Communication method and apparatus
By generating a channel key in the wireless communication system to encrypt and/or protect the identification information of the terminal device, the information theft problem caused by pseudo-base station attack is solved, and the security of the initial access process is improved.
Patent Information
- Application Number
- PCT/CN2024/136116
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-28
- Filing Date
- 2024-12-02
- Publication Date
- 2025-07-03
AI Technical Summary
In wireless communication, pseudo-base station attack causes the terminal device to be unable to verify the integrity of signaling messages during the initial access to the base station, eavesdropping on communication between the base station and the terminal device, and how to improve system security.
Before the secure mode is started, the terminal device and the network device generate a channel key by receiving the reference signal, encrypting and/or integrity protection of the sent messages, ensuring that the identification information of the terminal device is not stolen during the initial access process.
It improves the security of the wireless communication system during the initial access process, prevents pseudo-base station attacks, and ensures the security of important information interaction between terminal equipment and network equipment.
Smart Images

Figure CN2024136116_03072025_PF_FP_ABST
Abstract
Description
Communication method and device
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of the People's Republic of China on December 28, 2023, with application number 202311852056.5 and invention name "A Communication Method and Device", the entire contents of which are incorporated by reference into this application. Technical Field
[0003] The present application relates to the field of communication technology, and in particular to a communication method and device. Background Art
[0004] In wireless communications, communication security is a crucial factor, ensuring the safety of user data. Rogue base station attacks are a common threat to wireless security. A rogue base station is an illegal base station, typically consisting of simple wireless devices and specialized open-source software. By simulating a legitimate base station, a rogue base station sends signaling to a target terminal device according to relevant protocols, obtaining information related to the target terminal. This is particularly true before a terminal device initially connects to a base station. Because security mode is not activated and signaling lacks integrity protection and encryption, the terminal device cannot verify the integrity of received signaling messages, allowing third parties to eavesdrop on the plaintext messages transparently transmitted between the base station and the terminal.
[0005] To ensure the communication security between the base station and the terminal, the base station can start the security mode after the initial access of the terminal device, and send the encryption key and the integrity protection key KEY and other parameters to the terminal device. The subsequent signaling interaction between the base station and the terminal device can encrypt the transmitted data based on the encryption key to achieve data encryption and air interface integrity protection.
[0006] However, currently, signaling between the base station and the terminal device is not encrypted or integrity-protected before the base station sends the encryption key and integrity protection key KEY to the terminal device. Before secure mode is activated between the base station and the terminal device, a rogue base station could eavesdrop on the signaling between the base station and the terminal device, for example, obtaining the terminal device's identification information. Therefore, improving system security is an urgent issue. Summary of the Invention
[0007] The present application provides a communication method and apparatus for improving system security.
[0008] In a first aspect, the present application provides a communication method, wherein the method is performed by a terminal device or a module or chip in the terminal device, and is described herein using the terminal device as the performing entity. The method comprises: receiving a first reference signal from the network device; determining a first channel key based on the first reference signal; using the first channel key to encrypt and / or integrity-protect messages sent before the security mode is activated; and sending a first message; wherein the first message is encrypted and / or integrity-protected using the first channel key, and the first message includes identification information of the terminal device.
[0009] According to this method, during the initial access process, a first channel key is generated based on a first reference signal from a network device. When a first message including identification information of a terminal device is sent before the security mode is started, the first channel key is used to encrypt and / or integrity protect the first message to resist potential attacks, so that the terminal device and the network device can complete the interaction of important information during the initial access process, thereby improving the security of data transmission.
[0010] In one possible implementation, the method further includes: receiving first information from the network device; the first information is used to indicate a first resource; sending a second reference signal and first correction information through the first resource; the first correction information is determined based on the first channel key, the second reference signal is used to determine the second channel key, and the first correction information is used to correct the second channel key.
[0011] Through this method, the network device can correct the generated second channel key through the first correction information, so that the corrected second channel key is the same as the first channel key, thereby ensuring that the network device and the terminal device can decrypt messages sent by each other.
[0012] In a possible implementation manner, the first information is located in a system information block, or the first information is located in a random access response message in a random access process, or the first information is located in a second message.
[0013] The above-mentioned message is a message during the initial access process. This ensures that during the initial access process, the terminal device can send a second reference signal, allowing the network device to determine the second channel key based on the second reference signal, thereby improving the security of data transmission during the initial access process. In one possible implementation, the method further includes: receiving second correction information from the network device; the second correction information is used to correct the first channel key; correcting the first channel key based on the second correction information to obtain the corrected first channel key; the corrected first channel key is used to encrypt and / or integrity protect messages sent before the security mode is activated.
[0014] Through this method, the first channel key is corrected using the second correction information so that the corrected first channel key is the same as the second channel key generated by the network device, thereby ensuring that the network device and the terminal device can decrypt messages sent by each other.
[0015] In one possible implementation, determining the first channel key based on the first reference signal includes: determining a first channel measurement result based on the first reference signal; determining a value of a first channel characteristic parameter based on the first channel measurement result; and determining the first channel key based on the value of the first channel characteristic parameter and a first channel key generation algorithm.
[0016] In one possible implementation, the method further includes: receiving a system information block or a second message from the network device, the system information block or the second message including at least one of the following: a channel characteristic parameter list, the channel characteristic parameter list including at least one channel characteristic parameter; a channel key generation algorithm list, the channel key generation algorithm list including at least one channel key generation algorithm.
[0017] This implementation method is more flexible to implement, and the first channel characteristic parameters and the first channel key generation algorithm can be selected according to one's own capabilities, so that the selected first channel characteristic parameters and the first channel key generation algorithm are more matched with the capabilities of the terminal device, thereby ensuring the generation rate and accuracy of the channel key.
[0018] In a possible implementation, the method further includes: determining the first channel characteristic parameter from at least one channel characteristic parameter, and / or determining the first channel key generation algorithm from at least one channel key generation algorithm.
[0019] In a possible implementation, the method further includes: sending second information, where the second information is used to indicate at least one of the following: the first channel characteristic parameter; and the first channel key generation algorithm.
[0020] Through the second information, the network device also determines the channel key based on the first channel characteristic parameter and / or the first channel key generation algorithm, so that the channel key determined by the network device matches the channel key determined by the terminal device, and the network device and the terminal device can use the matching channel key to decrypt messages sent to each other.
[0021] In one possible implementation, the algorithm for encrypting the first message is a first encryption algorithm, the algorithm for integrity protection of the first message is a first integrity protection algorithm, and the input parameters of the first encryption algorithm and the first integrity protection algorithm include the first channel key; the method also includes: receiving a system information block or a second message from the network device, the system information block or the second message includes at least one of the following: a first encryption algorithm list, the first encryption algorithm list includes at least one encryption algorithm; a first integrity protection algorithm list, the first integrity protection algorithm list includes at least one integrity protection algorithm.
[0022] In a possible implementation manner, the method further includes: determining the first encryption algorithm from a first encryption algorithm list, and / or determining the first integrity protection algorithm from the first integrity protection algorithm list.
[0023] In a possible implementation, the method further includes: sending third information, where the third information is used to indicate at least one of the following: the first encryption algorithm; the first integrity protection algorithm.
[0024] In one possible implementation, the algorithm for encrypting the first message is a first encryption algorithm, the algorithm for integrity protection of the first message is a first integrity protection algorithm, and the input parameters of the first encryption algorithm and the first integrity protection algorithm include the first channel key; the method also includes: sending a third message, the third message including at least one of the following: a second encryption algorithm list, the second encryption algorithm list includes at least one encryption algorithm, the at least one encryption algorithm includes the first encryption algorithm; a second integrity protection algorithm list, the second integrity protection algorithm list includes at least one integrity protection algorithm, the at least one integrity protection algorithm includes the first integrity protection algorithm.
[0025] In a possible implementation, the method further includes: receiving fourth information from the network device, where the fourth information is used to indicate at least one of the following: the first encryption algorithm; the first integrity protection algorithm.
[0026] In a possible implementation, the method further includes: sending first information; the first information is used to indicate that the channel key generation capability is available, or that the channel key is desired to be used for encryption and / or integrity protection.
[0027] In a possible implementation, the first message is a radio resource control (RRC) establishment completion message, or an RRC recovery completion message, or an RRC re-establishment completion message.
[0028] In a possible implementation, the second message is an RRC establishment message, or an RRC recovery message, or an RRC reconstruction message.
[0029] In a possible implementation, the third message is an RRC establishment request message, or an RRC recovery request message, or an RRC re-establishment request message.
[0030] In a possible implementation, the first reference signal and the second reference signal are located within a coherent bandwidth; and a transmission time of the first reference signal and a transmission time of the second reference signal are within a coherent time.
[0031] In a second aspect, the present application provides a communication method, wherein the execution subject of the method is a network device or a module or chip in the network device. The method is described here using the network device as the execution subject as an example. The method includes: receiving a second reference signal from the terminal device; determining a second channel key based on the second reference signal; the second channel key is used to encrypt and / or integrity protect messages sent before the security mode is started; receiving a first message from the terminal device, the first message including identification information of the terminal device; and decrypting and / or integrity verifying the second message based on the second channel key.
[0032] According to this method, during the initial access process, a second channel key is generated based on a second reference signal from the terminal device; thus, before the security mode is started, the second channel key can be used to decrypt and / or verify the integrity of the first message including the identification information of the terminal device to resist potential attacks, so that the terminal device and the network device can complete the interaction of important information during the initial access process, thereby improving the security of data transmission.
[0033] In a possible implementation, the method further includes: sending first information; the first information indicating a first resource; and receiving a second reference signal from the terminal device through the first resource.
[0034] In one possible implementation, the method further includes: receiving first correction information from the terminal device; the first correction information is used to correct the second channel key; correcting the first channel key according to the first correction information to obtain a corrected second channel key; the corrected second channel key is used to encrypt and / or integrity protect messages sent before the security mode is started.
[0035] In a possible implementation manner, the first information is located in a system information block, or the first information is located in a random access response message in a random access process, or the first information is located in a second message.
[0036] In one possible implementation, the method further includes: sending a first reference signal and second correction information; the second correction information is determined based on the second channel key, the first reference signal is used to determine the first channel key, and the second correction information is used to correct the first channel key.
[0037] In one possible implementation, determining the second channel key based on the second reference signal includes: determining a second channel measurement result based on the second reference signal; determining a value of a first channel characteristic parameter based on the second channel measurement result; and determining the second channel key based on the value of the first channel characteristic parameter and a first channel key generation algorithm.
