Data packet sending method, system and equipment
By dynamically adjusting the MAC policy and calculating the MAC value, the problem of high MAC resource occupancy is solved, and more efficient and secure packet transmission is achieved.
Patent Information
- Application Number
- CN202311463177.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-02
- Publication Date
- 2025-05-06
AI Technical Summary
In the prior art, the message authentication code (MAC) policy is fixed, resulting in the MAC occupying higher network resources and computing resources during the packet transmission process.
By dynamically adjusting the MAC policy, calculate the MAC value based on the received MAC policy and message data, and dynamically adjust the MAC policy by counting the MAC verification error rate.
It reduces the use of network resources and computing resources of MAC, and improves the efficiency and security of packet transmission.
Smart Images

Figure CN119945696A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a method, system and device for sending a data packet. Background Art
[0002] Message Authentication Code (MAC) is a technology that confirms integrity and performs authentication. It is a verification mechanism used by both communicating entities and a tool to ensure the integrity of message data. MAC is a keyed hash function. Usually, the MAC strategy is fixed during the data packet transmission process, resulting in high MAC network resource and computing power resource usage. Summary of the invention
[0003] In view of this, an embodiment of the present invention provides a method, system and device for sending a data packet, which can dynamically adjust the MAC policy, thereby reducing the network resources and computing power resources occupied by the MAC.
[0004] In a first aspect, an embodiment of the present invention provides a method for sending a data packet, which is applied to a first device, and the method includes:
[0005] Obtain a first MAC value according to the first MAC policy and the first message data;
[0006] Packing the first message data and the first MAC value into a first data packet and sending it to the second device;
[0007] Receiving a second MAC policy sent by the second device;
[0008] Obtain a second MAC value according to the second MAC policy and the second message data;
[0009] The second message data and the second MAC value are packaged into a second data packet and sent to the second device. The embodiment of the present invention can dynamically adjust the MAC policy, thereby reducing the network resources and computing power resources occupied by the MAC.
[0010] In combination with the first aspect, in certain implementations of the first aspect, the first MAC policy is an initial MAC policy. In an embodiment of the present invention, the initial MAC policy is a MAC policy synchronized by the first device and the second device during the initialization phase. The initial MAC policy is usually a lower-level MAC policy selected by the first device 210 and the second device 220 from a pre-stored MAC policy table based on power consumption and latency. The initial MAC policy selection may be a decision by the second device 220 to notify the first device 210, or a decision by the first device 210 to notify the second device 220, or a dynamic negotiation handshake between the two parties; it may also be solidified in the first device 210 and the second device 220, or it may be selected by other methods. The embodiment of the present invention does not specifically limit the method of selecting the initial MAC policy.
[0011] In combination with the first aspect, in some implementations of the first aspect, the initial MAC policy includes: one or more of: a first network security level, a first MAC algorithm, and a first length.
[0012] In combination with the first aspect, in some implementations of the first aspect, obtaining the first MAC value according to the first MAC policy and the first message data includes:
[0013] Obtaining a first network security level according to the first MAC policy;
[0014] According to the first network security level, obtaining a first MAC algorithm matching the first network security level;
[0015] The first message data and the shared key are calculated by the first MAC algorithm to obtain the first MAC value, and the length of the first MAC value is the first length. The embodiment of the present invention determines the first network security level corresponding to the first MAC policy according to the first MAC policy, obtains the first MAC algorithm matching the first network security level, and calculates the first message data and the shared key by the first MAC algorithm to obtain the first MAC value, and the length of the first MAC value is the first length, thereby associating the MAC policy with the network security level, and being able to dynamically adjust the MAC policy as the network changes. Specifically, the embodiment of the present invention associates the MAC algorithm, the length of the MAC value and the network security level, so that the MAC algorithm and the length of the MAC value can be dynamically adjusted as the network security level changes.
[0016] In combination with the first aspect, in some implementations of the first aspect, the second MAC policy includes: one or more of a second network security level, a second MAC algorithm, and a second length; or
[0017] The second MAC policy includes: raising a network security level or lowering a network security level. In the embodiment of the present invention, the second MAC policy may be a specific policy, or may be raising a network security level or lowering a network security level based on the current network security level.
[0018] In combination with the first aspect, in some implementations of the first aspect, obtaining the second MAC value according to the second MAC policy and the second message data includes:
[0019] Obtain a second network security level according to the second MAC policy and the current network security level;
[0020] According to the second network security level, obtaining a second MAC algorithm matching the second network security level;
[0021] The second message data and the shared key are calculated by the second MAC algorithm to obtain the second MAC value, and the length of the second MAC value is the second length. The embodiment of the present invention determines the second network security level according to the second MAC policy and the current network security level, obtains the second MAC algorithm matching the second network security level, and calculates the second message data and the shared key by the second MAC algorithm to obtain the second MAC value, and the length of the second MAC value is the second length, thereby associating the MAC policy with the network security level, and being able to dynamically adjust the MAC policy as the network changes. Specifically, the embodiment of the present invention associates the MAC algorithm, the length of the MAC value and the network security level, so that the MAC algorithm and the length of the MAC value can be dynamically adjusted as the network security level changes.
[0022] In combination with the first aspect, in some implementations of the first aspect, obtaining, according to the second network security level, a second MAC algorithm matching the second network security level includes:
[0023] According to the second network security level, the second MAC algorithm is obtained by adjusting the value of the parameter in the current MAC algorithm to a value matching the second network security level. The embodiment of the present invention can use a MAC algorithm to achieve a change in network security level by adjusting the parameters of the MAC algorithm.
[0024] In combination with the first aspect, in some implementations of the first aspect, obtaining, according to the second network security level, a second MAC algorithm matching the second network security level includes:
[0025] According to the second network security level, the second MAC algorithm is obtained by selecting a MAC algorithm matching the second network security level from multiple MAC algorithms. In the embodiment of the present invention, multiple MAC algorithms can be used to associate different MAC algorithms with different network security levels, and the associated MAC algorithm is selected when the network security level changes.
[0026] In combination with the first aspect, in some implementations of the first aspect, the first length and the second length are different; the first network security level is higher than the second network security level, and the first length is greater than the second length; or, the first network security level is lower than the second network security level, and the first length is less than the second length. In an embodiment of the present invention, the length of the MAC value increases with the increase of the network security level, which can improve the security of the MAC verification.
[0027] In a second aspect, an embodiment of the present invention provides a method for sending a data packet, which is applied to a second device, and the method includes:
[0028] Receive a first data packet sent by a first device, and perform MAC verification on the first data packet using a first MAC policy;
[0029] Obtaining a second MAC policy by counting the error rate of MAC verification, and sending the second MAC policy to the first device;
[0030] Receive a second data packet sent by the first device, and perform MAC verification on the second data packet through the second MAC policy. The embodiment of the present invention associates the MAC policy with a network parameter, namely, the error rate of the MAC verification, and can dynamically adjust the MAC policy as the network changes, thereby reducing the network resources and computing power resources occupied by the MAC.
[0031] In conjunction with the second aspect, in some implementations of the second aspect, obtaining the second MAC policy by counting the error rate of MAC verification includes:
[0032] Statistics on MAC check error rate;
[0033] When the error rate does not fall within the preset interval, a second MAC policy is generated. For example, the preset interval is [5%, 10%]. When the error rate is greater than 10% or less than 5%, the second MAC policy is generated to adjust the MAC policy.
[0034] In conjunction with the second aspect, in certain implementations of the second aspect, the counting of the error rate of the MAC check includes: counting the error rate of the MAC check according to a preset number of times of the MAC check. For example, the preset number is 1000 times, and when 1000 MAC checks are performed for each 1000 data packets received, the error rate of the 1000 MAC checks is counted. If 20 of the 1000 MAC checks fail, the error rate of the 1000 MAC checks is 2%.
[0035] In conjunction with the second aspect, in certain implementations of the second aspect, the counting of the error rate of the MAC check includes: periodically counting the error rate of the MAC check according to the preset time of the MAC check. For example, the preset time is 30 minutes, and the error rate of the MAC check within 30 minutes is counted once every 30 minutes. If a total of 500 data packets are received within 30 minutes and 500 MAC checks are performed, and 10 of the checks fail, then the error rate of the MAC check within the 30 minutes is 2%.
