A processing method, apparatus and communication device for data transmission protection

By employing encrypted and integrity-protected signaling radio bearer transmission of C-RNTI during the PRACH process, the problem of C-RNTI leakage is solved, thereby improving the security and privacy of data transmission.

CN114915967BActive Publication Date: 2026-04-24CHINA MOBILE COMM LTD RES INST +1
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE COMM LTD RES INST
Filing Date
2021-02-08
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

In existing technologies, the Physical Random Access Channel (PRACH) process is not encrypted, which makes the Cell Radio Network Temporary Identifier (C-RNTI) easy to be leaked, affecting the security of user plane data.

Method used

Sending C-RNTI to the terminal via encrypted and integrity-protected signaling radio bearers, including transmitting C-RNTI via encrypted and integrity-protected RRC signaling when preset conditions are met, enhances the security of data transmission.

Benefits of technology

This effectively prevents C-RNTI from being obtained by unauthorized devices, protects user plane data, and ensures the security and privacy of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114915967B_ABST
    Figure CN114915967B_ABST
Patent Text Reader

Abstract

Embodiments of the present application disclose a processing method, device and communication equipment for data transmission protection. The method comprises: when a base station determines that a preset condition is met, sending a cell radio network temporary identifier (C-RNTI) to a terminal through an encrypted and integrity-protected signaling radio bearer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of wireless communication technology, and more specifically to a processing method, apparatus, and communication device for data transmission protection. Background Technology

[0002] Currently, terminals access the system via the Physical Random Access Channel (PRACH). To ensure successful access for all users, the PRACH process is unencrypted; subsequent signaling is encrypted only after successful access. The Cell-Radio Network Temporary Identifier (C-RNTI) exchanged during the PRACH process is crucial for obtaining user plane data, and the unencrypted PRACH process makes the C-RNTI susceptible to leakage. Summary of the Invention

[0003] To address the existing technical problems, embodiments of the present invention provide a processing method, apparatus, and communication device for data transmission protection.

[0004] To achieve the above objectives, the technical solution of this invention is implemented as follows:

[0005] In a first aspect, embodiments of the present invention provide a processing method for data transmission protection, the method comprising:

[0006] When the base station determines that the preset conditions are met, it sends C-RNTI to the terminal through encrypted and integrity-protected signaling radio bearers.

[0007] In the above scheme, sending C-RNTI to the terminal via encrypted and integrity-protected signaling radio bearer includes:

[0008] The C-RNTI is sent to the terminal via encrypted and integrity-protected Radio Resource Control (RRC) signaling.

[0009] In the above scheme, determining that the preset conditions are met includes:

[0010] After determining that the terminal has completed encryption and integrity protection, and before transmitting data, the base station determines that preset conditions are met.

[0011] In the above scheme, after the terminal completes integrity protection and encryption but before transmitting data, it determines that the preset conditions are met, including: the base station receives the authentication, encryption and integrity protection completion message sent by the terminal and determines that the preset conditions are met.

[0012] In the above scheme, determining that the preset conditions are met includes: when the base station determines that the preset conditions are met when it determines that the RRC link between it and the terminal is updated.

[0013] In the above scheme, when the base station determines an RRC link update with the terminal, it determines that preset conditions are met, including:

[0014] When the base station determines that the RRC link reconfiguration with the terminal is met, it determines that a preset condition is satisfied; or,

[0015] When the base station receives an RRC establishment request sent by the terminal, it determines that a preset condition is met; or,

[0016] When the base station receives the RRC reconstruction request sent by the terminal, it determines that the preset conditions are met.

[0017] In the above scheme, sending C-RNTI to the terminal via encrypted and integrity-protected signaling radio bearer includes:

[0018] If the base station receives an RRC establishment request sent by the terminal, the base station sends a C-RNTI to the terminal through encrypted and integrity-protected RRC establishment signaling;

[0019] If the base station receives an RRC reconstruction request sent by the terminal, the base station sends a C-RNTI to the terminal through encrypted and integrity-protected RRC reconstruction signaling.

[0020] In the above scheme, determining that the preset conditions are met includes:

[0021] The base station determines whether the preset conditions are met based on the indication information from the core network equipment.

[0022] In the above scheme, the base station determines that the preset conditions are met based on the notification message from the core network equipment, including: the base station sends a first message to the core network equipment, the first message being used to request confirmation of whether to update the C-RNTI; the first message includes at least one of the following information: terminal type, bearer type, session type, slice type, and device type;

[0023] The base station receives a first response message sent by the core network device, the first response message including indication information on whether to update C-RNTI;

[0024] If the indication information indicates an update to C-RNTI, it is determined that the preset conditions are met.

[0025] In the above scheme, sending C-RNTI to the terminal through encrypted and integrity-protected signaling radio bearers includes: the base station sending C-RNTI to the terminal through encrypted and integrity-protected RRC reconfiguration signaling.

[0026] In the above scheme, the method further includes: the base station obtaining the preamble identifier used by the terminal for random access, determining the Random Access-RadioNetwork Temporary Identifier (RA-RNTI) based on the preamble identifier, or scrambling the RA-RNTI based on the preamble identifier; the RA-RNTI is used to scramble the C-RNTI.

[0027] The method in the above scheme further includes:

[0028] The base station obtains resource information for transmitting the preamble;

[0029] The determination of RA-RNTI based on the preamble identifier includes:

[0030] The base station determines the RA-RNTI based on the resource information and the preamble identifier.

[0031] In the above scheme, the RA-RNTI is determined based on the following expression:

[0032] RA-RNTI=1+t_id+10*f_id+preambleID

[0033] Where t_id represents the identifier of the first subframe in which the Physical Random Access Channel (PRACH) for transmitting the preamble is located, f_id represents the frequency domain index of the PRACH that transmits the preamble in this subframe, and preambleID represents the preamble identifier.

[0034] In the above scheme, the RA-RNTI is determined based on the following expression:

[0035] RA-RNTI=1+s_id+14*t_id+14*80*f_id+14*80*8*ul_carrier_id+14*80*8*2*preambleID

[0036] Wherein, s_id represents the start sequence number of the orthogonal frequency division multiplexing (OFDM) of the time slot in which PRACH is located, t_id represents the start sequence number of the time slot of the system frame in which PRACH is located, f_id represents the start sequence number of the frequency domain in which PRACH is located, and ul_carrier_id represents the uplink carrier sequence number of the first message transmission in the PRACH process.

[0037] In the above scheme, the method further includes: the base station uses scrambling code parameters to scramble the data channel; the scrambling code parameters include one of the following: setting a scrambling code identifier, or a random number.

[0038] In the above scheme, if the base station uses a random number to scramble the data channel, the method further includes: the base station sending the random number to the terminal through encrypted and integrity-protected RRC reconfiguration signaling.

[0039] Secondly, embodiments of the present invention also provide a processing method for data transmission protection, the method comprising: a terminal receiving a C-RNTI sent by a base station through an encrypted and integrity-protected signaling radio bearer.

[0040] In the above scheme, the terminal receives the C-RNTI sent by the base station through encrypted and integrity-protected signaling radio bearer, including: the terminal receives the C-RNTI sent by the base station through encrypted and integrity-protected RRC signaling.

[0041] In the above scheme, the terminal receives the C-RNTI sent by the base station through the signaling radio bearer with encryption and integrity protection, including: after completing encryption and integrity protection and before data transmission, the terminal receives the C-RNTI sent by the base station through the signaling radio bearer with encryption and integrity protection.

[0042] In the above scheme, after completing encryption and integrity protection but before transmitting data, the terminal receives the C-RNTI sent by the base station through the signaling radio bearer for encryption and integrity protection, including:

[0043] After the terminal sends an authentication, encryption, and integrity protection completion message to the base station, it receives the C-RNTI sent by the base station through the encryption and integrity protection signaling radio bearer.

[0044] In the above scheme, the terminal receives the C-RNTI sent by the base station through encrypted and integrity-protected signaling radio bearer, including:

[0045] The terminal sends an RRC establishment request to the base station and receives the C-RNTI sent by the base station through encrypted and integrity-protected RRC establishment signaling; or...

[0046] The terminal sends an RRC reconstruction request to the base station and receives the C-RNTI sent by the base station through encrypted and integrity-protected RRC reconstruction signaling; or...

[0047] The terminal receives the C-RNTI sent by the base station through encrypted and integrity-protected RRC reconfiguration signaling.