[0038] In one possible implementation, the method further includes: sending a system information block or a second message, wherein the system information block or the second message includes at least one of the following: a channel characteristic parameter list, wherein the channel characteristic parameter list includes at least one channel characteristic parameter; and a channel key generation algorithm list, wherein the channel key generation algorithm list includes at least one channel key generation algorithm.
[0039] In a possible implementation, the method further includes: receiving second information from the terminal device, where the second information is used to indicate at least one of the following: the first channel characteristic parameter; and the first channel key generation algorithm.
[0040] In one possible implementation, the algorithm for encrypting the first message is a first encryption algorithm, the algorithm for integrity protection of the first message is a first integrity protection algorithm, and the input parameters of the first encryption algorithm and the first integrity protection algorithm include the first channel key; the method also includes: sending a system information block or a second message, the system information block or the second message includes at least one of the following: a first encryption algorithm list, the first encryption algorithm list includes at least one encryption algorithm; a first integrity protection algorithm list, the first integrity protection algorithm list includes at least one integrity protection algorithm.
[0041] In one possible implementation, the method further includes: receiving third information from the terminal device, where the third information is used to indicate at least one of the following: the first encryption algorithm; the first integrity protection algorithm.
[0042] In one possible implementation, the algorithm for encrypting the first message is a first encryption algorithm, the algorithm for integrity protection of the first message is a first integrity protection algorithm, and the input parameters of the first encryption algorithm and the first integrity protection algorithm include the first channel key; the method also includes: receiving a third message from the terminal device, the third message including at least one of the following: a second encryption algorithm list, the second encryption algorithm list includes at least one encryption algorithm, the at least one encryption algorithm includes the first encryption algorithm; a second integrity protection algorithm list, the second integrity protection algorithm list includes at least one integrity protection algorithm, the at least one integrity protection algorithm includes the first integrity protection algorithm.
[0043] In a possible implementation, the method further includes: sending fourth information, where the fourth information is used to indicate at least one of the following: the first encryption algorithm; the first integrity protection algorithm.
[0044] In a possible implementation, the method further includes: receiving first information from the terminal device; the first information is used to indicate that the terminal device has the ability to generate a channel key, or that the terminal device desires to use a channel key for encryption and / or integrity protection.
[0045] In a possible implementation, the first message is a radio resource control (RRC) establishment completion message, or an RRC recovery completion message, or an RRC re-establishment completion message.
[0046] In a possible implementation, the second message is an RRC establishment message, or an RRC recovery message, or an RRC reconstruction message.
[0047] In a possible implementation, the third message is an RRC establishment request message, or an RRC recovery request message, or an RRC re-establishment request message.
[0048] In a possible implementation, the first reference signal and the second reference signal are located within a coherent bandwidth; and a transmission time of the first reference signal and a transmission time of the second reference signal are within a coherent time.
[0049] In a third aspect, the present application further provides a communication device capable of implementing any of the methods provided in any of the first to second aspects above. The communication device may be implemented in hardware or by executing corresponding software implementations in hardware. The hardware or software includes one or more units or modules corresponding to the above functions.
[0050] In one possible implementation, the communication device includes a processor configured to support the communication device in executing the corresponding functions of the network device, terminal device, or core network device in the above-described method. The communication device may also include a memory, which may be coupled to the processor and stores program instructions and data necessary for the communication device. Optionally, the communication device also includes an interface circuit for supporting communication between the communication device and a device such as a terminal device.
[0051] In one possible implementation, the communication device includes corresponding functional modules for implementing the steps in the above method. The functions can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0052] In one possible implementation, the structure of the communication device includes a processing unit and a communication unit, which can perform the corresponding functions in the above method examples. For details, please refer to the description of the method provided in any one of the first aspect to the second aspect, which will not be repeated here.
[0053] In a fourth aspect, a communication device is provided, comprising a processor and an interface circuit, wherein the interface circuit is configured to receive signals from a communication device other than the communication device and transmit them to the processor, or to transmit signals from the processor to the communication device other than the communication device, wherein the processor implements the functional modules of the method in any possible implementation of any of the first and second aspects by means of logic circuits or by executing computer programs or instructions. Optionally, the communication device further comprises a memory configured to store the computer program or instructions.
[0054] In a fifth aspect, a computer-readable storage medium is provided, which stores a computer program or instruction. When the computer program or instruction is executed by a processor, the method in any possible implementation of any one of the first to second aspects is implemented.
[0055] In a sixth aspect, a computer program product storing instructions is provided, which, when read and executed by a computer, implements the method in any possible implementation of any one of the first to second aspects.
[0056] In a seventh aspect, a circuit is provided, which is used to execute the method in any possible implementation of any one of the first to second aspects above, and the circuit may include a chip circuit. Optionally, the circuit may also be coupled to a memory.
[0057] In an eighth aspect, a chip or chip system is provided, the chip including a processor, which, when executing a computer program or instruction, is used to implement the method in any possible implementation of any one of the first to second aspects. Optionally, the chip may also include a memory, and the chip may be composed of chips, or may include chips and other discrete devices. Optionally, the chip system includes at least one of a baseband system-on-a-chip (SOC) chip and a radio frequency (RF) chip, or the chip system includes at least one of a baseband chip and a radio frequency chipset.
[0058] In a ninth aspect, a communication device is provided, comprising a processor, which implements the method in any possible implementation of any one of the first to second aspects through a logic circuit or by executing a computer program or instruction.
[0059] In a tenth aspect, a communication device is provided, comprising a unit or module for executing the method in any possible implementation of any one of the first to second aspects above.
[0060] In an eleventh aspect, embodiments of the present application further provide a communication system. The communication system includes: a terminal device for implementing the method in the aforementioned first aspect and any possible implementation of the first aspect; and a network device for implementing the method in the aforementioned second aspect and any possible implementation of the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0061] FIG1 is a schematic diagram of a network device architecture provided by an embodiment of the present application;
[0062] FIG2 is a schematic diagram of a pseudo base station provided in an embodiment of the present application;
[0063] FIG3 is a schematic diagram of a man-in-the-middle attack provided in an embodiment of the present application;
[0064] FIG4 is a schematic diagram of a network architecture applicable to an embodiment of the present application;
[0065] FIG5 is a schematic diagram of a key generation method according to an embodiment of the present application;
[0066] FIG6 is a schematic diagram of an air interface integrity protection process provided in an embodiment of the present application;
[0067] FIG7 is a schematic diagram of an air interface encryption process provided in an embodiment of the present application;
[0068] FIG8 is a schematic diagram of an initial access process provided in an embodiment of the present application;
[0069] FIG9 is a flow chart of a communication method provided in an embodiment of the present application;
[0070] FIG10 is a flow chart of a communication method provided in an embodiment of the present application;
[0071] FIG11 is a flow chart of a communication method provided in an embodiment of the present application;
[0072] FIG12 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application;
[0073] FIG13 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application;
[0074] FIG14 is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0075] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. Obviously, the embodiments described are only a part of the embodiments of the present application, not all of the embodiments. The terms "first", "second" and corresponding terminology labels in the present application are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances. This is merely a way of distinguishing objects with the same properties when describing the embodiments of the present application. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, so that a process, method, system, product or device that includes a series of units is not necessarily limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or devices. The methods and devices provided in the embodiments of the present application are based on the same or similar technical concepts. Since the principles of solving problems by the methods and devices are similar, the implementation of the devices and methods can refer to each other, and the repetitions will not be repeated.
[0076] The method provided in the embodiment of the present application can be applied to various mobile communication systems, for example, the Internet of Things (IoT), narrowband Internet of Things (NB-IoT), a fourth generation (4G) communication system (such as long term evolution (LTE)), a fifth generation (5G) communication system (such as 5G new radio (NR)), a hybrid architecture of LTE and NR, 6G or new communication systems emerging in future communication developments, etc. The communication system may also include a machine to machine (M2M) network, a machine type communication (MTC) or other networks.
[0077] Below, some terms used in the embodiments of the present application are first explained to facilitate understanding by those skilled in the art.
[0078] In the embodiments of the present application, the network device may be a device in a wireless network, and the network device may also be referred to as a network apparatus, a radio access network device, or an access network device. For example, the network device may be a radio access network (RAN) node that connects a terminal device to a wireless network, and may also be referred to as an access network device. Network equipment includes but is not limited to: base stations, evolved NodeBs (eNodeBs), transmission reception points (TRPs), next generation NodeBs (gNBs) in fifth generation (5G) mobile communication systems, access network equipment in open radio access networks (O-RANs), next generation base stations in sixth generation (6G) mobile communication systems, base stations in future mobile communication systems, or access nodes in wireless fidelity (WiFi) systems, etc.; or it may be a module or unit that completes part of the functions of a base station, for example, a centralized unit (CU), a distributed unit (DU), a centralized unit control plane (CU-CP) module, or a centralized unit user plane (CU-UP) module. The access network equipment may be a macro base station, a micro base station, an indoor station, a relay node, a donor node, etc. The specific technology and specific device form adopted by the network equipment are not limited in this application.
[0079] As shown in Figure 1, in some implementations, network equipment may include a centralized unit (CU) and a distributed unit (DU). RAN equipment, including CU and DU nodes, splits the protocol layers of the gNB in the NR system. Some protocol layer functions are centrally controlled by the CU, while some or all of the remaining protocol layer functions are distributed in the DU, which is then centrally controlled by the CU. Furthermore, the CU can be divided into a control plane (CU-CP) and a user plane (CU-UP). The CU-CP is responsible for control plane functions, primarily including radio resource control (RRC) and the control plane's corresponding packet data convergence protocol (PDCP) (i.e., PDCP-C). PDCP-C is primarily responsible for encryption, decryption, integrity protection, and data transmission of control plane data. The CU-UP is responsible for user plane functions, primarily including the service data adaptation protocol (SDAP) and the user plane's corresponding PDCP (i.e., PDCP-U). SDAP is primarily responsible for processing core network data and mapping flows to bearers. The PDCP-U is primarily responsible for data plane encryption and decryption, integrity protection, header compression, sequence number maintenance, and data transmission. The CU-CP and CU-UP are connected via the E1 interface. The CU-CP represents the gNB's connection to the core network via the NG interface and to the DU via the F1 interface control plane (i.e., F1-C). The CU-UP connects to the DU via the F1 interface user plane (i.e., F1-U). Alternatively, the PDCP-C may also reside in the CU-UP.
