IP Library › Granted Patent US 12,495,302
Granted Patent B2
US 12,495,302 · App. 18/291,197 · Granted Dec 9, 2025

Communication method, user equipment, and base station

Inventor: Wei Hong (Beijing, CN)
Assignee: BEIJING XIAOMI MOBILE SOFTWARE CO., LTD.
H04W12/37H04W88/04H04W92/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,495,302
App. No.
18/291,197
Granted
Dec 9, 2025
Kind
B2
Abstract

A communication method performed by a relay user equipment (UE) includes: determining an activation status of a user plane (UP) security policy of a first link between the relay UE and a base station, and, on the basis of the activation status of the UP security policy of the first link, activating UP security of a second link between the relay UE and a remote UE. Related communication methods by a remote user equipment and a base station are also disclosed.

Claims (65)

1 . A communication method, performed by a relay user equipment (UE), comprising:

determining an activation status of a user plane (UP) security policy of a first link between the relay UE and a base station;

activating UP security of a second link between the relay UE and a remote UE based on the activation status of the UP security policy of the first link; and

establishing a signaling security of the second link;

wherein establishing the signaling security of the second link comprises:

obtaining a Direct Communication Request message sent by the remote UE;

sending a Relay Key Request message to a core network device based on the Direct Communication Request message, wherein the Relay Key Request message comprises a Relay Service Code;

receiving an authorization message sent by the core network device based on the Relay Service Code;

obtaining an intermediate key parameter and intermediate key related parameters sent by the core network device, wherein the intermediate key parameter comprises a 5G K NRP , and the intermediate key related parameters comprise a 5G K NRP Freshness Parameter and a 5GPRUK Info, the 5G K NRP is generated based on 5GPRUK, the 5G K NRP Freshness Parameter, Nonce 1, and the Relay Service Code;

determining a session key based on the intermediate key parameter, wherein the session key is configured to protect the signaling security of the second link;

sending a Direct Security Mode Command message to the remote UE, wherein the Direct Security Mode Command message is protected by the session key, and the Direct Security Mode Command message comprises the intermediate key related parameters; and

receiving a Direct Security Mode Complete message sent by the remote UE, wherein the Direct Security Mode Complete message is protected by the session key.

2 . The method of claim 1 , wherein the first link comprises a Uu link; and the second link comprises a PC5 link.

3 . The method of claim 1 , wherein determining the activation status of the UP security policy of the first link between the relay UE and the base station comprises:

determining whether there is a need to establish a new packet data unit (PDU) session between the relay UE and the base station;

in response to determining that there is no need to establish a new PDU session, determining an activation status of a UP security policy of a first interface in the relay UE corresponding to the first link as the activation status of the UP security policy of the first link;

in response to determining that there is a need to establish a new PDU session, sending a PDU session establishment request to a core network device via the base station; obtaining a first UP security activation indication sent by the base station, wherein the first UP security activation indication indicates whether to activate UP security of a first interface in the relay UE corresponding to the first link; activating the UP security of the first interface based on the first UP security activation indication, and determining an activation status of a UP security policy of the first interface as the activation status of the UP security policy of the first link.

4 . The method of claim 3 , wherein the first interface comprises a Uu interface.

5 . The method of claim 3 , wherein activating the UP security of the second link between the relay UE and the remote UE based on the activation status of the UP security policy of the first link comprises:

mapping the UP security policy of the first interface to a second interface in the relay UE corresponding to the second link;

determining a second UP security activation indication based on an activation status of a security policy of the second interface, wherein the second UP security activation indication indicates whether to activate UP security of the remote UE; and

sending the second UP security activation indication to the remote UE via a Direct Communication Accept message.

6 . The method of claim 5 , wherein the second interface includes a PC5-U interface;

wherein the UP security policy comprises at least one of: a policy of UP integrity protection; or a policy of UP encryption protection;

wherein the method further comprises: communicating with the base station based on the UP security policy of the first link; and communicating with the remote UE based on a UP security policy of the second link.

7 . The method of claim 6 , wherein the first UP security activation indication indicates at least one of:

whether to activate the UP integrity protection; or

whether to activate the UP encryption protection;

the second UP security activation indication indicates at least one of: whether to activate the UP integrity protection; or whether to activate the UP encryption protection.