[0048] In the above scheme, the method further includes: the terminal determining the RA-RNTI based on the preamble identifier, or obtaining the RA-RNTI based on the descrambled and scrambled RA-RNTI of the preamble identifier;

[0049] Based on the descrambled and scrambled C-RNTI of the RA-RNTI, the C-RNTI is obtained.

[0050] The method in the above scheme further includes:

[0051] The terminal determines the resource information used to transmit the preamble;

[0052] The terminal determines the RA-RNTI based on the preamble identifier, including:

[0053] The terminal determines the RA-RNTI based on the resource information and the preamble identifier.

[0054] In the above scheme, the RA-RNTI is determined based on the following expression:

[0055] RA-RNTI=1+t_id+10*f_id+preambleID

[0056] Where t_id represents the identifier of the first subframe in which the PRACH transmitting the preamble is located, f_id represents the index identifier of the PRACH transmitting the preamble in the frequency domain in this subframe, and preambleID represents the preamble identifier.

[0057] In the above scheme, the RA-RNTI is determined based on the following expression:

[0058] RA-RNTI=1+s_id+14*t_id+14*80*f_id+14*80*8*ul_carrier_id+14*80*8*2*preambleID

[0059] Wherein, s_id represents the OFDM start sequence number of the time slot in which PRACH is located, t_id represents the start sequence number of the time slot of the system frame in which PRACH is located, f_id represents the frequency domain start sequence number in which PRACH is located, and ul_carrier_id represents the uplink carrier sequence number of the first message transmission in the PRACH process.

[0060] In the above scheme, the method further includes: the terminal uses scrambling code parameters to descramble the scrambled data channel; the scrambling code parameters include one of the following: setting a scrambling code identifier, or a random number.

[0061] In the above scheme, if the terminal uses a random number to descramble the scrambled data channel, the method further includes: the terminal receiving the random number sent by the base station through encrypted and integrity-protected RRC reconfiguration signaling.

[0062] Thirdly, embodiments of the present invention also provide a processing apparatus for data transmission protection, the apparatus comprising: a first determining unit and a first communication unit; wherein,

[0063] The first determining unit is used to determine whether a preset condition is met;

[0064] The first communication unit is configured to send C-RNTI to the terminal through an encrypted and integrity-protected signaling radio bearer when the first determining unit determines that the preset conditions are met.

[0065] In the above scheme, the first communication unit is used to send C-RNTI to the terminal through encrypted and integrity-protected RRC signaling.

[0066] In the above scheme, the first determining unit is used to determine whether preset conditions are met after the terminal has completed encryption and integrity protection and before data transmission.

[0067] In the above scheme, the first determining unit is used to receive the authentication, encryption and integrity protection completion message sent by the terminal through the first communication unit and determine that the preset conditions are met.

[0068] In the above scheme, the first determining unit is used to determine that a preset condition is met when determining an RRC link update with the terminal.

[0069] In the above scheme, the first determining unit is used to determine that a preset condition is met when determining the reconfiguration of the RRC link with the terminal; or, when receiving an RRC establishment request sent by the terminal through the first communication unit, determine that the preset condition is met; or, when receiving an RRC reconstruction request sent by the terminal through the first communication unit, determine that the preset condition is met.

[0070] In the above scheme, the first communication unit is configured to send a C-RNTI to the terminal via encrypted and integrity-protected RRC establishment signaling if it receives an RRC establishment request from the terminal; and to send a C-RNTI to the terminal via encrypted and integrity-protected RRC reconstruction signaling if it receives an RRC reconstruction request from the terminal.

[0071] In the above scheme, the first determining unit is used to determine whether the preset conditions are met based on the indication information of the core network equipment.

[0072] In the above scheme, the first determining unit is used to send a first message to the core network device through the first communication unit. The first message is used to request confirmation of whether to update the C-RNTI. The first message includes at least one of the following information: terminal type, bearer type, session type, slice type, and device type. The unit receives a first response message sent by the core network device. The first response message includes indication information of whether to update the C-RNTI. If the indication information indicates that the C-RNTI is to be updated, the unit determines that a preset condition is met.

[0073] In the above scheme, the first communication unit is used to send C-RNTI to the terminal through encrypted and integrity-protected RRC reconfiguration signaling.

[0074] In the above scheme, the device further includes: an acquisition unit and a second determination unit.

[0075] The acquisition unit is used to obtain the preamble identifier used by the terminal for random access;

[0076] The second determining unit is used to determine the Random Access Radio Network Temporary Identifier (RA-RNTI) based on the preamble identifier;

[0077] Alternatively, the device may further include an acquisition unit and a first scrambling unit;

[0078] The acquisition unit is used to obtain the preamble identifier used by the terminal for random access;

[0079] The first scrambling unit is used to scramble the RA-RNTI based on the preamble identifier;

[0080] The RA-RNTI is used to scramble C-RNTI.

[0081] In the above scheme, the acquisition unit is also used to obtain resource information for transmitting the preamble;

[0082] The second determining unit is used to determine the RA-RNTI based on the resource information and the preamble identifier.

[0083] In the above scheme, the RA-RNTI is determined based on the following expression:

[0084] RA-RNTI=1+t_id+10*f_id+preambleID

[0085] Where t_id represents the identifier of the first subframe in which the PRACH transmitting the preamble is located, f_id represents the index identifier of the PRACH transmitting the preamble in the frequency domain in this subframe, and preambleID represents the preamble identifier.

[0086] In the above scheme, the RA-RNTI is determined based on the following expression:

[0087] RA-RNTI=1+s_id+14*t_id+14*80*f_id+14*80*8*ul_carrier_id+14*80*8*2*preambleID

[0088] Wherein, s_id represents the OFDM start sequence number of the time slot in which PRACH is located, t_id represents the start sequence number of the time slot of the system frame in which PRACH is located, f_id represents the frequency domain start sequence number in which PRACH is located, and ul_carrier_id represents the uplink carrier sequence number of the first message transmission in the PRACH process.

[0089] In the above scheme, the device further includes a second scrambling unit, used to scramble the data channel using scrambling code parameters; the scrambling code parameters include one of the following: setting a scrambling code identifier, or a random number.

[0090] In the above scheme, the first communication unit is further configured to send the random number to the terminal through an encrypted and integrity-protected RRC reconfiguration signaling if the second scrambling unit uses a random number to scramble the data channel.

[0091] Fourthly, embodiments of the present invention also provide a processing apparatus for data transmission protection, the apparatus including a second communication unit for receiving C-RNTI sent by a base station via a signaling radio bearer protected by encryption and integrity.

[0092] In the above scheme, the second communication unit is used to receive the C-RNTI sent by the base station through encrypted and integrity-protected RRC signaling.

[0093] In the above scheme, the second communication unit is used to receive the C-RNTI sent by the base station through the signaling radio bearer of encryption and integrity protection after encryption and integrity protection is completed and before data transmission is performed.

[0094] In the above scheme, the second communication unit is used to send an authentication, encryption and integrity protection completion message to the base station, and then receive the C-RNTI sent by the base station through the encryption and integrity protection signaling radio bearer.

[0095] In the above scheme, the second communication unit is used to send an RRC establishment request to the base station and receive the C-RNTI sent by the base station through encrypted and integrity-protected RRC establishment signaling; or, send an RRC reconstruction request to the base station and receive the C-RNTI sent by the base station through encrypted and integrity-protected RRC reconstruction signaling; or, receive the C-RNTI sent by the base station through encrypted and integrity-protected RRC reconfiguration signaling.

[0096] In the above scheme, the device further includes: a third determining unit and a first descrambling unit; wherein,

[0097] The third determining unit is used to determine RA-RNTI based on the preamble identifier;

[0098] The first descrambling unit is used to obtain the C-RNTI based on the descrambled C-RNTI obtained from the RA-RNTI; or,

[0099] The device further includes a second descrambling unit, used to obtain RA-RNTI based on the descrambled and scrambled RA-RNTI of the preamble identifier; and to obtain C-RNTI based on the descrambled and scrambled C-RNTI of the RA-RNTI.

[0100] In the above scheme, the third determining unit is further configured to determine resource information for transmitting the preamble; and determine RA-RNTI based on the resource information and the preamble identifier.

[0101] In the above scheme, the RA-RNTI is determined based on the following expression:

[0102] RA-RNTI=1+t_id+10*f_id+preambleID

[0103] Where t_id represents the identifier of the first subframe in which the PRACH transmitting the preamble is located, f_id represents the index identifier of the PRACH transmitting the preamble in the frequency domain in this subframe, and preambleID represents the preamble identifier.

