Broadcast message protection method and related device
Patent Information
- Application Number
- CN202280100177.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-24
- Publication Date
- 2025-05-06
AI Technical Summary
In wireless communication technology, broadcast messages sent by network equipment over the air interface lack security protection and are easily stolen and counterfeited by pseudo base stations, leading to leakage of private information of terminal equipment or service interruption.
By generating integrity protection information based on the beam index, the broadcast messages sent by the air interface of the network device are securely protected to prevent pseudo base station attacks, including using the integrity protection information and signature cycle for verification and adjustment during the beam scanning process.
It effectively prevents the replay and tampering of broadcast messages, improves the security of terminal equipment, and ensures communication confidence and service stability between network equipment and terminal equipment.
Smart Images

Figure CN119948902A_ABST
Abstract
Description
Broadcast message protection method and related device Technical Field
[0001] The present application relates to the field of wireless communication technology, and in particular to a broadcast message protection method and related devices. Background Art
[0002] In wireless communication technology, broadcast messages sent over the air interface of network devices are intended for all terminals within the cell's coverage area. Therefore, these messages cannot be encrypted using user-level symmetric keys. During the initial network access phase, terminals must first receive system messages broadcast over the air interface of network devices before establishing a communication connection. During cell search and synchronization, terminals must also receive system messages broadcast over the air interface of network devices before initiating random access, accessing the cell, and operating normally within it.
[0003] Therefore, if broadcast messages sent over the air interface of network devices lack any security protection, they will cause significant losses to users. For example, if system messages lack any security protection, legitimate base station system messages can be easily intercepted and spoofed by rogue base stations. For example, a rogue base station can first synchronize frequency and time with the legitimate base station, then spoof the legitimate base station's specific system messages and send them at a higher power, causing the terminal to be attracted and deceived by the rogue base station. In this way, the rogue base station can steal user privacy information from the terminal or cause the terminal to malfunction. Alternatively, by tampering with important fields in the spoofed system message, the terminal's calling capabilities can be disabled, the terminal cannot receive network called services, and the user cannot access the Internet, send text messages, or make phone calls for an extended period of time. Therefore, how to secure broadcast messages sent over the air interface of network devices is an urgent problem to be solved.
[0004] Summary of the Invention
[0005] The present application provides a broadcast message protection method and related devices, which can provide security protection for broadcast messages sent by the air interface of a network device.
[0006] In a first aspect, the present application provides a broadcast message protection method that can be performed by a communication device, which can be a communication device or a communication device capable of supporting the communication device to implement the functions required by the method, such as a chip. Exemplarily, the communication device is a network device, or a chip provided in the network device for implementing the functions of the network device, or other components for implementing the functions of the network device. The network device is used as an example for the implementation.
[0007] The method includes: a network device generates integrity protection information of a first broadcast message, where the integrity protection information is generated based on a beam index of a beam that sends the first broadcast message; and sends the integrity protection information of the first broadcast message.
[0008] It can be seen that the broadcast message protection method introduces the beam index of the beam that sends the broadcast message to generate integrity protection information. On the one hand, it can protect the broadcast messages in different beam directions with the beam direction as the granularity. On the other hand, it can prevent the broadcast messages in different beam directions from being replayed, thereby realizing the security protection of the broadcast messages sent over the air interface.
[0009] In an optional embodiment, the method may further include: the network device sends the signature period corresponding to the first broadcast message under the beam, and the signature period corresponding to the first broadcast message under the beam is the sending period of the integrity protection information of the first broadcast message under the beam. Optionally, for the case where the first broadcast message is sent on M beams in a beam scanning manner (M is an integer greater than 1), the signature period corresponding to each beam of the M beams may be the same or different and are independently configured. Optionally, the signature periods corresponding to different broadcast messages under the same beam may also be the same or different. It can be seen that in this embodiment, the integrity protection information of the first broadcast message is sent periodically, thereby reducing the additional air interface time and frequency resource overhead caused by sending the integrity protection information.
[0010] In an optional embodiment, the method may further include: the network device receives response information to the first broadcast message, the response information including the beam index and the verification result of the integrity protection information of the first broadcast message; the network device adjusts the signature period corresponding to the first broadcast message under the beam according to the verification result of the integrity protection information of the first broadcast message. It can be seen that in this embodiment, the network device can adjust the signature period corresponding to the beam according to the verification result of the integrity protection information of the broadcast message. For example, if it is determined based on the verification result that there may be an attacker such as a pseudo base station in the direction of the beam, the signature period can be shortened to prevent air interface attacks; if it is determined based on the verification result that there is no attack in the direction of the beam, the signature period can be increased, thereby helping to reduce the additional air interface time and frequency resource overhead brought by the integrity protection information.
[0011] Optionally, under the same beam, the integrity protection information of different broadcast messages can be generated independently or jointly. Optionally, under the same beam, the first broadcast message may include different broadcast messages with the same or different transmission periods, or the first broadcast message may include different broadcast messages with the same or different transmission periods and the same broadcast sending strategy, or the first broadcast message may include different broadcast messages with the same or different transmission periods, the same broadcast sending strategy and the same signature period. Optionally, a new information element may be added to the broadcast message to indicate the signature period of the broadcast message, or the signature period of the broadcast message may be added to the existing information element. Optionally, under the same beam, for multiple broadcast messages that can be jointly generated for integrity protection information, the signature period corresponding to the multiple broadcast messages is greater than or equal to the maximum transmission period among the transmission periods of the multiple broadcast messages.
[0012] In an optional implementation, the integrity protection information sent by the network device is generated not only based on the beam index of the beam, but also based on the timestamp, downlink frequency and cell identifier of sending the first broadcast message.
[0013] In an optional embodiment, the response information to the first broadcast message also includes an anti-replay parameter. Accordingly, the method further includes: the network device using the anti-replay parameter to verify whether the response information to the first broadcast message is a replay message; if not, performing the step of adjusting the signature period corresponding to the first broadcast message under the beam based on the verification result of the integrity protection information of the first broadcast message. This embodiment can prevent the response information to the first broadcast message from being a replay message.
[0014] In an optional embodiment, the response information to the first broadcast message is encrypted, and the method further includes: the network device decrypting the response information to the first broadcast message to obtain a verification result of the beam index and the integrity protection information of the first broadcast message. This improves the security of the received verification result.
[0015] In the second aspect, the present application also provides a broadcast message protection method, which corresponds to the broadcast message protection method described in the first aspect. The method can be executed by a communication device, which can be a communication device or a communication device that can support the communication device to implement the functions required by the method, such as a chip. Exemplarily, the communication device is a terminal device, or a chip provided in the terminal device for implementing the functions of the terminal device, or other components for implementing the functions of the terminal device. The terminal device is used as an example of the execution subject. The method includes: the terminal device receives the integrity protection information of the first broadcast message; the terminal device verifies the integrity protection information according to the beam index of the beam receiving the first broadcast message, and obtains the verification result of the integrity protection information of the first broadcast message.
[0016] It can be seen that in this broadcast message protection method, the terminal device verifies the integrity protection information with the beam index of the beam receiving the broadcast message. On the one hand, it can confirm the security of broadcast messages in different beam directions with the beam direction as the granularity; on the other hand, it can prevent the broadcast messages in different beam directions from being replayed, thereby improving the security of broadcast messages received at the air interface.
[0017] In an optional embodiment, the method may further include: the terminal device receives the signature period corresponding to the first broadcast message under the beam, and the signature period corresponding to the first broadcast message under the beam is the transmission period of the integrity protection information of the first broadcast message under the beam. Optionally, the beam is the beam with the highest signal strength among the beams in which the terminal device receives the first broadcast message. It can be seen that in this embodiment, under this beam, the integrity protection information of the first broadcast message is sent periodically, thereby reducing the additional air interface time-frequency resource overhead caused by receiving the integrity protection information.
[0018] In an optional embodiment, the method may further include: the terminal device sending a response message to the first broadcast message, the response message including the beam index and a verification result of the integrity protection information of the first broadcast message; wherein the verification result of the integrity protection information of the first broadcast message is used by the network device to adjust the signature period corresponding to the first broadcast message under the beam. It can be seen that in this embodiment, the terminal device reporting the verification result of the integrity protection information of the broadcast message facilitates the network device to adjust the signature period corresponding to the beam.
[0019] Optionally, under the same beam, the integrity protection information of different broadcast messages can be received independently by the terminal devices separately, or can be received jointly. Optionally, under the same beam, the first broadcast message may include different broadcast messages with the same or different transmission periods, or the first broadcast message may include different broadcast messages with the same or different transmission periods and the same broadcast sending strategy, or the first broadcast message may include different broadcast messages with the same or different transmission periods, the same broadcast sending strategy and the same signature period. Optionally, a new information element may be added to the broadcast message to represent the signature period of the broadcast message, or the signature period of the broadcast message may be added to the existing information element. Optionally, under the same beam, for multiple broadcast messages that can be jointly received for integrity protection information, the signature period corresponding to the multiple broadcast messages is greater than or equal to the maximum transmission period among the transmission periods of the multiple broadcast messages.
[0020] In an optional implementation, the terminal device verifies the integrity protection information based on the beam index of the beam receiving the first broadcast message to obtain the verification result of the integrity protection information of the first broadcast message. Specifically, the terminal device verifies the integrity protection information based on the timestamp, downlink frequency, cell identifier and beam index of the beam receiving the first broadcast message to obtain the verification result of the integrity protection information of the first broadcast message.
[0021] In an optional implementation manner, the response information of the first broadcast message further includes an anti-replay parameter, which is used by the network device to verify whether the response information of the first broadcast message is a replay message.
[0022] In an optional embodiment, the terminal device sending the response information to the first broadcast message includes: encrypting the response information to the first broadcast message to obtain the encrypted response information to the first broadcast message; and sending the encrypted response information to the first broadcast message. This improves the security of the verification result.
[0023] In a third aspect, the present application provides a broadcast message protection method. This method corresponds to the broadcast message protection method described in the first and second aspects above, and is described from the perspective of interaction between a network device and a terminal device. The beneficial effects of this part can be found in the relevant descriptions of the first and second aspects above, and will not be described in detail here. In addition, the method is described using one of the multiple beams transmitted by the network device and one of the terminal devices within the coverage range of the beam as an example.
[0024] The method includes: a network device generates and sends integrity protection information of a first broadcast message, wherein the integrity protection information is generated based on a beam index of a beam that sends the first broadcast message; a terminal device receives the integrity protection information of the first broadcast message; and based on the beam index of the beam that receives the first broadcast message, the integrity protection information is verified to obtain a verification result of the integrity protection information of the first broadcast message.
[0025] In an optional embodiment, the method may also include: the network device sends the signature period corresponding to the first broadcast message under the beam, and the terminal device receives the signature period corresponding to the first broadcast message under the beam, and the signature period corresponding to the first broadcast message under the beam is the sending period of the integrity protection information of the first broadcast message under the beam.
[0026] In an optional embodiment, the method may also include: the terminal device sends response information to the first broadcast message, and the network device receives the response information to the first broadcast message, the response information including the beam index and the verification result of the integrity protection information of the first broadcast message; the network device adjusts the signature period corresponding to the first broadcast message under the beam according to the verification result of the integrity protection information of the first broadcast message.
[0027] In an optional implementation, the first broadcast message includes different broadcast messages having the same or different transmission periods.
[0028] In an optional embodiment, the integrity protection information sent by the network device is generated not only based on the beam index of the beam, but also based on the timestamp, downlink frequency, and cell identifier of the first broadcast message. Accordingly, the terminal device verifies the integrity protection information based on the timestamp, downlink frequency, cell identifier, and beam index of the beam received from the first broadcast message, and obtains a verification result of the integrity protection information of the first broadcast message.
