Communication method and device

By carrying historical physical layer information in the messages of legitimate network devices, the terminal device can identify and prevent authentication relay attacks, solving the problem of difficult to prevent such attacks in the prior art and achieving higher network security.

CN119922548APending Publication Date: 2025-05-02HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311439235.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-10-31
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively prevent authentication and relay attacks, resulting in damage to network security, which may cause location misjudgment, billing fraud and communication interruption.

Method used

By carrying the historical physical layer measurement information and physical layer configuration information in the messages sent by the legal network device, the terminal device can compare these information to determine whether the message comes from the legal network device, thereby identifying and preventing authentication relay attacks.

Benefits of technology

Effectively identify and prevent authentication and relay attacks, ensure the legality of network equipment, prevent billing fraud and communication interruptions, and improve network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119922548A_ABST
    Figure CN119922548A_ABST
Patent Text Reader

Abstract

The invention provides a communication method and device which are used for preventing authentication relay attacks. The method comprises the following steps: receiving a first message, and determining whether network equipment is legal or not according to first information indicated by the first message and second information historically recorded by the network equipment; wherein the first information comprises first physical layer measurement information and / or first physical layer configuration information, and the second information comprises second physical layer measurement information and / or second physical layer configuration information. Physical layer measurement information and physical layer configuration information related to a channel are carried in a message sent by network equipment, and a channel between legal network equipment and terminal equipment is different from a channel between illegal network equipment and the terminal equipment. Therefore, the terminal equipment can judge whether the message is from the legal network equipment or not by comparing the information carried in the received message with the information recorded by the terminal equipment, so that the authentication relay attack can be prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a communication method and device. Background Art

[0002] An authentication relay attack refers to an attack in which an intermediate device (such as an illegal base station or illegal user equipment (UE)) steals the identity of a legitimate UE and intercepts messages. For example, a legitimate UE may be attracted to an illegal base station. Then, the illegal base station collaborates with another illegal UE through a private channel. The illegal base station forwards the registration request message of the legitimate UE to the remote illegal UE, and the illegal UE forwards it to the remote core network through the remote legal base station. For another example, the illegal base station and the illegal UE forward the response message sent by the core network to the legitimate UE and complete the authentication. If an authentication relay attack occurs, the consequences may be: the network's perceived user location may be inconsistent with the user's actual location; or, the legitimate UE may be guided by the intermediate device to access a roaming network, resulting in billing fraud; or, the intermediate device can completely / selectively reject the legitimate UE's phone / text / data transmission, resulting in the operating network being deprived of incoming / outgoing and text message charges.

[0003] In summary, how to prevent authentication relay attacks is an urgent problem to be solved. Summary of the invention

[0004] The present application provides a communication method and device for preventing authentication relay attacks.

[0005] In a first aspect, a communication method is provided, wherein the executor of the method may be a terminal device or a chip, a chip system or a circuit located in the terminal device, and the method may be implemented by the following steps: receiving a first message, wherein the first message indicates first information, and the first information includes at least one of the following: first physical layer measurement information, and first physical layer configuration information; determining whether the network device is legal based on the first information indicated by the first message and second information recorded by itself, wherein the second information includes at least one of the following: second physical layer measurement information recorded in the historical records, and second physical layer configuration information recorded in the historical records.

[0006] In the present application, the historical physical layer measurement information and the historical physical layer configuration information are carried in the messages sent by the legitimate network devices. Since the physical layer measurement information and the physical layer configuration information are related to the channels of the legitimate network devices, and the illegal network devices cannot obtain the channel conditions between the legitimate network devices and the terminal devices, they cannot carry information related to the channels of the legitimate network devices in the sent messages. Therefore, the terminal device can determine whether the message comes from the legitimate network device by comparing the information carried in the received message with the physical layer measurement information and the physical layer configuration information recorded by itself, thereby preventing authentication relay attacks.

[0007] In one possible design, the first physical layer measurement information includes the downlink channel state information carried by the first message, and the second physical layer measurement information includes the last reported downlink channel state information.

[0008] Since the downlink channel status information can provide feedback on the communication channel quality between the terminal device and the legitimate network device, if an illegal network device (or illegal terminal device) communicates with the terminal device, the communication channel will change, and the downlink channel status information measured by the terminal device will be inconsistent with the downlink channel status information of the legitimate network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0009] In one possible design, the first physical layer configuration information includes at least one of the following: a modulation level used by the first message, a system frame number carried by the first message, a random access timing index carried by the first message, and a preamble code index carried by the first message; the second physical layer configuration information includes at least one of the following: a modulation level used by the second message, a system frame number indicated by the second message, a random access timing index indicated by the second message, and a preamble code index indicated by the second message, wherein the second message is the last received downlink message, or the second message is the downlink message with the best signal quality among the downlink messages received within a preset time period.

[0010] Since the modulation level is related to the quality of the communication channel, the better the channel quality, the higher the modulation level. Therefore, if an illegal network device (or illegal terminal device) communicates with a terminal device, the communication channel will change. The channel quality between the illegal network device and the terminal device is different from the channel quality between the legal network device and the terminal device. The illegal network device may even be unable to support high-order modulation levels. Therefore, the modulation level of the downlink message sent by the illegal network device is inconsistent with the modulation level of the downlink message sent by the legal network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0011] The system frame number, random access timing index, preamble index and other information are configured by the legitimate network device, and the illegal network device cannot obtain this information. Therefore, the information carried in the downlink message sent by the illegal network device is inconsistent with the information carried in the downlink message sent by the legitimate network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of the authentication relay attack, thereby preventing the authentication relay attack.

[0012] In one possible design, whether the network device is legal is determined based on the first information and the second information, including: if the first information is consistent with the second information, then the network device is legal.

[0013] In one possible design, if the network device is legal, the method further includes: receiving a downlink reference signal; sending a response message to the first message, the response message carrying physical layer measurement information corresponding to the downlink reference signal. In this solution, the terminal device and the network device can record the downlink channel state information of this measurement to facilitate the terminal device to identify subsequent messages.

[0014] In one possible design, before receiving the first message, the method further includes: receiving a third message, the third message being used to indicate that the authentication is successful. In this way, it can be determined that the information recorded by the terminal device corresponds to a legitimate network device, so that it can be identified based on the recorded information whether the subsequent message comes from a legitimate network device, so as to prevent authentication relay attacks.

[0015] In one possible design, the first message is a radio resource control (RRC) reconfiguration message.

[0016] In one possible design, if the network device is legitimate, an RRC reconfiguration completion message may be sent.

