Data transmission method and device

By negotiating the keys and encrypting protection during the random access process of the cellular network, the problem of insufficient security protection of terminal devices and network devices during the random access process is solved, and effective security protection of the access process is achieved.

WO2025092301A1PCT designated stage expired Publication Date: 2025-05-08HUAWEI TECH CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/120525
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-03
Filing Date
2024-09-24
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

During random access in a cellular network, terminal devices and network devices cannot obtain aligned keys, resulting in insufficient security protection and vulnerability to attacks.

Method used

During the random access process, the aligned key is negotiated between the first communication device and the second communication device, and the aligned key is used to encrypt and protect the transmission data.

Benefits of technology

It effectively protects the security of the random access process and prevents attackers from interfering with the normal operation of terminal equipment and networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024120525_08052025_PF_FP_ABST
    Figure CN2024120525_08052025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are a data transmission method and a device. The method comprises: receiving a first downlink reference signal and, according to the first downlink reference signal, obtaining a first key; sending a first uplink reference signal; receiving a first message and, according to verification information of the first key and a second key, determining a third key; and, according to the third key, performing security protection on data transmitted to and from a second communication device, the second key being obtained by the second communication device on the basis of the received first uplink reference signal. The method can perform security protection on data transmitted during random access.
Need to check novelty before this filing date? Find Prior Art

Description

Data transmission method and device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on November 3, 2023, with application number 202311460695.7 and invention name “A method and device for data transmission”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communications, and more specifically, to a method and apparatus for data transmission. Background Art

[0003] Security is a key value proposition of cellular networks. Communications security not only impacts user data security but also significantly influences the smooth operation of industrial production. Therefore, as cellular networks evolve, security technologies must evolve alongside them.

[0004] In cellular networks, the initial access process (also known as the random access process) is a necessary process for terminal devices to access the network and obtain services. Since cellular networks use a key deduction mechanism based on the core network, during the random access process of terminal devices, the terminal device and network equipment cannot obtain aligned keys for protecting the random access process. However, some current attacks will take advantage of this to attack the random access process of terminal devices, thereby affecting the security of terminal devices and even the network.

[0005] Therefore, how to solve the security protection problem of the random access process has become an issue that needs to be solved urgently.

[0006] Summary of the Invention

[0007] The present application provides a data transmission method, which can securely protect data transmitted during a random access process.

[0008] In a first aspect, a method for data transmission is provided, which can be performed by a first communication device. The first communication device can be a terminal device, or it can also be a component of the terminal device, for example, a circuit, chip, or chip system of the terminal device, etc. It can also be a logic module or software that can realize all or part of the functions of the terminal device.

[0009] The method includes: receiving a first downlink reference signal, and obtaining a first key based on the first downlink reference signal; sending a first uplink reference signal; receiving a first message, the first message including verification information of a second key, the second key being obtained by a second communication device based on the received first uplink reference signal; determining a third key based on the verification information of the first key and the second key; and performing security protection on data transmitted between the second communication device and the second communication device based on the third key.

[0010] As an example, the receiving of the first downlink reference signal may be the first communication device receiving the first downlink reference signal sent by the second communication device, the sending of the first uplink reference signal may be the first communication device sending the first uplink reference signal to the second communication device, and the receiving of the first message may be the first communication device receiving the first message sent by the second communication device.

[0011] The first communication device is a chip of a terminal device, such as a baseband chip. Receiving the first downlink reference signal or the first message may involve the baseband chip of the terminal device receiving the first downlink reference signal or the first message, i.e., the first downlink reference signal or the first message being input to the baseband chip of the terminal device. Sending the first uplink reference signal may involve the baseband chip of the terminal device outputting the first uplink reference signal, for example, outputting the first uplink reference signal to a radio frequency signal of the terminal device.

[0012] It should be understood that the data transmitted between the first and second communication devices may include data and signaling transmitted between the first and second communication devices.

[0013] It should also be understood that the above security protection may include, but is not limited to: encrypting and / or integrity protecting the data transmitted between the first communication device and the second communication device.

[0014] In the above technical solution, the first communication device negotiates an aligned key with the second communication device during the random access process, and uses the aligned key to securely protect the data transmitted between the first communication device and the second communication device. In this way, the random access process can be protected, preventing attackers from attacking the random access process of the first communication device, thereby protecting the security of the first communication device and even the second communication device.

[0015] In combination with the first aspect, in certain implementations of the first aspect, when sending the first uplink reference signal, the first communication device also sends a preamble code.

[0016] Specifically, the first communication device may send a preamble code to the second communication device while sending the first uplink reference signal to the second communication device.

[0017] In the above technical solution, the first communication device can send the first uplink reference signal and the preamble together, and the second communication device can measure the first uplink reference signal after estimating the TA using the preamble, so that the measurement result of the first uplink reference signal by the second communication device is more accurate.

[0018] In combination with the first aspect, in certain implementations of the first aspect, before receiving the first downlink reference signal, the first communication device will also receive system information, which includes measurement configuration information and quantization configuration information; the first communication device will measure the first downlink reference signal according to the measurement configuration information to obtain a measurement result of the first downlink reference signal; and quantize the measurement result of the first downlink reference signal according to the quantization configuration information to obtain the first key.

[0019] In the above technical solution, the second communication device may send configuration information for key generation to the first communication device via system information, so that the first communication device and the second communication device may subsequently use the same configuration information to generate aligned keys.

[0020] In combination with the first aspect, in certain implementations of the first aspect, the alignment of the first key and the second key is determined based on verification information of the first key and the second key; the first key is determined as the third key; or the first key is calculated to obtain a fourth key, and the fourth key is determined as the third key.

[0021] It should be understood that the alignment of the first key and the second key can be understood as the first key and the second key being the same or consistent.

[0022] It should also be understood that the present application does not specifically limit the algorithm used to calculate the first key, and any algorithm that can achieve privacy amplification of the first key can be used. In one implementation, the algorithm is a hash algorithm.

[0023] The fourth key is obtained by calculating the first key and the fourth key is determined as the third key. This can further improve the security of data transmitted between the first communication device and the second communication device.

[0024] In combination with the first aspect, in certain implementations of the first aspect, it is determined that the first key and the second key are not aligned based on verification information of the first key and the second key; a second uplink reference signal is sent on the resources indicated by the first message; a second downlink reference signal is received, and a fifth key is obtained based on the second downlink reference signal; verification information of a sixth key is received; and the third key is determined based on the verification information of the fifth key and the sixth key.

[0025] It should be understood that the above-mentioned misalignment between the first key and the second key can be understood as the first key and the second key being different or inconsistent.

[0026] It should also be understood that the sixth key is obtained by the second communication device according to the received second uplink reference signal.

[0027] The process of determining the third key based on the verification information of the fifth key and the sixth key can refer to the process of determining the third key based on the verification information of the first key and the third key. For example, if the fifth key and the sixth key are aligned based on the verification information of the fifth key and the sixth key, the fifth key is determined to be the third key, or an eleventh key is calculated from the fifth key and the eleventh key is determined to be the third key.

[0028] In the above technical solution, the second uplink reference signal can be sent on the resources indicated by the first message, thereby avoiding retransmission of the preamble code and the second uplink reference signal and reducing delay overhead.

[0029] In combination with the first aspect, in certain implementations of the first aspect, the first message also includes a first redundancy version RV (Redundancy Version) of the first coding matrix, and the first key is decoded according to the first RV of the first coding matrix to obtain a seventh key; and the third key is determined based on the seventh key and verification information of the second key.

[0030] It should be understood that the first encoding matrix is ​​determined by the second communication device according to the second key.

[0031] In combination with the first aspect, in certain implementations of the first aspect, it is determined that the seventh key and the second key are aligned based on verification information of the seventh key and the second key, and the seventh key is determined as the third key.

[0032] In combination with the first aspect, in certain implementations of the first aspect, it is determined that the seventh key and the second key are not aligned based on the verification information of the seventh key and the second key; an RV request message is also sent, the RV request message is used to request the second RV of the first coding matrix, and the first key is decoded according to the first RV and the second RV of the first coding matrix to obtain an eighth key, and it is determined that the eighth key and the second key are aligned based on the verification information of the eighth key and the second key, and the eighth key is determined to be the third key.

[0033] In the above technical solution, by introducing the coding information mechanism of different RVs of the coding matrix, coding information can be applied for one by one, thereby reducing the large signaling overhead caused by sending the entire coding information.

[0034] In combination with the first aspect, in certain implementations of the first aspect, if it is determined based on the verification information of the eighth key and the second key that the eighth key and the second key are not aligned, it is also possible to fall back to sending a second uplink reference signal on the resources indicated by the first message, obtain the fifth key based on the second downlink reference signal, and determine the third key based on the verification information of the fifth key and the sixth key.

[0035] That is to say, in the above implementation, when the first key and the second key are not aligned, before the first communication device sends the second uplink reference signal to the second communication device through the resources indicated by the first message, the first communication device can first decode the first key according to the first RV and second RV of the received first coding matrix to obtain the eighth key. If the eighth key and the second key are not yet aligned, the first communication device then sends the above-mentioned second uplink reference signal to the second communication device through the resources indicated by the first message. The second communication device obtains the sixth key based on the received second uplink reference signal, the first communication device obtains the fifth key based on the second downlink reference signal sent by the second communication device, and the first communication device determines the third key based on the verification information of the fifth key and the sixth key. For the specific process of the first communication device determining the third key based on the verification information of the fifth key and the sixth key, please refer to the description in the above implementation, which will not be repeated here.

[0036] In combination with the first aspect, in some implementations of the first aspect, the first message is a random access response (RAR) message.

[0037] In the above technical solution, by carrying the key verification information in the RAR message, there is no need to add new dedicated information and reconcile the message, thereby reducing the delay overhead.

[0038] In a second aspect, a method for data transmission is provided, which can be performed by a second communication device. The second communication device can be a network device, or it can also be a component of the network device, for example, a circuit, chip, or chip system of the network device, etc. It can also be a logic module or software that can realize all or part of the functions of the network device.

[0039] The method includes: sending a first downlink reference signal; receiving a first uplink reference signal, and obtaining a second key based on the first uplink reference signal; sending a first message, wherein the first message includes verification information of the second key; determining a ninth key based on the second key; and, based on the ninth key, performing security protection on data transmitted between the first communication device and the first communication device.

[0040] As an example, the sending of the first downlink reference signal or the first message may be the second communication device sending the first downlink reference signal or the first message to the first communication device, and the receiving of the first uplink reference signal may be the second communication device receiving the first uplink reference signal sent by the first communication device.

[0041] The second communication device is a chip of a network device, such as a baseband chip. Receiving the first uplink reference signal may involve the baseband chip of the network device receiving the first uplink reference signal, i.e., receiving the first uplink reference signal as an input to the baseband chip of the network device. Sending the first downlink reference signal or the first message may involve the baseband chip of the network device outputting the first downlink reference signal or the first message, for example, outputting the first downlink reference signal or the first message to a radio frequency signal of the network device.

[0042] In combination with the second aspect, in certain implementations of the second aspect, the method further includes: broadcasting system information, the system information including measurement configuration information and quantization configuration information; measuring the first uplink reference signal according to the measurement configuration information to obtain a measurement result of the first uplink reference signal; and quantizing the measurement result of the first uplink reference signal according to the quantization configuration information to obtain the second key.

