Communication method and apparatus

By shortening and encrypting terminal identifiers during random access, the method mitigates covert communication risks while adhering to existing communication standards.

JP2025528753APending Publication Date: 2025-09-02HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025504722
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-07-29
Filing Date
2023-06-30
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

Unauthorized attackers can perform covert communication during the random access process by exploiting the transmission of terminal identifiers in plaintext, which compromises security.

Method used

Reduce the length of terminal identifiers transmitted during the random access process and implement encryption or data truncation to minimize the information available to unauthorized attackers, ensuring compatibility with existing protocols.

Benefits of technology

Reduces the amount of information available to unauthorized attackers, minimizing the impact of covert communication and maintaining protocol compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025528753000001_ABST
    Figure 2025528753000001_ABST
Patent Text Reader

Abstract

A communication method and apparatus are provided. The method includes: a first terminal determines an identifier of the first terminal, the length of the identifier of the first terminal being less than or equal to a first length, the first length being configured in the first terminal before the first terminal performs random access to the network; the first terminal sends a message 3 to a network device in the random access process, the message 3 including the identifier of the first terminal; the first terminal receives a message 4 from the network device in the random access process, the message 4 including information identifying a second terminal, the length of the information identifying the second terminal being less than the first length. In the solution, information that can be obtained by the first terminal by using the message 4 in the random access process is information identifying the second terminal, and the length of the information identifying the second terminal is less than the first length. Compared to a solution in which the first terminal can obtain information corresponding to the first length by using the message 4, this solution reduces the amount of information in the covert communication caused by the Sparrow vulnerability.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] TECHNICAL FIELD Embodiments of the present application relate to the field of communication technologies, and in particular to communication methods and devices. [Background technology]

[0002] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims priority to Chinese Patent Application No. 202210908597.4, entitled "COMMUNICATION METHOD AND APPARATUS," filed with the State Intellectual Property Office of China on July 29, 2022, the entire contents of which are incorporated herein by reference.

[0003] Random access is a process required to establish a wireless link between a terminal and a network. Data transmission can be performed successfully between a base station and a terminal only after random access is completed. In the random access process, a terminal may send Message 3 to a base station, where Message 3 carries an identifier of the terminal. Upon receiving Message 3, the base station broadcasts Message 4 in plaintext to the terminal, where Message 4 carries information, i.e., the identifier of the terminal carried in Message 3. In this process, an unauthorized attacker may perform covert communication by using Message 3 and Message 4 in the random access process. This application focuses on how to reduce the impact caused by covert communication. Summary of the Invention

[0004] The present application provides a communication method and apparatus for reducing the impact caused by covert communication in random access processing.

[0005] According to a first aspect, a communication method is provided. The method may be executed by a first terminal or a component (such as a processor or chip) located within the first terminal. For example, the method is executed by the first terminal. The method includes: the first terminal determines an identifier of the first terminal, the length of the identifier of the first terminal being equal to or less than a first length, the first length being configured in the first terminal before the first terminal performs random access to the network, or optionally, the first length being the length of the identifier of the terminal specified in a Long Term Evolution (LTE) system, the length of the identifier of the terminal specified in a New Radio (NR) system, or the length of the identifier of the terminal specified in a protocol. Optionally, the first length may be 40 bits. The first terminal sends a message 3 to a network device in the random access procedure, the message 3 including the identifier of the first terminal. The first terminal receives a message 4 from the network device in a random access process, the message 4 including information identifying the second terminal, and the length of the information identifying the second terminal is less than the first length.

[0006] According to the above design, the length of the information for identifying the second terminal obtained by the first terminal using message 4 in the random access process is less than the first length configured before the first terminal performs random access to the network. Even if the first terminal is an unauthorized attacker, the first terminal can only obtain an amount of information whose length is less than the first length. Compared with the current solution in which an unauthorized attacker can obtain an amount of information of the first length by using message 4 in the random access process, the present application can reduce the amount of information in the secret communication in the random access process and minimize the impact caused by the secret communication in the random access process.

[0007] In one design, the method further includes: the first terminal receiving a first broadcast message from the network device, the first broadcast message including information indicating a second length, the second length being less than the first length, and optionally, the first broadcast message being a system information block (SIB), e.g., SIB1. This is not limited to: determining an identifier of the first terminal includes: the first terminal determining an identifier of the first terminal based on the second length. Optionally, the length of the identifier of the first terminal may be the second length or less than the second length. For example, the first terminal may adjust the second length indicated by the network device based on a local configuration and a policy. Optionally, in a scenario where the length of the identifier of the first terminal determined by the first terminal is less than the second length, in addition to the identifier of the first terminal, message 3 in the random access procedure sent by the first terminal to the network device may further include indication information such as the length of the identifier of the first terminal or a location of the identifier of the first terminal.

[0008] According to the above design, the network device sends a first broadcast message to the first terminal, where the first broadcast message indicates a second length. The first terminal determines an identifier of the first terminal based on the second length, where the length of the identifier of the first terminal is less than or equal to the second length. Because the second length is less than the first length, the length of the identifier of the first terminal is certainly less than the first length. The first terminal includes the identifier of the first terminal in message 3 in a random access process, and the network device broadcasts information obtained from message 3 in plaintext by using message 4 in the random access process. In the above design, the length of the information obtained from message 3 and broadcast in plaintext by the network device is less than the first length. Compared to a current solution in which the network device broadcasts information of the first length in message 3 in plaintext by using message 4, the present application can reduce the number of bits of covert communication in the random access process and reduce the value of vulnerability used by an unauthorized attacker.

[0009] In one design, message 3 includes a first sequence, the first sequence including an identifier of the first terminal, and a length of the first sequence equal to the first length. Optionally, the first sequence further includes first data, the first data being preset data or the first data being data received from the network device before message 3. Optionally, the first data is data received from the network device before message 3, and the method further includes: the first terminal receives message 2 from the network device in a random access process, message 2 including the first data, the first data being a temporary cell-radio network temporary identity.

[0010] According to the above design, the first terminal reduces the length of its identifier to reduce the number of bits of covert communication in the random access process. However, because the length of the terminal identifier specified in the current protocol is a first length, in the above design, after determining a terminal identifier whose length is less than the first length, data padding is performed on the first terminal identifier by using preset data, previously notified data, etc., to determine a first sequence. The first terminal includes the first sequence in message 3 in the random access process, and the network device may broadcast the first sequence in plaintext by using message 4 in the random access process. This design can meet the specifications for the length of the terminal identifier in the current protocol, assuming that the number of bits of covert communication in the random access process is reduced, and this design is compatible with the current protocol.

[0011] In one design, the method further includes: the first terminal verifying information identifying the second terminal based on an identifier of the first terminal, where the information identifying the second terminal is an identifier of the second terminal; Optionally, if the identifier of the first terminal is the same as the identifier of the second terminal, the random access of the first terminal is deemed successful; and if the identifier of the first terminal is different from the identifier of the second terminal, the random access of the first terminal is deemed unsuccessful.

[0012] In one design, the method further includes: the first terminal receiving a second broadcast message from the network device, where the second broadcast message does not include information indicating a second length, the second length being less than the first length, and optionally, the second broadcast message may be an SIB, e.g., SIB1; and the first terminal determining an identifier of the first terminal includes: the first terminal determining an identifier of the first terminal based on the first length. For example, the length of the identifier of the first terminal is the first length.

[0013] In one design, message 4 includes a second sequence, the second sequence including information identifying the second terminal, and a length of the second sequence equal to the first length. Optionally, the second sequence further includes second data, the second data being preset data or the second data being data received from the network device before message 4. Optionally, the second data is data received from the network device before message 4, and the method further includes: the first terminal receives message 2 from the network device in a random access process, message 2 including the second data, the second data being a temporary cell-radio network temporary identity.

[0014] According to the above design, message 4 includes information identifying the second terminal and may be part of the data in the second terminal identifier. This can reduce the amount of information in the secret communication in the random access process. Furthermore, to satisfy the specification that the length of the terminal identifier is the first length specified in the current protocol, the second data is used to perform data padding on part of the data to obtain a second sequence, and message 4 includes the second sequence. The above design can be used not only to reduce the amount of information in the secret communication in the random access process, but also to satisfy the specification of the length of the terminal identifier in the current protocol and be compatible with the current protocol.

[0015] In one design, the method further includes: the first terminal determining, within the second sequence according to a data truncation rule, information identifying the second terminal, determining a first portion of data within the identifier of the first terminal, the information identifying the second terminal being part of the data within the identifier of the second terminal; and the first terminal verifying the information identifying the second terminal based on the first portion of the data.

[0016] According to the above design, message 4 includes a second sequence, and the second sequence includes a portion of the data in the identifier of the second terminal. The first terminal truncates the second sequence according to a data truncation rule to obtain the portion of the data, and also truncates the identifier of the first terminal to obtain the portion of the data. If the two portions of the data are the same, the random access is deemed successful. If the two portions of the data are different, the random access is deemed unsuccessful. The data truncation rule may be preset or may be notified to the first terminal by the network device in advance. This is not limited. In the above solution, when message 4 carries the second sequence, the first terminal determines whether the random access of the first terminal is successful.

[0017] In one design, the method further includes: the first terminal determining a second portion of the data in the identifier of the first terminal according to a data truncation rule, the first terminal verifying information identifying the second terminal included in message 4 based on the second portion of the data, and the information identifying the second terminal being part of the data in the identifier of the second terminal.

[0018] According to the above design, message 4 directly includes a portion of the data within the identifier of the second terminal. The first terminal may truncate the identifier of the first terminal according to a data truncation rule to obtain the portion of the data, which may be referred to as a second portion of the data. If the second portion of the data is the same as the portion of the data included in message 4, the random access of the first terminal is deemed successful. If the two portions of the data are different, the random access of the first terminal is deemed unsuccessful. In the above design, when message 4 carries the portion of the data within the identifier of the second terminal, the first terminal determines whether the random access of the first terminal was successful.

[0019] According to a second aspect, a communication method is provided. The method is executed by a network device or a component (such as a processor or a chip) disposed within the network device. For example, the method is executed by the network device. The method includes: the network device receives a message 3 from a terminal in a random access process, the message 3 including a terminal identifier, the length of the terminal identifier being equal to or less than a first length, the first length being configured in the terminal before the terminal performs random access to the network, or optionally, the first length being a terminal identifier length specified in a Long Term Evolution (LTE) system, a terminal identifier length specified in a New Radio (NR) system, or a terminal identifier length specified in a protocol. Optionally, the first length is 40 bits. The network device sends a message 4 to the terminal in the random access process, the message 4 including information identifying the terminal, the length of the information identifying the terminal being less than the first length.

