Method and device for transmitting system messages

By digitally signing and broadcasting system messages through network devices and combining them with public key verification of terminal devices, the security issue of system message modification in wireless communication systems is resolved, and the legitimacy verification of system messages and the accurate acquisition of characteristic parameters are achieved.

CN115442801BActive Publication Date: 2025-09-12HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202110619004.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-06-03
Publication Date
2025-09-12
Estimated Expiration
2041-06-03

AI Technical Summary

Technical Problem

In wireless communication systems, when initially accessing the network, terminal devices cannot identify the legitimacy of received system messages, which may result in them being modified by illegal network devices, posing a security risk.

Method used

The network device digitally signs the system message by obtaining characteristic parameters and private keys, and broadcasts the protected system message including the digital signature and timer parameters. The terminal device verifies the signature using the public key and characteristic parameters to ensure the legitimacy of the message.

Benefits of technology

This effectively prevents system messages of legitimate network devices from being modified by illegitimate network devices, thereby improving the security of system messages and the accuracy of terminal devices in obtaining characteristic parameters of network devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115442801B_ABST
    Figure CN115442801B_ABST
Patent Text Reader

Abstract

The present application provides a method and apparatus for transmitting system messages. The method includes: a network device obtaining characteristic parameters and its own corresponding private key, the private key and the characteristic parameters being used to digitally sign the system message, and the network device digitally signing the system message based on the private key, the characteristic parameters, and a first timer parameter; the network device broadcasting a protected system message, the protected system message including the system message, the digital signature, and information about the first timer parameter, wherein the characteristic parameters are inherent characteristic parameters of the network device, and the first timer parameter is a parameter of a first timer locally maintained by the network device. By digitally signing the system message, system messages sent by legitimate network devices are prevented from being modified by illegitimate network devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communications, and more particularly, to a method and apparatus for transmitting system messages. Background Art

[0002] In a wireless communication system, when a terminal device initially accesses the network, it obtains some basic information about the network device (for example, network information of the cell where the terminal device is located, information about the registration area, information about public channels, and information about other cells, etc.) through the system information (SI) broadcast by the network device, thereby completing the process of accessing the network device.

[0003] Since in the initial state, the network device does not know when the terminal device will access, and a security context cannot be established between the terminal device and the network device before the connection is established, the system messages sent by the network device cannot be encrypted and protected. There may be some security issues. For example, illegal network devices (or so-called fake base stations) may modify the system messages sent by legitimate network devices, and the terminal device cannot identify the legitimacy of the received system messages. Summary of the Invention

[0004] The present application provides a method for transmitting system messages, which can prevent system messages sent by legitimate network devices from being modified by illegal network devices.

[0005] In the first aspect, a method for transmitting system messages is provided. The method for transmitting system messages can be executed by a network device, or can also be executed by a chip or circuit provided in the network device. This application does not limit this. For the sake of ease of description, the following is an example of execution by a network device.

[0006] The method for transmitting a system message includes:

[0007] The network device obtains a characteristic parameter and a private key corresponding to the network device, and the private key and the characteristic parameter are used to digitally sign the system message; the network device digitally signs the system message based on the private key, the characteristic parameter and the first timer parameter; the network device broadcasts a protected system message, and the protected system message includes information about the system message, the digital signature and the first timer parameter, wherein the characteristic parameter is an inherent characteristic parameter of the network device, and the first timer parameter is a parameter of a first timer locally maintained by the network device.

[0008] According to the method for transmitting system messages provided in an embodiment of the present application, the network device digitally signs the system message to be sent based on its own inherent characteristic parameters, its own corresponding private key, and the parameters of the locally maintained first timer, thereby protecting the system message to be sent and preventing the system message sent by the legitimate network device from being modified by the illegal network device.

[0009] In combination with the first aspect, in certain implementations of the first aspect, the network device obtains the private key corresponding to the network device, including: the network device generates an identifier of the network device based on the characteristic parameter; the network device sends the identifier to a key generation center, and the identifier is used to generate the private key; the network device receives the private key from the key center.

[0010] In the method for transmitting system messages provided in an embodiment of the present application, the private key corresponding to the network device can be generated based on the identification of the network device, and the identification of the network device can be generated by the network device based on its own inherent characteristic parameters, so that the identification of the network device can be related to the inherent characteristic parameters of the network device itself, thereby avoiding the illegal network device from replaying the system messages of the legitimate network device in certain scenarios (for example, the inherent characteristics of the illegal network device and the legitimate network device are different) to attract terminal devices.

[0011] In combination with the first aspect, in certain implementations of the first aspect, the network device obtains characteristic parameters corresponding to the network device, including: the bottom-level processing unit of the network device determines the characteristic parameters; the bottom-level processing unit of the network device sends the characteristic parameters to the high-level processing unit of the network device, wherein the bottom-level layer of the network device includes at least one of a radio frequency device, a packet data convergence layer protocol PDCP layer, a radio link control RLC layer, a media access control MAC layer and a physical PHY layer, and the high-level layer of the network device includes a radio resource control RRC layer.

[0012] In the method for transmitting system messages provided in an embodiment of the present application, the characteristic parameters obtained by the network device can be the underlying parameters obtained by the underlying processing unit of the network device, and the underlying processing unit can be at least one of the radio frequency device, the packet data convergence layer protocol PDCP layer, the radio link control RLC layer, the media access control MAC layer and the physical PHY layer, thereby improving the flexibility of the solution.

[0013] In combination with the first aspect, in certain implementations of the first aspect, the protected system message also includes information about the characteristic parameter, and the information about the characteristic parameter is used to indicate the characteristic parameter.

[0014] The method for transmitting system messages provided in an embodiment of the present application can further include information for indicating characteristic parameters in the protected system messages broadcast by the network device, which can enable the terminal device to obtain the characteristic parameters of the network device through plain text transmission, thereby improving the accuracy of the terminal device in obtaining the characteristic parameters of the network device.

[0015] In combination with the first aspect, in certain implementations of the first aspect, the characteristic parameter includes at least one of the following: the frequency of the network device, the physical cell identifier PCI of the network device, the number of antennas of the network device, the control channel occupied symbol number CFI of the network device, or the radio frequency fingerprint of the network device.

[0016] The characteristic parameters of the above-mentioned network device may be the frequency of the network device, the physical cell identifier PCI of the network device, the number of antennas of the network device, the control channel occupied symbol number CFI of the network device or the radio frequency fingerprint of the network device, etc. There are many parameters that can be used as characteristic parameters of the network device, which improves the flexibility of the solution.

[0017] On the second aspect, a method for transmitting system messages is provided. The method for transmitting system messages can be executed by a terminal device, or can also be executed by a chip or circuit provided in the terminal device. This application does not limit this. For the sake of convenience of description, it can be illustrated by taking the execution by the terminal device as an example.

[0018] The method for transmitting a system message includes:

[0019] The terminal device obtains a public key and characteristic parameters of the network device, where the public key and the characteristic parameters are used to verify the digital signature of the system message; the terminal device receives a protected system message from the network device, where the protected system message includes information about the system message, the digital signature, and a first timer parameter; the terminal device verifies the digital signature based on the public key, the characteristic parameters, and a second timer parameter, where the characteristic parameter is an inherent characteristic parameter of the network device, the first timer parameter is a parameter of a first timer locally maintained by the network device, and the second timer parameter is a parameter of a second timer locally maintained by the terminal device.

[0020] According to the method for transmitting system messages provided in an embodiment of the present application, the system message received by the terminal device is a system message protected by the network device based on its own inherent characteristic parameters, its own corresponding private key and the parameters of the locally maintained first timer, thereby preventing the system message sent by the legitimate network device from being modified by the illegal network device.

[0021] In combination with the second aspect, in certain implementations of the second aspect, the terminal device obtains the characteristic parameters of the network device, including: the bottom-level processing unit of the terminal device obtains the characteristic parameters through blind detection; the bottom-level processing unit of the terminal device sends the characteristic parameters to the high-level processing unit of the terminal device, wherein the bottom level of the terminal device includes at least one of a radio frequency device, a packet data convergence layer protocol layer PDCP, a radio link control layer RLC, a media access control layer MAC and a physical layer PHY, and the high-level layer of the terminal device includes a radio resource control layer RRC.

[0022] In combination with the second aspect, in certain implementations of the second aspect, the protected system message also includes information about the characteristic parameter, and the information about the characteristic parameter is used to indicate the characteristic parameter.