[0043] In combination with the second aspect, in some implementations of the second aspect, the method further includes: receiving a preamble code.

[0044] As an example, when the second communication device receives the first uplink reference signal sent by the first communication device, it also receives the preamble sent by the first communication device.

[0045] In combination with the second aspect, in certain implementations of the second aspect, the first key and the second key are aligned, and the second key is determined as the ninth key; or the second key is calculated to obtain a tenth key, and the tenth key is determined as the ninth key.

[0046] In combination with the second aspect, in certain implementations of the second aspect, the first key and the second key are not aligned, and a second downlink reference signal is sent; a second uplink reference signal is received on the resources indicated by the first message; a sixth key is obtained based on the second uplink reference signal; verification information of the sixth key is sent through the first message; and the ninth key is determined based on the verification information of the fifth key and the sixth key, where the fifth key is obtained by the first communication device based on the second downlink reference signal.

[0047] It should be understood that the above process of determining the ninth key based on the verification information of the fifth key and the sixth key is the same as the process of determining the ninth key based on the second key. Specifically, if the fifth key and the sixth key are aligned, the sixth key can be determined as the ninth key, or the sixth key can be calculated to obtain the twelfth key, and the twelfth key can be determined as the ninth key.

[0048] In combination with the second aspect, in certain implementations of the second aspect, a first coding matrix is ​​determined based on the second key; and a first redundancy version RV of the first coding matrix is ​​sent through the first message.

[0049] In combination with the second aspect, in certain implementations of the second aspect, the method further includes: receiving an RV request message, the RV request message being used to request a second RV of the first coding matrix; and sending the second RV of the first coding matrix through the first message according to the RV request message.

[0050] In combination with the second aspect, in some implementations of the second aspect, the first message is a random access response RAR message.

[0051] It should be understood that the beneficial effects of the second aspect can be referred to the beneficial effects of the first aspect, and will not be repeated here.

[0052] In a third aspect, a communication device is provided, which may be a terminal device or a chip or circuit configured in the terminal device, and is not limited in this application. The device includes: a transceiver unit and a processing unit, wherein the transceiver unit is used to receive a first downlink reference signal, and the processing unit is used to obtain a first key based on the first downlink reference signal; the transceiver unit is also used to send a first uplink reference signal and receive a first message, the first message including verification information of a second key, the second key being obtained by a second communication device based on the received first uplink reference signal; the processing unit is also used to determine a third key based on the verification information of the first key and the second key, and to perform security protection on data transmitted between the second communication device and the second communication device based on the third key.

[0053] In combination with the third aspect, in certain implementations of the third aspect, when sending the first uplink reference signal, the transceiver unit is further configured to send a preamble code.

[0054] In combination with the third aspect, in certain implementations of the third aspect, before the transceiver unit receives the first downlink reference signal, the transceiver unit is also used to receive system information, the system information including measurement configuration information and quantization configuration information; the processing unit is further used to measure the first downlink reference signal according to the measurement configuration information to obtain a measurement result of the first downlink reference signal, and quantize the measurement result of the first downlink reference signal according to the quantization configuration information to obtain the first key.

[0055] In combination with the third aspect, in certain implementations of the third aspect, the processing unit is further used to determine the alignment of the first key and the second key based on the verification information of the first key and the second key; determine the first key as the third key; or calculate the first key to obtain a fourth key, and determine the fourth key as the third key.

[0056] In combination with the third aspect, in certain implementations of the third aspect, the processing unit is further used to determine that the first key and the second key are not aligned based on verification information of the first key and the second key; the transceiver unit is further used to send a second uplink reference signal on the resources indicated by the first message and receive a second downlink reference signal; the processing unit is further used to obtain a fifth key based on the second downlink reference signal; the transceiver unit is further used to receive verification information of a sixth key, and determine the third key based on the verification information of the fifth key and the sixth key.

[0057] In combination with the third aspect, in certain implementations of the third aspect, the first message also includes a first redundant version RV of the first coding matrix, and the processing unit is further used to decode the first key according to the first RV of the first coding matrix to obtain a seventh key, and determine the third key based on the seventh key and the verification information of the second key.

[0058] In combination with the third aspect, in certain implementations of the third aspect, the processing unit is further used to determine that the seventh key and the second key are aligned based on verification information of the seventh key and the second key, and determine the seventh key as the third key.

[0059] In combination with the third aspect, in certain implementations of the third aspect, the processing unit is further used to determine that the seventh key and the second key are not aligned based on the verification information of the seventh key and the second key; the transceiver unit is further used to send an RV request message, which is used to request the second RV of the first coding matrix; the processing unit is further used to decode the first key according to the first RV and the second RV of the first coding matrix to obtain an eighth key, determine that the eighth key and the second key are aligned based on the verification information of the eighth key and the second key, and determine the eighth key as the third key.

[0060] In combination with the third aspect, in some implementations of the third aspect, the first message is a random access response RAR message.

[0061] In a fourth aspect, a communication device is provided, which may be a network device or a chip or circuit configured in the network device, and is not limited in this application. The device includes: a transceiver unit and a processing unit, wherein the transceiver unit is configured to send a first downlink reference signal and receive a first uplink reference signal; the processing unit is configured to obtain a second key based on the first uplink reference signal; the transceiver unit is further configured to send a first message, wherein the first message includes verification information of the second key; the processing unit is further configured to determine a ninth key based on the second key, and based on the ninth key, securely protect data transmitted to and from the first communication device.

[0062] In combination with the fourth aspect, in certain implementations of the fourth aspect, the transceiver unit is further configured to receive a preamble code.

[0063] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first key and the second key are aligned, and the processing unit is further used to determine the second key as the ninth key; or calculate the second key to obtain the tenth key, and determine the tenth key as the ninth key.

[0064] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first key and the second key are not aligned, and the transceiver unit is further used to send a second downlink reference signal and receive a second uplink reference signal on the resources indicated by the first message; the processing unit is further used to obtain a sixth key based on the second uplink reference signal; the transceiver unit is further used to send verification information of the sixth key through the first message; the processing unit is further used to determine the ninth key based on the fifth key and the verification information of the sixth key, and the fifth key is obtained by the first communication device based on the second downlink reference signal.

[0065] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is further used to determine a first coding matrix based on the second key; and the transceiver unit is further used to send a first redundant version RV of the first coding matrix through the first message.

[0066] In combination with the fourth aspect, in certain implementations of the fourth aspect, the transceiver unit is further used to receive an RV request message, which is used to request the second RV of the first coding matrix; the processing unit is further used to send the second RV of the first coding matrix through the first message according to the RV request message.

[0067] In combination with the fourth aspect, in some implementations of the fourth aspect, the first message is a random access response RAR message.

[0068] In a fifth aspect, a communication device is provided, comprising: at least one processor, the processor being configured to enable the communication device to execute the method described in any one of the above aspects by executing computer instructions stored in a memory or through a logic circuit.

[0069] In some possible designs, the communication device further includes a memory for storing computer instructions and / or configuration files of logic circuits. Optionally, the memory is integrated with the processor, or the memory is independent of the processor.

[0070] In a sixth aspect, a communication device is provided, comprising: a processor and a communication interface; the communication interface is used to input and / or output signals; the processor is used to execute computer programs or instructions so that the communication device executes the method described in any of the above aspects.

[0071] In some possible designs, the communication interface is an interface circuit for reading and writing computer instructions. For example, the interface circuit is used to receive computer execution instructions (computer execution instructions are stored in a memory, may be read directly from the memory, or may pass through other devices) and transmit them to the processor.

[0072] In some possible designs, the communication interface is used to communicate with units outside the communication device.

[0073] In some possible designs, the communication device may be a chip or a chip system. When the device is a chip system, the chip system may include the chip or may include the chip and other discrete devices.

[0074] In the seventh aspect, a communication device is provided, comprising: a logic circuit and an interface circuit; the interface circuit is used to input information and / or output information; the logic circuit is used to execute the method described in any of the above aspects, and process and / or generate output information based on the input information.

[0075] In an eighth aspect, a computer-readable storage medium is provided, in which a computer program or instruction is stored. When the computer program or instruction is executed by a processor, the method described in any one of the above aspects is executed.

[0076] In a ninth aspect, a computer program product is provided, which, when executed by a processor, enables the method described in any one of the above aspects to be executed.

[0077] In a tenth aspect, a communication system is provided, comprising the communication device as described in the third aspect and the communication device as described in the fourth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0078] FIG1 is a schematic diagram of a system architecture provided in an embodiment of the present application.

[0079] FIG2 is a schematic diagram of a random access process and a security activation process in a current cellular network.

[0080] FIG3 is a schematic flowchart of a data transmission method provided in an embodiment of the present application.

[0081] FIG4 is a schematic flowchart of another data transmission method provided in an embodiment of the present application.

[0082] FIG5 is a schematic flowchart of another data transmission method provided in an embodiment of the present application.

[0083] FIG6 is a schematic block diagram of a communication device provided in an embodiment of the present application.

[0084] FIG7 is another schematic structural diagram of a communication device provided in an embodiment of the present application.

[0085] FIG8 is another schematic structural diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0086] The technical solution in this application will be described below with reference to the accompanying drawings.

[0087] The terms "first" and "second" and the like in the specification, claims, and drawings of this application are used to distinguish between different objects, not to describe a particular order. Furthermore, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of operations or units is not limited to the listed operations or units, but may optionally include operations or units not listed, or may optionally include other operations or units inherent to the process, method, product, or apparatus.

[0088] References to "embodiments" below mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0089] In the present application, "at least one (item)" refers to one or more, "more than one" refers to two or more, "at least two (items)" refers to two or three and more than three, and "and / or" is used to describe the corresponding relationship between corresponding objects, indicating that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the corresponding objects before and after are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0090] For ease of description, the system architecture of the embodiment of the present application is introduced in detail below.

[0091] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: Global System of Mobile communication (GSM) system, Code Division Multiple Access (CDMA) system, Wideband Code Division Multiple Access (WCDMA) system, General Packet Radio Service (GPRS), Long Term Evolution (LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (TDD), Universal Mobile Telecommunications System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX) communication system, Fifth Generation (5G) mobile communication system or New Radio (NR). Among them, the 5G mobile communication system can be a non-standalone (NSA) or a standalone (SA) network.

[0092] The technical solution provided in this application can also be applied to machine type communication (MTC), long term evolution-machine (LTE-M), device-to-device (D2D) network, machine-to-machine (M2M) network, Internet of Things (IoT) network or other networks. Among them, the IoT network can include, for example, the Internet of Vehicles. Among them, the communication mode in the Internet of Vehicles system is collectively referred to as vehicle to other devices (vehicle to X, V2X, X can represent anything), for example, the V2X can include: vehicle to vehicle (V2V) communication, vehicle to infrastructure (V2I) communication, vehicle to pedestrian (V2P) communication or vehicle to network (V2N) communication, etc.

[0093] The technical solution provided in this application can also be applied to future communication systems, such as the sixth generation (6G) mobile communication system, etc. This application does not limit this.

