Communication method and related apparatus

By acquiring and verifying the characteristic information of the second communication device, the problem of man-in-the-middle attacks in wireless communication networks is solved, achieving efficient communication security and resource conservation.

WO2025223263A1PCT designated stage Publication Date: 2025-10-30HUAWEI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/089136
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-26
Filing Date
2025-04-15
Publication Date
2025-10-30

AI Technical Summary

Technical Problem

In wireless communication networks, existing technologies are insufficient to effectively combat man-in-the-middle attacks, resulting in inadequate communication security.

Method used

By acquiring the characteristic information of the second communication device, the existence of a man-in-the-middle attack can be determined using the characteristic information, thereby reducing computational complexity and resource consumption. This includes receiving reference information and characteristic information, sending request messages to obtain characteristic information, and using random sequences and location information for authentication.

Benefits of technology

Effectively detect man-in-the-middle attacks, ensure communication security, reduce computational complexity and resource consumption, and improve communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025089136_30102025_PF_FP_ABST
    Figure CN2025089136_30102025_PF_FP_ABST
Patent Text Reader

Abstract

The present application is applied to the technical field of communications. Provided are a communication method and a related apparatus. In the embodiments of the present application, whether a man-in-the-middle attack is present can be determined by a first communication apparatus on the basis of feature information, wherein the feature information is determined on the basis of reference information of a second communication apparatus, and whether the man-in-the-middle attack is present is determined by means of the device uniqueness of the second communication apparatus that is included in the feature information and on the basis of the first feature information and the second feature information, such that the first communication apparatus can disconnect from the current device in a timely manner when it is determined that the man-in-the-middle attack is present, the man-in-the-middle attack is resisted against, and the communication security is effectively ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Communication methods and related devices

[0001] This application claims priority to Chinese Patent Application No. 202410520467.2, filed on April 26, 2024, entitled "Communication Method and Related Apparatus", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communication technology, and in particular to communication methods and related devices. Background Technology

[0003] Wireless communication networks are susceptible to man-in-the-middle attacks. To address this, some solutions check resource parameters for consistency to detect man-in-the-middle attacks. However, if an attacker knows the global allocation pattern of resource parameters, they can predict the parameters the base station will allocate and pre-assign the correct parameters to the terminal. In this case, the base station cannot distinguish between two resource parameter comparisons to detect a man-in-the-middle attack. Other solutions use a shared key to encrypt cyclic redundancy checks (CRC) and block IDs to reject man-in-the-middle forwarding signals. However, CRC checks cannot determine whether the current state is a transmission error or a man-in-the-middle attack, meaning its effectiveness against man-in-the-middle attacks is minimal. Still other solutions calculate the air interface delay by comparing the clocks of the transmitting and receiving ends to mitigate man-in-the-middle attacks. However, local clock drift can cause timestamp errors, leading to false positives for man-in-the-middle attacks, and frequent clock calibrations waste resources. Therefore, this solution also cannot completely prevent man-in-the-middle attacks.

[0004] Therefore, how to combat man-in-the-middle attacks and effectively ensure the security of communication is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0005] This application provides a communication method and related apparatus that can resist man-in-the-middle attacks and effectively ensure communication security.

[0006] In a first aspect, embodiments of this application provide a communication method applied to a first communication device. The first communication device may be, for example, a terminal device or a communication module within the terminal device, or a circuit or chip (such as a modem chip, also known as a baseband chip, or a system-on-chip (SoC) chip containing a modem core, or a system-in-package (SIP) chip) responsible for communication functions within the terminal device. The method includes: acquiring second feature information, wherein the second feature information is information determined based on second reference information of the second communication device; and determining whether a man-in-the-middle attack exists based on the first feature information and the second feature information, wherein the first feature information is determined based on the first reference information.

[0007] In this application, on the one hand, taking the first communication device as the terminal and the second communication device as the base station as an example, the terminal determines whether a man-in-the-middle attack exists based on a feature information verification process. The feature information is determined based on reference information from the second communication device, thus possessing device uniqueness as the base station's identity identifier. The first feature information reflects the identity information of the device initially communicating with the terminal. The second feature information obtained by the terminal reflects the identity information of the device currently communicating with the terminal. When the first and second feature information are inconsistent, it indicates that the identity information of the device initially securely communicating with the terminal is inconsistent with the identity information of the device currently communicating with the terminal, meaning they are not the same device. This suggests that the current communication network may have suffered a man-in-the-middle attack, enabling the terminal to promptly disconnect from the current device upon determining the existence of a man-in-the-middle attack, thus combating the attack and effectively ensuring communication security. On the other hand, because it does not involve operations such as verifying resource block identifier information, allocating resource parameters, or using timestamps for air interface latency detection, it reduces computational complexity and resource overhead.

[0008] In one possible implementation of the first aspect, the method further includes: receiving the first reference information and determining the first feature information based on the first reference information; or, receiving the first feature information.

[0009] Optionally, the acquired first feature information can be encrypted.

[0010] In the above embodiments, the first feature information is determined based on the reference information of the second communication device. Its feature has device uniqueness, indicating the identity information of the device that initially communicates securely with the terminal. It is used to enable the first communication device to extract or save the physical features or identifiers of the currently connected second communication device, laying the groundwork for subsequent determination of whether a man-in-the-middle attack exists.

[0011] In another possible implementation of the first aspect, the first reference information or the first feature information is information sent when the second communication device and the first communication device have established a secure communication connection.

[0012] In the above embodiments, after the first communication device and the second communication device establish a secure communication connection, even if a man-in-the-middle attack occurs, the man-in-the-middle cannot obtain the encryption key. Since the signaling generated by the physical layer and the medium access control (MAC) layer cannot be encrypted, encryption can be performed at the radio resource control (RRC) layer. In this way, the encrypted information transmitted after the establishment of a secure connection will not be deciphered by a man-in-the-middle, thus effectively ensuring the security of the encrypted information at this stage.

[0013] In another possible implementation of the first aspect, before obtaining the second feature information, the method further includes: sending a first request message to the second communication device, wherein the first request message is used to request the second communication device to send the second reference information or the second feature information.

[0014] In the above implementation, a first request message can be sent to actively request second feature information, thereby determining whether a man-in-the-middle attack exists based on the second feature information. This allows the first communication device to promptly disconnect the current connection if a man-in-the-middle attack is detected, ensuring the security of communication.

[0015] In another possible implementation of the first aspect, sending the first request message to the second communication device includes: sending the first request message to the second communication device when a triggering condition is met.

[0016] In the above implementation, after triggering the man-in-the-middle attack detection, the first communication device requests the second communication device to send the second feature information. The second feature information is used by the first communication device to detect man-in-the-middle attacks. This solution only starts the subsequent request to send the second feature information when the triggering condition is met, which can effectively save resource consumption and achieve the target operation.

[0017] In another possible implementation of the first aspect, the triggering condition includes at least one of the following: receiving a switching instruction; detecting that the air interface delay is greater than a first preset value; detecting that the relative position between the second communication device and the first communication device exceeds a preset range; or detecting that the radio frequency fingerprint characteristics of the signal received by the first communication device have changed.

[0018] In the above implementation, events that are prone to man-in-the-middle attacks (e.g., switching commands) or events suspected of being man-in-the-middle attacks (e.g., air interface delay greater than a first threshold, relative position exceeding a preset range, or changes in radio frequency fingerprint characteristics) are used as triggering conditions for requesting the second feature information, which can ensure communication security while saving resource consumption.

[0019] In another possible implementation of the first aspect, the first reference information includes identification information of the first communication device and identification information of the second communication device, and the first feature information is a random sequence generated based on the identification information of the first communication device and the identification information of the first communication device.

[0020] In the above embodiments, a random sequence generated based on the identification information of the first communication device and the identification information of the second communication device is used as the first feature information. Due to the flexibility of the random sequence, the uniqueness of the first feature information can be further enhanced, thereby improving the communication security between the first communication device and the second communication device.

[0021] In another possible implementation of the first aspect, the second reference information is information obtained based on the first feature information and the third reference information, wherein the third reference information includes first channel information, and the first channel is a channel for receiving the second feature information.

[0022] In the above embodiments, a method is provided to obtain second reference information by integrating multiple parameters, and then determine second feature information based on the second reference information. This makes the factors for determining the second feature information more comprehensive, making man-in-the-middle attacks more difficult. Furthermore, the first channel information can characterize the channel on which the first communication device and the second communication device communicate. If the first communication device determines that it initially communicated with the second communication device on channel A, but is currently communicating with the second communication device on channel B, and the channels in these two cases are inconsistent, it indicates that it may be under a man-in-the-middle attack. This allows the first communication device to take timely measures, such as disconnecting the communication connection with the current device, thereby effectively protecting communication security.

[0023] In another possible implementation of the first aspect, the third reference information further includes at least one of the following: the index value of the second feature information, the identification information of the first communication device, and the identification information of the second communication device.

[0024] In the above embodiments, the parameters of the third reference information are processed in a more refined manner. Specifically, the index value of the second feature information is associated with the sampling time point and can be used to characterize the sampling time point of communication between the first and second communication devices. By combining the index value of the second feature information, the identification information of the first and second communication devices, the second reference information is obtained. This makes it more difficult for a man-in-the-middle attack to forge the second reference information, thereby facilitating timely protective measures by the first communication device in the event of a potential man-in-the-middle attack, such as disconnecting the communication connection with the current device, thus effectively protecting communication security.

[0025] In another possible implementation of the first aspect, the second feature information is information derived from the second reference information using a one-way deduction algorithm.

[0026] In the above implementation, the second feature information can only be obtained by unidirectional deduction from the second reference information, such as through a hash algorithm. The second reference information needs to be obtained based on the first and third feature information. Furthermore, because the first feature information is encrypted at the RRC layer, it is difficult for a man-in-the-middle attack to crack it, thus ensuring communication security. Additionally, as long as the first feature information is secure, the presence of a man-in-the-middle attack can be quickly determined by checking whether the received second feature information is consistent, again ensuring communication security.

[0027] In another possible implementation of the first aspect, the first feature information includes a target key, and the second reference information is information obtained based on the target key and the first channel information.

[0028] In the above implementation, when a man-in-the-middle attack occurs, the man-in-the-middle may forge the content of the second feature information. Since the target key included in the first feature information is difficult to obtain, when the man-in-the-middle forges the second feature information, the first communication device will compare the first and second feature information, causing the verification of the second feature information to fail. This solution allows the first communication device to adaptively determine whether to disconnect the current connection between devices to ensure communication security.

[0029] In another possible implementation of the first aspect, the target key is obtained based on a first public key and a second public key, wherein the first public key is obtained based on a first private key, a first public key and a second public key, and the second public key is a public key sent by the second communication device.

[0030] In the above implementation, since the first private key is unique to the first communication device and is difficult for other devices to obtain, even if a man-in-the-middle obtains the first public key and the second public key, it is difficult to obtain the target key, thus causing the man-in-the-middle attack to fail and effectively ensuring communication security.

[0031] In another possible implementation of the first aspect, the first reference information includes a first positioning reference signal, which is used to measure at least one of the distance, signal strength and angle of the second communication device to obtain a measurement result, and the first feature information is the position information of the second communication device, which is determined based on the measurement result and the position information of the first communication device.

[0032] In the above embodiment, the measurement results obtained by the first communication device from the parameters associated with the position coordinates are combined with the position information of the first communication device itself to obtain the first feature information. The calculation is simple and the recording of the initial position of the second communication device makes it easy to determine whether the position information of the second communication device has changed. This allows for an adaptive determination of whether the connection between the current devices needs to be disconnected, thus effectively protecting the current communication security. In this way, it is more flexible to deal with man-in-the-middle attacks.

[0033] In another possible implementation of the first aspect, the second reference information includes a second positioning reference signal, which is used to measure at least one of the distance, signal strength, and angle of the second communication device to obtain a measurement result, and the position information of the second communication device is used as the second feature information, which is determined based on the measurement result and the position information of the first communication device.

