WO2021027435A1 - 一种安全保护方式确定方法及装置 - Google Patents
一种安全保护方式确定方法及装置 Download PDFInfo
- Publication number
- WO2021027435A1 WO2021027435A1 PCT/CN2020/100310 CN2020100310W WO2021027435A1 WO 2021027435 A1 WO2021027435 A1 WO 2021027435A1 CN 2020100310 W CN2020100310 W CN 2020100310W WO 2021027435 A1 WO2021027435 A1 WO 2021027435A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- security protection
- security
- mode
- terminal device
- protection
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/20—Network architectures or network communication protocols for network security for managing network security; network security policies in general
- H04L63/205—Network architectures or network communication protocols for network security for managing network security; network security policies in general involving negotiation or determination of the one or more network security mechanisms to be used, e.g. by negotiation between the client and the server or between peers or by selection according to the capabilities of the entities involved
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/20—Network architectures or network communication protocols for network security for managing network security; network security policies in general
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/105—Multiple levels of security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/18—Multiprotocol handlers, e.g. single devices capable of handling multiple protocols
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/30—Security of mobile devices; Security of mobile applications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/30—Security of mobile devices; Security of mobile applications
- H04W12/37—Managing security policies for mobile devices or for controlling mobile applications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/66—Trust-dependent, e.g. using trust scores or trust relationships
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W92/00—Interfaces specially adapted for wireless communication networks
- H04W92/16—Interfaces between hierarchically similar devices
- H04W92/18—Interfaces between hierarchically similar devices between terminal devices
Definitions
- This application relates to the field of communication technology, and in particular to a method and device for determining a security protection mode.
- communication systems can support communication between terminal devices through multiple communication methods. For example, PC5 interface communication method, Uu interface communication method, etc.
- PC5 interface communication mode Two terminal devices can establish a direct link for data communication through the PC5 interface.
- the Uu interface is the communication interface between the terminal equipment and the base station.
- the Uu interface communication mode specifically can include two scenarios:
- Scenario 1 The terminal device A and the terminal device B respectively access the network device A and network device B serving it through the Uu interface, and then the terminal device A sends the data to the core network device through the network device A (for example, the user plane function (User Plane Function (UPF) entity), and then forwarded by the core network device to the terminal device B through the network device B.
- the network device A for example, the user plane function (User Plane Function (UPF) entity
- UPF User Plane Function
- Terminal device A and terminal device B respectively connect to the network device A and network device B serving them through the Uu interface, and then terminal device A forwards the data to the data network through network device A and core network device (Date Network, The application server in DN), the application server then forwards the data to the terminal device B through the core network device and the network device B.
- network device A and core network device Date Network, The application server in DN
- the application server then forwards the data to the terminal device B through the core network device and the network device B.
- the communication system can support the terminal device to switch the communication mode. For example, when the terminal device uses the Uu interface communication mode to transmit service data, it can be triggered to use the PC5 interface communication mode to transmit subsequent service data. For another example, when the terminal device uses the PC5 interface communication mode to transmit service data, it can also be triggered to use the Uu interface communication mode to transmit subsequent service data.
- the data security protection methods corresponding to different communication methods may be different.
- the terminal device uses the Uu interface communication method
- the transmitted data is encrypted.
- the terminal device switches to the PC5 interface communication method
- the transmitted data is not encrypted.
- the non-receiving Other terminal devices at the end can also eavesdrop on the data, resulting in reduced data security of the terminal device.
- This application provides a method and device for determining a security protection mode, which are used to ensure the data transmission security of the terminal device after the terminal device switches the communication mode.
- an embodiment of the present application provides a method for determining a security protection mode.
- the method may include the following steps: a first terminal device obtains security protection information of a first communication mode, wherein the security protection information includes the first security Protection mode, and/or, a first security policy; the first security protection mode corresponds to the first communication mode, and is used to protect data transmitted when the first terminal device adopts the first communication mode, the The first security policy is the security policy of the first communication mode of the first terminal device; then, the first terminal device determines a second security protection mode according to the security protection information, and the second security protection The mode corresponds to the second communication mode and is used to protect the data transmitted when the first terminal device adopts the second communication mode.
- the first terminal device can determine the security protection mode of the second communication mode according to the security protection information of the first communication mode. In this way, when the first terminal device switches from the first communication mode to the second communication mode, it can directly use the security protection mode of the second communication mode to protect the transmitted data, thereby ensuring that the communication mode is switched The data security of the first terminal device.
- the first terminal device may obtain the security protection information of the first communication method when requesting to use the first communication method or when the first communication method is about to be used, and according to The security protection information predetermines the second security protection mode. In this way, when the first terminal device switches from the first communication mode to the second communication mode, it can directly use the second security protection mode for protection to avoid determining the second communication mode during the switching process. The time delay caused by the security protection mode can improve the communication efficiency of the first terminal device.
- the first terminal device may obtain the security protection information of the Uu interface communication mode from the network device during the PDU session establishment process or registration, and use the security protection information to determine the second security corresponding to the PC5 interface communication mode Protection method.
- the first terminal device may also obtain the security protection information of the PC5 interface communication mode from the local or application server when requesting the use of the PC5 interface communication mode, and use the security protection information to determine the corresponding Uu interface communication mode The second way of safety protection.
- the first terminal device may also obtain the first security protection information of the Uu interface communication mode from the network device and obtain the second security protection information of the PC5 interface communication mode from the local or application server when the PC5 interface communication mode is requested.
- Protect the information and then select the high priority security protection information as the target security protection information according to the priority of the first security protection information and the second security protection information (for example, the first security protection information is the first priority, or the first security protection information is the first priority.
- the second security protection information is the first priority
- the second security protection mode corresponding to the Uu interface communication mode is determined according to the target security protection information.
- the first terminal device may obtain the security protection information of the first communication mode in the case of determining to switch from the first communication mode to the second communication mode, and according to the For the security protection information, the second security protection mode is predetermined.
- the first terminal device may execute the foregoing process before, during, and after the handover, which is not limited in this application.
- the first security protection mode of the first communication mode may be determined by the first terminal device using the scenario one method, or determined by other methods, this application does not limit this.
- the protection level of the second security protection mode determined by the first terminal device Not lower than the protection level specified by the security protection information of the first communication mode.
- the first terminal device determines the second security protection mode according to the security protection information, including:
- the first terminal device determines that the second security protection mode is the same as the first security protection mode
- the first terminal device obtains a second security policy, where the second security policy is a security policy of the second communication mode of the first terminal device; the first terminal device according to the second security policy, The first security protection mode determines the second security protection mode, wherein the protection level of the second security protection mode is not lower than the protection level of the second security policy, and is not lower than the first security protection mode.
- the protection level of the security protection method is not lower than the protection level of the second security policy, and is not lower than the first security protection mode.
- the protection level of the second security protection mode is not lower than that of the first security protection mode.
- the first terminal device can obtain the second security policy, it is further ensured that the protection level of the second security protection mode is not lower than the protection level of the second security policy.
- the first terminal device determining the second security protection mode according to the second security policy and the first security protection mode includes:
- the first terminal device determines that the protection level of the second security protection mode is security protection required
- the first terminal device determines that the protection level of the second security protection mode is Need security protection
- the first terminal device determines the second security according to its own security protection capability Protection level of protection mode
- the first terminal device determines the protection level of the second security protection mode Because no security protection is required.
- the first terminal device determines the second security protection mode according to the security protection information, including:
- the first terminal device determines the second security protection mode according to the first security policy.
- the first terminal device obtains a second security policy, where the second security policy is a security policy of the second communication mode of the first terminal device; the first terminal device according to the second security policy, The first security policy determines the second security protection mode, wherein the protection level of the second security protection mode is not lower than the protection level of the second security policy, and is not lower than the first security The protection level of the strategy.
- the protection level of the second security protection mode is not lower than the first security policy.
- the first terminal device can obtain the second security policy, it is further ensured that the protection level of the second security protection mode is not lower than the protection level of the second security policy.
- the first terminal device determining the second security protection mode according to the second security policy and the first security policy includes:
- the first terminal device determines that the protection level of the second security protection mode is security protection required
- the first terminal device determines the protection level of the second security protection mode according to the protection level of the first security policy.
- the protection level of the second security protection mode is not lower than the protection levels of the second security policy and the first security policy.
- the first terminal device determining the second security protection mode according to the first security policy includes:
- the first terminal device determines that the protection level of the second security protection mode is security protection required
- the first terminal device determines the protection level of the second security protection mode according to its own security protection capability
- the first terminal device determines that the protection level of the second security protection mode is that security protection is not required.
- the first terminal device may also determine the fourth security protection mode by the following method, wherein the fourth security protection mode It is used to protect data transmitted between the first terminal device and the second terminal device when using the second communication mode for data transmission.
- the fourth security protection mode can be directly adopted to protect the first terminal device and the second terminal device. Data transferred between second terminal devices.
- Method 1 The first terminal device sends the second security protection mode to the second terminal device, and receives the fourth security determined by the second terminal device according to the second security protection mode and the third security protection mode Protection method.
- Method 2 The first terminal device receives the third security protection mode sent by the second terminal device, and determines the fourth security protection mode according to the second security protection mode and the third security protection mode.
- the protection level of the fourth security protection mode is not lower than the protection level of the second security protection mode, and is not lower than the protection level of the third security protection mode;
- the security protection mode is used to protect the data transmitted when the second terminal device adopts the second communication mode, and the fourth security protection mode is used to protect the first terminal device and the second terminal device using the Data transmitted during data transmission in the second communication method.
- the first terminal device determines the fourth security protection mode according to the second security protection mode and the third security protection mode, including:
- the first terminal device determines that the protection level of the fourth security protection mode is security protection required ;
- the first terminal device determines that the protection level of the fourth security protection mode does not require security protection.
- the second security protection mode is specifically used to protect the first terminal device and the second terminal device using the first terminal device.
- the data transmitted during data transmission in the second communication mode; the first terminal device may negotiate with the second terminal device through the following methods to determine the second security protection mode:
- Method 1 The first terminal device sends the first security policy to the second terminal device, and receives the second security policy determined by the second terminal device according to the first security policy and the third security policy Security protection method; or
- Method 2 The first terminal device receives the third security policy sent by the second terminal device; and determines the second security protection mode according to the first security policy and the third security policy;
- the protection level of the second security protection mode is not lower than the protection level of the first security policy, and is not lower than the protection level of the third security policy; the third security policy is the second security policy.
- the protection level of the first communication mode of the terminal device is not lower than the protection level of the first security policy, and is not lower than the protection level of the third security policy; the third security policy is the second security policy.
- the first terminal device determining the second security protection mode according to the first security policy and the third security policy includes:
- the first terminal device determines that the protection level of the second security protection mode is security protection required
- the first terminal device determines that the protection level of the second security protection mode is that security protection is not required;
- the first terminal device determines the protection level of the second security protection mode according to its own security protection capability.
- the first terminal device acquires the security protection information of the first communication mode when it determines to switch from the first communication mode to the second communication mode.
- the first terminal device determines the second security protection mode according to the security protection information, including:
- the first terminal device sends the security protection information to the network device; and receives the second security protection mode from the network device, where the second security protection mode is determined by the network device according to the security protection information Of; or
- the first terminal device sends the security protection information to the application server and sends a request message to the network device; the first terminal device receives the second security protection mode from the network device, and the second security protection The manner is determined by the network device according to the security protection information obtained from the application server.
- the first terminal device can obtain the second security protection mode from the network device.
- the second security protection mode is the same as the first security protection mode.
- the protection level of the second security protection mode is higher than the protection level of the first security protection mode
- the second security protection mode is determined by the network device according to the first security protection mode and/or a second security policy, wherein the second security policy is the first terminal obtained by the network device
- the device adopts the protection level of the second communication mode
- the second security protection mode is determined by the network device according to the first security protection mode and a third security protection mode, wherein the third security protection mode is the network device according to the second security policy definite.
- the network device can determine the second security protection mode through multiple methods.
- the protection level of the second security policy is security protection required
- the protection level of the second security protection mode is security protection required
- the protection level of the second security policy is priority security protection, and the protection level of the first security protection mode is security protection required, the protection level of the second security protection mode is security protection required;
- the protection level of the second security policy is priority security protection
- the protection level of the first security protection mode is that security protection is not required
- the protection level of the second security protection mode is specified by the network device
- the protection level of the second security policy is that security protection is not required, and the protection level of the first security protection mode is that security protection is required, the protection level of the second security protection mode is that security protection is required;
- the protection level of the second security policy is that security protection is not required
- the protection level of the first security protection mode is that security protection is not required
- the protection level of the second security protection mode is that security protection is not required
- the protection level of the third security protection mode is security protection required
- the protection level of the second security protection mode is security protection required
- the protection level of the third security protection mode is that security protection is not required, and the protection level of the first security protection mode is that security protection is required, the protection level of the second security protection mode is that security protection is required;
- the protection level of the third security protection mode is that security protection is not required
- the protection level of the first security protection mode is that security protection is not required
- the protection level of the second security protection mode is that security protection is not required
- the protection level of the second security protection mode is not lower than the protection levels of the third security protection mode and the first security protection mode.
- the second security protection mode is specifically used to protect the first terminal device and the second terminal device using the second Data transmitted during data transmission in a communication mode; the first terminal device may negotiate with the second terminal device through the following methods to determine the second security protection mode:
- Method 1 When the security protection information includes the first security protection method, the first terminal device sends the first security protection method to a second terminal device, and receives the first security protection method from the second terminal device.
- the second security protection mode wherein the second security protection mode is determined by the second terminal device according to the first security protection mode and the third security protection mode, and the protection level of the second security protection mode is not Lower than the protection level of the first security protection mode, and not lower than the protection level of the third security protection mode;
- Method 2 When the security protection information includes the first security protection mode, the first terminal device receives a third security protection mode from the second terminal device, and performs the third security protection mode according to the first security protection mode and the The third security protection mode determines the second security protection mode; wherein the protection level of the second security protection mode is not lower than the protection level of the first security protection mode, and is not lower than the third security protection mode.
- the protection level of the security protection method
- Method 3 When the security protection information includes the first security protection method and the first security policy, the first terminal device sends the first security protection method and the first security policy to the second terminal device The first security policy; the first terminal device receives the second security protection mode from the second terminal device; wherein, the second security protection mode is that the second terminal device is based on the first security protection Mode, the first security policy, the third security protection mode, and the second security policy; when the first security protection mode is the same as the third security protection mode, the second security protection mode is The first security protection mode is the same; when the first security protection mode is different from the third security protection mode, the protection level of the second security protection mode is not lower than the first security protection mode and The protection level of the second security protection mode is not lower than the protection levels of the first security policy and the second security policy;
- Method 4 When the security protection information includes the first security protection mode and the first security policy, the first terminal device receives the third security protection mode and the second security policy from the second terminal device The first terminal device determines the second security protection mode according to the first security protection mode, the first security policy, the third security protection mode, and the second security policy; wherein, When the first security protection mode is the same as the third security protection mode, the second security protection mode is the same as the first security protection mode; when the first security protection mode is the same as the third security protection mode When the protection modes are different, the protection level of the second security protection mode is not lower than the protection levels of the first security protection mode and the second security protection mode, and is not lower than the first security policy and the protection level. State the protection level of the second security strategy;
- the third security protection method is used to protect data transmitted when the second terminal device adopts the first communication method, and the second security policy is the first communication of the second terminal device Way of security policy.
