Signaling security protection method, apparatus, communication device and storage medium
By encrypting and integrity protecting the user plane control signaling, the problem of lack of security guarantee for the user plane control signaling is solved, and the security and reliability of the communication system are achieved.
Patent Information
- Application Number
- PCT/CN2025/088351
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-11
- Filing Date
- 2025-04-10
- Publication Date
- 2025-10-16
AI Technical Summary
In communication systems, user plane control signaling lacks a security mechanism and is vulnerable to malicious attacks.
A signaling security assurance method is provided, which performs encryption operations and integrity protection on user plane control signaling through encryption and integrity protection mechanisms, including encrypting or integrity protecting MAC sublayer protocol data units and specific parts of MAC protocol data units, and carrying indication information in the MAC subheader.
It achieves security protection for user plane control signaling, prevents malicious attacks, and ensures the security and reliability of the communication system.
Smart Images

Figure CN2025088351_16102025_PF_FP_ABST
Abstract
Description
Signaling security guarantee method and device, communication device, and storage medium
[0001] The present application claims priority to the Chinese patent application No. 2024104364301, filed on April 11, 2024, and entitled "Signaling security guarantee method, device, computer device, and storage medium", the contents of which are hereby incorporated by reference in their entirety. TECHNICAL FIELD
[0002] The present application relates to the field of communication technology, in particular to a signaling security guarantee method, device, communication device, storage medium, and computer program product. BACKGROUND
[0003] In a communication system, user plane control signaling refers to signaling used to manage and control user data transmission in the communication system. User plane control signaling, especially MAC CE (MAC Control Element), has a very large number of functions.
[0004] Currently, there are security guarantee mechanisms for RRC (Radio Resource Control) signaling and user plane data transmission. Encryption and integrity protection are used to ensure the security of RRC signaling and user plane data. For user plane control signaling, there is no corresponding security guarantee mechanism.
[0005] However, if user plane control signaling does not have security guarantee mechanisms such as encryption and integrity protection, it is very insecure and is vulnerable to malicious attacks. Therefore, there is an urgent need for a security guarantee method for user plane control signaling. SUMMARY
[0006] According to various embodiments of the present application, a signaling security guarantee method, device, communication device, computer readable storage medium, and computer program product capable of guaranteeing the security of user plane control signaling are provided.
[0007] In a first aspect, the present application provides a signaling security guarantee method, which is applied to a sending end, and the method comprises:
[0008] determining whether encryption operation and / or integrity protection are needed;
[0009] when encryption operation is needed, performing encryption operation on the user plane control signaling; and / or,
[0010] when integrity protection is needed, performing integrity protection on the user plane control signaling.
[0011] In the embodiments of the present application, the encryption operation on the user plane control signaling comprises:
[0012] encrypting parts of MAC subPDU containing the user plane control signaling except MAC sub-headers; or,
[0013] encrypting all MAC PDUs containing the user plane control signaling except the first MAC sub-header; or,
[0014] encrypting all half-MAC PDUs containing the user plane control signaling except the first MAC sub-header.
[0015] In the embodiments of the present application, the MAC sub-header carries indication information of whether the user plane control signaling is encrypted.
[0016] In the embodiments of the present application, the MAC PDU comprises one or more MAC subPDUs; or,
[0017] one or more MAC subPDUs containing the user plane control signaling in the MAC PDU are organized into half-MAC PDUs.
[0018] In the embodiments of the present application, the integrity protection operation on the user plane control signaling comprises:
[0019] integrity protection of parts of MAC subPDU containing the user plane control signaling except MAC sub-headers; or,
[0020] integrity protection of all MAC PDUs containing the user plane control signaling except the first MAC sub-header; or,
[0021] integrity protection of all MAC PDUs containing the user plane control signaling; or,
[0022] integrity protection of all half-MAC PDUs containing the user plane control signaling except the first MAC sub-header.
[0023] In the embodiments of the present application, the integrity protection operation on the user plane control signaling comprises:
[0024] After the integrity protection operation on the user plane control signaling, a MAC-I is generated and placed at the last position of the MAC subPDU subjected to integrity protection, or at the last position of the MAC PDU.
[0025] In the embodiments of the present application, the MAC subheader carries indication information of whether the user plane control signaling is integrity protected.
[0026] In the embodiments of the present application, the method further comprises:
[0027] The MAC layer acquires an encrypted key and / or an integrity protected key, or acquires an encrypted key parameter and / or an integrity protected key parameter; the key parameter is used to derive a key;
[0028] Determine the input parameter of encryption and / or integrity protection.
[0029] In the embodiments of the present application, the input parameter includes a bearer number and / or a counter, and the method further comprises:
[0030] The value of the bearer number is determined based on a communication protocol, or the value of the bearer number is configured by a network side when the encryption operation and / or the integrity protection of the user plane control signaling is configured;
[0031] The counter value is designated based on a communication protocol, or the counter value is configured by the network side when the encryption operation and / or the integrity protection of the user plane control signaling is configured, or the counter value is added in the MAC subheader by the network side when the user plane control signaling requiring encryption / integrity protection is configured.
[0032] In the embodiments of the present application, the encrypted key includes any one of the following:
[0033] A key for encrypting RRC signaling;
[0034] A key for encrypting user plane data;
[0035] A superior key parameter, which is used to generate a new encrypted key.
[0036] In the embodiments of the present application, the integrity protected key includes any one of the following:
[0037] A key for integrity protecting RRC signaling; a key for integrity protecting user plane data;
[0038] A superior key parameter, which is used to generate a new integrity protected key.
[0039] In the embodiments of the present application, the acquiring of the encrypted key and / or the integrity protected key includes:
[0040] The PDCP layer informs the MAC layer of the encrypted key and / or the integrity protected key; or,
[0041] The RRC layer informs the MAC layer of the encrypted key and / or the integrity-protected key; or, the RRC layer informs the MAC layer of input parameters for deriving the encrypted and / or integrity-protected key; or,
[0042] The encrypted key and / or the integrity-protected key are derived based on upper key parameters of an entity where the MAC layer is located or based on the upper key parameters obtained from a core network.
[0043] In an embodiment of the present application, when the sending end is a base station, the user plane control signaling is downlink user plane control signaling.
[0044] In an embodiment of the present application, when the sending end is a terminal, the user plane control signaling is uplink user plane control signaling.
[0045] In an embodiment of the present application, when the sending end is a base station, before the determination of whether encryption operation and / or integrity protection is needed, the method further comprises:
[0046] The RRC signaling is sent to the terminal, and the RRC signaling contains indication information about whether the user plane control signaling is encrypted and / or integrity-protected.
[0047] In an embodiment of the present application, the indication information includes any one of the following: whether a specific user plane control signaling is encrypted, whether all user plane control signaling of the terminal is encrypted, and whether all contents of a MAC protocol data unit of the MAC layer are encrypted; and / or,
[0048] any one of the following: whether a specific user plane control signaling is integrity-protected, whether all user plane control signaling of the terminal is integrity-protected, and whether all contents of a MAC protocol data unit of the MAC layer are integrity-protected.
[0049] In an embodiment of the present application, the determination of whether encryption operation and / or integrity protection is needed comprises:
[0050] Whether the user plane control signaling is encrypted and / or integrity-protected is determined based on a communication protocol or based on configuration of the RRC signaling.
[0051] In an embodiment of the present application, the determination of whether the user plane control signaling is encrypted and / or integrity-protected based on the communication protocol or based on the configuration of the RRC signaling comprises:
[0052] In RRC signaling of the network side for configuring parameters related to specific user plane control signaling, indication information for encryption operation and / or integrity protection of the specific user plane control signaling is added; or,
[0053] In RRC signaling of the network side for configuring the terminal, encryption operation and / or integrity protection of all user plane control signaling is configured; or,
[0054] In RRC signaling of the network side for configuring the terminal, encryption operation and / or integrity protection is configured at the MAC layer; or,
[0055] In the communication protocol, all user plane control signaling is configured to be encrypted and / or integrity protected; or,
[0056] In the communication protocol, specific user plane control signaling is configured to be encrypted and / or integrity protected; or,
[0057] In the communication protocol, specific MAC layer (or MAC entity) is configured to be encrypted and / or integrity protected.
[0058] In a second aspect, the present application provides a signaling security guarantee method, which is applied to a receiving end, and the method comprises the following steps:
[0059] Receiving user plane control signaling, and determining whether decryption operation and / or integrity protection verification is needed;
[0060] When decryption operation is needed, performing decryption operation on the user plane control signaling; and / or,
[0061] When integrity protection verification is needed, performing integrity protection verification on the user plane control signaling.
[0062] In the embodiments of the present application, the decryption operation on the user plane control signaling comprises the following steps:
[0063] Determining whether the MAC subPDU corresponding to the MAC subheader is encrypted according to the type of user plane control signaling indicated in the MAC subheader or the indication information of the user plane control signaling carried in the MAC subheader, and performing decryption operation on the encrypted load part of the MAC subPDU to obtain the user plane control signaling; or,
[0064] Determining whether the MAC PDU is encrypted according to the type of user plane control signaling indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, and performing decryption operation on the encrypted MAC PDU to obtain the user plane control signaling; or,
[0065] Determine whether the half-MAC PDU is encrypted according to the type of user plane control signaling indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, and perform decryption on the encrypted half-MAC PDU to obtain the user plane control signaling.
[0066] In the embodiments of the present application, the integrity protection verification of the user plane control signaling comprises:
[0067] Determine whether the MAC subPDU corresponding to the MAC subheader is integrity protected according to the type of user plane control signaling indicated in the MAC subheader or the indication information of the user plane control signaling carried in the MAC subheader, and perform integrity protection verification on the payload part of the integrity protected MAC subPDU to generate an X-MAC; or,
[0068] Determine whether the MAC PDU is integrity protected according to the type of user plane control signaling indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, and perform integrity protection verification on the integrity protected MAC PDU to generate an X-MAC; or,
[0069] Perform integrity verification on the part of the MAC PDU except MAC-I to generate an X-MAC; or,
[0070] Determine whether the half-MAC PDU is integrity protected according to the type of user plane control signaling indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, and perform integrity protection verification on the integrity protected half-MAC PDU to generate an X-MAC.
[0071] In the embodiments of the present application, after the decryption operation on the user plane control signaling, the method further comprises:
[0072] If the decryption is successful and / or the integrity protection verification is successful, apply the user plane control signaling;
[0073] If the decryption fails and / or the integrity protection verification fails, notify the corresponding high-function layer of the MAC layer.
[0074] In the embodiments of the present application, the method further comprises:
[0075] The MAC layer obtains an encrypted key and / or an integrity protected key, or obtains an encrypted key parameter and / or an integrity protected key parameter; the key parameter is used to derive a key;
[0076] determining an input parameter of encryption and / or integrity protection.
[0077] In the embodiments of the present application, the input parameter comprises a bearer number and a counter, and the method further comprises:
[0078] determining the value of the bearer number based on a communication protocol specification, or configuring the value of the bearer number by a network side when configuring the encryption operation and / or integrity protection of the user plane control signaling;
[0079] designating the counter value based on a communication protocol specification, or configuring the counter value by the network side when configuring the encryption operation and / or integrity protection of the user plane control signaling, or adding the counter value in the MAC subheader by the network side when configuring the user plane control signaling requiring encryption / integrity protection.
[0080] In the embodiments of the present application, the encryption key comprises any one of the following:
[0081] a key for encrypting RRC signaling;
[0082] a key for encrypting user plane data;
[0083] a superior key parameter used for generating a new encryption key.
[0084] In the embodiments of the present application, the integrity protection key comprises any one of the following:
[0085] a key for integrity protection of RRC signaling;
[0086] a key for integrity protection of user plane data;
[0087] a superior key parameter used for generating a new integrity protection key.
[0088] In the embodiments of the present application, the obtaining of the encryption key and / or the integrity protection key comprises:
[0089] the PDCP layer informs the MAC layer of the encryption key and / or the integrity protection key; or,
[0090] the RRC layer informs the MAC layer of the encryption key and / or the integrity protection key; or, the RRC layer informs the MAC layer of the input parameter of the derived key of encryption and / or integrity protection; or,
[0091] deriving the encryption key and / or the integrity protection key based on a superior key parameter of an entity where the MAC layer is located or based on the superior key parameter obtained from a core network.
[0092] In the embodiments of the present application, when the receiving end is a base station, the user plane control signaling is uplink user plane control signaling.
[0093] When the receiving end is a terminal, the user plane control signaling is downlink user plane control signaling.
[0094] In the embodiments of the present application, when the receiving end is a terminal, before determining whether encryption operation and / or integrity protection is needed, the method further comprises:
[0095] Receiving radio resource control (RRC) signaling sent by the base station, wherein the RRC signaling contains indication information about whether the user plane control signaling is encrypted and / or integrity protected.
[0096] In the embodiments of the present application, the determining whether decryption operation and / or integrity protection verification is needed comprises:
[0097] Based on the communication protocol or based on the configuration of the RRC signaling, determining whether decryption operation and / or integrity protection verification is needed for the user plane control signaling.
[0098] In a third aspect, the present application further provides a signaling security guarantee device, which is applied to a sending end, and comprises:
[0099] A judging module, configured to determine whether encryption operation and / or integrity protection is needed.
[0100] An encryption module, configured to perform encryption operation on the user plane control signaling when encryption operation is needed; and / or,
[0101] An integrity protection module, configured to perform integrity protection on the user plane control signaling when integrity protection is needed.
[0102] In a fourth aspect, the present application further provides a signaling security guarantee device, which is applied to a receiving end, and comprises:
[0103] A receiving determining module, configured to receive user plane control signaling and determine whether decryption operation and / or integrity protection verification is needed.
[0104] A decryption module, configured to perform decryption operation on the user plane control signaling when decryption operation is needed; and / or,
[0105] A verification module, configured to perform integrity protection verification on the user plane control signaling when integrity protection verification is needed.
[0106] In a fifth aspect, the present application provides a communication device applied to a sending end, comprising a memory, a transceiver, and a processor.
[0107] a memory for storing a computer program; a transceiver for transceiving data under control of the processor; and a processor for reading the computer program in the memory and performing the following operations:
[0108] determining whether encryption operation and / or integrity protection is needed;
[0109] when encryption operation is needed, performing encryption operation on the user plane control signaling; and / or,
[0110] when integrity protection is needed, performing integrity protection on the user plane control signaling.
[0111] In the embodiments of the present application, the encryption operation on the user plane control signaling comprises:
[0112] encrypting parts of MAC subPDU containing the user plane control signaling except MAC sub-headers; or,
[0113] encrypting all parts of MAC PDU containing the user plane control signaling except the first MAC sub-header; or,
[0114] encrypting all parts of half-MAC PDU containing the user plane control signaling except the first MAC sub-header.
[0115] In the embodiments of the present application, the MAC PDU comprises one or more MAC subPDUs; and one or more MAC subPDUs containing the user plane control signaling in the MAC PDU are organized into half-MAC PDU.
[0116] In the embodiments of the present application, the integrity protection operation on the user plane control signaling comprises:
[0117] performing integrity protection on parts of MAC subPDU containing the user plane control signaling except MAC sub-headers; or,
[0118] performing integrity protection on all parts of MAC PDU containing the user plane control signaling except the first MAC sub-header; or,
[0119] performing integrity protection on MAC PDU containing the user plane control signaling; or,
[0120] The MAC half-MAC PDU containing the user plane control signaling is integrity protected except the first MAC subheader.
[0121] In the embodiments of the present application, the operation of integrity protecting the user plane control signaling comprises:
[0122] After the user plane control signaling is integrity protected, a MAC-I is generated and placed at the last position of the MAC subPDU that is integrity protected, or at the last position of the MAC PDU.
[0123] In the embodiments of the present application, the MAC subheader carries indication information of whether the user plane control signaling is integrity protected.
[0124] In the embodiments of the present application, the processor is further configured to:
[0125] The MAC layer acquires an encryption key and / or an integrity protection key, or acquires an encryption key parameter and / or an integrity protection key parameter; the key parameter is used to derive a key;
[0126] Determine the input parameter of encryption and / or integrity protection.
