Communication method and communication device

By achieving integrity protection in the physical layer of the wireless cellular network, the problem of lack of security protection for signaling and data below the PDCP layer in the prior art is solved, and the security of signaling and data is improved.

CN120092414APending Publication Date: 2025-06-03HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280101231.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-10-25
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

In existing wireless cellular networks, the control plane protocol stack only provides security protection for non-access layer and wireless resource control signaling, while the security protection of the user plane protocol stack is limited to the PDCP layer, resulting in a lack of security protection for signaling and data of each protocol layer below the PDCP layer.

Method used

A communication method is proposed to achieve integrity protection by implementing physical layers at the transmitting and receiving ends. The specific steps include obtaining code blocks and related information, determining integrity protection information using security algorithms, and combining them with the code blocks, and outputting the code blocks after integrity protection.

Benefits of technology

Through the integrity protection of the physical layer, the security of signaling or data between the sending and receiving ends is improved, and the attacker prevents tampering with or replaying signaling or data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120092414A_ABST
    Figure CN120092414A_ABST
Patent Text Reader

Abstract

The invention provides a communication method and a communication device, and the method comprises the steps: taking at least one of a part of or all loads of a physical channel load, a check code, an anti-replay parameter, a secret key and downlink control information as the input of a security algorithm, and carrying out the calculation to obtain information for carrying out the integrity protection of the physical channel load, therefore, the integrity protection of the physical layer is realized, and the security of signaling or data between the sending end and the receiving end is improved.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method and a communication device

[0001] This application relates to the field of communications, and more particularly, to a communication method and a communication device.

[0002] Currently, in a wireless cellular network, the control plane protocol stack only involves the security protection of non-access stratum (NAS) signaling and radio resource control (RRC) signaling, including signaling encryption, integrity protection, anti-replay attack, etc.; the security protection of the user plane protocol stack is carried out at the Packet Data Convergence Protocol (PDCP) layer, including encryption, integrity protection, anti-replay attack. The PDCP layer provides security protection for RRC signaling and user data. There is no security protection for the signaling and data of each protocol layer below the PDCP layer.

[0003]

[0004] This application provides a communication method and a communication device, which can implement physical layer integrity protection and help improve the security of signaling or data between a sending end and a receiving end.

[0005] In a first aspect, a communication method is provided. The method can be executed by a sending end, or by a module or unit in the sending end. Optionally, the sending end can be a terminal or a network device (such as a base station).

[0006] The method includes: obtaining a first code block and first information, where the first code block is a physical channel payload, and the first information includes at least one of the following information: a partial payload or all payloads of the first code block, a first check code, an anti-replay parameter, a key, and downlink control information for scheduling the first code block; determining first integrity protection information according to the first information and a security algorithm; determining a second code block according to the first code block and the first integrity protection information, where the second code block includes the first code block and the first integrity protection information; and outputting the second code block.

[0007] Among them, the first integrity protection information is used to perform integrity protection on the first code block.

[0008] Based on the above method, physical layer integrity protection can be achieved, which helps to improve the security of signaling or data between the sending end and the receiving end. In addition, when the check code is used as one of the inputs of the security algorithm, the error detection function of the check code can be fully utilized. When the downlink control information is used as one of the inputs of the security algorithm, the correlation between the downlink control information and the physical uplink shared channel or the physical uplink shared channel can be utilized to further increase the difficulty of attack. When the cell-level parameters and the configuration parameters of the physical channel are used as one of the inputs of the security algorithm, anti-replay capabilities can be provided, such as preventing an attacker from replaying the signaling or data at other time-frequency, frequency domain, spatial domain, or encoded with other parameters.

[0009] Combined with the first aspect, in a possible implementation, the first check code includes the check code of the first code block and / or the check code of the transport block to which the first code block belongs.

[0010] Based on the above method, when the check code includes the check code of the transport block to which the code block belongs, since the check code of the transport block to which the code block belongs is calculated based on the transport block, a certain degree of integrity protection can be achieved for all the payloads of the physical channel.

[0011] Combined with the first aspect or any of its implementations, in another possible implementation, the second code block does not include the check code of the first code block.

[0012] In other words, the sending end uses the first integrity protection information to replace the check code of the first code block.

[0013] Based on the above method, the second code block does not include the check code of the first code block, which can reduce the number of transmitted bits.

[0014] Combined with the first aspect or any of its implementations, in another possible implementation, when the first information includes a partial payload of the first code block, the method further includes: obtaining the partial payload of the first code block according to a first offset and a first length, where the first offset is the offset of the start position of the partial payload of the first code block relative to the start position of the first code block, and the first length is the length of the partial payload of the first code block; or, dividing the first code block into multiple sub-code blocks according to division information, and obtaining the partial payload of each sub-code block according to a second offset and a second length, where the partial payload of the first code block includes the partial payload of each sub-code block, the second offset is the offset of the start position of the partial payload of each sub-code block relative to the start position of each sub-code block, and the second length is the length of the partial payload of each sub-code block.

[0015] Based on the above method, a partial payload of the first code block can be used as the input to the security algorithm. Compared with using the entire payload of the first code block as the input to the security algorithm, the length of the bit sequence input to the security algorithm can be reduced, thereby reducing the computational complexity. When a partial payload of the first code block and the first check code are used as the input to the security algorithm, while reducing the length of the bit sequence input to the security algorithm, a certain degree of integrity protection can be provided for all the payloads of the first code block.

[0016] Combined with the first aspect or any of its implementation manners, in another possible implementation manner, the first offset, the first length, the partitioning information, the second offset, and the second length are carried in the downlink control information.

[0017] Combined with the first aspect or any of its implementation manners, in another possible implementation manner, the physical channel is a physical uplink shared channel, a physical downlink shared channel, a physical uplink control channel, or a physical downlink control channel.

[0018] Combined with the first aspect or any of its implementation manners, in another possible implementation manner, when the first information includes the downlink control information, the physical channel is a physical uplink shared channel or a physical downlink shared channel.

[0019] Based on the above method, the correlation between the downlink control information and the physical uplink shared channel or the physical downlink shared channel can be utilized to further improve the security factor.

[0020] Combined with the first aspect or any of its implementation manners, in another possible implementation manner, the anti-replay parameter includes: a cell-level parameter and / or a configuration parameter of the physical channel; wherein, the cell-level parameter includes at least one of the following parameters: a physical cell identifier, a link frequency or frequency point, a system bandwidth, or a partial bandwidth (BandWidth Part, BWP) information; the configuration parameter of the physical channel includes at least one of the following parameters: a time-domain parameter, a frequency-domain parameter, a sequence generation parameter, a transmit power control parameter, or a coding parameter.

[0021] Based on the above method, an attacker can be prevented from replaying signaling or data in other time-frequency, frequency-domain, spatial-domain, or with other parameter encodings.

[0022] Combined with the first aspect or any of its implementation manners, in another possible implementation manner, the security algorithm is an integrity protection algorithm based on a symmetric key.

[0023] Combined with the first aspect or any of its implementation manners, in another possible implementation manner, the method further includes: after the access layer security protection mode is completed, activating the physical layer integrity protection mechanism.

[0024] Combined with the first aspect or any implementation thereof, in another possible implementation, the method further includes: after the radio link control reconfiguration is completed, updating the configuration parameters of the physical channel.

[0025] In a second aspect, a communication method is provided. The method can be executed by a receiving end, or by a module or unit in the receiving end. Optionally, the receiving end can be a terminal or a network device.

[0026] For the technical effects of the method shown in the second aspect and its possible implementations, reference can be made to the first aspect and its possible implementations, which will not be elaborated here.

[0027] The method includes: obtaining a received code block of a physical channel, where the received code block includes a physical channel payload and second integrity protection information; obtaining second information, where the second information includes at least one of the following: a partial payload or the entire payload of the physical channel payload, a second check code, an anti-replay parameter, a key, and downlink control information for scheduling the physical channel payload, and the second check code is obtained based on the physical channel payload; determining third integrity protection information according to the second information and a security algorithm; and performing an integrity check on the physical channel payload according to the second integrity protection information and the third integrity protection information.

[0028] Combined with the second aspect, in a possible implementation, the second check code includes a check code for the physical channel payload and / or a check code for a transport block to which the physical channel payload belongs.

[0029] Combined with the second aspect or any implementation thereof, in another possible implementation, the received code block does not include a check code for the physical channel payload.

[0030] Combined with the second aspect or any implementation thereof, in another possible implementation, when the second information includes a partial payload of the physical channel payload, the method further includes: obtaining the partial payload of the physical channel payload according to a first offset and a first length, where the first offset is an offset of a start position of the partial payload of the physical channel payload relative to a start position of the physical channel payload, and the first length is a length of the partial payload of the physical channel payload; or dividing the physical channel payload into multiple sub-code blocks according to division information, and obtaining partial payloads of each of the multiple sub-code blocks according to a second offset and a second length, where the partial payload of the physical channel payload includes the partial payloads of each of the sub-code blocks, the second offset is an offset of a start position of the partial payload of each sub-code block relative to a start position of each sub-code block, and the second length is a length of the partial payload of each sub-code block.

[0031] In combination with the second aspect or any of its implementations, in another possible implementation, the first offset, the first length, the partitioning information, the second offset, and the second length are carried in the downlink control information.

[0032] In combination with the second aspect or any of its implementations, in another possible implementation, the physical channel is a physical uplink shared channel, a physical downlink shared channel, a physical uplink control channel, or a physical downlink control channel.

[0033] In combination with the second aspect or any of its implementations, in another possible implementation, when the second information includes the downlink control information, the physical channel is a physical uplink shared channel or a physical downlink shared channel.

[0034] In combination with the second aspect or any of its implementations, in another possible implementation, the anti-replay parameter includes: a cell-level parameter and / or a configuration parameter of the physical channel; wherein, the cell-level parameter includes at least one of the following parameters: a physical cell identifier, a link frequency or frequency point, a system bandwidth, or BWP information; the configuration parameter of the physical channel includes at least one of the following parameters: a time-domain parameter, a frequency-domain parameter, a sequence generation parameter, a transmit power control parameter, or a coding parameter.

[0035] In combination with the second aspect or any of its implementations, in another possible implementation, the security algorithm is an integrity protection algorithm based on a symmetric key.

[0036] In combination with the second aspect or any of its implementations, in another possible implementation, the method further includes: after the access layer security protection mode is completed, activating the physical layer integrity protection mechanism.

[0037] In combination with the second aspect or any of its implementations, in another possible implementation, the method further includes: after the radio link control reconfiguration is completed, updating the configuration parameters of the physical channel.

[0038] In a third aspect, a communication device is provided, and this device is used to execute the method provided by any of the above aspects or its implementations. Specifically, the device may include units and / or modules for executing the method provided by any of the above aspects or its implementations, such as a processing unit and / or a communication unit.

[0039] In one implementation, the device is a sending end or a receiving end. When the device is a sending end or a receiving end, the communication unit may be a transceiver, or, an input / output interface, or a communication interface; the processing unit may be at least one processor. Optionally, the transceiver is a transceiver circuit. Optionally, the input / output interface is an input / output circuit.

[0040] In another implementation, the device is a chip, a chip system, or a circuit in a transmitting end or a receiving end. When the device is a chip, a chip system, or a circuit in a transmitting end or a receiving end, the communication unit may be an input / output interface, an interface circuit, an output circuit, an input circuit, a pin, or a related circuit, etc. on the chip, the chip system, or the circuit; the processing unit may be at least one processor, a processing circuit, or a logic circuit, etc.

[0041] In a fourth aspect, a communication device is provided, and the device includes: a memory for storing programs; at least one processor for executing the computer programs or instructions stored in the memory to perform the method provided in any of the above aspects or its implementation manners.

[0042] In one implementation manner, the device is a transmitting end or a receiving end.

[0043] In another implementation manner, the device is a chip, a chip system, or a circuit in a transmitting end or a receiving end.

