Information processing method, communication device, communication system, and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING XIAOMI MOBILE SOFTWARE CO LTD
- Filing Date
- 2024-10-29
- Publication Date
- 2026-06-16
AI Technical Summary
In existing technologies, the MAC layer control unit (MAC CE) is not encrypted and protected for integrity, which poses a security risk and may lead to information leakage or business anomalies.
When the MAC CE protection function is activated, the communication device determines whether to perform protection processing on the MAC CE, including encryption and/or integrity protection, by using integrity protection parameters and encryption protection parameters to process the MAC CE.
It improves the transmission security and reliability of MAC CE, prevents MAC CE from being tampered with or attacked, and reduces resource consumption and power consumption.
Smart Images

Figure CN122228644A_ABST
Abstract
Description
Information processing methods, communication equipment, communication systems and storage media Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to an information processing method, communication device, communication system and storage medium. Background Technology
[0002] The relevant protocols propose to encrypt and protect the integrity of Radio Resource Control (RRC) messages in order to prevent the content transmitted through RRC messages from being attacked.
[0003] Summary of the Invention
[0004] This disclosure provides an information processing method, a communication device, a communication system, and a storage medium.
[0005] The first aspect of this disclosure provides an information processing method, which is executed by a communication device, and the method includes:
[0006] Determine whether to perform protection processing on the Media Access Control (MAC) CE unit, wherein the MAC CE protection function is in an active state.
[0007] A second aspect of this disclosure provides a communication device, which includes:
[0008] The processing module is used to determine whether to perform protection processing on the Media Access Control (MAC) CE unit, wherein the MAC CE protection function is in an active state.
[0009] A third aspect of this disclosure provides a communication device, which includes one or more processors;
[0010] The processor is used to execute the method described in the first aspect above.
[0011] A communication system, comprising terminals and network devices, wherein the terminals and network devices are respectively used to perform the method described in the first aspect above.
[0012] A fourth aspect of this disclosure provides a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in the first aspect above.
[0013] A sixth aspect of this disclosure provides a computer program product including a computer program that, when executed by a processor, implements the method described in the first aspect above.
[0014] The solution proposed in this disclosure allows the communication device to determine whether to perform MAC CE protection when the MAC CE protection function is activated. This improves the flexibility of MAC CE protection and avoids the problem of MAC CE being attacked or tampered with. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in the embodiments or background art of this disclosure, the accompanying drawings used in the embodiments or background art of this disclosure will be described below.
[0016] Figure 1 is a schematic diagram of the architecture of a communication system provided in an embodiment of this disclosure;
[0017] Figures 2A-2E are schematic diagrams of the information processing method provided in the embodiments of this disclosure;
[0018] Figure 3 is a schematic diagram of the information processing method provided in an embodiment of this disclosure;
[0019] Figure 4 is a schematic diagram of the structure of a communication device provided in an embodiment of this disclosure;
[0020] Figure 5A is a schematic diagram of the structure of a communication device provided in an embodiment of this disclosure;
[0021] Figure 5B is a schematic diagram of the structure of a chip provided in an embodiment of this disclosure. Detailed Implementation
[0022] This disclosure provides an information processing method, a communication device, a communication system, and a storage medium.
[0023] In a first aspect, embodiments of this disclosure propose an information processing method, the method comprising: determining whether to perform protection processing on MACCE, wherein the MACCE protection function is in an active state.
[0024] In this embodiment of the disclosure, when the MAC CE protection function is activated, the communication device can determine whether to perform MAC CE protection processing, thereby improving the flexibility of MAC CE protection based on the implementation of MAC CE protection.
[0025] In conjunction with some embodiments of the first aspect, in some embodiments, the determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes:
[0026] If a MAC CE meets one or more of the following conditions, no protection will be applied to the MAC CE:
[0027] Included in message Msg3;
[0028] Included in the two-step random access message MsgA;
[0029] To fill the buffer status report (BSR), and this is the only padding BSR in the MAC protocol data unit (PDU) containing the MAC CE;
[0030] It is included in message Msg4.
[0031] In this embodiment of the disclosure, the communication device may not protect the MAC CE included in Msg3, MsgA, MAC CE including only BSR, or Msg4, thereby minimizing the amount of resources used for MAC CE protection while ensuring the security and integrity of MAC CEs that affect the security and reliability of communication services.
[0032] In conjunction with some embodiments of the first aspect, in some embodiments, the determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes:
[0033] The MAC CE is the first MAC CE, and protection processing is performed on the first MAC CE. The first MAC CE is one or more of the following:
[0034] Mobility LTM cell handover command MAC CE triggered by Layer 1 and / or Layer 2;
[0035] Discontinuous reception of DRX command MAC CE;
[0036] Long DRX command MAC CE;
[0037] Beam failure recovery BFR MAC CE;
[0038] MAC CE used to activate or deactivate the data retransmission function;
[0039] MAC CE used to control the activation or deactivation of the semi-persistent SP channel state information reference signal CSI-RS and / or CSI interference measurement resource set;
[0040] MAC CE used to control the activation or deactivation of the SP probe reference signal SRS;
[0041] MAC CE used to control the activation or deactivation of the physical uplink control channel (PUCCH) spatial relationships;
[0042] MAC CE used to control the activation or deactivation of the SP zero-power CSI-RS resource set;
[0043] MAC CE including time increment;
[0044] The MAC CE used to control the terminal-specific Physical Downlink Shared Channel (PDSCH) transmission configuration indication TCI status activation or deactivation;
[0045] MAC CE used to indicate the TCI state of a specific physical downlink control channel (PDCCH) of a terminal;
[0046] MAC CE used to activate or deactivate secondary cell SCell;
[0047] MAC CE is used to indicate that the Listen Before You Speak (LBT) has failed.
[0048] In this embodiment of the disclosure, the communication device can protect the MAC CE from information leakage or business abnormalities caused by tampering or illegal acquisition, thereby improving the security and reliability of the MAC CE.
[0049] In conjunction with some embodiments of the first aspect, in some embodiments, the above-described protection processing of the first MAC CE includes:
[0050] Perform one or more of the following on the MAC PDU containing the first MAC CE:
[0051] The first MAC CE is protected, while other MAC CEs in the MAC PDU besides the first MAC CE are not protected.
[0052] All MAC CEs in the MAC PDU are protected;
[0053] The MAC CEs other than the second MAC CE in the MAC PDU are protected, wherein the second MAC CE is not exactly the same as the first MAC CE, or is completely different.
[0054] In this embodiment of the disclosure, the communication device can perform different protection processes on each MAC CE in the MAC PDU containing the first MAC CE as needed, thereby improving the flexibility of MAC CE protection while ensuring the security of the first MAC CE.
[0055] In conjunction with some embodiments of the first aspect, in some embodiments the above method further includes:
[0056] The first MAC CE is not included in the following messages: Msg3, MsgA, Msg4.
[0057] In this embodiment of the disclosure, the communication device may not carry the first MAC CE in the unprotected message, thereby avoiding the risk of the first MAC CE being leaked or attacked and improving the security of the first MAC CE.
[0058] In conjunction with some embodiments of the first aspect, in some embodiments, the determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes:
[0059] The MAC protocol data unit (PDU) contains a second MAC CE. The second MAC CE is not protected. The second MAC CE is one or more of the following: regular buffer status report (BSR), filling BSR, periodic BSR, power remaining report (PHR), cell radio network temporary identifier (C-RNTI), terminal contention resolution identifier, MAC CE for confirming configuration authorization, and MAC CE for recommended bit rate.
[0060] In this embodiment of the disclosure, the communication device can not only protect the second MAC CE of the security requirements disclosure, thereby minimizing the cost and resource damage of MAC CE protection.
