Communication method and device

CN120283389APending Publication Date: 2025-07-08HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280102177.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-12-09
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

In fronthaul networking, there are security issues in the transmission of clock synchronization messages, which affects the accuracy of clock synchronization. In particular, some clock synchronization messages need to be stamped and transmitted in clear text, which poses the risk of tampering.

Method used

Encryption and decryption processing is used to encrypt and transmit the message that needs to be stamped. The first communication device encrypts the message and sends the encrypted message and timestamp. The receiving end performs decryption processing to ensure the security and safety of the message. accuracy.

Benefits of technology

It improves the security of message transmission, ensures data integrity and accuracy in the clock synchronization process, prevents the risk of tampering, and enhances the reliability of clock synchronization between communication devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120283389A_ABST
    Figure CN120283389A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, and discloses a communication method and device. The method comprises the following steps: a first communication device receives capability information, wherein the capability information is used for indicating that a second communication device supports encryption and decryption processing of a first message; and the first communication device encrypts the first message to obtain a second message and sends the second message and a first timestamp, and the first timestamp is used for indicating the sending time of the second message. With the adoption of the method, the encrypted message (namely the second message) and the first timestamp are sent to the second communication device by the first communication device, so that encrypted transmission of the message (such as a clock synchronization message) needing to be stamped can be realized, and the security of message transmission can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and device Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a communication method and device. Background Art

[0002] In fronthaul networking, the radio equipment controller (REC) and radio equipment (RE) can synchronize their clocks using a clock synchronization protocol. For example, clock synchronization can be achieved using the Precision Time Protocol (PTP) and Synchronous Ethernet (SyncE). PTP is also known as the 1588 protocol. How to effectively synchronize clocks is a technical issue worthy of research.

[0003] Summary of the Invention

[0004] The present application provides a communication method for encrypting and decrypting messages, thereby improving the security of message transmission.

[0005] In a first aspect, embodiments of the present application provide a communication method that can be applied to a first communication device. For example, the method can be performed by the first communication device, or by a module applicable to the first communication device, where the module can be a software module, a hardware circuit or chip, or a software module and a hardware circuit or chip. In this method, a first message is encrypted to obtain a second message; the second message and a first timestamp are sent, where the first timestamp indicates the time when the second message was sent.

[0006] Using the above method, the first communication device sends the second message and the first timestamp to the second communication device, thereby enabling encrypted transmission of messages that require stamping (such as clock synchronization messages), thereby improving the security of message transmission.

[0007] In one possible design, the type of the first message is the first type (ie, the first message is a first type message).

[0008] In one possible design, the method further includes: obtaining the type of the first message; after determining that the type of the first message is the first type, stamping the first message to obtain the first timestamp.

[0009] In one possible design, the method further includes: encrypting the third message to obtain a fourth message; sending the fourth message, and the type of the third message is the second type (that is, the third message is a second type message).

[0010] In one possible design, a first type of message refers to a message that needs to be stamped, and a second type of message refers to a message that does not need to be stamped. The message needs to be stamped, which may mean: when sending a message, the message needs to be stamped to obtain a sending timestamp of the message; and / or, when receiving a message, the message needs to be stamped to obtain a receiving timestamp of the message. Optionally, the first type of message includes but is not limited to at least one of the following: a synchronization message or a delay request message. The second type of message includes but is not limited to at least one of the following: a follow-up message or a delay response message.

[0011] In one possible design, the method further includes: sending a notification message, where the notification message is used to notify the second communication device to start encryption and decryption processing of the message.

[0012] In one possible design, the method further includes: receiving capability information of the second communication device, where the capability information is used to indicate that the second communication device supports encryption processing of the message.

[0013] In one possible design, the method further includes: sending a request message, where the request message is used to request capability information of the second communication device.

[0014] In one possible design, the method further includes: determining that the first communication device supports encryption and decryption processing of the message.

[0015] Using the above method, the first communication device and the second communication device can negotiate whether to support encryption and decryption processing of the message; when the first communication device determines that the first communication device supports encryption and decryption processing of the message, and the second communication device also supports encryption and decryption processing of the message, the second communication device can be notified to start encryption and decryption processing of the message.

[0016] In a second aspect, embodiments of the present application provide a communication method that can be applied to a second communication device. In this method, the second communication device receives a second message and a first timestamp, where the first timestamp indicates the time when the second message was sent; and decrypts the second message to obtain the first message.

[0017] In one possible design, the type of the first message is the first type.

[0018] In one possible design, the method further includes: stamping the second message to obtain a second timestamp, where the second timestamp is used to indicate a reception time of the second message.

[0019] In one possible design, the method further includes: receiving a fourth message; decrypting the fourth message to obtain a third message, wherein the type of the third message is the second type.

[0020] In one possible design, the method also includes: stamping the fourth message to obtain a third timestamp, wherein the third timestamp is used to indicate the reception time of the fourth message; after determining that the type of the third message is the second type, discarding the third timestamp.

[0021] In one possible design, the method further includes: receiving notification information, where the notification information is used to notify the second communication device to start encryption and decryption processing of the message.

[0022] In one possible design, the method further includes: sending capability information, where the capability information is used to indicate that the second communication device supports encryption and decryption processing of the message.

[0023] In one possible design, the method further includes: receiving request information, where the request information is used to request capability information of the second communication device.

[0024] It can be understood that the method described in the above-mentioned second aspect corresponds to the method described in the first aspect, and the beneficial effects of the relevant technical features in the second aspect can be referred to the description of the first aspect and will not be repeated here.

[0025] In a third aspect, an embodiment of the present application provides a communication method that can be applied to a first functional module in a first communication device. In this method, the first functional module in the first communication device sends a first message and indication information of the first message, where the indication information is used to indicate that the first message needs to be stamped; and receives a first timestamp, where the first timestamp is used to indicate the sending time of the first message.

[0026] In one possible design, the type of the first message is the first type.

[0027] In one possible design, the method further includes: sending a third message, where the type of the third message is the second type.

[0028] In a fourth aspect, an embodiment of the present application provides a communication method, which can be applied to a second functional module in a first communication device. In this method, the second functional module in the first communication device receives a first message and indication information of the first message, wherein the indication information indicates that the first message needs to be stamped; encrypts the first message to obtain a second message, and sends the second message; and, based on the indication information, stamps the second message to obtain a first timestamp, and sends the first timestamp, wherein the first timestamp is used to indicate the sending time of the second message.

[0029] In one possible design, the type of the first message is the first type.

[0030] In one possible design, the method further includes: receiving a third message, encrypting the third message to obtain a fourth message, and sending the fourth message; wherein the type of the third message is the second type.

[0031] In a fifth aspect, embodiments of the present application provide a communication method that can be applied to a third functional module in a second communication device. In this method, the third functional module in the second communication device receives a second message, stamps the second message to obtain a second timestamp, where the second timestamp indicates the time when the second message was received; decrypts the second message to obtain a first message; and sends the first message and the second timestamp.

[0032] In one possible design, sending the first message and the second timestamp includes: after determining that the type of the first message is the first type, sending the first message and the second timestamp.

[0033] In one possible design, the method further includes: receiving a fourth message, stamping the fourth message to obtain a third timestamp, where the third timestamp is used to indicate a time when the fourth message was received; decrypting the fourth message to obtain a third message; and after determining that the type of the third message is the second type, sending the third message. Optionally, the second timestamp is discarded.

