A method and system for cross-validation between different basebands

By performing cross-verification in the baseband communication chip, direct verification of the new baseband is achieved using the verified baseband and the unverified baseband encryption and decryption units, which reduces the verification difficulty and cost.

CN120282135BActive Publication Date: 2025-09-02BEIJING WINNER MICROELECTRONICS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510578902.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-09-02
Estimated Expiration
2045-05-07

AI Technical Summary

Technical Problem

In the development of baseband communication chips, when transplanting old basebands to new basebands, traditional verification methods require the design of special algorithm models, resulting in increased verification difficulty and cost.

Method used

By cross-verification between the verified baseband and the unverified baseband, the encryption and decryption operation of data packets is performed using a security module integrated by the encryption unit and the decryption unit, and verification is performed based on the decrypted data.

Benefits of technology

The verification complexity and cost of new basebands are reduced, and the new baseband is directly verified through the old baseband, without the need to design a special algorithm model for the new baseband.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120282135B_ABST
    Figure CN120282135B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for cross-verification between different basebands, comprising: obtaining a first encrypted data packet obtained by encrypting a specific data packet using an encryption unit in a first baseband, sending the first encrypted data packet to a decryption unit in a second baseband for decryption to obtain first decrypted data, and looping back to obtain second decrypted data; obtaining a second encrypted data packet obtained by encrypting a specific data packet using an encryption unit in a second baseband, sending the second encrypted data packet to the decryption unit in the first baseband for decryption to obtain third decrypted data, and looping back to obtain fourth decrypted data; and verifying a security module based on the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data. The present invention mutually verifies the security module using the first and second basebands, allowing the old baseband to directly verify the new baseband, eliminating the need to design a dedicated algorithm model for the new baseband and reducing verification costs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of communication baseband verification, and in particular relates to a method and system for cross-verification between different basebands. Background Art

[0002] The development process for baseband communication chips involves simulation verification of the encryption and decryption functions of the digital baseband security module. Traditional verification equipment uses algorithm models to provide simulation test vectors to verify the digital baseband security module. This conventional verification equipment requires the support of a pre-existing algorithm model.

[0003] However, for portable design and development, it is usually completed by transplanting the old baseband security module that has passed the Wi-Fi interoperability test certification to the new baseband and adding new timing control and state machine control. At this time, if a corresponding matching algorithm model is designed for verification, it will lead to increased verification difficulty and cost. Summary of the Invention

[0004] In order to solve the above problems existing in the prior art, the present invention provides a method and system for cross-validation between different basebands. The technical problem to be solved by the present invention is achieved through the following technical solutions:

[0005] A method for cross-validation between different basebands, comprising:

[0006] obtaining, based on a specific data packet, a first encrypted data packet obtained by encrypting the specific data packet using an encryption unit in the first baseband, sending the first encrypted data packet to a decryption unit in the second baseband for decryption to obtain first decrypted data, and looping the first encrypted data packet back to the decryption unit in the first baseband for decryption to obtain second decrypted data;

[0007] After obtaining a second encrypted data packet encrypted by an encryption unit in a second baseband based on a specific data packet, the second encrypted data packet is sent to a decryption unit in a first baseband for decryption to obtain third decrypted data, and the second encrypted data packet is looped back to the decryption unit in the second baseband for decryption to obtain fourth decrypted data, wherein the encryption unit and the decryption unit are integrated in a security module, the first baseband is a baseband that has been verified by the security module, and the second baseband is a baseband that has not been verified by the security module, the channel bandwidth, key, MAC frame header address, and data format of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence;

[0008] The security module is verified according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data.

[0009] In a specific embodiment, the encryption algorithm of the encryption unit includes one or more of WEP, TKIP, BIP, CCMP, GCMP and WAPI.

[0010] In a specific embodiment, the first encrypted data packet obtained by the encryption unit in the first baseband encrypting the specific data packet includes:

[0011] The encryption unit in the first baseband obtains the MAC frame body ciphertext and the MIC ciphertext for integrity verification according to the MAC frame header, the security header, and the MAC frame body plaintext;

[0012] Verifying the MAC frame body ciphertext and the MIC ciphertext to obtain a frame check sequence;

[0013] The MAC frame header, security header, MAC frame body ciphertext, MIC ciphertext and frame check sequence are sent to the physical layer for modulation to obtain a first encrypted data packet.

