Signal verification method and apparatus

By adding a verification signal to the PRS signal and using the time domain position relationship to detect the playback attack, the problem of unauthorized users interfering with the positioning results is solved, low-complexity attack protection is achieved, and the positioning accuracy is maintained.

WO2025152796A1PCT designated stage expired Publication Date: 2025-07-24HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/070493
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-15
Filing Date
2025-01-03
Publication Date
2025-07-24

AI Technical Summary

Technical Problem

In high-precision downlink positioning scenarios, unauthorized users use the periodic replay attacks of PRS signals to interfere with the positioning results of legitimate devices. The prior art encryption or time-hop/frequency hopping methods affect positioning accuracy or increase system complexity.

Method used

Without changing the PRS signal sequence or periodicity, the playback attack is detected using the time domain position relationship between the reference signal and the check signal, including generating the check signal and configuration information to indicate the time domain position, so as to realize the detection of the playback attack.

Benefits of technology

Without affecting the positioning accuracy and system complexity, unauthorized users are effectively prevented from interfering with the positioning results of legitimate devices, realizing low-complexity attack detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025070493_24072025_PF_FP_ABST
    Figure CN2025070493_24072025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present application are a signal verification method and apparatus. In the method, while not changing the sequence or the periodic characteristic of an original reference signal, i.e., not affecting the positioning accuracy of a system, replay attack detection is realized by means of adding a first verification signal, such that when a first reference signal is subjected to a replay attack, a first apparatus can detect the attack on the basis of a time-domain position relationship between the first reference signal and the first verification signal, thereby rejecting a positioning measurement result. In this way, the interference from an unauthorized user to a positioning result of a legitimate device can be prevented without the need for additional devices, the implementation complexity is relatively low, and the positioning accuracy of a legitimate user is not affected.
Need to check novelty before this filing date? Find Prior Art

Description

Signal verification method and device

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 15, 2024, with application number 202410056794.7 and application name “Method and Device for Signal Verification”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of communication technology, and in particular to a signal verification method and device. Background Art

[0003] Positioning technology is an important part of communication and perception integration. In high-precision downlink positioning scenarios, the positioning technology used in New Radio (NR) systems is based on the measurement of the downlink positioning reference signal (DL PRS).

[0004] However, the PRS signal is periodic. Unauthorized users can exploit the periodicity of the PRS signal using the autocorrelation method to obtain the PRS sequence and perform a replay attack, thereby interfering with the positioning results of legitimate devices.

[0005] Prior art methods typically encrypt PRS signals or employ time-hopping or frequency-hopping to randomize or alter the periodicity of the PRS sequence, preventing unauthorized users from obtaining the PRS through autocorrelation and performing replay attacks. However, encrypted PRS signals degrade their autocorrelation characteristics, affecting positioning accuracy. Using time-hopping or frequency-hopping also increases system complexity. Summary of the Invention

[0006] The embodiments of the present application provide a signal verification method and apparatus, which can prevent unauthorized users from interfering with the positioning results of legitimate devices without affecting positioning accuracy and system complexity.

[0007] In a first aspect, a signal verification method is provided. The method can be performed by a first device, which can be a terminal, a device including a terminal, or a chip or logic module in a terminal. The first device can also be a network device, a device including a network device, or a chip or logic module in a network device. For ease of description, the following description takes the method of the first aspect performed by the first device as an example. The method includes: receiving a first reference signal and a first verification signal from a second device. Based on the time domain position relationship between the first reference signal and the first verification signal, determining whether the first reference signal is a second reference signal from the second device. Sending first information to the second device, the first information is used to indicate whether the first reference signal is a second reference signal, and the second reference signal is used by the second device to locate the first device.

[0008] Based on the method of the first aspect, it can be seen that without changing the sequence or periodic characteristics of the original reference signal, that is, without affecting the system positioning accuracy, the detection of replay attacks is achieved by adding a first verification signal, so that when the first reference signal is subjected to a replay attack, the first device can detect the attack based on the time domain position relationship between the first reference signal and the first verification signal, thereby rejecting the positioning measurement results. In this way, unauthorized users can be prevented from interfering with the positioning results of legitimate devices without the participation of additional equipment, the implementation complexity is low, and the positioning accuracy of legitimate users is not affected.

[0009] In one possible implementation, determining whether the first reference signal is the second reference signal from the second device based on the time domain position relationship between the first reference signal and the first verification signal may include: determining whether the first reference signal is the second reference signal from the second device based on the time domain position relationship between the first reference signal and the first verification signal, and the time domain position relationship between the fourth reference signal and the second verification signal, wherein the fourth reference signal and the second verification signal are determined by the terminal.

[0010] Optionally, determining whether the first reference signal is the second reference signal from the second device based on the time domain position relationship between the first reference signal and the first verification signal, and the time domain position relationship between the fourth reference signal and the second verification signal, may include: determining a first offset, where the first offset may be the offset between the time domain position of the first reference signal and the time domain position of the first verification signal, and determining whether the first reference signal is the second reference signal from the second device based on matching the first offset with the second offset. The second offset is the offset between the time domain position of the fourth reference signal and the time domain position of the second verification signal.

[0011] It is understood that the fourth reference signal and the second verification signal can be accurate signals generated by the terminal, that is, they have not been interfered with by unauthorized users. If the first reference signal received by the terminal has not been attacked by unauthorized users, the time domain position relationship between the first reference signal and the first verification signal should match the time domain position relationship between the fourth reference signal and the second verification signal. Therefore, the fourth reference signal, the second verification signal, and the first verification signal can be used to verify whether the first reference signal originates from the second device. In this way, unauthorized users can be prevented from interfering with the positioning results of legitimate devices without affecting the positioning accuracy of the system, and the implementation complexity is relatively low.

[0012] In one possible implementation, the first reference signal and the first verification signal are included in a first signal frame. The signal verification method may further include: determining a first correlation peak based on the second verification signal and the signal received in the first signal frame, where the time domain position of the first correlation peak is the time domain position of the first verification signal. Determining a second correlation peak based on the fourth reference signal and the signal received in the first signal frame, where the time domain position of the second correlation peak is the time domain position of the first reference signal.

[0013] It can be understood that since the correlation peak can only be generated by performing correlation operations on two close or identical signals, the second reference signal and the second verification signal generated locally by the terminal are respectively correlated with the received first signal frame, and the time domain position where the correlation peak appears is the time domain position of the received first reference signal and the first verification signal. Therefore, whether the verification is passed is judged based on the time domain position relationship. In this way, the time domain position of the first reference signal and the first verification signal can be accurately located.

[0014] In addition, since the reference signal and the check signal are both contained in the same signal frame, the correlation operation can be performed with a single signal frame as the granularity, such as performing the correlation operation within one signal frame instead of multiple signal frames, which can reduce the operation overhead.

[0015] Optionally, the time domain position of the fourth reference signal and the time domain position of the second check signal are indicated by configuration information, and the configuration information is used to indicate the generation of the fourth reference signal and the second check signal. The configuration information is used to indicate that the second signal frame includes multiple fourth reference signals and second check signals, and the third offset of the time domain position between each two fourth reference signals in the second signal frame is the same. The offset of the time domain position between the second check signal and the fourth reference signal adjacent to the second check signal is the fourth offset, and the fourth offset is different from the third offset, or the fourth offset is the same as the third offset.

[0016] It can be understood that the configuration information can be a parameter related to the reference signal configuration, which can include the time domain position of the fourth reference signal and the time domain position of the second check signal. The configuration information indicates that the second signal frame has two frame structures. If the fourth offset is the same as the third offset, and the second check signal occupies a time domain position for placing the fourth reference signal, the existing frame structure is used for implementation, that is, the frame structure defined by the current standard is not changed, the change to the standard is smaller, more friendly, and the implementation is relatively simple. If the fourth offset is different from the third offset, that is, the second check signal is placed in the time domain position between the two fourth reference signals, the flexibility of placing the check signal is improved.

[0017] In a possible implementation, the signal verification method may further include: receiving configuration information, and generating a second reference signal and a second verification signal according to the configuration information.

[0018] Optionally, the configuration information may include an encryption key, and the first bit sequence is encrypted using the encryption key to obtain an encrypted first bit sequence. The encrypted first bit sequence is modulated to obtain a second symbol for the verification signal. The second symbol is mapped to the time domain position of the verification signal indicated by the configuration information to obtain a second verification signal. It is understood that the encryption key may be a key shared by the first device and the second device, and the encryption here may be randomized encryption. The first bit sequence encrypted with the encryption key is random and unpredictable, making it impossible for unauthorized users to discover / predict the verification signal, thereby preventing replay attacks.

[0019] Optionally, the signal verification method may further include: encrypting the second bit sequence according to an encryption key to obtain an encrypted second bit sequence. XORing the encrypted second bit sequence with the first bit sequence to obtain an encrypted first bit sequence. It is understood that the encrypted second bit sequence is XORed with the first bit sequence and then subjected to a hash function to obtain the encrypted first bit sequence. It is understood that the use of an irreversible hash function prevents unauthorized users from obtaining the encrypted second bit sequence by intercepting the encrypted first bit sequence, thereby ensuring the unpredictability of the verification signal and preventing replay attacks.

[0020] In one possible implementation, the signal verification method may further include performing ranging based on the first reference signal and the second reference signal to obtain a ranging result. If the first reference signal is the second reference signal from the second device, the ranging result is transmitted. It is understood that the ranging result may be transmitted upon determining that the first reference signal is the second reference signal from the second device. This ranging result, which has not been compromised by unauthorized users, can provide more accurate positioning.

[0021] In one possible implementation, the signal verification method may also include: sending a first information to the positioning management function LMF network element, so that the network side can know that the positioning of the terminal has not been interfered with by unauthorized users. Only in this way will the network side subsequently perform mobility management on the terminal to avoid the network performing mobility management on the terminal when the positioning of the terminal is interfered with by unauthorized users, thereby wasting network resources.

[0022] In a second aspect, a signal verification method is provided. The method can be performed by a first device, which can be a terminal, a device including a terminal, or a chip or logic module within a terminal. The first device can also be a network device, a device including a network device, or a chip or logic module within a network device. For ease of description, the following description uses the method of the first aspect performed by the first device as an example. The method can include: receiving a first reference signal, determining a first time domain location based on the first reference signal, a fourth reference signal, and a second verification signal, and then acquiring the first signal at the first time domain location. Based on the first signal and the second verification signal, determining whether the first reference signal is a second reference signal from a second device, the second reference signal being used by the second device to locate the first device, and the fourth reference signal and the second verification signal being determined by the first device. Sending first information to the second device, the first information being used to indicate whether the first reference signal is the second reference signal from the second device.