[0044] In a fifth aspect, a communication device is provided, and the device includes: at least one processor and a communication interface. The at least one processor is configured to obtain the computer programs or instructions stored in a memory through the communication interface to perform the method provided in any of the above aspects or its implementation manners. The communication interface may be implemented by hardware or software.

[0045] In one implementation manner, the device further includes the memory.

[0046] In a sixth aspect, a processor is provided for performing the methods provided in the above aspects.

[0047] For operations such as sending and obtaining / receiving involved by the processor, if there is no special indication, or if it does not conflict with its actual function or internal logic in the relevant description, then it can be understood as operations such as outputting, receiving, and inputting by the processor, and it can also be understood as sending and receiving operations performed by a radio frequency circuit and an antenna. This application does not make any limitation in this regard.

[0048] In a seventh aspect, a computer-readable storage medium is provided, and the computer-readable medium stores program codes for a device to execute. The program codes include those for performing the method provided in any of the above aspects or its implementation manners.

[0049] In an eighth aspect, a computer program product including instructions is provided. When the computer program product runs on a computer, it causes the computer to perform the method provided in any of the above aspects or its implementation manners.

[0050] In a ninth aspect, a chip is provided. The chip includes a processor and a communication interface. The processor reads instructions stored in a memory through the communication interface and executes the method provided in any of the above aspects or its implementation manners. The communication interface may be implemented by hardware or software.

[0051] Optionally, as an implementation manner, the chip further includes a memory. A computer program or instructions are stored in the memory. The processor is configured to execute the computer program or instructions stored in the memory. When the computer program or instructions are executed, the processor is configured to execute the method provided in any of the above aspects or its implementation manners.

[0052] Wherein, when the method provided in this application is executed by a chip, this application does not limit the number of chips for specifically implementing the method of this application. For example, it may be executed by one chip, or may be executed by two or more chips. And when the number of chips for implementing the method of this application is two or more, there is no limitation on the chip manufacturers, which may be the same manufacturer or different manufacturers.

[0053] In a tenth aspect, a communication system is provided, including the above-mentioned sending end and / or receiving end.

[0054] FIG. 1 is a schematic diagram of the architecture of a communication system to which the embodiments of this application can be applied.

[0055] FIG. 2 is a schematic diagram of the architecture of another communication system to which the embodiments of this application can be applied.

[0056] FIG. 3 is a schematic diagram of the signaling interaction between a terminal and a network in an initial access phase.

[0057] FIG. 4 is a schematic diagram of a control plane protocol stack.

[0058] FIG. 5 is a schematic diagram of a user plane protocol stack.

[0059] FIG. 6 is a schematic flow chart of an attacker obtaining PDCCH resource configuration and forging DCI instructions.

[0060] FIG. 7 is a schematic flow chart of a communication method 700 proposed in this application.

[0061] FIG. 8 is a schematic flow chart of a method for activating a physical layer integrity protection mechanism.

[0062] FIG. 9 is a schematic flow chart of a method for updating physical layer integrity protection parameters.

[0063] FIG. 10 is an overall schematic diagram of the communication method provided in this application.

[0064] FIG. 11 is a schematic diagram of a physical layer integrity protection method for PDCCH.

[0065] FIG. 12 is a schematic diagram of the physical layer integrity protection method for PUCCH.

[0066] FIG. 13 is a schematic diagram of the physical layer integrity protection method for PDSCH or PUSCH.

[0067] FIG. 14 is another schematic diagram of the physical layer integrity protection method for PDSCH or PUSCH.

[0068] FIG. 15 is another schematic diagram of the physical layer integrity protection method for PDSCH or PUSCH.

[0069] FIG. 16 is a schematic structural diagram of the device provided by the embodiment of the present application.

[0070] FIG. 17 is another schematic structural diagram of the device provided by the embodiment of the present application.

[0071] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings.

[0072] For ease of understanding the embodiments of the present application, before introducing the embodiments of the present application, the following points are first explained.

[0073] In the present application, "for indicating" or "indicating" may include direct indication and indirect indication, or in other words, "for indicating" or "indicating" may indicate explicitly and / or implicitly. For example, when describing that a certain piece of information is for indicating information I, it may include that this information directly indicates I or indirectly indicates I, and it does not necessarily mean that I is carried in this information. Another example is that implicit indication may be based on the position and / or resource for transmission; explicit indication may be based on one or more parameters, and / or one or more indexes, and / or one or more bit patterns it represents.

[0074] The definitions listed for many features in the present application are only used to explain the functions of the features by way of example, and the detailed content can refer to the prior art.

[0075] In the embodiments shown below, the first, second, third, fourth, and various numerical numbers are only for the convenience of description for distinction, and are not used to limit the scope of the embodiments of the present application. For example, to distinguish different fields, different information, etc.

[0076] "Pre-defined" can be implemented by pre-saving the corresponding code, table, or other means that can be used to indicate relevant information in the device. The present application does not limit its specific implementation manner. Among them, "saving" may mean saving in one or more memories. The type of memory can be any form of storage medium, and the present application does not limit this.

[0077] The “protocol” involved in the embodiments of the present application may refer to a standard protocol in the field of communications, such as a long term evolution (LTE) protocol, a new radio (NR) protocol, and related protocols used in future communication systems, which is not limited in the present application.

[0078] The present application will present various aspects, embodiments or features around a system including multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all devices, components, modules, etc. discussed in conjunction with the figures. In addition, combinations of these schemes may also be used.

[0079] In the embodiments of the present application, words such as "exemplary", "for example", "exemplarily", "as (another) example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "example" in the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of the word example is intended to present concepts in a concrete way.

[0080] The terms "include", "comprising", "having" and variations thereof all mean "including but not limited to", unless specifically emphasized otherwise.

[0081] "At least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b and c can mean: a, or b, or c, or a and b, or a and c, or b and c, or a, b and c. Where a, b and c can be single or plural, respectively.

[0082] In the embodiments of the present application, the description involving network element A sending a message, information or data to network element B, and network element B receiving a message, information or data from network element A is intended to illustrate to which network element the message, information or data is to be sent, but does not limit whether they are sent directly or indirectly via other network elements.

[0083] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if", and "when" all refer to the device making corresponding processing under certain objective circumstances, rather than limiting time, and do not require the device to have a judgment action during implementation, nor does it mean the existence of other limitations.

[0084] The embodiments of the present application can be applied to various communication systems. For example: Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD), Public Land Mobile Network (PLMN), 5th generation (5G) systems, 6th generation (6G) systems, or future communication systems, etc. The 5G systems in the present application include non-standalone (NSA) 5G mobile communication systems or standalone (SA) 5G mobile communication systems. The embodiments of the present application can also be applied to non-terrestrial network (NTN) communication systems such as satellite communication systems. The embodiments of the present application can also be applied to device-to-device (D2D) communication systems, sidelink (SL) communication systems, machine-to-machine (M2M) communication systems, machine type communication (MTC) systems, Internet of Things (IoT) communication systems, vehicle-to-everything (V2X) communication systems, uncrewed aerial vehicle (UAV) communication systems, or other communication systems.

[0085] The base station (or access network device) in this application can be a device for communicating with terminals or a device for connecting terminals to a wireless network. The base station can be a node in the radio access network. The base station can include a macro station (high-power cellular base station) and / or a micro station (low-power cellular base station). The macro station includes a macro cell, and the micro station includes a micro cell, a pico cell, and a femto cell. The base station can also include an evolved NodeB (eNodeB), a transmission reception point (TRP), an access point, a base station transceiver, a radio base station, a radio transceiver, a transceiver function entity, a basic service set (BSS), an extended service set (ESS), a transmission reception point (TRP), a home base station (e.g., home evolved NodeB, or home Node B, HNB), a Wi-Fi access point (AP), a mobile switching center, a next-generation base station (gNB) in a 5G mobile communication system, a next-generation base station in a sixth-generation (6G) mobile communication system, a base station or a base station module in an open radio access network (ORAN) system, or a base station in a future mobile communication system, etc. The base station can also be a module or unit that completes some functions of the base station. For example,

[0086] The access network device can include a CU and a DU. This design can be called the separation of CU and DU. Multiple DUs can be centrally controlled by one CU. As an example, the interface between the CU and the DU is called the F1 interface. Among them, the control plane (CP) interface can be F1-C, and the user plane (UP) interface can be F1-U. The present disclosure does not limit the specific names of each interface. The CU and the DU can be divided according to the protocol layers of the wireless network: for example, the functions of the protocol layers above the PDCP layer (such as the RRC layer and the SDAP layer, etc.) are set in the CU, and the functions of the protocol layers below the PDCP layer (such as the RLC layer, the MAC layer, and the PHY layer, etc.) are set in the DU; or for another example, the functions of the protocol layers above the PDCP layer are set in the CU, and the functions of the protocol layers at and below the PDCP layer are set in the DU, without limitation.

[0087] The above processing functions for the CU and DU are just examples according to the division of protocol layers, and can also be divided in other ways. For example, the CU or DU can be divided into functions with more protocol layers, or the CU or DU can be divided into partial processing functions of protocol layers. For example, some functions of the RLC layer and the protocol layers above the RLC layer are set in the CU, and the remaining functions of the RLC layer and the protocol layers below the RLC layer are set in the DU. Another example is that the functions of the CU or DU can be divided according to service types or other system requirements, such as by latency. The functions whose processing time needs to meet the latency requirements are set in the DU, and the functions that do not need to meet this latency requirement are set in the CU.

[0088] Optionally, the CU may have one or more functions of the core network.

[0089] Optionally, the radio unit (RU) of the DU can be remotely deployed. The RU has radio frequency functions. Exemplarily, the DU and the RU can be divided at the PHY layer. For example, the DU can implement the high-layer functions in the PHY layer, and the RU can implement the low-layer functions in the PHY layer. When used for transmission, the functions of the PHY layer can include at least one of the following: adding cyclic redundancy check (CRC) bits, channel coding, rate matching, scrambling, modulation, layer mapping, precoding, resource mapping, physical antenna mapping, or radio frequency transmission functions. When used for reception, the functions of the PHY layer can include at least one of the following: CRC check, channel decoding, descrambling, demodulation, de-layer mapping, channel detection, resource demapping, physical antenna demapping, or radio frequency reception functions. The high-layer functions in the PHY layer can include a part of the functions of the PHY layer that is closer to the MAC layer; the low-layer functions in the PHY layer can include another part of the functions of the PHY layer, for example, this part of the functions is closer to the radio frequency functions. For example, the high-layer functions in the PHY layer can include adding CRC bits, channel coding, rate matching, scrambling, modulation, and layer mapping, and the low-layer functions in the PHY layer can include precoding, resource mapping, physical antenna mapping, and radio frequency transmission functions; or, the high-layer functions in the PHY layer can include adding CRC bits, channel coding, rate matching, scrambling, modulation, layer mapping, and precoding, and the low-layer functions in the PHY layer can include resource mapping, physical antenna mapping, and radio frequency transmission functions. For example, the high-layer functions in the PHY layer can include CRC check, channel decoding, descrambling, decoding, demodulation, and de-layer mapping, and the low-layer functions in the PHY layer can include channel detection, resource demapping, physical antenna demapping, and radio frequency reception functions; or, the high-layer functions in the PHY layer can include CRC check, channel decoding, descrambling, decoding, demodulation, de-layer mapping, and channel detection, and the low-layer functions in the PHY layer can include resource demapping, physical antenna demapping, and radio frequency reception functions.

[0090] Optionally, the functions of the CU can be further divided, separating the control plane and the user plane and implementing them through different entities. The separated entities are the control plane CU entity (i.e., the CU-CP entity) and the user plane CU entity (i.e., the CU-UP entity). The CU-CP entity and the CU-UP entity can be respectively connected to the DU. In this application, an entity can be understood as a module or a unit, and its existence form can be a hardware structure, a software module, or a combination of a hardware structure and a software module, without limitation.