- the second security protection method is not lower than the protection level of the security protection information of the first communication method determined by the first terminal device, nor is it lower than the first communication method determined by the second terminal device.
- the security protection level of the communication method is not lower than the protection level of the security protection information of the first communication method determined by the first terminal device, nor is it lower than the first communication method determined by the second terminal device.
- the first terminal device determines the second security protection mode according to the first security protection mode and the third security protection mode, including:
- the first terminal device determines that the protection level of the second security protection mode is Need security protection
- the first terminal device determines the second security protection mode through a network device Protection level
- the first terminal device determines the protection level of the second security protection mode For safety protection
- the first terminal device determines the protection of the second security protection mode The grade does not require security protection.
- the protection level of the second security protection mode is not lower than the protection levels of the first security protection mode and the third security protection mode.
- the first terminal device determines the second security protection mode according to the first security protection mode, the first security policy, the third security protection mode, and the second security policy.
- Security protection methods including:
- the first terminal device determines that the second security protection mode is the first security protection mode
- the first terminal device determines the second security protection mode according to the first security policy and the second security policy.
- the first terminal device determines the second security protection mode according to the first security protection mode, the first security policy, the third security protection mode, and the second security policy.
- Security protection methods including:
- the first terminal device determines that the protection level of the second security protection mode is Need security protection
- the first terminal device determines the second security protection mode through a network device Protection level
- the first terminal device determines the protection level of the second security protection mode For safety protection
- the first terminal device is based on the first security policy and the The second security policy determines the second security protection mode.
- the first terminal device determining the second security protection mode according to the first security policy and the second security policy includes:
- the first terminal device determines that the protection level of the second security protection mode is security protection required
- the first terminal device determines that the protection level of the second security protection mode is that security protection is not required;
- the first terminal device determines the protection level of the second security protection mode according to its own security protection capability.
- the protection level of the second security protection mode is not lower than the protection levels of the first security policy and the second security policy.
- any of the above security policies includes: confidentiality protection requirements, and/or, integrity protection requirements; correspondingly, any of the above security protection methods include: confidentiality protection requirements, and/or, integrity Protection needs.
- an embodiment of the present application provides a security protection method determining device, which includes a unit for executing each step in the above first aspect.
- an embodiment of the present application provides a terminal device, including at least one processing element and at least one storage element, wherein the at least one storage element is used to store programs and data, and the at least one processing element is used to execute the first On the one hand, the method provided.
- the embodiments of the present application also provide a computer program, which when the computer program runs on a computer, causes the computer to execute the method provided in the first aspect.
- the embodiments of the present application also provide a computer storage medium in which a computer program is stored.
- the computer program is executed by a computer, the computer is caused to execute the method provided in the first aspect. .
- an embodiment of the present application also provides a chip, which is used to read a computer program stored in a memory and execute the method provided in the above-mentioned first aspect.
- an embodiment of the present application also provides a chip system, which includes a processor, and is configured to support a computer device to implement the method provided in the first aspect.
- the chip system further includes a memory, and the memory is used to store necessary programs and data of the computer device.
- the chip system can be composed of chips, or can include chips and other discrete devices.
- FIG. 1 is an architecture diagram of a communication system provided by an embodiment of this application.
- FIG. 2 is a flowchart of a user plane security protection mechanism provided by an application embodiment
- FIG. 3 is a flowchart of a method for determining a security protection method provided by an embodiment of the application
- FIG. 4 is a flowchart of an example of determining a security protection method provided by an embodiment of the application
- FIG. 5 is a flowchart of an example of determining a security protection method provided by an embodiment of the application
- FIG. 6 is a flowchart of an example of determining a security protection method provided by an embodiment of the application
- FIG. 7 is a flowchart of an example of determining a security protection method provided by an embodiment of the application.
- FIG. 8 is a structural diagram of a device for determining a security protection method provided by an embodiment of the application.
- FIG. 9 is a structural diagram of a terminal device provided by an embodiment of the application.
- the embodiments of the present application provide a method and device for determining a security protection mode, which are used to ensure the data transmission security of the terminal device after the terminal device switches the communication mode.
- the method and the device are based on the same technical idea. Since the principles of the method and the device to solve the problem are similar, the implementation of the device and the method can be referred to each other, and the repetition will not be repeated.
- Network equipment is the equipment in the communication system that connects terminal equipment to the wireless network.
- the network device may also be referred to as a base station, or may also be referred to as a radio access network (RAN) node (or device).
- RAN radio access network
- gNB transmission reception point
- TRP transmission reception point
- eNB evolved Node B
- RNC radio network controller
- Node B Node B
- NB access point
- access point access point
- AP base station controller
- BSC base transceiver station
- BTS home base station
- BBU baseband unit
- eLTE-DSA Enterprise LTE Discrete Spectrum Aggregation
- the network device may include a centralized unit (CU) node and a distributed unit (DU) node.
- CU centralized unit
- DU distributed unit
- This structure splits the protocol layer of the eNB in the long-term evolution (LTE) system.
- Some of the protocol layer functions are placed under the centralized control of the CU, and some or all of the protocol layer functions are distributed in the DU.
- Centralized control of DU For example, the method to be executed by the network device may be specifically executed by the CU, or of course, may also be executed by the DU.
- Terminal equipment is a device that provides users with voice and/or data connectivity. Terminal equipment may also be called user equipment (UE), mobile station (MS), mobile terminal (MT), and so on.
- UE user equipment
- MS mobile station
- MT mobile terminal
- the terminal device may be a handheld device with a wireless connection function, a vehicle-mounted device, etc.
- some examples of terminal equipment are: mobile phones (mobile phones), tablet computers, notebook computers, handheld computers, mobile internet devices (MID), smart point of sale (POS), wearable devices, Virtual reality (VR) equipment, augmented reality (AR) equipment, industrial control (industrial control) wireless terminals, unmanned driving (self-driving) wireless terminals, remote medical surgery (remote medical surgery)
- Uu interface is the interface between terminal equipment and access network (ie network equipment) in the communication system, also called air interface, mainly used to transmit user plane data and control plane correlation between terminal equipment and network equipment Signaling, establishment, reconfiguration and release of various mobile communication radio bearer services.
- access network ie network equipment
- air interface mainly used to transmit user plane data and control plane correlation between terminal equipment and network equipment Signaling, establishment, reconfiguration and release of various mobile communication radio bearer services.
- the PC5 interface is a direct communication interface between the terminal device and the terminal device introduced in the D2D project of the 3rd Generation Partnership Project (3rd Generation Partnership Project, 3GPP) version 12 (Rel-12).
- Neighboring terminals can transmit data through the direct link within the effective communication range of the PC5 interface, without forwarding through a central node (such as a base station), or transmitting information through a traditional cellular link.
- the communication is more Fast and convenient.
- Communication method corresponding to communication technology or communication interface, such as Uu interface communication method, PC5 interface communication method.
- the terminal device needs to adopt a certain communication method, use the corresponding communication technology, and establish a communication connection with other terminal devices through the corresponding communication interface to realize service transmission.
- the communication system can support multiple communication methods, that is, the terminal device can transmit via the first communication method or transmit via the second communication method.
- the communication system may also support the terminal device to switch the communication mode. For example, when the terminal device uses the Uu interface communication mode to transmit service data, it can be triggered to use the PC5 interface communication mode to transmit subsequent service data. For another example, when the terminal device uses the PC5 interface communication mode to transmit service data, it can also be triggered to use the Uu interface communication mode to transmit subsequent service data.
- the security strategy of the communication mode is a protection strategy specified by the network side when the terminal device adopts the communication mode.
- the security policy may include confidentiality protection requirements, and/or integrity protection requirements.
- the protection level of any protection requirement in the security policy can be but not limited to the following two levels:
- Dividing method 1 1. Need security protection, 2. Does not need security protection.
- the security protection mode of the communication mode is used to protect the data transmitted when the terminal device adopts the communication mode, and it specifies the protection level of the data.
- the security protection method can be determined by the security policy.
- the security protection mode may include confidentiality protection requirements, and/or integrity protection requirements.
- the protection level in the security protection mode is that security protection is required, or that security protection is not required.
- FIG. 1 shows the architecture of a possible communication system to which the method for determining a security protection mode provided by an embodiment of the present application is applicable.
- the communication system includes: terminal equipment, access network (AN), core network, and data network (DN).
- AN access network
- DN data network
- the DN may be the Internet, an IP Multi-media Service (IMS) network, a local area network, and the like.
- IMS IP Multi-media Service
- the DN includes an application server, and the application server provides business services for the terminal device through data transmission with the terminal device.
- the access network provides wireless access-related services for terminal equipment.
- the wireless access network includes network equipment, and the network equipment provides specific wireless access services for terminal devices, realizing physical layer functions, resource scheduling and wireless resource management, and quality of service (QoS) management , Wireless access control and mobility management functions.
- QoS quality of service
- the core network is the communication system responsible for connecting the terminal equipment to different data networks according to the call request or service request sent by the terminal equipment through the access network, as well as services such as charging, mobility management, and session management.
- the logical functions of the core network device are divided into control plane network elements and user plane network elements.
- the user plane network element can also be referred to as a user plane function (User Plane Function, UPF) entity, which is an anchor for maintaining business continuity of the terminal device and is responsible for forwarding user plane data of the terminal device.
- UPF User Plane Function
- the control plane network element is mainly responsible for the realization of session management, access and mobility management, and policy control and other network elements with control management functions.
- the control plane network elements may, but are not limited to, include: Access and Mobility Management Function (AMF) entities, Session Management Function (SMF) entities, or Policy Control Function (Policy Control Function) , PCF) entity, unified data management function (UDM) entity, network exposure function (NEF) entity, and authentication server function (authentication server function, AUSF).
- AMF Access and Mobility Management Function
- SMF Session Management Function
- Policy Control Function Policy Control Function
- PCF Policy Control Function
- UDM unified data management function
- NEF network exposure function
- AUSF authentication server function
- control plane network elements in the core network are described below.
- the AMF entity is used for functions such as registration, mobility management, and tracking area update procedures of the terminal device.
- the SMF entity is used to be responsible for the session management of the terminal device (including the establishment, modification and release of the session), the selection and reselection of the UPF entity, the IP address allocation of the terminal device, QoS control, etc.
- the PCF entity can be used for functions such as policy control decision-making.
- the UDM entity can be used to manage the subscription data of the terminal device and the registration information related to the terminal device.
- the AUSF entity is used for authentication of terminal equipment during the registration process.
- the above entities in the core network can be network elements implemented on dedicated hardware, software instances running on dedicated hardware, or instances of virtualized functions on an appropriate platform, such as ,
- the aforementioned virtualization platform may be a cloud platform.
- the above entities are divided according to functions. In actual applications, according to logical functions, any of the above functional entities can also be split into multiple functional entities, or multiple functional entities can be merged into one functional entity, which is not limited in this application. .
- the terminal equipment and the network equipment communicate through the Uu interface, as shown in the figure.
- the following scenarios can be included:
- Scenario 1 The terminal device a and the terminal device b respectively access the network device A and network device B serving it through the Uu interface, and then the terminal device A sends the data to the UPF entity in the core network through the network device A.
- the UPF entity is forwarded to terminal device B through network device B.
- Terminal equipment a and terminal equipment b respectively access network equipment A and network equipment B serving them through the Uu interface, and then terminal equipment A sends data to network equipment B through network equipment A, and then network equipment B forwards the data To terminal equipment B.
- Terminal device A and terminal device B respectively access network device A and network device B serving them through the Uu interface, and then terminal device A forwards the data to the application server in the DN through network device A and UPF entity, so The application server then forwards the data to the terminal device B through the UPF entity and the network device B.
- the network devices A and B in the above scenario may be the same or different.
- the UPF that the network device A communicates with and the UPF that the network device B communicates with may be the same or different.
- the communication system also supports edge connection (sidelink) communication technology
- two terminal devices in close proximity can establish a direct link through the PC5 interface for sidelink data transmission, that is, the PC5 interface is used between the two terminal devices Communication method for data transmission.
- the sidelink communication technology is a near field communication technology that can be directly connected between terminal devices, also known as proximity services (Proximity services, ProSe) communication technology, or D2D communication technology.
- ProSe proximity services
- D2D communication technology D2D communication technology.
- multiple terminal devices that are located in close geographic locations and support sidelink communication can form a sub-communication system.
- sidelink communication can be carried out between terminal devices.
- FIG. 1 does not constitute a limitation of the communication system applicable to the embodiments of the present application.
- the method provided in the embodiments of the present application can be applied to various communication systems supporting multiple communication modes.
- the multiple communication methods include but are not limited to the above two communication methods.
- the communication system provided in this application may be a comprehensive communication system coupled with a mobile communication system and any other system. Among them, this application does not limit the type and standard of the mobile communication system.
- the mobile communication system may be a future communication system (for example, the sixth generation communication system, the seventh generation communication system, etc.), the fifth generation (The 5th Generation) , 5G) communication system, Long Term Evolution (LTE) communication system, etc.
- the other systems may, but are not limited to, include: device to device (D2D), vehicle to everything (V2X), long-term evolution-vehicle network (LTE-vehicle, LTE-V), vehicle to vehicle (vehicle to vehicle, V2V), car networking, machine type communications (MTC), internet of things (IoT), long-term evolution-machine to machine (LTE-machine to machine, LTE-M), Communication systems such as machine to machine (M2M) and enterprise LTE discrete spectrum aggregation (eLTE-DSA) systems.
- D2D device to device
- V2X vehicle to everything
- LTE-vehicle network LTE-vehicle, LTE-V
- vehicle to vehicle vehicle to vehicle
- V2V car networking
- MTC machine type communications
- IoT internet of things
- LTE-machine to machine LTE-machine to machine
- Communication systems such as machine to machine (M2M) and enterprise LTE discrete spectrum aggregation (eL
- the communication system adopts a corresponding data security protection mechanism for each communication mode.
- the terminal device and the network device may adopt the user plane security protection mechanism shown in FIG. 2 to protect the data transmitted through the Uu interface.
- the specific process of the communication system using the user plane security protection method includes:
- S201 In the process of establishing a Packet Data Unit (PDU) session, the terminal device sends a NAS message to the AMF entity through the network device, where the NAS message contains single network slice selection assistance information (single network slice selection assistance). information, S-NSSAI), data network identification (data network number, DNN) and other parameters.
- PDU Packet Data Unit
- the NAS message also contains at least one or a combination of the following: PDU Session ID (PDU Session ID), request type (request type), Old PDU Session ID (Old PDU Session ID), N1 session Management container (N1SM container).
- PDU Session ID PDU Session ID
- request type request type
- Old PDU Session ID Old PDU Session ID
- N1SM container N1 session Management container
- the N1SM container includes a PDU session establishment request (PDU session establishment request).
