Communication method and related apparatus
By generating security information by managing nodes, point-to-point links are directly established between slave nodes and security protection, solving the problems of low data transmission efficiency and insufficient security between slave nodes, and improving the overall efficiency and security of the communication system.
Patent Information
- Application Number
- PCT/CN2025/076584
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-20
- Filing Date
- 2025-02-10
- Publication Date
- 2025-08-28
AI Technical Summary
In the communication system, links cannot be directly established between slave nodes, resulting in low data transmission efficiency and insufficient security. Especially when the communication pressure of the master node is high, it is impossible to negotiate secure communication parameters.
Security information is generated and distributed by management nodes, so that point-to-point links are directly established between nodes and data transmission is protected through security algorithms, including encryption and integrity protection.
Direct and secure data transmission between slave nodes is realized, data transmission efficiency is improved, communication pressure of master nodes is reduced, and communication security is improved.
Smart Images

Figure CN2025076584_28082025_PF_FP_ABST
Abstract
Description
A communication method and related device
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on February 20, 2024, with application number 202410193052.9 and application name “A communication method and related device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of communication technology, and in particular to the field of short-range communication technology, such as communications in scenarios such as smart cars, smart homes, smart terminals, and smart manufacturing, and specifically to a communication method and related devices. Background Art
[0003] With the continuous advancement of communication technology, intelligent application scenarios such as smart homes, smart cockpits, smart driving, smart manufacturing, and smart transportation have emerged. These communication systems, enabling diverse business functions, have improved productivity and brought convenience and enjoyment to people's lives. People's demands for the functionality of communication systems are also increasing, leading to a continuous increase in the number and variety of nodes in these systems. In most multi-node communication systems, the identities and communication capabilities of these nodes often vary significantly. This is done to facilitate the management of multi-node systems and to ensure compatibility between nodes with varying computing and communication capabilities. However, these differences in nodes also indirectly limit connectivity between them.
[0004] Some communication systems include master nodes and slave nodes. The master node has strong communication capabilities and the ability to manage slave nodes. It can establish links with multiple slave nodes, allowing communication between the master and slave nodes to achieve various functions. In this type of communication system, slave nodes often do not have the ability to establish links with each other, making communication needs between slave nodes difficult to achieve. When data needs to be transmitted between two slave nodes, they often rely on the master node for forwarding. On the one hand, the communication method of forwarding by the master node will increase the communication pressure on the master node. On the other hand, the slave nodes cannot negotiate parameters related to secure communication, making the data transmission between the two less secure. Summary of the Invention
[0005] The present application provides a communication method and related devices that can support direct and secure data transmission between two nodes managed by other nodes, thereby improving the efficiency of data transmission and enhancing communication security.
[0006] In a first aspect, the present application provides a communication method, comprising: a first node generating first information and sending the first information to a second node, and sending the first information to a third node, wherein the first information is used to securely protect data transmitted between the second node and the third node. The first node is connected to the second node and the third node, respectively, and the second node and the third node are managed by the first node.
[0007] Security protection includes integrity protection and / or confidentiality protection (i.e., encryption / decryption). Management refers to the ability to define, decide, or configure the communication process of another node (e.g., allocating communication resources or setting parameters during the communication process). In some embodiments, the second node and the third node are managed by the first node, i.e., the first node is the node that sends resource management information, and the second node and the third node are the nodes that receive resource management information and send and / or receive data based on the resource management information. Resource management information includes access layer resource management information.
[0008] In the present application, the second node and the third node are two nodes managed by the first node, and the first node generates first information for the two nodes, so that the second node and the third node both perform security protection on the data transmission process between the second node and the third node based on the first information provided by the first node. On the one hand, the present application realizes the direct transmission of data between two nodes managed by other nodes, thereby improving the efficiency of data transmission. On the other hand, the data communicated between the two nodes can be securely protected based on the first information generated and distributed by the first node, thereby improving the security of communication.
[0009] Optionally, the first information can be used to secure a point-to-point link between the second node and the third node. That is, data transmitted between the second node and the third node is specifically transmitted via the communication link between the two nodes. Of course, the present application is also applicable to situations where the first information is used to secure connectionless communication between the two nodes. For example, in some scenarios, the first information can be used to secure data transmitted between the two nodes in a broadcast format.
[0010] Optionally, the method may be executed by a module in the first node, for example, by a chip or a software module.
[0011] In one possible implementation of the first aspect, sending the first information to the second node includes: sending a first message to the second node, the first information being carried in the first message. The first message is used to instruct the second node to establish a link with a third node. For example, the first message has a specific format or carries special information to instruct the second node to establish a link with the third node. Exemplarily, the first message carries configuration information for the link, and the second node can establish a link with the third node based on the configuration information for the link. Optionally, the configuration information for the link is included in the resource management information.
[0012] In the above embodiment, the second node and the third node may be instructed by the first node to establish a point-to-point link between them. The first information may be carried in the first message, which can reduce the amount of signaling in the link establishment process and improve transmission efficiency.
[0013] In this document, a link refers to a point-to-point, direct link between two nodes. In some scenarios, it may also be referred to as a bearer (e.g., an access layer bearer), a connection, or an association. For example, the first node may be a management node (or G-node), and the second and third nodes may be terminal nodes (or T-nodes). The first message may be, for example, an asynchronous TT link establishment indication, indicating the establishment of a TT link (or TT link) between the second and third nodes. A TT link is a link between T-nodes.
[0014] In another possible implementation of the first aspect, sending the first information to the third node includes sending a second message to the third node, where the first information is carried in the second message. The second message is used to instruct the third node to establish a communication link with the second node, for example, the second message is an asynchronous TT link establishment instruction.
[0015] Optionally, the second message carries configuration information of the link, and the third node may establish a link with the second node based on the configuration information of the link.
[0016] In another possible implementation of the first aspect, the first information sent to the second node is carried in a third message, and the third message is different from the first message. The third message is, for example, security parameter indication information.
[0017] In another possible implementation of the first aspect, the method further includes: sending a first message to the second node, wherein the first message is used to instruct the second node to establish a communication link with the third node.
[0018] Furthermore, the first information is not carried in the first message. In this embodiment, the first node sends the first message to the second node to instruct the second node to establish a communication link with the third node, and sends the first information to the second node via an additional message (such as the third message), making the message function more refined and refined, and improving the reusability and combination flexibility of the message format.
[0019] In another possible implementation of the first aspect, the method further includes: sending a second message to the third node, where the second message is used to instruct the third node to establish a communication link with the second node. Further, the first information is not carried in the second message.
[0020] In another possible implementation of the first aspect, the first information sent to the third node is carried in a fourth message. The fourth message is different from the second message, and the fourth message is, for example, security parameter indication information.
[0021] In another possible implementation of the first aspect, the first information includes a first indication, wherein the first indication is carried in a first field, and a value of the first field may indicate a startup state of encryption and integrity protection of a link between the second node and the third node.
[0022] Exemplarily, when the first field is a first value, it indicates that encryption and integrity protection are simultaneously enabled for the link between the second node and the third node. When the first field is a second value, it indicates that encryption is not enabled for the link between the second node and the third node, but integrity protection is enabled. When the first field is a third value, it indicates that encryption is enabled for the link between the second node and the third node, but integrity protection is not enabled. When the first field is a fourth value, it indicates that encryption is enabled for the link between the second node and the third node, but integrity protection is not enabled.
[0023] Optionally, the first indication is included in the first message or the third message. Similarly, the first indication is included in the second message or the fourth message. For the relevant values of the first indication, see the above.
[0024] In another possible implementation of the first aspect, the first message includes a second indication, and the second indication is used to instruct the second node to send data first or later, wherein the node that sends data first is the first-sending node, and the node that sends data later is the second-sending node.
[0025] For example, the second indication is carried in the second field, and the value of the second field may indicate whether the second node sends the data first or later.
[0026] In another possible implementation of the first aspect, the second message includes a third indication, where the third indication is used to instruct the third node to send the data first or later. For example, the third indication is carried in a third field, and a value of the third field can indicate whether the second node sends the data first or later.
[0027] In another possible implementation of the first aspect, the first information may include one or more of a security algorithm indication, a key indication, an indication of parameters involved in the security algorithm, or a security-related status indication. The security algorithm includes one or more of an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, or a key agreement algorithm. A key is a confidential parameter input during the execution of a security algorithm. Parameters involved in the security algorithm are parameters input during the execution of the security algorithm in addition to the key, such as encryption salts or freshness parameters, thereby further improving security. The security-related status indication may be used to configure status parameters. For example, the security-related status indication may include a first indication indicating whether encryption and / or integrity protection is enabled.
[0028] Optionally, the first information may be sent via one message or multiple messages.
[0029] In another possible implementation of the first aspect, the first information includes one or more of the following information: an integrity protection algorithm indication, an integrity protection key indication, an encryption algorithm indication, an encryption key indication, a first parameter or a first indication, etc.
[0030] The integrity protection algorithm indication is used to indicate the first integrity protection algorithm used for the link between the second node and the third node. Optionally, the first integrity protection algorithm is the algorithm with the highest priority among the integrity protection algorithms supported by the second node and the third node, or the first integrity protection algorithm may be the algorithm selected by the first node. The integrity protection key indication is used to indicate the key used by the integrity protection algorithm (e.g., the first integrity protection algorithm). The encryption algorithm indication is used to indicate the first encryption algorithm used for the link between the second node and the third node. Optionally, the first encryption algorithm is the algorithm with the highest priority among the encryption algorithms supported by the second node and the third node, or the first encryption algorithm may be the algorithm selected by the first node. The encryption key indication is used to indicate the key used by the encryption algorithm (e.g., the first encryption algorithm). The first parameter is used to obtain the input parameter of the encryption and / or integrity protection process between the second node and the third node, for example, the first parameter is an initialization base value or an initialization vector.
[0031] In a second aspect, the present application provides a communication method, comprising: receiving first information from a first node, and performing security protection on first data based on the first information, wherein the first data is data transmitted between a second node and a third node.
[0032] The method is applied to the second node. Optionally, the method may be executed by a module in the second node, such as a chip or a software module.
[0033] In a possible implementation of the second aspect, receiving the first information from the first node includes: receiving a first message from the first node, the first information being carried in the first message, wherein the first message is used to instruct the second node to establish a connection with the third node.
[0034] In another possible implementation of the second aspect, the method further includes: receiving a first message from the first node, wherein the first message is used to instruct the second node to establish a connection with the third node.
[0035] In yet another possible implementation of the second aspect, the method further includes: establishing a communication link with a third node.
[0036] In another possible implementation of the second aspect, the first information includes one or more of the following information: an integrity protection algorithm indication, an integrity protection key indication, an encryption algorithm indication, an encryption key indication, or a first parameter.
[0037] The integrity protection algorithm indicator indicates the first integrity protection algorithm used for the link between the second node and the third node. Optionally, the first integrity protection algorithm is the highest-priority algorithm among the integrity protection algorithms supported by the second and third nodes, or the first integrity protection algorithm may be an algorithm selected by the first node. The integrity protection key indicator indicates the key used by the integrity protection algorithm. The encryption algorithm indicator indicates the first encryption algorithm used for the link between the second node and the third node. Optionally, the first encryption algorithm is the highest-priority algorithm among the encryption algorithms supported by the second and third nodes, or the first encryption algorithm may be an algorithm selected by the first node.
[0038] The encryption key indicator is used to indicate the key used by the encryption algorithm. The first parameter is used to obtain input parameters for the encryption and / or integrity protection process between the second node and the third node. For example, the first parameter is an initialization base value or an initialization vector.
[0039] In yet another possible implementation of the second aspect, the first information includes an integrity protection algorithm indication and an integrity protection key indication, where the integrity protection algorithm indication is used to indicate a first integrity protection algorithm, and the integrity protection key indication is used to indicate an integrity protection key. Security protection of the first data based on the first information includes: performing integrity protection on the first data based on the first integrity protection algorithm and the integrity protection key.
