Data transmission method and apparatus

By generating and sending multicast security parameters, the problem of newly added multicast group nodes lacking security parameters is solved, enabling encryption and integrity protection of multicast transmission in more scenarios and expanding the application scope of multicast transmission.

WO2026007686A1PCT designated stage Publication Date: 2026-01-08HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/101525
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-02
Filing Date
2025-06-17
Publication Date
2026-01-08

AI Technical Summary

Technical Problem

In existing multicast transmission technologies, newly joined nodes in a multicast group lack multicast security parameters, which limits the applicable scenarios for multicast transmission and makes it impossible to perform effective encrypted transmission and integrity protection.

Method used

Generate and send the first multicast security parameters, including the bit sequence of the multicast global frame number, to ensure that nodes newly joining the multicast group can obtain the parameters for encrypted transmission and integrity protection, and transmit data through the logical channel.

Benefits of technology

This expands the applicable scenarios for multicast transmission, enabling encrypted multicast transmission and integrity protection to be applied in more scenarios, thereby improving the reliability and security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025101525_08012026_PF_FP_ABST
    Figure CN2025101525_08012026_PF_FP_ABST
Patent Text Reader

Abstract

The present application provides a data transmission method and apparatus. The method comprises: generating a first multicast security parameter, wherein the first multicast security parameter includes a first bit sequence of a group globally frame number (GGFN), the first bit sequence is locally maintained by a node of a first multicast group, and the first multicast security parameter is used for encrypted transmission and / or integrity protection of multicast; and sending the first multicast security parameter to a first node, wherein the node of the first multicast group includes the first node. The number of scenarios to which multicast transmission is applicable can be increased, so that the application scenarios of the encrypted transmission of multicast are broader.
Need to check novelty before this filing date? Find Prior Art

Description

Method and apparatus for data transmission

[0001] The present application claims priority from the Chinese patent application No. 202410881419.6 filed on July 02, 2024, and entitled "Method and apparatus for data transmission", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0002] The present application relates to the field of communication, and in particular to a method and apparatus for data transmission. BACKGROUND

[0003] With the continuous development of communication technology, data transmission can be achieved in different ways. For example, in different scenarios, the sending end and the receiving end can be devices or apparatuses that are interested in each other, and they can perform unicast communication to achieve data transmission. Alternatively, the sending end can send information to all receiving ends in the same subnet, i.e., through broadcast to perform data transmission. Alternatively, through multicast, the sending end can send information to a group of receiving ends, and the devices or apparatuses in the group can receive the information, i.e., through multicast to achieve data transmission. Multicast transmission can solve the problems of repeated copying of data and repeated occupation of bandwidth in unicast transmission, and can also solve the problem of waste of bandwidth resources in broadcast mode, so it has received extensive attention. As can be seen, multicast transmission has certain transmission advantages.

[0004] In order to ensure the security of data transmission, when performing multicast transmission, the transmitted data can be protected, such as encrypted transmission and integrity protection, to prevent devices or apparatuses outside the group from interfering with the communication within the group, such as tampering and interference. Therefore, how to increase the scenarios in which multicast transmission can be applied and make the application scenarios of multicast encrypted transmission more extensive has become a problem to be solved. SUMMARY

[0005] The present application provides a method and apparatus for data transmission, which can increase the scenarios in which multicast transmission can be applied and make the application scenarios of multicast encrypted transmission more extensive.

[0006] In a first aspect, the present application provides a method for data transmission, which can be performed by a second communication device. The second communication device can refer to a second node (e.g., a management node (also referred to as a management device or a G node), a network device, etc.), a component (e.g., a processor, a chip, or a chip system, etc.) in the second node, or a logic module or software capable of implementing all or part of the functions of the second communication device. The method comprises: generating a first multicast security parameter, the first multicast security parameter comprising a first bit sequence of a group globally frame number (GGFN), the first bit sequence being locally maintained by a node of a first multicast group, the first multicast security parameter being used for encrypted transmission and / or integrity protection of a multicast; and sending the first multicast security parameter to a first node, the node of the first multicast group comprising the first node.

[0007] The present application enables the first node that does not maintain the first bit sequence to obtain the first bit sequence used for encrypted transmission, integrity protection, or encrypted transmission and integrity protection of the multicast, and thus implements context encrypted transmission and / or integrity protection in data transmission of the first multicast group. This method for data transmission effectively solves the limitation that only the node that locally maintains the first bit sequence can perform context encrypted transmission and / or integrity protection, supports new group members (e.g., members that join the first multicast group after the group is established), and enables the node that does not maintain the first bit sequence to perform multicast security parameter configuration, thereby increasing the scenarios in which multicast transmission can be applied and making the application scenarios of multicast transmission more extensive.

[0008] In a possible implementation, one first multicast security parameter corresponds to one logical channel of the first multicast group, or one first multicast security parameter corresponds to multiple logical channels of the first multicast group. That is, the first multicast group corresponds to at least one logical channel for transmitting multicast data, one logical channel can correspond to one first multicast security parameter, the first multicast security parameters of different logical channels can be different, or the first multicast security parameters of several logical channels in the multiple logical channels are the same, or the first multicast security parameters of different logical channels are the same (e.g., all set to zero). The second communication device and the first node can use the first multicast security parameter corresponding to the logical channel to perform context encrypted transmission and / or integrity protection.

[0009] In a possible implementation, the first bit sequence includes a high frame number. The high frame number of the GGFN can be maintained by the nodes in the first multicast group, but for the nodes newly joining the multicast group and the nodes whose maintained high frame number is lost, there is no high frame number, and when the procedures such as the context encryption transmission and / or the integrity protection are performed, the necessary security parameters are missing, which causes the procedures to be incorrect. Therefore, the high frame number is included in the first bit sequence, which can help the nodes without the high frame number to obtain the high frame number, so as to ensure that the procedures such as the context encryption transmission can be implemented when data is transmitted.

[0010] In a possible implementation, the first multicast security parameter further includes a second bit sequence of the GGFN, and the second bit sequence includes one or more of the following: a link control layer sequence number (SN), or a physical layer superframe number and a radio frame number. The second bit sequence can also be carried in the first multicast parameter, and the second bit sequence can indicate other required parameters in the procedures of data transmission, such as the SN, so that the indicated security parameters are more complete and comprehensive, and the correctness of the procedures such as the encryption, decryption, and integrity protection in the transmission is higher.

[0011] In a possible implementation, the method further includes: receiving a first message, the first message including an identity (ID) of the first node; and the generating the first multicast security parameter includes: generating the first multicast security parameter according to the first message. Assuming that the transmission scenario is that a second device and a plurality of first nodes, after the second device receives the first message, the second device can determine which first node sends the first message according to the ID of the first node carried in the first message, for example, the first message is from the first node 1, and the second device can determine whether the first node 1 is a node of the first multicast group according to the ID of the first node 1, and if so, the second device can determine and generate the corresponding first multicast security parameter according to the first multicast group. By determining whether the first node is a node of the first multicast group, it can be effectively avoided that the first multicast security parameter is sent to the node that is not in the first multicast group, and the security of transmission is increased.

[0012] In a possible implementation, if there is a first group key, the first multicast security parameter is obtained, and the first group key is a group key of the first multicast group; and if the first group key is generated, the first multicast security parameter is set to zero. By whether there is the first group key of the first multicast group, different manners are correspondingly used to obtain the first multicast security parameter, so that the method of obtaining the first multicast security parameter is more diverse, and the applicable scenarios are more extensive.

[0013] In a possible implementation, the sending the first groupcast security parameter to the first node comprises: sending the first groupcast security parameter to the first node through an association establishment message; or sending the first groupcast security parameter to the first node through a configuration message. The transmission method provided in the application can be applied in different scenarios, and the first groupcast security parameter is sent to the first node using different messages, so that the application scenarios are more extensive.

[0014] In a second aspect, the application provides a data transmission method, which can be executed by a first communication device. In the case where it is not specially stated, the "first communication device" in the application can refer to the first node itself (for example, a terminal node (also referred to as a T node or a terminal device), etc.), a component (for example, a processor, a chip, or a chip system, etc.) in the first node, or a logic module or software capable of realizing all or part of the functions of the first communication device. The method comprises: receiving a first groupcast security parameter, the first groupcast security parameter comprising a first bit sequence of a GGFN, the first bit sequence being locally maintained by a node of a first groupcast group, and the first groupcast security parameter being used for encrypted transmission and / or integrity protection of groupcast.

[0015] In a possible implementation, one of the first groupcast security parameters corresponds to a logical channel of the first groupcast group; or one of the first groupcast security parameters corresponds to multiple logical channels of the first groupcast group.

[0016] In a possible implementation, the first bit sequence comprises a high frame number.

[0017] In a possible implementation, the first groupcast security parameter further comprises a second bit sequence of the GGFN, the second bit sequence comprising one or more of the following: a link control layer SN; or a physical layer superframe number and a radio frame number.

[0018] In a possible implementation, the method further comprises: sending a first message, the first message comprising an ID of the first node.

[0019] In a possible implementation, the receiving the first groupcast security parameter comprises: receiving the first groupcast security parameter through an association establishment message; or receiving the first groupcast security parameter through a configuration message.

[0020] It should be understood that the second aspect of the application corresponds to the technical solutions of the first aspect of the application, and the beneficial effects obtained by each aspect and the corresponding possible implementation are similar, which will not be repeated here.

