Communication method and device

CN121264079APending Publication Date: 2026-01-02HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380099173.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-06-16
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

In the existing communication technology, the maintenance and management of keys are complex and easily exploited by non-target receiving nodes, resulting in reduced message security, especially those messages transmitted before key negotiation cannot effectively guarantee their security.

Method used

By safely processing and reordering message packets, errors are spread to multiple packets, thereby improving the security of messages and using fixed sequences to avoid error spread when decoding fails, ensuring communication quality and security.

Benefits of technology

It effectively improves the security of messages at non-target receiving nodes, avoids errors spreading between different message packets, and enhances the security and reliability of the communication system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121264079A_ABST
    Figure CN121264079A_ABST
Patent Text Reader

Abstract

The invention discloses a communication method and device. The method comprises: a first device performing security processing on q first message packets to obtain q second message packets; after the q second message packets are reordered, the first device can perform security processing on the reordered q second message packets to obtain q third message packets. The first device may then transmit q signals, the q signals being obtained from the q third message packets. Through the method, errors can be diffused in a plurality of message groups as far as possible at a non-target receiving node, so that the security of messages is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and device Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a communication method and device. Background Art

[0002] Secure transmission is the foundation of communication. Currently, most secure transmission solutions are key-based. Examples include symmetric and asymmetric encryption. In symmetric encryption, both communicating parties share a key and use it to encrypt and decrypt messages. In asymmetric encryption, one party sends a public key to the other. The sender uses the public key to encrypt the message, and the receiver uses the private key corresponding to the public key to decrypt the message. Regardless of the encryption scheme used, both parties must maintain and manage the key. Because key maintenance and management require complex protocol support, protocol vulnerabilities can often be exploited by unintended receiving nodes, compromising message security.

[0003] In addition, some messages are transmitted before key negotiation, so a key-based secure transmission scheme cannot be used for these messages, which reduces the security of these messages.

[0004] Summary of the Invention

[0005] The present application provides a communication method and apparatus to improve message security.

[0006] In a first aspect, embodiments of the present application provide a communication method. The method may be performed by a first apparatus. The first apparatus may be an access network device or a terminal device, or may be a device configured in the access network device or the terminal device, and this application does not limit this.

[0007] The method includes: a first device securely processing q first message packets to obtain q second message packets, where q is an integer greater than or equal to 1. After reordering the q second message packets, the first device may securely process the reordered q second message packets to obtain q third message packets, and transmit q signals, wherein the q signals are obtained based on the q third message packets.

[0008] With this method, after performing a first security processing on the q first message packets, the first device can reorder the resulting q second message packets and perform a second security processing on the reordered q second message packets. This allows errors at non-target receiving nodes to be spread across multiple message packets as much as possible, thereby improving message security.

[0009] In one possible design, the first device can reorder the q second message packets by arranging them in reverse order. In this way, at a non-target receiving node, an error in each message packet can be diffused to any of the q message packets, thereby improving message security.

[0010] In one possible design, the first device may further obtain a message to be transmitted, where the message to be transmitted includes q first message packets. In this way, errors at non-target receiving nodes can be diffused as much as possible across multiple message packets in the message to be transmitted, thereby improving message security.

[0011] In one possible design, the first device may transmit q signals after receiving q third message packets. Alternatively, the first device may transmit the ath signal among q signals after receiving the ath third message packet among q third message packets, where the ath signal is obtained based on the ath third message packet, and a is any positive integer from 1 to q. This design is relatively flexible to implement.

[0012] In one possible design, when it is determined that the receiving end has failed to decode the a-1th signal among q signals, and a is greater than or equal to 2 and less than or equal to q, the first device may securely process the ath second message packet according to a fixed sequence to obtain the ath third message packet. With this design, when signal decoding fails, the first device securely processes subsequent message packets based on the fixed sequence, thereby avoiding security processing of subsequent message packets based on the signal that failed decoding, and further preventing errors corresponding to the signal that failed decoding from propagating to the second device. This improves message security while ensuring the quality of communication between the first and second devices.

[0013] In one possible design, the first device may securely process the ath second message packet according to a fixed sequence in one of the following ways to obtain the ath third message packet:

[0014] Method 1: The first device sets the a-1th second message packet among the reordered q second message packets as a fixed sequence and determines a first random seed based on the fixed sequence. The first device then performs a calculation on the first random seed and the ath second message packet to complete security processing and obtain the ath third message packet. Method 1 prevents the propagation of errors between different message packets at the second device.

[0015] Method 2: The first device sets the first random seed to a fixed sequence and performs a calculation on the fixed sequence and the a-th second message packet to complete security processing and obtain the a-th third message packet. This method can prevent errors from propagating between different message packets at the second device.

[0016] In one possible design, a first device may obtain a message to be transmitted, where the message to be transmitted includes K message packet sets, and the i-th message packet set among the K message packet sets includes q first message packets, where K is an integer greater than or equal to 2, and i is any positive integer from 1 to K. With this design, the first device divides the message to be transmitted into multiple sets and adjusts the number of message packets included in each set, thereby balancing transmission reliability and security. Furthermore, in this design, the first device only needs to cache the q second message packets corresponding to one set, rather than all second message packets corresponding to the message to be transmitted, thereby reducing cache overhead.

[0017] In one possible design, the first initial random seed is used to securely process the q first message packets and / or the reordered q second message packets corresponding to the i-th message packet set.

[0018] In some examples, the first initial random seed is a set random seed. This allows errors to be diffused within each set, preventing errors in one set from propagating to another set. This improves message security while ensuring communication performance between the second device and the first device.

[0019] In other examples, when i is 1, or when i is greater than 1 and it is determined that the receiving end has failed to decode one or more signals corresponding to the i-1th message packet set, the first initial random seed is a set random seed; and / or, when i is greater than 1 and it is determined that the receiving end has successfully decoded all signals corresponding to the i-1th message packet set, the first initial random seed is a random seed obtained based on the i-1th message packet set. In this way, when the second device successfully decodes all signals corresponding to a message packet set, the message packet set can be used for security processing of subsequent message packet sets, thereby avoiding security processing based on message packet sets that failed decoding, and further preventing errors corresponding to signals that failed decoding from spreading between different sets, thereby improving message security while ensuring the communication quality between the first device and the second device.

[0020] In one possible design, when the first initial random seed is used to securely process q first message packets corresponding to the i-th message packet set, the first initial random seed is a random seed obtained based on the i-1th message packet set, including: securely processing the last first message packet in the i-1th message packet set to obtain the first initial random seed; and / or, when the first initial random seed is used to securely process q reordered second message packets corresponding to the i-th message packet set, the first initial random seed is a random seed obtained based on the i-1th message packet set, including: securely processing the last reordered second message packet corresponding to the i-1th message packet set to obtain the first initial random seed. Through this design, the first device can quickly obtain the first initial random seed, thereby improving the speed and efficiency of processing message packets.

[0021] In one possible design, when it is determined that the receiving end has failed to decode the ath signal among q signals, the first device may resend the ath signal until the receiving end successfully decodes the ath signal, or until the number of transmissions of the ath signal reaches a threshold, where a is any positive integer between 1 and q. This design can improve the performance of the second device in receiving signals.

[0022] In one possible design, the ath second message group among the q second message groups is obtained by securely processing the ath first message group among the q first message groups; the ath third message group among the q third message groups is obtained by securely processing the ath second message group among the reordered q second message groups; the ath signal among the q signals is obtained based on the ath third message group among the q third message groups; and a is any positive integer from 1 to q.

[0023] In a second aspect, embodiments of the present application provide a communication method. This method may be performed by a second device. The second device may be an access network device or a terminal device, or may be a device configured in the access network device or the terminal device, which is not limited in this application.

[0024] The method includes: a second device receiving q signals and obtaining q third message packets based on the q signals, wherein q is an integer greater than or equal to 1. The second device may perform a secure inverse process on the q third message packets to obtain q second message packets. After reordering the q second message packets, the second device may perform a secure inverse process on the reordered q second message packets to obtain q first message packets.

[0025] Through this method, after the second device performs a first secure inverse process on the q third message packets, it can reorder the resulting q second message packets and perform a second secure inverse process on the reordered q second message packets. This allows errors to be spread across multiple message packets as much as possible at non-target receiving nodes, while preventing errors from spreading across multiple message packets at the second device. This improves message security while maintaining communication quality between the first and second devices.

[0026] In one possible design, the second device may arrange the q second message packets in reverse order, thereby reordering the q second message packets. In this way, at a non-target receiving node, an error in each message packet can be diffused to any of the q message packets, thereby improving message security.

[0027] In one possible design, the second device may receive a first message including q signals. In this way, errors at non-target receiving nodes may be diffused as much as possible among multiple message packets in the message to be transmitted, thereby improving message security.