[0080] It is understandable that in different systems, CU (including CU-CP or CU-UP) or DU may have different names, but those skilled in the art can understand their meanings. For example, in an open radio access network (O-RAN) system, CU may also be called O-CU (open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, and CU-UP may also be called O-CU-UP. For convenience of description, this application uses CU, CU-CP, CU-UP and DU as examples. The network device may also include an active antenna unit (AAU). The CU implements some functions of the gNB, and the DU implements some functions of the gNB. For example, the CU is responsible for processing non-real-time protocols and services and implementing the functions of the RRC layer. The DU is responsible for processing physical layer protocols and real-time services and implementing the functions of the radio link control (RLC) layer, the media access control (MAC) layer and the physical (PHY) layer. In some deployments, the CU can be further divided into a Centralized Unit Control Plane (CU-CP) node and a Centralized Unit User Plane (CU-UP) node, where the CU-CP is responsible for control plane functions and the CU-UP is responsible for user plane functions.
[0081] The terminal device involved in the embodiments of the present application may be a wireless terminal device capable of receiving scheduling and instruction information from a network device. The terminal device may be referred to as a terminal device, and may also be referred to as user equipment (UE), terminal, mobile station (MS), mobile terminal (MT), etc. The terminal device may be a device that includes wireless communication capabilities (providing voice / data connectivity to the user). For example, a handheld device with wireless connection capabilities, or an in-vehicle device, in-vehicle module, etc. Currently, some examples of terminal devices include: mobile phones, tablet computers, laptop computers, PDAs, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in the Internet of Vehicles, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, or wireless terminals in smart homes, device-to-device (D2D) communication terminal devices, vehicle-to-everything (V2X) communication terminal devices, smart vehicles, telematics boxes (T-boxes), machine-to-machine / machine-type communications (M2M / MTC) terminal devices, Internet of Things (IoT) The IoT (Internet of Things) terminal devices, etc. For example, the terminal device can be an onboard device, complete vehicle equipment, an onboard module, a vehicle, an onboard unit (OBU), a roadside unit (RSU), a T-box, a chip, or a system on chip (SOC), etc. The above chip or SOC can be installed in the vehicle, OBU, RSU, or T-box. Wireless terminals in industrial control can be cameras, robots, etc. Wireless terminals in smart homes can be TVs, air conditioners, vacuum cleaners, speakers, set-top boxes, etc.The terminal device can also be a V2X device, such as a smart car (or intelligent car), a digital car, an unmanned car (or driverless car or pilotless car or automobile), a self-driving car or autonomous car, a pure electric vehicle (or Battery EV), a hybrid electric vehicle (HEV), a range extended EV (REEV), a plug-in hybrid electric vehicle (PHEV), a new energy vehicle (new energy vehicle), and a roadside unit (RSU). The terminal device can also be a device in device-to-device (D2D) communication, such as an electricity meter, a water meter, etc. In addition, in an embodiment of the present application, the terminal device can also be a terminal device in an IoT system. IoT is an important part of the future development of information technology. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network of human-machine interconnection and object-to-object interconnection.
[0082] In this application, predefined content generally refers to information that is defined by standards and does not require additional device configuration. It is pre-recorded / written in the hardware and / or software of the terminal device itself, or it can be understood as not being modifiable by the network device or other terminal devices. Pre-configured content generally refers to information that is pre-recorded / written in the hardware and / or software of the terminal device itself, determined by the equipment manufacturer, and can be modified through software or hardware.
[0083] (Pre) configuration can be divided into network device (pre) configuration and terminal device (pre) configuration. If it is a network device (pre) configuration, it can be (pre) configured through the system information block (SIB) or RRC signaling; if it is a terminal device (pre) configuration, it can be (pre) configured according to PC5-RRC signaling.
[0084] Channel measurement: refers to the measurement of the signal from the transmitter by the receiver to obtain various parameters such as the signal received power, phase, envelope amplitude, signal-to-noise ratio, etc. These parameters can characterize the transmission characteristics of the channel between the receiver and the transmitter.
[0085] Fake base station attack: A network attacker places an illegal base station within the coverage area of a target base station. The fake base station can force the target terminal nearby to reselect a cell, update its location, and switch cells, thereby deceiving the terminal or providing it with false information to achieve the purpose of spreading viruses or engaging in network fraud.
[0086] For example, as shown in Figure 2, a fake base station can be composed of an engineering terminal (for example, a computer / mobile phone), cables, and a wireless transceiver. By disguising itself as a base station of a mobile communication operator, it can deceive the terminal and launch an attack. A fake base station attack can be carried out by forging system messages, and the fake system messages will overwrite the real system messages in the network, causing the target terminal to refuse the service of the target base station. In addition, the fake base station can also trick the terminal into initiating a network registration or location update request to it, attracting the target terminal to reside in the fake base station, and then extracting the terminal's information. At this time, the terminal loses connection with the normal network and cannot obtain network services. The fake base station can also transmit information with the terminal, such as sending fraudulent text messages, malicious network links, or harassing text messages to the terminal.
[0087] Fake base stations can also intercept communication data between the target base station and the terminal, thereby monitoring the user's private data. While carrying out deceptive attacks on the terminal, fake base stations can also interfere with normal communication between the network and the terminal, affecting network performance.
[0088] Man-in-the-middle attack: A fake base station combines with a fake terminal to forward encrypted data between the terminal and the network in the form of relay forwarding, and tamper with the data to launch an attack without integrity protection.
[0089] For example, as shown in Figure 3, in the uplink when the target terminal transmits data to the target base station, the pseudo base station receives the target terminal's communication data and transparently transmits it to the target base station via the pseudo terminal. Correspondingly, in the downlink when the target base station transmits data to the target terminal, the pseudo terminal receives the communication data from the legitimate base station and, after tampering with the received data through the pseudo base station, transmits it to the target terminal.
[0090] During this process, it is difficult for the target terminal and the target base station to detect the existence of the fake base station and the fake terminal. If the integrity of the communication data between the target terminal and the target base station is not protected, attacks such as data tampering or packet loss may occur.
[0091] As shown in Figure 4, a schematic diagram of a network architecture provided by an embodiment of the present application is shown. The network architecture may include: a network device and at least one terminal device, for example, UE1 and UE2. The above network architecture may be an architecture in an LTE system, an architecture in an NR system, an LTE and NR hybrid architecture, or an architecture in a new communication system that emerges in 6G or future communication developments, and this application is not limited to this.
[0092] In order to avoid pseudo base station attacks and man-in-the-middle attacks, the data between the network device and the terminal device can be encrypted or integrity protected by a channel key. In the present application, the channel key can be generated by the network device and the terminal device respectively using a channel key generation technology. Channel key generation technology: In time division duplex (TDD) communication in wireless communication systems, the time periods for sending and receiving data by the communicating parties are different, but the uplink and downlink transmissions use the same frequency, and the uplink and downlink signals experience similar environments in the wireless channel and have short-term reciprocity. Therefore, an encryption key can be generated by extracting the common information of the public channel of the communicating parties. According to the short-term reciprocity of the channel, the channel characteristics measured by the communicating parties at the same time are the same, which can be used as a random source for generating the key; in addition, since the communication channel changes over time, the obtained channel key is automatically updated, and the updated key is unpredictable for eavesdroppers.
[0093] For example, Figure 5 shows a schematic flow chart of a key generation method based on channel measurement results. A in the figure may be the terminal device in Figure 4, and B in the figure may be the network device in Figure 4. Alternatively, A in the figure may be the network device in Figure 4, and B in the figure may be the terminal device in Figure 4. A and B each generate a key based on the channel measurement results, which primarily includes the following processes: channel estimation, channel feature extraction, initial key generation, key consistency verification, and key encryption and decryption.
[0094] In the channel estimation phase, A sends a training sequence to B. For example, the training sequence can be a demodulation reference signal (DMRS). B receives the training sequence and performs channel estimation to obtain a channel measurement result Y. B B sends a training sequence to A, A receives it and performs channel estimation to obtain the channel measurement result Y A , since the channel does not change during the channel coherence time, theoretically Y A =Y B .
[0095] Among them, the channel measurement result includes the measurement values of various channel characteristics obtained during the measurement process of the training sequence. For example, the training sequence sent by A is sent to B in the form of a wireless signal. B measures the wireless signal corresponding to the training sequence and can obtain measurement values such as the received signal power and received signal phase of the wireless signal. Therefore, the channel measurement result may include the measurement value of at least one of the following channel characteristics: received signal strength (RSS), received signal envelope, channel impulse response (CIR), received signal phase. The channel measurement result may also include other information, such as signal-to-noise ratio (SNR) or signal-to-interference-plus-noise ratio (SINR). The signal-to-noise ratio can be referred to as signal-to-noise ratio.
[0096] After obtaining the channel measurement results, A and B can use the same channel characteristics to generate the initial key. Taking side A as an example, extract the channel measurement result Y A When the channel characteristic is RSS, A can determine a string of bit values based on the comparison between RSS and the threshold, and use the string of bit values obtained after multiple comparisons as the initial key K A . Accordingly, B will measure the channel result Y B Compare the RSS with the threshold in the same way to get the initial key Y B Theoretically, Y A =Y B However, due to practical problems such as measurement error, the final initial key K A and K B are not necessarily equal, so key consistency correction is also required to change the initial key K A and K B Finally, A and B can obtain the same bit stream G. A and G B , and used as an encryption key to implement encryption or integrity protection between A and B.
[0097] Air Interface Integrity Protection: The transmitter uses regularly changing parameters and the transmitted data to perform a regular calculation to obtain a message authentication code for integrity (MAC-I). The receiver uses the same parameters and the same algorithm to calculate an expected message authentication code for integrity (XMAC-I). The receiver verifies the MAC-I and XMAC-I to determine if the data has been received completely, thereby protecting data integrity. As shown in Figure 6, taking the NR integrity protection algorithm (NIA) as an example, the input parameters of the NIA may include the integrity protection key KEY, the PDCP packet count (COUNT), the bearer identifier, the transmission direction (DIRECTION), and the message to be transmitted (MESSAGE). The transmitter appends the MAC-I to the message when sending it. The receiver uses the same method to calculate the XMAC-I of the received message and verifies the message integrity by comparing the MAC-I and XMAC-I. The transmission direction is uplink or downlink, for example, 0 indicates that the transmission direction is uplink, and 1 indicates that the transmission direction is downlink.