[0020] According to the above design, the length of the information included in message 4 in the random access process broadcast in plaintext by the network device is less than a first length. Compared with the solution in which the length of the information included in message 4 in the random access process broadcast in plaintext by the network device is a first length, the present application can reduce the amount of information in the secret communication obtained by an unauthorized attacker by using message 4.

[0021] In one design, the method further includes: the network device sending a first broadcast message to the terminal, the first broadcast message including information indicating a second length, the second length being less than the first length, and a length of the identifier of the terminal being determined based on the second length.

[0022] According to the above design, the network device uses the first broadcast message to notify the terminal in advance that the length of the terminal identifier carried in message 3 is a second length, where the second length is less than the first length, and the length of the information (i.e., the terminal identifier) ​​broadcast in plaintext by the network device in message 4 is also less than the first length. In a scenario of unauthorized communication in random access, an unauthorized receiving end can only obtain an amount of information whose length is less than the first length. This reduces the amount of information in secret communication in the random access process.

[0023] In one design, before sending the first broadcast message to the terminal, the method further includes: the network device determining the second length based on a network load.

[0024] According to the above design, when the load of the network device is high, the value of the second length may be set large, for example, to 39, to prevent multiple terminals from selecting the same random number as the terminal identifier. When the load of the network device is low, the value of the second length may be set small, for example, to 8, so that the network device flexibly adjusts the value of the second length based on the load.

[0025] In one design, Message 3 includes a first sequence, the first sequence including an identifier of the terminal, and a length of the first sequence equal to the first length. Optionally, the first sequence further includes first data, the first data being preset data or the first data being data sent to the terminal before Message 3. Optionally, the first data is data sent to the terminal before Message 3, and the method further includes: the network device sends Message 2 to the terminal in a random access process, Message 2 including the first data, the first data being a temporary cell-radio network temporary identity.

[0026] According to the above design, upon receiving message 3, the network device obtains the first sequence in message 3. The network device generates message 4 based on the first sequence, i.e., message 4 includes the first sequence. The first sequence includes a terminal identifier and first data, and the length of the terminal identifier is less than the first length. The first data is preset data or data previously notified to the terminal by the network device. In the case of an unauthorized attacker, even if the terminal identifier is set to information having a specific meaning, only an amount of information whose length is less than the first length can be transmitted by using message 4 in the random access process. This reduces the amount of information in secret communication in the random access process.

[0027] In one design, the method further includes: the network device sending a second broadcast message to the terminal, where the second broadcast message does not include information indicating a second length, the second length is less than the first length, and a length of the identifier of the terminal is equal to the first length.

[0028] According to the above design, message 3 includes a terminal identifier, and the length of the terminal identifier is equal to the first length. When obtaining the terminal identifier in message 3, the network device truncates the terminal identifier according to a data truncation rule to obtain a portion of the data, and broadcasts the portion of the data in plaintext by using message 4. The portion of the data is used as information identifying the terminal. In this way, an unauthorized receiving end can obtain only a portion of the data sent by another terminal by using message 3. This reduces the amount of information in the secret communication in the random access process.

[0029] In one design, message 4 includes a second sequence, the second sequence including information identifying the terminal, and a length of the second sequence equal to the first length. Optionally, the second sequence further includes second data, the second data being preset data or the second data being data sent to the terminal before message 4. Optionally, the second data is data sent to the terminal before message 4, and the method further includes: the network device sends message 2 to the terminal in a random access process, message 2 including the second data, and the second data being a temporary cell-radio network temporary identity.

[0030] According to the above design, to meet the terminal identifier length specification in the current protocol, a portion of the data is obtained by truncating the terminal identifier in message 3, and then data padding is performed on the portion of the data obtained through the truncation by using predetermined data or data notified to the terminal in advance to obtain a second sequence. The network device broadcasts the second sequence in plaintext by using message 4. The above design meets the terminal identifier length specification in the current protocol.

[0031] In one design, the method further includes: the network device determines a length of the information identifying the terminal based on a network load, the information identifying the terminal being a portion of the data obtained through truncating the identifier of the terminal.

[0032] According to the above design, when the network load is high, the length value of the portion of the data obtained through truncation can be set to be large to avoid collisions caused by the same portion of data in the identifiers of different terminals, or when the network load is low, the length value of the portion of the data obtained through truncation can be set to be small to further reduce the amount of information in secret communication in the random access process.

[0033] According to a third aspect, there is provided a communication method. The method is executed by a terminal or a component (such as a processor or chip) configured in the terminal. The method includes the following steps: the terminal receives a message 2 from a network device in a random access process, where the message 2 includes first data; the terminal sends a message 3 to the network device in the random access process, where the message 3 includes an identifier of the first terminal; the terminal receives a message 4 from the network device in the random access process, where the message 4 includes a first sequence, where the first sequence is determined based on the first data and the identifier of the second terminal; and the terminal verifies the first sequence based on the identifier of the first terminal and the first data.

[0034] According to the above design, upon receiving the terminal identifier sent by the terminal by using message 3, the network device determines a first sequence based on the terminal identifier and the first data. The network device includes the first sequence in message 4 and does not include the data obtained by using message 3 (i.e., the terminal identifier) ​​in plaintext. In this way, in a scenario where an unauthorized receiving end cannot know the first data, it is difficult to decode the first sequence and obtain the data carried in message 3. This solves the problem of unauthorized communication in the random access process to some extent.

[0035] Optionally, the receiving end needs to decode the first sequence carried in message 4 based on the first data to determine whether the random access of the current terminal is successful. In this application, it can be seen that the terminal needs to know the first data for encoding the data carried in message 3. In this design, the random first data originally carried in message 2 is encrypted, and the first data does not need to be additionally notified to the terminal. This reduces air interface overhead.

[0036] In one design, the terminal verifying the first sequence based on the identifier of the first terminal and the first data includes: the terminal performing a hash operation on the identifier of the first terminal and the first data to determine a hash value, the terminal obtaining the hash value through truncation according to a hash value truncation rule, and the terminal verifying the first sequence based on the hash value obtained through the truncation.

[0037] In the above design, if the hash value obtained by the terminal through truncation is the same as the first sequence, the random access of the current terminal is deemed successful, and if the hash value obtained by the terminal through truncation is different from the first sequence, the random access of the current terminal is deemed unsuccessful. The hash value truncation rule may be specified in a protocol or notified by a network device. For example, the terminal receives indication information of the hash value truncation rule from the network device, and the hash value truncation rule includes the following information: the length of the data obtained through truncation or the position of the data obtained through truncation.

[0038] In one design, the first data includes a temporary cell radio network temporary identification.

[0039] In one design, the length of the first sequence is the same as the length of the first terminal identifier and is a first length. The first length is the length of the terminal identifier specified in a Long Term Evolution (LTE) system, the length of the terminal identifier specified in a New Radio (NR) system, or the length of the terminal identifier specified in a protocol. Optionally, the first length is 40 bits.

[0040] According to the above design, the data in message 3, i.e., the terminal identifier, is no longer broadcast in plaintext in message 4, but is instead encoded based on the first data. This can solve the problem of secret communication at an unauthorized receiving end in a specific program during random access processing. Furthermore, since the terminal identifier specified in the current protocol has a first length, i.e., the length at the position corresponding to message 4 in the current protocol is also a first length, this design replaces the terminal identifier with a first sequence of the same first length. This satisfies the requirements of current protocols by implementing encryption protection for the terminal identifier, is easily integrated with current protocols, and has little impact on current networks.

[0041] According to a fourth aspect, there is provided a communication method. The method is executed by a network device or a component (such as a processor or a chip) disposed in the network device. For example, the method is executed by the network device. The method includes: the network device sends a message 2 to a terminal in a random access process, where the message 2 includes first data; the network device receives a message 3 from the terminal in the random access process, where the message 3 includes an identifier of the terminal; the network device determines a first sequence based on the first data and the identifier of the terminal; and the network device sends a message 4 to the terminal in the random access process, where the message 4 includes the first sequence.

[0042] In the above design, the network device no longer broadcasts the data carried in message 3 in plaintext, but determines the first sequence based on the data carried in message 3, i.e., the terminal identifier and the first data. Broadcasting the first sequence in plaintext by using message 4 can provide some protection against the data carried in message 3 being stolen by an unauthorized receiving end. Furthermore, in this design, the data obtained by using message 3 is encrypted by using the random first data in message 2, and the first data does not need to be additionally notified to the terminal. This reduces air interface overhead.

[0043] In one design, the network device determining the first sequence based on the first data and the identifier of the terminal includes: the network device performing a hash operation on the first data and the identifier of the terminal to determine a hash value, and the network device obtaining the hash value through truncation according to a hash value truncation rule to obtain the first sequence.

[0044] According to the above design, the length of the hash value directly determined based on the first data and the terminal identifier is usually long. In this design, to meet the requirement that the terminal identifier carried in message 4 has the first length, the determined hash value is obtained through truncation, the length of the hash value obtained through truncation is the first length, and the hash value obtained through truncation may be referred to as the first sequence. This meets the requirement of the terminal identifier carried in message 4 in the current protocol and satisfies the specifications of the current protocol.

[0045] In one design, the method further includes: the network device sends an indication of a hash value truncation rule to the terminal, the hash value truncation rule including the following information: a length of data obtained through truncation or a position of data obtained through truncation.

[0046] According to the above design, the network device notifies the terminal of a hash value truncation rule. The terminal performs a hash operation based on the first data and the identifier stored locally in the terminal, and obtains a hash value determined through truncation according to the same hash value truncation rule to determine a second sequence. The second sequence may be regarded as a hash value obtained through truncation. When the second sequence is the same as the first sequence received by using message 4, the random access is deemed successful. When the second sequence is different from the first sequence received by using message 4, the random access is deemed unsuccessful. The network device notifies the terminal of the hash value truncation rule, so that the terminal can verify the first sequence received by using message 4.

[0047] In one design, the first data includes a temporary cell radio network temporary identification.

[0048] In one design, the length of the first data is less than the length of the first sequence.

[0049] In one design, the length of the first sequence is the same as the length of the terminal identifier, which is a first length. The first length is the length of the terminal identifier specified in a Long Term Evolution (LTE) system, or the first length is the length of the terminal identifier specified in a New Radio (NR) system, or the first length is the length of the terminal identifier specified in a protocol. Optionally, the first length is 40 bits.

[0050] According to a fifth aspect, there is provided a communication device. The device may be a terminal, or a device (e.g., a chip) configured in a terminal, or a device that can be used in conjunction with a terminal. The device has functionality for implementing the method according to the first or third aspect. This functionality may be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more units corresponding to the above functionality, such as a transceiver unit and a processing unit.

[0051] According to a sixth aspect, there is provided a communication device, comprising units or means configured to perform the steps according to any one of the first or third aspects.

