Communication methods, first terminal, second terminal, and communication device and system
By encrypting messages in multi-hop U2N and U2U relay scenarios, the problem of information being tampered with or stolen is solved, and privacy protection and security of information transmission are achieved.
Patent Information
- Application Number
- PCT/CN2024/092948
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-13
- Publication Date
- 2025-11-20
AI Technical Summary
In multi-hop U2N and U2U relay scenarios, information in messages is easily tampered with or stolen, and existing technologies have failed to effectively protect privacy.
By encrypting the path information and other sensitive information in the encrypted message using a key stream, and then decrypting and verifying it at the receiving end, the privacy of the information transmission is ensured.
It achieves effective encryption protection of information in multi-hop relay scenarios, preventing information from being tampered with or stolen, and ensuring communication security.
Smart Images

Figure CN2024092948_20112025_PF_FP_ABST
Abstract
Description
Communication method, first terminal, second terminal, communication device and system TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of communication, and in particular to a communication method, a first terminal, a second terminal, a communication device and a system. BACKGROUND
[0002] Support for discovery, selection, authorization, connection establishment and data transfer in single-hop proximity based services (ProSe) user equipment (UE) to network (UE-to-Network, U2N) relay service and single-hop ProSe UE-to-UE (UE-to-UE, U2U) relay service has been addressed in previous releases.
[0003] SUMMARY
[0004] Embodiments of the present disclosure provide a communication method, a first terminal, a second terminal, a communication device and a system.
[0005] According to a first aspect of embodiments of the present disclosure, a communication method is provided, performed by a first terminal, the first terminal being a terminal supporting multi-hop UE-to-Network (U2N) service or a terminal supporting multi-hop UE-to-UE (U2U) service, the method comprising:
[0006] sending, to a second terminal, a first message, the first message comprising encryption information, the encryption information comprising encrypted first information, the first information being used to determine a path from the first terminal to the second terminal.
[0007] According to a second aspect of embodiments of the present disclosure, a communication method is provided, performed by a second terminal, the second terminal being a terminal supporting multi-hop U2N service or a terminal supporting multi-hop U2U service, the method comprising:
[0008] receiving a first message sent by a first terminal, the first message comprising encryption information, the encryption information comprising encrypted first information, the first information being used to determine a path from the first terminal to the second terminal.
[0009] According to a third aspect of embodiments of the present disclosure, a first terminal is provided, the first terminal being a terminal supporting multi-hop U2N service or a terminal supporting multi-hop U2U service, the first terminal comprising:
[0010] The transceiver module is configured to send a first message to the second terminal, the first message comprising encryption information, the encryption information comprising encrypted first information, the first information being used to determine a path from the first terminal to the second terminal.
[0011] According to a fourth aspect of the embodiments of the present disclosure, a second terminal is provided, the second terminal being a terminal supporting a multi-hop U2N service or a terminal supporting a multi-hop U2U service, the second terminal comprising:
[0012] The transceiver module is configured to receive a first message sent by a first terminal, the first message comprising encryption information, the encryption information comprising encrypted first information, the first information being used to determine a path from the first terminal to the second terminal.
[0013] According to a fifth aspect of the embodiments of the present disclosure, a communication device is provided, comprising:
[0014] one or more processors;
[0015] The communication device is configured to perform the communication method according to the first aspect or the second aspect.
[0016] According to a sixth aspect of the embodiments of the present disclosure, a communication system is provided, comprising:
[0017] The first terminal is configured to implement the communication method according to the first aspect;
[0018] The second terminal is configured to implement the communication method according to the second aspect.
[0019] According to a seventh aspect of the embodiments of the present disclosure, a storage medium is provided, the storage medium storing instructions, when the instructions are executed on a communication device, causing the communication device to perform the communication method according to the first aspect or the second aspect.
[0020] According to an eighth aspect of the embodiments of the present disclosure, a computer program product is provided, comprising a computer program, the computer program being executed on a communication device to implement the communication method according to the first aspect or the second aspect.
[0021] The embodiments of the present disclosure can protect the privacy of information in messages in multi-hop U2N relay and / or multi-hop U2U relay scenarios. BRIEF DESCRIPTION OF DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following describes the drawings required for the embodiments, and the following drawings are only some embodiments of the present disclosure, and do not specifically limit the protection scope of the present disclosure.
[0023] FIG. 1A is an exemplary schematic diagram of an architecture of multi-hop U2N relay, according to an embodiment of the present disclosure.
[0024] FIG. 1B is an exemplary schematic diagram of an architecture of multi-hop U2N relay, according to an embodiment of the present disclosure.
[0025] FIG. 1C is an exemplary schematic diagram of an architecture of multi-hop U2U relay, according to an embodiment of the present disclosure.
[0026] FIG. 1D is an exemplary schematic diagram of an architecture of multi-hop U2U relay, according to an embodiment of the present disclosure.
[0027] FIG. 1E is an exemplary schematic diagram of an architecture of a communication system, according to an embodiment of the present disclosure.
[0028] FIG. 2 is an exemplary interaction diagram of a communication method, according to an embodiment of the present disclosure.
[0029] FIG. 3A is an exemplary flow diagram of a communication method, according to an embodiment of the present disclosure.
[0030] FIG. 3B is an exemplary flow diagram of a communication method, according to an embodiment of the present disclosure.
[0031] FIG. 3C is an exemplary flow diagram of a communication method, according to an embodiment of the present disclosure.
[0032] FIG. 4A is an exemplary flow diagram of a communication method, according to an embodiment of the present disclosure.
[0033] FIG. 4B is an exemplary flow diagram of a communication method, according to an embodiment of the present disclosure.
[0034] FIG. 4C is an exemplary flow diagram of a communication method, according to an embodiment of the present disclosure.
[0035] FIG. 5 is an exemplary interaction diagram of a communication method, according to an embodiment of the present disclosure.
[0036] FIG. 6A is an exemplary interaction diagram of a communication method provided by the architecture of multi-hop U2N relay shown in FIG. 1B.
[0037] FIG. 6B is an exemplary interaction diagram of a communication method provided by the architecture of multi-hop U2U relay shown in FIG. 1D.
[0038] FIG. 7A is an exemplary schematic diagram of a structure of a first terminal, according to an embodiment of the present disclosure.
[0039] FIG. 7B is an exemplary schematic diagram of a structure of a second terminal, according to an embodiment of the present disclosure.
[0040] FIG. 8A is an exemplary schematic diagram of a structure of a communication device according to an embodiment of the present disclosure.
[0041] FIG. 8B is an exemplary schematic diagram of a structure of a chip according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0042] Embodiments of the present disclosure provide a communication method, a first terminal, a second terminal, a communication device and a system.
[0043] In a first aspect, embodiments of the present disclosure provide a communication method, performed by a first terminal, the first terminal being a terminal supporting multi-hop user terminal to network (U2N) service or a terminal supporting multi-hop user terminal to user terminal (U2U) service, the method comprising:
[0044] sending, to a second terminal, a first message, the first message comprising encrypted information, the encrypted information comprising encrypted first information, the first information being used to determine a path from the first terminal to the second terminal.
[0045] In the above embodiments, the information in the message is protected (encrypted) for privacy in the multi-hop U2N relay and / or multi-hop U2U relay scenario, and the message carries the encrypted first information, which is used to determine the path in the multi-hop U2N relay and / or multi-hop U2U relay scenario.
[0046] In some embodiments of the first aspect, in some embodiments, the first information comprises one of:
[0047] path information from the first terminal to the second terminal;
[0048] a transaction ID, the transaction ID being used to determine the path from the first terminal to the second terminal.
[0049] In the above embodiments, the first information can be path information or identification information.
[0050] In some embodiments of the first aspect, in some embodiments, the method further comprises:
[0051] determining a key stream according to the first key;
[0052] encrypting second information according to the key stream to obtain the encrypted information, the second information comprising the first information.
[0053] In the above embodiments, the information to be protected can be encrypted according to the key stream. In some embodiments, encryption can also be performed in other ways.
[0054] In some embodiments of the first aspect, in some embodiments, the second information further comprises at least one of:
[0055] a relay service code (RSC);
[0056] user identification information.
[0057] In the above embodiments, the second information can comprise the RSC and / or the user identification information, and thus the RSC and / or the user identification information can be encrypted.
[0058] In some embodiments of the first aspect, in some embodiments, the first key is determined based on at least one of:
[0059] a discovery user confidentiality key (DUCK);
[0060] a discovery user scrambling key (DUSK);
[0061] a long term credential.
[0062] In the above embodiments, the encryption can be based on the security material of the discovery phase, e.g., the first key can be set as the DUCK, or the DUSK, or the long term credential.
[0063] In some embodiments of the first aspect, in some embodiments, the key stream is determined based on the first key and at least one of:
[0064] a counter based on Coordinated Universal Time (UTC);
[0065] a bearer;
[0066] direction information;
[0067] length information;
[0068] a RSC.
[0069] In the above embodiments, the key stream can be determined based on the first key, the counter based on UTC, the bearer, the direction information and the length information, or the key stream can also be determined based on the first key, the counter based on UTC and the RSC.
[0070] In some embodiments of the first aspect, in some embodiments, the key stream is set as N least significant bits of a Key derivation function (KDF) output, and N is a total length of the second information.
