Method and device for detecting man-in-the-middle
By establishing an AS security context between the base station and the user equipment, and judging the physical frame matching of the RRC message, the detection problem of man-in-the-middle attack is solved, and the detection accuracy and communication security are improved.
Patent Information
- Application Number
- CN202080106462.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-29
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2040-10-29
AI Technical Summary
The prior art is difficult to effectively detect man-in-the-middle attacks, especially when the man-in-the-middle completely simulates the MIB/SIB of a real base station, its existence cannot be recognized.
By establishing an access layer AS security context between the base station and the user equipment, it is determined whether the physical frames of the transmitted and received radio resource control RRC messages match, and the frame information contained in the RRC messages protected by the AS are detected.
It improves the accuracy of middleman detection, prevents middleman from bypassing detection through technical means, and ensures communication security.
Smart Images

Figure CN116325657B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and more particularly, to a method and apparatus for detecting a man-in-the-middle in the field of communications. Background Art
[0002] In wireless communication systems, radio resource control (RRC) signaling or user-plane data can be sent between user equipment (UE) and base stations. However, attackers can deploy rogue base stations between the UE and base station to eavesdrop, tamper with, impersonate, inject, or release air interface messages, potentially causing a denial-of-service (DOS) attack on the terminal or network.
[0003] The middleman is a type of fake base station, which includes some functions of the fake base station and some functions of the fake UE. If the UE is in the idle state, when it approaches the fake base station, the UE measures that the cell signal quality of the fake base station is good, and meets the conditions for cell reselection, the UE will trigger the cell reselection process to reside in the cell of the fake base station; if the UE is in the connected state, when it approaches the fake station, the UE measures that the cell signal quality of the fake base station is good, and reports the measurement result to the serving cell. The serving cell will trigger the UE to switch to the cell of the fake base station, so that the UE resides in the cell of the fake base station. Some functions of the fake UE are used to forward or modify the communication data of the real UE, access the real base station as the real UE, and communicate with the access and mobility management function (AMF) through the N2 protocol. It is usually difficult for the network side and the terminal side to perceive the existence of the middleman.
[0004] The current method for discovering a man-in-the-middle is usually: the UE calculates the hash value of the received master information block (MIB) / system information block (SIB), and carries the hash value of the MIB / SIB in the measurement report (MR) / logged MR reported to the real base station. The real base station calculates the hash value of the MIB / SIB and compares it with the value reported by the UE. If they are inconsistent, it is determined that a man-in-the-middle exists.
[0005] However, when the middleman completely imitates the MIB / SIB of the real base station, this method cannot detect such a middleman.
[0006] Therefore, providing a method for detecting middlemen that can prevent middlemen from bypassing detection through their own mechanisms is an urgent problem to be solved. Summary of the Invention
[0007] The present application provides a method and apparatus for detecting man-in-the-middle, which can effectively improve the detection rate of air-intermediary man-in-the-middle and prevent the man-in-the-middle from circumventing the detection mechanism through technical means.
[0008] In a first aspect, a method for detecting a man-in-the-middle is provided, the method comprising: a base station receiving a first radio resource control (RRC) message from a user equipment (UE) in a first physical frame; the base station receiving a second RRC message from the UE, the second RRC message including frame information of a second physical frame; wherein the first RRC message and the second RRC message are securely protected by an access layer (AS) security context established between the UE and the base station; and the base station determining whether the first physical frame matches the second physical frame.
[0009] In combination with the first aspect, in a first possible implementation of the first aspect, the frame information of the second physical frame includes a frame number and a subframe number of the second physical frame.
[0010] In combination with the first possible implementation of the first aspect, in the second possible implementation of the first aspect, the base station determines whether the first physical frame matches the second physical frame, including: when the frame number of the first physical frame is the same as the frame number of the second physical frame and the subframe number of the first physical frame is the same as the subframe number of the second physical frame, the base station determines that the first physical frame matches the second physical frame; otherwise, the base station determines that the first physical frame does not match the second physical frame.
[0011] In combination with the first aspect or any possible implementation of the first to the second possible implementation of the first aspect, in the third possible implementation of the first aspect, after the base station receives a first radio resource control RRC message from the UE in a first physical frame, the method also includes: the base station saves the frame information of the first physical frame.
[0012] In combination with the first aspect or any one of the first to third possible implementations of the first aspect, in the fourth possible implementation of the first aspect, before the base station receives the first radio resource control RRC message from the UE in the first physical frame, the method also includes: the base station establishes the AS security context with the UE.
[0013] In combination with the first aspect or any possible implementation of the first to fourth possible implementations of the first aspect, in the fifth possible implementation of the first aspect, before the base station receives the first RRC message from the UE in the first physical frame, the method also includes: the base station sends indication information to the UE, and the indication information is used to instruct the UE to start middleman detection.
[0014] According to a second aspect, a method for detecting a man-in-the-middle is provided, the method comprising: a user equipment UE sends a first radio resource control RRC message to a base station in a second physical frame; the UE sends a second RRC message to the base station, the second RRC message including frame information of the second physical frame; wherein the first RRC message and the second RRC message are securely protected by an access layer AS security context established between the UE and the base station.
[0015] In combination with the second aspect, in a first possible implementation of the second aspect, the frame information of the second physical frame includes a frame number and a subframe number of the second physical frame.
[0016] In combination with the second aspect or the first possible implementation of the second aspect, in the second possible implementation of the second aspect, before the user equipment UE sends a first radio resource control RRC message to the base station in the second physical frame, the method also includes: the UE receives downlink control information DCI, which is used to determine the frame information of the second physical frame; the UE saves the frame information of the second physical frame.
[0017] In combination with the second aspect or any possible implementation of the first to second possible implementations of the second aspect, in the third possible implementation of the first aspect, before the user equipment UE sends a first radio resource control RRC message to the base station in the second physical frame, the method also includes: the UE accesses the base station and establishes the AS security context with the base station.
[0018] In combination with the second aspect or any one of the first to third possible implementations of the second aspect, in the fourth possible implementation of the second aspect, the user equipment UE sends a first radio resource control RRC message to the base station in the second physical frame, including: when a preset rule is met, the UE sends the first RRC message to the base station in the second physical frame.
[0019] In combination with the fourth possible implementation method of the second aspect, in the fifth possible implementation method of the second aspect, the preset rule includes: the UE receives an indication message sent by the base station, and the indication message is used to instruct the UE to start middleman detection; or the UE determines that the user plane integrity protection between it and the base station is not enabled.
[0020] According to a third aspect, a method for detecting a man-in-the-middle is provided, the method comprising: a user equipment UE sends a third radio resource control RRC message to a base station in a third physical frame; the UE receives a fourth RRC message from the base station, the fourth RRC message including frame information of a fourth physical frame; the UE determines whether the third physical frame matches the fourth physical frame; the UE sends a fifth RRC message to the base station, the fifth RRC message being used to indicate whether the third physical frame matches the fourth physical frame; wherein the third RRC message, the fourth RRC message and the fifth RRC message are securely protected by an access layer AS security context established between the UE and the base station.
[0021] In combination with the third aspect, in a first possible implementation manner of the third aspect, the frame information of the fourth physical frame includes a frame number and a subframe number of the fourth physical frame.
[0022] In combination with the first possible implementation manner of the third aspect, in the second possible implementation manner of the third aspect, the UE determines whether the third physical frame matches the fourth physical frame, including: when the frame number of the third physical frame is the same as the frame number of the fourth physical frame and the subframe number of the third physical frame is the same as the subframe number of the fourth physical frame, the UE determines that the third physical frame matches the fourth physical frame; otherwise, the UE determines that the third physical frame does not match the fourth physical frame.
[0023] In combination with the third aspect or any possible implementation of the first to the second possible implementation of the third aspect, in the third possible implementation of the third aspect, before the user equipment UE sends a third radio resource control RRC message to the base station in the third physical frame, the method also includes: the UE receives downlink control information DCI, which is used to determine the frame information of the third physical frame, and the frame information of the third physical frame includes the frame number and subframe number of the third physical frame; the UE saves the frame information of the third physical frame.
[0024] In combination with the third aspect or any one of the first to third possible implementations of the third aspect, in the fourth possible implementation of the third aspect, before the user equipment UE sends a third radio resource control RRC message to the base station in a third physical frame, the method also includes: the UE accesses the base station and establishes the AS security context with the base station.
[0025] In combination with the third aspect or any possible implementation of the first to fourth possible implementations of the third aspect, in the fifth possible implementation of the third aspect, the user equipment UE sends a third radio resource control RRC message to the base station in a third physical frame, including: when a preset rule is met, the UE sends the third RRC message to the base station in the third physical frame.
[0026] In combination with the third aspect or any possible implementation of the first to fifth possible implementations of the third aspect, in the sixth possible implementation of the third aspect, the first preset rule includes: the UE receives indication information sent by the base station, and the indication information is used to instruct the UE to start middleman detection; or the UE determines that the user plane integrity protection between it and the base station is not turned on.
[0027] In a fourth aspect, a method for detecting a middleman is provided, the method comprising: a base station receives a third RRC message from a user equipment UE in a fourth physical frame; the base station sends a fourth RRC message to the UE, the fourth RRC message including frame information of the fourth physical frame; the base station receives a fifth RRC message sent by the UE; the base station determines whether there is a middleman between the base station and the UE based on the fifth RRC message.
[0028] In combination with the fourth aspect, in a first possible implementation of the fourth aspect, the fifth RRC message is used to indicate whether the third physical frame matches the fourth physical frame, and the third physical frame is the physical frame for the UE to send the third RRC message; the base station determines whether there is an intermediary between the base station and the UE based on the fifth RRC message, including: when the third physical frame does not match the fourth physical frame, the base station determines that there is an intermediary between the base station and the UE; or, when the third physical frame matches the fourth physical frame, the base station determines that there is no intermediary between the base station and the UE.
[0029] In combination with the fourth aspect or the first possible implementation of the fourth aspect, in a second possible implementation of the fourth aspect, the frame information of the fourth physical frame includes the frame number and subframe number of the fourth physical frame.
[0030] In combination with the fourth aspect or any possible implementation of the first to second possible implementations of the fourth aspect, in the third possible implementation of the third aspect, before the base station receives the third RRC message sent by the user equipment UE in the fourth physical frame, the method also includes: the base station establishes the AS security context with the UE.