[0014] In a specific embodiment, the decryption unit in the second baseband performs decryption to obtain the first decrypted data, including:

[0015] The physical layer performs AGC detection on the first encrypted data packet and PHY layer demodulation to obtain a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext and a frame check sequence;

[0016] After the MAC frame body ciphertext and the MIC ciphertext are verified, the decryption unit decrypts the MAC frame body ciphertext to obtain first decrypted data.

[0017] In a specific implementation, the AGC detects that the signal type of the frame header is a dsss signal type or an ofdm signal type.

[0018] In a specific embodiment, the specific data packet has a plurality of identification fields, and the identification fields are located at different positions in the specific data packet, so that the specific positions of the first encrypted data packet or the second encrypted data packet have the same data identification by encrypting the specific data packet;

[0019] Accordingly, verifying the second baseband according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data includes:

[0020] When it is determined that the specific positions in the first decrypted data and the second decrypted data have the same data identifier, it is determined that the decryption unit of the second baseband has been verified, or when it is determined that the specific positions in the third decrypted data and the fourth decrypted data have the same data identifier, it is determined that the encryption unit of the second baseband has been verified.

[0021] The present invention also provides a method for cross-validation between different basebands, comprising:

[0022] obtaining, based on a specific data packet, a first encrypted data packet obtained by encrypting the specific data packet using an encryption unit in the first baseband, sending the first encrypted data packet to a decryption unit in the second baseband for decryption to obtain first decrypted data, and looping the first encrypted data packet back to the decryption unit in the first baseband for decryption to obtain second decrypted data;

[0023] obtaining, based on the second decrypted data, a second encrypted data packet encrypted by an encryption unit in the second baseband, sending the second encrypted data packet to the decryption unit in the first baseband for decryption to obtain third decrypted data, and looping the second encrypted data packet back to the decryption unit in the second baseband for decryption to obtain fourth decrypted data;

[0024] verifying the second baseband according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data;

[0025] In which, the encryption unit and the decryption unit are integrated in a security module, the first baseband is a baseband that has been verified by the security module, and the second baseband is a baseband that has not been verified by the security module. The channel bandwidth, key, MAC frame header address, and data format of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence.

[0026] The present invention also provides a system for cross-authentication between different basebands, comprising a first baseband and a second baseband having a transmitting port and a receiving port, wherein the first baseband and the second baseband are both integrated with a security module, wherein the security module includes an encryption unit and a decryption unit;

[0027] The transmitting port of the first baseband is connected to the receiving port of the second baseband, so that the receiving port of the first baseband is used to receive a specific data packet, obtain a first encrypted data packet based on the specific data packet by encrypting the specific data packet by the encryption unit in the first baseband, send the first encrypted data packet to the decryption unit in the second baseband for decryption to obtain first decrypted data, and loop back the first encrypted data packet to the decryption unit in the first baseband for decryption to obtain second decrypted data;

[0028] The transmitting port of the second baseband is connected to the receiving port of the first baseband, and the receiving port of the second baseband is used to obtain, based on a specific data packet, a second encrypted data packet encrypted by an encryption unit in the second baseband, and then send the second encrypted data packet to the decryption unit in the first baseband for decryption to obtain third decrypted data, and loop back the second encrypted data packet to the decryption unit in the second baseband for decryption to obtain fourth decrypted data, wherein the encryption unit and the decryption unit are integrated in a security module, the first baseband is a baseband that has been verified by the security module, and the second baseband is a baseband that has not been verified by the security module, the channel bandwidth, key, MAC frame header address, and data format of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence;

[0029] A verification module is configured to verify the security module according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data.

[0030] In a specific embodiment, the encryption algorithm of the encryption unit includes one or more of WEP, TKIP, BIP, CCMP, GCMP and WAPI.

[0031] In a specific implementation, the AGC detects that the signal type of the frame header is a dsss signal type or an ofdm signal type.

[0032] Beneficial effects of the present invention:

[0033] The method for cross-verification between different basebands of the present invention performs mutual security module verification through the first baseband and the second baseband, so that the new baseband can be directly verified through the old baseband without the need to design a special algorithm model for the new baseband, thereby reducing verification complexity and verification costs.

