Communication method and apparatus

By carrying historical physical layer information in the messages of the legitimate network device, the terminal device can identify the legitimate message and prevent authentication relay attacks, solving the problem of difficult to prevent such attacks in the prior art, and realizing the security and reliability of the communication channel.

WO2025092665A1PCT designated stage expired Publication Date: 2025-05-08HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/127797
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-31
Filing Date
2024-10-28
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively prevent authentication and relay attacks, resulting in impaired network security and may cause billing fraud and communication interruptions.

Method used

By carrying the historical physical layer measurement information and physical layer configuration information in the messages sent by the legal network device, the terminal device can determine whether the message comes from the legal network device by comparing the received message information with the information recorded by itself, thereby preventing authentication relay attacks.

Benefits of technology

Effectively identify and prevent authentication relay attacks, ensure the security and reliability of communication channels, and avoid billing fraud and network interruptions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024127797_08052025_PF_FP_ABST
    Figure CN2024127797_08052025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are a communication method and apparatus, which are used for preventing authentication relay attacks. The method comprises: receiving a first message, and on the basis of first information indicated by the first message and historically recorded second information, determining whether a network device is legitimate, wherein the first information comprises first physical layer measurement information and / or first physical layer configuration information, and the second information comprises second physical layer measurement information and / or second physical layer configuration information. Physical layer measurement information and physical layer configuration information that are related to a channel are carried in a message sent by a network device. Since a channel between a legitimate network device and a terminal device is different from a channel between an illegitimate network device and the terminal device, by means of comparing information carried in a received message with information recorded in the terminal device, the terminal device can determine whether the message comes from the legitimate network device, so that authentication relay attacks can be prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and device

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on October 31, 2023, with application number 202311439235.6 and application name "A Communication Method and Device", the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of communication technology, and in particular to a communication method and device. Background Art

[0004] An authentication relay attack refers to an attack in which an intermediate device (such as an illegal base station or illegal user equipment (UE)) steals the identity of a legitimate UE and intercepts messages. For example, a legitimate UE may be attracted to an illegal base station. The illegal base station then collaborates with another illegal UE through a private channel. The illegal base station forwards the registration request message of the legitimate UE to the remote illegal UE, and the illegal UE forwards it to the remote core network through the remote legal base station. For another example, the illegal base station and the illegal UE forward the response message sent by the core network to the legitimate UE and complete the authentication. If an authentication relay attack occurs, the consequences may be: the network's perceived user location may be inconsistent with the user's actual location; or, the legitimate UE may be guided by the intermediate device to access a roaming network, resulting in billing fraud; or, the intermediate device can completely / selectively reject the legitimate UE's phone / text / data transmission, resulting in the operating network being deprived of incoming / outgoing call and text message charges.

[0005] In summary, how to prevent authentication relay attacks is an urgent problem to be solved.

[0006] Summary of the Invention

[0007] The present application provides a communication method and apparatus for preventing authentication relay attacks.

[0008] In a first aspect, a communication method is provided, wherein the executing subject of the method may be a terminal device or a chip, a chip system or a circuit located in the terminal device, and the method may be implemented by the following steps: receiving a first message, the first message indicating first information, the first information including at least one of the following: first physical layer measurement information, first physical layer configuration information; determining whether the network device is legal based on the first information indicated by the first message and second information recorded by itself, the second information including at least one of the following: second physical layer measurement information recorded in the historical records, second physical layer configuration information recorded in the historical records.

[0009] In this application, the historical physical layer measurement information and the historical physical layer configuration information are carried in the messages sent by the legitimate network devices. Since the physical layer measurement information and the physical layer configuration information are related to the channel of the legitimate network device, and the illegal network device cannot obtain the channel conditions between the legitimate network device and the terminal device, it is impossible to carry information related to the channel of the legitimate network device in the sent message. Therefore, the terminal device can determine whether the message comes from the legitimate network device by comparing the information carried in the received message with the physical layer measurement information and physical layer configuration information recorded by itself, thereby preventing authentication relay attacks.

[0010] In one possible design, the first physical layer measurement information includes the downlink channel state information carried by the first message, and the second physical layer measurement information includes the downlink channel state information reported last time.

[0011] Since the downlink channel status information can provide feedback on the communication channel quality between the terminal device and the legitimate network device, if an illegal network device (or illegal terminal device) communicates with the terminal device, the communication channel will change, and the downlink channel status information measured by the terminal device will be inconsistent with the downlink channel status information of the legitimate network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0012] In one possible design, the first physical layer configuration information includes at least one of the following items: the modulation level used by the first message, the system frame number carried by the first message, the random access timing index carried by the first message, and the preamble code index carried by the first message; the second physical layer configuration information includes at least one of the following items: the modulation level used by the second message, the system frame number indicated by the second message, the random access timing index indicated by the second message, and the preamble code index indicated by the second message, wherein the second message is the downlink message received last time, or the second message is the downlink message with the best signal quality among the downlink messages received within a preset time period.

[0013] Since the modulation level is related to the quality of the communication channel, the better the channel quality, the higher the modulation level. Therefore, if an illegal network device (or illegal terminal device) communicates with a terminal device, the communication channel will change. The channel quality between the illegal network device and the terminal device is different from the channel quality between the legal network device and the terminal device. The illegal network device may even be unable to support high-order modulation levels. Therefore, the modulation level of the downlink message sent by the illegal network device is inconsistent with the modulation level of the downlink message sent by the legal network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0014] However, information such as the system frame number, random access timing index, and preamble index are configured by legitimate network devices, and illegal network devices cannot obtain this information. Therefore, the information carried in the downlink message sent by the illegal network device is inconsistent with the information carried in the downlink message sent by the legitimate network device. As a result, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0015] In one possible design, whether the network device is legal is determined based on the first information and the second information, including: if the first information is consistent with the second information, then the network device is legal.

[0016] In one possible design, if the network device is legitimate, the method further includes: receiving a downlink reference signal; and sending a response message to the first message, the response message carrying physical layer measurement information corresponding to the downlink reference signal. In this solution, the terminal device and the network device can record the downlink channel state information of the current measurement to facilitate the terminal device's identification of subsequent messages.

[0017] In one possible design, before receiving the first message, the method further includes: receiving a third message, the third message being used to indicate successful authentication. This approach can confirm that the information recorded by the terminal device corresponds to a legitimate network device, and thus, can identify whether subsequent messages are from the legitimate network device based on the recorded information, thereby preventing authentication relay attacks.

[0018] In one possible design, the first message is a radio resource control (RRC) reconfiguration message.

[0019] In one possible design, if the network device is legal, an RRC reconfiguration completion message can be sent.