[0021] In a third aspect, the present application provides a second communication device, which can be a second node itself (for example, a network device, a management device, etc.), a component in the second node (for example, a management node (which can also be referred to as a management device or a G node), a network device, etc.), a component in the second node (for example, a processor, a chip, or a chip system, etc.), or a logic module or software capable of realizing all or part of the functions of the second communication device. The second communication device comprises: a processing module configured to generate a first multicast security parameter, the first multicast security parameter comprising a first bit sequence of a GGFN, the first bit sequence being locally maintained by a node of a first multicast group, and the first multicast security parameter being used for encrypted transmission and / or integrity protection of a multicast; and a sending module configured to send the first multicast security parameter to a first node, the node of the first multicast group comprising the first node.

[0022] In a possible implementation, one of the first multicast security parameters corresponds to a logical channel of the first multicast group; or one of the first multicast security parameters corresponds to multiple logical channels of the first multicast group.

[0023] In a possible implementation, the first bit sequence comprises a high frame number.

[0024] In a possible implementation, the first multicast security parameter further comprises a second bit sequence of the GGFN, the second bit sequence comprising one or more of: a link control layer SN; or a physical layer superframe number and a radio frame number.

[0025] In a possible implementation, the second communication device further comprises: a receiving module configured to receive a first message, the first message comprising an ID of the first node; and the processing module is specifically configured to generate the first multicast security parameter according to the first message.

[0026] In a possible implementation, the processing module is further configured to obtain the first multicast security parameter if there is a first group key, the first group key being a group key of the first multicast group; and set the first multicast security parameter to zero if the first group key is generated.

[0027] In a possible implementation, the sending module is specifically configured to send the first multicast security parameter to the first node through an association establishment message; or send the first multicast security parameter to the first node through a configuration message.

[0028] It should be understood that the third aspect of the present application is the same as the technical solution of the first aspect of the present application, and the beneficial effects obtained by each aspect and the corresponding possible implementation are similar, which will not be described here.

[0029] In a fourth aspect, the present application provides a first communication device, which can be a first node (e.g., a terminal node (also referred to as a T node or a terminal device) or the like) itself, a component (e.g., a processor, a chip, or a chip system, or the like) in the first node, or a logic module or software capable of implementing all or part of the functions of the first communication device. The first communication device comprises a receiving module configured to receive a first groupcast security parameter, the first groupcast security parameter comprising a first bit sequence of a GGFN, the first bit sequence being locally maintained by a node of a first groupcast group, the first groupcast security parameter being used for encrypted transmission and / or integrity protection of groupcast.

[0030] In a possible implementation, one of the first groupcast security parameters corresponds to a logical channel of the first groupcast group; or one of the first groupcast security parameters corresponds to multiple logical channels of the first groupcast group.

[0031] In a possible implementation, the first bit sequence comprises a high frame number.

[0032] In a possible implementation, the first groupcast security parameter further comprises a second bit sequence of the GGFN, the second bit sequence comprising one or more of: a link control layer SN; or a physical layer superframe number and a radio frame number.

[0033] In a possible implementation, the first communication device further comprises a sending module configured to send a first message, the first message comprising an ID of the first node.

[0034] In a possible implementation, the receiving module is specifically configured to receive the first groupcast security parameter through an association establishment message; or the receiving module is specifically configured to receive the first groupcast security parameter through a configuration message.

[0035] It should be understood that the fourth aspect of the present application corresponds to the technical solution of the first aspect of the present application, and is the same as the technical solution of the second aspect of the present application, and the beneficial effects achieved by each aspect and the corresponding possible implementation are similar, which will not be described here again.

[0036] In a fifth aspect, the present application provides a communication device, which can be a node or a device (e.g., a chip) in the node. The communication device comprises a module (e.g., a processing module and a transceiving module) for performing the method as described in any of the above aspects or any possible implementation of any of the above aspects.

[0037] In a sixth aspect, the present application provides a communication apparatus, which can be a node or a device (e.g., a chip) in a node. The communication apparatus includes a transceiver and a processor for performing the method according to any one of the preceding aspects or any possible implementation of any one of the preceding aspects. The transceiver can be a radio frequency module, and the processor can include or not include a memory.

[0038] Optionally, the communication apparatus includes a transceiver, a memory and a processor for performing the method according to any one of the preceding aspects or any possible implementation of any one of the preceding aspects. The memory can be arranged in the communication apparatus or can be an external device of the communication apparatus.

[0039] In a seventh aspect, the present application provides a communication apparatus, which includes an input / output interface and a logic circuit. The input / output interface is configured to obtain input information and / or output information. The logic circuit is configured to perform the method according to any one of the preceding aspects or any possible implementation of any one of the preceding aspects, and process the input information and / or generate the output information.

[0040] In an eighth aspect, the present application provides a communication apparatus, which includes at least one processor and a storage medium. The at least one processor is coupled to the storage medium. The storage medium stores instructions, which are executed by the processor to perform the method according to any one of the preceding aspects or any possible implementation of any one of the preceding aspects. The storage medium can be arranged in the communication apparatus or can be an external device of the communication apparatus.

[0041] In a ninth aspect, the present application provides a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement the method according to any one of the preceding aspects or any possible implementation of any one of the preceding aspects.

[0042] In a tenth aspect, the present application provides a computer program product, which includes instructions for implementing the method according to any one of the preceding aspects or any possible implementation of any one of the preceding aspects when the instructions are executed on a processor.

[0043] In an eleventh aspect, the present application provides a chip, which includes an interface circuit and a processor. The interface circuit is connected to the processor. The processor is configured to cause the chip to perform the method according to any one of the preceding aspects and / or any possible implementation of any one of the preceding aspects.

[0044] In a twelfth aspect, the embodiments of the present application further provide a chip, comprising: at least one processor, the at least one processor being configured to execute code in a memory, when the at least one processor executes the code, the chip implements the method in any one of the preceding aspects and the parts or all operations included in any possible implementation manner of the preceding aspects.

[0045] Optionally, the chip further comprises a memory. The memory can be integrated with the processor, or can be separately arranged from the processor. The memory can be integrated on the same chip with the processor, or can be separately arranged on different chips.

[0046] Optionally, the chip can be an integrated circuit.

[0047] In a thirteenth aspect, the present application provides a system, which comprises the second communication device according to the third aspect and the first communication device according to the fourth aspect.

[0048] In a fourteenth aspect, the present application provides a system, which comprises the device according to any one of the third aspect to the twelfth aspect.

[0049] It should be understood that the fifth aspect to the fourteenth aspect of the present application are consistent with or corresponding to the technical solutions of the first aspect and the second aspect of the present application, and the beneficial effects obtained by the aspects and the corresponding feasible implementation manners are similar, which will not be described here. BRIEF DESCRIPTION OF DRAWINGS

[0050] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the description of the embodiments of the present application will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0051] Fig. 1 is a structural schematic diagram of a communication system 100 provided by the embodiments of the present application;

[0052] Fig. 2 is a schematic diagram of an example Starlink protocol framework provided by the embodiments of the present application;

[0053] Fig. 3 is a flow schematic diagram of a data transmission method provided by the embodiments of the present application;

[0054] Fig. 4 is a flow schematic diagram of a data transmission method provided by the embodiments of the present application;

[0055] Fig. 5a is a flow schematic diagram of a data transmission method provided by the embodiments of the present application;

[0056] Fig. 5b is a flow diagram of a fourth embodiment of a data transmission method according to the present application;

[0057] Fig. 6 is a flow diagram of a fifth embodiment of a data transmission method according to the present application;

[0058] Fig. 7 is a flow diagram of a sixth embodiment of a data transmission method according to the present application;

[0059] Fig. 8 is a flow diagram of a seventh embodiment of a data transmission method according to the present application;

[0060] Fig. 9 is a flow diagram of an eighth embodiment of a data transmission method according to the present application;

[0061] Fig. 10 is a flow diagram of a confidentiality protection method according to the present application;

[0062] Fig. 11 is a flow diagram of an integrity protection method according to the present application;

[0063] Fig. 12 is a flow diagram of an authentication encryption method according to the present application;

[0064] Fig. 13 is a schematic diagram of a structure of a second communication device according to the present application;

[0065] Fig. 14 is a schematic diagram of a structure of a second communication device according to the present application;

[0066] Fig. 15 is a schematic diagram of a structure of a first communication device according to the present application;

[0067] Fig. 16 is a schematic diagram of a structure of an apparatus 50 according to the present application;

[0068] Fig. 17 is a schematic diagram of a structure of an apparatus 60 according to the present application. DETAILED DESCRIPTION

[0069] In order to enable persons skilled in the art to better understand the schemes in the present application, the technical schemes in the present application will be described clearly and completely below in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments.

[0070] The term "and / or", merely describes an associated relationship, which means that there can be three relationships, for example, A and / or B, which means that A exists alone, A and B exist together, B exists alone, and A, B can be single or multiple. "At least one of the following" or similar expressions are used to represent any combination of the listed items, for example, at least one of A, B and (or) C, which means that A exists alone, B exists alone, C exists alone, A and B exist together, B and C exist together, A and C exist together, A, B and C exist together, and A, B, C can be single or multiple.

[0071] The terms "first" and "second" and the like in the description and claims of the present application are used to distinguish different objects, not to describe a specific order of the objects. For example, the first target object and the second target object are used to distinguish different target objects, not to describe a specific order of the target objects.

[0072] In the embodiments of the present application, the words "exemplary" or "for example" are used to mean serving as an example, instance, or illustration. Any embodiment or design presented as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or advantageous than other embodiments or designs. Rather, the use of "exemplary" or "for example" is intended to present concepts in a concrete manner.

[0073] In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality of" is two or more. For example, a plurality of processing units means two or more processing units; a plurality of systems means two or more systems.

