Communication method and apparatus
By protecting the integrity of Layer 2 messages during communication between the base station and the terminal device, the risk of signaling being tampered with before encryption is resolved, thus improving system security.
Patent Information
- Application Number
- PCT/CN2025/101289
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-09
- Filing Date
- 2025-06-16
- Publication Date
- 2026-01-15
AI Technical Summary
The signaling exchanged between the base station and the terminal device was not encrypted and protected for integrity before the safe mode was activated, which increased the risk of user data leakage or tampering.
During communication between terminal equipment and access network equipment, integrity protection information is determined by receiving and sending Layer 2 messages, thereby protecting the integrity of at least one Layer 2 message and reducing the risk of tampering.
This improves system security, reduces the risk of Layer 2 messages being tampered with during random access, and enhances the integrity protection of communication.
Smart Images

Figure CN2025101289_15012026_PF_FP_ABST
Abstract
Description
A communication method and apparatus
[0001] Cross-references to related applications
[0002] This application claims priority to Chinese Patent Application No. 202410918475.2, filed on July 9, 2024, entitled "A Communication Method and Apparatus", the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application relates to the field of communication technology, and in particular to a communication method and apparatus. Background Technology
[0004] In wireless communication, communication security is a crucial factor, involving the protection of user data. To ensure secure communication between base stations and terminals, the base station can initiate a secure mode after the terminal device initially connects, sending parameters such as an encryption key and an integrity protection key to the terminal device. Subsequent signaling interactions between the base station and the terminal device can encrypt transmitted data based on the encryption key and provide air interface integrity protection based on the integrity protection key.
[0005] However, currently, before the base station sends encryption and integrity protection keys to the terminal device, the signaling exchanged between the base station and the terminal device is not encrypted or protected for integrity. This could lead to the leakage or tampering of user data. For example, before a secure mode is activated between the base station and the terminal device, a fake base station can receive and modify the signaling exchanged between them, such as obtaining the terminal device's identification information. Therefore, improving system security is an urgent problem to be solved. Summary of the Invention
[0006] This application provides a communication method and apparatus to improve system security.
[0007] Firstly, this application provides a communication method, wherein the execution subject of the method is a terminal device or a module or chip within the terminal device, and the method is described here using a terminal device as an example. The method includes: receiving and / or sending at least one Layer 2 message within a first interval; sending first information to an access network device; the first information is used to perform integrity protection on the at least one Layer 2 message within the first interval, and the first information is determined based on the at least one Layer 2 message.
[0008] By using the above method, first information is determined based on at least one Layer 2 message received and / or sent within the first interval, thereby protecting the integrity of at least one Layer 2 message based on the first information, thus reducing the risk of at least one Layer 2 message being tampered with and improving system security.
[0009] In one possible implementation, at least one Layer 2 message includes Layer 2 messages transmitted during random access.
[0010] Since Layer 2 messages such as MAC CE cannot be encrypted or protected for integrity during random access, there is a risk of information leakage or tampering. In this application, by protecting the integrity of Layer 2 messages transmitted during random access, the risk of tampering of Layer 2 messages transmitted during random access can be reduced, thereby improving system security.
[0011] In one possible implementation, the method further includes: receiving second information from the access network device; the second information indicates recording received and / or transmitted Layer 2 messages.
[0012] In one possible implementation, the second information also indicates the first interval.
[0013] In one possible implementation, the first interval is a time range; or, the first interval is the interval from the start of the first message to the end of the second message; or, the first interval is the interval of N layer 2 message transmissions, where N is an integer greater than 0.
[0014] In one possible implementation, the first information is determined based on the at least one Layer 2 message, including:
[0015] The first information indicates at least one of the following: at least one logical channel identifier (LCID), the at least one LCID being an LCID included in the at least one Layer 2 message; the at least one Layer 2 message; and a first value, the first value being determined based on the at least one LCID and / or the at least one Layer 2 message.