[0036] In conjunction with the second aspect, in certain implementations of the second aspect, when the error rate is greater than the maximum value of the preset interval, the second MAC policy is to increase the network security level by one; or, when the error rate is less than the minimum value of the preset interval, the second MAC policy is to decrease the network security level by one. For example, when the preset interval is [5%, 10%], when the error rate is greater than 10%, the second MAC policy is to increase the network security level by one; when the error rate is less than 5%, the second MAC policy is to decrease the network security level by one.
[0037] In conjunction with the second aspect, in some implementations of the second aspect, the first data packet includes: first message data and a first MAC value;
[0038] The performing MAC verification on the first data packet by using the first MAC policy includes:
[0039] Obtaining a first network security level according to the first MAC policy;
[0040] According to the first network security level, obtaining a first MAC algorithm matching the first network security level;
[0041] Calculate the first message data and the shared key by using the first MAC algorithm to obtain a third MAC value;
[0042] Determine whether the first MAC value and the third MAC value are consistent;
[0043] If it is determined that the first MAC value and the third MAC value are consistent, the result of this MAC verification is successful;
[0044] If it is determined that the first MAC value and the third MAC value are inconsistent, the result of this MAC verification is failure. The embodiment of the present invention verifies the first MAC value by determining whether the first MAC value and the third MAC value are consistent. If the first MAC value and the third MAC value are consistent, the verification succeeds; if the first MAC value and the third MAC value are inconsistent, the verification fails.
[0045] In conjunction with the second aspect, in some implementations of the second aspect, the method further includes:
[0046] If the error rate does not decrease after changing the MAC policy, generating a third MAC policy;
[0047] The third MAC policy is sent to the first device. In the embodiment of the present invention, if the error rate has been reduced to a preset range after the MAC policy is changed, it indicates that the network is attacked externally, causing the error rate to increase, and the error rate can be effectively reduced by changing the MAC policy. Therefore, there is no need to adjust the MAC policy, and the current MAC policy can be maintained.
[0048] In the embodiment of the present invention, if the error rate does not decrease after the MAC policy is changed, it indicates that the network is affected by the environment and the error rate is increased. Even by changing the MAC policy, the error rate cannot be reduced. If the changed MAC policy is maintained at this time, the network resources and computing power resources of the MAC will be occupied more. It is necessary to generate a third MAC policy to restore to the previous MAC policy.
[0049] In conjunction with the second aspect, in certain implementations of the second aspect, the third MAC policy is to restore to the previous MAC policy. In the embodiment of the present invention, if the error rate does not decrease after the MAC policy is changed, it indicates that the network is affected by the environment and the error rate is increased, and even by changing the MAC policy, the error rate cannot be reduced, so the previous MAC policy can be restored. .
[0050] In a third aspect, an embodiment of the present invention provides a data packet sending system, the system comprising:
[0051] The first device is configured to obtain a first MAC value according to a first MAC policy and first message data; and to package the first message data and the first MAC value into a first data packet and send the first data packet to the second device;
[0052] The second device is configured to perform MAC verification on the first data packet by using the first MAC policy; obtain a second MAC policy by counting the error rate of the MAC verification, and send the second MAC policy to the first device;
[0053] The first device is further configured to obtain a second MAC value according to a second MAC policy and second message data; and to package the second message data and the second MAC value into a second data packet and send the second data packet to the second device;
[0054] The second device is further configured to perform MAC check on the second data packet using the second MAC policy.
[0055] In a fourth aspect, an embodiment of the present invention provides a device, comprising a processor and a memory, wherein the memory is used to store a program, the program comprising program instructions, and when the processor runs the program instructions, the device executes the steps of the method described above.
[0056] In a fifth aspect, an embodiment of the present invention provides a readable storage medium, wherein the readable storage medium stores a program, wherein the program includes program instructions, and when the program request is run by a device, the device is caused to execute the method as described above.
[0057] In a sixth aspect, an embodiment of the present invention provides a program product, which includes instructions. When the program product is run on a device or any at least one processor, the device executes the functions / steps in the above method.
[0058] In the technical solutions of the data packet sending method, system and device provided in the embodiments of the present invention, the first device obtains a first MAC value according to a first MAC policy and first message data, packages the first message data and the first MAC value into a first data packet and sends it to the second device; the second device performs MAC verification on the first data packet according to the first MAC policy, obtains a second MAC policy by counting the error rate of the MAC verification, and sends the second MAC policy to the first device; the first device obtains a second MAC value according to the second MAC policy and the second message data, packages the second message data and the second MAC value into a second data packet and sends it to the second device; the second device performs MAC verification on the second data packet according to the second MAC policy, and can dynamically adjust the MAC policy, thereby reducing the network resources and computing power resources occupied by the MAC. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] Figure 1 A schematic diagram of the structure of a device provided by an embodiment of the present invention;
[0060] Figure 2 is a software structure block diagram of the device 100 according to an embodiment of the present invention;
[0061] Figure 3 is a schematic diagram of a data packet sending system;
[0062] Figure 4An architectural diagram of a data packet sending system provided by an embodiment of the present invention;
[0063] Figure 5 A signaling interaction diagram for sending a data packet provided by an embodiment of the present invention;
[0064] Figure 6 for Figure 5 A flowchart in which a third calculation module obtains a first MAC value according to a first MAC strategy and first message data;
[0065] Figure 7 for Figure 5 A flowchart in which the fourth calculation module obtains a third MAC value according to the first MAC strategy and the first data message;
[0066] Figure 8 for Figure 5 The second check module performs MAC check on the first MAC value according to the third MAC value to obtain a flow chart of the result of this MAC check;
[0067] Fig. 9 for Figure 5 The second decision module obtains a flow chart of the second MAC strategy by counting the error rate of MAC verification;
[0068] Fig.10 for Figure 5 A flowchart in which a third calculation module obtains a second MAC value according to a second MAC strategy and second message data;
[0069] Fig.11 for Figure 5 A flowchart in which a fourth calculation module obtains a fourth MAC value according to a second MAC strategy and second message data;
[0070] Fig.12 A flow chart of sending a data packet provided by an embodiment of the present invention;
[0071] Fig.13 A schematic diagram of the structure of a first device provided in an embodiment of the present invention;
[0072] Fig.14 A schematic structural diagram of a second device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0073] In order to better understand the technical solution of the present invention, the embodiments of the present invention are described in detail below with reference to the accompanying drawings.
[0074] It should be clear that the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0075] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms "a", "said" and "the" used in the embodiments of the present invention and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings.
[0076] It should be understood that the term "and / or" used in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.
[0077] Figure 1 A schematic structural diagram of the device 100 is shown.
[0078] The device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, an air pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0079] It is to be understood that the structure illustrated in the embodiment of the present invention does not constitute a specific limitation on the device 100. In other embodiments of the present application, the device 100 may include more or fewer components than shown in the figure, or combine some components, or split some components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0080] The processor 110 may include one or more processing units, for example, the processor 110 may include an application processor (AP), a modem processor, a graphics processor (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units may be independent devices or integrated into one or more processors.
[0081] The controller can generate operation control signals according to the instruction operation code and timing signal to complete the control of instruction fetching and execution.
[0082] The processor 110 may also be provided with a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory may store instructions or data that the processor 110 has just used or cyclically used. If the processor 110 needs to use the instruction or data again, it may be directly called from the memory. This avoids repeated access, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.
[0083] In some embodiments, the processor 110 may include one or more interfaces. The interface may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0084] The USB interface 130 is an interface that complies with the USB standard specification, and specifically can be a Mini USB interface, a Micro USB interface, a USB Type C interface, etc. The USB interface 130 can be used to connect a charger to charge the device 100, and can also be used to transfer data between the device 100 and peripheral devices. It can also be used to connect headphones to play audio through the headphones. The interface can also be used to connect other devices, such as AR devices, etc.
[0085] It is understandable that the interface connection relationship between the modules illustrated in the embodiment of the present invention is only a schematic illustration and does not constitute a structural limitation on the device 100. In other embodiments of the present application, the device 100 may also adopt different interface connection methods in the above embodiments, or a combination of multiple interface connection methods.
[0086] The charging management module 140 is used to receive charging input from a charger. The charger can be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 can receive charging input from the wired charger through the USB interface 130. In some wireless charging embodiments, the charging management module 140 can receive wireless charging input through the wireless charging coil of the device 100. While the charging management module 140 is charging the battery 142, it can also power the device through the power management module 141.
[0087] The power management module 141 is used to connect the battery 142, the charging management module 140 and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140, and supplies power to the processor 110, the internal memory 121, the display screen 194, the camera 193, and the wireless communication module 160. The power management module 141 can also be used to monitor parameters such as battery capacity, battery cycle number, battery health status (leakage, impedance), etc. In some other embodiments, the power management module 141 can also be set in the processor 110. In other embodiments, the power management module 141 and the charging management module 140 can also be set in the same device.