[0061] In conjunction with some embodiments of the first aspect, in some embodiments, the second MAC CE is not protected as described above, including any of the following:
[0062] The MAC PDU contains only one or more of the second MAC CEs, and no protection processing is applied to the second MAC CEs;
[0063] The MAC PDU also includes a first MAC CE. The first MAC CE is protected, while all other MAC CEs in the MAC PDU except the first MAC CE are not protected.
[0064] The MAC PDU also includes a first MAC CE, which protects all other MAC CEs in the MAC PDU except for the second MAC CE.
[0065] In the embodiments of this disclosure, the communication device can perform different protection processes on each MAC CE in a MAC PDU that includes a second MAC CE that does not need protection, thereby improving the flexibility of MAC CE protection while ensuring the security of the MAC CE that needs protection.
[0066] In conjunction with some embodiments of the first aspect, in some embodiments, the determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes:
[0067] The MAC PDU contains a second MAC CE and a first MAC CE, and all MAC CEs in the MAC PDU are protected.
[0068] In conjunction with some embodiments of the first aspect, in some embodiments, the determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes:
[0069] For one or more of the following, determine whether to perform integrity protection on the MAC CE without encryption protection:
[0070] The terminal is in a connected state or an inactive state, and the MAC CE is included in the message MsgA of the two-step competitive random access CBRA.
[0071] MAC CE in the four-step random access message Msg4.
[0072] In this embodiment of the disclosure, the communication device can perform partial protection processing on the MAC CE as needed, thereby minimizing the resources consumed by MAC CE protection while ensuring service reliability.
[0073] In conjunction with some embodiments of the first aspect, in some embodiments, the determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes one or more of the following:
[0074] When performing CG small data transfer SDT with configuration authorization, MAC CE is protected.
[0075] The MAC CE is protected by performing random access RA SDT.
[0076] In conjunction with some embodiments of the first aspect, in some embodiments the above method further includes:
[0077] Send or receive indication information, wherein the indication information is used to indicate whether the function of protecting MAC CE is enabled during SDT.
[0078] In this embodiment of the disclosure, the function of protecting the MAC CE can be controlled to be turned on or off, which improves the flexibility of MAC CE protection.
[0079] In conjunction with some embodiments of the first aspect, in some embodiments, the determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes one or more of the following:
[0080] For RA SDT with 4-step contention random access to CBRA, MAC CE in Msg3 is not protected.
[0081] For the RA SDT and MsgA in the 2-step contention random access to CBRA, integrity protection is performed, but no encryption protection is performed.
[0082] In the embodiments of this disclosure, different processing can be performed on MAC CE in different access messages as needed, thereby improving the flexibility of MAC CE processing while ensuring the reliability of MAC CE, and providing conditions for reducing the power consumption wasted on MAC CE protection.
[0083] Secondly, embodiments of this disclosure provide a communication device, which includes: a processing module and a transceiver module, wherein...
[0084] The processing module is used to determine whether to perform MACCE protection processing, wherein the MACCE protection function is active.
[0085] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further configured to:
[0086] If a MAC CE meets one or more of the following conditions, no protection will be applied to the MAC CE:
[0087] Included in message Msg3;
[0088] Included in the two-step random access message MsgA;
[0089] To fill the buffer status report (BSR), and this is the only padding BSR in the MAC protocol data unit (PDU) containing the MAC CE;
[0090] It is included in message Msg4.
[0091] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further configured to:
[0092] The MAC CE is the first MAC CE, and protection processing is performed on the first MAC CE. The first MAC CE is one or more of the following:
[0093] Mobility LTM cell handover command MAC CE triggered by Layer 1 and / or Layer 2;
[0094] Discontinuous reception of DRX command MAC CE;
[0095] Long DRX command MAC CE;
[0096] Beam failure recovery BFR MAC CE;
[0097] MAC CE used to activate or deactivate the data retransmission function;
[0098] MAC CE used to control the activation or deactivation of the semi-persistent SP channel state information reference signal CSI-RS and / or CSI interference measurement resource set;
[0099] MAC CE used to control the activation or deactivation of the SP probe reference signal SRS;
[0100] MAC CE used to control the activation or deactivation of the physical uplink control channel (PUCCH) spatial relationships;
[0101] MAC CE used to control the activation or deactivation of the SP zero-power CSI-RS resource set;
[0102] MAC CE including time increment;
[0103] The MAC CE used to control the terminal-specific Physical Downlink Shared Channel (PDSCH) transmission configuration indication TCI status activation or deactivation;
[0104] MAC CE used to indicate the TCI state of a specific physical downlink control channel (PDCCH) of a terminal;
[0105] MAC CE used to activate or deactivate secondary cell SCell;
[0106] MAC CE is used to indicate that the Listen Before You Speak (LBT) has failed.
[0107] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further configured to:
[0108] Perform one or more of the following on the MAC PDU containing the first MAC CE:
[0109] The first MAC CE is protected, while other MAC CEs in the MAC PDU besides the first MAC CE are not protected.
[0110] All MAC CEs in the MAC PDU are protected;
[0111] The MAC CEs other than the second MAC CE in the MAC PDU are protected, wherein the second MAC CE is not exactly the same as the first MAC CE, or is completely different.
[0112] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further configured to:
[0113] The first MAC CE is not included in the following messages: Msg3, MsgA, Msg4.
[0114] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further configured to:
[0115] The MAC protocol data unit (PDU) contains a second MAC CE. The second MAC CE is not protected. The second MAC CE is one or more of the following: regular buffer status report (BSR), filling BSR, periodic BSR, power remaining report (PHR), cell radio network temporary identifier (C-RNTI), terminal contention resolution identifier, MAC CE for confirming configuration authorization, and MAC CE for recommended bit rate.
[0116] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further configured to:
[0117] The MAC PDU contains only one or more of the second MAC CEs, and no protection processing is applied to the second MAC CEs;
[0118] The MAC PDU also includes a first MAC CE. The first MAC CE is protected, while all other MAC CEs in the MAC PDU except the first MAC CE are not protected.
[0119] The MAC PDU also includes a first MAC CE, which protects all other MAC CEs in the MAC PDU except for the second MAC CE.
[0120] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further configured to:
[0121] The MAC PDU contains a second MAC CE and a first MAC CE, and all MAC CEs in the MAC PDU are protected.
[0122] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further configured to:
[0123] For one or more of the following, determine whether to perform integrity protection on the MAC CE without encryption protection:
[0124] The terminal is in a connected state or an inactive state, and the MAC CE is included in the message MsgA of the two-step competitive random access CBRA.
[0125] MAC CE in the four-step random access message Msg4.
[0126] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further configured to perform one or more of the following:
[0127] When performing CG small data transfer SDT with configuration authorization, MAC CE is protected.
[0128] The MAC CE is protected by performing random access RA SDT.
[0129] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described communication device further includes a transceiver module, used for:
[0130] Send or receive indication information, wherein the indication information is used to indicate whether the function of protecting MAC CE is enabled during SDT.
[0131] In conjunction with some embodiments of the second aspect, in some embodiments, the above-described processing module is further configured to perform one or more of the following:
[0132] For RA SDT with 4-step contention random access to CBRA, MAC CE in Msg3 is not protected.
[0133] For the RA SDT and MsgA in the 2-step contention random access to CBRA, integrity protection is performed, but no encryption protection is performed.
[0134] Thirdly, embodiments of this disclosure provide a communication device, which includes one or more processors; wherein the communication device is used to execute the first aspect and optional implementations of the first aspect.
[0135] Fourthly, embodiments of this disclosure provide a communication system comprising: a terminal and a network device; wherein the terminal and the network device are configured to perform the methods described in the first aspect and optional implementations thereof.
[0136] Fifthly, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in the first aspect and its optional implementations.
[0137] In a sixth aspect, embodiments of this disclosure provide a program product that, when executed by a communication device, causes the communication device to perform the method as described in the first aspect and its optional implementations.
