-
公开(公告)号:US20230239686A1
公开(公告)日:2023-07-27
申请号:US18193007
申请日:2023-03-30
Applicant: HUAWEI TECHNOLOGIES CO., LTD.
IPC: H04W12/033 , H04W12/08
CPC classification number: H04W12/033 , H04W12/08
Abstract: A secure communication method includes a second terminal device that receives a first request message about a first terminal device from a relay, the first request message includes a PC5 user plane security policy of the first terminal device and a PC5 user plane security policy of the relay; determines first information according to a PC5 user plane security policy of the second terminal device, the PC5 user plane security policy of the first terminal device, and the PC5 user plane security policy of the relay; and sends the first information to the relay, the first information indicates a user plane security protection method of a first PC5 link and a user plane security protection method of a second PC5 link, where the user plane security protection method of the first PC5 link is the same as the user plane security protection method of the second PC5 link.
-
公开(公告)号:US20220174063A1
公开(公告)日:2022-06-02
申请号:US17674607
申请日:2022-02-17
Applicant: Huawei Technologies Co., Ltd.
IPC: H04L9/40
Abstract: A communication method, apparatus, and system are provided, to resolve problems in a conventional technology that an AKMA authentication procedure is complex and signaling overheads are large. Principles of the method are as follows: In a registration procedure of a terminal device, AKMA authentication is implicitly indicated based on primary authentication. For example, if primary authentication succeeds, it may be considered that AKMA authentication also succeeds. In addition, an AKMA temporary identifier is allocated to the terminal device after AKMA authentication succeeds. According to the method, apparatus, and system in this application, no additional AKMA authentication is required. This simplifies a procedure and reduces signaling overheads.
-
公开(公告)号:US20200322798A1
公开(公告)日:2020-10-08
申请号:US16909601
申请日:2020-06-23
Applicant: HUAWEI TECHNOLOGIES CO., LTD.
Abstract: Embodiments of the present disclosure disclose a network roaming protection method and related device. The method includes: receiving, by a visited session management device, a first session establishment request that includes a first security requirement; obtaining, by the visited session management device, a target security policy, where the target security policy is obtained by processing the first security requirement set and a second security requirement set using a preset rule; and sending the target security policy to the UE instructing the UE to generate a target shared key based on a reference shared key and according to a rule defined by the target security policy, where the target shared key is used to protect secure end-to-end data transmission between the UE and the visited gateway.
-
公开(公告)号:US20190141531A1
公开(公告)日:2019-05-09
申请号:US16221566
申请日:2018-12-16
Applicant: HUAWEI TECHNOLOGIES CO., LTD.
Inventor: Rong WU , Lu GAN , Haiguang WANG
Abstract: Embodiments of the present invention disclose a vertical industry user system, including a service provider device, a terminal, a core network element, and a base station. The core network element is configured to: obtain a distribution instruction; and according to the distribution instruction, configure a core network identification number for the core network element, distribute a provider identification number to the service provider device, and distribute a base station identification number to the base station. The service provider device is configured to receive the provider identification number. The base station is configured to receive the base station identification number. The embodiments of the present invention further provide an identification number distribution method.
-
公开(公告)号:US20240373323A1
公开(公告)日:2024-11-07
申请号:US18773740
申请日:2024-07-16
Applicant: HUAWEI TECHNOLOGIES CO., LTD.
Inventor: Longhua GUO , Rong WU
Abstract: Embodiments of this application provide service verification methods, communication apparatuses, and communication systems. In an implementation, a method includes receiving identification information of a service from a terminal device, sending a request to a network element, where the request includes identification information of the terminal device and the identification information of the service, and the request is used to request to verify whether to allow the terminal device to use the service, and receiving a verification result from the network element.
-
公开(公告)号:US20240073681A1
公开(公告)日:2024-02-29
申请号:US18502410
申请日:2023-11-06
Applicant: HUAWEI TECHNOLOGIES CO., LTD.