[0071] In the above embodiments, in order to encrypt the information to be protected, the length of the key stream is equal to the length of the information to be protected.
[0072] In a second aspect, the embodiments of the present disclosure provide a communication method, executed by a second terminal, the second terminal being a terminal supporting a multi-hop U2N service or a terminal supporting a multi-hop U2U service, the method comprising:
[0073] receiving a first message sent by a first terminal, the first message comprising encrypted information, the encrypted information comprising first information after encryption, the first information being used to determine a path from the first terminal to the second terminal.
[0074] In some embodiments of the second aspect, in some embodiments, the first information comprises one of:
[0075] path information of the first terminal to the second terminal;
[0076] transaction identification, the transaction identification being used to determine the path from the first terminal to the second terminal.
[0077] In some embodiments of the second aspect, in some embodiments, the method further comprises:
[0078] determining a key stream according to a first key;
[0079] decrypting the encrypted information according to the key stream to obtain second information, the second information comprising the first information.
[0080] In some embodiments of the second aspect, in some embodiments, the second information further comprises at least one of:
[0081] RSC;
[0082] user identification information.
[0083] In some embodiments of the second aspect, in some embodiments, the method further comprises at least one of:
[0084] based on the second information obtained after decryption being different from stored second information, determining to abort establishing a PC5 link between the second terminal and the first terminal;
[0085] based on decryption failure, determining to abort establishing the PC5 link.
[0086] In the above embodiments, the PC5 link between the first terminal and the second terminal can be established in the case of protecting privacy between the first terminal and the second terminal by decrypting the encrypted information in the first message to obtain the second information, and determining whether to suspend the establishment of the PC5 link between the second terminal and the first terminal by comparing whether the decrypted second information is the same as the second information stored in the second terminal, or based on whether the decryption is successful or fails.
[0087] In some embodiments in combination with the second aspect, in some embodiments, the first key is determined based on at least one of:
[0088] DUCK;
[0089] DUSK;
[0090] Long-term credential.
[0091] In some embodiments in combination with the second aspect, in some embodiments, the key stream is determined based on the first key and at least one of:
[0092] UTC-based counter;
[0093] Bearing;
[0094] Direction information;
[0095] Length information;
[0096] RSC.
[0097] In some embodiments in combination with the second aspect, in some embodiments, the key stream is set to N least significant bits of the KDF output, and the N is the total length of the second information.
[0098] In a third aspect, the embodiments of the present disclosure provide a first terminal, the first terminal being a terminal supporting a multi-hop U2N service or a terminal supporting a multi-hop U2U service, and the first terminal comprising:
[0099] A transceiver module configured to send a first message to a second terminal, the first message comprising encrypted information, the encrypted information comprising encrypted first information, the first information being used to determine a path from the first terminal to the second terminal.
[0100] In a fourth aspect, the embodiments of the present disclosure provide a second terminal, the second terminal being a terminal supporting a multi-hop U2N service or a terminal supporting a multi-hop U2U service, and the second terminal comprising:
[0101] The transceiving module is configured to receive a first message sent by the first terminal, the first message comprising encrypted information, the encrypted information comprising encrypted first information, the first information being used to determine a path from the first terminal to the second terminal.
[0102] In a fifth aspect, an embodiment of the present disclosure provides a communication device, comprising:
[0103] one or more processors;
[0104] The communication device is configured to perform the method described in the optional implementation of the first aspect or the second aspect.
[0105] In a sixth aspect, an embodiment of the present disclosure provides a communication system, comprising:
[0106] The first terminal is configured to perform the method described in the optional implementation of the first aspect.
[0107] The second terminal is configured to perform the method described in the optional implementation of the second aspect.
[0108] In a seventh aspect, an embodiment of the present disclosure provides a storage medium, which stores instructions, when the instructions are run on a communication device, the communication device performs the method described in the optional implementation of the first aspect or the second aspect.
[0109] In an eighth aspect, an embodiment of the present disclosure provides a computer program product, comprising a computer program, when the computer program is executed by a communication device, the method described in the optional implementation of the first aspect or the second aspect is implemented.
[0110] In a ninth aspect, an embodiment of the present disclosure provides a chip or a chip system. The chip or the chip system comprises processing circuitry configured to perform the method described in the optional implementation of the first aspect or the second aspect.
[0111] It can be understood that the first terminal, the second terminal, the communication device, the communication system, the storage medium, the computer program product, the chip or the chip system are all used to perform the method proposed in the embodiments of the present disclosure. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method, which will not be repeated here.
[0112] The embodiments of the present disclosure are not exhaustive, but only illustrate some embodiments, and are not specific limitations on the protection scope of the present disclosure. In the case of no contradiction, each step in an embodiment can be implemented as an independent embodiment, and the steps can be combined arbitrarily, for example, the scheme after removing part of the steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, part or all steps of different embodiments can be combined arbitrarily, an embodiment can be combined with optional implementation manners of other embodiments arbitrarily.
[0113] In each embodiment of the present disclosure, the terms and / or descriptions between the embodiments are consistent if there is no special description and logical conflict, and can be referred to each other, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0114] The terms used in the embodiments of the present disclosure are only for the purpose of describing the specific embodiments, and not as a limitation on the present disclosure.
[0115] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as "one", "a", "the", "above", "said", "preceding", "this" and the like, can represent "one and only one", and can also represent "one or more", "at least one" and the like. For example, in the case of using articles such as "a", "an", "the" and the like in English, the noun after the article can be understood as singular expression, and can also be understood as plural expression.
[0116] In the embodiments of the present disclosure, "plurality" means two or more.
[0117] In some embodiments, the terms "at least one of", "one or more", "a plurality of", "multiple" and the like can be replaced with each other.
[0118] In some embodiments, "at least one of A, B", "A and / or B", "in one case A, in another case B", "responsive to case A, responsive to case B" and the like, can be interpreted to include both cases, A and B, in some embodiments, A (A is performed regardless of B), in some embodiments, B (B is performed regardless of A), in some embodiments, selected from the group consisting of A and B (the selection between A and B is an option), in some embodiments, A and B (both A and B are performed).
[0119] In some embodiments, "A or B" and the like, can be interpreted to include both cases, A and B, in some embodiments, A (A is performed regardless of B), in some embodiments, B (B is performed regardless of A), in some embodiments, selected from the group consisting of A and B (the selection between A and B is an option).
[0120] In some embodiments, the prefix words "first", "second" and the like in the disclosure do not limit the position, order, priority, number or content of the described objects, and the description of the described objects should be understood in the context of the claims or embodiments, and should not be construed as redundant limitations. For example, the described object is "field", and the ordinal words before "field" in "first field" and "second field" do not limit the position or order between "fields", and "first" and "second" do not limit whether the "fields" modified by them are in the same message or not, nor do they limit the order of "first field" and "second field". For another example, the described object is "level", and the ordinal words before "level" in "first level" and "second level" do not limit the priority between "levels". For another example, the number of described objects is not limited by ordinal words, and can be one or more. For example, "first device", where the number of "devices" can be one or more. In addition, the objects modified by different prefix words can be the same or different, for example, the described object is "device", and "first device" and "second device" can be the same device or different devices, and their types can be the same or different; for another example, the described object is "information", and "first information" and "second information" can be the same information or different information, and their contents can be the same or different.
[0121] In some embodiments, "including A", "containing A", "for indicating A", "carrying A" can be interpreted as directly carrying A, or indirectly indicating A.
[0122] In some embodiments, the terms "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.
[0123] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above", and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "fewer than", "fewer than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below", and the like can be replaced with each other.
[0124] In some embodiments, the apparatuses and devices can be interpreted as physical or virtual, and their names are not limited to the names described in the embodiments, and in some cases can also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "subject", and the like.
[0125] In some embodiments, "network" can be interpreted as an apparatus included in the network, such as an access network device, a core network device, and the like.
[0126] In some embodiments, an “access network device (AN device)” can also be referred to as a “radio access network device (RAN device),” a “base station (BS),” a “radio base station,” a “fixed station,” and in some embodiments can also be understood as a “node,” an “access point,” a “transmission point (TP),” a “reception point (RP),” a “transmission / reception point (TRP),” a “panel,” an “antenna panel,” an “antenna array,” a “cell,” a “macro cell,” a “small cell,” a “femto cell,” a “pico cell,” a “sector,” a “cell group,” a “serving cell,” a “carrier,” a “component carrier,” a “bandwidth part (BWP),” and the like.
[0127] In some embodiments, a "terminal" or "terminal device" can be referred to as a "user equipment" (UE), a "user terminal," a "mobile station" (MS), a "mobile terminal" (MT), a subscriber station, a mobile unit, a subscriber unit, a wireless unit, a remote unit, a mobile device, a wireless device, a wireless communication device, a remote device, a mobile subscriber station, an access terminal, a mobile terminal, a wireless terminal, a remote terminal, a handset, a user agent, a mobile client, a client, etc.
[0128] In some embodiments, data, information, etc. can be acquired in compliance with laws and regulations of the country in which the location is situated.
[0129] In some embodiments, data, information, etc. can be acquired after obtaining consent of the user.
[0130] In addition, each element, each row, or each column in the table of the embodiments of the present disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.
