Data transmission method and device
By negotiating the aligned keys during the random access of terminal devices in a cellular network, the problem that terminal devices cannot obtain the alignment keys is solved, and security protection for data transmission is achieved and network security is improved.
Patent Information
- Application Number
- CN202311460695.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-03
- Publication Date
- 2025-05-06
AI Technical Summary
The terminal devices in a cellular network cannot obtain the aligned key during random access, resulting in insufficient security protection and vulnerability to attacks.
By negotiating the aligned key during random access, the key is used to encrypt and complete the transmission data to ensure the security of data transmission.
It effectively protects the security of terminal devices and networks, prevents attackers from invading the random access process, and improves the security of the entire cellular network.
Smart Images

Figure CN119946622A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and more specifically, to a method and device for data transmission. Background Art
[0002] Security is an important value feature of cellular networks. The security of communications not only affects the security of user data, but also has a huge impact on whether industrial production can proceed normally. Therefore, as cellular networks evolve, security technologies will also evolve along with them.
[0003] In a cellular network, the initial access process (also called the random access process) is a necessary process for a terminal device to access the network and obtain services. Since the cellular network uses a key deduction mechanism based on the core network, during the random access process of the terminal device, the terminal device and the network device cannot obtain aligned keys for protecting the random access process. However, some current attacks will take advantage of this to attack the random access process of the terminal device, thereby affecting the security of the terminal device and even the network.
[0004] Therefore, how to solve the security protection problem of the random access process has become an issue that needs to be solved urgently. Summary of the invention
[0005] The present application provides a data transmission method, which can securely protect data transmitted during a random access process.
[0006] In a first aspect, a method for data transmission is provided, which can be performed by a first communication device, which can be a terminal device, or can also be a component of a terminal device, such as a circuit, chip, or chip system of the terminal device, or can also be a logic module or software that can implement all or part of the functions of the terminal device.
[0007] The method includes: receiving a first downlink reference signal, and obtaining a first key according to the first downlink reference signal; sending a first uplink reference signal; receiving a first message, the first message including verification information of a second key, the second key being obtained by a second communication device according to the received first uplink reference signal; determining a third key according to the verification information of the first key and the second key; and performing security protection on data transmitted between the second communication device and the second communication device according to the third key.
[0008] As an example, the receiving of the first downlink reference signal may be the first communication device receiving the first downlink reference signal sent by the second communication device, and the sending of the first uplink reference signal may be the first communication device sending the first uplink reference signal to the second communication device. The receiving of the first message may be the first communication device receiving the first message sent by the second communication device.
[0009] The first communication device is a chip of a terminal device, such as a baseband chip. The receiving of the first downlink reference signal or the first message may be that the baseband chip of the terminal device receives the first downlink reference signal or the first message, that is, the first downlink reference signal or the first message is used as an input of the baseband chip of the terminal device. The sending of the first uplink reference signal may be that the baseband chip of the terminal device outputs the first uplink reference signal, for example, outputs the first uplink reference signal to the radio frequency signal of the terminal device.
[0010] It should be understood that the data transmitted between the second communication device may include data and signaling transmitted between the first and second communication devices.
[0011] It should also be understood that the above security protection may include, but is not limited to: encrypting and / or integrity protecting the data transmitted between the first communication device and the second communication device.
[0012] In the above technical solution, the first communication device negotiates an aligned key with the second communication device during the random access process, and uses the aligned key to securely protect the data transmitted between the first communication device and the second communication device. In this way, the random access process can be protected to prevent attackers from attacking the random access process of the first communication device, thereby protecting the security of the first communication device and even the second communication device.
[0013] In combination with the first aspect, in some implementations of the first aspect, when sending the first uplink reference signal, the first communication device also sends a preamble code.
[0014] Specifically, the first communication device may send a preamble code to the second communication device while sending the first uplink reference signal to the second communication device.
[0015] In the above technical solution, the first communication device can send the first uplink reference signal together with the preamble, and the second communication device can measure the first uplink reference signal after estimating the TA using the preamble, so that the measurement result of the first uplink reference signal by the second communication device is more accurate.
[0016] In combination with the first aspect, in certain implementations of the first aspect, before receiving the first downlink reference signal, the first communication device will also receive system information, the system information including measurement configuration information and quantization configuration information; the first communication device will measure the first downlink reference signal according to the measurement configuration information to obtain a measurement result of the first downlink reference signal; and will quantize the measurement result of the first downlink reference signal according to the quantization configuration information to obtain the first key.
[0017] In the above technical solution, the second communication device can send the configuration information of key generation to the first communication device through system information, so that the first communication device and the second communication device can subsequently use the same configuration information to generate aligned keys.
[0018] In combination with the first aspect, in certain implementations of the first aspect, the alignment of the first key and the second key is determined based on verification information of the first key and the second key; the first key is determined as the third key; or the first key is calculated to obtain a fourth key, and the fourth key is determined as the third key.
[0019] It should be understood that the alignment of the first key and the second key can be understood as the first key and the second key being the same or consistent.
[0020] It should also be understood that the present application does not specifically limit the algorithm used to calculate the first key, and any algorithm that can achieve privacy amplification of the first key can be used. In one implementation, the algorithm is a hash algorithm.
[0021] The fourth key is obtained by calculating the first key, and the fourth key is determined as the third key, which can further improve the security of data transmitted between the first communication device and the second communication device.
[0022] In combination with the first aspect, in certain implementations of the first aspect, it is determined that the first key and the second key are not aligned based on verification information of the first key and the second key; a second uplink reference signal is sent on the resources indicated by the first message; a second downlink reference signal is received, and a fifth key is obtained based on the second downlink reference signal; verification information of a sixth key is received; and the third key is determined based on the verification information of the fifth key and the sixth key.
[0023] It should be understood that the above-mentioned misalignment between the first key and the second key can be understood as the first key and the second key being different or inconsistent.
[0024] It should also be understood that the sixth key is obtained by the second communication device according to the received second uplink reference signal.
[0025] The process of determining the third key according to the verification information of the fifth key and the sixth key can refer to the process of determining the third key according to the verification information of the first key and the third key. For example, if it is determined according to the verification information of the fifth key and the sixth key that the fifth key and the sixth key are aligned, the fifth key is determined as the third key, or the fifth key is calculated to obtain the eleventh key, and the eleventh key is determined as the third key.
[0026] In the above technical solution, the second uplink reference signal can be sent on the resources indicated by the first message, avoiding resending of the preamble code and the second uplink reference signal, thereby reducing delay overhead.
[0027] In combination with the first aspect, in certain implementations of the first aspect, the first message also includes a first redundancy version RV (Redundancy Version) of a first coding matrix, and the first key is decoded according to the first RV of the first coding matrix to obtain a seventh key; and the third key is determined based on the verification information of the seventh key and the second key.
[0028] It should be understood that the first encoding matrix is determined by the second communication device according to the second key.
[0029] In combination with the first aspect, in certain implementations of the first aspect, it is determined that the seventh key and the second key are aligned based on verification information of the seventh key and the second key, and the seventh key is determined as the third key.
[0030] In combination with the first aspect, in certain implementations of the first aspect, it is determined that the seventh key and the second key are not aligned based on verification information of the seventh key and the second key; an RV request message is also sent, the RV request message is used to request the second RV of the first coding matrix, and the first key is decoded according to the first RV and the second RV of the first coding matrix to obtain an eighth key, and it is determined that the eighth key and the second key are aligned based on verification information of the eighth key and the second key, and the eighth key is determined as the third key.
[0031] In the above technical solution, by introducing the coding information mechanism of different RVs of the coding matrix, the coding information can be applied for one by one, thereby reducing the large signaling overhead caused by sending the entire coding information.
[0032] In combination with the first aspect, in certain implementations of the first aspect, if it is determined based on the verification information of the eighth key and the second key that the eighth key and the second key are not aligned, it is also possible to fall back to sending a second uplink reference signal on the resources indicated by the first message, obtain the fifth key based on the second downlink reference signal, and determine the third key based on the verification information of the fifth key and the sixth key.
[0033] That is to say, in the above implementation, when the first key and the second key are not aligned, before the first communication device sends the second uplink reference signal to the second communication device through the resources indicated by the first message, the first communication device can first decode the first key according to the first RV and the second RV of the received first coding matrix to obtain the eighth key. If the eighth key and the second key are not aligned, the first communication device then sends the second uplink reference signal to the second communication device through the resources indicated by the first message. The second communication device obtains the sixth key based on the received second uplink reference signal, the first communication device obtains the fifth key based on the second downlink reference signal sent by the second communication device, and the first communication device determines the third key based on the verification information of the fifth key and the sixth key. For the specific process of the first communication device determining the third key based on the verification information of the fifth key and the sixth key, please refer to the description in the above implementation, which will not be repeated here.
[0034] In combination with the first aspect, in some implementations of the first aspect, the first message is a random access response (RAR) message.
[0035] In the above technical solution, by carrying the key verification information in the RAR message, there is no need to add new dedicated information and reconcile the message, thereby reducing the delay overhead.
[0036] According to a second aspect, a method for data transmission is provided, which can be performed by a second communication device, which can be a network device, or a component of a network device, such as a circuit, chip, or chip system of the network device, or a logic module or software that can implement all or part of the functions of the network device.
[0037] The method includes: sending a first downlink reference signal; receiving a first uplink reference signal, and obtaining a second key based on the first uplink reference signal; sending a first message, wherein the first message includes verification information of the second key; determining a ninth key based on the second key; and, based on the ninth key, performing security protection on data transmitted between the first communication device and the first communication device.
[0038] As an example, the sending of the first downlink reference signal or the first message may be the second communication device sending the first downlink reference signal or the first message to the first communication device, and the receiving of the first uplink reference signal may be the second communication device receiving the first uplink reference signal sent by the first communication device.
[0039] The second communication device is a chip of the network device, such as a baseband chip. The receiving of the first uplink reference signal may be that the baseband chip of the network device receives the first uplink reference signal, that is, the receiving of the first uplink reference signal as an input of the baseband chip of the network device. The sending of the first downlink reference signal or the first message may be that the baseband chip of the network device outputs the first downlink reference signal or the first message, for example, outputs the first downlink reference signal or the first message to the radio frequency signal of the network device.
[0040] In combination with the second aspect, in certain implementations of the second aspect, the method also includes: broadcasting system information, the system information including measurement configuration information and quantization configuration information; measuring the first uplink reference signal according to the measurement configuration information to obtain a measurement result of the first uplink reference signal; and quantizing the measurement result of the first uplink reference signal according to the quantization configuration information to obtain the second key.
[0041] In combination with the second aspect, in some implementations of the second aspect, the method further includes: receiving a preamble code.
[0042] As an example, when the second communication device receives the first uplink reference signal sent by the first communication device, it also receives the preamble code sent by the first communication device.
[0043] In combination with the second aspect, in certain implementations of the second aspect, the first key and the second key are aligned, and the second key is determined as the ninth key; or the second key is calculated to obtain a tenth key, and the tenth key is determined as the ninth key.