[0052] According to a seventh aspect, there is provided a communications device, comprising a processor and a memory, the memory configured to store computer instructions, and when the device operates, the processor executes the computer instructions stored in the memory, such that the device performs a method according to the first or third aspect.

[0053] According to an eighth aspect, a communications device is provided, including a processor coupled to a memory. The processor is configured to invoke a program stored in the memory to perform a method according to the first or third aspect. The memory may be located within the device or external to the device. Additionally, there may be one or more processors.

[0054] According to a ninth aspect, there is provided a communications device, comprising a processor and an interface circuit. The processor is configured to communicate with another device through the interface circuit and to perform a method according to the first or third aspect. There may be one or more processors.

[0055] According to a tenth aspect, there is provided a communication device. The device may be a network device, or a device (e.g., a chip) configured in a network device, or a device that can be used in conjunction with a network device. The device has functionality implementing the second or fourth aspect. The functionality may be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more units corresponding to the above functionality, such as a transceiver unit and a processing unit.

[0056] According to an eleventh aspect, there is provided a communication device, comprising units or means configured to perform the steps according to any one of the second or fourth aspects.

[0057] According to a twelfth aspect, there is provided a communications device, comprising a processor and a memory, the memory configured to store computer instructions, and when the device operates, the processor executes the computer instructions stored in the memory, such that the device performs a method according to the second or fourth aspect.

[0058] According to a thirteenth aspect, a communications device is provided, including a processor coupled to a memory. The processor is configured to invoke a program stored in the memory to perform a method according to the second or fourth aspect. The memory may be located within the device or external to the device. Additionally, there may be one or more processors.

[0059] According to a fourteenth aspect, there is provided a communications device, comprising a processor and an interface circuit. The processor is configured to communicate with another device through the interface circuit and to perform a method according to the second or fourth aspect. There may be one or more processors.

[0060] According to a fifteenth aspect, a chip system is provided, comprising a processor configured to perform a method according to any one of the first to fourth aspects.

[0061] According to a sixteenth aspect, there is provided a computer-readable storage medium storing instructions that, when executed on a communication device, perform a method according to any one of the first to fourth aspects.

[0062] According to a seventeenth aspect, there is provided a computer program product, the computer program product including computer programs or instructions which, when executed by a communications device, perform a method according to any one of the first to fourth aspects.

[0063] According to an eighteenth aspect, there is provided a communication system, the system including an apparatus according to any one of the fifth to ninth aspects and an apparatus according to any one of the tenth to fourteenth aspects. [Brief explanation of the drawings]

[0064] [Figure 1] 1 is a diagram of the architecture of a communication system according to the present application; [Figure 2] 1 is a flowchart of contention-based random access according to the present application. [Figure 3] 1 is a flowchart of a communication method according to the present application. [Figure 4] 1 is a diagram of a comparison between the identifier of a terminal device in the current protocol and the identifier of a terminal device in the present application. [Figure 5] 1 is a flowchart of a communication method according to the present application. [Figure 6] FIG. 10 is a diagram illustrating a comparison between the data carried in Msg4 in the current protocol and the data carried in Msg4 in the present application. [Figure 7] FIG. 1 is a diagram of a hashing operation according to the present application. [Figure 8] 1 is a flowchart of a communication method according to the present application. [Figure 9] FIG. 1 is a diagram of a hashing operation according to the present application. [Figure 10] 1 is a diagram of an apparatus according to the present application; [Figure 11] 1 is a diagram of an apparatus according to the present application; DETAILED DESCRIPTION OF THE INVENTION

[0065] FIG. 1 is an architecture diagram of a communication system 1000 to which the present application is applied. As shown in FIG. 1, the communication system includes a radio access network 100 and a core network 200. Optionally, the communication system 1000 may further include the Internet 300. The radio access network 100 may include at least one radio access network device (e.g., 110a and 110b in FIG. 1) and may further include at least one terminal (e.g., 120a to 120j in FIG. 1). The terminal is wirelessly connected to the radio access network device, and the radio access network device is connected to the core network in a wireless or wired manner. The core network device and the radio access network device may be separate and distinct physical devices, or the functions of the core network device and the logical functions of the radio access network device may be integrated into the same physical device, or some functions of the core network device and some functions of the radio access network device may be integrated into one physical device. A wired or wireless method may be used for the connection between the terminal and the radio access network device. FIG. 1 is merely a schematic diagram. The communication system may further include other network devices, for example, wireless relay devices and wireless backhaul devices not shown in FIG.

[0066] The radio access network device may also be referred to as a network device. The radio access network device may be a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), a next generation NodeB (gNB) in a fifth generation (5G) mobile communication system, a next generation base station in a sixth generation (6G) mobile communication system, a base station in a future mobile communication system, an access node in a wireless fidelity (Wi-Fi) system, etc. Alternatively, the radio access network device may be a module or unit that completes some functions of a base station, such as a central unit (CU) or a distributed unit (DU). The CU completes the functions of a radio resource control (RRC) protocol and a packet data convergence layer protocol (PDCP) of the base station, and may further complete the functions of a service data adaptation protocol (SDAP). The DU completes the functions of the radio link control (RLC) layer and medium access control (MAC) layer of the base station, and may further complete some or all of the physical (PHY) layer functions. For a detailed description of the above protocol layers, please refer to the relevant technical specifications of the 3rd generation partnership project (3GPP). The radio access network device may be a macro base station (e.g., 110a in FIG. 1), a micro base station or an indoor base station (e.g., 110b in FIG. 1), or a relay node or a donor node.The specific technology and the specific device form used by the radio access network device are not limited in this application. For ease of explanation, the following provides an explanation by using an example in which the radio access network device is a base station.

[0067] A terminal may alternatively be referred to as a terminal device, user equipment (UE), mobile station, mobile terminal, etc. Terminals may be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communications, machine-type communication (MTC), internet of things (IoT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearable, smart transportation, and smart city. A terminal may be a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, a wearable device, a vehicle, an unmanned aerial vehicle, a helicopter, an airplane, a ship, a robot, a mechanical arm, a smart home device, etc. The specific technology used by the terminal and the specific device form are not limited by this application.

[0068] The base station and the terminal may be in a fixed location or may be mobile. The base station and the terminal may be deployed on land, on water, or on an airplane, a balloon, or a satellite in the air, including an indoor device, an outdoor device, a handheld device, or a vehicle-mounted device. The application scenario of the base station and the terminal is not limited in this application.

[0069] The roles of a base station and a terminal may be relative. For example, helicopter or unmanned aerial vehicle 120i in FIG. 1 may be configured as a mobile base station. For terminal 120j accessing wireless access network 100 through 120i, terminal 120i is a base station. However, from base station 110a's perspective, 120i is a terminal. In other words, communication between 110a and 120i is performed based on a wireless air interface protocol. Indeed, communication between 110a and 120i may alternatively be performed based on an interface protocol between base stations. In this case, from base station 110a's perspective, 120i is also a base station. Therefore, both the base station and the terminal may be collectively referred to as a communication device. 110a and 110b in FIG. 1 may each be referred to as a communication device having the functionality of a base station, and 120a to 120j in FIG. 1 may each be referred to as a communication device having the functionality of a terminal.

[0070] Communications between base stations and terminals, between base stations, or between terminals may be performed on licensed spectrum, or on unlicensed spectrum, or on both licensed and unlicensed spectrum. Communications may be performed on spectrum below 6 gigahertz (GHz), or above 6 GHz, or on spectrum below and above 6 GHz. Spectral resources for wireless communications are not limited in this application.

[0071] In the present application, the functions of a base station may be performed by a module (e.g., a chip) within the base station, or may be performed by a control subsystem including the functions of the base station. The control subsystem including the functions of the base station in this specification may be a control center in the above application scenarios such as smart grid, industrial control, smart transportation, and smart city. The functions of a terminal may alternatively be performed by a module (e.g., a chip or modem) within the terminal, or may be performed by a device including the functions of the terminal.

[0072] In this application, a base station sends downlink signals or downlink information to a terminal, where the downlink information is carried on a downlink channel, and a terminal sends uplink signals or uplink information to the base station, where the uplink information is carried on an uplink channel. To communicate with a base station, a terminal needs to establish a wireless connection to a cell controlled by the base station. The cell to which the terminal establishes a wireless connection is called the terminal's serving cell. When communicating with the serving cell, the terminal is further interfered with by signals from neighboring cells.

[0073] Generally, random access is classified into contention-based random access and non-contention-based random access. In this application, contention-based random access is used as an example to describe the solution of this application. As shown in Figure 2, the contention-based random access process may include the following steps:

[0074] Step 201: A terminal sends a message 1 (Msg1) on a physical random access channel (PRACH), where Msg1 includes a random access preamble.

[0075] For example, the terminal selects one preamble from 64 preset preambles, determines a random access resource for sending the preamble, and sends Msg1 including the preamble to the base station on the determined random access resource.

[0076] Optionally, the preamble is a sequence. The base station may perform signal processing on the received preamble sequence to determine a start position at which the base station receives the preamble, thereby obtaining a transmission delay between the terminal and the base station through estimation, and further determining a timing advance (TA) based on the transmission delay between the terminal and the base station. The base station may notify the terminal of the TA by using Msg2, and the terminal may adjust uplink timing based on the TA.

[0077] Optionally, the base station may further determine a time unit at which the base station receives the preamble by detecting the preamble, further infer a time unit at which the terminal sends the preamble, and determine a downlink transmission beam for sending Msg2 based on the correspondence between the time unit at which the terminal sends the preamble and the downlink transmission beam for Msg2. In addition, on the terminal side, the terminal may infer a downlink beam for receiving Msg2 based on the time unit at which the terminal sends the preamble. Thus, the base station may notify the terminal in advance of the correspondence between the time unit at which the terminal sends the preamble and the downlink transmission beam for Msg2. For example, the terminal may broadcast a message to notify the terminal. This is not limited.

[0078] Optionally, the base station may determine a random access radio network temporary identity (RA-RNTI) based on the detected preamble identity (ID), a random access resource for transmitting the preamble, etc. The base station allocates a temporary cell radio network temporary identity (TC-RNTI) to the terminal performing random access, and determines an uplink grant (UL Grant) for scheduling message 3 (Msg3), etc. The base station may include the determined RA-RNTI, TC-RNTI, UL Grant, etc. in Msg2. This is not limited thereto.

[0079] Step 202: The base station sends a message 2 (Msg2) on a physical downlink shared channel (PDSCH), where Msg2 may be referred to as a random access response (RAP).