[0040] In another possible implementation of the second aspect, the first information includes an integrity protection algorithm indication, where the integrity protection algorithm indication is used to indicate a first integrity protection algorithm. Security protection of the first data based on the first information includes: performing integrity protection on the first data based on the first integrity protection algorithm and an integrity protection key. The integrity protection key is negotiated between the second node and the third node.
[0041] In another possible implementation of the second aspect, the first information includes an integrity protection key indication, where the integrity protection key indication is used to indicate the integrity protection key. Security protection of the first data based on the first information includes: performing integrity protection on the first data based on a first integrity protection algorithm and the integrity protection key. The first integrity protection algorithm is negotiated between the second node and the third node.
[0042] In another possible implementation of the second aspect, integrity protection is performed on the first data based on the first integrity protection algorithm and the integrity protection key, including: calculating an integrity check code based on the first integrity protection algorithm, the integrity protection key, the first integrity protection input and the first data.
[0043] The integrity check code is used to check the integrity of the first data. For example, the integrity check code and the first data may be carried in the same data packet.
[0044] In yet another possible implementation of the second aspect, the first integrity protection input includes a direction indication and / or a second parameter.
[0045] The direction indicator is used to indicate the order in which the sender and receiver of the first data are to send data in an event. For example, when the direction indicator is at the fifth value, it indicates that the first-sending node sends data and the second-sending node receives data, i.e., the first data is data sent by the first-sending node to the second-sending node. When the direction indicator is at the sixth value, it indicates that the second-sending node sends data and the first-sending node receives data, i.e., the first data is data sent by the second-sending node to the first-sending node.
[0046] The first-sending node is the node that sends data first in an event, and the second-sending node is the node that sends data last in an event.
[0047] In one implementation, the second parameter is related to the first parameter included in the first information. For example, the first parameter is an initialization base value of A bits, and the initialization base value is processed (for example, XOR, XOR processing) based on another bit sequence (for example, B bits), and the final value obtained is used as the second parameter, where A and B are integers greater than or equal to 1. Optionally, the aforementioned bit sequence of B bits may be related to the radio frame type. Exemplarily, the second parameter occupies 64 bits, where the initialization base value is a 64-bit value generated by a random number generator, and for radio frame type 1 and radio frame type 2, the final value (64 bits) is obtained by XORing the lower 32 bits of the initialization base value with the lower 32 bits of the synchronization sequence. For radio frame type 3 and radio frame type 4, the final value is obtained by XORing the lower 24 bits of the initialization base value with the 24 bits of the logical link identifier.
[0048] In another implementation, the second parameter is related to a third parameter from the second node and / or a fourth parameter from the third node. For example, the second node provides the third parameter and the third node provides the fourth parameter, and the second node derives the second parameter based on the third and fourth parameters. Exemplarily, the second node sends the third parameter (e.g., 32 bits) to the third node, and the third node sends the fourth parameter (32 bits) to the second node, and the second parameter is a 64-bit value obtained by concatenating the third and fourth parameters.
[0049] In another possible implementation of the second aspect, the first data is carried in a payload of a transmission data packet. The integrity check code is calculated based on a first integrity protection algorithm, an integrity protection key, a first integrity protection input, and the first data, including: obtaining a first output based on the first integrity protection algorithm, the integrity protection key, and the first integrity protection input; obtaining a second output based on the first integrity protection algorithm, the integrity protection key, the first output, and the second integrity protection input; and obtaining an integrity protection output corresponding to the first byte of the payload based on the first integrity protection algorithm, the integrity protection key, the second output, and first M bytes of the payload of the transmission data packet, where M is an integer and M ≥ 1.
[0050] When the payload of the transmitted data packet is less than or equal to M bytes, the integrity protection output of the first byte of the corresponding payload is the final output. When the payload of the transmitted data packet is greater than M bytes, based on the first integrity protection algorithm, the integrity protection key and the integrity protection output of the i-1th M bytes of the corresponding payload, the integrity protection output of the i-th M bytes of the corresponding payload is obtained, and the integrity protection output of the last part of the bytes of the corresponding payload is taken as the final output, where i is an integer and i ranges from 1 to The integrity check code is obtained based on the final output. Represents the integer obtained by rounding x upwards.
[0051] Optionally, obtaining the integrity check code according to the final output includes: using the lower X bits of the final output as the integrity check code.
[0052] In another possible implementation of the second aspect, the first information includes an encryption algorithm indication and an encryption key indication, where the encryption algorithm indication is used to indicate a first encryption algorithm, and the encryption key indication is used to indicate an encryption key. Securely communicating with the third node based on the first information includes encrypting the first data based on the first encryption algorithm and the encryption key.
[0053] In another possible implementation of the second aspect, the first information includes an encryption algorithm indication, where the encryption algorithm indication is used to indicate a first encryption algorithm. Securely communicating with the third node based on the first information includes: encrypting the first data based on the first encryption algorithm and an encryption key, where the encryption key is negotiated between the second node and the third node.
[0054] In another possible implementation of the second aspect, the first information includes an encryption key indication, where the encryption key indication is used to indicate the encryption key. Securely communicating with the third node based on the first information includes: encrypting the first data based on a first encryption algorithm and the encryption key, where the first encryption algorithm is negotiated between the second node and the third node.
[0055] In another possible implementation of the second aspect, encrypting the first data based on the first encryption algorithm and the encryption key includes: encrypting the first data based on the first encryption algorithm, the encryption key and the encryption input.
[0056] The encrypted input includes a direction indication and / or a second parameter.
[0057] In a possible implementation of the second aspect, the first data is carried in the payload of the transmission data packet, and the first data is encrypted based on the first encryption algorithm and the encryption key, including: for all bytes of the payload, based on the first encryption algorithm, the encryption key, the j-th K bytes of the payload and the encrypted input corresponding to the j-th K bytes, obtaining the j-th encrypted output, where j is an integer and j is 1 to Integer between .
[0058] In a possible implementation of the second aspect, when integrity protection between the second node and the third node is enabled, an encrypted integrity check code is obtained based on the first encryption algorithm, the encryption key, the integrity check code, and the encrypted input of the corresponding integrity check code.
[0059] In another possible implementation of the second aspect, the first message includes a first indication, the first indication is carried in a first field, and the value of the first field can indicate the startup status of encryption and integrity protection of the link between the second node and the third node.
[0060] In another possible implementation of the second aspect, the first message includes a second indication, where the second indication is used to instruct the second node to send the data first or later. For example, the second indication is carried in a second field, and a value of the second field can indicate whether the second node sends the data first or later.
[0061] In a third aspect, the present application provides a communication method, comprising: receiving a first message from a first node, establishing a link with a third node, negotiating with the third node to determine first information, and performing security protection on first data based on the first information. The first message is used to instruct a second node to establish a link with the third node, and the first data is data transmitted between the second node and the third node.
[0062] The method is applied to the second node. Optionally, the method may be executed by a module in the second node, such as a chip or a software module.
[0063] In another possible implementation of the third aspect, the first information includes one or more of the following information: an integrity protection algorithm indication, an integrity protection key indication, an encryption algorithm indication, an encryption key indication, or a first parameter.
[0064] In another possible implementation of the third aspect, security protection is performed on the first data based on the first information, including: performing integrity protection on the first data based on a first integrity protection algorithm and an integrity protection key.
[0065] In another possible implementation of the third aspect, securely communicating with the third node based on the first information includes: encrypting the first data based on a first encryption algorithm and an encryption key.
[0066] In another possible implementation of the third aspect, the first message includes a first indication, the first indication is carried in a first field, and the value of the first field can indicate the startup status of encryption and integrity protection of the link between the second node and the third node.
[0067] In another possible implementation of the third aspect, the first message includes a second indication, where the second indication is used to instruct the second node to send the data first or later.
[0068] In a fourth aspect, the present application provides a communication device, comprising a unit or module for executing the method described in the first aspect or any possible implementation of the first aspect, or comprising a unit or module for executing the method described in the second aspect or any possible implementation of the second aspect, or comprising a unit or module for executing the method described in the third aspect or any possible implementation of the third aspect.
[0069] Exemplarily, the communication device includes a processing unit and a communication unit, wherein the processing unit is used to implement one or more operations such as processing, determining, generating, calculating, encrypting, and decrypting, and the communication unit is used to implement one or more operations such as sending and receiving.
[0070] In a fifth aspect, the present application provides a communication device, which includes a processor and an interface circuit, wherein the interface circuit is used to receive signals from other communication devices and transmit them to the processor or send signals from the processor to other communication devices, and the processor is used to implement the method described in the first aspect or any possible implementation of the first aspect through a logic circuit or execution code instructions, or to implement the method described in the second aspect or any possible implementation of the second aspect, or to implement the method described in the third aspect or any possible implementation of the third aspect.
[0071] In a sixth aspect, the present application provides a communication system, which includes a first node, a second node, and a third node. The first node is used to implement the method described in the first aspect or any possible implementation method of the first aspect, and the second node and the third node are used to implement the method described in the second aspect or any possible implementation method of the second aspect.
[0072] In the seventh aspect, the present application provides a communication system, which includes a first node, a second node and a third node, the second node is used to send a first message to the second node and to send the second message to the third node, and the second node and the third node are used to implement the method described in the third aspect or any possible implementation method of the third aspect.
[0073] In an eighth aspect, the present application provides a terminal, which includes the communication device described in the fourth aspect or the fifth aspect, or includes the communication system described in the sixth aspect or the seventh aspect.
[0074] In the ninth aspect, the present application provides a readable storage medium, which is used to store a computer program. When the computer program is executed by a processor, the communication device including the processor implements the method described in the first aspect or any possible implementation of the first aspect, or implements the method described in the second aspect or any possible implementation of the second aspect, or implements the method described in the third aspect or any possible implementation of the third aspect.
[0075] In the tenth aspect, the present application provides a computer program, which, when executed by a processor, enables a communication device including the processor to implement the method described in the first aspect or any possible implementation of the first aspect, or implement the method described in the second aspect or any possible implementation of the second aspect, or implement the method described in the third aspect or any possible implementation of the third aspect.
[0076] The beneficial effects of the second to tenth aspects of this application can refer to the beneficial effects of the solution of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0077] The following is a brief introduction to the drawings required for describing the embodiments.
[0078] FIG1 is an architecture diagram of a communication system;
[0079] FIG2 is a schematic diagram of an application scenario of a communication system;
[0080] FIG3 is a schematic diagram of an application scenario of a communication system provided in an embodiment of the present application;
[0081] FIG4 is a schematic diagram of an application scenario of another communication system provided in an embodiment of the present application;
[0082] FIG5 is a flow chart of a communication method provided in an embodiment of the present application;
[0083] FIG6 is a schematic diagram of an integrity protection process provided in an embodiment of the present application;
[0084] FIG7 is a schematic diagram of data content of an integrity protection input provided by an embodiment of the present application;
[0085] FIG8 is a schematic diagram of an encryption process provided in an embodiment of the present application;
[0086] FIG9 is a schematic diagram of encrypted input data content provided by an embodiment of the present application;
[0087] FIG10 is a flow chart of a communication method according to an embodiment of the present application;
[0088] FIG11 is a flow chart of a communication method according to an embodiment of the present application;
[0089] FIG12 is a flow chart of another communication method provided in an embodiment of the present application;
[0090] FIG13 is a flow chart of another communication method provided in an embodiment of the present application;
[0091] FIG14 is a flow chart of another communication method provided in an embodiment of the present application;
[0092] FIG15 is a schematic structural diagram of a communication device provided in an embodiment of the present application;
[0093] FIG16 is a schematic structural diagram of another communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0094] The following is an introduction to some technical terms.
[0095] 1. Message Check Code
[0096] A message check code (MAC), also known as an integrity check, message authentication code (MAC), message authentication code, file message authentication code, or information authentication code (MAC), is a small piece of information generated by a specific algorithm and used to check the integrity of a message and / or authenticate the identity of the message.