[0138] In a seventh aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the methods described in the first aspect and optional implementations of the first aspect.
[0139] Eighthly, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the methods described according to the first aspect and optional implementations thereof.
[0140] It is understood that the aforementioned terminals, network devices, access network devices, core network devices, communication devices, communication systems, storage media, program products, computer programs, chips, or chip systems are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0141] This disclosure provides an information processing method, a communication device, a communication system, and a storage medium. In some embodiments, the terms "information processing method" and "communication method" can be used interchangeably; the terms "information processing method apparatus" and "communication apparatus" can be used interchangeably; and the terms "message transmission system" and "information processing system" can be used interchangeably.
[0142] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0143] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0144] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0145] In this disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the aforementioned," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular or a plural expression.
[0146] In the embodiments disclosed herein, "multiple" refers to two or more.
[0147] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.
[0148] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of B); in some embodiments, B (execute B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.
[0149] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.
[0150] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.
[0151] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0152] In some embodiments, the terms “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “if…”, “if…”, etc., can be used interchangeably.
[0153] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.
[0154] In some embodiments, the apparatus and device may be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. In some cases, they may also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "body", etc.
[0155] In some embodiments, "network" can be interpreted as devices included in the network, such as access network devices, core network devices, etc.
[0156] In some embodiments, "access network device (AN device)" may also be referred to as "radio access network device (RAN device)," "base station (BS)," "radio base station," or "fixed station." In some embodiments, it may also be understood as "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," or "bandwidth part (BWP)."
[0157] In some embodiments, "terminal" or "terminal device" may be referred to as "user equipment (UE)," "user terminal," "Narrow Band-Internet of Things (NB-IoT) device," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," etc.
[0158] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.
[0159] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.
[0160] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.
[0161] In some embodiments, data, information, etc., may be obtained with the user's consent.
[0162] Figure 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.
[0163] As shown in Figure 1, the communication system 100 includes a terminal 101 and a network device 102.
[0164] In some embodiments, terminal 101 includes, but is not limited to, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home.
[0165] In some embodiments, network device 102 may include at least one of access network device and core network device.
[0166] In some embodiments, the access network device is, for example, a node or device that connects a terminal to a wireless network. The access network device may include, but is not limited to, at least one of the following in a 5G communication system: evolved Node B (eNB), next-generation eNB (ng-eNB), next-generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system.
[0167] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.
[0168] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.
[0169] In some embodiments, a core network device may be a single device comprising one or more network elements, or it may be multiple devices or a group of devices, each comprising all or part of the aforementioned one or more network elements. Network elements may be virtual or physical. The core network may include, for example, at least one of an Evolved Protocol Core (EPC), a 5G Core Network (5GCN), or a Next Generation Core (NGC).
[0170] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.
[0171] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1 are illustrative. The communication system may include all or some of the main bodies in FIG1, or may include other main bodies outside of FIG1. The number and form of each main body are arbitrary. Each main body may be physical or virtual. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.
[0172] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other communication methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).
[0173] The relevant protocols propose to encrypt and protect the integrity of Radio Resource Control (RRC) messages in order to prevent the content transmitted through RRC messages from being attacked.
[0174] Optionally, RRC messages can be classified into P-type RRC messages, AI-type RRC messages, and AC-type RRC messages according to the protection strategy.
[0175] Among them, P-class RRC messages are messages that can be sent (unprotected) before AS security is activated; A–I-class RRC messages are messages that can be sent without integrity protection after the Access Stratum (AS) security is activated; and A–C-class RRC messages are messages that can be sent without encryption after the AS security is activated.
[0176] Currently, the Media Access Control (MAC) layer control element (CE) is not encrypted or protected for integrity. As a type of control signaling, the MAC CE may pose security risks if not encrypted and protected for integrity.
[0177] For example, if the MAC CE of the cell switch command (L1 / L2 Triggered Mobility, LTM) received by the terminal is tampered with, the terminal may switch to an illegal cell, thereby affecting the execution of terminal services.
[0178] Alternatively, if the terminal receives the attacked GNSS measurement command MAC CE, it will retune to the GNSS frequency to measure GNSS, thereby affecting the terminal's normal communication.
[0179] Alternatively, the terminal's private data may be tampered with. For example, if the terminal's report of the remaining validity period of the Global Navigation Satellite System (GNSS) data to the network device is altered, it may lead to the early or delayed release of the RRC. Or, if the terminal's private Timing Advance (TA) Command MAC CE is obtained by a third party, that third party can identify the terminal's location range relative to the network device, and so on.
[0180] This disclosure proposes a method for protecting MAC CEs. Before sending a MAC CE, the communication device can first protect the MAC CE, thereby improving the security and integrity of MAC CE transmission and providing conditions for avoiding the leakage of private data and improving the security and reliability of transmission.
[0181] The information processing method, communication equipment, communication system, and storage medium provided in this disclosure will be described in detail below with reference to the accompanying drawings.
[0182] Figure 2A is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure. As shown in Figure 2A, the information processing method according to the embodiment of the present disclosure is executed by a communication device, which can be a terminal or a network device. As shown in Figure 2A, the above method includes:
[0183] In step S2101, the MAC CE protection function is activated, and no protection processing is performed on a specific MAC CE.
[0184] In some embodiments, MAC CE protection includes MAC CE encryption protection and / or MAC CE integrity protection.
[0185] In some embodiments, MAC CE integrity protection includes performing integrity protection on the MAC CE based on integrity protection parameters, such as keys, integrity protection associated count (COUNT) values, transmission direction parameters, etc., to obtain a protection tag.
[0186] In some embodiments, the integrity protection associated count value is used to characterize the number of times integrity protection processing is performed on the MAC CE, and the count value is incremented by 1 each time integrity protection is completed.
[0187] In some embodiments, a transmission direction parameter is used to describe the transmission direction of the MAC CE. For example, it may be downlink (DL) and / or uplink (UL), etc.
[0188] In some embodiments, a protection tag is used to assist the receiving end in verifying the integrity of the received MAC CE after receiving it.
[0189] In some embodiments, terms such as “protection tag”, “message authentication code-integrity (MAC-I)”, “message integrity verification identifier”, “message integrity authentication code”, “information integrity verification identifier”, and “information integrity authentication code” can all indicate auxiliary information used to verify the integrity of a message (or information). In some scenarios, the above terms can be used interchangeably.
[0190] In some embodiments, the receiving end (such as a terminal or network device) can perform integrity calculations on the received MAC CE based on the same logic as the sending end (such as a network device or terminal) to obtain a new protection tag. If the protection tag obtained by the receiving end is the same as the received protection tag, it can be determined that the MAC CE has not been tampered with. This ensures the reliability and security of the received MAC CE and avoids service anomalies caused by the receiving end responding to information contained in a tampered MAC CE.
[0191] In some embodiments, MAC CE encryption protection can be achieved by encrypting the MAC CE based on encryption protection parameters, such as keys, counter values, transmission direction parameters, length values, etc., resulting in an encrypted MAC CE. By encrypting the MAC CE, it is possible to prevent third parties from illegally obtaining the information contained in the MAC CE, thus avoiding the leakage of private information.
[0192] In some embodiments, the length value is used to characterize the length of the MAC CE that needs to be encrypted.
[0193] In some embodiments, if multiple MAC CEs need to be encrypted as a whole, the length value can be the total length of the multiple MAC CEs.
[0194] In some embodiments, MAC CE includes UL MAC CE and DL MAC CE.
[0195] In some embodiments, MACCE protection includes one or more of the following: UL MAC CE encryption protection, UL MAC CE integrity protection, DL MAC CE encryption protection, and DL MAC CE integrity protection.
[0196] In some embodiments, the leakage or attack on some of the content carried by the MAC CE will not affect the operation of the business, so the MAC CE protection function can be activated or deactivated as needed.
[0197] In some embodiments, the activation of the MAC CE protection function can be determined based on protocol agreements or network configuration.
