Processing method and apparatus for integrity protection, related device and storage medium
By adjusting the integrity protection parameters on both the terminal and network sides, the problem of excessive power consumption of the terminal at high or full speeds was solved, achieving a match between the terminal's capabilities and the network's transmission rate, thus avoiding packet loss and link interruption.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-04-14
- Publication Date
- 2026-03-20
AI Technical Summary
As terminal computing power increases, some terminals may consume excessive power or exceed their capacity when performing high-speed or full-speed integrity protection, leading to problems such as data packet loss, integrity protection failure, and link interruption.
By adjusting relevant parameters for integrity protection at both the terminal and network sides, including rate, algorithm, and packet interval, it is possible to ensure that the terminal capabilities match the network transmission rate and avoid adverse consequences.
It effectively avoids packet loss, integrity protection failure, and link interruption, ensuring the stability of the terminal during the user plane integrity protection process.
Smart Images

Figure CN113596843B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of wireless communication, and in particular to a method and apparatus for integrity protection, related devices and storage media. BACKGROUND
[0002] In the fifth generation mobile communication technology (5G), integrity protection of user plane data is introduced (which can be referred to as integrity protection for short), but due to the processing capability of the terminal, not all terminals can send at the maximum rate, so the related technology requires integrity protection at a rate of 64 kbps, which is mandatory, and integrity protection at the full rate is an optional function.
[0003] With the development of terminal technology, the computing power of terminals is gradually improving, so more terminals will support integrity protection at a higher rate, and will be able to support integrity protection of data packets at a higher rate. When the terminal is currently unable to support the above capability due to some reasons, it will cause problems such as data packet loss, integrity protection failure, and even link interruption. SUMMARY
[0004] To solve the problems in the related art, the embodiments of the present application provide a method and apparatus for integrity protection, related devices and storage media.
[0005] The technical solutions of the embodiments of the present application are implemented as follows:
[0006] At least one embodiment of the present application provides a processing method for integrity protection, applied to a first communication node, comprising:
[0007] receiving first information sent by a second communication node;
[0008] adjusting related parameters of integrity protection by using the received first information.
[0009] In addition, according to at least one embodiment of the present application, the first information sent by the second communication node is received by one of the following ways:
[0010] a packet data convergence protocol (PDCP) protocol data unit (PDU);
[0011] a radio resource control (RRC) signaling;
[0012] a media access control layer control element (MAC CE);
[0013] a physical layer resource.
[0014] In addition, according to at least one of the embodiments of the present application, in the case that the first information is sent to the first communication node by the PDCP PDU, the first information is in a header of the PDCP PDU, or the first information is in a data field of the PDCP PDU.
[0015] In addition, according to at least one of the embodiments of the present application, the method further comprises:
[0016] sending second information to the second communication node; the second information is used to instruct the second communication node to adjust the related parameters of the integrity protection of the first communication node.
[0017] In addition, according to at least one of the embodiments of the present application, the second information is sent to the second communication node by one of the following ways:
[0018] PDCP PDU;
[0019] RRC signaling;
[0020] MAC CE;
[0021] Physical layer resource.
[0022] In addition, according to at least one of the embodiments of the present application, in the case that the second information is sent to the second communication node by the PDCP PDU, the second information is in a header of the PDCP PDU, or the first information is in a data field of the PDCP PDU.
[0023] In addition, according to at least one of the embodiments of the present application, the adjusting the related parameters of the integrity protection by using the received first information comprises at least one of the following:
[0024] adjusting the integrity protection rate by using the first information;
[0025] adjusting the integrity protection algorithm by using the first information;
[0026] adjusting the interval of the data packets to be integrity protected by using the first information.
[0027] In addition, according to at least one of the embodiments of the present application, the first information comprises at least one of the following:
[0028] a first integrity protection rate; the first integrity protection rate is used for the first communication node to adjust the integrity protection rate to the first integrity protection rate;
[0029] a difference between the current integrity protection rate and the first integrity protection rate; the difference is used for the first communication node to adjust the integrity protection rate to the first integrity protection rate;
[0030] a first integrity protection rate corresponding to the first integrity protection rate; and a first integrity protection rate corresponding to the first integrity protection rate is used for the first communication node to adjust the integrity protection rate to the first integrity protection rate corresponding to the first integrity protection rate.
[0031] a first integrity protection algorithm; the first integrity protection algorithm is used for the first communication node to adjust the integrity protection algorithm to the first integrity protection algorithm.
[0032] a first data packet interval; the first data packet interval is used for the first communication node to adjust the interval of the data packet to be integrity protected to N; N is an integer greater than or equal to zero.
[0033] In addition, according to at least one embodiment of the present application, the method further comprises:
[0034] sending the capability information to the second communication node; the capability information indicates the related capability of integrity protection supported by the first communication node.
[0035] In addition, according to at least one embodiment of the present application, the capability information contains at least one of the following:
[0036] the maximum integrity protection rate supported by the first communication node;
[0037] at least one integrity protection algorithm supported by the first communication node; each integrity protection algorithm in the at least one integrity protection algorithm corresponds to a different integrity protection rate;
[0038] an integrity protection rate corresponding to the maximum integrity protection rate supported by the first communication node.
[0039] In addition, according to at least one embodiment of the present application, in the case that the capability information contains the maximum integrity protection rate supported by the terminal, the capability information further contains one of the following:
[0040] the sum of the integrity protection rates of the plurality of data radio bearers (DRBs) does not exceed the maximum integrity protection rate;
[0041] the sum of the integrity protection rates of the plurality of DRBs does not exceed the maximum integrity protection rate, and the integrity protection rate of each DRB in the plurality of DRBs cannot exceed a first value;
[0042] the sum of the integrity protection rates of the plurality of DRBs exceeds the maximum integrity protection rate;
[0043] the sum of the integrity protection rates of the plurality of DRBs exceeds the maximum integrity protection rate, and the integrity protection rate of each DRB in the plurality of DRBs cannot exceed a first value.
[0044] Further, according to at least one of the embodiments of the present application, in a case where the capability information contains at least one integrity protection algorithm supported by the first communication node, the capability information further contains one of the following:
[0045] The maximum integrity protection rate corresponding to the number of DRBs subjected to integrity protection corresponding to each integrity protection algorithm.
[0046] Further, according to at least one of the embodiments of the present application, the related parameter of integrity protection is adjusted for at least one DRB in the plurality of DRBs.
[0047] At least one of the embodiments of the present application further provides a processing method of integrity protection, applied to a second communication node, comprising:
[0048] sending first information to the first communication node; the first information indicating that the first communication node adjusts the related parameter of integrity protection.
[0049] Further, according to at least one of the embodiments of the present application, the first information is sent to the first communication node by one of the following ways:
[0050] PDCP PDU;
[0051] RRC signaling;
[0052] MAC CE;
[0053] physical layer resource.
[0054] Further, according to at least one of the embodiments of the present application, in a case where the first information is sent to the first communication node by PDCP PDU, the first information is in the packet header of the PDCP PDU, or the first information is in the data field of the PDCP PDU.
[0055] Further, according to at least one of the embodiments of the present application, the method further comprises:
[0056] receiving second information sent by the first communication node; the second information being used to indicate that the second communication node adjusts the related parameter of integrity protection of the first communication node.
[0057] Further, according to at least one of the embodiments of the present application, the second information sent by the first communication node is received by one of the following ways:
[0058] PDCP PDU;
[0059] RRC signaling;
[0060] MAC CE;
[0061] Physical layer resources.
[0062] Furthermore, according to at least one embodiment of this application, when receiving second information sent by the first communication node via a PDCP PDU, the second information is either in the header of the PDCP PDU or in the data field of the PDCP PDU.
[0063] Furthermore, according to at least one embodiment of this application, the first information is used to adjust at least one of the following parameters:
[0064] Integrity protection rate;
[0065] Integrity protection algorithm;
[0066] The interval between data packets for integrity protection.
[0067] Furthermore, according to at least one embodiment of this application, the first information includes at least one of the following:
[0068] The first integrity protection rate; the first integrity protection rate is used for the first communication node to adjust the integrity protection rate to the first integrity protection rate;
[0069] The difference between the current integrity protection rate and the first integrity protection rate; the difference is used by the first communication node to adjust the integrity protection rate to the first integrity protection rate;
[0070] The integrity protection rate level corresponding to the first integrity protection rate; the integrity protection rate level corresponding to the first integrity protection rate is used for the first communication node to adjust the integrity protection rate level to the integrity protection rate level corresponding to the first integrity protection rate.
[0071] A first integrity protection algorithm; the first integrity protection algorithm is used by the first communication node to adjust the integrity protection algorithm to the first integrity protection algorithm;
[0072] The first data packet interval; the first data packet interval is used by the first communication node to adjust the interval of the data packets for integrity protection to N; N is an integer greater than or equal to zero.
[0073] Furthermore, according to at least one embodiment of this application, the method further includes:
[0074] Receive capability information sent by the first communication node; the capability information indicates the integrity protection capabilities supported by the first communication node.