[0091] Optionally, any one of the above-mentioned CU, CU-CP, CU-UP, DU, and RU can be a software module, a hardware structure, or a combination of a software module and a hardware structure, without limitation. Among them, the existence forms of different entities can be the same or different. For example, CU, CU-CP, CU-UP, and DU are software modules, and RU is a hardware structure. For the sake of concise description, all possible combination forms are not listed one by one here. These modules and the methods they execute are also within the protection scope of this application. For example, when the method of this application is executed by an access network device (or base station), it can be specifically executed by at least one of CU, CU-CP, CU-UP, DU, or RU.

[0092] The base station can also be a device that undertakes the base station function in a D2D communication system, a V2X communication system, an M2M communication system, and an IoT communication system, etc. The base station can also be a network device in NTN, that is, the base station can be deployed on a high-altitude platform or a satellite. The base station can also be a relay node or a donor node, etc. The specific technologies, device forms, and names adopted by the base station in the embodiments of this application are not limited. The base station can be called a radio access network device or a network device, etc.

[0093] The terminal in this application can also be referred to as a wireless terminal device, user equipment (UE), user, access terminal, user unit, user station, mobile station, mobile device, remote station, remote terminal, mobile device, user terminal, terminal device, wireless communication device, user agent, or user device, etc. For convenience of description, it will be uniformly referred to as a terminal hereinafter. A terminal is a device that can access a network. The terminal and the base station can communicate with each other using a certain air interface technology (such as NR or LTE technology). Terminals can also communicate with each other using a certain air interface technology (such as NR or LTE technology). The terminal can be a cellular phone, mobile phone, Session Initiation Protocol (SIP) phone, laptop computer, personal digital assistant (PDA), satellite radio, global positioning system, multimedia device, smart video device, digital audio player, game console, tablet computer, smart device, wearable device, smart watch, vehicle, smart meter, air pump, large or small kitchen appliance, healthcare device, sensor / actuator, display, or any other similar functional device. The terminal can also be an Internet of Things (IoT) device (for example, parking meter, smart meter, fuel pump, vehicle, heart monitor, etc.). The terminal can be a station, mobile station, subscriber station, mobile unit, subscriber unit, wireless unit, remote unit, mobile device, wireless device, wireless communication device, remote device, mobile subscriber station, access terminal, mobile terminal, wireless terminal, remote terminal, mobile phone, user agent, mobile client, client, computer with wireless transceiver function, virtual reality (VR) terminal, augmented reality (AR) terminal, terminal in satellite communication, terminal in an integrated access and backhaul (IAB) system, terminal in a WiFi communication system, terminal in industrial control, terminal in self-driving, terminal in remote medical, terminal in smart grid, terminal in transportation safety, terminal in smart city, terminal in smart home, etc. Embodiments of this application do not limit the specific technologies and specific device forms adopted by the UE.

[0094] The technical solutions provided by the embodiments of the present application can be applied to wireless communications between communication devices. Wireless communications between communication devices may include: wireless communications between a base station and a terminal, wireless communications between base stations, and wireless communications between terminals. Among them, in the embodiments of the present application, the term "wireless communication" may also be abbreviated as "communication", and the term "communication" may also be described as "data transmission", "information transmission", or "transmission".

[0095] As an example, FIG. 1 is a schematic diagram of the architecture of a communication system to which the embodiments of the present application can be applied.

[0096] As shown in FIG. 1, the communication system includes a core network (CN) part, a radio access network (RAN) part, and terminals. Among them, the core network part includes a 4th generation (4G) evolved packet core (EPC) and a 5G core network (5GC). The radio access network part includes 4G base stations (such as LTE eNBs) and 5G base stations (such as NR gNBs).

[0097] Among them, the 4G LTE eNB can be connected to the 4G core network through a backhaul network (S1 interface). The 5G NR gNB can be docked with the 5G core network through a backhaul network (Ng interface), or docked with the LTE EPC through the S1 interface. The base station can perform one or more of the following functions: user data and control signaling transmission, user data or air interface signaling encryption and decryption, integrity protection, header compression, mobility control functions (such as handover, dual connectivity), inter-cell interference coordination, connection establishment and release, load balancing, distribution of non-access stratum (NAS) messages, NAS node selection, synchronization, paging, positioning, and delivery of warning information, radio access network sharing, multimedia broadcast multicast service, user and device tracking, RAN information management, etc. Multiple base stations can communicate directly or indirectly through the backhaul network (X2, Xn interfaces). The base station can communicate with the terminal wirelessly. The base station provides an access point to the EPC or 5GC core network for the terminal. Each base station can provide communication services for terminal users within the corresponding geographical coverage area.

[0098] As another example, FIG. 2 is a schematic diagram of the architecture of another communication system to which the embodiments of the present application can be applied.

[0099] As shown in Figure 2, this communication system takes the 5th generation system (5GS) as an example. This network architecture can include three parts, namely the UE part, the data network (DN) part, and the operator network part. Among them, the operator network can include one or more of the following network elements: (radio) access network ((R)AN) devices, user plane function (UPF) network elements, authentication server function (AUSF) network elements, access and mobility management function (AMF) network elements, session management function (SMF) network elements, network slice selection function (NSSF) network elements, network exposure function (NEF) network elements, network repository function (NRF) network elements, policy control function (PCF) network elements, unified data management (UDM) network elements, and application function (AF) network elements. In the above operator network, the part other than the RAN part can be called the core network part.

[0100] Among them, the descriptions of the terminal and the RAN can refer to the above text.

[0101] The UPF is mainly responsible for the forwarding and reception of user data in the terminal. For example, the UPF can receive user plane data from the DN and send the user plane data to the terminal through the access network device. The UPF can also receive user plane data from the terminal through the access network device and forward it to the DN. The transmission resources and scheduling functions provided for the terminal in the UPF network element are managed and controlled by the SMF.

[0102] The DN is mainly used for the operator network that provides data services for the terminal. For example, the Internet, a third-party service network, or an IP multimedia service (IMS) network, etc.

[0103] The AUSF supports access authentication for both the 3rd generation partnership project (3GPP) and non-3GPP.

[0104] The AMF is mainly responsible for the signaling processing part, such as functions like access control, mobility management, attachment and detachment, and gateway selection. In the case of providing services for a session in the terminal, the AMF will provide control plane storage resources for the session to store session identifiers, SMF network element identifiers associated with the session identifier, etc.

[0105] The SMF is mainly responsible for user plane network element selection, user plane network element redirection, internet protocol (IP) address allocation, establishment, modification, and release of bearers, and quality of service (QoS) control, etc.

[0106] The NSSF is mainly responsible for network slice selection, and determines the network slice instances allowed for the terminal to access based on the terminal's slice selection assistance information, subscription information, etc.

[0107] The NEF mainly supports the interaction between the 3GPP network and third-party application security.

[0108] The NRF is mainly used to store network function entities and description information about the services they provide, etc.

[0109] The PCF is mainly responsible for policy control decisions, providing policy rules for control plane functions, and traffic-based charging control functions, etc.

[0110] The UDM is mainly responsible for the subscription data management of the terminal, including the storage and management of terminal identifiers, access authorization of the terminal, etc.

[0111] The AF mainly supports interacting with the 3GPP core network to provide services, such as influencing data routing decisions, policy control functions, or providing third-party services to the network. The AF can be an AF deployed by the operator's network itself or a third-party AF.

[0112] In the network architecture shown in Figure 2, the network elements can communicate through interfaces. The interfaces between the network elements can be point-to-point interfaces or service-based interfaces, which are not restricted in this application.

[0113] The 5G access network supports a centralized or distributed architecture. The distributed architecture supports the split of CU (Centralized Unit / Non-Real-Time Processing) and DU (Distributed Unit / Real-Time Processing). CU (Centralized Unit / Non-Real-Time Processing) has lower real-time requirements and can adopt virtualization technology and use a general-purpose processing platform. DU (Distributed Unit / Real-Time Processing) has higher real-time requirements and adopts a dedicated hardware platform to support high-density mathematical operations. The Packet Data Convergence Protocol (PDCP) and radio resource control (RRC) layers with low real-time requirements are processed in the CU, while the Media Access Control (MAC) layer, Radio Link Control (RLC) layer, and part of the physical layer processing functions are processed in the DU. The remaining part of the physical layer processing functions can be downshifted to the RRU (Remote Radio Unit), and the RRU and the antenna are combined into the AAU (Active Antenna Unit).

[0114] It should be understood that the functions or network elements such as AMF, SMF, UPF, PCF, UDM, AUSF, NSSF, NEF, NRF, AF shown in Figure 2 can be understood as network elements for implementing different functions. For example, they can be combined into network slices as needed. These network elements can be individual devices, or can be integrated into the same device to implement different functions, or can be network components in hardware devices, or can be software functions running on dedicated hardware, or can be virtualized functions instantiated on a platform (such as a cloud platform). The present application does not limit the specific form of the above network elements.

[0115] It should also be understood that the network architectures shown in Figures 1 and 2 above are only exemplary illustrations, and the network architectures applicable to the embodiments of the present application are not limited thereto. Any network architecture capable of implementing the functions of the above network elements is applicable to the embodiments of the present application.

[0116] It should also be understood that the above naming is only defined for the convenience of distinguishing different functions and should not constitute any limitation to the present application. The present application does not exclude the possibility of using other naming in the 6G network and future other networks. For example, in the 6G network, some or all of the above network elements may continue to use the terms in 5G, or may use other names, etc.

[0117] Currently, wireless communication networks support multiple communication access technologies, such as 5G NR, 4G LTE, WLAN, fixed networks, etc., and the types of terminals are becoming more and more diverse, such as mobile phones, VR devices, intelligent vehicles, unmanned aerial vehicles, intelligent water meters, etc. Like 4G, the 5G system has the characteristic of two-layer security, that is, the security mode commands are activated separately at the NAS layer and the access stratum (AS) to enable security functions such as encryption and integrity protection. After the terminal and the network authenticate each other's identities, the terminal and the network negotiate the security algorithms and keys used for the encryption and integrity protection of RRC signaling, NAS signaling, and user data during the subsequent communication process. After the NAS security algorithm negotiation is completed, the NAS messages between the AMF and the UE will be encrypted and integrity protected. During the AS security mode command interaction process, the gNodeB and the UE negotiate the cipher algorithms and keys for AS layer encryption and integrity protection, and initiate the encryption and integrity protection of AS layer RRC messages. The activation of AS layer user plane integrity protection and encryption is part of the data radio bearer (DRB) addition process and uses the RRC connection reconfiguration process.

[0118] Figure 3 is a schematic diagram of the signaling interaction between the terminal and the network in the initial access phase.

[0119] The signaling interaction process between the terminal and the base station and the core network in the initial access phase is shown in Figure 3. In the initial network access phase, the terminal first performs cell selection, then performs random access, and then completes the establishment of the RRC connection. Subsequently, the terminal and the network perform two-way authentication. After successful authentication, the NAS and AS layer key derivation and negotiation are enabled. Before the establishment of NAS security and AS security, all air interface signals are not protected by any security, including RRC signaling and NAS signaling. After the NAS security mode is completed (NAS Security Mode Complete), the NAS signaling enables encryption and integrity protection. After the AS security mode is completed (AS Security Mode Complete), the RRC signaling enables encryption and integrity protection. After establishing the DRB bearer through the RRC reconfiguration (RRC Reconfiguration) process, the base station and the terminal activate the corresponding user plane encryption and integrity protection.

[0120] Through the above process, the NAS signaling, RRC signaling, and user plane can enable encryption and integrity protection, but the signals and data at the lower layer (such as each protocol sub-layer below the PDCP layer) still have no security protection.

[0121] Figure 4 is a schematic diagram of the Control Plane (CP) protocol stack. All protocol stacks of the terminal are located within the terminal; on the network side, the NAS layer is not located on the base station gNB but on the AMF entity in the core network. Among them, the control plane protocol stack only involves the security protection of NAS signaling and RRC signaling, including signaling encryption, integrity protection, anti-replay attack, etc. There is no security protection for the underlying (such as the PDCP layer and below each protocol sub-layer) signaling.