[0028] In one possible design, after receiving q signals, the second device may obtain q third message packets based on the q signals. Alternatively, after receiving the ath signal among the q signals, the second device may obtain the ath third message packet among the q third message packets based on the ath signal, where a is any positive integer from 1 to q. This design is relatively flexible in implementation.

[0029] In one possible design, when the receiving end fails to decode the a-1th signal among q signals, the second device can perform secure inverse processing on the ath third message packet based on a fixed sequence to obtain the ath second message packet. With this design, when signal decoding fails, the second device performs secure inverse processing on subsequent message packets based on the fixed sequence, thereby avoiding performing secure inverse processing on subsequent message packets based on the signal that failed decoding. This further prevents the error corresponding to the signal that failed decoding from propagating to the second device, thereby improving message security while ensuring the communication quality between the first and second devices.

[0030] In one possible design, the second device may perform secure inverse processing on the ath third message packet according to a fixed sequence in one of the following ways to obtain the ath second message packet:

[0031] Method 1: The second device can set the a-1th second message group among the q second message groups as a fixed sequence and determine a second random seed based on the fixed sequence. The second device can then perform a secure inverse operation on the second random seed and the ath third message group to obtain the ath second message group. Method 1 prevents errors from propagating between different message groups at the second device.

[0032] Method 2: The second device sets the second random seed to a fixed sequence and performs a calculation on the ath third message packet, completing the secure inverse process to obtain the ath second message packet. This method prevents errors from propagating between different message packets at the second device.

[0033] In one possible design, the second device receives a second message, where the second message includes K signal sets, where the i-th signal set among the K signal sets includes q signals, where K is an integer greater than or equal to 2, and i ranges from 1 to K. With this design, the transmitted message may include multiple sets, and by adjusting the number of signals included in each set, transmission reliability and security may be balanced.

[0034] In one possible design, the second initial random seed is used to perform secure inverse processing on the q third message packets corresponding to the i-th signal set and / or the q reordered second message packets.

[0035] In some examples, the second initial random seed is a set random seed. This allows errors to be diffused within each set, preventing errors in one set from spreading to another set. This improves message security while ensuring communication performance between the second device and the first device.

[0036] In other examples, when i is 1, or when i is greater than 1 and decoding of one or more signals in the i-1th signal set fails, the second initial random seed is a set random seed; and / or, when i is greater than 1 and decoding of all signals in the i-1th signal set is successful, the second initial random seed is a random seed obtained based on the i-1th signal set. In this way, when the second device successfully decodes all signals corresponding to a message group set, the message group set can be used for secure inverse processing of subsequent message group sets, thereby avoiding secure inverse processing based on message group sets that failed decoding, and further preventing errors corresponding to signals that failed decoding from spreading between different sets, thereby improving message security while ensuring the communication quality between the first device and the second device.

[0037] In one possible design, when the second initial random seed is used to perform secure inverse processing on the q third message packets corresponding to the i-th signal set, the second initial random seed is a random seed obtained based on the i-1th signal set, including: performing secure inverse processing on the last third message packet corresponding to the i-1th signal set to obtain the second initial random seed; and / or, when the second initial random seed is used to perform secure inverse processing on the q reordered second message packets corresponding to the i-th signal set, the second initial random seed is a random seed obtained based on the i-1th signal set, including: performing secure inverse processing on the last reordered second message packet corresponding to the i-1th signal set to obtain the second initial random seed. Through this design, the first device can quickly obtain the first initial random seed, thereby improving the processing speed and efficiency of the message packets.

[0038] In one possible design, the ath third message group among q third message groups is obtained based on the ath signal among q signals; the ath second message group among q second message groups is obtained by securely inverting the ath third message group among q third message groups; the ath first message group among q first message groups is obtained by securely inverting the ath second message group among the reordered q second message groups; and a is any positive integer from 1 to q.

[0039] In a third aspect, an embodiment of the present application provides a communication device, comprising a unit for executing each step in any of the above aspects.

[0040] In a fourth aspect, an embodiment of the present application provides a communication device, including a processor, which is used to execute the methods described in the above aspects.

[0041] Optionally, the device may further include a memory for storing instructions and data. The memory is coupled to the processor, and when the processor executes the instructions stored in the memory, the methods described in the above aspects may be implemented.

[0042] In a fifth aspect, an embodiment of the present application provides a communication system, comprising: a first device for executing the method provided in the first aspect, and a second device for executing the method provided in the second aspect.

[0043] In a sixth aspect, an embodiment of the present application further provides a computer program product comprising computer executable instructions, which, when run, enables some or all of the steps of the method described in any of the above aspects to be executed.

[0044] In the seventh aspect, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a computer, the computer executes the method provided in any of the above aspects.

[0045] In an eighth aspect, an embodiment of the present application further provides a chip, which is used to read a computer program stored in a memory and execute the method provided in any of the above aspects.

[0046] Ninthly, embodiments of the present application further provide a chip system, comprising a processor configured to support a computer device in implementing the method provided in any of the above aspects. In one possible design, the chip system further comprises a memory configured to store programs and data necessary for the computer device. The chip system may be composed of a chip alone, or may include a chip and other discrete components.

[0047] The technical effects that can be achieved in any of the third to ninth aspects mentioned above can refer to the description of the technical effects that can be achieved in any possible design in any of the first or second aspects mentioned above, and the repetitions will not be discussed. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] FIG1 is an architecture diagram of a communication system provided in an embodiment of the present application;

[0049] FIG2 is a schematic diagram of a keyless secure transmission architecture provided in an embodiment of the present application;

[0050] FIG3 is a flow chart of a communication method provided in an embodiment of the present application;

[0051] FIG4 is a schematic diagram 1 of a first apparatus performing security processing on a message packet according to an embodiment of the present application;

[0052] FIG5 is a schematic diagram of a randomness extractor according to an embodiment of the present application performing security processing on q first message packets;

[0053] FIG6 is a second schematic diagram of a first apparatus performing security processing on a message group according to an embodiment of the present application;

[0054] FIG7 is a schematic diagram of an effect provided by an embodiment of the present application;

[0055] FIG8 is a third schematic diagram of a first apparatus for securely processing a message packet according to an embodiment of the present application;

[0056] FIG9 is a structural diagram of a communication device provided in an embodiment of the present application;

[0057] FIG10 is a structural diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0058] The technical solutions provided in the embodiments of the present application can be applied to various communication systems, such as: Global System of Mobile communication (GSM) system, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS), Long Term Evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD), Universal Mobile Telecommunications System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication system, fifth generation (5G) mobile communication system or new radio (NR), wireless local area network (WLAN) system, wireless fidelity (WiFi) system, sixth generation (6G) communication system and future communication systems. Among them, the 5G mobile communication system can be a non-standalone (NSA) or an independent network (SA).

[0059] The technical solution provided in this application can also be applied to machine type communication (MTC), long term evolution-machine (LTE-M), device-to-device (D2D) network, machine-to-machine (M2M) network, Internet of Things (IoT) network or other networks. Among them, the IoT network can include, for example, the Internet of Vehicles. Among them, the communication mode in the Internet of Vehicles system is collectively referred to as vehicle to other devices (vehicle to X, V2X, X can represent anything), for example, the V2X can include: vehicle to vehicle (V2V) communication, vehicle to infrastructure (V2I) communication, vehicle to pedestrian (V2P) communication or vehicle to network (V2N) communication, etc.

[0060] Figure 1 shows an architecture diagram of a communication system applicable to an embodiment of the present application. As shown in Figure 1, the communication system may include a terminal device and an access network device.

[0061] Terminal devices, also known as user equipment (UE), mobile stations (MS), and mobile terminals (MT), are devices that include wireless communication capabilities (providing voice / data connectivity to users). For example, they include handheld devices or vehicle-mounted devices with wireless connectivity. Currently, some examples of terminal devices include: mobile phones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in the Internet of Vehicles (IoV), wireless terminals in self-driving systems, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, and wireless terminals in smart homes. For example, wireless terminals in the IoV can be vehicle-mounted devices, complete vehicle equipment, vehicle-mounted modules, vehicles, etc. Wireless terminals in industrial control can be cameras, robots, etc. Wireless terminals in smart homes can be TVs, air conditioners, sweepers, speakers, set-top boxes, etc.

[0062] Access network equipment is a device in a wireless network, such as a radio access network (RAN) node or radio access network device that connects a terminal device to the wireless network. Currently, some examples of access network equipment include: next-generation base stations (gNodeBs, gNBs) in 5G, transmission reception points (TRPs), evolved Node Bs (eNBs), radio network controllers (RNCs), Node Bs (NBs), base station controllers (BSCs), base transceiver stations (BTSs), home base stations (e.g., home evolved NodeBs, or home Node Bs, HNBs), base band units (BBUs), wireless fidelity (Wi-Fi) access points (APs), and integrated access and backhaul (IABs). In some implementations, the access network equipment may also be access network equipment in future communication systems (e.g., 6G communication systems).

