二方面的一些实施例,在一些实施例中,接入网设备包括卫星基站;和/或,核心网设备包括AMF或者SMF或者PCF。
第三方面,本公开实施例提出了一种接入网设备,包括:第一收发模块,被配置为基于第一指示信息和第二指示信息,确定第一终端和第二终端的UP数据的安全保护;其中,第一指示信息用于指示第一终端的UP数据的传输方式和/或安全策略,第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略。
第四方面,本公开实施例提出了一种核心网设备,包括:第二收发模块,被配置为向接入网设备发送第一信息,第一信息包括第一指示信息;第一指示信息用于指示第一终端的UP数据的传输方式和/或安全策略;第二收发模块,还被配置为向接入网设备发送第二信息,第二信息包括第二指示信息;第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略;其中,第一指示信息和第二指示信息用于接入网设备确定第一终端和第二终端的UP数据的安全保护。
第五方面,本公开实施例提出了一种通信设备,包括一个或多个处理器;其中,上述通信设备用于执行如第一方面、第二方面、或者第一方面和第二方面的可选实现方式。
第六方面,本公开实施例中提出了一种通信系统,包括:接入网设备和核心网设备;其中,上述接入网设备被配置为执行如第一方面的可选实现方式所描述的方法、上述核心网设备被配置为执行如第二方面的可选实现方式所描述的方法。
第七方面,本公开实施例提出了一种存储介质,上述存储介质存储有指令,当上述指令在通信设备上运行时,使得上述通信设备执行如第一方面、第二方面、或者第一方面和第二方面的可选实现方式所描述的方法。
第八方面,本公开实施例提出了程序产品,上述程序产品被通信设备执行时,使得上述通信设备执行如第一方面、第二方面、或者第一方面和第二方面的可选实现方式所描述的方法。
第九方面,本公开实施例提出了计算机程序,当其在计算机上运行时,使得计算机执行如第一方面、第二方面、或者第一方面和第二方面的可选实现方式所描述的信息处理方法。
第十方面,本公开实施例提出了一种芯片或芯片系统;该芯片或芯片系统包括处理电路,被配置为执行根据上述第一方面、第二方面、或者第一方面和第二方面的可选实现方式所描述的方法。
可以理解的是,上述网络设备、第一设备、通信系统、存储介质、程序产品、计算机程序、芯片或芯片系统均用于执行本公开实施例所提供的方法。因此,其所能达到的有益效果可以参考对应方法中的有益效果,此处不再赘述。
本公开实施例提出了一种信息处理方法、设备、通信系统及存储介质。在一些实施例中,信息处理方法与通信方法等术语可相互替换,信息处理装置与通信装置等术语可相互替换,信息处理系统与通信系统等术语可相互替换。
本公开实施例并非穷举,仅为部分实施例的示意,不作为对本公开保护范围的具体限制。在不矛盾的情况下,某一实施例中的每个步骤均可作为独立实施例来实施,且各步骤之间可任意组合,例如,在某一实施例中去除部分步骤后的方案也可作为独立实施例来实施,且在某一实施例中各步骤的顺序可任意交换,另外,某一实施例中的可选实现方式可任意组合;此外,各实施例之间可任意组合,例如,不同实施例的部分或全部步骤可任意组合,某一实施例可以与其他实施例的可选实现方式任意组合。
在各本公开实施例中,如果没有特殊说明以及逻辑冲突,各实施例之间的术语和/或描述具有一致性,且可以互相利用,不同实施例中的技术特征根据其内在的逻辑关系可以组合形成新的实施例。
本公开实施例中所述使用的术语只是为了描述特定实施例中的目的,而并非作为对本公开的限制。
在本公开实施例中,除非另有说明,以单数形式表示的元素,如“一个”、“一种”、“该”、“上述”、“所述”、“前述”、“这一”等,可以表示“一个且只有一个”,也可以表示“一个或多个”、“至少一个”等。例如,在翻译中使用如英语中的“a”、“an”、“the”等冠词(article)的情况下,冠词之后的名词可以理解为单数表达形式,也可以理解为复数表达形式。
在本公开实施例中,“多个”是指两个或两个以上。
在一些实施例中,“至少一者(至少一项、至少一个)(at least one of)”、“一个或多个(one or more)”、“多个(a plurality of)”、“多个(multiple)等术语可以相互替换。
在一些实施例中,“A、B中的至少一者”、“A和/或B”、“在一情况下A,在另一情况下B”、“响应于一情况A,响应于另一情况B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择执行(A和B被选择性执行);在一些实施例中A和B(A和B都被执行)。当有A、B、C等更多分支时也类似上述。
在一些实施例中,“A或B”等记载方式,根据情况可以包括以下技术方案:在一些实施例中A(与B无关地执行A);在一些实施例中B(与A无关地执行B);在一些实施例中从A和B中选择执行(A和B被选择性执行)。当有A、B、C等更多分支时也类似上述。
本公开实施例中的“第一”、“第二”等前缀词,仅仅为了区分不同的描述对象,不对描述对象的位置、顺序、优先级、数量或内容等构成限制,对描述对象的陈述参见权利要求或实施例中上下文的描述,不应因为使用前缀词而构成多余的限制。例如,描述对象为“字段”,则“第一字段”和“第二字段”中“字段”之前的序数词并不限制“字段”之间的位置或顺序,“第一”和“第二”并不限制其修饰的“字段”是否在同一个消息中,也不限制“第一字段”和“第二字段”的先后顺序。再如,描述对象为“等级”,则“第一等级”和“第二等级”中“等级”之前的序数词并不限制“等级”之间的优先级。再如,描述对象的数量并不受序数词的限制,可以是一个或者多个,以“第一装置”为例,其中“装置”的数量可以是一个或者多个。此外,不同前缀词修饰的对象可以相同或不同,例如,描述对象为“装置”,则“第一装置”和“第二装置”可以是相同的装置或者不同的装置,其类型可以相同或不同;再如,描述对象为“信息”,则“第一信息”和“第二信息”可以是相同的信息或者不同的信息,其内容可以相同或不同。
在一些实施例中,“包括A”、“包含A”、“用于指示A”、“携带A”,可解释为直接携带A,也可解释为间接指示A。
在一些实施例中,“响应于……”、“响应于确定……”、“在……的情况下”、“在……时”、“当……时”、“若……”、“如果……”等术语可以相互替换。
在一些实施例中,“大于”、“大于或等于”、“不小于”、“多于”、“多于或等于”、“不少于”、“高于”、“高于或等于”、“不低于”、“以上”等术语可以相互替换,“小于”、“小于或等于”、“不大于”、“少于”、“少于或等于”、“不多于”、“低于”、“低于或等于”、“不高于”、“以下”等术语可以相互替换。
在一些实施例中,装置等可以解释为实体的、也可以解释为虚拟的,其名称不限定于实施例中所记载的名称,“装置”、“设备(equipment)”、“设备(device)”、“电路”、“网元”、“节点”、“功 能”、“单元”、“部件(section)”、“系统”、“网络”、“芯片”、“芯片系统”、“实体”、“主体”等术语可以相互替换。
在一些实施例中,“网络”可以解释为网络中包含的装置(例如,接入网设备、核心网设备等)。
在一些实施例中,“接入网设备(access network device,AN device)”、“无线接入网设备(radio access network device,RAN device)”、“基站(base station,BS)”、“无线基站(radio base station)”、“固定台(fixed station)”、“节点(node)”、“接入点(access point)”、“发送点(transmission point,TP)”、“接收点(reception point,RP)”、“发送接收点(transmission/reception point,TRP)”、“面板(panel)”、“天线面板(antenna panel)”、“天线阵列(antenna array)”、“小区(cell)”、“宏小区(macro cell)”、“小型小区(small cell)”、“毫微微小区(femto cell)”、“微微小区(pico cell)”、“扇区(sector)”、“小区组(cell group)”、“载波(carrier)”、“分量载波(component carrier)”、“带宽部分(bandwidth part,BWP)”等术语可以相互替换。
在一些实施例中,“终端(terminal)”、“终端设备(terminal device)”、“用户设备(user equipment,UE)”、“用户终端(user terminal)”、“移动台(mobile station,MS)”、“移动终端(mobile terminal,MT)”、订户站(subscriber station)、移动单元(mobile unit)、订户单元(subscriber unit)、无线单元(wireless unit)、远程单元(remote unit)、移动设备(mobile device)、无线设备(wireless device)、无线通信设备(wireless communication device)、远程设备(remote device)、移动订户站(mobile subscriber station)、接入终端(access terminal)、移动终端(mobile terminal)、无线终端(wireless terminal)、远程终端(remote terminal)、手持设备(handset)、用户代理(user agent)、移动客户端(mobile client)、客户端(client)等术语可以相互替换。
在一些实施例中,接入网设备、核心网设备、或网络设备可以被替换为终端。例如,针对将接入网设备、核心网设备、或网络设备以及终端间的通信置换为多个终端间的通信(例如,也可以被称为设备对设备(device-to-device,D2D)、车联网(vehicle-to-everything,V2X)等)的结构,也可以应用本公开的各实施例。在该情况下,也可以设为终端具有接入网设备所具有的全部或部分功能的结构。此外,“上行”、“下行”等语言也可以被替换为与终端间通信对应的语言(例如,“侧行(side)”)。例如,上行信道、下行信道等可以被替换为侧行信道,上行链路、下行链路等可以被替换为侧行链路。
在一些实施例中,终端可以被替换为接入网设备、核心网设备、或网络设备。在该情况下,也可以设为接入网设备、核心网设备、或网络设备具有终端所具有的全部或部分功能的结构。
在一些实施例中,获取数据、信息等可以遵照所在地国家的法律法规。
在一些实施例中,可以在得到用户同意后获取数据、信息等。
此外,本公开实施例的表格中的每一元素、每一行、或每一列均可以作为独立实施例来实施,任意元素、任意行、任意列的组合也可以作为独立实施例来实施。
图1A是根据本公开实施例示出的一种信息处理系统100的结构示意图。如图1A所示,信息处理系统100可以包括:终端(terminal)101、网络设备102。
在一些实施例中,网络设备102可包括接入网设备和核心网设备(core network device)的至少一者。
在一些实施例中,终端101例如包括手机(mobile phone)、可穿戴设备、物联网(IOT)设备或终端、具备通信功能的汽车、智能汽车、平板电脑(Pad)、带无线收发功能的电脑、虚拟现实(virtual reality,VR)终端设备、增强现实(augmented reality,AR)终端设备、工业控制(industrial control)中的无线终端设备、无人驾驶(self-driving)中的无线终端设备、远程手术(remote medical surgery)中的无线终端设备、智能电网(smart grid)中的无线终端设备、运输安全(transportation safety)中的无线终端设备、智慧城市(smart city)中的无线终端设备、智慧家庭(smart home)中的无线终端设备中的至少一者,但不限于此。