[0020] In one possible design, the first physical layer configuration information includes at least one of the following: the modulation level used by the first message, the system frame number carried by the first message, the random access timing index carried by the first message, and the preamble index carried by the first message; the second physical layer configuration information includes at least one of the following: the modulation level indicated by the fourth message, the system frame number carried or used by the fourth message, the random access timing index carried or used by the fourth message, and the preamble index carried or used by the fourth message, wherein the fourth message is the most recently received downlink message that has been successfully decrypted using the public key. The above example can identify whether the message content of the fourth message has been tampered with by encrypting the fourth message, and since illegal network devices cannot obtain configuration certificates and therefore cannot obtain legal public keys, the above scheme can also be used to determine whether the fourth message comes from a legal network device.

[0021] In one possible design, determining whether a network device is legitimate based on first and second information includes: if the first and second information are consistent, and the first message is successfully decrypted using the public key, then the network device is legitimate. This example encrypts the first message to identify whether the content of the first message has been tampered with. Furthermore, since an illegal network device cannot obtain a configuration certificate and, therefore, a legitimate public key, this scheme can also be used to determine whether the first message originated from a legitimate network device.

[0022] In one possible design, the method further includes: receiving a system message, where the system message indicates a public key.

[0023] In one possible design, the first message is message 4 in the random access process, and the fourth message is message 2 in the random access process.

[0024] According to a second aspect, a communication method is provided. The executing subject of the method may be a network device or a chip, chip system or circuit located in the network device. The method may be implemented by the following steps: sending a first message, the first message indicating first information, the first information including at least one of the following: first physical layer measurement information of the historical record, first physical layer configuration information of the historical record, the first information is used to determine whether the network device is legal.

[0025] In this application, the historical physical layer measurement information and the historical physical layer configuration information are carried in the messages sent by the legitimate network devices. Since the physical layer measurement information and the physical layer configuration information are related to the channel of the legitimate network device, and the illegal network device cannot obtain the channel conditions between the legitimate network device and the terminal device, it is impossible to carry information related to the channel of the legitimate network device in the sent message. Therefore, the terminal device can determine whether the message comes from the legitimate network device by comparing the information carried in the received message with the physical layer measurement information and physical layer configuration information recorded by itself, thereby preventing authentication relay attacks.

[0026] In one possible design, the first physical layer measurement information includes the downlink channel state information carried by the first message, and the second physical layer measurement information includes the downlink channel state information reported last time.

[0027] Since the downlink channel status information can provide feedback on the communication channel quality between the terminal device and the legitimate network device, if an illegal network device (or illegal terminal device) communicates with the terminal device, the communication channel will change, and the downlink channel status information measured by the terminal device will be inconsistent with the downlink channel status information of the legitimate network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0028] In one possible design, the first physical layer configuration information includes at least one of the following items: the modulation level used by the first message, the system frame number carried by the first message, the random access timing index carried by the first message, and the preamble code index carried by the first message; the second physical layer configuration information includes at least one of the following items: the modulation level used by the second message, the system frame number indicated by the second message, the random access timing index indicated by the second message, and the preamble code index indicated by the second message, wherein the second message is the downlink message received last time, or the second message is the downlink message with the best signal quality among the downlink messages received within a preset time period.

[0029] Since the modulation level is related to the quality of the communication channel, the better the channel quality, the higher the modulation level. Therefore, if an illegal network device (or illegal terminal device) communicates with a terminal device, the communication channel will change. The channel quality between the illegal network device and the terminal device is different from the channel quality between the legal network device and the terminal device. The illegal network device may even be unable to support high-order modulation levels. Therefore, the modulation level of the downlink message sent by the illegal network device is inconsistent with the modulation level of the downlink message sent by the legal network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0030] However, information such as the system frame number, random access timing index, and preamble index are configured by legitimate network devices, and illegal network devices cannot obtain this information. Therefore, the information carried in the downlink message sent by the illegal network device is inconsistent with the information carried in the downlink message sent by the legitimate network device. As a result, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0031] In one possible design, the method further includes: sending a downlink reference signal; and receiving a response message to the first message, the response message carrying physical layer measurement information corresponding to the downlink reference signal. In this solution, the terminal device and the network device may record the downlink channel state information of the current measurement to facilitate the terminal device's identification of subsequent messages.

[0032] In one possible design, before sending the first message, the method further includes: sending a third message indicating that authentication was successful. This approach can confirm that the information recorded by the terminal device corresponds to a legitimate network device, and thus, can identify whether subsequent messages are from the legitimate network device based on the recorded information, thereby preventing authentication relay attacks.

[0033] In one possible design, the first message is an RRC reconfiguration message.

[0034] In one possible design, an RRC reconfiguration completion message may also be received.

[0035] In one possible design, the first physical layer configuration information includes at least one of the following: the modulation level used by the first message, the system frame number carried by the first message, the random access timing index carried by the first message, and the preamble index carried by the first message; the second physical layer configuration information includes at least one of the following: the modulation level indicated by the fourth message, the system frame number carried or used by the fourth message, the random access timing index carried or used by the fourth message, and the preamble index carried or used by the fourth message, wherein the fourth message is the most recently received downlink message that has been successfully decrypted using the public key. The above example can identify whether the message content of the fourth message has been tampered with by encrypting the fourth message, and since illegal network devices cannot obtain configuration certificates and therefore cannot obtain legal public keys, the above scheme can also be used to determine whether the fourth message comes from a legal network device.

[0036] In one possible design, the method also includes: sending a system message, where the system message indicates the public key corresponding to the private key.

[0037] In one possible design, the first message is message 4 in the random access process, and the fourth message is message 2 in the random access process.

[0038] In a third aspect, the present application further provides a communication device, which is a terminal device or a chip in a terminal device. The communication device has the function of implementing any of the methods provided in the first aspect above. The communication device can be implemented in hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more units or modules corresponding to the above functions.

[0039] In one possible design, the communication device includes a processor configured to support the communication device in executing the corresponding functions of the terminal device in the method described above. The communication device may also include a memory, which may be coupled to the processor and stores program instructions and data necessary for the communication device. Optionally, the communication device also includes an interface circuit for supporting communication between the communication device and other devices, such as network equipment, such as the transmission and reception of data or signals. Exemplarily, the communication interface may be a transceiver, circuit, bus, module, or other type of communication interface.

[0040] In one possible design, the communication device includes corresponding functional modules for implementing the steps in the above method. The functions can be implemented by hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more modules corresponding to the above functions.