8 . A communication method, performed by a remote user equipment (UE), comprising:

obtaining a second user plane (UP) security activation indication sent by a relay UE, wherein the second UP security activation indication indicates whether to activate UP security of the remote UE;

in response to the second UP security activation indication indicating to activate the UP security, activating the UP security of the remote UE based on the second UP security activation indication; and

establishing a signaling security of the second link;

wherein establishing the signaling security of the second link comprises:

sending a Direct Communication Request message to the relay UE;

obtaining a Direct Security Mode Command message sent by the relay UE, wherein the Direct Security Mode Command message is protected by a session key, the Direct Security Mode Command message comprises intermediate key related parameters that are a 5G K NRP Freshness Parameter and a 5GPRUK Info;

determining the session key based on the intermediate key related parameters; and

sending a Direct Security Mode Complete message to the relay UE, wherein the Direct Security Mode Complete message is protected by the session key.

9 . The method of claim 8 , wherein a second link between the relay UE and the remote UE comprises a PC5 link.

10 . The method of claim 8 , wherein obtaining the second UP security activation indication sent by the relay UE comprises:

obtaining the second UP security activation indication sent by the relay UE via a Direct Communication Accept message.

11 . The method of claim 10 , further comprising:

communicating with the relay UE based on a UP security policy of the second link;

wherein the UP security policy comprises at least one of: a policy of UP integrity protection; or a policy of UP encryption protection;

wherein the second UP security activation indication indicates at least one of: whether to activate the UP integrity protection; or whether to activate the UP encryption protection.

12 . A communication method, performed by a base station, comprising:

obtaining a packet data unit (PDU) session establishment request sent by a relay user equipment (UE), and sending the PDU session establishment request to a core network device;

receiving a PDU session request message sent by the core network device, wherein the PDU session request message comprises a user plane (UP) security policy; and

activating UP security of a first link between the relay UE and the base station based on the UP security policy sent by the core network device;

wherein UP security of a second link between the relay UE and a remote UE is activated based on an activation status of the UP security policy; a signaling security of the second link is established by the relay UE to perform:

obtaining a Direct Communication Request message sent by the remote UE;

sending a Relay Key Request message to a core network device based on the Direct Communication Request message, wherein the Relay Key Request message comprises a Relay Service Code;

receiving an authorization message sent by the core network device based on the Relay Service Code;

obtaining an intermediate key parameter and intermediate key related parameters sent by the core network device, wherein the intermediate key parameter comprises a 5G K NRP , and the intermediate key related parameters comprise a 5G K NRP Freshness Parameter and a 5GPRUK Info, the 5G K NRP is generated based on 5GPRUK, the 5G K NRP Freshness Parameter, Nonce 1, and the Relay Service Code;

determining a session key based on the intermediate key parameter, wherein the session key is configured to protect the signaling security of the second link;

sending a Direct Security Mode Command message to the remote UE, wherein the Direct Security Mode Command message is protected by the session key, and the Direct Security Mode Command message comprises the intermediate key related parameters; and

receiving a Direct Security Mode Complete message sent by the remote UE, wherein the Direct Security Mode Complete message is protected by the session key.

13 . The method of claim 12 , wherein the first link comprises a Uu link.

14 . The method of claim 13 , wherein activating the UP security of the first link between the relay UE and the base station based on the UP security policy sent by the core network device comprises:

activating UP security of the base station based on the UP security policy; and

sending a first UP security activation indication to the relay UE based on the UP security policy, wherein the first UP security activation indication indicates whether to activate UP security of a first interface in the relay UE corresponding to the first link;

wherein the UP security policy comprises at least one of: a policy of UP integrity protection; or a policy of UP encryption protection; the first UP security activation indication indicates at least one of: whether to activate the UP integrity protection; or whether to activate the UP encryption protection.

15 . The method of claim 14 , wherein the first interface comprises a Uu interface.

16 . The method of claim 12 , further comprising:

communicating with the relay UE based on a UP security policy of the first link.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2024
From: HONG, WEI
To: BEIJING XIAOMI MOBILE SOFTWARE CO., LTD.
Reel/Frame 066219/0327 →
Continuity (1)
Related Publication 20250106635A1 · Mar 27, 2025
References Cited (9)
US 10660008B2 · Ma · 2020 [cited by examiner]
US 11297502B2 · Muhanna · 2022 [cited by examiner]
CN 111641582A · 2020 [cited by applicant]
CN 112166623A · 2021 [cited by applicant]
CN 113068180A · 2021 [cited by applicant]
WO WO2021027435A1 · 2021 [cited by applicant]
PCT/CN2021/109086 International Search Report dated Apr. 19, 2022, 3 pages. [cited by applicant]
European Patent Application No. 21951267.0, Search Report and Opinion dated Jul. 19, 2024, 10 pages. [cited by applicant]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on security aspects of enhancement for proximity based services in the 5G System (5GS)(Release 17) Mar. 12, 2021, 120 … [cited by applicant]