Air interface data security transmission method and device

CN117896720BActive Publication Date: 2026-09-25STATE GRID HEBEI ELECTRIC POWER CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311694724.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-11
Publication Date
2026-09-25
Estimated Expiration
2043-12-11

AI Technical Summary

Technical Problem

但是这种方式是对所有数据都进行相同形式的加密,难以保证不同种类的数据都能够满足相应的传输要求

Benefits of technology

[0048]本发明实施例通过确定目标空口数据的切片类型,能够明确目标空口数据的类型和相应的传输要求;通过切片类型和目标空口数据获取时的时间戳,确定加密方式,能够使加密方式更符合目标空口数据的传输要求,保证加密后的数据满足相应的时效性和传输质量;通过密文、切片类型、时间戳和分段数量,确定待发送数据,能够将切片类型、时间戳和分段数量发送至接收端,以确保接收端能够进行相应的解密,保证数据的准确接收。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117896720B_ABST
    Figure CN117896720B_ABST
Patent Text Reader

Abstract

The application provides an air interface data security transmission method and device, and belongs to the field of data encryption. The method comprises the following steps: obtaining target air interface data and a slice type corresponding to the target air interface data; segmenting the target air interface data to obtain a plurality of segmented data; determining a plurality of encryption modes according to the slice type and a timestamp when the target air interface data is obtained; encrypting the plurality of segmented data according to the plurality of encryption modes to obtain ciphertext of the target air interface data; determining to-be-sent data according to the ciphertext, the slice type, the timestamp and the number of segments, and sending the to-be-sent data to a preset receiving end. The application can make the encrypted air interface data meet the transmission requirements of data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data encryption technology, and in particular to a method and apparatus for secure air interface data transmission. Background Technology

[0002] During network use, user terminals and base stations transmit data via air interface. Because air interface transmission relies on a shared medium, the transmitted data is susceptible to interception, theft, and tampering. Therefore, protecting the security of air interface transmitted data is crucial.

[0003] In related technologies, data is primarily encrypted using encryption algorithms to reduce the risk of data leakage by transmitting encrypted data. However, this method applies the same form of encryption to all data, making it difficult to guarantee that different types of data can meet their respective transmission requirements. Summary of the Invention

[0004] This invention provides a method and apparatus for secure air interface data transmission, so that encrypted air interface data meets data transmission requirements.

[0005] In a first aspect, embodiments of the present invention provide a method for secure air interface data transmission, comprising:

[0006] Obtain the target air interface data and the slice type corresponding to the target air interface data;

[0007] The target air interface data is segmented to obtain multiple segmented data;

[0008] Based on the slice type and the timestamp when the target air interface data was acquired, multiple encryption methods are determined;

[0009] The multiple segments of data are encrypted using the various encryption methods to obtain the ciphertext of the target air interface data;

[0010] Based on the ciphertext, the slice type, the timestamp, and the number of segments, the data to be sent is determined and sent to the preset receiving end.

[0011] In one possible implementation, each segment of the target air interface data corresponds to a segment number;

[0012] The method of determining multiple encryption methods based on the slice type and the timestamp when the target air interface data was acquired includes:

[0013] Based on the slice type, the encryption library corresponding to the target air interface data is determined, wherein the encryption library includes multiple keys and multiple encryption functions, wherein different keys carry different encryption parameters, and different encryption functions carry different encryption parameters;

[0014] Based on the timestamp and the segment number of each segment of data, the encryption parameters corresponding to each segment of data are determined respectively;

[0015] Based on the encryption library and the encryption parameters corresponding to each data segment, the key and encryption function corresponding to each data segment are determined, and the encryption method of each data segment is obtained based on the key and encryption function corresponding to each data segment.

[0016] In one possible implementation, encrypting the multiple segmented data according to the multiple encryption methods to obtain the ciphertext of the target air interface data includes:

[0017] When the slice type corresponding to the target air interface data is the first type, the corresponding segment data is encrypted according to the encryption method corresponding to each segment data to obtain the encrypted data corresponding to each segment data.

[0018] Based on the encrypted data corresponding to each segment of data, the ciphertext of the target air interface data is obtained.

[0019] In one possible implementation, encrypting the multiple segmented data according to the multiple encryption methods to obtain the ciphertext of the target air interface data includes:

[0020] When the slice type corresponding to the target air interface data is the second type, the first segment data is encrypted according to the encryption method of the first segment data to obtain the first encrypted data;

[0021] Based on the encryption method of the second segment data, the first encrypted data and the second segment data are encrypted to obtain the second encrypted data;

[0022] For each data segment after the second data segment, the encrypted data segment and the encrypted data before it are encrypted in sequence according to the encryption method of each data segment until the encryption of all data segments is completed, and the ciphertext of the target air interface data is obtained.