[0023] The method for transmitting system messages provided in an embodiment of the present application can further include information for indicating characteristic parameters in the protected system messages broadcast by the network device, which can enable the terminal device to obtain the characteristic parameters of the network device through plain text transmission, thereby improving the accuracy of the terminal device in obtaining the characteristic parameters of the network device.

[0024] In combination with the second aspect, in certain implementations of the second aspect, the characteristic parameter includes at least one of the following: the frequency of the network device, the physical cell identifier PCI of the network device, the number of antennas of the network device, the control channel occupied symbol number CFI of the network device, or the radio frequency fingerprint of the network device.

[0025] The characteristic parameters of the above-mentioned network device may be the frequency of the network device, the physical cell identifier PCI of the network device, the number of antennas of the network device, the control channel occupied symbol number CFI of the network device or the radio frequency fingerprint of the network device, etc. There are many parameters that can be used as characteristic parameters of the network device, which improves the flexibility of the solution.

[0026] In a third aspect, a device for transmitting system messages is provided, wherein the device for transmitting system messages includes a processor for implementing the functions of the network device in the method described in the first aspect.

[0027] Optionally, the apparatus for transmitting a system message may further include a memory, wherein the memory is coupled to the processor, and the processor is configured to implement the function of the network device in the method described in the first aspect.

[0028] In one possible implementation, the memory is used to store program instructions and data. The memory is coupled to the processor, and the processor can call and execute the program instructions stored in the memory to implement the functions of the network device in the method described in the first aspect above. Optionally, the device for transmitting system messages may further include a communication interface, which is used for the device for transmitting system messages to communicate with other devices. When the device for transmitting system messages is a network device, the communication interface is a transceiver, an input / output interface, or a circuit.

[0029] In one possible design, the apparatus for transmitting a system message includes: a processor and a communication interface, configured to implement the functions of the network device in the method described in the first aspect above, specifically including:

[0030] The processor communicates with the outside world using the communication interface;

[0031] The processor is configured to run a computer program so that the device implements any one of the methods described in the first aspect above.

[0032] It can be understood that the external object may be an object other than the processor, or an object other than the device.

[0033] In another possible design, the device for transmitting system messages is a chip or a chip system. The communication interface may be an input / output interface, an interface circuit, an output circuit, an input circuit, a pin, or related circuits on the chip or chip system. The processor may also be embodied as a processing circuit or a logic circuit.

[0034] In a fourth aspect, a device for transmitting system messages is provided, wherein the device for transmitting system messages includes a processor for implementing the functions of the terminal device in the method described in the second aspect.

[0035] Optionally, the apparatus for transmitting a system message may further include a memory, the memory being coupled to the processor, and the processor being configured to implement the functions of the terminal device in the method described in the second aspect above.

[0036] In one possible implementation, the memory is used to store program instructions and data. The memory is coupled to the processor, and the processor can call and execute the program instructions stored in the memory to implement the functions of the terminal device in the method described in the second aspect above.

[0037] Optionally, the apparatus for transmitting system messages may further include a communication interface, wherein the communication interface is used for the apparatus for transmitting system messages to communicate with other devices. When the apparatus for transmitting system messages is a terminal device, the transceiver may be a communication interface, or an input / output interface.

[0038] In one possible design, the apparatus for transmitting a system message includes: a processor and a communication interface, configured to implement the functions of the terminal device in the method described in the second aspect above, specifically including:

[0039] The processor communicates with the outside world using the communication interface;

[0040] The processor is used to run a computer program so that the device implements any one of the methods described in the second aspect above.

[0041] It can be understood that the external object may be an object other than the processor, or an object other than the device.

[0042] In another implementation, when the device for transmitting the system message is a chip or a chip system, the communication interface may be an input / output interface, an interface circuit, an output circuit, an input circuit, a pin, or a related circuit on the chip or the chip system. The processor may also be embodied as a processing circuit or a logic circuit.

[0043] In a fifth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a communication device, the communication device implements the method in the first aspect and any possible implementation manner of the first aspect.

[0044] In a sixth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a communication device, the communication device implements the method in the second aspect and any possible implementation manner of the second aspect.

[0045] In a seventh aspect, a computer program product comprising instructions is provided, wherein when the instructions are executed by a computer, a communication device implements the method in the first aspect and any possible implementation manner of the first aspect.

[0046] In an eighth aspect, a computer program product comprising instructions is provided, wherein when the instructions are executed by a computer, a communication device implements the method in the second aspect and any possible implementation manner of the second aspect.

[0047] In a ninth aspect, a communication system is provided, comprising the apparatus for transmitting system messages shown in the third aspect and the apparatus for transmitting system messages shown in the fourth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 1 is a schematic diagram of a communication system 100 applicable to the method for transmitting system messages according to an embodiment of the present application.

[0049] Figure 2 This is a schematic block diagram of a system message provided in an embodiment of the present application.

[0050] Figure 3 This is a schematic flowchart of a method for transmitting system messages provided in an embodiment of the present application.

[0051] Figure 4 (a) and (b) are schematic block diagrams of another system message provided in an embodiment of the present application.

[0052] Figure 5 Schematic diagram of an apparatus 500 for transmitting system messages proposed in this application.

[0053] Figure 6 It is a structural diagram of a terminal device 600 applicable to an embodiment of the present application.

[0054] Figure 7 7 is a schematic diagram of an apparatus 700 for transmitting system messages proposed in this application.

[0055] Figure 8 It is a structural diagram of a network device 800 applicable to an embodiment of the present application. DETAILED DESCRIPTION

[0056] The technical solution in this application will be described below with reference to the accompanying drawings.

[0057] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD) system, world-wide interoperability for microwave access (WiMAX) communication system, fifth generation (5G) system, new radio (NR) or future network, etc. The 5G mobile communication system described in this application includes a non-standalone (NSA) 5G mobile communication system or a standalone (SA) 5G mobile communication system. The technical solutions provided in this application can also be applied to future communication systems, such as the sixth generation mobile communication system. The communication system can also be a public land mobile network (PLMN) network, a device-to-device (D2D) communication system, a machine-to-machine (M2M) communication system, an Internet of Things (IoT) communication system or other communication systems.

[0058] The terminal equipment in the embodiments of the present application may refer to an access terminal, a user unit, a user station, a mobile station, a mobile station, a relay station, a remote station, a remote terminal, a mobile device, a user terminal, a user equipment (UE), a terminal, a wireless communication device, a user agent, or a user device. The terminal equipment may also be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication capabilities, a computing device or other processing device connected to a wireless modem, an in-vehicle device, a wearable device, a terminal device in a 5G network, a terminal device in a future evolved public land mobile network (PLMN), or a terminal device in a future Internet of Vehicles, etc., and the embodiments of the present application are not limited thereto.

[0059] As an example and not a limitation, in the embodiments of the present application, wearable devices may also be referred to as wearable smart devices, which are a general term for wearable devices that are intelligently designed and developed using wearable technology for daily wear, such as glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothes or accessories. Wearable devices are not just hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are fully functional, large in size, and can achieve complete or partial functions without relying on smartphones, such as smart watches or smart glasses, as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.

[0060] Furthermore, in the embodiments of the present application, the terminal device may also be a terminal device in an IoT system. IoT is an important component of the future development of information technology. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network that interconnects humans and machines and things. In the embodiments of the present application, IoT technology can achieve massive connections, deep coverage, and terminal power saving through, for example, narrowband (NB) technology.

[0061] In addition, in an embodiment of the present application, the terminal device may also include sensors such as smart printers, train detectors, and gas stations. Its main functions include collecting data (part of the terminal device), receiving control information and downlink data from the network device, and sending electromagnetic waves to transmit uplink data to the network device.

[0062] The network device in the embodiment of the present application can be any communication device with wireless transceiver functions for communicating with a terminal device. The device includes but is not limited to: an evolved Node B (eNB), a radio network controller (RNC), a Node B (NB), a home evolved Node B (HeNB, or home Node B, HNB), a baseband unit (BBU), an access point (AP) in a wireless fidelity (WIFI) system, a wireless relay node, a wireless backhaul node, a transmission point (TP) or a transmission and reception point (TRP), etc., and can also be a 5G system, such as a gNB in ​​an NR system, or a transmission point (TRP or TP), one or a group of antenna panels (including multiple antenna panels) of a base station in a 5G system, or a network node constituting a gNB or a transmission point, such as a baseband unit (BBU) or a distributed unit (DU), etc.