[0034] Using the methods of aspects 3 to 5 above, from the perspective of the message sender, the first functional module in the sender can send the message and message indication information to the second functional module. The second functional module can then encrypt the message and then stamp the message based on the indication information. From the perspective of the message receiver, the third functional module can stamp all received messages. After decrypting the message, if the message is a first type message, it sends the message and a timestamp to the fourth functional module. In this way, the first type message can be timestamped while the message is being encrypted and decrypted, facilitating time synchronization between the first communication device and the second communication device.

[0035] In a sixth aspect, the present application provides a communication device, which has the functions of implementing the above-mentioned first to fifth aspects. For example, the communication device includes modules or units or means corresponding to the operations involved in the above-mentioned first to fifth aspects. The modules or units or means can be implemented through software, or through hardware, or the corresponding software implementation can be executed through hardware.

[0036] In one possible design, the communication device includes a processing unit and a communication unit. The communication unit can be used to send and receive signals to enable communication between the communication device and other devices; the processing unit can be used to perform certain internal operations of the communication device. The functions performed by the processing unit and the communication unit can correspond to the operations described in the first to fifth aspects above.

[0037] In one possible design, the communication device includes a processor, which can be coupled to a memory. The memory can store the necessary computer programs or instructions for implementing the functions of the first to fifth aspects described above. The processor can execute the computer programs or instructions stored in the memory. When the computer programs or instructions are executed, the communication device implements the method in any possible design or implementation of the first to fifth aspects described above.

[0038] In one possible design, the communication device includes a processor and a memory, and the memory may store the necessary computer programs or instructions for implementing the functions of the first to fifth aspects described above. The processor may execute the computer program or instructions stored in the memory. When the computer program or instructions are executed, the communication device implements the method of any possible design or implementation of the first to fifth aspects described above.

[0039] In one possible design, the communication device includes a processor and an interface circuit, wherein the processor is used to communicate with other devices through the interface circuit and execute the method in any possible design or implementation of the first to fifth aspects above.

[0040] It can be understood that in the sixth aspect above, the processor can be implemented by hardware or by software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor can be a general-purpose processor, which is implemented by reading the software code stored in the memory. In addition, the above processors can be one or more, and the memories can be one or more. The memory can be integrated with the processor, or the memory and the processor can be set separately. In the specific implementation process, the memory can be integrated with the processor on the same chip, or can be set on different chips respectively. The embodiment of the present application does not limit the type of memory and the setting method of the memory and the processor.

[0041] In the seventh aspect, the present application provides a communication system, which may include a first communication device and a second communication device; wherein the first communication device is used for the communication method provided in the first, third or fourth aspect above, and the second communication device is used to execute the communication method provided in the second or fifth aspect above.

[0042] In an eighth aspect, the present application provides a computer-readable storage medium, in which computer-readable instructions are stored. When a computer reads and executes the computer-readable instructions, the computer executes the method in any possible design of the first to fifth aspects above.

[0043] In a ninth aspect, the present application provides a computer program product, which, when read and executed by a computer, enables the computer to execute the method in any possible design of the first to fifth aspects above.

[0044] In the tenth aspect, the present application provides a chip, which includes a processor, and the processor is coupled to a memory, and is used to read and execute a software program stored in the memory to implement the method in any possible design of the first to fifth aspects above. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] FIG1a is a schematic diagram of a network architecture of a fronthaul network provided in an embodiment of the present application;

[0046] FIG1b is a schematic diagram of CPRI and eCPRI provided in an embodiment of the present application;

[0047] FIG2 is a schematic diagram of a communication system provided in an embodiment of the present application;

[0048] FIG3 is a schematic diagram of a possible structure of a first communication device and a second communication device provided in an embodiment of the present application;

[0049] FIG4 is a schematic diagram of a possible implementation flow of clock synchronization provided in an embodiment of the present application;

[0050] FIG5 is a schematic diagram of a flow chart corresponding to the communication method provided in this embodiment;

[0051] FIG6 is a schematic diagram of a flow chart corresponding to the communication method provided in this embodiment;

[0052] FIG7 is a possible exemplary block diagram of a device involved in an embodiment of the present application;

[0053] FIG8 is a schematic structural diagram of a communication device provided in an embodiment of the present application;

[0054] FIG9 is a schematic structural diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0055] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0056] First, some of the terms used in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.

[0057] (1) Clock synchronization

[0058] Clock synchronization may include time synchronization, and optionally, frequency synchronization.

[0059] Taking the clock synchronization of network node A and network node B as an example, time synchronization can mean: at the same moment, the time of network node A and network node B is the same, similar to adjusting the time of a watch; for example, the time of network node A is 10:00 am on November 1, 2022, and the time of network node B is also 10:00 am on November 1, 2022.

[0060] Frequency synchronization can mean that the clocks of network node A and network node B run at the same frequency; for example, the crystal oscillator frequency of network node A and network node B is the same, similar to adjusting the time accuracy of a watch. When the clocks of network node A and network node B run at the same frequency, the number of counts of network node A's clock and network node B's clock are the same during the same time period, and the time increments of network node A and network node B are the same. For example, if the time of network node A increases by 20 seconds, the time of network node B will also increase by 20 seconds.

[0061] For example, when network node A and network node B perform clock synchronization using a synchronization protocol, such as PTP and SyncE, network node A and network node B can perform time synchronization using PTP and frequency synchronization using SyncE. Other protocols may also be used between network nodes for time synchronization and / or frequency synchronization, without limitation. In the embodiments of the present application, clock synchronization between different network nodes using PTP is used as an example. In this case, clock synchronization can also be understood as time synchronization.

[0062] (2)PTP

[0063] PTP is a protocol published by the Institute of Electrical and Electronics Engineers (IEEE) for synchronizing the clocks of different network nodes in a clock network. This protocol timestamps specific PTP messages transmitted between two network nodes to measure the delay between them, thereby achieving clock synchronization between the two nodes. When synchronizing the clocks of two network nodes, the node whose clock needs to be adjusted is the slave node, and the other node is the master node. The slave node adjusts its local clock with reference to the master node's clock.

[0064] Exemplarily, PTP messages may include clock synchronization messages and management messages. The clock synchronization messages may include synchronization (sync) messages, follow (follow_up) messages, delay request (delay_req) messages, delay response (delay_resp) messages, and other possible messages, which are not specifically limited.

[0065] Clock synchronization messages that require stamping can include synchronization messages and delay request messages, while those that do not require stamping can include follow-up messages and delay response messages. Clock synchronization messages that require stamping can also be called event messages, while clock synchronization messages and management messages that do not require stamping can also be called general messages.

[0066] (3) Encryption and decryption processing

[0067] In order to ensure the security of the communication process, the sending end can encrypt the sent message, and correspondingly, the receiving end can decrypt the received message. The decryption process is the inverse process of the encryption process. For example, the encryption and decryption process can be a MACsec process performed based on the media access control security (MACsec) protocol, or an IPsec process performed based on the Internet Protocol security (IPsec) protocol. In the embodiment of the present application, the encryption and decryption process will be described as an example of MACsec processing. Among them, the MACsec protocol integrates security protection into the Ethernet, uses cryptographic technology to authenticate the origin of data, protects the integrity of information and provides replay protection and confidentiality, ensuring that attacks on the Layer 2 protocol are reduced. The MACsec process can be performed at the MAC layer or other layers. In the embodiment of the present application, the MACsec process performed at the MAC layer will be described as an example.

[0068] Exemplarily, when the encryption and decryption process is a MACsec process, the encryption and decryption process may be performed based on a media access control security agreement protocol (MKA).