[0023] In one possible implementation, encrypting the multiple segmented data according to the multiple encryption methods to obtain the ciphertext of the target air interface data includes:

[0024] When the slice type corresponding to the target air interface data is the third type, determine whether the number of segments of the target air interface data is greater than the preset number;

[0025] If the number of segments is greater than the preset number, then multiple groups are determined according to the preset number, wherein each group includes multiple segment data;

[0026] For each group, the first segment of data in the group is encrypted according to the encryption method corresponding to the first segment of data in the group to obtain the third encrypted data; the second segment of data in the group and the third encrypted data are encrypted according to the encryption method corresponding to the second segment of data in the group to obtain the fourth encrypted data; for each segment of data after the second segment of data in the group, the encrypted data of that segment and the encrypted data before that segment are encrypted in turn according to the encryption method of each segment of data in the group, until the encryption of all segment data in the group is completed to obtain the encrypted data of the group;

[0027] By concatenating the encrypted data of each group, the ciphertext of the target air interface data is obtained.

[0028] In one possible implementation, after determining whether the number of segments of the target air interface data is greater than a preset number, the method further includes:

[0029] If the number of segments is less than or equal to the preset number, then each segment of data is encrypted simultaneously according to the encryption method corresponding to each segment of data, so as to obtain the encrypted data corresponding to each segment of data.

[0030] By connecting the encrypted data corresponding to each segment of data, the ciphertext of the target air interface data is obtained.

[0031] In one possible implementation, determining the data to be sent based on the ciphertext, the slice type, the timestamp, and the number of segments includes:

[0032] The slice type, the timestamp, and the number of segments are combined according to a preset combination method;

[0033] The combined slice type, timestamp, and number of segments are set at preset positions in the ciphertext to obtain the data to be sent.

[0034] In one possible implementation, before sending the data to be sent to the preset receiving end, the method further includes:

[0035] The data to be sent is randomly filled according to the timestamp to obtain the updated data to be sent.

[0036] Sending the data to be sent to the preset receiving end includes:

[0037] The updated data to be sent is sent to the preset receiving end.

[0038] In one possible implementation, segmenting the target air interface data to obtain multiple segmented data includes:

[0039] Determine the data size of the target air interface data;

[0040] Based on the preset upper limit of segmented data size and the data size of the target air interface data, the target air interface data is segmented to obtain multiple segmented data.

[0041] Secondly, embodiments of the present invention provide an air interface data secure transmission device, comprising:

[0042] The acquisition module is used to acquire the target air interface data and the slice type corresponding to the target air interface data;

[0043] The segmentation module is used to segment the target air interface data to obtain multiple segmented data.

[0044] The determination module is used to determine multiple encryption methods based on the slice type and the timestamp when the target air interface data is acquired;

[0045] An encryption module is used to encrypt the multiple segmented data according to the multiple encryption methods to obtain the ciphertext of the target air interface data;

[0046] The sending module is used to determine the data to be sent based on the ciphertext, the slice type, the timestamp, and the number of segments, and to send the data to be sent to a preset receiving end.

[0047] The beneficial effects of the embodiments of the present invention compared with the prior art are as follows:

[0048] This invention, through determining the slice type of the target air interface data, clarifies the type of the target air interface data and its corresponding transmission requirements. By determining the encryption method based on the slice type and the timestamp at the time of acquisition of the target air interface data, the encryption method can be made more suitable for the transmission requirements of the target air interface data, ensuring that the encrypted data meets the corresponding timeliness and transmission quality. By determining the data to be sent through the ciphertext, slice type, timestamp, and number of segments, the slice type, timestamp, and number of segments can be sent to the receiving end to ensure that the receiving end can perform the corresponding decryption, thus ensuring accurate data reception. Attached Figure Description

[0049] To more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0050] Figure 1 This is an application scenario diagram of the air interface data secure transmission method provided in the embodiments of the present invention;

[0051] Figure 2 This is a flowchart illustrating the implementation of the secure air interface data transmission method provided in this embodiment of the invention.

[0052] Figure 3 This is a schematic diagram of the first type of encryption process provided in an embodiment of the present invention;

[0053] Figure 4 This is a schematic diagram of the second type of encryption process provided in an embodiment of the present invention;

[0054] Figure 5 This is a schematic diagram of the third type of encryption process provided in the embodiments of the present invention;

[0055] Figure 6 This is a schematic diagram of the structure of the air interface data secure transmission device provided in an embodiment of the present invention. Detailed Implementation

[0056] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of the invention. However, those skilled in the art will understand that the invention can be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods are omitted so as not to obscure the description of the invention with unnecessary detail.