[0198] In some embodiments, when the MAC CE protection function is active, the communication device may not perform protection processing on a specific MAC CE.
[0199] In some embodiments, a specific MAC CE may be the MAC CE contained in message (Msg)3. Since the terminal or network device can trigger the retransmission of Msg3 as needed, in order to reduce the terminal's power consumption and processing burden, when the MAC CE protection function is active, the terminal may also not perform protection processing on the MAC CE contained in Msg3, such as not performing encryption protection and / or integrity protection on the MAC CE contained in Msg3.
[0200] In some embodiments, when the MAC CE protection function is active, the communication device may also not perform protection processing on specific MAC CEs contained in the two-step random access (RA) message MsgA. Since MsgA can also be retransmitted as needed, when the MAC CE protection function is active, the terminal may also not perform protection processing on the MAC CEs contained in MsgA, thereby avoiding unnecessary power consumption and processing burden on the terminal.
[0201] In some embodiments, the two-step RA includes two-step non-contention-free random access (CFRA) MsgA and two-step contention-based random access (CBRA) MsgA.
[0202] In some embodiments, when the MAC CE protection function is activated, the communication device may not perform protection processing on the MAC CE containing the padding buffer status reporting (BSR). In this case, the MAC protocol data unit (PDU) containing the MAC CE only contains the padding BSR.
[0203] In this embodiment of the disclosure, since the padding BSR is content added by the terminal to the MAC PDU to avoid resource waste, its leakage or attack will not affect the security and reliability of the terminal. At this time, the terminal may not need to protect the MAC PDU containing only the padding BSR, thereby avoiding wasting the terminal's power consumption.
[0204] In some embodiments, when the MAC CE protection function is active, the network device may not protect the MAC CE contained in message Msg4. Since Msg4 can also be retransmitted as needed, the network device may not protect the MAC CE contained in Msg4 when the MAC CE protection function is active, thereby avoiding unnecessary power consumption and processing burden on the network device.
[0205] In this embodiment, the terminal and network device can be in a state where the MAC CE protection function is active, and the specific MAC CE can be left unprotected, thereby improving the flexibility of MAC CE protection and minimizing the waste of resources due to MAC CE protection.
[0206] Figure 2B is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure. As shown in Figure 2B, the information processing method according to the embodiment of the present disclosure is executed by a communication device, which can be a terminal or a network device. As shown in Figure 2B, the above method includes:
[0207] In step S2201, the MAC CE protection function is activated, and the first MAC CE is protected.
[0208] In some embodiments, the specific implementation of the protection processing of the first MAC CE can be referred to in the detailed description of step S2101, which will not be repeated here.
[0209] In some embodiments, the first MAC CE can be a cell switch command triggered based on Layer 1 and / or Layer 2 (L1 / L2 Triggered Mobility, LTM). Since tampering with the LTM Cell Switch Command MAC CE could cause the terminal to switch to an illegal cell, thus affecting normal terminal communication, protecting the LTM Cell Switch Command MAC CE can prevent tampering and improve the security and reliability of terminal services.
[0210] In some embodiments, the first MAC CE may be a Discontinuous Reception (DRX) command MAC CE or a Long DRX command MAC CE.
[0211] In this embodiment, the DRX command, or Long DRX command, can instruct the terminal to periodically listen to the channel, thereby reducing the terminal's power consumption when it does not need to receive data, thus extending the terminal's battery life. If this command is tampered with, it may cause the terminal to obtain incorrect listening timing, thereby affecting the reliable execution of terminal services. By protecting the DRX command MAC CE, or Long DRX command MAC CE, tampering of the (long) DRX command MAC CE is prevented, ensuring that the terminal can accurately determine the listening timing and improving the terminal's performance.
[0212] In some embodiments, the first MAC CE can be a Beam Failure Recovery (BFR) MAC CE.
[0213] In this embodiment, when a user equipment (UE) detects a beam failure, it triggers a beam failure recovery process by transmitting a BFR MAC CE. The BFR MAC CE contains information about the beam failure, which is crucial for network devices (such as gNBs) as they need this information to select an appropriate beam for recovery. If the BFR MAC CE is tampered with, the network device may be unable to select an appropriate beam for recovery, resulting in the terminal being unable to perform beam failure recovery in a timely manner and reducing the terminal's service level. By protecting the BFR MAC CE, tampering with the BFR MAC CE is prevented, ensuring the reliability and security of terminal services.
[0214] In some embodiments, the first MAC CE may be a MAC CE used to activate or deactivate the duplication activation / deactivation function for data.
[0215] In this embodiment of the disclosure, by protecting the Duplication Activation / Deactivation MAC CE, it is ensured that the terminal can accurately determine whether to activate or deactivate the data retransmission function, thus ensuring that the data transmission meets the service requirements.
[0216] In some embodiments, the first MAC CE may be a MAC CE for controlling the activation or deactivation of the Semi-Persistent (SP) Channel State Information-Reference Signal (CSI-RS) and / or the CSI Interference Measurement (IM) Resource Set, and / or a MAC CE for controlling the activation or deactivation of the SP Sounding Reference Signal (SRS).
[0217] In this embodiment of the disclosure, by protecting the SP CSI-RS / CSI-IM Resource Set Activation / Deactivation MAC CE and / or the SP SRS Activation / Deactivation MAC CE, the terminal can accurately and reliably activate or deactivate the SRS, CSI-RS resource sets, and / or the CSI-IM resource sets, thereby ensuring the reliable execution of channel measurements and providing conditions for ensuring the reliability and security of terminal services.
[0218] In some embodiments, the first MAC CE may be a MAC CE used to activate or deactivate the spatial relation of the Physical Uplink Control Channel (PUCCH).
[0219] When the network needs to change the PUCCH transmission beam, it activates the new spatial relation by sending a PUCCH spatial relation Activation / Deactivation MAC CE. Conversely, when the spatial relation is no longer needed, it is deactivated by sending a deactivation MAC CE. If this MAC CE is tampered with, the terminal may not be able to activate or deactivate the corresponding beam in time, resulting in uplink transmission failure. In this embodiment, by protecting the MAC CE containing the PUCCH spatial relation activation or deactivation, it is ensured that the terminal can activate or deactivate the correspondence between the PUCCH transmission beam and a certain reference signal (such as a Synchronization Signal Block (SSB), CSI-RS, or SRS) in a timely manner, thus ensuring the reliability of terminal communication.
[0220] In some embodiments, the first MAC CE can be a MAC CE used to control the activation or deactivation of the SP Zero Power CSI-RS resource set. Typically, Zero Power CSI-RS is a virtual resource that does not transmit signals and is used for interference measurement. When the network requires the UE to perform interference measurement, it activates the corresponding resource set by sending this MAC CE. Conversely, when the measurement is no longer needed, it stops the measurement by sending a deactivation MAC CE. By protecting this MAC CE, it can be ensured that the terminal can accurately start or stop interference measurement, improving the accuracy and reliability of the measurement results.
[0221] In some embodiments, the first MAC CE can be a MAC CE that includes a timing delta. By protecting this MAC CE, the timing delta corresponding to the terminal can be prevented from being tampered with, thereby ensuring that the terminal can perform accurate and reliable time synchronization and guaranteeing the reliability of communication.
[0222] In some embodiments, the first MAC CE can be a MAC CE used to activate or deactivate a Transmission Configuration Indication (TCI) state for controlling a terminal-specific Physical Downlink Shared Channel (PDSCH). Since the TCI state defines the beamforming or spatial relationships for PDSCH reception, by sending this MAC CE, the network can instruct the UE to use a specific TCI state when receiving PDSCH, or to deactivate a certain TCI state. Protecting this MAC CE ensures that the terminal can accurately and reliably receive it, providing conditions for optimizing downlink transmission performance and improving the reliability and efficiency of data reception.