[0016] In one possible implementation, the first value is a hash value determined based on the at least one LCID; or, the first value is the sum of the at least one LCID; or, the first value is a hash value determined based on the at least one Layer 2 message; or, the first value is a hash value determined based on the at least one LCID and the at least one Layer 2 message; or, the first value is a cyclic redundancy check value determined based on the at least one LCID; or, the first value is a cyclic redundancy check value determined based on the at least one Layer 2 message.
[0017] In one possible implementation, the first information is located in a third message, which is an encrypted and / or integrity-protected message.
[0018] Since the first information is located in a message that is encrypted and / or protected for integrity, the security of the first information transmission can be guaranteed, thereby improving system security.
[0019] In one possible implementation, the third message is a Radio Resource Control (RRC) resumecomplete message; or, the third message is a message sent after safe mode is started.
[0020] Since the third message is either the Radio Resource Control recovery completion (RRCresumecomplete) message or a message after the safe mode is started, it indicates that at least one Layer 2 message includes Layer 2 messages transmitted during random access, or at least one Layer 2 message is a Layer 2 message transmitted during random access. Therefore, by protecting the integrity of Layer 2 messages transmitted during random access, the risk of Layer 2 messages being tampered with during random access can be reduced, thereby improving system security.
[0021] Secondly, this application provides a communication method, wherein the execution subject of the method is an access network device or a module or chip within the access network device, and the method is described here using an access network device as an example. The method includes: receiving and / or sending at least one Layer 2 message within a first interval; receiving first information from a terminal device; the first information being used to perform integrity protection on the at least one Layer 2 message within the first interval, the first information being determined based on the at least one Layer 2 message; and performing integrity verification on the at least one Layer 2 message based on the first information.
[0022] In one possible implementation, the method further includes: sending a second message; the second message indicating the recording of received and / or sent Layer 2 messages.
[0023] In one possible implementation, the second information also indicates the first interval.
[0024] In one possible implementation, the first interval is a time range; or, the first interval is the interval from the start of the first message to the end of the second message; or, the first interval is the interval of N layer 2 message transmissions, where N is an integer greater than 0.
[0025] In one possible implementation, the first information is determined based on the at least one Layer 2 message, including:
[0026] The first information indicates at least one of the following: at least one logical channel identifier (LCID), the at least one LCID being an LCID included in the at least one Layer 2 message; the at least one Layer 2 message; and a first value, the first value being determined based on the at least one LCID and / or the at least one Layer 2 message.
[0027] In one possible implementation, the first value is a hash value determined based on the at least one LCID; or, the first value is the sum of the at least one LCID; or, the first value is a hash value determined based on the at least one Layer 2 message; or, the first value is a hash value determined based on the at least one LCID and the at least one Layer 2 message; or, the first value is a cyclic redundancy check value determined based on the at least one LCID; or, the first value is a cyclic redundancy check value determined based on the at least one Layer 2 message.
[0028] In one possible implementation, the first information is contained in a third message, which is an encrypted and / or integrity-protected message.
[0029] In one possible implementation, the third message is a Radio Resource Control (RRC) resumecomplete message; or, the third message is a message sent after safe mode is started.
[0030] In one possible implementation, if the integrity protection check of at least one Layer 2 message fails based on the first information, the method further includes: releasing the Radio Resource Control (RRC) connection with the terminal device.
[0031] Thirdly, this application provides a communication method, wherein the execution subject of the method is a terminal device or a module or chip within the terminal device, and the method is described here using a terminal device as the execution subject as an example. The method includes: receiving first information from an access network device; the first information being used to perform integrity protection on at least one Layer 2 message within a first interval, the first information being determined based on the at least one Layer 2 message; and performing integrity verification on the at least one Layer 2 message based on the first information.
[0032] By using the above method, first information is determined based on at least one Layer 2 message received and / or sent within the first interval, thereby protecting the integrity of at least one Layer 2 message based on the first information, thus reducing the risk of at least one Layer 2 message being tampered with and improving system security.
[0033] In one possible implementation, at least one Layer 2 message includes Layer 2 messages transmitted during random access.
[0034] Since Layer 2 messages such as MAC CE cannot be encrypted or protected for integrity during random access, there is a risk of information leakage or tampering. In this application, by protecting the integrity of Layer 2 messages transmitted during random access, the risk of tampering of Layer 2 messages transmitted during random access can be reduced, thereby improving system security.
