IP Library Granted Patent US 12,652,525
Granted Patent B2
US 12,652,525 · App. 18/437,407 · Granted Jun 9, 2026

Secure communication method and communication apparatus

Inventor: Yizhuang Wu (Beijing, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04W12/033H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,652,525
App. No.
18/437,407
Granted
Jun 9, 2026
Kind
B2
Abstract

A secure communication method and apparatus includes: a session management function network element receives first security capability indication information from a terminal device, where the first security capability indication information indicates that the terminal device supports establishment of a secure connection between the terminal device and a server. The session management function network element determines, based on the first security capability indication information, a first server that supports establishment of the secure connection. The session management function network element sends information about the first server to the terminal device to establish the secure connection. According to the method, a server that matches a security capability of the terminal device can be selected, to ensure security protection for communication between the terminal device and the server, avoid information leakage or tampering, and help improve information exchange transmission efficiency.

Claims (52)

1 . A secure communication method comprising:

receiving, by a session management function network element, first security capability indication information from a terminal device, wherein the first security capability indication information indicates that the terminal device supports establishment of a secure connection between the terminal device and a server;

determining, by the session management function network element based on the first security capability indication information, a first server that supports establishment of the secure connection; and

sending, by the session management function network element, information about the first server to the terminal device to establish the secure connection.

2 . The method according to claim 1 , wherein the determining, by the session management function network element based on the first security capability indication information, of the first server that supports establishment of the secure connection comprises:

in response to determining that user plane security protection is not enabled for a session of the terminal device, determining, by the session management function network element, the first server based on the first security capability indication information, wherein the session is configured for transmission of data between the terminal device and the first server.

3 . The method according to claim 2 , wherein the method further comprises:

determining, by the session management function network element based on a user plane security status of the session or a user plane security policy of the session, that user plane security protection is not enabled for the session.

4 . The method according to claim 3 , wherein the method further comprises:

receiving, by the session management function network element, indication information of the user plane security status of the session from an access network device.

5 . The method according to claim 3 , wherein:

the determining, by the session management function network element, that the user plane security protection is not enabled for the session is based on the user plane security status of the session; and

the user plane security status of the session is a non-activated state.

6 . The method according to claim 3 , wherein the method further comprises:

receiving, by the session management function network element, the user plane security policy of the session from a unified data management network element.

7 . The method according to claim 3 , wherein:

the determining, by the session management function network element, that the user plane security protection is not enabled for the session is based on the user plane security policy of the session; and

the user plane security policy of the session is that enabling is not needed.

8 . The method according to claim 1 , wherein the determining, by the session management function network element based on the first security capability indication information, of the first server that supports establishment of the secure connection comprises:

sending, by the session management function network element, a request message to a network repository function network element, wherein the request message comprises the first security capability indication information, and the request message is configured to request to discover a server that supports the secure connection; and receiving, by the session management function network element, a response message of the request message from the network repository function network element, wherein the response message comprises the information about the first server.

9 . The method according to claim 1 , wherein the determining, by the session management function network element based on the first security capability indication information, of the first server that supports establishment of the secure connection comprises:

sending, by the session management function network element, a request message to a network repository function network element, wherein the request message is configured to request to discover a server;

receiving, by the session management function network element, a response message of the request message from the network repository function network element, wherein the response message comprises the information about the first server and second security capability indication information, and the second security capability indication information indicates that the first server supports the secure connection or supports activation of the secure connection; and

determining, by the session management function network element, the first server based on the second security capability indication information and the first security capability indication information.

10 . The method according to claim 9 , wherein in response to the second security capability indication information indicating that the first server supports activation of the secure connection, the method further comprises:

sending, by the session management function network element, activation indication information to the first server, wherein the activation indication information indicates the first server to activate the secure connection.

11 . The method according to claim 10 , wherein the method further comprises:

sending, by the session management function network element, the activation indication information to the first server based on local second security capability indication information, wherein the activation indication information indicates the first server to activate the secure connection, and the second security capability indication information indicates that the first server supports activation of the secure connection.

12 . The method according to claim 1 , wherein the sending, by the session management function network element, information about the first server to the terminal device to establish the secure connection comprises:

sending, by the session management function network element, a session establishment accept message to the terminal device, wherein the session establishment accept message comprises the information about the first server; or

sending, by the session management function network element, a session modification command to the terminal device, wherein the session modification command comprises the information about the first server.

13 . The method according to claim 1 , wherein the information about the first server comprises at least one of an identifier of the first server, a security protocol supported by the first server, a security mechanism supported by the first server, a credential for verifying the first server, and a port number of the first server.

14 . An apparatus, comprising a processor and a memory, wherein the memory is coupled to the processor and configured to store instructions that are executable by the processor to cause the apparatus to:

receive first security capability indication information from a terminal device, wherein the first security capability indication information indicates that the terminal device supports establishment of a secure connection between the terminal device and a server;

determine, based on the first security capability indication information, a first server that supports establishment of the secure connection; and

send information about the first server to the terminal device to establish the secure connection.

15 . The apparatus according to claim 14 , wherein the apparatus is further caused to:

in response to determining that user plane security protection is not enabled for a session of the terminal device, determine the first server based on the first security capability indication information, wherein the session is configured for transmission of data between the terminal device and the first server.