[0034] In the above embodiment, the measurement results obtained by the first communication device from the measurement of parameters associated with the position coordinates are combined with the position information of the first communication device itself to obtain the first feature information. The first feature information can be combined to dynamically determine whether the position information of the second communication device has changed, and then adaptively determine whether it is necessary to disconnect the connection between the current devices to effectively protect the current communication security. In this way, the response to man-in-the-middle attacks is more flexible.

[0035] In another possible implementation of the first aspect, the second positioning reference signal is determined based on the offset of the positioning reference signal or the periodic interval of the positioning reference signal.

[0036] In the above embodiments, the second positioning reference signal is determined by the offset of the positioning reference signal or the periodic interval of the positioning reference signal, which makes the method of obtaining the second positioning reference signal more flexible.

[0037] In another possible implementation of the first aspect, the method further includes: receiving a switching instruction from the second communication device, wherein the switching instruction is used to instruct the first communication device to establish a communication connection with the third communication device; sending a second request message to the third communication device, wherein the second request message is used to request the third communication device to send fourth reference information or third feature information, wherein the third feature information is determined based on the fourth reference information; receiving the fourth reference information and determining the third feature information based on the fourth reference information; or, receiving the third feature information; and determining whether a man-in-the-middle attack exists based on the stored first feature information and the third feature information.

[0038] In the above embodiments, to combat man-in-the-middle attacks when switching to a new communication device for connection, cached data in the second communication device can be migrated to the third communication device when switching to a connection with the third communication device. The cached data in the second communication device is forwarded using higher-level protocols (e.g., encrypted forwarding via the RRC layer). During this process, the feature information stored in the second communication device is also migrated to the third communication device. This ensures that although the connection is now established with the third communication device, the authentication is still based on the secure feature information already established between the second and first communication devices, thereby guaranteeing communication security.

[0039] Secondly, embodiments of this application provide a communication method applied to a second communication device. The second communication device may be, for example, a terminal device or a communication module within a terminal device, or a circuit or chip within a terminal device responsible for communication functions (such as a modem chip, also known as a baseband chip, or a system-on-chip (SoC) chip containing a modem core, or a system-in-package (SIP) chip); or the second communication device may be, for example, a network device or a communication module within a network device, or a circuit or chip within a terminal device responsible for communication functions (such as a modem chip, also known as a baseband chip, or an SoC chip containing a modem core, or a SIP chip). The method includes: determining first reference information and second reference information, wherein the first reference information is used to determine first feature information, and the second reference information is used to determine second feature information, and the first feature information and the second feature information are used to determine whether a man-in-the-middle attack exists. In one possible implementation of the second aspect, the second reference information or the second feature information is sent to a first communication device.

[0040] In one possible implementation of the second aspect, the method further includes: sending the first reference signal or the first feature information to the first communication device.

[0041] In another possible implementation of the second aspect, the first reference information or the first feature information is information sent when the second communication device and the first communication device have established a secure communication connection.

[0042] In another possible implementation of the second aspect, before sending the second reference information to the first communication device, the method further includes: receiving a first request message from the first communication device, wherein the first request message is used to request the second communication device to send the second reference information or the second feature information.

[0043] In another possible implementation of the second aspect, the first reference information includes identification information of the first communication device and identification information of the second communication device, and the first feature information is a random sequence generated based on the identification information of the first communication device and the identification information of the first communication device.

[0044] In another possible implementation of the second aspect, the second reference information is information obtained based on the first feature information and the third reference information, wherein the third reference information includes first channel information, and the first channel is a channel for receiving the second feature information.

[0045] In another possible implementation of the second aspect, the third reference information further includes at least one of the following: the index value of the second feature information, the identification information of the first communication device, and the identification information of the second communication device.

[0046] In another possible implementation of the second aspect, the second feature information is information obtained from the second reference information through a one-way deduction algorithm.

[0047] In another possible implementation of the second aspect, the first feature information includes a target key, and the second reference information is information obtained based on the target key and the first channel information.

[0048] In another possible implementation of the second aspect, the target key is obtained based on a first public key and a second public key, the second public key being obtained based on a second private key, a first public key, and a second public key, and the first public key being the public key sent by the first communication device.

[0049] In another possible implementation of the second aspect, the first reference information includes a first positioning reference signal, which is used to measure at least one of the distance, signal strength and angle of the second communication device to obtain a measurement result, and the first feature information is the position information of the second communication device, which is determined based on the measurement result and the position information of the first communication device.

[0050] In another possible implementation of the second aspect, the second reference information includes a second positioning reference signal, which is used to measure at least one of the distance, signal strength and angle of the second communication device to obtain a measurement result, and the first feature information is the position information of the second communication device, which is determined based on the measurement result and the position information of the first communication device.

[0051] In another possible implementation of the second aspect, the second positioning reference signal is determined based on the offset of the positioning reference signal or the periodic interval of the positioning reference signal.

[0052] In another possible implementation of the second aspect, the method further includes: sending a switching instruction to the first communication device, wherein the switching instruction is used to instruct the first communication device to establish a communication connection with the third communication device.

[0053] In another possible implementation of the second aspect, the method further includes: sending the first feature information to the third communication device, or sending the first reference information to the third communication device.

[0054] Thirdly, embodiments of this application provide a communication device, which may be a terminal device, a device in the terminal device (e.g., a chip, a chip system, or a circuit), or a device that can be used in conjunction with the terminal device, or a logic module or software that can implement all or part of the functions of the terminal device.

[0055] In one possible implementation, the communication device may include modules or units that perform the methods / operations / steps / actions described in the first aspect. These modules or units may be hardware circuits, software, or a combination of hardware circuits and software.

[0056] Fourthly, embodiments of this application provide a communication device that can be used in the second communication device of the second aspect. The communication device can be a terminal device or a network device, or a device (e.g., a chip, a chip system, or a circuit) in the terminal device or network device, or a device that can be used in conjunction with the terminal device or network device, or a logic module or software that can implement all or part of the functions of the terminal device or network device.

[0057] In one possible implementation, the communication device may include modules or units that perform the methods / operations / steps / actions described in the second aspect one by one. These modules or units may be hardware circuits, software, or a combination of hardware circuits and software.

[0058] Fifthly, embodiments of this application provide a communication device, which includes at least one processor and a communication interface; the communication interface is used for inputting and / or outputting information, and the at least one processor is used for calling a computer program stored in at least one memory to implement the method described in any of the embodiments of the first aspect.

[0059] In one possible implementation of the fifth aspect, the communication device further includes at least one of the aforementioned memories. Optionally, the memory and processor are integrated together.

[0060] In a sixth aspect, embodiments of this application provide a communication device, which includes at least one processor and a communication interface; the communication interface is used for inputting and / or outputting information, and the at least one processor is used to call a computer program stored in at least one memory to implement the method described in any of the embodiments of the second aspect.

[0061] In one possible implementation of the sixth aspect, the communication device further includes at least one of the aforementioned memories. Optionally, the memory and processor are integrated together.

[0062] In a seventh aspect, embodiments of this application provide a communication device, which includes a logic circuit and an interface, the logic circuit and the interface being coupled; the interface is used to input and / or output information, and the logic circuit is used to implement the method described in any of the embodiments of the first to second aspects.

[0063] In one possible implementation of the seventh aspect, the communication device is a chip or chip system.

[0064] Eighthly, embodiments of this application provide a communication system including a first communication device and a second communication device, which are communicatively connected. The first communication device is used to implement the method of any embodiment of the first aspect, and the second communication device is used to implement the method of any embodiment of the second aspect.

[0065] In a ninth aspect, embodiments of this application provide a computer-readable storage medium for storing instructions or a computer program; when the instructions or the computer program are executed, the method of any one of the embodiments of the first to second aspects is implemented.

[0066] In a tenth aspect, this application provides a computer program product including computer instructions that, when executed on at least one processor, can implement the methods described in any of the first to second aspects or any possible implementations thereof. Exemplarily, the computer program product can be a software installation package, which can be downloaded and executed on a computing device when the aforementioned methods are required.

[0067] The beneficial effects of the technical solutions provided in aspects two through ten of this application can be referred to the beneficial effects of the technical solutions in aspect one, and will not be repeated here. Attached Figure Description

[0068] Figure 1 is a schematic diagram of the architecture of a communication system provided in an embodiment of this application;

[0069] Figure 2 is a schematic diagram of the architecture of another communication system provided in an embodiment of this application;

[0070] Figure 3 is a schematic diagram of the architecture of another communication system provided in an embodiment of this application;

[0071] Figure 4 is a schematic diagram of an O-RAN system provided in an embodiment of this application;

[0072] Figure 5 is a diagram showing the network element function division and protocol layer structure of an O-RAN system provided in an embodiment of this application;

[0073] Figure 6 is a flowchart illustrating a man-in-the-middle attack provided in an embodiment of this application;

[0074] Figure 7 is a schematic diagram of a legitimate node in a WLAN network being subjected to a man-in-the-middle attack, as provided in an embodiment of this application.

[0075] Figure 8 is a flowchart illustrating a communication method provided in an embodiment of this application;

[0076] Figure 9 is a schematic diagram of a signaling delay provided in an embodiment of this application;

[0077] Figure 10 is a schematic diagram of different fingerprint features provided in an embodiment of this application;

[0078] Figure 11 is a schematic diagram of second feature information obtained based on first feature information according to an embodiment of this application;

[0079] Figure 12 is a schematic diagram of obtaining first feature information according to an embodiment of this application;

[0080] Figure 13 is a schematic diagram of obtaining second feature information according to an embodiment of this application;

[0081] Figure 14 is a schematic diagram of the process of a first communication device switching from a second communication device to a third communication device according to an embodiment of this application.

[0082] Figure 15A is a schematic diagram of a process for determining whether a man-in-the-middle attack exists by a first communication device according to an embodiment of this application;

[0083] Figure 15B is a schematic diagram of another process by which a first communication device determines whether a man-in-the-middle attack exists, according to an embodiment of this application.

[0084] Figure 15C is a schematic diagram of another process provided by the first communication device to determine whether a man-in-the-middle attack exists, according to an embodiment of this application.

[0085] Figure 16 is a schematic diagram of the structure of a communication device 160 provided in an embodiment of this application;

[0086] Figure 17 is a schematic diagram of another communication device 170 provided in an embodiment of this application;

[0087] Figure 18 is a structural schematic diagram of another communication device 180 provided in an embodiment of this application. Detailed Implementation

[0088] The embodiments of this application will now be described in detail with reference to the accompanying drawings.

[0089] The system architecture used in the embodiments of this application is described below. It should be noted that the system architecture and business scenarios described in this application are for the purpose of more clearly illustrating the technical solutions of this application, and do not constitute a limitation on the technical solutions provided in this application. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided in this application are also applicable to similar technical problems.

[0090] Please refer to Figure 1, which is a schematic diagram of the architecture of a communication system provided in an embodiment of this application. As shown in Figure 1(a), the communication system includes a first communication device 101 and a second communication device 102. Optionally, the communication system also includes a third communication device 103. Optionally, the first communication device 101, the second communication device 102, and the third communication device 103 can be the same type of device or different types of devices. For example, as shown in Figure 1(b), the first communication device 101 is a terminal, the second communication device 102 is a first network device, and the third communication device 103 is a second network device. As another example, as shown in Figure 1(c), the first communication device 101 is a terminal, the second communication device 102 is a terminal, and the third communication device 103 is also a terminal. Next, taking the first communication device 101 as a terminal, the second communication device 102 as a first network device, and the third communication device 103 as a second network device as an example, the architecture of the communication system will be described in detail.