[0097] 2. Node
[0098] A node is a device with communication capabilities, including but not limited to one or more of user equipment, network equipment, and industrial equipment. User equipment includes one or more of handheld terminals, wearable terminals, vehicles, in-vehicle devices, sensor devices, smart home devices, or leisure and entertainment devices. Handheld terminals include but are not limited to mobile phones, tablets, or laptops. Wearable devices include but are not limited to headphones, smart bracelets, smart watches, or smart glasses. Vehicles include but are not limited to vehicles, ships, aircraft, rail transit (such as subways and high-speed trains), or logistics robots (such as automated guided vehicles (AGVs)). In-vehicle devices include but are not limited to domain controllers (DCs), screens, microphones, speakers, electronic keys, keyless entry, starter system controllers, battery management systems (BMSs), battery packs, or battery cells. Sensor devices include but are not limited to cameras, radars, lidars, light sensors, temperature sensors, or humidity sensors. Smart home devices include but are not limited to projectors, smart TVs, smart refrigerators, smart home gateways, and security devices. Leisure and entertainment equipment includes, but is not limited to, virtual reality (VR) devices, mixed reality (MR) devices, massage chairs, home theaters, game consoles, or 4D cinema cabins. Network equipment includes, but is not limited to, routers, switches, or base stations. Industrial equipment includes, but is not limited to, industrial robots or robotic arms.
[0099] It should be understood that the communication method, communication device, communication system or node of the embodiments of the present application are applicable to a variety of networks, for example, a wired communication network, a wireless communication network, or a network formed by a combination of wired communication and wireless communication. For example, the wireless communication network includes a network connected by the following communication technologies: SparkLink (or NearLink), 802.11b / g, Bluetooth (blue tooth), Zigbee, radio frequency identification technology (RFID), ultra-wideband (UWB) technology, or a wireless short-range communication system. And / or, the wireless communication network includes a long-range connection technology including a communication technology based on long term evolution (long term evolution), fifth generation mobile communication technology (5th generation mobile networks or 5th generation wireless systems, 5th-Generation, referred to as 5G or 5G technology), global system for mobile communications (GSM), general packet radio service (GPRS), universal mobile telecommunications system (UMTS) and other wireless communication technologies. For example, the wired communication network includes a network connected by the following communication technologies: one or more of fiber optic connection technology, vehicle-mounted wired communication technology, controller area network (CAN), local interconnect network bus (LIN), CAN flexible data-rate (CAN FD), or vehicle-mounted Ethernet.
[0100] The nodes in the embodiments of the present application can be applied to various scenarios such as smart cars, smart homes, smart terminals, smart manufacturing, smart exhibition halls, mobile internet (MI), industrial control, self-driving, transportation safety, or the Internet of Things (IoT). In some application scenarios or certain network types, similar devices with communication capabilities may not be called nodes. However, for the convenience of description, in the embodiments of the present application, devices with communication capabilities are collectively referred to as nodes.
[0101] 3. Communication system
[0102] A communication system is a system that uses electrical (or optical) signals to transmit information. It typically includes multiple nodes that communicate with each other to transmit information. Nodes in a communication system may have different identities and / or capabilities. In most communication systems, nodes are divided into master nodes and slave nodes. Master nodes have strong communication capabilities and the ability to manage slave nodes. They can establish links with multiple slave nodes, enabling communication between master nodes and between master nodes and slave nodes to achieve various functions.
[0103] Figure 1 shows the architecture of a communication system, which includes a management node (considered as a master node) and terminal nodes (considered as slave nodes). The terminal nodes are connected to the management node, and the connection relationship is represented by a dotted line. The communication between the management node and the terminal nodes includes bidirectional unicast and / or broadcast communication.
[0104] Among them, the management node has communication capabilities and management capabilities, and is also called G node, access point, or authorization node in some scenarios. Management capabilities include communication management capabilities, such as the ability to perform connection management, resource scheduling, or information security management. Exemplarily, the management node can send resource management information or data scheduling information, such as access layer resource management information. The terminal node, also called T node in some scenarios, is a node with communication capabilities that can transmit services with the management node. In some schemes, the terminal node is a node that receives resource management information (or data scheduling information) and sends data according to the resource management information (or data scheduling information). Exemplarily, the terminal device may include user equipment (UE), such as barcodes, radio frequency identification (RFID), sensors, global positioning systems (GPS), lidars, battery cells and other devices.
[0105] It should be understood that the identities of management nodes and terminal nodes are not absolute; they are merely exemplary names used to facilitate distinguishing the operations performed by communicating nodes in a possible connection scenario. In some scenarios, a node may belong to two or more communication domains simultaneously, acting as a terminal node in some communication domains and a management node in others. To facilitate understanding, such nodes are represented as G(T) nodes in some embodiments.
[0106] The above explanations of technical terms may be optionally applied to the following embodiments.
[0107] In combination with the above, in some communication systems including master nodes and slave nodes, the slave nodes often do not have the ability to establish links, making it difficult to achieve communication requirements between slave nodes. Please refer to Figure 2, which is a schematic diagram of an application scenario of a communication system. The vehicle includes four location anchor points, namely T1 node, T2 node, T3 node and T4 node. The four location anchor points are connected to the vehicle's master node (i.e., G node), and the T1 node, T2 node, T3 node and T4 node can establish GT links with the G node respectively. Location tags (such as mobile phones, car keys, etc.), namely T5 nodes, can also be connected to the G node and establish a GT link with the G node.
[0108] In a measurement scenario, measurements are performed between a location tag and a location anchor. The measurement results of the location tag and the location anchor are sent to the G node via the GT link. The G node then performs the calculations, such as locating the location tag. As shown in Figure 2, taking the measurement process between nodes T1 and T5 as an example, nodes T1 and T5 exchange measurement frames and obtain their own measurement results. Each node reports these results to the G node. In a specific implementation, the number of location anchors for interactive measurement is typically multiple, and the measurement process must be performed multiple times. This results in a high computational load for the master node (G node) and a slow measurement result calculation speed. Distributing the calculation function to each location anchor can significantly improve the measurement result calculation speed. However, when the measurement result calculation is distributed to the location anchor, the location tag's measurement results must be provided to the location anchor. For example, in Figure 2, the measurement results of node T5 must be provided to node T1. Since T nodes often lack the ability to establish links, communication between them is difficult to achieve. If forwarding through G nodes is considered, the communication pressure on the G nodes will also increase. Moreover, the parameters related to secure communication cannot be negotiated between T nodes, making the data transmission security between T nodes low, threatening the communication security of the nodes and thus affecting the safety of the entire vehicle.
[0109] In view of this, the present application provides a communication method and related devices that can support direct and secure data transmission between two nodes managed by other nodes, improve the efficiency of data transmission and enhance communication security.
[0110] Referring to Figure 3 , in one embodiment, node G sends first information to node T1 and node T5, respectively. This first information is security-related parameters. Based on the first information, node T1 and node T5 implement security protection for data transmitted between them. Furthermore, node G also sends link configuration information to node T1 and node T5, enabling node T1 and node T5 to establish a TT link based on the link configuration information. Referring to Figure 4 , in yet another embodiment, node G sends link establishment instructions to node T1 and node T5, respectively. Node T1 and node T5 establish the TT link based on the link establishment instructions, which may include link configuration information. Node T1 and node T5 may negotiate to obtain the first information and, based on the first information, implement security protection for data transmitted between them. Optionally, the above embodiments may be combined. That is, some of the information used for data security protection may be provided by node G, while some may be negotiated between node T1 and node T5.
[0111] In the above embodiment, measurement results are transmitted directly and securely between nodes T1 and T5 without forwarding through node G. This improves data transmission efficiency and reduces communication pressure and computation on the master node. Because the data transmitted between T1 and T5 is protected by the first information, communication security is enhanced.
[0112] Of course, the above only takes the ranging process as an example, and uses T1, T5 and G nodes as examples for explanation. In the specific implementation process, it is also applicable to similar technical problems, and is also applicable to scenarios with similar problems and communication systems including more or fewer nodes.
[0113] The method provided by this application is described below.
[0114] Please refer to Figure 5, which is a flow chart of a communication method provided in an embodiment of the present application. Optionally, the method can be applied to a communication system, such as one or more communication systems in Figures 1 to 4 above. The communication method shown in Figure 5 may include one or more steps from step S501 to step S504. It should be understood that for the convenience of description, the description is given in the order of steps S501 to S504, and it is not intended to limit the execution to the above order. The embodiment of the present application does not limit the order of execution, execution time, number of executions, etc. of the above one or more steps. Steps S501 to S504 are as follows:
[0115] Step S501: The first node generates first information.
[0116] The first information is a parameter related to communication security. As a possible implementation, the first information includes one or more of a security algorithm indication, a key indication, an indication of parameters involved in the security algorithm, or a security-related status indication. The security algorithm includes one or more of an encryption algorithm, an integrity protection algorithm, a key derivation algorithm, or a key agreement algorithm. A key is a confidential parameter input during the execution of a security algorithm. Parameters involved in a security algorithm are parameters input during the execution of a security algorithm in addition to the key, such as encryption salts or freshness parameters, thereby further improving security. The security-related status indication can be used to configure status parameters. For example, the security-related status indication may include a first indication (described below), which is used to indicate the activation status of encryption and / or integrity protection.
[0117] In some possible implementations, the first information includes one or more of the following information: an integrity protection algorithm indication, an integrity protection key indication, an encryption algorithm indication, an encryption key indication, a first parameter, or a first indication. Exemplarily, the first information includes the integrity protection algorithm indication, the integrity protection key indication, the encryption algorithm indication, the encryption key indication, the first parameter, and the first indication. Furthermore, the first information includes the integrity protection algorithm indication. Furthermore, the first information includes the encryption algorithm indication. Furthermore, the first information includes the integrity protection algorithm indication and the encryption algorithm indication. Furthermore, the first information includes the integrity protection algorithm indication, the integrity protection key indication, the encryption algorithm indication, and the encryption key indication.
[0118] The integrity protection algorithm indicator indicates the integrity protection algorithm used for the link between the second node and the third node. For ease of description, this is referred to as the first integrity protection algorithm and can be, for example, the AES-128 algorithm or the SM4 algorithm. For example, referring to Table 1, when the integrity protection algorithm indicator is 0100, the link between the second node and the third node uses the "INT1" algorithm for integrity protection. For another example, when the integrity protection algorithm indicator is 1000, the link between the second node and the third node uses the "AUTH1" algorithm for integrity protection.
[0119] Table 1 Security algorithm information table
[0120] In some implementations, the first integrity protection algorithm is the highest-priority algorithm among the integrity protection algorithms supported by the second and third nodes. For example, if the second node supports INT1, INT2, and INT4, and the third node supports INT1, INT2, INT3, and INT4, and the integrity protection algorithms supported by the second and third nodes have priorities of INT1, INT2, and INT4, respectively (where lower numbers indicate higher priorities), then INT1 is the first integrity protection algorithm. In other words, the first node may select the highest-priority algorithm among the integrity protection algorithms supported by the second and third nodes as the first integrity protection algorithm. Of course, the aforementioned implementations are merely examples. In some implementations, the first node may determine the first integrity protection algorithm using other methods, such as selecting a particular integrity protection algorithm as the first integrity protection algorithm based on other rules.
[0121] The integrity protection key indication is used to indicate the key used by the integrity protection algorithm.
[0122] The encryption algorithm indicator is used to indicate the first encryption algorithm used for the link between the second and third nodes. For example, it can be the AES-128 algorithm, the SM4 algorithm, or the like. Referring to Table 1, when the encryption algorithm indicator is 0000, the link between the second and third nodes is encrypted using the "ENC0" algorithm. For another example, when the encryption algorithm indicator is 1000, the link between the second and third nodes is encrypted using the "AUTH1" algorithm. It is not difficult to see that the encryption algorithm and the integrity protection algorithm may use the same algorithm.
[0123] Optionally, the first encryption algorithm is the algorithm with the highest priority among the encryption algorithms supported by the second node and the third node, or the first encryption algorithm may be the algorithm selected by the first node.
[0124] The encryption key indicator is used to indicate the key used by the encryption algorithm.
[0125] The first parameter is used to obtain input parameters for the encryption and / or integrity protection process between the second node and the third node. For example, the first parameter is an initialization base value, which is a 64-bit data randomly generated by the first node. In another example, the first parameter is a parameter obtained by processing a 64-bit random number, such as 64 bits of data obtained by XORing some or all bits of the 64-bit random number with a bit sequence. Of course, the aforementioned number of bits is only an example and can be replaced by other bit numbers in specific implementations.