[0131] Proximity based services (ProSe) enable user terminals (UEs) to communicate directly with other UEs in their proximity using a direct communication interface (PC5). Support for discovery, selection, authorization, connection establishment and data transfer for single-hop ProSe UE-to-Network (U2N) relay services and single-hop ProSe UE-to-UE (U2U) relay services has been addressed in previous releases.
[0132] In Release R19, multi-hop U2N relay needs to be supported. FIG. 1A is a schematic diagram of an architecture of multi-hop U2N relay according to an embodiment of the present disclosure, as shown in FIG. 1A, the architecture of multi-hop U2N relay includes a remote terminal (Remote UE), one or more intermediate relay terminals (Intermediate Relay), and a U2N relay terminal (U2N Relay) connected to the network through a Uu interface. In the embodiment of the present disclosure, the number of intermediate relay terminals is not limited. FIG. 1B is a schematic diagram of an architecture of multi-hop U2N relay according to an embodiment of the present disclosure, as shown in FIG. 1B, the architecture of multi-hop U2N relay includes a remote terminal, an intermediate relay terminal 1, an intermediate relay terminal 2, and a U2N relay terminal.
[0133] In Release R19, multi-hop U2U relay needs to be supported, i.e., two peer UEs can communicate with each other through multiple U2U relay terminals. FIG. 1C is a schematic diagram of an architecture of multi-hop U2U relay according to an embodiment of the present disclosure, as shown in FIG. 1C, the architecture of multi-hop U2U relay includes a source terminal, multiple U2U relay terminals, and a target terminal. In the embodiment of the present disclosure, the number of U2U relay terminals is not limited. FIG. 1D is a schematic diagram of an architecture of multi-hop U2U relay according to an embodiment of the present disclosure, as shown in FIG. 1D, the architecture of multi-hop U2U relay includes a source terminal, a U2U relay terminal 1, a U2U relay terminal 2, and a target terminal.
[0134] In some embodiments, the terminal described above includes at least one of a mobile phone, a wearable device, an Internet of Things device, a communication-capable car, a smart car, a Pad, a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in smart grid, a wireless terminal device in transportation safety, a wireless terminal device in smart city, a wireless terminal device in smart home, but is not limited thereto.
[0135] In some embodiments, the access network device is, for example, a node or device that accesses a terminal to a wireless network, and the access network device can include at least one of an evolved NodeB (eNB) in a 5G communication system, a next generation eNB (ng-eNB), a next generation NodeB (gNB), a node B (NB), a home node B (HNB), a home evolved node B (HeNB), a wireless backhaul device, a radio network controller (RNC), a base station controller (BSC), a base transceiver station (BTS), a base band unit (BBU), a mobile switching center, a base station in a 6G communication system, an open base station (Open RAN), a cloud base station (Cloud RAN), a base station in other communication systems, an access node in a Wi-Fi system, but is not limited thereto.
[0136] In some embodiments, the access network device can be composed of a central unit (CU) and a distributed unit (DU), wherein the CU can also be referred to as a control unit. The CU-DU structure can split the protocol layers of the access network device, and some of the protocol layers are controlled by the CU, and the rest or all of the protocol layers are distributed in the DU and controlled by the CU, but is not limited thereto.
[0137] After the multi-hop U2N relay discovery or the multi-hop U2U relay discovery, the remote terminal or the source terminal will send a message, which can be a request message (such as a direct communication request (DCR) message) or other messages. If the messages between the remote terminal and the intermediate relay terminal, the messages between the intermediate relay terminals, the messages between the intermediate relay terminal and the U2N relay terminal are not protected, or the messages between the source terminal and the U2U relay terminal, the messages between the U2U relay terminals, the messages between the U2U relay terminal and the target terminal are not protected, the information carried in the messages can be tampered with or stolen. Therefore, the embodiments of the present disclosure propose a message protection method in the multi-hop U2N relay and / or multi-hop U2U relay scenario.
[0138] FIG. 1E is a schematic diagram of an architecture of a communication system, according to an embodiment of the present disclosure. As shown in FIG. 1E, the communication system 100 includes a first terminal 101 and a second terminal 102. The first terminal 101 and the second terminal 102 are terminals supporting multi-hop U2N service or terminals supporting multi-hop U2U service. The first terminal and the second terminal are a sender and a receiver of a first message respectively, and the first message sent by the first terminal is received by the second terminal. The first message can be a DCR message or other message.
[0139] In the multi-hop U2N relay scenario, according to FIG. 1A, the first terminal can be a remote terminal, or the first terminal can be any one of one or more intermediate relay terminals; the second terminal can be any one of one or more intermediate relay terminals, or the second terminal can be a U2N relay terminal. Taking FIG. 1B as an example, the first terminal is a remote terminal, and the second terminal is an intermediate relay terminal 1; or, the first terminal is an intermediate relay terminal 1, and the second terminal is an intermediate relay terminal 2; or, the first terminal is an intermediate relay terminal 2, and the second terminal is a U2N relay terminal.
[0140] In the multi-hop U2U relay scenario, according to FIG. 1C, the first terminal can be a source terminal, or the first terminal can be any one of a plurality of U2U relay terminals; the second terminal can be any one of a plurality of U2U relay terminals, or the second terminal can be a target terminal. Taking FIG. 1D as an example, the first terminal is a source terminal, and the second terminal is a U2U relay terminal 1; or, the first terminal is a U2U relay terminal 1, and the second terminal is a U2U relay terminal 2; or, the first terminal is a U2U relay terminal 2, and the second terminal is a target terminal.
[0141] In the following, taking FIG. 1E as an example, a communication method is provided, which is used for protecting messages in a multi-hop U2N relay and / or multi-hop U2U relay scenario.
[0142] FIG. 2 is an interaction schematic diagram of a communication method, according to an embodiment of the present disclosure. As shown in FIG. 2, the present disclosure relates to a communication method, which includes the following steps:
[0143] In step S2101, the first terminal determines a key stream according to a first key.
[0144] The first terminal determines a first key and determines a key stream according to the first key. The first key is an encryption key for information in the first message. In some embodiments, the first message is a DCR message, and the first key is an encryption key for information in the DCR message, and thus can be referred to as a DCR key. By means of the key stream determined by the first key, all or part of the information in the first message can be encrypted, thereby protecting all or part of the information in the first message. The second information is all or part of the information in the first message, i.e., the second information is the information in the first message that needs to be encrypted and protected.
[0145] In some embodiments, the second information includes the first information, and the first information is used to determine a path from the first terminal to the second terminal.
[0146] In some embodiments, the second information includes the first information and at least one of the following:
[0147] a relay service code (RSC);
[0148] user identification information.
[0149] In some embodiments, the first key is determined based on at least one of the following:
[0150] a discovery user confidentiality key (DUCK);
[0151] a discovery user scrambling key (DUSK);
[0152] a long term credential.
[0153] In the above embodiments, the first message can be privacy protected based on discovery security materials.
[0154] Optionally, if the first terminal is configured with the DUCK / DUSK / long term credential, the first key is set to the DUCK / DUSK / long term credential.
[0155] Optionally, if the first terminal is configured with two or more of the DUCK, the DUSK and the long-term credential, the first key can be determined according to a preset priority. For example, the preset priority is: DUCK > DUSK > long-term credential. If the first terminal is configured with the DUCK, the first key is set as the DUCK. If the first terminal is configured with the DUSK but not configured with the DUCK, the first key is set as the DUSK. If the first terminal is configured with the long-term credential but not configured with the DUCK and the DUSK, the first key is set as the long-term credential. It should be understood that the above priority is only an example.
[0156] Optionally, if the first terminal is not configured with the DUCK, the DUSK and the long-term credential, the first message is unprotected, steps S2101-S2102 can be skipped, the first terminal sends the first message to the second terminal, and the first message includes the second information which is not encrypted. In some embodiments, the second information includes the first information, and thus the first message includes the first information which is not encrypted.
[0157] After determining the first key, a key stream corresponding to the first key can be determined. For example, the key stream can be determined based on only the first key, or the key stream can be determined based on the first key and other information (i.e., based on the first key and other information).
[0158] Optionally, the above key stream can be determined based on the first key and at least one of the following:
[0159] a counter based on Coordinated Universal Time (UTC);
[0160] a bearer;
[0161] direction information;
[0162] length information;
[0163] a Relay Service Code (RSC).
[0164] In some embodiments, the direction information can be used to indicate uplink or downlink.
[0165] In some embodiments, the length information can be the length of the second information, but is not limited thereto.
[0166] For example, the above key stream is determined based on the first key, the counter based on UTC, the bearer, the direction information and the length information.
[0167] For example, the above key stream is determined based on the first key, the counter based on UTC and the RSC.
[0168] For example, the key stream can be determined using an encryption algorithm specified in TS 33.501.
[0169] In summary, after determining the first key, a key stream related to the first key can be determined.
[0170] At step S2102, the first terminal encrypts the second information according to the key stream, to obtain encrypted information.
[0171] The first terminal performs privacy protection on the first message. For example, the privacy protection can be performed by encrypting all or part of the information (second information) in the first message by means of the key stream. In some embodiments, the first terminal encrypts the second information according to the key stream described above, to obtain encrypted information.
[0172] In some embodiments, the second information includes the first information, and the first information is used to determine the path from the first terminal to the second terminal, so that the encrypted information obtained after the second information is encrypted includes the encrypted first information. It should be understood that the second information here can be the same as the first information, or can include other information in addition to the first information.