[0041] In one possible design, the structure of the communication device includes a processing unit and a communication unit, which can perform the corresponding functions in the above method example. For details, please refer to the description of the method provided in the first aspect, which will not be repeated here.

[0042] In a fourth aspect, the present application further provides a communication device, which is a network device or a chip in a network device. The communication device has the function of implementing any of the methods provided in the second aspect above. The communication device can be implemented in hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more units or modules corresponding to the above functions.

[0043] In one possible design, the communication device includes a processor configured to support the communication device in executing the corresponding functions of the network device in the method described above. The communication device may also include a memory, which may be coupled to the processor and stores program instructions and data necessary for the communication device. Optionally, the communication device also includes an interface circuit for supporting communication between the communication device and a terminal device, such as the transmission and reception of data or signals. Exemplarily, the communication interface may be a transceiver, circuit, bus, module, or other type of communication interface.

[0044] In one possible design, the communication device includes corresponding functional modules for implementing the steps in the above method. The functions can be implemented by hardware or by hardware executing corresponding software implementations. The hardware or software includes one or more modules corresponding to the above functions.

[0045] In one possible design, the structure of the communication device includes a processing unit and a communication unit, which can perform the corresponding functions in the above method example. For details, please refer to the description of the method provided in the second aspect, which will not be repeated here.

[0046] In a fifth aspect, a communication device is provided, comprising a processor and an interface circuit, wherein the interface circuit is used to receive signals from other communication devices outside the communication device and transmit them to the processor or send signals from the processor to other communication devices outside the communication device, and the processor is used to implement the method in the aforementioned first aspect and any possible design through logic circuits or execution code instructions.

[0047] In the sixth aspect, a communication device is provided, comprising a processor and an interface circuit, the interface circuit being used to receive signals from other communication devices outside the communication device and transmit them to the processor or to send signals from the processor to other communication devices outside the communication device, the processor being used to implement the method in the aforementioned second aspect and any possible design through logic circuits or executing code instructions.

[0048] In the seventh aspect, a computer-readable storage medium is provided, which stores a computer program or instruction. When the computer program or instruction is executed by a processor, the method of the aforementioned first aspect or second aspect and any possible design is implemented.

[0049] In an eighth aspect, a computer program product storing instructions is provided, which, when executed by a processor, implements the method in the aforementioned first aspect or second aspect and any possible design.

[0050] In a ninth aspect, a chip system is provided, comprising a processor and a memory, for implementing the method of the first or second aspect and any possible design. The chip system may be composed of a chip alone or may include a chip and other discrete devices.

[0051] In a tenth aspect, a communication system is provided, which includes the device described in the first aspect (such as a terminal device) and the device described in the second aspect (such as a network device).

[0052] The technical effects that can be achieved by the technical solutions in any of the third to tenth aspects mentioned above can be described with reference to the technical effects that can be achieved by the technical solutions in the first aspect mentioned above, and the repeated parts will not be repeated. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] FIG1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present application;

[0054] FIG2 is a flow chart of a communication method according to an embodiment of the present application;

[0055] FIG3 is a schematic diagram of a process for preventing authentication relay attacks according to an embodiment of the present application;

[0056] FIG4 is a schematic diagram of another process for preventing authentication relay attacks according to an embodiment of the present application;

[0057] FIG5 is a schematic diagram of another process for preventing authentication relay attacks according to an embodiment of the present application;

[0058] FIG6 is a schematic structural diagram of a communication device according to an embodiment of the present application;

[0059] FIG7 is a schematic structural diagram of a communication device according to an embodiment of the present application. DETAILED DESCRIPTION

[0060] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.

[0061] Below, some terms used in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.

[0062] 1) Terminal device, which can be a device with wireless transceiver capabilities or a chip that can be set in any device, can also be called user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, wireless communication device, user agent or user device. The terminal device in the embodiments of the present application can be a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, an XR device (such as a VR device, an AR device, an MR device, etc.), a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in video surveillance, and a wearable terminal device. The terminal device can also be an eMBB UE, an ultra-reliable low latency communication (URLLC) UE, a drone, other Internet of Things (IoT) devices, a positioning device, etc.

[0063] A network device may be a device for implementing the functions of an access network device. An access network device may refer to a device in an access network that communicates with a wireless terminal device through one or more cells over the air interface. For example, it may be a next-generation base station (gNB) in an NR system, or an evolutionary base station (eNB) in a long-term evolution (LTE) system. A network device may also be a device that can support the network device to implement the functions of the access network device, such as a chip system, which may be installed in the network device. In some deployments, the network device may include at least one of a centralized unit (CU), a distributed unit (DU), and a radio unit (RU).

[0064] 2) The random access process includes a contention-based random access (CBRA) process and a contention-free random access (CFRA) process. The CBRA process is described below.

[0065] The CBRA process can be completed through a 4-step random access channel (RACH) or a 2-step RACH.

[0066] The 4-step RACH process includes:

[0067] S11. The terminal device sends a random access request message to the network device, and the network device receives the random access request message from the terminal device. The random access request message may also be referred to as a first message (Msg1), which includes a random access preamble.

[0068] S12: The network device sends a RAR message to the terminal device, and the terminal device receives the RAR message from the network device. The RAR message may also be referred to as a second message (Msg2).

[0069] S13: The terminal device sends scheduled transmission information to the network device, and the network device receives the scheduled transmission information from the terminal device. The message carrying the scheduled transmission information is called a third message (Msg3).

[0070] After receiving the RAR message, the terminal device transmits the message based on the scheduling of the RAR message. Specifically, the terminal device may send Msg3 via a physical uplink shared channel (PUSCH) scheduled by the RAR UL grant carried in the first RAR.

[0071] S14: The network device sends contention resolution information to the terminal device. The message carrying the contention resolution information is called a fourth message (Msg4). The terminal device receives Msg4 from the network device and obtains the contention resolution information.

[0072] The terms "system" and "network" in the embodiments of the present application can be used interchangeably. In the embodiments of the present application, "at least one" refers to one or more, and "plurality" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and subsequent associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple.

[0073] Furthermore, unless otherwise indicated, ordinal numbers such as "first" and "second" in the embodiments of the present application are used to distinguish between multiple objects and are not used to limit the size, content, sequence, timing, priority, or importance of the multiple objects. For example, the first message and the second message are only used to distinguish different messages and do not indicate a difference in the sending order, content, priority, or importance of the two messages.

[0074] The foregoing text introduces some of the terms and concepts involved in the embodiments of this application. The following text introduces the technical features involved in the embodiments of this application.

[0075] The following describes the technical features involved in the embodiments of this application.

