Communication method and apparatus
By encrypting clock synchronization messages and timestamping only specific types of messages, the method enhances security and maintains accuracy in clock synchronization, addressing vulnerabilities in existing fronthaul networking protocols.
Patent Information
- Application Number
- JP2025533291
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-12-09
- Publication Date
- 2025-12-11
- Estimated Expiration
- 2042-12-09
AI Technical Summary
Existing clock synchronization methods in fronthaul networking, such as those using Precision Time Protocol (PTP) and synchronization Ethernet (syncE), face challenges in ensuring the security and accuracy of message transmissions, particularly for clock synchronization messages that are transmitted in plaintext, making them vulnerable to tampering.
A communication method that encrypts specific types of messages, such as clock synchronization messages, before transmission and includes timestamping, ensuring that only encrypted messages marked for timestamping are processed, thereby enhancing security and maintaining synchronization accuracy.
The proposed method improves the security of message transmission by preventing tampering while maintaining the accuracy of clock synchronization between communication devices, ensuring reliable time synchronization.
Smart Images

Figure 2025540291000001_ABST
Abstract
Description
[Technical Field]
[0001] The present application relates to the field of communication technologies, and more particularly to communication methods and devices. [Background technology]
[0002] In fronthaul networking, clock synchronization may be performed between radio equipment control (REC) and radio equipment (RE) according to a clock synchronization protocol. For example, clock synchronization is performed according to the precision time protocol (PTP) and synchronization ethernet (syncE) protocols, where PTP is sometimes referred to as the IEEE 1588 protocol. How to effectively perform clock synchronization is a technical challenge worth considering. Summary of the Invention
[0003] The present application provides a communication method for encrypting / decrypting messages, thereby increasing the security of message transmissions. [Means for solving the problem]
[0004] According to a first aspect, an embodiment of the present application provides a communication method, which may be applied to a first communication device. For example, the method may be executed by the first communication device or by a module that may be used in the first communication device. The module may be a software module, a hardware circuit, a chip, or a combination of a software module and a hardware circuit or chip. In the method, a first message is encrypted to obtain a second message, and the second message and a first timestamp are transmitted, the first timestamp indicating a transmission time of the second message.
[0005] According to the above method, the first communication device sends the second message and the first timestamp to the second communication device, so that encrypted transmission can be performed for the message that needs to be stamped (e.g., a clock synchronization message), thereby improving the security of the message transmission.
[0006] In a possible design, the type of the first message is of the first type (ie, the first message is a message of the first type).
[0007] In a possible design, the method further includes obtaining a type of the first message; and, after determining that the type of the first message is a first type, stamping the first message to obtain a first timestamp.
[0008] In a possible design, the method further includes a step of encrypting the third message to obtain a fourth message and a step of sending the fourth message, wherein the type of the third message is the second type (i.e., the third message is a message of the second type).
[0009] In a possible design, the first type of message is a message that needs to be stamped, and the second type of message is a message that does not need to be stamped. A message that needs to be stamped may mean that when a message is sent, the message needs to be stamped to obtain a sending timestamp for the message, and / or when a message is received, the message needs to be stamped to obtain a receiving timestamp for the message. Optionally, the first type of message includes, but is not limited to, at least one of the following: a synchronization message or a delay request message. The second type of message includes, but is not limited to, at least one of the following: a follow-up message or a delay response message.
[0010] In a possible design, the method further includes sending notification information, the notification information notifying the second communication device of the start of encryption / decryption of the message.
[0011] In a possible design, the method further includes receiving capability information of the second communication device, the capability information indicating that the second communication device supports encryption of the message.
[0012] In a possible design, the method further includes transmitting request information, wherein the request information is used to request capability information of the second communication device.
[0013] In a possible design, the method further includes determining that the first communication device supports encryption / decryption of the message.
[0014] According to the above method, the first communication device and the second communication device may negotiate whether message encryption / decryption is supported. When the first communication device determines that message encryption / decryption is supported and the second communication device also determines that message encryption / decryption is supported, the first communication device may notify the second communication device to start message encryption / decryption.
[0015] According to a second aspect, an embodiment of the present application provides a communication method, which may be applied to a second communication device, in which the second communication device receives a second message and a first timestamp, where the first timestamp indicates a transmission time of the second message, and decodes the second message to obtain the first message.
[0016] In a possible design, the type of the first message is of the first type.
[0017] In a possible design, the method further includes stamping the second message to obtain a second timestamp, the second timestamp indicating a time of receipt of the second message.
[0018] In a possible design, the method further includes receiving a fourth message and decoding the fourth message to obtain a third message, wherein the type of the third message is the second type.
[0019] In a possible design, the method further includes stamping the fourth message to obtain a third timestamp, the third timestamp indicating a time of receipt of the fourth message, and discarding the third timestamp after determining that the type of the third message is the second type.
[0020] In a possible design, the method further includes receiving notification information, the notification information notifying the second communication device of the start of encryption / decryption of the message.
[0021] In a possible design, the method further includes transmitting capability information, where the capability information indicates that the second communication device supports encryption / decryption of the message.
[0022] In a possible design, the method further includes receiving request information, wherein the request information is used to request capability information of the second communication device.
[0023] It should be understood that the method according to the second aspect corresponds to the method according to the first aspect. For the beneficial effects of the related technical features in the second aspect, please refer to the description of the first aspect. The details will not be described again.
[0024] According to a third aspect, an embodiment of the present application provides a communication method, which may be applied to a first functional module in a first communication device, in which the first functional module in the first communication device transmits a first message and indication information for the first message, the indication information indicating that the first message needs to be stamped, and receives a first timestamp, the first timestamp indicating a transmission time of the first message.
[0025] In a possible design, the type of the first message is of the first type.
[0026] In a possible design, the method further includes transmitting a third message, wherein the type of the third message is the second type.
[0027] According to a fourth aspect, an embodiment of the present application provides a communication method, which may be applied to a second functional module in a first communication device, in which the second functional module in the first communication device receives a first message and instruction information for the first message, the instruction information indicating that the first message needs to be stamped, encrypts the first message to obtain a second message, sends the second message, stamps the second message according to the instruction information to obtain a first timestamp, and sends the first timestamp, where the first timestamp indicates a sending time of the second message.
[0028] In a possible design, the type of the first message is of the first type.
[0029] In a possible design, the method further includes receiving a third message, encrypting the third message to obtain a fourth message, and sending the fourth message, wherein the type of the third message is the second type.
[0030] According to a fifth aspect, an embodiment of the present application provides a communication method, which may be applied to a third functional module in a second communication device, in which the third functional module of the second communication device receives a second message, stamps the second message to obtain a second timestamp, the second timestamp indicating a reception time of the second message, decodes the second message to obtain a first message, and transmits the first message and the second timestamp.
[0031] In a possible design, the step of transmitting the first message and the second timestamp includes the step of transmitting the first message and the second timestamp after determining that the type of the first message is the first type.
[0032] In one possible design, the method further includes receiving a fourth message, stamping the fourth message to obtain a third timestamp, the third timestamp indicating a time of receipt of the fourth message, decoding the fourth message to obtain the third message, and transmitting the third message after determining that the type of the third message is the second type. Optionally, the second timestamp is discarded.
[0033] According to the methods of the third to fifth aspects, from the perspective of the message transmitting side, the first functional module of the transmitting side may send the message and message indication information to the second functional module, so that after encrypting the message, the second functional module may stamp the message based on the indication information. From the perspective of the message receiving side, the third functional module may stamp each received message, and after decrypting the message, if the obtained message is a first type message, send the message and a timestamp to the fourth functional module. In this way, it can be ensured that the first type message is marked with a timestamp when the message is encrypted / decrypted to help implement time synchronization between the first communication device and the second communication device.
[0034] According to a sixth aspect, the present application provides a communication device. The communication device has functions for implementing the first to fifth aspects. For example, the communication device includes corresponding modules, units, or means for performing the operations in the first to fifth aspects. The modules, units, or means may be implemented by software, hardware, or hardware executing the corresponding software.
