Data transmission method, electronic equipment and computer readable storage medium

By dynamically selecting the verification mode according to the link status to generate message verification code, the problem of difficult balance between security and bandwidth costs in the prior art is solved, and the effect of ensuring data transmission security while reducing bandwidth costs is achieved.

CN119945698APending Publication Date: 2025-05-06HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311467910.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-06
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing message verification code technology cannot achieve a dynamic balance between security and bandwidth costs in actual applications, resulting in poor results in security and bandwidth costs.

Method used

By dynamically selecting a suitable verification mode according to the actual link state to generate a message verification code, the link state between the first device and the second device is detected by using the link state to detect the handover condition, and instructing the second device to switch the verification mode, thereby achieving a dynamic trade-off of bandwidth cost and security.

Benefits of technology

While reducing bandwidth costs, it ensures the security of data transmission and improves the accuracy of verification mode switching, making the verification mode more in line with the actual link state.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945698A_ABST
    Figure CN119945698A_ABST
Patent Text Reader

Abstract

The invention provides a data transmission method, electronic equipment and a computer readable storage medium, and relates to the technical field of communication security. The message verification code is verified according to the first verification mode, after the verification result is obtained, whether the link state between the first device and the second device meets the switching condition or not can be detected according to the verification result, and when the link state meets the switching condition, the second device is indicated to be switched from the first verification mode to the second verification mode. Thus, according to the actual link state, the appropriate verification mode is dynamically selected to generate the message verification code, and the security of data transmission can be guaranteed while the bandwidth cost is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication security technology, and in particular to a data transmission method, an electronic device, and a computer-readable storage medium. Background Art

[0002] Message authentication code (MAC) technology is a common cryptographic technology used to ensure the authenticity and integrity of messages and is widely used in various communication protocols.

[0003] At present, there are many implementation schemes for message authentication code technology, such as long MAC independent authentication, short MAC group aggregation authentication, sliding window chain authentication, etc. Different implementation schemes have their own advantages and disadvantages in terms of security, bandwidth cost, verification real-time, and the degree of dependence on link status. However, in actual application, they cannot achieve good results, thus achieving a dynamic balance between security and bandwidth cost. Summary of the invention

[0004] The embodiments of the present application provide a data transmission method, an electronic device, and a computer-readable storage medium, which can dynamically select a suitable verification mode to generate a message verification code according to the actual link status, thereby reducing bandwidth costs while ensuring the security of data transmission.

[0005] In a first aspect, a data transmission method is provided, which is applied to a first device, and the method includes: obtaining a message verification code in a message from a second device; verifying the message verification code according to a first verification mode to obtain a verification result, wherein the message verification code is generated by the second device based on the first verification mode; according to the verification result, detecting whether the link status between the first device and the second device meets the switching condition; and issuing a mode switching instruction when the link status meets the switching condition, wherein the mode switching instruction is used to instruct the second device to switch from the first verification mode to the second verification mode.

[0006] Exemplarily, the first device can generate a message verification code according to the first verification mode. When the message verification code in the message is consistent with the message verification code generated by the first device, it indicates that the data carried by the message of the group is true and the verification result meets the requirements. When the message verification code in the message is inconsistent with the message verification code generated by the first device, it indicates that the data carried by the message of the group is incorrect and the verification result does not meet the requirements.

[0007] Exemplarily, detecting whether the link state between the first device and the second device meets the switching condition refers to whether the link state between the first device and the second device meets the switching condition of the first verification mode, wherein the switching condition of each verification mode may be different.

[0008] Exemplarily, the second verification mode can be determined according to an actual business scenario.

[0009] The scheme provided in the first aspect above can verify the message verification code according to the first verification mode and obtain the verification result. It can detect whether the link state between the first device and the second device meets the switching condition according to the verification result, and instruct the second device to switch from the first verification mode to the second verification mode when the link state meets the switching condition. In this way, according to the actual link state, the appropriate verification mode is dynamically selected to generate the message verification code, which can achieve a dynamic balance between bandwidth cost and security, and reduce bandwidth cost while ensuring the security of data transmission.

[0010] As a possible implementation, before obtaining the message verification code in the message from the second device, the method also includes: receiving a first verification parameter sent by a third device, the first verification parameter including a verification mode commonly supported by the first device and the second device, and the first verification mode is at least one of the verification modes commonly supported by the first device and the second device.

[0011] Exemplarily, the first verification parameter includes, but is not limited to, a shared key, mode-related information, a message length that the message verification code should reach, and a verification code length range that the first device and the second device can support.

[0012] The mode-related information includes the verification modes supported by the first device and the second device, the associated parameters corresponding to each verification mode, and the switching conditions of the verification modes. The associated parameters corresponding to each verification mode may include the number of related messages involved in generating a message verification code using the verification mode. The switching conditions of the verification mode refer to the conditions for switching the verification mode, which can be set according to business needs.

[0013] The message length that the message verification code should reach refers to the security strength that the message verification code should reach. By setting the security strength, the accuracy of verification can be improved and the security of data during transmission can be guaranteed.

[0014] Among them, the verification code length range that the first device and the second device can support refers to the variation range of the message length of the message verification code that can be supported by both ends. By setting the verification code length range that the first device and the second device can support, the first device and the second device can adjust the message length of the message verification code within the verification code length range, so that they can adapt to different verification modes and realize the switching of verification modes.

[0015] Exemplarily, the third device may be a device that receives business requirements and sends the first verification parameter to other devices according to the business requirements. By obtaining relevant information of the message verification code through the third device, the security of data transmission can be improved.

[0016] As a possible implementation, before obtaining the message verification code in the message from the second device, the method further includes: sending a first verification parameter to the second device, the first verification parameter including the verification mode supported by the first device; receiving a second verification parameter fed back by the second device based on the first verification parameter, the second verification parameter including the verification mode supported by the second device and the first device, and the first verification mode is at least one of the verification modes supported by the first device and the second device. In this way, through the interaction of the first verification parameter and the second verification parameter, the second device can select the first verification mode from the commonly supported verification modes to generate a message verification code, and the first device can select a switchable verification mode from the commonly supported verification modes.

[0017] Exemplarily, the first verification parameter also includes a verification code length range supported by the first device, associated parameters of a verification mode supported by the first device, and a message length that the message verification code should reach.

[0018] Exemplarily, the second verification parameter may also include a verification code length range supported by the second device. In this way, when the first device subsequently switches the verification mode, it can select the verification mode to be switched from the commonly supported verification modes, and can set the message length of the message verification code corresponding to the verification mode to be switched according to the verification code length range supported by the second device, so as to facilitate the second device to generate the message verification code.

[0019] Among them, obtaining relevant information of the message verification code through direct interaction between the first device and the second device can simplify the data transmission process and improve efficiency.

[0020] As a possible implementation, the message includes pattern data, and the pattern data is used to indicate a first verification pattern for generating a message verification code; verifying the message verification code according to the first verification pattern includes: verifying the message verification code according to the first verification pattern indicated by the pattern data in the message.

[0021] Exemplarily, the mode data includes an identifier of a verification mode, and the identifier can indicate a verification mode for generating a message verification code carried in the current message.

[0022] Exemplarily, the mode data may also include the message length of the generated message authentication code and associated parameters corresponding to the first authentication mode.

[0023] In this way, by carrying the mode data of the first verification mode in the message, when the first device receives the message, it can quickly adopt an accurate verification mode according to the mode data to verify the message verification code in the message.

[0024] As a possible implementation, issuing a mode switching instruction when the link state meets the switching condition includes: sending a mode switching instruction to the second device when the link state meets the switching condition. In this way, by directly sending the mode switching instruction to the second device, the second device can quickly respond to the mode switching instruction and switch the verification mode, which can improve processing efficiency.

[0025] As a possible implementation, issuing a mode switching instruction when the link state meets the switching condition includes: sending the mode switching instruction to the second device through the fourth device when the link state meets the switching condition. In this way, the security of data transmission can be improved by forwarding the mode switching instruction through the fourth device.

[0026] As a possible implementation, the mode switching instruction includes an identifier of the second verification mode. Thus, by setting the identifier of the second verification mode in the mode switching instruction, after receiving the mode switching instruction, the second device can quickly switch the first verification mode to the second verification mode according to the identifier in the mode switching instruction.

[0027] As a possible implementation method, according to the verification result, detecting whether the link state between the first device and the second device meets the switching condition includes: obtaining the number of first messages whose verification results meet the standard, and the number of second messages whose verification results do not meet the standard; according to the number of first messages and the number of second messages, detecting whether the link state between the first device and the second device meets the switching condition. When the link state between the first device and the second device is good, the number of messages that meet the verification standard of the first device will increase, and when the link state between the first device and the second device is poor, the number of messages that meet the verification standard of the first device will decrease. Therefore, the link state between the first device and the second device can be reflected by the number of first messages and the number of second messages, so as to obtain whether the link state meets the switching condition.

[0028] As a possible implementation, the message also includes a first message length of a message verification code corresponding to the first verification mode, and detects whether the link status between the first device and the second device meets the switching condition based on the first message quantity and the second message quantity, including: detecting whether the link status between the first device and the second device meets the switching condition based on the first message quantity, the second message quantity, the first message length and the second message length of the message verification code corresponding to the second verification mode.

[0029] For example, the length difference between the first message length and the second message length may be determined first, and then the bandwidth saving cost may be obtained according to the product of the length difference and the first message quantity, and the link loss may be obtained according to the product of the total message length of each message and the second quantity, and the link state between the first device and the second device may be detected to see whether it meets the switching condition according to the comparison result of the bandwidth saving cost and the link loss. In this way, according to the comparison result of the link loss and the bandwidth saving cost, it may be detected whether the link state between the first device and the second device meets the switching condition. On the one hand, a dynamic balance may be achieved between bandwidth cost and security, and the security of data transmission may be ensured while reducing bandwidth cost. On the other hand, the accuracy of the switching of the verification mode may be improved, so that the verification mode may be more in line with the actual link state between the first device and the second device.

[0030] In a second aspect, a data transmission method is provided, which is applied to a second device, and the method includes: generating a message verification code according to a first verification mode; encapsulating the message verification code and the data to be transmitted to obtain a message to be transmitted; sending a message to the first device, responding to a mode switching instruction of the first device, and switching the first verification mode to a second verification mode, wherein the mode switching instruction is issued by the first device when the link status between the first device and the second device determined by the message meets the switching conditions.

[0031] In the solution provided in the second aspect above, after the first device verifies the message verification code according to the first verification mode and obtains the verification result, it can detect whether the link state between the first device and the second device meets the switching condition based on the verification result, and instruct the second device to switch from the first verification mode to the second verification mode when the link state meets the switching condition. In this way, according to the actual link state, the appropriate verification mode is dynamically selected to generate the message verification code, which can achieve a dynamic balance between bandwidth cost and security, and reduce bandwidth cost while ensuring the security of data transmission.

[0032] As a possible implementation method, encapsulating the message verification code and the data to be transmitted to obtain the message to be transmitted includes: encapsulating the message verification code, the mode data of the first verification mode, and the data to be transmitted to obtain the message to be transmitted. In this way, by carrying the mode data of the first verification mode in the message, when the first device receives the message, it can quickly use an accurate verification mode according to the mode data to verify the message verification code in the message.

