System message transmission method and communication device
By calculating timestamps using system frame and slot numbers, and verifying system information blocks with digital signatures, the method reduces bit usage and enhances security against fake base stations in wireless communication.
Patent Information
- Application Number
- JP2024556282
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-03-23
- Filing Date
- 2023-03-21
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2043-03-21
AI Technical Summary
Existing wireless communication technologies face challenges in reducing the number of information bits occupied by timestamps in system messages while maintaining accuracy, making them vulnerable to interception and impersonation by fake base stations.
A method where the terminal device calculates timestamps based on system frame numbers and slot numbers, reducing the need to transmit timestamps explicitly, and uses digital signatures to verify the authenticity of system information blocks.
Reduces the number of information bits required for timestamps, enhances security by minimizing the risk of interception, and improves network latency by allowing timestamp calculation at the receiving end.
Smart Images

Figure 0007791349000017 
Figure 0007791349000018 
Figure 0007791349000019
Abstract
Description
[Technical Field]
[0001] This application claims priority to Chinese Patent Application No. 202210290757.3, entitled "SYSTEM MESSAGE TRANSMISSION METHOD AND COMMUNICATION APPARATUS," filed with the State Intellectual Property Office of the People's Republic of China on March 23, 2022, which is incorporated herein by reference in its entirety.
[0002] The present application relates to the field of communication technology, and in particular to a system message transmission method and communication device. [Background technology]
[0003] In existing wireless communication technologies, a terminal device user needs to obtain some basic information about a base station in an initial network access state. The base station broadcasts system messages to the terminal device at a specified periodicity. Typically, this type of system message is called a master information block (MIB) and a system information block (SIB). The terminal device receives MIB and SIB messages sent by the base station to obtain basic information about the base station in order to complete the procedure for accessing the base station. For example, as shown in FIG. 1, in the initial state, the base station does not know when the terminal device will access the base station and cannot establish a security context between the terminal device and the base station until a connection is established between the terminal device and the base station. As a result, encryption protection cannot be performed on the MIB and SIB messages sent by the base station. In this case, the MIB and SIB messages can be easily intercepted and impersonated by a fake base station. Based on this, a fake base station can connect to the terminal device, deceive the terminal device, and steal privacy information.
[0004] To prevent repetitive attacks, the base station signs the system message and timestamp to obtain a digital signature. The base station broadcasts the system message, timestamp, and digital signature together to the terminal device. After receiving the system message, timestamp, and digital signature, the terminal device verifies the digital signature using a public key based on the base station, system message, and timestamp to determine the validity of the system message. The length of the information bits (bits) occupied by the quantized timestamp varies depending on the precision of the timestamp. A higher precision of the timestamp indicates more information bits occupied. For example, as shown in Figure 2, when the precision of the timestamp is at the second level, the timestamp needs to occupy 32 bits when the calculation starts from 1970-1-1 0:0:0 GMT (Greenwich Mean Time). When the precision of the timestamp is at the millisecond level, the timestamp needs to occupy 43 bits when the calculation starts from 1970-1-1 0:0:0 GMT. When the timestamp accuracy is at the microsecond level, and the calculation starts from 1970-1-1 0:0:0 GMT, the timestamp needs to occupy 52 bits. How to reduce the amount of information bits occupied by the timestamp while ensuring the accuracy of the timestamp is currently an urgent problem to be solved. Summary of the Invention
[0005] The embodiments of the present application provide a system message transmission method and communication device to help reduce the amount of information bits occupied by the timestamp while ensuring the accuracy of the timestamp. [Means for solving the problem]
[0006] According to a first aspect, the present application provides a system message transmission method. The method may be executed by a terminal device, by a component of the terminal device (e.g., a processor, a chip, or a chip system), or by a logic module or software capable of implementing all or part of the functions of the terminal device. The method includes:
[0007] The terminal device receives a first message sent by an access network device based on scheduling information in OSI (Other System Information) in a first SIB1 (System Information Block 1) when the system frame number is λ1 and the slot number is υ1. The first message includes the OSI and a first digital signature. The first digital signature is a signature for the OSI and timestamp t1. The timestamp t1 is an absolute point in time corresponding to the access network device when the system frame number is λ1 and the slot number is υ1. The terminal device determines the timestamp t1 based on the system frame number λ1, slot number υ1, timestamp t2, system frame number λ2, and slot number υ2. The system frame number λ2 and slot number υ2 are the system frame number and slot number to which the first SIB1 belongs. The timestamp t2 is an absolute point in time corresponding to the access network device when the system frame number is λ2 and the slot number is υ2. The terminal device verifies the first digital signature based on the OSI and timestamp t1.
[0008] According to the method described in the first aspect, the timestamp t1 does not need to be transmitted during transmission of the OSI to help reduce the number of information bits occupied by the timestamp while ensuring the accuracy of the timestamp.
[0009] In a possible implementation, before receiving by the terminal device the first message sent by the access network device based on the OSI scheduling information in the first SIB1 when the system frame number is λ1 and the slot number is υ1, the terminal device may further perform the following steps:
[0010] The terminal device receives a second message transmitted by the access network device when the system frame number is λ2 and the slot number is υ2. The second message includes a first SIB1, a timestamp t2, and a second digital signature, and the second digital signature is a signature for the first SIB1 and the timestamp t2. The terminal device determines that the first SIB1 is valid based on the first SIB1, the timestamp t2, and the second digital signature.
[0011] Based on a possible implementation, when the first SIB1 is sent, the timestamp t2 corresponding to the first SIB1 still needs to be sent. Therefore, the protocol is slightly modified to facilitate implementation.
[0012] In a possible implementation, before receiving by the terminal device the first message sent by the access network device based on the OSI scheduling information in the first SIB1 when the system frame number is λ1 and the slot number is υ1, the terminal device may further perform the following steps:
[0013] The terminal device receives a second message sent by the access network device when the system frame number is λ2 and the slot number is υ2. The second message includes a first SIB1 and a second digital signature. The second digital signature is a signature for the first SIB1 and timestamp t2. The terminal device obtains timestamp t3. The timestamp t3 is an absolute point in time corresponding to the access network device when the system frame number is 0 and the slot number is 0. The terminal device determines timestamp t2 based on timestamp t3, the system frame number λ2, and the slot number υ2. The terminal device determines that the first SIB1 is valid based on the first SIB1, timestamp t2, and the second digital signature.
[0014] Based on a possible implementation, the timestamp t2 does not need to be transmitted during the transmission of the first SIB1 to help reduce the amount of information bits occupied by the timestamp while ensuring the accuracy of the timestamp.
[0015] In a possible implementation, before the terminal device receives the second message sent by the access network device, the terminal device may further perform the following steps:
[0016] The terminal device receives a third message sent by the access network device when the system frame number is 0 and the slot number is 0. The third message includes a second SIB1, a timestamp tx, a difference Δ, and a third digital signature. The third digital signature is a signature for the second SIB1 and the timestamp t3. The terminal device determines the timestamp t3 based on the timestamp tx and the difference Δ.
number
[0017] The second message further includes a timestamp tx, and a specific implementation of obtaining the timestamp t3 by the terminal device is as follows:
[0018] The terminal device obtains the difference Δ from the storage space. The terminal device determines a timestamp t3 based on the timestamp tx and the difference Δ.
[0019] Based on a possible implementation, when the first SIB1 is transmitted, the timestamp t3 is not transmitted directly, but the timestamp tx and the difference Δ are transmitted, so that the terminal device determines the timestamp t3 based on the timestamp tx and the difference Δ. The information bits occupied by the timestamp tx and the difference Δ are much fewer than the information bits occupied by the timestamp t3. This facilitates reducing the number of information bits occupied by the timestamps. In addition, by storing the difference Δ, the terminal device can determine the timestamp t3 when it receives a second message carrying the timestamp tx. This facilitates reducing network latency.
[0020] In one possible implementation, before the terminal device receives a second message sent by the access network device when the system frame number is λ2 and the slot number is υ2, the terminal device may further perform the following steps:
[0021] The terminal device receives a third message sent by the access network device when the system frame number is 0 and the slot number is 0. The third message includes a second SIB1, a timestamp tx, a difference Δ, and a third digital signature. The third digital signature is a signature for the second SIB1 and the timestamp t3. The terminal device determines the timestamp t3 based on the timestamp tx and the difference Δ.
number
[0022] A specific implementation form of obtaining the timestamp t3 by the terminal device is as follows: The terminal device obtains the timestamp tx and the difference Δ from the storage space; The terminal device determines the timestamp t3 based on the timestamp tx and the difference Δ.
[0023] According to a possible implementation, when the first SIB1 is transmitted, the timestamp t3 is not transmitted directly, but the timestamp tx and the difference Δ are transmitted, so that the terminal device determines the timestamp t3 based on the timestamp tx and the difference Δ. The information bits occupied by the timestamp tx and the difference Δ are much smaller than the information bits occupied by the timestamp t3. This facilitates reducing the number of information bits occupied by the timestamps. In addition, by storing the timestamp tx and the difference Δ, the terminal device can determine the timestamp t3 after receiving the first SIB1, even if the timestamp tx and the difference Δ are not subsequently received. This facilitates reducing network latency.
[0024] In a possible implementation, the distribution periodicity of the timestamp tx and / or the difference Δ is configured by the network device or is pre-specified in a protocol. If the network device configures the distribution periodicity of the timestamp tx and / or the difference Δ, the distribution periodicity of the timestamp tx and / or the difference Δ may be more flexible. If the distribution periodicity of the timestamp tx and / or the difference Δ is pre-specified in a protocol, network overhead may be reduced.
[0025] In a possible implementation, the timestamp t1 satisfies the following equation: t1=t2+(λ1-λ2)*10+(υ1-υ2)*α
[0026] The timestamp t1 is expressed in milliseconds, and α is the time length of one slot, also expressed in milliseconds.