[0091] It is understood that when the communication system only includes the first communication device 101 and the second communication device 102, the communication system only shows one terminal and one network device. In actual use, an architecture of at least one terminal and / or at least one network device can be adopted as needed (e.g., the architecture shown in Figure 1(a)). Exemplarily, the communication system shown in Figure 2 includes one network device and multiple terminals, or multiple network devices and one terminal, wherein a single network device can transmit data or send control signaling to one or more terminals. Multiple network devices can simultaneously transmit data or send control signaling to a single terminal.

[0092] In this embodiment, network device 210 is a node in a radio access network (RAN), also known as an access network device or an RAN node (or device). Network device 210 is used to help terminals achieve wireless access. Multiple network devices 210 in communication system 2000 can be nodes of the same type or different types. In some scenarios, the roles of network device 210 and terminal 220 are relative. For example, network element 220i in Figure 2 can be a helicopter or drone, which can be configured as a mobile base station. For terminals 220j that access RAN 200 through network element 220i, network element 220i is a base station; but for base station 210a, network element 220i is a terminal. Network device 210 and terminal 220 are sometimes referred to as communication devices. For example, network elements 210a and 210b in Figure 2 can be understood as communication devices with base station functions, and network elements 220a-220j can be understood as communication devices with terminal functions.

[0093] In one possible scenario, network equipment can be a base station, an evolved NodeB (eNodeB), a transmitting and receiving point (TRP), a transmitting point (TP), a next-generation NodeB (gNB), a next-generation base station in a 6th-generation (6G) mobile communication system, a base station in a future mobile communication system, a satellite, or an access point (AP) in a WiFi system, an integrated access and backhaul (IAB) node, or network equipment in a mobile switching center non-terrestrial network (NTN) communication system, i.e., it can be deployed on a high-altitude platform or satellite, etc. Network equipment can be a macro base station (as shown in Figure 2, 210a), a micro base station or indoor station (as shown in Figure 2, 210b), a relay node or donor node, or a radio controller in a cloud radio access network (CRAN) scenario. Network equipment can also function as a base station in device-to-device (D2D) communication, vehicle-to-everything (V2X) communication, drone communication, and machine-to-machine (M2M) communication. Optionally, network equipment can also be servers, wearable devices, vehicles, or in-vehicle equipment. For example, in vehicle-to-everything (V2X) technology, the access network equipment can be a roadside unit (RSU).

[0094] In another possible scenario, multiple network devices collaborate to assist terminals in achieving wireless access, with each network device performing a portion of the base station's functions. For example, network devices can be central units (CUs), distributed units (DUs), CU-control plane (CPs), CU-user plane (UPs), or radio units (RUs), etc. CUs and DUs can be set up separately or included in the same network element, such as a baseband unit (BBU). RUs can be included in radio equipment or radio units, such as remote radio units (RRUs), active antenna units (AAUs), or remote radio heads (RRHs). It is understood that network devices can be CU nodes, DU nodes, or devices comprising both CU and DU nodes. Furthermore, CUs can be classified as network devices in the access network (RAN) or the core network (CN), without limitation.

[0095] In this embodiment, the terminal involved may include various handheld devices, vehicle-mounted devices, wearable devices, computing devices, or other processing devices connected to a wireless modem with wireless communication capabilities. Terminal device 220 may also be referred to as user equipment (UE), mobile station (MS), mobile terminal (MT), etc., or a device used to provide voice or data connectivity to a user, or an Internet of Things (IoT) device. For example, terminal devices include handheld devices and vehicle-mounted devices with wireless connectivity. Currently, terminal devices can include: mobile phones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices (such as smartwatches, smart bracelets, pedometers, smart glasses, etc.), in-vehicle devices (such as cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), satellite terminals, virtual reality (VR) devices, augmented reality (AR) devices, point-of-sale (POS) machines, customer-premises equipment (CPE), light user equipment (UE), reduced capability user equipment (REDCAP UE), wireless terminals in industrial control, smart home devices (such as refrigerators, televisions, air conditioners, electricity meters, etc.), intelligent robots, robotic arms, workshop equipment, wireless terminals in autonomous driving, wireless terminals in telemedicine, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, or wireless terminals in smart homes, and flying equipment (such as intelligent robots, hot air balloons, drones, airplanes), etc. Terminal devices can also be vehicle devices, such as vehicle devices, vehicle modules, vehicle chips, on-board units (OBUs) or telematics boxes (T-BOXs). Terminal devices can also be other devices with terminal functions. For example, a terminal device can also be a device that performs terminal functions in D2D communication.

[0096] Optionally, the communication between each network device and each terminal device in the communication system shown in Figure 2 can also be represented in another form, as shown in Figure 3. The communication system includes a terminal 310 and a first network device 320. The terminal 310 includes a first processor 311, a first memory 312, and a first transceiver 313. The first transceiver 313 includes a first transmitter 3131, a first receiver 3132, and a first antenna 3133. The first network device 320 includes a second processor 321, a second memory 322, and a second transceiver 323. The second transceiver 323 includes a second transmitter 3231, a second receiver 3232, and a second antenna 3233. The first transmitter 3131 can be used to send a first request message to the first network device 320 through the first antenna 3133, and the first receiver 3132 can be used to receive second feature information from the first network device 320 through the first antenna 3133. The second transmitter 3231 can be used to send second feature information to the terminal 310 via the second antenna 3233, and the second receiver 3232 can be used to receive the first request message sent by the terminal 310 via the second antenna 3233.

[0097] Optionally, the method provided in this application embodiment can also be applied to an O-RAN system. Please refer to Figure 4, which is a schematic diagram of an O-RAN system provided in this application embodiment. The O-RAN system may also include other components besides those shown in Figure 4, and this application does not limit this. Optionally, the network device shown in Figure 4 can be an access network device, such as an eNB, gNB, or next-generation access network device. The access network device communicates with the core network (CN) via a backhaul link and with terminals via an air interface. The BBU in the access network device communicates with the core network via a backhaul link, and the RU in the access network device communicates with at least one terminal via an air interface. The BBU communicates with at least one RU via a fronthaul link. The BBU and RU may or may not be co-located. The BBU includes at least one control unit (CU) and at least one distributed unit (DU), which can communicate via at least one midhaul link.

[0098] Further optionally, please refer to Figure 5. Figure 5 is a diagram illustrating the network element functional division and protocol layer structure of an Open Radio Access Network (O-RAN) system provided in an embodiment of this application. As shown in Figure 5, in some examples, the CU is a logical node carrying the RRC layer, Service Data Adaptation Protocol (SDAP) layer, Packet Data Convergence Protocol (PDCP) layer, and other control functions of the access network equipment. The CU is connected to network nodes such as the core network through some interfaces, which may be interfaces such as E2 interfaces. Optionally, the CU may have some functions of the core network, such as the PDCP layer and higher layers. The CU is connected to the DU (e.g., RLC layer and lower layers) through some interfaces, which may be interfaces such as F1 interfaces. In some examples, these interfaces (e.g., the F1 interface) can provide control plane (C-Plane) and user plane (U-Plane) functions (e.g., interface management, system information management, UE context management, RRC message transmission, etc.). F1AP is the application protocol of the F1 interface, and in some examples, the signaling procedures of F1 are defined. The F1 interface supports the control plane F1-C and the user plane F1-U.

[0099] In some examples, the CU can be split into CU-CP (control unit-control plane) and CU-UP (control unit-user plane). CU-CP is a logical node carrying the RRC layer and PDCP-C (control plane part of PDCP) layer, used to implement the CU's control plane functions. CU-CP can interact with network elements in the core network used to implement control plane functions. These network elements in the core network can be access and mobility function (AMF) network elements, such as the access and mobility management function (AMF) in a 5G system. AMF network elements are responsible for mobility management in the mobile network, such as terminal location updates, terminal registration with the network, and terminal handover. CU-UP is a logical node carrying the SDAP layer and the PDCP-U (user plane part of PDCP) layer for user plane data, used to implement the CU's user plane functions. CU-UP can interact with network elements in the core network used to implement user plane functions. These network elements in the core network, such as the UPF (user plane function) in a 5G system, are responsible for data forwarding and receiving in terminal devices. It should be understood that the above configurations of CU and DU are merely examples, and the functions of CU and DU can be configured as needed. This application does not impose excessive limitations on this. For example, CU or DU can be configured to have more protocol layer functions, or CU or DU can be configured to have some protocol layer processing functions. Another example is to place some functions of the RLC layer and the protocol layer functions above the RLC layer in the CU, and place the remaining functions of the RLC layer and the protocol layer functions below the RLC layer in the DU. Yet another example is that the functions of CU or DU can be divided according to service type or other system requirements, such as by latency, placing functions that need to meet low latency requirements in the DU, and functions that do not need to meet this latency requirement in the CU.

[0100] In some examples, a DU is a logical node that carries the radio link control (RLC) layer, MAC layer, higher physical layer (PHY) layer, and other functions. In some examples, a DU can control at least one RU. The DU connects to the RU through interfaces, which can be fronthaul interfaces. In some examples, the Higher PHY layer includes the PHY layer processing, such as forward error correction (FEC) encoding and decoding, scrambling, modulation, and demodulation.

[0101] In some examples, the RU is a logical node that carries both lower physical layer (PHY) and radio frequency chain (RF chain) processing. In some examples, the RU can be a 3GPPTRP, a Remote Radio Header (RRH), or other similar functionalities. In some examples, the Low-PHY includes PHY processing functions such as Fast Fourier Transform (FFT), Inverse Fast Fourier Transform (IFFT), digital beamforming, and filtering. The RU communicates with one or more UEs via a radio link.

[0102] Optionally, the DU and RU may or may not be co-located. The DU and RU exchange control plane information via a fronthaul link through a lower-layer split-control, user plane information (LLS-CUS) and synchronization interface. The LLS-CUS may include LLS-C and LLS-U interfaces that respectively provide the control plane (C-Plane) and user plane (U-Plane). In some examples, the control plane (C-Plane) refers to real-time control between the DU and RU. The DU and RU exchange management information via an LLS-M interface on the fronthaul link; the management plane (M-Plane) refers to non-real-time management operations between the DU and RU.

[0103] Optionally, the DU and RU can cooperate to implement the functions of the PHY layer. A DU can be connected to one or more RUs. The functions of the DU and RU can be configured in various ways depending on the design. For example, the DU can be configured to implement baseband functions, and the RU can be configured to implement mid-RF functions. Alternatively, the DU can be configured to implement higher-level functions in the PHY layer, and the RU can be configured to implement lower-level functions in the PHY layer, or to implement both lower-level and RF functions. Higher-level functions in the physical layer may include a portion of the physical layer's functions that are closer to the MAC layer, while lower-level functions in the physical layer may include another portion of the physical layer's functions that are closer to the mid-RF side.

[0104] In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, in an ORAN system, CU can also be called O-CU (Open CU), DU can also be called O-DU, CU-CP can also be called O-CU-CP, CU-UP can also be called O-CU-UP, and RU can also be called O-RU. For ease of description, this application uses CU, CU-CP, CU-UP, DU, and RU as examples. The network device deployment methods listed here are only examples; as standard technologies evolve, network devices may have other deployment forms.

[0105] The network architecture and business scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions and network architectures provided in the embodiments of this application are also applicable to similar technical problems.

[0106] Figures 6 and 7 illustrate the man-in-the-middle attack. In the initial stage, the first and second communication devices establish a legitimate link connection through a higher-level authentication process and communicate normally on channel A. The man-in-the-middle attacker has two transceiver nodes, acting as a fake base station (FBS) and a fake user equipment (FUE), respectively. The FBS waits for the first communication device to switch to channel B, or sends a forged signal to induce the first communication device to switch to channel B. Simultaneously, the FUE continues to receive information on the original channel A, maintaining its connection with the second communication device. The man-in-the-middle attacker will receive information on channel A and forward it on channel B; conversely, it will forward the information received on channel A and vice versa. Since the connection is not interrupted for the legitimate first and second communication devices, neither device is aware that the current communication process is under a man-in-the-middle attack. Once the attacker establishes the location for the man-in-the-middle attack, subsequent authentication processes for both legitimate parties can be completed under the man-in-the-middle data forwarding mechanism.