[0088] The wireless communication function of the device 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor and the baseband processor.
[0089] Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve the utilization of the antennas. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.
[0090] The mobile communication module 150 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied on the device 100. The mobile communication module 150 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the processor 110. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the same device as at least some of the modules of the processor 110.
[0091] The modem processor may include a modulator and a demodulator. Among them, the modulator is used to modulate the low-frequency baseband signal to be sent into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After the low-frequency baseband signal is processed by the baseband processor, it is passed to the application processor. The application processor outputs a sound signal through an audio device (not limited to a speaker 170A, a receiver 170B, etc.), or displays an image or video through a display screen 194. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 110 and be set in the same device as the mobile communication module 150 or other functional modules.
[0092] The wireless communication module 160 can provide wireless communication solutions including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR), etc., which are applied to the device 100. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, modulates the frequency of the electromagnetic wave signal and performs filtering, and sends the processed signal to the processor 110. The wireless communication module 160 can also receive the signal to be sent from the processor 110, modulate the frequency of it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.
[0093] In some embodiments, the antenna 1 of the device 100 is coupled to the mobile communication module 150, and the antenna 2 is coupled to the wireless communication module 160, so that the device 100 can communicate with the network and other devices through wireless communication technology. The wireless communication technology may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology. The GNSS may include a global positioning system (GPS), a global navigation satellite system (GLONASS), a Beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS) and / or a satellite based augmentation system (SBAS).
[0094] The device 100 implements the display function through a GPU, a display screen 194, and an application processor. The GPU is a microprocessor for image processing, which connects the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 may include one or more GPUs that execute program instructions to generate or change display information.
[0095] The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode or an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), Miniled, MicroLed, Micro-oLed, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the device 100 may include 1 or N display screens 194, where N is a positive integer greater than 1.
[0096] The device 100 can implement a shooting function through an ISP, a camera 193, a video codec, a GPU, a display screen 194, and an application processor.
[0097] ISP is used to process the data fed back by camera 193. For example, when taking a photo, the shutter is opened, and the light is transmitted to the camera photosensitive element through the lens. The light signal is converted into an electrical signal, and the camera photosensitive element transmits the electrical signal to ISP for processing and converts it into an image visible to the naked eye. ISP can also perform algorithm optimization on the noise, brightness, and skin color of the image. ISP can also optimize the exposure, color temperature and other parameters of the shooting scene. In some embodiments, ISP can be set in camera 193.
[0098] The camera 193 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the optical signal into an electrical signal, and then passes the electrical signal to the ISP to be converted into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV or other format. In some embodiments, the device 100 may include 1 or N cameras 193, where N is a positive integer greater than 1.
[0099] The digital signal processor is used to process digital signals, and in addition to processing digital image signals, it can also process other digital signals. For example, when the device 100 is selecting a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy.
[0100] Video codecs are used to compress or decompress digital videos. Device 100 may support one or more video codecs. Thus, device 100 may play or record videos in multiple coding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, MPEG4, etc.
[0101] NPU is a neural network (NN) computing processor. By drawing on the structure of biological neural networks, such as the transmission mode between neurons in the human brain, it can quickly process input information and can also continuously self-learn. Through NPU, applications such as intelligent cognition of device 100 can be realized, such as image recognition, face recognition, voice recognition, text understanding, etc.
[0102] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the device 100. The external memory card communicates with the processor 110 through the external memory interface 120 to implement a data storage function, such as storing music, video and other files in the external memory card.
[0103] The internal memory 121 can be used to store computer executable program codes, which include instructions. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc. The data storage area may store data created during the use of the device 100 (such as audio data, a phone book, etc.), etc. In addition, the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc. The processor 110 executes various functional applications and data processing of the device 100 by running instructions stored in the internal memory 121 and / or instructions stored in a memory provided in the processor.
[0104] The device 100 can implement audio functions such as music playing and recording through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the headphone jack 170D, and the application processor.
[0105] The audio module 170 is used to convert digital audio information into analog audio signal output, and is also used to convert analog audio input into digital audio signals. The audio module 170 can also be used to encode and decode audio signals. In some embodiments, the audio module 170 can be arranged in the processor 110, or some functional modules of the audio module 170 can be arranged in the processor 110.
[0106] The speaker 170A, also called a "speaker", is used to convert an audio electrical signal into a sound signal. The device 100 can listen to music or listen to a hands-free call through the speaker 170A.
[0107] The receiver 170B, also called a "earpiece", is used to convert audio electrical signals into sound signals. When the device 100 receives a call or voice message, the voice can be received by placing the receiver 170B close to the human ear.
[0108] Microphone 170C, also called "microphone" or "microphone", is used to convert sound signals into electrical signals. When making a call or sending a voice message, the user can speak by putting their mouth close to microphone 170C to input the sound signal into microphone 170C. The device 100 can be provided with at least one microphone 170C. In other embodiments, the device 100 can be provided with two microphones 170C, which can not only collect sound signals but also realize noise reduction function. In other embodiments, the device 100 can also be provided with three, four or more microphones 170C to realize the collection of sound signals, noise reduction, identification of sound sources, realization of directional recording function, etc.
[0109] The earphone interface 170D is used to connect a wired earphone and can be a USB interface 130 or a 3.5 mm open mobile terminal platform (OMTP) standard interface or a cellular telecommunications industry association of the USA (CTIA) standard interface.
[0110] The key 190 includes a power key, a volume key, etc. The key 190 may be a mechanical key or a touch key. The device 100 may receive key input and generate key signal input related to user settings and function control of the device 100.
[0111] Motor 191 can generate vibration prompts. Motor 191 can be used for incoming call vibration prompts, and can also be used for touch vibration feedback. For example, touch operations acting on different applications (such as taking pictures, audio playback, etc.) can correspond to different vibration feedback effects. For touch operations acting on different areas of the display screen 194, motor 191 can also correspond to different vibration feedback effects. Different application scenarios (for example: time reminders, receiving messages, alarm clocks, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also support customization.
[0112] Indicator 192 may be an indicator light, which may be used to indicate charging status, power changes, messages, missed calls, notifications, etc.
[0113] The SIM card interface 195 is used to connect a SIM card. The SIM card can be connected to and separated from the device 100 by inserting it into the SIM card interface 195 or pulling it out from the SIM card interface 195. The device 100 can support 1 or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, and the like. Multiple cards can be inserted into the same SIM card interface 195 at the same time. The types of the multiple cards can be the same or different. The SIM card interface 195 can also be compatible with different types of SIM cards. The SIM card interface 195 can also be compatible with external memory cards. The device 100 interacts with the network through the SIM card to implement functions such as calls and data communications. In some embodiments, the device 100 uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the device 100 and cannot be separated from the device 100.
[0114] The software system of the device 100 may adopt a layered architecture, an event-driven architecture, a micro-kernel architecture, a micro-service architecture, or a cloud architecture. In the embodiment of the present invention, the Android system of the layered architecture is taken as an example to exemplify the software structure of the device 100.
[0115] Figure 2 It is a software structure block diagram of the device 100 according to an embodiment of the present invention.
[0116] The layered architecture divides the software into several layers, each with clear roles and division of labor. The layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers, from top to bottom: the application layer, the application framework layer, the Android runtime and system library, and the kernel layer.
[0117] The application layer can include a series of application packages.
[0118] like Figure 2As shown, the application package may include applications such as camera, gallery, calendar, call, map, navigation, WLAN, Bluetooth, music, video, short message, etc.
[0119] The application framework layer provides an application programming interface (API) and a programming framework for the applications in the application layer. The application framework layer includes some predefined functions.
[0120] like Figure 2 As shown, the application framework layer may include a window manager, a content provider, a view system, a phone manager, a resource manager, a notification manager, and the like.
[0121] The window manager is used to manage window programs. The window manager can obtain the display screen size, determine whether there is a status bar, lock the screen, capture the screen, etc.
[0122] Content providers are used to store and retrieve data and make it accessible to applications. The data may include videos, images, audio, calls made and received, browsing history and bookmarks, phone books, etc.
[0123] The view system includes visual controls, such as controls for displaying text, controls for displaying images, etc. The view system can be used to build applications. A display interface can be composed of one or more views. For example, a display interface including a text notification icon can include a view for displaying text and a view for displaying images.