[0023] Based on the method described in the second aspect, it can be known that when the time domain position relationship between the first signal received by the first device and the first reference signal matches the time domain position relationship between the local fourth reference signal and the second verification signal, it can be determined that the first reference signal is the second reference signal from the second device. Therefore, by obtaining the first signal through the time domain position relationship and comparing the received first signal with the local second verification signal, it is possible to detect whether the system has been attacked by an unauthorized user. In this way, unauthorized users can be prevented from interfering with the positioning results of legitimate devices without the participation of additional equipment, with low implementation complexity and without affecting the positioning accuracy of legitimate users.

[0024] In one possible implementation, the first time domain position is the time domain position of the first reference signal followed by the second offset, and the second offset is the offset between the time domain position of the fourth reference signal and the time domain position of the second check signal.

[0025] Optionally, whether the first reference signal is a third reference signal from the second device is determined based on whether the first signal matches the first verification signal.

[0026] It can be understood that if the first reference signal received by the first device is not attacked by an unauthorized user, the time domain position relationship between the local fourth reference signal and the second verification signal should match the time domain position relationship between the received first reference signal and the first signal, so that the first signal can be received through the second offset between the time domain positions of the local fourth reference signal and the second verification signal, and then by comparing whether the received first signal and the local second verification signal are consistent, it can be detected whether the system has been attacked, and the implementation complexity is relatively low.

[0027] Optionally, obtaining the first signal at the first time domain position may include: obtaining a first symbol for verifying the signal at the first time domain position. Demodulating the first symbol according to the symbol for demodulating the signal to obtain the first signal. It is understandable that the symbol for demodulating the signal may be a demodulation reference signal (DMRS), and the second device may map the symbol for demodulating the signal to the time-frequency resource corresponding to the verification signal on the second device side in advance, so that the terminal can demodulate the received first symbol into the first signal based on the symbol for demodulating the signal, and then compare it with the local second verification signal to ensure the accuracy of the verification result.

[0028] Optionally, the time domain position of the fourth reference signal and the time domain position of the second check signal are indicated by configuration information, and the configuration information is used to instruct generation of the fourth reference signal and the second check signal.

[0029] In which, the configuration information is used to indicate that the second signal frame includes multiple fourth reference signals and second verification signals, and the third offset of the time domain position between each two fourth reference signals in the second signal frame is the same; the offset of the time domain position between the second verification signal and the fourth reference signal adjacent to the second verification signal is the fourth offset, the fourth offset is different from the third offset, or the fourth offset is the same as the third offset.

[0030] In a possible implementation, the signal verification method may further include: receiving configuration information, and generating a fourth reference signal and a second verification signal according to the configuration information.

[0031] Optionally, the configuration information may include an encryption key. The first bit sequence is encrypted according to the encryption key to obtain an encrypted first bit sequence. The encrypted first bit sequence is modulated to obtain a second symbol for the verification signal. The second symbol is mapped to a time domain position of the verification signal to obtain a second verification signal.

[0032] Optionally, the signal verification method may further include: encrypting the second bit sequence according to the encryption key to obtain an encrypted second bit sequence, performing an XOR operation on the encrypted second bit sequence and the first bit sequence, and then performing a hash function to obtain an encrypted first bit sequence.

[0033] Optionally, the second symbol and the symbol used for the demodulation signal are mapped to a time domain position of the check signal to obtain a second check signal.

[0034] In a possible implementation, the signal verification method may further include: when the first reference signal is a second reference signal from a second device, sending a ranging result, where the ranging result is obtained based on the first reference signal and a fourth reference signal.

[0035] In one possible implementation, the signal verification method may further include: sending first information to a positioning management function LMF network element.

[0036] It can be understood that the relevant technical effects of the method of the second aspect mentioned above can also refer to the relevant introduction of the first aspect mentioned above, and will not be repeated here.

[0037] In a third aspect, a signal verification method is provided. The method can be performed by a second device. The second device can be a network device, a device including the network device, or a chip or logic module within the network device. In the future, the second device can also be a terminal. For ease of description, the following description uses the method of the third aspect performed by the second device as an example. The method includes: the second device sending a reference signal and a first verification signal to a first device, wherein the first verification signal is used to verify whether the reference signal received by the terminal is the first reference signal from the second device; and the second device receiving first information from the first device, wherein the first information is used to indicate whether the reference signal received by the first device is the first reference signal from the second device.

[0038] In one possible implementation, before sending the first reference signal and the first verification signal to the terminal, the signal verification method may further include:

[0039] The second device obtains configuration information, where the configuration information is used to instruct the generation of a reference signal and a verification signal;

[0040] The second device sends configuration information to the first device.

[0041] Optionally, the second device receives configuration information from the LMF network element, or determines configuration information.

[0042] In a possible implementation, the signal verification method may further include: the second device determines the first reference signal and the first verification signal according to the configuration information.

[0043] It can be understood that the relevant technical effects of the method of the third aspect mentioned above can also refer to the relevant introduction of the first aspect mentioned above, and will not be repeated here.

[0044] In a fourth aspect, a signal verification method is provided, which can be used for an LMF network element. The method may include: receiving first information from a first device or a second device, the first information being used to indicate whether a reference signal received by the first device comes from the second device.

[0045] In a possible implementation, the signal verification method may further include: sending configuration information to the second device, where the configuration information is used to instruct generation of a reference signal and a verification signal.

[0046] In a possible implementation, the signal verification method may further include: sending configuration information to the second device and the first device.

[0047] It can be understood that the relevant technical effects of the method of the fourth aspect mentioned above can also refer to the relevant introduction of the first aspect mentioned above, and will not be repeated here.

[0048] In a fifth aspect, a communication device is provided. The communication device includes: a module for executing the method described in any one of aspects 1 to 4, such as a transceiver module and a processing module. For example, the transceiver module is configured to indicate the transceiver function of the communication device, and the processing module is configured to perform functions of the communication device other than the transceiver function.

[0049] Optionally, the transceiver module may include a sending module and a receiving module, wherein the sending module is used to implement the sending function of the communication device described in the fifth aspect, and the receiving module is used to implement the receiving function of the communication device described in the fifth aspect.

[0050] Optionally, the communication device described in the fifth aspect may further include a storage module, wherein the storage module stores a program or instruction. When the processing module executes the program or instruction, the communication device can execute the method described in any one of the first to fourth aspects.

[0051] It can be understood that the communication device described in the fifth aspect can be a terminal or a network device, or a chip (system) or other parts or components that can be set in a terminal or a network device, or a device that includes a terminal or a network device. This application does not limit this.

[0052] In addition, the technical effects of the communication device described in the fifth aspect can refer to the technical effects of the first aspect mentioned above, and will not be repeated here.

[0053] In a sixth aspect, a communication device is provided, comprising: a processor configured to execute the method described in any one of the first to fourth aspects.

[0054] In one possible implementation, the communication device described in the sixth aspect may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device described in the sixth aspect to communicate with other communication devices.

[0055] In one possible implementation, the communication device described in aspect 6 may further include a memory. The memory may be integrated with the processor or provided separately. The memory may be used to store the computer program and / or data involved in the method described in any one of aspects 1 to 4.

[0056] In an embodiment of the present application, the communication device described in the sixth aspect may be the first device or the second device described in any one of the first to fourth aspects, or a chip (system) or other parts or components that may be provided in the first device or the second device, or a device that includes the first device or the second device.

[0057] In addition, the technical effects of the communication device described in the sixth aspect can refer to the technical effects of the methods described in any one of the first to fourth aspects, and will not be repeated here.

[0058] In a seventh aspect, a communication device is provided, comprising: a processor coupled to a memory, the processor configured to execute a computer program or instruction stored in the memory, so that the communication device performs the method described in any one of the first to fourth aspects.

[0059] In one possible implementation, the communication device may further include a transceiver. The transceiver may be a transceiver circuit or an interface circuit. The transceiver may be used for the communication device to communicate with other communication devices.

[0060] In a possible implementation, the communication device further includes the memory for storing the above-mentioned computer program or instruction. Optionally, the memory and the processor are integrated together.

[0061] In an embodiment of the present application, the communication device described in the seventh aspect may be the first device or the second device described in any one of the first to fourth aspects, or a chip (system) or other parts or components that may be provided in the first device or the second device, or a device that includes the first device or the second device.

[0062] In addition, the technical effects of the communication device described in the seventh aspect can refer to the technical effects of the methods described in any one of the first to fourth aspects, and will not be repeated here.

[0063] In an eighth aspect, a communication system is provided, comprising: a first device for executing the method according to the first aspect or the second aspect, and a second device for executing the method according to the third aspect.

[0064] In a ninth aspect, a computer-readable storage medium is provided, comprising: a computer program or instructions; when the computer program or instructions are executed on a computer, the method described in any one of the first to fourth aspects above is implemented.

[0065] In a tenth aspect, a computer program product is provided, comprising a computer program or instructions, which, when executed on a computer, enables the method described in any one of the first to fourth aspects to be implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] Figure 1 is a schematic diagram of the comb distribution of PRS time-frequency resources;

[0067] Figure 2 is a schematic diagram of PRS parameters;

[0068] FIG3 is a schematic diagram of an unauthorized user detecting a signal at a transmission location;

[0069] FIG4 is a schematic diagram of correlation peaks showing a successful attack by an unauthorized user;

[0070] Figure 5 is a schematic diagram of a replay attack on PRS;

[0071] Figure 6 is a schematic diagram of the replay attack results of PRS;

[0072] Figure 7(a) and Figure 7(b) are schematic diagrams of time hopping resource selection for PRS;

[0073] FIG8 is a first structural diagram of a communication system provided in an embodiment of the present application;

[0074] FIG9 is a second structural diagram of a communication system provided in an embodiment of the present application;

[0075] FIG10 is a schematic diagram of an application scenario of a communication system provided in an embodiment of the present application;

[0076] FIG11 is a schematic diagram 1 of a signal verification process according to an embodiment of the present application;

[0077] FIG12 is a first structural diagram of a PRS signal frame provided in an embodiment of the present application;

[0078] FIG13 is a second structural diagram of a PRS signal frame provided in an embodiment of the present application;

[0079] FIG14 is a schematic diagram of attack detection of PRS 1;

[0080] Figure 15 is a second diagram of attack detection of PRS;

[0081] FIG16 is a first schematic diagram of a flow chart of generating a verification signal according to an embodiment of the present application;

[0082] FIG17 is a second schematic diagram of a flow chart for generating a verification signal according to an embodiment of the present application;

[0083] FIG18 is a first schematic diagram of a comb distribution of a verification signal provided in an embodiment of the present application;

[0084] FIG19 is a second schematic diagram of a signal verification process according to an embodiment of the present application;

[0085] FIG20 is a second schematic diagram of comb distribution of a verification signal provided in an embodiment of the present application;

[0086] FIG21 is a third schematic diagram of a signal verification process according to an embodiment of the present application;

[0087] FIG22 is a first structural diagram of a communication device provided in an embodiment of the present application;

[0088] FIG23 is a second structural diagram of the communication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0089] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless network (Wi-Fi) systems, vehicle to everything (V2X) communication systems, device-to-device (D2D) communication systems, Internet of Vehicles communication systems, fourth-generation (4G) mobile communication systems, such as long-term evolution (LTE) systems, fifth-generation (5G) systems, such as new radio (NR) systems, and communication systems evolved after 5G, such as 6G.

