IP Library › Granted Patent US 12,406,059
Granted Patent B2
US 12,406,059 · App. 18/168,228 · Granted Sep 2, 2025

Communication method, apparatus, and system

Inventors: He Li (Shanghai, CN); Rong Wu (Shenzhen, CN); Yizhuang Wu (Beijing, CN); Ao Lei (Beijing, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
G06F21/554H04L9/40H04L63/20G06F2221/034H04W28/0875
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,406,059
App. No.
18/168,228
Granted
Sep 2, 2025
Kind
B2
Abstract

Embodiments of this application provide a communication method, apparatus, and system, to improve security of a vehicle-to-everything (V2X) PC5 establishment procedure. In the method, a first terminal device obtains a first security protection method, where the first security protection method is a security protection method determined in a discovery procedure between the first terminal device and a second terminal device. Also in the method, the first terminal device determines a second security protection method according to the first security protection method, where the second security protection method is a security protection method for a PC5 connection between the first terminal device and the second terminal device. For example, a security level of the second security protection method is higher than a security level of the first security protection method. The communication method is applicable to the V2X communication field.

Claims (47)

1. A communication method, wherein the method comprises:

determining, by a first terminal device, a first security protection method in a discovery procedure between the first terminal device and a second terminal device;

performing, by the first terminal device, security protection on at least one message in a PC5 establishment procedure between the first terminal device and the second terminal device using the first security protection method; and

sending, by the first terminal device, the at least one security-protected message to the second terminal device.

2. The method according to claim 1 , wherein the at least one message comprises a first message in the PC5 establishment procedure.

3. The method according to claim 1 , wherein the method further comprises:

determining, by the first terminal device, a second security protection method for a PC5 connection between the first terminal device and the second terminal device according to the first security protection method.

4. The method according to claim 3 , wherein the determining, by the first terminal device, the second security protection method according to the first security protection method comprises:

receiving, by the first terminal device, a second security policy from the second terminal device, wherein the second security policy is a security policy of the second terminal device in the PC5 connection; and

determining, by the first terminal device, the second security protection method according to the second security policy and the first security protection method.

5. The method according to claim 1 , wherein the obtaining, by the first terminal device, the first security protection method comprises:

sending, by the first terminal device, first information and 3 rd generation partnership project (3GPP) identity information of the first terminal device to a first direct communication discovery name management function network element, wherein the first information comprises identity information used for a proximity-based service (ProSe) or information used to determine the identity information used for the ProSe; and

receiving, by the first terminal device, the first security protection method from the first direct communication discovery name management function network element.

6. A communication method, wherein the method comprises:

receiving, by a first direct communication discovery name management function network element, first information and 3 rd generation partnership project (3GPP) identity information of a first terminal device from the first terminal device, wherein the first information comprises identity information used for a proximity-based service (ProSe) or information used to determine the identity information used for the ProSe;

determining, by the first direct communication discovery name management function network element based on the first information and the 3GPP identity information of the first terminal device, a security protection method required for using the ProSe by the first terminal device; and

sending, by the first direct communication discovery name management function network element to the first terminal device, the security protection method required for using the ProSe by the first terminal device.

7. The method according to claim 6 , wherein the security protection method required for using the ProSe is used to determine a security protection method for a PC5 connection between the first terminal device and the second terminal device.

8. The method according to claim 7 , wherein at least one of:

the security protection method for the PC5 connection is used to perform security protection on a part or all of parameters transferred in control plane signaling of the PC5 connection; or

the security protection method for the PC5 connection is used to perform security protection on a part or all of user plane data of the PC5 connection.

9. The method according to claim 6 , wherein the security protection method required for using the ProSe is used to perform security protection on at least one message in a PC5 establishment procedure between the first terminal device and the second terminal device.

10. The method according to claim 9 , wherein the at least one message comprises a first message in the PC5 establishment procedure.

11. A communication apparatus, comprising:

a processor coupled to a memory storing instructions and configured to execute the instructions to cause the communication apparatus to:

determine a first security protection method in a discovery procedure between the communication apparatus and a second terminal device;

perform security protection on at least one message in a PC5 establishment procedure between the communication apparatus and the second terminal device by using the first security protection method; and

send the at least one security-protected message to the second terminal device.

12. The communication apparatus according to claim 11 , wherein the at least one message comprises a first message in the PC5 establishment procedure.

13. The communication apparatus according to claim 11 , wherein the instructions further cause the communication apparatus to determine a second security protection method according to the first security protection method, wherein the second security protection method is a security protection method for a PC5 connection between the communication apparatus and the second terminal device.

