Method and system for cross validation between different base bands

By performing cross-verification in the baseband communication chip, the encryption and decryption units of the verified baseband and the unverified baseband are mutually verified, which solves the problem of difficulty and cost of verification when transplanting the baseband, and realizes low-cost baseband security module verification.

CN120282135AActive Publication Date: 2025-07-08BEIJING WINNER MICROELECTRONICS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510578902.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-07-08
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

In the development of baseband communication chips, when transplanting old basebands to new basebands, traditional verification methods require the design of special algorithm models, resulting in increased verification difficulty and cost.

Method used

By cross-verification between the verified first baseband and the unverified second baseband, the encryption unit and the decryption unit are used to verify each other in the security module, including the self-loopback processing of encrypted and decrypted data packets, and encryption algorithms such as WEP, TKIP, BIP, CCMP, GCMP and WAPI, ensuring the consistency of channel bandwidth, key and data format.

Benefits of technology

The verification complexity and cost of new basebands are reduced, and the security module functions of new basebands are directly verified through old basebands, without the need to design special algorithm models for new basebands.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120282135A_ABST
    Figure CN120282135A_ABST
Patent Text Reader

Abstract

The invention discloses a method for cross validation between different base bands, which comprises the following steps: acquiring a first encrypted data packet obtained by encrypting a specific data packet by an encryption unit in a first base band, and then sending the first encrypted data packet to a decryption unit in a second base band for decryption to obtain first decrypted data, performing self-loopback to obtain second decrypted data; acquiring a second encrypted data packet obtained by encrypting the specific data packet by an encryption unit in a second base band, sending the second encrypted data packet to a decryption unit in the first base band for decryption to obtain third decrypted data, and performing self-loopback to obtain fourth decrypted data, and verifying the security module according to the first decrypted data, the second decrypted data, the third decrypted data and the fourth decrypted data. According to the invention, the first baseband and the second baseband mutually carry out security module verification, so that the new baseband can be directly verified through the old baseband, a special algorithm model does not need to be designed for the new baseband, and the verification cost is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of communication baseband verification, and particularly relates to a method and system for cross-verification between different basebands. Background Art

[0002] In the development process of baseband communication chips, simulation verification of the encryption and decryption functions of the digital baseband security module is involved. The traditional verification device uses an algorithm model to provide simulation test vectors to verify the digital baseband security module. Such a conventional verification device requires the support of a pre-existing algorithm model.

[0003] However, for portable design and development, it is usually completed by transplanting the old baseband security module that has passed the WIFI interconnection and interoperability test certification to the new baseband and adding new timing control and state machine control. At this time, if a corresponding matching algorithm model is designed for verification, it will lead to an increase in verification difficulty and verification cost. Summary of the Invention

[0004] In order to solve the above problems existing in the prior art, the present invention provides a method and system for cross-verification between different basebands. The technical problems to be solved by the present invention are achieved through the following technical solutions:

[0005] A method for cross-verification between different basebands, comprising:

[0006] After obtaining a first encrypted data packet obtained by encrypting a specific data packet with an encryption unit in a first baseband based on the specific data packet, sending the first encrypted data packet to a decryption unit in a second baseband for decryption to obtain first decrypted data, and looping the first encrypted data packet back to the decryption unit in the first baseband for decryption to obtain second decrypted data;

[0007] After obtaining a second encrypted data packet obtained by encrypting the specific data packet with an encryption unit in the second baseband based on the specific data packet, sending the second encrypted data packet to a decryption unit in the first baseband for decryption to obtain third decrypted data, and looping the second encrypted data packet back to the decryption unit in the second baseband for decryption to obtain fourth decrypted data, wherein the encryption unit and the decryption unit are integrated in a security module, the first baseband is a baseband for which the security module has been verified, the second baseband is a baseband for which the security module has not been verified, the channel bandwidths, keys, MAC frame header addresses, and data formats of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, MAC frame body ciphertext, MIC ciphertext, and a frame check sequence;

[0008] Verifying the security module according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data.

[0009] In a specific embodiment, the encryption algorithm of the encryption unit includes one or more of WEP, TKIP, BIP, CCMP, GCMP, and WAPI.

[0010] In a specific embodiment, the first encrypted packet obtained by the encryption unit in the first baseband encrypting the specific data packet includes:

[0011] The encryption unit in the first baseband obtains the encrypted MAC frame body ciphertext and the MIC ciphertext for integrity check according to the MAC frame header, the security header, and the plaintext of the MAC frame body;

[0012] Check the encrypted MAC frame body ciphertext and the MIC ciphertext to obtain a frame check sequence;

[0013] Send the MAC frame header, the security header, the encrypted MAC frame body ciphertext, the MIC ciphertext, and the frame check sequence to the physical layer for modulation to obtain the first encrypted packet.

