Air interface frame-based unicast transmission method and system, electronic device and storage medium
By generating and verifying an air interface address that varies with the number of unicast transmissions, the problem of eavesdroppers continuously listening to air interface frames is solved, and identity protection for the air interface frame receiver and secure transmission of sensitive information are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2021-04-30
- Publication Date
- 2026-05-22
AI Technical Summary
Existing air interface frame encryption technology cannot prevent eavesdroppers from continuously obtaining sensitive information from encrypted data packets, while eavesdropping coding technology is difficult to deploy in multi-user wireless networks, which allows eavesdroppers to continuously eavesdrop on the air interface frames of specific users and expose sensitive information.
By generating an air interface address that changes with the number of unicast transmissions, the sender of the air interface frame marks the air interface frame, and the receiver verifies the air interface frame using a preset verification method, ensuring that only legitimate receivers can obtain service data, and eavesdroppers cannot determine the identity of the receiver.
It effectively prevents eavesdroppers from discovering the identity of the sender or receiver of the air interface frame, protecting communication privacy and preventing the leakage of sensitive information.
Smart Images

Figure CN115278661B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and more specifically, to a unicast transmission method, system, electronic device, and storage medium based on air interface frames. Background Technology
[0002] Air interface refers to the air interface in wireless communication. An air interface frame refers to the information transmitted between wireless air interfaces. An air interface address (radio ID) is a unique identifier used by the sender of an air interface frame to identify the sender or the receiver of the air interface frame.
[0003] Current air interface eavesdropping defense technologies are mainly divided into two categories: one is to encrypt the air interface frame at the data link layer, which is called air interface frame encryption. This type mainly prevents eavesdroppers from obtaining the content of the communication; the other is to introduce a special coding algorithm called wiretap code when coding the channel.
[0004] In current wireless protocol designs, the air interface address remains unchanged once it is determined. Therefore, once an eavesdropper detects the initial air interface address, they can filter out the air interface frames of a specific user (either the sender or receiver) from a large number of air interface frames, thus enabling continuous eavesdropping on that user.
[0005] Air interface frame encryption can effectively prevent eavesdroppers from obtaining plaintext data packets from legitimate users by listening to air interface frames, but it cannot prevent eavesdroppers from continuously obtaining ciphertext data packets carried by a particular user's air interface frames. Ciphertext data packets expose sensitive information such as data packet length, and multiple studies have shown that attackers can use continuous eavesdropping and analysis of ciphertext data packets to perform malicious acts such as obtaining sensitive information.
[0006] Wiretap coding technology prevents eavesdroppers from decoding intercepted air interface frames. Therefore, compared to air interface frame encryption, the sensitive information exposed by eavesdroppers in intercepted air interface frames is relatively less. However, wiretap coding requires prior knowledge of the eavesdropper's channel state, and its communication efficiency is strongly correlated with the eavesdropper's channel state. Therefore, it is basically impossible to deploy in multi-user wireless networks, and currently no wireless communication protocol uses this technology. Summary of the Invention
[0007] The present invention provides a unicast transmission method, system, electronic device and storage medium based on air interface frames to overcome or at least partially solve the above problems.
[0008] Firstly, a unicast transmission method based on air interface frames is provided, the method comprising:
[0009] The network device responds to the network access request initiated by the terminal, so that both the network device and the terminal obtain the initial air interface address;
[0010] The sending end of the air interface frame generates an air interface address that changes with the number of unicast transmissions, marks the air interface frame according to the air interface address, and unicasts the marked air interface frame to the receiving end of the air interface frame.
[0011] The receiving end of the air interface frame verifies the received air interface frame according to the preset verification method, and obtains the service data in the air interface frame after the verification is successful.
[0012] In the first unicast transmission of the air interface frame, the air interface address in the first unicast transmission air interface frame is the initial air interface address, and the receiving end of the air interface frame uses the initial air interface address to verify the first unicast transmission air interface frame.
[0013] When the sender of the air interface frame is a network device, the receiver of the air interface frame is a terminal; when the sender of the air interface frame is a terminal, the receiver of the air interface frame is a network device.
[0014] In one possible implementation, the network device and the terminal are in a mobile network; the sender of the air interface frame is the network device, and the receiver of the air interface frame is the terminal.
[0015] The network device responds to the network access request initiated by the terminal, enabling both the network device and the terminal to obtain initial air interface addresses, including:
[0016] In response to a network access request initiated by a terminal, the network device generates and sends an initial air interface address to the terminal.
[0017] In one possible implementation, in the scenario where the terminal sends uplink data to the network device, the sender of the air interface frame generates an air interface address that varies with the number of unicast transmissions, which is preceded by the terminal sending a channel resource allocation request to the network device.
[0018] The sending end of the air interface frame generates an air interface address that changes with the number of unicast transmissions, marks the air interface frame according to the air interface address, and unicasts the marked air interface frame to the receiving end of the air interface frame, including:
[0019] In response to a channel resource allocation request, the network device determines the number of unicast transmissions based on the cumulative number of channel resource allocation requests sent by the terminal.
[0020] The network device generates an air interface address that varies with the number of unicast transmissions, marks downlink control information according to the air interface address, and transmits the downlink control information as an air interface frame to the terminal via unicast. The service data in the downlink control information includes channel resources used to indicate the designated channel for transmitting uplink data.
[0021] In one possible implementation, the receiving end of the air interface frame verifies the received air interface frame according to a preset verification method, and obtains the service data in the air interface frame after successful verification, followed by:
[0022] The terminal determines the designated channel for transmitting uplink data based on channel resources, and sends uplink data on the designated channel;
[0023] Network devices receive uplink data sent by terminals on a designated channel.
[0024] In one possible implementation, in a scenario where a network device sends downlink data to a terminal, an air interface frame is marked according to its air interface address, and the marked air interface frame is unicasted to the receiving end of the air interface frame, including:
[0025] The downlink control information is marked with an air interface address and transmitted to the terminal as an air interface frame via unicast. The service data of the downlink control information includes channel resources used to indicate the designated channel for transmitting downlink data.
[0026] In one possible implementation, the receiving end of the air interface frame verifies the received air interface frame according to a preset verification method, and obtains the service data in the air interface frame after successful verification, followed by:
[0027] Network devices transmit downlink data on designated channels;
[0028] The terminal determines the designated channel for transmitting downlink data based on channel resources, and receives downlink data sent by network devices on the designated channel.
[0029] In one possible implementation, the downlink control information includes: a sequence number field for storing sequence numbers, an air interface address field for storing air interface addresses, and a data field for storing service data;
[0030] The air interface frame is marked according to the air interface address, including:
[0031] Store the air interface address in the air interface address field, obtain the sequence number based on the number of unicast transmissions, store the sequence number in the sequence number field, store the service data in the data field, and obtain the marked air interface frame.
[0032] In one possible implementation, the network device and the terminal are in a wireless local area network, and the sender of the air interface frame is the terminal or the network device.
[0033] The network device responds to the network access request initiated by the terminal, enabling both the network device and the terminal to obtain initial air interface addresses, including:
[0034] The network device responds to the network access request initiated by the terminal and obtains the initial air interface address included in the network access request.
[0035] In one possible implementation, the air interface frame includes a data field for storing service data, a receiving MAC address field for storing the air interface address, and a sequence field for storing the sequence number.
[0036] The air interface frame is marked according to the air interface address, including:
[0037] Store the air interface address in the receiver's MAC address field, obtain the sequence number based on the number of unicast transmissions, store the sequence number in the sequence field, store the service data in the data field, and obtain the marked air interface frame.
[0038] In one possible implementation, the sender of the air interface frame generates an air interface address that varies with the number of unicast transmissions, including:
[0039] When transmitting an air interface frame in a non-first unicast transmission, the sending end of the air interface frame determines the sequence number based on the number of unicast transmissions with the receiving end, encrypts the sequence number according to a preset encryption method, and uses the encryption result as the air interface address.
[0040] In one possible implementation, the serial number is encrypted according to a preset encryption method, and the encryption result is used as the air interface address, including:
[0041] The sending end uses the sequence number as plaintext and a preset session key as the encryption key to generate an air interface address;
[0042] The receiver of the air interface frame verifies the air interface frame using a preset verification method, including:
[0043] The receiving end uses the air interface address as the ciphertext and a pre-determined session key as the decryption key to decrypt the ciphertext. If the obtained plaintext matches the sequence number in the air interface frame, the verification is successful; or
[0044] The receiving end encrypts the sequence number using a pre-determined session key as the encryption key. If the obtained ciphertext is the same as the air interface address in the air interface frame, the verification is successful.
[0045] In one possible implementation, the serial number is encrypted according to a preset encryption method, and the encryption result is used as the air interface address, including:
[0046] According to the preset hash algorithm, the serial number and the preset session key are hashed, and the hash result is used as the air interface address.
[0047] The receiver of the air interface frame verifies the air interface frame using a preset verification method, including:
[0048] The receiving end performs a hash operation on the sequence number and the preset session key according to the pre-acquired hash algorithm. If the hash operation result is the same as the air interface address in the air interface frame, the verification is successful.
[0049] In one possible implementation, the sender of the air interface frame determines the sequence number based on the number of unicast transmissions with the receiver, including:
[0050] The sending end counts the cumulative number of air interface frames sent to the receiving end and obtains the count result;
[0051] If the sum of the count result and the preset value is less than the preset threshold, then the sum of the count result and the preset value will be used as the sequence number.
[0052] If the sum of the count result and the preset value is not less than the preset threshold, the count result will be restored to the initial value, and the initial value will be used as the sequence number. The initial value is less than the preset threshold.
[0053] Secondly, a unicast transmission system based on air interface frames is provided, including network equipment and terminals;
[0054] The terminal is used to initiate a network access request, and the network device is used to respond to the network access request initiated by the terminal, so that both the network device and the terminal obtain an initial air interface address.