[0104] In the above scheme, the RA-RNTI is determined based on the following expression:

[0105] RA-RNTI=1+s_id+14*t_id+14*80*f_id+14*80*8*ul_carrier_id+14*80*8*2*preambleID

[0106] Wherein, s_id represents the OFDM start sequence number of the time slot in which PRACH is located, t_id represents the start sequence number of the time slot of the system frame in which PRACH is located, f_id represents the frequency domain start sequence number in which PRACH is located, and ul_carrier_id represents the uplink carrier sequence number of the first message transmission in the PRACH process.

[0107] In the above scheme, the device further includes a third descrambling unit, which is used to descramble the scrambled data channel using scrambling code parameters; the scrambling code parameters include one of the following: setting a scrambling code identifier, or a random number.

[0108] In the above scheme, the second communication unit is further configured to receive the random number sent by the base station through RRC reconfiguration signaling with encryption and integrity protection if the third descrambling unit uses a random number to descramble the scrambled data channel.

[0109] Fifthly, embodiments of the present invention also provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the methods described in the first or second aspects of the present invention.

[0110] In a sixth aspect, embodiments of the present invention also provide a communication device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the method described in the first or second aspect of the present invention.

[0111] The present invention provides a processing method, apparatus, and communication device for data transmission protection. The method includes: when a base station determines that preset conditions are met, it sends a C-RNTI to a terminal via an encrypted and integrity-protected signaling radio bearer. By employing the technical solution of the present invention, the C-RNTI is transmitted via encrypted and integrity-protected signaling, preventing the C-RNTI from being obtained by devices other than the terminal, and preventing other devices from obtaining the terminal's user plane data for illegal operations. Attached Figure Description

[0112] Figure 1 This is a flowchart illustrating a data transmission protection processing method according to an embodiment of the present invention. Figure 1 ;

[0113] Figure 2 This is a flowchart illustrating a data transmission protection processing method according to an embodiment of the present invention. Figure 2 ;

[0114] Figure 3 This is a schematic diagram of the interaction flow of a processing method for data transmission protection according to an embodiment of the present invention;

[0115] Figure 4 This is a schematic diagram of the composition of a processing device for data transmission protection according to an embodiment of the present invention. Figure 1 ;

[0116] Figure 5 This is a schematic diagram of the composition of a processing device for data transmission protection according to an embodiment of the present invention. Figure 2 ;

[0117] Figure 6 This is a schematic diagram of the composition of a processing device for data transmission protection according to an embodiment of the present invention. Figure 3 ;

[0118] Figure 7 This is a schematic diagram of the composition of a processing device for data transmission protection according to an embodiment of the present invention. Figure 4 ;

[0119] Figure 8 This is a schematic diagram of the composition of a processing device for data transmission protection according to an embodiment of the present invention. Figure 5 ;

[0120] Figure 9 This is a schematic diagram of the composition of a processing device for data transmission protection according to an embodiment of the present invention. Figure 6 ;

[0121] Figure 10 This is a schematic diagram of the hardware composition structure of a communication device according to an embodiment of the present invention. Detailed Implementation

[0122] The present invention will now be described in further detail with reference to the accompanying drawings and specific embodiments.

[0123] Before providing a detailed description of the technical solutions of the embodiments of the present invention, the PRACH process will be briefly explained first.

[0124] Currently, the four-step contention-based random access process can include: Message 1 (msg1), the User Equipment (UE) sends a Random Access Preamble through the Random Access Channel (RACH); Message 2 (msg2), after receiving msg1, the base station (e.g., an evolved NB) sends a Random Access Response (RAR) on the Downlink-Shared Channel (DL-SCH); Message 3 (msg3), Scheduled Transmission, after receiving msg2, the UE determines whether it is its own RAR message and sends msg3, carrying the UE identifier (UE-ID). The UE's RRC layer generates an RRC Connection Request and maps it to the Uplink-Shared Channel (UL-SCH) for transmission; Message 4 (msg4) is the contention resolution message. The base station's (e.g., eNB) RRC layer generates an RRC Connection resolution message and transmits it on the DL-SCH. The UE correctly receives msg4 to complete the contention resolution.

[0125] In the aforementioned PRACH process, msg2 includes the C-RNTI, scrambled using RA-RNTI. msg3 and msg4 both include the Temporary Mobile Subscriber Identity (TMSI), scrambled using C-RNTI. Therefore, the C-RNTI can be obtained from msg2, and the TMSI can be obtained from msg3 and msg4 through the C-RNTI. This allows us to determine the relationship between the C-RNTI and TMSI. The relationship between the C-RNTI and TMSI allows us to obtain the user plane data of a specific terminal. Currently, user plane data is not encrypted or protected for integrity; it is only scrambled using C-RNTI. Therefore, obtaining the C-RNTI is sufficient to obtain the terminal's user plane data.

[0126] Based on this, in this embodiment of the invention, the C-RNTI is reconfigured twice by signaling radio bearers with encryption and integrity protection, so that secure transmission can be achieved when user plane data lacks encryption and integrity protection.

[0127] This invention provides a processing method for data transmission protection, which is applied in a base station. Figure 1This is a flowchart illustrating a data transmission protection processing method according to an embodiment of the present invention. Figure 1 ;like Figure 1 As shown, the method includes:

[0128] Step 101: When the base station determines that the preset conditions are met, it sends C-RNTI to the terminal through the encrypted and integrity-protected Signaling Radio Bearer (SRB).

[0129] The embodiments of the present invention employ a secondary reconfiguration method, which sends the C-RNTI to the terminal through an encrypted and integrity-protected SRB to prevent the C-RNTI from being obtained by devices other than the terminal. Optionally, the embodiments of the present invention are executed during the process when the terminal is in the connected state after the random access process is completed.

[0130] In some optional embodiments of the present invention, sending the Cell Radio Network Temporary Identifier (C-RNTI) to the terminal via encrypted and integrity-protected signaling radio bearer includes: sending the C-RNTI to the terminal via encrypted and integrity-protected RRC signaling. Exemplarily, RRC signaling includes, but is not limited to, RRC establishment signaling, RRC reconstruction signaling, RRC reconfiguration (also known as RRC reconfiguration) signaling, etc.

[0131] In the first implementation, the determination that the preset conditions are met includes: the base station determines that the preset conditions are met after determining that the terminal has completed encryption and integrity protection and before transmitting data.

[0132] Optionally, after the terminal completes integrity protection and encryption but before transmitting data, it determines that preset conditions are met, including: the base station receives the authentication, encryption and integrity protection completion message sent by the terminal and determines that the preset conditions are met.

[0133] In this embodiment, C-RNTI reconfiguration is performed after the terminal completes encryption and integrity protection but before data transmission begins. C-RNTI is transmitted via encrypted and integrity-protected SRB (e.g., RRC signaling) to prevent leakage and ensure the security of data plane transmission.

[0134] For example, after the terminal completes the PRACH process, it enters the connected state from the idle state. Upon entering the connected state, the terminal begins authentication, authorization, encryption, and integrity protection; the SRBs for these processes are not encrypted. For instance, the terminal completes integrity protection before the Security Mod Command signaling, and begins encryption and integrity protection after this signaling. Then, after receiving the Security Mod Command signaling from the terminal, the base station sends a C-RNTI to the terminal via an encrypted and integrity-protected SRB (such as RRC signaling), that is, the C-RNTI is carried in the first RRC signaling after the Security Mod Command signaling. Optionally, the base station can send the C-RNTI to the terminal via the first RRC Reconfiguration signaling after the Security Mod Command signaling, and the terminal sends an acknowledgment message to the base station after completing the RRC reconfiguration.

[0135] As a second implementation, the determination that the preset conditions are met includes: when the base station determines that the preset conditions are met when it determines that the RRC link between it and the terminal is updated.

[0136] In this embodiment, the base station decides whether to perform C-RNTI reconfiguration. Optionally, the base station may decide to perform C-RNTI reconfiguration when the user information corresponding to the terminal changes. For example, C-RNTI reconfiguration may be performed when a cell update occurs, or after encryption and integrity protection is performed; or, for example, after an RRC link update, C-RNTI reconfiguration may be performed. Alternatively, C-RNTI reconfiguration may be performed after a Protocol Data Unit (PDU) update.