[0017] In one possible design, the first physical layer configuration information includes at least one of the following: the modulation level used by the first message, the system frame number carried by the first message, the random access timing index carried by the first message, and the preamble index carried by the first message; the second physical layer configuration information includes at least one of the following: the modulation level indicated by the fourth message, the system frame number carried or used by the fourth message, the random access timing index carried or used by the fourth message, and the preamble index carried or used by the fourth message, wherein the fourth message is the most recently received downlink message that has been successfully decrypted using a public key. The above example can identify whether the message content of the fourth message has been tampered with by encrypting the fourth message, and since illegal network devices cannot obtain configuration certificates, they cannot obtain legal public keys. Therefore, the above scheme can also be used to determine whether the fourth message comes from a legal network device.

[0018] In one possible design, determining whether the network device is legitimate is based on the first information and the second information, including: if the first information is consistent with the second information, and the first message is successfully decrypted using the public key, then the network device is legitimate. The above example can identify whether the message content of the first message has been tampered with by encrypting the first message, and because an illegal network device cannot obtain a configuration certificate, it cannot obtain a legitimate public key. Therefore, the above scheme can also be used to determine whether the first message comes from a legitimate network device.

[0019] In one possible design, the method also includes: receiving a system message, where the system message indicates a public key.

[0020] In one possible design, the first message is message 4 in the random access process, and the fourth message is message 2 in the random access process.

[0021] According to a second aspect, a communication method is provided. The executor of the method may be a network device or a chip, a chip system or a circuit located in the network device. The method may be implemented by the following steps: sending a first message, the first message indicating first information, the first information including at least one of the following: first physical layer measurement information of the historical record, first physical layer configuration information of the historical record, the first information is used to determine whether the network device is legal.

[0022] In the present application, the historical physical layer measurement information and the historical physical layer configuration information are carried in the messages sent by the legitimate network devices. Since the physical layer measurement information and the physical layer configuration information are related to the channels of the legitimate network devices, and the illegal network devices cannot obtain the channel conditions between the legitimate network devices and the terminal devices, they cannot carry information related to the channels of the legitimate network devices in the sent messages. Therefore, the terminal device can determine whether the message comes from the legitimate network device by comparing the information carried in the received message with the physical layer measurement information and the physical layer configuration information recorded by itself, thereby preventing authentication relay attacks.

[0023] In one possible design, the first physical layer measurement information includes the downlink channel state information carried by the first message, and the second physical layer measurement information includes the last reported downlink channel state information.

[0024] Since the downlink channel status information can provide feedback on the communication channel quality between the terminal device and the legitimate network device, if an illegal network device (or illegal terminal device) communicates with the terminal device, the communication channel will change, and the downlink channel status information measured by the terminal device will be inconsistent with the downlink channel status information of the legitimate network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0025] In one possible design, the first physical layer configuration information includes at least one of the following: a modulation level used by the first message, a system frame number carried by the first message, a random access timing index carried by the first message, and a preamble code index carried by the first message; the second physical layer configuration information includes at least one of the following: a modulation level used by the second message, a system frame number indicated by the second message, a random access timing index indicated by the second message, and a preamble code index indicated by the second message, wherein the second message is the last received downlink message, or the second message is the downlink message with the best signal quality among the downlink messages received within a preset time period.

[0026] Since the modulation level is related to the quality of the communication channel, the better the channel quality, the higher the modulation level. Therefore, if an illegal network device (or illegal terminal device) communicates with a terminal device, the communication channel will change. The channel quality between the illegal network device and the terminal device is different from the channel quality between the legal network device and the terminal device. The illegal network device may even be unable to support high-order modulation levels. Therefore, the modulation level of the downlink message sent by the illegal network device is inconsistent with the modulation level of the downlink message sent by the legal network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0027] The system frame number, random access timing index, preamble index and other information are configured by the legitimate network device, and the illegal network device cannot obtain this information. Therefore, the information carried in the downlink message sent by the illegal network device is inconsistent with the information carried in the downlink message sent by the legitimate network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of the authentication relay attack, thereby preventing the authentication relay attack.

[0028] In one possible design, the method further includes: sending a downlink reference signal; receiving a response message to the first message, the response message carrying physical layer measurement information corresponding to the downlink reference signal. In this solution, the terminal device and the network device can record the downlink channel state information of this measurement to facilitate the terminal device to identify subsequent messages.

[0029] In one possible design, before sending the first message, the method further includes: sending a third message, the third message being used to indicate that the authentication is successful. In this way, it can be determined that the information recorded by the terminal device corresponds to a legitimate network device, so that it can be identified based on the recorded information whether the subsequent message comes from a legitimate network device, so as to prevent authentication relay attacks.

[0030] In one possible design, the first message is an RRC reconfiguration message.

[0031] In one possible design, an RRC reconfiguration completion message may also be received.

[0032] In one possible design, the first physical layer configuration information includes at least one of the following: the modulation level used by the first message, the system frame number carried by the first message, the random access timing index carried by the first message, and the preamble index carried by the first message; the second physical layer configuration information includes at least one of the following: the modulation level indicated by the fourth message, the system frame number carried or used by the fourth message, the random access timing index carried or used by the fourth message, and the preamble index carried or used by the fourth message, wherein the fourth message is the most recently received downlink message that has been successfully decrypted using a public key. The above example can identify whether the message content of the fourth message has been tampered with by encrypting the fourth message, and since illegal network devices cannot obtain configuration certificates, they cannot obtain legal public keys. Therefore, the above scheme can also be used to determine whether the fourth message comes from a legal network device.

[0033] In one possible design, the method also includes: sending a system message, where the system message indicates a public key corresponding to the private key.

[0034] In one possible design, the first message is message 4 in the random access process, and the fourth message is message 2 in the random access process.

[0035] In a third aspect, the present application further provides a communication device, which is a terminal device or a chip in a terminal device. The communication device has the function of implementing any of the methods provided in the first aspect above. The communication device can be implemented by hardware, or can be implemented by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the above functions.

[0036] In one possible design, the communication device includes: a processor, which is configured to support the communication device to perform the corresponding functions of the terminal device in the method shown above. The communication device may also include a memory, which can be coupled to the processor and stores the necessary program instructions and data of the communication device. Optionally, the communication device also includes an interface circuit, which is used to support communication between the communication device and a network device or other device, such as the transmission and reception of data or signals. Exemplarily, the communication interface can be a transceiver, circuit, bus, module or other type of communication interface.

[0037] In one possible design, the communication device includes corresponding functional modules, which are respectively used to implement the steps in the above method. The functions can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.

