Secure communication method and communication apparatus
A secure communication method and apparatus includes: a session management function network element receives first security capability indication information from a terminal device, where the first security capability indication information indicates that the terminal device supports establishment of a secure connection between the terminal device and a server. The session management function network element determines, based on the first security capability indication information, a first server that supports establishment of the secure connection. The session management function network element sends information about the first server to the terminal device to establish the secure connection. According to the method, a server that matches a security capability of the terminal device can be selected, to ensure security protection for communication between the terminal device and the server, avoid information leakage or tampering, and help improve information exchange transmission efficiency.
1 . A secure communication method comprising:
receiving, by a session management function network element, first security capability indication information from a terminal device, wherein the first security capability indication information indicates that the terminal device supports establishment of a secure connection between the terminal device and a server;
determining, by the session management function network element based on the first security capability indication information, a first server that supports establishment of the secure connection; and
sending, by the session management function network element, information about the first server to the terminal device to establish the secure connection.
2 . The method according to claim 1 , wherein the determining, by the session management function network element based on the first security capability indication information, of the first server that supports establishment of the secure connection comprises:
in response to determining that user plane security protection is not enabled for a session of the terminal device, determining, by the session management function network element, the first server based on the first security capability indication information, wherein the session is configured for transmission of data between the terminal device and the first server.
3 . The method according to claim 2 , wherein the method further comprises:
determining, by the session management function network element based on a user plane security status of the session or a user plane security policy of the session, that user plane security protection is not enabled for the session.
4 . The method according to claim 3 , wherein the method further comprises:
receiving, by the session management function network element, indication information of the user plane security status of the session from an access network device.
5 . The method according to claim 3 , wherein:
the determining, by the session management function network element, that the user plane security protection is not enabled for the session is based on the user plane security status of the session; and
the user plane security status of the session is a non-activated state.
6 . The method according to claim 3 , wherein the method further comprises:
receiving, by the session management function network element, the user plane security policy of the session from a unified data management network element.
7 . The method according to claim 3 , wherein:
the determining, by the session management function network element, that the user plane security protection is not enabled for the session is based on the user plane security policy of the session; and
the user plane security policy of the session is that enabling is not needed.
8 . The method according to claim 1 , wherein the determining, by the session management function network element based on the first security capability indication information, of the first server that supports establishment of the secure connection comprises:
sending, by the session management function network element, a request message to a network repository function network element, wherein the request message comprises the first security capability indication information, and the request message is configured to request to discover a server that supports the secure connection; and receiving, by the session management function network element, a response message of the request message from the network repository function network element, wherein the response message comprises the information about the first server.
9 . The method according to claim 1 , wherein the determining, by the session management function network element based on the first security capability indication information, of the first server that supports establishment of the secure connection comprises:
sending, by the session management function network element, a request message to a network repository function network element, wherein the request message is configured to request to discover a server;
receiving, by the session management function network element, a response message of the request message from the network repository function network element, wherein the response message comprises the information about the first server and second security capability indication information, and the second security capability indication information indicates that the first server supports the secure connection or supports activation of the secure connection; and
determining, by the session management function network element, the first server based on the second security capability indication information and the first security capability indication information.
10 . The method according to claim 9 , wherein in response to the second security capability indication information indicating that the first server supports activation of the secure connection, the method further comprises:
sending, by the session management function network element, activation indication information to the first server, wherein the activation indication information indicates the first server to activate the secure connection.
11 . The method according to claim 10 , wherein the method further comprises:
sending, by the session management function network element, the activation indication information to the first server based on local second security capability indication information, wherein the activation indication information indicates the first server to activate the secure connection, and the second security capability indication information indicates that the first server supports activation of the secure connection.
12 . The method according to claim 1 , wherein the sending, by the session management function network element, information about the first server to the terminal device to establish the secure connection comprises:
sending, by the session management function network element, a session establishment accept message to the terminal device, wherein the session establishment accept message comprises the information about the first server; or
sending, by the session management function network element, a session modification command to the terminal device, wherein the session modification command comprises the information about the first server.
13 . The method according to claim 1 , wherein the information about the first server comprises at least one of an identifier of the first server, a security protocol supported by the first server, a security mechanism supported by the first server, a credential for verifying the first server, and a port number of the first server.
14 . An apparatus, comprising a processor and a memory, wherein the memory is coupled to the processor and configured to store instructions that are executable by the processor to cause the apparatus to:
receive first security capability indication information from a terminal device, wherein the first security capability indication information indicates that the terminal device supports establishment of a secure connection between the terminal device and a server;
determine, based on the first security capability indication information, a first server that supports establishment of the secure connection; and
send information about the first server to the terminal device to establish the secure connection.
15 . The apparatus according to claim 14 , wherein the apparatus is further caused to:
in response to determining that user plane security protection is not enabled for a session of the terminal device, determine the first server based on the first security capability indication information, wherein the session is configured for transmission of data between the terminal device and the first server.
16 . The apparatus according to claim 15 , wherein the apparatus is further caused to:
determine, based on a user plane security status of the session or a user plane security policy of the session, that user plane security protection is not enabled for the session.
17 . The apparatus according to claim 16 , wherein the apparatus is further caused to:
receive indication information of the user plane security status of the session from an access network device; or
receive the user plane security policy of the session from a unified data management network element.
18 . The apparatus according to claim 16 , wherein the apparatus is further caused to:
determine, based on the user plane security status of the session being a non-activated state, that user plane security protection is not enabled for the session; or
determine, based on the user plane security policy of the session being that enabling is not needed, that user plane security protection is not enabled for the session.
19 . A non-transitory computer-readable medium, comprising instructions which are executable by an apparatus to cause the apparatus to:
receive first security capability indication information from a terminal device, wherein the first security capability indication information indicates that the terminal device supports establishment of a secure connection between the terminal device and a server;
determine, based on the first security capability indication information, a first server that supports establishment of the secure connection; and
send information about the first server to the terminal device to establish the secure connection.
20 . The non-transitory computer-readable medium according to claim 19 , wherein the apparatus is further caused to:
in response to determining that user plane security protection is not enabled for a session of the terminal device, determine the first server based on the first security capability indication information, wherein the session is configured for transmission of data between the terminal device and the first server.