[0127] In the embodiments of the present application, the input parameter comprises a bearer number and / or a counter, and the processor is further configured to:
[0128] The value of the bearer number is determined based on a communication protocol, or is configured by a network side when the encryption operation and / or the integrity protection of the user plane control signaling is configured;
[0129] The counter value is designated based on a communication protocol, or is configured by the network side when the encryption operation and / or the integrity protection of the user plane control signaling is configured, or is added in the MAC subheader by the network side when the user plane control signaling that needs to be encrypted / integrity protected is configured.
[0130] In the embodiments of the present application, the encryption key comprises any one of the following:
[0131] The encryption key for RRC signaling;
[0132] The encryption key for user plane data;
[0133] The upper key parameter is used to generate a new encryption key.
[0134] In the embodiments of the present application, the integrity protection key comprises any one of the following:
[0135] a key for RRC signaling integrity protection;
[0136] a key for user plane data integrity protection;
[0137] a superior key parameter, which is used to generate a new integrity-protected key.
[0138] In the embodiments of the present application, the key for encryption and / or integrity protection is obtained by:
[0139] the PDCP layer informs the MAC layer of the key for encryption and / or integrity protection;
[0140] the RRC layer informs the MAC layer of the key for encryption and / or integrity protection; or, the RRC layer informs the MAC layer of input parameters of the derived key for encryption and / or integrity protection;
[0141] the key for encryption and / or integrity protection is derived based on a superior key parameter of an entity where the MAC layer is located or based on the superior key parameter obtained from a core network.
[0142] In the embodiments of the present application, in the case where the sending end is a base station, the user plane control signaling is downlink user plane control signaling.
[0143] In the case where the sending end is a terminal, the user plane control signaling is uplink user plane control signaling.
[0144] In the embodiments of the present application, in the case where the sending end is a base station, the processor is further configured to:
[0145] send, to a terminal, radio resource control (RRC) signaling, wherein the RRC signaling contains indication information about whether the user plane control signaling is encrypted and / or integrity-protected.
[0146] In the embodiments of the present application, the indication information includes any one of: whether a specific user plane control signaling is encrypted, whether all user plane control signaling of the terminal is encrypted, and whether all contents of a MAC protocol data unit of the MAC layer are encrypted; and / or,
[0147] any one of: whether a specific user plane control signaling is integrity-protected, whether all user plane control signaling of the terminal is integrity-protected, and whether all contents of a MAC protocol data unit of the MAC layer are integrity-protected.
[0148] In the embodiments of the present application, the determination of whether encryption and / or integrity protection is needed includes:
[0149] determining, based on a communication protocol specification or a configuration based on RRC signaling, whether to perform encryption and / or integrity protection on the user plane control signaling.
[0150] In the embodiments of the present application, the determination of whether to perform encryption and / or integrity protection on the user plane control signaling based on the communication protocol specification or the configuration based on RRC signaling comprises:
[0151] adding, in RRC signaling in which the network side configures specific user plane control signaling related parameters, indication information of performing encryption and / or integrity protection on the specific user plane control signaling; or,
[0152] configuring, by the network side, RRC signaling to perform encryption and / or integrity protection on all user plane control signaling by the terminal; or,
[0153] configuring, by the network side, the terminal to perform encryption and / or integrity protection at the MAC layer; or,
[0154] performing encryption and / or integrity protection on all user plane control signaling according to the communication protocol specification; or,
[0155] performing encryption and / or integrity protection on specific user plane control signaling according to the communication protocol; or,
[0156] performing encryption and / or integrity protection on a specific MAC layer (or MAC entity) according to the communication protocol specification.
[0157] In a sixth aspect, the present application further provides a communication device applied to a receiving end, comprising a memory, a transceiver and a processor.
[0158] The memory is used to store computer programs; the transceiver is used to transceive data under the control of the processor; and the processor is used to read the computer programs in the memory and perform the following operations:
[0159] receiving user plane control signaling and determining whether decryption and / or integrity protection verification is needed;
[0160] performing decryption on the user plane control signaling when decryption is needed; and / or,
[0161] performing integrity protection verification on the user plane control signaling when integrity protection verification is needed.
[0162] In the embodiments of the present application, the decryption of the user plane control signaling comprises:
[0163] determine, through the user plane control signaling type indicated in the MAC subheader or the indication information of the user plane control signaling carried in the MAC subheader, whether the MAC subPDU corresponding to the MAC subheader is encrypted, and perform decryption on the payload part of the encrypted MAC subPDU to obtain the user plane control signaling; or
[0164] determine, through the user plane control signaling type indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, whether the MAC PDU generated by the MAC layer is encrypted, and perform decryption on the encrypted MAC PDU to obtain the user plane control signaling; or
[0165] determine, through the user plane control signaling type indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, whether the half-MAC PDU is encrypted, and perform decryption on the encrypted half-MAC PDU to obtain the user plane control signaling.
[0166] In the embodiments of the present application, the integrity protection verification of the user plane control signaling includes:
[0167] determine, through the user plane control signaling type indicated in the MAC subheader or the indication information of the user plane control signaling carried in the MAC subheader, whether the MAC subPDU corresponding to the MAC subheader is integrity protected, and perform integrity protection verification on the payload part of the integrity protected MAC subPDU to generate X-MAC; or
[0168] determine, through the user plane control signaling type indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, whether the MAC PDU is integrity protected, and perform integrity protection verification on the integrity protected MAC PDU to generate X-MAC; or
[0169] perform integrity verification on the part of the MAC PDU except MAC-I to generate X-MAC; or
[0170] determine, through the user plane control signaling type indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, whether the half-MAC PDU is integrity protected, and perform integrity protection verification on the integrity protected half-MAC PDU to generate X-MAC.
[0171] In the embodiments of the present application, the processor is further configured to:
[0172] If the decryption is successful and / or the integrity protection verification is successful, the user plane control signaling is applied.
[0173] If the decryption fails and / or the integrity protection verification fails, a corresponding high-level layer of the MAC layer is notified.
[0174] In the embodiments of the present application, the processor is further configured to:
[0175] The MAC layer acquires an encrypted key and / or an integrity protection key, or acquires an encrypted key parameter and / or an integrity protection key parameter; the key parameter is used to derive a key.
[0176] The input parameter of encryption and / or integrity protection is determined.
[0177] In the embodiments of the present application, the input parameter includes a bearer number and a counter, and the processor is further configured to:
[0178] The value of the bearer number is determined based on a communication protocol, or the value of the bearer number is configured by a network side when the encryption operation and / or the integrity protection of the user plane control signaling is configured.
[0179] The counter value is designated based on a communication protocol, or the counter value is configured by the network side when the encryption operation and / or the integrity protection of the user plane control signaling is configured, or the counter value is added in the MAC subheader by the network side when the user plane control signaling requiring encryption / integrity protection is configured.
[0180] In the embodiments of the present application, the encrypted key includes any one of the following:
[0181] A key for encrypting RRC signaling;
[0182] A key for encrypting user plane data;
[0183] A superior key parameter, which is used to generate a new encrypted key.
[0184] In the embodiments of the present application, the integrity protection key includes any one of the following:
[0185] A key for integrity protection of RRC signaling;
[0186] A key for integrity protection of user plane data;
[0187] A superior key parameter, which is used to generate a new integrity protection key.
[0188] In the embodiments of the present application, the obtaining of the encrypted key and / or the integrity protection key comprises:
[0189] The PDCP layer informs the MAC layer of the encrypted key and / or the integrity protection key; or,
[0190] The RRC layer informs the MAC layer of the encrypted key and / or the integrity protection key; or, the RRC layer informs the MAC layer of input parameters of the encrypted key and / or the integrity protection key; or,
[0191] The encrypted key and / or the integrity protection key are derived based on upper key parameters of an entity where the MAC layer is located or based on the upper key parameters obtained from a core network.
[0192] In the embodiments of the present application, when the receiving end is a base station, the user plane control signaling is uplink user plane control signaling.
[0193] When the receiving end is a terminal, the user plane control signaling is downlink user plane control signaling.
[0194] In the embodiments of the present application, the processor is further configured to:
[0195] receive radio resource control (RRC) signaling sent by a base station, wherein the RRC signaling comprises indication information about whether the user plane control signaling is encrypted and / or integrity protected.
[0196] In the embodiments of the present application, the determining of whether the decryption operation and / or the integrity protection verification is needed comprises:
[0197] determining, based on a communication protocol or based on configuration of the RRC signaling, whether the user plane control signaling is subjected to the decryption operation and / or the integrity protection verification.
[0198] In a seventh aspect, the present application further provides a computer readable storage medium having a computer program stored thereon, and the computer program is configured to implement the following steps when executed by a processor:
[0199] determining whether encryption operation and / or integrity protection is needed;
[0200] when the encryption operation is needed, performing the encryption operation on the user plane control signaling; and / or,
[0201] when the integrity protection is needed, performing the integrity protection on the user plane control signaling.
[0202] In an eighth aspect, the present application further provides a computer readable storage medium having a computer program stored thereon, and the computer program is configured to implement the following steps when executed by a processor:
[0203] receiving the user plane control signaling, determining whether decryption operation and / or integrity protection verification is needed;
[0204] when decryption operation is needed, performing decryption operation on the user plane control signaling; and / or,
[0205] when integrity protection verification is needed, performing integrity protection verification on the user plane control signaling.
[0206] In a ninth aspect, the present application provides a computer program product comprising a computer program which, when executed by a processor, implements the following steps:
[0207] determining whether encryption operation and / or integrity protection is needed;
[0208] when encryption operation is needed, performing encryption operation on the user plane control signaling; and / or,
[0209] when integrity protection is needed, performing integrity protection on the user plane control signaling.
[0210] In a tenth aspect, the present application provides a computer program product comprising a computer program which, when executed by a processor, implements the following steps:
[0211] receiving the user plane control signaling, determining whether decryption operation and / or integrity protection verification is needed;
[0212] when decryption operation is needed, performing decryption operation on the user plane control signaling; and / or,
[0213] when integrity protection verification is needed, performing integrity protection verification on the user plane control signaling.
[0214] The details of one or more embodiments of the application are set forth in the accompanying drawings and the description below. Other features, objects, and advantages of the application will be apparent from the description and drawings, and from the claims. BRIEF DESCRIPTION OF DRAWINGS
[0215] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced as follows. Obviously, the drawings in the following description are the drawings of the embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor on the basis of these drawings.
[0216] FIG. 1 is an application environment diagram of a signaling security guarantee method in an embodiment;
[0217] Figure 2 is a flowchart illustrating a key generation mechanism in one embodiment;
[0218] Figure 3 is a flowchart illustrating a MAC-I and X-MAC derivation process in one embodiment;
[0219] Figure 4 is a diagram illustrating a 5G control plane protocol stack structure in one embodiment;
[0220] Figure 5 is a flowchart illustrating a method for signaling security in one embodiment;
[0221] Figure 6a is a flowchart illustrating a first user plane control signaling encryption method in one embodiment;
[0222] Figure 6b is a flowchart illustrating a second user plane control signaling encryption method in one embodiment;
[0223] Figure 6c is a flowchart illustrating a third user plane control signaling encryption method in one embodiment;
[0224] Figure 7 is a diagram illustrating an internal structure of an uplink MAC PDU in one embodiment;
[0225] Figure 8 is a diagram illustrating an internal structure of a half-MAC PDU in one embodiment;
[0226] Figure 9a is a flowchart illustrating a first user plane control signaling integrity protection method in one embodiment;
[0227] Figure 9b is a flowchart illustrating a second user plane control signaling integrity protection method in one embodiment;
[0228] Figure 9c is a flowchart illustrating a third user plane control signaling integrity protection method in one embodiment;
[0229] Figure 9d is a flowchart illustrating a fourth user plane control signaling integrity protection method in one embodiment;
[0230] Figure 10 is a flowchart illustrating a step of determining input parameters in one embodiment;
[0231] Figure 11 is a flowchart illustrating a step of adding a counter value in a MAC subheader in one embodiment;
[0232] Figure 12a is a flowchart illustrating a first step of obtaining an encryption key and / or an integrity protection key in one embodiment;
[0233] Figure 12b is a flowchart illustrating a second step of obtaining an encryption key and / or an integrity protection key in one embodiment;
[0234] Figure 12c is a flow diagram illustrating a third method of obtaining a key for ciphering and / or integrity protection in an embodiment;
[0235] Figure 13a is a flow diagram illustrating a method of adding indication information for ciphering operation and / or integrity protection of user plane control signaling in an embodiment;
[0236] Figure 13b is a flow diagram illustrating a method of configuring ciphering operation and / or integrity protection of all user plane control signaling through RRC signaling in an embodiment;
[0237] Figure 13c is a flow diagram illustrating a method of configuring ciphering operation and / or integrity protection at MAC layer through network side in an embodiment;
[0238] Figure 13d is a flow diagram illustrating a method of configuring ciphering operation and / or integrity protection of all user plane control signaling through communication protocol in an embodiment;
[0239] Figure 13e is a flow diagram illustrating a method of configuring ciphering operation and / or integrity protection of specific user plane control signaling through communication protocol in an embodiment;
[0240] Figure 13f is a flow diagram illustrating a method of configuring ciphering operation and / or integrity protection of specific MAC layer through communication protocol in an embodiment;
[0241] Figure 14 is a flow diagram illustrating a method of signaling security in another embodiment;
[0242] Figure 15a is a flow diagram illustrating a first method of deciphering user plane control signaling in an embodiment;
[0243] Figure 15b is a flow diagram illustrating a second method of deciphering user plane control signaling in an embodiment;
[0244] Figure 15c is a flow diagram illustrating a third method of deciphering user plane control signaling in an embodiment;
[0245] Figure 16a is a flow diagram illustrating a first method of verifying integrity protection in an embodiment;
[0246] Figure 16b is a flow diagram illustrating a second method of verifying integrity protection in an embodiment;
[0247] Figure 16c is a flow diagram illustrating a third method of verifying integrity protection in an embodiment;
[0248] Figure 16d is a flow diagram illustrating a fourth method of verifying integrity protection in an embodiment;
[0249] FIG. 17 is a flow diagram of a process for handling user plane control signaling in an embodiment;
[0250] FIG. 18 is a flow diagram of a process for determining input parameters in an embodiment;
[0251] FIG. 19 is a flow diagram of a process for adding a counter value in a MAC subheader in an embodiment;
[0252] FIG. 20a is a flow diagram of a process for obtaining a secret key in a first 5G control plane protocol stack in an embodiment;
[0253] FIG. 20b is a flow diagram of a process for obtaining a secret key in a second 5G control plane protocol stack in an embodiment;
[0254] FIG. 20c is a flow diagram of a process for obtaining a secret key in a third 5G control plane protocol stack in an embodiment;
[0255] FIG. 21 is an example flow diagram of a process for implementing signaling security between a base station and a terminal in an embodiment;
[0256] FIG. 22 is a block diagram of a signaling security device on a sending side in an embodiment;
[0257] FIG. 23 is a block diagram of a signaling security device on a receiving side in an embodiment;
[0258] FIG. 24 is a block diagram of an internal structure of a communication device that is a terminal device in an embodiment;
[0259] FIG. 25 is a block diagram of an internal structure of a communication device that is a base station in an embodiment. DETAILED DESCRIPTION
[0260] To make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are intended to explain the present application, and are not intended to limit the present application.
[0261] In the embodiments of the present application, the term "and / or" describes the association relationship of the associated objects, and means that there can be three relationships, for example, A and / or B can mean that there are three cases of A alone, A and B together, and B alone. The character " / " generally represents an "or" relationship between the associated objects before and after it.
[0262] FIG. 1 is a schematic diagram of an application scenario of signaling security provided by an embodiment of the present application. As shown in FIG. 1, the scenario includes a sending end and a receiving end. In FIG. 1, a base station 100 is taken as an example of the sending end, and a terminal 200 is taken as an example of the receiving end. In the case where the sending end is a base station and the receiving end is a terminal, the base station can perform transmission of downlink user plane control signaling with the terminal. Conversely, in the case where the sending end is a terminal and the receiving end is a base station, the base station can perform transmission of uplink user plane control signaling with the terminal.