[0014] In a specific embodiment, the decryption unit in the second baseband decrypts to obtain the first decrypted data, including:

[0015] The physical layer performs AGC detection of the frame header and PHY layer demodulation on the first encrypted packet to obtain the MAC frame header, the security header, the encrypted MAC frame body ciphertext, the MIC ciphertext, and the frame check sequence;

[0016] After passing the check of the encrypted MAC frame body ciphertext and the MIC ciphertext, the decryption unit decrypts the encrypted MAC frame body ciphertext to obtain the first decrypted data.

[0017] In a specific embodiment, the signal type of the AGC detection frame header is the dsss signal type or the ofdm signal type.

[0018] In a specific embodiment, the specific data packet has a plurality of identification fields, and the identification fields are located at different positions in the specific data packet, so that the encryption of the specific data packet makes the specific positions of the first encrypted packet or the second encrypted packet have the same data identification;

[0019] Correspondingly, verifying the second baseband according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data includes:

[0020] When it is judged that the specific positions in the first decrypted data and the second decrypted data have the same data identification, it is determined that the decryption unit of the second baseband passes the verification, or when it is judged that the specific positions in the third decrypted data and the fourth decrypted data have the same data identification, it is determined that the encryption unit of the second baseband passes the verification.

[0021] The present invention also provides a method for cross-verification between different basebands, including:

[0022] After obtaining a first encrypted data packet obtained by encrypting the specific data packet with the encryption unit in the first baseband based on the specific data packet, sending the first encrypted data packet to the decryption unit in the second baseband for decryption to obtain first decrypted data, and loopbacking the first encrypted data packet to the decryption unit in the first baseband for decryption to obtain second decrypted data;

[0023] After obtaining a second encrypted data packet obtained by encrypting the second decrypted data with the encryption unit in the second baseband based on the second decrypted data, sending the second encrypted data packet to the decryption unit in the first baseband for decryption to obtain third decrypted data, and loopbacking the second encrypted data packet to the decryption unit in the second baseband for decryption to obtain fourth decrypted data;

[0024] Verifying the second baseband according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data;

[0025] Wherein, the encryption unit and the decryption unit are integrated in a security module, the first baseband is a baseband verified by the security module, the second baseband is a baseband not verified by the security module, the channel bandwidths, keys, MAC frame header addresses, and data formats of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, MAC frame body ciphertext, MIC ciphertext, and frame check sequence.

[0026] The present invention also provides a system for cross-verification between different basebands, including a first baseband and a second baseband having a sending port and a receiving port, both the first baseband and the second baseband are integrated with a security module, and the security module includes an encryption unit and a decryption unit;

[0027] The sending port of the first baseband is connected to the receiving port of the second baseband, and the receiving port of the first baseband is used to receive a specific data packet. After obtaining a first encrypted data packet obtained by encrypting the specific data packet with the encryption unit in the first baseband based on the specific data packet, sending the first encrypted data packet to the decryption unit in the second baseband for decryption to obtain first decrypted data, and loopbacking the first encrypted data packet to the decryption unit in the first baseband for decryption to obtain second decrypted data;

[0028] The transmission port of the second baseband is connected to the reception port of the first baseband. The reception port of the second baseband is used to obtain, based on a specific data packet, a second encrypted data packet obtained by encrypting the specific data packet with an encryption unit in the second baseband, and then send the second encrypted data packet to a decryption unit in the first baseband for decryption to obtain third decrypted data, and loop back the second encrypted data packet to the decryption unit in the second baseband for decryption to obtain fourth decrypted data. Wherein, the encryption unit and the decryption unit are integrated in a security module. The first baseband is a baseband verified by the security module, and the second baseband is a baseband not verified by the security module. The channel bandwidths, keys, MAC frame header addresses, and data formats of the first baseband and the second baseband are the same. The encrypted data packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence;

[0029] A verification module, configured to verify the security module according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data.

[0030] In a specific embodiment, the encryption algorithm of the encryption unit includes one or more of WEP, TKIP, BIP, CCMP, GCMP, and WAPI.

[0031] In a specific embodiment, the signal type of the AGC detection frame header is a dsss signal type or an ofdm signal type.