[0137] Optionally, when the base station determines that the RRC link between it and the terminal has been updated, it determines that the preset conditions are met, including: when the base station determines that the RRC link between it and the terminal has been reconfigured, it determines that the preset conditions are met; or, when the base station receives an RRC establishment request sent by the terminal, it determines that the preset conditions are met; or, when the base station receives an RRC reconstruction request sent by the terminal, it determines that the preset conditions are met.

[0138] Optionally, sending C-RNTI to the terminal via encrypted and integrity-protected signaling radio bearer includes: if the base station receives an RRC establishment request sent by the terminal, the base station sends C-RNTI to the terminal via encrypted and integrity-protected RRC establishment signaling; if the base station receives an RRC reconstruction request sent by the terminal, the base station sends C-RNTI to the terminal via encrypted and integrity-protected RRC reconstruction signaling.

[0139] In this embodiment, when a terminal initiates an RRC establishment request or an RRC reconstruction request, the base station can determine that preset conditions are met and send the C-RNTI to the terminal by carrying the C-RNTI in the RRC establishment signaling or RRC reconstruction signaling. Alternatively, the base station can trigger an RRC reconfiguration signaling, carrying the C-RNTI in the RRC reconfiguration signaling, and send the C-RNTI to the terminal. For example, the base station can send the C-RNTI to the terminal through the first RRC reconfiguration signaling after the Security Mod Command signaling, that is, reconfigure the C-RNTI after the terminal's security mode changes.

[0140] As a third implementation method, the determination that the preset conditions are met includes: the base station determining that the preset conditions are met based on the indication information of the core network equipment.

[0141] In this embodiment, the core network equipment decides whether to perform C-RNTI reconfiguration.

[0142] Optionally, the base station determines that the preset conditions are met based on the notification message from the core network device, including: the base station sending a first message to the core network device, the first message being used to request confirmation of whether to update the C-RNTI; the first message including at least one of the following information: terminal type, bearer type, session type, slice type, and device type; the base station receiving a first response message sent by the core network device, the first response message including indication information of whether to update the C-RNTI; if the indication information indicates that the C-RNTI is updated, it is determined that the preset conditions are met.

[0143] In this embodiment, the base station interacts with the core network equipment, requesting confirmation via a first message whether to update the C-RNTI. The first message includes at least one of the following: terminal type, bearer type, session type, slice type, and device type. The base station can determine whether to update the C-RNTI based on at least some of the information included in the first message, such as terminal type, bearer type, session type (e.g., PDU session type), slice type, and device type. In practical applications, the core network equipment may have a pre-obtained or configured policy regarding whether to update the C-RNTI; the core network equipment can then determine whether to update the C-RNTI by querying the relevant policy. Furthermore, it determines whether to update the C-RNTI based on the indication of the first response message. For example, the value of a bit in the first response message being "1" or "0" corresponds to updating or not updating the C-RNTI.

[0144] For example, the core network device may be at least one of the following: Access and Mobility Management Function (AMF), Session Management Function (SMF), and User Plane Function (UPF).

[0145] Optionally, in the third embodiment described above, sending C-RNTI to the terminal via encrypted and integrity-protected signaling radio bearer includes: the base station sending C-RNTI to the terminal via encrypted and integrity-protected RRC reconfiguration signaling.

[0146] In some optional embodiments of the present invention, the method further includes: the base station obtaining the preamble ID for random access of the terminal, determining the RA-RNTI based on the preamble ID, or scrambling the RA-RNTI based on the preamble ID; the RA-RNTI is used to scramble the C-RNTI.

[0147] In this embodiment, since the random access process is unencrypted, and the C-RNTI in msg2 of the aforementioned PRACH process is scrambled using RA-RNTI, this embodiment enhances the RA-RNTI to prevent it from being repeatedly attempted to be obtained by other devices. This, in turn, prevents the C-RNTI in the random access process from being obtained by other devices. That is, the RA-RNTI enhancement scheme of this embodiment can be applied to the random access process (e.g., the first step (msg1) or after the first step (msg1) in the aforementioned four-step PRACH process), and the base station and terminal can generate the RA-RNTI based on the RA-RNTI enhancement scheme of this embodiment.

[0148] In a conventional approach, the RA-RNTI is generated in a 4G system as follows:

[0149] RA-RNTI=1+t_id+10*f_id (1)

[0150] Where t_id represents the first subframe number where the PRACH for transmitting the preamble is located, 0 ≤ t_id < 10; f_id represents the frequency domain index of the PRACH for transmitting the preamble in that subframe, 0 ≤ f_id < 6. For Frequency Division Duplex (FDD) systems, there is only one PRACH resource per subframe, so f_id is fixed at 0, therefore RA-RNTI is 10 for FDD. For Time Division Duplex (TDD) systems, frequency resources must also be considered, and for TDD, the maximum is 60.

[0151] Therefore, for the conventional approach, RA-RNTI can be obtained by trying a maximum of 10 or 60 cycles.

[0152] In a 5G system, RA-RNTI can be generated as follows:

[0153] RA-RNTI=1+s_id+14*t_id+14*80*f_id+14*80*8*ul_carrier_id (2)

[0154] Wherein, s_id represents the OFDM start sequence number of the time slot in which PRACH is located, 0≤s_id<14; t_id represents the start sequence number of the time slot of the system frame in which PRACH is located, 0≤t_id<80; f_id is the frequency domain start sequence number sampled by PRACH, 0≤f_id<8; ul_carrier_id represents the uplink carrier sequence number of msg1 transmission, 0 indicates non-supplementary uplink (SUL) transmission, and 1 indicates SUL transmission.

[0155] In some optional embodiments of the present invention, the method further includes: the base station obtaining resource information for transmitting a preamble; the step of determining RA-RNTI based on the preamble identifier includes: the base station determining RA-RNTI based on the resource information and the preamble identifier.

[0156] In this embodiment, the resource information may include time-domain information and / or frequency-domain information of the transmission preamble.

[0157] As one implementation, the RA-RNTI is determined based on the following expression:

[0158] RA-RNTI=1+t_id+10*f_id+preambleID (3)

[0159] Where t_id represents the identifier of the first subframe in which the PRACH transmitting the preamble is located, 0≤t_id<10; f_id represents the index identifier of the PRACH transmitting the preamble in the frequency domain in this subframe, 0≤f_id<6; and preamble ID represents the preamble identifier.

[0160] As another implementation, the RA-RNTI is determined based on the following expression:

[0161] RA-RNTI=1+s_id+14*t_id+14*80*f_id+14*80*8*ul_carrier_id+14*80*8*2*preambleID(4)

[0162] Wherein, s_id represents the OFDM start sequence number of the time slot in which PRACH is located, 0≤s_id<14; t_id represents the start sequence number of the time slot of the system frame in which PRACH is located, 0≤t_id<80; f_id represents the frequency domain start sequence number in which PRACH is located, 0≤f_id<8; ul_carrier_id represents the uplink carrier sequence number of the first message transmission in the PRACH process, 0 indicates non-SUL transmission, and 1 indicates SUL transmission.

[0163] In this embodiment, after the base station receives msg1 sent by the terminal, it can obtain the preamble ID carried in the message through convolution processing. For example, there are 64 preamble IDs, which can be combined with existing RA-RNTI generation methods, such as generating RA-RNTI using the above expression (3) or (4), or scrambling with a preamble identifier on the basis of the conventional RA-RNTI generation method, to increase the difficulty of RA-RNTI cyclic attempts, reduce the possibility of RA-RNTI being cracked, and thus avoid RA-RNTI being obtained by other devices in a cyclic attempt.

[0164] Optionally, after determining the RA-RNTI, the base station scrambles the C-RNTI based on the RA-RNTI and sends message 2 (msg2) to the terminal. Message 2 (msg2) carries the C-RNTI scrambled with RA-RNTI.

[0165] In some optional embodiments of the present invention, the method further includes: the base station scrambling the data channel using scrambling code parameters; the scrambling code parameters include one of the following: setting a scrambling code identifier, or a random number.

[0166] In this embodiment, based on the above technical solution, the data channel can be further enhanced to improve its security. In conventional solutions, the data channel mostly uses C-RNTI scrambling, while in this embodiment, the data channel can be scrambled using a set scrambling code identifier or a random number.