[0107] The harm caused by man-in-the-middle attacks is multifaceted. For example, in cellular networks, a man-in-the-middle attacker can refuse to forward certain messages, denying users partial services and impacting user experience. Attackers can also use legitimate base stations to verify Subscribed Hidden Identifier (SUCI) information, granting them further attack capabilities. Furthermore, attackers can redirect users to malicious websites, causing serious information leaks. Similarly, in wireless local area networks (WLANs), open WLANs are more vulnerable to man-in-the-middle attacks than the more closed cellular networks. First, WLANs contain numerous unencrypted channel switching commands, such as channel switch announcements (CSAs), making them highly susceptible to man-in-the-middle attacks. As shown in Figure 7, attackers implemented man-in-the-middle attacks using unencrypted CSAs. Second, public WLANs often lack passwords or have easily accessible passwords, significantly increasing the risk of man-in-the-middle attacks. Finally, a master man-in-the-middle attacker who obtains the Wi-Fi key can arbitrarily access and tamper with user information, severely compromising wireless network security.

[0108] Because man-in-the-middle attacks have extremely serious consequences, some implementations establish a secure radio resource control (RRC) link (e.g., represented as RRC security established) between the first and second communication devices to counter them. The man-in-the-middle has two nodes: the FBS (Fixed Base Station) posing as a fake base station to deceive the user, and the FUE (Functional User Equipment) posing as a fake user to deceive the gNB (Gate Node Block). First, the UE requests resource parameters from the man-in-the-middle link (Schedule Request, SR), such as the system frame number (SFN). Taking the allocation of SFN1 as an example (exemplarily, SFN1 includes parameters such as the number of system frames, the number of subframes, the time slot, the symbol start position, and resource allocation information), the fake base station must respond according to the protocol procedure. Then, the man-in-the-middle also requests the allocation of resource parameter SFN2 from the gNB. Next, the UE transmits SFN1 in an RRC message (optionally, SFN1 is transmitted encrypted). The FUE forwards SFN1 to the gNB, and the gNB compares SFN1 and SFN2. If they are inconsistent, it indicates a potential man-in-the-middle attack. Because the fake base station and gNB each perform resource allocation twice, and these two allocations occur on two different channels, it's difficult for SFN1 and SFN2 to be identical. However, this method is predictable. If a man-in-the-middle attacker knows the global SFN allocation pattern, they can predict which resource the gNB will allocate, SFN2, and thus pre-allocate the correct SFN1 to the UE. Therefore, even if the gNB finds the two SFNs to be identical through comparison, it cannot be certain that it hasn't been subjected to a man-in-the-middle attack.

[0109] In other implementations, after the attacker has completed the man-in-the-middle attack and established the man-in-the-middle channel location, the legitimate UE and the base station (BS) first share a symmetric key. This symmetric key is used to ensure that data encrypted with this key cannot be tampered with by a man-in-the-middle attack. The blockid represents the resource block (RB) identifier allocated to the UE by the BS. Since the attacker is sending and receiving information on two different channels, the same data packet experiences different time-frequency resources on the two different channels, and their block IDs are also different. When transmitting data, the blockid and CRC are encrypted using the key to obtain a new CRC'.

[0110] CRC′ = MessageAuthenticationCodeComputation(K_PHYint, CRC|blockID)(*) where CRC is a 24-bit data checksum. For example, each data block generates a CRC checksum. If a transmission error occurs within the received data packet, the CRC_r calculated based on the received data will be inconsistent with the actual CRC. MessageAuthenticationCodeComputation() is an encryption function. When the BS receives a data packet on time-frequency resource B, it infers its block id B and uses block id B to calculate the CRC'_r of the data packet. If either the CRC or the block id is incorrect, the comparison between CRC' and CRC'_r will fail. The current scheme can use a shared key to encrypt the CRC and block id to reject man-in-the-middle forwarding signals. However, verifying the encrypted CRC cannot determine whether the current state is a transmission error or a man-in-the-middle attack, therefore it cannot be completely used to combat man-in-the-middle attacks.

[0111] In some implementations, the presence of a man-in-the-middle attack can be determined by detecting the air interface delay. If no man-in-the-middle exists, the air interface delay from transmitter to receiver is primarily the propagation time of the electromagnetic wave, approximately 150 ns over a distance of 50 meters. However, if a man-in-the-middle exists, data transfer occurs between the two nodes involved. The FBS needs to receive the data transmitted by the legitimate UE before transferring it to the FUE for transmission to the legitimate BS. If an attacker uses commercial equipment for a man-in-the-middle attack, the air interface delay increases to at least 42 μs; if the attacker uses an SDR device, the delay is at least 24 μs. This significantly increases the delay compared to direct signal transmission. Existing technologies estimate the air interface transmission delay by introducing counters (clocks) at both the transmitting and receiving ends. For example, using an 802.11 data packet, the packet includes a header, Time Synchronization Block Tracking (TSF_tracking), and the payload. The transmitter adds a time synchronization block to the data packet to track the transmission timestamp and encrypts the original data transmission to prevent man-in-the-middle tampering. A legitimate receiver compares the received data with its local clock line; if the difference is too large, it indicates a potential man-in-the-middle attack. This scheme calculates the signal delay over the air interface by comparing the clocks of the transmitting and receiving ends. However, local clock drift can cause timestamp errors, leading to false alarms about man-in-the-middle attacks. Furthermore, frequent clock calibration increases resource waste. Therefore, this scheme cannot completely determine whether a man-in-the-middle attack exists.

[0112] In view of this, embodiments of this application provide a communication method and related apparatus. On one hand, taking a first communication device as a terminal and a second communication device as a base station, the terminal determines whether a man-in-the-middle attack exists based on a feature information verification process. In other words, the device uniqueness of the feature information serves as the identity identifier of the base station. When the first feature information and the second feature information are inconsistent, it indicates that the current communication network has suffered a man-in-the-middle attack, thereby enabling the terminal to promptly disconnect the current connection upon determining the existence of a man-in-the-middle attack, ensuring communication security. On the other hand, because it does not involve operations such as verification of resource block identifier information, allocation of resource parameters, or detection of air interface latency using timestamps, it can reduce computational complexity and resource overhead.

[0113] In the communication method described below (as shown in Figure 8), the specific descriptions of the first communication device, the second communication device, and the third communication device can be found in Figures 1 to 5, and will not be detailed here. For ease of description, in the embodiments of this application, specific examples may be used to illustrate the first communication device as the terminal, the second communication device as the first network device, and the third communication device as the second network device, but this should not be construed as a limitation on the embodiments of this application.

[0114] The embodiments of this application will now be described in detail with reference to the accompanying drawings.

[0115] Please refer to Figure 8, which is a flowchart illustrating a communication method provided in an embodiment of this application. Optionally, this method can be applied to a communication system, such as the communication systems shown in Figures 1 to 5.

[0116] The communication method shown in Figure 8 may include multiple steps in steps S801-S805. Steps S801-S805 are detailed below:

[0117] Step S801: The second communication device determines the first reference information.

[0118] The first reference information is an exemplary name used to distinguish a particular reference message. Optionally, the first reference information is information sent when a secure communication connection is established between the second communication device and the first communication device.

[0119] The first reference information is used to determine the first feature information. The first feature information is an exemplary name used to distinguish a certain feature message. The first feature information is information determined based on the first reference information of the second communication device.

[0120] Optionally, after determining the first reference information, the second communication device may proactively send the first reference information to the first communication device, or it may send the first reference information to the first communication device based on a request from the first communication device.

[0121] Accordingly, the first communication device receives the first reference information.

[0122] Step S802: The first communication device acquires the first feature information.

[0123] Optionally, the acquisition of the first feature information can be unidirectional acquisition by the first communication device, or acquisition by both the first and second communication devices.

[0124] The following are three possible implementation methods for the first communication device to acquire the first feature information, as exemplified by the following:

[0125] In one implementation method, before acquiring the first feature information, the first communication device may also receive first reference information from the second communication device, and then the first communication device acquires the first feature information based on the first reference information.

[0126] In the second implementation, the first feature information may be sent by the second communication device to the first communication device in response to a request message from the first communication device.

[0127] In the third implementation method, the first feature information can also be actively sent from the second communication device to the first communication device (i.e., without the first communication device actively requesting to trigger it).

[0128] Alternatively, the first feature information may be periodically sent from the second communication device to the first communication device. For example, the period for the second communication device to send the first feature information to the first communication device is 10 μs, 10 ms, or 10 s.

[0129] It should be understood that the above steps S801 and S802 are only one possible example, and there are other ways, which are not limited in this application.

[0130] Step S803: The second communication device determines the second reference information.

[0131] The second reference information is an exemplary naming used to distinguish a particular reference message. Optionally, the second reference information is provided by the second communication device to the first communication device, and the second reference information is used by the first communication device to determine the second feature information.

[0132] Optionally, after determining the second reference information, the second communication device may proactively send the second reference information to the first communication device, or it may send the second reference information to the first communication device based on a request from the first communication device.

[0133] Accordingly, the first communication device receives the second reference information.

[0134] Step S804: The first communication device acquires the second feature information.

[0135] The following are three possible implementation methods for the first communication device to acquire the second feature information, as exemplified by the following:

[0136] In one implementation method, before acquiring the second feature information, the first communication device may also receive second reference information from the second communication device, and then the first communication device acquires the second feature information based on the second reference information.

[0137] In the second embodiment, the first communication device sends a first request message to the second communication device, and the second communication device sends second feature information to the first communication device based on the first request message from the first communication device.

[0138] In the third implementation method, the second communication device actively sends the second feature information to the first communication device.

[0139] Alternatively, if the triggering condition is met, the first communication device may send a first request message to the second communication device.

[0140] For example, the triggering condition includes at least one of the following:

[0141] (1) The first communication device receives a handover command. For example, the handover command can be a handover command message issued by the second communication device, which can be used to change the dedicated channel configuration and timing adjustment. This command is issued by the second communication device in the RRC connection reconfiguration command. Alternatively, the handover command can be a beam switching command, which is issued by the second communication device in the L2 layer MAC CE. Another example is that the handover command can be a channel switching signaling received by the first communication device in the Wi-Fi network, such as CSA signaling. Since attackers may launch attacks during channel switching, triggering man-in-the-middle attack detection every time a channel switch occurs can effectively prevent man-in-the-middle attacks.

[0142] (2) The first communication device detects that the air interface delay is greater than a first preset value. Generally, when the first communication device sends a request message to the second communication device to request target information (e.g., requesting other system information (OSI)), the target information (e.g., SIB2-SIB9 in OSI) is encrypted and sent at the RRC layer, thus preventing a man-in-the-middle attacker from successfully carrying out a man-in-the-middle attack by forging a fast response. For example, based on direct communication between the first and second communication devices without man-in-the-middle forwarding, as shown in Figure 9(a), the air interface delay is t1-t0, which only includes the time for radio propagation and the time for the second communication device to process data. However, when a man-in-the-middle attack exists, as shown in Figure 9(b), the information received by the first communication device is forwarded by a man-in-the-middle attacker. In this case, the air interface delay becomes t3-t2, which includes the delay of two receptions / forwards by the man-in-the-middle attacker. This increase in delay will significantly increase the air interface delay detected by the first communication device. For example, when the first communication device detects that the difference between avg(t3-t2) and avg(t1-t0) is greater than a first preset value, it triggers man-in-the-middle detection. Here, avg represents the average value, t1-t0 is the historical air interface delay value obtained by the first communication device through multiple measurements when there is no man-in-the-middle forwarding during direct communication between the first communication device and the second communication device, and t3-t2 is the air interface delay value obtained by the first communication device through multiple detections when there is a man-in-the-middle.