[0069] (4) Fronthaul Networking

[0070] Figure 1a is a schematic diagram of a network architecture for fronthaul networking according to an embodiment of the present application. As shown in Figure 1a, the network architecture for fronthaul networking may include at least one REC (such as REC1 and REC2 as shown in Figure 1a) and at least one RE (such as RE1, RE2, and RE3 as shown in Figure 1a), and optionally, at least one transmission equipment (TE) (such as TE1, TE2, TE3, TE4, TE5, and TE6 as shown in Figure 1a). REC1 is used to control RE1, and REC2 is used to control RE2 and RE3.

[0071] Taking REC1 and RE1 as an example, REC1 and RE1 can be directly connected, that is, there are no other intermediate network elements between REC1 and RE1. In this case, REC1 and RE1 can synchronize their clocks using the PTP protocol; REC1 is the master node for clock synchronization, and RE1 is the slave node. Alternatively, REC1 and RE1 can also be not directly connected. For example, REC1 and RE1 are connected through TE1, TE3, and TE5. In this case, REC1 and TE1 can synchronize their clocks using the PTP protocol (REC1 is the master node for clock synchronization, TE1 is the slave node), TE1 and TE3 can synchronize their clocks using the PTP protocol (TE1 is the master node for clock synchronization, TE3 is the slave node), TE3 and TE5 can synchronize their clocks using the PTP protocol (TE3 is the master node for clock synchronization, TE5 is the slave node), and TE5 and RE1 can synchronize their clocks using the PTP protocol (TE5 is the master node for clock synchronization, RE1 is the slave node).

[0072] The fronthaul networking in the embodiments of the present application can be applied to a radio access network (RAN). The RAN can be a cellular system related to the third generation partnership project (3GPP), for example, a fourth generation (4G), a fifth generation (5G) mobile communication system, or a future-oriented evolution system (for example, a sixth generation (6G) mobile communication system). The RAN can also be an open access network (open RAN, O-RAN or ORAN), or a cloud radio access network (CRAN). The RAN can also be a communication system that integrates two or more of the above systems.

[0073] The RAN includes RAN nodes. RAN nodes, sometimes also referred to as access network equipment, RAN entities, or access nodes, form part of a communication system and facilitate wireless access for terminals. When a communication system includes multiple RAN nodes, these nodes can be of the same or different types.

[0074] In one possible scenario, a RAN node may be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next-generation NodeB (gNB), a next-generation base station in a 6G mobile communication system, or a base station in a future mobile communication system. A RAN node may be a macro base station, a micro base station, an indoor station, a relay node, a donor node, or a wireless controller in a CRAN scenario. Optionally, a RAN node may also be a server, a wearable device, a vehicle, or an onboard device. For example, the access network device in vehicle-to-everything (V2X) technology may be a road side unit (RSU).

[0075] In another possible scenario, multiple RAN nodes collaborate to implement the functions of a base station, and different RAN nodes implement part of the functions of a base station respectively. For example, a RAN node can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or they can be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).

[0076] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0077] There is an interface between the DU and the RU. This interface can also be called a fronthaul (FH) interface, which is used to realize communication between the DU and the RU. Depending on the functions of the DU and the RU, and / or the different segmentation methods, the interface between the DU and the RU can be a common public radio interface (CPRI) or an enhanced common public radio interface (eCPRI). In one possible implementation, the DU is located in the BBU and the RU is located in the RRU / AAU. The interface between the BBU and the RRU / AAU can also be called a fronthaul interface. In order to realize the fronthaul interface, the BBU and the RRU / AAU / RRH can be connected through the fronthaul network, or the DU and the RU can be connected. For example, the fronthaul network includes but is not limited to: direct fiber connection and wavelength division network.

[0078] In one possible design, for CPRI as shown in Figure 1b, for downlink transmission, the DU is configured to implement one or more of the following physical layer baseband functions: coding, rate matching, scrambling, modulation, layer mapping, precoding, resource element (RE) mapping, digital beamforming (BF), or inverse fast Fourier transformation (IFFT) / cyclic prefix (CP) addition. The RU is configured to implement one or more of the following radio frequency functions: digital to analog (DA) conversion, or analog BF. For uplink transmission, the DU is configured to implement one or more of the following physical layer baseband functions: decoding, rate matching, descrambling, demodulation, inverse discrete Fourier transformation (IDFT), channel equalization (or channel estimation), RE demapping, digital BF, or fast Fourier transform (FFT) / CP removal. The RU is configured to implement one or more of the following radio frequency functions: analog to digital (AD) conversion, or analog BF.

[0079] In another possible implementation, as shown in Figure 1b, eCPRI moves some downlink and / or uplink baseband functions from the DU to the RU, compared to CPRI. The interface between the DU and RU can also be called a lower layer split (LLS). In one possible design, the DU is located in the BBU and the RU is located in the RRU / AAU. The processing unit in the BBU that implements baseband functions is called a baseband high (BBH) unit, and the processing unit in the RRU / AAU that implements baseband functions is called a baseband low (BBL) unit.

[0080] Figure 1b shows six possible implementations of eCPRI. These six implementations are shown in the figure as (category, Cat) A to Cat F. Different eCPRI categories can also be described as different types of eCPRI, different eCPRI options, or other possible names. For example, the six types of eCPRI in Figure 1b can also be called six eCPRI options. In addition to the eCPRI shown in Figure 1b, other types of eCPRI, that is, other segmentation methods, may exist, which are not limited.

[0081] For eCPRI Category B and Category C, as shown in Figure 1b, the uplink and downlink splitting of eCPRI can be symmetrical. For eCPRI Category A, Category D, Category E, and Category F, as shown in Figure 1b, the uplink and downlink splitting of eCPRI can be asymmetrical, without limitation. Optionally, different splitting methods can be configured for different channels or different channel groups for the uplink and / or downlink, i.e., different types of eCPRI can be configured. A channel group can include one or more channels.

[0082] Exemplarily, the REC can be a network element or device with baseband signal processing capabilities, such as a BBU or a software module, hardware circuit, or a combination of a software module and a hardware circuit within the BBU. Alternatively, the REC can be a DU or a software module, hardware circuit, or a combination of a software module and a hardware circuit within the DU. Optionally, the REC can also have at least one of the following functions: local and remote operation and maintenance, or operating status monitoring and alarm information reporting.

[0083] Exemplarily, the RE may be a network element or device having the function of processing wireless signals (e.g., intermediate frequency signals and / or radio frequency signals), also referred to as a radio frequency unit. For example, the RE may be an RRU, AAU, RRH, or RU, or may be a software module, hardware circuit, or software module + hardware circuit in these network elements.

[0084] It is understood that the above-mentioned REC and RE are names in the Common Public Radio Interface (CPRI) protocol. In other possible protocols, REC and RE may also have different names. For example, in the enhanced Common Public Radio Interface (eCPRI), REC is called eREC and RE is called eRE. For example, in the Open Radio Access Network (ORAN) protocol, REC can be a distributed unit (DU) and RE can be a RU.

[0085] The present application will hereinafter present various aspects, embodiments, or features with respect to a communication system that may include multiple devices, components, modules, etc. It should be understood and appreciated that the communication system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the accompanying drawings. Furthermore, combinations of these aspects may also be used.

[0086] The communication system and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. A person skilled in the art will appreciate that, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0087] To facilitate understanding of the embodiments of the present application, a communication system applicable to the embodiments of the present application will first be described in detail using the communication system shown in FIG2 as an example. As shown in FIG2 , the communication system includes a first communication device and a second communication device. The first communication device and the second communication device can synchronize their clocks using a clock synchronization protocol. In the embodiments of the present application, PTP is used as an example for synchronizing the clocks of the first and second communication devices.

[0088] The first communication device may be a master node and the second communication device may be a slave node; or the first communication device may be a slave node and the second communication device may be a master node. In the embodiments of the present application, the first communication device may be a master node and the second communication device may be a slave node.