[0029] In an optional embodiment, the response information of the first broadcast message also includes an anti-replay parameter. Accordingly, the method also includes: the network device uses the anti-replay parameter to verify whether the response information of the first broadcast message is a replay message; if it is not a replay message, execute the step of adjusting the signature period corresponding to the first broadcast message under the beam based on the verification result of the integrity protection information of the first broadcast message.
[0030] In an optional implementation, the terminal device encrypts the response information of the first broadcast message to obtain the encrypted response information of the first broadcast message; the terminal device sends the encrypted response information of the first broadcast message; correspondingly, the network device decrypts the received response information of the first broadcast message to obtain the response information of the first broadcast message.
[0031] The relevant explanations of this part can also be found in the above-mentioned first and second aspects, which will not be elaborated here.
[0032] Fourthly, the present application also provides a broadcast message protection method, which can be executed by a communication device, which can be a communication device or a communication device that can support the communication device to implement the functions required by the method, such as a chip. Exemplarily, the communication device is a network device, or a chip provided in the network device for implementing the functions of the network device, or other components for implementing the functions of the network device. The network device is used as an example for the execution subject. The method includes: sending a first broadcast message; receiving response information of the first broadcast message, the response information including the beam index of the beam for receiving the first broadcast message by the terminal device, and the integrity protection information of the first broadcast message generated by the terminal device based on the beam index; verifying the integrity protection information according to the first broadcast message and the beam index to obtain the verification result of the integrity information protection information of the first broadcast message.
[0033] It can be seen that this broadcast message protection method is beneficial for the network device to identify whether the terminal device on the beam is attacked by a fake base station based on the verification result of the complete information protection information of the first broadcast message, such as the content of the first broadcast message is tampered with by the fake base station.
[0034] In an optional embodiment, the method further includes: the network device adjusting the signature period corresponding to the first broadcast message in the beam based on the verification result of the integrity protection information of the first broadcast message; wherein the signature period corresponding to the first broadcast message in the beam is the transmission period of the integrity protection information of the first broadcast message sent by the network device in the beam. In other words, the signature period is unrelated to the period of the integrity protection information of the first broadcast message sent by the terminal device.
[0035] It can be seen that in this implementation, the network device can adjust the corresponding signature period under the beam according to the verification result of the integrity protection information of the broadcast message. For example, if it is determined based on the verification result that there may be attackers such as fake base stations in the direction of the beam, the signature period can be shortened to prevent air interface attacks; if it is determined based on the verification result that there is no attack in the direction of the beam, the signature period can be increased, which is conducive to reducing the additional air interface time and frequency resource overhead brought by the integrity protection information.
[0036] In an optional implementation, the method further includes: the network device may send the first broadcast message in a signature period corresponding to the beam.
[0037] In an optional implementation, under the same beam, the network device may generate integrity protection information for different broadcast messages independently or jointly. Optionally, under the same beam, the network device may generate integrity protection information for a first broadcast message, and the first broadcast message may include different broadcast messages with the same or different transmission periods, or the first broadcast message may include different broadcast messages with the same or different transmission periods and the same broadcast sending strategy, or the first broadcast message may include different broadcast messages with the same or different transmission periods, the same broadcast sending strategy, and the same signature period. Optionally, a new information element may be added to the broadcast message to indicate the signature period of the broadcast message, or the signature period of the broadcast message may be added to an existing information element. Optionally, under the same beam, multiple broadcast messages may be jointly generated for integrity protection information, and the signature period corresponding to the multiple broadcast messages may be greater than or equal to the maximum transmission period among the transmission periods of the multiple broadcast messages.
[0038] In an optional implementation, the network device verifies the integrity protection information based on the first broadcast message and the beam index to obtain a verification result of the integrity protection information of the first broadcast message, specifically: based on the first broadcast message and the timestamp, downlink frequency, cell identifier and beam index of sending the first broadcast message, the integrity protection information is verified to obtain a verification result of the integrity protection information of the first broadcast message.
[0039] In an optional embodiment, the response message also includes an anti-replay parameter. Accordingly, the method further includes: the network device uses the anti-replay parameter to verify whether the response message to the first broadcast message is a replay message; if it is not a replay message, performing the step of verifying the integrity protection information based on the first broadcast message and the beam index to obtain a verification result of the integrity protection information of the first broadcast message. This embodiment can prevent the response message to the first broadcast message from being a replay message.
[0040] In an optional implementation, the response information is encrypted, and the network device needs to decrypt the response information of the first broadcast message to obtain the beam index and the integrity protection information of the first broadcast message, thereby improving the security of the received information.
[0041] In a fifth aspect, the present application also provides a broadcast message protection method, which corresponds to the broadcast message protection method described in the fourth aspect. The method can be executed by a communication device, which can be a communication device or a communication device that can support the communication device to implement the functions required by the method, such as a chip. Exemplarily, the communication device is a terminal device, or a chip provided in the terminal device for implementing the functions of the terminal device, or other components for implementing the functions of the terminal device. The terminal device is used as the execution subject for example.
[0042] The method includes: the terminal device receives a first broadcast message; the terminal device generates integrity protection information for the first broadcast message, and the integrity protection information is generated based on the beam index of the beam that receives the first broadcast message; and sends response information to the first broadcast message, and the response information includes the beam index and the integrity protection information of the first broadcast message.
[0043] It can be seen that in this broadcast message protection method, the terminal device can report the integrity protection information of the first broadcast message, which is helpful for the network device to identify whether the terminal device in the beam direction is attacked by a fake base station, such as the content of the first broadcast message is tampered with by the fake base station.
[0044] In an optional implementation, before the terminal device generates the integrity protection information of the first broadcast message under the beam based on the beam index of the beam receiving the first broadcast message, the method further includes: the terminal device receives the signature period corresponding to the first broadcast message under the beam. The signature period corresponding to the first broadcast message under the beam is the sending period of the integrity protection information of the first broadcast message sent by the network device under the beam. In other words, the signature period has nothing to do with the period of the integrity protection information of the first broadcast message sent by the terminal device. It can be seen that in this implementation, under this beam, the network device periodically sends the integrity protection information of the first broadcast message, thereby reducing the additional air interface time and frequency resource overhead caused by sending the integrity protection information.
[0045] In an optional implementation, the first broadcast message includes different broadcast messages having the same or different transmission periods. In an optional implementation, the integrity protection information sent by the terminal device is further generated based on a timestamp, a downlink frequency, and a cell identifier of receiving the first broadcast message.
[0046] In an optional embodiment, the response information further includes an anti-replay parameter for the network device to verify whether the response information of the first broadcast message is a replay message. This embodiment can prevent the response information of the first broadcast message from being a replay message.
[0047] In an optional embodiment, the terminal device may encrypt the response information of the first broadcast message to obtain the encrypted response information of the first broadcast message, and send the encrypted response information of the first broadcast message. This embodiment can improve the security of the response information of the first broadcast message.
[0048] In a sixth aspect, the present application provides a broadcast message protection method. This method corresponds to the broadcast message protection method described in the fourth and fifth aspects above. It is described from the perspective of the interaction between a network device and a terminal device. The beneficial effects of this part can be found in the relevant descriptions of the fourth and fifth aspects above and will not be described in detail here. In addition, the method is described using one of the multiple beams transmitted by the network device and one of the terminal devices within the coverage range of the beam as an example.
[0049] The method includes: a network device sends a first broadcast message; a terminal device receives the first broadcast message; the terminal device generates integrity protection information for the first broadcast message, and the integrity protection information is generated based on a beam index of a beam that receives the first broadcast message; the terminal device sends response information to the first broadcast message, and accordingly, the network device receives response information to the first broadcast message, the response information including the beam index of the beam that the terminal device receives the first broadcast message, and integrity protection information of the first broadcast message generated by the terminal device based on the beam index; the network device verifies the integrity protection information based on the first broadcast message and the beam index, and obtains a verification result of the integrity protection information of the first broadcast message.
[0050] It can be seen that in this broadcast message protection method, the terminal device can report the integrity protection information of the first broadcast message, which helps the network device identify whether the terminal device in the beam direction has been attacked by a fake base station, such as if the fake base station has tampered with the content of the first broadcast message. For example, if the network device does not send the integrity protection information of the first broadcast message under the beam, the terminal device can also proactively report the integrity protection information of the first broadcast message, thereby facilitating the network device to promptly identify whether there is an attack in the beam direction, thereby improving the security of the broadcast message.
[0051] In an optional embodiment, the method further includes: the network device adjusting the signature period corresponding to the first broadcast message in the beam based on the verification result of the integrity protection information of the first broadcast message; accordingly, the network device may send the signature period corresponding to the first broadcast message in the beam; and the terminal device receives the signature period corresponding to the first broadcast message in the beam. The signature period corresponding to the first broadcast message in the beam is the period during which the network device sends the integrity protection information for the first broadcast message in the beam. In other words, the signature period is unrelated to the period during which the terminal device sends the integrity protection information for the first broadcast message.
[0052] It can be seen that in this implementation, the network device can timely adjust the corresponding signature period under the beam according to the verification result of the integrity protection information of the broadcast message. For example, based on the verification result within the statistical period, it is determined that there may be attackers such as fake base stations in the direction of the beam, and the signature period can be shortened to prevent air interface attacks; based on the verification result within the statistical period, it is determined that there is no attack in the direction of the beam, and the signature period can be increased, which is conducive to reducing the additional air interface time and frequency resource overhead brought by the integrity protection information.
[0053] In an optional implementation, under the same beam, the integrity protection information sent by the network device for different broadcast messages can be generated independently or jointly.
[0054] In an optional implementation, the integrity protection information sent by the terminal device is further generated based on the timestamp, downlink frequency, and cell identifier of receiving the first broadcast message. Accordingly, the network device verifies the integrity protection information based on the first broadcast message and the beam index, and obtains a verification result of the integrity protection information of the first broadcast message. Specifically, the network device verifies the integrity protection information based on the first broadcast message and the timestamp, downlink frequency, cell identifier, and beam index of sending the first broadcast message, and obtains a verification result of the integrity protection information of the first broadcast message.
[0055] In an optional embodiment, the response message also includes an anti-replay parameter. Accordingly, the method further includes: the network device using the anti-replay parameter to verify whether the response message to the first broadcast message is a replay message; if not, performing the step of verifying the integrity protection information based on the first broadcast message and the beam index to obtain a verification result of the integrity protection information of the first broadcast message. This embodiment can prevent the response message to the first broadcast message from being a replay message.
[0056] In an optional implementation, the terminal device may encrypt the response information to the first broadcast message to obtain the encrypted response information to the first broadcast message; the terminal device may send the encrypted response information to the first broadcast message; and the network device may receive and decrypt the response information to obtain the encrypted response information to the first broadcast message. This implementation can improve the security of the response information to the first broadcast message.
[0057] The relevant explanations of this part can also be found in the above-mentioned fourth and fifth aspects, which will not be elaborated here.
[0058] In a seventh aspect, the present application provides a communication device, which may be a network device, a device within a network device, or a device capable of being used in conjunction with a network device. The functions of the communication device may be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the above functions. The units or modules may be software and / or hardware.
[0059] Optionally, the communication device includes a processing unit and a communication unit, and executes the method according to the first aspect, wherein:
[0060] a processing unit, configured to generate integrity protection information for the first broadcast message, where the integrity protection information is generated based on a beam index of a beam that sends the first broadcast message;
[0061] The communication unit is configured to send integrity protection information of the first broadcast message.
[0062] In an optional embodiment, the communication unit is also used to send the signature period corresponding to the first broadcast message under the beam, and the signature period corresponding to the first broadcast message under the beam is the sending period of the integrity protection information of the first broadcast message under the beam.
