Communication method and communication apparatus

By interacting public keys between the terminal and the network device and generating a shared key, encrypting information transmission, the problem of information not being authenticated and integrity verified during random access is solved, and communication security is improved.

WO2025092738A1PCT designated stage expired Publication Date: 2025-05-08HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/128179
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-30
Filing Date
2024-10-29
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

During the random access process, due to the unauthentication and integrity verification, there are security vulnerabilities and are easily attacked and information is leaked.

Method used

By interacting with each other's public keys between the terminal and the network device, a shared key is generated and the message is encrypted based on the shared key, ensuring the secure transmission of information during the random access process.

Benefits of technology

It effectively reduces the risk of information leakage during random access, improves communication security, and prevents malicious attackers from tampering with and leaking information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024128179_08052025_PF_FP_ABST
    Figure CN2024128179_08052025_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a communication method and a communication apparatus, which are used for improving communication security. The method comprises: a network device sending to a terminal a public key of the network device and an encryption algorithm list supported by the network device; the terminal sending to the network device an identifier of an encryption algorithm selected by the terminal and a public key of a terminal device, wherein a first message further comprises a random access preamble or a random access cause value; the network device encrypting a second message on the basis of the encryption algorithm selected by the terminal and a shared key, and sending the second message, wherein the shared key is acquired on the basis of a second public key and a private key of the network device; and the terminal decrypting the second message on the basis of a first encryption algorithm and the shared key. By means of the method, a network device and a terminal make a key agreement during a random access process, such that information leakage during the random access process can be reduced, and communication security can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and communication device

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on October 30, 2023, with application number 202311435752.6 and application name "A Communication Method and Communication Device", the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of communication security technology, and in particular to a communication method and a communication device. Background Art

[0004] Terminal devices initiate random access to connect to network devices, enabling service transmission between them. However, because the information exchanged between network devices and terminal devices does not involve identity authentication, and much of the information during random access is transparent, the random access process has security vulnerabilities and is vulnerable to attacks. For example, a terminal device could leak information to other devices through the network device, resulting in low communication security.

[0005] Summary of the Invention

[0006] The present application provides a communication method and a communication device for protecting information security during random access and reducing information leakage due to attacks.

[0007] To achieve the above objectives, the present invention adopts the following technical solutions:

[0008] In a first aspect, embodiments of the present application provide a communication method that can be performed by a first communication device. The first communication device can be a terminal, or the first communication device can be a component used to implement the functions of a terminal. For example, the first communication device can be a unit / module, circuit, or chip within the terminal. The method provided in the first aspect is described below using the first communication device as an example of a terminal.

[0009] The communication method includes: a terminal receiving first information, sending a first message, receiving a second message, and decrypting the second message based on a first encryption algorithm and a shared key. The first information indicates a first public key and at least one encryption algorithm. The first message indicates the first encryption algorithm and the second public key. The at least one encryption algorithm is an encryption algorithm supported by the network device, and the first encryption algorithm belongs to the at least one encryption algorithm. The first message also includes a random access preamble or a random access cause value. The shared key is obtained based on the first public key and a first private key, where the first private key is a private key of the terminal.

[0010] In this scheme, the terminal obtains the network device's public key and supported encryption algorithms through a first message, and then notifies the network device of the terminal's public key and the first encryption algorithm used through a first message. That is, based on the first information and the first message, the network device and the terminal exchange their public keys. Subsequently, the network device and the terminal can derive a shared key using the obtained public key and its own private key, and encrypt messages to be sent based on the shared key. For example, the network device encrypts the second message based on the obtained shared key. Because the shared key is generated from both the private key and the public key, and because different terminals have different private keys, even if another terminal obtains the second message, it cannot decrypt it and obtain the content of the second message because it lacks the shared key. This reduces the possibility of leaking the second message's content and improves communication security. It should be understood that during the random access process, the messages exchanged between the terminal and the network device do not involve identity authentication or message integrity verification. Therefore, a malicious attacker could tamper with the content of the messages exchanged during the random access process and leak the information through network device broadcasts. In this solution, the first message also includes a random access preamble or a random access cause value, that is, the first message and the second message can be messages in the random access process. Therefore, this solution can reduce information leakage in the random access process and improve communication security.

[0011] In one implementation, the shared key is obtained based on the first public key and the first private key, including: the shared key is obtained based on the first public key, the first private key and the first parameter.

[0012] The first parameter can be a terminal-specific parameter or a parameter associated with a specific terminal. This solution uses the first parameter to derive a shared key. Even if one terminal knows the key of another terminal in advance, it cannot determine the shared key used by the other terminal because it does not know the first parameter used by the other terminal, further improving communication security.

[0013] In one implementation, the first parameter includes one or more of the following: a temporary cell radio network temporary identification (TC-RNTI), a synchronization signal index, or a random access resource index.

[0014] In one implementation, the first message is scrambled by a sequence generated by a preamble sequence index and / or a synchronization signal index.

[0015] By using the preamble sequence index and / or the synchronization signal index to scramble the first message, the decoding complexity of the first message at the receiving end can be increased, thereby further improving communication security.

[0016] In one implementation, the first message also includes a message verification code. When the first message includes a random access preamble, the message verification code is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm, and the second public key using the first encryption algorithm and a shared key.

[0017] In this solution, the terminal encrypts the random access preamble, the identifier of the first encryption algorithm, and the second public key using a first encryption algorithm and a shared key to obtain a message verification code, which is then carried in a first message and sent to the network device. This means that the terminal performs integrity protection on the first message, allowing the network device to determine whether the terminal maliciously initiates random access, thereby improving communication security. It is understood that different terminals use different shared keys. If there are multiple first messages sent using the same shared key, and the message verification codes in the first messages are encrypted using the same shared key, then there is a terminal maliciously initiating random access.

[0018] In one implementation, the first message also includes a message verification code. When the first message includes a random access reason value, the message verification code is obtained by encrypting the random access reason value, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and a shared key.

[0019] In this solution, the terminal performs integrity protection on the first message, so that the network device can determine whether the terminal maliciously initiates random access, thereby improving communication security.

[0020] In one implementation, before receiving the first information, the method further includes: the terminal receiving certificate information, the certificate information including a public key provided by an institution that issued the certificate; and the terminal performing signature verification on the certificate information based on the public key provided by the institution that issued the certificate.

[0021] In this solution, the network device can also send some content of the digital certificate to the terminal device to facilitate the terminal device to verify whether the network device is legitimate, so as to avoid the terminal from interacting with a fake network device. For example, if the terminal verifies that the network device is not legitimate, it may not receive the first information.

[0022] In a second aspect, embodiments of the present application provide a communication method that can be performed by a second communication device. The second communication device can be a network device, or a component used to implement the functions of the network device. For example, the second communication device can be a unit / module, circuit, or chip within the network device. The method provided in the second aspect is described below using the second communication device as an example, wherein the network device itself is the second communication device.

[0023] The communication method includes: a network device sending a first message, receiving a first message, encrypting a second message based on a first encryption algorithm and a shared key, and sending the encrypted second message. The first message indicates a first public key and at least one encryption algorithm. The at least one encryption algorithm is an encryption algorithm supported by the network device, and the first encryption algorithm is one of the at least one encryption algorithms. The first message indicates the first encryption algorithm and a second public key, where the second public key is the public key of the terminal. The shared key is obtained based on the second public key and a second private key, where the second private key is the private key of the network device.

[0024] In one implementation, the shared key is obtained based on the first public key and the first private key, including: the shared key is obtained based on the first public key, the first private key and the first parameter, and the first parameter includes one or more of the following: TC-RNTI, synchronization signal index, or random access resource index.

[0025] In one implementation, the first message is scrambled by a sequence generated by a preamble sequence index and / or a synchronization signal index.

[0026] In one implementation, the first message also includes a message verification code. When the first message includes a random access preamble, the message verification code is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm, and the second public key using the first encryption algorithm and a shared key.

[0027] In one implementation, the first message also includes a message verification code. When the first message includes a random access reason value, the message verification code is obtained by encrypting the random access reason value, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and a shared key.

[0028] In one implementation, before sending the first information, the method further includes: the network device obtaining certificate information and sending the certificate information. The certificate information includes a public key provided by an institution that issued the certificate, and the public key is used to perform signature verification on the certificate.

[0029] Regarding the beneficial effects of the second aspect and each implementation method, reference can be made to the beneficial effects of the aforementioned first aspect and each implementation method, which will not be repeated here.

[0030] In a third aspect, embodiments of the present application provide a communication method that can be performed by a first communication device. The first communication device can be a terminal, or the first communication device can be a component used to implement the functions of a terminal. For example, the first communication device can be a unit / module, circuit, or chip within the terminal. The method provided in the third aspect is described below using the first communication device being a terminal itself as an example.

[0031] The communication method includes: a terminal receiving first information, sending a first message, receiving a second message, encrypting a third message based on a first encryption algorithm and a shared key, and sending the encrypted third message. The first information indicates a first public key and at least one encryption algorithm, the at least one encryption algorithm being an encryption algorithm supported by the network device, and the first encryption algorithm being one of the at least one encryption algorithms. The first message indicates the first encryption algorithm and a second public key, the second public key being the public key of the terminal. The shared key used by the network device is obtained based on the second public key and a second private key, the second private key being the private key of the network device. The shared key used by the terminal is obtained based on the first public key and the first private key, the first private key being the private key of the terminal.

[0032] This solution differs from the solution provided in the first aspect in that, after obtaining the shared key, the terminal can encrypt the third message to be sent to the network device, while the network device does not need to encrypt the second message. In this solution, the terminal and network device exchange their public keys beforehand, then derive the shared key based on the obtained public key and its own private key. The message to be sent is encrypted based on the shared key, thereby improving communication security.

[0033] In one implementation, the method further includes: the terminal decrypting the second message according to the first encryption algorithm and the shared key.

[0034] In one implementation, the shared key is obtained based on the first public key and the first private key, including: the shared key is obtained based on the first public key, the first private key and the first parameter, and the first parameter includes one or more of the following: TC-RNTI, synchronization signal index, or random access resource index.

[0035] In one implementation, the first message is scrambled by a sequence generated by a preamble sequence index and / or a synchronization signal index.

[0036] In one implementation, the first message also includes a message verification code. When the first message includes a random access preamble, the message verification code is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm, and the second public key using the first encryption algorithm and a shared key.

[0037] In one implementation, the first message also includes a message verification code. When the first message includes a random access reason value, the message verification code is obtained by encrypting the random access reason value, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and a shared key.

[0038] In one implementation, before receiving the first information, the method further includes: the terminal receiving certificate information, the certificate information including a public key provided by an institution that issued the certificate; and the terminal performing signature verification on the certificate information based on the public key provided by the institution that issued the certificate.

[0039] Regarding the third aspect and the beneficial effects of each implementation method, reference can be made to the beneficial effects of the aforementioned first aspect and each implementation method, which will not be repeated here.

[0040] In a fourth aspect, embodiments of the present application provide a communication method that can be performed by a second communication device. The second communication device can be a network device, or a component used to implement the functions of the network device. For example, the second communication device can be a unit / module, circuit, or chip within the network device. The method provided in the fourth aspect is described below using the second communication device being the network device itself as an example.

[0041] The communication method includes: a network device sending a first message, receiving a first message, sending a second message, and decrypting a third message based on a first encryption algorithm and a shared key. The first message indicates a first public key and at least one encryption algorithm. The at least one encryption algorithm is an encryption algorithm supported by the network device, and the first encryption algorithm is one of the at least one encryption algorithms. The first message includes a random access preamble, an identifier of the first encryption algorithm, and a second public key, where the second public key is a public key of a terminal and an encryption algorithm supported by the network device. The shared key is obtained based on the second public key and a second private key, where the second private key is a private key of the network device.

[0042] In one implementation, before sending the second message, the method further includes: the network device encrypting the second message according to the first encryption algorithm and the shared key.

[0043] In one implementation, the shared key is obtained based on the first public key and the first private key, including: the shared key is obtained based on the first public key, the first private key and the first parameter, and the first parameter includes one or more of the following: TC-RNTI, synchronization signal index, or random access resource index.

[0044] In one implementation, the first message is scrambled by a sequence generated by a preamble sequence index and / or a synchronization signal index.

[0045] In one implementation, the first message also includes a message verification code. When the first message includes a random access preamble, the message verification code is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm, and the second public key using the first encryption algorithm and a shared key.

[0046] In one implementation, the first message also includes a message verification code. When the first message includes a random access reason value, the message verification code is obtained by encrypting the random access reason value, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and a shared key.