[0124] The phone manager is used to provide communication functions of the device 100, such as management of call status (including connection, disconnection, etc.).
[0125] The resource manager provides various resources for applications, such as localized strings, icons, images, layout files, video files, and so on.
[0126] The notification manager allows applications to display notification information in the status bar. It can be used to convey notification-type messages and can disappear automatically after a short stay without user interaction. For example, the notification manager is used to notify download completion, message reminders, etc. The notification manager can also be a notification that appears in the system top status bar in the form of a chart or scroll bar text, such as notifications of applications running in the background, or a notification that appears on the screen in the form of a dialog window. For example, a text message is displayed in the status bar, a prompt sound is emitted, the device vibrates, the indicator light flashes, etc.
[0127] Android Runtime includes core libraries and virtual machines. Android runtime is responsible for scheduling and management of the Android system.
[0128] The core library consists of two parts: one part is the function that needs to be called by the Java language, and the other part is the Android core library.
[0129] The application layer and the application framework layer run in a virtual machine. The virtual machine executes the Java files of the application layer and the application framework layer as binary files. The virtual machine is used to perform functions such as object life cycle management, stack management, thread management, security and exception management, and garbage collection.
[0130] The system library may include multiple functional modules, such as surface manager, media library, 3D graphics processing library (such as OpenGL ES), 2D graphics engine (such as SGL), etc.
[0131] The surface manager is used to manage the display subsystem and provide the fusion of 2D and 3D layers for multiple applications.
[0132] The media library supports playback and recording of a variety of commonly used audio and video formats, as well as static image files, etc. The media library can support a variety of audio and video encoding formats, such as: MPEG4, H.264, MP3, AAC, AMR, JPG, PNG, etc.
[0133] The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, compositing, and layer processing.
[0134] A 2D graphics engine is a drawing engine for 2D drawings.
[0135] The kernel layer is the layer between hardware and software. The kernel layer contains at least display driver, camera driver, audio driver, and sensor driver.
[0136] The following is an illustrative description of the software and hardware workflow of the device 100 in conjunction with the capture and photo shooting scene.
[0137] When the touch sensor 180K receives a touch operation, the corresponding hardware interrupt is sent to the kernel layer. The kernel layer processes the touch operation into a raw input event (including touch coordinates, timestamp of the touch operation, and other information). The raw input event is stored in the kernel layer. The application framework layer obtains the raw input event from the kernel layer and identifies the control corresponding to the input event. For example, if the touch operation is a touch single-click operation and the control corresponding to the single-click operation is the control of the camera application icon, the camera application calls the interface of the application framework layer to start the camera application, and then starts the camera driver by calling the kernel layer to capture static images or videos through the camera 193.
[0138] Figure 3A schematic diagram of a data packet sending system is shown in FIG. Figure 3 As shown, the MAC calculation system includes a sending device and a receiving device. The same shared key and the same MAC algorithm are pre-made in the sending device and the receiving device. The sending device uses the shared key and the MAC algorithm to calculate the MAC value for the message data, such as the MAC algorithm is the AES algorithm, the DES algorithm or the SHA-256 algorithm. The sending device packages the message data and the MAC value into a data packet and sends it to the receiving device. The receiving device calculates the MAC value based on the data packet using the shared key and the MAC algorithm; then compares the MAC value calculated by itself with the MAC value from the sending device. If the two MAC values are consistent, the receiving device can determine that the data packet is indeed from the sending device and has not been tampered with or a transmission error has occurred, that is, the authentication is successful. If the two MAC values are inconsistent, the receiving device can determine that the data packet is not from the sending device, that is, the authentication fails.
[0139] Figure 3 In the data packet sending system shown, the input of the MAC algorithm is a message of any length and a shared key between a sending device and a receiving device, and the output of the MAC algorithm is a MAC value of fixed length. The length of the MAC value is fixed, and the transmission link bandwidth occupied by the MAC value will cause bandwidth waste, especially when the message data is short. Among them, the MAC algorithm for calculating the MAC value is fixed, which is not friendly to platforms with strict computing power requirements, and the same MAC strategy is used in both the sending direction and the receiving direction.
[0140] In summary, Figure 3 The data packet sending system shown has a MAC algorithm and a fixed length of a MAC value, which results in a technical problem of high MAC network resource and computing power resource usage.
[0141] Based on the above technical problem, an embodiment of the present invention provides a data packet sending system. Figure 4 An architectural diagram of a data packet sending system provided in an embodiment of the present invention.
[0142] The data packet transmission system includes a first device and a second device, and the first device and the second device are connected by wire or wirelessly. For example, the first device is a transmitting end and the second device is a receiving end. Figure 4As shown, the data packet sending system 200 includes a first device 210 and a second device 220, and the first device 210 and the second device 220 are connected by wire or wirelessly. The first device 210 includes a first decision module 211, message data 213, a shared key 214, a third calculation module 215 and a third communication module 216. The second device 220 includes a second decision module 221, a fourth communication module 223, a shared key 224, a fourth calculation module 225 and a second verification module 226. Data transmission is achieved between the first device 210 and the second device 220 through the third communication module 216 and the fourth communication module 223.
[0143] The first device 210 is an electronic device or a server. The second device 220 is an electronic device or a server. The hardware structure and software structure of the device provided in the embodiment of the present invention can be referred to in Figure 1 and Figure 2 For relevant description about device 100.
[0144] The first device 210 and the second device 220 are pre-configured with the same shared key, so the shared key 214 and the shared key 224 are the same.
[0145] Decision modules are deployed in both the first device 210 and the second device 220. The decision module at the receiving end evaluates security risks based on the real-time network security status. When the security risks are not within the safety range, the decision module changes the MAC policy and notifies the decision module at the sending end.
[0146] The first device 210 and the second device 220 are both equipped with a computing module, which is controlled by the decision module. The computing module calculates the MAC value or verifies the MAC value according to the MAC policy of the decision module.
[0147] The first device 210 and the second device 220 perform two-way authentication and synchronize the initial MAC policy during the initialization phase, and then perform data transmission according to the synchronized initial MAC policy during the data transmission phase. The initial MAC policy is usually a lower-level MAC policy selected by the first device 210 and the second device 220 from a pre-stored MAC policy table based on power consumption and latency. The initial MAC policy selection may be a decision by the second device 220 to notify the first device 210, or a decision by the first device 210 to notify the second device 220, or a dynamic negotiation handshake between the two parties; it may also be solidified in the first device 210 and the second device 220, or it may be selected by other methods. The embodiment of the present invention does not specifically limit the method of selecting the initial MAC policy.
[0148] The first device 210 sends based on the initial MAC policy, and the second device 220 verifies the received MAC value of the first device 210 and counts the error rate of the MAC verification, and determines whether to reselect the MAC policy based on the error rate of the MAC verification. When the error rate does not fall within the preset range, the second device 220 reselects the MAC policy and feeds back to the first device 210, so that the first device 210 sends based on the reselected MAC policy.
[0149] based on Figure 4 The data packet sending system 200 shown in the figure provides a data packet sending method according to an embodiment of the present invention.
[0150] Figure 5 A signaling interaction diagram of a data packet sending method provided by an embodiment of the present invention. Figure 5 As shown, the method includes:
[0151] Step 302: The message data module sends the first message data to the third calculation module.
[0152] Before this step, it is assumed that the first device and the second device have completed the two-way authentication and synchronized initial MAC policy in the initialization phase. The initial MAC policy is usually a lower-level MAC policy selected by the first device and the second device from a pre-stored MAC policy table based on power consumption and latency.
[0153] In this step, if Figure 4 As shown, the message data module 213 sends the first message data to the third calculation module 215 .
[0154] Exemplarily, the first message data includes a message data packet sent by the first device using an initial MAC policy.
[0155] Step 304: The third calculation module obtains a first MAC value according to the first MAC policy and the first message data, and packages the first message data and the first MAC value into a first data packet.
[0156] In this step, if Figure 4 As shown, the third calculation module 215 obtains a first MAC value according to the first MAC policy and the first message data, and packages the first message data and the first MAC value into a first data packet.
[0157] Exemplarily, the first MAC policy is an initial MAC policy.
[0158] Exemplarily, the initial MAC policy includes: one or more of a first network security level, a first MAC algorithm, and a first length.
[0159] Exemplarily, the first length is the length of a first MAC value obtained based on a first MAC algorithm.
[0160] Exemplarily, the shared key is a shared key between the first device and the second device.