[0122] Figure 5 is a schematic diagram of the User Plane (UP) protocol stack. Security processing such as encryption, integrity protection, and anti-replay of user plane data is completed at the PDCP layer, and there is no security protection below the PDCP layer. Also, currently, the calculation of the security algorithm for integrity protection in the 3GPP standard is relatively complex. In order to ensure QoS indicators such as Aggregate Maximum Bit Rate (AMBR), many operators do not enable the user plane integrity protection of the PDCP layer in actual deployment.

[0123] In this way, in fact, there is no security protection for the signaling and data of each protocol layer below the PDCP layer.

[0124] Based on the new features of 5G such as short delay, high reliability, and energy saving, there have emerged some key instructions at the underlying layer (such as the PDCP layer and below each protocol sub-layer) that affect the function usage or characteristic performance indicators, such as downlink control information (DCI), Media Access Control layer Control Element (MAC CE), etc. And there is no security protection for the signaling and data of each protocol layer below the PDCP layer, and an attacker can obtain and tamper with these underlying instructions.

[0125] Exemplarily, Figure 6 is a schematic flowchart of an attacker obtaining PDCCH resource configuration and forging DCI instructions.

[0126] Step 1, the attacker listens to the master information block (MIB) sent by the legitimate base station on the physical broadcast channel (PBCH) and obtains the control resource set (CORESET) 0 and SearchSpace 0 in the MIB.

[0127] Step 2: The attacker listens for the DCI of System Information Block (SIB) 1 on CORESET0 and SearchSpace0 of the PDCCH, obtains information such as the time-frequency resource location of SIB1, and then listens for SIB1 on the PDSCH channel. The attacker obtains the cell RACH-ConfigCommon in SIB1, which indicates the configuration of the random access channel (RACH) time-frequency resources / preambles / response windows, etc. Based on these parameters, the attacker calculates the possible values of the random access-radio network temporary identifier (RA-RNTI).

[0128] Step 3: The attacker uses the RA-RNTI to listen for Msg2 and obtains the TC-RNTI (Temporary C-RNTI) carried in the Msg2 message.

[0129] Step 4: The attacker uses the TC-RNTI to listen for Msg4 and obtains parameters such as the user-level CORESET / Searchspace of cell BWP0 in the Msg4 message. When the UE competes for random access and succeeds, the TC-RNTI is upgraded to the C-RNTI. The attacker can obtain the C-RNTI assigned by the legitimate base station to the user through listening.

[0130] Step 5: The legitimate base station issues an RRC reconfiguration message with encryption and integrity protection to reconfigure the user-level cell parameters of each physical channel.

[0131] Although the attacker cannot obtain the cell parameters of each physical channel in the RRC reconfiguration message, the attacker can guess the relevant cells through multiple decoding attempts. Moreover, if most of the cell parameters sent in the encrypted RRC reconfiguration are the same as those in the plaintext Msg4, the attacker can easily crack and obtain the relevant physical channel parameters with less time and cost, and then imitate and tamper with the underlying signaling and data.

[0132] Step 6: The attacker continues to listen for the key DCI instructions issued by the legitimate base station, performs multiple blind detections, and further guesses the parameter configurations of the user-level CORESET and SearchSpace.

[0133] Step 7: Based on the user-level CORESET and SearchSpace parameters obtained in the previous steps, the attacker imitates or tampers with the key DCI instructions and sends them to the user, causing damage to the user's service functions or performance indicators.

[0134] An attacker can spoof the P-RNTI scrambled PDCCH DCI format 1_0 at the Paging Occasion (PO) location. This DCI contains a Short Message indicating a change in the SIB system message carried by the PDSCH. Combining with the tampered system message can further disable the calling and called services of legitimate terminals. The attacker can also spoof the DCI instruction of the PDCCH Order based on the C-RNTI, causing legitimate terminals to continuously initiate random access and unable to obtain normal network services. The terminal can also activate the UL grant type2 DCI instruction sent by the legitimate base station and obtain UE-specific parameters such as CS-RNTI and user-level CORESET / SearchSpace through multiple blind detections. Then, the attacker spoofs the DCI activation instruction and sends it to the terminal, making the user unable to use the grant-free scheduling resources and causing the terminal to fail to meet the short-delay performance index.

[0135] In this way, the attacker's acquisition, tampering, spoofing, etc. of the underlying signaling may lead to problems such as interruption of legitimate terminal services, impairment of terminal service performance, abnormal power consumption of the terminal, and abnormal resource scheduling of the base station.

[0136] In one solution, physical layer encryption of MAC layer messages is proposed to prevent attackers from obtaining and spoofing information. Specifically, the first device (such as a user equipment or a base station) generates a scrambling key based on a private shared key or the latest parameters. This solution can scramble the payload with the scrambling key before encoding. This solution can also include scrambling the encoded payload, and the scrambling operation is binary bitwise exclusive OR. This solution can also include aggregating the payload into a K-bit sequence using a K-bit aggregator (where K is a natural number greater than or equal to 2), aggregating the scrambled sequence into an M-bit rearrangement index using an M-bit aggregator (M is a natural number greater than K), and permuting and rearranging the K-bit aggregated payload sequence using the M-bit aggregated scrambling index to achieve the purpose of scrambling the payload. This solution can also include phase rotation or symbol inversion of the constellation points of Quadrature Phase Shift Keying (QPSK) or Quadrature Amplitude Modulation (QAM) modulation based on the aggregated scrambling key. This solution can also include complex multiplication of the modulated valid data and the modulated scrambling key. However, this solution does not describe the specific generation method of the physical layer scrambling key, nor does it explain how to obtain the shared key or the latest parameters input to the key generator, and thus fails to achieve the purpose of protecting the integrity of the physical layer payload.

[0137] In another solution, it is proposed that security parameters can be used to encrypt some bits in the PDCCH order DCI. These security parameters can be shared with both the BS and the UE through RRC signaling, MAC CE, and DCI. The encrypted DCI information bits can be the random access preamble sequence index (Preamble Index) and the physical random access channel (PRACH) PRACH mask index in the PDCCH Order DCI signaling. When the base station sends the PDCCH order DCI after security processing, an attacker cannot obtain and forge the DCI content. However, this solution cannot be directly applied to other DCIs or other underlying signaling, and this solution does not describe specific security parameters, specific key generation operations, and specific encryption operations.

[0138] Based on the above content, the present application provides a communication method and a communication device, adding physical layer integrity protection, which helps to improve the security of signaling or data between the sending end and the receiving end.

[0139] The communication method proposed by the present application will be described below.

[0140] Figure 7 is a schematic flowchart of the communication method 700 proposed by the present application.

[0141] The method 700 can be executed at the physical layer of the sending end and the receiving end. Optionally, the sending end can be a terminal, and the receiving end can be a network device (such as the base station described above). Optionally, the sending end can be a network device (such as the base station described above), and the receiving end can be a terminal. Optionally, both the sending end and the receiving end can be terminals. Optionally, both the sending end and the receiving end can be network devices (such as the base station described above).

[0142] The method 700 includes at least part of the following content.

[0143] Step 701, the sending end obtains a first code block and first information.

[0144] Among them, the first code block is the payload of a physical channel. The physical channel here can be any physical channel, such as a physical uplink shared channel (PUSCH), a physical downlink shared channel (PDSCH), a physical uplink control channel (PUCCH), or a physical downlink control channel (PDCCH).

[0145] Optionally, when the physical channel is PDCCH, the payload of the physical channel can be DCI. When the physical channel is PUCCH, the payload of the physical channel can be uplink control information (UCI). When the physical channel is PDSCH, the payload of the physical channel can be downlink data or DCI. When the physical channel is PUSCH, the payload of the physical channel can be uplink data or UCI.

[0146] This application does not specifically limit the way for the sending end to obtain the first code block.

[0147] A possible implementation is that the sending end obtains the first code block, including: the physical layer of the sending end obtains the first code block from the MAC layer of the sending end. For example, when the physical channel is PDCCH or PUCCH, the first code block can be obtained by the physical layer of the sending end from the MAC layer of the sending end.

[0148] Another possible implementation is that the sending end obtains the first code block, including: the physical layer of the sending end obtains a transport block (TB) from the MAC layer of the sending end; then the physical layer of the sending end calculates the check code of the transport block and adds the obtained check code to the back of the transport block; then the physical layer of the sending end divides the transport block and the check code as a whole into one or more code blocks (CBs), and the first code block is one of the one or more code blocks.

[0149] The first information of this application is the information used to calculate the integrity protection information. A possible implementation is that the first information can include at least one of the following information: a partial payload or the entire payload of the first code block, the first check code, an anti-replay parameter, a key, or downlink control information, where the downlink control information is used to schedule the first code block.

[0150] Among them, the first check code includes the check code of the first code block and / or the check code of the transport block to which the first code block belongs. For example, when the physical channel is PDCCH or PUCCH, the physical channel payload is relatively small and can be transmitted in one transport block. At this time, the first check code is the check code of the first code block or the check code of the transport block to which the first code block belongs. At this time, the check code of the first code block is the check code of the transport block to which the first code block belongs. Another example is that when the physical channel is PDSCH or PUSCH, the physical channel payload is relatively large, and it may be necessary to divide the physical channel payload into multiple code blocks for transmission, that is, divide the transport block into multiple code blocks for transmission. The multiple code blocks include the first code block. At this time, the first check code can be the check code of the transport block and the check code of the first code block, or the check code of the transport block, or the check code of the first code block. The check code of the first code block can be understood as the check code calculated according to the first code block, or the check code used for error checking of the first code block. Similarly, the check code of the transport block to which the first code block belongs can be understood as the check code calculated according to the transport block to which the first code block belongs, or the check code used for error checking of the transport block to which the first code block belongs. This application does not specifically limit the generation method of the check code. For example, the check code involved in this application can be a Cyclic Redundancy Check (CRC) code.

[0151] The anti-replay parameter may include: a cell-level parameter and / or a configuration parameter of the physical channel.

[0152] Among them, the cell-level parameter includes at least one of the following parameters: physical cell identifier, link frequency or frequency point, system bandwidth, or BWP information.

[0153] The configuration parameter of the physical channel includes the cell parameters of the physical channel sent by high-layer signaling (such as RRC signaling) and / or other parameters related to the physical channel transmission. Exemplarily, the configuration parameter of the physical channel includes at least one of the following parameters: time-domain parameter, frequency-domain parameter, sequence generation parameter, transmit power control parameter, or coding parameter. For a more detailed description of each parameter, reference can be made to the descriptions in FIGS. 10 to 15 below.

[0154] The key can be the key between the base station and the user, and the key is different for different users. The key can be a physical layer key derived from the base station key K_gNB with reference to the derivation method of the RRC integrity protection key K_RRCint, or a physical layer key derived from the channel entropy shared in the air interface environment between the base station and the terminal. The key can be shared by all the above physical channels, or each physical channel corresponds to a different key.

[0155] The downlink control information may also be referred to as scheduling DCI. When the physical channel is PUSCH or PDSCH, the first information may include downlink control information.

[0156] Optionally, when the first information includes the partial payload of the first code block, method 700 further includes: obtaining the partial payload of the first code block according to the first offset and the first length, where the first offset is the offset of the starting position of the partial payload of the first code block relative to the starting position of the first code block, and the first length is the length of the partial payload of the first code block. When the offset is 0, the starting position of the partial payload of the first code block is the same as the starting position of the first code block.

[0157] Optionally, when the first information includes the partial payload of the first code block, method 700 further includes: dividing the first code block into multiple sub-code blocks according to the division information, and obtaining the partial payload of each sub-code block among the multiple sub-code blocks according to the second offset and the second length. The partial payload of the first code block includes the partial payload of each sub-code block. The second offset is the offset of the starting position of the partial payload of each sub-code block relative to the starting position of each sub-code block, and the second length is the length of the partial payload of each sub-code block. Wherein, the division information may be the length of the sub-code block or the number of sub-code blocks.

[0158] The above first offset, first length, division information, second offset, and second length may be carried in the downlink control information.

[0159] Step 702, the sending end determines the first integrity protection information according to the first information and the security algorithm.