[0044] In combination with the second aspect, in certain implementations of the second aspect, the first key and the second key are not aligned, and a second downlink reference signal is sent; a second uplink reference signal is received on the resources indicated by the first message; a sixth key is obtained based on the second uplink reference signal; verification information of the sixth key is sent through the first message; and the ninth key is determined based on the fifth key and the verification information of the sixth key, the fifth key being obtained by the first communication device based on the second downlink reference signal.
[0045] It should be understood that the process of determining the ninth key based on the verification information of the fifth key and the sixth key is the same as the process of determining the ninth key based on the second key. Specifically, if the fifth key and the sixth key are aligned, the sixth key can be determined as the ninth key, or the sixth key can be calculated to obtain the twelfth key, and the twelfth key can be determined as the ninth key.
[0046] In combination with the second aspect, in some implementations of the second aspect, a first coding matrix is determined according to the second key; and a first redundant version RV of the first coding matrix is sent through the first message.
[0047] In combination with the second aspect, in certain implementations of the second aspect, the method further includes: receiving an RV request message, the RV request message being used to request a second RV of the first coding matrix; and sending the second RV of the first coding matrix through the first message according to the RV request message.
[0048] In combination with the second aspect, in some implementations of the second aspect, the first message is a random access response RAR message.
[0049] It should be understood that the beneficial effects of the second aspect can be referred to the beneficial effects of the first aspect, and will not be repeated here.
[0050] In a third aspect, a communication device is provided, which may be a terminal device, or a chip or circuit configured in the terminal device, which is not limited in this application. The device includes: a transceiver unit and a processing unit, wherein the transceiver unit is used to receive a first downlink reference signal, and the processing unit is used to obtain a first key according to the first downlink reference signal; the transceiver unit is also used to send a first uplink reference signal and receive a first message, wherein the first message includes verification information of a second key, and the second key is obtained by the second communication device according to the received first uplink reference signal; the processing unit is also used to determine a third key according to the verification information of the first key and the second key, and to perform security protection on the data transmitted between the second communication device and the third key.
[0051] In combination with the third aspect, in certain implementations of the third aspect, when sending the first uplink reference signal, the transceiver unit is further configured to send a preamble code.
[0052] In combination with the third aspect, in certain implementations of the third aspect, before the transceiver unit receives the first downlink reference signal, the transceiver unit is also used to receive system information, the system information including measurement configuration information and quantization configuration information; the processing unit is also used to measure the first downlink reference signal according to the measurement configuration information to obtain a measurement result of the first downlink reference signal, and quantize the measurement result of the first downlink reference signal according to the quantization configuration information to obtain the first key.
[0053] In combination with the third aspect, in certain implementations of the third aspect, the processing unit is also used to determine the alignment of the first key and the second key based on verification information of the first key and the second key; determine the first key as the third key; or calculate the first key to obtain a fourth key, and determine the fourth key as the third key.
[0054] In combination with the third aspect, in certain implementations of the third aspect, the processing unit is also used to determine that the first key and the second key are not aligned based on verification information of the first key and the second key; the transceiver unit is also used to send a second uplink reference signal on the resources indicated by the first message, and receive a second downlink reference signal; the processing unit is also used to obtain a fifth key based on the second downlink reference signal; the transceiver unit is also used to receive verification information of a sixth key, and determine the third key based on the verification information of the fifth key and the sixth key.
[0055] In combination with the third aspect, in certain implementations of the third aspect, the first message also includes a first redundant version RV of the first coding matrix, and the processing unit is also used to decode the first key according to the first RV of the first coding matrix to obtain a seventh key, and determine the third key based on the seventh key and verification information of the second key.
[0056] In combination with the third aspect, in certain implementations of the third aspect, the processing unit is further used to determine that the seventh key and the second key are aligned based on verification information of the seventh key and the second key, and determine the seventh key as the third key.
[0057] In combination with the third aspect, in certain implementations of the third aspect, the processing unit is also used to determine that the seventh key and the second key are not aligned based on verification information of the seventh key and the second key; the transceiver unit is also used to send an RV request message, which is used to request the second RV of the first coding matrix; the processing unit is also used to decode the first key according to the first RV and the second RV of the first coding matrix to obtain an eighth key, determine that the eighth key and the second key are aligned based on verification information of the eighth key and the second key, and determine the eighth key as the third key.
[0058] In combination with the third aspect, in certain implementations of the third aspect, the first message is a random access response RAR message.
[0059] In a fourth aspect, a communication device is provided, which may be a network device, or a chip or circuit configured in the network device, which is not limited in this application. The device includes: a transceiver unit and a processing unit, wherein the transceiver unit is used to send a first downlink reference signal and receive a first uplink reference signal; the processing unit is used to obtain a second key according to the first uplink reference signal; the transceiver unit is also used to send a first message, and the first message includes verification information of the second key; the processing unit is also used to determine a ninth key according to the second key, and according to the ninth key, the data transmitted between the first communication device is securely protected.
[0060] In combination with the fourth aspect, in certain implementations of the fourth aspect, the transceiver unit is further used to receive a preamble code.
[0061] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first key and the second key are aligned, and the processing unit is also used to determine the second key as the ninth key; or calculate the second key to obtain the tenth key, and determine the tenth key as the ninth key.
[0062] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first key and the second key are not aligned, the transceiver unit is also used to send a second downlink reference signal, and receive a second uplink reference signal on the resources indicated by the first message; the processing unit is also used to obtain a sixth key based on the second uplink reference signal; the transceiver unit is also used to send verification information of the sixth key through the first message; the processing unit is also used to determine the ninth key based on the fifth key and the verification information of the sixth key, and the fifth key is obtained by the first communication device based on the second downlink reference signal.
[0063] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is further used to determine a first coding matrix based on the second key; and the transceiver unit is further used to send a first redundant version RV of the first coding matrix through the first message.
[0064] In combination with the fourth aspect, in certain implementations of the fourth aspect, the transceiver unit is also used to receive an RV request message, which is used to request the second RV of the first coding matrix; the processing unit is also used to send the second RV of the first coding matrix through the first message according to the RV request message.
[0065] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first message is a random access response RAR message.
[0066] In a fifth aspect, a communication device is provided, comprising: at least one processor, the processor being configured to enable the communication device to execute the method described in any one of the above aspects by executing computer instructions stored in a memory or through a logic circuit.
[0067] In some possible designs, the communication device further includes a memory for storing computer instructions and / or configuration files of logic circuits. Optionally, the memory is integrated with the processor, or the memory is independent of the processor.
[0068] In a sixth aspect, a communication device is provided, comprising: a processor and a communication interface; the communication interface is used to input and / or output signals; the processor is used to execute a computer program or instruction so that the communication device executes the method described in any of the above aspects.
[0069] In some possible designs, the communication interface is an interface circuit for reading and writing computer instructions. For example, the interface circuit is used to receive computer execution instructions (computer execution instructions are stored in a memory, may be read directly from the memory, or may pass through other devices) and transmit them to the processor.
[0070] In some possible designs, the communication interface is used to communicate with units outside the communication device.
[0071] In some possible designs, the communication device may be a chip or a chip system. When the device is a chip system, the chip system may include a chip, or may include a chip and other discrete devices.
[0072] In the seventh aspect, a communication device is provided, comprising: a logic circuit and an interface circuit; the interface circuit is used to input information and / or output information; the logic circuit is used to execute the method described in any of the above aspects, and process and / or generate output information based on the input information.
[0073] In an eighth aspect, a computer-readable storage medium is provided, in which a computer program or instruction is stored. When the computer program or instruction is executed by a processor, the method described in any one of the above aspects is executed.
[0074] In a ninth aspect, a computer program product is provided, which, when executed by a processor, enables the method described in any one of the above aspects to be executed.
[0075] In a tenth aspect, a communication system is provided, comprising the communication device as described in the third aspect and the communication device as described in the fourth aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0076] Figure 1 It is a schematic diagram of a system architecture provided in an embodiment of the present application.
[0077] Figure 2 It is a flowchart of a random access process and security activation in current cellular networks.
[0078] Figure 3 It is a schematic flowchart of a data transmission method provided in an embodiment of the present application.
[0079] Figure 4 It is a schematic flowchart of another data transmission method provided in an embodiment of the present application.
[0080] Figure 5 It is a schematic flowchart of another data transmission method provided in an embodiment of the present application.
[0081] Figure 6It is a schematic block diagram of a communication device provided in an embodiment of the present application.
[0082] Figure 7 This is another schematic structural diagram of a communication device provided in an embodiment of the present application.
[0083] Figure 8 This is another schematic structural diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0084] The technical solution in this application will be described below in conjunction with the accompanying drawings.
[0085] The terms "first" and "second" and the like in the specification, claims and drawings of this application are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of operations or units is not limited to the listed operations or units, but may optionally include operations or units that are not listed, or may optionally include other operations or units that are inherent to these processes, methods, products or devices.
[0086] Reference to "embodiment" hereinafter means that a particular feature, structure, or characteristic described in conjunction with the embodiment may be included in at least one embodiment of the present application. The appearance of the phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0087] In the present application, "at least one (item)" means one or more, "more than one" means two or more, "at least two (items)" means two or three and more than three, and "and / or" is used to describe the corresponding relationship of corresponding objects, indicating that there may be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the corresponding objects before and after are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0088] For ease of description, the system architecture of the embodiment of the present application is introduced in detail below.
[0089] The technical solution of the embodiment of the present application can be applied to various communication systems, such as: Global System of Mobile communication (GSM) system, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS), Long Term Evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD), Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication system, Fifth Generation (5G) mobile communication system or new radio (NR). Among them, the 5G mobile communication system can be a non-standalone (NSA) or a standalone (SA).
[0090] The technical solution provided in the present application can also be applied to machine type communication (MTC), long term evolution-machine (LTE-M), device-to-device (D2D) network, machine-to-machine (M2M) network, Internet of Things (IoT) network or other networks. Among them, IoT network can include vehicle networking, for example. Among them, the communication methods in the vehicle networking system are collectively referred to as vehicle to other devices (vehicle to X, V2X, X can represent anything), for example, the V2X can include: vehicle to vehicle (V2V) communication, vehicle to infrastructure (V2I) communication, vehicle to pedestrian (V2P) communication or vehicle to network (V2N) communication, etc.
[0091] The technical solution provided in this application can also be applied to future communication systems, such as the sixth generation (6th Generation, 6G) mobile communication system, etc. This application does not limit this.
[0092] A device in a communication system can send a signal to another device or receive a signal from another device. The signal may include information, signaling, or data. The device may also be replaced by an entity, a network entity, a communication device, a communication unit, a node, a communication node, etc. The present application takes the device as an example for description. For example, the communication system may include at least one terminal device and at least one network device. The network device may send a downlink signal to the terminal device, and / or the terminal device may send an uplink signal to the network device.
[0093] Figure 1 1 is a schematic diagram of a communication system 100 provided in an embodiment of the present application. Figure 1 As shown, the communication system 100 includes a network device 110, a terminal device 120 and a terminal device 130. The network device 110 can send a downlink signal to the terminal device 120 and the terminal device 130, and the terminal device 120 and the terminal device 130 can send an uplink signal to the network device 110.
