5G terminal communication transmission encryption method
By deploying a central station and terminal cryptographic machines in the 5G communication network and adopting network layer and application layer encryption mechanisms, the problem of 5G terminal communication being easily interfered with and leaked is solved, and the confidentiality and integrity of data are protected, making it suitable for 5G terminal communication transmission.
Patent Information
- Application Number
- CN202511794391.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-02
- Publication Date
- 2026-02-13
AI Technical Summary
5G terminal communication transmission is susceptible to interference, eavesdropping, and data leakage, especially when channels are open and nodes are exposed. Existing technologies are unable to effectively protect data confidentiality, integrity, and authentication.
Deploying central station cryptographic machines and 5G terminal cryptographic machines in 5G communication networks, and using encryption mechanisms at the network layer and application layer, including in front of edge computing servers, between the bearer network and wired network interfaces, and at 5G terminals, enables the establishment of IPsec tunnels and data encryption and decryption, ensuring the confidentiality and integrity of data transmission.
It achieves confidentiality and integrity protection for 5G terminal communication data, prevents eavesdropping and interference from both wireless and wired sides, ensures the security and reliability of data transmission, and has a latency in the sub-second range, making it suitable for time-insensitive services.
Smart Images

Figure CN121531351A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method for secure and confidential wireless transmission, and more particularly to a method for encrypting 5G terminal communication transmission, belonging to the field of mobile communication security and confidentiality technology. Background Technology
[0002] 5G communication technology is now highly mature, with related infrastructure such as base stations and BBUs deployed on a large scale. 5G terminals, including smartphones and tablets, are widespread. Compared to existing trunked radio and 4G communication, 5G offers advantages such as high data rates, low latency, improved transmission quality, increased system capacity, and massive connectivity, significantly enhancing communication interoperability. However, 5G wireless transmission is characterized by open channels and exposed nodes, making it vulnerable to wireless sniffing and man-in-the-middle attacks, posing a risk of data leakage. Therefore, when users utilize 5G terminals for business data processing, they must encrypt IP network transmissions and communication application data transmissions to ensure the confidentiality, integrity, and authentication of business data transmissions.
[0003] Therefore, there is an urgent need to study a 5G terminal communication transmission encryption method, mainly to solve the risks of interference, eavesdropping and data leakage when 5G terminal service data is transmitted. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a 5G terminal communication transmission encryption method to address the deficiencies in the prior art.
[0005] The technical solution adopted by this invention to solve its technical problem is: This invention provides a 5G terminal communication transmission encryption method, which includes a 5G terminal, an edge computing server, a bearer network and wired network interface, an edge computing application, and a communication service application in a 5G communication network. Deploy a central station cryptographic machine in front of the edge computing server, deploy a central station cryptographic machine between the bearer network and the wired network interface, and deploy a 5G terminal cryptographic machine on the 5G terminal; achieve 5G communication transmission encryption through network layer transmission encryption between the 5G terminal cryptographic machine and the central station cryptographic machine, and application layer transmission encryption between the central station cryptographic machines. Deploy central station cryptographic machines in edge computing applications and communication service applications to provide cryptographic services for communication applications and achieve encrypted protection of data transmission in communication applications.
[0006] Furthermore, the specific process of the encryption mechanism for transmission between the 5G terminal cryptographic machine and the central station cryptographic machine in the method of the present invention includes: Step 1: The 5G terminal sends a request to establish a VPN tunnel; Step 2: The 5G terminal cryptographic device recognizes the VPN tunnel request. Based on the corresponding information for the central station cryptographic device in the VPN tunnel request, the 5G terminal cryptographic device sends the first packet for IPsec key negotiation to the central station cryptographic device. Step 3: After receiving and confirming the data, the central station cryptographic machine sends out the second packet for IPsec key negotiation; Step 4: The 5G terminal cryptographic device receives the second packet for IPsec key negotiation and sets the corresponding SA; Step 5: The 5G terminal cryptographic device sends the third packet for IPsec key negotiation; Step 6: The 5G terminal cryptographic device sends a VPN tunnel establishment completion message to the 5G terminal; Step 7: After receiving the IPsec key negotiation confirmation frame, the central station cryptographic machine sets the corresponding SA. At this point, the IPsec tunnel is established. Step 8: The 5G terminal sends out IP data frames; Step 9: The 5G terminal's cryptographic device encrypts the data and then sends out the tunnel-encrypted IP data; Step 10: The central station's cryptographic machine sends out encrypted tunnel-encrypted IP data; Step 11: After the 5G terminal cryptographic machine receives and decrypts the IP data frame without error, it sends the IP data frame to the 5G terminal. Step 12: Subsequent data information is encrypted via tunnel mode IP transmission between the 5G terminal cryptographic machine and the central station cryptographic machine.
[0007] Furthermore, in step 1 of the present invention, the 5G terminal sends a VPN tunnel establishment request in the following ways: through a custom VPN tunnel request frame; or through the 5G terminal's management channel for the 5G terminal's cryptographic machine.