[0263] The terminal and the base station perform transmission of RRC (Radio Resource Control) signaling, user plane control signaling and user plane data through a network. At present, there is a security guarantee mechanism for transmission of RRC (Radio Resource Control) signaling and user plane data. The security of RRC signaling and user plane data is guaranteed by means of encryption and integrity protection.
[0264] As shown in FIG. 2, for the security guarantee mechanism for transmission of RRC signaling and user plane data, the secret keys used by the access network include: K RRCint , K RRCenc , K Upint , K Upenc . Among them, K RRCint is used for integrity protection of RRC signaling, K RRCenc is used for encryption of RRC signaling, K UPint is used for integrity protection of user plane data, and K UPenc is used for encryption of user plane data.
[0265] The encryption technology used in the security guarantee mechanism for transmission of RRC signaling and user plane data is generally NEA (Encryption Algorithm for 5G). The input parameters involved in the encryption algorithm include: 1, a secret key KEY, 2, a BEARER bearer number, 3, a COUNT, 4, a DIRECTION data flow direction, and 5, a length of a secret key stream required. The secret key KEY is K RRCenc and K UPenc, 128bit; 2) BEARER, bearer number, 5bit; 3) COUNT, combination of HFN (Hyper Frame Number) and PDCP SN, 32bit; 4) DIRECTION, generally set to 0 for uplink and set to 1 for downlink, 1bit; 5) LENGTH, required length of key stream. The KEYSTREAM block output by the NEA algorithm encrypts the input data PLAINTEXT block to obtain the encrypted data block CIPHERTEXT block.
[0266] The integrity protection technology used in the security protection mechanism for RRC signaling and user plane data transmission is generally NIA (Integrity Algorithm for 5G). The MAC-I (MAC (Message authentication code) used for data integrity of signaling messages) and X-MAC (exXpected Message Authentication Code) (wherein the expected message authentication code can also be referred to as XMAC-I in different protocols, and the representation of the expected message authentication code is not limited in the embodiments of the present application) in the integrity protection process are generated from the input parameters shown in FIG. 3. As shown in FIG. 3, the input parameters include: 1) KEY, corresponding to K RRCint and K UPint , 128bit; 2) BEARER, bearer number, 5bit; 3) COUNT, combination of HFN (Hyper Frame Number) and PDCP SN, 32bit; 4) DIRECTION, generally set to 0 for uplink and set to 1 for downlink, 1bit. The MESSAGE in FIG. 3 is input data.
[0267] Figure 4 provides a schematic diagram of a 5G control plane protocol stack. As shown in Figure 4, in a 5G system, encryption and integrity protection functions for RRC signaling and user plane data are both implemented in the PDCP (Packet Data Convergence Protocol) layer. After encryption and integrity protection are completed, the PDCP layer delivers the generated PDCP PDU (Protocol Data Unit) to the RLC (Radio Link Control) layer, the RLC layer processes and delivers to the MAC (Medium Access Control) layer, and finally organizes into a MAC PDU and delivers to the physical layer for air interface transmission. After receiving the air interface transmission data, the receiving end delivers it to the MAC layer, the RLC layer, and the PDCP layer layer by layer, and finally completes decryption and integrity protection verification by the PDCP layer. The PDCP layer delivers the data whose decryption and integrity protection verification are successful to the upper layer (for example, the RRC layer), and discards the data whose decryption and integrity protection verification fail. The air interface key is controlled by the RRC and configured to the PDCP layer for use, and is not sent to other layers of the air interface.
[0268] In addition to RRC signaling, user plane control signaling is also included in the 5G system. This user plane control signaling is mainly implemented through MAC layer control elements (MAC CEs). There are many kinds of MAC CEs, each with different functions, mainly used to transmit various control information, such as buffer reporting, DRX (Discontinuous Reception) commands, TA (Timing Advance) commands, PHR (Power Headroom Report) reporting, secondary cell activation / deactivation, TCI (Transmission Configuration Indicator) indications for various channels, PDCP duplication (PDCP Data Replication) indications, BFR (Beam Failure Recovery) indications, LBT (Listen Before Talk) failure indications, IAB (Integrated Access and Backhaul) timing offset indications, etc. MAC CEs are generated at the MAC layer, and the sending end organizes them into MAC PDUs and sends them to the receiving end. The receiving end's MAC layer parses the MAC CEs and applies them directly. As can be seen, there is no security mechanism for MAC CEs in this transmission process. PDCP and RLC layers also have control PDUs (Protocol Data Units), but their functions are relatively limited, and there is also no security mechanism for MAC CEs.
[0269] In traditional technology, both RRC signaling and user plane data transmission have security mechanisms, including encryption, integrity protection, etc., but there is no security mechanism for user plane control signaling. However, user plane control signaling, especially MAC CEs, has a wide range of functions, and without security mechanisms such as encryption and integrity protection, it is very insecure. For example, if a fake base station sends a fake timing adjustment command to a terminal, it will cause the terminal to fail in data transmission with the normal base station or even fail to connect; a malicious terminal pretending to be another terminal sends a large amount of buffer reporting, which will cause chaos in base station resource allocation and affect the transmission of other terminals and the performance of the entire system.
[0270] Based on the security guarantee requirement of the user plane control signaling in the conventional technology, the embodiment of the present application provides a signaling security guarantee method. When encryption operation and / or integrity protection need to be performed on the user plane control signaling, the user plane control signaling is encrypted and / or integrity protected by the MAC layer of the sending end, and the corresponding decryption and / or integrity verification is performed by the MAC layer of the receiving end. Thus, the security of the user plane control signaling is guaranteed, the malicious attack interference by the pseudo base station or the malicious terminal is avoided, and the stability of the communication system is ensured.
[0271] It should be noted that the beneficial effects brought by the embodiment of the present application or the technical problems solved are not limited to this, but also other implicit or related problems. For details, please refer to the description of the following embodiments.
[0272] The technical solutions of the present application and how the technical solutions of the present application solve the above technical problems will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of the present application will be described below with reference to the drawings.
[0273] In one exemplary embodiment, as shown in FIG. 5, a signaling security guarantee method is provided. Taking the case that the method is applied to the sending end 100 in FIG. 1 as an example, the method includes the following steps 501 to 503. Wherein:
[0274] Step 501, determining whether encryption operation and / or integrity protection is needed.
[0275] In implementation, in view of the security of the user plane control signaling, the malicious attack in the communication process is avoided, and the performance of the entire communication system is affected. Therefore, encryption operation and / or integrity protection can be performed on specific or all user plane control signaling. Therefore, before the transmission of the user plane control signaling, the MAC layer of the sending end judges in advance whether the encryption operation and / or integrity protection needs to be performed on the to-be-transmitted user plane control signaling. Specifically, the MAC layer can judge whether the encryption operation and / or integrity protection is needed based on the configuration of the network side RRC signaling or the communication protocol, which will be described in detail in the subsequent embodiments, and will not be described in detail here.
[0276] Step 502, when encryption operation is needed, performing encryption operation on the user plane control signaling.
[0277] In implementation, when encryption operation is needed, the MAC layer performs encryption operation on the user plane control signaling.
[0278] Optionally, the MAC layer of the sending end can perform encryption operation on the user plane control signaling according to different MAC PDU granularity. Three encryption modes will be provided in the following embodiments of the present application as examples of encryption of the user plane control signaling. The MAC layer can select any one of the three encryption modes to encrypt the user plane control signaling, which will not be described in detail here.
[0279] Step 503, when integrity protection is needed, performing integrity protection on the user plane control signaling.
[0280] In implementation, when integrity protection is needed, the MAC layer performs integrity protection on the user plane control signaling.
[0281] Optionally, the MAC layer of the sending end can perform integrity protection on the user plane control signaling according to different MAC PDU granularity. Four integrity protection modes will be provided in the following embodiments of the present application as examples of integrity protection of the user plane control signaling. The MAC layer can select any one of the four integrity protection modes to perform integrity protection on the user plane control signaling, which will not be described in detail here.
[0282] In the above signaling security guarantee method, the MAC layer of the sending end determines in advance whether encryption operation and / or integrity protection is needed, and when encryption operation and / or integrity protection is needed, the MAC layer of the sending end performs encryption operation and / or integrity protection on the user plane control signaling based on the preset encryption mode and / or integrity protection mode, thereby guaranteeing the security of the user plane control signaling, avoiding malicious attack and interference by a fake base station or a malicious terminal, and ensuring the stability of the communication system.
[0283] In an optional embodiment, the user plane control signaling in the embodiments of the present application is applicable to all MAC CEs, RLC control PDUs, PDCP control PDUs in the 5G communication protocol, or other user plane control signaling newly introduced in addition to RRC signaling. For user plane control signaling not generated by the MAC layer (for example, RLC (Radio Link Control) control PDU), if the MAC layer wants to perform targeted encryption on the user plane control signaling, interlayer interaction needs to be introduced. Specifically, if encryption and / or integrity protection is needed for the RLC Control PDU, the MAC layer reads the RLC PDU submitted by the RLC layer and identifies the corresponding RLC Control PDU through the RLC header; the PDCP Control PDU needs the PDCP layer to inform the RLC layer and / or the MAC layer of the corresponding PDCP Control PDU.
[0284] In one exemplary embodiment, as shown in FIGS. 6a-6c, three encryption methods are provided for user plane control signaling, and the MAC layer can use any one of the three methods corresponding to steps 601a-601c when encrypting the user plane control signaling. Among them:
[0285] Step 601a, encrypt the part of the MAC subPDU containing user plane control signaling except the MAC subheader.
[0286] In implementation, the format of the MAC PDU is as shown in FIG. 7 (the upper row of MAC PDU in FIG. 7 is an example), one MAC protocol data unit (MAC PDU) contains one or more MAC sublayer protocol data units (MAC subPDU), and the structure of the MAC subPDU is one MAC subheader plus one payload part. One MAC subPDU can contain one MAC CE (i.e., user plane control signaling) or one MAC SDU (user plane data). Therefore, when encrypting the user plane control signaling, the MAC layer can encrypt the part of the MAC sublayer protocol data unit (MAC subPDU) containing user plane control signaling except the MAC subheader (i.e., the payload part), and does not encrypt the MAC subheader. The MAC subheader can optionally carry indication information of whether the MAC subPDU is encrypted. Therefore, when the MAC subPDU is organized into a MAC PDU, some MAC subPDUs can be encrypted and some MAC subPDUs can not be encrypted.
[0287] Alternatively, step 601b, encrypt the MAC protocol data unit (MAC PDU) containing user plane control signaling except the first MAC subheader.
[0288] In implementation, when the MAC layer encrypts the user plane control signaling, the entire MAC PDU can be encrypted except the first MAC subheader when generating the MAC PDU. The first MAC subheader can be used to carry indication information of whether the MAC PDU is encrypted.
[0289] Alternatively, step 601c, encrypt the half-MAC protocol data unit (half-MAC PDU) containing user plane control signaling except the first MAC subheader.
[0290] In implementation, the MAC layer can also divide the content to be transmitted into a data part (containing RRC signaling and user plane data) and a user plane control signaling part when organizing the MAC PDU. That is, the MAC layer is divided into a half-MAC protocol data unit (half-MAC PDU), and for the half-MAC PDU, encryption is performed except for the first MAC subheader, so as to achieve encryption protection of the user plane control signaling.
[0291] In this embodiment, three different encryption methods of user plane control signaling are provided, and the MAC layer of the sending end can select any one method to encrypt and protect the user plane control signaling based on actual application requirements. The content of the user plane control signaling is effectively prevented from being stolen or tampered with, and the attack resistance of the communication system is improved.
[0292] In an exemplary embodiment, the MAC PDU includes one or more MAC subPDUs. The specific organization process of the half-MAC PDU includes: one or more MAC subPDUs containing user plane control signaling in the MAC PDU are organized as a whole into a half-MAC PDU.
[0293] Taking a 5G downlink MAC PDU as an example, the structure of the half-MAC PDU is introduced, as shown in FIG. 8. The first MAC subheader can optionally carry indication information of whether the payload part is encrypted, specifically: the MAC layer of the sending end uses the MAC subheader of the first MAC subPDU of the half-MAC PDU to perform encryption indication (that is, carries the encryption indication information), or the MAC layer of the sending end adds a MAC subheader before the original structure of the half-MAC PDU to indicate whether the subsequent content is encrypted. The indication information of whether to encrypt carried in the MAC subheader can be: adding an encryption indication field in the MAC subheader, or using a special LCID (Language Code Identifier) to indicate that the subsequent content is encrypted. Moreover, if a 6G and an updated generation of mobile communication technology adopts a different MAC PDU structure (such as the half-MAC PDU being located in the middle or at the end of the MAC PDU), the design principle given in the embodiment of the application still holds.
[0294] In this embodiment, the MAC layer of the sending end defines the data structure of the half-MAC PDU to encrypt the user plane control signaling, so as to ensure the security of the user plane control signaling and avoid malicious attacks and interference by a pseudo base station or a malicious terminal, and ensure the stability of the communication system.
[0295] In one exemplary embodiment, as shown in FIGS. 9a-9d, four integrity protection modes are provided for user plane control signaling. When the MAC layer performs integrity protection on user plane control signaling, any one of the following four modes corresponding to steps 901a-901d can be used. Among them:
[0296] Step 901a, integrity protection is performed on the part of the MAC subPDU containing user plane control signaling except the MAC subheader.
[0297] In implementation, one MAC protocol data unit (MAC PDU) in the MAC layer contains one or more MAC sublayer protocol data units (MAC subPDU). Therefore, the MAC layer can perform integrity protection on the part (i.e. payload part) of the MAC subPDU in the MAC PDU containing user plane control signaling except the MAC subheader. No integrity protection is performed on the MAC subheader. The MAC subheader can carry indication information of whether the MAC subPDU is integrity protected. Therefore, when the MAC subPDU is organized into a MAC PDU, some MAC subPDUs can be integrity protected and some MAC subPDUs can not be integrity protected.
[0298] Then, the MAC layer of the sending end generates MAC-I (Message Authentication Code-Integrity) after performing integrity protection on the user plane control signaling, and then encapsulates it as the payload of the MAC subPDU. The MAC-I is a kind of message authentication code based on secret key, which is used to verify the integrity of the message.
[0299] Optionally, if there is a length indication field in the MAC subheader of the MAC subPDU, the length indication field indicates the length of the original user plane control signaling plus the length of the MAC-I. Generally, the length of the MAC-I is 4 bytes in 5G. If there is no length indication field in the MAC subheader, the last fixed number of bytes (e.g. 4 bytes) of the MAC subPDU which is integrity protected is the MAC-I.
[0300] Or, step 901b, integrity protection is performed on the MAC PDU containing user plane control signaling except the first MAC subheader.
[0301] In implementation, the MAC layer performs integrity protection on the whole MAC PDU except the first MAC subheader when generating the MAC PDU. The first MAC subheader can be used to carry the indication information of whether the MAC PDU is integrity protected. Then, the MAC layer of the sending end generates the MAC-I and places it at the last part (payload part) of the MAC PDU.
[0302] Or, step 901c, performing integrity protection on the MAC PDU containing the user plane control signaling.
[0303] In implementation, one MAC PDU contains one or more MAC subPDUs, and the constituent structure of the MAC subPDU is one MAC subheader plus one payload part. When generating the MAC PDU, the MAC layer can perform integrity protection on all MAC subheaders and payloads. Further, the MAC layer protects the contents of the MAC subheader and the payload, generates the MAC-I, and places it at the last position of the MAC PDU to obtain the final MAC PDU. The MAC-I is used to verify the integrity of the message.
[0304] Or, step 901d, performing integrity protection on the MAC half-MAC PDU containing the user plane control signaling except the first MAC subheader.