- the AMF entity After receiving the NAS message, the AMF entity sends a create SMF context request (create SMF context request) or an update SMF context request (update SMF context request) to the SMF entity, which carries the user permanent identification of the terminal device Symbol (subscription permanent identifier, SUPI), S-NSSAI, DNN.
- create SMF context request create SMF context request
- update SMF context request update SMF context request
- the SMF context establishment request or the SMF context update request may also include the N1SM container.
- the SMF entity requests a user plane security policy from the UDM entity, which specifically includes: the SMF entity sends a user plane security policy request to the UDM entity, and the request includes SUPI, DNN and/or S-NSSAI.
- the UDM entity may determine the user plane security policy of the contract according to SUPI, DNN and/or S-NSSAI, and if the UDM can determine the user plane security policy, then send the user plane security policy to the SMF entity .
- the SMF entity may obtain the user plane security policy from the UDM entity through this step; If the UDM entity does not save the user plane security policy signed by the terminal device, the SMF entity cannot obtain the user plane security policy from the UDM entity through this step.
- the SMF entity determines the final user plane security policy.
- the SMF entity determines that the obtained user plane security policy is the final user plane security policy; when the SMF entity passes S203
- the SMF entity may also determine the final user plane security policy in the locally stored user plane security policy according to the DNN and/or S-NSSAI.
- the user plane security policy includes confidentiality protection requirements and/or integrity protection requirements.
- the SMF entity sends the determined user plane security policy to the network device through the AMF entity.
- the network device determines the final user plane security protection method according to the local security protection capability (for example, whether the integrity protection rate is supported, etc.).
- the user plane security protection mode determined by the network device is security protection required. If the network device determines that security protection cannot be performed locally, the network device sends The SMF entity sends a rejection indication.
- the user plane security policy is priority security protection
- whether the user plane security protection method determined by the network device performs security protection is determined by the network device according to the local security protection capability.
- the user plane security protection mode determined by the network device is that security protection is not required.
- security protection in the above example can be confidentiality protection or integrity protection.
- the network device sends a user plane security protection mode to the terminal device.
- the network device may send a security protection instruction (for example, a confidentiality protection instruction, an integrity protection instruction) to the terminal device.
- a security protection instruction for example, a confidentiality protection instruction, an integrity protection instruction
- the security protection instruction is used to indicate whether confidentiality protection is required and whether integrity protection is required.
- the optional security protection instruction can also indicate the length of the key, or a specific confidentiality protection algorithm or a specific integrity protection algorithm.
- S208 The terminal device and the network device perform protection on the subsequently transmitted user plane data according to the user plane security protection mode.
- the communication system can support terminal equipment to switch communication modes. For example, when the terminal device uses the Uu interface communication mode to transmit service data, it can be triggered to use the PC5 interface communication mode to transmit subsequent service data.
- the terminal equipment in the communication system adopts different communication methods, there may be differences in the data security protection methods used. For example, when the terminal device adopts the Uu interface communication mode, the user plane security protection mode requires security protection, and when the terminal device adopts the PC5 interface communication mode, the security protection mode does not require security protection, then when the terminal device When switching from the Uu interface communication mode to the PC5 interface communication mode, the terminal device cannot encrypt data.
- the terminal device When the terminal device is in group communication, other terminal devices other than the receiving end can eavesdrop on the terminal device transmission The data security of the terminal device is reduced. In addition, if the initial data is protected but the data is not protected after the handover, the security of the business data will also be reduced.
- the embodiment of the present application provides a method for determining a security protection mode, which can be applied to a communication system that supports multiple communication modes and supports switching communication modes as shown in FIG. 1.
- the first terminal device involved in the method is any terminal device in the communication system. As shown in Figure 3, the method can include the following steps:
- S301 The first terminal device obtains the security protection information of the first communication mode.
- the security protection information includes a first security protection method, and/or, a first security policy;
- the first security protection method corresponds to the first communication method, and is used to protect the first terminal device using the For data transmitted in the first communication mode, the first security policy is the security policy of the first communication mode of the first terminal device.
- the first terminal device determines a second security protection mode according to the security protection information, where the second security protection mode corresponds to the second communication mode and is used to protect the first terminal device when the second communication mode is used The transmitted data.
- the method can be applied to the following two scenarios.
- the first terminal device may obtain the security protection information of the first communication mode when requesting to use the first communication mode or when the first communication mode is about to be used, and then obtain the security protection information of the first communication mode according to the security protection Information, the second security protection method is predetermined. In this way, when the first terminal device switches from the first communication mode to the second communication mode, it can directly use the second security protection mode for protection to avoid determining the second communication mode during the switching process. The time delay caused by the security protection mode can improve the communication efficiency of the first terminal device.
- the first terminal device may obtain the security protection information of the Uu interface communication mode from the network device during the PDU session establishment process or registration, and use the security protection information to determine the second security corresponding to the PC5 interface communication mode Protection method.
- the first terminal device may also obtain the security protection information of the PC5 interface communication mode from the local or application server when requesting the use of the PC5 interface communication mode, and use the security protection information to determine the corresponding Uu interface communication mode The second way of safety protection.
- the first terminal device may obtain the security protection information of the first communication mode in the case of determining to switch from the first communication mode to the second communication mode, and obtain the security protection information according to the security protection information , Predetermine the second security protection method.
- the first terminal device may execute the foregoing process before, during, and after the handover, which is not limited in this application.
- the first security protection mode of the first communication mode may be determined by the first terminal device using the scenario one method, or determined by other methods, this application does not limit this.
- the protection level of the second security protection mode determined by the first terminal device is not low
- the protection level specified in the security protection information of the first communication method is not low
- the first terminal device may perform S302 by the following method:
- Method 1 The first terminal device determines that the second security protection mode is the same as the first security protection mode.
- Method 2 The first terminal device acquires a second security policy, where the second security policy is the security policy of the second communication mode of the first terminal device; the first terminal device is based on the second The security policy, the first security protection mode, and the second security protection mode are determined, wherein the protection level of the second security protection mode is not lower than the protection level of the second security policy and is not lower than all State the protection level of the first safety protection mode.
- the first terminal device may obtain the second security policy from a local or an application server, and when the second communication mode is the Uu communication mode, The first terminal device may obtain the second security policy from a network device.
- the first terminal device determining the second security protection mode according to the second security policy and the first security protection mode includes:
- the first terminal device determines that the protection level of the second security protection mode is security protection required
- the first terminal device determines that the protection level of the second security protection mode is Need security protection
- the first terminal device determines the second security according to its own security protection capability Protection level of protection mode
- the first terminal device determines the protection level of the second security protection mode Because no security protection is required.
- the protection level of the second security protection mode determined by the first terminal device is not lower than the protection levels of the first security protection mode and the second security policy.
- the first terminal device may perform S302 by the following method:
- Method 1 The first terminal device determines the second security protection mode according to the first security policy.
- Method 2 The first terminal device acquires a second security policy, where the second security policy is the security policy of the second communication mode of the first terminal device; the first terminal device is based on the second The security policy and the first security policy determine the second security protection mode, wherein the protection level of the second security protection mode is not lower than the protection level of the second security policy, and is not lower than the protection level of the second security policy.
- the protection level of the first security policy is not lower than the protection level of the second security policy, and is not lower than the protection level of the second security policy.
- the first terminal device determining the second security protection mode according to the second security policy and the first security policy includes:
- the first terminal device determines that the protection level of the second security protection mode is security protection required
- the first terminal device determines the protection level of the second security protection mode according to the protection level of the first security policy
- the first terminal device determines the protection level of the second security protection mode according to the protection level of the first security policy. If the first security policy requires security protection, then the protection is performed. If the first security policy is priority security protection or security protection is not required, the first terminal device determines whether to perform protection according to the priority security protection mode.
- the first terminal device determining the second security protection mode according to the first security policy includes:
- the first terminal device determines that the protection level of the second security protection mode is security protection required
- the first terminal device determines the protection level of the second security protection mode according to its own security protection capability
- the first terminal device determines that the protection level of the second security protection mode is that security protection is not required.
- the first terminal device may also interface with the PC5
- the peer device of the communication mode (for ease of description, it may be referred to as the second terminal device in the following) negotiates to determine the fourth security protection mode, where the fourth security protection mode is used to protect the first terminal device and The data transmitted between the second terminal devices during data transmission using the PC5 interface communication mode.
- the specific negotiation process can include the following methods:
- Method 1 The first terminal device sends the second security protection mode to the second terminal device, and receives the fourth security determined by the second terminal device according to the second security protection mode and the third security protection mode Protection method.
- Method 2 The first terminal device receives the third security protection mode sent by the second terminal device, and determines the fourth security protection mode according to the second security protection mode and the third security protection mode.
- the protection level of the fourth security protection mode is not lower than the protection level of the second security protection mode, and is not lower than the protection level of the third security protection mode;
- the security protection mode is used to protect the data transmitted when the second terminal device adopts the second communication mode.
- the third security protection mode may be determined by the second terminal device through S301 and S302, which is not limited in this application.
- the first terminal device and the second terminal device may adopt the same method, and determine the first terminal device according to the second security protection mode and the third security protection mode.
- Four security protection methods The following takes the first terminal device as an example for description:
- the first terminal device determines that the protection level of the fourth security protection mode is security protection required ;
- the first terminal device determines that the protection level of the fourth security protection mode does not require security protection.
- the protection level of the fourth security protection mode determined by the first terminal device is not lower than the protection levels of the second security protection mode and the third security protection mode.
- the second security protection mode is specifically used to protect the communication between the first terminal device and the second terminal device.
- the second communication mode is the data transmitted during data transmission. That is, the first terminal device can directly determine the first terminal based on the security protection information of the first communication mode (the security protection information of the first communication mode of the first terminal device, which will be referred to as security protection information 1 in the following).
- security protection information 1 the security protection information of the first communication mode of the first terminal device
- the first terminal device may determine the second security protection mode through a method negotiated with the second terminal device.
- the specific negotiation process can include the following methods:
- the first terminal device sends the security protection information 1 to the second terminal device, and receives the information of the second terminal device according to the security protection information 1 and the first communication mode of the second terminal device
- the second security protection mode determined by the security protection information (hereinafter referred to as security protection information 2).
- Method 2 The first terminal device receives the security protection information 2 sent by the second terminal device; and determines the second security protection mode according to the security protection information 1 and the security protection information 2.
- the protection level of the second security protection mode is not lower than the protection level of the security protection information 1 and is not lower than the protection level of the security protection information 2.
- the security protection information 2 includes a third security protection method, and/or, a third security policy.
- the security protection information includes a security protection method
- the first terminal device and the second terminal device may use the same method, according to the first security protection method and the The third security protection mode in the security protection information 2 determines the second security protection mode.
- the third security protection mode is the security protection mode of the first communication mode of the second terminal device.
- the first terminal device determines that the protection level of the third security protection mode is security protection required ;
- the first terminal device determines that the protection level of the third security protection mode does not require security protection.
- the security protection information includes a security policy
- the first terminal device and the second terminal device may use the same method, according to the first security policy and the security protection information
- the third security policy in 2 determines the second security protection mode.
- the third security policy is the security protection mode of the first communication mode of the second terminal device.
- the first terminal device determines that the protection level of the second security protection mode is security protection required
- the first terminal device determines that the protection level of the second security protection mode is that security protection is not required;
- the first terminal device determines the protection level of the second security protection mode according to its own security protection capability.
- the protection level of the second security protection mode determined by the first terminal device is not lower than the protection levels of the first security policy and the third security policy.
- the security protection information includes a security protection method and a security policy
- the first terminal device and the second terminal device may use the same method, according to the security protection information 1
- the first security protection mode and the first security policy, and the third security protection mode and the second security policy in the security protection information 2 determine the second security protection mode.
- the first terminal device determines that the second security protection mode is the first security protection mode
- the first terminal device determines the second security protection mode according to the first security policy and the second security policy.
- the first terminal device determines that the protection level of the second security protection mode is Need security protection
- the first terminal device determines the second security protection mode through a network device Protection level
- the first terminal device determines the protection level of the second security protection mode For safety protection
- the first terminal device is based on the first security policy and the The second security policy determines the second security protection mode.
- determining the second security protection mode by the first terminal device according to the first security policy and the second security policy includes:
- the first terminal device determines that the protection level of the second security protection mode is security protection required
- the first terminal device determines that the protection level of the second security protection mode is that security protection is not required;
- the first terminal device determines the protection level of the second security protection mode according to its own security protection capability.
- the first terminal device may perform S302 by the following method:
- Method 1 The first terminal device sends the security protection information to the network device; and receives the second security protection method from the network device, and the second security protection method is that the network device is based on the security The protection information is determined.
- Method 2 The first terminal device sends the security protection information to the application server and sends a request message to the network device; the first terminal device receives the second security protection mode from the network device, and the first terminal device The second security protection mode is determined by the network device according to the security protection information obtained from the application server.
- the SMF entity in the core network obtains the security protection information from the application server, and then transfers the security protection information Sent to the network device.
- the network device requests the security protection information by sending a PDU session establishment request to the SMF entity.
- the first terminal device may simultaneously send the identification information of the security protection information when sending the security protection information to the application server. In this way, the first terminal device is sending the security protection information to the application server.
- the identification information may be carried. The network device sends the identification information to the SMF entity through a PDU session establishment request.
- the SMF entity can accurately obtain the security protection information from the application server according to the identification information; or simultaneously send the security protection information and the identification information to the SMF at the application server
- the SMF entity may accurately determine the security protection information corresponding to the identification information of the first terminal device from a plurality of locally stored security protection information according to the identification information.
- the identification information of the security protection information may be, but is not limited to: the operator network identifier of the UE, the generalized public subscription identifier (GPSI), the application ID, the application ID of the first terminal device, and the first terminal device. At least one of the operator network ID of a terminal device and the PC5 link identifier.
- GPSI generalized public subscription identifier
- the security protection information includes the first security protection mode; the network device may determine the second security protection mode in the following manner:
- Manner 1 The second security protection mode is the same as the first security protection mode.
- Manner 2 The protection level of the second security protection mode is higher than the protection level of the first security protection mode.
- the second security protection mode is determined by the network device according to the first security protection mode and/or a second security policy, where the second security policy is the network device obtained
- the first terminal device adopts the protection level of the second communication mode.
- the protection level of the second security policy is security protection required
- the protection level of the second security protection mode is security protection required
- the protection level of the second security policy is priority security protection, and the protection level of the first security protection mode is security protection required, the protection level of the second security protection mode is security protection required;
- the protection level of the second security policy is priority security protection
- the protection level of the first security protection mode is that security protection is not required
- the protection level of the second security protection mode is specified by the network device
- the protection level of the second security policy is that security protection is not required, and the protection level of the first security protection mode is that security protection is required, the protection level of the second security protection mode is that security protection is required;
- the protection level of the second security policy is that security protection is not required
- the protection level of the first security protection mode is that security protection is not required
- the protection level of the second security protection mode is that security protection is not required
- the second security protection mode is not lower than the protection level of the second security policy and the first security protection mode.
