A method and device for protecting data packet integrity
By grouping data packets and selecting some data packets for integrity protection, the problem of full-rate packet integrity protection in the 5G era is solved, and the efficiency of packet integrity protection is improved, which is suitable for the protection needs of high-rate packets in 5G networks.
Patent Information
- Application Number
- CN202011457763.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-11
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2040-12-11
AI Technical Summary
In the 5G era, mobile communication networks need to be combined with vertical industries and the Internet of Things on a larger scale, resulting in an increase in the demand for packet integrity protection, and it is difficult for the existing technology to provide integrity protection for full-speed packet traffic.
By grouping the data packets to be transmitted, selecting some data packets as the target data packets in the packet for integrity protection, generating integrity verification information, attaching it to the end of the data packet, and sending it to the receiver for verification.
It improves the efficiency of packet integrity protection, and can provide probabilistic integrity protection for user data packets when performance requirements are met, which is suitable for the protection requirements of high-speed data packets in 5G networks.
Smart Images

Figure CN114630327B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of mobile communications, and particularly to a method and device for protecting the integrity of data packets. Background Art
[0002] In a mobile communication network, the protection of data packets mainly includes three categories, namely confidentiality protection, integrity protection, and anti-replay protection. Among them, confidentiality protection focuses on solving the problem of data packet content leakage, integrity protection focuses on solving the problem of data packet content being tampered with or directly forging data packets, and anti-replay protection solves the problem of data packets being replayed after being cached on the basis of integrity protection.
[0003] For a mobile communication network, due to the instability of the air interface, there are naturally situations where data packets are distorted or even lost during the transmission process over the air interface. Applying integrity protection will cause these packets to be discarded or retransmitted, which will greatly affect real-time services (especially voice services), making users feel call interruptions and affecting the user experience. On the contrary, for voice services, the distortion of data packets will lead to a decline in call quality but will not cause the call to terminate. Therefore, in traditional 2G / 3G / 4G networks, integrity protection is only provided for air interface user signaling, and integrity protection is not provided for user air interface data packets, that is, the real-time transmission requirements are guaranteed at the cost of tolerating the modification of data packets. However, in the 5G era, since the mobile communication network will be combined with vertical industries, the Internet of Things, etc. on a larger scale. And a large number of control messages are included in vertical industry and Internet of Things communications, such as starting devices, adjusting parameters, etc. Their tolerance for data packet distortion, illegal tampering, or forgery is lower. Therefore, integrity protection for user data packets is introduced in 5G.
[0004] Currently, the prior art clearly defines that the integrity of user data packets will adopt the same algorithm as the integrity protection of Radio Resource Control (RRC) signaling, such as Figure 1 and Figure 2 shown, at the sending end, for each data packet (MESSAGE), combined with parameters related to the data packet, such as the uplink / downlink direction (DIRECTION), counter (COUNT), bearer identifier (BEARER), and the corresponding integrity key (KEY), integrity check parameters (MAC-I) are generated and attached to the data packet (MESSAGE) and sent to the peer end (receiving end). As Figure 1 and Figure 3 shown, at the receiving end side, the information to be verified (XMAC-I) is generated in the same way, and then compared with MAC-I. If the comparison is the same, it is regarded as a successful integrity check.
[0005] Due to the limitations of device capabilities, especially those of terminal devices, in a 5G system, for example, it is currently only possible to implement mandatory integrity protection for data packets with low-rate traffic (not greater than 64 Kbps), and it is difficult to provide integrity protection for full-rate data packet traffic. Summary of the Invention
[0006] At least one embodiment of the present invention provides a method, a terminal, and a network device for data packet integrity protection, which improve the efficiency of integrity protection.
[0007] According to one aspect of the present invention, at least one embodiment provides a method for data packet integrity protection, including:
[0008] A first device groups the data packets to be transmitted to obtain at least one group;
[0009] According to the grouping, integrity protection is performed on the target data packets in the group to generate integrity check information, where the number n of the target data packets is less than or equal to the total number m of the data packets in the group;
[0010] The data packets and the integrity check information are sent to a second device.
[0011] In addition, according to at least one embodiment of the present invention, the performing integrity protection on the target data packets in the group according to the grouping includes:
[0012] Select n data packets from the group as target data packets, and determine the data packets covered by the integrity protection of each target data packet, where the union of the data packets covered by the integrity protection of all target data packets is all the data packets in the group;
[0013] For the target data packets, a first sequence number is generated according to the sequence numbers of the data packets covered by the integrity protection of the target data packets;
[0014] Using preset parameters and an integrity key, integrity check information corresponding to the target data packets is generated and attached to the end of the target data packets, where the preset parameters at least include the first sequence number.
[0015] In addition, according to at least one embodiment of the present invention, the selecting n data packets from the group as target data packets includes:
[0016] According to a random selection method, randomly select n data packets from the group as target data packets;
[0017] Or,
[0018] According to a fixed-position selection method, select n data packets at preset positions from the group as the target data packets.
[0019] In addition, according to at least one embodiment of the present invention, the manner of selecting the target data packet from each group is independent of each other.
[0020] In addition, according to at least one embodiment of the present invention, the manner of determining the data packets covered by the integrity protection of each target data packet includes any one of the following determination manners:
[0021] Equal division determination manner: Divide the data packets in the group into n segments according to a preset data packet interval L; according to the correspondence between the segments and the target data packets, all the data packets in each segment are used as the data packets covered by the integrity protection of the corresponding target data packet, where L is the integer value obtained by rounding down m / n.
[0022] Full amount determination manner: All the data packets in the group where the target data packet is located are used as the data packets covered by the integrity protection of the target data packet.
[0023] Random determination manner: Randomly select at least one data packet from the group as the data packet covered by the integrity protection of the target data packet.
[0024] In addition, according to at least one embodiment of the present invention, when dividing the data packets in the group into n segments according to a preset data packet interval L, if m cannot be divided evenly by n, the remaining data packets are incorporated into the existing segments.
[0025] In addition, according to at least one embodiment of the present invention, when randomly selecting at least one data packet from the group as the data packet covered by the integrity protection of the target data packet, it further includes:
[0026] Cascade the sequence numbers of the randomly selected data packets with the target data packet to obtain the updated target data packet.
[0027] In addition, according to at least one embodiment of the present invention, it further includes:
[0028] Negotiate with the second device to determine the values of m and n, and the manner of determining the data packets covered by the integrity protection of each target data packet.
[0029] In addition, according to at least one embodiment of the present invention, the first sequence number is obtained by performing an exclusive OR calculation on the sequence numbers of the respective data packets covered by the integrity protection of the target data packet.
[0030] According to another aspect of the present invention, at least one embodiment provides a method for data packet integrity protection, including:
[0031] The second device receives the data packet sent by the first device and the integrity verification information of the data packet;
[0032] Group the received data packets, where each target data packet in each group has corresponding integrity verification information, and the number n of the target data packets is less than or equal to the total number m of the data packets in the group;
[0033] Perform integrity verification on the target data packets in the group to obtain the integrity verification result of each group.
