Communication method and communication device

The method reorders service data packets using existing security tunnel receiving ends to manage sequence numbers, addressing deployment challenges and packet delays in network security protocols.

JP2026502250APending Publication Date: 2026-01-21HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025538516
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-12-30
Publication Date
2026-01-21

Smart Images

  • Figure 2026502250000001_ABST
    Figure 2026502250000001_ABST
Patent Text Reader

Abstract

[0013] The present application provides a communication method and a communication device. The method includes: a security tunnel receiving end determines first information, the first information indicating a security protocol header sequence number of a service data packet received by the security tunnel receiving end; and the security tunnel receiving end transmits the service data packet based on the first information. According to the method provided in the present application, reordering of service data packets can be implemented without adding a new protocol, so as to reduce the deployment cost of the reordering function.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] TECHNICAL FIELD Embodiments of the present application relate to the field of communications, and in particular to a communication method and a communication device. [Background technology]

[0002] Because human society depends on communication and worries about network threats, network security protocols are widely applied in network communication scenarios. Packet security protocols can provide confidentiality, integrity, and source authentication protection for packets. Integrity protection includes connectionless integrity protection (i.e., a single packet cannot be tampered with) and partial-sequence integrity protection (i.e., the arrival of duplicate packets is detected and the duplicate packets are discarded). However, security protocols do not provide the ability to reorder data packets. Summary of the Invention [Means for solving the problem]

[0003] The embodiments of the present application provide a communication method and a communication device so that reordering of service data packets can be implemented without any newly added protocol, in order to reduce the deployment cost of the reordering function.

[0004] According to a first aspect, there is provided a communication method, the communication method including: a security tunnel receiving end determining first information, the first information indicating a security protocol header sequence number of a service data packet received by the security tunnel receiving end; and the security tunnel receiving end transmitting the service data packet based on the first information.

[0005] According to the method provided in the embodiment of the present application, reordering of service data packets can be implemented without any newly added protocol, so as to reduce the deployment cost of the reordering function.

[0006] Referring to the first aspect, in some implementation forms of the first aspect, the security tunnel receiving end sending a service data packet based on the first information includes:

[0007] The security tunnel receiving end transmits the service data packet based on the security protocol sequence number of the service data packet indicated by the first information being an expected sequence number, or the security tunnel receiving end buffers the service data packet based on the security protocol sequence number of the service data packet indicated by the first information not being an expected sequence number.

[0008] Referring to the first aspect, in some implementation forms of the first aspect, the security tunnel receiving end sending a service data packet based on the first information includes:

[0009] Based on the fact that the security protocol sequence number of the service data packet indicated by the first information is not the expected sequence number and the buffer is full, the security tunnel receiving end transmits the buffered service data packets sequentially and buffers the currently received service data packet.

[0010] It should be noted that when the sequence number of the service data packet received by the security tunnel receiving end is not the expected sequence number and the buffer is full, if a service data packet with a sequence number smaller than that of the currently received service data packet is buffered, the buffered service data packet with the smallest sequence number may be transmitted, and the currently received service data packet is buffered. If the currently received service data packet is already the service data packet with the smallest sequence number, the currently received service data packet is transmitted.

[0011] According to a second aspect, there is provided a communication device comprising a unit configured to perform the steps of the communication method according to the first aspect and an implementation of the first aspect.

[0012] In one design, the communications device is a communications chip, which may include an input circuit or interface configured to transmit information or data and an output circuit or interface configured to receive information or data.

[0013] In another design, the communication apparatus is a communication device (e.g., a terminal device), and the communication chip may include a transmitting machine configured to transmit information and a receiving machine configured to receive information or data.

[0014] According to a third aspect, there is provided a communication device including a processor and a memory, wherein the memory is configured to store a computer program, and the processor is configured to call the computer program from the memory and run the computer program to enable the communication device to perform the method according to the first aspect and an implementation form of the first aspect.

[0015] Optionally, there are one or more processors and one or more memories.