- the second security protection mode is determined by the network device according to the first security protection mode and the third security protection mode, wherein the third security protection mode is that the network device is based on the first security protection mode. 2.
- the security policy is determined.
- the protection level of the third security protection mode is security protection
- the protection level of the second security protection mode is security protection
- the protection level of the third security protection mode is that security protection is not required, and the protection level of the first security protection mode is that security protection is required, the protection level of the second security protection mode is that security protection is required;
- the protection level of the third security protection mode is that security protection is not required
- the protection level of the first security protection mode is that security protection is not required
- the protection level of the second security protection mode is that security protection is not required
- the second security protection mode is not lower than the protection levels of the first security protection mode and the third security protection mode.
- the second security protection mode is specifically used to protect the communication between the first terminal device and the second terminal device.
- the first terminal device may determine the second security protection mode through negotiation with the second terminal device.
- the third security protection mode is used to protect data transmitted when the second terminal device adopts the first communication mode
- the second security policy is the The security policy of the first communication method.
- Specific negotiation methods can include but are not limited to:
- Method 1 When the security protection information includes the first security protection method, the first terminal device sends the first security protection method to a second terminal device, and receives the first security protection method from the second terminal device.
- the second security protection mode wherein the second security protection mode is determined by the second terminal device according to the first security protection mode and the third security protection mode, and the protection level of the second security protection mode is not It is lower than the protection level of the first security protection mode, and not lower than the protection level of the third security protection mode.
- Method 2 When the security protection information includes the first security protection mode, the first terminal device receives a third security protection mode from the second terminal device, and performs the third security protection mode according to the first security protection mode and the The third security protection mode determines the second security protection mode; wherein the protection level of the second security protection mode is not lower than the protection level of the first security protection mode, and is not lower than the third security protection mode.
- the protection level of the security protection method is not lower than the protection level of the first security protection mode, and is not lower than the third security protection mode.
- the first terminal device determining the second security protection mode according to the first security protection mode and the third security protection mode includes:
- the first terminal device determines that the protection level of the second security protection mode is Need security protection
- the first terminal device determines the second security protection mode through a network device Protection level
- the first terminal device determines the protection level of the second security protection mode For safety protection
- the first terminal device determines the protection of the second security protection mode The grade does not require security protection.
- the protection level of the second security protection mode is not lower than the protection levels of the third security protection mode and the first security protection mode.
- Method 3 When the security protection information includes the first security protection method and the first security policy, the first terminal device sends the first security protection method and the first security policy to the second terminal device The first security policy; the first terminal device receives the second security protection mode from the second terminal device; wherein, the second security protection mode is that the second terminal device is based on the first security protection Mode, the first security policy, the third security protection mode, and the second security policy; when the first security protection mode is the same as the third security protection mode, the second security protection mode is The first security protection mode is the same; when the first security protection mode is different from the third security protection mode, the protection level of the second security protection mode is not lower than the first security protection mode and The protection level of the second security protection mode is not lower than the protection levels of the first security policy and the second security policy.
- Method 4 When the security protection information includes the first security protection mode and the first security policy, the first terminal device receives the third security protection mode and the second security policy from the second terminal device The first terminal device determines the second security protection mode according to the first security protection mode, the first security policy, the third security protection mode, and the second security policy; wherein, When the first security protection mode is the same as the third security protection mode, the second security protection mode is the same as the first security protection mode; when the first security protection mode is the same as the third security protection mode When the protection modes are different, the protection level of the second security protection mode is not lower than the protection levels of the first security protection mode and the second security protection mode, and is not lower than the first security policy and the protection level. Describe the protection level of the second security policy.
- the first terminal device determines the first security protection mode according to the first security protection mode, the first security policy, the third security protection mode, and the second security policy.
- Security protection methods including:
- the first terminal device determines that the second security protection mode is the first security protection mode
- the first terminal device determines the second security protection mode according to the first security policy and the second security policy.
- the first terminal device determines the first security protection mode, the first security policy, the third security protection mode, and the second security policy according to the The second security protection method includes:
- the first terminal device determines that the protection level of the second security protection mode is Need security protection
- the first terminal device determines the second security protection mode through a network device Protection level
- the first terminal device determines the protection level of the second security protection mode For safety protection
- the first terminal device is based on the first security policy and the The second security policy determines the second security protection mode.
- determining the second security protection mode by the first terminal device according to the first security policy and the second security policy includes:
- the first terminal device determines that the protection level of the second security protection mode is security protection required
- the first terminal device determines that the protection level of the second security protection mode is that security protection is not required;
- the first terminal device determines the protection level of the second security protection mode according to its own security protection capability.
- any of the above security policies can include: confidentiality protection requirements, and/or integrity protection requirements; correspondingly, any of the above security protection methods can include: confidentiality protection requirements, and /Or, integrity protection requirements.
- the confidentiality protection requirements in the second security protection method can be determined by referring to the specific method in the above example, and the second security protection The integrity protection requirement in the method can also be determined with reference to the specific method in the above example.
- the security policy for this application may also include: supporting key lengths such as 256 bits (for example, supporting 256 bits, 192 bits, etc.).
- the security policy may also include: a supported integrity protection rate (for example, supporting 64 kbps, 2 Mbps, etc.).
- the security policy may also include: the key life period (for example, one day, one hour, etc.).
- the embodiment of the present application provides a method for determining a security protection mode.
- the terminal device can determine the security protection mode of the second communication mode according to the security protection information of the first communication mode. In this way, when the terminal device is switching from the first communication mode to the second communication mode, it can directly use the security protection mode of the second communication mode to protect the transmitted data, thereby ensuring all the data after the communication mode is switched.
- the data security of the terminal equipment Further, the protection level of the security protection mode of the second communication mode determined by the terminal device is not lower than the protection level of the security protection information of the first communication mode. In this way, the protection level of the terminal device after the communication mode is switched can be further guaranteed. Data security.
- the present application also provides the following multiple security protection method determination examples, and the following examples can all be applied to the communication system as shown in FIG. 1.
- this example may include the following steps:
- S401 The terminal device A completes the registration process and registers to the operator network.
- S402-S405 is the process of establishing a session by a network device through a PDU session, requesting user plane security policies from the SMF entity and determining the security protection information of the Uu interface communication mode.
- S201 in the user plane security protection mechanism shown in Figure 2 -S306, no more details here.
- the SMF entity may determine the user plane security policy from the UDM entity or locally in S403 according to a traditional method.
- the SMF entity may also send a request to the application server in S403, obtain the application security policy of the PC5 interface communication mode from the application server side, and determine the user plane security policy according to the application security policy. For example, the SMF entity determines that the application security policy is the same as the user plane security policy; or the SMF entity determines the final user plane security policy according to the application security policy and the user plane security policy previously determined by the SMF entity.
- the SMF entity may directly communicate and interact with the application server, or the SMF entity may communicate with the application server across other network elements.
- the application server performs communication interaction, which is not limited in this application.
- classification method of the application security policy may be: classification method 1: security protection is required, and security protection is not required; or classification method 2: security protection is required, security protection is prioritized, and security protection is not required.
- the SMF entity determining that the application security policy is the same as the user plane security policy includes:
- the classification method of the application security policy is the classification method 1
- the SMF entity determines that the user plane security policy requires security protection; if the application security policy does not require security protection, Then the SMF entity determines that the user plane security policy does not require security protection.
- the SMF entity determines that the application security policy and the user plane security policy may be the same.
- the SMF entity determines the final user plane security policy according to the application security policy and the user plane security policy previously determined by the SMF entity; including:
- the SMF entity determines that the user plane security policy requires security protection; when the application security policy does not require security protection, then The final user plane security policy determined by the SMF entity may be the same as the previously determined user plane security policy.
- the SMF entity determines that the final user plane security policy requires security protection;
- the SMF entity determines that the final user plane security policy does not require protection; in other cases, the SMF entity determines that the final user plane security policy is Priority protection.
- the network device sends the security protection information of the Uu interface communication mode to the terminal device A, where the security protection information includes: the user plane security protection mode, and/or the user plane security policy.
- the terminal device A determines the security protection mode of the PC5 interface communication mode according to the security protection information of the Uu interface communication mode. Wherein, the protection level of the security protection mode of the PC5 interface communication mode is not lower than the protection level of the security protection information of the Uu interface communication mode.
- the protection level of the security protection mode of the PC5 interface communication mode is not lower than the protection level of the security protection information.
- the terminal device A determines the security protection mode of the PC5 interface communication mode by the following method:
- Method 1 The terminal device A determines that the security protection mode of the PC5 interface communication mode is the same as the user plane security protection mode.
- Method 2 The terminal device A obtains the application security policy, and determines the security protection mode of the PC5 interface communication mode according to the application security policy and the user plane security protection mode, wherein the PC5 interface communication
- the protection level of the security protection mode of this method is not lower than the protection level of the application security policy, and is not lower than the protection level of the user plane security protection mode.
- the terminal device A determines that the protection level of the security protection mode of the PC5 interface communication mode is security protection required;
- the terminal device A determines the protection level of the security protection mode of the PC5 interface communication mode For safety protection;
- the terminal device A determines the communication mode of the PC5 interface according to its own security protection capability.
- the terminal device A determines the protection of the security protection mode of the PC5 interface communication mode The grade does not require security protection.
- the terminal device A determines the security protection mode of the PC5 interface communication mode by the following method:
- Method 1 The terminal device A determines the security protection mode of the PC5 interface communication mode according to the user plane security policy, wherein the protection level of the security protection mode of the PC5 interface communication mode is not lower than that of the user plane The protection level of the security policy.
- Method 2 The terminal device A obtains the application security policy, and determines the security protection mode of the PC5 interface communication mode according to the application security policy and the user plane security policy, wherein the security of the PC5 interface communication mode is The protection level of the protection mode is not lower than the protection level of the application security policy, and is not lower than the protection level of the user plane security policy.
- the terminal device A determines that the protection level of the security protection mode of the PC5 interface communication mode is security protection required;
- the terminal device A determines the protection level of the security protection mode of the PC5 interface communication mode according to its own security protection capability;
- the terminal device A determines that the protection level of the security protection mode of the PC5 interface communication mode is that security protection is not required.
- the terminal device A determines that the protection level of the security protection mode of the PC5 interface communication mode is security protection
- the terminal device A When the protection level of the application security policy (or the user plane security policy) is priority security protection or does not require security protection, the terminal device A performs the operation according to the user plane security policy (or the application security policy)
- the protection level determines the protection level of the security protection mode of the PC5 interface communication mode, as described in the above example.
- the terminal device A determines that the peer device when the PC5 interface communication mode is adopted is the terminal device B, and the terminal device A sends the terminal device B the security protection mode of the PC5 interface communication mode. Or, the terminal device A broadcasts the determined security protection mode of the communication mode of the PC5 interface.
- the terminal device B After receiving the security protection mode of the PC5 interface communication mode, the terminal device B stores the security protection mode of the PC5 interface communication mode.
- the terminal device A when the terminal device A switches from the Uu interface communication mode to the PC5 interface communication mode, the terminal device A can directly use the security protection mode of the PC5 interface communication mode to protect the transmitted data.
- terminal device A can use the procedures S401-S407 shown in Figure 4 to determine the security protection mode 1 of the PC5 interface communication mode
- terminal device B can also use the procedures S401-S407 shown in Figure 4 to determine the PC5 interface Security protection mode of communication mode 2.
- the terminal device A and the terminal device B can negotiate to determine that the terminal device A and the terminal device B are using the security protection mode 1 of the PC5 interface communication mode and the security protection mode 2 of the PC5 interface communication mode.
- Security protection mode 3 of the PC5 interface communication method used in the PC5 interface communication method can be used in the procedures S401-S407 shown in Figure 4 to determine the security protection mode 1 of the PC5 interface communication mode
- terminal device B can also use the procedures S401-S407 shown in Figure 4 to determine the PC5 interface Security protection mode of communication mode 2.
- the terminal device A and the terminal device B can negotiate to determine that the terminal device A and the terminal device B are using the security protection mode 1 of the PC5 interface communication mode and the security protection mode 2 of the PC5 interface communication mode.
- any one of the terminal device A and the terminal device B can send the locally determined security protection mode of the PC5 interface communication mode to the other terminal device, and the other terminal device communicates according to the two PC5 interfaces To determine the final security protection mode 3 of the PC5 interface communication mode.
- terminal device A can send the determined security protection mode 1 of the PC5 interface communication mode to terminal device B, and then terminal device B determines the security protection mode 1 of the PC5 interface communication mode according to the security protection mode 1 of the PC5 interface communication mode The security protection mode 3 of the PC5 interface communication mode is then sent to the terminal device A. The security protection mode 3 of the PC5 interface communication mode is sent.
- the protection level of the security protection mode 3 of the PC5 interface communication mode is not lower than the protection levels of the security protection mode 1 of the PC5 interface communication mode and the security protection mode 2 of the PC5 interface communication mode.
- the terminal device B can determine the security protection mode 3 of the communication mode of the PC5 interface by the following method:
- the terminal device B determines the value of the PC5 interface communication mode
- the protection level of safety protection mode 3 is that safety protection is required
- the terminal device B determines the security protection of the PC5 interface communication mode
- the protection level of mode 3 is that no security protection is required.
- terminal device A can use the processes S401-S406 shown in FIG. 4 to obtain security protection information 1 (including user plane security policy 1 and/or user plane security protection mode 1) of the Uu interface communication mode
- the terminal device B may also use the processes S401-S406 shown in FIG. 4 to obtain the security protection information 2 of the Uu interface communication mode (including the user plane security policy 2 and/or the user plane security protection mode 2).
- the terminal device A and the terminal device B can negotiate to determine that the terminal device A and the terminal device B are using the Uu interface communication mode security protection information 1 and the Uu interface communication mode security protection information 2
- the security protection mode used in the PC5 interface communication mode hereinafter referred to as the security protection mode of the PC5 interface communication mode).
- any one of the terminal device A and the terminal device B may send the acquired security protection information of the Uu interface communication mode to the other terminal device, and the other terminal device will use the two Uu interface communication modes according to The security protection information of the final PC5 interface communication mode is determined.
- the protection level of the security protection mode 3 is not lower than the protection level of the security protection information 1 of the Uu interface communication mode and the security protection information 2 of the Uu interface communication mode.
- the security protection information of any Uu interface communication mode includes a user plane security policy, and any terminal device (taking terminal device A as an example) determines the PC5 interface according to user plane security policy 1 and user plane security policy 2.
- the security protection methods of communication methods include:
- the terminal device A determines that the protection level of the security protection mode of the PC5 interface communication mode is required safety protection
- the A terminal device determines that the protection level of the security protection mode of the PC5 interface communication mode is not required protection
- the terminal device A determines the protection level of the security protection mode of the PC5 interface communication mode according to its own security protection capability.
- the security protection information of any Uu interface communication mode includes user-plane security protection mode, and any terminal device (taking terminal device A as an example) is based on user-plane security protection mode 1 and user-plane security protection mode 2.