[0160] Wherein, the first integrity protection information is used to perform integrity protection on the first code block.

[0161] Specifically, the sending end uses the first information as the input information of the security algorithm and calculates the first integrity protection information.

[0162] This application does not specifically limit the security algorithm. Exemplarily, the security algorithm may be an integrity protection algorithm based on a symmetric key. For example, the security algorithm includes at least one of the following: SNOW 3G, SNOW V, AES-CMAC, ZUC (Zu Chongzhi), HMAC-SHA2, or HMAC-SHA3 and other integrity protection algorithms.

[0163] Step 703, the sending end determines the second code block according to the first code block and the first integrity protection information.

[0164] Wherein, the second code block includes the first code block and the first integrity protection information.

[0165] In a possible implementation, the sending end adds the first integrity protection information behind the first code block to which the check code has already been added, that is, the second code block includes the first code block, the check code of the first code block, and the first integrity protection information.

[0166] In another possible implementation, the sending end replaces the check code of the first code block with the first integrity protection information and appends it behind the first code block, that is, the second code block includes the first code block and the first integrity protection information, but does not include the check code of the first code block.

[0167] Step 704, the sending end outputs the second code block.

[0168] Subsequently, the sending end can also perform operations such as encoding, rate matching, scrambling, QAM modulation, and resource mapping on the second code block. For a more detailed description, reference can be made to the prior art and will not be elaborated here.

[0169] Step 705, wireless air interface transmission is performed between the sending end and the receiving end.

[0170] Step 706, the receiving end obtains the received code block of the physical channel.

[0171] Among them, the received code block includes the third code block and the second integrity protection information.

[0172] Specifically, the receiving end receives the signal transmitted through the wireless air interface and performs operations such as demapping, channel estimation, QAM demodulation, descrambling, derate matching, and decoding on the received signal to obtain the third code block. For a more detailed description, reference can be made to the prior art and will not be elaborated here.

[0173] It should be noted that the received code block may be the same as or different from the second code block in step 704. For example, if the second code block is not tampered with or counterfeited during transmission, the received code block is the same as the second code block in step 704. In this case, the integrity check shown in steps 707 to 709 below will succeed. Another example is that if the second code block is tampered with or counterfeited during transmission, the received code block is different from the second code block in step 704. In this case, the integrity check shown in steps 707 to 709 below will fail.

[0174] Step 707, the receiving end obtains the second information.

[0175] Among them, the second information includes at least one of the following information: part or all of the payload of the third code block, the second check code, anti-replay parameters, keys, or downlink control information.

[0176] Among them, the second check code is calculated based on the third code block in the received code block. The second check code includes the check code of the third code block and / or the check code of the transport block to which the third code block belongs. For example, when the physical channel is PDCCH or PUCCH, the physical channel payload is relatively small and can be transmitted in one transport block. At this time, the second check code is the check code of the third code block or the check code of the transport block to which the third code block belongs. At this time, the check code of the third code block is the check code of the transport block to which the third code block belongs. Another example is that when the physical channel is PDSCH or PUSCH, the physical channel payload is relatively large and may need to divide the physical channel payload into multiple code blocks for transmission, that is, divide the transport block into multiple code blocks for transmission. At this time, the second check code can be the check code of the transport block and the check code of the third code block, or the check code of the transport block, or the check code of the third code block. The check code of the third code block can be understood as the check code calculated according to the third code block, or the check code used for error checking of the third code block. Similarly, the check code of the transport block to which the third code block belongs can be understood as the check code calculated according to the transport block to which the third code block belongs, or the check code used for error checking of the transport block to which the third code block belongs. This application does not make specific limitations on the generation method of the check code. For example, the check code involved in this application can be a cyclic redundancy check code.

[0177] It should be noted that the first check code on the sending end side and the second check code on the receiving end side should be calculated in the same way.

[0178] The anti-replay parameters, keys, and downlink control information used by the receiving end are the same as those used by the sending end. These parameters can be pre-configured, or negotiated by the sending end and the receiving end through signaling, or generated by the sending end and the receiving end using the same generation method.

[0179] Optionally, when the second information includes a partial payload of the third code block, method 700 further includes: obtaining the partial payload of the third code block according to the first offset and the first length, where the first offset is the offset of the start position of the partial payload of the third code block relative to the start position of the third code block, and the first length is the length of the partial payload of the third code block.

[0180] Optionally, when the second information includes the partial payload of the third code block, method 700 further includes: dividing the third code block into multiple sub-code blocks according to the division information, and obtaining the partial payload of each sub-code block according to the second offset and the second length. The partial payload of the third code block includes the partial payload of each sub-code block. The second offset is the offset of the start position of the partial payload of each sub-code block relative to the start position of each sub-code block, and the second length is the length of the partial payload of each sub-code block. Among them, the division information may be the length of the sub-code block or the number of sub-code blocks. In a possible implementation, the second offset corresponding to each sub-code block may be the same or different, or the second length corresponding to each sub-code block may also be the same or different.

[0181] It should be noted that the first offset, the first length, the division information, the second offset, and the second length used by the receiving end are the same as those used by the sending end. These parameters may be pre-configured or negotiated by signaling between the sending end and the receiving end.

[0182] Step 708, the receiving end determines the third integrity protection information according to the second information and the security algorithm.

[0183] Specifically, the receiving end uses the second information as the input information of the security algorithm to calculate the third integrity protection information.

[0184] It should be noted that the security algorithm used by the receiving end is the same as that used by the sending end. The security algorithm may be pre-configured or negotiated by signaling between the sending end and the receiving end.

[0185] Step 709, perform integrity verification on the third code block according to the second integrity protection information and the third integrity protection information.

[0186] Specifically, when the second integrity protection information and the third integrity protection information are the same, the integrity verification of the third code block is successful. When the second integrity protection information and the third integrity protection information are different, the integrity verification of the third code block fails.

[0187] In this way, physical layer integrity protection can be achieved through method 700, which helps to improve the security of signaling or data between the transmitter and the receiver. When the check code is used as the input of the security algorithm, the error detection function of the check code can be fully utilized. And when the check code includes the check code of the transport block to which the code block belongs, since the check code of the transport block to which the code block belongs is calculated based on the transport block, a certain degree of integrity protection can be provided for all the payloads of the physical channel. When the downlink control information is used as the input of the security algorithm, the correlation between the DCI of the PDCCH and the PDSCH or PUSCH can be utilized to further increase the difficulty of attack. When the cell-level parameters and the configuration parameters of the physical channel are used as the input of the security algorithm, anti-replay capabilities can be provided, such as preventing an attacker from replaying signaling or data at other time-frequency, frequency domain, spatial domain, or encoded with other parameters.

[0188] The present application also provides a method for activating the physical layer integrity protection mechanism. In this method, the transmitter and the receiver can activate the physical layer integrity protection mechanism after the access layer security protection mode is completed.

[0189] Figure 8 is a schematic flowchart of the method for activating the physical layer integrity protection mechanism.

[0190] In Figure 8, the communication between the UE and the base station is taken as an example.

[0191] The L3 of the base station starts RRC integrity protection.

[0192] Step 1, the L3 of the UE (i.e., the RRC layer) sends an RRC message (i.e., the Security Mode Complete (SMC) message), which carries the RRC layer integrity protection information.

[0193] Step 2, the L1 of the base station (i.e., the physical layer) decodes the PUSCH carrying the SMC complete message.

[0194] Step 3, if the PUSCH decoding is successful, then the L1 of the base station sends down DCI, and the DCI indicates an uplink Hybrid Automatic Repeat Request (HARQ) Acknowledgement (ACK); if the PUSCH decoding fails, then the L1 of the base station sends down DCI, and the DCI indicates an uplink HARQ Negative Acknowledgement (NACK).

[0195] Step 4, the L3 of the base station checks the integrity of the SMC complete message.

[0196] If the integrity verification of the SMC completion message is successful, then the L3 of the base station notifies the L1 of the base station to start "physical layer integrity protection", that is, to activate the physical layer integrity protection mechanism.

[0197] Exemplarily, after activating the physical layer integrity protection mechanism, integrity protection information can be added to the payload of the physical channel when sending the payload of the physical channel. For example, the integrity protection information for the payload of the physical channel can be added in the manner shown in Method 700. It should be noted that after activating the physical layer integrity protection mechanism, the subsequent operations performed by the physical layer are not limited to the implementation manner shown in Method 700.

[0198] Step 5, the L1 of the base station starts the physical layer integrity protection mechanism.

[0199] Step 6, after the L1 of the UE receives the uplink HARQ ACK for the SMC completion message, it starts the physical layer integrity protection mechanism.

[0200] It should be noted that other steps for AS security establishment can also be performed before Step 1, and the detailed description can refer to the prior art.

[0201] It should also be noted that the method shown in FIG. 8 can be implemented alone or in combination with other embodiments of the present application. For example, the method shown in FIG. 8 can be combined with Method 700, that is, the method shown in FIG. 8 can be executed before Method 700.

[0202] The present application also provides a method for updating physical layer integrity protection parameters. In this method, the sending end and the receiving end can update the physical layer integrity protection parameters after the radio link control reconfiguration is completed.

[0203] FIG. 9 is a schematic flowchart of the method for updating physical layer integrity protection parameters.

[0204] In FIG. 9, the communication between the UE and the base station is taken as an example.

[0205] Step 1, the L3 of the UE sends an RRC Reconfiguration Complete message, and this message has encryption and integrity protection.

[0206] Step 2, the L1 of the base station decodes the PUSCH carrying the RRC Reconfiguration Complete.

[0207] Step 3, if the PUSCH decoding is successful, then the L1 of the base station sends down DCI, and the DCI indicates the uplink HARQ ACK; if the PUSCH decoding fails, then the L1 of the base station sends down DCI, and the DCI indicates the uplink HARQ NACK.

[0208] Step 4, the L3 of the base station decrypts and verifies the integrity of the RRC reconfiguration complete message.

[0209] If the integrity verification of the RRC reconfiguration complete message is successful, then the L3 of the base station notifies the L1 of the base station to update the configuration parameters of the physical channel. The configuration parameters of the physical channel can also be described as physical channel specific parameters. For a more detailed description, reference can be made to method 700, which will not be elaborated here.

[0210] Step 5, the L1 of the base station updates and uses the configuration parameters of the new physical channel.

[0211] Step 6, the L1 of the UE receives the uplink HARQ ACK for the RRC reconfiguration complete message, and the L1 of the UE updates and uses the configuration parameters of the new physical channel.

[0212] It should be noted that other steps of RRC reconfiguration can also be performed before step 1. For a detailed description, reference can be made to the prior art.

[0213] It should also be noted that the method shown in FIG. 9 can be implemented alone or in combination with other embodiments of the present application. For example, the method shown in FIG. 9 can be combined with method 700 and / or the method shown in FIG. 8.

[0214] Next, in combination with a specific scenario, the communication method of the present application will be described. Hereinafter, the physical channel specific parameters can correspond to the configuration parameters of the physical channel above.

[0215] Embodiment 1

[0216] FIG. 10 is an overall schematic diagram of the communication method provided by the present application. FIG. 10 takes the transmitting end as an example.

[0217] The communication method provided by the present application is applied after the activation of the AS access layer security mode. The transmitting end can use all or part of the bit string of the physical channel transmission information, the CRC check code of the TB, the CRC check code of the CB, the scheduling DCI information, cell-level parameters, physical channel specific parameters and other anti-replay parameters, at least one of the physical layer keys as the input of the security algorithm to generate integrity protection information; and replace the CRC check code with the integrity protection information and append it to the physical layer payload, so as to achieve integrity protection of the transmission information of the physical channel.

[0218] 1. The physical channel can be physical channels such as PDCCH, PDSCH, PUCCH, PUSCH, etc.

[0219] In a possible implementation manner, for PDCCH and PUCCH, all payloads can be used as one of the inputs of the integrity protection security algorithm.