[0035] In one possible design, the communication device includes a processing unit and a communication unit. The communication unit may be configured to receive and transmit signals to implement communication between the communication device and another device. The processing unit may be configured to perform some internal operations of the communication device. Functions performed by the processing unit and the communication unit may correspond to operations of the first to fifth aspects.
[0036] In a possible design, the communication device may include a processor, the processor being configured to be coupled to a memory. The memory may store computer programs or instructions necessary to implement the functionality of the first to fifth aspects. The processor may execute the computer programs or instructions stored in the memory. When the computer programs or instructions are executed, the communication device is enabled to implement the method of any possible design or implementation of the first to fifth aspects.
[0037] In one possible design, the communication device includes a processor and a memory. The memory may store computer programs or instructions necessary to implement the functions of the first to fifth aspects. The processor may execute the computer programs or instructions stored in the memory. When the computer programs or instructions are executed, the communication device is enabled to implement the method of any possible design or implementation of the first to fifth aspects.
[0038] In one possible design, the communication device includes a processor and an interface circuit, the processor configured to communicate with another device via the interface circuit and to perform a method in any possible design or implementation of the first to fifth aspects.
[0039] In the sixth aspect, it can be understood that the processor may be implemented by hardware or software. When the processor is implemented by hardware, the processor may be a logic circuit, an integrated circuit, etc. When the processor is implemented by software, the processor may be a general-purpose processor or may be implemented by reading software code stored in a memory. In addition, there may be one or more processors, and there may be one or more memories. The memory may be integrated with the processor, or the memory and the processor may be located separately. In a specific implementation process, the memory and the processor may be integrated on the same chip, or may be located separately on different chips. The type of memory and the method of arranging the memory and the processor are not limited in this embodiment of the present application.
[0040] According to a seventh aspect, the present application provides a communication system. The communication system may include a first communication device and a second communication device. The first communication device is configured to perform a communication method provided in the first, third, or fourth aspect, and the second communication device is configured to perform a communication method provided in the second or fifth aspect.
[0041] According to an eighth aspect, the present application provides a computer-readable storage medium having computer-readable instructions stored thereon, the computer-readable instructions, when read and executed by a computer, enabling the computer to perform the method of any possible design of the first to fifth aspects.
[0042] According to a ninth aspect, the present application provides a computer program product, which, when read and executed by a computer, enables the computer to carry out the method of any possible design of the first to fifth aspects.
[0043] According to a tenth aspect, the present application provides a chip, the chip including a processor, coupled to a memory, configured to read and execute a software program stored in the memory to implement a method in any possible design of the first to fifth aspects. [Brief explanation of the drawings]
[0044] [Figure 1a] FIG. 1 is a diagram of a network architecture for fronthaul networking according to an embodiment of the present application. [Figure 1b] FIG. 1 is a diagram of CPRI and eCPRI according to an embodiment of the present application. [Figure 2] 1 is a diagram of a communication system according to an embodiment of the present application; [Figure 3] 2 is a diagram of a possible structure of a first communication device and a second communication device according to an embodiment of the present application; [Figure 4] 1 is a schematic flow chart of a possible implementation of clock synchronization according to an embodiment of the present application; [Figure 5] 1 is a schematic flowchart corresponding to a communication method according to an embodiment of the present application; [Figure 6] 1 is a schematic flowchart corresponding to a communication method according to an embodiment of the present application; [Figure 7] 1 is a block diagram of a possible example of an apparatus according to an embodiment of the present application; [Figure 8] 1 is a diagram of the structure of a communication device according to an embodiment of the present application; [Figure 9] 1 is a diagram of the structure of a communication device according to an embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION
[0045] The following describes the technical solutions of the embodiments of the present application with reference to the accompanying drawings of the embodiments of the present application.
[0046] First, some terms in the embodiments of the present application will be explained to help those skilled in the art to understand better.
[0047] (1) Clock synchronization Clock synchronization may include time synchronization and, optionally, may further include frequency synchronization.
[0048] As an example, clock synchronization between network node A and network node B is used. Time synchronization may mean that the time of network node A is the same as the time of network node B, which is the same as adjusting the clock time. For example, the time of network node A is 10:00 AM on November 1, 2022, and the time of network node B is also 10:00 AM on November 1, 2022.
[0049] Frequency synchronization may mean that the clock of network node A and the clock of network node B operate at the same frequency. For example, the crystal oscillator frequency of network node A is the same as the crystal oscillator frequency of network node B, which is equivalent to adjusting the timing accuracy of the clocks. When the clock of network node A and the clock of network node B operate at the same frequency, in the same time period, the count number of the clock of network node A is the same as the count number of the clock of network node B, and the increment value of the time of network node A is the same as the increment value of the time of network node B. For example, the time of network node A is incremented by 20 seconds (s), and the time of network node B is also incremented by 20 seconds.
[0050] For example, when network node A and network node B perform clock synchronization according to synchronization protocols such as PTP and syncE protocol, network node A and network node B may perform time synchronization according to PTP and frequency synchronization according to syncE protocol. Time synchronization and / or frequency synchronization may alternatively be performed between network nodes according to another protocol. This is not limited thereto. In the embodiment of the present application, an example is used in which different network nodes perform clock synchronization according to PTP. In this case, clock synchronization may be understood as time synchronization.
[0051] (2)PTP PTP is a protocol published by the Institute of Electrical and Electronics Engineers (IEEE) for synchronizing the clocks of different network nodes in a clock network. In this protocol, certain PTP messages transmitted between two network nodes in a network are marked with a corresponding timestamp to measure the delay between the two network nodes, thereby achieving clock synchronization between the two network nodes. When two network nodes perform clock synchronization, the network node that needs to adjust its clock is the slave node, and the other network node is the master node; that is, the slave node adjusts its local clock by referring to the clock of the master node.
[0052] For example, the PTP message may include a clock synchronization message and a management message. The clock synchronization message may include a synchronization (sync) message, a follow-up (follow_up) message, a delay request (delay_req) message, a delay response (delay_resp) message, etc., and may further include other possible messages. This is not specifically limited.
[0053] Clock synchronization messages that need to be stamped may include synchronization messages and delay request messages, and clock synchronization messages that do not need to be stamped may include follow-up messages and delay response messages. Clock synchronization messages that need to be stamped may also be called event messages, and clock synchronization messages and management messages that do not need to be stamped may also be called general messages.
[0054] (3) Encryption / Decryption To ensure the security of the communication process, the transmitting side may encrypt a transmitted message, and the receiving side may correspondingly decrypt a received message. Decryption is the reverse process of encryption. For example, encryption / decryption may be a MACsec process performed according to the media access control security (MACsec) protocol, or an IPsec process performed according to the internet protocol security (IPsec) protocol. In the embodiments of the present application, an example in which encryption / decryption is a MACsec process is used for explanation. The MACsec protocol integrates security protection into Ethernet, using cryptographic techniques to authenticate the origin of data, protect the integrity of information, and provide replay protection and confidentiality to ensure that attacks against layer 2 protocols are reduced. MACsec processing may be performed at the MAC layer or at another layer. In the embodiments of the present application, an example in which MACsec processing is performed at the MAC layer is used for explanation.
[0055] For example, when the encryption / decryption is a MACsec process, the encryption / decryption may be performed according to the media access control security agreement protocol (MKA).
[0056] (4) Fronthaul Networking 1a is a diagram of a network architecture of fronthaul networking according to one embodiment of the present application. As shown in FIG. 1a, the network architecture of fronthaul networking may include at least one REC (e.g., REC1 and REC2 shown in FIG. 1a) and at least one RE (e.g., RE1, RE2, and RE3 shown in FIG. 1a), and may optionally further include at least one transmission equipment (TE) (e.g., TE1, TE2, TE3, TE4, TE5, and TE6 shown in FIG. 1a). REC1 is configured to control RE1, and REC2 is configured to control RE2 and RE3.