[0173] In some embodiments, the first information includes one of the following:
[0174] path information from the first terminal to the second terminal;
[0175] a transaction ID used to determine the path from the first terminal to the second terminal.
[0176] For example, referring to FIG. 1A, the first information can include path information from the remote terminal to the U2N relay terminal, which can be a list containing the identification information of each hop intermediate relay terminal. Alternatively, the first information can include a transaction identification, which can be an identification mapped by the identification of the remote terminal and / or the identification of the U2N relay terminal. The intermediate relay terminal can determine the next hop node by looking up all the transaction identifications stored previously according to the transaction identification. For example, referring to FIG. 1C, the first information can include path information from the source terminal to the target terminal, which can be a list containing the identification information of each hop U2U relay terminal. Alternatively, the first information can include a transaction identification, which can be an identification mapped by the identification of the source terminal and / or the identification of the target terminal. The U2U relay terminal can determine the next hop node by looking up all the transaction identifications stored previously according to the transaction identification. The transaction identification can be used in the discovery phase first. When the intermediate relay terminal or the U2U relay terminal receives a discovery message carrying the transaction identification, the transaction identification is stored and the terminal from which the discovery message comes is recorded. In this way, the transaction identification can be used in the subsequent communication phase. The first message is sent in the communication phase.
[0177] Therefore, for the first terminal, the first terminal can determine the next hop node according to the path information from the first terminal to the second terminal or according to the transaction identification, i.e., determine the path to the second terminal.
[0178] Optionally, the second information further includes at least one of:
[0179] RSC;
[0180] User identification information.
[0181] Therefore, the encrypted information obtained by encrypting the second information includes:
[0182] The encrypted first information, and further includes at least one of:
[0183] The encrypted RSC;
[0184] The encrypted user identification information.
[0185] Optionally, the user identification information can include but is not limited to at least one of:
[0186] Proximity service remote user key identification (ProSe Remote User Key ID, PRUK ID)
[0187] User information identification (user info ID).
[0188] Optionally, the PRUK ID can include, but is not limited to, a Control Plane ProSe Remote User Key ID (CP-PRUK ID) and / or a User Plane ProSe Remote User Key ID (UP-PRUK ID), etc.
[0189] In some embodiments, the key stream is set to N least significant bits of the output of a key derivation function (KDF), and N is the total length of the second information. For example, the second information includes the first information and the RSC, and N is the total length of the first information and the RSC. For another example, the second information includes the PRUK ID, the first information and the RSC, and N is the total length of the PRUK ID, the first information and the RSC.
[0190] In some embodiments, the first terminal encrypts the second information according to the key stream, for example, the first terminal performs XOR operation between the key stream and the second information to obtain encrypted information. In an implementation, taking the second information including the PRUK ID, the first information and the RSC as an example, the length of the key stream is equal to the total length of the PRUK ID, the first information and the RSC, and the key stream is XORed with the PRUK ID, the first information and the RSC to obtain the encrypted information. In an implementation, the first L bits (L is the length of the RSC) of the key stream are XORed with the RSC, and the remaining bits of the key stream are XORed with the other information in the second information to obtain the encrypted information. Still taking the second information including the PRUK ID, the first information and the RSC as an example, the first L1 bits (L1 is the length of the RSC) of the key stream are XORed with the RSC, the middle L2 bits (L2 is the length of the PRUK ID) of the key stream are XORed with the PRUK ID, and the last L3 bits (L3 is the length of the first information) of the key stream are XORed with the first information to obtain the encrypted information.
[0191] In some embodiments, the first terminal also performs integrity protection on the first message. The first terminal calculates a message integrity check (MIC) using a second key according to the encrypted information, and the MIC is included in the first message. Optionally, the second key can be a discovery user integrity key (DUIK). Optionally, the integrity protection is performed after the privacy protection (encryption step), and in some embodiments, the integrity protection can also be performed before the privacy protection.
[0192] In some embodiments, steps S2101-S2102 are optional steps, for example, the first terminal can encrypt the second information by other manners to obtain the encrypted information.
[0193] Step S2103, the first terminal sends the first message to the second terminal, the first message comprising the encrypted information.
[0194] Optionally, the first message further comprises a MIC.
[0195] Step S2104, the second terminal determines the key stream according to the first key.
[0196] Optional implementation of step S2104 can refer to optional implementation of step S2101 of FIG. 2, which will not be described herein.
[0197] Step S2105, the second terminal decrypts the encrypted information according to the key stream.
[0198] The step of decrypting the encrypted information by the second terminal according to the key stream corresponds to the step of encrypting the second information by the first terminal according to the key stream. Optional implementation of the decryption step in step S2105 can refer to optional implementation of the encryption step in step S2102 of FIG. 2, which will not be described herein.
[0199] The first terminal and the second terminal use the same first key and key stream for encryption and decryption as the sender and receiver of the same message.
[0200] In some embodiments, the second terminal decrypts the encrypted information according to the key stream, for example, the second terminal XORs the key stream and the encrypted information to obtain the second information. In an implementation, taking an example that the encrypted information comprises encrypted PRUK ID, encrypted first information and encrypted RSC, XORing the key stream and the encrypted PRUK ID, the encrypted first information and the encrypted RSC to obtain the second information. In an implementation, XORing the first L bits (L is the length of the RSC) of the key stream and the encrypted RSC, and then XORing the remaining bits of the key stream and other encrypted information in the encrypted information to obtain the second information. Still taking an example that the encrypted information comprises encrypted PRUK ID, encrypted first information and encrypted RSC, XORing the first L1 bits (L1 is the length of the RSC) of the key stream and the encrypted RSC, then XORing the middle L2 bits (L2 is the length of the PRUK ID) of the key stream and the encrypted PRUK ID, and finally XORing the last L3 bits (L3 is the length of the first information) of the key stream and the encrypted first information to obtain the second information.
[0201] Optionally, the second terminal also performs integrity verification on the first message. The second terminal calculates a MIC using the second key according to the encrypted information, and if the calculated MIC is the same as the MIC in the first message, the integrity verification passes, and if the calculated MIC is different from the MIC in the first message, the integrity verification fails. Optionally, the integrity verification is performed before the privacy protection verification (decryption step), and if the integrity verification fails, steps S2104-S2107 can not be performed. In some embodiments, the integrity verification can also be performed after the privacy protection verification.
[0202] In some embodiments, steps S2104-S2105 are optional steps. For example, the first terminal can encrypt the second information by other manners to obtain the encrypted information, and correspondingly, the second terminal can decrypt the encrypted information by other manners to obtain the second information.
[0203] In step S2106, the second terminal determines to abort the establishment of the PC5 link between the second terminal and the first terminal based on the decrypted second information being different from the stored second information.
[0204] Optionally, the stored second information can be the second information carried in the discovery message. In the discovery phase, for an intermediate relay terminal or a U2U relay terminal, after receiving the discovery message, the second information carried in the discovery message is stored.
[0205] Optionally, the decrypted second information being different from the stored second information means that at least one item in the decrypted second information is different from the corresponding information in the stored second information.
[0206] Taking the second information including PRUK ID, the first information and RSC as an example, the second terminal determines to abort the establishment of the PC5 link between the second terminal and the first terminal based on the decrypted PRUK ID being different from the stored PRUK ID, based on the decrypted first information being different from the stored first information, and based on the decrypted RSC being different from the stored RSC.
[0207] In step S2107, the second terminal determines to abort the establishment of the PC5 link between the second terminal and the first terminal based on the decryption failure.
[0208] Optionally, the second terminal determines that the decryption fails when the second terminal fails to successfully restore the second information by using the decryption algorithm.
[0209] In some embodiments, steps S2106-S2107 are optional steps.
[0210] In the above embodiments, the PC5 link between the first terminal and the second terminal can be established in the case of protecting privacy between the first terminal and the second terminal by decrypting the encrypted information in the first message to obtain the second information, and determining whether to suspend the establishment of the PC5 link between the second terminal and the first terminal by comparing whether the decrypted second information is the same as the second information stored in the second terminal, or based on whether the decryption is successful or fails.
[0211] In some embodiments, the second terminal continues to perform subsequent processes, such as sending a next message to a next-hop node, based on the decrypted second information being the same as the stored second information. For example, the second terminal can serve as a sender of the next message, the next-hop node can serve as a receiver of the next message, the second terminal can serve as a new first terminal, and the next-hop node can serve as a new second terminal, and the next message can be privacy-protected according to steps S2101-S2107.
[0212] According to the embodiments of the present disclosure, the information in the message in the multi-hop U2N relay and / or multi-hop U2U relay scenario is privacy-protected, the message carries encrypted first information, and the first information is used to determine the path in the multi-hop U2N relay and / or multi-hop U2U relay scenario.
[0213] In some embodiments, the terms “uplink”, “uplink”, “physical uplink”, and the like can be replaced with each other, the terms “downlink”, “downlink”, “physical downlink”, and the like can be replaced with each other, and the terms “side”, “sidelink”, “sidelink communication”, “sidelink communication”, “direct connection”, “direct connection link”, “direct connection communication”, “direct connection link communication”, and the like can be replaced with each other.