[0016] Optionally, the memory may be integrated with the processor, or the memory may be located separately from the processor.

[0017] Optionally, the communication device further includes a transmitting machine (ie, transmitter) and a receiving machine (ie, receiver).

[0018] According to a fourth aspect, there is provided a computer program product. The computer program product includes a computer program (which may also be referred to as code or instructions). When the computer program is executed, the computer is enabled to perform a communication method according to any one of the first to fourth aspects and implementation forms of each of the first to fourth aspects.

[0019] According to a fifth aspect, there is provided a communication system, the system including at least one device configured to perform the method according to the first aspect and each implementation of the first aspect.

[0020] Optionally, the communication system further includes at least one apparatus configured to perform the method according to the second aspect and each implementation of the second aspect.

[0021] Optionally, the communication system further includes at least one apparatus configured to perform the method according to the third aspect and each implementation of the third aspect.

[0022] According to a sixth aspect, there is provided a chip system including a memory and a processor, wherein the memory is configured to store a computer program, and the processor is configured to call the computer program from the memory and run the computer program to enable a communication device in which the chip system is installed to perform a method according to any one of the aforementioned aspects and implementations of the aforementioned aspects.

[0023] The chip system may include an input circuit or interface configured to transmit information or data, and an output circuit or interface configured to receive information or data. [Brief explanation of the drawings]

[0024] [Figure 1] FIG. 1 is a diagram of a system architecture according to an embodiment of the present application. [Figure 2] FIG. 2 is a diagram of a Sequence Number field in the IPsec protocol according to an embodiment of the present application. [Figure 3] FIG. 2 is a diagram of an AH field according to an embodiment of the present application. [Figure 4] FIG. 2 is a diagram of a PN field in a MACsec protocol according to an embodiment of the present application. [Figure 5] FIG. 1 is a diagram of an example of a communication method according to an embodiment of the present application. [Figure 6] FIG. 10 is a diagram of another example of a communication method according to an embodiment of the present application. [Figure 7] FIG. 10 is a diagram of another example of a communication method according to an embodiment of the present application. [Figure 8] FIG. 10 is a diagram of another example of a communication method according to an embodiment of the present application. [Figure 9] 1 is a diagram of an example of a communication device according to an embodiment of the present application; [Figure 10] FIG. 2 is a diagram of another example of a communication device according to an embodiment of the present application. [Figure 11] FIG. 2 is a diagram of another example of a communication device according to an embodiment of the present application. DETAILED DESCRIPTION OF THE INVENTION

[0025] The following describes the technical solutions of the embodiments of the present application with reference to the accompanying drawings.

[0026] The technical solutions of the embodiments of the present application may be applied to various communication systems, such as a Global System for Mobile communication (GSM) system, a Code Division Multiple Access (CDMA) system, a Wideband Code Division Multiple Access (WCDMA) system, a General Packet Radio Service (GPRS), a Long Term Evolution (LTE) system, an LTE Frequency Division Duplex (FDD) system, an LTE Time Division Duplex (TDD) system, a Universal Mobile Telecommunication System (UMTS), a Worldwide Interoperability for Microwave Access (WiMAX) communication system, and a 5th Generation (5G) system or a New Radio (NR) system.

[0027] The terminal device in the embodiments of the present application may be referred to as user equipment, access terminal, subscriber unit, subscriber station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user equipment. The terminal device may alternatively be a mobile phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA), a handheld device with wireless communication capabilities, a computing device or another processing device connected to a wireless modem, an in-vehicle device, a wearable device, a terminal device in a 5G network, a terminal device in a future evolved Public Land Mobile Network (PLMN), etc. This is not limited in the embodiments of the present application.