[0074] For ease of understanding, the related terms or terms used in the embodiments of the present application are explained as follows:

[0075] 1、Starlink (technology)

[0076] Starlink alliance is established and committed to promoting innovation of new generation of wireless short distance communication technology, Starlink technology can be applied in intelligent vehicles, smart home, intelligent terminals and intelligent manufacturing, etc. and meet the extreme performance requirements. The nodes involved in the embodiments of the present application can communicate based on the new generation of wireless short distance communication technology designed by Starlink alliance, and the new generation of wireless short distance communication system based on Starlink alliance designed in the embodiments of the present application is simply referred to as Starlink wireless communication system.

[0077] 2、G node and T node

[0078] The G node refers to a management node, which can be applied in a star flash wireless communication system as a node for sending data scheduling information. The T node refers to a terminal node, which can be applied in a star flash wireless communication system as a node for receiving data scheduling information and sending data according to the data scheduling information. Embodiments of the present application take the G node and the T node as examples for description in the star flash wireless communication system, but are not limited thereto. The G node and the T node can also be applied in other systems, and the data transmission method of the embodiments of the present application can be used for multicast transmission.

[0079] 3. Initialization vector (IV), also referred to as initial vector, initial vector, etc.

[0080] It is an input value, and the length of the input value can be fixed, usually a random number or a pseudo-random number.

[0081] 4. Multicast global frame number (GGFN)

[0082] In a network, especially in a data link layer (such as Ethernet) or a physical layer (such as Wi-Fi), a frame number refers to a unique identifier or sequence number of a network frame. Each transmitted data frame is assigned a frame number for unique identification and sequential recombination of the frame at the receiving end. The GGFN is the frame number of the multicast data.

[0083] The communication system 100 to which the embodiments of the present application are applicable can include a plurality of nodes including electronic devices with data transceiving capability. For example, the nodes can be cockpit domain devices, or one of the modules in the cockpit domain devices (e.g., one or more of a cockpit domain controller (CDC), a camera, a screen, a microphone, a speaker, an electronic key, a keyless entry or start system controller, etc.). In specific implementations, the nodes can also include data relay devices such as routers, repeaters, bridges, or switches; terminal devices such as various types of user equipment (UE), mobile phones, pads, desktop computers, earphones, speakers, etc.; machine intelligence devices such as self-driving devices, transportation safety devices, virtual reality (VR) terminal devices, augmented reality (AR) terminal devices, machine type communication (MTC) devices, industrial control devices, remote medical devices, smart grid devices, smart city devices; wearable devices (e.g., smart watches, smart bands, pedometers, etc.); and the like. In certain technical scenarios, the names of devices with similar data transceiving capability can not be referred to as nodes, but for the convenience of description, electronic devices with data transceiving capability are collectively referred to as nodes in the embodiments of the present application.

[0084] The node can be applied to various types of communication systems. For example, referring to FIG. 1, the node can be applied to a communication system 100, which includes at least one first node 10 and at least one second node 20. If the communication system 100 is a Starlink wireless communication system, the first node can be a T node, and the second node can be a G node, both of which support Starlink Alliance protocols. In addition, the first node and the second node can also be nodes in a wireless local area network (WLAN), a narrowband Internet of Things (NB-IoT), a global system for mobile communications (GSM), an enhanced data rates for GSM evolution (EDGE), a wideband code division multiple access (WCDMA), a code division multiple access 2000 (CDMA2000), a time division-synchronous code division multiple access (TD-SCDMA), an LTE system, a satellite communication, a fifth-generation (5G) communication system, a sixth-generation (6G) communication system, or a new communication system to be developed in the future, as a sending end or a receiving end, and the embodiments of the present application are not limited thereto. The communication system 100 shown in FIG. 1 is only used for example and is not intended to limit the technical solutions of the present application. Those skilled in the art should understand that in the specific implementation process, the communication system 100 can also include other devices, and the number of nodes can also be determined according to specific needs, and is not limited.

[0085] Referring to the communication system 100 shown in FIG. 1, the first node 10 and the second node 20 can both be a sending end or a receiving end. In the embodiments of the present application, the initiator of communication is defined as a sending end device, and the receiver of communication is defined as a receiving end device. For example, when the G node sends information to the T node, the G node is the sending end device and the T node is the receiving end device. When the T node sends information to the G node, the T node is the sending end device and the G node is the receiving end device.

[0086] The sending end device and the receiving end device provided by the embodiments of the present application can be any device with a transceiving function, including but not limited to: an evolved Node B (NodeB or eNB or e-NodeB, evolutional Node B) in a long term evolution (LTE) system of a general mobile communication technology, a base station (gNodeB or gNB) or a transmission receiving point (TRP) in a new radio (NR) system, a base station evolved from the 3rd generation partnership project (3GPP), an access node in a wireless communication system (such as WiFi, Bluetooth, etc.), a wireless relay node, a wireless backhaul node, a data relay device (such as a router, a relay, a bridge or a switch), etc. The base station can be: a macro base station, a micro base station, a pico base station, a small station, a relay station, or a balloon station, etc.

[0087] The sending end device or the receiving end device can also be a wireless controller, a centralized unit (CU) and / or a distributed unit (DU) in a cloud radio access network (CRAN) scenario.

[0088] The sending end device or the receiving end device can also be a server, a wearable device (such as a smart watch, a smart bracelet, a pedometer, etc.), a machine communication device, or a vehicle-mounted device, etc.

[0089] The sending end device or the receiving end device can also be a mobile phone, a tablet computer (Pad), a computer with wireless transceiver function, a headset, a sound equipment, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a terminal in machine type communication (MTC), a terminal in industrial control, a vehicle-mounted terminal device, a terminal in self driving, a terminal in auxiliary driving, a terminal in remote medical, a terminal in smart grid, a terminal in transportation safety, a terminal in smart city, a terminal in smart home, and a robot, a smart robot, etc. The terminal can also be referred to as a terminal device, a user equipment (UE), an access terminal device, a vehicle-mounted terminal, an industrial control terminal, a UE unit, a UE station, a mobile station, a mobile station, a remote station, a remote terminal device, a mobile device, a UE terminal device, a wireless communication device, a machine terminal, a UE agent, or a UE apparatus, etc. The terminal can be fixed or mobile.

[0090] The sending end device or the receiving end device can also be a car cockpit domain device, or a module (a cockpit domain controller (CDC), a camera, a screen, a microphone, a sound equipment, an electronic key, a keyless entry and start system controller, etc.) in the car cockpit domain device.

[0091] Embodiments of the present application do not limit the application scenarios, and for the purpose of describing the multicast data transmission method, the embodiments of the present application take the multicast transmission in the star flash system as an example, but are not limited thereto.

[0092] The embodiment of the present application provides a star flash alliance protocol framework, which can support the star flash alliance wireless short-distance communication technology and implement the complete process of short-distance service for the above-mentioned scenario. FIG. 2 is a schematic diagram of an exemplary star flash alliance protocol framework provided by the embodiment of the present application. The protocol framework can be applied to any node that can implement short-distance communication, such as any one node in the communication system 100 shown in FIG. 1. Referring to FIG. 2, the protocol framework 200 includes an access layer 201, a network and transmission layer 202 and an application layer 203 from bottom to top, wherein the access layer 201 can be used to process the bottom logical link, such as the access layer 201 can be responsible for the establishment, reconfiguration, deletion and the like of the logical link, to undertake the service requirements of the network and transmission layer 202. Exemplarily, the access layer 201 includes various access technologies, such as the access technology of the star flash basic (SLB) short-distance wireless communication system, the access technology of the star flash low energy (SLE) short-distance wireless communication system and other access technologies and the like. The network and transmission layer 202 can be used to create, add, delete and release transmission channels and the like, and can also be used for the control of the logical link, such as selecting a certain access technology, to undertake the traffic, rate and the like service requirements of the application layer 203. The application layer 203 can be divided into the transmission of the control plane and the transmission of the service plane and the like.

[0093] In combination with the protocol framework 200, the channel of data transmission is described: the transmission path of the network and transmission layer 202 can be defined as a transmission channel (TC), the transmission channel can implement that multiple transmission channels are mapped to the same logical channel, or one transmission channel can also map the logical channels of different access systems. The logical channel (LC) is the transmission path of the access layer 201, which can undertake the mapping of multiple transmission channels, and optionally, the logical channel can also be referred to as a logical link, a logical channel and the like, and the embodiment of the present application is exemplarily described by taking the logical channel, but is not limited. Further, in order to distinguish the logical channels, the embodiment of the present application defines the identification (LCID) of the logical channel, which is used to uniquely identify the logical channel, that is, each logical channel corresponds to an LCID.

[0094] Since the multicast transmission can solve the problem of repeated copying of data and repeated occupation of bandwidth in the unicast case, and can also solve the waste of bandwidth resources in the broadcast mode, it is more applicable to more scenarios. Taking a multicast authentication and security context negotiation process as an example, the steps of multicast data transmission are briefly described: the G node can first broadcast the key negotiation algorithm capability; the T node in the multicast group sends an association request message to the G node; the G node sends a security context request message, and the T node feeds back a security context response message, and after the G node receives the response message, the G node can send an association establishment message, and in the association establishment message, the group key, group ID, group algorithm, group key validity period and other multicast security parameters of the multicast group to which the T node belongs are issued; the T node receives the association establishment message, feeds back an association completion message, and performs encrypted communication with the G node according to the multicast security parameters. After the establishment of this encrypted process, data transmission is applicable to the encryption communication between the T node in the multicast group and the G node when the group is established (the multicast group is established), but it does not consider the new group members (hereinafter referred to as new group members) after the group is established. The new group members cannot obtain some security parameters (or first bit sequence) maintained (or saved) locally by the T node in the multicast group for encrypted transmission and / or integrity protection, that is, the new group members are limited by the lack of the first bit sequence, and the multicast security parameters that the new group members can obtain are insufficient to support subsequent encrypted transmission, or integrity protection, or encrypted transmission and integrity protection, etc. Operation, limiting the applicable range of multicast transmission. In order to solve this problem, the data transmission method provided by the embodiment of the application can support the new group members to obtain the first bit sequence, increase the scenarios applicable to the multicast transmission, and make the application scenarios of the multicast transmission more extensive.