[0055] The sending end of the air interface frame generates an air interface address that changes with the number of unicast transmissions, marks the air interface frame according to the air interface address, and unicasts the marked air interface frame to the receiving end of the air interface frame so that the receiving end of the air interface frame can verify the received air interface frame according to a preset verification method, and obtain the service data in the air interface frame after the verification is successful.
[0056] In the first unicast transmission of the air interface frame, the air interface address in the first unicast transmission air interface frame is the initial air interface address, and the receiving end of the air interface frame uses the initial air interface address to verify the first unicast transmission air interface frame.
[0057] When the sender of the air interface frame is a network device, the receiver of the air interface frame is a terminal; when the sender of the air interface frame is a terminal, the receiver of the air interface frame is a network device.
[0058] In one possible implementation, the network device and the terminal are in a mobile network; the sender of the air interface frame is the network device, and the receiver of the air interface frame is the terminal.
[0059] The network device includes: an air interface address allocation module for responding to a network access request initiated by a terminal, so that both the network device and the terminal obtain an initial air interface address;
[0060] The air interface address allocation module is specifically used to: generate and send an initial air interface address to the terminal in response to a network access request initiated by the terminal.
[0061] In one possible implementation, in the scenario where the terminal sends uplink data to the network device, the sender of the air interface frame generates an air interface address that varies with the number of unicast transmissions, which is preceded by the terminal sending a channel resource allocation request to the network device.
[0062] The sending end of the air interface frame generates an air interface address that changes with the number of unicast transmissions, marks the air interface frame according to the air interface address, and unicasts the marked air interface frame to the receiving end of the air interface frame, including:
[0063] In response to a channel resource allocation request, the network device determines the number of unicast transmissions based on the cumulative number of channel resource allocation requests sent by the terminal.
[0064] The network device generates an air interface address that varies with the number of unicast transmissions, marks downlink control information according to the air interface address, and transmits the downlink control information as an air interface frame to the terminal via unicast. The service data in the downlink control information includes channel resources used to indicate the designated channel for transmitting uplink data.
[0065] In one possible implementation, the receiving end of the air interface frame verifies the received air interface frame according to a preset verification method, and obtains the service data in the air interface frame after successful verification, followed by:
[0066] The terminal determines the designated channel for transmitting uplink data based on channel resources, and sends uplink data on the designated channel;
[0067] Network devices receive uplink data sent by terminals on a designated channel.
[0068] In one possible implementation, in a scenario where a network device sends downlink data to a terminal, an air interface frame is marked according to its air interface address, and the marked air interface frame is unicasted to the receiving end of the air interface frame, including:
[0069] The network device marks the downlink control information according to the air interface address and transmits the downlink control information as an air interface frame to the terminal via unicast. The service data of the downlink control information includes channel resources used to indicate the designated channel for transmitting downlink data.
[0070] In one possible implementation, the receiving end of the air interface frame verifies the received air interface frame according to a preset verification method, and obtains the service data in the air interface frame after successful verification, followed by:
[0071] Network devices transmit downlink data on designated channels;
[0072] The terminal determines the designated channel for transmitting downlink data based on channel resources, and receives downlink data sent by network devices on the designated channel.
[0073] Downlink control information includes: a sequence number field for storing sequence numbers, an air interface address field for storing air interface addresses, and a data field for storing service data;
[0074] The process of a network device marking an air interface frame based on its air interface address includes: storing the air interface address in the air interface address field, obtaining the sequence number based on the number of unicast transmissions, storing the sequence number in the sequence number field, storing the service data in the data field, and obtaining the marked air interface frame.
[0075] In one possible implementation, the network device and the terminal are in a wireless local area network, and the sender of the air interface frame is the terminal or the network device.
[0076] The network device responds to the network access request initiated by the terminal, enabling both the network device and the terminal to obtain initial air interface addresses, including:
[0077] The network device responds to the network access request initiated by the terminal and obtains the initial air interface address included in the network access request.
[0078] In one possible implementation, the air interface frame includes a data field for storing service data, a receiving MAC address field for storing the air interface address, and a sequence field for storing the sequence number.
[0079] The air interface frame is marked according to the air interface address, including:
[0080] Store the air interface address in the receiver's MAC address field, obtain the sequence number based on the number of unicast transmissions, store the sequence number in the sequence field, store the service data in the data field, and obtain the marked air interface frame.
[0081] In one possible implementation, the air interface frame sender includes an air interface address update module for generating an air interface address that changes with the number of unicast transmissions;
[0082] The air interface address update module is specifically used for: when transmitting an air interface frame for the first time, the sending end of the air interface frame determines the sequence number based on the number of unicast transmissions with the receiving end, encrypts the sequence number according to a preset encryption method, and uses the encryption result as the air interface address.
[0083] In one possible implementation, the air interface address update module includes a first encryption module that encrypts the serial number according to a preset encryption method;
[0084] The encryption module is specifically used to generate an air interface address using the serial number as plaintext and a preset session key as the encryption key.
[0085] The receiver of the air interface frame includes a first verification module for verifying the air interface frame using a preset verification method;
[0086] The first verification module is specifically used for:
[0087] The ciphertext is obtained by using the air interface address as the ciphertext and a pre-determined session key as the decryption key. If the resulting plaintext matches the sequence number in the air interface frame, the verification is successful; or
[0088] The sequence number is encrypted using a pre-determined session key as the encryption key. If the resulting ciphertext is the same as the air interface address in the air interface frame, the verification is successful.
[0089] In one possible implementation, the air interface address update module includes a second encryption module that encrypts the sequence number according to a preset encryption method;
[0090] The second encryption module is specifically used to perform a hash operation on the serial number and the preset session key according to a preset hash algorithm, and use the hash operation result as the air interface address.
[0091] The receiver of the air interface frame includes a second verification module for verifying the air interface frame using a preset verification method;
[0092] The second verification module is specifically used to: perform a hash operation on the sequence number and the preset session key according to the pre-acquired hash algorithm; if the hash operation result is the same as the air interface address in the air interface frame, the verification is successful.
[0093] In one possible implementation, the air interface address update module includes a sequence number determination module for determining the sequence number based on the number of unicast transmissions with the receiver;
[0094] The serial number determination module specifically includes:
[0095] The counting unit is used to count the cumulative number of air interface frames sent to the receiving end and obtain the counting result;
[0096] The first summation unit is used to use the sum of the counting result and the preset value as a sequence number if the sum of the counting result and the preset value is less than the preset threshold.
[0097] The cyclic update unit is used to restore the counting result to the initial value if the sum of the counting result and the preset value is not less than the preset threshold, and to use the initial value as the sequence number. The initial value is less than the preset threshold.
[0098] Thirdly, embodiments of the present invention provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the method provided in the first aspect.
[0099] Fourthly, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method provided in the first aspect.
[0100] Fifthly, embodiments of the present invention provide a computer program including computer instructions stored in a computer-readable storage medium. When a processor of a computer device reads the computer instructions from the computer-readable storage medium, the processor executes the computer instructions, causing the computer device to perform steps implementing the method provided in the first aspect.
[0101] The unicast transmission, system, electronic device, and storage medium based on air interface frames provided in this invention allow network devices to respond to network access requests initiated by terminals, obtaining the initial air interface address included in the network access request, or assigning an initial air interface address generated based on the network access request to the terminal, so that both the network device and the terminal can obtain the initial air interface address. When the network device and the terminal unicast a frame for the first time, the sender of the air interface frame marks the air interface frame with the initial air interface address, so that the receiver of the air interface frame can use the air interface address to verify the air interface frame and obtain the service data in the air interface frame. Since only the network device and the terminal know the initial air interface address, eavesdroppers cannot determine the identity of the receiver of the air interface frame during the first transmission of the air interface frame. When the network device and the terminal unicast a frame for the second time, the sender of the air interface frame generates an air interface address that changes with the number of unicast transmissions, making it impossible for eavesdroppers to determine the identity of the receiver by tracking the fixed air interface addresses of multiple air interface frames, thereby effectively preventing eavesdroppers from eavesdropping on the identity of the sender or receiver of the air interface frame. Attached Figure Description
[0102] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments of this application will be briefly introduced below.
[0103] Figure 1 A flowchart illustrating a unicast transmission method based on air interface frames provided in this application embodiment;
[0104] Figure 2 This application provides an embodiment of an interaction diagram of a terminal sending uplink data to a network device in a mobile network.
[0105] Figure 3 This application provides an embodiment of an interaction diagram of a network device sending downlink data to a terminal in a mobile network.
[0106] Figure 4 This is a schematic diagram of the DCI structure for unicast transmission according to an embodiment of this application;
[0107] Figure 5 A schematic diagram of the frame format of an 802.11 protocol air interface frame;
[0108] Figure 6 This is a schematic diagram illustrating the interaction between a terminal in a wireless local area network (WLAN) and a network device in an embodiment of this application, where the terminal sends uplink data.
[0109] Figure 7 This is a schematic diagram illustrating the interaction between a network device in a wireless local area network and a terminal when sending downlink data, according to an embodiment of this application.
[0110] Figure 8 This is a schematic diagram illustrating a process for obtaining a changed air interface address, provided as an embodiment of this application.
[0111] Figure 9 A schematic diagram illustrating the process of determining the serial number in an embodiment of this application;
[0112] Figure 10 A flowchart illustrating the anti-eavesdropping method in unicast transmission provided in the embodiments of this application;
[0113] Figure 11 A schematic diagram illustrating how an eavesdropper can eavesdrop on the anti-eavesdropping system provided in the unicast transmission embodiment of this application.
[0114] Figure 12 A schematic diagram of an optional structure of a distributed system applied to a blockchain system, as provided in an embodiment of this application;
[0115] Figure 13 An optional schematic diagram of the block structure provided in an embodiment of the present invention;
[0116] Figure 14 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0117] The embodiments of this application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting the invention.