[0034] In addition, according to at least one embodiment of the present invention, the performing integrity verification on the target data packets in the group includes:
[0035] Determine the target data packets in the group and determine the data packets covered by the integrity protection of each target data packet, where the union of the data packets covered by the integrity protection of all target data packets is all the data packets in the group;
[0036] For the target data packet, generate a first sequence number according to the sequence numbers of the data packets covered by the integrity protection of the target data packet;
[0037] Generate the information to be verified corresponding to the target data packet by using preset parameters and an integrity key, where the preset parameters at least include the first sequence number;
[0038] Compare the information to be verified corresponding to the target data packet with the integrity verification information corresponding to the target data packet to obtain the integrity verification result of the target data packet, where the integrity verification information corresponding to the target data packet is attached to the end of the target data packet.
[0039] In addition, according to at least one embodiment of the present invention, the obtaining the integrity verification result of each group includes:
[0040] When the integrity verification results of all target data packets in the group are all passed, obtain the verification result that the integrity verification of the group passes, otherwise, determine the verification result that the integrity verification of the group fails;
[0041] Or,
[0042] When the integrity verification result of each target data packet is passed, obtain the verification result that the integrity verification of all the data packets covered by the integrity protection of the target data packet passes, otherwise, obtain the verification result that the integrity verification of all the data packets covered by the integrity protection of the target data packet fails.
[0043] In addition, according to at least one embodiment of the present invention, the target data packet is:
[0044] n data packets randomly selected from the group;
[0045] Or,
[0046] n data packets at preset positions in the group.
[0047] In addition, according to at least one embodiment of the present invention, the manner of selecting the target data packets in each group is independent of each other.
[0048] In addition, according to at least one embodiment of the present invention, determining the data packets covered by the integrity protection of the target data packet includes any of the following determination methods:
[0049] Equal division determination method: Divide the data packets in the group into n segments according to a preset data packet interval L; According to the correspondence between the segments and the target data packets, determine all the data packets in each segment as the data packets covered by the integrity protection of the corresponding target data packet, where L is the integer value obtained by rounding down m / n.
[0050] Full amount determination method: Determine all the data packets in the group where the target data packet is located as the data packets covered by the integrity protection of the target data packet;
[0051] Random determination method: Obtain the sequence number of the data packet cascaded with the target data packet, and determine the data packets covered by the integrity protection of the target data packet according to the obtained sequence number.
[0052] In addition, according to at least one embodiment of the present invention, when dividing the data packets in the group into n segments according to a preset data packet interval L, if m cannot be divided evenly by n, the remaining data packets are incorporated into the existing segments.
[0053] In addition, according to at least one embodiment of the present invention, it further includes:
[0054] Negotiate with the first device to determine the values of m and n, and the manner of determining the data packets covered by the integrity protection of each target data packet.
[0055] In addition, according to at least one embodiment of the present invention, the first sequence number is obtained by performing an exclusive OR calculation on the sequence numbers of the data packets covered by the integrity protection of the target data packet.
[0056] According to another aspect of the present invention, at least one embodiment provides a first device, including:
[0057] A grouping module, configured to group the data packets to be transmitted to obtain at least one group;
[0058] A protection module, configured to perform integrity protection on target data packets in a group according to the group, and generate integrity check information, where the number n of the target data packets is less than or equal to the total number m of data packets in the group;
[0059] A sending module, configured to send the data packets and the integrity check information to a second device.
[0060] According to another aspect of the present invention, at least one embodiment provides a first device, including a transceiver and a processor, where,
[0061] The processor is configured to group data packets to be transmitted to obtain at least one group; perform integrity protection on target data packets in the group according to the group, and generate integrity check information, where the number n of the target data packets is less than or equal to the total number m of data packets in the group;
[0062] The transceiver is configured to send the data packets and the integrity check information to a second device.
[0063] According to another aspect of the present invention, at least one embodiment provides a first device, including: a processor, a memory, and a program stored on the memory and executable on the processor, where when the program is executed by the processor, the steps of the method described above are implemented.
[0064] According to another aspect of the present invention, at least one embodiment provides a second device, including:
[0065] A receiving module, configured to receive data packets sent by a first device and integrity check information of the data packets;
[0066] A grouping module, configured to group the received data packets, where each target data packet in a group has corresponding integrity check information, and the number n of the target data packets is less than or equal to the total number m of data packets in the group;
[0067] A verification module, configured to perform integrity verification on target data packets in a group to obtain an integrity verification result of each group.
[0068] According to another aspect of the present invention, at least one embodiment provides a second device, including a transceiver and a processor, where,
[0069] The transceiver is configured to receive data packets sent by a first device and integrity check information of the data packets;
[0070] The processor is configured to group the received data packets, where each target data packet in a group has corresponding integrity check information, and the number n of the target data packets is less than or equal to the total number m of the data packets in the group; perform integrity check on the target data packets in the group to obtain the integrity check result of each group.
[0071] According to another aspect of the present invention, at least one embodiment provides a second device, which includes: a processor, a memory, and a program stored on the memory and executable on the processor. When the program is executed by the processor, the steps of the method described above are implemented.
[0072] According to another aspect of the present invention, at least one embodiment provides a computer-readable storage medium, on which a program is stored. When the program is executed by a processor, the steps of the method described above are implemented.
[0073] Compared with the prior art, the method and device for protecting the integrity of data packets provided by the embodiments of the present invention regard several data packets as a whole to provide partial integrity protection, so as to provide probabilistic integrity protection for user data packets while meeting performance requirements. Description of the Drawings
[0074] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:
[0075] Figure 1 It is a schematic diagram of the prior art for protecting the integrity of data packets at the sending end and the receiving end;
[0076] Figure 2 It is a schematic diagram of the prior art for performing integrity protection operation on data packets at the sending end;
[0077] Figure 3 It is a schematic diagram of the prior art for performing integrity protection verification operation on data packets at the receiving end;
[0078] Figure 4 It is a flowchart of a method for protecting the integrity of data packets according to an embodiment of the present invention;
[0079] Figure 5 It is a schematic diagram of performing integrity protection operation on data packets at the sending end according to an embodiment of the present invention;
[0080] Figure 6 It is a schematic diagram of negotiating relevant parameters between the sending end and the receiving end according to an embodiment of the present invention;
[0081] Figure 7 Another flowchart of the method for protecting the integrity of data packets according to an embodiment of the present invention;
[0082] Figure 8 A schematic diagram for verifying the integrity protection of data packets at the receiving end according to an embodiment of the present invention;
[0083] Figure 9 A schematic structural diagram of a first device provided by an embodiment of the present invention;
[0084] Figure 10 Another schematic structural diagram of a first device provided by an embodiment of the present invention;
[0085] Figure 11 A schematic structural diagram of a second device provided by an embodiment of the present invention;
[0086] Figure 12 Another schematic structural diagram of a second device provided by an embodiment of the present invention. Detailed implementation manners
[0087] Hereinafter, exemplary embodiments of the present invention will be described in more detail with reference to the accompanying drawings. Although the exemplary embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present invention can be more thoroughly understood and the scope of the present invention can be completely conveyed to those skilled in the art.