[0305] In implementation, when generating the MAC PDU, the MAC layer divides the content to be transmitted into a data part (containing RRC signaling and user plane data) and a user plane control signaling part. Then, the MAC layer obtains one or more MAC subPDUs containing the user plane control signaling as a whole to obtain the half-MAC PDU. For the half-MAC PDU, the MAC layer uniformly performs integrity protection on the other parts of the half-MAC PDU except the first MAC subheader. Then, the MAC layer of the sending end generates the MAC-I and places it at the last position of the MAC PDU to generate the final MAC PDU.
[0306] The first MAC subheader of the half-MAC PDU can carry the indication information of whether the user plane control signaling is integrity protected. Specifically, the MAC layer uses the MAC subheader of the first MAC subPDU of the half-MAC PDU to perform integrity protection indication, or the MAC layer adds a MAC subheader before the original structure of the half-MAC PDU to indicate that the subsequent content is integrity protected.
[0307] Optionally, the indication information of whether the integrity protection is carried in the MAC subheader can be implemented in one of the following ways: adding an integrity inclusion indication field in the MAC subheader; or using a special LCID to indicate that the subsequent content is integrity protected.
[0308] In this embodiment, four different integrity protection modes of user plane control signaling are provided, and the MAC layer can select any one mode to perform integrity protection on the user plane control signaling based on actual application requirements. The content of the user plane control signaling is effectively prevented from being stolen or tampered with, and the attack resistance of the communication system is improved.
[0309] In the embodiments of the present application, after the MAC layer performs integrity protection on the user plane control signaling, a MAC-I is generated, and the MAC-I is placed at the last position of the MAC subPDU subjected to integrity protection, or at the last position of the MAC PDU.
[0310] In implementation, after the MAC layer performs integrity protection on the user plane control signaling, a MAC-I is generated, and then the MAC layer places the MAC-I at the last position of the MAC subPDU subjected to integrity protection, or at the last position of the MAC PDU, which is taken as the load of the MAC subPDU by the MAC layer. If the MAC subheader has a length indication field, the length indication field indicates the length of the original user plane control signaling + the length of the MAC-I. Generally, the length of the MAC-I is 4 bytes in 5G. If the MAC subheader does not have a length indication field, the MAC layer regards the content of the last fixed number of bytes (such as 4 bytes) of the MAC subPDU subjected to integrity protection as the MAC-I.
[0311] In one embodiment, the MAC subheader carries indication information of whether the user plane control signaling is subjected to integrity protection.
[0312] In an optional exemplary embodiment, as shown in FIG. 10, the MAC layer can pre-acquire a secret key for encryption, integrity protection, etc., to prepare for subsequent security protection of the user plane control signaling. The method further includes the following steps:
[0313] In step 1001, the MAC layer acquires an encryption secret key and / or an integrity protection secret key, or acquires an encryption secret key parameter and / or an integrity protection secret key parameter.
[0314] The secret key parameter is used to derive the secret key.
[0315] In implementation, the MAC layer of the sending end can multiplex the key for encryption operation and / or integrity protection operation of the RRC signaling or user plane data, so that the MAC layer directly obtains the encryption key and / or integrity protection key. Alternatively, the MAC layer can also obtain the encryption key parameter and / or integrity protection key parameter. Then, the MAC layer derives the key from the key parameter.
[0316] In step 1002, the input parameter for encryption and / or integrity protection is determined.
[0317] In implementation, in order to realize the security guarantee of the user plane control signaling, after obtaining the key, the MAC layer also needs to determine the corresponding encryption input parameter and / or integrity protection input parameter. Specifically, the MAC layer is equivalent to the same process as user plane data encryption / integrity protection, and when the user plane control signaling is encrypted and / or integrity protected, the MAC layer will adjust the input parameter accordingly.
[0318] In this embodiment, the MAC layer directly obtains or derives the key to prepare for the encryption or integrity protection of the user plane control signaling, so as to ensure the secure transmission of the user plane control signaling in the communication system.
[0319] In an exemplary embodiment, as shown in FIG. 11, the input parameter that needs to be adjusted in the encryption operation and / or integrity protection process of the user plane control signaling includes the bearer number and / or the counter, and the method further includes:
[0320] In step 1101, the value of the bearer number is determined based on the communication protocol, or the value of the bearer number is configured by the network side when the encryption operation and / or integrity protection of the user plane control signaling is configured.
[0321] In implementation, for the bearer number BEARER, the MAC layer can set the value of BEARER specified by the communication protocol as the value of BEARER for the user plane control signaling, or the MAC layer configures the corresponding BEARER value when the encryption / integrity protection function of the user plane control signaling is configured by the network side.
[0322] In step 1102, the value of the counter is specified based on the communication protocol, or the value of the counter is configured by the network side when the encryption operation and / or integrity protection of the user plane control signaling is configured, or the value of the counter is added in the MAC subheader by the network side when the user plane control signaling that needs to be encrypted / protected is configured.
[0323] In implementation, the configuration of the value of the counter COUNT can adopt any one of the following three configuration modes:
[0324] 1. The MAC layer can set the counter value specified in the communication protocol as the COUNT value for the user plane control signaling.
[0325] 2. The network side configures the value of the corresponding COUNT when configuring the encryption operation and / or integrity protection function of the user plane control signaling.
[0326] 3. The network side adds the value of the COUNT in the MAC subheader when configuring the user plane control signaling that needs to be encrypted / protected.
[0327] For the third method, the sender adds the COUNT value configured by the network side in the MAC subheader of the user plane control signaling that needs to be encrypted / protected. Two methods can be used:
[0328] 1. A set of COUNT values is used for all user plane control signaling that needs to be encrypted / protected. The MAC layer increments the COUNT value carried in the MAC subheader of the MAC subPDU containing the user plane control signaling that needs to be encrypted / protected by 1 after generating each MAC subPDU with the COUNT value.
[0329] 2. A set of COUNT values is maintained for different types of user plane control signaling. Different COUNT values are maintained for BSR MAC CE (Bootstrapping MAC Configuration Entity) and PHR MAC CE (Public Key Hash-based Routing Message Authentication Code Configuration Entity).
[0330] In this embodiment, the input parameters are adjusted to perform encryption operation and / or integrity protection based on the adjusted input parameters when ensuring the security of the user plane control signaling, thereby achieving secure transmission of the user plane control signaling in the communication system.
[0331] In one example embodiment, the encryption key in step 1001 includes any of the following:
[0332] 1. The key for encrypting RRC signaling;
[0333] 2. The key for encrypting user plane data;
[0334] 3. The upper key parameter, wherein the upper key parameter is used to generate a new encryption key.
[0335] In implementation, when the MAC layer obtains the key for encrypting the user plane control signaling, it can choose to reuse the key K used to encrypt the RRC signaling. RRCenc , or the MAC layer reuses the secret key K to encrypt the user plane data Upenc , or the MAC layer generates a new key based on the upper key parameters (such as KgNB and / or NH (Next Hop)). The MAC layer generates a new key based on the upper key parameters by inputting the upper key and a separate algorithm ID (Alg-ID) into the KDF (Key derivation Function) to obtain the key K MACenc .
[0336] In this embodiment, the MAC layer can directly reuse the encryption key by obtaining the encryption key for RRC signaling and user plane data, or generate a new encryption key based on the upper-level key parameters, thereby effectively protecting the security of user plane control signaling and ensuring the reliability and confidentiality of communications.
[0337] In an exemplary embodiment, the integrity protection key in step 1001 includes any of the following:
[0338] 1. The key for protecting the integrity of RRC signaling;
[0339] 2. Secret key for protecting the integrity of user-plane data;
[0340] 3. Upper-level key parameters, where the upper-level key parameters are used to generate new integrity protection keys.
[0341] In implementation, when the MAC layer obtains the key for integrity protection of the user plane control signaling, it can choose to reuse the key K for integrity protection of the RRC signaling. RRCint , or the MAC layer reuses the key K for integrity protection of user plane data Upint , or the MAC layer generates a new key based on the upper layer key parameters (such as KgNB and / or NH (Next Hop)). Among them, the MAC layer generates a new key based on the upper layer key parameters by inputting the upper layer key and a separate algorithm ID (Alg-ID) into the KDF (Key derivation Function) to obtain the key K MACint .
[0342] In this embodiment, the MAC layer can directly reuse the key by obtaining the key used to protect the integrity of RRC signaling and user plane data, or generate a new encryption key based on the upper-level key parameters, thereby effectively protecting the security of user plane control signaling and ensuring the reliability and confidentiality of communications.
[0343] In an example embodiment, as shown in FIGS. 12a to 12c, for the three ways of obtaining the encryption key and / or the integrity protection key, the application gives the hierarchical relationship of key obtaining in combination with the specific 5G control plane protocol stack, and the specific processing procedure of obtaining the encryption key and / or the integrity protection key in step 1001 includes any of the following steps:
[0344] Step 1201a, the PDCP layer informs the MAC layer of the encryption key and / or the integrity protection key.
[0345] In implementation, the PDCP layer of the sending end informs the MAC layer of the corresponding encryption key and / or the integrity protection key, which is especially suitable for the key reuse scenario. For example, for the scenario that the PDCP layer and the MAC layer are located in different network entities, such as the scenario that the PDCP layer is located in the CU (Central Unit) and the MAC layer is located in the DU (Distributed Unit) in 5G, the CU where the PDCP layer is located informs the MAC layer of the encryption key and / or the integrity protection key through the interface with the DU, specifically the F1 interface.
[0346] Step 1201b, the RRC layer informs the MAC layer of the encryption key and / or the integrity protection key, or informs the MAC layer of the input parameters of the derived encryption key and / or the integrity protection key through the RRC layer.
[0347] In implementation, the RRC layer of the sending end informs the MAC layer of the corresponding encryption key and / or the integrity protection key or the input parameters of the derived encryption key and / or the integrity protection key. For the case that the RRC and the MAC layer are located in different network entities, such as the scenario that the RRC layer is located in the CU and the MAC layer is located in the DU in 5G, the CU where the RRC layer is located informs the MAC layer of the encryption key and / or the integrity protection key through the interface with the DU, specifically the F1 interface. Or, the CU where the RRC layer is located informs the MAC layer of the input parameters of the derived encryption key and / or the integrity protection key through the F1 interface, such as KgNB, NH, and NCC (Next Hop Chaining Counter).
[0348] Step 1201c, the encryption key and / or the integrity protection key is derived based on the upper key parameter of the entity where the MAC layer is located or based on the upper key parameter obtained from the core network.
[0349] In implementation, the entity where the MAC layer is located (such as the DU) can derive the encryption key and / or the integrity protection key according to the upper key parameter, such as the known KgNB, or the upper key parameter obtained from the core network.
[0350] In the embodiment, the MAC layer is informed of the key for encryption and / or integrity protection by each high layer of the MAC layer. Alternatively, a new encryption key is generated based on the upper key parameter, thereby effectively protecting the security of the user plane control signaling and ensuring the reliability and confidentiality of the communication.
[0351] In one example embodiment, in the case where the sending end is a base station, the user plane control signaling is downlink user plane control signaling; in the case where the sending end is a terminal, the user plane control signaling is uplink user plane control signaling.
[0352] In implementation, the sending end and the receiving end in the communication system can be a base station and a terminal respectively, and the MAC layer of the sending end encrypts and / or performs integrity protection on the user plane control signaling, and the MAC layer of the receiving end performs corresponding decryption and / or integrity verification. Therefore, in the case where the sending end is a base station, the user plane control signaling sent by the base station to the terminal is encrypted downlink user plane control signaling. In the case where the sending end is a terminal, the user plane control signaling sent by the terminal to the base station is encrypted uplink user plane control signaling.
[0353] When the sending end is a base station, the MAC layer of the base station can perform corresponding encryption and / or integrity protection operation. When the sending end is a terminal, the MAC layer of the terminal can perform corresponding encryption and / or integrity protection operation. The embodiments of the application will not be described in more detail.
[0354] Optionally, when the sending end is a terminal and the receiving end is also a terminal, i.e., the sidelink between terminals can adopt a similar process as between the base station and the terminal, therefore, the embodiments of the application will not be described in more detail herein.
[0355] In the embodiment, the security and integrity of the user plane control signaling in the transmission process are ensured. Through the encryption and / or integrity of the user plane control signaling, the signaling can be prevented from being stolen or tampered, thereby ensuring the reliability and security of the communication.
[0356] In one example embodiment, in the case where the sending end is a base station, before step 501, the method further comprises:
[0357] sending a radio resource control (RRC) signaling to the terminal.
[0358] The RRC signaling contains indication information on whether the user plane control signaling is encrypted and / or integrity protected.
[0359] In implementation, when the sending end is a base station, the base station sends the RRC signaling to the terminal, configures whether the local user plane control signaling is encrypted and / or integrity protected through the RRC signaling, and the base station also notifies the terminal side through the RRC signaling to determine whether the user plane control signaling is encrypted and / or integrity protected.
[0360] In the embodiment, the base station configures whether the user plane control signaling is encrypted and / or integrity protected through the RRC signaling, thereby explicitly determining the user plane control signaling that needs to be encrypted and / or integrity protected.
[0361] In an example embodiment, the indication information carried in the RRC signaling includes at least one of the indication information of whether the user plane control signaling is encrypted and integrity protected,
[0362] The indication information of whether the user plane control signaling is encrypted includes:
[0363] 1) whether a specific user plane control signaling is encrypted;
[0364] 2) whether all user plane control signaling of the terminal is encrypted;
[0365] 3) any one of whether all contents of the MAC protocol data unit of the MAC layer are encrypted.
[0366] The indication information of whether the user plane control signaling is integrity protected includes:
[0367] 1) whether a specific user plane control signaling is integrity protected;
[0368] 2) whether all user plane control signaling of the terminal is integrity protected;
[0369] 3) any one of whether all contents of the MAC protocol data unit of the MAC layer are integrity protected.
[0370] In the embodiment, the indication information includes the indication of encryption and / or integrity protection of different cases such as specific user plane control signaling, all user plane control signaling, and all contents of the MAC PDU, which can be configured based on service requirements, thereby improving the flexibility of security protection of the user plane control signaling.
[0371] In an example embodiment, the specific processing process of determining whether encryption operation and / or integrity protection is needed in step 501 includes:
[0372] Based on the communication protocol specification, or based on the configuration of the RRC signaling corresponding to the user plane control signaling, it is determined whether the user plane control signaling is encrypted and / or integrity protected.
[0373] In implementation, the MAC layer determines whether to perform encryption operation and / or integrity protection on the user plane control signaling based on the provision of the communication protocol or based on the configuration of the RRC signaling. Specifically, the indication information carried in the RRC signaling disclosed in the above embodiments enables the MAC layer to explicitly determine whether to perform encryption operation and / or integrity protection on the user plane control signaling, and specifically, on which user plane control signaling to perform encryption operation and / or integrity protection, and on which user plane control signaling not to perform encryption operation and / or integrity protection. In the following embodiments, specific examples of explicitly determining which user plane control signaling needs to perform encryption operation and / or integrity protection based on the communication protocol or based on the configuration of the RRC signaling will be given, and will not be described in detail here.
[0374] In the present embodiment, the MAC layer determines whether to perform encryption operation and / or integrity protection on the user plane control signaling based on the provision of the communication protocol or the configuration of the RRC signaling, to ensure the security and integrity of the user plane control signaling that needs to be secured during transmission.
[0375] In one exemplary embodiment, as shown in FIGS. 13a-13f, based on the provision of the communication protocol or based on the configuration of the RRC signaling corresponding to the user plane control signaling, the specific processing procedure of determining whether to perform encryption operation and / or integrity protection on the user plane control signaling includes any of the following steps:
[0376] Step 1301a, adding indication information of performing encryption operation and / or integrity protection on specific user plane control signaling in the RRC signaling of configuring specific user plane control signaling related parameters by the network side.
[0377] In implementation, the sending end can configure encryption operation and integrity protection independently. Specifically, in the RRC signaling of configuring specific user plane control signaling (such as BSR (Buffer Status Report) reporting) related parameters, the network side adds an indication of whether to perform encryption and / or integrity protection on the user plane control signaling.