[0080] Optionally, Msg2 carries a timing advance (TA) corresponding to the transmission delay determined in step 201, an RA-RNTI, a TC-RNTI, an UL grant for scheduling Msg3, etc. In one design, the base station broadcasts Msg2 in the downlink, and terminals within the coverage area of ​​the base station may receive Msg2 and verify the RA-RNTI included in Msg2. If the verification is successful, the terminal sends Msg3 to the base station based on the UL grant scheduling in Msg2, or if the verification fails, the terminal does not perform any processing on Msg2. For example, the base station may determine the RA-RNTI based on the preamble sequence sent in Msg1 and the random access resource for sending the preamble. The terminal compares the RA-RNTI determined by the terminal with the RA-RNTI obtained in Msg2. If the two are the same, the RA-RNTI is considered to be successfully verified and the following step 203 of sending Msg3 to the base station is performed based on the UL grant scheduling in Msg2; if the two are different, the terminal does not perform any processing on Msg2 and the terminal may initiate random access again.

[0081] Step 203: The terminal sends a message 3 (message3, Msg3) to the base station, where Msg3 includes the identifier of the terminal.

[0082] Step 204: The base station sends a message 4 (message 4, Msg4) to the terminal, where Msg4 may be referred to as a contention resolution message, and Msg4 includes a contention resolution identity, which includes the identifier of the terminal received in Msg3. Msg4 can be used to resolve issues such as contention and conflict caused when multiple terminals attempt to use the same random access resource and the same preamble for access.

[0083] In the random access process shown in FIG. 2, a scenario may occur in which multiple terminals simultaneously select the same random access resource and send the same preamble. In this scenario, the base station can only receive or detect the preamble with the strongest energy, and the base station cannot determine the number of terminals simultaneously requesting uplink resources. This is a scenario in which collisions occur during random access performed by multiple terminals. After receiving Msg1, the base station broadcasts Msg2 in the downlink on the PDSCH, and Msg2 carries the RA-RNTI. Upon receiving Msg2, the terminal calculates the RA-RNTI based on the preamble sent in Msg1, the random access resource for sending the preamble, etc. If the RA-RNTI calculated locally by the terminal is the same as the RA-RNTI received from the base station, the terminal considers that Msg2 has been sent to the terminal and continues to send Msg3 to the base station based on the UL grant scheduling in Msg2. When multiple terminals send Msg1 by using the same preamble and the same random access resource, the RA-RNTI determined by the multiple terminals based on the preamble and the random access resource is the same. If the RA-RNTI determined by the multiple terminals is the same as the RA-RNTI notified by the base station in Msg2, the multiple terminals send Msg3 to the base station based on the UL grant scheduling in Msg2. Because the multiple terminals send Msg3 on the same time-frequency resource based on the UL grant scheduling, the Msg3s from the multiple terminals collide with each other over the air interface, and the base station can correctly decode only one Msg3. To solve the contention access problem, the terminal sends a 40-bit random number to the base station in Msg3 to identify the terminal's identity, which may be referred to as a terminal identifier. Optionally, the 40-bit random number may include a 39-bit random number and one reserved bit. Therefore, the 40-bit random number may also be referred to as a 39-bit random number and one reserved bit.In the following description, an example in which the identifier of a terminal device is a random number is used for explanation. Upon receiving and successfully decoding Msg3, the base station broadcasts the 40-bit random number received in Msg3 in a terminal contention resolution identification in Msg4 in the downlink. That is, the base station broadcasts Msg4 in the downlink. Msg4 includes a contention resolution identification, which may include 48 bits. Of the 48 bits, 40 bits may be the terminal identifier carried in Msg3, and the remaining 8 bits may be a service type identifier. This application focuses on the transmission of the 40-bit identifier of the terminal. Therefore, the following description mainly describes the process in which Msg4 includes the terminal identifier. Upon receiving Msg4, each of the multiple terminals may compare the 40-bit identifier carried in Msg4 with the terminal identifier sent in Msg3. If the two identifiers are the same, the terminal considers the random access to be successful, or if the two identifiers are different, the terminal considers the random access to be unsuccessful. Optionally, Msg4 may carry scheduling information, etc. After successful random access, the terminal may perform uplink communication, downlink communication, etc. with the base station based on the scheduling information carried in Msg4.

[0084] A vulnerability exists in the contention-based random access process. This vulnerability exploits the characteristics of the air interface downlink broadcast in the random access process to secretly transmit confidential information by overwriting valid information (Sparrow stealth pirate attack by RACH rebroadcast overwrite, or simply referred to as a covert communication attack in the random access process). A malicious terminal may exploit the Sparrow vulnerability in the random access mechanism to perform unauthorized covert communication. For example, attacker terminal A and attacker terminal B may pre-negotiate information with a specific meaning. When terminal A's geographic location is far from terminal B's geographic location, terminal A may send information with a specific meaning to the base station in Msg3, replacing the random number indicating terminal A's identifier. After receiving and correctly decoding Msg3 from terminal A, the base station broadcasts information having a specific meaning contained in Msg3 by terminal A in plaintext in Msg4, and terminal B may acquire Msg4 through blind detection over the air interface at a remote geographical location to obtain the information having a specific meaning sent by terminal A and carried in Msg4. The communication between terminal A and terminal B is performed covertly, and the base station cannot detect the communication. How to avoid or reduce covert communication caused by the Sparrow vulnerability is a technical problem to be solved in this application.

[0085] The present application provides a solution to the Sparrow attack, including the following: A terminal determines a terminal identifier, the length of the terminal identifier being less than or equal to a first length, the first length being configured in the terminal before the terminal performs random access to the network. For example, the first length may be 40 bits. The terminal sends Msg3 to a base station in the random access process, where Msg3 includes the terminal identifier. Upon receiving Msg3 in the random access process, the base station sends Msg4 to the terminal in the random access process, where Msg4 in the random access process includes information identifying the terminal, the length of the information identifying the terminal being less than the first length. For example, the first length is 40 bits. In a current solution, the length of the terminal identifier included in Msg4 by the base station is 40 bits. For an unauthorized attacker, the amount of meaningful information obtained by using Msg4 in the random access process is 40 bits. However, in this solution, the length of the terminal identifier included in Msg4 by the base station is less than 40 bits. The amount of meaningful information that can be obtained by an unauthorized attacker using Msg4 in random access processing is less than 40 bits, which reduces the amount of information in covert communication caused by the Sparrow vulnerability.

[0086] Embodiment 1 In embodiment 1, the length of the terminal identifier included in Msg3 sent by the terminal to the base station is less than a first length. Upon receiving Msg3, the base station may obtain the terminal identifier from Msg3 and use the terminal identifier as information identifying the terminal. The base station sends Msg4 to the terminal, where Msg4 includes information identifying the terminal, where the information identifying the terminal is the terminal identifier, and the length of the information identifying the terminal is less than the first length. Alternatively, upon obtaining the terminal identifier from Msg3, the base station truncates the terminal identifier to obtain a portion of the data and uses the portion of the data obtained through the truncation as information identifying the terminal. The base station sends Msg4 to the terminal, where Msg4 includes information identifying the terminal. In this case, the information identifying the terminal is a portion of the data obtained by truncating the terminal identifier, and the length of the information identifying the terminal is less than the first length.

[0087] For example, the information identifying the terminal included in Msg4 is a terminal identifier. In one design, the base station may send a broadcast message to the terminal, where the broadcast message may be referred to as a first broadcast message, and the first broadcast message may indicate information of a second length, where the second length is less than the first length. The terminal may determine the terminal identifier based on the second length. For example, the length of the terminal identifier may be equal to the second length, or the length of the terminal identifier may be less than the second length. This is not limited.

[0088] For example, in one implementation, the base station may notify the second length by using a first broadcast message, and the terminal may adjust the second length notified by the base station based on a local configuration, a local policy, etc. Indeed, the adjustment is typically a length adjustment toward a reduction in the size of the second length. For example, the length of the terminal identifier determined by the terminal is a third length, and the third length is less than the second length, etc. Optionally, since the length of the terminal identifier is the third length and is different from the second length notified by the base station, in addition to the terminal carrying the terminal identifier in Msg3, Msg3 further carries at least one of indication information of the third length, the position of the terminal identifier in Msg3, etc., so that the base station can extract the terminal identifier from Msg3.

[0089] In one implementation, the terminal may directly include the terminal identifier in Msg3 (i.e., it can be understood that the terminal identifier does not need to be padded), or the terminal may determine a first sequence based on the determined terminal identifier. The length of the first sequence is equal to the first length, and the terminal includes the first sequence in Msg3. Optionally, in addition to the terminal identifier, the first sequence may further include first data, the length of the terminal identifier, and the length of the first data. The sum of the length of the terminal identifier and the length of the first data is equal to the first length. Alternatively, it can be described as follows: After determining the terminal identifier, the terminal may perform data padding on the terminal identifier based on the first data to determine the first sequence, the length of the first sequence is the first length, and the terminal includes the first sequence in Msg3. According to the specifications in the current protocol, the length of the terminal identifier carried in Msg3 is the first length. However, in this design, in consideration of reducing the amount of fraudulent information in communication caused by the Sparrow vulnerability, the length of the terminal identifier is set to be less than the first length. In addition, to satisfy the specifications in the current protocol, the terminal identifier is padded by using first data to obtain a first sequence having a first length, and the terminal includes the first sequence having a first length in Msg3.

[0090] The above design, premised on reducing the amount of information in secret communication caused by the Sparrow vulnerability, can further satisfy the terminal identifier length specification in the current protocol and is compatible with the current protocol. Optionally, the first data may be preset data or data received from the base station before Msg3. For example, before Msg3, the terminal may receive Msg2 from the base station, where Msg2 includes TC-RNTI. TC-RNTI may be used as the first data, and TC-RNTI may be used to pad the terminal identifier, determine the first sequence, etc. For details, please refer to the following description for rules, padding schemes, etc. for padding the terminal identifier by the terminal.

[0091] As shown in Figure 3, the present application provides a procedure for a communication method, which includes at least the following steps:

[0092] Step 301: The base station sends a first broadcast message to the terminal.

[0093] The first broadcast message indicates a second length, and the second length is less than the first length. The first length is a length of a terminal identifier configured in the terminal before the terminal performs random access to the network. For example, when the terminal is powered on, the base station may notify the terminal of the first length by using a broadcast message, or the base station may periodically send a broadcast message to notify the terminal of the first length. Alternatively, the first length is a length of a terminal identifier specified in a protocol, or the first length is a length of a terminal identifier specified in a fourth-generation mobile communication system (long term evolution (LTE)) system, or the first length is a length of a terminal identifier specified in a fifth-generation mobile communication system (new radio (NR)) system. Optionally, the first length is 40 bits. The first broadcast message may be a system information block (SIB), for example, SIB1. Optionally, the identifier of the terminal may be represented by using a random number, and the first broadcast message may be in a random access Msg3 and may be used to inform the terminal of a quantity N of bits of the random number representing the identifier of the terminal, where the quantity N of bits corresponds to the second length.