[0126] Step S502: The first node sends first information to the second node.
[0127] Correspondingly, the second node receives the first information from the first node, where the first information is used to securely protect data transmitted between the second node and the third node.
[0128] The first node is connected to the second node and the third node respectively. Referring to Figure 5, a communication link is established between the first node and the second node. For example, the first node is a G node, the second node is a T node, and the third node is a T node. A connection is established between the first node and the second node, and a connection is also established between the first node and the third node.
[0129] Furthermore, the second node is managed by the first node. Management refers to the ability to define, decide, or configure the communication process of another node (for example, allocating communication resources or setting parameters during the communication process). In some embodiments, the second node and the third node are managed by the first node, that is, the first node is the node that sends resource management information, and the second node and the third node are the nodes that receive resource management information and send or receive data based on the resource management information. Exemplarily, the resource management information includes access layer resource management information.
[0130] Optionally, the first information may be sent via one message or multiple messages.
[0131] In one possible implementation, the first information is carried in (i.e., carried in) a first message and sent to the second node. The first message is used to instruct the second node to establish a link with the third node. For example, the first message has a specific format or carries special information to instruct the second node to establish a link with the third node. Exemplarily, the first message carries the configuration information of the link, and the second node can establish a link with the third node based on the configuration information of the link. In some schemes, the first message is also called an asynchronous TT link establishment indication to indicate the establishment of a TT link (or TT link) between the second node and the third node, and the TT link is a link between T nodes and T nodes. Of course, this application does not strictly limit the name of the message. In a specific implementation, the name of the message, the name of the information, and the name of the parameter can be replaced arbitrarily. In some implementations, the configuration information of the link belongs to resource management information (or access layer resource management information).
[0132] Please refer to Tables 2 and 3, which are schematic diagrams of the message format for an asynchronous TT link establishment indication provided in an embodiment of the present application. The asynchronous TT link establishment indication includes link configuration information, such as a send-before-send indication, a radio frame type indication, a logical link identifier, a bandwidth indication, a pilot density indication, a maximum protocol data unit value, or a maximum time offset. For details, see Table 2 and are not further described here. In this way, the second node can configure a link with the third node based on the link configuration information.
[0133] Table 2 Field name, signaling bit width, signaling value range and quantity unit of asynchronous TT link establishment indication
[0134] Table 3 Field names and signaling descriptions of asynchronous TT link establishment indication
[0135] In another possible implementation, a first node sends a first message to a second node, instructing the second node to establish a link with a third node. However, the first information is not included in the first message but is instead indicated via an additional message, for example, a third message. In some implementations, the third message is referred to as security parameter information.
[0136] In some embodiments, the first node also sends a first indication to the second node. The first indication is carried in the first field. The value of the first field may indicate the activation status of encryption and integrity protection for the link between the second node and the third node. For example, in conjunction with Table 3, the first indication is indicated by an 8-bit field. When the first field is a first value (e.g., 0), it indicates that encryption and integrity protection are simultaneously activated for the link between the second node and the third node. When the first field is a second value (e.g., 1), it indicates that encryption is not activated but integrity protection is activated for the link between the second node and the third node. When the first field is a third value (e.g., 2), it indicates that encryption is activated but integrity protection is not activated for the link between the second node and the third node. When the first field is a fourth value (e.g., 3), it indicates that encryption is activated but integrity protection is not activated for the link between the second node and the third node. In some scenarios, the first indication may be referred to as an encryption and integrity protection indication. Furthermore, the first indication may include two indications, one indicating the activation status of encryption and the other indicating the activation status of integrity protection.
[0137] In some embodiments, the first indication is included in the first message. In still other embodiments, the first indication may be carried in the first message, with the first field being a field in the first message. Alternatively, the first indication may be carried in a third message, with the first field being a field in the first message. Of course, the first indication may be carried in another message sent to the second node, for example, carried in a fifth message that is different from the first and third messages.
[0138] In some embodiments, the first node further sends a second indication to the second node, the second indication being used to instruct the second node to send data first or later. For example, the second indication is carried in a second field, and the value of the second field can indicate whether the second node should send data first or later. The node that sends data first in an event is the first-sending node, and similarly, the node that sends data later in an event is the second-sending node.
[0139] Optionally, the second indication may be carried in the first message, and the second field is a field in the first message. Alternatively, the second indication may be carried in a third message, and the second field is a field in the third message.
[0140] Step S503: The first node sends first information to the third node.
[0141] Accordingly, the third node receives the first information from the first node.
[0142] The first information is used to securely protect data transmitted between the second node and the third node. The first node is connected to the third node. Referring to Figure 5 , a communication link is established between the first node and the third node. For example, the first node is a G node and the third node is a T node, and a GT link is established between the first and third nodes. Furthermore, the third node is managed by the first node.
[0143] In one possible implementation, the first information is carried in (i.e., included in) a second message and sent to the third node. The second message is used to instruct the third node to establish a link with the second node. For related descriptions, see the aforementioned introduction to the second message. In some solutions, the first message is also referred to as an asynchronous TT link establishment indication.
[0144] In another possible implementation, the first node sends a second message to the third node, where the second message instructs the third node to establish a link with the second node. However, the first information is not included in the second message but is instead indicated via an additional message, for example, a fourth message. In some implementations, the fourth message is referred to as security parameter information.
[0145] In some embodiments, the first node further sends a first indication to the third node. The first indication is carried in a first field, and the value of the first field may indicate the activation status of encryption and integrity protection for the link between the second and third nodes. Optionally, the first indication is included in the first message. Optionally, the first indication may be carried in a second message, with the first field being a field in the second message. Alternatively, the first indication may be carried in a fourth message, with the first field being a field in the fourth message.
[0146] In some implementations, the first node further sends a third indication to the third node, where the third indication is used to instruct the third node to send data first or later. For example, the third indication is carried in a third field, and the value of the third field can instruct the third node to send data first or later.
[0147] Optionally, the third indication may be carried in the second message, and the third field is a field in the second message. Alternatively, the third indication may be carried in the fourth message, and the third field is a field in the fourth message.
[0148] Step S504: The second node performs security protection on the first data based on the first information.
[0149] The first data is data transmitted between the second node and the third node, and security protection includes encryption and / or integrity protection. Several possible implementation methods are listed below:
[0150] In implementation mode 1, the second node performs integrity protection on the first data based on the first integrity protection algorithm and the integrity protection key. Optionally, the first integrity protection algorithm and the integrity protection key may be indicated by information in the first information. For example, the first information includes an integrity protection algorithm indicator and an integrity protection key indicator, where the integrity protection algorithm indicator indicates the first integrity protection algorithm, and the integrity protection key indicator indicates the integrity protection key. Alternatively, the first integrity protection algorithm or the integrity protection key may be obtained through negotiation between the second node and the third node.
[0151] Taking the first data as an example, which is data sent by the second node to the third node, the second node calculates the integrity check code based on the first integrity protection algorithm and the integrity protection key, and sends the integrity check code and the first data to the third node. The third node can check the integrity of the first data based on the integrity check code.
[0152] Taking first data as data sent by a third node to a second node as an example, the third node calculates an integrity check code based on a first integrity protection algorithm and an integrity protection key, and sends the integrity check code and the first data to the second node. The second node may calculate a check code using the first integrity protection algorithm and the integrity protection key, and check the integrity of the first data based on the check code and the integrity check code.
[0153] The following describes an exemplary integrity protection process using the second node as an example. The second node calculates an integrity check code based on the first integrity protection algorithm, the integrity protection key, the first integrity protection input, and the first data. As an example of an integrity protection process, the first data is the payload of a transmission data packet or the first data carries the payload of the transmission data packet. In conjunction with Figure 6 , the first calculation process is based on the first integrity protection algorithm, the session key, and the first integrity protection input (i.e., input 0 in Figure 6 ) to obtain a first output (i.e., output 0 in Figure 6 ). The second calculation process is based on the first integrity protection algorithm, the session key, the first output, and the second integrity protection input (i.e., input 1 in Figure 6 ) to obtain a second output (i.e., output 1 in Figure 6 ). Here, "⊕" represents an exclusive-OR operation. The third calculation process is based on the first integrity protection algorithm, the session key, the second output, and the first M bytes of the payload of the transmission data packet to obtain an integrity protection output corresponding to the first byte of the payload, where M is an integer and M ≥ 1, for example, 16 or 32.
[0154] When the payload of the transmitted data packet is less than or equal to M bytes, the integrity protection output of the first byte of the corresponding payload is the final output (i.e., output 2 shown in Figure 6). When the payload of the transmitted data packet is greater than M bytes, the third calculation process is performed multiple times. In the i-th calculation process, based on the first integrity protection algorithm, the session key, and the integrity protection output of the i-1 M bytes of the corresponding payload, the integrity protection output of the i-th M bytes of the corresponding payload is obtained, and the integrity protection output of the last part of the bytes of the corresponding payload is used as the final output, where i is an integer and i ranges from 1 to 1. An integer between . Based on the final output, an integrity check code can be obtained. It should be understood that when i is When , the i-th M bytes refer to the last part of the bytes of the payload, and the actual number of bytes of the i-th M bytes may be M or less than M.
[0155] Optionally, an integrity check code is derived based on the final output, including using X bits of the final output as the integrity check code. As shown in Figure 6 , the dotted line indicates looping the calculation of the remaining bytes until all bytes of the payload are calculated. Output N is the integrity-protected output corresponding to the last portion of bytes of the payload, and X bits of output N are used as the integrity check code. For example, the lower 4 bytes of output N are used as the integrity check code.
[0156] Optionally, the session key includes an integrity protection key, an encryption key, or an authenticated encryption key, etc. In some solutions, during the process of obtaining the integrity check code, the session key may be replaced with the integrity protection key.
[0157] In some possible implementations, the first integrity protection input (i.e., input 0 shown in FIG6 ) includes a direction indicator, a second parameter, or the like. The direction indicator is used to indicate the order in which the sender and receiver of the first data send data in an event. For example, when the direction indicator is a fifth value, the first-sending node sends and the second-sending node receives. When the direction indicator is a sixth value, the second-sending node sends and the first-sending node receives. The first-sending node is the node that sends data first in an event, and the second-sending node is the node that sends data last in an event.
[0158] The second parameter is a parameter involved in the security algorithm and can be a random number or a parameter obtained by processing the random number. In some solutions, the second parameter is called an initialization vector.
[0159] In one implementation, the second parameter is related to the aforementioned first parameter, and the first parameter is optionally provided by the first node to the second node. For example, the first parameter is an A-bit initialization base value, and the initialization base value is processed (e.g., XOR, XOR, etc.) based on another bit sequence (e.g., B bits), and the final value obtained is used as the second parameter, where A and B are integers greater than or equal to 1. Optionally, the aforementioned B-bit bit sequence may be related to the radio frame type, and optionally, the radio frame type is the type of radio frame sent by the second node, or the type of radio frame sent by the third node. Exemplarily, the second parameter occupies 64 bits, wherein the initialization base value is a 64-bit value generated by a random number generator. For radio frame type 1 and radio frame type 2, the second parameter is the final value (64 bits) obtained by XORing the lower 32 bits of the initialization base value with the lower 32 bits of the synchronization sequence. For radio frame type 3 and radio frame type 4, the second parameter is the final value obtained by XORing the lower 24 bits of the initialization base value with the 24 bits of the logical link identifier.
[0160] In another implementation, the second parameter is related to a third parameter from the second node and / or a fourth parameter from the third node. For example, the second node provides the third parameter and the third node provides the fourth parameter, and the second node derives the second parameter based on the third and fourth parameters. Exemplarily, the second node sends the third parameter (e.g., 32 bits) to the third node, and the third node sends the fourth parameter (32 bits) to the second node, and the second parameter is a 64-bit value obtained by concatenating the third and fourth parameters.