[0095] The data transmission method provided by the embodiment of the application can be applied to wireless short-range communication for communication to realize wireless transmission of information sharing and services, such as the method can be applied to the star flash wireless communication system. FIG. 3 is one of the flow diagrams of the data transmission method provided by the embodiment of the application, which is taken as an example to illustrate that the method is executed by the second device, which can be a device in the G node or the G node. The embodiment of the application does not limit it. In the flow diagram shown in FIG. 3, the second device can be regarded as a sending end device, and the T node (including the first node) can be regarded as a receiving end device. As shown in FIG. 3, the method includes S101 to S102.

[0096] S101, the second device generates first multicast security parameters, the first multicast security parameters include a first bit sequence of the GGFN, the first bit sequence is maintained locally by the nodes of the first multicast group, and the first multicast security parameters are used for encrypted transmission and / or integrity protection of the multicast.

[0097] The second device is a G node, for example. The G node establishes a multicast group with at least one T node. The multicast group can be defined as a first multicast group. The first multicast group can include at least one T node that joins the group when the group is established, and can also include a new member (such as a T node, which can be defined as a first node) that joins the group after the group is established. Each T node that joins the group when the group is established locally maintains (or is locally stored with) a first bit sequence. The first bit sequence can be used for encrypted transmission, integrity protection, or encrypted transmission and integrity protection of the first multicast group. The first node also needs to obtain the first bit sequence for encrypted transmission, integrity protection, or encrypted transmission and integrity protection. That is, the first node needs to perform step S102. That is, the first multicast group includes a plurality of T nodes, and the plurality of nodes include at least one T node that joins the group after the group is established, which is defined as a first node. Each first node needs to perform step S102 to enable encrypted transmission and / or integrity protection of the multicast group in subsequent transmission.

[0098] In S102, the second device sends a first multicast security parameter to the first node. The nodes of the first multicast group include the first node.

[0099] The first multicast security parameter sent by the second device to the first node includes the first bit sequence, which can facilitate the first node to receive and locally maintain the first bit sequence to enable encrypted transmission, integrity protection, or encrypted transmission and integrity protection in transmission of the first multicast group.

[0100] The first multicast security parameter can be a GGFN, and the first bit sequence can be a bit sequence of a high frame number of the GGFN, such as a bit sequence corresponding to a high frame number. The high frame number includes at least one of HFN or HSFN.

[0101] It should be understood that the second device can send the first multicast security parameter to any T node in the first multicast group. The embodiments of the present application are described by taking the second device sending the first node as an example, but are not limited thereto.

[0102] The embodiments of the present application enable the first node to obtain the first bit sequence for encrypted transmission, or integrity protection, or encrypted transmission and integrity protection of the multicast group by sending the first multicast security parameter to the first node in the first multicast group. Then, the first node can perform context encrypted transmission and / or integrity protection in data transmission of the first multicast group. The embodiments of the present application effectively solve the problem that only the T node that joins the first multicast group when the group is established locally maintains the first bit sequence, and the T node that newly joins the first multicast group cannot obtain the first bit sequence. The embodiments of the present application can support configuration of the multicast security parameter of the new group member, increase the scenarios in which the multicast transmission can be applied, and make the application scenarios of the multicast transmission more extensive.

[0103] In a possible implementation, the first groupcast security parameter can include a first bit sequence, or the first groupcast security parameter can include a first bit sequence and a second bit sequence. The first bit sequence can include at least one of a high frame number (HFN) or a high super frame number (HSFN), and the second bit sequence includes one or more of the following: a link control layer sequence number SN, or a physical layer super frame number and a radio frame number.

[0104] For example, the first groupcast security parameter can be a GGFN, including an HFN and a link control layer SN, where the first bit sequence is the HFN and the second bit sequence is the link control layer SN; or the first groupcast security parameter can be a GGFN, including an HSFN, a physical layer super frame number, and a radio frame number, where the first bit sequence is the HSFN and the second bit sequence is the physical layer super frame number and the radio frame number; or the first groupcast security parameter can be a first bit sequence, such as the first bit sequence is a high frame number, and the high frame number includes at least one of an HFN or an HSFN.

[0105] In a possible implementation, based on FIG. 3, the flow of the data transmission method can further include other steps. For example, FIG. 4 is a flowchart of another data transmission method provided by an embodiment of the application, which is described by taking that a second device executes the method as an example. The second device can be a device in a G node, or can be a G node, which is not limited in the embodiment of the application. In the flowchart shown in FIG. 4, the second device can be regarded as a sending end device, and a T node (including a first node) can be regarded as a receiving end device. As shown in FIG. 4, the method includes S201 to S203.

[0106] S201, the second device receives a first message, and the first message includes an ID of the first node.

[0107] Optionally, in some possible implementation scenarios, a second device can receive a first message sent by multiple first nodes (in the embodiment of the application, the first node can refer to a T node). Some of the first nodes are nodes that newly join a groupcast group, and some of the first nodes are nodes that are in the groupcast group when the group is established. Since the nodes that are in the groupcast group when the group is established have already maintained the required groupcast security parameter (defined as a first groupcast security parameter in the embodiment of the application) locally, the embodiment of the application can be described by taking a T node that newly joins the groupcast group or a T node that loses the maintained first groupcast security parameter as an example to illustrate data transmission as the first node.

[0108] For example, referring to the multicast authentication and security context negotiation procedure in the above example, the first message can be an association request message, and the first message includes the ID of the first node. The first message can be different in different application scenarios, and is not limited by the examples of the embodiments of the present application.

[0109] S202, the second device generates first multicast security parameters according to the first message.

[0110] For example, assuming that a first multicast group has been established in a transmission scenario of one G node and multiple T nodes, the G node can determine whether the first node from which the first message originates is a node of the first multicast group according to the first message after receiving the first message. The determination method is not limited. The embodiments of the present application take the second device obtaining the ID (or fixed ID) of the first node according to the first message as an example for description. The second device can determine whether the first node belongs to the first multicast group based on the ID of the first node, and generate first multicast security parameters based on the related parameters of the first multicast group if the first node belongs to the first multicast group. For example, the G node obtains the fixed ID of the first node (such as a T node 1) from the first message, determines whether the G node has preconfigured a group ID corresponding to the fixed ID of the T node 1 according to the fixed ID, and generates first multicast security parameters based on the multicast group corresponding to the group ID (such as the first multicast group) if the G node has preconfigured the group ID corresponding to the fixed ID of the T node 1.

[0111] For example, the first multicast group corresponds to at least one logical channel for transmitting multicast data. Optionally, one first multicast security parameter generated by the G node corresponds to one logical channel of the first multicast group; or one first multicast security parameter generated by the G node corresponds to multiple logical channels of the first multicast group.

[0112] For example, if the G node determines that the first multicast group has a group key (which can be defined as a first group key), the G node obtains the first multicast security parameters of the first multicast group. If the G node determines that the first multicast group currently does not have a group key, the G node generates a first group key and sets all the first multicast security parameters of the first multicast group to zero.

[0113] In summary of the above description, if the first multicast group corresponds to M logical channels, the G node can obtain M first multicast security parameters, which means that each logical channel corresponds to one first multicast security parameter. Alternatively, the first multicast group corresponds to M logical channels, and the G node can obtain N first multicast security parameters, where M is a positive integer, and N is a positive integer less than M, which means that multiple logical channels correspond to one first multicast security parameter.

[0114] S203, the second device sends the first multicast security parameters to the first node.

[0115] The second device determines, through the first message, that the first node from which the first message originates is a node in the first multicast group, and can generate and send, to the first node, first multicast security parameters for encrypted transmission and / or integrity protection in multicast data transmission based on relevant parameters of the first multicast group, such as whether there is a group key. After the first node learns the first multicast security parameters, the first node can perform one or more of encrypted transmission, integrity protection, and the like in subsequent data transmission with the G node according to the first multicast security parameters, thereby effectively configuring the first multicast security parameters for a new member (a T node that joins the first multicast group after the group is established) of the first multicast group or a group member (a T node that joins the first multicast group when the group is established) that has lost the locally maintained first multicast security parameters due to some reason, increasing the scenarios in which multicast transmission can be applied and making the application scenarios of multicast transmission more extensive.

[0116] FIG. 5a is a flow diagram of a data transmission method provided by an embodiment of the present application, which is described by taking an example of a first device performing the method. The first device can be a device in a T node (such as the first node) or a T node (such as the first node), which is not limited by the present application. In the flow diagram shown in FIG. 5, the G node can be regarded as a sending end device, and the first device can be regarded as a receiving end device. As shown in FIG. 5a, the method includes S301.

[0117] S301, the first device receives first multicast security parameters, the first multicast security parameters including a first bit sequence of a GGFN, the first bit sequence being locally maintained by a node of the first multicast group, and the first multicast security parameters being used for one or more of encrypted transmission or integrity protection of multicast.

[0118] The first multicast security parameters received by the first device can be the first multicast security parameters generated and sent by the second device in the examples of FIG. 3 or FIG. 4, which is not described again. The method shown in FIG. 5a can achieve the effect of increasing the scenarios in which multicast transmission can be applied and making the application scenarios of multicast transmission more extensive.