[0028] The network device in the embodiments of the present application may be a device configured to communicate with a terminal device. The network device may be a base transceiver station (BTS) in a Global System for Mobile communications (GSM) or Code Division Multiple Access (CDMA) system, a Node B (NB) in a Wideband Code Division Multiple Access (WCDMA) system, an Evolutional Node B (eNB or eNodeB) in an LTE system, or a radio controller in a Cloud Radio Access Network (CRAN) scenario. Alternatively, the network device may be a relay station, an access point, an in-vehicle device, a wearable device, a network device in a 5G network, a network device in an evolved PLMN network, etc. This is not limited in the embodiments of the present application.

[0029] 1 is a diagram of a system architecture according to an embodiment of the present application. As shown in FIG. 1, the embodiment of the present application may be applied to a secure networking scenario. The system includes:

[0030] Security tunnel sending / receiving end: The security tunnel sending / receiving end is mainly used to deploy security protocols to realize encryption, integrity protection, and source authentication functions, and may be an O-RU, O-DU, or O-CU that supports security functions, or may be a switch or security gateway that supports security functions, which is not limited in the embodiments of the present application.

[0031] Service Data Packets: The transmission of service data packets is usually accomplished in an encrypted manner through a security tunnel.

[0032] Security Tunnel Header: A security tunnel header is sometimes referred to as a header field of a network security protocol. For example, the ESP (Encapsulating Security Payload) header, the AH (Authentication Header), and the MACsec (Media Access Control Security) header all contain a sequence number field.

[0033] Service transmitting end / receiving end: The service transmitting end / receiving end includes, but is not limited to, an O-CU device, an O-DU device, and an O-RU device, which is not limited in the embodiments of the present application.

[0034] The scenarios in the embodiments of the present application include, but are not limited to, a scenario in which the security tunnel receiving end and the service receiving end are a unified device.

[0035] The security protocol in the embodiment of the present application includes, but is not limited to, AH, ESP, MACsec, or another security protocol that carries ascending or descending sequence numbers. Note that in the embodiment of the present application, an example in which the security protocol carries ascending sequence numbers is used for explanation, but the case in which the security protocol carries other sequences is not limited.

[0036] Below we describe some typical security protocols.

[0037] 1. IPsec Protocol FIG. 2 shows the Sequence Number field in the IPsec protocol.

[0038] 2. AH Protocol FIG. 3 shows the fields in the AH protocol.

[0039] 3. MACsec Protocol FIG. 4 shows the PN field in the MACsec protocol.

[0040] 5 is an example of a communication method according to an embodiment of the present application. As shown in FIG. 5, the method 500 includes the following steps:

[0041] S510: The security tunnel receiving end determines first information, where the first information indicates a security protocol header sequence number of a service data packet received by the security tunnel receiving end.

[0042] Specifically, the first information indicates the security protocol header sequence number of the service data packet received by the security tunnel receiving end, so that the security tunnel receiving end can determine whether to send the service data packet based on the security protocol header sequence number of the service data packet.

[0043] S520: The security tunnel receiving end sends a service data packet based on the first information.

[0044] In a possible embodiment, if the security tunnel receiving end determines based on the first information that the security protocol header sequence number of the service data packet is an expected sequence number, the security tunnel receiving end sends the current service data packet.If the security tunnel receiving end determines based on the first information that the security protocol header sequence number of the service data packet is not an expected sequence number, the security tunnel receiving end buffers the current service data packet.

[0045] It should be noted that in this case, the first information may be equivalent to the security protocol header sequence number indicated by the first information of the service data packet received by the security tunnel receiving end.

[0046] Specifically, if the sequence number of the service data packet received by the security tunnel receiving end is the expected sequence number, the security tunnel receiving end will send the service data packet, and the security tunnel receiving end may update the next expected sequence number to the current sequence number plus 1.

[0047] Specifically, if the sequence number of a service data packet received by the security tunnel receiving end is not the expected sequence number, the security tunnel receiving end will buffer the service data packet, or the security tunnel receiving end will discard the service data packet.