[0161] In some possible embodiments, Figure 6 As shown, step 304 specifically includes:
[0162] Step 3042: The third calculation module obtains the first network security level according to the first MAC policy.
[0163] In this step, if Figure 4 As shown, the third calculation module 215 obtains the first network security level matching the first MAC policy according to the first MAC policy. The embodiment of the present invention associates the MAC policy with the network security level, and can dynamically adjust the MAC policy as the network changes.
[0164] Step 3044: The third calculation module obtains a first MAC algorithm that matches the first network security level according to the first network security level.
[0165] In this step, if Figure 4 As shown, the third calculation module 215 obtains a first MAC algorithm matching the first network security level according to the first network security level. The embodiment of the present invention associates the network security level with the MAC algorithm, and can dynamically adjust the MAC policy by dynamically adjusting the MAC algorithm as the network changes.
[0166] Step 3046: The third calculation module calculates the first message data and the shared key using the first MAC algorithm to obtain a first MAC value, and the length of the first MAC value is the first length.
[0167] In this step, if Figure 4 As shown, the third calculation module 215 calculates the first message data and the shared key through the first MAC algorithm to obtain a first MAC value, and the length of the first MAC value is the first length.
[0168] Exemplarily, the embodiments of the present invention can use a short MAC chain verification algorithm based on a sliding association window as a MAC algorithm to calculate the MAC value. A single data packet carries a short MAC value, and security is accumulated and enhanced through the associated subsequent data packets, and finally reaches the set security strength. The number of associated data packets is determined by setting the size of the association window. If the association window is 3, the association window can accommodate three data packets. Each time a new data packet is added, an old data packet needs to be discarded. If the previous data packet is forged, the MAC value authentication of the subsequent associated data packet will also fail; if the MAC value of the subsequent associated data packet is successfully verified, the security of the previous associated data packet will be enhanced. Among them, the cumulative security strength is related to the size of the association window, and the final accumulated security strength of a single data packet depends on the length of the MAC value that can be carried and the number of subsequent data packets that can be enhanced for verification. For example, the MAC value 1 of a data packet affects the MAC values of the three subsequent data packets, namely, MAC value 2, MAC value 3, and MAC value 4; MAC value 2 affects the MAC values of the three subsequent data packets, namely, MAC value 3, MAC value 4, and MAC value 5.
[0169] In the embodiment of the present invention, the MAC policy table includes multiple MAC policies, which are not limited to the above-mentioned network security level, MAC value length and MAC algorithm.
[0170] Step 306: The third computing module sends the first data packet to the third communication module.
[0171] In this step, if Figure 4 As shown, the third computing module 215 sends the first data packet to the third communication module 216 .
[0172] Step 308: The third communication module sends the first data packet to the fourth communication module.
[0173] In this step, if Figure 4 As shown, the third communication module 216 sends the first data packet to the fourth communication module 223 .
[0174] Step 310: The fourth communication module sends the first data to the fourth computing module.
[0175] In this step, if Figure 4 As shown, the fourth communication module 223 sends the first data to the fourth calculation module 225 .
[0176] Step 312: The fourth calculation module obtains a third MAC value according to the first MAC strategy and the first data message.
[0177] In this step, if Figure 4 As shown, the fourth calculation module 225 obtains a third MAC value according to the first MAC strategy and the first data message.
[0178] In some possible embodiments, Figure 7 As shown, step 312 specifically includes:
[0179] Step 3122: The fourth calculation module obtains the first network security level according to the first MAC policy.
[0180] In this step, if Figure 4 As shown, the fourth calculation module 225 obtains the first network security level matching the first MAC policy according to the first MAC policy. The embodiment of the present invention associates the MAC policy with the network security level, and can dynamically adjust the MAC policy as the network changes.
[0181] Step 3124: The fourth calculation module obtains a first MAC algorithm that matches the first network security level according to the first network security level.
[0182] In this step, if Figure 4 As shown, the fourth calculation module 225 obtains a first MAC algorithm matching the first network security level according to the first network security level. The embodiment of the present invention associates the network security level with the MAC algorithm, and can dynamically adjust the MAC policy by dynamically adjusting the MAC algorithm as the network changes.
[0183] Step 3126: The fourth calculation module calculates the first message data and the shared key using the first MAC algorithm to obtain a third MAC value.
[0184] In this step, if Figure 4 As shown, the fourth calculation module 225 calculates the first message data and the shared key through the first MAC algorithm to obtain a third MAC value.
[0185] Step 314: The fourth calculation module sends the first MAC value and the third MAC value to the second verification module.
[0186] In this step, if Figure 4 As shown, the fourth calculation module 225 sends the first MAC value and the third MAC value to the second verification module 226.
[0187] Step 316: The second verification module performs a MAC verification on the first MAC value according to the third MAC value to obtain a result of this MAC verification.
[0188] In this step, if Figure 4 As shown, the second verification module 226 performs a MAC verification on the first MAC value according to the third MAC value to obtain a result of this MAC verification.
[0189] In some possible embodiments, Figure 8As shown, step 316 specifically includes:
[0190] Step 3162: The second verification module determines whether the first MAC value and the third MAC value are consistent. If so, execute step 3164; if not, execute step 3166.
[0191] In this step, if Figure 4 As shown, the second verification module 226 determines whether the first MAC value and the third MAC value are consistent.
[0192] Step 3164: The result of this MAC verification is success; and continue to step 318.
[0193] In this step, if Figure 4 As shown, the second verification module 226 determines that the first MAC value and the third MAC value are consistent, and the result of this MAC verification is success.
[0194] Step 3166: The result of this MAC verification is failure; and continue to step 318.
[0195] In this step, if Figure 4 As shown, the second verification module 226 determines that the first MAC value and the third MAC value are inconsistent, and the result of this MAC verification is failure.
[0196] Step 318: The second verification module sends the result of this MAC verification to the second decision module.
[0197] In this step, if Figure 4 As shown, the second verification module 226 sends the result of this MAC verification to the second decision module 221.
[0198] Step 320: The second decision module obtains a second MAC policy by counting the error rate of MAC verification.
[0199] In this step, if Figure 4 As shown, the second decision module 221 obtains the second MAC policy by counting the error rate of MAC verification.
[0200] Exemplarily, the second MAC policy includes: one or more of: a second network security level, a second MAC algorithm, and a second length; or the second MAC policy includes: raising a network security level or lowering a network security level.
[0201] Exemplarily, the second length is the length of a second MAC value obtained based on the second MAC algorithm.
[0202] In the embodiment of the present invention, the MAC policy table includes multiple MAC policies, which are not limited to the above-mentioned network security level, MAC value length and MAC algorithm, and may also be other forms of MAC policies, which are not limited in the embodiment of the present invention.
[0203] In some possible embodiments, Fig. 9 As shown, step 320 specifically includes:
[0204] Step 3202: The second decision module counts the error rate of MAC verification.
[0205] In this step, if Figure 4 As shown, the second decision module 221 counts the error rate of MAC verification.
[0206] In some possible embodiments, step 3202 specifically includes: the second decision module 221 counts the error rate of MAC verification according to a preset number of MAC verifications.
[0207] For example, the preset number of times is 1000, and when 1000 MAC checks are performed for each 1000 packets received, the error rate of the 1000 MAC checks is counted. If 20 of the 1000 MAC checks fail, the error rate of the 1000 MAC checks is 2%.
[0208] In some possible embodiments, step 3202 specifically includes: the second decision module 221 periodically counts the error rate of the MAC check according to the preset time of the MAC check.
[0209] For example, the preset time is 30 minutes, and the MAC check error rate within 30 minutes is counted every 30 minutes. If a total of 500 data packets are received within 30 minutes and 500 MAC checks are performed, and 10 of them fail, then the MAC check error rate within this 30 minutes is 2%.
[0210] Step 3204: When the error rate does not fall within the preset interval, the second decision module generates a second MAC policy.
[0211] In this step, if Figure 4 As shown, when the error rate does not belong to the preset interval, the second decision module 221 generates a second MAC policy.
[0212] Exemplarily, if the error rate is greater than the maximum value of the preset interval, the second MAC policy is to increase the network security level; or, if the error rate is less than the minimum value of the preset interval, the second MAC policy is to decrease the network security level.
[0213] For example, the preset interval is [5%, 10%]. When the error rate is greater than 10% or less than 5%, the second MAC policy is triggered to adjust the MAC policy.
[0214] The embodiment of the present invention associates the MAC policy with a network parameter, namely, the error rate of MAC verification, and can dynamically adjust the MAC policy as the network changes, thereby reducing the network resources and computing power resources occupied by the MAC.