在一些实施例中,接入网设备例如是将终端接入到无线网络的节点或设备,接入网设备可包括5G通信系统中的演进节点B(evolved NodeB,eNB)、下一代演进节点B(next generation eNB,ng-eNB)、下一代节点B(next generation NodeB,gNB)、节点B(node B,NB)、家庭节点B(home node B,HNB)、家庭演进节点B(home evolved nodeB,HeNB)、无线回传设备、无线网络控制器(radio network controller,RNC)、基站控制器(base station controller,BSC)、基站收发台(base transceiver station,BTS)、基带单元(base band unit,BBU)、移动交换中心、6G通信系统中的基站、开放型基站(Open RAN)、云基站(Cloud RAN)、其他通信系统中的基站、无线保真(wireless fidelity,WiFi)系统中的接入节点中的至少一者,但不限于此。
在一些实施例中,本公开的技术方案可适用于Open RAN架构,此时,本公开实施例所涉及的接入网 设备间或者接入网设备内的接口可变为Open RAN的内部接口,这些内部接口之间的流程和信息交互可以通过软件或者程序实现。
在一些实施例中,接入网设备可以由集中单元(central unit,CU)与分布式单元(distributed unit,DU)组成的,其中,CU也可以称为控制单元(control unit),采用CU-DU的结构可以将接入网设备的协议层拆分开,部分协议层的功能放在CU集中控制,剩下部分或全部协议层的功能分布在DU中,由CU集中控制DU,但不限于此。
在一些实施例中,核心网设备可以是一个设备,包括第一设备、第二设备等,也可以是多个设备或设备群,分别包括上述第一设备和第二设备中的全部或部分。第一设备和第二设备可以是网元;网元可以是虚拟的,也可以是实体的。核心网例如包括演进分组核心(Evolved Packet Core,EPC)、5G核心网络(5G Core Network,5GCN)、下一代核心(Next Generation Core,NGC)中的至少一者。
可以理解的是,本公开实施例描述的信息处理系统是为了更加清楚的说明本公开实施例的技术方案,并不构成对于本公开实施例提供的技术方案的限定,本领域普通技术人员可知,随着系统架构的演变和新业务场景的出现,本公开实施例提供的技术方案对于类似的技术问题同样适用。
下述本公开实施例可应用于图1A所示的信息处理系统100、或部分主体,但不限于此。图1A所示的各主体是例示,信息处理系统可以包括图1A中全部或者部分主体,也可以包括图1A以外的其他主体,各主体数量和形态为任意,各主体之间的连接关系是例示,各主体之间可以不连接也可以连接,其连接可以是任意方式,可以是直接连接也可以是间接连接,可以是有线连接也可以是无线连接。
本公开各实施例可以应用于长期演进(Long Term Evolution,LTE)、LTE-Advanced(LTE-A)、LTE-Beyond(LTE-B)、SUPER 3G、IMT-Advanced、第四代移动通信系统(4th generation mobile communication system,4G)、)、第五代移动通信系统(5th generation mobile communication system,5G)、5G新空口(New Radio,NR)、未来无线接入(Future Radio Access,FRA)、新无线接入技术(New-Radio Access Technology,RAT)、新无线(New Radio,NR)、新无线接入(New Radio access,NX)、未来一代无线接入(Future generation radio access,FX)、Global System for Mobile communications(GSM(注册商标))、CDMA2000、超移动宽带(Ultra Mobile Broadband,UMB)、IEEE 802.11(Wi-Fi(注册商标))、IEEE 802.16(WiMAX(注册商标))、IEEE 802.20、超宽带(Ultra-WideBand,UWB)、蓝牙(Bluetooth(注册商标))、陆上公用移动通信网(Public Land Mobile Network,PLMN)网络、设备到设备(Device-to-Device,D2D)系统、机器到机器(Machine to Machine,M2M)系统、物联网(Internet of Things,IoT)系统、车联网(Vehicle-to-Everything,V2X)、利用其他通信方法的系统、基于它们而扩展的下一代系统等。此外,也可以将多个系统组合(例如,LTE或者LTE-A与5G的组合等)应用。
在一些实施例中,UE到卫星到UE(UE—SAT-UE)通信是指一个或多个服务器卫星覆盖下,用户面(User Plane,UP)数据不经过地面网络而通过本地交换在UE之间进行的通信。该UE到卫星到UE通信可以是终端到卫星到终端通信;例如可以是第一终端到卫星到第二终端通信。
示例性的,如图1B所示,提供了一种UE-SAT-UE提供服务的场景;图1B描述的网络系统支持UE-SAT-UE通信,该网络系统可包括UE x、UE y、和搭载在卫星(Satellite,SAT)x上的基站(例如,gNB)等。卫星X上的gNB与地面之间具有反馈链路(feeder link),该反馈链路可用于卫星x上的gNB连接到核心网。卫星X上的gNB有形成卫星小区A,小区A可以与地面小区相邻。卫星x上的gNB和UE x和UE y之间的Uu口之间的连接是卫星链路;UE x和UE y之间,可以基于卫星X上的基站进行用户面数据的传输;搭载在卫星x上的gNB与地面之间的连接可用于控制面(Control Plane,CP)信令交互。这里,两个UE(例如UE x和UE y)处于通信中,但该通信可涉及两个以上UE;AMF为5G核心网的网络功能(Network Function,NF)代表,当然也可以是包含其它的NF(例如SMF)。这里,如果卫星服务于一个以上的小区,该两个或者两个以上UE可以在不同的小区中。
在一些实施例中,基于从核心网络发送的安全策略(Security Policy)来激活Uu接口上的用户面数据的安全,该安全策略由统一数据管理(Unified Data Management,UDM)或SMF基于UE请求的特定服务来设置。SMF在PDU会话建立时基于以下因素确定协议数据单元(Protocol Data Unit,PDU)会话的UP安全实施信息:订阅的安全策略是从UDM收到的会话管理订阅信息的一部分;或者,在SMF中按(单个数据网络名称(Date Network Name,DNN),或者单网络切片选择辅助信息(Single Network Slice Selection AssiSATnce Information,S-NSSAI)本地配置的UP安全策略在UDM不提供UP安全策略时使用。这里,Uu接口为UE与基站之间的蜂窝通信接口。
在一些实施例中,UP安全策略指示是否应该在该PDU会话的Uu接口激活UP数据的安全保护。UP安全策略用于激活PDU会话的保密性和/或完整性的安全保护。根据SMF提供的UP安全策略,如果该 UP安全策略指示“需要(Required)”,则gNB使用RRC信令激活每个数据无线承载(Data Radio Bearer,DRB)的Uu UP安全保护;或者,如果UP安全策略指示“不需要(Not Needed)”,则PDU会话的建立将在没有保护的情况下继续进行;或者,如果UP安全策略指示“优选(Preferred)”,则gNB可以决定是否激活Uu UP安全保护。但是,当UP安全策略显示“需要”或“不需要”时,gNB不能否决从SMF收到的UP安全策略。可选地,UP数据可以为UP业务数据或者UP流量等。
在一些实施例中,对于通过5G网络的UE到UE通信,UE分别经由可能独立的基站与核心网设备建立单独的PDU会话。则gNB对UE的单独PDU会话应用可能不同的对应UE的UP安全策略。
对于UE-SAT-UE通信,其在本地交换UP数据,而不让其通过核心网设备(例如SMF)驻留的地面网络,可以假设UE-SAT-UE通信可以利用单个PDU会话来建立。如果gNB分别为UE接收可能不同的UP安全策略,则gNB应该如何将这些UP安全策略应用于单个PDU会话以保护用户面流量将是一个问题。
假设为UE-SAT-UE通信建立两个单独的PDU会话,如果通信的UE具有不同的UP安全策略,则可能导致对单个UE-SAT-UE通信会话的两个Uu接口应用不同的安全保护。在这种情况下,一个Uu接口上的较高安全保护(例如,完整性和机密性保护)可能被另一个Uu接口上的较低安全保护(例如,仅完整性保护或仅机密性保护或无保护)所降级。
因此,对于UE-SAT-UE通信,gNB应该如何处理通信UE的UP安全策略,以及应该如何在发送UE和卫星上的gNB以及接收UE之间激活Uu UP安全,这些都需要研究。
如图2是根据本公开实施例示出的一种信息处理方法的交互示意图。如图2所示,本公开实施例涉及信息处理方法用于信息处理系统100,上述方法包括:
步骤S2101,核心网设备向接入网设备发送第一信息。
在一些实施例中,接入网设备接收核心网设备发送的第一信息。
可选地,接入网设备可以为基站;例如可以为卫星基站等。
可选地,核心网设备可以为AMF或者SMF或者PCF等。
在一些实施例中,第一信息包括第一指示信息。
可选地,第一信息可包括与UP安全策略相关的信息。示例性的,第一信息可包括以下至少之一:会话管理信息、第一终端的第一标识、UE-SAT-UE通信的业务标识、UE-SAT-UE通信使用的数据网络名称以及UE-SAT-UE通信使用的当网络切片选择辅助信息等。
可选地,第一标识可以为用于指示第一终端的任意编号或者字符串等。可选地,第一标识可以为第一终端的用户信息标识(User Info)、签约用户隐式标识(Subscription Concealed Identifier,SUCI)、用户永久标识符(Subscription Permanent Identity,SUPI)或者全球唯一临时标识(Globally Unique Temporary UE Identity,GUTI)等。
可选地,UE-SAT-UE通信可配置有一个或多个业务,这些业务的业务流量或者业务数据可基于UE-SAT-UE通信传输。
可选地,UE-SAT-UE通信可以是指本地通信或者基于卫星的本地通信。
可选地,第一信息的名称可不做限定,其例如可以是安全策略信息或者UP安全策略信息或者UP安全策略或者Uu UP安全策略等。
在一些实施例中,第一指示信息用于指示第一终端的UP数据的传输方式和/或安全策略。可选地,UP数据可由UP流量、UP业务、UP业务数据或者、UP业务流量等替换。
可选地,第一指示信息用于指示UE-SAT-UE通信情况下第一终端的UP数据的安全策略。
可选地,传输方式可包括UE-SAT-UE通信或者非UE-SAT-UE通信。该非UE-SAT-UE通信可以是指除UE-SAT-UE通信之外的通信。
可选地,安全策略可以为之前实施例中UP安全策略。
可选地,安全策略可包括第一类安全策略和/或第二类安全策略。示例性的,第一类安全策略可包括需要保护或者不需要保护。示例性的,第二类安全策略可包括优选保护;优选保护指示优选接入网设备选择的安全保护或者安全策略。
可选地,安全策略可包括需要保护、不需要保护和/或优先保护。
可选地,该需要保护可以为之前实施例中的“需要”;该不需要保护可以为之前实施例中的“不需要”;该优选保护可以为之前实施例中“优选”。
可选地,需要保护可包括需要完整性保护和/或机密性保护。
可选地,不需要保护可包括不需要安全保护和/或不需要机密性保护。