[0118] Those skilled in the art will understand that, unless explicitly stated otherwise, the singular forms “a,” “an,” and “the” used herein may also include the plural forms. It should be further understood that the term “comprising” as used in the specification of this application means the presence of features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. It should be understood that when we say an element is “connected” or “coupled” to another element, it can be directly connected or coupled to the other element, or there may be intermediate elements. Furthermore, “connected” or “coupled” as used herein can include wireless connections or wireless coupling. The term “and / or” as used herein includes all or any units and all combinations of one or more associated listed items.
[0119] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0120] First, let's introduce and explain several terms used in this application:
[0121] 1. Terminal Equipment. In this embodiment, the terminal equipment is a device with wireless transceiver capabilities, which may be referred to as a terminal, user equipment (UE), mobile station (MS), mobile terminal (MT), access terminal equipment, vehicle-mounted terminal equipment, industrial control terminal equipment, UE unit, UE station, mobile station, remote station, remote terminal equipment, mobile device, UE terminal equipment, wireless communication equipment, UE agent, or UE device, etc. The terminal equipment can be fixed or mobile. It should be noted that the terminal equipment can support at least one wireless communication technology, such as LTE, NR, wideband code division multiple access (WCDMA), etc. For example, terminal devices can be mobile phones, tablets, desktop computers, laptops, all-in-one computers, in-vehicle terminals, virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to a wireless modem, wearable devices, in-vehicle terminal devices, terminal devices in future mobile communication networks, or terminal devices in future evolved public land mobile networks (PLMNs), etc. In some embodiments of this application, the terminal may also be a device with transceiver functions, such as a chip system. The chip system may include a chip, and may also include other discrete components.
[0122] 2. Network Equipment. In this application embodiment, the network equipment is a device that provides wireless communication functions for terminal devices, and can also be referred to as access network equipment, radio access network (RAN) equipment, etc. The network equipment can support at least one wireless communication technology, such as LTE, NR, WCDMA, etc. For example, the network equipment includes, but is not limited to: next-generation base stations (gNB), evolved node B (eNB), radio network controllers (RNC), node B (NB), base station controllers (BSC), base transceiver stations (BTS), home base stations (e.g., home evolved node B, or home node B (HNB)), baseband units (BBU), transmitting and receiving points (TRP), transmitting points (TP), mobile switching centers, etc., in 5th-generation (5G) mobile communication systems. Network devices can also be wireless controllers, centralized units (CUs), and / or distributed units (DUs) in cloud radio access network (CRAN) scenarios, or they can be relay stations, access points, vehicle-mounted devices, terminal devices, wearable devices, and network devices in future mobile communications or future evolved PLMNs. In some embodiments, network devices can also be means for providing wireless communication capabilities to terminal devices, such as chip systems. For example, a chip system may include chips, and may also include other discrete devices.
[0123] 3. Communication between terminal device and network device. In this embodiment, the terminal device and network device communicate via an air interface. For example, the communication interface between the terminal device and the network device can be a universal UE to network interface (Uu air interface). When the communication interface between the terminal device and the network device is the Uu air interface, the communication between the terminal device and the network device can also be referred to as Uu air interface communication.
[0124] 4. Air interface frame: Information transmitted between the terminal and network equipment over the wireless air interface.
[0125] 5. Air Interface Address: In wireless communication scenarios, it is a unique identifier used by the sender of an air interface frame to identify the sender or the target receiver. In other words, the air interface address can be used to identify either the sender or the target receiver, depending on actual needs.
[0126] For example, in the air interface frame transmission process under mobile networks (3G, 4G, 5G, etc.), the transmission of the air interface address is unidirectional. That is, the network device only sends the air interface address to the terminal, while the terminal does not send the air interface address to the network device. The air interface frame sent by the network device to the terminal records the air interface address and the channel resources for subsequent data transmission. The air interface address here is used to indicate the identity of the terminal, so that the terminal corresponding to the air interface address can send uplink / downlink data according to the channel resources after receiving the air interface frame.
[0127] In a wireless local area network (WLAN), air interface frame transmission is bidirectional, meaning both the terminal and network devices (such as routers) send air interface frames. The air interface frames sent by the terminal include its own air interface address, which facilitates the network device's identification of the terminal. The air interface frames sent by the network device include the target terminal's air interface address, allowing the terminal to identify whether the received air interface frames were intended for it.
[0128] 6. Hash: Generally translated as hashing, hashing, or transliterated as hash, it transforms an input of arbitrary length (also called a pre-image) into a fixed-length output through a hash algorithm. This transformation is a compression mapping, meaning that the space of hash values is usually much smaller than the space of inputs. Different inputs may hash to the same output, so it has the property of being unidirectional and irreversible, that is, it is impossible to determine a unique inverse input value from the hash value.
[0129] 7. Session Key: Also known as the data encryption key or working key, it is a randomly generated encryption and decryption key used to ensure secure communication sessions between a user and other computers or between two computers. It can be negotiated between the communicating users. The session key is generally dynamic and generated only when session data encryption is required.
[0130] 8. Blockchain is a new application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. Essentially, a blockchain is a decentralized database, a chain of data blocks linked together using cryptographic methods. Each data block contains information about a batch of network transactions, used to verify the validity of the information (anti-counterfeiting) and generate the next block. A blockchain can include an underlying platform, a platform product service layer, and an application service layer.
[0131] The underlying blockchain platform can include processing modules such as user management, basic services, smart contracts, and operational monitoring. The user management module is responsible for managing the identity information of all blockchain participants, including maintaining public and private key generation (account management), key management, and maintaining the correspondence between user real identities and blockchain addresses (access management). Furthermore, under authorization, it monitors and audits transactions of certain real identities and provides risk control rule configuration (risk control audit). The basic services module is deployed on all blockchain node devices to verify the validity of business requests. After consensus is reached on valid requests, they are recorded in storage. For a new business request, the basic services first perform interface adaptation parsing and authentication (interface adaptation), and then encrypt the business information through a consensus algorithm (consensus management). After encryption, the data is transmitted completely and consistently to the shared ledger (network communication) and recorded and stored. The smart contract module is responsible for contract registration, issuance, triggering, and execution. Developers can define contract logic using a programming language and publish it to the blockchain (contract registration). According to the contract terms, the key or other events are invoked to trigger execution and complete the contract logic. It also provides functions for contract upgrades and cancellations. The operation monitoring module is mainly responsible for deployment, configuration modification, contract settings, cloud adaptation, and real-time status visualization output during product release, such as alarms, monitoring network conditions, and monitoring the health status of node devices.
[0132] The platform's product service layer provides the basic capabilities and implementation frameworks for typical applications. Developers can leverage these basic capabilities, along with the specific characteristics of their business needs, to implement blockchain-based business logic. The application service layer provides blockchain-based application services to business stakeholders.
[0133] Existing wireless protocol designs are mainly divided into two categories. These two types of wireless protocols use air interface addresses differently during the transmission of air interface frames. The two types of wireless protocols include mobile networks and wireless local area networks, which will be introduced separately below.
[0134] The unicast transmission method, apparatus, electronic device, and storage medium based on air interface frames provided in this application aim to solve the above-mentioned technical problems of the prior art.
[0135] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0136] Please see Figure 1 The figure illustrates a flowchart of a unicast transmission method based on an air interface frame provided in an embodiment of this application, as shown in the figure, which includes:
[0137] S101. The network device responds to the network access request initiated by the terminal, so that both the network device and the terminal obtain the initial air interface address.
[0138] To address the problem of continuous eavesdropping on existing air interface frames due to their fixed air interface addresses, this application's inventive concept solves this problem by updating the air interface address. When a terminal accesses the network, it initiates a network access request to the network device. Depending on the application scenario, the network device can directly obtain the initial air interface address from the network access request, or allocate an initial air interface address to the terminal based on the network access request. That is, the initial air interface address can be written into the network access request by the terminal, or it can be generated by the network device after receiving the network access request. After step S101, both the terminal and the network device will have the initial air interface address. Therefore, regardless of whether the sender of the initial unicast transmission air interface frame is the terminal or the network device, the air interface frame can be marked using the initial air interface address. Correspondingly, the receiver of the air interface frame can also use the initial air interface address to verify the air interface frame.
[0139] S102. The sending end of the air interface frame generates an air interface address that changes with the number of unicast transmissions, marks the air interface frame according to the air interface address, and unicasts the marked air interface frame to the receiving end of the air interface frame. When unicasting the air interface frame for the first time, the air interface address in the air interface frame of the first unicast transmission is the initial air interface address.
[0140] The application scenarios for unicast transmission of air interface frames between network devices and terminals can be either uplink data transmission from the terminal to the network device or downlink data transmission from the network device to the terminal.
[0141] When a network device and a terminal unicast an air interface frame for the first time, the sending end of the air interface frame marks the air interface frame with an initial air interface address. Since only the network device and the terminal that has just connected to the network know the initial air interface address, an eavesdropper cannot determine the identity of the receiving end of the air interface frame based on the first unicast transmission of the air interface frame.
[0142] Starting from the second unicast transmission of the air interface frame between the network device and the terminal, the air interface address in each unicast transmission air interface frame is different from the air interface address in the previous unicast transmission air interface frame. Since the air interface address generated by the sending end of the air interface frame changes continuously with the number of unicast transmissions, eavesdroppers cannot determine the identity of the receiving end of the air interface frame by repeatedly eavesdropping on the air interface address in the air interface frame.
[0143] S103. The receiving end of the air interface frame verifies the received air interface frame according to the preset verification method, and obtains the service data in the air interface frame after the verification is successful; when the receiving end of the air interface frame receives the air interface frame for the first time, it uses the initial air interface address to verify the air interface frame of the first unicast transmission.