[0063] In some deployments, the network device in the embodiments of the present application may refer to a centralized unit (CU) or a distributed unit (DU), or the network device may include both a CU and a DU. The gNB may also include an active antenna unit (AAU). The CU implements some gNB functions, while the DU implements some gNB functions. For example, the CU is responsible for processing non-real-time protocols and services, implementing the functions of the radio resource control (RRC) layer and the packet data convergence protocol (PDCP) layer. The DU is responsible for processing physical layer protocols and real-time services, implementing the functions of the radio link control (RLC) layer, the media access control (MAC) layer, and the physical (PHY) layer. The AAU implements some physical layer processing functions, RF processing, and active antenna-related functions. Because RRC layer information ultimately becomes PHY layer information, or is converted from PHY layer information, in this architecture, higher-layer signaling, such as RRC layer signaling, can also be considered to be sent by the DU, or by both the DU and the AAU. It is understood that the network device may include one or more of a CU node, a DU node, and an AAU node. In addition, the CU may be classified as a network device in an access network (RAN) or a network device in a core network (CN), which is not limited in this application.

[0064] Furthermore, the CU can be divided into a control plane central unit (CU-CP) and a user plane central unit (CU-UP). The CU-CP and CU-UP can also be deployed on different physical devices. The CU-CP is responsible for control plane functions, primarily including the RRC layer and the PDCP-C layer. The PDCP-C layer is primarily responsible for encryption and decryption, integrity protection, and data transmission of control plane data. The CU-UP is responsible for user plane functions, primarily including the SDAP layer and the PDCP-U layer. The SDAP layer is primarily responsible for processing core network data and mapping flows to bearers. The PDCP-U layer is primarily responsible for at least one function in the data plane, including encryption and decryption, integrity protection, header compression, sequence number maintenance, and data transmission. Specifically, the CU-CP and CU-UP are connected via a communication interface (e.g., the E1 interface). The CU-CP, representing a network device, connects to the core network device via a communication interface (e.g., the Ng interface) and connects to the DU via a communication interface (e.g., the F1-C (control plane) interface). The CU-UP connects to the DU via a communication interface (e.g., the F1-U (user plane) interface).

[0065] There is another possible implementation in which the PDCP-C layer is also included in the CU-UP.

[0066] It is understandable that the above protocol layer divisions of CU and DU, and CU-CP and CU-UP are merely examples, and there may be other division methods, which are not limited in the embodiments of the present application.

[0067] The network device mentioned in the embodiments of the present application may be a device including a CU, or a DU, or a device including a CU and a DU, or a device including a control plane CU node (CU-CP node) and a user plane CU node (CU-UP node) and a DU node.

[0068] The network equipment and terminal devices can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; they can also be deployed in the air on aircraft, balloons, and satellites. The embodiments of this application do not limit the scenarios in which the network equipment and terminal devices are located.

[0069] In the embodiments of the present application, a terminal device or network device includes a hardware layer, an operating system layer running on top of the hardware layer, and an application layer running on the operating system layer. The hardware layer includes hardware such as a central processing unit (CPU), a memory management unit (MMU), and memory (also known as main memory). The operating system can be any one or more computer operating systems that implement business processing through processes, such as the Linux operating system, Unix operating system, Android operating system, iOS operating system, or Windows operating system. The application layer includes applications such as browsers, address books, word processing software, and instant messaging software.

[0070] In addition, various aspects or features of the present application can be implemented as methods, apparatus, or articles of manufacture using standard programming and / or engineering techniques. The term "article of manufacture" as used in this application encompasses a computer program that can be accessed from any computer-readable device, carrier, or medium. For example, computer-readable media may include, but are not limited to: magnetic storage devices (e.g., hard disks, floppy disks, or magnetic tapes, etc.), optical disks (e.g., compact discs (CDs), digital versatile discs (DVDs), etc.), smart cards, and flash memory devices (e.g., erasable programmable read-only memories (EPROMs), cards, sticks, or key drives, etc.). In addition, the various storage media described herein may represent one or more devices and / or other machine-readable media for storing information. The term "machine-readable storage medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.

[0071] To facilitate understanding of the embodiments of the present application, first Figure 1 The communication system shown in FIG. 1 is used as an example to describe in detail a communication system applicable to an embodiment of the present application. Figure 1 1 is a schematic diagram of a communication system 100 applicable to a method for transmitting system messages according to an embodiment of the present application. Figure 1 As shown, the communication system 100 may include at least one network device, such as Figure 1 The network device 110 shown; the communication system 100 may also include at least one terminal device, such as Figure 1The terminal device 120 shown in FIG. Network device 110 and terminal device 120 can communicate via a wireless link. Each communication device, such as network device 110 or terminal device 120, can be configured with multiple antennas. For each communication device in the communication system 100, the configured multiple antennas may include at least one transmit antenna for sending signals and at least one receive antenna for receiving signals. Therefore, communication devices in the communication system 100, such as network device 110 and terminal device 120, can communicate using multi-antenna technology.

[0072] It should be understood that Figure 1 This is a simplified schematic diagram for ease of understanding only. The communication system 100 may also include other network devices or other terminal devices. Figure 1 Not drawn in.

[0073] To facilitate understanding of the embodiments of the present application, several basic concepts involved in the embodiments of the present application are briefly explained. It should be understood that the basic concepts introduced below are briefly explained using the basic concepts specified in the NR protocol as an example, but the embodiments of the present application are not limited to being applicable only to NR systems. Therefore, the standard names that appear when describing the NR system as an example are all functional descriptions, and the specific names are not limited. They only indicate the functions of the device and can be extended to other systems accordingly, such as 2G, 3G, 4G or future communication systems.

[0074] 1. System message.

[0075] It can refer to a message sent by a network device to a terminal device in a cell in a wireless communication system. The message may include cell-level information of the cell and is valid for all terminal devices in the cell. Generally, the network device can send system messages in a broadcast manner. Alternatively, it can refer to a message sent by a scheduling group head on a sidelink resource to a terminal device served by the scheduling group head. The message may include information about a certain area served by the scheduling group head. In this case, for the terminal devices in the scheduling group, the function of the scheduling group head is similar to that of the network device. Generally, the scheduling group head can send system messages in a broadcast manner.

[0076] For example, a system message may include a master information block (MIB) and at least one system information block (SIB). SIB1 includes the information required for a terminal device to access a cell and scheduling information for other SIBs. Typically, when receiving a system message, a terminal device may first receive the MIB, then SIB1, and then other information in the system message (such as SIB2 and SIB3).

[0077] It should be understood that the system messages involved in the embodiments of the present application can be understood as broadcast messages without encryption protection sent by network devices, including but not limited to the above-mentioned MIB and SIB (such as SIB1, SIB2, SIB3, etc.), such as paging messages.

[0078] 2. Identity-based signature.

[0079] Identity-based signature technology is a type of asymmetric encryption. The key involved in this asymmetric encryption technology consists of two parts: an identity-based public key and a private key. However, unlike traditional public keys, the basic characteristic of an identity-based public key is a meaningful string of numbers or characters, such as a phone number or email address. In traditional public key systems, the private key is generally generated by the user or device, and the public key is signed by a digital certificate authority (CA) system to form a certificate. In identity-based signature systems, the traditional CA is replaced by a key generation center (PKG). The key center generates global public and private keys. When a user needs to generate an identity-based key, they provide their identity to the key center. The key center generates a private key for the user based on their identity and the global public or private key. The key center then sends the identity, global public key, and private key to the user. The user can then use the private key to sign or decrypt.

[0080] 3. Carrier frequency number (E-UTRA absolute radio frequency channel number, EARFCN).

[0081] To uniquely identify the frequency range of an LTE or NR system, frequency band and channel bandwidth alone are insufficient. For example, China Mobile's frequency band 40 covers a 50 MHz frequency range, while the maximum LTE channel bandwidth is 20 MHz. Therefore, it's impossible to define the specific location of the 20 MHz within this 50 MHz range. This requires the introduction of a new parameter: the center carrier frequency (Fc), also known as the carrier frequency. The carrier frequency number is used to identify the carrier frequency, and there is a one-to-one correspondence between the carrier frequency number and the carrier frequency, allowing for conversion between the two.

[0082] 4. Physical cell identifier (PCI)

[0083] In LTE, terminal devices use the PCI to distinguish wireless signals from different cells. In the physical layer, this is typically referred to as a cell group identifier (Cell ID). Terminal devices obtain the Cell ID by blindly detecting the primary synchronization signal (PSS) and / or secondary synchronization signal (SSS).

[0084] 5. Control format indicator (CFI)

[0085] The information carried by the physical control format indicator channel (PCFICH) in LTE can be specifically described in the current protocol (eg, Table 6.7-1 in 36.211), which will not be described in detail in this application.

[0086] 6. Replay attacks.