[0034] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 This is a flow chart of a method for cross-validation between different basebands provided by an embodiment of the present invention;

[0036] Figure 2 This is a specific example diagram of a method for cross-validation between different basebands provided by an embodiment of the present invention;

[0037] Figure 3 1 is a baseband structure diagram of a method for cross-validation between different basebands provided by an embodiment of the present invention;

[0038] Figure 4 The present invention provides a block diagram of a system module for cross-validation between different basebands. DETAILED DESCRIPTION

[0039] The present invention will be further described in detail below with reference to specific examples, but the embodiments of the present invention are not limited thereto.

[0040] Example 1

[0041] See Figure 1 , Figure 1 1 is a flow chart of a method for cross-validation between different basebands provided by an embodiment of the present invention, including:

[0042] obtaining, based on a specific data packet, a first encrypted data packet obtained by encrypting the specific data packet using an encryption unit in the first baseband, sending the first encrypted data packet to a decryption unit in the second baseband for decryption to obtain first decrypted data, and looping the first encrypted data packet back to the decryption unit in the first baseband for decryption to obtain second decrypted data;

[0043] In this embodiment, the first baseband may be, for example, a baseband that has passed the WIFI interoperability test and certification, and the second baseband may be a baseband that has not passed the WIFI interoperability test and certification.

[0044] The first encrypted data packet mainly includes a MAC frame header, a security header, a MAC frame body ciphertext, an integrity check MIC ciphertext, and a frame check sequence (FCS). Specifically, the MAC frame header, security header, and MAC frame body plaintext are encrypted by the security module to obtain the MAC frame body ciphertext and integrity check MIC ciphertext, and then a CRC check is performed to obtain the FCS. The MAC frame header, security header, MAC frame body ciphertext, integrity check MIC ciphertext, and frame check sequence (FCS) are sent to the physical layer (PHY) for modulation to obtain the first encrypted data packet, which is then sent through the txDAC port. The encryption algorithm of the encryption unit includes one or more of WEP, TKIP, BIP, CCMP, GCMP, and WAPI.

[0045] The first encrypted data packet sent by the first baseband's TxDAC port is received by the second baseband's rxADC port. This process simulates wireless signal transmission over the air interface. The first encrypted data packet received over the air interface first undergoes AGC frame header detection. Frame header detection primarily includes automatic gain adjustment, sideband detection, and frame header detection. Automatic gain adjustment and sideband detection can be adjusted based on specific circumstances. Frame header detection requires signal type detection, for example, to determine whether the signal type is DSSS or OFDM. It should be noted that for data compliant with Wi-Fi 1-6 standards, the frame header signal type is OFDM in 802.11a, 802.11g, 802.11n, 802.11ac, and 802.11ax, and DSSS in 802.11b. Demodulation is performed based on the signal type. In order to ensure the consistency of data verification, it is necessary to ensure that the data format of the transceiver is consistent (for example, all are signed number format, or all are unsigned number format), the transceiver channel bandwidth is consistent (for example, all are 20MHz channel bandwidth, or all are 40MHz channel bandwidth), the local key settings are consistent, and the MAC frame header address settings are consistent. The specific MAC frame header addresses may include Address1 (receiver), Address2 (transmitter), and Address3 (BSSID).

[0046] In this process, the physical layer performs AGC detection on the first encrypted data packet and PHY layer demodulation to obtain the MAC frame header, security header, MAC frame body ciphertext, MIC ciphertext and frame check sequence;

[0047] After the MAC frame body ciphertext and the MIC ciphertext are verified, the decryption unit decrypts the MAC frame body ciphertext to obtain first decrypted data.

[0048] The first encrypted data packet is then looped back to its own (first baseband) decryption unit for decryption to obtain the second decrypted data; that is, it is equivalent to using the same ciphertext data stream to stimulate both the baseband that has passed the WiFi interoperability test certification and the baseband that has not passed the WiFi interoperability test certification, so as to compare the intermediate data of nodes at the same level during the decryption process.