[0143] (3) The first communication device detects that the relative position between the second communication device and the first communication device exceeds a preset range. Optionally, when a man-in-the-middle attacker forges the first feature information, the first communication device measures based on the first feature information and finds that the relative position between the second communication device and the first communication device has changed, thereby determining that the position of the second communication device has changed. However, if the first communication device does not switch to the second communication device, it can be considered that a man-in-the-middle attack exists. In other words, the communication device currently connected to the first communication device is not the real second communication device, but a man-in-the-middle device. For example, suppose that the initial position of the second communication device relative to the first communication device obtained by the first communication device is: 20° southwest, distance 300m. After the first communication device detects again, it finds that the position of the second communication device relative to the first communication device is: 5° southwest, distance 400m. The preset range is 19.9°~20.5° southwest, distance 290m~310m. It can be seen that the position of the second communication device relative to the first communication device obtained after the second detection exceeds the preset range. Therefore, it can be determined that a man-in-the-middle attack may exist, thereby triggering man-in-the-middle detection.

[0144] (4) The first communication device detects a change in the radio frequency fingerprint characteristics of the signal received by the first communication device. It should be noted that radio frequency fingerprint refers to the distortion of radio electromagnetic waves during reception and transmission caused by imperfections in the manufacturing process of radio frequency devices. For example, as shown in Figures 10(a) and 10(b), the same pilot signal received on two different devices has different fingerprint characteristics. When a man-in-the-middle attack causes the connection link of the first communication device to switch from the second communication device to the attacker's communication device, its radio frequency fingerprint characteristics will also change, thereby triggering man-in-the-middle detection.

[0145] In the second implementation method, the second feature information can also be actively sent by the second communication device to the first communication device (i.e., without the first communication device actively requesting to trigger it).

[0146] Alternatively, the second feature information may be periodically sent from the second communication device to the first communication device. For example, the period for the second communication device to send the second feature information to the first communication device is 10 μs, 10 ms, or 10 s.

[0147] Step S805: The first communication device determines whether a man-in-the-middle attack exists based on the first feature information and the second feature information.

[0148] As one possible implementation, the first reference information includes a first positioning reference signal, which is used to measure at least one of the distance, signal strength, and angle of the second communication device to obtain a measurement result. The position information of the second communication device is used as the first feature information, and the position information of the second communication device is determined based on the measurement result and the position information of the first communication device.

[0149] For example, the location information of the first communication device is (40°03′54.90″N, 116°20′29.30″E), the frequency of the first positioning reference signal is 15kHz, and the measurement result obtained by the first communication device in measuring the second communication device based on the first positioning reference signal is that the distance between the first communication device and the second communication device is 300m, or the signal strength of the second communication device is -40dBm, or the azimuth angle of the second communication device relative to the first communication device is 20° in the southwest direction. Based on the measurement result and the location information of the first communication device, the first communication device determines a more accurate location information of the second communication device, which is (40°12′66.90″N, 116°36′78.30″E). Finally, the location information of the second communication device is used as the first feature information. Optionally, the second reference information includes a second positioning reference signal, which is used to measure at least one of the distance, signal strength, and angle of the second communication device to obtain a measurement result. The position information of the second communication device is used as the second feature information, and the position information of the second communication device is determined based on the measurement result and the position information of the first communication device. Further optionally, the second positioning reference signal is determined based on the offset of the positioning reference signal or the periodic interval of the positioning reference signal.

[0150] For example, the location information of the first communication device is (40°03′54.90″N, 116°20′29.30″E), the frequency of the second positioning reference signal is 13kHz, and the measurement result obtained by the first communication device in measuring the second communication device according to the first positioning reference signal is that the distance between the first communication device and the second communication device is 302m, or the signal strength of the second communication device is -42dBm, or the azimuth angle of the second communication device relative to the first communication device is 20° in the southwest direction. The first communication device determines a more accurate location information of the second communication device based on the measurement result and the location information of the first communication device. The location information of the second communication device is (40°12′66.90″N, 116°36′78.30″E), and finally the location information of the second communication device is used as the second feature information.

[0151] As can be seen from the above examples, if the first communication device compares the first feature information and the second feature information and determines that they are consistent, it indicates that there is no man-in-the-middle in the current connection process. However, if the first communication device compares the first feature information and the second feature information and determines that they are inconsistent, it indicates that there is a man-in-the-middle in the current connection process. In some implementations, if the first communication device compares the first feature information and the second feature information and determines that their positional deviation is within a threshold range, it indicates that there is no man-in-the-middle in the current connection process. However, if the first communication device compares the first feature information and the second feature information and determines that their positional deviation is outside the threshold range, it indicates that there is a man-in-the-middle in the current connection process.

[0152] Alternatively, the second reference information may be specific reference information sent by the second communication device according to the needs of the first communication device, or it may be non-specific reference information sent by the second communication device itself (i.e., unaffected by the needs of the first communication device).

[0153] As one possible implementation, the first reference information includes the identification information of the first communication device and the identification information of the second communication device, and the first feature information is a random sequence generated based on the identification information of the first communication device and the identification information of the second communication device.

[0154] For example, the random sequence can be generated by the second communication device using the identification information of the first communication device and the local timestamp of the second communication device as random seeds, and then using a pseudorandom number generator (PNG). This process can also be expressed by the formula: Signal = PNG(id, Timestamp). Finally, the random sequence is used as the first feature information. The first communication device stores the acquired first feature information as the root feature of the initial connection with the second communication device.

[0155] For example, the random sequence can be generated by the second communication device using the identification information of the first communication device and the root key of the second communication device as random seeds, and then using PNG. This process can also be expressed by the formula: Signal = PNG(id, key). Finally, the random sequence is used as the first feature information. The first communication device stores the acquired first feature information as the root feature for the initial connection with the second communication device.

[0156] In some implementations, the random sequence is generated by a random number chip in a second communication device.

[0157] In another implementation, the random sequence can be obtained by the second communication device from other devices. For example, the random sequence can be sent from the core network to the second communication device.

[0158] In some implementations, after obtaining the first feature information, the second feature information can be obtained from the first feature information by the first communication device. Optionally, the second reference information is information obtained based on the first feature information and the third reference information. Further optionally, the third reference information includes first channel information. The first channel is the channel through which the second feature information is received. Optionally, the first channel information includes at least one of SFN, frequency center point, RB start position, etc. For example, the first channel is channel A. Further optionally, the third reference information also includes at least one of the following: the index value of the second feature information, the identification information of the first communication device, and the identification information of the second communication device.

[0159] There are many ways to obtain the second feature information based on the first feature information. Optionally, the second feature information can be obtained from the first feature information through a one-way deduction algorithm under a counter, such as by deduction using a hash algorithm. A counter is used to prevent the second feature information obtained from the first feature information from remaining unchanged each time, thus preventing man-in-the-middle attacks. For example, as shown in Figure 11, the counter value obtained is: counter x + UEID + BSID + channel ID. Here, the counter value represents the third reference information, counter x represents the index value of the second feature information, UE ID represents the identification information of the first communication device, BS ID represents the identification information of the second communication device, and channel ID represents the identification information of the first channel. For example, the value of counter x can be used to indicate a timestamp; for example, the index has four levels: 1, 2, 3, 4, and 5. The sampling time point corresponding to counter 1 is 5ms, counter 2 is 10ms, counter 3 is 15ms, counter 4 is 20ms, and counter 5 is 25ms.

[0160] Optionally, the second feature information can also be obtained by encrypting the count value obtained by the counter using an encryption algorithm (such as AES). In this scheme, the first communication device decrypts the received second feature information using the first feature information stored locally. If the decrypted value is different from the expected count value, it will lead to an inconsistency between the first feature information and the second feature information, indicating the existence of a man-in-the-middle attack.

[0161] In one possible implementation, when a triggering condition is met, such as when the first communication device receives a handover command, the first communication device sends a first request message to the second communication device. This first request message requests the second communication device to send second feature information, which is information determined based on the second reference information of the second communication device. The first communication device compares the feature information it generates locally based on the first feature information with the second feature information to determine if a man-in-the-middle attack exists. For example, when there is no man-in-the-middle attack, the identifier information of the second communication device is BS_001; when there is a man-in-the-middle attack, the identifier information of the second communication device is BS_002. However, the identifier information of the second communication device that has established a secure connection with the first communication device is BS_001, indicating a discrepancy. Furthermore, when there is no man-in-the-middle attack, the first and second communication devices communicate on channel A, and the channel IDs of the two channels are identical. When a man-in-the-middle attack exists, the first communication device communicates with the fake base station on channel A, and the second communication device communicates with the fake terminal on channel B, resulting in a discrepancy in the channel IDs of the two channels. For example, when there is no man-in-the-middle attack, the first communication device generates a counter value of 1 locally based on the first feature information, and the counter value in the second feature information is also 1. At this time, the two counter values ​​are consistent. When there is a man-in-the-middle attack, the first communication device generates a counter value of 1 locally based on the first feature information, and the counter value in the second feature information is 3. At this time, the two counter values ​​are inconsistent.

[0162] In summary, when any of the above parameters changes, causing the final obtained second feature information to be inconsistent with the feature information generated locally by the first communication device based on the first feature information, it indicates that a man-in-the-middle attack exists.

[0163] As another possible implementation, the first and second feature information are obtained through public key exchange, and the first communication device can use this method to determine whether a man-in-the-middle attack exists.

[0164] Optionally, the first feature information includes a target key, and the second feature information is information obtained based on the target key and the first channel information. Further optionally, the target key can be obtained based on a first public key and a second public key, where the first public key is obtained based on a first private key, a first public key, and a second public key, and the second public key is a public key sent by the second communication device. For example, as shown in FIG12, the first communication device and the second communication device each prepare a first private key A and a second private key B (where A and B are both positive integers). The first communication device sends a first public key G and a second public key P to the second communication device (where G and P are also positive integers, and G and P ≠ 1). Then, the first public key and the second public key exchanged by the first communication device and the second communication device are respectively G... A modP, G B modP. In some implementations, for G A modP, G B In terms of mod P, G is smaller and P is larger. For example, when G is 2, P is 9. In (G A modP) B =(G B modP) A =G AB When modP holds true, the first and second communication devices respectively obtain the common target key G. AB modP, ultimately the target key G AB modP serves as the first characteristic information for the initial connection between the first and second communication devices.

[0165] In some implementations, after obtaining the first feature information, the first communication device can obtain the second feature information based on the first feature information. Optionally, the second reference message is information obtained based on the first feature information and the third reference information. Further optionally, the third reference information includes first channel information. The first channel is the channel through which the second feature information is received. Optionally, the first channel information includes SFN, frequency center point, RB start position, etc. For example, the first channel is channel A. Further optionally, the third reference information also includes the index value of the second feature information, the identification information of the first communication device, and the identification information of the second communication device.

[0166] There are many ways to obtain the second feature information based on the first feature information. For example, as shown in FIG13, the first public key and the second public key exchanged between the first communication device and the second communication device are G and G, respectively. AC mod P and G BC mod P, where C is the channel information of the channel currently connected to the first and second communication devices, such as the channel ID. In (G BC modP)A =(G AC modP) B =G ABC When modP holds true, both parties eventually obtain the common second feature information G. ABC mod P. When a man-in-the-middle exists, the first and second communication devices communicate on different channels (e.g., the first communication device communicates with the fake base station on channel C1, and the second communication device communicates with the fake terminal on channel C2). The first and second communication devices cannot negotiate a common second feature information, and the local second feature information obtained by the first communication device is (G). AB modP) C 1 = G ABC 1 mod P, the feature information obtained by the second communication device is G ABC 2 mod P shows that C is inconsistent, which means that the channel IDs of the two are inconsistent, so it can be concluded that there is a man-in-the-middle.

[0167] Optionally, when the first communication device sends a first request message to the second communication device, the common parameters required for the above-mentioned interaction process, such as G and P, can be provided together, and the interaction of these common parameters does not require encryption.