[0378] Or, step 1301b, configuring the terminal to perform encryption operation and / or integrity protection on all user plane control signaling by the RRC signaling sent by the network side.
[0379] In implementation, the RRC signaling sent by the network side is used to configure all user plane control signaling of the corresponding terminal, to achieve encryption and / or integrity protection on all user plane control signaling.
[0380] Optionally, all user plane control signaling corresponding to the terminal can be configured separately or uniformly in uplink and downlink, and the embodiments of the present application do not limit this.
[0381] Alternatively, step 1301c, the network side configures the terminal to perform encryption operation and / or integrity protection at the MAC layer.
[0382] In implementation, the network side configures the corresponding terminal to perform encryption and / or integrity protection at the overall MAC layer. The overall MAC layer includes all contents of the MAC layer, wherein the uplink and downlink of the user plane control signaling can be configured separately or uniformly.
[0383] Alternatively, step 1301d, all user plane control signaling is encrypted and / or integrity protected according to the communication protocol.
[0384] Alternatively, step 1301e, the communication protocol specifies that specific user plane control signaling is encrypted and / or integrity protected.
[0385] Alternatively, step 1301f, the communication protocol specifies that specific MAC layer (or MAC entity) is encrypted and / or integrity protected.
[0386] In implementation, similarly, whether the user plane control signaling is encrypted and / or integrity protected is also divided into three cases according to the communication protocol, that is, all user plane control signaling corresponding to the terminal, specific user plane control signaling (such as BSR reporting), or specific MAC layer (or MAC entity). The present application does not limit which user plane control signaling is encrypted and / or integrity protected.
[0387] In the present embodiment, the RRC signaling configuration or the communication protocol is used to realize the configuration of whether the user plane control signaling is encrypted and / or integrity protected, so as to ensure the security and integrity of the user plane control signaling that needs to be secured during transmission.
[0388] In one exemplary embodiment, as shown in FIG. 14, a signaling security guarantee method is provided, which is applied to the receiving end 200 in FIG. 1 as an example for illustration, including the following steps 1401 to 1403. Among them:
[0389] Step 1401, receiving user plane control signaling, determining whether decryption operation and / or integrity protection verification is needed.
[0390] In implementation, the receiving end receives the user plane control signaling sent by the sending end, and determines whether decryption operation and / or integrity protection verification is needed for the user plane control signaling. Specifically, the MAC layer of the receiving end can determine whether decryption operation and / or integrity protection verification is needed based on the configuration of the network side RRC signaling or the communication protocol, which will be described in detail in subsequent embodiments and will not be described here.
[0391] Step 1402, when decryption operation is needed, the user plane control signaling is decrypted.
[0392] In implementation, when decryption operation is needed, the MAC layer of the receiving end decrypts the user plane control signaling.
[0393] Optionally, the MAC layer can perform different MAC PDU granularity decryption operations on the user plane control signaling corresponding to different MAC PDU granularity encryption methods. Three decryption methods will be provided in the subsequent embodiments of the present application as examples of decrypting the user plane control signaling. The MAC layer can select any one of the three decryption methods to decrypt the user plane control signaling, which will not be described here.
[0394] Step 1403, when integrity protection verification is needed, the user plane control signaling is subjected to integrity protection verification.
[0395] In implementation, when integrity protection verification is needed, the MAC layer of the receiving end performs integrity protection verification on the user plane control signaling.
[0396] Optionally, the MAC layer can perform different MAC PDU granularity integrity protection verification on the user plane control signaling corresponding to different MAC PDU granularity integrity protection methods. Four integrity protection verification methods will be provided in the subsequent embodiments of the present application as examples of integrity protection verification of the user plane control signaling. The MAC layer can select any one of the four integrity protection verification methods to perform integrity protection verification on the user plane control signaling, which will not be described here.
[0397] In the above signaling security guarantee method, the MAC layer of the sending end encrypts and / or performs integrity protection on the user plane control signaling, so that when the receiving end receives the user plane control signaling, it first determines whether decryption operation and / or integrity protection verification is needed, and if so, decrypts and / or performs integrity protection verification on the user plane control signaling, thereby ensuring the security of the user plane control signaling, avoiding malicious attacks and interference by fake base stations or malicious terminals, and ensuring the stability of the communication system.
[0398] In an exemplary embodiment, as shown in FIGS. 15a to 15c, corresponding to three different encryption modes of the sending end user plane control signaling, the following three decryption modes are provided, and the MAC layer can use any one of the following steps 1501 to 1503 to decrypt the user plane control signaling. Among them:
[0399] Step 1501a, determine whether the MAC subPDU corresponding to the MAC subheader is encrypted according to the user plane control signaling type indicated in the MAC subheader or the indication information of the user plane control signaling carried in the MAC subheader, and decrypt the encrypted MAC subPDU payload to obtain the user plane control signaling.
[0400] In implementation, the receiving end MAC layer can determine whether the received user plane control signaling MAC subPDU is encrypted according to the user plane control signaling type (such as MAC CE type indication) indicated in the MAC subheader, or the receiving end MAC layer determines whether the corresponding MAC subPDU is encrypted according to the encryption indication information of the user plane control signaling carried in the MAC subheader. If encrypted, the receiving end MAC layer decrypts the encrypted MAC subPDU payload, and if decryption is successful, the decrypted user plane control signaling is obtained. Further, the user plane control signaling can be applied, otherwise, the user plane control signaling or the entire MAC PDU is discarded.
[0401] Or, step 1501b, determine whether the MAC PDU generated by the MAC layer is encrypted according to the user plane control signaling type indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, and decrypt the encrypted MAC PDU to obtain the user plane control signaling.
[0402] In implementation, the receiving end MAC layer can determine whether the corresponding MAC PDU is encrypted according to the user plane control signaling type (such as MAC CE type indication) indicated in the first MAC subheader, or the receiving end MAC layer determines whether the corresponding MAC PDU is encrypted according to the encryption indication information of the user plane control signaling carried in the first MAC subheader. If encrypted, the receiving end MAC layer decrypts the encrypted MAC PDU payload, and if decryption is successful, the decrypted user plane control signaling is obtained, and the user plane control signaling in the MAC PDU can be applied, otherwise, the MAC PDU is discarded.
[0403] Specifically, in this scenario, the receiving end cannot parse the subsequent MAC subPDU before the decryption operation on the payload part of the MAC PDU is completed, thereby ensuring the security of the user plane control signaling.
[0404] Alternatively, in step 1501c, the user plane control signaling type indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader is used to determine whether the half-MAC PDU is encrypted, and the encrypted half-MAC PDU is decrypted to obtain the user plane control signaling.
[0405] In implementation, the MAC layer of the receiving end identifies the MAC subheader, determines whether the remaining part of the half-MAC PDU is encrypted according to the encryption indication information of the user plane control signaling carried in the first MAC subheader of the half-MAC PDU, and if encrypted, the MAC layer of the receiving end decrypts the encrypted half-MAC PDU. If the decryption is successful, the decrypted user plane control signaling is obtained, and the user plane control signaling in the half-MAC PDU is applied, otherwise, the half-MAC PDU or the entire MAC PDU is discarded.
[0406] Specifically, in this scenario, the receiving end can normally receive data before the decryption of the half-MAC PDU is completed, and the user plane control signaling part needs to be decrypted uniformly.
[0407] In this embodiment, three different decryption methods of user plane control signaling are provided corresponding to three different encryption methods, and the MAC layer of the receiving end can select any one of the methods to decrypt the user plane control signaling based on actual application requirements, thereby realizing the transmission and acquisition of secure user plane control signaling. The content of the user plane control signaling is effectively prevented from being stolen or tampered with, and the attack resistance of the communication system is improved.
[0408] In an exemplary embodiment, as shown in FIGS. 16a-16d, corresponding to four different integrity protection methods of the user plane control signaling of the sending end, the following four integrity protection verification methods are provided. When the MAC layer performs integrity protection verification on the user plane control signaling, any one of the following four methods corresponding to steps 1601-1604 can be used. Among them:
[0409] Step 1601a, determine whether the MAC subPDU corresponding to the MAC subheader is integrity protected by the type of user plane control signaling indicated in the MAC subheader or the indication information of the user plane control signaling carried in the MAC subheader, and perform integrity protection verification on the payload part of the integrity protected MAC subPDU to generate X-MAC.
[0410] In implementation, the receiving end MAC layer can determine whether the corresponding MAC subPDU is integrity protected by the type of user plane control signaling (such as MAC CE type indication) indicated in the MAC subheader, or the receiving end MAC layer determines whether the corresponding MAC subPDU is integrity protected according to the integrity protection indication information carried in the MAC subheader. When it is determined that the corresponding MAC subPDU is integrity protected, i.e. the payload part contains MAC-I, the receiving end analyzes the payload part of the MAC subPDU and performs integrity protection verification on the part excluding MAC-I to generate X-MAC (an extended message authentication code). Then, the receiving end MAC layer compares X-MAC with MAC-I, and if they are the same, the integrity protection verification is successful, otherwise, the integrity protection verification fails.
[0411] Or, step 1601b, determine whether the MAC PDU is integrity protected by the type of user plane control signaling indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, and perform integrity protection verification on the integrity protected MAC PDU to generate X-MAC.
[0412] In implementation, the receiving end can determine whether the corresponding MAC PDU is integrity protected by the type of user plane control signaling (such as MAC CE type indication) indicated in the first MAC subheader, or the receiving end MAC layer determines whether the corresponding MAC PDU is integrity protected according to the integrity protection indication information carried in the first MAC subheader. When it is determined that the corresponding MAC PDU is integrity protected, the receiving end MAC layer performs corresponding integrity protection verification. If the integrity protection verification is successful, the user plane control signaling in the MAC PDU is applied, and if the integrity protection verification fails, the MAC PDU is discarded.
[0413] Among them, the process of the receiving end MAC layer performing corresponding integrity protection verification is also to generate X-MAC corresponding to the MAC PDU, and then compare it with MAC-I carried in the payload part of the MAC PDU. If they are the same, the integrity protection verification is successful, otherwise, the integrity protection verification fails.
[0414] Or, step 1601c, integrity verification is performed on the part of the MAC PDU except the MAC-I, and X-MAC is generated.
[0415] In implementation, when the MAC layer performs integrity protection on all MAC sub-headers and payload in generating the MAC PDU, the receiving end performs integrity protection verification on the part of the MAC PDU except the MAC-I, and generates X-MAC. X-MAC is compared with the MAC-I. If they are the same, the integrity protection verification is successful, and the user plane control signaling in the MAC PDU is applied. Otherwise, the integrity protection verification is considered to fail, and the MAC PDU is discarded.
[0416] Or, step 1601d, the user plane control signaling type indicated in the first MAC sub-header or the indication information of the user plane control signaling carried in the first MAC sub-header is used to determine whether the half-MAC PDU is integrity protected, and integrity protection verification is performed on the integrity protected half-MAC PDU to generate X-MAC.
[0417] In implementation, the receiving end identifies the half-MAC protocol data unit (half-MAC PDU) containing the user plane control signaling. The user plane control signaling type indicated in the identified first MAC sub-header or the indication information of the user plane control signaling carried in the first MAC sub-header is used by the receiving end to determine whether the half-MAC PDU is integrity protected. If the half-MAC PDU is integrity protected, the receiving end performs integrity protection verification on the part except the first MAC sub-header and the MAC-I to generate X-MAC. Then, the receiving end compares X-MAC with the MAC-I. If they are the same, the integrity protection verification is successful, and the user plane control signaling in the MAC PDU is applied. Otherwise, the integrity protection verification is considered to fail, and the half-MAC PDU or the entire MAC PDU is discarded.
[0418] In this embodiment, four different integrity protection verification methods of the user plane control signaling are provided corresponding to four different integrity protection methods. Any one of the methods can be selected to perform integrity protection verification on the user plane control signaling based on actual application requirements, so as to realize the transmission and acquisition of safe user plane control signaling. The content of the user plane control signaling is effectively prevented from being stolen or tampered, and the attack resistance of the communication system is improved.
[0419] In an exemplary embodiment, as shown in FIG. 17, after step 1402, the method further includes:
[0420] Step 1701, if the decryption is successful and / or the integrity protection verification is successful, the user plane control signaling is applied.
[0421] In implementation, when the real receiving end successfully decrypts and / or integrity protects the user plane control signaling, the receiving end can apply the user plane control signaling, and realize the secure transmission of the user plane control signaling.
[0422] In step 1702, if the decryption and / or integrity protection fails, the MAC layer informs the corresponding high function layer.
[0423] In implementation, if the decryption and / or integrity protection fails, it indicates that the current user plane control signaling cannot be applied, and the MAC PDU or half-MAC PDU carrying the user plane control signaling is discarded. In addition, the receiving end informs the MAC layer of the corresponding high function layer, such as the RRC layer. Alternatively, when the receiving end is a terminal, the MAC layer of the receiving end can organize the integrity protection failure information into air interface transmission signaling and send it to the base station.
[0424] In the embodiment, the receiving end performs different processing methods on the user plane control signaling according to different decryption and / or integrity protection verification results of the user plane control signaling, realizes reasonable detection and effective utilization of the user plane control signaling, and improves the reliability of the communication system.
[0425] In an exemplary embodiment, as shown in FIG. 18, the receiving end also needs to use a secret key when decrypting and / or integrity protecting the user plane control signaling. The method of obtaining the secret key is similar to the method of obtaining the secret key by the sending end. Specifically, the method further includes:
[0426] In step 1801, the MAC layer obtains the encrypted secret key and / or the integrity protected secret key, or obtains the encrypted secret key parameter and / or the integrity protected secret key parameter.
[0427] The secret key parameter is used to derive the secret key.
[0428] In implementation, the MAC layer of the receiving end can reuse the secret key used for encrypting the RRC signaling or the user plane data and / or integrity protection. Therefore, the MAC layer directly obtains the encrypted secret key and / or the integrity protected secret key. Alternatively, the MAC layer can obtain the encrypted secret key parameter and / or the integrity protected secret key parameter, and derive the secret key from the secret key parameter. The encrypted secret key is the same as the decrypted secret key, and the integrity protected secret key is the same as the integrity protection verification secret key.
[0429] In step 1802, the input parameters of encryption and / or integrity protection are determined.
[0430] In implementation, the receiving end also determines the corresponding encrypted input parameter and / or the integrity-protected input parameter as the necessary condition for decryption and / or integrity protection verification. Specifically, when decrypting and / or verifying the integrity protection of the user plane control signaling, the receiving end needs the input parameter to parse the encrypted data or the message authentication code for integrity protection verification.
[0431] In the embodiment, the receiving end prepares for decryption or integrity protection verification of the user plane control signaling by directly obtaining or deriving the secret key, so as to ensure the information security of the user plane control signaling in the communication system.
[0432] In an exemplary embodiment, as shown in FIG. 19, the receiving end also needs to determine the adjusted input parameter corresponding to the adjusted input parameter of the sending end when encrypting and / or integrity protecting the user plane control signaling, and specifically, the input parameter includes the bearer number and the counter. The method further includes:
[0433] In step 1901, the value of the bearer number is determined based on the communication protocol or is configured by the network side when configuring the encryption operation and / or integrity protection of the user plane control signaling.
[0434] In implementation, for the bearer number BEARER, the MAC layer of the receiving end can set the value of BEARER specified by the communication protocol as the value of BEARER for the user plane control signaling, or the MAC layer of the receiving end configures the corresponding BEARER value when the network side configures the encryption / integrity protection function of the user plane control signaling.
[0435] In step 1902, the value of the counter is specified based on the communication protocol, is configured by the network side when configuring the encryption operation and / or integrity protection of the user plane control signaling, or is added in the MAC subheader by the network side when configuring the user plane control signaling that needs to be encrypted / integrity protected.
