Security verification method and apparatus for user plane control signaling, and storage medium
By decrypting and verifying the integrity of the data packets associated with user-plane control signaling, the problem of lack of security protection for user-plane control signaling in 5G systems is solved, thereby improving the security and performance of the system.
Patent Information
- Application Number
- PCT/CN2025/086379
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-03
- Filing Date
- 2025-03-31
- Publication Date
- 2025-10-09
AI Technical Summary
The user plane control signaling in the 5G system lacks a security protection mechanism, resulting in fake base station attacks and malicious terminal behavior affecting system performance.
By decrypting and verifying the integrity of the associated data packets of the user plane control signaling, the security verification result is determined, and the signaling is applied when the verification is successful, and discarded or rolled back when it fails, the security verification of the user plane control signaling is achieved.
The security of user-plane control signaling is improved, the impact of attacks from pseudo base stations and malicious terminals on the network is reduced, and the overall performance of the system is improved.
Smart Images

Figure CN2025086379_09102025_PF_FP_ABST
Abstract
Description
Security verification method, device and storage medium for user plane control signaling
[0001] This disclosure claims priority to Chinese patent application number 2024104032857, filed on April 3, 2024, entitled “Security Verification Method, Device and Storage Medium for User Plane Control Signaling,” the entire text of which is hereby incorporated by reference. Technical Field
[0002] The present disclosure relates to the field of communication technology, and in particular to a method, device, and storage medium for verifying the security of user plane control signaling. Background Art
[0003] In the 5G system, there are security protection mechanisms for Radio Resource Control (RRC) signaling and user-plane data transmission, including encryption and integrity protection, but there is no security mechanism to protect user-plane control signaling.
[0004] User-plane control signaling, especially the Media Access Control (MAC) Control Element (CE), has many functions. Without security verification mechanisms such as encryption and decryption, security is low. For example, if a fake base station sends a false timing adjustment command to a terminal, data transmission between the terminal and the normal base station may fail, or even the connection may fail. If a malicious terminal impersonates another terminal and sends a large amount of buffered data, it may cause confusion in base station resource allocation, affecting the transmission of other terminals and the performance of the entire system. Therefore, there is an urgent need to provide a method to ensure the security of user-plane control signaling. Summary of the Invention
[0005] According to various embodiments of the present disclosure, a method, apparatus, and storage medium for security verification of user plane control signaling are provided.
[0006] In a first aspect, the present disclosure provides a method for security verification of user plane control signaling, including:
[0007] Receive a transport block and parse the transport block to obtain user plane control signaling;
[0008] Perform security verification on data packets associated with user plane control signaling;
[0009] The security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
[0010] In some embodiments, the associated data packet includes one or more of the following:
[0011] Radio resource control (RRC) signaling or user plane data organized in the same transport block as user plane control signaling, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection;
[0012] Null data packets organized in the same transport block as user plane control signaling undergo one or more of the following operations: encryption, integrity protection;
[0013] The RRC signaling or user plane data in the transmission block that has a deterministic time relationship with the transmission time of the transmission block where the user plane control signaling is located, the RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection; the deterministic time relationship refers to: the previous transmission of the transmission block where the user plane control signaling is located, or, the next transmission of the transmission block where the user plane control signaling is located, or, the transmission performed simultaneously with the transmission block where the user plane control signaling is located, and simultaneous transmission means that the transmission time overlaps or completely overlaps with the transmission time of the transmission block where the user plane control signaling is located.
[0014] In some embodiments, performing security verification on data packets associated with user plane control signaling includes any of the following:
[0015] Decrypting the associated data packet; if the decryption is successful, determining the security verification result of the associated data packet as a security verification success; if the decryption fails, determining the security verification result of the associated data packet as a security verification failure;
[0016] Performing integrity verification on the associated data packet; if the integrity verification succeeds, determining the security verification result of the associated data packet as a security verification success; if the integrity verification fails, determining the security verification result of the associated data packet as a security verification failure;
[0017] Decrypt and verify the integrity of the associated data packet; if the decryption is successful and the integrity verification is successful, the security verification result of the associated data packet is determined to be security verification success; if the decryption fails or the integrity verification fails, the security verification result of the associated data packet is determined to be security verification failure.
[0018] In some embodiments, the user plane control signaling includes one or more of the following:
[0019] Packet Data Convergence Protocol PDCP control protocol data unit PDU;
[0020] Radio link control RLC control PDU;
[0021] Media Access Control MAC Control Unit CE.
[0022] In some embodiments, performing security verification on data packets associated with user plane control signaling includes:
[0023] In the PDCP layer, security verification is performed on associated data packets;
[0024] Determining a security verification result of the user plane control signaling based on the security verification result of the associated data packet includes:
[0025] In the layer corresponding to the user plane control signaling, the security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
[0026] In some embodiments, the user plane control signaling has an associated data packet, and the method further includes:
[0027] The PDCP layer sends the security verification result of an associated data packet to the corresponding layer of the user plane control signaling.
[0028] In some embodiments, the user plane control signaling has multiple associated data packets, and the method further includes any one of the following:
[0029] After the PDCP layer performs security verification on each associated data packet, it sends the security verification result of the associated data packet to the corresponding layer of the user plane control signaling;
[0030] After performing security verification on the first associated data packet, the PDCP layer sends the security verification result of the first associated data packet to the corresponding layer of the user plane control signaling, where the first associated data packet is a data packet in the multiple associated data packets;
[0031] After the PDCP layer completes the security verification of all associated data packets, if the security verification of all associated data packets is successful, it sends the security verification success result to the corresponding layer of the user plane control signaling;
[0032] After determining that the security verification of any associated data packet fails, the PDCP layer sends the security verification failure result to the corresponding layer of the user plane control signaling.
[0033] In some embodiments, the method further comprises:
[0034] If the security verification of the user plane control signaling is successful, applying the user plane control signaling in the user plane control signaling corresponding layer;
[0035] If the security verification of the user plane control signaling fails, the user plane control signaling is discarded.
[0036] In some embodiments, the method further comprises:
[0037] When the user plane control signaling is obtained through parsing, the user plane control signaling is applied;
[0038] When the security verification of the user plane control signaling is successful, maintaining the application result of the user plane control signaling;
[0039] In the event that the security verification of the user plane control signaling fails, the system falls back to the state before receiving the transport block or falls back to a preset state.
[0040] In some embodiments, the method further comprises:
[0041] If the associated data packet is an empty data packet, and the empty data packet has undergone one or more operations of encryption and integrity protection, the associated data packet is discarded after completing security verification of the associated data packet.
[0042] In some embodiments, determining a security verification result of user plane control signaling based on a security verification result of an associated data packet includes:
[0043] Determining target user plane control signaling to be security verified based on the configuration information;
[0044] If the user plane control signaling is target user plane control signaling, the security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
[0045] In a second aspect, the present disclosure provides a method for security verification of user plane control signaling, including:
[0046] generating user plane control signaling;
[0047] A transmission block including user plane control signaling is sent, where the transmission block also includes an associated data packet of the user plane control signaling, or a transmission block having a deterministic time relationship with the transmission time of the transmission block includes an associated data packet of the user plane control signaling, and the security verification result of the associated data packet is used to determine the security verification result of the user plane control signaling.
[0048] In some embodiments, the transport block also includes an associated data packet, the associated data packet includes radio resource control RRC signaling or user plane data, the radio resource control RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection, the method further includes:
[0049] Generate a first media access control protocol MAC sub-protocol data unit subPDU based on radio resource control RRC signaling or user plane data;
[0050] generating a second MAC subPDU based on the user plane control signaling;
[0051] organizing the first MAC subPDU and the second MAC subPDU in a first transport block;
[0052] Sending a transport block including user plane control signaling, comprising:
[0053] A first transport block is sent.
[0054] In some embodiments, the transmission block further includes associated data packets, the associated data packets include null data packets, and the null data packets undergo one or more of the following operations: encryption and integrity protection. The method further includes:
[0055] generating a second MAC subPDU based on the user plane control signaling;
[0056] If no data packet to be sent exists in the buffer, a null data packet is generated, an operation is performed on the null data packet, and a third MAC subPDU is generated based on the null data packet after the operation, the operation including one or more of the following: encryption and integrity protection;
[0057] organizing the second MAC subPDU and the third MAC subPDU in a second transport block;
[0058] Sending a transport block including user plane control signaling, comprising:
[0059] Send a second transport block.
[0060] In some embodiments, the transmission block further includes associated data packets, the associated data packets include null data packets, and the null data packets undergo one or more of the following operations: encryption and integrity protection. The method further includes:
[0061] In a case where it is determined that there is a user plane control signaling security verification requirement, generating a null data packet, performing an operation on the null data packet, and generating a third MAC subPDU based on the null data packet after the operation, the operation including one or more of the following: encryption and integrity protection;
[0062] generating a second MAC subPDU based on the user plane control signaling;
[0063] If there is no data packet to be sent in the buffer, organizing the second MAC subPDU and the third MAC subPDU into a second transmission block;
[0064] Sending a transport block including user plane control signaling, comprising:
[0065] Send a second transport block.
[0066] In some embodiments, the method further comprises:
[0067] A null data packet indication is added in the PDCP header of the PDCP PDU containing the null data packet, or in the RLC header of the RLC PDU, or in the MAC subheader of the MAC subPDU.
[0068] In some embodiments, a transport block having a deterministic time relationship with a transmission time of the transport block includes an associated data packet, the associated data packet includes RRC signaling or user plane data, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption and integrity protection, and the method further includes:
[0069] Generate a first MAC subPDU based on RRC signaling or user plane data;
[0070] generating a second MAC subPDU based on the user plane control signaling;
[0071] Organizing the second MAC subPDU in a third transmission block, where the third transmission block does not include other MAC subPDUs;
[0072] organizing the first MAC subPDU in a fourth transport block, the fourth transport block being a transport block having a deterministic time relationship with a transmission time of the third transport block;
[0073] sending a fourth transport block;
[0074] Sending a transport block including user plane control signaling, comprising:
[0075] The third transport block is sent.
[0076] In some embodiments, the fourth transmission block includes any one of the following:
[0077] A transport block whose transmission time is the last transmission of the third transport block;
[0078] a transport block whose transmission time is the next transmission of the third transport block;
[0079] A transport block that is transmitted simultaneously with the third transport block, wherein simultaneously means that the transmission time overlaps or completely overlaps with the third transport block.
[0080] In some embodiments, the method further comprises:
[0081] Determining target user plane control signaling to be security verified based on the configuration information;
[0082] If the user plane control signaling is the target user plane control signaling, an associated data packet of the user plane control signaling is determined.
[0083] In some embodiments, the user plane control signaling includes one or more of the following:
[0084] Packet Data Convergence Protocol PDCP control protocol data unit PDU;
[0085] Radio link control RLC control PDU;
[0086] Media Access Control MAC Control Unit CE.
[0087] In a third aspect, the present disclosure provides a security verification device for user plane control signaling, including a memory, a transceiver, and a processor:
[0088] A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of a processor; and a processor for reading the computer program in the memory and performing the following operations:
[0089] Receive a transport block and parse the transport block to obtain user plane control signaling;
[0090] Perform security verification on data packets associated with user plane control signaling;
[0091] The security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
[0092] In some embodiments, the associated data packet includes one or more of the following:
[0093] Radio resource control (RRC) signaling or user plane data organized in the same transport block as user plane control signaling, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection;
[0094] Null data packets organized in the same transport block as user plane control signaling undergo one or more of the following operations: encryption, integrity protection;
[0095] The RRC signaling or user plane data in a transmission block that has a deterministic time relationship with the transmission time of the transmission block where the user plane control signaling is located, the RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection; the deterministic time relationship includes any one of the following:: it is the previous transmission of the transmission block where the user plane control signaling is located, or, it is the next transmission of the transmission block where the user plane control signaling is located, or, it is transmitted simultaneously with the transmission block where the user plane control signaling is located, and simultaneous transmission means that the transmission time overlaps or completely overlaps with the transmission time of the transmission block where the user plane control signaling is located.
[0096] In some embodiments, performing security verification on data packets associated with user plane control signaling specifically includes any one of the following:
[0097] Decrypting the associated data packet; if the decryption is successful, determining the security verification result of the associated data packet as a security verification success; if the decryption fails, determining the security verification result of the associated data packet as a security verification failure;
[0098] Performing integrity verification on the associated data packet; if the integrity verification succeeds, determining the security verification result of the associated data packet as a security verification success; if the integrity verification fails, determining the security verification result of the associated data packet as a security verification failure;
[0099] Decrypt and verify the integrity of the associated data packet; if the decryption is successful and the integrity verification is successful, the security verification result of the associated data packet is determined to be security verification success; if the decryption fails or the integrity verification fails, the security verification result of the associated data packet is determined to be security verification failure.
[0100] In some embodiments, the user plane control signaling includes one or more of the following:
[0101] Packet Data Convergence Protocol PDCP control protocol data unit PDU;
[0102] Radio link layer control protocol RLC control PDU;
[0103] Radio link layer control protocol RLC control PDU;
[0104] Media Access Control Protocol MAC Control Unit CE.
[0105] In some embodiments, security verification is performed on data packets associated with user plane control signaling, specifically including:
[0106] In the PDCP layer, security verification is performed on associated data packets;
[0107] Determining a security verification result of the user plane control signaling based on the security verification result of the associated data packet includes:
[0108] In the layer corresponding to the user plane control signaling, the security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
[0109] In some embodiments, the user plane control signaling has an associated data packet, and the processor is further configured to perform any one of the following operations:
[0110] The PDCP layer sends the security verification result of an associated data packet to the corresponding layer of the user plane control signaling.