[0047] In one implementation, before receiving the first information, the method further includes: the network device obtaining certificate information and sending the certificate information, where the certificate information includes a public key provided by an institution that issues the certificate.

[0048] Regarding the fourth aspect and the beneficial effects of each implementation method, reference can be made to the beneficial effects of the aforementioned first aspect and each implementation method, which will not be repeated here.

[0049] In a fifth aspect, embodiments of the present application provide a communication method that can be performed by a first communication device. The first communication device can be a terminal, or the first communication device can be a component used to implement the functions of a terminal. For example, the first communication device can be a unit / module, circuit, or chip within the terminal. The method provided in the fifth aspect is described below using the first communication device being a terminal itself as an example.

[0050] The communication method includes: the terminal receives a first message, sends a first message, and receives a second message, and decrypts the second message according to a first encryption algorithm and a shared key. The first information indicates a first public key and at least one encryption algorithm, and the first public key is a public key of a network device. The at least one encryption algorithm is an encryption algorithm supported by the network device, and the first encryption algorithm belongs to at least one encryption algorithm. The first message indicates the first encryption algorithm and a second public key, and the second public key is the public key of the terminal. The first message is scrambled by a sequence generated by a preamble sequence index and / or a synchronization signal index. The first message also includes a random access preamble or a random access reason value. The shared key is obtained based on the first public key and the first private key, and the first private key is the private key of the terminal.

[0051] Accordingly, in a sixth aspect, embodiments of the present application provide a communication method that can be performed by a second communication device. The second communication device can be a network device, or the second communication device can be a component used to implement the functions of the network device. For example, the second communication device can be a unit / module, circuit, or chip within the network device. The method provided in the sixth aspect is described below using the second communication device as the network device itself as an example. Of course, the method provided in the sixth aspect can also be implemented by a unit / module, circuit, or chip within the network device.

[0052] The communication method includes: a network device sends a first information, receives a first message, and encrypts a second message according to a first encryption algorithm and a shared key. The first information indicates a first public key and at least one encryption algorithm, and the at least one encryption algorithm is an encryption algorithm supported by the network device. The first message indicates a first encryption algorithm and a second public key, the second public key is a public key of the terminal, and the first message is scrambled by a sequence generated by a preamble sequence index and / or a synchronization signal index. The first encryption algorithm belongs to at least one encryption algorithm. The first message also includes a random access preamble or a random access cause value. The shared key is obtained based on the second public key and the second private key, and the first private key is the private key of the network device.

[0053] In the method provided in the fifth or sixth aspect, the network device and the terminal exchange public keys during the random access process, and subsequently encrypt messages to be sent based on the shared key. This solution can reduce information leakage during the random access process and improve communication security. Furthermore, the terminal can scramble the first message using a sequence generated by a preamble sequence index and / or a synchronization signal index to further enhance communication security.

[0054] In a seventh aspect, an embodiment of the present application provides a communication method that can be performed by a first communication device and a second communication device. The first communication device may be a terminal, or the first communication device may be a component for implementing the functions of the terminal. For example, the first communication device is a unit / module, circuit, or chip inside the terminal. The second communication device may be a network device, or the second communication device may be a component for implementing the functions of the network device. For example, the second communication device is a unit / module, circuit, or chip inside the network device. The method provided in the seventh aspect is described below using the first communication device as the terminal itself and the second communication device as the network device itself as an example.

[0055] The communication method includes: a network device sending first information to a terminal, the first information indicating a first public key and at least one encryption algorithm, the at least one encryption algorithm being an encryption algorithm supported by the network device; the terminal sending a first message to the network device, the first message indicating the first encryption algorithm and the second public key; the network device encrypting a second message according to the first encryption algorithm and a shared key, and sending a second message, the shared key being obtained based on the second public key and the first private key, the first private key being the private key of the network device, and the first encryption algorithm being one of the at least one encryption algorithms; the terminal receiving the second message, decrypting the second message according to the first encryption algorithm and the shared key, the shared key being obtained based on the first public key and the second private key, the second private key being the private key of the terminal. The first message also includes a random access preamble or a random access cause value.

[0056] In an eighth aspect, an embodiment of the present application provides a communication method that can be performed by a first communication device and a second communication device. The first communication device may be a terminal, or the first communication device may be a component for implementing the functions of the terminal. For example, the first communication device is a unit / module, circuit, or chip inside the terminal. The second communication device may be a network device, or the second communication device may be a component for implementing the functions of the network device. For example, the second communication device is a unit / module, circuit, or chip inside the network device. The method provided in the eighth aspect is described below using the first communication device as the terminal itself and the second communication device as the network device itself as an example.

[0057] The communication method includes: a network device sends first information to a terminal, the first information indicating a first public key and at least one encryption algorithm, the at least one encryption algorithm being an encryption algorithm supported by the network device; the terminal sends a first message to the network device, the first message indicating a first encryption algorithm and a second public key, the first encryption algorithm being one of the at least one encryption algorithms; the network device sends a second message to the terminal; the terminal encrypts a third message based on the first encryption algorithm and a shared key, and sends the encrypted third message to the network device. The shared key is obtained based on the first public key and a first private key, and the first private key is a private key of the terminal.

[0058] In the ninth aspect, an embodiment of the present application provides a communication device, which has the function of implementing the behaviors in the method examples of the first to sixth aspects above. The beneficial effects can be found in the relevant descriptions of the first to sixth aspects and will not be repeated here. For example, the communication device may be the terminal in the first aspect or the third aspect or the fifth aspect, or the communication device may be the network device in the second aspect or the fourth aspect or the sixth aspect. For another example, the communication device may be a device that can support the terminal to implement the functions required by the method provided in the first aspect or the third aspect or the fifth aspect, for example, the communication device may be a chip or chip system in the terminal. Or, for another example, the communication device may be a device that can support the network device to implement the functions required by the method provided in the second aspect or the fourth aspect or the sixth aspect, for example, the communication device may be a chip or chip system in the network device.

[0059] In one possible design, the communication device includes a baseband device and a radio frequency device.

[0060] In one possible design, the communication device includes corresponding means (means) or modules for executing the method of any aspect from the first aspect to the sixth aspect. For example, the communication device includes a processing unit (sometimes also referred to as a processing module or processor) and / or a transceiver unit (sometimes also referred to as a transceiver module or transceiver). The transceiver unit can realize the sending function and the receiving function. When the transceiver unit realizes the sending function, it can be called a sending unit (sometimes also referred to as a sending module). When the transceiver unit realizes the receiving function, it can be called a receiving unit (sometimes also referred to as a receiving module). The sending unit and the receiving unit can be the same functional unit, which is called a transceiver unit, and the functional unit can realize the sending function and the receiving function; or, the sending unit and the receiving unit can be different functional units, and the transceiver unit is a general term for these functional units. These units (modules) can perform the corresponding functions in the method examples of any aspect from the first aspect to the sixth aspect above. Please refer to the detailed description in the method examples for details, which will not be repeated here.

[0061] In a tenth aspect, an embodiment of the present application provides a communication device, which may be the communication device in the ninth aspect of the above-mentioned embodiment, or a chip or chip system provided in the communication device in the ninth aspect. The communication device includes a communication interface and a processor, and optionally, also includes a memory. The memory is used to store computer programs or instructions or data, and the processor is coupled to the memory and the communication interface. When the processor reads the computer program or instructions or data, the communication device executes the method executed by the terminal in the above-mentioned method embodiment. For example, the communication device may be a terminal or a functional module in the terminal, such as a baseband chip and a radio frequency chip. Alternatively, when the processor reads the computer program or instructions or data, the communication device executes the method executed by the network device in the above-mentioned method embodiment. For example, the communication device may be a network device or a functional module in the network device, such as a baseband chip and a radio frequency chip.

[0062] In the eleventh aspect, an embodiment of the present application provides a chip system, which includes a processor and may also include a communication interface for implementing the method described in any of the first to fourth aspects. Optionally, the chip system also includes a memory. The memory is used to store a computer program (also referred to as code, or instruction). The processor is used to call and run a computer program from the memory, so that a device equipped with the chip system executes the method in the first aspect and any possible implementation thereof, or causes a device equipped with the chip system to execute the method in the second aspect and any possible implementation thereof, or causes a device equipped with the chip system to execute the method in the third aspect and any possible implementation thereof, or causes a device equipped with the chip system to execute the method in the fourth aspect and any possible implementation thereof, or causes a device equipped with the chip system to execute the method in the fifth aspect and any possible implementation thereof, or causes a device equipped with the chip system to execute the method in the sixth aspect and any possible implementation thereof. The chip system can be composed of chips, or it can include chips and other discrete devices.

[0063] In a twelfth aspect, an embodiment of the present application provides a communication device comprising an input / output interface and a logic circuit. The input / output interface is used to input and / or output information. The input / output interface can be an interface circuit, an output circuit, an input circuit, a pin, or related circuits. The logic circuit is used to execute the method described in any of aspects 1 to 6.

[0064] In a specific implementation, the communication device may be a chip, the input circuit may be an input pin, the output circuit may be an output pin, and the logic circuit may be a transistor, a gate circuit, a trigger, or various logic circuits. The input signal received by the input circuit may be, for example, but not limited to, received and input by a receiver, and the signal output by the output circuit may be, for example, but not limited to, output to and transmitted by a transmitter. The input circuit and the output circuit may be the same circuit, which functions as an input circuit and an output circuit, respectively, at different times. This application does not limit the specific implementation of the input and output interfaces and logic circuits.

[0065] In one implementation, when the communication device is a wireless communication device, the wireless communication device may be a terminal device such as a mobile phone, the interface circuit may be a radio frequency processing chip in the wireless communication device, and the processing circuit may be a baseband processing chip in the wireless communication device.

[0066] In a thirteenth aspect, an embodiment of the present application provides a communication system, comprising a terminal and a network device. The terminal is configured to implement the functions of the method described in the first aspect, and the network device is configured to implement the functions of the method described in the second aspect; or the terminal is configured to implement the functions of the method described in the third aspect, and the network device is configured to implement the functions of the method described in the fourth aspect; or the terminal is configured to implement the functions of the method described in the fifth aspect, and the network device is configured to implement the functions of the method described in the sixth aspect.

[0067] In the fourteenth aspect, an embodiment of the present application provides a computer-readable storage medium, which is used to store computer programs or instructions. When the computer-readable storage medium is executed, the method described in the first aspect and any possible implementation thereof is implemented, or the method described in the second aspect and any possible implementation thereof is implemented, or the method described in the third aspect and any possible implementation thereof is implemented, or the method described in the fourth aspect and any possible implementation thereof is implemented, or the method described in the fifth aspect and any possible implementation thereof is implemented, or the method described in the sixth aspect and any possible implementation thereof is implemented.

[0068] In a fifteenth aspect, an embodiment of the present application further provides a computer program product comprising instructions, which, when run on a computer, enables the method described in the first aspect and any possible implementation thereof to be implemented, or enables the method described in the second aspect and any possible implementation thereof to be implemented, or enables the method described in the third aspect and any possible implementation thereof to be implemented, or enables the method described in the fourth aspect and any possible implementation thereof to be implemented, or enables the method described in the fifth aspect and any possible implementation thereof to be implemented, or enables the method described in the sixth aspect and any possible implementation thereof to be implemented.

[0069] The beneficial effects of the above-mentioned ninth to fifteenth aspects and their implementation methods can refer to the description of the beneficial effects of the first to sixth aspects and any possible implementation methods thereof. BRIEF DESCRIPTION OF THE DRAWINGS

[0070] FIG1 is a schematic diagram of a communication system provided in an embodiment of the present application;

[0071] FIG2 is a schematic diagram of an example of a SPARROW attack provided in an embodiment of the present application;

[0072] FIG3 is a schematic diagram of the process of DH key negotiation and generating a shared key according to an embodiment of the present application;

[0073] FIG4 is a flow chart of a communication method 400 provided in an embodiment of the present application;

[0074] FIG5 is a schematic diagram of a shared key derivation process provided in an embodiment of the present application;

[0075] FIG6 is a flow chart of a communication method 600 provided in an embodiment of the present application;

[0076] FIG7 is a flow chart of a communication method 700 provided in an embodiment of the present application;

[0077] FIG8 is a schematic structural diagram of a communication device provided in an embodiment of the present application;

[0078] FIG9 is another schematic diagram of the structure of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0079] The method provided by the embodiment of the present application can prevent malicious attack devices from leaking information, improve the reliability of identifying malicious attack devices that tamper with information, and thus improve communication security. The solution provided by the embodiment of the present application is further described below with reference to the accompanying drawings.