[0048] Optionally, if the sequence number of a service data packet received by the security tunnel receiving end is larger than the expected sequence number, the security tunnel receiving end may buffer the service data packet, and the security tunnel receiving end may update the next expected sequence number to be the same as the current expected sequence number. If the sequence numbers of the previously buffered service data packet and the currently received service data packet are consecutive and the sequence number of the currently received service data packet is the expected sequence number, all service data packets with consecutive sequence numbers are transmitted together.

[0049] For example, if the sequence number of a service data packet received by a security tunnel receiving end is 2 and the sequence number of a service data packet expected to be received by the security tunnel receiving end is 1, the security tunnel receiving end may buffer the currently received service data packet with a sequence number of 2 and still set the next expected sequence number to 1.

[0050] Optionally, if the sequence number of the service data packet received by the security tunnel receiving end is smaller than the expected sequence number, the security tunnel receiving end may forward the service data packet.

[0051] For example, if the sequence number of the service data packet received by the security tunnel receiving end is 1 and the sequence number of the service data packet expected to be received by the security tunnel receiving end is 3, the security tunnel receiving end may send the currently received service data packet with sequence number 1, and the security tunnel receiving end may update the next expected sequence number to the sequence number of the current service data packet plus 1, i.e., 2.

[0052] Optionally, if the sequence number of a service data packet received by the security tunnel receiving end is smaller than the expected sequence number, the security tunnel receiving end may discard the service data packet, and the security tunnel receiving end may set the next expected sequence number to the current expected sequence number.

[0053] For example, if the sequence number of the service data packet received by the security tunnel receiving end is 1 and the sequence number of the service data packet expected to be received by the security tunnel receiving end is 3, the security tunnel receiving end may discard the currently received service data packet, and the security tunnel receiving end may set the next expected sequence number to the current expected sequence number, i.e., 3.

[0054] In the possible embodiment described above, the buffer is not full by default.

[0055] In a possible embodiment, if the security tunnel receiving end determines based on the first information that the security protocol header sequence number of the service data packet is not the expected sequence number and the buffer is full, the security tunnel receiving end transmits the current service data packet. In this way, the service data packet will not be stuck at this node due to a buffer problem. Optionally, the security tunnel receiving end may set the next expected sequence number to the sequence number of the currently transmitted service data packet plus one. In particular, if the security protocol header sequence number of the service data packet is not the expected sequence number and the buffer is full, and the security tunnel receiving end has buffered a service data packet whose sequence number is smaller than the sequence number of the current service data packet, then the buffered service data packet with the smallest sequence number will be transmitted.

[0056] For example, if the sequence number of the service data packet expected to be received by the security tunnel receiving end is 3, the service data packet actually received by the security tunnel receiving end is 5, and the buffer is full, the security tunnel receiving end will send the current data packet with sequence number 5. If a service data packet with sequence number 4 exists in the buffer, the service data packet with sequence number 4 will be sent.

[0057] According to the method provided in this embodiment of the present application, the reordering of service data packets can be implemented without adding a new protocol, so as to reduce the deployment cost of the reordering function. In addition, when the buffer is full, the transmission process is performed regardless of whether a service data packet with an expected sequence number is received, so that the stuck of service data packets caused by the buffer problem can be avoided.

[0058] 6 is another example of a communication method according to an embodiment of the present application. As shown in FIG. 6, the method includes the following steps:

[0059] S610: The security tunnel receiving end performs a system initialization process and records the expected sequence number of the current service data packet.

[0060] Optionally, the expected sequence number of the service data packet may be the sequence number value of the first packet, and the sequence number value may be, but is not limited to, 0.

[0061] Specifically, the security tunnel receiving end may require a specific buffer space for buffering service data packets or buffering data packet pointers, or in other words, the buffer space is for implementing the solution in this embodiment of the present application.

[0062] S620: The security tunnel receiving end receives the service data packet and performs security processing on the service data packet.

[0063] For example, security processing may include decryption processing, anti-replay processing, ACL filtering, and the like.

[0064] S630: The security tunnel receiving end determines the first information.

[0065] Specifically, after performing security processing on the service data packet, the security tunnel receiving end obtains the content of the service data packet.