[0161] The first integrity protection input may optionally include other information, such as one or more of a flag bit, payload count, or data length. For ease of understanding, the following describes a possible first integrity protection input with reference to Figure 7. The first integrity protection input includes a flag (1 byte), a random number (13 bytes), a high-order data length bit (1 byte), and a low-order data length bit (1 byte). For example, the flag value can be a first flag value, which can be predefined or customized, for example, defined by one of the first, second, or third nodes or negotiated by multiple nodes. For example, the first flag value is 0x49. The random number includes a payload count, a direction indicator, and an initialization vector. The payload count occupies 39 bits and refers to the cumulative number of payloads in the transmitted data packets. The direction indicator occupies 1 bit; 1 indicates that the first sending node sends and the second sending node receives, while 0 indicates that the first sending node receives and the second sending node sends. The initialization vector (which can be considered the second parameter) occupies 64 bits. The determination method is: first use a random number generator to generate a 64-bit initialization base value (the base value can be the first parameter, optionally produced by the first node, the second node, or the third node). For wireless frame type 1 and wireless frame type 2, the lower 32 bits of the initialization base value are XORed with the lower 32 bits of the synchronization sequence to obtain the final value (64 bits). For wireless frame type 3 and wireless frame type 4, the lower 24 bits of the initialization base value are XORed with the 24 bits of the logical link identifier to obtain the final value. The data length occupies 11 bits, and the number of bytes occupied by the payload. Among them, the high-order byte of the data length occupies 3 bits, which is the value of the high-order 3 bits of the 11-bit data length. The low-order byte of the data length occupies 8 bits, which is the value of the low-order 8 bits of the 11-bit data length. The remaining 5 high-order bits of the data length are 0.
[0162] In a second implementation method, the second node encrypts and / or decrypts the first data based on the first encryption algorithm and the encryption key. For example, for data sent from the second node to the third node, the second node encrypts the first data based on the first encryption algorithm and the encryption key and then sends it. For data sent from the third node to the second node, the second node decrypts the encrypted first data based on the first encryption algorithm and the encryption key to obtain the plaintext of the first data. Optionally, the first encryption algorithm and the encryption key can be indicated by information in the first information. For example, the first information includes an encryption algorithm indication and an encryption key indication, the encryption algorithm indication is used to indicate the first encryption algorithm, and the encryption key indication is used to indicate the encryption key. Alternatively, the first encryption algorithm or the encryption key can also be obtained through negotiation between the second node and the third node.
[0163] The following takes the encryption of the second node as an example to introduce an encryption process.
[0164] In some embodiments, the second node may encrypt the first data based on the first encryption algorithm, the encryption key, and the encryption input. The encryption input includes a direction indication and / or a second parameter. As an example of an encryption process, the first data is a payload of a transmission data packet or the first data carries and transmits the payload of the data packet. In conjunction with FIG8 , for all bytes of the payload, based on the first encryption algorithm, the session key, the jth K bytes of the payload and the encryption input corresponding to the jth K bytes, the jth encryption output is obtained, where j is an integer and j ranges from 1 to An integer between , K is an integer and K≥1, for example, K is 16, or 32, etc., and K=M is optional. For example, for the first K bytes of the payload, the output is obtained based on input 1, the session key, and the first encryption algorithm, and the output is XORed with the first K bytes of the payload (indicated by “⊕”) to obtain the encrypted payload. Similarly, for the second K bytes of the payload, the output is obtained based on input 2, the session key, and the first encryption algorithm, and the output is XORed with the second K bytes of the payload (indicated by (represented by), the encrypted payload is obtained. And so on, until the remaining bytes of the payload are encrypted. It should be understood that when j is When , the j-th K bytes refer to the last part of the bytes of the payload, and the actual number of bytes of the j-th K bytes may be K or less than K.
[0165] In some possible implementations, when integrity protection between the second node and the third node is turned on, an encrypted integrity check code is obtained based on the first encryption algorithm, the session key, the integrity check code, and the encrypted input of the corresponding integrity check code (input 0 as shown in Figure 8).
[0166] Optionally, the session key includes an integrity protection key, an encryption key, or an authenticated encryption key. In some implementations, the session key can be replaced with an encryption key during the encryption process. Furthermore, the encryption key can be the same as the integrity protection key. That is, the session key used in the encryption process and the session key used in the integrity protection process can be the same, or they can be different.
[0167] In some possible implementations, the encryption inputs (e.g., input 0, input 1, or input 2, as shown in FIG8 ) during the encryption process may include a direction indicator and / or a second parameter, and may optionally include other information, such as one or more of a flag bit, a payload count, or a transaction count. For a detailed description of the direction indicator and the second parameter, see Implementation 1.
[0168] For ease of understanding, the following describes a possible encryption input content in conjunction with Figure 9. The encryption input includes a flag (1 byte), a random number (13 bytes), a high-order processing number count (1 byte), and a low-order processing number count (1 byte). The flag value can be a second flag value, which can be predefined or customized, for example, defined by one of the first node, the second node, or the third node or negotiated by multiple nodes, such as a second flag value of 0x01. The random number includes a payload count, a direction indicator, and an initialization vector. The payload count occupies 39 bits and refers to the cumulative number of the payload of the transmitted data packet. The direction indicator occupies 1 bit, 1 indicates that the first sending node sends and the second sending node receives, and 0 indicates that the first sending node receives and the second sending node sends. It can be optionally ignored in single-send or single-receive scenarios. The initialization vector occupies 64 bits and is determined as follows: first, a 64-bit initialization base value is generated using a random number generator (the base value can be the first parameter, optionally generated by the first node, the second node, or the third node). For radio frame types 1 and 2, the lower 32 bits of the initialization base value are XORed with the lower 32 bits of the synchronization sequence to obtain the final value (64 bits). For radio frame types 3 and 4, the lower 24 bits of the initialization base value are XORed with the 24 bits of the logical link identifier to obtain the final value. The processing number count can be used to indicate the number of times encryption processing is performed. Taking Figure 8 as an example, the processing number count corresponding to input 0 is 0, the processing number count corresponding to input 1 is 1, and so on. The processing number count corresponding to input N is N. Among them, the high-order byte of the processing number count occupies 8 bits and is the value of the high-order 8 bits of the 16-bit processing number count; the low-order byte of the processing number count occupies 8 bits and refers to the value of the low-order 8 bits of the 16-bit processing number count.
[0169] It should be understood that the above encryption and integrity protection processes can be combined. In an exemplary embodiment, when both encryption and integrity protection are enabled between the second node and the third node, the second node performs integrity protection on the first data and encrypts the integrity check code and the first data. In another exemplary embodiment, when encryption is enabled but integrity protection is not enabled between the second node and the third node, the second node encrypts the first data. In another exemplary embodiment, when encryption is not enabled but integrity protection is enabled between the second node and the third node, the second node performs integrity protection on the first data.
[0170] In some possible implementations, a second node may establish a link with a third node, and the first data may be transmitted via the link between the second and third nodes. For example, the second node may receive a first message that includes link configuration information, and the second node may establish a communication link with the third node based on the link configuration information. Furthermore, the second and third nodes may encrypt and / or integrity-protect the link between the second and third nodes based on security parameters (i.e., a security algorithm, a security key, and parameters involved in the security algorithm). In this manner, data transmitted via the link may be encrypted and / or integrity-protected based on the security parameters.
[0171] In the embodiment shown in Figure 5, the second node and the third node are two nodes managed by the first node, and the first node can generate first information for the two nodes, so that the second node and the third node can both perform security protection on the data transmission process between the two nodes based on the first information provided by the first node. On the one hand, the present application realizes data transmission between two nodes managed by other nodes, thereby improving the efficiency of data transmission. On the other hand, the data communicated between the two nodes can be securely protected based on the information generated and distributed by the first node, thereby improving the security of communication.
[0172] Please refer to Figure 10, which is a flow chart of another communication method provided in an embodiment of the present application. Optionally, the method can be applied to a communication system, such as one or more communication systems in Figures 1 to 4 above. The communication method shown in Figure 10 may include one or more steps in step S1001 and / or step S1005. It should be understood that for the convenience of description, the description is given in the order of steps S1001 to S1005, and it is not intended to limit the execution to the above order. The embodiment of the present application does not limit the order of execution, execution time, number of executions, etc. of the above one or more steps. Steps S1001 to S1005 are as follows:
[0173] Step S1001: A first node sends a first message to a second node.
[0174] Accordingly, the second node receives the first message from the first node.
[0175] Among them, the first message is used to instruct the second node to establish a link with the third node. For example, the first message has a specific format or carries special information to instruct the second node to establish a link with the third node. Exemplarily, the first message carries the configuration information of the link, and the second node can establish a link with the third node based on the configuration information of the link. In some schemes, the first message is also called an asynchronous TT link establishment indication to indicate the establishment of a TT link (or TT link) between the second node and the third node. The TT link is a link between T nodes and T nodes. Of course, this application does not strictly limit the name of the message. In the specific implementation, the name of the message, the name of the information, and the name of the parameter can be replaced arbitrarily.
[0176] Please refer to Tables 2 and 3, which are schematic diagrams of the message format for an asynchronous TT link establishment indication provided in an embodiment of the present application. The asynchronous TT link establishment indication includes link configuration information, such as a send-before-send indication, a radio frame type indication, a logical link identifier, a bandwidth indication, a pilot density indication, a maximum protocol data unit value, or a maximum time offset. For details, see Table 2 and are not further described here. In this way, the second node can configure a link with the third node based on the link configuration information.
[0177] Step S1002: The first node sends a second message to the third node.
[0178] Accordingly, the third node receives the second message from the first node.
[0179] The second message is used to instruct the third node to establish a link with the second node.
[0180] Step S1003: The second node establishes a communication connection with the third node.
[0181] Step S1004: The second node and the third node negotiate to determine the first information.
[0182] The first information includes one or more of the following information: an integrity protection algorithm indication, an integrity protection key indication, an encryption algorithm indication, an encryption key indication, or a first parameter.
[0183] Step S1005: The second node performs security protection on the first data based on the first information.
[0184] Exemplarily, the second node and the third node encrypt and / or integrity protect the link between the second node and the third node based on security parameters (i.e., security algorithm, security key and parameters involved in the security algorithm, etc.), and the data transmitted through the link can be encrypted and / or integrity protected based on the security parameters.
[0185] The specific process of security protection can be found in the description of step S504.
[0186] The embodiments shown in Figures 5 and 10 above provide multiple possible solutions. Below, some of these possible designs are exemplarily described in conjunction with Figures 11, 12, 13, and 14. It should be understood that the logic, terminology, and other aspects of the embodiments shown in Figures 11, 12, 13, and 14 can be found in the preceding text. In addition, in some of the diagrams of this application, the information indicated by the message is schematically depicted in brackets in the accompanying drawings, but this does not constitute a strict limitation on the content of the message.
[0187] Please refer to Figure 11, which is a flow chart of another communication method provided in an embodiment of the present application. Optionally, the method is applied to the aforementioned communication system. The communication method shown in Figure 11 may include one or more steps of step S1101 and / or step S1103. Steps S1101 to S1103 are as follows:
[0188] Step S1101: A first node sends a first message to a second node.
[0189] A communication connection is established between the first node and the second node, for example, a GT link is established.
[0190] The first message is used to instruct the second node to establish a link with the third node. For example, the first message is a TT link establishment instruction. In some solutions, the first message may also be called an asynchronous TT link establishment instruction.
[0191] The first message includes first information. Exemplarily, the first information includes one or more of the following information: an integrity protection algorithm indication, an integrity protection key indication, an encryption algorithm indication, an encryption key indication, or a first parameter. The first information may be generated by the first node.
[0192] Furthermore, the first message also includes link configuration information, such as a send-before-send indication, a radio frame type indication, a logical link identifier, a bandwidth indication, a pilot density indication, a maximum value of a protocol data unit, or a maximum time offset, etc. For details, see Table 2. In this way, the second node can establish and configure a link with the third node based on the link configuration information.
[0193] Step S1102: The first node sends a second message to the third node.
[0194] A communication connection is established between the first node and the third node, for example, a GT link is established.