[0031] In combination with the fourth aspect or any possible implementation of the first to third possible implementations of the fourth aspect, in the fourth possible implementation of the third aspect, before the base station receives the third RRC message sent by the user equipment UE in the fourth physical frame, the method also includes: the base station sends indication information to the UE, and the indication information is used to instruct the UE to start middleman detection.
[0032] In a fifth aspect, a device for detecting a man-in-the-middle is provided, the device comprising: a transceiver module for receiving a first radio resource control RRC message from a user equipment UE in a first physical frame; the transceiver module is also used to receive a second RRC message from the UE, the second RRC message including frame information of a second physical frame; wherein the first RRC message and the second RRC message are securely protected by an access layer AS security context established between the UE and the base station; a processing module for determining whether the first physical frame matches the second physical frame.
[0033] In combination with the fifth aspect, in a first possible implementation of the fifth aspect, the frame information of the second physical frame includes a frame number and a subframe number of the second physical frame.
[0034] In combination with the first possible implementation of the fifth aspect, in the second possible implementation of the fifth aspect, the processing module is specifically used to: when the frame number of the first physical frame is the same as the frame number of the second physical frame and the subframe number of the first physical frame is the same as the subframe number of the second physical frame, the base station determines that the first physical frame matches the second physical frame; otherwise, the base station determines that the first physical frame does not match the second physical frame.
[0035] In combination with the fifth aspect or any possible implementation of the first to second possible implementations of the fifth aspect, in a third possible implementation of the fifth aspect, the processing module is further used to: save the frame information of the first physical frame.
[0036] In combination with the fifth aspect or any possible implementation of the first to third possible implementations of the fifth aspect, in a fourth possible implementation of the fifth aspect, the processing module is further used to: establish the AS security context with the UE.
[0037] In combination with the fifth aspect or any one of the first to fourth possible implementations of the fifth aspect, in the fifth possible implementation of the fifth aspect, the transceiver module is also used to: send indication information to the UE, and the indication information is used to instruct the UE to start middleman detection.
[0038] In the sixth aspect, a device for detecting a middleman is provided, which includes: a transceiver module for sending a first wireless resource control RRC message to a base station in a second physical frame; the transceiver module is also used to send a second RRC message to the base station, and the second RRC message includes frame information of the second physical frame; wherein the first RRC message and the second RRC message are securely protected by an access layer AS security context established by the UE and the base station.
[0039] In combination with the sixth aspect, in a first possible implementation manner of the sixth aspect, the frame information of the second physical frame includes the frame number and subframe number of the second physical frame.
[0040] In combination with the sixth aspect or the first possible implementation of the sixth aspect, in the second possible implementation of the sixth aspect, the transceiver module is also used to: receive downlink control information DCI, which is used to determine the frame information of the second physical frame; the device also includes a processing module, which is used to save the frame information of the second physical frame.
[0041] In combination with any possible implementation of the sixth aspect or the first to second possible implementations of the fifth aspect, in the third possible implementation of the sixth aspect, the processing module is also used to: access the base station and establish the AS security context with the base station.
[0042] In combination with the sixth aspect or any one of the first to third possible implementations of the sixth aspect, in the fourth possible implementation of the sixth aspect, the transceiver module is specifically used to: when the preset rules are met, the UE sends the first RRC message to the base station in the second physical frame.
[0043] In combination with the fourth possible implementation method of the sixth aspect, in the fifth possible implementation method of the sixth aspect, the preset rules include: the UE receives an indication message sent by the base station, and the indication message is used to instruct the UE to start middleman detection; or the UE determines that the user plane integrity protection between it and the base station is not turned on.
[0044] In the seventh aspect, a device for detecting a man-in-the-middle is provided, which includes: a transceiver module, which sends a third wireless resource control RRC message to a base station in a third physical frame; the transceiver module is also used to receive a fourth RRC message from the base station, and the fourth RRC message includes frame information of a fourth physical frame; the transceiver module is also used to send a fifth RRC message to the base station, and the fifth RRC message is used to indicate whether the third physical frame matches the fourth physical frame; wherein the third RRC message, the fourth RRC message and the fifth RRC message are securely protected by the access layer AS security context established by the UE and the base station.
[0045] In combination with the seventh aspect, in a first possible implementation manner of the seventh aspect, the frame information of the fourth physical frame includes the frame number and subframe number of the fourth physical frame.
[0046] In combination with the seventh aspect or the first possible implementation manner of the seventh aspect, in the second possible implementation manner of the seventh aspect, the processing module is specifically used to: when the frame number of the third physical frame is the same as the frame number of the fourth physical frame and the subframe number of the third physical frame is the same as the subframe number of the fourth physical frame, the UE determines that the third physical frame matches the fourth physical frame; otherwise, the UE determines that the third physical frame does not match the fourth physical frame.
[0047] In combination with the seventh aspect or any possible implementation of the first to the second possible implementation of the seventh aspect, in the third possible implementation of the seventh aspect, the transceiver module is also used to: receive downlink control information DCI, which is used to determine the frame information of the third physical frame, and the frame information of the third physical frame includes the frame number and subframe number of the third physical frame; the processing module is also used to: save the frame information of the third physical frame.
[0048] In combination with the seventh aspect or any one of the first to third possible implementations of the seventh aspect, in the fourth possible implementation of the seventh aspect, the processing module is also used to: access the base station and establish the AS security context with the base station.
[0049] In combination with the seventh aspect or any one of the first to fourth possible implementations of the seventh aspect, in the fifth possible implementation of the seventh aspect, the first preset rule includes: the UE receives indication information sent by the base station, and the indication information is used to instruct the UE to start middleman detection; or the UE determines that the user plane integrity protection between it and the base station is not turned on.
[0050] In the eighth aspect, a device for detecting a middleman is provided, which includes: a transceiver module for receiving a third RRC message from a user equipment UE in a fourth physical frame; the transceiver module is also used to send a fourth RRC message to the UE, and the fourth RRC message includes frame information of the fourth physical frame; the transceiver module is also used to receive a fifth RRC message sent by the UE; and a processing module is used to determine whether there is a middleman between the base station and the UE based on the fifth RRC message.
[0051] In combination with the eighth aspect, in a first possible implementation method of the eighth aspect, the fifth RRC message is used to indicate whether the third physical frame matches the fourth physical frame, and the third physical frame is the physical frame for the UE to send the third RRC message; the processing module can be specifically used to: when the third physical frame does not match the fourth physical frame, determine that there is an intermediary between the UE; or, when the third physical frame matches the fourth physical frame, determine that there is no intermediary between the UE.
[0052] In combination with the eighth aspect or the first possible implementation of the eighth aspect, in a second possible implementation of the eighth aspect, the frame information of the fourth physical frame includes the frame number and subframe number of the fourth physical frame.
[0053] In combination with the eighth aspect or any possible implementation of the first to second possible implementations of the eighth aspect, in the third possible implementation of the eighth aspect, the processing module is further used to: establish the AS security context with the UE.
[0054] In combination with the eighth aspect or any one of the first to third possible implementations of the eighth aspect, in the fourth possible implementation of the eighth aspect, the transceiver module is also used to: send indication information to the UE, and the indication information is used to instruct the UE to start middleman detection.
[0055] In the ninth aspect, a communication device is provided, comprising: a processor for executing a computer program stored in a memory, so that the communication device executes the communication method in any one of the first to fifth possible implementations of the first aspect, or executes the communication method in any one of the first to fifth possible implementations of the second aspect, or executes the communication method in any one of the first to fourth possible implementations of the third aspect, or executes the communication method in any one of the first to fourth possible implementations of the fourth aspect.
[0056] In the tenth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is run on a computer, the computer is caused to execute the communication method in any one of the first to fifth possible implementations of the first aspect, or execute the communication method in any one of the first to fifth possible implementations of the second aspect, or execute the communication method in any one of the first to fourth possible implementations of the third aspect, or execute the communication method in any one of the first to fourth possible implementations of the fourth aspect.
[0057] In the eleventh aspect, a chip system is provided, which includes: a processor for calling and running a computer program from a memory, so that a communication device installed with the chip system executes the communication method in any one of the first to fifth possible implementations of the first aspect, or executes the communication method in any one of the first to fifth possible implementations of the second aspect, or executes the communication method in any one of the first to fourth possible implementations of the third aspect, or executes the communication method in any one of the first to fourth possible implementations of the fourth aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] Figure 1This is an example diagram of the system architecture of the embodiment of the present application.
[0059] Figure 2 This is a diagram of the intermediary work architecture according to an embodiment of the present application.
[0060] Figure 3 This is a schematic interactive diagram of an example of a method for detecting a middleman in an embodiment of the present application.
[0061] Figure 4 This is a schematic diagram of message transmission between a user equipment and a base station in an embodiment of the present application.
[0062] Figure 5 This is another schematic interaction diagram of the method for detecting a man-in-the-middle according to an embodiment of the present application.
[0063] Figure 6 This is another schematic interaction diagram of the method for detecting a man-in-the-middle according to an embodiment of the present application.
[0064] Figure 7 This is another schematic interaction diagram of the method for detecting a man-in-the-middle according to an embodiment of the present application.
[0065] Figure 8 This is a schematic block diagram of an example of a user equipment of the present application.
[0066] Figure 9 It is a schematic block diagram of an example of a base station of the present application.
[0067] Figure 10 This is a schematic block diagram of another example of the user equipment of the present application.
[0068] Figure 11 It is a schematic block diagram of another example of the base station of the present application.
[0069] Figure 12 This is a schematic block diagram of an example of a communication device of the present application.
[0070] Figure 13 It is a schematic block diagram of another example of the communication device of the present application.
[0071] Figure 14 It is a schematic structural diagram of the terminal device of this application. DETAILED DESCRIPTION
[0072] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0073] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: long term evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD) system, universal mobile telecommunication system (UMTS), new radio (NR) system, etc.
[0074] The following combination Figure 1 A structure of the communication system of this application is described. Figure 1 As shown, the communication system includes but is not limited to the following network elements:
[0075] 1. User equipment (UE)
[0076] The UE in the embodiments of the present application may also be referred to as: mobile station (MS), mobile terminal (MT), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device, etc.