[0167] The scrambling parameters include one of the following: dataScrambling IdentityPDSCH, pdcch-DMRS-ScramblingID, sequenceGenerationConfig, scramblingID0, scramblingID1, msgA-DataScramblingIndex, msgA-ScramblingID0, msgA-ScramblingID1, dataScramblingIdentityPUSCH, etc.

[0168] The aforementioned scrambling parameters can be determined in a pre-agreed manner, that is, the base station and the terminal can determine in a pre-agreed manner which scrambling parameter to use for scrambling and descrambling of the data channel; or, the base station can also send the scrambling parameters to the terminal through RRC reconfiguration signaling to prevent other terminals from obtaining the scrambling parameters.

[0169] Optionally, if the base station uses a random number to scramble the data channel, the method further includes: the base station sending the random number to the terminal via encrypted and integrity-protected RRC reconfiguration signaling.

[0170] This embodiment increases the security and privacy of data transmission between the base station and the terminal by scrambling the data channel with set scrambling parameters or random numbers.

[0171] Based on the above embodiments, this invention provides a processing method for data transmission protection, which is applied in a terminal. Figure 2 This is a flowchart illustrating a data transmission protection processing method according to an embodiment of the present invention. Figure 2 ;like Figure 2 As shown, the method includes:

[0172] Step 201: The terminal receives the C-RNTI sent by the base station through the encrypted and integrity-protected signaling radio bearer.

[0173] The embodiments of the present invention employ a secondary reconfiguration method, which sends the C-RNTI to the terminal through an encrypted and integrity-protected SRB to prevent the C-RNTI from being obtained by devices other than the terminal. Optionally, the embodiments of the present invention are executed during the process when the terminal is in the connected state after the random access process is completed.

[0174] In some optional embodiments of the present invention, the terminal receives the C-RNTI sent by the base station via encrypted and integrity-protected signaling radio bearer, including: the terminal receives the C-RNTI sent by the base station via encrypted and integrity-protected RRC signaling. Exemplarily, RRC signaling includes, but is not limited to, RRC establishment signaling, RRC reconstruction signaling, RRC reconfiguration (also known as RRC reconfiguration) signaling, etc.

[0175] In some optional embodiments of the present invention, the terminal receives the C-RNTI sent by the base station through an encrypted and integrity-protected signaling radio bearer, including: the terminal receives the C-RNTI sent by the base station through an encrypted and integrity-protected signaling radio bearer after completing encryption and integrity protection and before transmitting data.

[0176] Optionally, after completing encryption and integrity protection but before transmitting data, the terminal receives the C-RNTI sent by the base station through the signaling radio bearer for encryption and integrity protection, including: after the terminal sends an authentication, encryption and integrity protection completion message to the base station, it receives the C-RNTI sent by the base station through the signaling radio bearer for encryption and integrity protection.

[0177] In this embodiment, C-RNTI reconfiguration is performed after the terminal completes encryption and integrity protection but before data transmission begins. C-RNTI is transmitted via encrypted and integrity-protected SRB (e.g., RRC signaling) to prevent leakage and ensure the security of data plane transmission.

[0178] For example, after the terminal completes the PRACH process, it enters the connected state from the idle state. Upon entering the connected state, the terminal begins authentication, authorization, encryption, and integrity protection; the SRBs for these processes are not encrypted. For instance, the terminal completes integrity protection before the Security Mod Command signaling, and begins encryption and integrity protection after this signaling. Then, after receiving the Security Mod Command signaling from the terminal, the base station sends a C-RNTI to the terminal via an encrypted and integrity-protected SRB (such as RRC signaling), that is, the C-RNTI is carried in the first RRC signaling after the Security Mod Command signaling. Optionally, the terminal sends a Security Mod Command signaling to the base station, and the base station can send a C-RNTI to the terminal via the first RRC Reconfiguration signaling after the Security Mod Command signaling. After completing the RRC reconfiguration, the terminal sends an acknowledgment message to the base station.

[0179] In some optional embodiments of the present invention, the terminal receives the C-RNTI sent by the base station through encrypted and integrity-protected signaling radio bearer, including: the terminal sending an RRC establishment request to the base station and receiving the C-RNTI sent by the base station through encrypted and integrity-protected RRC establishment signaling; or, the terminal sending an RRC reconstruction request to the base station and receiving the C-RNTI sent by the base station through encrypted and integrity-protected RRC reconstruction signaling; or, the terminal receiving the C-RNTI sent by the base station through encrypted and integrity-protected RRC reconfiguration signaling.

[0180] In some optional embodiments of the present invention, the method further includes: the terminal determining the RA-RNTI based on the preamble identifier, or obtaining the RA-RNTI based on the descrambled and scrambled RA-RNTI of the preamble identifier; and obtaining the C-RNTI based on the descrambled and scrambled C-RNTI of the RA-RNTI.

[0181] In this embodiment, since the random access process is unencrypted, and the C-RNTI in msg2 of the aforementioned PRACH process is scrambled using RA-RNTI, this embodiment enhances the RA-RNTI to prevent it from being repeatedly attempted to be obtained by other devices. This, in turn, prevents the C-RNTI in the random access process from being obtained by other devices. That is, the RA-RNTI enhancement scheme of this embodiment can be applied to the random access process (e.g., the first step (msg1) or after the first step (msg1) in the aforementioned four-step PRACH process), and the base station and terminal can generate the RA-RNTI based on the RA-RNTI enhancement scheme of this embodiment.

[0182] Optionally, the method further includes: the terminal determining resource information for transmitting the preamble; the terminal determining the RA-RNTI based on the preamble identifier, including: the terminal determining the RA-RNTI based on the resource information and the preamble identifier.

[0183] In this embodiment, the resource information may include time-domain information and / or frequency-domain information of the transmission preamble.

[0184] As one implementation, the RA-RNTI is determined based on the following expression:

[0185] RA-RNTI=1+t_id+10*f_id+preambleID

[0186] Where t_id represents the identifier of the first subframe in which the PRACH of the preamble is transmitted, f_id represents the index of the PRACH of the preamble in the frequency domain in that subframe, and preambleID represents the preamble identifier.

[0187] As another implementation, the RA-RNTI is determined based on the following expression:

[0188] RA-RNTI=1+s_id+14*t_id+14*80*f_id+14*80*8*ul_carrier_id+14*80*8*2*preambleID

[0189] Wherein, s_id represents the OFDM start sequence number of the time slot in which PRACH is located, 0≤s_id<14; t_id represents the start sequence number of the time slot of the system frame in which PRACH is located, 0≤t_id<80; f_id represents the frequency domain start sequence number in which PRACH is located, 0≤f_id<8; ul_carrier_id represents the uplink carrier sequence number of the first message transmission in the PRACH process, 0 indicates non-SUL transmission, and 1 indicates SUL transmission.

[0190] In this embodiment, the terminal can confirm the preamble ID according to the System Information Block (SIB) parameter RACH_ROOT_SEQUENCE\Ncs\Format\Highspeedflag; after receiving message 2 (msg2) sent by the base station, message 2 (msg2) carries the C-RNTI scrambled with RA-RNTI; the RA-RNTI is determined according to the preamble ID and the above expression, and then the C-RNTI scrambled with RA-RNTI carried in message 2 (msg2) is descrambled according to the RA-RNTI to obtain the C-RNTI.

[0191] In some optional embodiments of the present invention, the method further includes: the terminal using scrambling code parameters to descramble the scrambled data channel; the scrambling code parameters include one of the following: setting a scrambling code identifier, or a random number.

[0192] In this embodiment, based on the above technical solution, the data channel can be further enhanced to improve its security. In conventional solutions, the data channel mostly uses C-RNTI scrambling, while in this embodiment, the data channel can be scrambled using a set scrambling code identifier or a random number.

[0193] The scrambling parameters include one of the following: dataScrambling IdentityPDSCH, pdcch-DMRS-ScramblingID, sequenceGenerationConfig, scramblingID0, scramblingID1, msgA-DataScramblingIndex, msgA-ScramblingID0, msgA-ScramblingID1, dataScramblingIdentityPUSCH, etc.

[0194] The aforementioned scrambling parameters can be determined in a pre-agreed manner, that is, the base station and the terminal can determine in a pre-agreed manner which scrambling parameter to use for scrambling and descrambling of the data channel; or, the base station can also send the scrambling parameters to the terminal through RRC reconfiguration signaling to prevent other terminals from obtaining the scrambling parameters.