[0057] To make the objectives, technical solutions, and advantages of the present invention clearer, specific embodiments will be described below in conjunction with the accompanying drawings.

[0058] Figure 1 This diagram illustrates an application scenario of the secure air interface data transmission method provided in an embodiment of the present invention. For example... Figure 1 As shown, the interface between the terminal and the base station is an air interface, where the base station is the access network, and the access network is connected to the core network through the bearer network. In a 5G network, a physical network is divided into multiple virtual logical networks, each corresponding to a different application scenario, forming network slices. Since different network slices correspond to different application scenarios, the characteristics of data transmission under different network slices are also different, such as low latency and high reliability, high capacity and high bandwidth, and massive access requirements.

[0059] Based on this, this application provides a method for secure transmission of air interface data, which determines different secure transmission methods for data with different requirements, so that the encrypted air interface data meets the data transmission requirements.

[0060] Figure 2 The implementation flowchart of the air interface data secure transmission method provided in the embodiments of the present invention is described in detail below:

[0061] Step S201: Obtain the target air interface data and the slice type corresponding to the target air interface data.

[0062] In this embodiment, the target air interface data includes data sent from the terminal to the base station and data sent from the base station to the terminal. The slice type is determined according to the different transmission requirements of 5G network slices, such as low latency and high reliability, massive access, and high data capacity. The slice type is divided according to different transmission requirements.

[0063] Step S202: Segment the target air interface data to obtain multiple segmented data.

[0064] In this embodiment, the target air interface data can be segmented according to the size of the data or the number of segments. For example, the target air interface data can be segmented according to a preset data volume, such that the last segment can be less than or equal to the preset data volume, for example, the preset data volume can be 16 characters, 32 characters, 128 characters, etc.; or the target air interface data can be randomly segmented according to a preset number of segments to obtain multiple segmented data.

[0065] Optionally, in this embodiment, the target air interface data is segmented to obtain multiple segmented data. This can be done by: first determining the data size of the target air interface data; then, based on the preset upper limit of the segmented data size and the data size of the target air interface data, segmenting the target air interface data to obtain multiple segmented data.

[0066] In this embodiment, the data is segmented according to its size so that the size of each segment does not exceed the upper limit of the preset segment size. The size of each segment can be the same or different.

[0067] Step S203: Determine multiple encryption methods based on the slice type and the timestamp when the target air interface data is acquired.

[0068] In this embodiment, different slice types have different transmission requirements. Therefore, the encryption method can be determined based on the slice type of the target air interface data. Alternatively, the encryption method can be determined by the timestamp, associating the encryption method of the target air interface data with the timestamp. This avoids using the same encryption method for all target air interface data or target air interface data of the same type, thereby reducing the risk of data decryption. The encryption method can be the encryption method for each segment of data.

[0069] Step S204: Encrypt multiple segments of data using various encryption methods to obtain the ciphertext of the target air interface data.

[0070] In this embodiment, the encryption method and the segmented data may or may not correspond. For example, if the encryption method corresponds to the segmented data, the encryption method corresponding to each segmented data can be used to encrypt that segmented data; if the encryption method does not correspond to the segmented data, multiple different encryption methods can be used to encrypt the target air interface data, where one encryption method is used to encrypt multiple segments of data.

[0071] Step S205: Determine the data to be sent based on the ciphertext, slice type, timestamp, and number of segments, and send the data to be sent to the preset receiving end.

[0072] In this embodiment, the encryption method of the target air interface data is related to the slice type, timestamp, and number of segments. Therefore, the slice type, timestamp, and number of segments can be sent to the preset receiving end to ensure that the preset receiving end can correctly decrypt the corresponding data after receiving the data.

[0073] The preset receiver is determined based on the transmission direction of the target air interface data. The preset receiver can be a base station or a terminal.

[0074] Optionally, in this embodiment, when determining the data to be sent based on the ciphertext, slice type, timestamp, and number of segments, the slice type, timestamp, and number of segments can be combined according to a preset combination method; then the combined slice type, timestamp, and number of segments can be set in a preset position in the ciphertext to obtain the data to be sent.

[0075] In this embodiment, there are no restrictions on the combination order of the slice type, timestamp, and number of segments, nor on the preset positions; the ciphertext, slice type, timestamp, and number of segments can be combined together. For example, the slice type, timestamp, and number of segments can be sequentially set before the ciphertext to obtain the data to be sent. Alternatively, there can be multiple preset positions, where the slice type, timestamp, and number of segments can be set at different positions within the ciphertext.

[0076] Optionally, in this embodiment, when sending the data to be sent to the preset receiving end, the data to be sent may be encoded and modulated to obtain a corresponding analog signal, and the analog signal may be sent to the preset receiving end.