[0075] Furthermore, according to at least one embodiment of this application, the capability information includes at least one of the following:
[0076] a maximum integrity protection rate supported by the first communication node;
[0077] at least one integrity protection algorithm supported by the first communication node, each of the at least one integrity protection algorithm corresponding to a different integrity protection rate;
[0078] the maximum integrity protection rate supported by the first communication node corresponds to an integrity protection rate level.
[0079] In addition, according to at least one embodiment of the present application, when the capability information contains the maximum integrity protection rate supported by the terminal, the capability information further contains one of the following:
[0080] the sum of the integrity protection rates of the plurality of DRBs does not exceed the maximum integrity protection rate;
[0081] the sum of the integrity protection rates of the plurality of DRBs exceeds the maximum integrity protection rate, and the integrity protection rate of each DRB in the plurality of DRBs cannot exceed a first value.
[0082] the sum of the integrity protection rates of the plurality of DRBs exceeds the maximum integrity protection rate;
[0083] the sum of the integrity protection rates of the plurality of DRBs exceeds the maximum integrity protection rate, and the integrity protection rate of each DRB in the plurality of DRBs cannot exceed a first value.
[0084] In addition, according to at least one embodiment of the present application, when the capability information contains the at least one integrity protection algorithm supported by the first communication node, the capability information further contains one of the following:
[0085] the maximum integrity protection rate corresponding to the number of DRBs subjected to integrity protection corresponding to each of the integrity protection algorithms.
[0086] In addition, according to at least one embodiment of the present application, the first information is used for the terminal to adjust related parameters of integrity protection for at least one DRB in the plurality of DRBs.
[0087] At least one embodiment of the present application further provides a processing device for integrity protection, comprising:
[0088] a first receiving unit configured to receive first information sent by a second communication node;
[0089] an adjusting unit configured to adjust related parameters of integrity protection by using the received first information.
[0090] At least one embodiment of the present application further provides a processing device for integrity protection, comprising:
[0091] a second sending unit, configured to send first information to the first communication node, wherein the first information indicates the first communication node to adjust a related parameter of the integrity protection.
[0092] At least one embodiment of the present application further provides a first communication node, comprising:
[0093] a first communication interface, configured to receive first information sent by a second communication node;
[0094] a first processor, configured to adjust a related parameter of the integrity protection by using the received first information.
[0095] At least one embodiment of the present application further provides a second communication node, comprising a second communication interface and a second processor, wherein:
[0096] the second communication interface is configured to send first information to the first communication node, wherein the first information indicates the first communication node to adjust a related parameter of the integrity protection.
[0097] At least one embodiment of the present application further provides a first communication node, comprising a first processor and a first memory for storing a computer program capable of running on the processor,
[0098] wherein the first processor is configured to execute steps of any method on the first communication node side when running the computer program.
[0099] At least one embodiment of the present application further provides a second communication node, comprising a second processor and a second memory for storing a computer program capable of running on the processor,
[0100] wherein the second processor is configured to execute steps of any method on the second communication node side when running the computer program.
[0101] At least one embodiment of the present application further provides a storage medium having a computer program stored thereon, wherein the computer program is executed by a processor to implement steps of any method on the first communication node side or steps of any method on the second communication node side.
[0102] The method, device, related equipment and storage medium for integrity protection provided by the embodiments of the present application are as follows: a second communication node sends first information to a first communication node; and the first communication node adjusts related parameters for integrity protection by using the received first information. By adjusting the related parameters for integrity protection, the occurrence of adverse consequences such as data packet loss, integrity protection failure and even link interruption due to insufficient terminal capability during the process of user plane integrity protection can be avoided in time. BRIEF DESCRIPTION OF DRAWINGS
[0103] Figure 1 A processing method flowchart for integrity protection on the side of a first communication node according to an embodiment of the present application is shown in the figure.
[0104] Figure 2 A PDCP PDU format according to an embodiment of the present application is shown in the figure.
[0105] Figure 3 A processing method flowchart for integrity protection according to an embodiment of the present application is shown in the figure.
[0106] Figure 4 A processing method flowchart for integrity protection on the side of a terminal according to an embodiment of the present application is shown in the figure.
[0107] Figure 5 A processing method flowchart for integrity protection according to a second embodiment of the present application is shown in the figure.
[0108] Figure 6 A processing method flowchart for integrity protection on the side of a network device according to an embodiment of the present application is shown in the figure.
[0109] Figure 7 A processing method flowchart for integrity protection according to a third embodiment of the present application is shown in the figure.
[0110] Figure 8 A processing device structure for integrity protection according to an embodiment of the present application is shown in the figure.
[0111] Figure 9 Another processing device structure for integrity protection according to an embodiment of the present application is shown in the figure.
[0112] Figure 10 A first communication node structure according to an embodiment of the present application is shown in the figure.
[0113] Figure 11 A second communication node structure according to an embodiment of the present application is shown in the figure.
[0114] Figure 12 A processing system structure for integrity protection according to an embodiment of the present application is shown in the figure. DETAILED DESCRIPTION
[0115] The application will be described in further detail below with reference to the drawings and embodiments.
[0116] With the progress of terminals, the computing capability is gradually improved, so more terminals can support integrity protection for user plane data at a higher rate, even at full rate. When the terminal performs integrity protection at a higher rate, or at full rate, the terminal power consumption can be too high, or exceed the current maximum capability of the terminal, so the terminal cannot maintain the current integrity protection rate, but the network side continues to use the rate to transmit user plane data, which will result in packet loss, integrity protection failure, or even link termination, etc.
[0117] Therefore, in various embodiments of the application, when the terminal power consumption is too high, or exceeds the current integrity protection capability, or enters the energy saving mode, etc., the terminal and / or the network side adjusts the related parameters of the integrity protection, so that the integrity protection matches the current capability of the terminal, to avoid the above-mentioned adverse consequences.
[0118] Of course, when the above-mentioned conditions of the terminal do not exist, the terminal and / or the network side can also adjust the related parameters of the integrity protection, so that the integrity protection matches the current capability of the terminal.
[0119] In the embodiments of the application, the integrity protection rate refers to the rate that can be reached when the terminal and the network side start user plane integrity protection (start integrity protection for user plane data), which can also be understood as the rate used when the terminal and the network side start user plane integrity protection.
[0120] The embodiments of the application provide a processing method for integrity protection, applied to a first communication node, such as a network device, as shown in the figure, the method comprises the following steps: Figure 1
[0121] Step 101: receiving first information sent by a second communication node;
[0122] Step 102: adjusting the related parameters of the integrity protection by using the received first information.
[0123] Here, in actual application, the communication node that performs integrity protection refers to a data sending device, i.e. a device that wants to send data, specifically, in the downlink direction, the first communication node is a network device, such as a base station, and the second communication node is a terminal; in the uplink direction, the first communication node is a terminal, and the second communication device is a network device.
[0124] The communication node can also be understood as a communication device.
[0125] In an embodiment, the first information sent by the second communication node can be received by one of the following ways:
[0126] PDCP PDU;
[0127] RRC signaling;
[0128] MAC CE;
[0129] Physical layer resource.
[0130] In actual application, in the case that the second communication node sends the first information to the first communication node by PDCP PDU (the first communication node receives the first information sent by the second communication node by PDCP PDU), that is, if the second communication node sends the first information to the first communication node by PDCP PDU, the first information is in the header of the PDCP PDU, or the first information is in the data field (also can be understood as Data bit) of the PDCP PDU, of course, the first information can also be in other positions in the PDCP PDU.
[0131] Here, when the first information is in the header of the PDCP PDU, as shown in Figure 2 , the first information can be set in the reserved bit (also can be understood as reserved field).
[0132] When the first communication node is a terminal and the second communication node is a network device, the terminal can request the network side to adjust the related parameters of the integrity protection.
[0133] Based on this, in an embodiment, the method can further include:
[0134] sending second information to the second communication node; the second information is used to indicate the second communication node to adjust the related parameters of the integrity protection of the first communication node, and can also be understood as the second information is used to request the second communication node to adjust the related parameters of the integrity protection of the first communication node.
[0135] In an embodiment, the second information is sent to the second communication node by one of the following ways:
[0136] PDCP PDU;
[0137] RRC signaling;
[0138] MAC CE;
[0139] Physical layer resource.
[0140] Here, in the case that the second information is sent to the second communication node by PDCP PDU, the second information is in the header of the PDCP PDU, or the first information is in the data field of the PDCP PDU; of course, the second information can also be in other positions in the PDCP PDU.
[0141] In an embodiment, the implementation of step 102 can comprise at least one of the following:
[0142] adjusting the integrity protection rate using the first information;
[0143] adjusting the integrity protection algorithm using the first information;
[0144] adjusting the interval of data packets to be integrity protected using the first information.
[0145] That is, the first information is used to adjust at least one of the following parameters:
[0146] the integrity protection rate;
[0147] the integrity protection algorithm;
[0148] the interval of data packets to be integrity protected.