[0088] The terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily limit to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices. "And / or" in the specification and claims means at least one of the connected objects.
[0089] The following description provides examples and is not intended to limit the scope, applicability, or configuration set forth in the claims. Changes may be made to the function and arrangement of the elements discussed without departing from the spirit and scope of the disclosure. Various examples may appropriately omit, substitute, or add various procedures or components. For example, the described method may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0090] Please refer to Figure 4 , a method for protecting the integrity of data packets provided by an embodiment of the present invention is applied to a first device. Specifically, the first device may be a sending device. Considering the two-way transmission of data, the first device may also be both a sending device and a receiving device. As Figure 4 shown, the method for protecting the integrity of data packets includes:
[0091] Step 41, the first device groups the data packets to be transmitted to obtain at least one group.
[0092] Here, when the first device sends data packets to the second device, it groups the data packets to be transmitted. Specifically, it can group them according to a preset group size, and the group size can be characterized by the number of data packets included in the group. This can make most groups have the same number of data packets. Of course, in the embodiment of the present invention, a dynamic group size may also be adopted, and the group size can be dynamically adjusted according to the rate of the received data packets. Generally, the group size is positively correlated with the rate of the data packets, that is, the greater the rate of the data packets, the more data packets included in the group; conversely, the smaller the rate of the data packets, the fewer data packets included in the group. Through the above method, one or more groups can be obtained, and one group can include one or more data packets. Figure 5 An example of grouping data packets according to the group size m is given, where data packets Message_1 to Message_m are the first group, data packets Message_m + 1 to Message_2m are the second group, and so on, to obtain multiple groups.
[0093] Step 42, according to the group, perform integrity protection on the target data packets in the group to generate integrity verification information, where the number n of the target data packets is less than or equal to the total number m of the data packets in the group.
[0094] Here, when the embodiment of the present invention performs integrity protection, it is based on grouping, thus changing the practice of performing integrity protection on each data packet in the prior art. Therefore, when there are multiple data packets in a group, the embodiment of the present invention can reduce the computational load of integrity protection and improve the efficiency of data integrity protection. When performing integrity protection on a group, integrity protection can be performed on all or part of the data packets in the group. In this article, these data packets that have undergone integrity protection operations are referred to as target data packets.
[0095] Step 43, send the data packet and the integrity verification information to the second device.
[0096] Here, after generating the integrity verification information, the first device can send the integrity verification information and the data packet to the second device together. Specifically, usually the integrity verification information can be attached to the tail of the target data packet. When generating one integrity verification information for multiple target data packets, this integrity verification information can be attached to the tail of the last data packet among the multiple target data packets.
[0097] Figure 5 An example of performing integrity protection on n target data packets out of m data packets in each group is given. For example, integrity protection is performed on the data packet Message_2 in the first group, and the integrity verification information MAC-I_1 is generated and attached to the tail of the data packet Message_2.
[0098] Through the above steps, the embodiment of the present invention groups the data packets to be sent and then performs data integrity protection on the groups. Thus, even in the case where full-rate data packets cannot be fully integrity processed, the embodiment of the present invention can regard several data packets as a whole to provide partial integrity protection, so as to provide probabilistic integrity protection for user data packets while meeting performance requirements and improve the efficiency of data integrity protection.
[0099] When the embodiment of the present invention performs integrity protection on a group in the above step 42, it can perform protection on the target data packets in the group. Specifically, performing integrity protection on the target data packets in the group according to the group may include:
[0100] A) Select n data packets from the group as target data packets, and determine the data packets covered by the integrity protection of each target data packet, where the union of the data packets covered by the integrity protection of all target data packets is all the data packets in the group.
[0101] Here, n data packets are selected from the group as target data packets. Specifically, it can be randomly selecting n data packets from the group as target data packets according to a random selection method, or selecting n data packets at a preset position from the group as the target data packets according to a fixed-position selection method. For example, selecting odd- or even-positioned data packets within the group, or selecting a data packet at a specific position from each segment as the target data packet. The definition of the segment can refer to the description below. The methods of selecting target data packets in different groups can be the same, that is, they are all selected according to the same rule. To improve the security of integrity protection, the methods of selecting the target data packets in each group of embodiments of the present invention can be independent of each other, that is, each group independently selects its own target data packet, and their respective selection methods may be the same or different.
[0102] In embodiments of the present invention, the data packets covered by the integrity protection of each target data packet refer to the data packets targeted when the integrity protection of the target data packet is performed. Generally, it can include the target data packet itself (as an implementation method, it can also not include the target data packet itself), and can also include other data packets within the group. The method of determining the data packets covered by the integrity protection of each target data packet can include any of the following determination methods:
[0103] 1) Equal-division determination method: Divide the data packets in the group into n segments according to a preset data packet interval L; according to the corresponding relationship between the segments and the target data packets, all the data packets in each segment are used as the data packets covered by the corresponding target data packet integrity protection, where L is an integer value obtained by rounding down m / n.
[0104] For example, if there are 12 data packets in the group, they can be divided into 4 segments according to every 3 data packets belonging to the same segment, that is, data packets 1-3 in the group are the first segment, data packets 4-6 are the second segment, data packets 7-9 are the third segment, and data packets 10-12 are the fourth segment.
[0105] These four segments correspond one-to-one with the 4 target data packets in this group:
[0106] As an implementation, assume that the 4 target data packets are respectively the first data packets in each segment. Then, the data packets covered by data packet 1 in the first segment (i.e., the first target data packet in this segment) are all the data packets in the first segment; the data packets covered by data packet 4 in the second segment (i.e., the first target data packet in this segment) are all the data packets in the second segment; the data packets covered by data packet 7 in the third segment (i.e., the first target data packet in this segment) are all the data packets in the third segment; and the data packets covered by data packet 10 in the fourth segment (i.e., the first target data packet in this segment) are all the data packets in the fourth segment.
[0107] As another implementation, assume that the 4 target data packets are respectively data packets 1 to 4 in the packet. Then, the data packets covered by data packet 1 are all the data packets in the first segment; the data packets covered by data packet 2 are all the data packets in the second segment; the data packets covered by data packet 3 are all the data packets in the third segment; and the data packets covered by data packet 4 are all the data packets in the fourth segment.
[0108] In addition, when dividing the data packets in the packet into n segments according to the preset data packet interval L, if m cannot be divided evenly by n, the remaining data packets are incorporated into the existing segments. The specific incorporation method can be to incorporate all the remaining data packets into the last segment or the first segment.