[0027] Depending on the possible implementation, the timestamp t1 can be determined accurately.
[0028] In a possible implementation, the timestamp t2 satisfies the following equation: t2=t3+λ2*10+υ2*α
[0029] The timestamp t2 is expressed in milliseconds, and α is the time length of one slot, also expressed in milliseconds.
[0030] Depending on the possible implementation, the timestamp t2 can be determined accurately.
[0031] According to a second aspect, the present application provides a system message transmission method. The method may be performed by an access network device, or by a component (e.g., a processor, a chip, or a chip system) of the access network device, or by a logic module or software capable of implementing all or part of the functionality of the access network device. The method includes:
[0032] The access network device generates a first digital signature. The first digital signature is a signature over OSI (other system information) and timestamp t1. The timestamp t1 is an absolute point in time corresponding to the access network device when the system frame number is λ1 and the slot number is υ1. The access network device transmits a first message to the terminal device when the system frame number is λ1 and the slot number is υ1. The first message includes the OSI and the first digital signature. The first message does not include the timestamp t1.
[0033] In a possible implementation, before the access network device generates the first digital signature, the access network device may further transmit a second message to the terminal device when the system frame number is λ2 and the slot number is υ2. The second message includes a first system information block 1 (SIB1), a timestamp t2, and a second digital signature. The second digital signature is a signature of the first SIB1 and the timestamp t2. The timestamp t2 is an absolute point in time corresponding to the access network device when the system frame number is λ2 and the slot number is υ2. The first SIB1 includes OSI scheduling information.
[0034] In a possible implementation, before the access network device generates the first digital signature, the access network device may further transmit a second message to the terminal device when the system frame number is λ2 and the slot number is υ2. The second message includes a first SIB1 (System Information Block 1) and a second digital signature. The second digital signature is a signature of the first SIB1 and a timestamp t2. The timestamp t2 is an absolute point in time corresponding to the access network device when the system frame number is λ2 and the slot number is υ2. The second message does not include the timestamp t2. The first SIB1 includes OSI scheduling information.
[0035] In a possible implementation, the access network device may further transmit a third message to the terminal device when the system frame number is 0 and the slot number is 0. The third message includes a second SIB1, a timestamp tx, a difference Δ, and a third digital signature. The third digital signature is a signature for the second SIB1 and a timestamp t3. The timestamp t3 is an absolute point in time corresponding to the access network device when the system frame number is 0 and the slot number is 0.
number
[0036] In a possible implementation, the second message further comprises a timestamp tx.
[0037] In a possible implementation, the periodicity of delivery of the timestamps tx and / or the periodicity of delivery of the difference Δ is configured by the network device or is pre-specified in a protocol.
[0038] The beneficial effects of the second aspect are described in the beneficial effects of the first aspect, and will not be described in detail here.
[0039] According to a third aspect, the present application provides a communication device. The communication device may be a terminal device, a device within a terminal device, or a device compatible with a terminal device. Alternatively, the communication device may be a chip system. The communication device may implement the method in the first aspect. The functions of the communication device may be implemented by hardware or by executing corresponding software by the hardware. The hardware or software includes one or more units or modules corresponding to the aforementioned functions. The units or modules may be software and / or hardware. For operations and beneficial effects performed by the communication device, please refer to the method and beneficial effects of the first aspect.
[0040] According to a fourth aspect, the present application provides a communication device. The communication device may be an access network device, a device within the access network device, or a device compatible with the access network device. Alternatively, the communication device may be a chip system. The communication device may perform the method of the second aspect. The functions of the communication device may be implemented by hardware or by executing corresponding software by the hardware. The hardware or software may include one or more units or modules corresponding to the aforementioned functions. The units or modules may be software and / or hardware. For operations and beneficial effects performed by the communication device, please refer to the method and beneficial effects of the second aspect.
[0041] According to a fifth aspect, the present application provides a communications device, the communications device including a processor, which, when invoked by the processor in a memory, is capable of performing the method of the first or second aspect.
[0042] According to a sixth aspect, the present application provides a communication device, the communication device including a processor and a memory, the processor coupled to the memory, the processor configured to perform a method according to the first or second aspect.
[0043] According to a seventh aspect, the present application provides a communication device. The communication device includes a processor, a memory, and a transceiver. The processor is coupled to the memory. The transceiver is configured to receive and transmit data. The processor is configured to perform a method according to the first or second aspect.
[0044] According to an eighth aspect, the present application provides a communication device, the communication device including a processor and an interface, the interface configured to receive or output a signal, the processor configured to implement a method according to the first or second aspect using logic circuits or by executing code instructions.
[0045] According to a ninth aspect, the present application provides a computer-readable storage medium, the storage medium storing a computer program or instructions, which, when executed by a communication device, performs the method of the first or second aspect.
[0046] According to a tenth aspect, the present application provides a computer program product including instructions that, when read and executed by a computer, enable the computer to perform the method of the first or second aspect. [Brief explanation of the drawings]
[0047] [Figure 1] 1 is a schematic flowchart of an existing system message transmission. [Figure 2] FIG. 1 is a diagram of existing timestamp transmission. [Figure 3] 1 is a diagram of a communication system according to the present application; [Figure 4] 1 is a schematic flowchart of a system message transmission method according to the present application; [Figure 5] FIG. 2 is a diagram of system message transmission according to the present application. [Figure 6] 1 is a schematic flowchart of a system message transmission method according to the present application; [Figure 7] FIG. 1 is a diagram of system message transmission according to the present application. [Figure 8] 1 is a schematic flowchart of a system message transmission method according to the present application; [Figure 9] FIG. 2 is a diagram of system message transmission according to the present application. [Figure 10] 1 is a schematic flowchart of a system message transmission method according to the present application; [Figure 11] FIG. 1 is a diagram of system message transmission according to the present application. [Figure 12] FIG. 2 is a diagram of system message transmission according to the present application. [Figure 13A] 1 is a schematic flowchart of a system message transmission method according to the present application; [Figure 13B] 1 is a schematic flowchart of a system message transmission method according to the present application; [Figure 14] FIG. 1 is a diagram of system message transmission according to the present application. [Figure 15] FIG. 1 is a diagram of transmission periodicity according to the present application. [Figure 16] 1 is a diagram of the structure of a communication device according to this application; [Figure 17] 1 is a diagram of the structure of a communication device according to the present application; [Figure 18] 1 is a diagram of the structure of a chip according to the present application; DETAILED DESCRIPTION OF THE INVENTION
[0048] Specific embodiments of the present application are further described below with reference to the accompanying drawings.
[0049] In the specification, claims, and accompanying drawings of this application, terms such as "first," "second," etc. are used to distinguish between different objects and do not necessarily indicate a particular order. Furthermore, the terms "include," "contain," and any variations thereof are intended to refer to a non-exclusive inclusion. For example, a process, method, system, product, or device that includes steps or units is not limited to the listed steps or units, but may optionally include additional steps or units that are not listed, or may optionally include additional steps or units that are specific to the process, method, product, or device.
[0050] It can be understood that the "embodiment" referred to in this specification means that a particular feature, structure, or characteristic described with reference to this embodiment can be included in at least one embodiment of the present application. Phrases appearing in various places in this specification may not necessarily refer to the same embodiment, and are not independent or optional embodiments that do not intersect with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described in this specification can be combined with other embodiments.
[0051] In this application, "at least one (item)" means one or more, "multiple" means two or more, "at least two (items)" means two, three, or more, and "and / or" is used to describe an associative relationship between related objects, indicating that a three-way relationship may exist. For example, "A and / or B" may indicate that only A is present, only B is present, or both A and B are present. A and B may be singular or plural. The character " / " typically indicates an "or" relationship between related subjects. "At least one of the following items (moieties)" or similar phrases refers to any combination of these items, including a singular item (moiety) or any combination of multiple items (moieties). For example, "at least one of a, b, or c" may refer to a, b, c, a and b, a and c, b and c, or a, b, and c, where a, b, and c may be singular or plural.
[0052] In order to better understand the embodiment of the present application, the system architecture in the embodiment of the present application will be described first below.
[0053] The technical solutions in the embodiments of the present application may be applied to various communication systems, such as a global system for mobile communications (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) system, a general packet radio service (GPRS) system, a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD), a universal mobile telecommunications system (UMTS), a worldwide interoperability for microwave access (WiMAX) communication system, a fifth generation (5G) system, or a new radio (NR) system, and future communication systems.
[0054] 3 is a diagram of a communication system according to an embodiment of the present application. As shown in FIG. 3, the communication system includes a terminal device 30 and an access network device 31. The number of terminal devices is merely an example, and the number of terminal devices is not particularly limited in the embodiment of the present application.
[0055] The terminal device and the access network device of FIG. 3 will be described in detail below.
[0056] 1. Terminal Device Terminal devices include devices that provide voice and / or data connectivity to users. For example, terminal devices are devices with wireless transceiver capabilities, including indoor, outdoor, handheld, wearable, or vehicle-mounted devices, and may be deployed on land, on water (e.g., on a ship), or in the air (e.g., on an airplane, balloon, or satellite). Terminal devices may be mobile phones, tablet computers, computers with wireless transceiver capabilities, virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, industrial control wireless terminals, in-vehicle terminal devices, self-driving wireless terminals, remote medical wireless terminals, smart grid wireless terminals, transportation safety wireless terminals, smart city wireless terminals, smart home wireless terminals, and wearable terminal devices. Application scenarios are not limited by the embodiments of this application. A terminal may also be called a terminal, user equipment (UE), access terminal device, vehicle-mounted terminal, industrial control terminal, UE unit, UE station, mobile station, remote station, remote terminal device, mobile device, UE terminal device, terminal device, or wireless communication device, UE proxy, UE apparatus, etc. A terminal device may be fixed or mobile.