- Determine the security protection mode of the PC5 interface communication mode including:
- the terminal device A determines the protection level of the security protection mode of the PC5 interface communication mode For safety protection;
- the terminal device A determines that the protection level of the security protection mode of the PC5 interface communication mode is no Need security protection.
- the security protection information of any Uu interface communication mode includes user-plane security protection policies and user-plane security protection methods.
- Any terminal device (taking terminal device A as an example) is based on user-plane security policy 1 and user Plane security strategy 2, user plane security protection mode 1 and user plane security protection mode 2, determine the security protection mode of the PC5 interface communication mode, including the following methods:
- Method 1 When the user plane security protection mode 1 is the same as the user plane security protection mode 2, the A terminal device determines that the security protection mode of the PC5 interface communication mode is the same as the user plane security protection mode 1 When the user plane security protection mode 1 is different from the user plane security protection mode 2, the terminal device A determines the PC5 interface according to the user plane security policy 1 and the user plane security policy 2. Security protection method of communication method.
- Method 2 When at least one protection level of the user plane security protection mode 1 and the user plane security protection mode 2 requires security protection, the terminal device A determines the security protection mode of the PC5 interface communication mode The protection level is that security protection is required; when both of the user plane security protection mode 1 and the user plane security protection mode 2 do not require security protection, the terminal device A is based on the user plane security policy 1 and the user In face security policy 2, the security protection mode of the communication mode of the PC5 interface is determined.
- Method 3 When the protection level of the user plane security protection mode 2 is that security protection is required, and the protection level of the user plane security protection mode 1 is that security protection is required, the terminal device A determines the communication mode of the PC5 interface The protection level of the security protection mode is that security protection is required; when the protection level of the user-plane security protection mode 2 is that security protection is required, and the protection level of the user-plane security protection mode 1 is that security protection is not required, the terminal device A.
- the terminal device A determines that the protection level of the security protection mode of the PC5 interface communication mode is that security protection is required; when the protection level of the user plane security protection mode 2 is that security protection is not required, the user plane When the protection level of the security protection mode 1 is that security protection is not required, the terminal device A determines the security protection mode of the PC5 interface communication mode according to the user plane security policy 1 and the user plane security policy 2.
- the terminal device A determines the security protection mode of the communication mode of the PC5 interface according to the user plane security policy 1 and the user plane security policy 2. You can refer to the description in the above implementation mode, which will not be repeated here. .
- this example may include the following steps:
- the terminal device A sends a registration request to the AMF entity through the network device.
- the registration request may include the user concealed identifier (SUCI) of the terminal device A.
- the SUCI is encrypted SUPI.
- the registration request may also include at least one or a combination of the following: PC5 capability information, application identification (for example, V2X application ID), DNN, S-NSSAI, and so on.
- application identification for example, V2X application ID
- DNN for example, DNN
- S-NSSAI S-NSSAI
- the PC5 capability information is used to notify the AMF entity that this registration process is related to the PC5 interface, and the AMF entity needs to determine the user plane security policy during the registration process.
- S502 Perform a two-way authentication process between the terminal device A and the network.
- This process is an existing technology, and the network participating network elements include AMF entities, AUSF entities and UDM entities.
- the AMF entity can obtain SUPI according to SUCI during the authentication process.
- the AMF entity can determine the user plane security policy through the following two implementation methods.
- the AMF entity sends a request message to the UDM entity.
- the request message is used to request the user plane security policy of the terminal device A.
- the request message includes at least one of SUPI, application ID, DNN and S-NSSAI.
- the UDM entity After receiving the request message, the UDM entity determines a user plane security policy according to the parameters included in the request message.
- the UDM entity may use a traditional method to determine the user plane security policy subscribed by the terminal device A.
- the UDM entity may obtain the application security policy from the application server by sending a request, and determine the user plane security policy according to the application security policy. Specifically, the UDM entity may determine that the user plane security policy is the same as the application security policy; or determine the final user plane security policy according to the application security policy and the signed user plane security policy.
- the process of determining the final user plane security policy by the UDM entity can refer to the process of determining the user plane security policy by the SMF entity in the example shown in FIG. 4, which will not be repeated here.
- the UDM entity when the UDM entity requests the application security policy from the application server, the UDM entity may directly communicate and interact with the application server, or the UDM entity may communicate with the application server across other network elements.
- the application server performs communication interaction, which is not limited in this application.
- the UDM entity sends a response message to the AMF entity, where the response message includes the determined user plane security policy.
- S506 The AMF entity sends a first request message to the SMF entity.
- the first request message includes at least one of SUPI, application ID, DNN and S-NSSAI.
- the SMF entity sends a second request message to the UDM entity.
- the second request message includes at least one of SUPI, application ID, DNN and S-NSSAI.
- S507b When the UDM entity searches for the user plane security policy subscribed by the terminal device in the locally stored user plane security policy according to the parameters included in the second request message. If found, send a second response message carrying the user plane security policy to the SMF entity. If it is not found, the SMF is notified through a second response message or other means.
- the UDM entity may also obtain an application security policy from an application server, and determine the user plane security policy according to the application security policy.
- an application security policy from an application server, and determine the user plane security policy according to the application security policy.
- the SMF entity receives the second response message, and when the second response message includes a user plane security policy, determines that the user plane security policy is the user plane security policy of the terminal device A;
- the SMF entity may also determine the user plane security policy based on at least one of SUPI, application ID, DNN, and S-NSSAI in the locally stored user plane security policy. Describe the user plane security policy of terminal device A.
- the SMF entity may also obtain the application security policy from the application server, and determine the final user plane security policy according to the application security policy.
- the specific process may be Refer to the description of the SMF entity determining the user plane security policy in the embodiment shown in FIG. 4, which will not be repeated here.
- the SMF entity sends a first response message to the AMF entity, where the first response message carries the user plane security policy determined by the SMF entity.
- the AMF entity may also obtain the application security policy from the application server, and the previously determined user plane security policy obtained from the SMF entity to determine the final user plane security policy.
- the application security policy may also obtain the application security policy from the application server, and the previously determined user plane security policy obtained from the SMF entity to determine the final user plane security policy.
- the UDM entity determining the final user plane security policy.
- S510 The AMF entity sends the user plane security policy to the network device.
- the network device sends the security protection information of the Uu interface communication mode to the terminal device A.
- the security protection information includes: the user plane security protection method, and/or the user plane security policy.
- the terminal device A determines the security protection mode of the PC5 interface communication mode according to the security protection information of the Uu interface communication mode. For the specific process, refer to the descriptions in Example 1 to Example 3, which will not be repeated here.
- the PC5 interface communication mode is used for data transmission between the terminal device A and the terminal device B, and the security protection mode 1 is used to protect the transmitted data.
- Security protection mode 1 is maintained in both terminal equipment A and terminal equipment B.
- the security protection mode 1 may be determined by the method in the above example, or determined according to an application security policy obtained locally or from an application server, which is not limited in this application.
- this example may include the following steps:
- the terminal device A determines to switch from the PC5 interface communication mode to the Uu interface communication mode.
- S602a The terminal device A sends a PDU session establishment request to the network device, where the PDU session establishment request includes security protection mode 1.
- the network device sends the PDU session establishment request to the SMF entity through the AMF entity.
- the PDU session establishment request includes security protection mode 1.
- the terminal device A may also send a NAS message carrying the security protection mode 1 to the AMF entity, and then the AMF entity sends the security protection mode 1 to the SMF entity.
- the SMF entity determines the user plane security policy. For the specific process, refer to S203 and S204 in the figure, which will not be repeated here. In another implementation manner, the SMF entity may also obtain the application security policy from the application server, and determine the user plane security policy according to the application security policy. For the specific process, refer to the SMF entity in the example shown in FIG. 2 Determining the description of the user plane security policy will not be repeated here.
- the SMF entity sends a user plane security policy and security protection mode 1 to the network device.
- the network device determines the security protection mode 2 of the Uu interface communication mode according to the user plane security policy and the security protection mode 1.
- the network device can determine the security protection mode 2 in multiple implementation modes.
- the network device directly determines the security protection mode 2 according to the user plane security policy and the security protection mode 1 according to the strongest principle, and ensures that the protection level of the security protection mode 2 is not The protection level is lower than the user plane security policy and the security protection mode 1.
- the network device first determines the user plane security protection mode according to the user plane security policy; then determines the security protection mode according to the determined user plane security protection mode and the security protection mode 1. 2. Wherein, the protection level of the security protection mode 2 is not lower than the protection levels of the user plane security protection mode and the security protection mode 1.
- the steps of determining and sending the above-mentioned user plane security policy are optional.
- the network device After obtaining the security protection mode 1 from the terminal device A, the network device uses the security protection mode 1 as the security protection mode 2. .
- the network device activates the user plane security mechanism, and performs user plane protection on the subsequently transmitted user plane data of the terminal device A according to the determined security protection mode 2.
- the PC5 interface communication mode is used for data transmission between the terminal device A and the terminal device B, and the security protection mode 1 is used to protect the transmitted data.
- Security protection mode 1 is maintained in both terminal equipment A and terminal equipment B.
- the specific process can refer to the embodiment shown in Figure 6. The difference is that after the terminal device A can send security protection mode 1 to the network device through S602a, the network device carries all the information when sending the PDU session establishment request to the SMF entity.
- the security protection mode 1 is optional.
- the SMF entity sending security protection mode 1 to the network device in S604 is also optional.
- the security protection mode 2 can be determined by the following implementation:
- the network device determines that the security protection mode 2 is the same as the security protection mode 1.
- the network device determines that the protection level of the security protection mode 2 is higher than the protection level of the security protection mode 1.
- the terminal device determines the security protection mode 2 according to the user plane security policy obtained in S604 and the security protection mode 1. Wherein, the protection level of the security protection mode 2 is not lower than the protection level of the user plane security policy and the security protection mode 1.
- the PC5 interface communication mode is used for data transmission between the terminal device A and the terminal device B, and the security protection mode 1 is used to protect the transmitted data.
- Security protection mode 1 is maintained in both terminal equipment A and terminal equipment B.
- the difference is: when the terminal device A executes S602a, it does not carry the security protection mode 1 in the PDU session establishment request, but pre-sets the security protection mode 1 sent to the application server; the SMF entity may obtain the security protection mode 1 from the application server, and when the SMF entity executes S604, the user plane security policy and the security protection mode 1 may be sent simultaneously To the network equipment.
- the terminal device A when the terminal device A sends the security protection mode 1 to the application server, at least one of the following can be sent at the same time: the UE’s operator network identity, and the general public subscription identity (Generic Public Subscription Identifier, GPSI) , Application ID, UE application ID, UE's operator network ID, PC5 link identification.
- the application server sends the aforementioned parameters and the security protection mode 1 to the SMF entity at the same time.
- the terminal device A may send at least one of the application ID, the UE application ID, the UE's operator network ID and the PC5 link identifier to the SMF entity, for example, the above parameters are carried in the PDU session establishment request in.
- the SMF entity receives at least one of the application ID, the UE application ID, the UE’s operator network ID and the PC5 link identifier sent by the terminal equipment, the SMF entity may determine the Security protection method 1.
- the terminal device A may also send the application security policy when sending the security protection mode 1.
- the network device determines the security protection mode 2
- it may also refer to the application security policy, where the protection level of the security protection mode 2 is not lower than the application security policy.
- the security protection mode 1 in the example can be replaced with the application security policy.
- terminal device A and terminal device B each adopt Uu interface communication mode for data transmission, wherein terminal device A saves the security protection information 1 of Uu interface communication mode, and terminal device B saves the security protection of Uu interface communication mode Information 2.
- the security protection information 1 includes a security protection method 1 and/or a user-plane security policy 1;
- the security protection information 2 includes a security protection method 2 and/or a user-plane security policy 2.
- this example may include the following steps:
- S701 The terminal device A and the terminal device determine to switch from the Uu interface communication mode to the PC5 interface communication mode.
- Terminal device A sends security protection information 1 to terminal device B.
- the terminal device A may broadcast the security protection information 1.
- the terminal device A may determine that the terminal device B is the peer device when the terminal device B adopts the PC5 interface communication mode through traditional methods such as device direct discovery.
- the terminal device A may determine that the terminal device B is the peer device when the PC5 interface communication mode is adopted by the user input information.
- the terminal device B determines the security protection mode a of the PC5 interface communication mode according to the received security protection information 1 and the locally stored security protection information 2. It should be noted that the protection level of the security protection method a is not lower than the protection levels of the security protection information 1 and the security protection information 2. For the specific determination process, please refer to the description in the above embodiment and example 3, which will not be repeated here.
- the terminal device B sends the security protection mode a to the terminal device A, and uses the security protection mode a to protect the data transmitted between the terminal device A and the terminal device B.
- the network device or terminal device can determine the final security protection method according to the user plane security policy or application security policy, without considering the security protection methods of different communication methods. In this way, this method It can better refer to the safety protection capabilities of the equipment.
- the network device or the terminal device can determine whether to use the user plane security policy or the application security policy to determine the final security protection method according to the priority. For example, if there is an application security policy, only the application security policy is used as the basis for judgment; or if there is a user-plane security policy, only the user-plane security policy is used as the basis for judgment.
- the terminal device A and the terminal device B each adopt the PC5 interface communication mode for data transmission, wherein the terminal device A saves the security protection information 1 and the terminal device B saves the security protection information 2.
- the security protection information 1 includes a security protection method 1 and/or a user-plane security policy 1;
- the security protection information 2 includes a security protection method 2 and/or a user-plane security policy 2.
- the security protection information 1 and 2 can be preset, or the application or service is only for the terminal, or obtained through other methods, without limitation.
- the terminal device A may also store the service identification 1, where the security protection information 1 is related to the service identification 1.
- the terminal device A may also save the application identification 1, where the security protection information 1 is related to the application identification 1.
- the terminal device B may also store the service identification 1, where the security protection information 2 is related to the service identification 1.
- the terminal device A may also save the application identification 1, where the security protection information 2 is related to the application identification 1.
- This example can include the following steps:
- Terminal device A sends security protection information 1 to terminal device B.
- the terminal device A may broadcast the security protection information 1.
- the terminal device A may determine that the terminal device B is the peer device when the terminal device B adopts the PC5 interface communication mode through traditional methods such as device direct discovery.
- the terminal device A may determine that the terminal device B is the peer device when the PC5 interface communication mode is adopted by the user input information.
- terminal device A also sends service identification 1;
- the terminal device A also sends an application identification 1;
- the terminal device B determines the security protection mode a of the PC5 interface communication mode according to the received security protection information 1 and the locally stored security protection information 2. It should be noted that the protection level of the security protection method a is not lower than the protection levels of the security protection information 1 and the security protection information 2. For the specific method of determining the security protection mode of the PC5 interface according to the security protection information 1 and the locally stored security protection information 2, please refer to the description in the above embodiment and example 3, which will not be repeated here.
- the terminal device B also accepts the service identifier 1 sent by the terminal device A, and determines the security protection information 2 for local protection according to the service identifier 1.