[0094] A device in a communication system can send signals to or receive signals from another device. These signals may include information, signaling, or data. The term "device" can also be replaced by an entity, network entity, communication device, communication unit, node, communication node, etc. This application uses devices as an example for description. For example, a communication system may include at least one terminal device and at least one network device. A network device can send downlink signals to a terminal device, and / or a terminal device can send uplink signals to a network device.

[0095] Figure 1 is a schematic diagram of a communication system 100 provided in an embodiment of the present application. As shown in Figure 1, communication system 100 includes a network device 110, a terminal device 120, and a terminal device 130. Network device 110 can send downlink signals to terminal devices 120 and 130, and terminal devices 120 and 130 can send uplink signals to network device 110.

[0096] It should be understood that the embodiments of the present application do not specifically limit the number of terminal devices and network devices included in the communication system. Figure 1 illustrates the example of communication 100 including one network device and two terminal devices.

[0097] The terminal device involved in the embodiments of this application is an entity on the user side that is used to receive or transmit signals. The terminal device can be a device that provides voice and / or data connectivity to the user, such as a handheld device or vehicle-mounted device with wireless connectivity. The terminal device can also be other processing devices connected to a wireless modem. The terminal device can communicate with a radio access network (RAN).

[0098] In an embodiment of the present application, the terminal device may also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent or user device, etc.

[0099] The terminal devices in the embodiments of the present application include various devices with wireless communication functions, which can be used to connect people, objects, machines, etc. The terminal devices can be widely used in various scenarios, such as: cellular communication, D2D, V2X, peer to peer (P2P), M2M, MTC, IoT, virtual reality (VR), augmented reality (AR), industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearable, smart transportation, smart city drones, robots, remote sensing, passive sensing, positioning, navigation and tracking, autonomous delivery, etc. The terminal device can be a terminal in any of the above scenarios, such as an MTC terminal, an IoT terminal, etc. The terminal device may be a user equipment (UE) of the third generation partnership project (3GPP) standard, a terminal, a fixed device, a mobile station device or a mobile device, a subscriber unit, a handheld device, a vehicle-mounted device, a wearable device, a cellular phone, a smart phone, a session initialization protocol (SIP) phone, a wireless data card, a personal digital assistant (PDA), a computer, a tablet computer, a notebook computer, a wireless modem, a handheld device (handset), a laptop computer, a computer with wireless transceiver function, a smart book, a vehicle, a satellite, a global positioning system (GPS) device, a target tracking device, an aircraft (such as a drone, a helicopter, a multi-copter, a quadcopter, or an airplane), a ship, a remote control device, a smart home device, an industrial device, or a device built into the above-mentioned device (such as a communication unit, a modem or a chip in the above-mentioned device), or other processing devices connected to a wireless modem. For the sake of convenience of description, the terminal device will be described below by taking the terminal or UE as an example.

[0100] Wearable devices, also known as wearable smart devices, are a general term for wearable devices that use wearable technology to intelligently design and develop wearable devices for daily wear, such as glasses, gloves, watches, clothing, and shoes. Wearable devices are portable devices that are worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not just hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. In a broad sense, wearable smart devices include those that are fully functional, large in size, and can achieve full or partial functions without relying on smartphones, such as smart watches or smart glasses, as well as those that only focus on a certain type of application function and need to be used in conjunction with other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.

[0101] Furthermore, terminal devices can also be end devices in the Internet of Things (IoT) system. IoT is a crucial component of future information technology development. Its primary technical feature is connecting objects to the Internet through communications technology, thereby enabling intelligent networks that interconnect humans and machines, and objects and things. IoT technology, for example, utilizes narrowband (NB) technology to achieve massive connectivity, deep coverage, and power-saving terminals.

[0102] In an embodiment of the present application, the terminal device can also be a vehicle or a whole vehicle, which can achieve communication through the Internet of Vehicles, or it can be a component located in the vehicle (for example, placed in the vehicle or installed in the vehicle), that is, a vehicle-mounted terminal device, a vehicle-mounted unit or an on-board unit (OBU).

[0103] In addition, terminal devices can also include sensors such as smart printers, train detectors, and gas stations. Their main functions include collecting data (part of the terminal devices), receiving control information and downlink data from network devices, and sending electromagnetic waves to transmit uplink data to network devices.

[0104] In this application, the device for implementing the function of a terminal device may be a terminal device; it may also be a device capable of supporting the terminal device in implementing the function, such as a chip system, a hardware circuit, a software unit, or a hardware circuit and a software unit. The device may be installed in the terminal device or may be used in conjunction with the terminal device. In the technical solutions provided in this disclosure, the technical solutions provided in this disclosure are described by taking the device for implementing the function of the terminal device as a terminal device, and the terminal device as a UE as an example.

[0105] The network device in the embodiment of the present application is an entity on the network side for transmitting or receiving signals, which can be used to convert received air frames into Internet Protocol (IP) packets, and serve as a router between the terminal device and the rest of the access network, where the rest of the access network may include an IP network, etc.

[0106] The network device in the embodiments of the present application may be a device for communicating with a terminal device, and may also be referred to as an access network device or a radio access network device. For example, the network device may be a base station. The network device in the embodiments of the present application may refer to a radio access network (RAN) node (or device) that connects a terminal device to a wireless network. Base station can broadly cover various names as follows, or replace with the following names, such as: NodeB, evolved NodeB (eNB), next generation NodeB (gNB), relay station, access point, transmission point (TRP), transmission point (TP), master station, auxiliary station, multi-standard radio (motor slide retainer, MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The base station can be a macro base station, a micro base station, a relay node, a donor node or the like, or a combination thereof. The base station can also refer to a communication unit, a modem or a chip used to be set in the aforementioned device or apparatus. The base station can also be a mobile switching center and a device that performs base station functions in D2D, V2X, and M2M communications, a network-side device in a 6G network, or a device that performs base station functions in future communication systems. The base station can support networks with the same or different access technologies. The embodiments of this application do not limit the specific technology and specific device form used by the network equipment.

[0107] Base stations can be fixed or mobile. For example, a helicopter or drone can be configured to act as a mobile base station, and one or more cells can move based on the location of the mobile base station. In other examples, a helicopter or drone can be configured to act as a device that communicates with another base station.

[0108] In some deployments, a gNB may include a centralized unit (CU) and a DU. The gNB may also include an active antenna unit (AAU). The CU implements some gNB functions, while the DU implements some gNB functions. For example, the CU is responsible for processing non-real-time protocols and services, implementing the functions of the radio resource control (RRC) and packet data convergence protocol (PDCP) layers. The DU is responsible for processing physical layer protocols and real-time services, implementing the functions of the radio link control (RLC), medium access control (MAC), and physical (PHY) layers. The AAU implements some physical layer processing functions, RF processing, and active antenna-related functions. Because RRC layer information ultimately becomes PHY layer information, or is converted from PHY layer information, in this architecture, higher-layer signaling, such as RRC layer signaling, can also be considered to be sent by the DU, or by both the DU and the CU. It is understood that a network device can be a device that includes one or more of a CU node, a DU node, or an AAU node. In addition, the CU may be classified as a network device in an access network (radio access network, RAN), or may be classified as a network device in a core network (core network, CN), which is not limited in this application.

[0109] The above-mentioned network equipment provides services for the cell, and the terminal device communicates with the cell through the transmission resources (for example, frequency domain resources, or spectrum resources) allocated by the network equipment. The cell can belong to a macro base station (for example, macro eNB or macro gNB, etc.), or it can belong to a base station corresponding to a small cell. The small cells here may include: metro cells, micro cells, pico cells, femto cells, etc. These small cells have the characteristics of small coverage and low transmission power, and are suitable for providing high-speed data transmission services.

[0110] In this application, the device for implementing the function of an access network device may be the access network device; it may also be a device capable of supporting the access network device in implementing the function, such as a chip system, a hardware circuit, a software unit, or a hardware circuit and a software unit. The device may be installed in the access network device or may be used in conjunction with the access network device. In the technical solution provided in this application, the technical solution provided in this application is described by taking the device for implementing the function of the access network device as the access network device, and the access network device as a base station as an example.

[0111] In the embodiment of the present application, a network device may include one or more cells, and each cell may include one or more transmission reception points (TRPs) or transmission points (TPs).

[0112] Optionally, in an embodiment of the present application, the network device can also communicate with the core network device.

[0113] Network devices and terminal devices can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on the water surface; they can also be deployed on aircraft, balloons and satellites in the air. The embodiments of this application do not limit the scenarios in which network devices and terminal devices are located. In addition, terminal devices and network devices can be hardware devices, or they can be software functions running on dedicated hardware, software functions running on general-purpose hardware, such as virtualization functions instantiated on a platform (e.g., a cloud platform), or entities including dedicated or general-purpose hardware devices and software functions. This application does not limit the specific forms of terminal devices and network devices.

[0114] Security is a key value proposition of cellular networks, especially as they evolve towards 2B services. Communications security not only impacts user data security but also significantly impacts the ability of industrial production to proceed normally. Therefore, as cellular networks evolve, security technologies must evolve alongside them. In cellular networks, the initial access process (also known as the random access process) is essential for terminal devices to access the network and obtain services. Because cellular networks utilize a core network-based key derivation mechanism, during the random access process, the terminal device and network equipment cannot obtain aligned keys to protect the random access process. However, some current attacks exploit this vulnerability to attack the random access process, potentially compromising the security of the terminal device and even the network. Therefore, addressing the security protection issues associated with the random access process is a crucial consideration in the evolution of cellular networks.

[0115] For ease of description, a random access process and a security activation process in a current cellular network are first introduced below with reference to FIG. 2 .

[0116] As shown in Figure 2, Figure 2 is a schematic diagram of a random access process and security activation process in a current cellular network. As shown in Figure 2, the process includes steps 0 to 9, and steps 0 to 9 are described in detail below.

[0117] It should be understood that FIG2 is described by taking the terminal device as UE, the network device as base station, and the core network device as core network (CN) as an example.

[0118] Step 0: The UE in RRC_IDLE or CM_IDLE sends a preamble of an access channel to the base station to initiate a random access procedure.

[0119] Step 0a: The UE in RRC_IDLE or CM_IDLE receives a random access response (RAR) message from the base station. The RAR message includes information such as timing advance (TA) and UL-grant.

[0120] Step 1: The UE in RRC_IDLE or CM_IDLE sends a radio resource control connection setup request (RRCsetuprequest) message to the base station using the TA and UL-grant included in the RAR message.

[0121] Step 2: After the base station receives the RRCsetuprequest message, if the base station agrees to the RRC establishment request, it returns an RRC connection configuration (RRCsetup) message to the UE in RRC_IDLE, CM_IDLE. The RRCsetup message includes the configuration of the radio signaling bearer (SRB0), the physical layer and the media access control (MAC) configuration parameters.

[0122] Step 2a: After the UE in RRC_IDLE or CM_IDLE receives the RRC connection configuration parameters, the UE enters RRC_CONNECTED and sends an RRC connection configuration complete (RRCsetupcomplete) message to the base station. The message includes the non-access stratum (NAS) message sent by the UE to the AMF, such as the registration request message, based on other information used by the base station to select the core network.

[0123] Step 3: The base station sends an initial UE message to the CN, which includes the NAS message sent by the UE to the base station in step 2a to the CN.