[0057] 2. Access Network Devices An access network device is an entity configured to transmit or receive signals on the network side, including, but not limited to, a next generation NodeB (gNB), evolved NodeB (eNB), next generation evolved NodeB (ng-eNB), wireless backhaul device, radio network controller (RNC), NodeB (NB), base station controller (BSC), base transceiver station (BTS), home evolved NodeB (HeNB) or home NodeB (HNB), baseband unit (BBU), transmission reception point (TRP), transmission point (TP), mobile switching center, and tag terminal device, such as a reader, in a 5G communication system.
[0058] In order to better understand the embodiments of the present application, some technical terms in the present application are explained below.
[0059] 1. System information The system information for new radio (NR) includes the master information block (MIB) and system information blocks (SIB). SIBs other than MIB and SIB1 are called other system information (OSI). In 38.331, SIBs are classified into nine types, namely, SystemInformationBlockType1 to SystemInformationBlockType9, which are simply called SIB1, SIB2...SIBX.
[0060] The definition of broadcast messages in NR is shown in Table 1 below. [Table 1]
[0061] 2. MIB Messages In 5G communication systems, MIB messages are broadcast periodically and carried in synchronization signal blocks (SS Blocks, SSBs). SSBs include three parts: PSS (Primary Synchronization Signal), SSS (Secondary Synchronization Signal), and PBCH (Physical Broadcast Channel). MIB messages are carried in PBCHs. The PBCH payload is in the format of MIB + 1 bit + 8 bits. Since MIB messages are carried in SSBs, the transmission periodicity of MIB messages is the transmission periodicity of SSBs. The transmission periodicity of SSBs is related to factors such as subcarrier spacing and the amount of beams.
[0062] The meaning of the fields in the MIB message is shown in Table 2 below.
[0063] [Table 2]
[0064] If the terminal device receives and analyzes the SSB correctly, the processing steps are as follows:
[0065] 1. Perform frame synchronization with the access network device by detecting the PSS and SSS.
[0066] 2. Correctly decode the PBCH and obtain the MIB message from the PBCH by parsing.
[0067] 3. Get the first 6 bits of systemFrameNumber from the MIB message.
[0068] 4.Get the last 4 bits of systemFrameNumber from the PBCH payload.
[0069] 5. By combining these, a 10-bit system frame number ranging from 0 to 1023 is obtained.
[0070] 6. The calculation of the PBCH DMRS refers to the half-frame number where the PBCH is located and the SSB indication number. To perform slot-level frame synchronization with the current access network device, the terminal device may obtain the specific location where the received SSB is located within the radio frame by performing blind detection on the PBCH DMRS to obtain the slot number where the access network device transmits the SSB.
[0071] 3.SIB1 message The meaning of the fields in the SIB1 message is shown in Table 3 below.
[0072] [Table 3]
[0073] 4. OSI Scheduling Information Each SI message includes one or more OSI pieces with the same scheduling requirements (the OSI pieces have the same transmission periodicity). si-SchedulingInfo in the SIB1 message is scheduling information for the OSI. si-SchedulingInfo includes an SI message list, an SI window length, and an SI broadcast periodicity. To receive the OSI, the terminal device may determine the position of the reception time domain window for the OSI based on the SI message list, the SI window length, and the SI broadcast periodicity in si-SchedulingInfo.
[0074] 4 is a schematic flowchart of a system message transmission method according to an embodiment of the present application. FIG. 4 illustrates an example in which a terminal device and an access network device are used as the method execution entities. The execution entities of the method are not limited in the present application. For example, the terminal device or the access network device in FIG. 4 may alternatively be a chip, a chip system, or a processor that supports the terminal device or the access network device in implementing the method, or may be a logic module or software that can implement all or part of the functions of the terminal device or the access network device.
[0075] 401: An access network device generates a first digital signature, the first digital signature being a signature for an OSI and a timestamp t1.
[0076] The timestamp t1 is an absolute point in time corresponding to the access network device when the system frame number is λ1 and the slot number is υ1. The unit of the timestamp t1 may be milliseconds, or may be seconds, microseconds, etc. This is not limited in the embodiment of the present application.
[0077] Optionally, the system frame number may alternatively be referred to as the system radio frame number, occupying 10 bits and ranging from 0 to 1023. The duration of a radio frame is approximately 10 ms. The value of the system frame number λ1 can be any one of 0 to 1023.
[0078] 5G defines multiple radio frame formats. Each slot has 14 symbols. In different frame formats, the radio frame includes different numbers of slots, and the slot lengths are different. For example, the slot configuration for a normal cyclic prefix (CP) may be shown in Table 4 below, and the slot configuration for an extended CP may be shown in Table 5 below.
[0079] As shown in Tables 4 and 5 below, when the subcarrier spacing (SCS) is 15 kHz, one radio frame includes 10 slots, the slot numbers range from 0 to 9, and the value of slot number υ1 can be any one of 0 to 9.
[0080] When the SCS is 30 kHz, one radio frame includes 20 slots, the slot numbers range from 0 to 19, and the value of the slot number υ1 can be any one of 0 to 19.
[0081] When the SCS is 60 kHz, one radio frame includes 40 slots, the slot numbers range from 0 to 39, and the value of the slot number υ1 can be any one of 0 to 39.
[0082] When the SCS is 120 kHz, one radio frame includes 80 slots, the slot numbers range from 0 to 79, and the value of the slot number υ1 can be any one of 0 to 79.
[0083] When the SCS is 240 kHz, one radio frame includes 160 slots, the slot numbers range from 0 to 159, and the value of the slot number υ1 can be any one of 0 to 159.
[0084] [Table 4]
[0085] [Table 5]
[0086] A digital signature (also known as a public-key digital signature) is a digital string that can only be generated by the sender of the information and cannot be forged by others. The digital string is also a valid proof of the authenticity of the information sent by the sender of the information. A digital signature is similar to a typical physical signature written on paper and is implemented using techniques from the field of public-key cryptography and is a method used to identify digital information. A set of digital signatures usually defines two complementary operations: one for signing and one for verifying. Digital signatures are the application of asymmetric key cryptography and digital digest technology.
[0087] The access network device may process the OSI and timestamp t1 using a hash function to obtain a digest, and then encrypt the digest using the access network device's private key. The encrypted digest is a first digital signature. The access network device sends the OSI and the first digital signature to the terminal device. After the terminal device obtains the OSI, timestamp t1, and the first digital signature, the terminal device processes the OSI and timestamp t1 by using the same hash function as the access network device's hash function to obtain a digest. The terminal device decrypts the first digital signature by using the access network device's public key to obtain the digest generated by the access network device. If the digest generated by the terminal device is the same as the digest generated by the access network device, the terminal device confirms that the verification of the first digital signature was successful. The successful verification of the first digital signature indicates that the OSI has not been tampered with.
[0088] In the existing solution, the access network device needs to send the OSI, the timestamp t1, and the first digital signature together to the terminal device, so that the terminal device can process the OSI and the timestamp t1 by using the same hash function as the hash function of the access network device to obtain a digest. In order to reduce the information bits occupied by the timestamp, in the embodiment of the present application, after generating the first digital signature, the access network device only needs to send the OSI and the first digital signature to the terminal device, and does not need to send the timestamp t1 to the terminal device. The terminal device may calculate the timestamp t1, so that the information bits occupied by the timestamp can be reduced.
[0089] 402: The access network device sends a first message to the terminal device when the system frame number is λ1 and the slot number is υ1, the first message including an OSI and a first digital signature, and the first message does not include a timestamp t1.
[0090] 403: The terminal device receives a first message sent by the access network device based on OSI scheduling information in the first SIB1 when the system frame number is λ1 and the slot number is υ1.
[0091] In an embodiment of the present application, before receiving the first message, the terminal device may further receive a first SIB1 when the system frame number is λ2 and the slot number is υ2. After receiving the first SIB1, if the terminal device determines that the first SIB1 is valid, the terminal device receives a first message sent by the access network device when the system frame number is λ1 and the slot number is υ1 based on the OSI scheduling information in the first SIB1. The OSI scheduling information may be si-SchedulingInfo in the SIB1 message. The terminal device may estimate the position of the receiving time window for receiving the OSI based on information such as the OSI scheduling periodicity and the scheduling time window length in the si-SchedulingInfo.
[0092] 404: The terminal device determines a timestamp t1 based on the system frame number λ1, the slot number υ1, the timestamp t2, the system frame number λ2, and the slot number υ2.
[0093] The system frame number λ2 and slot number υ2 are the system frame number and slot number to which the first SIB1 belongs. The timestamp t2 is the absolute point in time corresponding to the access network device when the system frame number is λ2 and the slot number is υ2.
[0094] In the embodiment of the present application, the system frame number λ2 may be any one within a system frame number range, and the slot number υ2 may be any one within a slot number range. For a description of the system frame number range and the slot number range, please refer to the above description. Details will not be described here. The unit of the timestamp t2 may be milliseconds, or the unit of the timestamp t2 may be seconds, microseconds, etc. This is not limited in the embodiment of the present application.
[0095] In one possible implementation, when system frame number λ1 and system frame number λ2 are within the same system frame number periodicity, timestamp t1 satisfies the following equation: t1=t2+(λ1-λ2)*10+(υ1-υ2)*α(1)
[0096] The timestamps t1 and t2 are in milliseconds, and α is the time length of one slot. α is also in milliseconds. When the timestamps t1 and t2 are in different units, adaptive modifications may be made to equation (1).
[0097] In another possible implementation, if the system frame number λ1 and the system frame number λ2 are not in the same system frame number periodicity, equation (1) may be adjusted based on the scheduling information of the OSI in the first SIB1 to calculate the timestamp t1. For example, the maximum broadcast periodicity of the SI is 512 system frames, and the system frame number ranges from 0 to 1023. If the system frame number λ1 and the system frame number λ2 are not in the same system frame number periodicity, the difference between the system frame number λ1 and the system frame number λ2 is only one frame number periodicity, and the timestamp t1 may satisfy the following equation: t1=t2+(λ1*10+ν1*α+10240)-(λ2*10+υ2*α)(2)
[0098] The timestamps t1 and t2 are in milliseconds, and α is the time length of one slot. α is also in milliseconds. When the timestamps t1 and t2 are in different units, adaptive modifications may be made to equation (2).