[0063] In an optional embodiment, the communication unit is also used to receive response information of the first broadcast message, and the response information includes the beam index and the verification result of the integrity protection information of the first broadcast message; the processing unit is also used to adjust the signature period corresponding to the first broadcast message under the beam according to the verification result of the integrity protection information of the first broadcast message.
[0064] In an optional embodiment, the response information of the first broadcast message also includes an anti-replay parameter. Accordingly, the processing unit uses the anti-replay parameter to verify whether the response information of the first broadcast message is a replay message; if it is not a replay message, the operation of adjusting the signature period corresponding to the first broadcast message under the beam is executed based on the verification result of the integrity protection information of the first broadcast message.
[0065] In an optional implementation, the response information of the first broadcast message is encrypted, and the processing unit is further used to decrypt the response information of the first broadcast message to obtain the beam index and the verification result of the integrity protection information of the first broadcast message.
[0066] The relevant operations and beneficial effects performed by the communication device can refer to the method and beneficial effects described in the first aspect above.
[0067] Optionally, the communication device includes a communication unit and a processing unit, and performs the method according to the fourth aspect, wherein:
[0068] A communication unit, configured to send a first broadcast message;
[0069] The communication unit is further configured to receive response information to the first broadcast message, the response information including a beam index of a beam for receiving the first broadcast message by the terminal device, and integrity protection information of the first broadcast message generated by the terminal device based on the beam index;
[0070] The processing unit is configured to verify the integrity protection information according to the first broadcast message and the beam index to obtain a verification result of the integrity protection information of the first broadcast message.
[0071] In an optional embodiment, the processing unit is also used to adjust the signature period corresponding to the first broadcast message under the beam based on the verification result of the integrity protection information of the first broadcast message; wherein, the signature period corresponding to the first broadcast message under the beam is the sending period of the integrity protection information of the first broadcast message sent by the network device under the beam.
[0072] In an optional implementation, the communication unit is further configured to send a signature period corresponding to the first broadcast message under the beam.
[0073] In an optional embodiment, the processing unit verifies the integrity protection information based on the first broadcast message and the beam index to obtain the verification result of the integrity protection information of the first broadcast message, specifically: based on the first broadcast message and the timestamp, downlink frequency, cell identifier and beam index of sending the first broadcast message, the integrity protection information is verified to obtain the verification result of the integrity protection information of the first broadcast message.
[0074] In an optional embodiment, the response information also includes an anti-replay parameter. Accordingly, the processing unit uses the anti-replay parameter to verify whether the response information of the first broadcast message is a replay message; if it is not a replay message, the operation of verifying the integrity protection information based on the first broadcast message and the beam index is performed to obtain the verification result of the integrity protection information of the first broadcast message.
[0075] In an optional implementation, the response information is encrypted, and the processing unit needs to decrypt the response information of the first broadcast message to obtain the beam index and the integrity protection information of the first broadcast message.
[0076] The relevant operations and beneficial effects performed by the communication device can refer to the method and beneficial effects described in the fourth aspect above.
[0077] In an eighth aspect, the present application provides a communication device, which may be a terminal device, a device in a terminal device, or a device that can be used in conjunction with a terminal device. The communication device may also be a chip system. The functions of the communication device may be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the above functions. The units or modules may be software and / or hardware.
[0078] Optionally, the communication device may execute the communication method described in the second aspect, which may include a processing unit and a communication unit, wherein:
[0079] a communication unit, configured to receive integrity protection information of a first broadcast message;
[0080] The processing unit is configured to verify the integrity protection information according to the beam index of the beam receiving the first broadcast message, and obtain a verification result of the integrity protection information of the first broadcast message.
[0081] In an optional embodiment, the communication unit is also used to receive the signature period corresponding to the first broadcast message under the beam, and the signature period corresponding to the first broadcast message under the beam is the sending period of the integrity protection information of the first broadcast message sent by the network device under the beam.
[0082] In an optional embodiment, the communication unit is also used to send response information to the first broadcast message, and the response information includes the beam index and the verification result of the integrity protection information of the first broadcast message; wherein, the verification result of the integrity protection information of the first broadcast message is used by the network device to adjust the signature period corresponding to the first broadcast message under the beam.
[0083] In an optional embodiment, the processing unit verifies the integrity protection information according to the beam index of the beam for receiving the first broadcast message, and obtains the verification result of the integrity protection information of the first broadcast message. Specifically, it can be as follows: according to the timestamp of receiving the first broadcast message, the downlink frequency, the cell identifier and the beam index of the beam, the integrity protection information is verified to obtain the verification result of the integrity protection information of the first broadcast message.
[0084] In an optional implementation, the processing unit further encrypts the response information of the first broadcast message to obtain the encrypted response information of the first broadcast message; correspondingly, the communication unit specifically sends the encrypted response information of the first broadcast message.
[0085] The operations and beneficial effects performed by the communication device can refer to the method and beneficial effects described in the second aspect above.
[0086] Optionally, the communication device may execute the communication method described in the fifth aspect, which may include a processing unit and a communication unit, wherein:
[0087] a communication unit, configured to receive a first broadcast message;
[0088] a processing unit, configured to generate integrity protection information for the first broadcast message, where the integrity protection information is generated based on a beam index of a beam receiving the first broadcast message;
[0089] The communication unit is further used to send response information to the first broadcast message, where the response information includes the beam index and integrity protection information of the first broadcast message.
[0090] In an optional implementation, the communication unit is further configured to receive a signature period corresponding to the first broadcast message under the beam.
[0091] In an optional embodiment, the processing unit is further configured to encrypt the response information of the first broadcast message to obtain the encrypted response information of the first broadcast message; specifically, the communication unit transmits the encrypted response information of the first broadcast message. This embodiment can improve the security of the response information of the first broadcast message.
[0092] The operations and beneficial effects performed by the communication device can refer to the method and beneficial effects described in the fifth aspect above.
[0093] In the ninth aspect, the present application provides a computer-readable storage medium, which stores instructions. When the computer program or instructions are executed by a communication device, the method shown in any one of the first, second, fourth and fifth aspects or any possible implementation methods thereof is implemented.
[0094] In the tenth aspect, the present application provides a computer program product comprising instructions, which, when a communication device reads and executes the instructions, enables the communication device to perform a method as shown in any one of the first, second, fourth and fifth aspects or any possible implementation thereof.
[0095] In the eleventh aspect, the present application provides a communication system, comprising at least one communication device for executing the method described in the seventh aspect, and at least one communication device for executing the method described in the eighth aspect.
[0096] In a twelfth aspect, the present application provides a circuit, coupled to a memory, configured to execute the method as described in any one of the first, second, fourth, and fifth aspects or any possible implementation thereof. The circuit may include a chip circuit. BRIEF DESCRIPTION OF THE DRAWINGS
[0097] FIG1 is a schematic diagram of a communication scenario in which a fake base station fakes a broadcast message;
[0098] FIG2 is a schematic diagram of a beam scanning scenario for a broadcast message;
[0099] FIG3 is a schematic diagram of generating integrity protection information for a broadcast message according to an embodiment of the present application;
[0100] FIG4 is a schematic diagram of generating integrity protection information for multiple broadcast messages provided in an embodiment of the present application;
[0101] FIG5 is a schematic diagram of an embodiment of the present application providing a method for independently configuring signature periods for broadcast messages under different beams and for jointly signing different broadcast messages under the same beam;
[0102] FIG6 is a flow chart of a broadcast message protection method 100 provided in an embodiment of the present application;
[0103] FIG7 is a flow chart of a broadcast message protection method 101 provided in an embodiment of the present application;
[0104] FIG8 is a flow chart of a broadcast message protection method 200 provided in an embodiment of the present application;
[0105] FIG9 is a flow chart of a broadcast message protection method 201 provided in an embodiment of the present application;
[0106] FIG10 is a flow chart of a broadcast message protection method 300 provided in an embodiment of the present application;
[0107] FIG11 is a schematic structural diagram of a communication device provided in an embodiment of the present application;
[0108] FIG12 is a schematic structural diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0109] In the embodiments of the present application, the network device may also be referred to as an access network device. The access network device may be a device that provides wireless access for a terminal device, and may include a radio access network (RAN) device and an access node (AN) device. RAN devices are mainly wireless network devices in a 3GPP network, and AN devices may be access network devices that are not defined by 3GPP. RAN devices are mainly responsible for wireless resource management, quality of service (QoS) management, data compression and encryption, and other functions on the air interface side. RAN devices may include various forms of base stations, such as macro base stations, micro base stations (also referred to as small stations), relay stations, access points, balloon stations, and the like. In systems using different radio access technologies, the names of devices with base station functions may vary. For example, in long-term evolution (LTE) systems, fifth-generation (5G), sixth-generation (6G), and even seventh-generation (7G) systems, network devices may be called: RAN or next-generation Node basestation (gNB), evolved NodeB (eNB or eNodeB), base station controller (BSC), base transceiver station (BTS), home network device (e.g., home evolved Node B or home Node B, HNB), baseband unit (BBU), access point (AP) in wireless fidelity (WIFI) systems, wireless relay node, wireless backhaul node, transmission and reception point (TRP), transmission point (TP) point, TP), etc.; or one or a group of (including multiple antenna panels) antenna panels of a network device in a 5G system, or it can also be a network node constituting a gNB or transmission point, such as a baseband unit (BBU), or a distributed unit (DU), or a road side unit (RSU) in a vehicle to everything (V2X) or intelligent driving scenario.
[0110] In some deployments, a gNB or transmission point may include a centralized unit (CU) and a DU. A gNB or transmission point may also include a radio unit (RU). The CU implements some of the gNB or transmission point's functions, while the DU implements some of the gNB or transmission point's functions. For example, the CU implements radio resource control (RRC) and packet data convergence protocol (PDCP) layer functions, while the DU implements radio link control (RLC), media access control (MAC), and physical (PHY) layer functions. Because RRC layer information ultimately becomes physical layer information, or is converted from physical layer information, in this architecture, higher-layer signaling, such as RRC layer signaling or PDCP layer signaling, can also be considered to be sent by the DU, or by both the DU and the RU. It is understood that a network device can be a CU node, a DU node, or a device that includes both a CU node and a DU node. Optionally, the network device can also be an auxiliary communication device, such as a satellite.
[0111] In the embodiments of the present application, a terminal device is a device with wireless transceiver capabilities that can be deployed on land, including indoors or outdoors, handheld, wearable, or vehicle-mounted; can also be deployed on water (such as ships); and can also be deployed in the air (such as airplanes, balloons, and satellites). The terminal can be a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal in industrial control, a vehicle-mounted terminal device, a wireless terminal in self-driving, a wireless terminal in remote medical care, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, a wearable terminal device, and the like. A terminal may also be sometimes referred to as terminal equipment, user equipment (UE), access terminal equipment, vehicle-mounted terminal, industrial control terminal, UE unit, UE station, mobile station, mobile station, remote station, remote terminal equipment, mobile device, UE agent, or UE device, etc. A terminal may also be fixed or mobile.
[0112] The present application can be applied to communication systems of various radio access technologies (RATs), such as LTE communication systems, 5G (or new radio (NR)) communication systems, or transition systems between LTE communication systems and 5G communication systems, which transition systems can also be called 4.5G communication systems. Of course, they can also be future communication systems, such as the sixth generation (6G) or even the seventh generation (7G) system. The network architecture and service scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. It is known to those skilled in the art that with the evolution of communication network architectures and the emergence of new service scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0113] In order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit them to be different. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent three situations: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the related objects before and after are in an "or" relationship.
[0114] In wireless communication technology, broadcast messages sent over the air interface of network devices are intended for all terminals within the cell's coverage area. Therefore, these messages cannot be encrypted using user-level symmetric keys. During the initial network access phase, terminals must first receive system messages broadcast over the air interface of network devices before establishing a communication connection. During cell search and synchronization, terminals must also receive system messages broadcast over the air interface of network devices before initiating random access, accessing the cell, and operating normally within it.