[0094] Optionally, before step 301, the method may further include: the base station determines the second length based on a network load. For example, in a scenario with a low network load, the base station may consider that the probability of Msg1 collision in the current network is low, and the terminal may identify the terminal's identity by using a small number of bits. The value of the second length may be small. For example, the value of the second length may be 8 bits. Alternatively, in a scenario with a high network load, the base station may consider that the probability of Msg1 collision in the current network is high, and the terminal needs to use a large number of bits to identify the terminal's identity. The value of the second length may be large to prevent terminals from selecting the same random number to represent the terminal. For example, the value of the second length may be 39 bits.

[0095] Step 302: The terminal sends Msg1 to the base station on a random access resource, where Msg1 includes a preamble.

[0096] Step 303: The base station sends Msg2 to the terminal, where Msg2 includes at least one of a TA, an RA-RNTI, a TC-RNTI, and an UL grant for scheduling Msg3.

[0097] Steps 301 to 303 are optional.

[0098] Step 304: The terminal sends Msg3 to the base station, where Msg3 includes an identifier of the terminal.

[0099] In one design, the terminal may determine the terminal identifier based on the second length signaled by the first broadcast message. The determined length of the terminal identifier may be equal to the second length, less than the second length, etc. For details, see the description above. Optionally, the terminal identifier may be a random number.

[0100] In a possible implementation, Msg3 directly includes the terminal's identifier. The terminal may determine an N-bit random number based on the second length notified by the first broadcast message, where the N-bit random number indicates the terminal's identifier and the length corresponding to the N bits is less than or equal to the second length. In this implementation, Msg3 sent by the terminal to the base station includes the N-bit random number.

[0101] In another possible implementation, Msg3 includes a first sequence. In addition to determining the terminal identifier in the above method, the terminal may further determine first data and perform data padding on the terminal identifier based on the first data to determine the first sequence. In addition to the terminal identifier, the first sequence further includes the first data. Optionally, the first data is preset data. For example, the preset data may be preset data for padding, which may also be referred to as fixed data, or may be data received by the terminal from the base station before Msg3. This is not limited. In this implementation, Msg3 sent by the terminal to the base station includes the first sequence, and the first sequence includes an N-bit random number (i.e., the terminal identifier) ​​and the first data.

[0102] In particular, the terminal may perform data padding on the terminal identifier based on the first data according to a data padding rule, and the padded data is referred to as a first sequence. The data padding rule is not limited. For example, the first data may be padded at a front position of the terminal identifier, or at a rear position of the terminal identifier, or at a middle position of the terminal identifier, or the first data may be padded at equal intervals according to the rule. This is not limited. The data padding rule may be set in advance or may be notified to the terminal by the network device in advance. For example, in addition to the second length, the first broadcast message may further notify the data padding rule, etc. For example, the first length is 40 bits, and the second length is a length corresponding to N bits.

[0103] As shown in FIG. 4, in the current protocol, a 40-bit random number represents a terminal identifier. In this implementation, an N-bit random number represents the terminal identifier, where N is a positive integer between 8 and 39. The terminal performs data padding on the N-bit random number based on preset data or the TC-RNTI, and the length of the padded data is 40 bits. FIG. 4 provides an explanation using an example in which first data is padded to the rear position of the N-bit random number. According to the specifications of the current protocol, the length of the terminal identifier in Msg3 is a first length. In this solution, the length of the terminal identifier is reduced to reduce the amount of information in secret communication caused by the Sparrow vulnerability. However, the length of the terminal identifier is padded to the first length based on the preset data in Msg3 or data previously obtained from the base station. As a result, this solution is applicable to and compatible with the specifications of the current protocol.

[0104] Step 305: The base station sends Msg4 to the terminal, where Msg4 includes information identifying the terminal, and the length of the information identifying the terminal is less than the first length. As described above, the information identifying the terminal may be the identifier of the terminal, or may be part of the data obtained by truncating the identifier of the terminal.

[0105] Optionally, in the procedure of Figure 3, the length of the terminal identifier is a second length, and the information identifying the terminal is the terminal identifier or a portion of the data obtained through truncating the terminal identifier. Thus, in the procedure of Figure 3, the length of the information identifying the terminal is equal to or less than the second length.

[0106] When the information identifying the terminal is a terminal identifier, the above Msg3 may directly include the terminal identifier or may include the first sequence. In the present application, when receiving Msg3, the base station may directly acquire the information included in Msg3, and the acquired information may be the terminal identifier or the first sequence. The base station broadcasts Msg4 in plain text, and Msg4 includes information acquired from Msg3. For example, Msg4 includes a contention resolution identification, which includes information acquired from Msg3, i.e., the contention resolution identification includes the terminal identifier. Since Msg4 is a broadcast message, a terminal within the service range of Msg4 may receive Msg4 and acquire the information carried in Msg4. The terminal compares the information acquired from Msg4 with the information included in Msg3 by the terminal. If the information is the same, the terminal's random access may be deemed successful. If the information is different, the terminal's random access may be deemed unsuccessful. Optionally, if a terminal fails random access, the terminal may restart the random access process. For example, the first length is 40 bits, and the second length is N bits. In this design, after receiving Msg4, the Sparrow attack receiving end may reduce the transmitted bits from 40 bits to N bits by using stealth information. This reduces the information bits that can be used by an attacker for stealth transmission and reduces the value of the attacker exploiting the vulnerability.

[0107] Similarly, when the information identifying the terminal is part of the data in the terminal identifier, the above Msg3 may directly include the terminal identifier or may include a first sequence, where the first sequence includes the terminal identifier and the first data. Upon receiving Msg3, the base station may obtain the terminal identifier from Msg3. Part of the data is obtained by truncating the terminal identifier. For a description of the part of the data obtained by truncating, see the description below in FIG. 5. For example, Msg4 includes a contention resolution identification, which includes the Mth to (M+K)th bits of the data obtained by truncating the terminal identifier in Msg3.

[0108] The base station broadcasts Msg4 in plaintext, where Msg4 carries a portion of the data obtained through truncation. Optionally, Msg4 may carry a portion of the data directly. Alternatively, the base station may pad a portion of the data obtained through truncation to determine a second sequence, where the length of the second sequence is equal to the first length. Msg4 carries the second sequence. In this design, a portion of the data is carried in Msg4, where the length of the portion of the data is less than the second length. This further reduces the information bits used by a Sparrow attacker to transmit information covertly.

[0109] Note that the above focuses on the process in which Msg3 or Msg4 carries terminal identifier-related data. In one design, Msg3 or Msg4 carries two parts of data. One part of the data is terminal identifier-related data, and the other part of the data is a service type identifier. The size of the service type identifier may be 8 bits. Optionally, in the present application, in addition to the terminal identifier-related data, Msg3 or Msg4 may further include a service type identifier.

[0110] In the present application, in the random access process, a terminal sends Msg3 to a base station, and the base station broadcasts the received data in Msg3 in plaintext using Msg4. As a result, the random access process is vulnerable to covert communication attacks. For example, when attacker terminal A is far away from attacker terminal B, terminal A may send information with a predetermined meaning to the base station in Msg3. After receiving and correctly decrypting Msg3 from terminal A, the base station broadcasts the information with the predetermined meaning included in Msg3 by terminal A in plaintext using Msg4. After receiving Msg4 broadcast in plaintext, terminal B may obtain the information with the predetermined meaning sent by terminal A to communicate between terminals A and B. However, in the above process, the communication between terminals A and B is performed covertly, and the base station cannot detect the communication. As a result, the communication between terminals A and B is fraudulent. In one design, the length of the data (i.e., the terminal identifier) ​​included by the terminal in Msg3 is a first length. In the above fraudulent communication scenario, a fraudulent attacking receiver can obtain a data amount corresponding to the first length by using Msg4. However, in this design, the base station uses a first broadcast message to notify the terminal that the length of the terminal identifier, i.e., the length of the data included by the terminal in Msg3, is a second length, and the second length is less than the first length. The base station may broadcast data of the second length in plaintext by using Msg4, or may further perform data truncation on the second data to obtain a portion of the data and broadcast the portion of the data in plaintext by using Msg4. According to the solution of the present application, in the above fraudulent communication scenario, the data that can be obtained by a fraudulent attacking receiver by using Msg4 is less than the data corresponding to the first length. This reduces the information bits in secret communication in the random access process and reduces the value for an attacker to exploit vulnerabilities.

[0111] The present application further provides another solution to the Sparrow attack, including: a terminal determines a terminal identifier, where the length of the terminal identifier is equal to a first length; the terminal sends Msg3 to a base station in a random access process, where Msg3 includes the terminal identifier; the base station obtains the terminal identifier of the first length from Msg3 and truncates the terminal identifier to obtain part of the data, where the part of the data can be used as information identifying the terminal.

[0112] The base station sends Msg4 to the terminal, where Msg4 carries a portion of data, and the length of the portion of data is less than a first length. For example, the first length is 40 bits. In this solution, the amount of meaningful information that an unauthorized attacker can obtain by using Msg4 in a random access process is less than 40 bits. This reduces the amount of information in secret communication caused by the Sparrow vulnerability.

[0113] Embodiment 2 In embodiment 2, the terminal may determine a terminal identifier based on the first length, and the length of the terminal identifier may be the first length. The terminal sends Msg3 to the base station in the random access process, where Msg3 includes a terminal identifier having a length of the first length. When obtaining the terminal identifier from Msg3, the base station truncates the terminal identifier to obtain a portion of the data. The base station sends Msg4 to the terminal, where Msg4 directly includes the portion of the data obtained through the truncation (i.e., it can be understood that the terminal identifier does not need to be padded), or Msg4 includes a second sequence, where the second sequence includes the portion of the data obtained through the truncation, and the length of the second sequence is equal to the first length. Optionally, the second sequence may further include second data. The second data may be preset data or may be sent to the terminal before message 4. For example, the second data is the TC-RNTI carried in Msg2 in the random access process.

[0114] As shown in Figure 5, the present application provides a procedure for a communication method, which includes at least the following steps:

[0115] Step 500: The base station sends a second broadcast message to the terminal.

[0116] The second broadcast message may not include information indicating the second length, and the second length is less than the first length. For the first length, see the description of FIG. 3.

[0117] Optionally, the second broadcast message may be a SIB, for example, SIB1.

[0118] Step 501: The terminal sends Msg1 to the base station, where Msg1 includes a preamble.

[0119] Step 502: The base station sends Msg2 to the terminal, where Msg2 includes at least one of a TA, an RA-RNTI, a TC-RNTI, and an UL grant for scheduling Msg3.

[0120] Steps 500 to 502 are optional.

[0121] Step 503: The terminal sends Msg3 to the base station, where Msg3 includes an identifier of the terminal.

[0122] For example, the terminal determines a terminal identifier based on the first length, the length of the terminal identifier may be the first length, and the terminal identifier may be a random number.