[0077] This invention, through determining the slice type of the target air interface data, clarifies the type of the target air interface data and its corresponding transmission requirements. By determining the encryption method based on the slice type and the timestamp at the time of acquisition of the target air interface data, the encryption method can be made more suitable for the transmission requirements of the target air interface data, ensuring that the encrypted data meets the corresponding timeliness and transmission quality. By determining the data to be sent through the ciphertext, slice type, timestamp, and number of segments, the slice type, timestamp, and number of segments can be sent to the receiving end to ensure that the receiving end can perform the corresponding decryption, thus ensuring accurate data reception.

[0078] In one embodiment, each segment of the target air interface data corresponds to a segment number.

[0079] This embodiment determines multiple encryption methods based on the slice type and the timestamp when the target air interface data is acquired. It can be as follows: First, based on the slice type, determine the encryption library corresponding to the target air interface data. The encryption library includes multiple keys and multiple encryption functions. Different keys carry different encryption parameters, and different encryption functions carry different encryption parameters.

[0080] Secondly, based on the timestamp and the segment number of each segment of data, the encryption parameters corresponding to each segment of data are determined.

[0081] Finally, based on the encryption library and the encryption parameters corresponding to each data segment, the key and encryption function corresponding to each data segment are determined, and the encryption method of each data segment is obtained based on the key and encryption function corresponding to each data segment.

[0082] In this embodiment, different slice types correspond to different encryption libraries. Each encryption library stores multiple keys and encryption functions suitable for the corresponding slice type. For example, if there are three slice types: a first type, a second type, and a third type, then three encryption libraries are set accordingly: a first encryption library for the first type, a second encryption library for the second type, and a third encryption library for the third type.

[0083] The first type can be low latency and high reliability. Correspondingly, the first encryption library stores keys and encryption algorithms that meet the requirements of low latency and high reliability. For example, the encryption algorithms can be symmetric encryption algorithms, such as Data Encryption Standard (DES), Triple DES, and Advanced Encryption Standard (AES). The second type can be high capacity and high bandwidth. Correspondingly, the second encryption library stores keys and encryption algorithms that meet the requirements of high capacity and high bandwidth. The third type can be massive access. Correspondingly, the second encryption library stores keys and encryption algorithms that meet the requirements of massive access.

[0084] Here, each key and encryption function in the encryption library corresponds to an encryption parameter. The encryption parameter can uniquely identify a key in the encryption library, and it can also uniquely identify an encryption function in the encryption library. However, the key and encryption function are not necessarily corresponding.

[0085] Furthermore, the encryption parameters corresponding to the keys and encryption functions in the encryption library are rotated periodically. For example, if the encryption library contains five keys (a, b, c, d, and e) and five encryption functions (A, B, C, D, and E), within a given time period, the correspondence between keys and encryption parameters can be a-1, b-2, c-3, d-4, e-5, and the correspondence between encryption functions and encryption parameters can be A-1, B-2, C-3, D-4, E-5. After rotation, the correspondence between keys and encryption parameters can be a-2, b-4, c-5, d-3, e-1, and the correspondence between encryption functions and encryption parameters can be A-4, B-1, C-5, D-2, E-3; where 1, 2, 3, 4, and 5 represent encryption parameters.

[0086] In this embodiment, the encryption parameters corresponding to each segment of data are determined according to the timestamp and the segment number of each segment of data. By determining the encryption parameters according to the segment number of the segment of data, the encryption parameters can be closely related to the segment data, ensuring the dynamism of the key and encryption algorithm. During decryption, the decryption side can also determine the corresponding key and encryption algorithm in a timely manner and perform decryption quickly.

[0087] In one embodiment, see Figure 3 The diagram shown illustrates the first type of encryption process. Multiple data segments are encrypted using various encryption methods to obtain the ciphertext of the target air interface data. This can be:

[0088] When the slice type corresponding to the target air interface data is the first type, the corresponding segment data is first encrypted according to the encryption method corresponding to each segment data to obtain the encrypted data corresponding to each segment data; then, based on the encrypted data corresponding to each segment data, the ciphertext of the target air interface data is obtained.

[0089] In this embodiment, the first type of transmission requirement can be low latency and high reliability. For example, data in scenarios such as differential protection, power distribution automation, and autonomous driving all fall into this first type. Correspondingly, the target air interface data of the first type requires fast encryption and decryption speeds. Therefore, each segment of data can be encrypted separately, and the encryption and decryption of each segment will not affect each other, thereby reducing encryption time. Figure 3 In the table, 1, 2, 3...N represent segmented data, and 1*, 2*, 3*...N* represent the encrypted data corresponding to each segment.

[0090] Here, each segment of data can also be encrypted simultaneously, further reducing the encryption time required.