[0099] 405: The terminal device verifies the first digital signature based on the OSI and the timestamp t1.
[0100] In an embodiment of the present application, the terminal device processes the OSI and timestamp t1 by using the same hash function as the hash function of the access network device to obtain a digest. The terminal device decrypts the first digital signature by using the public key of the access network device to obtain the digest generated by the access network device. If the digest generated by the terminal device is the same as the digest generated by the access network device, the terminal device confirms that the verification of the first digital signature was successful. If the digest generated by the terminal device is different from the digest generated by the access network device, the terminal device confirms that the verification of the first digital signature failed.
[0101] Optionally, after successfully verifying the first digital signature, the terminal device may further determine whether the difference between the timestamp t1 and the local time is less than a threshold value to determine whether the attack is a repeated attack. If the difference between the timestamp t1 and the local time is less than the threshold value, the terminal device determines that the received OSI message is valid.
[0102] For example, the OSI message is SIB2 / 4. As shown in FIG. 5, the access network device first generates a first digital signature based on SIB2 / 4 and timestamp t1, and then transmits SIB2 / 4 and the first digital signature to the terminal device when the system frame number is λ1 and the slot number is υ1. After receiving SIB2 / 4 and the first digital signature based on the scheduling information in the first SIB1, the terminal device determines timestamp t1 based on the system frame number λ1, slot number υ1, timestamp t2, system frame number λ2, and slot number υ2. The terminal device then verifies the first digital signature based on the OSI and timestamp t1. FIG. 5 illustrates an example in which the system frame number λ1 and the system frame number λ2 are in the same system frame number periodicity.
[0103] 4, it can be understood that after generating the first digital signature, the access network device only needs to send the OSI and the first digital signature to the terminal device, and does not need to send the timestamp t1 to the terminal device. The terminal device may calculate the timestamp t1, so that the information bits occupied by the timestamp can be reduced.
[0104] 6 is a schematic flowchart of a system message transmission method according to an embodiment of the present application. FIG. 6 illustrates an example in which a terminal device and an access network device are used as the method execution entities. The execution entities of the method are not limited in the present application. For example, the terminal device or the access network device in FIG. 6 may alternatively be a chip, a chip system, or a processor that supports the terminal device or the access network device in implementing the method, or may be a logic module or software that can implement all or part of the functions of the terminal device or the access network device.
[0105] 601: The access network device generates a second digital signature, where the second digital signature is a signature for the first SIB1 and a timestamp t2.
[0106] The timestamp t2 is the absolute point in time corresponding to the access network device when the system frame number is λ2 and the slot number is υ2.
[0107] The principle by which the access network device generates the second digital signature based on the first SIB1 and the timestamp t2 is the same as the principle by which the access network device generates the first digital signature based on the OSI and the timestamp t1, and will not be described in detail here.
[0108] 602: The access network device sends a second message to the terminal device when the system frame number is λ2 and the slot number is υ2, the second message including a first SIB1, a timestamp t2, and a second digital signature, where the first SIB1 includes OSI scheduling information. Correspondingly, when the system frame number is λ2 and the slot number is υ2, the terminal device may receive the second message sent by the access network device.
[0109] In other words, in this embodiment, the access network device transmits the first SIB1, the timestamp t2, and the second digital signature together to the terminal device.
[0110] 603: The terminal device determines that the first SIB1 is valid based on the first SIB1, the timestamp t2, and the second digital signature.
[0111] In an embodiment of the present application, the terminal device may first verify the second digital signature based on the first SIB1 and timestamp t2. If the verification of the second digital signature is successful, the terminal device may further determine whether the difference between timestamp t2 and the local time is less than a threshold to determine whether the attack is a recursive attack. If the difference between timestamp t2 and the local time is less than the threshold, the terminal device determines that the first SIB1 is valid.
[0112] For example, as shown in FIG. 7, the access network device first generates a second digital signature based on the first SIB1 and timestamp t2, and then transmits the first SIB1, timestamp t2, and second digital signature to the terminal device when the system frame number is λ2 and the slot number is υ2. After receiving the first SIB1, timestamp t2, and second digital signature, the terminal device verifies the second digital signature based on the first SIB1 and timestamp t2. If the verification of the second digital signature is successful, the terminal device may further determine whether the difference between timestamp t2 and the local time is less than a threshold to determine whether the attack is a replay attack. If the difference between timestamp t2 and the local time is less than the threshold, the terminal device determines that the first SIB1 is valid.
[0113] 604: The access network device generates a first digital signature, where the first digital signature is a signature for the OSI and timestamp t1.
[0114] The timestamp t1 is the absolute point in time corresponding to the access network device when the system frame number is λ1 and the slot number is υ1.
[0115] For specific implementation forms of steps 604 to 608, please refer to the description of the embodiment corresponding to Figure 4. Details will not be described here.
[0116] 605: The access network device sends a first message to the terminal device when the system frame number is λ1 and the slot number is υ1, where the first message includes an OSI and a first digital signature, and the first message does not include a timestamp t1.
[0117] 606: The terminal device receives a first message sent by the access network device based on OSI scheduling information in the first SIB1 when the system frame number is λ1 and the slot number is υ1.
[0118] 607: The terminal device determines a time stamp t1 based on the system frame number λ1, the slot number υ1, the time stamp t2, the system frame number λ2, and the slot number υ2.
[0119] 608: The terminal device verifies the first digital signature based on the OSI and the timestamp t1.
[0120] According to the method described in Figure 6, when the first SIB1 is sent, the timestamp t2 corresponding to the first SIB1 still needs to be sent, so the protocol is slightly modified to facilitate implementation.
[0121] 8 is a schematic flowchart of a system message transmission method according to an embodiment of the present application. FIG. 8 illustrates an example in which a terminal device and an access network device are used as performers of the method. The performers of the method are not limited in the present application. For example, the terminal device or the access network device in FIG. 8 may alternatively be a chip, a chip system, or a processor that supports the terminal device or the access network device in implementing the method, or may be a logic module or software that can implement all or part of the functions of the terminal device or the access network device.
[0122] 801: The access network device generates a second digital signature, the second digital signature being a signature for the first SIB1 and a timestamp t2.
[0123] The timestamp t2 is the absolute point in time corresponding to the access network device when the system frame number is λ2 and the slot number is υ2.
[0124] 802: The access network device sends a second message to the terminal device when the system frame number is λ2 and the slot number is υ2, the second message including the first SIB1 and the second digital signature, the second message does not include the timestamp t2, and the first SIB1 includes OSI scheduling information. Correspondingly, when the system frame number is λ2 and the slot number is υ2, the terminal device may receive the second message sent by the access network device.
[0125] In other words, in this embodiment, the access network device does not send the first SIB1, the timestamp t2, and the second digital signature together to the terminal device. The access network device sends only the first SIB1 and the second digital signature together to the terminal device. The terminal device calculates the timestamp t2.
[0126] 803: The terminal device acquires a timestamp t3.
[0127] In the embodiment of the present application, after receiving the second message, the terminal device acquires timestamp t3. The timestamp t3 is an absolute point in time corresponding to the access network device when the system frame number is 0 and the slot number is 0. The unit of the timestamp t3 may be milliseconds, or may be seconds, microseconds, etc. This is not limited in the embodiment of the present application.
[0128] For a specific method of obtaining the timestamp t3 by the terminal device, please refer to the description of the following embodiment corresponding to Figure 10 and Figure 13A and Figure 13B, and the details will not be described here.
[0129] 804: The terminal device determines a timestamp t2 based on the timestamp t3, the system frame number λ2, and the slot number υ2.
[0130] In a possible implementation, the timestamp t2 satisfies the following equation: t2=t3+λ2*10+υ2*α(3)
[0131] The timestamps t2 and t3 are in milliseconds, and α is the time length of one slot. α is also in milliseconds. When the timestamps t2 and t3 are in different units, adaptive modifications may be made to equation (3).
[0132] For example, as shown in FIG. 9, the access network device first generates a second digital signature based on the first SIB1 and timestamp t2, and then transmits the first SIB1 and the second digital signature to the terminal device when the system frame number is λ2 and the slot number is υ2. After receiving the first SIB1 and the second digital signature, the terminal device obtains timestamp t3, determines timestamp t2 based on timestamp t3, the system frame number λ2, and the slot number υ2, and then verifies the second digital signature based on the first SIB1 and timestamp t2. If the verification of the second digital signature is successful, the terminal device may further determine whether the difference between timestamp t2 and the local time is less than a threshold to determine whether the attack is a replay attack. If the difference between timestamp t2 and the local time is less than the threshold, the terminal device determines that the first SIB1 is valid.
[0133] 805: The terminal device determines that the first SIB1 is valid based on the first SIB1, the timestamp t2, and the second digital signature.
[0134] For a specific implementation of step 805, please refer to the description of the embodiment corresponding to Figure 6. Details will not be described here.
[0135] 806: The access network device generates a first digital signature, the first digital signature being a signature for the OSI and timestamp t1, where timestamp t1 is an absolute point in time corresponding to the access network device when the system frame number is λ1 and the slot number is υ1.
[0136] For specific implementation forms of steps 806 to 810, please refer to the description of the embodiment corresponding to Figure 4. Details will not be described here.
[0137] 807: The access network device sends a first message to the terminal device when the system frame number is λ1 and the slot number is υ1, where the first message includes an OSI and a first digital signature, and the first message does not include a timestamp t1.