[0223] In some embodiments, the first MAC CE can be a MAC CE used to indicate the TCI state of a specific Physical Downlink Control Channel (PDCCH) of the terminal. By protecting this MAC CE, the terminal can accurately determine the TCI state used when receiving the PDCCH, thereby ensuring that the terminal can decode downlink control information more accurately, thus improving the overall performance of the system.
[0224] In some embodiments, the first MAC CE can be a MAC CE used to activate or deactivate a secondary cell (SCell). By protecting this MAC CE, it is ensured that the terminal can accurately activate or deactivate the SCell indicated by the network device, thereby ensuring the utilization of network resources and improving network stability and efficiency.
[0225] In some embodiments, the first MAC CE can be a MAC CE used to indicate a Listen Before Talk (LBT) failure. By protecting this MAC CE, channel conflicts and resource waste are accurately avoided, thereby improving the performance of the communication system.
[0226] Step S2202: Do not perform protection processing on other MAC CEs in the MAC PDU that contains the first MAC CE, except for the first MAC CE.
[0227] For example, if a MAC PDU includes a first MAC CE and other MAC CEs, the communication device can encrypt and / or protect the integrity of the first MAC CE, while leaving the other MAC CEs unprotected. This minimizes the resources used to protect the MAC CEs while ensuring their security and reliability.
[0228] In some embodiments, if the MAC PDU contains a first MAC CE and other MAC CEs, all MAC CEs in the MAC PDU may also be protected.
[0229] In some embodiments, when the MAC PDU contains a first MAC CE and other MAC CEs, the other MAC CEs in the MAC PDU besides the second MAC CE can also be protected, wherein the second MAC CE is not exactly the same as the first MAC CE, or is completely different.
[0230] In some embodiments, the second MAC CE may be a MAC CE that is agreed upon by the protocol or indicated by the network device and does not require protection at this time.
[0231] In some embodiments, the first MAC CE is not included in the following messages: Msg3, MsgA, Msg4.
[0232] In this embodiment of the disclosure, since the MAC CE in Msg3, MsgA, or Msg4 may not be protected, in order to ensure the security of the first MAC CE, the first MAC CE may not be protected in Msg3, MsgA, or Msg4, thereby ensuring the security and reliability of the first MAC CE, and thus providing conditions for ensuring the reliable and stable operation of communication services.
[0233] Figure 2C is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure. As shown in Figure 2C, the information processing method according to the embodiment of the present disclosure is executed by a communication device, which can be a terminal or a network device. As shown in Figure 2C, the above method includes:
[0234] In step S2301, the MAC CE protection function is activated. The MACPDU contains a second MAC CE, but no protection processing is performed on the second MAC CE.
[0235] In some embodiments, the second MAC CE is one or more of the following: regular buffer status report (BSR), filling BSR, periodic BSR, power headroom report (PHR), cell-radio network temporary identifier (C-RNTI), terminal contention resolution identity, MAC CE for confirming configured grant confirmation, and MAC CE for recommending bit rate.
[0236] In this embodiment of the disclosure, since the tampering of the MAC CE, which includes BSR, PHR, C-RNTI, contention resolution identifier, etc., will not cause service failure, in order to minimize the power consumption and processing burden of the communication device, when the MAC PDU includes a second MAC CE, the second MAC CE may not be protected.
[0237] In some embodiments, if the MAC PDU contains only one or more of the second MAC CEs, then the second MAC CEs may not need to be protected.
[0238] In some embodiments, if the MAC PDU also contains a first MAC CE, then the first MAC CE can be protected, while all other MAC CEs in the MAC PDU except the first MAC CE are not protected.
[0239] In some embodiments, if the MAC PDU also contains a first MAC CE, then all other MAC CEs in the MAC PDU except for the second MAC CE can be protected. That is, if the MAC PDU contains a first MAC CE and a second MAC CE, then all other MAC CEs except for the second MAC CE (there may be other MAC CEs besides the first MAC CE) can be protected.
[0240] In some embodiments, if the MAC PDU contains both a second MAC CE and a first MAC CE, all MAC CEs in the MAC PDU are protected. That is, if the MAC PDU contains both a first MAC CE and a second MAC CE, then all MAC CEs can be protected, thereby simplifying the complexity of protecting the MAC PDU.
[0241] In this embodiment of the disclosure, when the MAC CE protection function is activated and the second MAC CE is protected in the MAC PDU, it is possible to determine whether to protect each MAC CE in the MAC PDU as needed, thereby improving the flexibility and reliability of MAC CE protection.
[0242] Figure 2D is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure. As shown in Figure 2D, the information processing method according to the embodiment of the present disclosure is executed by a communication device, which can be a terminal or a network device. As shown in Figure 2D, the above method includes:
[0243] Step S2401: The MAC CE protection function is active, the terminal is in a connected state or an inactive state, and the MAC CE is included in the CBRA message MsgA. It is determined that the MAC CE will be subjected to integrity protection processing, but no encryption protection processing will be performed.
[0244] In this embodiment of the disclosure, since private information is not protected in CBRAMsgA, only integrity protection can be performed on CBRAMsgA without encryption protection, thereby minimizing the power consumption of the terminal while ensuring reliable completion of random access.
[0245] In some embodiments, the MAC CE in the four-step random access message Msg4 may only undergo integrity protection processing without encryption protection. This minimizes the terminal's power consumption while ensuring reliable random access.
[0246] Figure 2E is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure. As shown in Figure 2E, the information processing method according to the embodiment of the present disclosure is executed by a communication device, which can be a terminal or a network device. As shown in Figure 2E, the above method includes:
[0247] Step S2501: Send or receive instruction information.
[0248] The indication information is used to indicate whether the function of protecting the MAC CE is enabled during SDT.
[0249] In this embodiment of the disclosure, the function of protecting MAC CE in SDT scenarios can be enabled or disabled as needed. This improves the flexibility of MAC CE protection in SDT scenarios and provides conditions for reducing terminal power consumption.
[0250] In some embodiments, the network can configure the MAC CE security parameters used by the terminal during SDT, such as security algorithms and keys.
[0251] In some embodiments, the MAC CE encryption / integrity protection configuration indicated by the indication information may apply only to the cell where the terminal is located, or to an area (which may be configured by the network), or to the current Radio Access Network (RNA) notification area.
[0252] Step S2502: The instruction message indicates that the MAC CE protection function is enabled, and the MAC CE is protected when the CG small data transmission SDT configuration authorization is executed.
[0253] In this embodiment of the disclosure, if the MAC CE protection function is active and CG SDT is being executed, that is, the terminal is transmitting data based on pre-configured resources, then protecting the MAC CE at this time can ensure that the data can be transmitted reliably, avoid resource waste, and improve resource utilization.
[0254] In some embodiments, if the MAC CE protection function is active and Random Access (RA) SDT is being performed, MAC CE protection can be applied.
[0255] In this embodiment, since the terminal needs to randomly access the target cell based on a contention-based method to establish a connection with the target cell, and then transmit small packet data based on the connection established with the target cell, protecting the MAC CE at this time provides conditions for improving the security and reliability of data transmission.
[0256] In some embodiments, when the MAC CE protection function is active and there is a 4-step contention for random access to CBRA RA SDT, MAC CE protection in Msg3 may not be performed. Alternatively, in the case of a 2-step contention for random access to CBRA RA SDT, integrity protection may be performed on the MAC CE in MsgA, but encryption protection may not be performed.
[0257] In this embodiment of the disclosure, by selecting whether to protect the MAC CE and the method of protection according to the specific scenario of SDT, the flexibility of MAC CE protection is improved while ensuring reliable transmission of SDT.
[0258] Figure 3 is an interactive schematic diagram of an information processing method according to an embodiment of the present disclosure. As shown in Figure 3, the information processing method involved in this embodiment is executed by a communication device, which can be a terminal or a network device. As shown in Figure 3, the above method includes:
[0259] Step S3101: Determine whether to perform MACCE protection processing, wherein the MACCE protection function is in an active state.