[0109] In the embodiments of the present invention, the equal division determination method selects to perform the integrity protection operation in an equal division manner. For example, the integrity check information MAC-I_1 is generated based on the packet sequence numbers (COUNT) of MESSAGE_1, MESSAGE_2,..., MESSAGE_m / n; the integrity check information MAC-I_2 is generated based on the packet sequence numbers (COUNT) of MESSAGE_m / n + 1,..., MESSAGE_2m / n, and so on. In the case where m / n cannot be divided evenly, the extra packet IDs can be incorporated into the integrity protection operation of the last data packet, or evenly distributed to the integrity protection operations of several data packets from back to front.
[0110] 2) Full amount determination method: All the data packets in the packet where the target data packet is located are used as the data packets covered by the integrity protection of the target data packet.
[0111] When the full amount determination method is adopted, the data packets covered by each target data packet are all the data packets in the packet. For example, the integrity check information MAC-I_1 is generated based on all the COUNTs from MESSAGE_1 to MESSAGE_m, and the same applies to MAC-I_2 to MAC-I_n.
[0112] 3) Random determination method: Randomly select at least one data packet from within the said group as the data packets covered by the integrity protection of the said target data packet.
[0113] For example, MAC-I_1 is generated based on the COUNT of MESSAGE_1, MESSAGE_3, etc., MAC-I_2 is generated based on the COUNT of MESSAGE_4, etc., and MAC-I_n is generated based on the COUNT of MESSAGE_2, etc. The union of the data packets covered by all target data packets is: all data packets within the respective group. Additionally, when adopting the said random determination method, the sequence number of the randomly selected data packet can also be concatenated with the said target data packet to obtain the updated said target data packet. In this way, the target data packet contains the sequence numbers of all the data packets it covers. For example, when adopting the random determination method to select the data packets covered by the data packet MESSAGE, the data packet MESSAGE is updated, and a list of the sequence number (COUNT) values of the covered data packets is added after the original data packet MESSAGE. Assume that the MAC-I of the data packet MESSAGE needs to cover t data packets, and these t data packets are respectively denoted as MESSAGE[1], MESSAGE[2], ……, MESSAGE[t]. Then:
[0114] MESSAGE’ = MESSAGE || COUNT[1] || COUNT[2] || …… || COUNT[t]
[0115] where COUNT[i] represents the sequence number of the i-th data packet, and || represents concatenation.
[0116] In the embodiments of the present invention, for the target data packets for which integrity protection operations are implemented, their distribution can be random or fixed. To ensure that an attacker cannot know which data packet contains the MAC-I information required for integrity protection, the data packets for which operations are implemented in each group of data packets can be randomly selected, and the selection of data packets between groups can be independent.
[0117] B) For the said target data packet, generate a first sequence number according to the sequence numbers of the data packets covered by the integrity protection of the said target data packet.
[0118] As an implementation, the first sequence number is obtained by performing an exclusive OR (XOR) calculation on the sequence numbers of each data packet covered by the integrity protection of the target data packet. For example, assume that the MAC-I of a specific data packet needs to cover t data packets, and these t data packets are respectively denoted as MESSAGE[1], MESSAGE[2], ……, MESSAGE[t]. Then, the first sequence number COUNT can be calculated in the following manner:
[0119] COUNT = COUNT[1] XOR COUNT[2] XOR …… XOR COUNT[t].
[0120] Where XOR represents the exclusive OR.
[0121] As another implementation, the first sequence number can also be obtained by concatenating the sequence numbers of each data packet covered by the integrity protection of the target data packet.
[0122] C) Using preset parameters and an integrity key, generate the integrity check information corresponding to the target data packet, and append it to the end of the target data packet, where the preset parameters at least include the first sequence number.
[0123] Here, when generating the integrity check information MAC-I information corresponding to the target data packet, an existing MAC-I generation process can be adopted. For example, using parameters related to the data packet, which can include the uplink / downlink direction DIRECTION of the data packet, the sequence number (COUNT, also referred to as the counter), the bearer identifier BEARER, and the corresponding integrity key KEY for calculation. However, MESSAGE and COUNT need to change. Since the MAC-I may contain the sequence number information of multiple MESSAGEs at this time, the first sequence number is used to replace the sequence number of this data packet for calculation; and for the method of determining the data packets covered by the integrity protection of each target data packet being the random determination method, when generating the MAC-I information, the data packet is replaced by MESSAGE’.
[0124] Specifically, the preset parameters including the first sequence number can be input into an integrity check algorithm to generate the integrity check information corresponding to the target data packet. In an embodiment of the present invention, the generated integrity check information can be appended to the end of the target data packet, that is, at the tail position of the packet.
[0125] In an embodiment of the present invention, the first device can also negotiate with the second device to determine the values of m and n, and the method of determining the data packets covered by the integrity protection of each target data packet. Figure 6 An example of negotiating parameters at the receiving end and the sending end is given.Figure 6 The sending end in can be the first device, and the receiving end can be the second device. Between the receiving end and the sending end, relevant parameters need to be negotiated in advance so that the receiving end and the sending end can share information such as m, n, and the operation rules (i.e., the way of the data packets covered by the target data packet integrity protection, denoted by OP). Among them, the operation rules can be pre-coded and replaced by the code during transmission. For example, the equal division determination method is coded as OP1, the full amount determination method is coded as OP2, and the random determination method is coded as OP3. The negotiation between the receiving end and the sending end can be transmitted through the radio resource control (RRC) signaling. The sending end sends the expected value ranges of m, n, and OP in Message 1, and the receiving end selects a value of each parameter from the above value ranges and then returns it to the receiving end in Message 2, thus completing the parameter negotiation process. Since the RRC signaling channel has the capabilities of encryption and integrity protection, the negotiation and transmission of parameters can be safely implemented between the receiving end and the sending end.
[0126] As can be seen from the above, in the embodiment of the present invention, at the sending end, several (assumed to be m) data packets are encoded into a group, and among them, some (assumed to be n, n ≤ m) data (target data packets) are selected to perform the integrity protection operation. When performing operations on some data packets, the information of other data packets in the group will be included. Since the data integrity protection is performed on the group, the embodiment of the present invention can improve the efficiency of integrity protection.
[0127] The method of the embodiment of the present invention has been described above from the sending end. The following further describes it from the receiving end.
[0128] Please refer to Figure 7 , the method for data packet integrity protection provided by the embodiment of the present invention, when applied to the second device, includes:
[0129] Step 71, the second device receives the data packets sent by the first device and the integrity verification information of the data packets.
[0130] Step 72, group the received data packets. Among them, each target data packet in the group has corresponding integrity verification information, and the number n of the target data packets is less than or equal to the total number m of the data packets in the group.
[0131] Here, the second device can group the received data packets according to the group size m. The values of the group size m and n can be obtained in advance through negotiation with the first device.
[0132] Step 73, perform integrity verification on the target data packets in the group to obtain the integrity verification result of each group.