[0038] In one possible design, the structure of the communication device includes a processing unit and a communication unit, which can perform the corresponding functions in the above method example. For details, please refer to the description of the method provided in the first aspect, which will not be repeated here.

[0039] In a fourth aspect, the present application further provides a communication device, which is a network device or a chip in a network device. The communication device has the function of implementing any method provided in the second aspect above. The communication device can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the above functions.

[0040] In one possible design, the communication device includes: a processor, which is configured to support the communication device to perform the corresponding functions of the network device in the method shown above. The communication device may also include a memory, which can be coupled to the processor and stores the necessary program instructions and data of the communication device. Optionally, the communication device also includes an interface circuit, which is used to support communication between the communication device and a terminal device or other device, such as the transmission and reception of data or signals. Exemplarily, the communication interface can be a transceiver, circuit, bus, module or other type of communication interface.

[0041] In one possible design, the communication device includes corresponding functional modules, which are respectively used to implement the steps in the above method. The functions can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.

[0042] In one possible design, the structure of the communication device includes a processing unit and a communication unit, which can perform the corresponding functions in the above method example. For details, please refer to the description of the method provided in the second aspect, which will not be repeated here.

[0043] In a fifth aspect, a communication device is provided, comprising a processor and an interface circuit, wherein the interface circuit is used to receive signals from other communication devices outside the communication device and transmit them to the processor or to send signals from the processor to other communication devices outside the communication device, and the processor is used to implement the method in the aforementioned first aspect and any possible design through logic circuits or execution code instructions.

[0044] In a sixth aspect, a communication device is provided, comprising a processor and an interface circuit, the interface circuit being used to receive signals from other communication devices outside the communication device and transmit them to the processor or to send signals from the processor to other communication devices outside the communication device, the processor being used to implement the method in the aforementioned second aspect and any possible design through logic circuits or execution code instructions.

[0045] In the seventh aspect, a computer-readable storage medium is provided, in which a computer program or instruction is stored. When the computer program or instruction is executed by a processor, the method of the first aspect or the second aspect and any possible design is implemented.

[0046] In an eighth aspect, a computer program product storing instructions is provided, which, when executed by a processor, implements the method in the aforementioned first aspect or second aspect and any possible design.

[0047] In a ninth aspect, a chip system is provided, the chip system including a processor and a memory, for implementing the method in the first aspect or the second aspect and any possible design. The chip system may be composed of a chip, or may include a chip and other discrete devices.

[0048] In a tenth aspect, a communication system is provided, the system comprising the apparatus described in the first aspect (such as a terminal device) and the apparatus described in the second aspect (such as a network device).

[0049] The technical effects that can be achieved by the technical solutions of any of the third to tenth aspects mentioned above can be described with reference to the technical effects that can be achieved by the technical solutions of the first aspect mentioned above, and the repeated parts will not be repeated. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 A schematic diagram of the architecture of a communication system according to an embodiment of the present application;

[0051] Figure 2 A flow chart of a communication method according to an embodiment of the present application;

[0052] Figure 3 A schematic diagram of a process for preventing authentication relay attacks according to an embodiment of the present application;

[0053] Figure 4 A schematic diagram of another process for preventing authentication relay attacks according to an embodiment of the present application;

[0054] Figure 5 A schematic diagram of another process for preventing authentication relay attacks according to an embodiment of the present application;

[0055] Figure 6 A schematic diagram of the structure of a communication device according to an embodiment of the present application;

[0056] Figure 7 A schematic diagram of the structure of a communication device according to an embodiment of the present application. DETAILED DESCRIPTION

[0057] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.

[0058] Below, some terms in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.

[0059] 1) Terminal equipment, which can be a device with wireless transceiver function or a chip that can be set in any device, can also be called user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication equipment, user agent or user device. The terminal equipment in the embodiment of the present application can be a mobile phone, a tablet computer (Pad), a computer with wireless transceiver function, an XR device (such as VR device, AR device, MR device, etc.), a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in video surveillance, and a wearable terminal device. The terminal equipment can also be an eMBB UE, an ultra-reliable low latency communication (URLLC) UE, a drone, other Internet of things (IoT) devices, a positioning device, etc.

[0060] The network device may be a device for realizing the functions of the access network device. The access network device may refer to a device in the access network that communicates with the wireless terminal device through one or more cells at the air interface, for example, it may be the next generation base station (next Generation node B, gNB) in the NR system, it may be the evolutionary base station (evolutional node B, eNB) in the long term evolution (long term evolution, LTE) system, etc. The network device may also be a device that can support the network device to realize the functions of the access network device, such as a chip system, which can be installed in the network device. In some deployments, the network device may include at least one of a centralized unit (CU), a distributed unit (DU), and a radio unit (RU).

[0061] 2) The random access process includes a contention-based random access (CBRA) process and a contention-free random access (CFRA) process. The CBRA process is described below.

[0062] The CBRA process can be completed through a 4-step random access channel (RACH) or a 2-step RACH.

[0063] The 4-step RACH process includes:

[0064] S11, the terminal device sends a random access request message to the network device, and the network device receives the random access request message from the terminal device. The random access request message may also be called a first message (Msg1), which includes a random access preamble.

[0065] S12: The network device sends a RAR message to the terminal device, and the terminal device receives the RAR message from the network device. The RAR message may also be referred to as a second message (Msg2).

[0066] S13, the terminal device sends scheduled transmission information to the network device, and the network device receives the scheduled transmission information from the terminal device. The message carrying the scheduled transmission information is called the third message (Msg3).

[0067] After receiving the RAR message, the terminal device transmits the message based on the scheduling of the RAR message. Specifically, the terminal device may send Msg3 via a physical uplink shared channel (PUSCH) scheduled by the RAR UL grant carried in the first RAR.

[0068] S14, the network device sends contention resolution information to the terminal device, and the message carrying the contention resolution information is called the fourth message (Mg4). The terminal device receives Msg4 from the network device and can obtain the contention resolution information.

[0069] The terms "system" and "network" in the embodiments of the present application can be used interchangeably. In the embodiments of the present application, "at least one" refers to one or more, and "plurality" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0070] Furthermore, unless otherwise specified, ordinal numbers such as "first" and "second" mentioned in the embodiments of the present application are used to distinguish multiple objects, and are not used to limit the size, content, sequence, timing, priority or importance of multiple objects. For example, the first message and the second message are only used to distinguish different messages, and do not indicate the difference in the sending order, content, priority or importance of the two messages.