[0119] In a possible implementation manner, the present application can also provide a data transmission method, which is shown in FIG. 5b and includes S302 on the basis of FIG. 5a.

[0120] S302, the first device uses the first multicast security parameters to perform multicast transmission.

[0121] For example, the first device can parse data on a corresponding logical channel based on the first multicast security parameters to implement one or more of encrypted transmission or integrity protection.

[0122] The data transmission method provided in FIG. 3 to FIG. 5b of the embodiments of the present application can be implemented in different manners in different scenarios. For example, the G node can send the first groupcast security parameter to at least one T node in the first groupcast group through an association establishment message; or the G node can send the first groupcast security parameter to at least one T node included in the first groupcast group through a configuration message, and the like.

[0123] The method is exemplarily described below by taking different frame numbers of the first groupcast security parameter and sending the first groupcast security parameter to the T node through the association establishment message or the configuration message as examples, but is not limited thereto.

[0124] FIG. 6 is a flowchart of a fifth data transmission method provided by the embodiments of the present application, which is executed by the G node and the T node, and can also be executed by the device in the node, and the embodiments of the present application are not limited thereto. FIG. 6 exemplarily describes the method by taking the method executed by the G node and the T node as an example. As shown in FIG. 6, the method includes S401 to S405.

[0125] S401. The T node sends an association request message to the G node.

[0126] The association request message can include the ID of the T node, such as the fixed ID of the T node, for identifying the T node. Optionally, the association request message can further include at least one of the key exchange algorithm (KE alg), the key exchange algorithm timestamp (KEt), the security capability set (sec capabilities) or the random number (NONCEt) for establishing the request, for guaranteeing the security of the wireless network, wherein the KEt represents the timestamp used in the key exchange algorithm, for ensuring the security of the key exchange; the security capability set (sec capabilities) can be used to describe the encryption and authentication capabilities of the two communication parties (such as the G node and the T node in the embodiments of the present application), so as to facilitate the selection of appropriate encryption and authentication algorithms; and the random number (NONCEt) can be used to prevent replay attacks and the like.

[0127] S402. The G node sends a security context request message to the T node.

[0128] Exemplarily, the security context request message can carry at least one of the encryption session key (KEg), the random number (NONCEg), the encryption context identifier (Kgt ID) or the encryption algorithm (algorithm), and the security context request message can further include the field of the message integrity check (MIC).

[0129] S403, the T-node sends a security context response message to the G-node.

[0130] For example, the security context response message can carry a message authentication code (AUTHt) for verifying message integrity.

[0131] S404, the G-node sends an association setup message to the T-node, and the association setup message includes a GGFN.

[0132] For example, the GGFN includes a first bit sequence and a second bit sequence. That is, the GGFN can include an HFN and a link control layer SN, or the GGFN can include an HSFN, a physical layer superframe number, and a radio frame number, etc. The first bit sequence of the GGFN can refer to the example of S102, and the second bit sequence of the GGFN can also refer to the description of the above examples, which will not be described here.

[0133] After the G-node receives the association request message and the context response message sent by the T-node, the G-node can determine that the T-node is a member of the first multicast group based on the association request message. It should be understood that when a new member joins the first multicast group, the member list in the first multicast group, which can also be referred to as a group ID, will be updated, and the updated group ID should include the fixed ID (such as a physical layer ID (phy-ID)) of the T-node. For example, the G-node can determine whether the G-node is preconfigured with a group ID corresponding to the fixed ID of the T-node according to the fixed ID of the T-node. If there is a group ID corresponding to the fixed ID of the T-node, such as the fixed ID of the T-node 1, in the group ID of the first multicast group, it means that the G-node determines that the T-node 1 is a member of the first multicast group.

[0134] For example, after the G-node determines that the T-node is a node of the first multicast group, the G-node can first determine whether the first multicast group, to which the T-node belongs, has a group key (GK) and a group algorithm (galgorithm).

[0135] For example, the G node judges whether there is a group key (GK) of the first multicast group. In one possible case, the first multicast group does not have a group key (GK), based on which the G node generates a random number, such as a random number (rand), and generates a group key (GK) according to the group ID of the first multicast group and the random number (rand), and generates a group key identifier (GK ID) of the group key (GK). After the group key (GK) is generated, the GGFN is initialized to 0, that is, the first bit sequence and the second bit sequence in the GGFN are both set to zero. For example, assuming that the first multicast group corresponds to M logical channels, the GGFN of the M logical channels can all be initialized to 0. In another possible case, the first multicast group has a group key (GK), and the G node obtains the GGFN of different logical channels of the current multicast. Table 1 is an example of the GGFN corresponding to the logical channels of the first multicast group provided in an embodiment of the present application. As shown in the example of Table 1, each logical channel of the first multicast group corresponds to a GGFN.

[0136] Table 1

[0137] Referring to the example of Table 1, the first multicast group includes two logical channels, which are respectively identified as LCID 1 and LCID 2, and each channel corresponds to a GGFN, such as that the GGFN corresponding to LCID 1 is GGFN 1, and the GGFN corresponding to LCID 2 is GGFN 2. It should be understood that the bytes occupied by each LCID and GGFN in Table 1 and the bit positions are all examples and are not limited, and the frame numbers of GGFN 1 and GGFN 2 can be determined in actual use scenarios, which are only distinguished by GGFN 1 and GGFN 2 here, but are not limited.

[0138] The G node judges whether there is a group algorithm (galgorithm). In one possible case, the first multicast group does not determine a group algorithm (galgorithm), and the G node can select a group algorithm (galgorithm) from the algorithms supported by all T nodes in the first multicast group according to a preconfigured algorithm preference strategy. The method for the G node to obtain the group algorithm (galgorithm) in the case that the first multicast group does not determine a group algorithm (galgorithm) is not limited by the example of the embodiment of the present application. The group algorithm (galgorithm) includes a key derivation function, an encryption algorithm, and an integrity protection algorithm or an authentication encryption algorithm, etc., wherein the key derivation function has the highest priority. In another possible case, the first multicast group has a group algorithm (galgorithm), and the G node uses the current group algorithm (galgorithm).

[0139] The G node further derives the encryption key and the integrity protection key, or the authentication encryption key from the group key (GK) according to the obtained group algorithm (galgorithm), such as a key derivation function. The G node and the T node can perform encrypted transmission on the data to be transmitted through the derived key.

[0140] For example, in the association establishment message, in addition to the GGFN corresponding to each logical channel obtained by the G node through the above method, the association establishment message can further include at least one of the temporary ID, the encryption context expiration time (Kgt expiration), the group key (GK) (carrying the GK when the encryption protection of the unicast signaling plane is enabled), the GKc (carrying the GKc when the encryption protection of the unicast signaling plane is not enabled, and the G node encrypts the GK to obtain the GKc), the group key identifier (GK ID), the group algorithm (galgorithm), and the validity period of the group key, or the group key expiration time (GK expiration). The GKc / GK indicates that the GKc is carried when the encryption protection of the unicast signaling plane (that is, for transmission between one T node in the first multicast group and the G node, which can be regarded as unicast) is not enabled, and the GK is carried when the encryption protection of the unicast signaling plane is enabled.

[0141] Optionally, the association establishment message can further include the MIC to verify the integrity and authenticity of the association establishment message including the foregoing content, and to ensure that the message is not tampered with or impersonated during transmission.

[0142] S405, the T node sends an association completion message to the G node.

[0143] Optionally, the association completion message can include the MIC to verify the integrity and authenticity.

[0144] The method provided by the embodiments of the application indicates the GGFN to the T node through the association establishment message sent to the T node, so that the nodes in the first multicast group that do not locally maintain the GGFN can obtain the GGFN and perform at least one of the encrypted transmission and the integrity protection of the multicast. The nodes in the first multicast group that do not locally maintain the GGFN include new members that join the first multicast group, or group members that lose the locally maintained GGFN, and the like. The data transmission method provided by the embodiments of the application effectively avoids errors in the encrypted transmission and / or the integrity protection process of the nodes in the first multicast group due to the lack of maintenance of the GGFN, expands the multicast application scenario, and makes the multicast transmission application scenario more extensive.

[0145] FIG. 7 is a flowchart of a sixth method for data transmission provided in the embodiments of the present application, which is performed by a G node and a T node, and can also be performed by a device in a node, and the embodiments of the present application do not limit the same, as shown in FIG. 7, the method is compared with the method shown in FIG. 6, S406 replaces S404, that is, the method comprises S401-S403, S406 and S405.

[0146] S401. The T node sends an association request message to the G node.

[0147] S402. The G node sends a security context request message to the T node.

[0148] S403. The T node sends a security context response message to the G node.

[0149] S401-S403 refer to the description in the example in FIG. 6, and will not be expanded here.

[0150] S406. The G node sends an association setup message to the T node, and the association setup message comprises at least one of HFN or HSFN.

[0151] Referring to the example in S404, after the G node determines to send the first group of multicast security parameters comprising the high frame number of GGFN to the T node, the G node can first determine whether the first multicast group has a group key (GK) and a group algorithm (galgorithm), the method for determining can refer to the example in S404, and the method for obtaining the group key (GK) and the group algorithm (galgorithm) can also refer to the example in S404, which will not be expanded here.

[0152] Different from S404, if it is determined that the first multicast group has a group key (GK), the G node obtains at least one of HFN or HSFN of different logical channels of the current multicast. That is, the G node can obtain the high frame number of GGFN to obtain the first bit sequence.