[0077] A UE may be a device that provides voice / data connectivity to a user, such as a handheld device or vehicle-mounted device with a wireless connection function. At present, some examples of terminals include: mobile phones, tablet computers, laptop computers, PDAs, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to wireless modems, vehicle-mounted devices, wearable devices, UEs in future 5G networks or future evolved public land mobile communication networks (PLMNs), etc. network, PLMN), etc., and the embodiments of the present application are not limited to this.
[0078] As an example and not a limitation, in the embodiment of the present application, the UE may also be a wearable device. Wearable devices may also be called wearable smart devices, which are a general term for wearable devices that use wearable technology to intelligently design and develop wearable devices for daily wear, such as glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothes or accessories. Wearable devices are not only hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include full-featured, large-sized, and independent of smartphones to achieve complete or partial functions, such as smart watches or smart glasses, as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.
[0079] In addition, in the embodiment of the present application, the UE can also be a UE in the Internet of Things (IoT) system. The IoT is an important part of the future development of information technology. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network of human-machine interconnection and object-to-object interconnection.
[0080] In the embodiments of the present application, IoT technology can achieve massive connectivity, deep coverage, and terminal power saving through, for example, narrowband NB technology. For example, an NB can include one resource block (RB), that is, the NB bandwidth is only 180KB. To achieve massive access, it is necessary to require discrete terminals in access. According to the communication method of the embodiments of the present application, it can effectively solve the congestion problem of massive IoT terminals when accessing the network through NB.
[0081] In addition, in the embodiment of the present application, the UE may also communicate with UEs of other communication systems, for example, inter-device communication, etc. For example, the UE may also transmit (for example, send and / or receive) time synchronization messages with UEs of other communication systems.
[0082] 2. Base Station
[0083] In addition, the base station in the embodiment of the present application can be a device for communicating with the UE. The base station can also be referred to as an access network device or a wireless access network device. For example, the base station can be an evolved NodeB (eNB or eNodeB) in the LTE system, or a wireless controller in a cloud radio access network (CRAN) scenario, or the base station can be a relay station, an access point, a vehicle-mounted device, a wearable device, a base station in a future 5G network, or a base station in a future evolved PLMN network, etc. It can be an access point (AP) in a WLAN, or it can be a gNB in a new wireless system (NR) system. The embodiment of the present application is not limited.
[0084] In addition, in the embodiment of the present application, the base station is a device in the RAN, or in other words, a RAN node that connects the UE to the wireless network. For example, as an example and not a limitation, as a base station, the following can be listed: gNB, transmission reception point (TRP), evolved Node B (eNB), radio network controller (RNC), Node B (NB), base station controller (BSC), base transceiver station (BTS), home base station (e.g., home evolved Node B, or home Node B, HNB), base band unit (BBU), etc. In a network structure, the network device may include a centralized unit (CU) node, a distributed unit (DU) node, or a RAN device including a CU node and a DU node, or a RAN device including a control plane CU node (CU-CP node) and a user plane CU node (CU-UP node) and a DU node.
[0085] A base station provides services for a cell. A UE communicates with the base station through the transmission resources used by the cell (e.g., frequency domain resources, or spectrum resources). The cell may be a cell corresponding to a base station (e.g., a base station). A cell may belong to a macro base station or a base station corresponding to a small cell. Small cells may include metro cells, micro cells, pico cells, and femto cells. These small cells have the characteristics of small coverage and low transmission power, and are suitable for providing high-speed data transmission services.
[0086] In addition, multiple cells can operate simultaneously on the same frequency on a carrier in an LTE or 5G system. In certain special scenarios, the concepts of carrier and cell can be considered equivalent. For example, in a carrier aggregation (CA) scenario, when a secondary carrier is configured for a UE, both the carrier index of the secondary carrier and the cell identification (Cell ID) of the secondary cell operating on the secondary carrier are carried. In this case, the concepts of carrier and cell can be considered equivalent, for example, a UE accessing a carrier is equivalent to accessing a cell.
[0087] 3. Access management functional entity
[0088] The access management function entity is mainly used for mobility management and access management, and can be used to implement other functions of the mobility management entity (MME) in the LTE system except session management, such as lawful interception and access authorization / authentication.
[0089] In a 5G communication system, the access management network element may be an access and mobility management function (AMF) entity.
[0090] In future communication systems, the access management function entity may still be an AMF entity, or may have other names, which is not limited in this application.
[0091] It is understandable that the above entities or functions can be network elements in hardware devices, software functions running on dedicated hardware, or virtualized functions instantiated on a platform (e.g., a cloud platform).
[0092] It should be understood that the network elements or entities included in the communication system listed above are only exemplary and are not specifically limited in this application.
[0093] Figure 2 The following diagram shows the working structure of the middleman. Figure 2 As can be seen from the figure, the middleman includes a pseudo base station part and a pseudo UE part. The pseudo base station part is used to attract UEs to reside in the middleman cell, and the pseudo UE part is used to access the real base station and forward or modify the communication data of the real UE. The AMF network element is the network element mainly responsible for access and mobility management. Base station ( Figure 2 The gNB (in this example) and the AMF are connected via the N2 interface, which is similar to the S1 interface and transmits messages between the RAN and the AMF. The UE and AMF communicate via the N1 / NAS interface, transmitting messages between the UE and the AMF, typically relayed by the RAN to the AMF. The UE and the base station are connected via the UU interface, allowing them to exchange RRC signaling and user plane data. The base station and the AMF are connected via the N2 interface, and communication between the base station and the AMF is based on the N2 protocol.
[0094] This type of middleman can eavesdrop, tamper with, forge, inject, or replay over-the-air messages, causing denial-of-service (DOS) attacks on terminals and networks. The network and terminal sides often have difficulty detecting the presence of a middleman.
[0095] For ease of explanation, the following takes the frame structure in LTE and NR systems as an example to first introduce the physical frame in air interface communication.
[0096] A physical frame generally refers to a protocol data unit (PDU) at the data link layer. A physical frame consists of several parts that perform different functions, and a frame structure refers to a frame that can be composed of different repetition periods depending on the information being transmitted. To meet the requirements for uplink and downlink time conversion in time division multiplexing, TD-LTE has designed a dedicated radio frame structure. In the TD-LTE time domain, there are two types of frame structures: radio frames and half frames, which are transmitted simultaneously in a periodic manner and have a standard number of uplink and downlink subframes. A radio frame lasts 10ms, a half frame lasts 5ms, and a radio frame consists of two half frames. Each half frame consists of five subframes of 1ms, each subframe consists of two time slots of 0.5ms. Each time slot can consist of six or seven CP+OFDM symbols, depending on the duration of the cyclic prefix (CP).
[0097] Compared to the fixed 4G frame structure, the most significant feature of the 5G frame structure is its flexibility. The 5G frame employs a layered structure consisting of a fixed architecture and a flexible architecture. The fixed architecture, like 4G, consists of a 10ms radio frame and 1ms subframes. Each frame is divided into two half-frames: the first half-frame contains subframes 0 through 4, and the second half-frame contains subframes 5 through 9. Each subframe consists of several time slots.
[0098] In both LTE and NR systems, the system frame number (SFN) ranges from 0 to 1023, meaning the basic data transmission period is 1024 frames. The subframe number ranges from 0 to 9, meaning some control information is transmitted every 10 subframes.
[0099] The following will be combined Figures 3 to 7 The method for detecting a man-in-the-middle in the present application is described in detail.
[0100] Figure 3 FIG1 shows a schematic flow chart of a method 100 for detecting a middleman according to an embodiment of the present application. Figure 3 As can be seen, method 100 includes:
[0101] S110, the base station receives a first RRC message sent by the UE in a first physical frame;
[0102] S120, the base station receives a second RRC message sent by the UE, where the second RRC message includes frame information of a second physical frame;
[0103] S130: The base station determines whether the first physical frame matches the second physical frame.
[0104] Specifically, after the base station successfully establishes the AS security context with the UE, it receives the first RRC message from the UE in the first physical frame. The base station then receives a second RRC message with security protection from the UE, and the UE provides the base station with frame information of the second physical frame through the second RRC message. The frame information of the second physical frame is the physical frame in which the UE sends the first RRC message. When there is a man-in-the-middle attack, the air interface communication between the base station and the UE is intercepted by the middleman, and the air interface between the UE and the pseudo base station is independent of the air interface between the pseudo UE and the base station, that is, the base station cannot directly receive the first RRC message sent by the UE. The middleman receives the first RRC message through the pseudo base station and forwards the first RRC message to the base station through the pseudo UE. The first RRC message is securely protected by the access layer security context established by the UE and the base station, so the middleman cannot crack or tamper with the first RRC message. After a man-in-the-middle attack occurs between the UE and the base station, the physical frame in which the UE sends the uplink message and the physical frame in which the base station receives the uplink message cannot be consistent. Therefore, when the first physical frame and the second physical frame match, the base station determines that there is no man-in-the-middle between the UE and the base station; when the first physical frame and the second physical frame do not match, the base station determines that there is a man-in-the-middle between the UE and the base station.
[0105] Therefore, the method for detecting a middleman in an embodiment of the present application determines whether there is a middleman in the air interface communication by judging whether the physical frame of the UE sending the uplink message matches the physical frame of the base station receiving the uplink message, thereby preventing the middleman from using its own mechanism to bypass detection and improving the detection rate of the middleman.
[0106] According to method 100, the method for detecting man-in-the-middle in the embodiment of the present application is based on the following: when a man-in-the-middle attack occurs between the UE and the base station, the physical frame of the uplink message sent by the UE and the physical frame of the uplink message received by the base station cannot match, that is, the frame information of the physical frame of the uplink message sent by the UE is inconsistent with the frame information of the physical frame of the uplink message received by the base station. Figure 4 In the uplink scheduling request mechanism shown, when there is an intermediary between the UE and the base station, the uplink message sent by the UE to the base station, such as the first RRC message, cannot be directly received by the base station. The base station can only receive the first RRC message transparently transmitted by the intermediary. At this time, the frame information of the physical frame of the uplink message sent by the intermediary through the fake UE cannot be consistent with the frame information of the physical frame of the uplink message sent by the real UE. Specifically, Figure 4 The illustrated process 200 includes:
[0107] S210: The UE sends a first scheduling request (SR) to the middleman.
[0108] Specifically, when a man-in-the-middle attack occurs, the UE and the base station are indirectly connected through the middleman. That is, the middleman establishes connections with the real UE and the real base station through a fake base station and a fake UE, respectively. After the connection is established, the UE sends a first SR to the fake base station to request uplink transmission resources.