IPC: H04W12/033 , H04W12/10
CPC classification number: H04W12/033 , H04W12/10
Abstract: This application provides security activation methods and communication apparatuses. In an example method, a first access network device in a first communication standard requests a second access network device in a second communication standard to allocate a resource for dual connectivity of a terminal device, and sends, to the second access network device, a user plane security policy. The first access network device further receives identification information of a bearer and a security activation status from the second access network device and sends the identification information of the bearer and the security activation status to the terminal device.
-
公开(公告)号:US20230319554A1
公开(公告)日:2023-10-05
申请号:US18311998
申请日:2023-05-04
Applicant: HUAWEI TECHNOLOGIES CO., LTD.
Inventor: Longhua GUO , Yuanping ZHU , Li HU , Rong WU
IPC: H04W12/041 , H04W12/069
CPC classification number: H04W12/041 , H04W12/069
Abstract: A key generation method and an apparatus are provided. One example key generation method includes the following steps: determining, by a communication apparatus, that a master base station or a secondary base station serves as an integrated access and backhaul (IAB) donor, wherein the master base station and the secondary base station are connected to an IAB node; and performing at least one of the following when the master base station serves as the IAB donor, generating, by the communication apparatus, an IAB key KIAB based on a master base station key; or when the secondary base station serves as the IAB donor, generating, by the communication apparatus, the IAB key KIAB based on a secondary base station key.
-
公开(公告)号:US20230239689A1
公开(公告)日:2023-07-27
申请号:US18191944
申请日:2023-03-29
Applicant: HUAWEI TECHNOLOGIES CO., LTD.
IPC: H04W12/041 , H04W12/06
CPC classification number: H04W12/041 , H04W12/06
Abstract: A key derivation method, an apparatus, and a system. The method includes: user equipment (UE) receives an authentication success message from a mobility management function network element, generates a master session key (MSK) and an extended master session key (EMSK) based on the authentication success message; and determines whether an authentication device is located outside a 3rd generation partnership project (3GPP) network, to determine whether to obtain Kausf based on the EMSK or the MSK. Therefore, the UE can be compatible with a key derivation manner used when the authentication device is located outside the 3GPP network and a key derivation manner used when the authentication device is located inside the 3GPP network.
-
公开(公告)号:US20230188993A1
公开(公告)日:2023-06-15
申请号:US18163938
申请日:2023-02-03
Applicant: HUAWEI TECHNOLOGIES CO., LTD.
Inventor: Ao LEI , He LI , Yizhuang WU , Rong WU
Abstract: Embodiments of this application provide a communication method and an apparatus to resolve a PC5 unicast establishment failure due to inconsistency between security parameters of terminal devices in a V2X scenario with security negotiation introduced into a PC5 unicast establishment procedure. The communication method includes: A first direct communication discovery name management function network element obtains a security parameter of a first terminal device. A security parameter is required for establishing a PC5 connection between the first terminal device and a second terminal device. The first direct communication discovery name management function network element receives a security parameter of the second terminal device from a second direct communication discovery name management function network element and determines, based on whether the security parameter of the first terminal device matches the security parameter of the second terminal device, whether the first terminal device and the second terminal device support mutual communication.
-
公开(公告)号:US20230188519A1
公开(公告)日:2023-06-15
申请号:US18105597
申请日:2023-02-03
Applicant: HUAWEI TECHNOLOGIES CO., LTD.
CPC classification number: H04L63/0853 , G06F9/547
Abstract: This application provides a method and an apparatus for invoking an API. The method includes: An API-providing network element receives an API-invoking request for a target application from an application server, where the API-invoking request is for requesting to operate information of a terminal device, and includes a first identifier of the terminal device and an identifier of the target application on the application server side; obtains an authorization result based on the first identifier of the terminal device and the identifier of the target application on an application server side, where the authorization result indicates whether the application server is allowed to operate the information of the terminal device; and determines, based on the authorization result, whether to allow the application server to operate the information of the terminal device.
-
-
-
-
-
-
-
-
-