Communication method and device

CN119948827APending Publication Date: 2025-05-06HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280100409.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-10-31
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In existing mobile communication systems, the underlying signaling (such as physical layer signaling) of 4G and 5G mobile communication systems lacks security protection. Attackers can eavesdrop and tamper with these signalings, causing service interruption, performance impairment, and consumption of legitimate terminal equipment. Abnormal power supply and abnormal network equipment resource scheduling.

Method used

Random numbers are generated through a random number generator that interacts between terminal equipment and network equipment, which is used to generate physical channel encryption keys, encrypt or decrypt the physical channel, increase the update of scrambling sequences and pilot sequences, and increase the risk of attackers The difficulty of cracking.

Benefits of technology

It improves the security of the underlying signaling transmitted between network equipment and terminal equipment, enhances the security strength against eavesdropping and anti-tampering, and reduces the difficulty of cracking by attackers and the risk of counterfeiting.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119948827A_ABST
    Figure CN119948827A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, discloses a communication method and device, and aims to improve the security of underlying signaling transmitted between network equipment and terminal equipment and enhance the security strength of eavesdropping prevention and tampering prevention of the underlying signaling. The method comprises the steps that the terminal equipment generates at least one random number through a random number generator according to user exclusive parameters of a physical channel from network equipment and set historical messages of interaction between the terminal equipment and the network equipment, and the at least one random number comprises a first random number; the terminal equipment generates a physical channel encryption key through a key generator according to the first random number; and the terminal equipment encrypts or decrypts the physical channel according to the physical channel encryption key.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and device Technical Field

[0001] The embodiments of the present application relate to the field of communication technology, and in particular to a communication method and apparatus. Background Art

[0002] The fifth-generation (5G) mobile communication system is similar to the fourth-generation (4G) mobile communication system in that it features two layers of security, with security mode command activation and security protection performed at the non-access stratum (NAS) and access stratum (AS), respectively. After the terminal device and the network mutually authenticate each other, they negotiate the security algorithms and keys used for encryption and integrity protection of NAS signaling, radio resource control (RRC) signaling, and user data during subsequent communications. After the NAS security algorithm negotiation is complete, NAS signaling between the access and mobility management function (AMF) network element on the network side and the terminal device will be encrypted and integrity protected based on the negotiated security algorithms and keys used for encryption and integrity protection. During the AS security mode command exchange, the network equipment and the terminal device negotiate the security algorithms and keys for AS encryption and integrity protection, and activate encryption and integrity protection of AS RRC signaling and user data.

[0003] However, the above security protection scheme only provides security protection for NAS signaling and RRC signaling. For 4G and 5G mobile communication systems, the packet data convergence protocol (PDCP) layer in the AS layer provides signaling transmission services for the RRC layer and implements encryption and integrity protection of RRC signaling, as well as decryption and integrity verification of RRC signaling in the reverse direction. However, the signaling of the various protocol sublayers below the PDCP layer has no security protection. For example, the physical (PHY) layer and media access control (MAC) layer signaling, such as media access control layer control element (MAC CE), uplink control information (UCI), and downlink control information (DCI), lacks security protection. Attackers can eavesdrop on and tamper with these underlying signaling, which may cause legitimate terminal device service interruption, terminal device service performance impairment, abnormal terminal device power consumption, and abnormal network device resource scheduling.

[0004] Summary of the Invention

[0005] The present application provides a communication method and apparatus to improve the security of underlying signaling transmitted between network devices and terminal devices, and to strengthen the security strength of the underlying signaling against eavesdropping and tampering.

[0006] In a first aspect, an embodiment of the present application provides a communication method, which can be executed by a terminal device, or by a component of the terminal device (such as a processor, a chip, or a chip system, etc.), or by a logic module or software that can realize all or part of the functions of the terminal device. The following is an example of the method being executed by a terminal device. The method includes: the terminal device generates at least one random number through a random number generator based on user-specific parameters of a physical channel from a network device and setting history messages exchanged between the terminal device and the network device, the at least one random number including a first random number; the terminal device generates a physical channel encryption key through a key generator based on the first random number; and the terminal device encrypts or decrypts the physical channel based on the physical channel encryption key.

[0007] Optionally, the physical channel may be a physical downlink control channel (PDCCH), a physical downlink shared channel (PDSCH), a physical uplink control channel (PUCCH), or a physical uplink shared channel (PUSCH), etc.

[0008] Using the above method, a terminal device can extract random numbers based on user-specific parameters of the physical channel from the network device and historical messages exchanged with the network device to generate a physical channel encryption key (e.g., extracting random numbers at a certain period to generate the physical channel encryption key), thereby encrypting or decrypting the physical channel. This can provide protection for the underlying signaling (e.g., physical layer signaling) transmitted between the network device and the terminal device, improving the security of the underlying signaling transmitted between the network device and the terminal device, and strengthening the security of the underlying signaling against eavesdropping and tampering. Furthermore, generating random numbers based on historical messages can increase the difficulty of cracking by attackers and prevent message spoofing and network device identity spoofing.

[0009] In one possible design, at least one random number also includes a second random number, and the method also includes: the terminal device updates the physical channel scrambling sequence corresponding to the physical channel according to the second random number; and the terminal device scrambles or descrambles the physical channel according to the updated physical channel scrambling sequence.

[0010] In the above design, the physical channel scrambling sequence can be updated based on the generated random number (e.g., updated at a certain period), which can increase the difficulty for an attacker to correctly descramble the signal, thereby increasing the computational and time costs for the attacker to eavesdrop on the signaling interacting between the terminal device and the network device.

[0011] In one possible design, at least one random number also includes a third random number, and the method also includes: the terminal device updates the physical channel pilot sequence corresponding to the physical channel according to the third random number; and the terminal device performs resource mapping or channel estimation on the physical channel according to the updated physical channel pilot sequence.

[0012] In the above design, the physical channel pilot sequence can be updated based on the generated random number (e.g., updated at a certain period), which can increase the difficulty for an attacker to correctly estimate the channel, thereby increasing the computational and time costs for the attacker to eavesdrop on the signaling interacting between the terminal device and the network device.

[0013] In one possible design, the method also includes: the terminal device receives a scrambling code-specific parameter of a physical channel from the network device, and the number of bits included in the scrambling code-specific parameter is greater than a first quantity threshold; the terminal device generates a physical channel scrambling sequence corresponding to the physical channel based on the first sub-scrambling code parameter, the first sub-scrambling code parameter is determined by the terminal device according to a first selection rule and the scrambling code-specific parameter, and the number of bits included in the first sub-scrambling code parameter is equal to the first quantity threshold; the terminal device generates a physical channel pilot sequence corresponding to the physical channel based on the second sub-scrambling code parameter, the second sub-scrambling code parameter is determined by the terminal device according to a second selection rule and the scrambling code-specific parameter, and the number of bits included in the second sub-scrambling code parameter is equal to the first quantity threshold.

[0014] In the above design, by increasing the length of the scrambling code-specific parameters, the first sub-scrambling code parameters and the second sub-scrambling code parameters are extracted according to preset rules and used to update the physical channel scrambling sequence and the physical channel pilot sequence. This increases the random space of the scrambling code-specific parameters and increases the difficulty of cracking by attackers.

[0015] In one possible design, the terminal device generates at least one random number through a random number generator based on user-specific parameters of a physical channel from the network device and set historical messages of interaction between the terminal device and the network device, including: the terminal device obtains the set historical message of the most recent interaction with the network device according to a set period; the terminal device generates at least one random number through a random number generator based on user-specific parameters and the set historical message of the most recent interaction.

[0016] In the above design, the terminal device can periodically obtain user-specific parameters and the latest historical messages, generate random numbers, and use them to generate or update physical channel encryption keys, etc. This can further increase the difficulty for attackers to crack physical channel encryption keys, etc., and improve the security of signaling transmission between network devices and terminal devices.

[0017] In one possible design, user-specific parameters of the physical channel are randomly configured by the network device.

[0018] In the above design, the network device randomly configures the user-specific parameters of the physical channel, which can further increase the difficulty for attackers to crack the user-specific parameters, prevent the physical channel encryption keys used by the network device and terminal devices from being cracked, and further improve the security of signaling transmission between the network device and the terminal device.

[0019] In the second aspect, an embodiment of the present application provides a communication method, which can be executed by a network device, or by a component of the network device (such as a processor, a chip, or a chip system, etc.), or by a logic module or software that can realize all or part of the network device functions. The following is an example of the method being executed by a network device. The method includes: the network device generates at least one random number through a random number generator based on user-specific parameters of a physical channel sent to a terminal device, and setting history messages of interaction between the terminal device and the network device, and the at least one random number includes a first random number; the network device generates a physical channel encryption key through a key generator based on the first random number; the network device decrypts or encrypts the physical channel based on the physical channel encryption key.

[0020] Optionally, the physical channel may be PDCCH, PDSCH, PUCCH, or PUSCH, etc.

[0021] In one possible design, at least one random number also includes a second random number, and the method also includes: the network device updates the physical channel scrambling sequence corresponding to the physical channel based on the second random number; and the network device descrambles or scrambles the physical channel based on the updated physical channel scrambling sequence.

[0022] In one possible design, at least one random number also includes a third random number, and the method also includes: the network device updates the physical channel pilot sequence corresponding to the physical channel based on the third random number; and the network device performs channel estimation or resource mapping on the physical channel based on the updated physical channel pilot sequence.