[0214] In some embodiments, the terms “acquire”, “obtain”, “get”, “receive”, “transmit”, “bidirectional transmission”, “send and / or receive”, and the like can be replaced with each other, and can be interpreted as receiving from other subjects, obtaining from protocols, obtaining from higher layers, obtaining by self-processing, and the like.
[0215] In some embodiments, the terms “send”, “transmit”, “report”, “issue”, “transmit”, “bidirectional transmission”, “send and / or receive”, and the like can be replaced with each other.
[0216] In some embodiments, the terms "certain", "preset", "pre-set", "set", "indicated", "any", "first", and the like can be replaced by each other, and "certain A", "preset A", "pre-set A", "set A", "indicated A", "any A", "first A" can be interpreted as A predetermined in a protocol or the like, or A obtained by setting, configuration, or indication, or a specific A, any A, or first A, but are not limited thereto.
[0217] The communication method related to the embodiments of the present disclosure can include at least one of steps S2101-S2107. For example, step S2103 can be implemented as an independent embodiment, steps S2101+S2102+S2103 can be implemented as an independent embodiment, steps S2103+S2104+S2105 can be implemented as an independent embodiment, steps S2103+S2104+S2105+S2106 can be implemented as an independent embodiment, steps S2103+S2104+S2105+S2107 can be implemented as an independent embodiment, steps S2103+S2104+S2105+S2106+S2107 can be implemented as an independent embodiment, steps S2103+S2106 can be implemented as an independent embodiment, steps S2103+S2107 can be implemented as an independent embodiment, steps S2103+S2106+S2107 can be implemented as an independent embodiment, but are not limited thereto.
[0218] In some embodiments, steps S2101-S2102, S2104-S2107 are optional, and one or more of these steps can be omitted or replaced in different embodiments.
[0219] In some embodiments, other optional implementations described before or after the description corresponding to FIG. 2 can be referred to.
[0220] FIG. 3A is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3A, the embodiments of the present disclosure relate to a communication method, which is performed by a first terminal, comprising:
[0221] Step S3101, determining a key stream according to the first key.
[0222] The optional implementation of step S3101 can refer to the optional implementation of step S2101 of FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be described here.
[0223] Step S3102, encrypt the second information according to the key stream, to obtain encrypted information.
[0224] The optional implementation of step S3102 can refer to the optional implementation of step S2102 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.
[0225] Step S3103, send the first message, the first message including the encrypted information.
[0226] The optional implementation of step S3103 can refer to the optional implementation of step S2103 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.
[0227] FIG. 3B is a flow diagram of a communication method according to some embodiments of the present disclosure. As shown in FIG. 3B, the embodiments of the present disclosure relate to a communication method, which is performed by a first terminal and includes:
[0228] Step S3201, encrypt the second information, to obtain encrypted information.
[0229] The optional implementation of step S3201 can refer to the optional implementation of steps S2101-S2102 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.
[0230] In some embodiments, the second information can include the first information, the first information being used to determine a path from the first terminal to the second terminal. The encrypted information includes the encrypted first information.
[0231] In some embodiments, the first information includes one of:
[0232] path information from the first terminal to the second terminal;
[0233] a transaction identifier, the transaction identifier being used to determine the path from the first terminal to the second terminal.
[0234] In some embodiments, the second information further includes at least one of:
[0235] an RSC;
[0236] user identification information.
[0237] Therefore, the encrypted information further includes the encrypted RSC and / or the encrypted user identification information.
[0238] In some embodiments, a key stream can be determined according to the first key, and the second information can be encrypted according to the key stream, to obtain the encrypted information. Optionally, encrypting the second information according to the key stream can include performing an exclusive OR operation between the key stream and the second information.
[0239] In some embodiments, the second information can also be encrypted in other manners, for example, by using other encryption algorithms. The encryption manner is not limited in the embodiments of the present disclosure.
[0240] Step S3202: sending the first message, the first message comprising the encrypted information.
[0241] The optional implementation of step S3202 can refer to the optional implementation of step S2103 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.
[0242] FIG. 3C is a flow diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 3C, the embodiments of the present disclosure relate to a communication method, which is performed by a first terminal and comprises:
[0243] Step S3301: sending the first message, the first message comprising the encrypted information.
[0244] The optional implementation of step S3301 can refer to the optional implementation of step S2103 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be repeated here.
[0245] In some embodiments, the first message comprises the encrypted information, the encrypted information comprising encrypted first information, the first information being used to determine a path from the first terminal to a second terminal.
[0246] In some embodiments, the first information comprises one of:
[0247] path information from the first terminal to the second terminal;
[0248] transaction identification, the transaction identification being used to determine the path from the first terminal to the second terminal.
[0249] In some embodiments, a key stream can be determined according to the first key, and the second information can be encrypted according to the key stream to obtain the encrypted information. The second information comprises the first information. Alternatively, encrypting the second information according to the key stream can comprise: performing XOR operation between the key stream and the second information.
[0250] In some embodiments, the second information can also be encrypted in other manners, for example, by using other encryption algorithms. The encryption manner is not limited in the embodiments of the present disclosure.
[0251] In some embodiments, the second information further comprises at least one of:
[0252] RSC;
[0253] user identification information.
[0254] Thus, the encrypted information further comprises the encrypted RSC and / or the encrypted user identification information.
[0255] In some embodiments, the first key is determined based on at least one of:
[0256] DUCK;
[0257] DUSK;
[0258] Long-term credential.
[0259] In some embodiments, the key stream is determined based on the first key and at least one of:
[0260] UTC-based counter;
[0261] Bearer;
[0262] Direction information;
[0263] Length information;
[0264] RSC.
[0265] In some embodiments, the key stream is set as N least significant bits of a key derivation function (KDF) output, N being a total length of the second information.
[0266] FIG. 4A is a flow diagram illustrating a communication method according to an embodiment of the present disclosure. As shown in FIG. 4A, the embodiment of the present disclosure relates to a communication method, which is performed by a second terminal, comprising:
[0267] Step S4101, receiving a first message, the first message comprising encrypted information.
[0268] The optional implementation of step S4101 can refer to the optional implementation of step S2103 of FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be described here.
[0269] Step S4102, determining a key stream according to a first key.
[0270] The optional implementation of step S4102 can refer to the optional implementation of step S2104 of FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be described here.
[0271] Step S4103, decrypting the encrypted information according to the key stream.
[0272] The optional implementation of step S4103 can refer to the optional implementation of step S2105 of FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be described here.
[0273] In some embodiments, the method further includes at least one of:
[0274] determining to abort the establishment of the PC5 link between the second terminal and the first terminal based on the second information obtained after the decryption being different from the stored second information;
[0275] determining to abort the establishment of the PC5 link between the second terminal and the first terminal based on the decryption failure.
[0276] FIG. 4B is a flow diagram illustrating a communication method according to some embodiments of the present disclosure. As shown in FIG. 4B, the embodiments of the present disclosure relate to a communication method, which is performed by a second terminal, and includes:
[0277] Step S4201, receiving a first message, the first message including encrypted information.
[0278] The optional implementation of step S4201 can refer to the optional implementation of step S2103 of FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be described here.
[0279] Step S4202, decrypting the encrypted information.
[0280] The optional implementation of step S4202 can refer to the optional implementation of steps S2104-S2105 of FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be described here.
[0281] In some embodiments, the encrypted information is obtained by encrypting second information. The second information can include first information, the first information being used to determine a path from the first terminal to the second terminal. The encrypted information includes the encrypted first information.
[0282] In some embodiments, the first information includes one of:
[0283] path information from the first terminal to the second terminal;
[0284] a transaction identifier, the transaction identifier being used to determine the path from the first terminal to the second terminal.
[0285] In some embodiments, the second information further includes at least one of:
[0286] an RSC;
[0287] user identification information.
[0288] Therefore, the encrypted information further includes the encrypted RSC and / or the encrypted user identification information.
[0289] In some embodiments, the key stream can be determined according to the first key, and the encrypted information can be decrypted according to the key stream. Optionally, decrypting the encrypted information according to the key stream can include performing an exclusive-OR operation between the key stream and the encrypted information.
[0290] In some embodiments, the encrypted information can also be decrypted in other manners, for example, by using other decryption algorithms. The disclosure embodiments are not limited to the decryption manner.
[0291] In some embodiments, the method further includes at least one of the following:
[0292] based on the decrypted second information being different from the stored second information, determining to abort establishing the PC5 link between the second terminal and the first terminal;
[0293] based on the decryption failure, determining to abort establishing the PC5 link between the second terminal and the first terminal.
[0294] FIG. 4C is a flow diagram of a communication method according to some embodiments of the present disclosure. As shown in FIG. 4C, the present disclosure relates to a communication method, which is performed by a second terminal, and includes the following steps:
[0295] Step S4301: receiving a first message, the first message including encrypted information.
[0296] The optional implementation of step S4301 can refer to the optional implementation of step S2103 in FIG. 2 and other associated parts in the embodiments related to FIG. 2, which will not be described here.
[0297] In some embodiments, the encrypted information is obtained by encrypting second information. The second information can include first information, and the first information is used to determine a path from the first terminal to the second terminal. The encrypted information includes the encrypted first information.
[0298] In some embodiments, the first information includes at least one of the following:
[0299] path information from the first terminal to the second terminal;
[0300] transaction identification, the transaction identification being used to determine the path from the first terminal to the second terminal.
