Transmission timeliness verification method, system and device and readable medium
By introducing a transmission timeliness verification method in the 5G network, and using the sending time stamp and data packet transmission life cycle to generate a timeliness verification code, the problem of man-in-the-middle playback attack is solved, and the packet timeliness verification and network stability guarantee is achieved.
Patent Information
- Application Number
- CN202311692924.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-08
- Publication Date
- 2025-06-10
AI Technical Summary
The existing 5G network lacks effective measures to defend against replay attacks initiated by man-in-the-middle, resulting in inconsistent information between the network and terminal, unable to provide or receive services normally, and may even trigger DoS/DDoS attacks, resulting in production paralysis in severe cases.
By introducing a transmission timeliness verification method between the receiving device and the sending device, the timeliness verification code is generated by the sending time stamp of the message and the packet transmission life cycle. The receiving device verifies the timeliness of the message, ensuring the maximum time of transmission of the message on the network, thereby preventing playback attacks initiated by the man in the middle.
Effectively prevent replay attacks initiated by the middleman, ensure the timeliness of received messages, ensure the consistency of network and terminal information, and avoid production paralysis and service interruption.
Smart Images

Figure CN120128926A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of mobile communication technology, and in particular to a transmission timeliness verification method, system, device and readable medium. Background Art
[0002] As the basic infrastructure for the development of the national economy, the stability, reliability and security of mobile communication networks are becoming increasingly important, especially in industrial production control scenarios. The fifth generation mobile communication technology (5G) network has the characteristics of mobility, large connections, wide coverage, high speed, and low latency. The stability and security of 5G networks are also gradually improving with the evolution of mobile networks. However, the current 5G network still has deficiencies in security, such as the security protection of broadcast messages and some unicast frames.
[0003] In response to problems such as tampering, spoofing, and replay attacks that can be initiated by middlemen, the 3rd Generation Partnership Project (3GPP) has also proposed improvement measures and suggestions based on existing technologies, such as integrity protection for broadcast messages and encryption or integrity protection of unicast frames without security protection. Some of these improvements or suggestions have been standardized, while others are still in the research stage.
[0004] The existing security mechanism still has no good preventive measures against replay attacks of broadcast frames or partial unicast frames, such as the RRC reject (RRC, Radio Resource Control) message. The receiver can only verify the integrity of the message. In the scenario of man-in-the-middle attack, even if the network and terminal use integrity protection, replay attacks can still be launched: the middleman captures the message and transmits it to the network or terminal after a period of time. During this period of time, the configuration of the network or terminal may have changed or adjusted. The middleman uses the previously captured message to launch a replay attack, resulting in inconsistent information between the network and the terminal, and the inability to provide or receive services normally. It will also cause DoS / DDoS attacks on the network or users. In severe cases, it will cause production paralysis and users cannot use the network. Summary of the invention
[0005] Embodiments of the present disclosure provide a transmission timeliness verification method, system, device, and readable medium.
[0006] A first aspect of the present disclosure provides a transmission timeliness verification method, which is applied to a receiving device. The method includes:
[0007] Receive a message from a sending end device, and determine a first timeliness verification parameter of the message, a first timeliness verification code of the message, and a reception timestamp of the message;
[0008] Verifying the timeliness of the message according to the first timeliness verification parameter of the message, the first timeliness verification code of the message and the reception timestamp of the message to obtain a timeliness verification result;
[0009] Among them, the first timeliness verification parameter includes the sending timestamp of the message and the data packet transmission life cycle.
[0010] A second aspect of the present disclosure provides a transmission timeliness verification method, which is applied to a transmitting end device. The method includes:
[0011] Obtaining a first timeliness verification parameter of the message; wherein the first timeliness verification parameter includes a sending timestamp of the message and a data packet transmission life cycle;
[0012] Generate a first timeliness verification code for the message according to the first timeliness verification parameter;
[0013] The message is sent, wherein the message includes the sending timestamp and the first timeliness verification code, so that the receiving device verifies the timeliness of the received message.
[0014] A third aspect of the present disclosure provides a transmission timeliness verification system, including:
[0015] A sending end device, used to obtain a first timeliness verification parameter of a message; wherein the first timeliness verification parameter includes a sending timestamp of the message and a data packet transmission life cycle; generate a first timeliness verification code of the message according to the first timeliness verification parameter; send the message, wherein the message includes the sending timestamp and the first timeliness verification code, so that the receiving end device verifies the timeliness of the received message;
[0016] A receiving device is used to receive a message from a sending device, and determine a first timeliness verification parameter of the message, a first timeliness verification code of the message and a receiving timestamp of the message; verify the timeliness of the message according to the first timeliness verification parameter of the message, the first timeliness verification code of the message and the receiving timestamp of the message to obtain a timeliness verification result.
[0017] A fourth aspect of the present disclosure provides an electronic device, including:
[0018] at least one processor;
[0019] a memory having at least one program stored thereon, wherein when the at least one program is executed by the at least one processor, the at least one processor implements the method according to the first aspect;
[0020] At least one I / O interface is connected between the processor and the memory and is configured to implement information interaction between the processor and the memory.
[0021] A fifth aspect of the embodiments of the present disclosure provides a computer-readable medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the method described in the first aspect.