[0008] Furthermore, the specific process of the data transmission encryption mechanism in the communication application of the method of the present invention includes: Step 1: Deploy a 5G terminal cryptographic device on the 5G terminal; Step 2: The communication application software on the 5G terminal calls the 5G terminal cryptographic machine to encrypt the communication application data and sends the encrypted data to the edge computing application server and the communication service application server in the data center. Step 3: Deploy the central station cryptographic machine on the edge computing application server and the communication service application server in the data center; Step 4: Decrypt the communication application data by calling the central station's cryptographic machine to obtain the plaintext data; Step 5: Complete the encryption and decryption service for data transmission in communication applications.
[0009] The beneficial effects of this invention are: This invention proposes a 5G terminal communication transmission encryption method. By deploying a central station cryptographic machine in front of the edge computing server, a central station cryptographic machine between the bearer network and the wired network interface, a 5G terminal cryptographic machine in the 5G terminal, and a central station cryptographic machine in edge computing applications and communication service applications, the method provides network transmission encryption protection and cryptographic services for communication applications, thereby achieving network transmission confidentiality and integrity protection, as well as encryption protection for data transmission in communication applications. Attached Figure Description
[0010] The present invention will be further described below with reference to the accompanying drawings and embodiments. In the accompanying drawings: Figure 1 This is a 5G terminal communication transmission encryption method according to an embodiment of the present invention; Figure 2 This is the network layer transmission encryption mechanism between the 5G terminal cryptographic device and the central station cryptographic machine in this embodiment of the invention; Figure 3 This is the processing mechanism of the 5G terminal cryptographic machine and the central station cryptographic machine in this embodiment of the invention; Figure 4 This is a data transmission encryption mechanism for communication applications in this embodiment of the invention. Detailed Implementation
[0011] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0012] like Figure 1 As shown in the figure, a 5G terminal communication transmission encryption method according to an embodiment of the present invention mainly solves the risks of interference, eavesdropping and data leakage when 5G terminal service data is transmitted for communication.
[0013] 5G communication transmission encryption includes network layer transmission encryption between the 5G terminal cryptographic machine and the central station cryptographic machine, as well as application layer transmission encryption between the central station cryptographic machines. The 5G terminal communication transmission encryption method is as follows: Figure 1 As shown, a cryptographic device deployed on 5G terminals, including smartphones and tablets, is defined as a 5G terminal cryptographic device, and a cryptographic device deployed on the server side is defined as a central station cryptographic device. To prevent wireless eavesdropping, espionage, and interference, a 5G terminal cryptographic device is deployed on the 5G terminal and a central station cryptographic device is deployed on the 5G bearer network server side. To prevent wired eavesdropping, espionage, and interference, a central station cryptographic device is deployed on the 5G bearer network server side and a central station cryptographic device is deployed on the data center server side.
[0014] Network transmission encryption: For network transmission data between 5G terminals and edge computing servers and wired networks, a central station cryptographic machine is deployed in front of the edge computing server, working in conjunction with the 5G terminal cryptographic machine. A central station cryptographic machine is also deployed between the bearer network and wired network interfaces, working in conjunction with the 5G terminal cryptographic machine, to achieve IP network transmission encryption protection and realize the confidentiality and integrity protection of network transmission.
[0015] Encryption of data transmission for communication applications: Deploy 5G terminal cryptographic machines in 5G terminals and central station cryptographic machines in edge computing applications and communication service applications to provide cryptographic services for communication application systems and achieve encrypted protection of data transmission for communication applications.
[0016] See Figure 2 This invention provides a network layer transmission encryption mechanism between a 5G terminal cryptographic device and a central station cryptographic machine. When a 5G terminal accesses a 5G network, the 5G terminal cryptographic device can communicate with the central station cryptographic machine deployed between the 5G bearer network and the wired network, or with the central station cryptographic machine between the 5G bearer network and the 5G edge computing network. This enables encrypted transmission of 5G terminal data within the 5G access network, bearer network, and core network, preventing attacks such as sniffing and tampering from affecting the internal network.
[0017] See Figure 3 This invention provides a processing mechanism for 5G terminal cryptographic machines and central station cryptographic machines, the processing flow of which is as follows: 1) The 5G terminal sends a request to establish a VPN tunnel (either through a custom VPN tunnel request frame or through the 5G terminal's management channel for the 5G terminal's cryptographic device). 2) The 5G terminal cryptographic device recognizes the VPN tunnel request. Based on the corresponding information of the peer central station cryptographic device in the tunnel request frame, the 5G terminal cryptographic device sends the first packet of IPsec key negotiation to the peer central station cryptographic device. 3) After receiving and confirming the data, the central station cryptographic machine sends out the second packet for IPsec key negotiation; 4) The 5G terminal cryptographic device receives the second packet for IPsec key negotiation and sets the corresponding SA; 5) The 5G terminal cryptographic device sends the third packet for IPsec key negotiation; 6) The 5G terminal's cryptographic device sends a VPN tunnel establishment completion message to the 5G terminal; 7) After receiving the IPsec key negotiation confirmation frame, the central station cryptographic machine sets the corresponding SA. At this point, the IPsec tunnel is established. 8) The 5G terminal sends out IP data frames; 9) The 5G terminal's cryptographic device encrypts the data before sending out tunnel-encrypted IP data; 10) The central station's cryptographic machine sends out encrypted tunnel-encrypted IP data; 11) After the 5G terminal cryptographic machine receives and decrypts the data frame without error, it sends the IP data frame to the 5G terminal. 12) All subsequent data information is encrypted via IP transmission in tunnel mode between the 5G terminal cryptographic machine and the central station cryptographic machine.