[0032] Advantages of the present invention:

[0033] The method for cross-verification between different basebands of the present invention performs security module verification between the first baseband and the second baseband, enabling the old baseband to directly verify the new baseband without the need to design a dedicated algorithm model for the new baseband, thereby reducing the verification complexity and verification cost.

[0034] The following will further describe the present invention in detail with reference to the accompanying drawings and embodiments. Description of the Drawings

[0035] Figure 1 is a schematic flowchart of a method for cross-verification between different basebands provided by an embodiment of the present invention;

[0036] Figure 2 is a specific example diagram of a method for cross-verification between different basebands provided by an embodiment of the present invention;

[0037] Figure 3 is a baseband structure diagram of a method for cross-verification between different basebands provided by an embodiment of the present invention;

[0038] Figure 4 It is a system module block diagram provided by an embodiment of the present invention for cross-verification between different basebands. Detailed implementation manners

[0039] The present invention will be further described in detail below in conjunction with specific embodiments, but the implementation manners of the present invention are not limited thereto.

[0040] Embodiment 1

[0041] Please refer to Figure 1 , Figure 1 It is a schematic diagram of a method flow for cross-verification between different basebands provided by an embodiment of the present invention, including:

[0042] After obtaining a first encrypted data packet obtained by encrypting the specific data packet with an encryption unit in the first baseband based on the specific data packet, the first encrypted data packet is sent to a decryption unit in the second baseband for decryption to obtain first decryption data, and the first encrypted data packet is looped back to the decryption unit in the first baseband for decryption to obtain second decryption data;

[0043] The first baseband in this embodiment may be, for example, a baseband that has passed the WIFI interconnection and interoperability test and certification, and the second baseband correspondingly is a baseband that has not passed the WIFI interconnection and interoperability test and certification. Of course, it is not limited to the above certification method.

[0044] For the first encrypted data packet, it mainly includes a MAC frame header, a security header, a MAC frame body ciphertext, an integrity check MIC ciphertext, and a frame check sequence FCS. Specifically, the MAC frame header, the security header, and the MAC frame body plaintext are encrypted by a security module to obtain the MAC frame body ciphertext and the integrity check MIC ciphertext, and then CRC check is performed to obtain the FCS. The MAC frame header, the security header, the MAC frame body ciphertext, the integrity check MIC ciphertext, and the frame check sequence FCS are sent to the physical layer (PHY) for modulation to obtain the first encrypted data packet, and then sent through the txDAC port. The encryption algorithm of the encryption unit includes one or more of WEP, TKIP, BIP, CCMP, GCMP, and WAPI.

[0045] The first encrypted data packet sent by the first baseband TxDAC port is received through the rxADC port of the second baseband. This process is the process of simulating the wireless signal transmission in the air interface. The first encrypted data packet received through the air interface first needs to perform AGC detection of the frame header. The frame header detection mainly includes automatic gain adjustment, sideband detection, and frame header detection. Among them, the automatic gain adjustment and sideband detection can be adjusted according to specific situations. The frame header detection needs to perform signal type detection. For example, if the detected signal type is the dsss signal type or the ofdm signal type, it should be noted that for data following the WIFI 1-6 protocol standards, in the 802.11a, 802.11g, 802.11n, 802.11ac, 802.11ax standards, the signal type of the frame header is the ofdm signal, and in the 802.11b standard, the signal type of the frame header is the dsss signal, so as to perform demodulation according to different signal types. To ensure the consistency of data verification, it is necessary to ensure that the data formats of the transceiver are the same (for example, both are signed number formats, or both are unsigned number formats), the transceiver channel bandwidths are the same (for example, both are 20MHz channel bandwidths, or both are 40MHz channel bandwidths), the local key settings are the same, and the MAC frame header address settings are the same. The specific MAC frame header address can include Address1 (receiver), Address2 (transmitter), Address3 (BSSID).

[0046] In this process, the physical layer performs AGC detection of the frame header on the first encrypted data packet and PHY layer demodulation to obtain the MAC frame header, security header, MAC frame body ciphertext, MIC ciphertext, and frame check sequence;

[0047] After passing the verification of the MAC frame body ciphertext and the MIC ciphertext, the decryption unit decrypts the MAC frame body ciphertext to obtain the first decrypted data.

[0048] After that, the first encrypted data packet is looped back to the decryption unit of itself (the first baseband) for decryption to obtain the second decrypted data; that is, it is equivalent to applying the same ciphertext data stream to both the baseband that has passed the WIFI interoperability test certification and the baseband that has not passed the WIFI interoperability test certification, so as to compare the intermediate data of the same-level nodes during the decryption process.