[0023] In one possible design, the method also includes: the network device sends a scrambling code-specific parameter of a physical channel to the terminal device, and the number of bits included in the scrambling code-specific parameter is greater than a first quantity threshold; the network device generates a physical channel scrambling sequence corresponding to the physical channel based on the first sub-scrambling code parameter, the first sub-scrambling code parameter is determined by the network device according to a first selection rule and the scrambling code-specific parameter, and the number of bits included in the first sub-scrambling code parameter is equal to the first quantity threshold; the network device generates a physical channel pilot sequence corresponding to the physical channel based on the second sub-scrambling code parameter, the second sub-scrambling code parameter is determined by the network device according to a second selection rule and the scrambling code-specific parameter, and the number of bits included in the second sub-scrambling code parameter is equal to the first quantity threshold.

[0024] In one possible design, the network device generates at least one random number through a random number generator based on user-specific parameters of a physical channel sent to the terminal device and set historical messages of interaction between the terminal device and the network device, including: the network device obtains the set historical message of the most recent interaction with the terminal device according to a set period; the network device generates at least one random number through a random number generator based on user-specific parameters and the set historical message of the most recent interaction.

[0025] In one possible design, user-specific parameters of the physical channel are randomly configured by the network device.

[0026] In a third aspect, embodiments of the present application provide a communication device having the functionality to implement the method of the first aspect. The functionality may be implemented by hardware or by hardware executing corresponding software. The hardware or software may include one or more modules corresponding to the functionality, such as an interface unit and a processing unit.

[0027] In one possible design, the device may be a chip or an integrated circuit.

[0028] In one possible design, the apparatus includes a processor, which may be coupled to a memory for storing instructions executed by the processor. When the instructions are executed by the processor, the apparatus may perform the method of the first aspect described above. "Coupled" refers to two components being directly or indirectly connected or having some type of communication relationship.

[0029] In one possible design, the device may be a complete terminal device.

[0030] In a fourth aspect, embodiments of the present application provide a communication device having the functionality to implement the method of the second aspect described above. The functionality may be implemented through hardware or through hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the functionality described above, such as an interface unit and a processing unit.

[0031] In one possible design, the device may be a chip or an integrated circuit.

[0032] In one possible design, the apparatus includes a processor, which may be coupled to a memory for storing instructions executed by the processor. When the instructions are executed by the processor, the apparatus may perform the method of the second aspect described above. "Coupled" refers to two components being directly or indirectly connected or having some type of communication relationship.

[0033] In one possible design, the device may be a complete network device.

[0034] In a fifth aspect, an embodiment of the present application provides a communication device, comprising an interface circuit and a processor, wherein the processor and the interface circuit are coupled to each other. The processor implements the method of the first aspect described above through a logic circuit or execution instructions. The interface circuit is configured to receive signals from other communication devices outside the communication device and transmit them to the processor, or to transmit signals from the processor to other communication devices outside the communication device. It is understood that the interface circuit may be a transceiver, a transceiver, a transceiver, or an input / output interface.

[0035] Optionally, the communication device may further include a memory for storing instructions executed by the processor, or storing input data required by the processor to execute instructions, or storing data generated after the processor executes instructions. The memory may be a physically independent unit, or may be coupled to the processor, or the processor may include the memory.

[0036] In a sixth aspect, an embodiment of the present application provides a communication device, comprising an interface circuit and a processor, wherein the processor and the interface circuit are coupled to each other. The processor implements the method of the second aspect described above through a logic circuit or execution instructions. The interface circuit is configured to receive signals from other communication devices outside the communication device and transmit them to the processor, or to transmit signals from the processor to other communication devices outside the communication device. It is understood that the interface circuit may be a transceiver, a transceiver, a transceiver, or an input / output interface.

[0037] Optionally, the communication device may further include a memory for storing instructions executed by the processor, or storing input data required by the processor to execute instructions, or storing data generated after the processor executes instructions. The memory may be a physically independent unit, or may be coupled to the processor, or the processor may include the memory.

[0038] In a seventh aspect, an embodiment of the present application provides a communication system, which includes a terminal device and a network device. The terminal device can implement the method of the first aspect above, and the network device can implement the method of the second aspect above.

[0039] In an eighth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program or instruction is stored. When the computer program or instruction is executed by a processor, the method of the first or second aspect mentioned above can be implemented.

[0040] In the ninth aspect, an embodiment of the present application further provides a computer program product, including a computer program or instructions, which, when executed by a processor, can implement the method of the first or second aspect above.

[0041] In the tenth aspect, an embodiment of the present application also provides a chip system, which includes a processor, the processor is used to couple with a memory, and the memory is used to store programs or instructions. When the program or instruction is executed by the processor, the method of the first or second aspect mentioned above can be implemented.

[0042] The technical effects that can be achieved in the above-mentioned second to tenth aspects can refer to the technical effects that can be achieved in the above-mentioned first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] FIG1 is a schematic diagram of the architecture of a communication system provided in an embodiment of the present application;

[0044] FIG2 is a schematic diagram of a 5G NR control plane protocol stack provided in an embodiment of the present application;

[0045] FIG3 is a schematic diagram of a signaling interaction process between a terminal device and a network device and a core network during the access phase according to an embodiment of the present application;

[0046] FIG4 is a process for an attacker to eavesdrop on PDCCH resource configuration and forge DCI according to an embodiment of the present application;

[0047] FIG5 is a schematic diagram of a communication method provided in an embodiment of the present application;

[0048] FIG6 is a schematic diagram of scrambling code ID allocation according to an embodiment of the present application;

[0049] FIG7 is a schematic diagram of a measurement report provided in an embodiment of the present application;

[0050] FIG8 is a schematic diagram of an encryption key generation process according to an embodiment of the present application;

[0051] FIG9 is a schematic diagram of one of the scrambled ID access rules provided in an embodiment of the present application;

[0052] FIG10 is a second schematic diagram of scrambled ID access rules provided in an embodiment of the present application;

[0053] FIG11 is a third schematic diagram of scrambled ID access rules provided in an embodiment of the present application;

[0054] FIG12 is a schematic diagram of a collision of scrambling code-specific parameters provided in an embodiment of the present application;

[0055] FIG13 is a schematic diagram of enhanced PDCCH security protection provided by an embodiment of the present application;

[0056] FIG14 is a schematic diagram of physical layer PDCCH encryption provided in an embodiment of the present application;

[0057] FIG15 is a schematic diagram of constellation phase rotation encryption provided in an embodiment of the present application;

[0058] FIG16 is a schematic diagram of data and pilot subcarrier confusion interleaving encryption provided in an embodiment of the present application;

[0059] FIG17 is a schematic diagram of enhanced PDSCH security protection provided by an embodiment of the present application;

[0060] FIG18 is a schematic diagram of enhanced PUSCH security protection provided by an embodiment of the present application;

[0061] FIG19 is a schematic diagram of a structure of a communication device according to an embodiment of the present application;

[0062] FIG20 is a second structural diagram of the communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0063] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as the fourth generation (4G) mobile communication system, the fifth generation (5G) new radio (NR) mobile communication system, etc. The technical solutions provided by the present application can also be applied to future communication systems, such as the sixth generation mobile communication system. The communication system can also be an Internet of Things (IoT) network or other network.

[0064] The architecture of the communication system used in the embodiment of the present application can be shown in Figure 1. The communication system includes a wireless access network 100 and a core network 200. Optionally, the communication system may also include the Internet 300. The wireless access network 100 may include at least one network device, such as 110a and 110b in Figure 1, and may also include at least one terminal device, such as 120a-120j in Figure 1. 110a is a base station, 110b is a micro station, 120a, 120e, 120f, and 120j are mobile phones, 120b is a car, 120c is a gas pump, 120d is a home access point (HAP) arranged indoors or outdoors, 120g is a laptop, 120h is a printer, and 120i is a drone. The same terminal device or network device can provide different functions in different application scenarios. For example, in FIG1 , there are mobile phones 120 a , 120 e , 120 f , and 120 j . Mobile phone 120 a can access base station 110 a , connect to car 120 b , communicate directly with mobile phone 120 e , and access HAP. Mobile phone 120 b can access HAP and communicate directly with mobile phone 120 a . Mobile phone 120 f can be connected as micro station 110 b , connect to laptop computer 120 g , and connect to printer 120 h . Mobile phone 120 j can control drone 120 i .

[0065] Wireless communication is carried out between the terminal device and the network device, and the network device is connected to the core network (such as the evolved packet core (EPC) of the 4G mobile communication system, the core network (5G core, 5GC) of the 5G mobile communication system, etc.). The core network device and the network device can be independent and different physical devices, or the functions of the core network device and the logical functions of the network device can be integrated on the same physical device, or the functions of some core network devices and some network devices can be integrated on one physical device. Terminal devices and terminal devices, as well as network devices and network devices, can be connected to each other by wire or wireless means. Figure 1 is only a schematic diagram, and the communication system can also include other devices, such as wireless relay devices and wireless backhaul devices, which are not drawn in Figure 1.

[0066] Network equipment, also known as wireless access network equipment, may be a base station, an evolved NodeB (eNodeB), a Node B, a transmission reception point (TRP), an access point, a base station transceiver, a transceiver function, a wireless transceiver, a basic service set (BSS), an extended service set (ESS), a next generation NodeB (gNB) in a fifth generation (5G) mobile communication system, a base station in a future mobile communication system, or an access node in a WiFi system; it may also be a module or unit that performs part of the functions of a base station, for example, a centralized unit (CU) or a distributed unit (DU). The CU here completes the functions of the radio resource control protocol and the packet data convergence protocol (PDCP) of the base station, and can also complete the function of the service data adaptation protocol (SDAP); the DU completes the functions of the radio link control layer and the medium access control (MAC) layer of the base station, and can also complete the functions of part of the physical layer or all of the physical layer. For the specific description of the above-mentioned protocol layers, please refer to the relevant technical specifications of the 3rd Generation Partnership Project (3GPP). The network device can be a macro base station (such as 110a in Figure 1), a micro base station or an indoor station (such as 110b in Figure 1), a relay node or a donor node, etc. The embodiments of the present application do not limit the specific technology and specific device form adopted by the network device.