[0195] The second message is used to instruct the second node to establish a link with the third node. For example, the second message is a TT link establishment instruction. In some solutions, the second message may also be called an asynchronous TT link establishment instruction. The second message includes first information. Exemplarily, the first information includes one or more of the following information: an integrity protection algorithm indication, an integrity protection key indication, an encryption algorithm indication, an encryption key indication, or a first parameter.
[0196] Furthermore, the second message also includes configuration information of the link, and the third node can establish and configure the link with the second node based on the configuration information of the link.
[0197] Step S1103: The second node and the third node communicate based on the configured first information.
[0198] Illustratively, the second node and the third node perform security protection on the data transmitted between the second node and the third node based on the configured first information. For details, see step S504.
[0199] In the embodiment shown in Figure 11, the second node and the third node can be instructed by the first node to establish a point-to-point link between them. The first information can be carried in the first message, which can reduce the amount of signaling during the link establishment process and improve transmission efficiency.
[0200] Please refer to Figure 12, which is a flow chart of another communication method provided in an embodiment of the present application. Optionally, the method is applied to the aforementioned communication system. The communication method shown in Figure 12 may include one or more steps of step S1201 and / or step S1205. Steps S1201 to S1205 are as follows:
[0201] Step S1201: The first node sends a first message to the second node.
[0202] A communication connection is established between the first node and the second node, for example, a GT link is established.
[0203] The first message is used to instruct the second node to establish a link with the third node. For example, the first message is a TT link establishment instruction. In some scenarios, the first message may also be referred to as an asynchronous TT link establishment instruction. Exemplarily, the first message also includes link configuration information, such as a send-before-send indicator, a radio frame type indicator, a logical link identifier, a bandwidth indicator, a pilot density indicator, a maximum protocol data unit value, or a maximum time offset. For details, see Table 2. In this way, the second node can establish and configure a link with the third node based on the link configuration information.
[0204] Step S1202: The first node sends a second message to the third node.
[0205] A communication connection is established between the first node and the third node, for example, a GT link is established.
[0206] The second message is used to instruct the second node to establish a link with the third node. For example, the second message is a TT link establishment instruction. In some embodiments, the second message may also be referred to as an asynchronous TT link establishment instruction. Furthermore, the second message includes link configuration information. The third node may establish and configure the link with the second node based on the link configuration information.
[0207] Step S1203: The first node sends a third message to the second node.
[0208] The third message includes the first information. Exemplarily, the first information includes an encryption algorithm indication, an integrity protection algorithm indication, an encryption key indication, an integrity protection key indication, a first indication, and a first parameter. The first information may be generated by the first node.
[0209] For detailed description, please refer to the above. Exemplarily, the third message may be referred to as security parameter indication information.
[0210] Step S1204: the first node sends a fourth message to the third node.
[0211] The fourth message includes the first information. Exemplarily, the first information includes an encryption algorithm indication, an integrity protection algorithm indication, an encryption key indication, an integrity protection key indication, a first indication, and a first parameter. For details, see the foregoing. Exemplarily, the fourth message may be referred to as security parameter indication information.
[0212] Step S1205: The second node and the third node communicate based on the configured first information.
[0213] Exemplarily, the second node and the third node encrypt and / or integrity protect the link between them based on configured security parameters (i.e., a security algorithm, a security key, and parameters of the security algorithm). Data transmitted over the link may be encrypted and / or integrity protected based on the security parameters. For details, see the description of step S504.
[0214] In the embodiment shown in Figure 12, the first node sends a first message to the second node to instruct the second node to establish a communication link with the third node, and sends the first information to the second node through an additional message (such as a third message), so that the function of the message is more refined and refined, and the reusability and combination flexibility of the message format are improved.
[0215] For example, in some schemes, the first node may also instruct another G node to establish a GT link (or GG link) with another node. In this case, the first node may send a GT link establishment indication (or a GG link establishment indication) to the G node. Since the G node itself can configure security-related parameters, the first node does not need to send security-related parameters to the G node. Therefore, there is no need to set fields related to the first information in the GT link establishment indication (or the GG link establishment indication). In the above embodiment, the security-related parameters are indicated by additional third and fourth messages, which refines the function of the signaling, so that the TT link establishment indication and the GT link establishment indication can use the same message format, thereby improving the reusability and combination flexibility of the message format.
[0216] Please refer to Figure 13, which is a flow chart of another communication method provided in an embodiment of the present application. Optionally, the method is applied to the aforementioned communication system. The communication method shown in Figure 13 may include one or more steps of step S1301 and / or step S1307. Steps S1301 to S1307 are as follows:
[0217] Step S1301: The first node sends a first message to the second node.
[0218] A communication connection is established between the first node and the second node, for example, a GT link is established.
[0219] The first message is used to instruct the second node to establish a link with the third node. For example, the first message is a TT link establishment instruction. In some scenarios, the first message may also be referred to as an asynchronous TT link establishment instruction. Exemplarily, the first message also includes link configuration information, such as a send-before-send indicator, a radio frame type indicator, a logical link identifier, a bandwidth indicator, a pilot density indicator, a maximum protocol data unit value, or a maximum time offset. For details, see Table 2. In this way, the second node can establish and configure a link with the third node based on the link configuration information.
[0220] Optionally, the first message may include a first indication.
[0221] Step S1302: The first node sends a second message to the third node.
[0222] A communication connection is established between the first node and the third node, for example, a GT link is established.
[0223] The second message is used to instruct the second node to establish a link with the third node. For example, the second message is a TT link establishment instruction. In some embodiments, the second message may also be referred to as an asynchronous TT link establishment instruction. Furthermore, the second message includes link configuration information. The third node may establish and configure the link with the second node based on the link configuration information.
[0224] Optionally, the second message may include the first indication.
[0225] Step S1303: The first node sends a third message to the second node.
[0226] The third message includes the first information. Exemplarily, the first information includes an encryption algorithm indication, an integrity protection algorithm indication, an encryption key indication, and an integrity protection key indication. The first information may be generated by the first node. Exemplarily, the third message may be referred to as security parameter indication information.
[0227] Step S1304: the first node sends a fourth message to the third node.
[0228] The fourth message includes the first information. Exemplarily, the first information includes an encryption algorithm indication, an integrity protection algorithm indication, an encryption key indication, and an integrity protection key indication. Exemplarily, the fourth message may be referred to as security parameter indication information.
[0229] Step S1305: The second node sends a third parameter to the third node.
[0230] Exemplarily, the third parameter may be referred to as a second node initialization vector, which is, for example, 32 bits.
[0231] Step S1306: The third node sends a fourth parameter to the second node.
[0232] Exemplarily, the fourth parameter may be referred to as a third node initialization vector, which is, for example, 32 bits.
[0233] Step S1307: The second node and the third node perform secure communication.
[0234] The second parameter used in the security protection process is determined by the third parameter and the fourth parameter. For example, the second parameter is 64 bits, and the second parameter = the third parameter + the fourth parameter, where + represents the concatenation of bits.
[0235] As can be seen, the second node and the third node can securely protect data transmitted between the second node and the third node based on the configured first information and the negotiated second parameters. In some solutions, the second node and the third node encrypt and / or integrity protect the link between the second node and the third node based on security parameters (i.e., a security algorithm, a security key, and parameters involved in the security algorithm, etc.), and data transmitted over the link can be encrypted and / or integrity protected based on the security parameters.
[0236] For the specific process, please refer to the description in step S504.
[0237] In the embodiment shown in Figure 13, a first node sends a first message to a second node to instruct the second node to establish a communication link with a third node. The first message is then sent to the second node via an additional message (e.g., a third message). This further refines the functionality of the message and improves the reusability and combination flexibility of the message format. Furthermore, the second and third nodes negotiate and determine the parameters (e.g., the second parameter) involved in the security algorithm, further enhancing the security of communication between the second and third nodes.
[0238] Please refer to Figure 14, which is a flow chart of another communication method provided in an embodiment of the present application. Optionally, the method is applied to the aforementioned communication system. The communication method shown in Figure 14 may include one or more steps of step S1401 and / or step S1405. Steps S1401 to S1405 are as follows:
[0239] Step S1401: The first node sends a first message to the second node.
[0240] A communication connection is established between the first node and the second node, for example, a GT link is established.
[0241] The first message is used to instruct the second node to establish a link with the third node. For example, the first message is a TT link establishment instruction. In some scenarios, the first message may also be referred to as an asynchronous TT link establishment instruction. Exemplarily, the first message also includes link configuration information, such as a send-before-send indicator, a radio frame type indicator, a logical link identifier, a bandwidth indicator, a pilot density indicator, a maximum protocol data unit value, or a maximum time offset. For details, see Table 2. In this way, the second node can establish and configure a link with the third node based on the link configuration information.
[0242] Step S1402: The first node sends a second message to the third node.
[0243] A communication connection is established between the first node and the third node, for example, a GT link is established.
[0244] The second message is used to instruct the second node to establish a link with the third node. For example, the second message is a TT link establishment instruction. In some embodiments, the second message may also be referred to as an asynchronous TT link establishment instruction. Furthermore, the second message includes link configuration information. The third node may establish and configure the link with the second node based on the link configuration information.
[0245] Step S1403: The second node and the third node perform algorithm negotiation and key negotiation.
[0246] For example, the second node may indicate to the third node the security algorithms supported by the second node, and the third node may select an algorithm from the security algorithms supported by the second node (e.g., select the algorithm with the highest priority). Alternatively, the third node may indicate to the second node the security algorithms supported by the third node, and the second node may select an algorithm from the security algorithms supported by the second node (e.g., select the algorithm with the highest priority). The security algorithm includes one or more of an encryption algorithm, an integrity protection algorithm, and an authenticated encryption algorithm.
[0247] Key agreement can be determined using the DH algorithm or key information. For example, multiple keys are configured on the second and third nodes, each corresponding to key information. The second node sends the key information to the third node, which then selects a corresponding key as the session key based on the key information. The session key includes one or more of an encryption key, an integrity protection key, and an authenticated encryption key.
[0248] Step S1404: The second node and the third node negotiate to determine the second parameter.
[0249] For example, the second node determines a second parameter and provides it to the third node.
[0250] Alternatively, the third node determines the second parameter and provides it to the second node.
[0251] Alternatively, the second node determines a third parameter and provides it to the third node, and the third node determines a fourth parameter and provides it to the second node. The second parameter is determined based on the third parameter and the fourth parameter.
[0252] Step S1405: The second node and the third node perform secure communication.
[0253] For example, the second node and the third node perform security protection on the data transmitted between the second node and the third node based on the negotiated security algorithm, session key, and parameters of the security algorithm (such as the second parameter). The specific process of security protection can be seen in step S504.
[0254] In the embodiment shown in Figure 14, the first node sends a first message to the second node to instruct the second node to establish a communication link with the third node. The second node and the third node determine the security algorithm, key and parameters participating in the security algorithm (such as the second parameter) through negotiation, so that the security of communication between the second node and the third node is further improved.
[0255] The above describes in detail the method of the embodiment of the present application. The following provides an apparatus of the embodiment of the present application.
[0256] It should be understood that the division of the units in the device provided in the embodiments of the present application is only a division of logical functions, and in actual implementation, they can be fully or partially integrated into one physical entity, or they can be physically separated. In addition, the units in the device can be implemented in the form of a processor calling software. For example, the device includes a processor, the processor is connected to a memory, and instructions are stored in the memory. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of each unit of the device, wherein the processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is a memory within the device or a memory outside the device.
[0257] Alternatively, the units in the device may be implemented in the form of hardware circuits, and the functions of some or all of the units may be implemented by designing the hardware circuits, which may be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), which implements the functions of some or all of the above units by designing the logical relationships between the components within the circuit. For another example, in another implementation, the hardware circuit may be implemented by a programmable logic device (PLD), such as a field programmable gate array (FPGA), which may include a large number of logic gate circuits, and the connection relationships between the logic gate circuits may be configured through configuration files, thereby implementing the functions of some or all of the above units.