[0089] It is understandable that the communication system illustrated in FIG2 can be applicable to a variety of possible scenarios, such as a fronthaul networking scenario. When applicable to the fronthaul networking scenario, the first communication device may be a REC, and the second communication device may be a RE, such as the first communication device is REC1, the second communication device is RE1, and there is no other intermediate network element between REC1 and RE1; or, the first communication device may be a REC, and the second communication device may be a TE, such as the first communication device is REC1 illustrated in FIG1a, and the second communication device is TE1 illustrated in FIG1a; or, the first communication device may be one TE, and the second communication device may be another TE, such as the first communication device is TE1 illustrated in FIG1a, and the second communication device is TE3 illustrated in FIG1a; or, the first communication device may be a TE, and the second communication device may be a RE, such as the first communication device is TE5 illustrated in FIG1a, and the second communication device is RE1 illustrated in FIG1a.

[0090] In addition, the communication between the first communication device and the second communication device involved in the embodiments of the present application may refer to direct communication between the first communication device and the second communication device, such as the first communication device directly sending information 1 to the second communication device, or the second communication device directly sending information 2 to the first communication device; or, it may also refer to the first communication device and the second communication device communicating through a relay node, such as the first communication device sending information 1 to the relay node, and after the relay node receives information 1, it forwards information 1 to the second communication device.

[0091] Figure 3 is a schematic diagram of a possible structure of a first communication device and a second communication device according to an embodiment of the present application. As shown in Figure 3, the first communication device may include a first functional module and a second functional module, and the second communication device may include a third functional module and a fourth functional module.

[0092] The first functional module may be a PTP functional module (referred to as PTP functional module 1 for ease of description), which is used to implement PTP layer related functions, such as generating a PTP message, parsing the PTP message to obtain information in the PTP message, etc.

[0093] The second functional module may be an Ethernet port functional module, configured to implement Ethernet port-related functions. For example, the second functional module may include a MAC layer functional module 1, a timestamp functional module 1, and a physical layer functional module 1. The timestamp functional module 1 may be located between the MAC layer functional module 1 and the physical layer functional module 1. For example, the timestamp functional module 1 may be located near the physical layer functional module 1 (i.e., the timestamp is provided near the physical layer). In other possible examples, the timestamp functional module 1 may also be located within the physical layer functional module 1 (i.e., the timestamp is provided within the physical layer).

[0094] The location of the timestamp is explained as follows: Since PTP uses timestamps to achieve clock synchronization between the slave node and the master node, the location of the timestamp will affect the accuracy of the clock synchronization. In the specific implementation, timestamps can be performed by software or by hardware. When timestamps are performed by software, the location of the timestamp is close to the operating system, the jitter time is relatively large, and the time offset is within 100 microseconds; when timestamps are performed by hardware, the location of the timestamp is in or near the physical layer, the jitter time is less than the jitter time of timestamps performed by software, and the accuracy can reach the nanosecond level. In the embodiment of the present application, the relevant implementation is described based on the solution of timestamping by hardware (that is, the timestamp function module is close to the physical layer or located in the physical layer).

[0095] The MAC layer function module 1 is used to implement MAC layer related functions, the timestamp function module 1 is used to perform stamping processing on the first type of PTP message, and the physical layer function module 1 is used to implement physical layer related functions.

[0096] For example, when the first communication device is the sender of a message, the MAC layer function module 1 can perform MAC layer encapsulation processing on the message received from the upper layer (such as the PTP layer) and send the encapsulated message to the physical layer function module 1, so that the physical layer function module 1 can send the message to another communication device (such as the second communication device). In addition, the timestamp function module 1 can detect whether the message transmitted from the MAC layer function module 1 to the physical layer function module 1 is a first type message. If so, it can perform stamping processing on the message to obtain a sending timestamp of the message and send the timestamp to the PTP function module 1.

[0097] When the first communication device is the receiving end of the message, after the physical layer function module 1 receives the message from other communication devices (such as the second communication device), it can transmit the message to the MAC layer function module 1, and then the MAC layer function module 1 can decapsulate the message and send the decapsulated message to the PTP function module 1; and the timestamp function module 1 can detect whether the message transmitted from the physical layer function module 1 to the MAC layer function module 1 is a first type of message. If so, it can perform stamping processing on the message to obtain the receiving timestamp of the message, and send the timestamp to the PTP function module 1.

[0098] The above-mentioned third functional module and fourth functional module can refer to the description of the first functional module and the second functional module. For example, the third functional module can be an Ethernet port functional module, and the third functional module can include a MAC layer functional module 2, a timestamp functional module 2 and a physical layer functional module 2. The fourth functional module can be a PTP functional module 2, which will not be repeated.

[0099] A possible implementation process of clock synchronization between the first communication device and the second communication device is described below in conjunction with Figure 4. As shown in Figure 4, the implementation process may include:

[0100] S401, the first communication device sends a synchronization message to the second communication device, and stamps the synchronization message to obtain a timestamp T1, which is used to indicate the sending time of the synchronization message; accordingly, the second communication device receives the synchronization message, and stamps the synchronization message to obtain a timestamp T2, which is used to indicate the receiving time of the synchronization message.

[0101] Exemplarily, from the perspective of the first communication device: the PTP function module 1 generates a synchronization message and sends the synchronization message to the MAC layer function module 1. After receiving the synchronization message, the MAC layer function module 1 encapsulates the synchronization message and sends the encapsulated message to the physical layer function module 1; and, after the timestamp function module 1 detects that the message transmitted from the MAC layer function module 1 to the physical layer function module 1 is a synchronization message, it stamps the synchronization message to obtain a timestamp T1, and sends the timestamp T1 to the PTP function module 1.

[0102] From the perspective of the second communication device: after the physical layer function module 2 receives the message from the first communication device, it transmits the message to the MAC layer function module 2, and then the MAC layer function module 2 decapsulates the message to obtain a synchronization message, and then transmits the synchronization message to the PTP function module 2; among them, after the timestamp function module 2 detects that the message transmitted from the physical layer function module 2 to the MAC layer function module 2 is a synchronization message, it stamps the synchronization message to obtain a timestamp T2, and sends the timestamp T2 to the PTP function module 2.

[0103] S402: The first communication device sends a follow-up message of the synchronization message to the second communication device, where the follow-up message includes a timestamp T1. Accordingly, after receiving the follow-up message, the second communication device obtains the timestamp T1.

[0104] Exemplarily, from the perspective of the first communication device: after the PTP function module 1 receives the timestamp T1 from the timestamp function module 1, it generates a follow-up message and sends the follow-up message to the MAC layer function module 1. After the MAC layer function module 1 receives the follow-up message, it encapsulates the follow-up message and sends the encapsulated message to the physical layer function module 1; and, after the timestamp function module 1 detects that the message transmitted from the MAC layer function module 1 to the physical layer function module 1 is a follow-up message, the stamping process may not be performed.

[0105] From the perspective of the second communication device: after the physical layer function module 2 receives the message from the first communication device, it transmits the message to the MAC layer function module 2, and then the MAC layer function module 2 decapsulates the message to obtain a follow-up message, and transmits the follow-up message to the PTP function module 2; and, after the timestamp function module 2 detects that the message transmitted from the physical layer function module 2 to the MAC layer function module 2 is a follow-up message, it may not perform the stamping process.

[0106] S403: The second communication device sends a delay request message to the first communication device, and performs a stamping process on the delay request message to obtain a timestamp T3, where the timestamp T3 is used to indicate the sending time of the delay request message.