[0098] The air interface encryption protection process is similar to the integrity protection process. As shown in Figure 7, taking the NR Encryption Algorithm (NEA) as an example, the input parameters of the air interface encryption algorithm include the encryption key KEY, the PDCP packet count (COUNT), the bearer identifier, the transmission direction (DIRECTION), and the required key stream length (LENGTH). During encryption, the transmitter generates a key stream block (KEYSTREAMBLOCK) based on the input parameters. This key stream block is XORed with the plaintext block (PLAINTEXTBLOCK) to generate a ciphertext block (CIPHERTEXTBLOCK). At the receiver, the same key stream block is generated using the same input parameters and XORed with the ciphertext block to recover the plaintext block.
[0099] Initial access process: When the terminal device changes from the RRC idle state or the RRC inactive state to the RRC connected state, it first initiates a random access process (2-step random access or 4-step random access) to the base station, thereby triggering the initial access process.
[0100] For example, as shown in FIG8 , the initial access process may include the following steps:
[0101] Step 801: The terminal device sends an RRC setup request (RRCSetupRequest) message to the base station.
[0102] Among them, the terminal device sends an RRC establishment request message to the base station in the RRC idle state or the RRC inactive state.
[0103] Step 802: The base station sends an RRC setup (RRCSetup) message to the terminal.
[0104] When the terminal device receives the RRC establishment message, it completes random access and switches to the RRC connected state.
[0105] Step 802a: The terminal device sends an RRC setup complete (RRCSetupComplete) message to the base station.
[0106] The RRC setup process includes the Subscription Concealed Identifier (SUCI). The SUCI is obtained by encrypting the Subscription Permanent Identifier (SUPI) using an asymmetric algorithm. Therefore, its security depends entirely on the asymmetric encryption algorithm and key length used by the terminal device. Once the SUCI is obtained by an attacker, using a quantum computer and a corresponding cracking algorithm, it is possible to decrypt it within a limited time and obtain the corresponding SUPI. This SUPI can then be used to track the terminal device and perform other illegal activities.
[0107] Step 803: The base station sends an initial UE message to the access and mobility management function (AMF) network element.
[0108] Step 804: The AMF network element sends a downlink (DL) non-access stratum (NAS) transport message to the base station.
[0109] Step 804a: The base station sends a downlink information transfer (DLInformationTransfer) message to the terminal device.
[0110] Step 805: The terminal device sends an uplink (UL) information transfer (ULInformationTransfer) message to the base station.
[0111] Step 805a: The base station sends an uplink non-access layer transport (UL NAS transport) message to the AMF.
[0112] Step 806: The AMF network element sends an Initial Context Setup Request message to the base station.
[0113] The initial context establishment request message may include context data of the terminal device, PDU session context, security key, wireless capability and security capability of the terminal, etc. After receiving the initial context establishment request message, the base station starts the security mode.
[0114] Step 807: The base station sends a security mode command (securitymodecommand) message to the terminal device.
[0115] The security mode command message includes a security key configured by the core network, and the security key can be used for encryption and integrity protection.
[0116] Step 807a: The terminal device sends a security mode complete message to the base station.
[0117] That is, the base station starts the security mode and sends parameters such as the encryption key and / or air interface integrity protection key configured by the core network to the terminal.
[0118] The message after step 807a starts, and the security mode is started between the base station and the terminal device. After the security mode is started, the communication between the base station and the terminal device will be encrypted and integrity protected using the security key.
[0119] As can be seen from the above process, before secure mode is initiated, messages between the base station and the terminal device are not encrypted or integrity-protected, allowing other devices to obtain information transmitted before secure mode is initiated. For example, in step 802a, an attacker can obtain the SUCI in the RRC Setup Complete message. Therefore, how to improve the security of communications between the terminal device and the base station before secure mode is an urgent problem to be solved.
[0120] When the method provided in this application is applied to the network architecture in Figure 4, the functions of the network device can also be performed by a module (such as a chip) in the network device, or by a control subsystem that includes the network device function. The control subsystem that includes the network device function here can be a control center in the above-mentioned application scenarios such as smart grid, industrial control, smart transportation, and smart city. The functions of the terminal device can also be performed by a module (such as a chip or modem) in the terminal device, or by a device that includes the terminal device function.
[0121] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0122] It can be understood that the present application does not specifically limit the specific structure of the execution subject of the method provided in the embodiment of the present application. It can be applied to modules in terminal devices or network devices. As long as it can communicate according to the method provided in the embodiment of the present application by running a program that records the code of the method provided in the embodiment of the present application, it can be used. The interaction between the terminal device and the network device is used as an example for explanation below.
[0123] In the present application, before the security mode is started, the network device and the terminal device can send reference signals to each other, and the network device and the terminal device can each generate a channel key based on the received reference signal, so that before the security mode is started, the channel key can be used to encrypt and / or integrity protect the sent messages, thereby improving the security of data transmission.
[0124] FIG9 is a flow chart of a communication method provided in an embodiment of the present application, wherein the method includes:
[0125] Step 901: A network device sends a first reference signal.
[0126] Correspondingly, the terminal device receives the first reference signal.
[0127] The network device sending the first reference signal may refer to the network device outputting the first reference signal. For example, in one possible implementation, the network device may output the first reference signal to the radio frequency chip via a baseband chip. The radio frequency chip of the network device modulates the first reference signal and transmits it over the air interface. This application does not limit the specific process. The network device sending other information or messages may also refer to the description herein.
[0128] In the present application, the first reference signal may be a DMRS, or a reference signal such as a synchronization signal broadcast channel block (Synchronization Signal and PBCH Block, SSB). The present application does not limit the type of the first reference signal.
[0129] Step 902: The terminal device determines a first channel key according to a first reference signal.
[0130] The first channel key is used to encrypt and / or perform integrity protection on messages sent before the security mode is started.
[0131] For example, the terminal device determines a first channel measurement result based on a first reference signal, and determines a value of a first channel characteristic parameter based on the first channel measurement result. The terminal device may determine the first channel key based on the value of the first channel characteristic parameter and a first channel key generation algorithm. For example, the first channel measurement result includes at least one of the received signal envelope, received signal phase, received signal power, or channel impulse response (CIR) of the first reference signal. The terminal device may use one of them as the first channel characteristic parameter, for example, the received signal power as the first channel characteristic parameter; the terminal device quantizes the value of the first channel characteristic parameter (for example, the value of the received signal power) according to the first channel key generation algorithm, obtains L bits after quantization, and uses these L bits as the first channel key. L is an integer greater than 1, for example, L is 128 or 256.
[0132] The first channel characteristic may be any one of the following: a received signal envelope of a reference signal, a channel impulse response (CIR) of a reference signal, a received signal power of a reference signal, or a received signal phase of a reference signal.
[0133] This application does not limit how the terminal device determines the first channel characteristic parameter and the first channel key generation algorithm used to generate the first channel key. For example, in implementation method one, the first channel characteristic parameter and the first channel key generation algorithm are preset, for example, the preset first channel characteristic parameter is the received signal power, and the preset first channel key generation algorithm is a quantization algorithm. In this implementation method, after the terminal device determines the first channel measurement result based on the first reference signal, it can directly generate the first channel key based on the preset first channel characteristic parameter and the first channel key generation algorithm, so that the channel key can be determined early, and the channel key generation efficiency is high.
[0134] In implementation method 2, the network device may indicate at least one of the following to the terminal device:
[0135] A first channel characteristic parameter list includes at least one channel characteristic parameter; a first channel key generation algorithm list includes at least one channel key generation algorithm.
[0136] For example, the network device may indicate a first channel characteristic parameter list and / or a first channel key generation algorithm list through a system information block or a second message; wherein the second message is a message before the security mode is started, for example, the second message is an RRC establishment (RRCSetup) message, or an RRC recovery (RRCResume) message, or an RRC reconstruction (RRCReestablishment) message.
[0137] The terminal device may determine the first channel characteristic parameter from at least one channel characteristic parameter included in the channel characteristic parameter list, and / or determine the first channel key generation algorithm from at least one channel key generation algorithm included in the first channel key generation algorithm list.
[0138] This implementation method is more flexible. The terminal device can select the first channel characteristic parameters and the first channel key generation algorithm according to its own capabilities, so that the selected first channel characteristic parameters and the first channel key generation algorithm are more matched with the capabilities of the terminal device, thereby ensuring the generation rate and accuracy of the channel key.
[0139] In this implementation, the terminal device can also send second information to the network device, where the second information is used to indicate the first channel characteristic parameters and / or the first channel key generation algorithm, so that the network device can also determine the channel key based on the first channel characteristic parameters and / or the first channel key generation algorithm, so that the channel key determined by the network device matches the channel key determined by the terminal device, and the network device and the terminal device can use the matching channel keys to decrypt messages sent to each other.
[0140] Implementation method three, the terminal device can send the channel characteristic parameters and / or channel key generation algorithm supported by itself to the network device. For example, the terminal device can send a third message to the network device, and the third message includes at least one of the following: a second channel characteristic parameter list, the second channel characteristic parameter list includes at least one channel characteristic parameter; a second channel key generation algorithm list, the second channel key generation algorithm list includes at least one channel key generation algorithm.
[0141] The third message is a message sent before the security mode is started, for example, the third message is an RRC establishment request (RRCSetupRequest) message, or an RRC recovery request (RRCResumeRequest) message, or an RRC reconstruction request (RRCReestablishmentRequest) message.
[0142] The network device can determine the first channel characteristic parameter from at least one channel characteristic parameter included in the second channel characteristic parameter list, determine the first channel key generation algorithm from at least one channel key generation algorithm included in the second channel key generation algorithm list, and indicate the first channel characteristic parameter and / or the first channel key generation algorithm to the terminal device.
[0143] In this implementation, the first channel characteristic parameters and / or the first channel key generation algorithm indicated by the network device are both supported by the terminal device, which can ensure that the terminal device can determine the channel key based on the above parameters, and the implementation is more flexible.
[0144] Step 903: The terminal device sends a second reference signal through the first resource.
[0145] Correspondingly, the network device receives a second reference signal, wherein the second reference signal may be a channel state information reference signal (CSI-RS) or a reference signal such as an SRS, and the present application does not limit the type of the second reference signal.