[0133] Here, the target data packets can be n data packets randomly selected from the packets, or n data packets at preset positions in the packets. Additionally, the manner of selecting the target data packets in each packet can be independent of each other.
[0134] When the target data packets are randomly selected at the sending end (the first device) for integrity protection operations, the second device can determine which data packets in the packet are the target data packets that have undergone integrity protection operations in the following manner: Since the first device attaches integrity check information to the tail of the corresponding target data packets, the second device can determine the target data packets in the packet based on whether there is integrity check information at the tail. For the case where the sending end (the first device) selects the data packets at preset positions in the packet for integrity protection operations, the second device can determine the target data packets according to the preset positions.
[0135] When performing integrity verification on the target data packets in the packet, it can specifically include the following steps s1 to s4:
[0136] Step s1: The second device can determine the target data packets in the packet and determine the data packets covered by the integrity protection of each target data packet. Among them, the union of the data packets covered by the integrity protection of all target data packets is all the data packets in the packet.
[0137] Here, the second device can negotiate and interact with the first device in advance to determine the values of m and n, and the manner of determining the data packets covered by the integrity protection of each target data packet. In this way, the second device can determine which of the following methods to use to determine the data packets covered by the integrity protection of the target data packets. These methods specifically include:
[0138] A) Equal division determination method: Divide the data packets in the packet into n segments according to a preset data packet interval L; according to the correspondence between the segments and the target data packets, determine all the data packets in each segment as the data packets covered by the integrity protection of the corresponding target data packet, where L is the integer value obtained by rounding down m / n. Among them, when dividing the data packets in the packet into n segments according to the preset data packet interval L, if m cannot be divided evenly by n, then incorporate the remaining data packets into the existing segments.
[0139] B) Full amount determination method: Determine all the data packets in the packet where the target data packet is located as the data packets covered by the integrity protection of the target data packet.
[0140] C) Random determination method: Obtain the sequence numbers of the data packets cascaded with the target data packet, and determine the data packets covered by the integrity protection of the target data packet according to the obtained sequence numbers.
[0141] Step S2: For the target data packet, generate a first sequence number according to the sequence numbers of the data packets covered by the integrity protection of the target data packet. For example, the first sequence number may be obtained by performing an exclusive OR calculation on the sequence numbers of the respective data packets covered by the integrity protection of the target data packet.
[0142] Step S3: Use preset parameters and an integrity key to generate verification information to be verified corresponding to the target data packet, where the preset parameters at least include the first sequence number.
[0143] Step S4: Compare the verification information to be verified corresponding to the target data packet with the integrity verification information corresponding to the target data packet to obtain the integrity verification result of the target data packet. For example, whether the target data packet passes the integrity verification, where the integrity verification information corresponding to the target data packet is attached to the end of the target data packet.
[0144] After obtaining the integrity verification result of the target data packet, the embodiment of the present invention may further generate an integrity verification result of a group as the final verification result of the data packets within the group.
[0145] As an implementation manner, the embodiment of the present invention may obtain the final verification result that the integrity verification of the group passes when the integrity verification results of all target data packets within the group are all passed; otherwise, determine the final verification result that the integrity verification of the group fails. In this manner, it is required that the verification of all target data packets in the group passes before determining that the integrity verification of the group passes. That is to say, there are only two final verification results for this verification method: all data packets within the group pass the verification or all do not pass the verification. Figure 8 An example of this verification method is given. In this example, in the group Message_m+1~Message_2m, the integrity verification information MAC-I_2n of the data packet Message_2m does not match the verification information to be verified XMAC-I_2n of this data packet generated by the second device, resulting in the entire group Message_m+1~Message_2m failing to pass the integrity verification.
[0146] For another example, as another implementation, in the embodiments of the present invention, when the integrity verification result of each target data packet passes, the final verification result that the integrity verification of all data packets covered by the integrity protection of the target data packet passes is obtained; otherwise, the final verification result that the integrity verification of all data packets covered by the integrity protection of the target data packet fails is obtained. In this implementation, the verification result is only responsible for the data packets covered by the integrity protection of the target data packet. That is to say, there may be a situation where some data packets in the packet pass the verification and some data packets fail the verification. This verification method is generally applicable to the scenario where the data packets covered by different target data packets in the packet do not overlap.
[0147] In addition, for the method of randomly determining the data packets covered by the integrity protection of each target data packet, when the final verification result of the integrity verification of the corresponding packet passes, the embodiments of the present invention also strip the list of sequence number (COUNT) values of the covered data packets from the target data packet, and restore the data packet to the form of the original data packet, that is, restore the data packet MESSAGE’ to MESSAGE.
[0148] Considering that when an attacker tries to tamper with a data packet, the attacker needs to continuously or randomly select data packets for attack. And the attacker does not want to be discovered during the attack. Then, for the case of continuous attack, usually the data packets protected by integrity are tampered with, which will lead to the discovery of the attack, so that the attack behavior can be discovered. And for the case of randomly selecting data packets for attack, the probability that the attacker selects a data packet protected by integrity is approximately p = n / m, which will lead to the discovery of the attack. Therefore, the embodiments of the present invention can prevent the attacker to a certain extent.
[0149] Through the above steps, the embodiments of the present invention can verify the data packets containing integrity information sent by the first device. Since the embodiments of the present invention perform integrity protection and verification on a packet basis, the computing amount can be reduced and the efficiency of integrity protection and verification can be improved.
[0150] The various methods of the embodiments of the present invention are introduced above. Next, an apparatus for implementing the above methods will be further provided.
[0151] Please refer to Figure 9 , the embodiments of the present invention provide a first device, including:
[0152] A grouping module 91, configured to group the data packets to be transmitted to obtain at least one group;
[0153] A protection module 92 is used to perform integrity protection on the target data packets in the group according to the group, generate integrity check information, where the number n of the target data packets is less than or equal to the total number m of the data packets in the group;
[0154] A sending module 93 is used to send the data packets and the integrity check information to a second device.
[0155] Through the above modules, the first device according to the embodiment of the present invention can improve the efficiency of data integrity protection, and can, to a certain extent, detect the behavior of an attacker tampering with data packets, thereby improving the security of data transmission.
[0156] Optionally, the protection module 92 is further used for:
[0157] Select n data packets from the group as target data packets, and determine the data packets covered by the integrity protection of each target data packet, where the union of the data packets covered by the integrity protection of all target data packets is all the data packets in the group;
[0158] For the target data packets, generate a first sequence number according to the sequence numbers of the data packets covered by the integrity protection of the target data packets;
[0159] Generate the integrity check information corresponding to the target data packets by using preset parameters and an integrity key, and append it to the end of the target data packets, where the preset parameters at least include the first sequence number.
[0160] Optionally, the protection module 92 is further used for:
[0161] Randomly select n data packets from the group as target data packets according to a random selection method;
[0162] Or,
[0163] Select n data packets at preset positions from the group as the target data packets according to a fixed position selection method.
[0164] Optionally, the methods of selecting the target data packets from each group are independent of each other.