[0111] The PDCP layer sends the security verification result of an associated data packet to the corresponding layer of the user plane control signaling.
[0112] In one embodiment, the user plane control signaling has multiple associated data packets, and the processor is further configured to perform the following operations:
[0113] After the PDCP layer performs security verification on each associated data packet, it sends the security verification result of the associated data packet to the corresponding layer of the user plane control signaling;
[0114] After performing security verification on the first associated data packet, the PDCP layer sends the security verification result of the first associated data packet to the corresponding layer of the user plane control signaling, where the first associated data packet is a data packet in the multiple associated data packets;
[0115] After the PDCP layer completes the security verification of all associated data packets, if the security verification of all associated data packets is successful, it sends the security verification success result to the corresponding layer of the user plane control signaling;
[0116] After determining that the security verification of any associated data packet fails, the PDCP layer sends the security verification failure result to the corresponding layer of the user plane control signaling.
[0117] In some embodiments, the processor is further configured to perform the following operations:
[0118] If the security verification of the user plane control signaling is successful, applying the user plane control signaling in the user plane control signaling corresponding layer;
[0119] If the security verification of the user plane control signaling fails, the user plane control signaling is discarded.
[0120] In some embodiments, the processor is further configured to perform the following operations:
[0121] When the user plane control signaling is obtained through parsing, the user plane control signaling is applied;
[0122] When the security verification of the user plane control signaling is successful, maintaining the application result of the user plane control signaling;
[0123] In the event that the security verification of the user plane control signaling fails, the system falls back to the state before receiving the transport block or falls back to a preset state.
[0124] In some embodiments, the processor is further configured to perform the following operations:
[0125] If the associated data packet is an empty data packet, and the empty data packet has undergone one or more operations of encryption and integrity protection, the associated data packet is discarded after completing security verification of the associated data packet.
[0126] In some embodiments, determining a security verification result of user plane control signaling based on a security verification result of an associated data packet specifically includes:
[0127] Determining target user plane control signaling to be security verified based on the configuration information;
[0128] If the user plane control signaling is target user plane control signaling, the security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
[0129] In a fourth aspect, the present disclosure provides a user plane control signaling security verification device, including a memory, a transceiver, and a processor:
[0130] A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of a processor; and a processor for reading the computer program in the memory and performing the following operations:
[0131] generating user plane control signaling;
[0132] A transport block including user plane control signaling is sent, where the transport block also includes an associated data packet of the user plane control signaling, or a transport block having a deterministic time relationship with the transmission time of the transport block includes an associated data packet of the user plane control signaling, and the security verification result of the associated data packet is used to determine the security verification result of the user plane control signaling.
[0133] In some embodiments, the transport block also includes an associated data packet, the associated data packet includes radio resource control RRC signaling or user plane data, the radio resource control RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection, and the processor is further configured to perform the following operations:
[0134] Generate a first media access control protocol MAC sub-protocol data unit subPDU based on radio resource control RRC signaling or user plane data;
[0135] generating a second MAC subPDU based on the user plane control signaling;
[0136] organizing the first MAC subPDU and the second MAC subPDU in a first transport block;
[0137] Sending a transport block including user plane control signaling, specifically including:
[0138] A first transport block is sent.
[0139] In some embodiments, the transport block further includes associated data packets, the associated data packets include null data packets, the null data packets undergo one or more of the following operations: encryption, integrity protection, and the processor is further configured to perform the following operations:
[0140] generating a second MAC subPDU based on the user plane control signaling;
[0141] If there is no data packet to be sent in the buffer, generate an empty data packet, perform an operation on the empty data packet, and generate a third MAC subPDU based on the empty data packet after the operation, the operation including one or more of the following: encryption and integrity protection;
[0142] organizing the second MAC subPDU and the third MAC subPDU in a second transport block;
[0143] Sending a transport block including user plane control signaling, specifically including:
[0144] Send a second transport block.
[0145] In some embodiments, the transport block further includes associated data packets, the associated data packets include null data packets, and the null data packets undergo one or more of the following operations: encryption and integrity protection. The processor is further configured to perform the following operations:
[0146] In a case where it is determined that there is a user plane control signaling security verification requirement, generating a null data packet, performing an operation on the null data packet, and generating a third MAC subPDU based on the null data packet after the operation, the operation including one or more of the following: encryption and integrity protection;
[0147] generating a second MAC subPDU based on the user plane control signaling;
[0148] If there is no data packet to be sent in the buffer, organizing the second MAC subPDU and the third MAC subPDU into a second transmission block;
[0149] Sending a transport block including user plane control signaling, specifically including:
[0150] Send a second transport block.
[0151] In some embodiments, the processor is further configured to perform the following operations:
[0152] A null data packet indication is added in the PDCP header of the PDCP PDU containing the null data packet, or in the RLC header of the RLC PDU, or in the MAC subheader of the MAC subPDU.
[0153] In some embodiments, a transport block having a deterministic time relationship with a transmission time of the transport block includes an associated data packet, the associated data packet includes RRC signaling or user plane data, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption and integrity protection, and the processor is further configured to perform the following operations:
[0154] Generate a first MAC subPDU based on RRC signaling or user plane data;
[0155] generating a second MAC subPDU based on the user plane control signaling;
[0156] Organizing the second MAC subPDU in a third transmission block, where the third transmission block does not include other MAC subPDUs;
[0157] organizing the first MAC subPDU in a fourth transport block, the fourth transport block being a transport block having a deterministic time relationship with a transmission time of the third transport block;
[0158] sending a fourth transport block;
[0159] sending a fourth transport block;
[0160] Sending a transport block including user plane control signaling, specifically including:
[0161] The third transport block is sent.
[0162] In some embodiments, the fourth transmission block includes any one of the following:
[0163] A transport block whose transmission time is the last transmission of the third transport block;
[0164] a transport block whose transmission time is the next transmission of the third transport block;
[0165] A transport block that is transmitted simultaneously with the third transport block, wherein simultaneously means that the transmission time overlaps or completely overlaps with the third transport block.
[0166] In some embodiments, the processor is further configured to perform the following operations:
[0167] Determining target user plane control signaling to be security verified based on the configuration information;
[0168] If the user plane control signaling is the target user plane control signaling, an associated data packet of the user plane control signaling is determined.
[0169] In one embodiment, the user plane control signaling includes one or more of the following:
[0170] Packet Data Convergence Protocol PDCP control protocol data unit PDU;
[0171] Radio link control RLC control PDU;
[0172] Media Access Control MAC Control Unit CE.
[0173] In a fifth aspect, the present disclosure provides a security verification device for user plane control signaling, including:
[0174] A receiving unit, configured to receive a transport block and parse the transport block to obtain user plane control signaling;
[0175] A verification unit, configured to perform security verification on data packets associated with user plane control signaling;
[0176] The determining unit is configured to determine a security verification result of the user plane control signaling according to a security verification result of the associated data packet.
[0177] In a sixth aspect, the present disclosure provides a security verification device for user plane control signaling, including:
[0178] A first generating unit, configured to generate user plane control signaling;
[0179] A first sending unit is configured to send a transmission block including user plane control signaling, wherein the transmission block also includes an associated data packet of the user plane control signaling, or a transmission block having a deterministic time relationship with the transmission time of the transmission block includes an associated data packet of the user plane control signaling, wherein the security verification result of the associated data packet is used to determine the security verification result of the user plane control signaling.
[0180] In the seventh aspect, the present disclosure also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it implements the security verification method for user plane control signaling provided by the first aspect or any one of the embodiments of the first aspect, or implements the security verification method for user plane control signaling provided by the second aspect or any one of the embodiments of the second aspect.
[0181] In the eighth aspect, the present disclosure also provides a computer program product, including a computer program, which, when executed by a processor, implements the security verification method for user plane control signaling provided by the first aspect or any one of the embodiments of the first aspect, or implements the security verification method for user plane control signaling provided by the second aspect or any one of the embodiments of the second aspect.
[0182] The details of one or more embodiments of the present disclosure are set forth in the accompanying drawings and the description below. Other features, objects, and advantages of the present disclosure will become apparent from the description, drawings, and claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0183] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0184] FIG1 is a schematic diagram showing a key generation mechanism of a 5G system in the related art;
[0185] FIG2 shows a schematic diagram of a 5G system user plane protocol stack in the related art;
[0186] FIG3 shows a schematic diagram of a 5G system control plane protocol stack in the related art;
[0187] FIG4 is a diagram illustrating an application environment of a method for verifying the security of user plane control signaling according to an embodiment of the present disclosure;
[0188] FIG5 is a schematic flow chart of a method for verifying the security of user plane control signaling according to an embodiment of the present disclosure;
[0189] FIG6 is a schematic flow chart of a method for verifying the security of user plane control signaling according to an embodiment of the present disclosure;
[0190] FIG7 is a schematic flow chart of a method for verifying the security of user plane control signaling according to an embodiment of the present disclosure;
[0191] FIG8 is a schematic flow chart of a method for verifying the security of user plane control signaling according to an embodiment of the present disclosure;
[0192] FIG9 is a schematic flow chart of a method for verifying the security of user plane control signaling according to an embodiment of the present disclosure;
[0193] FIG10 is a schematic flow chart of a method for verifying the security of user plane control signaling according to an embodiment of the present disclosure;
[0194] FIG11 is a schematic flow chart of a method for verifying the security of user plane control signaling according to an embodiment of the present disclosure;
[0195] FIG12 is a structural block diagram of a device for verifying the security of user plane control signaling according to an embodiment of the present disclosure;
[0196] FIG13 is a structural block diagram of a device for verifying the security of user plane control signaling according to an embodiment of the present disclosure;
[0197] FIG14 is a structural diagram of a device for verifying the security of user plane control signaling in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0198] In the embodiments of the present disclosure, the term "and / or" describes the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally indicates that the associated objects are in an "or" relationship.
[0199] In the embodiments of the present disclosure, the term "plurality" refers to two or more than two, and other quantifiers are similar thereto.
[0200] The following will be combined with the accompanying drawings in the embodiments of the present disclosure to clearly and completely describe the technical solutions in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure and not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present disclosure.
[0201] Figure 1 shows a schematic diagram of the key generation mechanism of the 5G system. As shown in Figure 1, the keys used in the access network include K RRCint , K RRCenc , K UPint and K UPenc , where K RRCint Used for Radio Resource Control (RRC) signaling integrity protection, K RRCenc Used for RRC signaling encryption, K UPint Used for user plane data integrity protection, K UPenc Used for user plane data encryption. As can be seen, the 5G system provides a security protection mechanism for RRC signaling and user plane data. The other parts shown in Figure 1 can refer to the relevant technology and will not be repeated here.
[0202] Figure 2 shows a schematic diagram of the user plane protocol stack of a 5G system. As shown in Figure 2, on the user plane, the protocol stack of the user equipment (UE) may include, from top to bottom, the Service Data Adaptation Protocol (SDAP), Packet Data Convergence Protocol (PDCP), Radio Link Control (RLC) protocol, Medium Access Control (MAC) protocol, and the physical layer (PHY) protocol. On the user plane, the protocol layers of a 5G base station (gNB) may include, from top to bottom, SDAP, PDCP, RLC, MAC, and PHY (physical layer). As shown in Figure 2, the protocol layers of the UE correspond to the protocol layers of the gNB.
[0203] Figure 3 shows a schematic diagram of the 5G system control plane protocol stack. As shown in Figure 3, on the control plane, the UE's protocol stack may include, from top to bottom: the Non-Access Stratum (NAS) protocol, the Radio Resource Control (RRC) protocol, the PDCP, the RLC protocol, the MAC protocol, and the PHY protocol. On the control plane, the gNB's protocol stack may include, from top to bottom: the RRC protocol, PDCP, the RLC protocol, the MAC protocol, and the PHY protocol. The protocol stack of the Authentication Management Function (AMF) of the 5G core network may include NAS. As shown in Figure 3, the NAS layer of the UE corresponds to the NAS layer of the AMF, and the UE's RRC layer, PDCP layer, RLC layer, MAC layer, and PHY layer correspond one-to-one to the RRC layer, PDCP layer, RLC layer, MAC layer, and PHY layer of the gNB.
[0204] In the 5G system, the encryption and integrity protection functions of RRC signaling and user plane data are implemented at the PDCP layer on the sending end. After completing the encryption and / or integrity protection of the RRC signaling or user plane data, the PDCP layer on the sending end submits the generated PDCP protocol data unit (PDU) to the RLC layer. The RLC layer submits it to the MA layer after processing. Finally, the MAC layer organizes the PDCP PDU into a MAC PDU and submits it to the physical layer for air interface transmission. After receiving the data transmitted over the air interface, the receiving end passes through the MAC layer, RLC layer and PDCP layer in sequence, and finally the PDCP layer completes one or more of the following operations: decryption and integrity verification. The PDCP layer will submit the RRC signaling or user plane data that has been successfully operated to the upper layer (such as the RRC layer or the application layer). The successful operation includes one or more of the following: successful decryption and successful integrity verification. If the decryption fails or the integrity verification fails, the PDCP layer will discard the RRC signaling or user plane data.