[0115] Therefore, if the broadcast messages sent by network devices over the air interface lack any security protection, they will cause significant losses to users. For example, if system messages lack any security protection, then system messages sent by legitimate base stations can easily be stolen and counterfeited by fake base stations. As shown in the communication scenario of a fake base station counterfeiting broadcast messages in Figure 1, fake base station 101 can first complete frequency and time synchronization with legitimate base station 102, then counterfeit a specific system message from legitimate base station 102 and send the counterfeit system message at a higher power, causing terminal device 103 to be attracted and deceived by fake base station 101. In this way, fake base station 101 can steal user privacy information from terminal device 103, or cause terminal device 103 to malfunction. Or, because fake base station 101 tampers with important fields in the counterfeit system message, terminal device 103's calling capability may be disabled, resulting in the inability to receive network called services, or the inability to access the Internet, send text messages, or make phone calls for a long time. Therefore, how to provide security protection for broadcast messages sent over the air interface of network devices is an urgent problem to be solved.
[0116] This application provides a broadcast message protection method based on the beam scanning scenario, which can generate integrity protection information of the broadcast message in the corresponding beam direction based on the beam index to improve the security of the broadcast message that needs security protection.
[0117] To facilitate understanding of the present application, some concepts involved in the embodiments of the present application are explained below.
[0118] 1. Broadcast Message
[0119] In this application, messages sent by broadcast over the air interface between a network device and a terminal device are collectively referred to as broadcast messages. For example, system messages and paging messages transmitted between a network device and a terminal device are sent by broadcast, that is, broadcast messages can be system messages or paging messages. Among them, the system message can be a Master Information Block (MIB) or a System Information Block (SIB). Among them, MIB+SIB1 is called Minimum System Information (MSI), and other system information outside MIB and SIB1, such as SIB2 to SIB12, is called Other System Information Blocks (OSI). SIB1 is also called Remaining Minimum System Information (RMSI).
[0120] Among them, the MIB carries the necessary information for the terminal device to access the network, such as the system frame number (SFN) used for time synchronization between the terminal device and the network side, the subcarrier spacing, and the parameter configuration of the DCI that indicates the scheduling of SIB1. The MIB message is carried on the physical broadcast channel (PBCH). The primary synchronization signal PSS, the secondary synchronization signal SSS and the broadcast channel PBCH form a synchronization signal block (SSB) and are sent together. One SSB occupies 20 resource blocks (RBs) in the frequency domain and 4 symbols in the time domain. Among them, the symbol can be an orthogonal frequency division multiplexing (OFDM) symbol, and one RB contains 12 subcarriers.
[0121] SIB1 carries cell access information, OSI scheduling information, and access restriction parameters. OSI generally includes the current cell's residency parameters, reselection parameters, and parameters such as intra-frequency, inter-frequency, and inter-system neighboring cells, which are not detailed here. SIB1 and OSI are transmitted on the Physical Downlink Shared Channel (PDSCH), and the RBs (or frequency domain locations) occupied by the PDSCH for transmitting SIB1 and OSI are dynamically scheduled.
[0122] 2. Transmission cycle
[0123] In this application, broadcast messages are periodically transmitted based on a transmission period. In this application, the transmission period of a broadcast message refers to the transmission period of the broadcast message at Layer 1. In this application, the transmission period of an MIB or SIB1 refers to the repeated transmission period of the MIB or SIB1 at Layer 1; the scheduled transmission period of an MIB or SIB1 refers to the transmission period of the system information at Layer 3. For example, within each scheduled transmission period, the RRC layer message content of the MIB or SIB1 remains unchanged. For example, the scheduled transmission period of an MIB is 80ms, and the MIB can be repeatedly transmitted at a period of 20ms within 80ms, that is, it can be repeatedly transmitted four times within 80ms, that is, the repetition period is 20ms. For another example, the scheduled transmission period of SIB1 is 160ms, and the repetition period is 20ms, that is, the SIB1 can be repeatedly transmitted at a period of 20ms within 160ms. Optionally, for other SIBs, if repetition is not required at Layer 1, then the transmission period of the other SIB is equal to the scheduled transmission period of Layer 3.
[0124] Optionally, the network device can configure the SSB period to 5ms, 10ms, 20ms, 40ms, 80ms, or 160ms through the "ssb-periodicityServingCell" element in the system information. The SSB period is the SSB beam scanning period, during which multiple SSBs are sent, each corresponding to a different beam direction, to complete beam scanning.
[0125] 3. Beam scanning
[0126] In this application, the broadcast message is sent in a beam scanning manner. Beam scanning means that within a specific period or time period, the beam is sent and / or received in a pre-set direction to cover a specific spatial area. For example, the schematic diagram of the beam scanning scenario shown in Figure 2 takes the broadcast message as an SSB as an example. Assuming that the beam scanning set of the SSB is configured with 8 SSBs, each SSB corresponds to an SSB beam or an SSB resource block. From the time domain point of view, within the half frame of 5ms of each SSB transmission period, the network device will send an SSB under each SSB beam and send 8 SSBs, such as SSB0 to SSB7. That is, the network device uses beam scanning to send 8 SSBs in different beam directions to complete the beam scanning of the entire cell coverage. When a terminal device moves within the system, it continuously searches and measures cells based on the SSB, selects the appropriate SSB beam, and after parsing an SSB, obtains information such as the cell identifier, system frame number (SFN), and the SSB index of the parsed SSB, enabling initial access and mobility management for the terminal device. The SSB index can be used as a beam index. One SSB refers to one SSB resource block or one SSB beam corresponding to one SSB index.
[0127] This application provides a broadcast message protection method 100 based on the beam scanning scenario. The network device can generate and send integrity protection information of the broadcast message based on the beam index of the beam that sends the broadcast message. Correspondingly, the terminal device can receive the integrity protection information of the broadcast message. In addition, the terminal device verifies the integrity protection information according to the beam index of the beam that receives the broadcast message, and obtains the verification result of the integrity protection information of the broadcast message, such as identifying whether the broadcast message is secure or whether it comes from a legitimate base station. It can be seen that the broadcast message protection method 100 uses the beam index as an input parameter of the algorithm for generating integrity protection information. On the one hand, it can protect broadcast messages at the beam granularity, and on the other hand, it can prevent broadcast messages of different beams from being replayed, thereby improving the security of broadcast messages.
[0128] Based on the beam scanning scenario, the present application also provides a broadcast message protection method 200, in which a network device sends a broadcast message, a terminal device receives the broadcast message, and generates integrity protection information of the broadcast message based on the beam index of the beam receiving the broadcast message; the terminal device sends response information of the broadcast message, and the response information includes the beam index and the integrity protection information; the network device receives the response information of the broadcast message, and verifies the integrity protection information based on the broadcast message and the beam index to obtain the verification result of the integrity protection information of the broadcast message. It can be seen that the broadcast message protection method 200 enables the network device to identify whether there is a fake base station attack in the beam direction, such as the fake base station tampering with the content of the broadcast message, thereby improving the security of the broadcast message.
[0129] Based on the beam scanning scenario, the present application also provides a broadcast message protection method 300, which may include the broadcast message protection method 100 and the broadcast message protection method 200. For a broadcast message for which the network device does not send integrity protection information, after receiving the broadcast message, the terminal device may choose to generate integrity protection information for the broadcast message, so that the network device verifies the integrity protection information, obtains the verification result of the integrity protection information of the broadcast message, and promptly identifies whether there is a fake base station attack in the beam direction, such as tampering with the content of the broadcast message by the fake base station; for a broadcast message for which the network device sends integrity protection information, the terminal device may promptly report the verification result, so that the network device promptly knows whether the broadcast message received by the terminal device is safe, thereby improving the security of the broadcast message.
[0130] Optionally, in this application, the network device may also transmit the signature period corresponding to the broadcast message in the beam. The signature period corresponding to the broadcast message in the beam is the transmission period of the integrity protection information of the broadcast message in the beam. In this way, this application transmits the integrity protection information of the broadcast message in the signature period, which can reduce the air interface time and frequency resource overhead caused by the integrity protection information.
[0131] Optionally, in this application, the network device may adjust the signature period corresponding to the broadcast message in the beam based on the verification result of the integrity protection information of the broadcast message in the beam. In this way, the network device can shorten the signature period on the beam where the fake base station exists to improve the security of the broadcast message, and increase the signature period on the beam where the fake base station does not exist to reduce the air interface time and frequency resource overhead.
[0132] Optionally, the broadcast message protection method described in this application for a broadcast message under one beam may be applicable to some or all of the multiple scanning beams configured for the broadcast message, and this application does not limit this.
[0133] Optionally, the security algorithms used to obtain integrity protection information can be divided into two categories: symmetric schemes and asymmetric schemes. Among them, the symmetric scheme uses a symmetric key for integrity protection, that is, the key used to generate the integrity protection information is the same as the key used to verify the integrity protection information. The integrity protection information can be a hash (HASH) value or a message authentication code for integrity (MAC-I); the security algorithms of the symmetric scheme may include but are not limited to message authentication algorithms such as Hash-based Message Authentication Code-Security Hash Algorithm (HMAC-SHA)2 and HMAC-SHA3, or post-quantum algorithms.
[0134] Asymmetric schemes use asymmetric keys for integrity protection. This means that the key used to generate integrity-protected information differs from the key used to verify it. For example, network devices use the base station's private key to generate integrity-protected information, while terminal devices verify the integrity-protected information using a master public key and the base station's public key from the network device. The core network device generates a pair of master public keys (MPKs) and master private keys (MSKs). The master private key is securely stored within the core network device, and the master public key is securely distributed to the terminal device. The master public key can be pre-installed in the terminal device at the factory. After the network device and the core network device perform mutual authentication based on the Internet Protocol Security (IPsec), the network device sends a request message to the core network device. The request message includes the base station's public key and requests the base station's private key corresponding to the base station's public key. The base station's public key consists of a base station identifier and a validity period. Upon receiving the request message, the core network device generates a base station private key for the base station based on the base station's public key and the locally stored master private key, and sends the base station private key to the network device. In asymmetric schemes, the integrity protection information can be a digital signature (DS). Asymmetric schemes are mainly divided into two categories: one is a signature protection scheme based on digital certificates or public key infrastructure (PKI), in which the integrity protection information needs to carry a digital signature and digital certificate; the other is a signature protection scheme based on identity identifiers, in which the integrity protection information needs to carry a digital signature and identity identifier. The secure signature algorithm of an asymmetric scheme may include but is not limited to the Elliptic Curve Digital Signature Algorithm (ECDSA), or classical cryptographic algorithms such as RSA proposed by Ron Rivest, Adi Shamir, and Leonard Adleman, or post-quantum cryptographic algorithms such as lattice-based algorithms.
[0135] Optionally, the integrity protection information of the broadcast message is generated not only based on the beam index of the beam that sends or receives the broadcast message, but also based on one or more of the following information of sending or receiving the broadcast message: timestamp, downlink frequency and cell identifier. Optionally, the broadcast message sent by the network device and the integrity protection information of the broadcast message can be sent together, or can be sent relatively independently, such as by defining another message to transmit the integrity protection information of the broadcast message. Optionally, the broadcast message sent by the network device can carry not only the integrity protection information, but also the beam index and one or more of the above-mentioned information. These information can be called anti-replay parameters, which are used by the terminal device to determine whether the broadcast message is a replay message.