[0080] The technical solutions provided in the embodiments of the present application can be applied to communication systems related to the 3rd Generation Partnership Project (3GPP), such as the Long Term Evolution (LTE) communication system, the sixth generation (5G) mobile communication system, or can also be applied to other next-generation mobile communication systems, such as the sixth generation (6G) communication system, or other similar communication systems. Other similar communication systems may include wireless fidelity (WIFI), vehicle to everything (V2X), Internet of Things (IoT) system, narrowband Internet of Things (NB-IoT) system, and the like.

[0081] Referring to Figure 1 , a communication system applicable to an embodiment of the present application is shown. The communication system includes a radio access network 100 and a core network 200. Optionally, the communication system may also include the Internet 300 (Figure 1 uses this as an example).

[0082] The wireless access network 100 may include at least one network device and at least one terminal. For example, the wireless access network 100 includes two network devices 110a and 110b and terminals 120a through 120j. The network architecture shown in FIG1 is merely illustrative, and the number of terminals and / or network devices may be fewer or greater. The communication system described in the embodiments of the present application is intended to more clearly illustrate the technical solutions of the embodiments of the present application and does not constitute a limitation on the communication systems to which the embodiments of the present application are applicable. For example, the communication system may also include other devices, such as wireless relay devices and wireless backhaul devices, which are not shown in FIG1. ​​Persons skilled in the art will appreciate that as network architectures evolve, the technical solutions provided in the embodiments of the present application will remain applicable to similar technical problems. When applying the technical solutions of the embodiments of the present application to other communication systems, the devices, components, and modules in the embodiments may be replaced with corresponding devices, components, and modules in other communication systems without limitation.

[0083] The network devices involved in the embodiments of the present application are mainly access network devices. Therefore, in the following text, unless otherwise specified, the "network devices" referred to are radio access network (RAN) devices, which can be referred to as access network devices for short. RAN can be a 3GPP-related cellular system, for example, a 5G mobile communication system, or a future-oriented evolution system (such as a 6G mobile communication system). RAN can also be an open access network (open RAN, O-RAN or ORAN), a cloud radio access network (cloud radio access network, CRAN), or a virtualized radio access network (virtualized RAN, vRAN), etc. RAN can also be a communication system that is a fusion of two or more of the above systems. RAN devices can also be referred to as RAN nodes, RAN entities, or access nodes, etc.

[0084] In one possible scenario, a RAN node can be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next-generation NodeB (gNB), a next-generation base station in a 6G mobile communication system, or a base station in a future mobile communication system. A RAN node can be a macro base station, a micro base station, an indoor station, a relay node, a donor node / host node, or a wireless controller. A RAN node can also be a server, a wearable device, a vehicle, or an onboard device. For example, a RAN node in V2X technology can be a roadside unit (RSU).

[0085] In another possible scenario, the RAN node may be a module or unit that performs part of the functions of the base station; or multiple RAN nodes collaborate to assist terminal devices in achieving wireless access, and different RAN nodes respectively perform part of the functions of the base station. For example, the RAN node may be a centralized unit (CU), a distributed unit (DU), or a radio unit (RU). The functions of the CU may be implemented by one entity, or by different entities. For example, the functions of the CU may be further divided, that is, the control plane and the user plane may be separated and implemented by different entities, namely the control plane CU entity (i.e., CU-control plane (CP) entity) and the user plane CU entity (i.e., CU-user plane (UP) entity). The CU-CP entity and the CU-UP entity may be coupled with the DU to jointly perform the functions of the RAN node. The CU and DU may be set separately, or may be included in the same network element, such as the baseband unit (BBU).

[0086] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the Open-RAN (ORAN) system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application takes CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0087] The CU and DU can be configured according to the protocol layer functions of the wireless network they implement: for example, the CU is configured to implement the functions of the packet data convergence protocol (PDCP) layer and the protocol layers above it (such as the radio resource control (RRC) layer and / or the service data adaptation protocol (SDAP) layer, etc.); the DU is configured to implement the functions of the protocol layers below the PDCP layer (such as the radio link control (RLC), MAC layer, and / or physical (PHY) layer, etc.). For another example, the CU is configured to implement the functions of the protocol layers above the PDCP layer (such as the RRC layer and / or the SDAP layer), and the DU is configured to implement the functions of the PDCP layer and the protocol layers below it (such as the RLC layer, the MAC layer, and / or the PHY layer, etc.). For a detailed description of each of the above protocol layers, please refer to the relevant technical specifications of 3GPP or the technical specifications of other applicable communication protocols. The above division of the processing functions of the CU and DU according to the protocol layer is only an example, and can also be divided in other ways, which is not limited by this application. For example, in one design, the CU or DU can also be divided into parts with partial processing functions of the protocol layer. In one design, part of the RLC layer functions and the functions of the protocol layers above the RLC layer are set in the CU, and the remaining functions of the RLC layer and the functions of the protocol layers below the RLC layer are set in the DU.

[0088] In the embodiments of the present application, the device for implementing the functions of the network device can be the network device itself, or a device that can support the network device to implement the functions, such as a chip system or a combination of devices or components that can implement the functions of the network device, and the device can be installed in the network device. The embodiments of the present application do not limit the specific technology and specific device form used by the network device.

[0089] In the embodiments of the present application, anything that can communicate data with a base station can be considered a terminal. A terminal is also referred to as a terminal device, terminal apparatus, user equipment (UE), mobile station, or mobile terminal. Terminals can be widely used in various scenarios, such as D2D communication, V2X communication, machine-type communication (MTC), IoT, virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grid, smart furniture, smart office, smart wearable, smart transportation, or smart city. For example, a terminal device can be: a mobile phone, a computer, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a station (STA) robotic arm, a camera, a robot, or a smart home device (such as a TV, air conditioner, vacuum cleaner, speaker, set-top box), a relay, a customer premise equipment (CPE), etc.

[0090] The various terminals introduced above, if located on a vehicle (for example, placed / installed in a vehicle), can all be considered as on-board terminals. The on-board terminal can be an on-board module, on-board module, on-board component, on-board chip or on-board unit built into the vehicle as one or more components or units, and the vehicle can implement the method of the present application through the built-in on-board module, on-board module, on-board component, on-board chip or on-board unit. The on-board terminal can be a complete vehicle device, an on-board module, a vehicle, an on-board unit (OBU), a roadside unit (RSU), a vehicle system (or a vehicle-mounted sending unit) (telematics box, T-box), a chip or a system on chip (SOC), etc. The above chip or SOC can be installed in a vehicle, OBU, RSU or T-box.

[0091] In the embodiments of the present application, the device for implementing the functions of the terminal can be the terminal device itself, or it can be a device that can support the terminal to implement the functions, such as a chip system or a combination of devices or components that can implement the terminal functions, which can be installed in the terminal. The embodiments of the present application do not limit the specific technology and specific device form used by the terminal. In the embodiments of the present application, the terminal and the terminal device are interchangeable.

[0092] Before introducing specific embodiments, some technical terms involved in this application are introduced in detail.

[0093] (1) Random access process

[0094] The random access process includes two-step random access and four-step random access. Let's first introduce four-step random access. Four-step random access involves four random access messages: Random Access Message 1 to Random Access Message 4. Random Access Message 1 is the random access preamble and can be simply referred to as Message 1 (Msg1). Random Access Message 2 is the response message to Random Access Message 1, also known as the random response message, and can be simply referred to as Message 2 (Msg2). Random Access Message 3 and Random Access Message 4 are used to resolve contention conflicts in the contention access mechanism. Random Access Message 3, also known as Msg3, can carry a random access cause value. Random Access Message 4, also known as a Contention Resolution Message / Content Resolution Message / Msg4, can carry the content carried by Random Access Message 3. Any terminal can send Msg1 and Msg3 to a network device. Accordingly, the network device responds to Msg1 with Msg2 and to Msg3 with Msg4. (2) Stealth pirating attack by RACH rebroadcast overwriting (SPARROW)

[0095] A SPARROW attack involves exploiting the MAC layer protocol to achieve covert communication by using another person's network for remote communication. In embodiments of the present application, covert communication includes, but is not limited to, data leakage, remote commands, and control activities. For example, a vulnerability in the MAC layer protocol may allow an unauthorized device (i.e., a malicious attack device) to leak unsecured information through the service provider's infrastructure. Continuing with the example of FIG. 1 , the unauthorized device may be terminal 120 a, the service provider's infrastructure may be network device 110 a, and terminal 120 a may leak unsecured information to terminal 120 e through network device 110 a.

[0096] It's understandable that the messages exchanged during random access are transmitted at the MAC layer. Because the terminal isn't in the RRC connected state, the network and terminal can't align keys. Therefore, much of the information exchanged during random access isn't protected, creating security vulnerabilities and making it easy for information to be leaked. A typical SPARROW attack exploits information leaks during the random access process.

[0097] For example, see Figure 2, which shows an example of a SPARROW attack. In Figure 2, both the first terminal and the second terminal are within the coverage of the network device. It can be understood that, taking the first terminal performing random access as an example, the process includes S201-S204.

[0098] S201: A first terminal sends a random access preamble (RA-preamble) to a network device. The random access preamble is Msg1. After sending Msg1, the first terminal starts a random access response time window (RA-ResponseWindow) to detect Msg2 from the network device within the RA-Response time window.

[0099] S202. The network device sends a response message of the random access preamble to the first terminal.

[0100] In response to Msg1, the network device sends Msg2 to the first terminal. Msg2 is the response message of the random access preamble. If the Msg2 carries the identifier (ID) of the RA-preamble, the first terminal considers that the RA response is successful and subsequently executes S203. If the first terminal does not receive the Msg2 corresponding to Msg1 in the random access response time window, the first terminal considers that the RA response has failed. The first terminal does not receive the Msg2 corresponding to Msg1; or, the first terminal receives Msg2, but the identifier of the RA-preamble in the Msg2 is not the identifier of Msg1. When the first terminal considers that the RA response has failed, it may initiate the random access process again until the number of times the random access process is initiated is equal to the maximum number of random access attempts.

[0101] S203. The first terminal sends a random access message 3 to the network device.

[0102] The first terminal receives Msg2 and may send a random access message 3, i.e., Msg3, to the network device. Msg3 may be an RRC Setup Request message transmitted during the RRC establishment process, including the RRC connection establishment cause and the identifier (ID) of the first terminal. The ID of the first terminal may be an S-temporary mobile subscriber identity (S-TMSI) or a random number. Msg3 may also be an RRC Resume Request message during the RRC recovery process, or an RRC Re-establishment Request message during the RRC re-establishment process. If Msg3 is an RRC Re-establishment Request, the ID of the first terminal included in Msg3 may be composed of the cell radio network temporary identifier (C-RNTI), the physical cell ID, and the short message authentication code for integrity (MAC-I) of the cell.

[0103] S204 : The network device broadcasts a response message to the random access message 3 .

[0104] After receiving Msg3, the network device may broadcast a response message to random access message 3, namely Msg4, which may include the content carried by Msg3. Msg4 may be carried on the physical downlink shared channel (PDSCH) scheduled by the physical downlink control channel (PDCCH).

[0105] The principle of resolving contention conflicts between Msg3 and Msg4 is as follows: after the first terminal sends Msg3, it can start a contention resolution timer and detect Msg4 from the network device within the timing duration of the timer. In one scenario, the C-RNTI MAC CE is included in Msg3. If UE1 can successfully parse the PDCCH of Msg4 based on the C-RNTI, then the random access is considered successful, and the first terminal stops the contention resolution timer. Otherwise, the contention resolution timer is not stopped. In another scenario, the common control channel (CCCH) service data unit (SDU) sent by UE1 in Msg3 includes a contention resolution identity. The CCCH SDU, for example, carries the content of the RRC Setup Request message. If the first terminal detects Msg4 carried by the PDSCH scheduled by the PDCCH, successfully parses the PDCCH of Msg4 using the TC-RNTI, and successfully parses the contention resolution identity MAC CE in Msg4, and the identity in the MAC CE is the same as the contention resolution identity carried by the Msg3 sent by the first terminal (i.e., the MAC PDU decoding is successful), then the first terminal considers that the random access is successful, stops the contention resolution timer, and sets the TC-RNTI to C-RNTI. If the contention resolution timer times out, the first terminal will discard the TC-RNTI and consider that the contention resolution has failed.

