US 12,218,983 B2
Security protection method and apparatus, and access network device
He Li, Shanghai (CN); Jing Chen, Shanghai (CN); Liwei Qiu, Shenzhen (CN); and Chong Lou, Shanghai (CN)
Assigned to Huawei Technologies Co., Ltd., Shenzhen (CN)
Filed by HUAWEI TECHNOLOGIES CO., LTD., Guangdong (CN)
Filed on Aug. 11, 2020, as Appl. No. 16/990,317.
Application 16/990,317 is a continuation of application No. PCT/CN2019/074281, filed on Jan. 31, 2019.
Claims priority of application No. 201810143062.6 (CN), filed on Feb. 11, 2018.
Prior Publication US 2020/0374320 A1, Nov. 26, 2020
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01); H04W 12/02 (2009.01); H04W 76/15 (2018.01); H04W 76/27 (2018.01)
CPC H04L 63/205 (2013.01) [H04W 12/02 (2013.01); H04W 76/15 (2018.02); H04W 76/27 (2018.02); H04L 63/0428 (2013.01)] 18 Claims
OG exemplary drawing
 
1. A security protection method, comprising:
obtaining, by a master station, a user plane security policy of a session of a terminal, wherein the user plane security policy indicates whether two types of user plane security protection are enabled, wherein the two types of user plane security protection comprise user plane encryption protection and user plane integrity protection, and wherein the master station communicates with a secondary station under a dual connectivity scenario;
sending, by the master station to the secondary station, a first message comprising the user plane security policy, security capability of the terminal, and granularity information corresponding to the user plane security policy, wherein the granularity information comprises a session identifier indicating the session, and wherein the security capability includes at least a security algorithm supported by the terminal;
receiving, by the secondary station, the first message from the master station;
determining, by the secondary station, a user plane security algorithm based on the user plane security policy and the security capability;
sending, by the secondary station to the master station, a second message comprising an indication indicating a type of user plane security protection enabled by the secondary station; and
receiving, by the master station, the second message from the secondary station.