[0144] The anti-eavesdropping method in unicast transmission of this application embodiment obtains the initial air interface address included in the network access request by responding to the network access request initiated by the terminal, or assigns an initial air interface address generated according to the network access request to the terminal, so that both the network device and the terminal can obtain the initial air interface address. When the network device and the terminal unicast transmit an air interface frame for the first time, the sending end of the air interface frame marks the air interface frame with the initial air interface address, so that the receiving end of the air interface frame uses the air interface address to verify the air interface frame and obtain the service data in the air interface frame. Since only the network device and the terminal know the initial air interface address, the eavesdropper cannot determine the identity of the receiving end of the air interface frame when the air interface frame is transmitted for the first time. When the network device and the terminal unicast transmit an air interface frame for the second time, the sending end of the air interface frame generates an air interface address that changes with the number of unicast transmissions, so that the eavesdropper can no longer determine the identity of the receiving end by tracking the fixed air interface address of multiple air interface frames. The embodiments of this application can effectively prevent eavesdroppers from eavesdropping on the identity of the sending end or the receiving end of the air interface frame.
[0145] As can be seen from the above embodiments, existing wireless protocol designs are mainly divided into two categories. The two types of wireless protocols have significant differences in the use of air interface addresses during the transmission of air interface frames. Therefore, the embodiments of this application will subsequently make improvements to the two types of wireless protocols respectively.
[0146] Based on the above embodiments, as an optional embodiment, the network device and terminal are in a mobile network.
[0147] In mobile networks, air interface frames can only be sent from network devices to terminals. Therefore, in mobile networks, the sender of air interface frames is always the network device, and the receiver is always the terminal.
[0148] In response to a network access request initiated by a terminal, the network device obtains the initial air interface address included in the network access request, or assigns an initial air interface address generated based on the network access request to the terminal, including:
[0149] In response to a network access request initiated by a terminal, the network device assigns an initial air interface address to the terminal.
[0150] In other words, in a mobile network, the initial air interface address is generated by the network device. When the network device receives a network access request initiated by the terminal, it generates the initial air interface address and assigns it to the terminal.
[0151] Based on the above embodiments, when the network device and the terminal are in a mobile network, the air interface frame includes downlink control information (DCI). The DCI is carried by the downlink physical control channel (PDCCH). The downlink control information sent by the network device to the terminal may include uplink / downlink channel resources, Hybrid Automatic Repeat Request (HARQ) information, power control, etc.
[0152] In scenarios where a terminal sends uplink data to a network device, the sender of the air interface frame generates an air interface address that varies with the number of unicast transmissions. This process also includes the terminal sending a channel resource allocation request to the network device.
[0153] It should be understood that in mobile networks, the interaction between terminals and network devices needs to be carried out on designated channels. Therefore, when a terminal sends uplink data to a network device, it first needs to send a channel resource allocation request to the network device. The network device allocates a designated channel to the terminal based on the request, and then the terminal sends uplink data to the network device on the designated channel.
[0154] The sending end of the air interface frame generates an air interface address that changes with the number of unicast transmissions, marks the air interface frame according to the air interface address, and unicasts the marked air interface frame to the receiving end of the air interface frame, including:
[0155] In response to a channel resource allocation request, the network device determines the number of unicast transmissions based on the cumulative number of channel resource allocation requests sent by the terminal; in this embodiment, the cumulative number of channel resource allocation requests sent can be used as the number of unicast propagation.
[0156] The network device generates an air interface address that varies with the number of unicast transmissions, marks downlink control information according to the air interface address, and transmits the downlink control information as an air interface frame to the terminal via unicast. The service data in the downlink control information includes channel resources used to indicate the designated channel for transmitting uplink data.
[0157] In this embodiment of the application, downlink control information is transmitted in the form of air interface frames in a mobile network. In the scenario of sending uplink data, the downlink control information includes channel resources that indicate the designated channel for transmitting uplink data.
[0158] The receiving end of the air interface frame verifies the received air interface frame according to a preset verification method, and obtains the service data in the air interface frame after successful verification, and then includes:
[0159] The terminal determines the designated channel for transmitting uplink data based on channel resources, and sends uplink data on the designated channel;
[0160] Network devices receive uplink data sent by terminals on a designated channel.
[0161] Please see Figure 2 The example illustrates an interaction diagram of a terminal sending uplink data to a network device in a mobile network, as provided in an embodiment of this application. Figure 2 As shown, in mobile networks, the transmission of air interface addresses is unidirectional, meaning that air interface addresses can only be sent from network devices to terminals. Figure 2 The base station is used as a network device in the explanation.
[0162] When a terminal accesses a mobile network through a network device, the terminal first sends a request to the network device to access the mobile network. Upon receiving the request, the network device assigns a unique initial air interface address to the terminal, enabling the terminal to determine the designated channel for its first uplink data transmission based on the initial air interface address.
[0163] During the data uplink phase, the terminal first sends a channel resource allocation request to the network device, so that the network device can allocate channel resources to the terminal after receiving the channel resource allocation request. It should be understood that each terminal needs to be on the channel configured by the network device in order to transmit data.
[0164] After receiving a channel resource allocation request, the network device determines the channel resources to allocate to the terminal. Since channel resources are confidential information and unique to each terminal, this embodiment uses the DCI (Distributed Interface Frame) for storing channel resources as an air interface frame and the channel resources as service data. When sending downlink data to the terminal for the first time, the network device identifies the DCI with the allocated initial air interface address. In subsequent downlink data transmissions, the network device determines the air interface address based on the number of air interface frames sent to the terminal, stores the air interface address and channel resources in the downlink control information, and then sends the downlink control information to the terminal. This ensures that the air interface address of the DCI sent by the network device changes each time, making it difficult for eavesdroppers to continuously eavesdrop on the DCI received by a specific terminal, thus guaranteeing communication security.
[0165] After receiving and parsing the downlink control information, the terminal verifies the information based on the air interface address. If the verification is successful, it determines that the channel resource in the downlink control information is intended for itself, and then sends uplink data on the channel specified by the channel resource. The network device receives the uplink data sent by the terminal on the specified channel.
[0166] Based on the above embodiments, as an optional embodiment, in a scenario where a network device sends downlink data to a terminal, marking the air interface frame according to the air interface address and unicasting the marked air interface frame to the receiving end of the air interface frame includes:
[0167] The downlink control information is marked with an air interface address and transmitted to the terminal as an air interface frame via unicast. The service data of the downlink control information includes channel resources used to indicate the designated channel for transmitting downlink data.
[0168] It is important to note that when a network device sends downlink data to a terminal, the terminal does not need to request a specific channel from the network device. Instead, the network device directly instructs the terminal on the specific channel for transmitting downlink data, and this information is also sent through downlink control information.
[0169] Based on the above embodiments, as an optional embodiment, the receiving end of the air interface frame verifies the received air interface frame according to a preset verification method, and obtains the service data in the air interface frame after successful verification, and then further includes:
[0170] Network devices transmit downlink data on designated channels;
[0171] The terminal determines the designated channel for transmitting downlink data based on channel resources, and receives downlink data sent by network devices on the designated channel.
[0172] Please see Figure 3 The example illustrates an interaction diagram of a network device sending downlink data to a terminal in a mobile network, as provided in an embodiment of this application. Figure 3 As shown, during the downlink data phase, the network device does not need to receive a channel resource allocation request. Instead, it uses the DCI used to store channel resources as an air interface frame, uses the channel resources as service data, determines the air interface address based on the number of air interface frames sent to the terminal, stores the air interface address and channel resources in the downlink control information, then sends the downlink control information to the terminal, and sends downlink data on the channel specified by the channel resource.
[0173] After receiving and parsing the downlink control information, the terminal obtains the current sequence number, air interface address, and channel resources in the downlink control information. The terminal verifies the air interface address. If the verification is successful, it determines that the channel resources in the downlink control information are sent to itself, and thus receives downlink data on the channel specified by the channel resources.
[0174] It should be understood that when a terminal interacts with a base station for the first time, the terminal identifies the air interface frame sent to itself based on the initial air interface address allocated by the base station. Starting from the second interaction, the terminal will verify the air interface address in the received air interface frame according to the verification method pre-determined with the base station.
[0175] Depend on Figure 2 and Figure 3 As can be seen, in a mobile network environment, when the network device and terminal of this application embodiment transmit uplink and downlink data, they use DCI information as the air interface frame, channel resources as the service data in the air interface frame, and determine the air interface address based on the number of interactions with the target terminal each time, so that the channel resources are fully kept confidential. Since the eavesdropper cannot continuously eavesdrop on the channel resources used by a certain terminal, he / she cannot continuously steal the uplink and downlink data exchanged between the network device and a certain terminal.
[0176] The downlink control information in this embodiment includes a sequence number field for storing sequence numbers, an air interface address field for storing air interface addresses, and a data field for storing channel resources required for uplink or downlink data transmission. The sequence number is generated by the sending end based on the number of unicast transmissions with the receiving end; for example, the number of unicast transmissions can be directly used as the sequence number.
[0177] The DCI structure in related technologies, specifically the pre-improvement DCI structure, includes an air interface address field and a data field. When a network device sends multiple DCI messages to the same terminal, the air interface address in the air interface address field is always ID1. Therefore, by repeatedly eavesdropping on the DCI messages and using the unchanging air interface address, an eavesdropper can determine the identity of the receiving end of the DCI message.
[0178] Please see Figure 4 The figure illustrates a schematic diagram of the DCI structure for unicast transmission in an embodiment of this application. As shown in the figure, the DCI structure in this embodiment of the application adds a sequence number field, which is used to store the sequence number of each DCI sent by the network device. It can be seen from the figure that the air interface address in the air interface address field and the sequence number in the sequence number field are different in each DCI sent, thereby avoiding the problem of the target receiving end of the DCI being continuously eavesdropped on by the eavesdropper.
[0179] In a mobile network environment, the embodiments of this application include marking air interface frames according to air interface addresses, including:
[0180] The network device stores the air interface address in the air interface address field, obtains the sequence number based on the number of unicast transmissions, stores the sequence number in the sequence number field, stores the service data in the data field, and obtains the marked air interface frame.
[0181] Based on the above embodiments, as an optional embodiment, the network device and the terminal are located in a wireless local area network (WLAN). In a WLAN, both the network device and the terminal can send air interface frames to each other; therefore, both the network device and the terminal can act as either a sender or a receiver of air interface frames. When the sender is the terminal, the receiver is the network device; conversely, when the sender is the network device, the receiver is the terminal.
