Security policy processing method and communication device
Embodiments of this application disclose a security policy processing method, to implement a best-effort on-demand user plane security activation mechanism in a network in which there is a core network element that does not support on-demand user plane security protection. The security policy processing method in embodiments of this application includes: A target 1 receives a message # 50 - 2 from a core network device # 30 - 1 , where the message # 50 - 2 includes container information from a source access network device. The target access network device determines a user plane security activation status between the target access network device and a terminal device based on the message # 50 - 2 , where the user plane security activation status indicates whether user plane ciphering protection is activated and/or whether user plane integrity protection is activated.
1 . A security policy processing method, comprising:
receiving, by a target access network device, a message (# 50 - 2 ) from a core network device (# 30 - 1 ), wherein the message (# 50 - 2 ) comprises container information generated by a source access network device; and
determining, by the target access network device, a user plane security activation status between the target access network device and a terminal device based on the message (# 50 - 2 ), wherein the user plane security activation status indicates at least one of whether user plane ciphering protection is activated or whether user plane integrity protection is activated;
wherein determining, by the target access network device, the user plane security activation status between the target access network device and the terminal device based on the message (# 50 - 2 ) comprises:
when the message (# 50 - 2 ) further comprises a user plane security policy (# 40 - 2 ) and the container information comprises a user plane security policy (# 40 - 1 ), determining, by the target access network device, the user plane security activation status according to the user plane security policy (# 40 - 2 ).
2 . The method according to claim 1 , wherein determining, by the target access network device, the user plane security activation status between the target access network device and the terminal device according to the user plane security policy (#40-2) comprises:
ignoring, by the target access network device, the user plane security policy (# 40 - 1 ); and
determining, by the target access network device, the user plane security activation status directly according to the user plane security policy (# 40 - 2 ).
3 . The method according to claim 1 , wherein determining, by the target access network device, the user plane security activation status between the target access network device and the terminal device based on the message (# 50 - 2 ) further comprises:
when neither the message (# 50 - 2 ) nor the container information comprises a user plane security policy, determining, by the target access network device, the user plane security activation status according to a preconfigured user plane security policy (# 40 - 3 ).
4 . The method according to claim 1 , wherein the container information is a source evolved NodeB (eNB) to target eNB transparent container.
5 . The method according to claim 1 , wherein the message (# 50 - 2 ) is a handover request message, and the handover request message is for requesting the target access network device to prepare a handover resource for the terminal device.
6 . The method according to claim 1 , wherein the message (# 50 - 2 ) further comprises indication information, and before determining, by the target access network device, the user plane security activation status between the target access network device and the terminal device based on the message (# 50 - 2 ), the method further comprises:
determining, by the target access network device based on the indication information, that the terminal device supports on-demand user plane security protection.
7 . The method according to claim 6 , wherein the indication information is indicated by one or more bits of a security capability of the terminal device, and the security capability of the terminal device indicates at least one security algorithm that can be used by the terminal device.
8 . The method according to claim 7 , wherein the security capability of the terminal device is a user equipment (UE) evolved packet system security capability.
9 . An apparatus, comprising:
at least one processor coupled to at least one memory storing programming instructions for execution by the at least one processor to cause the apparatus to:
receive a message (# 50 - 2 ) from a core network device (# 30 - 1 ), wherein the message (# 50 - 2 ) comprises container information generated by a source access network device; and
determine a user plane security activation status between the apparatus and a terminal device based on the message (# 50 - 2 ), wherein the user plane security activation status indicates whether user plane ciphering protection is activated and/or whether user plane integrity protection is activated;
wherein determining the user plane security activation status comprises:
when the message (# 50 - 2 ) further comprises a user plane security policy (# 40 - 2 ) and the container information comprises a user plane security policy (# 40 - 1 ), determining the user plane security activation status according to the user plane security policy (# 40 - 2 ).
10 . The apparatus according to claim 9 , wherein determining the user plane security activation status according to the user plane security policy (# 40 - 2 ) comprises:
ignoring the user plane security policy (# 40 - 1 ); and
determining the user plane security activation status directly according to the user plane security policy (# 40 - 2 ).
11 . The apparatus according to claim 9 , wherein determining the user plane security activation status between the apparatus and the terminal device based on the message (# 50 - 2 ) further comprises:
when neither the message (# 50 - 2 ) nor the container information comprises a user plane security policy, determining the user plane security activation status according to a preconfigured user plane security policy (# 40 - 3 ).
12 . The apparatus according to claim 9 , wherein the container information is a source evolved NodeB (eNB) to target eNB transparent container.
13 . The apparatus according to claim 9 , wherein the message (# 50 - 2 ) is a handover request message, and the handover request message is for requesting the apparatus to prepare a handover resource for the terminal device.
14 . The apparatus according to claim 9 , wherein the message (# 50 - 2 ) further comprises indication information, and the programming instructions are for execution by the at least one processor to cause the apparatus to:
before determining the user plane security activation status, determine, based on the indication information, that the terminal device supports on-demand user plane security protection.
15 . The apparatus according to claim 14 , wherein the indication information is indicated by one or more bits of a security capability of the terminal device, and the security capability of the terminal device indicates at least one security algorithm that can be used by the terminal device.
16 . The apparatus according to claim 15 , wherein the security capability of the terminal device is a user equipment (UE) evolved packet system security capability.
17 . A non-transitory computer-readable storage medium, comprising instructions for execution by at least one processor of an apparatus to cause the apparatus to:
receive a message (# 50 - 2 ) from a core network device (# 30 - 1 ), wherein the message (# 50 - 2 ) comprises container information generated by a source access network device; and
determine a user plane security activation status between the apparatus and a terminal device based on the message (# 50 - 2 ), wherein the user plane security activation status indicates whether user plane ciphering protection is activated and/or whether user plane integrity protection is activated;
wherein determining the user plane security activation status comprises:
when the message (# 50 - 2 ) further comprises a user plane security policy (# 40 - 2 ) and the container information comprises a user plane security policy (# 40 - 1 ), determining the user plane security activation status according to the user plane security policy (# 40 - 2 ).
18 . The non-transitory computer-readable storage medium according to claim 17 , wherein determining the user plane security activation status according to the user plane security policy (# 40 - 2 ) further comprises:
ignoring the user plane security policy (# 40 - 1 ); and
determining the user plane security activation status directly according to the user plane security policy (# 40 - 2 ).
19 . The non-transitory computer-readable storage medium according to claim 17 , wherein determining the user plane security activation status between the apparatus and the terminal device based on the message (# 50 - 2 ) further comprises:
when neither the message (# 50 - 2 ) nor the container information comprises a user plane security policy, determining the user plane security activation status according to a preconfigured user plane security policy (# 40 - 3 ).
20 . The non-transitory computer-readable storage medium according to claim 17 , wherein the container information is a source evolved NodeB (eNB) to target eNB transparent container.