[0109] S220: The middleman sends first downlink control information (DCI) to the UE.
[0110] Specifically, after receiving the first SR sent by the UE, the middleman sends a first DCI to the UE, and indicates appropriate available resources to the UE through the first DCI.
[0111] S230: The UE sends a first RRC message to the middleman.
[0112] Specifically, the UE receives a first DCI sent by the middleman, determines a physical frame a according to the first DCI, and sends a first RRC message to the middleman in the physical frame a.
[0113] For example, after the UE receives the first DCI in subframe n, it sends the first RRC message to the middleman in subframe n+x, and the physical frame in which the subframe n+x is located is physical frame a. It should be understood that in the LTE system, the x is a value defined by the protocol, and under a unified configuration, the value of x is fixed. For example, in the frequency division duplexing (FDD) scenario, the value of x is fixed to 4. For details, please refer to Chapter 8 of the protocol 3GPP TS 36.213. For another example, in the NR system, the UE receives the first DCI, and the first DCI carries information parameters. The UE determines the value of x based on the information parameters. The specific determination method can be referred to Chapter 6 of the protocol 3GPP TS 38.214.
[0114] S240: The middleman sends a first SR to the base station.
[0115] Specifically, after receiving the first SR sent by the UE in step S210, the middleman reports the first SR to the real base station through the fake UE.
[0116] S250: The base station sends a second DCI to the middleman.
[0117] Specifically, after receiving the first SR sent by the pseudo UE, the base station sends a second DCI to the middleman to indicate appropriate available resources for the pseudo UE.
[0118] S260: The middleman sends a first RRC message to the base station.
[0119] Specifically, the middleman receives the second DCI sent by the base station, determines the physical frame b according to the second DCI, and sends the first RRC message to the base station in the physical frame b.
[0120] It should be understood that physical frame a is the time domain resource location indicated by the middleman to the UE, and physical frame b is the time domain resource location indicated by the base station to the middleman. Because the middleman cannot predict the specific location of physical frame b indicated by the base station, it is impossible to match physical frame a with physical frame b. Therefore, when a man-in-the-middle attack occurs, the physical frame in which the UE sends an uplink message cannot match the physical frame in which the base station receives the uplink message.
[0121] Figure 5 FIG2 shows a schematic flow chart of a method 300 for detecting a man-in-the-middle attack according to an embodiment of the present application when a man-in-the-middle attack occurs between a UE and a base station. Figure 5 It can be seen that the method 300 includes:
[0122] S310: An AS security context is established between the UE and the base station.
[0123] Specifically, a UE accesses a base station, establishing an indirect connection with the base station through an intermediary. The UE then establishes an access stratum (AS) security context with the base station. It should be understood that after the UE and base station establish an AS security context, RRC messages are protected, preventing intermediaries from tampering with RRC messages sent between the UE and base station. This security protection includes RRC integrity protection and RRC confidentiality protection. RRC integrity protection prevents RRC messages from being tampered with during transmission, while RRC confidentiality protection ensures that the information content of RRC messages is not leaked during transmission.
[0124] S320: The middleman sends a third DCI to the UE, where the third DCI is used to determine the physical frame p in which the UE sends the RRC message.
[0125] It should be understood that before S320, the UE sends a buffer status report (BSR) to the intermediary to indicate the amount of data in the uplink buffer, and then the intermediary sends a third DCI to the UE to allocate appropriate available resources to the UE. The UE determines the physical frame p based on the third DCI. For example, in the NR system, the UE receives the third DCI in physical frame c, the frame number and subframe number of the physical frame c are 10 and 6 respectively, and the time indicated by the physical frame c is 10*10+6=106. The third DCI carries an information parameter, and the UE calculates the value of x as 2 based on the information parameter, then the time indicated by the physical frame e is 106+2=108, so the frame number and subframe number of the physical frame e are 10 and 8 respectively.
[0126] Optionally, after determining the physical frame p according to the third DCI, the UE saves the frame information of the physical frame p, where the frame information of the physical frame p includes the frame number and subframe number of the physical frame p.
[0127] It should be understood that before step S320, when the first preset rule is met, the UE initiates man-in-the-middle detection. Initiating man-in-the-middle detection refers to the UE performing the method mentioned in this application. For example, initiating man-in-the-middle may include the UE sending a first physical frame query request message and a second physical frame query request message carrying frame information of physical frame p.
[0128] The first preset rule includes: the UE receiving an indication from the base station, the indication information being used to instruct the UE to initiate man-in-the-middle detection; or determining that user plane integrity protection between the UE and the base station is not enabled. It should be understood that the disabling of user plane integrity protection means that user plane data between the UE and the base station is at risk of being tampered with. In this case, if a man-in-the-middle is present, the authenticity of the user plane data cannot be guaranteed, and therefore, man-in-the-middle detection needs to be enabled.
[0129] Optionally, when a second preset rule is met, the base station sends an instruction message to the UE to instruct the UE to start man-in-the-middle detection. The second preset rule may be, for example, that a key performance indicator (KPI) is greater than a second threshold.
[0130] S330: The UE sends a first physical frame query request message to the middleman.
[0131] Specifically, the UE sends a first physical frame query request carried in an RRC message in physical frame p to perform man-in-the-middle detection. The message has security protection and therefore cannot be tampered with by a man-in-the-middle.
[0132] It should be understood that the first physical frame query request message may be an empty RRC message.
[0133] S340: The base station sends a fourth DCI to the middleman, where the fourth DCI is used to determine the physical frame q.
[0134] It should be understood that before S340 , the middleman sends a BSR to the base station through the pseudo UE to indicate the amount of data in the uplink buffer, and then the base station sends a fourth DCI to the middleman, where the fourth DCI is used to determine the physical frame q.
[0135] S350: The base station saves the frame information of the physical frame q.
[0136] Optionally, after indicating the physical frame q to the middleman through the fourth DCI, the base station saves the frame information of the physical frame q.
[0137] S360: The middleman sends a first physical frame query request message to the base station.
[0138] Specifically, the intermediary receives the first physical frame query request message sent by the UE in physical frame p. This first physical frame query request message is protected by the AS security context established between the UE and the base station. Therefore, the intermediary cannot tamper with it and can only be transparently transmitted to the base station. Therefore, the intermediary sends the first physical frame query request message to the base station in physical frame q indicated by the base station.
[0139] S370: The base station continues to store the frame information of the physical frame q.
[0140] Specifically, after receiving the first physical frame query request message forwarded by the middleman in the physical frame q, the base station locally records the frame information of the physical frame q, where the frame information of the physical frame q includes the frame number and subframe number of the physical frame q.
[0141] Optionally, when the first physical frame query request message includes specific indication information, for example, the first physical frame query request message is an RRC message for initiating middleman detection or the first RRC message includes specific indication information (for example, an indication bit is carried in an existing measurement report, and this indication bit is optionally used to indicate the initiation of middleman detection), the base station continues to retain the frame information of the physical frame q or re-saves the frame information of the physical frame q.
[0142] Optionally, the base station determines, based on the first RRC message, that the terminal has initiated man-in-the-middle detection.
[0143] It should be understood that the feature in which the base station continues to retain the frame information of the physical frame q can be applied to other embodiments that require retaining physical frame information, and the present application is not limited thereto.
[0144] Optionally, in the NR system, the frame information of the physical frame q may further include the time slot number of the physical frame q. In the NR system, when a subframe consists of multiple time slots, the base station (or pseudo base station) may indicate the frame number, subframe number, and time slot number of the physical frame q to the UE through DCI.
[0145] S380, the UE sends a second physical frame query request message to the middleman.
[0146] Specifically, after the UE sends a first physical frame query request message to the middleman in physical frame p, it sends a second physical frame query request message with security protection to the middleman, and the second physical frame query request message includes frame information of physical frame p. It should be understood that after the UE determines to start the middleman detection, the frame information of physical frame p is carried in the second physical frame query request message for middleman detection. It should also be understood that the second RRC message is sent to perform the middleman detection process so that the base station can determine whether there is a middleman based on the physical frame information carried in the second physical frame query request message.
[0147] It should be noted that since the first physical frame query request message is an RRC layer message, the RRC layer cannot determine the physical frame to send the message when encoding and constructing the message. After the first physical frame query request message is encoded, it enters the cache queue. The UE reports the cache status report to the base station. The base station then performs unified scheduling of the UE, and the UE sends after obtaining resources. At the same time, there is a possibility of retransmission when sending the message, and it cannot be guaranteed that the transmission will be successful at the time of sending. Therefore, the first physical frame query request message cannot carry the frame information of physical frame p.
[0148] S390: The middleman sends a second physical frame query request message to the base station.
[0149] Specifically, the middleman receives the second physical frame query request message sent by the UE, but since the second physical frame query request message is sent by the UE based on the AS security context, the middleman cannot crack or tamper with the second physical frame query request message and can only transmit it to the base station.
[0150] S311 , the base station determines whether the physical frame p matches the physical frame q.
[0151] Specifically, after receiving the second physical frame request message transparently transmitted by the middleman, the base station extracts the frame number and subframe number of physical frame p carried in the second physical frame query request message and compares them with the frame number and subframe number of physical frame q stored locally. If the frame number of physical frame p is the same as the frame number of physical frame q, and the subframe number of physical frame p is the same as the subframe number of physical frame q, it indicates that physical frame p and physical frame q match, and there is no middleman between the UE and the base station. Otherwise, it indicates that physical frame p and physical frame q do not match, and there is a middleman between the UE and the base station.
[0152] Optionally, in an NR system, when the time slot number of the physical frame is considered, the second physical frame query request message carries the frame number, subframe number, and time slot number of physical frame p, and compares them with the frame number, subframe number, and time slot number of the locally recorded physical frame q. When the frame number, subframe number, and time slot number of physical frame p are the same as those of physical frame q, respectively, it indicates that physical frame p and physical frame q match, and there is no middleman between the UE and the base station. Otherwise, it indicates that physical frame p and physical frame q do not match, and there is a middleman between the UE and the base station.
[0153] Optionally, when the base station determines that there is a middleman, it may issue a warning or take defensive measures.
[0154] Therefore, the method for detecting the middleman in an embodiment of the present application uses the fact that the physical frame of the uplink message sent by the middleman through the fake UE cannot be consistent with the physical frame of the uplink message sent by the real UE to perform middleman detection, which can prevent the middleman from using its own mechanism to bypass detection and improve the detection rate of the middleman.