可选地,优选保护可包括优先选择接入网设备选择的安全保护和/或机密性保护。
可选地,第一指示信息可包括一个或多个比特,或者一个或多个字段。例如,可通过第一指示信息一个或多个比特来指示需要完整性保护和/或机密性保护、不需要安全保护和/或不需要机密性保护以及优先选择接入网设备选择的安全、保护和/或机密性保护。又如,可通过第一指示信息中不同的字段来分别指示需要保护、不需要保护及优先保护;如通过第一指示信息的第一字段为第一取值时指示需要完整性保护,或者通过第一指示信息的第一字段为第二取值时指示需要机密性保护,或者通过第一指示信息的第一字段为第三取值时,指示需要完整性保护和机密性保护;又如通过第一指示信息的第二字段为第一取值时指示不需要完整性保护,或者通过第一指示信息的第二字段为第二取值时指示不需要机密性保护,或者通过第一指示信息的第二字段为第三取值时,指示不需要完整性保护和不需要机密性保护。
可选地,第一指示信息的名称可不做限定,其例如是UE-SAT-UE通信指示或者安全策略指示等。
在一些可选实施例中,第一信息是核心网设备在接收到第一终端发送的PDU会话请求后发送的。可选地,PDU会话请求用于请求建立PDU会话。可选地,PDU会话请求可包括用于指示第二终端作为目标终端的标识信息。这里,第一终端可以为第一UE或者UE1或者为之前实施例中UE x。
步骤S2102,核心网设备向接入网设备发送第二信息。
在一些实施例中,接入网设备接收核心网设备发送的第二信息。
在一些实施例中,第二信息包括第二指示信息。
可选地,第二信息可包括与UP安全策略相关的信息。示例性的,第二信息可包括以下至少之一:会话管理信息、第二终端的第二标识、UE-SAT-UE通信的业务标识、UE-SAT-UE通信使用的数据网络名称以及UE-SAT-UE通信使用的当网络切片选择辅助信息等。
可选地,第二标识可以为用于指示第二终端的任意编号或者字符串等。可选地,第二标识可以为第一终端的用户信息标识(User Info)、SUCI、SUPI或者GUTI等。
可选地,第二信息的名称可不做限定,其例如可以是安全策略信息或者UP安全策略信息或者UP安全策略或者Uu UP安全策略等。
在一些实施例中,第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略。
可选地,第二指示信息用于指示UE-SAT-UE通信情况下第二终端的UP数据的安全策略。
可选地,第二指示信息可包括一个或多个比特,或者一个或多个字段。例如,可通过第二指示信息一个或多个比特来指示需要完整性保护和/或机密性保护、不需要安全保护和/或不需要机密性保护以及优先选择接入网设备选择的安全保护和/或机密性保护。又如,可通过第二指示信息中不同的字段来分别指示需要保护、不需要保护及优先保护;如通过第二指示信息的第一字段为第一取值时指示需要完整性保护,或者通过第二指示信息的第一字段为第二取值时指示需要机密性保护,或者通过第二指示信息的第一字段为第三取值时,指示需要完整性保护和机密性保护;又如通过第二指示信息的第二字段为第一取值时指示不需要完整性保护,或者通过第二指示信息的第二字段为第二取值时指示不需要机密性保护,或者通过第二指示信息的第二字段为第三取值时,指示不需要完整性保护和不需要机密性保护。
可选地,第二指示信息的名称可不做限定,其例如是UE-SAT-UE通信指示或者安全策略指示等。
在一些可选实施例中,第二信息是核心网设备在接收到第二终端发送的PDU会话请求后发送的。可选地,PDU会话请求用于请求建立PDU会话。这里,第二终端可以为第二UE或者UE2或者为之前实施例中的UE y。
步骤S2103,接入网设备确定第一终端和第二终端的UP数据的安全保护。
可选地,接入网设备确定第一终端到卫星到第二终端(UE-SAT-UE)通信情况下的UP数据的安全保护。
在一些实施例中,确定第一终端和第二终端的UP数据的安全保护,包括以下至少之一:确定第一终端是否支持UE-SAT-UE的传输方式、确定是否启用第一终端和第二终端的UP数据一致性安全保护的判断或者判决、确定第一终端和第二终端的UP数据是否需要进行安全保护;确定第一终端和第二终端的UP数据是否进行一致性安全保护;确定第一终端和/或第二终端的UP数据进行安全保护的安全策略。
在一些实施例中,接入网设备在第一指示信息和第二指示信息指示的UP数据的传输方式均为UE-SAT-UE本地传输或者UE-SAT-UE通信的情况下,确定对第一终端和第二终端的UP数据启用一致性安全保护的判断。这里,启用一致性安全保护的判断可以为:确定第一终端和第二终端的UP数据是否进行一致性安全保护。
可选地,是否进行一致性安全保护是指:是否使用相同的安全策略。
在一些实施例中,接入网设备在第一指示信息和第二指示信息指示的UP数据的安全策略相同且为第一类安全策略的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护。
可选地,接入网设备在第一指示信息和第二指示信息指示的UP数据的安全策略均为需要保护的情况 下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为需要保护。
示例性的,在第一指示信息和第二指示信息指示的UP数据的安全策略均为需要完整性保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为需要完整性保护。
示例性的,在第一指示信息和第二指示信息指示的UP数据的安全策略均为需要机密性保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为需要机密性保护。
示例性的,在第一指示信息和第二指示信息指示的UP数据的安全策略均为需要完整性保护和需要机密性保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为需要完整性保护和需要机密性保护。
可选地,接入网设备在第一指示信息和第二指示信息指示的UP数据的安全策略均为不需要保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为不需要保护。
示例性的,在第一指示信息和第二指示信息指示的UP数据的安全策略均为不需要完整性保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为不需要完整性保护。
示例性的,在第一指示信息和第二指示信息指示的UP数据的安全策略均为不需要机密性保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为不需要机密性保护。
示例性的,在第一指示信息和第二指示信息指示的UP数据的安全策略均为不需要完整性保护和不需要机密性保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为不需要完整性保护和不需要机密性保护。
示例性的,在第一指示信息和第二指示信息指示的UP数据的安全策略均为不需要完整性保护和需要机密性保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为不需要完整性保护和需要机密性保护。
示例性的,在第一指示信息和第二指示信息指示的UP数据的安全策略均为需要完整性保护和不需要机密性保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为需要完整性保护和不需要机密性保护。
在一些实施例中,接入网设备在第一指示信息和第二指示信息指示的UP数据的安全策略相同且为第二类安全策略的情况下,确定基于接入网设备确定如何对UP数据进行一致性安全保护。
可选地,接入网设备在第一指示信息和第二指示信息指示的UP数据的安全策略均为优选保护情况下,确定基于接入网设备确定如何对UP数据进行一致性安全保护。这里,确定如何对UP数据进行一致性安全保护可以为确定是否进行一致性安全保护。
示例性的,在第一指示信息和第二指示信息指示的UP数据的安全策略均为优选保护情况下,则接入网设备自行确定UP数据的安全策略。此时接入网设备可以确定UP数据进行一致性保护或者不进行一致性保护;例如,接入网设备确定第一终端和第二终端的UP数据均需要保护,或者接入网设备确定第一终端和第二终端的UP数据均不需要保护;或者,接入网设备确定第一终端和第二终端的UP数据中的一个需要保护或者不需要保护。
在一些实施例中,接入网设备在第一指示信息和第二指示信息指示的UP数据的安全策略不同的情况下,根据第一指示信息和第二指示信息分别指示的安全策略的类别,确定第一终端和第二终端的UP数据是否进行一致性保护。
可选地,接入网在第一指示信息和第二指示信息中一个指示第一类安全策略及另一个指示第二类安全策略的情况下,确定第一终端和第二终端的UP数据进行第一类安全策略的一致性保护;其中,第一类安全策略包括需要保护或者不需要保护,第二类安全策略包括优选保护。
示例性的,在第一指示信息指示需要保护及第二指示信息指示优选保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为需要保护。
示例性的,在第一指示信息指示不需要保护及第二指示信息指示优选保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为不需要保护。
示例性的,在第一指示信息指示优选保护及第二指示信息指示需要保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为需要保护。
示例性的,在第一指示信息指示优选保护及第二指示信息指示不需要保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为不需要保护。
示例性的,在第一指示信息和第二指示信息均指示优选保护的情况下,确定第一终端和第二终端的UP数据进行一致性安全保护;且还可以确定第一终端和第二终端的UP数据的安全策略均为不需要保护或均为需要保护。
在一些实施例中,接入网设备在第一指示信息和第二指示信息均指示第一类安全策略、且第一指示信息和第二指示信息指示的安全策略不同的情况下,确定第一终端和第二终端的UP数据无法进行一致性保护。可选地,无法进行一致性保护,即不进行一致性保护。
可选地,接入网设备在第一指示信息指示需要保护及第二指示信息指示不需要保护的情况下,确定第一终端和第二终端的UP数据无法进行一致性安全保护。
可选地,接入网设备在第一指示信息指示不需要保护及第二指示信息指示需要保护的情况下,确定第一终端和第二终端的UP数据无法进行一致性安全保护。
在一些实施例中,接入网设备在确定第一终端与第二终端无法进行一致性保护的情况下,拒绝与第一终端和第二终端建立会话。
可选地,会话为PDU会话或者其他任意UP业务相关的会话等。
在一些实施例中,接入网设备在确定第一终端与第二终端无法进行一致性保护的情况下,基于第一指示信息指示的安全策略对第一终端的UP数据进行安全保护,和/或,基于第二指示信息指示的安全策略对第二终端的UP数据进行安全保护。
示例性的,在第一指示信息指示需要保护及第二指示信息指示不需要保护的情况下,确定第一终端和第二终端的UP数据无法进行一致性安全保护;并且确定第一终端的UP数据需要安全保护以及确定第二终端的UP数据不需要安全保护。
示例性的,在第一指示信息指示不需要保护及第二指示信息指示需要保护的情况下,确定第一终端和第二终端的UP数据无法进行一致性安全保护;并且确定第一终端的UP数据不需要安全保护以及确定第二终端的UP数据需要安全保护。
在一些可选实施例中,接入网设备基于针对第一终端和第二终端的UP数据的安全策略,激活第一终端和/或第二终端的UP数据的安全保护。
示例性的,若第一终端和第二终端的UP数据均为需要保护,激活或者确定第一终端和第二终端的UP数据进行安全保护。
示例性的,若第一终端和第二终端的UP数据均为不需要保护,激活或者确定第一终端和第二终端的UP数据不进行安全保护。