[0067] The network device can perform one or more of the following functions: user data and control signaling transmission, user data or air interface signaling encryption and decryption, integrity protection, header compression, mobile control functions (e.g., handover, dual connectivity), inter-cell interference coordination, connection establishment and release, load balancing, NAS message distribution, NAS node selection, synchronization, paging, positioning and transmission of warning information, wireless access network (RAN) sharing, multimedia broadcast multicast service (MBMS), user and device tracking, RAN information management (RIM), etc. Multiple network devices can communicate directly or indirectly through the backhaul network (X2, Xn interface). The network device can communicate with the terminal device wirelessly and provide the terminal device with an access point to the EPC or 5GC core network. Each network device can provide communication services for terminal device users within the corresponding geographical coverage area.

[0068] A terminal device may also be referred to as a terminal, user equipment (UE), station, mobile station, subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, user agent, mobile client, client, etc. Terminal devices can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), IoT, virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearable, smart transportation, smart city, etc. Terminal devices can be cellular phones, mobile phones, Session Initiation Protocol (SIP) phones, tablets, computers with wireless transceiver capabilities, personal digital assistants (PDAs), wearable devices, vehicles, drones, helicopters, airplanes, ships, robots, robotic arms, smart home devices, healthcare devices, etc. It can also be an IoT device such as a parking meter, a smart meter, a gas pump, a vehicle, a heart monitor, etc. The embodiments of this application do not limit the specific technology and specific device form used by the terminal device.

[0069] Network devices and terminal devices can be fixed or mobile. They can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; on water; and in the air on aircraft, balloons, and satellites. The embodiments of this application do not limit the application scenarios of network devices and terminal devices.

[0070] Network devices and terminal devices, network devices and network devices, and terminal devices and terminal devices can communicate through authorized spectrum, unauthorized spectrum, or both; can communicate through spectrum below 6 gigahertz (GHz), spectrum above 6 GHz, or spectrum below 6 GHz and spectrum above 6 GHz simultaneously. The embodiments of the present application do not limit the spectrum resources used for wireless communications.

[0071] In the embodiments of the present application, the functions of the network device may also be performed by a module (such as a chip) in the network device, or by a control subsystem that includes the network device functions. The control subsystem that includes the network device functions here may be a control center in the above-mentioned application scenarios such as smart grid, industrial control, smart transportation, and smart city. The functions of the terminal device may also be performed by a module (such as a chip or a modem) in the terminal device, or by a device that includes the terminal device functions.

[0072] In this application, a network device sends a downlink signal or downlink information to a terminal device, and the downlink information is carried on a downlink channel. A terminal device sends an uplink signal or uplink information to a network device, and the uplink information is carried on an uplink channel. In order to communicate with the network device, the terminal device needs to establish a wireless connection with the cell controlled by the network device. The cell with which the terminal device has established a wireless connection is called the serving cell of the terminal device. When the terminal device communicates with the serving cell, it will also be interfered with by signals from neighboring cells.

[0073] The control plane protocol stack of 5G NR is the same as the control plane protocol stack of 4G long term evolution (LTE). Figure 2 is a schematic diagram of a control plane protocol stack of 5G NR provided in an embodiment of the present application. As shown in Figure 2, it includes a physical (PHY) layer (also called L1 layer), a media access control (MAC) layer, a radio link control (RLC) layer, a packet data convergence protocol (PDCP) layer, a radio resource control (RRC) layer and a non-access stratum (NAS), where the layers other than the NAS layer can be called the access stratum (AS). On the terminal device side, all protocol stacks are located in the terminal device; on the network side, the NAS layer is not located on the network device, but on the AMF entity of the core network.

[0074] Referring to the signaling interaction flow diagram of the terminal device with the network device and the core network during the access phase as shown in Figure 3, the terminal device first performs cell selection in the initial access phase, then performs random access to establish a connection with the network device, and then completes the RRC connection establishment. The terminal device then performs two-way identity authentication with the core network (such as the AMF entity of the core network), and after successful authentication, the NAS and AS layer key derivation and negotiation are enabled. Before NAS security and AS security mode are completed (SecurityModeComplete), all air interface signaling is without any security protection, including RRC signaling and NAS signaling. After NAS security and AS security are completed, encryption and integrity protection can be enabled for RRC, NAS signaling, and user plane data.

[0075] However, the above security protection scheme only provides security protection for NAS signaling and RRC signaling. For 4G and 5G mobile communication systems, the PDCP layer in the AS layer provides signaling transmission services for the RRC layer, implementing encryption and integrity protection for RRC signaling, as well as decryption and integrity verification of RRC signaling in the reverse direction. However, signaling at the various protocol sublayers below the PDCP layer is not protected in any way. For example, PHY and MAC layer signaling such as MAC CE, UCI, and DCI lacks security protection. Attackers can eavesdrop on and tamper with these underlying signaling to counterfeit them, potentially leading to legitimate terminal device service interruptions, impaired terminal device service performance, abnormal terminal device power consumption, and abnormal network device resource scheduling.

[0076] Taking DCI as an example, DCI, as a message carried by PDCCH, has no security protection. Attackers can eavesdrop and tamper with the message to forge it, which may cause legitimate terminal device service interruption, terminal device service performance damage, abnormal terminal device power consumption, abnormal network device resource scheduling, and other problems. Assuming the network device is a base station and the terminal device is a UE, the process of an attacker eavesdropping on PDCCH resource configuration and forging DCI can be shown in Figure 4, including:

[0077] S401: The attacker monitors the master information block (MIB) sent by the legitimate base station on the physical broadcast channel (PBCH) and obtains the cell parameters control resource set (CORESET) 0 and search space (SearchSpace) 0 in the MIB. The physical cell identifier (PCI) can be carried in the MIB.

[0078] S402: The attacker monitors the DCI of system information block (SIB) 1 in PDCCH CORESET0 and SearchSpace0, and obtains information such as the time-frequency resource location of SIB1. The attacker then monitors SIB1 on the physical downlink shared channel (PDSCH) and obtains the information element RACH-ConfigCommon in SIB1, which indicates the configuration of the random access channel (RAC) time-frequency resources / preamble / response window. Based on these parameters, the attacker calculates the possible values ​​of the random access-radio network temporary identifier (RA-RNTI) (used to receive random access message 2 (Msg2)).

[0079] S403: The attacker uses RA-RNTI to monitor Msg2 and obtains the temporary cell RNTI (TC-RNTI) carried in Msg2.

[0080] S404: The attacker uses the TC-RNTI to monitor Random Access Message 4 (Msg4) and obtains user-level parameters such as the bandwidth part (BWP) 0 in Msg4, including the CORESET / Searchspace. After the UE successfully competes for random access, the TC-RNTI is upgraded to the cell radio network temporary identifier (C-RNTI). By monitoring, the attacker can obtain the C-RNTI assigned to the user by the legitimate base station.

[0081] S405: The legitimate base station sends an encrypted RRC reconfiguration message (RRC reconfiguration), in which the user-level CORESET and SearchSpace parameters may be the same as those sent in plain text in Msg4.

[0082] S406: Optionally, the attacker continues to monitor the key DCI sent by the legitimate base station, performs multiple blind detections, and further guesses the parameter configurations of the user-level CORESET and SearchSpace.

[0083] S407: Based on the user-level CORESET and SearchSpace parameters obtained in the previous steps, the attacker forges the key DCI.

[0084] In the above process, the DCI format includes downlink PDSCH scheduling, uplink PUSCH scheduling, time slot format indication, resource preemption indication, transmission power control, sidelink scheduling, and multicast broadcast services (MBS) scheduling. For details on different DCI formats, refer to Section 7.3.1 of TS 38.212 of the 3rd Generation Partnership Project (3GPP) standard.

[0085] PDCCH SearchSpace is divided into public SearchSpace and UE-specific SearchSpace. Public SearchSpace is mainly used to transmit scheduling DCI for system information, random access response (RAR), paging messages, etc. UE-specific SearchSpace is mainly used to transmit user-specific information, such as uplink and downlink user data scheduling, uplink (UL) grants, etc. For public SearchSpace, attackers can determine the location of public SearchSpace through the cell-common parameters sent by the legitimate base station, thereby carrying out interference, counterfeiting and tampering attacks on legitimate UEs. For UE-specific SearchSpace, it is mainly sent by Msg4 and RRC reconfiguration messages. If the information element parameters of the UE-specific CORESET and SearchSpace sent by the RRC reconfiguration message are exactly the same or partially the same as those of Msg4, the attacker will perform blind detection on the UE-specific DCI sent by the legitimate base station and guess the information element parameters of the UE-specific CORESET and SearchSpace, which will make it easy for the attacker to interfere, counterfeit and tamper with the legitimate UE.