[0153] Table 2 is an example of HFN and HSFN corresponding to a logical channel of a first multicast group provided in the embodiments of the present application. As shown in the example of Table 2, each logical channel of the first multicast group corresponds to an HFN or an HSFN. For example, the M logical channels of the first multicast group obtained by the G node can all correspond to HFN, or the M logical channels of the first multicast group obtained by the G node can all correspond to HSFN, or of the M logical channels of the first multicast group obtained by the G node, Q correspond to HFN, and M-Q correspond to HSFN, wherein Q is a positive integer less than or equal to M. Table 2 of the embodiments of the present application is exemplarily illustrated by taking some logical channels of the first multicast group corresponding to HFN and some logical channels corresponding to HSFN, but the embodiments of the present application are not limited thereto.

[0154] Table 2

[0155] Referring to the example of Table 2, the first multicast group includes two logical channels, respectively identified as LCID 1 and LCID 2, the first channel corresponds to an HFN, and the second channel corresponds to an HSFN, for example, LCID 1 corresponds to an HFN of HFN1, and LCID 2 corresponds to an HSFN of HSFN1. It should be understood that the number of bytes and the bit positions of each LCID, HFN and HSFN in Table 2 are examples and are not limited, and the frame numbers of HFN1 and HSFN1 can also be determined in actual use scenarios. Table 2 is only an example and is not limited.

[0156] For example, in the association establishment message, in addition to at least one of the HFN or HSFN corresponding to each logical channel obtained by the G node through the above method, the association establishment message can also include at least one of the temporary ID, the encryption context expiration time (Kgt expiration), the GK / GKc, the GK ID, the group algorithm (galgorithm), the validity period of the group key or the group key expiration time (GK expiration), wherein the GKc / GK represents the GKc carried when the encryption protection of the unicast signaling plane is not started, and the GK carried when the encryption protection of the unicast signaling plane is started.

[0157] S405, the T node sends an association completion message to the G node.

[0158] S405 refers to the description in the example of FIG. 6, which will not be expanded.

[0159] The method provided by the embodiment of the application indicates the first bit sequence of the GGFN, i.e., at least one of the HFN or HSFN, to the T node through the association establishment message sent to the T node, compared with the method provided in FIG. 6, the association establishment message only includes the first bit sequence, which can reduce the transmission overhead.

[0160] FIG. 8 is a flowchart of a data transmission method provided by an embodiment of the application, which is executed by a G node and a T node, and can also be executed by a device in the node, and the embodiment of the application is not limited, and FIG. 8 takes the method executed by the G node and the T node as an example for description, as shown in FIG. 8, the method includes S501 to S502.

[0161] The T node and the G node that have established a connection will exchange various control messages, such as public control messages and dedicated control messages. The embodiment of the application takes the transmission of the first multicast security parameter through the dedicated control message as an example for description, but is not limited.

[0162] S501, the T node sends a dedicated control message to the G node, and the dedicated control message includes the GGFN.

[0163] When the T-node is in the connected state, the G-node can configure the T-node through a dedicated control message, such as an XRC reconfiguration (xrcReconfiguration) message, for example, to establish more logical channels for the T-node, to perform security-related configuration for the T-node, to perform measurement-related configuration for the T-node, to perform scheduling resource configuration for the T-node, to configure more data transmission carriers for the T-node, and the like. Among them, the XRC reconfiguration (xrcReconfiguration) can realize reconfiguration without interrupting network connection, can minimize the impact on network performance and availability, and can be suitable for configuration when the T-node is in the connected state.

[0164] For example, the G-node configures the T-node with different logical channel corresponding GGFN of groupcast through the groupcast configuration (groupcastConfig) carried in the XRC reconfiguration (xrcReconfiguration) message. The G-node can refer to the example of S404 to obtain the GGFN of the logical channel of the first groupcast group. Table 3 is an example of the GGFN corresponding to the logical channel of the first groupcast group provided by an embodiment of the present application. As shown in the example of Table 3, each logical channel of the first groupcast group corresponds to a GGFN. The groupcast configuration (groupcastConfig) can carry the GGFN corresponding to different logical channels by referring to Table 3.

[0165] Table 3

[0166] Referring to the example of Table 3, the first groupcast group includes two logical channels, which are identified as LCID 1 and LCID 2, respectively. Each channel corresponds to a GGFN, such as LCID 1 corresponding to GGFN 1, GGFN 1 occupying bytes 2 to 5, LCID 2 corresponding to GGFN 2, and GGFN 2 occupying bytes 7 to 10. It should be understood that the bytes occupied by each LCID and GGFN in Table 3 and the bit positions thereof are examples and are not limited. The frame numbers of GGFN 1 and GGFN 2 can also be determined in actual use scenarios. Here, they are only distinguished by GGFN 1 and GGFN 2, but are not limited.

[0167] Optionally, the groupcast configuration (groupcastConfig) can further include at least one of the following: a physical layer identifier of the groupcast group, such as the first groupcast group, a groupcast type, and control information resources, and an acknowledge character (ACK) or negative acknowledge (NACK) feedback resource.

[0168] S502, the T-node receives the dedicated control message and acquires the GGFN for groupcast transmission.

[0169] For example, if the T-node receives an XRC reconfiguration (xrcReconfiguration) message, the T-node can perform encryption transmission and / or integrity protection in subsequent groupcast transmission according to the GGFN carried in the groupcast configuration (groupcastConfig) in the XRC reconfiguration (xrcReconfiguration) message.

[0170] The method provided by the embodiments of the present application can indicate the GGFN to the T-node through the dedicated control message such as the XRC reconfiguration (xrcReconfiguration) sent to the T-node, so that the nodes in the first groupcast group without locally maintaining the GGFN can acquire the GGFN and perform at least one of the encryption transmission and the integrity protection of the groupcast, effectively avoiding the nodes in the first groupcast group from causing errors in the encryption transmission and / or the integrity protection process due to the lack of maintenance of the GGFN. The data transmission method provided by the embodiments of the present application expands the groupcast application scenario, making the groupcast transmission application scenario more extensive.

[0171] FIG. 9 is a flowchart of a data transmission method provided by an embodiment of the present application, which is executed by a G-node and a T-node, and can also be executed by a device in a node, and the embodiments of the present application are not limited thereto, and FIG. 9 takes the method executed by the G-node and the T-node as an example for description, as shown in FIG. 9, the method includes S601 to S602.

[0172] For example, the T-node and the G-node can exchange a plurality of control messages.

[0173] S601, the T-node sends a dedicated control message to the G-node, and the dedicated control message includes a high frame number of the GGFN.

[0174] For example, the dedicated control message includes the high frame number of the GGFN, and the high frame number can include at least one of the HFN or the HSFN, and the high bit can also include other frame numbers, which are not limited to the HFN or the HSFN.

[0175] When the T-node is in the connected state, the G-node can configure the T-node through a dedicated control message, such as an XRC reconfiguration (xrcReconfiguration) message. For example, the G-node configures the T-node with at least one of the HFN or the HSFN corresponding to different logical channels of the groupcast through the groupcast configuration (groupcastConfig) carried in the XRC reconfiguration (xrcReconfiguration) message. The G-node can refer to the example of S406 to obtain the high frame number corresponding to the logical channel of the first groupcast group.

[0176] Table 4 is an example of the HFN and the HSFN corresponding to the logical channel of a first groupcast group provided by an embodiment of the present application. The groupcast configuration (groupcastConfig) can refer to Table 4 to carry at least one of the HFN or the HSFN corresponding to different logical channels.

[0177] Table 4

[0178] Referring to Table 4, the first groupcast group includes two logical channels, which are identified as LCID 1 and LCID 2, respectively. The first channel corresponds to an HFN, and the second channel corresponds to an HSFN. For example, the HFN corresponding to LCID 1 is HFN1, and the HSFN corresponding to LCID 2 is HSFN1. It should be understood that the number of bytes and the bit positions of each LCID, HFN, and HSFN in Table 4 are examples and are not limited. The frame numbers of HFN1 and HSFN1 can also be determined in actual use scenarios. Table 4 is only an example and is not limited.

[0179] S602, the T-node receives a dedicated control message and obtains the high frame number of the GGFN for groupcast transmission.

[0180] The method provided by the embodiment of the present application can indicate the high frame number of the GGFN to the T-node through a dedicated control message, such as an XRC reconfiguration (xrcReconfiguration), compared with the method provided by Figure 8. The dedicated control message carries the high frame number of the GGFN, which can reduce the transmission overhead.

[0181] The data transmission method in any of the examples of Figures 3 to 9 can be applied in different groupcast transmission processes. The following examples are described.

[0182] Referring to FIG. 10, in the confidentiality protection process, plaintext can be converted into ciphertext by a key stream obtained by an encryption algorithm. The encryption algorithm can be used by a sending device, such as a G node, to generate a key stream based on an encryption key (kenc), a freshness parameter, and a length (length), and to perform an exclusive OR operation on the plaintext and the key stream to obtain the ciphertext. The freshness parameter can include a GGFN, a logical channel identifier, and a reserved field, and the length (length) is the length of the plaintext to be encrypted and can be used to control the length of the key stream. After the G node encrypts the plaintext into the ciphertext based on the freshness parameter and the length (length), the G node sends the ciphertext to a receiving device, such as a T node. The T node can refer to the methods described above with reference to FIGS. 3-9 to obtain a bit sequence corresponding to the high bits of the GGFN, i.e., a first bit sequence, and then obtain the GGFN based on the first bit sequence and generate the same key stream using the same input parameters (such as the encryption key (kenc), the freshness parameter, and the length (length)) as the G node. The T node performs an exclusive OR operation on the key stream and the ciphertext to recover the plaintext. The method of obtaining other fields (such as the logical channel identifier) in the freshness parameter and the length (length) that can be obtained can be obtained according to information carried in other messages or obtained according to configuration, and the like, which is not limited in the embodiments of the present application. The method of obtaining the GGFN in the freshness parameter includes: obtaining the GGFN (including the first bit sequence (i.e., the bit sequence corresponding to the high frame number) and the second bit sequence) carried by the first message; or obtaining the first bit sequence from the first bit sequence carried by the first message and obtaining the second bit sequence by other means (such as other messages) to obtain the GGFN, which is not limited in the embodiments of the present application.