[0071] The foregoing introduces some terminology concepts involved in the embodiments of the present application. The following introduces the technical features involved in the embodiments of the present application.

[0072] The technical features involved in the embodiments of the present application are introduced below.

[0073] An authentication relay attack refers to an attack in which an intermediate device (such as an illegal base station or illegal user equipment (UE)) steals the identity of a legitimate UE and intercepts messages. For example, a legitimate UE may be attracted to an illegal base station. Then, the illegal base station collaborates with another illegal UE through a private channel. The illegal base station forwards the registration request message of the legitimate UE to the remote illegal UE, and the illegal UE forwards it to the remote core network through the remote legal base station. For another example, the illegal base station and the illegal UE forward the response message sent by the core network to the legitimate UE and complete the authentication. If an authentication relay attack occurs, the consequences may be: the network's perceived user location may be inconsistent with the user's actual location; or, the legitimate UE may be guided by the intermediate device to access a roaming network, resulting in billing fraud; or, the intermediate device can completely / selectively reject the legitimate UE's phone / text message / data transmission, resulting in the operating network being deprived of incoming / outgoing and text message charges. In summary, there is an urgent need for a solution to prevent authentication relay attacks.

[0074] Based on this, the embodiment of the present application provides a communication method and device for preventing authentication relay attacks. The method and device are based on the same concept. Since the method and device solve the problem in a similar way, the implementation of the device and the method can refer to each other, and the repeated parts will not be repeated.

[0075] The communication method provided in this application can be applied to various communication systems, for example, it can be the Internet of Things (IoT), narrowband Internet of Things (NB-IoT), long term evolution (LTE), it can also be a fifth generation (5G) communication system, it can also be a hybrid architecture of LTE and 5G, it can also be a 5G new radio (NR) system, and 6G or new communication systems that will appear in the future communication development. The 5G communication system described in this application may include at least one of a non-standalone (NSA) 5G communication system and a standalone (SA) 5G communication system. The communication system can also be a machine to machine (M2M) network or other network.

[0076] The network device and the terminal device can communicate through the licensed spectrum, or through the unlicensed spectrum, or through both the licensed spectrum and the unlicensed spectrum. The network device and the terminal device can communicate through the spectrum below 6G, or through the spectrum above 6G, or through both the spectrum below 6G and the spectrum above 6G. The embodiment of the present application does not limit the spectrum resources used between the network device and the terminal device.

[0077] See also Figure 1 A communication system architecture is shown, the communication system includes a network device 101 and a terminal device 102. It should be noted that: Figure 1 The number of devices in the communication system shown is only an example and is not intended to limit the present application.

[0078] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. A person of ordinary skill in the art can appreciate that with the evolution of the network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0079] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0080] In this application, "record" can also be replaced by "save", "maintain" and so on.

[0081] See also Figure 2 , which is a flow chart of a communication method provided by the present application. The execution subject of the method may be a network device or a chip, a chip system or a circuit located in the network device, and a terminal device or a chip, a chip system or a circuit located in the terminal device. For ease of introduction, in the following, the method is taken as being executed by a network device and a terminal device as an example. The processing described below as being executed by a single execution subject may also be divided into being executed by multiple execution subjects, which may be logically and / or physically separated. For example, the processing performed by the network device may be divided into being executed by at least one of a CU, a DU and a RU. The method includes:

[0082] S201, a network device sends a first message, and a terminal device receives the first message accordingly.

[0083] The first message indicates first information, and the first information includes at least one of the following: first physical layer measurement information and first physical layer configuration information.

[0084] Exemplarily, if the above network device is a legal network device, the first physical layer measurement information is the first physical layer measurement information of the legal network device history record. It can be understood that the first physical layer measurement information of the legal network device history record can be the measurement result of the reference signal between the terminal device and the legal network device before S201, which is used to characterize the channel between the terminal device and the legal network device.

[0085] For example, the first physical layer measurement information may be a measurement result of measuring a downlink reference signal of a legal network device before S201, used to characterize a downlink channel between the terminal device and the legal network device. Exemplarily, the first physical layer measurement information may be downlink channel state information.

[0086] In a specific example, the first physical layer measurement information may be the downlink channel state information from the terminal device received by the legitimate network device at a certain time, for example, the downlink channel state information from the terminal device received for the first time, or the downlink channel state information from the terminal device received for the most recent time, or the downlink channel state information from the terminal device received for the last time, or the downlink channel state information from the terminal device received for the Nth time, or the downlink channel state information corresponding to the best downlink reference signal quality, and so on.

[0087] The downlink channel state information may include, but is not limited to: a channel quality indicator (CQI) of a downlink reference signal, a precoding matrix indicator (PMI) of an uplink reference signal, a rank indication (RI) of an uplink reference signal, and the like.

[0088] In a possible implementation, before S201, the terminal device measures a downlink reference signal (such as a channel state information reference signal (CSI-RS)) from a legitimate network device and records the measurement result of the downlink reference signal. The terminal device sends the measurement result to the legitimate network device, and the legitimate network device records the measurement result after receiving it.

[0089] Optionally, the downlink reference signal measurement may be periodic, for example, the legal network device configures the downlink reference signal transmission period and time-frequency resource position, and sends it according to the configured period. Alternatively, the downlink reference signal measurement may be semi-periodic, for example, the legal network device notifies the terminal device of each downlink reference signal transmission through downlink control information (DCI) signaling. Alternatively, the downlink reference signal measurement may be semi-static, and the legal network device configures the downlink reference signal transmission period and time-frequency resource position and notifies the terminal device, and activates / deactivates the transmission of the downlink reference signal through the media intervention control element (MAC control element, MAC CE). This application does not make specific limitations.

[0090] Since the modulation level is related to the quality of the communication channel, the better the channel quality, the higher the modulation level. Therefore, if an illegal network device (or illegal terminal device) communicates with a terminal device, the communication channel will change. The channel quality between the illegal network device and the terminal device is different from the channel quality between the legal network device and the terminal device. The illegal network device may even be unable to support high-order modulation levels. Therefore, the modulation level of the downlink message sent by the illegal network device is inconsistent with the modulation level of the downlink message sent by the legal network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0091] If the above-mentioned network device is a legal network device, the first physical layer configuration information is the first physical layer configuration information recorded in the history of the legal network device. It can be understood that the first physical layer configuration information can be the configuration information of the uplink message or downlink message between the terminal device and the legal network device before S201, and the configuration information of the message is related to the channel between the terminal device and the legal network device. For example, the first physical layer measurement information recorded in the history can be the configuration information of the downlink message of the legal network device before S201. For another example, the first physical layer measurement information recorded in the history can be the configuration information of the uplink message sent by the terminal device to the legal network device before S201.