[0149] In an embodiment, the first information comprises at least one of the following:
[0150] a first integrity protection rate; the first integrity protection rate is used for the first communication node to adjust the integrity protection rate to the first integrity protection rate;
[0151] a difference between the current integrity protection rate and the first integrity protection rate; the difference is used for the first communication node to adjust the integrity protection rate to the first integrity protection rate;
[0152] an integrity protection rate level corresponding to the first integrity protection rate; the integrity protection rate level corresponding to the first integrity protection rate is used for the first communication node to adjust the integrity protection rate level to the integrity protection rate level corresponding to the first integrity protection rate;
[0153] a first integrity protection algorithm; the first integrity protection algorithm is used for the first communication node to adjust the integrity protection algorithm to the first integrity protection algorithm;
[0154] a first data packet interval; the first data packet interval is used for the first communication node to adjust the interval of data packets to be integrity protected to N; N is an integer greater than or equal to zero.
[0155] When the first communication node is a terminal and the second communication node is a network device, the first communication node can send its capability to the network side, so that the second communication node can indicate the related parameters of the integrity protection of the terminal based on the capability information, i.e., can determine the first information based on the capability information.
[0156] Based on this, in an embodiment, the method can further include:
[0157] sending the capability information to the second communication node; the capability information indicating the related capability of the integrity protection supported by the first communication node.
[0158] In an embodiment, the capability information includes at least one of the following:
[0159] the maximum integrity protection rate supported by the first communication node;
[0160] at least one integrity protection algorithm supported by the first communication node; each of the at least one integrity protection algorithm corresponds to a different integrity protection rate;
[0161] the maximum integrity protection rate supported by the first communication node corresponds to an integrity protection rate level.
[0162] When the first communication node has only one DRB, the integrity protection rate M can be used, but when two DRBs need to be integrity protected, the integrity rates M1 and M2 of the two DRBs will decrease compared to M, i.e., M1 and M2 are both less than M, and whether the sum of M1 and M2 can exceed M depends on the capability of the first communication node.
[0163] Based on this, in an embodiment, when the capability information includes the maximum integrity protection rate supported by the terminal, the capability information further includes one of the following:
[0164] the sum of the integrity protection rates of the multiple DRBs does not exceed the maximum integrity protection rate;
[0165] the sum of the integrity protection rates of the multiple DRBs does not exceed the maximum integrity protection rate, and the integrity protection rate of each DRB in the multiple DRBs cannot exceed a first value;
[0166] the sum of the integrity protection rates of the multiple DRBs exceeds the maximum integrity protection rate;
[0167] the sum of the integrity protection rates of the multiple DRBs exceeds the maximum integrity protection rate, and the integrity protection rate of each DRB in the multiple DRBs cannot exceed a first value.
[0168] The first value can be set as needed.
[0169] Here, since the integrity protection is configured for each DRB, the first information is used for the first communication node to adjust the related parameters of the integrity protection for at least one DRB in the plurality of DRBs. That is, the first communication node adjusts the related parameters of the integrity protection for at least one DRB in the plurality of DRBs.
[0170] In actual application, for each integrity protection algorithm, when the number of DRBs for integrity protection is different, the corresponding maximum integrity protection rate needs to be limited. For example, assuming that for integrity protection algorithm A, when there is 1 DRB for integrity protection, the limited maximum rate is A1, and when there are 2 DRBs for integrity protection, the limited maximum rate is A2; for integrity protection algorithm B, when there is 1 DRB for integrity protection, the limited maximum rate is B1, and when there are 2 DRBs for integrity protection, the limited maximum rate is B2.
[0171] Based on this, in an embodiment, when the capability information comprises at least one integrity protection algorithm supported by the first communication node, the capability information further comprises one of the following:
[0172] The maximum integrity protection rate corresponding to the number of DRBs for integrity protection corresponding to each integrity protection algorithm.
[0173] Correspondingly, the embodiment of the present application further provides a processing method of integrity protection, applied to a second communication node, comprising:
[0174] sending first information to the first communication node; the first information indicating the first communication node to adjust the related parameters of the integrity protection.
[0175] In an embodiment, the first information is sent to the first communication node by one of the following ways:
[0176] PDCP PDU;
[0177] RRC signaling;
[0178] MAC CE;
[0179] Physical layer resource.
[0180] In an embodiment, when the first information is sent to the first communication node by PDCP PDU, the first information is in the packet header of the PDCP PDU, or the first information is in the data field of the PDCP PDU.
[0181] In an embodiment, the method can further comprise:
[0182] receiving second information sent by the first communication node; the second information is used to indicate that the second communication node adjusts the related parameter of the integrity protection of the first communication node.
[0183] In an embodiment, the second information sent by the first communication node is received by one of the following ways:
[0184] PDCP PDU;
[0185] RRC signaling;
[0186] MAC CE;
[0187] physical layer resource.
[0188] Here, in an embodiment, when the second information sent by the first communication node is received by PDCP PDU, the second information is in the header of the PDCP PDU, or the second information is in the data field of the PDCP PDU.
[0189] In an embodiment, the method can further include:
[0190] receiving the capability information sent by the first communication node; the capability information indicates the related capability of the integrity protection supported by the first communication node.
[0191] It should be noted that: in actual application, the first information and the second information can be called as indication information, or auxiliary information, or request information, or integrity protection adjustment information, etc., and the embodiments of the present application do not limit this.
[0192] The embodiments of the present application provide a processing method of integrity protection, as shown in Figure 3 The method includes:
[0193] Step 301: the second communication node sends the first information to the first communication node.
[0194] Step 302: the first communication node adjusts the related parameter of the integrity protection by using the received first information.
[0195] It should be noted that the specific processing process of the first communication node and the second communication node has been described in detail above, and will not be repeated here.
[0196] The method for processing integrity protection provided in the embodiments of the present application comprises: a second communication node sending first information to a first communication node; and the first communication node adjusting relevant parameters of integrity protection by using the received first information. By adjusting the relevant parameters of integrity protection, the method can timely avoid the occurrence of adverse consequences such as data packet loss, integrity protection failure, and even link interruption due to insufficient terminal capability during the process of user plane integrity protection.
[0197] The scheme of the embodiments of the present application is described below from the perspective of adjusting the relevant parameters of integrity protection by the terminal and the network device respectively.
[0198] First, the process of adjusting the relevant parameters of integrity protection by the terminal is described.
[0199] The method for processing integrity protection provided in the embodiments of the present application is applied to a terminal, and as shown in the figure, the method comprises the following steps. Figure 4
[0200] Step 401: receiving first information sent by the network side;
[0201] Step 402: adjusting the relevant parameters of integrity protection by using the first information.
[0202] In actual application, in step 401, when the terminal itself has conditions such as excessively high power consumption, exceeding the current integrity protection capability, or entering the energy saving mode, the terminal can request the network side to adjust the relevant parameters of integrity protection, that is, the terminal requests the network side to adjust the relevant parameters of integrity protection.
[0203] Based on this, in an embodiment, the method can further comprise the following steps.
[0204] Step 403: sending second information to the network side; the second information indicates adjusting the relevant parameters of integrity protection.
[0205] Correspondingly, the terminal receives first information sent by the network side based on the second information.
[0206] Here, in actual application, when the terminal has conditions such as excessively high power consumption, exceeding the current capability, or entering the energy saving mode, the terminal can send second information to the network side, at this time, the second information can request to reduce the integrity protection rate, can request to adjust the integrity protection algorithm to reduce the processing capability of the terminal, and can also request to adjust the interval of data packets for integrity protection to reduce the processing capability of the terminal.
[0207] Of course, when the terminal recovers from the above-mentioned situations to the normal working state, the second information can also be sent to the network side, at this time, the second information can request to increase the integrity protection rate, can request to adjust the integrity protection algorithm to match the processing capability of the terminal, and can also request to adjust the interval of the data packet for integrity protection to match the processing capability of the terminal.
[0208] In an embodiment, the second information can be sent to the network side in one of the following ways:
[0209] PDCP PDU;
[0210] RRC signaling;
[0211] MAC CE;
[0212] Uplink physical layer resources.
[0213] In actual application, in the case of sending the second information to the network side through the PDCP PDU, that is, if the second information is sent to the network side through the PDCP PDU, the second information is in the packet header of the PDCP PDU, or the second information is in the data field of the PDCP PDU (also can be understood as Data bit), of course, the second information can also be in other positions in the PDCP PDU.
[0214] In the case of sending the second information to the network side through the PDCP PDU, the second information can contain at least one of the following information:
[0215] Whether to enable integrity protection information;
[0216] Integrity protection algorithm information;
[0217] Speed adjustment indication information.
[0218] The whether to enable integrity protection information indicates whether the data packet uses integrity protection.
[0219] The integrity protection algorithm information is used to indicate which integrity protection algorithm is used for the data packet;
[0220] The speed adjustment indication information is used to indicate to increase the integrity protection rate or to decrease the integrity protection rate, or to adjust the integrity protection rate to a certain speed gear.