[0066] Specifically, the first information indicates the security protocol header sequence number of the service data packet received by the security tunnel receiving end.

[0067] In a possible embodiment, the security tunnel receiving end determining the first information may be the security tunnel receiving end determining that the security protocol sequence number is an expected sequence number.

[0068] In a possible embodiment, the security tunnel receiving end determining the first information may be the security tunnel receiving end determining that the security protocol sequence number is not the expected sequence number and that the buffer is full.

[0069] In a possible embodiment, the security tunnel receiving end determining the first information may be the security tunnel receiving end determining that the security protocol sequence number is not an expected sequence number and that the buffer is not full.

[0070] S640: The security tunnel receiving end sends a service data packet based on the first information.

[0071] In a possible embodiment, the security tunnel receiving end determines, based on the first information, that the security protocol sequence number of the current service data packet is an expected sequence number, and the security tunnel receiving end transmits the service data packet.

[0072] For example, if a security tunnel receiving end expects to receive a service data packet whose sequence number is 1, and the security tunnel receiving end determines based on the security protocol header sequence number that the header sequence number of the service data packet currently received by the security tunnel receiving end is 1, then the security tunnel receiving end will send the service data packet.

[0073] In a possible embodiment, the security tunnel receiving end determines, based on the first information, that the security protocol sequence number of the current service data packet is not the expected sequence number and the buffer is full, and the security tunnel receiving end transmits the service data packet, or the security tunnel receiving end transmits the buffered service data packet with the smallest sequence number.

[0074] For example, the security tunnel receiving end expects to receive a service data packet whose sequence number is 1, but the security tunnel receiving end determines, based on the security protocol header sequence number, that the header sequence number of the service data packet currently received by the security tunnel receiving end is 2. Because the buffer is full, the security tunnel receiving end sends the service data packet even though the service data packet received by the security tunnel receiving end is 2. Optionally, the sequence number of the next service data packet expected by the security tunnel receiving end may be updated to 3.

[0075] In another example, the security tunnel receiving end expects to receive a service data packet with a sequence number of 2, but the security tunnel receiving end determines, based on the security protocol header sequence number, that the header sequence number of the service data packet currently received by the security tunnel receiving end is 1. Because the buffer is full, the security tunnel receiving end transmits the service data packet even though the service data packet received by the security tunnel receiving end is 1. Optionally, the sequence number of the next service data packet expected by the security tunnel receiving end may be 2. Alternatively, because the buffer is full, the security tunnel receiving end may discard the data packet with the sequence number of 1, and the sequence number of the next service data packet expected by the security tunnel receiving end may be 2.

[0076] In one possible embodiment, the security tunnel receiving end determines based on the first information that the security protocol sequence number is not the expected sequence number and the buffer is not full, and buffers the service data packet. Furthermore, the security tunnel receiving end updates the expected sequence number to be the same as the current expected sequence number. This step is repeated until the expected sequence number matches the sequence number of the service data packet to be transmitted and the service data packet is transmitted. Alternatively, if the sequence numbers of the service data packet to be transmitted and the buffered service data packets form consecutive sequence numbers and the sequence numbers of the service data packets to be transmitted are the same as the expected sequence numbers, the series of service data packets with consecutive sequence numbers are transmitted.

[0077] It should be noted that although this embodiment of the present application is described based on the sequence numbers being arranged in ascending order, the order of the sequence numbers is not particularly limited in this embodiment of the present application.

[0078] According to the method provided in this embodiment of the present application, reordering of service data packets can be implemented without any newly added protocol, so as to reduce the deployment cost of the reordering function.

[0079] 7 is another example of a communication method according to an embodiment of the present application. As shown in FIG. 7, the method includes the following steps:

[0080] S710: The security tunnel receiving end performs a system initialization process and records the expected sequence number of the current service data packet.

[0081] Optionally, the expected sequence number of the service data packet may be the sequence number value of the first packet, and the sequence number value may be, but is not limited to, 0.