[0022] The embodiments of the present disclosure have the following advantages:
[0023] A message sent by a receiving device is obtained, and a first timeliness verification parameter of the message, a first timeliness verification code of the message, and a receiving timestamp of the message are determined. The first timeliness verification parameter includes a sending timestamp of the message and a data packet transmission life cycle. The data packet transmission life cycle indicates the maximum time allowed for the message to be transmitted in the network. The timeliness of the message is verified according to the first timeliness verification parameter, the first timeliness verification code of the message, and the receiving timestamp of the message. Verification of the timeliness of the message is achieved. The maximum time allowed for the message transmission process is limited by introducing the data packet transmission life cycle. Control of the data packet transmission life cycle can effectively prevent replay attacks initiated by middlemen, thereby ensuring the timeliness of received messages. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 A schematic flow chart of a method for verifying transmission validity by a receiving device provided in an embodiment of the present disclosure;
[0025] Figure 2 A schematic diagram of a verification process of a timeliness verification function module of a receiving device provided in an embodiment of the present disclosure;
[0026] Figure 3 A schematic diagram of a process of generating a first timeliness verification code by a timeliness verification code generating function module of a receiving end device provided in an embodiment of the present disclosure;
[0027] Figure 4a A schematic diagram of generating a message verification code at a sending end provided in an embodiment of the present disclosure;
[0028] Figure 4b A schematic diagram of generating a message verification code at a receiving end provided in an embodiment of the present disclosure;
[0029] Figure 5 A schematic diagram of a method flow for verifying transmission validity by a transmitting device provided in an embodiment of the present disclosure;
[0030] Figure 6a A schematic diagram of a process for generating a first timeliness verification code by a timeliness verification code generation function module provided in an embodiment of the present disclosure Figure 1 ;
[0031] Figure 6b A schematic diagram of a process for generating a first timeliness verification code by a timeliness verification code generation function module provided in an embodiment of the present disclosure Figure 2 ;
[0032] Figure 7 A schematic diagram of an interaction process between a terminal and a network side device provided in an embodiment of the present disclosure;
[0033] Figure 8 A schematic diagram of a 5G PDCP layer implementation timeliness verification mechanism provided in an embodiment of the present disclosure;
[0034] Fig. 9 A schematic diagram of the integration of a timeliness verification mechanism and a PDCP layer integrity protection mechanism provided in an embodiment of the present disclosure;
[0035] Fig.10a A schematic diagram of the architecture of a transmission timeliness verification system provided in an embodiment of the present disclosure;
[0036] Fig.10b A schematic diagram of the structure of a transmission timeliness verification device applied to a receiving device provided in an embodiment of the present disclosure;
[0037] Fig.11 A schematic diagram of the structure of a transmission timeliness verification device applied to a sending end device provided in an embodiment of the present disclosure;
[0038] Fig.12 A schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0039] The specific implementation of the present disclosure is described in detail below in conjunction with the accompanying drawings. It should be understood that the specific implementation described herein is only used to illustrate and explain the present disclosure, and is not used to limit the present disclosure.
[0040] As used in this disclosure, the term "and / or" includes any and all combinations of one or more of the associated listed items.
[0041] The terms used in the present disclosure are only used to describe specific embodiments and are not intended to limit the present disclosure.As used in the present disclosure, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0042] When the terms “comprising” and / or “made of…” are used in the present disclosure, it specifies the existence of the stated features, integers, steps, operations, elements and / or components, but does not exclude the existence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.
[0043] Unless otherwise defined, all terms (including technical and scientific terms) used in this disclosure have the same meaning as those commonly understood by those of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and this disclosure, and will not be interpreted as having an idealized or overly formal meaning unless explicitly defined in this disclosure.
[0044] The inventors found in the process of analyzing the prior art that:
[0045] At present, the receiving device can only verify the integrity of the message, but not the timeliness of the message. The middleman controls the playback time of the captured message, and the receiving device cannot identify the timeliness of the message through existing solutions such as message integrity protection and Packet Data Convergence Protocol (PDCP) count (COUNT). Although the existing 5G protocol PDCP layer can limit the message reception time through the PDCP COUNT combined with the reordering timer (t-Reordering), this function is for the reordering timeout caused by transmission packet loss, and it is an optional function, and does not verify the timeliness of the message. In response to the above problems, the 5G mobile communication network needs to introduce a timeliness verification scheme for transmitted messages to ensure that the received messages not only have the integrity of the content, but also meet the timeliness required by the application.
[0046] Based on this, the embodiment of the present disclosure provides a transmission timeliness verification method, which realizes the transmission timeliness verification of the message through the cooperation of the receiving device and the sending device. The transmission timeliness verification method can be applied to the scenario of preventing the middleman message replay attack in the mobile communication network and the scenario with specified timeliness requirements in the industrial scenario. The mobile communication network includes but is not limited to 5G, 5G+ or the sixth generation mobile communication technology (6th Generation Mobile Communication Technology, referred to as 6G), etc.
[0047] In a first aspect, the present disclosure provides a transmission timeliness verification method applied to a receiving device. Figure 1 The figure is a flow chart of a method for verifying transmission validity by a receiving device, which mainly includes the following steps:
[0048] Step 101: A receiving device receives a message from a sending device, and determines a first timeliness verification parameter of the message, a first timeliness verification code of the message, and a reception timestamp of the message.
[0049] The first timeliness verification code is a timeliness verification code for sending a message, which is generated by a sending end device and is expressed as TLAC-I (Transmission Liftetime Authentication Code Integrity).
[0050] In some embodiments, the receiving device determines the first timeliness verification parameter of the message and the first timeliness verification code of the message, including: parsing the message to obtain the first timeliness verification code of the message, the sending timestamp of the message and the data packet transmission life cycle; determining the first timeliness verification parameter according to the timestamp of the message and the data packet transmission life cycle. In this embodiment, the sending timestamp and the data packet transmission life cycle are directly carried in the message, so that the receiving device can directly parse and obtain the sending timestamp and the data packet transmission life cycle, and then perform the next step of timeliness verification, which is highly flexible.
[0051] In some embodiments, the receiving device determines the first timeliness verification parameter of the message and the first timeliness verification code of the message, including: obtaining the data packet transmission life cycle locally; parsing the message to obtain the sending timestamp of the message and the first timeliness verification code of the message; determining the first timeliness verification parameter according to the sending timestamp of the message and the data packet transmission life cycle. In this embodiment, it is not necessary to carry the data packet transmission life cycle in the message. The receiving device obtains the data packet transmission life cycle according to a pre-configured method, parses the message to obtain the sending timestamp, and then performs the next timeliness verification, thereby reducing the amount of data transmitted by the message.