[0260] In some embodiments, determining whether to perform protection processing on the Media Access Control (MAC) control unit CE includes:
[0261] If a MAC CE meets one or more of the following conditions, no protection will be applied to the MAC CE:
[0262] Included in message Msg3;
[0263] Included in the two-step random access message MsgA;
[0264] To fill the buffer status report (BSR), and this is the only padding BSR in the MAC protocol data unit (PDU) containing the MAC CE;
[0265] It is included in message Msg4.
[0266] In some embodiments, determining whether to perform protection processing on the Media Access Control (MAC) control unit CE includes:
[0267] The MAC CE is the first MAC CE, and protection processing is performed on the first MAC CE. The first MAC CE is one or more of the following:
[0268] Mobility LTM cell handover command MAC CE triggered by Layer 1 and / or Layer 2;
[0269] Discontinuous reception of DRX command MAC CE;
[0270] Long DRX command MAC CE;
[0271] Beam failure recovery BFR MAC CE;
[0272] MAC CE used to activate or deactivate the data retransmission function;
[0273] MAC CE used to control the activation or deactivation of the semi-persistent SP channel state information reference signal CSI-RS and / or CSI interference measurement resource set;
[0274] MAC CE used to control the activation or deactivation of the SP probe reference signal SRS;
[0275] MAC CE used to control the activation or deactivation of the physical uplink control channel (PUCCH) spatial relationships;
[0276] MAC CE used to control the activation or deactivation of the SP zero-power CSI-RS resource set;
[0277] MAC CE including time increment;
[0278] The MAC CE used to control the terminal-specific Physical Downlink Shared Channel (PDSCH) transmission configuration indication TCI status activation or deactivation;
[0279] MAC CE used to indicate the TCI state of a specific physical downlink control channel (PDCCH) of a terminal;
[0280] MAC CE used to activate or deactivate secondary cell SCell;
[0281] MAC CE is used to indicate that the Listen Before You Speak (LBT) has failed.
[0282] In some embodiments, the above-described protection processing for the first MAC CE includes:
[0283] Perform one or more of the following on the MAC PDU containing the first MAC CE:
[0284] The first MAC CE is protected, while other MAC CEs in the MAC PDU besides the first MAC CE are not protected.
[0285] All MAC CEs in the MAC PDU are protected;
[0286] The MAC CEs other than the second MAC CE in the MAC PDU are protected, wherein the second MAC CE is not exactly the same as the first MAC CE, or is completely different.
[0287] In some embodiments, the above method further includes:
[0288] The first MAC CE is not included in the following messages: Msg3, MsgA, Msg4.
[0289] In some embodiments, the determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes:
[0290] The MAC protocol data unit (PDU) contains a second MAC CE. The second MAC CE is not protected. The second MAC CE is one or more of the following: regular buffer status report (BSR), filling BSR, periodic BSR, power remaining report (PHR), cell radio network temporary identifier (C-RNTI), terminal contention resolution identifier, MAC CE for confirming configuration authorization, and MAC CE for recommended bit rate.
[0291] In some embodiments, the second MAC CE is not protected as described above, including any of the following:
[0292] The MAC PDU contains only one or more of the second MAC CEs, and no protection processing is applied to the second MAC CEs;
[0293] The MAC PDU also includes a first MAC CE. The first MAC CE is protected, while all other MAC CEs in the MAC PDU except the first MAC CE are not protected.
[0294] The MAC PDU also includes a first MAC CE, which protects all other MAC CEs in the MAC PDU except for the second MAC CE.
[0295] In some embodiments, the determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes:
[0296] The MAC PDU contains a second MAC CE and a first MAC CE, and all MAC CEs in the MAC PDU are protected.
[0297] In some embodiments, the determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes:
[0298] For one or more of the following, determine whether to perform integrity protection on the MAC CE without encryption protection:
[0299] The terminal is in a connected state or an inactive state, and the MAC CE is included in the message MsgA of the two-step competitive random access CBRA.
[0300] MAC CE in the four-step random access message Msg4.
[0301] In some embodiments, the determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes one or more of the following:
[0302] When performing CG small data transfer SDT with configuration authorization, MAC CE is protected.
[0303] The MAC CE is protected by performing random access RA SDT.
[0304] In some embodiments, the above method further includes:
[0305] Send or receive indication information, wherein the indication information is used to indicate whether the function of protecting MAC CE is enabled during SDT.
[0306] In some embodiments, the determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes one or more of the following:
[0307] For RA SDT with 4-step contention random access to CBRA, MAC CE in Msg3 is not protected.
[0308] For the RA SDT and MsgA in the 2-step contention random access to CBRA, integrity protection is performed, but no encryption protection is performed.
[0309] The information processing method provided in this disclosure will be further explained below with reference to the following embodiments, taking a communication device as an example.
[0310] When the MAC CE encryption / integrity protection function is activated, encryption and / or integrity protection of the MAC CE may be performed under certain circumstances.
[0311] Optionally, the MAC CE may not be encrypted and / or protected for one or more of the following specific cases: the MAC CE is contained in Msg3; the MAC CE is contained in 2-step CFRA MsgA; the MAC CE is contained in 2-step CBRA MsgA; the MAC CE is a padding BSR, and the MAC PDU contains only the padding BSR; the MAC CE is contained in Msg4.
[0312] In some embodiments, when the MAC PDU contains a specific MAC CE, the specific MAC CE is encrypted and / or protected for integrity. The specific MAC CE is at least one of the following: LTM cell switch command; DRX command; long DRX command; Timing Advance Report; Timing Advance Command; BFR MAC CE; Duplication Activation / Deactivation; Semi-Persistent Channel State Information Reference Signal and / or CSI Interference Measurement Resource Set Activation / Deactivation; SP Probe Reference Signal Activation / Deactivation; Physical Uplink Control Channel Spatial Relation Activation / Deactivation; SP Zero Power CSI-RS Resource Set Activation / Deactivation; Timing... Delta); TCI States Activation / Deactivation for UE-specific PDSCH; TCI State Indication for UE-specific PDCCH; LBT failure MAC CE.
[0313] In some embodiments, the aforementioned MAC CEs: Msg3, MsgA, and Msg4 are not included in the following messages.
[0314] Optionally, when the MAC PDU contains the specific MAC CE, the following processing methods are available:
[0315] Encryption / integrity protection is performed only on the specific MAC CE, and no encryption / integrity protection is performed on other MAC CEs;
[0316] Encrypt / protect the integrity of all MAC CEs;
[0317] Encryption / integrity protection is applied to all MAC CEs (excluding a few special MAC CEs).
[0318] In some embodiments, the special MAC CE, such as the padding BSR, can be any of the special MAC CEs listed in the following embodiments.
[0319] Optionally, a specific MAC CE may be included in the MAC PDU without encryption and / or integrity protection. The specific MAC CE may include one or more of the following: regular BSR; padding BSR; periodic BSR; power remaining report PHR; C-RNTI; UE Contention Resolution Identity; Configured Grant Confirmation MAC CE; and Recommended bit rate MAC CE.
[0320] In some embodiments, when the specific MAC CE is included in the MAC PDU, the following processing methods are used:
[0321] No encryption or integrity protection is provided for the specific MAC CE;
[0322] If the MAC PDU contains only one or more of the specific MAC CE, then the specific MAC CE is not encrypted or protected for integrity.
[0323] If the MAC PDU contains one or more of the specific MAC CEs, as well as MAC CEs that require encryption / integrity protection, it shall be processed according to the optional processing method described above.
[0324] Optionally, the UE may perform integrity protection for MAC CE without encryption in one or more of the following situations:
[0325] The terminal is in a connected state or an inactive state, and the MAC CE is contained in the 2-step CBRA MsgA.