[0168] In one possible implementation, during the process of a first communication device receiving a handover command from a second communication device and switching to a new communication device (e.g., a third communication device), the first communication device disconnects from the second communication device and then connects to the third communication device via random access. However, this handover process is highly vulnerable to man-in-the-middle attacks. To combat man-in-the-middle attacks when switching to a new communication device, cached data from the second communication device can be migrated to the third communication device during the handover. The cached data in the second communication device is forwarded using higher-level protocols (e.g., encrypted forwarding via the RRC layer). During this process, the feature information stored in the second communication device is also migrated to the third communication device. This ensures that although the connection is now established with the third communication device, the authentication is still based on the secure feature information already established between the second and first communication devices, thus guaranteeing communication security. In the scenario of switching to a new communication device, the physical characteristics of the third communication device have changed (e.g., its location has changed). Optionally, the migration feature information can be first feature information and second feature information obtained based on public key exchange, or it can be a random sequence generated based on the identification information of the first communication device and the identification information of the first communication device as the first feature information, and information obtained based on the first feature information and the third reference information as the second feature information.

[0169] For example, as shown in Figure 14, the steps for detecting man-in-the-middle attacks during the process of the first communication device switching from the second communication device to the third communication device are as follows:

[0170] (1) The second communication device sends the first feature information to the third communication device.

[0171] Accordingly, the third communication device receives and stores the first feature information from the second communication device.

[0172] Optionally, the second communication device may actively send the first feature information to the third communication device, or it may send the first feature information to the third communication device based on a request from the third communication device.

[0173] Optionally, the second communication device may also send first reference information to the third communication device, and after receiving the first reference information, the third communication device obtains the first feature information based on the first reference information.

[0174] (2) The second communication device sends a switching command to the first communication device.

[0175] Accordingly, the first communication device receives a switching command from the second communication device.

[0176] The switching instruction is used to instruct the first communication device to establish a communication connection with the third communication device.

[0177] (3) The first communication device sends a second request message to the third communication device.

[0178] The second request message is used to request the third communication device to send the fourth reference information or the third feature information.

[0179] The third feature information is determined based on the fourth reference information.

[0180] Optionally, the fourth reference message is information obtained based on the first feature information and the third reference information. Optionally, the third reference information includes first channel information. The first channel is the channel through which the second feature information is received. Optionally, the first channel information includes at least one of SFN, frequency center point, RB start position, etc. For example, the first channel is channel A. Further optionally, the third reference information also includes at least one of the following: the index value of the second feature information, the identification information of the first communication device, and the identification information of the second communication device.

[0181] There are many ways to obtain the third feature information based on the first feature information. Optionally, the third feature information can be obtained from the first feature information through a one-way deduction algorithm under a counter, such as through a hash algorithm. A counter is used to prevent the third feature information obtained from the first feature information from remaining unchanged each time, thus preventing man-in-the-middle attacks. For example, the counter value obtained is: counter x + UEID + BSID + channel ID. Here, the counter value represents the third reference information, counter x represents the index value of the third feature information, UE ID represents the identification information of the first communication device, BS ID represents the identification information of the second communication device, and channel ID represents the identification information of the first channel. For example, the value of counter x can be used to indicate a timestamp, for example, with four index levels: 1, 2, 3, 4, and 5. Counter 1 corresponds to a sampling time point of 5ms, counter 2 to a sampling time point of 10ms, counter 3 to a sampling time point of 15ms, counter 4 to a sampling time point of 20ms, and counter 5 to a sampling time point of 25ms.

[0182] (4) The third communication device sends the fourth reference information or the third feature information to the first communication device.

[0183] Accordingly, the first communication device receives the fourth reference information or the third feature information.

[0184] Optionally, after receiving the fourth reference information, the first communication device obtains the third feature information based on the fourth reference information.

[0185] (5) The first communication device determines whether a man-in-the-middle attack exists based on the stored first feature information and third feature information.

[0186] As can be seen from the above example, if the first communication device compares the first feature information and the third feature information and determines that they are consistent, it indicates that there is no man-in-the-middle in the current connection process. However, if the first communication device compares the first feature information and the third feature information and determines that they are inconsistent, it indicates that there is a man-in-the-middle in the current connection process.

[0187] For example, when there is no man-in-the-middle attack, the identification information of the second communication device is BS_001; when there is a man-in-the-middle attack, the identification information of the second communication device is BS_002. However, the identification information of the second communication device that establishes a secure connection with the first communication device is BS_001, showing a discrepancy. Furthermore, when there is no man-in-the-middle attack, the first and second communication devices communicate on channel A, and the channel IDs of the two channels are the same; when there is a man-in-the-middle attack, the first communication device communicates with the fake base station on channel A, and the second communication device communicates with the fake terminal on channel B, resulting in different channel IDs. Moreover, when there is no man-in-the-middle attack, the first communication device generates a counter value of 1 locally based on the first feature information, and the counter value in the third feature information is also 1, showing a consistency between the two counter values; when there is a man-in-the-middle attack, the first communication device generates a counter value of 1 locally based on the first feature information, and the counter value in the third feature information is 3, showing a discrepancy between the two counter values.

[0188] In summary, when any of the above parameters changes, causing the final obtained third feature information to be inconsistent with the feature information generated locally by the first communication device based on the first feature information, it indicates that a man-in-the-middle attack exists.

[0189] In some implementations, if the first communication device compares the first feature information and the third feature information and determines that their positional deviation is within a threshold range, it indicates that there is no man-in-the-middle in the current connection process. However, if the first communication device compares the first feature information and the third feature information and determines that their positional deviation is outside the threshold range, it indicates that there is a man-in-the-middle in the current connection process.

[0190] In this application, on the one hand, taking the first communication device as the terminal and the second communication device as the base station as an example, the terminal determines whether a man-in-the-middle attack exists based on a feature information verification process. The feature information is determined based on reference information from the second communication device, thus possessing device uniqueness as the base station's identity identifier. The first feature information reflects the identity information of the device initially communicating with the terminal. The second feature information obtained by the terminal reflects the identity information of the device currently communicating with the terminal. When the first and second feature information are inconsistent, it indicates that the identity information of the device initially securely communicating with the terminal is inconsistent with the identity information of the device currently communicating with the terminal, meaning they are not the same device. This suggests that the current communication network may have suffered a man-in-the-middle attack, enabling the terminal to promptly disconnect from the current device upon determining the existence of a man-in-the-middle attack, thus combating the attack and effectively ensuring communication security. On the other hand, because it does not involve operations such as verifying resource block identifier information, allocating resource parameters, or using timestamps for air interface latency detection, it reduces computational complexity and resource overhead.

[0191] The embodiment shown in Figure 8 provides a detailed explanation of the interaction principle between the first communication device and the second communication device. To facilitate understanding, the following examples, in conjunction with Figures 15A, 15B, and 15C, illustrate three specific cases in which the first communication device determines whether a man-in-the-middle attack exists.

[0192] Please refer to Figure 15A. Figure 15A is a flowchart illustrating how a first communication device determines whether a man-in-the-middle attack exists, according to an embodiment of this application. As shown in Figure 15A, the specific steps of Case 1 are as follows:

[0193] Step 11: The first communication device establishes a secure communication connection with the second communication device.

[0194] Step 12: The second communication device sends the first feature information to the first communication device.

[0195] Accordingly, the first communication device receives first feature information from the second communication device.

[0196] The first feature information is information determined based on the first reference information of the second communication device. The first reference information includes the identification information of the first communication device and the identification information of the second communication device. The first feature information is a random sequence generated based on the identification information of the first communication device and the identification information of the first communication device.

[0197] Step 13: The first communication device stores the first feature information.

[0198] It should be understood that steps 11-13 are in the initial connection phase of a legitimate link.

[0199] Step 14: The first communication device sends a first request message to the second communication device.

[0200] Accordingly, the second communication device receives a first request message from the first communication device.

[0201] Optionally, if the triggering condition is met, the first communication device sends a first request message to the second communication device.

[0202] The first request message is used to request second feature information. The second feature information is information determined based on second reference information of the second communication device. The second reference information is information obtained based on the first feature information and third reference information. The third reference information includes first channel information C (where C is the channel information of the currently connected channel between the first and second communication devices, such as channel ID), the index value counter of the second feature information, the identification information UE ID of the first communication device, and the identification information BS ID of the second communication device. The first channel is the channel for receiving the second feature information.

[0203] Step 15: The second communication device sends the second feature information to the first communication device.

[0204] Accordingly, the first communication device receives the second feature information from the second communication device.

[0205] Step 16: The first communication device determines whether a man-in-the-middle attack exists based on the first feature information and the second feature information.

[0206] For example, when there is no man-in-the-middle attack, the identification information of the second communication device is BS_001; when there is a man-in-the-middle attack, the identification information of the second communication device is BS_002. However, the identification information of the second communication device that establishes a secure connection with the first communication device is BS_001, showing a discrepancy. Similarly, when there is no man-in-the-middle attack, the first and second communication devices communicate on channel A, and the channel IDs of the two channels are identical. When a man-in-the-middle attack occurs, the first communication device communicates with the fake base station on channel A, and the second communication device communicates with the fake terminal on channel B, resulting in different channel IDs. Furthermore, when there is no man-in-the-middle attack, the counter value generated locally by the first communication device based on the first feature information is 1, and the counter value in the second feature information is also 1, resulting in identical counter values. When a man-in-the-middle attack occurs, the counter value generated locally by the first communication device based on the first feature information is 1, while the counter value in the second feature information is 3, resulting in different counter values.

[0207] In summary, when any of the above parameters changes, causing the final obtained second feature information to be inconsistent with the feature information generated locally by the first communication device based on the first feature information, it indicates that a man-in-the-middle attack exists.

[0208] It should be understood that steps 14-16 are in the man-in-the-middle attack detection phase.

[0209] Please refer to Figure 15B. Figure 15B is a schematic diagram of another process by which the first communication device determines whether a man-in-the-middle attack exists, as provided in an embodiment of this application. As shown in Figure 15B, the specific steps of Case 2 are as follows:

[0210] Step 21: The first communication device establishes a secure communication connection with the second communication device.

[0211] Step 22: The first communication device acquires the first feature information.

[0212] The first feature information is information determined based on the first reference information of the second communication device. The first reference information includes a first positioning reference signal, which is used to measure at least one of the distance, signal strength and angle of the second communication device to obtain a measurement result. The first feature information is the position information of the second communication device, which is determined based on the measurement result and the position information of the first communication device.

[0213] For example, the location information of the first communication device is (40°03′54.90″N, 116°20′29.30″E), the frequency of the first positioning reference signal is 15kHz, and the measurement result obtained by the first communication device in measuring the second communication device based on the first positioning reference signal is that the distance between the first communication device and the second communication device is 300m, or the signal strength of the second communication device is -40dBm, or the azimuth angle of the second communication device relative to the first communication device is 20° in the southwest direction. Based on the measurement result and the location information of the first communication device, the first communication device determines a more accurate location information of the second communication device, which is (40°12′66.90″N, 116°36′78.30″E). Finally, the location information of the second communication device is used as the first feature information.

[0214] Step 23: The first communication device stores the first feature information.

[0215] It should be understood that steps 21-23 are in the initial connection phase of a legitimate link.

[0216] Step 24: The first communication device acquires the second feature information.

[0217] Optionally, if the triggering condition is met, the first communication device obtains the second feature information based on the second reference information.

[0218] The second reference information includes a second positioning reference signal, which is used to measure at least one of the distance, signal strength, and angle of the second communication device to obtain a measurement result. The second feature information is the position information of the second communication device, which is determined based on the measurement result and the position information of the first communication device. The second positioning reference signal is determined based on the offset of the positioning reference signal or the periodic interval of the positioning reference signal.