示例性的,若第一终端的UP数据为需要保护和第二终端的UP数据为不需要保护,激活或者确定第一终端的UP数据进行安全保护和第二终端的UP数据不进行安全保护。
示例性的,若第一终端的UP数据为不需要保护和第二终端的UP数据为需要保护,激活或者确定第一终端的UP数据不进行安全保护和第二终端的UP数据进行安全保护。
上述实施例中需要保护包括需要机密性保护和/或需要完整性保护;不需要保护包括不需要机密性保护和/或不需要完整性保护。
步骤S2104,接入网设备向第一终端和/或第二终端发送第三信息。
在一些实施例中,第一终端和/或第二终端接收接入网设备发送的第三信息。
在一些实施例中,第三信息用于指示接入网设备确定的第一终端和/第二终端的UP数据的安全保护;第三信息用于第一终端和/或第二终端进行UP数据的安全保护。
可选地,接入网设备确定的第一终端和/或第二终端的UP数据的安全保护,可包括:接入网设备自行确定的第一终端和/或第二终端的UP数据的安全保护,或者,接入网设备基于第一指示信息和第二指示信息确定第一终端和/或第二终端的UP数据的安全保护。这里,安全保护可以是指安全策略;该安全保护可以是指需要保护或者不需要保护等。
可选地,第三信息还可包括以下至少之一:第一标识、第二标识、UE-SAT-UE通信的业务标识UE-SAT-UE通信使用的数据网络名称以及UE-SAT-UE通信使用的当网络切片选择辅助信息等。
可选地,第三信息的名称不做限定,其例如可以是安全策略信息、UP安全策略信息或者安全策略指 示信息等。
上述实施例中需要保护包括需要机密性保护和/或需要完整性保护;不需要保护包括不需要机密性保护和/或不需要完整性保护。
在一些可选实施例中,第一终端基于第三信息进行UP数据的安全保护。
在一些可选实施例中,第二终端基于第三信息进行UP数据的安全保护。
在一些可选实施例中,接入网设备也可将第三信息发送给核心网设备。
在一些实施例中,信息等的名称不限定于实施例中所记载的名称,“信息(information)”、“消息(message)”、“信号(signal)”、“信令(signaling)”、“报告(report)”、“配置(configuration)”、“指示(indication)”、“指令(instruction)”、“命令(command)”、“信道”、“参数(parameter)”、“域”、“字段”、“符号(symbol)”、“码元(symbol)”、“码本(codebook)”、“码字(codeword)”、“码点(codepoint)”、“比特(bit)”、“数据(data)”、“程序(program)”、“码片(chip)”等术语可以相互替换。
在一些实施例中,“获取”、“获得”、“得到”、“接收”、“传输”、“双向传输”、“发送和/或接收”可以相互替换,其可以解释为从其他主体接收,从协议中获取,从高层获取,自身处理得到、自主实现等多种含义。
在一些实施例中,“发送”、“发射”、“上报”、“下发”、“传输”、“双向传输”、“发送和/或接收”等术语可以相互替换。
在一些实施例中,“特定(certain)”、“预定(preset)”、“预设”、“设定”、“指示(indicated)”、“某一”、“任意”、“第一”等术语可以相互替换,“特定A”、“预定A”、“预设A”、“设定A”、“指示A”、“某一A”、“任意A”、“第一A”可以解释为在协议等中预先规定的A,也可以解释为通过设定、配置、或指示等得到的A,也可以解释为特定A、某一A、任意A、或第一A等,但不限于此。
在一些实施例中,判定或判断可以通过以1比特表示的值(0或1)来进行,也可以通过以真(true)或者假(false)表示的真假值(布尔值(boolean))来进行,也可以通过数值的比较(例如,与预定值的比较)来进行,但不限于此。
本公开实施例所涉及的信息处理方法可以包括步骤S2101至步骤S2104中至少一者。例如,步骤S2101可以作为独立实施例来实施;步骤S2102可以作为独立实施例来实施;步骤S2103可以作为独立实施例来实施;步骤S2104可以作为独立实施例来实施例;步骤S2101和步骤S2102的组合可以作为独立实施例来实施;步骤S2101和步骤S2103的组合可以作为独立实施例来实施;步骤S2102和步骤S2103的组合可以作为独立实施例来实施;步骤S2101和步骤S2102和步骤S2103的组合可以作为独立实施例来实施;步骤S2103和步骤S2104的组合可以作为独立实施例来实施;步骤S2101至步骤S2104的组合可以作为独立实施例来实施。
在一些实施例中,步骤S2101、步骤S2102及步骤S2104可以是可选地,在不同实施例中可对这些步骤中的一个或多个步骤进行省略或替代。
在一些实施例中,步骤S2101及步骤S2102可以是可选地,在不同实施例中可对这些步骤中的一个或多个步骤进行省略或替代。
在一些实施例中,步骤S2104可以是可选地,在不同实施例中可对这些步骤中的一个或多个步骤进行省略或替代。
在本公开实施例中,各实施例均可以被单独实施或者相互组合地实施,且各实施例中步骤可区分先后步骤。
图3A是根据本公开实施例示出的一种信息处理方法的流程示意图。如图3A所示,本公开实施例涉及信息处理方法,由接入网设备执行,上述方法包括:
步骤S3101,获取第一信息。
步骤S3101的可选实现方式可参见图2的步骤S2101的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,接入网设备接收核心网设备发送的第一信息,但不限于此,也可以接收由其他主体发送的第一信息。
在一些实施例中,接入网设备获取协议规定的第一信息。
在一些实施例中,接入网设备从高层(upper layer(s))获取第一信息。
在一些实施例中,接入网设备进行处理从而得到第一信息。
在一些实施例中,步骤S3101被省略,接入网设备自主实现第一信息所指示的功能,或上述功能为缺 省或默认。
步骤S3102,获取第二信息。
步骤S3102的可选实现方式可参见图2的步骤S2102的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,接入网设备接收核心网设备发送的第二信息,但不限于此,也可以接收由其他主体发送的第二信息。
在一些实施例中,接入网设备获取协议规定的第二信息。
在一些实施例中,接入网设备从高层(upper layer(s))获取第二信息。
在一些实施例中,接入网设备进行处理从而得到第二信息。
在一些实施例中,步骤S3102被省略,接入网设备自主实现第二信息所指示的功能,或上述功能为缺省或默认。
步骤S3103,确定第一终端和第二终端的UP数据的安全保护。
步骤S3103的可选实现方式可参见图2的步骤S2103的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
步骤S3104,发送第三信息。
步骤S3104的可选实现方式可参见图2的步骤S2104的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,接入网设备向第一设备发送第三信息,但不限于此,也可以向其他主体发送第三信息。
本公开实施例所涉及的信息处理方法可以包括步骤S3101至步骤S3104中至少一者。例如,步骤S3101可以作为独立实施例来实施;步骤S3102可以作为独立实施例来实施;步骤S3103可以作为独立实施例来实施;步骤S3104可以作为独立实施例来实施例;步骤S3101和步骤S3102的组合可以作为独立实施例来实施;步骤S3101和步骤S3103的组合可以作为独立实施例来实施;步骤S3102和步骤S3103的组合可以作为独立实施例来实施;步骤S3101和步骤S3102和步骤S3103的组合可以作为独立实施例来实施;步骤S3103和步骤S3104的组合可以作为独立实施例来实施;步骤S3101至步骤S3104的组合可以作为独立实施例来实施。
在一些实施例中,步骤S3101、步骤S3102及步骤S3104可以是可选地,在不同实施例中可对这些步骤中的一个或多个步骤进行省略或替代。
在一些实施例中,步骤S3101及步骤S3102可以是可选地,在不同实施例中可对这些步骤中的一个或多个步骤进行省略或替代。
在一些实施例中,步骤S3104可以是可选地,在不同实施例中可对这些步骤中的一个或多个步骤进行省略或替代。
在本公开实施例中,各实施例均可以被单独实施或者相互组合地实施,且各实施例中步骤可区分先后步骤。
图3B是根据本公开实施例示出的一种信息处理方法的流程示意图。如图3B所示,本公开实施例涉及信息处理方法,由接入网设备执行,上述方法包括:
步骤S3201,基于第一指示信息和第二指示信息,确定第一终端和第二终端的UP数据的安全保护。
步骤S3201的可选实现方式可参见图2中步骤S2103、或者图3A中步骤S3103的可选实现方式、及图2、图3A所涉及的实施例中其他关联部分,在此不再赘述。
在一些实施例中,第一指示信息用于指示第一终端的UP数据的传输方式和/或安全策略,第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略。
在一些实施例中,确定第一终端和第二终端的UP数据的安全保护,包括以下至少之一:确定第一终端和第二终端的UP数据是否需要进行安全保护;确定第一终端和第二终端的UP数据是否进行一致性安全保护;以及确定第一终端和/或第二终端的UP数据进行安全保护的安全策略。
在一些实施例中,方法还包括:接收核心网设备发送的第一信息,其中,第一信息包括第一指示信息;接收核心网设备发送的第二信息,其中,第二信息包括第二指示信息。
在一些实施例中,基于第一指示信息和第二指示信息,确定第一终端和第二终端的用户面UP数据的安全保护,包括以下之一:在第一指示信息和第二指示信息指示的UP数据的传输方式均为UE-SAT-UE本地传输的情况下,确定对第一终端和第二终端的UP数据启用一致性安全保护的判断;在第一指示信息和第二指示信息指示的UP数据的安全策略相同且为第一类安全策略的情况下,确定第一终端和第二终端 的UP数据进行一致性安全保护;在第一指示信息和第二指示信息指示的UP数据的安全策略相同且为第二类安全策略的情况下,确定基于接入网设备确定如何对UP数据进行一致性安全保护;以及在第一指示信息和第二指示信息指示的UP数据的安全策略不同的情况下,根据第一指示信息和第二指示信息分别指示的安全策略的类别,确定第一终端和第二终端的UP数据是否进行一致性保护。
在一些实施例中,第一类安全策略包括需要保护或者不需要保护;和/或,第二类安全策略包括优选保护;其中,优选保护指示优选接入网设备选择的安全保护。
在一些实施例中,根据第一指示信息和第二指示信息分别指示的安全策略的类别,确定第一终端和第二终端的UP数据是否进行一致性保护,包括以下至少之一:在第一指示信息和第二指示信息中一个指示第一类安全策略及另一个指示第二类安全策略的情况下,确定第一终端和第二终端的UP数据进行第一类安全策略的一致性保护;其中,第一类安全策略包括需要保护或者不需要保护,第二类安全策略包括优选保护;以及在第一指示信息和第二指示信息均指示第一类安全策略、且第一指示信息和第二指示信息指示的安全策略不同的情况下,确定第一终端和第二终端的UP数据无法进行一致性保护。
在一些实施例中,方法还包括:在确定第一终端与第二终端无法进行一致性保护的情况下,拒绝与第一终端和第二终端建立会话;或者,在确定第一终端与第二终端无法进行一致性保护的情况下,基于第一指示信息指示的安全策略对第一终端的UP数据进行安全保护,和/或,基于第二指示信息指示的安全策略对第二终端的UP数据进行安全保护。
在一些实施例中,方法还包括:基于针对第一终端和第二终端的UP数据的安全保护,激活第一终端和/或第二终端的UP数据的安全保护。
在一些实施例中,方法还包括:向第一终端和/或第二终端发送第三信息,其中,第三信息用于指示接入网设备确定的第一终端和/第二终端的UP数据的安全保护;第三信息用于第一终端和/或第二终端进行UP数据的安全保护。