[0086] An attacker can forge the P-RNTI-scrambled DCI format 1_0 at the paging occasion (PO) position. This DCI contains a short message indicating a system message change. Combined with the tampered system message, the legitimate UE's calling and called services can be further banned. The attacker can also forge the DCI instruction of the PDCCH order based on the C-RNTI, causing the legitimate UE to continuously initiate random access and be unable to obtain normal network services. The attacker can also monitor the DCI activation instruction of UL grant type (type) 2 issued by the legitimate base station, and obtain UE-specific parameters such as the configured scheduling RNTI (CS-RNTI) and user-level CORESET / SearchSpace through multiple blind detections. The attacker can then forge the DCI deactivation instruction, making it impossible for the user to use the unauthorized scheduling resources, resulting in the UE being unable to achieve the short-latency performance indicators.

[0087] An attacker can obtain the public CORESET and SearchSpace by eavesdropping on the MIB, SIB1, Msg2, and Msg4. They can also obtain the user-specific CORESET and SearchSpace of BWP0 sent in the plaintext Msg4, and can also obtain temporary identifiers such as the C-RNTI of the legitimate user. This allows them to forge and tamper with key DCI signaling. Although the RRC reconfiguration message with encryption and integrity protection will re-send the user-specific CORESET and SearchSpace, if the RRC reconfiguration and the user-specific CORESET and SearchSpace of Msg4 have some of the same parameters, such as the PDCCH demodulation reference signal (DMRS) scrambling ID (pdcch-DMRS-ScramblingID), it will also allow attackers to easily crack the user-specific DCI with relatively little time and cost. Attackers can also impersonate legitimate UEs to access the base station and obtain user-specific CORESET and SearchSpace configurations. If multiple users under the same base station have many identical CORESET and SearchSpace parameter configurations, such as the frequency domain resources (FrequencyDomainResources) in the CORESET information element, it will be easy for attackers to crack and impersonate DCI sent to other UEs.

[0088] In view of this, the present application provides a communication method and apparatus to improve the security of underlying signaling transmitted between network devices and terminal devices, and to strengthen the security strength of the underlying signaling against eavesdropping and tampering. The embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0089] Furthermore, it should be understood that ordinal numbers such as "first" and "second" in the embodiments of this application are used to distinguish between multiple objects and are not used to define the size, content, order, timing, priority, or importance of the multiple objects. For example, a first random number and a second random number do not indicate a difference in priority or importance between the two random numbers.

[0090] In the embodiments of the present application, the number of nouns, unless otherwise specified, means "singular noun or plural noun", that is, "one or more". "At least one" means one or more, and "plural" means two or more. "And / or" describes the association relationship of associated objects, indicating that there may be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. For example, A / B means: A or B. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c means: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, c can be single or multiple.

[0091] Figure 5 is a schematic diagram of a communication method provided by an embodiment of the present application. In Figure 5, the method is schematically illustrated using a terminal device and a network device as the execution subjects. Among them, the present application does not limit the execution subject of the method. For example: the terminal device in Figure 5 can also be a chip, a chip system, or a processor that can support the terminal device to implement the method, or a logic module or software that can implement all or part of the terminal device functions; the network device in Figure 5 can also be a chip, a chip system, or a processor that supports the network device to implement the method, or a logic module or software that can implement all or part of the network device functions. In addition, Figure 5 is introduced using the physical channel PDCCH as an example. It can be understood that the physical channel can also be PDSCH, PUCCH, or PUSCH, etc. The method includes:

[0092] S501: The terminal device generates at least one random number through a random number generator according to user-specific parameters of a PDCCH from a network device and setting history messages exchanged between the terminal device and the network device, where the at least one random number includes a first random number.

[0093] In an embodiment of the present application, the user-specific parameters of the PDCCH sent by the network device to the terminal device may be information element parameters such as the PDCCH scrambling code ID (such as pdcch-DMRS-ScramblingID) and the time-frequency resource information of the user-level CORESET / SearchSpeace sent by the network device to the terminal device through the RRC reconfiguration message. Optionally, in order to prevent an attacker from knowing the user-specific parameters of the PDCCH, the user-specific parameters of the PDCCH sent by the network device to the terminal device are not the same as the user-specific parameters of the PDCCH sent by the network device in plain text, and are randomly configured by the network device to increase the randomness and unpredictability of the user-specific parameters of the PDCCH sent by the network device to the terminal device. For example: when the user-specific parameter of PDCCH is the pdcch-DMRS-ScramblingID in the RRC reconfiguration message, the value of the pdcch-DMRS-ScramblingID in the RRC reconfiguration message is different from the pdcch-DMRS-ScramblingID in the random access message (Msg4) sent by the network device, and is randomly configured by the network device to increase the randomness and unpredictability of the pdcch-DMRS-ScramblingID to prevent it from being obtained or predicted by attackers.

[0094] Taking the user-specific parameter of PDCCH as the pdcch-DMRS-ScramblingID sent by the network device through the RRC reconfiguration message as an example, the pdcch-DMRS-ScramblingID is related to the generation of the PDCCH scrambling sequence and the PDCCH pilot sequence (such as the PDCCH DMRS sequence). In order to avoid confusion of DCI sent to different terminal devices in the cell, it is necessary to ensure that the PDCCH scrambling sequence and the PDCCH pilot sequence of different terminal devices in the same cell will not collide at the same time. Usually, when deploying cells, physical shared channel (PSCH) mod 3 interference of different cells is avoided, that is, cells with the same physical cell identifier (PCI) mod 3 are generally not deployed together.

[0095] To ensure the randomness and unpredictability of the pdcch-DMRS-ScramblingID in the RRC reconfiguration message, the network device can configure the pdcch-DMRS-ScramblingID as follows. Currently, the pdcch-DMRS-ScramblingID in the 3GPP standard is 16 bits long and has a value space of 65536. The network device can first remove the pdcch-DMRS-ScramblingID set used in the plaintext Msg4 configuration, taking 4800 as an example. The remaining pdcch-DMRS-ScramblingID value set is then divided into three groups according to PCI modulo 3, which is equal to 0, 1, and 2. The number of pdcch-DMRS-ScramblingIDs in each group is floor(65536-4800) / 3=24245, where floor represents rounding down. In each cell of the network device, the corresponding pdcch-DMRS-ScramblingID value set is selected according to its own PCI mode 3 to allocate pdcch-DMRS-ScramblingID values ​​to users in this cell. And try to keep the allocation random. As shown in the scrambling code ID (such as pdcch-DMRS-ScramblingID) allocation diagram in Figure 6, the network device can periodically randomly scramble the unassigned scrambling code ID queue of the cell where the terminal device is located, and take it out from the head of the queue when sending a new scrambling code ID to the user through the RRC reconfiguration message. After the user RRC connection is released, the corresponding scrambling code ID is put back to the end of the queue.

[0096] The historical messages exchanged between the terminal device and the network device can be historical messages sent by the terminal device to the network device, which the network device acknowledges receipt of; or messages sent by the network device to the terminal device, which the terminal device acknowledges receipt of. For example, these can be measurement values ​​in a measurement report (MR) in RRC signaling reported by the terminal device to the network device, or NAS messages, such as dedicated NAS messages that transmit UE-specific NAS layer signaling.

[0097] Taking the setting history message of the interaction between the terminal device and the network device as the L3 layer measurement value in the measurement report as an example, the measurement objects are the service cell and the neighboring cell, and the measurement values ​​include the beam measurement values ​​of the service cell and the neighboring cell (such as beam ID, reference signal receiving power (RSRP), reference signal receiving quality (RSRQ), signal to interference plus noise ratio (SINR), etc.). The network device can configure the measurement report as periodic feedback. When generating a random number, the setting history message used by the terminal device or the network device is the setting history message of the most recent interaction obtained by the terminal device or the network device according to the set period (such as the period configured by the network device). As shown in Figure 7, the measurement values ​​in the L3RRC signaling MR measurement report may include RSRP, RSRQ, SINR at the cell level (such as the terminal device service cell) and RSRP, RSRQ, SINR at the beam level (such as one or more beams corresponding to the terminal device service cell).

[0098] Taking the L1 layer measurement value in the measurement report as an example, the setting history message exchanged between the terminal device and the network device is used. The measurement object is the serving cell of the terminal device. The measurement value (i.e., the measurement feedback amount) includes the channel measurement amount of the serving cell (including precoding matrix indication (PMI), channel quality indicator (CQI), rank indication RI, etc.) and beam measurement amount (such as beam ID and corresponding RSRP, etc.). The L1 measurement feedback amount typically includes frequency domain subband-level measurement information, which provides richer feedback information and a shorter feedback cycle, making it difficult for attackers to eavesdrop and track.

[0099] A random number generator, which can be called a randomness extractor, can use a hash algorithm, a deterministic random bit generator (DRBG), a one-way hash algorithm deterministic random bit generator (Hash-DRBG), a hash-based message authentication code DRBG (HMAC-DRBG), a counter mode deterministic random bit generator (CTR_DRBG), etc., among which DRBG is also called a pseudo random number generator (PRNG).

[0100] After obtaining the user-specific parameters of the PDCCH from the network device and the setting history messages exchanged between the terminal device and the network device, the terminal device can generate at least one random number through a random number generator based on the user-specific parameters and the setting history messages.

[0101] S502: The terminal device generates a PDCCH encryption key through a key generator according to the first random number.

[0102] In an embodiment of the present application, the key generator may use a cryptographic key derivation algorithm, or a chaotic mathematical model, etc. to derive (or generate) the PDCCH encryption key.