[0155] Figure 6 FIG2 shows a schematic flow chart of another method 400 for detecting a man-in-the-middle according to an embodiment of the present application. Figure 6 As can be seen, method 400 includes:
[0156] S410, the UE sends a third RRC message to the base station in a third physical frame;
[0157] S420, the UE receives a fourth RRC message sent by the base station, where the fourth RRC message includes frame information of a fourth physical frame;
[0158] S430, the UE determines whether the third physical frame matches the fourth physical frame;
[0159] S440: The UE sends a fifth RRC message to the base station, where the fifth RRC message is used to indicate whether the third physical frame matches the fourth physical frame.
[0160] Specifically, after the UE successfully establishes the AS security context with the base station, it sends a third RRC message with security protection to the base station in the third physical frame. The third physical frame is the time domain resource specified by the base station (or pseudo base station) for the UE. The third RRC message is protected by the access layer AS security context established by the UE and the base station, so the middleman cannot crack or tamper with the third RRC message. When there is a man-in-the-middle attack, the air interface communication between the UE and the base station is intercepted by the middleman. The air interface between the UE and the pseudo base station is independent of the air interface between the pseudo UE and the base station, that is, the base station cannot directly receive the third RRC message sent by the UE. The middleman receives the third RRC message through the pseudo base station and forwards the third RRC message to the base station through the pseudo UE. The base station receives the third RRC message in the fourth physical frame and sends a fourth RRC message with security protection to the UE. The fourth RRC message includes frame information of the fourth physical frame. The UE receives the fourth RRC message, obtains the frame information of the fourth physical frame through the fourth RRC message, and determines whether the third physical frame and the fourth physical frame match. Because a man-in-the-middle attack occurs between the UE and the base station, the physical frame in which the UE sends the uplink message and the physical frame in which the base station receives the uplink message are inconsistent. Therefore, when the third physical frame and the fourth physical frame match, the UE determines that there is no man-in-the-middle between the UE and the base station; when the third physical frame and the fourth physical frame do not match, the UE determines that there is a man-in-the-middle between the UE and the base station. The UE then sends a fifth RRC message to the base station, which is used to indicate whether the third physical frame and the fourth physical frame match.
[0161] Therefore, the method for detecting a middleman in an embodiment of the present application determines whether there is a middleman in the air interface communication by judging whether the physical frame of the UE sending the uplink message matches the physical frame of the base station receiving the uplink message, thereby preventing the middleman from using its own mechanism to bypass detection and improving the detection rate of the middleman.
[0162] Figure 7 FIG2 shows a schematic flow chart of a method 500 for detecting a man-in-the-middle attack according to an embodiment of the present application when a man-in-the-middle attack occurs between a UE and a base station. Figure 7 As can be seen in FIG. 5 , the method 500 includes:
[0163] S510: An AS security context is established between the UE and the base station.
[0164] Specifically, a UE accesses a base station, establishing an indirect connection with the base station through an intermediary. The UE then establishes an access stratum (AS) security context with the base station. It should be understood that after the UE and base station establish an AS security context, RRC messages are protected, preventing an intermediary from tampering with RRC messages sent between the UE and base station.
[0165] S520: The middleman sends a fifth DCI to the UE, where the fifth DCI is used to determine a physical frame in which the UE sends an RRC message.
[0166] It should be understood that before S520, the UE sends a buffer status report (BSR) to the intermediary to indicate the amount of data in the uplink buffer, and then the intermediary sends the fifth DCI to the UE to allocate appropriate available resources to the UE. The UE determines the physical frame e according to the fifth DCI.
[0167] Optionally, the UE locally records the frame information of the physical frame e, where the frame information of the physical frame e includes the frame number and subframe number of the physical frame e.
[0168] It should be understood that before step S520, when the first preset rule is met, the UE initiates the middleman detection. Initiating the middleman detection means that the UE performs the method mentioned in this application. For example, initiating the middleman may include the UE sending a physical frame query request message and saving frame information of the physical frame e.
[0169] The first preset rule includes: the UE receiving indication information from the base station, where the indication information is used to instruct the UE to start man-in-the-middle detection; or determining that user plane integrity protection between the UE and the base station is not enabled.
[0170] Optionally, when a second preset rule is met, the base station sends an instruction message to the UE to instruct the UE to start man-in-the-middle detection. The second preset rule may be, for example, that a key performance indicator (KPI) is greater than a second threshold.
[0171] S530, the UE sends a physical frame query request message to the middleman.
[0172] Specifically, the UE sends a physical frame query request carried in an RRC message in physical frame e for middleman detection. The message is protected by the access layer AS security context established between the UE and the base station, and therefore cannot be tampered with by the middleman.
[0173] It should be understood that the physical frame query request message may be an empty RRC message.
[0174] S540: The base station sends a sixth DCI to the middleman, where the sixth DCI is used to determine a physical frame for the middleman to perform RRC communication.
[0175] Optionally, before S540, the intermediary sends a buffer status report (BSR) to the base station to indicate the amount of data in the uplink buffer. The intermediary then sends a fifth DCI to the UE to allocate appropriate available resources to the UE. The UE determines the physical frame f based on the sixth DCI.
[0176] S550: The middleman sends a physical frame query request message to the base station.
[0177] Specifically, the middleman receives the physical frame query request message sent by the UE in S530. Since the message has security protection, the middleman cannot tamper with it. Therefore, the middleman forwards the physical frame query request to the base station in the physical frame f indicated by the base station.
[0178] S560: The base station sends a physical frame query response message to the middleman.
[0179] Specifically, after the base station receives the physical frame query request message transmitted through the middleman in the physical frame f, it sends a physical frame query response message with security protection to the pseudo UE, and the physical frame query response message carries the frame information of the physical frame f, and the frame information of the physical frame f includes the frame number and subframe number of the physical frame f.
[0180] S570 , the middleman sends a physical frame query response message to the UE.
[0181] Specifically, after receiving the physical frame query response message sent by the base station, the middleman forwards the physical frame query response message to the UE through the pseudo base station.
[0182] S580: The UE determines whether the physical frame e matches the physical frame f.
[0183] Specifically, after the UE receives the physical frame query response message sent by the pseudo base station, it can extract the frame number and subframe number of the physical frame f carried in the physical frame query response message, and compare it with the frame number and subframe number of the physical frame e when the physical frame query request message was successfully sent, which is stored in the local record. If the frame number of physical frame e is the same as the frame number of physical frame f, and the subframe number of physical frame e is the same as the subframe number of physical frame f, it means that physical frame e and physical frame f match, and there is no middleman between the UE and the base station. Otherwise, it means that physical frame e and physical frame f do not match, and there is a middleman between the UE and the base station.
[0184] S590, the UE sends a physical frame query indication message to the base station.
[0185] Specifically, after determining whether physical frames e and f match, the UE sends a security-protected Physical Frame Query Indication message to the base station. The message is transparently transmitted by the middleman and received by the base station. The Physical Frame Query Indication message includes the determination result, indicating whether physical frames e and f match. If the base station determines the presence of a middleman based on the Physical Frame Query Indication message, it can issue a warning or take defensive measures.
[0186] Therefore, the method for detecting the middleman in an embodiment of the present application uses the fact that the physical frame of the uplink message sent by the middleman through the fake UE cannot be consistent with the physical frame of the uplink message sent by the real UE to perform middleman detection, which can prevent the middleman from using its own mechanism to bypass detection and improve the detection rate of the middleman.
[0187] Above, combined Figures 3 to 7 The method provided in the embodiment of the present application is described in detail. Figures 8 to 12 The communication device provided in the embodiments of the present application is described in detail.
[0188] Figure 8 FIG. 1 is a schematic block diagram of a communication device according to an embodiment of the present application. As shown in the figure, the communication device 10 may include a transceiver module 11 and a processing module 12.
[0189] In one possible design, the communication device 10 may correspond to the base station in the above method embodiment.
[0190] Specifically, the communication device 10 may correspond to the user equipment in the method 100, the method 200 and the method 300 according to the embodiment of the present application, and the communication device 10 may include a method for performing Figure 3 Method 100 or Figure 4 Method 200 or Figure 5 The modules of the method executed by the base station in the method 300. In addition, the units in the communication device 10 and the above-mentioned other operations and / or functions are respectively for implementing Figure 3 Method 100 or Figure 4 Method 200 or Figure 5 The corresponding process of method 300 in FIG.
[0191] Wherein, when the communication device 10 is used to perform Figure 3 When the method 100 is performed, the transceiver module 11 may be used to execute step S110 and step S120 in the method 100, and the processing module 12 may be used to execute step S130 in the method 100.
[0192] When the communication device 10 is used to perform Figure 4 When the method 200 is performed, the transceiver module 11 can be used to execute step S240, step S250 and step S260 in the method 200.
[0193] When the communication device 10 is used to perform Figure 5 When the method 300 is performed, the transceiver module 11 can be used to execute steps S340, S350 and S380 in the method 300, and the processing module 12 can be used to execute steps S360 and S390 in the method 300.
[0194] Specifically, the transceiver module 11 is used to receive a first radio resource control RRC message from a user equipment UE in a first physical frame; the transceiver module is also used to receive a second RRC message from the UE, and the second RRC message includes frame information of a second physical frame; wherein the first RRC message and the second RRC message are securely protected by an access layer AS security context established between the UE and the base station; and the processing module is used to determine whether the first physical frame matches the second physical frame.
[0195] Optionally, the processing module 12 can be specifically used to: when the frame number of the first physical frame is the same as the frame number of the second physical frame and the subframe number of the first physical frame is the same as the subframe number of the second physical frame, the base station determines that the first physical frame matches the second physical frame; otherwise, the base station determines that the first physical frame does not match the second physical frame.
[0196] Optionally, the processing module 12 is further configured to store frame information of the third physical frame.
[0197] Optionally, the processing module 12 is further configured to establish the AS security context with the UE.
[0198] Optionally, the transceiver module 11 is further used to send indication information to the UE, where the indication information is used to instruct the UE to send the fourth RRC message to the base station.
[0199] Figure 9 2 is a schematic block diagram of a communication device according to an embodiment of the present application. As shown in the figure, the communication device 20 may include a transceiver module 21 and a processing module 22.