[0076] An authentication relay attack refers to an attack in which an intermediate device (such as an illegal base station or illegal user equipment (UE)) steals the identity of a legitimate UE and intercepts messages. For example, a legitimate UE may be attracted to an illegal base station. The illegal base station then collaborates with another illegal UE through a private channel. The illegal base station forwards the registration request message of the legitimate UE to the remote illegal UE, which then forwards it to the remote core network through the remote legal base station. For another example, the illegal base station and the illegal UE forward the response message sent by the core network to the legitimate UE and complete the authentication. If an authentication relay attack occurs, the consequences may be: the network's perceived user location may be inconsistent with the user's actual location; or the legitimate UE may be guided by the intermediate device to access a roaming network, resulting in billing fraud; or the intermediate device may completely / selectively reject the legitimate UE's phone / text messages / data transmission, resulting in the operating network being deprived of incoming / outgoing call and text message charges. In summary, there is an urgent need for a solution to prevent authentication relay attacks.

[0077] Based on this, embodiments of the present application provide a communication method and apparatus for preventing authentication relay attacks. The method and apparatus are based on the same concept. Since the method and apparatus solve similar problems, the implementation of the apparatus and method can refer to each other, and any repetitions will not be repeated.

[0078] The communication method provided in this application can be applied to various communication systems, for example, the Internet of Things (IoT), narrowband Internet of Things (NB-IoT), long term evolution (LTE), fifth generation (5G) communication system, LTE and 5G hybrid architecture, 5G new radio (NR) system, and 6G or new communication systems emerging in future communication development. The 5G communication system described in this application may include at least one of a non-standalone (NSA) 5G communication system and a standalone (SA) 5G communication system. The communication system may also be a machine to machine (M2M) network or other network.

[0079] The network device and the terminal device can communicate through the licensed spectrum, the unlicensed spectrum, or both. The network device and the terminal device can communicate through the spectrum below 6G, the spectrum above 6G, or both. The network device and the terminal device can communicate through the spectrum below 6G and the spectrum above 6G at the same time. The embodiments of the present application do not limit the spectrum resources used between the network device and the terminal device.

[0080] 1 shows a communication system architecture, which includes a network device 101 and a terminal device 102. It should be noted that the number of devices in the communication system shown in FIG1 is only an example and is not intended to limit the present application.

[0081] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0082] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0083] In this application, "record" can also be replaced by "save", "maintain" and so on.

[0084] Refer to Figure 2, which is a flow chart of a communication method provided by the present application. The execution subject of the method can be a network device or a chip, chip system or circuit located in the network device, and a terminal device or a chip, chip system or circuit located in the terminal device. For ease of introduction, the following takes the method being executed by a network device and a terminal device as an example. The processing described below as being executed by a single execution subject can also be divided into being executed by multiple execution subjects, and these execution subjects can be logically and / or physically separated. For example, the processing performed by the network device can be divided into being executed by at least one of the CU, DU and RU. The method includes:

[0085] S201: A network device sends a first message, and a terminal device receives the first message accordingly.

[0086] The first message indicates first information, and the first information includes at least one of the following: first physical layer measurement information and first physical layer configuration information.

[0087] Exemplarily, if the network device is a legitimate network device, the first physical layer measurement information is first physical layer measurement information recorded in a history of the legitimate network device. It is understood that the first physical layer measurement information recorded in a history of the legitimate network device may be a measurement result of a reference signal between the terminal device and the legitimate network device before S201, used to characterize the channel between the terminal device and the legitimate network device.

[0088] For example, the first physical layer measurement information may be a measurement result of a downlink reference signal of a legitimate network device before S201, used to characterize a downlink channel between the terminal device and the legitimate network device. Exemplarily, the first physical layer measurement information may be downlink channel state information.

[0089] In a specific example, the first physical layer measurement information may be the downlink channel status information from the terminal device received by the legal network device at a certain time, for example, the downlink channel status information from the terminal device received for the first time, or the downlink channel status information from the terminal device received for the most recent time, or the downlink channel status information from the terminal device received for the last time, or the downlink channel status information from the terminal device received for the Nth time, or the downlink channel status information corresponding to the best downlink reference signal quality, etc.

[0090] The downlink channel state information may include, but is not limited to, a channel quality indicator (CQI) of a downlink reference signal, a precoding matrix indicator (PMI) of an uplink reference signal, a rank indication (RI) of an uplink reference signal, and the like.

[0091] In one possible implementation, before step S201, the terminal device measures a downlink reference signal (e.g., a channel state information reference signal (CSI-RS)) from a legitimate network device and records the measurement result of the downlink reference signal. The terminal device sends the measurement result to the legitimate network device, and the legitimate network device records the measurement result after receiving it.

[0092] Optionally, the above-mentioned downlink reference signal measurement may be periodic, for example, the legal network device configures the downlink reference signal sending period and time-frequency resource position, and sends it according to the configured period. Alternatively, the above-mentioned downlink reference signal measurement may also be semi-periodic, for example, the legal network device notifies the terminal device of each downlink reference signal transmission through downlink control information (DCI) signaling. Alternatively, the above-mentioned downlink reference signal measurement may also be semi-static, and the legal network device configures the downlink reference signal sending period and time-frequency resource position and notifies the terminal device, and activates / deactivates the transmission of the downlink reference signal through the media access control element (MAC control element, MAC CE). This application does not make specific restrictions.

[0093] Since the modulation level is related to the quality of the communication channel, the better the channel quality, the higher the modulation level. Therefore, if an illegal network device (or illegal terminal device) communicates with a terminal device, the communication channel will change. The channel quality between the illegal network device and the terminal device is different from the channel quality between the legal network device and the terminal device. The illegal network device may even be unable to support high-order modulation levels. Therefore, the modulation level of the downlink message sent by the illegal network device is inconsistent with the modulation level of the downlink message sent by the legal network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0094] If the above-mentioned network device is a legitimate network device, the first physical layer configuration information is the first physical layer configuration information recorded in the history of the legitimate network device. It is understandable that the first physical layer configuration information can be the configuration information of the uplink message or downlink message between the terminal device and the legitimate network device before S201, and the configuration information of the message is related to the channel between the terminal device and the legitimate network device. For example, the first physical layer measurement information recorded in the history can be the configuration information of the downlink message of the legitimate network device before S201. For another example, the first physical layer measurement information recorded in the history can be the configuration information of the uplink message sent by the terminal device to the legitimate network device before S201.

[0095] Exemplarily, the first physical layer configuration information may include at least one of the following items: the modulation level adopted by the second message, the system frame number carried or used by the second message, the random access timing index carried or used by the second message, and the preamble code index carried or used by the second message, wherein the second message is the downlink message sent last time, or the second message is the downlink message with the best signal quality among the downlink messages sent within a preset time period.