[0103] As an example, the key generator may employ a password-based key derivation function 2 (PBKDF2), a scrypt key derivation algorithm, or a relatively faster key-based key derivation function (KBKDF) algorithm, such as the counter-mode KDF, feedback-mode KDF, and dual-line superposition-based KDF algorithms mentioned in SP800 (SP800 is a series of information security guidelines published by the National Institute of Standards and Technology (NIST)). As shown in FIG8 , when a PDCCH encryption key is generated using a key derivation algorithm, two random numbers generated by a random number generator (e.g., two first random numbers used to generate the PDCCH encryption key) may be used as key material (key): Q and a salt value (salt): P, respectively, and input into the key derivation algorithm to generate the PDCCH encryption key.

[0104] As another example: the key generator can adopt a mathematical model such as chaotic distribution, use one or more first random numbers output by the random number generator for generating the PDCCH encryption key as chaotic parameters according to certain combination rules, and generate a "long random chaotic sequence x" based on chaotic mapping. The length of the long random chaotic sequence can support different physical layer encryption keys for each signaling within the PDCCH encryption key update period. For example, assuming the update period is 20ms, there are a total of 40 time slots, and each slot requires 5000 constellation points for physical layer encryption, then the length of the long random chaotic sequence that can be generated is 200000=40*5000, so that the physical layer encryption key used in each slot is different. Among them, the mathematical model such as chaotic distribution can be a chaotic logic (logistic) model, a chaotic Chebyshev (Chebyshev) model, etc.

[0105] 1) Using a chaotic logistic model, we can set y0 = P (chaos initial value = first random number 1) and μ = Q (bifurcation parameter = first random number 2). The value of the element (x) in the long random chaotic sequence can be determined as the PDCCH encryption key using the following formula, where x ranges from -1 to 1.

[0106] y n+1 =μ*y n (1-y n ),y∈(0.0,1.0),3.569945672<μ≤4.0;

[0107] x=1-2*y,x∈(-1.0,1.0).

[0108] 2) Using the chaotic Chebyshev model, you can choose to set x0 = P (chaos initial value = the first random number 1), μ = Q (bifurcation parameter = the first random number 2). The following formula can be used to determine the value of each element (x n+1 ) value as the PDCCH encryption key.

[0109] x n+1 = cos(μ*cos -1 (x n )),x∈(-1.0,1.0),2.0<μ

[0110] It is understandable that the terminal device can periodically generate PDCCH encryption keys according to the key generation cycle and update the PDCCH encryption keys used to improve security. In some implementations, in order to avoid duplication of the generated PDCCH encryption keys, the terminal device can also add anti-replay information when generating the PDCCH encryption key through the key generator, where the anti-replay information can be the transmission frequency, PCI, timestamp, etc., where the timestamp can be the time domain information such as the system frame number and slot number when the PDCCH encryption key is updated. The terminal device can also use the anti-replay information as the input of the key generator, such as splicing the anti-replay information with the salt value: P as a new salt value: P; the anti-replay information can also be spliced ​​with the PDCCH encryption key output by the key generator to obtain a new PDCCH encryption key, etc.

[0111] S503: The terminal device decrypts the PDCCH according to the PDCCH encryption key. Conversely, the network device encrypts the PDCCH according to the PDCCH encryption key.

[0112] In an embodiment of the present application, the network device can generate the PDCCH encryption key in a similar manner to the terminal device. The specific process of generating the PDCCH encryption key can refer to the implementation on the terminal device side and will not be repeated here.

[0113] After the terminal device and the network device determine the PDCCH encryption key, they can encrypt and decrypt the PDCCH based on the PDCCH encryption key. For example, the network device can encrypt the PDCCH (such as the DCI carried by the PDCCH) using the PDCCH encryption key, and the terminal device can also decrypt the PDCCH using the PDCCH encryption key, thereby providing protection for the PDCCH (such as the DCI carried by the PDCCH).

[0114] In some embodiments, the number of bits of the scrambling code-specific parameters (such as pdcch-DMRS-ScramblingID, etc.) of the PDCCH sent by the network device to the terminal device can be increased, thereby increasing the random space of the user-specific parameters and making it more difficult for an attacker to crack the PDCCH.

[0115] Taking the PDCCH scrambling code-specific parameter pdcch-DMRS-ScramblingID as an example, the bit length of the information element parameter pdcch-DMRS-ScramblingID contained in the CORESET in the current 3GPP standard is 16 bits. In an embodiment of the present application, 16 bits can be used as the first threshold, and the number of pdcch-DMRS-ScramblingID bits can be increased so that the length of pdcch-DMRS-ScramblingID is greater than the first threshold, such as 24, 28 or 32 bits. The pdcch-DMRS-ScramblingID is used for PDCCH scrambling sequence generation and PDCCH pilot sequence generation at the physical layer. When the length of the pdcch-DMRS-ScramblingID is increased, in an embodiment of the present application, selection rules for the pdcch-DMRS-ScramblingID value can be configured for the PDCCH scrambling sequence and the PDCCH pilot sequence respectively, for the generation of the PDCCH scrambling sequence and the PDCCH pilot sequence. For example: the first selection rule for the PDCCH scrambling sequence configuration may be to select the first 16 bits or the last 16 bits of the pdcch-DMRS-ScramblingID, and the second selection rule may be to select the last 16 bits or the first 16 bits of the pdcch-DMRS-ScramblingID, etc., wherein the first selection rule and the second selection rule may be the same or different.

[0116] Taking the pdcch-DMRS-ScramblingID length of 32 bits as an example, as shown in Figure 9, the first selection rule may be to select the first 16 bits of the pdcch-DMRS-ScramblingID as the first sub-scrambling code parameter for use in generating the PDCCH scrambling sequence, and the second selection rule may be to select the last 16 bits of the pdcch-DMRS-ScramblingID as the second sub-scrambling code parameter for use in generating the PDCCH pilot sequence (such as the PDCCH DMRS sequence). As shown in Figure 10, the first selection rule may be to select the last 16 bits of the pdcch-DMRS-ScramblingID as the first sub-scrambling code parameter for use in generating the PDCCH scrambling sequence, and the second selection rule may be to select the first 16 bits of the pdcch-DMRS-ScramblingID as the second sub-scrambling code parameter for use in generating the PDCCH pilot sequence (such as the PDCCH DMRS sequence). As shown in Figure 11, the first selection rule may be to divide the pdcch-DMRS-ScramblingID into multiple small blocks according to M bits (M may be 2, 4, 6, 8, etc.). For example, when M=4, the pdcch-DMRS-ScramblingID is divided into 8 small blocks, each with 4 bits, where the even index blocks are recombined into 16 bits as the first sub-scrambling code parameter for generating the PDCCH scrambling sequence. The second selection rule may be to divide the pdcch-DMRS-ScramblingID into multiple small blocks according to M bits (M may be 2, 4, 6, 8, etc.), where the odd index blocks are recombined into 16 bits as the second sub-scrambling code parameter for generating the PDCCH pilot sequence (such as the PDCCH DMRS sequence).

[0117] As an example: the PDCCH scrambling sequence may be a pseudo-random sequence, and the initialization of the PDCCH scrambling sequence generation may be as follows:

[0118]

[0119] The first sub-scrambling code parameter n ID :For terminal device-specific search space, if the high-level parameter pdcch-DMRS-ScramblingID is configured, then n ID∈{0,1,…,65535} is equal to the first 16 bits of the higher-level parameter pdcch-DMRS-ScramblingID; for the case where the RNTI whose PDCCH cyclic redundancy check (CRC) is scrambled in the common search space is G-RNTI, G-CS-RNTI, or MCCH-RNTI, if the higher-level parameter pdcch-DMRS-ScramblingID is configured on the common MBS frequency domain resources, n ID ∈{0,1,…,65535}∈{0,1,…,65535} is equal to the first 16 bits of the higher-layer parameter pdcch-DMRS-ScramblingID.

[0120] n RNTI :If the high-level parameter pdcch-DMRS-ScramblingID is configured, n RNTI Equal to the C-RNTI in the search space, otherwise n RNTI =0.

[0121] c init : Indicates the initialization value of the PDCCH scrambling sequence.

[0122] Among them, the above is introduced based on the first selection rule of selecting the first 16 bits of the pdcch-DMRS-ScramblingID as the first sub-scrambling code parameter as an example. It can be understood that the first selection rule is not limited to selecting the first 16 bits of the pdcch-DMRS-ScramblingID as the first sub-scrambling code parameter, and can also be selecting the last 16 bits of the pdcch-DMRS-ScramblingID as the first sub-scrambling code parameter.

[0123] PDCCH pilot sequence (such as PDCCH DMRS sequence) l (m) is generated as follows:

[0124]

[0125] Among them, the pseudo-random sequence c(i) is initialized (c init )as follows:

[0126]

[0127] l is the OFDM symbol index in the slot, It is the slot index number in the system frame, and j is an imaginary unit.

[0128] The second sub-scrambling code parameter N IDThe definition is as follows: For the terminal device-specific search space, if the high-level parameter pdcch-DMRS-ScramblingID is configured, N ID ∈{0,1,…,65535} is equal to the last 16 bits of the high-level parameter pdcch-DMRS-ScramblingID; if the high-level parameter pdcch-DMRS-ScramblingID is configured in the public search space on the public MBS frequency domain resource, N ID ∈{0,1,…,65535} is equal to the last 16 bits of the higher-layer parameter pdcch-DMRS-ScramblingID; otherwise

[0129] Among them, the above is introduced based on the second selection rule of selecting the last 16 bits of the pdcch-DMRS-ScramblingID as the second sub-scrambling code parameter. It can be understood that the second selection rule is not limited to selecting the last 16 bits of the pdcch-DMRS-ScramblingID as the first sub-scrambling code parameter, and can also be selecting the first 16 bits of the pdcch-DMRS-ScramblingID as the first sub-scrambling code parameter.