[0091] Optionally, in this embodiment, the encrypted data corresponding to each segment can be concatenated to obtain the ciphertext of the target air interface data. When concatenating, multiple segment identifiers can be set, and two encrypted data can be connected through these identifiers to enable rapid segmentation during decryption.

[0092] In one embodiment, see Figure 4 The diagram shown illustrates the second type of encryption process. Multiple data segments are encrypted using various encryption methods to obtain the ciphertext of the target air interface data. This can be:

[0093] When the slice type corresponding to the target air interface data is the second type, the first segment data is first encrypted according to the encryption method of the first segment data to obtain the first encrypted data.

[0094] Then, based on the encryption method of the second segment data, the first encrypted data and the second segment data are encrypted to obtain the second encrypted data.

[0095] For each data segment after the second data segment, the encrypted data segment and the encrypted data before it are encrypted in turn according to the encryption method of each data segment until all data segments are encrypted to obtain the ciphertext of the target air interface data.

[0096] In this embodiment, the second type of transmission requirement can be high capacity and high bandwidth, such as data in scenarios like video surveillance, ultra-high-definition video, and holographic technology. Correspondingly, the target air interface data of the second type requires high data transmission quality. Therefore, each segment of data can be encrypted sequentially to ensure data security and high quality.

[0097] Here, as Figure 4 As shown, during the encryption process, there is a correlation between the various data segments. Encrypted data, along with unencrypted data, is then encrypted again. Through layers of encryption, data security is improved, ensuring high-quality data transmission. Figure 4 In the diagram, 1, 2, 3...N represent segmented data, 1* represents the encrypted data corresponding to segment 1, 2* represents the encrypted data obtained by combining the encrypted data corresponding to segment 1 and segment 2, and so on, N* represents the ciphertext of the final target air interface data.

[0098] Alternatively, in this embodiment, the last segment of data can be encrypted first, and then encrypted sequentially forward until the encryption of the first segment of data is completed.

[0099] In one embodiment, see Figure 5 The diagram shown illustrates the third type of encryption process. Multiple data segments are encrypted using various encryption methods to obtain the ciphertext of the target air interface data. This can be:

[0100] When the slice type corresponding to the target air interface data is the third type, first determine whether the number of segments of the target air interface data is greater than the preset number.

[0101] If the number of segments is greater than the preset number, then multiple groups are determined according to the preset number, and each group includes multiple segment data.

[0102] For each group, the first segment of data in the group is encrypted according to the encryption method corresponding to the first segment of data in the group, to obtain the third encrypted data; the second segment of data in the group and the third encrypted data are encrypted according to the encryption method corresponding to the second segment of data in the group, to obtain the fourth encrypted data; for each segment of data after the second segment of data in the group, the encrypted data of that segment and the encrypted data before that segment are encrypted in turn according to the encryption method of each segment of data in the group, until all segment data in the group is encrypted, to obtain the encrypted data of the group.

[0103] Finally, the encrypted data of each group is concatenated to obtain the ciphertext of the target air interface data.

[0104] In this embodiment, the third type of transmission requirement can be massive access, such as data in scenarios like electricity consumption information collection and smart cities. The characteristics of the target air interface data of the third type are small data packets, low power consumption, and large quantity.

[0105] Based on this, this embodiment can first determine the number of segments in the target air interface data, and use different encryption methods for different numbers of segments. If the number of segments is large, it indicates a large amount of data, which can be encrypted in groups to quickly and with high quality.

[0106] Here, multiple groups are defined based on a preset number. This can be achieved by selecting a preset number of data segments as encryption start points, with one encryption start point leading to the next as a group, or one encryption start point leading to the last data segment as a group. Each group contains one encryption start point. Encryption begins from the encryption start point. The preset number can be 3, 5, 8, etc., and can be set according to the specific scenario of the slicing application.

[0107] See Figure 5 Where 1, 2, 3...N represent segmented data, and 1*, 2*, 3*...N* represent encrypted data obtained after encrypting the segmented data. Figure 5 The data segments 1, 2, 3, and 4 are grouped together, and the data segments 5, 6, 7, and 8 are grouped together to obtain multiple groups. 4*, 8*, and N* can all represent the encrypted data of the corresponding groups. By concatenating 4*, 8*, ..., N*, the ciphertext of the target air interface data can be obtained.

[0108] Optionally, if the number of segments is less than or equal to the preset number, this embodiment can encrypt each segment of data simultaneously according to the encryption method corresponding to each segment of data to obtain the encrypted data corresponding to each segment of data; finally, the encrypted data corresponding to each segment of data are concatenated to obtain the ciphertext of the target air interface data.

[0109] In this embodiment, if the number of segments is small, it means that the amount of data is small. Each segment of data can be directly encrypted in order to quickly process a large amount of air interface data.