[0057] REC1 and RE1 are used as an example. REC1 and RE1 may be directly connected, i.e., there are no other intermediate network elements between REC1 and RE1. In this case, REC1 and RE1 may perform clock synchronization according to the PTP protocol, with REC1 being the master node of the clock synchronization and RE1 being the slave node. Alternatively, REC1 and RE1 may not be directly connected. For example, REC1 and RE1 are connected via TE1, TE3, and TE5. In this case, REC1 and TE1 may perform clock synchronization according to the PTP protocol (REC1 is the master node for clock synchronization and TE1 is the slave node), TE1 and TE3 may perform clock synchronization according to the PTP protocol (TE1 is the master node for clock synchronization and TE3 is the slave node), TE3 and TE5 may perform clock synchronization according to the PTP protocol (TE3 is the master node for clock synchronization and TE5 is the slave node), and TE5 and RE1 may perform clock synchronization according to the PTP protocol (TE5 is the master node for clock synchronization and RE1 is the slave node).
[0058] The fronthaul networking in this embodiment of the present application may be used in a radio access network (RAN). The RAN may be a cellular system related to the 3rd generation partnership project (3GPP), such as a fourth-generation (4G) or fifth-generation (5G) mobile communication system, or a future-oriented evolution system (e.g., a sixth-generation (6G) mobile communication system). Alternatively, the RAN may be an open access network (O-RAN or ORAN), a cloud radio access network (CRAN), or the like. Alternatively, the RAN may be a communication system that integrates two or more of the above systems.
[0059] The RAN includes RAN nodes, which may also be referred to as access network devices, RAN entities, access nodes, etc., and form part of a communication system to help terminals implement radio access. When a communication system includes multiple RAN nodes, the multiple RAN nodes may be the same type of node or different types of nodes.
[0060] In possible scenarios, a RAN node may be a base station, evolved NodeB (eNodeB), access point (AP), transmission reception point (TRP), next generation NodeB (gNB), next generation NodeB in a 6G mobile communication system, a base station in a future mobile communication system, etc. The RAN node may be a macro base station, a micro base station, an indoor base station, a relay node, a donor node, or a radio controller in a CRAN scenario. Optionally, the RAN node may alternatively be a server, a wearable device, a vehicle, an in-vehicle device, etc. For example, an access network device in vehicle-to-everything (V2X) technology may be a road side unit (RSU).
[0061] In another possible scenario, multiple RAN nodes cooperate to perform the functions of a base station, with different RAN nodes separately performing some of the functions of a base station. For example, a RAN node may be a central unit (CU), a distributed unit (DU), a CU control plane (CP), a CU user plane (UP), a radio unit (RU), etc. The CU and DU may be located separately or may be included in the same network element, e.g., a baseband unit (BBU). The RU may be included in a radio frequency device or radio frequency unit, e.g., a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).
[0062] In different systems, the CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand the meaning of the names. For example, in an ORAN system, the CU may be called an O-CU (open CU), the DU may be called an O-DU, the CU-CP may be called an O-CU-CP, the CU-UP may be called an O-CU-UP, and the RU may be called an O-RU. For ease of explanation, the CU, CU-CP, CU-UP, DU, and RU are used as examples for explanation in this application. Any one of the CU (or CU-CP and CU-UP), DU, and RU in this application may be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0063] There is an interface between the DU and the RU. The interface, sometimes called a fronthaul (FH) interface, is configured to implement communication between the DU and the RU. Depending on the different functions and / or division schemes of the DU and the RU, the interface between the DU and the RU may be a common public radio interface (CPRI) or an enhanced common public radio interface (eCPRI). In a possible implementation, the DU is located in the BBU, and the RU is located in the RRU / AAU, and the interface between the BBU and the RRU / AAU is sometimes called a fronthaul interface. To implement the fronthaul interface, the BBU and the RRU / AAU / RRH, or the DU and the RU, may be connected via a fronthaul network. For example, the fronthaul network includes, but is not limited to, optical fiber direct connection and a wavelength division multiplexing network.
[0064] In a possible design, for CPRI shown in FIG. 1b, for downlink transmission, the DU is configured to implement one or more of the following physical layer baseband functions: encoding, rate matching, scrambling, modulation, layer mapping, precoding, resource element (RE) mapping, digital beamforming (BF), or inverse fast Fourier transformation (IFFT) / cyclic prefix (CP) addition. The RU is configured to perform one or more of the following radio frequency functions: digital-to-analog (DA) conversion or analog BF. For uplink transmission, the DU is configured to perform one or more of the following physical layer baseband functions: decoding, de-rate matching, descrambling, demodulation, inverse discrete Fourier transformation (IDFT), channel equalization (or channel estimation), RE demapping, digital BF, or fast Fourier transform (FFT) / CP removal. The RU is configured to perform one or more of the following radio frequency functions: analog to digital (AD) conversion or analog BF.
[0065] In another possible implementation, compared to CPRI, eCPRI shown in FIG. 1b moves some of the downlink and / or uplink baseband functions from the DU to the RU for implementation. The interface between the DU and the RU is sometimes referred to as a lower layer split (LLS). In a possible design, the DU is located in the BBU, the RU is located in the RRU / AAU, and a processing unit in the BBU configured to perform the baseband functions is referred to as a baseband high (BBH) unit, and a processing unit in the RRU / AAU configured to perform the baseband functions is referred to as a baseband low (BBL) unit.
[0066] FIG. 1b shows six possible implementations of eCPRI. In the figure, the six implementations are shown as Categories (Cat) A to F. Different categories of eCPRI may alternatively be described as different types of eCPRI, different options of eCPRI, or other possible names. For example, the six eCPRIs in FIG. 1b may also be referred to as six options of eCPRI. In addition to the eCPRI shown in FIG. 1b, other types of eCPRI may exist, i.e., other division schemes may exist. This is not limiting.
[0067] For eCPRI Cat B and Cat C shown in Figure 1b, the division of the eCPRI uplink and downlink parts may be symmetric. For eCPRI Cat A, Cat D, Cat E, and Cat F shown in Figure 1b, the division of the eCPRI uplink and downlink parts may be asymmetric. This is not a limitation. Optionally, for the uplink and / or downlink, different division schemes may be configured for different channels or different channel groups, i.e., different types of eCPRI are configured. One group of channels may include one or more channels.
[0068] For example, the REC may be a network element or a device having a baseband signal processing function, such as a BBU or a software module, a hardware circuit, or a software module and a hardware circuit in the BBU. Alternatively, the REC may be a DU or a software module, a hardware circuit, or a software module and a hardware circuit in the DU. Optionally, the REC may further have at least one of the following functions: local and remote operation and maintenance functions, operating status monitoring and alarm information reporting functions, etc.
[0069] For example, an RE may be a network element or device having the function of processing wireless signals (e.g., intermediate frequency signals and / or radio frequency signals), also referred to as a radio frequency unit. For example, an RE may be an RRU, an AAU, an RRH, or an RU, or may be a software module, a hardware circuit, or a software module and a hardware circuit within these network elements.
[0070] It will be understood that REC and RE are names in the common public radio interface (CPRI) protocol, and that REC and RE may have different names in other possible protocols. For example, in the enhanced common public radio interface (eCPRI), the REC is called eREC and the RE is called eRE. As another example, in the open radio access network (ORAN) protocol, the REC may be a distributed unit (DU) and the RE may be an RU.
[0071] All aspects, embodiments, or features are presented below in this application by describing a communication system that may include multiple devices, components, modules, etc. It is to be understood that the communication system may include other devices, components, modules, etc. and / or may not include all the devices, components, modules, etc. described with reference to the accompanying drawings. Additionally, combinations of these solutions may be used.
[0072] The communication systems and service scenarios described in the embodiments of the present application are intended to more clearly explain the technical solutions in the embodiments of the present application, and do not constitute limitations on the technical solutions provided in the embodiments of the present application. Those skilled in the art may know that with the development of network architectures and the emergence of new service scenarios, the technical solutions provided in the embodiments of the present application can also be applied to similar technical problems.
[0073] In order to facilitate understanding of the embodiments of the present application, the communication system shown in Figure 2 is first used as an example to describe in detail the communication system applicable to the embodiments of the present application. As shown in Figure 2, the communication system includes a first communication device and a second communication device. The first communication device and the second communication device may perform clock synchronization according to a clock synchronization protocol. In the embodiments of the present application, an example is used in which the first communication device and the second communication device perform clock synchronization according to PTP.