[0087] Also known as a replay attack or playback attack, a replay attack occurs when an attacker sends a packet that has already been received by the destination host in order to deceive the system. This attack is primarily used during the authentication process to compromise the authentication process. A replay attack can be carried out by the attacker or by an adversary who intercepts and retransmits the data. The attacker steals the authentication credentials through network eavesdropping or other means and then resends them to the authentication server. Replay attacks can occur during any network communication process and are a common attack method used by computer hackers.

[0088] 7. Digital signature.

[0089] A public-key digital signature, also known as a public-key digital signature, is a string of numbers generated by the sender of a message that effectively verifies the authenticity of the message. A digital signature is similar to a physical signature on paper, but is implemented using public-key cryptography techniques. It is a method used to authenticate digital information. A digital signature typically defines two complementary operations: one for signing and the other for verification. Digital signatures are the application of asymmetric key cryptography and digital digest technology.

[0090] In addition, in order to facilitate understanding of the embodiments of the present application, the following explanations are made.

[0091] First, in this application, "used to indicate" can include being used for direct indication and being used for indirect indication. When describing that a certain indication information is used to indicate A, it can include that the indication information directly indicates A or indirectly indicates A, but it does not mean that the indication information must include A.

[0092] The information indicated by the indication information is referred to as the information to be indicated. In specific implementations, there are various ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be indicated directly, such as the information to be indicated itself or an index of the information to be indicated. The information to be indicated can also be indicated indirectly by indicating other information, where the other information is associated with the information to be indicated. Alternatively, only a portion of the information to be indicated can be indicated, while the rest of the information to be indicated is known or agreed upon in advance.

[0093] In addition, the specific indication method can also be various existing indication methods, such as but not limited to the above-mentioned indication methods and various combinations thereof. The specific details of the various indication methods can be referred to the prior art and will not be repeated herein. As can be seen from the above, for example, when it is necessary to indicate multiple information of the same type, there may be a situation where the indication methods for different information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiment of the present application does not limit the selected indication method. In this way, the indication method involved in the embodiment of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0094] In addition, the information to be indicated may exist in other equivalent forms. For example, a row vector can be expressed as a column vector, a matrix can be represented by its transposed matrix, a matrix can be expressed as a vector or array, and the vector or array can be formed by connecting the row vectors or column vectors of the matrix, etc. The technical solutions provided in the embodiments of this application should be understood to cover various forms. For example, some or all of the features involved in the embodiments of this application should be understood to cover various forms of such features.

[0095] The information to be indicated can be sent as a whole, or divided into multiple sub-information and sent separately, and the sending period and / or sending timing of these sub-information can be the same or different. The specific sending method is not limited in this application. The sending period and / or sending timing of these sub-information can be predefined, for example, predefined according to a protocol, or configured by the transmitting device by sending configuration information to the receiving device. The configuration information can include, for example, but not limited to, one or a combination of at least two of radio resource control signaling, media access control (MAC) layer signaling, and physical layer signaling. The radio resource control signaling includes, for example, radio resource control (RRC) signaling; the MAC layer signaling includes, for example, a MAC control element (CE); and the physical layer signaling includes, for example, downlink control information (DCI).

[0096] Second, the first, second, and various numerical numbers (e.g., "#1," "#2") in this application are merely distinctions for ease of description and are not intended to limit the scope of the embodiments of this application. For example, to distinguish between different network devices.

[0097] Third, in this application, "pre-set" may include indications by network device signaling or pre-defined, such as protocol definitions. "Pre-defined" may be implemented by pre-storing corresponding codes, tables, or other methods that can be used to indicate relevant information in devices (e.g., including terminal devices and network devices). This application does not limit the specific implementation method.

[0098] Fourth, the term "storage" used in the embodiments of this application may refer to storage in one or more memories. The one or more memories may be provided separately or integrated into an encoder or decoder, a processor, or a communication device. The one or more memories may also be provided in part separately and in part integrated into a decoder, a processor, or a communication device. The memory may be any type of storage medium, and this application is not limited thereto.

[0099] Fifth, the "protocol" involved in the embodiments of the present application may refer to a standard protocol in the communication field, for example, it may include an LTE protocol, an NR protocol, and related protocols used in future communication systems. This application does not limit this.

[0100] Combined with the above Figure 1The application scenarios of the method for transmitting system messages provided in the embodiments of the present application are briefly introduced, as well as the basic concepts that may be involved in the embodiments of the present application. The method for transmitting system messages provided in the embodiments of the present application will be described in detail with reference to the accompanying drawings.

[0101] It should be understood that the method for transmitting system messages provided in the embodiments of the present application can be applied to systems communicating via multi-antenna technology, for example, Figure 1 The communication system 100 shown in FIG. The communication system may include at least one network device and at least one terminal device. The network device and the terminal device may communicate with each other via a multi-antenna technology.

[0102] It should also be understood that the embodiments shown below do not specifically limit the specific structure of the execution subject of the method provided in the embodiments of the present application. As long as it is possible to communicate according to the method provided in the embodiments of the present application by running a program that records the code of the method provided in the embodiments of the present application, for example, the execution subject of the method provided in the embodiments of the present application can be a terminal device or a network device, or a functional module in the terminal device or the network device that can call and execute the program.

[0103] Below, without loss of generality, the method for transmitting system messages provided in an embodiment of the present application is described in detail by taking the interaction between a network device and a terminal device as an example.

[0104] exist Figure 1 In the illustrated system architecture, network devices can use system messages to notify terminal devices within their coverage area of ​​various network-related information. Because system messages currently lack any security protection, terminal devices cannot verify the legitimacy of received system messages. To ensure that terminal devices can verify the legitimacy of system messages, a key mechanism can be considered to provide integrity protection for system messages, such as an asymmetric key mechanism.

[0105] A method for transmitting a system message includes:

[0106] Step 1: PKG generates a public key, which is notified to the terminal device through pre-configuration or other methods.

[0107] Step 2: PKG generates a private key for each network device, which is used by the network device to digitally sign system messages.

[0108] Step 3: To prevent replay attacks, a timer (TimeCounter) parameter needs to be entered when generating the digital signature. The Time Counter parameter can be included as part of the system message and protected by the digital signature.

[0109] For example, in order to save overhead, multiple system messages may be digitally signed together.

[0110] For example, the protected system message generated by the network device is as follows: Figure 2 As shown, Figure 2 This is a schematic block diagram of a system message provided in an embodiment of the present application.

[0111] from Figure 2 As can be seen from the figure, the protected system message includes the system message (system information), the digital signature (digital signature) and the least signification bits of the Time Counter parameter (least signification bits of Time Counter, LSBs of Time Counter). The LSBs of Time Counter can be understood as the information of the timer parameter, which is used to indicate the timer parameter.

[0112] The system message is a system message to be sent; the digital signature is generated by using a security algorithm using the system message to be sent, the private key of the network device, and the Time Counter parameter; and the LSBs of Time Counter are used to identify the Time Counter parameter.

[0113] It should be understood that the embodiments of the present application do not limit how to generate a digital signature, and reference may be made to the description of current digital signature technologies.

[0114] Step 4: After receiving the system message, the terminal device uses the public key to verify the signature of the system message to confirm the legitimacy of the received message.

[0115] Another method of transmitting system messages includes:

[0116] Step 1: PKG generates a pair of keys: a public key generated by a private key generator (PKPKG) and a security key generated by a private key generator (SKPKG). SKPKG is stored in the PKG and pre-configured to the terminal device. PKG generates an SK for each network device based on the device ID and SKPKG.

[0117] Step 2: Each network device has a global ID, which is public and global. The ID is associated with the SK. Any changes to the ID must be verified by the PKG, which issues a new ID and corresponding SK.

[0118] Step 3: Each network device sends a request message to PKG, requesting PKG to generate an SK for it.

[0119] For example, network device #1 sends a request message #1 to PKG, requesting PKG to generate SK#1 for network device #1, and the request message #1 carries the identification ID#1 of network device #1; network device #2 sends a request message #2 to PKG, requesting PKG to generate SK#2 for network device #2, and the request message #2 carries the identification ID#2 of network device #2.

[0120] Step 4: When each network device needs to broadcast a system message, it uses SK to digitally sign the system message.

[0121] For example, when network device #1 needs to broadcast system message #1, SK#1 is used to digitally sign system message #1; when network device #2 needs to broadcast system message #2, SK#2 is used to digitally sign system message #2.

[0122] Step 5: The terminal device uses PKPKG and ID to verify the system message.

