Communication method and device
By using air interface time synchronization to determine the COUNT during lower-layer packet interaction in the PDCP layer, the integrity verification and encryption of data packets are achieved. This solves the problem of spoofing and tampering of lower-layer data/signaling in the PDCP layer, improves the security and reliability of data transmission, and reduces air interface resource overhead.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-11
- Publication Date
- 2026-03-13
AI Technical Summary
In existing technologies, the lower-layer data/signaling of the PDCP layer is at risk of being counterfeited and tampered with, resulting in insufficient data transmission security.
By using the air interface time synchronization mechanism to determine the COUNT during the lower-layer data packet interaction process of the PDCP layer, the integrity verification and encryption of data packets can be achieved, avoiding the carrying of additional indication information in the data packets and reducing air interface overhead.
It effectively reduces the risk of data/signaling at the lower layer of PDCP being counterfeited and tampered with, improves the security and reliability of data transmission, and reduces air interface resource overhead.
Smart Images

Figure CN121664439A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communications, and more particularly to communication methods and apparatus. Background Technology
[0002] In mobile communication scenarios, the interaction of service information between terminals and network devices relies on the radio access network (RAN) protocol stack. For example, during user plane data transmission, the RAN protocol stack may include the Service Data Adaptation Protocol (SDAP) layer, the Packet Data Convergence Protocol (PDCP) layer, the Radio Link Control (RLC) layer, the Media Access Link Control (MAC) layer, and the Physical (PHY) layer. During the control of user plane data transmission, the RAN protocol stack may also include the Non-Access Stratum (NAS) layer and the Radio Resource Control (RRC) layer.
[0003] To ensure the security of RRC layer signaling and user plane data, the current common approach is to encrypt / decrypt and perform integrity protection / verification of data packets at the PDCP layer using security algorithms. However, the underlying data / signaling of the PDCP layer still faces the risk of being counterfeited and tampered with. Summary of the Invention
[0004] This application provides a communication method and apparatus that can effectively reduce the risk of lower-layer data / signaling of the PDCP layer being counterfeited and tampered with, thereby improving the security of data transmission.
[0005] In a first aspect, a communication method is provided. This method can be executed by a second communication device, by a component applied to the second communication device (e.g., a processor, circuit, chip, or chip system), or by a logic node, logic module, or software capable of implementing all or part of the functions of the second communication device. The method includes: receiving a first data packet from a first communication device, the first data packet being a data packet at a lower layer of the Packet Data Convergence Protocol (PDCP) layer; performing integrity verification on the first data packet according to a first COUNT; and / or decrypting the first data packet according to the first COUNT, wherein the first COUNT is determined based on a first superframe number (HFN) and a first air interface time corresponding to the first data packet, and the first HFN is the HFN corresponding to the first air interface time.
[0006] Based on this scheme, this application provides a communication method. During the interaction of data packets (first data packets) at the lower layer of the PDCP layer between the first communication device and the second communication device, the first communication device can perform integrity protection and / or encryption on the first data packet based on the first COUNT, and the second communication device can perform integrity verification and / or decryption on the first data packet based on the first COUNT, thereby achieving security protection for the data packets at the lower layer of the PDCP layer. This helps reduce the risk of the lower layer data / signaling of the PDCP layer being counterfeited and tampered with. The first COUNT is determined based on the first HFN and the first air interface time corresponding to the first data packet. The first HFN is the HFN corresponding to the first air interface time. That is to say, the determination of the first COUNT mainly depends on the air interface time corresponding to the first data packet. Since the first communication device and the second communication device that communicate over the air interface through the wireless protocol stack will keep the air interface time synchronized, the first air interface time can be determined based on the air interface time of transmitting the first data packet or the scheduling information of scheduling the first data packet when the first data packet is interacting. There is no need to carry the indication information for determining the first COUNT in the first data packet. This helps to achieve security protection for the first data packet without increasing air interface overhead or with a small increase in air interface overhead.
[0007] Secondly, a communication method is provided. This method can be executed by a first communication device, by a component applied to the first communication device (e.g., a processor, circuit, chip, or chip system), or by a logic node, logic module, or software capable of implementing all or part of the functions of the first communication device. The method includes: performing integrity protection on data to be transmitted according to a first COUNT, and / or encrypting the data to be transmitted according to the first COUNT to obtain a first data packet, wherein the first data packet is a data packet at the lower layer of the Packet Data Convergence Protocol (PDCP) layer; and sending the first data packet to a second communication device. The first COUNT is determined based on a first superframe number (HFN) and a first air interface time corresponding to the first data packet, and the first HFN is the HFN corresponding to the first air interface time. The technical effects of the second aspect are similar to those of the first aspect and will not be elaborated further here.
[0008] In conjunction with the first aspect, the communication method further includes: receiving or sending first scheduling information, the first scheduling information being used to schedule the first data packet, and the first scheduling information indicating a first air interface time. Correspondingly, in conjunction with the second aspect, the communication method further includes: sending or receiving first scheduling information, the first scheduling information being used to schedule the first data packet, and the first scheduling information indicating a first air interface time.
[0009] Based on this scheme, the first air interface time is indicated by the first scheduling information, so that the second communication device’s understanding of the first COUNT is consistent with that of the first communication device. Furthermore, the first air interface time does not need to be carried in the first data packet, which facilitates the second communication device to decrypt and / or verify the integrity of the first data packet, and helps to control the air interface resource overhead of transmitting the first data packet.
[0010] In conjunction with the first aspect, the communication method further includes: receiving or sending first indication information, wherein the first indication information indicates that the redundancy version RV corresponding to the first data packet is RV0. Correspondingly, in conjunction with the second aspect, the communication method further includes: sending or receiving first indication information, wherein the first indication information indicates that the redundancy version RV corresponding to the first data packet is RV0.
[0011] Based on this scheme, when the first indication information indicates that the RV corresponding to the first data packet is RV0, the first communication device and the second communication device will use the air interface time indicated by the first scheduling information as the first air interface time. There is no need to add additional signaling to indicate the first air interface time, which helps to reduce the signaling overhead in the scheduling process of the first data packet.
[0012] In conjunction with the first aspect, the communication method further includes: receiving a second data packet from the first communication device, the second data packet being a retransmission of the first data packet; performing integrity verification on the second data packet according to a first COUNT, and / or decrypting the second data packet according to the first COUNT. Correspondingly, in conjunction with the second aspect, the communication method further includes: sending a second data packet to the second communication device, the second data packet being a retransmission of the first data packet, and the second data packet being a data packet that is integrity protected and / or encrypted according to the first COUNT.
[0013] Based on this scheme, during the process of exchanging retransmission data packets (second data packets) of the first data packet, the first communication device and the second communication device directly use the first COUNT corresponding to the first data packet as the COUNT corresponding to the second data packet, so as to ensure the consistency of the content between the retransmission data packet and the initial data packet and avoid conflict with the current retransmission mechanism.
[0014] In conjunction with the first aspect, the communication method further includes: receiving or sending second scheduling information, the second scheduling information being used to schedule the second data packet, the second scheduling information indicating a second air interface time; receiving or sending second indication information, the second indication information indicating a first offset and / or a second offset, the first offset being the offset between the first air interface time and the second air interface time, the second offset being the offset between the first HFN and the second HFN, the second HFN being the HFN corresponding to the second air interface time. Correspondingly, in conjunction with the second aspect, the communication method further includes: sending or receiving second scheduling information, the second scheduling information being used to schedule the second data packet, the second scheduling information indicating a second air interface time; receiving or sending second indication information, the second indication information indicating a first offset and / or a second offset, the first offset being the offset between the first air interface time and the second air interface time, the second offset being the offset between the first HFN and the second HFN, the second HFN being the HFN corresponding to the second air interface time.
[0015] Based on this scheme, during the interaction of the second data packet, the first and second communication devices can directly use the second air interface time indicated by the second scheduling information and the first and second offsets indicated by the second indication information as the air interface time corresponding to the second data packet, and use the first superframe number as the superframe number for determining the COUNT corresponding to the second data packet. This approach helps ensure the consistency between retransmitted and initial data packets, preventing interference with the performance of the current retransmission mechanism. Furthermore, when the COUNT corresponding to the second data packet is determined based on the second scheduling and second indication information, regardless of whether the second data packet is a retransmitted data packet, both the first and second communication devices have the same understanding of the COUNT, thus ensuring that the transmission of the second data packet is not limited by the current retransmission mechanism.
[0016] In conjunction with the first aspect, the communication method further includes: receiving a third data packet from the first communication device, the third data packet being a retransmission data packet of the first data packet; performing integrity verification on the third data packet according to a second COUNT, and / or decrypting the third data packet according to the second COUNT, wherein the second COUNT is determined based on the third HFN and the third air interface time corresponding to the third data packet, and the third HFN is the HFN corresponding to the third air interface time. Correspondingly, in conjunction with the second aspect, the communication method further includes: generating a third data packet according to the second COUNT, the third data packet being a retransmission data packet of the first data packet; and sending the third data packet to the second communication device; wherein the second COUNT is determined based on the third HFN and the third air interface time corresponding to the third data packet, and the third HFN is the HFN corresponding to the third air interface time.
[0017] Based on this scheme, during the retransmission of the first data packet, the retransmitted data packet (the third data packet) is equivalent to using it as a new initial data packet. A second COUNT is generated based on the air interface time (third air interface time) corresponding to the third data packet and the third HFN corresponding to the third air interface time to achieve security protection for the third data packet. This avoids the second communication device from having to perform security verification and / or decryption on the received third data packet based on the first COUNT if it fails to obtain the first COUNT, thereby improving the reliability of data transmission.
[0018] In conjunction with the first aspect, the communication method further includes: receiving third scheduling information, the third scheduling information being used to schedule a third data packet, the third scheduling information indicating a third air interface time and the RV corresponding to the third data packet being RV0. Correspondingly, in conjunction with the second aspect, the communication method further includes: sending or receiving third scheduling information, the third scheduling information being used to schedule a third data packet, the third scheduling information indicating a third air interface time and the RV corresponding to the third data packet being RV0.
[0019] Based on this scheme, the first and second communication devices can accurately use the air interface time indicated by the third scheduling information as the third air interface time, so that the second communication device's understanding of the second COUNT is consistent with the first communication device's understanding of the second COUNT. Furthermore, the third air interface time does not need to be carried in the first data packet, nor does it need to set additional indication information or signaling for the third air interface time, which is beneficial for controlling the air interface resource overhead of transmitting the third data packet.
[0020] Combining the first and second aspects, in one possible design, the air interface time includes at least one of the following: frame number FN, subframe number SFN, or time slot number.
[0021] In conjunction with the first aspect, the communication method further includes: receiving or sending third indication information, the third indication information indicating the initial value of the superframe number; and incrementing the superframe number by 1 in the case of frame number FN flipping in the air interface time. Correspondingly, in conjunction with the second aspect, the communication method further includes: sending or receiving third indication information, the third indication information indicating the initial value of the superframe number; and incrementing the superframe number by 1 in the case of frame number FN flipping in the air interface time.
[0022] Based on this scheme, the first communication device and the second communication device maintain the HFN according to the same initial HFN and the same rules. In this case, the first communication device and the second communication device can directly determine the first HFN based on the first air interface time and the maintained HFN. The first data packet does not need to carry the first HFN. On the basis of ensuring that the first communication device and the second communication device have a consistent understanding of the first COUNT, it is beneficial to further reduce the air interface resource overhead of transmitting the first data packet.
[0023] In combination with the first and second aspects, in one possible design, the communication method further includes: receiving a system information block (MIB), the MIB including fourth indication information indicating the current FN; and determining the air interface time based on the current FN.
[0024] Based on this scheme, the first or second communication device can perform air interface time maintenance according to the MIB, which significantly reduces the probability of air interface time asynchrony between the first and second communication devices and improves the reliability of data packet security protection based on air interface time.
[0025] Thirdly, a communication device is provided for implementing various methods. The communication device includes modules, units, or means corresponding to the implementation of the methods, which can be implemented in hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the functions.
[0026] In some possible designs, the communication device may include a processing module and a transceiver module. The processing module can be used to implement the processing functions in any of the above aspects and any possible implementations thereof. The transceiver module may include a receiving module and a transmitting module, respectively used to implement the receiving function and the transmitting function in any of the above aspects and any possible implementations thereof.
[0027] In some possible designs, the transceiver module can consist of transceiver circuits, transceivers, transceivers, or communication interfaces.
[0028] Fourthly, a communication device is provided, comprising: a processor and a memory; the memory being used to store computer instructions that, when executed by the processor, cause the communication device to perform the method described in either aspect.
[0029] Fifthly, a communication device is provided, comprising: a processor and a communication interface; the communication interface being used to communicate with a module outside the communication device; the processor being used to execute a computer program or instructions to cause the communication device to perform the method described in any one of these aspects.
[0030] A sixth aspect provides a communication device comprising: at least one processor; said processor being configured to execute a computer program or instructions stored in a memory to cause the communication device to perform the method described in any of the aspects. The memory may be coupled to the processor, or may be independent of the processor.
[0031] In a seventh aspect, a communication device (e.g., the communication device may be a chip or a chip system) is provided, the communication device including a processor for implementing the functions involved in either the first aspect or the second aspect.
[0032] In some possible designs, the communication device includes a memory for storing necessary program instructions and data.
[0033] In some possible designs, when the device is a chip system, it can be composed of chips or contain chips and other discrete components.
[0034] It is understood that the communication device provided in the third to seventh aspects may be the second communication device in the first aspect, or a module or unit (e.g., a chip, chip system, or circuit) in the second communication device that performs the methods / operations / steps / actions described in the first aspect, or a module or unit that can be used in conjunction with the second communication device, or a logic node, logic module, or software that can implement all or part of the functions of the second communication device; or the communication device may be the first communication device in the second aspect, or a module or unit (e.g., a chip, chip system, or circuit) in the first communication device that performs the methods / operations / steps / actions described in the second aspect, or a module or unit that can be used in conjunction with the first communication device, or a logic node, logic module, or software that can implement all or part of the functions of the first communication device.
[0035] It is understandable that when the communication device provided by any of the third to seventh aspects is a chip, the sending action / function of the communication device can be understood as outputting information, and the receiving action / function of the communication device can be understood as inputting information.
[0036] Eighthly, a computer-readable storage medium is provided that stores a computer program or instructions that, when executed on a communication device, enable the communication device to perform the method described in either the first or second aspect.
[0037] A ninth aspect provides a computer program product containing instructions that, when run on a communication device, enables the communication device to perform the method described in either the first or second aspect.
[0038] A tenth aspect provides a communication system comprising a first communication device and a second communication device. The second communication device is configured to perform the method described in the first aspect and any possible design thereof, and the first communication device is configured to perform the method described in the second aspect and any possible design thereof.