[0258] In an embodiment of the present application, each unit in the device may be one or more processors (or processing circuits) configured to implement the above method, such as: CPU, (graphics processing unit, GPU), neural network processing unit (neural network processing unit, NPU), tensor processing unit (tensor processing unit, TPU), deep learning processing unit (deep learning processing unit, DPU), microprocessor (micro processor unit, MPU), digital signal processor (digital signal processor, DSP), ASIC, FPGA, or a combination of at least two of these processor forms.
[0259] In addition, the various units in the above devices can be fully or partially integrated together, or can be implemented independently. In one implementation, these units are integrated together and implemented in the form of a system-on-a-chip (SOC). The SOC may include at least one processor for implementing any of the above methods or implementing the functions of the various units of the device. The type of the at least one processor may be different, for example, including a CPU and an FPGA, or including a CPU and an artificial intelligence processor, or including a CPU and a GPU, etc. Several possible devices are listed below.
[0260] Please refer to Figure 15, which is a schematic diagram of the structure of a communication device provided in an embodiment of the present application. Optionally, the communication device 150 can be an independent device, such as a node. Alternatively, the communication device 150 can also be a device in an independent device (such as a node), such as a chip or an integrated circuit. The communication device 150 is used to implement the aforementioned communication method, such as the communication method shown in Figure 5, Figure 10, Figure 11, Figure 12, Figure 13, or Figure 14.
[0261] Exemplarily, the communication device 150 includes a processing unit 1501 and a communication unit 1502. The processing unit 1501 is used to implement one or more operations such as processing, determining, generating, calculating, encrypting, and decrypting, and the communication unit 1502 is used to implement one or more operations such as sending and receiving.
[0262] In one possible design, the communication device is used to execute the method performed by the first node in the aforementioned communication method.
[0263] In one possible implementation, processing unit 1501 is configured to generate first information. Communication unit 1502 is configured to send the first information to a second node and to send the first information to a third node. The first information is used to securely protect data transmitted between the second and third nodes. The first node is connected to the second and third nodes, respectively, and the second and third nodes are managed by the first node.
[0264] In another possible implementation, the communication unit 1502 is further configured to send a first message to the second node, the first information being carried in the first message. Optionally, the first message carries link configuration information, and the second node may establish a link with the third node based on the link configuration information.
[0265] In another possible implementation, the communication unit 1502 is further configured to send a second message to the third node, with the first information carried in the second message. Optionally, the second message carries link configuration information, and the third node may establish a link with the second node based on the link configuration information.
[0266] In another possible implementation, the first information sent to the second node is carried in a third message. That is, the communication unit 1502 is further configured to send a third message to the second node, where the third message includes the first information.
[0267] In another possible implementation, the communication unit 1502 is further configured to send a first message to the second node, wherein the first message is configured to instruct the second node to establish a communication link with the third node. Furthermore, the first information is not carried in the first message.
[0268] In another possible implementation, the communication unit 1502 is further configured to send a second message to the third node, where the second message is configured to instruct the third node to establish a communication link with the second node. Furthermore, the first information is not carried in the second message.
[0269] In another possible implementation, the first information sent to the third node is carried in a fourth message. That is, the communication unit 1502 is further configured to send a fourth message to the third node, where the fourth message includes the first information.
[0270] For related descriptions, please refer to the description of the aforementioned embodiment, which will not be explained here one by one.
[0271] In one possible design, the communication device is used to execute the method performed by the second node in the aforementioned communication method, for example.
[0272] In a possible implementation, the communication unit 1502 is configured to receive first information from the first node, and the processing unit 1501 is configured to perform security protection on first data based on the first information, where the first data is data transmitted between the second node and the third node.
[0273] In a possible implementation, the communication unit 1502 is further configured to receive a first message from the first node, the first information being carried in the first message, wherein the first message is used to instruct the second node to establish a connection with the third node.
[0274] In one possible implementation, the communication unit 1502 is further configured to receive a first message from the first node. The first message is used to instruct the second node to establish a connection with the third node. Furthermore, the first information is not carried in the first message.
[0275] In a possible implementation, the communication unit 1502 is further configured to receive a third message from the first node, and the first information is carried in the third message.
[0276] In a possible implementation, the processing unit 1501 and the communication unit 1502 are further configured to establish a communication link with a third node.
[0277] In a possible implementation, the processing unit 1501 is further configured to perform integrity protection on the first data based on a first integrity protection algorithm and an integrity protection key.
[0278] In a possible implementation, the processing unit 1501 is further configured to perform integrity protection on the first data based on a first integrity protection algorithm and an integrity protection key, wherein the integrity protection key is obtained through negotiation between the second node and the third node.
[0279] In a possible implementation, the processing unit 1501 is further configured to perform integrity protection on the first data based on a first integrity protection algorithm and an integrity protection key, wherein the first integrity protection algorithm is obtained through negotiation between the second node and the third node.
[0280] In a possible implementation, the processing unit 1501 is further configured to calculate an integrity check code based on the first integrity protection algorithm, the integrity protection key, the first integrity protection input, and the first data.
[0281] In one possible implementation, the first data is carried in a payload of the transmission data packet. The processing unit 1501 is further configured to: obtain a first output based on a first integrity protection algorithm, an integrity protection key, and a first integrity protection input; obtain a second output based on the first integrity protection algorithm, the integrity protection key, the first output, and the second integrity protection input; and obtain an integrity protection output corresponding to the first byte of the payload based on the first integrity protection algorithm, the integrity protection key, the second output, and the first M bytes of the payload of the transmission data packet, where M is an integer and M ≥ 1.
[0282] When the payload of the transmitted data packet is less than or equal to M bytes, the integrity protection output of the first byte of the corresponding payload is the final output. When the payload of the transmitted data packet is greater than M bytes, based on the first integrity protection algorithm, the integrity protection key and the integrity protection output of the i-1th M bytes of the corresponding payload, the integrity protection output of the i-th M bytes of the corresponding payload is obtained, and the integrity protection output of the last part of the bytes of the corresponding payload is taken as the final output, where i is an integer and i ranges from 1 to The integrity check code is obtained based on the final output. Represents the integer obtained by rounding x upwards.
[0283] Optionally, obtaining the integrity check code according to the final output includes: using the lower X bits of the final output as the integrity check code.
[0284] In a possible implementation, the processing unit 1501 is further configured to encrypt the first data based on a first encryption algorithm and an encryption key.
[0285] In a possible implementation, the processing unit 1501 is further configured to encrypt the first data based on a first encryption algorithm and an encryption key, where the encryption key is obtained through negotiation between the second node and the third node.
[0286] In a possible implementation, the processing unit 1501 is further configured to encrypt the first data based on a first encryption algorithm and an encryption key, where the first encryption algorithm is obtained through negotiation between the second node and the third node.
[0287] In a possible implementation, the processing unit 1501 is further configured to encrypt the first data based on the first encryption algorithm, the encryption key, and the encryption input, wherein the encryption input includes the direction indication and / or the second parameter.
[0288] In one possible implementation, the first data is carried in the payload of the transmission data packet. The processing unit 1501 is further configured to: for all bytes of the payload, obtain the jth encrypted output based on the first encryption algorithm, the encryption key, the jth K bytes of the payload and the encryption input corresponding to the jth K bytes, where j is an integer and j ranges from 1 to Integer between .
[0289] In one possible implementation, when integrity protection between the second node and the third node is enabled, the processing unit 1501 is further configured to obtain an encrypted integrity check code based on the first encryption algorithm, the encryption key, the integrity check code, and the encrypted input of the corresponding integrity check code.
[0290] For related descriptions, please refer to the description of the aforementioned embodiment, which will not be explained here one by one.
[0291] In one possible design, the communication device is used, for example, to execute the method executed by the second node in the aforementioned communication method. Specifically, the communication unit 1502 is used to receive a first message from the first node, the processing unit 1501 and the communication unit 1502 are used to establish a link with the third node and negotiate with the third node to determine the first information, and the processing unit 1501 is used to securely protect the first data based on the first information. The first message is used to instruct the second node to establish a link with the third node, and the first data is data transmitted between the second node and the third node.
[0292] In yet another possible implementation, the processing unit 1501 is further configured to perform integrity protection on the first data based on a first integrity protection algorithm and an integrity protection key.
[0293] In yet another possible implementation, the processing unit 1501 is further configured to encrypt the first data based on a first encryption algorithm and an encryption key.
[0294] For related descriptions, please refer to the description of the aforementioned embodiment, which will not be explained here one by one.
[0295] Please refer to Figure 16, which is a schematic diagram of the structure of another communication device provided in an embodiment of the present application. The communication device 160 can be an independent device, such as a node, or a device included in an independent device, such as a chip, a software module, or an integrated circuit. The communication device 160 may include at least one processor 1601 and a communication interface 1602. Optionally, it may also include at least one memory 1603. Further optionally, it may also include a connection line 1604, wherein the processor 1601, the communication interface 1602 and / or the memory 1603 are connected via the connection line 1604, and / or communicate with each other via the connection line 1604 to transmit control signals and / or data signals.
[0296] in:
[0297] The processor 1601 is a module that performs arithmetic operations and / or logical operations, and may specifically include one or more of the following modules: a filter, a modem, a power amplifier, a low noise amplifier (LNA), a baseband processor, a radio frequency processor, a radio frequency circuit, a central processing unit (CPU), an application processor (AP), a microcontroller unit (MCU), an electronic control unit (ECU), a graphics processing unit (GPU), a microprocessor unit (MPU), an application specific integrated circuit (ASIC), an image signal processor (ISP), a digital signal processor (DSP), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), or a coprocessor, etc.
[0298] The communication interface 1602 may be used to provide information input or output for at least one processor, or to receive externally transmitted signals and / or send externally transmitted signals.
[0299] For example, communication interface 1602 may include interface circuitry.
[0300] For example, the communication interface 1602 may include a wired link interface such as an Ethernet cable, or a wireless link interface (Wi-Fi, Bluetooth, general wireless transmission, vehicle-mounted short-range communication technology, and other short-range wireless communication technologies, etc.).
[0301] Optionally, the communication interface 1602 may further include a radio frequency transmitter, an antenna, etc. When the communication interface 1602 includes an antenna, the number of antennas may be one or more.
[0302] As a possible design, if the communication device 160 is a standalone device, the communication interface 1602 may include a receiver and a transmitter. The receiver and the transmitter may be the same component or different components. When the receiver and the transmitter are the same component, the component may be referred to as a transceiver.
[0303] As another possible design, if the communication device 160 is a chip or a circuit, the communication interface 1602 may include an input interface and an output interface. The input interface and the output interface may be the same interface, or may be different interfaces.
[0304] Optionally, the functions of the communication interface 1602 may be implemented by a transceiver circuit or a dedicated transceiver chip.
[0305] Memory 1603 is used to provide storage space for storing data such as the operating system and computer programs. Memory 1603 can be one or a combination of random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CD-ROM).
[0306] The functions and actions of the modules or units in the communication device 160 listed above are only for illustrative purposes.
[0307] Each functional unit in the communication device 160 can be used to implement the aforementioned communication method, such as the communication method shown in Figure 5, Figure 10, Figure 11, Figure 12, Figure 13, or Figure 14, for example, for executing the method executed by the first node or the second node.
[0308] Optionally, processor 1601 may be a processor specifically used to execute the aforementioned method (for convenience of distinction, referred to as a dedicated processor), or a processor that executes the aforementioned method by calling a computer program (for convenience of distinction, referred to as a dedicated processor). Optionally, at least one processor may include both a dedicated processor and a general-purpose processor.
[0309] Optionally, in the case where the communication device 160 includes at least one memory 1603 , if the processor 1601 implements the aforementioned communication method by calling a computer program, the computer program may be stored in the memory 1603 .
[0310] An embodiment of the present application further provides a chip comprising a logic circuit and a communication interface. The communication interface is configured to receive or transmit signals, and the logic circuit is configured to receive or transmit signals via the communication interface. The chip is configured to implement the aforementioned communication methods, such as those shown in Figures 5, 10, 11, 12, 13, or 14.
[0311] An embodiment of the present application also provides a computer-readable storage medium, which stores instructions. When the instructions are executed on at least one processor (or communication device), the aforementioned communication method is implemented, such as the communication method shown in Figures 5, 10, 11, 12, 13, or 14.