[0049] The above process is the first stage. After that, it is necessary to exchange the baseband that has passed the WIFI interoperability test certification with the baseband that has not passed the WIFI interoperability test certification and then perform type verification, that is, based on the specific data packet, obtain the second encrypted data packet that is encrypted by the encryption unit in the second baseband, send the second encrypted data packet to the decryption unit in the first baseband for decryption to obtain the third decrypted data, and loop the second encrypted data packet back to the decryption unit in the second baseband for decryption to obtain the fourth decrypted data, wherein the encryption unit and the decryption unit are integrated in a security module, the first baseband is the baseband that has been verified by the security module, and the second baseband is the baseband that has not been verified by the security module, the channel bandwidth, key, MAC frame header address, and data format of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence;

[0050] Finally, the module is verified according to the first decrypted data, the second decrypted data, the third decrypted data and the fourth decrypted data.

[0051] For a specific example, see Figure 2 , the old baseband refers to the baseband that has passed the WIFI interoperability test certification, and the new baseband refers to the baseband whose security module is to be verified. In the first process, the data packet encrypted by the old baseband is output from the transmitter Tx, sent all the way through the air interface to the receiver Rx of the new baseband to be decrypted and output by the new baseband, and all the way through the self-loop from the receiver Rx of the old baseband to be decrypted and output by the old baseband. In the second process, the data packet encrypted by the new baseband is output from the transmitter Tx, sent all the way through the air interface to the receiver Rx of the old baseband to be decrypted and output by the old baseband, and all the way through the self-loop from the receiver Rx of the new baseband to be decrypted and output by the new baseband. In this way, the encryption and decryption functions of the new baseband can be verified through two-way cross-validation. For the flow of encrypted data and decrypted data within the baseband, please refer to Figure 3 This process is an existing solution and will not be described here.

[0052] In a preferred embodiment, the specific data packet has a plurality of identification fields, and the identification fields are located at different positions in the specific data packet, so that the specific positions of the first encrypted data packet or the second encrypted data packet have the same data identification by encrypting the specific data packet;

[0053] Accordingly, verifying the second baseband according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data includes:

[0054] When it is determined that the first decrypted data and the second decrypted data have the same data identifier at a specific location, the second baseband decryption unit is determined to have passed verification. Alternatively, when it is determined that the third decrypted data and the fourth decrypted data have the same data identifier at a specific location, the second baseband encryption unit is determined to have passed verification. To improve comparison efficiency, this embodiment pre-marks several identification fields in the specific data packet. Therefore, during subsequent data transmission, data encryption, and data decryption, it is possible to determine whether the data was completely transmitted, correctly encrypted, or correctly decrypted solely based on these identification fields, eliminating the need for a global comparison.

[0055] As a preferred embodiment, the present invention also provides a method for cross-validation between different basebands, comprising:

[0056] obtaining, based on a specific data packet, a first encrypted data packet obtained by encrypting the specific data packet using an encryption unit in the first baseband, sending the first encrypted data packet to a decryption unit in the second baseband for decryption to obtain first decrypted data, and looping the first encrypted data packet back to the decryption unit in the first baseband for decryption to obtain second decrypted data;

[0057] obtaining, based on the second decrypted data, a second encrypted data packet encrypted by an encryption unit in the second baseband, sending the second encrypted data packet to the decryption unit in the first baseband for decryption to obtain third decrypted data, and looping the second encrypted data packet back to the decryption unit in the second baseband for decryption to obtain fourth decrypted data;

[0058] verifying the second baseband according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data;

[0059] In which, the encryption unit and the decryption unit are integrated in a security module, the first baseband is a baseband that has been verified by the security module, and the second baseband is a baseband that has not been verified by the security module. The channel bandwidth, key, MAC frame header address, and data format of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence.

[0060] It should be noted that in this preferred process, the data used for cross-validation is the decrypted data obtained in the previous round. In other words, this process cannot perform cross-validation in parallel and requires waiting for one verification to complete before performing reverse cross-validation. Therefore, the process will first obtain the first decrypted data and the second decrypted data. After obtaining the first and second decrypted data, the decryption module can also be verified by verifying the first and second decrypted data. If the decryption module is verified correctly, the encryption module is then verified, avoiding an invalid verification. At the same time, since the input data for the second verification is the previous decrypted data, no additional data marking is required and data screening can be performed directly, resulting in higher resource utilization. However, the disadvantage of this process is that it cannot perform a one-time verification, resulting in low verification efficiency.