在一些实施例中,接入网设备包括卫星基站;和/或,核心网设备包括AMF或者SMF或者PCF。
上述实施例可以被单独实施或者相互组合地实施,可选实现方式可参见图2和图3A的步骤的可选实现方式,此处不再赘述。
图3C是根据本公开实施例示出的一种信息处理方法的流程示意图。如图3C所示,本公开实施例涉及信息处理方法,由接入网设备执行,上述方法包括:
步骤S3301,接收第一信息。
步骤S3301的可选实现方式可参见图2中步骤S2101、或者图3A中步骤S3101的可选实现方式、及图2、图3A所涉及的实施例中其他关联部分,在此不再赘述。
步骤S3302,接收第二信息。
步骤S3302的可选实现方式可参见图2中步骤S2102、或者图3A中步骤S3102的可选实现方式、及图2、图3A所涉及的实施例中其他关联部分,在此不再赘述。
步骤S3303,基于第一信息和第二信息,确定第一终端和第二终端的UP数据的安全保护。
可选地,第一信息包括第一指示信息;第二信息包括第二指示信息。
步骤S3303的可选实现方式可参见图2中步骤S2103、或者图3A中步骤S3103的可选实现方式、及图2、图3A所涉及的实施例中其他关联部分,在此不再赘述。
上述实施例可以被单独实施或者相互组合地实施,可选实现方式可参见图2和图3A的步骤的可选实现方式,此处不再赘述。
图3D是根据本公开实施例示出的一种信息处理方法的流程示意图。如图3D所示,本公开实施例涉及信息处理方法,由接入网设备执行,上述方法包括:
步骤S3401,确定第一终端和第二终端的UP数据的安全保护。
步骤S3401的可选实现方式可参见图2中步骤S2103、或者图3A中步骤S3103的可选实现方式、及图2、图3A所涉及的实施例中其他关联部分,在此不再赘述。
步骤S3402,向第一终端和/或第二终端发送第三信息。
可选地,第三信息用于指示接入网设备确定的第一终端和/第二终端的UP数据的安全保护。
步骤S3402的可选实现方式可参见图2中步骤S2104、或者图3A中步骤S3104的可选实现方式、及图2、图3A所涉及的实施例中其他关联部分,在此不再赘述。
上述实施例可以被单独实施或者相互组合地实施,可选实现方式可参见图2和图3A的步骤的可选实现方式,此处不再赘述。
图4A是根据本公开实施例示出的一种信息处理方法的流程示意图。如图4A所示,本公开实施例涉及信息处理方法,由核心网设备执行,上述方法包括:
步骤S4101,发送第一信息。
步骤S4101的可选实现方式可参见图2的步骤S2101的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,核心网设备向接入网设备发送第一信息,但不限于此,也可以向其他主体发送第一信息。
步骤S4102,发送第二信息。
步骤S4102的可选实现方式可参见图2的步骤S2102的可选实现方式、及图2所涉及的实施例中其他关联部分,此处不再赘述。
在一些实施例中,核心网设备向接入网设备发送第二信息,但不限于此,也可以向其他主体发送第二信息。
在一些可选实施例中,在步骤S4101之前,核心网设备获取第一信息。
在一些实施例中,核心网设备接收第一终端发送的第一信息,但不限于此,也可以接收由其他主体发送的第一信息。
在一些实施例中,核心网设备获取协议规定的第一信息。
在一些实施例中,核心网设备从高层(upper layer(s))获取第一信息。
在一些实施例中,核心网设备进行处理从而得到第一信息。
在一些可选实施例中,在步骤S4102之前,核心网设备获取第二信息。
在一些实施例中,核心网设备接收第二终端发送的第二信息,但不限于此,也可以接收由其他主体发送的第二信息。
在一些实施例中,核心网设备获取协议规定的第二信息。
在一些实施例中,核心网设备从高层(upper layer(s))获取第二信息。
在一些实施例中,核心网设备进行处理从而得到第二信息。
在一些可选实施例中,在步骤S4102之后,核心网设备也可获取第三信息。
在一些实施例中,核心网设备接收接入网设备发送的第三信息,但不限于此,也可以接收由其他主体发送的第三信息。
在一些实施例中,核心网设备获取协议规定的第三信息。
在一些实施例中,核心网设备从高层(upper layer(s))获取第三信息。
在一些实施例中,核心网设备进行处理从而得到第三信息。
在一些实施例中,第一设备向网络设备发送测量结果,但不限于此,也可以向其他主体发送测量结果。
本公开实施例所涉及的信息处理方法可以包括步骤S4101至步骤S4102中至少一者。例如,步骤S4101可以作为独立实施例来实施,步骤S4102可以作为独立实施例来实施;步骤S4101和步骤S4102可以作为独立实施例来实施。
在一些实施例中,步骤S4101可以是可选地,在不同实施例中可对这些步骤中的一个或多个步骤进行省略或替代。
在一些实施例中,步骤S4102可以是可选地,在不同实施例中可对这些步骤中的一个或多个步骤进行省略或替代。
在本公开实施例中,各实施例均可以被单独实施或者相互组合地实施,且各实施例中步骤可区分先后步骤。
图4B是根据本公开实施例示出的一种信息处理方法的流程示意图。如图4B所示,本公开实施例涉及信息处理方法,由核心网设备执行,上述方法包括:
步骤S4201,向接入网设备发送第一信息和第二信息。
可选地,第一信息和第二信息可以是分别单独发送的或者可以是一起发送的。
步骤S4201的可选实现方式可参见图2中步骤S2101、或者图4A中步骤S4101的可选实现方式、及图2、图4A所涉及的实施例中其他关联部分,在此不再赘述。
在一些实施例中,第一指示信息用于指示第一终端的UP数据的传输方式和/或安全策略;第二信息包括第二指示信息;第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略;其中,第一指示信息和第二指示信息用于接入网设备确定第一终端和第二终端的UP数据的安全保护。
在一些实施例中,方法还包括:接收第一终端发送的第一信息;和/或,接收第二终端发送的第二信息。
在一些实施例中,接入网设备包括卫星基站;和/或,核心网设备包括AMF或者SMF或者PCF。
上述实施例可以被单独实施或者相互组合地实施,可选实现方式可参见图2和图4A的步骤的可选实现方式,此处不再赘述。
图5是根据本公开实施例示出的信息处理方法的流程示意图。如图5所示,本公开实施例涉及信息处理方法,上述方法包括:
可选地,上述方法可包括CASE1或者CASE2;CASE1表示重复使用现有机制的假设程序;CASE2表示对整个UP数据进行一致性保护的增强程度。CASE1可包括步骤S5101至步骤S5103;其中,步骤S5101可包括步骤S5101A和/或步骤S5101B;步骤S5102可包括步骤S5102A和/或步骤S5102B。CASE2可包括步骤S5104至步骤S5108。
CASE1:
步骤S5101A,UE1的PDU会话建立。
可选地,UE1向核心网设备发送PDU会话建立过程;在此过程中,核心网设备向基站(例如gNB)发送UE1的UP安全策略。该基站为在卫星上的基站,例如为卫星基站。
可选地,UE1可以为之前实施例中的第一终端。核心网设备可以之前实施例中的AMF或者SMF;UE1的AMF可以为AMF1;UE1的SMF可以为SMF1。
步骤S5101B,基站激活Uu UP安全保护。
可选地,基站根据接收到的UE1的安全策略激活Uu UP安全保护。Uu UP安全保护可以为Uu接口的UP数据的安全保护;该Uu接口为UE1与基站之间的通信接口。
步骤S5102A,UE2的PDU会话建立。
可选地,在UE1请求通信的网络触发的情况下,UE2向核心网设备发送PDU会话建立过程;在此过程中,核心网设备向基站发送UE2的UP安全策略。
可选地,UE2可以为之前实施例中的第二终端。核心网设备可以之前实施例中的AMF或者SMF;UE2的AMF可以为AMF2;UE2的SMF可以为SMF2。
步骤S5102B,基站激活Uu UP安全保护。
可选地,基站根据接收到的UE2的安全策略激活Uu UP安全保护。Uu UP安全保护可以为Uu接口的UP数据的安全保护;该Uu接口为UE2与基站之间的通信接口。
可选地,UE1的UP安全策略(UE1UP安全策略)可能与UE2的UP安全策略(UE2UP安全策略)不同。因此,为UE1激活的Uu UP安全保护可能与为UE2激活的Uu UP安全保护不同。
步骤S5103,UE1与基站之间的UP数据和UE2与基站之间的UP数据受到安全保护。
可选地,UE1与基站之间的UP数据受到激活的UE1的安全策略的安全保护,以及UE2与基站之间的UP数据受到激活的UE2的安全策略的安全保护。
可选地,如果为UE1激活的Uu UP安全策略不同于为UE2激活的Uu UP安全策略,则应用于UE1和基站之间的UP数据的安全保护可能不同于应用于UE2和基站之间的UP数据的保护。
可选地,如果重用现有机制,则可能导致应用于单个UE-卫星通信会话的UP数据的不一致的安全保护。在这种情况下,一段UP数据的较高安全策略保护(例如完整性和机密性保护)将被另一段UP数据的较低安全策略保护(例如仅完整性保护或仅机密性保护或无保护)降级。
CASE2:
步骤S5104,UE1的PDU会话建立。
可选地,UE1向核心网发起PDU会话建立过程,指示UE2作为通信的目标UE。在该过程中,核心网将UE1的UP安全策略发送给基站(例如eNB)。该UE1的UP安全策略可包括UE1-SAT-UE2通信指示;UE1-SAT-UE2通信指示也由核心网络(例如,SMF1或者AMF1)发送到基站,UE1-SAT-UE2通信指示作为会话管理订阅数据或会话管理信息的一部分。基站在接收到UE1-SAT-UE2通信指示后,不应该立即为UE1激活Uu UP安全策略,而是将等待在UE2的PDU会话建立过程中接收到UE2的UP安全策略。
可选地,UE1的UP安全策略可以为之前实施例中的第一信息;UE1的UE1-SAT-UE2通信指示可以为之前实施例中的第一指示信息。
步骤S5105,UE2的PDU会话建立。
可选地,在UE1请求通信的网络触发的情况下,UE,2向核心网发起PDU会话建立过程,指示UE2作为通信的目标UE。在该过程中,核心网将UE2的UP安全策略发送给基站(例如eNB)。该UE2的UP安全策略可包括UE1-SAT-UE2通信指示;UE1-SAT-UE2通信指示也由核心网络(例如,SMF2或者 AMF2)发送到基站,UE1-SAT-UE2通信指示作为会话管理订阅数据或会话管理信息的一部分。
可选地,UE2的UP安全策略可以为之前实施例中的第二信息;UE2的UE1-SAT-UE2通信指示可以为之前实施例中的第二指示信息。
可选地,UE1的UP安全策略(UE1UP安全策略)可能与UE2的UP安全策略(UE2UP安全策略)不同。因此,为UE1激活的Uu UP安全保护可能与为UE2激活的Uu UP安全保护不同。
步骤S5106,基站确定如何激活UE1和UE2的安全保护。
可选地,基站基于接收到的UE1UP安全策略和UE2UP安全策略确定如何在具有UE1和UE2的两个Uu接口上一致地激活UP安全;可如下所示:
示例1:如果UE1UP安全策略和UE2UP安全策略一致(例如,两者都指示“需要”或两者都指示“不需要”),则基站采用接收到的UE1UP安全策略和UE2UP安全策略(“需要”或“不需要”)来对UP数据进行一致性安全保护。这里,进行一致性安全保护可以理解为对第一终端的UP数据和第二终端的UP数据的安全保护相同;例如使用相同的安全策略。
示例2:如果UE1UP安全策略和UE2UP安全策略都指示“优选”,则基站自行确定UP的安全策略。
示例3:如果UE1UP安全策略和UE2UP安全策略中一个安全策略指示“需要”以及另一个安全策略指示“优选”,则基站将“需要”作为对UP数据进行一致性安全保护。
示例4:如果UE1UP安全策略和UE2UP安全策略中一个安全策略指示“不需要”以及另一个安全策略指示“优选”,则基站将“不需要”作为对UP数据进行一致性安全保护。