[0082] Specifically, the security tunnel receiving end may require a specific buffer space for buffering service data packets or buffering data packet pointers, or in other words, the buffer space is for implementing the solution in this embodiment of the present application.

[0083] S720: The security tunnel receiving end receives the service data packet and performs security processing on the service data packet.

[0084] For example, security processing may include decryption processing, anti-replay processing, ACL filtering, and the like.

[0085] S730: The security tunnel receiving end determines the first information.

[0086] It should be noted that step S730 is similar to step S630 in method 600. Reference can be made to the description of S630, and the details will not be described again here.

[0087] S740: When the buffer time of the security tunnel receiving end exceeds a limit, the security tunnel receiving end sends a service data packet based on the first information.

[0088] It should be noted that step S740 is similar to step S640 in method 600. Reference can be made to the description of S630, and the details will not be described again here.

[0089] It should be noted that when the buffering of service data packets by the security tunnel receiving end exceeds a certain buffer time limit, the security tunnel receiving end will perform transmission processing on the buffered service data packets, so that the transmission delay of the service data packets at the security tunnel receiving end does not exceed a preset limit, and the system delay is reduced.

[0090] According to the communication method provided in this embodiment of the present application, the reordering of service data packets can be implemented without adding any new protocol, so as to reduce the deployment cost of the reordering function, and in addition, the system delay is reduced.

[0091] 8 is another example of a communication method according to an embodiment of the present application. As shown in FIG. 8, the method includes the following steps:

[0092] S810: The security tunnel receiving end performs a system initialization process and records the expected sequence number of the current service data packet.

[0093] Optionally, the expected sequence number of the service data packet may be the sequence number value of the first packet, and the sequence number value may be, but is not limited to, 0.

[0094] Specifically, the security tunnel receiving end may require a specific buffer space for buffering service data packets or buffering data packet pointers, or in other words, the buffer space is for implementing the solution in this embodiment of the present application.

[0095] S820: The security tunnel receiving end receives the service data packet and performs security processing on the service data packet.

[0096] For example, security processing may include decryption processing, anti-replay processing, ACL filtering, and the like.

[0097] S830: The security tunnel receiving end determines the first information.

[0098] It should be noted that step S830 is similar to step S630 in method 600. Reference can be made to the description of S630, and the details will not be described again here.

[0099] S840: The sequence number of the service data packet received by the security tunnel receiving end is smaller than the expected sequence number, and the security tunnel receiving end sends the service data packet based on the first information.

[0100] It should be noted that step S840 is similar to step S640 in method 600. Reference can be made to the description of S630, and the details will not be described again here.

[0101] It should be noted that, unlike step 640, in step 840, if the sequence number of the service data packet received by the security tunnel transmitting end is smaller than the expected sequence number, the security tunnel receiving end will discard the current service data packet, so that the anti-replay function of the security tunnel receiving end is improved and the received service data packet will not be replayed.

[0102] According to the communication method provided in this embodiment of the present application, the reordering of service data packets can be implemented without adding any new protocol, so as to reduce the deployment cost of the reordering function, and the anti-replay function of the receiving end of the security tunnel is improved.

[0103] It should be noted that in the method provided in this embodiment of the present application, the opportunity to determine whether the buffer of the security tunnel receiving end is full may be at any step of the entire method. In other words, when the security tunnel receiving end determines that the buffer is full, a buffer clearing process may be performed, and the time sequence between whether the buffer is full and the service data packet reordering is not limited.

[0104] Therefore, the method provided in this embodiment of the present application provides a flexible separation deployment manner, so that functions are supported to be deployed in the manner of independent modules or independent devices.

[0105] 9 is a diagram of an example of a communication device according to an embodiment of the present application. As shown in FIG. 9, the communication device 900 may include a transceiver unit 910 and a processing unit 920.

[0106] In some embodiments, the communication device 900 may be configured to implement the functionality of a security tunnel receiving end in any one of the manners described above. For example, the communication device 900 may correspond to a security tunnel receiving end.