[0039] The technical effects of any of the design methods in aspects three through ten can be found in the technical effects of different design methods in aspects one and two, and will not be repeated here. Attached Figure Description
[0040] Figure 1 A schematic diagram of a wireless protocol stack architecture provided in this application;
[0041] Figure 2 This application provides a flowchart illustrating the implementation of a security protection function.
[0042] Figure 3 A schematic diagram of the structure of a PDCP COUNT provided in this application;
[0043] Figure 4 A flowchart illustrating a HARQ process provided in this application;
[0044] Figure 5 A schematic diagram of an RV version provided in this application;
[0045] Figure 6 A flowchart illustrating a multi-process HARQ provided in this application;
[0046] Figure 7 A schematic diagram illustrating a security protection process based on an SN provided in this application;
[0047] Figure 8 A schematic diagram of the architecture of a communication system provided in this application;
[0048] Figure 9 A schematic diagram of a wireless protocol stack architecture on the base station side provided in this application;
[0049] Figure 10 A schematic diagram of a wireless protocol stack architecture on the terminal side provided in this application;
[0050] Figure 11 A schematic diagram of a chip structure provided in this application;
[0051] Figure 12 A flowchart of a communication method provided in this application;
[0052] Figure 13 A schematic diagram of a COUNT provided for this application;
[0053] Figure 14 A schematic diagram of a data retransmission process provided in this application;
[0054] Figure 15 A schematic diagram of a DCI and data packet provided in this application;
[0055] Figure 16 A schematic diagram of another data retransmission process provided for this application;
[0056] Figure 17A flowchart illustrating the process of maintaining air interface time and HFN provided for this application;
[0057] Figures 18-20 A schematic diagram of the communication device provided in this application. Detailed Implementation
[0058] In the description of this application, unless otherwise stated, " / " indicates that the objects before and after are in an "or" relationship. For example, A / B can mean A or B. "And / or" in this application is merely a description of the relationship between the related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. A and B can be singular or plural.
[0059] In the description of this application, unless otherwise stated, "multiple" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.
[0060] Furthermore, to facilitate a clear description of the technical solutions in the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish identical or similar items with substantially the same function and effect. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, and the terms "first" and "second" are not necessarily different.
[0061] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner to facilitate understanding.
[0062] It is understood that the term "embodiment" used throughout the specification means that a specific feature, structure, or characteristic related to an embodiment is included in at least one embodiment of this application. Therefore, various embodiments throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It is understood that in the various embodiments of this application, the sequence number of each process does not imply the order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0063] It is understood that in this application, "...when" and "if" both refer to the corresponding processing that will be carried out under certain objective circumstances, and are not limited to a specific time, nor do they require a judgment action to be performed during implementation, nor do they imply any other limitations.
[0064] It is understood that some optional features in the embodiments of this application can be implemented independently in certain scenarios without relying on other features, such as the current solution on which they are based, to solve the corresponding technical problems and achieve the corresponding effects. Alternatively, they can be combined with other features as needed in certain scenarios. Correspondingly, the apparatus given in the embodiments of this application can also implement these features or functions, which will not be elaborated here.
[0065] In this application, unless otherwise specified, the same or similar parts between the various embodiments can be referred to each other. In the various embodiments of this application, unless otherwise specified or there is a logical conflict, the terminology and / or descriptions between different embodiments are consistent and can be mutually referenced. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships. The following descriptions of the embodiments of this application do not constitute a limitation on the scope of protection of this application.
[0066] To facilitate understanding of the technical solutions of the embodiments of this application, a brief introduction to the relevant technologies of this application is given below.
[0067] 1. Wireless access network side protocol stack:
[0068] The radio protocol stack on the radio access network side can be divided into the user plane protocol stack and the control plane protocol stack. (See reference) Figure 1 In (a) of this document, the user plane protocol stack between the terminal and the access network equipment mainly includes the Service Data Adaptation Protocol (SDAP) layer, the Packet Data Convergence Protocol (PDCP) layer, the Radio Link Control (RLC) layer, the Media Access Control (MAC) layer, and the Physical (PHY) layer. (See reference) Figure 1 In (b), the control plane protocol stack mainly includes the non-access stratum (NAS) layer, radio resource control (RRC) layer, PDCP layer, RLC layer, MAC layer and PHY layer. The NAS layer is used for the interaction between the terminal and the devices in the core network.
[0069] Among them, the PHY layer belongs to the first layer (also known as layer 1, L1); the MAC layer, RLC layer, PDCP layer and SDAP layer belong to the second layer (also known as layer 2, L2); the RRC layer and NAS layer belong to the third layer (also known as layer 3, L3).
[0070] Currently, the PDCP layer is mainly used to process RRC layer messages on the control plane and Internet Protocol (IP) packets on the user plane. The main functions of the PDCP layer include: security functions (such as data encryption / decryption, data integrity protection / verification), IP header compression / decompression, discarding timed-out user plane packets, user plane data reordering, and user plane data retransmission.
[0071] refer to Figure 2 In (a) of the diagram, during the data encryption / decryption process implemented by the PDCP layer, the PDCP layer at the sender of the data packet takes the data transmission direction identifier, data bearer identifier, key, keystream length, and PDCP packet count as inputs to the security algorithm. The security algorithm calculates a keystream block for encrypting / decrypting the data packet. Then, based on the keystream block, the plaintext block corresponding to the data packet is encrypted to generate a ciphertext block, which is then sent to the receiver. Upon receiving the ciphertext block, the receiver obtains the keystream block using a similar security algorithm, and then decrypts the ciphertext block to retrieve the plaintext block.
[0072] refer to Figure 2In section (b), during the data integrity protection / verification process implemented by the PDCP layer, the PDCP layer at the sender of the data packet takes the data transmission direction identifier, data bearer identifier, key, message content, and PDCP packet count as input to the security algorithm. It calculates the corresponding message authentication code (MAC) for the data packet using the security algorithm and sends this MAC (denoted as mac1) to the receiver by attaching it to the end of the data packet. The PDCP layer at the receiver calculates the MAC corresponding to the received data packet using the security algorithm. If the calculated MAC (denoted as mac2) matches the received MAC (mac1), the data integrity is deemed to have passed the verification.
[0073] The key can be determined through RRC signaling negotiation; the data bearer identifier is used to indicate the type of channel used by the data packet, such as data radio bearer (DRB) and signaling radio bearer (SRB); the data transmission direction identifier is used to indicate whether the data transmission is uplink or downlink.
[0074] refer to Figure 3 In (a) of the diagram, the COUNT, used as input to the security algorithm in the PDCP layer, consists of a high-order hyperframe number (HFN) and a low-order PDCP sequence number (SN). The COUNT value is a 32-bit unsigned value. The PDCP SN is added to the data unit sent from the PDCP layer to the PLC layer. The HFN is maintained by both the transmitter and receiver. If the PDCP SN exceeds its maximum value, the HFN is incremented by 1, indicating a toggle of the PDCP SN. (See reference...) Figure 3 In (b), the length of the PDCP SN may be 12 bits or 18 bits, which can be determined by the upper protocol layer. The PDCP SN is used to indicate the sequence number corresponding to the data unit in the radio bearer.
[0075] 2. Hybrid Automatic Repeat Request (HARQ):
[0076] HARQ is a transmission technology that combines forward error correction (FEC) and automatic repeat-request (ARQ). Its key feature is that the receiving end stores the received data and then performs soft combining of the retransmitted data and the stored data after requesting a retransmission, thereby obtaining a certain combining gain.
[0077] In data transmission using HARQ technology, after receiving data, the receiving end first checks the data for correctness using FEC (Fault-Corrected Error Control) and performs automatic error correction within the capabilities of FEC. If the error level of the received data exceeds the limits of FEC, the ARQ mechanism requests the sending end to retransmit the data. The retransmitted data is then subject to additional restrictions, aiming to minimize the amount of data sent by the sending end while ensuring the receiving end can successfully decode the received data, thereby improving network transmission efficiency.
[0078] Based on the timing of retransmissions, HARQ can be divided into synchronous HARQ and asynchronous HARQ. In synchronous HARQ, retransmissions occur at a fixed time, and the receiver knows the timing of the retransmission in advance; in asynchronous HARQ, retransmissions can occur at any time, and the receiver does not know the timing of the retransmission in advance.
[0079] Based on the resources and MAC order used during retransmission, HARQ can be divided into adaptive HARQ and non-adaptive HARQ. In adaptive HARQ, the MAC order and radio bearer resources used by the service channel during retransmission are different from those used in the initial transmission. In non-adaptive HARQ, the MAC order and radio bearer resources used by the service channel during retransmission are the same as those used in the initial transmission.
[0080] Currently, the most commonly used HARQ is asynchronous adaptive HARQ, see reference. Figure 4In (a) of the diagram, when asynchronous adaptive HARQ is applied during downlink data transmission, the base station needs to indicate the time-domain location for feedback data reception results to the terminal. That is, it needs to indicate the time-domain location for feedback ACK (acknowledgment) and NACK (negative acknowledgment). The base station can send downlink control information (DCI) to the terminal via the physical downlink control channel (PDCCH). The terminal obtains the DCI from the base station through blind detection via the PDCCH and, according to the DCI, receives downlink data and feeds back the data reception results at the specified time-domain location. If downlink data retransmission is required, the base station re-indicates the time-domain location for data transmission and the time-domain location for feedback data reception results to the terminal via the DCI.
[0081] During downlink data transmission, the DCI can include a downlink scheduling delay field (K0) and a downlink HARQ feedback delay field (K1). K0 is used to indicate the resource location (DL grant) at which the terminal receives downlink data on the physical downlink shared channel (PDSCH), and the time interval D1 between the resource location at which the terminal receives the DCI. K1 is used to indicate the resource location at which the terminal feeds back ACK / NACK through the physical uplink control channel (PUCCH) or the physical uplink shared channel (PUSCH), and the time interval D2 between the resource location at which the terminal receives the DCI.
[0082] Similarly, see reference Figure 4 In (b) of the diagram, when asynchronous adaptive HARQ is applied during uplink data transmission, the base station can send a DCI to the terminal via the PDCCH, and the terminal obtains the DCI from the base station through blind detection of the PDCCH. During uplink data transmission, the DCI may include an uplink scheduling delay field (K2), where K2 indicates the time domain position (UL grant) at which the terminal sends uplink data to the base station via the PUSCH, and the interval D3 between this time domain position and the time domain position at which the terminal receives the DCI. In cases where uplink data retransmission is required, the base station, after failing to successfully receive uplink data, reschedules the time domain position for uplink data transmission for the terminal via the DCI.
[0083] It is important to understand that uplink data and downlink data are defined according to the direction of data flow and transmission. Uplink data can be understood as data flowing from the terminal to the base station, and downlink data can be understood as data flowing from the base station to the terminal.
[0084] 3. Redundancy version (RV):
[0085] RV is used to implement incremental redundancy (IR) HARQ transmission. HARQ includes IR-HARQ and chase combining (CC) HARQ, depending on whether the retransmitted bits are identical to the original bits.
[0086] In CC-HARQ mode, the transmitter sends the same data during both initial and retransmission. The receiver does not discard the received data but combines the data received during the initial and retransmissions for decoding and verification, thus obtaining a combining gain. In IR-HARQ mode, the redundant bits transmitted by the transmitter are different in each transmission during the initial and retransmission. These redundant bits are used to implement cyclic redundancy check (CRC) on the data. The receiver combines the redundant bits obtained in each transmission and uses the combined redundant bits to decode and verify the retransmitted data, obtaining a combining gain. Compared to CC-HARQ, IR-HARQ can obtain both the gain from combining and additional information due to the presence of some redundant bits, thus improving decoding performance.
[0087] In IR-HARQ mode, before data transmission occurs, the transmitter encodes the original cell bits using the FEC algorithm to obtain the encoded cell bits and multiple redundant bits. Then, through rate matching or puncturing, a redundant bit group corresponding to each RV is formed.
[0088] For example, refer to Figure 5 In (a) of the diagram, after encoding the original information cell bits using quasi-cyclic low-density parity-check (QC-LDPC) codes, the resulting redundant bits (system bits S and parity bits P) are placed in a ring buffer. Based on rate matching and the ring buffer, the redundant bit group corresponding to each RV can be determined. The starting point of the redundant bits for each RV from RV0 to RV3 can be determined through rate matching. During transmission based on RVs, for each HARQ transmission, data is read out of the ring buffer in RV number order.
[0089] For example, using a finite buffer rate matching method to determine the starting point of redundant bits for different RVs, when the length of the encoded original information cell bit 1 (denoted as BG1) is 66Z (Z being the boost value), the starting points for RV0, RV1, RV2, and RV3 are 0, 17Z, 33Z, and 56Z, respectively; when the length of the encoded original information cell bit 2 (BG2) is 50Z, the starting points for RV0, RV1, RV2, and RV3 are 0, 13Z, 25Z, and 43Z, respectively. It is easy to see that the intervals between the starting points of adjacent RVs are different; that is, the interval between the first redundant bits corresponding to each RV number is non-uniform. This method is beneficial for improving decoding performance.
[0090] The redundant bits included in RV0 to RV3 can be referenced. Figure 5 As can be seen from (b) in the diagram, RV0 and RV3 have self-decoding capabilities. The QC-LDPC code design primarily focuses on the initial transmission performance, so RV0 is preferred for the initial data transmission. When it's uncertain whether the receiver has received the initial data, RV3 is preferred for the first retransmission (because RV3 not only has self-decoding capabilities but also provides a certain incremental redundancy coding performance gain). Otherwise, RV2, with the best incremental redundancy coding performance, is preferred. The specific RV used during data retransmission is indicated by the RV number in the DCI. The RV numbers carried in the DCI are usually issued sequentially according to the number of retransmissions, in the order of 2, 3, and 1.
[0091] Furthermore, during the application of HAQR, the HARQ-related fields in the DCI also include the new data indicator (NDI) flag. The NDI flag is identified by one bit and has two states: 0 and 1. If the NDI flag in the current DCI is different from the NDI flag in the previously received DCI, the terminal determines that the current DCI is scheduling the transmission of an initial data packet. If the NDI flag in the current DCI is the same as the NDI flag in the previously received DCI, the terminal determines that the current DCI is scheduling the transmission of a retransmission data packet.
[0092] 4. Multi-process HARQ:
[0093] To improve data transmission efficiency during HARQ applications, a multi-process HARQ implementation at the PHY layer was designed. (Reference) Figure 6 In example (a), the base station uses a 4-process HARQ to send downlink data to the terminal.