[0220] A possible implementation is that for PDSCH and PUSCH, they are grouped according to the transmission payload length and a part of the bit string is intercepted as the input of the security algorithm. Optionally, parameters such as the grouping length, the interception length, and the starting offset can be sent down in the scheduling DCI.

[0221] A possible implementation is that for PDCCH and PUCCH, the CRC check code refers to the CRC check code of the transport block TB. For PDSCH and PUSCH, the CRC check code can be the CRC check code of the TB and / or the CRC check code of the CB.

[0222] A possible implementation is that for PDSCH and PUSCH, the payload information of their corresponding scheduling DCI (carried by PDCCH) can also be used as one of the inputs of the integrity protection security algorithm for PDSCH and PUSCH.

[0223] A possible implementation is that the anti-replay parameters can be composed of cell-level parameters and physical-channel-specific parameters.

[0224] Specifically, the anti-replay parameters can include the cell parameter of this physical channel encrypted and sent down by the high-layer RRC signaling, and / or other parameters related to the physical-layer transmission of this physical channel.

[0225] Among them, the cell-level parameters can include at least one of the physical cell ID, the downlink frequency point, the uplink frequency point, the system bandwidth, the BWP information, etc.

[0226] The physical-channel-specific parameters can include at least one of the time-domain parameters, frequency-domain parameters, space-domain parameters, sequence generation parameters, or coding parameters related to the transport block processing of this physical channel.

[0227] Among them, the time-domain parameters include at least one of the system frame number, the slot, the symbol starting position, and the number of symbols; the frequency-domain parameters include at least one of the starting RB, the number of occupied RBs, and the frequency hopping information; the space-domain parameters include the number of antenna ports or the number of scheduled streams.

[0228] The sequence generation parameters include the parameters for generating the bit scrambling sequence and the Demodulation Reference Signal (DMRS) sequence, the DMRS port number, etc.

[0229] The coding parameters include the interleaving information, the precoding granularity, the Modulation and Coding Scheme (MCS), the HARQ information, etc.

[0230] Among them, the key, which can also be referred to as the physical layer key, can have a granularity that is shared by all physical channels or different for each physical channel. Exemplarily, the physical layer key can be derived from the base station key K_gNB with reference to the derivation method of the RRC integrity protection key K_RRCint, or can be derived from the channel entropy shared in the air interface environment between the base station and the terminal.

[0231] The physical layer integrity protection for different channels will be described below in conjunction with Embodiment 2 to Embodiment 4.

[0232] Embodiment 2

[0233] This embodiment provides a method for physical layer integrity protection of PDCCH. Among them, DCI can correspond to the first code block mentioned above.

[0234] FIG. 11 is a schematic diagram of the integrity protection mechanism of 1 transport block DCI on the PDCCH physical channel in a transmission time slot. The upper part of FIG. 11 corresponds to the relevant processing of PDCCH transmission on the base station side, and the lower part corresponds to the relevant processing of PDCCH reception on the UE side.

[0235] Specifically, on the base station side, first according to the existing process in 3GPP standard TS 38.212, calculate the CRC check code of the TB of DCI, then perform an XOR masking operation on the last 16 bits of the TB CRC with the RNTI corresponding to this DCI, and use the TB CRC masked by RNTI as one of the inputs of the integrity protection generation algorithm. The base station takes all the PDCCH payload DCI, TB CRC, anti-replay parameters, and physical layer key as the inputs of the PDCCH integrity protection algorithm (i.e., the security algorithm) to generate the integrity protection information H; the base station replaces the TB CRC with the integrity protection information H and attaches it behind the transport block DCI as the input of Polar coding. Among them, the anti-replay parameters include cell-level parameters and PDCCH-specific parameters.

[0236] The UE calculates the TB CRC corresponding to the decoded DCI based on the output result of polar decoding, and takes the received decoded DCI, the TB CRC calculated by the receiver, the anti-replay parameters, and the physical layer key as the inputs of the PDCCH integrity protection algorithm to generate the integrity protection information H'; the UE completes the verification of the physical layer integrity protection by comparing the received integrity protection information H with the integrity protection information H' calculated by itself. If H is the same as H', it indicates that the PDCCH DCI integrity protection verification is successful, otherwise the DCI integrity verification fails.

[0237] Other operations in the figure can refer to the prior art and will not be elaborated here.

[0238] The input parameters of the security algorithm are described below.

[0239] 1. Anti-replay parameters

[0240] The anti-replay parameters can be composed of cell-level parameters and PDCCH-specific parameters, and specifically can include PDCCH cell parameters encrypted and sent by high-layer RRC signaling, and / or other parameters related to the physical-layer transmission of PDCCH DCI, etc. These anti-replay parameters, as the input of the security algorithm, can defend against or mitigate replay attacks. The anti-replay parameters include but are not limited to the following information:

[0241] 1) Cell-level parameters: Physical cell ID, downlink frequency ARFCN, system bandwidth, BWP information, etc.

[0242] 2) The PDCCH-specific parameters can be time-domain parameters, frequency-domain parameters, sequence generation parameters, coding information, etc. related to the PDCCH's transport block processing. Among them,

[0243] (1) The time-domain parameters include at least one of the following: system frame number, slot, time-domain related parameters in the cell SearchSpace (e.g., monitoring period and slot offset: monitoringSlotPeriodicityAndOffset; number of monitored slots: duration), time-domain related parameters in the cell CORESET (e.g., PDCCH start symbol: monitoringSymbolsWithSlot; number of PDCCH symbols: duration).

[0244] (2) The frequency-domain parameters include at least one of the following: CORESET frequency-domain resources (e.g., cell frequencyDomainResources), CCE aggregation level and number of candidate sets (e.g., aggregationLevel and nrofCandidates in the cell SearchSpace), starting CCE index.

[0245] (3) The sequence generation parameters include at least one of the following: parameters for generating PDCCH scrambling sequences and DMRS sequences (e.g., pdcch-DMRS-ScramblingID in the cell CORESET).

[0246] (4) The encoded information includes at least one of the following: the mapping method from CCE to REG (e.g., cce-REG-MappingType in the cell CORESET), the interleaved block size (reg-BundleSize), the interleaved depth (interleaverSize), the REG interleaved offset index (shiftIndex), and the precoding granularity (precoderGranularity).

[0247] The high-layer configuration parameters related to PDCCH are in the CORESET and SearchSpace cells, and these two cells can be sent by the base station to inform the UE through the RRCSetup or RRCReconfiguration signaling. Among them, the RRC reconfiguration signaling has encryption and integrity protection.

[0248] 2. Security algorithm

[0249] The security algorithm can adopt a known integrity protection algorithm based on symmetric keys, which is not limited here.

[0250] Optionally, integrity protection algorithms such as SNOW 3G or SNOW V, AES-CMAC, and ZUC (Zu Chongzhi) adopted by the PDCP layer in the 4G and 5G standards can be selected.

[0251] Optionally, integrity protection algorithms such as HMAC-SHA2 and HMAC-SHA3 can be selected. HMAC (Hash-based Message Authentication Code) is a message authentication code based on hash operations. SHA2 and SHA-3 (Secure Hash Algorithm 3) are different secure hash algorithms. Based on a shared symmetric key, HMAC can use any iterative hash function that can be used for encryption.

[0252] In this embodiment, all or part of the output result of the security algorithm can be truncated as the physical layer integrity protection information, and then this physical layer integrity protection information is used to replace the CRC bit string and appended to the back of the transport block.

[0253] Embodiment 3

[0254] This embodiment provides a method for physical layer integrity protection of PUCCH. Among them, UCI can correspond to the first code block above.

[0255] Figure 12 is a schematic diagram of the method for physical layer integrity protection of PUCCH.

[0256] The sender (i.e., the UE) takes the entire PUCCH payload UCI, TB CRC, anti-replay parameters, and physical layer key as the input of the PUCCH integrity protection algorithm to generate the integrity protection information H. Then, it replaces the TB CRC with the integrity protection information and appends it behind the transport block UCI as the input for Polar coding.

[0257] The receiver (i.e., the base station) calculates the TB CRC corresponding to the decoded UCI based on the Polar decoding output, and takes the received decoded UCI, the TB CRC calculated by the receiver, anti-replay parameters, and physical layer key as the input of the PUCCH integrity protection algorithm (i.e., the security algorithm) to generate the integrity protection information H'. The receiver completes the verification of the physical layer integrity protection by comparing the received integrity protection information H with the integrity protection information H' calculated by itself. If H is equal to H', it indicates that the PUCCH UCI integrity protection verification is successful; otherwise, the UCI integrity verification fails.

[0258] For other operations on the transport block UCI, reference can be made to Figure 11, which will not be elaborated here.

[0259] The input parameters of the security algorithm are described below.

[0260] 1. Anti-replay parameters

[0261] The anti-replay parameters can be composed of cell-level parameters and PUCCH-specific parameters, specifically including PUCCH cell parameters encrypted and sent by high-layer RRC signaling, and / or other parameters related to the physical layer transmission of PUCCH UCI, etc. These anti-replay parameters, as the input of the security algorithm, can defend against or mitigate replay attacks. Among them,

[0262] The cell-level parameters include at least one of the following information: physical cell ID, uplink center frequency point, system bandwidth, BWP information, etc.

[0263] The PUCCH-specific parameters can be time-domain parameters, frequency-domain parameters, sequence generation parameters, coding parameters, or other parameters related to the transport block processing of PUCCH. Specifically,

[0264] (1) The time-domain parameters include at least one of the following information: system frame number, slot, the number of symbols nrofSymbols and the starting symbol index startingSymbolIndex in the cell PUCCH-Config.

[0265] (2) The frequency-domain parameters include at least one of the following information: the number of PRBs nrofPRBs in the cell PUCCH-Config, the starting PRB of the resource set in the frequency domain startingPRB, and the index of the second PRB after PUCCH frequency hopping secondHopPRB.

[0266] (3) The sequence generation parameters include at least one of the following information: the additional DMRS pilot parameter additionalDMRS, and the hopping parameters pucch-GroupHopping and hoppingId of the PUCCH sequence group and sequence.

[0267] (4) The coding parameters include at least one of the following information: PUCCH format, the OCC information (occ-Index, occ-Length) of format4, the maximum code rate (maxCodeRate) of UCI, and the intra-slot frequency hopping (intraSlotFrequencyHopping).

[0268] (5) The other parameters include the transmit power control parameter (p0-nominal).

[0269] The high-layer configuration parameters related to PUCCH are in the PUCCH-Config cell, and this cell can be sent by the base station to inform the UE through the RRCSetup or RRCReconfiguration signaling. Among them, the RRC reconfiguration signaling has encryption and integrity protection.

[0270] 2. Security algorithms

[0271] The security algorithm can adopt a known integrity protection algorithm based on symmetric keys, which is not limited here.

[0272] Optionally, integrity protection algorithms such as SNOW 3G or SNOW V, AES-CMAC, and ZUC (Zu Chongzhi) adopted by the PDCP layer in the 4G and 5G standards can be selected.

[0273] Optionally, integrity protection algorithms such as HMAC-SHA2 and HMAC-SHA3 can be selected. The HMAC (Hash-based Message Authentication Code) is a message authentication code based on hash operations. Based on a shared symmetric key, HMAC can use any iterative hash function that can be used for encryption.

[0274] In this embodiment, all or part of the output result of the security algorithm can be truncated as the physical layer integrity protection information, and then this physical layer integrity protection information is used to replace the CRC bit string and appended to the back of the transport block.

[0275] Example 4

[0276] This embodiment provides a method for physical layer integrity protection of PDSCH or PUSCH. Among them, the data carried in PDSCH or PUSCH may correspond to the first code block above.

[0277] PDSCH is the Physical Downlink Shared Channel, which is used to carry data from the transport channel (downlink shared channel, DSCH), specifically including downlink information such as downlink user data, NAS signaling, RRC signaling, and MAC CE.

[0278] PUSCH is the Physical Uplink Shared Channel, which is used to carry data from the transport channel (uplink shared channel, USCH), specifically including uplink information such as uplink user data, NAS signaling, RRC signaling, L2MAC CE, and L1UCI (uplink control information UCI can be sent along with PUSCH. When there is no PUSCH, PUCCH can send UCI).