[0124] Steps 4 & 4a: After processing the NAS message received from the base station, the CN sends some response NAS messages to the UE through the base station.

[0125] Step 5 & 5a: After receiving the NAS response message from the CN, the UE continues to respond to the message, and then sends a response message of the NAS response message to the CN through the base station.

[0126] Step 6: After receiving the NAS response message in step 5a, the CN performs relevant checks and processing. For the registration process, the exchange of NAS messages in steps 2a, 3, 4, and 5 completes the authentication and authorization of both the UE and the network. The CN then sends an Initial UE Context Establishment Request message to the base station, which contains key information for secure communication with the UE, security algorithms supported by the network (encryption algorithm, integrity protection algorithm, etc.), and may also include the UE's wireless capabilities.

[0127] Steps 7 & 7a: The base station sends a security activation command to the UE. Upon receipt, the UE verifies the message and, if verified, derives the keys for signaling, data encryption, and security, which are used to protect subsequent signaling and data transmission, respectively. The UE also sends a security activation complete message to the base station, informing it that air interface security has been activated.

[0128] Steps 8 & 8a: The base station may reconfigure the air interface transmission parameters. The reconfiguration message and the reconfiguration completion message are protected by encryption and integrity of the base station and UE respectively.

[0129] Step 9: The base station sends an initial UE context setup completion message to the CN. The entire initial link establishment process is completed, and subsequent data and signaling transmissions between the UE and the base station will be securely protected.

[0130] In the random access and security activation processes described above, the UE and base station align security keys only after steps 7 and 8. These keys are used to protect signaling and data transmission after steps 7 and 8. However, messages sent between the UE and base station before steps 7 and 8 are not protected and are vulnerable to attacks.

[0131] In view of this, an embodiment of the present application provides a method for data transmission, which can securely protect data transmitted during a random access process.

[0132] Figure 3 is a schematic flow chart of a data transmission method provided by an embodiment of the present application. As shown in Figure 3, the method may include steps 310-380, and steps 310-380 are described in detail below.

[0133] Step 310: The first communication device receives a first downlink reference signal sent by the second communication device.

[0134] The first communication device is a chip of a terminal device, such as a baseband chip. The first communication device receiving the first downlink reference signal sent by the second communication device may be the baseband chip of the terminal device receiving the first downlink reference signal sent by the second communication device, that is, the first downlink reference signal serves as an input to the baseband chip of the terminal device.

[0135] Step 320: The first communications device obtains a first key according to the first downlink reference signal.

[0136] In the embodiment of the present application, after the first communication device receives the first downlink reference signal sent by the second communication device, the first key can be obtained according to the first downlink reference signal.

[0137] In an embodiment of the present application, before step 320, the first communication device will also receive system information broadcast by the second communication device, and the system information includes but is not limited to the above-mentioned measurement configuration information and quantization configuration information. For example, the measurement configuration information may include but is not limited to: which characteristics of the channel are used for channel key generation, such as channel state information (CSI), really simple syndication (RSS), angle, etc. The quantization configuration information may include but is not limited to: the merging method of measurement results on different resource elements (RE) or resource blocks (RB), the number of bits generated in a single time, the method / threshold for discarding bits in quantization (different values ​​can be configured according to different signal-to-noise ratios), etc. For example, the above-mentioned merging method may include but is not limited to: separate generation, or merging first and then generating, or generating independently first and then merging.

[0138] Optionally, the system information may also include: reference signal configuration information, information negotiation configuration information, privacy amplification configuration information, etc. For example, the reference signal configuration information may include but is not limited to: downlink reference signal configuration information (including time domain, frequency domain position and other information), uplink reference signal configuration information, preamble configuration information, time constraints, etc., wherein the uplink reference signal and the downlink signal have a pairing relationship, and the preamble and the uplink reference signal have a corresponding relationship. The information negotiation configuration information may include but is not limited to: the number of check bits, etc. The privacy amplification configuration information may include but is not limited to: the number of bits of HASH operation, etc.

[0139] In one implementation, the first communication device measures the first downlink reference signal according to the measurement configuration information received above to obtain the measurement result of the first downlink reference signal, and quantizes the measurement result of the first downlink reference signal according to the quantization configuration information received above to obtain the first key.

[0140] Step 330: The first communication device sends a first uplink reference signal to the second communication device.

[0141] Optionally, the first communication device may further send a preamble code to the second communication device when sending the first uplink reference signal to the second communication device.

[0142] Step 340: The second communication device obtains a second key according to the first uplink reference signal.

[0143] In the embodiment of the present application, after the second communication device receives the first uplink reference signal sent by the first communication device, the second communication device may further obtain the second key according to the first uplink reference signal.

[0144] In one implementation, the second communication device measures the first uplink reference signal according to the measurement configuration information to obtain a measurement result of the first uplink reference signal, and quantizes the measurement result of the first uplink reference signal according to the quantization configuration information to obtain the second key.

[0145] Step 350: The first communication device receives a first message sent by the second communication device, where the first message includes verification information of the second key.

[0146] In the embodiment of the present application, after the second communication device obtains the second key, it can generate verification information of the second key based on the second key, and send the verification information of the second key to the first communication device through the first message.

[0147] There are many ways to generate the verification information of the second key, which is not specifically limited in the embodiments of the present application. In one possible implementation, the second key can be used as input, and a certain operation is performed to obtain a result, which can be used as the verification information of the second key, such as a cyclic redundancy check.

[0148] It should be understood that the number of bits of the verification information of the second key generated by the second communication device can be determined according to the configuration information of the information negotiation broadcasted by the second communication device to the first communication device.

[0149] As an example, the first message is a RAR message.

[0150] Step 360: The first communication device determines a third key based on the verification information of the first key and the second key.

[0151] There are many ways to implement the first communication device to determine the third key based on the verification information of the first key and the second key. The embodiments of the present application do not specifically limit this. Several possible implementation methods are introduced below.

[0152] Example 1: The first communication device determines that the first key and the second key are aligned according to verification information of the first key and the second key, and determines the first key as the third key.

[0153] It should be understood that the first communication device can generate verification information for the first key based on the first key. If the verification information for the first key is the same as the verification information for the second key, it can be determined that the first key and the second key are aligned. In one possible implementation, the first communication device uses the first key as input, performs a certain operation (the same operation performed by the second communication device to obtain the verification information for the second key), and obtains a result, which can be used as the verification information for the first key.

[0154] It should also be understood that the alignment of the first key and the second key can be understood as the first key and the second key being the same or consistent.

[0155] Example 2: The first communication device determines that the first key and the second key are aligned based on verification information of the first key and the second key, calculates the first key to obtain a fourth key, and determines the fourth key as the third key.

[0156] It should also be understood that the present application does not specifically limit the algorithm used to calculate the first key, and any algorithm that can achieve privacy amplification of the first key can be used. In one implementation, the algorithm is a hash algorithm.

[0157] As an example, in a specific implementation, one way to amplify privacy is to ensure that the length of the third key is less than or equal to the length of the first key minus the number of bits of the check information in the first message.

[0158] Example 3: The first communication device determines that the first key and the second key are not aligned based on the verification information of the first key and the second key, the first communication device re-determines the fifth key, and determines the third key based on the verification information of the fifth key and the sixth key.

[0159] That is, the first communications device determines that the first key and the second key are not aligned based on the verification information of the first key and the second key. The first communications device retransmits the second uplink reference signal to the second communications device on the resources indicated by the first message, receives the second downlink reference signal retransmitted by the second communications device, and obtains the fifth key based on the second downlink reference signal. The first communications device also receives verification information of the sixth key sent by the second communications device, the sixth key being obtained by the second communications device based on the received second uplink reference signal. The first communications device determines the third key based on the verification information of the fifth and sixth keys.

[0160] The process for the first communication device to determine the third key based on the verification information of the fifth and sixth keys can refer to the process for determining the third key based on the verification information of the first and third keys. For example, if the fifth key and the sixth key are aligned based on the verification information of the fifth and sixth keys, the fifth key is determined to be the third key, or an eleventh key is calculated from the fifth key and determined to be the third key. For details, please refer to the process for determining the third key based on the verification information of the first and third keys, and will not be repeated here.

[0161] It should be understood that the above-mentioned misalignment between the first key and the second key can be understood as the first key and the second key being different or inconsistent.

[0162] Example 4: The first communication device determines that the first key and the second key are not aligned based on the verification information of the first key and the second key. The first communication device decodes the first key according to the first RV of the first coding matrix received from the second communication device to obtain the seventh key, and determines the third key based on the seventh key and the verification information of the second key.

[0163] It should be understood that the first encoding matrix is ​​determined by the second communication device according to the second key.

[0164] For example, the first communication device determines that the seventh key is aligned with the second key according to verification information of the seventh key and the second key, and determines the seventh key as the third key.

[0165] For another example, the first communication device determines that the seventh key and the second key are not aligned based on the verification information of the seventh key and the second key, and also requests the second RV of the first coding matrix from the second communication device, decodes the first key based on the first RV and the second RV of the first coding matrix to obtain the eighth key, and determines the third key based on the eighth key and the verification information of the second key.

[0166] It should be understood that the process by which the first communication device determines the third key based on the verification information of the eighth key and the second key is the same as the process by which the third key is determined based on the verification information of the seventh key and the second key. For example, if the first communication device determines that the eighth key and the second key are aligned based on the verification information of the eighth key and the second key, the eighth key may be determined as the third key. For another example, if the first communication device determines that the eighth key and the second key are not aligned based on the verification information of the eighth key and the second key, the first communication device may again request another RV of the first coding matrix from the second communication device and repeat the above process.

[0167] In the above example 4, if the number of times the first communication device requests the RV of the first coding matrix from the second communication device reaches the maximum number of requests, it can fall back to the above example 3, and the first communication device and the second communication device respectively re-determine the key based on the new reference signal, and determine the third key according to the method of the above example 3.

[0168] Step 370: The first communication device securely protects data transmitted between the first communication device and the second communication device according to the third key.

[0169] It should be understood that the data transmitted between the first communication device and the second communication device may include data and signaling transmitted between the first and second communication devices.

[0170] It should be understood that the above security protection may include but is not limited to: encrypting and / or integrity protecting the data transmitted between the first communication device and the second communication device.

[0171] It should be noted that the embodiment of the present application does not specifically limit the execution order of steps 310-370.

[0172] In the above technical solution, the first communication device negotiates an aligned key with the second communication device during the random access process, and uses the aligned key to securely protect the data transmitted between the first communication device and the second communication device. In this way, the random access process can be protected, preventing attackers from attacking the random access process of the first communication device, thereby protecting the security of the first communication device and even the second communication device.

[0173] Step 380: The second communication device determines a ninth key based on the second key, and securely protects data transmitted between the second communication device and the first communication device based on the ninth key.

[0174] In an embodiment of the present application, the method by which the second communication device determines the ninth key based on the second key is similar to the method by which the first communication device determines the third key based on the first key. In one example, if the first key and the second key are aligned, the second communication device determines the second key as the ninth key. In another example, if the first key and the second key are aligned, the second communication device calculates the second key to obtain the tenth key, and determines the tenth key as the ninth key. In another example, if the first key and the second key are not aligned, the second communication device determines the sixth key based on the second uplink reference signal sent by the first communication device, and if the sixth key is aligned with the fifth key determined by the first communication device based on the second downlink reference signal, the second communication device can determine the sixth key as the ninth key, or calculate the sixth key to obtain the twelfth key, and determine the twelfth key as the ninth key.