- the terminal device B also accepts the application identifier 1 sent by the terminal device A, and determines the security protection information 2 for local protection according to the application identifier 1.
- the terminal device B sends the security protection method a to the terminal device A, and uses the security protection method a to protect the data transmitted between the terminal device A and the terminal device B.
- the terminal device B also sends a service identification 1;
- the terminal device B also sends the application identifier 1;
- the terminal device B also sends security protection information 1 and/or security protection information 2.
- the determination of the security protection mode between the terminal devices is not limited to the switching scenario of the two access modes.
- the two terminals can also negotiate with basically locally stored security protection information.
- the determination of the security protection mode between terminal devices can also be based on the security protection information of one of the terminals.
- terminal device A sends security protection information 1
- terminal device B determines the security protection methods of both parties according to security protection information 1.
- the terminal device A sends a communication request
- the terminal device B determines the security protection mode of both parties according to the security protection information 2.
- terminal device A sends a communication request
- terminal device B sends security protection information 2 to terminal device A.
- the terminal device A determines the security protection mode of both parties according to the security protection information 2. No restrictions.
- the terminal device B sends the security protection information 1 to the terminal device A, so that the terminal device A can verify the security protection information 1 sent before and the slave terminal Whether the security protection information 2 received by device B is consistent. If they are inconsistent, optionally send a rejection message to the terminal device B; or interrupt the communication without restrictions. It is also possible that the terminal device B sends the security protection information 2 to the terminal device A, so that the terminal device A determines the content of the security protection information 2.
- the security protection information 1 and/or the security protection information 2 sent by the terminal device B need to support integrity protection to prevent modification by other attackers.
- the service identification and/or application identification described in Embodiment 12 are also applicable to other embodiments of this application.
- the sent security protection information is related to the service ID or application ID, so the negotiated protection method is also consistent with the service ID or application ID.
- the negotiated protection mode is also applicable to the session granularity, bearer granularity, flow granularity, and slice granularity between terminals.
- the structure of the terminal device A or the terminal device B in Embodiment 12 may refer to the structure shown in FIG. 8 or FIG. 9.
- the method shown in Embodiment 12 can be performed through the structure shown in FIG. 8 or FIG. 9.
- an embodiment of the present application also provides a device for determining a security protection mode.
- the device can be applied to a terminal device in a communication system as shown in FIG. 1, and can implement the security protection mode in the above embodiment. Determine the method.
- the structure of the device includes a communication unit 801 and a processing unit 802. The function of each unit is described below by taking the terminal device applied by the apparatus as the first terminal device as an example.
- the communication unit 801 is used to receive and send data
- the processing unit 802 is configured to perform the following steps through the communication unit 801:
- the security protection information includes a first security protection mode, and/or a first security policy
- the first security protection mode corresponds to the first communication mode, and is used for Protecting data transmitted when the first terminal device adopts the first communication mode, where the first security policy is a security policy of the first communication mode of the first terminal device;
- a second security protection mode is determined.
- the second security protection mode corresponds to the second communication mode and is used to protect data transmitted when the first terminal device adopts the second communication mode.
- the processing unit 802 when determining the second security protection mode according to the security protection information, specifically Used for:
- a second security policy where the second security policy is the security policy of the second communication mode of the first terminal device; determine the first security policy according to the second security policy and the first security protection mode Two security protection modes, wherein the protection level of the second security protection mode is not lower than the protection level of the second security policy, and is not lower than the protection level of the first security protection mode.
- the processing unit 802 is specifically configured to: when determining the second security protection mode according to the second security policy and the first security protection mode:
- the protection level of the first security protection mode is that security protection is not required, and the protection level of the second security policy is priority security protection, the protection level of the second security protection mode is determined according to its own security protection capability;
- the protection level of the first security protection mode is that security protection is not required
- the protection level of the second security policy is that security protection is not required
- the processing unit 802 when determining the second security protection mode according to the security protection information, specifically uses in:
- the second security policy is the security policy of the second communication mode; determining the second security protection mode according to the second security policy and the first security policy, wherein, the protection level of the second security protection mode is not lower than the protection level of the second security policy, and is not lower than the protection level of the first security policy.
- the processing unit 802 when determining the second security protection mode according to the second security policy and the first security policy, is specifically configured to:
- the protection level of the second security protection mode is determined according to the protection level of the first security policy.
- the processing unit 802 when determining the second security protection mode according to the first security policy, is specifically configured to:
- the protection level of the first security policy is priority security protection
- the protection level of the first security policy is that security protection is not required
- it is determined that the protection level of the second security protection mode is that security protection is not required.
- processing unit 802 is further configured to:
- the communication unit 801 sends the second security protection mode to the second terminal device, and receives the second security protection mode according to the second security protection mode and the third security protection mode.
- the fourth security protection method determined by the method; or
- the third security protection mode sent by the second terminal device is received through the communication unit 801, and the fourth security protection mode is determined according to the second security protection mode and the third security protection mode. Protection method
- the protection level of the fourth security protection mode is not lower than the protection level of the second security protection mode, and is not lower than the protection level of the third security protection mode; the third security protection mode is used for Protect the data transmitted when the second terminal device adopts the second communication method, and the fourth security protection method is used to protect the data transmission when the second terminal device adopts the second communication method for data transmission. The data.
- the processing unit 802 is specifically configured to: when determining the fourth security protection mode according to the second security protection mode and the third security protection mode:
- the second security protection manner is specifically used to protect the first terminal device and the second terminal device.
- the data transmitted during data transmission in the second communication mode; the processing unit 802, when determining the second security protection mode according to the security protection information, is specifically configured to:
- the protection level of the second security protection mode is not lower than the protection level of the first security policy, and is not lower than the protection level of the third security policy; the third security policy is the second security policy.
- the protection level of the first communication mode of the terminal device is not lower than the protection level of the first security policy, and is not lower than the protection level of the third security policy; the third security policy is the second security policy.
- the processing unit 802 when determining the second security protection mode according to the first security policy and the third security policy, is specifically configured to:
- the protection level of the first security policy and the third security policy are both priority security protection, or when the protection level of one of the first security policy and the third security policy is priority security protection If the protection level of the other item is that no security protection is required, the protection level of the second security protection mode is determined according to its own security protection capability.
- the processing unit 802 is specifically configured to: when acquiring the security protection information of the first communication mode:
- the processing unit 802 is specifically configured to determine the second security protection mode according to the security protection information :
- the security protection information is sent to the application server through the communication unit 801, and the request message is sent to the network device; the second security protection method is received from the network device through the communication unit 801, the second security protection The manner is determined by the network device according to the security protection information obtained from the application server.
- the second security protection mode is the same as the first security protection mode.
- the protection level of the second security protection mode is higher than the protection level of the first security protection mode
- the second security protection mode is determined by the network device according to the first security protection mode and/or a second security policy, wherein the second security policy is the first terminal obtained by the network device
- the device adopts the protection level of the second communication mode
- the second security protection mode is determined by the network device according to the first security protection mode and a third security protection mode, wherein the third security protection mode is the network device according to the second security policy definite.
- the protection level of the second security protection mode is security protection required
- the protection level of the second security policy is priority security protection, and the protection level of the first security protection mode is security protection required, the protection level of the second security protection mode is security protection required;
- the protection level of the second security policy is priority security protection
- the protection level of the first security protection mode is that security protection is not required
- the protection level of the second security protection mode is specified by the network device
- the protection level of the second security policy is that security protection is not required, and the protection level of the first security protection mode is that security protection is required, the protection level of the second security protection mode is that security protection is required;
- the protection level of the second security policy is that security protection is not required
- the protection level of the first security protection mode is that security protection is not required
- the protection level of the second security protection mode is that security protection is not required
- the protection level of the third security protection mode is security protection required
- the protection level of the second security protection mode is security protection required
- the protection level of the third security protection mode is that security protection is not required, and the protection level of the first security protection mode is that security protection is required, the protection level of the second security protection mode is that security protection is required;
- the protection level of the third security protection mode is that security protection is not required
- the protection level of the first security protection mode is that security protection is not required
- the protection level of the second security protection mode is that security protection is not required
- the second security protection mode when the second communication mode is the PC5 interface communication mode, the second security protection mode is specifically used to protect the communication between the first terminal device and the second terminal device.
- the data transmitted during data transmission in the second communication mode; the processing unit 802, when determining the second security protection mode according to the security protection information, is specifically used to:
- the communication unit 801 sends the first security protection method to the second terminal device, and receives the second security protection method from the second terminal device. Protection mode; wherein, the second security protection mode is determined by the second terminal device according to the first security protection mode and the third security protection mode, and the protection level of the second security protection mode is not lower than all The protection level of the first security protection mode is not lower than the protection level of the third security protection mode; or
- a third security protection method is received from the second terminal device through the communication unit 801, and according to the first security protection method and the third security protection method
- the security protection mode determines the second security protection mode; wherein the protection level of the second security protection mode is not lower than the protection level of the first security protection mode, and is not lower than the third security protection mode Protection level; or
- the communication unit 801 sends the first security protection method and the first security policy to the second terminal device.
- Strategy receiving the second security protection mode from the second terminal device through the communication unit 801; wherein, the second security protection mode is the second terminal device according to the first security protection mode, The first security policy, the third security protection mode, and the second security policy are determined; when the first security protection mode is the same as the third security protection mode, the second security protection mode is the same as the first security protection mode. 1.
- the security protection mode is the same; when the first security protection mode is different from the third security protection mode, the protection level of the second security protection mode is not lower than the first security protection mode and the first security protection mode. 2.
- the protection level of the security protection method is not lower than the protection levels of the first security policy and the second security policy; or
- the security protection information includes the first security protection mode and the first security policy
- the first security protection mode, the first security policy, the third security protection mode, and the second security policy determine the second security protection mode; wherein, when the first security protection mode is When the third security protection mode is the same, the second security protection mode is the same as the first security protection mode; when the first security protection mode is different from the third security protection mode, the first security protection mode 2.
- the protection level of the security protection mode is not lower than the protection levels of the first security protection mode and the second security protection mode, and is not lower than the protection levels of the first security policy and the second security policy;
- the third security protection method is used to protect data transmitted when the second terminal device adopts the first communication method
- the second security policy is the security of the first communication method of the second terminal device Strategy.
- the processing unit 802 when determining the second security protection manner according to the first security protection manner and the third security protection manner, is specifically configured to:
- the protection level of the third security protection mode is that security protection is required
- the protection level of the first security protection mode is that security protection is required
- the protection level of the third security protection mode is that security protection is required, and the protection level of the first security protection mode is that security protection is not required, the protection level of the second security protection mode is determined by a network device;
- the protection level of the third security protection mode is that security protection is not required, and the protection level of the first security protection mode is that security protection is required, determining that the protection level of the second security protection mode is that security protection is required;
- the protection level of the third security protection mode is that security protection is not required
- the protection level of the first security protection mode is that security protection is not required
- the processing unit 802 determines the first security protection mode, the first security policy, the third security protection mode, and the second security policy according to the In the second security protection mode, it is specifically used for:
- the second security protection mode is determined according to the first security policy and the second security policy.
- the processing unit 802 determines all the information based on the first security protection mode, the first security policy, the third security protection mode, and the second security policy.
- the second security protection method it is specifically used for:
- the protection level of the third security protection mode is that security protection is required
- the protection level of the first security protection mode is that security protection is required
- the protection level of the third security protection mode is that security protection is required, and the protection level of the first security protection mode is that security protection is not required, the protection level of the second security protection mode is determined by a network device;
- the protection level of the third security protection mode is that security protection is not required, and the protection level of the first security protection mode is that security protection is required, determining that the protection level of the second security protection mode is that security protection is required;
- the protection level of the third security protection mode is that security protection is not required
- the protection level of the first security protection mode is that security protection is not required
- the processing unit 802 is specifically configured to: when determining the second security protection mode according to the first security policy and the second security policy:
- the protection level of at least one of the first security policy and the second security policy is that security protection is required, determining that the protection level of the second security protection mode is security protection;
- the protection level of the first security policy and the second security policy are both priority security protection, or when the protection level of one of the first security policy and the third security policy is priority security protection If the protection level of the other item is that no security protection is required, the protection level of the second security protection mode is determined according to its own security protection capability.
- the above security policy includes: confidentiality protection requirements, and/or integrity protection requirements; each of the above security protection methods includes: confidentiality protection requirements, and/or integrity protection requirements.
- the embodiment of the present application provides an apparatus for determining a security protection mode.
- a terminal device can determine the security protection mode of the second communication mode according to the security protection information of the first communication mode. In this way, when the terminal device is switching from the first communication mode to the second communication mode, it can directly use the security protection mode of the second communication mode to protect the transmitted data, thereby ensuring all the data after the communication mode is switched.
- the data security of the terminal equipment Further, the protection level of the security protection mode of the second communication mode determined by the terminal device is not lower than the protection level of the security protection information of the first communication mode. In this way, the protection level of the terminal device after the communication mode is switched can be further guaranteed. Data security.
- each function in each embodiment of this application can be integrated into one processing unit, or it can exist alone physically, or two or more units can be integrated into one unit.
- the above-mentioned integrated unit can be implemented in the form of hardware or software functional unit.
- the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium.
- the technical solution of this application essentially or the part that contributes to the existing technology or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium , Including a number of instructions to make a computer device (which may be a personal computer, a server, or a network device, etc.) or a processor (processor) execute all or part of the steps of the method described in each embodiment of the present application.
- the aforementioned storage media include: U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk and other media that can store program code .
- an embodiment of the present application also provides a terminal device, which can be applied to the communication system shown in FIG. 1 and has the function of the security protection method determining device shown in FIG. 8, and can The method for determining the security protection mode in the above embodiment is implemented.
- the terminal device 900 includes: a transceiver 901 and a processor 902.
- the terminal device 900 further includes a memory 903.
- the transceiver 901, the processor 902, and the memory 903 are connected to each other.
- the transceiver 901, the processor 902, and the memory 903 are connected to each other through a bus 904.
- the bus 904 may be a peripheral component interconnect standard (PCI) bus or an extended industry standard architecture (EISA) bus, etc.
- PCI peripheral component interconnect standard
- EISA extended industry standard architecture
- the bus can be divided into address bus, data bus, control bus, etc. For ease of representation, only one thick line is used in FIG. 9, but it does not mean that there is only one bus or one type of bus.
- the transceiver 901 is used to receive and send signals to realize communication with other devices in the communication system.
- the transceiver 901 may be implemented by a radio frequency device and an antenna.
- the processor 902 is configured to implement the function of the terminal device in the method for determining the security protection mode in the above figures. For details, reference may be made to the description in the above embodiment, which will not be repeated here.
- the processor 902 may be a central processing unit (CPU), a network processor (NP), a combination of a CPU and an NP, or the like.
- the processor 902 may further include a hardware chip.
- the aforementioned hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or a combination thereof.
- the above-mentioned PLD may be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof.
- CPLD complex programmable logic device
- FPGA field-programmable gate array
- GAL generic array logic
- the memory 903 is used to store program instructions and the like.
- the program instructions may include program code, and the program code includes computer operation instructions.