[0221] In the case of sending the second information through the MAC CE, that is, if the second information is sent through the MAC CE, the MAC CE can be a newly defined MAC CE, or an existing MAC CE, and the present application embodiment does not limit this.
[0222] In actual application, the uplink physical layer resource can include uplink control information (UCI). The UCI can be carried in a physical uplink control channel (PUCCH) or a physical uplink shared channel (PUSCH).
[0223] In actual application, the network side can also actively send the first information to the terminal, that is, the terminal does not need to send a request message first, and the network side directly sends the first information.
[0224] Here, the network side can actively send the first information to the terminal according to needs, such as when the network side sends a reconfiguration message to the terminal, when a DRB is added, modified or deleted, the first information can be sent; for example, the network side has reached the maximum processing capacity, at which time the network side can send the first information to the terminal to reduce the processing complexity of the network side; for example, the network side knows that the current capability of the terminal and the current integrity protection parameter cannot be matched according to the obtained data (such as the terminal overheating or overloading, etc.), and actively sends the first information to the terminal to reduce the processing complexity of the terminal.
[0225] In actual application, the network side can send the first information to the terminal by one of the following ways, that is, the terminal receives the first information sent by the network side by one of the following ways:
[0226] PDCP PDU;
[0227] RRC signaling;
[0228] MAC CE;
[0229] Downlink physical layer resource.
[0230] Similarly to the second information, in the case where the network side sends the first information to the terminal through a PDCP PDU, the first information can be in the header of the PDCP PDU, or the first information can be in the data field of the PDCP PDU, or in other positions in the PDCP PDU.
[0231] The downlink physical layer resource can include downlink control information (DCI). The DCI can be carried in a physical downlink control channel (PDCCH).
[0232] In actual application, the related parameters of integrity protection can include an integrity protection rate, so the adjustable integrity protection rate can be adjusted.
[0233] Based on this, in an embodiment, the specific implementation of step 402 can include:
[0234] The integrity protection rate is adjusted by using the first information.
[0235] The first information can include at least one of the following:
[0236] The first integrity protection rate;
[0237] A difference between the current integrity protection rate and the first integrity protection rate;
[0238] An integrity protection rate level corresponding to the first integrity protection rate.
[0239] The first integrity protection rate can be understood as a target integrity protection rate. That is, the integrity protection rate is adjusted to the first integrity protection rate.
[0240] Exemplarily, P (P is an integer greater than or equal to 2) integrity rate levels are set, and the terminal can request to increase or decrease the rate level, and of course, the network side can directly increase or decrease the rate level without the request of the terminal.
[0241] In actual application, the related parameters of the integrity protection can also include an integrity protection algorithm, so the integrity protection algorithm can be adjusted.
[0242] Based on this, in an embodiment, the specific implementation of step 402 can include:
[0243] The integrity protection algorithm is adjusted by using the first integrity protection algorithm included in the first information.
[0244] The first integrity algorithm can be understood as a target integrity protection algorithm. That is, the integrity protection algorithm is adjusted to the first integrity protection algorithm.
[0245] The maximum integrity protection rate corresponding to different integrity algorithms is different, and by adjusting the integrity algorithm, a lower integrity protection complexity can be achieved while maintaining the same integrity protection rate; correspondingly, by adjusting the integrity algorithm, a higher integrity protection rate can be used.
[0246] In actual application, the related parameters of the integrity protection can also include a data packet interval for integrity protection, so the data packet interval for integrity protection can be adjusted.
[0247] Based on this, in an embodiment, the specific implementation of step 402 can include:
[0248] The interval of the data packets for integrity protection is adjusted to N by using the first data packet interval included in the first information; N is an integer greater than or equal to zero.
[0249] That is, the interval of the integrity-protected data packet is adjusted to the target data packet interval. That is, the interval of the integrity-protected data packet is adjusted to the first data packet interval.
[0250] Exemplarily, each data packet can be integrity-protected, the interval of 1 data packet is adjusted to be integrity-protected, or the interval of Q data packets is adjusted to be integrity-protected, to reduce the complexity of integrity protection. Wherein, Q is an integer greater than 1 and less than or equal to N.
[0251] In actual application, at least one of the above-mentioned adjusting the integrity protection rate, adjusting the integrity protection algorithm, and adjusting the interval of the data packet that is integrity-protected can be selected according to the needs to achieve the purpose of adjusting the related parameters of integrity protection.
[0252] In actual application, the terminal can report its capability to the network side, so that the network side can instruct the related parameters of integrity protection of the terminal based on the capability information.
[0253] Based on this, in an embodiment, the method can further include:
[0254] sending the capability information to the network side; the capability information indicates the related capability of integrity protection supported by the terminal.
[0255] In an embodiment, the capability information includes at least one of the following:
[0256] the maximum integrity protection rate supported by the terminal;
[0257] at least one integrity protection algorithm supported by the terminal;
[0258] the integrity protection rate corresponding to each integrity protection algorithm in the at least one integrity protection algorithm is different;
[0259] the integrity protection rate corresponding to the maximum integrity protection rate supported by the terminal.
[0260] Here, since the integrity protection is configured for each DRB, the first information is used for the terminal to adjust the related parameters of integrity protection for at least one DRB in the plurality of DRBs. That is, the terminal adjusts the related parameters of integrity protection for at least one DRB in the plurality of DRBs.
[0261] When the terminal has only one DRB, the integrity protection rate M can be used, but when two DRBs need to be integrity-protected, the integrity rates M1 and M2 of the two DRBs will be lower than M, and whether the sum of M1 and M2 can exceed M depends on the terminal capability.
[0262] Based on this, in an embodiment, in the case that the capability information contains the maximum integrity protection rate supported, the capability information further contains one of the following:
[0263] The sum of the integrity protection rates of the plurality of DRBs does not exceed the maximum integrity protection rate;
[0264] The sum of the integrity protection rates of the plurality of DRBs does not exceed the maximum integrity protection rate, and the integrity protection rate of each DRB in the plurality of DRBs cannot exceed a first value;
[0265] The sum of the integrity protection rates of the plurality of DRBs exceeds the maximum integrity protection rate;
[0266] The sum of the integrity protection rates of the plurality of DRBs exceeds the maximum integrity protection rate, and the integrity protection rate of each DRB in the plurality of DRBs cannot exceed a first value.
[0267] In actual application, for each integrity protection algorithm, when the number of DRBs that are subjected to integrity protection is different, the corresponding maximum integrity protection rate needs to be limited. For example, it is assumed that for integrity protection algorithm A, when there is 1 DRB subjected to integrity protection, the limited maximum rate is A1, and when there are 2 DRBs subjected to integrity protection, the limited maximum rate is A2; for integrity protection algorithm B, when there is 1 DRB subjected to integrity protection, the limited maximum rate is B1, and when there are 2 DRBs subjected to integrity protection, the limited maximum rate is B2.
[0268] Based on this, in an embodiment, in the case that the capability information contains at least one integrity protection algorithm supported by the terminal, the capability information further contains one of the following:
[0269] The maximum integrity protection rate corresponding to each integrity protection algorithm and the number of DRBs subjected to integrity protection.
[0270] Correspondingly, an embodiment of the present application further provides a processing method for integrity protection, applied to a network device, comprising:
[0271] Sending first information to a terminal; the first information is used for the terminal to adjust related parameters of integrity protection.
[0272] In an embodiment, the method can further comprise:
[0273] Receiving second information sent by the terminal;
[0274] Sending first information to the terminal based on the second information.
[0275] Here, in an embodiment, the second information sent by the terminal is received by one of the following ways:
[0276] PDCP PDU;
[0277] RRC signaling;
[0278] MAC CE;
[0279] uplink physical layer resource.
[0280] Specifically, when the terminal sends the second information through a PDCP PDU, the network device receives the second information through the PDCP PDU; when the terminal sends the second information through RRC signaling, the network device receives the second information through the RRC signaling; when the terminal sends the second information through a MAC CE, the network device receives the second information through the MAC CE; and when the terminal sends the second information through an uplink physical layer resource, the network device receives the second information through the uplink physical layer resource.
[0281] In an embodiment, the first information is used to adjust an integrity protection rate.
[0282] In an embodiment, the first information is used to adjust an integrity protection algorithm, and the first information comprises a first integrity protection algorithm.
[0283] In an embodiment, the first information is used to adjust a data interval for integrity protection, and the first information comprises a first data packet interval.
[0284] In an embodiment, the method can further comprise:
[0285] receiving capability information reported by the terminal, wherein the capability information indicates related capabilities of the terminal for supporting integrity protection.
[0286] Correspondingly, an embodiment of the present application further provides a processing method for integrity protection, as shown in Figure 5 the method comprises:
[0287] Step 501: a network device sends first information to a terminal.
[0288] Step 502: the terminal adjusts related parameters for integrity protection by using the received first information.
[0289] It should be noted that the specific processing procedures of the network device and the terminal have been described in the foregoing, and thus will not be described herein.