[0146] The terminal device transmitting the second reference signal may refer to the terminal device outputting the second reference signal. For example, in one possible implementation, the terminal device may output the second reference signal to the RF chip via a baseband chip. The RF chip of the terminal device modulates the second reference signal and transmits it over the air interface. This application does not limit the specific process. The terminal device may also transmit other information or messages, as described herein.
[0147] In one implementation, the first resource is preset, so that the terminal device does not need to wait for resource scheduling by the network device before sending the second reference signal, thereby reducing the delay of the reference signal and the overhead of resource indication.
[0148] In another implementation, the first resource is configured by a network device. For example, the network device sends first information to the terminal device, where the first information indicates the first resource. This allows for more flexible transmission of the second reference signal, enabling scheduling of the first resource for the terminal device based on the needs of the terminal device.
[0149] The network device may carry the first information through any message before the security mode is started. For example, the first information may be located in any of the following messages: a system information block (SIB), such as SIB1; a random access response message in a random access process; or a second message.
[0150] In this application, the first reference signal and the second reference signal are located within the coherence bandwidth; the transmission time of the first reference signal and the transmission time of the second reference signal are within the coherence time. This ensures reciprocity between the uplink and downlink channels, ensuring that the channel key determined by the network device based on the second reference signal is similar to the channel key determined by the terminal device based on the first reference signal.
[0151] In the above process, the order of step 901 and step 903 is not limited, and step 903 can also be before step 901. The above is just an example, and other situations will not be repeated.
[0152] Implementation method 1: If step 901 precedes step 903 and the terminal device first determines the first channel key based on the first reference signal, the terminal device determines the first correction information based on the first channel key and sends the first correction information to the network device. In this implementation method, the terminal device can send the first correction information via the first resource, that is, the terminal device can send the second reference signal and the first correction information via the first resource.
[0153] After the network device generates a second channel key based on the second reference signal of the terminal device, it corrects the second channel key based on the first correction information to obtain a corrected second channel key; the corrected second channel key is the same as the first channel key, which ensures that the network device and the terminal device can decrypt messages sent by each other.
[0154] Implementation method 2: If step 903 precedes step 901 and the network device first determines the second channel key based on the second reference signal, the network device then determines the second correction information based on the second channel key and sends the second correction information to the terminal device. In this implementation method, the network device may send the second correction information when sending the first reference signal, or the network device may send the first reference signal and the second correction information using the same resource.
[0155] After the terminal device generates a first channel key based on the first reference signal of the network device, it corrects the first channel key based on the second correction information to obtain a corrected first channel key; the corrected first channel key and the second channel key are the same, which can ensure that the network device and the terminal device can decrypt messages sent by each other.
[0156] Step 904: The network device determines a second channel key according to the second reference signal.
[0157] The second channel key is used to encrypt and / or perform integrity protection on messages sent before the security mode is started.
[0158] The network device may also determine the second channel key based on the first channel characteristic parameter and the first channel key generation algorithm, and the specific process will not be described in detail.
[0159] Step 905: The terminal device sends a first message; the first message is encrypted and / or integrity protected using a first channel key.
[0160] Correspondingly, the network device receives the first message from the terminal device.
[0161] The first message may be a message sent before the secure mode is initiated. For example, the first message may be an RRC Setup Complete (RRCSetupComplete) message, an RRC Recovery Complete (RRCResumeComplete) message, or an RRC Reestablishment Complete (RRCReestablishmentComplete) message. The first message includes identification information of the terminal device, which may be, for example, a SUCI. By using this method, encryption and / or integrity protection are performed on the first message including the identification information of the terminal device before the secure mode is initiated. This prevents the identification information from being obtained by a third-party device, thereby improving the security of data transmission.
[0162] Optionally, the first message may also be a message sent after the safe mode is started, which is not limited in this application.
[0163] In the present application, the terminal device may encrypt the first message using a first encryption algorithm, the input parameters of the first encryption algorithm including a first channel key; and may perform integrity protection on the first message using a first integrity protection algorithm, the input parameters of the first integrity protection algorithm including the first channel key. For example, the first message includes the SUCI or SUPI of the terminal device. The NAS layer of the terminal device may use the first channel key as an encryption key and symmetrically encrypt the SUCI or SUPI using the first encryption algorithm. The specific process can be referred to the description in Figures 5 and 6 and will not be repeated here. Through this encryption process, the first message sent by the terminal device includes information that is symmetrically encrypted using the first encryption algorithm using the first channel key as the encryption key for the SUCI or SUPI. Therefore, a third-party device can only obtain the encrypted information and cannot obtain the SUCI or SUPI before encryption, thereby achieving encryption protection for the SUCI or SUPI.
[0164] This application does not limit how the terminal device determines the first encryption algorithm and the first integrity protection algorithm.
[0165] For example, in implementation method 1, the first encryption algorithm and the first integrity protection algorithm are preset, such as 128-NEA1 and 128-NIA1. In this implementation method, since the first encryption algorithm and the first integrity protection algorithm are preset, the overhead of obtaining the encryption algorithm and the integrity protection algorithm between the network device and the terminal device can be reduced, thereby improving resource utilization.
[0166] In implementation mode 2, the network device may send a system information block or a second message to the terminal device, where the system information block or the second message includes at least one of the following:
[0167] A first encryption algorithm list includes at least one encryption algorithm; a first integrity protection algorithm list includes at least one integrity protection algorithm.
[0168] The terminal device may determine the first encryption algorithm from the first encryption algorithm list and / or determine the first integrity protection algorithm from the first integrity protection algorithm list.
[0169] For example, the first encryption algorithm list includes 128-NEA1 and 256-NEA1, and the first integrity protection algorithm list includes 128-NIA1 and 256-NIA1. Assuming that the terminal device supports 256-NEA1 and 128-NIA1, 256-NEA1 and 128-NIA1 can be selected.
[0170] This implementation method is more flexible. The terminal device can select the first encryption algorithm and the first integrity protection algorithm according to its own capabilities, so that the selected first encryption algorithm and the first integrity protection algorithm are more matched with the capabilities of the terminal device, thereby improving communication security.
[0171] In this implementation, the terminal device can also send third information to the network device, and the third information is used to indicate the first encryption algorithm and / or the first integrity protection algorithm, so that the network device can also perform encryption and / or integrity protection according to the first encryption algorithm and / or the first integrity protection algorithm. The messages between the terminal device and the network device can use the same encryption algorithm and / or integrity protection algorithm, so that they can decrypt each other's messages.
[0172] Implementation method three, the terminal device can send the channel characteristic parameters and / or channel key generation algorithm it supports to the network device. For example, the terminal device can send a third message to the network device, and the third message includes at least one of the following: a second encryption algorithm list, the second encryption algorithm list includes at least one encryption algorithm, and the at least one encryption algorithm includes the first encryption algorithm; a second integrity protection algorithm list, the second integrity protection algorithm list includes at least one integrity protection algorithm, and the at least one integrity protection algorithm includes the first integrity protection algorithm.
[0173] The network device can determine the first encryption algorithm from the second encryption algorithm list, determine the first integrity protection algorithm from the second integrity protection algorithm list, and send fourth information to the terminal device, where the fourth information is used to indicate the first encryption algorithm and / or the first integrity protection algorithm.
[0174] In this implementation, the first encryption algorithm and / or first integrity protection algorithm indicated by the network device are both algorithms supported by the terminal device, which can ensure that the terminal device can encrypt and / or integrity protect the message according to the above algorithms, and is more flexible to implement.
[0175] The above are just examples, and other situations will not be elaborated on.
[0176] Step 906: The network device decrypts and / or performs integrity verification on the first message according to the second channel key.
[0177] This application does not limit how the network device decrypts and / or verifies the integrity of the first message based on the second channel key. For example, you can refer to the description in Figures 5 and 6, and the specific process will not be repeated here.
[0178] According to the method provided in the present application, during the initial access process, the terminal device generates a first channel key based on a first reference signal from the network device; the network device generates a second channel key based on a second reference signal from the terminal device, so that before the security mode is started, the terminal device uses the first channel key to encrypt and / or integrity protect the sent message, and the network device uses the second channel key to encrypt and / or integrity protect the sent message. This can achieve resistance to potential attacks during the initial access process, and enables the terminal device and the network device to complete the interaction of important information during the initial access process, which can improve the security of data transmission.
[0179] In combination with the previous description, the process of this application is described in detail below in combination with the initial access process.
[0180] As shown in FIG10 , a flow chart of a communication method provided in an embodiment of the present application is provided. In this flow, the terminal device first generates a first channel key based on a reference signal of the network device. The terminal device determines first correction information based on the first channel key and sends the first correction information to the network device. After the network device generates a second channel key based on the reference signal of the terminal device, the network device corrects the second channel key based on the first correction information to obtain a corrected second channel key. The corrected second channel key is the same as the first channel key, which ensures that the network device and the terminal device can decrypt messages sent by each other. Specifically, the method includes:
[0181] Step 1001: The network device sends a system information block.
[0182] The system information block may be SIB1 or another type of system information block. The system information block may indicate that the network device supports channel key generation. For example, the system information block includes channel key indication information, which indicates that the network device supports channel key generation or has channel key generation capability.
[0183] The system information block may also include other information, for example, the system information block includes resource configuration information, the resource configuration information indicating a preamble and / or a physical random access channel (PRACH) resource, where the preamble and PRACH resources are used for random access by the terminal device. Optionally, the resource configuration information may also indicate a dedicated preamble and / or a dedicated PRACH resource. If a terminal device has a channel key generation capability or desires to use a channel key for encryption and / or integrity protection, the terminal device may initiate random access using a dedicated preamble and / or a dedicated PRACH resource.
[0184] The above are just examples. The system information block may also include other contents, which will not be illustrated one by one here.
[0185] Step 1002: The terminal device sends a preamble code.
[0186] Among them, before the terminal device sends the preamble code, it is in the RRC idle state or the RRC inactive state.
[0187] The preamble is used to initiate random access. The preamble may also be called a random access preamble, a random access request message, or message 1 in the random access process, etc., which is not limited in this application.
[0188] The preamble code sent by the terminal device can be determined according to the system information block, and the PRACH resources used to send the preamble code can also be determined according to the system information block.