[0205] In addition to RRC signaling, the 5G system also has user-plane control signaling, such as the MAC Control Element (CE). There are many types of MAC CEs, each with different functions, such as buffer reporting, discontinuous reception (DRX) commands, timing advance (TA) commands, power headroom reports (PHR), secondary cell activation / deactivation, transmission configuration indicators (TCIs) for various channels, PDCP duplication indications, beam failure recovery (BFR) indications, listen before talk (LBT) failure indications, and integrated access and backhaul (IAB) timing offset indications. MAC CEs are generated at the MAC layer. The transmitter organizes them into MAC PDUs and sends them to the receiver. After the MAC layer at the receiver parses the MAC CEs, they can be directly applied. As can be seen, MAC CEs in the 5G system do not have encryption and decryption processes, nor do they have integrity protection and integrity verification processes. In addition to the MAC layer, the PDCP layer and the RLC layer also have control PDUs, namely user plane control signaling, which have different functions. The PDCP control PDUs and the RLC control PDUs are not encrypted or integrity protected.
[0206] User-plane control signaling, especially MAC CE, has numerous functions. Without security verification mechanisms such as encryption and decryption, security is compromised. For example, if a fake base station sends a false timing adjustment command to a terminal, data transmission or even connection failure between the terminal and the legitimate base station may occur. A malicious terminal, impersonating another terminal and sending a large number of buffer reports, can disrupt base station resource allocation, impacting transmissions for other terminals and overall system performance.
[0207] The embodiments of the present disclosure provide a method and apparatus for security verification of user plane control signaling, which are used to determine the security verification result of the user plane control signaling based on the security verification result of the associated data packets of the user plane control signaling, thereby achieving security verification of the user plane control signaling without performing one or more operations of encryption and integrity protection on the user plane control signaling, thereby reducing the adverse effects caused by malicious attacks on the network by pseudo base stations or malicious terminals through unencrypted and unintegrity-protected user plane control signaling, and improving network security.
[0208] Among them, the method and the device are based on the same application concept. Since the principles of solving problems by the method and the device are similar, the implementation of the device and the method can refer to each other, and the repeated parts will not be repeated.
[0209] In an exemplary embodiment, the security verification method for user plane control signaling provided by the embodiment of the present disclosure may be applied in an application environment as shown in Figure 4. In the embodiment, the terminal device 100 and the network device 200 communicate with each other via a wireless system.
[0210] The technical solutions provided by the embodiments of the present disclosure can be applicable to a variety of wireless systems. For example, applicable systems may be Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Long Term Evolution Advanced (LTE-A) systems, Universal Mobile Telecommunication System (UMTS), Worldwide interoperability for Microwave access (WiMAX) systems, 5G New Radio (NR) systems and their evolved communication systems, etc. These various systems may include terminal devices and network devices. The system may also include a core network part, such as an evolved packet system (EPS), a 5G system (5GS), etc.
[0211] The terminal device involved in the embodiments of the present disclosure may be a device that provides voice and / or data connectivity to a user, a handheld device with wireless connection function, or other processing device connected to a wireless modem. In different systems, the name of the terminal device may also be different. For example, in a 5G system, the terminal device may be called User Equipment (UE). A wireless terminal device may be a USB storage device, other personal computer memory devices, and a dongle. It may also communicate with one or more core networks (CN) via a radio access network (RAN). A wireless terminal device may be a mobile terminal device, such as a mobile phone (or "cellular" phone) and a computer with a mobile terminal device. For example, it may be a portable, pocket-sized, handheld, computer-built-in, or vehicle-mounted mobile device that exchanges language and data with a radio access network. For example, Personal Communication Service (PCS) phones, cordless phones, Session Initiated Protocol (SIP) phones, Wireless Local Loop (WLL) stations, Personal Digital Assistants (PDAs), personal computers, tablet computers, Machine-type Communication (MTC) terminal devices, etc. Wireless terminal devices may also be referred to as systems, subscriber units, subscriber stations, mobile stations, mobile stations, remote stations, access points, remote terminal devices, access terminal devices, user terminal devices, user agents, user devices, and wireless access points and routers / modems that meet the limitations of this definition, but are not limited in the embodiments of the present disclosure.
[0212] The network device involved in the embodiments of the present disclosure may be a base station, which may include multiple cells providing services to the terminal. Depending on the specific application scenario, the base station may also be called an access point, or may be a device in the access network that communicates with the wireless terminal device through one or more sectors on the air interface, or other names. The network device may be used to interchange received air frames with Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, wherein the rest of the access network may include an Internet Protocol (IP) communication network. The network device may also coordinate the attribute management of the air interface. For example, the network device involved in the embodiments of the present disclosure may be an evolutionary network device (eNB or e-NodeB) in a long term evolution (LTE) system, a 5G base station (gNB) in a next generation 5G network architecture, etc., or a home evolved Node B (HeNB), a relay node, a femto, a pico base station, a network test device, etc., which is not limited in the embodiments of the present disclosure. In some network structures, network devices may include centralized unit (CU) nodes and distributed unit (DU) nodes, and the centralized unit and the distributed unit may also be arranged geographically separately.
[0213] The terminal device in the embodiment of the present disclosure sends relevant information or similar descriptions to the network device, which only indicates that the terminal device sends the relevant information in the form of a wireless signal, and its intended recipient is the network device. The network device can obtain the relevant information by receiving the wireless signal.
[0214] In an exemplary embodiment, the security verification method for user plane control signaling provided by the embodiments of the present disclosure can also be applied to sidelink scenarios. Sidelink technology is used in 5G (NR) for vehicle-to-everything (V2X) communications, and in sidelink relays for communication between terminals (vehicles). Sidelink extends network coverage beyond the direct coverage area of the network infrastructure.
[0215] In the embodiments of the present disclosure, a transmitting end may be a terminal, a base station, or a sidelink terminal, and a corresponding receiving end may be another terminal in the base station, the terminal, or the sidelink terminal. It should be noted that the above is merely an exemplary description of the transmitting end and the receiving end in the embodiments of the present disclosure and is not intended to limit the transmitting end and the receiving end.
[0216] In an exemplary embodiment, as shown in Figure 5, a method for verifying the security of user plane control signaling is provided, which can be applied to a transmitting end. As shown in Figure 5, the method can include the following steps.
[0217] Step S501: Generate user plane control signaling.
[0218] The transmitting end can generate user plane control signaling at different protocol layers. These user plane control signalings have different functions, such as buffer reporting, TA command, or IAB timing offset indication. In one example, user plane control signaling includes, but is not limited to, one or more of PDCP Control PDUs, RLC Control PDUs, and MAC CEs. The PDCP Control PDU is generated by the PDCP layer, the RLC Control PDU is generated by the RLC layer, and the MAC CE is generated by the MAC layer.
[0219] In the embodiments of the present disclosure, the protocol layer that generates user plane control signaling is referred to as the user plane control signaling corresponding layer. For example, the PDCP layer is referred to as the PDCP Control PDU corresponding layer; the RLC layer is referred to as the RLC Control PDU corresponding layer; and the MAC layer is referred to as the MAC CE corresponding layer.
[0220] After the transmitting end generates user plane control signaling at the protocol layer, it is processed sequentially by each protocol layer before being delivered to the MAC layer. The MAC layer then organizes the user plane control signaling into a MAC PDU and delivers it to the physical layer for air interface transmission. For example, the PDCP layer generates a PDCP Control PDU and passes it to the RLC layer for processing. The RLC layer then passes it to the MAC layer for further processing. The MAC layer then organizes the PDCP Control PDU into a MAC PDU.
[0221] Step S502: Send a transport block including user plane control signaling, the transport block also including a data packet associated with the user plane control signaling, or a transport block having a deterministic time relationship with the transmission time of the transport block including a data packet associated with the user plane control signaling.
[0222] A transport block (TB) is a data block containing a MAC PDU. A transport block represents the amount of data to be transmitted within a period of time, and its size affects the bandwidth and symbol rate.
[0223] The transmitting end sends a transport block including user plane control signaling to the receiving end. In this way, after receiving the transport block, the receiving end can parse the user plane control signaling from it and apply the user plane control signaling to implement the function corresponding to the user plane control signaling.
[0224] The transmitting end may also send a data packet associated with user plane control signaling to the receiving end. This associated data packet is a data packet that is associated with the user plane control signaling in terms of transmission time. The security verification result of the associated data packet can be used to determine the security verification result of the user plane control signaling. In this way, after receiving at least one transport block, the receiving end can determine the security verification result of the user plane control signaling based on the security verification result of the associated data packet, thereby implementing security verification of the user plane control signaling.
[0225] In one example, the associated data packet of the user plane control signaling may include one or more of the following: radio resource control (RRC) signaling or user plane data organized in the same transport block as the user plane control signaling, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption and integrity protection; an empty data packet organized in the same transport block as the user plane control signaling, and the empty data packet undergoes one or more of the following operations: encryption and integrity protection; RRC signaling or user plane data in a transport block that has a deterministic time relationship with the transmission time of the transport block where the user plane control signaling is located, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption and integrity protection. The deterministic time relationship includes any of the following: the previous transmission of the transport block where the user plane control signaling is located, or the next transmission of the transport block where the user plane control signaling is located, or the transmission performed simultaneously with the transport block where the user plane control signaling is located, where simultaneous transmission refers to overlapping or complete overlap with the transmission time of the transport block where the user plane control signaling is located.
[0226] The RRC signaling that undergoes one or more encryption and integrity protection operations includes any of the following: encrypted RRC signaling; integrity-protected RRC signaling; and encrypted and integrity-protected RRC signaling. User plane data that undergoes one or more encryption and integrity protection operations, and null data packets that undergo one or more encryption and integrity protection operations, may refer to the RRC signaling that undergoes one or more encryption and integrity protection operations, and are not further described here.
[0227] In the disclosed embodiments, user plane control signaling and associated data packets may be organized in the same transport block or in different transport blocks. That is, the transport block containing user plane control signaling and the transport block containing associated data packets sent from the transmitter to the receiver may be the same transport block or different transport blocks. The associated data packets may be existing data packets (RRC signaling or user plane data) or newly generated empty data packets. The following describes the transport block generation and transmission process for different associated data packets and different organization methods.
[0228] For ease of understanding, some of the terms involved below are first explained. The first MAC sub-protocol data unit (subPDU) may represent a MAC subPDU containing RRC signaling or user plane data, and the contained RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection. The second MAC subPDU may represent a MAC subPDU containing user plane control signaling. The third MAC subPDU may represent a MAC subPDU containing an empty data packet. The first transmission block may represent a transmission block containing a first MAC subPDU and a second MAC subPDU, the second transmission block may represent a transmission block containing a second MAC subPDU and a third MAC subPDU, the third transmission block may represent a transmission block containing only a second MAC subPDU, and the fourth transmission block may represent a transmission block having a deterministic time relationship with the third transmission block in terms of transmission time.
[0229] In one possible implementation, user plane control signaling and associated data packets are organized in the same transport block (i.e., the transport block that includes the user plane control signaling also includes the associated data packets). The associated data packets include RRC signaling or user plane data, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption and integrity protection. The transmitting end may generate a first MAC subPDU based on the RRC signaling or user plane data; generate a second MAC subPDU based on the user plane control signaling; and organize the first MAC subPDU and the second MAC subPDU into the first transport block. Accordingly, step S502 may include: sending the first transport block.
[0230] Take MAC CE as user plane control signaling as an example. On the one hand, the transmitter performs one or more of the following operations on the RRC signaling or user plane data at the PDCP layer: encryption, integrity protection, generating a PDCP PDU, and delivering the PDCP PDU to the lower layer up to the MAC layer. The transmitter processes the PDCP PDU at the MAC layer to obtain a first MAC subPDU. On the other hand, the transmitter processes the MAC CE at the MAC layer to obtain a second MAC subPDU. Afterwards, the transmitter organizes the first MAC subPDU containing the PDCP PDU and the second MAC subPDU containing the MAC CE at the MAC layer into the same transport block (i.e., the first transport block) at the MAC layer.
[0231] It should be noted that the embodiment of the present disclosure does not restrict the order of generating the first MAC subPDU and generating the second MAC subPDU. The first MAC subPDU can be generated before or after the second MAC subPDU, or it can be generated at the same time as the second MAC subPDU. When the MAC layer of the transmitting end needs to send the second MAC subPDU, if it finds that the first MAC subPDU exists in the cache, the two can be organized in the same transmission block. Similarly, when the MAC layer of the transmitting end needs to send the first MAC subPDU, if it finds that the second MAC subPDU exists in the cache, the two can be organized in the same transmission block. In the embodiment of the present disclosure, the first MAC subPDU and the second MAC subPDU can be organized in the same transmission block. In addition, the process of generating MAC subPDU (including the first MAC subPDU, the second MAC subPDU and the third MAC subPDU, etc.) in the embodiment of the present disclosure can refer to the relevant technology, and the process of transmitting PDU between different protocol layers can also refer to the relevant technology, which will not be repeated here.
[0232] Since the PDCP layer at the receiving end can decrypt encrypted RRC signaling or user-plane data, and the PCDP layer at the receiving end can perform integrity verification on integrity-protected RRC signaling or user-plane data, when user-plane control signaling and RRC signaling or user-plane data (which undergo one or more of the following operations: encryption, integrity protection) are organized in the same transport block, the user-plane control signaling and the RRC signaling or user-plane data undergo the same network transmission process. If the network is attacked maliciously, the RRC signaling or user-plane data operation will fail. The operation failure includes one or more of the following: decryption failure and integrity verification failure. Therefore, the receiving end can determine the security verification result of the user-plane control signaling based on the security verification result of the data packet associated with the user-plane control signaling.