[0018] See Figure 4 This invention provides a data transmission encryption mechanism for communication applications. A 5G terminal cryptographic machine and a central station cryptographic machine are deployed in 5G terminals, edge computing applications, and communication service applications respectively to achieve encrypted data transmission in communication applications. The processing flow is as follows: 1) Deploy 5G terminal cryptographic machines in 5G terminals; 2) The communication application software on the 5G terminal calls the 5G terminal cryptographic machine to encrypt the communication application data and send the encrypted data to the edge computing application server and the communication service application server of the data center. 3) Deploy central station cryptographic machines on edge computing application servers and data center communication service application servers; 4) By calling the central station's cryptographic machine, the communication application data is decrypted to obtain plaintext data; 5) Complete the encryption and decryption service for data transmission in communication applications.
[0019] According to industry research, the processing latency of current 5G terminal cryptographic machines and central station cryptographic machines is in the hundreds of milliseconds range. Therefore, for a communication interaction process, the latency introduced by encryption is approximately in the sub-second range. For time-insensitive services, encryption measures should be taken as much as possible to avoid the risk of information leakage. For time-sensitive services, encryption should be used judiciously, and the impact of the latency introduced by encryption on the service should be considered.
[0020] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0021] It should be understood that those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims.
Claims
1. A 5G terminal communication transmission encryption method, comprising a 5G terminal, an edge computing server, a bearer network and wired network interface, an edge computing application, and a communication service application in a 5G communication network; characterized in that: Deploy a central station cryptographic machine in front of the edge computing server, deploy a central station cryptographic machine between the bearer network and the wired network interface, and deploy a 5G terminal cryptographic machine on the 5G terminal; achieve 5G communication transmission encryption through network layer transmission encryption between the 5G terminal cryptographic machine and the central station cryptographic machine, and application layer transmission encryption between the central station cryptographic machines. Deploy central station cryptographic machines in edge computing applications and communication service applications to provide cryptographic services for communication applications and achieve encrypted protection of data transmission in communication applications.
2. The 5G terminal communication transmission encryption method according to claim 1, characterized in that, The specific process of the encryption mechanism for transmission between the 5G terminal cryptographic machine and the central station cryptographic machine in this method includes: Step 1: The 5G terminal sends a request to establish a VPN tunnel; Step 2: The 5G terminal cryptographic device recognizes the VPN tunnel request. Based on the corresponding information for the central station cryptographic device in the VPN tunnel request, the 5G terminal cryptographic device sends the first packet for IPsec key negotiation to the central station cryptographic device. Step 3: After receiving and confirming the data, the central station cryptographic machine sends out the second packet for IPsec key negotiation; Step 4: The 5G terminal cryptographic device receives the second packet for IPsec key negotiation and sets the corresponding SA; Step 5: The 5G terminal cryptographic device sends the third packet for IPsec key negotiation; Step 6: The 5G terminal cryptographic device sends a VPN tunnel establishment completion message to the 5G terminal; Step 7: After receiving the IPsec key negotiation confirmation frame, the central station cryptographic machine sets the corresponding SA. At this point, the IPsec tunnel is established. Step 8: The 5G terminal sends out IP data frames; Step 9: The 5G terminal's cryptographic device encrypts the data and then sends out the tunnel-encrypted IP data; Step 10: The central station's cryptographic machine sends out encrypted tunnel-encrypted IP data; Step 11: After the 5G terminal cryptographic machine receives and decrypts the IP data frame without error, it sends the IP data frame to the 5G terminal. Step 12: Subsequent data information is encrypted via tunnel mode IP transmission between the 5G terminal cryptographic machine and the central station cryptographic machine.
3. The 5G terminal communication transmission encryption method according to claim 2, characterized in that, The methods by which the 5G terminal sends a VPN tunnel establishment request in step 1 include: through a custom VPN tunnel request frame; or through the 5G terminal's management channel for the 5G terminal's cryptographic machine.
4. The 5G terminal communication transmission encryption method according to claim 1, characterized in that, The specific process of the data transmission encryption mechanism in this method includes: Step 1: Deploy a 5G terminal cryptographic device on the 5G terminal; Step 2: The communication application software on the 5G terminal calls the 5G terminal cryptographic machine to encrypt the communication application data and sends the encrypted data to the edge computing application server and the communication service application server in the data center. Step 3: Deploy the central station cryptographic machine on the edge computing application server and the communication service application server in the data center; Step 4: Decrypt the communication application data by calling the central station's cryptographic machine to obtain the plaintext data; Step 5: Complete the encryption and decryption service for data transmission in communication applications.