[0290] As can be seen from the foregoing description, related parameters for integrity protection are adjusted at the terminal side to avoid the occurrence of adverse consequences such as data packet loss, integrity protection failure, and even link interruption.
[0291] In the process, the behavior of the terminal mainly includes:
[0292] The terminal reports the integrity protection rate related capability to the network side, i.e., the related capability of the integrity protection supported by the terminal;
[0293] After the network starts the user plane integrity protection for the terminal, the terminal sends second information to the network side (including: reporting the integrity protection rate to the network side (i.e., the terminal requests to report the integrity protection rate as the integrity protection rate); speed reduction or speed increase request message (the speed reduction request message is used for the terminal to indicate that the current rate has exceeded the integrity protection capability of the terminal, resulting in adverse consequences, and requests to reduce the integrity protection rate; the speed increase request message is used for the terminal to request to increase the integrity protection rate again after the adverse consequences are alleviated)).
[0294] Adjusting the related parameters of the integrity protection.
[0295] The network behavior mainly includes:
[0296] Receiving the integrity protection rate related capability reported by the terminal;
[0297] The network side sends first information to the terminal (the network side requires the terminal to adjust the related parameters of the integrity protection, to realize speed reduction or speed increase, etc.).
[0298] In the embodiment of the application, the terminal receives the first information sent by the network side; and adjusts the related parameters of the integrity protection by using the received first information. By adjusting the related parameters of the integrity protection by the terminal, the occurrence of adverse consequences such as data packet loss, integrity protection failure, and even link interruption due to insufficient terminal capability during the integrity protection process can be avoided in time.
[0299] Then, the process of adjusting the related parameters of the integrity protection by the network side is described. By adjusting the related parameters of the integrity protection by the network side, the occurrence of adverse consequences such as data packet loss, integrity protection failure, and even link interruption can also be avoided.
[0300] Based on this, the embodiment of the application further provides a processing method of integrity protection, applied to a terminal, and including:
[0301] Sending first information to the network side; the first information indicates (and can also be understood as requesting) the network side to adjust the related parameters of the integrity protection.
[0302] In actual application, when the terminal power consumption is too high, exceeds the current capability or enters the energy saving mode, the terminal determines that the first information needs to be sent to the network side, and the terminal can send the first information to the network side. At this time, the first information can request to reduce the network side integrity protection rate, can request to adjust the network side integrity protection algorithm to reduce the terminal processing capability, and can request to adjust the network side data packet interval for integrity protection to reduce the terminal processing capability.
[0303] Of course, when the terminal recovers from the above-mentioned conditions to the normal working state, the terminal determines that the first information needs to be sent to the network side, and can send the first information to the network side. At this time, the first information can request to increase the network side integrity protection rate, can request to adjust the network side integrity protection algorithm to match the terminal processing capability, and can request to adjust the network side data packet interval for integrity protection to match the terminal processing capability.
[0304] In an embodiment, the first information can be sent to the network side by one of the following ways:
[0305] PDCP PDU;
[0306] RRC signaling;
[0307] MAC CE;
[0308] Uplink physical layer resource.
[0309] In actual application, when the first information is sent to the network side through the PDCP PDU, that is, if the first information is sent to the network side through the PDCP PDU, the first information is in the packet header of the PDCP PDU, or the first information is in the data field (also can be understood as Data bit) of the PDCP PDU. Of course, the first information can also be in other positions in the PDCP PDU.
[0310] Here, when the first information is in the packet header of the PDCP PDU, as shown in Figure 2 The second information can be set in the reserved bit (also can be understood as the reserved field).
[0311] In the case of sending the first information through the MAC CE, that is, if the first information is sent through the MAC CE, the MAC CE can be a newly defined MAC CE, or an existing MAC CE, and the embodiment of the present application does not limit this.
[0312] In actual application, the uplink physical layer resource can include UCI. The UCI can be carried in PUCCH or PUSCH.
[0313] Correspondingly, the embodiment of the present application further provides a processing method for integrity protection, applied to a network device, such as a base station. Figure 6 The method comprises the following steps:
[0314] Step 601: receiving first information sent by a terminal; the first information indicates (may be understood as requests) the network side to adjust related parameters of integrity protection;
[0315] Step 602: adjusting the related parameters of integrity protection by using the first information.
[0316] In an embodiment, the first information sent by the terminal can be received in one of the following ways:
[0317] PDCP PDU;
[0318] RRC signaling;
[0319] MAC CE;
[0320] uplink physical resources.
[0321] Specifically, when the terminal sends the first information through PDCP PDU, the network device receives the first information through PDCP PDU; when the terminal sends the first information through RRC signaling, the network device receives the first information through RRC signaling; when the terminal sends the first information through MAC CE, the network device receives the first information through MAC CE; and when the terminal sends the first information through uplink physical layer resources, the network device receives the first information through uplink physical layer resources.
[0322] In actual application, the related parameters of integrity protection can include an integrity protection rate, so the integrity protection rate can be adjusted.
[0323] Based on this, in an embodiment, the adjusting of the related parameters of integrity protection based on the first information comprises:
[0324] adjusting the integrity protection rate based on the first information.
[0325] The first information can include at least one of the following:
[0326] a first integrity protection rate;
[0327] a difference between a current integrity protection rate and the first integrity protection rate;
[0328] an integrity protection rate level corresponding to the first integrity protection rate.
[0329] Here, in actual application, the terminal can instruct (can be understood as request) the network device to increase or decrease the integrity protection rate, and the network side can increase or decrease the integrity protection rate according to the instruction of the terminal.
[0330] In actual application, the related parameters of integrity protection can also include an integrity protection algorithm, so that the integrity protection algorithm can be adjusted.
[0331] Based on this, in an embodiment, the adjusting the related parameters of integrity protection by using the first information comprises:
[0332] Adjusting the integrity protection algorithm by using the first integrity protection algorithm contained in the first information.
[0333] Here, in actual application, when the terminal requests to decrease the integrity complexity, a new integrity protection algorithm can be used to decrease the integrity protection complexity of the terminal. Of course, after the integrity algorithm is adjusted, when the terminal requests to recover, the network side can be requested to recover the integrity complexity, at this time, the network device can adjust the integrity protection algorithm again.
[0334] In actual application, the related parameters of integrity protection can also include a data packet interval for integrity protection, so that the data packet interval for integrity protection can be adjusted.
[0335] Based on this, in an embodiment, the adjusting the related parameters of integrity protection by using the first information comprises:
[0336] Adjusting the interval of the data packet for integrity protection to N by using the first data packet interval contained in the first information; N is an integer greater than or equal to zero.
[0337] Here, in actual application, when the terminal requests to decrease the integrity complexity, the data packet interval for integrity protection can be adjusted from 0 to 1, or can be adjusted to 2 or a larger data packet interval, so as to decrease the integrity protection complexity of the terminal. Of course, after the data packet interval for integrity protection is adjusted, when the terminal requests to recover, the network side can be requested to recover the integrity complexity, at this time, the network device can adjust the data packet interval for integrity protection again, for example, adjusting the data packet interval for integrity protection from 1 to 0, that is, each data packet is protected by integrity.
[0338] Since the integrity protection is configured for each DRB, the network device can adjust the related parameters of integrity protection for at least one DRB in the multiple DRBs.
[0339] The embodiment of the present application provides a processing method for integrity protection, as shown in Figure 7 The method comprises:
[0340] Step 701: the terminal sends first information to the network device; the first information indicates that the network side adjusts related parameters of integrity protection;
[0341] Step 702: the network device adjusts related parameters of integrity protection based on the first information.
[0342] It should be noted that the specific processing procedures of the network device and the terminal have been described above, and will not be repeated here.
[0343] The processing method of integrity protection provided in the embodiments of the present application is that the terminal sends first information to the network device; the first information indicates that the network side adjusts related parameters of integrity protection; the network device adjusts related parameters of integrity protection based on the first information. By indicating the network side to adjust related parameters of integrity protection of the network side through the terminal, it can be avoided in time that the data packet is lost, the integrity protection fails, or even the link terminal, etc. due to insufficient terminal capability.
[0344] The present application will be further described in detail in conjunction with application examples.
[0345] Application Example One
[0346] In the present application example, the communication system is provided with P integrity protection rate levels.
[0347] The terminal reports its own integrity protection rate level p, wherein p is less than or equal to P. When the terminal power consumption is too high, or exceeds the current capability, or enters the energy saving mode, etc., the terminal sends a rate adjustment indication to the network side, which is used to request to reduce the speed. The indication requests to adjust the integrity protection rate level to q, wherein < p. After receiving it, the network side issues first information to the terminal to indicate the terminal to adjust the integrity protection rate level to q. Of course, the network side can also maintain the original rate, but cancel the user plane integrity protection.
[0348] Of course, the terminal can also send a rate adjustment indication to the network side, which is used to increase the speed, and increase the integrity protection rate level by p. For example, when the above-mentioned situation disappears, i.e. after the adverse consequences are removed, the speed can be increased.