[0090] The following first introduces the technical terms involved in this application.

[0091] 1. Positioning technology

[0092] Positioning technology is one of the important aspects of communication perception integration, and its purpose is to locate another device in a secure manner through wireless devices. The 3rd Generation Partnership Project (3GPP) defines a new downlink reference signal (DL PRS). DL PRS is used in the radio access technology (RAT)-dependent positioning service of the NR system. Here, RAT-dependent refers to the fact that the implementation of the bit depends on the 5G mobile communication system network. In the high-precision downlink positioning scenario, the positioning technologies used in the NR system, such as downlink time difference of arrival (DL-TDOA) technology, downlink angle of departure (DL-AoD) technology, and multi-round trip time (Multi-RTT) technology, are all based on the signal measurement of DL PRS. Therefore, the signal protection of PRS is crucial.

[0093] 2. PRS

[0094] The bit sequence of PRS is defined by a set of 31-bit Gold sequences, which are pseudo-random sequences with good characteristics. Its initialization sequence is:

[0095] Among them, the initialization parameters These are all unencrypted parameters sent from the high-level core network. It can be a serial identification number (identity, ID) issued by the upper layer, and It can be a parameter related to the time-frequency domain position of sequence mapping.

[0096] The PRS bit sequence is modulated by quadrature phase-shift keying (QPSK) to generate the final PRS sequence:

[0097] When the base station (BS) transmits the PRS through the antenna, it also needs to map the PRS to the corresponding time-frequency resources, which can be called the PRS pattern. As shown in Figure 1, the PRS is often arranged in a comb-like pattern on the time-frequency resources, where: Indicates the offset of the starting symbol of the PRS relative to symbol 0 in a time slot, L PRSIndicates the number of symbols occupied by the PRS in the time domain. For ease of explanation, the comb-shaped PRS signal is referred to as the PRS, the time-frequency block on the time-frequency resource (the shaded area in Figure 1) is referred to as the PRS symbol, and the initially generated Gold sequence of the PRS is referred to as the PRS bit sequence.

[0098] The BS periodically sends PRS to provide downlink timing services for user equipment (UE). The BS determines the period for sending PRS and the offset in time relative to the initial position based on the parameters sent by the high-layer encryption. The parameters may include the period of the PRS signal (dl-PRS-Periodicity) and the offset in time relative to the initial position of the PRS signal (dl-PRS-Resource Slot Offset). For example, as shown in Figure 2, a PRS signal set consists of 10 time slots, and the PRS signal set is repeatedly sent. The 10 time slots here are the period for sending PRS in the parameters. The signal set contains two PRS signals #1, that is, the repetition coefficient of PRS signal #1 is 2, and the time slot offset between the two signals is 2. The offset of PRS signal #1 relative to the initial position is 3, which includes the offset of 2 from the initial position set by the system for the PRS signal and the initial offset of 1 for PRS signal #1 in the parameters. Here, initial offset 1 for PRS signal #1 can be the offset of PRS signal #1 relative to the first position, which is the position of the PRS signal offset by 2 time slots relative to the initial position. It can be seen that the BS sends the PRS signal using the PRS signal period and PRS signal offset parameters sent by the higher layer.

[0099] 3. PRS security vulnerabilities

[0100] As can be seen from the above introduction to PRS, PRS is a set of reference signals that provide downlink positioning services. The PRS generation parameters are public, and the PRS repetition period, transmission time, and transmission location are encrypted. However, due to the periodicity of PRS, the received PRS signal exhibits strong autocorrelation over time. Unauthorized users can exploit this periodicity to obtain the PRS sequence through autocorrelation attacks, thereby attacking the PRS signal through replay attacks and other means, thereby interfering with the positioning results of legitimate devices.

[0101] The following describes the steps for an unauthorized user to perform a PRS replay attack using the examples shown in Figures 3 to 6:

[0102] Step 1: As shown in Figure 3, the PRS indication information is contained in the Positioning System Information Block (posSIB). The network-side BS encrypts and transmits the posSIB to the UE using the Advanced Encryption Standard (AES) algorithm, maps the posSIB to the corresponding system information (SI), and sends it to the UE via a wireless channel. Because the posSIB transmission location is public (i.e., the public location corresponds to the SI delivery location), an unauthorized user detecting a signal at a specified location can detect that the BS is about to send a PRS. For example, if an unauthorized user receives and decodes SIB1 at a specified location and obtains a system information message related to the posSIB, it can detect that the BS is about to send a PRS.

[0103] Step 2: The unauthorized user uses two sliding windows of length N, separated by the resource set period T, to intercept the signal sent by the BS. The signals within the two sliding windows are then autocorrelated. This means the two sliding windows of length N are moved across the signal by one sampling point at a time. A correlation is performed with each movement to measure the similarity. A similarity graph is then generated to determine whether a peak has appeared. Figure 4 illustrates a successful unauthorized user attack. As shown in Figure 4, a correlation peak appears, indicating that the unauthorized user has learned the PRS signal length N and repetition period T.

[0104] Step 3: The unauthorized user transmits the intercepted PRS at high power, that is, sends a high-power fake PRS, where the fake PRS may be a PRS processed from the intercepted PRS, thereby interfering with the positioning result of the UE.

[0105] As shown in Figure 5, after detecting the start of PRS transmission, the unauthorized user uses autocorrelation to guess the PRS configuration parameters and transmits a high-power false PRS ahead of the legitimate PRS transmission time, thus initiating a replay attack. Because the UE uses a locally generated PRS to correlate with the received signal during ranging (positioning), the peak of the correlation peak is located at the start of the PRS. The presence of the false PRS confuses the UE receiver's correlation results. As shown in Figure 6, after the unauthorized user launches a replay attack, the peak of the correlation obtained by the UE receiver during the correlation calculation is ahead of the actual PRS signal transmitted by the BS. For example, the correlation peak corresponding to gNB4 in Figure 6 is ahead of time, creating a false correlation peak. This premature correlation peak shortens the UE's measured distance, resulting in incorrect ranging results.

[0106] In view of the above problems, there are two solutions in the prior art, which are introduced below respectively.

[0107] Solution 1: Use PRS encryption to address replay attacks. Specifically, the transmitter randomizes the PRS according to a key agreed upon by both the sender and receiver, preventing unauthorized users from accurately obtaining the PRS and launching replay attacks. However, after encryption, the PRS is no longer a Gold sequence with excellent ranging performance, and its autocorrelation characteristics deteriorate, affecting the positioning accuracy of authorized users.

[0108] Solution 2: Use time or frequency hopping to change the PRS signal's periodic characteristics in time, thereby preventing replay attacks. Specifically, a set of optional time domain offsets (gap) and initial values ​​(offset_initial_i) are defined. The BS / UE calculates the hopping PRS transmission position based on the offset indication (offset_initial_i) transmitted using a key encryption. Since the PRS transmission period is related to positioning services, a large period span will affect positioning services. Therefore, a maximum hopping parameter (max_shift) is defined to limit the range of variation of each PRS transmission. That is, the hopping position of each PRS transmission does not exceed the maximum hopping parameter. For example, as shown in Figures 7(a) and 7(b), if the initial time domain offset is 64, the second hopping can only select the hopping length of the surrounding maximum hopping parameter length. The time domain offset of the second time slot PRS is selected as 20, the time domain offset of the third time slot PRS is selected as 32, and the time domain offset of the fourth time slot PRS is selected as 40, etc. The maximum hopping parameter ensures that time hopping does not jump from a time offset of 64 to a time offset of 10240, significantly impacting legitimate user positioning services. However, time and frequency hopping lead to high system complexity. Furthermore, when the maximum hopping parameter is small, the PRS transmission interval does not vary much, leaving a high probability of attack by unauthorized users.

[0109] In response to the above technical problems, the embodiments of the present application propose the following technical solutions.

[0110] The technical solution in this application will be described below with reference to the accompanying drawings.

[0111] In the embodiment of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information (such as the first indication information, the second indication information, or the third indication information below) is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, where there is an association between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can be achieved by means of the arrangement order of each piece of information agreed in advance (such as specified in the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.

[0112] In addition, the specific indication method can also be various existing indication methods, such as but not limited to the above-mentioned indication methods and various combinations thereof. As can be seen from the above, for example, when it is necessary to indicate multiple pieces of information of the same type, different indication methods may be used for different pieces of information. During the specific implementation process, the desired indication method can be selected according to specific needs. The embodiments of the present application do not limit the selected indication method. As such, the indication methods involved in the embodiments of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0113] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending period and / or sending time of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of this application. Among them, the sending period and / or sending time of these sub-information can be predefined, for example, predefined according to a protocol, or can be configured by the sending node device by sending configuration information to the receiving node device.

[0114] "Pre-definition" or "pre-configuration" can be implemented by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device, and the embodiments of the present application do not limit the specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially set separately and partially integrated in a decoder, a processor, or a communication device. The type of memory can be any form of storage medium, and the embodiments of the present application do not limit this.

[0115] The "protocol" involved in the embodiments of the present application may refer to a protocol family in the communication field, a standard protocol with a similar protocol family frame structure, or a related protocol used in future communication systems. The embodiments of the present application do not make specific limitations on this.

[0116] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device will perform corresponding processing under certain objective circumstances. It does not limit the time, nor does it require the device to perform judgment actions when implemented, nor does it mean that there are other limitations.

[0117] In the description of the embodiments of the present application, unless otherwise specified, " / " indicates that the objects associated with each other are in an "or" relationship. For example, A / B can represent A or B. "And / or" in the embodiments of the present application is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, in the description of the embodiments of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with basically the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or implementation described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or implementations. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.

[0118] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0119] To facilitate understanding of the embodiments of the present application, a communication system applicable to the embodiments of the present application is first described in detail using the communication system shown in Figure 8 as an example. For example, Figure 8 is a schematic diagram of the architecture of a communication system applicable to the method provided in the embodiments of the present application.

[0120] The communication system includes a first device and a second device, wherein the first device may be a terminal or a network device. The second device may be a network device or a terminal. In a specific example, as shown in FIG8 , the communication system mainly includes at least one of the following: a terminal and a network device.

[0121] In one possible scenario, the communication system can be applied to 5G or future 6G communication systems. For example, as shown in FIG9 , the communication system 10 includes a radio access network (RAN) 100, a core network (CN) 200, and the Internet 300. RAN 100 includes at least one RAN node (e.g., 110a and 110b in FIG9 , collectively referred to as 110) and at least one terminal (e.g., 120a-120j in FIG9 , collectively referred to as 120). RAN 100 may also include other RAN nodes, such as wireless relay devices and / or wireless backhaul devices (not shown in FIG9 ). Terminal 120 is wirelessly connected to RAN node 110. RAN node 110 is wirelessly or wiredly connected to core network 200. The core network devices in core network 200 and RAN node 110 in RAN 100 can be separate physical devices, or they can be a single physical device that integrates core network logical functions and radio access network logical functions.