[0094] The HARQ feedback timing is (n+4), where n is the air interface time for the current HARQ process to transmit downlink data packets. That is, after the base station transmits a data packet in time slot 0 through HARQ Process 1, if the data packet transmitted in time slot 0 is successfully received by the terminal (the base station receives an ACK from the terminal), the base station will then transmit the next data packet in time slot 4 through HARQ Process 1. If the data packet transmitted in time slot 4 is not successfully received by the terminal (the base station receives a NACK from the terminal), the base station will retransmit the data packet for the first time in time slot 8 through HARQ Process 1. If the data packet transmitted in time slot 8 is still not successfully received by the terminal, the base station will retransmit the data packet for the second time in time slot 12 through HARQ Process 1, and based on the response information from the terminal, will continue to retransmit the data packet in time slot 16 or transmit a new data packet.
[0095] Similarly, before the base station transmits data packets in time slot 4 through HARQ Process 1, it transmits other data packets in time slots 1, 2 and 3 through HARQ Process 2, HARQ Process 3 and HARQ Process 4 respectively. The data packet transmission logic of each HARQ process can refer to HARQ Process 1.
[0096] In other words, during data transmission using multi-process HARQ, different time slots correspond to different HARQ processes. Data transmission in each time slot corresponding to a single HARQ process follows retransmission logic; that is, a HARQ process transmits the data packets processed by that process sequentially. Data transmission between different HARQ processes is independent, and the data transmission progress of each HARQ process does not affect the others.
[0097] In other words, currently, during data transmission based on the wireless protocol stack, the PDCP layer provides security protection for the upper-layer data packets. The principle behind this security protection is that the PDCP layer determines the corresponding COUNT for the data packet based on the PDCP SN and the HFN maintained by the PDCP layer. Then, based on the corresponding COUNT, a security algorithm is used to perform integrity verification / protection and encryption / decryption of the data packet. Current security protection algorithms cannot provide security protection for data packets at the PDCP layer and its lower layers, such as the RLC layer, MAC layer, and PHY layer.
[0098] Previous research reports from relevant organizations have pointed out that in the event of a denial-of-service (DoS) attack by spoofing uplink scheduling requests (SRs) or buffer status reports (BSRs), the PHY and MAC layers are susceptible to packet tampering or spoofing, and carrier aggregation may lead to user information leakage at the MAC layer. The GSMA has proposed security protection recommendations for MAC layer packets, DCI, uplink control information (UCI), and other PDCP layer and lower-layer packets. (Refer to...) Figure 6 In (b), it is recommended to extend the protected layer of security protection from the layer above the PDCP layer to all protocol layers included in the wireless protocol stack.
[0099] To achieve packet security protection across the entire wireless protocol stack, one possible approach is to move the security functions of the PDCP layer down to between the MAC and PHY layers.
[0100] refer to Figure 7 In example (a), the PHY layer uses a 3-process HARQ, with the SN being the sequence number of the higher-layer data packet. During the transmission of higher-layer data packets in the PHY layer, the sending end transmits each higher-layer data packet to the receiving end through a different HARQ process based on the SN corresponding to the higher-layer data packet. Each HARQ process transmits data at a different air interface time.
[0101] During the initial transmission, HARQ process 0 successfully transmitted the data packet with SN=0, HARQ process 1 failed to transmit the data packet with SN=1, and HARQ process 2 successfully transmitted the data packet with SN=2. In the second transmission, HARQ processes 0 and 2 transmit new data packets, while HARQ process 1 retransmits the data packet corresponding to SN1. During the second transmission, HARQ process 0 successfully transmitted the data packet with SN=3, HARQ process 1 successfully transmitted the data packet with SN=1, and HARQ process 2 successfully transmitted the data packet with SN=4.
[0102] After two rounds of multi-process HARQ transmission, the receiving end successfully received a total of 5 data packets. After sorting the data packets according to their air interface time, the corresponding serial numbers (SNs) for each data packet were 0, 2, 3, 1, and 4. This means that the SNs of the data packets received by the receiving end may not be continuous with the air interface time. Therefore, the security protection function of the PDCP layer is directly moved down from the PDCP layer to between the PHY and MAC layers. To ensure that the receiving end can correctly calculate the COUNT for each data packet, it is necessary to add the corresponding SN to the data packet.
[0103] For example, with SNs added to each channel of the PHY layer, the main channels of the PHY layer are PDCCH, PDSCH, and PUSCH. When security protection functions are implemented through the physical layer, the data processing flow for DCI transmission on the PDCCH channel and data packets transmission on the PDSCH and PUSCH channels can be referenced. Figure 7 (b) In the case of security protection for the PDCCH channel, the base station first performs integrity protection on the DCI, then generates data with physical layer security protection after channel coding, modulation, and framing, and then sends the DCI to the terminal via air interface transmission. After the terminal receives the DCI via air interface reception, it performs integrity verification on the DCI after deframing, demodulation, and channel decoding. In the case of security protection for both the PDSCH and PUSCH channels, the transmitting end encrypts and / or protects the data information, selects redundant version coding according to the number of transmissions of the data information, modulates and frames the encrypted and / or integrity-protected data information according to the selected redundant version coding, generates security-protected data, and sends the security-protected data to the terminal via air interface transmission. After the terminal receives the data via air interface reception, it performs deframing, demodulation, and channel decoding on the data. During the decoding process, if the data is retransmitted data, it is soft-merged before decoding. After successful decoding, the decoded data information is decrypted and / or its integrity is verified.
[0104] Since each channel needs to perform security operations independently, a separate serial number (SN) needs to be added to each channel. The format of the COUNT for each channel after adding the SN can be found by referring to [reference needed]. Figure 7 In (c), the COUNT of the PDCCH channel is determined based on the PDCCH SN and HFN, the COUNT of the PDSCH channel is determined based on the PDSCH SN and HFN, and the COUNT of the PUSCH channel is determined based on the PUSCH SN and HFN. This method requires adding a 12- to 18-bit SN field to each message in the channel, which will significantly impact the air interface performance of the three channels: PDCCH, PDSCH, and PUSCH.
[0105] Based on this, this application provides a communication method. During the interaction of data packets (first data packets) at the lower layer of the PDCP layer between the first communication device and the second communication device, the first communication device can perform integrity protection and / or encryption on the first data packet based on the first COUNT, and the second communication device can perform integrity verification and / or decryption on the first data packet based on the first COUNT, thereby achieving security protection for the data packets at the lower layer of the PDCP layer. This helps reduce the risk of the lower layer data / signaling of the PDCP layer being counterfeited and tampered with. The first COUNT is determined based on the first HFN and the first air interface time corresponding to the first data packet. The first HFN is the HFN corresponding to the first air interface time. That is to say, the determination of the first COUNT mainly depends on the air interface time corresponding to the first data packet. Since the first communication device and the second communication device that communicate over the air interface through the wireless protocol stack will keep the air interface time synchronized, the first air interface time can be determined based on the air interface time of transmitting the first data packet or the scheduling information of scheduling the first data packet when the first data packet is interacting. There is no need to carry the indication information for determining the first COUNT in the first data packet. This helps to achieve security protection for the first data packet without increasing air interface overhead or with a small increase in air interface overhead.
[0106] The technical solutions of this application embodiment can be used in various communication systems, including 3GPP communication systems such as 4th generation (4G) systems (e.g., Long Term Evolution (LTE) systems), 5G systems (e.g., New Radio (NR) systems), LTE and 5G hybrid networking systems, non-terrestrial networks (NTN), device-to-device (D2D) communication systems, vehicle-to-everything (V2X) communication systems, machine-type communication (MTC) systems, Internet of Things (IoT) systems, or other future communication systems. The communication system can also be a non-3GPP communication system; there is no limitation on this.
[0107] The communication systems described above are merely illustrative examples, and are not limited to those described herein. The communication systems provided in this application do not impose any limitations on the solutions described herein. This will be explained uniformly here and will not be repeated below.
[0108] Figure 8 Figure (a) shows a possible, non-limiting system diagram. Figure 8 As shown in (a), the communication system includes a first communication device 801 and a second communication device 802. One of the first communication device 801 and the second communication device 802 is an access network device, and the other is a terminal. The access network device can be a network-side device with wireless transceiver capabilities, used to provide access services to the terminal. The terminal can be a user-side device with wireless transceiver capabilities.
[0109] refer to Figure 8 In (b) of the user plane protocol stack, the SDAP layer is above the PDCP layer, the PDCP layer is above the RLC layer, the RLC layer is above the MAC layer, and the MAC layer is above the physical layer. During user plane data interaction between the terminal and the access network equipment, after the data arrives at the sending end, each protocol layer follows... Figure 8 As shown in (b), data packets are processed sequentially from top to bottom and finally transmitted to the receiving end via the air interface. After receiving the data packets at the air interface, the receiving end processes the data packets in the reverse order of the sending end. The processing of data packets by each protocol layer is implemented by the corresponding multi-functional entity of that protocol layer; for example, the processing of the PDCP layer is implemented by the corresponding PDCP layer entity.
[0110] In one possible scenario, the access network device can be a base station, an evolved NodeB (eNodeB), an access point (AP), a TRP, a next-generation NodeB (gNB), a base station in a future mobile communication system, or an access node in a WiFi system. The access network device can be a macro base station, a micro base station or indoor station, a relay node or donor node, or a radio controller in a CRAN scenario. Optionally, the access network device can also be a server, wearable device, vehicle, or in-vehicle equipment. For example, the access network device in V2X technology can be a roadside unit (RSU). All or part of the functions of the access network device in this application can also be implemented through software functions running on hardware, or through virtualization functions instantiated on a platform (e.g., a cloud platform). The access network device in this application can also be a logical node, logical module, or software capable of implementing all or part of the access network device functions.
[0111] In another possible scenario, multiple access network devices collaborate to assist the terminal in achieving wireless access, with each device performing a portion of the base station's functions. For example, the access network devices can be a central unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be separate entities or included in the same network element, such as a baseband unit (BBU). The RU can be included in radio frequency equipment or radio frequency units, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).
[0112] As the first possible implementation, refer to Figure 9 In (a), CU can be used to implement the functions of RRC layer, SDAP layer and PDCP layer, and DU can be used to implement the functions of RLC layer, MAC layer and PHY layer, and communicate with radio frequency unit through PHY layer.
[0113] As a second possible implementation, see reference Figure 9 In (b), CU is used to implement the functions of RRC layer, SDAP layer and PDCP layer, DU is used to implement the functions of RLC layer, MAC layer, security layer and PHY layer, and is connected to the radio frequency unit through PHY layer. The PDCP layer can implement security functions or not.
[0114] In other words, the security functions of the PDCP layer can be implemented in a security layer set between the MAC layer and the PHY layer, or the security functions can be implemented in a separate security layer outside the PDCP layer. The security layer can be a new protocol layer predefined by the protocol.
[0115] Optionally, the security layer may be used solely to implement security functions (integrity verification / protection and / or encryption / decryption functions), or the security layer may implement security functions and functions such as packet assembly, packet segmentation, and header addition.
[0116] As a third possible implementation, see reference Figure 9In (c), CU is used to implement the functions of RRC layer, SDAP layer and PDCP layer, DU is used to implement the functions of RLC layer, MAC layer and PHY layer, and is connected to the radio frequency unit through PHY layer. The PDCP layer may or may not have security functions. The security functions are implemented by the bottom layer of MAC layer.
[0117] In other words, the security functions of the PDCP layer are implemented at the lower level of the MAC layer, or security functions are added at the lower level of the MAC layer.
[0118] As a fourth possible implementation, see reference Figure 9 In (d), CU is used to implement the functions of RRC layer, SDAP layer and PDCP layer, and DU is used to implement the functions of RLC layer, MAC layer and PHY layer, and is connected to the radio frequency unit through PHY layer. PDCP layer may or may not have security functions. Security functions are implemented by the upper layer of PHY layer.
[0119] In other words, the security functions of the PDCP layer are implemented at the upper layer of the PHY layer, or security functions are added at the upper layer of the PHY layer.
[0120] In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, in an ORAN system, CU can also be called O-CU (open CU), DU can also be called O-DU, CU-CP can also be called O-CU-CP, CU-UP can also be called O-CU-UP, and RU can also be called O-RU. For ease of description, this application uses CU, CU-CP, CU-UP, DU, and RU as examples. Any of the units among CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented through software modules, hardware modules, or a combination of software and hardware modules.
[0121] A terminal can also be referred to as a terminal device, user equipment (UE), mobile station, mobile terminal, etc. Terminals can be widely used in various scenarios, such as D2D, V2X communication, MTC, IoT, virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, smart cities, etc. Terminals can be mobile phones, tablets, computers with wireless transceiver capabilities, wearable devices, vehicles, drones, helicopters, airplanes, ships, robots, robotic arms, smart home devices, etc. The embodiments of this application do not limit the device form of the terminal.
[0122] As the first possible implementation, refer to Figure 10 In (a), the wireless protocol stack on the terminal side may include an RRC layer, an SDAP layer, a PDCP layer, an RLC layer, a MAC layer, a security layer, and a PHY layer, with the PHY layer connected to the radio frequency unit.
[0123] In other words, the security functions of the PDCP layer can be implemented in a security layer set between the MAC layer and the PHY layer, or the security functions can be implemented in a separate security layer outside the PDCP layer. The security layer can be a new protocol layer predefined by the protocol.
[0124] Optionally, the security layer may be used solely to implement security functions (integrity verification / protection and / or encryption / decryption functions), or the security layer may implement security functions and functions such as packet assembly, packet segmentation, and header addition.
[0125] As a second possible implementation, see reference Figure 10 In (b), the wireless protocol stack on the terminal side may include an RRC layer, an SDAP layer, a PDCP layer, an RLC layer, a MAC layer, and a PHY layer. The PHY layer is connected to the radio frequency unit. The PDCP layer may or may not have security functions. The security functions are implemented by the lower layer of the MAC layer.
[0126] In other words, the security functions of the PDCP layer are implemented at the lower level of the MAC layer, or security functions are added at the lower level of the MAC layer.
[0127] As a third possible implementation, see reference Figure 10 In (c), the wireless protocol stack on the terminal side may include an RRC layer, an SDAP layer, a PDCP layer, an RLC layer, a MAC layer, and a PHY layer. The PHY layer is connected to the radio frequency unit. The PDCP layer may or may not have security functions. The security functions are implemented by the upper layer of the PHY layer.
[0128] In other words, the security functions of the PDCP layer are implemented at the upper layer of the PHY layer, or security functions are added at the upper layer of the PHY layer.