[0200] In one possible design, the communication device 20 may correspond to the user equipment UE in the above method embodiment, or be configured with a chip in the UE.
[0201] Specifically, the communication device 20 may correspond to the base station in the method 100, the method 200 and the method 300 according to the embodiment of the present application, and the communication device 20 may include a method for performing Figure 3 Method 100 or Figure 4 Method 200 or Figure 5The modules of the method executed by the user equipment in the method 300. In addition, the units in the communication device 20 and the above-mentioned other operations and / or functions are respectively for implementing Figure 3 Method 100 or Figure 4 Method 200 or Figure 5 The corresponding process of method 300 in FIG.
[0202] Wherein, when the communication device 20 is used to perform Figure 3 When the method 100 is performed, the transceiver module 11 can be used to execute step S110 and step S120 in the method 100.
[0203] When the communication device 20 is used to perform Figure 4 When the method 200 is performed, the transceiver module 11 can be used to execute step S210, step S220 and step S230 in the method 200.
[0204] When the communication device 20 is used to perform Figure 5 When the method 300 is performed, the transceiver module 11 can be used to execute step S320, step S330 and step S370 in the method 300.
[0205] Specifically, the transceiver module 21 is used to send a first wireless resource control RRC message to the base station in the second physical frame; the transceiver module is also used to send a second RRC message to the base station, and the second RRC message includes frame information of the second physical frame; wherein the first RRC message and the second RRC message are securely protected by the access layer AS security context established by the UE and the base station.
[0206] Optionally, the transceiver module 21 is further configured to receive downlink control information DCI, where the DCI is used to determine frame information of the second physical frame.
[0207] Optionally, the processing module 22 is configured to save the frame information of the second physical frame.
[0208] Optionally, the processing module 22 is further configured to access the base station and establish the AS security context with the base station.
[0209] Optionally, the transceiver module 21 is specifically configured to, when a preset rule is met, enable the UE to send the first RRC message to the base station in the second physical frame.
[0210] Optionally, the processing module 22 is further configured to receive indication information sent by the base station, where the indication information is used to instruct the UE to start man-in-the-middle detection; or to determine that user plane integrity protection between the UE and the base station is not enabled.
[0211] Figure 103 is a schematic block diagram of a communication device provided in an embodiment of the present application. As shown in the figure, the communication device 30 may include a transceiver module 31 and a processing module 32.
[0212] In one possible design, the communication device 30 may correspond to the user equipment UE in the above method embodiment.
[0213] Specifically, the communication device 30 may correspond to the base station in the method 400 and the method 500 according to the embodiment of the present application, and the communication device 30 may include a method for performing Figure 6 Method 400 or Figure 7 The modules of the method executed by the UE in the method 500 are as follows. In addition, the units in the communication device 30 and the above-mentioned other operations and / or functions are respectively for implementing Figure 6 Method 400 or Figure 7 The corresponding process of method 500 in FIG.
[0214] Wherein, when the communication device 30 is used to perform Figure 6 When the method 400 is performed, the transceiver module 41 may be used to execute step S410 and step S420 in the method 400, and the processing module 42 may be used to execute step S430 in the method 400.
[0215] When the communication device 30 is used to perform Figure 7 When the method 500 is performed, the transceiver module 41 can be used to execute step S520, step S530, step S570 and step S590 in the method 500, and the processing module 42 can be used to execute step S580 in the method 500.
[0216] Specifically, the transceiver module 31 is used to send a third wireless resource control RRC message to the base station in the third physical frame; the transceiver module is also used to receive a fourth RRC message from the base station, and the fourth RRC message includes frame information of the fourth physical frame; the transceiver module is also used to send a fifth RRC message to the base station, and the fifth RRC message is used to indicate whether the third physical frame matches the fourth physical frame; wherein the third RRC message, the fourth RRC message and the fifth RRC message are securely protected by the access layer AS security context established by the UE and the base station.
[0217] Optionally, the processing module 32 can be specifically used to determine that the UE matches the third physical frame when the frame number of the third physical frame is the same as the frame number of the fourth physical frame and the subframe number of the third physical frame is the same as the subframe number of the fourth physical frame; otherwise, the UE determines that the third physical frame does not match the fourth physical frame.
[0218] Optionally, the transceiver module 31 is further configured to receive downlink control information DCI, where the DCI is used to determine frame information of the third physical frame, where the frame information of the third physical frame includes a frame number and a subframe number of the third physical frame;
[0219] Optionally, the processing module 32 is further configured to store frame information of the third physical frame.
[0220] Optionally, the processing module 32 is further configured to access the base station and establish the AS security context with the base station.
[0221] Figure 11 FIG. 3 is a schematic block diagram of a communication device according to an embodiment of the present application. As shown in the figure, the communication device 30 may include a transceiver module 41 and a processing module 42.
[0222] In one possible design, the communication device 40 may correspond to the base station in the above method embodiment.
[0223] Specifically, the communication device 40 may correspond to the base station in the method 400 and the method 500 according to the embodiment of the present application, and the communication device 40 may include a method for performing Figure 6 Method 400 or Figure 7 The modules of the method executed by the base station in the method 500 are as follows. In addition, the units in the communication device 30 and the above-mentioned other operations and / or functions are respectively for implementing Figure 6 Method 400 or Figure 7 The corresponding process of method 500 in FIG.
[0224] Wherein, when the communication device 40 is used to perform Figure 6 When the method 400 is performed, the transceiver module 41 can be used to execute step S410, step S420 and step S440 in the method 400.
[0225] When the communication device 40 is used to perform Figure 7 When the method 500 is performed, the transceiver module 41 can be used to execute step S540, step S550, step S560 and step S590 in the method 500, and the processing module 42 can be used to execute step S510 in the method 500.
[0226] Specifically, the transceiver module 41 is used to receive a third RRC message from a user equipment UE in a fourth physical frame; the transceiver module is also used to send a fourth RRC message to the UE, where the fourth RRC message includes frame information of the fourth physical frame; the transceiver module is also used to receive a fifth RRC message sent by the UE; the processing module is used to determine whether there is an intermediary between the base station and the UE based on the fifth RRC message.
[0227] Optionally, the processing module 42 can be specifically used to determine that there is a middleman between the UE when the third physical frame does not match the fourth physical frame; or, when the third physical frame matches the fourth physical frame, determine that there is no middleman between the UE.
[0228] Optionally, the processing module 42 is further configured to establish the AS security context with the UE.
[0229] Optionally, the transceiver module 41 is further configured to send indication information to the UE, where the indication information is used to instruct the UE to start man-in-the-middle detection.
[0230] According to the above method, Figure 12 A schematic diagram of a communication device 50 provided in an embodiment of the present application is shown as follows: Figure 12 As shown, the apparatus 50 can be a device that needs to detect a man-in-the-middle, including various handheld devices with wireless communication functions, vehicle-mounted devices, wearable devices, computing devices or other processing devices connected to a wireless modem, as well as various forms of terminals, mobile stations (MS), terminals, user equipment UE, soft terminals, etc.
[0231] The device 50 may include a processor 51 (ie, an example of a processing module) and a memory 52. The memory 52 is used to store instructions, and the processor 51 is used to execute the instructions stored in the memory 52, so that the device 30 can implement the following Figure 3 、 Figure 4 、 Figure 5 、 Figure 6 or Figure 7 Steps performed by the device that registers on the network in the corresponding method.
[0232] Furthermore, the device 50 may also include an input port 53 (i.e., an example of a transceiver module) and an output port 54 (i.e., another example of a transceiver module). Furthermore, the processor 51, memory 52, input port 53, and output port 54 may communicate with each other via internal connection paths to transmit control and / or data signals. The memory 32 is used to store a computer program, and the processor 51 may be used to call and execute the computer program from the memory 52 to control the input port 53 to receive signals and the output port 54 to send signals, thereby completing the steps of the terminal device in the above method. The memory 52 may be integrated into the processor 51 or provided separately from the processor 51.
[0233] Alternatively, if the communication device 50 is a communication device, the input port 53 is a receiver and the output port 54 is a transmitter. The receiver and transmitter may be the same or different physical entities. When they are the same physical entity, they may be collectively referred to as a transceiver.
[0234] Optionally, if the communication device 50 is a chip or a circuit, the input port 53 is an input interface, and the output port 54 is an output interface.
[0235] As an implementation method, the functions of the input port 53 and the output port 54 can be implemented by a transceiver circuit or a dedicated transceiver chip. The processor 51 can be implemented by a dedicated processing chip, a processing circuit, a processor or a general-purpose chip.
[0236] As another implementation, it is possible to use a general-purpose computer to implement the communication device provided in the embodiments of the present application. Specifically, the program code that implements the functions of the processor 51, input port 53, and output port 54 is stored in the memory 52, and the general-purpose processor executes the code in the memory 52 to implement the functions of the processor 51, input port 53, and output port 54.
[0237] Among them, each module or unit in the communication device 50 can be used to execute each action or processing process performed by the device (e.g., user equipment) for detecting the middleman in the above method. Here, in order to avoid redundancy, its detailed description is omitted.
[0238] For the concepts, explanations, detailed descriptions and other steps involved in the device 50 and related to the technical solutions provided in the embodiments of the present application, please refer to the descriptions of these contents in the aforementioned methods or other embodiments, and will not be repeated here.
[0239] According to the above method, Figure 13 A schematic diagram of a communication device 60 provided in an embodiment of the present application is shown as follows: Figure 10 As shown, the device 60 can be a device for detecting middlemen, including a network element with access management function, such as AMF.
[0240] The device 60 may include a processor 61 (ie, an example of a processing module) and a memory 62. The memory 62 is used to store instructions, and the processor 61 is used to execute the instructions stored in the memory 62, so that the device 60 can implement the following Figure 3 、 Figure 4 、 Figure 5 、 Figure 6 or Figure 7 The corresponding method performs steps for detecting the execution of the middleman's device.
[0241] Furthermore, the device 60 may also include an input port 63 (i.e., an example of a transceiver module) and an output port 64 (i.e., another example of a transceiver module). Furthermore, the processor 61, memory 62, input port 63, and output port 64 may communicate with each other via internal connection paths to transmit control and / or data signals. The memory 62 is used to store a computer program, and the processor 61 may be used to call and execute the computer program from the memory 62 to control the input port 63 to receive signals and the output port 64 to send signals, thereby completing the steps of the terminal device in the above method. The memory 62 may be integrated into the processor 61 or provided separately from the processor 61.