[0106] Because Msg4 broadcast by the network device contains the content carried by Msg3, and when the first terminal attempts to access the network device for the first time, the messages (Msg1 to Msg4) exchanged between the first terminal and the network device do not involve identity authentication or information integrity verification. Therefore, if the first terminal is a malicious attacker, it can tamper with the content carried by Msg3 and conduct covert communication by broadcasting Msg4 through the network device. For example, the first terminal can carry the content (such as information A) that it wants to disclose to the second terminal in Msg3 (Figure 2 is used as an example) and send it to the network device; the network device responds to Msg3 by broadcasting Msg4, which carries the content included in Msg3 (such as information A). The second terminal is within the coverage area of ​​the network device and can receive Msg4 from the network device to obtain information A. It can be understood that because Msg3 and Msg4 exchanged between the first terminal and the network device do not involve identity authentication, they can avoid legal interception and cannot track malicious attackers, resulting in low communication security.

[0107] The process shown in Figure 2 allows the first terminal to leak information to other devices covered by the network device by tampering with the content contained in Msg3 during the random access process before completing network identity authentication. As the network coverage expands, malicious attackers can leak information to a longer distance. For example, the first terminal will leak information to the second terminal covered by the network device through the network device, and the second terminal can continue to leak information to the third terminal through the network device. The third terminal and the second terminal are located in the coverage area of ​​the same network device. The network device and the network device covering the first terminal can be the same network device or different network devices.

[0108] The above Figure 2 takes 4-step random access as an example. In the 2-step random access process, 2 types of random access messages are involved, and these 2 random access messages are random access message 1 (also called random access message A, abbreviated as MsgA) to random access message 2 (also called random access message B, abbreviated as MsgB). It can be understood that the random access message 1 / random access message A in the 2-step random access process is equivalent to the random access message 1 and random access message 3 in the 4-step random access process; the random access message 2 / random access message B in the 2-step random access process is equivalent to the random access message 2 and random access message 4 in the 4-step random access process. For details, please refer to the introduction of the aforementioned 4-step random access process, which will not be repeated here. In the embodiment of the present application, MsgA can be replaced with Msg1 or Msg3, and correspondingly, MsgB can be replaced with Msg2 or Msg4. Alternatively, Msg1 may be replaced by MsgA, Msg2 may be replaced by MsgB; Msg3 may be replaced by MsgA, and Msg4 may be replaced by MsgB.

[0109] (3) Diffie-Hellman (DH) key negotiation

[0110] DH key negotiation is actually exchanging part of the content used to generate a shared key to create a shared key that can be used for encryption and / or security verification. The communicating parties encrypt and / or secure the information to be exchanged based on the shared key. Taking the communicating parties as device A and device B as an example, device A can generate a shared key based on the private key stored locally on device A and the public key from device B; device B can generate a shared key based on the private key stored locally on device B and the public key from device A. Device A encrypts or secures the information sent to device B based on the generated shared key. Correspondingly, device B decrypts or secures the information received from device A based on the generated shared key.

[0111] The DH key negotiation is actually for the two communicating parties to exchange their respective public keys. Please refer to FIG. 3, which is a schematic diagram of the DH key negotiation and the generation of the shared key provided by an embodiment of the present application. FIG. 3 takes the negotiation of the DH key between device A and device B as an example.

[0112] As shown in FIG. 3, before device A and device B negotiate the DH key, they need to exchange some public parameters for determining the public keys exchanged between device A and device B. These public parameters are public and can be obtained by any device. For example, when device A is connected to device B, it can send the public parameters p and g to device B. Among them, p is a prime number, and g is a generator for generating p. Device A can generate a random number Xa as the private key of device A, and then determine the public key Ya of device A according to Xa, g, and p. Among them, Ya = (g Xa ) mod p, "mod" is for modulo operation, and Xa < p. Device A sends Ya to device B. Device B receives Ya and calculates the shared key K according to Ya and the private key Xb of device B, K = (Ya Xb ) mod p, Xb < p. Similarly, device B generates a random number Xb as the private key of device B, and then determines the public key Yb of device B according to Xb, g, and p. Among them, Yb = (g Xb ) mod p, "mod" is for modulo operation. Device B sends Yb to device A. Device A receives the public key Yb of device B and calculates the shared key K according to Yb and the private key Xa of device A, K = (Yb Xa ) mod p. Among them, the K generated by device A and the K generated by device B are a pair of DH keys, and they are the same, that is, the shared key K = g XaXb (mod p).

[0113] Xa is saved locally by device A, and Xb is stored locally by device B. Device A sends Ya to device B, and device B sends Yb to device A. Since the shared key K of device A needs to be generated according to Xa, and the shared key K of device B needs to be generated according to Xb, even if Ya or Yb is obtained by a malicious attacker during the transmission process, the malicious attacker cannot generate the shared key K, which helps to reduce the leakage of information.

[0114] (4) Digital certificate

[0115] A digital certificate, also known as a digital ID, includes the certificate's issuing authority, validity period, public key owner information, the public key, and a signature generated by a certificate authority (CA) server using its local private key. Because the CA server is an authoritative and impartial third-party organization, using this digital certificate in a communication system allows the device to establish a secure transmission channel and authenticate its identity based on the certificate issued by the CA server.

[0116] Taking device A as an example, device A can submit a certificate application to a CA, including its public key, information about device A (i.e., the public key holder), and domain name. Upon receiving the application, the CA verifies the legitimacy of device A. If there are no anomalies, the CA uses a hash algorithm to perform a hash operation on the plaintext information (e.g., the certificate issuing authority, validity period, the public key sent by device A, and device A's information) to generate a digest. The CA then encrypts this digest with its local private key to generate a digital signature. The combination of this digital signature and the plaintext information constitutes a digital certificate. The CA then issues the digital certificate to device A.

[0117] When device A and device B communicate, device A can send its digital certificate to device B. After receiving the digital certificate from device A, device B can use the CA's public key to verify the signature of the digital certificate. If the verification is successful, it means that device B's identity is legitimate and it can use the public key of device B contained in the digital certificate. It should be noted that the CA's public key needs to be distributed using a certificate. Therefore, device A must install the CA's certificate to obtain the CA's public key. Suppose that device C tampered with device B's digital certificate midway. Then, when device A uses the CA's private key to verify the signature of the digital certificate, the verification fails. Since the signature of the digital certificate depends on the CA's private key, device C cannot obtain the CA's private key. After modifying device B's digital certificate, it cannot calculate the digital signature corresponding to the digital certificate. It can be seen that identity authentication can be achieved based on digital certificates.

[0118] (5) Integrity protection refers to the sending end combining regularly changing parameters with the information to be transmitted to obtain a message authentication code for integrity (MAC-I). Correspondingly, the receiving end can use the same parameters and the same rules to calculate the expected MAC-I (XMAC-I). By verifying the MAC-I and XMAC-I, it can determine whether the received data is complete, thereby achieving the purpose of protecting data integrity. If the MAC-I and XMAC-I are consistent, the receiving end can confirm that the information from the sender has not been tampered with.

[0119] It should be noted that the present application can encrypt and / or perform integrity verification on one or more messages exchanged during the random access process based on DH key negotiation. To facilitate understanding of the solutions mentioned in the embodiments of the present application, the technical terms involved in the embodiments of the present application are first introduced. In the embodiments of the present application, "integrity verification" can also be referred to as integrity verification / integrity protection, abbreviated as integrity verification / integrity check / integrity. In the embodiments of the present application, "encryption" and "integrity verification" can be independent algorithms. Alternatively, "encryption" also includes "integrity verification". That is to say, "encryption" includes both encryption and integrity verification.

[0120] The above analysis demonstrates that malicious attack devices can leak information through network devices during the random access process. In light of this, the solution provided by the embodiments of this application is proposed. In this embodiment, one or more messages exchanged during the random access process are encrypted and / or integrity verified to improve communication security.

[0121] The technical solutions provided by the embodiments of the present application are described below with reference to the accompanying drawings.

[0122] In various embodiments of this application, the phrases "when," "if," and "if" all imply that the device will perform a corresponding action under certain objective circumstances. These phrases do not limit the timeframe, do not require the device to perform a judgment action, and do not imply any other limitations. Unless otherwise specified, "if" and "if" are interchangeable, and "when" and "under the circumstances" are interchangeable. "When" and "if" are interchangeable.

[0123] In the embodiments of the present application, the number of nouns, unless otherwise specified, means "singular noun or plural noun", that is, "one or more". "At least one" means one or more, and "plural" means two or more. "And / or" describes the association relationship of associated objects, indicating that there may be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. For example, A / B means: A or B. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c means: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, c can be single or multiple.

[0124] The ordinal numbers such as "first" and "second" mentioned in the embodiments of this application are used to distinguish between multiple objects, and are not used to limit the size, content, order, timing, priority or importance of multiple objects. For example, the first group of terminals and the second group of terminals refer to two different terminal groups, and do not indicate the difference in content, priority or importance of the two terminal groups. For a technical feature, "A", "B", "C" and "D" are used to distinguish the technical features in the technical feature, and there is no order of precedence or order of size between the technical features described by "A", "B", "C" and "D". For example, the method A and method B in this article are only to distinguish different conjugate processing methods, and do not limit the order of precedence or order of size, priority or importance, etc. between method A and method B.

[0125] The following describes the communication method provided in the embodiment of the present application by taking the communication method performed by a network device and a terminal as an example. The steps performed by the network device can be implemented by the RAN device itself, or by components in the RAN device (such as a baseband chip, or other processing units or processor modules). For example, the network device can be the network device in Figure 1, such as the network device 110a, or it can also be a chip (system) in the network device in Figure 1. The steps performed by the terminal can be implemented by the terminal itself, or by components in the first terminal (such as a chip, a processing unit, or a processor module). The terminal can be the terminal shown in Figure 1, such as the terminal 120a, or it can also be a chip (system) in the terminal in Figure 1.

[0126] The communication method provided by the embodiment of the present application is to combine the DH key negotiation process with the random access process to realize encryption and / or complete protection of one or more information exchanged during the random access process, thereby effectively ensuring the security of communication. In the embodiment of the present application, the first public key is the public key of the network device, denoted by Y NB , the first private key is the private key of the terminal, denoted as X UE ; The second public key is the public key of the terminal, denoted as Y UE , the second private key is the private key of the network device, denoted as X NB , the shared key is denoted as K. In the embodiment of the present application, obtaining the shared key, obtaining the shared key, generating the shared key, and determining the shared key are interchangeable. For example, obtaining the shared key based on the first private key and the first public key can be replaced by obtaining / generating / determining the shared key based on the first private key and the first public key.

[0127] Please refer to Figure 4, which is a schematic flow diagram of a communication method 400 provided in an embodiment of the present application. Figure 4 describes the method from the perspective of interaction between a network device and a terminal. It should be understood that communication method 400 can also be implemented by other devices, such as a chip or communication device with communication capabilities. As shown in Figure 4, the process of communication method 400 includes the following steps.

[0128] S401. A network device sends first information to a terminal, where the first information indicates a first public key and at least one encryption algorithm.

[0129] Accordingly, the terminal receives the first information from the network device. The first information can be used to inform the terminal of the public key of the network device and the encryption algorithm supported by the network device. For example, the first information indicates the first public key Y NB and at least one encryption algorithm. For example, the first information includes a first public key Y NB and an encryption algorithm list, where the encryption algorithm list can be used to indicate at least one encryption algorithm supported by the network device.

[0130] The network device sends the first public key Y through the first information NB Sent to the terminal for the terminal to use according to the first public key Y NB and the terminal's private key (ie X UE ) obtains a shared key K, thereby using the shared key K to encrypt and / or secure the information to be sent, or using the shared key K to decrypt and / or securely verify the received information, thereby effectively preventing information from being leaked during the communication process. The network device notifies the terminal of the encryption algorithm supported by the network device through the first information, thereby avoiding a mismatch between the encryption algorithm selected by the terminal and the encryption algorithm supported by the network device, resulting in a failure of normal communication.

[0131] Optionally, the network device may also send a digital certificate issued by a certificate authority for the network device to the terminal. Accordingly, the terminal may determine the legitimacy of the network device by performing signature verification on the digital certificate. For details, please refer to the relevant content of the aforementioned digital certificate, which will not be repeated here. If the terminal determines that the network device is not legal, then the terminal may not receive the first information. The terminal not receiving the first information includes the terminal receiving the first information and discarding the first information; or the terminal refusing to receive the first information. If the network device is issued a digital certificate, the network device may also send some content included in the digital certificate to the terminal. For example, the first information may also include one or more of the following contents: the issuing authority of the digital certificate, the validity period of the digital certificate, the identity information of the network device, etc.

[0132] The first information may be carried in a system message, which may be system information block 1 (SIB1). In this case, the network device sending the first information may be replaced by the network device broadcasting the first information. It should be noted that the embodiments of the present application do not limit the signaling that carries the first information. For example, the first information may also be carried in RRC signaling.

