IP Library › Granted Patent US 12,621,657
Granted Patent B2
US 12,621,657 · App. 18/348,473 · Granted May 5, 2026

Secure communication method and device

Inventors: He Li (Shanghai, CN); Yizhuang Wu (Beijing, CN); Rong Wu (Shenzhen, CN)
Assignee: Huawei Technologies Co., Ltd.
H04W12/02H04W12/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,657
App. No.
18/348,473
Granted
May 5, 2026
Kind
B2
Abstract

A method includes: User equipment determines whether confidentiality protection is activated for communication data between the user equipment and an application function device. The user equipment sends a user plane message to the application function device. The user plane message includes an identifier of the user equipment, and the identifier is an encrypted identifier in a case in which the confidentiality protection is inactivated.

Claims (50)

1 . A secure communication method, comprising:

determining, by a communication apparatus, to implement a procedure with privacy protection of interaction between user equipment and an application function device when the communication apparatus determines that a user plane message will carry a permanent identifier of the user equipment;

determining, by the communication apparatus based on the procedure with privacy protection, a communication key for interaction with the application function device and a non-null encryption algorithm; and

sending, by the communication apparatus, the user plane message to the application function device, wherein the user plane message comprises the permanent identifier of the user equipment, and wherein confidentiality protection is performed on the user plane message by using the communication key and the non-null encryption algorithm.

2 . The method according to claim 1 , wherein the procedure with privacy protection comprises an authentication and key management for applications (AKMA) procedure.

3 . The method according to claim 1 , wherein determining, by the communication apparatus, to implement the procedure with privacy protection comprises:

determining, by the communication apparatus, to implement the procedure with privacy protection when an application started by the communication apparatus indicates the communication apparatus to select the procedure with privacy protection, wherein a server of the application is comprised in the application function device.

4 . The method according to claim 1 , wherein determining, by the communication apparatus, to implement the procedure with privacy protection comprises:

determining, by the communication apparatus, to implement the procedure with privacy protection when an application indicates that one of a plurality of interaction procedures can be selected, wherein the plurality of interaction procedures comprises the procedure with privacy protection, and a server of the application is comprised in the application function device.

5 . The method according to claim 1 , wherein determining, by the communication apparatus, to implement the procedure with privacy protection comprises:

determining, by the communication apparatus, to implement the procedure with privacy protection when an application indicates that one of a plurality of interaction procedures can be selected, wherein the plurality of interaction procedures comprises the procedure with privacy protection, the procedure with privacy protection has a highest priority of the plurality of interaction procedures wherein the plurality of interaction procedures comprises the procedure with privacy protection, and a server of the application is comprised in the application function device.

6 . The method according to claim 1 , wherein determining, by the communication apparatus, to implement the procedure with privacy protection comprises:

determining, by the communication apparatus, to implement the procedure with privacy protection when the communication apparatus receives an indication of preferably selecting the procedure with privacy protection.

7 . The method according to claim 1 , wherein determining, by the communication apparatus, to implement the procedure with privacy protection comprises:

determining, by the communication apparatus, to implement the procedure with privacy protection when the communication apparatus determines that the user equipment has a 5G universal subscriber identity module (SIM).

8 . The method according to claim 1 , wherein determining, by the communication apparatus, to implement the procedure with privacy protection comprises:

determining, by the communication apparatus, to implement the procedure with privacy protection when the communication apparatus determines that the user equipment has a valid public key and a valid private key.

9 . The method according to claim 1 , wherein the communication apparatus is the user equipment or a chip in the user equipment.

10 . The method according to claim 1 , wherein determining, by the communication apparatus based on the procedure with privacy protection, the communication key for interaction with the application function device and the non-null encryption algorithm comprises:

generating, by the communication apparatus, the communication key based on an anchor key stored in the communication apparatus;

sending, by the communication apparatus, a request message to the application function device, wherein the request message comprises a key identifier and information indicating to use the procedure with privacy protection, and the key identifier is used to assist the application function device in obtaining the communication key; and

receiving, by the communication apparatus, a response message from the application function device, wherein the response message comprises information about the non-null encryption algorithm.

11 . The method according to claim 10 , wherein the request message further comprises indication information for negotiating the non-null encryption algorithm.

12 . The method according to claim 10 , wherein the request message further comprises information about an encryption algorithm supported by the communication apparatus, the information about the encryption algorithm supported by the communication apparatus indicates the application function device to select the non-null encryption algorithm, and the encryption algorithm supported by the communication apparatus is the non-null encryption algorithm.