[0063] In a network structure, the access network equipment may also refer to a centralized unit (CU), a distributed unit (DU), or the access network equipment may also include a CU and a DU. The CU and the DU are set separately, or they may be included in the same network element, for example, the BBU. The CU and the DU can be understood as a division of the access network equipment from a logical functional perspective. The CU and the DU are connected via the F1 interface; the CU may represent the gNB and is connected to the core network via the NG interface. Among them, the CU and the DU may be physically separated or deployed together, and this embodiment of the present application does not specifically limit this. One CU can be connected to one DU, or multiple DUs can share one CU, which can save costs and facilitate network expansion. The CU and DU can be divided according to the protocol stack. One possible way is to deploy the radio resource control (RRC) layer, the service data adaptation protocol stack (SDAP) layer, and the packet data convergence protocol (PDCP) layer in the CU, and the remaining radio link control (RLC) layer, the media access control (MAC) layer, and the physical layer (PHY) in the DU. The embodiment of the present application is not limited to the above-mentioned protocol stack division method, and other division methods may also be used.

[0064] In addition, the access network device may also be a radio unit (RU, etc.). The RU may be included in a radio frequency device or radio frequency unit, for example, a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).

[0065] CU, DU, or RU may have different names in different systems, but those skilled in the art will understand their meanings. For example, in an open radio access network (O-RAN) system, the CU may be referred to as an O-CU (Open CU), the DU may be referred to as an O-DU (Open DU), and the RU may be referred to as an O-RU (Open RU).

[0066] In an embodiment of the present application, the communication device used to implement the function of the access network device or terminal device may be the access network device or terminal device itself, or it may be a device that can support the access network device or terminal device to implement the function, such as a chip system, which can be installed in the access network device or terminal device.

[0067] It should be understood that FIG1 is only a simplified schematic diagram for ease of understanding, and the communication system may also include other access network devices and / or other terminal devices, which are not shown in FIG1 .

[0068] It should also be understood that the communication system shown in Figure 1 is only an example of an application scenario of an embodiment of the present application. The present application can also be applied to communication between any two devices, for example, communication between terminal devices, and communication between access network devices.

[0069] The terms used in this application are explained below.

[0070] 1. Keyless secure transmission architecture:

[0071] Figure 2 is a schematic diagram of data transmission in a keyless secure transmission architecture. As shown in Figure 2, a first message to be transmitted undergoes preprocessing, sequentially entering the channel coding process, modulation / waveform processing, and multiple input multiple output (MIMO) processing. It is then transmitted from the transmitter to the receiver via a wireless channel. The message received by the receiver undergoes the MIMO process, demodulation / waveform processing, and channel decoding, followed by post-processing to obtain the first message.

[0072] Post-processing is the inverse of pre-processing. Both pre-processing and post-processing can be performed by a security module. On the sending end, the security module is responsible for securely processing the input message; on the receiving end, the security module is responsible for securely reversing the processing of the input message. Optionally, the security module can be a randomness extractor, responsible for extracting randomness from the input message. The randomness extractor can be a hardware device or implemented in software.

[0073] 2. A random seed (also known as random bits, random bit stream, random entropy, or state information) can be used to securely process messages input to the security module, for example, to encrypt or integrity-protect messages input to the security module. Alternatively, the random seed can be used directly to securely process messages input to the security module, or it can be used to generate a key through an algorithm for securely processing messages input to the security module.

[0074] 3. A message packet, also known as a code block or data packet, is part of a message. A message may include one or more message packets. When a message includes a message packet, the message packet is also referred to as a message. Message packets may include, for example, source message packets and encoded code block packets.

[0075] 4. In this application, “when…”, “if…then”, and “if…then” have the same meaning and can be replaced with each other.

[0076] Currently, the security module operates by securely processing multiple message packets based on a random seed. The random seeds corresponding to later message packets are derived from earlier message packets. This allows the channel noise entropy of previous message packets to accumulate across multiple message packets, thereby promoting error diffusion between different message packets and degrading decoding performance at non-target receiving nodes.

[0077] However, if the error occurs in a message packet with a later sequence number, for example, the error occurs in the last message packet, a non-target receiving node may correctly decode most of the message packets, thereby affecting the security of the message.

[0078] On the other hand, the security level that the communication system can achieve and the error floor of the non-target receiving node satisfy the following relationship:

[0079] Among them, λ represents the security level, L represents the length of the message packet, and H ∞ (X|Z) represents the minimum entropy per bit, p e represents the error floor introduced at the target receiving node. From this formula, we can see that there is a positive correlation between the security level and the error floor. If the communication system uses feedback retransmission (such as Hybrid Automatic Repeat Request (HARQ)) mechanism to improve the transmission reliability of the target receiving node, then non-target receiving nodes can also use this mechanism to improve their own error performance and reduce p e , which will lead to insufficient minimum entropy introduced by physical layer security transmission technology at non-target receiving nodes, resulting in a decrease in security level.

[0080] In view of this, an embodiment of the present application provides a communication method, which can be applied to the communication system shown in Figure 1. Referring to the flowchart shown in Figure 3 below, the process of the method is specifically described by taking the transmitting end as the first device and the receiving end as the second device as an example. Among them, the first device can be an access network device or a terminal device, or a device in the access network device for implementing the functions of the access network device (for example, a chip system or module), or a device in the terminal device for implementing the functions of the terminal device (for example, a chip system or module). The second device can be an access network device or a terminal device, or a device in the access network device for implementing the functions of the access network device, or a device in the terminal device for implementing the functions of the terminal device. Optionally, the first device and / or the second device can be a CU or a DU.

[0081] The method includes S301 to S308:

[0082] S301: The first device performs security processing on q first message packets to obtain q second message packets, where q is an integer greater than or equal to 1.

[0083] Optionally, the security processing is implemented by the first security module. In this case, the first device can input q first message packets into the first security module to obtain q second message packets. The first security module is used to perform security processing on the q first message packets. Exemplarily, the first security module is a randomness extractor, and the security processing is a randomness extraction process. For example, as shown in FIG4 , the q first message packets are represented as m1, m2, ..., m q The first security module performs security processing on the q first message packets to obtain q second message packets, which are represented as n1, n2, ..., n q .

[0084] In some possible ways, the ath second message packet n among the q second message packets a , is the ath first message packet m among q first message packets aObtained through security processing, a takes any positive integer from 1 to q. For example, as shown in Figure 5, the first security module is a randomness extractor, and the randomness extractor includes: a bidirectional randomness extractor (BRE), a compressive randomness extractor (CRE) and a one-way randomness extractor (ORE). For the first first message packet m1, the first security module can perform security processing on m1 according to the random seed t0 to obtain the random seed t1 and the first second message packet n1. Among them, the random seed t1 can be obtained according to n1 and the random seed t0, or according to m1 and the random seed t0. When a is greater than or equal to 2, and less than or equal to q, the first security module can obtain the random seed t1 and the first second message packet n1 according to the random seed t0. a-1 To m a Perform security processing and obtain random seed t a and n a Among them, the random seed t a It can be based on n a and random seed t a-1 It can also be obtained based on m a and random seed t a-1 Got it.

[0085] S302: The first device reorders q second message packets.

[0086] In some possible approaches, the first device may reorder the q second message packets according to a first rule. The first rule may be pre-set, determined by the first device or the second device, or configured for the first device or the second device by another device.

[0087] Exemplarily, the first rule is reverse order, that is, the first device can arrange the q second message packets in reverse order. For example, the q second message packets are represented as n1, n2, ..., n q After the first device reorders the q second message packets, the reordered q second message packets are n q ,n q-1 ,…,n1.

[0088] S303: The first device performs security processing on the reordered q second message packets to obtain q third message packets.

[0089] Optionally, the security processing in S303 is implemented by a second security module. In this case, the first device can input the reordered q second message packets into the second security module to obtain q third message packets. The second security module is used to perform security processing on the reordered q second message packets. Exemplarily, the second security module is a randomness extractor, and the security processing is a randomness extraction process. For example, as shown in FIG4 , the reordered q second message packets are represented as n q ,n q-1 ,…,n1; The second security module performs security processing on the reordered q second message packets to obtain q third message packets, which are represented as c1, c2,…, c q .

[0090] In some examples, the second security module and the first security module can be the same module. Thus, after the first device completes S301 and reorders the q second message packets via the first security module, the reordered q second message packets are input to the first security module to execute S303. This example conserves computing resources of the first device.