[0074] The first communication device may be a master node, and the second communication device may be a slave node, or the first communication device may be a slave node, and the second communication device is a master node. In the embodiment of the present application, an example in which the first communication device is a master node and the second communication device is a slave node is used for description.
[0075] It will be understood that the communication system shown in FIG. 2 is applicable to multiple possible scenarios, for example, a fronthaul networking scenario. When the communication system is applicable to a fronthaul networking scenario, the first communication device may be an REC and the second communication device is an RE. For example, the first communication device is REC1 and the second communication device is RE1, with no other intermediate network elements between REC1 and RE1. Alternatively, the first communication device may be an REC and the second communication device is a TE. For example, the first communication device is REC1 shown in FIG. 1a, and the second communication device is TE1 shown in FIG. 1a. Alternatively, the first communication device may be a TE and the second communication device is another TE. For example, the first communication device is TE1 shown in FIG. 1a, and the second communication device is TE3 shown in FIG. 1a. Alternatively, the first communication device may be a TE and the second communication device is an RE. For example, the first communication device is TE5 shown in FIG. 1a, and the second communication device is RE1 shown in FIG. 1a.
[0076] In addition, in the embodiments of the present application, a first communication device communicating with a second communication device may mean that the first communication device communicates directly with the second communication device. For example, the first communication device directly transmits information 1 to the second communication device, or the second communication device directly transmits information 2 to the first communication device. Alternatively, in the embodiments of the present application, a first communication device communicating with a second communication device may mean that the first communication device communicates with the second communication device via a relay node. For example, the first communication device transmits information 1 to the relay node, and the relay node receives information 1 and then forwards information 1 to the second communication device.
[0077] 3 is a diagram of a possible structure of a first communication device and a second communication device according to an embodiment of the present application. As shown in FIG. 3, the first communication device may include a first functional module and a second functional module, and the second communication device may include a third functional module and a fourth functional module.
[0078] The first functional module may be a PTP functional module (referred to as PTP functional module 1 for ease of explanation) and is configured to implement functions related to the PTP layer, for example, to generate PTP messages and parse PTP messages to obtain information within the PTP messages.
[0079] The second functional module may be an Ethernet port functional module and is configured to perform functions related to an Ethernet port. For example, the second functional module may include a MAC layer functional module 1, a timestamp functional module 1, and a physical layer functional module 1. The timestamp functional module 1 may be located between the MAC layer functional module 1 and the physical layer functional module 1. For example, the timestamp functional module 1 may be close to the physical layer functional module 1 (i.e., the position where the timestamp is marked is near the physical layer). In another possible example, the timestamp functional module 1 may alternatively be located in the physical layer functional module 1 (i.e., the position where the timestamp is marked is in the physical layer).
[0080] The location where the timestamp is marked is described as follows: In PTP, the timestamp is used to implement clock synchronization between the slave node and the master node, so the location where the timestamp is marked affects the accuracy of the clock synchronization. In a specific implementation, the timestamp may be marked by using software or hardware. When the timestamp is marked using software, the location where the timestamp is marked is close to the operating system, the jitter time is long, and the time offset is within 100 microseconds. When the timestamp is marked using hardware, the location where the timestamp is marked is in or near the physical layer, the jitter time is shorter than the jitter time of marking the timestamp using software, and the accuracy can reach the nanosecond level. In the embodiments of the present application, related implementation forms are described based on a solution in which the timestamp is marked using hardware (i.e., the timestamp function module is close to or located in the physical layer).
[0081] The MAC layer function module 1 is configured to perform functions related to the MAC layer, the timestamp function module 1 is configured to stamp a first type of PTP message, and the physical layer function module 1 is configured to perform functions related to the physical layer.
[0082] For example, when a first communication device is a message transmitter, the MAC layer function module 1 may perform MAC layer encapsulation on a message received from an upper layer (e.g., a PTP layer) and send the message obtained by the encapsulation to the physical layer function module 1, which then sends the message to another communication device (e.g., a second communication device). In addition, the timestamp function module 1 may detect whether the message transmitted from the MAC layer function module 1 to the physical layer function module 1 is a first type message. If the message transmitted from the MAC layer function module 1 to the physical layer function module 1 is a first type message, the timestamp function module 1 may stamp the message to obtain a transmission timestamp of the message and send the timestamp to the PTP function module 1.
[0083] When the first communication device is a message receiver, after receiving a message from another communication device (e.g., a second communication device), the physical layer function module 1 may transmit the message to the MAC layer function module 1, so that the MAC layer function module 1 may decapsulate the message and send the message obtained by decapsulation to the PTP function module 1. In addition, the timestamp function module 1 may detect whether the message transmitted from the physical layer function module 1 to the MAC layer function module 1 is a first type message. If the message transmitted from the physical layer function module 1 to the MAC layer function module 1 is a first type message, the timestamp function module 1 may stamp the message to obtain a reception timestamp of the message and send the timestamp to the PTP function module 1.
[0084] For the third and fourth functional modules, please refer to the description of the first and second functional modules. For example, the third functional module may be an Ethernet port functional module, and the third functional module may include a MAC layer functional module 2, a timestamp functional module 2, and a physical layer functional module 2, and the fourth functional module may be a PTP functional module 2. Details will not be described again.
[0085] 4, the following describes a possible implementation procedure for the first communication device and the second communication device to perform clock synchronization. As shown in FIG. 4, the implementation procedure may include the following steps:
[0086] S401: A first communication device sends a synchronization message to a second communication device and stamps the synchronization message to obtain a timestamp T1, where the timestamp T1 indicates the sending time of the synchronization message. Correspondingly, the second communication device receives the synchronization message and stamps the synchronization message to obtain a timestamp T2, where the timestamp T2 indicates the receiving time of the synchronization message.
[0087] For example, from the perspective of the first communication device, the PTP function module 1 generates a synchronization message and sends the synchronization message to the MAC layer function module 1. After receiving the synchronization message, the MAC layer function module 1 encapsulates the synchronization message and sends the message obtained by encapsulation to the physical layer function module 1. In addition, after the timestamp function module 1 detects that the message transmitted from the MAC layer function module 1 to the physical layer function module 1 is a synchronization message, it stamps the synchronization message to obtain a timestamp T1 and sends the timestamp T1 to the PTP function module 1.
[0088] From the perspective of the second communication device, after receiving a message from the first communication device, the physical layer function module 2 transmits the message to the MAC layer function module 2, and then the MAC layer function module 2 decapsulates the message to obtain a synchronization message and transmits the synchronization message to the PTP function module 2. After detecting that the message transmitted from the physical layer function module 2 to the MAC layer function module 2 is a synchronization message, the timestamp function module 2 stamps the synchronization message to obtain a timestamp T2 and transmits the timestamp T2 to the PTP function module 2.
[0089] S402: The first communication device sends a follow-up message of the synchronization message to the second communication device, where the follow-up message includes a timestamp T1. Correspondingly, after receiving the follow-up message, the second communication device obtains the timestamp T1.
[0090] For example, from the perspective of the first communication device, after receiving the timestamp T1 from the timestamp function module 1, the PTP function module 1 generates a follow-up message and sends the follow-up message to the MAC layer function module 1. After receiving the follow-up message, the MAC layer function module 1 encapsulates the follow-up message and sends the message obtained by encapsulation to the physical layer function module 1. In addition, after detecting that the message transmitted from the MAC layer function module 1 to the physical layer function module 1 is a follow-up message, the timestamp function module 1 does not need to perform stamping.
[0091] From the perspective of the second communication device, after receiving a message from the first communication device, the physical layer function module 2 transmits the message to the MAC layer function module 2, and then the MAC layer function module 2 decapsulates the message to obtain a follow-up message and transmits the follow-up message to the PTP function module 2. In addition, after the timestamp function module 2 detects that the message transmitted from the physical layer function module 2 to the MAC layer function module 2 is a follow-up message, it does not need to perform stamping.
[0092] S403: The second communication device sends a delay request message to the first communication device, and stamps the delay request message to obtain a timestamp T3, where the timestamp T3 indicates the sending time of the delay request message.