14. The communication apparatus according to claim 13 , wherein the instructions cause the communication apparatus to determine the second security protection method by:

receiving a second security policy from the second terminal device, wherein the second security policy is a security policy of the second terminal device in the PC5 connection; and

determining the second security protection method according to the second security policy and the first security protection method.

15. The communication apparatus according to claim 11 , wherein the instructions cause the communication apparatus to obtaini the first security protection method by:

sending first information and 3 rd generation partnership project (3GPP) identity information of the communication apparatus to a first direct communication discovery name management function network element, wherein the first information comprises identity information used for a proximity-based service (ProSe) or information used to determine the identity information used for the ProSe; and

receiving the first security protection method from the first direct communication discovery name management function network element.

16. A first direct communication discovery name management function network element, comprising:

a processor coupled to a memory storing instructions and configured to execute the instructions to cause the first direct communication discovery name management function network element to:

receive first information and 3 rd generation partnership project (3GPP) identity information of a first terminal device from the first terminal device, wherein the first information comprises identity information used for a proximity-based service (ProSe) or information used to determine the identity information used for the ProSe;

determine, based on the first information and the 3GPP identity information of the first terminal device, a security protection method required for using the ProSe by the first terminal device; and

send, to the first terminal device, the security protection method required for using the ProSe by the first terminal device.

17. The first direct communication discovery name management function network element according to claim 16 , wherein the security protection method required for using the ProSe is used to determine a security protection method for a PC5 connection between the first terminal device and the second terminal device.

18. The first direct communication discovery name management function network element according to claim 17 , wherein at least one of:

the security protection method for the PC5 connection is used to perform security protection on a part or all of parameters transferred in control plane signaling of the PC5 connection; or

the security protection method for the PC5 connection is used to perform security protection on a part or all of user plane data of the PC5 connection.

19. The first direct communication discovery name management function network element according to claim 16 , wherein the security protection method required for using the ProSe is used to perform security protection on at least one message in a PC5 establishment procedure between the first terminal device and the second terminal device.

20. The first direct communication discovery name management function network element according to claim 19 , wherein the at least one message comprises a first message, and the first message is a first message in the PC5 establishment procedure.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2024
From: LI, HE; WU, RONG; WU, YIZHUANG; LEI, AO
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 068420/0015 →
Continuity (2)
Continuation PCTCN2020109382 · Aug 14, 2020
Related Publication 20230185910A1 · Jun 15, 2023
References Cited (23)
US 9706340B2 · Kim · 2017 [cited by examiner]
US 9813842B2 · Ahmad · 2017 [cited by examiner]
US 10667119B2 · Loehr et al. · 2020 [cited by applicant]
US 20140344578A1 · Kim · 2014 [cited by examiner]
US 20160295347A1 · Ahmad · 2016 [cited by examiner]
US 20180007497A1 · Ahmad · 2018 [cited by examiner]
US 20190394631A1 · Stojanovski et al. · 2019 [cited by applicant]
US 20190394816A1 · Kim · 2019 [cited by applicant]
US 20200205209A1 · Pan · 2020 [cited by examiner]
US 20200221298A1 · Pan et al. · 2020 [cited by applicant]
CN 110830993A · 2020 [cited by applicant]
CN 111247820A · 2020 [cited by applicant]
CN 111373782A · 2020 [cited by applicant]
EP 3863314A1 · 2021 [cited by applicant]
WO 2017028901A1 · 2017 [cited by applicant]
WO 2019095128A1 · 2019 [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security aspects of 3GPP support for advanced Vehicle-to-Everything (V2X) services (Release 16)”, 3GPP TS 33.536 V16.… [cited by applicant]
3GPP TS 33.303 V16.0.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Proximity-based Services (ProSe); Security aspects (Release 16)”, Jul. 2020; 90 total pages. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on system enhancement for Proximity based Services (ProSe) in the 5G System (5GS) (Release 17)”, 3GPP TR 23.752… [cited by applicant]
OPPO et al., “Solution for direct discovery”, SA WG2 Meeting #136, S2-1912459, Nov. 18-22, 2019, Reno USA (Merge of S2-1911151 and S2-1911800); 4 total pages. [cited by applicant]
3GPP TS 23.501 V15.10.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 15)”, Jul. 2020; 249 total pages. [cited by applicant]
3GPP TSG RAN WG1 Meeting #80bis, R1-151234, Belgrade, Serbia, “PRACH for LC-MTC,” Alcatel-Lucent, Alcatel-Lucent Shanghai Bell, Apr. 20-24, 2015; 4 total pages. [cited by applicant]
Qualcomm Incorporated: “Security establishment procedures for ProSe one-to-one communication.” 3GPP TSG-CT WG1 Meeting #96 C1-161418 Jeju (Korea), Feb. 15-19, 2016 (was C1-161255); 37 total pages. [cited by applicant]