[0138] 808: The terminal device receives a first message sent by the access network device based on OSI scheduling information in the first SIB1 when the system frame number is λ1 and the slot number is υ1.
[0139] 809: The terminal device determines a timestamp t1 based on the system frame number λ1, the slot number υ1, the timestamp t2, the system frame number λ2, and the slot number υ2.
[0140] 810: The terminal device verifies the first digital signature based on the OSI and the timestamp t1.
[0141] According to the method described in FIG. 8, the timestamp t2 does not need to be transmitted during the transmission of the first SIB1, and the terminal device calculates the timestamp t2 to help reduce the amount of information bits occupied by the timestamp while ensuring the accuracy of the timestamp.
[0142] 10 is a schematic flowchart of a system message transmission method according to an embodiment of the present application. FIG. 10 illustrates an example in which a terminal device and an access network device are used as the execution entities of the method. The execution entities of the method are not limited in the present application. For example, the terminal device or the access network device in FIG. 10 may alternatively be a chip, a chip system, or a processor that supports the terminal device or the access network device in implementing the method, or may be a logic module or software that can implement all or part of the functions of the terminal device or the access network device.
[0143] 1001: The access network device sends a third message to the terminal device when the system frame number is 0 and the slot number is 0, where the third message includes a second SIB1, a timestamp tx, a difference Δ, and a third digital signature. Correspondingly, the terminal device may receive the third message when the system frame number is 0 and the slot number is 0.
[0144] The third digital signature is a signature over the second SIB1 and timestamp t3.
number
[0145] In other words, instead of sending timestamp t3, the access network device sends timestamp tx and a difference Δ.
[0146] 1002: The terminal device determines a timestamp t3 based on the timestamp tx and the difference Δ.
[0147] In the embodiment of the present application, after receiving the third message when the system frame number is 0 and the slot number is 0, the terminal device determines the timestamp t3 based on the timestamp tx and the difference Δ.
[0148] 1003: The terminal device determines that the second SIB1 is valid based on the second SIB1, the timestamp t3, and the third digital signature.
[0149] The principle by which the terminal device determines that the second SIB1 is valid based on the second SIB1, the timestamp t3, and the third digital signature is the same as the principle by which the terminal device determines that the first SIB1 is valid based on the first SIB1, the timestamp t2, and the second digital signature, and will not be described in detail here.
[0150] For example, as shown in FIG. 11, the access network device first signs the second SIB1 and timestamp t3 to obtain the third digital signature. The access network device determines a timestamp tx and a difference Δ based on the timestamp t3. When the system frame number is 0 and the slot number is 0, the access network device transmits the second SIB1, timestamp tx, the difference Δ, and the third digital signature to the terminal device. When the system frame number is 0 and the slot number is 0, the terminal device receives the information. After receiving the information, the terminal device determines a timestamp t3 based on the timestamp tx and the difference Δ, and determines that the second SIB1 is valid based on the second SIB1, timestamp t3, and the third digital signature.
[0151] 1004: The terminal device stores the difference Δ in a storage space.
[0152] In the embodiment of the present application, the terminal device stores the difference Δ in a storage space, and then determines the timestamp t3 by using the difference Δ.
[0153] 1005: The access network device sends a second message to the terminal device when the system frame number is λ2 and the slot number is υ2, where the second message includes the first SIB1, a timestamp tx, and a second digital signature. Correspondingly, when the system frame number is λ2 and the slot number is υ2, the terminal device may receive the second message sent by the access network device.
[0154] The second digital signature is a signature of the first SIB1 and timestamp t2, which is an absolute point in time corresponding to the access network device when system frame number is λ2 and slot number is υ2. The second message does not include timestamp t2, and the first SIB1 contains OSI scheduling information.
[0155] In other words, in this embodiment, the access network device transmits only the first SIB1, the timestamp tx, and the second digital signature together to the terminal device, and the terminal device calculates the timestamp t2.
[0156] 1006: The terminal device obtains the difference Δ from the storage space, and determines a timestamp t3 based on the timestamp tx and the difference Δ.
[0157] 1007: The terminal device determines a timestamp t2 based on the timestamp t3, the system frame number λ2, and the slot number υ2.
[0158] For the specific implementation of step 1007, please refer to the description of the embodiment corresponding to Figure 8. Details will not be described here.
[0159] 1008: The terminal device determines that the first SIB1 is valid based on the first SIB1, the timestamp t2, and the second digital signature.
[0160] For a specific implementation of step 1008, please refer to the description of the embodiment corresponding to Figure 6. Details will not be described here.
[0161] For example, as shown in FIG. 12, the access network device first generates a second digital signature based on the first SIB1 and timestamp t2, and then transmits the first SIB1, timestamp tx, and the second digital signature to the terminal device when the system frame number is λ2 and the slot number is υ2. After receiving the first SIB1, timestamp tx, and the second digital signature, the terminal device retrieves the difference Δ from the storage space and determines a timestamp t3 based on the timestamp tx and the difference Δ. The terminal device determines a timestamp t2 based on the timestamp t3, the system frame number λ2, and the slot number υ2, and then verifies the second digital signature based on the first SIB1 and timestamp t2. If the verification of the second digital signature is successful, the terminal device may further determine whether the difference between the timestamp t2 and the local time is less than a threshold to determine whether the attack is a replay attack. If the difference between the timestamp t2 and the local time is less than the threshold, the terminal device determines that the first SIB1 is valid.
[0162] 1009: The access network device generates a first digital signature, the first digital signature being a signature for the OSI and timestamp t1, where timestamp t1 is an absolute point in time corresponding to the access network device when the system frame number is λ1 and the slot number is υ1.
[0163] For specific implementation forms of steps 1009 to 1013, please refer to the description of the embodiment corresponding to Fig. 4. Details will not be described here.
[0164] 1010: The access network device sends a first message to the terminal device when the system frame number is λ1 and the slot number is υ1, the first message including an OSI and a first digital signature, and the first message does not include a timestamp t1.
[0165] 1011: The terminal device receives a first message sent by the access network device based on OSI scheduling information in the first SIB1 when the system frame number is λ1 and the slot number is υ1.
[0166] 1012: The terminal device determines a time stamp t1 based on the system frame number λ1, the slot number υ1, the time stamp t2, the system frame number λ2, and the slot number υ2.
[0167] 1013: The terminal device verifies the first digital signature based on the OSI and the timestamp t1.
[0168] According to the method described in FIG. 10, when the first SIB1 is transmitted, the timestamp t3 is not transmitted directly, but the timestamp tx and the difference Δ are transmitted. As a result, the terminal device determines the timestamp t3 based on the timestamp tx and the difference Δ. The information bits occupied by the timestamp tx and the difference Δ are much smaller than the information bits occupied by the timestamp t3. This facilitates reducing the number of information bits occupied by the timestamps. In addition, by storing the difference Δ, the terminal device can determine the timestamp t3 when receiving a second message carrying the timestamp tx, and the maximum latency of the terminal device is the transmission periodicity T1 of the timestamp tx. If the terminal device does not store the difference Δ and the timestamp tx, the maximum latency of the terminal device is the maximum value between the transmission periodicity T1 of the timestamp tx and the transmission periodicity T of the difference Δ. Therefore, storing the difference Δ facilitates reducing network latency.
[0169] 13A and 13B are schematic flowcharts of a system message transmission method according to an embodiment of the present application. FIG. 13A and 13B illustrate an example in which a terminal device and an access network device are used as the execution entities of the method. The execution entities of the method are not limited in the present application. For example, the terminal device or the access network device in FIG. 13A and 13B may alternatively be a chip, a chip system, or a processor that supports the terminal device or the access network device in implementing the method, or may be a logic module or software that can implement all or part of the functions of the terminal device or the access network device.
[0170] 1301: The access network device sends a third message to the terminal device when the system frame number is 0 and the slot number is 0, where the third message includes a second SIB1, a timestamp tx, a difference Δ, and a third digital signature. Correspondingly, the terminal device may receive the third message when the system frame number is 0 and the slot number is 0.
[0171] The third digital signature is a signature over the second SIB1 and timestamp t3.
number
[0172] In other words, instead of sending timestamp t3, the access network device sends timestamp tx and a difference Δ.
[0173] 1302: The terminal device determines a timestamp t3 based on the timestamp tx and the difference Δ.
[0174] In the embodiment of the present application, after receiving the third message when the system frame number is 0 and the slot number is 0, the terminal device determines the timestamp t3 based on the timestamp tx and the difference Δ.
[0175] 1303: The terminal device determines that the second SIB1 is valid based on the second SIB1, the timestamp t3, and the third digital signature.
[0176] The principle by which the terminal device determines that the second SIB1 is valid based on the second SIB1, the timestamp t3, and the third digital signature is the same as the principle by which the terminal device determines that the first SIB1 is valid based on the first SIB1, the timestamp t2, and the second digital signature, and will not be described in detail here.
[0177] 1304: The terminal device stores the timestamp tx and the difference Δ in a storage space.
[0178] In the embodiment of the present application, the terminal device stores the difference Δ in a storage space, and then determines the timestamp t3 by using the difference Δ.
[0179] 1305: The access network device sends a second message to the terminal device when the system frame number is λ2 and the slot number is υ2, where the second message includes the first SIB1 and the second digital signature. Correspondingly, when the system frame number is λ2 and the slot number is υ2, the terminal device may receive the second message sent by the access network device.
[0180] The second digital signature is a signature of the first SIB1 and timestamp t2, which is an absolute point in time corresponding to the access network device when system frame number is λ2 and slot number is υ2. The second message does not include timestamp t2, and the first SIB1 contains OSI scheduling information.
[0181] In other words, in this embodiment, the access network device sends only the first SIB1 and the second digital signature together to the terminal device, and the terminal device calculates the timestamp t2.
[0182] 1306: The terminal device obtains the timestamp tx and the difference Δ from the storage space, and determines the timestamp t3 based on the timestamp tx and the difference Δ.