[0123] Step 504: The base station sends Msg4 to the terminal, where Msg4 includes information identifying the terminal, and the length of the information identifying the terminal is less than the first length.

[0124] In one design, after obtaining the terminal identifier from Msg3, the base station may obtain a portion of the data in the terminal identifier through truncation according to a data truncation rule. The data truncation rule includes the position of the data obtained through truncation, the length of the data obtained through truncation, etc. The data truncation rule may be preset or determined by the base station based on a current network load status. For example, the base station may determine the length of the data obtained through truncation based on the network load, and the length of the data obtained through truncation is the length of the portion of the data obtained through truncation. For example, the data truncation rule may truncate the terminal identifier to obtain the Mth to (M+K)th bits of data, where M and K are positive integers greater than 0, M represents the starting bit of the data obtained through truncating the terminal identifier, and K represents the length of the data obtained through truncating the terminal identifier, i.e., the length of the portion of the data obtained through truncation. For example, in a scenario with low network load, the base station may consider that the probability of Msg1 collision in the current network is low and that the probability of multiple terminals selecting the same random number in Msg3 is extremely low. Therefore, K may be set to a small value. In a scenario with high network load, the base station considers that the probability of Msg1 collision in the current network is high. The terminal needs to use a large amount of random numbers in Msg3 to identify the terminal's identity, and the amount of bits of the message in Msg3 returned by the base station in Msg4 needs to be increased. Therefore, K may be set to a large value. Optionally, Msg4 may include a contention resolution identification, which includes the Mth to (M+K)th bits of data obtained through truncating the terminal's identifier in Msg3.

[0125] Optionally, the base station may send indication information of the data truncation rule to the terminal, and the data truncation rule may indicate at least one of a location of data obtained through truncation, a length of data obtained through truncation, etc. The data truncation rule may explicitly or implicitly indicate at least one of a location of data obtained through truncation, a length of data obtained through truncation, etc. In a possible implementation, the data truncation rule may explicitly indicate at least one of a location of data obtained through truncation, a length of data obtained through truncation, etc. In this case, the data truncation rule may be described as including at least one of a location of data obtained through truncation, a length of data obtained through truncation, etc. For example, the base station may notify the terminal of the data truncation rule by using a second broadcast message in step 500. For example, the second broadcast message may include indication information of the data truncation rule.

[0126] In a possible implementation, Msg4 directly includes a portion of the data obtained through truncation. Upon receiving and correctly decoding Msg4, the terminal may obtain a portion of the data in Msg4. The terminal determines a second portion of the data in the terminal's locally generated identifier according to a data truncation rule, and the terminal identifier locally generated by the terminal is the terminal identifier sent by the terminal to the base station in Msg3. The terminal verifies the portion of the data included in Msg4 based on the second portion of the data. For example, if the second portion of the data is the same as the portion of the data received in Msg4, the terminal's random access is deemed successful. If the second portion of the data is different from the portion of the data received in Msg4, the terminal's random access is deemed unsuccessful. The data truncation rule may be preset or received by the terminal from the base station. For the process by which the base station sends the data truncation rule to the terminal, see the description above. The above example still applies. The data truncation rule may truncate the terminal identifier to obtain the Mth to (M+K)th bits of data. The terminal may truncate the terminal's locally generated identifier to obtain Mth through (M+K)th bits of the data as the second portion of the data according to a data truncation rule.

[0127] In another possible implementation, after acquiring a portion of the data acquired through truncation, the base station may perform data padding on the portion of the data acquired through truncation based on the second data to determine a second sequence. In addition to the portion of the data acquired through truncation, the second sequence further includes the second data, and the length of the second sequence is the first length. The rule for performing data padding on the portion of the data acquired through truncation based on the second data is not limited. For example, the second data may be padded at a front position of the portion of the data acquired through truncation, or the second data may be padded at a rear position of the portion of the data acquired through truncation, or the second data may be padded at an intermediate position of the portion of the data acquired through truncation, or the second data may be padded at equal intervals to the portion of the data acquired through truncation. This is not limited. The rule for performing data padding on the portion of the data acquired through truncation may be predetermined or may be notified to the terminal by the base station. This is not limited. For example, the base station may inform the terminal of a rule for performing data padding on a portion of the data obtained through truncation by using the second broadcast message in step 500. Msg4 sent by the base station to the terminal includes the second sequence. In the above design in which the second sequence is carried in Msg4 and the length of the second sequence is the first length, to reduce the amount of information in the covert communication caused by a Sparrow attack, a portion of the data carried in Msg3 is broadcast in plaintext in Msg4. In addition, to meet the requirements of Msg4 in the current protocol, the length of the portion of the data is padded with the first length specified in the protocol. This is compatible with the current protocol.

[0128] The manner in which the terminal verifies the second sequence when it receives Msg4 includes:

[0129] The terminal determines a portion of the data obtained by truncating the second sequence according to a data truncation rule, and the terminal determines a first portion of the data in the terminal's local identifier according to the data truncation rule. Optionally, the data truncation rule may be preset or may be notified to the terminal in advance by the base station. This is not limited to this. The terminal verifies the portion of the data obtained by truncating the second sequence based on the first portion of the data. For example, if the two portions of the data are the same, the terminal's random access is deemed successful, or if the two portions of the data are different, the terminal's random access is deemed unsuccessful. For example, the data truncation rule is to obtain the Mth to (M+K)th bits of the data in the terminal's identifier through truncation. When obtaining the terminal's identifier from Msg3, the base station truncates the terminal's identifier to obtain the Mth to (M+K)th bits of the data, and the Mth to (M+K)th bits of the data obtained through truncation are referred to as a portion of the data. The 1st to (M-1)th bits and the (M+K+1)th to (first length)th bits of a portion of the data are padded with preset data or TC-RNTI, and the padded data is called a second sequence.

[0130] For example, as shown in FIG. 6, the first sequence has a length of 40 bits. In the current solution, Msg4 includes a 40-bit random number, which represents the terminal's identifier. However, in the present application, Msg4 includes a second sequence, which also has a length of 40 bits. Of the 40 bits, the 1st to (M-1st) bits are padded data, the Mth to (M+Kth) bits are a random number obtained by truncating Msg3, and the (M+K+1st) to 40th bits are padded data. The padded data may be fixed data, TC-RNTI, etc. Upon receiving the second sequence in Msg4, the terminal truncates the second sequence to obtain a portion of the data within the Mth to (M+Kth)th bits. In the terminal's local identifier, the data within the Mth to (M+Kth)th bits is obtained by truncating, and the data obtained by truncating is referred to as the first portion of data. The portion of the data obtained by truncating the second sequence is verified based on the first portion of the data, and if the first portion of the data is the same as the portion of the data obtained by truncating the second sequence, the random access of the terminal is deemed successful, and if the first portion of the data is different from the portion of the data obtained by truncating the second sequence, the random access of the terminal is deemed unsuccessful.

[0131] Alternatively, the terminal may perform data truncation on the terminal's local identifier according to a data truncation rule, and the portion of the data obtained through the truncation may be referred to as the third portion of data. The terminal then performs data padding on the third portion of data according to a data padding rule to determine a third sequence. The data truncation rule and the data padding rule may be preset or may be notified to the terminal by the base station in advance. This is not limited. The terminal verifies the second sequence in Msg4 based on the third sequence. If the third sequence is the same as the second sequence, the terminal's random access is deemed successful. If the third sequence and the second sequence are different, the terminal's random access is deemed unsuccessful. The above example is still used, and the first length is 40 bits. The terminal may first obtain a portion of the data for the local identifier through truncation in the manner shown in FIG. 6, and then pad the portion of the data obtained through the truncation based on the preset data or the TC-RNTI to obtain the third sequence. The third sequence is used to verify the second sequence obtained in Msg4.

[0132] According to the above design, after receiving Msg4, the malicious receiver of the Sparrow attack can reduce the bits that can be used to transmit stealth information from the bits corresponding to the terminal identifier to bits that correspond to part of the data in the terminal identifier, thereby reducing the information bits that can be used by the attacker for stealth transmission and reducing the amount of secret communication information that can be obtained by the attacker.

[0133] In one design, in a scenario where a collision occurs during random access of multiple terminals, the multiple terminals each send Msg3 to the base station based on the UL grant scheduling in Msg2, where each Msg3 includes a corresponding terminal identifier. The Msg3s sent by the multiple terminals collide with each other over the air interface, and the base station can correctly decode only one Msg3. The terminal identifier is obtained from the correctly decoded Msg3, and information identifying the terminal is broadcast in plaintext by using Msg4. Terminals within the base station's coverage area may receive Msg4, and each terminal verifies the terminal identifier obtained in Msg4 based on the terminal identifier sent by the terminal in Msg3. If the verification is successful, the terminal's random access is considered successful. If the verification is unsuccessful, the terminal's random access is considered unsuccessful. From each terminal's perspective, the terminal sends its terminal identifier in Msg3. The terminal identifier received in Msg4 may be information identifying the terminal or information identifying another terminal. For ease of distinction, the solution in the above embodiment may be described as follows: A first terminal determines an identifier of the first terminal, and the first terminal sends Msg3 to the base station in the random access process, where Msg3 includes the identifier of the first terminal, and the length of the identifier of the first terminal is less than or equal to the first length; and the first terminal receives Msg4 from the base station in the random access process, where Msg4 includes information identifying a second terminal, and the length of the information identifying the second terminal is less than the first length. Optionally, the second terminal is the same as or different from the first terminal. For example, in a contention-based random access process, if terminal A and terminal B select the same random access resource and send the same preamble, it is considered that a collision occurs between terminal A and terminal B in the random access process. Terminal A and terminal B may each send Msg3 to the base station based on the UL grant scheduling in Msg2.If the base station correctly decodes Msg3 sent by terminal A, Msg4 carries information identifying terminal A, or if the base station correctly decodes Msg3 sent by terminal B, Msg4 carries information identifying terminal B. From the perspective of terminal A, the terminal identifying information obtained by terminal A by using Msg4 may be information identifying terminal A, i.e., information identifying terminal A, or may be information identifying another terminal, for example, information identifying terminal B.