[0183] Referring to FIG. 11, in the integrity protection procedure, the data transmitted between the G node and the T node, such as a certain message carrying data, can be verified by a message authentication code (MAC) whether it is complete and whether it is tampered. The integrity protection algorithm can be referred to as an integrity protection algorithm, which can obtain the MAC based on an integrity protection key (kint), a freshness parameter and information (message). The freshness parameter can include the fields in the example of FIG. 10, but is not limited. The information (message) is the content to be protected by integrity. The sending end device, such as the G node, calculates a message integrity code (MIC) based on the integrity protection key (kint), the freshness parameter and the information (message) using the integrity protection algorithm, and appends the MIC to the message when sending the message. The receiving end device, such as a T node in a multicast, can obtain the GGFN by referring to the methods in FIGS. 3 to 9, and then calculate an expected message integrity code (XMIC) based on the GGFN, other fields in the freshness parameter that can be obtained, and the obtained information (message). The T node can compare the XMIC and the received MIC. If the XMIC is consistent with the MIC, the integrity protection verification is passed, indicating that the received message is complete and not tampered. If it is not consistent, the integrity protection verification is not passed, indicating that the message may not be complete or may be tampered, etc. The method for obtaining the GGFN in the freshness parameter includes: obtaining the GGFN (including the first bit sequence (i.e., the bit sequence corresponding to the high frame number) and the second bit sequence) carried by the first message; or obtaining the first bit sequence by the first message carrying the first bit sequence, and obtaining the second bit sequence by other means (such as other messages) to obtain the GGFN. The embodiments of the present application are not limited.

[0184] Referring to FIG. 12, in the authentication encryption process, a sending device such as a G node can obtain ciphertext and MIC by using an authentication encryption algorithm based on an initialisation vector (IV), plaintext, additional authentication data (AAD), an authentication encryption key (k ac ), and the like. The G node can send the ciphertext, the AAD, and the MIC to a T node, where the IV includes a GGFN. The T node can obtain the GGFN by referring to the method described above with reference to FIGS. 3 to 9. The T node receives the ciphertext, the AAD, and the MIC, and can generate plaintext and XMIC based on the received ciphertext by using the same input parameters as those used by the G node to generate the data, such as the encryption key (k ac ), the IV, and the ADD, and compares the XMIC with the received MIC to determine whether the transmission of the ciphertext passes the integrity protection verification. The step of determining whether the transmission of the ciphertext passes the integrity protection verification can refer to the description of FIG. 11, which is not repeated here. The method of obtaining the GGFN in the IV includes obtaining the GGFN by the first bit sequence (i.e., the bit sequence corresponding to the high frame number) and the second bit sequence carried by the first message, or obtaining the first bit sequence by the first bit sequence carried by the first message, and obtaining the second bit sequence by other means (such as other messages) to obtain the GGFN, which is not limited in the embodiments of the present application.

[0185] The data transmission method provided by the embodiments of the present application can be widely applied in different processes, and FIGS. 10 to 12 are only examples, which are not limited by the examples of FIGS. 10 to 12.

[0186] FIG. 13 is a schematic structural diagram of a second communication device according to an embodiment of the present application. The second communication device can refer to a second node itself (for example, a management node (which can also be referred to as a management device or a G node), a network device, and the like), a component in the second node (for example, a processor, a chip, or a chip system, and the like), or a logic module or software capable of realizing all or part of the functions of the second communication device. As shown in FIG. 13, the second communication device 30 includes a processing module 301 and a sending module 302.

[0187] The processing module 301 is configured to generate a first groupcast security parameter, where the first groupcast security parameter includes a first bit sequence of a GGFN, the first bit sequence is locally maintained by a node of a first groupcast group, and the first groupcast security parameter is used for encrypted transmission and / or integrity protection of groupcast.

[0188] The sending module 302 is configured to send the first groupcast security parameter to a first node, where the node of the first groupcast group includes the first node.

[0189] In a possible implementation, one of the first multicast security parameters corresponds to one logical channel of the first multicast group; or one of the first multicast security parameters corresponds to multiple logical channels of the first multicast group.

[0190] In a possible implementation, the first bit sequence comprises a high frame number.

[0191] In a possible implementation, the first multicast security parameters further comprise a second bit sequence of the GGFN, and the second bit sequence comprises one or more of the following: a link control layer SN; or a physical layer superframe number and a radio frame number.

[0192] In a possible implementation, the second communication apparatus shown in FIG. 14 further includes a receiving module 303 configured to receive a first message, and the first message comprises an ID of the first node.

[0193] The processing module 301 is specifically configured to generate the first multicast security parameters according to the first message.

[0194] In a possible implementation, the processing module 301 is further configured to acquire the first multicast security parameters if there is a first group key, and the first group key is a group key of the first multicast group; and set the first multicast security parameters to zero if the first group key is generated.

[0195] In a possible implementation, the sending module 302 is specifically configured to send the first multicast security parameters to the first node through an association establishment message; or send the first multicast security parameters to the first node through a configuration message.

[0196] It should be understood that the modules shown in FIG. 13 and FIG. 14 are only examples, and each module can perform its operation according to the method part of the embodiments of the present application or a variation of the operation thereof. In the examples provided by the embodiments of the present application, other operations can also be performed, and the examples of the embodiments of the present application are not limited.

[0197] FIG. 15 is a structural schematic diagram of a first communication apparatus provided by an embodiment of the present application. The first communication apparatus can refer to the first node itself (for example, a terminal node (also referred to as a T node or a terminal device), etc.), a component in the first node (for example, a processor, a chip, or a chip system, etc.), or a logic module or software capable of realizing all or part of the functions of the first communication apparatus. As shown in FIG. 15, the first communication apparatus 40 includes a receiving module 401 and a sending module 402.

[0198] The receiving module 401 is configured to receive a first groupcast security parameter, the first groupcast security parameter comprising a first bit sequence of a GGFN, the first bit sequence being locally maintained by a node of a first groupcast group, and the first groupcast security parameter being used for encrypted transmission and / or integrity protection of groupcast.

[0199] In a possible implementation, one of the first groupcast security parameters corresponds to a logical channel of the first groupcast group; or, one of the first groupcast security parameters corresponds to multiple logical channels of the first groupcast group.

[0200] In a possible implementation, the first bit sequence comprises a high frame number.

[0201] In a possible implementation, the first groupcast security parameter further comprises a second bit sequence of the GGFN, the second bit sequence comprising one or more of: a link control layer SN; or, a physical layer superframe number and a radio frame number.

[0202] In a possible implementation, the apparatus further comprises a sending module 402 configured to send a first message, the first message comprising an ID of the first node.

[0203] In a possible implementation, the receiving module 401 is specifically configured to receive the first groupcast security parameter through an association establishment message; or, receive the first groupcast security parameter through a configuration message.

[0204] It should be understood that the modules shown in FIG. 15 are merely examples, and each module can perform its operation according to the method part of the embodiments of the present application or a variation of the operation. In the examples provided by the embodiments of the present application, other operations can also be performed, and the examples of the embodiments of the present application are not limited. For example, the first communication device can further comprise a processing module configured to use the first groupcast security parameter to perform groupcast transmission. Or, configured to parse encrypted data according to the first groupcast security parameter, and the sending module and the receiving module can be one module, etc.

[0205] In addition, as shown in FIG. 16, FIG. 16 is a structural schematic diagram of the device 50 of the embodiment of the present application. The device 50 shown in FIG. 16 comprises a transceiver 501 and a processor 502. The device 50 corresponds to the second communication device, or the second node, or the G node exemplified in the method, and is used to execute the method S101 to S102 in the above embodiment, or execute S201 to S203, or execute S401 to S405, or execute S401 to S403, S406 and S405, or execute S501 to S502, or execute S601 to S602. The device 50 corresponds to the first communication device, or the first node, or the T node exemplified in the method, and is used to execute the method S301 in the above embodiment, or S301 to S302, execute S401 to S405, or execute S401 to S403, S406 and S405, or execute S501 to S502, or execute S601 to S602.

[0206] It should be noted that the division of each part in the embodiment of the present application is illustrative, and is only a logical function division. In actual implementation, another division manner can be used. Each function in the embodiment of the present application can be integrated in a processor, or the transceiver and the processor can exist separately. In addition, the device 50 can comprise a built-in memory, or can not comprise a memory, and can further comprise an external memory, and the like, and is not limited to the division exemplified in the embodiment of the present application. The integrated device can be realized in the form of hardware, for example, a chip, or in the form of a software function unit, or in the form of a combination of software and hardware.