- the memory 903 may include a random access memory (RAM), and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory.
- the processor 902 executes the program instructions stored in the memory 903 to realize the aforementioned functions, thereby realizing the method for determining the security protection mode provided in the aforementioned embodiment.
- the embodiments of the present application also provide a computer program, which when the computer program runs on a computer, causes the computer to execute the method for determining the security protection mode provided by the above embodiments.
- the embodiments of the present application also provide a computer storage medium in which a computer program is stored.
- the computer program executes the method for determining the security protection mode provided by the above embodiment .
- an embodiment of the present application also provides a chip, which is used to read a computer program stored in a memory to implement the method for determining a security protection mode provided by the above embodiment.
- the embodiments of the present application provide a chip system that includes a processor and is used to support a computer device to implement the method for determining the security protection mode provided in the above embodiments.
- the chip system further includes a memory, and the memory is used to store necessary programs and data of the computer device.
- the chip system can be composed of chips, or include chips and other discrete devices.
- this application provides a method and device for determining a security protection mode.
- the terminal device can determine the security protection mode of the second communication mode according to the security protection information of the first communication mode. In this way, when the terminal device is switching from the first communication mode to the second communication mode, it can directly use the security protection mode of the second communication mode to protect the transmitted data, thereby ensuring all the data after the communication mode is switched. The data security of the terminal equipment.
- the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, this application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
- a computer-usable storage media including but not limited to disk storage, CD-ROM, optical storage, etc.
- These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing equipment to work in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including the instruction device.
- the device implements the functions specified in one process or multiple processes in the flowchart and/or one block or multiple blocks in the block diagram.
- These computer program instructions can also be loaded on a computer or other programmable data processing equipment, so that a series of operation steps are executed on the computer or other programmable equipment to produce computer-implemented processing, so as to execute on the computer or other programmable equipment.
- the instructions provide steps for implementing functions specified in a flow or multiple flows in the flowchart and/or a block or multiple blocks in the block diagram.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
- Telephone Function (AREA)
Abstract
Description
Claims (16)
- 一种安全保护方式确定方法,其特征在于,包括:第一终端设备获取第一通信方式的安全保护信息,其中,所述安全保护信息包含第一安全保护方式,和/或,第一安全策略;所述第一安全保护方式对应所述第一通信方式,用于保护所述第一终端设备采用所述第一通信方式时传输的数据,所述第一安全策略为所述第一终端设备的所述第一通信方式的安全策略;所述第一终端设备根据所述安全保护信息,确定第二安全保护方式,所述第二安全保护方式对应第二通信方式,用于保护所述第一终端设备采用第二通信方式时传输的数据。
- 如权利要求1所述的方法,其特征在于,当所述安全保护信息为所述第一安全保护方式时,所述第一终端设备根据所述安全保护信息,确定所述第二安全保护方式,包括:所述第一终端设备确定所述第二安全保护方式与所述第一安全保护方式相同;或者所述第一终端设备获取第二安全策略,所述第二安全策略为所述第一终端设备的所述第二通信方式的安全策略;所述第一终端设备根据所述第二安全策略、所述第一安全保护方式,确定所述第二安全保护方式,其中,所述第二安全保护方式的保护等级不低于所述第二安全策略的保护等级,且不低于所述第一安全保护方式的保护等级。
- 如权利要求1所述的方法,其特征在于,当所述安全保护信息为所述第一安全策略时,所述第一终端设备根据所述安全保护信息,确定所述第二安全保护方式,包括:所述第一终端设备根据所述第一安全策略,确定所述第二安全保护方式;或者所述第一终端设备获取第二安全策略,所述第二安全策略为所述第一终端设备的所述第二通信方式的安全策略;所述第一终端设备根据所述第二安全策略、所述第一安全策略,确定所述第二安全保护方式,其中,所述第二安全保护方式的保护等级不低于所述第二安全策略的保护等级,且不低于所述第一安全策略的保护等级。
- 如权利要求1-3任一项所述的方法,其特征在于,在所述第一终端设备确定第二安全保护方式之后,所述方法还包括:所述第一终端设备向第二终端设备发送所述第二安全保护方式,并接收所述第二终端设备根据所述第二安全保护方式和第三安全保护方式确定的第四安全保护方式;或者所述第一终端设备接收第二终端设备发送的第三安全保护方式,并根据所述第二安全保护方式和所述第三安全保护方式,确定第四安全保护方式;其中,所述第四安全保护方式的保护等级不低于所述第二安全保护方式的保护等级,且不低于所述第三安全保护方式的保护等级;所述第三安全保护方式用于保护所述第二终端设备采用第二通信方式时传输的数据,所述第四安全保护方式用于保护所述第一终端设备与所述第二终端设备之间采用所述第二通信方式进行数据传输时传输的数据。
- 如权利要求1所述的方法,其特征在于,所述第一终端设备获取所述第一通信方式的所述安全保护信息,包括:所述第一终端设备确定从第一通信方式切换到第二通信方式时,获取所述第一通信方式的所述安全保护信息。
- 如权利要求5所述的方法,其特征在于,当所述第二通信方式为Uu接口通信方式时,所述第一终端设备根据所述安全保护信息,确定所述第二安全保护方式,包括:所述第一终端设备向网络设备发送所述安全保护信息;并从所述网络设备接收所述第二安全保护方式,所述第二安全保护方式为所述网络设备根据所述安全保护信息确定的;或者所述第一终端设备向应用服务器发送所述安全保护信息,以及向网络设备发送请求消息;所述第一终端设备从所述网络设备接收所述第二安全保护方式,所述第二安全保护方式为所述网络设备根据从所述应用服务器获取的所述安全保护信息确定的。
- 如权利要求1或5所述的方法,其特征在于,当所述第二通信方式为PC5接口通信方式时,所述第二安全保护方式具体用于保护所述第一终端设备与第二终端设备之间采用所述第二通信方式进行数据传输时传输的数据;所述第一终端设备根据所述安全保护信息,确定所述第二安全保护方式,包括:当所述安全保护信息包含所述第一安全保护方式时,所述第一终端设备向第二终端设备发送所述第一安全保护方式,并从所述第二终端设备接收所述第二安全保护方式;其中,所述第二安全保护方式为所述第二终端设备根据所述第一安全保护方式和第三安全保护方式确定的,所述第二安全保护方式的保护等级不低于所述第一安全保护方式的保护等级,且不低于所述第三安全保护方式的保护等级;或者当所述安全保护信息包含所述第一安全保护方式时,所述第一终端设备从所述第二终端设备接收第三安全保护方式,并根据所述第一安全保护方式和所述第三安全保护方式,确定所述第二安全保护方式;其中,所述第二安全保护方式的保护等级不低于所述第一安全保护方式的保护等级,且不低于所述第三安全保护方式的保护等级;或者当所述安全保护信息包含所述第一安全保护方式和所述第一安全策略时,所述第一终端设备向所述第二终端设备发送所述第一安全保护方式和所述第一安全策略;所述第一终端设备从所述第二终端设备接收所述第二安全保护方式;其中,所述第二安全保护方式为所述第二终端设备根据所述第一安全保护方式、所述第一安全策略,第三安全保护方式,以及第二安全策略确定的;当所述第一安全保护方式与所述第三安全保护方式相同时,所述第二安全保护方式与所述第一安全保护方式相同;当所述第一安全保护方式与所述第三安全保护方式不相同时,所述第二安全保护方式的保护等级不低于所述第一安全保护方式和所述第二安全保护方式的保护等级,且不低于所述第一安全策略和所述第二安全策略的保护等级;或者当所述安全保护信息包含所述第一安全保护方式和所述第一安全策略时,所述第一终端设备从所述第二终端设备接收第三安全保护方式和第二安全策略;所述第一终端设备根据所述第一安全保护方式、所述第一安全策略、所述第三安全保护方式,和所述第二安全策略,确定所述第二安全保护方式;其中,当所述第一安全保护方式与所述第三安全保护方式相同时,所述第二安全保护方式与所述第一安全保护方式相同;当所述第一安全保护方式与所述第三安全保护方式不相同时,所述第二安全保护方式的保护等级不低于所述第一安全保护方式和所述第二安全保护方式的保护等级,且不低于所述第一安全策略和所述第二安全策略的保护等级;其中,所述第三安全保护方式用于保护所述第二终端设备采用第一通信方式时传输的数据,所述第二安全策略为所述第二终端设备的所述第一通信方式的安全策略。
- 如权利要求1-7任一项所述的方法,其特征在于,所述第一安全策略包含:机密性保护需求,和/或,完整性保护需求;所述第一安全保护方式、所述第二安全保护方式均包含:机密性保护需求,和/或,完整性保护需求。
- 一种安全保护方式确定装置,所述装置应用于第一终端设备中,其特征在于,包括:收发器,用于接收和发送数据;处理器,用于通过所述收发器执行以下步骤:获取第一通信方式的安全保护信息,其中,所述安全保护信息包含第一安全保护方式,和/或,第一安全策略;所述第一安全保护方式对应所述第一通信方式,用于保护所述第一终端设备采用所述第一通信方式时传输的数据,所述第一安全策略为所述第一终端设备的所述第一通信方式的安全策略;根据所述安全保护信息,确定第二安全保护方式,所述第二安全保护方式对应第二通信方式,用于保护所述第一终端设备采用第二通信方式时传输的数据。
- 如权利要求9所述的装置,其特征在于,当所述安全保护信息为所述第一安全保护方式时,所述处理器在根据所述安全保护信息,确定所述第二安全保护方式时,具体用于:确定所述第二安全保护方式与所述第一安全保护方式相同;或者获取第二安全策略,所述第二安全策略为所述第一终端设备的所述第二通信方式的安全策略;根据所述第二安全策略、所述第一安全保护方式,确定所述第二安全保护方式,其中,所述第二安全保护方式的保护等级不低于所述第二安全策略的保护等级,且不低于所述第一安全保护方式的保护等级。
- 如权利要求9所述的装置,其特征在于,当所述安全保护信息为所述第一安全策略时,所述处理器在根据所述安全保护信息,确定所述第二安全保护方式时,具体用于:根据所述第一安全策略,确定所述第二安全保护方式;或者获取第二安全策略,所述第二安全策略为所述第一终端设备的所述第二通信方式的安全策略;所述第一终端设备根据所述第二安全策略、所述第一安全策略,确定所述第二安全保护方式,其中,所述第二安全保护方式的保护等级不低于所述第二安全策略的保护等级,且不低于所述第一安全策略的保护等级。
- 如权利要求9-11任一项所述的装置,其特征在于,所述处理器还用于:在确定第二安全保护方式之后,通过所述收发器向第二终端设备发送所述第二安全保护方式,并通过所述收发器接收所述第二终端设备根据所述第二安全保护方式和第三安全保护方式确定的第四安全保护方式;或者在确定第二安全保护方式之后,通过所述收发器接收第二终端设备发送的第三安全保护方式,并根据所述第二安全保护方式和所述第三安全保护方式,确定第四安全保护方式;其中,所述第四安全保护方式的保护等级不低于所述第二安全保护方式的保护等级,且不低于所述第三安全保护方式的保护等级;所述第三安全保护方式用于保护所述第二终端设备采用第二通信方式时传输的数据,所述第四安全保护方式用于保护所述第一终端设备与所述第二终端设备之间采用所述第二通信方式进行数据传输时传输的数据。
- 如权利要求9所述的装置,其特征在于,所述处理器在获取所述第一通信方式的所述安全保护信息时,具体用于:确定从第一通信方式切换到第二通信方式时,获取所述第一通信方式的所述安全保护 信息。
- 如权利要求13所述的装置,其特征在于,当所述第二通信方式为Uu接口通信方式时,所述处理器在根据所述安全保护信息,确定所述第二安全保护方式时,具体用于:通过所述收发器向网络设备发送所述安全保护信息;并通过所述收发器从所述网络设备接收所述第二安全保护方式,所述第二安全保护方式为所述网络设备根据所述安全保护信息确定的;或者通过所述收发器向应用服务器发送所述安全保护信息,以及向网络设备发送请求消息;通过所述收发器从所述网络设备接收所述第二安全保护方式,所述第二安全保护方式为所述网络设备根据从所述应用服务器获取的所述安全保护信息确定的。
- 如权利要求9或13所述的装置,其特征在于,当所述第二通信方式为PC5接口通信方式时,所述第二安全保护方式具体用于保护所述第一终端设备与第二终端设备之间采用所述第二通信方式进行数据传输时传输的数据;所述处理器在根据所述安全保护信息,确定所述第二安全保护方式时,具体用于:当所述安全保护信息包含所述第一安全保护方式时,通过所述收发器向第二终端设备发送所述第一安全保护方式,并从所述第二终端设备接收所述第二安全保护方式;其中,所述第二安全保护方式为所述第二终端设备根据所述第一安全保护方式和第三安全保护方式确定的,所述第二安全保护方式的保护等级不低于所述第一安全保护方式的保护等级,且不低于所述第三安全保护方式的保护等级;或者当所述安全保护信息包含所述第一安全保护方式时,通过所述收发器从所述第二终端设备接收第三安全保护方式,并根据所述第一安全保护方式和所述第三安全保护方式,确定所述第二安全保护方式;其中,所述第二安全保护方式的保护等级不低于所述第一安全保护方式的保护等级,且不低于所述第三安全保护方式的保护等级;或者当所述安全保护信息包含所述第一安全保护方式和所述第一安全策略时,通过所述收发器向所述第二终端设备发送所述第一安全保护方式和所述第一安全策略;通过所述收发器从所述第二终端设备接收所述第二安全保护方式;其中,所述第二安全保护方式为所述第二终端设备根据所述第一安全保护方式、所述第一安全策略,第三安全保护方式,以及第二安全策略确定的;当所述第一安全保护方式与所述第三安全保护方式相同时,所述第二安全保护方式与所述第一安全保护方式相同;当所述第一安全保护方式与所述第三安全保护方式不相同时,所述第二安全保护方式的保护等级不低于所述第一安全保护方式和所述第二安全保护方式的保护等级,且不低于所述第一安全策略和所述第二安全策略的保护等级;或者当所述安全保护信息包含所述第一安全保护方式和所述第一安全策略时,通过所述收发器从所述第二终端设备接收第三安全保护方式和第二安全策略;根据所述第一安全保护方式、所述第一安全策略、所述第三安全保护方式,和所述第二安全策略,确定所述第二安全保护方式;其中,当所述第一安全保护方式与所述第三安全保护方式相同时,所述第二安全保护方式与所述第一安全保护方式相同;当所述第一安全保护方式与所述第三安全保护方式不相同时,所述第二安全保护方式的保护等级不低于所述第一安全保护方式和所述第二安全保护方式的保护等级,且不低于所述第一安全策略和所述第二安全策略的保护等级;其中,所述第三安全保护方式用于保护所述第二终端设备采用第一通信方式时传输的 数据,所述第二安全策略为所述第二终端设备的所述第一通信方式的安全策略。
- 如权利要求9-15任一项所述的装置,其特征在于,所述第一安全策略包含:机密性保护需求,和/或,完整性保护需求;所述第一安全保护方式、所述第二安全保护方式均包含:机密性保护需求,和/或,完整性保护需求。
Priority Applications (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR1020227007917A KR102708129B1 (ko) | 2019-08-09 | 2020-07-05 | 보안 보호 모드 결정 방법 및 장치 |
| EP20853191.3A EP3863314B1 (en) | 2019-08-09 | 2020-07-05 | Method and apparatus for determining security protection mode |
| JP2022507845A JP7389225B2 (ja) | 2019-08-09 | 2020-07-05 | セキュリティ保護モードを決定するための方法および装置 |
| US17/346,961 US12335319B2 (en) | 2019-08-09 | 2021-06-14 | Method and apparatus for determining security protection mode |
Applications Claiming Priority (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201910736599 | 2019-08-09 | ||
| CN201910736599.8 | 2019-08-09 | ||
| CN201911088795.5A CN112351431B (zh) | 2019-08-09 | 2019-11-08 | 一种安全保护方式确定方法及装置 |
| CN201911088795.5 | 2019-11-08 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US17/346,961 Continuation US12335319B2 (en) | 2019-08-09 | 2021-06-14 | Method and apparatus for determining security protection mode |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2021027435A1 true WO2021027435A1 (zh) | 2021-02-18 |