[0033] As a possible implementation, responding to the mode switching instruction of the first device, switching from the first verification mode to the second verification mode includes: after receiving the mode switching instruction sent by the first device through the fourth device, switching from the first verification mode to the second verification mode. In this way, the security of data transmission can be improved by forwarding the mode switching instruction through the fourth device.

[0034] As a possible implementation, responding to the mode switching instruction of the first device and switching from the first verification mode to the second verification mode includes: after receiving the mode switching instruction sent by the first device, switching from the first verification mode to the second verification mode. In this way, by directly sending the mode switching instruction to the second device, the second device can quickly respond to the mode switching instruction and switch the verification mode, which can improve processing efficiency.

[0035] As a possible implementation, before generating a message authentication code according to the first authentication mode, the method further includes: receiving a first authentication parameter sent by the first device, the first authentication parameter including an authentication mode supported by the first device; sending a second authentication parameter to the first device, the second authentication parameter including an authentication mode supported by the second device and the first device, the first authentication mode being at least one of the authentication modes supported by the first device and the second device. In this way, by directly interacting with the first device and the second device to obtain relevant information of the message authentication code, the data transmission process can be simplified and efficiency can be improved.

[0036] As a possible implementation, before generating a message authentication code according to the first authentication mode, the method further includes: receiving a first authentication parameter sent by a third device, the first authentication parameter at least including an authentication mode commonly supported by the first device and the second device, and the first authentication mode is at least one of the authentication modes commonly supported by the first device and the second device. In this way, by obtaining relevant information of the message authentication code through the third device, the security of data transmission can be improved.

[0037] In a third aspect, a data transmission device is provided, which is applied to a first device, and the data transmission device includes: a message extraction module, which is used to obtain a message verification code in a message from a second device; a verification module, which is used to verify the message verification code according to a first verification mode to obtain a verification result, and the message verification code is generated by the second device based on the first verification mode; a link status detection module, which is used to detect whether the link status between the first device and the second device meets the switching condition according to the verification result; a switching indication module, which is used to issue a mode switching instruction when the link status meets the switching condition, and the mode switching instruction is used to instruct the second device to switch from the first verification mode to the second verification mode.

[0038] Among them, the beneficial effects of the data transmission device provided in the third aspect can be referred to the description of any implementation in the first aspect, and will not be repeated here. The data transmission device has the function of implementing the behavior in the method example of any implementation in the first aspect above. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.

[0039] In a fourth aspect, a data transmission device is provided, which is applied to a second device, and the data transmission device includes: a verification code generation module, which is used to generate a message verification code according to a first verification mode; an encapsulation module, which is used to encapsulate the message verification code and the data to be transmitted to obtain a message to be transmitted; a message sending module, which is used to send a message to the first device; a mode switching module, which is used to respond to a mode switching instruction issued by the first device, and switch from the first verification mode to the second verification mode, wherein the mode switching instruction is issued by the first device when the link status between the first device and the second device determined by the message meets the switching conditions.

[0040] Among them, the beneficial effects of the data transmission device provided in the fourth aspect can be referred to the description of any implementation in the second aspect, and will not be repeated here. The data transmission device has the function of implementing the behavior in the method example of any implementation in the second aspect above. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.

[0041] In a fifth aspect, an electronic device is provided, comprising: a transceiver for sending and receiving messages; a memory for storing computer program instructions; and a processor for executing computer program instructions to support the electronic device to implement a method as any possible implementation method in the first aspect or to implement a method as any possible implementation method in the second aspect.

[0042] Exemplarily, when the electronic device is a first device, the method described in any possible implementation manner in the first aspect is implemented; when the electronic device is a second device, the method described in any possible implementation manner in the second aspect is implemented.

[0043] In a sixth aspect, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processing circuit, a method as in any possible implementation of the first aspect or a method as in any possible implementation of the second aspect is implemented.

[0044] In the seventh aspect, a chip system is provided, which includes a processing circuit and a storage medium, in which computer program instructions are stored; when the computer program instructions are executed by the processing circuit, a method as in any possible implementation method in the first aspect or a method as in any possible implementation method in the second aspect is implemented.

[0045] In an eighth aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the computer to execute a method as any possible implementation method in the first aspect or implement a method as any possible implementation method in the second aspect.

[0046] In a ninth aspect, a first device is provided, comprising a method for executing any possible implementation manner as described in the first aspect.

[0047] In a tenth aspect, a second device is provided, comprising a method for executing any possible implementation method of the second aspect.

[0048] In an eleventh aspect, a communication system is provided, comprising a first device and a second device, wherein the first device is used to implement a method as described in any possible implementation manner of the first aspect, and the second device is used to implement a method as described in any possible implementation manner of the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 A technical schematic diagram of a message verification code provided in an embodiment of the present application;

[0050] Figure 2 A schematic diagram of a principle of a long MAC independent verification solution provided in an embodiment of the present application;

[0051] Figure 3 A schematic diagram of a principle of a short MAC independent verification scheme according to an embodiment of the present application;

[0052] Figure 4 A schematic diagram of a principle of a short MAC packet aggregation verification solution provided in an embodiment of the present application;

[0053] Figure 5 A schematic diagram of the principle of a sliding window chain verification solution provided in an embodiment of the present application;

[0054] Figure 6 A schematic diagram of the structure of a communication system provided in an embodiment of the present application;

[0055] Figure 7 A schematic diagram of the structure of a receiving device provided in an embodiment of the present application;

[0056] Figure 8 A schematic diagram of information interaction between a source device and a receiving device provided in an embodiment of the present application;

[0057] Fig. 9 A schematic diagram of the sending process of a source device provided in an embodiment of the present application;

[0058] Fig.10A schematic diagram of a receiving process of a receiving device provided in an embodiment of the present application;

[0059] Fig.11 One of the flowcharts of the data transmission method provided in the embodiment of the present application;

[0060] Fig.12 One of the interactive timing diagrams of the data transmission method provided in the embodiment of the present application;

[0061] Fig.13 One of the message format diagrams provided in the embodiment of the present application;

[0062] Fig.14 The second schematic diagram of the message format provided in the embodiment of the present application;

[0063] Fig.15 A second flowchart of a data transmission method provided in an embodiment of the present application;

[0064] Fig.16 A schematic diagram of the architecture of an application scenario of the data transmission method provided in an embodiment of the present application;

[0065] Fig.17 The third flowchart of the data transmission method provided in the embodiment of the present application;

[0066] Fig.18 This is the second interactive sequence diagram of the data transmission method provided in an embodiment of the present application. DETAILED DESCRIPTION

[0067] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0068] The terms "including" and "having" and any variations thereof mentioned in the description of the embodiments of the present application are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but may optionally include other steps or units that are not listed, or may optionally include other steps or units that are inherent to these processes, methods, products or devices.

[0069] In the following, the terms "first", "second", etc. are used for descriptive purposes only and are not to be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first", "second", etc. may explicitly or implicitly include one or more of the features.

[0070] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.

[0071] In the description of the embodiments of the present application, unless otherwise specified, the meaning of "multiple" refers to two or more. The "and / or" in this article is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.

[0072] Message authentication code (MAC) technology is a common cryptographic technology used to ensure the authenticity and integrity of messages and is widely used in various communication protocols.

[0073] To facilitate understanding, the technical principles and implementation solutions of message verification codes are explained below.

[0074] See also Figure 1 When generating a message verification code, the two communicating parties, i.e. the sender and the receiver, need to share the key in advance. When sending a message m, the sender calculates and generates the verification code tag based on the shared key and the message m to be sent. The verification code tag is carried with the message, i.e. the message includes the message m to be sent and the verification code tag. The receiver is responsible for receiving the message. When the receiver receives the message and obtains the message m', it calculates and generates the verification code tag' based on the shared key and the message m', and compares the verification code tag' generated locally with the tag carried in the message. If the verification code tag' generated locally is consistent with the tag carried in the message, it means that the received message m' is consistent with the message m sent by the sender.

[0075] The security strength of the message verification code is strongly related to its length, which is an exponential relationship. The longer the length of the message verification code, the more difficult it is for an attacker to crack it, and the more difficult it is to forge a message. Therefore, for the message verification code, it is usually recommended to use a length of 128 bits or more to ensure the authenticity of the message and improve the security of data transmission. However, there are many scenarios that require the use of shorter message verification codes. For example, for scenarios with low power consumption requirements, such as the Internet of Things (IoT) scenario with limited capabilities, the power consumption and bandwidth capabilities of the device itself limit the amount of data transmission, so the length of the message verification code should be as short as possible. For another example, for short message scenarios, such as CAN bus messages and control command messages in IoT scenarios, the length of these messages is relatively short, usually less than 10 bytes, while the length of the message verification code can be as long as 16 bytes. If a longer message verification code is added to the message, the security field will account for too large a proportion and the bandwidth utilization efficiency will be low. Therefore, for short message scenarios, a shorter message verification code is required.

[0076] At present, there are many implementation schemes for message authentication code technology, including, but not limited to, long MAC independent authentication scheme, short MAC independent authentication scheme, short MAC group aggregation authentication scheme and sliding window chain authentication scheme, among which the sliding window chain authentication scheme can also be called short MAC forward chain authentication scheme.

[0077] Please refer to Figure 2 When using the long MAC independent authentication scheme, for each message, a verification code (Tag) is calculated by the MAC algorithm according to the payload it carries, that is, the message to be sent, and the shared key. Therefore, each message has its own verification code (Tag). It can be understood that the process of generating the verification code by calculating the MAC algorithm can refer to the explanation of conventional technology, which will not be repeated here.

[0078] The long MAC independent verification scheme is the most basic way to use the message authentication code. The length of the verification code calculated by it is usually greater than 128 bits. The long MAC independent verification scheme has the advantages of high security, no reliance on other messages, and instant verification. However, due to the long length of the verification code calculated by it, it also has the problem of high bandwidth cost.

[0079] like Figure 3As shown, when using the short MAC independent verification scheme, for each message, a longer verification code, i.e., a long Tag, is calculated by the MAC algorithm according to the payload it carries and the shared key, and then the calculated verification code Tag is intercepted according to the set rules to obtain a shorter verification code, i.e., a short Tag. The set rules can be set according to business needs and are not specifically limited. For example, the first N numbers can be intercepted in order from the beginning to the end, where N is a positive integer; for another example, the numbers from the Kth to the K+Lth positions can be intercepted, where K and L are positive integers.

[0080] Like the long MAC independent verification scheme, for the short MAC independent verification scheme, each message has its own verification code, but for the short MAC independent verification scheme, the length of the verification code calculated for each message is usually 32 bits. For the short MAC independent verification scheme, it has the advantages of low bandwidth cost, no dependence on other messages, and instant verification, but because the verification code calculated by it is short, it also has the problem of poor security.