[0129] In one possible implementation, the security layer is located at L1, or the security functions are implemented above the PHY layer. The chip architecture diagrams of the first and / or second communication devices can be referenced. Figure 11In (a), the L1 layer input / output interfaces of the chip include a common public radio interface (CPRI) and an enhanced common public radio interface (eCPRI). eCPRI is used to connect the transceiver module and a massive multiple input multiple output (MMIMO) antenna array, while CPRI is used to connect the transceiver module and radio equipment (RE). The L1 layer also includes a digital signal processor (DSP) for implementing DCI security functions, processing modules for implementing PDSCH and PUSCH security functions, and a control module for the L1 layer. The L2 layer includes processing modules for implementing PDCP layer packet compression and header addition functions, RLC layer functions, and MAC layer functions, respectively. The L3 layer includes processing modules for implementing SDAP functions and PDCP layer PDCP SN allocation functions.
[0130] It is worth mentioning that the processing module that implements the PDSCH and PUSCH security functions can be an additional new processing module or a DSP.
[0131] In another possible implementation, the security layers are located at L1 and L2, or, in the case where the security functions are jointly implemented by the upper layer of the PHY layer and the lower layer of the MAC layer, the chip architecture diagram of the first communication device and / or the second communication device can be referenced. Figure 11 (b) The input / output interfaces in Layer 1 include CPRI and eCPRI. Layer 1 contains a control module, a transceiver module, and a DSP for implementing DCI security functions. Layer 2 includes processing modules for implementing PDCP layer packet compression and header addition functions, RLC layer functions, and MAC layer functions. The MAC layer processing module also implements PDSCH and PUSCH security functions. Layer 3 includes processing modules for implementing SDAP functions and PDCP layer PDCP SN allocation functions.
[0132] refer to Figure 11In step (c), the process for implementing data packet security protection mainly includes: determining whether to enable security protection based on security instructions; if security protection is enabled, determining the implementation method of security protection, such as whether data packets need to be encrypted / decrypted, and / or whether data packets need to be integrity protected / verified. Then, based on the determined security protection implementation method, performing security protection operations on the physical layer data, and finally transmitting the data packets after security protection operations to the next module.
[0133] It should be noted that the communication system described in the embodiments of this application is for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and does not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0134] The following is combined Figure 8 The communication system shown uses the interaction between the first communication device and the second communication device as an example to describe the communication method provided in the embodiments of this application. It should be noted that in the following embodiments of this application, the message names, parameter names, or information names between the first communication device and the second communication device are just examples, and other names may be used in other embodiments. The method provided in this application is not specifically limited in this regard.
[0135] It is understood that in the embodiments of this application, the first communication device and the second communication device may execute some or all of the steps in the embodiments of this application. These steps or operations are merely examples, and the embodiments of this application may also execute other operations or variations thereof. Furthermore, the various steps may be executed in different orders as presented in the embodiments of this application, and it is not necessarily necessary to execute all the operations in the embodiments of this application.
[0136] It is understood that this application uses the first and second communication devices as examples to illustrate the execution of the interaction, but this application does not limit the execution of the interaction. For example, the method executed by the first communication device in this application can also be executed by a module (e.g., a chip, chip system, or processor) applied to the first communication device, or by a logic node, logic module, or software capable of implementing all or part of the functions of the first communication device; similarly, the method executed by the second communication device in this application can also be executed by a module (e.g., a chip, chip system, or processor) applied to the second communication device, or by a logic node, logic module, or software capable of implementing all or part of the functions of the second communication device.
[0137] Furthermore, in this application, "sending information" can be understood as one device sending information to another device, or it can also be understood as one logic module within a device sending information to another logic module. For example, "the first communication device sending information" can be understood as the first communication device sending information to another device (such as the second communication device), or it can be understood as logic module 1 (such as the processing module) in the first communication device sending information to logic module 2 (such as the transceiver module) in the first communication device.
[0138] In this application, "receiving information" can be understood as one device receiving information from another device, or it can also be understood as a logic module within a device receiving information from another logic module. For example, "the second communication device receiving information" can be understood as the second communication device receiving information from another device (such as the first communication device), or it can be understood as logic module 1 (such as a processing module) in the second communication device receiving information from logic module 2 (such as a transceiver module) in the second communication device.
[0139] In this application, the phrase "sending information to... (e.g., a second communication device)" or the related illustrations in the accompanying drawings can be understood as the destination of the information being the second communication device. This can include sending information directly or indirectly to the second communication device. Similarly, the phrase "receiving information from... (e.g., a first communication device)," "receiving information from... (e.g., a first communication device)," or "receiving information sent (e.g., by the first communication device)," or the related illustrations in the accompanying drawings, can be understood as the source of the information being the first communication device. This can include receiving information directly or indirectly from the first communication device. Information may undergo necessary processing between the source and destination, such as format changes, but the destination can understand the valid information from the source. Similar expressions in this application can be interpreted similarly, and will not be elaborated further here.
[0140] See Figure 12 , Figure 12 A flowchart of a communication method provided in this application embodiment, the method may include the following steps:
[0141] S1201, The first communication device generates a first data packet based on the first COUNT. The first data packet is a data packet from the lower layer of the PDCP layer.
[0142] The first COUNT is determined based on the first HFN and the first air interface time corresponding to the first data packet. The first HFN is the HFN corresponding to the first air interface time.
[0143] For example, the first air interface time can be understood as the air interface time when transmitting the first data packet, or it can also be understood as the air interface time indicated by the scheduling information for scheduling the first data packet. The first HFN can be understood as the value of the HFN maintained by the first communication device when the air interface time is the first air interface time. Furthermore, the value of HFN is maintained based on the initial value of HFN and the air interface time. The initial value setting and specific maintenance method of HFN are described in the later embodiments and will not be repeated here.
[0144] As one possible implementation, the format of COUNT can be referenced. Figure 13 In (a), COUNT can be an unsigned value of N bits consisting of HFN and air interface time, where N is an integer greater than or equal to 1, for example, N equals 5, 8, 15, 20, 32, 45, 56, etc.
[0145] Figure 13 (a) uses HFN as the first half of COUNT and air interface time as the second half of COUNT as an example. In actual application, the order of HFN and air interface time can be swapped, with air interface time as the first half of COUNT and HFN as the second half of COUNT, without restriction.
[0146] In one possible implementation, the air interface time includes at least one of the following: frame number FN, subframe number SFN, or slot number (slot Num).
[0147] In this context, FN is a parameter that identifies the current air interface time during air interface transmission between the base station and the terminal. Its value ranges from 0 to 1023, and it is transmitted from the base station to the terminal via the physical broadcast channel (PBCH). Increasing the FN value by 1 represents an increase of 10 milliseconds (ms) in the air interface time. SFN identifies which subframe the current air interface time falls within within an FN. Its value ranges from 0 to 9, and increasing the SFN value by 1 represents an increase of 1 ms in the air interface time. The timeslot number identifies which timeslot the current air interface time falls within within an SFN. The number of timeslots within each SFN and the corresponding time length of each timeslot are determined by the frame structure of the air interface. For example, in a 30K subcarrier scenario, there are 2 timeslots within an SFN, and the timeslot number is either 0 or 1. Increasing the timeslot number by 1 represents an increase of 0.5 ms in the air interface time.
[0148] Typically, during air interface transmission, the current time of the air interface can be recorded in units of one time slot by combining FN, SFN and time slot number. The maximum effective duration that can be recorded is 10.24 seconds.
[0149] For example, taking the air interface time, which includes FN, SFN, and slot number, as an example, the format of COUNT can be found in [reference needed]. Figure 13 In (b), HFN is the first half of COUNT, and the FN, SFN and time slot number included in the air interface time are the second half of COUNT.
[0150] It is worth mentioning that, Figure 13 (b) is an example of the air interface time being arranged in sequence as FN, SFN and time slot number. In the application process, the order of FN, SFN and time slot number can also be changed. For example, the order of each element in the air interface time can be changed to time slot number, FN and SFN, or SFN, time slot number and FN, etc., without restriction.
[0151] In addition, COUNT serves as a unique identifier for data packets in the key stream block generated by the security algorithm. COUNT can also be called a unique identifier (ID) for the data packet, a data packet number, or a sequence number (Nonce) for the data packet. There are no restrictions on the naming of COUNT.
[0152] The process of generating the first data packet based on the first COUNT can be understood as performing integrity protection and / or encryption on the data to be transmitted based on the first COUNT to obtain the first data packet.
[0153] For example, the first data packet is obtained by performing integrity protection on the data to be transmitted according to the first COUNT and encrypting the data to be transmitted according to the first COUNT; or, the first data packet is obtained by performing integrity protection on the data to be transmitted according to the first COUNT; or, the first data packet is obtained by encrypting the data to be transmitted according to the first COUNT.
[0154] As one possible implementation, when the first data packet is a DCI data packet, the first air interface time is the air interface time for transmitting the first data packet. Generating the first data packet according to the first COUNT can be understood as generating the first data packet after performing integrity protection on the DCI information to be transmitted according to the first COUNT.
[0155] As another possible implementation, if the first data packet is a PDSCH data packet or a PUSCH data packet, the first air interface time can be either the air interface time when transmitting the first data packet or the air interface time indicated by the scheduling information for scheduling the first data packet. Generating the first data packet based on the first COUNT can be achieved by encrypting and / or protecting the integrity of the uplink or downlink data to be transmitted based on the first COUNT.
[0156] In this embodiment, the implementation of integrity protection and encryption of the data to be transmitted based on the first COUNT is similar to the implementation of integrity protection and encryption of data packets based on COUNT and security algorithms in the PDCP layer in the previous embodiment. The relevant descriptions in the previous embodiment can be referred to. The difference lies in the different way of determining COUNT, which will not be repeated here.
[0157] Here, the first data packet is the initial data packet. For example, the first data packet being the initial data packet can be understood as the first interaction between the first communication device and the second communication device using the first data packet, or the content of the first data packet being different from the content of the data packets transmitted before the first data packet is transmitted.
[0158] For example, the first data packet being a data packet of the lower layer of the PDCP layer can be understood as the first data packet being a data packet generated by the PDCP layer or the lower protocol layer of the PDCP layer, or it can also be understood as the first data packet being a service data unit (SDU) received by the lower protocol layer of the PDCP layer, or it can also be understood as the first data packet being an upper protocol data unit (PDU) generated by the lower protocol layer of the PDCP layer after implementing the protocol layer function.
[0159] For example, if the wireless protocol stack does not include a new security layer, or if the wireless protocol stack includes a new security layer but the security layer does not have packet assembly or packet segmentation capabilities, the first data packet can be a data packet generated by the PDCP layer, a data packet generated by the RLC layer, a data packet generated by the MAC layer, or a data packet generated by the PHY layer; or, the first data packet can also be an RRC PDU (also known as a PDCP SDU), a PDCP PDU (also known as an RLC SDU), a MAC SDU, a MAC PDU (also known as a PHY SDU), or a PHY PDU (such as a DCI), etc.
[0160] For example, if the wireless protocol stack includes a new security layer, and the security layer has packet assembly or packet segmentation functions, the first data packet can be a data packet generated by the PDCP layer, a data packet generated by the RLC layer, a data packet generated by the MAC layer, a data packet generated by the security layer, or a data packet generated by the PHY layer; or, the first data packet can also be an RRC PDU (also known as a PDCP SDU), a PDCP PDU (also known as an RLC SDU), a MAC SDU, a MAC PDU (also known as a security layer SDU), a security layer PDU (also known as a PHY SDU), or a PHY PDU (such as a DCI), etc.
[0161] For ease of description, the following embodiments of this application use PHY PDU as an example for illustration. In the application process, the first data packet can also be PDU or SDU of other protocol layers.
[0162] Step S1202: The first communication device sends a first data packet to the second communication device. Correspondingly, the second communication device receives the first data packet from the first communication device.
[0163] For example, after determining the air interface time for sending the first data packet to the second communication device, the first communication device sends the first data packet to the second communication device during the air interface time. The second communication device can receive the first data packet from the first communication device during the air interface time according to pre-received scheduling information or periodic channel scanning.
[0164] For example, if the first data packet is a DCI data packet, the first communication device sends the first data packet via PDCCH, and the second communication device obtains the first data packet through blind detection via PDCCH. As another example, if the first data packet is a PDSCH data packet or a PUSCH data packet, the second communication device obtains the first data packet at the air interface time indicated by the pre-received or transmitted scheduling information.
[0165] Step S1203: The second communication device performs a security check on the first data packet based on the first COUNT.
[0166] The meaning of the first COUNT can be referred to the relevant description in the foregoing embodiments, and will not be repeated here. In determining the first COUNT, the second communication device may use the air interface time of receiving the first data packet or the air interface time indicated by the scheduling information of scheduling the first data packet as the first air interface time, and use the value of the maintained HFN at the first air interface time as the first HFN.
[0167] For example, during the process of acquiring the first COUNT, if the first data packet is a DCI data packet, the second communication device can use the air interface time of receiving the first data packet as the first air interface time; if the first data packet is a PDSCH data packet or a PUSCH data packet, the first air interface time can be either the air interface time when the first data packet is received or the air interface time indicated by the scheduling information of the first data packet.
[0168] For example, performing security checks on the first data packet based on the first COUNT can be understood as decrypting the first data packet based on the first COUNT; or performing integrity checks on the first data packet based on the first COUNT; or performing integrity checks and decryption on the first data packet based on the first COUNT.
[0169] As one possible implementation, when the first data packet is a DCI data packet, the first air interface time is the air interface time for transmitting the first data packet. Performing security checks on the first data packet based on the first COUNT can be understood as performing integrity checks on the first data packet based on the first COUNT.
[0170] As another possible implementation, if the first data packet is a PDSCH data packet or a PUSCH data packet, the first air interface time can be either the air interface time when transmitting the first data packet or the air interface time indicated by the scheduling information for scheduling the first data packet. Performing security checks on the first data packet based on the first COUNT can involve decrypting and / or verifying the integrity of the first data packet based on the first COUNT.
[0171] In this embodiment, the implementation of integrity verification of the first data packet based on the first COUNT and the decryption of the first data packet based on the first COUNT is similar to the implementation of integrity verification and decryption of data packets based on COUNT and security algorithms in the PDCP layer in the previous embodiment. Please refer to the relevant descriptions in the previous embodiments, and they will not be repeated here.
[0172] It is worth noting that, since the terminal synchronizes its air interface time with the base station based on the system information broadcast by the base station during random access, the first communication device and the second communication device have the same understanding of the first air interface time corresponding to the first data packet. Furthermore, if the first and second communication devices maintain the HFN according to the same method and the initial value of the HFN is the same, then the first and second communication devices also have the same understanding of the first HFN corresponding to the first air interface time for the first data packet. In other words, the COUNT used by the first communication device in generating the first data packet and the COUNT used by the second communication device in performing integrity verification and / or decryption of the first data packet are the same.