[0183] 1307: The terminal device determines a timestamp t2 based on the timestamp t3, the system frame number λ2, and the slot number υ2.
[0184] For the specific implementation of step 1307, please refer to the description of the embodiment corresponding to Figure 8. Details will not be described here.
[0185] If the difference between the timestamp t2 and the local time is less than a threshold, the terminal device determines that the first SIB1 is valid.
[0186] 1308: The terminal device determines that the first SIB1 is valid based on the first SIB1, the timestamp t2, and the second digital signature.
[0187] For a specific implementation of step 1308, please refer to the description of the embodiment corresponding to Figure 6. Details will not be described here.
[0188] For example, as shown in FIG. 14, the access network device first generates a second digital signature based on the first SIB1 and timestamp t2, and then transmits the first SIB1 and the second digital signature to the terminal device when the system frame number is λ2 and the slot number is υ2. After receiving the first SIB1 and the second digital signature, the terminal device retrieves the timestamp tx and the difference Δ from the storage space and determines the timestamp t3 based on the timestamp tx and the difference Δ. The terminal device determines the timestamp t2 based on the timestamp t3, the system frame number λ2, and the slot number υ2, and then verifies the second digital signature based on the first SIB1 and timestamp t2. If the verification of the second digital signature is successful, the terminal device may further determine whether the difference between the timestamp t2 and the local time is less than a threshold to determine whether the attack is a replay attack. If the difference between the timestamp t2 and the local time is less than the threshold, the terminal device determines that the first SIB1 is valid.
[0189] 1309: The access network device generates a first digital signature, the first digital signature being a signature for the OSI and timestamp t1, where timestamp t1 is an absolute point in time corresponding to the access network device when the system frame number is λ1 and the slot number is υ1.
[0190] For specific implementation forms of steps 1309 to 1313, please refer to the description of the embodiment corresponding to Fig. 4. Details will not be described here.
[0191] 1310: The access network device sends a first message to the terminal device when the system frame number is λ1 and the slot number is υ1, the first message including an OSI and a first digital signature, and the first message does not include a timestamp t1.
[0192] 1311: The terminal device receives a first message sent by the access network device based on OSI scheduling information in the first SIB1 when the system frame number is λ1 and the slot number is υ1.
[0193] 1312: The terminal device determines a timestamp t1 based on the system frame number λ1, the slot number υ1, the timestamp t2, the system frame number λ2, and the slot number υ2.
[0194] 1313: The terminal device verifies the first digital signature based on the OSI and the timestamp t1.
[0195] According to the method described in FIG. 13A and FIG. 13B, when the first SIB1 is transmitted, the timestamp t3 is not transmitted directly, but the timestamp tx and the difference Δ are transmitted. As a result, the terminal device determines the timestamp t3 based on the timestamp tx and the difference Δ. The information bits occupied by the timestamp tx and the difference Δ are much smaller than the information bits occupied by the timestamp t3. This facilitates reducing the number of information bits occupied by the timestamps. Furthermore, the terminal device stores the timestamp tx and the difference Δ so that the latency of the terminal device is zero. If the terminal device does not store the difference Δ and the timestamp tx, the longest latency of the terminal device is the maximum value between the transmission periodicity T1 of the timestamp tx and the transmission periodicity T of the difference Δ. Therefore, storing the timestamp tx and the difference Δ facilitates reducing network latency.
[0196] 10 and 13A and 13B, the distribution periodicity of the timestamp tx and / or the distribution periodicity of the difference Δ are configured by the network device or are pre-specified in a protocol. If the network device configures the distribution periodicity of the timestamp tx and / or the distribution periodicity of the difference Δ, the distribution periodicity of the timestamp tx and / or the distribution periodicity of the difference Δ may be more flexible. If the distribution periodicity of the timestamp tx and / or the distribution periodicity of the difference Δ are pre-specified in a protocol, network overhead may be reduced.
[0197] For example, as shown in Figure 15, the transmission periodicity of the timestamp tx is T1, and the transmission periodicity of the difference Δ is T. If the transmission periodicity T1 of the timestamp tx and the transmission periodicity T of the difference Δ are configurable, the delivery periodicity of the timestamp tx and / or the delivery periodicity of the difference Δ may be more flexible. This facilitates reducing the network latency of terminal devices in the system. Optionally, the transmission periodicity T1 of the timestamp tx and the transmission periodicity T of the difference Δ may be the same or different.
[0198] 10, 13A, and 13B illustrate two methods for obtaining timestamp t3. In FIGS. 10, 13A, and 13B, when the system frame number and slot number are 0, the access network device transmits the second SIB1, timestamp tx, the difference Δ, and the third digital signature. In other words, the timestamp tx and the difference Δ are transmitted instead of the timestamp t3. In another implementation of the present application, when the system frame number and slot number are 0, the access network device may alternatively directly transmit the second SIB1, timestamp t3, and the third digital signature. In other words, it is not necessary to transmit the timestamp tx and the difference Δ instead of the timestamp t3. Optionally, after receiving the timestamp t3, the terminal device may store the timestamp t3 in a storage space and then use the timestamp t3 to calculate the timestamp t2. Optionally, the transmission periodicity of the timestamp t3 is configured by the network device or pre-specified in a protocol.
[0199] FIG. 16 is a diagram of the structure of a communication device according to one embodiment of the present application. The communication device shown in FIG. 16 may be configured to perform some or all of the functions of the terminal device in the aforementioned method embodiments. The device may be a terminal device, a device within the terminal device, or a device compatible with the terminal device. The communication device may instead be a chip system. The communication device shown in FIG. 16 may include a communication unit 1601 and a processing unit 1602. The processing unit 1602 is configured to perform data processing. The communication unit 1601 incorporates a receiving unit and a transmitting unit. The communication unit 1601 may also be referred to as a transceiver unit. Alternatively, the communication unit 1601 may be divided into a receiving unit and a transmitting unit.
[0200] The communication unit 1601 is configured to receive a first message sent by an access network device based on scheduling information in OSI (Other System Information) in a first SIB1 (System Information Block 1) when the system frame number is λ1 and the slot number is υ1. The first message includes the OSI and a first digital signature. The first digital signature is a signature for the OSI and a timestamp t1. The timestamp t1 is an absolute point in time corresponding to the access network device when the system frame number is λ1 and the slot number is υ1. The processing unit 1602 is configured to determine the timestamp t1 based on the system frame number λ1, the slot number υ1, the timestamp t2, the system frame number λ2, and the slot number υ2. The system frame number λ2 and the slot number υ2 are the system frame number and slot number to which the first SIB1 belongs. The timestamp t2 is an absolute point in time corresponding to the access network device when the system frame number is λ2 and the slot number is υ2. The processing unit 1602 is further configured to verify the first digital signature based on the OSI and the timestamp t1.
[0201] In one possible implementation, the communication unit 1601 is further configured to receive a second message transmitted by the access network device when the system frame number is λ2 and the slot number is υ2, before receiving a first message transmitted by the access network device based on OSI scheduling information in the first SIB1 when the system frame number is λ1 and the slot number is υ1. The second message includes the first SIB1, a timestamp t2, and a second digital signature. The second digital signature is a signature for the first SIB1 and the timestamp t2. The processing unit 1602 is configured to determine that the first SIB1 is valid based on the first SIB1, the timestamp t2, and the second digital signature.
[0202] In a possible implementation, the communication unit 1601 is further configured to receive a second message transmitted by the access network device when the system frame number is λ2 and the slot number is υ2, prior to receiving a first message transmitted by the access network device based on OSI scheduling information in the first SIB1 when the system frame number is λ1 and the slot number is υ1. The second message includes the first SIB1 and a second digital signature. The second digital signature is a signature for the first SIB1 and a timestamp t2. The processing unit 1602 is further configured to obtain a timestamp t3. The timestamp t3 is an absolute point in time corresponding to the access network device when the system frame number is 0 and the slot number is 0. The processing unit 1602 is further configured to determine a timestamp t2 based on the timestamp t3, the system frame number λ2, and the slot number υ2. The processing unit 1602 is further configured to determine, based on the first SIB1, the timestamp t2, and the second digital signature, that the first SIB1 is valid.
[0203] In a possible implementation, the communication unit 1601 is further configured to receive a third message transmitted by the access network device when the system frame number is 0 and the slot number is 0, before receiving the second message transmitted by the access network device. The third message includes a second SIB1, a timestamp tx, a difference Δ, and a third digital signature. The third digital signature is a signature on the second SIB1 and the timestamp t3. The processing unit 1602 is further configured to determine the timestamp t3 based on the timestamp tx and the difference Δ.
number
[0204] The second message further includes a timestamp tx, and the processing unit 1602 obtaining the timestamp t3 includes the processing unit 1602 obtaining the difference Δ from the memory space and determining the timestamp t3 based on the timestamp tx and the difference Δ.
[0205] In a possible implementation, the communication unit 1601 is further configured to receive a third message transmitted by the access network device when the system frame number is λ2 and the slot number is υ2, before receiving a second message transmitted by the access network device when the system frame number is λ2 and the slot number is υ2. The third message includes a second SIB1, a timestamp tx, a difference Δ, and a third digital signature. The third digital signature is a signature on the second SIB1 and the timestamp t3. The processing unit 1602 is further configured to determine the timestamp t3 based on the timestamp tx and the difference Δ. The timestamp
number
[0206] The processing unit 1602 obtaining the timestamp t3 includes the processing unit 1602 obtaining the timestamp tx and the difference Δ from the storage space, and determining the timestamp t3 based on the timestamp tx and the difference Δ.
[0207] In a possible implementation, the periodicity of delivery of the timestamps tx and / or the periodicity of delivery of the difference Δ is configured by the network device or is pre-specified in a protocol.