[0189] In one implementation, if a terminal device has channel key generation capability or desires to use channel keys for encryption and / or integrity protection, the terminal device may initiate random access using a dedicated preamble and / or dedicated PRACH resources. This allows the network device to determine that the terminal device has channel key generation capability or desires to use channel keys for encryption and / or integrity protection. In this manner, the terminal device implicitly indicates that it has channel key generation capability or desires to use channel keys for encryption and / or integrity protection, which can reduce signaling overhead.
[0190] Step 1003: The network device sends a random access response (RAR) message to the terminal device.
[0191] The random access response message may be referred to as message 2 in the random access process, etc., and this application does not limit this.
[0192] The random access response message may include uplink grant (UL grant) information, and the uplink grant information is used to schedule transmission resources of message 3 in the random access process.
[0193] Among them, message 3 can be an RRC setup request (RRCSetupRequest) message in the RRC establishment process, which is used to request the establishment of an RRC connection. The message may include the reason for the RRC connection establishment and the identifier of the terminal device. The identifier of the terminal device can be an S temporary mobile subscriber identity (S-temporary mobile subscriber identity, S-TMSI) or a random number.
[0194] Alternatively, message 3 may also be an RRC recovery request (RRCResumeRequest) message in the RRC recovery process, used to request the restoration of the RRC connection. The message may include the reason for the RRC connection restoration and the identifier of the terminal device.
[0195] Alternatively, message 3 may also be an RRC Reestablishment Request (RRCReestablishmentRequest) message in the RRC reconstruction process, used to request the reestablishment of the RRC connection. The message may include the RRC reconstruction reason and the identifier of the terminal device.
[0196] Step 1004: The terminal device sends message 3 to the network device.
[0197] In this application, message 3 may also be referred to as the third message or other names.
[0198] The content included in Message 3 is not limited by this application. For example, Message 3 may include fifth information, and the fifth information is used to indicate that the terminal device has the channel key generation capability, or expects to use the channel key for encryption and / or integrity protection. Optionally, when the system information block received by the terminal device indicates that the network device supports channel key generation, the fifth information is carried in Message 3. This ensures that the capabilities of the network device and the terminal device are consistent, avoids the terminal device unilaterally generating a channel key when the network device does not have the channel key generation capability, resulting in the network device being unable to decrypt the message encrypted by the terminal device, and improves system stability.
[0199] In another implementation, the fifth information can be located in a MAC control element (CE). When the terminal device sends message 3, it can also send a MAC CE including the fifth information, so that after the network device receives the transmission block corresponding to message 3, it can identify and receive the MAC CE at the MAC layer.
[0200] Step 1005: The network device sends message 4 and a first reference signal to the terminal device.
[0201] In this application, message 4 may also be referred to as a second message or the like. Message 4 may be an RRC Setup message in an RRC establishment process, or an RRC Resume message in an RRC Resume process, or an RRC Reestablishment message in an RRC Reestablishment process.
[0202] Optionally, the message 4 includes first information, and the first information indicates a first resource.
[0203] Step 1006: The terminal device determines a first channel key according to the first reference signal.
[0204] For example, a terminal device measures a first reference signal to obtain a first channel measurement result, and determines a value of a first channel characteristic parameter based on the first channel measurement result. The terminal device may quantize the value of the first channel characteristic parameter according to a first channel key generation algorithm to obtain L bits, and use these L bits as the first channel key. L is an integer greater than 1, for example, 128 or 256.
[0205] This application does not limit how the terminal device determines the first channel characteristic parameter and the first channel key generation algorithm. For example, the first channel characteristic parameter and the first channel key generation algorithm are preset.
[0206] For another example, the system information block or message 4 includes at least one of the following: a first channel characteristic parameter list; and a first channel key generation algorithm list. The terminal device may determine the first channel characteristic parameter from the first channel characteristic parameter list and / or determine the first channel key generation algorithm from the first channel key generation algorithm list.
[0207] For another example, the terminal device reports the second channel characteristic parameter list and / or the second channel key generation algorithm list through message 3; the network device can determine the first channel characteristic parameter from the second channel characteristic parameter list, determine the first channel key generation algorithm from the second channel key generation algorithm list, and send fourth information to the terminal device through message 4, where the fourth information is used to indicate the first channel characteristic parameter and / or the first channel key generation algorithm.
[0208] Step 1007a: The terminal device sends a second reference signal and first correction information to the network device through the first resource.
[0209] If the message 4 does not include the first information for indicating the first resource, the first resource may also be preset.
[0210] In the present application, the first correction information is determined according to the first channel key, and the first correction information is used to correct the second channel key, where the second channel key is generated by the network device.
[0211] Theoretically, the first channel key and the second channel key are the same. However, due to measurement errors and other reasons, the final first channel key and the second channel key may not be the same. The terminal device can add a cyclic redundancy check to the first channel key bit sequence, and encode the bit sequence with the cyclic redundancy check added using low-density parity-check codes (LDPC) or polar codes to obtain an encoded bit sequence. The terminal device can use a portion of the encoded bit sequence as the first correction information.
[0212] Step 1008a: The network device determines a second channel key according to the second reference signal.
[0213] For the specific process of the network device determining the second channel key, please refer to the previous description and will not be repeated here.
[0214] Optionally, if the network device receives the first correction information, it may further correct the second channel key according to the first correction information to obtain a corrected second channel key.
[0215] Step 1009a: The terminal device sends message 5, and message 5 is encrypted and / or integrity protected using the first channel key.
[0216] For example, message 5 is the RRC setup complete (RRCSetupComplete) message in the RRC establishment process, or message 5 is the RRC recovery complete (RRCResumeComplete) message in the RRC recovery process, or message 5 is the RRC reconstruction complete (RRCReestablishmentComplete) message in the RRC re-establishment process.
[0217] Message 5 includes information such as the SUCI of the terminal device. Through this method, since the message including the SUCI is encrypted and / or integrity protected before the security mode is started, the SUCI can be prevented from being obtained by a third-party device, thereby improving the security of data transmission.
[0218] Optionally, the terminal device may encrypt and / or integrity protect only the SUCI in message 5, and not encrypt or integrity protect other information in message 5. This can protect the SUCI while reducing the terminal device's overhead and improving the terminal device's battery life.
[0219] In this application, the terminal device can use the first encryption algorithm to encrypt message 5, and the input parameters of the first encryption algorithm include the first channel key; use the first integrity protection algorithm to perform integrity protection on message 5, and the input parameters of the first integrity protection algorithm include the first channel key; the specific process can refer to the description in Figures 5 and 6, and will not be repeated here.
[0220] This application does not limit how the terminal device determines the first encryption algorithm and the first integrity protection algorithm.
[0221] For example, the first encryption algorithm and the first integrity protection algorithm are preset.
[0222] For another example, the system information block or message 4 includes at least one of the following: a first encryption algorithm list; a first integrity protection algorithm list.
[0223] The terminal device may determine the first encryption algorithm from the first encryption algorithm list and / or determine the first integrity protection algorithm from the first integrity protection algorithm list. The terminal device may also send third information through message 3 or message 5, where the third information is used to indicate the first encryption algorithm and / or the first integrity protection algorithm.
[0224] If the terminal device sends the third information via message 5, the terminal device may not encrypt and integrity protect the third information, but only encrypt and integrity protect the other parts of message 5.
[0225] For another example, message 3 sent by the terminal device includes at least one of the following: a second encryption algorithm list; a second integrity protection algorithm list. The network device may determine the first encryption algorithm from the second encryption algorithm list, determine the first integrity protection algorithm from the second integrity protection algorithm list, and send fourth information to the terminal device via message 4, where the fourth information indicates the first encryption algorithm and / or the first integrity protection algorithm.
[0226] The above steps 1007a to 1009a are the first implementation provided by this application. In the second implementation, steps 1007a to 1009a can also be replaced by steps 1007b to 1008b.
[0227] Step 1007b: The terminal device sends message 5, the second reference signal and the first correction information to the network device.
[0228] The terminal device can send the second reference signal and the first correction information on the time-frequency resource carrying Message 5. In this case, Message 5 is encrypted and / or integrity-protected using the first channel key, but the second reference signal and the first correction information are not encrypted and integrity-protected using the first channel key. This protects Message 5 in the time slot and allows the network device to obtain the second reference signal and the first correction information.
[0229] Step 1008b: The network device determines a second channel key according to the second reference signal.
[0230] The specific content of this step can be referred to step 1008 and will not be described in detail here.
[0231] Step 1010: The network device decrypts and / or performs integrity verification on the message 5 according to the second channel key.
[0232] If the network device corrects the second channel key according to the first correction information, then the network device decrypts and / or performs integrity verification on the message 5 according to the corrected second channel key.
[0233] For other messages in the initial access process, encryption and / or integrity protection can also be performed. For example, the following steps may also be included:
[0234] Step 1011: The network device sends a downlink information transfer (DLInformationTransfer) message to the terminal device.
[0235] The downlink information transfer message is decrypted and / or integrity verified using the corrected second channel key.
[0236] Accordingly, the terminal device decrypts and / or performs integrity verification on the downlink information transfer message according to the first channel key.
[0237] Step 1012: The terminal device sends an uplink information transfer (ULInformationTransfer) message to the network device.
[0238] The uplink information transfer message is encrypted and / or integrity protected using the first channel key.
[0239] Accordingly, the network device decrypts and / or performs integrity verification on the uplink information transfer message according to the corrected second channel key.
[0240] The above is just an example, and other messages in the initial access process will not be further described.
[0241] From the above process, it can be seen that during the initial access process, before the security mode is started, the channel key is determined between the network device and the terminal device, so that the channel key can be used to encrypt and / or integrity protect the messages before the security mode is started, such as message 5, thereby preventing third-party devices from obtaining information of the terminal device and improving the security of data transmission.
[0242] In the present application, the network device may first generate the second channel key, and then the terminal device may generate the first channel key. As shown in FIG11 , which is a flow chart of a communication method provided by an embodiment of the present application, in this flow, the network device first generates the second channel key based on the reference signal of the terminal device, determines the second correction information based on the second channel key, and sends the second correction information to the terminal device; after the terminal device generates the first channel key based on the reference signal of the network device, it corrects the first channel key based on the second correction information to obtain a corrected first channel key; the corrected first channel key and the second channel key are the same, which can ensure that the network device and the terminal device can decrypt messages sent by each other. Specifically, the method includes:
[0243] Step 1101: The network device sends a system information block.
[0244] Step 1102: The terminal device sends a preamble code.
[0245] Step 1103: The network device sends a random access response message to the terminal device.