[0349] Application Example Two
[0350] In the present application example, the maximum integrity protection rate corresponding to different integrity protection algorithms is different. Therefore, a higher integrity protection rate can be used by adjusting the integrity protection algorithm; or a lower complexity can be achieved by replacing the integrity protection algorithm while maintaining the same integrity protection rate.
[0351] When the terminal reports the related capability of the integrity protection, the terminal reports the rate corresponding to each integrity protection algorithm, for example, the maximum rate reached by using the second integrity protection algorithm is A, and the maximum rate reached by using the third integrity protection algorithm is B. When the network side configures the terminal to use the second integrity protection algorithm, the rate is ensured to be not more than A; when the network side configures the terminal to use the third integrity protection algorithm, the rate is ensured to be not more than B. Since the complexity of the second integrity protection algorithm is higher than that of the third integrity protection algorithm, A < B.
[0352] When the network side configures the terminal to use the second integrity protection algorithm, the terminal sends an integrity protection algorithm replacement request (i.e., the second information) to the network side when the terminal has a poor running state, or the power consumption is too high, or exceeds the current capability, or enters the energy saving mode, etc., to request to change the algorithm to the third integrity protection algorithm to reduce the complexity of the integrity protection. Alternatively, when the terminal is overheated or the cache is overloaded, the network side sends an integrity protection algorithm replacement message to the terminal to change the integrity protection algorithm to the second integrity protection algorithm.
[0353] In addition, when the network side configures the terminal to use the second integrity protection algorithm, the sending end and the receiving end perform integrity protection on each data packet. When the terminal has a poor running state, or the power consumption is too high, or exceeds the current capability, or enters the energy saving mode, etc., the terminal can request the network side to adjust the integrity protection to perform integrity protection on every 1 data packet, or every 2 data packets, or every more data packets, to reduce the complexity of the integrity protection; or when the above-mentioned situation occurs, (without the terminal requesting), the network side actively sends an integrity protection configuration message to the terminal to adjust the integrity protection to perform integrity protection on every 1 data packet, or every 2 data packets, or every more data packets, to reduce the complexity of the integrity protection.
[0354] As can be seen from the above description, when the terminal performs integrity protection at a high rate, or at full rate, the terminal may have a high power consumption, or a large heat generation, or exceed the current maximum capability of the terminal. At this time, the terminal will not be able to maintain the current rate. By sending the related capability of the integrity protection and the auxiliary indication message by the terminal side, the network side can be helped to timely adjust the related parameters of the integrity protection, so as to avoid the occurrence of the bad consequences such as data packet loss, integrity protection failure, and even link termination.
[0355] In order to implement the method of the embodiment of the present application, the embodiment of the present application further provides a processing device for integrity protection, which is arranged on a first communication node, as shown in Figure 8 The device comprises:
[0356] A first receiving unit 81 is configured to receive the first information sent by the second communication node.
[0357] The adjusting unit 82 is configured to adjust the related parameters of the integrity protection by using the received first information.
[0358] In an embodiment, the first receiving unit 81 is specifically configured to:
[0359] receive the first information sent by the second communication node in one of the following manners:
[0360] a PDCP PDU;
[0361] RRC signaling;
[0362] a MAC CE;
[0363] a physical layer resource.
[0364] In an embodiment, the apparatus can further include:
[0365] The first sending unit is configured to send second information to the second communication node, wherein the second information is used to instruct the second communication node to adjust the related parameters of the integrity protection of the first communication node.
[0366] Here, the first sending unit is specifically configured to send the second information to the second communication node in one of the following manners:
[0367] a PDCP PDU;
[0368] RRC signaling;
[0369] a MAC CE;
[0370] a physical layer resource.
[0371] In an embodiment, the adjusting unit 82 is specifically configured to perform at least one of the following operations:
[0372] adjust the integrity protection rate by using the first information;
[0373] adjust the integrity protection algorithm by using the first information;
[0374] adjust the interval of data packets to be integrity protected by using the first information.
[0375] In an embodiment, the first sending unit is further configured to send capability information to the second communication node, wherein the capability information indicates the related capability of the integrity protection supported by the first communication node.
[0376] In an embodiment, the adjusting unit 82 is specifically configured to:
[0377] adjust the related parameters of the integrity protection for at least one DRB in a plurality of DRBs.
[0378] In actual application, the first receiving unit 81 and the first sending unit can be implemented by a communication interface in the integrity-protected processing device; and the adjusting unit 82 can be implemented by a processor in the integrity-protected processing device.
[0379] To implement the method at the second communication node side, the embodiments of the present application further provide an integrity-protected processing device arranged on the second communication node, as shown in the following figure, which comprises: Figure 9
[0380] A second sending unit 91 is configured to send first information to the first communication node; the first information is used for the first communication node to adjust related parameters of integrity protection.
[0381] The second sending unit 91 is configured to send the first information to the first communication node by one of the following ways:
[0382] PDCP PDU;
[0383] RRC signaling;
[0384] MAC CE;
[0385] Physical layer resource.
[0386] In an embodiment, as shown in the following figure, the device can further comprise: Figure 9
[0387] A second receiving unit 92 is configured to receive second information sent by the first communication node; the second information is used to indicate the second communication node to adjust related parameters of integrity protection of the first communication node.
[0388] The second sending unit 91 is configured to send the first information to the first communication node based on the second information.
[0389] In an embodiment, the second receiving unit 92 is specifically configured to receive the second information sent by the first communication node by one of the following ways:
[0390] PDCP PDU;
[0391] RRC signaling;
[0392] MAC CE;
[0393] Physical layer resource.
[0394] In an embodiment, the second receiving unit 92 is further configured to receive capability information sent by the first communication node; the capability information indicates related capability of integrity protection supported by the first communication node.
[0395] In actual application, the second sending unit 91 and the second receiving unit 92 can be realized by a processor in the integrity-protected processing device in combination with a communication interface.
[0396] It should be noted that, when performing the integrity protection processing, the integrity-protected processing device provided in the above embodiments is only exemplified by the above division of the program modules, and in actual application, the above processing can be completed by different program modules according to needs, that is, the internal structure of the device is divided into different program modules to complete all or part of the above-described processing. In addition, the integrity-protected processing device and the integrity-protected processing method provided in the above embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be repeated here.
[0397] Based on the hardware implementation of the above program modules, and in order to realize the method of the terminal side in the embodiments of the present application, the embodiments of the present application further provide a terminal, as shown in the following Figure 10 The first communication node 100 includes:
[0398] The first communication interface 101 is capable of performing information interaction with the second communication node;
[0399] The first processor 102 is connected with the first communication interface 101 to realize information interaction with the second communication node, and is used to execute the above-mentioned method provided by one or more technical solutions of the first communication node side when running a computer program. The computer program is stored on the first memory 103.
[0400] Specifically, the first communication interface 101 is configured to receive the first information sent by the second communication node.
[0401] The first processor 102 is configured to adjust the related parameters of the integrity protection by using the received first information.
[0402] In an embodiment, the first communication interface 101 is specifically configured to receive the first information sent by the second communication node by one of the following ways:
[0403] PDCP PDU;
[0404] RRC signaling;
[0405] MAC CE;
[0406] Physical layer resource.
[0407] In an embodiment, the first communication interface 101 is further configured to send second information by the second communication node; the second information is used to indicate the second communication node to adjust the related parameters of the integrity protection of the first communication node
[0408] In an embodiment, the first communication interface 101 is specifically configured to send the second information to the second communication node by one of the following ways:
[0409] a PDCP PDU;
[0410] RRC signaling;
[0411] a MAC CE;
[0412] a physical layer resource.
[0413] In an embodiment, the first processor 102 is specifically configured to perform at least one of the following operations:
[0414] adjust an integrity protection rate by using the first information;
[0415] adjust an integrity protection algorithm by using the first information;
[0416] adjust an interval of data packets to be integrity protected by using the first information.
[0417] In an embodiment, the first communication interface 101 is further configured to:
[0418] send capability information to the second communication node; the capability information indicates related capabilities of integrity protection supported by the first communication node.
[0419] In an embodiment, the first processor 102 is specifically configured to:
[0420] adjust related parameters of integrity protection for at least one DRB of the multiple DRBs.
[0421] It should be noted that the specific processing procedures of the first processor 102 and the first communication interface 101 are described in the method embodiments, and will not be described here.
[0422] Of course, in actual application, various components in the first communication node 100 are coupled together through a bus system 104. It can be understood that the bus system 104 is used to realize the connection and communication between the components. The bus system 104 includes not only a data bus, but also a power bus, a control bus and a status signal bus. However, in order to clearly illustrate, all kinds of buses are marked as the bus system 104 in the Figure 10 .
[0423] The first memory 103 in the embodiment of the application is used to store various types of data to support the operation of the first communication node 100. Examples of these data include any computer programs used to operate on the first communication node 100.