[0122] The RAN 100 may be a 3GPP-related cellular system, such as a 4G or 5G mobile communication system, or a future-oriented evolutionary system (such as a 6G mobile communication system). The RAN 100 may also be an open access network (O-RAN or ORAN), a cloud radio access network (CRAN), or a Wi-Fi system. The RAN 100 may also be a communication system that integrates two or more of the above systems.

[0123] RAN node 110, sometimes also referred to as access network equipment, RAN entity, or access node, constitutes part of the communication system and facilitates wireless access for terminals. Multiple RAN nodes 110 in the communication system 10 can be of the same type or different types. In some scenarios, the roles of RAN node 110 and terminal 120 are relative. For example, network element 120i in Figure 9 can be a helicopter or drone, which can be configured as a mobile base station. For terminal 120j accessing the RAN 100 via network element 120i, network element 120i is a base station; however, for base station 110a, network element 120i is a terminal. RAN node 110 and terminal 120 are sometimes referred to as communication devices. For example, network elements 110a and 110b in Figure 9 can be understood as communication devices with base station functionality, and network elements 120a-120j can be understood as communication devices with terminal functionality.

[0124] In one possible scenario, a RAN node may be a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), a next generation NodeB (gNB), a next generation base station in a 6G mobile communication system, a base station in a future mobile communication system, or an access point (AP) in a Wi-Fi system. A RAN node may be a macro base station (such as 110a in FIG9 ), a micro base station or an indoor station (such as 110b in FIG9 ), a relay node or a donor node, or a wireless controller in a CRAN scenario. Optionally, a RAN node may also be a server, a wearable device, a vehicle or an onboard device. For example, an access network device in vehicle to everything (V2X) technology may be a road side unit (RSU). All or part of the functions of a RAN node in this application may also be implemented by software functions running on hardware, or by virtualized functions instantiated on a platform (such as a cloud platform). A RAN node in this application may also be a logical node, a logical module, or software that can implement all or part of the functions of a RAN node.

[0125] In another possible scenario, multiple RAN nodes collaborate to assist the terminal in achieving wireless access, and different RAN nodes respectively implement part of the functions of the base station. For example, the RAN node can be a centralized unit (CU), a distributed unit (DU), a CU-control plane (CP), a CU-user plane (UP), or a radio unit (RU). The CU and DU can be set separately, or they can be included in the same network element, such as a baseband unit (BBU). The RU can be included in a radio frequency device or radio frequency unit, such as a remote radio unit (RRU), an active antenna unit (AAU), or a remote radio head (RRH).

[0126] In different systems, CU (or CU-CP and CU-UP), DU or RU may also have different names, but those skilled in the art can understand their meanings. For example, in the ORAN system, CU may also be called O-CU (Open CU), DU may also be called O-DU, CU-CP may also be called O-CU-CP, CU-UP may also be called O-CU-UP, and RU may also be called O-RU. For the convenience of description, this application uses CU, CU-CP, CU-UP, DU and RU as examples for description. Any unit of CU (or CU-CP, CU-UP), DU and RU in this application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.

[0127] It is understood that the above-mentioned RAN node can be a newly defined name, and RAN node can also be expressed in different ways, such as access node, network device, wireless access node, etc., without limitation. Unless otherwise specified in this application, network device is used to express it.

[0128] Terminals can also be referred to as terminal devices, user equipment (UE), mobile stations, or mobile terminals. They can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), the Internet of Things (IoT), smart point-of-sale (POS), customer-premises equipment (CPE), virtual reality (VR), augmented reality (AR), industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables (such as smart watches, smart bracelets, pedometers, and smart glasses), smart transportation, and smart cities. Terminals can be mobile phones, tablets, computers with wireless transceiver capabilities, wearable devices, vehicle devices (such as complete vehicle devices, vehicle-mounted modules, vehicle-mounted chips, on-board units (OBUs), or telematics boxes (T-BOXs)), drones, helicopters, airplanes, ships, robots, robotic arms, smart home devices, and satellite terminals. The embodiments of the present application do not limit the device form of the terminal.

[0129] In another possible scenario, the communication system can be applied to communication systems such as WLAN and Wi-Fi. For example, as shown in Figure 10, the network device may include an access point, and the terminal may include a station device (STA). Of course, the above device form is only an example. The embodiment of the present application does not limit the specific device form of the terminal and the network device. Any device that can be applied to the solution proposed in this application can be understood as the terminal and network device in this application.

[0130] In this communication system, without changing the sequence or periodic characteristics of the original reference signal, that is, without affecting the system positioning accuracy, the detection of replay attacks is achieved by adding a first verification signal, so that when the first reference signal is subjected to a replay attack, the first device can detect the attack based on the time domain position relationship between the first reference signal and the first verification signal, thereby rejecting the positioning measurement result. In this way, unauthorized users can be prevented from interfering with the positioning results of legitimate devices without the participation of additional equipment, the implementation complexity is low, and the positioning accuracy of legitimate users is not affected.

[0131] The embodiments of this application do not limit the device form factor of the network device. The device used to implement the function of the network device can be a network device; it can also be a device that supports the network device to implement the function, such as a chip system. The device can be installed in the network device or used in conjunction with the network device. In the embodiments of this application, the chip system can be composed of chips or can include chips and other discrete components.

[0132] The following will be combined with Figure 11 to specifically describe the interaction process between each network element / device in the above communication system through a method embodiment. The signal verification method provided in the embodiment of the present application can be applied to the above communication system and specifically applied to the various scenarios / processes mentioned in the above communication system, which are described in detail below.

[0133] Figure 11 is a flow chart of a signal verification method provided in an embodiment of the present application. The signal verification method is applicable to the above-mentioned communication system, and mainly involves the interaction between the first device and the second device.

[0134] As shown in FIG11 , the flow of the signal verification method is as follows:

[0135] S1101: A second device sends a second reference signal and a first verification signal to a first device. The first device receives the first reference signal and the first verification signal from the second device.

[0136] The first device may be a terminal, and the second device may be a network device. The first reference signal received by the first device may be one or more, that is, it may be a reference signal from one or more devices. The first reference signal may include a second reference signal from the second device; it may also include a third reference signal from an unauthorized device, that is, the first reference signal may have been attacked / tampered with. The second reference signal from the second device is used by the second device to locate the first device, and the third reference signal from the unauthorized device will interfere with the positioning result. For example, if the first reference signal received by the first device is the same as the second reference signal from the second device, it indicates that no attack has been received; if the first reference signal received by the first device is different from the second reference signal from the second device, it indicates that an attack has been received. Therefore, it is necessary to verify whether the first reference signal received by the first device is from the second device, or whether it is only from the second device. The first verification signal may be a signal generated by the second device and can be used to verify whether the first reference signal is from the second device.

[0137] S1102: The first device determines whether the first reference signal is a second reference signal from the second device based on a time domain position relationship between the first reference signal and the first verification signal.

[0138] It should be noted that the time domain position of a signal includes the time slot occupied by the signal in a signal frame, and a time slot (timeslot) can be a time segment in a signal frame, for example, each signal frame contains 32 time slots. In the embodiment of the present application, a reference signal or a check signal in a signal frame occupies a time slot, and of course it can also occupy half a time slot, multiple time slots, etc., which are not limited here. The time domain position of the first reference signal can be, for example, that in the first signal frame, the first reference signal occupies the third time slot, and the time domain position of the first check signal can be, for example, that in the first signal frame, the first check signal occupies the fourth time slot. Among them, the signal frame can be a time frame (frame) or a subframe (subframe), and the signal frame can be the basic unit of the frame structure. The terminal can perform verification with the signal frame as the granularity.

[0139] S1103: The first device sends the first information to the second device. Correspondingly, the second device receives the first information from the first device.

[0140] The first information is used to indicate whether the first reference signal originates from the second device. It is understood that the first information may include a verification result of whether the first reference signal is a second reference signal originating from the second device. If the first device determines that the first reference signal is a second reference signal originating from the second device, the first information indicates that the first reference signal originates from the second device. If the first device determines that the first reference signal is not a second reference signal originating from the second device, the first information indicates that the first reference signal does not originate from the second device. For example, the first information may be a single-bit information element, with two values ​​of 0 / 1 indicating whether the first reference signal originates from the second device. The first information may be carried in any possible access stratum (AS) message used for communication between the first and second devices, such as a radio resource control (RRC) message or a media access control element (MAC-CE) message, or carried in a message transmitted on a channel such as a physical uplink shared channel (PUSCH) or a physical uplink control channel (PUCCH), or may be a message newly defined in the future, which is not limited thereto.

[0141] In summary, without changing the sequence or periodic characteristics of the original reference signal, that is, without affecting the system positioning accuracy, the detection of replay attacks is achieved by adding a first verification signal, so that when the first reference signal is subjected to a replay attack, the first device can detect the attack based on the time domain position relationship between the first reference signal and the first verification signal, thereby rejecting the positioning measurement results. In this way, unauthorized users can be prevented from interfering with the positioning results of legitimate devices without the participation of additional equipment, the implementation complexity is low, and the positioning accuracy of legitimate users is not affected.

[0142] The following is a detailed introduction to S1101.

[0143] The second reference signal from the second device is used by the second device to locate the first device. The second reference signal may be a reference signal that enables positioning between the second device and the first device, i.e., the first and second devices rely on the reference signal to achieve positioning. For example, the second reference signal may be a PRS signal, and the terminal and base station rely on the PRS signal to achieve positioning. The first verification signal may be a signal generated by the second device and may be used to verify whether the first reference signal originates from the second device.

[0144] Since the first reference signal may be a forged PRS signal from an unauthorized user, the first device cannot determine whether the first reference signal is from the second device or the unauthorized user when receiving the first reference signal. Therefore, the terminal needs to verify through the first verification signal whether the received first reference signal is the second reference signal sent by the second device.

[0145] The second reference signal and the first verification signal are included in a first signal frame. The first signal frame includes multiple second reference signals. The time domain position difference between every two second reference signals in the first signal frame is the same. The absolute value of the time domain position difference is called the first difference. The absolute value of the time domain position difference between the first verification signal and the second reference signal adjacent to the first verification signal is called the second difference. The second difference is different from the first difference, or the second difference is the same as the first difference.

[0146] It can be understood that the second reference signal and the first verification signal overlap in the frequency domain. The first difference in the time domain positions between each two second reference signals is the same, indicating that the second reference signal is placed at a time domain position within the first signal frame where a reference signal can be periodically placed. Here, a time domain position where a reference signal can be periodically placed indicates that the time domain position has the capability to periodically place a reference signal. A second reference signal adjacent to a first verification signal within the first signal frame can be the second reference signal preceding the first verification signal in the time domain, or alternatively, the second reference signal following the first verification signal in the time domain. A difference between the second difference and the first difference indicates that the first verification signal is placed at a time domain position between the two second reference signals, increasing flexibility in verification signal placement. A difference between the second difference and the first difference indicates that the first verification signal is placed at a time domain position where a reference signal can be periodically placed, meaning that the first verification signal occupies a time domain position already occupied by the first reference signal. This allows for continued use of the existing frame structure, i.e., the frame structure defined by the current standard remains unchanged, resulting in minimal changes to the standard, a more user-friendly design, and relatively simple implementation.