[0326] MAC CE in Msg4.
[0327] In some embodiments, the terminal may encrypt and / or protect the integrity of the MAC CE when performing CG SDT and / or RA-SDT.
[0328] Optionally, the network can configure whether the terminal enables MAC CE encryption / integrity protection during SDT.
[0329] In some embodiments, the network can be configured via RRC signaling, such as RRC release messages, and can be configured separately for CG-SDT and RA-SDT, as well as separately for encryption and integrity protection.
[0330] Optionally, the network can configure the MAC CE security parameters used by the terminal during SDT, such as security algorithms and keys.
[0331] In some embodiments, the MAC CE encryption / integrity protection configuration applies only to the cell where the UE is located, or to an area configured by the network, or to the current RNA (RAN notification area).
[0332] In some embodiments, the MAC CE in msg3 of the RA-SDT of the 4-step CBRA is not encrypted or protected for integrity.
[0333] In some embodiments, the MAC CE in msgA of the RA-SDT of the 2-step CBRA is protected for integrity but not encrypted.
[0334] This disclosure also provides an apparatus for implementing any of the above methods. For example, an apparatus is provided that includes units or modules for implementing the steps performed by the terminal in any of the above methods. Alternatively, another apparatus is provided that includes units or modules for implementing the steps performed by a network device (e.g., an access network device, a core network functional node, a core network device, etc.) in any of the above methods.
[0335] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.
[0336] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).
[0337] Figure 4 is a schematic diagram of the structure of a communication device according to an embodiment of this disclosure. As shown in Figure 4, the communication device 4100 may include at least one of a transceiver module 5101, a processing module 5102, etc. In some embodiments, the processing module is used to determine whether to perform MAC CE protection processing, wherein the MAC CE protection function is in an active state.
[0338] In some embodiments, the above-described processing module is further configured to:
[0339] If a MAC CE meets one or more of the following conditions, no protection will be applied to the MAC CE:
[0340] Included in message Msg3;
[0341] Included in the two-step random access message MsgA;
[0342] To fill the buffer status report (BSR), and this is the only padding BSR in the MAC protocol data unit (PDU) containing the MAC CE;
[0343] It is included in message Msg4.
[0344] In some embodiments, the above-described processing module is further configured to:
[0345] The MAC CE is the first MAC CE, and protection processing is performed on the first MAC CE. The first MAC CE is one or more of the following:
[0346] Mobility LTM cell handover command MAC CE triggered by Layer 1 and / or Layer 2;
[0347] Discontinuous reception of DRX command MAC CE;
[0348] Long DRX command MAC CE;
[0349] Beam failure recovery BFR MAC CE;
[0350] MAC CE used to activate or deactivate the data retransmission function;
[0351] MAC CE used to control the activation or deactivation of the semi-persistent SP channel state information reference signal CSI-RS and / or CSI interference measurement resource set;
[0352] MAC CE used to control the activation or deactivation of the SP probe reference signal SRS;
[0353] MAC CE used to control the activation or deactivation of the physical uplink control channel (PUCCH) spatial relationships;
[0354] MAC CE used to control the activation or deactivation of the SP zero-power CSI-RS resource set;
[0355] MAC CE including time increment;
[0356] The MAC CE used to control the terminal-specific Physical Downlink Shared Channel (PDSCH) transmission configuration indication TCI status activation or deactivation;
[0357] MAC CE used to indicate the TCI state of a specific physical downlink control channel (PDCCH) of a terminal;
[0358] MAC CE used to activate or deactivate secondary cell SCell;
[0359] MAC CE is used to indicate that the Listen Before You Speak (LBT) has failed.
[0360] In some embodiments, the above-described processing module is further configured to:
[0361] Perform one or more of the following on the MAC PDU containing the first MAC CE:
[0362] The first MAC CE is protected, while other MAC CEs in the MAC PDU besides the first MAC CE are not protected.
[0363] All MAC CEs in the MAC PDU are protected;
[0364] The MAC CEs other than the second MAC CE in the MAC PDU are protected, wherein the second MAC CE is not exactly the same as the first MAC CE, or is completely different.
[0365] In some embodiments, the above-described processing module is further configured to:
[0366] The first MAC CE is not included in the following messages: Msg3, MsgA, Msg4.
[0367] In some embodiments, the above-described processing module is further configured to:
[0368] The MAC protocol data unit (PDU) contains a second MAC CE. The second MAC CE is not protected. The second MAC CE is one or more of the following: regular buffer status report (BSR), filling BSR, periodic BSR, power remaining report (PHR), cell radio network temporary identifier (C-RNTI), terminal contention resolution identifier, MAC CE for confirming configuration authorization, and MAC CE for recommended bit rate.
[0369] In some embodiments, the above-described processing module is further configured to:
[0370] The MAC PDU contains only one or more of the second MAC CEs, and no protection processing is applied to the second MAC CEs;
[0371] The MAC PDU also includes a first MAC CE. The first MAC CE is protected, while all other MAC CEs in the MAC PDU except the first MAC CE are not protected.
[0372] The MAC PDU also includes a first MAC CE, which protects all other MAC CEs in the MAC PDU except for the second MAC CE.
[0373] In some embodiments, the above-described processing module is further configured to:
[0374] The MAC PDU contains a second MAC CE and a first MAC CE, and all MAC CEs in the MAC PDU are protected.
[0375] In some embodiments, the above-described processing module is further configured to:
[0376] For one or more of the following, determine whether to perform integrity protection on the MAC CE without encryption protection:
[0377] The terminal is in a connected state or an inactive state, and the MAC CE is included in the message MsgA of the two-step competitive random access CBRA.
[0378] MAC CE in the four-step random access message Msg4.
[0379] In some embodiments, the above-described processing module is further configured to perform one or more of the following:
[0380] When performing CG small data transfer SDT with configuration authorization, MAC CE is protected.
[0381] The MAC CE is protected by performing random access RA SDT.
[0382] In some embodiments, the communication device further includes a transceiver module for:
[0383] Send or receive indication information, wherein the indication information is used to indicate whether the function of protecting MAC CE is enabled during SDT.
[0384] In some embodiments, the above-described processing module is further configured to perform one or more of the following:
[0385] For RA SDT with 4-step contention random access to CBRA, MAC CE in Msg3 is not protected.
[0386] For the RA SDT and MsgA in the 2-step contention random access to CBRA, integrity protection is performed, but no encryption protection is performed.
[0387] Optionally, the transceiver module described above is used to perform at least one of the communication steps such as sending and / or receiving performed by the terminal in any of the above methods, which will not be elaborated here.
[0388] Optionally, the above processing module is used to perform at least one of the other steps executed by the terminal in any of the above methods, which will not be elaborated here.
[0389] Figure 5A is a schematic diagram of the structure of the communication device 5100 proposed in an embodiment of this disclosure. The communication device 5100 can be a network device (e.g., access network device, core network device, etc.), a terminal (e.g., user equipment, etc.), a chip, chip system, or processor that supports the network device in implementing any of the above methods, or a chip, chip system, or processor that supports the terminal in implementing any of the above methods. The communication device 5100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.
[0390] As shown in Figure 5A, the communication device 5100 includes one or more processors 5101. The processor 5101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. The communication device 5100 is used to execute any of the above methods.
[0391] In some embodiments, the communication device 5100 further includes one or more memories 5102 for storing instructions. Optionally, all or part of the memories 5102 may also be located outside the communication device 5100.
[0392] In some embodiments, the communication device 5100 further includes one or more transceivers 5103. When the communication device 5100 includes one or more transceivers 5103, the transceivers 5103 perform at least one of the communication steps such as sending and / or receiving in the above method, and the processor 5101 performs other steps, such as at least one of steps S2101, S2201, etc.
[0393] In some embodiments, a transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, etc., may be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., may be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., may be used interchangeably.