[0436] In implementation, for the configuration of the value of the counter COUNT, the MAC layer of the receiving end can set the value of the counter specified by the communication protocol as the value of COUNT for the user plane control signaling, or the network side configures the corresponding value of COUNT when configuring the encryption operation and / or integrity protection function of the user plane control signaling, or the network side adds the value of COUNT in the MAC subheader when configuring the user plane control signaling that needs to be encrypted / integrity protected. Similar to the configuration process of the sending end, since the configuration process of the input parameter has been described in detail in the sending end, and the configuration principle of the input parameter is the same in the sending end and the receiving end, the embodiment of the present application will not be described here.
[0437] In this embodiment, when ensuring the security of user plane control signaling, the receiving end also needs to adjust the input parameters accordingly to perform decryption operations and / or integrity protection verification based on the adjusted input parameters, thereby achieving accurate parsing of user plane control signaling in the communication system.
[0438] In an exemplary embodiment, the encryption key includes any of the following:
[0439] 1. The key used to encrypt RRC signaling;
[0440] 2. The secret key for encrypting user-plane data;
[0441] 3. Upper-level secret key parameters, where the upper-level secret key parameters are used to generate new encryption keys.
[0442] In implementation, when the MAC layer of the receiving end obtains the key for encrypting the user plane control signaling, it can choose to reuse the key K used to encrypt the RRC signaling. RRCenc , or reuse the secret key K for encrypting user plane data Upenc , or the MAC layer generates a new key based on the upper key parameters (such as KgNB and / or NH (Next Hop)). Among them, the MAC layer of the receiving end generates a new key based on the upper key parameters by inputting the upper key and a separate algorithm ID (Alg-ID) into the KDF (Key derivation Function) to obtain the key K MACenc .
[0443] In this embodiment, the MAC layer at the receiving end can directly reuse the encryption key by obtaining the encryption key for RRC signaling and user plane data. Alternatively, it can generate a new encryption key based on the upper-level key parameters, thereby accurately parsing the user plane control signaling and ensuring the reliability and confidentiality of the user plane control signaling.
[0444] In an exemplary embodiment, the integrity protection key includes any of the following:
[0445] 1. The key for protecting the integrity of RRC signaling;
[0446] 2. Secret key for protecting the integrity of user-plane data;
[0447] 3. Upper-level key parameters, where the upper-level key parameters are used to generate new integrity protection keys.
[0448] In implementation, when the MAC layer of the receiving end obtains the key for integrity protection of the user plane control signaling, it can choose to reuse the key K for integrity protection of the RRC signaling. RRCint , or reuse the secret key K for integrity protection of user plane dataUpint Alternatively, the MAC layer generates a new key based on the upper key parameter (such as KgNB and / or NH (Next Hop)). Wherein, the new key is generated based on the upper key and a separate algorithm ID (Alg-ID) input into the KDF (Key derivation Function), and the key K is obtained MACint .
[0449] In this embodiment, the MAC layer of the receiving end can achieve direct reuse of the key by obtaining the key for integrity protection of RRC signaling and user plane data. Alternatively, the MAC layer of the receiving end generates a new encryption key based on the upper key parameter, so as to accurately verify whether the user plane control signaling is tampered with, and ensure the reliability and confidentiality of the user plane control signaling.
[0450] In one example embodiment, as shown in FIGS. 20a-20c, the process of obtaining the key by the receiving end is similar to the process of obtaining the key by the sending end. The transmission process of the key in the 5G control plane protocol stack by the receiving end is given in this application, that is, the specific processing process of step 1801 includes any of the following steps:
[0451] Step 2001a, the PDCP layer informs the MAC layer of the encryption key and / or the integrity protection key. Alternatively,
[0452] Step 2001b, the RRC layer informs the MAC layer of the encryption key and / or the integrity protection key. Alternatively, the input parameters of the derived encryption and / or integrity protection key are informed to the MAC layer through the RRC layer. Alternatively,
[0453] Step 2001c, the encryption key and / or the integrity protection key is derived based on the upper key parameter of the entity where the MAC layer is located or based on the upper key parameter obtained from the core network.
[0454] In implementation, the receiving end can obtain the key or key parameter for encryption and / or integrity protection of RRC signaling and user plane data through the high layer (such as the PDCP layer, the RRC layer) of the MAC layer informing the MAC layer. Alternatively, the MAC layer of the receiving end directly derives the required key based on the local upper key parameter or the upper key parameter obtained from the core network. The specific process is similar to the process of obtaining the key by the sending end, which has been described in detail in steps 1201-1203 of the embodiment, and will not be repeated here. As known, the encryption key is the same as the decryption key and can be used for decryption, and the integrity protection key is the same as the integrity protection verification key and can be used for integrity protection verification.
[0455] In the embodiment, the MAC layer of the receiving end is informed of the encryption and / or integrity protection key by the upper layer. Alternatively, the MAC layer of the receiving end generates a new encryption key based on the upper key parameter, thereby preparing for decryption and integrity protection verification of the user plane control signaling, ensuring effective parsing of the user plane control signaling, and improving the reliability of the communication system.
[0456] In an example embodiment, in the case where the receiving end is a base station, the user plane control signaling is uplink user plane control signaling; in the case where the receiving end is a terminal, the user plane control signaling is downlink user plane control signaling.
[0457] In implementation, in the case where the receiving end is a base station, the user plane control signaling is sent from the terminal to the base station, and at this time, the user plane control signaling is uplink user plane control signaling. In the case where the receiving end is a terminal, the user plane control signaling, which is downlink user plane control signaling, can be sent from the terminal (terminal-to-terminal sidelink link) or from the base station to the terminal.
[0458] Therefore, when the receiving end is a base station, the MAC layer of the base station can perform corresponding decryption and / or integrity protection verification operations. When the receiving end is a terminal, the MAC layer of the terminal can perform corresponding decryption and / or integrity protection verification operations. The embodiments of the application will not be described in more detail.
[0459] In the embodiment, whether the user plane control signaling is uplink user plane control signaling or downlink user plane control signaling, the encryption and / or integrity protection of the sending end can ensure the security and integrity of the user plane control signaling in the transmission process. The encryption and / or integrity key of the user plane control signaling can prevent the signaling from being stolen or tampered with, thereby ensuring the reliability and security of the communication.
[0460] In an example embodiment, in the case where the receiving end is a terminal, before step 1401, the method further includes:
[0461] Receiving radio resource control (RRC) signaling sent by the base station.
[0462] The RRC signaling contains indication information about whether the user plane control signaling is encrypted and / or integrity protected.
[0463] In implementation, in the case where the receiving end is a terminal, the terminal receives the RRC signaling sent by the base station, and the RRC signaling is used to realize the interaction between the base station and the terminal, and to inform the terminal whether the received user plane control signaling has been encrypted and / or integrity protected.
[0464] In the embodiment, whether the user plane control signaling is encrypted and / or integrity protected is configured through RRC signaling, so that whether the user plane control signaling needs to be decrypted and / or integrity protected is determined.
[0465] In an example embodiment, the specific process of step 1401 includes:
[0466] Based on the communication protocol or the configuration of the RRC signaling, whether the user plane control signaling needs to be decrypted and / or integrity protected is determined.
[0467] In implementation, for the receiving end, before processing the user plane control signaling, whether the user plane control signaling needs to be decrypted and / or integrity protected is also determined, so that, corresponding to the processing operation of the sending end, the receiving end determines whether the user plane control signaling needs to be decrypted and / or integrity protected based on the communication protocol or the configuration of the RRC signaling.
[0468] In the embodiment, whether the user plane control signaling needs to be decrypted and / or integrity protected is determined based on the communication protocol or the configuration of the RRC signaling, so that the user plane control signaling is accurately parsed, and the information security of the user plane control signaling is ensured.
[0469] In an example embodiment, as shown in FIG. 21, an example flow of the signaling security guarantee method is given, in which the sending end is a base station and the receiving end is a terminal, including:
[0470] Step 2101, the base station sends RRC signaling to the terminal to configure MAC layer encryption.
[0471] Step 2102, the terminal receives the RRC signaling sent by the base station and determines the MAC layer encryption configuration.
[0472] Step 2103, the MAC layer of the base station obtains the encrypted key or derives the key from the key parameters.
[0473] Step 2104, the MAC layer of the base station determines whether encryption and / or integrity protection is needed. When encryption and / or integrity protection is needed, a preset encryption and / or integrity protection method is used to guarantee the signaling security of the user plane control signaling.
[0474] Step 2105, the terminal receives the user plane control signaling.
[0475] Step 2106, the encrypted key is obtained or the key is derived from the key parameters, and whether decryption and / or integrity protection verification is needed is determined.
[0476] Step 2107, when decryption and / or integrity protection verification is needed, the user plane control signaling is decrypted and / or integrity verified by using a preset decryption mode and / or integrity protection verification mode.
[0477] It should be understood that, although each step in the flowchart involved in each embodiment as described above is shown in sequence according to the arrow, these steps are not necessarily performed in the order indicated by the arrow. Unless otherwise specified herein, there is no strict order limitation for the performance of these steps, and these steps can be performed in other orders. Moreover, at least part of the steps in the flowchart involved in each embodiment as described above can include multiple steps or multiple stages, which are not necessarily performed at the same time, but can be performed at different times, and the order of performance of these steps or stages is not necessarily sequential, but can be performed alternately or alternately with at least part of other steps or steps or stages in other steps.
[0478] Based on the same inventive concept, the embodiments of the present application also provide a signaling security guarantee device for implementing the above-mentioned signaling security guarantee method. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme described in the above method, so the specific limitations in one or more signaling security guarantee device embodiments provided below can refer to the limitations of the signaling security guarantee method described above, which will not be repeated here.
[0479] In an exemplary embodiment, as shown in FIG. 22, a signaling security guarantee device 2200 is provided, which is applied to a sending end and includes a judgment module 2201, an encryption module 2202 and an integrity protection module 2203, wherein:
[0480] The judgment module 2201 is configured to determine whether encryption operation and / or integrity protection is needed.
[0481] The encryption module 2202 is configured to perform encryption operation on the user plane control signaling when encryption operation is needed; and / or,
[0482] The integrity protection module 2203 is configured to perform integrity protection on the user plane control signaling when integrity protection is needed.
[0483] In the embodiments of the present application, the encryption module 2202 is specifically configured to encrypt the part of the MAC subPDU containing the user plane control signaling, except the MAC subheader; or,
[0484] encrypt the part of the MAC PDU containing the user plane control signaling, except the first MAC subheader; or,
[0485] The half-MAC PDU containing user plane control signaling is encrypted except the first MAC subheader.
[0486] In the embodiments of the present application, the MAC PDU includes one or more MAC subPDUs; and the one or more MAC subPDUs containing user plane control signaling in the MAC PDU are organized into a half-MAC PDU.
[0487] In the embodiments of the present application, the integrity protection module 2203 is specifically configured to perform integrity protection on the part of the MAC subPDU containing user plane control signaling except the MAC subheader; or,
[0488] The MAC PDU containing user plane control signaling is integrity protected except the first MAC subheader; or,
[0489] The MAC PDU containing user plane control signaling is integrity protected; or,
[0490] The MAC half-MAC PDU containing user plane control signaling is integrity protected except the first MAC subheader; and the MAC subheader carries indication information of whether the user plane control signaling is integrity protected.
[0491] In the embodiments of the present application, the integrity protection module 2203 is specifically configured to generate a MAC-I after performing integrity protection on the user plane control signaling, and place the MAC-I at the last position of the MAC subPDU subjected to integrity protection, or at the last position of the MAC PDU.
[0492] In the embodiments of the present application, the MAC subheader carries indication information of whether the user plane control signaling is integrity protected.
[0493] In the embodiments of the present application, the apparatus 2200 further includes:
[0494] The obtaining module is configured to obtain, by the MAC layer, a key for encryption and / or a key for integrity protection, or obtain a key parameter for encryption and / or a key parameter for integrity protection; the key parameter is used to derive the key.
[0495] The determining module is configured to determine an input parameter for encryption and / or integrity protection.
[0496] In the embodiments of the present application, the input parameter includes a bearer number and / or a counter, and the apparatus 2200 further includes:
[0497] The first configuration module is configured to determine the value of the bearer number based on a communication protocol, or to configure the value of the bearer number by the network side when configuring the encryption operation and / or the integrity protection of the user plane control signaling.
[0498] The second configuration module is configured to determine the value of the counter based on a communication protocol, or to configure the value of the counter by the network side when configuring the encryption operation and / or the integrity protection of the user plane control signaling, or to add the value of the counter in the MAC subheader by the network side when configuring the user plane control signaling that needs to be encrypted / integrity protected.
[0499] In the embodiments of the present application, the encryption key includes any one of the following:
[0500] The encryption key for RRC signaling;
[0501] The encryption key for user plane data;
[0502] The upper key parameter, wherein the upper key parameter is used to generate a new encryption key.
[0503] In the embodiments of the present application, the integrity protection key includes any one of the following:
[0504] The integrity protection key for RRC signaling;
[0505] The integrity protection key for user plane data;
[0506] The upper key parameter, wherein the upper key parameter is used to generate a new integrity protection key.
[0507] In the embodiments of the present application, the obtaining module is specifically configured to notify the MAC layer of the encryption key and / or the integrity protection key by the PDCP layer; or,
[0508] The RRC layer notifies the MAC layer of the encryption key and / or the integrity protection key; or, the RRC layer notifies the MAC layer of the input parameter of the derived encryption key and / or the integrity protection key; or,
[0509] The encryption key and / or the integrity protection key are derived based on the upper key parameter of the entity where the MAC layer is located or based on the upper key parameter obtained from the core network.
[0510] In the embodiments of the present application, when the sending end is a base station, the user plane control signaling is downlink user plane control signaling.
[0511] When the sending end is a terminal, the user plane control signaling is uplink user plane control signaling.
[0512] In the embodiments of the present application, when the sending end is a base station, the apparatus 2200 further includes:
[0513] The sending module sends radio resource control (RRC) signaling to the terminal, and the RRC signaling contains indication information about whether to perform encryption and / or integrity protection on the user plane control signaling.
[0514] In the embodiments of the present application, the indication information includes any one of whether to perform encryption on specific user plane control signaling, whether to perform encryption on all user plane control signaling of the terminal, and whether to perform encryption on all contents of a MAC protocol data unit of a MAC layer; and / or,
[0515] any one of whether to perform integrity protection on specific user plane control signaling, whether to perform integrity protection on all user plane control signaling of the terminal, and whether to perform integrity protection on all contents of a MAC protocol data unit of a MAC layer.
[0516] In the embodiments of the present application, the determining module 2201 is specifically configured to determine, based on a communication protocol or based on configuration of the RRC signaling, whether to perform encryption and / or integrity protection on the user plane control signaling.
[0517] In the embodiments of the present application, the determining module 2201 is specifically configured to add indication information about performing encryption and / or integrity protection on specific user plane control signaling in RRC signaling in which the network side configures parameters related to the specific user plane control signaling; or,
[0518] the RRC signaling sent by the network side configures the terminal to perform encryption and / or integrity protection on all user plane control signaling; or,
[0519] the network side configures the terminal to perform encryption and / or integrity protection at a MAC layer; or,
[0520] all user plane control signaling is configured to perform encryption and / or integrity protection according to the communication protocol; or,
[0521] the communication protocol specifies that specific user plane control signaling is to be encrypted and / or integrity protected; or,
[0522] the communication protocol specifies that a specific MAC layer (or MAC entity) is to be encrypted and / or integrity protected.
[0523] In one exemplary embodiment, as shown in FIG. 23, a signaling security assurance apparatus 2300 is provided, which is applied to a receiving end and includes a receiving determining module 2301, a decryption module 2302, and a verification module 2303, wherein:
[0524] The receiving determining module 2301 is configured to receive user plane control signaling and determine whether decryption and / or integrity protection verification is needed.
[0525] decrypting the user plane control signaling when a decryption operation is needed; and / or,
[0526] verifying the user plane control signaling when integrity protection verification is needed.