[0147] It can be understood that, corresponding to the time domain positions of the second reference signal and the first check signal in the first signal frame, the first signal frame can be generated in two ways, or in other words, there are two frame structures, which are described below with examples.

[0148] The first frame structure is: there are multiple periodically repeated second reference signals in the first signal frame, that is, the second reference signal is periodically placed in the first signal frame, and the first check signal is placed between the two second reference signal time slots in the first signal frame. The first check signal here can be one or more, and one or more first check signals can be placed between the two second reference signal time slots, which is not limited here.

[0149] For example, as shown in Figure 12, a PRS frame consists of N (N > 1) periodically repeated PRS signals and p check signals, where p is an integer greater than or equal to 1 and N is greater than p. The terminal uses idle time slots between PRS signal time slots to place the check signals. These idle time slots can be time slots not occupied by PRS signals or other service signals. This PRS frame structure eliminates the time and frequency resources of the PRS signal, improving the effectiveness of the terminal's reference signal-based positioning.

[0150] The second frame structure is: there are multiple periodically repeated second reference signals in the first signal frame, that is, the second reference signal is periodically placed in the first signal frame, and the first check signal occupies the time domain position of a second reference signal. For example, it can be placed after the last second reference signal, in front of the first second reference signal, or of course, it can be placed in any time domain position in the middle with the same period as the second reference signal, wherein the first check signal can be one or more, and is not limited here. If there are multiple first check signals, each first check signal occupies the time domain position of a second reference signal, and there is at most one first check signal between every two second reference signals. The second frame structure can be used when there is no idle time slot allocated to the second check signal between the two first reference signals in the first frame structure. There is no idle time slot, that is, the time domain resources between the two second reference signal time slots in the first signal frame have been occupied by other business signals. Therefore, the second frame structure can be used to generate the second reference signal and the first check signal.

[0151] For example, as shown in FIG13 , when there is no idle time slot between two PRSs allocated to the check signal, the PRS frame consists of N periodically repeated PRS signals and 1 check signal, and the check signal occupies the time slot position of the N+1th PRS.

[0152] Optionally, the second reference signal and the first verification signal are included in a first signal frame, the first signal frame includes a second reference signal and a first verification signal, and the difference in time domain position between the second reference signal and the first verification signal is a preset value.

[0153] It is understood that the second device uses the same rules for generating the reference signal and verification signal as the first device. If the first reference signal received by the first device has not been forged by an unauthorized user, the time-domain positional relationship between the first reference signal and the first verification signal should match the time-domain positional relationship between the fourth reference signal and the second verification signal generated by the first device. Only then can the fourth reference signal and the second verification signal generated by the first device be used to verify the first reference signal.

[0154] Optionally, when generating the second reference signal and the first verification signal, the second device may generate them through configuration information issued by a location management function (LMF) network element, or through configuration information determined by the second device itself. For details about the configuration information, please refer to the following description of the generation of the second signal frame by the first device, which will not be repeated here.

[0155] The following is a detailed introduction to S1102.

[0156] It is understood that the time domain position relationship can be the difference in time domain position between the first reference signal and the first verification signal (also referred to as an offset). For example, the time domain position difference or offset between the reference signal and the verification signal can be preset. The first device determines whether the first reference signal is the second reference signal from the second device by verifying whether the time domain position relationship between the received first reference signal and the first verification signal satisfies a preset value. That is, if the preset value is met, the first reference signal is the second reference signal from the second device; otherwise, the first reference signal is not the second reference signal from the second device.

[0157] In one possible implementation, S1102 may include: the first device determines whether the first reference signal is the second reference signal from the second device based on the time domain position relationship between the first reference signal and the first verification signal, and the time domain position relationship between the fourth reference signal and the second verification signal, wherein the fourth reference signal and the second verification signal can be determined by the first device based on the configuration information from the second device.

[0158] Specifically, it may include: the first device determines a first offset, wherein the first offset is the offset between the time domain position of the first verification signal and the time domain position of the first reference signal; and determines whether the first reference signal is a second reference signal from the second device based on the first offset and the second offset, wherein the second offset may be the offset between the time domain position of the fourth reference signal and the time domain position of the second verification signal.

[0159] It is understood that the first offset may be the time domain position offset between the first verification signal received by the first device and the first reference signal, and the second offset may be the time domain position offset between the second verification signal locally generated by the first device and the fourth reference signal. Since the fourth reference signal and the second verification signal are accurate signals generated by the first device, i.e., they have not been interfered with by unauthorized users, and if the first reference signal received by the first device has not been attacked or tampered with by unauthorized users, the time domain position relationship between the first reference signal and the first verification signal should match the time domain position relationship between the fourth reference signal and the second verification signal. Therefore, based on the fourth reference signal, the second verification signal, and the first verification signal, it is possible to verify whether the first reference signal is the second reference signal from the second device.

[0160] The time domain position offset can be calculated based on the starting position of the check signal and the starting position of the reference signal, or can also be calculated based on the ending position of the check signal and the ending position of the reference signal. The time domain position offset between the check signal and the reference signal can also be understood as the time period between the check signal and the reference signal in the time domain. Matching the first offset and the second offset can include the difference between the first offset and the second offset being within a preset range, i.e., the first offset and the second offset are similar, and can also include the first offset and the second offset being the same.

[0161] Since the first device and the second device use the same rules to generate the reference signal and the verification signal, the reference signal and the verification signal involved in the following description can be the reference signal and the verification signal generated by the first device, or the reference signal and the verification signal generated by the second device.

[0162] When the reference signal and the check signal have the first frame structure, when performing attack detection, the time domain position offset between the reference signal and the check signal is as shown in FIG14. If the signal frame contains multiple check signals, the terminal can select any check signal for verification. As shown in FIG14, the terminal knows that the time domain position difference between the local i-th check signal and the previous PRS signal is T(i), and the time domain position offset between the i+1-th check signal and the previous PRS signal is T(i+1). The second device sends a PRS signal and a first check signal to the first device. The first device can verify using the i-th check signal or the i+1-th check signal, such as determining whether the time interval between the received i-th check signal and the previous PRS signal matches the T(i) time interval, or determining whether the time interval between the received i+1-th check signal and the previous PRS signal matches the T(i+1) time interval, thereby determining whether the received PRS signal is a PRS signal from the second device.

[0163] When the reference signal and the check signal have the second frame structure, during attack detection, the time domain offset T(i) between the reference signal and the check signal is as shown in Figure 15. As shown in Figure 15, the terminal knows that the time domain offset between the local i-th check signal and the previous PRS signal is T(i). This time period T(i) is also the repetition period of the PRS signal in the configuration information. The second device sends a PRS signal and a first check signal to the first device. The first device determines whether the time period between the received i-th check signal and the previous PRS signal matches the T(i) time period, thereby determining whether the received PRS signal is from the second device.

[0164] That is to say, by comparing / matching the offset between the time domain position of the received verification signal and the reference signal with the offset between the time domain position of the locally generated verification signal and the reference signal, it is determined whether the received first reference signal is the second reference signal from the second device, thereby realizing the verification of the received reference signal.

[0165] In one possible implementation, the signal verification method may further include: including a first reference signal and a first verification signal in a first signal frame, the first device determining a first correlation peak based on a second verification signal and a signal received in the first signal frame, wherein the time domain position of the first correlation peak is the time domain position of the first verification signal. The terminal determining a second correlation peak based on a signal received in the first signal frame by a fourth reference signal, wherein the time domain position of the second correlation peak is the time domain position of the first reference signal.

[0166] It can be understood that since the correlation peak can only be generated by performing a correlation operation on two close or identical signals, the fourth reference signal and the second verification signal generated locally by the first device are respectively correlated with the received first signal frame, and the time domain position where the correlation peak appears is the time domain position of the received first reference signal and the first verification signal, so that whether the verification is passed is judged based on the time domain position relationship. In this way, the time domain position of the first reference signal and the first verification signal can be accurately located.

[0167] In addition, since the reference signal and the check signal are both contained in the same signal frame, the correlation operation can be performed with a single signal frame as the granularity, such as performing the correlation operation within one signal frame instead of multiple signal frames, which can reduce the operation overhead.

[0168] It can be understood that the first device uses a locally generated second verification signal to perform a correlation operation on the first signal frame, for example, using a sliding window correlation algorithm to perform a sliding correlation operation. The first correlation peak may appear when the second verification signal and the first verification signal overlap in time. The time domain location of the first correlation peak may be the time when the first correlation peak appears. The time when the first correlation peak appears is the time when the first verification signal appears, that is, the time domain location of the first verification signal. Similarly, the first device uses a locally generated fourth reference signal to perform a correlation operation on the first signal frame, for example, using a sliding window correlation algorithm to perform a sliding correlation operation. The second correlation peak may appear when the fourth reference signal and the first reference signal overlap in time. The time domain location of the second correlation peak may be the time when the second correlation peak appears. The time when the second correlation peak appears is the time when the first reference signal appears, that is, the time domain location of the first reference signal.

[0169] If the first reference signal received by the first device is the second reference signal from the second device, the time domain position difference between the first correlation peak and the second correlation peak should match the time domain position difference between the fourth reference signal and the second verification signal generated locally by the first device. For example, when the PRS signal transmitted by the second device is not under attack, the correlation peak obtained by the first device by correlating the local PRS signal with the received signal should differ by a time period of T(i) from the correlation peak obtained by correlating the local verification signal with the received signal.

[0170] Optionally, the time domain position of the fourth reference signal and the time domain position of the second check signal are indicated by configuration information, and the configuration information is used to indicate the generation of the fourth reference signal and the second check signal. The configuration information is used to indicate that the fourth reference signal and the second check signal are included in the second signal frame, and the second signal frame includes multiple fourth reference signals. The offset of the time domain position between each two fourth reference signals in the second signal frame is the same, and the offset of the time domain position is called the third offset. The offset of the time domain position between the second check signal and the fourth reference signal adjacent to the second check signal is called the fourth offset, wherein the fourth offset is different from the third offset, or the fourth offset is the same as the third offset. The second signal frame can refer to the description of the first signal frame and will not be repeated here.

[0171] Among them, the configuration information may be a parameter related to the reference signal configuration, for example, it may be a parameter related to the PRS configuration (posSIB), the configuration information may include the time domain position of the fourth reference signal and the time domain position of the second check signal, the configuration information may be sent down by a higher layer, for example, by an LMF network element, or the second device may generate the configuration information and send it to the first device.