[0233] Considering that when the sending end needs to send user plane control signaling, there may be no other data packets to be sent in the cache, the sending end can generate an empty data packet at this time, use the operated empty data packet as an associated data packet of the user plane control signaling, and send the two together, so that the receiving end can determine the security verification result of the user plane control signaling based on the security verification result of the empty data packet, where the operation can include one or more of the following: encryption, integrity protection.
[0234] In one possible implementation, user plane control signaling and associated data packets are organized in the same transport block (i.e., the transport block that includes the user plane control signaling also includes the associated data packets). The associated data packets may include a null data packet, which undergoes one or more of the following operations: encryption and integrity protection. The transmitting end may generate a second MAC subPDU based on the user control signaling; if no data packets to be sent exist in the cache, generate a null data packet, and generate a third MAC subPDU based on the null data packet after the operations, which may include one or more of the following operations: encryption and integrity protection; and organizing the second MAC subPDU and the third MAC subPDU in the second transport block. Accordingly, step S502 may include: transmitting the second transport block.
[0235] Take MAC CE as the user plane control signaling as an example. First, the sending end generates a MAC CE at the MAC layer and processes the MAC CE to obtain the second MAC subPDU. Afterwards, the sending end determines whether there is a data packet to be sent in the cache at the MAC layer. If there is no data packet to be sent, it notifies the PDCP layer to generate an empty data packet. After receiving the notification, the PDCP layer of the sending end generates an empty data packet and operates on the empty data packet to obtain a PDCP PDU. The operation includes one or more of the following: encryption and integrity protection. Afterwards, the PDCU layer of the sending end delivers the PDCP PDU to the MAC layer through the various protocol layers of the sending end. The MAC layer of the sending end processes the PDCP PDU to obtain a third MAC subPDU. Finally, the sending end organizes the third MAC subPDU containing the PDCP PDU and the second MAC subPDU containing the MAC CE in the same transmission block (i.e., the second transmission block) at the MAC layer.
[0236] Because the null data packet is generated and manipulated by the PDCP layer at the transmitting end, the PDCP layer at the receiving end is able to decrypt the encrypted null data and perform integrity verification on the integrity-protected null data. When user-plane control signaling and the manipulated null data packet are organized in the same transmission block, the network transmission process experienced by the user-plane control signaling and the manipulated null data packet is similar. Therefore, the receiving end can determine the security verification result of the user-plane control signaling based on the security verification result of the data packet associated with the user-plane control signaling, where the operations involved may include one or more of the following: encryption and integrity protection.
[0237] In one example, the transmitting end may add an empty data packet indication in the PDCP header of the PDCP PDU containing the empty data packet, or in the RLC header of the RLC PDU, or in the MAC subheader of the MAC subPDU. In other words, the transmitting end may add an empty data packet indication when generating empty data or in the process of transmitting the empty data packet. In this way, after the receiving end performs one or more operations including decryption and integrity verification on the empty data packet, the empty data packet may be discarded, thereby saving storage resources. The empty data packet indication may be an identifier such as "0" or "1", or may be other identifiers, and is not limited in comparison with the embodiments of the present disclosure.
[0238] The PDCP layer at the transmitting end generates an empty data packet and performs one or more operations of encryption and integrity protection on the empty data packet to generate a PDCP PDU. The PDCP layer at the transmitting end may add an empty data packet indication in the PDCP header. Alternatively, after the PDCP layer at the transmitting end generates the PDCP PDU, it passes the PDCP PDU to the RLC layer, and the RLC layer may generate an RLC PDU based on the PDCP PDU. The RLC layer may add an empty data packet indication in the RLC layer. Alternatively, the RLC layer may pass the RLC PDU to the MAC layer, and the MAC layer may generate a MAC subPDU based on the RLC PDU. The MAC layer may add an empty data packet indication in the MAC subheader.
[0239] In the disclosed embodiment, when the transmitting end needs to send user plane control signaling, the method of generating an empty data packet after discovering that there are no data packets to be sent in the cache can be called the transmitting end generating an empty data packet on demand, which can save storage resources. Of course, the transmitting end can also pre-generate an empty data packet and a third MAC subPDU containing the empty data packet for standby, and directly use the third MAC subPDU without waiting when discovering that there are no data packets to be sent in the cache. This method is called the transmitting end pre-generating an empty data packet, which can reduce waiting time and improve efficiency. The following describes the method of pre-generating an empty data packet by the transmitting end.
[0240] In one possible implementation, user plane control signaling and associated data packets are organized in the same transport block (i.e., the transport block including user plane control signaling also includes associated data packets), and the associated data packets include a null data packet, and the null data packet undergoes one or more of the following operations: encryption and integrity protection. Upon determining that there is a need for user plane control signaling security verification, the transmitting end may generate a null data packet, perform operations on the data packet, and generate a third MAC subPDU based on the null data packet after the operations, the operations including one or more of the following: encryption and integrity protection; generating a second MAC subPDU based on the user plane control signaling; and organizing the second MAC subPDU and the third MAC subPDU in a second transport block if no data packet to be sent exists in the cache. Accordingly, step S502 may include: sending the second transport block.
[0241] Take MAC CE as the user plane control signaling as an example. If the sending end determines that there is a need for security verification of the user plane control signaling (not for specific user plane control signaling), it will generate an empty data packet at the PDCP layer, perform one or more operations of encryption and integrity protection on the empty data packet, obtain the PDCP PDU, and pass the PDCP PDU to the MAC layer through the various protocol layers of the sending end. Then, the MAC layer of the sending end processes the PDCP PDU to obtain a third MAC subPDU for standby. The MAC layer of the sending end generates a MAC CE and processes the MAC CE to obtain a second MAC subPDU. Then, the MAC layer of the sending end determines whether there is a data packet to be sent in the cache. If there is no data packet to be sent, the third MAC subPDU containing the PDCP PDU and the second MAC subPDU containing the MAC CE are organized in the same transmission block (i.e., the second transmission block).
[0242] Considering that a transport block represents the amount of data to be transmitted over a period of time, its size affects bandwidth and symbol rate. The transmitter can adjust the transport block size as needed. Therefore, the transmitter may organize the second MAC subPDU after a transport block and not organize other MAC subPDUs in the same transport block. In this case, user plane control signaling and its associated data packets are sent in different transport blocks.
[0243] In one possible implementation, a transport block having a deterministic time relationship with the transmission time of a transport block containing user plane control signaling includes an associated data packet (i.e., the user plane control signaling and the associated data packet are organized in different transport blocks), the associated data packet includes RRC signaling or user plane data, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption and integrity protection. The transmitting end may generate a first MAC subPDU based on the RRC signaling or user plane data; generate a second MAC subPDU based on the user plane control signaling; organize the second MAC subPDU in a third transport block, the third transport block not including other MAC subPDUs; organize the first MAC subPDU in a fourth transport block, the fourth transport block being a different transport block from the third transport block, the fourth transport block being a transport block having a deterministic time relationship with the transmission time of the third transport block. Accordingly, step S502 may include: sending the third transport block and the fourth transport block.
[0244] In one example, the fourth transmission block includes any one of the following: a transmission block whose transmission time is the previous transmission of the third transmission block; a transmission block whose transmission time is the next transmission of the third transmission block; a transmission block transmitted simultaneously with the third transmission block, where simultaneous means that the transmission time overlaps or completely overlaps with the transmission time of the third transmission block.
[0245] Because the PDCP layer at the receiving end can decrypt encrypted RRC signaling or user-plane data, and the PCDP layer at the receiving end can perform integrity verification on integrity-protected RRC signaling or user-plane data, when user-plane control signaling and RRC signaling or user-plane data (which undergo one or more of encryption and integrity protection) are organized in adjacent transmission blocks, the user-plane control signaling and the RRC signaling or user-plane data undergo similar network transmission processes. If the network is attacked maliciously, the RRC signaling or user-plane data operation may fail. This operation failure may include one or more of the following: decryption failure and integrity verification failure. Therefore, the receiving end can determine the security verification result of the user-plane control signaling based on the security verification result of the data packet associated with the user-plane control signaling.
[0246] The above-mentioned security verification method for user plane control signaling determines the security of user plane control signaling based on the security verification results of the associated data packets of the user plane control signaling, and realizes the security verification of user plane control signaling without performing one or more operations of encryption and integrity protection on the user plane control signaling, thereby reducing the adverse effects caused by malicious attacks on the network by fake base stations or malicious terminals through unencrypted and unintegrity-protected user plane control signaling, and improving network security.
[0247] In one possible implementation, the security verification method of the user plane control signaling may also include: determining the target user plane control signaling to be security verified based on the configuration information; if the user plane control signaling in step S501 is the target user plane control signaling, determining the associated data packet of the user plane control signaling, and then sending the user plane control signaling and its associated data packet in the same transmission block or different transmission blocks.
[0248] The configuration information may be locally configured or sent by the receiving end. In one example, the configuration information may indicate which user plane control signaling requires (or enables) security verification. In some embodiments, an indication of whether security verification is required (supported / enabled) may be added to the RRC signaling that configures parameters related to specific user plane control signaling (such as BSR reporting). The configuration information may also indicate that all user plane control signaling requires security verification.
[0249] In addition, it may be stipulated at the transmitting end and the receiving end that all user plane control signaling must undergo security verification; it may also be stipulated that security verification must be performed for specific user plane control signaling.
[0250] If the transmitting end is a base station or a terminal that transmits RRC configuration in a sidelink, and the receiving end is a terminal or a terminal that receives RRC configuration in a sidelink, the transmitting end sends an indication of whether user plane control signaling requires security verification to the receiving end.
[0251] If the transmitting end is a Uu port terminal or a terminal receiving RRC configuration in Sidelink, and the receiving end is a base station or a terminal sending RRC configuration in Sidelink, the transmitting end receives an indication from the receiving end on whether user plane control signaling requires security verification.
[0252] In an exemplary embodiment, as shown in Figure 6, a method for security verification of user plane control signaling is provided, which can be applied to a receiving end. As shown in Figure 6, the method can include the following steps.
[0253] Step S601: Receive a transport block and parse the transport block to obtain user plane control signaling.
[0254] The receiving end may receive one or more transport blocks. The receiving end parses each received transport block separately. If the transport block contains user plane control signaling, the receiving end can parse the user plane control signaling from the transport block. The layer corresponding to the user plane control signaling can implement corresponding functions, such as buffer reporting and discontinuous reception, by applying this user plane control signaling.
[0255] In one example, the user plane control signaling may include: one or more of: PDCP control PDU, RLC control PDU and MAC CE. Accordingly, the corresponding layers of the user plane control signaling are the PDCP layer, RLC layer and MAC layer respectively.
[0256] Step S602: Perform security verification on data packets associated with user plane control signaling.
[0257] In one possible implementation, the associated data packet of the user plane control signaling may include one or more of the following: RRC signaling or user plane data organized in the same transmission block as the user plane control signaling, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection; an empty data packet organized in the same transmission block as the user plane control signaling, and the empty data packet undergoes one or more of the following operations: encryption, integrity protection; RRC signaling or user plane data in a transmission block that has a deterministic time relationship with the transmission time of the transmission block where the user plane control signaling is located, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection. Among them, the deterministic time relationship includes any of the following: the previous transmission of the transmission block where the user plane control signaling is located, or the next transmission of the transmission block where the user plane control signaling is located, or the transmission performed simultaneously with the transmission block where the user plane control signaling is located. Here, simultaneous transmission means overlapping or completely overlapping with the transmission time of the transmission block where the user plane control signaling is located.
[0258] The PDCP layer at the receiving end can perform security verification on the data packets associated with the user plane control signaling.
[0259] In one example, the method for performing security verification on the associated data packet may include any of the following: decrypting the associated data packet; if the decryption is successful, determining the security verification result of the associated data packet as a security verification success; if the decryption fails, determining the security verification result of the associated data packet as a security verification failure. Performing integrity verification on the associated data packet; if the integrity verification is successful, determining the security verification result of the associated data packet as a security verification success; if the integrity verification fails, determining the security verification result of the associated data packet as a security verification failure. Performing decryption and integrity verification on the associated data packet; if the decryption is successful and the integrity verification is successful, determining the security verification result of the associated data packet as a security verification success; if the decryption fails or the integrity verification fails, determining the security verification result of the associated data packet as a security verification failure.
[0260] The manner in which the PDCP layer can decrypt the associated data packets and perform security verification can be referred to in related technologies and will not be described in detail here.
[0261] Step S603: Determine the security verification result of the user plane control signaling according to the security verification result of the associated data packet.
[0262] In one possible implementation, step S602 may include: performing security verification on the associated data packet in the PDCP layer. Step S603 may include: determining the security verification result of the user plane control signaling based on the security verification result of the associated data packet in the layer corresponding to the user plane control signaling.
[0263] After the PACP layer at the receiving end performs security verification on the associated data packet, it may notify the corresponding layer for user plane control signaling of the security verification result. The notification method may refer to the information transmission method between protocol layers in the related art and will not be further described here. After receiving the security verification result of the associated data packet, the corresponding layer for user plane control signaling may determine the security verification result of the user plane control signaling based on the security verification result.