[0136] For example, please refer to Figure 3, which is a structural diagram of a broadcast message to be sent provided by an embodiment of the present application. Figure 3 takes a broadcast message carrying integrity protection information as an example. As shown in Figure 3, when sending the broadcast message, not only the broadcast message itself and its integrity protection information are carried, but also the beam index, downlink frequency and cell identifier (such as physical cell identifier) and timestamp of the beam that sends or receives the broadcast message are carried. Generating integrity protection information based on the security algorithm can be: using the broadcast message, timestamp, downlink frequency and cell identifier, the beam index of the beam that sends or receives the broadcast message, and the key as inputs to the security algorithm to obtain integrity protection information. The broadcast message itself carried by the broadcast message to be sent, or the broadcast message itself input by the security algorithm, can be the information element of the broadcast message from the upper layer. If the broadcast message is a system message, then the broadcast message itself is the message content of the system message at layer 3, and the other parameters carried by the broadcast message can be parameter information added by the physical layer.
[0137] Optionally, in the present application, in addition to being based on the beam index, the generation of integrity protection information may also be based on other beam index information instead of the beam index, such as other parameters that have a mapping correspondence with the beam index, such as the SSB index, the SFN or time slot corresponding to the broadcast message sent under the beam, the subframe number, etc. Optionally, the cell identifier may be a physical cell identifier (PCI); the downlink frequency may be a downlink absolute radio frequency channel number (DL ARFCN); and the timestamp may include information such as year, month, date, hour, minute, and second (milliseconds or microseconds) corresponding to the transmission time (transmission time interval (TTI), subframe, time slot, minislot, etc.). Optionally, if the time synchronization between the terminal and the network device is accurate to the minute level, it may be possible to choose not to transmit the year / month / day / hour, and only transmit the value of "minute mod 3" and the value of the second to reduce the air interface transmission overhead. In this way, the terminal device side can combine the truncated timestamp and the system frame number sent by the broadcast message to obtain the complete time synchronized with the access network. Optionally, the timestamp can also use a time counter, which is Coordinated Universal Time (UTC), such as seconds or minutes or other. The timestamp or time counter can use the least significant bit (LSB) instead of the full value. Optionally, the timestamp can also use a sequence number.
[0138] Optionally, within the cell coverage, the signature periods corresponding to different scanning beams configured for the broadcast message are independently configured, and the network device adaptively adjusts the signature period of the broadcast message under the corresponding beam based on the verification results or integrity protection information reported by the terminal device.
[0139] Optionally, different broadcast messages with the same or different transmission periods, or different broadcast messages with the same or different transmission periods and the same broadcast transmission strategy, or different broadcast messages with the same or different transmission periods, the same broadcast transmission strategy, and the same signature period, within the same beam, can jointly generate corresponding integrity protection information (also referred to as jointly signed). Optionally, a new element can be added to the broadcast message to indicate the signature period of the broadcast message, or the signature period of the broadcast message can be added to an existing element.
[0140] Optionally, under the same beam, multiple broadcast messages can be jointly generated for integrity protection information, and the signature period corresponding to the multiple broadcast messages is greater than or equal to the maximum transmission period among the transmission periods of the multiple broadcast messages. For example, the scheduling transmission period of SIB1 is 160ms (the RRC layer message content of SIB1 does not change during the scheduling transmission period), and the network device repeats it 8 times within 160ms (in order for different terminal devices to access the base station as quickly as possible and reduce the key indicator of the terminal device's network access delay), that is, the repetition period of the physical layer SIB1 is 20ms. Assuming that the transmission period of SIB2 and SIB4 is 320ms; assuming that the transmission period of SIB5 is 640ms, then, assuming that the network device chooses SIB1, SIB2 and SIB4 to sign jointly, the signature period must be greater than or equal to the maximum value of the transmission periods of SIB1, SIB2 and SIB4, 20ms and 320ms. For example, the minimum signature period can be set to 320ms. Assuming that the network device selects SIB1, SIB2, SIB4 and SIB5 for joint signature, the signature period must be greater than or equal to the maximum value of the SIB1, SIB2, SIB4 and SIB5 transmission periods of 20ms, 320ms and 640ms. For example, the minimum signature period can be set to 640ms.
[0141] Optionally, the integrity protection information jointly generated by multiple broadcast messages can be carried and transmitted in each broadcast message, in one of the broadcast messages, in the last broadcast message (i.e., the broadcast message with the last time domain resource position in the same transmission period among the multiple broadcast messages), or in a separate message. The multiple broadcast messages may also be referred to as jointly signed broadcast messages.
[0142] Please refer to Figure 4, which is a structural diagram of another broadcast message to be sent provided by an embodiment of the present application. Figure 4 takes the transmission of integrity protection information carried in one of the broadcast messages as an example. As shown in Figure 4, for multiple broadcast messages with the same beam index, downlink frequency and cell identifier, integrity protection information can be jointly generated. The difference from the method of generating integrity protection information shown in Figure 3 is that the input of the security algorithm shown in Figure 4 is the jointly signed broadcast message, that is, the multiple broadcast messages. As shown in Figure 4, the use of a security algorithm to generate integrity protection information can be: using the jointly signed broadcast message, timestamp, downlink frequency and cell identifier, beam index and key as input to the security algorithm to obtain.
[0143] For another example, FIG5 is a schematic diagram of an embodiment of the present application, which provides an independently configured broadcast message corresponding to a signature period under different beams and a joint signature of different broadcast messages under the same beam. As shown in FIG5 , assuming that MIB and SIB1 have the same broadcast transmission strategy (such as both are sent in a broadcast manner), the same transmission period and the same signature period, they can be jointly signed. As shown in FIG5 , under the same beam 0, the joint signature of MIB and SIB1 (i.e., the jointly generated integrity protection information) can be carried in a non-critical field in SIB1, or carried in a new information element, or carried in the payload of layer 1 or layer 2 of the SIB1. In addition, under the beam 0, the signature period corresponding to MIB and SIB1 is N 00 ; In the same beam 0, the joint signature of SIB3 and SIB5 (i.e., the jointly generated integrity protection information) can be carried in a non-critical field in SIB5, or carried in a new information element, or carried in the layer 1 or layer 2 payload of the SIB5. In addition, in the beam 0, the signature period of SIB3 and SIB5 is N 01 In the same beam 1, the joint signature of MIB and SIB1 (i.e., the integrity protection information generated jointly) can be carried in a non-critical field in SIB1, or carried in a new information element, or carried in the layer 1 or layer 2 payload of the SIB1. In addition, in the beam 1, the signature period of MIB and SIB1 is not N. 10 ; In the same beam 1, the joint signature of SIB3 and SIB5 (i.e., the jointly generated integrity protection information) can be carried in a non-critical field in SIB5, or carried in a new information element, or carried in the layer 1 or layer 2 payload of the SIB5. In addition, in the beam 1, the signature period of SIB3 and SIB5 is N 11 It can be seen that the network device can independently configure MIB and SIB1 in different beams, such as beam 0 and beam 1, and the corresponding signature period is N 00 、N 10 .
[0144] The following further illustrates the broadcast message protection method provided in the embodiments of the present application in conjunction with the accompanying drawings.
[0145] Please refer to Figure 6, which is a flow chart of a broadcast message protection method 100 provided in an embodiment of the present application. As shown in Figure 6, the broadcast message protection method 100 can generate and send integrity protection information of the broadcast message by a network device. The broadcast message protection method 100 can include but is not limited to the following steps:
[0146] S101. A network device generates integrity protection information for a first broadcast message, where the integrity protection information is generated based on a beam index of a beam that sends the first broadcast message.
[0147] Optionally, the method for the network device to generate integrity protection information for the first broadcast message can be described in any of Figures 3 to 5 and will not be further described here. For example, the integrity protection information generated by the network device using a symmetric scheme can be a HASH value or MAC-I; the integrity protection information generated by the network device using an asymmetric scheme can be a digital signature. Accordingly, the first broadcast message can be a single broadcast message, such as an MIB, or multiple broadcast messages, such as an MIB and SIB1.
[0148] S102. The network device sends integrity protection information of a first broadcast message, and accordingly, the terminal device receives the integrity protection information of the first broadcast message;
[0149] As previously described, the network device may include the integrity protection information in the first broadcast message or transmit it independently of the first broadcast message. This is not further described here. If the network device transmits the first broadcast message for a beam independently of the integrity protection information for the first broadcast message for that beam, the network device must also transmit the integrity protection information for the first broadcast message on the beam.
[0150] S103. The terminal device verifies the integrity protection information according to the beam index of the beam receiving the first broadcast message, and obtains a verification result of the integrity protection information of the first broadcast message.
[0151] Optionally, for a terminal device, the terminal device may be able to receive the first broadcast message under multiple beams, but the integrity protection information verified by the terminal device is the integrity protection information of the first broadcast message under the beam with the largest signal reception strength of the first broadcast message received by the terminal device.
[0152] Optionally, among the input parameters of the security algorithm described in Figures 3 and 4, the timestamp, downlink frequency, cell identifier, and beam index can also be referred to as anti-replay parameters to prevent the broadcast message received by the terminal device from being a replayed message. Accordingly, the network device can send the anti-replay parameters along with the integrity protection information to the terminal device. The terminal device can then verify whether the broadcast message originates from a legitimate base station based on the anti-replay parameters and the integrity protection information.
[0153] In an optional implementation, if the network device uses a symmetric scheme to generate integrity protection information, the terminal device can verify whether the first broadcast message comes from a legitimate base station based on the anti-replay parameters and integrity protection information, as well as the same key and the same security algorithm as the network device side. Specifically, step S103 may include: the terminal device generates integrity protection information based on the received anti-replay parameters (including the beam index), the received first broadcast message, the same key and the same security algorithm; the terminal device verifies whether the generated integrity protection information is consistent with the integrity protection information sent by the network device (that is, whether they are exactly the same). If they are consistent, the verification result of the integrity protection information of the first broadcast message is that the first broadcast message comes from a legitimate base station; if they are inconsistent, the verification result of the integrity protection information of the first broadcast message is that the first broadcast message comes from an illegal base station.
[0154] In another optional implementation, if the network device uses an asymmetric scheme to generate integrity protection information, the terminal device can verify whether the first broadcast message comes from a legitimate base station based on the anti-replay parameter, the integrity protection information, and the existing public key. Specifically, step S103 may include: the terminal device verifies the integrity protection information sent by the network device based on the received anti-replay parameter (including the beam index), the received first broadcast message, the existing public key, and the known identical security algorithm, and obtains a verification result of the integrity protection information of the first broadcast message, such as whether the first broadcast message comes from a legitimate base station or the first broadcast message comes from an illegal base station.
[0155] It can be seen that the broadcast message protection method 100 uses the beam index as the input parameter of the integrity protection information generation algorithm. On the one hand, it can protect the broadcast messages at the beam granularity, and on the other hand, it can prevent the broadcast messages of different beams from being replayed, thereby improving the security of the broadcast messages.
[0156] Please refer to Figure 7, which is a flow chart of a broadcast message protection method 101 provided in an embodiment of the present application. The difference between the broadcast message protection method 101 shown in Figure 7 and the broadcast message protection method 100 shown in Figure 6 is that in the broadcast message protection method 101, the network device can send the signature period corresponding to the broadcast message under the beam, and adjust the signature period corresponding to the broadcast message under the beam based on the verification result of the integrity protection information of the broadcast message under the beam. As shown in Figure 7, the broadcast message protection method 101 may include but is not limited to the following steps:
[0157] S101. A network device generates integrity protection information for a first broadcast message, where the integrity protection information is generated based on a beam index of a beam that sends the first broadcast message.
[0158] S102. The network device sends integrity protection information of a first broadcast message and a signature period corresponding to the first broadcast message. Correspondingly, the terminal device receives the integrity protection information of the first broadcast message and the signature period corresponding to the first broadcast message under the beam.