[0096] Since the modulation level is related to the quality of the communication channel, the better the channel quality, the higher the modulation level. Therefore, if an illegal network device (or illegal terminal device) communicates with a terminal device, the communication channel will change. The channel quality between the illegal network device and the terminal device is different from the channel quality between the legal network device and the terminal device. The illegal network device may even be unable to support high-order modulation levels. Therefore, the modulation level of the downlink message sent by the illegal network device is inconsistent with the modulation level of the downlink message sent by the legal network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0097] However, information such as the system frame number, random access timing index, and preamble index are configured by legitimate network devices, and illegal network devices cannot obtain this information. Therefore, the information carried in the downlink message sent by the illegal network device is inconsistent with the information carried in the downlink message sent by the legitimate network device. As a result, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0098] If the network device is an illegal network device, the first physical layer measurement information may be the first physical layer measurement information recorded in the illegal network device's history, and the first physical layer configuration information may be the first physical layer configuration information recorded in the illegal network device's history. Alternatively, the first physical layer measurement information and the first physical layer configuration information may be empty, which can also be understood as indicating that the first message does not indicate the first information. Alternatively, if the network device is an illegal network device, the first message may also carry other information, which is not specifically limited here.

[0099] S202: The terminal device determines whether the network device is legal based on the first information and the second information, where the second information includes at least one of the following: historical second physical layer measurement information and historical second physical layer configuration information.

[0100] It is understood that the second physical layer measurement information recorded in the history may be physical layer measurement information recorded for the legitimate network device before S201. For example, the second physical layer measurement information may be the measurement result of the reference signal between the terminal device and the legitimate network device before S201, used to characterize the channel between the terminal device and the legitimate network device. The second physical layer measurement information can refer to the relevant description of the first physical layer measurement information of the legitimate network device, and will not be repeated here.

[0101] The second physical layer configuration information recorded in the historical record may be physical layer configuration information recorded for the legitimate network device before S201. For example, the second physical layer configuration information recorded in the historical record may be configuration information for an uplink message or a downlink message between the terminal device and the legitimate network device before S201, where the configuration information of the message is related to the channel between the terminal device and the legitimate network device. The second physical layer configuration information can refer to the description of the first physical layer configuration information of the legitimate network device, and will not be repeated here.

[0102] The method for determining whether a network device is legitimate will be explained in detail below in conjunction with specific scenarios.

[0103] In this application, the historical physical layer measurement information and the historical physical layer configuration information are carried in the messages sent by the legitimate network devices. Since the physical layer measurement information and the physical layer configuration information are related to the channel of the legitimate network device, and the illegal network device cannot obtain the channel conditions between the legitimate network device and the terminal device, it is impossible to carry information related to the channel of the legitimate network device in the sent message. Therefore, the terminal device can determine whether the message comes from the legitimate network device by comparing the information carried in the received message with the physical layer measurement information and physical layer configuration information recorded by itself, thereby preventing authentication relay attacks.

[0104] The following describes the implementation of S202 in conjunction with specific scenarios.

[0105] Example 1: An implementation method for preventing authentication relay attacks on a connected terminal device. This example uses a first message to indicate the downlink channel state information last reported by the terminal device. The first message is illustrated by taking a radio resource control (RRC) reconfiguration message (RRCReconfiguration message) as an example. It should be noted that the first message can also be other messages, and this application does not make specific limitations.

[0106] As shown in Figure 3, this method includes:

[0107] S301: The terminal device performs random access.

[0108] Specifically, the terminal device can perform random access through a four-step random access process or a two-step random access process, which will not be further explained here.

[0109] It can be understood that after performing random access, the terminal device establishes an RRC connection with the legal network device and switches from the idle state to the connected state.

[0110] S302: The terminal device and the core network device complete security authentication.

[0111] It is understood that after the terminal device and the core network device complete security authentication, the core network device can send a message for notifying that the authentication is successful, and accordingly, the terminal device can receive a message for notifying that the authentication is successful. In one possible implementation, the core network device can send a message for notifying that the authentication is successful to the terminal device via a network device. It is understood that after forwarding by the network device, the terminal device can receive a third message, which is used to indicate that the authentication is successful.

[0112] In this way, security authentication is performed through the terminal device and the core network, so that the terminal device can record relevant information of the downlink message after security authentication (such as downlink channel status information, modulation level, etc.), so that it can be identified whether the subsequent message comes from a legitimate network device based on the recorded information, so as to prevent authentication relay attacks.

[0113] Optionally, after the terminal device and the core network device complete security authentication, the network device and the terminal device have a symmetric key. The terminal device and the network device can use this key to encrypt messages, thereby preventing unauthorized base stations from tampering with authentication messages.

[0114] For example, the network device can carry a digital signature in the RRC reconfiguration message below, and the digital signature is encrypted using the private key corresponding to the key. Accordingly, after receiving the RRC reconfiguration message, the terminal device can use the public key corresponding to the key to decrypt the digital signature of the RRC reconfiguration message.

[0115] S303, the network device sends a downlink reference signal to the terminal device.

[0116] S304: The terminal device measures the downlink reference signal.

[0117] S305: The terminal device sends downlink channel status information to the network device.

[0118] S306: The terminal device records the downlink channel state information.

[0119] There is no strict execution order for S306 and S305. S305 may be executed first and then S306, or S306 may be executed first and then S305, or S305 and S306 may be executed simultaneously.

[0120] S307: The network device records the downlink channel state information.

[0121] There is no strict execution order for S306 and S307. S307 may be executed first and then S306, or S306 may be executed first and then S307, or S307 and S306 may be executed simultaneously.

[0122] S308, the network device sends an RRC reconfiguration message to the terminal device.

[0123] The RRC reconfiguration message carries the above-mentioned downlink channel state information.

[0124] S309: The terminal device compares the downlink channel state information carried in the RRC reconfiguration message with the last reported downlink channel state information recorded by itself.

[0125] If the downlink channel state information carried in the RRC reconfiguration message is consistent with the downlink channel state information last reported in its own record, the terminal device can determine that the network device is legitimate. Optionally, if the network device is legitimate, the terminal device sends an RRC reconfiguration complete message to the network device.

[0126] If the downlink channel state information carried in the RRC reconfiguration message is inconsistent with the last reported downlink channel state information recorded by the terminal device, the terminal device can determine that the network device is illegal.

[0127] Optionally, in Example 1 above, after S307, the network device may also send a downlink reference signal, so that the terminal device can carry the measured downlink channel state information in the RRC reconfiguration complete message. In this solution, the terminal device and the network device can record the downlink channel state information measured this time to facilitate the terminal device to identify subsequent messages.