[0182] The network device responds to the network access request initiated by the terminal, enabling both the network device and the terminal to obtain initial air interface addresses, including:
[0183] The network device responds to the network access request initiated by the terminal and obtains the initial air interface address included in the network access request.
[0184] In a wireless local area network, when a terminal joins the network, it sends an initial air interface address to the network device. This initial air interface address is recorded by the terminal in the network access request.
[0185] Based on the above embodiments, in a wireless local area network (WLAN), an air interface frame includes at least a data field for storing service data, a receiver MAC address field for storing the air interface address, and a sequence number field for storing the sequence number. The sequence number is generated by the sending end based on the number of unicast transmissions with the receiving end.
[0186] In wireless local area networks (WLANs), both terminals and network devices can act as transmitters of air interface frames. The 802.11 standard defined by the Institute of Electrical and Electronics Engineers (IEEE) is the current standard for WLANs. In this application embodiment, the air interface frame in a WLAN does not need to be modified in the same way as the air interface frame in a mobile network. Instead, it reuses some fields of the air interface frame, making this application embodiment applicable to current WLANs.
[0187] Please see Figure 5 The figure illustrates an example of the frame format of an 802.11 protocol air interface frame. As shown in the figure, the air interface frame includes the following fields:
[0188] Frame Control, a structure that describes and controls information related to MAC frames;
[0189] Duration indicates how long the frame and its acknowledgment frame will occupy the channel. The Duration value is used in the calculation of the network allocation vector.
[0190] Address1 to 4 represent the address fields, which are generally RA (Receiver Address), TA (Transmission Address), SA (Sender Address), and DA (Destination Address).
[0191] Sequence, the sequence control field, is used to filter duplicate frames;
[0192] The Data field stores information sent or received. The format of this field varies considerably depending on the type of data frame.
[0193] FCS (Frame Check Sequence): Includes a 32-bit cyclic redundancy check (CRC) used to check whether the received frame is complete.
[0194] Each field in an air frame has a length limit. Most fields have a fixed byte length, such as the Duration field being 2 bytes and the sequence field being 4 bytes. However, the byte length of some fields can vary. For example, the length of the data field is 0-2312 bytes, meaning the data field can be empty (0 bytes) or it can be up to 2312 bytes.
[0195] In this embodiment, the service data is written into the data field, the sequence number is written into the Sequence field, and the air interface address is written into the receiver's MAC address field. Without changing the 802.11 protocol, the encrypted transmission of the air interface frame is guaranteed, preventing eavesdroppers from continuously eavesdropping on the receiver in a wireless LAN scenario.
[0196] Furthermore, in a wireless network environment, the embodiment of this application includes marking air interface frames according to air interface addresses, including:
[0197] The sending end of the air interface frame stores the air interface address in the MAC address field of the receiving end, obtains the sequence number according to the number of unicast transmissions, stores the sequence number in the sequence field, stores the service data in the data field, and obtains the marked air interface frame.
[0198] Please see Figure 6 It exemplarily illustrates an interaction diagram of a terminal in a wireless local area network sending uplink data to a network device, such as... Figure 6As shown, when a terminal accesses a wireless local area network, the terminal first needs to send an initial air interface address to the network device, so that when the router receives an air interface frame, it can determine the identity of the sender of the air interface frame based on the air interface address in the air interface frame.
[0199] During the data uplink phase, the terminal identifies the service data. When sending uplink data for the first time, the terminal marks the air interface frame with an initial air interface address. The air interface frame carries the service data. After receiving the air interface frame, the network device parses the air interface frame with the initial air interface address to determine the identity of the sender of the air interface frame, and then obtains the service data. Starting from the second uplink data transmission, the terminal generates an air interface address that changes with the number of unicast transmissions. Each air interface address is different from the previous one. The network device verifies the received air interface frame with a preset verification method to determine the identity of the sender of the air interface frame, and then obtains the service data.
[0200] Please see Figure 7 It exemplarily illustrates an interaction diagram of a network device (shown as a router in the figure) sending downlink data to a terminal in a wireless local area network, such as... Figure 8 As shown, when a terminal accesses a wireless local area network, the terminal first needs to send an initial air interface address to the network device, so that the router can determine the identity of the receiver of the air interface frame based on the air interface address in the air interface frame when it sends the first air interface frame.
[0201] During the downlink data transmission phase, the router identifies the service data. When sending downlink data for the first time, the router marks the air interface frame with an initial air interface address. The air interface frame carries the service data. After receiving the air interface frame, the terminal resolves the air interface frame with the initial air interface address to determine that the air interface frame was sent to itself, and then obtains the service data. Starting from the second downlink data transmission, the router generates an air interface address that changes with the number of unicast transmissions. Each air interface address is different from the previous one. The terminal verifies the received air interface frame with a preset verification method to determine that the air interface frame was sent to itself, and then obtains the service data.
[0202] Depend on Figure 6 and Figure 7As can be seen, air interface frames in a wireless LAN are transmitted bidirectionally—a terminal needs to send an air interface frame when sending uplink data to a network device, and the network device also needs to send an air interface frame when sending downlink data to a terminal. When a terminal sends uplink data to a router for the first time, the air interface address in the air interface frame is the initial air interface address that the terminal sent to the router when it accessed the network. In subsequent uplink data transmissions, the current sequence number and air interface address are determined based on the number of interactions. When a router sends downlink data to a terminal, the air interface address contained in the first air interface frame it sends is the initial air interface address that the terminal sent to the router when it accessed the network. In subsequent downlink data transmissions, the sequence number and air interface address are determined based on the number of interactions.
[0203] Based on the above embodiments, as an optional embodiment, the air interface frame sender generates an air interface address that varies with the number of unicast transmissions, including:
[0204] When transmitting an air interface frame in a non-first unicast transmission, the sending end of the air interface frame determines the sequence number based on the number of unicast transmissions with the receiving end, encrypts the sequence number according to a preset encryption method, and uses the encryption result as the air interface address.
[0205] In other words, in both mobile network and wireless LAN environments, when the transmitting end of the air interface frame determines the air interface address, it will first determine the sequence number based on the number of unicast transmissions when transmitting the air interface frame for the first time, and then encrypt the sequence number according to a preset encryption method, and use the encryption result as the air interface address.
[0206] The air interface frame generated in this embodiment contains two pieces of information: a sequence number and an air interface address. Unlike existing air interface frames, firstly, the air interface address in the air interface frame in this embodiment is constantly changing, making it impossible for an eavesdropper to determine the receiving end of the air interface frame by continuously eavesdropping on the air interface address. Secondly, the air interface frame includes a sequence number, which can be used by the receiving end to verify whether the air interface frame was sent to itself.
[0207] Please see Figure 8The figure illustrates a flowchart of obtaining a changing air interface address according to an embodiment of this application. As shown in the figure, during the process of obtaining the air interface address, the session key remains unchanged, while the sequence number is continuously updated with the number of unicast transmissions. In the figure, sequence number 2 represents the sequence number determined according to the second unicast transmission, and sequence number T represents the sequence number determined according to the Tth (T is a positive integer greater than 3) unicast transmission. The session key and sequence number are encrypted using a preset encryption algorithm to obtain the corresponding air interface address for the unicast transmission (as shown in the figure: air interface address 2, air interface address 3, ..., air interface address T). It should be understood that the session key and encryption algorithm are information pre-agreed by the sender and receiver, and can be determined during the first interaction between the sender and receiver.
[0208] Specifically, the method for generating an air interface address in this application embodiment includes:
[0209] Option 1: Use the current serial number as plaintext and the preset session key as the encryption key to generate an air interface address.
[0210] Scheme 1 requires the receiving end and the sending end to pre-confirm that the encryption and decryption keys are consistent, so that after the receiving end receives the air interface frame, the air interface frame can be correctly decrypted by the receiving end, and the current sequence number can be obtained. This application does not specify a particular encryption algorithm; for example, it can be the following encryption algorithms:
[0211] 1. DES (Data Encryption Standard): A data encryption standard that is relatively fast and suitable for encrypting large amounts of data;
[0212] 2. 3DES (Triple DES): Based on DES, it encrypts a piece of data three times using three different keys, resulting in higher encryption strength.
[0213] 3. AES (Advanced Encryption Standard): High-speed encryption standard with a high level of security, supporting encryption with 128, 192, 256, and 512-bit keys;
[0214] 4. Blowfish is a block cipher algorithm.
[0215] Option 2: Perform a hash operation on the current sequence number and session key according to the preset hash algorithm, and use the hash result as the air interface address;
[0216] Since it is difficult to find the reverse pattern of hash algorithms, that is, it is difficult to deduce the current sequence number from the hash value, when using hash algorithms for encryption, the sending end and the receiving end need to agree on the same hash algorithm in advance. Then, the receiving end uses the agreed hash algorithm to perform a hash operation on the current sequence number in the air interface frame. If the calculated hash value is the same as the air interface address in the air interface frame, it is determined that it is an air interface frame sent to itself.
[0217] Based on the above embodiments, as an optional embodiment, the receiving end can verify the air interface frame using the preset verification method in the following ways:
[0218] For encryption methods that use the session key as the encryption key, the corresponding verification method is as follows:
[0219] The ciphertext is obtained by using the air interface address as the ciphertext and a pre-determined session key as the decryption key. If the resulting plaintext matches the sequence number in the air interface frame, the verification is successful; otherwise, the verification fails.
[0220] The serial number is encrypted using a pre-determined session key. If the ciphertext obtained is the same as the air interface address, the verification is successful; otherwise, the verification fails.
[0221] For encryption methods using hash algorithms, the corresponding verification method is:
[0222] The receiving end performs a hash operation on the sequence number and the preset session key according to the pre-acquired hash algorithm. If the hash operation result is the same as the air interface address in the air interface frame, then the receiving end determines itself to be the target receiving end.