[0081] When using short MAC group aggregation authentication, the messages can be grouped, each group includes multiple messages, and for each group, the loads carried by the multiple messages included in the group can be aggregated. Based on the shared key, a long tag is calculated through the MAC algorithm, and then the long tag is divided into multiple short tags and distributed to the multiple messages included in the group, and the multiple messages carry the long tag together. Figure 4 As shown, the packet is set to include message 1, message 2, message 3 and message 4, message 1 carries payload 1 (payload1), message 2 carries payload 2 (payload2), message 3 carries payload 3 (payload3), and message 4 carries payload 4 (payload4). Then payload 1, payload 2, payload 3 and payload 4 can be aggregated and jointly calculated to obtain a long tag, and then the long tag is divided into Tag 1, Tag 2, Tag 3 and Tag 4, wherein Tag 1 is carried by message 1, Tag 2 is carried by message 2, Tag 3 is carried by message 3, and Tag 4 is carried by message 4. When using short MAC packet aggregation verification, after receiving all the messages of the packet, the receiving end assembles the short tags of all the messages of the packet into a long tag, aggregates the payloads carried by all the messages of the packet, and locally calculates a long tag through the MAC algorithm based on the shared key, and then compares the assembled long tag with the locally calculated long tag for verification.

[0082] For short MAC packet aggregation verification, it has the advantages of low bandwidth cost and high security cost. However, since the verification code is calculated by all messages in the group, the messages in the same group are dependent on each other and cannot be verified instantly. It also depends on the link status.

[0083] When using the sliding window chain verification scheme, the generation of the verification code of each message requires the information of the previous message as input. If the previous message is forged, the verification code authentication of the associated subsequent message will also fail. For the previous message, the verification of the subsequent message can enhance security. Figure 5 As shown, for the first message, since the message has no preceding message, the verification code Tag1 of the first message is calculated based on its own payload1, that is, Tag1 = Gen k (p 1 ), p 1 is the payload of the first message; for the verification code Tag2 of the second message, it can be calculated based on the payload of the first message and its own payload2, that is, Tag2 = Gen k (p 2 ,h(p 1 )), h(p 1 ) indicates the load of the first input message, p 2 is the payload of the second message; for the verification code Tag3 of the third message, it can be calculated based on the payload of the first message, the payload of the second message and its own payload3, that is, Tag3 = Gen k (p 3 ,h(p 2 ),h(p 1 )), h(p 2 ) indicates the load of the second message input, p 3 is the payload of the third message; for the verification code Tag4 of the fourth message, it can be calculated based on the payload of the first message, the payload of the second message, the payload of the third message and its own payload4, that is, Tag4 = Gen k (p 4 ,h(p 3 ),h(p 2 ),h(p 1 )), h(p 3 ) represents the load of the third message input, p 4 This is the payload of the fourth message.

[0084] Among them, for the sliding window chain scheme, an associated window W is usually set, and the value of W determines the number of previous messages associated when calculating the verification code for each message in the sliding window chain scheme. For example, when W=2, for each message, when calculating the verification code for the message, it is necessary to associate the load of the previous message of the message, and calculate the verification code based on the load of the previous message and its own load; when W=3, for each message, when calculating the verification code for the message, it is necessary to associate the load of the previous two messages of the message, and calculate the verification code based on the load of the previous two messages and its own load. It can be understood that the value of W can be set according to actual business needs.

[0085] In the sliding window chain verification, the dependency between tag calculation and verification is unidirectional. For the receiving end, if the message arrives in order, the received message can be verified immediately without waiting for the subsequent message, because it only depends on the previous message, but requires the link status to be good and the packet loss disorder is not serious. That is, for the sliding window chain verification scheme, it has the advantages of security accumulation enhancement and low bandwidth cost, but because it depends on the information of the previous message, it has high requirements for the link status.

[0086] For both short MAC packet aggregation verification and sliding window chain verification, there is mutual dependence of message verification. If the link status is poor, that is, there are many packet losses and disorder, the verification efficiency of the receiving end will be significantly reduced, or even verification will be impossible.

[0087] The above solutions have their own advantages and disadvantages in terms of security, bandwidth cost, verification real-time, and dependence on link status. However, in actual application, they cannot achieve good results and achieve a dynamic balance between security and bandwidth cost.

[0088] Based on the above research, the embodiment of the present application provides a data transmission method, which verifies the message verification code according to the first verification mode, and after obtaining the verification result, can detect whether the link state between the first device and the second device meets the switching condition according to the verification result, and instruct the second device to switch from the first verification mode to the second verification mode when the link state meets the switching condition. In this way, according to the actual link state, the appropriate verification mode is dynamically selected to generate the message verification code, which can reduce the bandwidth cost while ensuring the security of data transmission.

[0089] See also Figure 6 , Figure 6 A schematic diagram of the architecture of a communication system applicable to the data transmission method provided in the embodiment of the present application. Figure 6As shown, the communication system may include a source device 110 and a receiving device 120, wherein a communication connection may be established between the source device 110 and the receiving device 120 via a network, and data may be transmitted between the source device 110 and the receiving device 120 that have established a communication connection.

[0090] In the embodiment of the present application, the source device 110 may be a device having data processing and data transceiving functions or a chip or chip system that can be set in the device. Correspondingly, the receiving device 120 may be a device having data processing and data transceiving functions or a chip or chip system that can be set in the device.

[0091] In the embodiment of the present application, the source device 110 mainly refers to a device that sends data, which may be a signaling server, a server for interacting with business information (such as a media server), etc. Exemplarily, the signaling server may include an account management server, which can be used to perform registration, information maintenance, and information query functions of the call device; in addition, the signaling server may also include a signaling forwarding server, which is responsible for the transmission of call signaling such as calls, answers, and rejections between devices. The media server can be used to establish a route between the media server and the end-side device, and is responsible for forwarding audio, video, and media control data between call devices. Under the framework of the RTP or RTCP protocol, the media server is responsible for forwarding RTP or RTCP messages. In some embodiments, the source device 110 may also be a storage device, a terminal, etc. Among them, the terminal can be a mobile phone, a tablet computer, a computer with wireless transceiver function, a personal communication service (PCS) phone, a desktop computer, a personal digital assistant (PDA), a wearable device, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc.

[0092] In the embodiment of the present application, the receiving device 120 mainly refers to a device for receiving data, and the receiving device 120 may also be a signaling server, a server for exchanging service information (such as a media server), etc. In some embodiments, the receiving device 120 may also be a terminal. In some embodiments, the receiving device 120 may also be a real-time audio and video transmission network (RTN) access node, etc.

[0093] It is worth noting that the above-mentioned source device 110 and receiving device 120 are merely examples provided in the embodiments of the present application and should not be understood as limitations on the present application. The present application does not limit the specific form and quantity of the source device 110 and the receiving device 120 in the communication system.

[0094] It is understandable that in some scenarios, the source device 110 may also serve as the receiving device 120 to receive data, and the receiving device 120 may also serve as the source device 110 to send data.

[0095] For ease of understanding, the following takes the receiving device 120 as an example to introduce the specific structure of the receiving device 120. Figure 7 As shown, the receiving device 120 may include a processor 121, a memory 122, and a communication interface 123. The communication interface 123 is used to communicate with other devices. For example, information exchange may be performed with the source device 110 through the communication interface 123.

[0096] The processor 121 may be a central processing unit (CPU) or other specific integrated circuits. The processor 121 may also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. In practical applications, the receiving device 120 may also include multiple processors 121, and the processor 121 may include one or more processor cores.

[0097] The processor 121 is connected to the memory 122 via a double data rate (DDR) bus or other types of buses. The memory 122 is generally used to store executable program codes of computer programs. The executable program codes include instructions, and the processor 121 executes various functional applications and data processing of the receiving device by running the instructions stored in the memory 122. The memory 122 may include a program storage area and a data storage area. The program storage area may store an operating system, an application required for at least one function, etc., and the data storage area may store data created during the use of the source device, etc.

[0098] In addition, the memory 122 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc. The processor 121 executes various functional applications and data processing of the receiving device by running instructions stored in the memory 122.

[0099] In the embodiment of the present application, the memory 122 also includes a cache memory (Cache) for storing instructions or data just used or cyclically used by the processor 121. If the processor 121 needs to use the instruction or data again, it can be directly called from the cache memory, avoiding repeated access, reducing the waiting time of the processor 121, and thus improving the query efficiency.

[0100] It should be noted that the source device 110 may also have corresponding components, such as a processor, a memory, and a communication interface, which will not be described in detail here.

[0101] It is understandable that this application Figure 7 The structure shown does not constitute a specific limitation on the source device 110 and the receiving device 120. In other embodiments of the present application, the source device 110 and the receiving device 120 may include more or fewer components than shown in the figure, or combine some components, or split some components, or arrange the components differently, and the components may be implemented in hardware, software, or a combination of software and hardware.

[0102] In order to improve the security of information transmission between the source device 110 and the receiving device 120, in the embodiment of the present application, when the source device 110 sends data to the receiving device 120, it usually adds a message verification code to the sent data to ensure the authenticity of the data and improve the security of data transmission. At the same time, in order to achieve a dynamic balance between security and bandwidth cost, the embodiment of the present application can dynamically select a suitable verification mode to generate a message verification code according to the actual link status between the source device 110 and the receiving device 120, thereby reducing the bandwidth cost and ensuring the security of data transmission.

[0103] like Figure 8 As shown, the interaction between the source device 110 and the receiving device 120 can be divided into an initialization phase and a data transmission phase. In the initialization phase, the source device 110 and the receiving device 120 can negotiate the relevant information of the message authentication code, and the relevant information includes a shared key, a verification mode for generating and verifying the message authentication code, and associated parameters of the verification mode, wherein the associated parameters of the verification mode include the number of related messages involved in the verification mode. The source device 110 can generate a message authentication code according to the shared key, the verification mode, and the associated parameters of the verification mode negotiated in the initialization phase, and the receiving device 120 can verify the message authentication code according to the shared key, the verification mode, and the associated parameters of the verification mode negotiated in the initialization phase.

[0104] During the data transmission phase, the source device 110 may send the message verification code and the data packet to be transmitted to the receiving device 120. In order to facilitate the receiving device 120 to verify the message verification code, the source device 110 may also send the mode data of the verification mode, the message verification code and the data to be transmitted to the receiving device 120 in a package, wherein the mode data of the verification mode includes the message length of the message verification code generated by the verification mode, the associated parameters of the verification mode and the identification of the verification mode, etc. In this way, after receiving the message, the receiving device 120 can quickly and conveniently verify the message according to the mode data in the message.

[0105] The following uses the sliding window chain verification mode as an example to explain the respective processes of the source device 110 and the receiving device 120. Fig. 9 , Fig. 9 The sending process of the source device 110 is as follows: Fig. 9As shown, the source device 110 obtains the shared key, the verification mode for currently generating the message verification code, and the corresponding associated parameters, etc. When the obtained verification mode is the sliding window chain verification mode, it is necessary to update the cache state of the message, and obtain the data in the associated message from the updated cache based on the associated parameters, and then generate the message verification code using the sliding window chain verification mode according to the shared key, the data to be transmitted, and the data in the associated message. After the message verification code is generated, the message verification code, the data to be transmitted, and the mode data can be encapsulated to obtain the message to be transmitted, and the message is sent to the receiving device 120.