[0165] Optionally, the protection module 92 is further used for: determining the data packets covered by the integrity protection of each target data packet according to any one of the following determination methods:
[0166] Equal division determination method: Divide the data packets in the group into n segments according to a preset data packet interval L; according to the correspondence between the segments and the target data packet, all the data packets in each segment are used as the data packets covered by the integrity protection of the corresponding target data packet, where L is an integer value obtained by rounding down m / n.
[0167] Full amount determination method: All the data packets in the group where the target data packet is located are used as the data packets covered by the integrity protection of the target data packet.
[0168] Random determination method: Randomly select at least one data packet from the group as the data packet covered by the integrity protection of the target data packet.
[0169] Optionally, when dividing the data packets in the group into n segments according to a preset data packet interval L, the grouping module is further configured to incorporate the remaining data packets into the existing segments if m cannot be divided evenly by n.
[0170] Optionally, when randomly selecting at least one data packet from the group as the data packet covered by the integrity protection of the target data packet, the protection module 92 is further configured to concatenate the sequence number of the randomly selected data packet with the target data packet to obtain the updated target data packet.
[0171] Optionally, the first device further includes:
[0172] A negotiation module, configured to negotiate with the second device to determine the values of m and n, and the method for determining the data packets covered by the integrity protection of each target data packet.
[0173] Optionally, the first sequence number is obtained by performing an exclusive OR calculation on the sequence numbers of the data packets covered by the integrity protection of the target data packet.
[0174] It should be noted that the device in this embodiment corresponds to the device in the above Figure 4 The implementation manners in the above embodiments are all applicable to the embodiments of this device and can also achieve the same technical effects. The above device provided by the embodiments of the present invention can implement all the method steps implemented by the above method embodiments and can achieve the same technical effects. The same parts and beneficial effects as those in the method embodiments will not be specifically described in this embodiment.
[0175] Please refer to Figure 10 , a schematic structural diagram of a first device provided by an embodiment of the present invention. The first device 1000 includes: a processor 1001, a transceiver 1002, a memory 1003, a user interface 1004, and a bus interface.
[0176] In an embodiment of the present invention, the first device 1000 further includes: a program stored on the memory 1003 and executable on the processor 1001.
[0177] When the processor 1001 executes the program, the following steps are implemented:
[0178] Optionally, when the processor executes the program, the following steps are further implemented:
[0179] Group the data packets to be transmitted to obtain at least one group;
[0180] According to the group, perform integrity protection on the target data packets in the group to generate integrity check information, where the number n of the target data packets is less than or equal to the total number m of the data packets in the group;
[0181] Send the data packets and the integrity check information to the second device.
[0182] It can be understood that in an embodiment of the present invention, when the computer program is executed by the processor 1001, the above Figure 4 shown various processes of the method embodiment for data packet integrity protection can be implemented, and the same technical effects can be achieved. To avoid repetition, it will not be elaborated here.
[0183] In Figure 10 , the bus architecture may include any number of interconnected buses and bridges, specifically various circuits of one or more processors represented by the processor 1001 and the memory represented by the memory 1003 are linked together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, etc. These are well known in the art, so they will not be further described herein. The bus interface provides an interface. The transceiver 1002 can be multiple components, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on the transmission medium. For different user devices, the user interface 1004 can also be an interface capable of externally connecting and internally connecting required devices, and the connected devices include but are not limited to a keypad, a display, a speaker, a microphone, a joystick, etc.
[0184] The processor 1001 is responsible for managing the bus architecture and general processing, and the memory 1003 can store the data used by the processor 1001 when executing operations.
[0185] It should be noted that the terminal in this embodiment is related to the above Figure 4The device corresponding to the method shown above. The implementation methods in the above embodiments are all applicable to the embodiments of this device and can achieve the same technical effects. In this device, the transceiver 1002 and the memory 1003, as well as the transceiver 1002 and the processor 1001, can all be communicatively connected through a bus interface. The functions of the processor 1001 can also be implemented by the transceiver 1002, and the functions of the transceiver 1002 can also be implemented by the processor 1001. It should be noted here that the above device provided by the embodiments of the present invention can implement all the method steps implemented by the above method embodiments and can achieve the same technical effects. Therefore, the same parts and beneficial effects as those in the method embodiments will not be specifically described in this embodiment.
[0186] In some embodiments of the present invention, a computer-readable storage medium is further provided, on which a program is stored. When the program is executed by a processor, the following steps are implemented:
[0187] Group the data packets to be transmitted to obtain at least one group;
[0188] According to the group, perform integrity protection on the target data packets in the group to generate integrity check information, where the number n of the target data packets is less than or equal to the total number m of the data packets in the group;
[0189] Send the data packets and the integrity check information to a second device.
[0190] When the program is executed by the processor, it can implement all the implementation methods in the method for protecting the integrity of data packets applied to the first device and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0191] The embodiments of the present invention provide Figure 11 A second device 110 shown as follows, including:
[0192] A receiving module 111, configured to receive the data packets and the integrity check information of the data packets sent by the first device;
[0193] A grouping module 112, configured to group the received data packets, where each target data packet in each group has corresponding integrity check information, and the number n of the target data packets is less than or equal to the total number m of the data packets in the group;
[0194] A verification module 113, configured to perform integrity verification on the target data packets in the group to obtain the integrity verification result of each group.
[0195] Optionally, the verification module 113 is further configured to:
[0196] Determine the target data packets in the group, and determine the data packets covered by the integrity protection of each target data packet. The union of all the data packets covered by the integrity protection of all target data packets is all the data packets in the group;
[0197] For the target data packets, generate a first sequence number according to the sequence numbers of the data packets covered by the integrity protection of the target data packets;
[0198] Generate the information to be verified corresponding to the target data packet by using preset parameters and an integrity key, where the preset parameters at least include the first sequence number;
[0199] Compare the information to be verified corresponding to the target data packet with the integrity verification information corresponding to the target data packet to obtain the integrity verification result of the target data packet, where the integrity verification information corresponding to the target data packet is attached to the end of the target data packet.
[0200] Optionally, the verification module 113 is further configured to:
[0201] When the integrity verification results of all target data packets in the group are all passed, obtain the verification result that the integrity verification of the group passes; otherwise, judge the verification result that the integrity verification of the group fails;
[0202] Or,
[0203] When the integrity verification result of each target data packet is passed, obtain the verification result that the integrity verification of all the data packets covered by the integrity protection of the target data packet passes; otherwise, obtain the verification result that the integrity verification of all the data packets covered by the integrity protection of the target data packet fails.
[0204] Optionally, the target data packet is:
[0205] n data packets randomly selected from the group;
[0206] Or,
[0207] n data packets at preset positions in the group.
[0208] Optionally, the ways of selecting the target data packets in each group are independent of each other.