[0195] Optionally, if the terminal uses a random number to descramble the scrambled data channel, the method further includes: the terminal receiving the random number sent by the base station through encrypted and integrity-protected RRC reconfiguration signaling.

[0196] This embodiment increases the security and privacy of data transmission between the base station and the terminal by scrambling the data channel with set scrambling parameters or random numbers.

[0197] Figure 3 This is a schematic diagram of the interaction flow of a data transmission protection processing method according to an embodiment of the present invention; as shown below. Figure 3 As shown, the method includes:

[0198] Step 301: The UE sends message 1 (msg1) to the base station (gNB); the UE sends a random access preamble via RACH.

[0199] Step 302: The base station sends message 2 (msg2) to the UE; after receiving msg1, the base station sends a random access response (RAR) on the DL-SCH.

[0200] Step 303: The UE sends message 3 (msg3) to the base station; Scheduled Transmission: After receiving msg2, the UE determines whether it is its own RAR message and sends msg3, carrying the UE identifier (UE-ID). The UE's RRC layer generates an RRC Connection Request and maps it to the Uplink-Shared Channel (UL–SCH) for transmission.

[0201] Step 304: The base station sends message 4 (msg4) to the UE; Contention Resolution: The RRC layer on the base station side (e.g., eNB) generates an RRC Connection and sends it on the DL-SCH. The UE correctly receives msg4 to complete the contention resolution.

[0202] Step 305: The UE sends an RRC Setup Complete message to the base station, which is mainly used to request registration.

[0203] In steps 301 to 305 above, the UE is in an idle state and the interaction process is not encrypted.

[0204] Step 306: The UE interacts with the base station to obtain UE context and information such as (SUCI).

[0205] Step 307: The UE interacts with the base station to perform authentication and obtain authentication values ​​and information such as (SUPI).

[0206] Step 308: The UE and the base station interact to establish a PDU session.

[0207] Step 309: The UE interacts with the base station. The UE sends a Security ModCommand signaling to the gNB to obtain encryption and integrity protection parameters and start encryption and integrity protection.

[0208] In steps 306 to 309 above, the UE is in the connected state, and the interaction process is not encrypted.

[0209] Step 310: The gNB sends an RRC Reconfiguration signaling message to the UE, which carries the reassigned C-RNTI. The signaling message also carries Registration Accept.

[0210] Step 311: The UE sends an RRC Reconfiguration Complete message to the gNB.

[0211] Step 312: The UE sends a Registration Complete message to the gNB, indicating that registration is complete and uplink and downlink data transmission begins.

[0212] This invention also provides a processing device for data transmission protection. Figure 4 This is a schematic diagram of the composition of a processing device for data transmission protection according to an embodiment of the present invention. Figure 1 ;like Figure 4 As shown, the device includes: a first determining unit 11 and a first communication unit 12; wherein,

[0213] The first determining unit 11 is used to determine whether a preset condition is met;

[0214] The first communication unit 12 is used to send C-RNTI to the terminal through an encrypted and integrity-protected signaling radio bearer when the first determining unit 11 determines that the preset conditions are met.

[0215] In some optional embodiments of the present invention, the first communication unit 12 is used to send C-RNTI to the terminal via encrypted and integrity-protected RRC signaling.

[0216] In a first optional embodiment, the first determining unit 11 is used to determine whether preset conditions are met after the terminal has completed encryption and integrity protection and before data transmission.

[0217] Optionally, the first determining unit 11 is used to receive the authentication, encryption and integrity protection completion message sent by the terminal through the first communication unit 12, and determine that the preset conditions are met.

[0218] In a second alternative embodiment, the first determining unit 11 is used to determine that a preset condition is met when determining an RRC link update with the terminal.

[0219] Optionally, the first determining unit 11 is configured to determine that a preset condition is met when determining the reconfiguration of the RRC link with the terminal; or, when receiving an RRC establishment request sent by the terminal through the first communication unit 12, determine that the preset condition is met; or, when receiving an RRC reconstruction request sent by the terminal through the first communication unit 12, determine that the preset condition is met.

[0220] Optionally, the first communication unit 12 is configured to send a C-RNTI to the terminal via encrypted and integrity-protected RRC establishment signaling if it receives an RRC establishment request from the terminal; and to send a C-RNTI to the terminal via encrypted and integrity-protected RRC reconstruction signaling if it receives an RRC reconstruction request from the terminal.

[0221] In a third alternative implementation, the first determining unit 11 is used to determine whether preset conditions are met based on the indication information of the core network equipment.

[0222] Optionally, the first determining unit 11 is configured to send a first message to the core network device through the first communication unit 12, the first message being used to request confirmation of whether to update the C-RNTI; the first message includes at least one of the following information: terminal type, bearer type, session type, slice type, and device type; receive a first response message sent by the core network device, the first response message including indication information of whether to update the C-RNTI; if the indication information indicates that the C-RNTI is to be updated, determine that a preset condition is met.

[0223] Optionally, the first communication unit 12 is configured to send C-RNTI to the terminal via encrypted and integrity-protected RRC reconfiguration signaling.

[0224] In some alternative embodiments of the present invention, such as Figure 5 As shown, the device further includes: an acquisition unit 13 and a second determination unit 14, wherein the acquisition unit 13 is used to obtain the preamble identifier used by the terminal for random access;

[0225] The second determining unit 14 is used to determine the RA-RNTI based on the preamble identifier;

[0226] Alternatively, the device may further include an acquisition unit 13 and a first scrambling unit 15;

[0227] The acquisition unit 13 is used to obtain the preamble identifier used by the terminal for random access;

[0228] The first scrambling unit 15 is used to scramble the RA-RNTI based on the preamble identifier;

[0229] The RA-RNTI is used to scramble C-RNTI.

[0230] In some optional embodiments of the present invention, the acquisition unit 13 is further configured to acquire resource information for transmitting the preamble;

[0231] The second determining unit 14 is used to determine RA-RNTI based on the resource information and the preamble identifier.

[0232] In one implementation, the RA-RNTI is determined based on the following expression:

[0233] RA-RNTI=1+t_id+10*f_id+preambleID

[0234] Where t_id represents the identifier of the first subframe in which the PRACH transmitting the preamble is located, f_id represents the index identifier of the PRACH transmitting the preamble in the frequency domain in this subframe, and preambleID represents the preamble identifier.

[0235] In another implementation, the RA-RNTI is determined based on the following expression:

[0236] RA-RNTI=1+s_id+14*t_id+14*80*f_id+14*80*8*ul_carrier_id+14*80*8*2*preambleID

[0237] Wherein, s_id represents the OFDM start sequence number of the time slot in which PRACH is located, t_id represents the start sequence number of the time slot of the system frame in which PRACH is located, f_id represents the frequency domain start sequence number in which PRACH is located, and ul_carrier_id represents the uplink carrier sequence number of the first message transmission in the PRACH process.

[0238] In some alternative embodiments of the present invention, such as Figure 6 As shown, the device further includes a second scrambling unit 16, used to scramble the data channel using scrambling code parameters; the scrambling code parameters include one of the following: setting a scrambling code identifier, or a random number.

[0239] Optionally, the first communication unit 12 is further configured to send the random number to the terminal via an encrypted and integrity-protected RRC reconfiguration signaling if the second scrambling unit 16 scrambles the data channel using a random number.

[0240] The processing device for data transmission protection in this embodiment of the invention can be implemented using a base station in practical applications. The first determining unit 11, the acquiring unit 13, the second determining unit 14, the first scrambling unit 15, and the second scrambling unit 16 in the device can all be implemented using a central processing unit (CPU), a digital signal processor (DSP), a microcontroller unit (MCU), or a field-programmable gate array (FPGA) in practical applications. The first communication unit 12 in the device can be implemented using a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and transceiver antennas in practical applications.

[0241] This invention also provides a processing device for data transmission protection. Figure 7 This is a schematic diagram of the composition of a processing device for data transmission protection according to an embodiment of the present invention. Figure 4 ;like Figure 7 As shown, the device includes a second communication unit 21 for receiving C-RNTI sent by a base station via an encrypted and integrity-protected signaling radio bearer.

[0242] In some alternative embodiments of the present invention, the second communication unit 21 is used to receive C-RNTI sent by the base station via encrypted and integrity-protected RRC signaling.

[0243] In some optional embodiments of the present invention, the second communication unit 21 is used to receive the C-RNTI sent by the base station through the signaling radio bearer of encryption and integrity protection after encryption and integrity protection is completed and before data transmission is performed.