[0394] In some embodiments, the communication device 5100 may include one or more interface circuits 5104. Optionally, the interface circuit 5104 is connected to the memory 5102, and the interface circuit 5104 can be used to receive signals from the memory 5102 or other devices, and can be used to send signals to the memory 5102 or other devices. For example, the interface circuit 5104 can read instructions stored in the memory 5102 and send the instructions to the processor 5101.
[0395] The communication device 5100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 5100 described in this disclosure is not limited thereto, and the structure of the communication device 5100 may not be limited by FIG. 5A. The communication device may be a standalone device or a part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.
[0396] Figure 5B is a schematic diagram of the structure of chip 5200 according to an embodiment of this disclosure. For cases where the communication device 5100 can be a chip or a chip system, please refer to the schematic diagram of chip 5200 shown in Figure 5B, but it is not limited thereto.
[0397] Chip 5200 includes one or more processors 5201, which are used to perform any of the above methods.
[0398] In some embodiments, chip 5200 further includes one or more interface circuits 5202. Optionally, the interface circuit 5202 is connected to memory 5203, and the interface circuit 5202 can be used to receive signals from memory 5203 or other devices, and the interface circuit 5202 can be used to send signals to memory 5203 or other devices. For example, the interface circuit 5202 can read instructions stored in memory 5203 and send the instructions to processor 5201.
[0399] In some embodiments, the interface circuit 5202 performs at least one of the communication steps such as sending and / or receiving in the above method, and the processor 5201 performs at least one of the other steps, such as steps S2101 and S2201.
[0400] In some embodiments, the terms interface circuit, interface, transceiver pin, transceiver, etc., can be used interchangeably.
[0401] In some embodiments, chip 5200 further includes one or more memories 5203 for storing instructions. Optionally, all or part of the memories 5203 may be located outside of chip 5200.
[0402] This disclosure also proposes a storage medium storing instructions that, when executed on the communication device 5100, cause the communication device 5100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.
[0403] This disclosure also provides a program product that, when executed by the communication device 5100, causes the communication device 5100 to perform any of the above methods. Optionally, the program product is a computer program product.
[0404] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.
[0405] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer programs. When the computer program is loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this disclosure are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program can be transferred from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., high-density digital video discs (DVDs)), or semiconductor media (e.g., solid-state disks (SSDs)).
[0406] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.
[0407] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0408] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.
Claims
1. An information processing method, characterized in that, The method includes: Determine whether to perform protection processing on the Media Access Control (MAC) CE unit, wherein the MAC CE protection function is in an active state.
2. The method as described in claim 1, characterized in that, The process of determining whether to perform protection processing on the Media Access Control (MAC) unit CE includes: The MAC CE will not be protected if it meets one or more of the following conditions: Included in message Msg3; Included in the two-step random access message MsgA; To fill the buffer status report (BSR), and the MAC protocol data unit (PDU) containing the MAC CE contains only this padding BSR; It is included in message Msg4.
3. The method as described in claim 1, characterized in that, The process of determining whether to perform protection processing on the Media Access Control (MAC) unit CE includes: The MAC CE is a first MAC CE, and protection processing is performed on the first MAC CE. The first MAC CE is one or more of the following: Mobility LTM cell handover command MAC CE triggered by Layer 1 and / or Layer 2; Discontinuous reception of DRX command MAC CE; Long DRX command MAC CE; Beam failure recovery BFR MAC CE; MAC CE used to activate or deactivate the data retransmission function; MAC CE used to control the activation or deactivation of the semi-persistent SP channel state information reference signal CSI-RS and / or CSI interference measurement resource set; MAC CE used to control the activation or deactivation of the SP probe reference signal SRS; MAC CE used to control the activation or deactivation of the physical uplink control channel (PUCCH) spatial relationships; MAC CE used to control the activation or deactivation of the SP zero-power CSI-RS resource set; MAC CE including time increment; The MAC CE used to control the terminal-specific Physical Downlink Shared Channel (PDSCH) transmission configuration indication TCI status activation or deactivation; MAC CE used to indicate the TCI state of a specific physical downlink control channel (PDCCH) of a terminal; MAC CE used to activate or deactivate secondary cell SCell; MAC CE is used to indicate that the Listen Before You Speak (LBT) has failed.
4. The method as described in claim 3, characterized in that, The protection process for the first MAC CE includes: Perform one or more of the following on the MAC PDU containing the first MAC CE: The first MAC CE is protected, while other MAC CEs in the MAC PDU besides the first MAC CE are not protected. All MAC CEs in the MAC PDU are protected; The MAC CEs other than the second MAC CE in the MAC PDU are protected, wherein the second MAC CE is not exactly the same as the first MAC CE, or is completely different.
5. The method as described in claim 3 or 4, characterized in that, The method further includes: The first MAC CE is not included in the following messages: Msg3, MsgA, Msg4.
6. The method according to any one of claims 1-5, characterized in that, The process of determining whether to perform protection processing on the Media Access Control (MAC) unit CE includes: The MAC protocol data unit (PDU) contains a second MAC CE. The second MAC CE is not protected. The second MAC CE is one or more of the following: regular buffer status report (BSR), filling BSR, periodic BSR, power remaining report (PHR), cell radio network temporary identifier (C-RNTI), terminal contention resolution identifier, MAC CE for confirming configuration authorization, and MAC CE for recommended bit rate.
7. The method as described in claim 6, characterized in that, The statement that the second MAC CE is not protected includes any of the following: The MAC PDU contains only one or more of the second MAC CEs, and no protection processing is applied to the second MAC CEs; The MAC PDU also includes a first MAC CE. The first MAC CE is protected, while all other MAC CEs in the MAC PDU except the first MAC CE are not protected. The MAC PDU also includes a first MAC CE, which protects all other MAC CEs in the MAC PDU except for the second MAC CE.
8. The method according to any one of claims 1-6, characterized in that, The process of determining whether to perform protection processing on the Media Access Control (MAC) unit CE includes: The MAC PDU contains a second MAC CE and a first MAC CE, and all MAC CEs in the MAC PDU are protected.
9. The method as described in claim 1, characterized in that, The process of determining whether to perform protection processing on the Media Access Control (MAC) unit CE includes: For one or more of the following, determine whether to perform integrity protection on the MAC CE without encryption protection: The terminal is in a connected state or an inactive state, and the MAC CE is included in the message MsgA of the two-step competitive random access CBRA. MAC CE in the four-step random access message Msg4.
10. The method as described in claim 1, characterized in that, The determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes one or more of the following: When performing CG small data transfer SDT with configuration authorization, MAC CE is protected. The MAC CE is protected by performing random access RA SDT.
11. The method as described in claim 10, characterized in that, The method further includes: Send or receive indication information, wherein the indication information is used to indicate whether the function of protecting MAC CE is enabled during SDT.
12. The method as described in claim 10 or 11, characterized in that, The determination of whether to perform protection processing on the Media Access Control (MAC) control unit CE includes one or more of the following: For RA SDT with 4-step contention random access to CBRA, MAC CE in Msg3 is not protected. For the RA SDT and MsgA in the 2-step contention random access CBRA, integrity protection is performed, but no encryption protection is performed.
13. A communication device, characterized in that, The communication device includes: The processing module is used to determine whether to perform protection processing on the Media Access Control (MAC) CE unit, wherein the MAC CE protection function is in an active state.
14. A communication device, characterized in that, include: One or more processors; The processor is used to execute the information processing method according to any one of claims 1-12.
15. A communication system, characterized in that, It includes a terminal and a network device, wherein the terminal and the network device are respectively used to perform the transmission as described in any one of claims 1-12.
16. A storage medium storing instructions, characterized in that, When the instruction is executed on the communication device, the communication device performs the information processing method as described in any one of claims 1-12.
17. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the information processing method according to any one of claims 1-12.