[0134] This application also provides another solution to the Sparrow attack. In this solution, after the base station obtains the terminal identifier carried in Msg3, the base station selects a random number Nounce as a salt value based on the terminal identifier, where the salt value is a random value added in the hash operation. The base station performs a hash operation based on the terminal identifier and Nounce, and truncates the hash operation result to obtain a portion of the hash value. The hash value and the salt value Nounce obtained through truncation are broadcast in plaintext in Msg4, i.e., Msg4 includes the hash value and Nounce obtained through truncation. For example, in one implementation, as shown in FIG. 7, both Nounce and the terminal identifier are 40 bits long. The base station performs a hash operation on the 40-bit Nounce and the 40-bit terminal identifier, and truncates the hash operation result h(x) to obtain 40 bits of data. The base station broadcasts, in plaintext, Nounce and 40-bit data obtained by truncating the hash calculation result using Msg4. Upon receiving Msg4, the terminal performs a hash operation on the Nounce included in Msg4 and the terminal's locally generated identifier and truncates the hash calculation result to obtain a portion of the hash value. The terminal compares the portion of the hash value obtained locally through truncation with the portion of the hash value received using Msg4. If the two portions are the same, the terminal's random access is deemed successful. If the two portions are different, the terminal's random access is deemed unsuccessful. In this design, the base station no longer broadcasts the information received in Msg3 in plaintext, but instead broadcasts the hash calculation result and Nounce determined based on the information received from Msg3 and Nounce in plaintext. In theory, it is difficult for a malicious receiver of a Sparrow attack to infer the information carried in Msg3 based on the hash calculation result and Nounce carried in Msg4. This solves the covert communication problem caused by the Sparrow vulnerability.

[0135] However, in this solution, the base station needs to further notify the terminal of the Nounce by using Msg4, which increases the air interface overhead of Msg4. For example, the terminal contention resolution identification in Msg4 has only 48 bits in the current protocol definition. Of the 48 bits, 40 bits are used to transmit the information received in Msg3, and the remaining 8 bits are used for the service type identifier. However, in the hash solution shown in FIG. 7, the length of the hash value obtained through truncation and the length of the Nounce value are both 40 bits. The hash value obtained through truncation can be set in the information bits corresponding to the 40 bits of the terminal contention resolution identification in Msg4. To transmit the Nounce, 40 information bits need to be added to Msg4, which increases the air interface overhead of Msg4.

[0136] In this application, the solution is improved as follows: Before Msg4, the base station notifies the terminal of first data used as Nounce. The base station performs a hash operation based on the first data received in Msg3 and the terminal identifier, and truncates the hash operation result to obtain a portion of the hash value. In Msg4, the base station notifies the terminal of the portion of the hash value obtained through the truncation, and does not notify Nounce in Msg4. This reduces the air interface overhead of Msg4.

[0137] As shown in Figure 8, the present application provides a procedure for a communication method, which includes at least the following steps:

[0138] Step 801: The terminal sends Msg1 to the base station to start a random access process. Step 801 is optional.

[0139] Step 802: The base station sends Msg2 to the terminal, where Msg2 includes first data. Optionally, the first data may be TC-RNTI, where TC-RNTI is generated by the base station and the length of TC-RNTI is 16 bits. Alternatively, the first data may be random data excluding TC-RNTI. This is not limited.

[0140] Step 803: The terminal sends Msg3 to the base station, where Msg3 includes the terminal identifier, and the length of the terminal identifier is a first length. For the first length, please refer to the procedure description shown in FIG. 3.

[0141] Step 804: The base station determines a first sequence based on the first data and the identifier of the terminal.

[0142] For example, the base station may perform a hash operation on the terminal identifier and the first data to determine a hash value, where the hash value is the hash operation result, and obtain the hash value through truncation according to a hash value truncation rule to obtain a first sequence. Optionally, the length of the first sequence may be the same as the length of the terminal identifier and is a first length. For example, the first length is 40 bits. The hash value truncation rule may include at least one of the length of the data obtained through truncation, the position of the data obtained through truncation, etc. The length of the data obtained through truncation may be the first length. The position of the data obtained through truncation may be data obtained through truncation of the first length at a front position of the hash operation result, data obtained through truncation of the first length at a rear position of the hash operation result, data obtained through truncation of the first length at an intermediate position of the hash operation result, etc. This is not limited.

[0143] For example, upon receiving Msg3, the base station obtains the terminal identifier from Msg3, where the length of the terminal identifier is 40 bits. As shown in FIG. 9, X may represent the terminal identifier, and the TC-RNTI received in Msg2 is used as a hash Nounce salt value. The base station performs a hash operation on the terminal identifier and TC-RNTI to obtain a hash value h(x). Because the length of the obtained hash value h(x) is usually long, the hash value h(x) generally needs to be obtained through truncation. For example, 40-bit data may be obtained by truncating h(x), and the data obtained through truncation may be referred to as a first sequence.

[0144] Step 805: The base station sends Msg4 to the terminal, where Msg4 includes the first sequence.

[0145] In the solution, the contention resolution identification in Msg4 may include a first sequence, and the length of the first sequence may be 40 bits. In addition to the first sequence, the contention resolution identification may further include an 8-bit service type identifier.

[0146] Upon receiving Msg4, the terminal may perform a hash operation on the terminal's locally generated identifier and the received first data to determine a hash value, and obtain the hash value through truncation according to a hash value truncation rule. The hash value truncation rule may be predefined or notified to the terminal by the base station. For example, the base station may send indication information of the hash value truncation rule to the terminal, where the indication information of the hash value truncation rule indicates at least one of the length of the data obtained through truncation, the position of the data obtained through truncation, etc. The terminal may verify the first sequence based on the hash value obtained locally through truncation. For example, if the hash value obtained locally by the terminal through truncation is the same as the first sequence, the terminal's random access is successful, or if the hash value obtained locally by the terminal through truncation is different from the first sequence, the terminal's random access is unsuccessful.

[0147] According to the above solution, the information received from Msg3 is not broadcast in plaintext in Msg4, but the first sequence determined based on the information received from Msg3 is broadcast in plaintext. This makes it difficult for the receiving end of a Sparrow attack to infer the information carried in Msg3 based on the first sequence carried in Msg4. This solves the problem of covert communication caused by the Sparrow vulnerability. Furthermore, this is because Msg4 carries only the 40-bit first sequence. This reduces air interface overhead, minimizes the impact on current networks, and is more compatible with current networks.

[0148] In the procedure shown in FIG. 8, from the terminal's perspective, it should be noted that Msg3 sent by the terminal to the base station carries the terminal's identifier. Msg3 successfully decoded by the base station may be sent by the terminal or another terminal. For ease of explanation, the above process may be described as follows: A first terminal sends Msg3 to the base station, and Msg3 carries the first terminal's identifier. Msg3 successfully decoded by the base station carries the second terminal's identifier, which may be the same as or different from the first terminal's identifier. The base station performs a hash operation on the second terminal's identifier and the first data to obtain a hash value, and truncates the hash value according to a hash value truncation rule to obtain a first sequence. The base station sends Msg4 to the first terminal, and Msg4 carries the first sequence. The first sequence carried in Msg4 received by the first terminal is determined based on the second terminal's identifier and the first data. The first terminal performs a hash operation on the identifier of the first terminal and the first data to determine a hash value, truncates the determined hash value according to a hash value truncation rule, and verifies the first sequence based on the hash value obtained through the truncation. For example, if the hash value obtained by the first terminal through the truncation is the same as the first sequence, the random access of the first terminal is deemed successful, and if the hash value obtained by the first terminal through the truncation is different from the first sequence, the random access of the first terminal is deemed unsuccessful.

[0149] It can be understood that to implement the functions in the above embodiments, the base station and the terminal include corresponding hardware structures and / or software modules for performing various functions. Those skilled in the art should easily recognize that the units and method steps in the examples described with reference to the embodiments disclosed in this application can be implemented by hardware or a combination of hardware and computer software. Whether the functions are performed by hardware or by hardware driven by computer software depends on the specific application scenario and design constraints of the technical solution.

[0150] 10 and 11 are diagrams of possible structures of communication devices according to an embodiment of the present application. These communication devices may be configured to implement the functions of the terminal or base station in the above method embodiments, and thus may also achieve the beneficial effects of the above method embodiments. In this embodiment of the present application, the communication device may be one of the terminals 120a to 120j shown in FIG. 1, or may be the base station 110a or 110b shown in FIG. 1, or may be a unit (e.g., a chip) used in the terminal or base station.

[0151] 10, the communication device 10000 includes a processing unit 1010 and a transceiver unit 1020. The communication device 10000 is configured to perform the functions of a terminal or a base station in the embodiments of the method shown in FIG.

[0152] When the communication device 10000 is configured to perform the functions of the terminal in the embodiment of the method shown in FIG. 3 or FIG. 5, the processing unit 1010 is configured to determine an identifier of a first terminal, the length of the identifier of the first terminal being less than or equal to a first length, the first length being configured in the first terminal before the first terminal performs random access to the network, the transceiver unit 1020 is configured to send a message 3 to the network device in the random access process, the message 3 including the identifier of the first terminal, and to receive a message 4 from the network device in the random access process, the message 4 including information identifying a second terminal, the length of the information identifying the second terminal being less than the first length.

[0153] 3 or 5, the transceiver unit 1020 is configured to: receive a message 3 from a terminal in a random access process, the message 3 including an identifier of the terminal, the length of the identifier of the terminal being less than or equal to a first length, the first length being configured in the terminal before the terminal performs random access to the network; and send a message 4 to the terminal in the random access process, the message 4 including information identifying the terminal, the length of the information identifying the terminal being less than the first length. Optionally, the processing unit 1010 is configured to process the message 3, generate the message 4, etc.

[0154] When the communication device 10000 is configured to perform the functions of a terminal in the embodiment of the method shown in FIG. 8, the transceiver unit 1020 is configured to receive message 2 from the network device in a random access process, message 2 including first data, send message 3 to the network device in the random access process, message 3 including an identifier of the first terminal, receive message 4 from the network device in the random access process, message 4 including a first sequence, the first sequence being determined based on the first data and the identifier of the second terminal, and the processing unit 1010 is configured to verify the first sequence based on the identifier of the first terminal and the first data.

[0155] 8, the transceiver unit 1020 is configured to send a message 2 including first data to the terminal in the random access process and to receive a message 3 including an identifier of the terminal from the terminal in the random access process, and the processing unit 1010 is configured to determine a first sequence based on the first data and the identifier of the terminal. The transceiver unit 1020 is further configured to send a message 4 to the terminal in the random access process, the message 4 including the first sequence.

[0156] For a more detailed description of the processing unit 1010 and the transceiver unit 1020, please directly refer to the relevant descriptions in the method embodiments shown in Figures 3, 5 and 8, and the details will not be described again here.

[0157] 11 , the communication device 1100 includes a processor 1110 and an interface circuit 1120. The processor 1110 and the interface circuit 1120 are coupled to each other. It may be understood that the interface circuit 1120 may be a transceiver or an input / output interface. Optionally, the communication device 1100 may further include a memory 1130 configured to store instructions to be executed by the processor 1110, or to store input data required by the processor 1110 to execute the instructions, or to store data generated after the processor 1110 executes the instructions.

[0158] When the communication device 1100 is configured to implement the method shown in FIG. 3, FIG. 5, or FIG. 8, the processor 1110 is configured to perform the functions of the processing unit 1010 described above, and the interface circuit 1120 is configured to perform the functions of the transceiver unit 1020 described above.