[0301] In some embodiments, the second information further includes at least one of the following:
[0302] RSC;
[0303] user identification information.
[0304] Therefore, the encrypted information further includes the encrypted RSC and / or the encrypted user identification information.
[0305] In some embodiments, the key stream can be determined according to the first key, and the encrypted information can be decrypted according to the key stream. Optionally, decrypting the encrypted information according to the key stream can include performing exclusive-OR operation between the key stream and the encrypted information.
[0306] In some embodiments, the encrypted information can also be decrypted in other manners, for example, by using other decryption algorithms. The decryption manner is not limited in the embodiments of the present disclosure.
[0307] In some embodiments, the first key is determined based on at least one of the following:
[0308] DUCK;
[0309] DUSK;
[0310] Long-term credential.
[0311] In some embodiments, the key stream is determined based on the first key and at least one of the following:
[0312] UTC-based counter;
[0313] Bearing;
[0314] Direction information;
[0315] Length information;
[0316] RSC.
[0317] In some embodiments, the key stream is set as N least significant bits of the KDF output, and N is the total length of the second information.
[0318] In some embodiments, the method further includes at least one of the following:
[0319] Based on the decrypted second information being different from the stored second information, determining to abort the establishment of the PC5 link between the second terminal and the first terminal;
[0320] Based on the decryption failure, determining to abort the establishment of the PC5 link between the second terminal and the first terminal.
[0321] FIG. 5 is an interaction diagram of a communication method according to an embodiment of the present disclosure. As shown in FIG. 5, the embodiments of the present disclosure relate to a communication method, which includes:
[0322] In step S5101, the first terminal encrypts the second information to obtain encrypted information.
[0323] The optional implementation of step S5101 can refer to the optional implementation of steps S2101-S2102 in FIG. 2, the optional implementation of step S3201 in FIG. 3B, and other associated parts in the embodiments related to FIG. 2 and FIG. 3B, which will not be repeated here.
[0324] In some embodiments, the second information includes the first information. The first information is used to determine the path from the first terminal to the second terminal. The encrypted information includes the encrypted first information.
[0325] In some embodiments, the first information includes one of the following:
[0326] path information from the first terminal to the second terminal;
[0327] transaction identification, the transaction identification being used to determine the path from the first terminal to the second terminal.
[0328] In some embodiments, the second information further includes at least one of the following:
[0329] RSC;
[0330] user identification information.
[0331] Therefore, the encrypted information further includes the encrypted RSC and / or the encrypted user identification information.
[0332] Step S5102, the first terminal sends a first message to the second terminal, and the first message includes the encrypted information.
[0333] The optional implementation of step S5102 can refer to the optional implementation of step S2103 in FIG. 2, the optional implementation of step S3202 in FIG. 3B, the optional implementation of step S4201 in FIG. 4B, and other associated parts in the embodiments related to FIG. 2, FIG. 3B and FIG. 4B, which will not be repeated here.
[0334] Step S5103, the second terminal decrypts the encrypted information.
[0335] The optional implementation of step S5103 can refer to the optional implementation of steps S2104-S2105 in FIG. 2, the optional implementation of step S4202 in FIG. 4B, and other associated parts in the embodiments related to FIG. 2 and FIG. 4B, which will not be repeated here.
[0336] In order to facilitate understanding of the embodiments of the present disclosure, the communication method provided by the embodiments of the present disclosure will be described below taking FIG. 1B and FIG. 1D as examples. It should be understood that when the number of intermediate relay terminals or U2U relay terminals changes, the implementation mode can still refer to the description of FIG. 6A and FIG. 6B.
[0337] FIG. 6A is an interaction diagram of a communication method shown in the architecture of multi-hop U2N relay shown in FIG. IB. As shown in FIG. 6A, the communication method comprises:
[0338] Step 1.1, the remote terminal sends a first DCR to the intermediate relay terminal 1.
[0339] The remote terminal connects to the nearest intermediate relay terminal 1 in the selected multi-hop path, and sends a first DCR to the intermediate relay terminal 1. The first DCR includes route information or transaction ID to indicate the selected multi-hop path. The route information can be a list containing user info ID of the intermediate relay terminal. The transaction ID is related to the route information. The first DCR also includes RSC and PRUK ID.
[0340] The remote terminal protects the first DCR by using discovery security materials, including integrity protection and / or privacy protection. The integrity protection of the first DCR is performed after the privacy protection. The discovery security materials are related to at least one of the RSC, the proximity service direct discovery service, the proximity service query code, the proximity service response code, the proximity service restricted code, etc.
[0341] For privacy protection, a DCR key is used as an encryption and decryption key. The DCR key corresponds to the first key in the above embodiments. The remote terminal encrypts the first DCR using the first DCR key according to the path information (or transaction ID) in the first DCR that needs to be protected, the PRUK ID and the RSC, to obtain first encrypted information. The optional implementation of encryption is described below.
[0342] For integrity protection, a DUIK is used as a protection key. The remote terminal calculates a first MIC using the DUIK according to the first encrypted information, and the first MIC is included in the first DCR.
[0343] Step 1.2, the intermediate relay terminal 1 sends a second DCR to the intermediate relay terminal 2.
[0344] After receiving the first DCR sent by the remote terminal, the intermediate relay terminal 1 verifies the first DCR by using discovery security materials, including integrity verification and / or privacy protection verification. The integrity verification of the first DCR is performed before the privacy protection verification.
[0345] For integrity verification, the intermediate relay terminal 1 computes a second MIC using the DUIK according to the first encrypted information in the first DCR, and compares whether the second MIC is the same as the first MIC in the first DCR. If the two are not the same, the integrity verification fails. If the two are the same, the privacy protection verification can be performed.
[0346] For privacy protection verification, the intermediate relay terminal 1 decrypts the first encrypted information using the first DCR key. The optional implementation of decryption is described below. The intermediate relay terminal 1 compares whether the PRUK ID, the path information (or transaction identification) and the RSC obtained after decryption match the values in the discovery message. If one of the values does not match, the link establishment process is aborted.
[0347] The intermediate relay terminal 1 establishes a new PC5 connection with the next hop node (i.e. the intermediate relay terminal 2) of the selected multi-hop path, and sends a second DCR to the intermediate relay terminal 2. The intermediate relay terminal 1 protects the second DCR using the discovery security materials, including integrity protection and / or privacy protection.
[0348] For privacy protection, the intermediate relay terminal 1 encrypts the path information (or transaction identification) and the PRUK ID and the RSC that need to be protected according to the second DCR using the second DCR key, to obtain second encrypted information. Optionally, the second DCR key is the same as or different from the first DCR key.
[0349] For integrity protection, the intermediate relay terminal 1 computes a third MIC using the DUIK according to the second encrypted information, and the third MIC is included in the second DCR.
[0350] Step 1.3, the intermediate relay terminal 2 sends a third DCR to the U2N relay terminal.
[0351] After receiving the second DCR sent by the intermediate relay terminal 1, the intermediate relay terminal 2 verifies the second DCR using the discovery security materials, including integrity verification and / or privacy protection verification.
[0352] The intermediate relay terminal 2 establishes a new PC5 connection with the U2N relay terminal, and sends a third DCR to the U2N relay terminal. The intermediate relay terminal 2 protects the third DCR using the discovery security materials, including integrity protection and / or privacy protection.
[0353] The optional implementation of the verification of the second DCR by the intermediate relay terminal 2 and the protection of the third DCR can refer to the optional implementation of step 1.2, which will not be described here.
[0354] Step 1.4. The U2N relay terminal sends a first Direct Communication Accept (DCA) to the intermediate relay terminal 2.
[0355] After receiving the third DCR from the intermediate relay terminal 2, the U2N relay terminal verifies the third DCR by using the discovery security material, including integrity verification and / or privacy protection verification. The optional implementation of the U2N relay terminal verifying the third DCR can refer to the optional implementation of step 1.2, which will not be described here.
[0356] Then the U2N relay terminal sends a first DCA to the intermediate relay terminal 2.
[0357] Step 1.5. The intermediate relay terminal 2 sends a second DCA to the intermediate relay terminal 1.
[0358] Step 1.6. The intermediate relay terminal 1 sends a third DCA to the remote terminal.
[0359] In the embodiments of the present disclosure, the optional implementation of encryption can include but is not limited to the following scheme 1 and scheme 2.
[0360] Scheme 1:
[0361] Privacy protection is performed using the encryption algorithm specified in TS 33.501. The terminal encrypts the PRUK ID, path information (or transaction identifier) and RSC in the following manner:
[0362] (1) If the terminal is configured with DUCK / DUSK / long-term credential, the DCR key is set to DUCK / DUSK / long-term credential. If the terminal is not configured with DUCK / DUSK / long-term credential, the DCR is not protected, and the following steps (2)-(3) are skipped.
[0363] (2) Determine the keystream according to the DCR key, UTC-based counter, bearer, direction information and length information.
[0364] (3) XOR the keystream with the PRUK ID, path information (or transaction identifier) and RSC to perform encryption to obtain encrypted information.
[0365] Scheme 2:
[0366] The terminal encrypts the PRUK ID, path information (or transaction identifier) and RSC in the following manner:
[0367] (1) If the terminal is configured with DUCK, the DCR key is set to DUCK. If the terminal is configured with DUSK, not DUCK, the DCR key is set to DUSK. If the terminal is not configured with DUCK and DUSK, the DCR is unprotected and the following steps (2)-(3) are skipped.