[0208] In a possible implementation, the timestamp t1 satisfies the following equation: t1=t2+(λ1-λ2)*10+(υ1-υ2)*α
[0209] The timestamp t1 is expressed in milliseconds, and α is the time length of one slot, also expressed in milliseconds.
[0210] In a possible implementation, the timestamp t2 satisfies the following equation: t2=t3+λ2*10+υ2*α
[0211] The timestamp t2 is expressed in milliseconds, and α is the time length of one slot, also expressed in milliseconds.
[0212] FIG. 16 is a diagram of the structure of a communication device according to one embodiment of the present application. The communication device shown in FIG. 16 may be configured to perform some or all of the functions of the access network device in the aforementioned method embodiments. The device may be an access network device, a device within the access network device, or a device compatible with the access network device. The communication device may alternatively be a chip system. The communication device shown in FIG. 16 may include a communication unit 1601 and a processing unit 1602. The processing unit 1602 is configured to perform data processing. The communication unit 1601 incorporates a receiving unit and a transmitting unit. The communication unit 1601 may also be referred to as a transceiver unit. Alternatively, the communication unit 1601 may be divided into a receiving unit and a transmitting unit.
[0213] The processing unit 1602 is configured to generate a first digital signature. The first digital signature is a signature of OSI (other system information) and timestamp t1. The timestamp t1 is an absolute point in time corresponding to the access network device when the system frame number is λ1 and the slot number is υ1. The communication unit 1601 is configured to send a first message to the terminal device when the system frame number is λ1 and the slot number is υ1. The first message includes the OSI and the first digital signature. The first message does not include the timestamp t1.
[0214] In a possible implementation, the communication unit 1601 is further configured to send a second message to the terminal device when the system frame number is λ2 and the slot number is υ2 before the processing unit 1602 generates the first digital signature. The second message includes a first system information block 1 (SIB1), a timestamp t2, and a second digital signature. The second digital signature is a signature of the first SIB1 and the timestamp t2. The timestamp t2 is an absolute point in time corresponding to the access network device when the system frame number is λ2 and the slot number is υ2. The first SIB1 includes OSI scheduling information.
[0215] In a possible implementation, the communication unit 1601 is further configured to send a second message to the terminal device when the system frame number is λ2 and the slot number is υ2 before the processing unit 1602 generates the first digital signature. The second message includes a first system information block 1 (SIB1) and a second digital signature. The second digital signature is a signature of the first SIB1 and a timestamp t2. The timestamp t2 is an absolute point in time corresponding to the access network device when the system frame number is λ2 and the slot number is υ2. The second message does not include the timestamp t2. The first SIB1 includes OSI scheduling information.
[0216] In a possible implementation, the communication unit 1601 is further configured to send a third message to the terminal device when the system frame number is 0 and the slot number is 0. The third message includes a second SIB1, a timestamp tx, a difference Δ, and a third digital signature. The third digital signature is a signature for the second SIB1 and a timestamp t3. The timestamp t3 is an absolute point in time corresponding to the access network device when the system frame number is 0 and the slot number is 0.
number
[0217] In a possible implementation, the second message further comprises a timestamp tx.
[0218] In a possible implementation, the periodicity of delivery of the timestamps tx and / or the periodicity of delivery of the difference Δ is configured by the network device or is pre-specified in a protocol.
[0219] 17 is a diagram of a configuration of a communication device. The communication device 1700 may be a terminal device in the aforementioned method embodiment, an access network device in the aforementioned method embodiment, a chip, chip system, processor, etc. supporting the terminal device in implementing the aforementioned method, or a chip, chip system, processor, etc. supporting the access network device in implementing the aforementioned method. The communication device may be configured to implement the method described in the aforementioned method embodiment. For details, please refer to the description in the aforementioned method embodiment.
[0220] The communication device 1700 may include one or more processors 1701. The processor 1701 may be a general-purpose processor, a special-purpose processor, or the like, and may be, for example, a baseband processor or a central processing unit. The baseband processor may be configured to process communication protocols and communication data. The central processing unit may be configured to control the communication device (such as a base station, a baseband chip, a terminal, a terminal chip, a DU, or a CU), execute software programs, and process data of the software programs.
[0221] Optionally, the communication device 1700 may include one or more memories 1702. The one or more memories 1702 may store instructions 1704. The instructions may be executed on the processor 1701 to enable the communication device 1700 to perform the methods described in the foregoing method embodiments. Optionally, the memory 1702 may further store data. The processor 1701 and the memory 1702 may be located separately or integrated with each other.
[0222] Optionally, the communication device 1700 may further include a transceiver 1705 and an antenna 1706. The transceiver 1705 may be referred to as a transceiver unit, transceiver, transceiver circuit, etc., and is configured to implement transceiver functionality. The transceiver 1705 may include a receiver and a transmitter. The receiver may be referred to as a receiver, receiver circuit, etc., and is configured to implement receiving functionality. The transmitter may be referred to as a transmitter, transmitter circuit, etc., and is configured to implement transmitting functionality. The processing unit 1602 shown in FIG. 16 may be a processor 1701. The communication unit 1601 may be the transceiver 1705.
[0223] The communication device 1700 is a terminal device, and the processor 1701 is configured to perform the data processing operations of the terminal device in the above-described method embodiments. The transceiver 1705 is configured to perform the data transmission and reception operations of the terminal device in the above-described method embodiments.
[0224] The communication device 1700 is an access network device, and the processor 1701 is configured to perform the data processing operations of the access network device in the aforementioned method embodiments. The transceiver 1705 is configured to perform the data receiving and transmitting operations of the access network device in the aforementioned method embodiments.
[0225] In another possible design, the processor 1701 may include a transceiver configured to perform reception and transmission functions. For example, the transceiver may be a transceiver circuit, an interface, or an interface circuit. The transceiver circuit, interface, or interface circuit configured to implement the transmission and reception functions may be separate or integrated. The transceiver circuit, interface, or interface circuit may be configured to read and write code / data, and the transceiver circuit, interface, or interface circuit may be configured to transmit or forward signals.
[0226] In yet another possible design, the processor 1701 may optionally store instructions 1703. The instructions 1703 are executed on the processor 1701 to enable the communication device 1700 to perform the methods described in the preceding method embodiments. The instructions 1703 may be fixed within the processor 1701. In this case, the processor 1701 may be implemented by hardware.
[0227] In yet another possible design, the communications device 1700 may include circuitry. The circuitry may perform the transmitting, receiving, or communication functions in the aforementioned method embodiments. The processors and transceivers described in this embodiment of the present application may be implemented in an integrated circuit (IC), an analog IC, a radio frequency integrated circuit (RFIC), a mixed-signal IC, an application specific integrated circuit (ASIC), a printed circuit board (PCB), an electronic device, or the like. The processors and transceivers may alternatively be fabricated using various IC process technologies, such as complementary metal oxide semiconductor (CMOS), n-type metal oxide semiconductor (nMOS), p-type metal oxide semiconductor (PMOS), bipolar junction transistor (BJT), bipolar CMOS (BiCMOS), silicon germanium (SiGe), and gallium arsenide (GaAs).
[0228] The communication device described in the above embodiment may be a terminal device or an access network device. However, the scope of the communication device described in the embodiment of this application is not limited thereto, and the structure of the communication device may not be limited by FIG. 17. The communication device may be an independent device or part of a larger device. For example, the communication device may be: (1) An independent integrated circuit IC, or chip, or chip system, or subsystem; (2) A set having one or more ICs. Optionally, the IC set may also include a storage component configured to store data and instructions; (3) ASIC, e.g., modem (MSM), (4) Modules that can be built into other devices; (5) Receivers, terminals, intelligent terminals, mobile phones, wireless devices, handheld devices, mobile units, in-vehicle devices, network devices, cloud devices, artificial intelligence devices, etc.; (6) Others, etc.
[0229] For cases where the communication device may be a chip or a chip system, please refer to the diagram of the chip structure shown in Figure 18. The chip 1800 shown in Figure 18 includes a processor 1801 and an interface 1802, and may optionally further include a memory 1803. There may be more than one processor 1801, and there may be more than one interface 1802.
[0230] In a design where a chip is configured to implement the functionality of a terminal device in an embodiment of the present application, The interface 1802 is configured to receive or output signals; The processor 1801 is configured to perform data processing operations of the terminal device.
[0231] In a design where a chip is configured to implement the functionality of an access network device in an embodiment of the present application, The interface 1802 is configured to receive or output signals; The processor 1801 is configured to perform data processing operations of the access network device.
[0232] It should be understood that in some scenarios, some optional features in the embodiments of this application can be implemented independently to solve corresponding technical problems and achieve corresponding effects, without relying on other features, for example, the solutions on which the optional features are currently based. Alternatively, in some scenarios, optional features may be combined with other features based on requirements. Correspondingly, the communication devices provided in the embodiments of this application can also implement these features or functions accordingly. Details will not be described here.
[0233] It should be understood that the processor in the embodiments of the present application may be an integrated circuit chip and have signal processing capabilities. In one implementation process, the steps in the above method embodiments can be implemented by using hardware integrated logic circuitry in the processor or by using instructions in the form of software. Such a processor may be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or another programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component.
[0234] It will be understood that the memory of the embodiments of the present application may be volatile or non-volatile memory, or may include volatile and non-volatile memory. Non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM) used as an external cache. By way of example and not limitation, many forms of RAM may be used, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct Rambus random access memory (DR RAM). It should be noted that the memory of the systems and methods described herein includes, but is not limited to, these and any other suitable types of memory.
[0235] This application further provides a computer-readable medium. The storage medium stores a computer program or instructions. When the computer program is executed by a communication device or when the instructions are executed by a communication device, the functions of any one of the above-mentioned method embodiments are performed.
[0236] This application further provides a computer program product comprising instructions, which, when read and executed by a computer, enable the computer to perform the functions of any one of the method embodiments described above.