[0093] S404: After receiving the delay request message, the first communication device stamps the delay request message to obtain a timestamp T4, where the timestamp T4 indicates the reception time of the delay request message, and sends a delay response message to the second communication device, where the delay response message includes the timestamp T4.
[0094] For example, for specific implementations of S403 and S404, see S401 and S402.
[0095] Through S401 to S404, the second communication device can obtain timestamps T1, T2, T3, and T4, determine the time difference and path delay in the transmission process between the first communication device and the second communication device based on the timestamps T1, T2, T3, and T4, and perform clock synchronization between the first communication device and the second communication device based on the determined time difference and path delay.
[0096] From the description of FIG. 4, it can be seen that in the clock synchronization process, some clock synchronization messages (e.g., synchronization messages and delay request messages) need to be stamped. Therefore, to facilitate stamping these clock synchronization messages, the clock synchronization messages are transmitted in a plaintext manner. As a result, security issues may exist, and the accuracy of clock synchronization between the first communication device and the second communication device may be affected. For example, if the synchronization message sent by the first communication device to the second communication device is tampered with, after receiving the follow-up message, the second communication device may not be able to accurately determine the synchronization message whose transmission time is indicated by the timestamp T1 included in the follow-up message. As a result, the accuracy of clock synchronization may be affected.
[0097] Based on this, an embodiment of the present application provides a communication method for encrypting / decrypting messages that need to be stamped, thereby improving the security of message transmission.
[0098] Embodiment 1 5 is a schematic flowchart corresponding to a communication method according to an embodiment of the present application. As shown in FIG. 5, the communication method may include the following steps:
[0099] S501: A first communication device encrypts a first message to obtain a second message.
[0100] The first message here may be a message that needs to be stamped. For example, the first message may be the aforementioned clock synchronization message that needs to be stamped (for example, a synchronization message or a delay request message), or may be another message that needs to be stamped. This is not specifically limited. In this embodiment of the present application, an example in which the first message is a clock synchronization message that needs to be stamped is used for description.
[0101] S502: The first communication device transmits a second message and a first timestamp to the second communication device, where the first timestamp indicates the transmission time of the first message or the second message. In response, the second communication device receives the second message and the first timestamp.
[0102] In this specification, there may be multiple implementation forms in which a first communication device transmits a first timestamp to a second communication device. For example, the first communication device may transmit a second message to the second communication device, and then transmit a message to the second communication device, the message including the first timestamp. The message may be encrypted or unencrypted. This is not limited.
[0103] For example, in this embodiment of the present application, messages can be classified into two types: a first type and a second type. The first type of message is a message that needs to be stamped, and the second type of message is a message that does not need to be stamped. The type of the first message is the first type.
[0104] When the first message is a clock synchronization message (e.g., a synchronization message) that needs to be stamped, the first timestamp can be used for clock synchronization between the first communication device and the second communication device. The first communication device can send the first timestamp to the second communication device using a follow-up message of the synchronization message.
[0105] S503: The second communication device decodes the second message to obtain the first message.
[0106] S504: The second communication device stamps the second message to obtain a second timestamp, where the second timestamp indicates a receiving time of the second message.
[0107] S504 is an optional step herein. For example, when the first message is a clock synchronization message that needs to be stamped, S504 may be performed, or when the first message is another message that needs to be stamped, S504 may not be performed.
[0108] It should be understood that the above uses an example in which a first type of message is transmitted between a first communication device and a second communication device. A second type of message may also be transmitted between the first communication device and the second communication device. For example, the first communication device may encrypt a third message (the type of the third message is the second type) to obtain a fourth message and send the fourth message (which, unlike the first type of message, does not transmit a timestamp for the fourth message) to the second communication device. After receiving the fourth message, the second communication device may stamp the fourth message to obtain a third timestamp, which indicates the time of receipt of the fourth message, decrypt the fourth message to obtain the third message, and discard the third timestamp after determining that the type of the third message is the second type.
[0109] In addition, the above has been described using an example in which a first communication device transmits a message to a second communication device. That is, the first communication device is the message transmitter, and the second communication device is the message receiver. In another possible embodiment, the second communication device may alternatively transmit a message to the first communication device. That is, the second communication device is the message transmitter, and the first communication device is the message receiver. For an implementation in which a second communication device transmits a message to a first communication device, please refer to the implementation in which a first communication device transmits a message to a second communication device. Details will not be described again.
[0110] According to the aforementioned method, the first communication device sends the second message and the first timestamp to the second communication device, so that an encrypted transmission can be performed for the message that needs to be stamped, thereby improving the security of the message transmission.
[0111] Optionally, the above method further comprises the following steps:
[0112] S505: The first communication device sends request information to the second communication device, where the request information is used to request capability information of the second communication device.
[0113] For example, the request information may include an identity of the requesting device (i.e., the first communication device) and an encryption / decryption capability request indication. The identity of the first communication device may be, for example, the clock identity of the first communication device. The encryption / decryption capability request indication indicates that capability information indicating whether the second communication device supports encryption / decryption of the message is requested.
[0114] For example, a first communication device may send a first management message to a second communication device, where the first management message includes request information. For example, the first management message may include a type, length, value (TLV) type field, a TLV length field, a requesting device identity field (which may be referred to as a requestIdentity field), and an encryption / decryption capability request indication field (which may be referred to as a requestMACsecAbility field). The TLV type field indicates a TLV type, which may be a TLV type newly introduced in this embodiment of the present application. The TLV length field indicates the total number of bytes occupied by the requesting device identity field and the encryption / decryption capability request indication field. The requesting device identity field is used to carry the requesting device identity. The MACsec capability request indication field is used to carry the encryption / decryption capability request indication.
[0115] Table 1 shows an example of the fields included in the first management message.
[0116] [Table 1]
[0117] In this embodiment of the present application, the TLV type field indicates the type or function of the message carrying the TLV type field. For example, in this case, the TLV type field of the first management message indicates that the message is used to request capability information of the second communication device.
[0118] The number of bytes occupied by each field in Table 1 above and Tables 2 and 3 below is merely an example and is not limited to a particular implementation.
[0119] It will be understood that the first communication device may send the request information to the second communication device when it determines that the first communication device supports encryption / decryption of the message, and if the first communication device does not support encryption / decryption of the message, the first communication device does not need to send the request information to the second communication device in order to save transmission resources.
[0120] S506: The second communication device sends capability information to the first communication device based on the request information. In response, the first communication device receives capability information from the second communication device, where the capability information indicates whether the second communication device supports encryption / decryption of the message.
[0121] When the capability information indicates that the second communication device supports message encryption / decryption, the message encryption / decryption method in this embodiment of the present application may be executed.
[0122] For example, the second communication device may send a second management message to the second communication device, and the second management message may include capability information. For example, the second management message may include a TLV type field, a TLV length field, a requesting device identity field, a responding device identity field (which may be denoted as grantIdentity), and a responding device capability field (which may be denoted as grantMACsecAbility). For the TLV type field, the TLV length field, and the requesting device identity field, please refer to the above description. The responding device identity field is used to convey the identity of the responding device (i.e., the second communication device). The identity of the second communication device is, for example, the clock identity of the second communication device. The responding device capability field is used to convey capability information. Table 2 shows an example of fields included in the second management message.
[0123] [Table 2]
[0124] The TLV type field of the second management message indicates that the message is used to report capability information of the second communication device, i.e., the message carries capability information of the second communication device.
[0125] In one example, the grantMACsecAbility field is used as an example. When the grantMACsecAbility field includes 2 bytes (i.e., 16 bits), one bit of the 16 bits may indicate whether message encryption / decryption is supported (e.g., when the value of the bit is 0, it indicates that message encryption / decryption is not supported, or when the value of the bit is 1, it indicates that message encryption / decryption is supported), and the remaining 15 bits may be reserved bits.
[0126] It should be understood that S505 is an optional step. In other words, the second communication device may send the capability information to the first communication device based on the request information, or the second communication device may actively send the capability information to the first communication device. This is not specifically limited.