[0128] Since the downlink channel status information can provide feedback on the communication channel quality between the terminal device and the legitimate network device, if an illegal network device (or illegal terminal device) communicates with the terminal device, the communication channel will change, and the downlink channel status information measured by the terminal device will be inconsistent with the downlink channel status information of the legitimate network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0129] Example 2: Another implementation method for preventing authentication relay attacks on a connected terminal device. This example is illustrated by taking the first message indicating the modulation level adopted (or indicated) by the second message, the first message being a radio resource control (RRC) reconfiguration message (RRCReconfiguration message), and the second message being the last downlink message sent, or the second message being the downlink message with the best signal quality among the downlink messages sent within a preset time period. It should be noted that the first message can also be other messages, and this application does not make specific limitations.

[0130] As shown in Figure 4, this method includes:

[0131] S401 to S402 may refer to the above-mentioned S301 to S302 and will not be described again here.

[0132] S403: The network device sends a downlink message to the terminal device.

[0133] It is understandable that in step S403, the network device may send one or more downlink messages to the terminal device. This application does not limit the order in which the multiple downlink messages are sent.

[0134] S404: The terminal device records the modulation level of the received downlink message.

[0135] The modulation level of the downlink message may refer to the modulation level adopted or indicated by the downlink message.

[0136] For example, the modulation level of the received downlink message may be recorded after the timer T is started. Optionally, the timer T may be started after the terminal device receives the first downlink message.

[0137] S405: The network device sends an RRC reconfiguration message to the terminal device.

[0138] The RRC reconfiguration message is modulated using the modulation level of the second message, wherein the second message is the last downlink message sent, or the second message is the downlink message with the best signal quality among the downlink messages sent within a preset time period, wherein the preset time period may be the timer T.

[0139] S406: The terminal device compares the modulation level used in the RRC reconfiguration message with the modulation level of the second message recorded in the terminal device.

[0140] If the modulation level used in the RRC reconfiguration message is consistent with the modulation level of the second message recorded in the terminal device, the terminal device can determine that the network device is legitimate. Optionally, if the network device is legitimate, the terminal device sends an RRC reconfiguration completion message to the network device.

[0141] If the modulation level used in the RRC reconfiguration message is inconsistent with the modulation level of the second message recorded in the terminal device, the terminal device can determine that the network device is illegal.

[0142] Since the modulation level is related to the quality of the communication channel, the better the channel quality, the higher the modulation level. Therefore, if an illegal network device (or illegal terminal device) communicates with a terminal device, the communication channel will change. The channel quality between the illegal network device and the terminal device is different from the channel quality between the legal network device and the terminal device. The illegal network device may even be unable to support high-order modulation levels. Therefore, the modulation level of the downlink message sent by the illegal network device is inconsistent with the modulation level of the downlink message sent by the legal network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0143] Example 3: An implementation method for preventing authentication relay attacks in a non-connected terminal device. Specifically, a non-connected terminal device can prevent authentication relay attacks during the random access process. This example uses the first message indicating the modulation level used (or indicated) by Msg2 as an example, where the first message is Msg4.

[0144] As shown in Figure 5, this method includes:

[0145] S501: The terminal device sends Msg1 to the network device.

[0146] For Msg1, please refer to the relevant introduction of Msg1 in the previous terminology, and will not be repeated here.

[0147] S502: The network device sends Msg2 to the terminal device.

[0148] For Msg2, please refer to the relevant introduction of Msg2 in the previous terminology, and will not be repeated here.

[0149] Optionally, Msg2 can be encrypted using a private key. For example, Msg2 can carry a digital signature encrypted using the private key. In one possible implementation, the network device can summarize the message content of Msg2 and then encrypt the summary using the private key.

[0150] If Msg2 is encrypted, the terminal device can use the public key to decrypt Msg2 to verify that the content of Msg2 has not been tampered with by an unauthorized device. For example, if Msg2 carries a digital signature, the terminal device can use the public key to decrypt the signature to determine whether the content of Msg2 has been tampered with by an unauthorized device. Furthermore, since unauthorized network devices cannot obtain the configuration certificate and therefore the legitimate public key, this solution can also determine whether Msg2 originated from a legitimate network device.

[0151] Among them, the public key can be indicated to the terminal device by the network device. For example, the network device can obtain a configuration certificate from a third-party device (such as an operator, application (APP) server, etc.), and the configuration certificate includes the public key and indicates it to the terminal device.

[0152] The terminal device and the network device may record the modulation level indicated by Msg2.

[0153] S503: The terminal device sends Msg3 to the network device.

[0154] For Msg3, please refer to the relevant introduction of Msg3 in the previous terminology, and will not be repeated here.

[0155] S504: The network device sends Msg4 to the terminal device.

[0156] The modulation level used in Msg4 is the modulation level indicated by Msg2.

[0157] Optionally, Msg4 can be encrypted using a private key. For example, Msg4 can carry a digital signature encrypted using the private key. In one possible implementation, the network device can summarize the message content of Msg4 and then encrypt the summary using the private key.

[0158] The above example can identify whether the message content of the fourth message has been tampered with by encrypting the fourth message. Moreover, since an illegal network device cannot obtain a configuration certificate, it cannot obtain a legal public key. Therefore, the above scheme can also be used to determine whether Msg4 comes from a legal network device.

[0159] S505: The terminal device compares the modulation level used in Msg4 with the modulation level indicated by Msg2 recorded in the terminal device.

[0160] If the modulation level used in Msg4 is consistent with the modulation level indicated by Msg2 recorded in the terminal device, the terminal device can determine that the network device is legitimate. Optionally, if the network device is legitimate, the terminal device can perform data transmission with the network device.

[0161] If the modulation level used in Msg4 is inconsistent with the modulation level indicated by Msg2 recorded in the terminal device, the terminal device may determine that the network device is illegal.

[0162] Optionally, if Msg2 and Msg4 carry digital signatures, the terminal device can also use the public key to decrypt the digital signature of Msg4 when determining whether the network device is legitimate, to determine whether the content of Msg4 has been tampered with. The public key used to decrypt the digital signature of Msg4 is the same as the public key used to decrypt the digital signature of Msg2.

[0163] Since the modulation level is related to the quality of the communication channel, the better the channel quality, the higher the modulation level. Therefore, if an illegal network device (or illegal terminal device) communicates with a terminal device, the communication channel will change. The channel quality between the illegal network device and the terminal device is different from the channel quality between the legal network device and the terminal device. The illegal network device may even be unable to support high-order modulation levels. Therefore, the modulation level of Msg4 sent by the illegal network device is inconsistent with the modulation level of Msg2 sent by the legal network device. Therefore, after receiving the message from the illegal network device, the terminal device can identify the existence of an authentication relay attack, thereby preventing the authentication relay attack.