Family
ID=74367876
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2020/100310 Ceased WO2021027435A1 (zh) | 2019-08-09 | 2020-07-05 | 一种安全保护方式确定方法及装置 |
Country Status (6)
| Country | Link |
|---|---|
| US (1) | US12335319B2 (zh) |
| EP (1) | EP3863314B1 (zh) |
| JP (1) | JP7389225B2 (zh) |
| KR (1) | KR102708129B1 (zh) |
| CN (1) | CN112351431B (zh) |
| WO (1) | WO2021027435A1 (zh) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN115885572A (zh) * | 2021-07-28 | 2023-03-31 | 北京小米移动软件有限公司 | 一种通信方法、装置、用户设备、基站、核心网设备及存储介质 |
| JP2024520916A (ja) * | 2021-05-13 | 2024-05-27 | 華為技術有限公司 | セキュリティ保護有効化方式を決定するための方法、通信方法、および通信装置 |
| EP4380294A4 (en) * | 2021-07-28 | 2024-08-21 | Beijing Xiaomi Mobile Software Co., Ltd. | Direct communication method and apparatus, user equipment, and storage medium |
Families Citing this family (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11758405B2 (en) * | 2019-11-05 | 2023-09-12 | Qualcomm Incorporated | Proximity service authorization and provisioning |
| CN115836539B (zh) * | 2020-08-14 | 2025-09-12 | 华为技术有限公司 | 通信方法、装置及系统 |
| KR102739481B1 (ko) * | 2020-09-10 | 2024-12-10 | 엘지전자 주식회사 | Prose 중계 통신에서 pc5 링크와 uu 링크의 보안 적용 정책을 합의하는 방법 및 이를 지원하는 장치 |
| CN115706998A (zh) * | 2021-08-04 | 2023-02-17 | 华为技术有限公司 | 通信方法和装置 |
| WO2023070560A1 (zh) * | 2021-10-29 | 2023-05-04 | 北京小米移动软件有限公司 | 信息传输方法、装置、通信设备和存储介质 |
| CN114286339B (zh) * | 2021-12-21 | 2024-11-12 | 中国电信股份有限公司 | 安全策略的确定方法及系统 |
| KR20240149694A (ko) * | 2023-04-06 | 2024-10-15 | 삼성전자주식회사 | 전송 계층을 고려한 페이로드 데이터 구조 정보 제공 방법 및 장치 |
| WO2024207505A1 (zh) * | 2023-04-07 | 2024-10-10 | 北京小米移动软件有限公司 | 一种通信方法、装置、设备及存储介质 |
| CN119598530B (zh) * | 2024-11-20 | 2025-11-25 | 北京中科昊芯科技有限公司 | 一种片上固件安全保护的方法、装置、设备及介质 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103297961A (zh) * | 2012-03-05 | 2013-09-11 | 上海贝尔股份有限公司 | 一种用于设备间安全通信的设备与系统 |
| CN104737570A (zh) * | 2012-10-19 | 2015-06-24 | 诺基亚技术有限公司 | 生成用于第一用户设备和第二用户设备之间的设备对设备通信的密钥的方法和设备 |
| CN109729524A (zh) * | 2017-10-31 | 2019-05-07 | 华为技术有限公司 | 一种rrc连接恢复方法及装置 |
| US20190223008A1 (en) * | 2018-01-14 | 2019-07-18 | Qualcomm Incorporated | Cellular unicast link establishment for vehicle-to-vehicle (v2v) communication |
Family Cites Families (24)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050091355A1 (en) * | 2003-10-02 | 2005-04-28 | International Business Machines Corporation | Providing a necessary level of security for computers capable of connecting to different computing environments |
| JP4812123B2 (ja) * | 2007-06-15 | 2011-11-09 | 株式会社リコー | 情報処理装置およびプログラム |
| JP5096588B2 (ja) * | 2007-10-17 | 2012-12-12 | テレフオンアクチーボラゲット エル エム エリクソン(パブル) | セキュリティ設定を決定するための方法及び構成 |
| CN102932382B (zh) * | 2011-08-08 | 2018-03-23 | 中兴通讯股份有限公司 | 安全按需供给方法及系统、业务类型获取方法 |
| EP2992696B1 (en) * | 2013-04-29 | 2018-10-03 | Hughes Network Systems, LLC | Data encryption protocols for mobile satellite communications |
| EP3213486B1 (en) * | 2014-10-30 | 2018-12-19 | Samsung Electronics Co., Ltd. | Device to device communication between user equipments |
| WO2017028901A1 (en) * | 2015-08-17 | 2017-02-23 | Telefonaktiebolaget Lm Ericsson (Publ) | Method and apparatus for direct communication key establishment |
| WO2017075410A1 (en) * | 2015-10-30 | 2017-05-04 | Convida Wireless, Llc | System and methods for achieving end-to-end security for hop-by-hop services |
| EP3393200A4 (en) * | 2016-02-04 | 2018-10-24 | Huawei Technologies Co., Ltd. | Data transmission system, method, and device |
| CN109076444B (zh) * | 2016-04-01 | 2023-02-03 | 华为技术有限公司 | 一种接入方法、装置、设备及系统 |
| EP4164271A1 (en) * | 2016-08-10 | 2023-04-12 | InterDigital Patent Holdings, Inc. | Method and apparatus for power efficient d2d communications for wearable and iot devices |
| CN108347416B (zh) * | 2017-01-24 | 2021-06-29 | 华为技术有限公司 | 一种安全保护协商方法及网元 |
| KR102304709B1 (ko) * | 2017-03-03 | 2021-09-23 | 현대자동차주식회사 | V2x 통신 메시지에 대하여 적응적 보안 레벨을 적용하는 방법 및 장치 |
| CN108990125B (zh) * | 2017-06-01 | 2020-12-22 | 华为技术有限公司 | 数据传输的方法、终端设备和网络设备 |
| CN110169160B (zh) * | 2017-09-14 | 2022-07-29 | Lg电子株式会社 | 用于在无线通信系统中执行v2x通信的方法及其设备 |
| CN109600803B (zh) * | 2017-09-30 | 2024-01-30 | 华为技术有限公司 | 一种安全保护的方法、装置和系统 |
| CN109788474A (zh) * | 2017-11-14 | 2019-05-21 | 华为技术有限公司 | 一种消息保护的方法及装置 |
| KR102436652B1 (ko) * | 2018-04-05 | 2022-08-29 | 삼성전자 주식회사 | 5g 시스템에서 차량 통신 서비스 제공 방법 |
| US20190364424A1 (en) * | 2018-05-28 | 2019-11-28 | Qualcomm Incorporated | Roll-over of identifiers and keys for unicast vehicle to vehicle communication links |
| CN111417092B (zh) * | 2019-01-04 | 2023-03-24 | 华硕电脑股份有限公司 | 支持单个一对一侧链路通信链路车联网服务的方法和设备 |
| ES3055984T3 (en) * | 2019-01-18 | 2026-02-17 | Interdigital Patent Holdings Inc | Procedures enabling v2x unicast communication over pc5 interface |
| WO2020198216A1 (en) * | 2019-03-26 | 2020-10-01 | Idac Holdings, Inc. | Methods, apparatus and systems for secured radio resource control (rrc) signaling over a pc5 interface for unicast communication |
| US11388054B2 (en) * | 2019-04-30 | 2022-07-12 | Intel Corporation | Modular I/O configurations for edge computing using disaggregated chiplets |
| KR102739592B1 (ko) * | 2020-02-17 | 2024-12-06 | 삼성전자주식회사 | V2x 통신 시스템에서 보안 정책들을 처리하기 위한 방법 및 장치 |
-
2019
- 2019-11-08 CN CN201911088795.5A patent/CN112351431B/zh active Active
-
2020
- 2020-07-05 KR KR1020227007917A patent/KR102708129B1/ko active Active
- 2020-07-05 JP JP2022507845A patent/JP7389225B2/ja active Active
- 2020-07-05 EP EP20853191.3A patent/EP3863314B1/en active Active
- 2020-07-05 WO PCT/CN2020/100310 patent/WO2021027435A1/zh not_active Ceased
-
2021
- 2021-06-14 US US17/346,961 patent/US12335319B2/en active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103297961A (zh) * | 2012-03-05 | 2013-09-11 | 上海贝尔股份有限公司 | 一种用于设备间安全通信的设备与系统 |
| CN104737570A (zh) * | 2012-10-19 | 2015-06-24 | 诺基亚技术有限公司 | 生成用于第一用户设备和第二用户设备之间的设备对设备通信的密钥的方法和设备 |
| CN109729524A (zh) * | 2017-10-31 | 2019-05-07 | 华为技术有限公司 | 一种rrc连接恢复方法及装置 |
| US20190223008A1 (en) * | 2018-01-14 | 2019-07-18 | Qualcomm Incorporated | Cellular unicast link establishment for vehicle-to-vehicle (v2v) communication |
Non-Patent Citations (3)
| Title |
|---|
| CATT: "Uu and PC5 Availabity", 3GPP DRAFT; R2-1905809_UUPC5 AVALIABILITY, vol. RAN WG2, 3 May 2019 (2019-05-03), Reno, USA, pages 1 - 3, XP051710162 * |
| LG ELECTRONICS INC: "Protection of PC5-RRC Messages", 3GPP TSG-RAN WG2 #105BIS, R2-1905052, vol. RAN WG2, 29 March 2019 (2019-03-29), Xian, China, pages 1 - 2, XP051694238 * |
| See also references of EP3863314A4 * |
Cited By (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2024520916A (ja) * | 2021-05-13 | 2024-05-27 | 華為技術有限公司 | セキュリティ保護有効化方式を決定するための方法、通信方法、および通信装置 |
| CN115885572A (zh) * | 2021-07-28 | 2023-03-31 | 北京小米移动软件有限公司 | 一种通信方法、装置、用户设备、基站、核心网设备及存储介质 |
| EP4380294A4 (en) * | 2021-07-28 | 2024-08-21 | Beijing Xiaomi Mobile Software Co., Ltd. | Direct communication method and apparatus, user equipment, and storage medium |
| EP4380211A4 (en) * | 2021-07-28 | 2024-08-21 | Beijing Xiaomi Mobile Software Co., Ltd. | Communication method and apparatus, user equipment, base station, core network device, and storage medium |
| CN115885572B (zh) * | 2021-07-28 | 2025-07-15 | 北京小米移动软件有限公司 | 一种通信方法、装置、用户设备、基站、核心网设备及存储介质 |
| US12495302B2 (en) | 2021-07-28 | 2025-12-09 | Beijing Xiaomi Mobile Software Co., Ltd. | Communication method, user equipment, and base station |
Also Published As
| Publication number | Publication date |
|---|---|
| KR102708129B1 (ko) | 2024-09-19 |
| CN112351431B (zh) | 2023-06-30 |
| US12335319B2 (en) | 2025-06-17 |
| JP7389225B2 (ja) | 2023-11-29 |
| EP3863314A4 (en) | 2022-01-26 |
| EP3863314B1 (en) | 2026-03-04 |
| US20210306381A1 (en) | 2021-09-30 |
| JP2022543167A (ja) | 2022-10-07 |
| EP3863314A1 (en) | 2021-08-11 |
| CN112351431A (zh) | 2021-02-09 |
| KR20220044341A (ko) | 2022-04-07 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN112351431B (zh) | 一种安全保护方式确定方法及装置 | |
| US10187370B2 (en) | Fast-accessing method and apparatus | |
| JP7095942B2 (ja) | 通信方法、通信装置、及び通信システム | |
| CN108024253B (zh) | 一种通信方法以及终端、接入网设备、核心网设备 | |
| US12213194B2 (en) | Method and apparatus for admission control of sessions based on priority | |
| EP3771242A1 (en) | Key generation method and relevant apparatus | |
| WO2016161867A1 (zh) | 终端直通中继节点的确定、使用方法及装置 | |
| WO2020001562A1 (zh) | 一种通信方法及装置 | |
| WO2021047454A1 (zh) | 位置信息获取、位置服务配置方法和通信设备 | |
| WO2019201017A1 (zh) | 一种安全算法的协商方法及装置 | |
| WO2019024650A1 (zh) | 一种资源配置方法和装置 | |
| WO2021134701A1 (zh) | D2d通信方法、装置及系统 | |
| CN110519172A (zh) | 无线通信方法和设备 | |
| WO2017113130A1 (zh) | 一种资源请求方法、设备、网络侧节点及系统 | |
| CN115836539B (zh) | 通信方法、装置及系统 | |
| WO2017152360A1 (zh) | 一种为无线承载进行安全配置方法和设备 | |
| CN115996399A (zh) | 通信方法、通信装置、以及机算机存储介质 | |
| EP4340461A1 (en) | Network function selection for user equipment via a gateway network node | |
| WO2020238684A1 (zh) | 通信方法、装置、设备及计算机可读存储介质 | |
| WO2020142884A1 (zh) | 切换传输路径的方法及装置 | |
| CN117641239A (zh) | 通信方法、装置及存储介质 | |
| WO2022160275A1 (zh) | 无线通信方法、设备及存储介质 | |
| WO2022126641A1 (zh) | 无线通信方法、终端设备、第一接入网设备以及网元 | |
| TWI691230B (zh) | 一種使用者設備間的通信及其控制方法及裝置 | |
| WO2025140305A1 (zh) | 一种通信方法及装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 20853191 Country of ref document: EP Kind code of ref document: A1 |
|
| ENP | Entry into the national phase |
Ref document number: 2020853191 Country of ref document: EP Effective date: 20210503 |
|
| ENP | Entry into the national phase |
Ref document number: 2022507845 Country of ref document: JP Kind code of ref document: A |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 20227007917 Country of ref document: KR Kind code of ref document: A |
|
| WWG | Wipo information: grant in national office |
Ref document number: 2020853191 Country of ref document: EP |