[0279] The computational processing processes of PDSCH and PUSCH at the physical layer are similar, and the physical layer integrity protection methods of PDSCH and PUSCH can also adopt similar solutions. However, the physical channel specific parameters of PDSCH and PUSCH are different, resulting in different anti-replay parameters for physical layer integrity protection of the two channels.

[0280] In existing standards, if the length of the transport block TB is relatively large, it will be grouped into multiple code blocks CB according to certain rules, that is, one TB consists of one or more CBs.

[0281] The following takes the PDSCH integrity protection method as an example for illustration. The PUSCH integrity protection method can refer to the PDSCH integrity protection method and will not be elaborated here.

[0282] The sender (i.e., the base station) takes at least one of the entire or partial payload of the PDSCH code block CB, CB CRC, TB CRC, downlink scheduling DCI, anti-replay parameter, and physical layer key, etc. as the input of the PDSCH integrity protection algorithm (security algorithm) to generate the integrity protection information H; then replaces the CB CRC with the integrity protection information H and attaches it behind the code block CB, and / or replaces the TB CRC with the integrity protection information H and attaches it behind the transport block TB, and finally takes them together as the input of LDPC coding.

[0283] The receiving party (i.e., the UE) calculates the TB CRC or CB CRC corresponding to the decoded TB or CB based on the LDPC decoding output, and uses all or part of the payload of the decoded CB, and / or the CB CRC calculated by the receiving party, and / or the TB CRC calculated by the receiving party, and / or the downlink scheduling DCI, and / or the anti-replay parameter, and / or the physical layer key as the input of the PDSCH integrity protection algorithm to generate the integrity protection information H'; the receiving party completes the verification of the physical layer integrity protection by comparing the received integrity protection information H with the integrity protection information H' calculated by itself. If H is equal to H', it indicates that the integrity protection verification of the PDSCH TB and / or CB is successful, otherwise the integrity verification fails.

[0284] Figures 13 to 15 are schematic diagrams of the physical layer integrity protection method for PDSCH or PUSCH. As shown in Figure 13, all or part of the payload of the CB, the CB CRC, the anti-replay parameter, and the physical layer key can be used as the input of the PDSCH integrity protection algorithm (security algorithm) to generate the integrity protection information H. As shown in Figure 14, all or part of the payload of the CB, the CB CRC, the TB CRC, the anti-replay parameter, and the physical layer key can be used as the input of the PDSCH integrity protection algorithm (security algorithm) to generate the integrity protection information H. As shown in Figure 15, all or part of the payload of the CB, the CB CRC, the TB CRC, the scheduling DCI, the anti-replay parameter, and the physical layer key can be used as the input of the PDSCH integrity protection algorithm (security algorithm) to generate the integrity protection information H.

[0285] The input parameters of the security algorithm are described below.

[0286] 1. Anti-replay parameter

[0287] The anti-replay parameter can be composed of cell-level parameters and PDSCH-specific parameters, and can specifically include PDSCH cell parameters encrypted and sent by high-layer RRC signaling, and / or other parameters related to the physical layer transmission of the PDSCH transport block, etc. These anti-replay parameters can be used as the input of the security algorithm to defend against or mitigate replay attacks. Among them,

[0288] The cell-level parameters include one or more of the following information: physical cell ID, downlink frequency ARFCN, system bandwidth, BWP information, etc.

[0289] The PDSCH-specific parameters can include one or more of the following information: time-domain parameters, frequency-domain parameters, sequence generation parameters, coding parameters, etc. related to the transport block processing of the PDSCH. Specifically,

[0290] (1) Time domain parameters include one or more of the following information: system frame number, slot, time domain resource configuration index (Time domain resource assignment in DCI), time domain resource configuration (k0 in the cell PDSCH-Config (indicating the offset between the PDSCH transmission time slot and the scheduling DCI transmission time slot), mapping type mappingType, start symbol and number of consecutive OFDM symbols startSymbolAndLength).

[0291] (2) Frequency domain parameters include one or more of the following information: allocation type (resourceAllocation, bitmap or RIV (Resource Indication Value)), rbg-Size, start RB, number of PRBs, frequency hopping (Frequency Hopping Flag).

[0292] (3) Sequence generation parameters include one or more of the following information: dmrs-Type, dmrs-AdditionalPosition, maxLength, DMRS ports. DMRS sequence generation parameters scramblingID0 and scramblingID1 in the cell DMRS-DownlinkConfig. Data scrambling identity PDSCH for the scrambling sequence generation parameter in the cell PDSCH-Config.

[0293] (4) Coding parameters include one or more of the following information: MCS (Modulation and Coding Scheme), new data indication (NDI), redundancy version (RV), HARQ process number.

[0294] The high-layer configuration parameters related to PDSCH are in the PDSCH-Config and DMRS-DownlinkConfig cells. These two cells can be sent by the base station to inform the UE through the RRCSetup or RRCReconfiguration signaling, and the RRC reconfiguration signaling has encryption and integrity protection.

[0295] The high-layer configuration parameters related to PUSCH are in the PUSCH-config and DMRS-UplinkConfig cells. These two cells can be sent by the base station to inform the UE through the RRCSetup or RRCReconfiguration signaling, and the RRC reconfiguration signaling has encryption and integrity protection. k2 in the cell PUSCH-Config indicates the offset between the PUSCH transmission time slot and the scheduling DCI transmission time slot.

[0296] 2. Security Algorithm

[0297] The security algorithm can adopt known integrity protection algorithms based on symmetric keys, which are not limited herein.

[0298] Optionally, integrity protection algorithms such as SNOW 3G or SNOW V, AES-CMAC, and ZUC (Zu Chongzhi) adopted by the PDCP layer in the 4G and 5G standards can be selected for use.

[0299] Optionally, integrity protection algorithms such as HMAC-SHA2 and HMAC-SHA3 can be selected for use. HMAC (Hash-based Message Authentication Code) is a message authentication code based on hash operations. Based on a shared symmetric key, HMAC can use any iterative hash function that can be used for encryption.

[0300] In this embodiment, all or part of the output result of the security algorithm can be truncated as the physical layer integrity protection information, and then this physical layer integrity protection information is used to replace the TB CRC or CB CRC and appended behind the transport block or code block.

[0301] 3. When a partial combination of the CB is used as one of the inputs of the security algorithm, the method of taking the partial payload of the CB can include any one of the following methods:

[0302] Method 1: A single CB code block is used as a sub-block, and a payload with a length of Length is intercepted starting from the starting offset position offset within a single CB. The intercepted payload with a length of Length is used as the input of the security algorithm. Where offset + Length < the length of the CB block.

[0303] The base station issues parameters such as the offset offset and the intercepted length Length in the scheduling DCI corresponding to the transport block to inform the terminal.

[0304] Method 2: A single CB code block is split into N sub-blocks, and the length of each sub-block is subblock_size, where N * subblock_size = the length of the CB block. A payload with a length of Length is intercepted starting from the starting offset position offset within each sub-block, and the N segments of payload intercepted from the N sub-blocks are combined into a bit sequence, which is used as one of the inputs of the security algorithm. Where offset + Length < the length of the sub-block.

[0305] The base station issues parameters such as the sub-block length, the offset offset, and the intercepted length Length in the scheduling DCI corresponding to the transport block to inform the terminal.

[0306] It should be noted that the relevant descriptions in Embodiments 1 to 4 can be adaptively applied to the method embodiments described in FIGS. 7-9. Similarly, the relevant descriptions in the method embodiments described in FIGS. 7-9 can also be adaptively applied to Embodiments 1-4. For the sake of brevity, they will not be repeated in this application.

[0307] Above, in connection with FIGS. 7 to 15, the method provided by this application has been described in detail. Next, in connection with FIGS. 16 to 17, the device embodiments of this application will be described in detail.

[0308] It can be understood that, in order to implement the functions in the above embodiments, the devices in FIG. 16 or FIG. 17 include corresponding hardware structures and / or software modules for executing various functions. Those skilled in the art should easily realize that, in combination with the units and method steps of the examples described in the embodiments disclosed in this application, this application can be implemented in the form of hardware or a combination of hardware and computer software.

[0309] FIGS. 16 and 17 are schematic structural diagrams of possible devices provided by the embodiments of this application. These devices can be used to implement the functions of the sending end or the receiving end in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments.

[0310] As shown in FIG. 16, the device 10 includes a transceiver unit 11 and a processing unit 12.

[0311] When the device 10 is used to implement the function of the sending end in the above method embodiment, the transceiver unit 11 is used to: obtain a first code block and first information, where the first code block is the payload of a physical channel, and the first information includes at least one of the following information: a partial payload or the entire payload of the first code block, a first check code, an anti-replay parameter, a key, and downlink control information for scheduling the first code block. The processing unit 12 is used to: determine first integrity protection information according to the first information and a security algorithm; determine a second code block according to the first code block and the first integrity protection information, where the second code block includes the first code block and the first integrity protection information. The transceiver unit 11 is further used to: output the second code block.

[0312] Optionally, the first check code includes a check code for the first code block and / or a check code for the transport block to which the first code block belongs.

[0313] Optionally, the second code block does not include the check code of the first code block.

[0314] Optionally, when the first information includes a partial payload of the first code block, the processing unit 12 is further configured to: obtain the partial payload of the first code block according to a first offset and a first length, where the first offset is an offset of a start position of the partial payload of the first code block relative to a start position of the first code block, and the first length is a length of the partial payload of the first code block; or divide the first code block into a plurality of sub-code blocks according to division information, and obtain a partial payload of each sub-code block among the plurality of sub-code blocks according to a second offset and a second length, where the partial payload of the first code block includes the partial payload of each sub-code block, the second offset is an offset of a start position of the partial payload of each sub-code block relative to a start position of each sub-code block, and the second length is a length of the partial payload of each sub-code block.

[0315] Optionally, the first offset, the first length, the division information, the second offset, and the second length are carried in the downlink control information.

[0316] Optionally, the physical channel is a physical uplink shared channel, a physical downlink shared channel, a physical uplink control channel, or a physical downlink control channel.

[0317] Optionally, when the first information includes the downlink control information, the physical channel is a physical uplink shared channel or a physical downlink shared channel.

[0318] Optionally, the anti-replay parameter includes: a cell-level parameter and / or a configuration parameter of the physical channel; where the cell-level parameter includes at least one of the following parameters: a physical cell identifier, a link frequency or frequency point, a system bandwidth, or BWP information; the configuration parameter of the physical channel includes at least one of the following parameters: a time-domain parameter, a frequency-domain parameter, a sequence generation parameter, a transmit power control parameter, or a coding parameter.

[0319] Optionally, the security algorithm is an integrity protection algorithm based on a symmetric key.

[0320] Optionally, the processing unit 12 is further configured to: activate a physical layer integrity protection mechanism after the access layer security protection mode is completed.

[0321] Optionally, the processing unit 12 is further configured to: update the configuration parameter of the physical channel after the radio link control reconfiguration is completed.

[0322] When the device 10 is used to implement the functions of the receiving end in the above method embodiments, the transceiver unit 11 is used to: obtain the received code block of the physical channel, where the received code block includes the physical channel payload and the second integrity protection information; obtain the second information, where the second information includes at least one of the following information: a partial payload or all payloads of the physical channel payload, a second check code, an anti-replay parameter, a key, and downlink control information, where the downlink control information is used to schedule the physical channel payload, and the second check code is obtained based on the physical channel payload. The processing unit 12 is used to: determine the third integrity protection information according to the second information and a security algorithm; perform integrity verification on the physical channel payload according to the second integrity protection information and the third integrity protection information.

[0323] Optionally, the second check code includes a check code for the physical channel payload and / or a check code for the transport block to which the physical channel payload belongs.

[0324] Optionally, the received code block does not include the check code for the physical channel payload.