[0052] In some embodiments, the method of obtaining the data packet transmission life cycle locally is as follows:
[0053] Based on the message, the data packet transmission life cycle is generated using a preconfigured data packet transmission life cycle generator, wherein the data packet transmission life cycle generator is used to generate the data packet transmission life cycle according to the length or content of the message;
[0054] Alternatively, the data packet transmission lifecycle pre-agreed with the sending end device is obtained locally.
[0055] In some embodiments, there are multiple ways to implement the data packet transmission lifecycle, including but not limited to the following ways:
[0056] (1) The sending device generates a data packet transmission lifecycle according to a local policy, and carries the data packet transmission lifecycle in a message sent to the receiving device; wherein the local policy may be a pre-configured policy for generating a data packet transmission lifecycle according to the length and content of the message, for example, the length of the message is positively correlated with the data packet transmission lifecycle, and the messages are divided into categories according to the content of the messages, and each category corresponds to the same data packet transmission lifecycle;
[0057] (2) The transmitting device and the receiving device pre-agreed on the data packet transmission lifecycle, which does not need to be transmitted in the message;
[0058] (3) The receiving device automatically generates the data packet transmission life cycle through a data packet transmission life cycle generator, which is a function generator or device that automatically generates the data packet transmission life cycle based on the length or content of the input message.
[0059] The method for obtaining the data packet transmission lifecycle can be determined through negotiation based on the capabilities of the network, the receiving device, and the sending device.
[0060] Among them, the sending timestamp (Sending Timestamps) is the sending timestamp of the message recorded by the sending device at the specified processing point. The appropriate number of bytes for the sending timestamp is selected according to the needs. For example, the length can be 8 bytes, representing the year, month, day, hour, minute, second and millisecond.
[0061] It should be noted that there is no restriction on the location of the message sending timestamp, data packet transmission life cycle and first timeliness verification code carried in the message, and only requires mutual agreement between the sending device and the receiving device.
[0062] In some embodiments, the receiving device records the time when the message is received as the reception timestamp of the message.
[0063] Step 102, verify the timeliness of the message according to the first timeliness verification parameter of the message, the first timeliness verification code of the message and the receiving timestamp of the message to obtain a timeliness verification result; wherein, the first timeliness verification parameter includes the sending timestamp of the message and the data packet transmission life cycle.
[0064] Among them, the packet transmission lifecycle (Packet Transmission Lifetime), that is, the maximum end-to-end transmission time allowed for a message in the network, that is, the packet transmission lifecycle is used to indicate the maximum duration allowed for a message to be transmitted in the network. Different from the message lifetime (time to live, TTL, ranging from 0 to 255) based on the number of node hops in the existing IP network. The transmission time of the existing TTL mechanism message is related to the number of network hops and node processing delay, and has uncertainty. The packet transmission lifecycle proposed in the embodiment of the present disclosure represents the end-to-end deterministic maximum transmission time.
[0065] In some embodiments, a receiving device verifies the timeliness of the message according to a first timeliness verification parameter of the message, a first timeliness verification code of the message and a receiving timestamp of the message to obtain a timeliness verification result, including: generating a second timeliness verification code corresponding to the message based on the first timeliness verification parameter; comparing the first timeliness verification code and the second timeliness verification code to obtain a comparison result; when the comparison result is consistent, determining the timeliness verification result of the message according to the receiving timestamp of the message, the sending timestamp of the message and the data packet transmission life cycle; when the comparison result is inconsistent, determining the timeliness verification result of the message as failed.
[0066] The integrity of the sending timestamp is verified by comparing whether the first timeliness verification code and the second timeliness verification code are the same. If the integrity verification of the sending timestamp fails, it is equivalent to that the timeliness verification result of the message fails. If the integrity verification of the sending timestamp passes, the timeliness of the message is further verified by verifying whether the time difference between the receiving timestamp and the sending timestamp is within the life cycle of the data packet transmission.
[0067] In some embodiments, the receiving device generates a second timeliness verification code corresponding to the message based on the first timeliness verification parameter, including: inputting the first timeliness verification parameter into an integrity protection algorithm, and obtaining a second timeliness verification code corresponding to the message output by the integrity protection algorithm. The integrity protection algorithm includes but is not limited to the Advanced Encryption Standard (AES) introduced in 3GPP5G, the word-oriented stream encryption algorithm (SNOW3G) or the Zu Chongzhi algorithm (ZUC).
[0068] In some embodiments, the receiving end device inputs the key into the integrity protection algorithm while inputting the first time validity verification parameter into the integrity protection algorithm to obtain the second time validity verification code corresponding to the message output by the integrity protection algorithm. By adding the key to the integrity protection algorithm, the security of the integrity protection can be further guaranteed.
[0069] In some embodiments, the receiving device determines a timeliness verification result of the message based on the reception timestamp of the message, the transmission timestamp of the message, and the data packet transmission life cycle, including: determining the duration between the transmission timestamp of the message and the reception timestamp of the message; when the duration is less than or equal to the data packet transmission life cycle, determining that the timeliness verification result of the message is passed; when the duration is greater than the data packet transmission life cycle, determining that the timeliness verification result of the message is failed.
[0070] If the time difference between the received timestamp and the sent timestamp of a message is less than or equal to the data packet transmission life cycle, the message that transmits the message meets the timeliness requirement and can be passed to the upper layer or used for processing at this layer; if the time difference between the received timestamp and the sent timestamp of a message is greater than the data packet transmission life cycle, the message that transmits the message does not meet the timeliness requirement and is discarded, recorded, or alarmed according to the configured policy.