[0159] As previously mentioned, the signature period can be carried in the first broadcast message, such as in a newly added or existing cell. This will not be detailed here. The integrity protection information for the first broadcast message under this beam can be carried and sent together with the first broadcast message, or sent separately. For terminal devices, the terminal device can periodically receive the integrity protection information for the first broadcast message under the corresponding beam based on the signature period.
[0160] S103. The terminal device verifies the integrity protection information according to the beam index of the beam receiving the first broadcast message, and obtains a verification result of the integrity protection information of the first broadcast message.
[0161] Optionally, the relevant contents of steps S101 to S103 can also be found in the broadcast message protection method 100 described in FIG6 , which will not be described in detail here.
[0162] S104. The terminal device sends response information to the first broadcast message. Correspondingly, the network device receives the response information to the first broadcast message, where the response information includes the beam index and a verification result of the integrity protection information of the first broadcast message.
[0163] Optionally, the terminal device may choose to encrypt the response information and then feed it back to the network device. For example, the terminal device may choose to encrypt the response information using a symmetric key in a radio resource control (RRC) connected state, or choose to encrypt the response information using the base station public key in an RRC disconnected state. Accordingly, the network device needs to use the corresponding key to decrypt the received response information and obtain the verification result of the integrity protection information of the first broadcast message.
[0164] Optionally, the verification result included in the response information may be indication information for indicating the verification result. Optionally, if the verification result is a verification failure, the response information may also include a signature acquisition instruction for requesting the network device to generate and send integrity protection information when sending the broadcast message again on the beam.
[0165] Optionally, the terminal device may use the following signaling to send response information, such as messages in the random access process, message (Message, MSG) 3 (RRC setup request (RRCSetupRequest) message), MSG5 (RRC setup completion (RRCSetupComplete) message), registration request (RegistrationRequest) message, non-access layer identity response (NAS Identity Response) message, authentication response (AuthenticationResponse) message, non-access layer security mode completion (NAS SecurityModeComplete) message, access layer security mode completion (AS SecurityModeComplete) message, measurement report (MeasurementReport) message, etc.; the terminal device may also use a redefined new message type to send response information.
[0166] S105. The network device adjusts the signature period corresponding to the first broadcast message under the beam according to the verification result of the integrity protection information of the first broadcast message.
[0167] Optionally, if the verification result of the integrity protection information of the first broadcast message is that the terminal device identifies that the first broadcast message comes from a legitimate base station or is secure, the signature period corresponding to the first broadcast message under the beam can be increased; if the verification result of the integrity protection information of the first broadcast message is that the terminal device identifies that the first broadcast message comes from an illegal base station or has been tampered with, the signature period corresponding to the first broadcast message under the beam can be reduced.
[0168] Optionally, the network device may also perform statistical analysis on the verification results of the integrity protection information of the first broadcast message under the beam within the statistical period to adaptively adjust the signature period corresponding to the first broadcast message under the beam. For example, if the success rate of the verification results of the integrity protection information of the first broadcast message under the beam is high within the statistical period, the signature period corresponding to the first broadcast message under the beam is increased; if the success rate is low, the signature period corresponding to the first broadcast message under the beam is decreased. Optionally, a high success rate in the verification results of the integrity protection information of the first broadcast message under the beam may mean that the proportion of successful verification results among all verification results within the statistical period is greater than or equal to a threshold; a low success rate in the verification results of the integrity protection information of the first broadcast message under the beam may mean that the proportion of successful verification results among all verification results within the statistical period is less than the threshold. Optionally, the threshold may be preset by the system or indicated by signaling, and is not limited in this application.
[0169] It can be seen that the broadcast message protection method 101 can not only introduce beam index to improve the security of broadcast messages in the beam direction, but also adaptively adjust the signature period corresponding to the broadcast message under the beam, thereby achieving a balance between the security of the broadcast message and the required air interface time and frequency resource overhead.
[0170] Please refer to Figure 8, which is a flow chart of a broadcast message protection method 200 provided in an embodiment of the present application. As shown in Figure 8, the broadcast message protection method 200 can generate and send integrity protection information for a broadcast message by a terminal device. The broadcast message protection method 200 can include but is not limited to the following steps:
[0171] S201: A network device sends a first broadcast message; accordingly, a terminal device receives the first broadcast message;
[0172] S202. The terminal device generates integrity protection information for the first broadcast message, where the integrity protection information is generated based on a beam index of a beam that receives the first broadcast message.
[0173] Optionally, for a terminal device, the terminal device may be able to receive the first broadcast message under multiple beams, but the integrity protection information generated by the terminal device is the integrity protection information of the first broadcast message under the beam with the largest signal reception strength of the first broadcast message received by the terminal device.
[0174] Optionally, the method for the terminal device to generate integrity protection information for the first broadcast message can be found in the relevant content described in any one of Figures 3 to 5, and will not be described in detail here. In addition, in this method, the terminal device uses the symmetric scheme described above to generate integrity protection information for the first broadcast message. The integrity protection information can be a HASH value or MAC-I.
[0175] S203. The terminal device sends response information to the first broadcast message. Correspondingly, the network device receives the response information to the first broadcast message, where the response information includes the beam index of the beam and integrity protection information of the first broadcast message generated by the terminal device.
[0176] Optionally, the terminal device may choose to encrypt the response information and then feed it back to the network device. For example, the terminal device may choose to encrypt the response information using a symmetric key in a radio resource control (RRC) connected state, or choose to encrypt the response information using the base station public key in an RRC disconnected state. Accordingly, the network device may decrypt the response information to obtain the beam index carried in the response information and the integrity protection information of the first broadcast message under the beam.
[0177] Optionally, among the input parameters of the security algorithm used to obtain the integrity protection information, the timestamp, downlink frequency and cell identifier, and beam index can also be called anti-replay parameters. Accordingly, the terminal device can send the anti-replay parameters together with the integrity protection information to the network device. The network device can determine whether the response information of the first broadcast message is a replay message based on the anti-replay parameters. If not, the response information is decrypted.
[0178] The signature period corresponding to the first broadcast message in the beam is the period during which the network device in the beam sends the integrity protection information for the first broadcast message. In other words, the signature period is independent of the period during which the terminal device sends the integrity protection information for the first broadcast message. For example, the terminal device can independently determine whether to report the integrity protection information for the first broadcast message.
[0179] Optionally, when the terminal device receives the broadcast message without integrity protection information, it may carry a signature acquisition indication in the response information to request the network device to generate and send integrity protection information when sending the broadcast message again on the beam.
[0180] Optionally, the terminal device may send response information using the various messages or signaling described above, which will not be described in detail here.
[0181] S204: The network device verifies the integrity protection information according to the first broadcast message and the beam index to obtain a verification result of the integrity protection information of the first broadcast message.
[0182] In this method, the network device verifies whether the first broadcast message comes from a legitimate base station based on anti-replay parameters and integrity protection information, as well as the same key and the same security algorithm as the terminal device side. Specifically, step S204 may include: the network device generates integrity protection information based on the received anti-replay parameters (including the beam index), the first broadcast message sent, the same key and the same security algorithm; the network device verifies whether the generated integrity protection information is consistent with the integrity protection information sent by the terminal device. If they are consistent, the verification result of the integrity protection information of the first broadcast message is that the verification is successful or the first broadcast message received by the terminal device has not been tampered with; if they are inconsistent, the verification result of the integrity protection information of the first broadcast message is that the verification failed or the first broadcast message received by the terminal device has been tampered with.
[0183] It can be seen that the broadcast message protection method 200 uses the beam index as the input parameter of the integrity protection information generation algorithm, which enables the network device to identify whether there is a fake base station attack in the beam direction, such as the content of the broadcast message being tampered with by the fake base station, thereby improving the security of the broadcast message.
[0184] Please refer to Figure 9, which is a flow chart of a broadcast message protection method 201 provided in an embodiment of the present application. The difference between the broadcast message protection method 201 shown in Figure 9 and the broadcast message protection method 200 shown in Figure 8 is that in the broadcast message protection method 201, the network device can send the signature period corresponding to the broadcast message under the beam, and adjust the signature period corresponding to the broadcast message under the beam based on the verification result of the integrity protection information of the broadcast message under the beam. As shown in Figure 9, the broadcast message protection method 201 may include but is not limited to the following steps:
[0185] S201. A network device sends a first broadcast message and a signature period corresponding to the first broadcast message. Correspondingly, a terminal device receives the first broadcast message and the signature period corresponding to the first broadcast message.
[0186] As mentioned above, the signature period corresponding to the first broadcast message under the beam can be carried in the first broadcast message, which will not be described in detail here.
[0187] S202. The terminal device generates integrity protection information for the first broadcast message, where the integrity protection information is generated based on a beam index of a beam that receives the first broadcast message.
[0188] S203. The terminal device sends response information to the first broadcast message. Correspondingly, the network device receives the response information to the first broadcast message, where the response information includes a beam index of a beam used by the terminal device to receive the first broadcast message, and integrity protection information of the first broadcast message generated by the terminal device based on the beam index.
[0189] S204: The network device verifies the integrity protection information according to the first broadcast message and the beam index to obtain a verification result of the integrity protection information of the first broadcast message.
[0190] Optionally, the relevant description of steps S201 to S204 can be found in the broadcast message protection method 200 described in FIG8 , which will not be described in detail here.
[0191] S205. The network device adjusts the signature period corresponding to the first broadcast message under the beam according to the verification result of the integrity protection information of the first broadcast message.
[0192] Accordingly, the network device may send the adjusted signature period corresponding to the first broadcast message under the beam; accordingly, the terminal device receives the adjusted signature period corresponding to the first broadcast message under the beam.
[0193] Optionally, the network device may also perform statistical analysis on the verification results of the integrity protection information of the first broadcast message in the beam during the statistical period to adaptively adjust the signature period corresponding to the first broadcast message in the beam. For example, if the verification success rate of the integrity protection information verification results of the first broadcast message in the beam during the statistical period is high, the signature period corresponding to the first broadcast message in the beam is increased; if the verification success rate is low, the signature period corresponding to the first broadcast message in the beam is decreased.
[0194] It can be seen that the broadcast message protection method 201 can not only introduce the beam index to generate integrity protection information by the terminal device, so that the network device can identify whether there is a fake base station attack in the beam direction, such as the content of the broadcast message is tampered with by the fake base station, but also the network device can adjust the signature period of the integrity protection information of the first broadcast message sent under the beam, so as to achieve a balance between the security of the broadcast message and the required air interface time and frequency resource overhead.
[0195] Please refer to Figure 10, which is a flow chart of a broadcast message protection method 300 provided in an embodiment of the present application. As shown in Figure 10, the broadcast message protection method 300 can not only generate and send integrity protection information of the broadcast message by the network device, but also generate and send integrity protection information of the broadcast message by the terminal device. Taking the same broadcast message under the same beam i, the network device sends it at different times as an example. Assume that the broadcast message P (such as the system message SIB1) at different sending times j, k, and m can be represented as broadcast messages P(j), P(k), and P(m), respectively. The signature periods carried by the broadcast messages P(j), P(k), and P(m) may be different, represented as Period(j), Period(k), and Period(m), respectively. Among them, the broadcast message protection method 300 may include but is not limited to the following steps:
[0196] S301: At time j, a network device sends a broadcast message P(j) under beam i. Correspondingly, a terminal device receives the broadcast message P(j).
[0197] Here, it is assumed that the terminal device receives the broadcast message in each beam direction, and the signal strength on beam i is the largest. In addition, the broadcast message P(j) carries the signature period Period(j).
[0198] S302. The terminal device generates integrity protection information Int(j) for the broadcast message P(j), where the integrity protection information Int(j) is generated based on the beam index of the beam i that receives the broadcast message P(j).
[0199] Among them, the method for the terminal device to generate the integrity protection information Int(j) of the broadcast message P(j) can be referred to the symmetric solution described above and will not be described in detail here.