[0368] (2) Determine the key stream according to the DCR key, the UTC-based counter, and the RSC.
[0369] (3) XOR the first L bits of the key stream with the RSC (L is the length of the RSC), and then XOR the remaining bits of the key stream with the PRUK ID, the path information (or transaction identification) to perform encryption to obtain the encrypted information.
[0370] In the embodiments of the present disclosure, the optional implementation manner of decryption can include but is not limited to the following scheme 1 and scheme 2.
[0371] Scheme 1:
[0372] The terminal decrypts the encrypted PRUK ID, the encrypted path information (or transaction identification), and the encrypted RSC in the following manner:
[0373] (1) If the terminal is configured with DUCK / DUSK / long-term credential, the DCR key is set to DUCK / DUSK / long-term credential. If the terminal is not configured with DUCK / DUSK / long-term credential, the DCR is unprotected and the following steps (2)-(3) are skipped.
[0374] (2) Determine the key stream according to the DCR key, the UTC-based counter, the Bearer, the direction information, and the length information.
[0375] (3) XOR the key stream with the encrypted PRUK ID, the encrypted path information (or transaction identification), and the encrypted RSC to perform decryption.
[0376] Scheme 2:
[0377] The terminal decrypts the encrypted PRUK ID, the encrypted path information (or transaction identification), and the encrypted RSC in the following manner:
[0378] (1) If the terminal is configured with DUCK, the DCR key is set to DUCK. If the terminal is configured with DUSK, not DUCK, the DCR key is set to DUSK. If the terminal is not configured with DUCK and DUSK, the DCR is unprotected and the following steps (2)-(3) are skipped.
[0379] (2) Determine the key stream based on the DCR key, UTC-based counter, and RSC.
[0380] (3) XOR the first L bits of the key stream with the encrypted RSC (L is the length of RSC), and then XOR the remaining bits of the key stream with the encrypted PRUK ID, encrypted path information (or transaction identifier) to decrypt.
[0381] For the encryption and decryption process of scheme 2, the input of the key derivation function (KDF) when determining the key stream includes the following parameters:
[0382] FC = 0xBB
[0383] P0 = UTC-based counter
[0384] L0 = UTC-based counter length (i.e., 0x00 0x04)
[0385] P1 = RSC
[0386] L1 = Length of RSC (i.e., 0x00 0x03)
[0387] The input key of the KDF is a 256-bit DCR key.
[0388] The key stream is set to the N least significant bits of the KDF output, where N = length of RSC + length of PRUK ID + length of path information (or transaction identifier).
[0389] FIG. 6B is an interaction schematic of a communication method shown in the architecture of the multi-hop U2U relay shown in FIG. ID. In contrast to FIG. 6A and FIG. 6B, in FIG. 6B, the source terminal acts as a remote terminal, the optional implementation thereof can be referred to the optional implementation of the remote terminal, the U2U relay terminal acts as an intermediate relay terminal, the optional implementation thereof can be referred to the optional implementation of the intermediate relay terminal, and the target terminal acts as a U2N relay terminal, the optional implementation thereof can be referred to the optional implementation of the U2N relay terminal. As shown in FIG. 6B, the method includes:
[0390] Step 2.1, the source terminal sends a first DCR to the U2U relay terminal 1.
[0391] The optional implementation of step 2.1 can be referred to the optional implementation of step 1.1 of FIG. 6A and other associated parts in the embodiments involved in FIG. 6A, which will not be described here.
[0392] Step 2.2, the U2U relay terminal 1 sends a second DCR to the U2U relay terminal 2.
[0393] The optional implementation of step 2.2 can refer to the optional implementation of step 1.2 of FIG. 6A and other associated parts in the embodiments involved in FIG. 6A, which will not be repeated here.
[0394] Step 2.3, the U2U relay terminal 2 sends a third DCR to the target terminal.
[0395] The optional implementation of step 2.3 can refer to the optional implementation of step 1.3 of FIG. 6A and other associated parts in the embodiments involved in FIG. 6A, which will not be repeated here.
[0396] Step 2.4, the target terminal sends a first DCA to the U2U relay terminal 2.
[0397] The optional implementation of step 2.4 can refer to the optional implementation of step 1.4 of FIG. 6A and other associated parts in the embodiments involved in FIG. 6A, which will not be repeated here.
[0398] Step 2.5, the U2U relay terminal 2 sends a second DCA to the U2U relay terminal 1.
[0399] The optional implementation of step 2.5 can refer to the optional implementation of step 1.5 of FIG. 6A and other associated parts in the embodiments involved in FIG. 6A, which will not be repeated here.
[0400] Step 2.6, the U2U relay terminal 1 sends a third DCA to the source terminal.
[0401] The optional implementation of step 2.6 can refer to the optional implementation of step 1.6 of FIG. 6A and other associated parts in the embodiments involved in FIG. 6A, which will not be repeated here.
[0402] In the embodiments of the present disclosure, part or all of the steps and their optional implementations can be combined with part or all of the steps in other embodiments, or combined with optional implementations of other embodiments.
[0403] The embodiments of the present disclosure also propose a device for implementing any of the above methods, for example, a device including units or modules for implementing the steps performed by the terminal in any of the above methods. For another example, another device is proposed, including units or modules for implementing the steps performed by the network equipment (such as access network equipment, core network function node, core network equipment, etc.) in any of the above methods.
[0404] It should be understood that the division of each unit or module in the above apparatus is only a logical function division, and all or part of them can be integrated into a physical entity or physically separated in actual implementation. In addition, the units or modules in the apparatus can be implemented in the form of processor calling software: for example, the apparatus includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to realize any of the above methods or realize the functions of each unit or module of the above apparatus, wherein the processor is a general processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the apparatus or a memory outside the apparatus. Alternatively, the units or modules in the apparatus can be implemented in the form of hardware circuit, and the functions of part or all of the units or modules can be realized by the design of hardware circuit. The above hardware circuit can be understood as one or more processors; for example, in one implementation, the above hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units or modules are realized by the design of the logical relationship of elements in the circuit; for another example, in another implementation, the above hardware circuit is a programmable logic device (PLD), and a field programmable gate array (FPGA) is taken as an example, which can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured by a configuration file, so as to realize the functions of part or all of the above units or modules. All units or modules of the above apparatus can be all implemented in the form of processor calling software, or all implemented in the form of hardware circuit, or part implemented in the form of processor calling software and the remaining part implemented in the form of hardware circuit.
[0405] In the embodiments of the present disclosure, the processor is a circuit with signal processing capability. In one implementation, the processor can be a circuit with instruction reading and running capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), a digital signal processor (DSP), or the like. In another implementation, the processor can implement certain functions through a logical relationship of a hardware circuit, and the logical relationship of the hardware circuit is fixed or can be reconfigured. For example, the processor is a hardware circuit implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In the reconfigurable hardware circuit, the processor loads a configuration document to implement the configuration of the hardware circuit. It can be understood that the processor loads instructions to implement the functions of the above part or all units or modules. In addition, the hardware circuit can also be designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), or the like.
[0406] FIG. 7A is a structural schematic diagram of a first terminal according to an embodiment of the present disclosure. As shown in FIG. 7A, the first terminal 7100 can include at least one of a transceiver module 7101, a processing module 7102, and the like. In some embodiments, the transceiver module is configured to send a first message to a second terminal, the first message including encryption information, the encryption information including encrypted first information, the first information being used to determine a path from the first terminal to the second terminal. Optionally, the transceiver module is configured to perform at least one of the communication steps (for example, step 2103, but not limited thereto) performed by the first terminal in any of the above methods, and details are not described herein. Optionally, the processing module is configured to perform at least one of the other steps (for example, step S2101, step S2102, but not limited thereto) performed by the first terminal in any of the above methods, and details are not described herein.
[0407] FIG. 7B is a structural schematic diagram of a second terminal according to an embodiment of the present disclosure. As shown in FIG. 7B, the second terminal 7200 can include at least one of a transceiver module 7201, a processing module 7202, and the like. In some embodiments, the transceiver module is configured to receive a first message sent by a first terminal, the first message including encryption information, the encryption information including encrypted first information, the first information being used to determine a path from the first terminal to the second terminal. Optionally, the transceiver module is configured to perform at least one of the communication steps (such as sending and / or receiving) performed by the second terminal in any of the methods described above, which will not be repeated here. Optionally, the processing module is configured to perform at least one of the other steps (such as steps S2104, S2105, S2106, and S2107, but not limited thereto) performed by the second terminal in any of the methods described above, which will not be repeated here.
[0408] In some embodiments, the transceiver module can include a sending module and / or a receiving module, which can be separate or integrated together. Optionally, the transceiver module can be replaced by a transceiver.
[0409] In some embodiments, the processing module can be one module or include multiple sub-modules. Optionally, the multiple sub-modules perform all or part of the steps required to be performed by the processing module. Optionally, the processing module can be replaced by a processor.
[0410] FIG. 8A is a structural schematic diagram of a communication device 8100 according to an embodiment of the present disclosure. The communication device 8100 can be a terminal, or a chip, chip system, or processor supporting the terminal to implement any of the methods described above. The communication device 8100 can be used to implement the methods described in the above method embodiments, which can be referred to the descriptions in the above method embodiments.