[0071] In an exemplary embodiment, a time validity verification function module is introduced into the receiving end device. Figure 2 The figure shows a verification process diagram of the timeliness verification function module. The timeliness verification function module of the receiving device includes two parts: a sending timestamp integrity verification module and a message timeliness verification module. The receiving device receives the timeliness-related parameters of the received message, including the sending timestamp and data packet transmission life cycle parsed from the received message, as well as the uplink and downlink transmission direction information of the message. The timeliness verification key of the receiving device is input into the sending timestamp integrity verification module to generate the expected timeliness verification code XTLAC-I of the received message. The integrity of the sending timestamp is verified by comparing whether TLAC-I and XTLAC-I are the same. If the sending timestamp integrity verification passes, the timeliness of the message is verified by verifying whether the time difference between the receiving timestamp and the sending timestamp is within the data packet transmission life cycle. If the timeliness requirement is met, that is, the time difference between the receiving timestamp and the sending timestamp is less than or equal to the data packet transmission life cycle, it means that the message received by the receiver meets the timeliness.
[0072] In an exemplary embodiment, a time verification code generation function module is introduced into the receiving end device. Figure 3The figure shows a schematic diagram of the process of the time validity verification code generation function module of the receiving device generating the second time validity verification code. The receiving device parses the sending timestamp and data packet transmission life cycle of the received message, the uplink and downlink transmission direction information of the received message and the locally stored symmetric key, inputs them into the time validity verification code generation function module, and outputs the second time validity verification code XTLAC-I.
[0073] In practical applications, in order to reduce the delay caused by the calculation of the time verification code generation function module, an independent hardware computing unit such as MCU can be used to complete the calculation function of the integrity protection algorithm. If you are not sensitive to the calculation delay of the time verification code generation function module, you can also implement the algorithm calculation function through the software function module.
[0074] In some embodiments, the first timeliness verification parameter further includes at least one of the following:
[0075] The uplink and downlink transmission direction information of the message, referred to as Direction;
[0076] The first timeliness verification parameter also includes the data content of the message.
[0077] The uplink and downlink transmission direction information of the message is added to the first timeliness verification parameter to increase the generation complexity of the first timeliness verification code and the second timeliness verification code and improve security.
[0078] In some embodiments, the first timeliness verification parameter further includes uplink and downlink transmission direction information of the message;
[0079] The receiving end device generates a second timeliness verification code corresponding to the message based on the first timeliness verification parameter, including:
[0080] Determine the uplink and downlink transmission direction information of the message in the first time validity verification parameter; input the sending timestamp of the message, the data packet transmission life cycle and the uplink and downlink transmission direction information of the message into the integrity protection algorithm to obtain the second time validity verification code corresponding to the message.
[0081] In an exemplary embodiment, the receiving device generates a second timeliness verification code for the message through an integrity protection algorithm based on the sending timestamps of the message, the data packet transmission life cycle, the uplink and downlink transmission direction information of the message, and the key used for timeliness verification of the message, that is, the expected timeliness verification code is expressed as XTLAC-I (Expected Transmission Liftetime Authentication Code Integrity).
[0082] In some embodiments, the first timeliness verification parameter further includes the data content of the message;
[0083] The receiving end device generates a second timeliness verification code corresponding to the message based on the first timeliness verification parameter, including:
[0084] Determine the data content of the message in the first timeliness verification parameter; input the sending timestamp of the message, the data packet transmission life cycle, the uplink and downlink transmission direction information of the message and the data content of the message into the integrity protection algorithm to obtain a second timeliness verification code corresponding to the message.
[0085] Among them, the data content of the message is added to the first timeliness verification parameter, so that the integrity verification of the data content of the message is combined with the integrity verification of timeliness verification parameters such as the sending timestamp of the message. A single verification code generation process is used for the integrity verification of two pieces of information, thereby improving resource utilization and improving integrity verification efficiency.
[0086] In an exemplary embodiment, Figure 4a and Figure 4b The figure shows the schematic diagram of the combination of message timeliness verification and message integrity protection mechanism, where Figure 4a A schematic diagram for generating a message verification code for the sender. Figure 4b This is a schematic diagram of the message authentication code generation at the receiving end. The message timeliness verification can be extended based on the existing 5G network integrity protection mechanism. The sending end device extends the timeliness-related parameters, mainly including the sending timestamp and the data packet transmission life cycle, to the message authentication code generation function module, and uses the existing integrity protection mechanism to jointly generate a message authentication code, which is expressed as MAC-I (Message Authentication Code Integrity), that is, the first timeliness verification code.
[0087] The sending device transmits the sending timestamp, data packet transmission life cycle and MAC-I along with the message to the receiving device.
[0088] The receiving device parses the sending timestamp, data packet transmission lifecycle and MAC-I, and generates an expected message authentication code together with the parsed sending timestamp, data packet transmission lifecycle, data content of the received message and other related parameters, expressed as XMAC-I (Expected Message Authentication Code Integrity), which is the second timeliness verification code.
[0089] The receiving device determines the integrity of the message content, the sending timestamp, and the integrity of the data packet transmission life cycle by comparing whether MAC-I and XMAC-I are the same. If MAC-I and XMAC-I are the same, the integrity verification is passed. The receiving device further determines the timeliness of the message by comparing the time difference between the receiving timestamp and the sending timestamp with the data packet transmission life cycle.
[0090] The method of extending the message timeliness verification based on the existing 5G network integrity protection mechanism can simultaneously verify the integrity of the message content and the timeliness of the message transmission.
[0091] In a second aspect, the present disclosure provides a transmission timeliness verification method applied to a transmitting device. Figure 5 The figure is a flow chart of a method for verifying transmission validity by a transmitting device, which mainly includes the following steps:
[0092] Step 501: The sending end device obtains a first timeliness verification parameter of a message; wherein the first timeliness verification parameter includes a sending timestamp of the message and a data packet transmission life cycle.
[0093] In some embodiments, it also includes:
[0094] Generating the data packet transmission lifecycle according to a preconfigured data packet transmission lifecycle generator, wherein the data packet transmission lifecycle generator is used to generate the data packet transmission lifecycle according to the length or content of the message;
[0095] Alternatively, the data packet transmission lifecycle pre-agreed between the sending end device and the receiving end device is obtained.