[0092] Exemplarily, the first physical layer configuration information may include at least one of the following items: a modulation level adopted by the second message, a system frame number carried or used by the second message, a random access timing index carried or used by the second message, and a preamble code index carried or used by the second message, wherein the second message is the last downlink message sent, or the second message is the downlink message with the best signal quality among the downlink messages sent within a preset time period.

[0093] Since the modulation level is related to the quality of the communication channel, the better the channel quality, the higher the modulation level. Therefore, if an illegal network device (or illegal terminal device) communicates with a terminal device, the communication channel will change. The channel quality between the illegal network device and the terminal device is different from the channel quality between the legal network device and the terminal device. The illegal network device may even be unable to support high-order modulation levels. Therefore, the modulation level of the downlink message sent by the illegal network device is inconsistent with the modulation level of the downlink message sent by the legal network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0094] The system frame number, random access timing index, preamble index and other information are configured by the legitimate network device, and the illegal network device cannot obtain this information. Therefore, the information carried in the downlink message sent by the illegal network device is inconsistent with the information carried in the downlink message sent by the legitimate network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of the authentication relay attack, thereby preventing the authentication relay attack.

[0095] If the network device is an illegal network device, the first physical layer measurement information may be the first physical layer measurement information of the illegal network device history record, and the first physical layer configuration information may be the first physical layer configuration information of the illegal network device history record. Alternatively, the first physical layer measurement information and the first physical layer configuration information may also be empty, and this example may also be understood as the first message not indicating the first information. Alternatively, if the network device is an illegal network device, the first message may also carry other information, which is not specifically limited here.

[0096] S202, the terminal device determines whether the network device is legal according to the first information and the second information, where the second information includes at least one of the following: second physical layer measurement information recorded in the history, and second physical layer configuration information recorded in the history.

[0097] It can be understood that the second physical layer measurement information recorded in the history can be the physical layer measurement information recorded for the legal network device before S201. For example, the second physical layer measurement information can be the measurement result of the reference signal between the terminal device and the legal network device before S201, which is used to characterize the channel between the terminal device and the legal network device. The second physical layer measurement information can refer to the relevant description of the first physical layer measurement information of the legal network device, which will not be repeated here.

[0098] The second physical layer configuration information recorded in the historical record may be the physical layer configuration information recorded for the legal network device before S201. For example, the second physical layer configuration information recorded in the historical record may be the configuration information of the uplink message or downlink message between the terminal device and the legal network device before S201, and the configuration information of the message is related to the channel between the terminal device and the legal network device. The second physical layer configuration information may refer to the relevant description of the first physical layer configuration information of the legal network device, and will not be repeated here.

[0099] The method of determining whether a network device is legitimate will be described in detail below in conjunction with specific scenarios.

[0100] In the present application, the historical physical layer measurement information and the historical physical layer configuration information are carried in the messages sent by the legitimate network devices. Since the physical layer measurement information and the physical layer configuration information are related to the channels of the legitimate network devices, and the illegal network devices cannot obtain the channel conditions between the legitimate network devices and the terminal devices, they cannot carry information related to the channels of the legitimate network devices in the sent messages. Therefore, the terminal device can determine whether the message comes from the legitimate network device by comparing the information carried in the received message with the physical layer measurement information and the physical layer configuration information recorded by itself, thereby preventing authentication relay attacks.

[0101] The implementation method of S202 is introduced below in combination with specific scenarios.

[0102] Example 1, a method for implementing a connected terminal device to prevent an authentication relay attack. This example uses a first message to indicate the downlink channel state information last reported by the terminal device. The first message is illustrated by taking a radio resource control (RRC) reconfiguration message (RRCReconfiguration message) as an example. It should be noted that the first message can also be other messages, and this application does not make specific limitations.

[0103] like Figure 3 As shown, the method includes:

[0104] S301, the terminal device performs random access.

[0105] Specifically, the terminal device can perform random access through a four-step random access process or a two-step random access process, which will not be further described here.

[0106] It can be understood that after performing random access, the terminal device establishes an RRC connection with a legitimate network device and switches from an idle state to a connected state.

[0107] S302, the terminal device and the core network device complete security authentication.

[0108] It is understandable that after the terminal device and the core network device complete the security authentication, the core network device can send a message for notifying that the authentication is successful, and accordingly, the terminal device can receive a message for notifying that the authentication is successful. In one possible implementation, the core network device can send a message for notifying that the authentication is successful to the terminal device through the network device, and it is understandable that after forwarding by the network device, the terminal device can receive a third message, which is used to indicate that the authentication is successful.

[0109] In this way, security authentication is performed through the terminal device and the core network, so that the terminal device can record the relevant information of the downlink message after security authentication (such as downlink channel status information, modulation level, etc.), so that it can be identified whether the subsequent message comes from a legitimate network device based on the recorded information, so as to prevent authentication relay attacks.

[0110] Optionally, after the terminal device and the core network device complete security authentication, the network device and the terminal device have a symmetric key. The terminal device and the network device can use the key to encrypt messages, thereby preventing illegal base stations from tampering with authentication messages.

[0111] For example, the network device can carry a digital signature in the RRC reconfiguration message below, and the digital signature is encrypted using the private key corresponding to the key. Accordingly, after receiving the RRC reconfiguration message, the terminal device can use the public key corresponding to the key to decrypt the digital signature of the RRC reconfiguration message.

[0112] S303, the network device sends a downlink reference signal to the terminal device.

[0113] S304, the terminal device measures the downlink reference signal.

[0114] S305: The terminal device sends downlink channel status information to the network device.

[0115] S306: The terminal device records the downlink channel status information.

[0116] There is no strict execution order for S306 and S305. S305 may be executed first and then S306, or S306 may be executed first and then S305, or S305 and S306 may be executed simultaneously.

[0117] S307: The network device records the downlink channel state information.

[0118] There is no strict execution order for S306 and S307. S307 may be executed first and then S306, or S306 may be executed first and then S307, or S307 and S306 may be executed simultaneously.

[0119] S308, the network device sends an RRC reconfiguration message to the terminal device.

[0120] The RRC reconfiguration message carries the above-mentioned downlink channel state information.

[0121] S309: The terminal device compares the downlink channel state information carried in the RRC reconfiguration message with the last reported downlink channel state information recorded by itself.