[0107] S404, after receiving the delay request message, the first communication device stamps the delay request message to obtain a timestamp T4, which is used to indicate the reception time of the delay request message, and sends a delay response message to the second communication device, where the delay response message includes the timestamp T4.

[0108] For example, the specific implementation of S403 and S404 may refer to the above-mentioned S401 and S402.

[0109] Through the above S401 to S404, the second communication device can obtain timestamps T1, T2, T3 and T4, and can determine the time difference between the first communication device and the second communication device and the path delay of the transmission process based on the timestamps T1, T2, T3 and T4, and then realize clock synchronization between the first communication device and the second communication device based on the determined time difference and path delay.

[0110] As shown in FIG4 , during the clock synchronization process, some clock synchronization messages (such as synchronization messages and delay request messages) require stamping. To facilitate stamping of these clock synchronization messages, the clock synchronization messages are transmitted in plain text, which may pose security issues and affect the accuracy of clock synchronization between the first communication device and the second communication device. For example, if the synchronization message sent by the first communication device to the second communication device is tampered with, the second communication device may not be able to accurately determine which synchronization message was sent by the timestamp T1 included in the follow-up message after receiving the follow-up message, thereby affecting the accuracy of clock synchronization.

[0111] Based on this, an embodiment of the present application provides a communication method for encrypting and decrypting messages that need to be stamped, thereby improving the security of message transmission.

[0112] Example 1

[0113] FIG5 is a flow chart of a communication method according to an embodiment of the present invention. As shown in FIG5 , the communication method may include:

[0114] S501: The first communication device encrypts the first message to obtain a second message.

[0115] Here, the first message may be a message that needs to be stamped. For example, the first message may be a clock synchronization message that needs to be stamped as described above (such as a synchronization message, a delay request message, etc.), or may be other messages that need to be stamped, without limitation. In the embodiments of the present application, the first message will be described as a clock synchronization message that needs to be stamped as an example.

[0116] S502, the first communication device sends a second message and a first timestamp to the second communication device, where the first timestamp is used to indicate the sending time of the first message or the second message; accordingly, the second communication device receives the second message and the first timestamp.

[0117] Here, there are various ways to implement the first timestamp sent by the first communication device to the second communication device. For example, after the first communication device sends the second message to the second communication device, it can send another message to the second communication device, the message including the first timestamp. The message can be encrypted or unencrypted, without limitation.

[0118] For example, in the embodiment of the present application, messages can be divided into two types, namely, a first type and a second type. The first type of message refers to a message that needs to be stamped, and the second type of message refers to a message that does not need to be stamped. The type of the first message mentioned above is the first type.

[0119] When the first message is a clock synchronization message that needs to be stamped (such as a synchronization message), the first timestamp can be used for clock synchronization between the first communication device and the second communication device. The first communication device can send the first timestamp to the second communication device via a follow-up message of the synchronization message.

[0120] S503: The second communication device decrypts the second message to obtain the first message.

[0121] S504: The second communication device performs a stamping process on the second message to obtain a second timestamp, where the second timestamp is used to indicate a reception time of the second message.

[0122] Here, S504 is an optional step. For example, when the first message is a clock synchronization message that needs to be stamped, S504 can be executed, and when the first message is other messages that need to be stamped, S504 may not be executed.

[0123] It is understandable that the above example uses the transmission of a first type of message between a first communication device and a second communication device, and that a second type of message can also be transmitted between the first communication device and the second communication device. For example, the first communication device can encrypt a third message (the type of the third message is the second type) to obtain a fourth message, and send the fourth message to the second communication device (which is different from the first type of message and does not send a timestamp of the fourth message); after receiving the fourth message, the second communication device stamps the fourth message to obtain a third timestamp, which is used to indicate the time of receipt of the fourth message, and decrypts the fourth message to obtain a third message; after determining that the type of the third message is the second type, the third timestamp can be discarded.

[0124] Furthermore, the above description uses the example of a first communication device sending a message to a second communication device, i.e., the first communication device is the message sender and the second communication device is the message receiver. In other possible embodiments, the second communication device may also send a message to the first communication device, i.e., the second communication device is the message sender and the first communication device is the message receiver. The implementation of the second communication device sending a message to the first communication device can refer to the implementation of the first communication device sending a message to the second communication device, and will not be further described.

[0125] By adopting the above method, the first communication device sends the second message and the first timestamp to the second communication device, thereby realizing encrypted transmission of the message that needs to be stamped, thereby improving the security of message transmission.

[0126] Optionally, the above method further includes:

[0127] S505: The first communication device sends a request message to the second communication device, where the request message is used to request capability information of the second communication device.

[0128] Exemplarily, the request information may include an identifier of the requesting device (i.e., the first communication device) and a requested encryption and decryption capability indication. The identifier of the first communication device is, for example, the clock identifier (ClockIdentity) of the first communication device. The requested encryption and decryption capability indication is used to indicate whether the request is for capability information of whether the second communication device supports encryption and decryption processing of messages.

[0129] Exemplarily, the first communication device may send a first management message to the second communication device, and the first management message includes request information. For example, the first management message may include a type, length, value (type, length, value, TLV) type field, a TLV length field, an identification field of the requesting device (which can be recorded as a requestIdentity field), and a request encryption and decryption capability indication field (which can be recorded as a requestMACsecAbility field). Among them, the TLV type field is used to indicate the TLV type, and the TLV type can be a newly introduced TLV type in the embodiment of the present application. The TLV length field is used to indicate the total number of bytes occupied by the identification field of the requesting device and the request encryption and decryption capability indication field. The identification field of the requesting device is used to carry the identification of the requesting device. The request MACsec capability indication field is used to carry the request encryption and decryption capability indication.

[0130] Table 1 shows an example of fields included in the first management message.

[0131] Table 1: Example of fields included in the first management message

[0132] The first management message includes the following fields: Number of bytes occupied by the field: TLV type: 2 TLV length: 2 requestIdentity field: 8 requestMACsecAbility field: 2

[0133] In the embodiment of the present application, the TLV type field is used to indicate the type or function of the message carrying the TLV type field. For example, the TLV type field of the first management message is used to indicate that the message is used to request capability information of the second communication device.

[0134] The number of bytes occupied by each field in Table 1 above and Tables 2 and 3 below is only an example and is not limited in specific implementations.

[0135] It is understandable that the first communication device can send request information to the second communication device when it is determined that the first communication device supports encryption and decryption processing of the message; if the first communication device does not support encryption and decryption processing of the message, there is no need to send request information to the second communication device to save transmission resources.

[0136] S506, the second communication device sends capability information to the first communication device according to the request information; correspondingly, the first communication device receives the capability information from the second communication device, where the capability information indicates whether the second communication device supports encryption and decryption of messages.

[0137] When the capability information indicates that the second communication device supports message encryption and decryption processing, the message encryption and decryption method of the embodiment of the present application can be executed.

[0138] Exemplarily, the second communication device can send a second management message as a second communication device, and the second management message can include capability information. For example, the second management message can include a TLV type field, a TLV length field, an identification field of the requesting device, an identification field of the responding device (which can be recorded as grantIdentity), and a capability field of the responding device (which can be recorded as grantMACsecAbility field). Among them, the TLV type field, the TLV length field, and the identification field of the requesting device can refer to the description above. The identification field of the responding device is used to carry the identification of the responding device (i.e., the second communication device). The identification of the second communication device is, for example, the clock identification of the second communication device. The capability field of the responding device is used to carry capability information. As shown in Table 2, an example of the fields included in the second management message is provided.