[0035] In one possible implementation, the method further includes: receiving second information from an access network device; the second information indicating the recording of received and / or transmitted Layer 2 messages.
[0036] In one possible implementation, the second information also indicates the first interval.
[0037] In one possible implementation, the first interval is a time range; or, the first interval is the interval from the start of the first message to the end of the second message; or, the first interval is the interval of N layer 2 message transmissions, where N is an integer greater than 0.
[0038] In one possible implementation, the first information is determined based on the at least one Layer 2 message, including: the first information indicating at least one of the following: at least one logical channel identifier (LCID), the at least one LCID being an LCID included in the at least one Layer 2 message; the at least one Layer 2 message; and a first value, the first value being determined based on the at least one LCID and / or the at least one Layer 2 message.
[0039] In one possible implementation, the first value is a hash value determined based on the at least one LCID; or, the first value is the sum of the at least one LCID; or, the first value is a hash value determined based on the at least one Layer 2 message; or, the first value is a hash value determined based on the at least one LCID and the at least one SDU; or, the first value is a cyclic redundancy check value determined based on the at least one LCID; or, the first value is a cyclic redundancy check value determined based on the at least one Layer 2 message.
[0040] In one possible implementation, the first information is located in a third message, which is an encrypted and / or integrity-protected message.
[0041] In one possible implementation, the third message is a Radio Resource Control (RRC) setup message; or, the third message is a message sent after safe mode is started.
[0042] In one possible implementation, if the integrity protection verification of at least one Layer 2 message fails based on the first information, the method further includes: triggering Radio Resource Control (RRC) connection re-establishment.
[0043] Fourthly, this application provides a communication method, wherein the execution subject of the method is an access network device or a module or chip within the access network device, and the method is described here using an access network device as an example. The method includes: receiving and / or sending at least one Layer 2 message within a first interval; sending first information to a terminal device, wherein the first information is used to perform integrity protection on at least one Layer 2 message within the first interval, and the first information is determined based on the at least one Layer 2 message.
[0044] In one possible implementation, the method further includes: sending a second message; the second message indicates the recording of received and / or sent Layer 2 messages.
[0045] In one possible implementation, the second information also indicates the first interval.
[0046] In one possible implementation, the first interval is a time range; or, the first interval is the interval from the start of the first message to the end of the second message; or, the first interval is the interval of N layer 2 message transmissions, where N is an integer greater than 0.
[0047] In one possible implementation, the first information is determined based on the at least one Layer 2 message, including: the first information indicating at least one of the following: at least one logical channel identifier (LCID), the at least one LCID being an LCID included in the at least one Layer 2 message; the at least one Layer 2 message; and a first value, the first value being determined based on the at least one LCID and / or the at least one Layer 2 message.
[0048] In one possible implementation, the first value is a hash value determined based on the at least one LCID; or, the first value is the sum of the at least one LCID; or, the first value is a hash value determined based on the at least one Layer 2 message; or, the first value is a hash value determined based on the at least one LCID and the at least one SDU; or, the first value is a cyclic redundancy check value determined based on the at least one LCID; or, the first value is a cyclic redundancy check value determined based on the at least one Layer 2 message.
[0049] In one possible implementation, the first information is contained in a third message, which is an encrypted and / or integrity-protected message.
[0050] In one possible implementation, the third message is a Radio Resource Control (RRC) setup message; or, the third message is a message sent after safe mode is started.
[0051] Fifthly, this application also provides a communication device capable of implementing any of the methods provided in any of the first to fourth aspects. This communication device can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more units or modules corresponding to the aforementioned functions.
[0052] In one possible implementation, the communication device includes a processor configured to support the communication device in performing corresponding functions of the access network device or terminal device described above. The communication device may also include a memory coupled to the processor, which stores necessary program instructions and data for the communication device. Optionally, the communication device further includes an interface circuit for supporting communication between the communication device and devices such as terminal devices.
[0053] In one possible implementation, the communication device includes corresponding functional modules, each used to implement the steps in the above method. The functions can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the functions described above.