[0130] Different cells independently configure and deliver scrambling code-specific parameters, resulting in a certain probability of collision. Figure 12 shows a schematic diagram of scrambling code-specific parameter collisions, where the horizontal axis represents the number of cells and the vertical axis represents the probability of scrambling code-specific parameter collisions. Figure 12 uses the pdcch-DMRS-Scrambling ID as an example of the scrambling code-specific parameter. As shown in Figure 12, when the pdcch-DMRS-Scrambling ID bit length is 16, the probability of inter-cell pdcch-DMRS-Scrambling ID collisions is 1.526e-5. When the pdcch-DMRS-Scrambling ID bit length is 32, the probability of inter-cell pdcch-DMRS-Scrambling ID collisions is 2.328e-10. Increasing the pdcch-DMRS-Scrambling ID bit length can significantly reduce the probability of inter-cell pdcch-DMRS-Scrambling ID collisions, thereby reducing interference in inter-cell DCI transmissions.

[0131] If the terminal device's dedicated search space has four candidate sets, four blind checks are required. Assuming a DCI blind check takes 5 microseconds (µs), the cracking time for a single attacker using 64 parallel threads is as shown in the following formula. Because the attacker does not know the encrypted pdcch-DMRS-ScramblingID value, they need to try all possible values. When the pdcch-DMRS-ScramblingID bit length is 16, the attacker can crack this DCI in approximately 0.02 seconds. When the pdcch-DMRS-ScramblingID bit length is 32, the attacker needs 1342 seconds to crack this DCI. Increasing the random bit length of the pdcch-DMRS-ScramblingID can significantly improve DCI security.

[0132] 16 bits: ~5us*(2^16)*4 candidate sets / 64 / 1000 / 1000=0.02 seconds.

[0133] 32 bits: ~5us*(2^32)*4candidate sets / 64 / 1000 / 1000=1342 seconds.

[0134] In some implementations, to further improve security, the terminal device may also update the PDCCH scrambling sequence corresponding to the PDCCH according to a random number generated by a random number generator, and / or update the PDCCH pilot sequence corresponding to the PDCCH.

[0135] As an example, when the terminal device generates at least one random number through a random number generator based on the user-specific parameters of the PDCCH and the setting history messages of the interaction between the terminal device and the network device, it can also generate a second random number for updating the PDCCH scrambling sequence, wherein the second random number can be the same as or different from the first random number used to generate the PDCCH encryption key. After the terminal device obtains the second random number, it can update the PDCCH scrambling sequence according to the second random number. For example: the second random number is used as a new scrambling code id parameter to generate a new PDCCH scrambling sequence, or the first sub-scrambling code parameter is selected from the second random number according to the first selection rule, and the first sub-scrambling code parameter is used to generate a new PDCCH scrambling sequence.

[0136] Similarly, when the terminal device generates at least one random number through a random number generator based on the user-specific parameters of the PDCCH and the setting history message of the interaction between the terminal device and the network device, it can also generate a third random number for updating the PDCCH pilot sequence (such as the PDCCH DMRS sequence), wherein the third random number can be the same as the above-mentioned first random number or the second random data, or can be different from the above-mentioned first random number and the second data number. After the terminal device obtains the third random number, it can update the PDCCH scrambling code sequence according to the third random number. For example: the third random number is used as a new scrambling code id parameter to generate a new PDCCH scrambling code sequence, or a second sub-scrambling code parameter is selected from the third random number according to the second selection rule, and the second sub-scrambling code parameter is used to generate a new PDCCH scrambling code sequence.

[0137] Figure 13 is a schematic diagram of strengthening PDCCH security protection provided by an embodiment of the present application. The terminal device can generate at least one random number through a random number generator periodically based on the user-specific parameters of the PDCCH sent by the network device through the RRC reconfiguration message, and the setting history messages exchanged between the terminal device and the network device; wherein, the user-specific parameters of the PDCCH can be parameters such as pdcch-DMRS-ScramblingID in the user-level CORESET, and the setting history messages exchanged between the terminal device and the network device can be RRC messages, such as MeasurementReport reported by the terminal device through RRC messages. It can also be a NAS message, such as DedicatedNAS-Message.

[0138] The terminal device may generate a PDCCH encryption key using a key generator based on a random number generated by a random number generator (e.g., a first random number); and may also update a PDCCH scrambling sequence and a PDCCH pilot sequence (e.g., a PDCCH DMRS sequence) based on random numbers generated by the random number generator (e.g., a second random number and a third random number). Similar network devices may also determine a PDCCH encryption key and update a PDCCH scrambling sequence and a PDCCH pilot sequence (e.g., a PDCCH DMRS sequence) in a manner similar to that of the terminal device.

[0139] Referring to the physical layer PDCCH encryption diagram shown in Figure 14, the network device can send the PDCCH information to be transmitted (such as DCI) through the air interface after adding one or more processes such as cyclic redundancy check (CRC), radio network temporary identity (RNTI) masking, polar coding, rate matching / interleaving, scrambling, quadrature amplitude modulation (QAM) modulation, resource mapping, inverse fast Fourier transform (IFFT), and adding a cyclic prefix (CP). The signal received by the terminal device is subjected to CP removal, fast Fourier transform (FFT), demapping, channel estimation, multiple input multiple output (MIMO) decoding, QAM demodulation, descrambling / derate matching, polar decoding, RNTI demasking, CRC check, etc. to obtain the transmission information (such as DCI). Among them, the network device can encrypt the PDCCH information to be transmitted (such as DCI) according to the PDCCH encryption key before adding CRC, or before resource mapping or after resource mapping; the terminal device can decrypt the PDCCH information to be transmitted according to the PDCCH encryption key after CRC check, or after demapping or before demapping.

[0140] In addition, the terminal device and the network device can also update the PDCCH scrambling sequence and the PDCCH pilot sequence according to the random numbers generated by the random number generator (such as the second random number and the third random number), the network device scrambles and maps resources on the PDCCH according to the latest PDCCH scrambling sequence and PDCCH pilot sequence, and the terminal device descrambles and estimates the physical channel according to the latest PDCCH scrambling sequence and PDCCH pilot sequence.

[0141] The PDCCH information to be transmitted (such as DCI) is encrypted according to the PDCCH encryption key, and bit-level encryption can be used. For example, before adding the CRC, the bit sequence of the transmitted information can be encrypted using a traditional cryptographic encryption algorithm (such as AES, Zuc, Snow, etc.).

[0142] Of course, the PDCCH information to be transmitted (such as DCI) can be encrypted according to the PDCCH encryption key, and complex domain encryption can also be used. For example, the PDCCH information to be transmitted can be encrypted in the complex domain by using operations such as constellation phase rotation, data and pilot subcarrier confusion interleaving, etc. As shown in Figure 15, when constellation phase rotation is used for encryption, the constellation phase encryption key K can be calculated first, K = x*2π, K∈(-2π, 2π). Then, constellation phase rotation is performed according to K, S' = S*e jK , where S' is the constellation point after encryption, x represents an element in the PDCCH encryption key, and S is the constellation point before encryption, such as the data of the PDCCH physical transmission payload after encoding and QAM modulation. As shown in Figure 16, when using data and pilot subcarrier interleaving encryption, the PDCCH encryption key can be post-processed and converted into an encrypted interleaving index. The coordinate information of the data and pilot subcarriers can be rearranged and scrambled to achieve encryption.

[0143] It is understandable that the above description is made by taking the physical channel as PDCCH as an example. It is understandable that the physical channel may also be PDSCH, PUCCH, or PUSCH, etc.

[0144] Taking the physical channel as PDSCH as an example, Figure 17 is a schematic diagram of strengthening PDSCH security protection provided by an embodiment of the present application. The terminal device can generate at least one random number through a random number generator period based on the user-specific parameters of the PDSCH sent by the network device through the RRC reconfiguration message, and the setting history message of the terminal device interacting with the network device; wherein, the user-specific parameters of the PDSCH can be the scrambling code ID in the user-level PDSCH configuration (PDSCH-Config) (such as the data scrambling identity PDSCH (dataScramblingIdentityPDSCH), the scrambling (scrambling) ID0 and scramblingID1 in the DMRS downlink configuration (DMRS-DownlinkConfig) and other information element parameters. The user-specific parameters of the PDSCH need to remain random and unpredictable and cannot be the same as those sent in plain text. The setting history message of the interaction between the terminal device and the network device can be an RRC message, such as a MeasurementReport reported by the terminal device through an RRC message. It can also be a NAS message, such as a DedicatedNAS-Message, or it can be the PDSCH payload data that the terminal device has received in the same downlink HARQ process.

[0145] The terminal device may generate a PDSCH encryption key using a key generator based on a random number generated by a random number generator (such as a first random number); and may also update a PDSCH scrambling sequence and a PDSCH pilot sequence (such as a PDSCH DMRS sequence) based on random numbers generated by the random number generator (such as a second random number and a third random number). Similar network devices may also determine a PDSCH encryption key and update a PDSCH scrambling sequence and a PDSCH pilot sequence (such as a PDSCH DMRS sequence) in a manner similar to that of the terminal device.