[0223] It should be understood that in mobile network scenarios, the sender of the air interface frame—the network device—broadcasts the air interface frame to all terminals within its cell range and performs uplink and downlink data transmission with each terminal. However, each terminal only transmits uplink and downlink data with one network device. This means the network device stores encryption methods agreed upon with all terminals within its cell range, while the terminal stores authentication methods agreed upon with only one network device. Therefore, if the terminal fails to authenticate the received control frame using the pre-stored authentication method, it can directly discard the service data in the air interface frame. In wireless LAN scenarios, the sender of the air interface frame can be either a network device or a terminal. When the sender is a network device, the receiver is a terminal; when the sender is a terminal, the receiver is a network device. When the receiver is a terminal, if the terminal determines authentication has failed on the first attempt, it can directly discard the service data. When the receiver is a network device, since the network device stores encryption methods agreed upon with multiple terminals, it also stores authentication methods agreed upon with multiple terminals. Only when all authentication methods fail will the service data be discarded, thus ensuring normal data transmission.
[0224] As an optional embodiment, this application uses a cyclic counting method to determine the serial number, thereby limiting the serial number to a certain numerical range and avoiding the drawback of the generated air interface address occupying too many characters due to the serial number increasing infinitely. Please refer to [link to relevant documentation]. Figure 9 The figure illustrates an exemplary flowchart of the process for determining a serial number according to an embodiment of this application. As shown, the process includes:
[0225] S201. Count the number of times air interface frames are sent to the receiving end and obtain the counting result;
[0226] S202. Calculate the sum of the counting result and the preset value to obtain the summation result;
[0227] S203. Determine the summation result and the preset threshold. If the summation result is less than the preset threshold, proceed to step S204. If the summation result is not less than the preset threshold, proceed to step S205.
[0228] S204. Use the sum of the counting result and the preset value as the sequence number, and the process ends;
[0229] S205. Restore the counting result to the initial value and use the initial value as the sequence number. The process ends when the initial value is less than the preset threshold.
[0230] In this embodiment, the transmitting end counts the number of times an air interface frame has been sent to the target receiving end after each transmission. The count result is then summed with a preset value, which in this embodiment can be 1 (meaning the count is incremented by 1 for each air interface frame sent). The summation result is then compared with a preset threshold, which can be 2. 16 If the summation result is less than a preset threshold, the summation result is used as the current sequence number; otherwise, the technical result is restored to the initial value. In this embodiment, the initial value can be 0. The initial value is then used as the current sequence number. It should be noted that the preset values, preset thresholds, and initial values listed above are only examples, and this embodiment does not impose any specific limitations on them.
[0231] For example, in this embodiment of the application, a preset value of 1 and a preset threshold of 100 are set, and an initial value of 3 are set. If the sending end has sent 50 air interface frames to the target receiving end, the sum of 50 and 1 is less than the preset threshold of 100. Therefore, the current sequence number of the sending end when sending the air interface frame for the 51st time is 51. If the sending end has sent 99 air interface frames to the target receiving end, the sum of 99 and 1 is not less than the preset threshold of 100. Therefore, the count result is restored to 3. 3 is used as the current sequence number. It can be further inferred that when the sending end sends the air interface frame again, the count result of the air interface frames sent is 3, thereby achieving the purpose of cyclic update.
[0232] Please see Figure 10 The figure illustrates an exemplary flowchart of an anti-eavesdropping method in unicast transmission provided in an embodiment of this application, as shown in the figure, including:
[0233] S301. In response to a network access request initiated by a terminal, the network device generates and sends an initial air interface address to the terminal.
[0234] S302. When the network device and the terminal transmit an air interface frame for the first time via unicast, the sending end of the air interface frame marks the air interface frame with an initial air interface address so that the receiving end of the air interface frame can use the air interface address to verify the air interface frame and obtain the service data in the air interface frame.
[0235] S303. When a network device and a terminal are transmitting an air interface frame via unicast for the first time, the sending end of the air interface frame counts the number of times it has sent an air interface frame to the receiving end and obtains the counting result.
[0236] S304. The sending end calculates the sum of the counting result and the preset value to obtain the summation result;
[0237] S305. The sending end determines the summation result and the preset threshold. If the summation result is less than the preset threshold, then proceed to step S306. If the summation result is not less than the preset threshold, then proceed to step S307.
[0238] S306. The sending end uses the sum of the counting result and the preset value as the sequence number and executes step S308.
[0239] S307. The sending end restores the counting result to the initial value and uses the initial value as the sequence number. If the initial value is less than the preset threshold, proceed to step S308.
[0240] S308. The sending end generates an air interface address using the sequence number as plaintext and a preset session key as the encryption key.
[0241] S309. The receiving end uses a preset verification method to verify the air interface frame, and obtains the service data in the air interface frame after the verification is successful.
[0242] This application provides an anti-eavesdropping system for unicast transmission, including network devices and terminals;
[0243] The terminal is used to initiate a network access request, and the network device is used to respond to the network access request initiated by the terminal, so that both the network device and the terminal obtain an initial air interface address.
[0244] The sending end of the air interface frame generates an air interface address that changes with the number of unicast transmissions, marks the air interface frame according to the air interface address, and unicasts the marked air interface frame to the receiving end of the air interface frame so that the receiving end of the air interface frame can verify the received air interface frame according to a preset verification method, and obtain the service data in the air interface frame after the verification is successful.
[0245] In the first unicast transmission of the air interface frame, the air interface address in the first unicast transmission air interface frame is the initial air interface address, and the receiving end of the air interface frame uses the initial air interface address to verify the first unicast transmission air interface frame.
[0246] When the sender of the air interface frame is a network device, the receiver of the air interface frame is a terminal; when the sender of the air interface frame is a terminal, the receiver of the air interface frame is a network device.
[0247] By responding to a network access request initiated by a terminal, the network device obtains the initial air interface address included in the network access request, or assigns an initial air interface address generated according to the network access request to the terminal, so that both the network device and the terminal can obtain the initial air interface address. When the network device and the terminal unicast an air interface frame for the first time, the sending end of the air interface frame marks the air interface frame with the initial air interface address, so that the receiving end of the air interface frame can use the air interface address to verify the air interface frame and obtain the service data in the air interface frame. Since only the network device and the terminal know the initial air interface address, an eavesdropper cannot determine the identity of the receiving end of the air interface frame when it is first transmitted. When the network device and the terminal unicast an air interface frame for the second time, the sending end of the air interface frame generates an air interface address that changes with the number of unicast propagations, so that an eavesdropper can no longer determine the identity of the receiving end by tracking the fixed air interface address of multiple air interface frames. The embodiments of this application can effectively prevent eavesdroppers from eavesdropping on the identity of the sending end or the receiving end of the air interface frame.
[0248] Network devices and terminals are in a mobile network; the sender of the air interface frame is the network device, and the receiver of the air interface frame is the terminal.
[0249] The network device includes: an air interface address allocation module for responding to a network access request initiated by a terminal, so that both the network device and the terminal obtain an initial air interface address;
[0250] The air interface address allocation module is specifically used to: generate and send an initial air interface address to the terminal in response to a network access request initiated by the terminal.
[0251] In one possible implementation, when a terminal sends uplink data to a network device, the sender of the air interface frame generates an air interface address that varies with the number of unicast transmissions. This is preceded by the terminal sending a channel resource allocation request to the network device.
[0252] The sending end of the air interface frame generates an air interface address that changes with the number of unicast transmissions, marks the air interface frame according to the air interface address, and unicasts the marked air interface frame to the receiving end of the air interface frame, including:
[0253] In response to a channel resource allocation request, the network device determines the number of unicast transmissions based on the cumulative number of channel resource allocation requests sent by the terminal.
[0254] The network device generates an air interface address that varies with the number of unicast transmissions, marks downlink control information according to the air interface address, and transmits the downlink control information as an air interface frame to the terminal via unicast. The service data in the downlink control information includes channel resources used to indicate the designated channel for transmitting uplink data.
[0255] In one possible implementation, the receiving end of the air interface frame verifies the received air interface frame according to a preset verification method, and obtains the service data in the air interface frame after successful verification, followed by:
[0256] The terminal determines the designated channel for transmitting uplink data based on channel resources, and sends uplink data on the designated channel;
[0257] Network devices receive uplink data sent by terminals on a designated channel.
[0258] In one possible implementation, in a scenario where a network device sends downlink data to a terminal, an air interface frame is marked according to its air interface address, and the marked air interface frame is unicasted to the receiving end of the air interface frame, including:
[0259] The network device marks the downlink control information according to the air interface address and transmits the downlink control information as an air interface frame to the terminal via unicast. The service data of the downlink control information includes channel resources used to indicate the designated channel for transmitting downlink data.
[0260] In one possible implementation, the receiving end of the air interface frame verifies the received air interface frame according to a preset verification method, and obtains the service data in the air interface frame after successful verification, followed by:
[0261] Network devices transmit downlink data on designated channels;
[0262] The terminal determines the designated channel for transmitting downlink data based on channel resources, and receives downlink data sent by network devices on the designated channel.
[0263] Downlink control information includes: a sequence number field for storing sequence numbers, an air interface address field for storing air interface addresses, and a data field for storing service data;
[0264] The process of a network device marking an air interface frame based on its air interface address includes: storing the air interface address in the air interface address field, obtaining the sequence number based on the number of unicast transmissions, storing the sequence number in the sequence number field, storing the service data in the data field, and obtaining the marked air interface frame.
[0265] In one possible implementation, the network device and the terminal are in a wireless local area network, and the sender of the air interface frame is the terminal or the network device.
[0266] The network device responds to the network access request initiated by the terminal, enabling both the network device and the terminal to obtain initial air interface addresses, including:
[0267] The network device responds to the network access request initiated by the terminal and obtains the initial air interface address included in the network access request.
[0268] In one possible implementation, the air interface frame includes a data field for storing service data, a receiving MAC address field for storing the air interface address, and a sequence field for storing the sequence number.