[0091] In other examples, the second security module and the first security module can be two modules. In this way, while the first device securely processes the reordered q second message packets corresponding to one message through the second security module, it can also securely process the q first message packets corresponding to another message through the first security module, thereby improving message processing efficiency. Furthermore, in this example, the structure of the first device is relatively simple and easy to implement.

[0092] In some possible ways, the ath third message packet c among the q third message packets a , is the ath second message packet (for example, n q-a+1 The specific process of security processing can be referred to S301 and will not be described here in detail.

[0093] S304: The first device sends q signals, and correspondingly, the second device receives q signals, wherein the q signals are obtained based on the q third message groups.

[0094] Among them, the a-th signal x among the q signals a , can be based on the ath third message group c in q third message groups a For example, the ath signal x a It can be the ath third message group c aA signal obtained after performing one or more of a channel coding process, a modulation / waveform process, a MIMO process, and a cyclic redundancy check (CRC) process. Optionally, when q is greater than 1, the first device may simultaneously perform one or more of the channel coding process, the modulation / waveform process, the MIMO process, and the CRC process on multiple third message packets, or may perform one or more of the channel coding process, the modulation / waveform process, the MIMO process, and the CRC process on different third message packets at different times.

[0095] Optionally, the first device may send q signals after obtaining q third message packets; or may send q signals after obtaining a third message packet c. a After that, the ath signal x is sent a That is, each time a signal determined according to a third message group is obtained, the signal is sent.

[0096] S305: The second device obtains q third message groups according to the q signals.

[0097] Among them, the ath third message group c in q third message groups a , can be based on the a-th signal x among the q signals a For example, the ath third message packet c a It can be the a-th signal x a The message packet is obtained after performing one or more of the following processes: CRC check, MIMO process, demodulation / waveform process, and channel decoding process. Optionally, when q is greater than 1, the second device may simultaneously perform one or more of the following processes: CRC check, MIMO process, demodulation / waveform process, and channel decoding process on multiple signals among the q signals, or may perform one or more of the following processes: CRC check, MIMO process, demodulation / waveform process, and channel decoding process on different signals among the q signals at different times.

[0098] Optionally, the second device may obtain q third message packets according to the q signals after receiving the q signals; or may obtain q third message packets after receiving the a-th signal x a After that, according to the a-th signal x a , get the ath third message group c a .

[0099] S306: The second device performs security inverse processing on the q third message packets to obtain q second message packets. If the second device successfully decodes the q signals, the q second message packets obtained by the second device are the q second message packets reordered in S302 and S303. For example, n q ,n q-1 ,…,n1.

[0100] Optionally, in S306, the secure inverse processing is implemented by a third security module. In this case, the second device may input q third message packets into the third security module to obtain q second message packets. The third security module is configured to perform secure inverse processing on the q third message packets. Exemplarily, the third security module is a randomness extractor, and the secure inverse processing is a randomness extraction inverse process.

[0101] In some possible ways, the ath second message packet (eg, n q-a+1 ), is the ath third message group c among q third message groups a Obtained by performing safe inverse processing.

[0102] In this application, the security inverse processing is the inverse processing of the security processing. The content of the security inverse processing of the q third message groups can be referred to the description of "security processing of the reordered q second message groups" in S303, which will not be repeated here.

[0103] S307: The second device reorders the q second message packets in S306.

[0104] Here, S307 can be the reverse operation of S302. Thus, if the second device successfully decodes q signals, the q second message packets after reordering obtained in S307 are the q second message packets before reordering in S302, for example, n1, n2, ..., n q .

[0105] In some possible ways, the second device may reorder the q second message packets in S306 according to a second rule. The second rule may be pre-set, determined by the first device or the second device, or configured for the first device or the second device by another device.

[0106] Exemplarily, the second rule is reverse order, that is, the second device can arrange the q second message groups in reverse order. For example, the q second message groups in S306 are respectively represented as n q ,n q-1 ,…,n1. After the second device reorders the q second message packets, the reordered q second message packets are n1, n2,…,nq .

[0107] S308: The second device performs security inverse processing on the q second message packets reordered in S307 to obtain q first message packets.

[0108] Optionally, in S308, the secure inverse processing is implemented by a fourth security module. In this case, the second device may input the q reordered second message packets in S307 into the fourth security module to obtain q first message packets. The fourth security module is configured to perform the secure inverse processing on the q reordered second message packets. Exemplarily, the fourth security module is a randomness extractor, and the secure inverse processing is the randomness extraction inverse processing.

[0109] In some possible ways, the ath first message packet m among the q first message packets a , is the ath second message packet n among the q second message packets after reordering a Obtained by performing safe inverse processing.

[0110] In this application, the security inverse processing is the inverse processing of the security processing. The content of the security inverse processing of the reordered q second message groups can refer to the description of "security processing of q first message groups to obtain q second message groups" in S301, which will not be repeated here.

[0111] Using the method shown in FIG3 , after performing a first security process on the q first message packets, the first device can reorder the resulting q second message packets and perform a second security process on the reordered q second message packets. This allows errors at non-target receiving nodes to be spread across multiple message packets as much as possible, thereby improving message security.

[0112] In some possible ways, in order to improve the performance of the second device receiving the signal, a retransmission mechanism can be applied to the method shown in FIG3. Specifically, if it is determined that the second device receives the ath signal x a If the decoding result is a decoding failure, the first device may resend the a-th signal x to the second device. a , until the receiving end receives the ath signal x a Decoding is successful, or until the ath signal x is transmitted a The number of times the ath signal x is reached. The number threshold can be pre-set, or determined by the first device or the second device, or configured by other devices for the first device or the second device. a If the decoding result is successful, the second device can decode the a-th signal x a Execute the method in S305 to S308.

[0113] For example, the second device may determine the ath signal x in the following manner: a The second device can decode the a-th signal x a Decode and perform CRC check on the decoded result. If the check succeeds, the second device can determine the ath signal x a1 If the decoding is successful, then the second device can determine the second device's response to the a-th signal x. a Decoding failed.

[0114] When the second device determines the a-th signal x a When the decoding is successful, the second device may send an instruction to the first device to decode the a-th signal x a When the second device determines that the ath signal x a When decoding fails, the second device may send an instruction to the first device to decode the ath signal x a The first device can determine the response information of the decoding failure (eg, non-acknowledgement (NACK)). In this way, the first device can determine the response information of the second device to the a-th signal x a The decoding result of .

[0115] In some possible implementations, the q first message groups in S301 may be all message groups in the message to be transmitted; alternatively, the message groups in the message to be transmitted may be divided into multiple message group sets, with all message groups in each message group set being the q first message groups in S301. This will be described below in conjunction with implementations 1 and 2, respectively.

[0116] Implementation method 1:

[0117] The method shown in Figure 3 also includes: the first device obtains a message to be transmitted, where the message to be transmitted includes q first message packets. In this case, the q first message packets can be all message packets in the message to be transmitted. Accordingly, the first message received by the second device includes q signals. In this way, the first device can perform the methods in S301 to S304 for the q first message packets in the message to be transmitted, and the second device can perform the methods in S304 to S308 for the q signals.

[0118] Exemplarily, as shown in FIG6 , the first device includes a first security module, a first reordering module, and a second security module; the message to be transmitted includes q first message packets, denoted as m1, m2, …, m q The first device sets m1, m2, ..., m qInput to the first security module to obtain q second message packets: n1, n2, ..., n q The first device reorders the q second message packets through the first reordering module to obtain the reordered q second message packets: n q ,n q-1 ,…,n1, and n q ,n q-1 ,…,n1 is input to the second security module to obtain q third message packets: c1,c2,…,c q The first device is based on c1, c2, ..., c q , q signals can be obtained and sent. The specific operations of the first device can be referred to S301 to S304, and the repeated parts are not repeated here. Correspondingly, the second device may include the same structure as the first device and perform the reverse operation of the first device, which is also not repeated here.

[0119] Through this first implementation, after performing a first security processing on the q first message packets in the message to be transmitted, the first device can reorder the resulting q second message packets and perform a second security processing on the reordered q second message packets. This reordering can minimize the spread of errors within the message to be transmitted at non-target receiving nodes, thereby improving message security.

[0120] For example, suppose the non-target receiving node receives the last message packet (e.g., c q ) decoding error. If the first device includes the first security module but does not include the first reordering module and the second security module, then the message packet c q The error can only cause m q This message packet is wrong, so the error introduced by the physical layer security transmission technology cannot be spread. As shown in Figure 7, if the first device includes a first security module, a first reordering module and a second security module, the message packet c q An error in the packet can cause errors in all message packets in the message to be transmitted. Therefore, through implementation method one, even if the non-target receiving node decodes a message packet with a later sequence number, it can still achieve error diffusion among all message packets, causing all message packets to be erroneous. In this way, even if the packet error rate of the non-target receiving node is significantly reduced due to retransmission merging, the two security processing steps can still generate a large number of errors at the non-target receiving node, thereby achieving the desired security level.