[0173] Based on this scheme, this application provides a communication method. During the interaction of data packets (first data packets) at the lower layer of the PDCP layer between the first communication device and the second communication device, the first communication device can perform integrity protection and / or encryption on the first data packet based on the first COUNT, and the second communication device can perform integrity verification and / or decryption on the first data packet based on the first COUNT, thereby achieving security protection for the data packets at the lower layer of the PDCP layer. This helps reduce the risk of the lower layer data / signaling of the PDCP layer being counterfeited and tampered with. The first COUNT is determined based on the first HFN and the first air interface time corresponding to the first data packet. The first HFN is the HFN corresponding to the first air interface time. That is to say, the determination of the first COUNT mainly depends on the air interface time corresponding to the first data packet. Since the first communication device and the second communication device that communicate over the air interface through the wireless protocol stack will keep the air interface time synchronized, the first air interface time can be determined based on the air interface time of transmitting the first data packet or the scheduling information of scheduling the first data packet when the first data packet is interacting. There is no need to carry the indication information for determining the first COUNT in the first data packet. This helps to achieve security protection for the first data packet without increasing air interface overhead or with a small increase in air interface overhead.
[0174] The overall process of the communication method provided in this application has been described above. The specific implementation of each step is described below.
[0175] In one possible implementation, before step S1201, the first communication device sends or receives first scheduling information. Correspondingly, the second communication device receives or sends the first scheduling information. The first scheduling information is used to schedule the first data packet and indicates a first air interface time.
[0176] For example, when the first communication device is a base station and the second communication device is a terminal, the first communication device sends the first scheduling information and the second communication device receives the first scheduling information; when the first communication device is a terminal and the second communication device is a base station, the first communication device receives the first scheduling information and the second communication device sends the first scheduling information.
[0177] Here, the first scheduling information can be understood as the DCI for scheduling the first data packet, or it can be understood as the information contained in the field of the DCI for scheduling the first data packet used to indicate the air interface time. The first scheduling information indicating the first air interface time can be understood as the first air interface time being determined based on the air interface time indicated by the first scheduling information.
[0178] Optionally, determining the first air interface time based on the air interface time indicated by the first scheduling information includes the following two possible implementation methods:
[0179] Method 1: The first air interface time is the air interface time indicated by the first scheduling information.
[0180] For example, take the first scheduling information as DCI. DCI contains K0 field and K2 field. The air interface time indicated by the first scheduling information can be understood as the air interface time with a time domain interval length of T between it and the air interface time of transmitting DCI. T is the time domain interval length indicated by K0 field, or T is the time domain interval length indicated by K2 field.
[0181] In other words, the first air interface time is the air interface time with a time domain interval length equal to T between the air interface time of the DCI that schedules the first data packet.
[0182] Method 2: The interval between the first air interface time and the air interface time indicated by the first scheduling information is equal to the air interface time offset value.
[0183] For example, taking the first scheduling information as DCI, the DCI includes a K0 field, a K2 field, and a preset offset field. The preset offset field is used to indicate the air interface time offset value (denoted as T1). The air interface time indicated by the first scheduling information (denoted as T2) can be understood as the air interface time with a time domain interval length of T between it and the air interface time of transmitting the DCI. T is the time domain interval length indicated by the K0 field, or T is the time domain interval length indicated by the K2 field.
[0184] For example, the air interface time offset value can be a value greater than or equal to 0, such as 0, 2, 4, 7, or 9.
[0185] In other words, the first air interface time is the air interface time with a time-domain interval length equal to T1 between it and T2. When the air interface time offset is 0, the first air interface time is the air interface time indicated by the first scheduling information. When the air interface time offset is greater than 0, the time-domain interval length between the first air interface time and T2 is equal to T1. This can be understood as the first air interface time being earlier than T2 and the time-domain interval length between it and T2 being equal to T1; or it can be understood as the first air interface time being later than T2 and the time-domain interval length between it and T2 being equal to T1.
[0186] In addition, the air interface time offset value can be any value. For example, if the first air interface time is earlier than T2, the air interface time offset value is negative, and if the first air interface time is later than T2, the air interface time offset value is positive; or, if the first air interface time is earlier than T2, the air interface time offset value is positive, and if the first air interface time is later than T2, the air interface time offset value is negative.
[0187] The preset offset field can be a field predefined in the protocol, or it can be a field pre-agreed upon by the first communication device and the second communication device.
[0188] It is worth mentioning that the above embodiment is illustrated by taking the example that the preset offset field indicating the air interface time offset value is located in the first scheduling information. In the application process, the air interface time offset value can also be predefined by the protocol or pre-agreed by the first communication device and the second communication device, or it can also be carried in other indication information exchanged between the first communication device and the second communication device, without limitation.
[0189] In one possible implementation, before step S1201, the first communication device sends or receives first indication information. Correspondingly, the second communication device receives or sends the first indication information. The first indication information is used to determine whether the first air interface time is the air interface time indicated by the first scheduling information.
[0190] The implementation method of the first communication device and the second communication device interacting with the first instruction information is similar to the implementation method of the first communication device and the second communication device interacting with the first scheduling information. Please refer to the relevant description in the foregoing embodiments, and it will not be repeated here.
[0191] For example, the first indication information is used to determine whether the first air interface time is the air interface time indicated by the first scheduling information. This can be understood as the first indication information being used to indicate whether the first data packet is an initial transmission data packet. The meaning of the initial transmission data packet can be referred to the relevant description in the foregoing embodiments. Alternatively, it can also be understood as the first indication information being used to indicate whether the RV corresponding to the first data packet is RV0.
[0192] As one possible implementation, the first indication information is carried in the NDI identifier in the DCI.
[0193] When the first indication information is carried on the NDI identifier, the first communication device and the second communication device detect whether the current NDI identifier and the NDI identifier in the previous DCI are in the same state. When the NDI identifier and the NDI identifier in the previous DCI are in different states, the first indication information indicates that the first data packet is the initial data packet, or in other words, the first indication information indicates that the first air interface time is the air interface time indicated by the first scheduling information.
[0194] As another possible implementation, the first indication information is carried in the RV field of the DCI.
[0195] When the first indication information is carried in the RV field, the first communication device and the second communication device detect the RV value corresponding to the RV field in the DCI of the first data packet. When the RV field is set to 0, the first indication information indicates that the RV corresponding to the first data packet is RV0, or in other words, the first indication information indicates that the first air interface time is the air interface time indicated by the first scheduling information.
[0196] Optionally, the first indication information and the first scheduling information can be carried in the same message. For example, the first indication information can be carried in the RV field or NDI identifier in the DCI, and the first scheduling information can be carried in the K0 field and / or K2 field in the DCI. When the first indication information and the first scheduling information are carried in the same message, it is beneficial to reduce the signaling overhead in the process of scheduling the first data packet, and it can minimize the amount of protocol modification caused by implementing data packet security protection based on the first COUNT.
[0197] In one possible implementation, the first communication device sends a retransmission data packet of the first data packet to the second communication device. Correspondingly, the second communication device receives the retransmission data packet of the first data packet from the first communication device. The first and second communication devices achieve secure interaction of information corresponding to the first data packet through the retransmission data packet.
[0198] For example, if the second communication device fails to decode the first data packet, the first communication device sends a retransmission data packet of the first data packet to the second communication device; or, if the second communication device fails to demodulate the first data packet, the first communication device sends a retransmission data packet of the first data packet to the second communication device; or, if the second communication device fails to receive the first data packet, the first communication device sends a retransmission data packet of the first data packet to the second communication device.
[0199] The secure interaction of information corresponding to the first data packet between the first communication device and the second communication device through the retransmission of the first data packet can include the following two possible implementation methods:
[0200] Method 1: The first communication device sends a second data packet to the second communication device. The second data packet is a retransmission of the first data packet. Correspondingly, the second communication device receives the second data packet from the first communication device and performs a security check on the second data packet according to the first COUNT.
[0201] For example, the second data packet being a retransmission of the first data packet can be understood as the second data packet having the same content as the first data packet, and the second data packet being a data packet that is protected for integrity and / or encrypted according to the first COUNT, that is, the second data packet and the first data packet are completely identical; or, it can also be understood as the NDI identifier in the DCI that schedules the second data packet being set to the same state as the NDI identifier in the DCI that schedules the first data packet.
[0202] For example, the second communication device performing security detection on the second data packet based on the first COUNT can be understood as performing integrity verification on the second data packet based on the first COUNT, and / or decrypting the second data packet based on the first COUNT.
[0203] The implementation method of the first communication device generating the second data packet based on the first COUNT is similar to the implementation method of the first communication device generating the first data packet based on the first COUNT in the previous embodiment. Please refer to the relevant description in the previous embodiment, and it will not be repeated here. Similarly, the implementation method of the second communication device performing security detection on the second data packet based on the first COUNT is similar to the implementation method of the second communication device performing security detection on the second data packet based on the first COUNT in the previous embodiment. Please refer to the relevant description in the previous embodiment, and it will not be repeated here.
[0204] Protecting the second data packet based on the first COUNT can include the following two possible implementation methods:
[0205] Method 1: Protect the second data packet by using the pre-stored first COUNT.
[0206] In other words, after obtaining the first COUNT corresponding to the first data packet according to preset rules, the first communication device and the second communication device record the first COUNT corresponding to the first data packet. If the second communication device fails to parse the first data packet, the first communication device generates a second data packet according to the first COUNT corresponding to the first data packet. After receiving the retransmission data packet (second data packet) of the first data packet according to the scheduling information, the second communication device performs security detection on the second data packet according to the first COUNT corresponding to the first data packet.
[0207] The preset rules can be understood as data processing rules predefined in the protocol, or as data processing rules pre-agreed upon by the first communication device and the second communication device.
[0208] For example, taking the first communication device as the base station and the second communication device as the terminal. The first data packet is an initial transmission data packet in the PDSCH channel, as shown in the reference. Figure 14 The base station sends a message containing a DCI and a PDSCH data packet (the first data packet) to the terminal at the air interface time (FN=21, SFN=0, timeslot number=0). The DCI indicates the air interface time of the first data packet as (FN=21, SFN=0, timeslot number=0). The HFN corresponding to the air interface time (FN=21, SFN=0, timeslot number=0) is 0. Since both the DCI and the first data packet are initial transmission data packets, the HFN in the first COUNT corresponding to both the DCI and the first data packet is 0, and the air interface time is FN=21, SFN=0, timeslot number=0.
[0209] After correctly receiving the DCI according to the first COUNT, the terminal receives the first data packet at the air interface time (FN=21, SFN=0, timeslot number=0) according to the DCI's indication, and performs operations such as decoding the first data packet. If the terminal cannot correctly decode or demodulate the first data packet, it sends a NACK to the base station. After receiving the NACK from the terminal, the base station generates a second data packet according to the first COUNT corresponding to the first data packet, and sends a message containing the new DCI and the second data packet to the terminal at the new air interface time (FN=21, SFN=4, timeslot number=0). The DCI indicates that the air interface time of the second data packet is FN=21, SFN=4, and timeslot number=0.
[0210] Since the HFN corresponding to the air interface time (FN=21, SFN=4, timeslot number=0) is also 0, the HFN in the first COUNT corresponding to this DCI and the second data packet is 0. This DCI is a new DCI transmitted for the first time, so the corresponding air interface time is FN=21, SFN=4, timeslot number=0. The second data packet is a retransmission of the first data packet, so the air interface time in the COUNT corresponding to the second data packet is FN=21, SFN=0, timeslot number=0. After the terminal correctly receives the DCI according to the COUNT corresponding to the DCI, it receives the second data packet at air interface time FN=21, SFN=4, timeslot number=0. Based on the DCI, it determines that the second data packet is a retransmission of the first data packet. After successfully decoding the second data packet, it sends an ACK back to the base station and performs security checks on the second data packet according to the COUNT (first COUNT) corresponding to the first data packet.
[0211] Furthermore, the above description uses the first communication device as a base station as an example. When the first communication device is a terminal, if the base station fails to decode or demodulate the first data packet, it will send a DCI (Digital Instruction Code) to the terminal instructing the retransmission of the first data packet. After receiving the DCI, the terminal sends a second data packet generated based on the first COUNT to the base station according to preset rules at the data packet transmission time indicated by the DCI. The base station then performs security checks on the second data packet based on the first COUNT. The specific implementation method is similar to that in the above embodiments and will not be repeated here.
[0212] Based on this scheme, during the process of exchanging the first data packet and the second communication device transmitting the data packet (second data packet), the first communication device implements security protection for the second data packet based on the first COUNT corresponding to the first data packet. This ensures that the retransmission of the first data packet, which is protected by the first COUNT, complies with the requirements of the HARQ mechanism in the current protocol, thereby reducing the impact of the security protection function based on the first COUNT on the HARQ mechanism.
[0213] Method 2: Based on the second scheduling information and the second instruction information, the second data packet is protected by the first COUNT.
[0214] As one possible implementation, if the second communication device fails to decode or demodulate the first data packet, the first communication device sends or receives second indication information and second scheduling information. Correspondingly, the second communication device receives or sends the second indication information and the second scheduling information.
[0215] The implementation method of the first communication device and the second communication device interacting with the second scheduling information and the second instruction information is similar to the implementation method of the first communication device and the second communication device interacting with the first scheduling information and the first instruction information. Please refer to the relevant description in the foregoing embodiments, and it will not be repeated here.
[0216] The second scheduling information is used to schedule the second data packet, and the second scheduling information indicates the second air interface time.
[0217] For example, the second scheduling information can be understood as the DCI for scheduling the second data packet, or it can be understood as the information contained in the field of the DCI for scheduling the second data packet used to indicate the second air interface time. The second scheduling information indicating the second air interface time can be understood as the second air interface time being determined based on the air interface time indicated by the second scheduling information.
[0218] The implementation method of the second scheduling information indicating the second air interface time is similar to the implementation method of the first scheduling information indicating the first air interface time. Please refer to the relevant description in the foregoing embodiments, and it will not be repeated here.
[0219] The second indication information is used to determine the COUNT corresponding to the second data packet.
[0220] For example, the second indication information indicates a first offset (timer offset) and / or a second offset. The air interface time in the COUNT corresponding to the second data packet is determined based on the second air interface time and the first offset, or the air interface time in the COUNT corresponding to the second data packet is determined based on the second air interface time, the first offset, and the second offset.
[0221] Wherein, the first offset is the offset between the first air interface time and the second air interface time; the second offset is the offset between the first HFN and the second HFN, and the second HFN is the HFN corresponding to the second air interface time.