[0133] As shown in Figure 2 above, since Msg1 to Msg4 do not involve identity authentication or information integrity verification, the terminal can tamper with the content carried by Msg3 and conduct covert communication by broadcasting Msg4 through the network device. To this end, in an embodiment of the present application, the network device uses the first information to enable the terminal to generate a shared key. During subsequent interactions, the terminal can encrypt and / or secure the information to be sent based on the generated shared key to improve communication security.

[0134] S402. The terminal sends a first message to the network device. The first message indicates a first encryption algorithm and a second public key, and the first message also includes a random access preamble or a random access cause value.

[0135] Accordingly, the network device receives the first message from the terminal. The terminal can use the first message to send the terminal's public key (ie, Y UE ) and the encryption algorithm used by the terminal are notified to the network device. For example, the first message indicates the second public key Y UE Assuming that the first encryption algorithm is the encryption algorithm used by the terminal, the first message may include the second public key Y UE It is understandable that the first encryption algorithm is an encryption algorithm supported by the network device, and the terminal can select the first encryption algorithm from the encryption algorithm list after receiving the first information.

[0136] In one implementation, the identifier of the first encryption algorithm and the second public key may be sent along with the random access preamble, i.e., the first message may also include the random access preamble. For example, in a two-step random access process, the first message may be Msg1 / MsgA, i.e., the random access preamble, the identifier of the first encryption algorithm, and the second public key are included in Msg1 / MsgA. For another example, in a four-step random access process, when the terminal sends the first message, it is actually the terminal sending Msg1, and the identifier of the first encryption algorithm and the second public key are also sent along with Msg1.

[0137] In another implementation, the identifier of the first encryption algorithm and the second public key can be sent along with Msg3. Alternatively, the identifier and public key of the first encryption algorithm can be carried in Msg3. In this case, the first message can be Msg3, and the first message includes the identifier of the first encryption algorithm and the second public key. It is understood that Msg3 also carries the random access cause value, that is, the first message can also include the random access cause value.

[0138] In the above two implementations, when the terminal attempts to access the network device for the first time, it will send the second public key Y UE Notify the network device. In this way, the network device uses the second public key Y UE A shared key K may be generated, based on which messages sent to the terminal during the random access process may be encrypted and / or secured, thereby improving communication security.

[0139] S403: The network device sends a second message.

[0140] The network device receives the first message and, in response to the first message, may send a second message to the terminal. Accordingly, the terminal receives the second message from the network device. It is understood that the second message is a response message to the first message. Depending on the implementation of the first message, the second message may also vary. The second message is a corresponding message to the first message, and can be alternatively described as follows: when the first message includes a random access preamble, the second message is Msg2; or, when the first message is Msg3, the second message is Msg4; or, when the first message is MsgA, the second message is MsgB.

[0141] The network device receives the first message and can obtain the second public key Y from the first message UE , according to the second public key Y UE and the private key of the network device (the second private key X in this article) NB ) Generate a shared key. When the network device sends the second message, it can encrypt the second message according to the shared key K to prevent the content carried by the second message from being leaked.

[0142] S404: The terminal may decrypt the second message according to the first encryption algorithm and the generated shared key.

[0143] The terminal can obtain the first public key Y from the first information NB , according to the first public key Y NB and the first private key X UE The shared key K is obtained, and the second message is decrypted using the shared key K to obtain the content carried by the second message.

[0144] In the communication method 400, the terminal and the network device can generate a shared key K by exchanging their respective public keys during the random access process. In this way, the network device can subsequently encrypt the second message sent to the terminal based on the shared key K to prevent the content carried by the second message from being leaked. For example, when the first message is Msg3 and the second message is Msg4, the network device broadcasts the second message. Although other terminals can receive the second message, since the shared key K used to encrypt the second message is generated by a private key and a public key, and the private keys corresponding to each terminal are kept by each terminal itself, the other terminals do not know each other's private keys. Therefore, other terminals cannot obtain the shared key and cannot decrypt the second message, which can prevent the content carried by Msg4 from being leaked.

[0145] It is understandable that if the first message includes a random access preamble, that is, the first message is Msg1 in the random intervention process, the network device can also encrypt Msg2 sent to the terminal based on the shared key K. The embodiment of the present application does not limit whether the network device encrypts and / or secures Msg2. For example, the first message includes a random access preamble, an identifier of the first encryption algorithm, and a second public key. After receiving the first message, the network device sends Msg2 to the terminal. The Msg2 can be encrypted based on the shared key K generated by the network device, or it can not be encrypted based on the shared key K generated by the network device.

[0146] Similarly, the terminal generates a shared key K and can also encrypt and / or secure messages sent to the network device based on the shared key K. For example, the first message includes a random access preamble, an identifier of the first encryption algorithm, and a second public key Y. UE After receiving the second message, the terminal may further execute S405.

[0147] S405: The terminal sends a third message to the network device.

[0148] Accordingly, the network device receives a third message from the terminal, which may be Msg3. When the first message includes a random access preamble and the second message is Msg2, the terminal may further send Msg3 to the network device after receiving the second message.

[0149] The terminal may encrypt and / or secure the third message based on the generated shared key K. Alternatively, the terminal may not encrypt the third message.

[0150] It should be noted that whether the network device encrypts and / or secures the second message is independent of whether the terminal encrypts and / or secures the third message. For example, when the first message includes a random access preamble, the network device may encrypt and / or secure the second message to be sent based on the generated shared key K. When the network device encrypts and / or secures the second message based on the generated shared key K, the terminal receives the second message and executes S404. Thereafter, the terminal may encrypt and / or secure the third message to be sent based on the generated shared key K, or may not encrypt and / or secure the third message. When the network device does not encrypt and / or secure the second message, the terminal receives the second message and does not execute S404. Therefore, S404 is not a required step and is illustrated by a dotted line in Figure 4. Thereafter, the terminal may encrypt and / or secure the third message to be sent based on the generated shared key K, or may not encrypt and / or secure the third message.

[0151] In addition, after the terminal and the network device exchange their respective public keys with each other, the two determine whether to encrypt and / or secure the messages to be sent. For example, the network device receives the third message and broadcasts Msg4. Msg4 can be encrypted based on the shared key and can also be secured. After the terminal receives Msg4, it can send Msg5 to the network device. The Msg5 can be encrypted and / or secured based on the shared key. Msg5, for example, is an RRC setup complete message, an RRC resume complete message, or an RRC re-establishment complete message. After Msg5, the terminal and the network device can exchange downlink information transfer (DL Information Transfer) messages, uplink information transfer (UL Information Transfer) messages, etc.

[0152] As mentioned above, since the terminals do not know each other's private keys, the communication method 400 can reduce the leakage of information from the terminal (for example, terminal A) to other devices (for example, terminal B) through Msg3 and Msg4 sent by the network device, or reduce SPARROW attacks. This is because the shared key used to encrypt Msg3 / Msg4 is generated based on the private key of the device sending Msg3 / Msg4 and the public key of the device receiving Msg3 / Msg4. The private key of each device is maintained by itself, and each device does not know each other's private keys. Naturally, the devices cannot generate a shared key K for each other to use, thereby achieving the purpose of information protection. In a possible scenario, a terminal may leak its private key to other terminals. Continuing with the above example, terminal A may leak its private key to terminal B. In this case, terminal B can also generate a shared key K based on the private key of terminal A and the public key of the network device (i.e., the first public key). In this case, if terminal A tampers with the content of Msg3 (for example, Msg3 includes information that terminal A wants to disclose), even if the network device encrypts the broadcast Msg4, terminal B can still obtain the information disclosed by terminal A. This is because terminal B can generate the shared key used by terminal A and obtain the information disclosed by terminal A by decrypting the received Msg4.

[0153] In order to further improve the security of communication, in an embodiment of the present application, the shared key used by the terminal and the network device can also be used to deduce the shared key based on the information that the terminal and the network device only know each other, combined with their own private key and the other party's public key. For the convenience of description, the embodiment of the present application refers to the information that the terminal and the network device only know each other as the first parameter, or in other words, the first parameter in the embodiment of the present application is a terminal-specific (UE specific) parameter, or the first parameter can be a parameter associated with a specific terminal (UE associated). For example, the first parameter may include one or more of the following: TC-RNTI, synchronization signal and physical broadcast channel (PBCH) block (SSB) index (referred to as synchronization signal index), or random access resource index. The random access resource index can replace the random access preamble index. Then, the shared key K used by the terminal can be obtained / generated based on the private key of the terminal and the public key of the network device and the first parameter; the shared key K used by the network device can be obtained / generated based on the public key of the terminal and the private key of the network device and the first parameter.

[0154] For example, see Figure 5, which is a schematic diagram of the shared key derivation process. As shown in Figure 5, the terminal uses the first public key Y eNB and the first private key X UEGenerate an initial shared key, and then deduce the final shared key K based on the first parameter and the initial shared key. The network device uses the second public key Y UE and the first private key X NB Generate an initial shared key, and then deduce the final shared key K based on the first parameter and the initial shared key. The terminal and the network device use the shared key K for encryption or security. In other words, the first parameter and the initial shared key are input parameters for generating the key stream. When generating the key stream, the terminal uses the first parameter and the initial shared key. Correspondingly, when generating the key stream, the terminal also uses the first parameter and the initial shared key. In other words, the first parameter and the initial shared key are input parameters for generating the security information MAC-I. When generating the security information MAC-I, the terminal uses the first parameter and the initial shared key. Correspondingly, when verifying the security information XMAC-I, the terminal also uses the first parameter and the initial shared key.

[0155] It is understandable that for terminal A, the information about TC-RNTI, SSB index, and random access preamble index is information known only to terminal A and the network device. Terminal B cannot know the TC-RNTI, SSB index, and random access preamble index of terminal A. In this case, even if terminal B knows the private key of terminal A in advance, it cannot obtain the shared key K that terminal A actually wants to use. The embodiment of the present application further improves the security of communication by combining the information known only to each other between the terminal and the network device with their respective private keys and the other party's public key to obtain the shared key K.

[0156] In one implementation, in the method provided in the present application, the first message may also be protected so that the network device can determine whether there is a terminal that maliciously initiates random access.

[0157] Securing the integrity of the first message can be understood as performing a calculation on certain contents included in the first message, with the resulting calculation result being used to verify the integrity of the first message. This calculation result can be sent along with the first message, or it can be carried within the first message. For ease of description, this embodiment of the present application refers to this calculation result as a message authentication code. It should be noted that this embodiment of the present application does not impose any restrictions on the specific name of this calculation result; for example, it can also be referred to as a MAC-I.

[0158] When the first message includes a random access preamble, the first message also includes a message verification code, which is a code that encrypts the random access preamble, the identifier of the first encryption algorithm, and the second public key Y using the first encryption algorithm and the shared key K. UE Alternatively, the terminal uses the first encryption algorithm and the shared key K to encrypt the random access preamble, the first encryption algorithm identifier and the second public key Y UE Encrypt to obtain a message verification code.

[0159] When the first message includes a random access cause value or the first message is Msg3, the first message also includes a message verification code, which uses the first encryption algorithm and the shared key K to perform the random access cause, the first encryption algorithm and the second public key Y. UE Alternatively, the terminal uses the first encryption algorithm and the shared key K to encrypt the random access reason, the first encryption algorithm and the second public key Y UE It should be noted that the random access reason, the first encryption algorithm and the second public key Y contained in the first message are used here. UE For example, if the first message also includes other content, the message authentication code can be obtained by using the first encryption algorithm and the shared key K to perform random access, the first encryption algorithm's label and the second public key Y. UE and the other contents are encrypted.

[0160] For the network device, receiving the first message, obtaining the identifier of the first encryption algorithm and the second public key Y in the first message UE The network device uses the second public key Y UE and the second private key X eNB Obtain the shared key K, or according to the second public key Y UE and the second private key X NB The network device may perform integrity verification on the message authentication code in the first message based on the identifier of the first algorithm and the shared key K, and obtain a verification result. If the verification result is consistent with the content of the first message excluding the message authentication code, it can be determined that the content of the first message has not been tampered with and the terminal did not maliciously initiate random access.

[0161] It is understandable that different terminals use different shared keys. If there are many first messages sent using the same shared key, and the message verification code in the first message is encrypted using the same shared key, then it indicates that there is a terminal that maliciously initiates random access. Therefore, the embodiment of the present application allows the network device to determine whether the terminal maliciously initiates random access by fully protecting the first message. If the network device determines that the terminal maliciously initiates random access, the network device does not respond to the first message to improve communication security. If the terminal does not maliciously initiate random access and does not receive a response from the network device, it can replace the shared key and use the replaced shared key to resend the first message.