[0121] In some possible ways, in S303, the first device generates a random seed t a-1 , for the ath second message packet (for example, n q-a+1 ) performs security processing and obtains the ath third message group ca Among them, the random seed t a-1 The first device is the first a-1 second message packet (for example, n q-a+2 ) is obtained by security processing. Accordingly, in S306, the second device can generate a random seed t a-1 , group the ath third message into c a Perform security inverse processing to obtain the ath second message group among the q second message groups (for example, n q-a+1 ). Among them, the random seed t a-1 The second device is the third message group c a-1 Obtained by performing safe inverse processing.

[0122] In this case, the second device may decode the q signals before performing security inverse processing on the q third message packets. a If the decoding fails, the second device may request the first device to resend the a-th signal x a , until the second device receives the ath signal x a Decoding is successful, or the first device transmits the ath signal x a If the second device successfully decodes all q signals, the second device then performs security inverse processing on the q third message packets to obtain q second message packets. If the second device fails to decode one or more of the q signals, the second device may determine that the transmission of the q signals has failed.

[0123] In some other possible ways, when a is 1, in S303, the first device, according to the random seed t0, sorts the first second message group (for example, n q ) is processed securely to obtain the first third message group c1. Correspondingly, in S306, the second device may perform security inverse processing on the first third message group c1 according to the random seed t0 to obtain the first second message group (for example, n q ). When a is greater than or equal to 2 and less than or equal to q, in S303, the first device may perform the following operations on the a-1th signal x of the q signals according to the second device. a-1 The decoding result of the a-th second message packet (for example, n q-a+1 ) performs security processing and obtains the ath third message group c a Correspondingly, in S306, the second device may process the a-1th signal x according to the second device. a-1 The decoding result of the a-th third message group c aPerform security inverse processing to obtain the ath second message group among the q second message groups (for example, n q-a+1 ).

[0124] In this case, if the second device successfully decodes all q signals, or the second device decodes only the last second message packet n before reordering among the q signals, q If the decoding of the corresponding first signal fails, the second device may determine to execute the method from S305 to S308 on the q signals to obtain q first message groups; if the second device fails to decode one or more signals other than the first signal among the q signals, the second device determines that the transmission of the q signals has failed.

[0125] The following describes the second device's response to the a-1th signal x among the q signals. a-1 When the decoding result is decoding success or decoding failure, the first device performs a security processing operation and the second device performs a security inverse processing operation.

[0126] Case 1: The second device processes the a-1th signal x among the q signals. a-1 The decoding result is decoding success.

[0127] The first device may be configured to generate a random seed t a-1 , for the ath second message packet (for example, n q-a+1 ) performs security processing and obtains the ath third message group c a Among them, the random seed t a-1 is the a-1th second message packet (for example, n q-a+2 ) is obtained by performing security processing. Accordingly, the second device can perform the reverse operation of the first device, which will not be described in detail here. In this way, the first device can update the random seed based on the message packet corresponding to the signal successfully decoded by the second device, so that the second device can correctly receive subsequent signals, thereby improving the security of the message while ensuring the communication quality between the first and second devices.

[0128] Case 2: The second device processes the a-1th signal x among the q signals. a-1 The decoding result is decoding failure.

[0129] The first device may process the ath second message packet (eg, nth second message packet) among the reordered q second message packets according to a fixed sequence. q-a+1 ) performs security processing and obtains the ath third message group c a Correspondingly, the second device groups the ath third message into c according to a fixed sequence. aPerform security inverse processing to obtain the ath second message group in S306 (for example, n q-a+1 ). Optionally, the fixed sequence is pre-set, or may be agreed upon in advance by the first device and the second device. The fixed sequence may be, for example, an all-0 sequence, an all-1 sequence, or the like. In this way, when signal decoding fails, the first device performs security processing on subsequent message packets based on the fixed sequence, thereby avoiding security processing on subsequent message packets based on the signal where decoding failed; correspondingly, the second device performs security inverse processing on subsequent message packets based on the fixed sequence, thereby avoiding security inverse processing on subsequent message packets based on the signal where decoding failed, thereby avoiding the error corresponding to the signal where decoding failed from spreading at the second device, thereby improving the security of the message while ensuring the communication quality between the first device and the second device.

[0130] The following describes possible solutions for situation 2 by combining method 1 and method 2.

[0131] Method 1: The second device processes the a-1th signal x a-1 When the decoding result is a decoding failure, the first device reorders the a-1th second message packet (for example, n q-a+2 ) is set as a fixed sequence, and according to the fixed sequence, the ath third message group c is obtained a Correspondingly, the second device groups the a-1th second message obtained in S306 (for example, n q-a+2 ) is set as a fixed sequence, and according to the fixed sequence, the ath second message packet in S306 (for example, n q-a+1 ).

[0132] For example, the first device may group the a-1th second message (for example, n q-a+2 ) is set as a fixed sequence, and the first random seed is determined according to the set fixed sequence. The first random seed can be obtained by performing security processing on the a-1th second message group set as a fixed sequence. Then, the first device can combine the first random seed with the ath second message group (for example, n q-a+1 ) to perform the operation and complete the security processing to obtain the a-th third message group c a Accordingly, the second device may group the a-1th second message (eg, n q-a+2 ) is set as a fixed sequence, and a second random seed is determined based on the fixed sequence. The second random seed can be a function of the a-1th second message packet set as a fixed sequence, such as a hash function. The second random seed can be the same as the first random seed. Then, the second device can combine the second random seed with the ath third message packet c aPerform the operation to complete the security inverse process and obtain the a-th second message group (for example, n q-a+1 ).

[0133] Currently, if the second device fails to decode the signal, then even if the second device performs a secure inverse process on the decoded message packet, it will not obtain the correct first message packet, and the error will spread between different message packets. Through method one, in the case of a signal decoding error, the first device and the second device can set the second message packet corresponding to the signal to a fixed sequence, thereby avoiding the error from spreading between different message packets. At the same time, since the channel between the non-target receiving node and the first device is independent of the channel between the second device and the first device, the message packet sequence number that generates a decoding error in the non-target receiving node cannot be completely consistent with that of the second device, which means that the non-target receiving node cannot maintain synchronization with the random seed of the first device and the second device, so it is possible to ensure that the decoding error of the non-target receiving node is diffused, thereby achieving the improvement of communication security while not affecting the transmission performance of the second device.

[0134] Method 2: The second device processes the a-1th signal x a-1 When the decoding result is a decoding failure, the first device sets the first random seed to a fixed sequence, and obtains the ath third message packet c according to the fixed sequence. a Correspondingly, the second device sets the second random seed as a fixed sequence, and obtains the ath second message group (for example, n q-a+1 ).

[0135] Exemplarily, the first device sets the first random seed to a fixed sequence, and groups the fixed sequence with the ath second message (e.g., n q-a+1 ) to perform the operation and complete the security processing to obtain the a-th third message group c a Correspondingly, the second device sets the second random seed to a fixed sequence; and combines the fixed sequence with the ath third message group c a Perform the operation to complete the security inverse process and obtain the a-th second message group in S306 (for example, n q-a+1 ). The second random seed may be the same as the first random seed.

[0136] Currently, if the second device fails to decode the signal, then even if the second device performs a secure inverse process on the decoded message group, it will not obtain the correct first message group, and the error will spread between different message groups. Through the second method, in the case of a signal decoding error, the first device and the second device can set the random seed corresponding to the signal to a fixed sequence, thereby avoiding the error from spreading between different message groups. At the same time, since the channel between the non-target receiving node and the first device is independent of the channel between the second device and the first device, the message group sequence number that generates the decoding error in the non-target receiving node cannot be completely consistent with that of the second device, which means that the non-target receiving node cannot maintain synchronization of the random seed with the first device and the second device, so it is possible to ensure that the decoding error of the non-target receiving node is spread, thereby achieving the improvement of communication security while not affecting the transmission performance of the second device.

[0137] In some possible implementations, before the above-mentioned methods 1 and 2, if the second device receives the a-1th signal x a-1 The decoding result is a decoding failure, the first device may resend the a-1th signal x to the second device. a-1 , until the receiving end receives the a-1th signal x a-1 Decoding is successful, or until the a-1th signal x is transmitted a-1 If the number of times reaches the quantity threshold, the second device still processes the a-1th signal x a-1 If the decoding fails, the first device and the second device can execute the technical solutions in the first and second methods. a-1 If the decoding is successful, the second device can decode the a-1th signal x successfully. a-1 Execute steps S305 to S308, which will not be repeated here.