[0209] Optionally, the verification module 113 is further configured to determine the data packets covered by the integrity protection of the target data packet according to any one of the following determination methods:
[0210] Equal division determination method: Divide the data packets in the group into n segments according to a preset data packet interval L; according to the correspondence between the segments and the target data packets, determine all the data packets in each segment as the data packets covered by the integrity protection of the corresponding target data packet, where L is the integer value obtained by rounding down m / n.
[0211] Full amount determination method: Determine all the data packets in the group where the target data packet is located as the data packets covered by the integrity protection of the target data packet.
[0212] Random determination method: Obtain the sequence number of the data packet cascaded with the target data packet, and determine the data packets covered by the integrity protection of the target data packet according to the obtained sequence number.
[0213] Optionally, when the packet module divides the data packets in the group into n segments according to a preset data packet interval L, if m cannot be divided evenly by n, the remaining data packets are incorporated into the existing segments.
[0214] Optionally, the second device further includes:
[0215] A negotiation module, configured to negotiate with the first device to determine the values of m and n, and the method for determining the data packets covered by the integrity protection of each target data packet.
[0216] Optionally, the first sequence number is obtained by performing an exclusive OR calculation on the sequence numbers of the data packets covered by the integrity protection of the target data packet.
[0217] It should be noted that the device in this embodiment corresponds to the device in the above Figure 7 shown method. The implementation methods in the above embodiments are all applicable to the embodiments of this device and can also achieve the same technical effects. Here, it should be noted that the above device provided by the embodiment of the present invention can implement all the method steps implemented by the above method embodiment and can achieve the same technical effects. The same parts and beneficial effects as those in the method embodiment in this embodiment will not be specifically described herein.
[0218] Please refer to Figure 12 , a schematic structural diagram of the second device 1200 provided by the embodiment of the present invention includes: a processor 1201, a transceiver 1202, a memory 1203, and a bus interface, where:
[0219] In the embodiment of the present invention, the second device 1200 further includes: a program stored on the memory 1203 and executable on the processor 1201. When the program is executed by the processor 1201, the following steps are implemented:
[0220] Receive the data packet sent by the first device and the integrity verification information of the data packet;
[0221] Group the received data packets. Among them, each target data packet in a group has corresponding integrity verification information, and the number n of the target data packets is less than or equal to the total number m of the data packets in the group;
[0222] Perform integrity verification on the target data packets in the group to obtain the integrity verification result of each group.
[0223] It can be understood that in the embodiments of the present invention, when the computer program is executed by the processor 1201, it can implement the various processes of the method embodiments of the above-mentioned Figure 7 shown data packet integrity protection, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0224] In Figure 12 , the bus architecture may include any number of interconnected buses and bridges, specifically, various circuits of one or more processors represented by the processor 1201 and the memory represented by the memory 1203 are linked together. The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art. Therefore, they will not be further described herein. The bus interface provides an interface. The transceiver 1202 can be multiple components, that is, including a transmitter and a receiver, and provides a unit for communicating with various other devices on the transmission medium.
[0225] The processor 1201 is responsible for managing the bus architecture and general processing, and the memory 1203 can store the data used by the processor 1201 when performing operations.
[0226] It should be noted that the terminal in this embodiment is a device corresponding to the above Figure 7 shown method. The implementation manners in the above embodiments are all applicable to the embodiments of this device and can also achieve the same technical effects. In this device, the transceiver 1202 and the memory 1203, as well as the transceiver 1202 and the processor 1201 can all be communicatively connected through the bus interface. The function of the processor 1201 can also be implemented by the transceiver 1202, and the function of the transceiver 1202 can also be implemented by the processor 1201. It should be noted here that the above device provided by the embodiments of the present invention can implement all the method steps implemented by the above method embodiments and can achieve the same technical effects. The same parts and beneficial effects as those in the method embodiments will not be specifically elaborated in this embodiment.
[0227] In some embodiments of the present invention, a computer-readable storage medium is further provided, on which a program is stored, and when the program is executed by a processor, the following steps are implemented:
[0228] Receive the data packet sent by the first device and the integrity verification information of the data packet;
[0229] Group the received data packets. Among them, each target data packet in a group has corresponding integrity verification information, and the number n of the target data packets is less than or equal to the total number m of the data packets in the group;
[0230] Perform integrity verification on the target data packets in the group to obtain the integrity verification result of each group.
[0231] When the program is executed by the processor, it can implement all implementation manners in the above method for protecting the integrity of data packets applied to the second device, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0232] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0233] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated here.
[0234] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0235] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present invention.
[0236] In addition, in each embodiment of the present invention, each functional unit may be integrated into a processing unit, may exist physically alone for each unit, or two or more units may be integrated into one unit.
[0237] If the above-mentioned function is implemented in the form of a software functional unit and sold or used as an independent product, it may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0238] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A method for protecting the integrity of data packets, characterized in that, it includes: The first device groups the data packets to be transmitted to obtain at least one group; According to the group, integrity protection is performed on the target data packets in the group to generate integrity check information, where the number n of the target data packets is less than or equal to the total number m of the data packets in the group; Send the data packets and the integrity check information to the second device; Among them, the union of the data packets covered by the integrity protection of all the target data packets in the group is all the data packets in the group. The data packets covered by the integrity protection of each target data packet are determined in any of the following ways: Equal division determination method: According to the preset data packet interval L, the data packets in the group are divided into n segments; according to the correspondence between the segments and the target data packets, all the data packets in each segment are used as the data packets covered by the integrity protection of the corresponding target data packet, where L is the integer value obtained by rounding down m / n; Full amount determination method: All the data packets in the group where the target data packet is located are used as the data packets covered by the integrity protection of the target data packet; Random determination method: Randomly select at least one data packet from the group as the data packet covered by the integrity protection of the target data packet.
2. The method according to claim 1, characterized in that, The integrity protection of the target data packets in the group according to the group includes: Select n data packets from the group as target data packets, and determine the data packets covered by the integrity protection of each target data packet; For the target data packets, generate a first sequence number according to the sequence numbers of the data packets covered by the integrity protection of the target data packets; Use the preset parameters and the integrity key to generate the integrity check information corresponding to the target data packet, and append it to the end of the target data packet, where the preset parameters at least include the first sequence number.
3. The method according to claim 2, characterized in that, The selection of n data packets from the group as target data packets includes: Randomly select n data packets from the group as target data packets according to the random selection method; Or, Select n data packets at preset positions from the group as the target data packets according to the fixed position selection method.
4. The method according to claim 3, characterized in that, The ways of selecting the target data packets from each group are independent of each other.
5. The method according to claim 1, characterized in that, When dividing the data packets in the group into n segments according to the preset data packet interval L, if m cannot be divided evenly by n, the remaining data packets are incorporated into the existing segments.
6. The method according to claim 1, characterized in that, When randomly selecting at least one data packet from the group as the data packet covered by the integrity protection of the target data packet, it further includes: Cascade the sequence number of the randomly selected data packet with the target data packet to obtain the updated target data packet.