[0106] Among them, in the sliding window chain verification mode, since the data of the associated previous message is required to generate the message verification code, the data of the associated previous message needs to be cached, and after the current message is sent to the receiving device 120, in order to improve the utilization rate of the cache space, the cached data can be released to update the cache state of the message. For example, for the generation of the message verification code of the current message, it is necessary to associate the data of the two previous messages, so when the message verification code of the current message is generated, the source device 110 caches the data of the two previous messages, and after the current message is sent to the receiving device 120, the source device 110 can release the data of the message with the previous sending order in the two previous messages, and cache the data of the current message at the same time.

[0107] Please refer to Fig.10 , Fig.10 The receiving process of the receiving device 120 is as follows: Fig.10 As shown, after receiving the message, the receiving device 120 extracts the message verification code and mode data in the message, obtains the currently adopted verification mode as the sliding window chain verification mode according to the identifier in the mode data, and then updates the cache state of the message, and obtains the data in the associated message from the updated cache based on the associated parameters in the mode data, and then generates the message verification code using the sliding window chain verification mode according to the shared key, the data in the currently received message, and the data in the associated message, and compares the locally generated message verification code with the message verification code in the currently received message, so as to verify the message verification code in the currently received message, if the verification fails, the message can be discarded, if the verification passes, the message can continue to be processed. And the receiving device 120 can detect whether the link state between the source device 110 and the receiving device 120 needs to adjust the verification mode according to the verification result, and if the verification mode needs to be adjusted, the mode switching is initiated to the source device 110 to instruct the source device 110 to switch the verification mode.

[0108] The process of updating the cache status of the message by the receiving device 120 may refer to the process of updating the cache status of the message by the source device 110, which will not be described in detail here.

[0109] The embodiment of the present application can adaptively adjust the message authentication code authentication method according to the actual link status of the source device 110 and the receiving device 120 to achieve a trade-off between bandwidth cost and security.

[0110] For ease of understanding, the data transmission method provided in the embodiment of the present application is described in detail with the source device 110 as the second device and the receiving device 120 as the first device. Fig.11 and Fig.12 , Fig.11 A schematic diagram of a data transmission method provided in an embodiment of the present application. Fig.12 An interactive timing diagram of a data transmission method is provided for an embodiment of the present application, such as Fig.11 and Fig.12 As shown, the data transmission method provided in the embodiment of the present application may include steps S201 to S209.

[0111] S201: The first device and the second device receive a first verification parameter sent by a third device.

[0112] The first verification parameter may include, but is not limited to, a shared key K, mode-related information, a message length that a message verification code should reach, and a verification code length range that the first device and the second device can support.

[0113] Among them, the shared key K refers to the key participating in the MAC algorithm. The first device can generate a message authentication code using the MAC algorithm based on the shared key K. Correspondingly, the second device can generate a message authentication code using the MAC algorithm based on the shared key K. The second device can compare the locally generated message authentication code with the message authentication code transmitted by the first device to verify the authenticity of the data transmission.

[0114] In an embodiment of the present application, mode-related information refers to a security policy that can be adopted by a device, and may include a verification mode for generating a message verification code that can be adopted by the first device and the second device, that is, a verification mode supported by the first device and the second device, associated parameters corresponding to each verification mode, and switching conditions for each verification mode, etc.

[0115] Among them, the verification modes that can be adopted by the first device and the second device can be, but not limited to, long MAC independent verification mode, short MAC group aggregation verification mode, sliding window chain verification mode, etc. As an example, in order to facilitate the first device and the second device to identify and switch the verification mode, the verification mode can be indicated by an identifier, that is, the first verification parameter can include the identifier of the verification mode that can be adopted by the first device and the second device, and the first device and the second device can identify the verification mode through the identifier. Among them, the identifier can be represented by characters such as numbers, letters, and symbols. It can be understood that different verification modes have different corresponding identifiers.

[0116] The associated parameters corresponding to each verification mode may include the number of related messages involved when using the verification mode to generate a message verification code, for example, the number of preceding messages involved when using a sliding window chain verification mode, or the number of messages in the same group involved when using a short MAC packet aggregation verification mode.

[0117] Among them, the switching condition of the verification mode refers to the condition for switching the verification mode. For any verification mode, when the first device and the second device are adopting the verification mode, if the link status between the first device and the second device meets the switching condition of the verification mode, then the verification mode can be switched to other verification modes, and the message verification code can be generated and verified based on the switched verification mode.

[0118] In the embodiment of the present application, the message length that the message verification code should reach refers to the security strength that the message verification code should reach. When the message length is longer, the security strength is higher. The message length that the message verification code should reach can be set according to business requirements, such as 96 bits, 128 bits, etc. By setting the security strength, the accuracy of verification can be improved and the security of data during transmission can be guaranteed.

[0119] Exemplarily, taking the long MAC independent verification mode as an example, for the long MAC independent verification mode, a message verification code with a message length not less than the security strength can be generated, and when performing verification, the message length of the verified message verification code is also not less than the security strength. For example, if the security strength is set to 96 bits, when the second device generates a message verification code using the long MAC independent verification mode, a message verification code with a message length not less than 96 bits can be generated. In this way, when performing verification, the message verification code that needs to be verified can achieve the required security strength.

[0120] Exemplarily, the short MAC packet aggregation verification mode is used as an example for explanation. For the short MAC packet aggregation verification mode, since the data carried by all messages in the group are aggregated to jointly generate a message verification code, and then the generated message verification code is allocated to the messages in the group, and during verification, the message verification codes carried by all messages in the group are also spliced ​​and verified. Therefore, for the short MAC packet aggregation verification mode, the message length of the aggregated message verification code can be made not less than the security strength. In this way, when performing verification, the required security strength can be achieved for the message verification code that needs to be verified. For example, if the security strength is 96 bits, then for each group, after the second device aggregates the data carried by all messages in the group, the message length of the generated message verification code should be not less than 96 bits.

[0121] Exemplarily, the sliding window chain verification mode is used as an example for explanation. For the sliding window chain verification mode, since it is associated with the previous message, for the sliding window chain verification mode, the sum of the message lengths of the message verification codes carried by the associated messages can be made not less than the security strength, which can meet the required security strength. For example, if the security strength is 96 bits and the association parameter is 3, the sum of the message lengths of the message verification codes carried by the three messages associated before and after can be made not less than 96 bits. In this way, through the association verification of the three messages before and after, the security strength of each of the three messages before and after can be made equivalent to the security strength of the message carrying the message verification code with a message length of 96 bits.

[0122] It should be noted that in order to facilitate the verification and generation of message verification codes, in the sliding window chain verification mode, the message lengths of the message verification codes carried by the associated messages can be equal, and the sum of the message lengths of the message verification codes carried by the associated messages is not less than the security strength.

[0123] In the embodiment of the present application, the verification code length range that the first device and the second device can support refers to the range of changes in the message length of the message verification code that can be supported by both ends, such as (32bit, 64bit, 96bit, 128bit). By setting the verification code length range that the first device and the second device can support, the first device and the second device can adjust the message length of the message verification code within the verification code length range, so that they can adapt to different verification modes and realize the switching of verification modes.

[0124] As an example, for the convenience of calculation, when the verification mode jointly supported by the first device and the second device includes a sliding window chained verification mode, the first verification parameter may also include an initial state S0, where the initial state S0 refers to a random number involved in generating a message verification code or verifying a message verification code in the sliding window chained verification mode, wherein the initial state S0 can be used to carry the status information of the preceding associated message in the window, and the status information may include a message verification code value calculated based on the load of the preceding associated message and / or the load of the preceding associated message.

[0125] It can be understood that the initial state S0 can be updated according to the calculation results of the messages in the window. Exemplarily, taking W=3 as an example, when a message verification code is generated for the first message, since there is no preceding message for the first message, the preceding message can be replaced by the initial state S0, and the message verification code of the first message is generated based on the initial state S0 and the load of the first message. After the message verification code of the first message is generated, the initial state S0 can be updated to the initial state S1, and the initial state S1 carries the state information of the first message. When a message verification code is generated for the second message, the message verification code of the second message can be generated according to the initial state S1 and the load of the second message. After the message verification code of the second message is generated, the initial state S1 can be updated to the initial state S2, and the initial state S2 carries the state information of the first message and the second message. When a message verification code is generated for the third message, the message verification code of the third message can be generated according to the initial state S2 and the load of the third message. After the message verification code of the third message is generated, the initial state S2 can be updated to the initial state S3, and the initial state S3 carries the state information of the second message and the third message, and so on.

[0126] It can be understood that by setting the initial state S0, the convenience of calculating the message verification code can be improved when generating and verifying the message verification code, and the authenticity and security of the message verification code can also be guaranteed. In order to improve the security of information during transmission, in an embodiment of the present application, the first verification parameter can be sent by the third device to the first device and the second device.

[0127] As one example, the third device may be a device that receives business requirements and sends the first verification parameter to other devices according to the business requirements. After the first device and the second device establish a connection, the first device and the second device may send a parameter request to the third device, wherein the parameter request is used to instruct the third device to send the first verification parameter. After receiving the parameter request, the third device may send the first verification parameter to the first device and the second device according to the business requirements. The manner in which the third device sends the first verification parameter to the first device and the second device is not limited in the embodiment of the present application and may be specifically set according to the actual application environment.

[0128] S202: The second device generates a message verification code based on the first verification mode.

[0129] After receiving the first verification parameter, the second device can select a first verification mode for generating a message verification code from the first verification parameter.

[0130] In an embodiment of the present application, when there are multiple verification modes supported by the first device and the second device indicated in the mode-related information in the first verification parameter, the second device can arbitrarily select the first verification mode from the multiple verification modes supported together, or select the first verification mode according to the set conditions. For example, according to the security priority, the verification mode with higher security can be preferentially selected as the first verification mode. For example, according to the bandwidth cost priority, the verification mode with the lowest bandwidth cost can be preferentially selected as the first verification mode. It can be set according to actual needs, and the embodiment of the present application does not make specific restrictions. After selecting the first verification mode, a message verification code can be generated based on information such as a shared key, a first verification mode, and associated parameters corresponding to the first verification mode. It can be understood that the generated message verification code should comply with the security strength in the first verification parameter (i.e., the message length that the message verification code should reach) and the supported verification code length range.

[0131] In the embodiment of the present application, when there are multiple verification modes supported by the first device and the second device indicated in the mode-related information in the first verification parameter, the selected first verification mode may be one or more of the multiple verification modes. It is understandable that when the first verification mode is only one verification mode, the generated message verification code is only the message verification code generated by the verification mode; when the first verification mode is multiple verification modes, the generated message verification code includes the message verification codes generated by multiple verification modes.

[0132] Exemplarily, when the first verification mode includes the long MAC independent verification mode and the sliding window chained verification mode, the generated message verification code includes a message verification code generated using the long MAC independent verification mode and a message verification code generated using the sliding window chained verification mode.

[0133] It should be noted that the first verification mode may refer to the verification mode selected by the second device from the mode-related information of the first verification parameter after initialization negotiation, or it may refer to the verification mode currently adopted by the second device during data transmission. It can be understood that the verification mode currently adopted by the second device during data transmission may be a verification mode that has been switched, or it may be a verification mode that has not been switched, which can be determined based on the actual business scenario.

[0134] S203: The second device encapsulates the message verification code and the data to be transmitted to obtain a message to be transmitted.