[0138] Implementation method 2:

[0139] The method shown in Figure 3 also includes: the first device obtains a message to be transmitted, the message to be transmitted includes K message group sets, the i-th message group set in the K message group sets includes q first message groups, K is an integer greater than or equal to 2, and i is any positive integer from 1 to K. Correspondingly, the second device receives a second message, the second message includes K signal sets, the i-th signal set in the K signal sets includes q signals, K is an integer greater than or equal to 2, and i is any positive integer from 1 to K. In this way, the first device can perform steps S301 to S304 for the q first message groups in each message group set, and the second device can perform steps S304 to S308 for the q signals in each signal set.

[0140] For example, as shown in FIG8 , the first device includes K first security modules, K first reordering modules, and K second security modules; the message to be transmitted includes K message group sets, q=2, each message group set includes two first message groups, for example, the i-th message group set includes two first message groups, denoted as m and m respectively. i ,m 2i Each message packet set corresponds to a first security module, a first reordering module and a second security module. The first device m i ,m 2i Input into the first security module, the first reordering module and the second security module corresponding to the i-th message group set in sequence, and obtain two third message groups: c i ,c 2i The first device is based on c i ,c 2i , two signals can be obtained and sent. The specific operations of the first device can be referred to S301 to S304, and the repeated parts are not repeated here. Accordingly, the second device can have a similar structure to the first device and perform the reverse operation of the first device, which is also not repeated here.

[0141] 8 illustrates an example in which K message group sets all include the same number of first message groups. It should be understood that in actual use, the number of first message groups in different message group sets may be the same or different.

[0142] It should also be understood that the first device can simultaneously process at least two of the K message group sets, i.e., the at least two message group sets can be processed in parallel; or it can process different message group sets from the K message group sets at different times, i.e., the K message group sets can be processed serially. Correspondingly, the second device can simultaneously process at least two of the K signal sets, i.e., the at least two signal sets can be processed in parallel; or it can process different signal sets from the K signal sets at different times, i.e., the K signal sets can be processed serially.

[0143] If the second device successfully decodes all signals in a signal set, the second device may perform operations from S304 to S308 on all signals in the signal set to obtain q first message packets; if the second device fails to decode one or more signals in a signal set, the second device determines that the signal set fails. Optionally, in each signal set, when the second device decodes any signal x a When decoding fails, the second device may directly determine that the signal set fails; or the second device may request the first device to resend the signal x a, until all signals in the signal set are decoded successfully or the number of signals transmitted here reaches the set threshold.

[0144] In this second implementation, the first device divides the messages to be transmitted into multiple sets and executes the method shown in Figure 3 for each set. By adjusting the number of message packets included in each set, a balance between transmission reliability and security can be achieved. Furthermore, in this second implementation, the first device only needs to cache the q second message packets corresponding to one set, rather than all second message packets corresponding to the messages to be transmitted, thus reducing cache overhead.

[0145] In some possible implementations, on the first device side, the first initial random seeds corresponding to the K message group sets may be identical. The first initial random seed is used by the first device to securely process the q first message groups and / or the q reordered second message groups corresponding to the i-th message group set. Accordingly, on the second device side, the second initial random seeds corresponding to the K signal groups may be identical. The second initial random seed is used by the second device to securely reverse process the q third message groups and / or the q reordered second message groups corresponding to the i-th signal group set. The second initial random seed may be the same as the first initial random seed.

[0146] Exemplarily, the first initial random seed and the second random seed are set random seeds. The set random seeds may be pre-set, determined by the first device or the second device, or determined for the first device or the second device by another device. For example, as shown in FIG8 , the first initial random seeds corresponding to the K message group sets are all t0; correspondingly, the second initial random seeds corresponding to the K signal groups are all t0.

[0147] In this way, errors can be diffused within each set, and errors in one set will not diffuse to another set, thereby improving the security of the message while ensuring the communication performance between the second device and the first device.

[0148] In other possible approaches, on the first device side, the first initial random seed corresponding to the first message group set may be a set random seed; when i is greater than 1, the first initial random seed corresponding to the i-th message group set may be determined based on the decoding results of the q signals corresponding to the i-1-th message group set. Accordingly, on the second device side, the second initial random seed corresponding to the first signal set may be a set random seed; when i is greater than 1, the second initial random seed corresponding to the i-th signal set may be determined based on the decoding results of the q signals in the i-1-th signal set. The second initial random seed may be the same as the first initial random seed.

[0149] The following, in combination with Case 1 and Case 2, explains that "the first initial random seed corresponding to the i-th message group set can be determined based on the decoding results of the q signals corresponding to the i-1-th message group set", and "the second initial random seed corresponding to the i-th signal set can be determined based on the decoding results of the q signals in the i-1-th signal set".

[0150] Case 1: When the second device successfully decodes all q signals corresponding to the i-1th message group set, the first initial random seed corresponding to the i-1th message group set is the random seed obtained based on the i-1th message group set; correspondingly, the second initial random seed corresponding to the i-th signal set is the random seed obtained based on the i-1th signal set.

[0151] In some examples, when the first initial random seed is used to securely process the q first message packets corresponding to the i-th message packet set, the first initial random seed may be obtained by the first device securely processing the last first message packet in the i-1-th message packet set. Accordingly, when the second initial random seed is used to securely inversely process the q reordered second message packets corresponding to the i-th signal set, the second initial random seed is obtained by the second device securely inversely processing the last reordered second message packet in the i-1-th signal set.

[0152] For example, as shown in FIG8 , the first initial random seed corresponding to the second message group set is the random seed t obtained by performing security processing on m2. G1,1 The first initial random seed corresponding to the third message group set is the random seed t obtained by security processing of m4. G2,1 , and so on. Correspondingly, the second initial random seed corresponding to the second signal set is the random seed t obtained by performing a secure inverse process on n2. G1,1 The second initial random seed corresponding to the third signal set is the random seed t obtained by securely inverting n4. G2,1 , and so on.

[0153] In other examples, when the first initial random seed is used to securely process the q reordered second message packets corresponding to the i-th message packet set, the first initial random seed may be obtained by the first device securely processing the last reordered second message packet corresponding to the i-1-th message packet set. Accordingly, when the second initial random seed is used to securely reverse process the q third message packets corresponding to the i-th signal set, the second initial random seed is obtained by the second device securely reverse processing the last third message packet corresponding to the i-1-th signal set.

[0154] For example, as shown in FIG8 , the first initial random seed corresponding to the second message group set is the random seed t obtained by security processing n1. G1,2 The first initial random seed corresponding to the third message group set is the random seed t obtained by security processing of n3. G2,2 , and so on. Correspondingly, the second initial random seed corresponding to the second signal set is the random seed t obtained by securely inverting c2. G1,2 The second initial random seed corresponding to the third signal set is the random seed t obtained by securely inverting c4. G2,2 , and so on.

[0155] Case 2: When the second device fails to decode one or more signals corresponding to the (i-1)th message group set, the first initial random seed and the second random seed are set random seeds. The specific content of the set random seed can be found in the description of "set random seed" above and will not be repeated here.

[0156] In this way, when the second device successfully decodes all signals corresponding to a message group set, the message group set can be used for security processing or security inverse processing of subsequent message group sets, thereby avoiding security processing or security inverse processing based on message group sets that failed to be decoded, and further avoiding the spread of errors corresponding to signals that failed to be decoded between different sets, thereby improving the security of messages while ensuring the communication quality between the first device and the second device.

[0157] Based on the same technical concept as the method embodiment of Figure 3, the embodiment of the present application provides a communication device through Figure 9, which can be used to perform the functions of the relevant steps in the above method embodiment. The functions can be implemented by hardware, or by software or hardware executing corresponding software implementations. The hardware or software includes one or more modules corresponding to the above functions. The structure of the communication device is shown in Figure 9, including a communication unit 901 and a processing unit 902. The communication device 900 can be applied to a terminal device or an access network device, and can implement the communication method provided in the above embodiments and examples of the present application. The functions of each unit in the communication device 900 are introduced below.

[0158] The communication unit 901 is used to receive and send information. In some embodiments, the communication unit 901 can be implemented through a physical interface, a communication module, a communication interface, or an input / output interface. The communication device 900 can be connected to a network cable or a cable through the communication unit to establish a physical connection with other devices. In other embodiments, the communication unit 901 can be implemented through a transceiver, for example, a mobile communication module. The mobile communication module may include at least one antenna, at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc.

[0159] The processing unit 902 can be used to support the communication device 900 in performing the processing actions in the above method embodiment. The processing unit 902 can be implemented by a processor. For example, the processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.

[0160] In one embodiment, the communication device 900 is applied to the first device in the embodiment of the present application shown in Figure 3. The specific functions of the processing unit 902 in this embodiment are introduced below.