[0411] As shown in FIG. 8A, the communication device 8100 includes one or more processors 8101. The processor 8101 can be a general-purpose processor or a special-purpose processor, for example, a baseband processor or a central processing unit. The baseband processor can be used to process communication protocols and communication data, and the central processing unit can be used to control the communication device (such as a base station, a baseband chip, a terminal device, a terminal device chip, a DU or a CU, etc.), execute programs, and process data of the programs. The communication device 8100 is configured to execute any of the methods described above.
[0412] In some embodiments, the communication device 8100 further includes one or more memories 8102 for storing instructions. Optionally, all or part of the memory 8102 can also be outside the communication device 8100.
[0413] In some embodiments, the communication device 8100 further includes one or more transceivers 8103. When the communication device 8100 includes one or more transceivers 8103, the transceiver 8103 performs at least one of the communication steps (for example, step S2103, but not limited to) in the above-described method, and the processor 8101 performs at least one of the other steps (for example, step S2101, step S2102, step S2104, step S2105, step S2106, step S2107, but not limited to).
[0414] In some embodiments, the transceiver can include a receiver and / or a transmitter, which can be separate or integrated together. Optionally, the terms of transceiver, transceiving unit, transceiver, transceiving circuit, etc. can be replaced with each other, the terms of transmitter, transmitting unit, transmitter, transmitting circuit, etc. can be replaced with each other, and the terms of receiver, receiving unit, receiver, receiving circuit, etc. can be replaced with each other.
[0415] In some embodiments, the communication device 8100 can include one or more interface circuits 8104. Optionally, the interface circuit 8104 is connected to the memory 8102, and the interface circuit 8104 can be used to receive signals from the memory 8102 or other devices, and can be used to send signals to the memory 8102 or other devices. For example, the interface circuit 8104 can read instructions stored in the memory 8102 and send the instructions to the processor 8101.
[0416] The communication device 8100 described in the above embodiments can be a network device or a terminal, but the scope of the communication device 8100 described in the present disclosure is not limited thereto, and the structure of the communication device 8100 can not be limited by Figure 8A. The communication device can be a standalone device or can be part of a larger device. For example, the communication device can be: 1) a standalone integrated circuit (IC), or a chip, or a chip system or subsystem; (2) a set of one or more ICs, which can optionally also include storage components for storing data, programs; (3) an ASIC, such as a Modem; (4) a module that can be embedded in other devices; (5) a receiver, a terminal device, a smart terminal device, a cellular phone, a wireless device, a handset, a mobile unit, a vehicle-mounted device, a network device, a cloud device, an artificial intelligence device, etc.; (6) others, etc.
[0417] Figure 8B is a structural schematic diagram of a chip 8200 according to an embodiment of the present disclosure. For the case where the communication device 8100 is a chip or a chip system, the structural schematic diagram of the chip 8200 shown in Figure 8B can be referred to, but is not limited thereto.
[0418] The chip 8200 comprises one or more processors 8201, and the chip 8200 is configured to execute any of the above methods.
[0419] In some embodiments, the chip 8200 further comprises one or more interface circuits 8202. Optionally, the interface circuit 8202 is connected with the memory 8203, and the interface circuit 8202 can be configured to receive signals from the memory 8203 or other devices, and the interface circuit 8202 can be configured to send signals to the memory 8203 or other devices. For example, the interface circuit 8202 can read instructions stored in the memory 8203 and send the instructions to the processor 8201.
[0420] In some embodiments, the interface circuit 8202 performs at least one of the communication steps (for example, step S2103, but not limited thereto) in the above methods, and the processor 8201 performs at least one of the other steps (for example, step S2101, step S2102, step S2104, step S2105, step S2106, step S2107, but not limited thereto).
[0421] In some embodiments, the terms of interface circuit, interface, transceiver pin, transceiver, etc. can be replaced with each other.
[0422] In some embodiments, the chip 8200 further comprises one or more memories 8203 configured to store instructions. Optionally, all or part of the memory 8203 can be outside the chip 8200.
[0423] The present disclosure further proposes a storage medium, and instructions are stored on the storage medium. When the instructions are executed on the communication device 8100, the communication device 8100 performs any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer readable storage medium, but is not limited thereto, and it can also be a storage medium readable by other devices. Optionally, the storage medium can be a non-transitory storage medium, but is not limited thereto, and it can also be a transitory storage medium.
[0424] The present disclosure further proposes a program product, and the program product is executed by the communication device 8100, so that the communication device 8100 performs any of the above methods. Optionally, the program product is a computer program product.
[0425] The present disclosure further proposes a computer program, and when the computer program is executed on a computer, the computer program makes the computer perform any of the above methods.
Claims
1. A communication method characterized by comprising: The method is performed by a first terminal, the first terminal being a terminal supporting a multi-hop user terminal to network, U2N, service or a terminal supporting a multi-hop user terminal to user terminal, U2U, service, the method comprising: sending, to a second terminal, a first message, the first message comprising encrypted information, the encrypted information comprising encrypted first information, the first information being used to determine a path of the first terminal to the second terminal.
2. The method of claim 1, wherein, The first information comprises one of: path information of the first terminal to the second terminal; a transaction identification, the transaction identification being used to determine the path of the first terminal to the second terminal.
3. The method according to claim 1 or 2, characterized in that, The method further comprises: determining a key stream based on a first key; encrypting, based on the key stream, second information to obtain the encrypted information, the second information comprising the first information.
4. The method of claim 3, wherein, The second information further comprises at least one of: a relay service code, RSC; user identification information.
5. The method according to claim 3 or 4, characterized in that, The first key is determined based on at least one of: a discovery user encryption key, DUCK; a discovery user scrambling key, DUSK; a long-term credential.
6. The method according to any one of claims 3-5, characterized in that, The key stream is determined based on the first key and at least one of: a counter based on coordinated universal time, UTC; a bearer; direction information; length information; a relay service code, RSC.
7. The method according to any one of claims 3-6, characterized in that, The key stream is set to N least significant bits of a key derivation function, KDF, output, the N being a total length of the second information.
8. A communication method characterized by comprising: The method is performed by a second terminal, the second terminal being a terminal supporting a multi-hop U2N service or a terminal supporting a multi-hop U2U service, the method comprising: receiving a first message sent by a first terminal, the first message comprising encrypted information, the encrypted information comprising encrypted first information, the first information being used to determine a path of the first terminal to the second terminal.
9. The method of claim 8, wherein, The first information comprises one of: path information of the first terminal to the second terminal; a transaction identification, the transaction identification being used to determine the path of the first terminal to the second terminal.
10. The method according to claim 8 or 9, characterized in that, The method further comprises: determining a key stream based on a first key; decrypting, based on the key stream, the encrypted information to obtain second information, the second information comprising the first information.
11. The method of claim 10, wherein, The second information further comprises at least one of: a relay service code, RSC; user identification information.
12. The method according to claim 10 or 11, characterized in that, The method further comprises at least one of: based on the second information obtained after decryption being different from stored second information, determining to abort establishing a PC5 link between the second terminal and the first terminal; based on decryption failure, determining to abort establishing the PC5 link.
13. The method according to any one of claims 10-12, characterized in that, The first key is determined based on at least one of: a discovery user encryption key, DUCK; a discovery user scrambling key, DUSK; a long-term credential.
14. The method according to any one of claims 10-13, characterized in that, The key stream is determined based on the first key and at least one of: a counter based on UTC; a bearer; direction information; length information; a relay service code, RSC.
15. The method according to any one of claims 10-14, characterized in that, The key stream is set to N least significant bits of a KDF output, the N being a total length of the second information.
16. A first terminal, characterized by The first terminal is a terminal supporting a multi-hop U2N service or a terminal supporting a multi-hop U2U service, the first terminal comprising: The transceiver module is configured to send a first message to the second terminal, the first message comprising encryption information, the encryption information comprising encrypted first information, the first information being used to determine a path of the first terminal to the second terminal.
17. A second terminal, comprising: The second terminal is a terminal supporting a multi-hop U2N service or a terminal supporting a multi-hop U2U service, and the second terminal comprises: The transceiver module is configured to receive a first message sent by the first terminal, the first message comprising encryption information, the encryption information comprising encrypted first information, the first information being used to determine a path of the first terminal to the second terminal.
18. A communication device, characterized by Comprise: One or more processors; The communication device is configured to perform the communication method of any one of claims 1-15.
19. A communication system, characterized by Comprise: The first terminal is configured to implement the communication method of any one of claims 1-7; The second terminal is configured to implement the communication method of any one of claims 8-15.
20. A storage medium, the storage medium storing instructions, wherein, When the instructions are run on the communication device, the communication device is caused to perform the communication method of any one of claims 1-15.
21. A computer program product comprising a computer program, characterized in that, The computer program, when executed by the communication device, implements the communication method of any one of claims 1-15.
Citation Information
Patent Citations
Routing method, device and system
CN117158114A
Relay discovery method, communication device, communication system and storage medium
CN117716735A
Routing method, apparatus, and system
US20230319682A1
Terminal identification for communication using relay terminal device
WO2023117873A1
Proximity communication method and apparatus
WO2024050846A1