[0424] The method disclosed by the embodiments of the present application can be applied to the first processor 102 or implemented by the first processor 102. The first processor 102 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by integrated logic circuits of hardware in the first processor 102 or instructions in the form of software. The first processor 102 described above can be a general processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 102 can implement or execute each method, step and logic block disclosed in the embodiments of the present application. The general processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the steps, or the combination of hardware and software modules in the decoding processor can be executed. The software module can be located in a storage medium, which is located in the first memory 103, and the first processor 102 reads the information in the first memory 103 to combine the hardware to complete the steps of the above method.
[0425] In the exemplary embodiments, the first communication node 100 can be implemented by one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field programmable gate arrays (FPGAs), general processors, controllers, micro controllers (MCUs), microprocessors (Microprocessors), or other electronic elements, for executing the above method.
[0426] Based on the hardware implementation of the above program module, and in order to implement the method on the second communication node side according to the embodiments of the present application, as shown in the following figure, the second communication node 110 includes: Figure 11
[0427] A second communication interface 111 capable of information interaction with the first communication node;
[0428] The second processor 112 is connected with the second communication interface 111 to realize information interaction with the first communication node, and is used to execute a computer program to implement the method provided by one or more technical solutions of the second communication node. The computer program is stored in the second memory 113.
[0429] Specifically, the second communication interface 111 is configured to send first information to the first communication node, and the first information is used for the first communication node to adjust the related parameters of the integrity protection.
[0430] In an embodiment, the second communication interface 111 is configured to send the first information to the first communication node by one of the following manners:
[0431] PDCP PDU;
[0432] RRC signaling;
[0433] MAC CE;
[0434] Physical layer resource.
[0435] In an embodiment, the second communication interface 111 is further configured to receive second information sent by the first communication node, and the second information is used to indicate the second communication node to adjust the related parameters of the integrity protection of the first communication node.
[0436] The second communication interface 111 is configured to send the first information to the first communication node based on the second information.
[0437] In an embodiment, the second communication interface 111 is specifically configured to receive the second information sent by the first communication node by one of the following manners:
[0438] PDCP PDU;
[0439] RRC signaling;
[0440] MAC CE;
[0441] Physical layer resource.
[0442] In an embodiment, the second communication interface 111 is further configured to receive capability information sent by the first communication node, and the capability information indicates the related capability of the integrity protection supported by the first communication node.
[0443] It should be noted that the specific processing process of the second processor 112 and the second communication interface 111 is described in the method embodiment, which will not be repeated here.
[0444] Of course, in actual applications, the various components in the second communication node 110 are coupled together by a bus system 114. It can be understood that the bus system 114 is used to realize the connection communication between the components. The bus system 114 includes not only a data bus, but also a power supply bus, a control bus, and a status signal bus. However, for the purpose of clear illustration, all the buses are marked as the bus system 114 in the following description. Figure 11
[0445] The second memory 113 in the embodiment of the present application is used to store various types of data to support the operation of the second communication node 110. Examples of the data include any computer programs used for operating on the second communication node 110.
[0446] The method disclosed in the above embodiment of the present application can be applied to or implemented by the second processor 112. The second processor 112 can be an integrated circuit chip with the processing capability of signals. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware or the instruction in the form of software in the second processor 112. The second processor 112 disclosed above can be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The second processor 112 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the completion, or the hardware and software modules in the decoding processor are combined to execute the completion. The software module can be located in the storage medium, which is located in the second memory 113. The second processor 112 reads the information in the second memory 113 and combines the hardware to complete the steps of the above method.
[0447] In the exemplary embodiment, the second communication node 110 can be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic elements, which are used to execute the above method.
[0448] It can be understood that the memory (the first memory 103 and the second memory 113) of the embodiments of the present application can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. The non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM). The magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example but not limitation, many forms of RAM can be used, such as a static random access memory (SRAM), a synchronous static random access memory (SSRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a sync link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DRRAM).The memory described in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memory.
[0449] To implement the method of the embodiments of the present application, the embodiments of the present application further provide an integrity protection processing system, as shown in the following figure, which comprises a first communication node 121 and a second communication node 122. Figure 12
[0450] It should be noted that the specific processing procedures of the first communication node 121 and the second communication node 122 have been described in the foregoing, and will not be described here.
[0451] In exemplary embodiments, the embodiments of the present application further provide a storage medium, i.e. a computer storage medium, specifically a computer readable storage medium, such as a first memory 103 storing a computer program executable by the first processor 102 of the first communication node 100 to complete the steps of the aforementioned first communication node side method. For example, a second memory 113 storing a computer program executable by the second processor 112 of the second communication node 110 to complete the steps of the aforementioned second communication node side method. The computer readable storage medium can be a FRAM, a ROM, a PROM, an EPROM, an EEPROM, a Flash Memory, a magnetic surface memory, an optical disc, or a CD-ROM, etc.
[0452] It should be noted that "first", "second", etc. are used to distinguish similar objects, and do not necessarily describe a specific order or sequence.
[0453] In addition, the technical solutions described in the embodiments of the present application can be arbitrarily combined without conflict.
[0454] The above is only a preferred embodiment of the present application, and is not intended to limit the protection scope of the present application.
Claims
1. A method for integrity protection, characterized in that, Applied to the first communication node, including: Receive the first information sent by the second communication node; Using the received first information, for at least one of multiple Data Radio Bearers (DRBs), the integrity protection rate and / or integrity protection algorithm are adjusted, and / or the interval between data packets requiring integrity protection is adjusted, or integrity protection is canceled; wherein, the first communication node is a data transmitting device; the second communication node transmits the first information through a Packet Data Convergence Protocol (PDCP) Protocol Data Unit (PDU); the first information is set in a preset bit in the header of the PDCP PDU; if only one DRB requires integrity protection, the integrity protection rate corresponding to one DRB is M; if two DRBs require integrity protection, the integrity protection rates M1 and M2 corresponding to the two DRBs are both less than M; Send a second message to the second communication node; the second message is used to instruct the second communication node to adjust the integrity protection rate of the first communication node, and / or the integrity protection algorithm, and / or the interval of data packets to be protected for integrity, or to cancel integrity protection; the first communication node sends the second message through the PDCP PDU; the second message is set in a preset bit in the packet header of the PDCP PDU.
2. The method according to claim 1, characterized in that, Receive the first information sent by the second communication node using one of the following methods: Radio Resource Control (RRC) signaling; The control unit (MAC CE) of the media access control layer; Physical layer resources.
3. The method according to claim 1, characterized in that, When sending first information to the first communication node via PDCP PDU, the first information is within the data field of PDCP PDU.
4. The method according to claim 1, characterized in that, Send the second message to the second communication node using one of the following methods: RRC signaling; MAC CE; Physical layer resources.
5. The method according to claim 4, characterized in that, When sending second information to a second communication node via a PDCP PDU, the second information is within the data field of the PDCP PDU.
6. The method according to claim 1, characterized in that, The first information includes at least one of the following: The first integrity protection rate; the first integrity protection rate is used for the first communication node to adjust the integrity protection rate to the first integrity protection rate; The difference between the current integrity protection rate and the first integrity protection rate; the difference is used by the first communication node to adjust the integrity protection rate to the first integrity protection rate; The integrity protection rate level corresponding to the first integrity protection rate; The integrity protection rate level corresponding to the first integrity protection rate is used to allow the first communication node to adjust the integrity protection rate level to the integrity protection rate level corresponding to the first integrity protection rate. A first integrity protection algorithm; the first integrity protection algorithm is used by the first communication node to adjust the integrity protection algorithm to the first integrity protection algorithm; The first data packet interval; the first data packet interval is used by the first communication node to adjust the interval of the data packets for integrity protection to N; N is an integer greater than or equal to zero.
7. The method according to any one of claims 1 to 6, characterized in that, The method further includes: Send capability information to the second communication node; the capability information indicates the integrity protection capabilities supported by the first communication node.
8. The method according to claim 7, characterized in that, The capability information includes at least one of the following: The maximum integrity protection rate supported by the first communication node; The first communication node supports at least one integrity protection algorithm; each integrity protection algorithm has a different integrity protection rate. The integrity protection rate level corresponding to the maximum integrity protection rate supported by the first communication node.
9. The method according to claim 8, characterized in that, If the capability information includes the maximum integrity protection rate supported by the first communication node, the capability information further includes one of the following: The sum of the integrity protection rates of multiple data radio bearers (DRBs) shall not exceed the maximum integrity protection rate. The sum of the integrity protection rates of multiple DRBs shall not exceed the maximum integrity protection rate, and the integrity protection rate of each DRB among the multiple DRBs shall not exceed the first value. The sum of the integrity protection rates of multiple DRBs exceeds the maximum integrity protection rate; The sum of the integrity protection rates of multiple DRBs exceeds the maximum integrity protection rate, and the integrity protection rate of each DRB among the multiple DRBs cannot exceed a first value.
10. The method according to claim 8, characterized in that, If the capability information includes at least one integrity protection algorithm supported by the first communication node, the capability information further includes one of the following: The maximum integrity protection rate corresponding to the number of DRBs performing integrity protection for each integrity protection algorithm.