[0222] For example, the second indication information indicates the first offset. During the process of the first and second communication devices determining the COUNT corresponding to the second data packet based on the second indication information, according to the second air interface time indicated by the second scheduling information and the first offset, the air interface time with a time domain interval length equal to the first offset (denoted as T3) between the second air interface time and the second air interface time is used as the air interface time constituting the COUNT corresponding to the second data packet. Since the first offset is the offset between the first air interface time corresponding to the first data packet and the second air interface time indicated by the second scheduling information, T3 is the air interface time corresponding to the first data packet (first air interface time). The COUNT corresponding to the second data packet determined based on T3 is the same as the COUNT (first COUNT) determined based on the first air interface time and the first HFN corresponding to the first air interface time.
[0223] For example, the second indication information indicates the first offset and the second offset. During the process of the first and second communication devices determining the COUNT corresponding to the second data packet based on the second indication information, when the second offset is 0, they directly use the second air interface time indicated by the second scheduling information and the first offset, taking the air interface time (denoted as T3) whose time-domain interval length between the current HFN and the second air interface time is the first offset as the air interface time constituting the COUNT corresponding to the second data packet; when the second offset is 1, they take the air interface time (denoted as T3) whose time-domain interval length between the previous HFN and the second air interface time is the first offset as the air interface time constituting the COUNT corresponding to the second data packet, either from the air interface time corresponding to the previous HFN or the air interface time corresponding to the next HFN.
[0224] Since the first offset is the offset between the first air interface time corresponding to the first data packet and the second air interface time indicated by the second scheduling information, T3 is exactly the first air interface time. Therefore, the COUNT determined based on T3 and the HFN corresponding to T3 can also be understood as the first COUNT based on the first air interface time and the first HFN corresponding to the first air interface time, i.e., the COUNT corresponding to the second data packet.
[0225] As one possible implementation, the second indication information and the second scheduling information are contained in the same message. For example, refer to... Figure 15 In (a) the second indication information is carried in the preset offset field of the DCI, and the second scheduling information is carried in the K2 and K0 fields of the DCI for scheduling the second data packet. Alternatively, the second indication information is carried in the preset offset field of the DCI, and the second scheduling information is the DCI for scheduling the second data packet.
[0226] As another possible implementation, the second indication information and the second scheduling information are contained in different messages. For example, refer to Figure 15In (b), the second scheduling information is the DCI for scheduling the second data packet, or the second scheduling information is carried in the K2 and K0 fields of the DCI for scheduling the second data packet; the second indication information is carried in the header of the second data packet, and the header of the second data packet is only protected for integrity and not encrypted.
[0227] It is worth noting that since the upper limit of the transmission time-interval (TTI) between the retransmitted data packet and the initial data packet is usually less than 100, while the number of TTIs corresponding to one HFN is usually much greater than 100, the value of the second offset is usually 0 or 1. When the second indication information explicitly indicates the first and second offsets, the second offset can be indicated by one bit, and the first offset by eight bits. That is, the COUNT corresponding to the second data packet can be indicated by an additional nine bits. In contrast, in the scheme of adding a SN to each data packet, each message requires at least an additional 12 to 18 bits. Therefore, the scheme in this application embodiment helps to reduce the air interface overhead caused by implementing full protocol stack data packet security protection.
[0228] In addition, refer to Figure 15 In (c), because the system's frame structure and scheduling rules do not change in real time, the retransmission timing of data retransmission during the application of data retransmission techniques (such as HARQ) is regular, and the number of data retransmissions has a clear upper limit. Therefore, with a fixed frame structure, the interval between the air interface time corresponding to the initial transmission data packet and the retransmission data packet can only be a few fixed intervals, usually 4 to 8.
[0229] Therefore, when the second indication information implicitly indicates the first offset, two or three bits can be used to indicate the type of fixed interval between the first and second data packets (e.g., indicating the index corresponding to that fixed interval). The specific interval value for each fixed interval can be predefined by the protocol, or pre-sent to the terminal by the base station via an RCC message. In other words, when the second indication information implicitly indicates the first offset, two or three bits can be used to indicate the COUNT corresponding to the second data packet, significantly reducing the air interface overhead associated with implementing full protocol stack data packet security protection.
[0230] Based on this scheme, during the interaction of the first and second communication devices on the second data packet, the first COUNT corresponding to the first data packet can be used as the COUNT corresponding to the second data packet to protect the second data packet, according to the second scheduling information and the second indication information. This avoids the problem that the content of the second data packet is inconsistent with that of the first data packet after directly determining the COUNT corresponding to the second data packet based on the air interface time indicated by the DCI of the second data packet for security protection. This makes the transmission of the second data packet conform to the requirements of the current data retransmission mechanism (such as HARQ) and minimizes the impact of implementing full protocol stack data packet security protection based on the COUNT corresponding to the data packet on the retransmission mechanism.
[0231] Method 2: The first communication device generates a third data packet based on the second COUNT and sends the third data packet to the second communication device. Correspondingly, the second communication device receives the third data packet from the first communication device and performs a security check on the third data packet based on the second COUNT. The third data packet is a retransmission of the first data packet.
[0232] For example, the third data packet being a retransmission of the first data packet can be understood as the information cell corresponding to the third data packet being the same as the information cell corresponding to the first data packet, or the information contained in the third data packet being the same as the information contained in the first data packet, or it can also be understood as the NDI identifier in the DCI that schedules the first data packet and the NDI identifier in the DCI that schedules the third data packet being set to the same state.
[0233] The second COUNT is determined based on the third HFN and the third air interface time corresponding to the third data packet. The third HFN is the HFN corresponding to the third air interface time.
[0234] For example, the third air interface time can be understood as the air interface time when transmitting the third data packet, or it can be understood as the air interface time indicated by the scheduling information for scheduling the third data packet. The third HFN can be understood as the value of the HFN maintained by the first communication device when the air interface time is the third air interface time.
[0235] The method of determining the second COUNT based on the third HFN and the third air interface time corresponding to the third data packet is similar to the method of determining the first COUNT based on the first HFN and the first air interface time in the previous embodiment. You can refer to the relevant description in the previous embodiment. The difference is that the first air interface time is replaced with the third air interface time and the first HFN is replaced with the third HFN. It will not be repeated here.
[0236] In one possible implementation, the first communication device is a base station and the second communication device is a terminal. After the first communication device sends a first data packet to the second communication device, if it does not receive an ACK or NACK from the second communication device during the air interface time when the scheduling information of the first data packet indicates feedback on the transmission result of the first data packet, the first communication device sends a third data packet generated according to the second COUNT to the second communication device during the third air interface time.
[0237] For example, the fact that the base station does not receive ACK and NACK feedback from the second communication device can be understood as the scheduling information (e.g., DCI) of the first data packet sent by the base station to the terminal being lost, and therefore the terminal does not provide ACK or NACK feedback; or, it can also be understood as the ACK or NACK feedback being lost during transmission after the terminal successfully receives the scheduling information and the first data packet (i.e., the response information is lost); or, it can also be understood as the terminal failing to successfully receive the first data packet after successfully receiving the scheduling information, and therefore not providing ACK or NACK feedback to the base station.
[0238] For example, taking the first communication device as the base station and the second communication device as the terminal, the first data packet is an initial transmission data packet in the PDSCH channel, referencing... Figure 16 In (a), the base station sends a message containing a DCI and a PDSCH data packet (the first data packet) to the terminal during the first air interface time. The DCI indicates that the air interface time of the first data packet is (FN=22, SFN=6, timeslot number=0). Since the HFN corresponding to the air interface time (FN=22, SFN=0, timeslot number=0) is 0, the first HFN in the first COUNT corresponding to the DCI and the first data packet is 0, and the corresponding first air interface time is FN=22, SFN=6, timeslot number=0.
[0239] In the event of a lost DCI transmission, the terminal cannot receive the first data packet at the first air interface time indicated by the DCI, and will not send an ACK or NACK response to the base station. After the base station transmits the DCI and the first data packet, if it does not receive feedback from the terminal at the air interface time for sending the decoding and / or demodulation results of the first data packet, the base station will send a retransmission data packet to the terminal based on the retransmission mechanism. If the base station retransmits the retransmission data packet generated according to the first COUNT to the terminal at a new air interface time (FN=23, SFN=0, timeslot number=0) based on the current retransmission mechanism, the terminal, upon receiving the retransmission data packet, will treat the retransmission data packet as the initial data packet because it did not receive the DCI and the first data packet sent by the base station at the first air interface time. The terminal will determine the COUNT corresponding to the retransmission data packet based on the air interface time (FN=23, SFN=0, timeslot number=0) and the HFN corresponding to that air interface time. In this case, the terminal and the base station have different understandings of the COUNT corresponding to the retransmission data packet, and the terminal cannot perform integrity verification and decryption of the retransmission data packet.
[0240] Therefore, refer to Figure 16 In (b) of this embodiment, during the process of the base station sending a retransmitted data packet to the terminal based on the retransmission mechanism, it can first determine the third air interface time (FN=23, SFN=0, timeslot number=0) of the retransmitted first data packet according to a preset rule, and determine the HFN corresponding to the third data packet based on the third air interface time. Then, at the third air interface time (FN=23, SFN=0, timeslot number=0), the base station sends a message to the terminal containing a new DCI and a third data packet generated according to the second COUNT. The DCI indicates that the air interface time of the third data packet is FN=23, SFN=0, and timeslot number=0. The meaning of the preset rule can be referred to the relevant description in the foregoing embodiments, and will not be repeated here.
[0241] Since the terminal did not receive the message sent by the base station at the air interface time (FN=22, SFN=6, timeslot number=0), the DCI and third data packet sent by the base station at the air interface time (FN=23, SFN=0, timeslot number=0) are considered initial transmission data by the terminal. After receiving the message from the base station, the terminal uses the air interface time (FN=23, SFN=0, timeslot number=0) as the air interface time corresponding to the DCI and third data packet. Since the HFN corresponding to the air interface time (FN=23, SFN=0, timeslot number=0) is also 0, the terminal sets the HFN in the COUNT corresponding to the DCI and third data packet to 0. After successfully receiving the third data packet according to the DCI, the terminal sends an ACK to the base station and performs integrity verification and / or decryption on the third data packet based on the COUNT (second COUNT) determined according to the air interface time (FN=23, SFN=0, timeslot number=0).
[0242] The above embodiments are illustrated using the example of a terminal not receiving a message sent by the base station during the first air interface time. If the terminal fails to receive the first data packet during the first air interface time according to the scheduling information of the first data packet, the retransmission of the first data packet can be referred to the description in the above embodiments.
[0243] Based on this scheme, during the interaction of information corresponding to the first data packet between the first and second communication devices, in the event of loss of scheduling information, loss of the first data packet, or loss of response information (ACK / NACK), the first and second communication devices can treat the first retransmitted data packet as a new initial data packet during the retransmission of information corresponding to the first data packet. The security protection of the data packet is achieved based on the air interface time (third air interface time) corresponding to the data packet, avoiding the problem of inconsistent understanding of COUNT used by the first and second communication devices in the process of implementing security protection of the third data packet.
[0244] Furthermore, in the event that the ACK or NACK feedback from the terminal is lost, or if the first data packet is an uplink data packet and the base station does not receive the first data packet after sending the scheduling information for the first data packet, the base station may also send third scheduling information to the terminal, indicating through the third scheduling information that the COUNT corresponding to the retransmission data packet (third data packet) of the first data packet is determined based on the third air interface time and the third HFN.
[0245] In other words, the first communication device generates a third data packet using the second COUNT based on the third scheduling information. Correspondingly, the second communication device performs security checks on the third data packet using the second COUNT based on the third scheduling information.
[0246] Optionally, the first communication device sends or receives the third scheduling information. Correspondingly, the second communication device receives or sends the third scheduling information.
[0247] The third scheduling information is used to schedule the third data packet. The third scheduling information indicates that the third air interface time and the RV corresponding to the third data packet are RV0.
[0248] For example, the third scheduling information can be understood as the DCI for scheduling the third data packet, or it can be understood as the information contained in the fields indicating the third air interface time and the RV field in the DCI for scheduling the third data packet. The third scheduling information indicating the third air interface time can be understood as the third air interface time being determined based on the air interface time indicated by the third scheduling information. The RV corresponding to the third data packet is indicated by the RV field in the DCI.
[0249] The implementation method of the third scheduling information indicating the third air interface time is similar to the implementation method of the first scheduling information indicating the first air interface time in the aforementioned embodiments. Refer to the relevant descriptions in the aforementioned embodiments, and they will not be repeated here. The method by which the first communication device and the second communication device interact with the third scheduling information is similar to the method by which the first communication device and the second communication device interact with the first scheduling information in the aforementioned embodiments. Refer to the relevant descriptions in the aforementioned embodiments, and they will not be repeated here.
[0250] For example, taking the first communication device as the base station and the second communication device as the terminal, the base station sends a message containing a DCI and PDSCH data packet (the first data packet) to the terminal during the first air interface time. If no feedback information is received from the terminal during the air interface time for receiving the decoding and / or demodulation results of the first data packet, the base station enters the discontinuous transmission (DTX) mode according to the protocol and initiates the retransmission of the first data packet (the third data packet). After determining the air interface time for transmitting the third data packet (the third air interface time), the base station determines the second COUNT based on a preset rule according to the HFN corresponding to the third air interface time, generates the third data packet based on the second COUNT, and then sends a message containing a new DCI and the third data packet to the terminal during the third air interface time. The RV field in the new DCI is set to 0 according to the protocol.
[0251] Since this DCI is the initial DCI, after receiving it at the third air interface time, the terminal uses the third air interface time as the air interface time for constructing the COUNT corresponding to this DCI, and uses the third HFN corresponding to the third air interface time as the HFN for constructing the COUNT corresponding to this DCI, thus obtaining the COUNT (second COUNT) corresponding to this DCI. After performing integrity verification on the DCI according to the second COUNT, the terminal receives the third data packet at the third air interface time according to the indication of this DCI. Since this DCI indicates that the RV corresponding to the third data packet is RV0, the terminal determines the COUNT (second COUNT) corresponding to the third data packet based on preset rules according to the third air interface time and the third HFN, and performs integrity verification and / or decryption on the third data packet according to the second COUNT.
[0252] Furthermore, upon receiving the third data packet, the second communication device treats the third data packet directly as the initial transmission data packet, without performing a soft merge with the first data packet, because the COUNT (second COUNT) corresponding to the third data packet is different from the COUNT (first COUNT) corresponding to the first data packet. Moreover, if no retransmission data packet with the same COUNT as the first data packet is received after a certain time interval, the first data packet is discarded.
[0253] The above scheme is illustrated using the first communication device as the base station and the second communication device as the terminal as an example. When the first communication device is the terminal and the second communication device is the base station, if the base station does not receive an ACK or NACK from the terminal after sending the DCI for scheduling the first data packet, it can directly enter the DTX mode and send a new DCI with the RV field set to 0 to the terminal, instructing the terminal to generate a second COUNT according to the third air interface time indicated by the new DCI to retransmit the information corresponding to the first data packet. For the specific implementation method, please refer to the relevant description in the above embodiments, which will not be repeated here.