[0200] S303: The terminal device sends response information Resp(j) to the broadcast message P(j). Correspondingly, the network device receives the response information Resp(j) to the broadcast message P(j). The response information Resp(j) includes the beam index of the beam i and the integrity protection information Int(j) of the broadcast message P(j).
[0201] S304: The network device verifies the integrity protection information Int(j) according to the sent broadcast message P(j) and the beam index of the beam i, and obtains a verification result check(j) of the integrity protection information Int(j) of the broadcast message P(j).
[0202] S305. The network device adjusts the signature period Period(j) corresponding to the broadcast message under the beam i to the signature period Period(k) according to the check result check(j) of the integrity protection information Int(j) of the broadcast message P(j).
[0203] Optionally, in step S305, the network device may adjust the signature period based on the verification result of the integrity protection information of the broadcast message P within the statistical period between time j and time k, to obtain the signature period Period(k) required to carry the broadcast message P(k) sent under beam i at time k.
[0204] S306. The network device sends a broadcast message P(k) under beam i at time k. Correspondingly, the terminal device receives the broadcast message P(k).
[0205] The broadcast message P(k) carries the signature period Period(k) and the complete information protection information Int(k) generated by the network device for the broadcast message P(k). Assume that the terminal device receives the broadcast message in each beam direction, and the signal strength on beam i is the largest.
[0206] S307. The terminal device verifies the integrity protection information Int(k) according to the beam index of the beam i receiving the broadcast message P(k), and obtains a verification result check(k) of the integrity protection information Int(k) of the broadcast message P(k).
[0207] S308. The terminal device sends response information Resp(k) to the broadcast message P(k), and the network device receives the response information Resp(k) to the broadcast message P(k). The response information Resp(k) includes the beam index of the beam i and the check result check(k) of the integrity protection information Int(k) of the broadcast message P(k).
[0208] S309. The network device sends a broadcast message P(m) under beam i at time m, and correspondingly, the terminal device receives the broadcast message P(m).
[0209] The broadcast message P may be sent based on a self-configured transmission period, and is not limited to the three broadcast messages P(i) to P(m) shown in the example of FIG. 10 .
[0210] The broadcast message P(m) carries the signature period Period(m) and the complete information protection information Int(m) generated by the network device for the broadcast message P(m); alternatively, the broadcast message P(m) carries the signature period Period(m) but does not carry the complete information protection information Int(m) for the broadcast message P(m). Assume that the terminal device receives the broadcast message in each beam direction with the highest signal strength on beam i.
[0211] It can be seen that in the broadcast message protection method 300, for the broadcast message P(j) for which the network device does not send integrity protection information, the terminal device can choose to generate integrity protection information Int(j) of the broadcast message P(j) after receiving the broadcast message P(j), so that the network device can verify the integrity protection information Int(j), obtain the verification result check(j) of the complete information protection information Int(j) of the broadcast message P(j), and promptly identify whether there is a fake base station attack in the beam direction, such as the content of the broadcast message being tampered with by the fake base station; for the broadcast message P(k) for which the network device sends integrity protection information Int(k), the terminal device can promptly report the verification result check(k), so that the network device can promptly know whether the broadcast message P under the beam is safe, thereby improving the security of the broadcast message.
[0212] It is understood that in order to implement the functions in the above embodiments, the network devices and terminal devices include hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily appreciate that, in combination with the units and method steps of each example described in the embodiments disclosed in this application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a manner driven by computer software depends on the specific application scenario and design constraints of the technical solution.
[0213] Figures 11 and 12 are schematic diagrams of the structures of possible communication devices provided in embodiments of the present application. These communication devices can be used to implement the functions of the network device or terminal device in the above-mentioned method embodiments, and thus can also achieve the beneficial effects possessed by the above-mentioned method embodiments. In the embodiments of the present application, the communication device can be any possible terminal device with wireless transceiver functions as described above, or any possible network device capable of providing wireless access for the terminal device as described above, or a module (such as a chip) applied to the network device or terminal device.
[0214] As shown in FIG11 , the communication device includes a processing unit 410 and a communication unit 420. The communication device is used to implement the functions of the network device or terminal device in any of the embodiments shown in FIG3 to FIG10 and their implementation methods. For example:
[0215] When the communication device is used to implement the function of the network device in the method embodiment shown in FIG6 or FIG7:
[0216] The processing unit 410 is used to generate integrity protection information of the first broadcast message, where the integrity protection information is generated based on the beam index of the beam that sends the first broadcast message; the communication unit 420 is used to send the integrity protection information of the first broadcast message.
[0217] In an optional embodiment, the communication unit 420 is also used to send the signature period corresponding to the first broadcast message under the beam, and the signature period corresponding to the first broadcast message under the beam is the sending period of the integrity protection information of the first broadcast message under the beam.
[0218] In an optional embodiment, the communication unit 420 is also used to receive response information of the first broadcast message, and the response information includes the beam index and the verification result of the integrity protection information of the first broadcast message; the processing unit 410 is also used to adjust the signature period corresponding to the first broadcast message under the beam according to the verification result of the integrity protection information of the first broadcast message.
[0219] In an optional embodiment, the response information of the first broadcast message also includes an anti-replay parameter. Accordingly, the processing unit 410 uses the anti-replay parameter to verify whether the response information of the first broadcast message is a replay message; if it is not a replay message, the operation of adjusting the signature period corresponding to the first broadcast message under the beam is executed based on the verification result of the integrity protection information of the first broadcast message.
[0220] In an optional implementation, the response information of the first broadcast message is encrypted, and the processing unit 410 is further configured to decrypt the response information of the first broadcast message to obtain a verification result of the integrity protection information of the first broadcast message.
[0221] When the communication device is used to implement the functions of the terminal device in the method embodiment shown in FIG6 or FIG7:
[0222] The communication unit 420 is used to receive the integrity protection information of the first broadcast message; the processing unit 410 is used to verify the integrity protection information according to the beam index of the beam receiving the first broadcast message to obtain the verification result of the integrity protection information of the first broadcast message.
[0223] In an optional embodiment, the communication unit 420 is also used to receive the signature period corresponding to the first broadcast message under the beam, and the signature period corresponding to the first broadcast message under the beam is the sending period of the integrity protection information of the first broadcast message sent by the network device under the beam.
[0224] In an optional embodiment, the communication unit 420 is also used to send response information to the first broadcast message, and the response information includes the beam index and the verification result of the integrity protection information of the first broadcast message; wherein, the verification result of the integrity protection information of the first broadcast message is used by the network device to adjust the signature period corresponding to the first broadcast message under the beam.
[0225] In an optional implementation, the processing unit 410 verifies the integrity protection information according to the beam index of the beam receiving the first broadcast message to obtain the verification result of the integrity protection information of the first broadcast message. Specifically, the processing unit 410 verifies the integrity protection information according to the timestamp, downlink frequency, cell identifier and beam index of the beam receiving the first broadcast message to obtain the verification result of the integrity protection information of the first broadcast message.
[0226] In an optional implementation, the processing unit 410 further encrypts the response information of the first broadcast message to obtain the encrypted response information of the first broadcast message; correspondingly, the communication unit 420 specifically sends the encrypted response information of the first broadcast message.
[0227] A more detailed description of the processing unit 410 and the communication unit 420 can be directly obtained by referring to the relevant description in the method embodiment shown in Figure 6 or Figure 7, and will not be repeated here.
[0228] When the communication device is used to implement the function of the network device in the method embodiment shown in FIG8 or FIG9:
[0229] The communication unit 420 is used to send a first broadcast message; the communication unit 420 is also used to receive response information of the first broadcast message, the response information including the beam index of the beam for receiving the first broadcast message by the terminal device, and the integrity protection information of the first broadcast message generated by the terminal device based on the beam index; the processing unit 410 is used to verify the integrity protection information according to the first broadcast message and the beam index to obtain a verification result of the integrity protection information of the first broadcast message.
[0230] In an optional embodiment, the processing unit 410 is also used to adjust the signature period corresponding to the first broadcast message under the beam based on the verification result of the integrity protection information of the first broadcast message; wherein, the signature period corresponding to the first broadcast message under the beam is the sending period of the integrity protection information of the first broadcast message sent by the network device under the beam.
[0231] In an optional implementation, the communication unit 420 is further configured to send a signature period corresponding to the first broadcast message under the beam.
[0232] In an optional implementation, the processing unit 410 verifies the integrity protection information based on the first broadcast message and the beam index to obtain a verification result of the integrity protection information of the first broadcast message, specifically: based on the first broadcast message and the timestamp, downlink frequency, cell identifier and beam index of sending the first broadcast message, the integrity protection information is verified to obtain a verification result of the integrity protection information of the first broadcast message.
[0233] In an optional embodiment, the response information also includes an anti-replay parameter. Accordingly, the processing unit 410 uses the anti-replay parameter to verify whether the response information of the first broadcast message is a replay message; if it is not a replay message, the operation of verifying the integrity protection information based on the first broadcast message and the beam index to obtain the verification result of the integrity protection information of the first broadcast message is performed.
[0234] In an optional implementation, the response information is encrypted, and the processing unit 410 needs to decrypt the response information of the first broadcast message to obtain the beam index and the integrity protection information of the first broadcast message.
[0235] When the communication device is used to implement the functions of the terminal device in the method embodiment shown in FIG8 or FIG9:
[0236] The communication unit 420 is used to receive a first broadcast message; the processing unit 410 is used to generate integrity protection information for the first broadcast message, where the integrity protection information is generated based on the beam index of the beam that receives the first broadcast message; the communication unit 420 is also used to send response information to the first broadcast message, where the response information includes the beam index and the integrity protection information of the first broadcast message.
[0237] In an optional implementation, the communication unit 420 is further configured to receive a signature period corresponding to the first broadcast message under the beam.
[0238] In an optional implementation, the processing unit 410 is further configured to encrypt the response information of the first broadcast message to obtain the encrypted response information of the first broadcast message; specifically, the communication unit 420 sends the encrypted response information of the first broadcast message.
[0239] A more detailed description of the processing unit 410 and the communication unit 420 can be directly obtained by referring to the relevant description in the method embodiment shown in Figure 8 or Figure 9, and will not be repeated here.
[0240] When the communication device is used to implement the function of the network device in the method embodiment shown in FIG10 :
[0241] The communication unit 420 is configured to send a broadcast message P(j) under beam i at time j; the communication unit 420 is further configured to receive response information Resp(j) to the broadcast message P(j), where the response information j includes the beam index of the beam i and the integrity protection information Int(j) of the broadcast message P(j); the processing unit 410 is configured to verify the integrity protection information Int(j) based on the sent broadcast message P(j) and the beam index of the beam i, and obtain a verification result j of the integrity protection information Int(j) of the broadcast message P(j); the processing unit 410 is further configured to verify the integrity protection information Int(j) of the broadcast message P(j) based on the integrity protection information Int(j) of the broadcast message P(j). , adjusts the signature period Period(j) corresponding to the broadcast message under the beam i to the signature period Period(k) based on the verification result; the communication unit 420 is further used to send a broadcast message P(k) under beam i at time k, and the broadcast message P(k) carries the signature period Period(k) and the integrity information protection information Int(k) of the broadcast message P(k) generated by the network device; the communication unit 420 is also used to receive the response information Resp(k) of the broadcast message P(k), and the response information Resp(k) includes the beam index of the beam i and the verification result check(k) of the integrity protection information Int(k) of the broadcast message P(k).