11. A method for integrity protection, characterized in that, Applied to the second communication node, including: The first communication node sends first information; the first information instructs the first communication node to adjust the integrity protection rate and / or integrity protection algorithm, and / or the interval of data packets to be protected for integrity protection, or to cancel integrity protection for at least one of the multiple DRBs; the first communication node is a data transmission device; the second communication node sends the first information through a Packet Data Convergence Protocol (PDCP) Protocol Data Unit (PDU); the first information is set in a preset bit in the header of the PDCP PDU; if only one DRB needs integrity protection, the integrity protection rate corresponding to one DRB is M; if two DRBs need integrity protection, the integrity protection rates M1 and M2 corresponding to the two DRBs are both less than M; The first communication node receives a second message sent by the first communication node; the second message is used to instruct the second communication node to adjust the integrity protection rate and / or integrity protection algorithm of the first communication node, and / or the interval of data packets to be protected for integrity, or to cancel integrity protection. The first communication node sends the second message through the PDCP PDU; the second message is set in a preset bit in the packet header of the PDCP PDU.
12. The method according to claim 11, characterized in that, The first message is sent to the first communication node using one of the following methods: RRC signaling; MAC CE; Physical layer resources.
13. The method according to claim 11, characterized in that, When sending first information to the first communication node via PDCP PDU, the first information is within the data field of PDCP PDU.
14. The method according to claim 11, characterized in that, The second information sent by the first communication node is received in one of the following ways: RRC signaling; MAC CE; Physical layer resources.
15. The method according to claim 11, characterized in that, When receiving the second information sent by the first communication node via the PDCP PDU, the second information is within the data field of the PDCP PDU.
16. The method according to claim 11, characterized in that, The first information includes at least one of the following: The first integrity protection rate; the first integrity protection rate is used for the first communication node to adjust the integrity protection rate to the first integrity protection rate; The difference between the current integrity protection rate and the first integrity protection rate; the difference is used by the first communication node to adjust the integrity protection rate to the first integrity protection rate; The integrity protection rate level corresponding to the first integrity protection rate; The integrity protection rate level corresponding to the first integrity protection rate is used to allow the first communication node to adjust the integrity protection rate level to the integrity protection rate level corresponding to the first integrity protection rate. A first integrity protection algorithm; the first integrity protection algorithm is used by the first communication node to adjust the integrity protection algorithm to the first integrity protection algorithm; The first data packet interval; the first data packet interval is used by the first communication node to adjust the interval of the data packets for integrity protection to N; N is an integer greater than or equal to zero.
17. The method according to any one of claims 11 to 16, characterized in that, The method further includes: Receive capability information sent by the first communication node; the capability information indicates the integrity protection capabilities supported by the first communication node.
18. The method according to claim 17, characterized in that, The capability information includes at least one of the following: The maximum integrity protection rate supported by the first communication node; The first communication node supports at least one integrity protection algorithm; each integrity protection algorithm has a different integrity protection rate. The integrity protection rate level corresponding to the maximum integrity protection rate supported by the first communication node.
19. The method according to claim 18, characterized in that, If the capability information includes the maximum integrity protection rate supported by the first communication node, the capability information further includes one of the following: The sum of the integrity protection rates of multiple DRBs shall not exceed the maximum integrity protection rate. The sum of the integrity protection rates of multiple DRBs shall not exceed the maximum integrity protection rate, and the integrity protection rate of each DRB among the multiple DRBs shall not exceed the first value. The sum of the integrity protection rates of multiple DRBs exceeds the maximum integrity protection rate; The sum of the integrity protection rates of multiple DRBs exceeds the maximum integrity protection rate, and the integrity protection rate of each DRB among the multiple DRBs cannot exceed a first value.
20. The method according to claim 19, characterized in that, If the capability information includes at least one integrity protection algorithm supported by the first communication node, the capability information further includes one of the following: The maximum integrity protection rate corresponding to the number of DRBs performing integrity protection for each integrity protection algorithm.
21. A processing device for integrity protection, characterized in that, Applied to the first communication node, including: The first receiving unit is used to receive the first information sent by the second communication node; An adjustment unit is used to adjust the integrity protection rate and / or integrity protection algorithm, and / or the interval of data packets to be protected for integrity protection, or cancel integrity protection, for at least one of a plurality of DRBs, using the received first information; wherein, the second communication node sends the first information through a Packet Data Convergence Protocol (PDCP) Protocol Data Unit (PDU); the first information is set in a preset bit in the header of the PDCP PDU; if only one DRB needs to be protected for integrity, the integrity protection rate corresponding to one DRB is M; if two DRBs need to be protected for integrity, the integrity protection rates M1 and M2 corresponding to the two DRBs are both less than M; The first transmitting unit is used to transmit second information to the second communication node; the second information is used to instruct the second communication node to adjust the integrity protection rate and / or integrity protection algorithm of the first communication node, and / or the interval of data packets to be protected for integrity, or to cancel integrity protection; the first communication node transmits the second information through a PDCP PDU; the second information is set in a preset bit in the packet header of the PDCP PDU; the first communication node is a data transmitting device.
22. A processing device for integrity protection, characterized in that, Applied to the second communication node, including: The second sending unit is used to send first information to the first communication node; the first information instructs the first communication node to adjust the integrity protection rate and / or integrity protection algorithm, and / or the interval of data packets to be protected for integrity protection, or to cancel integrity protection for at least one of the multiple DRBs; the first communication node is a data sending device; the first information is sent by the second communication node through the Protocol Data Unit (PDU) of the Packet Data Convergence Protocol (PDCP); the first information is set in a preset bit in the header of the PDCP PDU; if only one DRB needs to be protected for integrity, the integrity protection rate corresponding to one DRB is M; if two DRBs need to be protected for integrity, the integrity protection rates M1 and M2 corresponding to the two DRBs are both less than M; The second receiving unit is used to receive second information sent by the first communication node; the second information is used to instruct the second communication node to adjust the integrity protection rate and / or integrity protection algorithm of the first communication node, and / or the interval of data packets to be protected for integrity, or to cancel integrity protection, and the first communication node sends the second information through the PDCP PDU; the second information is set in a preset bit in the packet header of the PDCP PDU.
23. A first communication node, characterized in that, include: The first communication interface is used to receive the first information sent by the second communication node; The first processor is configured to, using the received first information, adjust the integrity protection rate and / or integrity protection algorithm, and / or the interval between data packets to be protected for integrity, or cancel integrity protection for at least one of a plurality of DRBs; the second communication node transmits the first information through a Packet Data Convergence Protocol (PDCP) Protocol Data Unit (PDU); the first information is set in a preset bit in the header of the PDCP PDU; if only one DRB needs to be protected for integrity, the integrity protection rate corresponding to one DRB is M; if two DRBs need to be protected for integrity, the integrity protection rates M1 and M2 corresponding to the two DRBs are both less than M; The first communication interface is also used to send second information to the second communication node; the second information is used to instruct the second communication node to adjust the integrity protection rate and / or integrity protection algorithm of the first communication node, and / or the interval of data packets to be protected for integrity, or to cancel integrity protection; the first communication node sends the second information through a PDCP PDU; the second information is set in a preset bit in the packet header of the PDCP PDU; the first communication node is a data transmission device.
24. A second communication node, characterized in that, include: A second communication interface and a second processor; wherein... The second communication interface is used to send first information to the first communication node; The first information instructs the first communication node to adjust the integrity protection rate and / or integrity protection algorithm, and / or the interval of data packets to be protected for integrity protection, or to cancel integrity protection for at least one of the multiple DRBs; the first communication node is a data transmission device; the first information is sent by the second communication node through the Packet Data Convergence Protocol (PDCP) Protocol Data Unit (PDU); the first information is set in a preset bit in the header of the PDCP PDU; if only one DRB needs integrity protection, the integrity protection rate corresponding to one DRB is M; if two DRBs need integrity protection, the integrity protection rates M1 and M2 corresponding to the two DRBs are both less than M; The second communication interface is also used to receive second information sent by the first communication node; the second information is used to instruct the second communication node to adjust the integrity protection rate and / or integrity protection algorithm of the first communication node, and / or the interval of data packets to be protected for integrity, or to cancel integrity protection, and the first communication node sends the second information through the PDCP PDU; the second information is set in a preset bit in the packet header of the PDCP PDU.
25. A first communication node, characterized in that, include: A first processor and a first memory for storing computer programs capable of running on the processor. Wherein, when the first processor is used to run the computer program, it performs the steps of the method according to any one of claims 1 to 10.
26. A second communication node, characterized in that, include: A second processor and a second memory for storing computer programs that can run on the processor. Wherein, when the second processor is used to run the computer program, it performs the steps of the method according to any one of claims 11 to 20.
27. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 10, or the steps of the method according to any one of claims 11 to 20.
Citation Information
Patent Citations
Techniques to manage integrity protection
WO2019191974A1