[0107] The communications device 900 may be a security tunnel receiving end and perform steps performed by the security tunnel receiving end in the aforementioned method embodiments. The transceiver unit 910 may be configured to assist the communications device 900 in performing communications, e.g., in performing transmission and / or reception operations performed by the security tunnel receiving end in the aforementioned method embodiments. The processing unit 920 may be configured to assist the communications device 900 in performing processing operations, e.g., in performing processing operations performed by the security tunnel receiving end in the aforementioned method embodiments.

[0108] Optionally, the communications device may further include a storage unit 930 (not shown in FIG. 9) configured to store program codes and data for the communications device.

[0109] For more details, see the description below.

[0110] The processing unit 910 is configured to determine first information, where the first information indicates a security protocol header sequence number of a service data packet of the processing unit.

[0111] The transceiver unit 920 is configured to transmit a service data packet based on the first information.

[0112] The transceiver unit transmitting the service data packet based on the first information includes:

[0113] The transceiver unit transmits the service data packet based on the security protocol sequence number of the service data packet indicated by the first information being an expected sequence number.

[0114] The transceiver unit buffers the service data packet based on the security protocol sequence number of the service data packet indicated by the first information not being an expected sequence number.

[0115] The transceiver unit transmitting the service data packet based on the first information includes:

[0116] The transceiver unit transmits the service data packet based on the security protocol sequence number indicated by the first information of the service data packet not being an expected sequence number and the buffer being full.

[0117] 10 is an example of a signal transmission device 1000 according to an embodiment of the present application. As shown in FIG. 10, the device 1000 includes a transceiver 1010, a processor 1020, and a memory 1030. The memory 1030 is configured to store instructions. The processor 1020 is coupled to the memory 1030 and is configured to execute the instructions stored in the memory to perform the methods provided in the above-mentioned embodiments of the present application.

[0118] In particular, the transceiver 1010 in the device 1000 may correspond to the transceiver unit 910 in the device 900 , and the processor 1020 in the communications device 1000 may correspond to the processing unit 920 in the communications device 900 .

[0119] It should be understood that the memory 1030 and the processor 1020 may be integrated into a processing unit, and the processor 1020 is configured to execute program code stored in the memory 1030 to achieve the above-described functions. In a specific implementation, the memory 1030 may alternatively be integrated into the processor 1020 or may be separate from the processor 1010.

[0120] 11 is a diagram of another example of a communication device according to an embodiment of the present application. The communication device may be configured to perform a method performed by a security tunnel receiving end. As shown in FIG. 11, the communication device includes: It includes at least one input interface (Input(s)) 1110, a logic circuit 1120, and at least one output interface (Output(s)) 1130. Optionally, the logic circuit may be a chip or another integrated circuit capable of performing the methods of the present application.

[0121] The input interface 1110 is configured to input or receive data. The output interface 1130 is configured to output or transmit data. The logic circuit 1120 is configured to perform the above-described possible method shown in FIG.

[0122] Those skilled in the art may recognize that, in combination with the examples described in the embodiments disclosed herein, the units and algorithm steps may be realized by electronic hardware or a combination of computer software and electronic hardware. Whether a function is performed by hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use various methods to realize the described functions for each specific application, but such realization should not be considered as going beyond the scope of this application.

[0123] For the sake of convenience and conciseness, those skilled in the art can clearly understand that the detailed operation processes of the above-mentioned systems, devices and units can be referred to the corresponding processes in the above-mentioned method embodiments, and the details will not be described again here.

[0124] In some embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods may be realized in other ways. For example, the described device embodiments are merely examples. For example, the division of units is merely a logical division of function, and other divisions may be used in actual implementation. For example, multiple units or components may be combined or integrated into another system, or some features may be omitted or not performed. In addition, the shown or described mutual couplings or direct couplings or communication connections may be realized through some interfaces. Indirect couplings or communication connections between devices or units may be realized in electronic, mechanical, or other forms.