[0135] The data to be transmitted refers to the data that the second device needs to send to the first device. When encapsulating the message, the second device needs to encapsulate the data to be transmitted and the generated message verification code together.

[0136] Considering that there are multiple verification modes in the first verification parameter, in order to facilitate the first device to verify the message verification code sent by the second device, in the embodiment of the present application, the second device encapsulates the message verification code and the data to be transmitted, and the step of obtaining the message to be transmitted may also include:

[0137] The message verification code, the mode data of the first verification mode, and the data to be transmitted are encapsulated to obtain a message to be transmitted.

[0138] The mode data is used to indicate the verification mode of the message verification code carried in the current message.

[0139] As an example, the mode data of the first verification mode includes an identifier of the first verification mode, and the identifier can indicate a verification mode for generating a message verification code carried in the current message.

[0140] In the embodiment of the present application, by carrying the mode data of the first verification mode in the message, when the first device receives the message, it can be obtained that the message verification code carried in the message is generated by adopting the first verification mode, and the message verification code in the message is verified by adopting the first verification mode.

[0141] To further facilitate the first device to quickly and accurately verify the message verification code, in the embodiment of the present application, the mode data of the first verification mode may also include the message length of the generated message verification code and the associated parameters corresponding to the first verification mode. In this way, when the first device receives the message, it can locally generate a message verification code of the corresponding message length according to the information such as the associated parameters corresponding to the first verification mode, so as to perform verification.

[0142] It can be understood that when the first verification mode is multiple verification modes, the mode data can indicate each verification mode for generating a message verification code in the current message, as well as the message length of the message verification code generated by each verification mode and associated parameters of each verification mode.

[0143] As just one example, the second device may use a mode control bit (Mode) to carry mode data. Fig.13As shown, the message sent by the second device to the first device may include the following four parts: payload, message verification code (Tag), mode control bit (Mode) and sequence number. Among them, the payload part is used to carry the data transmitted by the second device to the first device, the message verification code part is used to carry the verification code generated by the second device for verifying the authenticity of the data, the mode control bit part is used to carry the mode data of the first verification mode for generating the message verification code, and the sequence number part is used to carry the sequence number of the current message.

[0144] It can be understood that in the embodiment of the present application, for each message, the preceding message and the succeeding message of the message can be obtained according to the sequence number of the message, and the messages in the same group as the message can be obtained.

[0145] In the embodiment of the present application, the message verification code part may carry message verification codes generated by multiple verification modes. Fig.14 As shown, as an example, the message authentication codes generated by multiple authentication modes can be divided into iTag and dTag, wherein iTag is an independent authentication tag, i.e., a message authentication code generated by an independent authentication mode, and dTag is an associated authentication tag, i.e., a message authentication code generated by an associated authentication mode, usually a short tag, and the associated authentication mode includes a short MAC packet aggregation authentication mode and a sliding window chain authentication mode. In some embodiments, the second device may also carry two types of message authentication codes.

[0146] Correspondingly, the mode control bit part can also carry mode data of multiple verification modes. Taking the first verification mode as the long MAC independent verification mode and the sliding window chain verification mode as an example, the data carried by the mode control bit part is illustrated. Set the associated parameter W=1 of the long MAC independent verification mode, the associated parameter W=3 of the sliding window chain verification mode, the message length generated by the long MAC independent verification mode is 96 bits, and the message length generated by the sliding window chain verification mode is 32 bits. Assuming that 10 represents the sliding window chain verification mode and 11 represents the long MAC independent verification mode, the mode control bit can include (11, W=1, 96 bits) and (10, W=3, 32 bits) mode data.

[0147] S204: The second device sends a message to the first device.

[0148] Among them, after the second device encapsulates the message verification code, the data to be transmitted, and the mode data of the first verification mode to obtain the message to be transmitted, it can send the message to the first device.

[0149] S205: The first device obtains a message verification code in a message from the second device.

[0150] After receiving the message sent by the second device, the first device parses the message to obtain the message verification code in the message and the data carried by the message.

[0151] It can be understood that, since the message sent by the second device also includes the mode data, the first device can also obtain the mode data in the message after parsing the message.

[0152] S206: The first device verifies the message verification code according to the first verification mode to obtain a verification result.

[0153] When verifying the message verification code, the first device needs to adopt the same verification mode as the second device, that is, the message verification code needs to be verified according to the first verification mode.

[0154] In the embodiment of the present application, since the mode data indicates the first verification mode for generating the message verification code, after obtaining the mode data, the first device can verify the message verification code according to the first verification mode indicated by the mode data to obtain a verification result.

[0155] Exemplarily, the field indicating the first verification mode for generating a message verification code in the mode data obtained by the first device is 11. Assuming that 11 is the long MAC independent verification mode, the first device can use the long MAC independent verification mode to verify the message verification code.

[0156] It can be understood that when the pattern data contains the associated parameters of the first verification mode and the message length of the message verification code, after obtaining the pattern data, the first device can use the first verification mode to locally generate a message verification code of the message length according to the associated parameters of the first verification mode in the pattern data for verification.

[0157] Exemplarily, the long MAC independent verification mode is set to be represented by field 10. If the mode data obtained by the first device is (10, W=1, 96bit), it means that the first verification mode adopted by the second device is the long MAC independent verification mode, the associated parameter is 1, and the message length of the generated message verification code is 96bit. Therefore, when the first device performs verification, it can adopt the long MAC independent verification mode, and locally generate a 96-bit message verification code according to the data carried in the received message and the shared key K received in the initialization phase. Then, the locally generated message verification code is compared with the message verification code in the received message. If the locally generated message verification code is consistent with the message verification code in the received message, it indicates that the data carried in the message is authentic. If the locally generated message verification code is inconsistent with the message verification code in the received message, it indicates that the data carried in the message is unauthentic.

[0158] Exemplarily, the short MAC packet aggregation verification mode is set to be represented by field 11, and the sliding window chain verification mode is represented by field 12. If the mode data obtained by the first device is (11, W = 3, 32bit) and (12, W = 3, 32bit), it means that the first verification mode adopted by the second device is the short MAC packet aggregation verification mode and the sliding window chain verification mode, wherein the associated parameter of the short MAC packet aggregation verification mode is 3, and the message length is 32bit, which means that the group contains 3 messages, and the message length of the message verification code carried by each message in the group is 32bit. The associated parameter of the sliding window chain verification mode is 3, and the message length is 32bit, which means that the data of the first 2 messages need to be associated when generating the message verification code, and the message length of the message verification code carried in the message is 32bit.

[0159] Therefore, when the first device performs verification, it needs to adopt the short MAC group aggregation verification mode and the sliding window chain verification mode for verification. Among them, when the first device adopts the short MAC group aggregation verification mode for verification, after receiving all the messages in the group where the current message is located, the message verification codes carried by all the messages in the group can be spliced ​​to obtain the spliced ​​message verification code, and the message length of the spliced ​​message verification code is 32*3=96bit. Then the first device aggregates the data carried by all the messages in the group, and locally generates a 96-bit message verification code based on the aggregated data and the shared key K received in the initialization phase, and then compares the locally generated message verification code with the spliced ​​message verification code. If the locally generated message verification code is consistent with the spliced ​​message verification code, it means that the data carried by the message of the group is true. If the locally generated message verification code is inconsistent with the spliced ​​message verification code, it means that the data carried by the message of the group is false.

[0160] Among them, when the first device adopts the sliding window chain verification mode for verification, it can locally generate a 32-bit message verification code for the currently received message according to the data carried by the message and the data of the previous two messages associated with the message, and the shared key K received in the initialization phase, and then compare the locally generated message verification code with the message verification code carried in the message. If the locally generated message verification code is consistent with the message verification code carried in the message, it indicates that the data carried by the message is authentic. If the locally generated message verification code is inconsistent with the message verification code carried in the message, it indicates that the data carried by the message is incorrect.

[0161] It can be understood that when the message does not carry mode data, the first device can verify the message authentication code through the verification mode included in the first verification parameter.

[0162] S207: The first device detects, based on the verification result, whether the link status between the first device and the second device meets the switching condition.

[0163] In the embodiment of the present application, the verification result includes two situations: the verification result meets the standard and the verification result does not meet the standard. It can be understood that when the data carried by the message is considered to be true, the verification result of the message meets the standard, and when the data carried by the message is considered to be incorrect, the verification result of the message does not meet the standard.

[0164] As an example, when the first verification mode includes multiple verification modes, if the verification of the multiple verification modes indicates that the data carried by the message is true, then the verification result of the message is that the verification result meets the standard, and if the verification of one verification mode among the multiple verification modes indicates that the data carried by the message is incorrect, then the verification result of the message is that the verification result does not meet the standard. As an example only, when the verification result of the message does not meet the standard, the message can be discarded, and when the verification result of the message meets the standard, the message can continue to be processed.

[0165] In the embodiment of the present application, the switching condition refers to the condition for switching the verification mode, and detecting whether the link state between the first device and the second device meets the switching condition refers to whether the link state between the first device and the second device meets the currently adopted verification mode, that is, the switching condition of the first verification mode. Among them, the switching condition of each verification mode can be set according to business needs, and there is no specific limitation.

[0166] Considering that when the link status between the first device and the second device is good, the number of messages that meet the verification criteria of the first device will increase. At this time, in order to reduce bandwidth costs, the verification mode can be switched to the sliding window chain verification mode and / or the short MAC packet aggregation verification mode. When the link status between the first device and the second device is poor, the messages sent by the second device to the first device may be lost, disordered, attacked, etc., resulting in a decrease in the number of messages that meet the verification criteria. At this time, in order to reduce the losses caused by the poor link status, the verification mode can be switched to the long MAC independent verification mode. Therefore, please refer to Fig.15 In the embodiment of the present application, according to the verification result, the step of detecting whether the link status between the first device and the second device meets the switching condition may also include steps S2071 to S2072.

[0167] S2071: Obtain the number of first messages whose verification results meet the requirements and the number of second messages whose verification results do not meet the requirements.

[0168] S2072: Detect, according to the number of first messages and the number of second messages, whether the link status between the first device and the second device meets the switching condition.

[0169] Among them, the first device can count the verification results of each message. When the first device verifies the current message and obtains the verification result, the statistical result is updated based on the verification result of the current message. For example, if the verification result of the current message is not up to standard, the number of messages whose verification results do not meet the standard can be increased by 1. If the verification result of the current message is up to standard, the number of messages whose verification results meet the standard can be increased by 1.

[0170] After the statistical result is updated, the number of first messages whose verification results meet the standard and the number of second messages whose verification results do not meet the standard can be obtained from the updated statistical result.

[0171] As an example, the first device may also count the verification results of each message according to a set time window to obtain the number of first messages with qualified verification results and the number of second messages with unqualified verification results within each time window. The time window may be set according to business needs, and the embodiments of the present application do not impose specific restrictions.

[0172] As an example, the first device may also collect statistics on the verification results of the messages currently received in the same batch to obtain the number of first messages whose verification results meet the standards and the number of second messages whose verification results do not meet the standards in the same batch.