[0161] The processing unit 902 is used to: securely process q first message packets to obtain q second message packets, where q is an integer greater than or equal to 1; reorder the q second message packets; securely process the reordered q second message packets to obtain q third message packets; and send q signals through the communication unit 901, where the q signals are obtained based on the q third message packets.

[0162] Optionally, the processing unit 902 is specifically configured to: arrange the q second message groups in reverse order.

[0163] In a first implementation manner, the processing unit 902 is further configured to: obtain a message to be transmitted, where the message to be transmitted includes q first message groups.

[0164] Exemplarily, the processing unit 902 is specifically used to: after obtaining q third message groups, send q signals through the communication unit 901; or, after obtaining the ath third message group among q third message groups, send the ath signal among q signals through the communication unit 901, where the ath signal is obtained based on the ath third message group, and a is any positive integer from 1 to q in sequence.

[0165] Optionally, the processing unit 902 is specifically used to: when it is determined that the receiving end fails to decode the a-1th signal among q signals, and a is greater than or equal to 2 and less than or equal to q, securely process the ath second message group according to a fixed sequence to obtain the ath third message group.

[0166] In some examples, the processing unit 902 is specifically used to: set the a-1th second message group among the reordered q second message groups as a fixed sequence; determine the first random seed based on the set fixed sequence; perform operations on the first random seed and the ath second message group to complete security processing and obtain the ath third message group.

[0167] In some other examples, the processing unit 902 is specifically used to: set the first random seed as a fixed sequence; operate the set fixed sequence and the a-th second message group to complete security processing and obtain the a-th third message group.

[0168] In the second implementation method, the processing unit 902 is also used to: obtain the message to be transmitted, the message to be transmitted includes K message group sets, the i-th message group set in the K message group sets includes q first message groups, K is an integer greater than or equal to 2, and i is any positive integer from 1 to K.

[0169] In some possible embodiments, the processing unit 902 is also used to: when it is determined that the receiving end fails to decode the a-th signal among q signals, resend the a-th signal through the communication unit 901 until the receiving end successfully decodes the a-th signal, or until the number of times the a-th signal is transmitted reaches a quantity threshold, where a is any positive integer from 1 to q.

[0170] In another embodiment, the communication device 900 is applied to the second device in the embodiment of the present application shown in Figure 3. The specific functions of the processing unit 902 in this embodiment are introduced below.

[0171] The processing unit 902 is used to: receive q signals through the communication unit 901, where q is an integer greater than or equal to 1; obtain q third message groups based on the q signals; perform security inverse processing on the q third message groups to obtain q second message groups; reorder the q second message groups; and perform security inverse processing on the reordered q second message groups to obtain q first message groups.

[0172] Optionally, the processing unit 902 is specifically configured to: arrange the q second message groups in reverse order.

[0173] In a first implementation manner, the processing unit 902 is specifically configured to: receive a first message through the communication unit 901, where the first message includes q signals.

[0174] Exemplarily, the processing unit 902 is specifically used to: after receiving q signals, obtain q third message groups based on the q signals; or, after receiving the a-th signal among the q signals, obtain the a-th third message group among the q third message groups based on the a-th signal, where a is any positive integer from 1 to q in sequence.

[0175] Optionally, the processing unit 902 is specifically configured to: when the receiving end fails to decode the a-1th signal among the q signals, perform security inverse processing on the ath third message packet according to a fixed sequence to obtain the ath second message packet.

[0176] In some examples, the processing unit 902 is specifically used to: set the a-1th second message group among q second message groups as a fixed sequence; determine the second random seed based on the set fixed sequence; operate the second random seed with the ath third message group to complete the security inverse processing to obtain the ath second message group.

[0177] In some other examples, the processing unit 902 is specifically used to: set the second random seed as a fixed sequence; operate the set fixed sequence with the ath third message group to complete the security inverse processing to obtain the ath second message group.

[0178] In the second implementation method, the processing unit 902 is specifically used to: receive a second message through the communication unit 901, the second message includes K signal sets, the i-th signal set in the K signal sets includes q signals, K is an integer greater than or equal to 2, and i ranges from 1 to K.

[0179] It should be noted that the division of modules in the above embodiments of the present application is illustrative and is only a logical functional division. In actual implementation, there may be other division methods. In addition, the functional units in the various embodiments of the present application may be integrated into a processing unit, or may exist separately physically, or two or more units may be integrated into a single unit. The above-mentioned integrated units may be implemented in the form of hardware or in the form of software functional units.

[0180] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0181] Based on the same technical concept, an embodiment of the present application provides a communication device as shown in Figure 10, which can be used to perform the relevant steps in the above method embodiment. The communication device can be applied to a terminal device or an access network device, can implement the communication method provided in the above embodiments and examples of the present application, and has the functions of the communication device shown in Figure 9. Referring to Figure 10, the communication device 1000 includes: a processor 1002. Optionally, the communication device 1000 also includes: a transceiver 1001 and a memory 1003. The transceiver 1001, the processor 1002 and the memory 1003 are interconnected.

[0182] Optionally, the transceiver 1001, the processor 1002, and the memory 1003 are interconnected via a bus 1004. The bus 1004 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be classified as an address bus, a data bus, a control bus, etc. For ease of illustration, FIG10 shows only one thick line, but this does not mean that there is only one bus or only one type of bus.

[0183] The transceiver 1001 is used to receive and send information to achieve communication interaction with other devices. For example, the transceiver 1001 can be implemented through a physical interface, a communication module, a communication interface, and an input / output interface.

[0184] The processor 1002 may be used to support the communication device 1000 in executing the processing actions in the above-described method embodiment. When the communication device 1000 is used to implement the above-described method embodiment, the processor 1002 may also be used to implement the functions of the processing unit 902. The processor 1002 may be a CPU, other general-purpose processors, DSPs, ASICs, FPGAs, other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor may be a microprocessor or any conventional processor.

[0185] In one embodiment, the communication device 1000 is applied to the first device in the embodiment of the present application shown in Figure 3. The specific functions of the processor 1002 in this embodiment are introduced below.

[0186] The processor 1002 is configured to: securely process q first message packets to obtain q second message packets, where q is an integer greater than or equal to 1; reorder the q second message packets; securely process the reordered q second message packets to obtain q third message packets; and send q signals through the transceiver 1001, where the q signals are obtained based on the q third message packets.

[0187] In another embodiment, the communication device 1000 is applied to the second device in the embodiment of the present application shown in Figure 3. The specific functions of the processor 1002 in this embodiment are introduced below.

[0188] The processor 1002 is configured to: receive q signals through the transceiver 1001, where q is an integer greater than or equal to 1; obtain q third message packets based on the q signals; perform security inverse processing on the q third message packets to obtain q second message packets; reorder the q second message packets; and perform security inverse processing on the reordered q second message packets to obtain q first message packets.

[0189] The specific functions of the processor 1002 can refer to the description of the communication method provided in the above embodiments and examples of the present application, as well as the specific functional description of the communication device 900 in the embodiment of the present application shown in Figure 9, which will not be repeated here.

[0190] The memory 1003 is used to store program instructions and / or data, etc. Specifically, the program instructions may include program code, which includes computer operation instructions. The memory 1003 may include RAM, and may also include non-volatile memory (non-volatile memory), such as at least one disk storage. The processor 1002 executes the program instructions stored in the memory 1003, and uses the data stored in the memory 1003 to implement the above functions, thereby realizing the communication method provided in the above embodiment of the present application. The memory 1003 can be integrated with the processor 1002, or it can be a memory outside the communication device.

[0191] It is understood that the memory 1003 in FIG. 10 of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be ROM, programmable read-only memory (Programmable ROM, PROM), erasable programmable read-only memory (Erasable PROM, EPROM), electrically erasable programmable read-only memory (Electrically EPROM, EEPROM) or flash memory. The volatile memory may be RAM, which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0192] Based on the above embodiments, an embodiment of the present application further provides a computer program product including computer-executable instructions. When the computer program product is run, the method provided in the above embodiments is executed.

[0193] Based on the above embodiments, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a computer, the computer executes the method provided in the above embodiments.

[0194] The storage medium may be any available medium that can be accessed by a computer. By way of example and not limitation, computer-readable media may include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer.

[0195] Based on the above embodiments, an embodiment of the present application further provides a chip, which is used to read a computer program stored in a memory to implement the method provided in the above embodiments.

[0196] Based on the above embodiments, embodiments of the present application provide a chip system, which includes a processor for supporting a computer device to implement the functions involved in each device in the above embodiments. In one possible design, the chip system also includes a memory for storing the necessary programs and data for the computer device. The chip system can be composed of a chip or can include a chip and other discrete devices.

[0197] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0198] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0199] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or box in the flow chart and / or block diagram, as well as the combination of the flow chart and / or box in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more flow charts and / or one or more boxes in the block diagram.