[0219] For example, the location information of the first communication device is (40°03′54.90″N, 116°20′29.30″E), the frequency of the second positioning reference signal is 13kHz, and the measurement result obtained by the first communication device in measuring the second communication device according to the first positioning reference signal is that the distance between the first communication device and the second communication device is 302m, or the signal strength of the second communication device is -42dBm, or the azimuth angle of the second communication device relative to the first communication device is 20° in the southwest direction. The first communication device determines a more accurate location information of the second communication device based on the measurement result and the location information of the first communication device. The location information of the second communication device is (40°12′66.90″N, 116°36′78.30″E), and finally the location information of the second communication device is used as the second feature information.

[0220] Step 25: The first communication device determines whether a man-in-the-middle attack exists based on the first feature information and the second feature information.

[0221] As can be seen from the above examples, if the first communication device compares the first feature information and the second feature information and determines that they are consistent, it indicates that there is no man-in-the-middle in the current connection process. However, if the first communication device compares the first feature information and the second feature information and determines that they are inconsistent, it indicates that there is a man-in-the-middle in the current connection process. In some implementations, if the first communication device compares the first feature information and the second feature information and determines that their positional deviation is within a threshold range, it indicates that there is no man-in-the-middle in the current connection process. However, if the first communication device compares the first feature information and the second feature information and determines that their positional deviation is outside the threshold range, it indicates that there is a man-in-the-middle in the current connection process.

[0222] It should be understood that steps 24-25 are in the man-in-the-middle attack detection phase.

[0223] Please refer to Figure 15C, which is a schematic diagram of another process by which a first communication device determines whether a man-in-the-middle attack exists, according to an embodiment of this application. As shown in Figure 15C, the specific steps of Case 3 are as follows:

[0224] Step 31: The first communication device establishes a secure communication connection with the second communication device.

[0225] Step 32: The second communication device exchanges the first public key and the second public key with the first communication device to obtain the first feature information.

[0226] The first feature information includes the target key.

[0227] For example, the first communication device and the second communication device each prepare a first private key A and a second private key B (where A and B are both positive integers). The first communication device sends a first public key G and a second public key P to the second communication device (where G and P are also positive integers, and G and P ≠ 1). Then, the first public key and the second public key exchanged by the first communication device and the second communication device are respectively G A modP, G B modP. In some implementations, for G A modP, G B In terms of mod P, G is smaller and P is larger. For example, when G is 2, P is 9. In (G A modP) B =(G B modP) A =G AB When modP holds true, the first and second communication devices respectively obtain the common target key G. AB modP, ultimately the target key G AB modP serves as the first characteristic information for the initial connection between the first and second communication devices.

[0228] Step 33: The first communication device stores the first feature information.

[0229] It should be understood that steps 31-33 are in the initial connection phase of a legitimate link.

[0230] Step 34: The first communication device sends a first request message to the second communication device.

[0231] Accordingly, the second communication device receives a first request message from the first communication device.

[0232] Optionally, if the triggering condition is met, the first communication device sends a first request message to the second communication device.

[0233] The first request message is used to request the second feature information. The second feature information is information obtained based on the target key and the first channel information.

[0234] Step 35: The first communication device and the second communication device exchange the first public key and the first channel information, as well as the second public key and the first channel information, to obtain the second feature information.

[0235] Step 36: The first communication device determines whether a man-in-the-middle attack exists based on the first feature information and the second feature information.

[0236] For example, the first public key and the second public key exchanged between the first communication device and the second communication device are G and G, respectively. AC mod P and G BC mod P, where C is the channel information of the channel currently connected to the first and second communication devices, such as the channel ID. In (G BC modP) A =(G AC modP) B =G ABC When modP holds true, both parties eventually obtain the common second feature information G. ABC mod P. When a man-in-the-middle exists, the first and second communication devices communicate on different channels (e.g., the first communication device communicates with the fake base station on channel C1, and the second communication device communicates with the fake terminal on channel C2). The first and second communication devices cannot negotiate a common second feature information, and the local second feature information obtained by the first communication device is (G). AB modP) C 1 = G ABC 1 mod P, the feature information obtained by the second communication device is G ABC 2 mod P shows that C is inconsistent, which means that the channel IDs of the two are inconsistent, so it can be concluded that there is a man-in-the-middle.

[0237] It should be understood that steps 34-36 are in the man-in-the-middle attack detection phase.

[0238] It should be noted that detailed explanations of steps 11-16, 21-25, and 31-36 above can be found in the embodiment described in Figure 8, and will not be repeated here.

[0239] The methods of the embodiments of this application have been described in detail above. The apparatus of the embodiments of this application is provided below.

[0240] It should be understood that the division of units in the apparatus provided in this application embodiment is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units in the apparatus can be implemented by a processor calling software. For example, the apparatus includes a processor connected to a memory, which stores instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of each unit of the apparatus. The processor is, for example, a general-purpose processor, such as a central processing unit (CPU) or a microprocessor, and the memory is either internal or external to the apparatus.

[0241] Alternatively, the units in the device can be implemented as hardware circuits. The functionality of some or all of the units can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the above units is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through a configuration file, thereby achieving the functionality of some or all of the above units.

[0242] In the embodiments of this application, each unit in the device may be one or more processors (or processing circuits) configured to implement the above methods, such as: CPU, graphics processing unit (GPU), neural network processing unit (NPU), tensor processing unit (TPU), deep learning processing unit (DPU), microprocessor unit (MPU), digital signal processor (DSP), ASIC, FPGA, or a combination of at least two of these processor forms.

[0243] Furthermore, the units in the above devices can be integrated in whole or in part, or they can be implemented independently. In one implementation, these units are integrated together as a system-on-a-chip (SOC). The SOC may include at least one processor for implementing any of the above methods or for implementing the functions of the units in the device. The at least one processor can be of different types, such as including a CPU and an FPGA, or including a CPU and an AI processor, or including a CPU and a GPU, etc. Several possible devices are listed below.

[0244] Please refer to Figure 16, which is a schematic diagram of the structure of a communication device 160 provided in an embodiment of this application. Optionally, the communication device 160 can be an independent device, such as a terminal. Alternatively, the communication device 160 can also be a component in an independent device (such as a terminal), such as a chip or integrated circuit. The communication device 160 is used to implement the aforementioned communication method, such as the communication method shown in Figure 8.

[0245] In one possible design, the communication device 160 includes a communication unit 1601 and a processing unit 1602. The communication device 160 is used to implement the aforementioned communication method, such as the communication method shown in FIG8. Exemplarily, the communication device is used, for example, to execute the method executed by the first communication device.

[0246] In one possible implementation, the communication unit 1601 is configured to acquire second feature information, wherein the second feature information is information determined based on second reference information of the second communication device. The processing unit 1602 is configured to determine whether a man-in-the-middle attack exists based on the first feature information and the second feature information, wherein the first feature information is determined based on the first reference information.

[0247] In another possible implementation, the communication unit 1601 is further configured to receive the first reference information and determine the first feature information based on the first reference information; or, receive the first feature information.

[0248] In another possible implementation, the first reference information or the first feature information is information sent when the second communication device and the first communication device have established a secure communication connection.

[0249] In another possible implementation, the communication unit 1601 is further configured to send a first request message to the second communication device, wherein the first request message is configured to request the second communication device to send the second reference information or the second feature information.

[0250] In another possible implementation, in terms of sending the first request message to the second communication device, the communication unit 1601 is specifically configured to: send the first request message to the second communication device when a triggering condition is met.

[0251] In another possible implementation, the triggering condition includes at least one of the following: receiving a switching command, detecting that the air interface delay is greater than a first preset value, detecting that the relative position between the second communication device and the first communication device exceeds a preset range, or detecting that the radio frequency fingerprint characteristics of the signal received by the first communication device have changed.

[0252] In another possible implementation, the first reference information includes the identification information of the first communication device and the identification information of the second communication device, and the first feature information is a random sequence generated based on the identification information of the first communication device and the identification information of the first communication device.

[0253] In another possible implementation, the second reference information is information obtained based on the first feature information and the third reference information, wherein the third reference information includes first channel information, and the first channel is the channel for receiving the second feature information.

[0254] In another possible implementation, the third reference information further includes at least one of the following: the index value of the second feature information, the identification information of the first communication device, and the identification information of the second communication device.

[0255] In another possible implementation, the second feature information is information derived from the second reference information using a one-way deduction algorithm.

[0256] In another possible implementation, the first feature information includes a target key, and the second reference information is information obtained based on the target key and the first channel information.

[0257] In another possible implementation, the target key is obtained based on a first public key and a second public key, wherein the first public key is obtained based on a first private key, a first public key, and a second public key, and the second public key is a public key sent by the second communication device.

[0258] In another possible implementation, the first reference information includes a first positioning reference signal, which is used to measure at least one of the distance, signal strength and angle of the second communication device to obtain a measurement result, and the second feature information is the position information of the second communication device, which is determined based on the measurement result and the position information of the first communication device.

[0259] In another possible implementation, the second reference information includes a second positioning reference signal, which is used to measure at least one of the distance, signal strength, and angle of the second communication device to obtain a measurement result. The position information of the second communication device is used as the first feature information, and the position information of the second communication device is determined based on the measurement result and the position information of the first communication device.

[0260] In another possible implementation, the second positioning reference signal is determined based on the offset of the positioning reference signal or the periodic interval of the positioning reference signal.

[0261] In another possible implementation, the communication unit 1601 is further configured to receive a switching instruction from the second communication device, wherein the switching instruction is used to instruct the first communication device to establish a communication connection with the third communication device. The communication unit 1601 is further configured to send a second request message to the third communication device, wherein the second request message is used to request the third communication device to send fourth reference information or third feature information, wherein the third feature information is determined based on the fourth reference information. The communication unit 1601 is further configured to receive the fourth reference information and determine the third feature information based on the fourth reference information; or, receive the third feature information. The processing unit 1602 is further configured to determine whether a man-in-the-middle attack exists based on the stored first feature information and the third feature information.

[0262] The embodiments of this application and the method embodiments shown above are based on the same concept and have the same technical effects. For the specific principles, please refer to the description of the embodiments shown above, which will not be repeated here.

[0263] Please refer to Figure 17, which is a schematic diagram of another communication device 170 provided in an embodiment of this application. Optionally, the communication device 170 can be a standalone device, such as a network device. Alternatively, the communication device 170 can also be a component in a standalone device (such as a network device), such as a chip or integrated circuit. The communication device 170 is used to implement the aforementioned communication method, such as the communication method shown in Figure 8.

[0264] In one possible design, the communication device 170 includes a communication unit 1701 and a processing unit 1702. The communication device 170 is used to implement the aforementioned communication method, such as the communication method shown in FIG8. Exemplarily, the communication device may be used to execute a method executed by a second communication device.

[0265] In one possible implementation, the communication unit 1701 is used to send and receive data. The processing unit 1702 is used to determine first reference information and second reference information, wherein the first reference information is used to determine first feature information, the second reference information is used to determine second feature information, and the first feature information and the second feature information are used to determine whether a man-in-the-middle attack exists.

[0266] In another possible implementation, the communication unit 1701 is further configured to send the second reference information or the second feature information to the first communication device.

[0267] In another possible implementation, the communication unit 1701 is further configured to send the first reference information or the first feature information to the first communication device.

[0268] In another possible implementation, the first reference information or the first feature information is information sent when the second communication device and the first communication device have established a secure communication connection.

[0269] In another possible implementation, the communication unit 1701 is further configured to receive a first request message from the first communication device, wherein the first request message is configured to request the second communication device to send the second reference information or the second feature information.

[0270] In another possible implementation, the communication unit 1701 is further configured to send a switching instruction to the first communication device, wherein the switching instruction is configured to instruct the first communication device to establish a communication connection with the third communication device.

[0271] In another possible implementation, the communication unit 1701 is further configured to send the first feature information to the third communication device, or to send the first reference information to the third communication device.

[0272] The embodiments of this application and the method embodiments shown above are based on the same concept and have the same technical effects. For the specific principles, please refer to the description of the embodiments shown above, which will not be repeated here.