[0175] In an embodiment of the present application, after determining the third key aligned with the ninth key, the first communication device sends a message, such as Msg3, to the second communication device. After receiving the message, the second communication device can determine, based on the message, that the ninth key determined by it is aligned with the third key determined by the first communication device. At this point, the second communication device can securely protect data transmitted between it and the first communication device based on the ninth key.

[0176] It should be understood that the above security protection may include but is not limited to: encrypting and / or integrity protecting the data transmitted between the second communication device and the first communication device.

[0177] Below, in conjunction with FIG4, a specific implementation process of the data transmission method provided in an embodiment of the present application is described in detail. It should be understood that the example of FIG4 is only to help those skilled in the art understand the embodiment of the present application, and is not intended to limit the application embodiment to the specific numerical values ​​or specific scenarios illustrated in FIG4. Those skilled in the art can obviously make various equivalent modifications or changes based on the following example given in FIG4, and such modifications and changes also fall within the scope of the embodiment of the present application.

[0178] Figure 4 is a schematic flow chart of another data transmission method provided by an embodiment of the present application. As shown in Figure 4, the method may include steps 410-490, which are described in detail below.

[0179] It should be understood that, for the convenience of description, FIG4 is illustrated by taking the first communication device as a UE and the second communication device as a base station as an example.

[0180] Step 410: The base station broadcasts system information, where the system information includes configuration information related to secure random access.

[0181] In an embodiment of the present application, a base station may broadcast system information to other devices in the network, where the system information includes configuration information related to a secure random access process. As an example, the configuration information related to the secure random access process is used to generate a symmetric or aligned key between the base station and the UE during the random access process.

[0182] In the above technical solution, the base station can use system information to send a new configuration message for key generation to the UE, so that the UE and the base station can subsequently align the parameters for key generation.

[0183] For example, the configuration information related to the secure random access process may include, but is not limited to, reference signal configuration information, measurement configuration information, quantization configuration information, information negotiation configuration information, privacy amplification configuration information, etc. For a specific description of these configuration information, please refer to the description in step 320 and will not be repeated here.

[0184] Step 415: The base station sends a downlink reference signal (DLreferencesignal) to the UE.

[0185] Step 420: The UE receives a downlink reference signal sent by the base station, and measures and quantizes the downlink reference signal according to the system information broadcast by the base station to obtain the key key1.

[0186] In an embodiment of the present application, a base station may send a downlink reference signal to a UE. After receiving the downlink reference signal sent by the base station, the UE may measure the downlink reference signal according to measurement configuration information in system information broadcast by the base station. The UE may also quantize the measurement result according to quantization configuration information in the system information broadcast by the base station to obtain a key key1. Specifically, the UE may quantize the measurement result into a bit stream consisting of a series of 0s and 1s, and the bit stream consisting of a series of 0s and 1s constitutes the key key1.

[0187] The embodiment of the present application does not specifically limit the time when the UE measures and quantizes the downlink reference signal based on the system information broadcast by the base station to obtain the key key1. In one example, the UE can measure and quantize the received downlink reference signal within a period of time before initiating a random access process to the base station (for example, sending a preamble) to obtain the key key1. In another example, the UE can also measure and quantize the received downlink reference signal at the most recent time point before initiating a random access process to the base station (for example, sending a preamble) to obtain the key key1. In this way, the accuracy of measurement and quantization can be improved.

[0188] Step 425: The UE sends a preamble and an uplink reference signal (UL reference signal) at a corresponding position to the base station according to the system information broadcast by the base station.

[0189] In the embodiment of the present application, the UE may send an uplink reference signal and a preamble at a corresponding position to the base station according to the configuration information of the reference signal in the system information broadcast by the base station.

[0190] In the above technical solution, the UE can send the uplink reference signal and preamble together, so that the base station can measure the uplink reference signal after estimating the TA using the preamble, making the base station's measurement result of the uplink reference signal more accurate.

[0191] Step 430: The base station measures and quantizes the received uplink reference signal to obtain the key key2.

[0192] In the embodiment of the present application, after receiving the preamble and the uplink reference signal at the corresponding position sent by the UE, the base station may measure and quantize the uplink reference signal to obtain the key key2. It should be understood that the method by which the base station obtains the key key2 is similar to the method by which the UE obtains the key key1. Specifically, the base station may measure the uplink reference signal based on the broadcasted measurement configuration information, and may also quantize the measurement result based on the broadcasted quantization configuration information to obtain the key key2.

[0193] Step 435: The base station sends a RAR message to the UE. The RAR message may include verification information of the key key2.

[0194] In the embodiment of the present application, after obtaining the key key2, the base station may calculate verification information of the key key2, include the verification information of the key2 in a RAR message, and send the message to the UE.

[0195] There are various ways to generate verification information for the key2, which are not specifically limited in the present embodiment. In one possible implementation, key2 can be used as input, and a certain operation can be performed to obtain a result, which can be used as the verification information for key2. It should be understood that the number of bits in the verification information for key2 generated by the base station can be determined based on the configuration information negotiated during its broadcast.

[0196] For example, a cyclic redundancy check (CRC) may be used as the verification information of the key2.

[0197] In the above technical solution, the base station can use the RAR message to carry the verification information of the key key2, which does not require adding new dedicated information and reconciliation messages, thereby reducing the system delay and overhead.

[0198] Step 440: The UE verifies the verification information of the key key2 according to the key key1.

[0199] In an embodiment of the present application, after the UE receives the verification information of the key key2 sent by the base station, it verifies the received verification information of the key key2 according to the key key1 generated by itself. Specifically, in one possible implementation method, the UE can use key1 as input according to the method in which the base station generates the verification information of key2 in step 435, perform a certain operation to obtain a result, and the result can be used as the verification information of key1, and determine whether the verification information of key1 and the verification information of key2 are the same. If the verification information of key1 and the verification information of key2 are the same, it can be understood that the verification information of key2 has passed the verification of the UE; if the verification information of key1 and the verification information of key2 are not exactly the same, it can be understood that the verification information of key2 has not passed the verification of the UE.

[0200] It should be understood that the number of bits of the verification information of key1 generated by the UE is the same as the number of bits of the verification information of key2. Specifically, the UE can determine the number of bits of the verification information of key1 based on the configuration information negotiated by the information broadcast by the base station.

[0201] As an example, the UE may also determine whether the key key1 generated by the UE and the key key2 generated by the base station are aligned based on whether the verification information of key2 passes verification.

[0202] Case 1 (step 445-step 450):

[0203] Step 445: The UE determines that the key key1 is aligned with the key key2.

[0204] As an example, if the verification information of key1 is the same as the verification information of key2, the verification information of key2 passes the verification of the UE, and the UE can determine that the keys key1 and key2 are aligned.

[0205] Step 450: The UE and the base station may use the aligned key1 and key2 to perform encryption and / or integrity protection on subsequently transmitted signaling or data.

[0206] As an example, if the UE determines that key 1 and key 2 are aligned, the UE may use key 1 to encrypt and / or integrity protect the signaling and / or data of subsequent uplink transmissions. Similarly, the base station may also use key 2 to encrypt and / or integrity protect the signaling and / or data of subsequent downlink transmissions.

[0207] It should be understood that the signaling and / or data of the above-mentioned subsequent uplink transmission may be the signaling and / or data of the uplink transmission in the random access process (for example, steps 1 to 7 of Figure 2), or may be the signaling and / or data of the uplink transmission in other processes, and the signaling and / or data of the above-mentioned subsequent downlink transmission may be the signaling and / or data of the downlink transmission in the random access process (for example, steps 1 to 7 of Figure 2), or may be the signaling and / or data of the downlink transmission in other processes. The embodiments of the present application do not make specific limitations on this.

[0208] Optionally, since the verification information of key2 sent by the base station to the UE is not protected, once it is used by an illegal person, key2 may become unavailable. In some embodiments, in order to prevent the verification information of key2 sent by the base station from being obtained by other illegal persons, the base station can also perform a hash operation on key2 according to the number of bits of the HASH operation in the privacy amplification configuration information it broadcasts, and obtain the key2 indicating the number of bits. (1) and use key2 (1) The signaling and / or data of subsequent downlink transmissions are encrypted and / or integrity protected. Similarly, the UE can also perform a hash operation on key1 based on the number of bits of the HASH operation in the privacy amplification configuration information broadcast by the base station to obtain the key1 indicating the number of bits. (1) and use key1 (1) Perform encryption and / or integrity protection on the signaling and / or data of subsequent uplink transmissions.

[0209] It should be understood that key1 (1) Indicates that based on key1, key1 is hashed to obtain key1 (1) .key2 (1) Indicates that based on key2, key2 is hashed to obtain key2 (1) .

[0210] Case 2 (steps 455 to 490):

[0211] Step 455: The UE determines that there is no alignment between the key key1 and the key key2.

[0212] As an example, if the verification information of key1 is not the same as or not completely the same as the verification information of key2, it means that the verification information of key2 has not passed the verification of the UE, and the UE may determine that the keys key1 and key2 are not aligned.

[0213] Step 460: The UE continues to send the uplink reference signal on the resources indicated by the RAR message.

[0214] In the embodiment of the present application, after determining that key1 and key2 are not aligned, the UE can resend the uplink reference signal on the resources indicated by the RAR message. This can avoid the UE from resending the preamble and uplink reference signal from step 425, thereby reducing the latency of the access process.

[0215] Step 465: The base station measures and quantizes the re-received uplink reference signal to obtain the key key3.

[0216] In this embodiment of the present application, after receiving the uplink reference signal retransmitted by the UE on the resources indicated by the RAR message, the base station may measure and quantize the re-received uplink reference signal to obtain the key key3. It should be understood that the process of determining the key key3 is similar to the process of determining the key key2 in step 430. For details, please refer to the description of step 430 and will not be repeated here.

[0217] Step 470: The UE continues to measure and quantize the downlink reference signal sent by the base station to obtain the key key4.

[0218] In the embodiment of the present application, the base station periodically sends a downlink reference signal to the UE, and the UE can continue to measure and quantize the downlink reference signal sent by the base station to obtain the key key4.

[0219] Step 475: The base station sends a RAR message to the UE. The RAR message may include verification information of the key key3.

[0220] Step 480: The UE verifies the verification information of the key key3 according to the key key4.

[0221] It should be understood that step 480 corresponds to step 440. Please refer to the description in step 440 for details, which will not be repeated here.

[0222] Step 485: The UE determines that the key key4 is aligned with the key key3.

[0223] It should be understood that step 485 corresponds to step 445. Please refer to the description in step 445 for details, which will not be repeated here.

[0224] Step 490: The UE and the base station may use the aligned key4 and key3 to perform encryption and / or integrity protection on subsequently transmitted signaling or data.

[0225] It should be understood that step 490 corresponds to step 450. Please refer to the description in step 450 for details, which will not be repeated here.