[0139] Table 2: Example of fields included in the second management message

[0140] The second management message includes the following fields: Number of bytes occupied by the field: TLV type: 2 TLV length: 2 requestIdentity field: 8 grantIdentity field: 8 grantMACsecAbility field: 2

[0141] The TLV type field of the second management message is used to indicate that the message is used to report the capability information of the second communication device, that is, the message carries the capability information of the second communication device.

[0142] In one example, taking the grantMACsecAbility field as an example, when the grantMACsecAbility field includes 2 bytes (i.e., 16 bits), one of the 16 bits can be used to indicate whether encryption and decryption processing of the message is supported (for example, when the value of this bit is 0, it indicates not supported, and when the value of this bit is 1, it indicates support), and the remaining 15 bits can be reserved bits.

[0143] It is understandable that the above S505 is an optional step, that is, the second communication device can send capability information to the first communication device according to the request information, or the second communication device can also actively send capability information to the first communication device, which is not specifically limited.

[0144] S507 , the first communication device sends notification information to the second communication device, where the notification information is used to notify the second communication device to start encryption and decryption processing of the PTP message; accordingly, the second communication device receives the notification information.

[0145] Exemplarily, the first communication device may send a third management message to the second communication device, where the third management message includes notification information. For example, the third management message may include a TLV type field, a TLV length field, a requesting device identification field, and an encryption and decryption capability field (denoted as a MACsecAbility field). The TLV type field, the TLV length field, and the requesting device identification field may refer to the description above, and the MACsec capability field is used to carry the notification information.

[0146] Table 3 shows an example of fields included in the third management message.

[0147] Table 3: Example of fields included in the third management message

[0148] The second management message includes the following fields: Number of bytes occupied by the field: TLV type: 2 TLV length: 2 RequestIdentity field: 8 MACsecAbility field: 2

[0149] The TLV type field of the third management message is used to indicate that the message is used to notify the second communication device to start encryption and decryption processing of the PTP message.

[0150] For example, after the second communication device receives the notification information, the first communication device and the second communication device can perform an encryption and decryption negotiation process, such as using the MKA key negotiation protocol to negotiate and calculate the SAK and supporting parameter information for encrypting and decrypting the message. Specific implementations can refer to the description in existing protocols (such as IEEE 802.1x) or future evolution versions of such existing protocols.

[0151] It can be understood that: (1) the above S505 to S507 are optional steps. For example, as the functions of the communication devices evolve, when all the communication devices in the communication system support the encryption and decryption processing of the message, the first communication device can assume that both the first communication device and the second communication device support the encryption and decryption processing of the message, and there is no need to execute the above S505 to S507. In the actual networking scenario, if some communication devices support the encryption and decryption processing of the message, while some communication devices do not support the encryption and decryption processing of the message, the above S505 to S507 can be executed so that the two communication devices transmitting the message first negotiate whether to support the encryption and decryption processing of the message; when the first communication device (i.e., the master node) determines that the first communication device supports the encryption and decryption processing of the message, and the second communication device (i.e., the slave node) also supports the encryption and decryption processing of the message, it can notify the second communication device to start the encryption and decryption processing of the message, and then the first communication device and the second communication device can transmit the message in ciphertext, thereby improving the security of the message transmission.

[0152] (2) In the embodiments of the present application, the encryption and decryption of clock synchronization messages is described as an example. If management messages are transmitted during the clock synchronization process, the management messages may also be encrypted and decrypted to ensure security. That is, the first communication device and the second communication device negotiate through S505 to S507 (the management messages transmitted during the negotiation process are not encrypted and decrypted). After the negotiation is completed, the first communication device and the second communication device may encrypt and decrypt the PTP messages (including clock synchronization messages and management messages) transmitted between them.

[0153] Example 2

[0154] Based on the description of FIG. 3 above, as a possible implementation, taking the first communication device as an example, the first communication device encrypting the message in Embodiment 1 may refer to the MAC layer function module of the first communication device encrypting the clock synchronization message. In this case, taking the first communication device as the sender of the message as an example, the MAC layer function module of the first communication device encrypts the message and then transmits the encrypted message to the physical layer function module, which then transmits it to the second communication device. However, since the message is encrypted, the timestamp function module cannot identify whether the message is a first type message, resulting in an inability to determine whether to stamp the message, affecting the implementation of the stamping process.

[0155] To solve this problem, a possible solution is provided in Example 2 of the present application, which is described below in conjunction with Figure 6.

[0156] FIG6 is a flow chart of a communication method according to an embodiment of the present invention. As shown in FIG6 , the communication method may include:

[0157] S601: A first functional module of a first communication device sends a first message and indication information of the first message to a second functional module of the first communication device; accordingly, the second functional module receives the first message and indication information of the first message from the first functional module.

[0158] Here, the indication information of the first message indicates that the first message needs to be stamped, or indicates that the type of the first message is the first type. For example, the indication information of the first message includes type information of the first message, and the type information is used to indicate that the type of the first message is the first type; optionally, the indication information of the first message also includes an identifier of the first message, and the identifier of the first message can be a serial number of the first message.

[0159] It can be understood that if the first message is a first type message, the first functional module can send the first message and indication information of the first message to the second functional module; if the first message is not a first type message (for example, the first message is a second type message or a management message), the first functional module can send the first message to the second functional module without sending indication information of the first message.

[0160] S602: The second functional module encrypts the first message to obtain a second message, and sends the second message to the second communication device.

[0161] S603, the second functional module stamps the second message according to the indication information to obtain a first timestamp, and sends the first timestamp to the PTP functional module. The first timestamp is used to indicate the sending time of the first message or the second message; accordingly, the first functional module receives the first timestamp from the second functional module.

[0162] With respect to S602 and S603 above, a possible implementation is as follows: the MAC layer function module 1 in the second function module encrypts the first message to obtain the second message, and sends the second message and indication information of the first message to the timestamp function module 1. Accordingly, after receiving the second message and the indication information of the first message, the timestamp function module 1 can stamp the second message according to the indication information to obtain the first timestamp, and send the first timestamp to the first function module; optionally, if the indication information of the first message includes the identifier of the first message, the timestamp function module 1 can also send the identifier of the first message to the first function module so that the first function module can determine that the first timestamp indicates the sending time of the first message. Furthermore, the timestamp function module 1 sends the second message to the physical layer function module 1 so that the physical layer function module 1 can send the second message to the second communication device.

[0163] Optionally, after receiving the first timestamp, the first functional module of the first communication device may send the first timestamp to the second communication device.

[0164] S604: After the second communication device receives the second message, the third functional module of the second communication device stamps the second message to obtain a second timestamp, where the second timestamp is used to indicate the reception time of the second message.

[0165] S605: The third functional module of the second communication device decrypts the second message to obtain a first message.

[0166] S606: When the type of the first message is the first type, the third functional module sends the first message and the second timestamp to the fourth functional module of the second communication device.

[0167] Regarding S604 to S606 above, one possible implementation is as follows: Physical layer function module 2 in the third function module receives the second message from the first communication device, sends the second message to timestamp function module 2, timestamp function module 2 stamps the second message to obtain a second timestamp, and sends the second message and the second timestamp to MAC layer function module 2 in the third function module; after receiving the second message and the second timestamp, MAC layer function module 2 decrypts the second message to obtain the first message. Furthermore, MAC layer function module 2 can identify whether the type of the first message is the first type, and if so, can send the first message and the second timestamp to the fourth function module.

[0168] Optionally, if the MAC layer function module 2 identifies that the first message is not a message of the first type, the first message may be sent to the fourth function module and the second timestamp may be discarded.

[0169] In an example, the first message may be a synchronization message, the first timestamp may be the timestamp T1 mentioned above, and the second timestamp may be the timestamp T2 mentioned above.