[0164] Furthermore, the above example can identify whether the message contents of Msg2 and Msg4 have been tampered with by carrying digital signatures in Msg2 and Msg4, which is beneficial to improving communication security.

[0165] Based on the same inventive concept as the method embodiment, an embodiment of the present application provides a communication device, the structure of which may be as shown in FIG6 , including a communication unit 601 and a processing unit 602 .

[0166] In one embodiment, a communication device can be specifically used to implement the method executed by the terminal device in the embodiment of Figure 2. The device can be the terminal device itself, or it can be a chip or chipset in the terminal device, or a part of the chip used to execute the function of the relevant method. Among them, the communication unit 601 is used to receive a first message, and the first message indicates first information. The first information includes at least one of the following: first physical layer measurement information, first physical layer configuration information. The processing unit 602 is used to determine whether the network device is legal based on the first information and second information. The second information includes at least one of the following: second physical layer measurement information recorded in the history, and second physical layer configuration information recorded in the history.

[0167] Exemplarily, the first physical layer measurement information includes the downlink channel state information carried by the first message, and the second physical layer measurement information includes the downlink channel state information reported last time.

[0168] Exemplarily, the first physical layer configuration information includes at least one of the following items: the modulation level adopted by the first message, the system frame number carried by the first message, the random access timing index carried by the first message, and the preamble index carried by the first message; the second physical layer configuration information includes at least one of the following items: the modulation level adopted by the second message, the system frame number indicated by the second message, the random access timing index indicated by the second message, and the preamble index indicated by the second message, wherein the second message is the downlink message received last time, or the second message is the downlink message with the best signal quality among the downlink messages received within a preset time period.

[0169] Optionally, the processing unit 602 is specifically configured to: if the first information is consistent with the second information, the network device is legal.

[0170] Optionally, if the network device is legal, the communication unit 601 is further configured to: receive a downlink reference signal; and send a response message to the first message, where the response message carries physical layer measurement information corresponding to the downlink reference signal.

[0171] Optionally, the communication unit 601 is further used to: receive a third message before receiving the first message, where the third message is used to indicate that the authentication is successful.

[0172] Exemplarily, the first message is an RRC reconfiguration message.

[0173] Exemplarily, the first physical layer configuration information includes at least one of the following items: the modulation level used by the first message, the system frame number carried by the first message, the random access timing index carried by the first message, and the preamble code index carried by the first message; the second physical layer configuration information includes at least one of the following items: the modulation level indicated by the fourth message, the system frame number carried or used by the fourth message, the random access timing index carried or used by the fourth message, and the preamble code index carried or used by the fourth message, wherein the fourth message is the most recently received downlink message that was successfully decrypted using the public key.

[0174] Optionally, the processing unit 602 is specifically configured to: if the first information is consistent with the second information, and the first message is successfully decrypted using the public key, then the network device is legal.

[0175] Optionally, the communication unit 601 is further configured to: receive a system message, where the system message indicates a public key.

[0176] Exemplarily, the first message is message 4 in the random access process, and the fourth message is message 2 in the random access process.

[0177] In one embodiment, the communication device can be used to implement the method performed by the network device in the embodiment of FIG. 2 . The device can be the network device itself, or a chip or chipset in the network device or a part of the chip used to perform the functions of the related method.

[0178] The processing unit 602 is used to send a first message through the communication unit 601. The first message indicates first information. The first information includes at least one of the following: first physical layer measurement information of the historical record, first physical layer configuration information of the historical record, and the first information is used to determine whether the network device is legal.

[0179] Exemplarily, the first physical layer measurement information is the downlink channel state information received last time.

[0180] Exemplarily, the first physical layer configuration information includes at least one of the following items: the modulation level adopted by the second message, the system frame number carried or used by the second message, the random access timing index carried or used by the second message, and the preamble code index carried or used by the second message, wherein the second message is the downlink message sent last time, or the second message is the downlink message with the best signal quality among the downlink messages sent within a preset time period.

[0181] Optionally, the communication unit 601 is further configured to: send a downlink reference signal; and receive a response message to the first message, where the response message carries physical layer measurement information corresponding to the downlink reference signal.

[0182] Optionally, the communication unit 601 is further used to: send a third message before sending the first message, where the third message is used to indicate that the authentication is successful.

[0183] Exemplarily, the first message is a radio resource control RRC reconfiguration message.

[0184] Exemplarily, the first physical layer configuration information includes at least one of the following items: a modulation level indicated by a fourth message, a system frame number indicated by the fourth message, a random access timing index indicated by the fourth message, and a preamble code index indicated by the fourth message, wherein the fourth message is the most recently sent downlink message encrypted using a private key, and the private key is the same as the private key used to encrypt the first message.

[0185] Optionally, the communication unit 601 is further configured to send a system message, where the system message indicates a public key corresponding to the private key.

[0186] Exemplarily, the first message is message 4 in the random access process, and the fourth message is message 2 in the random access process.

[0187] The division of modules in the embodiments of the present application is schematic and is only a logical function division. In actual implementation, there may be other division methods. In addition, the functional modules in the various embodiments of the present application can be integrated into a processor, or can exist physically separately, or two or more modules can be integrated into one module. The above-mentioned integrated modules can be implemented in the form of hardware or in the form of software functional modules. It is understood that the functions or implementations of the various modules in the embodiments of the present application can be further referred to the relevant description of the method embodiment.

[0188] In one possible embodiment, a communication device may be as shown in FIG7 . The device may be a communication device or a chip within the communication device, wherein the communication device may be a terminal device or a network device in the above embodiments. The device includes a processor 701 and a communication interface 702, and may also include a memory 703. The processing unit 602 may be the processor 701. The communication unit 601 may be the communication interface 702. Optionally, the processor 701 and the memory 703 may be integrated.

[0189] The processor 701 may be a CPU, a digital processing unit, or the like. The communication interface 702 may be a transceiver, an interface circuit such as a transceiver circuit, or a transceiver chip, or the like. The apparatus further includes a memory 703 for storing programs executed by the processor 701. The memory 703 may be a non-volatile memory, such as a hard disk drive (HDD) or a solid-state drive (SSD), or a volatile memory (volatile memory), such as a random-access memory (RAM). The memory 703 is any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.