[0226] Optionally, since the verification information of key3 sent by the base station to the UE is not protected, once it is used by an illegal person, key3 may become unavailable. In some embodiments, in order to prevent the verification information of key3 sent by the base station from being obtained by other illegal persons, the base station can also perform a hash operation on key3 according to the number of bits of the HASH operation in the privacy amplification configuration information it broadcasts, and obtain the key3 indicating the number of bits. (1) and use key3 (1) The signaling and / or data of subsequent downlink transmissions are encrypted and / or integrity protected. Similarly, the UE can also perform a hash operation on key4 according to the number of bits of the HASH operation in the privacy amplification configuration information broadcast by the base station to obtain the key4 indicating the number of bits. (1) and use key4 (1) Perform encryption and / or integrity protection on the signaling and / or data of subsequent uplink transmissions.

[0227] It should be understood that key3 (1) Indicates that based on key3, key3 is hashed to obtain key3 (1) .key4 (1) Indicates that based on key4, key4 is hashed to obtain key4 (1) .

[0228] It should be noted that if the result of the UE verifying the verification information of key key3 based on key key4 in step 480 is that key4 and key3 are not aligned, then the UE and the base station can continue to repeat steps 460-490 until the UE and the base station determine the aligned keys.

[0229] Optionally, the base station may also set a maximum number of limits. If the number of retries exceeds the maximum number, it will fall back to the normal RACH or reselect another cell.

[0230] In the above technical solution, by enhancing the uplink and downlink signal measurement and quantization of the UE and the base station during the random access process, working keys are obtained respectively, and then the signaling and / or data in the random access process are encrypted and integrity protected, thereby achieving secure random access of the UE and preventing attackers from attacking the random access process.

[0231] Below, in conjunction with FIG5, another specific implementation process of the method for data transmission provided by the embodiment of the present application is described in detail. It should be understood that the example of FIG5 is only to help those skilled in the art understand the embodiment of the present application, and is not intended to limit the embodiment of the application to the specific numerical values ​​or specific scenarios illustrated in FIG5. It is obvious that those skilled in the art can make various equivalent modifications or changes based on the following example given in FIG5, and such modifications and changes also fall within the scope of the embodiment of the present application.

[0232] Figure 5 is a schematic flow chart of another data transmission method provided by an embodiment of the present application. As shown in Figure 5, the method may include steps 510-580, and steps 510-580 are described in detail below.

[0233] It should be understood that, for the convenience of description, FIG5 is illustrated by taking the first communication device as a UE and the second communication device as a base station as an example.

[0234] Step 510: The base station broadcasts system information, where the system information includes configuration information related to secure random access.

[0235] For example, the above-mentioned configuration information related to the secure random access may include but is not limited to: reference signal configuration information, measurement configuration information, quantization configuration information, information negotiation configuration information, privacy amplification configuration information, etc. Among them, the information negotiation configuration information may include but is not limited to: the number of check bits, the encoding method used for the negotiation information (such as low-density parity check code (LDPC), Polar or other encoding), whether multiple RV versions of the check bit are supported, the total number of RV versions, etc.

[0236] It should be understood that the above-mentioned other configuration information (for example, reference signal configuration information, measurement configuration information, quantization configuration information, and privacy amplification configuration information) is the same as the configuration in step 410. For specific descriptions of these configuration information, please refer to the description in step 410 and will not be repeated here.

[0237] Step 515: The base station sends a downlink reference signal to the UE.

[0238] Step 520: The UE receives a downlink reference signal sent by the base station, and measures and quantizes the downlink reference signal according to the system information broadcast by the base station to obtain the key key1.

[0239] Step 525: The UE sends a preamble and an uplink reference signal at a corresponding position to the base station according to the system information broadcast by the base station.

[0240] Step 530: The base station measures and quantizes the received uplink reference signal to obtain the key key2.

[0241] Step 535: The base station sends a RAR message to the UE. The RAR message may include verification information of the key key2 and a redundant version (RV) of a coding check matrix.

[0242] It should be understood that the verification information of the key key2 contained in the RAR message sent by the base station to the UE in step 535 is the same as the verification information of the key key2 in step 435. For details, please refer to the description in step 435 and will not be repeated here.

[0243] In step 535, in addition to sending verification information of the key key2 to the UE via a RAR message, the base station also sends an additional RV of the coding check matrix. The coding check matrix can be determined based on the key key2 generated by the base station, and is used to correct errors in the key key1 generated by the UE so that the key key1 generated by the UE can be aligned with the key2 generated by the base station. In the embodiment of the present application, since the coding check matrix is ​​large, in order to reduce the large signaling overhead caused by transmitting the coding check matrix, the base station can send an RV version of the coding check matrix to the UE via a RAR message. The RV version of the coding check matrix can be understood as a part of the coding check matrix.

[0244] In the above technical solution, by introducing the coding information mechanism of different RV versions, coding information (eg, coding check matrix) can be applied for one by one, thus avoiding the large signaling overhead caused by sending the entire coding information.

[0245] Step 540: The UE decodes the key key1 according to an RV version of the code check matrix to obtain key1 (2) , and according to key1 (2) Verify the verification information of key key2.

[0246] In the embodiment of the present application, after the UE receives an RV version of the code check matrix sent by the base station, it can decode the key key1 generated by it based on the RV version of the code check matrix to obtain key1 (2)The UE can also use key1 (2) Verify the verification information of key2 to determine the key1 obtained by the UE (2) Whether the key is aligned with the key key2 generated by the base station. The following describes the situation 1 and situation 2 respectively.

[0247] It should be understood that the UE uses key1 (2) The process of verifying the verification information of the key key2 is similar to the process of verifying the verification information of the key key2 by the UE according to key1 in step 440. For details, please refer to the description in step 440 and will not be repeated here.

[0248] It should be understood that key1 (2) Indicates that based on key1, key1 is decoded to obtain key1 (2) .

[0249] Case 1 (step 545-step 550):

[0250] Step 545: UE determines key1 (2) Aligned with key key2.

[0251] As an example, if key1 (2) If the verification information of key1 is the same as the verification information of key2, then the verification information of key2 has passed the verification of UE, and UE can determine the key1 (2) Aligned with key key2.

[0252] Step 550: The UE and the base station can use the aligned key1 (2) and key2 to encrypt and / or integrity protect the subsequently transmitted signaling or data.

[0253] As an example, if the UE determines the key key1 (2) Aligned with key2, UE can use key1 (2) The signaling and / or data of subsequent uplink transmissions are encrypted and / or integrity protected. Similarly, the base station can also use key2 to encrypt and / or integrity protect the signaling and / or data of subsequent downlink transmissions.

[0254] Optionally, in some embodiments, in order to prevent the verification information of key2 sent by the base station from being obtained by other illegal persons, the base station may also perform a hash operation on key2 according to the number of bits of the HASH operation in the privacy amplification configuration information it broadcasts, and obtain the key2 indicating the number of bits. (1) and use key2 (1)The signaling and / or data of subsequent downlink transmissions are encrypted and / or integrity protected. Similarly, the UE can also perform encryption and / or integrity protection on key1 according to the number of bits of the HASH operation in the privacy amplification configuration information broadcast by the base station. (2) Perform hash operation to get the key1 indicating the number of bits (3) and use key1 (3) Perform encryption and / or integrity protection on the signaling and / or data of subsequent uplink transmissions.

[0255] It should be understood that key1 (3) Indicates that in key1 (2) Based on key1 (2) Perform hash operation to get key1 (3) .

[0256] Case 2 (steps 555 to 580):

[0257] Step 555: UE determines key1 (2) There is no alignment between key key2.

[0258] As an example, if key1 (2) If the verification information of key1 is different from or not completely the same as the verification information of key2, it means that the verification information of key2 has not passed the verification of UE. UE can determine the key1. (2) There is no alignment between key key2.

[0259] Step 560: The UE sends a request message for other RVs of the coding check matrix to the base station on the resources indicated by the RAR message.

[0260] In the embodiment of the present application, the UE determines the key key1 (2) After there is no alignment between and key key2, a request message for other RVs of the coding check matrix may be sent on the resources indicated by the RAR message. The request message for other RVs of the coding check matrix is ​​used to request other RVs of the coding check matrix from the base station.

[0261] Step 565: The base station sends a RAR message to the UE, where the RAR message includes other RVs of the coding check matrix.

[0262] In the embodiment of the present application, after receiving a request message for other RVs of the coding check matrix sent by the UE, the base station may send other RVs of the coding check matrix to the UE.

[0263] Step 570: The UE combines different RVs of the code check matrix and decodes the key key1 based on the combined RV to obtain key1 (4) , and according to key1 (4)Verify the verification information of key key2.

[0264] In the embodiment of the present application, after the UE receives the other RV of the coding check matrix sent by the base station, it can merge the RV with the RV of the coding check matrix received in step 540, and decode the key key1 based on the merged RV to obtain key1 (4) , and according to key1 (4) Verify the verification information of key key2.

[0265] It should be understood that the UE uses key1 (4) The process of verifying the verification information of the key key2 is similar to the process of verifying the verification information of the key key2 by the UE according to key1 in step 440. For details, please refer to the description in step 440 and will not be repeated here.

[0266] Step 575: UE determines key1 (4) Aligned with key key2.

[0267] As an example, if key1 (4) If the verification information of key1 is the same as the verification information of key2, the verification information of key2 has passed the verification of UE, and UE can determine the key key1. (4) Aligned with key key2.

[0268] Step 580: The UE and the base station can use the aligned key1 (4) and key2 to encrypt and / or integrity protect the subsequently transmitted signaling or data.

[0269] As an example, if the UE determines the key key1 (4) Aligned with key2, UE can use key1 (4) The signaling and / or data of subsequent uplink transmissions are encrypted and / or integrity protected. Similarly, the base station can also use key2 to encrypt and / or integrity protect the signaling and / or data of subsequent downlink transmissions.

[0270] Optionally, in some embodiments, in order to prevent the verification information of key2 sent by the base station from being obtained by other illegal persons, the base station may also perform a hash operation on key2 according to the number of bits of the HASH operation in the privacy amplification configuration information it broadcasts, and obtain the key2 indicating the number of bits. (1) and use key2 (1) The signaling and / or data of subsequent downlink transmissions are encrypted and / or integrity protected. Similarly, the UE can also perform encryption and / or integrity protection on key1 according to the number of bits of the HASH operation in the privacy amplification configuration information broadcast by the base station. (4)Perform hash operation to get the key1 indicating the number of bits (5) and use key1 (5) Perform encryption and / or integrity protection on the signaling and / or data of subsequent uplink transmissions.

[0271] It should be understood that key1 (5) Indicates that in key1 (4) Based on key1 (4) Perform hash operation to get key1 (5) .

[0272] Optionally, in some embodiments, if the UE determines the key key1 (4) If there is no alignment between the key key1 and the key key2, the UE and the base station may continue to repeatedly perform steps 560 to 570, and the UE continues to request other RVs of the coding check matrix from the base station until the key determined by the UE and the key determined by the base station are aligned with each other.