[0061] The method for cross-verification between different basebands in this embodiment performs mutual security module verification between the first baseband and the second baseband, so that the new baseband can be directly verified by the old baseband without the need to design a special algorithm model for the new baseband, thereby reducing verification complexity and verification costs.

[0062] See Figure 4 The present invention also provides a system for cross-authentication between different basebands, including a first baseband and a second baseband having a transmitting port and a receiving port, wherein the first baseband and the second baseband are both integrated with a security module, and the security module includes an encryption unit and a decryption unit;

[0063] The transmitting port of the first baseband is connected to the receiving port of the second baseband, so that the receiving port of the first baseband is used to receive a specific data packet, obtain a first encrypted data packet based on the specific data packet by encrypting the specific data packet by the encryption unit in the first baseband, send the first encrypted data packet to the decryption unit in the second baseband for decryption to obtain first decrypted data, and loop back the first encrypted data packet to the decryption unit in the first baseband for decryption to obtain second decrypted data;

[0064] The transmitting port of the second baseband is connected to the receiving port of the first baseband, and the receiving port of the second baseband is used to obtain, based on a specific data packet, a second encrypted data packet encrypted by an encryption unit in the second baseband, and then send the second encrypted data packet to the decryption unit in the first baseband for decryption to obtain third decrypted data, and loop back the second encrypted data packet to the decryption unit in the second baseband for decryption to obtain fourth decrypted data, wherein the encryption unit and the decryption unit are integrated in a security module, the first baseband is a baseband that has been verified by the security module, and the second baseband is a baseband that has not been verified by the security module, the channel bandwidth, key, MAC frame header address, and data format of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence;

[0065] A verification module is configured to verify the security module according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data.

[0066] In a specific embodiment, the encryption algorithm of the encryption unit includes one or more of WEP, TKIP, BIP, CCMP, GCMP and WAPI.

[0067] In a specific implementation, the AGC detects that the signal type of the frame header is a dsss signal type or an ofdm signal type.

[0068] In the description of this specification, the reference terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" mean that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any appropriate manner in any one or more embodiments or examples. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification.

[0069] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art can understand and implement other changes to the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. A single processor or other unit can implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0070] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.

Claims

1. A method for cross-validation between different basebands, characterized in that: include: obtaining, based on a specific data packet, a first encrypted data packet obtained by encrypting the specific data packet using an encryption unit in the first baseband, sending the first encrypted data packet to a decryption unit in the second baseband for decryption to obtain first decrypted data, and looping the first encrypted data packet back to the decryption unit in the first baseband for decryption to obtain second decrypted data; After obtaining a second encrypted data packet encrypted by an encryption unit in a second baseband based on a specific data packet, the second encrypted data packet is sent to a decryption unit in a first baseband for decryption to obtain third decrypted data, and the second encrypted data packet is looped back to the decryption unit in the second baseband for decryption to obtain fourth decrypted data, wherein the encryption unit and the decryption unit are integrated in a security module, the first baseband is a baseband that has been verified by the security module, and the second baseband is a baseband that has not been verified by the security module, the channel bandwidth, key, MAC frame header address, and data format of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence; The security module is verified according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data.

2. The method for cross-validation between different basebands according to claim 1, wherein: The encryption algorithm of the encryption unit includes one or more of WEP, TKIP, BIP, CCMP, GCMP and WAPI.

3. The method for cross-validation between different basebands according to claim 1, wherein: The first encrypted data packet obtained by the encryption unit in the first baseband encrypting the specific data packet includes: The encryption unit in the first baseband obtains the MAC frame body ciphertext and the MIC ciphertext for integrity verification according to the MAC frame header, the security header, and the MAC frame body plaintext; Verifying the MAC frame body ciphertext and the MIC ciphertext to obtain a frame check sequence; The MAC frame header, security header, MAC frame body ciphertext, MIC ciphertext and frame check sequence are sent to the physical layer for modulation to obtain a first encrypted data packet.