[0096] Step 502: The sending end device generates a first timeliness verification code for the message according to the first timeliness verification parameter.
[0097] In some embodiments, the sending end device generates a first timeliness verification code for the message according to the first timeliness verification parameter, including: based on the first timeliness verification parameter, using an integrity protection algorithm to generate a first timeliness verification code corresponding to the message.
[0098] The first timeliness verification code is used for integrity verification by the receiving device. Exemplarily, the selected integrity protection algorithm and configuration strategy are used to generate a first timeliness verification code of a certain length based on the first timeliness verification parameter for integrity verification. For example, the length of the first timeliness verification code is 32 bits. The integrity protection algorithm includes but is not limited to AES, SNOW3G or ZUC introduced in 3GPP 5G.
[0099] In some embodiments, the transmitting device inputs the first timeliness verification parameter into the integrity protection algorithm to obtain a first timeliness verification code corresponding to the message output by the integrity protection algorithm.
[0100] In some embodiments, the transmitting device inputs the first timeliness verification parameter into the integrity protection algorithm and at the same time inputs the key into the integrity protection algorithm to obtain a first timeliness verification code corresponding to the message output by the integrity protection algorithm.
[0101] It should be noted that the integrity protection algorithm used by the sender to generate the first timeliness verification code and the integrity protection algorithm used by the receiver to generate the second timeliness verification code should be the same integrity protection algorithm. The receiver and the sender agree on the key to be input into the integrity protection algorithm to ensure that the sender and the receiver use the same process to generate the timeliness verification code, thereby ensuring that both parties can obtain consistent timeliness verification codes.
[0102] In some embodiments, the first timeliness verification parameter and the message further include at least one of the following:
[0103] Uplink and downlink transmission direction information of the message;
[0104] The data content of the message.
[0105] The purpose of including the uplink and downlink transmission direction information of the message in the first timeliness verification parameter is to increase the complexity of generating the first timeliness verification code and improve security.
[0106] The first timeliness verification parameter includes the data content of the message, so that the generated first timeliness verification code simultaneously verifies the integrity of the data content of the message and the integrity of timeliness parameters such as the sending timestamp, thereby improving resource utilization and efficiency.
[0107] In an exemplary embodiment, a time verification code generation function module is introduced in the sending end device. Figure 6a and Figure 6b The figure shows a schematic diagram of the process of generating the first timeliness verification code by the timeliness verification code generation function module. By inputting the timeliness verification parameters of the sent message, including the sending timestamp, the data packet transmission life cycle, the uplink and downlink transmission direction information of the message and the timeliness verification key of the message, the first timeliness verification code TLAC-I of the sent message is generated by the timeliness verification code generation function module.
[0108] In order to reduce the delay caused by the calculation of the time verification code generation function module, an independent hardware computing unit such as MCU can be used to complete the operation function of the integrity protection algorithm. If the calculation delay of the time verification code generation function module is not sensitive, the algorithm operation function can also be implemented through the software function module.
[0109] Step 503: The sending end device sends the message, which includes the sending timestamp and the first timeliness verification code, so that the receiving end device verifies the timeliness of the received message.
[0110] In some embodiments, the message also includes the data packet transmission lifecycle. Whether to include the data packet transmission lifecycle in the message is implemented according to the mutual agreement between the sending end device and the receiving end device. When both parties agree to generate the data packet transmission lifecycle, both parties generate the data packet transmission lifecycle according to the agreed generation rules. When both parties agree that the data packet transmission lifecycle is transmitted through the message, the data packet transmission lifecycle is transmitted in the message according to the agreement.
[0111] In an exemplary embodiment, the timeliness verification process is described by taking the sending end device as a terminal and the receiving end device as a network side device as an example. Figure 7 The figure shows a schematic diagram of the interaction process between the terminal and the network side device, which mainly includes the following steps:
[0112] Step 701: The terminal indicates that it has the capability to verify the timeliness of messages through capability information reporting signaling.
[0113] The terminal reports its own message timeliness verification capability to the network side device through capability information reporting signaling, so that the network side device can learn the message timeliness verification capability of the terminal and start the timeliness verification related process by interacting with the terminal.
[0114] In step 702, the network side device interacts with the terminal for timeliness signaling configuration, including enabling the message timeliness verification function, negotiating the granularity of timeliness verification, negotiating the input method of timeliness verification parameters and the generation method of the data packet transmission life cycle.
[0115] Among them, the network side device and the terminal enable the message timeliness verification function through interactive agreement. For example, when the network side device obtains that the terminal has the ability to verify the message timeliness, it returns the signaling for enabling the message timeliness verification function to the terminal, so that the terminal interacts with the terminal through signaling in a timeliness verification manner.
[0116] Among them, the network side device and the terminal interactively negotiate the granularity of timeliness verification, including negotiating the messages that need to be verified for timeliness, for example, all messages are subject to timeliness verification; or, timeliness verification is performed on messages of specified types, and the specified types of messages include but are not limited to the following situations: voice type messages, messages carrying IP addresses.
[0117] The network side device and the terminal interactively negotiate the input method of the timeliness verification parameter, including the input method of the timeliness verification parameter required when generating the timeliness verification code into the integrity protection algorithm. For example, the password input into the integrity protection algorithm is manually input through negotiation; or, the password generation algorithm is agreed through negotiation, and the password is generated by the algorithm and input into the integrity protection algorithm.
[0118] Among them, the network side device and the terminal interactively negotiate the method for generating the data packet transmission lifecycle, including negotiating the generation strategy of the data packet transmission lifecycle, so that the terminal and the network side device generate the data packet transmission lifecycle according to the agreed generation strategy respectively; or, agree on the configuration parameters of the data packet transmission lifecycle generator, so that the configuration parameters of the data packet transmission lifecycle generators of the terminal and the network side device are the same, and the same data packet transmission lifecycle can be generated for the same parameters.