[0162] It should be noted that, in one implementation, the first message may not be fully secured, that is, the first message does not include a message verification code, which can reduce the load of the first message and reduce the impact on uplink coverage.

[0163] In one implementation, the first message may be scrambled to increase the decoding complexity of the first message by the other end, thereby further improving communication security. The terminal may scramble the first message using information known to both the terminal and the network device. For example, the terminal may scramble the first message using a random access preamble index and / or an SSB index. Scrambling the first message using a random access preamble index and / or an SSB index includes scrambling the first message using a sequence generated by the random access preamble index and / or the SSB index. In other words, the first message is scrambled using a sequence generated by the random access preamble index and / or the SSB index. This makes it impossible for other terminals to parse the first message, thereby achieving the purpose of protecting the content carried by the first message.

[0164] The embodiment of the present application reduces SPARROW attacks by performing DH key negotiation during random access. The embodiment of the present application does not limit the timing of DH key negotiation. For example, the terminal can use the second public key Y UE With the notification of Msg1 to the network device; for example, the terminal can send the second public key Y through Msg3 UE Notify the network device. For the network device, whether the message sent to the terminal is encrypted based on the shared key K can be decided by the network device itself. For the terminal, after obtaining the shared key K, whether the information sent to the network device is encrypted based on the shared key K is also decided by the terminal itself. For ease of understanding, the following two examples (i.e., the first example and the second example) are used as examples to introduce the method provided in the embodiment of the present application. In the first example, the terminal sends the second public key Y UE In the second example, the terminal sends the second public key Y to the network device through Msg3. UE Take the notification to the network device as an example.

[0165] First example:

[0166] Please refer to Figure 6, which is a flow chart of a communication method 600 provided in an embodiment of the present application. The communication method 600 includes the following steps:

[0167] S601: A network device sends first information to a terminal, where the first information indicates a first public key and at least one encryption algorithm.

[0168] The specific implementation of S601 can refer to the relevant content of S401 above, which will not be repeated here. Optionally, the network device can also send a digital certificate issued by a certificate authority to the terminal. Accordingly, the terminal can verify the signature of the digital certificate to determine the legitimacy of the network device.

[0169] S602: The terminal sends a first message to the network device. The first message indicates a first encryption algorithm and a second public key, and the first message also includes a random access preamble.

[0170] In S602, the first message includes a random access preamble. The terminal sends the second public key Y UE As Msg1 is sent to the network device, please refer to the relevant content of S402 above for details, which will not be repeated here. Optionally, the terminal can complete the protection of the first message.

[0171] S603: The network device sends a second message.

[0172] The second message is a response message to the first message. For example, the first message is Msg1 and the second message is Msg2. Optionally, the network device may encrypt and / or secure the second message based on the shared key K to improve communication security (Figure 6 takes this as an example). Alternatively, the network device may not encrypt and / or secure the second message. For details, please refer to the relevant content of S403 above, which will not be repeated here. It is understandable that if the network device encrypts the second message, the terminal decrypts the second message accordingly.

[0173] S604: The terminal sends a third message to the network device, where the third message includes a random access cause value.

[0174] The third message is Msg3. The terminal encrypts the third message based on the first encryption algorithm and the shared key K to include the content carried by the third message. The specific implementation of the terminal encrypting the third message can refer to the relevant content of the aforementioned S405.

[0175] S605: The network device broadcasts a fourth message, where the fourth message is a response message to the third message.

[0176] The fourth message is Msg4. After receiving the third message, the network device may broadcast a fourth message in response to the third message. The fourth message may carry the content included in the third message. The network device may encrypt the fourth message based on the first encryption algorithm and the shared key K. In this case, even if the fourth message is received by other terminals, since the other terminals cannot obtain the shared key K, they cannot obtain the content carried by the fourth message. This reduces the leakage of the content carried by the third message due to the network device broadcasting the fourth message, thereby improving communication security.

[0177] Second example:

[0178] Please refer to Figure 7, which is a flow chart of a communication method 700 provided in an embodiment of the present application. The difference between communication method 700 and communication method 600 is that the terminal sends the second public key and the first encryption algorithm to the network device via Msg3. For any repetitions, please refer to the relevant content of the aforementioned communication method 600 and will not be repeated here. Communication method 700 includes the following steps:

[0179] S701. A network device sends first information to a terminal, where the first information indicates a first public key and at least one encryption algorithm.

[0180] S702: The terminal sends a random access preamble to the network device.

[0181] S703: The network device sends a second message.

[0182] S704: The terminal sends a third message to the network device. The third message includes a random access reason value, an identifier of the first encryption algorithm, and a second public key.

[0183] The third message is Msg3. The difference from S604 is that the terminal sends the second public key and the first encryption algorithm to the network device through Msg3. For specific implementation, please refer to the relevant content of the aforementioned S402.

[0184] S705. The network device broadcasts a fourth message, where the fourth message is a response message to the third message.

[0185] The fourth message is Msg4. After receiving the third message, the network device may broadcast a fourth message in response to the third message. The fourth message may carry the content included in the third message. The network device may encrypt the fourth message based on the first encryption algorithm and the shared key K. In this case, even if the fourth message is received by other terminals, since the other terminals cannot obtain the shared key K, they cannot obtain the content carried by the fourth message. This reduces the leakage of the content carried by the third message due to the network device broadcasting the fourth message, thereby improving communication security.

[0186] The embodiments provided in the present application described above respectively introduce the methods provided in the embodiments of the present application from the perspective of the interaction between the terminal and the network device. Among them, the steps executed by the terminal can be implemented by different functional entities that constitute the terminal. The steps executed by the network device can be implemented by different functional entities that constitute the network device. For example, the network device can be a CU-DU architecture, the CU can generate a second message, and the DU can send a second message. In order to implement the various functions in the methods provided in the embodiments of the present application described above, the terminal and the network device may include a hardware structure and / or a software module to implement the above functions in the form of a hardware structure, a software module, or a hardware structure plus a software module. Whether one of the above functions is executed in the form of a hardware structure, a software module, or a hardware structure plus a software module depends on the specific application and design constraints of the technical solution.

[0187] The following describes the communication device used to implement the above method in the embodiment of the present application with reference to the accompanying drawings. Therefore, the above contents can be used in subsequent embodiments, and repeated contents will not be repeated.

[0188] Figure 8 is a schematic block diagram of a communication device 800 provided in an embodiment of the present application. The communication device 800 may be a network device or terminal in the aforementioned embodiments. For example, the communication device 800 may be the network device or terminal in Figure 1; alternatively, the communication device 800 may be a chip (system) in a network device or a chip (system) in a terminal; or alternatively, the communication device 800 may be a software module in a network device or terminal. The communication device 800 may implement the functions or steps implemented by the terminal or network device in the aforementioned method embodiments. The communication device 800 may include a processing module 810 and a transceiver module 820. Optionally, it may also include a storage module, which may be used to store instructions (code or program) and / or data. The storage module may be, for example, a memory. The processing module 810 and the transceiver module 820 may be coupled to the storage module. For example, the processing module 810 may read instructions (code or program) and / or data in the storage module to implement the corresponding method. When the communication device 800 is a chip in a terminal, the storage module may be a storage module within the chip, such as a register or cache. For example, the storage module may also be a storage module located outside the chip within the network device / terminal, such as a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM), etc. The above-mentioned units may be independently provided or partially or fully integrated.

[0189] In one possible implementation, the processing module 810 may be a processor or controller, such as a general-purpose central processing unit (CPU), a general-purpose processor, a digital signal processing (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. The processor may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like. The transceiver module 820 is a transceiver, an interface circuit, a bus, a pin, or other possible communication interface for receiving signals from other devices. For example, when the device is implemented in the form of a chip, the transceiver module 820 is an interface circuit for the chip to receive signals from other chips or devices, or an interface circuit for the chip to send signals to other chips or devices.

[0190] For example, the communication device 800 can implement the behaviors and functions of the terminal in the above-mentioned method embodiments. The communication device 800 can be a terminal, or a component (such as a chip or circuit) used in a terminal, or a chip or chipset in the terminal, or a part of the chip used to perform the functions of the relevant method, or a software module capable of implementing the method executed by the terminal in the above-mentioned method (such as communication method 400, communication method 600, or communication method 700), without limitation.

[0191] For example, the communication device 800 may implement the method executed by the terminal in the embodiment of Figure 4, Figure 6, or Figure 7. For example, the transceiver module 820 may be used to execute S401, S402, S403, and S405 in the embodiment shown in Figure 4, and / or other processes for supporting the technology described herein; the processing module 810 may be used to execute S404 in the embodiment shown in Figure 4, and / or other processes for executing the technology described herein.

[0192] In one implementation, the transceiver module 820 is configured to receive a first message, send a first message, and receive a second message. The first message indicates a first public key and a list of at least one encryption algorithm, the first public key being the public key of the network device, and the at least one encryption algorithm being an encryption algorithm supported by the network device. The first message indicates a first encryption algorithm and a second public key, the second public key being the public key of the communication device 800, the first encryption algorithm belonging to at least one encryption algorithm, and the first message also including a random access preamble or a random access reason value. The processing module 810 is configured to decrypt the second message based on the first encryption algorithm and a shared key, the shared key being obtained based on the first public key and the first private key, the first private key being the private key of the communication device 800.

[0193] As an optional implementation method, the shared key is obtained based on the first public key and the first private key, including: the shared key is obtained based on the first public key, the first private key and the first parameter, wherein the first parameter includes one or more of the following: TC-RNTI, synchronization signal index, or random access resource index.

[0194] As an optional implementation manner, the first message is scrambled by a sequence generated by a preamble code sequence index and / or a synchronization signal index.

[0195] As an optional implementation method, the first message also includes a message verification code. When the first message includes a random access preamble, the message verification code is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and the shared key.

[0196] As an optional implementation method, the first message also includes a message verification code. When the first message includes a random access reason value, the message verification code is obtained by encrypting the random access reason value, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and the shared key.

[0197] As an optional implementation, before receiving the first information, the transceiver module 820 is further configured to receive certificate information including a public key provided by the institution that issued the certificate. The processing module 810 is further configured to perform signature verification on the certificate information based on the public key provided by the institution that issued the certificate.

[0198] In another implementation, the transceiver module 820 is used to receive the first information, send the first message, receive the second message, and send the third message. The first information indicates a first public key and at least one encryption algorithm, the first public key is the public key of the network device, and the at least one encryption algorithm is an encryption algorithm supported by the network device. The first message indicates a first encryption algorithm and a second public key, the second public key is the public key of the communication device 800, the first encryption algorithm belongs to at least one encryption algorithm supported by the network device, and the first message also includes a random access preamble or a random access reason value. The processing module 810 is also used to encrypt the third message according to the first encryption algorithm and the shared key. The shared key is obtained based on the first public key and the first private key, and the first private key is the private key of the communication device 800.

[0199] As an optional implementation, the processing module 810 is further configured to decrypt the second message according to the first encryption algorithm and the shared key.

[0200] As an optional implementation method, the shared key is obtained based on the first public key and the first private key, including: the shared key is obtained based on the first public key, the first private key and the first parameter, wherein the first parameter includes one or more of the following: TC-RNTI, synchronization signal index, or random access resource index.

[0201] As an optional implementation manner, the first message is scrambled by a sequence generated by a preamble code sequence index and / or a synchronization signal index.

[0202] As an optional implementation method, the first message also includes a message verification code. When the first message includes a random access preamble, the message verification code is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and the shared key.

[0203] As an optional implementation, before receiving the first information, the transceiver module 820 is further configured to receive certificate information including a public key provided by the institution that issued the certificate. The processing module 810 is further configured to perform signature verification on the certificate information based on the public key provided by the institution that issued the certificate.

[0204] In another implementation, the transceiver module 820 is used to receive the first information, send the first message, and receive the second message. The first information indicates a first public key and at least one encryption algorithm, the first public key is the public key of the network device, and the at least one encryption algorithm is an encryption algorithm supported by the network device. The first message indicates the first encryption algorithm and the second public key, the second public key is the public key of the communication device 800, the first encryption algorithm belongs to at least one encryption algorithm supported by the network device, and the first message also includes a random access preamble or a random access reason value. The first message is scrambled by a sequence generated by a preamble sequence index and / or a synchronization signal index. The processing module 810 is also used to decrypt the second message according to the first encryption algorithm and a shared key. The shared key is obtained based on the first public key and the first private key, and the first private key is the private key of the communication device 800.