[0122] If the downlink channel state information carried by the RRC reconfiguration message is consistent with the downlink channel state information reported last time recorded by itself, the terminal device can determine that the network device is legal. Optionally, if the network device is legal, the terminal device sends an RRC reconfiguration completion message to the network device.

[0123] If the downlink channel state information carried in the RRC reconfiguration message is inconsistent with the last reported downlink channel state information recorded by the terminal device, the terminal device can determine that the network device is illegal.

[0124] Optionally, in the above example 1, after S307, the network device may also send a downlink reference signal, so that the terminal device may carry the measured downlink channel state information in the RRC reconfiguration completion message. In this solution, the terminal device and the network device may record the downlink channel state information measured this time, so that the terminal device can identify subsequent messages.

[0125] Since the downlink channel status information can provide feedback on the communication channel quality between the terminal device and the legitimate network device, if an illegal network device (or illegal terminal device) communicates with the terminal device, the communication channel will change, and the downlink channel status information measured by the terminal device will be inconsistent with the downlink channel status information of the legitimate network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0126] Example 2, another implementation method for preventing authentication relay attacks on a connected terminal device. This example is illustrated by taking the first message indicating the modulation level adopted (or indicated) by the second message, the first message being a radio resource control (RRC) reconfiguration message (RRCReconfiguration message), and the second message being the last downlink message sent, or the second message being the downlink message with the best signal quality among the downlink messages sent within a preset time period. It should be noted that the first message may also be other messages, and this application does not make specific limitations.

[0127] like Figure 4 As shown, the method includes:

[0128] S401~S402, refer to the above-mentioned S301~S302, and will not be repeated here.

[0129] S403, the network device sends a downlink message to the terminal device.

[0130] It is understandable that in step S403, the network device may send one or more downlink messages to the terminal device. The present application does not limit the order in which the multiple downlink messages are sent.

[0131] S404, the terminal device records the modulation level of the received downlink message.

[0132] The modulation level of the downlink message may refer to the modulation level adopted or indicated by the downlink message.

[0133] For example, the modulation level of the received downlink message may be recorded after the timer T is started. Optionally, the timer T may be started after the terminal device receives the first downlink message.

[0134] S405, the network device sends an RRC reconfiguration message to the terminal device.

[0135] The RRC reconfiguration message is modulated using the modulation level of the second message, wherein the second message is the last sent downlink message, or the second message is the downlink message with the best signal quality among the downlink messages sent within a preset time period, wherein the preset time period may be the above-mentioned timer T.

[0136] S406: The terminal device compares the modulation level adopted by the RRC reconfiguration message with the modulation level of the second message recorded by itself.

[0137] If the modulation level used by the RRC reconfiguration message is consistent with the modulation level of the second message recorded by itself, the terminal device can determine that the network device is legal. Optionally, if the network device is legal, the terminal device sends an RRC reconfiguration completion message to the network device.

[0138] If the modulation level used by the RRC reconfiguration message is inconsistent with the modulation level of the second message recorded by itself, the terminal device can determine that the network device is illegal.

[0139] Since the modulation level is related to the quality of the communication channel, the better the channel quality, the higher the modulation level. Therefore, if an illegal network device (or illegal terminal device) communicates with a terminal device, the communication channel will change. The channel quality between the illegal network device and the terminal device is different from the channel quality between the legal network device and the terminal device. The illegal network device may even be unable to support high-order modulation levels. Therefore, the modulation level of the downlink message sent by the illegal network device is inconsistent with the modulation level of the downlink message sent by the legal network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0140] Example 3, a method for implementing a non-connected terminal device to prevent an authentication relay attack. Specifically, a non-connected terminal device can prevent an authentication relay attack during a random access process. This example is described by taking the first message indicating the modulation level used (or indicated) by Msg2, and the first message being Msg4 as an example.

[0141] like Figure 5 As shown, the method includes:

[0142] S501, the terminal device sends Msg1 to the network device.

[0143] For Msg1, please refer to the related introduction of Msg1 in the previous terminology, which will not be repeated here.

[0144] S502, the network device sends Msg2 to the terminal device.

[0145] For Msg2, please refer to the related introduction of Msg2 in the previous terminology, which will not be repeated here.

[0146] Optionally, Msg2 may be encrypted using a private key. For example, Msg2 may carry a digital signature encrypted using the private key. In a possible implementation, the network device may summarize the message content of Msg2 and then encrypt the summary using the private key.

[0147] If Msg2 is encrypted, the terminal device can use the public key to decrypt Msg2 to verify that the content of the Msg2 sent has not been tampered with by an illegal device. For example, if Msg2 carries a digital signature, the terminal device can use the public key to decrypt the digital signature of Msg2 to determine whether the content of the Msg2 sent has been tampered with by an illegal device. In addition, since an illegal network device cannot obtain a configuration certificate, it cannot obtain a legal public key. Therefore, the above solution can also be used to determine whether Msg2 comes from a legal network device.

[0148] Among them, the public key can be indicated to the terminal device by the network device. For example, the network device can obtain a configuration certificate from a third-party device (such as an operator, application (APP) server, etc.), and the configuration certificate includes the public key and indicates it to the terminal device.

[0149] The terminal device and the network device can record the modulation level indicated by Msg2.

[0150] S503, the terminal device sends Msg3 to the network device.

[0151] For Msg3, please refer to the related introduction of Msg3 in the previous terminology, which will not be repeated here.

[0152] S504, the network device sends Msg4 to the terminal device.

[0153] The modulation level used by Msg4 is the modulation level indicated by Msg2.

[0154] Optionally, Msg4 may be encrypted using a private key. For example, Msg4 may carry a digital signature encrypted using the private key. In a possible implementation, the network device may summarize the message content of Msg4 and then encrypt the summary using the private key.

[0155] The above example can identify whether the message content of the fourth message has been tampered with by encrypting the fourth message. In addition, since illegal network devices cannot obtain configuration certificates, they cannot obtain legal public keys. Therefore, the above scheme can also be used to determine whether Msg4 comes from a legal network device.

[0156] S505: The terminal device compares the modulation level used by Msg4 with the modulation level indicated by Msg2 recorded in the terminal device.

[0157] If the modulation level used in Msg4 is consistent with the modulation level indicated by Msg2 recorded by itself, the terminal device can determine that the network device is legal. Optionally, if the network device is legal, the terminal device can perform data transmission with the network device.

[0158] If the modulation level used in Msg4 is inconsistent with the modulation level indicated by Msg2 recorded in itself, the terminal device can determine that the network device is illegal.