[0094] It should be understood that the embodiments of the present application do not specifically limit the number of terminal devices and network devices included in the communication system. Figure 1The description is made by taking the communication 100 including one network device and two terminal devices as an example.
[0095] The terminal device involved in the embodiments of the present application is an entity on the user side for receiving or transmitting signals. The terminal device can be a device that provides voice and / or data connectivity to the user, for example, a handheld device with wireless connection function, a vehicle-mounted device, etc. The terminal device can also be other processing devices connected to a wireless modem. The terminal device can communicate with a radio access network (RAN).
[0096] In an embodiment of the present application, the terminal device may also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device, etc.
[0097] The terminal devices in the embodiments of the present application include various devices with wireless communication functions, which can be used to connect people, objects, machines, etc. The terminal devices can be widely used in various scenarios, such as: cellular communication, D2D, V2X, peer to peer (P2P), M2M, MTC, IoT, virtual reality (VR), augmented reality (AR), industrial control, automatic driving, telemedicine, smart grid, smart furniture, smart office, smart wear, smart transportation, smart city drones, robots, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery, etc. The terminal device can be a terminal in any of the above scenarios, such as an MTC terminal, an IoT terminal, etc. The terminal device may be a user equipment (UE), terminal, fixed device, mobile station device or mobile device of the third generation partnership project (3GPP) standard, a subscriber unit, a handheld device, a vehicle-mounted device, a wearable device, a cellular phone, a smart phone, a session initialization protocol (SIP) phone, a wireless data card, a personal digital assistant (PDA), a computer, a tablet computer, a notebook computer, a wireless modem, a handheld device (handset), a laptop computer, a computer with wireless transceiver function, a smart book, a vehicle, a satellite, a global positioning system (GPS) device, a target tracking device, an aircraft (such as a drone, a helicopter, a multi-copter, a quadcopter, or an airplane, etc.), a ship, a remote control device, a smart home device, an industrial device, or a device built into the above-mentioned device (for example, a communication unit, a modem or a chip in the above-mentioned device, etc.), or other processing devices connected to the wireless modem. For the convenience of description, the terminal device is described below by taking the terminal or UE as an example.
[0098] Among them, wearable devices can also be called wearable smart devices, which are a general term for the intelligent design and development of wearable devices for daily wear using wearable technology, such as glasses, gloves, watches, clothing and shoes. Wearable devices are portable devices that are worn directly on the body or integrated into the user's clothes or accessories. Wearable devices are not only hardware devices, but also realize powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include full-featured, large-sized, and independent of smartphones to achieve complete or partial functions, such as smart watches or smart glasses, as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.
[0099] In addition, the terminal device can also be a terminal device in the Internet of Things (IoT) system. IoT is an important part of the future development of information technology. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network of human-machine interconnection and object-to-object interconnection. IoT technology can achieve massive connections, deep coverage, and terminal power saving through narrowband (NB) technology, for example.
[0100] In an embodiment of the present application, the terminal device may also be a vehicle or a whole vehicle, which can achieve communication through the Internet of Vehicles, or it may be a component located in the vehicle (for example, placed in the vehicle or installed in the vehicle), that is, a vehicle-mounted terminal device, a vehicle-mounted unit or an on-board unit (OBU).
[0101] In addition, terminal devices can also include sensors such as smart printers, train detectors, and gas stations. Their main functions include collecting data (part of the terminal equipment), receiving control information and downlink data from network devices, and sending electromagnetic waves to transmit uplink data to network devices.
[0102] In the present application, the device for realizing the function of the terminal device may be the terminal device; or it may be a device capable of supporting the terminal device to realize the function, such as a chip system, a hardware circuit, a software unit, or a hardware circuit plus a software unit, and the device may be installed in the terminal device or may be used in combination with the terminal device. In the technical solution provided by the present disclosure, the technical solution provided by the present disclosure is described by taking the device for realizing the function of the terminal device as the terminal device, and the terminal device as the UE as an example.
[0103] The network device in the embodiment of the present application is an entity on the network side for transmitting or receiving signals, which can be used to convert received air frames into Internet Protocol (IP) packets and serve as a router between the terminal device and the rest of the access network, where the rest of the access network may include an IP network, etc.
[0104] The network device in the embodiment of the present application may be a device for communicating with a terminal device, and the network device may also be referred to as an access network device or a wireless access network device, such as a base station. The network device in the embodiment of the present application may refer to a wireless access network (RAN) node (or device) that connects a terminal device to a wireless network. Base station can broadly cover various names as follows, or replace with the following names, such as: NodeB, evolved NodeB (eNB), next generation NodeB (gNB), relay station, access point, transmission point (TRP), transmission point (TP), master station, auxiliary station, multi-standard wireless (motor slide retainer, MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The base station can be a macro base station, a micro base station, a relay node, a donor node or the like, or a combination thereof. The base station can also refer to a communication unit, a modem or a chip used to be set in the aforementioned device or apparatus. The base station can also be a mobile switching center and a device that performs the base station function in D2D, V2X, and M2M communications, a network-side device in a 6G network, or a device that performs the base station function in a future communication system. The base station can support networks with the same or different access technologies. The embodiments of this application do not limit the specific technology and specific device form used by the network device.
[0105] A base station can be fixed or mobile. For example, a helicopter or drone can be configured to act as a mobile base station, and one or more cells can move according to the location of the mobile base station. In other examples, a helicopter or drone can be configured to act as a device that communicates with another base station.
[0106] In some deployments, the gNB may include a centralized unit (CU) and a DU. The gNB may also include an active antenna unit (AAU). The CU implements some functions of the gNB, and the DU implements some functions of the gNB. For example, the CU is responsible for processing non-real-time protocols and services, and implementing the functions of the radio resource control (RRC) and packet data convergence protocol (PDCP) layers. The DU is responsible for processing physical layer protocols and real-time services, and implementing the functions of the radio link control (RLC) layer, the medium access control (MAC) layer, and the physical (PHY) layer. The AAU implements some physical layer processing functions, radio frequency processing, and related functions of active antennas. Since the information of the RRC layer will eventually become the information of the PHY layer, or be converted from the information of the PHY layer, under this architecture, high-level signaling, such as RRC layer signaling, can also be considered to be sent by the DU, or by the DU and the CU. It can be understood that the network device can be a device including one or more of a CU node, a DU node, and an AAU node. In addition, the CU may be classified as a network device in an access network (radio access network, RAN), or the CU may be classified as a network device in a core network (core network, CN), which is not limited in the present application.
[0107] The above-mentioned network equipment provides services for the cell, and the terminal equipment communicates with the cell through the transmission resources (for example, frequency domain resources, or spectrum resources) allocated by the network equipment. The cell may belong to a macro base station (for example, macro eNB or macro gNB, etc.), or may belong to a base station corresponding to a small cell. The small cell here may include: metro cell, micro cell, pico cell, femto cell, etc. These small cells have the characteristics of small coverage and low transmission power, and are suitable for providing high-speed data transmission services.
[0108] In the present application, the device for realizing the function of the access network device may be the access network device; or it may be a device capable of supporting the access network device to realize the function, such as a chip system, a hardware circuit, a software unit, or a hardware circuit plus a software unit, and the device may be installed in the access network device or may be used in combination with the access network device. In the technical solution provided in the present application, the technical solution provided in the present application is described by taking the device for realizing the function of the access network device as the access network device, and the access network device as a base station as an example.
[0109] In the embodiment of the present application, a network device may include one or more cells, and each cell may include one or more transmission reception points (TRP) or transmission points (TP).
[0110] Optionally, in an embodiment of the present application, the network device can also communicate with the core network device.
[0111] Network devices and terminal devices can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on the water; they can also be deployed on aircraft, balloons and satellites in the air. The scenarios in which network devices and terminal devices are located are not limited in the embodiments of the present application. In addition, terminal devices and network devices can be hardware devices, or they can be software functions running on dedicated hardware, software functions running on general-purpose hardware, such as virtualization functions instantiated on a platform (e.g., a cloud platform), or entities including dedicated or general-purpose hardware devices and software functions. The present application does not limit the specific forms of terminal devices and network devices.
[0112] Security is an important value feature of cellular networks. Especially as cellular networks move towards 2B services, the security of communications not only affects the security of user data, but also has a huge impact on whether industrial production can proceed normally. Therefore, in the evolution of cellular networks, security technologies will also evolve together. In cellular networks, the initial access process (also known as the random access process) is a necessary process for terminal devices to access the network and obtain services. Since the cellular network adopts a key deduction mechanism based on the core network, during the random access process of the terminal device, the terminal device and the network device cannot obtain aligned keys for the protection of the random access process. However, some current attacks will take advantage of this to attack the random access process of the terminal device, thereby affecting the security of the terminal device and even the network. Therefore, solving the security protection problem of the random access process is an issue that must be considered in the evolution of cellular networks.
[0113] For the convenience of description, the following Figure 2 This article introduces a random access process and a security activation process in current cellular networks.
[0114] like Figure 2 As shown, Figure 2 This is a schematic diagram of a random access process and security activation process in the current cellular network. Figure 2 As shown, the process includes step 0 to step 9, and steps 0 to step 9 are described in detail below.
[0115] It should be understood that Figure 2 In the description, the terminal device is UE, the network device is base station, and the core network device is core network (core network, CN) as an example.
[0116] Step 0: The UE in RRC_IDLE, CM_IDLE sends a preamble of the access channel to the base station to initiate a random access procedure.
[0117] Step 0a: The UE in RRC_IDLE or CM_IDLE receives a random access response (RAR) message from the base station. The RAR message includes information such as timing advance (TA) and UL-grant.
[0118] Step 1: The UE in RRC_IDLE, CM_IDLE uses the TA and UL-grant included in the RAR message to send a radio resource control connection establishment request (RRC setup request) message to the base station.
[0119] Step 2: After the base station receives the RRC setup request message, if the base station agrees to the RRC establishment request, it returns an RRC connection configuration (RRC setup) message to the UE in RRC_IDLE, CM_IDLE. The RRC setup message includes the configuration of the signaling radio bearer (SRB0), the physical layer and the configuration parameters of the media access control (MAC).
[0120] Step 2a: After the UE in RRC_IDLE, CM_IDLE receives the RRC connection configuration parameters, the UE enters RRC_CONNECTED and sends an RRC setup complete message to the base station, which includes a non-access stratum (NAS) message sent by the UE to the AMF, such as a registration request message, based on other information used by the base station to select the core network.
[0121] Step 3: The base station sends an initial UE message to the CN, which includes the NAS message sent by the UE to the base station in step 2a to the CN.
[0122] Step 4&4a: After processing the NAS message received from the base station, the CN will send some response NAS messages to the UE through the base station.
[0123] Step 5&5a: After receiving the NAS response message from the CN, the UE continues to respond to the message, and then sends a response message of the NAS response message to the CN through the base station.
[0124] Step 6: After receiving the response message of the NAS response message in step 5a, the CN performs relevant verification and processing. For the registration process, the authentication and certification of both the UE and the network can be completed through the interaction of the NAS messages in steps 2a, 3, 4, and 5. Then the CN will send an initial UE context establishment request message to the base station, which contains key information for UE secure communication, security algorithms supported by the network side (encryption algorithm, integrity protection algorithm, referred to as integrity protection algorithm, etc.), and may also include the wireless capabilities of the UE.