[0123] For example, a terminal device uses PKPKG and ID #1 to verify System Message #1 from Network Device #1. If the terminal device has the PKPKG stored locally and the verification succeeds, the terminal device treats System Message #1 as authentic. If the terminal device has the PKPKG stored locally and the verification fails, the terminal device discards System Message #1. If the terminal device does not have the PKPKG stored locally, the terminal device determines how to handle System Message #1 based on local policies.

[0124] As can be seen from the above, the ID of the network device in this method of transmitting system messages is global and public, and the terminal device obtains the ID in plain text. In some scenarios, it is still impossible to prevent illegal network devices from modifying the system messages broadcast by legitimate network devices. For example, in the following scenario:

[0125] Scenario 1: Although the PCI value of an illegal network device is different from that of a legitimate network device, the illegal device can forge a neighbor relationship and replay the system messages of the legitimate network device to attract the terminal device.

[0126] Scenario 2: The illegal network device selects a high-priority frequency and replays the system messages of the legitimate network device, making it easier for the terminal device to attract the illegal network device;

[0127] Scenario 3: Although the number of antennas on an illegal network device is different from that on a legitimate network device, the illegal device can still deceive the terminal device.

[0128] It should be understood that Scenarios 1 to 3 above are merely examples of how an unauthorized network device can modify system messages broadcast by authorized network devices, and do not limit the scope of protection of this application. Other possible scenarios exist, such as when the CFI value of an unauthorized network device differs from that of an authorized network device. Examples are not provided here.

[0129] The present application also provides a method for transmitting system messages, which uses certain characteristic parameters of the network device (such as the frequency, PCI, number of transmitting antennas, CFI value, radio frequency fingerprint and other characteristic parameters of the network device) as input parameters for verifying the system message, thereby preventing the system messages broadcast by legitimate network devices from being modified by illegal network devices.

[0130] Figure 3 This is a schematic flowchart of a method for transmitting system messages provided in an embodiment of the present application.

[0131] The method for transmitting system messages comprises the following steps:

[0132] S310: The key generation center generates a public key.

[0133] In the embodiments of the present application, there is no limitation on how the key generation center generates the public key. You can refer to the description in the current related technology and will not go into details here.

[0134] After the public key is generated, it needs to be notified to the terminal device. Figure 3 The method flow shown also includes:

[0135] S311, the terminal device obtains the public key.

[0136] Specifically, the public key is notified to the terminal device through pre-configuration or other methods.

[0137] In the embodiment of the present application, there is no limitation on how the public key is notified to the terminal device. You can refer to the description in the current related technology and will not go into details here.

[0138] S320: The key generation center generates a private key for each network device.

[0139] For ease of description, a network device is used as an example for illustration below. The private key of the network device is used by the network device to digitally sign the system message to be broadcast.

[0140] As a possible implementation manner, the key generation center may generate a private key for the network device by: the key generation center generates the corresponding private key based on the global public identification of the network device.

[0141] As another possible implementation manner, the key generation center may generate a private key for the network device by: the key generation center generates the corresponding private key based on the inherent identifier of the network device.

[0142] As another possible implementation, the key generation center generates a private key for each network device. The key generation center generates the corresponding private key based on the identifier reported by the network device, wherein the identifier reported by the network device is generated by the network device based on its own inherent characteristic parameters. In this implementation, Figure 3 The method flow shown also includes:

[0143] S321: The network device generates an identifier of the network device based on the characteristic parameters.

[0144] The characteristic parameters are inherent characteristic parameters of the network device, such as those extracted and quantified from the PDCP layer, RLC layer, MAC layer, PHY layer, and some unique characteristic parameters of the radio frequency device. For example, the characteristic parameters may be frequency, PCI, number of antennas of the network device, CFI value, radio frequency fingerprint, and other characteristic parameters.

[0145] It should be understood that the above-mentioned frequency, PCI, number of antennas of the network device, CFI value, radio frequency fingerprint, etc. in the embodiments of the present application are merely examples and do not constitute any limitation on the scope of protection of the present application. The characteristic parameters can also be other inherent underlying parameters of the network device, which are not illustrated one by one here.

[0146] The network device generates an identification of the network device based on the characteristic parameters, specifically including: the bottom processing unit of the network device (such as the processing unit of the PDCP layer of the network device, the processing unit of the RLC layer, the processing unit of the MAC layer, the processing unit of the PHY layer and the processing unit of the radio frequency device) sends the quantifiable characteristic parameters of the network device to the processing unit of the RRC layer or other high-level processing units of the network device.

[0147] Furthermore, the processing unit of the RRC layer or other high-level processing units of the network device performs certain operations on the characteristic parameters to obtain an identifier of the network device.

[0148] Exemplarily, the network device generates an identifier of the network device based on the characteristic parameter, which may be: the network device uses a certain characteristic parameter as the identifier of the network device, for example, the identifier of the network device is a CFI value of the network device;

[0149] Exemplarily, the network device generates an identification of the network device based on the characteristic parameters by: the network device uses a structure combining several characteristic parameters as the identification of the network device.

[0150] It should be understood that the embodiments of the present application do not limit how the network device generates an identifier of the network device based on the characteristic parameters, and the generated identifier of the network device can be associated with the characteristic parameters.

[0151] Furthermore, the network device sends the generated network device identification to the key generation center. Figure 3 The method flow shown also includes:

[0152] S322: The network device sends an identifier of the network device to the key generation center.

[0153] In the embodiment of the present application, there is no limitation on how the network device sends the identifier of the network device to the key generation center, and reference may be made to the current information transmission method between the network device and the key generation center.

[0154] Specifically, after receiving the identifier sent by the network device, the key generation center can generate a private key corresponding to the network device based on the identifier.

[0155] Furthermore, the key generation center sends the generated private key to the network device. Figure 3 The method flow shown also includes:

[0156] S330: The key generation center sends the private key to the network device, or the network device obtains the private key.

[0157] As a possible implementation method, after the private key corresponding to the network device is generated by the key generation center in the embodiment of the present application, it is sent to the high-level processing unit of the network device (such as the processing unit of the RRC layer, or the processing unit of other layers above the RRC layer).

[0158] Exemplarily, the key generation center is integrated with the network device, and the key generation center sending the private key to the network device can be understood as: the key generation center in the network device sends the private key to a high-level processing unit of the network device;

[0159] Exemplarily, the key generation center is an independent functional entity, and the key generation center sending the private key to the network device can be understood as: the independent functional entity sending the private key to a high-level processing unit of the network device.

[0160] In the embodiments of the present application, there is no limitation on the setting of the key generation center. It can be integrated with the network device, or integrated with other devices, or can be set up independently.

[0161] Before broadcasting system messages, in order to prevent the system messages sent by legitimate network devices from being modified by illegal network devices, the system messages need to be protected. Figure 3 The method flow shown also includes:

[0162] S340: The network device digitally signs the system message.

[0163] Specifically, the network device digitally signs the system message based on the private key, the characteristic parameter, and the first timer parameter.

[0164] Among them, the network device can obtain the private key for digitally signing the system message to be broadcast from the key generation center; the network device can obtain the characteristic parameters for digitally signing the system message to be broadcast from the underlying processing unit; and the network device can determine the first timer parameter for digitally signing the system message to be broadcast based on the first timer maintained locally.

[0165] Specifically, digitally signing the system message based on the private key, characteristic parameters and first timer parameters can be: taking the private key, characteristic parameters, first timer parameters and system message as inputs of the security algorithm, generating a digital signature after processing by the security algorithm, and the digital signature is used to protect the authenticity of the system message.

[0166] Furthermore, network devices can broadcast protected system messages. Figure 3 The method flow shown may also include:

[0167] S350: The network device broadcasts a protected system message.

[0168] Specifically, the protected system message at least includes system information, a digital signature, and information about first timer parameters (least signification bits of Time Counter #1, LSBs of Time Counter #1).

[0169] The system message is information that the network device needs to broadcast (eg, broadcast messages such as MIB, SIB, or paging messages); and the digital signature is the digital signature generated in the above step S340.

[0170] In addition, to prevent replay attacks, the first timer parameter can be notified to the terminal device in plain text, so the information of the first timer parameter can be broadcast as part of the protected system message. The embodiments of this application do not limit how to prevent replay attacks based on the timer parameter, and reference can be made to the description of the current related art.

[0171] The following combination Figure 4 Briefly introduce the system message structure in the embodiment of this application. Figure 4 (a) and (b) are schematic block diagrams of another system message provided in an embodiment of the present application.