[0246] Step 1104: The terminal device sends message 3 and a second reference signal to the network device.
[0247] The resource where the second reference signal is located is preset.
[0248] For the specific contents of steps 1101 to 1104 , please refer to the description of steps 1001 to 1004 , which will not be repeated here.
[0249] Step 1105: The network device determines a second channel key according to the second reference signal.
[0250] For the specific content of step 1105, please refer to the description of step 1008a, which will not be repeated here.
[0251] Step 1106: The network device sends message 4, the first reference signal, and the second correction information to the terminal device.
[0252] In this application, the second correction information is determined based on the second channel key, and the second correction information is used to correct the first channel key, which is generated by the terminal device. This application does not limit how the second correction information is determined, and reference can be made to the previous description of the first correction information.
[0253] For other contents of message 4 and the first reference signal, please refer to the description in step 1005 and will not be repeated here.
[0254] Step 1107: The terminal device determines the first channel key according to the first reference signal.
[0255] For the specific content of step 1107, please refer to the description of step 1006, which will not be repeated here.
[0256] Step 1108: The terminal device sends message 5, and message 5 is encrypted and / or integrity protected using the first channel key.
[0257] If the terminal device corrects the first channel key according to the second correction information, then the terminal device encrypts and / or performs integrity protection on the message 5 according to the corrected first channel key.
[0258] Message 5 includes information such as the SUCI of the terminal device. For other contents of message 5, please refer to the description in step 1009a and will not be repeated here.
[0259] Step 1109: The network device decrypts and / or performs integrity verification on the message 5 according to the second channel key.
[0260] For other messages in the initial access process, encryption and / or integrity protection may also be performed. For example, reference may be made to the description in steps 1011 to 1012, which will not be repeated here.
[0261] From the above process, it can be seen that during the initial access process, before the security mode is started, the channel key is determined between the network device and the terminal device, so that the channel key can be used to encrypt and / or integrity protect the messages before the security mode is started, such as message 5, thereby preventing third-party devices from obtaining information of the terminal device and improving the security of data transmission.
[0262] It is understood that in order to implement the functions in the above embodiments, the terminal device or network device includes hardware structures and / or software modules corresponding to the execution of each function. It should be readily apparent to those skilled in the art that, in combination with the units and method steps of each example described in the embodiments disclosed in this application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a manner driven by computer software depends on the specific application scenario and design constraints of the technical solution.
[0263] The following is a schematic diagram of the structure of possible communication devices provided in the embodiments of the present application. These communication devices can be used to implement the functions of the terminal device or network device in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments.
[0264] As shown in Figure 12, the communication device 1200 includes a processing unit 1210 and a communication unit 1220. The communication device 1200 is used to implement the functions of the terminal device or network device in the above-mentioned method embodiments.
[0265] When the communication device 1200 is used to implement the functions of the terminal device:
[0266] a communication unit, configured to receive a first reference signal from a network device;
[0267] a processing unit, configured to determine a first channel key based on the first reference signal; the first channel key being used to encrypt and / or integrity protect messages sent before the security mode is activated;
[0268] The communication unit is used to send a first message; the first message is encrypted and / or integrity protected using the first channel key, and the first message includes identification information of the terminal device.
[0269] When the communication device 1200 is used to implement the functions of a network device:
[0270] a communication unit, configured to receive a second reference signal from the terminal device;
[0271] a processing unit, configured to determine a second channel key based on the second reference signal; the second channel key being used to encrypt and / or integrity protect messages sent before the security mode is started;
[0272] The communication unit is configured to receive a first message from the terminal device, where the first message includes identification information of the terminal device; and the processing unit is configured to decrypt and / or perform integrity verification on the first message according to the second channel key.
[0273] A more detailed description of the processing unit 1210 and the communication unit 1220 can be directly obtained by referring to the relevant descriptions in the above-mentioned method embodiments, and will not be repeated here.
[0274] It should be understood that the division of units in the above device is merely a division of logical functions. In actual implementation, they can be fully or partially integrated into one physical entity, or physically separated. Moreover, the units in the device can all be implemented in the form of software called through processing elements; or all be implemented in the form of hardware; or some units can be implemented in the form of software called through processing elements, and some units can be implemented in the form of hardware. For example, each unit can be a separately established processing element, or it can be integrated into a certain chip of the device. In addition, it can also be stored in the form of a program in a memory, called by a certain processing element of the device and execute the function of the unit. In addition, all or part of these units can be integrated together, or they can be implemented independently. The processing element here can also be a processor, which can be an integrated circuit with signal processing capabilities. In the implementation process, each operation of the above method or each unit above can be implemented by the integrated logic circuit of the hardware in the processor element or by software called through the processing element.
[0275] In one example, the units in any of the above devices may be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more digital single processors (DSPs), one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. For another example, when the units in the device can be implemented in the form of a processing element scheduler, the processing element can be a processor, such as a general-purpose central processing unit (CPU), or other processor that can call programs. For another example, these units can be integrated together and implemented in the form of a system-on-a-chip (SOC). The above-mentioned receiving unit is an interface circuit of the device, which is used to receive signals from other devices. For example, when the device is implemented in the form of a chip, the receiving unit is the interface circuit of the chip used to receive signals from other chips or devices. The above-mentioned sending unit is an interface circuit of the device, which is used to send signals to other devices. For example, when the device is implemented in the form of a chip, the sending unit is the interface circuit of the chip used to send signals to other chips or devices.
[0276] As another possible product form, the terminal device or network device of the embodiment of the present application can be implemented by a general bus architecture. For ease of explanation, refer to Figure 13, which is a structural diagram of a communication device 1300 provided in an embodiment of the present application, wherein the communication device 1300 includes a processor 1301 and a transceiver 1302. The communication device 1300 can be a terminal device, or a chip or chip system therein; or, the communication device 1300 can be a network device, or a chip or module therein. Figure 13 only shows the main components of the communication device 1300. In addition to the processor 1301 and the transceiver 1302, the communication device 1300 can further include a memory 1303, and an input and output device (not shown in the figure).
[0277] Optionally, processor 1301 is primarily used to process communication protocols and communication data, as well as control the entire communication device, execute software programs, and process software program data. Memory 1303 is primarily used to store software programs and data. Transceiver 1302 may include a radio frequency circuit and an antenna. The radio frequency circuit is primarily used to convert baseband signals into radio frequency signals and process radio frequency signals. The antenna is primarily used to transmit and receive radio frequency signals in the form of electromagnetic waves. Input and output devices, such as a touch screen, display, and keyboard, are primarily used to receive user input and output data to the user.
[0278] Optionally, the processor 1301 , the transceiver 1302 , and the memory 1303 may be connected via a communication bus.
[0279] When the communication device is powered on, the processor 1301 can read the software program in the memory 1303, interpret and execute the instructions of the software program, and process the data of the software program. When data needs to be sent wirelessly, the processor 1301 performs baseband processing on the data to be sent and outputs the baseband signal to the radio frequency circuit. The radio frequency circuit performs radio frequency processing on the baseband signal and then transmits the radio frequency signal to the outside in the form of electromagnetic waves through the antenna. When data is sent to the communication device, the radio frequency circuit receives the radio frequency signal through the antenna, converts the radio frequency signal into a baseband signal, and outputs the baseband signal to the processor 1301. The processor 1301 converts the baseband signal into data and processes the data.
[0280] In another implementation, the RF circuit and antenna can be set independently of the processor performing baseband processing. For example, in a distributed scenario, the RF circuit and antenna can be arranged remotely from the communication device.
[0281] In some embodiments, in terms of hardware implementation, those skilled in the art may conceive that the above-mentioned communication device 1200 may take the form of the communication device 1300 shown in FIG. 13 .
[0282] As an example, the functions / implementation process of the processing unit 1210 in FIG12 may be implemented by the processor 1301 in the communication device 1300 shown in FIG13 calling computer-executable instructions stored in the memory 1303. The functions / implementation process of the communication unit 1220 in FIG12 may be implemented by the transceiver 1302 in the communication device 1300 shown in FIG13.
[0283] As another possible product form, the terminal device or network device in the present application may adopt the structure shown in Figure 14, or include the components shown in Figure 14. Figure 14 is a schematic diagram of the structure of a communication device 1400 provided in the present application.
[0284] As shown in Figure 14, a communication device 1400 includes at least one processor 1401. Optionally, the communication device also includes a communication interface 1402. When the program instructions are executed in the at least one processor 1401, the device 1400 can implement the method provided in any of the aforementioned embodiments and any possible designs therein. Alternatively, the processor 1401 implements the method provided in any of the aforementioned embodiments and any possible designs therein through logic circuits or by executing code instructions.
[0285] The communication interface 1402 may be used to receive program instructions and transmit them to the processor. Alternatively, the communication interface 1402 may be used for communication between the communication device 1400 and other communication devices, such as exchanging control signaling and / or service data. Exemplarily, the communication interface 1402 may be used to receive signals from devices other than the communication device 1400 and transmit them to the processor 1401, or to send signals from the processor 1401 to communication devices other than the communication device 1400.
[0286] Optionally, the communication interface 1402 may be a code and / or data read / write interface circuit, or the communication interface 1402 may be a signal transmission interface circuit between a communication processor and a transceiver, or a pin of a chip.
[0287] Optionally, the communication device 1400 may further include at least one memory 1403, which may be used to store required program instructions and / or data. It should be noted that the memory 1403 may exist independently of the processor 1401 or may be integrated with the processor 1401. The memory 1403 may be located within or outside the communication device 1400, without limitation.
[0288] Optionally, the communication device 1400 may further include a power supply circuit 1404, which may be used to supply power to the processor 1401. The power supply circuit 1404 may be located in the same chip as the processor 1401, or in another chip other than the chip where the processor 1401 is located.
[0289] Optionally, the communication device 1400 may further include a bus, and various parts of the communication device 1400 may be interconnected via the bus.
[0290] In some embodiments, in terms of hardware implementation, those skilled in the art may conceive that the communication device 1200 shown in FIG. 12 may take the form of the communication device 1400 shown in FIG. 14 .
[0291] As an example, the functions / implementation process of the processing unit 1210 in FIG12 may be implemented by the processor 1401 in the communication device 1400 shown in FIG14 calling computer-executable instructions stored in the memory 1403. The functions / implementation process of the communication unit 1220 in FIG12 may be implemented by the communication interface 1402 in the communication device 1400 shown in FIG14.