[0125] Step 7 & 7a: The base station sends a security activation command to the UE. After receiving the message, the UE verifies it. If the verification is correct, it will deduce the keys used for signaling, data encryption and security, which are used for the protection of subsequent signaling and data transmission respectively. The UE will also send a security activation completion message to the base station to inform the base station that air interface security has been activated.
[0126] Step 8&8a: The base station may reconfigure the air interface transmission parameters, and the reconfiguration message and the reconfiguration completion message are protected by encryption and integrity of the base station and UE respectively.
[0127] Step 9: The base station sends an initial UE context setup completion message to the CN. The entire initial link establishment process is completed, and subsequent data and signaling transmissions between the UE and the base station are securely protected.
[0128] In the above random access process and security activation process, the UE and the base station can align the security key after step 7 and step 8, and the key is used to protect the signaling and data transmission after step 7 and step 8. However, the messages sent between the UE and the base station before step 7 and step 8 are not protected and are vulnerable to attacks.
[0129] In view of this, an embodiment of the present application provides a method for data transmission, which can securely protect data transmitted during a random access process.
[0130] Figure 3 FIG. 1 is a schematic flow chart of a data transmission method provided in an embodiment of the present application. Figure 3 As shown, the method may include steps 310-380, and steps 310-380 are described in detail below.
[0131] Step 310: The first communication device receives a first downlink reference signal sent by the second communication device.
[0132] The first communication device is a chip of a terminal device, such as a baseband chip. The first communication device receiving the first downlink reference signal sent by the second communication device may be that the baseband chip of the terminal device receives the first downlink reference signal sent by the second communication device, that is, the first downlink reference signal is used as an input of the baseband chip of the terminal device.
[0133] Step 320: The first communication device obtains a first key according to the first downlink reference signal.
[0134] In the embodiment of the present application, after the first communication device receives the first downlink reference signal sent by the second communication device, the first key can be obtained according to the first downlink reference signal.
[0135] In an embodiment of the present application, before step 320, the first communication device also receives system information broadcast by the second communication device, and the system information includes but is not limited to the above-mentioned measurement configuration information and quantization configuration information. For example, the measurement configuration information may include but is not limited to: which characteristics of the channel are used for channel key generation, such as channel state information (CSI), really simple syndication (RSS), angle, etc. The quantization configuration information may include but is not limited to: the merging method of measurement results on different resource elements (RE) or resource blocks (RB), the number of bits generated at a time, the method / threshold of discarding bits in quantization (different values can be configured according to different signal-to-noise ratios), etc. For example, the above-mentioned merging method may include but is not limited to: separate generation, or merging first and then generating, or generating independently first and then merging.
[0136] Optionally, the system information may also include: reference signal configuration information, information negotiation configuration information, privacy amplification configuration information, etc. For example, the reference signal configuration information may include but is not limited to: downlink reference signal configuration information (including time domain, frequency domain position and other information), uplink reference signal configuration information, preamble configuration information, time constraints, etc., wherein the uplink reference signal has a pairing relationship with the downlink signal, and the preamble has a corresponding relationship with the uplink reference signal. The information negotiation configuration information may include but is not limited to: the number of check bits, etc. The privacy amplification configuration information may include but is not limited to: the number of bits for HASH operations, etc.
[0137] In one implementation, the first communication device measures the first downlink reference signal according to the received measurement configuration information to obtain a measurement result of the first downlink reference signal, and quantizes the measurement result of the first downlink reference signal according to the received quantization configuration information to obtain the first key.
[0138] Step 330: The first communication device sends a first uplink reference signal to the second communication device.
[0139] Optionally, the first communication device may also send a preamble code to the second communication device when sending the first uplink reference signal to the second communication device.
[0140] Step 340: The second communication device obtains a second key according to the first uplink reference signal.
[0141] In the embodiment of the present application, after the second communication device receives the first uplink reference signal sent by the first communication device, the second communication device may also obtain the second key according to the first uplink reference signal.
[0142] In one implementation, the second communication device measures the first uplink reference signal according to the measurement configuration information to obtain a measurement result of the first uplink reference signal, and quantizes the measurement result of the first uplink reference signal according to the quantization configuration information to obtain the second key.
[0143] Step 350: The first communication device receives a first message sent by the second communication device, where the first message includes verification information of the second key.
[0144] In the embodiment of the present application, after the second communication device obtains the second key, it can generate verification information of the second key according to the second key, and send the verification information of the second key to the first communication device through the first message.
[0145] There are many ways to generate the verification information of the second key, which is not specifically limited in the embodiments of the present application. In one possible implementation, the second key can be used as input to perform a certain operation to obtain a result, which can be used as the verification information of the second key, such as a cyclic redundancy code check.
[0146] It should be understood that the number of bits of the verification information of the second key generated by the second communication device can be determined according to the configuration information of the information negotiation broadcasted by the second communication device to the first communication device.
[0147] As an example, the first message mentioned above is a RAR message.
[0148] Step 360: The first communication device determines a third key based on verification information of the first key and the second key.
[0149] There are multiple implementation methods for the first communication device to determine the third key based on the verification information of the first key and the second key. The embodiments of the present application do not specifically limit this. Several possible implementation methods are introduced below.
[0150] Example 1: The first communication device determines that the first key and the second key are aligned according to verification information of the first key and the second key, and determines the first key as the third key.
[0151] It should be understood that the first communication device can generate verification information of the first key based on the first key. If the verification information of the first key is the same as the verification information of the second key, it can be determined that the first key and the second key are aligned. In a possible implementation, the first communication device takes the first key as input, performs a certain operation (the same as the operation performed by the second communication device to obtain the verification information of the second key) to obtain a result, and the result can be used as the verification information of the first key.
[0152] It should also be understood that the alignment of the first key and the second key can be understood as the first key and the second key being the same or consistent.
[0153] Example 2: The first communication device determines that the first key and the second key are aligned according to verification information of the first key and the second key, calculates the first key to obtain a fourth key, and determines the fourth key as the third key.
[0154] It should also be understood that the present application does not specifically limit the algorithm used to calculate the first key, and any algorithm that can achieve privacy amplification of the first key can be used. In one implementation, the algorithm is a hash algorithm.
[0155] As an example, in a specific implementation, one way to amplify privacy is to ensure that the length of the third key is less than or equal to the length of the first key minus the number of bits of the check information in the first message.
[0156] Example 3: The first communication device determines that the first key and the second key are not aligned based on the verification information of the first key and the second key, the first communication device redetermines the fifth key, and determines the third key based on the verification information of the fifth key and the sixth key.
[0157] That is, the first communication device determines that the first key and the second key are not aligned based on the verification information of the first key and the second key, and the first communication device re-sends the second uplink reference signal to the second communication device on the resources indicated by the first message, and receives the second downlink reference signal re-sent by the second communication device, and obtains the fifth key based on the second downlink reference signal. The first communication device also receives the verification information of the sixth key sent by the second communication device, and the sixth key is obtained by the second communication device based on the received second uplink reference signal. The first communication device determines the third key based on the verification information of the fifth key and the sixth key.
[0158] The process of determining the third key according to the verification information of the fifth key and the sixth key by the first communication device can refer to the process of determining the third key according to the verification information of the first key and the third key. For example, if the fifth key and the sixth key are aligned according to the verification information of the fifth key and the sixth key, the fifth key is determined as the third key, or the fifth key is calculated to obtain the eleventh key, and the eleventh key is determined as the third key. For details, please refer to the process of determining the third key according to the verification information of the first key and the third key, which will not be repeated here.
[0159] It should be understood that the above-mentioned misalignment between the first key and the second key can be understood as the first key and the second key being different or inconsistent.
[0160] Example 4: The first communication device determines that the first key and the second key are not aligned based on the verification information of the first key and the second key. The first communication device decodes the first key according to the first RV of the first coding matrix received from the second communication device to obtain the seventh key, and determines the third key based on the seventh key and the verification information of the second key.
[0161] It should be understood that the first encoding matrix is determined by the second communication device according to the second key.
[0162] For example, the first communication device determines that the seventh key is aligned with the second key according to verification information of the seventh key and the second key, and determines the seventh key as the third key.
[0163] For another example, the first communication device determines that the seventh key and the second key are not aligned based on the verification information of the seventh key and the second key, and also requests the second RV of the first coding matrix from the second communication device, decodes the first key based on the first RV and the second RV of the first coding matrix to obtain the eighth key, and determines the third key based on the verification information of the eighth key and the second key.
[0164] It should be understood that the process of the first communication device determining the third key based on the eighth key and the verification information of the second key is the same as the process of determining the third key based on the seventh key and the verification information of the second key. For example, if the first communication device determines that the eighth key and the second key are aligned based on the verification information of the eighth key and the second key, the eighth key is determined as the third key. For another example, if the first communication device determines that the eighth key and the second key are not aligned based on the verification information of the eighth key and the second key, the first communication device will request the other RVs of the first coding matrix from the second communication device again and repeat the above process.
[0165] In the above example 4, if the number of times the first communication device requests the RV of the first coding matrix from the second communication device reaches the maximum number of requests, it can fall back to the above example 3, and the first communication device and the second communication device respectively redetermine the key based on the new reference signal, and determine the third key according to the method of the above example 3.
[0166] Step 370: The first communication device performs security protection on data transmitted between the first communication device and the second communication device according to the third key.
[0167] It should be understood that the data transmitted between the first communication device and the second communication device may include data, signaling, etc. transmitted between the first and second communication devices.
[0168] It should be understood that the above security protection may include, but is not limited to: encrypting and / or integrity protecting the data transmitted between the first communication device and the second communication device.
[0169] It should be noted that the embodiment of the present application does not specifically limit the execution order of steps 310-370.
[0170] In the above technical solution, the first communication device negotiates an aligned key with the second communication device during the random access process, and uses the aligned key to securely protect the data transmitted between the first communication device and the second communication device. In this way, the random access process can be protected to prevent attackers from attacking the random access process of the first communication device, thereby protecting the security of the first communication device and even the second communication device.
[0171] Step 380: The second communication device determines a ninth key according to the second key, and performs security protection on data transmitted between the second communication device and the first communication device according to the ninth key.
[0172] In an embodiment of the present application, the method for the second communication device to determine the ninth key based on the second key is similar to the method for the first communication device to determine the third key based on the first key. In one example, if the first key and the second key are aligned, the second communication device determines the second key as the ninth key. In another example, if the first key and the second key are aligned, the second communication device calculates the second key to obtain the tenth key, and determines the tenth key as the ninth key. In another example, if the first key and the second key are not aligned, the second communication device determines the sixth key based on the second uplink reference signal sent by the first communication device, and if the sixth key and the fifth key determined by the first communication device based on the second downlink reference signal are aligned, the second communication device can determine the sixth key as the ninth key, or calculate the sixth key to obtain the twelfth key, and determine the twelfth key as the ninth key.