[0264] In the embodiment of the present disclosure, the number of data packets associated with the user plane control signaling may be one or more. In step S603, the receiving end may determine the security verification result of the user plane control signaling based on the security verification result of one associated data packet, or may comprehensively determine the security verification result of the user plane control signaling based on the security verification results of multiple associated data packets.
[0265] In one possible implementation, user plane control signaling has an associated data packet. The PDCP layer at the receiving end may send the security verification result of this associated data packet to the layer corresponding to the user plane control signaling. The layer corresponding to the user plane control signaling may determine the security verification result of this associated data packet as the security verification result of the user plane control signaling. In other words, if the security verification of this associated data packet succeeds, it can be determined that the security verification of the user plane control signaling succeeds; if the security verification of this associated data packet fails, it can be determined that the security verification of the user plane signaling fails.
[0266] In one possible implementation, there are multiple associated data packets for the user plane control signaling. The PDCP layer at the receiving end can perform security verification on each associated data packet, and then send the security verification result of the associated data packet to the corresponding layer of the user plane control signaling. The corresponding layer of the user plane control signaling can determine that the security verification of the user plane control signaling is successful if the security of all associated data packets is successfully verified; and determine that the security verification of the user plane control signaling is failed if the security verification of any associated data packet fails. In one example, the corresponding layer of the user plane control signaling can determine that the security verification of the user plane control signaling is failed when it receives the security verification result of the first associated data packet that fails security verification.
[0267] In one possible implementation, user plane control signaling may contain multiple associated data packets. The PDCP layer at the receiving end may perform security verification on the first of the multiple associated data packets and then send the security verification result of the first associated data packet to the layer corresponding to the user plane control signaling. The layer corresponding to the user plane control signaling may determine the security verification result of the first associated data packet as the security verification result of the user plane control signaling. This improves efficiency.
[0268] In one possible implementation, there are multiple associated data packets for the user plane control signaling. After completing the security verification of all associated data packets, the PDCP layer at the receiving end may send the result of the security verification success to the corresponding layer of the user plane control signaling if the security verification of all associated data packets is successful. If the corresponding layer of the user plane control signaling receives the result of the security verification success within a certain time (which can be set as needed and is not limited in the embodiments of the present disclosure), it can be determined that the security verification of the user plane control signaling is successful. If the corresponding layer of the user plane control signaling does not receive the result of the security verification success within a certain time, it can be determined that the security verification of the user plane control signaling has failed.
[0269] In one possible implementation, there are multiple associated data packets for user plane control signaling. The PDCP layer at the receiving end may send the result of security verification failure to the corresponding layer of the user plane control signaling after determining that the security verification of any associated data packet has failed. The PDCP layer at the receiving end may not send the security verification result if it is determined that the security verification of an associated data packet is successful, and may send the result of security verification failure and stop the security verification of the remaining associated data packets if it is determined that the security verification of an associated data packet has failed before the security verification of all data packets is completed. If the PDCP layer at the receiving end completes the security verification of all associated data packets and the security verification of all associated data packets is successful, the result of security verification success may be sent. If the corresponding layer of the user plane control signaling receives the result of security verification success, it is determined that the security verification of the user plane control signaling is successful; if the corresponding layer of the user plane control signaling receives the result of security performance verification failure, it is determined that the security verification of the user plane control signaling has failed.
[0270] The above-mentioned security verification method for user plane control signaling determines the security of user plane control signaling based on the security verification results of the associated data packets of the user plane control signaling, and realizes the security verification of user plane control signaling without performing one or more operations of encryption and integrity protection on the user plane control signaling, thereby reducing the adverse effects caused by malicious attacks on the network by fake base stations or malicious terminals through unencrypted and unintegrity-protected user plane control signaling.
[0271] In one possible implementation, the security verification method of the user plane control signaling may also include: if the security verification of the user plane control signaling is successful, applying the user plane control signaling in the corresponding layer of the user plane control signaling; if the security verification of the user plane control signaling fails, discarding the user plane control signaling.
[0272] In an embodiment of the present disclosure, after parsing the user plane control signaling, the receiving end can first determine the security verification result of the user plane control signaling based on the security verification result of the associated data packet, and then apply the user plane control signaling to implement the corresponding function if the security verification of the user plane control signaling is successful, thereby improving security.
[0273] In one possible implementation, the security verification method for the user plane control signaling may further include: applying the user plane control signaling when the user plane control signaling is obtained through parsing; maintaining the application result of the user plane control signaling when the security verification of the user plane control signaling is successful; and falling back to the state before receiving the transmission block where the user plane control signaling is located or falling back to a preset state when the security verification of the user plane control signaling fails.
[0274] Considering that determining the security verification result of user-plane control signaling takes a certain amount of time, in embodiments of the present disclosure, after parsing the user-plane control signaling, it can be directly applied without waiting for the security verification result of the user-plane control signaling. If the security verification of the user-plane control signaling subsequently fails, indicating that the user-plane control signaling is unreliable, and therefore applying the user-plane control signaling carries certain risks, it is possible to fall back to the state before receiving the transport block containing the user-plane control signaling, or to a preset state, thereby improving security.
[0275] In one example, the preset state may refer to a pre-set state, which may be an initial state, a temporary state, or a set state, etc. In the embodiment of the present disclosure, there is no limitation on the preset state.
[0276] In one possible implementation, the security verification method of the user plane control signaling may also include: if the associated data packet is an empty data packet, and the empty data packet has undergone one or more of the following operations: encryption, integrity protection, then after completing the security verification of the associated data packet through step S603, the associated data packet is discarded.
[0277] In the embodiment of the present disclosure, the null data packet is generated for verifying the user plane control signaling and has no practical significance. Therefore, after the security of the null data packet is verified, it can be directly discarded to save storage resources.
[0278] In one example, the transmitting end adds a null data packet indication in the PDCP header of the PDCP PDU containing the null data packet, or in the RLC header of the RLC PDU, or in the MAC subheader of the MAC subPDU. Therefore, the receiving end can determine whether the associated data packet is a null data packet based on the null data packet indication.
[0279] For example, if an empty data packet indication is added to the MAC subheader of the MAC subPDU, the MAC layer at the receiving end can identify that the associated data packet is actually an empty data packet and report it to the RLC layer and the PDCP layer. After the PDCP layer completes the security verification of the associated data packet, it can be discarded directly. If an empty data packet indication is added to the RLC header of the RLC PDU, the RLC layer at the receiving end can identify that the associated data packet is actually an empty data packet and report it to the PDCP layer. After the PDCP layer completes the security verification of the associated data packet, it can be discarded directly. If an empty data packet indication is added to the PDCP header of the PDCP PDU, the PDCP layer at the receiving end can identify that the associated data packet is actually an empty data packet. After the PDCP layer completes the security verification of the associated data packet, it can be discarded directly.
[0280] In another example, the transmitting end does not add an empty data packet indication for the empty data packet, for example, does not add an empty data packet indication in the PDCP header of the PDCP PDU containing the empty data packet, or in the RLC header of the RLC PDU, or in the MAC subheader of the MAC subPDU. After completing the security verification of the associated data packet, the receiving end PDCP can submit it to the upper layer (such as the RRC layer or the application layer), and the upper layer will discard the associated data packet after determining that the associated data packet is invalid.
[0281] In one possible implementation, the security verification method for the user plane control signaling may further include: if the security verification of the user plane control signaling fails, the layer where the user plane control signaling is located notifies the upper layer (such as the RRC layer or the application layer) of the failure of the security verification of the user plane control signaling so that the upper layer can perform further processing.
[0282] In one possible implementation, step S603 may include: determining the target user control signaling to be security verified based on the configuration information; if the user plane control signaling is the target user plane control signaling, determining the security verification result of the user plane control signaling based on the security verification of the associated data packet.
[0283] The configuration information may be used to indicate whether user plane control signaling requires / enables security verification.
[0284] The configuration information may indicate that all user plane control signaling requires security verification, or indicate that all user plane control signaling enables security verification, or that specific user plane control signaling requires security verification, or enables security verification for specific user plane control signaling.
[0285] In an exemplary embodiment, the transmitting end organizes the associated data packets and user plane control signaling into a transmission block, as shown in Figure 7, and provides a method for verifying the security of user plane control signaling. As shown in Figure 7, the method may include the following steps.
[0286] Step S700: Configuration information is transmitted between the sending end and the receiving end.
[0287] The configuration information may be used to indicate whether user plane control signaling requires / enables security verification.
[0288] The configuration information may indicate that all user plane control signaling requires security verification, or indicate that all user plane control signaling enables security verification, or that specific user plane control signaling requires security verification, or enables security verification for specific user plane control signaling.
[0289] In a possible implementation, step S700 may include: the transmitting end is a base station, the receiving end is a terminal, or the transmitting end is a terminal that sends RRC configuration in SideLink, the receiving end is a terminal that receives RRC configuration in SideLink, and the transmitting end sends configuration information to the receiving end.
[0290] In a possible implementation, step S700 may include: the transmitting end is a Uu port terminal, the receiving end is a base station, or the transmitting end is a terminal that receives RRC configuration in the sidelink, the receiving end is a terminal that sends RRC configuration in the sidelink, and the receiving end sends configuration information to the transmitting end.
[0291] It should be noted that step S700 is an optional step.
[0292] In step S701, the transmitting end performs one or more of the following operations on the RRC signaling or user plane data at the PDCP layer: encryption, integrity protection, generates a PDCP PDU, and delivers the PDCP PDU to the MAC layer through the various protocol layers of the transmitting end.
[0293] In step S702, the transmitting end places the MAC subPDU containing the PDCP PDU and the MAC subPDU containing the user plane control signaling in the same transport block at the MAC layer.
[0294] Step S703: The transmitting end sends a transport block to the receiving end.
[0295] Step S704: The receiving end receives the transport block and parses the transport block to obtain user plane control signaling.
[0296] Step S705: The receiving end performs security verification on the associated data packet at the PDCP layer.
[0297] The step S705 may refer to the step S602 and will not be described in detail here.
[0298] Step S706: If it is determined that the user plane control signaling needs to be security verified, the PDCP layer at the receiving end notifies the user plane control signaling corresponding layer of the security verification result of the associated data packet.
[0299] If it is predetermined that all user plane control signaling requires security verification, or it is predetermined that the user plane control signaling requires security verification, or the configuration information of step S700 indicates the user plane control signaling, it can be determined that the user plane control signaling requires security verification.
[0300] In step S707, the receiving end determines the security verification result of the user plane control signaling at the corresponding layer of the user plane control signaling based on the security verification result notified by the PDCP layer; if the security verification of the user plane control signaling is successful, the user plane control signaling is applied; if the security verification of the user plane control signaling fails, the user plane control signaling is discarded.
[0301] Step S708: If the security verification of the user plane control signaling fails, the corresponding layer of the user plane control signaling notifies the higher layer that the security verification of the user plane notification signaling fails.
[0302] The high layer is the RRC layer or the application layer, and step S708 is an optional step.
[0303] In an exemplary embodiment, the transmitting end generates a null data packet on demand, as shown in Figure 8, which provides a method for verifying the security of user plane control signaling. As shown in Figure 8, the method may include the following steps.
[0304] Step S800: Configuration information is transmitted between the sending end and the receiving end.
[0305] The step S800 may refer to the step S700 and will not be described in detail here.
[0306] In step S801, after the transmitting end generates user plane control signaling, if it is determined that security verification of the user plane control signaling is required, it is determined in the MAC layer whether there is a data packet to be sent in the cache; if there is no data packet to be sent in the cache, an empty data packet is generated in the PDCP layer, and the empty data packet is operated to generate a PDCP PDU, which operation includes one or more of the following: encryption and integrity protection.
[0307] Step S802: The transmitting end processes the PDCP PDU to generate a MAC subPDU.
[0308] In step S803, the MAC layer of the transmitting end places the MAC subPDU containing the PDCP PDU and the MAC subPDU containing the user plane control signaling in the same transport block.
[0309] Step S804: The transmitting end sends a transport block to the receiving end.
[0310] Step S805: The receiving end receives the transport block and parses the transport block to obtain user plane control signaling.
[0311] Step S806: The receiving end performs security verification on the associated data packet at the PDCP layer.
[0312] The step S806 may refer to the step S602 and will not be described in detail here.
[0313] In step S807, when it is determined that the user plane control signaling needs to be security verified, if an empty data packet indication is identified, the PDCP layer of the receiving end determines that the associated data packet does not need to be submitted to the upper layer; if no empty data packet indication is identified, the PDCP layer of the receiving end submits the associated data packet to the upper layer, and the upper layer determines that the data packet is invalid.
[0314] If it is predetermined that all user plane control signaling requires security verification, or it is predetermined that the user plane control signaling requires security verification, or the configuration information of step S800 indicates the user plane control signaling, it can be determined that the user plane control signaling requires security verification.
[0315] Step S808: When it is determined that the user plane control signaling needs to be security verified, the PDCP layer at the receiving end notifies the corresponding layer of the user plane control signaling of the security verification result of the associated data packet.
[0316] In step S809, the corresponding layer of the user plane control signaling at the receiving end applies the user plane control signaling if it is determined that the security verification of the user plane control signaling is successful according to the security verification result notified by the PDCP layer; and discards the user plane control signaling if it is determined that the security verification of the user plane control signaling fails according to the security verification result notified by the PDCP layer.
[0317] Step S810: If the security verification of the user plane control signaling fails, the corresponding layer of the user plane control signaling notifies the upper layer that the security verification of the user plane notification signaling fails.