16 . The apparatus according to claim 15 , wherein the apparatus is further caused to:

determine, based on a user plane security status of the session or a user plane security policy of the session, that user plane security protection is not enabled for the session.

17 . The apparatus according to claim 16 , wherein the apparatus is further caused to:

receive indication information of the user plane security status of the session from an access network device; or

receive the user plane security policy of the session from a unified data management network element.

18 . The apparatus according to claim 16 , wherein the apparatus is further caused to:

determine, based on the user plane security status of the session being a non-activated state, that user plane security protection is not enabled for the session; or

determine, based on the user plane security policy of the session being that enabling is not needed, that user plane security protection is not enabled for the session.

19 . A non-transitory computer-readable medium, comprising instructions which are executable by an apparatus to cause the apparatus to:

receive first security capability indication information from a terminal device, wherein the first security capability indication information indicates that the terminal device supports establishment of a secure connection between the terminal device and a server;

determine, based on the first security capability indication information, a first server that supports establishment of the secure connection; and

send information about the first server to the terminal device to establish the secure connection.

20 . The non-transitory computer-readable medium according to claim 19 , wherein the apparatus is further caused to:

in response to determining that user plane security protection is not enabled for a session of the terminal device, determine the first server based on the first security capability indication information, wherein the session is configured for transmission of data between the terminal device and the first server.

Assignments (2)
SECURITY INTEREST Recorded Aug 1, 2025
From: APPLIED OPTOELECTRONICS, INC.
To: BOKF, NA D/B/A BOK FINANCIAL
Reel/Frame 072338/0695 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2024
From: WU, YIZHUANG
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 069618/0243 →
Priority Claims (1)
CN 202110915945.6 · Aug 10, 2021 · national
Continuity (2)
Continuation PCTCN2022110832 · Aug 8, 2022
Related Publication 20240179516A1 · May 30, 2024
References Cited (28)
US 10785652B1 · Ravindranath · 2020 [cited by examiner]
US 20200068391A1 · Liu · 2020 [cited by examiner]
US 20200196101A1 · Edge · 2020 [cited by examiner]
US 20210112049A1 · Yigit · 2021 [cited by examiner]
US 20210127386A1 · Edge · 2021 [cited by examiner]
US 20210168594A1 · Wu et al. · 2021 [cited by applicant]
US 20210176640A1 · Rajadurai · 2021 [cited by examiner]
US 20210360565A1 · Agrawal · 2021 [cited by examiner]
US 20210392477A1 · Taft · 2021 [cited by examiner]
US 20220070855A1 · Zhang · 2022 [cited by examiner]
US 20220086632A1 · Wang · 2022 [cited by examiner]
US 20220095260A1 · Shan · 2022 [cited by examiner]
US 20220104154A1 · Wei · 2022 [cited by examiner]
US 20220116908A1 · Chun · 2022 [cited by examiner]
US 20220116964A1 · Islam · 2022 [cited by examiner]
US 20220141662A1 · Liao · 2022 [cited by examiner]
US 20230370423A1 · Muñoz De La Torre Alonso · 2023 [cited by examiner]
Kim, Kihong et al. New secure session resume protocol using IV count for wireless networks. 2005 IEEE 16th International Symposium on Personal, Indoor and Mobile Radio Communications. https://ieeexplore.ieee.org/stamp/s… [cited by examiner]
Fries, Steffen; Suhr, Andre. Securing Telecontrol in Smart Grid Environments. International ETG-Congress 2013; Symposium 1: Security in Critical Infrastructures Today. https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arn… [cited by examiner]
Al-Jarrah, Mohammad; Tamimi, Abdel-karim R. A Thin Security Layer Protocol over IP Protocol on TCP/IP Suite for Security Enhancement. 2006 Innovations in Information Technology. https://ieeexplore.ieee.org/stamp/stamp.j… [cited by examiner]
3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; 5G System Enhancements for Edge Computing; Stage 2 (Release 17). 3GPP TS 23.548 V0.1.0 (Mar. 2021). total 32 pages. [cited by applicant]
Lenovo et al:“KI #1, Sol #22: update on LDNSR as standalone NF.”3GPP TSG-SA2 Meeting #140E, Oct. 12-23, 2020, Electronic. S2-2007699, total 10 pages. [cited by applicant]
Ericsson, Deutsche Telekom:“Connectivity Models for Edge Computing.”3GPP TSG-SA/WG2 Meeting #136-AH, Jan. 13-17, 2020, Incheon, Korea. S2-2001548, total 5 pages. [cited by applicant]
Ericsson:“IP Address Translation. ”3GPP TSG-SA2 # 142E (e-meeting) Nov. 16-20, 2020, Elbonia. S2-2008492, total 4 pages. [cited by applicant]
Vodafone (Rapporteur):“Minutes of UPIP discussion in SA3 #99.”3GPP TSG-SA3 Meeting #99Bis-e, e-meeting, May 11-15, 2020. Draft 3 S3-201429, total 33 pages. [cited by applicant]
International Search Report dated Nov. 11, 2022, issued for International Application No. PCT/CN2022/110832 (11 pages). [cited by applicant]
Examination Report dated Jan. 14, 2025, issued for Australian Application No. 2022327451 (4 pages). [cited by applicant]
Extended European Search Report dated Sep. 30, 2024, issued for European Application No. 22855376.4. [cited by applicant]