[0173] In the embodiment of the present application, after determining the third key aligned with the ninth key, the first communication device will send a message, such as Msg3, to the second communication device. After receiving the message, the second communication device can determine the alignment between the ninth key determined by it and the third key determined by the first communication device according to the message, and at this time, the second communication device can perform security protection on the data transmitted between the second communication device and the first communication device according to the ninth key.
[0174] It should be understood that the above security protection may include but is not limited to: encrypting and / or integrity protecting the data transmitted between the second communication device and the first communication device.
[0175] Combine the following Figure 4 , a specific implementation process of the data transmission method provided in the embodiment of the present application is described in detail. It should be understood that Figure 4 The examples are only intended to help those skilled in the art understand the embodiments of the present application, and are not intended to limit the embodiments of the present application to Figure 4 The specific numerical values or specific scenarios shown in the examples. Figure 4 The examples given below are obviously susceptible to various equivalent modifications or changes, and such modifications and changes also fall within the scope of the embodiments of the present application.
[0176] Figure 4 FIG. 1 is a schematic flow chart of another method for data transmission provided in an embodiment of the present application. Figure 4 As shown, the method may include steps 410-490, and steps 410-490 are described in detail below.
[0177] It should be understood that for ease of description, Figure 4 In the description, the first communication device is a UE and the second communication device is a base station as an example.
[0178] Step 410: The base station broadcasts system information, where the system information includes configuration information related to secure random access.
[0179] In an embodiment of the present application, the base station may broadcast system information to other devices in the network, and the system message includes relevant configuration information of the secure random access process. As an example, the relevant configuration information of the secure random access process is used to generate a symmetric or aligned key between the base station and the UE during the random access process.
[0180] In the above technical solution, the base station can use the system information to send a new configuration message for key generation to the UE, so that the UE and the base station can subsequently align the parameters for key generation.
[0181] For example, the configuration information related to the above-mentioned secure random access process may include, but is not limited to: reference signal configuration information, measurement configuration information, quantization configuration information, information negotiation configuration information, privacy amplification configuration information, etc. For a specific description of these configuration information, please refer to the description in step 320, which will not be repeated here.
[0182] Step 415: The base station sends a downlink reference signal (DLreference signal) to the UE.
[0183] Step 420: The UE receives a downlink reference signal sent by the base station, and measures and quantizes the downlink reference signal according to the system information broadcast by the base station to obtain a key key1.
[0184] In an embodiment of the present application, the base station may send a downlink reference signal to the UE. After receiving the downlink reference signal sent by the base station, the UE may measure the downlink reference signal according to the measurement configuration information in the system information broadcast by the base station, and may also quantize the measurement result according to the quantization configuration information in the system information broadcast by the base station to obtain the key key1. Specifically, the UE may quantize the measurement result into a bit stream of a string of 01s, and the bit stream of a string of 01s constitutes the above-mentioned key key1.
[0185] The embodiment of the present application does not specifically limit the time when the UE measures and quantizes the downlink reference signal to obtain the key key1 according to the system information broadcast by the base station. As an example, the UE can measure and quantize the received downlink reference signal within a period of time before initiating a random access process to the base station (for example, sending a preamble) to obtain the key key1. As another example, the UE can also measure and quantize the received downlink reference signal at the most recent time point before initiating a random access process to the base station (for example, sending a preamble) to obtain the key key1, so that the accuracy of measurement and quantization can be improved.
[0186] Step 425: The UE sends a preamble code and an uplink reference signal (UL reference signal) at a corresponding position to the base station according to the system information broadcast by the base station.
[0187] In the embodiment of the present application, the UE may send an uplink reference signal and a preamble (preamble) at a corresponding position to the base station according to the configuration information of the reference signal in the system information broadcast by the base station.
[0188] In the above technical solution, the UE can send the uplink reference signal and the preamble together, so that the base station can measure the uplink reference signal after estimating the TA using the preamble, making the measurement result of the uplink reference signal by the base station more accurate.
[0189] Step 430: The base station measures and quantizes the received uplink reference signal to obtain the key key2.
[0190] In the embodiment of the present application, after receiving the preamble sent by the UE and the uplink reference signal at the corresponding position, the base station can measure and quantize the uplink reference signal to obtain the key key2. It should be understood that the method for the base station to obtain the key key2 is similar to the method for the UE to obtain the key key1. Specifically, the base station can measure the uplink reference signal according to the broadcast measurement configuration information, and can also quantize the measurement result according to the broadcast quantization configuration information to obtain the key key2.
[0191] Step 435: The base station sends a RAR message to the UE. The RAR message may include verification information of the key key2.
[0192] In the embodiment of the present application, after obtaining the key key2, the base station may calculate verification information of the key key2, and include the verification information of the key2 in a RAR message and send it to the UE.
[0193] There are many ways to generate the verification information of the key key2, which is not specifically limited in the embodiments of the present application. In one possible implementation, key2 can be used as input, and a certain operation can be performed to obtain a result, which can be used as the verification information of key2. It should be understood that the number of bits of the verification information of key2 generated by the base station can be determined according to the configuration information of the information negotiation broadcast by it.
[0194] For example, a cyclic redundancy check (CRC) may be used as the verification information of the key2.
[0195] In the above technical solution, the base station can use the RAR message to carry the verification information of the key key2, so there is no need to add new dedicated information and reconcile the message, thereby reducing the system delay and overhead.
[0196] Step 440: The UE verifies the verification information of the key key2 according to the key key1.
[0197] In an embodiment of the present application, after the UE receives the verification information of the key key2 sent by the base station, the UE verifies the received verification information of the key key2 according to the key key1 generated by itself. Specifically, in a possible implementation, the UE can use key1 as input according to the method in which the base station generates the verification information of key2 in step 435, perform a certain operation to obtain a result, and the result can be used as the verification information of key1, and determine whether the verification information of key1 is the same as the verification information of key2. If the verification information of key1 is the same as the verification information of key2, it can be understood that the verification information of key2 has passed the verification of the UE; if the verification information of key1 is not exactly the same as the verification information of key2, it can be understood that the verification information of key2 has not passed the verification of the UE.
[0198] It should be understood that the number of bits of the verification information of key1 generated by the UE is the same as the number of bits of the verification information of key2. Specifically, the UE can determine the number of bits of the verification information of key1 according to the configuration information negotiated by the information broadcast by the base station.
[0199] As an example, the UE may also determine whether the key key1 generated by the UE and the key key2 generated by the base station are aligned based on whether the verification information of key2 passes the verification. The following describes the situation 1 and situation 2 respectively.
[0200] Case 1 (step 445-step 450):
[0201] Step 445: The UE determines that the key key1 is aligned with the key key2.
[0202] As an example, if the verification information of key1 is the same as the verification information of key2, the verification information of key2 passes the verification of the UE, and the UE can determine that the key key1 is aligned with the key key2.
[0203] Step 450: The UE and the base station may use the aligned key1 and key2 to perform encryption and / or integrity protection on subsequently transmitted signaling or data.
[0204] As an example, if the UE determines that the key key1 and the key key2 are aligned, the UE can use key1 to encrypt and / or integrity protect the signaling and / or data of subsequent uplink transmissions. Similarly, the base station can also use key2 to encrypt and / or integrity protect the signaling and / or data of subsequent downlink transmissions.
[0205] It should be understood that the signaling and / or data of the subsequent uplink transmission may be a random access process (for example, Figure 2 The signaling and / or data transmitted uplink in step 1 to step 7) of the present invention may also be the signaling and / or data transmitted uplink in other processes, and the signaling and / or data transmitted downlink in the subsequent process may be a random access process (for example, Figure 2 The signaling and / or data transmitted downlink in step 1 to step 7) may also be the signaling and / or data transmitted downlink in other processes, and the embodiments of the present application do not make specific limitations on this.
[0206] Optionally, since the key2 verification information sent by the base station to the UE is not protected, once it is used by an illegal person, key2 may become unavailable. In some embodiments, in order to prevent the key2 verification information sent by the base station from being obtained by other illegal persons, the base station may also perform a hash operation on key2 according to the number of bits of the HASH operation in the privacy amplification configuration information it broadcasts, and obtain a key2 indicating the number of bits. (1) and use key2 (1) The signaling and / or data of the subsequent downlink transmission is encrypted and / or integrity protected. Similarly, the UE can also perform a hash operation on key1 according to the number of bits of the HASH operation in the privacy amplification configuration information broadcast by the base station to obtain the number of bits of key1 indicating the number of bits. (1) , and use key1 (1) The signaling and / or data of subsequent uplink transmission is encrypted and / or integrity protected.
[0207] It should be understood that key1 (1) Indicates that based on key1, a hash operation is performed on key1 to obtain key1 (1) .key2 (1)Indicates that based on key2, a hash operation is performed on key2 to obtain key2 (1) .
[0208] Case 2 (step 455-step 490):
[0209] Step 455: The UE determines that there is no alignment between key key1 and key2.
[0210] As an example, if the verification information of key1 is not the same as or is not completely the same as the verification information of key2, it means that the verification information of key2 has not passed the verification of the UE, and the UE may determine that the key key1 is not aligned with the key key2.
[0211] Step 460: The UE continues to send the uplink reference signal on the resources indicated by the RAR message.
[0212] In the embodiment of the present application, after determining that key1 and key2 are not aligned, the UE can resend the uplink reference signal on the resource indicated by the RAR message, so as to avoid the UE from resending the preamble and uplink reference signal from step 425, thereby reducing the delay of the access process.
[0213] Step 465: The base station measures and quantizes the re-received uplink reference signal to obtain the key key3.
[0214] In the embodiment of the present application, after receiving the uplink reference signal retransmitted by the UE on the resource indicated by the RAR message, the base station can measure and quantize the re-received uplink reference signal to obtain the key key3. It should be understood that the process of determining the key key3 is similar to the process of determining key2 in step 430. For details, please refer to the description in step 430, which will not be repeated here.
[0215] Step 470: The UE continues to measure and quantize the downlink reference signal sent by the base station to obtain the key key4.
[0216] In the embodiment of the present application, the base station periodically sends a downlink reference signal to the UE, and the UE can continue to measure and quantize the downlink reference signal sent by the base station to obtain the key key4.
[0217] Step 475: The base station sends a RAR message to the UE. The RAR message may include verification information of the key key3.
[0218] Step 480: The UE verifies the verification information of the key key3 according to the key key4.
[0219] It should be understood that step 480 corresponds to step 440. Please refer to the description in step 440 for details, which will not be repeated here.
[0220] Step 485: The UE determines that the key key4 is aligned with the key key3.
[0221] It should be understood that step 485 corresponds to step 445. Please refer to the description in step 445 for details, which will not be repeated here.
[0222] Step 490: The UE and the base station may use the aligned key4 and key3 to perform encryption and / or integrity protection on subsequently transmitted signaling or data.
[0223] It should be understood that step 490 corresponds to step 450. Please refer to the description in step 450 for details, which will not be repeated here.