[0269] The air interface frame is marked according to the air interface address, including:
[0270] Store the air interface address in the receiver's MAC address field, obtain the sequence number based on the number of unicast transmissions, store the sequence number in the sequence field, store the service data in the data field, and obtain the marked air interface frame.
[0271] In one possible implementation, the air interface frame sender includes an air interface address update module for generating an air interface address that changes with the number of unicast transmissions;
[0272] The air interface address update module is specifically used for: when transmitting an air interface frame for the first time, the sending end of the air interface frame determines the sequence number based on the number of unicast transmissions with the receiving end, encrypts the sequence number according to a preset encryption method, and uses the encryption result as the air interface address.
[0273] In one possible implementation, the air interface address update module includes a first encryption module that encrypts the serial number according to a preset encryption method;
[0274] The encryption module is specifically used to generate an air interface address using the serial number as plaintext and a preset session key as the encryption key.
[0275] The receiver of the air interface frame includes a first verification module for verifying the air interface frame using a preset verification method;
[0276] The first verification module is specifically used for:
[0277] The ciphertext is obtained by using the air interface address as the ciphertext and a pre-determined session key as the decryption key. If the resulting plaintext matches the sequence number in the air interface frame, the verification is successful; or
[0278] The sequence number is encrypted using a pre-determined session key as the encryption key. If the resulting ciphertext is the same as the air interface address in the air interface frame, the verification is successful.
[0279] In one possible implementation, the air interface address update module includes a second encryption module that encrypts the sequence number according to a preset encryption method;
[0280] The second encryption module is specifically used to perform a hash operation on the serial number and the preset session key according to a preset hash algorithm, and use the hash operation result as the air interface address.
[0281] The receiver of the air interface frame includes a second verification module for verifying the air interface frame using a preset verification method;
[0282] The second verification module is specifically used to: perform a hash operation on the sequence number and the preset session key according to the pre-acquired hash algorithm; if the hash operation result is the same as the air interface address in the air interface frame, the verification is successful.
[0283] In one possible implementation, the air interface address update module includes a sequence number determination module for determining the sequence number based on the number of unicast transmissions with the receiver;
[0284] The serial number determination module specifically includes:
[0285] The counting unit is used to count the cumulative number of air interface frames sent to the receiving end and obtain the counting result;
[0286] The first summation unit is used to use the sum of the counting result and the preset value as a sequence number if the sum of the counting result and the preset value is less than the preset threshold.
[0287] The cyclic update unit is used to restore the counting result to the initial value if the sum of the counting result and the preset value is not less than the preset threshold, and to use the initial value as the sequence number. The initial value is less than the preset threshold.
[0288] Please see Figure 11 The illustration shows a schematic diagram of an eavesdropper using the anti-eavesdropping system in unicast transmission provided in this application embodiment. As shown in the figure, the system includes a network device 201 and two terminals, namely 202 and 203. When the network device 201 first unicasts an air interface frame to the two terminals, the network device marks the air interface frame 1 sent to terminal 202 with the initial air interface address A1 and the air interface frame 2 sent to terminal 203 with the air interface address A2. When the eavesdropper hears the two air interface frames, since he does not know which terminal the air interface addresses A1 and A2 correspond to, he cannot know the correspondence between the air interface frames and the terminals. However, the eavesdropper continues to listen to whether the air interface addresses A1 and A2 appear in new air interface frames.
[0289] When network device 201 unicasts air interface frames to two terminals for the second time, the network device generates air interface addresses A3 and A4 that change with the number of unicast transmissions. Air interface frame 3 sent to terminal 202 is marked using air interface address A3, and air interface frame 4 sent to terminal 202 is marked using air interface address A4. When an eavesdropper hears the two air interface frames, they find that the air interface addresses in the two air interface frames are not A1 or A2, but A3 and A4, which makes it impossible to determine the correspondence between the air interface frames and the terminals. Therefore, the embodiments of this application can effectively prevent eavesdroppers from identifying the identity of the receiving end of the air interface frame.
[0290] The system involved in the embodiments of the present invention can be a distributed system formed by connecting a client and multiple nodes (any form of computing device in the network, such as a server or a user terminal) through network communication.
[0291] Taking a distributed system as an example, see blockchain system. Figure 12 , Figure 12 This is an optional structural diagram of the distributed system 100 provided in this embodiment of the invention applied to a blockchain system. It consists of multiple nodes 200 (any form of computing device connected to the network, such as servers or user terminals) and clients 300. The nodes form a peer-to-peer (P2P) network. The P2P protocol is an application layer protocol running on top of the Transmission Control Protocol (TCP). In the distributed system, any machine, such as a server or terminal, can join and become a node. A node includes a hardware layer, a middleware layer, an operating system layer, and an application layer.
[0292] See Figure 12 The functions of each node in the blockchain system shown include:
[0293] 1) Routing: A basic function of nodes used to support communication between nodes.
[0294] In addition to routing capabilities, nodes can also have the following functions:
[0295] 2) Applications are deployed in the blockchain to implement specific business needs. They record data related to the implementation of functions to form record data, carry digital signatures in the record data to indicate the source of the task data, and send the record data to other nodes in the blockchain system. When other nodes successfully verify the source and integrity of the record data, they add the record data to a temporary block.
[0296] For example, the business logic implemented by the application includes:
[0297] 2.1) A wallet is used to provide the function of conducting electronic currency transactions, including initiating transactions (i.e., sending the transaction record of the current transaction to other nodes in the blockchain system; after other nodes successfully verify the transaction, they store the transaction record data in the temporary block of the blockchain as a response to acknowledge the validity of the transaction; of course, the wallet also supports querying the remaining electronic currency in the electronic currency address;
[0298] 2.2) Shared ledger, used to provide functions such as storage, query and modification of ledger data. It sends the record data of the operation on the ledger data to other nodes in the blockchain system. After the other nodes verify the validity, as a response to acknowledge the validity of the ledger data, they store the record data in a temporary block. They can also send confirmation to the node that initiated the operation.
[0299] 2.3) Smart contracts are computerized protocols that can execute the terms of a contract. They are implemented through code deployed on a shared ledger that executes when certain conditions are met. Based on actual business needs, the code is used to complete automated transactions, such as querying the logistics status of goods purchased by a buyer and transferring the buyer's electronic money to the merchant's address after the buyer signs for the goods. Of course, smart contracts are not limited to executing contracts for transactions; they can also execute contracts for processing received information.
[0300] 3) A blockchain consists of a series of blocks that are sequentially generated. Once a new block is added to the blockchain, it will not be removed. The blocks contain the data submitted by the nodes in the blockchain system.
[0301] When the embodiments of this application are applied to a blockchain system, the air interface frame will be represented by a block. When a node in the blockchain system sends the recorded data to other nodes in the blockchain system, the node acts as the sender and the other nodes act as the receivers. The method for preventing eavesdropping when the sender and receiver interact can be specifically referred to the above embodiments, and will not be repeated in this application.
[0302] See Figure 13 , Figure 13 This is an optional schematic diagram of the block structure provided in this embodiment of the invention. Each block includes the hash value of the transaction records stored in this block (the hash value of this block) and the hash value of the previous block. The blocks are connected through their hash values to form a blockchain. Additionally, the block may include information such as a timestamp when it was generated. A blockchain is essentially a decentralized database, a chain of data blocks linked together using cryptographic methods. Each data block contains relevant information used to verify the validity of the information (anti-counterfeiting) and to generate the next block.
[0303] This application provides an electronic device comprising: a memory and a processor; at least one program stored in the memory, which, when executed by the processor, can, compared to the prior art, achieve the following: in response to a network access request initiated by a terminal, the network device obtains an initial air interface address included in the network access request, or assigns an initial air interface address generated according to the network access request to the terminal, so that both the network device and the terminal can obtain the initial air interface address; when the network device first unicasts an air interface frame between the terminal, the sending end of the air interface frame marks the air interface frame with the initial air interface address. This allows the receiving end of an air interface frame to verify the air interface frame using the air interface address and obtain the service data in the air interface frame. Since the initial air interface address is only known to the network device and the terminal, an eavesdropper cannot determine the identity of the receiving end of the air interface frame when it is transmitted for the first time. When the network device and the terminal transmit air interface frames non-first times via unicast, the sending end of the air interface frame generates an air interface address that changes with the number of unicast transmissions. This makes it impossible for an eavesdropper to determine the identity of the receiving end by tracking the fixed air interface addresses of multiple air interface frames. The embodiments of this application can effectively prevent eavesdroppers from eavesdropping on the identity of the sending end or the receiving end of the air interface frame.
[0304] In one alternative embodiment, an electronic device is provided, such as Figure 14 As shown, Figure 14 The illustrated electronic device 4000 includes a processor 4001 and a memory 4003. The processor 4001 and the memory 4003 are connected, for example, via a bus 4002. Optionally, the electronic device 4000 may also include a transceiver 4004. It should be noted that in practical applications, the transceiver 4004 is not limited to one type, and the structure of this electronic device 4000 does not constitute a limitation on the embodiments of this application.
[0305] Processor 4001 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 4001 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0306] Bus 4002 may include a pathway for transmitting information between the aforementioned components. Bus 4002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. Bus 4002 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 14 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0307] The memory 4003 may be ROM (Read Only Memory) or other types of static storage devices capable of storing static information and instructions, RAM (Random Access Memory) or other types of dynamic storage devices capable of storing information and instructions, or EEPROM (Electrically Erasable Programmable Read Only Memory), CD-ROM (Compact Disc Read Only Memory) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto.
[0308] The memory 4003 stores application code that executes the scheme of this application, and its execution is controlled by the processor 4001. The processor 4001 executes the application code stored in the memory 4003 to implement the content shown in the foregoing method embodiments.