[0173] As an example, in an embodiment of the present application, based on the number of first messages and the number of second messages, it is detected whether the link status between the first device and the second device meets the switching condition. Based on the number of first messages and the number of second messages, the proportion of the number of first messages can be determined. Based on the proportion of the number of first messages, it is detected whether the link status between the first device and the second device meets the switching condition.

[0174] As an example, the number of first messages may be compared with the number of second messages, and based on the comparison result, it may be detected whether the link state between the first device and the second device is switched to meet the switching condition.

[0175] It can be understood that when the proportion of the number of first messages is high or the number of first messages is greater than the number of second messages, it means that the link state between the first device and the second device is good. At this time, it is possible to detect whether to switch the verification mode from the purpose of saving bandwidth costs. When the proportion of the number of first messages is low or the number of first messages is less than the number of second messages, it means that the link state between the first device and the second device is poor. At this time, it is necessary to detect whether to switch the verification mode from the purpose of improving the security of data transmission and reducing the losses caused by the poor link state.

[0176] For example, the current first verification mode is the long MAC independent verification mode. Assuming that the second verification mode is the sliding window chain verification mode, when the proportion of the number of first messages obtained is greater than the set proportion threshold or the number of first messages is greater than the number of second messages, the link state between the first device and the second device is better. At this time, you can switch to the sliding window chain verification mode to save the bandwidth of the link. When the proportion of the number of first messages obtained is less than the set proportion threshold or the number of first messages is less than the number of second messages, the link state between the first device and the second device is poor. At this time, in order to reduce the loss of the link, you can continue to use the long MAC independent verification mode, that is, no switching is performed.

[0177] In order to improve the accuracy of switching the verification mode and make the verification mode more consistent with the actual link state between the first device and the second device, in the embodiment of the present application, according to the verification result, the step of detecting whether the link state between the first device and the second device meets the switching condition may also include:

[0178] According to the number of first messages, the number of second messages, the first message length of the message authentication code corresponding to the first verification mode, and the second message length of the message authentication code corresponding to the second verification mode, it is detected whether the link status between the first device and the second device meets the switching condition.

[0179] The second verification mode is a verification mode that the first device can switch to, and the second verification mode is different from the first verification mode. Like the first verification mode, the second verification mode can also have multiple verification modes, which can be set according to business needs.

[0180] In the embodiment of the present application, the first message length corresponding to the first verification mode refers to the message length of the message verification code carried in the message in the first verification mode.

[0181] In some embodiments, the message length of the message verification code may be directly carried in the message. Therefore, when the first device receives the message, it may directly obtain the first message length corresponding to the first verification mode from the message.

[0182] As an example, when the message length of the message verification code is not carried in the message, after receiving the message, the first device may also calculate the message length of the message verification code in the message to obtain the first message length corresponding to the first verification mode.

[0183] Accordingly, in the embodiment of the present application, the second message length of the message authentication code corresponding to the second authentication mode refers to the message length of the message authentication code carried by each message in the second authentication mode.

[0184] As an example, the second message length of the message verification code corresponding to the second verification mode can be obtained according to the security strength in the first verification parameter (i.e., the message length that the message verification code should reach), the verification code length range that the first device and the second device can support, and the associated parameters of the second verification mode. For example, the minimum message length of the message verification code of each message in the second verification mode can be determined according to the associated parameters and security strength of the second verification mode, and then the second message length can be obtained according to the verification code length range and the minimum message length. For example, the second verification mode is a sliding window chain verification mode, the associated parameter W=3, the security strength is 96bit, the verification code length range that the first device and the second device can support is (32bit, 64bit, 96bit, 128bit), then the minimum message length of the message verification code carried in each message can be 96 / 3=32bit, wherein the minimum message length is within the verification code length range, therefore, the second message length of the message verification code corresponding to the second verification mode can be 32bit. For another example, the associated parameter W=2, the security strength is 96 bits, and the verification code length range that the first device and the second device can support is (32 bits, 64 bits, 96 bits, 128 bits). Then the minimum message length of the message verification code carried in each message can be 96 / 2=48 bits, wherein the minimum message length is not within the verification code length range. In order to ensure the security strength and save bandwidth costs, the value closest to the minimum message length can be selected within the verification code length range, and at the same time, the security strength of the message can reach the required strength as the second message length, that is, 64 bits can be selected as the second message length within the verification code length range.

[0185] To facilitate mode switching, in some embodiments, the first verification parameter may also directly include the message length of the message verification code corresponding to each verification mode. In this way, when detecting whether to switch the verification mode, the second message length of the message verification code corresponding to the second verification mode and the first message length of the message verification code corresponding to the first verification mode can be obtained from the first verification parameter.

[0186] In an embodiment of the present application, based on the number of first messages, the number of second messages, the first message length of the message verification code corresponding to the first verification mode, and the second message length of the message verification code corresponding to the second verification mode, it is detected whether the link status between the first device and the second device meets the switching condition. The length difference between the first message length and the second message length can be first determined, and then the bandwidth saving cost between the first verification mode and the second verification mode is obtained according to the product of the length difference and the number of first messages. The current link loss is obtained according to the product of the total message length of each message and the number of second messages. Based on the comparison result of the bandwidth saving cost and the link loss, it is detected whether the link status between the first device and the second device meets the switching condition.

[0187] Exemplarily, whether the link status between the first device and the second device meets the switching condition may be detected by the following formula:

[0188] NormalNum×ΔlenTag-badlinkNum×lenPacket>0

[0189] Right now:

[0190]

[0191] Among them, NormalNum is the number of first messages, ΔlenTag is the length difference between the first message length and the second message length, badlinkNum is the number of second messages, lenPacket is the message length, NormalNum×ΔlenTag represents the bandwidth cost that can be saved when switching between the first verification mode and the second verification mode, and badlinkNum×lenPacket represents the link loss between the first device and the second device.

[0192] In the embodiment of the present application, based on the comparison results of link loss and bandwidth saving cost, it is detected whether the link status between the first device and the second device meets the switching conditions. On the one hand, a dynamic trade-off can be achieved between bandwidth cost and security, and the security of data transmission can be guaranteed while reducing bandwidth cost. On the other hand, the accuracy of verification mode switching can be improved, so that the verification mode can better fit the actual link status between the first device and the second device.

[0193] S208: The first device issues a mode switching instruction when the link status meets the switching condition, where the mode switching instruction is used to instruct the second device to switch from the first verification mode to the second verification mode.

[0194] In an embodiment of the present application, the second verification mode to be switched can be determined according to the actual business scenario. For example, if the current business scenario is delay-sensitive and has a short MAC requirement, the real-time verification requirement should be met as much as possible for this scenario, and a shorter message verification code should be used as much as possible. Therefore, for this business scenario, when the link state is good, the sliding window chain verification mode can be used, and when the link state is poor, it can be switched to the long MAC independent verification mode to reduce dependence on the link state.

[0195] For another example, if the current business scenario is latency-insensitive and has a short MAC requirement, then for this scenario, a short MAC is used as much as possible. Therefore, for this business scenario, when the link status is good, a short MAC packet aggregation verification mode can be used. While meeting the short MAC requirement, the number of MAC calculations can be reduced, saving computing resources. When the link status is poor, the long MAC independent verification mode can be switched to reduce dependence on the link status. It can be understood that the second verification mode is also one or more of the verification modes supported by the first device and the second device.

[0196] In the embodiment of the present application, since each verification mode has different characteristics, the switching conditions of each verification mode may be different.

[0197] Exemplarily, for the long MAC independent verification mode, the corresponding switching condition may be that the bandwidth cost saved after the mode switching is greater than the link loss. For example, the current first verification mode is the long MAC independent verification mode, and it is assumed that the second verification mode to be switched is the sliding window chain verification mode. If, after switching to the sliding window chain verification mode, the bandwidth cost saved by the sliding window chain verification mode is greater than the link loss, it can be considered that the current link state between the first device and the second device meets the switching condition of the long MAC independent verification mode, and if, after switching to the sliding window chain verification mode, the bandwidth cost saved by the sliding window chain verification mode is less than the link loss, it can be considered that the current link state between the first device and the second device does not meet the switching condition of the long MAC independent verification mode.

[0198] Exemplarily, for the sliding window chained verification mode, the corresponding switching condition may be that the bandwidth cost saved after the mode is switched is less than the link loss. For example, the current first verification mode is the sliding window chained verification mode, and it is assumed that the second verification mode to be switched is the long MAC independent verification mode. If, after switching to the long MAC independent verification mode, the bandwidth cost saved by the sliding window chained verification mode is less than the link loss, it can be considered that the current link state between the first device and the second device meets the switching condition of the sliding window chained verification mode, and if, after switching to the long MAC independent verification mode, the bandwidth cost saved by the sliding window chained verification mode is still greater than the link loss, it can be considered that the current link state between the first device and the second device does not meet the switching condition of the sliding window chained verification mode.

[0199] It can be understood that when the first device detects that the current link state meets the switching condition of the first verification mode, it can instruct the second device to switch from the first verification mode to the second verification mode and generate a message verification code using the second verification mode.

[0200] In order to facilitate the second device to switch the verification mode, in the embodiment of the present application, when the link state meets the switching condition, a mode switching instruction is issued, including:

[0201] When the link state meets the switching condition, the mode switching instruction is sent to the second device through the fourth device; or,

[0202] When the link status meets the switching condition, a mode switching instruction is sent to the second device.

[0203] In order to improve the security of data transmission, the first device can send a mode switching instruction to the fourth device when the link state meets the switching condition, and the mode switching instruction is sent to the second device through the fourth device. In the embodiment of the present application, the fourth device can be the third device or any other device, without specific limitation.

[0204] As an example, when the fourth device is the third device, the first device may send a first mode switching instruction including the link status between the first device and the second device to the fourth device. After receiving the first mode switching instruction sent by the first device, the fourth device responds to the first mode switching instruction, determines the second verification mode that the second device can switch to according to the actual business demand scenario and the link status between the first device and the second device, and then sends a second mode switching instruction including the second verification mode to the second device to instruct the second device to switch the first verification mode to the second verification mode.

[0205] In some embodiments, to improve processing efficiency, the first device can directly send a mode switching instruction to the second device when the link state meets the switching condition to instruct the second device to switch from the first verification mode to the second verification mode. In this way, the mode switching instruction can be quickly responded to and the verification mode can be switched.

[0206] S209: The second device responds to the mode switching instruction of the first device and switches from the first verification mode to the second verification mode.

[0207] When the first device sends a mode switching instruction to the second device through the fourth device, the second device may respond to the mode switching instruction and switch the verification mode after receiving the mode switching instruction sent by the fourth device.

[0208] Correspondingly, when the first device directly sends a mode switching instruction to the second device, after the second device receives the mode switching instruction sent by the first device, it can respond to the mode switching instruction and execute the switching of the verification mode.

[0209] In the embodiment of the present application, in order to facilitate the second device to switch the verification mode, the mode switching instruction sent to the second device may include an identifier of the second verification mode to be switched. In this way, after receiving the mode switching instruction, the second device can quickly switch the first verification mode to the second verification mode according to the identifier in the mode switching instruction.