[0049] The above process is the first stage. After that, it is necessary to exchange the baseband that has passed the WIFI interconnection and interoperability test certification and the baseband that has not passed the WIFI interconnection and interoperability test certification, and then perform type verification, that is, obtain a second encrypted packet obtained by encrypting the specific packet with the encryption unit in the second baseband based on the specific packet, and then send the second encrypted packet to the decryption unit in the first baseband for decryption to obtain the third decrypted data, and loop back the second encrypted packet to the decryption unit in the second baseband for decryption to obtain the fourth decrypted data, where the encryption unit and the decryption unit are integrated in a security module, the first baseband is the baseband verified by the security module, the second baseband is the baseband not verified by the security module, the channel bandwidth, key, MAC frame header address, and data format of the first baseband and the second baseband are the same, and the encrypted packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence;

[0050] Finally, verify the module according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data.

[0051] In a specific example, please refer to Figure 2 , the old baseband refers to the baseband that has passed the WIFI interconnection and interoperability test certification, and the new baseband refers to the baseband to be verified by the security module. In the first process, the encrypted packet of the old baseband is output from the transmitter Tx, and one path is sent through the air interface to the receiver Rx of the new baseband for decryption and output through the new baseband, and the other path is input from the receiver Rx of the old baseband through the loopback and decrypted by the old baseband itself and then output. In the second process, the encrypted packet of the new baseband is output from the transmitter Tx, and one path is sent through the air interface to the receiver Rx of the old baseband for decryption and output through the old baseband, and the other path is input from the receiver Rx of the new baseband through the loopback and decrypted by the new baseband itself and then output. In this way, through two-way cross-verification, the encryption and decryption functions of the new baseband can be verified. For the flow of encrypted data and decrypted data in the baseband, please refer to Figure 3 , this process is an existing solution and will not be elaborated here.

[0052] In a preferred embodiment, the specific packet has several identification fields, and the identification fields are located at different positions in the specific packet, so that the same data identification is obtained at specific positions of the first encrypted packet or the second encrypted packet through the encryption of the specific packet;

[0053] Correspondingly, verifying the second baseband according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data includes:

[0054] When it is determined that the data identifiers at specific positions in the first decrypted data and the second decrypted data are the same, it is determined that the decryption unit of the second baseband passes the verification; or when it is determined that the data identifiers at specific positions in the third decrypted data and the fourth decrypted data are the same, it is determined that the encryption unit of the second baseband passes the verification. To improve the comparison efficiency, in this embodiment, several identification fields are pre-marked in the specific data packet, so that during subsequent data transmission, data encryption, and data decryption, it can be determined whether the data is completely transmitted or correctly encrypted or decrypted only through the identification field, thus eliminating the need for global comparison.

[0055] As a preference, the present invention also provides a method for cross-verification between different basebands, including:

[0056] After obtaining the first encrypted data packet obtained by encrypting the specific data packet with the encryption unit in the first baseband based on the specific data packet, the first encrypted data packet is sent to the decryption unit in the second baseband for decryption to obtain the first decrypted data, and the first encrypted data packet is looped back to the decryption unit in the first baseband for decryption to obtain the second decrypted data;

[0057] After obtaining the second encrypted data packet obtained by encrypting the second decrypted data with the encryption unit in the second baseband based on the second decrypted data, the second encrypted data packet is sent to the decryption unit in the first baseband for decryption to obtain the third decrypted data, and the second encrypted data packet is looped back to the decryption unit in the second baseband for decryption to obtain the fourth decrypted data;

[0058] Verify the second baseband according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data;

[0059] Wherein, the encryption unit and the decryption unit are integrated in a security module, the first baseband is the baseband that has been verified by the security module, the second baseband is the baseband that has not been verified by the security module, the channel bandwidths, keys, MAC frame header addresses, and data formats of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence.

[0060] It should be noted that, in this optimization process, the data for cross-validation is the decryption data obtained in the previous step. That is to say, cross-validation cannot be performed in parallel in this process. Instead, reverse cross-validation needs to be carried out after one round of validation is completed. Therefore, in this process, first, the first decryption data and the second decryption data are obtained. After obtaining the first decryption data and the second decryption data, the decryption module can be verified by validating the first decryption data and the second decryption data. If the decryption module passes the verification, then the encryption module can be verified, thus avoiding an invalid verification. At the same time, since the input data for the second verification is the decryption data from the previous step, no additional data marking is required, and data screening can be directly performed with relatively high resource utilization. However, the drawback of this process is that one-time verification cannot be carried out, resulting in relatively low verification efficiency.