[0054] In one possible implementation, the communication device includes a processing unit and a communication unit, which can perform the corresponding functions in the above method examples, as described in the methods provided in any of the first to fourth aspects, and will not be repeated here.
[0055] A sixth aspect provides a communication device, including a processor and an interface circuit. The interface circuit is used to receive signals from other communication devices outside the communication device and transmit them to the processor, or to send signals from the processor to other communication devices outside the communication device. The processor implements the functional modules of the methods in any possible implementation of any of the first to fourth aspects through logic circuits or by executing computer programs or instructions. Optionally, the communication device further includes a memory for storing computer programs or instructions.
[0056] In a seventh aspect, a computer-readable storage medium is provided, which stores a computer program or instructions that, when executed by a processor, implement the method in any possible implementation of any of the first to fourth aspects.
[0057] Eighthly, a computer program product storing instructions is provided, which, when read and executed by a computer, implements the method in any possible implementation of any of the first to fourth aspects.
[0058] A ninth aspect provides a circuit for performing the methods in any possible implementation of any of the first to fourth aspects described above, the circuit including chip circuitry. Optionally, the circuit may also be coupled to a memory.
[0059] In a tenth aspect, a chip is provided, the chip including a processor, which, when executing a computer program or instructions, implements the methods in any possible implementation of any of the first to fourth aspects. Optionally, the chip may further include a memory, and the chip may be composed of chips or may include chips and other discrete devices.
[0060] Eleventhly, a communication device is provided, including a processor that implements the methods in any possible implementation of any of the first to fourth aspects by means of logic circuits or by executing computer programs or instructions. Optionally, the communication device may further include a memory, which may be a computer program or instructions.
[0061] In a twelfth aspect, a communication apparatus is provided, comprising a unit or module for performing a method in any possible implementation of any of the first to fourth aspects described above.
[0062] In a thirteenth aspect, embodiments of this application also provide a communication system. The communication system includes: a terminal device for implementing the methods of the first aspect and any possible implementations thereof; and an access network device for implementing the methods of the second aspect and any possible implementations thereof. Alternatively, the communication system includes: a terminal device for implementing the methods of the third aspect and any possible implementations thereof; and an access network device for implementing the methods of the fourth aspect and any possible implementations thereof. Attached Figure Description
[0063] Figure 1 is a schematic diagram of a base station architecture provided in an embodiment of this application;
[0064] Figure 2 is a schematic diagram of a network architecture applicable to an embodiment of this application;
[0065] Figure 3 is a schematic diagram of a fake base station provided in an embodiment of this application;
[0066] Figure 4 is a schematic diagram of a man-in-the-middle attack provided in an embodiment of this application;
[0067] Figure 5 is a schematic diagram of a network architecture applicable to an embodiment of this application;
[0068] Figure 6 is a schematic flowchart of a communication method provided in an embodiment of this application;
[0069] Figure 7 is a schematic flowchart of a communication method provided in an embodiment of this application;
[0070] Figure 8 is a schematic flowchart of a communication method provided in an embodiment of this application;
[0071] Figure 9 is a schematic diagram of a communication device structure provided in an embodiment of this application;
[0072] Figure 10 is a schematic diagram of a communication device structure provided in an embodiment of this application;
[0073] Figure 11 is a schematic diagram of a communication device structure provided in an embodiment of this application. Detailed Implementation
[0074] The technical solutions of the embodiments of this application will be described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. The terms "first," "second," and corresponding terminology in this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. The methods and apparatus provided in the embodiments of this application are based on the same or similar technical concepts. Since the principles by which the methods and apparatus solve problems are similar, the implementation of the apparatus and methods can refer to each other, and repeated details will not be repeated.
[0075] The technical solutions provided in the embodiments of this application can be applied to communication systems related to the 3rd Generation Partnership Project (3GPP), such as Long Term Evolution (LTE) communication systems, 5th Generation (5G) mobile communication systems, or to future communication systems or other similar communication systems. Furthermore, the technical solutions provided in the embodiments of this application can be applied to cellular links, public land mobile networks (PLMNs), machine-to-machine (M2M) networks, Internet of Things (IoT) networks, or other networks. They can also be applied to device-to-device links, such as device-to-device (D2D) links or sidelinks.