[0237] All or part of the above embodiments may be implemented using software, hardware, firmware, or any combination thereof. When software is used for implementation, all or part of the above embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded into a computer and executed, the procedures or functions according to the embodiments of the present application are generated, in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or another programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wire (e.g., coaxial cable, optical fiber, or digital subscriber line (DSL)) or wireless (e.g., infrared, radio wave, or microwave) transmission. The computer-readable storage medium may be any available medium accessible by a computer, or a data storage device, such as a server or data center, that integrates one or more available media. The usable media may be magnetic media (e.g., floppy disks, hard disks, or magnetic tapes), optical media (e.g., high-density digital video discs (DVDs)), or semiconductor media (e.g., solid state disks (SSDs)).
[0238] The above description is merely a specific implementation form of the present application and is not intended to limit the protection scope of the present application. Any variations or replacements that can be easily conceived by those skilled in the art within the technical scope disclosed in the present application shall fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims. [Explanation of symbols]
[0239] 30 Terminal Devices 31 Access Network Devices 1601 Communication Unit 1602 Processing Unit 1700 Communication Equipment 1701 processor 1702 memory 1703 Command 1704 Command 1705 Transceiver 1706 Antenna 1800 chips 1801 processor 1802 interface 1803 memory
Claims
1. receiving, by a terminal device, a first message sent by an access network device based on scheduling information of other system information OSI in a first system information block 1 (SIB1) when the system frame number is λ1 and the slot number is υ1, the first message including the OSI and a first digital signature, the first digital signature being a signature of the OSI and a signature on a timestamp t1, the timestamp t1 being a signature of the access network device when the system frame number is λ1 and the slot number is υ1; determining the timestamp t1 by the terminal device based on the system frame number λ1, the slot number υ1, timestamp t2, system frame number λ2, and slot number υ2, where the system frame number λ2 and the slot number υ2 are the system frame number and slot number to which the first SIB1 belongs, and the timestamp t2 is an absolute time point corresponding to the access network device when the system frame number is λ2 and the slot number is υ2; verifying the first digital signature by the terminal device based on the OSI and the timestamp t1; A system message sending method including:
2. before receiving, by the terminal device, a first message sent by the access network device based on OSI scheduling information in a first SIB1 when the system frame number is λ1 and the slot number is υ1; receiving, by the terminal device, a second message sent by the access network device when the system frame number is λ2 and the slot number is υ2, the second message including the first SIB1, the timestamp t2, and a second digital signature, the second digital signature being a signature over the first SIB1 and the timestamp t2; determining, by the terminal device, that the first SIB1 is valid based on the first SIB1, the timestamp t2, and the second digital signature; 2. The method of claim 1, comprising:
3. before receiving, by the terminal device, a first message sent by the access network device based on OSI scheduling information in a first SIB1 when the system frame number is λ1 and the slot number is υ1; receiving, by the terminal device, a second message sent by the access network device when the system frame number is λ2 and the slot number is υ2, the second message including the first SIB1 and a second digital signature, the second digital signature being a signature over the first SIB1 and the timestamp t2; acquiring a timestamp t3 by the terminal device, the timestamp t3 being an absolute point in time corresponding to the access network device when the system frame number is 0 and the slot number is 0; determining the timestamp t2 by the terminal device based on the timestamp t3, the system frame number λ2, and the slot number υ2; determining, by the terminal device, that the first SIB1 is valid based on the first SIB1, the timestamp t2, and the second digital signature; 2. The method of claim 1, comprising:
4. before the step of receiving, by the terminal device, a second message sent by the access network device; receiving, by the terminal device, a third message sent by the access network device when the system frame number is 0 and the slot number is 0, the third message including a second SIB1, a timestamp tx, a difference Δ, and a third digital signature, the third digital signature being a signature for the second SIB1 and the timestamp t3; determining the timestamp t3 by the terminal device based on the timestamp tx and the difference Δ, [Equation 1] , M is the maximum value of the system frame number, and the timestamp t3 is equal to the sum of the timestamp tx and the difference Δ; determining, by the terminal device, that the second SIB1 is valid based on the second SIB1, the timestamp t3, and the third digital signature; storing, by the terminal device, the difference Δ in a storage space; Including, The second message further includes the timestamp tx, and the step of obtaining the timestamp t3 by the terminal device includes: obtaining, by the terminal device, a difference Δ from the storage space; determining the timestamp t3 by the terminal device based on the timestamp tx and the difference Δ; 4. The method of claim 3, comprising:
5. before the step of receiving, by the terminal device, a second message sent by the access network device when the system frame number is λ2 and the slot number is υ2; receiving, by the terminal device, a third message sent by the access network device when the system frame number is 0 and the slot number is 0, the third message including a second SIB1, a timestamp tx, a difference Δ, and a third digital signature, the third digital signature being a signature for the second SIB1 and the timestamp t3; determining the timestamp t3 by the terminal device based on the timestamp tx and the difference Δ, [Equation 2] , M is the maximum value of the system frame number, and the timestamp t3 is equal to the sum of the timestamp tx and the difference Δ; determining, by the terminal device, that the second SIB1 is valid based on the second SIB1, the timestamp t3, and the third digital signature; storing, by the terminal device, the timestamp tx and the difference Δ in a storage space; Including, The step of obtaining a timestamp t3 by the terminal device comprises: acquiring, by the terminal device, the timestamp tx and the difference Δ from the storage space; determining the timestamp t3 by the terminal device based on the timestamp tx and the difference Δ; 4. The method of claim 3, comprising:
6. The method of claim 4 , wherein at least one of the delivery periodicity of the timestamps tx and the delivery periodicity of the difference Δ is configured by a network device or is pre-specified in a protocol.
7. The timestamp t1 is calculated by the following formula: t1=t2+(λ1-λ2)*10+(υ1-υ2)*α Fulfilling 7. The method according to claim 1, wherein the timestamp t1 is expressed in milliseconds, and α is the time length of one slot, and α is also expressed in milliseconds.
8. The timestamp t2 is calculated by the following formula: t2=t3+λ2*10+υ2*α Fulfilling 7. The method according to claim 3, wherein the timestamp t2 is expressed in milliseconds, and α is the time length of one slot, and α is also expressed in milliseconds.
9. generating a first digital signature by an access network device, the first digital signature being a signature over other system information OSI and a timestamp t1, the timestamp t1 being an absolute point in time corresponding to the access network device when system frame number is λ1 and slot number is υ1; sending a first message by the access network device to a terminal device when the system frame number is λ1 and the slot number is υ1, the first message including the OSI and the first digital signature, and the first message not including the timestamp t1; A system message sending method, including:
10. before the step of generating, by the access network device, a first digital signature; sending a second message by the access network device to the terminal device when the system frame number is λ2 and the slot number is υ2, the second message including a first system information block 1 (SIB1), a timestamp t2, and a second digital signature, the second digital signature being a signature for the first SIB1 and the timestamp t2, the timestamp t2 being an absolute point in time corresponding to the access network device when the system frame number is λ2 and the slot number is υ2, and the first SIB1 including the OSI scheduling information; 10. The method of claim 9, further comprising:
11. before the step of generating, by the access network device, a first digital signature; sending a second message by the access network device to the terminal device when the system frame number is λ2 and the slot number is υ2, the second message including a first system information block 1, SIB1, and a second digital signature, the second digital signature being a signature for the first SIB1 and a timestamp t2, the timestamp t2 being an absolute point in time corresponding to the access network device when the system frame number is λ2 and the slot number is υ2, the second message not including the timestamp t2, and the first SIB1 including the OSI scheduling information; 10. The method of claim 9, further comprising:
12. transmitting a third message by the access network device to the terminal device when the system frame number is 0 and the slot number is 0, the third message including a second SIB1, a timestamp tx, a difference Δ, and a third digital signature, the third digital signature being a signature for the second SIB1 and a timestamp t3, the timestamp t3 being an absolute point in time corresponding to the access network device when the system frame number is 0 and the slot number is 0, [Equation 3] , M is the maximum value of the system frame number, and the timestamp t3 is equal to the sum of the timestamp tx and the difference Δ; 12. The method of claim 11, further comprising:
13. The method of claim 12 , wherein the second message further includes the timestamp tx.
14. 14. The method of claim 12 or 13, wherein at least one of the delivery periodicity of the timestamps tx and the delivery periodicity of the difference Δ is configured by a network device or pre-specified in a protocol.
15. A communication device comprising a unit configured to perform the method according to any one of claims 1 to 6.
16. A communication device comprising a unit configured to perform the method according to any one of claims 9 to 13.
17. A communications device comprising a processor and a memory, the processor coupled to the memory, the processor configured to perform the method of any one of claims 1 to 6.
18. A communications device comprising a processor and a memory, the processor coupled to the memory, and the processor configured to execute a method according to any one of claims 9 to 13.
19. A chip comprising a processor and an interface, the processor coupled to the interface, the interface configured to receive or output signals, the processor configured to execute code instructions to enable the method of any one of claims 1 to 6.
20. A chip comprising a processor and an interface, wherein the processor is coupled to the interface, the interface is configured to receive or output signals, and the processor is configured to execute code instructions to enable a method described in any one of claims 9 to 13.
21. 7. A computer-readable storage medium storing computer-executable instructions that, when executed by a computer, enable the computer to perform the method of any one of claims 1 to 6.
22. A computer-readable storage medium, the computer-readable storage medium storing computer-executable instructions, which, when activated by a computer, enable the computer to execute a method according to any one of claims 9 to 13.
23. 7. A computer program comprising computer program code which, when executed by a computer, enables the computer to carry out the method of any one of claims 1 to 6.
24. A computer program comprising computer program code which, when executed by a computer, enables the computer to perform a method according to any one of claims 9 to 13.
Citation Information
Patent Citations
System and method for validating authenticity of base station and / or information received from base station
US20170295489A1
Verification of cell authenticity in a wireless network using an extended time stamp
US20180124697A1