[0159] Optionally, if Msg2 and Msg4 carry digital signatures, the terminal device can also use the public key to decrypt the digital signature of Msg4 when determining whether the network device is legitimate, so as to determine whether the content of the sent Msg4 has been tampered with. The public key for decrypting the digital signature of Msg4 is the same as the public key for decrypting the digital signature of Msg2.

[0160] Since the modulation level is related to the quality of the communication channel, the better the channel quality, the higher the modulation level. Therefore, if an illegal network device (or illegal terminal device) communicates with a terminal device, the communication channel will change. The channel quality between the illegal network device and the terminal device is different from the channel quality between the legal network device and the terminal device. Even the illegal network device may not be able to support high-order modulation levels. Therefore, the modulation level of Msg4 sent by the illegal network device is inconsistent with the modulation level of Msg2 sent by the legal network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0161] In addition, the above example can identify whether the message contents of Msg2 and Msg4 have been tampered with by carrying digital signatures in Msg2 and Msg4, which is beneficial to improving communication security.

[0162] Based on the same inventive concept as the method embodiment, the present application embodiment provides a communication device, the structure of which can be as follows: Figure 6 As shown, it includes a communication unit 601 and a processing unit 602.

[0163] In one embodiment, the communication device can be used to implement Figure 2In the embodiment of the method executed by the terminal device, the device may be the terminal device itself, or a chip or chipset in the terminal device or a part of the chip for executing the function of the related method. Among them, the communication unit 601 is used to receive a first message, the first message indicates first information, and the first information includes at least one of the following: first physical layer measurement information, first physical layer configuration information. The processing unit 602 is used to determine whether the network device is legal based on the first information and the second information, and the second information includes at least one of the following: second physical layer measurement information recorded in the history, and second physical layer configuration information recorded in the history.

[0164] Exemplarily, the first physical layer measurement information includes the downlink channel state information carried by the first message, and the second physical layer measurement information includes the downlink channel state information reported last time.

[0165] Exemplarily, the first physical layer configuration information includes at least one of the following: a modulation level used by the first message, a system frame number carried by the first message, a random access timing index carried by the first message, and a preamble code index carried by the first message; the second physical layer configuration information includes at least one of the following: a modulation level used by the second message, a system frame number indicated by the second message, a random access timing index indicated by the second message, and a preamble code index indicated by the second message, wherein the second message is the last received downlink message, or the second message is the downlink message with the best signal quality among the downlink messages received within a preset time period.

[0166] Optionally, the processing unit 602 is specifically configured to: if the first information is consistent with the second information, the network device is legal.

[0167] Optionally, if the network device is legal, the communication unit 601 is further used to: receive a downlink reference signal; and send a response message to the first message, wherein the response message carries physical layer measurement information corresponding to the downlink reference signal.

[0168] Optionally, the communication unit 601 is further used to: receive a third message before receiving the first message, where the third message is used to indicate that the authentication is successful.

[0169] Exemplarily, the first message is an RRC reconfiguration message.

[0170] Exemplarily, the first physical layer configuration information includes at least one of the following: a modulation level used by the first message, a system frame number carried by the first message, a random access timing index carried by the first message, and a preamble code index carried by the first message; the second physical layer configuration information includes at least one of the following: a modulation level indicated by a fourth message, a system frame number carried or used by the fourth message, a random access timing index carried or used by the fourth message, and a preamble code index carried or used by the fourth message, wherein the fourth message is the most recently received downlink message that was successfully decrypted using a public key.

[0171] Optionally, the processing unit 602 is specifically used to: if the first information is consistent with the second information, and the first message is successfully decrypted using the public key, then the network device is legal.

[0172] Optionally, the communication unit 601 is further used to: receive a system message, where the system message indicates a public key.

[0173] Exemplarily, the first message is message 4 in the random access process, and the fourth message is message 2 in the random access process.

[0174] In one embodiment, the communication device can be used to implement Figure 2 In the embodiment of the method executed by the network device, the device may be the network device itself, or a chip or chipset in the network device or a part of the chip used to execute the function of the related method.

[0175] The processing unit 602 is used to send a first message through the communication unit 601, where the first message indicates first information, and the first information includes at least one of the following: first physical layer measurement information recorded in the historical records, first physical layer configuration information recorded in the historical records, and the first information is used to determine whether the network device is legal.

[0176] Exemplarily, the first physical layer measurement information is the downlink channel state information received last time.

[0177] Exemplarily, the first physical layer configuration information includes at least one of the following: a modulation level adopted by the second message, a system frame number carried or used by the second message, a random access timing index carried or used by the second message, and a preamble code index carried or used by the second message, wherein the second message is the last downlink message sent, or the second message is the downlink message with the best signal quality among the downlink messages sent within a preset time period.

[0178] Optionally, the communication unit 601 is further used to: send a downlink reference signal; and receive a response message to the first message, where the response message carries physical layer measurement information corresponding to the downlink reference signal.

[0179] Optionally, the communication unit 601 is further used to: send a third message before sending the first message, where the third message is used to indicate that the authentication is successful.

[0180] Exemplarily, the first message is a radio resource control RRC reconfiguration message.

[0181] Exemplarily, the first physical layer configuration information includes at least one of the following items: a modulation level indicated by a fourth message, a system frame number indicated by the fourth message, a random access timing index indicated by the fourth message, and a preamble code index indicated by the fourth message, wherein the fourth message is the most recently sent downlink message encrypted with a private key, and the private key is the same as the private key used to encrypt the first message.

[0182] Optionally, the communication unit 601 is further used to: send a system message, where the system message indicates a public key corresponding to the private key.

[0183] Exemplarily, the first message is message 4 in the random access process, and the fourth message is message 2 in the random access process.

[0184] The division of modules in the embodiments of the present application is schematic and is only a logical function division. There may be other division methods in actual implementation. In addition, each functional module in each embodiment of the present application may be integrated into a processor, or may exist physically separately, or two or more modules may be integrated into one module. The above-mentioned integrated modules may be implemented in the form of hardware or in the form of software functional modules. It is understood that the functions or implementations of each module in the embodiments of the present application may further refer to the relevant description of the method embodiment.

[0185] In one possible approach, the communication device may be as follows Figure 7 As shown, the device may be a communication device or a chip in a communication device, wherein the communication device may be a terminal device in the above embodiment or a network device in the above embodiment. The device includes a processor 701 and a communication interface 702, and may also include a memory 703. Among them, the processing unit 602 may be the processor 701. The communication unit 601 may be the communication interface 702. Optionally, the processor 701 and the memory 703 may also be integrated together.