[0242] Alternatively, if the communication device 60 is a communication device, the input port 63 is a receiver and the output port 64 is a transmitter. The receiver and transmitter may be the same or different physical entities. When they are the same physical entity, they may be collectively referred to as a transceiver.
[0243] Optionally, if the communication device 60 is a chip or a circuit, the input port 63 is an input interface, and the output port 44 is an output interface.
[0244] As an implementation method, the functions of the input port 63 and the output port 64 can be implemented by a transceiver circuit or a dedicated transceiver chip. The processor 61 can be implemented by a dedicated processing chip, a processing circuit, a processor or a general-purpose chip.
[0245] As another implementation, it is possible to use a general-purpose computer to implement the communication device provided in the embodiments of the present application. Specifically, the program code that implements the functions of the processor 61, input port 63, and output port 64 is stored in the memory 62, and the general-purpose processor executes the code in the memory 62 to implement the functions of the processor 61, input port 63, and output port 64.
[0246] Among them, each module or unit in the communication device 60 can be used to execute each action or processing process performed by the network side device (ie, network device) during network registration in the above method. Here, in order to avoid redundancy, its detailed description is omitted.
[0247] For the concepts, explanations, detailed descriptions and other steps involved in the device 60 and related to the technical solutions provided in the embodiments of the present application, please refer to the descriptions of these contents in the aforementioned methods or other embodiments, which are not repeated here.
[0248] Figure 14 This is a schematic diagram of the structure of a terminal device 500 provided in this application. For ease of explanation, Figure 14 Only the main components of the terminal device are shown. Figure 14As shown, the terminal device 500 includes a processor, a memory, a control circuit, an antenna, and an input and output device.
[0249] The processor is primarily used to process communication protocols and communication data, control the entire terminal device, execute software programs, and process software program data, such as supporting the terminal device in executing the actions described in the embodiment of the method for indicating a transmission precoding matrix. The memory is primarily used to store software programs and data, such as the codebook described in the above embodiment. The control circuit is primarily used to convert baseband signals into radio frequency signals and process radio frequency signals. The control circuit and antenna together are also called a transceiver, which is primarily used to transmit and receive radio frequency signals in the form of electromagnetic waves. Input and output devices, such as touch screens, displays, and keyboards, are primarily used to receive user input and output data to the user.
[0250] When the terminal device is powered on, the processor reads the software program stored in the storage unit, interprets and executes the program's instructions, and processes the program's data. When data needs to be transmitted wirelessly, the processor performs baseband processing on the data to be transmitted and outputs the baseband signal to the RF circuit. The RF circuit then performs RF processing on the baseband signal and transmits it via the antenna as electromagnetic waves. When data is sent to the terminal device, the RF circuit receives the RF signal via the antenna, converts it into a baseband signal, and outputs the baseband signal to the processor, which converts the baseband signal into data and processes it.
[0251] Those skilled in the art will understand that for ease of explanation, Figure 14 Only one memory and processor are shown. In an actual terminal device, there may be multiple processors and memories. The memory may also be referred to as a storage medium or a storage device, etc., which is not limited in the embodiments of the present application.
[0252] As an optional implementation, the processor may include a baseband processor and a central processing unit. The baseband processor is mainly used to process communication protocols and communication data, and the central processing unit is mainly used to control the entire terminal device, execute software programs, and process software program data. Figure 14The processor in the embodiment integrates the functions of the baseband processor and the central processing unit. Those skilled in the art will appreciate that the baseband processor and the central processing unit may also be independent processors interconnected through technologies such as buses. Those skilled in the art will appreciate that a terminal device may include multiple baseband processors to adapt to different network standards, and a terminal device may include multiple central processing units to enhance its processing capabilities, and the various components of the terminal device may be connected through various buses. The baseband processor may also be expressed as a baseband processing circuit or a baseband processing chip. The central processing unit may also be expressed as a central processing circuit or a central processing chip. The function of processing the communication protocol and communication data may be built into the processor, or may be stored in a storage unit in the form of a software program, and the processor executes the software program to implement the baseband processing function.
[0253] like Figure 14 As shown, terminal device 700 includes a transceiver unit 710 and a processing unit 720. The transceiver unit may also be referred to as a transceiver, transceiver, transceiver device, etc. Optionally, the device in transceiver unit 710 that implements the receiving function may be considered a receiving unit, and the device in transceiver unit 710 that implements the transmitting function may be considered a transmitting unit, that is, the transceiver unit 510 includes a receiving unit and a transmitting unit. For example, the receiving unit may also be referred to as a receiver, receiver, receiving circuit, etc., and the transmitting unit may be referred to as a transmitter, transmitter, or transmitting circuit, etc.
[0254] Figure 14 The terminal device shown can execute each action executed by the user equipment in the above-mentioned method 100, 200, 300, 400 or 500. Here, in order to avoid redundancy, its detailed description is omitted.
[0255] It should be understood that in the embodiments of the present application, the processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0256] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0257] The above embodiments can be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0258] It should be understood that the term "and / or" in this document simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document generally indicates that the related objects are in an "or" relationship.
[0259] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0260] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application. Those skilled in the art will clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here. In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. On the other hand, the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, which may be electrical, mechanical or other forms.
[0261] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed across multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. In addition, the functional units in the various embodiments of the present application may be integrated into a processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit. If the functions are implemented in the form of software functional units and sold or used as independent products, they may be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or the part of the technical solution, may be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for enabling a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage media include: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc., which can store program codes.
[0262] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A method for detecting a man-in-the-middle, characterized in that: include: The base station receives a first radio resource control RRC message from a user equipment UE in a first physical frame; The base station receives a second RRC message from the UE, where the second RRC message includes frame information of a second physical frame; wherein the first RRC message and the second RRC message are securely protected by an access layer AS security context established between the UE and the base station; and the second physical frame is a physical frame in which the UE sends the first RRC message; determining, by the base station, whether the first physical frame matches the second physical frame; When the first physical frame and the second physical frame match, the base station determines that there is no middleman between the UE and the base station; when the first physical frame and the second physical frame do not match, the base station determines that there is a middleman between the UE and the base station.
2. The method according to claim 1, characterized in that The frame information of the second physical frame includes a frame number and a subframe number of the second physical frame.
3. The method according to claim 2, characterized in that The base station determining whether the first physical frame matches the second physical frame includes: When the frame number of the first physical frame is the same as the frame number of the second physical frame and the subframe number of the first physical frame is the same as the subframe number of the second physical frame, the base station determines that the first physical frame matches the second physical frame; otherwise, the base station determines that the first physical frame does not match the second physical frame.
4. The method according to any one of claims 1 to 3, characterized in that After the base station receives a first radio resource control RRC message from the UE in the first physical frame, the method further includes: The base station stores frame information of the first physical frame.
5. The method according to any one of claims 1 to 3, characterized in that Before the base station receives a first radio resource control RRC message from the UE in the first physical frame, the method further includes: The base station establishes the AS security context with the UE.
6. The method according to any one of claims 1 to 3, characterized in that Before the base station receives the first RRC message from the UE in the first physical frame, the method further includes: The base station sends indication information to the UE, where the indication information is used to instruct the UE to start man-in-the-middle detection.
7. A method for detecting a man-in-the-middle, characterized in that: include: The user equipment UE sends a first radio resource control RRC message to the base station in the second physical frame; The UE sends a second RRC message to the base station, where the second RRC message includes frame information of the second physical frame; wherein the first RRC message and the second RRC message are securely protected by an access layer AS security context established between the UE and the base station; The second physical frame and the first physical frame are used to determine the matching, and when the first physical frame and the second physical frame match, there is no middleman between the UE and the base station; when the first physical frame and the second physical frame do not match, there is a middleman between the UE and the base station; The first physical frame is a physical frame in which the base station receives the first RRC message.
8. The method according to claim 7, characterized in that The frame information of the second physical frame includes a frame number and a subframe number of the second physical frame.
9. The method according to claim 7 or 8, characterized in that Before the user equipment UE sends the first radio resource control RRC message to the base station in the second physical frame, the method further includes: The UE receives downlink control information DCI, where the DCI is used to determine frame information of the second physical frame; The UE stores the frame information of the second physical frame.
10. The method according to claim 7 or 8, characterized in that Before the user equipment UE sends the first radio resource control RRC message to the base station in the second physical frame, the method further includes: The UE accesses the base station and establishes the AS security context with the base station.
11. The method according to claim 7 or 8, characterized in that The user equipment UE sends a first radio resource control RRC message to the base station in the second physical frame, including: When a preset rule is met, the UE sends the first RRC message to the base station in the second physical frame.
12. The method according to claim 11, characterized in that The preset rules include: The UE receives instruction information sent by the base station, where the instruction information is used to instruct the UE to start man-in-the-middle detection; or The UE determines that user plane integrity protection between the UE and the base station is not enabled.
13. A method for detecting a man-in-the-middle, characterized in that: include: The user equipment UE sends a third radio resource control RRC message to the base station in a third physical frame; The UE receives a fourth RRC message from the base station, where the fourth RRC message includes frame information of a fourth physical frame; the fourth physical frame is a physical frame in which the base station receives the third RRC message; The UE determines, by the user equipment (UE), whether the third physical frame matches the fourth physical frame; wherein, when the third physical frame matches the fourth physical frame, the UE determines that there is no middleman between the UE and the base station; and when the third physical frame does not match the fourth physical frame, the UE determines that there is a middleman between the UE and the base station; The UE sends a fifth RRC message to the base station, where the fifth RRC message is used to indicate whether the third physical frame matches the fourth physical frame; wherein the third RRC message, the fourth RRC message and the fifth RRC message are securely protected by the access layer AS security context established between the UE and the base station.
14. The method according to claim 13, characterized in that The frame information of the fourth physical frame includes the frame number and subframe number of the fourth physical frame.
15. The method according to claim 14, characterized in that The UE determining whether the third physical frame matches the fourth physical frame includes: When the frame number of the third physical frame is the same as the frame number of the fourth physical frame and the subframe number of the third physical frame is the same as the subframe number of the fourth physical frame, the UE determines that the third physical frame matches the fourth physical frame; otherwise, the UE determines that the third physical frame does not match the fourth physical frame.