[0172] It is understood that the configuration information indicates two ways to generate the fourth reference signal and the second check signal within the second signal frame, or in other words, the second signal frame has two frame structures. Since the first device and the second device align in the manner in which they generate the reference signal and the check signal, the specific frame structure of the second signal frame can refer to the frame structure of the first signal frame described above and is not further described here.

[0173] In addition, the configuration information related to the generation of the fourth reference signal and the second check signal can be specifically indicated by an indication field, specifically indicating: the number of fourth reference signals and the number of second check signals within the second signal frame, the position of the second check signal within the second signal frame, and the structure type of the signal frame. Subfields can also be used to indicate the number of fourth reference signals after which each second check signal appears, as well as the offset between each second check signal and the previous fourth reference signal. The structure type of the signal frame can refer to the two types of frame structures described above.

[0174] For example, the posSIB resource related to the PRS signal configuration includes four indication fields related to the generation of PRS signals and check signals to indicate the generation of PRS signal frames. The four fields are the number of PRS signals (dl-PRS-NumberPerFrame), the number of check signals (dl-PRS-IntegritySignalNumber), the offset of the check signal (dl-PRS-IntegritySignalOffsets), and the frame structure type of the PRS frame (dl-PRS-FrameType). The newly added fields "Number of PRS Signals" and "Number of Check Signals" indicate the number N of PRS signals and the number p of check signals in a PRS frame; the newly added field "Offset of Check Signal" indicates the position of the check signal. This field includes two parts: the order of the check signal (dl-PRS-IntegritySignalOffsets-Order), which is used to indicate the number of PRS signals after which each check signal appears, and the value of the offset of the check signal (dl-PRS-IntegritySignalOffsets-Value), which is used to indicate the offset of each check signal from the previous PRS signal. For example, in FIG12 , the offset between check signal #1 and PRS signal #2 is 1, and the offset between check signal #2 and PRS signal #j is 2. PRS signal #2 is the second PRS signal, and PRS signal #j is the jth PRS signal, where j is less than or equal to N. It can be seen that the offsets may be unequal, but they may also be equal, which is not limited here.

[0175] In a possible implementation, the signal verification method may further include: the first device receives configuration information, and generates a fourth reference signal and a second verification signal according to the configuration information.

[0176] Specifically, the fourth reference signal and the second check signal may be generated according to any one of the two frame structures indicated by the configuration information.

[0177] Optionally, the first device receives configuration information from the LMF network element, or receives configuration information from the second device.

[0178] Two methods of encrypting the second verification signal are introduced below.

[0179] In one possible implementation, the configuration information includes an encryption key. The first device encrypts the first bit sequence according to the encryption key to obtain an encrypted first bit sequence. The encrypted first bit sequence is modulated to obtain a second symbol for a verification signal. The second symbol is mapped to the time domain position of the verification signal indicated by the configuration information to obtain a second verification signal.

[0180] Among them, the encryption key can be a key shared by the second device and the first device. For example, the terminal generates a second verification signal based on the AES algorithm encryption according to the key shared with the second device. The AES algorithm is an efficient forward encryption algorithm. Without knowing the encryption key, unauthorized users cannot obtain plaintext through ciphertext (nor can they obtain ciphertext through plaintext), so unauthorized users cannot obtain the second verification signal.

[0181] The first bit sequence may be a PRS bit sequence, i.e., an initially generated Gold sequence. The PRS bit sequence is encrypted using an encryption key, and the resulting encrypted bit sequence is the bit sequence of the check signal. The encrypted first bit sequence may be modulated using a digital modulation scheme, such as a QPSK modulation scheme, to obtain a second symbol, which may be used to subsequently generate a second check signal.

[0182] For example, as shown in FIG16 , the PRS bit sequence (i.e., the initially generated Gold sequence) is directly AES encrypted using the shared key of the first and second devices, ensuring the randomness and unpredictability of the check signal. The encrypted bit sequence is then QPSK modulated to obtain a check symbol (a second symbol). Furthermore, the AES algorithm's parameter counter (counter) increments by 1 each time the encrypted bit sequence is generated. The constant change of the counter ensures that each generated encrypted bit sequence is different, ensuring the non-repetitiveness of subsequently generated check signals. This prevents unauthorized users from discovering or predicting the check signal, thereby preventing replay attacks.

[0183] In another possible implementation, the signal verification method may further include: the first device encrypting the second bit sequence according to the encryption key to obtain an encrypted second bit sequence; and performing an XOR operation on the encrypted second bit sequence and the first bit sequence to obtain an encrypted first bit sequence.

[0184] The second bit sequence can be any unchanging secret sequence, such as the sequence ID of the PRS or the identity ID of the UE. The second bit sequence can be referred to as a root sequence. The encrypted second bit sequence is used as a new key to encrypt the PRS bit sequence. Specifically, the encrypted second bit sequence can be XORed with the PRS bit sequence and then subjected to an irreversible hash function (HASH) to obtain the encrypted first bit sequence. This prevents unauthorized users from intercepting the encrypted first bit sequence to obtain the encrypted second bit sequence, thereby ensuring the unpredictability of the verification signal. Furthermore, the encrypted first bit sequence is modulated to obtain a second symbol for the verification signal.

[0185] For example, as shown in Figure 17, a root sequence is encrypted using AES using the key shared by the first and second devices to generate an updated shared key. This updated shared key is continuously generated by the changes in the counter. The PRS bit sequence is XORed with the updated shared key and then fed into a hash function to produce an encrypted bit sequence (the encrypted first bit sequence). The encrypted check bit sequence is then modulated to produce a check symbol. Furthermore, the changes in the AES counter generate a continuously changing updated shared key, ensuring the non-repetitive nature of the check signal.

[0186] After obtaining the second symbol, the first device maps the second symbol to the time domain position of the check signal indicated by the configuration information to obtain a second check signal.

[0187] Here, the time domain position of the check signal indicated by the configuration information may include the time-frequency resource allocated for the second check signal, for example, it may be the position between two second reference signal time slots in the second signal frame in the first frame structure, or it may be the time domain position of the second check signal occupying a second reference signal in the second frame structure. For example, as shown in FIG18 , after obtaining the check symbol, the check symbol is placed on the corresponding time-frequency resource and occupies all time-frequency resources (resource element, RE), where RE is the shaded portion in the figure, to obtain the final check signal.

[0188] In one possible implementation, the signal verification method further includes: transmitting a ranging result when the first reference signal is the second reference signal. It is understood that the ranging result may include the distance between the first and second devices. This distance can be calculated based on the time domain location of the correlation peaks of the first and fourth reference signals and the speed of light. For example, it can be the product of the time difference between the time of occurrence of the correlation peak within the first signal frame and the start time of the fourth reference signal, and the speed of light. The ranging result can be used by the second device to subsequently locate the first device. The ranging process can be performed when the first device determines that the first reference signal is the second reference signal from the second device, and then transmit the ranging result. The first device can also perform ranging first and then transmit the ranging result when the first reference signal is the second reference signal from the second device. The ranging result is transmitted when the first reference signal is determined to be the reference signal from the second device and is not compromised by unauthorized users, thereby improving the accuracy of the second device's terminal positioning. Accordingly, upon receiving first information indicating that the first reference signal is the reference signal from the second device, the second device can locate the first device based on the ranging result, thereby improving the accuracy of the positioning result.

[0189] In combination with the above S1101-S1103, optionally, the first device can also send the first information to the LMF network element. Correspondingly, the LMF network element receives the first information from the first device. For example, the terminal can send a NAS message to the AMF, and the NAS message can carry the first information. The AMF can obtain the first information in the NAS message, and then pass the first information to the LMF through the interface message between the AMF and the LMF. Alternatively, when the terminal can communicate directly with the LMF, the terminal can also send the first information directly to the LMF. At this time, the first information can be carried in the message sent by the terminal directly communicating with the LMF, and the specific message type is not limited. In this way, the LMF can know that the positioning of the terminal has not been interfered with by the attacker's unauthorized user based on the received first information. Only then will the network side perform mobility management on the terminal to avoid the network from performing mobility management on the terminal even when the terminal's positioning is interfered with by the attacker's unauthorized user, resulting in a waste of network resources.

[0190] Additionally, the first device may also send a ranging result to the LMF network element in a manner similar to that of the first information, which can be understood by reference and will not be described in detail here. In this way, the LMF network element may directly use the ranging result sent by the first device to locate the first device.

[0191] Figure 19 is a flow chart of another signal verification method provided by an embodiment of the present application. The signal verification method is applicable to the above-mentioned communication system, and mainly involves the interaction between the first device and the second device.

[0192] As shown in FIG19 , the flow of the signal verification method is as follows:

[0193] S1901: The second device sends a second reference signal and a first verification signal to the first device. The first device receives the first reference signal.

[0194] The first reference signal received by the first device may be one or more, that is, it may be a reference signal from one or more devices. The first reference signal may include a second reference signal from a second device, and may also include a third reference signal from an unauthorized device. The first reference signal here can refer to the description of the first reference signal in S1101 and is not repeated here. When the first device receives the first reference signal, it can obtain the time domain position of the first reference signal by performing a correlation operation with the received signal through a fourth reference signal. The fourth reference signal may be generated by the first device. For details, refer to the description of the fourth reference signal in S1102 and is not repeated here.

[0195] S1902, the first device determines a first time domain position according to the first reference signal, the fourth reference signal and the second verification signal, and obtains a first signal at the first time domain position.

[0196] The fourth reference signal and the second verification signal are determined by the first device, that is, the fourth reference signal and the second verification signal can be generated by the first device. The fourth reference signal can refer to the description of the fourth reference signal in S1102, and the second verification signal can refer to the description of the second verification signal in S1102, and are not further described here. Since the fourth reference signal and the second verification signal are determined by the first device, the first device can obtain the time domain positions of the fourth reference signal and the second verification signal. The first device can determine the first time domain position based on the time domain position of the first reference signal, the time domain position of the fourth reference signal, and the time domain position of the second verification signal. Here, the difference between the first time domain position and the time domain position of the first reference signal is the same as the time domain position difference between the fourth reference signal and the second verification signal. The first signal can be a signal within the same signal frame as the first reference signal. If the first reference signal is the second reference signal from the second network device, the first signal obtained at the first time domain position should be consistent with the second verification signal. Therefore, the first signal can be used to verify whether the first reference signal is the second reference signal from the second device.

[0197] S1903: The first device determines, based on the first signal and the second verification signal, whether the first reference signal comes from the second reference signal of the second device.

[0198] The second reference signal from the second device is used by the second device to locate the first device.

[0199] Optionally, if the first signal matches the second verification signal, the first reference signal is determined to be the second reference signal sent by the second device. If the first signal does not match the second verification signal, the first reference signal is determined not to be the second reference signal sent by the second device. It can be understood that by comparing the received first signal and the local second verification signal to see if they match, it is possible to detect whether the system has been attacked, with low implementation complexity. The match here can be consistency or similarity.