[0146] Taking the physical channel as PUSCH as an example, Figure 18 is a schematic diagram of strengthening PUSCH security protection provided by an embodiment of the present application. The terminal device can generate at least one random number through a random number generator period based on the user-specific parameters of the PUSCH sent by the network device through the RRC reconfiguration message, and the setting history message of the terminal device interacting with the network device; wherein, the user-specific parameters of the PUSCH can be the scrambling code ID in the user-level PUSCH configuration (PUSCH-Config) (such as the data scrambling identity PUSCH (dataScramblingIdentityPUSCH), the DMRS uplink configuration (DMRS-UplinkConfig) and other information element parameters such as scramblingID0 and scramblingID1. The user-specific parameters of the PUSCH need to remain random and unpredictable and cannot be the same as those sent in plain text. The setting history message of the interaction between the terminal device and the network device can be an RRC message, such as a MeasurementReport reported by the terminal device through an RRC message. It can also be a NAS message, such as a DedicatedNAS-Message, or it can be the PUSCH payload data that the terminal device has received in the same downlink HARQ process.

[0147] The terminal device may generate a PUSCH encryption key using a key generator based on a random number generated by a random number generator (such as a first random number); and may also update a PUSCH scrambling sequence and a PUSCH pilot sequence (such as a PUSCH DMRS sequence) based on random numbers generated by the random number generator (such as a second random number and a third random number). Similar network devices may also determine a PUSCH encryption key and update a PUSCH scrambling sequence and a PUSCH pilot sequence (such as a PUSCH DMRS sequence) in a manner similar to that of the terminal device.

[0148] It is understood that in order to implement the functions in the above embodiments, the terminal devices and network devices include hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily appreciate that, in combination with the units and method steps of each example described in the embodiments disclosed in this application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a manner driven by computer software depends on the specific application scenario and design constraints of the technical solution.

[0149] Figures 19 and 20 are schematic diagrams of the structures of possible communication devices provided by embodiments of the present application. These communication devices can be used to implement the functions of the terminal device or network device in the above method embodiments, thereby also achieving the beneficial effects of the above method embodiments. In one possible implementation, the communication device can be a terminal device or a network device, or it can be a module (such as a chip) applied to the terminal device or network device.

[0150] As shown in Figure 19, a communication device 1900 includes a processing unit 1910 and an interface unit 1920, wherein the interface unit 1920 may also be a transceiver unit or an input / output interface. The communication device 1900 may be used to implement the functions of a terminal device or a network device in the method embodiment shown in Figure 7 above.

[0151] When the communication device 1900 is used to implement the functions of the terminal device in the method embodiment shown in Figure 5: the interface unit 1920 is used to receive user-specific parameters of the physical channel of the network device; the processing unit 1910 is used to generate at least one random number through a random number generator based on the user-specific parameters and the setting history messages interacting with the network device, and the at least one random number includes a first random number; based on the first random number, a physical channel encryption key is generated through a key generator; the processing unit 1910 is also used to encrypt or decrypt the physical channel based on the physical channel encryption key.

[0152] In one possible design, at least one random number also includes a second random number, and the processing unit 1910 is further used to update the physical channel scrambling sequence corresponding to the physical channel according to the second random number; and to scramble or descramble the physical channel according to the updated physical channel scrambling sequence.

[0153] In one possible design, at least one random number also includes a third random number, and the processing unit 1910 is further used to update the physical channel pilot sequence corresponding to the physical channel according to the third random number; and perform resource mapping or channel estimation on the physical channel according to the updated physical channel pilot sequence.

[0154] In one possible design, the interface unit 1920 is further used to receive a scrambling code-specific parameter of a physical channel from a network device, where the number of bits included in the scrambling code-specific parameter is greater than a first quantity threshold; the processing unit 1910 is further used to generate a physical channel scrambling sequence corresponding to the physical channel based on a first sub-scrambling code parameter, where the first sub-scrambling code parameter is determined by the processing unit 1910 according to a first selection rule and the scrambling code-specific parameter, and the number of bits included in the first sub-scrambling code parameter is equal to the first quantity threshold; and to generate a physical channel pilot sequence corresponding to the physical channel based on a second sub-scrambling code parameter, where the second sub-scrambling code parameter is determined by the processing unit 1910 according to a second selection rule and the scrambling code-specific parameter, and the number of bits included in the second sub-scrambling code parameter is equal to the first quantity threshold.

[0155] In one possible design, when the processing unit 1910 generates at least one random number through a random number generator based on user-specific parameters and the set historical messages of the interface unit 1920 interacting with the network device, it is specifically used to obtain the set historical messages of the most recent interaction with the network device through the interface unit 1920 according to a set period; and generate at least one random number through the random number generator based on the user-specific parameters and the set historical messages of the most recent interaction.

[0156] In one possible design, user-specific parameters of the physical channel may be randomly configured by the network device.

[0157] For example, the physical channel may be PDCCH, PDSCH, PUCCH, or PUSCH, etc.

[0158] When the communication device 1900 is used to implement the functions of the network device in the method embodiment shown in Figure 5: the interface unit 1920 is used to send user-specific parameters of the physical channel to the terminal device; the processing unit 1910 is used to generate at least one random number through a random number generator based on the user-specific parameters and the setting history messages interacted with the terminal device, and the at least one random number includes a first random number; based on the first random number, a physical channel encryption key is generated through a key generator; the processing unit 1910 is also used to decrypt or encrypt the physical channel based on the physical channel encryption key.

[0159] In one possible design, at least one random number also includes a second random number, and the processing unit 1910 is further used to update the physical channel scrambling sequence corresponding to the physical channel according to the second random number; and descramble or scramble the physical channel according to the updated physical channel scrambling sequence.

[0160] In one possible design, at least one random number also includes a third random number, and the processing unit 1910 is further used to update the physical channel pilot sequence corresponding to the physical channel according to the third random number; and perform channel estimation or resource mapping on the physical channel according to the updated physical channel pilot sequence.

[0161] In one possible design, the interface unit 1920 is further used to send a scrambling code-specific parameter of a physical channel to the terminal device, where the number of bits included in the scrambling code-specific parameter is greater than a first quantity threshold; the processing unit 1910 is further used to generate a physical channel scrambling sequence corresponding to the physical channel based on the first sub-scrambling code parameter, where the first sub-scrambling code parameter is determined by the processing unit 1910 according to the first selection rule and the scrambling code-specific parameter, and the number of bits included in the first sub-scrambling code parameter is equal to the first quantity threshold; and to generate a physical channel pilot sequence corresponding to the physical channel based on the second sub-scrambling code parameter, where the second sub-scrambling code parameter is determined by the processing unit 1910 according to the second selection rule and the scrambling code-specific parameter, and the number of bits included in the second sub-scrambling code parameter is equal to the first quantity threshold.

[0162] In one possible design, when the processing unit 1910 generates at least one random number through a random number generator based on user-specific parameters and set historical messages of interaction with the terminal device, it is specifically used to obtain the set historical messages of the most recent interaction with the terminal device through the interface unit 1920 according to a set period; and generate at least one random number through a random number generator based on user-specific parameters and the set historical messages of the most recent interaction.

[0163] In one possible design, user-specific parameters of the physical channel may be randomly configured by processing unit 1910 .

[0164] For example, the physical channel may be PDCCH, PDSCH, PUCCH, or PUSCH, etc.

[0165] As shown in Figure 20, the present application also provides a communication device 2000, including a processor 2010 and an interface circuit 2020. The processor 2010 and the interface circuit 2020 are coupled to each other. It is understood that the interface circuit 2020 can be a transceiver, an input / output interface, an input interface, an output interface, a communication interface, etc. Optionally, the communication device 2000 may also include a memory 2030 for storing instructions executed by the processor 2010, or storing input data required by the processor 2010 to execute instructions, or storing data generated after the processor 2010 executes instructions. Optionally, the memory 2030 may also be integrated with the processor 2010.

[0166] When the communication device 2000 is used to implement the method shown in FIG. 7 , the processor 2010 may be used to implement the functions of the processing unit 1910 , and the interface circuit 2020 may be used to implement the functions of the interface unit 1920 .

[0167] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), logic circuits, field programmable gate arrays (FPGA) or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0168] The method steps in the embodiments of the present application can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a network device or a terminal device. Of course, the processor and the storage medium can also be present in a network device or a terminal device as discrete components.

[0169] In the above embodiments, all or part of the embodiments can be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are performed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer program or instructions can be transmitted from one network device, terminal, computer, server, or data center to another network device, terminal, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video disk; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.

[0170] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0171] In addition, it should be understood that in the embodiments of this application, the word "exemplary" is used to mean an example, illustration, or description. Any embodiment or design described in this application as "exemplary" should not be construed as preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete way.

[0172] It is understood that the various numbers used in the embodiments of this application are merely for ease of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily imply a specific order of execution; the order of execution of the processes should be determined by their functions and inherent logic.

Claims

1. A communication method, characterized in that: include: The terminal device generates at least one random number through a random number generator according to the user-specific parameters of the physical channel from the network device and the setting history message exchanged between the terminal device and the network device, wherein the at least one random number includes a first random number; The terminal device generates a physical channel encryption key through a key generator according to the first random number; The terminal device encrypts or decrypts the physical channel according to the physical channel encryption key.

2. The method according to claim 1, wherein The at least one random number further includes a second random number, and the method further includes: The terminal device updates a physical channel scrambling sequence corresponding to the physical channel according to the second random number; The terminal device scrambles or descrambles the physical channel according to the updated physical channel scrambling sequence.

3. The method according to claim 1 or 2, wherein: The at least one random number further includes a third random number, and the method further includes: The terminal device updates a physical channel pilot sequence corresponding to the physical channel according to the third random number; The terminal device performs resource mapping or channel estimation on the physical channel according to the updated physical channel pilot sequence.