13 . A communication apparatus, wherein the communication apparatus comprises at least one processor coupled to at least one memory storing instructions, and configured to execute the instructions to cause the communication apparatus to:

determine to implement a procedure with privacy protection of interaction between user equipment and an application function device when the communication apparatus determines that a user plane message will carry a permanent identifier of the user equipment;

determine, based on the procedure with privacy protection, a communication key for interaction with the application function device and a non-null encryption algorithm; and

send the user plane message to the application function device, wherein the user plane message comprises the permanent identifier to the user equipment, and wherein confidentiality protection is performed on the user plane message by using the communication key and the non-null encryption algorithm.

14 . The communication apparatus according to claim 13 , wherein the procedure with privacy protection comprises an authentication and key management for applications (AKMA) procedure.

15 . The communication apparatus according to claim 13 , wherein the instructions to determine to implement the procedure with privacy protection comprise instructions to determine to implement the procedure with privacy protection when one or more of the following conditions are met:

an application started by the communication apparatus indicates the communication apparatus to select the procedure with privacy protection, wherein a server of the application is comprised in the application function device;

the application indicates that one of a plurality of interaction procedures can be selected, wherein the plurality of interaction procedures comprises the procedure with privacy protection;

the communication apparatus receives an indication of selecting the procedure with privacy protection;

the communication apparatus determines that the user equipment has a 5G universal subscriber identity module;

the communication apparatus determines that the user equipment has a valid public key and a valid private key; or

the communication apparatus determines that the user plane message carries the permanent identifier of the user equipment.

16 . The communication apparatus according to claim 15 , wherein the instructions to determine to implement the procedure with privacy protection comprises instructions to determine to implement the procedure with privacy protection when the application indicates that one of the plurality of interaction procedures can be selected, and the procedure with privacy protection has a highest priority of the plurality of interaction procedures.

17 . The communication apparatus according to claim 13 , wherein the communication apparatus is the user equipment or a chip in the user equipment.

18 . A non-transitory computer-readable storage medium, storing a computer program, wherein when the computer program is executed, a communication apparatus is enabled to perform a method of:

determining to implement a procedure with privacy protection of interaction between user equipment and an application function device when determining that a user plane message will carry a permanent identifier of the user equipment;

determining, based on the procedure with privacy protection, a communication key for interaction with the application function device and a non-null encryption algorithm; and

sending the user plane message to the application function device, wherein the user plane message comprises the permanent identifier of the user equipment and wherein confidentiality protection is performed on the user plane message by using the communication key and the non-null encryption algorithm.

19 . The non-transitory computer-readable storage medium according to claim 18 , wherein the procedure with privacy protection comprises an authentication and key management for applications (AKMA) procedure.

20 . The non-transitory computer-readable storage medium according to claim 18 , wherein instructions for determining to use the procedure with privacy protection comprise instructions for determining to use the procedure with privacy protection when one or more of the following conditions are met:

an application started by the communication apparatus indicates the communication apparatus to select the procedure with privacy protection, wherein a server of the application is comprised in the application function device;

the application indicates that one of a plurality of interaction procedures can be selected, wherein the plurality of interaction procedures comprises the procedure with privacy protection;

the communication apparatus receives an indication of preferably selecting the procedure with privacy protection;

the communication apparatus determines that the user equipment has a 5G universal subscriber identity module (SIM);

the communication apparatus determines that the user equipment has a valid public key and a valid private key; or

the communication apparatus determines that the user plane message carries the permanent identifier of the user equipment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2025
From: LI, HE; WU, YIZHUANG; WU, RONG
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 072171/0508 →
Continuity (2)
Continuation PCTCN2021070979 · Jan 8, 2021
Related Publication 20230354013A1 · Nov 2, 2023
References Cited (14)
US 8812567B1 · Caklovic · 2014 [cited by applicant]
US 20110145296A1 · Ellison et al. · 2011 [cited by applicant]
US 20120039472A1 · Liu · 2012 [cited by examiner]
US 20170006469A1 · Palanigounder · 2017 [cited by examiner]
US 20200068391A1 · Liu et al. · 2020 [cited by applicant]
US 20210185523A1 · Targali · 2021 [cited by examiner]
US 20220086632A1 · Wang · 2022 [cited by examiner]
US 20220337408A1 · You · 2022 [cited by examiner]
WO 2020145064A1 · 2020 [cited by applicant]
WO 2020146974A1 · 2020 [cited by applicant]
WO 2020249861A1 · 2020 [cited by applicant]
3GPP, “3rd Generation Partnership Project Technical Specification Group Services and System Aspects Proximity-based Services (ProSe) Security aspects (Release 16)”, 3GPP TS 33.303 V16.0.0 Technical Specification, Jul. 3… [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and Key Management for Applications (AKMA) based on 3GPP credentials in the 5G System (5GS) (Release 1… [cited by applicant]
Wright, “Kernel Korner—Unionfs: Bringing Filesystems Together,” Dec. 1, 2004, total 9 pages. [cited by applicant]