[0200] Optionally, the first device determines whether the first reference signal is from the second reference signal of the second device based on whether the first time domain position is the same as the second time domain position, wherein the second time domain position may be the time domain position of the second verification signal. It is understood that if the first reference signal is the second reference signal from the second network device, then the first time domain position should be the same as the time domain position of the second verification signal locally on the first device. Here, the first time domain position may be, for example, a time domain position within the first signal frame, and the time domain position of the second verification signal may be, for example, a time domain position within the second signal frame. For details, please refer to the description of the time domain position of the signal within the signal frame in S1102 to S1103, which will not be repeated here.

[0201] S1904: The first device sends the first information to the second device. Correspondingly, the second device receives the first information from the first device.

[0202] The first information is used to indicate whether the first reference signal is a second reference signal from the second device.

[0203] The following is a detailed introduction to S1902.

[0204] Optionally, the first time domain position is a time domain position that is spaced a second offset behind the time domain position of the first reference signal, wherein the second offset is an offset between the time domain position of the fourth reference signal and the time domain position of the second check signal.

[0205] The first offset between the time domain position of the fourth reference signal and the time domain position of the second verification signal can also be understood as the time period between the fourth reference signal and the second verification signal in the time domain. When acquiring the first signal from a time domain position that is spaced the second offset away from the time domain position of the first reference signal, the first time domain position can be used as the starting time, and a signal segment that is the length of one verification signal after the starting time can be used as the received first signal, where the length of the verification signal can be a preset length.

[0206] For example, the first device uses T(i) time after the received PRS signal as the starting time, counts a signal segment of the length of the verification signal from the starting time, and extracts it as the received first signal for verification. T(i) time is the interval between the reference signal and the verification signal generated by the first device. Corresponding to the two frame structures, there are two possible values ​​for T(i). For details, please refer to the description of Figures 12 and 14 in S1101 to S1102, and are not further described here.

[0207] Optionally, the first device acquiring the first signal at the first time domain position may include: acquiring a first symbol for verifying the signal at the first time domain position, and demodulating the first symbol according to a symbol for demodulating the signal to obtain the first signal.

[0208] It can be understood that the symbol used for demodulating the signal can be a demodulation reference signal DMRS, and the second device can map the symbol used for demodulating the signal to the time-frequency resource corresponding to the verification signal on the second device side in advance. For example, as shown in FIG20, the second device allocates the corresponding time-frequency resource for the first verification signal. For specific allocation of the two frame structures corresponding to the configuration information indication, please refer to the description in S1102, which will not be repeated here. Among them, a part of the RE resources (the time-frequency block in the figure) in the time-frequency resources is placed with the verification symbol (first symbol), and the remaining RE resources are placed with a deterministic DMRS signal. The role of the DMRS signal is to be used for channel estimation, so that the terminal can perform channel estimation based on the symbol used for demodulating the signal, use the channel estimation result to demodulate the received first symbol into the first signal, and then compare the first signal with the local second verification signal. If the comparison is consistent, the verification is correct; otherwise, it is incorrect, which ensures the accuracy of the verification result.

[0209] Optionally, the time domain position of the fourth reference signal and the time domain position of the second check signal are indicated by configuration information, and the configuration information is used to instruct generation of the fourth reference signal and the second check signal.

[0210] In which, the configuration information is used to indicate that the second signal frame includes multiple fourth reference signals and second verification signals, and the offset of the time domain position between each two fourth reference signals in the second signal frame is the same, and this offset is called the third offset; the offset of the time domain position between the second verification signal and the fourth reference signal adjacent to the second verification signal is called the fourth offset, and the fourth offset is different from the third offset, or the fourth offset is the same as the third offset.

[0211] In a possible implementation, the signal verification method may further include: the first device receives configuration information, and generates a fourth reference signal and a second verification signal according to the configuration information.

[0212] Optionally, the configuration information includes an encryption key, and the first bit sequence is encrypted according to the encryption key to obtain an encrypted first bit sequence. The encrypted first bit sequence is modulated to obtain a second symbol for a verification signal. The second symbol is mapped to a time domain position of the verification signal to obtain a second verification signal.

[0213] Optionally, the signal verification method may further include: encrypting the second bit sequence according to the encryption key to obtain an encrypted second bit sequence, and performing an XOR operation on the encrypted second bit sequence and the first bit sequence to obtain an encrypted first bit sequence.

[0214] For the above content, please refer to the specific description in S1102 and will not be repeated here.

[0215] Optionally, the first device maps the second symbol and the symbol used for the demodulation signal to the time domain position of the verification signal to obtain a second verification signal. It can be understood that the first device and the second device generate the verification signal in the same manner. The first device maps the second symbol and the symbol used for the demodulation signal to the time-frequency resources corresponding to the verification signal to obtain the second verification signal, so that the first device can perform channel estimation based on the symbol used for the demodulation signal and use the channel estimation result to demodulate the received first symbol into the first signal.

[0216] In a possible implementation, the signal verification method may further include: when the first reference signal is the second reference signal, the first device sends a ranging result, and the ranging result is obtained based on the first reference signal and the fourth reference signal.

[0217] In one possible implementation, the signal verification method may further include: the first device sends first information to the positioning management function LMF network element.

[0218] The above content can refer to the specific description in S1101 to S1103 and will not be repeated here.

[0219] In summary, when the time domain position relationship between the first signal received by the first device and the first reference signal matches the time domain position relationship between the local fourth reference signal and the verification signal, it can be determined that the first reference signal is the second reference signal from the second device. Therefore, by receiving the first signal through this time domain position relationship and comparing the received first signal with the local second verification signal, it is possible to detect whether the system has been attacked by an unauthorized user. In this way, unauthorized users can be prevented from interfering with the positioning results of legitimate devices without the participation of additional equipment, with low implementation complexity and without affecting the positioning accuracy of legitimate users.

[0220] The above describes the overall process of the signal transmission method provided by the embodiment of the present application in conjunction with Figures 11 to 20. The following describes the specific process of the signal verification method provided by the embodiment of the present application in a specific scenario in conjunction with Figure 21.

[0221] Figure 21 is a flow chart of the third method for signal verification provided in this embodiment. The signal verification method is applicable to the above-mentioned communication system, and specifically involves the interaction between the terminal (i.e., the first device), the base station (i.e., the second device), and the LMF network element. The terminal and the base station respectively receive the configuration information sent by the LMF network element, and each generates a PRS signal frame. Each PRS signal frame includes a PRS signal indicated by the configuration information and a verification signal, so as to verify whether the PRS signal is attacked based on the verification signal. In this way, unauthorized users can be prevented from interfering with the positioning results of legitimate devices without the participation of additional equipment, and the implementation complexity is low, and the positioning accuracy of legitimate users is not affected.

[0222] Specifically, as shown in FIG21 , the process of the signal verification method is as follows:

[0223] S2101, the LMF network element sends configuration information to the base station and terminal.

[0224] The configuration information may include an encryption key, which may be a key shared by the base station and the terminal. The configuration information may also include parameters related to PRS configuration (posSIB), including a newly added indication field for indicating the generation of a verification signal. For details, please refer to the description of S1102 and will not be repeated here.

[0225] S2102: The base station generates a first PRS signal according to the configuration information, and the terminal generates a second PRS signal according to the configuration information.

[0226] S2103: The base station generates a first verification signal according to the configuration information, and the terminal generates a second verification signal according to the configuration information.

[0227] It can be understood that the first PRS signal and the first check signal are carried in the first PRS signal frame, and the second PRS signal and the second check signal are carried in the second PRS signal frame. The specific method of generating the PRS signal and the check signal can be referred to the description of S1101 to S1102, and will not be repeated here.

[0228] S2104: The base station sends a first PRS signal frame to the terminal. Correspondingly, the terminal receives a second PRS signal frame.

[0229] It can be understood that the first PRS signal frame sent by the base station to the terminal may include the first PRS signal and the first verification signal, but the second PRS signal included in the second PRS signal frame received by the terminal may be attacked / tampered with, that is, it may not be a reference signal from the base station, or not only a reference signal from the base station.

[0230] S2105: The terminal performs ranging and verification of the PRS signal.

[0231] The terminal needs to verify whether the PRS signal in the received second PRS signal frame is the PRS signal sent by the base station, that is, whether it is the first PRS signal generated by the base station, based on the local second PRS signal and the second verification signal. The verification of the PRS signal corresponds to the two verification methods of S1101 to S1102 and S1901 to S1902, and will not be repeated here.

[0232] S2106: The terminal reports the ranging result and verification result to the base station and LMF network element.

[0233] It is understood that when the verification result is verified to be passed, that is, when the terminal determines that the received PRS signal is the PRS signal sent by the base station, the ranging result is reported to the base station and the LMF network element. For details, please refer to the description of S1102 and will not be repeated here.

[0234] In summary, the terminal and base station respectively receive the configuration information sent by the LMF network element and generate a PRS signal frame. Each PRS signal frame includes a PRS signal and a verification signal indicated by the configuration information, so as to verify whether the PRS signal has been attacked based on the verification signal. In this way, unauthorized users can be prevented from interfering with the positioning results of legitimate devices without the participation of additional equipment. The implementation complexity is low and the positioning accuracy of legitimate users is not affected.

[0235] The method provided by the embodiment of the present application is described in detail above in conjunction with Figures 11 to 21. The communication device for executing the signal verification method provided by the embodiment of the present application is described in detail below in conjunction with Figures 22 to 23.

[0236] Figure 22 is a structural diagram of a communication device according to an embodiment of the present application. As shown in Figure 22, the communication device 2200 includes a transceiver module 2201 and a processing module 2202. For ease of illustration, Figure 22 only shows the main components of the communication device.

[0237] Among them, the transceiver module 2201 is used to perform the transceiver function of the method shown in Figure 11 or Figure 19 above, and the processing module 2202 is used to perform other functions of the method shown in Figure 11 or Figure 19 except the transceiver function.

[0238] Optionally, the transceiver module 2201 may include a sending module (not shown in FIG22 ) and a receiving module (not shown in FIG22 ). The sending module is used to implement the sending function of the communication device 2200 , and the receiving module is used to implement the receiving function of the communication device 2200 .

[0239] Optionally, the communication device 2200 may further include a storage module (not shown in FIG. 22 ) storing a program or instruction. When the processing module 2202 executes the program or instruction, the communication device 2200 may perform the functions of the terminal or network device in the method shown in FIG. 11 or FIG. 19 in the above method.

[0240] It can be understood that the communication device 2200 can be a terminal or a network device, or a chip (system) or other parts or components that can be set in the terminal or network device, or a device that includes a terminal or network device. This application does not limit this.

[0241] In addition, the technical effects of the communication device 2200 can refer to the technical effects of the signal verification method shown in Figure 11 or Figure 19, and will not be repeated here.