[0242] When the communication device is used to implement the functions of the terminal device in the method embodiment shown in FIG10 :
[0243] The communication unit 420 is configured to receive a broadcast message P(j) under beam i at time j; the processing unit 410 is configured to generate integrity protection information for the broadcast message P(j), where the integrity protection information is generated based on the beam index of the beam i receiving the broadcast message P(j); the communication unit 420 is further configured to send response information Resp(j) of the broadcast message P(j), where the response information Resp(j) includes the beam index of the beam i and the integrity protection information Int(j) of the broadcast message P(j); the communication unit 420 is further configured to receive the broadcast message P(k), where the broadcast message P(k) carries a signature period Perio d(k) and the integrity information protection information Int(k) of the broadcast message P(k) generated by the network device; the processing unit 410 is further used to verify the integrity protection information Int(k) according to the beam index of the beam i that receives the broadcast message P(k), and obtain the verification result check(k) of the integrity protection information Int(k) of the broadcast message P(k); the communication unit 420 is further used to send the response information Resp(k) of the broadcast message P(k), and the response information Resp(k) includes the beam index of the beam i and the verification result check(k) of the integrity protection information Int(k) of the broadcast message P(k).
[0244] A more detailed description of the processing unit 410 and the communication unit 420 can be directly obtained by referring to the relevant description in the method embodiment shown in FIG10 , and is not repeated here.
[0245] As shown in Figure 12, the communication device includes a processor 510 and an interface circuit 520. The processor 510 and the interface circuit 520 are coupled to each other. It is understood that the interface circuit 520 can be a transceiver or an input / output interface. Optionally, the communication device may further include a memory 530 for storing instructions executed by the processor 510, input data required by the processor 510 to execute instructions, or data generated by the processor 510 after executing instructions.
[0246] When the communication device is used to implement any one of the methods shown in FIG. 6 to FIG. 10 , the processor 510 is used to implement the functions of the processing unit 410 , and the interface circuit 520 is used to implement the functions of the communication unit 420 .
[0247] When the communication device is a chip used in a terminal device, the chip implements the functions of the terminal device in the above method embodiments. The chip receives information from other modules in the terminal device (such as a radio frequency module or antenna), and the information is sent by the network device to the terminal device; or the chip sends information to other modules in the terminal device (such as a radio frequency module or antenna), and the information is sent by the terminal device to the network device.
[0248] When the above-mentioned communication device is a module applied to a network device, the module implements the functions of the network device in the above-mentioned method embodiment. The module receives information from other modules in the network device (such as a radio frequency module or an antenna), and the information is sent by the terminal device to the network device; or the module sends information to other modules in the network device (such as a radio frequency module or an antenna), and the information is sent by the network device to the terminal device. The module here can be a baseband chip of the network device, or a distributed unit (DU) or other module. The DU here can be a DU under the open radio access network (O-RAN) architecture.
[0249] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0250] The method steps in the embodiments of the present application can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a base station or a terminal. Of course, the processor and the storage medium can also exist in a base station or a terminal as discrete components.
[0251] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are performed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.
[0252] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0253] It is understood that the various numbers used in the embodiments of this application are merely for ease of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily imply a specific order of execution; the order of execution of the processes should be determined by their functions and inherent logic.
Claims
1. A broadcast message protection method, characterized in that: The method comprises: Generating integrity protection information for a first broadcast message, where the integrity protection information is generated based on a beam index of a beam that sends the first broadcast message; Send integrity protection information of the first broadcast message.
2. The method according to claim 1, characterized in that The method further comprises: The signature period corresponding to the first broadcast message under the beam is sent, and the signature period corresponding to the first broadcast message under the beam is the sending period of the integrity protection information of the first broadcast message under the beam.
3. The method according to claim 2, characterized in that The method further comprises: receiving response information of the first broadcast message, the response information including a verification result of the beam index and integrity protection information of the first broadcast message; Adjust the signature period corresponding to the first broadcast message under the beam according to the verification result of the integrity protection information of the first broadcast message.
4. The method according to any one of claims 1 to 3, characterized in that The first broadcast messages include different broadcast messages having the same transmission period.
5. The method according to any one of claims 1 to 4, characterized in that The integrity protection information is also generated based on a timestamp of sending the first broadcast message, a downlink frequency, and a cell identifier.
6. The method according to claim 3, characterized in that The response information also includes an anti-replay parameter, and the method further includes: Verifying, using the anti-replay parameter, whether the response information to the first broadcast message is a replay message; If it is not a replay message, perform the step of adjusting the signature period corresponding to the first broadcast message under the beam according to the verification result of the integrity protection information of the first broadcast message.
7. The method according to claim 3, characterized in that The response information is encrypted, and the method further includes: The response information of the first broadcast message is decrypted to obtain a verification result of the beam index and the integrity protection information of the first broadcast message.
8. A broadcast message protection method, characterized in that: The method comprises: receiving integrity protection information of a first broadcast message; The integrity protection information is verified according to the beam index of the beam for receiving the first broadcast message to obtain a verification result of the integrity protection information of the first broadcast message.
9. The method according to claim 8, characterized in that The method further comprises: Receive the signature period corresponding to the first broadcast message under the beam, where the signature period corresponding to the first broadcast message under the beam is the sending period of integrity protection information of the first broadcast message under the beam.
10. The method according to claim 9, characterized in that The method further comprises: Sending response information to the first broadcast message, where the response information includes a verification result of the beam index and integrity protection information of the first broadcast message; The verification result of the integrity protection information of the first broadcast message is used by the network device to adjust the signature period corresponding to the first broadcast message under the beam.
11. The method according to any one of claims 8 to 10, characterized in that The first broadcast messages include different broadcast messages having the same transmission period.
12. The method according to any one of claims 8 to 11, characterized in that Verifying the integrity protection information according to the beam index of the beam receiving the first broadcast message to obtain a verification result of the integrity protection information of the first broadcast message includes: The integrity protection information is verified according to the timestamp, downlink frequency, cell identifier and beam index of the beam of the received first broadcast message to obtain a verification result of the integrity protection information of the first broadcast message.
13. The method according to claim 10, characterized in that The response information also includes an anti-replay parameter, which is used by the network device to verify whether the response information of the first broadcast message is a replay message.
14. The method according to claim 10, characterized in that The sending of the response information of the first broadcast message includes: Encrypting the response information of the first broadcast message to obtain encrypted response information of the first broadcast message; Sending encrypted response information of the first broadcast message.
15. A broadcast message protection method, characterized in that: The method further comprises: Sending a first broadcast message; receiving response information of the first broadcast message, the response information including a beam index of a beam for receiving the first broadcast message by the terminal device, and integrity protection information of the first broadcast message generated by the terminal device based on the beam index; The integrity protection information is verified according to the first broadcast message and the beam index to obtain a verification result of the integrity protection information of the first broadcast message.
16. The method according to claim 15, characterized in that The method further comprises: Adjusting, according to a verification result of the integrity protection information of the first broadcast message, a signature period corresponding to the first broadcast message under the beam; The signature period corresponding to the first broadcast message under the beam is a sending period for sending integrity protection information of the first broadcast message under the beam.
17. The method according to claim 16, characterized in that The method further includes adjusting, according to a verification result of the integrity protection information of the first broadcast message, a signature period corresponding to the first broadcast message in the beam: Send the signature period corresponding to the first broadcast message under the beam.
18. The method according to any one of claims 15 to 17, characterized in that The first broadcast messages include different broadcast messages having the same transmission period.
19. The method according to any one of claims 15 to 18, characterized in that Verifying the integrity protection information according to the first broadcast message and the beam index to obtain a verification result of the integrity protection information of the first broadcast message includes: The integrity protection information is verified according to the first broadcast message and the timestamp, downlink frequency, cell identifier and beam index of sending the first broadcast message to obtain a verification result of the integrity protection information of the first broadcast message.
20. The method according to any one of claims 15 to 19, characterized in that The response information also includes an anti-replay parameter, and the method further includes: Verifying, using the anti-replay parameter, whether the response information to the first broadcast message is a replay message; If it is not a replay message, perform the step of verifying the integrity protection information according to the first broadcast message and the beam index to obtain the verification result of the integrity protection information of the first broadcast message.
21. The method according to any one of claims 15 to 20, characterized in that The response information is encrypted, and the method further includes: Decrypt response information of the first broadcast message to obtain the beam index and the integrity protection information.
22. A broadcast message protection method, characterized in that: The method further comprises: receiving a first broadcast message; generating integrity protection information for the first broadcast message, where the integrity protection information is generated based on a beam index of a beam receiving the first broadcast message; Send response information to the first broadcast message, where the response information includes the beam index and integrity protection information of the first broadcast message.
23. The method according to claim 22, characterized in that Before generating, according to the beam index of the beam for receiving the first broadcast message, the integrity protection information of the first broadcast message in the beam, the method further includes: receiving a signature period corresponding to the first broadcast message under the beam, The signature period corresponding to the first broadcast message under the beam is a sending period of integrity protection information of the first broadcast message sent by the network device under the beam.
24. The method according to claim 22 or 23, characterized in that The first broadcast messages include different broadcast messages having the same transmission period.
25. The method according to any one of claims 22 to 24, characterized in that The integrity protection information is also generated based on a timestamp of receiving the first broadcast message, a downlink frequency, and a cell identifier.
26. The method according to any one of claims 22 to 25, characterized in that The response information also includes an anti-replay parameter, which is used by the network device to verify whether the response information of the first broadcast message is a replay message.
27. The method according to any one of claims 22 to 26, characterized in that The sending of the response information of the first broadcast message includes: Encrypting the response information of the first broadcast message to obtain encrypted response information of the first broadcast message; Sending encrypted response information of the first broadcast message.
28. A communication system, characterized in that: The communication system includes a network device and a terminal device, the network device is used to execute the method according to any one of claims 1 to 7, and the terminal device is used to execute the method according to any one of claims 8 to 14; or The network device is used to execute the method according to any one of claims 15 to 21, and the terminal device is used to execute the method according to any one of claims 22 to 27.
29. A communication device comprising a module for executing the method according to any one of claims 1 to 7, or comprising a module for executing the method according to any one of claims 8 to 14, or comprising a module for executing the method according to any one of claims 15 to 21, or comprising a module for executing the method according to any one of claims 22 to 27.
30. A communication device, characterized in that: The invention comprises a processor and an interface circuit, wherein the interface circuit is used to receive signals from other communication devices outside the communication device and transmit them to the processor or send signals from the processor to other communication devices outside the communication device, and the processor is used to implement the method according to any one of claims 1 to 7 through a logic circuit or execute code instructions, or to implement the method according to any one of claims 8 to 14, or to implement the method according to any one of claims 15 to 21, or to implement the method according to any one of claims 22 to 27.
31. A computer-readable storage medium, characterized in that The storage medium stores a computer program or instruction. When the computer program or instruction is executed by the communication device, it implements the method according to any one of claims 1 to 7, or implements the method according to any one of claims 8 to 14, or implements the method according to any one of claims 15 to 21, or implements the method according to any one of claims 22 to 27.
32. A communication device, characterized in that: The communication device includes a processor and a transceiver; The transceiver is used to communicate with other communication devices, and the processor is used to run a computer program so that the communication device implements the method according to any one of claims 1 to 7, or implements the method according to any one of claims 8 to 14, or implements the method according to any one of claims 15 to 21, or implements the method according to any one of claims 22 to 27.
33. A communication device, characterized in that: The communication device includes a memory, a processor and a transceiver; The transceiver is used to receive signals or send signals, the memory is used to store instructions or computer programs, and the processor is used to execute the computer programs or instructions stored in the memory so that the communication device performs the method according to any one of claims 1 to 7, or implements the method according to any one of claims 8 to 14, or implements the method according to any one of claims 15 to 21, or implements the method according to any one of claims 22 to 27.
34. A computer program product, characterized in that The method comprises computer instructions, which, when executed on a computer, cause the computer to perform the method according to any one of claims 1 to 7, or implement the method according to any one of claims 8 to 14, or implement the method according to any one of claims 15 to 21, or implement the method according to any one of claims 22 to 27.