[0318] The high layer is the RRC layer or the application layer, step S810 is an optional step, and step S807 can be executed in parallel with steps S808 to S809.
[0319] In an exemplary embodiment, the transmitting end generates a null data packet in advance, as shown in Figure 9, which provides a method for verifying the security of user plane control signaling. As shown in Figure 9, the method may include the following steps.
[0320] Step S900: Configuration information is transmitted between the sending end and the receiving end.
[0321] The step S900 may refer to the step S700 and will not be described in detail here.
[0322] Step S901: When it is determined that there is a need for user plane control signaling security verification, the PDCP layer of the transmitting end generates a null data packet and operates on the null data packet to generate a PDCP PDU. The operation includes one or more of the following.
[0323] In step S902, the transmitting end generates user plane control signaling; if it is determined that security verification of the user plane control signaling is required, the MAC layer determines whether there is a data packet to be sent in the cache; if there is no data packet to be sent in the cache, the MAC subPDU containing the PDCP PDU and the MAC subPDU containing the user plane control signaling are placed in the same transmission block.
[0324] Step S903: The transmitting end sends a transport block to the receiving end.
[0325] Step S904: The receiving end receives the transport block and parses the transport block to obtain user plane control signaling.
[0326] Step S905: The receiving end performs security verification on the associated data packet at the PDCP layer.
[0327] In step S906, when it is determined that the user plane control signaling requires security verification, if an empty data packet indication is identified, the PDCP layer determines that the associated data packet does not need to be submitted to the upper layer; if no empty data packet indication is identified, the PDCP layer submits it to the upper layer, and the upper layer determines that the data packet is invalid.
[0328] Step S907: If it is determined that the user plane control signaling needs to be security verified, the PDCP layer at the receiving end notifies the layer corresponding to the user plane control signaling of the security verification result of the associated data packet.
[0329] If it is predetermined that all user plane control signaling requires security verification, or it is predetermined that the user plane control signaling requires security verification, or the configuration information of step S900 indicates the user plane control signaling, it can be determined that the user plane control signaling requires security verification.
[0330] In step S908, the corresponding layer of the user plane control signaling at the receiving end applies the user plane control signaling when it is determined that the security verification of the user plane control signaling is successful according to the security verification result notified by the PDCP layer; and discards the user plane control signaling when it is determined that the security verification of the user plane control signaling fails according to the security verification result notified by the PDCP layer.
[0331] Step S909: If the security verification of the user plane control signaling fails, the corresponding layer of the user plane control signaling notifies the higher layer that the security verification of the user plane notification signaling fails.
[0332] The high layer is the RRC layer or the application layer, step S909 is an optional step, and step S906 can be executed in parallel with steps S907 to S909.
[0333] In an exemplary embodiment, the user plane control signaling is delayed in taking effect, and a method for verifying the security of the user plane control signaling is provided as shown in Figure 10. As shown in Figure 10, the method may include the following steps.
[0334] Step S1000: Configuration information is transmitted between the sending end and the receiving end.
[0335] It should be noted that step S1000 is an optional step.
[0336] Step S1001: The transmitting end sends a transport block including user plane control signaling to the receiving end. The transport block does not include other data.
[0337] Step S1002: The transmitting end sends a transport block including associated data packets to the receiving end. The transmitting end performs one or more of the following operations on the associated data packets: encryption and integrity protection.
[0338] Among them, the associated data packet refers to any of the following items: a data packet in a transmission block before the transmission block containing user plane control signaling; a data packet in a transmission block sent after the transmission block containing user plane control signaling; a data packet in a transmission block whose sending time partially intersects or completely overlaps with the transmission block containing user plane control signaling.
[0339] Step S1003: The receiving end receives a transport block including user plane control signaling, and parses the transport block to obtain the user plane control signaling.
[0340] Step S1004: When it is determined that the user plane control signaling needs to be security verified, the PDCP layer at the receiving end notifies the layer where the user plane control signaling is located of the security verification result of the associated data packet.
[0341] If it is predetermined that all user plane control signaling requires security verification, or it is predetermined that the user plane control signaling requires security verification, or the configuration information of step S1000 indicates the user plane control signaling, it can be determined that the user plane control signaling requires security verification.
[0342] In step S1005, the corresponding layer of the user plane control signaling at the receiving end applies the user plane control signaling when it is determined that the security verification of the user plane control signaling is successful according to the security verification result notified by the PDCP layer; and discards the user plane control signaling when it is determined that the security verification of the user plane control signaling fails according to the security verification result notified by the PDCP layer.
[0343] Step S1006: If the security verification of the user plane control signaling fails, the corresponding layer of the user plane control signaling notifies the higher layer that the security verification of the user plane notification signaling fails.
[0344] The high layer is the RRC layer or the application layer, and step S1006 is an optional step.
[0345] In an exemplary embodiment, the user plane control instruction takes effect immediately, and as shown in Figure 11, a method for verifying the security of user plane control signaling is provided. As shown in Figure 11, the method may include the following steps.
[0346] Step S1100: Configuration information is transmitted between the sending end and the receiving end.
[0347] It should be noted that step S1100 is an optional step.
[0348] Step S1101: The transmitting end sends a transport block including user plane control signaling to the receiving end. The transport block does not include other data.
[0349] Step S1102: The transmitting end sends a transport block including associated data packets to the receiving end. The transmitting end performs one or more of the following operations on the associated data packets: encryption and integrity protection.
[0350] Among them, the associated data packet refers to any of the following items: a data packet in a transmission block before the transmission block containing user plane control signaling; a data packet in a transmission block sent after the transmission block containing user plane control signaling; a data packet in a transmission block whose sending time partially intersects or completely overlaps with the transmission block containing user plane control signaling.
[0351] Step S1103: The receiving end receives a transport block including user plane control signaling, parses the transport block to obtain the user plane control signaling, and applies the user plane control signaling.
[0352] Step S1104: When it is determined that the user plane control signaling needs to be security verified, the PDCP layer of the receiving end notifies the layer where the user plane control signaling is located of the security verification result of the associated data packet.
[0353] If it is predetermined that all user plane control signaling requires security verification, or it is predetermined that the user plane control signaling requires security verification, or the configuration information of step S1100 indicates the user plane control signaling, it can be determined that the user plane control signaling requires security verification.
[0354] In step S1105, the corresponding layer of the user plane control signaling at the receiving end maintains the current application result of the user plane control signaling when it is determined that the security verification of the user plane control signaling is successful according to the security verification result notified by the PDCP layer; and falls back to the state before the user plane control signaling is received or the preset state when it is determined that the security verification of the user plane control signaling fails according to the security verification result notified by the PDCP layer.
[0355] The preset state may be an initial state, a temporary state or a set state.
[0356] Step S1106: If the security verification of the user plane control signaling fails, the corresponding layer of the user plane control signaling notifies the higher layer that the security verification of the user plane notification signaling fails.
[0357] The high layer is the RRC layer or the application layer, and step S1106 is an optional step.
[0358] It should be understood that, although the steps in the flowcharts of the above-mentioned embodiments are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts of the above-mentioned embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0359] Based on the same inventive concept, the embodiments of the present disclosure also provide a user plane control signaling security verification device for implementing the aforementioned user plane control signaling security verification method. The implementation solution provided by this device is similar to the implementation solution described in the aforementioned method. Therefore, the specific limitations in the embodiments of one or more user plane control signaling security verification devices provided below can be found in the above-mentioned limitations on the user plane control signaling security verification method, and will not be repeated here.
[0360] In an exemplary embodiment, as shown in FIG12 , a device for verifying the security of user plane control signaling is provided. The device 1200 may include: a receiving unit 1201, a verifying unit 1202, and a determining unit 1203, wherein:
[0361] The receiving unit 1201 is configured to receive a transport block and parse the transport block to obtain user plane control signaling;
[0362] The verification unit 1202 is configured to perform security verification on data packets associated with the user plane control signaling;
[0363] The determining unit 1203 is configured to determine a security verification result of the user plane control signaling according to the security verification result of the associated data packet.
[0364] In one embodiment, the associated data packet includes one or more of the following:
[0365] Radio resource control (RRC) signaling or user plane data organized in the same transport block as user plane control signaling, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection;
[0366] Null data packets organized in the same transport block as user plane control signaling undergo one or more of the following operations: encryption, integrity protection;
[0367] The RRC signaling or user plane data in a transmission block that has a deterministic time relationship with the transmission time of the transmission block where the user plane control signaling is located, the RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection; the deterministic time relationship includes any one of the following: the previous transmission of the transmission block where the user plane control signaling is located, or, the next transmission of the transmission block where the user plane control signaling is located, or, the transmission performed simultaneously with the transmission block where the user plane control signaling is located, and simultaneous transmission means that the transmission time overlaps or completely overlaps with the transmission time of the transmission block where the user plane control signaling is located.
[0368] In one embodiment, performing security verification on data packets associated with user plane control signaling includes any of the following:
[0369] Decrypting the associated data packet; if the decryption is successful, determining the security verification result of the associated data packet as a security verification success; if the decryption fails, determining the security verification result of the associated data packet as a security verification failure;
[0370] Performing integrity verification on the associated data packet; if the integrity verification succeeds, determining the security verification result of the associated data packet as a security verification success; if the integrity verification fails, determining the security verification result of the associated data packet as a security verification failure;
[0371] Decrypt and verify the integrity of the associated data packet; if the decryption is successful and the integrity verification is successful, the security verification result of the associated data packet is determined to be security verification success; if the decryption fails or the integrity verification fails, the security verification result of the associated data packet is determined to be security verification failure.
[0372] In one embodiment, the user plane control signaling includes one or more of the following:
[0373] Packet Data Convergence Protocol PDCP control protocol data unit PDU;
[0374] Radio link control RLC control PDU;
[0375] Media Access Control MAC Control Unit CE.
[0376] In one embodiment, the verification unit is further configured to:
[0377] In the PDCP layer, security verification is performed on associated data packets;
[0378] Determining a security verification result of the user plane control signaling based on the security verification result of the associated data packet includes:
[0379] In the layer corresponding to the user plane control signaling, the security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
[0380] In one embodiment, the user plane control signaling has an associated data packet, and the apparatus further includes:
[0381] The first sending unit is used for the PDCP layer to send the security verification result of an associated data packet to the corresponding layer of the user plane control signaling.
[0382] In one embodiment, the user plane control signaling has multiple associated data packets, and the apparatus further includes any one of the following:
[0383] A second sending unit is configured to send the security verification result of each associated data packet to the corresponding layer of the user plane control signaling after the PDCP layer performs security verification on each associated data packet;
[0384] a third sending unit, configured to send, after the PDCP layer performs security verification on the first associated data packet, a security verification result of the first associated data packet to a layer corresponding to user plane control signaling, where the first associated data packet is a data packet in the multiple associated data packets;
[0385] a fourth sending unit, configured to, after the PDCP layer completes the security verification of all associated data packets, send a security verification success result to a corresponding layer of user plane control signaling if the security verification of all associated data packets is successful;
[0386] The fifth sending unit is configured to send the security verification failure result to the user plane control signaling corresponding layer after the PDCP layer determines that the security verification of any associated data packet fails.
[0387] In one embodiment, the apparatus further comprises:
[0388] a first application unit, configured to apply the user plane control signaling in a layer corresponding to the user plane control signaling when the security verification of the user plane control signaling succeeds;
[0389] The first discarding unit is configured to discard the user plane control signaling when the security verification of the user plane control signaling fails.
[0390] In one embodiment, the apparatus further comprises:
[0391] A second application unit is configured to apply the user plane control signaling when the user plane control signaling is obtained through parsing;
[0392] a maintaining unit, configured to maintain an application result of the user plane control signaling when the security verification of the user plane control signaling succeeds;
[0393] The fallback unit is used to fall back to the state before receiving the transmission block or to a preset state when the security verification of the user plane control signaling fails.
[0394] In one embodiment, the apparatus further comprises:
[0395] The second discarding unit is configured to discard the associated data packet after completing security verification of the associated data packet if the associated data packet is an empty data packet and the empty data packet has undergone one or more operations of encryption and integrity protection.
[0396] In one embodiment, the determining unit is further configured to:
[0397] Determining target user plane control signaling to be security verified based on the configuration information;
[0398] If the user plane control signaling is target user plane control signaling, the security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
[0399] In an exemplary embodiment, as shown in FIG13 , a device for verifying the security of user plane control signaling is provided. The device 1300 includes: a first generating unit 1301 and a first sending unit 1302 , wherein:
[0400] The first generating unit 1301 is configured to generate user plane control signaling;
[0401] The first sending unit 1302 is used to send a transmission block including user plane control signaling, which also includes an associated data packet of the user plane control signaling, or a transmission block that has a deterministic time relationship with the transmission time of the transmission block and includes an associated data packet of the user plane control signaling, and the security verification result of the associated data packet is used to determine the security verification result of the user plane control signaling.
[0402] In one embodiment, the transport block also includes an associated data packet, and the associated data packet includes radio resource control RRC signaling or user plane data, and the radio resource control RRC signaling or user plane data undergoes one or more of the following operations: encryption and integrity protection. The apparatus further includes:
[0403] The second generating unit is configured to generate a first media access control protocol MAC sub-protocol data unit subPDU based on radio resource control RRC signaling or user plane data;
[0404] A third generating unit, configured to generate a second MAC subPDU based on the user plane control signaling;
[0405] a first organizing unit, configured to organize the first MAC subPDU and the second MAC subPDU into a first transmission block;
[0406] The first sending unit is further configured to:
[0407] A first transport block is sent.