[0125] Units described as separate parts may or may not be physically separate, and parts shown as units may or may not be physical units, and may be located in one place or distributed over multiple network units. Some or all of the units may be selected based on actual requirements to achieve the objectives of the solutions of the embodiments.

[0126] In addition, the functional units in the embodiments of the present application may be integrated into one processing unit, and each of the units may exist physically alone, or two or more units may be integrated into one unit.

[0127] When a function is implemented in the form of a software functional unit and sold or used as an independent product, the function may be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, a portion contributing to the prior art, or a portion of the technical solution may be essentially realized in the form of a software product. The computer software product is stored in a storage medium and includes some instructions that instruct a computer device (which may be a personal computer, a server, a network device, etc.) to perform all or part of the steps of the method described in the embodiments of the present application. The aforementioned storage medium includes any medium that can store program code, such as a USB flash drive, a removable hard disk drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, etc.

[0128] The above description is merely a specific implementation form of the present application and does not limit the protection scope of the present application. Any variations or replacements that can be easily conceived by those skilled in the art within the technical scope disclosed in the present application shall fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims. [Explanation of symbols]

[0129] 500 ways 600 ways 900 Communication Equipment 910 Transceiver Unit 920 Processing Unit 930 Storage Unit 1000 Signal Transmitting Device 1010 Transceiver 1020 processor 1030 memory 1110 Input Interface 1120 Logic Circuit 1130 Output Interface

Claims

1. 1. A communication method comprising: determining, by a security tunnel receiving end, first information, the first information indicating a security protocol header sequence number of a service data packet received by the security tunnel receiving end; sending the service data packet by the security tunnel receiving end based on the first information; A method comprising:

2. The step of transmitting the service data packet by the security tunnel receiving end based on the first information includes: transmitting, by the security tunnel receiving end, the service data packet based on the security protocol sequence number of the service data packet being an expected sequence number, as indicated by the first information; or buffering the service data packet by the security tunnel receiving end based on the security protocol sequence number of the service data packet being not an expected sequence number, as indicated by the first information.

2. The method of claim 1, comprising:

3. The step of transmitting the service data packet by the security tunnel receiving end based on the first information includes: transmitting the buffered service data packets by the security tunnel receiving end in sequence based on the security protocol sequence number of the service data packet being not an expected sequence number and the buffer being full, as indicated by the first information; 2. The method of claim 1, comprising:

4. A communication device, a processing unit configured to determine first information, the first information indicating a security protocol header sequence number of a service data packet of the processing unit; a transceiver unit configured to transmit the service data packet based on the first information; An apparatus comprising:

5. transmitting the service data packet based on the first information by the transceiver unit, the transceiver unit transmitting the service data packet based on the security protocol sequence number of the service data packet being an expected sequence number, as indicated by the first information; or the transceiver unit buffering the service data packet based on the first information indicating that the security protocol sequence number of the service data packet is not an expected sequence number; 5. The apparatus of claim 4, comprising:

6. transmitting the service data packet based on the first information by the transceiver unit, the transceiver unit sequentially transmits the buffered service data packets and buffers the service data packets based on the security protocol sequence number of the service data packet being not an expected sequence number and the buffer being full, as indicated by the first information; 5. The apparatus of claim 4, comprising:

7. 1. A communications device comprising at least one processor, the processor coupled to a memory; the memory is configured to store program instructions and data; 4. A communications device, wherein the processor is configured to execute the instructions in the memory to perform the method of any one of claims 1 to 3.

8. A communication device comprising a logic circuit and an input / output interface, the input / output interface is configured to input or output data or information; A communications device, wherein the logic circuitry is configured to perform the method of any one of claims 1 to 3 based on the data or information.

9. 4. A computer-readable storage medium having stored thereon computer instructions that, when executed in a computer, enable the computer to perform the method of any one of claims 1 to 3.

10. A computer program product comprising instructions, which when run on a computer, perform the method of any one of claims 1 to 3.