[0172] As a possible implementation method, the underlying characteristic parameters can be used as part of the digital signature protection. Since the terminal device can obtain the characteristic parameters of the network device through methods such as blind detection signals, these characteristic parameters do not need to be sent to the terminal device in the protected system message. However, when generating the digital signature of the system message, these characteristic parameters need to be added to the protection of the mathematical signature. Specifically, Figure 4 As shown in (a) in .

[0173] from Figure 4 As can be seen from (a) in FIG. 1 , the protected system message includes the system message, the digital signature, and the information of the first timer parameter.

[0174] Furthermore, for certain characteristic parameters of network devices, there may be deviations between the calculated results and the actual values. In this case, the terminal device can adjust the error in the extracted results to adjust the tolerance. For correctable characteristic parameters, they do not need to be transmitted in plain text in system messages.

[0175] For example, the terminal device may report the characteristic parameter value detected by the network device, and the network device may determine whether the value calculated by the terminal device deviates from the actual value;

[0176] For another example, the terminal device may perform offline calculations to simulate and calculate whether the terminal device can restore characteristic parameters of the network device.

[0177] When there is a deviation between the characteristic value result extracted by the terminal device through calculation and the actual value, and this deviation exceeds the correction range of the terminal device, the characteristic parameters of the network device can be sent to the terminal device through a system message, as shown in the following example: Figure 4 As shown in (b) in .

[0178] from Figure 4As can be seen from (b) in the figure, the protected system message includes system information, a digital signature, information about the first timer parameter (least signification bits of Time Counter #1, LSBs of Time Counter #1), and information about the characteristic parameter (least signification bits of gNB character, LSBs of gNB character). The characteristic parameter information is used to indicate the characteristic parameter.

[0179] Exemplarily, the network device broadcasts the protected system message including:

[0180] The RRC layer or other high-level processing units of the network device transmit the protected system message to the bottom-level processing unit of the network device; the bottom-level processing unit of the network device encodes the protected system message and broadcasts the encoded protected system message through the air interface.

[0181] The above steps S310 to S350 describe in detail the distribution of keys in the key generation center and the process of network devices generating and broadcasting protected system messages. It should be understood that when the protection method of the protected system message is as shown above, the verification method of the received protected system message at the terminal device needs to correspond to the protection method. The following details the process of the terminal device processing the received protected system message in conjunction with the specific process. Figure 3 The method flow shown also includes:

[0182] S360: The terminal device obtains characteristic parameters.

[0183] It should be noted that in the embodiment of the present application, in the initial state, the terminal device has not established synchronization and connection with the network device, and the terminal device cannot obtain the characteristic parameters of the network device. At this time, the system message broadcast by the network device cannot be verified; only after the terminal device and the network device have established a connection normally, and the terminal device periodically receives the system message broadcast by the network device, can the terminal device verify the digital signature of the system message.

[0184] The terminal device obtains the characteristic parameters specifically including: the terminal device establishes synchronization and RRC connection with the network device, the bottom processing unit of the terminal device obtains the fixed characteristic parameters of the network device through blind detection and other calculations, such as the above-mentioned characteristic parameters, which will not be repeated here; the bottom processing unit of the terminal device transmits the characteristic parameters of the network device to the RRC layer or other high-level processing units of the terminal device.

[0185] The above-mentioned step S350 in which the network device broadcasts the protected system message can be understood as: the terminal device receives the protected system message.

[0186] Specifically, the bottom layer of the terminal device periodically receives protected system messages such as MIB or SIB; the bottom layer of the terminal device passes the received protected system messages to the RRC layer of the terminal device. After the terminal device receives the protected system messages, it needs to verify the protected system messages. Figure 3 The method flow shown also includes:

[0187] S370, the terminal device verifies the protected system message.

[0188] The terminal device verifies the digital signature in the protected system message based on the public key, the characteristic parameter and the second timer parameter.

[0189] Among them, the public key can be obtained through the above-mentioned step S311, which will not be repeated here; the characteristic parameters can be obtained through the above-mentioned step S360, which will not be repeated here; and the terminal device can determine the second timer parameters based on the second timer maintained locally.

[0190] Exemplarily, the verification method used by the terminal device to verify the protected system message can be an identity-based signature verification algorithm, specifically including: confirming that the received digital signature is on an elliptic curve; calculating a hash value based on a second timer parameter, characteristic parameters (e.g., PCI), a public key, and other parameters; and finally, verifying according to a calculation formula. The specific verification method is not limited in the embodiments of this application; the focus is that in the process of generating and verifying the digital signature, the input parameters involve the above-mentioned characteristic parameters.

[0191] It can be understood that the input parameters and verification parameters for generating the digital signature in the embodiment of the present application add characteristic parameters of some network devices below the RRC layer (e.g., from the PDCP layer to the PHY layer) and the RF devices. Compared with the solution in which the verification input and verification parameters are globally public identifiers, it can better prevent the system messages from being modified by illegal network devices.

[0192] In the above method embodiments, the order of the sequence numbers of the above processes does not necessarily indicate the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. In addition, it is possible that not all operations in the above method embodiments need to be executed.

[0193] It should be understood that the terminal device and / or network device in the above method embodiment can execute some or all of the steps in the embodiment. These steps or operations are only examples. The embodiments of the present application can also include executing other operations or variations of various operations.

[0194] It should also be understood that in the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments may be consistent and may be referenced to each other, and the technical features in different embodiments may be combined to form new embodiments according to their inherent logical relationships.

[0195] Combined with the above Figure 3 The method for transmitting system messages provided by the embodiment of the present application is described in detail. Figure 5 - Figure 8 The device for transmitting system messages provided in an embodiment of the present application is introduced in detail.

[0196] See also Figure 5 , Figure 5 Schematic diagram of the device 500 for transmitting system messages proposed in this application. Figure 5 As shown, the apparatus 500 includes an acquisition unit 510 and a processing unit 520 .

[0197] An acquisition unit 510 is configured to acquire a public key and characteristic parameters of a network device, wherein the public key and the characteristic parameters are used to verify a digital signature of a system message;

[0198] The acquiring unit 510 is further configured to receive a protected system message from the network device, where the protected system message includes the system message, the digital signature, and information about a first timer parameter;

[0199] The processing unit 520 is configured to verify the digital signature of the system message based on the public key, the characteristic parameter, and the second timer parameter,

[0200] The characteristic parameter is an inherent characteristic parameter of the network device, the first timer parameter is a parameter of a first timer maintained locally by the network device, and the second timer parameter is a parameter of a second timer maintained locally by the device.

[0201] As an example, the processing unit 520 further includes: a bottom-layer processing unit and a high-layer processing unit, wherein the bottom-layer processing unit is configured to obtain the feature parameter through blind detection;

[0202] The bottom processing unit is also used to send the characteristic parameters to the upper processing unit of the terminal device.

[0203] The bottom layer includes at least one of radio frequency, packet data convergence protocol layer PDCP, radio link control layer RLC, media access control layer MAC and physical layer PHY, and the upper layer includes radio resource control layer RRC.

[0204] The apparatus 500 corresponds to the terminal device in the method embodiment, and the apparatus 500 may be the terminal device in the method embodiment, or a chip or functional module inside the terminal device in the method embodiment. Figure 3 The corresponding steps in the method embodiment shown are executed by the terminal device.

[0205] The processing unit 520 in the apparatus 500 is configured to execute the steps corresponding to the processing of the terminal device in the method embodiment. The acquisition unit 510 in the apparatus 500 is configured to execute the terminal device acquisition step in the method embodiment. The apparatus 1300 may further include a sending unit configured to execute the terminal device sending step, for example, sending information to another device. The sending unit and the acquisition unit 510 may form a transceiver unit having both receiving and transmitting functions. The processing unit 520 may be at least one processor. The sending unit may be a transmitter or an interface circuit, and the acquisition unit 510 may be a receiver or an interface circuit. The receiver and transmitter may be integrated together to form a transceiver or an interface circuit.

[0206] Optionally, the device 500 may also include a storage unit for storing data and / or signaling, and the processing unit 520, the sending unit, and the acquisition unit 510 may interact or couple with the storage unit, for example, to read or call the data and / or signaling in the storage unit, so that the method of the above embodiment is executed.

[0207] The above units can exist independently or be fully or partially integrated.

[0208] See also Figure 6 , Figure 6 This is a schematic diagram of the structure of a terminal device 600 applicable to an embodiment of the present application. The terminal device 600 can be applied to Figure 1 In the system shown. For the sake of convenience, Figure 6 Only the main components of the terminal device are shown. Figure 6 As shown, terminal device 600 includes a processor, memory, control circuitry, an antenna, and input / output devices. The processor is used to control the antenna and input / output devices to transmit and receive signals. The memory is used to store a computer program. The processor is used to retrieve and execute the computer program from the memory to execute the corresponding processes and / or operations performed by the terminal device in the registration method proposed in this application. This description will not be repeated here.