示例5:如果UE1UP安全策略和UE2UP安全策略中一个安全策略指示“需要”以及另一个安全策略指示“不需要”,这意味着无法对UP数据进行一致性安全保护。那么基站可以决定:拒绝与UE1和UE2建立PDU会话;或者,继续基于不同的安全策略分别为UE1和UE2激活Uu UP的安全保护,即对UP数据激活不一致的安全保护。这里,无法进行一致性安全保护可以理解为对第一终端的UP数据和第二终端的UP数据的安全保护不同;例如使用不同的安全策略。
步骤S5107,基站激活UE1和UE2的Uu UP安全保护。
可选地,gNB基于步骤S5106中确定的UP安全策略激活UE1和UE2的Uu UP的安全保护;这里也可以是指基站激活UE1和UE2的安全保护的安全状态,该安全状态是指需要保护或者不需要保护的状态。
步骤S5108,UE1和UE2分别与基站交互的UP数据受到安全保护。
可选地,UE1和UE2之间通过基站交互的UP数据始终受到激活的UP安全策略进行安全保护。
上述实施例中需要保护包括需要机密性保护和/或需要完整性保护;不需要保护包括不需要机密性保护和/或不需要完整性保护。
在本公开实施例中,各实施例均可以被单独实施或者相互组合地实施,且各实施例中步骤可区分先后步骤。
公开实施例涉及信息处理方法,该方法包括:
在一些实施例中,基站应能够从核心网设备接收UE(例如UE1、UE2)UE1-SAT-UE2通信指示。
在一些实施例中,基站应能够基于来自核心网设备的UE1-SAT-UE2指示来确定如何处理所涉及的UE(例如UE1、UE2)的UP安全策略。
在一些实施例中,基站应该能够基于所涉及的UE(例如UE1、UE2)的UP安全策略,为UE-SAT-UE通信的UP数据确定一致的UP安全策略。
在一些实施例中,基站应能够根据自己确定的UP安全策略,为UE-SAT-UE通信的UP数据激活一致的Uu UP的安全保护。
在一些实施例中,核心网络设备应能够发送UE1-SAT-UE2通信指示,作为会话管理订阅数据或会话管理信息的一部分。
本公开实施例中,部分或全部步骤、其可选实现方式可以与其他实施例中部分或者全部步骤任意组合,也可以与其他实施例的可选实现方式任意组合。
本公开实施例还提出用于实现以上任一方法的装置,例如,提出一装置,上述装置包括用以实现以上任一方法中终端所执行的各步骤的单元或模块。再如,还提出另一装置,包括用以实现以上任一方法中网络设备(例如接入网设备、核心网功能节点、核心网设备等)所执行的各步骤的单元或模块。
应理解以上装置中各单元或模块的划分仅是一种逻辑功能的划分,在实际实现时可以全部或部分集成到一个物理实体上,也可以物理上分开。此外,装置中的单元或模块可以以处理器调用软件的形式实现:例如装置包括处理器,处理器与存储器连接,存储器中存储有指令,处理器调用存储器中存储的指令,以 实现以上任一方法或实现上述装置各单元或模块的功能,其中处理器例如为通用处理器,例如中央处理单元(Central Processing Unit,CPU)或微处理器,存储器为装置内的存储器或装置外的存储器。或者,装置中的单元或模块可以以硬件电路的形式实现,可以通过对硬件电路的设计实现部分或全部单元或模块的功能,上述硬件电路可以理解为一个或多个处理器;例如,在一种实现中,上述硬件电路为专用集成电路(Application-Specific Integrated Circuit,ASIC),通过对电路内元件逻辑关系的设计,实现以上部分或全部单元或模块的功能;再如,在另一种实现中,上述硬件电路为可以通过可编程逻辑器件(Programmable Logic Levice,PLD)实现,以现场可编程门阵列(Field Programmable Gate Array,FPGA)为例,其可以包括大量逻辑门电路,通过配置文件来配置逻辑门电路之间的连接关系,从而实现以上部分或全部单元或模块的功能。以上装置的所有单元或模块可以全部通过处理器调用软件的形式实现,或全部通过硬件电路的形式实现,或部分通过处理器调用软件的形式实现,剩余部分通过硬件电路的形式实现。
在本公开实施例中,处理器是具有信号处理能力的电路,在一种实现中,处理器可以是具有指令读取与运行能力的电路,例如中央处理单元(Central Processing Unit,CPU)、微处理器、图形处理器(graphics processing unit,GPU)(可以理解为微处理器)、或数字信号处理器(Digital Signal Processor,DSP)等;在另一种实现中,处理器可以通过硬件电路的逻辑关系实现一定功能,上述硬件电路的逻辑关系是固定的或可以重构的,例如处理器为专用集成电路(Application-Specific Integrated Circuit,ASIC)或可编程逻辑器件(programmable logic device,PLD)实现的硬件电路,例如FPGA。在可重构的硬件电路中,处理器加载配置文档,实现硬件电路配置的过程,可以理解为处理器加载指令,以实现以上部分或全部单元或模块的功能的过程。此外,还可以是针对人工智能设计的硬件电路,其可以理解为ASIC,例如神经网络处理单元(Neural Network Processing Unit,NPU)、张量处理单元(Tensor Processing Unit,TPU)、深度学习处理单元(Deep learning Processing Unit,DPU)等。
图6A是本公开实施例提供的接入网设备6100的结构示意图。如图6A所示,接入网设备6100包括:第一收发模块6101和处理模块6102。在一些实施例中,第一收发模块6101,用于接收核心网设备发送的第一信息和/或第二信息。可选地,上述第一收发模块6101,用于执行以上任一方法中接入网设备执行的发送和/或接收等步骤(例如步骤S2101和/或S2102和/或步骤S2104等步骤,但不限于此)中的至少一者,此处不再赘述。可选地,上述处理模块6102,用于确定第一终端和第二终端的UP数据的安全保护。可选地,上述处理模块6102,用于执行以上任一方法中接入网设备执行的处理等步骤(例如步骤S2103等步骤,但不限于此)中的至少一者,此处不再赘述。
图6B是本公开实施例提供的核心网设备6200的结构示意图。如图6B所示,核心网设备6200包括:第二收发模块6201。可选地,上述第二收发模块6201,用于向核心网设备发送第一信息和/或第二信息。可选地,上述第二收发模块6201,用于执行以上任一方法中核心网设备执行的发送和/或接收等步骤(例如步骤S2101和/或步骤S2102和/或步骤S2104等步骤,但不限于此)中的至少一者,此处不再赘述。
在一些实施例中,收发模块可以包括发送模块和/或接收模块,发送模块和接收模块可以是分离的,也可以集成在一起。可选地,收发模块可以与收发器相互替换。示例性的,上述第一收发模块包括第一发送模块和/或第一接收模块。示例性的,上述第二收发模块包括第二发送模块和/或第二接收模块。
在一些实施例中,处理模块可以是一个模块,也可以包括多个子模块。可选地,上述多个子模块分别执行处理模块所需执行的全部或部分步骤。可选地,处理模块可以与处理器相互替换。
图7A是本公开实施例提出的通信设备7100的结构示意图。通信设备7100可以是网络设备(例如接入网设备、核心网设备、第一网元、第二网元等),也可以是终端(例如用户设备等)等,也可以是支持网络设备实现以上任一方法的芯片、芯片系统、或处理器等,还可以是支持终端实现以上任一方法的芯片、芯片系统、或处理器等。通信设备7100可用于实现上述方法实施例中描述的方法,具体可以参见上述方法实施例中的说明。
如图7A所示,通信设备7100包括一个或多个处理器7101。处理器7101可以是通用处理器或者专用处理器等,例如可以是基带处理器或中央处理器。基带处理器可以用于对通信协议以及通信数据进行处理,中央处理器可以用于对通信装置(如,基站、基带芯片,终端设备、终端设备芯片,DU或CU等)进行控制,执行程序,处理程序的数据。可选地,通信设备7100用于执行以上任一方法。可选地,一个或多个处理器7101用于调用指令以使得通信设备7100执行以上任一方法。
在一些实施例中,通信设备7100还包括一个或多个收发器7102。在通信设备7100包括一个或多个收发器7102时,收发器7102执行上述方法中的发送和/或接收等通信步骤(例如步骤S2101和/或步骤S2102,但不限于此)中的至少一者,处理器7101执行其他步骤中的至少一者。在可选的实施例中,收发器可以包括接收器和/或发送器,接收器和发送器可以是分离的,也可以集成在一起。可选地,收发器、收发单元、 收发机、收发电路、接口电路、接口等术语可以相互替换,发送器、发送单元、发送机、发送电路等术语可以相互替换,接收器、接收单元、接收机、接收电路等术语可以相互替换。
在一些实施例中,通信设备7100还包括用于存储数据的一个或多个存储器7103。可选地,全部或部分存储器7103也可以处于通信设备7100之外。在可选的实施例中,通信设备7100可以包括一个或多个接口电路7104。可选地,接口电路7104与存储器7103连接,接口电路7104可用于从存储器7103或其他装置接收数据,可用于向存储器7103或其他装置发送数据。例如,接口电路7104可读取存储器7103中存储的数据,并将该数据发送给处理器7101。
以上实施例描述中的通信设备7100可以是网络设备或者终端,但本公开中描述的通信设备7100的范围并不限于此,通信设备7100的结构可以不受图7A的限制。通信设备可以是独立的设备或者可以是较大设备的一部分。例如所述通信设备可以是:(1)独立的集成电路IC,或芯片,或,芯片系统或子系统;(2)具有一个或多个IC的集合,可选地,上述IC集合也可以包括用于存储数据,程序的存储部件;(3)ASIC,例如调制解调器(Modem);(4)可嵌入在其他设备内的模块;(5)接收机、终端设备、智能终端设备、蜂窝电话、无线设备、手持机、移动单元、车载设备、网络设备、云设备、人工智能设备等等;(7)其他等等。
图7B是本公开实施例提出的芯片7200的结构示意图。对于通信设备7100可以是芯片或芯片系统的情况,可以参见图7B所示的芯片7200的结构示意图,但不限于此。
芯片7200包括一个或多个处理器7201。芯片7200用于执行以上任一方法。
在一些实施例中,芯片7200还包括一个或多个接口电路7202。可选地,接口电路、接口、收发管脚等术语可以相互替换。在一些实施例中,芯片7200还包括用于存储数据的一个或多个存储器7203。可选地,全部或部分存储器7203可以处于芯片7200之外。可选地,接口电路7202与存储器7203连接,接口电路7202可以用于从存储器7203或其他装置接收数据,接口电路7202可用于向存储器7203或其他装置发送数据。例如,接口电路7202可读取存储器7203中存储的数据,并将该数据发送给处理器7201。
在一些实施例中,接口电路7202执行上述方法中的发送和/或接收等通信步骤(例如步骤S2101和/或步骤S2102,但不限于此)中的至少一者。接口电路7202执行上述方法中的发送和/或接收等通信步骤例如是指:接口电路7202执行处理器7201、芯片7200、存储器7203或收发器件之间的数据交互。在一些实施例中,处理器7201执行其他步骤中的至少一者。
虚拟装置、实体装置、芯片等各实施例中所描述的各模块和/或器件可以根据情况任意组合或者分离。可选地,部分或全部步骤也可以由多个模块和/或器件协作执行,此处不做限定。
本公开还提出存储介质,上述存储介质上存储有指令,当上述指令在通信设备7100上运行时,使得通信设备7100执行以上任一方法。可选地,上述存储介质是电子存储介质。可选地,上述存储介质是计算机可读存储介质,但不限于此,其也可以是其他装置可读的存储介质。可选地,上述存储介质可以是非暂时性(non-transitory)存储介质,但不限于此,其也可以是暂时性存储介质。
本公开还提出程序产品,上述程序产品被通信设备7100执行时,使得通信设备7100执行以上任一方法。可选地,上述程序产品是计算机程序产品。
本公开还提出计算机程序,当其在计算机上运行时,使得计算机执行以上任一方法。