[0224] Optionally, since the key3 verification information sent by the base station to the UE is not protected, once it is used by an illegal person, key3 may become unavailable. In some embodiments, in order to prevent the key3 verification information sent by the base station from being obtained by other illegal persons, the base station may also perform a hash operation on key3 according to the number of bits of the HASH operation in the privacy amplification configuration information it broadcasts, and obtain a key3 indicating the number of bits. (1) , and use key3 (1) The signaling and / or data of the subsequent downlink transmission is encrypted and / or integrity protected. Similarly, the UE can also perform a hash operation on key4 according to the number of bits of the HASH operation in the privacy amplification configuration information broadcast by the base station to obtain the number of bits of key4 indicating the number of bits. (1) , and use key4 (1) The signaling and / or data of subsequent uplink transmission is encrypted and / or integrity protected.
[0225] It should be understood that key3 (1) Indicates that based on key3, a hash operation is performed on key3 to obtain key3 (1) .key4 (1) Indicates that based on key4, a hash operation is performed on key4 to obtain key4 (1) .
[0226] It should be noted that if the result of the UE verifying the verification information of key key3 according to key key4 in step 480 is that key4 and key3 are not aligned, then the UE and the base station can continue to repeat steps 460-490 until the UE and the base station determine the aligned keys.
[0227] Optionally, the base station may also set a maximum number of limits. If the number of retries exceeds the maximum number, it will fall back to the normal RACH or reselect another cell.
[0228] In the above technical solution, by enhancing the uplink and downlink signal measurement and quantization of the UE and the base station during the random access process, working keys are obtained respectively, and then the signaling and / or data in the random access process are encrypted and integrity protected, thereby achieving secure random access of the UE and preventing attackers from attacking the random access process.
[0229] Combine the following Figure 5 , another specific implementation process of the data transmission method provided in the embodiment of the present application is described in detail. It should be understood that Figure 5 The examples are only intended to help those skilled in the art understand the embodiments of the present application, and are not intended to limit the embodiments of the present application to Figure 5 The specific numerical values or specific scenarios shown in the examples. Figure 5 The examples given below are obviously susceptible to various equivalent modifications or changes, and such modifications and changes also fall within the scope of the embodiments of the present application.
[0230] Figure 5 FIG. 1 is a schematic flow chart of another method for data transmission provided in an embodiment of the present application. Figure 5 As shown, the method may include steps 510-580, and steps 510-580 are described in detail below.
[0231] It should be understood that for ease of description, Figure 5 In the description, the first communication device is a UE and the second communication device is a base station as an example.
[0232] Step 510: The base station broadcasts system information, where the system information includes configuration information related to secure random access.
[0233] For example, the above-mentioned configuration information related to the secure random access may include but is not limited to: reference signal configuration information, measurement configuration information, quantization configuration information, information negotiation configuration information, privacy amplification configuration information, etc. Among them, the configuration information of information negotiation may include but is not limited to: the number of check bits, the encoding method used for the negotiation information (such as low-density parity check code (LDPC), Polar or other encoding), whether to support multiple RV versions of the check bit, the total number of RV versions, etc.
[0234] It should be understood that the other configuration information mentioned above (for example, reference signal configuration information, measurement configuration information, quantization configuration information, and privacy amplification configuration information) is the same as the configuration in step 410. For specific descriptions of these configuration information, please refer to the description in step 410, which will not be repeated here.
[0235] Step 515: The base station sends a downlink reference signal to the UE.
[0236] Step 520: The UE receives a downlink reference signal sent by the base station, and measures and quantizes the downlink reference signal according to the system information broadcast by the base station to obtain a key key1.
[0237] Step 525: The UE sends a preamble code and an uplink reference signal at a corresponding position to the base station according to the system information broadcast by the base station.
[0238] Step 530: The base station measures and quantizes the received uplink reference signal to obtain the key key2.
[0239] Step 535: The base station sends a RAR message to the UE. The RAR message may include verification information of the key key2 and a redundant version (RV) of a coding check matrix.
[0240] It should be understood that the verification information of the key key2 contained in the RAR message sent by the base station to the UE in step 535 is the same as the verification information of the key key2 in step 435. For details, please refer to the description in step 435, which will not be repeated here.
[0241] In step 535, in addition to sending the verification information of the key key2 to the UE through the RAR message, the base station will also send an additional RV of the coding check matrix. The coding check matrix can be determined according to the key key2 generated by the base station, and is used to correct the error of the key key1 generated by the UE, so that the key key1 generated by the UE can be aligned with the key2 generated by the base station. In the embodiment of the present application, since the coding check matrix is large, in order to reduce the large signaling overhead caused by the transmission of the coding check matrix, the base station can send an RV version of the coding check matrix to the UE through the RAR message. The RV version of the coding check matrix can be understood as a part of the coding check matrix.
[0242] In the above technical solution, by introducing the coding information mechanism of different RV versions, coding information (for example, coding check matrix) can be applied for one by one, avoiding the large signaling overhead caused by sending the entire coding information.
[0243] Step 540: The UE decodes the key key1 according to an RV version of the coding check matrix to obtain key1(2) , and according to key1 (2) Verify the verification information of key key2.
[0244] In the embodiment of the present application, after the UE receives an RV version of the coding check matrix sent by the base station, it can decode the key key1 generated by it based on the RV version of the coding check matrix to obtain key1 (2) The UE can also use key1 (2) Verify the verification information of key key2 to determine the key key1 obtained by the UE (2) Whether the key is aligned with the key key2 generated by the base station. The following describes the situation 1 and situation 2 respectively.
[0245] It should be understood that the UE uses key1 (2) The process of verifying the verification information of the key key2 is similar to the process of the UE verifying the verification information of the key key2 according to key1 in step 440. For details, please refer to the description in step 440, which will not be repeated here.
[0246] It should be understood that key1 (2) It means that based on key1, key1 is decoded to get key1 (2) .
[0247] Case 1 (step 545-step 550):
[0248] Step 545: UE determines key1 (2) Aligned with key key2.
[0249] As an example, if key1 (2) If the verification information of key1 is the same as the verification information of key2, the verification information of key2 has passed the verification of UE, and UE can determine the key key1. (2) Aligned with key key2.
[0250] Step 550: The UE and the base station can use the aligned key1 (2) and key2 to encrypt and / or integrity protect the subsequently transmitted signaling or data.
[0251] As an example, if the UE determines the key key1 (2) Aligned with key key2, UE can use key1 (2) The signaling and / or data of subsequent uplink transmission is encrypted and / or integrity protected. Similarly, the base station can also use key2 to encrypt and / or integrity protect the signaling and / or data of subsequent downlink transmission.
[0252] Optionally, in some embodiments, in order to prevent the verification information of key2 sent by the base station from being obtained by other illegal persons, the base station may also perform a hash operation on key2 according to the number of bits of the HASH operation in the configuration information of the privacy amplification broadcasted by it, and obtain the key2 indicating the number of bits. (1) and use key2 (1) The signaling and / or data of the subsequent downlink transmission is encrypted and / or integrity protected. Similarly, the UE can also perform encryption and / or integrity protection on key1 according to the number of bits of the HASH operation in the privacy amplification configuration information broadcast by the base station. (2) Perform hash operation to get the key1 indicating the number of bits (3) , and use key1 (3) The signaling and / or data of subsequent uplink transmission is encrypted and / or integrity protected.
[0253] It should be understood that key1 (3) Indicates that in key1 (2) Based on key1 (2) Perform hash operation to get key1 (3) .
[0254] Case 2 (step 555-step 580):
[0255] Step 555: UE determines key1 (2) There is no alignment between key key2.
[0256] As an example, if key1 (2) If the verification information of key1 is different from or not completely the same as the verification information of key2, it means that the verification information of key2 has not passed the verification of UE. UE can determine the key key1. (2) There is no alignment between key key2.
[0257] Step 560: The UE sends a request message for other RVs of the coding check matrix to the base station on the resources indicated by the RAR message.
[0258] In the embodiment of the present application, the UE determines the key key1 (2) After there is no alignment between and key key2, a request message for other RVs of the coding check matrix may be sent on the resources indicated by the RAR message, where the request message for other RVs of the coding check matrix is used to request the base station for other RVs of the above coding check matrix.
[0259] Step 565: The base station sends a RAR message to the UE, where the RAR message includes other RVs of the coding check matrix.
[0260] In the embodiment of the present application, after receiving a request message for other RVs of the coding check matrix sent by the UE, the base station may send other RVs of the coding check matrix to the UE.
[0261] Step 570: The UE combines different RVs of the coding check matrix and decodes the key key1 based on the combined RV to obtain key1 (4) , and according to key1 (4) Verify the verification information of key key2.
[0262] In the embodiment of the present application, after the UE receives the other RV of the coding check matrix sent by the base station, it can merge the RV with the RV of the coding check matrix received in step 540, and decode the key key1 based on the merged RV to obtain key1 (4) , and according to key1 (4) Verify the verification information of key key2.
[0263] It should be understood that the UE uses key1 (4) The process of verifying the verification information of the key key2 is similar to the process of the UE verifying the verification information of the key key2 according to key1 in step 440. For details, please refer to the description in step 440, which will not be repeated here.
[0264] Step 575: UE determines key1 (4) Aligned with key key2.
[0265] As an example, if key1 (4) If the verification information of key1 is the same as the verification information of key2, the verification information of key2 has passed the verification of UE, and UE can determine the key key1. (4) Aligned with key key2.
[0266] Step 580: The UE and the base station can use the aligned key1 (4) and key2 to encrypt and / or integrity protect the subsequently transmitted signaling or data.
[0267] As an example, if the UE determines the key key1 (4) Aligned with key key2, UE can use key1 (4) The signaling and / or data of subsequent uplink transmission is encrypted and / or integrity protected. Similarly, the base station can also use key2 to encrypt and / or integrity protect the signaling and / or data of subsequent downlink transmission.
[0268] Optionally, in some embodiments, in order to prevent the verification information of key2 sent by the base station from being obtained by other illegal persons, the base station may also perform a hash operation on key2 according to the number of bits of the HASH operation in the configuration information of the privacy amplification broadcasted by it, and obtain the key2 indicating the number of bits. (1) and use key2 (1) The signaling and / or data of the subsequent downlink transmission is encrypted and / or integrity protected. Similarly, the UE can also perform encryption and / or integrity protection on key1 according to the number of bits of the HASH operation in the privacy amplification configuration information broadcast by the base station. (4) Perform hash operation to get the key1 indicating the number of bits (5) , and use key1 (5) The signaling and / or data of subsequent uplink transmission is encrypted and / or integrity protected.
[0269] It should be understood that key1 (5) Indicates that in key1 (4) Based on key1 (4) Perform hash operation to get key1 (5) .
[0270] Optionally, in some embodiments, if the UE determines the key key1 (4) If there is no alignment between the key key1 and the key key2, the UE and the base station may continue to repeatedly perform steps 560 to 570, and the UE continues to request other RVs of the coding check matrix from the base station until the key determined by the UE and the key determined by the base station are aligned with each other.