[0210] In some embodiments, in order to facilitate the second device to generate a message verification code after switching the verification mode, and also to facilitate the first device to verify the message verification code after switching the verification mode, the mode switching instruction may include the mode data of the second verification mode, that is, the identifier of the second verification mode, the associated parameters corresponding to the second verification mode, and the message length of the generated message verification code. In this way, after receiving the mode switching instruction, the second device can respond to the mode switching instruction to switch the first verification mode to the second verification mode, and generate a message verification code according to the mode data in the mode switching instruction.

[0211] It can be understood that after the second device switches the first verification mode to the second verification mode, in the subsequent data transmission process, when the link status meets the switching condition of the second verification mode, the second verification mode can be switched again.

[0212] For ease of understanding, the data transmission method provided by the embodiment of the present application is described below using two specific scenarios: a delay-sensitive scenario with a short MAC requirement and a delay-insensitive scenario with a short MAC requirement. Fig.16 As shown, the second device is responsible for the generation part of the message verification code, and the first device is responsible for the verification part of the message verification code. Among them, the verification mode can be divided into three categories, namely, the default mode, the short MAC class mode, and the long MAC class mode. The default mode refers to the verification mode adopted by the device by default. If this mode is selected, there is no need to detect the link status. The short MAC class mode can be used to save traffic and reduce bandwidth costs, such as the short MAC packet aggregation verification mode and the sliding window chain verification mode. The long MAC class mode can be used to deal with poor links and attack behaviors, such as the long MAC independent verification mode. The three modes can be distinguished by different identifiers.

[0213] like Fig.16As shown, both the first device and the second device have the function of selecting a mode. After selecting the mode, the second device will use the selected verification mode to generate a message verification code, and then send the message verification code, the mode data of the selected verification mode and the transmission data to the first device. The first device selects the corresponding verification mode according to the mode data to verify the message verification code. After the verification, the first device can, on the one hand, discard the message that fails the verification and continue to process the message that meets the verification. On the other hand, based on the verification result, it detects whether the link status meets the switching conditions. When the switching conditions are met, a mode switching instruction can be issued to instruct the second device to switch the verification mode.

[0214] Among them, for scenarios that are sensitive to delay and have short MAC requirements, due to the high sensitivity to delay, the verification of the message verification code should meet the real-time verification requirements, and at the same time, a shorter message verification code should be used as much as possible. Therefore, it can be set to switch between the long MAC independent verification mode and the sliding window chain verification mode according to the link status. It is set that in the initialization negotiation phase, the negotiated security strength is 96 bits, the minimum message length of the message verification code that the first device and the second device can support is 32 bits, and the verification mode is the long MAC independent verification mode and the sliding window chain verification mode. The associated parameter range of the sliding window chain verification mode is W = {1,2,3}. When W = 1, the message length of the message verification code is 96 bits. When W = 2, the message length of the message verification code is 48 bits, and it is necessary to associate the data of the previous message to generate the message verification code, and realize its own security accumulation through the data of the previous message. When W = 3, the message length of the message verification code is 32 bits, and it is necessary to associate the data of the previous two messages to generate the message verification code, and realize its own security accumulation through the data of the previous two messages.

[0215] As an example, for the sliding window chain verification mode, the second device can select the corresponding associated parameter within the associated parameter range according to the actual message sending situation. For example, when sending the first message, since there is no previous associated message, the associated parameter W can be 1 at this time, when sending the second message, since there is a previous message, the associated parameter W can be 2 at this time, when sending the third message, since there are two previous messages, the associated parameter can be 3 at this time, when sending the fourth message, there are three previous messages, at this time, in order to improve security, the associated parameter can still be 3, and so on.

[0216] In the data transmission stage, in order to distinguish the verification mode, the mode data is set in the mode control bit of the message, and the mode identifier in the mode data may include 11, 10, and 0x. Among them, 0x means that the link status is not detected and the default mode (long MAC independent verification) is adopted; 11 means that the long MAC independent verification mode (W=1, independent verification) is adopted; 10 means that the sliding window chain verification mode (W=3, forward association) is adopted.

[0217] When the second device transmits data to the first device, the second device first selects a verification mode to generate a message verification code, sets the current verification mode to the sliding window chain verification mode, and the second device uses the sliding window chain verification mode to generate a message verification code, and then encapsulates the message verification code, the corresponding mode data (10, W=3, 32bit), and the transmission data into a message and sends it to the first device. After receiving the message, the first device can use the sliding window chain verification mode to verify according to the mode identifier 10 in the mode data to obtain a verification result, and then detects whether the link state between the first device and the second device meets the switching condition of the sliding window chain verification mode according to the verification result, that is, detects whether the bandwidth cost saved after switching to the long MAC independent verification mode is less than the link loss. If the bandwidth cost saved is greater than the link loss, it is confirmed that the switching condition of the sliding window chain verification mode is not met, and the sliding window chain verification mode is continued to be used. If the bandwidth cost saved is not greater than the link loss, it is confirmed that the link state meets the switching condition, and then a mode switching instruction is sent to the second device. After receiving the mode switching instruction, the second device can select the long MAC independent verification mode to generate a message verification code, and then encapsulate the generated message verification code, the corresponding mode data (11, W = 1, 96bit), and the transmission data into a message and send it to the first device. After receiving the message, the first device can use the long MAC independent verification mode to verify according to the mode identifier 11 in the mode data to obtain a verification result, and then detect whether the link state between the first device and the second device meets the switching conditions of the long MAC independent verification mode according to the verification result, and repeat this until the data stops transmitting or reaches other stop conditions. It can be understood that when the second device selects the default mode to generate a message verification code, that is, when the first device obtains the mode identifier 0x in the mode data, it does not detect the link state, but only verifies the message verification code.

[0218] For scenarios that are not sensitive to latency and require short MAC, it is necessary to use a shorter message authentication code as much as possible. From the perspective of reducing the number of calculations, it can be set to switch between the long MAC independent authentication mode and the short MAC group aggregation authentication mode according to the link status. Set in the initialization negotiation phase, the negotiated security strength is 96 bits, the minimum message length of the message authentication code that the first device and the second device can support is 32 bits, and the authentication mode is the long MAC independent authentication mode and the short MAC group aggregation authentication mode, where the associated parameter W of the short MAC group aggregation is {1,2,3}. When W=1, the message length of the message authentication code is 96 bits, and the group includes only 1 message, which is consistent with the independent authentication mode. When W=2, the message length of the message authentication code is 48 bits, and the group includes two messages. When W=3, the message length of the message authentication code is 32 bits, and the group includes 3 messages.

[0219] As an example, for the short MAC packet aggregation verification mode, the second device can also select the corresponding associated parameters within the associated parameter range according to the actual grouping situation. For example, when grouping the messages to be sent, they can be divided into groups based on 3 messages, at this time W=3, and when the number of remaining messages is less than 3, 1 message can be divided into a group or 2 messages can be divided into a group, at this time W=1 or W=2.

[0220] In the data transmission stage, in order to distinguish the verification mode, the mode data is set in the mode control bit of the message, and the mode identifier in the mode data may include 11, 12, and 0x. Among them, 0x means no link status detection, and the long MAC independent verification mode is adopted by default; 11 means the long MAC independent verification mode (W=1, independent verification) is adopted; 12 means the short MAC group aggregation verification mode (W=3, group aggregation) is adopted.

[0221] When the second device transmits data to the first device, the second device first selects a verification mode to generate a message verification code, sets the current verification mode to the short MAC packet aggregation verification mode, and the second device uses the short MAC packet aggregation verification mode to generate a message verification code, and then encapsulates the message verification code, the corresponding mode data (12, W=3, 32bit), and the transmission data into a message and sends it to the first device. After receiving the message, the first device can use the short MAC packet aggregation verification mode for verification according to the mode identifier 12 in the mode data to obtain a verification result, and then detects whether the link state between the first device and the second device meets the switching condition of the short MAC packet aggregation verification mode according to the verification result, that is, detects whether the bandwidth cost saved after switching to the long MAC independent verification mode is less than the link loss. If the bandwidth cost saved is greater than the link loss, it is confirmed that it does not meet the switching condition of the short MAC packet aggregation verification mode, and continues to use the short MAC packet aggregation verification mode. If the bandwidth cost saved is not greater than the link loss, it is confirmed that the link state meets the switching condition of the short MAC packet aggregation verification mode, and then sends a mode switching instruction to the second device. After receiving the mode switching instruction, the second device can select the long MAC independent verification mode to generate a message verification code, and then encapsulate the generated message verification code, the corresponding mode data (11, W=1, 96bit), and the transmission data into a message and send it to the first device. After receiving the message, the first device can use the long MAC independent verification mode to verify according to the mode identifier 11 in the mode data to obtain a verification result, and then detect whether the link status between the first device and the second device meets the switching conditions of the long MAC independent verification mode based on the verification result, and repeat this process until the data stops transmitting or other stop conditions are met.

[0222] To improve data processing efficiency and simplify data transmission, please refer to Fig.17 and Fig.18 In the embodiment of the present application, the data transmission method may further include steps S301 to S310.

[0223] S301: The first device sends a first verification parameter to the second device.

[0224] In order to simplify the data transmission process, the first device can directly send the first verification parameter to the second device.

[0225] In the embodiment of the present application, the first verification parameter sent by the first device to the second device may include a verification mode supported by the first device.

[0226] In the embodiment of the present application, the first verification parameter sent by the first device to the second device may also include the associated parameters of the verification mode supported by the first device, the shared key, the security strength, and the verification code length range supported by the first device. The explanation of the associated parameters, the shared key, the security strength, and the verification code length range can refer to step S201, which will not be repeated here.

[0227] S302: The second device sends a second verification parameter to the first device.

[0228] After receiving the first verification parameter sent by the first device, the second device can obtain the verification mode supported by the first device according to the first verification parameter.

[0229] After obtaining the verification mode supported by the first device, the second device can match the verification mode supported by the first device with the verification mode supported by itself to obtain the verification mode supported by both parties. After obtaining the verification mode supported by both parties, the second device can select the first verification mode from the verification modes supported by both parties to generate a message verification code, that is, the first verification mode is at least one of the verification modes supported by both parties.

[0230] Among them, the second device can select the first verification mode arbitrarily from the verification modes supported by both parties, or select the first verification mode according to set conditions. For example, according to the security priority, the verification mode with higher security can be preferentially selected as the first verification mode. For example, according to the bandwidth cost priority, the verification mode with the lowest bandwidth cost can be preferentially selected as the first verification mode. The specific settings can be based on actual needs, and the embodiments of the present application do not impose specific restrictions.

[0231] It can be understood that the first verification parameters also include the associated parameters of the verification mode supported by the first device, the shared key, the message length that the message verification code should reach, and the verification code length range supported by the first device. Therefore, after the second device obtains the first verification mode, it can generate a message verification code based on the associated parameters of the first verification mode, the shared key, the message length that the message verification code should reach, and the verification code length range supported by the first device.

[0232] Accordingly, to facilitate the subsequent switching of the verification mode by the first device, the second device can send a second verification parameter to the first device after obtaining the verification mode supported by both parties, wherein the second verification parameter includes the verification mode supported by both the first device and the second device.

[0233] It can be understood that after receiving the second verification parameter sent by the second device, the first device analyzes the second verification parameter to obtain the verification mode commonly supported by the first device and the second device. In this way, when the first device subsequently switches the verification mode, it can select the verification mode to be switched from the commonly supported verification modes.