[0292] It should be noted that the structure shown in FIG14 does not constitute a specific limitation on the terminal device or network device. For example, in other embodiments of the present application, the terminal device or network device may include more or fewer components than shown, or combine or split certain components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0293] When the communication device is a chip used in a terminal, the terminal chip implements the functions of the terminal in the above method embodiments. The terminal chip receives information from other modules in the terminal (such as a radio frequency module or antenna), and the information is sent by the base station to the terminal; or the terminal chip sends information to other modules in the terminal (such as a radio frequency module or antenna), and the information is sent by the terminal to the base station.
[0294] When the above-mentioned communication device is a module applied to a base station, the base station module implements the functions of the base station in the above-mentioned method embodiment. The base station module receives information from other modules in the base station (such as a radio frequency module or an antenna), and the information is sent by the terminal to the base station; or the base station module sends information to other modules in the base station (such as a radio frequency module or an antenna), and the information is sent by the base station to the terminal. The base station module here can be the baseband chip of the base station, or it can be a DU or other module. The DU here can be a DU under the open radio access network (O-RAN) architecture.
[0295] It is understood that the processor in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0296] The method steps in the embodiments of the present application can be implemented by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, and the software modules can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a CD-ROM or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a base station or a terminal. Of course, the processor and the storage medium can also exist in a base station or a terminal as discrete components.
[0297] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are performed in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or nonvolatile storage medium, or may include both volatile and nonvolatile types of storage media.
[0298] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0299] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, optical storage, etc.) that contain computer-usable program code.
[0300] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each flow and / or box in the flow chart and / or block diagram, as well as the combination of the flow chart and / or box in the flow chart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more flow charts and / or one or more boxes in the block diagram.
[0301] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0302] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include these modifications and variations.
Claims
1. A communication method, characterized in that, including: receiving a first reference signal from a network device; determining a first channel key according to the first reference signal; the first channel key is used for encrypting and / or integrity protecting messages sent before the start of the security mode; sending a first message; the first message is encrypted and / or integrity protected using the first channel key, and the first message includes identification information of the terminal device.
2. The method according to claim 1, wherein The method further includes: receiving first information from the network device; the first information is used to indicate a first resource; sending a second reference signal and first correction information through the first resource; the first correction information is determined according to the first channel key, the second reference signal is used to determine a second channel key, and the first correction information is used to correct the second channel key.
3. The method according to claim 2, wherein The first information is located in a system information block SIB, or the first information is located in a random access response RAR message in a random access process, or the first information is located in a second message.
4. The method according to claim 1, characterized in that The method further includes: receiving second correction information from the network device; the second correction information is used to correct the first channel key; correcting the first channel key according to the second correction information to obtain the corrected first channel key; the corrected first channel key is used for encrypting and / or integrity protecting messages sent before the start of the security mode.
5. The method according to any one of claims 1 to 4, characterized in that The determining the first channel key according to the first reference signal includes: determining a first channel measurement result according to the first reference signal; determining a value of a first channel characteristic parameter according to the first channel measurement result; determining the first channel key according to the value of the first channel characteristic parameter and a first channel key generation algorithm.
6. The method according to claim 5, wherein The method further includes: receiving the system information block SIB or the second message from the network device, the system information block SIB or the second message includes at least one of the following: a list of channel characteristic parameters, the list of channel characteristic parameters includes at least one channel characteristic parameter; a list of channel key generation algorithms, the list of channel key generation algorithms includes at least one channel key generation algorithm.
7. The method according to claim 6, characterized in that, The method further includes: sending second information, the second information is used to indicate at least one of the following: the first channel characteristic parameter; the first channel key generation algorithm.
8. The method according to any one of claims 1 to 7, characterized in that The algorithm for encrypting the first message is a first encryption algorithm, and the algorithm for integrity protecting the first message is a first integrity protection algorithm. The input parameters of the first encryption algorithm and the first integrity protection algorithm include the first channel key; the method further includes: receiving the system information block SIB or the second message from the network device, the system information block SIB or the second message includes at least one of the following: a list of first encryption algorithms, the list of first encryption algorithms includes at least one encryption algorithm; a list of first integrity protection algorithms, the list of first integrity protection algorithms includes at least one integrity protection algorithm.
9. The method according to claim 8, wherein The method further includes: sending third information, the third information is used to indicate at least one of the following: The first encryption algorithm The first integrity protection algorithm 10. The method according to any one of claims 1 to 7, characterized in that, The algorithm for encrypting the first message is the first encryption algorithm, and the algorithm for integrity protecting the first message is the first integrity protection algorithm. The input parameters of the first encryption algorithm and the first integrity protection algorithm include the first channel key. The method further includes: Sending a third message, where the third message includes at least one of the following: A second encryption algorithm list, where the second encryption algorithm list includes at least one encryption algorithm, and the at least one encryption algorithm includes the first encryption algorithm A second integrity protection algorithm list, where the second integrity protection algorithm list includes at least one integrity protection algorithm, and the at least one integrity protection algorithm includes the first integrity protection algorithm 11. The method according to claim 10, wherein The method further includes: Receiving fourth information from the network device, where the fourth information is used to indicate at least one of the following: The first encryption algorithm The first integrity protection algorithm 12. The method according to any one of claims 1 to 11, characterized in that, The first message is a Radio Resource Control (RRC) Setup Complete message, or an RRC Resume Complete message, or an RRC Reestablishment Complete message 13. The method according to any one of claims 3, 6, and 8, characterized in that, The second message is an RRC Setup message, or an RRC Resume message, or an RRC Reestablishment message 14. The method according to claim 10, wherein The third message is an RRC Setup Request message, or an RRC Resume Request message, or an RRC Reestablishment Request message 15. A communication method, characterized in that, Including: Receiving a second reference signal from the terminal device Determining a second channel key according to the second reference signal The second channel key is used to encrypt and / or integrity protect the messages sent before the start of the security mode Receiving a first message from the terminal device, where the first message includes the identification information of the terminal device Decrypting and / or integrity verifying the first message according to the second channel key 16. The method according to claim 15, wherein The method further includes: Receiving first correction information from the terminal device; the first correction information is used to correct the second channel key Correcting the first channel key according to the first correction information to obtain the corrected second channel key; the corrected second channel key is used to encrypt and / or integrity protect the messages sent before the start of the security mode 17. The method according to claim 15, wherein The method further includes: Sending a first reference signal and second correction information; the second correction information is determined according to the second channel key, the first reference signal is used to determine a first channel key, and the second correction information is used to correct the first channel key 18. The method according to any one of claims 15 to 17, characterized in that The determining the second channel key according to the second reference signal includes: Determine a second channel measurement result according to the second reference signal; Determine a value of a first channel characteristic parameter according to the second channel measurement result; Determine the second channel key according to the value of the first channel characteristic parameter and a first channel key generation algorithm.
19. The method according to claim 18, characterized in that, The method further includes: Transmit a system information block SIB or a second message, where the system information block SIB or the second message includes at least one of the following: A list of channel characteristic parameters, where the list of channel characteristic parameters includes at least one channel characteristic parameter; A list of channel key generation algorithms, where the list of channel key generation algorithms includes at least one channel key generation algorithm.
20. The method according to claim 19, wherein The method further includes: Receive second information from the terminal device, where the second information is used to indicate at least one of the following: The first channel characteristic parameter; The first channel key generation algorithm.
21. The method according to any one of claims 15 to 18, characterized in that, The algorithm for encrypting the first message is a first encryption algorithm, and the algorithm for integrity protecting the first message is a first integrity protection algorithm. The input parameters of the first encryption algorithm and the first integrity protection algorithm include the first channel key; the method further includes: Transmit a system information block SIB or a second message, where the system information block SIB or the second message includes at least one of the following: A list of first encryption algorithms, where the list of first encryption algorithms includes at least one encryption algorithm; A list of first integrity protection algorithms, where the list of first integrity protection algorithms includes at least one integrity protection algorithm.
22. The method according to any one of claims 15 to 20, characterized in that The algorithm for encrypting the first message is a first encryption algorithm, and the algorithm for integrity protecting the first message is a first integrity protection algorithm. The input parameters of the first encryption algorithm and the first integrity protection algorithm include the first channel key; the method further includes: Receive a third message from the terminal device, where the third message includes at least one of the following: A list of second encryption algorithms, where the list of second encryption algorithms includes at least one encryption algorithm, and the at least one encryption algorithm includes the first encryption algorithm; A list of second integrity protection algorithms, where the list of second integrity protection algorithms includes at least one integrity protection algorithm, and the at least one integrity protection algorithm includes the first integrity protection algorithm.
23. A communication device, characterized in that, Includes: A communication unit, configured to receive a first reference signal from a network device; A processing unit, configured to determine a first channel key according to the first reference signal; The first channel key is used to encrypt and / or perform integrity protection on a message sent before the start of the security mode; The communication unit, configured to send a first message; The first message is encrypted and / or integrity protected using the first channel key, and the first message includes identification information of the terminal device.
24. A communication device, characterized in that, Includes: A communication unit, configured to receive a second reference signal from the terminal device; A processing unit, configured to determine a second channel key according to the second reference signal; The second channel key is used to encrypt and / or perform integrity protection on a message sent before the start of the security mode; The communication unit, configured to receive the first message from the terminal device, where the first message includes identification information of the terminal device; The processing unit is configured to decrypt and / or perform integrity verification on the first message according to the second channel key.
25. A communication device, characterized in that, Comprising a processor; The processor is configured to execute the computer program or instruction stored in the memory, so that the communication device implements the method according to any one of claims 1 to 22.
26. A computer-readable storage medium, characterized in that, Stored with a computer program or instruction, when the computer program or instruction runs on a computer, the computer implements the method according to any one of claims 1 to 22.
27. A chip or chip system, characterized in that, Comprising a processor, the processor is coupled to the memory and is configured to execute the computer program or instruction stored in the memory, so that the chip implements the method according to any one of claims 1 to 22.
28. A computer program product, characterized in that, When the computer reads and executes the computer program product, the method according to any one of claims 1 to 22 is executed.
Citation Information
Patent Citations
Physical layer key generation method, electronic equipment and storage medium
CN112073965A
Encryption method and device based on channel secret key
CN116866900A
Method, apparatus and system for physical channel encryption in wireless network
CN117136573A
Techniques for secret key extraction during an access procedure
WO2023219714A1