[0205] For another example, the communication device 800 can implement the behaviors and functions of the network device in the above-mentioned method embodiments. The communication device 800 can be a network device, or a component (such as a chip or circuit) used in a network device, or a chip or chipset in the network device, or a part of the chip used to perform the functions of the relevant method, or a software module capable of implementing the method performed by the network device in the above-mentioned method (such as communication method 400, communication method 600, or communication method 700), without limitation.

[0206] In one implementation, the transceiver module 820 is configured to send a first message, receive a first message, and send a second message. The first message indicates a first public key and a list of at least one encryption algorithm, where the at least one encryption algorithm is an encryption algorithm supported by the communication device 800. The first message indicates a first encryption algorithm and a second public key, where the second public key is the public key of the terminal, and the first encryption algorithm is one of at least one encryption algorithm supported by the communication device 800. The processing module 810 is configured to encrypt the second message based on the first encryption algorithm and a shared key. The second message is a response message to the first message, where the shared key is obtained based on the second public key and the second private key, where the second private key is the private key of the communication device 800.

[0207] As an optional implementation method, the shared key is obtained based on the first public key and the first private key, including: the shared key is obtained based on the first public key, the first private key and the first parameter, wherein the first parameter includes one or more of the following: TC-RNTI, synchronization signal index, or random access resource index.

[0208] As an optional implementation manner, the first message is scrambled by a sequence generated by a preamble code sequence index and / or a synchronization signal index.

[0209] As an optional implementation method, the first message also includes a message verification code. When the first message includes a random access preamble, the message verification code is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and the shared key.

[0210] As an optional implementation method, the first message also includes a message verification code. When the first message includes a random access reason value, the message verification code is obtained by encrypting the random access reason value, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and the shared key.

[0211] As an optional implementation, before receiving the first information, the transceiver module 820 is further configured to send certificate information, where the certificate information includes a public key provided by an institution that issues the certificate.

[0212] In another implementation, the transceiver module 820 is configured to send a first message, receive a first message, and send a second message. The first message indicates a first public key and a list of at least one encryption algorithm, where the at least one encryption algorithm is an encryption algorithm supported by the communication device 800. The first message includes a random access preamble, an identifier of the first encryption algorithm, and a second public key, where the second public key is the public key of the terminal, and the first encryption algorithm is one of the at least one encryption algorithms supported by the communication device 800. The processing module 810 is configured to decrypt the third message based on the first encryption algorithm and a shared key, where the shared key is obtained based on the second public key and the second private key, where the second private key is the private key of the communication device 800.

[0213] As an optional implementation, before sending the second message, the processing module 810 is further configured to encrypt the second message according to the first encryption algorithm and the shared key.

[0214] As an optional implementation method, the shared key is obtained based on the first public key and the first private key, including: the shared key is obtained based on the first public key, the first private key and the first parameter, wherein the first parameter includes one or more of the following: TC-RNTI, synchronization signal index, or random access resource index.

[0215] As an optional implementation manner, the first message is scrambled by a sequence generated by a preamble code sequence index and / or a synchronization signal index.

[0216] As an optional implementation method, the first message also includes a message verification code. When the first message includes a random access preamble, the message verification code is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and the shared key.

[0217] As an optional implementation, before receiving the first information, the transceiver module 820 is further configured to send certificate information, where the certificate information includes a public key provided by an institution that issues the certificate.

[0218] In another implementation, the transceiver module 820 is used to send a first message, receive a first message, and send a second message. The first information indicates a first public key and at least one encryption algorithm, the first public key is the public key of the network device, and the at least one encryption algorithm is an encryption algorithm supported by the network device. The first message indicates a first encryption algorithm and a second public key, the second public key is the public key of the communication device 800, the first encryption algorithm belongs to at least one encryption algorithm supported by the network device, and the first message also includes a random access preamble or a random access reason value. The first message is scrambled by a sequence generated by a preamble sequence index and / or a synchronization signal index. The processing module 810 is also used to encrypt the second message according to the first encryption algorithm and a shared key. The shared key is obtained based on the second public key and the second private key, and the second private key is the private key of the communication device 800.

[0219] When the communication device 800 is a chip-type device or circuit, the transceiver module may be an input / output circuit and / or a communication interface; the processing module may be an integrated processor or microprocessor or integrated circuit.

[0220] Figure 9 is a schematic block diagram of a communication device 900 provided in an embodiment of the present application. The communication device 900 can be a network device or a first terminal in the above embodiment. For example, the communication device 900 can be the network device or terminal in Figure 1; or the communication device 900 is a chip (system) in a network device terminal. In the embodiment of the present application, the chip system can be composed of a chip, or it can include a chip and other discrete devices. For specific functions, please refer to the description in the above method embodiment.

[0221] The communication device 900 includes one or more processors 901, which are used to implement or support the communication device 900 to implement the functions of the terminal or network device in the method provided in the embodiment of the present application. Please refer to the detailed description in the method example for details, which will not be repeated here. The processor 901 can also be called a processing unit or a processing module, which can implement certain control functions. The processor 901 can be a general-purpose processor or a dedicated processor. For example, it includes: a baseband processor, a central processing unit, an application processor, a modem processor, a graphics processor, an image signal processor, a digital signal processor, a video codec processor, a controller, a memory, and / or a neural network processor. The baseband processor can be used to process communication protocols and communication data. The central processing unit can be used to control the communication device 900 (such as a network device or terminal device), execute software programs and / or process data. Different processors can be independent devices or integrated into one or more processors, for example, integrated into one or more dedicated integrated circuits.

[0222] In one design, the processor 901 may include a program 903 (sometimes also referred to as code or instructions), which may be executed on the processor 901 to cause the communication device 900 to perform the methods described in the following embodiments. In another possible design, the communication device 900 includes circuitry (not shown in FIG9 ) configured to implement the network device or terminal functions described in the above embodiments.

[0223] In one design, the communication device 900 may include one or more memories 902 on which a program 904 (sometimes also referred to as code or instructions) is stored. The program 904 can be run on the processor 901, so that the communication device 900 performs the method described in the above method embodiment, such as the process shown in Figure 4, Figure 6 or Figure 7.

[0224] In one design, the processor 901 and / or the memory 902 may include an artificial intelligence (AI) module 907 and an AI module 908, each configured to implement AI-related functions. The AI ​​module may be implemented using software, hardware, or a combination of software and hardware. For example, the AI ​​module may include a RAN intelligent controller (RIC) module. For example, the AI ​​module may be a near real-time RIC or a non-real-time RIC.

[0225] In a possible design, data may also be stored in the processor 901 and / or the memory 902. The processor and the memory may be provided separately or integrated together.

[0226] In one possible design, the communication device 900 may further include a transceiver 905 and / or an antenna 906. The processor 901 may also be sometimes referred to as a processing unit, and controls the communication device 900. The transceiver 905 may also be sometimes referred to as a transceiver unit, a transceiver, a transceiver circuit, or a transceiver, and is configured to implement the transceiver function of the communication device through the antenna 906.

[0227] In one possible design, the communication device 900 may further include one or more of the following components: a wireless communication module, an audio module, an external memory interface, an internal memory, a universal serial bus (USB) interface, a power management module, an antenna, a speaker, a microphone, an input / output module, a sensor module, a motor, a camera, or a display screen, etc. It will be appreciated that in some embodiments, the communication device 900 may include more or fewer components, or some components may be integrated or separated. These components may be implemented in hardware, software, or a combination of software and hardware.

[0228] The communication device in the above embodiments can be a terminal (or network device), a circuit, a chip used in a terminal (or network device), or other combined devices or components with the above terminals (or network devices). When the communication device is a terminal (or network device), the transceiver module can be a transceiver, which can include an antenna and a radio frequency circuit, etc., and the processing module can be a processor, such as a CPU. When the communication device is a component with the functions of the above terminal (or network device), the transceiver module can be a radio frequency unit, and the processing module can be a processor. When the communication device is a chip system, the communication device can be an FPGA, a dedicated ASIC, a system on chip (SoC), a CPU, a network processor (NP), a DSP, a microcontroller unit (MCU), a programmable logic device (PLD), or other integrated circuit. The processing module can be the processor of the chip system. The transceiver module or communication interface can be the input / output interface or interface circuit of the chip system. For example, the interface circuit can be a code / data read / write interface circuit. The interface circuit can be used to receive code instructions (the code instructions are stored in a memory and can be read directly from the memory or read from the memory via another device) and transmit them to the processor; the processor can be used to execute the code instructions to perform the method in the above method embodiment. For example, the interface circuit can also be a signal transmission interface circuit between a communication processor and a transceiver.

[0229] The present application also provides a communication system. Specifically, the communication system includes a network device and a terminal. Exemplarily, the communication system includes a terminal and a network device for implementing the functions described in FIG4, FIG6, or FIG7. For details, please refer to the relevant descriptions in the above method embodiments, which will not be repeated here.

[0230] An embodiment of the present application also provides a computer-readable storage medium, including instructions, which, when executed on a computer, enables the computer to execute the method performed by the terminal or network device in Figure 4, Figure 6, or Figure 7.

[0231] An embodiment of the present application also provides a computer program product, including instructions, which, when executed on a computer, enables the computer to execute the method performed by the terminal or network device in Figure 4, Figure 6, or Figure 7.

[0232] The embodiment of the present application provides a chip system, which includes a processor and may also include a memory, for implementing the functions of the terminal device or network device in the above method. The chip system can be composed of a chip or include a chip and other discrete devices.

[0233] To implement the functions of the communication device shown in Figures 8 and 9, embodiments of the present application further provide a chip including a processor for supporting the communication device in implementing the functions of the terminal or network device described in the method embodiments. In one possible design, the chip is connected to or includes a memory, which is used to store computer programs, instructions, and data necessary for the communication device.

[0234] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0235] Those skilled in the art will appreciate that the various illustrative logical blocks and steps described in conjunction with the embodiments disclosed herein can be implemented using electronic hardware, computer software, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0236] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0237] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0238] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0239] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the part that essentially contributes to the technical solution of the present application or the part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a RAM, a magnetic disk or an optical disk.

[0240] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include these modifications and variations.

Claims

1. A communication method, applied to a terminal, characterized in that: include: Receiving first information, the first information indicating a first public key and at least one encryption algorithm, the first public key is a public key of a network device, and the at least one encryption algorithm is an encryption algorithm supported by the network device; Sending a first message, where the first message indicates a first encryption algorithm and a second public key, where the second public key is a public key of the terminal, and the first encryption algorithm belongs to the at least one encryption algorithm, wherein the first message further includes a random access preamble code or a random access cause value; receiving a second message; The second message is decrypted according to the first encryption algorithm and a shared key, where the shared key is obtained according to the first public key and a first private key, and the first private key is a private key of the terminal device.

2. The method according to claim 1, characterized in that The shared key is obtained according to the first public key and the first private key, including: The shared key is obtained according to the first public key, the first private key and a first parameter, where the first parameter includes one or more of the following: a temporary cell radio network temporary identifier TC-RNTI, a synchronization signal index, or a random access resource index.

3. The method according to claim 1 or 2, characterized in that The first message is scrambled by a sequence generated by a preamble sequence index and / or a synchronization signal index.

4. The method according to any one of claims 1 to 3, characterized in that The first message also includes a message verification code, wherein: When the first message includes the random access preamble, the message authentication code is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm and the second public key by using the first encryption algorithm and the shared key; or When the first message includes a random access cause value, the message authentication code is obtained by encrypting the random access cause value, an identifier of the first encryption algorithm and the second public key by using the first encryption algorithm and the shared key.

5. The method according to any one of claims 1 to 4, characterized in that Before receiving the first information, the method further includes: Receiving certificate information, the certificate information including a public key provided by an institution that issued the certificate; The certificate information is signed and verified according to the public key provided by the institution that issued the certificate.

6. A communication method, characterized in that: include: Sending first information, where the first information indicates a first public key and at least one encryption algorithm, where the first public key is a public key of a network device, and the at least one encryption algorithm is an encryption algorithm supported by the network device; receiving a first message, the first message indicating a first encryption algorithm and a second public key, the second public key being a public key of a terminal, and the first encryption algorithm belonging to the at least one encryption algorithm; The second message is encrypted according to the first encryption algorithm and the shared key, and the encrypted second message is sent, the shared key is obtained according to the second public key and the second private key, and the second private key is the private key of the network device.

7. The method according to claim 6, characterized in that The shared key is obtained according to the second public key and the second private key, including: The shared key is obtained according to the second public key, the second private key and a first parameter, where the first parameter includes one or more of the following: a temporary cell radio network temporary identifier TC-RNTI, a synchronization signal index, or a random access resource index.

8. The method according to claim 6 or 7, characterized in that The first message is scrambled by a sequence generated by a preamble sequence index and / or an index of a synchronization signal.