[0527] In the embodiments of the present application, the decryption module 2302 is specifically configured to determine whether the MAC subPDU corresponding to the MAC subheader is encrypted through the user plane control signaling type indicated in the MAC subheader or the indication information of the user plane control signaling carried in the MAC subheader, and decrypt the payload part of the encrypted MAC subPDU to obtain the user plane control signaling; or,
[0528] determine whether the MAC PDU is encrypted through the user plane control signaling type indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, and decrypt the encrypted MAC PDU to obtain the user plane control signaling; or,
[0529] determine whether the half-MAC PDU is encrypted through the user plane control signaling type indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, and decrypt the encrypted half-MAC PDU to obtain the user plane control signaling.
[0530] In the embodiments of the present application, the verification module 2303 is specifically configured to determine whether the MAC subPDU corresponding to the MAC subheader is integrity protected through the user plane control signaling type indicated in the MAC subheader or the indication information of the user plane control signaling carried in the MAC subheader, and perform integrity protection verification on the payload part of the integrity protected MAC subPDU to generate an X-MAC; or,
[0531] determine whether the MAC PDU is integrity protected through the user plane control signaling type indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, and perform integrity protection verification on the integrity protected MAC PDU to generate an X-MAC; or,
[0532] perform integrity verification on the part of the MAC PDU except the MAC-I to generate an X-MAC; or,
[0533] The half-MAC PDU is determined whether to be integrity protected according to the user plane control signaling type indicated in the first MAC subheader or the indication information of the user plane control signaling carried in the first MAC subheader, and integrity protection verification is performed on the half-MAC PDU to generate an X-MAC.
[0534] In the embodiments of the present application, the apparatus 2300 further includes:
[0535] The first decryption module is configured to apply the user plane control signaling if the decryption is successful and / or the integrity protection verification is successful.
[0536] The second decryption module is configured to notify a corresponding high-function layer of the MAC layer if the decryption fails and / or the integrity protection verification fails.
[0537] In the embodiments of the present application, the apparatus 2300 further includes:
[0538] The obtaining module is configured to obtain an encrypted key and / or an integrity protected key by the MAC layer, or obtain an encrypted key parameter and / or an integrity protected key parameter; the key parameter is used to derive the key.
[0539] The determining module is configured to determine an input parameter of encryption and / or integrity protection.
[0540] In the embodiments of the present application, the input parameter includes a bearer number and a counter, and the apparatus 2300 further includes:
[0541] The first configuration module is configured to determine the value of the bearer number based on a communication protocol, or configure the value of the bearer number by a network side when configuring the encryption operation and / or the integrity protection of the user plane control signaling.
[0542] The second configuration module is configured to specify the value of the counter based on a communication protocol, configure the value of the counter by the network side when configuring the encryption operation and / or the integrity protection of the user plane control signaling, or add the value of the counter in the MAC subheader by the network side when configuring the user plane control signaling which needs to be encrypted / integrity protected.
[0543] In the embodiments of the present application, the encrypted key includes any one of the following:
[0544] The key for encrypting the RRC signaling;
[0545] The key for encrypting the user plane data;
[0546] The upper key parameter is used to generate a new encrypted key.
[0547] In the embodiments of the present application, the integrity protected key includes any one of the following:
[0548] a key for RRC signaling integrity protection;
[0549] a key for user plane data integrity protection;
[0550] a superior key parameter, which is used to generate a new key for integrity protection.
[0551] In the embodiments of the present application, the obtaining module is specifically configured to notify the MAC layer of the key for encryption and / or the key for integrity protection by the PDCP layer; or,
[0552] the RRC layer notifies the MAC layer of the key for encryption and / or the key for integrity protection; or, the RRC layer notifies the MAC layer of the input parameter for deriving the key for encryption and / or the key for integrity protection.
[0553] or, the key for encryption and / or the key for integrity protection is derived based on the superior key parameter of the entity where the MAC layer is located or based on the superior key parameter obtained from the core network.
[0554] In one of the embodiments, in the case where the receiving end is a base station, the user plane control signaling is uplink user plane control signaling.
[0555] In the case where the receiving end is a terminal, the user plane control signaling is downlink user plane control signaling.
[0556] In the embodiments of the present application, in the case where the receiving end is a terminal, the apparatus 2300 further includes:
[0557] The receiving module is configured to receive radio resource control (RRC) signaling sent by a base station, wherein the RRC signaling contains indication information about whether to perform encryption and / or integrity protection on user plane control signaling.
[0558] In the embodiments of the present application, the receiving and determining module 2301 is specifically configured to determine whether to perform decryption operation and / or integrity protection verification on the user plane control signaling based on the communication protocol or based on the configuration of the RRC signaling.
[0559] It should be noted that the division of the modules in the embodiments of the present application is illustrative, and is a logical function division. In actual implementation, another division mode can be used. In addition, each functional module in each embodiment of the present application can be integrated in one processing module, or each module can exist physically independently, or two or more modules can be integrated in one module. The integrated module can be realized in the form of hardware or in the form of a software functional unit.
[0560] The integrated module, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a processor-readable storage medium. Based on such an understanding, the technical solutions of the present application, essentially or in other words, the part of the conventional technology that makes a contribution or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in the various embodiments of the present application.
[0561] It should be noted that the above-mentioned device provided by the embodiments of the present application can realize all the method steps achieved by the method embodiments and achieve the same technical effects. Therefore, the same parts and beneficial effects of the method embodiments will not be described in detail.
[0562] The communication device related by the embodiments of the present application can be a terminal device, which can be a device providing voice and / or data connectivity to a user, a handheld device having wireless connection function, or other processing devices connected to a wireless modem, etc. In different systems, the name of the terminal device can also be different, for example, in the 5G system, the terminal device can be called user equipment (UE). The wireless terminal device can be a USB storage device, other personal computer memory devices and a dongle, and can also communicate with one or more core networks (CN) through a radio access network (RAN). The wireless terminal device can be a mobile terminal device, such as a mobile phone (or called "cellular" phone) and a computer with a mobile terminal device, for example, it can be a portable, pocket, handheld, built-in computer or vehicle-mounted mobile device, which exchanges voice and / or data with a radio access network. For example, personal communication service (PCS) phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), personal computers, tablet computers, machine-type communication (MTC) terminal devices, etc. The wireless terminal device can also be called a system, a subscriber unit, a subscriber station, a mobile station, a mobile, a remote station, an access point, a remote terminal, an access terminal, a user terminal, a user agent, a user device, and a wireless access router and modem that meet the limitations of the definition, etc. The embodiments of the present application are not limited.
[0563] Specifically, as shown in FIG. 24, the terminal device includes a transceiver 2410 for receiving and transmitting data under the control of the processor 2400.
[0564] In Figure 24, the bus architecture can include any number of interconnected buses and bridges, specifically, various circuitry linking one or more processors, represented by the processor 2400, and memory, represented by the memory 2420. The bus architecture can also link various other circuitry, such as peripheral devices, voltage regulators, and power management circuitry, which are well known in the art and thus, are not further described herein. The bus interface provides an interface. The transceiver 2410 can be a plurality of elements, i.e., including a transmitter and a receiver, providing a means for communicating with various other apparatus over a transmission medium, including wireless channels, wired channels, optical cables, etc. The user interface 2430 can also be a means for coupling to input and output devices, including, but not limited to, a keypad, a display, a speaker, a microphone, a joystick, etc., for a user of the various user devices.
[0565] The processor 2400 is responsible for managing the bus architecture and general processing, and the memory 2420 can store data used by the processor 2400 in executing operations.
[0566] Optionally, the processor 2400 can be a CPU (Central Processor Unit), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a CPLD (Complex Programmable Logic Device), and the processor 2400 can also adopt a multi-core architecture.
[0567] The processor 2400 is responsible for managing the bus architecture and general processing, and the memory 2420 can store data used by the processor 2400 in executing operations.
[0568] The communication device related to the embodiments of the present application can be a base station, which can include multiple cells serving terminals. According to different application scenarios, the base station can also be referred to as an access point, or can be a device in an access network that communicates with wireless terminal devices through one or more sectors over an air interface, or other names. The network device can be used to exchange received air frames and Internet Protocol (IP) packets as a router between the wireless terminal device and the rest of the access network, which can include an Internet Protocol (IP) communication network. The network device can also coordinate the management of the properties of the air interface. For example, the network device related to the embodiments of the present application can be an evolved network device (eNB or e-NodeB) in a long term evolution (LTE) system, a 5G base station (gNB) in a 5G network architecture, etc., and can also be a home evolved base station (HeNB), a relay node, a femto, a pico, a network test device, etc., which is not limited in the embodiments of the present application. In some network structures, the network device can include a centralized unit (CU) node and a distributed unit (DU) node, and the centralized unit and the distributed unit can also be arranged geographically apart.
[0569] For the base station side, as shown in FIG. 25, it includes a transceiver 2510 for receiving and transmitting data under the control of a processor 2500.
[0570] In FIG. 25, the bus architecture can include any number of interconnected buses and bridges, which link various circuits together, including one or more processors represented by the processor 2500 and the memory represented by the memory 2520. The bus architecture can also link various other circuits such as peripheral devices, voltage stabilizers and power management circuits, which are well known in the art, and therefore, will not be further described herein. The bus interface provides an interface. The transceiver 2510 can be multiple elements, i.e., including a transmitter and a receiver, which provide units for communicating with various other devices over transmission media, including wireless channels, wired channels, optical cables, etc. The processor 2500 is responsible for managing the bus architecture and general processing, and the memory 2520 can store data used by the processor 2500 in performing operations.
[0571] The processor 2500 can be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or a complex programmable logic device (CPLD), and can also take a multi-core architecture.
[0572] In the embodiments of the present application, a computer readable storage medium is provided, which stores a computer program. The computer program is executed by a processor to implement the steps in the above method embodiments.
[0573] In the embodiments of the present application, a computer program product is provided, which includes a computer program. The computer program is executed by a processor to implement the steps in the above method embodiments.
[0574] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage and optical storage) containing computer usable program code.
[0575] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments of each method. Any reference to memory, database or other medium used in each embodiment provided by the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in each embodiment provided by the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in each embodiment provided by the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, etc., without being limited thereto.
[0576] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of each technical feature in the above embodiments are not described, however, as long as the combination of these technical features does not exist, it should be considered as the scope of the present application.
[0577] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent of the present application. It should be pointed out that for ordinary skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A signaling security assurance method, applied to a sending end, comprising: Determine whether encryption and / or integrity protection is required; When encryption is required, encrypt the user plane control signaling; and / or, When integrity protection is required, integrity protection is performed on the user plane control signaling.
2. The method according to claim 1, wherein The encrypting operation on the user plane control signaling includes: Encrypting a portion of a media access control sub-protocol data unit MAC subPDU containing the user plane control signaling, except for a media access control MAC subheader; or Encrypting the MAC protocol data unit (MAC PDU) containing the user plane control signaling except for the first MAC subheader; or The half-MAC protocol data unit (half-MAC PDU) containing the user plane control signaling is encrypted except for the first MAC subheader.
3. The method according to claim 2, wherein: The MAC subheader carries indication information of whether the user plane control signaling is encrypted.
4. The method according to claim 2, wherein: The MAC PDU includes one or more MAC subPDUs; or, One or more MAC subPDUs containing user plane control signaling in the MAC PDU are organized into a half-MAC PDU.
5. The method according to claim 1, wherein The performing an integrity protection operation on the user plane control signaling includes: Performing integrity protection on the MAC subPDU containing the user plane control signaling, excluding the MAC subheader; or, Performing integrity protection on the MAC PDU containing the user plane control signaling except for the first MAC subheader; or, Performing integrity protection on the MAC PDU containing the user plane control signaling; or, The MAC half-MAC PDU containing the user plane control signaling is integrity protected except for the first MAC subheader.
6. The method according to claim 5, wherein: The performing an integrity protection operation on the user plane control signaling includes: After integrity protection is performed on the user plane control signaling, a MAC-I is generated, and the MAC-I is placed at the last position of the integrity-protected MAC subPDU, or at the last position of the MAC PDU; The MAC-I is a message authentication code used for signaling message data integrity.
7. The method according to claim 5, wherein: The MAC subheader carries indication information of whether integrity protection is performed on the user plane control signaling.
8. The method according to claim 1, further comprising: The MAC layer obtains the encryption key and / or the integrity protection key, or obtains the encryption key parameter and / or the integrity protection key parameter; The secret key parameters are used to derive the secret key; Determine input parameters for encryption and / or integrity protection.
9. The method according to claim 8, wherein The input parameters include a bearer number and / or a counter, and the method further includes: Determining the value of the bearer number based on a communication protocol provision, or configuring the value of the bearer number by the network side when configuring the encryption operation and / or integrity protection of the user plane control signaling; The counter value is specified based on the communication protocol, or the network side configures the counter value when configuring the encryption operation and / or integrity protection of the user plane control signaling, or the counter value is added to the MAC subheader.
10. The method according to claim 8, wherein The encryption key includes any of the following: The key used to encrypt RRC signaling; The secret key for encrypting user plane data; The upper-level secret key parameter is used to generate a new encryption key.
11. The method according to claim 8, wherein The integrity protection key includes any of the following: The key for RRC signaling integrity protection; The key for protecting the integrity of user plane data; The upper-level key parameter is used to generate a new integrity protection key.
12. The method according to claim 8, wherein The obtaining of the encryption key and / or the integrity protection key comprises: The PDCP layer notifies the MAC layer of the encryption key and / or integrity protection key; or, The RRC layer notifies the MAC layer of the encryption key and / or integrity protection key; or, the RRC layer notifies the MAC layer of the input parameters of the encryption and / or integrity protection derived key; or, The encryption key and / or the integrity protection key is derived based on the upper key parameter of the entity where the MAC layer is located or based on the upper key parameter obtained from the core network.
13. The method according to claim 1, wherein When the transmitting end is a base station, the user plane control signaling is downlink user plane control signaling; In the case where the transmitting end is a terminal, the user plane control signaling is uplink user plane control signaling.
14. The method according to claim 1, wherein In the case where the transmitting end is a base station, before determining whether encryption operation and / or integrity protection is required, the method further includes: A radio resource control (RRC) signaling is sent to the terminal, where the RRC signaling includes indication information of whether to perform encryption and / or integrity protection on the user plane control signaling.
15. The method according to claim 14, wherein The indication information includes: whether to perform an encryption operation on a specific user plane control signaling, whether to perform an encryption operation on all user plane control signaling of the terminal, and whether to perform an encryption operation on all contents of a MAC protocol data unit of a MAC layer; and / or, Any one of whether to perform integrity protection on specific user plane control signaling, whether to perform integrity protection on all user plane control signaling of the terminal, and whether to perform integrity protection on all contents of the MAC protocol data unit of the MAC layer.
16. The method according to claim 1, 14 or 15, wherein The determining whether encryption operation and / or integrity protection is required includes: Based on the provisions of the communication protocol or the configuration of the RRC signaling, it is determined whether to perform encryption operation and / or integrity protection on the user plane control signaling.
17. The method according to claim 16, wherein The determining, based on a communication protocol provision or a configuration of an RRC signaling, whether to perform an encryption operation and / or integrity protection on the user plane control signaling includes: Adding, in the RRC signaling for configuring parameters related to specific user plane control signaling on the network side, indication information for performing encryption operation and / or integrity protection on the specific user plane control signaling; or Configuring the terminal to perform encryption and / or integrity protection on all user plane control signaling through the RRC signaling sent by the network side; or, By configuring the terminal on the network side to perform encryption operations and / or integrity protection at the MAC layer; or, The communication protocol specifies that all user plane control signaling is encrypted and / or integrity protected; or, Encryption and / or integrity protection is specified for specific user plane control signaling via the communication protocol; or The communication protocol stipulates that a specific MAC layer (or MAC entity) must perform encryption and / or integrity protection.
18. A signaling security assurance method, applied to a receiving end, comprising: Receive user plane control signaling and determine whether decryption operation and / or integrity protection verification is required; When a decryption operation is required, decrypting the user plane control signaling; and / or, When integrity protection verification is required, integrity protection verification is performed on the user plane control signaling.