[0273] It should be noted that, in an embodiment of the present application, the base station may also indicate the maximum number of RVs in the broadcast system information. If the number of other RVs of the coding check matrix that the UE requests from the base station reaches the maximum number of RVs indicated in the system information, the UE cannot continue to request other RVs of the coding check matrix from the base station, but needs to continue to send the uplink reference signal on the resource indicated by the RAR message. The base station measures and quantizes the re-received uplink reference signal to obtain a new key. The UE continues to measure and quantize the downlink reference signal sent by the base station to obtain a new key. The UE verifies the key re-obtained by the base station and the key re-obtained by itself to determine whether the key re-obtained by the base station and the key re-obtained by the UE are aligned. That is, when the number of other RVs of the coding check matrix that the UE requests from the base station reaches the maximum number of RVs indicated in the system information, the UE needs to repeatedly perform steps 460-480 in Figure 4 until the key determined by the UE and the key determined by the base station are aligned with each other.

[0274] In the above technical solution, based on the method shown in FIG4 , in the link of key alignment, information reconciliation based on coding can be considered, and different RVs of coding check matrices can be introduced to improve the efficiency of information reconciliation.

[0275] The method provided in the embodiments of the present application is described in detail above with reference to Figures 1 to 5 . Below, the apparatus provided in the embodiments of the present application is described in detail with reference to Figures 6 to 8 . It should be understood that the description of the apparatus embodiment corresponds to the description of the method embodiment. Therefore, for matters not described in detail, reference can be made to the method embodiment above, and for the sake of brevity, they will not be repeated here.

[0276] Figure 6 is a schematic block diagram of a communication device 600 provided in an embodiment of the present application. As shown in Figure 6, the device 600 may include a transceiver unit 610 and a processing unit 620, wherein the transceiver unit 610 can communicate with the outside, for example, data / information received from the outside can be input to the processing unit, and for example, data / information processed by the processing unit can be output to the outside. The transceiver unit 610 can also be referred to as a communication interface or a communication unit. The processing unit 620 is used to process data / information so that the function of the first communication device in the method shown in Figures 3 to 5 above is realized, or the function of the second communication device in the method shown in Figures 3 to 5 above is realized.

[0277] In one possible implementation, the device 600 may be the first communication device in the method shown in Figures 3-5 above, or may be a chip used to implement the functions of the first communication device in the method shown in Figures 3-5 above. Specifically, the device 600 may implement the process executed by the first communication device in the method shown in Figures 3-5 above, wherein the transceiver unit 610 and the processing unit 620 are used to perform operations related to the processing of the first communication device in the above method process.

[0278] The transceiver unit 610 is configured to receive a first downlink reference signal, send a first uplink reference signal, and receive a first message, where the first message includes verification information of a second key obtained by the second communication device based on the received first uplink reference signal.

[0279] The processing unit 620 is configured to obtain a first key according to the first downlink reference signal, determine a third key according to verification information of the first key and the second key, and perform security protection on data transmitted with the second communication device according to the third key.

[0280] Optionally, when sending the first uplink reference signal, the transceiver unit 610 is further configured to send a preamble code.

[0281] Optionally, before the transceiver unit 610 receives the first downlink reference signal, the transceiver unit 610 is also used to receive system information, which includes measurement configuration information and quantization configuration information; the processing unit 620 is also used to measure the first downlink reference signal according to the measurement configuration information to obtain the measurement result of the first downlink reference signal, and quantize the measurement result of the first downlink reference signal according to the quantization configuration information to obtain the first key.

[0282] Optionally, the processing unit 620 is further used to determine the alignment of the first key and the second key based on the verification information of the first key and the second key; determine the first key as the third key; or calculate the first key to obtain a fourth key, and determine the fourth key as the third key.

[0283] Optionally, the processing unit 620 is further used to determine that the first key and the second key are not aligned based on the verification information of the first key and the second key; the transceiver unit 610 is further used to send a second uplink reference signal on the resources indicated by the first message and receive a second downlink reference signal; the processing unit 620 is further used to obtain a fifth key based on the second downlink reference signal; the transceiver unit 610 is further used to receive verification information of the sixth key, and determine the third key based on the verification information of the fifth key and the sixth key.

[0284] Optionally, the first message also includes a first redundant version RV of the first coding matrix, and the processing unit 620 is further used to decode the first key according to the first RV of the first coding matrix to obtain a seventh key, and determine the third key based on the verification information of the seventh key and the second key.

[0285] Optionally, the processing unit 620 is further configured to determine, based on verification information of the seventh key and the second key, that the seventh key is aligned with the second key, and determine the seventh key as the third key.

[0286] Optionally, the processing unit 620 is further used to determine that the seventh key and the second key are not aligned based on the verification information of the seventh key and the second key; the transceiver unit 610 is further used to send an RV request message, which is used to request the second RV of the first coding matrix; the processing unit 620 is also used to decode the first key according to the first RV and the second RV of the first coding matrix to obtain an eighth key, determine that the eighth key and the second key are aligned based on the verification information of the eighth key and the second key, and determine the eighth key as the third key.

[0287] Optionally, the first message is a random access response RAR message.

[0288] It should be understood that the above-mentioned processing unit 620 and transceiver unit 610 can also respectively execute any other steps, operations and / or functions implemented by the first communication device in the methods shown in Figures 3-5 above. The specific process of each unit executing the above-mentioned corresponding steps has been described in detail in the above-mentioned method embodiments. For the sake of brevity, it will not be repeated here.

[0289] In another possible implementation, the device 600 may be the second communication device in the method shown in Figures 3-5 above, or may be a chip used to implement the functions of the second communication device in the method shown in Figures 3-5 above. Specifically, the device 600 may implement the process executed by the second communication device in the method shown in Figures 3-5 above, wherein the transceiver unit 610 and the processing unit 620 are used to perform operations related to the processing of the second communication device in the above method process.

[0290] The transceiver unit 610 is configured to send a first downlink reference signal, receive a first uplink reference signal, and receive a first message, where the first message includes verification information of the second key.

[0291] The processing unit 620 is configured to obtain a second key according to the first uplink reference signal, determine a ninth key according to the second key, and perform security protection on data transmitted with the first communication device according to the ninth key.

[0292] Optionally, the transceiver unit 610 is further configured to receive a preamble code.

[0293] Optionally, the first key and the second key are aligned, and the processing unit 620 is further configured to determine the second key as the ninth key; or calculate the second key to obtain a tenth key, and determine the tenth key as the ninth key.

[0294] Optionally, the first key and the second key are not aligned, and the transceiver unit 610 is further used to send a second downlink reference signal and receive a second uplink reference signal on the resources indicated by the first message; the processing unit 620 is further used to obtain a sixth key based on the second uplink reference signal; the transceiver unit 610 is further used to send verification information of the sixth key through the first message; the processing unit 620 is further used to determine the ninth key based on the fifth key and the verification information of the sixth key, and the fifth key is obtained by the first communication device based on the second downlink reference signal.

[0295] Optionally, the processing unit 620 is further configured to determine a first coding matrix according to the second key; and the transceiver unit 610 is further configured to send a first redundancy version RV of the first coding matrix through the first message.

[0296] Optionally, the transceiver unit 610 is further configured to receive an RV request message, where the RV request message is used to request a second RV of the first coding matrix; and the processing unit 620 is further configured to send the second RV of the first coding matrix through the first message according to the RV request message.

[0297] It should be understood that the above-mentioned processing unit 620 and transceiver unit 610 can also respectively execute any other steps, operations and / or functions implemented by the second communication device in the methods shown in Figures 3-5 above. The specific process of each unit executing the above-mentioned corresponding steps has been described in detail in the above-mentioned method embodiments. For the sake of brevity, it will not be repeated here.

[0298] It should also be understood that in any of the above implementations, the above transceiver unit 610 may include a receiving unit and a sending unit, wherein the receiving unit is used to perform the receiving function in the above transceiver unit 610, and the sending unit is used to perform the sending function in the above transceiver unit 610.

[0299] The above-mentioned device 600 has the function of implementing the corresponding steps performed by the first communication device in the method shown in Figures 3 to 5, or the above-mentioned device 600 has the function of implementing the corresponding steps performed by the second communication device in the method shown in Figures 3 to 5. The functions can be implemented by hardware, or the corresponding software can be implemented by hardware. The hardware or software includes one or more units corresponding to the above-mentioned functions; for example, the transceiver unit can be replaced by a transceiver (for example, the sending unit in the transceiver unit can be replaced by a transmitter, and the receiving unit in the transceiver unit can be replaced by a receiver), and other units, such as the processing unit, can be replaced by a processor to respectively perform the sending and receiving operations and related processing operations in each method embodiment.

[0300] It should be understood that the device 600 here is embodied in the form of a functional unit. The term "unit" here may refer to an application specific integrated circuit (ASIC), an electronic circuit, a processor (such as a shared processor, a dedicated processor or a group processor, etc.) and a memory for executing one or more software or firmware programs, a merging logic circuit and / or other suitable components that support the described functions. In an optional example, those skilled in the art will understand that the device 600 may be specifically the first communication device in the above embodiment or a chip applied to the first communication device, and may be used to execute the process corresponding to the first communication device in the above method embodiment, or the device 600 may be specifically the second communication device in the above embodiment or a chip applied to the second communication device, and may be used to execute the process corresponding to the second communication device in the above method embodiment. To avoid repetition, it will not be described here.

[0301] In addition, the above-mentioned transceiver unit can also be a transceiver circuit (for example, it can include a receiving circuit and a transmitting circuit), and the processing unit can be a processing circuit. In an embodiment of the present application, the device 600 can be the first communication device or the second communication device in the aforementioned embodiment, or it can be a chip or a chip system, such as a system on chip (SoC). Among them, the transceiver unit can be an input and output circuit or a communication interface. The processing unit is a processor or microprocessor or integrated circuit integrated on the chip. This is not limited here.

[0302] Figure 7 is another schematic structural diagram of a communication device provided in an embodiment of the present application. As shown in Figure 7, the communication device 700 includes: at least one processor 710 and a transceiver 720, wherein the transceiver 720 is configured to send and / or receive signals, and the processor 710 is configured to execute instructions to implement the functions of the first communication device in the methods shown in Figures 3-5 above, or to implement the functions of the second communication device in the methods shown in Figures 3-5 above.

[0303] Optionally, the communication device 700 further includes a memory 730 for storing instructions. The processor 710 is coupled to the memory and is configured to execute the instructions stored in the memory to control the transceiver 7020 to send and / or receive signals.

[0304] It should be understood that the processor 710 and memory 730 may be combined into a processing device, and the processor 710 is used to execute the program code stored in the memory 730 to implement the above functions. In specific implementations, the memory 730 may also be integrated into the processor 710 or independent of the processor 710.

[0305] It should also be understood that the transceiver 720 may include a receiver (or receiver) and a transmitter (or transmitter). The transceiver 720 may further include an antenna, and the number of antennas may be one or more. The transceiver 720 may also be a communication interface or interface circuit.

[0306] When the communication device 700 is a chip, the chip includes a transceiver unit and a processing unit, wherein the transceiver unit may be an input / output circuit or a communication interface; and the processing unit may be a processor, microprocessor, or integrated circuit integrated on the chip.

[0307] The present application also provides a processing device including a processor and an interface. The processor can implement the method in the above method embodiment.

[0308] It should be understood that the processing device may be a chip. For example, the processing device may be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated chips.