[0119] Step 703: The terminal receives the user data message to be sent and records the sending timestamp.
[0120] The user data message to be sent is a message that needs to be sent by the terminal to the network side device.
[0121] Step 704: The terminal inputs the timeliness verification parameter through the timeliness verification code generation function module to generate the transmission timeliness verification code TLAC-I of the terminal, that is, the first timeliness verification code;
[0122] Among them, the terminal and the network side device mutually agree on the timeliness verification parameters to be input into the timeliness verification code generation function model. For example, the timeliness verification parameters agreed to be input into the timeliness verification code generation function module include the data packet transmission life cycle, the message sending timestamp, the message up and down transmission method information and the message data content.
[0123] In step 705, the terminal attaches the message sending timestamp, data packet transmission life cycle and TLAC-I to the message, wherein the positions of the sending timestamp, data packet transmission life cycle and TLAC-I in the message can be selected according to the specific implementation.
[0124] Among them, the terminal and the network side device can mutually agree on the sending timestamp, data packet transmission life cycle and the position of TLAC-I in the message, and there is no restriction on the specific position in the message.
[0125] Step 706, the terminal transmits the user data message with the sending timestamp, the data packet transmission life cycle and the TLAC-I to the network side device through the network.
[0126] Step 707, after receiving the message, the network side device records the receiving timestamp of the received message, and parses the sending timestamp, data packet transmission life cycle and TLAC-I in the message; inputs the sending timestamp, data packet transmission life cycle, uplink and downlink transmission direction information of the message and the locally stored symmetric key KEY into the time validity verification code generation function module to generate the expected transmission time validity verification code XTLAC-I, that is, the second time validity verification code; compares TLAC-I and XTLAC-I, if they are the same, the sending timestamp and data packet transmission life cycle of the message have not changed, and have integrity; if TLAC-I and XTLAC-I are not the same, it means that the sending timestamp and data packet transmission life cycle of the message have been tampered with, and have no integrity, and the message can be discarded, recorded or alarmed according to the configuration policy.
[0127] Step 708, when the TLAC-I and XTLAC-I of the network side devices are the same, if the time difference obtained by subtracting the sending timestamp from the receiving timestamp is less than or equal to the data packet transmission life cycle, the message meets the timeliness requirement; if the time difference obtained is greater than the data packet transmission life cycle, the timeliness requirement is not met, and the message can be discarded, recorded or alarmed according to the configuration policy.
[0128] The transmission timeliness verification method provided by the embodiment of the present disclosure is applied to different protocol layers according to actual needs. For example, in a 5G network, a timeliness verification mechanism can be implemented at the PDCP layer based on the integrity protection mechanism of the PDCP layer. Figure 8 Schematic diagram of implementing timeliness verification mechanism for 5G PDCP layer, such as Figure 8 As shown, the transmitting device generates a first timeliness verification code at the PDCP layer. A 2-bit timeliness verification indication flag is added to the PDCP layer header to indicate that this message needs timeliness verification, and timeliness verification-related parameters and the first timeliness verification code are carried in the PDCP PDU along with the message.
[0129] After receiving the PDCP layer message, the receiving device parses out the timeliness verification related parameters (such as the sending timestamp and the data packet transmission life cycle) and the first timeliness verification code TLAC-I according to the timeliness verification indication flag. The receiving device inputs the parsed timeliness verification related parameters and the locally stored timeliness verification key KEY into the timeliness verification code generation function module to generate XTLAC-I. Compare whether TLAC-I and XTLAC-I are consistent to verify the integrity of the timeliness verification parameters. If they are consistent, the timeliness verification of the message transmission is performed. If the time difference between the receiving timestamp and the sending timestamp of the message is less than the data packet transmission life cycle, the message meets the transmission timeliness.
[0130] In addition, the transmission timeliness verification method provided by the embodiments of the present disclosure can also be used in combination with the existing integrity protection mechanism of the PDCP layer. Fig. 9 It is a schematic diagram of the integration of the timeliness verification mechanism and the PDCP layer integrity protection mechanism. As Fig. 9 shown, when the sending device generates the message integrity verification code, it simultaneously inputs the parameters related to timeliness verification (sending timestamp and packet transmission life cycle), generates the message integrity verification code MAC-I, and carries the parameters related to timeliness verification and the message integrity verification code in the PDCP PDU along with the message. The receiving device verifies the integrity and timeliness of the PDCP PDU by verifying the message integrity verification code.
[0131] The transmission timeliness verification method provided by the embodiments of the present disclosure can be applied to various scenarios. For example, the timeliness verification of all broadcast messages in the 5G network, such as broadcast alerts, earthquake and tsunami notifications, etc.; the timeliness verification of some unicast messages in the 5G network, such as RRC reject, Deregistration, etc.; the timeliness verification of data messages in the user plane in 5G applications, etc.
[0132] According to the configuration policy, the use of the timeliness verification mechanism can be at the granularity of message level, QoS flow level, PDU session level, UE level or cell level.
[0133] The transmission timeliness verification method provided by the embodiments of the present disclosure can effectively prevent replay attacks initiated by a man-in-the-middle and ensure the timeliness of received messages. In addition, a new definition of the packet transmission life cycle is introduced in the 5G network, that is, the maximum transmission time allowed for the packet to be end-to-end in the network. The embodiments of the present disclosure are not only a simple and effective solution to solve the existing replay attack of 5G network messages, but the introduction of the packet transmission life cycle can also be used for subsequent optimization of network capacity, etc.
[0134] The step division of the above various methods is only for clear description. When implemented, they can be combined into one step or some steps can be split into multiple steps. As long as the same logical relationship is included, they are all within the protection scope of the present disclosure; adding insignificant modifications or introducing insignificant designs to the algorithm or process, but not changing the core design of its algorithm and process are all within the protection scope of the present disclosure.