[0061] The method for cross-validation between different basebands in this embodiment performs security module verification between the first baseband and the second baseband, enabling the old baseband to directly verify the new baseband without the need to design a dedicated algorithm model for the new baseband, thereby reducing the verification complexity and cost.

[0062] Please refer to Figure 4 , the present invention also provides a system for cross-validation between different basebands, including a first baseband and a second baseband each having a sending port and a receiving port. The first baseband and the second baseband are both integrated with a security module, and the security module includes an encryption unit and a decryption unit;

[0063] The sending port of the first baseband is connected to the receiving port of the second baseband. The receiving port of the first baseband is used to receive a specific data packet, and based on the specific data packet, the first encryption data packet obtained by encrypting the specific data packet with the encryption unit in the first baseband is sent to the decryption unit in the second baseband for decryption to obtain the first decryption data. In addition, the first encryption data packet is looped back to the decryption unit in the first baseband for decryption to obtain the second decryption data;

[0064] The transmission port of the second baseband is connected to the reception port of the first baseband. The reception port of the second baseband is used for obtaining, based on a specific data packet, a second encrypted data packet obtained by encrypting the specific data packet with an encryption unit in the second baseband, and then sending the second encrypted data packet to a decryption unit in the first baseband for decryption to obtain third decrypted data, and for looping back the second encrypted data packet to the decryption unit in the second baseband for decryption to obtain fourth decrypted data. Wherein, the encryption unit and the decryption unit are integrated in a security module, the first baseband is a baseband verified by the security module, the second baseband is a baseband not verified by the security module, the channel bandwidths, keys, MAC frame header addresses, and data formats of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence;

[0065] A verification module, configured to verify the security module according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data.

[0066] In a specific embodiment, the encryption algorithm of the encryption unit includes one or more of WEP, TKIP, BIP, CCMP, GCMP, and WAPI.

[0067] In a specific embodiment, the signal type of the AGC detection frame header is a DSSS signal type or an OFDM signal type.

[0068] In the description of this specification, the descriptions with reference to the terms "an embodiment", "some embodiments", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification.

[0069] Although the present application has been described in connection with various embodiments, those skilled in the art will recognize other variations of the disclosed embodiments while practicing the claimed application by viewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other elements or steps, and the indefinite article "a" or "an" does not exclude a plurality. A single processor or other unit may implement several functions recited in the claims. Certain measures are recited in mutually different dependent claims, but this does not mean that these measures cannot be combined to good effect.

[0070] The above is a further detailed description of the present invention in connection with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is limited only to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can be made, and all should be regarded as falling within the protection scope of the present invention.

Claims

1. A method for cross-verification between different basebands, characterized in that, Including: After obtaining a first encrypted packet obtained by encrypting a specific data packet with an encryption unit in a first baseband, sending the first encrypted packet to a decryption unit in a second baseband for decryption to obtain first decrypted data, and looping the first encrypted packet back to the decryption unit in the first baseband for decryption to obtain second decrypted data; After obtaining a second encrypted packet obtained by encrypting the specific data packet with an encryption unit in the second baseband, sending the second encrypted packet to a decryption unit in the first baseband for decryption to obtain third decrypted data, and looping the second encrypted packet back to the decryption unit in the second baseband for decryption to obtain fourth decrypted data, wherein the encryption unit and the decryption unit are integrated in a security module, the first baseband is a baseband verified by the security module, the second baseband is a baseband not verified by the security module, the channel bandwidths, keys, MAC frame header addresses, and data formats of the first baseband and the second baseband are the same, and the encrypted packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence; Verifying the security module according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data.

2. The method for cross-verification between different basebands according to claim 1, wherein The encryption algorithm of the encryption unit includes one or more of WEP, TKIP, BIP, CCMP, GCMP, and WAPI.

3. The method for cross-verification between different basebands according to claim 1, characterized in that The first encrypted packet obtained by encrypting the specific data packet with the encryption unit in the first baseband includes: The encryption unit in the first baseband obtains a MAC frame body ciphertext and a MIC ciphertext for integrity check according to the MAC frame header, the security header, and the MAC frame body plaintext; Checking the MAC frame body ciphertext and the MIC ciphertext to obtain a frame check sequence; Sending the MAC frame header, the security header, the MAC frame body ciphertext, the MIC ciphertext, and the frame check sequence to the physical layer for modulation to obtain a first encrypted packet.