[0242] Figure 23 is a second structural diagram of a communication device provided in an embodiment of the present application. Exemplarily, the communication device may be a terminal, or a chip (system) or other component or assembly that can be provided in a terminal. As shown in Figure 23, the communication device 2300 may include a processor 2301. Optionally, the communication device 2300 may further include a memory 2302 and / or a transceiver 2303. The processor 2301 is coupled to the memory 2302 and / or the transceiver 2303, such as by connecting via a communication bus, by connecting via an interface within the chip, or by connecting via other communication lines. Optionally, the memory 2302 may be integrated with the processor 2301.

[0243] The following is a detailed introduction to the various components of the communication device 2300 with reference to FIG23 :

[0244] The processor 2301 is the control center of the communication device 2300 and can be a single processor or a collective term for multiple processing elements. For example, the processor 2301 can be one or more central processing units (CPUs), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).

[0245] Optionally, the processor 2301 can perform various functions of the communication device 2300 by running or executing software programs stored in the memory 2302 and calling data stored in the memory 2302, such as executing the signal verification method shown in Figure 11 or Figure 19 above.

[0246] In a specific implementation, as an embodiment, the processor 2301 may include one or more CPUs, such as CPU0 and CPU1 shown in FIG. 23 .

[0247] In a specific implementation, as an embodiment, the communication device 2300 may also include multiple processors, such as the processor 2301 and the processor 2304 shown in FIG23 . Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0248] Among them, the memory 2302 is used to store the software program for executing the solution of this application, and the execution is controlled by the processor 2301. The specific implementation method can refer to the above method embodiment and will not be repeated here.

[0249] Alternatively, the memory 2302 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 2302 may be integrated with the processor 2301 or exist independently and be coupled to the processor 2301 via an interface circuit (not shown in FIG. 23 ) of the communication device 2300, which is not specifically limited in this embodiment of the present application.

[0250] Transceiver 2303 is used for communication with other communication devices. For example, if communication device 2300 is a terminal, transceiver 2303 can be used to communicate with a network device or another terminal device. For another example, if communication device 2300 is a network device, transceiver 2303 can be used to communicate with a terminal or another network device.

[0251] Optionally, the transceiver 2303 may include a receiver and a transmitter (not shown separately in FIG23 ). The receiver is used to implement a receiving function, and the transmitter is used to implement a transmitting function. Optionally, the transceiver 2303 may be integrated with the processor 2301, or may exist independently and be coupled to the processor 2301 via an interface circuit (not shown in FIG23 ) of the communication device 2300, which is not specifically limited in this embodiment of the present application.

[0252] It is understandable that the structure of the communication device 2300 shown in FIG23 does not constitute a limitation on the communication device, and the actual communication device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0253] In addition, the technical effects of the communication device 2300 can refer to the technical effects of the method described in the above method embodiment, and will not be repeated here.

[0254] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, DSPs, ASICs, FPGAs or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0255] It should also be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a ROM, a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an EEPROM, or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0256] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (such as infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0257] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0258] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0259] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0260] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0261] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0262] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0263] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0264] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0265] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes the various possible memories mentioned above.

Claims

1. A method for signal verification, characterized in that, The method is applied to a first device and includes: Receiving a first reference signal and a first verification signal from a second device; Determining whether the first reference signal is a second reference signal from the second device according to a time-domain position relationship between the first reference signal and the first verification signal; Sending first information to the second device, where the first information is used to indicate whether the first reference signal is the second reference signal, and the second reference signal is used by the second device to locate the first device.

2. The method according to claim 1, wherein The determining whether the first reference signal is a second reference signal from the second device according to a time-domain position relationship between the first reference signal and the first verification signal includes: Determining whether the first reference signal is the second reference signal from the second device according to a time-domain position relationship between the first reference signal and the first verification signal, and a time-domain position relationship between a fourth reference signal and a second verification signal, where the fourth reference signal and the second verification signal are determined by the first device.

3. The method according to claim 2, wherein The determining whether the first reference signal is the second reference signal from the second device according to a time-domain position relationship between the first reference signal and the first verification signal, and a time-domain position relationship between a fourth reference signal and a second verification signal includes: Determining a first offset, where the first offset is an offset between a time-domain position of the first reference signal and a time-domain position of the first verification signal; Determining whether the first reference signal is the second reference signal from the second device according to whether the first offset matches a second offset, where the second offset is an offset between a time-domain position of the fourth reference signal and a time-domain position of the second verification signal.

4. The method according to claim 3, wherein The first reference signal and the first verification signal are included in a first signal frame, and the method further includes: Determining a first correlation peak according to the second verification signal and a signal received in the first signal frame, where a time-domain position where the first correlation peak is located is the time-domain position of the first verification signal; Determining a second correlation peak according to the fourth reference signal and a signal received in the first signal frame, where a time-domain position where the second correlation peak is located is the time-domain position of the first reference signal.

5. The method according to any one of claims 2 to 4, characterized in that A time-domain position of the fourth reference signal and a time-domain position of the second verification signal are indicated by configuration information, and the configuration information is used to indicate generation of the fourth reference signal and the second verification signal.

6. The method according to claim 5, wherein The configuration information is used to indicate that a second signal frame includes a plurality of the fourth reference signals and the second verification signals, and a third offset between time-domain positions of every two fourth reference signals in the second signal frame is the same; an offset between a time-domain position of the second verification signal and a time-domain position of a fourth reference signal adjacent to the second verification signal is a fourth offset, and the fourth offset is different from the third offset, or the fourth offset is the same as the third offset.

7. The method according to claim 5 or 6, characterized in that, The method further includes: Receiving the configuration information; Generating the fourth reference signal and the second verification signal according to the configuration information.

8. The method according to claim 7, wherein The configuration information includes an encryption key; generating the second verification signal according to the configuration information includes: encrypting a first bit sequence according to the encryption key to obtain an encrypted first bit sequence; modulating the encrypted first bit sequence to obtain a second symbol for the verification signal; mapping the second symbol to a time domain position of the verification signal indicated by the configuration information to obtain the second verification signal.

9. The method according to any one of claims 1 to 8, characterized in that The method further includes: when the first reference signal is the second reference signal, sending a ranging result; the ranging result is obtained according to the first reference signal and the fourth reference signal.

10. A method for signal verification, characterized in that, The method is applied to a first device and includes: receiving a first reference signal; determining a first time domain position according to the first reference signal, the fourth reference signal, and the second verification signal; acquiring a first signal at the first time domain position; determining whether the first reference signal is a second reference signal from a second device according to the first signal and the second verification signal, where the second reference signal is used by the second device to locate the first device, and the fourth reference signal and the second verification signal are determined by the first device; sending first information to the second device, where the first information is used to indicate whether the first reference signal is the third reference signal.

11. The method according to claim 10, characterized in that, The first time domain position is a time domain position that is spaced apart from the time domain position of the first reference signal by a second offset, and the second offset is an offset between the time domain position of the fourth reference signal and the time domain position of the second verification signal.

12. The method according to claim 11, wherein The acquiring the first signal at the first time domain position includes: acquiring a first symbol for the verification signal at the first time domain position; demodulating the first symbol according to a symbol for demodulating a signal to obtain the first signal.

13. The method according to any one of claims 10 to 12, characterized in that, The determining whether the first reference signal is a second reference signal from a second device according to the first signal and the second verification signal includes: determining whether the first reference signal is the third reference signal from the second device according to whether the first signal matches the second verification signal.

14. The method according to any one of claims 10 to 13, characterized in that, The time domain positions of the fourth reference signal and the second verification signal are indicated by configuration information, and the configuration information is used to indicate the generation of the fourth reference signal and the second verification signal.

15. The method according to claim 14, wherein The configuration information is used to indicate that a second signal frame includes a plurality of the fourth reference signals and the second verification signal, and a third offset of time domain positions between every two fourth reference signals within the second signal frame is the same; an offset of a time domain position between the second verification signal and a fourth reference signal adjacent to the second verification signal is a fourth offset, and the fourth offset is different from the third offset, or the fourth offset is the same as the third offset.

16. The method according to claim 14 or 15, characterized in that, The method further includes: receiving the configuration information; generating the fourth reference signal and the second verification signal according to the configuration information.

17. The method according to claim 16, wherein The configuration information includes an encryption key; generating the second verification signal according to the configuration information includes: Encrypt the first bit sequence according to the encryption key to obtain the encrypted first bit sequence; Modulate the encrypted first bit sequence to obtain a second symbol for the check signal; Map the second symbol to the time domain position of the check signal indicated by the configuration information to obtain the second check signal.

18. The method according to claim 17, characterized in that, The mapping of the second symbol to the time domain position of the check signal to obtain the second check signal includes: Map the second symbol and the symbol for demodulating the signal to the time domain position of the check signal to obtain the second check signal.

19. The method according to any one of claims 10 to 18, characterized in that, The method further includes: When the first reference signal is the second reference signal, send a ranging result obtained based on the first reference signal and the fourth reference signal.

20. The method according to any one of claims 1 to 19, characterized in that The method further includes: Send the first information to a positioning management function (LMF) network element.

21. A method for signal verification, characterized in that, The application of the method to a second device includes: The second device sends a first reference signal and a first check signal to the first device, where the first check signal is used to verify whether the reference signal received by the first device is the first reference signal from the second device; The second device receives the first information from the first device, and the first information is used to indicate whether the reference signal received by the first device is the first reference signal from the second device.

22. The method according to claim 21, wherein Before the second device sends the first reference signal and the first check signal to the first device, the method further includes: The second device obtains configuration information for indicating the generation of the reference signal and the check signal; The second device sends the configuration information to the first device.

23. The method according to claim 22, wherein The obtaining of the configuration information includes: The second device receives the configuration information from the LMF network element or determines the configuration information.

24. The method according to claim 22 or 23, characterized in that, The method further includes: The second device determines the first reference signal and the first check signal according to the configuration information.

25. A communication device, characterized in that, The device includes a module for executing the method according to any one of claims 1-24.

26. A communication device, characterized in that, The communication device includes a processor and a memory; the memory is used to store computer instructions, and when the processor executes the instructions, the method according to any one of claims 1-24 is executed.

27. A communication device, characterized in that, The communication device includes a processor and an interface circuit; the interface circuit is used to receive signals from other communication devices outside the communication device and transmit them to the processor or send signals from the processor to other communication devices outside the communication device, and the processor is used to implement the method according to any one of claims 1-24 through logic circuits or by executing code instructions.

28. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer programs or instructions, and when the computer programs or instructions run on a computer, the computer executes the method according to any one of claims 1-24.

29. A computer program product, characterized in that, The computer program product includes computer programs or instructions, and when the computer programs or instructions run on a computer, the computer executes the method according to any one of claims 1-24.

Citation Information

Patent Citations

  • Signal measurement method, device, equipment, medium and program product

    CN114731263A

  • Partial positioning signaling for preventing new radio positioning attacks

    CN117321967A

  • Methods and apparatus for maintaining transmission integrity and authenticity through channel measurements and reporting

    WO2022271275A1