[0076] The following section will first explain some of the terms used in the embodiments of this application so that those skilled in the art can understand them.
[0077] In this embodiment, the access network device can be a device in a wireless network, or it can be called a network device or a wireless access network device. For example, the access network device can be a radio access network (RAN) node that connects terminal devices to the wireless network, and it can also be called an access network device. The access network device includes, but is not limited to: base station, evolved NodeB (eNodeB), transmission reception point (TRP), next-generation NodeB (gNB) in 5th generation (5G) mobile communication systems, access network devices in open radio access networks (O-RAN), base stations in future mobile communication systems, or access nodes in wireless fidelity (WiFi) systems; or it can be a module or unit that performs some functions of a base station, such as a central unit (CU), a distributed unit (DU), a central unit control plane (CU-CP) module, or a central unit user plane (CU-UP) module. Access network equipment can be macro base stations, micro base stations, indoor stations, relay nodes, or donor nodes, etc. This application does not limit the specific technologies or equipment forms used in the access network equipment.
[0078] In some implementations, access network equipment can include centralized units (CUs) and distributed units (DUs). This includes RAN equipment at CU and DU nodes that separate the protocol layers of the gNB in the NR system. Some protocol layer functions are centrally controlled by the CU, while the remaining partial or complete protocol layer functions are distributed across the DUs, which are then centrally controlled by the CU. Furthermore, the CU can be divided into a control plane (CU-CP) and a user plane (CU-UP). The CU-CP handles control plane functions, primarily including radio resource control (RRC) and the corresponding packet data convergence protocol (PDCP) (PDCP-C). PDCP-C is mainly responsible for control plane data encryption / decryption, integrity protection, and data transmission. The CU-UP handles user plane functions, primarily including the service data adaptation protocol (SDAP) and the corresponding PDCP (PDCP-U). SDAP is mainly responsible for processing core network data and mapping flows to bearers. PDCP-U is primarily responsible for data plane encryption / decryption, integrity protection, header compression, sequence number maintenance, and data transmission. CU-CP and CU-UP are connected via the E1 interface. CU-CP represents the gNB connected to the core network via the NG interface and to the DU via the F1 interface control plane (F1-C). CU-UP is connected to the DU via the F1 interface user plane (F1-U). Alternatively, PDCP-C may also be located within CU-UP.
[0079] It is understood that CU (including CU-CP or CU-UP) or DU may have different names in different systems, but those skilled in the art will understand their meaning. For example, in an open radio access network (O-RAN) system, CU can also be called O-CU (open CU), DU can also be called O-DU, CU-CP can also be called O-CU-CP, and CU-UP can also be called O-CU-UP. For ease of description, this application uses CU, CU-CP, CU-UP, and DU as examples. The access network equipment may also include an active antenna unit (AAU). CU implements some of the functions of gNB, and DU implements some of the functions of gNB. For example, CU is responsible for handling non-real-time protocols and services, implementing the functions of the RRC layer. DU is responsible for handling physical layer protocols and real-time services, implementing the functions of the radio link control (RLC) layer, media access control (MAC) layer, and physical (PHY) layer. In some deployments, the CU can also be divided into a centralized unit control plane (CU-CP) node and a centralized unit user plane (CU-UP) node. The CU-CP is responsible for control plane functions, while the CU-UP is responsible for user plane functions.