[0312] An embodiment of the present application also provides a computer program product, which includes computer instructions, and the computer instructions are used to implement the aforementioned communication method, such as the communication method shown in Figure 5, Figure 10, Figure 11, Figure 12, Figure 13, or Figure 14.
[0313] An embodiment of the present application further provides a terminal, which includes the aforementioned communication device 150 and / or communication device 160.
[0314] As a possible implementation, the terminal includes a terminal node. Further, the terminal also includes a first management node and / or a second management node. Further, the terminal also includes a control node.
[0315] For example, terminals may include intelligent terminals or vehicles such as vehicles, robots, drones, ships, and boats. Vehicles are broadly defined and may include transportation vehicles (e.g., commercial vehicles, passenger cars, motorcycles, flying cars, trains, etc.), industrial vehicles (e.g., forklifts, trailers, tractors, etc.), engineering vehicles (e.g., excavators, bulldozers, cranes, etc.), agricultural equipment (e.g., mowers, harvesters, etc.), and so on. Robots may also include automated guided vehicles (AGVs), mobile conversational robots, service robots, and other robots.
[0316] It should be noted that in the embodiments of this application, words such as "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplarily" or "for example" is intended to present the relevant concepts in a concrete manner.
[0317] In the embodiments of the present application, the names of information and devices are exemplarily named to facilitate understanding of the content of this solution. In specific implementations, their names may have other designs. In addition, different designs may exist for the names of the same thing in different scenarios (such as different communication layers). For example, time resource configuration information may also be referred to as reference information, etc. For another example, different communication layers have different names for the encapsulation of business data. At the application layer, the first business is directly transmitted in the form of data, but at the network layer, the data of the first business is encapsulated in the message transmission of the first business.
[0318] In the embodiments of this application, "at least one" refers to one or more, and "more" refers to two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items.
[0319] For example, at least one of a, b, or c can represent: a, b, c, (a and b), (a and c), (b and c), or (a and b and c), where a, b, and c can be single or plural. "And / or" describes the relationship between associated objects, indicating that three possible relationships exist. For example, A and / or B can represent: A alone, A and B together, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects are in an "or" relationship.
[0320] Furthermore, unless otherwise specified, ordinal numbers such as "first," "second," "M1," "M2," "M3," "M4," "M5," "S1," "S2," and "S3" used in the embodiments of the present application are used to distinguish multiple objects and are not used to limit the order, timing, priority, or importance of the multiple objects. For example, the first node and the second node are merely for the convenience of describing new parameters in different implementations and do not indicate differences in their execution operations, importance, structure, etc.
[0321] In the above embodiments, the term "when" can be interpreted to mean "if...", "after...", "in response to determining...", or "in response to detecting...", depending on the context. The above are merely optional embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the concepts and principles of the present application shall be included in the scope of protection of the present application.
[0322] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.
Claims
1. A communication method, characterized in that: Applied to a first node, the first node is connected to a second node and a third node respectively, the second node and the third node are managed by the first node, The method comprises: generating first information, where the first information is used to securely protect data transmitted between the second node and the third node; The first information is sent to the second node, and the first information is sent to the third node.
2. The method according to claim 1, characterized in that The sending the first information to the second node includes: Sending a first message to the second node, where the first information is carried in the first message, and the first message is used to instruct the second node to establish a link with the third node; The sending the first information to the third node includes: A second message is sent to the third node, where the first information is carried in the second message, and the second message is used to instruct the third node to establish a link with the second node.
3. The method according to claim 1, characterized in that The method further comprises: Sending a first message to the second node, where the first message is used to instruct the second node to establish a link with the third node; A second message is sent to the third node, where the second message is used to instruct the third node to establish a link with the second node.
4. The method according to any one of claims 1 to 3, characterized in that The first information includes one or more of the following information: Integrity protection algorithm indication, integrity protection key indication, encryption algorithm indication, encryption key indication or first parameter; The integrity protection algorithm indication is used to indicate a first integrity protection algorithm used by the link between the second node and the third node; The integrity protection key indication is used to indicate a key used by the integrity protection algorithm; The encryption algorithm indication is used to indicate a first encryption algorithm used in a link between the second node and the third node; The encryption key indication is used to indicate the key used by the encryption algorithm; The first parameter is used to obtain an input parameter of an encryption and / or integrity protection process between the second node and the third node.
5. The method according to any one of claims 1 to 4, characterized in that The first information further includes a first indication, which is carried in a first field; When the first field is a first value, it indicates that link encryption and startup integrity protection between the second node and the third node are started simultaneously; Alternatively, when the first field is a second value, it indicates that encryption is not enabled and integrity protection is enabled for the link between the second node and the third node; Alternatively, when the first field is a third value, it indicates that encryption is enabled on the link between the second node and the third node, but integrity protection is not enabled; Alternatively, when the first field is a fourth value, it indicates that encryption and integrity protection are not enabled for the link between the second node and the third node.
6. A communication method, characterized in that: Applied to a second node, the second node is connected to a first node, the first node is also connected to a third node and the first node manages the second node and the third node, The method comprises: receiving first information from the first node; Security protection is performed on first data based on the first information, where the first data is data transmitted between the second node and the third node.
7. The method according to claim 6, characterized in that The receiving first information from the first node includes: A first message is received from the first node, where the first information is carried in the first message, and the first message is used to instruct the second node to establish a link with the third node.
8. The method according to claim 6, characterized in that The method further comprises: A first message is received from the first node, where the first message is used to instruct the second node to establish a link with the third node.
9. The method according to any one of claims 6 to 8, characterized in that: The method further comprises: A link is established with the third node.
10. The method according to any one of claims 6 to 9, characterized in that: The first information includes one or more of the following information: Integrity protection algorithm indication, integrity protection key indication, encryption algorithm indication, encryption key indication or first parameter; The integrity protection algorithm indication is used to indicate a first integrity protection algorithm used for the link between the second node and the third node, and the first integrity protection algorithm is an algorithm with the highest priority among the integrity protection algorithms supported by the second node and the third node; The integrity protection key indication is used to indicate a key used by the integrity protection algorithm; The encryption algorithm indication is used to indicate a first encryption algorithm used for the link between the second node and the third node, where the first encryption algorithm is an algorithm with the highest priority among the encryption algorithms supported by the second node and the third node; The encryption key indication is used to indicate the key used by the encryption algorithm; The first parameter is used to obtain an input parameter of an encryption and / or integrity protection process between the second node and the third node.
11. The method according to any one of claims 6 to 10, characterized in that: The first information includes an integrity protection algorithm indication and an integrity protection key indication, where the integrity protection algorithm indication is used to indicate a first integrity protection algorithm, and the integrity protection key indication is used to indicate an integrity protection key; The performing security protection on the first data based on the first information includes: Perform integrity protection on the first data based on the first integrity protection algorithm and the integrity protection key.
12. The method according to claim 11, characterized in that The performing integrity protection on the first data based on the first integrity protection algorithm and the integrity protection key includes: Calculate an integrity check code based on the first integrity protection algorithm, the integrity protection key, the first integrity protection input, and the first data, where the integrity check code is used to check the integrity of the first data; wherein the first integrity protection input includes a direction indication and / or a second parameter; The direction indication is used to indicate the order in which the sender and receiver of the first data send data in an event; The second parameter is related to the first parameter included in the first information, or the second parameter is related to the third parameter from the second node and / or the fourth parameter from the third node.
13. The method according to any one of claims 6 to 12, characterized in that: The first information includes an encryption algorithm indication and an encryption key indication, wherein the encryption algorithm indication is used to indicate a first encryption algorithm, and the encryption key indication is used to indicate an encryption key; The securely communicating with the third node based on the first information includes: The first data is encrypted based on the first encryption algorithm and the encryption key.
14. The method according to claim 13, characterized in that The encrypting the first data based on the first encryption algorithm and the encryption key includes: encrypting the first data based on the first encryption algorithm, the encryption key, and encryption input; The encrypted input includes a direction indication and / or a second parameter.
15. The method according to claim 12 or 14, characterized in that When the direction indication is the fifth value, it indicates that the first sending node sends and the second sending node receives; When the direction indication is the sixth value, it indicates that the later-sending node sends and the earlier-sending node receives, the earlier-sending node is the node that sends data first in an event, and the later-sending node is the node that sends data last in an event.
16. The method according to any one of claims 6 to 15, characterized in that: The first information further includes a first indication, which is carried in a first field; When the first field is a first value, it indicates that link encryption and startup integrity protection between the second node and the third node are started simultaneously; Alternatively, when the first field is a second value, it indicates that encryption is not enabled and integrity protection is enabled for the link between the second node and the third node; Alternatively, when the first field is a third value, it indicates that encryption is enabled on the link between the second node and the third node, but integrity protection is not enabled; Alternatively, when the first field is a fourth value, it indicates that encryption is enabled for the link between the second node and the third node, but integrity protection is not enabled.
17. A communication method, characterized in that: Applied to a second node, the second node is connected to a first node, the first node is also connected to a third node and the first node manages the second node and the third node, The method comprises: receiving a first message from a first node, where the first message is used to instruct the second node to establish a link with the third node; establishing a link with the third node; Negotiate with the third node to determine the first information; Security protection is performed on first data based on the first information, where the first data is data transmitted between the second node and the third node.
18. The method according to claim 17, characterized in that The first information includes one or more of the following information: Integrity protection algorithm indication, integrity protection key indication, encryption algorithm indication, encryption key indication or first parameter; The integrity protection algorithm indication is used to indicate a first integrity protection algorithm used by the link between the second node and the third node; The integrity protection key indication is used to indicate a key used by the integrity protection algorithm; The encryption algorithm indication is used to indicate a first encryption algorithm used in a link between the second node and the third node; The encryption key indication is used to indicate the key used by the encryption algorithm; The first parameter is used to obtain an input parameter of an encryption and / or integrity protection process between the second node and the third node.
19. The method according to claim 17 or 18, characterized in that The first message includes a first indication, where the first indication is carried in a first field; When the first field is a first value, it indicates that link encryption and startup integrity protection between the second node and the third node are started simultaneously; Alternatively, when the first field is a second value, it indicates that encryption is not enabled and integrity protection is enabled for the link between the second node and the third node; Alternatively, when the first field is a third value, it indicates that encryption is enabled on the link between the second node and the third node, but integrity protection is not enabled; Alternatively, when the first field is a fourth value, it indicates that encryption is enabled for the link between the second node and the third node, but integrity protection is not enabled.
20. A communication device, characterized in that: comprising a unit or module for performing the method according to any one of claims 1 to 5; Or, comprising a unit or module for performing the method according to any one of claims 6 to 16; Alternatively, the method comprises a unit or module for executing the method according to any one of claims 17 to 19.
21. A communication device, characterized in that: The method comprises a processor and an interface circuit, wherein the interface circuit is used to receive signals from other communication devices and transmit them to the processor or send signals from the processor to other communication devices, and the processor is used to implement the method according to any one of claims 1 to 19 through a logic circuit or executing code instructions.
22. A communication system, characterized in that: The communication system includes a first node, a second node and a third node, the second node is used to execute the communication method according to any one of claims 1 to 5, and the second node and the third node are used to implement the communication method according to any one of claims 6 to 16.
23. A communication system, characterized in that: The communication system includes a first node, a second node and a third node, the second node is used to send a first message to the second node and send the second message to the third node, and the second node and the third node are used to implement the communication method described in any one of claims 17-19.
24. A terminal, characterized in that: The terminal includes the communication device according to claim 20 or 21, or includes the communication system according to claim 22 or 23.
25. A readable storage medium, characterized in that The readable storage medium is used to store a computer program, and when the computer program is executed by a processor, the communication device including the processor executes the method according to any one of claims 1 to 19.
26. A computer program, characterized in that When the computer program is executed by a processor, the communication device including the processor is caused to perform the method according to any one of claims 1 to 19.
Citation Information
Patent Citations
Communication method and related device
CN120529297A
Communication method, device and system
CN112449323A
Communication method and device
CN115175189A
Information processing method and device and storage medium
CN117322027A
Key obtaining method and related apparatus
US20230099065A1