[0207] Further, the embodiment of the present application further provides a device 60, as shown in FIG. 17, which is a structural schematic diagram of the device 60 provided by the embodiment of the present application. As shown in FIG. 17, the device 60 can include a processor 601, a memory 602 coupled with the processor 601, and a transceiver 603. The transceiver 603 can include an MR, an LR, a communication interface, an optical module, etc., and is configured to receive a packet or data information, etc. The processor 601 can include a central processing unit (CPU), a network processor (NP), or a combination of the CPU and the NP, and is configured to perform the related steps of the wake-up signal processing in the device exemplified in the above embodiment. The processor can also be an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or a combination thereof. The PLD can be a complex programmable logic device (CPLD), a feld-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof. The processor 601 can refer to one processor, or can include a plurality of processors. The memory 602 can include a volatile memory such as a random-access memory (RAM); the memory can also include a non-volatile memory such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD); and the memory 602 can further include a combination of the above-mentioned memories. The memory 602 can refer to one memory, or can include a plurality of memories, and is configured to store program instructions. In an embodiment, the memory 602 stores computer readable instructions, and the computer readable instructions include a plurality of software modules, such as a sending module, a processing module and a receiving module. The processor 601 performs the respective software modules and can perform corresponding operations according to the instructions of the respective software modules. In the embodiment, the operation performed by one software module is actually the operation performed by the processor 601 according to the instructions of the software module.Optionally, the processor 601 can also store program codes or instructions for implementing the embodiments of the present application, in which case the processor 601 does not need to read the program codes or instructions from the memory 602.

[0208] The device 60 can be configured to perform the method in the above embodiments. Specifically, the device 60 corresponds to the second communication device, or the second node, or the G node in the example of the method, and can perform the method S101-S102 in the above embodiments, or perform S201-S203, or perform S401-S405, or perform S401-S403, S406 and S405, or perform S501-S502, or perform S601-S602.

[0209] Alternatively, the device 60 corresponds to the first communication device, or the first node, or the T node in the example of the method, and is configured to perform the method S301 in the above embodiments, or S301-S302, perform S401-S405, or perform S401-S403, S406 and S405, or perform S501-S502, or perform S601-S602.

[0210] In addition, the embodiments of the present application further provide a communication device. The communication device includes a storage medium and a processor connected with the storage medium. The storage medium stores instructions, and the processor executes the instructions to implement part or all of the operations in any of the methods in any of the embodiments described above.

[0211] In addition, the embodiments of the present application further provide a communication device. The communication device includes a processor, and the processor is connected with a storage medium. The storage medium can be arranged in the communication device or arranged outside the communication device, and the storage medium stores instructions, and the processor executes the instructions to implement part or all of the operations in any of the methods in any of the embodiments described above.

[0212] The embodiments of the present application further provide a computer readable storage medium, which stores instructions, and when the instructions are executed on a processor, part or all of the operations in any of the methods in any of the embodiments described above are implemented.

[0213] The embodiments of the present application further provide a computer program product, which includes a computer program, and when the computer program is executed on a processor, part or all of the operations in any of the methods in any of the embodiments described above are implemented.

[0214] The embodiments of the present application further provide a chip, which includes an interface circuit and a processor. The interface circuit and the processor are connected, and the processor is configured to cause the chip to perform part or all of the operations in any of the methods in any of the embodiments described above.

[0215] The chip system according to the embodiments of the present application can be a system on chip (SoC), a central processing unit (CPU), a network processor (NP), a digital signal processor (DSP), a micro controller unit (MCU), a programmable logic device (PLD) or other integrated chip.

[0216] Optionally, the processor in the chip system can be one or more. The processor can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented by software, the processor can be a general-purpose processor, which is implemented by reading software code stored in the memory.

[0217] Optionally, the memory in the chip system can also be one or more. The memory can be integrated with the processor or set separately from the processor, which is not limited in the embodiments of the present application. For example, the memory can be a non-transient processor, such as a read-only memory (ROM), which can be integrated on the same chip with the processor or set on different chips respectively, and the embodiments of the present application do not make specific limitation on the type of the memory and the setting mode of the memory and the processor.

[0218] For example, the chip system can be an FPGA, an ASIC, a system on chip (SoC), a CPU, an NP, a digital signal processor (DSP), a micro controller unit (MCU), a programmable logic device (PLD) or other integrated chip.

[0219] The embodiments of the present application also provide a system including one or more of the above-mentioned device, apparatus, computer readable storage medium, computer program product, chip or chip system. It can be applied in the scenario shown in FIG. 1, but is not limited to.

[0220] In a possible implementation, the system according to the embodiments of the present application includes at least one first communication apparatus and at least one second communication apparatus.

[0221] The terms "first", "second", "third", "fourth", and the like in the description and in the claims of the present application, and above, if any, are used for distinguishing between similar objects and not necessarily for describing a particular sequential or chronological order. It is to be understood that the use of these terms herein is to be construed to cover the embodiments of the application whether or not the embodiments are described using the same term. For example, a "first" object can be construed as a desired object of the embodiments of the application whether or not the same is described using the same term. It is to be understood that the terms "comprises", "comprising", "includes", "including", "contains", "containing" and any variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, system, product, or apparatus that comprises, includes, contains or contains one or more features, steps, units, elements, components, or the like is not to be limited to those features, steps, units, elements, components or the like that are expressly listed, but can include other features, steps, units, elements, components, or the like.

[0222] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.

[0223] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, and the division of units is only a logical business division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be omitted or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0224] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e. they can be located in one place or distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.

[0225] In addition, each business unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically, or two or more units can be integrated into one unit. The above integrated unit can be realized in the form of hardware or in the form of a software business unit.

[0226] The integrated unit, if implemented in the form of a software service unit and sold or used as an independent product, can be stored in a computer-readable storage medium. Based on this understanding, all or part of the technical solutions of the present application can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods of the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a ROM, a RAM, a Random Access Memory, a magnetic disk or an optical disk, and various media that can store program codes.

[0227] Those skilled in the art should be aware that, in one or more of the above examples, the services described in the present application can be implemented in hardware, software, firmware, or any combination thereof. When implemented in software, these services can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. The computer-readable medium includes a computer storage medium and a communication medium, wherein the communication medium includes any medium that facilitates the transfer of a computer program from one place to another. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0228] The above detailed description of the specific embodiments of the present application has further explained the purposes, technical solutions, and beneficial effects of the present application. It should be understood that the above is only a specific embodiment of the present application.

[0229] The above, the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacements for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A method of data transmission, characterized by, The method comprises: generating first groupcast security parameters, the first groupcast security parameters comprising a first bit sequence of a group global frame number (GGFN), the first bit sequence being locally maintained by a node of a first groupcast group, the first groupcast security parameters being used for ciphering transmission and / or integrity protection of groupcast; sending the first groupcast security parameters to a first node, the node of the first groupcast group comprising the first node.

2. The method of claim 1, wherein one of the first groupcast security parameters corresponds to one logical channel of the first groupcast group; or one of the first groupcast security parameters corresponds to multiple logical channels of the first groupcast group.

3. The method according to claim 1 or 2, characterized in that, The first bit sequence comprises a high frame number.

4. The method according to any one of claims 1 to 3, characterized in that, The first groupcast security parameters further comprise a second bit sequence of the GGFN, the second bit sequence comprising one or more of: a link control layer sequence number (SN); or a physical layer superframe number and a radio frame number.

5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises: receiving a first message, the first message comprising an identity (ID) of the first node; The generating the first groupcast security parameters comprises: generating the first groupcast security parameters according to the first message.

6. The method of claim 2, wherein, The method further comprises: if there is a first group key, obtaining the first groupcast security parameters, the first group key being a group key of the first groupcast group; if the first group key is generated, setting the first groupcast security parameters to zero.

7. The method according to any one of claims 1 to 6, characterized in that, The sending the first groupcast security parameters to a first node comprises: sending the first groupcast security parameters to the first node through an association establishment message; or sending the first groupcast security parameters to the first node through a configuration message.

8. A method of data transmission, characterized by The method comprises: receiving first groupcast security parameters, the first groupcast security parameters comprising a first bit sequence of a group global frame number (GGFN), the first bit sequence being locally maintained by a node of a first groupcast group, the first groupcast security parameters being used for ciphering transmission and / or integrity protection of groupcast.

9. The method of claim 8, wherein one of the first groupcast security parameters corresponds to one logical channel of the first groupcast group; or one of the first groupcast security parameters corresponds to multiple logical channels of the first groupcast group.

10. The method according to claim 8 or 9, characterized in that, The first bit sequence comprises a high frame number.

11. The method according to any one of claims 8 to 10, characterized in that, The first groupcast security parameters further comprise a second bit sequence of the GGFN, the second bit sequence comprising one or more of: a link control layer sequence number (SN); or a physical layer superframe number and a radio frame number.

12. The method according to any one of claims 8 to 11, characterized in that, The method further comprises: sending a first message, the first message comprising an identity (ID) of the first node.

13. The method according to any one of claims 8 to 12, characterized in that, The receiving the first groupcast security parameters comprises: receiving the first groupcast security parameters through an association establishment message; or receiving the first groupcast security parameters through a configuration message.

14. A communications device, characterized by The communication device comprises a module for performing the method of any one of claims 1 to 7, or a module for performing the method of any one of claims 8 to 13.

15. A communications device, characterized by The communication device comprises a processor configured to perform the method of any one of claims 1 to 7, or configured to perform the method of any one of claims 8 to 13.

16. A communications device, characterized by comprising: an input-output interface for at least one of obtaining input information or outputting information; and a logic circuit for performing the method of any one of claims 1 to 7, or performing the method of any one of claims 8 to 13.

17. A computer readable storage medium characterized by: The computer-readable storage medium comprises instructions which, when executed, cause the method of any one of claims 1 to 7 to be performed, or cause the method of any one of claims 8 to 13 to be performed.

18. A computer program product, characterised in that, The computer program product comprises instructions which, when executed, cause the method of any one of claims 1 to 7 to be performed, or cause the method of any one of claims 8 to 13 to be performed.

Citation Information

Patent Citations

  • Method and device for generating group safety association

    CN102655452A

  • Agent re-encryption method used for group traffic

    CN103888249A

  • Data transmission method and device

    CN117979285A

  • Electronic device for performing integrity inspection and operating method therefor

    WO2021221329A1