[0209] Those skilled in the art will understand that for ease of explanation, Figure 6 Only one memory and processor are shown. In an actual terminal device, there may be multiple processors and memories. The memory may also be referred to as a storage medium or a storage device, etc., which is not limited in the embodiments of the present application.

[0210] See also Figure 7 , Figure 7 Schematic diagram of the device 700 for transmitting system messages proposed in this application. Figure 7 As shown, the apparatus 700 includes an acquiring unit 710 , a processing unit 720 and a sending unit 730 .

[0211] an acquisition unit 710, configured to acquire characteristic parameters and a private key corresponding to the device, the private key and the characteristic parameters being used to digitally sign the system message;

[0212] A processing unit 720 is configured to digitally sign the system message based on the private key, the characteristic parameter, and the first timer parameter;

[0213] The sending unit 730 is configured to broadcast a protected system message, where the protected system message includes the system message, the digital signature, and information about the first timer parameter.

[0214] The characteristic parameter is an inherent characteristic parameter of the device, and the first timer parameter is a parameter of a first timer maintained locally by the device.

[0215] As an example, the processing unit 720 is further configured to generate an identifier of the network device based on the characteristic parameter;

[0216] The sending unit 730 is further configured to send the identifier to a key generation center, where the identifier is used to generate the private key;

[0217] The obtaining unit 710 obtains the private key corresponding to the device, including:

[0218] The acquisition unit 710 receives the private key from the key center.

[0219] As an example, the processing unit 720 further includes: a bottom-level processing unit and a high-level processing unit, wherein the bottom-level processing unit is used to determine the characteristic parameter;

[0220] The bottom processing unit is also used to send the characteristic parameters to the upper processing unit.

[0221] The bottom layer includes at least one of radio frequency, packet data convergence protocol layer PDCP, radio link control layer RLC, media access control layer MAC and physical layer PHY, and the upper layer includes radio resource control layer RRC.

[0222] The apparatus 700 corresponds to the network device in the method embodiment. The apparatus 700 may be the network device in the method embodiment, or a chip or functional module inside the network device in the method embodiment. The corresponding units of the apparatus 700 are used to execute Figure 3 The method embodiment shown includes corresponding steps executed by the network device.

[0223] The acquisition unit 710 in the apparatus 700 is used to execute the network device acquisition step in the method embodiment. The processing unit 720 in the apparatus 700 is used to execute the corresponding processing-related steps within the network device. The sending unit 730 in the apparatus 700 is used to execute the network device sending step.

[0224] The acquisition unit 710 and the transmission unit 730 may form a transceiver unit, having both receiving and transmitting functions. The processing unit 720 may be at least one processor. The transmission unit 730 may be a transmitter or an interface circuit. The acquisition unit 710 may be a receiver or an interface circuit. The receiver and transmitter may be integrated together to form a transceiver or an interface circuit.

[0225] Optionally, the device 700 may also include a storage unit for storing data and / or signaling, and the processing unit 720, the sending unit 730, and the acquisition unit 710 may interact or couple with the storage unit, for example, to read or call the data and / or signaling in the storage unit, so that the method of the above embodiment is executed.

[0226] The above units can exist independently or be fully or partially integrated.

[0227] See also Figure 8 , Figure 8 This is a schematic diagram of the structure of a network device 800 applicable to an embodiment of the present application, which can be used to implement the functions of the network device in the above-mentioned method for transmitting system messages.

[0228] In one possible approach, such as in certain implementations of a 5G communication system, the network device 800 may include a CU, a DU, and an AAU. Compared to the access network equipment in an LTE communication system, which consists of one or more radio frequency units, such as a remote radio unit (RRU) 801 and one or more baseband units (BBU), the non-real-time portion of the original BBU will be separated and redefined as a CU, responsible for processing non-real-time protocols and services. Part of the physical layer processing functions of the BBU will be merged with the original RRU and passive antenna into an AAU, and the remaining functions of the BBU will be redefined as a DU, responsible for processing physical layer protocols and real-time services. In short, the CU and DU are distinguished by the real-time nature of the processing content, and the AAU is a combination of the RRU and antenna.

[0229] CU, DU, and AAU can be deployed separately or together, so there will be a variety of network deployment forms. One possible deployment form is consistent with traditional 4G access network equipment, where CU and DU share the same hardware. It should be understood that Figure 8 This is just an example and does not limit the scope of protection of this application. For example, the deployment form can also be DU deployed in the 5G BBU room, CU centralized deployment, or DU centralized deployment, CU higher-level centralized, etc.

[0230] The AAU 801 can implement transceiver functions and is referred to as a transceiver unit 801. Optionally, the transceiver unit 801 can also be referred to as a transceiver, a transceiver circuit, or a transceiver, and may include at least one antenna 8011 and a radio frequency unit 8012. Optionally, the transceiver unit 801 may include a receiving unit and a transmitting unit. The receiving unit may correspond to a receiver (or receiver, receiving circuit), and the transmitting unit may correspond to a transmitter (or transmitter, transmitting circuit). The CU and DU 802 can implement internal processing functions and are referred to as a processing unit 802. Optionally, the processing unit 802 can control access network equipment and may be referred to as a controller. The AAU 801 and the CU and DU 802 may be physically arranged together or physically separated.

[0231] In addition, access network equipment is not limited to Figure 8 The form shown may also be other forms: for example, including BBU and ARU, or including BBU and AAU; it may also be CPE, or it may be other forms, which are not limited in this application.

[0232] It should be understood that Figure 8 The network device 800 shown is capable of implementing Figure 3The network device involved in the method embodiment. The operations and / or functions of each unit in the network device 800 are respectively for implementing the corresponding processes executed by the network device in the method embodiment of the present application. To avoid repetition, detailed description is appropriately omitted here. Figure 8 The structure of the network device in the example is only one possible form and should not constitute any limitation to the embodiments of the present application. The present application does not exclude the possibility of other forms of network device structures that may appear in the future.

[0233] An embodiment of the present application also provides a communication system, which includes the aforementioned terminal device and network device.

[0234] The present application also provides a computer-readable storage medium having instructions stored therein. When the instructions are executed on a computer, the computer is enabled to execute the above-mentioned Figure 3 The steps performed by the terminal device in the method shown are as follows.

[0235] The present application also provides a computer-readable storage medium having instructions stored therein. When the instructions are executed on a computer, the computer is enabled to execute the above-mentioned Figure 3 The various steps performed by the network device in the method shown.

[0236] The present application also provides a computer program product comprising instructions, which, when run on a computer, causes the computer to execute the following Figure 3 The steps performed by the terminal device in the method shown are as follows.

[0237] The present application also provides a computer program product comprising instructions, which, when run on a computer, causes the computer to execute the following Figure 3 The various steps performed by the network device in the method shown.

[0238] The present application also provides a chip including a processor. The processor is configured to read and execute a computer program stored in a memory to execute the corresponding operations and / or processes performed by a terminal device in the method for transmitting system messages provided in the present application. Optionally, the chip also includes a memory, which is connected to the processor via a circuit or wire, and the processor is configured to read and execute the computer program in the memory. Further optionally, the chip also includes a communication interface, to which the processor is connected. The communication interface is configured to receive and process data and / or information, and the processor obtains the data and / or information from the communication interface and processes the data and / or information. The communication interface may be an input / output interface, an interface circuit, an output circuit, an input circuit, a pin, or a related circuit on the chip. The processor may also be embodied as a processing circuit or a logic circuit.

[0239] The present application also provides a chip including a processor. The processor is configured to read and execute a computer program stored in a memory to execute the corresponding operations and / or processes performed by the network device in the method for transmitting system messages provided in the present application. Optionally, the chip also includes a memory, which is connected to the processor via circuits or wires, and the processor is configured to read and execute the computer program in the memory. Further optionally, the chip also includes a communication interface, to which the processor is connected. The communication interface is configured to receive and process data and / or information, and the processor obtains the data and / or information from the communication interface and processes the data and / or information. The communication interface may be an input / output interface, interface circuit, output circuit, input circuit, pin, or related circuit on the chip. The processor may also be embodied as a processing circuit or a logic circuit.

[0240] The above-mentioned chip can also be replaced by a chip system, which will not be described here.

[0241] The terms "comprises" and "having" and any variations thereof in this application are intended to cover non-exclusive inclusions. For example, a process, method, system, product or apparatus that includes a series of steps or elements is not necessarily limited to those steps or elements expressly listed but may include other steps or elements not expressly listed or inherent to such process, method, product or apparatus.