16. The method according to any one of claims 13 to 15, characterized in that Before the user equipment UE sends the third radio resource control RRC message to the base station in the third physical frame, the method further includes: The UE receives downlink control information DCI, where the DCI is used to determine frame information of the third physical frame, where the frame information of the third physical frame includes a frame number and a subframe number of the third physical frame; The UE stores the frame information of the third physical frame.
17. The method according to any one of claims 13 to 15, characterized in that Before the user equipment UE sends the third radio resource control RRC message to the base station in the third physical frame, the method further includes: The UE accesses the base station and establishes the AS security context with the base station.
18. The method according to any one of claims 13 to 15, characterized in that The user equipment UE sends a third radio resource control RRC message to the base station in a third physical frame, including: When a preset rule is met, the UE sends the third RRC message to the base station in the third physical frame.
19. The method according to claim 18, characterized in that The preset rules include: The UE receives instruction information sent by the base station, where the instruction information is used to instruct the UE to start man-in-the-middle detection; or The UE determines that user plane integrity protection between the UE and the base station is not enabled.
20. A method for detecting a man-in-the-middle, characterized in that: include: The base station receives a third RRC message from the user equipment UE in a fourth physical frame; Sending, by the base station, a fourth RRC message to the UE, where the fourth RRC message includes frame information of the fourth physical frame; The base station receives a fifth RRC message sent by the UE, where the fifth RRC message is used to indicate whether a third physical frame matches the fourth physical frame, and the third physical frame is a physical frame in which the UE sends the third RRC message; wherein the third RRC message, the fourth RRC message, and the fifth RRC message are securely protected by an access stratum AS security context established between the UE and the base station; determining, by the base station, based on the fifth RRC message, whether there is a middleman between the base station and the UE; The base station determining, according to the fifth RRC message, whether there is a middleman between the base station and the UE includes: In a case where the third physical frame does not match the fourth physical frame, the base station determines that there is a middleman between the base station and the UE; or, In a case where the third physical frame matches the fourth physical frame, the base station determines that no middleman exists between the base station and the UE.
21. The method according to claim 20, characterized in that The frame information of the fourth physical frame includes the frame number and subframe number of the fourth physical frame.
22. The method according to claim 20 or 21, characterized in that Before the base station receives a third RRC message sent by the user equipment UE in the fourth physical frame, the method further includes: The base station establishes the AS security context with the UE.
23. The method according to claim 20 or 21, characterized in that Before the base station receives a third RRC message sent by the user equipment UE in the fourth physical frame, the method further includes: The base station sends indication information to the UE, where the indication information is used to instruct the UE to start man-in-the-middle detection.
24. A device for detecting a man-in-the-middle, characterized in that: include: A transceiver module, configured to receive a first radio resource control RRC message from a user equipment UE in a first physical frame; The transceiver module is further configured to receive a second RRC message from the UE, where the second RRC message includes frame information of a second physical frame; wherein the first RRC message and the second RRC message are securely protected by an access layer AS security context established between the UE and the base station; and the second physical frame is a physical frame for the UE to send the first RRC message; A processing module is used to determine whether the first physical frame matches the second physical frame, wherein when the first physical frame and the second physical frame match, it is determined that there is no middleman between the UE and the base station; when the first physical frame and the second physical frame do not match, it is determined that there is a middleman between the UE and the base station.
25. The device according to claim 24, characterized in that The frame information of the second physical frame includes a frame number and a subframe number of the second physical frame.
26. The device according to claim 25, characterized in that The processing module is specifically used for: When the frame number of the first physical frame is the same as the frame number of the second physical frame and the subframe number of the first physical frame is the same as the subframe number of the second physical frame, the base station determines that the first physical frame matches the second physical frame; otherwise, the base station determines that the first physical frame does not match the second physical frame.
27. The device according to any one of claims 24 to 26, characterized in that The processing module is further configured to: The frame information of the first physical frame is saved.
28. The device according to any one of claims 24 to 26, characterized in that The processing module is further configured to: Establishing the AS security context with the UE.
29. The device according to any one of claims 24 to 26, characterized in that The transceiver module is also used for: Sending indication information to the UE, where the indication information is used to instruct the UE to start man-in-the-middle detection.
30. A device for detecting a man-in-the-middle, characterized in that: include: A transceiver module, configured to send a first radio resource control RRC message to the base station in a second physical frame; The transceiver module is further configured to send a second RRC message to the base station, where the second RRC message includes frame information of the second physical frame; wherein the first RRC message and the second RRC message are securely protected by an access layer AS security context established between a user equipment UE and the base station; The second physical frame and the first physical frame are used to determine the matching, and when the first physical frame and the second physical frame match, there is no middleman between the UE and the base station; when the first physical frame and the second physical frame do not match, there is a middleman between the UE and the base station; The first physical frame is a physical frame in which the base station receives the first RRC message.
31. The device according to claim 30, characterized in that The frame information of the second physical frame includes a frame number and a subframe number of the second physical frame.
32. The device according to claim 30 or 31, characterized in that The transceiver module is also used for: receiving downlink control information DCI, where the DCI is used to determine frame information of the second physical frame; The device further includes a processing module, which is configured to store frame information of the second physical frame.
33. The device according to claim 30 or 31, characterized in that The device further includes a processing module, which is further configured to: access the base station and establish the AS security context with the base station.
34. The device according to claim 30 or 31, characterized in that The transceiver module is specifically used for: When a preset rule is met, the UE sends the first RRC message to the base station in the second physical frame.
35. The device according to claim 34, characterized in that The preset rules include: The UE receives instruction information sent by the base station, where the instruction information is used to instruct the UE to start man-in-the-middle detection; or The UE determines that user plane integrity protection between the UE and the base station is not enabled.
36. A device for detecting a man-in-the-middle, characterized in that: include: a transceiver module, configured to send a third radio resource control RRC message to the base station in a third physical frame; The transceiver module is further configured to receive a fourth RRC message from the base station, where the fourth RRC message includes frame information of a fourth physical frame; the fourth physical frame is a physical frame in which the base station receives the third RRC message; The transceiver module is further configured to send a fifth RRC message to the base station, where the fifth RRC message is used to indicate whether the third physical frame matches the fourth physical frame; wherein the third RRC message, the fourth RRC message, and the fifth RRC message are securely protected by an access layer AS security context established between a user equipment UE and the base station; A processing module is used to determine whether the third physical frame matches the fourth physical frame, wherein when the third physical frame and the fourth physical frame match, it is determined that there is no middleman between the UE and the base station; when the third physical frame and the fourth physical frame do not match, it is determined that there is a middleman between the UE and the base station.
37. The device according to claim 36, characterized in that The frame information of the fourth physical frame includes the frame number and subframe number of the fourth physical frame.
38. The device according to claim 37, characterized in that The processing module is specifically used for: When the frame number of the third physical frame is the same as the frame number of the fourth physical frame and the subframe number of the third physical frame is the same as the subframe number of the fourth physical frame, the UE determines that the third physical frame matches the fourth physical frame; otherwise, the UE determines that the third physical frame does not match the fourth physical frame.
39. The device according to any one of claims 36 to 38, characterized in that The transceiver module is also used for: receiving downlink control information DCI, where the DCI is used to determine frame information of the third physical frame, where the frame information of the third physical frame includes a frame number and a subframe number of the third physical frame; The processing module is further configured to: save the frame information of the third physical frame.
40. The device according to any one of claims 36 to 38, characterized in that The processing module is further configured to: Access the base station and establish the AS security context with the base station.
41. The device according to any one of claims 36 to 38, characterized in that The transceiver module is also used for: When a preset rule is met, the UE sends the third RRC message to the base station in the third physical frame.
42. The device according to claim 41, characterized in that The preset rules include: The UE receives instruction information sent by the base station, where the instruction information is used to instruct the UE to start man-in-the-middle detection; or The UE determines that user plane integrity protection between the UE and the base station is not enabled.
43. A device for detecting a man-in-the-middle, characterized in that: include: a transceiver module, configured to receive a third RRC message from a user equipment UE in a fourth physical frame; The transceiver module is further configured to send a fourth RRC message to the UE, where the fourth RRC message includes frame information of the fourth physical frame; The transceiver module is further configured to receive a fifth RRC message sent by the UE; the fifth RRC message is used to indicate whether a third physical frame matches the fourth physical frame, and the third physical frame is a physical frame in which the UE sends the third RRC message; wherein the third RRC message, the fourth RRC message, and the fifth RRC message are securely protected by an access layer AS security context established between the UE and the base station; a processing module, configured to determine, according to the fifth RRC message, whether there is a middleman between the base station and the UE; The processing module is specifically configured to: In a case where the third physical frame does not match the fourth physical frame, determining that there is a middleman between the UE and the UE; or In a case where the third physical frame matches the fourth physical frame, it is determined that no middleman exists between the UE and the third physical frame.
44. The device according to claim 43, characterized in that The frame information of the fourth physical frame includes the frame number and subframe number of the fourth physical frame.
45. The device according to claim 43 or 44, characterized in that The processing module is further configured to establish the AS security context with the UE.
46. The device according to claim 43 or 44, characterized in that The transceiver module is also used for: Sending indication information to the UE, where the indication information is used to instruct the UE to start man-in-the-middle detection.
47. A communication device, characterized in that include: A processor for executing a computer program stored in a memory so that the communication device performs the method for detecting a middleman as described in any one of claims 1 to 6, or performs the method for detecting a middleman as described in any one of claims 7 to 12, or performs the method for detecting a middleman as described in any one of claims 13 to 19, or performs the method for detecting a middleman as described in any one of claims 20 to 23.
48. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed on a computer, enables the computer to execute the method for detecting a middleman according to any one of claims 1 to 6, or the method for detecting a middleman according to any one of claims 7 to 12, or the method for detecting a middleman according to any one of claims 13 to 19, or the method for detecting a middleman according to any one of claims 20 to 23.
49. A chip system, characterized in that include: A processor for calling and running a computer program from a memory so that a communication device equipped with the chip system executes the method for detecting a middleman according to any one of claims 1 to 6, or executes the method for detecting a middleman according to any one of claims 7 to 12, or executes the method for detecting a middleman according to any one of claims 13 to 19, or executes the method for detecting a middleman according to any one of claims 20 to 23.
Citation Information
Patent Citations
Information processing method and device, equipment and computer readable storage medium
CN110545253A