Claims (18)

  1. 一种信息处理方法,其特征在于,由接入网设备执行,包括:
    基于第一指示信息和第二指示信息,确定第一终端和第二终端的用户面UP数据的安全保护;其中,第一指示信息用于指示所述第一终端的UP数据的传输方式和/或安全策略,所述第二指示信息用于指示所述第二终端的UP数据的传输方式和/或安全策略。
  2. 根据权利要求1所述的方法,其特征在于,所述确定第一终端和第二终端的用户面UP数据的安全保护,包括以下至少之一:
    确定所述第一终端和所述第二终端的UP数据是否需要进行安全保护;
    确定所述第一终端和所述第二终端的UP数据是否进行一致性安全保护;
    确定所述第一终端和/或所述第二终端的UP数据进行安全保护的安全策略。
  3. 根据权利要求1或2所述的方法,其特征在于,所述方法还包括:
    接收核心网设备发送的第一信息,其中,所述第一信息包括所述第一指示信息;
    接收所述核心网设备发送的第二信息,其中,所述第二信息包括所述第二指示信息。
  4. 根据权利要求1至3任一项所述的方法,其特征在于,所述基于第一指示信息和第二指示信息,确定第一终端和第二终端的用户面UP数据的安全保护,包括以下之一:
    在所述第一指示信息和所述第二指示信息指示的UP数据的传输方式均为UE-SAT-UE本地传输的情况下,确定对所述第一终端和所述第二终端的UP数据启用一致性安全保护的判断;
    在所述第一指示信息和所述第二指示信息指示的UP数据的安全策略相同且为第一类安全策略的情况下,确定所述第一终端和所述第二终端的UP数据进行一致性安全保护;
    在所述第一指示信息和所述第二指示信息指示的UP数据的安全策略相同且为第二类安全策略的情况下,确定基于所述接入网设备确定如何对UP数据进行一致性安全保护;
    在所述第一指示信息和所述第二指示信息指示的UP数据的安全策略不同的情况下,根据所述第一指示信息和第二指示信息分别指示的安全策略的类别,确定所述第一终端和所述第二终端的UP数据是否进行一致性保护。
  5. 根据权利要求4所述的方法,其特征在于,
    所述第一类安全策略包括需要保护或者不需要保护;
    和/或,
    所述第二类安全策略包括优选保护;其中,所述优选保护指示优选所述接入网设备选择的安全保护。
  6. 根据权利要求4所述的方法,其特征在于,所述根据所述第一指示信息和第二指示信息分别指示的安全策略的类别,确定所述第一终端和所述第二终端的UP数据是否进行一致性保护,包括以下至少之一:
    在所述第一指示信息和第二指示信息中一个指示第一类安全策略及另一个指示第二类安全策略的情况下,确定所述第一终端和所述第二终端的UP数据进行所述第一类安全策略的一致性保护;其中,第一类安全策略包括需要保护或者不需要保护,所述第二类安全策略包括优选保护;
    在所述第一指示信息和所述第二指示信息均指示第一类安全策略、且所述第一指示信息和所述第二指示信息指示的安全策略不同的情况下,确定所述第一终端和所述第二终端的UP数据无法进行一致性保护。
  7. 根据权利要求4或6所述的方法,其特征在于,所述方法还包括以下之一:
    在确定所述第一终端与所述第二终端无法进行一致性保护的情况下,拒绝与第一终端和第二终端建立会话;
    在确定所述第一终端与所述第二终端无法进行一致性保护的情况下,基于所述第一指示信息指示的安全策略对所述第一终端的UP数据进行安全保护,和/或,基于所述第二指示信息指示的安全策略对所述第二终端的UP数据进行安全保护。
  8. 根据权利要求1至7任一项所述的方法,其特征在于,所述方法还包括:
    基于针对第一终端和第二终端的UP数据的安全策略,激活第一终端和/或第二终端的UP数据的安全保护。
  9. 根据权利要求1至8任一项所述的方法,其特征在于,所述方法还包括:
    向第一终端和/或第二终端发送第三信息,其中,所述第三信息用于指示所述接入网设备确定的所述第一终端和/所述第二终端的UP数据的安全保护;所述第三信息用于所述第一终端和/或所述第二终端进行UP数据的安全保护。
  10. 根据权利要求1至9任一项所述的方法,其特征在于,所述接入网设备包括卫星基站;和/或,核心网设备包括:接入和移动性管理功能AMF,或者,会话管理功能SMF,或者策略控制功能PCF。
  11. 一种信息处理方法,其特征在于,由核心网设备执行,包括:
    向接入网设备发送第一信息,所述第一信息包括第一指示信息;所述第一指示信息用于指示第一终端的用户面UP数据的传输方式和/或安全策略;
    向所述接入网设备发送第二信息,所述第二信息包括第二指示信息;所述第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略;
    其中,所述第一指示信息和所述第二指示信息用于接入网设备确定所述第一终端和第二终端的UP数据的安全保护。
  12. 根据权利要求11所述的方法,其特征在于,所述方法还包括:
    接收所述第一终端发送的所述第一信息;
    和/或,
    接收所述第二终端发送的所述第二信息。
  13. 根据权利要求11或12所述的方法,其特征在于,接入网设备包括卫星基站;和/或,所述核心网设备包括:接入和移动性管理功能AMF,或者,会话管理功能SMF,或者,策略控制功能PCF。
  14. 一种接入网设备,其特征在于,包括:
    第一收发模块,被配置为基于第一指示信息和第二指示信息,确定第一终端和第二终端的用户面UP数据的安全保护;其中,第一指示信息用于指示所述第一终端的UP数据的传输方式和/或安全策略,所述第二指示信息用于指示所述第二终端的UP数据的传输方式和/或安全策略。
  15. 一种核心网设备,其特征在于,包括:
    第二收发模块,被配置为向接入网设备发送第一信息,所述第一信息包括第一指示信息;所述第一指示信息用于指示第一终端的用户面UP数据的传输方式和/或安全策略;
    所述第二收发模块,还被配置为向所述接入网设备发送第二信息,所述第二信息包括第二指示信息;所述第二指示信息用于指示第二终端的UP数据的传输方式和/或安全策略;
    其中,所述第一指示信息和所述第二指示信息用于接入网设备确定所述第一终端和第二终端的UP数据的安全保护。
  16. 一种通信设备,其特征在于,包括:
    一个或多个处理器;
    其中,所述通信设备用于执行权利要求1至10、或者权利要求11至13中任一项所述的信息处理方法。
  17. 一种通信系统,其特征在于,包括:接入网设备和第一设备;其中,所述接入网设备被配置为实现权利要求1至10中任一项所述的信息处理方法,所述第一设备被配置为实现权利要求11至13中任一项所述的信息处理方法。
  18. 一种存储介质,所述存储介质存储有指令,其特征在于,当所述指令在通信设备上运行时,使得所述通信设备执行如权利要求1至10、或者权利要求11至13中任一项所述的信息处理方法。
PCT/CN2024/073381 2024-01-19 2024-01-19 信息处理方法、通信系统及存储介质 Pending WO2025152190A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN202480005598.5A CN120677735A (zh) 2024-01-19 2024-01-19 信息处理方法、通信系统及存储介质
PCT/CN2024/073381 WO2025152190A1 (zh) 2024-01-19 2024-01-19 信息处理方法、通信系统及存储介质