[0110] Here, when connecting encrypted data, multiple segment identifiers can be set to connect two encrypted data sets through these segment identifiers, so that they can be quickly divided during decryption.

[0111] Optionally, this embodiment can also determine the encryption parameters corresponding to the timestamp when the target air interface data is acquired; then, based on the encryption parameters, determine the key and encryption function corresponding to the timestamp, and determine the connection encryption method based on the obtained key and encryption function; finally, encrypt the connected encrypted data again according to the connection encryption method. By re-encrypting the connected encrypted data, the security of the data is improved. Specifically, whether to re-encrypt the encrypted data can be determined based on the importance of the data.

[0112] In one embodiment, before sending the data to be sent to the preset receiving end, the data to be sent can be randomly filled according to the timestamp to obtain the updated data to be sent.

[0113] Correspondingly, sending the data to be sent to the preset receiving end can be done by sending the updated data to the preset receiving end.

[0114] In this embodiment, considering the existence of attacks that decrypt data by analyzing the characteristics of transmitted data, such as sending fixed-length data multiple times in a short period of time to analyze the amount of data transmitted by the user and thus decrypt the information transmitted by the user, the data to be sent can be randomly padded to change its size. This avoids the possibility of obtaining the statistical characteristics of the target air interface data and decrypting it simply by analyzing the data to be sent, thereby further improving data security.

[0115] Optionally, there can be multiple locations for random padding. The random padding can occur before, after, or in the middle of the data to be sent. For example, when the slice type, timestamp, and number of segments are set sequentially before the ciphertext, the random padding can occur between the slice type and the timestamp, between the timestamp and the number of segments, between the number of segments and the ciphertext, or at a specific location within the ciphertext. When random padding occurs at a specific location within the ciphertext or at other difficult-to-distinguish locations, markers can be added before and after the random padding location so that the randomly padded data can be ignored during decryption.

[0116] This invention, by determining the slice type of the target air interface data, clarifies the type of the target air interface data and its corresponding transmission requirements. By determining the encryption method based on the slice type and the timestamp when the target air interface data was acquired, the encryption method is made more suitable for the transmission requirements of the target air interface data, ensuring that the encrypted data meets the corresponding timeliness and transmission quality. Specifically, determining the encryption library based on the slice type allows for the selection of keys and encryption algorithms from a suitable library for that slice type. Furthermore, determining the encryption parameters for each data segment using the timestamp and segment sequence number enables dynamic selection, preventing all air interface data from using the same encryption method and reducing the risk of being cracked. The selected encryption method encrypts each segment of data, and can also encrypt data according to the segment type corresponding to the target air interface data, ensuring that the encryption speed and encryption result meet the transmission requirements of that segment type. By using ciphertext, segment type, timestamp, and number of segments, the data to be sent can be determined, and the segment type, timestamp, and number of segments can be sent to the receiving end to ensure that the receiving end can perform the corresponding decryption and ensure accurate data reception. In addition, before sending the data to be sent to the preset receiving end, the data to be sent can be randomly padded to avoid the data to be sent having corresponding statistical characteristics, reducing the possibility of data decryption through statistical analysis.

[0117] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0118] The following are device embodiments of the present invention. For details not described in detail, please refer to the corresponding method embodiments described above.

[0119] Figure 6 A schematic diagram of the air interface data secure transmission device provided in an embodiment of the present invention is shown. For ease of explanation, only the parts related to the embodiment of the present invention are shown, and are described in detail below:

[0120] like Figure 6 As shown, the air interface data secure transmission device 60 includes:

[0121] Module 61 is used to obtain the target air interface data and the slice type corresponding to the target air interface data;

[0122] Segmentation module 62 is used to segment the target air interface data to obtain multiple segmented data;

[0123] The determination module 63 is used to determine multiple encryption methods based on the slice type and the timestamp when the target air interface data is acquired;

[0124] Encryption module 64 is used to encrypt multiple segments of data according to various encryption methods to obtain the ciphertext of the target air interface data;

[0125] The sending module 65 is used to determine the data to be sent based on the ciphertext, slice type, timestamp, and number of segments, and to send the data to be sent to the preset receiving end.

[0126] In one possible implementation, each segment of the target air interface data corresponds to a segment number;

[0127] Module 63 is specifically used for:

[0128] Based on the slice type, determine the encryption library corresponding to the target air interface data. The encryption library includes multiple keys and multiple encryption functions. Different keys carry different encryption parameters, and different encryption functions carry different encryption parameters.

[0129] Based on the timestamp and the segment number of each segment of data, the encryption parameters corresponding to each segment of data are determined respectively;

[0130] Based on the encryption library and the encryption parameters corresponding to each data segment, the key and encryption function corresponding to each data segment are determined, and the encryption method of each data segment is obtained based on the key and encryption function corresponding to each data segment.