[0254] Based on this scheme, during the retransmission of information corresponding to the first data packet by the first and second communication devices, when the third scheduling information indicates that the RV corresponding to the third data packet is RV0, the security protection of the data packet is achieved according to the air interface time (third air interface time) corresponding to the third data packet. Even if the scheduling information is lost during the transmission of the first data packet, the first and second communication devices can still determine the COUNT used to achieve security protection of the third data packet according to the instruction of the third scheduling information and the third air interface time, so that the understanding of the COUNT corresponding to the third data packet by the first and second communication devices is consistent, thereby improving the reliability of data transmission.
[0255] In one possible implementation, the first communication device sends or receives third indication information. Correspondingly, the second communication device receives or sends the third indication information. The third indication information indicates the initial value of HFN.
[0256] The way in which the first communication device and the second communication device interact with the third instruction information is similar to the way in which the first communication device and the second communication device interact with the first instruction information in the foregoing embodiments. Please refer to the relevant descriptions in the foregoing embodiments, and they will not be repeated here.
[0257] In other words, the initial value of HFN is indicated by the base station to the terminal. The initial value of HFN can be understood as the current HFN maintained by the base station based on the air interface time when sending the third indication information.
[0258] For example, the third indication information may be carried in a predefined field in the signaling for implementing random access, or it may be carried in a predefined field in the signaling used for security mode negotiation after random access, or it may be carried in predefined signaling. Predefined can be understood as predefined by the protocol, or it can be understood as pre-agreed upon by the first communication device and the second communication device.
[0259] As one possible implementation, the first and second communication devices maintain the HFN according to the air interface time.
[0260] For example, after FN is sent K times during the air interface time, the value of HFN is incremented by one. K is an integer greater than 0, such as 10, 25, 50, 100, or 500. Sending an FN change can be understood as the value of FN changing from n to (n+1) or 0, where n is an integer greater than or equal to 0.
[0261] For example, in the case of FN flipping during air interface time, the value of HFN is incremented by one.
[0262] The FN flip in the air interface time can be understood as FN changing from 1023 to 0. That is, after the first and second communication devices unify the initial value of HFN through the interaction of the third indication information, the value of HFN is incremented by one each time FN changes from 1023 to 0 in the air interface time. In other words, the maximum air interface duration corresponding to each value of HFN is 10.24 seconds.
[0263] Based on this scheme, since the air interface time of the first and second communication devices is synchronized, and the first and second communication devices maintain the HFN value according to the initial HFN value indicated by the third indication information and the air interface time, the first and second communication devices have the same understanding of the HFN corresponding to each air interface time. Therefore, the first and second communication devices also have the same understanding of the COUNT corresponding to different air interface times, which improves the reliability of the security protection of the entire protocol stack data packets based on COUNT.
[0264] In one possible implementation, the first communication device is a terminal, and the second communication device is a base station. The first communication device receives a MIB from the second communication device and updates the maintained air interface time according to the MIB. The MIB includes fourth indication information, which indicates the current FN.
[0265] For example, the fourth indication information is carried in the FN field of the MIB, or the fourth indication information is carried in a predefined field of the MIB. The predefined field may be predefined by the protocol or pre-agreed upon by the first communication device and the second communication device.
[0266] In other words, after the terminal receives the MIB sent by the base station, it updates the air interface time maintained by the terminal according to the air interface time corresponding to the FN (current FN) carried in the MIB, and updates the air interface time maintained by the terminal to the air interface time corresponding to the current FN.
[0267] Based on this scheme, the first communication device can verify and correct its maintained air interface time based on the periodically broadcast MIB, reducing the possibility of air interface time asynchrony between the first and second communication devices and improving the reliability of data packet security protection based on air interface time.
[0268] In one possible implementation, the first communication device is a base station, and the second communication device is a terminal. The second communication device receives the MIB from the first communication device and updates the maintained air interface time according to the MIB. The MIB includes fourth indication information, which indicates the current FN.
[0269] The second communication device updates the air interface time according to the MIB in a similar way to the first communication device, and can be referred to the relevant description in the foregoing embodiments, which will not be repeated here.
[0270] Taking the first communication device as the base station and the second communication device as the terminal as an example, the process for the first and second communication devices to maintain air interface time and HFN can be referred to Figure 17 It includes the following steps:
[0271] S1701, The base station broadcasts the MIB. Correspondingly, the terminal receives the MIB from the base station. The MIB includes the base station's current FN.
[0272] For example, the base station periodically broadcasts synchronization signals, physical broadcast channel blocks (SSBs), and median blocks (MIBs) according to the broadcast intervals specified in the protocol. After receiving the SSB, the terminal parses the system information carried in the MIB based on the SSB and obtains the base station's current field of view (FN).
[0273] S1702, The terminal and the base station achieve air interface time synchronization.
[0274] For example, after obtaining the current FN of the base station, the terminal determines the SFN and timeslot number corresponding to the FN through synchronization point calculation, thereby obtaining the current air interface time of the base station. Then, the terminal sets the air interface time it maintains to the current air interface time of the base station, thereby achieving synchronization with the air interface time of the base station.
[0275] Furthermore, after the base station and terminal achieve air interface time synchronization, they can maintain the air interface time according to the unit duration of a time slot. Each time slot is incremented by 1; if the time slot number flips, SFN is incremented by 1; if SFN flips, FN is incremented by 1.
[0276] As one possible implementation, after the terminal and the base station achieve stable time synchronization, an automatic timer can be started and the duration of the automatic timer can be set to the length of a time slot. After each time slot, the air interface time maintained by the terminal is updated once.
[0277] Based on this scheme, even if the terminal experiences a short-term disconnection, the terminal's understanding of the air interface time can remain consistent with that of the base station, reducing the probability of inconsistencies between the terminal's and base station's understanding of the air interface time.
[0278] S1703, the terminal and the base station achieve uplink synchronization.
[0279] For example, the terminal performs random access through a random access procedure to achieve uplink synchronization with the base station.
[0280] S1704. The base station transmits the initial value of HFN. Correspondingly, the terminal receives the initial value of HFN.
[0281] For example, during the AS Security Mode negotiation process with the terminal, the base station carries the initial value of HFN in the initial HFN field of the AS Security Mode signaling. After receiving the AS Security Mode signaling, the terminal obtains the initial value of HFN based on the parsing result of the initial HFN field.
[0282] The initial HFN field can be predefined by the protocol or pre-agreed upon by the base station and the terminal.
[0283] S1705. Terminals and base stations maintain HFN based on air interface time.
[0284] For example, during the maintenance of HFN based on air interface time, the value of FN can be detected. If FN flips, the value of HFN can be updated from the current value (e.g., the initial value) to the current value plus 1. Alternatively, if the number of changes to the value of FN is greater than a preset value, the value of HFN can be updated from the current value to the current value plus 1.
[0285] S1706. The terminal corrects the air interface time and HFN according to the MIB.
[0286] In the event of a brief disconnection, the terminal will be unable to obtain air interface signals sent by the base station for a short period of time. Since there may be deviations in the process of the terminal maintaining its own air interface time and HFN, the terminal can update the air interface time and HFN maintained by the terminal according to the MIB message sent by the base station.
[0287] As one possible implementation, with a stable connection between the terminal and the base station, the terminal periodically acquires MIB messages broadcast by the base station. Upon receiving the MIB message, it calculates the current air interface time of the base station based on the MIB message and updates the air interface time maintained by the terminal according to the current air interface time of the base station. Then, it verifies the maintained HFN based on the updated air interface time and corrects the HFN maintained by the terminal if there is an offset.
[0288] As another possible implementation, after a brief disconnection and reconnection, upon receiving a MIB message from the base station, the terminal can recalculate the current air interface time of the base station based on the FN in the MIB message. Then, based on the calculated current air interface time, the timing result of the automatic timer and the air interface time maintained by the terminal are updated. Finally, the maintained HFN is verified based on the updated air interface time, and the HFN maintained by the terminal is corrected if there is an offset.
[0289] Based on the above scheme, during the interaction of the lower-layer data packets (first data packets) of the PDCP layer between the first communication device and the second communication device, the first communication device can perform integrity protection and / or encryption of the first data packets based on the first COUNT, and the second communication device can perform integrity verification and / or decryption of the first data packets based on the first COUNT, thereby achieving security protection for the lower-layer data packets of the PDCP layer. This helps reduce the risk of spoofing and tampering with the lower-layer data / signaling of the PDCP layer. The first COUNT is determined based on the first HFN and the first air interface time corresponding to the first data packet. The first HFN is the HFN corresponding to the first air interface time. In other words, the determination of the first COUNT mainly depends on the air interface time corresponding to the first data packet. Since the first communication device and the second communication device, which communicate over the air interface through the wireless protocol stack, will maintain air interface time synchronization, the first air interface time can be determined based on the air interface time of transmitting the first data packet or the scheduling information of scheduling the first data packet when exchanging the first data packets. There is no need to carry the indication information for determining the first COUNT in the first data packet. This helps to achieve security protection for the first data packet without increasing air interface overhead or with a small increase in air interface overhead.
[0290] The method provided in this application has been described above. In addition, this application also provides a communication device for implementing the functions described in the above method embodiments.
[0291] It is understood that, in order to achieve the aforementioned functions, the communication device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0292] This application embodiment can divide the communication device into functional modules according to the above method embodiment. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods.
[0293] Figure 18 A schematic diagram of a communication device 180 is shown. The communication device 180 includes a processing module 1801 and a transceiver module 1802. The communication device 180 can be used to implement the functions of the first or second communication device described above.
[0294] In some embodiments, the communication device 180 may further include a storage module. Figure 18 (Not shown in the image) is used to store program instructions and data.
[0295] In some embodiments, the transceiver module 1802, also referred to as a transceiver unit, is used to implement sending and / or receiving functions. The transceiver module 1802 may consist of a transceiver circuit, a transceiver, a transceiver unit, or a communication interface.
[0296] In some embodiments, the transceiver module 1802 may include a receiving module and a sending module, respectively configured to perform receiving and sending steps performed by the first communication device or the second communication device in the above method embodiments, and / or other processes to support the technology described herein; the processing module 1801 may be configured to perform processing steps performed by the first communication device or the second communication device in the above method embodiments, and / or other processes to support the technology described herein.
[0297] When the communication device 180 is used to implement the function of the first communication device, in one possible implementation: the transceiver module 1802 is used to send or receive first scheduling information, the first scheduling information is used to schedule the first data packet, and the first scheduling information indicates the first air interface time.
[0298] In one possible implementation, the transceiver module 1802 is used to send or receive first indication information, which indicates that the redundancy version RV corresponding to the first data packet is RV0.
[0299] In one possible implementation, the transceiver module 1802 is used to send a second data packet to a second communication device. The second data packet is a retransmission data packet of the first data packet, and the second data packet is a data packet that is protected for integrity and / or encrypted according to the first COUNT.
[0300] In one possible implementation, the transceiver module 1802 is used to send or receive second scheduling information, which is used to schedule second data packets and indicates a second air interface time; and to receive or send second indication information, which indicates a first offset and / or a second offset, wherein the first offset is the offset between the first air interface time and the second air interface time, and the second offset is the offset between the first HFN and the second HFN, and the second HFN is the HFN corresponding to the second air interface time.
[0301] In one possible implementation, processing module 1801 is used to generate a third data packet based on a second COUNT, wherein the third data packet is a retransmission data packet of the first data packet; transceiver module 1802 is used to send the third data packet to the second communication device. The second COUNT is determined based on a third HFN and the third air interface time corresponding to the third data packet, wherein the third HFN is the HFN corresponding to the third air interface time.
[0302] In one possible implementation, the transceiver module 1802 is used to send or receive third scheduling information, which is used to schedule a third data packet. The third scheduling information indicates that the third air interface time and the RV corresponding to the third data packet are RV0.
[0303] In one possible implementation, the transceiver module 1802 is used to send or receive third indication information, which indicates the initial value of the superframe number; the processing module 1801 is used to increment the superframe number by 1 when the frame number FN in the air interface time is flipped.
[0304] In one possible implementation, the transceiver module 1802 is used to receive a system information block (MIB), the MIB including fourth indication information, the fourth indication information indicating the current FN; the processing module 1801 is used to determine the air interface time based on the current FN.
[0305] When the communication device 180 is used to implement the function of the second communication device, in one possible implementation: the transceiver module 1802 is used to receive or send first scheduling information, the first scheduling information is used to schedule the first data packet, and the first scheduling information indicates the first air interface time.
[0306] In one possible implementation, the transceiver module 1802 is used to receive or send first indication information, which indicates that the redundancy version RV corresponding to the first data packet is RV0.
[0307] In one possible implementation, the transceiver module 1802 is used to receive a second data packet from the first communication device, the second data packet being a retransmission data packet of the first data packet; the processing module 1801 is used to perform integrity verification on the second data packet according to the first COUNT, and / or to decrypt the second data packet according to the first COUNT.
[0308] In one possible implementation, the transceiver module 1802 is used to receive or send second scheduling information, which is used to schedule second data packets and indicates a second air interface time; and to receive or send second indication information, which indicates a first offset and / or a second offset, wherein the first offset is the offset between the first air interface time and the second air interface time, and the second offset is the offset between the first HFN and the second HFN, and the second HFN is the HFN corresponding to the second air interface time.
[0309] In one possible implementation, the transceiver module 1802 is used to receive a third data packet from the first communication device, the third data packet being a retransmission data packet of the first data packet; the processing module 1801 is used to perform integrity verification on the third data packet according to a second COUNT, and / or to decrypt the third data packet according to the second COUNT. The second COUNT is determined based on the third HFN and the third air interface time corresponding to the third data packet, where the third HFN is the HFN corresponding to the third air interface time.
[0310] In one possible implementation, the transceiver module 1802 is used to receive or send third scheduling information, which is used to schedule a third data packet. The third scheduling information indicates that the third air interface time and the RV corresponding to the third data packet are RV0.
[0311] In one possible implementation, the transceiver module 1802 is used to receive or send third indication information, which indicates the initial value of the superframe number; the processing module 1801 is used to increment the superframe number by 1 when the frame number FN in the air interface time is flipped.
[0312] In one possible implementation, the transceiver module 1802 is used to receive a system information block (MIB), the MIB including fourth indication information, the fourth indication information indicating the current FN; the processing module 1801 is used to determine the air interface time based on the current FN.
[0313] All relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.
[0314] In this application, the communication device 180 can be presented in an integrated manner by dividing it into various functional modules. Here, "module" can refer to an application-specific integrated circuit (ASIC), a circuit, a processor and memory that executes one or more software or firmware programs, integrated logic circuits, and / or other devices that can provide the above functions.