[0408] In one embodiment, the transmission block further includes associated data packets, the associated data packets including null data packets, the null data packets undergoing one or more of the following operations: encryption, integrity protection, and the apparatus further includes:
[0409] a fourth generating unit, configured to generate a second MAC subPDU based on the user plane control signaling;
[0410] a fifth generating unit, configured to generate a null data packet if no data packet to be sent exists in the buffer, perform an operation on the null data packet, and generate a third MAC subPDU based on the null data packet after the operation, the operation comprising one or more of the following: encryption and integrity protection;
[0411] a second organizing unit, configured to organize the second MAC subPDU and the third MAC subPDU into a second transmission block;
[0412] The first sending unit is further configured to:
[0413] Send a second transport block.
[0414] In one embodiment, the transport block further includes associated data packets, the associated data packets include null data packets, and the null data packets undergo one or more of the following operations: encryption and integrity protection. The apparatus further includes:
[0415] a sixth generating unit, configured to, when determining that there is a user plane control signaling security verification requirement, generate a null data packet, perform an operation on the null data packet, and generate a third MAC subPDU based on the null data packet after the operation, the operation including one or more of the following: encryption and integrity protection;
[0416] a seventh generating unit, configured to generate a second MAC subPDU based on the user plane control signaling;
[0417] a third organizing unit, configured to organize the second MAC subPDU and the third MAC subPDU into a second transmission block if no data packet to be sent exists in the buffer;
[0418] The first sending unit is further configured to:
[0419] Send a second transport block.
[0420] In one embodiment, the apparatus further comprises:
[0421] The adding unit is configured to add a null data packet indication in a PDCP header of a PDCP PDU containing a null data packet, in an RLC header of an RLC PDU, or in a MAC subheader of a MAC subPDU.
[0422] In one embodiment, a transport block having a deterministic time relationship with a transmission time of a transport block includes an associated data packet, the associated data packet includes RRC signaling or user plane data, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption and integrity protection, and the apparatus further includes:
[0423] an eighth generating unit, configured to generate a first MAC subPDU based on the RRC signaling or user plane data;
[0424] a ninth generating unit, configured to generate a second MAC subPDU based on the user plane control signaling;
[0425] a fourth organizing unit, configured to organize the second MAC subPDU into a third transmission block, where the third transmission block does not include other MAC subPDUs;
[0426] a fifth organizing unit, configured to organize the first MAC subPDU into a fourth transmission block, the fourth transmission block being a transmission block having a deterministic time relationship with a transmission time of the third transmission block;
[0427] A second sending unit, configured to send a fourth transmission block;
[0428] The first sending unit is further configured to:
[0429] The third transport block is sent.
[0430] In one embodiment, the fourth transmission block includes any one of the following:
[0431] A transport block whose transmission time is the last transmission of the third transport block;
[0432] a transport block whose transmission time is the next transmission of the third transport block;
[0433] A transport block that is transmitted simultaneously with the third transport block, wherein simultaneously means that the transmission time overlaps or completely overlaps with the third transport block.
[0434] In one embodiment, the apparatus further comprises:
[0435] A first determining unit, configured to determine, based on the configuration information, a target user plane control signaling to be security verified;
[0436] The second determining unit is configured to determine an associated data packet of the user plane control signaling if the user plane control signaling is the target user plane control signaling.
[0437] In one embodiment, the user plane control signaling includes one or more of the following:
[0438] Packet Data Convergence Protocol PDCP control protocol data unit PDU;
[0439] Radio link control RLC control PDU;
[0440] Media Access Control MAC Control Unit CE.
[0441] It should be noted that the division of units in the embodiments of the present disclosure is schematic and is merely a logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of the present disclosure may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0442] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of the present disclosure, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) or a processor to execute all or part of the steps of the method described in each embodiment of the present disclosure.
[0443] It should be noted here that the above-mentioned device provided in the embodiment of the present disclosure can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.
[0444] In an exemplary embodiment, a security verification device for user plane control signaling is provided. The security verification device for user plane control signaling can be a terminal device or a network device. The security verification device can be a sending end or a receiving end. The processor-readable storage medium can be any available medium or data storage device that can be accessed by the processor, including but not limited to magnetic storage (such as floppy disks, hard disks, tapes, magneto-optical disks (MO), etc.), optical storage (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (such as ROMs, EPROMs, EEPROMs, non-volatile memories (NAND FLASH), solid-state drives (SSDs)), etc.
[0445] Those skilled in the art will appreciate that the embodiments of the present disclosure may be provided as methods, systems, or computer program products. Therefore, the present disclosure may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage and optical storage, etc.) containing computer-usable program code.
[0446] The present disclosure is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present disclosure. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by processor-executable instructions. These processor-executable instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0447] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the processor-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0448] Obviously, those skilled in the art may make various modifications and variations to the present disclosure without departing from the spirit and scope of the present disclosure. Thus, if these modifications and variations fall within the scope of the claims of the present disclosure and their equivalents, the present disclosure also intends to encompass these modifications and variations. The structure may be as shown in FIG14 . The user plane control signaling security verification device includes a memory 1420, a transceiver 1410, and a processor 1400.
[0449] A transceiver is used to receive and send data under the control of the processor.
[0450] In FIG14 , the bus architecture may include any number of interconnected buses and bridges, specifically linking together various circuits of one or more processors represented by a processor and a memory represented by a memory. The bus architecture may also link together various other circuits such as peripherals, voltage regulators, and power management circuits, which are well known in the art and are therefore not further described herein. The bus interface provides an interface. The transceiver may be a plurality of components, i.e., a transmitter and a receiver, providing a unit for communicating with various other devices over a transmission medium, such as a wireless channel, a wired channel, an optical cable, or the like. The processor is responsible for managing the bus architecture and general processing, and the memory may store data used by the processor when performing operations.
[0451] The processor can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or a complex programmable logic device (CPLD), and the processor can also adopt a multi-core architecture.
[0452] The processor calls the program stored in the memory to execute any of the methods provided by the embodiments of the present disclosure according to the obtained executable instructions. The processor and the memory can also be physically separated.
[0453] It should be noted here that the above-mentioned device provided in the embodiment of the present disclosure can implement all the method steps implemented in the above-mentioned method embodiment and can achieve the same technical effect. The parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.
[0454] In an exemplary embodiment, a security verification device for user plane control signaling is provided, and the processor-readable storage medium can be any available medium or data storage device that can be accessed by the processor, including but not limited to magnetic storage (such as floppy disks, hard disks, tapes, magneto-optical disks (MO), etc.), optical storage (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (such as ROMs, EPROMs, EEPROMs, non-volatile memories (NAND FLASH), solid-state drives (SSDs)), etc.
[0455] Those skilled in the art will appreciate that the embodiments of the present disclosure may be provided as methods, systems, or computer program products. Therefore, the present disclosure may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage and optical storage, etc.) containing computer-usable program code.
[0456] The present disclosure is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present disclosure. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by processor-executable instructions. These processor-executable instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0457] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the processor-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0458] Obviously, those skilled in the art may make various modifications and variations to the present disclosure without departing from the spirit and scope of the present disclosure. Thus, if such modifications and variations fall within the scope of the claims of the present disclosure and their equivalents, the present disclosure is intended to include such modifications and variations. The present disclosure may be a terminal device or a network device, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the steps of the above-described method embodiments are implemented.
[0459] In an exemplary embodiment, a device for verifying the security of user plane control signaling is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0460] In an exemplary embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0461] The processor-readable storage medium can be any available medium or data storage device that can be accessed by the processor, including but not limited to magnetic storage (such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO)), optical storage (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (such as ROMs, EPROMs, EEPROMs, non-volatile memories (NAND FLASH), solid-state drives (SSDs)), etc.
[0462] Those skilled in the art will appreciate that the embodiments of the present disclosure may be provided as methods, systems, or computer program products. Therefore, the present disclosure may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage and optical storage, etc.) containing computer-usable program code.
[0463] The present disclosure is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present disclosure. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by processor-executable instructions. These processor-executable instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0464] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the processor-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0465] Obviously, those skilled in the art may make various changes and modifications to the present disclosure without departing from the spirit and scope of the present disclosure. Thus, if these modifications and variations of the present disclosure fall within the scope of the claims of the present disclosure and their equivalents, the present disclosure is intended to include these modifications and variations.
Claims
1. A method for verifying the security of user plane control signaling, wherein: The method comprises: Receiving a transport block and parsing the transport block to obtain user plane control signaling; Performing security verification on data packets associated with the user plane control signaling; The security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
2. The method according to claim 1, wherein The associated data packet includes one or more of the following: Radio resource control RRC signaling or user plane data organized in the same transport block as the user plane control signaling, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection; A null data packet organized in the same transport block as the user plane control signaling, the null data packet undergoing one or more of the following operations: encryption, integrity protection; The RRC signaling or user plane data in the transmission block that has a deterministic time relationship with the transmission time of the transmission block where the user plane control signaling is located, the RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection; the deterministic time relationship includes any one of the following: the previous transmission of the transmission block where the user plane control signaling is located, or, the next transmission of the transmission block where the user plane control signaling is located, or, the transmission performed simultaneously with the transmission block where the user plane control signaling is located, and the simultaneous transmission means that the transmission time overlaps or completely overlaps with the transmission time of the transmission block where the user plane control signaling is located.
3. The method according to claim 1 or 2, wherein: The performing security verification on the data packets associated with the user plane control signaling includes any one of the following: Decrypting the associated data packet; if the decryption is successful, determining the security verification result of the associated data packet as a security verification success; if the decryption fails, determining the security verification result of the associated data packet as a security verification failure; Performing integrity verification on the associated data packet; If the integrity verification is successful, determining the security verification result of the associated data packet is a security verification success; If the integrity verification fails, determining that the security verification result of the associated data packet is a security verification failure; Decrypting and verifying the integrity of the associated data packet; If the decryption is successful and the integrity verification is successful, the security verification result of the associated data packet is determined to be a security verification success; if the decryption fails or the integrity verification fails, the security verification result of the associated data packet is determined to be a security verification failure.
4. The method according to any one of claims 1 to 3, wherein The user plane control signaling includes one or more of the following: Packet Data Convergence Protocol PDCP control protocol data unit PDU; Radio link control RLC control PDU; Media Access Control MAC Control Unit CE.
5. The method according to claim 1, wherein The performing security verification on the data packet associated with the user plane control signaling includes: In the PDCP layer, performing security verification on the associated data packet; The determining, according to the security verification result of the associated data packet, the security verification result of the user plane control signaling includes: In the user plane control signaling corresponding layer, the security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
6. The method according to claim 5, wherein: The user plane control signaling has an associated data packet, and the method further includes: The PDCP layer sends the security verification result of the associated data packet to the user plane control signaling corresponding layer.
7. The method according to claim 5, wherein: The user plane control signaling has multiple associated data packets, and the method further includes any one of the following: After the PDCP layer performs security verification on each associated data packet, the security verification result of each associated data packet is sent to the user plane control signaling corresponding layer; After performing security verification on a first associated data packet, the PDCP layer sends a security verification result of the first associated data packet to the user plane control signaling corresponding layer, where the first associated data packet is a data packet among the multiple associated data packets; After the PDCP layer completes the security verification of all associated data packets, if the security verification of all associated data packets is successful, the PDCP layer sends the security verification success result to the user plane control signaling corresponding layer; After determining that the security verification of any associated data packet fails, the PDCP layer sends a security verification failure result to the user plane control signaling corresponding layer.
8. The method according to any one of claims 1 to 7, wherein The method further comprises: If the security verification of the user plane control signaling is successful, applying the user plane control signaling in a layer corresponding to the user plane control signaling; If the security verification of the user plane control signaling fails, the user plane control signaling is discarded.
9. The method according to any one of claims 1 to 7, wherein The method further comprises: When the user plane control signaling is obtained through parsing, applying the user plane control signaling; If the security verification of the user plane control signaling is successful, maintaining the application result of the user plane control signaling; In the event that the security verification of the user plane control signaling fails, fall back to the state before receiving the transport block or fall back to a preset state.
10. The method according to claim 1, wherein The method further comprises: If the associated data packet is an empty data packet, and the empty data packet has undergone one or more operations of encryption and integrity protection, the associated data packet is discarded after completing the security verification of the associated data packet.
11. The method according to any one of claims 1 to 10, wherein: The determining, according to the security verification result of the associated data packet, the security verification result of the user plane control signaling includes: Determining target user plane control signaling to be security verified based on the configuration information; If the user plane control signaling is the target user plane control signaling, the security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
12. A method for verifying the security of user plane control signaling, wherein: The method comprises: generating user plane control signaling; A transmission block including the user plane control signaling is sent, wherein the transmission block also includes an associated data packet of the user plane control signaling, or a transmission block having a deterministic time relationship with the transmission time of the transmission block includes an associated data packet of the user plane control signaling, and the security verification result of the associated data packet is used to determine the security verification result of the user plane control signaling.
13. The method according to claim 12, wherein: The transport block also includes the associated data packet, the associated data packet includes radio resource control (RRC) signaling or user plane data, the radio resource control (RRC) signaling or user plane data undergoing one or more of the following operations: encryption and integrity protection, and the method further includes: Generate a first media access control protocol MAC sub-protocol data unit subPDU based on the radio resource control RRC signaling or user plane data; generating a second MAC subPDU based on the user plane control signaling; Organizing the first MAC subPDU and the second MAC subPDU in a first transport block; The sending of the transport block including the user plane control signaling comprises: Sending the first transport block.