[0131] In one possible implementation, encryption module 64 is specifically used for:

[0132] When the slice type corresponding to the target air interface data is the first type, the corresponding segment data is encrypted according to the encryption method corresponding to each segment data to obtain the encrypted data corresponding to each segment data.

[0133] Based on the encrypted data corresponding to each segment of data, the ciphertext of the target air interface data is obtained.

[0134] In one possible implementation, encryption module 64 is specifically used for:

[0135] When the slice type corresponding to the target air interface data is the second type, the first segment data is encrypted according to the encryption method of the first segment data to obtain the first encrypted data;

[0136] Based on the encryption method of the second segment data, the first encrypted data and the second segment data are encrypted to obtain the second encrypted data;

[0137] For each data segment after the second data segment, the encrypted data segment and the encrypted data before it are encrypted in turn according to the encryption method of each data segment until all data segments are encrypted to obtain the ciphertext of the target air interface data.

[0138] In one possible implementation, encryption module 64 is specifically used for:

[0139] When the slice type corresponding to the target air interface data is the third type, determine whether the number of segments of the target air interface data is greater than the preset number.

[0140] If the number of segments is greater than the preset number, then multiple groups are determined according to the preset number, and each group includes multiple segment data.

[0141] For each group, the first segment of data in the group is encrypted according to the encryption method corresponding to the first segment of data in the group, to obtain the third encrypted data; the second segment of data in the group and the third encrypted data are encrypted according to the encryption method corresponding to the second segment of data in the group, to obtain the fourth encrypted data; for each segment of data after the second segment of data in the group, the encrypted data of that segment and the encrypted data before that segment are encrypted in turn according to the encryption method of each segment of data in the group, until all segment data in the group is encrypted, to obtain the encrypted data of the group;

[0142] By concatenating the encrypted data from each group, the ciphertext of the target air interface data is obtained.

[0143] In one possible implementation, encryption module 64 is also used for:

[0144] If the number of segments is less than or equal to the preset number, then each segment of data is encrypted simultaneously according to the encryption method corresponding to each segment of data, so as to obtain the encrypted data corresponding to each segment of data.

[0145] By connecting the encrypted data corresponding to each segment of data, the ciphertext of the target air interface data is obtained.

[0146] In one possible implementation, the sending module 65 is specifically used for:

[0147] Combine the slice type, timestamp, and number of segments according to the preset combination method;

[0148] Set the combined slice type, timestamp, and number of segments in the preset position in the ciphertext to obtain the data to be sent.

[0149] In one possible implementation, before sending the data to be sent to the preset receiver, the method further includes:

[0150] The data to be sent is randomly populated based on the timestamp to obtain the updated data to be sent.

[0151] Sending the data to be sent to the preset receiver includes:

[0152] Send the updated data to be sent to the preset receiver.

[0153] In one possible implementation, segmentation module 62 is specifically used for:

[0154] Determine the data size of the target air interface data;

[0155] Based on the preset upper limit of segmented data size and the data size of the target air interface data, the target air interface data is segmented to obtain multiple segmented data.

[0156] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0157] Those skilled in the art will recognize that the templates, units, and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0158] If a module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory, random access memory, electrical carrier signals, telecommunication signals, and software distribution media, etc.

[0159] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A method for secure air interface data transmission, characterized in that, include: Obtain the target air interface data and the slice type corresponding to the target air interface data; The target air interface data is segmented to obtain multiple segmented data; Based on the slice type and the timestamp when the target air interface data was acquired, multiple encryption methods are determined; The multiple segments of data are encrypted using the various encryption methods to obtain the ciphertext of the target air interface data; Based on the ciphertext, the slice type, the timestamp, and the number of segments of the target air interface data, the data to be sent is determined and sent to the preset receiving end; Each segment of the target air interface data corresponds to a segment number; The method of determining multiple encryption methods based on the slice type and the timestamp when the target air interface data was acquired includes: Based on the slice type, the encryption library corresponding to the target air interface data is determined, wherein the encryption library includes multiple keys and multiple encryption functions, wherein different keys carry different encryption parameters, and different encryption functions carry different encryption parameters; Based on the timestamp and the segment number of each segment of data, the encryption parameters corresponding to each segment of data are determined respectively; Based on the encryption library and the encryption parameters corresponding to each segment of data, the key and encryption function corresponding to each segment of data are determined, and the encryption method of each segment of data is obtained based on the key and encryption function corresponding to each segment of data.