[0215] Step 322: The second decision module sends the second MAC policy to the fourth communication module and the fourth calculation module.
[0216] In this step, if Figure 4 As shown, the second decision module 221 sends the second MAC policy to the fourth communication module 223 and the fourth calculation module 225 .
[0217] Step 324: The fourth communication module sends the second MAC policy to the third communication module.
[0218] In this step, if Figure 4 As shown, the fourth communication module 223 sends the second MAC policy to the third communication module 216 .
[0219] Step 326: The third communication module sends the second MAC policy to the first decision module.
[0220] In this step, if Figure 4 As shown, the third communication module 216 sends the second MAC policy to the first decision module 211 .
[0221] Step 328: The first decision module sends the second MAC policy to the third calculation module.
[0222] In this step, if Figure 4 As shown, the first decision module 211 sends the second MAC policy to the third calculation module 215 .
[0223] Step 330: The message data module sends the second message data to the third calculation module.
[0224] In this step, if Figure 4 As shown, the message data module 213 sends the second message data to the third calculation module 215 .
[0225] Exemplarily, the second message data includes a message data packet sent by the first device using the second MAC policy.
[0226] Step 332: The third calculation module obtains a second MAC value according to the second MAC policy and the second message data, and packages the second message data and the second MAC value into a second data packet.
[0227] In this step, if Figure 4 As shown, the third calculation module 215 obtains a second MAC value according to the second MAC policy and the second message data, and packages the second message data and the second MAC value into a second data packet.
[0228] In some possible embodiments, Fig.10 As shown, step 332 specifically includes:
[0229] Step 3322: The third calculation module obtains a second network security level according to the second MAC policy and the current network security level.
[0230] In this step, if Figure 4 As shown, the third calculation module 215 obtains the second network security level according to the second MAC policy and the current network security level.
[0231] Exemplarily, if the second MAC policy is to increase the network security level by one level, then the second network security level is one level higher than the current network security level; if the second MAC policy is to decrease the network security level by one level, then the second network security level is one level lower than the current network security level.
[0232] Step 3324: The third calculation module obtains a second MAC algorithm that matches the second network security level according to the second network security level.
[0233] In this step, if Figure 4 As shown, the third calculation module 215 obtains a second MAC algorithm matching the second network security level according to the second network security level.
[0234] In some possible embodiments, step 3324 specifically includes: the third calculation module obtains the second MAC algorithm by adjusting the value of the parameter in the current MAC algorithm to a value matching the second network security level according to the second network security level. The embodiment of the present invention can use a MAC algorithm to achieve a change in the network security level by adjusting the parameters of the MAC algorithm.
[0235] In some possible embodiments, step 3324 specifically includes: the third calculation module obtains the second MAC algorithm by selecting a MAC algorithm matching the second network security level from multiple MAC algorithms according to the second network security level. Embodiments of the present invention can use multiple MAC algorithms, associate different MAC algorithms with different network security levels, and select the associated MAC algorithm when the network security level changes.
[0236] Step 3326: The third calculation module calculates the second message data and the shared key using a second MAC algorithm to obtain a second MAC value, and the length of the second MAC value is the second length.
[0237] In this step, if Figure 4 As shown, the third calculation module 215 calculates the second message data and the shared key through the second MAC algorithm to obtain a second MAC value, and the length of the second MAC value is the second length.
[0238] Optionally, the first length and the second length are the same. The embodiment of the present invention associates the MAC algorithm of the MAC policy with the network security level, so as to dynamically adjust the MAC policy by dynamically adjusting the MAC algorithm as the network security level changes.
[0239] Optionally, the first length and the second length are different; the first network security level is higher than the second network security level, and the first length is greater than the second length; or, the first network security level is lower than the second network security level, and the first length is less than the second length. In the embodiment of the present invention, the length of the MAC value increases as the network security level increases, which can improve the security of the MAC verification. In the embodiment of the present invention, the MAC algorithm and the length of the MAC value of the MAC policy are associated with the network security level, so that the MAC policy can be dynamically adjusted by dynamically adjusting the MAC algorithm and the length of the MAC value as the network security level changes.
[0240] Step 334: The third computing module sends the second data packet to the third communication module.
[0241] In this step, if Figure 4 As shown, the third computing module 215 sends the second data packet to the third communication module 216 .
[0242] Step 336: The third communication module sends the second data packet to the fourth communication module.
[0243] In this step, if Figure 4 As shown, the third communication module 216 sends the second data packet to the fourth communication module 223 .
[0244] Step 338: The fourth communication module sends the second data to the fourth computing module.
[0245] In this step, if Figure 4 As shown, the fourth communication module 223 sends the second data to the fourth calculation module 225 .
[0246] Step 340: The fourth calculation module obtains a fourth MAC value according to the second MAC policy and the second message data.
[0247] In this step, if Figure 4 As shown, the fourth calculation module 225 obtains a fourth MAC value according to the second MAC strategy and the second message data. In some possible embodiments, as Fig.11 As shown, step 340 specifically includes:
[0248] Step 3402: The fourth calculation module obtains the second network security level according to the second MAC policy and the current network security level.
[0249] In this step, if Figure 4 As shown, the fourth calculation module 225 obtains the second network security level according to the first MAC policy and the current network security level. The embodiment of the present invention associates the MAC policy with the network security level, and can dynamically adjust the MAC policy as the network changes.
[0250] Step 3404: The fourth calculation module obtains a second MAC algorithm that matches the second network security level according to the second network security level.
[0251] In this step, if Figure 4 As shown, the fourth calculation module 225 obtains a second MAC algorithm matching the second network security level according to the second network security level. The embodiment of the present invention associates the network security level with the MAC algorithm, and can dynamically adjust the MAC policy by dynamically adjusting the MAC algorithm as the network changes.
[0252] Step 3406: The fourth calculation module calculates the second message data and the shared key using the second MAC algorithm to obtain a fourth MAC value.
[0253] In this step, if Figure 4 As shown, the fourth calculation module 225 calculates the second message data and the shared key through the second MAC algorithm to obtain a fourth MAC value.
[0254] Step 342: The fourth calculation module sends the second MAC value and the fourth MAC value to the second verification module.
[0255] Step 344: The second verification module verifies the second MAC value according to the fourth MAC value.
[0256] In some possible embodiments, step 344 specifically includes:
[0257] Step 3442: The second verification module determines whether the second MAC value and the fourth MAC value are consistent. If so, execute step 3444; if not, execute step 3446.
[0258] In this step, if Figure 4 As shown, the second verification module 226 determines whether the second MAC value is consistent with the fourth MAC value.
[0259] Step 3444: The result of this MAC verification is success.
[0260] In this step, if Figure 4 As shown, the second verification module 226 determines that the second MAC value and the fourth MAC value are consistent, and the result of this MAC verification is successful. The second verification module 226 sends the result of this MAC verification to the second decision module 221, so that the second decision module 221 counts the error rate of MAC verification.
[0261] Step 3446: The result of this MAC verification is failure.
[0262] In this step, if Figure 4 As shown, the second verification module 226 determines that the second MAC value and the fourth MAC value are inconsistent, and the result of this MAC verification is failure. The second verification module 226 sends the result of this MAC verification to the second decision module 221, so that the second decision module 221 counts the error rate of MAC verification.
[0263] Optionally, the method further includes: if the statistical MAC check error rate does not decrease after the second decision module changes the MAC policy, generating a third MAC policy and sending the third MAC policy to the first device.
[0264] In the embodiment of the present invention, if the error rate has been reduced to a preset range after the MAC policy is changed, it indicates that the network is attacked externally, causing the error rate to increase. The error rate can be effectively reduced by changing the MAC policy. Therefore, there is no need to adjust the MAC policy, and the current MAC policy can be maintained.
[0265] In an embodiment of the present invention, if the error rate does not decrease after the MAC policy is changed, it indicates that the error rate of the network is increased due to the environment, and the error rate cannot be reduced even by changing the MAC policy. If the changed MAC policy is maintained at this time, the network resources and computing power resources of the MAC will be higher, and a third MAC policy needs to be generated to restore to the previous MAC policy.
[0266] Exemplarily, the third MAC policy is to restore to the previous MAC policy. In the embodiment of the present invention, if the error rate does not decrease after changing the MAC policy, it indicates that the network error rate is increased due to the environment, and the error rate cannot be reduced even by changing the MAC policy, so the previous MAC policy can be restored.