[0244] Optionally, the second communication unit 21 is configured to receive the C-RNTI sent by the base station via the encrypted and integrity-protected signaling radio bearer after sending an authentication, encryption and integrity protection completion message to the base station.

[0245] In some optional embodiments of the present invention, the second communication unit 21 is configured to send an RRC establishment request to the base station and receive the C-RNTI sent by the base station through encrypted and integrity-protected RRC establishment signaling; or, send an RRC reconstruction request to the base station and receive the C-RNTI sent by the base station through encrypted and integrity-protected RRC reconstruction signaling; or, receive the C-RNTI sent by the base station through encrypted and integrity-protected RRC reconfiguration signaling.

[0246] In some alternative embodiments of the present invention, such as Figure 8 As shown, the device further includes: a third determining unit 22 and a first descrambling unit 23; wherein,

[0247] The third determining unit 22 is used to determine RA-RNTI based on the preamble identifier;

[0248] The first descrambling unit 23 is used to obtain the C-RNTI based on the C-RNTI after descrambling and scrambling the RA-RNTI; or,

[0249] The device further includes a second descrambling unit 24, used to obtain RA-RNTI based on the descrambled and scrambled RA-RNTI of the preamble identifier; and to obtain C-RNTI based on the descrambled and scrambled C-RNTI of the RA-RNTI.

[0250] In some optional embodiments of the present invention, the third determining unit 22 is further configured to determine resource information for transmitting the preamble; and determine RA-RNTI based on the resource information and the preamble identifier.

[0251] As one implementation, the RA-RNTI is determined based on the following expression:

[0252] RA-RNTI=1+t_id+10*f_id+preambleID

[0253] Where t_id represents the identifier of the first subframe in which the PRACH of the preamble is transmitted, f_id represents the index of the PRACH of the preamble in the frequency domain in that subframe, and preambleID represents the preamble identifier.

[0254] As another implementation, the RA-RNTI is determined based on the following expression:

[0255] RA-RNTI=1+s_id+14*t_id+14*80*f_id+14*80*8*ul_carrier_id+14*80*8*2*preambleID

[0256] Wherein, s_id represents the OFDM start sequence number of the time slot in which PRACH is located, t_id represents the start sequence number of the time slot of the system frame in which PRACH is located, f_id represents the frequency domain start sequence number in which PRACH is located, and ul_carrier_id represents the uplink carrier sequence number of the first message transmission in the PRACH process.

[0257] In some alternative embodiments of the present invention, such as Figure 9 As shown, the device further includes a third descrambling unit 25, used to descramble the scrambled data channel using scrambling code parameters; the scrambling code parameters include one of the following: setting a scrambling code identifier, or a random number.

[0258] Optionally, the second communication unit 21 is further configured to receive the random number sent by the base station through RRC reconfiguration signaling with encryption and integrity protection if the third descrambling unit 25 uses a random number to descramble the scrambled data channel.

[0259] The data transmission protection processing device in this embodiment of the invention can be implemented through a terminal in practical applications. The third determining unit 22, the first descrambling unit 23, the second descrambling unit 24, and the third descrambling unit 25 in the device can all be implemented by a CPU, DSP, MCU, or FPGA in practical applications; the second communication unit 21 in the device can be implemented through a communication module (including: basic communication kit, operating system, communication module, standardized interface, and protocol, etc.) and a transceiver antenna in practical applications.

[0260] It should be noted that the processing device for data transmission protection provided in the above embodiments is only illustrated by the division of the above program modules. In practical applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the processing device for data transmission protection provided in the above embodiments and the processing method embodiments for data transmission protection belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.

[0261] This invention also provides a communication device, which may be a base station or a terminal. Figure 10 This is a schematic diagram of the hardware composition structure of the communication device according to an embodiment of the present invention, such as... Figure 10 As shown, the communication device includes a memory 32, a processor 31, and a computer program stored in the memory 32 and executable on the processor 31. When the processor 31 executes the program, it implements the steps of the processing method for data transmission protection applied in a base station in the foregoing embodiments of the present invention; or, when the processor 31 executes the program, it implements the steps of the processing method for data transmission protection applied in a terminal in the foregoing embodiments of the present invention.

[0262] In this embodiment, the communication device also includes one or more network interfaces 33. It is understood that the various components in the communication device are coupled together via a bus system 34. It is understood that the bus system 34 is used to implement communication between these components. In addition to a data bus, the bus system 34 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 10 The general labeled all buses as Bus System 34.

[0263] It is understood that memory 32 can be volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); magnetic surface memory can be disk storage or magnetic tape storage. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memory 32 described in the embodiments of the present invention is intended to include, but is not limited to, these and any other suitable types of memory.

[0264] The methods disclosed in the above embodiments of the present invention can be applied to or implemented by processor 31. Processor 31 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in processor 31 or by instructions in software form. The processor 31 may be a general-purpose processor, DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 31 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of the present invention can be directly manifested as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in memory 32. Processor 31 reads the information in memory 32 and completes the steps of the aforementioned method in combination with its hardware.

[0265] In an exemplary embodiment, the communication device may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0266] In an exemplary embodiment, the present invention also provides a computer-readable storage medium, such as a memory 32 including a computer program, which can be executed by a processor 31 of a communication device to perform the steps described in the foregoing method. The computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM; or it may be various devices including one or any combination of the above-mentioned memories.

[0267] The computer-readable storage medium provided in the embodiments of the present invention stores a computer program thereon. When the program is executed by a processor, it implements the steps of the processing method for data transmission protection applied in a base station in the foregoing embodiments of the present invention; or, when the program is executed by a processor, it implements the steps of the processing method for data transmission protection applied in a terminal in the foregoing embodiments of the present invention.

[0268] The methods disclosed in the several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.

[0269] The features disclosed in the several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.

[0270] The features disclosed in the several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.

[0271] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.

[0272] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.

[0273] In addition, in the various embodiments of the present invention, each functional unit can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0274] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.

[0275] Alternatively, if the integrated units of this invention are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.

[0276] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A processing method for data transmission protection, characterized in that, The method includes: After the terminal completes random access, when it is determined that the preset conditions are met, the base station sends an updated or reconfigured Cell Radio Network Temporary Identifier (C-RNTI) to the terminal through an encrypted and integrity-protected signaling radio bearer. The method further includes: The base station obtains the preamble identifier used by the terminal for random access, and determines the random access radio network temporary identifier RA-RNTI based on the preamble identifier, or scrambles the RA-RNTI based on the preamble identifier; the RA-RNTI is used to scramble the C-RNTI.

2. The method according to claim 1, characterized in that, The transmission of the Cell Radio Network Temporary Identifier (C-RNTI) to the terminal via a signaling radio bearer protected by encryption and integrity includes: The C-RNTI is sent to the terminal via encrypted and integrity-protected Radio Resource Control (RRC) signaling.

3. The method according to claim 1 or 2, characterized in that, The determination that the preset conditions are met includes: After determining that the terminal has completed encryption and integrity protection, and before transmitting data, the base station determines that preset conditions are met.

4. The method according to claim 3, characterized in that, After the terminal completes encryption and integrity protection but before transmitting data, it determines that preset conditions are met, including: The base station receives the authentication, encryption, and integrity protection completion message sent by the terminal and determines that the preset conditions are met.

5. The method according to claim 1 or 2, characterized in that, The determination that the preset conditions are met includes: When the base station determines that the RRC link update with the terminal is met, it determines that the preset conditions are met.

6. The method according to claim 5, characterized in that, When the base station determines an RRC link update with the terminal, it determines that preset conditions are met, including: When the base station determines that the RRC link reconfiguration with the terminal is met, it determines that a preset condition is satisfied; or, When the base station receives an RRC establishment request sent by the terminal, it determines that a preset condition is met; or, When the base station receives the RRC reconstruction request sent by the terminal, it determines that the preset conditions are met.

7. The method according to claim 6, characterized in that, The transmission of C-RNTI to the terminal via a signaling radio bearer protected by encryption and integrity includes: If the base station receives an RRC establishment request sent by the terminal, the base station sends a C-RNTI to the terminal through encrypted and integrity-protected RRC establishment signaling; If the base station receives an RRC reconstruction request sent by the terminal, the base station sends a C-RNTI to the terminal through encrypted and integrity-protected RRC reconstruction signaling.