9. The method according to any one of claims 6 to 8, characterized in that The first message also includes a message verification code; Wherein, when the first message includes the random access preamble, the message authentication code is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm and the second public key by using the first encryption algorithm and the shared key; or, When the first message includes a random access cause value, the message authentication code is obtained by encrypting the random access cause value, an identifier of the first encryption algorithm and the second public key by using the first encryption algorithm and the shared key.

10. The method according to any one of claims 6 to 9, characterized in that Before sending the first information, the method further includes: Acquire certificate information, the certificate information including a public key provided by an institution that issued the certificate, the public key being used to perform signature verification on the certificate; The certificate information is sent.

11. A communication method, characterized in that: include: Receiving first information, the first information indicating a first public key and at least one encryption algorithm, the first public key is a public key of a network device, and the at least one encryption algorithm is an encryption algorithm supported by the network device; Sending a first message, where the first message includes a random access preamble, an identifier of a first encryption algorithm, and a second public key, where the second public key is a public key of a terminal, and the first encryption algorithm belongs to the at least one encryption algorithm; receiving a second message; The third message is encrypted according to the first encryption algorithm and a shared key, and the encrypted third message is sent, the shared key is obtained according to the first public key and a first private key, and the first private key is a private key of the terminal.

12. The method according to claim 11, characterized in that The method further comprises: The second message is decrypted according to the first encryption algorithm and the shared key.

13. The method according to claim 11 or 12, characterized in that: The shared key is obtained according to the first public key and the first private key, including: The shared key is obtained according to the first public key, the first private key and a first parameter, where the first parameter includes one or more of the following: a temporary cell radio network temporary identifier TC-RNTI, a synchronization signal index, or a random access resource index.

14. The method according to any one of claims 11 to 13, characterized in that The first message is scrambled by a sequence generated by a preamble sequence index and / or an index of a synchronization signal.

15. The method according to any one of claims 11 to 14, characterized in that The first message also includes a message verification code, which is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and the shared key.

16. The method according to any one of claims 11 to 15, characterized in that Before receiving the first information, the method further includes: Receiving certificate information, the certificate information including a public key provided by an institution that issued the certificate; The certificate information is signed and verified according to the public key provided by the institution that issued the certificate.

17. A communication method, characterized in that: include: Sending first information, where the first information indicates a first public key and at least one encryption algorithm, where the first public key is a public key of a network device, and the at least one encryption algorithm is an encryption algorithm supported by the network device; receiving a first message, the first message including a random access preamble, an identifier of a first encryption algorithm, and a second public key, the second public key being a public key of a terminal, and the first encryption algorithm belonging to the at least one encryption algorithm; sending a second message; The third message is decrypted according to the first encryption algorithm and a shared key, where the shared key is obtained according to the second public key and a second private key, and the second private key is a private key of the network device.

18. The method according to claim 17, characterized in that Before sending the second message, the method further includes: The second message is encrypted according to the first encryption algorithm and the shared key.

19. The method according to claim 17 or 18, characterized in that The shared key is obtained according to the second public key and the second private key, including: The shared key is obtained according to the second public key, the second private key and a first parameter, where the first parameter includes one or more of the following: a temporary cell radio network temporary identifier TC-RNTI, a synchronization signal index, or a random access resource index.

20. The method according to any one of claims 17 to 19, characterized in that The first message is scrambled by a sequence generated by a preamble sequence index and / or an index of a synchronization signal.

21. The method according to any one of claims 17 to 20, characterized in that The first message also includes a message verification code, which is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and the shared key.

22. The method according to any one of claims 17 to 21, characterized in that Before sending the first information, the method further includes: Acquire certificate information, the certificate information including a public key provided by an institution that issued the certificate, the public key being used to perform signature verification on the certificate; The certificate information is sent.

23. A communication device, applied to a terminal, characterized in that: include: A transceiver module is used to receive a first message, send a first message, and receive a second message; wherein the first message indicates a first public key and at least one encryption algorithm, the first public key is a public key of a network device, and the at least one encryption algorithm is a public key supported by the network device. encryption algorithm; the first message indicates a first encryption algorithm and a second public key, the second public key is a public key of the terminal, the first encryption algorithm belongs to the at least one encryption algorithm, and the first message further includes a random access preamble or a random access reason value; A processing module is used to decrypt the second message according to the first encryption algorithm and a shared key, where the shared key is obtained according to the first public key and a first private key, and the first private key is a private key of the terminal device.

24. The device according to claim 23, characterized in that The shared key is obtained according to the first public key and the first private key, including: The shared key is obtained according to the first public key, the first private key and a first parameter, where the first parameter includes one or more of the following: a temporary cell radio network temporary identifier TC-RNTI, a synchronization signal index, or a random access resource index.

25. The device according to claim 23 or 24, characterized in that The first message is scrambled by a sequence generated by a preamble sequence index and / or a synchronization signal index.

26. The device according to any one of claims 23 to 25, characterized in that The first message also includes a message verification code, wherein: When the first message includes the random access preamble, the message authentication code is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm and the second public key by using the first encryption algorithm and the shared key; or When the first message includes a random access cause value, the message authentication code is obtained by encrypting the random access cause value, an identifier of the first encryption algorithm and the second public key by using the first encryption algorithm and the shared key.

27. The device according to any one of claims 23 to 26, characterized in that Before receiving the first information, the transceiver module is further used to: receive certificate information, the certificate information including a public key provided by an institution that issues the certificate; The processing module is further used to perform signature verification on the certificate information according to the public key provided by the institution that issued the certificate.

28. A communication device, characterized in that: include: A transceiver module, configured to send a first information and receive a first message; wherein the first information indicates a first public key and at least one encryption algorithm, the first public key is a public key of a network device, and the at least one encryption algorithm is an encryption algorithm supported by the network device; the first message indicates a first encryption algorithm and a second public key, the second public key is a public key of a terminal, and the first encryption algorithm belongs to the at least one encryption algorithm; A processing module is used to encrypt a second message according to the first encryption algorithm and a shared key, and send the encrypted second message, wherein the shared key is obtained according to the second public key and a second private key, and the second private key is a private key of the network device.

29. The device according to claim 28, characterized in that The shared key is obtained according to the second public key and the second private key, including: The shared key is obtained according to the second public key, the second private key and a first parameter, where the first parameter includes one or more of the following: a temporary cell radio network temporary identifier TC-RNTI, a synchronization signal index, or a random access resource index.

30. The device according to claim 28 or 29, characterized in that The first message is scrambled by a sequence generated by a preamble sequence index and / or an index of a synchronization signal.

31. The device according to any one of claims 28 to 30, characterized in that The first message also includes a message verification code; Wherein, when the first message includes the random access preamble, the message authentication code is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm and the second public key by using the first encryption algorithm and the shared key; or, When the first message includes a random access cause value, the message authentication code is obtained by encrypting the random access cause value, an identifier of the first encryption algorithm and the second public key by using the first encryption algorithm and the shared key.

32. The device according to any one of claims 28 to 31, characterized in that Before sending the first information, the transceiver module is further used for: Acquire certificate information, the certificate information including a public key provided by an institution that issued the certificate, the public key being used to perform signature verification on the certificate; The certificate information is sent.

33. A communication device, characterized in that: include: A transceiver module, configured to receive a first information, send a first message, and receive a second message; wherein the first information indicates a first public key and at least one encryption algorithm, the first public key is a public key of a network device, and the at least one encryption algorithm is an encryption algorithm supported by the network device; the first message includes a random access preamble, an identifier of the first encryption algorithm, and a second public key, the second public key is a public key of a terminal, and the first encryption algorithm belongs to the at least one encryption algorithm; A processing module is used to encrypt a third message according to the first encryption algorithm and a shared key, and send the encrypted third message, wherein the shared key is obtained according to the first public key and a first private key, and the first private key is a private key of the terminal.

34. The device according to claim 33, characterized in that The processing module is also used for: The second message is decrypted according to the first encryption algorithm and the shared key.

35. The device according to claim 33 or 34, characterized in that The shared key is obtained according to the first public key and the first private key, including: The shared key is obtained according to the first public key, the first private key and a first parameter, where the first parameter includes one or more of the following: a temporary cell radio network temporary identifier TC-RNTI, a synchronization signal index, or a random access resource index.

36. The device according to any one of claims 33 to 35, characterized in that The first message is scrambled by a sequence generated by a preamble sequence index and / or an index of a synchronization signal.

37. The device according to any one of claims 33 to 36, characterized in that The first message also includes a message verification code, which is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and the shared key.

38. The device according to any one of claims 33 to 37, characterized in that Before receiving the first information, the transceiver module is further used to: receive certificate information, the certificate information including a public key provided by an institution that issues the certificate; The processing module is further used to perform signature verification on the certificate information according to the public key provided by the institution that issued the certificate.

39. A communication device, characterized in that: include: A transceiver module, configured to send a first message, receive a first message, and send a second message; wherein the first information indicates a first public key and at least one encryption algorithm, the first public key is a public key of a network device, and the at least one encryption algorithm is an encryption algorithm supported by the network device; the first message includes a random access preamble, an identifier of the first encryption algorithm, and a second public key, the second public key is a public key of a terminal, and the first encryption algorithm belongs to the at least one encryption algorithm; A processing module is used to decrypt the third message according to the first encryption algorithm and a shared key, where the shared key is obtained according to the second public key and a second private key, and the second private key is a private key of the network device.

40. The device according to claim 39, characterized in that Before sending the second message, the processing module is further used for: The second message is encrypted according to the first encryption algorithm and the shared key.

41. The device according to claim 39 or 40, characterized in that The shared key is obtained according to the second public key and the second private key, including: The shared key is obtained according to the second public key, the second private key and a first parameter, where the first parameter includes one or more of the following: a temporary cell radio network temporary identifier TC-RNTI, a synchronization signal index, or a random access resource index.

42. The device according to any one of claims 39 to 41, characterized in that The first message is scrambled by a sequence generated by a preamble sequence index and / or an index of a synchronization signal.

43. The device according to any one of claims 39 to 42, characterized in that The first message also includes a message verification code, which is obtained by encrypting the random access preamble, the identifier of the first encryption algorithm and the second public key using the first encryption algorithm and the shared key.

44. The device according to any one of claims 39 to 43, characterized in that Before sending the first information, the transceiver module is further used for: Acquire certificate information, the certificate information including a public key provided by an institution that issued the certificate, the public key being used to perform signature verification on the certificate; The certificate information is sent.

45. A communication device, characterized in that: The communication device includes a processor and a memory, the memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory, so that the communication device performs the method as described in any one of claims 1 to 5, or the communication device performs the method as described in any one of claims 6 to 10, or the communication device performs the method as described in any one of claims 11 to 16, or the communication device performs the method as described in any one of claims 17 to 22.

46. ​​A chip or a chip system, characterized in that: The chip or chip system comprises: At least one processor and an interface, the at least one processor being used to call and run instructions from the interface, so that when the at least one processor executes the instructions, the method as claimed in any one of claims 1 to 5 is executed, or the method as claimed in any one of claims 6 to 10 is executed, or the method as claimed in any one of claims 11 to 16 is executed, or the method as claimed in any one of claims 17 to 22 is executed.

47. A computer-readable storage medium, characterized in that The computer-readable storage medium is used to store a computer program. When the computer program is run on a computer, the computer executes the method as claimed in any one of claims 1 to 5, or the computer executes the method as claimed in any one of claims 6 to 10, or the computer executes the method as claimed in any one of claims 11 to 16, or the computer executes the method as claimed in any one of claims 17 to 22.

48. A computer program product, characterized in that The computer program product comprises a computer program, which, when executed on a computer, enables the computer to execute the method as claimed in any one of claims 1 to 5, or enables the computer to execute the method as claimed in any one of claims 6 to 10, or enables the computer to execute the method as claimed in any one of claims 11 to 16, or enables the computer to execute the method as claimed in any one of claims 17 to 22.

49. A chip system, characterized in that: The chip system comprises: A processor and an interface, wherein the processor is used to call and run instructions from the interface, and when the processor executes the instructions, the method according to any one of claims 1 to 5 is implemented, or the method according to any one of claims 6 to 10 is implemented, or the method according to any one of claims 11 to 16 is implemented, or the method according to any one of claims 17 to 22 is implemented.

Citation Information

Patent Citations

  • Network connection method, terminal, equipment to be subjected to network configuration and storage medium

    CN114125832A

  • Authentication authentication method and related device

    CN114650530A

  • Method and device for data processing in random access process

    CN116546489A

  • Enhanced Security for Access Stratum Transmission

    US20210204129A1