[0309] During implementation, each step of the above method can be completed by an integrated logic circuit of hardware in a processor or by instructions in the form of software. The steps of the method disclosed in conjunction with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or can be executed by a combination of hardware and software units in the processor. The software unit can be located in a storage medium mature in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. The storage medium is located in a memory, and the processor reads the information in the memory and completes the steps of the above method in conjunction with its hardware. To avoid repetition, it will not be described in detail here.

[0310] Figure 8 is another schematic structural diagram of a communication device provided in an embodiment of the present application. As shown in Figure 8, the device 800 includes a processing circuit 810 and a transceiver circuit 820. The processing circuit 810 is used to execute instructions so that the functions of the first communication device in the method shown in Figures 3-5 above are implemented, or the functions of the second communication device in the method shown in Figures 3-5 above are implemented. The processing circuit 810 and the transceiver circuit 820 communicate with each other through an internal connection path, and the processing circuit 810 can control the transceiver circuit 820 to send and / or receive signals.

[0311] Optionally, the apparatus 800 may further include a storage medium 830, which communicates with the processing circuit 810 and the transceiver circuit 820 via an internal connection path. The storage medium 830 is used to store instructions, and the processing circuit 810 may execute the instructions stored in the storage medium 830.

[0312] In a possible implementation, the apparatus 800 is used to implement the process corresponding to the first communication apparatus in the above method embodiment.

[0313] In another possible implementation, the device 800 is used to implement the process corresponding to the second communication device in the above method embodiment.

[0314] According to the method provided in the embodiment of the present application, the present application also provides a computer program product, which includes instructions. When the instructions are executed by the processor, the function of the first communication device in the method shown in Figures 3-5 above is implemented, or the function of the second communication device in the method shown in Figures 3-5 above is implemented.

[0315] According to the method provided in an embodiment of the present application, the present application also provides a computer-readable storage medium, which includes instructions. When the instructions are executed by the processor, the function of the first communication device in the method shown in Figures 3-5 above is implemented, or the function of the second communication device in the method shown in Figures 3-5 above is implemented.

[0316] According to the method provided in the embodiment of the present application, the present application also provides a system, which includes the aforementioned one or more first communication devices and one or more second communication devices.

[0317] In the above embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated therein. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a high-density digital video disc (DVD)), or a semiconductor medium (eg, a solid state disk (SSD)).

[0318] In the embodiments of this application, words such as "exemplary" and "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" should not be construed as preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete way.

[0319] It should be understood that references to "embodiments" throughout this specification mean that a particular feature, structure, or characteristic associated with the embodiment is included in at least one embodiment of the present application. Therefore, various embodiments throughout this specification do not necessarily refer to the same embodiment. Furthermore, these particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0320] It should be understood that in the various embodiments of the present application, the size of the sequence number of each process does not mean the order of execution, and the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present application. The names of all nodes and messages in this application are merely names set by this application for the convenience of description. The names in the actual network may be different. It should not be understood that this application limits the names of various nodes and messages. On the contrary, any name with the same or similar function as the node or message used in this application is regarded as the method or equivalent replacement of this application, and is within the scope of protection of this application.

[0321] It should also be understood that in this application, "when", "if" and "if" all mean that the UE or base station will take corresponding measures under certain objective circumstances. It does not limit the time, and does not require the UE or base station to take judgment actions when implementing it, nor does it mean that there are other limitations.

[0322] It should be noted that in the embodiments of the present application, "pre-setting", "pre-configuration", etc. can be achieved by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in a device (for example, a terminal device). This application does not limit its specific implementation method, such as the preset rules, preset constants, etc. in the embodiments of the present application.

[0323] Additionally, the terms "system" and "network" are often used interchangeably. The term "and / or" is simply used to describe an association between related objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists alone, A and B exist simultaneously, or B exists alone.

[0324] As used herein, the term "at least one of" or "at least one of" refers to all or any combination of the listed items. For example, "at least one of A, B, and C" or "at least one of A, B, or C" can refer to the following six situations: A alone, B alone, C alone, A and B together, B and C together, and A, B, and C together. As used herein, "at least one" means one or more. "A plurality" means two or more.

[0325] It should be understood that in the various embodiments of the present application, "B corresponding to A" means that B is associated with A and can be determined based on A. However, it should also be understood that determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information. The terms "include," "comprising," "having," and their variations all mean "including but not limited to," unless otherwise specifically emphasized.

[0326] It should be understood that in various embodiments of the present application, the first, second, and various numerical numbers are merely distinctions for ease of description and are not intended to limit the scope of the embodiments of the present application.

[0327] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0328] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0329] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0330] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0331] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0332] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0333] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A method for data transmission, characterized in that: The method is applied to a first communication device, and the method includes: receiving a first downlink reference signal, and obtaining a first key according to the first downlink reference signal; Sending a first uplink reference signal; receiving a first message, where the first message includes verification information of a second key, where the second key is obtained by the second communication device according to the received first uplink reference signal; Determine a third key according to verification information of the first key and the second key; Data transmitted between the second communication device and the second communication device is securely protected according to the third key.

2. The method according to claim 1, characterized in that: When sending the first uplink reference signal, the method further includes: Send preamble.

3. The method according to claim 1 or 2, characterized in that: Before receiving the first downlink reference signal, the method further includes: receiving system information, wherein the system information includes measurement configuration information and quantization configuration information; The obtaining a first key according to the first downlink reference signal comprises: Measuring the first downlink reference signal according to the measurement configuration information to obtain a measurement result of the first downlink reference signal; The measurement result of the first downlink reference signal is quantized according to the quantization configuration information to obtain the first key.

4. The method according to any one of claims 1 to 3, characterized in that The determining the third key according to the verification information of the first key and the second key includes: Determining alignment between the first key and the second key according to verification information of the first key and the second key; The first key is determined as the third key; or the first key is calculated to obtain a fourth key, and the fourth key is determined as the third key.

5. The method according to any one of claims 1 to 3, characterized in that The determining the third key according to the verification information of the first key and the second key includes: determining, according to verification information of the first key and the second key, that the first key and the second key are not aligned; Sending a second uplink reference signal on the resources indicated by the first message; receiving a second downlink reference signal, and obtaining a fifth key according to the second downlink reference signal; receiving verification information of a sixth key, where the sixth key is obtained by the second communication device according to the received second uplink reference signal; The third key is determined according to verification information of the fifth key and the sixth key.

6. The method according to any one of claims 1 to 3, characterized in that The first message also includes a first redundancy version RV of a first coding matrix, where the first coding matrix is ​​determined by the second communication device according to the second key. The determining the third key according to the verification information of the first key and the second key includes: Decoding the first key according to the first RV of the first encoding matrix to obtain a seventh key; The third key is determined according to verification information of the seventh key and the second key.

7. The method according to claim 6, characterized in that The determining the third key according to the verification information of the seventh key and the second key includes: Determining alignment between the seventh key and the second key according to verification information of the seventh key and the second key; The seventh key is determined as the third key.

8. The method according to claim 6, characterized in that The determining the third key according to the verification information of the seventh key and the second key includes: determining, according to verification information of the seventh key and the second key, that the seventh key and the second key are not aligned; Sending an RV request message, where the RV request message is used to request a second RV of the first coding matrix; Receiving a second RV of the first coding matrix; Decoding the first key according to the first RV and the second RV of the first encoding matrix to obtain an eighth key; Determining alignment between the eighth key and the second key according to verification information of the eighth key and the second key; The eighth key is determined as the third key.

9. The method according to any one of claims 1 to 8, characterized in that The first message is a random access response RAR message.

10. A method for data transmission, characterized in that: The method is applied to a second communication device, and the method includes: Sending a first downlink reference signal; receiving a first uplink reference signal, and obtaining a second key according to the first uplink reference signal; Sending a first message, where the first message includes verification information of the second key; determining a ninth key according to the second key; According to the ninth key, data transmitted between the first communication device is securely protected.

11. The method according to claim 10, characterized in that The method further comprises: Broadcasting system information, wherein the system information includes measurement configuration information and quantization configuration information; The obtaining a second key according to the first uplink reference signal includes: Measuring the first uplink reference signal according to the measurement configuration information to obtain a measurement result of the first uplink reference signal; The measurement result of the first uplink reference signal is quantized according to the quantization configuration information to obtain the second key.

12. The method according to claim 10 or 11, characterized in that: The method further comprises: Receive preamble.

13. The method according to any one of claims 10 to 12, characterized in that The first key and the second key are aligned, and determining the ninth key according to the second key includes: The second key is determined as the ninth key; or the second key is calculated to obtain a tenth key, and the tenth key is determined as the ninth key.

14. The method according to any one of claims 10 to 12, characterized in that The first key and the second key are not aligned, and determining the ninth key according to the verification information of the second key and the first key includes: Sending a second downlink reference signal; Receiving a second uplink reference signal on the resources indicated by the first message; Obtaining a sixth key according to the second uplink reference signal; Sending verification information of the sixth key through the first message; The ninth key is determined according to verification information of a fifth key and the sixth key, where the fifth key is obtained by the first communication device according to the second downlink reference signal.

15. The method according to any one of claims 10 to 14, characterized in that The sending of the first message comprises: determining a first encoding matrix according to the second key; A first redundancy version RV of the first coding matrix is ​​sent through the first message.

16. The method according to claim 15, characterized in that The method further comprises: receiving an RV request message, where the RV request message is used to request a second RV of the first coding matrix; A second RV of the first coding matrix is ​​sent through the first message according to the RV request message.

17. The method according to any one of claims 10 to 16, characterized in that The first message is a random access response RAR message.

18. A communication device, characterized in that: The communication device includes a processor and a storage medium, wherein the storage medium stores instructions, and when the instructions are executed by the processor, the method according to any one of claims 1 to 9 is implemented.

19. A communication device, characterized in that: The communication device comprises a processor and a communication interface, wherein the communication interface is used to input and / or output signals, and the processor is used to execute a computer program or instruction so that the method according to any one of claims 1 to 9 is implemented.

20. A communication device, characterized in that: The communication device includes a processor and a storage medium, wherein the storage medium stores instructions. When the instructions are executed by the processor, the method according to any one of claims 10 to 17 is implemented.

21. A communication device, characterized in that: The communication device comprises a processor and a communication interface, wherein the communication interface is used to input and / or output signals, and the processor is used to execute a computer program or instruction so that the method according to any one of claims 10 to 17 is implemented.

22. A communication system, characterized in that: include: The communication device according to claim 18 and / or the communication device according to claim 20, or the communication device according to claim 19 and / or the communication device according to claim 21.

23. A computer-readable storage medium, characterized in that: The computer-readable storage medium comprises instructions, which, when executed by a processor, enable the method according to any one of claims 1 to 9 to be implemented, or enable the method according to any one of claims 10 to 17 to be implemented.

24. A computer program product, characterized in that The computer program product comprises instructions, which, when executed by a processor, enable the method according to any one of claims 1 to 9 to be implemented, or enable the method according to any one of claims 10 to 17 to be implemented.

Citation Information

Patent Citations

  • Data transmission method and device

    CN119946622A

  • Information transmission method, information transmission system, first device and second device

    CN111726362A

  • Authentication authentication method and related device

    CN114650530A

  • Communication method and device

    CN115802505A

  • Message integrity protection and verification method and related device

    CN116709333A