[0135] In a third aspect, the embodiments of the present disclosure provide a transmission timeliness verification system. Fig.10a It is a schematic diagram of the architecture of the transmission timeliness verification system. As Fig.10a shown, the system includes:
[0136] The sending device 11 is configured to obtain a first timeliness verification parameter of a message; wherein, the first timeliness verification parameter includes a sending timestamp of the message and a data packet transmission lifecycle; generate a first timeliness verification code of the message according to the first timeliness verification parameter; and send the message, where the message includes the sending timestamp and the first timeliness verification code, so that the receiving device verifies the timeliness of the received message.
[0137] The receiving device 12 is configured to receive a message from the sending device; obtain the first timeliness verification parameter of the message, the first timeliness verification code of the message, and the receiving timestamp of the message, and verify the timeliness of the message according to the first timeliness verification parameter of the message, the first timeliness verification code of the message, and the receiving timestamp of the message, to obtain a timeliness verification result; wherein, the first timeliness verification parameter includes the sending timestamp of the message and a data packet transmission lifecycle.
[0138] Specific implementations of the sending device can refer to the relevant descriptions of the sending device in the first aspect and the second aspect, which will not be repeated here.
[0139] Specific implementations of the receiving device can refer to the relevant descriptions of the receiving device in the first aspect and the second aspect, which will not be repeated here.
[0140] In a fourth aspect, an embodiment of the present disclosure provides a transmission timeliness verification device, which is applied to a receiving device. Specific implementations of the device can refer to the relevant descriptions of the method embodiments of the receiving device in the first aspect or the second aspect, which will not be repeated here. Fig.10b The following shows a schematic structural diagram of the device, as Fig.10b shown, the device mainly includes:
[0141] A receiving module 1001 is configured to receive a message from the sending device, and determine the first timeliness verification parameter of the message, the first timeliness verification code of the message, and the receiving timestamp of the message;
[0142] An obtaining module 1002 is configured to verify the timeliness of the message according to the first timeliness verification parameter of the message, the first timeliness verification code of the message, and the receiving timestamp of the message, to obtain a timeliness verification result;
[0143] Wherein, the first timeliness verification parameter includes the sending timestamp of the message and a data packet transmission lifecycle.
[0144] Fifth aspect, an embodiment of the present disclosure provides a transmission timeliness verification device, which is applied to a sending-end device. For the specific implementation of this device, reference can be made to the relevant descriptions of the method embodiments of the sending-end device in the first aspect or the second aspect, and details will not be repeated here. Fig.11 The following shows the structural schematic diagram of the device. As Fig.11 shown, the device mainly includes:
[0145] An acquisition module 1101, configured to acquire a first timeliness verification parameter of a message; wherein, the first timeliness verification parameter includes a sending timestamp of the message and a data packet transmission lifecycle.
[0146] A generation module 1102, configured to generate a first timeliness verification code of the message according to the first timeliness verification parameter.
[0147] A sending module 1103, configured to send the message, where the message includes the sending timestamp and the first timeliness verification code, so that the receiving-end device can verify the timeliness of the received message.
[0148] The functions or modules included in the device provided by the embodiment of the present disclosure can be used to execute the methods described in the method embodiments. For the specific implementation and technical effects, reference can be made to the descriptions of the above method embodiments. For the sake of brevity, details will not be repeated here.
[0149] It should be noted that each module involved in this embodiment is a logical module. In actual applications, a logical unit can be a physical unit, a part of a physical unit, or a combination of multiple physical units. In addition, to highlight the innovative part of the present disclosure, units that are not closely related to solving the technical problems proposed by the present disclosure are not introduced in this embodiment, but this does not mean that there are no other units in this embodiment.
[0150] Fig.12 An embodiment of the present disclosure provides an electronic device. As Fig.12 shown, the electronic device includes:
[0151] At least one processor 1201;
[0152] A memory 1202, on which at least one program is stored. When the at least one program is executed by the at least one processor, the at least one processor implements the above method.
[0153] At least one I / O interface 1203, connected between the processor and the memory, and configured to implement information interaction between the processor and the memory.
[0154] Among them, the processor 1201 is a device with data processing capabilities, including but not limited to a central processing unit (CPU), etc.; the memory 1202 is a device with data storage capabilities, including but not limited to a random access memory (RAM, more specifically such as SDRAM, DDR, etc.), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory (FLASH); the I / O interface (read / write interface) 1203 is connected between the processor 1201 and the memory 1202, and can realize the information interaction between the processor 1201 and the memory 1202, including but not limited to a data bus (Bus), etc.
[0155] In some embodiments, the processor 1201, the memory 1202, and the I / O interface 1203 are interconnected through a bus, and then connected to other components of the computing device.
[0156] This embodiment also provides a computer-readable medium, on which a computer program is stored. When the program is executed by a processor, the method provided in this embodiment is implemented. To avoid repeated description, the specific steps of this method will not be elaborated here.
[0157] Those of ordinary skill in the art can understand that all or some of the steps in the methods, and the functional modules / units in the systems and devices described above can be implemented as software, firmware, hardware, and their appropriate combinations. In the hardware implementation, the division between the functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, one physical component can have multiple functions, or one function or step can be executed by several physical components in cooperation. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or can be implemented as hardware, or can be implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory, or other memory technologies, CD-ROM, digital versatile disks (DVDs), or other optical disk storage, magnetic cassettes, tapes, magnetic disk storage, or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those of ordinary skill in the art, a communication medium typically contains computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery medium.
[0158] It should be noted that, in this article, the term "including", "comprising", or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article, or device that includes a series of elements includes not only those elements but also other elements not expressly listed, or elements that are inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article, or device that includes such element.
[0159] Those skilled in the art can understand that although some of the embodiments described herein include certain features included in other embodiments rather than other features, the combination of features of different embodiments means that it is within the scope of this embodiment and forms different embodiments.
[0160] It is understood that the above embodiments are merely exemplary embodiments adopted to illustrate the principles of the present disclosure. However, the present disclosure is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and essence of the present disclosure, and these modifications and improvements are also regarded as the protection scope of the present disclosure.