[0242] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0243] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0244] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0245] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected based on practical needs to achieve the objectives of this embodiment.

[0246] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0247] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0248] In addition, the term "and / or" in this application is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can represent three situations: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects are in an "or" relationship; the term "at least one" in this application can mean "one" and "two or more". For example, at least one of A, B, and C can represent seven situations: A exists alone, B exists alone, C exists alone, A and B exist at the same time, A and C exist at the same time, C and B exist at the same time, and A, B, and C exist at the same time.

[0249] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A method for transmitting system messages, characterized in that: include: The network device obtains a characteristic parameter and a private key corresponding to the network device, wherein the private key and the characteristic parameter are used to digitally sign the system message; The network device digitally signs the system message based on the private key, the characteristic parameter, and the first timer parameter; The network device broadcasts a protected system message, where the protected system message includes the system message, the digital signature, and information about the first timer parameter. Among them, the characteristic parameters are the inherent characteristic parameters of the network device, the first timer parameters are the parameters of the first timer locally maintained by the network device, and the inherent characteristic parameters of the network device are extracted and quantified from the unique characteristic parameters of at least one of the packet data convergence layer protocol PDCP layer, radio link control RLC layer, media access control MAC layer, physical PHY layer or radio frequency device of the network device.

2. The method according to claim 1, characterized in that The network device obtaining a private key corresponding to the network device includes: The network device generates an identifier of the network device based on the characteristic parameter; The network device sends the identifier to a key generation center, where the identifier is used to generate the private key; The network device receives the private key from the key generation center.

3. The method according to claim 1 or 2, characterized in that The network device acquiring characteristic parameters corresponding to the network device includes: The bottom layer processing unit of the network device determines the characteristic parameter; The bottom processing unit of the network device sends the characteristic parameters to the upper processing unit of the network device. Among them, the bottom layer of the network device includes at least one of a radio frequency device, a packet data convergence layer protocol PDCP layer, a radio link control RLC layer, a media access control MAC layer and a physical PHY layer, and the upper layer of the network device includes a radio resource control RRC layer.

4. The method according to claim 1 or 2, characterized in that The protected system message also includes information about the characteristic parameters, and the information about the characteristic parameters is used to indicate the characteristic parameters.

5. The method according to claim 1 or 2, characterized in that The characteristic parameters include at least one of the following: The frequency point of the network device, the physical cell identifier PCI of the network device, the number of antennas of the network device, the control channel occupied symbol number CFI of the network device, or the radio frequency fingerprint of the network device.

6. A method for transmitting system messages, characterized in that: include: The terminal device obtains a public key and characteristic parameters of the network device, wherein the public key and the characteristic parameters are used to verify the digital signature of the system message; The terminal device receives a protected system message from the network device, where the protected system message includes the system message, the digital signature, and information about a first timer parameter; The terminal device verifies the digital signature based on the public key, the characteristic parameter and the second timer parameter, Among them, the characteristic parameters are the inherent characteristic parameters of the network device, the first timer parameters are the parameters of the first timer locally maintained by the network device, the second timer parameters are the parameters of the second timer locally maintained by the terminal device, and the inherent characteristic parameters of the network device are obtained by extracting and quantifying the unique characteristic parameters of at least one of the packet data convergence layer protocol PDCP layer, radio link control RLC layer, media access control MAC layer, physical PHY layer or radio frequency device of the network device.

7. The method according to claim 6, characterized in that The terminal device acquiring characteristic parameters of the network device includes: The bottom processing unit of the terminal device obtains the characteristic parameters through blind detection; The bottom processing unit of the terminal device sends the characteristic parameters to the upper processing unit of the terminal device. The bottom layer of the terminal device includes at least one of a radio frequency device, a packet data convergence protocol layer PDCP, a radio link control layer RLC, a media access control layer MAC and a physical layer PHY, and the upper layer of the terminal device includes a radio resource control layer RRC.

8. The method according to claim 6 or 7, characterized in that The protected system message also includes information about the characteristic parameters, and the information about the characteristic parameters is used to indicate the characteristic parameters.

9. The method according to claim 6 or 7, characterized in that The characteristic parameters include at least one of the following: The frequency point of the network device, the physical cell identifier PCI of the network device, the number of antennas of the network device, the control channel occupied symbol number CFI of the network device, or the radio frequency fingerprint of the network device.

10. A device for transmitting system messages, characterized in that: include: an acquiring unit, configured to acquire characteristic parameters and a private key corresponding to the device, wherein the private key and the characteristic parameters are used to digitally sign the system message; a processing unit, configured to digitally sign the system message based on the private key, the characteristic parameter, and the first timer parameter; a sending unit, configured to broadcast a protected system message, wherein the protected system message includes the system message, the digital signature, and information about the first timer parameter; Among them, the characteristic parameters are inherent characteristic parameters of the device, the first timer parameters are parameters of the first timer locally maintained by the device, and the inherent characteristic parameters of the device are obtained by extracting and quantifying the unique characteristic parameters of at least one of the packet data convergence layer protocol PDCP layer, radio link control RLC layer, media access control MAC layer, physical PHY layer or radio frequency device of the device.

11. The device according to claim 10, characterized in that The processing unit is further configured to generate an identification of the device based on the characteristic parameters; The sending unit is further configured to send the identifier to a key generation center, where the identifier is used to generate the private key; The acquiring unit acquiring the private key corresponding to the device includes: The acquiring unit receives the private key from the key generation center.

12. The device according to claim 10 or 11, characterized in that The processing unit further includes: a bottom layer processing unit and a high layer processing unit, wherein the bottom layer processing unit is used to determine the characteristic parameter; The bottom processing unit is further configured to send the characteristic parameters to the upper processing unit. The bottom layer includes at least one of radio frequency, packet data convergence protocol layer PDCP, radio link control layer RLC, media access control layer MAC and physical layer PHY, and the upper layer includes radio resource control layer RRC.

13. The device according to claim 10 or 11, characterized in that The protected system message also includes information about the characteristic parameters, and the information about the characteristic parameters is used to indicate the characteristic parameters.

14. The device according to claim 10 or 11, characterized in that The characteristic parameters include at least one of the following: The frequency point of the device, the physical cell identifier PCI of the device, the number of antennas of the device, the control channel occupied symbol number CFI of the device or the radio frequency fingerprint of the device.

15. A device for transmitting system messages, characterized in that: include: an acquiring unit, configured to acquire a public key and characteristic parameters of a network device, wherein the public key and the characteristic parameters are used to verify the digital signature of the system message; The acquiring unit is further configured to receive a protected system message from the network device, where the protected system message includes information about the system message, the digital signature, and a first timer parameter; a processing unit, configured to verify the digital signature of the system message based on the public key, the characteristic parameter, and the second timer parameter, Among them, the characteristic parameters are the inherent characteristic parameters of the network device, the first timer parameters are the parameters of the first timer locally maintained by the network device, the second timer parameters are the parameters of the second timer locally maintained by the device, and the inherent characteristic parameters of the network device are obtained by extracting and quantifying the unique characteristic parameters of at least one of the packet data convergence layer protocol PDCP layer, radio link control RLC layer, media access control MAC layer, physical PHY layer or radio frequency device of the network device.

16. The device according to claim 15, characterized in that The processing unit further includes: a bottom-level processing unit and a high-level processing unit, wherein the bottom-level processing unit is configured to obtain the feature parameters through blind detection; The bottom processing unit is further configured to send the characteristic parameters to the upper processing unit of the device. The bottom layer includes at least one of radio frequency, packet data convergence protocol layer PDCP, radio link control layer RLC, media access control layer MAC and physical layer PHY, and the upper layer includes radio resource control layer RRC.

17. The device according to claim 15 or 16, characterized in that The protected system message also includes information about the characteristic parameters, and the information about the characteristic parameters is used to indicate the characteristic parameters.

18. The device according to claim 15 or 16, characterized in that The characteristic parameters include at least one of the following: The frequency point of the network device, the physical cell identifier PCI of the network device, the number of antennas of the network device, the control channel occupied symbol number CFI of the network device, or the radio frequency fingerprint of the network device.

19. A communication system comprising the apparatus for transmitting a system message according to any one of claims 10 to 14 and the apparatus for transmitting a system message according to any one of claims 15 to 18.

20. A communication device, comprising a processor, wherein the processor is connected to a memory, the memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory, so that the device performs the method according to any one of claims 1 to 9.

21. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed, the method according to any one of claims 1 to 9 is implemented.