14. The method according to claim 12, wherein: The transmission block also includes the associated data packet, the associated data packet includes a null data packet, and the null data packet undergoes one or more of the following operations: encryption and integrity protection. The method further includes: generating a second MAC subPDU based on the user plane control signaling; If no data packet to be sent exists in the buffer, generating a null data packet, performing an operation on the null data packet, and generating a third MAC subPDU based on the null data packet after the operation, the operation comprising one or more of the following: encryption and integrity protection; organizing the second MAC subPDU and the third MAC subPDU in a second transport block; The sending of the transport block including the user plane control signaling comprises: The second transport block is sent.
15. The method according to claim 12, wherein: The transport block also includes the associated data packet, the associated data packet includes a null data packet, and the null data packet undergoes one or more of the following operations: encryption and integrity protection. The method further includes: If it is determined that there is a user plane control signaling security verification requirement, generate a null data packet, perform an operation on the null data packet, and generate a third MAC subPDU based on the null data packet after the operation, the operation including one or more of the following: encryption and integrity protection; generating a second MAC subPDU based on the user plane control signaling; If there is no data packet to be sent in the buffer, organizing the second MAC subPDU and the third MAC subPDU into a second transmission block; The sending of the transport block including the user plane control signaling comprises: The second transport block is sent.
16. The method according to claim 14 or 15, wherein: The method further comprises: A null data packet indication is added in the PDCP header of the PDCP PDU containing the null data packet, or in the RLC header of the RLC PDU, or in the MAC subheader of the MAC subPDU.
17. The method according to claim 12, wherein: The associated data packet is included in a transport block having a deterministic time relationship with the transmission time of the transport block, the associated data packet includes RRC signaling or user plane data, and the RRC signaling or user plane data is subjected to one or more of the following operations: encryption and integrity protection, the method further comprising: Generate a first MAC subPDU based on the RRC signaling or user plane data; generating a second MAC subPDU based on the user plane control signaling; Organizing the second MAC subPDU in a third transport block, the third transport block not including other MAC subPDUs; Organizing the first MAC subPDU in a fourth transport block, the fourth transport block being a transport block having a deterministic time relationship with a transmission time of the third transport block; sending the fourth transport block; The sending of the transport block including the user plane control signaling comprises: The third transport block is sent.
18. The method according to claim 17, wherein The fourth transmission block includes any one of the following: A transmission block whose transmission time is the last transmission of the third transmission block; A transmission block whose transmission time is the next transmission of the third transmission block; A transport block that is transmitted simultaneously with the third transport block, wherein the simultaneous transmission means that the transmission time overlaps or completely overlaps with the third transport block.
19. The method according to claim 12, wherein: The method further comprises: Determining target user plane control signaling to be security verified based on the configuration information; If the user plane control signaling is the target user plane control signaling, an associated data packet of the user plane control signaling is determined.
20. The method according to claim 12, wherein The user plane control signaling includes one or more of the following: Packet Data Convergence Protocol PDCP control protocol data unit PDU; Radio link control RLC control PDU; Media Access Control MAC Control Unit CE.
21. A security verification device for user plane control signaling, wherein: Including memory, transceiver, processor: Memory for storing computer programs; a transceiver, configured to transmit and receive data under the control of the processor; A processor is configured to read the computer program in the memory and perform the following operations: Receiving a transport block and parsing the transport block to obtain user plane control signaling; Performing security verification on data packets associated with the user plane control signaling; The security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
22. The device according to claim 21, wherein The associated data packet includes one or more of the following: Radio resource control RRC signaling or user plane data organized in the same transport block as the user plane control signaling, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection; A null data packet organized in the same transport block as the user plane control signaling, the null data packet undergoing one or more of the following operations: encryption, integrity protection; The RRC signaling or user plane data in the transmission block that has a deterministic time relationship with the transmission time of the transmission block where the user plane control signaling is located, the RRC signaling or user plane data undergoes one or more of the following operations: encryption, integrity protection; the deterministic time relationship includes any one of the following: the previous transmission of the transmission block where the user plane control signaling is located, or, the next transmission of the transmission block where the user plane control signaling is located, or, the transmission performed simultaneously with the transmission block where the user plane control signaling is located, and the simultaneous transmission means that the transmission time overlaps or completely overlaps with the transmission time of the transmission block where the user plane control signaling is located.
23. The device according to claim 21 or 22, wherein The security verification of the data packet associated with the user plane control signaling specifically includes any one of the following: Decrypting the associated data packet; if the decryption is successful, determining the security verification result of the associated data packet as a security verification success; if the decryption fails, determining the security verification result of the associated data packet as a security verification failure; Performing integrity verification on the associated data packet; If the integrity verification is successful, determining the security verification result of the associated data packet is a security verification success; If the integrity verification fails, determining that the security verification result of the associated data packet is a security verification failure; Decrypting and verifying the integrity of the associated data packet; If the decryption is successful and the integrity verification is successful, the security verification result of the associated data packet is determined to be a security verification success; if the decryption fails or the integrity verification fails, the security verification result of the associated data packet is determined to be a security verification failure.
24. The device according to any one of claims 21 to 23, wherein The user plane control signaling includes one or more of the following: Packet Data Convergence Protocol PDCP control protocol data unit PDU; Radio link control RLC control PDU; Media Access Control MAC Control Unit CE.
25. The apparatus according to claim 21, wherein The performing security verification on the data packet associated with the user plane control signaling specifically includes: In the PDCP layer, performing security verification on the associated data packet; The determining, according to the security verification result of the associated data packet, the security verification result of the user plane control signaling includes: In the user plane control signaling corresponding layer, the security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
26. The device according to claim 25, wherein There is an associated data packet for the user plane control signaling, and the processor is further configured to perform the following operations: The PDCP layer sends the security verification result of the associated data packet to the user plane control signaling corresponding layer.
27. The apparatus according to claim 25, wherein There are multiple associated data packets for the user plane control signaling, and the processor is further configured to perform any one of the following operations: After the PDCP layer performs security verification on each associated data packet, the security verification result of the associated data packet is sent to the corresponding layer of the user plane control signaling; After performing security verification on a first associated data packet, the PDCP layer sends a security verification result of the first associated data packet to the user plane control signaling corresponding layer, where the first associated data packet is a data packet among the multiple associated data packets; After the PDCP layer completes the security verification of all associated data packets, if the security verification of all associated data packets is successful, the PDCP layer sends the security verification success result to the user plane control signaling corresponding layer; After determining that the security verification of any associated data packet fails, the PDCP layer sends a security verification failure result to the user plane control signaling corresponding layer.
28. The device according to any one of claims 21 to 27, wherein The processor is further configured to perform the following operations: If the security verification of the user plane control signaling is successful, applying the user plane control signaling in a layer corresponding to the user plane control signaling; If the security verification of the user plane control signaling fails, the user plane control signaling is discarded.
29. The device according to any one of claims 21 to 27, wherein The processor is further configured to perform the following operations: When the user plane control signaling is obtained through parsing, applying the user plane control signaling; If the security verification of the user plane control signaling is successful, maintaining the application result of the user plane control signaling; In the event that the security verification of the user plane control signaling fails, fall back to the state before receiving the transport block or fall back to a preset state.
30. The apparatus according to claim 21, wherein The processor is further configured to perform the following operations: If the associated data packet is an empty data packet, and the empty data packet has undergone one or more operations of encryption and integrity protection, the associated data packet is discarded after completing the security verification of the associated data packet.
31. The device according to any one of claims 21 to 30, wherein The determining, according to the security verification result of the associated data packet, the security verification result of the user plane control signaling specifically includes: Determining target user plane control signaling to be security verified based on the configuration information; If the user plane control signaling is the target user plane control signaling, the security verification result of the user plane control signaling is determined according to the security verification result of the associated data packet.
32. A security verification device for user plane control signaling, wherein: Including memory, transceiver, processor: Memory for storing computer programs; a transceiver, configured to transmit and receive data under the control of the processor; A processor is configured to read the computer program in the memory and perform the following operations: generating user plane control signaling; A transmission block including the user plane control signaling is sent, wherein the transmission block also includes an associated data packet of the user plane control signaling, or a transmission block having a deterministic time relationship with the transmission time of the transmission block includes an associated data packet of the user plane control signaling, and the security verification result of the associated data packet is used to determine the security verification result of the user plane control signaling.
33. The apparatus according to claim 32, wherein The transport block also includes the associated data packet, where the associated data packet includes radio resource control (RRC) signaling or user plane data, where the radio resource control (RRC) signaling or user plane data undergoes one or more of the following operations: encryption and integrity protection. The processor is further configured to perform the following operations: Generate a first media access control protocol MAC sub-protocol data unit subPDU based on the radio resource control RRC signaling or user plane data; generating a second MAC subPDU based on the user plane control signaling; Organizing the first MAC subPDU and the second MAC subPDU in a first transport block; The sending of the transport block including the user plane control signaling specifically includes: Sending the first transport block.
34. The apparatus of claim 32, wherein: The transmission block also includes the associated data packet, the associated data packet includes an empty data packet, and the empty data packet undergoes one or more of the following operations: encryption and integrity protection. The processor is further configured to perform the following operations: generating a second MAC subPDU based on the user plane control signaling; If no data packet to be sent exists in the buffer, generating a null data packet, performing an operation on the null data packet, and generating a third MAC subPDU based on the null data packet after the operation, the operation comprising one or more of the following: encryption and integrity protection; organizing the second MAC subPDU and the third MAC subPDU in a second transport block; The sending of the transport block including the user plane control signaling specifically includes: The second transport block is sent.
35. The apparatus of claim 32, wherein: The transmission block also includes the associated data packet, the associated data packet includes a null data packet, and the null data packet undergoes one or more of the following operations: encryption and integrity protection, and the processor is further configured to perform the following operations: If it is determined that there is a user plane control signaling security verification requirement, generate a null data packet, perform an operation on the null data packet, and generate a third MAC subPDU based on the null data packet after the operation, the operation including one or more of the following: encryption and integrity protection; generating a second MAC subPDU based on the user plane control signaling; If there is no data packet to be sent in the buffer, organizing the second MAC subPDU and the third MAC subPDU into a second transmission block; The sending of the transport block including the user plane control signaling specifically includes: The second transport block is sent.
36. The apparatus according to claim 34 or 35, wherein The processor is further configured to perform the following operations: A null data packet indication is added in the PDCP header of the PDCP PDU containing the null data packet, or in the RLC header of the RLC PDU, or in the MAC subheader of the MAC subPDU.
37. The apparatus of claim 32, wherein: The associated data packet is included in a transport block having a deterministic time relationship with the transmission time of the transport block, the associated data packet includes RRC signaling or user plane data, and the RRC signaling or user plane data undergoes one or more of the following operations: encryption and integrity protection, and the processor is further configured to perform the following operations: Generate a first MAC subPDU based on the RRC signaling or the user plane data; generating a second MAC subPDU based on the user plane control signaling; Organizing the second MAC subPDU in a third transport block, the third transport block not including other MAC subPDUs; Organizing the first MAC subPDU in a fourth transport block, the fourth transport block being a transport block having a deterministic time relationship with a transmission time of the third transport block; sending the fourth transport block; The sending of the transport block including the user plane control signaling specifically includes: The third transport block is sent.
38. The apparatus according to claim 37, wherein The fourth transmission block includes any one of the following: A transmission block whose transmission time is the last transmission of the third transmission block; A transmission block whose transmission time is the next transmission of the third transmission block; A transport block that is transmitted simultaneously with the third transport block, wherein the simultaneous transmission means that the transmission time overlaps or completely overlaps with the third transport block.
39. The apparatus of claim 32, wherein: The processor is further configured to perform the following operations: Determining target user plane control signaling to be security verified based on the configuration information; If the user plane control signaling is the target user plane control signaling, an associated data packet of the user plane control signaling is determined.
40. The apparatus of claim 32, wherein: The user plane control signaling includes one or more of the following: Packet Data Convergence Protocol PDCP control protocol data unit PDU; Radio link control RLC control PDU; Media Access Control MAC Control Unit CE.
41. A security verification device for user plane control signaling, wherein: include: a receiving unit, configured to receive a transport block and parse the transport block to obtain user plane control signaling; a verification unit, configured to perform security verification on data packets associated with the user plane control signaling; A determining unit is configured to determine a security verification result of the user plane control signaling according to a security verification result of the associated data packet.
42. A security verification device for user plane control signaling, wherein: include: A first generating unit, configured to generate user plane control signaling; A first sending unit is configured to send a transmission block including the user plane control signaling, wherein the transmission block also includes an associated data packet of the user plane control signaling, or a transmission block having a deterministic time relationship with the transmission time of the transmission block includes an associated data packet of the user plane control signaling, wherein the security verification result of the associated data packet is used to determine the security verification result of the user plane control signaling.
43. A processor-readable storage medium, wherein: The processor-readable storage medium stores a program, and the program is used to enable the processor to execute the method according to any one of claims 1 to 11 or the method according to any one of claims 12 to 20.
Citation Information
Patent Citations
Method and device for transmitting data
CN102647332A
Page table integrity protection method, device and equipment
CN112597488A
Communication method and device
CN115696319A
Communication method and device
CN115884173A
Data generation method and device, computer equipment and storage medium
CN117171193A