4. The method for cross-verification between different basebands according to claim 1, wherein The decryption unit in the second baseband decrypts to obtain first decrypted data, including: The physical layer performs AGC detection of the frame header and PHY layer demodulation on the first encrypted packet to obtain a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence; After passing the check on the MAC frame body ciphertext and the MIC ciphertext, the decryption unit decrypts the MAC frame body ciphertext to obtain first decrypted data.

5. The method for cross-verification between different basebands according to claim 4, wherein The signal type of the AGC detection frame header is a dsss signal type or an ofdm signal type.

6. The method for cross-verification between different basebands according to claim 1, wherein The specific data packet has a plurality of identification fields, and the identification fields are located at different positions in the specific data packet, so that the same data identification is obtained at a specific position of the first encrypted packet or the second encrypted packet through the encryption of the specific data packet; Correspondingly, verifying the second baseband according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data includes: When it is determined that the data identifiers at specific positions in the first decrypted data and the second decrypted data are the same, it is determined that the decryption unit of the second baseband passes the verification. Or when it is determined that the data identifiers at specific positions in the third decrypted data and the fourth decrypted data are the same, it is determined that the encryption unit of the second baseband passes the verification.

7. A method for cross-verification between different basebands, characterized in that, Comprising: After obtaining the first encrypted data packet obtained by encrypting the specific data packet with the encryption unit in the first baseband based on the specific data packet, sending the first encrypted data packet to the decryption unit in the second baseband for decryption to obtain the first decrypted data, and looping the first encrypted data packet back to the decryption unit in the first baseband for decryption to obtain the second decrypted data; After obtaining the second encrypted data packet obtained by encrypting the second decrypted data with the encryption unit in the second baseband based on the second decrypted data, sending the second encrypted data packet to the decryption unit in the first baseband for decryption to obtain the third decrypted data, and looping the second encrypted data packet back to the decryption unit in the second baseband for decryption to obtain the fourth decrypted data; Verifying the second baseband according to the first decrypted data, the second decrypted data, the third decrypted data and the fourth decrypted data; Wherein, the encryption unit and the decryption unit are integrated in a security module, the first baseband is a baseband that has been verified by the security module, the second baseband is a baseband that has not been verified by the security module, the channel bandwidths, keys, MAC frame header addresses, and data formats of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence.

8. A system for cross-verification between different basebands, characterized in that, Comprising a first baseband and a second baseband having a transmission port and a reception port, both the first baseband and the second baseband are integrated with a security module, and the security module includes an encryption unit and a decryption unit; The transmission port of the first baseband is connected to the reception port of the second baseband. The reception port of the first baseband is used to receive a specific data packet. After obtaining the first encrypted data packet obtained by encrypting the specific data packet with the encryption unit in the first baseband based on the specific data packet, sending the first encrypted data packet to the decryption unit in the second baseband for decryption to obtain the first decrypted data, and looping the first encrypted data packet back to the decryption unit in the first baseband for decryption to obtain the second decrypted data; The transmission port of the second baseband is connected to the reception port of the first baseband. The reception port of the second baseband is used for obtaining a second encrypted packet obtained by encrypting the specific packet with an encryption unit in the second baseband based on the specific packet, and then sending the second encrypted packet to a decryption unit in the first baseband for decryption to obtain third decrypted data, and for looping the second encrypted packet back to the decryption unit in the second baseband for decryption to obtain fourth decrypted data. Wherein, the encryption unit and the decryption unit are integrated in a security module. The first baseband is a baseband verified by the security module, and the second baseband is a baseband not verified by the security module. The channel bandwidths, keys, MAC frame header addresses, and data formats of the first baseband and the second baseband are the same. The encrypted packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence; A verification module, configured to verify the security module according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data.

9. The method system for cross-validation between different basebands according to claim 8, characterized in that, The encryption algorithm of the encryption unit includes one or more of WEP, TKIP, BIP, CCMP, GCMP, and WAPI.

10. The system for cross-verification between different basebands according to claim 8, wherein, The signal type of the AGC detection frame header is a dsss signal type or an ofdm signal type.

Citation Information

Patent Citations

  • Parallel processing system and method for encryption and decryption coexistence of WAPI, CCMP and GCMP in wireless local area network

    CN119342459A

  • RRC connection resume method and apparatus

    US20200260283A1