[0273] Please refer to Figure 18, which is a schematic diagram of another communication device 180 provided in an embodiment of this application. The communication device 180 can be a standalone device, such as a terminal or network device, or a component included in a standalone device, such as a chip, software module, or integrated circuit. The communication device 180 may include at least one processor 1801 and a communication interface 1802. Optionally, it may also include at least one memory 1803. Further optionally, it may also include a connection line 1804, wherein the processor 1801, the communication interface 1802, and / or the memory 1803 are connected via the connection line 1804, and / or communicate with each other via the connection line 1804 to transmit control signals and / or data signals.

[0274] Wherein: Processor 1801 is a module that performs arithmetic and / or logical operations, and may specifically include one or more of the following modules: filter, modem, power amplifier, low noise amplifier (LNA), baseband processor, radio frequency processor, radio frequency circuit, CPU, AP, microcontroller unit (MCU), electronic control unit (ECU), GPU, MPU, ASIC, image signal processor (ISP), DSP, FPGA, complex programmable logic device (CPLD), or coprocessor, etc.

[0275] The communication interface 1802 can be used to provide information input or output to at least one processor, or to receive signals sent externally and / or send signals externally.

[0276] For example, the communication interface 1802 may include interface circuitry, such as input / output interfaces, chip pins, etc.

[0277] For example, the communication interface 1802 may include a wired link interface such as an Ethernet cable, or a wireless link interface (Wi-Fi, Bluetooth, general wireless transmission, vehicle short-range communication technology and other short-range wireless communication technologies, etc.).

[0278] Optionally, the communication interface 1802 may also include a radio frequency transmitter, an antenna, etc. When the communication interface 1802 includes an antenna, the number of antennas can be one or more.

[0279] As one possible design, if the communication device 180 is a standalone device, the communication interface 1802 may include a receiver and a transmitter. The receiver and transmitter may be the same component or different components. When the receiver and transmitter are the same component, this component may be referred to as a transceiver.

[0280] As another possible design, if the communication device 180 is a chip or circuit, the communication interface 1802 may include an input interface and an output interface, which may be the same interface or different interfaces.

[0281] Alternatively, the functionality of the communication interface 1802 can be implemented via transceiver circuitry or a dedicated transceiver chip.

[0282] The memory 1803 provides storage space, in which data such as the operating system and computer programs can be stored. The memory 1803 can be one or a combination of several of the following: cache, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), compact disc read-only memory (CD-ROM), synchronous dynamic random access memory (SDRAM), hard disk drive (HDD), solid-state drive (SSD), etc. Memory is any other medium capable of carrying or storing desired program code in the form of instructions or data structures, and accessible by a computer, but is not limited thereto. The memory in the embodiments of this application can also be a circuit or any other device capable of implementing storage functions, used to store computer programs or instructions, and / or data.

[0283] The functions and operations of each module or unit in the communication device 180 listed above are merely illustrative examples.

[0284] Each functional unit in the communication device 180 can be used to implement the aforementioned communication method, such as the communication method shown in FIG8, FIG15A, FIG15B, and FIG15C, for example, to execute the method executed by the first communication device, or to execute the method executed by the second communication device.

[0285] Optionally, the processor 1801 may be a processor specifically designed to perform the aforementioned methods (for ease of distinction, referred to as a dedicated processor), or a processor that performs the aforementioned methods by calling a computer program (for ease of distinction, referred to as a dedicated processor). Optionally, at least one processor may include both dedicated processors and general-purpose processors.

[0286] Optionally, if the communication device 180 includes at least one memory 1803, and the processor 1801 implements the aforementioned communication method by calling a computer program, the computer program can be stored in the memory 1803.

[0287] This application also provides a chip including logic circuitry and a communication interface. The communication interface is used to receive or transmit signals; the logic circuitry is used to receive or transmit signals through the communication interface. The chip is used to implement the aforementioned communication methods, such as the communication methods shown in Figures 8, 15A, 15B, and 15C, for example, to execute a method executed by a first communication device, or to execute a method executed by a second communication device.

[0288] This application also provides a computer-readable storage medium storing instructions that, when executed on at least one processor (or communication device), implement the aforementioned communication method, such as the communication methods shown in FIG8, FIG15A, FIG15B, and FIG15C, for example, for executing a method executed by a first communication device, or for executing a method executed by a second communication device.

[0289] This application also provides a computer program product, which includes computer instructions for implementing the aforementioned communication methods, such as the communication methods shown in FIG8, FIG15A, FIG15B, and FIG15C, for example, for executing a method executed by a first communication device or network device, or for executing a method executed by a second communication device.

[0290] It should be noted that, in the embodiments of this application, the words "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design scheme described as "exemplarily" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the words "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner.

[0291] In the embodiments of this application, "at least one" refers to one or more items, and "more than one" refers to two or more items. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items.

[0292] For example, at least one of a, b, or c can be represented as: a, b, c, (a and b), (a and c), (b and c), or (a and b and c), where a, b, and c can be single or multiple. "AND / OR" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects have an "OR" relationship.

[0293] Furthermore, unless otherwise stated, the use of ordinal numbers such as "first" and "second" in the embodiments of this application is for distinguishing multiple objects and is not for limiting the order, sequence, priority, or importance of multiple objects. Similarly, terms like "first node" and "second node" are merely for convenience in describing new parameters in different implementations and do not indicate differences in their execution operations, importance, structure, etc.

[0294] In the above embodiments, the term "when..." can be interpreted, depending on the context, as meaning "if...", "before...", "determined...", or "detected...". The above descriptions are merely optional embodiments of this application and are not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the concept and principles of this application should be included within the protection scope of this application.

[0295] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.

Claims

1. A communication method, characterized in that, Applied to a first communication device, the method includes: Acquire second feature information, wherein the second feature information is information determined based on second reference information of the second communication device; The existence of a man-in-the-middle attack is determined based on the first feature information and the second feature information, wherein the first feature information is determined based on the first reference information.

2. The method according to claim 1, characterized in that, The method further includes: Receive the first reference information, and determine the first feature information based on the first reference information; or... Receive the first feature information.

3. The method according to claim 2, characterized in that, The first reference information or the first feature information is information sent when the second communication device and the first communication device have established a secure communication connection.

4. The method according to any one of claims 1-3, characterized in that, Before obtaining the second feature information, the method further includes: Send a first request message to the second communication device, wherein the first request message is used to request the second communication device to send the second reference information or the second feature information.

5. The method according to claim 4, characterized in that, Sending the first request message to the second communication device includes: If the triggering conditions are met, the first request message is sent to the second communication device.

6. The method according to claim 5, characterized in that, The triggering condition includes at least one of the following: Received switching instruction; The air interface delay detected is greater than the first preset value; The relative position between the second communication device and the first communication device is detected to be outside a preset range; or A change in the radio frequency fingerprint characteristics of the signal received by the first communication device was detected.

7. The method according to any one of claims 2-6, characterized in that, The first reference information includes the identification information of the first communication device and the identification information of the second communication device, and the first feature information is a random sequence generated based on the identification information of the first communication device and the identification information of the first communication device.

8. The method according to any one of claims 1-7, characterized in that, The second reference information is information obtained based on the first feature information and the third reference information. The third reference information includes first channel information, where the first channel is the channel for receiving the second feature information.

9. The method according to claim 8, characterized in that, The third reference information also includes at least one of the following: the index value of the second feature information, the identification information of the first communication device, and the identification information of the second communication device.

10. The method according to any one of claims 1-9, characterized in that, The second feature information is information derived from the second reference information using a one-way deduction algorithm.

11. The method according to claim 8, characterized in that, The first feature information includes a target key, and the second reference information is information obtained based on the target key and the first channel information.

12. The method according to claim 11, characterized in that, The target key is obtained based on a first public key and a second public key. The first public key is obtained based on a first private key, a first public key, and a second public key. The second public key is the public key sent by the second communication device.

13. The method according to any one of claims 2-6, characterized in that, The first reference information includes a first positioning reference signal, which is used to measure at least one of the distance, signal strength and angle of the second communication device to obtain a measurement result. The first feature information is the position information of the second communication device, which is determined based on the measurement result and the position information of the first communication device.

14. The method according to any one of claims 2-6, characterized in that, The second reference information includes a second positioning reference signal, which is used to measure at least one of the distance, signal strength and angle of the second communication device to obtain a measurement result. The second feature information is the position information of the second communication device, which is determined based on the measurement result and the position information of the first communication device.

15. The method according to claim 14, characterized in that, The second positioning reference signal is determined based on the offset of the positioning reference signal or the periodic interval of the positioning reference signal.

16. The method according to any one of claims 1-15, characterized in that, The method further includes: Receive a switching instruction from the second communication device, wherein the switching instruction is used to instruct the first communication device to establish a communication connection with the third communication device; Send a second request message to the third communication device, wherein the second request message is used to request the third communication device to send fourth reference information or third feature information, wherein the third feature information is determined based on the fourth reference information; Receive the fourth reference information and determine the third feature information based on the fourth reference information; or, receive the third feature information. The existence of a man-in-the-middle attack is determined based on the stored first feature information and the third feature information.

17. A communication method, characterized in that, Applied to a second communication device, the method includes: First reference information and second reference information are determined, wherein the first reference information is used to determine first feature information, the second reference information is used to determine second feature information, and the first feature information and the second feature information are used to determine whether a man-in-the-middle attack exists.

18. The method according to claim 17, characterized in that, The method further includes: Send the second reference information or the second feature information to the first communication device.

19. The method according to claim 17 or 18, characterized in that, The method further includes: Send the first reference information or the first feature information to the first communication device.

20. The method according to claim 19, characterized in that, The first reference information or the first feature information is information sent when the second communication device and the first communication device have established a secure communication connection.

21. The method according to any one of claims 18-20, characterized in that, Before sending the second reference information or the second feature information to the first communication device, the method further includes: A first request message is received from the first communication device, wherein the first request message is used to request the second communication device to send the second reference information or the second feature information.

22. The method according to any one of claims 17-21, characterized in that, The method further includes: A switching instruction is sent to the first communication device, wherein the switching instruction is used to instruct the first communication device to establish a communication connection with the third communication device.

23. The method according to any one of claims 17-22, characterized in that, The method further includes: The first feature information is sent to the third communication device, or the first reference information is sent to the third communication device.

24. A communication device, characterized in that, The communication device includes a communication unit and a processing unit, the communication unit and the processing unit being used to perform the method as described in any one of claims 1-16.

25. A communication device, characterized in that, The communication device includes a communication unit and a processing unit, the communication unit and the processing unit being used to perform the method as described in any one of claims 17-23.

26. A communication device, characterized in that, The communication device includes a processor; When the processor invokes a computer program or instruction in memory, it implements the method as described in any one of claims 1-16.

27. A communication device, characterized in that, The communication device includes a processor; When the processor invokes a computer program or instruction in memory, it implements the method as described in any one of claims 17-23.

28. A communication device, characterized in that, It includes logic circuits and interfaces, wherein the logic circuits and the interfaces are coupled; The interface is used for inputting and / or outputting information, and the logic circuit is used for performing the method as described in any one of claims 1-23.

29. The apparatus according to claim 28, characterized in that, The communication device is a chip or chip system.

30. A communication system, characterized in that, The communication system includes the communication device as described in claim 24 and the communication device as described in claim 25; or The communication system includes the communication device as described in claim 26 and the communication device as described in claim 27.

31. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store instructions or computer programs; When the instructions or the computer program are executed, the method described in any one of claims 1-23 is implemented.

32. A computer program product, characterized in that, include: Instructions or computer programs; When the instructions or the computer program are executed, the method described in any one of claims 1-23 is implemented.

Citation Information

Patent Citations

  • System information transmission method and device

    CN115567940A

  • Method and device for detecting pseudo base station

    CN116669034A

  • Encryption method and device based on channel secret key

    CN116866900A

  • Positioning reference signal attack detection in wireless communication network

    CN117099380A

  • Communication control device

    US20210144175A1