[0080] For example, taking the access network device as a base station as an example, see Figure 1, which is a schematic diagram of two typical protocol stacks of the base station provided in the embodiments of this application. In the base station (1), the base station is divided into CU and DU. The CU is configured to implement the functions of the PDCP layer and above protocol layers (such as the RRC layer and / or SDAP layer, etc.); the DU is configured to implement the functions of the protocol layers below the PDCP layer (such as the RLC layer, MAC layer, and / or PHY layer, etc.). The CU and DU communicate with each other based on the F1 interface. In the base station (2), the base station is divided into CU and DU. The CU includes CU-CP and CU-UP. CU-CP is used to implement the control plane function of the CU, and CU-UP is used to implement the user plane function of the CU. CU-CP and CU-UP can communicate based on the E1 interface. CU-CP and DU communicate based on the F1 interface (also called F1-C) that supports the control plane. CU-UP and DU communicate based on the F1 interface (also called F1-U) that supports the user plane. CU-CP is configured to implement the control plane and RRC layer functions of the PDCP layer, and CU-UP is configured to implement the user plane and SDAP layer functions of the PDCP layer. DU is configured to implement the functions of protocol layers below the PDCP layer (such as RLC, MAC, and / or PHY layers).
[0081] The above division of CU and DU processing functions according to the protocol layer is merely an example; other division methods are also possible, and this application does not impose any restrictions.
[0082] The terminal device involved in the embodiments of this application can be a wireless terminal device capable of receiving scheduling and instruction information from network devices (e.g., access network devices). The terminal device can be referred to as a terminal device, or it can also be called user equipment (UE), terminal, mobile station (MS), mobile terminal (MT), etc. The terminal device can be a device that includes wireless communication functions (providing voice / data connectivity to the user). For example, a handheld device with wireless connectivity, or an in-vehicle device, in-vehicle module, etc. Currently, examples of terminal devices include: mobile phones, tablets, laptops, PDAs, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in vehicle-to-everything (V2X) communication, wireless terminals in vehicle-to-everything (V2X) communication, intelligent vehicles, in-vehicle infotainment systems (or onboard transmitters) (T-boxes), machine-to-machine / machine-type communications (M2M / MTC) terminal devices, and the Internet of Things (IoT). Wireless terminals in industrial control systems can include devices such as IoT (Internet of Things) terminals. For example, terminal devices can be in-vehicle equipment, vehicle-mounted modules, vehicles, on-board units (OBUs), roadside units (RSUs), T-boxes, chips, or systems-on-chips (SoCs), which can be installed in vehicles, OBUs, RSUs, or T-boxes. Wireless terminals in industrial control systems can be cameras, robots, etc. Wireless terminals in smart homes can be televisions, air conditioners, robot vacuums, speakers, set-top boxes, etc.Furthermore, in this embodiment, the terminal device can also be a terminal device in an IoT system. IoT is an important component of the future development of information technology. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network of human-machine interconnection and object-to-object interconnection.
[0083] This application also applies to O-RAN architecture. As shown in Figure 2, an O-RAN system may include access network equipment, terminal equipment, and core network equipment. An O-RAN system may include other components besides those shown in the figure. As shown in Figure 2, the access network equipment (e.g., an eNB, gNB, or next-generation access network equipment) communicates with the core network (CN) equipment via a backhaul link and with the user equipment (UE) via an air interface.
[0084] For example, the baseband unit (BBU) in the access network equipment can communicate with the core network via a backhaul link, while the radio unit (RU) in the access network equipment can communicate with at least one UE via an air interface. The BBU communicates with at least one RU via a fronthaul link. The BBU and RU may or may not be co-located.
[0085] A BBU includes at least one of a Control Unit (CU) and at least one Distributed Unit (DU), which can communicate via at least one midhaul link. In the ORAN system, the CU can also be called an open CU (O-CU), and the DU can also be called an open DU (O-DU).
[0086] In this application embodiment, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or multiple items; for example, at least one of a, b, or c can represent: a, b, c, a and b, a and c, b and c, or a, b, and c.
[0087] Fake base station attack: refers to network attackers placing illegal base stations within the coverage area of the target base station. Fake base stations can force nearby target terminals to perform cell reselection, location updates, and cell handover, thereby deceiving the terminal or providing the terminal with incorrect information to achieve purposes such as spreading viruses or network fraud.
[0088] For example, as shown in Figure 3, a fake base station can consist of an engineering terminal (e.g., a computer / mobile phone), cables, and a wireless transceiver. By impersonating a mobile communication operator's base station, it deceives terminals and launches attacks. Fake base station attacks can forge system messages, which overwrite genuine system messages in the network, causing the target terminal to reject the target base station's services. Additionally, fake base stations can trick terminals into initiating network registration or location update requests, attracting the target terminal to reside on the fake base station and extracting its information. At this point, the terminal is disconnected from the normal network and unable to obtain network services. Fake base stations can also transmit information with terminals, such as sending fraudulent text messages, malicious network links, or harassing text messages.