[0186] The processor 701 may be a CPU, or a digital processing unit, etc. The communication interface 702 may be a transceiver, or an interface circuit such as a transceiver circuit, or a transceiver chip, etc. The device further includes: a memory 703 for storing programs executed by the processor 701. The memory 703 may be a non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), etc., or a volatile memory (volatile memory), such as a random-access memory (RAM). The memory 703 is any other medium that can be used to carry or store desired program codes in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.

[0187] The processor 701 is used to execute the program code stored in the memory 703, specifically to execute the actions of the processing unit 602, which will not be described in detail in this application. The communication interface 702 is specifically used to execute the actions of the communication unit 601, which will not be described in detail in this application.

[0188] The specific connection medium between the communication interface 702, the processor 701 and the memory 703 is not limited in the embodiment of the present application. Figure 7 In the embodiment, the memory 703, the processor 701 and the communication interface 702 are connected via a bus 704. Figure 7 The connections between other components are shown in bold lines, which are only for illustration and are not intended to be limiting. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 7 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0189] An embodiment of the present invention further provides a computer-readable storage medium for storing computer software instructions required to be executed by the above-mentioned processor, which includes a program required to be executed by the above-mentioned processor.

[0190] The present application also provides a communication system, including a Figure 2 In the embodiment of the terminal device function and the communication device for realizing Figure 2 The communication device of the network device function in the embodiment.

[0191] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0192] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0193] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0194] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0195] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

Claims

1. A communication method, characterized in that: The method comprises: receiving a first message, where the first message indicates first information, where the first information includes at least one of the following: first physical layer measurement information and first physical layer configuration information; Determine whether the network device is legal based on the first information and the second information, where the second information includes at least one of the following: second physical layer measurement information recorded in the historical records, and second physical layer configuration information recorded in the historical records.

2. The method according to claim 1, characterized in that The first physical layer measurement information includes the downlink channel state information carried by the first message, and the second physical layer measurement information includes the downlink channel state information reported last time.

3. The method according to claim 1 or 2, characterized in that The first physical layer configuration information includes at least one of the following: a modulation level used by the first message, a system frame number carried by the first message, a random access opportunity index carried by the first message, and a preamble index carried by the first message; The second physical layer configuration information includes at least one of the following: a modulation level adopted by the second message, a system frame number indicated by the second message, a random access timing index indicated by the second message, and a preamble code index indicated by the second message, wherein the second message is the last received downlink message, or the second message is the downlink message with the best signal quality among the downlink messages received within a preset time period.

4. The method according to any one of claims 1 to 3, characterized in that: The determining whether the network device is legal according to the first information and the second information includes: If the first information is consistent with the second information, the network device is legal.

5. The method according to any one of claims 1 to 4, characterized in that: If the network device is legal, the method further includes: receiving a downlink reference signal; A response message is sent to the first message, where the response message carries physical layer measurement information corresponding to the downlink reference signal.

6. The method according to any one of claims 1 to 5, characterized in that: Before receiving the first message, the method further includes: A third message is received, where the third message is used to indicate that the authentication is successful.

7. The method according to any one of claims 1 to 6, characterized in that: The first message is a radio resource control RRC reconfiguration message.

8. The method according to claim 1 or 2, characterized in that: The first physical layer configuration information includes at least one of the following: a modulation level used by the first message, a system frame number carried by the first message, a random access opportunity index carried by the first message, and a preamble index carried by the first message; The second physical layer configuration information includes at least one of the following items: a modulation level indicated by a fourth message, a system frame number carried or used by the fourth message, a random access timing index carried or used by the fourth message, and a preamble code index carried or used by the fourth message, wherein the fourth message is the most recently received downlink message that was successfully decrypted using a public key.

9. The method according to claim 8, characterized in that The determining whether the network device is legal according to the first information and the second information includes: If the first information is consistent with the second information, and the first message is successfully decrypted using the public key, then the network device is legal.

10. The method according to claim 8 or 9, characterized in that The method further comprises: A system message is received, the system message indicating the public key.

11. The method according to any one of claims 8 to 10, characterized in that: The first message is message 4 in the random access process, and the fourth message is message 2 in the random access process.

12. A communication method, characterized in that: The method comprises: A first message is sent, where the first message indicates first information, where the first information includes at least one of the following: first physical layer measurement information recorded in history, first physical layer configuration information recorded in history, and the first information is used to determine whether the network device is legal.

13. The method according to claim 12, characterized in that The first physical layer measurement information is the downlink channel state information received last time.

14. The method according to claim 12 or 13, characterized in that The first physical layer configuration information includes at least one of the following: a modulation level adopted by the second message, a system frame number carried or used by the second message, a random access timing index carried or used by the second message, and a preamble code index carried or used by the second message, wherein the second message is the last downlink message sent, or the second message is the downlink message with the best signal quality among the downlink messages sent within a preset time period.

15. The method according to any one of claims 12 to 14, characterized in that: The method further comprises: Sending a downlink reference signal; A response message to the first message is received, where the response message carries physical layer measurement information corresponding to the downlink reference signal.

16. The method according to any one of claims 12 to 15, characterized in that: Before sending the first message, the method further includes: A third message is sent, where the third message is used to indicate that the authentication is successful.

17. The method according to any one of claims 12 to 16, characterized in that: The first message is a radio resource control RRC reconfiguration message.

18. The method according to claim 12 or 13, characterized in that The first physical layer configuration information includes at least one of the following items: a modulation level indicated by a fourth message, a system frame number indicated by a fourth message, a random access timing index indicated by a fourth message, and a preamble code index indicated by a fourth message, wherein the fourth message is the most recently sent downlink message encrypted with a private key, and the private key is the same as the private key used to encrypt the first message.

19. The method according to claim 18, characterized in that The method further comprises: A system message is sent, where the system message indicates a public key corresponding to the private key.

20. The method according to claim 18 or 19, characterized in that The first message is message 4 in the random access process, and the fourth message is message 2 in the random access process.

21. A communication device, characterized in that: The method comprises a unit or module for executing the method according to any one of claims 1 to 11, or comprises a unit or module for executing the method according to any one of claims 12 to 20.

22. A computer-readable storage medium, characterized in that: The computer storage medium stores computer-readable instructions, and when the computer-readable instructions are executed on the communication device, the method according to any one of claims 1 to 11 is executed, or the method according to any one of claims 12 to 20 is executed.

23. A computer program product, characterized in that When the computer program product runs on a device, the device is enabled to execute the method according to any one of claims 1 to 11 or the method according to any one of claims 12 to 20.