[0315] In some embodiments, when Figure 18 When the communication device 180 is a chip or chip system, the function / implementation process of the transceiver module 1802 can be implemented through the input / output interface (or communication interface) of the chip or chip system, and the function / implementation process of the processing module 1801 can be implemented through the processor (or processing circuit) of the chip or chip system.
[0316] Since the communication device 180 provided in this embodiment can execute the above method, the technical effects it can achieve can be referred to the above method embodiment, and will not be repeated here.
[0317] As a possible product form, the first or second communication device described in the embodiments of this application can be implemented using one or more field programmable gate arrays (FPGAs), programmable logic devices (PLDs), controllers, state machines, gate logic, discrete hardware components, any other suitable circuits, or any combination of circuits capable of performing the various functions described throughout this application.
[0318] As another possible product form, the first or second communication device described in the embodiments of this application can be implemented using a general bus architecture. For ease of explanation, see [link to documentation]. Figure 19 , Figure 19This is a schematic diagram of the structure of a communication device 1900 provided in an embodiment of this application. The communication device 1900 includes a processor 1901 and a transceiver 1902. The communication device 1900 can be a first communication device, or a chip or chip system therein; or, the communication device 1900 can be a second communication device, or a chip or module therein. Figure 19 Only the main components of the communication device 1900 are shown. In addition to the processor 1901 and transceiver 1902, the communication device may further include a memory 1903 and input / output devices (not shown).
[0319] Optionally, the processor 1901 is mainly used to process communication protocols and communication data, control the entire communication device, execute software programs, and process the data of the software programs, thereby implementing the methods provided in the above-described method embodiments. The memory 1903 is mainly used to store software programs and data. The transceiver 1902 may include radio frequency (RF) circuitry and an antenna. The RF circuitry is mainly used for converting baseband signals to RF signals and processing RF signals. The antenna is mainly used for transmitting and receiving RF signals in the form of electromagnetic waves. Input / output devices, such as touchscreens, displays, and keyboards, are mainly used to receive user input data and output data to the user.
[0320] Optionally, the processor 1901, transceiver 1902, and memory 1903 can be connected via a communication bus.
[0321] When the communication device is powered on, the processor 1901 can read the software program in the memory 1903, interpret and execute the instructions of the software program, and process the data of the software program. When data needs to be transmitted wirelessly, the processor 1901 performs baseband processing on the data to be transmitted and outputs the baseband signal to the radio frequency (RF) circuit. The RF circuit processes the baseband signal and transmits the RF signal outward in the form of electromagnetic waves through the antenna. When data is sent to the communication device, the RF circuit receives the RF signal through the antenna, converts the RF signal into a baseband signal, and outputs the baseband signal to the processor 1901. The processor 1901 converts the baseband signal into data and processes the data.
[0322] In another implementation, the radio frequency circuitry and antenna can be set up independently of the processor performing baseband processing. For example, in a distributed scenario, the radio frequency circuitry and antenna can be arranged remotely, independent of the communication device.
[0323] In some embodiments, those skilled in the art will recognize that the above-described communication device 180 can be implemented in hardware using... Figure 19 The communication device shown is in the form of 1900.
[0324] As an example, Figure 18The function / implementation process of the processing module 1801 can be obtained through Figure 19 The processor 1901 in the communication device 1900 shown calls computer execution instructions stored in memory 1903 to achieve this. Figure 18 The function / implementation process of the transceiver module 1802 in the middle can be obtained through Figure 19 This is achieved through the transceiver 1902 in the communication device 1900 shown.
[0325] As another possible product form, the first or second communication device in this application can be adopted. Figure 20 The shown composition structure, or including Figure 20 The components shown. Figure 20 This application provides a schematic diagram of the composition of a communication device 2000, which may be a first communication device or a chip or system-on-a-chip in the first communication device; or, it may be a second communication device or a module, chip or system-on-a-chip in the second communication device.
[0326] like Figure 20 As shown, the communication device 2000 includes at least one processor 2001 and at least one communication interface. Figure 20 (This is merely an example illustration, using a communication interface 2004 and a processor 2001 as examples.) Optionally, the communication device 2000 may also include a communication bus 2002 and a memory 2003.
[0327] Processor 2001 can be a general-purpose central processing unit (CPU), a general-purpose processor, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a PLD, or any combination thereof. Processor 2001 can also be other devices with processing capabilities, such as circuits, devices, or software modules, without limitation.
[0328] The communication bus 2002 is used to connect different components in the communication device 2000, enabling communication between them. The communication bus 2002 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 20 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0329] Communication interface 2004 is used for communicating with other devices or communication networks. For example, communication interface 2004 can be a module, circuit, transceiver, or any device capable of communication. Optionally, communication interface 2004 can also be an input / output interface located within processor 2001, used to implement signal input and signal output for the processor.
[0330] Memory 2003 can be a device with storage function for storing instructions and / or data. Instructions can be computer programs.
[0331] For example, the memory 2003 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and / or instructions; it may also be a random access memory (RAM) or other type of dynamic storage device capable of storing information and / or instructions; it may also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, etc., without limitation.
[0332] It should be noted that the memory 2003 can exist independently of the processor 2001, or it can be integrated with the processor 2001. The memory 2003 can be located inside or outside the communication device 2000, without limitation. The processor 2001 can be used to execute the instructions stored in the memory 2003 to implement the methods provided in the following embodiments of this application.
[0333] As an optional implementation, the communication device 2000 may also include an output device 2005 and an input device 2006. The output device 2005 communicates with the processor 2001 and can display information in various ways. For example, the output device 2005 may be a liquid crystal display (LCD), a light-emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, etc. The input device 2006 communicates with the processor 2001 and can receive user input in various ways. For example, the input device 2006 may be a mouse, keyboard, touchscreen device, or sensing device, etc.
[0334] In some embodiments, the hardware implementation will be apparent to those skilled in the art as described above. Figure 18 The communication device 180 shown can employ Figure 20 The communication device shown is in the form of 2000.
[0335] As an example, Figure 18 The function / implementation process of the processing module 1801 can be obtained through Figure 20 The processor 2001 in the communication device 2000 shown calls computer execution instructions stored in the memory 2003 to achieve this. Figure 18 The function / implementation process of the transceiver module 1802 in the middle can be obtained through Figure 20 This is achieved through the communication interface 2004 in the communication device 2000 shown.
[0336] It should be noted that, Figure 20 The structures shown do not constitute a specific limitation on the first or second communication device. For example, in other embodiments of this application, the first or second communication device may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0337] In some embodiments, this application also provides a communication device, which includes a processor for implementing the methods in any of the above method embodiments.
[0338] As one possible implementation, the communication device also includes a memory. This memory stores necessary computer programs and data. The computer program may include instructions, which a processor can invoke to instruct the communication device to execute the methods described in any of the above method embodiments. Alternatively, the memory may not be present in the communication device.
[0339] As another possible implementation, the communication device also includes an interface circuit, which is a code / data read / write interface circuit, used to receive computer execution instructions (which are stored in memory and may be read directly from memory or may be transmitted through other devices) and transmit them to the processor.
[0340] As another possible implementation, the communication device also includes a communication interface for communicating with modules outside the communication device.
[0341] It is understood that the communication device can be a chip or a chip system. When the communication device is a chip system, it can be composed of chips or may include chips and other discrete devices. This application does not specifically limit this.
[0342] This application also provides a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed by a computer, implements the functions of any of the above-described method embodiments.
[0343] This application also provides a computer program product that, when executed by a computer, implements the functions of any of the above method embodiments.
[0344] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0345] It is understood that the systems, apparatuses, and methods described in this application can also be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0346] The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. The components shown as units may or may not be physical units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0347] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0348] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be, in whole or in part, in the form of a computer program product. This computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device containing one or more servers, data centers, etc., that can be integrated with the medium. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive (SSD)). In this embodiment, the computer may include the aforementioned apparatus.
[0349] Although this application has been described herein in conjunction with various embodiments, those skilled in the art, by reviewing the accompanying drawings, disclosure, and appended claims, will understand and implement other variations of the disclosed embodiments in carrying out the claimed application. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude a plurality. A single processor or other unit can implement several functions listed in the claims. While different dependent claims may recite certain measures, this does not mean that these measures cannot be combined to produce good results.
[0350] Although this application has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the scope of this application. Accordingly, this specification and drawings are merely illustrative descriptions of the application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from the scope of this application. Thus, if such modifications and modifications of this application fall within the scope of the claims of this application and their equivalents, this application is also intended to include such modifications and modifications.
Claims
1. A communication method, characterized in that, The method includes: Receive a first data packet from the first communication device, wherein the first data packet is a data packet of the lower layer of the Packet Data Convergence Protocol (PDCP) layer; The integrity of the first data packet is verified according to the first COUNT, and / or the first data packet is decrypted according to the first COUNT. The first COUNT is determined based on the first superframe number HFN and the first air interface time corresponding to the first data packet. The first HFN is the HFN corresponding to the first air interface time.
2. The method according to claim 1, characterized in that, The method further includes: receiving or sending first scheduling information, the first scheduling information being used to schedule the first data packet, the first scheduling information indicating the first air interface time.
3. The method according to claim 2, characterized in that, The method further includes: receiving or sending first indication information, wherein the first indication information indicates that the redundancy version RV corresponding to the first data packet is RV0.
4. The method according to any one of claims 1 to 3, characterized in that, The method further includes: Receive a second data packet from the first communication device, wherein the second data packet is a retransmission data packet of the first data packet; The second data packet is subjected to integrity verification based on the first COUNT, and / or the second data packet is decrypted based on the first COUNT.
5. The method according to claim 4, characterized in that, The method further includes: Receive or send second scheduling information, the second scheduling information being used to schedule the second data packet, the second scheduling information indicating a second air interface time; Receive or send a second indication message, the second indication message indicating a first offset and / or a second offset, the first offset being the offset between the first air interface time and the second air interface time, the second offset being the offset between the first HFN and the second HFN, the second HFN being the HFN corresponding to the second air interface time.
6. The method according to any one of claims 1 to 3, characterized in that, The method further includes: Receive a third data packet from the first communication device, wherein the third data packet is a retransmission data packet of the first data packet; The integrity of the third data packet is verified according to the second COUNT, and / or the third data packet is decrypted according to the second COUNT. The second COUNT is determined based on the third HFN and the third air interface time corresponding to the third data packet. The third HFN is the HFN corresponding to the third air interface time.
7. The method according to claim 6, characterized in that, The method further includes: Receive or send third scheduling information, the third scheduling information being used to schedule the third data packet, the third scheduling information indicating that the third air interface time and the RV corresponding to the third data packet are RV0.
8. The method according to any one of claims 1 to 7, characterized in that, The air interface time includes at least one of the following: frame number FN, subframe number SFN, or time slot number.
9. The method according to any one of claims 1 to 8, characterized in that, The method further includes: Receive or send a third indication message, the third indication message indicating the initial value of the superframe number; In the case of frame number FN flipping during air interface time, the superframe number is incremented by 1.
10. The method according to claim 9, characterized in that, The method further includes: Receive system information block (MIB), the MIB including fourth indication information, the fourth indication information indicating the current FN; The air interface time is determined based on the current FN.
11. A communication method, characterized in that, The method includes: Integrity protection is performed on the data to be transmitted according to the first COUNT, and / or the data to be transmitted is encrypted according to the first COUNT to obtain a first data packet, wherein the first data packet is a data packet of the lower layer of the Packet Data Convergence Protocol (PDCP) layer. Send the first data packet to the second communication device; The first COUNT is determined based on the first superframe number HFN and the first air interface time corresponding to the first data packet, where the first HFN is the HFN corresponding to the first air interface time.
12. The method according to claim 11, characterized in that, The method further includes: sending or receiving first scheduling information, the first scheduling information being used to schedule the first data packet, the first scheduling information indicating the first air interface time.
13. The method according to claim 12, characterized in that, The method further includes: sending or receiving first indication information, wherein the first indication information indicates that the redundancy version RV corresponding to the first data packet is RV0.
14. The method according to any one of claims 11 to 13, characterized in that, The method further includes: Send a second data packet to a second communication device. The second data packet is a retransmission of the first data packet. The second data packet is a data packet that is protected for integrity and / or encrypted according to the first COUNT.
15. The method according to claim 14, characterized in that, The method further includes: Sending or receiving second scheduling information, the second scheduling information being used to schedule the second data packet, the second scheduling information indicating a second air interface time; Receive or send a second indication message, the second indication message indicating a first offset and / or a second offset, the first offset being the offset between the first air interface time and the second air interface time, the second offset being the offset between the first HFN and the second HFN, the second HFN being the HFN corresponding to the second air interface time.
16. The method according to any one of claims 11 to 13, characterized in that, The method further includes: A third data packet is generated based on the second COUNT, and the third data packet is a retransmission data packet of the first data packet; The third data packet is sent to the second communication device; The second COUNT is determined based on the third HFN and the third air interface time corresponding to the third data packet, wherein the third HFN is the HFN corresponding to the third air interface time.
17. The method according to claim 16, characterized in that, The method further includes: sending or receiving third scheduling information, the third scheduling information being used to schedule the third data packet, the third scheduling information indicating that the third air interface time and the RV corresponding to the third data packet are RV0.
18. The method according to any one of claims 11 to 17, characterized in that, The air interface time includes at least one of the following: frame number FN, subframe number SFN, or time slot number.
19. The method according to any one of claims 11 to 18, characterized in that, The method further includes: Send or receive third indication information, the third indication information indicating the initial value of the superframe number; In the case of frame number FN flipping during air interface time, the superframe number is incremented by 1.
20. The method according to claim 19, characterized in that, The method further includes: Receive system information block (MIB), the MIB including fourth indication information, the fourth indication information indicating the current FN; The air interface time is determined based on the current FN.
21. A communication device, characterized in that, The communication device includes a processor; the processor is configured to run a computer program or instructions to cause the communication device to perform the method as described in any one of claims 1-10, or to cause the communication device to perform the method as described in any one of claims 11-20.
22. A communication system, characterized in that, The communication system includes a first communication device and a second communication device; The first communication device is used to perform the method as described in any one of claims 1-10, and the second communication device is used to perform the method as described in any one of claims 11-20.
23. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions or programs that, when executed on a computer, cause the method described in any one of claims 1-10 to be performed, or cause the method described in any one of claims 11-20 to be performed.
24. A computer program product, characterized in that, The computer program product includes computer instructions; when some or all of the computer instructions are run on a computer, they cause the method as described in any one of claims 1-10 to be performed, or cause the method as described in any one of claims 11-20 to be performed.