[0127] S507: The first communication device sends notification information to the second communication device, which notifies the second communication device of the start of encryption / decryption of the PTP message. In response, the second communication device receives the notification information.
[0128] For example, the first communication device may send a third management message to the second communication device, where the third management message includes notification information. For example, the third management message may include a TLV type field, a TLV length field, a requesting device identity field, and an encryption / decryption capability field (referred to as a MACsecAbility field). For the TLV type field, the TLV length field, and the requesting device identity field, see the above description. The MACsec capability field is used to carry the notification information.
[0129] Table 3 shows an example of the fields contained in the third management message.
[0130] [Table 3]
[0131] The TLV type field of the third management message indicates that the message notifies the second communication device to start encryption / decryption of PTP messages.
[0132] For example, after the second communication device receives the notification information, the first communication device and the second communication device may perform an encryption / decryption negotiation procedure, and may calculate SAK and matching parameter information through negotiation according to an MKA key agreement protocol to encrypt / decrypt messages. For specific implementation forms, please refer to descriptions of existing protocols (e.g., IEEE 802.1x) or future evolved versions of existing protocols.
[0133] (1) It should be understood that steps S505 to S507 are optional. For example, when all communication devices in a communication system support message encryption / decryption due to functional evolution of communication devices, a first communication device may assume by default that both the first communication device and the second communication device support message encryption / decryption, and therefore steps S505 to S507 do not need to be performed. In a practical networking scenario, if some communication devices support message encryption / decryption but some do not, steps S505 to S507 may be performed, so that two communication devices that transmit messages first negotiate whether message encryption / decryption is supported. When a first communication device (i.e., a master node) determines that it supports message encryption / decryption and a second communication device (i.e., a slave node) also supports message encryption / decryption, the first communication device may notify the second communication device to begin message encryption / decryption, so that the first communication device and the second communication device may perform message transmission in a ciphertext manner to improve the security of the message transmission.
[0134] (2) In this embodiment of the present application, an example in which clock synchronization messages are encrypted / decrypted is used for explanation. When management message transmission is performed in the clock synchronization process, the management messages may also be encrypted / decrypted to ensure security. Specifically, the first communication device and the second communication device perform negotiation through S505 to S507 (the management messages transmitted in the negotiation process are not encrypted / decrypted). After the negotiation is completed, the first communication device and the second communication device may encrypt / decrypt PTP messages (including clock synchronization messages and management messages) transmitted between the first communication device and the second communication device.
[0135] Embodiment 2 Based on the above description of FIG. 3, in a possible implementation, a first communication device is used as an example. In embodiment 1, the first communication device encrypting a message may mean that the MAC layer function module of the first communication device encrypts a clock synchronization message. In this case, an example is used in which the first communication device is used as the message transmitter. After encrypting the message, the MAC layer function module of the first communication device transmits the encrypted message to the physical layer function module, which then transmits the encrypted message to the second communication device. However, after the message is encrypted, the timestamp function module cannot identify whether the message is a first type message. As a result, it cannot determine whether to stamp the message, and the implementation of stamping is affected.
[0136] To solve this problem, embodiment 2 of the present application provides a possible solution, which will be described below with reference to FIG.
[0137] 6 is a schematic flowchart corresponding to a communication method according to an embodiment of the present application. As shown in FIG. 6, the communication method may include the following steps:
[0138] S601: A first functional module of a first communication device transmits a first message and indication information of the first message to a second functional module of the first communication device, and in response, the second functional module receives the first message and indication information of the first message from the first functional module.
[0139] The indication information of the first message here indicates that the first message needs to be stamped or indicates that the type of the first message is a first type. For example, the indication information of the first message includes type information of the first message, and the type information indicates that the type of the first message is a first type. Optionally, the indication information of the first message further includes an identity of the first message, and the identity of the first message may be a sequence number of the first message.
[0140] It will be understood that if the first message is a first type of message, the first functional module may send the first message and indication information of the first message to the second functional module, or if the first message is not a first type of message (e.g., the first message is a second type of message or an administrative message), the first functional module may send the first message to the second functional module but not send indication information of the first message.
[0141] S602: A second function module encrypts the first message to obtain a second message, and sends the second message to a second communication device.
[0142] S603: The second function module stamps the second message according to the instruction information to obtain a first timestamp, and sends the first timestamp to the PTP function module, where the first timestamp indicates the sending time of the first message or the second message. In response, the first function module receives the first timestamp from the second function module.
[0143] Regarding S602 and S603, in a possible implementation, the MAC layer function module 1 in the second function module encrypts the first message to obtain a second message and sends the second message and indication information of the first message to the timestamp function module 1. Correspondingly, after receiving the indication information of the second message and the first message, the timestamp function module 1 may stamp the second message based on the indication information to obtain a first timestamp and send the first timestamp to the first function module. Optionally, if the indication information of the first message includes the identity of the first message, the timestamp function module 1 may further send the identity of the first message to the first function module to help the first function module determine that the first timestamp indicates the transmission time of the first message. In addition, the timestamp function module 1 sends the second message to the physical layer function module 1, so that the physical layer function module 1 sends the second message to the second communication device.
[0144] Optionally, the first functional module of the first communication device may, after receiving the first timestamp, transmit the first timestamp to the second communication device.
[0145] S604: After the second communication device receives the second message, a third functional module of the second communication device stamps the second message to obtain a second timestamp, where the second timestamp indicates the receiving time of the second message.
[0146] S605: A third functional module of the second communication device decodes the second message to obtain the first message.
[0147] S606: When the type of the first message is the first type, the third function module sends the first message and the second timestamp to a fourth function module of the second communication device.
[0148] Regarding S604 to S606, in a possible implementation, the physical layer function module 2 in the third function module receives a second message from the first communication device and sends the second message to the timestamp function module 2. The timestamp function module 2 stamps the second message to obtain a second timestamp and sends the second message and the second timestamp to the MAC layer function module 2 in the third function module. After receiving the second message and the second timestamp, the MAC layer function module 2 decodes the second message to obtain the first message. Furthermore, the MAC layer function module 2 may identify whether the type of the first message is the first type. If the type of the first message is the first type, the MAC layer function module 2 may send the first message and the second timestamp to the fourth function module.
[0149] Optionally, if the MAC layer function module 2 identifies that the first message is not a message of the first type, the MAC layer function module 2 may send the first message to a fourth function module and discard the second timestamp.
[0150] In one example, the first message may be a synchronization message, the first timestamp may be the aforementioned timestamp T1, and the second timestamp is the aforementioned timestamp T2.
[0151] Optionally, the above method further comprises the following steps:
[0152] S607: The second function module of the first communication device sends second request information to the first function module, and the second request information is used to request the start of encryption / decryption of the message. In response, the first function module receives the second request information.
[0153] S608: The first functional module sends first request information to the second communication device based on the second request information, where the first request information is used to request capability information of the second communication device.
[0154] It should be understood that S607 is an optional step. In other words, the first functional module may send the first request information to the second communication device based on the second request information, or the first functional module may actively send the first request information to the second communication device.
[0155] S609: The fourth function module of the second communication device sends capability information of the second communication device to the first communication device based on the first request information.
[0156] S610: A first functional module of a first communication device receives capability information of a second communication device and sends first notification information to the second communication device, where the first notification information notifies the second communication device of the start of encryption / decryption of a message.
[0157] For example, after receiving the capability information of the second communication device, if both the first communication device and the second communication device determine that they support encryption / decryption of a message, the first functional module of the first communication device may determine to start encryption / decryption of the message and send first notification information to the fourth functional module of the second communication device. After receiving the first notification information, the fourth functional module may send second notification information to the third functional module, where the second notification information notifies the third functional module of the start of encryption / decryption of the message. Optionally, the first functional module may further send third notification information to the second functional module, where the third notification information notifies the second functional module to start encryption / decryption of the message. Then, the second functional module of the first communication device and the third functional module of the second communication device may perform an encryption / decryption negotiation procedure to subsequently encrypt / decrypt the message.