[0267] Before the second device counts the error rate of MAC verification, the first device and the second device negotiate the MAC policy. The first device selects a low-level MAC policy based on power consumption and latency to send. The second device verifies the MAC value received from the first device and counts the error rate of MAC verification, and determines whether to reselect the MAC policy based on the error rate of MAC verification. When the error rate does not fall within the preset range, the second device reselects the MAC policy.
[0268] In summary, the embodiment of the present invention deploys a decision module in the device, decides the MAC strategy according to the actual network parameters, and converges to the optimal MAC strategy through closed-loop feedback of the transceiver, so as to dynamically adjust the MAC strategy and reduce the network resources and computing power resources occupied by the MAC.
[0269] Furthermore, different MAC strategies match different network security levels, and different network security levels match different MAC algorithms. When there is no external attack, low-computing-power weak-level algorithms can be used. Therefore, the MAC algorithm can be dynamically adjusted according to the actual network status to reduce the occupancy of MAC computing resources. At the same time, the receiving direction and the sending direction are controlled separately, and the closed-loop feedback convergence is controlled separately. The sending end and the receiving end can choose different MAC strategies.
[0270] Furthermore, different MAC algorithms correspond to different MAC value lengths, so that the length of the MAC value becomes longer as the network security level increases, which can improve the security of MAC verification.
[0271] Fig.12 A flow chart of a method for sending a data packet provided by an embodiment of the present invention. Fig.12 As shown, the method includes:
[0272] Step 402: The first device obtains a first MAC value according to the first MAC policy and the first message data, packages the first message data and the first MAC value into a first data packet, and sends the first data packet to the second device.
[0273] In some possible embodiments, step 402 specifically includes: the first device obtains a first network security level according to a first MAC policy; according to the first network security level, obtains a first MAC algorithm that matches the first network security level; calculates the first message data and the shared key through the first MAC algorithm to obtain a first MAC value, and the length of the first MAC value is a first length.
[0274] Exemplarily, the first MAC policy is an initial MAC policy.
[0275] Step 404: The second device performs MAC verification on the first data packet using the first MAC policy, obtains a second MAC policy by counting the error rate of the MAC verification, and sends the second MAC policy to the first device.
[0276] In some possible embodiments, step 404 specifically includes: the second device obtains a first network security level according to a first MAC policy; according to the first network security level, obtains a first MAC algorithm that matches the first network security level; calculates the first message data and the shared key through the first MAC algorithm to obtain a third MAC value; determines whether the first MAC value and the third MAC value are consistent; if it is determined that the first MAC value and the third MAC value are consistent, the result of this MAC verification is success; if it is determined that the first MAC value and the third MAC value are inconsistent, the result of this MAC verification is failure.
[0277] Exemplarily, the second MAC policy includes: increasing a network security level or decreasing a network security level.
[0278] In some possible embodiments, step 404 specifically includes: the second device counts the error rate of MAC verification; when the error rate does not fall within a preset range, generates a second MAC policy.
[0279] In some possible embodiments, the second device counts the error rate of the MAC check according to a preset number of MAC checks.
[0280] In some possible embodiments, the second device periodically counts the error rate of the MAC check according to a preset time of the MAC check.
[0281] Exemplarily, if the error rate is greater than the maximum value of the preset interval, the second MAC policy is to increase the network security level; or, if the error rate is less than the minimum value of the preset interval, the second MAC policy is to decrease the network security level.
[0282] Step 406: The first device obtains a second MAC value according to the second MAC policy and the second message data, packages the second message data and the second MAC value into a second data packet and sends it to the second device.
[0283] In some possible embodiments, step 406 specifically includes: the first device obtains a second network security level according to the second MAC policy and the current network security level; obtains a second MAC algorithm matching the second network security level according to the second network security level; calculates the second message data and the shared key through the second MAC algorithm to obtain a second MAC value, and the length of the second MAC value is the second length.
[0284] In some possible embodiments, the first device obtains the second MAC algorithm according to the second network security level by adjusting the values of parameters in the current MAC algorithm to values matching the second network security level.
[0285] In some possible embodiments, the first device obtains the second MAC algorithm by selecting a MAC algorithm matching the second network security level from a plurality of MAC algorithms according to the second network security level.
[0286] Exemplarily, the first length and the second length are different; the first network security level is higher than the second network security level, and the first length is greater than the second length; or, the first network security level is lower than the second network security level, and the first length is less than the second length.
[0287] Step 408: The second device performs MAC check on the second data packet using the second MAC policy.
[0288] Optionally, after step 408, the following steps are further included:
[0289] Step 410: If the error rate does not decrease after the MAC policy is changed, the second device generates a third MAC policy and sends the third MAC policy to the first device.
[0290] Exemplarily, the third MAC policy is to restore to the previous MAC policy.
[0291] In the technical solution of the data packet sending method provided by the embodiment of the present invention, the first device obtains a first MAC value according to a first MAC policy and first message data, packages the first message data and the first MAC value into a first data packet and sends it to the second device; the second device performs MAC verification on the first data packet through the first MAC policy, obtains a second MAC policy by counting the error rate of the MAC verification, and sends the second MAC policy to the first device; the first device obtains a second MAC value according to the second MAC policy and the second message data, packages the second message data and the second MAC value into a second data packet and sends it to the second device; the second device performs MAC verification on the second data packet through the second MAC policy, and can dynamically adjust the MAC policy, thereby reducing the network resources and computing power resources occupied by the MAC.
[0292] Fig.13 The first device 500 is a schematic diagram of a structure of a first device provided in an embodiment of the present invention. It should be understood that the first device 500 can execute each step of the first device in the above-mentioned data packet sending method. To avoid repetition, it is not described in detail here. The first device 500 includes: a first transceiver unit 501 and a first processing unit 502.
[0293] A first processing unit 502, configured to obtain a first MAC value according to a first MAC policy and first message data;
[0294] The first transceiver unit 501 is used to package the first message data and the first MAC value into a first data packet and send it to the second device; receive the second MAC policy sent by the second device;
[0295] The first processing unit 502 is further configured to obtain a second MAC value according to the second MAC policy and the second message data;
[0296] The first transceiver unit 501 is further configured to package the second message data and the second MAC value into a second data packet and send the second data packet to the second device.
[0297] Optionally, the first processing unit 502 is specifically used to obtain a first network security level according to the first MAC policy; according to the first network security level, obtain a first MAC algorithm that matches the first network security level; calculate the first message data and the shared key through the first MAC algorithm to obtain the first MAC value, and the length of the first MAC value is a first length.
[0298] Optionally, the first MAC policy is an initial MAC policy.
[0299] Optionally, the second MAC policy includes: raising a network security level or lowering a network security level.
[0300] Optionally, the first processing unit 502 is specifically used to obtain a second network security level based on the second MAC policy and the current network security level; obtain a second MAC algorithm matching the second network security level based on the second network security level; calculate the second message data and the shared key through the second MAC algorithm to obtain the second MAC value, and the length of the second MAC value is the second length.
[0301] Optionally, the first processing unit 502 is specifically configured to obtain the second MAC algorithm by adjusting a value of a parameter in the current MAC algorithm to a value matching the second network security level according to the second network security level.
[0302] Optionally, the first processing unit 502 is specifically configured to obtain the second MAC algorithm by selecting a MAC algorithm matching the second network security level from multiple MAC algorithms according to the second network security level.
[0303] Optionally, the first length and the second length are different; the first network security level is higher than the second network security level, and the first length is greater than the second length; or, the first network security level is lower than the second network security level, and the first length is less than the second length.
[0304] Fig.14The second device 600 is a schematic diagram of a structure of a second device provided in an embodiment of the present invention. It should be understood that the second device 600 can execute each step of the second device in the above-mentioned data packet sending method. To avoid repetition, it is not described in detail here. The second device 600 includes: a second transceiver unit 601 and a second processing unit 602.
[0305] The second transceiver unit 601 is used to receive a first data packet sent by a first device;
[0306] The second processing unit 602 is configured to perform MAC verification on the first data packet according to the first MAC policy; and obtain a second MAC policy by counting the error rate of the MAC verification;
[0307] The second transceiver unit 601 is further configured to send the second MAC policy to the first device; and receive a second data packet sent by the first device;
[0308] The second processing unit 602 is further configured to perform MAC check on the second data packet according to the second MAC policy.
[0309] Optionally, the second processing unit 602 is specifically configured to count the error rate of MAC verification; when the error rate does not fall within a preset interval, generate a second MAC policy.