[0271] It should be noted that, in an embodiment of the present application, the base station may also indicate the maximum number of RVs in the broadcast system information. If the number of other RVs of the coding check matrix that the UE requests from the base station reaches the maximum number of RVs indicated in the system information, the UE cannot continue to request other RVs of the coding check matrix from the base station, but needs to continue to send uplink reference signals on the resources indicated by the RAR message. The base station measures and quantizes the re-received uplink reference signal to obtain a new key. The UE continues to measure and quantize the downlink reference signal sent by the base station to obtain a new key. The UE verifies the key re-obtained by the base station and its own key re-obtained to determine whether the key re-obtained by the base station is aligned with the key re-obtained by the UE. That is, when the number of other RVs of the coding check matrix that the UE requests from the base station reaches the maximum number of RVs indicated in the system information, the UE needs to execute repeatedly. Figure 4 Steps 460-480 are performed until the key determined by the UE and the key determined by the base station are aligned with each other.
[0272] In the above technical solution, Figure 4On the basis of the method shown, in the link of key alignment, information reconciliation based on coding is considered, and different RVs of coding check matrices are introduced to improve the efficiency of information reconciliation.
[0273] Above, combined Figures 1 to 5 The method provided by the embodiment of the present application is described in detail. Figures 6 to 8 The device provided in the embodiment of the present application is described in detail. It should be understood that the description of the device embodiment corresponds to the description of the method embodiment, so the contents not described in detail can be referred to the method embodiment above, and for the sake of brevity, they are not described here.
[0274] Figure 6 600 is a schematic block diagram of a communication device 600 provided in an embodiment of the present application. Figure 6 As shown, the device 600 may include a transceiver unit 610 and a processing unit 620, wherein the transceiver unit 610 may communicate with the outside, for example, data / information received from the outside may be input to the processing unit, and data / information processed by the processing unit may be output to the outside. The transceiver unit 610 may also be referred to as a communication interface or a communication unit. The processing unit 620 is used to process data / information so that the above Figure 3-Figure 5 The function of the first communication device in the method shown is realized, or the above Figure 3-Figure 5 In the method shown, the functionality of the second communication device is implemented.
[0275] In a possible implementation, the device 600 may be Figure 3-Figure 5 The first communication device in the method shown can also be used to implement the above Figure 3-Figure 5 Specifically, the device 600 can implement the function of the first communication device in the method shown above. Figure 3-Figure 5 The process executed by the first communication device in the method shown, wherein the transceiver unit 610 and the processing unit 620 are used to perform operations related to the processing of the first communication device in the above method process.
[0276] The transceiver unit 610 is used to receive a first downlink reference signal, send a first uplink reference signal, and receive a first message, where the first message includes verification information of a second key, and the second key is obtained by the second communication device according to the received first uplink reference signal.
[0277] The processing unit 620 is configured to obtain a first key according to the first downlink reference signal, determine a third key according to verification information of the first key and the second key, and perform security protection on data transmitted between the second communication device and the second communication device according to the third key.
[0278] Optionally, when sending the first uplink reference signal, the transceiver unit 610 is further configured to send a preamble code.
[0279] Optionally, before the transceiver unit 610 receives the first downlink reference signal, the transceiver unit 610 is also used to receive system information, which includes measurement configuration information and quantization configuration information; the processing unit 620 is also used to measure the first downlink reference signal according to the measurement configuration information to obtain a measurement result of the first downlink reference signal, and quantize the measurement result of the first downlink reference signal according to the quantization configuration information to obtain the first key.
[0280] Optionally, the processing unit 620 is also used to determine the alignment of the first key and the second key based on the verification information of the first key and the second key; determine the first key as the third key; or calculate the first key to obtain a fourth key, and determine the fourth key as the third key.
[0281] Optionally, the processing unit 620 is also used to determine that the first key and the second key are not aligned based on verification information of the first key and the second key; the transceiver unit 610 is also used to send a second uplink reference signal on the resources indicated by the first message, and receive a second downlink reference signal; the processing unit 620 is also used to obtain a fifth key based on the second downlink reference signal; the transceiver unit 610 is also used to receive verification information of the sixth key, and determine the third key based on the verification information of the fifth key and the sixth key.
[0282] Optionally, the first message also includes a first redundant version RV of the first coding matrix, and the processing unit 620 is further used to decode the first key according to the first RV of the first coding matrix to obtain a seventh key, and determine the third key according to the seventh key and verification information of the second key.
[0283] Optionally, the processing unit 620 is further configured to determine that the seventh key is aligned with the second key according to verification information of the seventh key and the second key, and determine the seventh key as the third key.
[0284] Optionally, the processing unit 620 is also used to determine that the seventh key and the second key are not aligned based on the verification information of the seventh key and the second key; the transceiver unit 610 is also used to send an RV request message, which is used to request the second RV of the first coding matrix; the processing unit 620 is also used to decode the first key according to the first RV and the second RV of the first coding matrix to obtain an eighth key, determine that the eighth key and the second key are aligned based on the verification information of the eighth key and the second key, and determine the eighth key as the third key.
[0285] Optionally, the first message is a random access response RAR message.
[0286] It should be understood that the processing unit 620 and the transceiver unit 610 may also respectively perform the above Figure 3-Figure 5 For any other steps, operations and / or functions implemented by the first communication device in the method shown, the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and for the sake of brevity, it will not be repeated here.
[0287] In another possible implementation, the device 600 may be Figure 3-Figure 5 The second communication device in the method shown can also be used to implement the above Figure 3-Figure 5 Specifically, the device 600 can implement the function of the second communication device in the method shown above. Figure 3-Figure 5 The process executed by the second communication device in the method shown, wherein the transceiver unit 610 and the processing unit 620 are used to perform operations related to the processing of the second communication device in the above method process.
[0288] The transceiver unit 610 is configured to send a first downlink reference signal, receive a first uplink reference signal, and receive a first message, wherein the first message includes verification information of the second key.
[0289] The processing unit 620 is configured to obtain a second key according to the first uplink reference signal, determine a ninth key according to the second key, and perform security protection on data transmitted with the first communication device according to the ninth key.
[0290] Optionally, the transceiver unit 610 is further configured to receive a preamble code.
[0291] Optionally, the first key and the second key are aligned, and the processing unit 620 is further used to determine the second key as the ninth key; or calculate the second key to obtain the tenth key, and determine the tenth key as the ninth key.
[0292] Optionally, the first key and the second key are not aligned, and the transceiver unit 610 is also used to send a second downlink reference signal and receive a second uplink reference signal on the resources indicated by the first message; the processing unit 620 is also used to obtain a sixth key based on the second uplink reference signal; the transceiver unit 610 is also used to send verification information of the sixth key through the first message; the processing unit 620 is also used to determine the ninth key based on the fifth key and the verification information of the sixth key, and the fifth key is obtained by the first communication device based on the second downlink reference signal.
[0293] Optionally, the processing unit 620 is further configured to determine a first coding matrix according to the second key; and the transceiver unit 610 is further configured to send a first redundancy version RV of the first coding matrix through the first message.
[0294] Optionally, the transceiver unit 610 is further used to receive an RV request message, where the RV request message is used to request a second RV of the first coding matrix; the processing unit 620 is further used to send the second RV of the first coding matrix through the first message according to the RV request message.
[0295] It should be understood that the processing unit 620 and the transceiver unit 610 may also respectively perform the above Figure 3-Figure 5 For any other steps, operations and / or functions implemented by the second communication device in the method shown, the specific process of each unit executing the above corresponding steps has been described in detail in the above method embodiment, and will not be repeated here for the sake of brevity.
[0296] It should also be understood that in any of the above-mentioned implementations, the above-mentioned transceiver unit 610 may include a receiving unit and a sending unit, wherein the receiving unit is used to execute the receiving function in the above-mentioned transceiver unit 610, and the sending unit is used to execute the sending function in the above-mentioned transceiver unit 610.
[0297] The above-mentioned device 600 has the function of realizing Figure 3-Figure 5 The functions of the corresponding steps executed by the first communication device in the method shown in FIG. 1 , or the above-mentioned device 600 has the function of implementing the above-mentioned Figure 3-Figure 5 The functions of the corresponding steps performed by the second communication device in the method shown. The functions can be implemented by hardware, or by hardware executing corresponding software implementations. The hardware or software includes one or more units corresponding to the above functions; for example, the transceiver unit can be replaced by a transceiver (for example, the sending unit in the transceiver unit can be replaced by a transmitter, and the receiving unit in the transceiver unit can be replaced by a receiver), and other units, such as the processing unit, can be replaced by a processor to respectively perform the transceiver operations and related processing operations in each method embodiment.
[0298] It should be understood that the device 600 here is embodied in the form of a functional unit. The term "unit" here may refer to an application specific integrated circuit (ASIC), an electronic circuit, a processor (e.g., a shared processor, a proprietary processor, or a group processor, etc.) and a memory for executing one or more software or firmware programs, a merged logic circuit, and / or other suitable components that support the described functions. In an optional example, those skilled in the art may understand that the device 600 may be specifically the first communication device in the above-mentioned embodiment or a chip applied to the first communication device, and may be used to execute the process corresponding to the first communication device in the above-mentioned method embodiment, or the device 600 may be specifically the second communication device in the above-mentioned embodiment or a chip applied to the second communication device, and may be used to execute the process corresponding to the second communication device in the above-mentioned method embodiment, and to avoid repetition, it will not be described here.
[0299] In addition, the above-mentioned transceiver unit can also be a transceiver circuit (for example, it can include a receiving circuit and a sending circuit), and the processing unit can be a processing circuit. In an embodiment of the present application, the device 600 can be the first communication device or the second communication device in the aforementioned embodiment, or it can be a chip or a chip system, for example: a system on chip (SoC). Among them, the transceiver unit can be an input and output circuit, a communication interface. The processing unit is a processor or a microprocessor or an integrated circuit integrated on the chip. It is not limited here.
[0300] Figure 7 is another schematic structural diagram of a communication device provided in an embodiment of the present application. Figure 7 As shown, the communication device 700 includes: at least one processor 710 and a transceiver 720, the transceiver 720 is used to send signals and / or receive signals, and the processor 710 is used to execute instructions so that the above Figure 3-Figure 5 The function of the first communication device in the method shown is realized, or the above Figure 3-Figure 5 The functionality of the second communication device in the method shown is implemented.
[0301] Optionally, the communication device 700 further includes a memory 730 for storing instructions. The processor 710 is coupled to the memory and is configured to execute the instructions stored in the memory to control the transceiver 7020 to send and / or receive signals.
[0302] It should be understood that the processor 710 and the memory 730 can be combined into one processing device, and the processor 710 is used to execute the program code stored in the memory 730 to implement the above functions. In specific implementation, the memory 730 can also be integrated into the processor 710, or independent of the processor 710.
[0303] It should also be understood that the transceiver 720 may include a receiver (or receiver) and a transmitter (or transmitter). The transceiver 720 may further include an antenna, and the number of antennas may be one or more. The transceiver 720 may also be a communication interface or an interface circuit.
[0304] When the communication device 700 is a chip, the chip includes a transceiver unit and a processing unit, wherein the transceiver unit may be an input / output circuit or a communication interface; and the processing unit may be a processor or a microprocessor or an integrated circuit integrated on the chip.
[0305] The present application also provides a processing device, including a processor and an interface. The processor can implement the method in the above method embodiment.