[0234] In an embodiment of the present application, in order to further facilitate the subsequent switching of the verification mode by the first device, the second verification parameter may also include the verification code length range supported by the second device. In this way, when the first device subsequently switches the verification mode, it can select the verification mode to be switched from the commonly supported verification modes, and can set the message length of the message verification code corresponding to the verification mode to be switched according to the verification code length range supported by the second device, so as to facilitate the second device to generate the message verification code.

[0235] S303: The second device generates a message verification code based on the first verification mode.

[0236] S304: The second device encapsulates the message verification code and the data to be transmitted to obtain a message to be transmitted.

[0237] S305: The second device sends a message to the first device.

[0238] S306: The first device obtains a message verification code in the message from the second device.

[0239] S307: The first device verifies the message verification code according to the first verification mode to obtain a verification result.

[0240] S308: The first device detects whether the link status between the first device and the second device meets the switching condition according to the verification result.

[0241] S309: The first device issues a mode switching instruction when the link status meets the switching condition, where the mode switching instruction is used to instruct the second device to switch from the first verification mode to the second verification mode.

[0242] S310: The second device responds to the mode switching instruction of the first device and switches from the first verification mode to the second verification mode.

[0243] The process of step S303 to step S310 may refer to step S202 to step S209, and will not be described in detail here.

[0244] The data transmission method provided in the embodiment of the present application verifies the message verification code according to the first verification mode, and after obtaining the verification result, it can detect whether the link state between the first device and the second device meets the switching condition according to the verification result, and instruct the second device to switch from the first verification mode to the second verification mode when the link state meets the switching condition. In this way, according to the actual link state, the appropriate verification mode is dynamically selected to generate the message verification code, which can achieve a dynamic balance between bandwidth cost and security, and reduce bandwidth cost while ensuring the security of data transmission.

[0245] Based on the same inventive concept, an embodiment of the present application provides an electronic device, which may be a source device or a receiving device in the above embodiment. The electronic device may specifically include a transceiver, a memory, a processor, and one or more computer programs. Among them, the transceiver, the memory, and the processor may be connected through one or more communication buses. Among them, the one or more computer programs are stored in the above memory and are configured to be executed by the processor, and when the one or more computer programs are executed by the processor, the functions or steps in the above data transmission method are implemented.

[0246] An embodiment of the present application further provides a computer-readable storage medium having computer program instructions stored thereon. When the computer program instructions are executed by a processing circuit, the functions or steps in the above-mentioned data transmission method are implemented.

[0247] In addition, an embodiment of the present application can also provide a chip system, which includes a processing circuit and a storage medium, in which computer program instructions are stored. When the computer program instructions are executed by the processing circuit, the functions or steps in the above-mentioned data transmission method are implemented.

[0248] In addition, the embodiments of the present application may also provide a computer program product including instructions, which, when executed on a computer, enables the computer to execute the functions or steps in the above-mentioned data transmission method.

[0249] In addition, an embodiment of the present application may also provide a communication system, which includes a source device and a receiving device, and the source device and the receiving device can be used to execute the functions or steps in the above-mentioned data transmission method.

[0250] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that, for the convenience and conciseness of description, the specific working processes of the chip system, electronic device, computer-readable storage medium, computer program product containing instructions, and communication system described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0251] It is understandable that the steps of the method or algorithm described in conjunction with the embodiments of the present application can be implemented in a hardware manner, or can be implemented by a processor executing a software instruction. The software instruction can be composed of corresponding software modules, and the software module can be stored in a random access memory, a flash memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a read-only optical disk, or any other form of storage medium. An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and can write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an application specific integrated circuit (Application Specific Integrated Circuit, ASIC). In addition, the ASIC can be located in an electronic device. Of course, the processor and the storage medium can also be present in an electronic device as discrete components.

[0252] In an optional manner, when software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is implemented in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a digital video disk (DVD)), or a semiconductor medium (e.g., a solid state disk (SSD)), etc.

[0253] The above is only a specific implementation of the embodiment of the present application, but the protection scope of the embodiment of the present application is not limited thereto, and any changes or replacements within the technical scope disclosed in the embodiment of the present application should be included in the protection scope of the embodiment of the present application. Therefore, the protection scope of the embodiment of the present application should be based on the protection scope of the claims.

Claims

1. A data transmission method, characterized in that: Applied to a first device, the method includes: Obtaining a message verification code in a message from a second device; Verify the message verification code according to the first verification mode to obtain a verification result, where the message verification code is generated by the second device based on the first verification mode; According to the verification result, detecting whether the link status between the first device and the second device meets the switching condition; When the link status meets the switching condition, a mode switching instruction is issued, where the mode switching instruction is used to instruct the second device to switch from the first verification mode to the second verification mode.

2. The method according to claim 1, characterized in that Before obtaining the message verification code in the message from the second device, the method further includes: A first verification parameter sent by a third device is received, where the first verification parameter includes a verification mode commonly supported by the first device and the second device, and the first verification mode is at least one of the verification modes commonly supported by the first device and the second device.

3. The method according to claim 2, characterized in that The first verification parameter also includes one or more of the following: a shared key, a verification code length range supported by the first device and the second device, a message length that the message verification code should reach, associated parameters corresponding to each of the verification modes, and a switching condition for each of the verification modes.

4. The method according to claim 1, characterized in that: Before obtaining the message verification code in the message from the second device, the method further includes: Sending a first verification parameter to the second device, where the first verification parameter includes a verification mode supported by the first device; Receive a second verification parameter fed back by the second device based on the first verification parameter, where the second verification parameter includes a verification mode commonly supported by the second device and the first device, and the first verification mode is at least one of the verification modes commonly supported by the first device and the second device.

5. The method according to claim 4, characterized in that The first verification parameter further includes one or more of the following: a shared key, a verification code length range supported by the first device, an associated parameter of a verification mode supported by the first device, and a message length that the message verification code should reach; The second verification parameter also includes a verification code length range supported by the second device.

6. The method according to any one of claims 1 to 5, characterized in that: The message includes mode data, where the mode data is used to indicate the first verification mode for generating the message verification code; The verifying the message verification code according to the first verification mode includes: The message authentication code is verified according to the first verification mode indicated by the mode data in the message.

7. The method according to claim 6, characterized in that The mode data includes an identifier of the first verification mode, associated parameters corresponding to the first verification mode, and a message length of a message verification code generated by the first verification mode.

8. The method according to any one of claims 1 to 7, characterized in that: The issuing of a mode switching instruction when the link state meets the switching condition comprises: sending the mode switching instruction to the second device when the link state meets the switching condition; or, When the link state meets the switching condition, sending the mode switching instruction to the second device through a fourth device; The mode switching instruction includes an identifier of the second verification mode.

9. The method according to any one of claims 1 to 8, characterized in that: The detecting, according to the verification result, whether the link state between the first device and the second device meets the switching condition includes: Obtain the number of first messages whose verification results meet the standard, and the number of second messages whose verification results do not meet the standard; According to the first number of messages and the second number of messages, it is detected whether the link status between the first device and the second device meets the switching condition, wherein the link status is related to the first number of messages and the second number of messages.

10. The method according to claim 9, characterized in that The message also includes a first message length of a message authentication code corresponding to the first authentication mode, and detecting whether a link state between the first device and the second device meets a switching condition according to the first message quantity and the second message quantity includes: Whether the link status between the first device and the second device meets the switching condition is detected according to the first message quantity, the second message quantity, the first message length, and the second message length of the message authentication code corresponding to the second verification mode.

11. The method according to claim 10, characterized in that The detecting, according to the first message quantity, the second message quantity, the first message length, and the second message length of the message authentication code corresponding to the second verification mode, whether the link state between the first device and the second device meets the switching condition includes: Obtaining a bandwidth saving cost between the first verification mode and the second verification mode according to a length difference between the first message length and the second message length, and the number of the first messages; Obtaining a link loss according to the number of the second messages and the total message length of the messages; According to the bandwidth saving cost and the link loss, it is detected whether the link status between the first device and the second device meets the switching condition.

12. A data transmission method, characterized in that: Applied to the second device, the method includes: Generate a message verification code according to the first verification mode; Encapsulating the message verification code and the data to be transmitted to obtain a message to be transmitted; Sending the message to the first device; In response to a mode switching instruction issued by the first device, switch from the first verification mode to the second verification mode, wherein the mode switching instruction is issued by the first device when the link status between the first device and the second device determined by the message meets the switching condition.

13. The method according to claim 12, characterized in that The step of encapsulating the message verification code and the data to be transmitted to obtain a message to be transmitted includes: The message verification code, the mode data of the first verification mode, and the data to be transmitted are encapsulated to obtain a message to be transmitted.

14. The method according to claim 13, characterized in that The mode data includes an identifier of the first verification mode, associated parameters corresponding to the first verification mode, and a message length of a message verification code generated by the first verification mode.

15. The method according to claim 12, characterized in that The step of responding to the mode switching instruction issued by the first device and switching from the first verification mode to the second verification mode includes: After receiving the mode switching instruction sent by the first device through the fourth device or after receiving the mode switching instruction sent by the first device, switching from the first verification mode to the second verification mode.

16. The method according to claim 12, characterized in that Before generating a message authentication code according to the first authentication mode, the method further includes: receiving a first verification parameter sent by the first device, where the first verification parameter includes a verification mode supported by the first device; A second verification parameter is sent to the first device, where the second verification parameter includes a verification mode commonly supported by the second device and the first device, and the first verification mode is at least one of the verification modes commonly supported by the first device and the second device.

17. The method according to claim 16, characterized in that The first verification parameter further includes one or more of the following: a shared key, a verification code length range supported by the first device, an associated parameter of a verification mode supported by the first device, and a message length that the message verification code should reach; The second verification parameter also includes a verification code length range supported by the second device.

18. The method according to claim 12, characterized in that Before generating a message authentication code according to the first authentication mode, the method further includes: A first verification parameter sent by a third device is received, where the first verification parameter includes at least a verification mode commonly supported by the first device and the second device, and the first verification mode is at least one of the verification modes commonly supported by the first device and the second device.

19. The method according to claim 18, characterized in that The first verification parameter also includes one or more of the following: a shared key, a verification code length range supported by the first device and the second device, a message length that the message verification code should reach, associated parameters corresponding to each of the verification modes, and a switching condition for each of the verification modes.

20. An electronic device, characterized in that: The electronic device comprises: A transceiver, used for sending and receiving messages; a memory for storing computer program instructions; A processor is used to execute the computer program instructions to support the electronic device to implement the method as described in any one of claims 1-11 or any one of claims 12-19.

21. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by the processing circuit, the method according to any one of claims 1 to 11 or the method according to any one of claims 12 to 19 is implemented.

22. A chip system, characterized in that: The chip system includes a processing circuit and a storage medium, wherein the storage medium stores computer program instructions; when the computer program instructions are executed by the processing circuit, the method as described in any one of claims 1-11 or the method as described in any one of claims 12-19 are implemented.

23. A computer program product comprising instructions, characterized in that When the computer program product is executed on a computer, the computer is enabled to execute the method according to any one of claims 1 to 11 or the method according to any one of claims 12 to 19.