[0309] This application provides a computer-readable storage medium storing a computer program that, when run on a computer, enables the computer to execute the corresponding content in the aforementioned method embodiments. Compared to existing technologies, this application addresses the issue by having network devices respond to network access requests initiated by terminals, obtaining the initial air interface address included in the request, or assigning an initial air interface address generated based on the request to the terminal. This ensures that both the network device and the terminal can obtain the initial air interface address. When the network device and the terminal unicast an air interface frame for the first time, the sending end of the air interface frame marks the frame with the initial air interface address, allowing the receiving end to verify the frame and obtain the service data within it. Since only the network device and the terminal know the initial air interface address, eavesdroppers cannot determine the identity of the receiving end of the air interface frame during the initial transmission. Furthermore, during subsequent unicast transmissions of air interface frames between the network device and the terminal, the sending end generates an air interface address that changes with the number of unicast transmissions, preventing eavesdroppers from identifying the receiving end by tracking the fixed air interface addresses of multiple air interface frames. This effectively prevents eavesdroppers from discovering the identity of the sending or receiving end of air interface frames.
[0310] This application provides a computer program that includes computer instructions stored in a computer-readable storage medium. When a processor of a computer device reads the computer instructions from the computer-readable storage medium, the processor executes the computer instructions, causing the computer device to perform the content shown in the foregoing method embodiments. Compared with existing technologies, this application's embodiment effectively prevents eavesdroppers from discovering the identity of the sender or receiver of air interface frames when a network device responds to a network access request initiated by a terminal, either by obtaining the initial air interface address included in the request or by assigning an initial air interface address generated based on the request to the terminal. This allows both the network device and the terminal to obtain the initial air interface address. When the network device and the terminal unicast an air interface frame for the first time, the sender marks the air interface frame with the initial air interface address, enabling the receiver to verify the frame and obtain the service data within it. Since only the network device and the terminal know the initial air interface address, an eavesdropper cannot determine the identity of the receiver during the initial air interface frame transmission. Furthermore, when the network device and the terminal unicast an air interface frame multiple times, the sender generates an air interface address that changes with the number of unicast transmissions, preventing an eavesdropper from determining the identity of the receiver by tracking the fixed air interface addresses of multiple air interface frames.
[0311] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0312] The above are only some embodiments of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A unicast transmission method based on air interface frames, characterized in that, include: The network device responds to the network access request initiated by the terminal, so that both the network device and the terminal obtain an initial air interface address; The sending end of the air interface frame generates an air interface address that changes with the number of unicast transmissions, marks the air interface frame according to the air interface address, and unicasts the marked air interface frame to the receiving end of the air interface frame. The receiving end of the air interface frame verifies the received air interface frame according to a preset verification method, and obtains the service data in the air interface frame after the verification is successful. In the first unicast transmission of the air interface frame, the air interface address in the first unicast transmission air interface frame is the initial air interface address, and the receiving end of the air interface frame uses the initial air interface address to verify the first unicast transmission air interface frame. When the sender of the air interface frame is the network device, the receiver of the air interface frame is the terminal; when the sender of the air interface frame is the terminal, the receiver of the air interface frame is the network device.
2. The unicast transmission method based on air interface frames according to claim 1, characterized in that, The network device and the terminal are in a mobile network; the network device is the sender of the air interface frame, and the terminal is the receiver of the air interface frame. The network device responds to a network access request initiated by the terminal, enabling both the network device and the terminal to obtain initial air interface addresses, including: In response to a network access request initiated by a terminal, the network device generates and sends the initial air interface address to the terminal.
3. The unicast transmission method based on air interface frames according to claim 2, characterized in that, In the scenario where the terminal sends uplink data to the network device, the sending end of the air interface frame generates an air interface address that varies with the number of unicast transmissions, and the process further includes: the terminal sending a channel resource allocation request to the network device. The transmitting end of the air interface frame generates an air interface address that varies with the number of unicast transmissions, marks the air interface frame according to the air interface address, and unicasts the marked air interface frame to the receiving end of the air interface frame, including: In response to the channel resource allocation request, the network device determines the number of unicast transmissions based on the cumulative number of channel resource allocation requests sent by the terminal. The network device generates an air interface address that varies with the number of unicast transmissions, marks downlink control information according to the air interface address, and transmits the downlink control information as an air interface frame via unicast to the terminal; the service data in the downlink control information includes channel resources used to indicate a designated channel for transmitting uplink data.
4. The unicast transmission method based on air interface frames according to claim 3, characterized in that, The receiving end of the air interface frame verifies the received air interface frame according to a preset verification method, and obtains the service data in the air interface frame after successful verification, and then further includes: The terminal determines the designated channel for transmitting uplink data based on the channel resources, and sends uplink data on the designated channel. The network device receives uplink data sent by the terminal on the designated channel.
5. The unicast transmission method based on air interface frames according to claim 2, characterized in that, In a scenario where a network device sends downlink data to the terminal, the step of marking the air interface frame according to the air interface address and unicasting the marked air interface frame to the receiving end of the air interface frame includes: According to the air interface address marking downlink control information, the downlink control information is transmitted to the terminal as an air interface frame via unicast. The service data of the downlink control information includes channel resources for indicating a designated channel for transmitting downlink data.
6. The unicast transmission method based on air interface frames according to claim 5, characterized in that, The receiving end of the air interface frame verifies the received air interface frame according to a preset verification method, and obtains the service data in the air interface frame after successful verification, and then further includes: The network device transmits downlink data on the designated channel; The terminal determines a designated channel for transmitting downlink data based on the channel resources, and receives downlink data sent by the network device on the designated channel.
7. The unicast transmission method based on air interface frames according to claim 3 or 5, characterized in that, The downlink control information includes: a sequence number field for storing sequence numbers, an air interface address field for storing air interface addresses, and a data field for storing service data; The step of marking the air interface frame according to the air interface address includes: The air interface address is stored in the air interface address field, the sequence number is obtained according to the number of unicast transmissions, the sequence number is stored in the sequence number field, the service data is stored in the data field, and the marked air interface frame is obtained.
8. The unicast transmission method based on air interface frames according to claim 1, characterized in that, The network device and the terminal are located in a wireless local area network, and the sender of the air interface frame is the terminal or the network device. The network device responds to a network access request initiated by the terminal, enabling both the network device and the terminal to obtain initial air interface addresses, including: The network device responds to the network access request initiated by the terminal and obtains the initial air interface address included in the network access request.
9. The unicast transmission method based on air interface frames according to claim 8, characterized in that, The air interface frame includes a data field for storing service data, a receiving MAC address field for storing the air interface address, and a sequence field for storing the sequence number. The air interface frame is marked according to the air interface address, including: The air interface address is stored in the MAC address field of the receiving end, the sequence number is obtained according to the number of unicast transmissions, the sequence number is stored in the sequence field, the service data is stored in the data field, and the marked air interface frame is obtained.
10. The unicast transmission method based on air interface frames according to claim 1, characterized in that, The sender of the air interface frame generates an air interface address that varies with the number of unicast transmissions, including: When transmitting an air interface frame in a non-first unicast transmission, the sending end of the air interface frame determines the sequence number based on the number of unicast transmissions with the receiving end, encrypts the sequence number according to a preset encryption method, and uses the encryption result as the air interface address.
11. The unicast transmission method based on air interface frames according to claim 10, characterized in that, The step of encrypting the serial number according to a preset encryption method and using the encryption result as an air interface address includes: The sending end uses the sequence number as plaintext and a preset session key as encryption key to generate the air interface address; The receiving end of the air interface frame verifies the air interface frame using a preset verification method, including: The receiving end uses the air interface address as ciphertext and a pre-determined session key as the decryption key to decrypt the ciphertext. If the obtained plaintext matches the sequence number in the air interface frame, the verification is successful; or The receiving end encrypts the sequence number using a pre-determined session key as the encryption key. If the obtained ciphertext is the same as the air interface address in the air interface frame, the verification is successful.
12. The unicast transmission method based on air interface frames according to claim 10, characterized in that, The step of encrypting the serial number according to a preset encryption method and using the encryption result as an air interface address includes: According to a preset hash algorithm, the sequence number and the preset session key are hashed, and the hash result is used as the air interface address. The receiving end of the air interface frame verifies the air interface frame using a preset verification method, including: The receiving end performs a hash operation on the sequence number and the preset session key according to a pre-acquired hash algorithm. If the hash operation result is the same as the air interface address in the air interface frame, the verification is successful.
13. The unicast transmission method based on air interface frames according to claim 10, characterized in that, The sending end of the air interface frame determines the sequence number based on the number of unicast transmissions with the receiving end, including: The sending end counts the cumulative number of air interface frames sent to the receiving end and obtains the counting result; If the sum of the counting result and the preset value is less than the preset threshold, then the sum of the counting result and the preset value shall be used as the sequence number; If the sum of the counting result and the preset value is not less than the preset threshold, then the counting result is restored to the initial value, and the initial value is used as the sequence number, wherein the initial value is less than the preset threshold.
14. A unicast transmission system based on air interface frames, characterized in that, Including network equipment and terminals; The terminal is used to initiate a network access request, and the network device is used to respond to the network access request initiated by the terminal, so that both the network device and the terminal obtain an initial air interface address. The sending end of the air interface frame generates an air interface address that changes with the number of unicast transmissions, marks the air interface frame according to the air interface address, and unicasts the marked air interface frame to the receiving end of the air interface frame, so that the receiving end of the air interface frame can verify the received air interface frame according to a preset verification method, and obtain the service data in the air interface frame after the verification is successful. In the first unicast transmission of the air interface frame, the air interface address in the first unicast transmission air interface frame is the initial air interface address, and the receiving end of the air interface frame uses the initial air interface address to verify the first unicast transmission air interface frame. When the sender of the air interface frame is the network device, the receiver of the air interface frame is the terminal; when the sender of the air interface frame is the terminal, the receiver of the air interface frame is the network device.
15. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the unicast transmission method based on air interface frames as described in any one of claims 1 to 13.
16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause the computer to perform the steps of the unicast transmission method based on air interface frames as described in any one of claims 1 to 13.