4. The method for cross-validation between different basebands according to claim 1, wherein: The decryption unit in the second baseband performs decryption to obtain first decrypted data, including: The physical layer performs AGC detection on the first encrypted data packet and PHY layer demodulation to obtain a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext and a frame check sequence; After the MAC frame body ciphertext and the MIC ciphertext are verified, the decryption unit decrypts the MAC frame body ciphertext to obtain first decrypted data.

5. The method for cross-validation between different basebands according to claim 4, characterized in that: The AGC detects whether the signal type of the frame header is a dsss signal type or an ofdm signal type.

6. The method for cross-validation between different basebands according to claim 1, wherein: The specific data packet has a plurality of identification fields, and the identification fields are located at different positions in the specific data packet, so that the specific positions of the first encrypted data packet or the second encrypted data packet have the same data identification by encrypting the specific data packet; Accordingly, verifying the second baseband according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data includes: When it is determined that the specific positions in the first decrypted data and the second decrypted data have the same data identifier, it is determined that the decryption unit of the second baseband has been verified, or when it is determined that the specific positions in the third decrypted data and the fourth decrypted data have the same data identifier, it is determined that the encryption unit of the second baseband has been verified.

7. A method for cross-validation between different basebands, characterized in that: include: obtaining, based on a specific data packet, a first encrypted data packet obtained by encrypting the specific data packet using an encryption unit in the first baseband, sending the first encrypted data packet to a decryption unit in the second baseband for decryption to obtain first decrypted data, and looping the first encrypted data packet back to the decryption unit in the first baseband for decryption to obtain second decrypted data; obtaining, based on the second decrypted data, a second encrypted data packet encrypted by an encryption unit in the second baseband, sending the second encrypted data packet to the decryption unit in the first baseband for decryption to obtain third decrypted data, and looping the second encrypted data packet back to the decryption unit in the second baseband for decryption to obtain fourth decrypted data; verifying the second baseband according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data; In which, the encryption unit and the decryption unit are integrated in a security module, the first baseband is a baseband that has been verified by the security module, and the second baseband is a baseband that has not been verified by the security module. The channel bandwidth, key, MAC frame header address, and data format of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence.

8. A system for cross-validation between different basebands, characterized in that: The system comprises a first baseband and a second baseband having a transmitting port and a receiving port, wherein the first baseband and the second baseband are both integrated with a security module, and the security module comprises an encryption unit and a decryption unit; The transmitting port of the first baseband is connected to the receiving port of the second baseband, so that the receiving port of the first baseband is used to receive a specific data packet, obtain a first encrypted data packet based on the specific data packet by encrypting the specific data packet by the encryption unit in the first baseband, send the first encrypted data packet to the decryption unit in the second baseband for decryption to obtain first decrypted data, and loop back the first encrypted data packet to the decryption unit in the first baseband for decryption to obtain second decrypted data; The transmitting port of the second baseband is connected to the receiving port of the first baseband, and the receiving port of the second baseband is used to obtain, based on a specific data packet, a second encrypted data packet encrypted by an encryption unit in the second baseband, and then send the second encrypted data packet to the decryption unit in the first baseband for decryption to obtain third decrypted data, and loop back the second encrypted data packet to the decryption unit in the second baseband for decryption to obtain fourth decrypted data, wherein the encryption unit and the decryption unit are integrated in a security module, the first baseband is a baseband that has been verified by the security module, and the second baseband is a baseband that has not been verified by the security module, the channel bandwidth, key, MAC frame header address, and data format of the first baseband and the second baseband are the same, and the encrypted data packet includes a MAC frame header, a security header, a MAC frame body ciphertext, a MIC ciphertext, and a frame check sequence; A verification module is configured to verify the security module according to the first decrypted data, the second decrypted data, the third decrypted data, and the fourth decrypted data.

9. The system for cross-validation between different basebands according to claim 8, characterized in that: The encryption algorithm of the encryption unit includes one or more of WEP, TKIP, BIP, CCMP, GCMP and WAPI.

10. The system for cross-validation between different basebands according to claim 8, characterized in that: The AGC detects whether the signal type of the frame header is a dsss signal type or an ofdm signal type.

Citation Information

Patent Citations

  • Parallel processing system and method for encryption and decryption coexistence of WAPI, CCMP and GCMP in wireless local area network

    CN119342459A

  • RRC connection resume method and apparatus

    US20200260283A1