4. The method according to any one of claims 1 to 3, wherein The method further comprises: The terminal device receives a scrambling code-specific parameter of the physical channel from the network device, where the number of bits included in the scrambling code-specific parameter is greater than a first number threshold; The terminal device generates, according to a first sub-scrambling code parameter, a physical channel scrambling sequence corresponding to the physical channel, where the first sub-scrambling code parameter is determined by the terminal device according to a first selection rule and the scrambling code-specific parameter, and the number of bits included in the first sub-scrambling code parameter is equal to the first number threshold; The terminal device generates a physical channel pilot sequence corresponding to the physical channel based on a second sub-scrambling code parameter, the second sub-scrambling code parameter is determined by the terminal device according to a second selection rule and the scrambling code-specific parameter, and the number of bits included in the second sub-scrambling code parameter is equal to the first number threshold.

5. The method according to any one of claims 1 to 4, wherein The terminal device generates at least one random number through a random number generator according to user-specific parameters of a physical channel from a network device and setting history messages exchanged between the terminal device and the network device, including: The terminal device obtains the set history message of the most recent interaction with the network device according to the set period; The terminal device generates at least one random number through a random number generator according to the user-specific parameters and the setting history message of the most recent interaction.

6. The method according to any one of claims 1 to 5, wherein The user-specific parameters of the physical channel are randomly configured by the network device.

7. The method according to any one of claims 1 to 6, wherein The physical channel is a physical downlink control channel PDCCH, a physical downlink shared channel PDSCH, a physical uplink control channel PUCCH, or a physical uplink shared channel PUSCH.

8. A communication method, characterized in that: include: The network device generates at least one random number using a random number generator according to the user-specific parameters of the physical channel sent to the terminal device and the setting history message exchanged between the terminal device and the network device, wherein the at least one random number includes a first random number; The network device generates a physical channel encryption key through a key generator according to the first random number; The network device decrypts or encrypts the physical channel according to the physical channel encryption key.

9. The method according to claim 8, wherein The at least one random number further includes a second random number, and the method further includes: The network device updates a physical channel scrambling sequence corresponding to the physical channel according to the second random number; The network device descrambles or scrambles the physical channel according to the updated physical channel scrambling sequence.

10. The method according to claim 8 or 9, characterized in that The at least one random number further includes a third random number, and the method further includes: The network device updates a physical channel pilot sequence corresponding to the physical channel according to the third random number; The network device performs channel estimation or resource mapping on the physical channel according to the updated physical channel pilot sequence.

11. The method according to any one of claims 8 to 10, wherein: The method further comprises: The network device sends a scrambling code-specific parameter of the physical channel to the terminal device, where the number of bits included in the scrambling code-specific parameter is greater than a first number threshold; The network device generates, according to a first sub-scrambling code parameter, a physical channel scrambling sequence corresponding to the physical channel, where the first sub-scrambling code parameter is determined by the network device according to a first selection rule and the scrambling code-specific parameter, and the number of bits included in the first sub-scrambling code parameter is equal to the first number threshold; The network device generates a physical channel pilot sequence corresponding to the physical channel according to a second sub-scrambling code parameter, where the second sub-scrambling code parameter is determined by the network device according to a second selection rule and the scrambling code-specific parameter, and the number of bits included in the second sub-scrambling code parameter is equal to the first number threshold.

12. The method according to any one of claims 8 to 11, wherein The network device generates at least one random number through a random number generator according to user-specific parameters of a physical channel sent to a terminal device and a setting history message exchanged between the terminal device and the network device, including: The network device obtains a set history message of the most recent interaction with the terminal device according to a set period; The network device generates at least one random number through a random number generator according to the user-specific parameters and the setting history message of the most recent interaction.

13. The method according to any one of claims 8 to 12, wherein: The user-specific parameters of the physical channel are randomly configured by the network device.

14. The method according to any one of claims 8 to 13, wherein The physical channel is a physical downlink control channel PDCCH, a physical downlink shared channel PDSCH, a physical uplink control channel PUCCH, or a physical uplink shared channel PUSCH.

15. A communication device, characterized in that: including an interface unit and a processing unit; The interface unit is configured to receive user-specific parameters of a physical channel from a network device; The processing unit is configured to generate at least one random number using a random number generator based on the user-specific parameters and a setting history message exchanged with the network device, the at least one random number including a first random number; and generate a physical channel encryption key using a key generator based on the first random number; The processing unit is further configured to encrypt or decrypt the physical channel according to the physical channel encryption key.

16. The device according to claim 15, characterized in that The at least one random number further includes a second random number; The processing unit is further configured to update a physical channel scrambling sequence corresponding to the physical channel according to the second random number; and scramble or descramble the physical channel according to the updated physical channel scrambling sequence.

17. The device according to claim 15 or 16, characterized in that The at least one random number further includes a third random number; The processing unit is further configured to update a physical channel pilot sequence corresponding to the physical channel according to the third random number; and perform resource mapping or channel estimation on the physical channel according to the updated physical channel pilot sequence.

18. The device according to any one of claims 15 to 17, characterized in that The interface unit is further configured to receive a scrambling code-specific parameter of the physical channel from the network device, wherein the number of bits included in the scrambling code-specific parameter is greater than a first number threshold; the processing unit is further configured to generate a physical channel scrambling sequence corresponding to the physical channel according to a first sub-scrambling code parameter, where the first sub-scrambling code parameter is determined by the processing unit according to a first selection rule and the scrambling code-specific parameter, and the number of bits included in the first sub-scrambling code parameter is equal to the first number threshold; and generating a physical channel pilot sequence corresponding to the physical channel according to a second sub-scrambling code parameter, where the second sub-scrambling code parameter is determined by the processing unit according to a second selection rule and the scrambling code-specific parameter, and the number of bits included in the second sub-scrambling code parameter is equal to the first number threshold.

19. The device according to any one of claims 15 to 18, characterized in that When the processing unit generates at least one random number through a random number generator based on the user-specific parameters and the setting history messages of the interface unit interacting with the network device, the processing unit is specifically used to obtain the setting history messages of the most recent interaction with the network device through the interface unit according to a set period; and generate at least one random number through a random number generator based on the user-specific parameters and the setting history messages of the most recent interaction.

20. The device according to any one of claims 15 to 19, characterized in that The user-specific parameters of the physical channel are randomly configured by the network device.

21. The device according to any one of claims 15 to 20, characterized in that The physical channel is a physical downlink control channel PDCCH, a physical downlink shared channel PDSCH, a physical uplink control channel PUCCH, or a physical uplink shared channel PUSCH.

22. A communication device, characterized in that: including an interface unit and a processing unit; The interface unit is used to send user-specific parameters of the physical channel to the terminal device; The processing unit is configured to generate at least one random number using a random number generator based on the user-specific parameter and a setting history message exchanged with the terminal device, the at least one random number including a first random number; and generate a physical channel encryption key using a key generator based on the first random number; The processing unit is further configured to decrypt or encrypt the physical channel according to the physical channel encryption key.

23. The device according to claim 22, wherein The at least one random number further includes a second random number; The processing unit is further configured to update a physical channel scrambling sequence corresponding to the physical channel according to the second random number; and descramble or scramble the physical channel according to the updated physical channel scrambling sequence.

24. The device according to claim 22 or 23, characterized in that The at least one random number further includes a third random number; The processing unit is further configured to update a physical channel pilot sequence corresponding to the physical channel according to the third random number; and perform channel estimation or resource mapping on the physical channel according to the updated physical channel pilot sequence.

25. The device according to any one of claims 22 to 24, characterized in that The interface unit is further configured to send a scrambling code-specific parameter of the physical channel to the terminal device, wherein the number of bits included in the scrambling code-specific parameter is greater than a first number threshold; the processing unit is further configured to generate a physical channel scrambling sequence corresponding to the physical channel according to a first sub-scrambling code parameter, where the first sub-scrambling code parameter is determined by the processing unit according to a first selection rule and the scrambling code-specific parameter, and the number of bits included in the first sub-scrambling code parameter is equal to the first number threshold; and generating a physical channel pilot sequence corresponding to the physical channel according to a second sub-scrambling code parameter, where the second sub-scrambling code parameter is determined by the processing unit according to a second selection rule and the scrambling code-specific parameter, and the number of bits included in the second sub-scrambling code parameter is equal to the first number threshold.

26. The device according to any one of claims 22 to 25, characterized in that When the processing unit generates at least one random number through a random number generator based on the user-specific parameters and the setting history messages interacted with the terminal device, it is specifically used to obtain the setting history messages of the most recent interaction with the terminal device through the interface unit according to a set period; and generate at least one random number through a random number generator based on the user-specific parameters and the setting history messages of the most recent interaction.

27. The device according to any one of claims 22 to 26, characterized in that The user-specific parameters of the physical channel are randomly configured by the processing unit.

28. The device according to any one of claims 22 to 27, characterized in that The physical channel is a physical downlink control channel PDCCH, a physical downlink shared channel PDSCH, a physical uplink control channel PUCCH, or a physical uplink shared channel PUSCH.

29. A chip system, characterized in that: The chip system includes a processor, which is coupled to a memory, and the memory is used to store programs or instructions. When the program or instructions are executed by the processor, the method according to any one of claims 1 to 14 is implemented.

30. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program or instructions. When the computer program or instructions are executed by a processor, the method according to any one of claims 1 to 14 is implemented.

31. A computer program product, characterized in that The computer program product comprises a computer program or instructions, and when the computer program or instructions are executed by a processor, the method according to any one of claims 1 to 14 is implemented.