[0170] Optionally, the above method further includes:

[0171] S607 , the second functional module of the first communication device sends a second request message to the first functional module, where the second request message is used to request to start encryption and decryption processing of the message; accordingly, the first functional module receives the second request message.

[0172] S608: The first functional module sends first request information to the second communication device according to the second request information, where the first request information is used to request capability information of the second communication device.

[0173] It is understandable that the above S607 is an optional step, that is, the first functional module may send the first request information to the second communication device according to the second request information; or the first functional module may actively send the first request information to the second communication device.

[0174] S609: The fourth functional module of the second communication device sends the capability information of the second communication device to the first communication device according to the first request information.

[0175] S610: The first functional module of the first communication device receives capability information of the second communication device and sends first notification information to the second communication device. The first notification information is used to notify the second communication device to start encryption and decryption processing of the message.

[0176] Exemplarily, after the first functional module of the first communication device receives the capability information of the second communication device, if it is determined that both the first communication device and the second communication device support message encryption and decryption processing, it can determine to initiate message encryption and decryption processing and send a first notification message to the fourth functional module of the second communication device; after receiving the first notification message, the fourth functional module can send a second notification message to the third functional module, and the second notification message is used to notify the third functional module to initiate message encryption and decryption processing. Optionally, the first functional module can also send a third notification message to the second functional module, and the third notification message is used to notify the second functional module to initiate message encryption and decryption processing. Furthermore, the second functional module of the first communication device and the third functional module of the second communication device can execute an encryption and decryption negotiation process to subsequently encrypt and decrypt the message.

[0177] Using the above method, from the perspective of the sender of the clock synchronization message, since the first functional module in the sender can send the message and message indication information to the second functional module, after the MAC functional module in the second functional module encrypts the message, the timestamp functional module in the second functional module can stamp the message based on the indication information. From the perspective of the message receiver, the timestamp functional module in the third functional module can stamp all received messages. After the MAC functional module in the third functional module decrypts the message, if the message is a first type message, the message and timestamp are sent to the fourth functional module. In this way, the first type message can be timestamped while the message is being encrypted and decrypted, facilitating time synchronization between the first communication device and the second communication device.

[0178] With respect to the above-mentioned embodiment 1 and embodiment 2, it can be understood that:

[0179] (1) The above description focuses on the differences between Example 1 and Example 2. Except for the differences, Example 1 and Example 2 can refer to each other. In addition, in the same embodiment, different implementations or different examples can also refer to each other.

[0180] (2) The step numbers in the flowcharts described in Example 1 and Example 2 are merely examples of the execution process and do not limit the order in which the steps are executed. In the embodiments of the present application, there is no strict execution order between the steps that have no temporal dependencies. Not all of the steps shown in the flowcharts are mandatory steps. Some steps may be deleted from each flowchart as needed, or other possible steps may be added to each flowchart as needed.

[0181] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the interaction between the first communication device and the second communication device. It can be understood that in order to implement the above functions, the first communication device and the second communication device may include hardware structures and / or software modules corresponding to the execution of each function. It should be easily appreciated by those skilled in the art that, in combination with the units and algorithm steps of the various examples described in the embodiments disclosed herein, the embodiments of the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in a hardware or computer software driven hardware manner depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0182] In the embodiments of the present application, the first communication device and the second communication device may be divided into functional units according to the above method examples. For example, the functional units may be divided into corresponding functional units, or two or more functions may be integrated into one unit. The above integrated unit may be implemented in the form of hardware or software functional units.

[0183] Figure 7 shows a possible exemplary block diagram of the device involved in the embodiments of the present application. As shown in Figure 7, the device 700 may include: a processing unit 702 and a communication unit 703. The processing unit 702 is used to control and manage the actions of the device 700. The communication unit 703 is used to support communication between the device 700 and other devices. Optionally, the communication unit 703 is also called a transceiver unit, and may include a receiving unit and / or a sending unit, which are used to perform receiving and sending operations, respectively. The device 700 may also include a storage unit 701 for storing program code and / or data of the device 700.

[0184] The apparatus 700 may be the first communication apparatus in the above-described embodiment, or may be a component (e.g., a software module, a hardware circuit or chip, or a combination of a software module and a hardware circuit or chip) provided in the first communication apparatus. The processing unit 702 may support the apparatus 700 in executing the actions of the first communication apparatus in each of the above-described method examples. Alternatively, the processing unit 702 may primarily execute the internal actions of the first communication apparatus in the method examples, and the communication unit 703 may support communication between the apparatus 700 and other devices.

[0185] For example, in one embodiment, the processing unit 702 is used to encrypt the first message to obtain a second message; the communication unit 703 is used to send the second message and a first timestamp, where the first timestamp is used to indicate the sending time of the second message.

[0186] The apparatus 700 may be the second communication apparatus in the above-described embodiments, or may be a component (e.g., a software module, a hardware circuit or chip, or a combination of a software module and a hardware circuit or chip) provided in the second communication apparatus. The processing unit 702 may support the apparatus 700 in executing the actions of the second communication apparatus in each of the above-described method examples. Alternatively, the processing unit 702 may primarily execute the internal actions of the second communication apparatus in the method examples, and the communication unit 703 may support communication between the apparatus 700 and other devices.

[0187] In one embodiment, the communication unit 703 is configured to receive a second message and a first timestamp, where the first timestamp indicates a sending time of the second message; and the processing unit 702 is configured to decrypt the second message to obtain a first message.

[0188] It should be understood that the division of units in the above device is merely a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. Moreover, the units in the device can all be implemented in the form of software calling through processing elements; or they can all be implemented in the form of hardware; or some units can be implemented in the form of software calling through processing elements, and some units can be implemented in the form of hardware. For example, each unit can be a separately established processing element, or it can be integrated into a certain chip of the device. In addition, it can also be stored in the memory in the form of a program, called by a certain processing element of the device and execute the function of the unit. In addition, all or part of these units can be integrated together, or they can be implemented independently. The processing element described here can also be a processor, which can be an integrated circuit with signal processing capabilities. In the implementation process, each operation of the above method or each unit above can be implemented by the integrated logic circuit of the hardware in the processor element or in the form of software calling through the processing element.

[0189] In one example, the unit in any of the above devices may be one or more integrated circuits configured to implement the above method, such as one or more application specific integrated circuits (ASICs), one or more digital singnal processors (DSPs), one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. For another example, when the unit in the device can be implemented in the form of a processing element scheduler, the processing element can be a processor, such as a general-purpose central processing unit (CPU), or other processor that can call a program. For another example, these units can be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0190] The above-mentioned receiving unit is an interface circuit of the device, which is used to receive signals from other devices. For example, when the device is implemented as a chip, the receiving unit is the interface circuit of the chip used to receive signals from other chips or devices. The above-mentioned sending unit is an interface circuit of the device, which is used to send signals to other devices. For example, when the device is implemented as a chip, the sending unit is the interface circuit of the chip used to send signals to other chips or devices.

[0191] Referring to FIG8 , which is a schematic structural diagram of a communication device provided in an embodiment of the present application, for implementing the operation of the first communication device in the above embodiment.

[0192] As shown in Figure 8, the communication device 800 may include a processor 801, a memory 802, and an interface circuit 803. The processor 801 may be used to process the communication protocol and communication data, and to control the communication device 800. The memory 802 may be used to store programs and data, and the processor 801 may execute the method performed by the first communication device in the embodiment of the present application based on the program. The interface circuit 803 may be used for the communication device 800 to communicate with other devices. The communication may be wired or wireless, and the interface circuit may also be replaced by a transceiver.