[0310] Optionally, the second processing unit 602 is specifically configured to count the error rate of the MAC check according to a preset number of times of the MAC check.
[0311] Optionally, the second processing unit 602 is specifically configured to periodically count the error rate of the MAC check according to a preset time of the MAC check.
[0312] Optionally, if the error rate is greater than the maximum value of the preset interval, the second MAC policy is to increase the network security level; or, if the error rate is less than the minimum value of the preset interval, the second MAC policy is to decrease the network security level.
[0313] Optionally, the first data packet includes: first message data and a first MAC value;
[0314] The second processing unit 602 is specifically used to obtain a first network security level according to the first MAC policy; obtain a first MAC algorithm matching the first network security level according to the first network security level; calculate the first message data and the shared key through the first MAC algorithm to obtain a third MAC value; determine whether the first MAC value and the third MAC value are consistent; if it is determined that the first MAC value and the third MAC value are consistent, the result of this MAC verification is success; if it is determined that the first MAC value and the third MAC value are inconsistent, the result of this MAC verification is failure.
[0315] Optionally, the second processing unit 602 is further configured to generate a third MAC policy if the error rate does not decrease after the MAC policy is changed;
[0316] The second transceiver unit 601 is further configured to send the third MAC policy to the first device.
[0317] Optionally, the third MAC policy is to restore to a previous MAC policy.
[0318] It should be understood that the first device 500 and the second device 600 here are embodied in the form of functional units. The term "unit" here can be implemented in the form of software and / or hardware, and is not specifically limited to this. For example, a "unit" can be a software program, a hardware circuit, or a combination of the two that implements the above functions. The hardware circuit may include an application specific integrated circuit (ASIC), an electronic circuit, a processor (such as a shared processor, a proprietary processor, or a group processor, etc.) and a memory for executing one or more software or firmware programs, a merged logic circuit, and / or other suitable components that support the described functions.
[0319] Therefore, the units of each example described in the embodiments of the present invention can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0320] The embodiment of the present application provides a device, which may be a terminal device or a circuit device built into the terminal device. The device may be used to execute the functions / steps in the above method embodiment.
[0321] An embodiment of the present application provides a readable storage medium, in which instructions are stored. When the instructions are executed on a device, the device executes the functions / steps in the above method embodiment.
[0322] The embodiment of the present application also provides a program product including instructions, which, when executed on a device or at least one processor, enables the device to execute the functions / steps in the above method embodiment.
[0323] In the embodiments of the present application, "at least one" refers to one or more, and "plurality" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent the existence of A alone, the existence of A and B at the same time, and the existence of B alone. Among them, A and B can be singular or plural. The character " / " generally indicates that the previous and subsequent associated objects are in an "or" relationship. "At least one of the following" and similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b and c can be represented by: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.
[0324] Those of ordinary skill in the art will appreciate that the various units and algorithm steps described in the embodiments disclosed herein can be implemented in a combination of electronic hardware, computer software, and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0325] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0326] In several embodiments provided in the present application, any function can be stored in a computer-readable storage medium if it is implemented in the form of a software functional unit and sold or used as an independent product. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including several instructions for enabling a device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0327] The above is only a specific implementation of the present application. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. The protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A method for sending a data packet, characterized in that: Applied to a first device, the method includes: Obtain a first MAC value according to the first MAC policy and the first message data; Packing the first message data and the first MAC value into a first data packet and sending it to the second device; Receiving a second MAC policy sent by the second device; Obtain a second MAC value according to the second MAC policy and the second message data; The second message data and the second MAC value are packaged into a second data packet and sent to the second device.
2. The method according to claim 1, characterized in that: The first MAC policy is an initial MAC policy.
3. The method according to claim 2, characterized in that The initial MAC policy includes: one or more of a first network security level, a first MAC algorithm and a first length.
4. The method according to any one of claims 1 to 3, characterized in that The obtaining a first MAC value according to the first MAC policy and the first message data includes: Obtaining a first network security level according to the first MAC policy; According to the first network security level, obtaining a first MAC algorithm matching the first network security level; The first message data and the shared key are calculated using the first MAC algorithm to obtain the first MAC value, where the length of the first MAC value is a first length.
5. The method according to any one of claims 1 to 4, characterized in that The second MAC policy includes: one or more of a second network security level, a second MAC algorithm, and a second length; or The second MAC policy includes: raising a network security level or lowering a network security level.
6. The method according to claim 5, characterized in that The obtaining a second MAC value according to the second MAC policy and the second message data includes: Obtain a second network security level according to the second MAC policy and the current network security level; According to the second network security level, obtaining a second MAC algorithm matching the second network security level; The second message data and the shared key are calculated using the second MAC algorithm to obtain the second MAC value, where the length of the second MAC value is the second length.
7. The method according to claim 6, characterized in that Obtaining, according to the second network security level, a second MAC algorithm matching the second network security level, including: According to the second network security level, the second MAC algorithm is obtained by adjusting the values of the parameters in the current MAC algorithm to values matching the second network security level.
8. The method according to claim 6, characterized in that Obtaining, according to the second network security level, a second MAC algorithm matching the second network security level, including: According to the second network security level, the second MAC algorithm is obtained by selecting a MAC algorithm matching the second network security level from a plurality of MAC algorithms.
9. The method according to any one of claims 6 to 8, characterized in that: The first length and the second length are different; the first network security level is higher than the second network security level, and the first length is greater than the second length; or, the first network security level is lower than the second network security level, and the first length is less than the second length.
10. A method for sending a data packet, characterized in that: Applied to the second device, the method includes: Receive a first data packet sent by a first device, and perform MAC verification on the first data packet using a first MAC policy; Obtaining a second MAC policy by counting the error rate of MAC verification, and sending the second MAC policy to the first device; Receive a second data packet sent by the first device, and perform MAC check on the second data packet using the second MAC policy.
11. The method according to claim 10, characterized in that The obtaining of the second MAC strategy by counting the error rate of MAC verification includes: Statistics on MAC check error rate; When the error rate does not fall within a preset range, the second MAC policy is generated.
12. The method according to claim 11, characterized in that The counting of the error rate of the MAC check includes: counting the error rate of the MAC check according to a preset number of times of the MAC check.
13. The method according to claim 11, characterized in that The counting of the error rate of the MAC check includes: periodically counting the error rate of the MAC check according to a preset time of the MAC check.
14. The method according to any one of claims 11 to 13, characterized in that If the error rate is greater than the maximum value of the preset interval, the second MAC policy is to increase the network security level; or if the error rate is less than the minimum value of the preset interval, the second MAC policy is to decrease the network security level.
15. The method according to any one of claims 10 to 14, characterized in that The first data packet includes: first message data and a first MAC value; The performing MAC verification on the first data packet by using the first MAC policy includes: Obtaining a first network security level according to the first MAC policy; According to the first network security level, obtaining a first MAC algorithm matching the first network security level; Calculate the first message data and the shared key by using the first MAC algorithm to obtain a third MAC value; Determine whether the first MAC value and the third MAC value are consistent; If it is determined that the first MAC value and the third MAC value are consistent, the result of this MAC verification is successful; If it is determined that the first MAC value and the third MAC value are inconsistent, the result of this MAC check is failure.
16. The method according to any one of claims 10 to 15, characterized in that The method further comprises: If the error rate does not decrease after changing the MAC policy, generating a third MAC policy; The third MAC policy is sent to the first device.
17. The method according to claim 16, characterized in that The third MAC policy is to restore to the previous MAC policy.
18. A data packet sending system, characterized in that: The system comprises: The first device is configured to obtain a first MAC value according to a first MAC policy and first message data; and to package the first message data and the first MAC value into a first data packet and send the first data packet to the second device; The second device is configured to perform MAC verification on the first data packet by using the first MAC policy; obtain a second MAC policy by counting the error rate of the MAC verification, and send the second MAC policy to the first device; The first device is further configured to obtain a second MAC value according to the second MAC policy and the second message data; and to package the second message data and the second MAC value into a second data packet and send the second data packet to the second device; The second device is further configured to perform MAC check on the second data packet using the second MAC policy.
19. A device, characterized in that The device comprises a processor and a memory, wherein the memory is used to store a program, and the program comprises program instructions. When the processor runs the program instructions, the device executes the steps of the method as claimed in any one of claims 1 to 17.
20. A readable storage medium, characterized in that: The readable storage medium stores a program, wherein the program includes program instructions. When the program instructions are executed by a device, the device is enabled to perform the method according to any one of claims 1 to 17.