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2024/073381 WO2025152190A1 (zh) 2024-01-19 2024-01-19 信息处理方法、通信系统及存储介质

Publications (1)

Publication Number Publication Date
WO2025152190A1 true WO2025152190A1 (zh) 2025-07-24

Family

ID=96470561

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2024/073381 Pending WO2025152190A1 (zh) 2024-01-19 2024-01-19 信息处理方法、通信系统及存储介质

Country Status (2)

Country Link
CN (1) CN120677735A (zh)
WO (1) WO2025152190A1 (zh)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2022104617A1 (zh) * 2020-11-18 2022-05-27 华为技术有限公司 通信方法、装置及系统
CN115348585A (zh) * 2021-05-13 2022-11-15 华为技术有限公司 确定安全保护开启方式的方法、通信方法及通信装置
US20230239686A1 (en) * 2020-10-01 2023-07-27 Huawei Technologies Co., Ltd. Secure communication method, apparatus, and system
WO2024015498A1 (en) * 2022-07-14 2024-01-18 Innopeak Technology, Inc. Security establishing method and user equipment

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20230239686A1 (en) * 2020-10-01 2023-07-27 Huawei Technologies Co., Ltd. Secure communication method, apparatus, and system
WO2022104617A1 (zh) * 2020-11-18 2022-05-27 华为技术有限公司 通信方法、装置及系统
CN115348585A (zh) * 2021-05-13 2022-11-15 华为技术有限公司 确定安全保护开启方式的方法、通信方法及通信装置
WO2024015498A1 (en) * 2022-07-14 2024-01-18 Innopeak Technology, Inc. Security establishing method and user equipment

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
ALAIN SULTAN, NOVAMINT, HUAWEI: "Text Proposal for the Overview section", 3GPP DRAFT; S1-230475; TYPE PCR; FS_5GSAT_PH3, 3RD GENERATION PARTNERSHIP PROJECT (3GPP), vol. SA WG1, 1 March 2023 (2023-03-01), FR, XP052250138 *

Also Published As

Publication number Publication date
CN120677735A (zh) 2025-09-19

Similar Documents

Publication Publication Date Title
WO2025097406A1 (zh) 信息处理方法、网元、通信系统及存储介质
WO2025065653A1 (zh) 中继通信方法、中继设备、通信系统及存储介质
WO2025065642A1 (zh) 中继通信方法、中继设备、终端、通信系统及存储介质
WO2025035417A1 (zh) 信息处理方法、装置及存储介质
WO2025030300A1 (zh) 信息指示方法、第一api调用者、第一网络功能和存储介质
WO2025030327A1 (zh) 信息确定方法、网元、终端
WO2025152190A1 (zh) 信息处理方法、通信系统及存储介质
WO2025189403A1 (zh) 信息处理方法、装置及存储介质
WO2025166651A1 (zh) 信息处理方法、网元、接入网设备、通信系统及存储介质
WO2025231886A1 (zh) 通信方法、网元、通信系统、存储介质及计算机程序产品
WO2025152007A1 (zh) 策略控制方法、设备和存储介质
WO2025091380A1 (zh) 指示方法、装置以及存储介质
WO2025086180A1 (zh) 信息处理方法、网络设备、终端、通信系统及存储介质
WO2025166701A1 (zh) 信息处理方法、网元、接入网设备、通信系统及存储介质
WO2025060012A1 (zh) 信息处理方法、设备和存储介质
WO2025025026A1 (zh) 信息处理方法、网络设备、终端、通信系统及存储介质
WO2025054788A1 (zh) 通信方法、终端、以及通信系统
WO2025000394A9 (zh) 建立用户面连接的方法及装置、存储介质
WO2026030945A1 (zh) 通信方法、装置、设备、通信系统、存储介质及程序产品
WO2025050393A1 (zh) 信息上报方法、终端、网络设备
WO2025086235A1 (zh) 通信方法、终端、第一网元、第二网元、网络设备
WO2026030941A1 (zh) 通信方法、装置、设备、通信系统、存储介质及程序产品
WO2025111820A1 (zh) 通信方法、终端、网络设备、通信系统和存储介质
WO2026000315A1 (zh) 通信方法、设备、系统及存储介质
WO2025010573A1 (zh) 基于ntn的通信方法和装置、通信设备、通信系统及存储介质

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 202480005598.5

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 24917811

Country of ref document: EP

Kind code of ref document: A1

WWP Wipo information: published in national office

Ref document number: 202480005598.5

Country of ref document: CN