[0159] When the communication device is a chip used in a terminal, the chip in the terminal implements the functions of the terminal in the above method embodiments. The chip in the terminal receives information from another unit (e.g., a radio frequency unit or an antenna) in the terminal, and the information is sent to the terminal by the base station, or the chip in the terminal sends information to another unit (e.g., a radio frequency unit or an antenna) in the terminal, and the information is sent to the base station by the terminal.

[0160] When the communication device is a unit used in a base station, the unit in the base station performs the functions of the base station in the above method embodiments. The unit in the base station receives information from another unit (e.g., a radio frequency unit or an antenna) in the base station, and the information is sent to the base station by a terminal, or the unit in the base station sends information to another unit (e.g., a radio frequency unit or an antenna) in the base station, and the information is sent to the terminal by the base station. The unit in the base station in this specification may be a baseband chip in the base station, or may be a DU or another unit. The DU in this specification may be a DU in an open radio access network (O-RAN) architecture.

[0161] It may be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be another general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a transistor logic device, a hardware component, or any combination thereof. A general-purpose processor may be a microprocessor or any conventional processor, etc.

[0162] The method steps in the embodiments of the present application may be implemented in a hardware manner or in a manner in which a processor executes software instructions. The software instructions may include corresponding software modules. The software modules may be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disk, removable hard disk, CD-ROM, or any other form of storage medium well known in the art. For example, the storage medium is coupled to the processor, so that the processor can read information from and write information to the storage medium. Indeed, the storage medium may be components of the processor. The processor and the storage medium may be located in an ASIC. In addition, the ASIC may be located in a base station or a terminal. Indeed, the processor and the storage medium may reside as separate components in the base station or the terminal.

[0163] All or part of the above embodiments may be implemented using software, hardware, firmware, or any combination thereof. When software is used to implement the embodiments, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded into a computer and executed, all or part of the procedures or functions in the embodiments of the present application are performed. The computer may be a general-purpose computer, an individual computer, a computer network, a network device, user equipment, or another programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transmitted from a computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions may be sent from a website, computer, server, or data center to another website, computer, server, or data center via wired or wireless communication. The computer-readable storage medium may be any available medium that can be accessed by a computer, or a data storage device, such as a server or data center that integrates one or more available media. The available media may be magnetic media such as floppy disks, hard disks, or magnetic tape, or optical media such as digital video disks, or semiconductor media such as solid-state drives. The computer-readable storage media may be volatile or non-volatile storage media, or may include both types of storage media: volatile and non-volatile storage media.

[0164] In the embodiments of the present application, unless otherwise specified or there is no logical contradiction, the terms and / or descriptions between different embodiments are consistent and may refer to each other, and the technical features of different embodiments may be combined into a new embodiment based on their internal logical relationships.

[0165] In this application, "at least one" means one or more, and "multiple" means two or more. The term "and / or" describes an association relationship between related objects and indicates that three relationships may exist. For example, A and / or B may represent the following cases: only A is present, both A and B are present, and only B is present. A and B may be singular or plural. In text descriptions in this application, the character " / " indicates an "or" relationship between related objects. In formulas in this application, the character " / " indicates a "split" relationship between related objects. "Comprising at least one of A, B, and C" may represent including A, including B, including C, including A and B, including A and C, including B and C, and including A, B, and C.

[0166] It can be understood that various numbers in the embodiments of the present application are only used for distinction to facilitate description, and are not used to limit the scope of the embodiments of the present application. The sequence numbers of the above processes do not mean the execution order, and the execution order of the processes should be determined based on the functions and internal logic of the processes.

Claims

1. determining an identifier of a first terminal, the length of the identifier of the first terminal being less than or equal to a first length, the first length being configured in the first terminal before the first terminal performs random access to a network; sending a message 3 to a network device in a random access procedure, the message 3 including the identifier of the first terminal; receiving a message 4 from the network device in the random access process, the message 4 including information identifying a second terminal, the length of the information identifying the second terminal being less than the first length; A communication method comprising:

2. The method further comprises receiving a first broadcast message from the network device, the first broadcast message including information indicating a second length, the second length being less than the first length; The method of claim 1 , wherein determining an identifier of a first terminal comprises determining the identifier of the first terminal based on the second length.

3. 3. The method of claim 2, wherein the message 3 includes a first sequence, the first sequence including the identifier of the first terminal, and the length of the first sequence equals the first length.

4. 4. The method of claim 3, wherein the first sequence further includes first data, and the first data is preset data or data received from the network device before the message 3.

5. the first data being the data received from the network device prior to the message 3, and the method comprising:

5. The method of claim 4, further comprising the step of receiving a message 2 from the network device in the random access process, the message 2 including the first data, the first data being a temporary cell radio network temporary identity.

6. The method comprises:

6. The method of claim 2, further comprising the step of verifying the information identifying the second terminal based on the identifier of the first terminal, wherein the information identifying the second terminal is an identifier of the second terminal.

7. The method comprises: receiving a second broadcast message from the network device, wherein the second broadcast message does not include information indicating a second length, and the second length is less than the first length; The method of claim 1 , wherein determining an identifier of a first terminal comprises determining the identifier of the first terminal based on the first length.

8. 8. The method of claim 1, wherein the message 4 comprises a second sequence, the second sequence comprising the information identifying the second terminal, the length of the second sequence being equal to the first length.

9. 9. The method of claim 8, wherein the second sequence further includes second data, and the second data is preset data or the second data is data received from the network device before the message 4.

10. the second data being the data received from the network device prior to the message 4, and the method further comprising:

10. The method of claim 9, further comprising the step of receiving the message 2 from the network device in the random access process, the message 2 including the second data, the second data being a temporary cell radio network temporary identity.

11. The method comprises: determining the information identifying the second terminal in the second sequence according to a data truncation rule and determining a first portion of data in the identifier of the first terminal, wherein the information identifying the second terminal is part of data in the identifier of the second terminal; verifying the information identifying the second terminal based on a first portion of the data; The method of claim 1 , further comprising:

12. The method comprises: determining a second portion of data in the identifier of the first terminal according to a data truncation rule; verifying the information identifying the second terminal contained in the message 4 based on the second portion of data, the information identifying the second terminal being part of data within the identifier of the second terminal; The method of claim 1 , further comprising:

13. 13. The method of claim 1, wherein the first length is 40 bits.

14. receiving a message 3 from a terminal in a random access process, the message 3 including an identifier of the terminal, the length of the identifier of the terminal being less than or equal to a first length, the first length being configured in the terminal before the terminal performs random access to a network; sending a message 4 in the random access process to the terminal, the message 4 including information identifying the terminal, and the length of the information identifying the terminal being less than the first length; A communication method comprising:

15. The method comprises:

15. The method of claim 14, further comprising: sending a first broadcast message to the terminal, the first broadcast message including information indicating a second length, the second length being less than the first length, and the length of the identifier of the terminal being determined based on the second length.

16. Before the step of sending a first broadcast message to the terminal, the method further comprises: The method of claim 15 further comprising determining the second length based on a network load.

17. 17. The method of claim 15 or 16, wherein the message 3 comprises a first sequence, the first sequence comprising the identifier of the terminal, the length of the first sequence being equal to the first length.

18. 18. The method of claim 17, wherein the first sequence further includes first data, and the first data is preset data or data sent to the terminal before the message 3.

19. the first data being the data sent to the terminal before the message 3, and the method comprising:

20. The method of claim 18, further comprising the step of sending a message 2 to the terminal in the random access procedure, the message 2 including the first data, the first data being a temporary cell radio network temporary identity.

20. The method comprises:

15. The method of claim 14, further comprising: sending a second broadcast message to the terminal, wherein the second broadcast message does not include information indicating a second length, the second length is less than the first length, and the length of the identifier of the terminal is equal to the first length.

21. 21. The method of claim 14, wherein the message 4 comprises a second sequence, the second sequence comprising the information identifying the terminal, the length of the second sequence being equal to the first length.

22. 22. The method of claim 21, wherein the second sequence further includes second data, and the second data is preset data or data sent to the terminal before the message 4.

23. the second data being the data sent to the terminal before the message 4, and the method comprising:

23. The method of claim 22, further comprising the step of sending a message 2 to the terminal in the random access procedure, the message 2 including the second data, the second data being a temporary cell radio network temporary identity.

24. The method comprises:

24. The method of any one of claims 14 to 23, further comprising determining the length of the information identifying the terminal based on the network load.

25. 25. The method of any one of claims 14 to 24, wherein the first length is 40 bits.

26. A communication device comprising a unit adapted to perform the method according to any one of claims 1 to 13.

27. 14. A communication device comprising a processor and an interface circuit, the interface circuit being configured to receive signals from a communication device other than the communication device and to pass the signals to the processor or pass signals from the processor to a communication device other than the communication device, the processor being configured to perform the method of any one of claims 1 to 13 via logic circuits or by executing code instructions.

28. A communication device comprising a processor and a memory, A communications device, wherein the processor is configured to execute computer programs or instructions stored in the memory such that the communications device implements a method according to any one of claims 1 to 13.

29. A communication device comprising a unit configured to perform the method of any one of claims 14 to 25.

30. 26. A communication device comprising a processor and an interface circuit, the interface circuit configured to receive signals from a communication device other than the communication device and to pass the signals to the processor or pass signals from the processor to a communication device other than the communication device, the processor configured to perform the method of any one of claims 14 to 25 via logic circuits or by executing code instructions.

31. A communication device comprising a processor and a memory, A communications device, wherein the processor is configured to execute computer programs or instructions stored in the memory such that the communications device implements a method according to any one of claims 14 to 25.

32. 26. A computer-readable storage medium, the storage medium storing a computer program or instructions which, when executed by a communication device, causes the method of any one of claims 1 to 13 or any one of claims 14 to 25 to be performed.

33. A chip comprising a processor, the processor coupled to a memory and configured to execute computer programs or instructions stored in the memory, such that the chip performs the method of any one of claims 1 to 13 or any one of claims 14 to 25.

34. A computer program product comprising a computer program or instructions, which when executed by an apparatus performs the method of any one of claims 1 to 13 or the method of any one of claims 14 to 25.

35. a first terminal device configured to perform the method according to any one of claims 1 to 13; a second terminal device configured to perform the method of any one of claims 14 to 25; A communication system comprising:

Citation Information

Patent Citations

  • Method and apparatus for transferring messages on a common control channel for random access in a wireless communication network

    JP2011508538A

  • Communication method and communication device

    JP2023513261A

  • Method and apparatus for management of extended mobile device identity information

    US20210160726A1

  • User equipment and base station device

    WO2020157993A1

  • Communication method and communication apparatus

    WO2021159986A1