Claims
1. A method for verifying transmission timeliness, characterized in that, applied to the receiving end device, the method includes: Receiving a message from the sending end device, and determining a first timeliness verification parameter of the message, a first timeliness verification code of the message, and a receiving timestamp of the message; Verifying the timeliness of the message according to the first timeliness verification parameter of the message, the first timeliness verification code of the message, and the receiving timestamp of the message, to obtain a timeliness verification result; Wherein, the first timeliness verification parameter includes a sending timestamp of the message and a data packet transmission lifecycle.
2. The method according to claim 1, characterized in that, Determining the first timeliness verification parameter of the message and the first timeliness verification code of the message includes: Parsing from the message to obtain the first timeliness verification code of the message, the sending timestamp of the message, and the data packet transmission lifecycle; Determining the first timeliness verification parameter according to the timestamp of the message and the data packet transmission lifecycle.
3. The method according to claim 1, characterized in that, Determining the first timeliness verification parameter of the message and the first timeliness verification code of the message includes: Obtaining the data packet transmission lifecycle locally; Parsing from the message to obtain the sending timestamp of the message and the first timeliness verification code of the message; Determining the first timeliness verification parameter according to the sending timestamp of the message and the data packet transmission lifecycle.
4. The method according to claim 3, characterized in that, The manner of obtaining the data packet transmission lifecycle locally is as follows: Based on the message, using a pre-configured data packet transmission lifecycle generator to generate the data packet transmission lifecycle, and the data packet transmission lifecycle generator is used to generate the data packet transmission lifecycle according to the length of the message or the content of the message; Or, obtaining the data packet transmission lifecycle agreed in advance with the sending end device locally.
5. The method according to claim 1, characterized in that, The verifying the timeliness of the message according to the first timeliness verification parameter of the message, the first timeliness verification code of the message, and the receiving timestamp of the message, to obtain a timeliness verification result includes: Generating a second timeliness verification code corresponding to the message based on the first timeliness verification parameter; Comparing the first timeliness verification code and the second timeliness verification code to obtain a comparison result; When the comparison result is consistent, determining the timeliness verification result of the message according to the receiving timestamp of the message, the sending timestamp of the message, and the data packet transmission lifecycle; When the comparison result is inconsistent, determining that the timeliness verification result of the message fails.
6. The method according to claim 5, characterized in that, The determining the timeliness verification result of the message according to the receiving timestamp of the message, the sending timestamp of the message, and the data packet transmission lifecycle includes: Determining the duration between the sending timestamp of the message and the receiving timestamp of the message; When the duration is less than or equal to the data packet transmission life cycle, determine that the timeliness verification result of the message passes; When the duration is greater than the data packet transmission life cycle, determine that the timeliness verification result of the message fails.
7. The method according to claim 5, wherein, generating the second timeliness verification code corresponding to the message based on the first timeliness verification parameter includes: determining the uplink and downlink transmission direction information of the message in the first timeliness verification parameter; inputting the sending timestamp of the message, the data packet transmission life cycle, and the uplink and downlink transmission direction information of the message into an integrity protection algorithm to obtain the second timeliness verification code corresponding to the message.
8. The method according to claim 5, wherein, generating the second timeliness verification code corresponding to the message based on the first timeliness verification parameter includes: determining the data content of the message in the first timeliness verification parameter; inputting the sending timestamp of the message, the data packet transmission life cycle, the uplink and downlink transmission direction information of the message, and the data content of the message into an integrity protection algorithm to obtain the second timeliness verification code corresponding to the message.
9. A transmission timeliness verification method, wherein, applied to a sending end device, the method includes: obtaining a first timeliness verification parameter of a message; wherein, the first timeliness verification parameter includes the sending timestamp of the message and the data packet transmission life cycle; generating a first timeliness verification code of the message according to the first timeliness verification parameter; sending the message, where the message includes the sending timestamp and the first timeliness verification code, so that the receiving end device verifies the timeliness of the received message.
10. The method according to claim 9, wherein, generating the first timeliness verification code of the message according to the first timeliness verification parameter includes: generating the first timeliness verification code corresponding to the message based on the first timeliness verification parameter by using an integrity protection algorithm.
11. The method according to claim 9, wherein, the method further includes: generating the data packet transmission life cycle according to a pre-configured data packet transmission life cycle generator, and the data packet transmission life cycle generator is used to generate the data packet transmission life cycle according to the length or content of the message; or, obtaining the data packet transmission life cycle pre-agreed between the sending end device and the receiving end device.
12. A transmission timeliness verification system, wherein, including: a sending end device, configured to obtain a first timeliness verification parameter of a message; wherein, the first timeliness verification parameter includes the sending timestamp of the message and the data packet transmission life cycle; generating a first timeliness verification code of the message according to the first timeliness verification parameter; sending the message, where the message includes the sending timestamp and the first timeliness verification code, so that the receiving end device verifies the timeliness of the received message; A receiving end device, configured to receive a message from a sending end device, and determine a first timeliness verification parameter of the message, a first timeliness verification code of the message, and a reception timestamp of the message; verify the timeliness of the message according to the first timeliness verification parameter of the message, the first timeliness verification code of the message, and the reception timestamp of the message, to obtain a timeliness verification result.
13. An electronic device, characterized in that, it includes: at least one processor; a memory, storing at least one program thereon, and when the at least one program is executed by the at least one processor, enabling the at least one processor to implement the method according to any one of claims 1-8 or the method according to any one of claims 9-11; at least one I / O interface, connected between the processor and the memory, configured to implement information interaction between the processor and the memory.
14. A computer-readable medium, storing a computer program thereon, and when the program is executed by a processor, implementing the method according to any one of claims 1-8 or the method according to any one of claims 9-11.
Citation Information
Cited By
Instruction timeliness verification method and device, equipment and storage medium
CN120956632A