[0325] Optionally, when the second information includes a partial payload of the physical channel payload, the processing unit 12 is further used to: obtain the partial payload of the physical channel payload according to a first offset and a first length, where the first offset is the offset of the start position of the partial payload of the physical channel payload relative to the start position of the physical channel payload, and the first length is the length of the partial payload of the physical channel payload; or, divide the physical channel payload into multiple sub-code blocks according to division information, and obtain the partial payload of each sub-code block in the multiple sub-code blocks according to a second offset and a second length, where the partial payload of the physical channel payload includes the partial payload of each sub-code block, the second offset is the offset of the start position of the partial payload of each sub-code block relative to the start position of each sub-code block, and the second length is the length of the partial payload of each sub-code block.

[0326] Optionally, the first offset, the first length, the division information, the second offset, and the second length are carried in the downlink control information.

[0327] Optionally, the physical channel is a physical uplink shared channel, a physical downlink shared channel, a physical uplink control channel, or a physical downlink control channel.

[0328] Optionally, when the second information includes the downlink control information, the physical channel is a physical uplink shared channel or a physical downlink shared channel.

[0329] Optionally, the replay prevention parameter includes: a cell-level parameter and / or a configuration parameter of the physical channel; wherein, the cell-level parameter includes at least one of the following parameters: a physical cell identifier, a link frequency or frequency point, a system bandwidth, or BWP information; the configuration parameter of the physical channel includes at least one of the following parameters: a time-domain parameter, a frequency-domain parameter, a sequence generation parameter, a transmit power control parameter, or a coding parameter.

[0330] Optionally, the security algorithm is an integrity protection algorithm based on a symmetric key.

[0331] Optionally, the processing unit 12 is further configured to: after the access stratum security protection mode is completed, activate the physical layer integrity protection mechanism.

[0332] Optionally, the processing unit 12 is further configured to: after the radio link control reconfiguration is completed, update the configuration parameter of the physical channel.

[0333] For a more detailed description of the above transceiver unit 11 and processing unit 12, reference may be made to the relevant descriptions in the above method embodiments, which will not be elaborated herein.

[0334] As shown in FIG. 17, the apparatus 20 includes a processor 21. The processor 21 is coupled to a memory 23, and the memory 23 is used to store instructions. When the apparatus 20 is used to implement the method described above, the processor 21 is configured to execute the instructions in the memory 23 to implement the functions of the above processing unit 12.

[0335] Optionally, the apparatus 20 further includes a memory 23.

[0336] Optionally, the apparatus 20 further includes an interface circuit 22. The processor 21 and the interface circuit 22 are coupled to each other. It can be understood that the interface circuit 22 may be a transceiver or an input / output interface. When the apparatus 20 is used to implement the method described above, the processor 21 is configured to execute instructions to implement the functions of the above processing unit 12, and the interface circuit 22 is configured to implement the functions of the above transceiver unit 11.

[0337] Exemplarily, when the apparatus 20 is a chip applied to a transmitting end or a receiving end, the chip implements the functions of the transmitting end or the receiving end in the above method embodiments. The chip receives information from other modules (such as a radio frequency module or an antenna) in the transmitting end or the receiving end, and this information is sent by other devices to the transmitting end or the receiving end; or, the chip sends information to other modules (such as a radio frequency module or an antenna) in the transmitting end or the receiving end, and this information is sent by the transmitting end or the receiving end to other devices.

[0338] The present application also provides a communication device, including a processor coupled to a memory. The memory is used to store computer programs or instructions and / or data. The processor is used to execute the computer programs or instructions stored in the memory, or read the data stored in the memory, so as to execute the methods in the above method embodiments. Optionally, the processor is one or more. Optionally, the communication device includes a memory. Optionally, the memory is one or more. Optionally, the memory is integrated with the processor or is separately provided.

[0339] The present application also provides a computer-readable storage medium, on which computer instructions for implementing the methods executed by the sending end or the receiving end in the above method embodiments are stored.

[0340] The present application also provides a computer program product, including instructions which, when executed by a computer, are used to implement the methods executed by the sending end or the receiving end in the above method embodiments.

[0341] The present application also provides a communication system, which includes at least one of the sending end or the receiving end in the above embodiments.

[0342] For the explanations and beneficial effects of the relevant content in any of the above-mentioned devices, reference can be made to the corresponding method embodiments provided above, and details are not described herein again.

[0343] It can be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0344] The method steps in the embodiments of the present application can be implemented in a hardware manner or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a removable hard disk, a compact disc read-only memory (CD-ROM), or any other form of storage medium well-known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an ASIC. Additionally, the ASIC can be located in the transmitter or the receiver. Of course, the processor and the storage medium can also exist as discrete components in the transmitter or the receiver.

[0345] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable devices. The computer program or instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless manner. The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or a data center integrating one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it can also be an optical medium, such as a digital video disc; or it can be a semiconductor medium, such as a solid-state drive.

[0346] In the various embodiments of the present application, if there is no special explanation and logical conflict, the terms and / or descriptions between different embodiments are consistent and can be cross-referenced, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0347] It should be understood that the various numerical numbers involved in the embodiments of the present application are only for the convenience of description and are not used to limit the scope of the embodiments of the present application. The magnitude of the serial numbers of the above processes does not mean the sequence of execution, and the execution sequence of each process should be determined by its function and internal logic.

[0348] Unless otherwise specified, all technical and scientific terms used in the embodiments of the present application have the same meaning as commonly understood by those skilled in the technical field of the present application. The terms used in the present application are only for the purpose of describing specific embodiments and are not intended to limit the scope of the present application. It should be understood that the above is for illustrative purposes, and the above examples are only to help those skilled in the art understand the embodiments of the present application, rather than limiting the embodiments of the application to the specific numerical values or specific scenarios shown. Those skilled in the art can obviously make various equivalent modifications or changes based on the examples given above, and such modifications and changes also fall within the scope of the embodiments of the present application.

[0349] As described above, the above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the technical field of the present application can easily think of changes or substitutions within the technical scope disclosed by the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

A communication method, characterized in that, the method includes: obtaining a first code block and first information, where the first code block is the payload of a physical channel, and the first information includes at least one of the following information: partial payload or all payload of the first code block, a first check code, an anti-replay parameter, a key, or downlink control information for scheduling the first code block; determining first integrity protection information according to the first information and a security algorithm; determining a second code block according to the first code block and the first integrity protection information, where the second code block includes the first code block and the first integrity protection information; and outputting the second code block. The method according to claim 1, characterized in that, the first check code includes a check code for the first code block and / or a check code for a transport block to which the first code block belongs. The method according to claim 1 or 2, characterized in that, the second code block does not include the check code of the first code block. The method according to any one of claims 1 to 3, characterized in that, when the first information includes the partial payload of the first code block, the method further includes: obtaining the partial payload of the first code block according to a first offset and a first length, where the first offset is the offset of the start position of the partial payload of the first code block relative to the start position of the first code block, and the first length is the length of the partial payload of the first code block; or, dividing the first code block into multiple sub-code blocks according to division information, and obtaining the partial payload of each sub-code block among the multiple sub-code blocks according to a second offset and a second length, where the partial payload of the first code block includes the partial payload of each sub-code block, the second offset is the offset of the start position of the partial payload of each sub-code block relative to the start position of each sub-code block, and the second length is the length of the partial payload of each sub-code block. The method according to claim 4, characterized in that, the first offset, the first length, the division information, the second offset, and the second length are carried in the downlink control information. The method according to any one of claims 1 to 5, characterized in that, the physical channel is a physical uplink shared channel, a physical downlink shared channel, a physical uplink control channel, or a physical downlink control channel. The method according to any one of claims 1 to 6, characterized in that, when the first information includes the downlink control information, the physical channel is a physical uplink shared channel or a physical downlink shared channel. The method according to any one of claims 1 to 7, characterized in that, the anti-replay parameter includes: a cell-level parameter and / or a configuration parameter of the physical channel; where the cell-level parameter includes at least one of the following parameters: a physical cell identifier, a link frequency or frequency point, a system bandwidth, or partial bandwidth BWP information; the configuration parameter of the physical channel includes at least one of the following parameters: a time-domain parameter, a frequency-domain parameter, a sequence generation parameter, a transmit power control parameter, or a coding parameter. The method according to any one of claims 1 to 8, It is characterized in that, the security algorithm is an integrity protection algorithm based on a symmetric key. The method according to any one of claims 1 to 9, it is characterized in that, the method further includes: after the access layer security protection mode is completed, activating the physical layer integrity protection mechanism. The method according to any one of claims 1 to 10, it is characterized in that, the method further includes: after the radio link control reconfiguration is completed, updating the configuration parameters of the physical channel. A communication method, it is characterized in that, the method includes: obtaining a received code block of a physical channel, the received code block including a third code block and second integrity protection information, the third code block being the payload of the physical channel; obtaining second information, the second information including at least one of the following information: a partial payload or the entire payload of the third code block, a second check code, an anti-replay parameter, a key, or downlink control information for scheduling the received code block, the second check code being obtained based on the third code block; determining third integrity protection information according to the second information and the security algorithm; and performing an integrity check on the third code block according to the second integrity protection information and the third integrity protection information. The method according to claim 12, it is characterized in that, the second check code includes a check code for the third code block and / or a check code for the transport block to which the third code block belongs. The method according to claim 12 or 13, it is characterized in that, the received code block does not include a check code for the third code block. The method according to any one of claims 12 to 14, it is characterized in that, when the second information includes a partial payload of the third code block, the method further includes: obtaining the partial payload of the third code block according to a first offset and a first length, the first offset being the offset of the start position of the partial payload of the third code block relative to the start position of the third code block, and the first length being the length of the partial payload of the third code block; or, dividing the third code block into a plurality of sub-code blocks according to division information and obtaining the partial payload of each sub-code block according to a second offset and a second length, the partial payload of the third code block including the partial payload of each sub-code block, the second offset being the offset of the start position of the partial payload of each sub-code block relative to the start position of each sub-code block, and the second length being the length of the partial payload of each sub-code block. The method according to claim 15, it is characterized in that, the first offset, the first length, the division information, the second offset, and the second length are carried in the downlink control information. The method according to any one of claims 12 to 16, it is characterized in that, the physical channel is a physical uplink shared channel, a physical downlink shared channel, a physical uplink control channel, or a physical downlink control channel. The method according to any one of claims 12 to 17, it is characterized in that, When the second information includes the downlink control information, the physical channel is a physical uplink shared channel or a physical downlink shared channel. The method according to any one of claims 12 to 18, wherein, the anti-replay parameter includes: a cell-level parameter and / or a configuration parameter of the physical channel; wherein, the cell-level parameter includes at least one of the following parameters: a physical cell identifier, a link frequency or frequency point, a system bandwidth, or partial bandwidth BWP information; the configuration parameter of the physical channel includes at least one of the following parameters: a time-domain parameter, a frequency-domain parameter, a sequence generation parameter, a transmit power control parameter, or a coding parameter. The method according to any one of claims 12 to 19, wherein, the security algorithm is an integrity protection algorithm based on a symmetric key. The method according to any one of claims 12 to 20, wherein, the method further includes: activating a physical layer integrity protection mechanism after the access layer security protection mode is completed. The method according to any one of claims 12 to 21, wherein, the method further includes: updating the configuration parameter of the physical channel after the radio link control reconfiguration is completed. A communication device, wherein, comprising: a processor for executing a computer program stored in a memory, so that the device executes the method according to any one of claims 1 to 11, or executes the method according to any one of claims 12 to 22. The device according to claim 23, wherein, the device further includes the memory. A computer-readable storage medium, wherein, a computer program is stored on the computer-readable storage medium, and when the computer program runs on a computer, the computer is made to execute the method according to any one of claims 1 to 11, or execute the method according to any one of claims 12 to 22. A computer program product, wherein, the computer program product includes instructions for executing the method according to any one of claims 1 to 11, or includes instructions for executing the method according to any one of claims 12 to 22. A communication system, wherein, comprising at least one of the following devices: a sending end for executing the method according to any one of claims 1 to 11; and a receiving end for executing the method according to any one of claims 12 to 22.