2. The air interface data secure transmission method according to claim 1, characterized in that, The step of encrypting the multiple segmented data according to the multiple encryption methods to obtain the ciphertext of the target air interface data includes: When the slice type corresponding to the target air interface data is the first type, the corresponding segment data is encrypted according to the encryption method corresponding to each segment data to obtain the encrypted data corresponding to each segment data. Based on the encrypted data corresponding to each segment of data, the ciphertext of the target air interface data is obtained.

3. The air interface data secure transmission method according to claim 1, characterized in that, The step of encrypting the multiple segmented data according to the multiple encryption methods to obtain the ciphertext of the target air interface data includes: When the slice type corresponding to the target air interface data is the second type, the first segment data is encrypted according to the encryption method of the first segment data to obtain the first encrypted data; Based on the encryption method of the second segment data, the first encrypted data and the second segment data are encrypted to obtain the second encrypted data; For each data segment after the second data segment, the encrypted data segment and the encrypted data before it are encrypted in sequence according to the encryption method of each data segment until the encryption of all data segments is completed, and the ciphertext of the target air interface data is obtained.

4. The method for secure air interface data transmission according to claim 1, characterized in that, The step of encrypting the multiple segmented data according to the multiple encryption methods to obtain the ciphertext of the target air interface data includes: When the slice type corresponding to the target air interface data is the third type, determine whether the number of segments of the target air interface data is greater than the preset number; If the number of segments is greater than the preset number, then multiple groups are determined according to the preset number, wherein each group includes multiple segment data; For each group, the first segment of data in the group is encrypted according to the encryption method corresponding to the first segment of data in the group to obtain the third encrypted data; the second segment of data in the group and the third encrypted data are encrypted according to the encryption method corresponding to the second segment of data in the group to obtain the fourth encrypted data; for each segment of data after the second segment of data in the group, the encrypted data of that segment and the encrypted data before that segment are encrypted in turn according to the encryption method of each segment of data in the group, until the encryption of all segment data in the group is completed to obtain the encrypted data of the group; By concatenating the encrypted data of each group, the ciphertext of the target air interface data is obtained.

5. The air interface data secure transmission method according to claim 4, characterized in that, After determining whether the number of segments of the target air interface data is greater than a preset number, the process also includes: If the number of segments is less than or equal to the preset number, then each segment of data is encrypted simultaneously according to the encryption method corresponding to each segment of data, so as to obtain the encrypted data corresponding to each segment of data. By connecting the encrypted data corresponding to each segment of data, the ciphertext of the target air interface data is obtained.

6. The air interface data secure transmission method according to any one of claims 1-5, characterized in that, The step of determining the data to be sent based on the ciphertext, the slice type, the timestamp, and the number of segments of the target air interface data includes: According to a preset combination method, the slice type, the timestamp, and the number of segments of the target air interface data are combined; The combined slice type, timestamp, and number of segments are set at preset positions in the ciphertext to obtain the data to be sent.

7. The method for secure air interface data transmission according to any one of claims 1-5, characterized in that, Before sending the data to be sent to the preset receiving end, the method further includes: The data to be sent is randomly filled according to the timestamp to obtain the updated data to be sent. Sending the data to be sent to the preset receiving end includes: The updated data to be sent is sent to the preset receiving end.

8. The method for secure air interface data transmission according to any one of claims 1-5, characterized in that, The target air interface data is segmented to obtain multiple segmented data, including: Determine the data size of the target air interface data; Based on the preset upper limit of segmented data size and the data size of the target air interface data, the target air interface data is segmented to obtain multiple segmented data.

9. An air interface data secure transmission device, characterized in that, include: The acquisition module is used to acquire the target air interface data and the slice type corresponding to the target air interface data; The segmentation module is used to segment the target air interface data to obtain multiple segmented data. The determination module is used to determine multiple encryption methods based on the slice type and the timestamp when the target air interface data is acquired; An encryption module is used to encrypt the multiple segmented data according to the multiple encryption methods to obtain the ciphertext of the target air interface data; The sending module is used to determine the data to be sent based on the ciphertext, the slice type, the timestamp, and the number of segments of the target air interface data, and to send the data to be sent to a preset receiving end; Each segment of the target air interface data corresponds to a segment number; The determining module is specifically used for: Based on the slice type, the encryption library corresponding to the target air interface data is determined, wherein the encryption library includes multiple keys and multiple encryption functions, wherein different keys carry different encryption parameters, and different encryption functions carry different encryption parameters; Based on the timestamp and the segment number of each segment of data, the encryption parameters corresponding to each segment of data are determined respectively; Based on the encryption library and the encryption parameters corresponding to each segment of data, the key and encryption function corresponding to each segment of data are determined, and the encryption method of each segment of data is obtained based on the key and encryption function corresponding to each segment of data.

Citation Information

Patent Citations

  • Data transmission method and device, electronic device and storage medium

    CN110958255A

  • User network communication method and system

    CN116744302A