[0158] According to the above method, from the perspective of the clock synchronization message transmitting side, the first functional module on the transmitting side may send the message and its indication information to the second functional module. After the MAC functional module in the second functional module encrypts the message, the timestamp functional module in the second functional module may stamp the message based on the indication information. From the perspective of the message receiving side, the timestamp functional module in the third functional module may stamp each received message. After decrypting the message, if the obtained message is a first type message, the MAC functional module in the third functional module sends the message and the timestamp to the fourth functional module. In this way, it can be ensured that the first type message is marked with a timestamp when the message is encrypted / decrypted to help implement time synchronization between the first communication device and the second communication device.
[0159] Regarding the above-described Embodiments 1 and 2, the following will be understood.
[0160] (1) The above focuses on the differences between Embodiment 1 and Embodiment 2. For content other than the differences, Embodiment 1 and Embodiment 2 may be mutually referenced. In addition, different implementation forms or different examples of the same embodiment may be mutually referenced.
[0161] (2) Note that the step numbers in the flowcharts described in the first and second embodiments are merely examples of how to execute procedures and do not limit the order in which the steps are executed. In the embodiments of the present application, there is no strict execution order between steps that do not have chronological dependency on each other. Not all steps shown in the flowcharts are necessarily required steps. Some steps may be deleted from the flowcharts according to actual requirements, or other possible steps may be added to the flowcharts according to actual requirements.
[0162] The above mainly describes the solutions provided in the embodiments of the present application from the perspective of the interaction between the first communication device and the second communication device. It should be understood that, to implement the aforementioned functions, the first communication device and the second communication device may include corresponding hardware structures and / or software modules for performing the functions. Those skilled in the art should easily recognize that, in combination with the example units and algorithm steps described in the embodiments disclosed herein, the embodiments of the present application may be implemented by hardware or a combination of hardware and computer software. Whether the functions are performed by hardware or hardware driven by computer software depends on the specific application and design constraints of the technical solution. Those skilled in the art may implement the described functions using various methods for each specific application, but such implementations should not be considered to go beyond the scope of the present application.
[0163] In the embodiment of the present application, the first communication device and the second communication device may be divided into functional units based on the above-mentioned method example. For example, each functional unit may be obtained by dividing based on the corresponding function, or two or more functions may be integrated into one unit. The integrated unit may be implemented in the form of hardware or in the form of a software functional unit.
[0164] 7 is a block diagram of a possible example of an apparatus according to an embodiment of the present application. As shown in FIG. 7, the apparatus 700 may include a processing unit 702 and a communication unit 703. The processing unit 702 is configured to control and manage operation of the apparatus 700. The communication unit 703 is configured to support communication between the apparatus 700 and another device. Optionally, the communication unit 703, also referred to as a transceiver unit, may include a receiving unit and / or a transmitting unit configured to perform receiving and transmitting operations, respectively. The apparatus 700 may further include a storage unit 701 configured to store program codes and / or data of the apparatus 700.
[0165] The device 700 may be the first communication device in the above-described embodiments, or may be a component (e.g., a software module, a hardware circuit, a chip, or a combination of a software module and a hardware circuit or chip) located in the first communication device. The processing unit 702 may support the device 700 in performing the operations of the first communication device in the above-described example method. Alternatively, the processing unit 702 may mainly perform the internal operations of the first communication device in the example method, and the communication unit 703 may support communication between the device 700 and another device.
[0166] For example, in one embodiment, the processing unit 702 is configured to encrypt a first message to obtain a second message, and the communication unit 703 is configured to transmit the second message and a first timestamp, where the first timestamp indicates the transmission time of the second message.
[0167] The device 700 may be the second communication device in the above-described embodiments, or may be a component (e.g., a software module, a hardware circuit, a chip, or a combination of a software module and a hardware circuit or chip) disposed in the second communication device. The processing unit 702 may support the device 700 in performing the operations of the second communication device in the above-described example method. Alternatively, the processing unit 702 may mainly perform the internal operations of the second communication device in the example method, and the communication unit 703 may support communication between the device 700 and another device.
[0168] In one embodiment, the communication unit 703 is configured to receive a second message and a first timestamp, where the first timestamp indicates a transmission time of the second message, and the processing unit 702 is configured to decode the second message to obtain the first message.
[0169] It should be understood that the division into units within the device is merely a logical division of function. In actual implementation, all or some of the units may be integrated into one physical entity or physically separated. In addition, all units in the device may be implemented in the form of software called by a processing element, or in the form of hardware, or some units may be implemented in the form of software called by a processing element and some units may be implemented in the form of hardware. For example, each unit may be a separately located processing element or may be integrated into a chip of the device for implementation. In addition, each unit may alternatively be stored in memory in the form of a program to be called by a processing element of the device to perform the function of the unit. In addition, all or some of the units may be integrated together or implemented independently. The processing element in this specification may also be called a processor and may be an integrated circuit having signal processing capabilities. In the implementation process, the above-mentioned method or the operations in the above-mentioned units may be implemented by using a hardware integrated logic circuit in the processor element or may be implemented in the form of software called by the processing element.
[0170] In one example, a unit in any one of the aforementioned devices may be one or more integrated circuits configured to perform the aforementioned method, such as one or more application specific integrated circuits (ASICs), one or more microprocessors (digital signal processors (DSPs)), one or more field programmable gate arrays (FPGAs), or a combination of at least two of these forms of integrated circuits. As another example, when a unit in an apparatus may be implemented in the form of a program scheduled by a processing element, the processing element may be a processor, such as a general-purpose central processing unit (CPU) or another processor capable of calling a program. As another example, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0171] The aforementioned unit configured to receive is an interface circuit of the device and is configured to receive a signal from another device. For example, when the device is implemented using a chip, the receiving unit is an interface circuit of the chip and configured to receive a signal from another chip or device. The aforementioned unit configured to transmit is an interface circuit of the device and is configured to transmit a signal to another device. For example, when the device is implemented by a chip, the transmitting unit is an interface circuit of the chip and configured to transmit a signal to another chip or device.
[0172] 8 is a structural diagram of a communication device according to an embodiment of the present application. The communication device is configured to perform the operations of the first communication device in the foregoing embodiment.
[0173] 8, the communication device 800 may include a processor 801, a memory 802, and an interface circuit 803. The processor 801 may be configured to process communication protocols and communication data and control the communication device 800. The memory 802 may be configured to store programs and data, and the processor 801 may execute the method performed by the first communication device in the embodiment of the present application based on the program. The interface circuit 803 may be used for the communication device 800 to communicate with other devices, and the communication may be wired communication or wireless communication, or the interface circuit may be replaced by a transceiver.
[0174] Alternatively, the memory 802 may be externally connected to the communication device 800. In this case, the communication device 800 may include the interface circuit 803 and the processor 801. Alternatively, the interface circuit 803 may be externally connected to the communication device 800. In this case, the communication device 800 may include the memory 802 and the processor 801. When both the interface circuit 803 and the memory 802 are externally connected to the communication device 800, the communication device 800 may include the processor 801.
[0175] The communication device shown in Fig. 8 can implement the processes related to the first communication device in the above-mentioned method embodiments. The operations and / or functions of the modules in the communication device shown in Fig. 8 are respectively used to implement the corresponding procedures in the above-mentioned method embodiments. For details, please refer to the descriptions in the above-mentioned method embodiments. To avoid repetition, detailed descriptions will be omitted here as appropriate.
[0176] 9 is a structural diagram of a communication device according to an embodiment of the present application. The communication device is configured to perform the operations of the second communication device in the above embodiment.
[0177] 9, the communication device 900 may include a processor 901, a memory 902, and an interface circuit 903. The processor 901 may be configured to process communication protocols and communication data and control the communication device 900. The memory 902 may be configured to store programs and data, and the processor 901 may execute the method performed by the second communication device in the embodiment of the present application based on the program. The interface circuit 903 may be used for the communication device 900 to communicate with other devices, and the communication may be wired communication or wireless communication, or the interface circuit may be replaced by a transceiver.
[0178] Alternatively, the memory 902 may be externally connected to the communication device 900. In this case, the communication device 900 may include the interface circuit 903 and the processor 901. Alternatively, the interface circuit 903 may be externally connected to the communication device 900. In this case, the communication device 900 may include the memory 902 and the processor 901. When both the interface circuit 903 and the memory 902 are externally connected to the communication device 900, the communication device 900 may include the processor 901.