[0200] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0201] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0202] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.

[0203] In this application, "at least one" means one or more, and "more" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "Including at least one of A, B and C" can mean: including A; including B; including C; including A and B; including A and C; including B and C; including A, B and C.

[0204] It is understood that the various numbers used in the embodiments of this application are merely for ease of description and are not intended to limit the scope of the embodiments of this application. The order of the sequence numbers of the above-mentioned processes does not necessarily imply a specific order of execution; the order of execution of the processes should be determined by their functions and inherent logic.

[0205] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include these modifications and variations.

Claims

1. A communication method, characterized in that: include: Performing security processing on q first message packets to obtain q second message packets, where q is an integer greater than or equal to 1; Reordering the q second message packets; Performing security processing on the reordered q second message packets to obtain q third message packets; Sending q signals, where the q signals are obtained according to the q third message groups.

2. The method according to claim 1, characterized in that Reordering the q second message packets, comprising: Arrange the q second message groups in reverse order.

3. The method according to claim 1 or 2, characterized in that Also includes: A message to be transmitted is obtained, where the message to be transmitted includes the q first message groups.

4. The method according to any one of claims 1 to 3, characterized in that Sending the q signals comprises: After obtaining the q third message packets, sending the q signals; or After obtaining the ath third message group among the q third message groups, sending the ath signal among the q signals, the ath signal is obtained according to the ath third message group, and a is any positive integer from 1 to q in sequence.

5. The method according to claim 4, characterized in that When it is determined that the receiving end fails to decode the a-1th signal among the q signals, and a is greater than or equal to 2 and less than or equal to q, performing security processing on the ath second message packet among the q second message packets after reordering to obtain the ath third message packet, including: According to a fixed sequence, the ath second message group is securely processed to obtain the ath third message group.

6. The method according to claim 5, characterized in that According to the fixed sequence, the ath second message group is security processed to obtain the ath third message group, including: Setting the a-1th second message group among the q reordered second message groups as the fixed sequence; Determine a first random seed according to the set fixed sequence; The first random seed is operated on the ath second message group to complete security processing and obtain the ath third message group.

7. The method according to claim 5, characterized in that According to the fixed sequence, the ath second message group is security processed to obtain the ath third message group, including: Setting a first random seed to the fixed sequence; The set fixed sequence is operated with the ath second message group to complete security processing and obtain the ath third message group.

8. The method according to claim 1 or 2, characterized in that: Also includes: Obtain a message to be transmitted, wherein the message to be transmitted includes K message group sets, the i-th message group set among the K message group sets includes the q first message groups, K is an integer greater than or equal to 2, and i is any positive integer from 1 to K.

9. The method according to claim 8, characterized in that The first initial random seed is used to perform security processing on the q first message packets corresponding to the i-th message packet set and / or the q second message packets after reordering; The first initial random seed is a set random seed; or, When the i is 1, or when the i is greater than 1 and it is determined that the receiving end fails to decode one or more of the signals corresponding to the i-1th message group set, the first initial random seed is a set random seed; and / or, when the i is greater than 1 and it is determined that the receiving end successfully decodes all of the signals corresponding to the i-1th message group set, the first initial random seed is a random seed obtained based on the i-1th message group set.

10. The method according to claim 9, characterized in that When the first initial random seed is used to perform security processing on the q first message packets corresponding to the i-th message packet set, the first initial random seed is a random seed obtained according to the i-1-th message packet set, including: performing security processing on the last first message packet in the i-1-th message packet set to obtain the first initial random seed; and / or, When the first initial random seed is used to perform security processing on the q second message groups after reordering corresponding to the i-th message group set, the first initial random seed is a random seed obtained based on the i-1th message group set, including: performing security processing on the last second message group after reordering corresponding to the i-1th message group set to obtain the first initial random seed.

11. The method according to any one of claims 1 to 10, characterized in that Also includes: When it is determined that the receiving end fails to decode the ath signal among the q signals, the ath signal is resent until the receiving end successfully decodes the ath signal, or until the number of times the ath signal is transmitted reaches a quantity threshold, where a is any positive integer from 1 to q.

12. The method according to any one of claims 1 to 11, characterized in that The ath second message group among the q second message groups is obtained by performing security processing on the ath first message group among the q first message groups; The ath third message group among the q third message groups is obtained by performing security processing on the ath second message group among the q second message groups after reordering; The ath signal among the q signals is obtained according to the ath third message grouping among the q third message groups; The a can be any positive integer from 1 to q.

13. A communication method, characterized in that: include: Receiving q signals, where q is an integer greater than or equal to 1; Obtaining q third message packets according to the q signals; Performing security inverse processing on the q third message packets to obtain q second message packets; Reordering the q second message packets; The reordered q second message packets are subjected to security inverse processing to obtain q first message packets.

14. The method according to claim 13, characterized in that Reordering the q second message packets, comprising: Arrange the q second message groups in reverse order.

15. The method according to claim 13 or 14, characterized in that Receive q signals, including: A first message is received, wherein the first message includes the q signals.

16. The method according to any one of claims 13 to 15, characterized in that According to the q signals, q third message packets are obtained, including: After receiving the q signals, obtaining q third message packets according to the q signals; or After receiving the ath signal among the q signals, the ath third message group among the q third message groups is obtained according to the ath signal, where a is any positive integer from 1 to q in sequence.

17. The method according to claim 16, characterized in that When the receiving end fails to decode the a-1th signal among the q signals, performing security inverse processing on the ath third message packet to obtain the ath second message packet among the q second message packets, including: According to a fixed sequence, the ath third message group is subjected to security inverse processing to obtain the ath second message group.

18. The method according to claim 17, characterized in that According to the fixed sequence, the ath third message group is security processed to obtain the ath second message group, including: Setting the a-1th second message group among the q second message groups to the fixed sequence; Determine a second random seed according to the set fixed sequence; The second random seed is operated on the ath third message group to complete the security inverse processing to obtain the ath second message group.

19. The method according to claim 17, characterized in that According to the fixed sequence, the ath third message group is security processed to obtain the ath second message group, including: Setting a second random seed to the fixed sequence; The set fixed sequence is operated on the ath third message group to complete the security inverse processing to obtain the ath second message group.

20. The method according to claim 13 or 14, characterized in that Receive q signals, including: A second message is received, where the second message includes K signal sets, the i-th signal set among the K signal sets includes the q signals, K is an integer greater than or equal to 2, and i ranges from 1 to K.

21. The method of claim 20, wherein: The second initial random seed is used to perform security inverse processing on the q third message packets corresponding to the i-th signal set and / or the q reordered second message packets; The second initial random seed is a set random seed; or, When the i is 1, or when the i is greater than 1 and the decoding of one or more of the signals in the i-1th signal set fails, the second initial random seed is a set random seed; and / or when the i is greater than 1 and the decoding of all the signals in the i-1th signal set is successful, the second initial random seed is a random seed obtained based on the i-1th signal set.

22. The method according to claim 21, characterized in that When the second initial random seed is used to perform secure inverse processing on the q third message packets corresponding to the i-th signal set, the second initial random seed is a random seed obtained according to the i-1-th signal set, including: performing secure inverse processing on the last third message packet corresponding to the i-1-th signal set to obtain the second initial random seed; and / or, When the second initial random seed is used to perform secure inverse processing on the q reordered second message groups corresponding to the i-th signal set, the second initial random seed is a random seed obtained based on the i-1th signal set, including: performing secure inverse processing on the last reordered second message group corresponding to the i-1th signal set to obtain the second initial random seed.

23. The method according to any one of claims 13 to 22, characterized in that The ath third message group among the q third message groups is obtained according to the ath signal among the q signals; The ath second message group among the q second message groups is obtained by performing security inverse processing on the ath third message group among the q third message groups; The ath first message group among the q first message groups is obtained by performing security inverse processing on the ath second message group among the q second message groups after reordering; The a can be any positive integer from 1 to q.

24. A communication device, characterized in that: include: A communication unit for receiving and sending information; A processing unit, configured to execute the method according to any one of claims 1 to 23 through the communication unit.

25. A communication device, characterized in that: The method comprises a processor configured to execute the method according to any one of claims 1 to 23.

26. A communication system, characterized in that: include: A first device, configured to implement the method according to any one of claims 1 to 12; The second device is used to implement the method according to any one of claims 13-23.

27. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program or instructions. When the computer program or instructions are executed by the communication device, the method according to any one of claims 1 to 23 is implemented.

28. A chip, characterized in that: The chip is coupled to a memory, and the chip reads a computer program stored in the memory to execute the method according to any one of claims 1 to 23.

29. A computer program product, characterized in that The computer program product comprises: a computer program code, and when the computer program code is executed, the method according to any one of claims 1 to 23 is implemented.