[0193] The memory 802 may also be externally connected to the communication device 800. In this case, the communication device 800 may include an interface circuit 803 and a processor 801. The interface circuit 803 may also be externally connected to the communication device 800. In this case, the communication device 800 may include the memory 802 and the processor 801. When both the interface circuit 803 and the memory 802 are externally connected to the communication device 800, the communication device 800 may include the processor 801.

[0194] The communication device shown in FIG8 is capable of implementing the various processes related to the first communication device in the above-described method embodiment. The operations and / or functions of the various modules in the communication device shown in FIG8 are respectively for implementing the corresponding processes in the above-described method embodiment. For details, please refer to the description of the above-described method embodiment; to avoid repetition, detailed descriptions are omitted here.

[0195] Referring to FIG9 , which is a schematic structural diagram of a communication device provided in an embodiment of the present application, used to implement the operation of the second communication device in the above embodiment.

[0196] As shown in Figure 9, the communication device 900 may include a processor 901, a memory 902, and an interface circuit 903. The processor 901 may be used to process the communication protocol and communication data, and to control the communication device 900. The memory 902 may be used to store programs and data, and the processor 901 may execute the method performed by the second communication device in the embodiment of the present application based on the program. The interface circuit 903 may be used for the communication device 900 to communicate with other devices. The communication may be wired or wireless, and the interface circuit may also be replaced by a transceiver.

[0197] The memory 902 may also be externally connected to the communication device 900, in which case the communication device 900 may include an interface circuit 903 and a processor 901. The interface circuit 903 may also be externally connected to the communication device 900, in which case the communication device 900 may include the memory 902 and the processor 901. When both the interface circuit 903 and the memory 902 are externally connected to the communication device 900, the communication device 900 may include the processor 901.

[0198] The communication device shown in Figure 9 is capable of implementing the various processes involving the second communication device in the aforementioned method embodiment. The operations and / or functions of the various modules in the communication device shown in Figure 9 are for implementing the corresponding processes in the aforementioned method embodiment. For details, please refer to the description of the aforementioned method embodiment; to avoid repetition, detailed descriptions are omitted here.

[0199] The terms "system" and "network" in the embodiments of the present application can be used interchangeably. "At least one" refers to one or more, and "plurality" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of A, B or C" includes A, B, C, AB, AC, BC or ABC, and "at least one of A, B and C" can also be understood to include A, B, C, AB, AC, BC or ABC. And, unless otherwise specified, the ordinal numbers such as "first" and "second" mentioned in the embodiments of the present application are used to distinguish multiple objects and are not used to limit the order, timing, priority or importance of multiple objects.

[0200] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, optical storage, etc.) that contain computer-usable program code.

[0201] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or box in the flow chart and / or block diagram, as well as the combination of the flow chart and / or box in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more flow charts and / or one or more boxes in the block diagram.

[0202] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0203] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0204] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A communication method, characterized in that: The method is applied to a first communication device side, and the method includes: receiving capability information, where the capability information is used to indicate that the second communication device supports encryption and decryption processing of the first message; Encrypting the first message to obtain a second message; The second message and a first timestamp are sent, where the first timestamp is used to indicate a sending time of the second message.

2. The method according to claim 1, characterized in that The type of the first message is the first type.

3. The method according to claim 2, characterized in that The method further comprises: encrypting the third message to obtain a fourth message; The fourth message is sent, and the type of the third message is the second type.

4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: Notification information is sent, where the notification information is used to notify the second communication device to start encryption and decryption processing of the message.

5. The method according to any one of claims 1 to 4, characterized in that The method further comprises: Sending request information, where the request information is used to request capability information of the second communication device.

6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: Determine whether the first communication device supports encryption and decryption processing of the message.

7. A communication method, characterized in that: The method is applied to the second communication device side, and the method includes: Sending capability information, where the capability information is used to indicate that the second communication device supports encryption and decryption processing of the first message; receiving a second message and a first timestamp, where the first timestamp is used to indicate a sending time of the second message; The second message is decrypted to obtain the first message.

8. The method according to claim 7, characterized in that The type of the first message is the first type.

9. The method according to claim 7 or 8, characterized in that The method further comprises: The second message is stamped to obtain a second timestamp, where the second timestamp is used to indicate a reception time of the second message.

10. The method according to any one of claims 7 to 9, characterized in that: The method further comprises: receiving a fourth message; The fourth message is decrypted to obtain a third message, where the type of the third message is the second type.

11. The method according to claim 10, characterized in that The method further comprises: Stamping the fourth message to obtain a third timestamp, where the third timestamp is used to indicate a reception time of the fourth message; After determining that the type of the third message is the second type, discard the third timestamp.

12. The method according to any one of claims 7 to 11, characterized in that The method further comprises: Notification information is received, where the notification information is used to notify the second communication device to start encryption and decryption processing of the message.

13. The method according to any one of claims 7 to 12, characterized in that The method further comprises: Receive request information, where the request information is used to request capability information of the second communication device.

14. A communication method, characterized in that: The method is applied to a first functional module side of a first communication device, and the method includes: Sending a first message and indication information of the first message, where the indication information is used to indicate that the first message needs to be stamped; A first timestamp is received, where the first timestamp is used to indicate a sending time of the first message.

15. A communication method, characterized in that: The method is applied to the second functional module side of the first communication device, and the method includes: receiving a first message and indication information of the first message, wherein the indication information indicates that a stamping process needs to be performed on the first message; encrypting the first message to obtain a second message, and sending the second message; The second message is stamped to obtain a first timestamp, and the first timestamp is sent, where the first timestamp is used to indicate the sending time of the second message.

16. A communication method, characterized in that: The method is applied to the third functional module side of the second communication device, and the method includes: receiving a second message; Stamping the second message to obtain a second timestamp, where the second timestamp is used to indicate a reception time of the second message; Decrypting the second message to obtain a first message; Send the first message and the second timestamp.

17. A communication device, characterized in that: The method comprises a unit for implementing the method according to any one of claims 1 to 6.

18. A communication device, characterized in that: The method comprises a processor coupled to a memory, and the processor is configured to implement the method according to any one of claims 1 to 6.

19. A communication device, characterized in that: The method comprises means for implementing the method according to any one of claims 7 to 13.

20. A communication device, characterized in that: The method comprises a processor coupled to a memory, and the processor is configured to implement the method according to any one of claims 7 to 13.

21. A communication system, characterized in that: Includes the communication device according to claim 17 or 18, and the communication device according to claim 19 or 20.

22. A communication device, characterized in that: The device comprises means for implementing the method of claim 14.

23. A communication device, characterized in that: The device comprises a processor coupled to a memory, and the processor is configured to implement the method according to claim 14.

24. A communication device, characterized in that: The device comprises means for implementing the method of claim 15.

25. A communication device, characterized in that: The device comprises a processor coupled to a memory, and the processor is configured to implement the method according to claim 15 .

26. A communication device, characterized in that: The method comprises means for implementing the method of claim 16.

27. A communication device, characterized in that: The device comprises a processor coupled to a memory, and the processor is configured to implement the method according to claim 16.

28. A communication system, characterized in that: comprising the communication device according to claim 22 or 23, and the communication device according to claim 24 or 25; or, The communication device comprises the communication device according to claim 22 or 23, the communication device according to claim 24 or 25, and the communication device according to claim 26 or 27.

29. A computer-readable storage medium, characterized in that The storage medium stores a computer program or instruction. When the computer program or instruction is executed by a computer, the method according to any one of claims 1 to 16 is implemented.

30. A computer program product, characterized in that When a computer reads and executes the computer program product, the computer is caused to perform the method according to any one of claims 1 to 16.