[0179] The communication device shown in Fig. 9 can perform the processes related to the second communication device in the above-mentioned method embodiments. The operations and / or functions of the modules in the communication device shown in Fig. 9 are respectively used to perform the corresponding procedures in the above-mentioned method embodiments. For details, please refer to the descriptions in the above-mentioned method embodiments. To avoid repetition, detailed descriptions will be omitted here as appropriate.
[0180] In the embodiments of the present application, the terms "system" and "network" may be used interchangeably. "At least one" means one or more, and "multiple" means two or more. The term "and / or" describes an association relationship between related objects and indicates that three relationships may exist. For example, A and / or B can indicate the following three cases: when only A is present, when both A and B are present, and when only B is present, and A and B may be singular or plural. The character " / " generally indicates an "or" relationship between related objects. "At least one of the following items (moieties)" or similar expressions indicates any combination of these items, including a single item (moiety) or any combination of multiple items (moieties). For example, "at least one of A, B, or C" may be understood to include A, B, C, AB, AC, BC, or ABC, and "at least one of A, B, and C" may be understood to include A, B, C, AB, AC, BC, or ABC. Additionally, unless otherwise specified, ordinal numbers such as "first" and "second" in the embodiments of this application are used to distinguish between multiple objects, but are not used to limit the order, chronology, priority, or importance of the multiple objects.
[0181] Those skilled in the art will understand that the embodiments of the present application may be provided as a method, a system, or a computer program product. Thus, the present application may use hardware-only embodiments, software-only embodiments, or embodiments having a combination of software and hardware. In addition, the present application may use the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, magnetic disk memory, optical memory, etc.) that contain computer-usable program code.
[0182] This application has been described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to this application. It will be understood that computer program instructions can be used to implement each procedure and / or each block of the flowcharts and / or block diagrams, and combinations of the procedures and / or blocks of the flowcharts and / or block diagrams. The computer program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or another programmable data processing device to create a machine, whereby the instructions, executed by the processor of the computer or another programmable data processing device, create an apparatus for performing the particular function(s) in one or more procedures of the flowcharts and / or one or more blocks of the block diagrams.
[0183] The computer program instructions may alternatively be stored in a computer-readable memory that can instruct a computer or another programmable data processing device to act in a specific manner, such that the instructions stored in the computer-readable memory create an artefact that includes an instruction apparatus that implements a particular function of one or more steps of the flowcharts and / or one or more blocks of the block diagrams.
[0184] The computer program instructions may alternatively be loaded into a computer or other programmable data processing device, such that a sequence of operations and steps are performed on the computer or other programmable device, thereby generating a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing a particular function in one or more procedures of the flowcharts and / or one or more blocks of the block diagrams.
[0185] It is apparent that those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Therefore, the present application intends to cover these modifications and variations of the present application if they fall within the scope of the claims of the present application and their equivalent technologies. [Explanation of symbols]
[0186] 700 equipment 701 Storage Unit 702 Processing Unit 703 Communication Unit 800 Communication Equipment 801 processor 802 memory 803 Interface Circuit 900 Communication Equipment 901 processor 902 memory 903 Interface Circuit
Claims
1. A communication method, the method being applied on a first communication device side, the method comprising: receiving capability information, the capability information indicating that the second communication device supports encryption / decryption of the first message; encrypting the first message to obtain a second message; transmitting the second message and a first timestamp, the first timestamp indicating a transmission time of the second message; A communication method comprising:
2. The method of claim 1 , wherein the first message type is a first type.
3. The method comprises: encrypting the third message to obtain a fourth message; transmitting the fourth message, wherein the type of the third message is the second type; The method of claim 2 further comprising:
4. The method comprises: sending notification information, the notification information informing the second communication device to begin encryption / decryption of a message; 4. The method of claim 1, further comprising:
5. The method comprises: transmitting request information, the request information being used to request the capability information of the second communication device; 5. The method of claim 1, further comprising:
6. The method comprises: determining that the first communication device supports encryption / decryption of the message; 6. The method of claim 1, further comprising:
7. A communication method, the method being applied on a second communication device side, the method comprising: sending capability information, the capability information indicating that the second communication device supports encryption / decryption of a first message; receiving a second message and a first timestamp, the first timestamp indicating a transmission time of the second message; decrypting the second message to obtain the first message; A communication method comprising:
8. The method of claim 7 , wherein the first message type is a first type.
9. The method comprises: stamping the second message to obtain a second timestamp, the second timestamp indicating a time of receipt of the second message; 9. The method of claim 7 or 8, further comprising:
10. The method comprises: receiving a fourth message; decrypting the fourth message to obtain a third message, the third message being of a second type; 10. The method of claim 7, further comprising:
11. The method comprises: stamping the fourth message to obtain a third timestamp, the third timestamp indicating a time of receipt of the fourth message; discarding the third timestamp after determining that the type of the third message is the second type; The method of claim 10 further comprising:
12. The method comprises: receiving notification information, the notification information informing the second communication device to begin encrypting / decrypting a message; 12. The method of claim 7, further comprising:
13. The method comprises: receiving request information, the request information being used to request the capability information of the second communication device; 13. The method of any one of claims 7 to 12, further comprising:
14. A communication method, the method being applied to a first functional module side in a first communication device, the method comprising: sending a first message and indication information of the first message, the indication information indicating that the first message needs to be stamped; receiving a first timestamp, the first timestamp indicating a transmission time of the first message; A communication method comprising:
15. A communication method, the method being applied to a second functional module in a first communication device, the method comprising: receiving a first message and indication of the first message, the indication indicating that the first message needs to be stamped; encrypting the first message to obtain a second message and sending the second message; stamping the second message to obtain a first timestamp and transmitting the first timestamp, the first timestamp indicating a transmission time of the second message; A communication method comprising:
16. A communication method, the method being applied to a third functional module in a second communication device, the method comprising: receiving a second message; stamping the second message to obtain a second timestamp, the second timestamp indicating a time of receipt of the second message; decrypting the second message to obtain a first message; transmitting the first message and the second timestamp; A communication method comprising:
17. A communication device comprising a unit configured to perform the method according to any one of claims 1 to 6.
18. A communications device comprising a processor, the processor coupled to a memory, the processor configured to perform the method of any one of claims 1 to 6.
19. A communication device comprising a unit configured to perform the method according to any one of claims 7 to 13.
20. A communications device comprising a processor, coupled to a memory, the processor configured to perform a method according to any one of claims 7 to 13.
21. A communication system comprising a communication device according to claim 17 or 18 and a communication device according to claim 19 or 20.
22. A communication device comprising a unit configured to perform the method according to claim 14.
23. A communications device comprising a processor, the processor coupled to a memory, the processor configured to perform the method of claim 14.
24. A communication device comprising a unit configured to perform the method of claim 15.
25. 16. A communications device comprising a processor, the processor coupled to a memory, the processor configured to perform the method of claim 15.
26. A communication device comprising a unit configured to perform the method of claim 16.
27. 17. A communications device comprising a processor, the processor coupled to a memory, the processor configured to perform the method of claim 16.
28. comprising a communication device according to claim 22 or 23 and a communication device according to claim 24 or 25, or A communication device comprising: a communication device according to claim 22 or 23; a communication device according to claim 24 or 25; and a communication device according to claim 26 or 27. Communication system.
29. 17. A computer-readable storage medium, the storage medium storing a computer program or instructions which, when executed by a computer, perform the method of any one of claims 1 to 16.
30. A computer program which, when read and executed by a computer, enables the computer to carry out the method of any one of claims 1 to 16.
Citation Information
Patent Citations
Clock synchronization method, device and equipment in packet network
CN102064933A
Synchronized method and device of encrypted messages between each other
CN103118029A
Method and apparatus for distributing keys for the PTP protocol
JP2014504826A
Terminal device, core network node, base station, security gateway, device, method, program, and recording medium
WO2018084081A1
Terminal registration system and terminal registration method
WO2020036070A1