[0190] The processor 701 is used to execute the program code stored in the memory 703, specifically to execute the actions of the processing unit 602, which will not be described in detail in this application. The communication interface 702 is specifically used to execute the actions of the communication unit 601, which will not be described in detail in this application.

[0191] The specific connection medium between the communication interface 702, processor 701, and memory 703 is not limited in the embodiments of the present application. In Figure 7, the memory 703, processor 701, and communication interface 702 are connected via bus 704. The bus is represented by a bold line in Figure 7. The connection between other components is only for illustrative purposes and is not intended to be limiting. Buses can be divided into address buses, data buses, control buses, etc. For ease of illustration, Figure 7 only uses a single bold line, but this does not mean that there is only one bus or only one type of bus.

[0192] An embodiment of the present invention further provides a computer-readable storage medium for storing computer software instructions required to be executed by the above-mentioned processor, which includes a program required to be executed by the above-mentioned processor.

[0193] An embodiment of the present application also provides a communication system, including a communication device for implementing the terminal device function in the embodiment of Figure 2 and a communication device for implementing the network device function in the embodiment of Figure 2.

[0194] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0195] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or box in the flow chart and / or block diagram, as well as the combination of the flow chart and / or box in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more flow charts and / or one or more boxes in the block diagram.

[0196] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0197] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0198] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A communication method, characterized in that: The method comprises: receiving a first message, where the first message indicates first information, where the first information includes at least one of the following: first physical layer measurement information and first physical layer configuration information; Determine whether the network device is legal based on the first information and the second information, where the second information includes at least one of the following: second physical layer measurement information recorded in the historical records, and second physical layer configuration information recorded in the historical records.

2. The method according to claim 1, characterized in that The first physical layer measurement information includes the downlink channel state information carried by the first message, and the second physical layer measurement information includes the downlink channel state information reported last time.

3. The method according to claim 1 or 2, characterized in that The first physical layer configuration information includes at least one of the following: a modulation level used by the first message, a system frame number carried by the first message, a random access opportunity index carried by the first message, and a preamble index carried by the first message; The second physical layer configuration information includes at least one of the following: a modulation level adopted by the second message, a system frame number indicated by the second message, a random access timing index indicated by the second message, and a preamble code index indicated by the second message, wherein the second message is the last received downlink message, or the second message is the downlink message with the best signal quality among the downlink messages received within a preset time period.

4. The method according to any one of claims 1 to 3, characterized in that: The determining whether the network device is legal according to the first information and the second information includes: If the first information is consistent with the second information, the network device is legal.

5. The method according to any one of claims 1 to 4, characterized in that: If the network device is legal, the method further includes: receiving a downlink reference signal; A response message is sent to the first message, where the response message carries physical layer measurement information corresponding to the downlink reference signal.

6. The method according to any one of claims 1 to 5, characterized in that: Before receiving the first message, the method further includes: A third message is received, where the third message is used to indicate that the authentication is successful.

7. The method according to any one of claims 1 to 6, characterized in that: The first message is a radio resource control RRC reconfiguration message.

8. The method according to claim 1 or 2, characterized in that: The first physical layer configuration information includes at least one of the following: a modulation level used by the first message, a system frame number carried by the first message, a random access opportunity index carried by the first message, and a preamble index carried by the first message; The second physical layer configuration information includes at least one of the following items: a modulation level indicated by a fourth message, a system frame number carried or used by the fourth message, a random access timing index carried or used by the fourth message, and a preamble code index carried or used by the fourth message, wherein the fourth message is the most recently received downlink message that was successfully decrypted using a public key.

9. The method according to claim 8, characterized in that The determining whether the network device is legal according to the first information and the second information includes: If the first information is consistent with the second information, and the first message is successfully decrypted using the public key, then the network device is legal.

10. The method according to claim 8 or 9, characterized in that The method further comprises: A system message is received, the system message indicating the public key.

11. The method according to any one of claims 8 to 10, characterized in that: The first message is message 4 in the random access process, and the fourth message is message 2 in the random access process.

12. A communication method, characterized in that: The method comprises: A first message is sent, where the first message indicates first information, where the first information includes at least one of the following: first physical layer measurement information recorded in history, first physical layer configuration information recorded in history, and the first information is used to determine whether the network device is legal.

13. The method according to claim 12, characterized in that The first physical layer measurement information is the downlink channel state information received last time.

14. The method according to claim 12 or 13, characterized in that The first physical layer configuration information includes at least one of the following: a modulation level adopted by the second message, a system frame number carried or used by the second message, a random access timing index carried or used by the second message, and a preamble code index carried or used by the second message, wherein the second message is the last downlink message sent, or the second message is the downlink message with the best signal quality among the downlink messages sent within a preset time period.

15. The method according to any one of claims 12 to 14, characterized in that: The method further comprises: Sending a downlink reference signal; A response message to the first message is received, where the response message carries physical layer measurement information corresponding to the downlink reference signal.

16. The method according to any one of claims 12 to 15, characterized in that: Before sending the first message, the method further includes: A third message is sent, where the third message is used to indicate that the authentication is successful.

17. The method according to any one of claims 12 to 16, characterized in that: The first message is a radio resource control RRC reconfiguration message.

18. The method according to claim 12 or 13, characterized in that The first physical layer configuration information includes at least one of the following items: a modulation level indicated by a fourth message, a system frame number indicated by a fourth message, a random access timing index indicated by a fourth message, and a preamble code index indicated by a fourth message, wherein the fourth message is the most recently sent downlink message encrypted with a private key, and the private key is the same as the private key used to encrypt the first message.

19. The method according to claim 18, characterized in that The method further comprises: A system message is sent, where the system message indicates a public key corresponding to the private key.

20. The method according to claim 18 or 19, characterized in that The first message is message 4 in the random access process, and the fourth message is message 2 in the random access process.

21. A communication device, characterized in that: The method comprises a unit or module for executing the method according to any one of claims 1 to 11, or comprises a unit or module for executing the method according to any one of claims 12 to 20.

22. A computer-readable storage medium, characterized in that: The computer storage medium stores computer-readable instructions, and when the computer-readable instructions are executed on the communication device, the method according to any one of claims 1 to 11 is executed, or the method according to any one of claims 12 to 20 is executed.

23. A computer program product, characterized in that When the computer program product runs on a device, the device is enabled to execute the method according to any one of claims 1 to 11 or the method according to any one of claims 12 to 20.

Citation Information

Patent Citations

  • Network equipment legality identification method and device, storage medium, terminal equipment and base station

    CN114390522A

  • Method and device for detecting pseudo base station

    CN116669034A

  • Information protection to detect FAKE base stations

    US20200236554A1

  • Wireless channel power profile false base station detection

    US20210153024A1