19. The method according to claim 18, wherein The decrypting operation on the user plane control signaling includes: determining, by using a user plane control signaling type indicated in a media access control (MAC) subheader or indication information of the user plane control signaling carried in the MAC subheader, whether a MAC sub-protocol data unit (MAC subPDU) corresponding to the MAC subheader is encrypted, and performing a decryption operation on a payload portion of the encrypted MAC subPDU to obtain the user plane control signaling; or determining whether a MAC protocol data unit (MAC PDU) is encrypted by using a user plane control signaling type indicated in a first MAC subheader or indication information of the user plane control signaling carried in the first MAC subheader, and performing a decryption operation on the encrypted MAC PDU to obtain the user plane control signaling; or Determine whether the half-MAC protocol data unit half-MAC PDU is encrypted according to the user plane control signaling type indicated in the first MAC subheader, or the indication information of the user plane control signaling carried in the first MAC subheader, and perform a decryption operation on the encrypted half-MAC PDU to obtain the user plane control signaling.
20. The method according to claim 18, wherein The performing integrity protection verification on the user plane control signaling includes: determining whether integrity protection is performed on the MAC subPDU corresponding to the MAC subheader based on the user plane control signaling type indicated in the MAC subheader or the indication information of the user plane control signaling carried in the MAC subheader, and performing integrity protection verification on the payload part of the integrity-protected MAC subPDU to generate an X-MAC; or Determine whether the MAC PDU is integrity protected based on the user plane control signaling type indicated in the first MAC subheader, or the indication information of the user plane control signaling carried in the first MAC subheader, and perform integrity protection verification on the integrity-protected MAC PDU to generate an X-MAC; or Performing integrity verification on the portion of the MAC PDU other than the MAC-I to generate an X-MAC; or Determine whether the half-MAC PDU is integrity protected based on the user plane control signaling type indicated in the first MAC subheader, or the indication information of the user plane control signaling carried in the first MAC subheader, and perform integrity protection verification on the integrity-protected half-MAC PDU to generate an X-MAC.
21. The method according to claim 18, wherein After performing the decryption operation on the user plane control signaling, the method further includes: If decryption is successful and / or integrity protection verification is successful, applying the user plane control signaling; If decryption fails and / or integrity protection verification fails, the higher-function layer corresponding to the MAC layer is notified.
22. The method according to claim 18, wherein The method further comprises: The MAC layer obtains an encryption key and / or an integrity protection key, or obtains encryption key parameters and / or integrity protection key parameters; the key parameters are used to derive a key; Determine input parameters for encryption and / or integrity protection.
23. The method according to claim 22, wherein The input parameters include a bearer number and a counter, and the method further includes: Determining the value of the bearer number based on a communication protocol provision, or configuring the value of the bearer number by the network side when configuring the encryption operation and / or integrity protection of the user plane control signaling; The counter value is specified based on the communication protocol, or the network side configures the counter value when configuring the encryption operation and / or integrity protection of the user plane control signaling, or the network side adds the counter value in the MAC subheader when configuring the user plane control signaling that requires encryption / integrity protection.
24. The method according to claim 22, wherein The encryption key includes any of the following: The key used to encrypt RRC signaling; The secret key for encrypting user plane data; The upper-level secret key parameter is used to generate a new encryption key.
25. The method according to claim 22, wherein The integrity protection key includes any of the following: The key for RRC signaling integrity protection; The key for protecting the integrity of user plane data; The upper-level key parameter is used to generate a new integrity protection key.
26. The method according to claim 22, wherein The obtaining of the encryption key and / or the integrity protection key comprises: The PDCP layer notifies the MAC layer of the encryption key and / or integrity protection key; or, The RRC layer notifies the MAC layer of the encryption key and / or integrity protection key; or, the RRC layer notifies the MAC layer of the input parameters of the encryption and / or integrity protection derived key; or, The encryption key and / or the integrity protection key is derived based on the upper key parameter of the entity where the MAC layer is located or based on the upper key parameter obtained from the core network.
27. The method according to claim 18, wherein When the receiving end is a base station, the user plane control signaling is uplink user plane control signaling; In a case where the receiving end is a terminal, the user plane control signaling is downlink user plane control signaling.
28. The method according to claim 27, wherein In the case where the receiving end is a terminal, before determining whether encryption operation and / or integrity protection is required, the method further includes: A radio resource control (RRC) signaling is received from a base station, where the RRC signaling includes indication information of whether to perform encryption and / or integrity protection on the user plane control signaling.
29. The method of claim 18, 27 or 28, wherein The determining whether a decryption operation and / or integrity protection verification is required includes: Based on the provisions of the communication protocol or the configuration of the RRC signaling, it is determined whether to perform a decryption operation and / or integrity protection verification on the user plane control signaling.
30. A signaling security device, wherein: The device is applied to a transmitting end, and includes: A judgment module, used to determine whether encryption operation and / or integrity protection is required; an encryption module, configured to perform encryption operations on user plane control signaling when encryption operations are required; and / or, The integrity protection module is used to perform integrity protection on the user plane control signaling when integrity protection is required.
31. A signaling security assurance device, applied to a receiving end, comprising: A receiving and determining module is used to receive user plane control signaling and determine whether a decryption operation and / or integrity protection verification is required; a decryption module, configured to perform a decryption operation on the user plane control signaling when a decryption operation is required; and / or, The verification module is used to perform integrity protection verification on the user plane control signaling when integrity protection verification is required.
32. A communication device, used at a transmitting end, comprising a memory, a transceiver, and a processor: memory for storing computer programs; a transceiver, configured to transmit and receive data under the control of the processor; A processor is configured to read the computer program in the memory and perform the following operations: Determine whether encryption and / or integrity protection is required; When encryption is required, encrypting the user plane control signaling; and / or, When integrity protection is required, integrity protection is performed on the user plane control signaling.
33. The communication device according to claim 32, wherein: The encrypting operation on the user plane control signaling includes: Encrypting a portion of a MAC sublayer protocol data unit MAC subPDU containing the user plane control signaling, except for a MAC subheader; or Encrypting the MAC protocol data unit (MAC PDU) containing the user plane control signaling except for the first MAC subheader; or The half-MAC PDU of the MAC layer containing the user plane control signaling is encrypted except for the first MAC subheader.
34. The communication device according to claim 33, wherein The MAC PDU includes one or more MAC subPDUs; or, Organize one or more MAC subPDUs containing the user plane control signaling in the MAC PDU into a half-MAC PDU.
35. The communication device according to claim 32, wherein The performing an integrity protection operation on the user plane control signaling includes: Performing integrity protection on the MAC subPDU containing the user plane control signaling, excluding the MAC subheader; or, Performing integrity protection on the MAC PDU containing the user plane control signaling except for the first MAC subheader; or, Performing integrity protection on the MAC PDU containing the user plane control signaling; or, The MAC half-MAC PDU containing the user plane control signaling is integrity protected except for the first MAC subheader.
36. The communication device according to claim 32, wherein The processor is further configured to: The MAC layer obtains an encryption key and / or an integrity protection key, or obtains encryption key parameters and / or integrity protection key parameters; the key parameters are used to derive a key; Determine input parameters for encryption and / or integrity protection.
37. The communication device according to claim 36, wherein The input parameter includes a bearer number and / or a counter, and the processor is further configured to: Determining the value of the bearer number based on a communication protocol provision, or configuring the value of the bearer number by the network side when configuring the encryption operation and / or integrity protection of the user plane control signaling; The counter value is specified based on the communication protocol, or the network side configures the counter value when configuring the encryption operation and / or integrity protection of the user plane control signaling, or the network side adds the counter value in the MAC subheader when configuring the user plane control signaling that requires encryption / integrity protection.
38. The communication device according to claim 36, wherein The encryption key includes any of the following: The key used to encrypt RRC signaling; The secret key for encrypting user plane data; The upper-level secret key parameter is used to generate a new encryption key.
39. The communication device according to claim 36, wherein The integrity protection key includes any of the following: The key for RRC signaling integrity protection; The key for protecting the integrity of user plane data; The upper-level key parameter is used to generate a new integrity protection key.
40. The communication device according to claim 36, wherein The obtaining of the encryption key and / or the integrity protection key comprises: The PDCP layer notifies the MAC layer of the encryption key and / or integrity protection key; or, The RRC layer notifies the MAC layer of the encryption key and / or integrity protection key; or, the RRC layer notifies the MAC layer of the input parameters of the encryption and / or integrity protection derived key; or, The encryption key and / or the integrity protection key is derived based on the upper key parameter of the entity where the MAC layer is located or based on the upper key parameter obtained from the core network.
41. The communication device according to claim 32, wherein When the transmitting end is a base station, the user plane control signaling is downlink user plane control signaling; In the case where the transmitting end is a terminal, the user plane control signaling is uplink user plane control signaling.
42. The communication device according to claim 32, wherein When the transmitting end is a base station, the processor is further configured to: A radio resource control (RRC) signaling is sent to the terminal, where the RRC signaling includes indication information of whether to perform encryption and / or integrity protection on the user plane control signaling.
43. The communication device according to claim 42, wherein The indication information includes: whether to perform an encryption operation on a specific user plane control signaling, whether to perform an encryption operation on all user plane control signaling of the terminal, and whether to perform an encryption operation on all contents of a MAC protocol data unit of a MAC layer; and / or, Any one of whether to perform integrity protection on specific user plane control signaling, whether to perform integrity protection on all user plane control signaling of the terminal, and whether to perform integrity protection on all contents of the MAC protocol data unit of the MAC layer.
44. The communication device according to claim 32, 42 or 43, wherein: The determining whether encryption operation and / or integrity protection is required includes: Based on the provisions of the communication protocol or the configuration of the RRC signaling, it is determined whether to perform encryption operation and / or integrity protection on the user plane control signaling.
45. The communication device according to claim 44, wherein The determining, based on a communication protocol provision or a configuration of an RRC signaling, whether to perform an encryption operation and / or integrity protection on the user plane control signaling includes: Adding, in the RRC signaling for configuring parameters related to specific user plane control signaling on the network side, indication information for performing encryption operation and / or integrity protection on the specific user plane control signaling; or Configuring the terminal to perform encryption and / or integrity protection on all user plane control signaling through the RRC signaling sent by the network side; or, By configuring the terminal on the network side to perform encryption operations and / or integrity protection at the MAC layer; or, The communication protocol specifies that all user plane control signaling is encrypted and / or integrity protected; or, Encryption and / or integrity protection is specified for specific user plane control signaling via the communication protocol; or The communication protocol stipulates that a specific MAC layer (or MAC entity) must perform encryption and / or integrity protection.
46. A communication device, used at a receiving end, comprising a memory, a transceiver, and a processor: memory for storing computer programs; a transceiver, configured to transmit and receive data under the control of the processor; A processor is configured to read the computer program in the memory and perform the following operations: Receive user plane control signaling and determine whether decryption operation and / or integrity protection verification is required; When a decryption operation is required, decrypting the user plane control signaling; and / or, When integrity protection verification is required, integrity protection verification is performed on the user plane control signaling.
47. The communication device according to claim 46, wherein The decrypting operation on the user plane control signaling includes: determining, based on the user plane control signaling type indicated in the MAC subheader or the indication information of the user plane control signaling carried in the MAC subheader, whether the MAC sublayer protocol data unit MAC subPDU corresponding to the MAC subheader is encrypted, and performing a decryption operation on the payload portion of the encrypted MAC subPDU to obtain the user plane control signaling; or determining whether a MAC protocol data unit (MAC PDU) is encrypted by using a user plane control signaling type indicated in a first MAC subheader or indication information of the user plane control signaling carried in the first MAC subheader, and performing a decryption operation on the encrypted MAC PDU to obtain the user plane control signaling; or Determine whether the half-MAC protocol data unit half-MAC PDU is encrypted according to the user plane control signaling type indicated in the first MAC subheader, or the indication information of the user plane control signaling carried in the first MAC subheader, and perform a decryption operation on the encrypted half-MAC PDU to obtain the user plane control signaling.
48. The communication device according to claim 46, wherein The performing integrity protection verification on the user plane control signaling includes: determining whether integrity protection is performed on the MAC subPDU corresponding to the MAC subheader based on the user plane control signaling type indicated in the MAC subheader or the indication information of the user plane control signaling carried in the MAC subheader, and performing integrity protection verification on the payload part of the integrity-protected MAC subPDU to generate an X-MAC; or Determine whether the MAC PDU is integrity protected based on the user plane control signaling type indicated in the first MAC subheader, or the indication information of the user plane control signaling carried in the first MAC subheader, and perform integrity protection verification on the integrity-protected MAC PDU to generate an X-MAC; or Performing integrity verification on the portion of the MAC PDU other than the MAC-I to generate an X-MAC; or Determine whether the half-MAC PDU is integrity protected based on the user plane control signaling type indicated in the first MAC subheader, or the indication information of the user plane control signaling carried in the first MAC subheader, and perform integrity protection verification on the integrity-protected half-MAC PDU to generate an X-MAC.
49. The communication device according to claim 46, wherein The processor is further configured to: If decryption is successful and / or integrity protection verification is successful, applying the user plane control signaling; If decryption fails and / or integrity protection verification fails, the higher-function layer corresponding to the MAC layer is notified.
50. The communication device of claim 46, wherein The processor is further configured to: The MAC layer obtains an encryption key and / or an integrity protection key, or obtains encryption key parameters and / or integrity protection key parameters; the key parameters are used to derive a key; Determine input parameters for encryption and / or integrity protection.
51. The communication device according to claim 50, wherein The input parameters include a bearer number and a counter, and the processor is further configured to: Determining the value of the bearer number based on a communication protocol provision, or configuring the value of the bearer number by the network side when configuring the encryption operation and / or integrity protection of the user plane control signaling; The counter value is specified based on the communication protocol, or the network side configures the counter value when configuring the encryption operation and / or integrity protection of the user plane control signaling, or the network side adds the counter value in the MAC subheader when configuring the user plane control signaling that requires encryption / integrity protection.
52. The communication device according to claim 50, wherein The encryption key includes any of the following: The key used to encrypt RRC signaling; The secret key for encrypting user plane data; The upper-level secret key parameter is used to generate a new encryption key.
53. The communication device according to claim 50, wherein The integrity protection key includes any of the following: The key for RRC signaling integrity protection; The key for protecting the integrity of user plane data; The upper-level key parameter is used to generate a new integrity protection key.
54. The communication device according to claim 50, wherein The obtaining of the encryption key and / or the integrity protection key comprises: The PDCP layer notifies the MAC layer of the encryption key and / or integrity protection key; or, The RRC layer notifies the MAC layer of the encryption key and / or integrity protection key; or, the RRC layer notifies the MAC layer of the input parameters of the encryption and / or integrity protection derived key; or, The encryption key and / or the integrity protection key is derived based on the upper key parameter of the entity where the MAC layer is located or based on the upper key parameter obtained from the core network.
55. The communication device of claim 46, wherein When the receiving end is a base station, the user plane control signaling is uplink user plane control signaling; In a case where the receiving end is a terminal, the user plane control signaling is downlink user plane control signaling.
56. The communication device according to claim 55, wherein The processor is further configured to: A radio resource control (RRC) signaling is received from a base station, where the RRC signaling includes indication information of whether to perform encryption and / or integrity protection on the user plane control signaling.
57. The communication device according to claim 46, 55 or 56, wherein The determining whether a decryption operation and / or integrity protection verification is required includes: Based on the provisions of the communication protocol or the configuration of the RRC signaling, it is determined whether to perform a decryption operation and / or integrity protection verification on the user plane control signaling.
58. A computer-readable storage medium having a computer program stored thereon, wherein: When the computer program is executed by a processor, the computer program implements the steps of the method according to any one of claims 1 to 29.
59. A computer program product comprising a computer program, wherein When the computer program is executed by a processor, the computer program implements the steps of the method according to any one of claims 1 to 29.
Citation Information
Patent Citations
Safety protection method, device and system
CN109362108A
System and method for dynamic activation and deactivation of user plane integrity in wireless networks
CN110915249A
Communication Method and Related Apparatus
US20190246282A1
Information processing method and device, network entity and storage medium
WO2019137121A1
Communication method and apparatus
WO2023005929A1