8. The method according to claim 1 or 2, characterized in that, The determination that the preset conditions are met includes: The base station determines whether the preset conditions are met based on the indication information from the core network equipment.

9. The method according to claim 8, characterized in that, The base station determines that preset conditions are met based on notification messages from the core network equipment, including: The base station sends a first message to the core network equipment. The first message is used to request confirmation of whether to update the C-RNTI. The first message includes at least one of the following information: terminal type, bearer type, session type, slice type, and device type. The base station receives a first response message sent by the core network device, the first response message including indication information on whether to update C-RNTI; If the indication information indicates an update to C-RNTI, it is determined that the preset conditions are met.

10. The method according to claim 9, characterized in that, The transmission of C-RNTI to the terminal via a signaling radio bearer protected by encryption and integrity includes: The base station sends C-RNTI to the terminal via encrypted and integrity-protected RRC reconfiguration signaling.

11. The method according to claim 1, characterized in that, The method further includes: The base station obtains resource information for transmitting the preamble; The determination of RA-RNTI based on the preamble identifier includes: The base station determines the RA-RNTI based on the resource information and the preamble identifier.

12. The method according to claim 11, characterized in that, The RA-RNTI is determined based on the following expression: RA-RNTI = 1 + t_id + 10 * f_id + preambleID Where t_id represents the identifier of the first subframe in which the physical random access channel (PRACH) for transmitting the preamble is located, f_id represents the frequency domain index of the PRACH for transmitting the preamble in this subframe, and preambleID represents the preamble identifier.

13. The method according to claim 11, characterized in that, The RA-RNTI is determined based on the following expression: RA-RNTI=1+s_id+14*t_id+14*80*f_id+14*80*8*ul_carrier_id+14*80*8*2*preambleID Wherein, s_id represents the orthogonal frequency division multiplexing (OFDM) start sequence number of the time slot in which PRACH is located, t_id represents the start sequence number of the time slot of the system frame in which PRACH is located, f_id represents the frequency domain start sequence number in which PRACH is located, ul_carrier_id represents the uplink carrier sequence number of the first message transmission in the PRACH process, and preambleID represents the preamble identifier.

14. The method according to claim 1, characterized in that, The method further includes: The base station uses scrambling code parameters to scramble the data channel; the scrambling code parameters include one of the following: setting a scrambling code identifier, or a random number.

15. The method according to claim 14, characterized in that, If the base station uses random numbers to scramble the data channel, the method further includes: The base station sends the random number to the terminal via encrypted and integrity-protected RRC reconfiguration signaling.

16. A processing method for data transmission protection, characterized in that, The method includes: After completing random access, the terminal receives the updated or reconfigured Cell Radio Network Temporary Identifier (C-RNTI) sent by the base station through an encrypted and integrity-protected signaling radio bearer, provided that preset conditions are met. The method further includes: The terminal determines the Random Access Radio Network Temporary Identifier (RA-RNTI) based on the preamble identifier, or obtains the RA-RNTI based on the descrambled and scrambled RA-RNTI of the preamble identifier; and obtains the C-RNTI based on the descrambled and scrambled C-RNTI of the RA-RNTI.

17. The method according to claim 16, characterized in that, The terminal receives the C-RNTI sent by the base station via an encrypted and integrity-protected signaling radio bearer, including: The terminal receives the C-RNTI sent by the base station through encrypted and integrity-protected Radio Resource Control (RRC) signaling.

18. The method according to claim 16 or 17, characterized in that, The terminal receives the C-RNTI sent by the base station via an encrypted and integrity-protected signaling radio bearer, including: After completing encryption and integrity protection and before transmitting data, the terminal receives the C-RNTI sent by the base station through the signaling radio bearer for encryption and integrity protection.

19. The method according to claim 18, characterized in that, After completing encryption and integrity protection but before transmitting data, the terminal receives the C-RNTI sent by the base station via the encryption and integrity protection signaling radio bearer, including: After the terminal sends an authentication, encryption, and integrity protection completion message to the base station, it receives the C-RNTI sent by the base station through the encrypted and integrity protection signaling radio bearer.

20. The method according to claim 16 or 17, characterized in that, The terminal receives the C-RNTI sent by the base station via an encrypted and integrity-protected signaling radio bearer, including: The terminal sends an RRC establishment request to the base station and receives the C-RNTI sent by the base station through encrypted and integrity-protected RRC establishment signaling; or... The terminal sends an RRC reconstruction request to the base station and receives the C-RNTI sent by the base station through encrypted and integrity-protected RRC reconstruction signaling; or... The terminal receives the C-RNTI sent by the base station through encrypted and integrity-protected RRC reconfiguration signaling.

21. The method according to claim 16, characterized in that, The method further includes: The terminal determines the resource information used to transmit the preamble; The terminal determines the RA-RNTI based on the preamble identifier, including: The terminal determines the RA-RNTI based on the resource information and the preamble identifier.

22. The method according to claim 21, characterized in that, The RA-RNTI is determined based on the following expression: RA-RNTI = 1 + t_id + 10 * f_id + preambleID Where t_id represents the identifier of the first subframe in which the PRACH of the preamble is transmitted, f_id represents the index of the PRACH of the preamble in the frequency domain in this subframe, and preambleID represents the preamble identifier.

23. The method according to claim 21, characterized in that, The RA-RNTI is determined based on the following expression: RA-RNTI=1+s_id+14*t_id+14*80*f_id+14*80*8*ul_carrier_id+14*80*8*2*preambleID Wherein, s_id represents the OFDM start sequence number of the time slot in which PRACH is located, t_id represents the start sequence number of the time slot of the system frame in which PRACH is located, f_id represents the frequency domain start sequence number in which PRACH is located, ul_carrier_id represents the uplink carrier sequence number of the first message transmission in the PRACH process, and preambleID represents the preamble identifier.

24. The method according to claim 16, characterized in that, The method further includes: The terminal uses scrambling parameters to descramble the scrambled data channel; the scrambling parameters include one of the following: setting a scrambling code identifier, or a random number.

25. The method according to claim 24, characterized in that, If the terminal uses random numbers to descramble the scrambled data channel, the method further includes: The terminal receives the random number sent by the base station via encrypted and integrity-protected RRC reconfiguration signaling.

26. A processing apparatus for data transmission protection, characterized in that, The device includes: a first determining unit and a first communication unit; wherein... The first determining unit is used to determine whether preset conditions are met after the terminal completes random access; The first communication unit is configured to send an updated or reconfigured Cell Radio Network Temporary Identifier (C-RNTI) to the terminal via an encrypted and integrity-protected signaling radio bearer when the first determining unit determines that the preset conditions are met. The apparatus further includes: an acquisition unit and a second determination unit, wherein the acquisition unit is configured to obtain a preamble identifier used by the terminal for random access; and the second determination unit is configured to determine the RA based on the preamble identifier. RNTI; Alternatively, the apparatus further includes an acquisition unit and a first scrambling unit; wherein the acquisition unit is configured to obtain a preamble identifier used by the terminal for random access; and the first scrambling unit is configured to scramble the RA based on the preamble identifier. RNTI; the RA RNTI is used for scrambling C RNTI.

27. A processing apparatus for data transmission protection, characterized in that, The device includes a second communication unit, used to receive, after completing random access, an updated or reconfigured Cell Radio Network Temporary Identifier (C-RNTI) sent by the base station under preset conditions via an encrypted and integrity-protected signaling radio bearer. The device further includes: a third determining unit and a first descrambling unit; wherein, the third determining unit is used to determine the RA based on the preamble identifier. RNTI; the first descrambling unit, configured to, based on the RA C after RNTI descrambling and scrambling RNTI, obtained C RNTI; Alternatively, the apparatus may further include a second descrambling unit, configured to descramble the RA based on the preamble identifier. RNTI, obtain RA RNTI; based on the RA C after RNTI descrambling and scrambling RNTI, obtained C RNTI.

28. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 15; or, when the program is executed by a processor, it implements the steps of the method according to any one of claims 16 to 25.

29. A communication device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method according to any one of claims 1 to 15; or, when the processor executes the program, it implements the steps of the method according to any one of claims 16 to 25.

Citation Information

Patent Citations

  • Data transmission methods and devices

    CN102300331A

  • Intra-cell handover method and intra-cell handover equipment

    CN103024835A

  • Random access method and device

    CN110831223A

  • Apparatus and method for random access procedure in wireless communication system

    WO2021006588A1