7. The method according to claim 1, It is characterized in that It further includes: Negotiate with the second device to determine the values of m and n, and determine the way of determining the data packets covered by the integrity protection of each target data packet.
8. The method according to claim 2, It is characterized in that The first sequence number is obtained by performing an exclusive OR calculation on the sequence numbers of the respective data packets covered by the integrity protection of the target data packet.
9. A method for data packet integrity protection, It is characterized in that It includes: The second device receives the data packets sent by the first device and the integrity verification information of the data packets; Group the received data packets, where each target data packet in each group has corresponding integrity verification information, and the number n of the target data packets is less than or equal to the total number m of the data packets in the group; Perform integrity verification on the target data packets in the group to obtain the integrity verification result of each group; Among them, the union of the data packets covered by the integrity protection of all the target data packets in the group is all the data packets in the group, and the data packets covered by the integrity protection of each target data packet are determined in any of the following ways: Equal division determination method: Divide the data packets in the group into n segments according to a preset data packet interval L; according to the corresponding relationship between the segments and the target data packets, determine all the data packets in each segment as the data packets covered by the integrity protection of the corresponding target data packet, where L is the integer value obtained by rounding down m / n; Full amount determination method: Determine all the data packets in the group where the target data packet is located as the data packets covered by the integrity protection of the target data packet; Random determination method: Obtain the sequence number of the data packet cascaded with the target data packet, and determine the data packets covered by the integrity protection of the target data packet according to the obtained sequence number.
10. The method according to claim 9, It is characterized in that The performing integrity verification on the target data packets in the group includes: Determine the target data packets in the group, and determine the data packets covered by the integrity protection of each target data packet; For the target data packet, generate a first sequence number according to the sequence numbers of the data packets covered by the integrity protection of the target data packet; Generate the information to be verified corresponding to the target data packet by using preset parameters and an integrity key, where the preset parameters at least include the first sequence number; Compare the information to be verified corresponding to the target data packet with the integrity verification information corresponding to the target data packet to obtain the integrity verification result of the target data packet, where the integrity verification information corresponding to the target data packet is attached to the end of the target data packet.
11. The method according to claim 10, It is characterized in that The obtaining the integrity verification result of each group includes: When the integrity verification results of all the target data packets in the group are all passed, obtain the verification result that the integrity verification of the group is passed, otherwise, judge the verification result that the integrity verification of the group fails; Or, When the integrity verification result of each target data packet passes, obtain the verification results that the integrity verifications of all data packets covered by the integrity protection of the target data packet pass; otherwise, obtain the verification results that the integrity verifications of all data packets covered by the integrity protection of the target data packet all fail.
12. The method according to claim 10, wherein, the target data packet is: n data packets randomly selected from the group; or, n data packets at preset positions in the group.
13. The method according to claim 12, wherein, the ways of selecting the target data packets in each group are independent of each other.
14. The method according to claim 9, wherein, when dividing the data packets in the group into n segments according to a preset data packet interval L, if m cannot be divided evenly by n, incorporate the remaining data packets into the existing segments.
15. The method according to claim 9, wherein, further comprising: negotiating with the first device to determine the values of m and n, and the way to determine the data packets covered by the integrity protection of each target data packet.
16. The method according to claim 10, wherein, the first sequence number is obtained by performing an exclusive OR calculation on the sequence numbers of the data packets covered by the integrity protection of the target data packet.
17. A first device for data packet integrity protection, wherein, comprising: a grouping module, configured to group the data packets to be transmitted to obtain at least one group; a protection module, configured to perform integrity protection on the target data packets in the group according to the group to generate integrity verification information, where the number n of the target data packets is less than or equal to the total number m of the data packets in the group; a sending module, configured to send the data packets and the integrity verification information to a second device.
18. A first device for data packet integrity protection, wherein, comprising a transceiver and a processor, wherein, the processor is configured to group the data packets to be transmitted to obtain at least one group; perform integrity protection on the target data packets in the group according to the group to generate integrity verification information, where the number n of the target data packets is less than or equal to the total number m of the data packets in the group; the transceiver is configured to send the data packets and the integrity verification information to a second device; wherein, the union of the data packets covered by the integrity protection of all the target data packets in the group is all the data packets in the group, and the data packets covered by the integrity protection of each target data packet are determined in any of the following ways: Equal division determination method: divide the data packets in the group into n segments according to a preset data packet interval L; according to the corresponding relationship between the segments and the target data packets, take all the data packets in each segment as the data packets covered by the integrity protection of the corresponding target data packet, where L is the integer value obtained by rounding down m / n; Full amount determination method: take all the data packets in the group where the target data packet is located as the data packets covered by the integrity protection of the target data packet; Random determination method: Randomly select at least one data packet from within the group as the data packets covered by the integrity protection of the target data packet.
19. A first device for data packet integrity protection Characterized in that It includes: A processor, a memory, and a program stored on the memory and executable on the processor. When the program is executed by the processor, it implements the steps of the method according to any one of claims 1 to 8.
20. A second device for data packet integrity protection Characterized in that It includes: A receiving module, configured to receive a data packet sent by a first device and integrity verification information of the data packet; A grouping module, configured to group the received data packets. Among them, each target data packet in each group has corresponding integrity verification information, and the number n of the target data packets is less than or equal to the total number m of the data packets within the group; A verification module, configured to perform integrity verification on the target data packets in the group to obtain an integrity verification result for each group; Among them, the union of the data packets covered by the integrity protection of all the target data packets within the group is all the data packets within the group. For each data packet covered by the integrity protection of a target data packet, it is determined in any one of the following ways: Equal division determination method: Divide the data packets within the group into n segments according to a preset data packet interval L; according to the corresponding relationship between the segments and the target data packets, determine all the data packets within each segment as the data packets covered by the integrity protection of the corresponding target data packet, where L is an integer value obtained by rounding down m / n; Full amount determination method: Determine all the data packets within the group where the target data packet is located as the data packets covered by the integrity protection of the target data packet; Random determination method: Obtain the sequence number of the data packet cascaded with the target data packet, and determine the data packets covered by the integrity protection of the target data packet according to the obtained sequence number.
21. A second device for data packet integrity protection Characterized in that It includes a transceiver and a processor, where The transceiver is configured to receive a data packet sent by a first device and integrity verification information of the data packet; The processor is configured to group the received data packets. Among them, each target data packet in each group has corresponding integrity verification information, and the number n of the target data packets is less than or equal to the total number m of the data packets within the group; perform integrity verification on the target data packets in the group to obtain an integrity verification result for each group.
22. A second device for data packet integrity protection Characterized in that It includes: A processor, a memory, and a program stored on the memory and executable on the processor. When the program is executed by the processor, it implements the steps of the method according to any one of claims 9 to 16.
23. A computer-readable storage medium Characterized in that A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 16.
Citation Information
Patent Citations
Method and apparatus for verifying data packet integrity in a streaming data channel
CN102057650A
Data transmission method and device
CN111800372A