[0306] It should be understood that the above-mentioned processing device can be a chip. For example, the processing device can be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a micro controller unit (MCU), a programmable logic device (PLD) or other integrated chips.
[0307] In the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in a processor or an instruction in the form of software. The steps of the method disclosed in conjunction with the embodiment of the present application can be directly embodied as a hardware processor for execution, or a combination of hardware and software units in a processor for execution. The software unit can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in a memory, and the processor reads the information in the memory and completes the steps of the above method in conjunction with its hardware. To avoid repetition, it is not described in detail here.
[0308] Figure 8 is another schematic structural diagram of a communication device provided in an embodiment of the present application. Figure 8 As shown, the device 800 includes a processing circuit 810 and a transceiver circuit 820. The processing circuit 810 is used to execute instructions so that the above Figure 3-Figure 5 The function of the first communication device in the method shown is realized, or the above Figure 3-Figure 5 The function of the second communication device in the method shown is realized. The processing circuit 810 and the transceiver circuit 820 communicate with each other through the internal connection path, and the processing circuit 810 can control the transceiver circuit 820 to send signals and / or receive signals.
[0309] Optionally, the device 800 may further include a storage medium 830, which communicates with the processing circuit 810 and the transceiver circuit 820 via an internal connection path. The storage medium 830 is used to store instructions, and the processing circuit 810 may execute the instructions stored in the storage medium 830.
[0310] In a possible implementation manner, the device 800 is used to implement the process corresponding to the first communication device in the above method embodiment.
[0311] In another possible implementation manner, the device 800 is used to implement the process corresponding to the second communication device in the above method embodiment.
[0312] According to the method provided in the embodiment of the present application, the present application also provides a computer program product, which includes instructions. When the instructions are executed by a processor, the above Figure 3-Figure 5 The function of the first communication device in the method shown is realized, or the above Figure 3-Figure 5 The functionality of the second communication device in the method shown is implemented.
[0313] According to the method provided in the embodiment of the present application, the present application also provides a computer-readable storage medium, which includes instructions. When the instructions are executed by the processor, the above Figure 3-Figure 5 The function of the first communication device in the method shown is realized, or the above Figure 3-Figure 5 The functionality of the second communication device in the method shown is implemented.
[0314] According to the method provided in the embodiment of the present application, the present application also provides a system, which includes the aforementioned one or more first communication devices and one or more second communication devices.
[0315] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions may be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (digital subscriber line, DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a high-density digital video disc (DVD)), or a semiconductor medium (eg, a solid state disk (SSD)).
[0316] In the embodiments of the present application, words such as "exemplary" and "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" in the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of the word "exemplary" is intended to present concepts in a concrete way.
[0317] It should be understood that the "embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, the various embodiments in the entire specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner.
[0318] It should be understood that in various embodiments of the present application, the size of the sequence number of each process does not mean the order of execution, and the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application. The names of all nodes and messages in this application are merely names set by this application for the convenience of description. The names in the actual network may be different. It should not be understood that this application limits the names of various nodes and messages. On the contrary, any name with the same or similar function as the node or message used in this application is regarded as the method or equivalent replacement of this application, and is within the scope of protection of this application.
[0319] It should also be understood that in the present application, "when", "if" and "if" all mean that the UE or base station will take corresponding actions under certain objective circumstances. It is not a time limit, and it does not require the UE or base station to make judgments when implementing it, nor does it mean that there are other limitations.
[0320] It should be noted that in the embodiments of the present application, "pre-setting", "pre-configuration", etc. can be implemented by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in a device (for example, a terminal device). The present application does not limit its specific implementation method, such as the preset rules, preset constants, etc. in the embodiments of the present application.
[0321] In addition, the terms "system" and "network" are often used interchangeably in this article. The term "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0322] The term "at least one of..." or "at least one of..." herein refers to all or any combination of the listed items. For example, "at least one of A, B, and C", or "at least one of A, B, or C" may refer to the following six situations: A exists alone, B exists alone, C exists alone, A and B exist at the same time, B and C exist at the same time, and A, B, and C exist at the same time. "At least one" herein refers to one or more. "More than one" refers to two or more.
[0323] It should be understood that in each embodiment of the present application, "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean determining B only according to A, but B can also be determined according to A and / or other information. The terms "include", "comprises", "has" and their variations all mean "including but not limited to", unless otherwise specifically emphasized.
[0324] It should be understood that in various embodiments of the present application, the first, second and various digital numbers are only used for the convenience of description and are not used to limit the scope of the embodiments of the present application. For example, to distinguish different information.
[0325] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0326] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0327] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0328] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0329] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0330] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0331] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A method for data transmission, characterized in that: The method is applied to a first communication device, and the method includes: receiving a first downlink reference signal, and obtaining a first key according to the first downlink reference signal; Sending a first uplink reference signal; receiving a first message, where the first message includes verification information of a second key, where the second key is obtained by the second communication device according to the received first uplink reference signal; Determine a third key according to verification information of the first key and the second key; Data transmitted between the second communication device and the second communication device is securely protected according to the third key.
2. The method according to claim 1, characterized in that When sending the first uplink reference signal, the method further includes: Send preamble.
3. The method according to claim 1 or 2, characterized in that: Before receiving the first downlink reference signal, the method further includes: receiving system information, wherein the system information includes measurement configuration information and quantization configuration information; The obtaining a first key according to the first downlink reference signal comprises: Measuring the first downlink reference signal according to the measurement configuration information to obtain a measurement result of the first downlink reference signal; The measurement result of the first downlink reference signal is quantized according to the quantization configuration information to obtain the first key.
4. The method according to any one of claims 1 to 3, characterized in that The determining the third key according to the verification information of the first key and the second key includes: Determining alignment between the first key and the second key according to verification information of the first key and the second key; The first key is determined as the third key; or the first key is calculated to obtain a fourth key, and the fourth key is determined as the third key.
5. The method according to any one of claims 1 to 3, characterized in that The determining the third key according to the verification information of the first key and the second key includes: determining, according to verification information of the first key and the second key, that the first key and the second key are not aligned; Sending a second uplink reference signal on the resources indicated by the first message; receiving a second downlink reference signal, and obtaining a fifth key according to the second downlink reference signal; receiving verification information of a sixth key, where the sixth key is obtained by the second communication device according to the received second uplink reference signal; The third key is determined according to verification information of the fifth key and the sixth key.
6. The method according to any one of claims 1 to 3, characterized in that The first message also includes a first redundancy version RV of a first coding matrix, where the first coding matrix is determined by the second communication device according to the second key. The determining the third key according to the verification information of the first key and the second key includes: Decoding the first key according to the first RV of the first encoding matrix to obtain a seventh key; The third key is determined according to verification information of the seventh key and the second key.
7. The method according to claim 6, characterized in that The determining the third key according to the verification information of the seventh key and the second key includes: Determining alignment between the seventh key and the second key according to verification information of the seventh key and the second key; The seventh key is determined as the third key.
8. The method according to claim 6, characterized in that The determining the third key according to the verification information of the seventh key and the second key includes: determining, according to verification information of the seventh key and the second key, that the seventh key and the second key are not aligned; Sending an RV request message, where the RV request message is used to request a second RV of the first coding matrix; Receiving a second RV of the first coding matrix; Decoding the first key according to the first RV and the second RV of the first encoding matrix to obtain an eighth key; Determining alignment between the eighth key and the second key according to verification information of the eighth key and the second key; The eighth key is determined as the third key.
9. The method according to any one of claims 1 to 8, characterized in that The first message is a random access response RAR message.
10. A method for data transmission, characterized in that: The method is applied to a second communication device, and the method includes: Sending a first downlink reference signal; receiving a first uplink reference signal, and obtaining a second key according to the first uplink reference signal; Sending a first message, where the first message includes verification information of the second key; determining a ninth key according to the second key; According to the ninth key, data transmitted between the first communication device is securely protected.
11. The method according to claim 10, characterized in that The method further comprises: Broadcasting system information, wherein the system information includes measurement configuration information and quantization configuration information; The obtaining a second key according to the first uplink reference signal includes: Measuring the first uplink reference signal according to the measurement configuration information to obtain a measurement result of the first uplink reference signal; The measurement result of the first uplink reference signal is quantized according to the quantization configuration information to obtain the second key.
12. The method according to claim 10 or 11, characterized in that: The method further comprises: Receive preamble.
13. The method according to any one of claims 10 to 12, characterized in that The first key and the second key are aligned, and determining the ninth key according to the second key includes: The second key is determined as the ninth key; or the second key is calculated to obtain a tenth key, and the tenth key is determined as the ninth key.
14. The method according to any one of claims 10 to 12, characterized in that The first key and the second key are not aligned, and determining the ninth key according to the verification information of the second key and the first key includes: Sending a second downlink reference signal; Receiving a second uplink reference signal on the resources indicated by the first message; Obtaining a sixth key according to the second uplink reference signal; Sending verification information of the sixth key through the first message; The ninth key is determined according to verification information of a fifth key and the sixth key, where the fifth key is obtained by the first communication device according to the second downlink reference signal.
15. The method according to any one of claims 10 to 14, characterized in that The sending of the first message comprises: determining a first encoding matrix according to the second key; A first redundancy version RV of the first coding matrix is sent through the first message.
16. The method according to claim 15, characterized in that The method further comprises: receiving an RV request message, where the RV request message is used to request a second RV of the first coding matrix; A second RV of the first coding matrix is sent through the first message according to the RV request message.
17. The method according to any one of claims 10 to 16, characterized in that The first message is a random access response RAR message.
18. A communication device, characterized in that: The communication device includes a processor and a storage medium, wherein the storage medium stores instructions, and when the instructions are executed by the processor, the method according to any one of claims 1 to 9 is implemented.
19. A communication device, characterized in that: The communication device comprises a processor and a communication interface, wherein the communication interface is used to input and / or output signals, and the processor is used to execute a computer program or instruction so that the method according to any one of claims 1 to 9 is implemented.
20. A communication device, characterized in that: The communication device includes a processor and a storage medium, wherein the storage medium stores instructions. When the instructions are executed by the processor, the method according to any one of claims 10 to 17 is implemented.
21. A communication device, characterized in that: The communication device comprises a processor and a communication interface, wherein the communication interface is used to input and / or output signals, and the processor is used to execute a computer program or instruction so that the method according to any one of claims 10 to 17 is implemented.
22. A communication system, characterized in that: include: The communication device according to claim 18 and / or the communication device according to claim 20, or the communication device according to claim 19 and / or the communication device according to claim 21.
23. A computer-readable storage medium, characterized in that: The computer-readable storage medium comprises instructions, which, when executed by a processor, enable the method according to any one of claims 1 to 9 to be implemented, or enable the method according to any one of claims 10 to 17 to be implemented.
24. A computer program product, characterized in that The computer program product comprises instructions, which, when executed by a processor, enable the method according to any one of claims 1 to 9 to be implemented, or enable the method according to any one of claims 10 to 17 to be implemented.
Citation Information
Cited By
Data transmission method and device
EP4794365A1
Data transmission method and device
WO2025092301A1