[0089] Fake base stations can also intercept communication data between the target base station and the terminal, thereby monitoring users' private data. While launching deceptive attacks on terminals, fake base stations also interfere with normal communication between the network and the terminal, impacting network performance.
[0090] Man-in-the-middle attack: refers to a fake base station combined with a fake terminal relaying encrypted data between the terminal and the network, and tampering with the data to carry out the attack when there is no integrity protection.
[0091] For example, as shown in Figure 4, in the uplink where the target terminal transmits data to the target base station, the fake base station receives the communication data from the target terminal and transmits it to the target base station via the fake terminal. Correspondingly, in the downlink where the target base station transmits data to the target terminal, the fake terminal receives the communication data from the legitimate base station, modifies the received data via the fake base station, and then transmits it to the target terminal.
[0092] During this process, it is difficult for the target terminal and the target base station to detect the existence of fake base stations and fake terminals. If there is no integrity protection for communication data between the target terminal and the target base station, attacks such as data tampering or packet loss may occur.
[0093] Figure 5 illustrates a network architecture diagram provided in an embodiment of this application. This network architecture may include: access network equipment and at least one terminal device, such as UE1 and UE2. The above network architecture can be an architecture in an LTE system, an architecture in an NR system, a hybrid LTE and NR architecture, or an architecture in a new communication system that will emerge in future communication developments; this application is not limited to any of these.
[0094] To prevent attacks from fake base stations and man-in-the-middle attacks, data between access network devices and terminal devices can be encrypted or protected for integrity using keys. During network access, before activating secure mode, information obtained during the random access process is not encrypted or protected for integrity, posing a risk of information leakage or tampering, thus threatening the security of the terminal device. Therefore, this application provides a method to improve the security of communication between the terminal device and the base station before activating secure mode.
[0095] The method will be described below from the perspective of the interaction between the terminal device and the access network device. The steps executed by the terminal device can also be implemented by components within the terminal device (such as a baseband chip, or other processing units or processor modules). Similarly, the steps executed by the access network device can also be implemented by components within the access network device (such as a baseband chip, or other processing units or processor modules).
[0096] It is understood that this application does not specifically limit the structure of the execution subject of the method provided in the embodiments of this application. It can be applied to modules in terminal devices or access network devices, as long as they can communicate according to the method provided in the embodiments of this application by running a program that records the code of the method provided in the embodiments of this application. The following description takes the interaction between terminal devices and access network devices as an example.
[0097] Figure 6 shows a flowchart of a communication method provided in an embodiment of this application. The method includes:
[0098] Step 601: The terminal device receives and / or sends at least one layer 2 (L2) message within the first interval.
[0099] Correspondingly, the access network device can also receive and / or send at least one Layer 2 message within the first interval. The at least one Layer 2 message is a message transmitted between the terminal device and the access network device.
[0100] The terminal device may be in an RRC inactive state, an RRC idle state, or an RRC connected state. At least one Layer 2 message may include messages received and / or sent by the terminal device during the random access process; for example, the first Layer 2 message in at least one Layer 2 message may be a message received and / or sent by the terminal device during the random access process.
[0101] At least one Layer 2 message can be entirely uplink messages, i.e., messages sent by the terminal device; or, at least one Layer 2 message can be entirely downlink messages, i.e., messages received by the terminal device and messages sent by the access network device; or, at least one Layer 2 message can include both uplink and downlink messages. It can be preset or agreed upon by protocol that at least one Layer 2 message is entirely uplink, entirely downlink, or includes both uplink and downlink messages. Alternatively, the access network device can indicate that at least one Layer 2 message is entirely uplink, entirely downlink, or includes both uplink and downlink messages.
[0102] A Layer 2 message can be a MAC sub-protocol data unit (PDU); or a Layer 2 message can be a MAC service data unit (SDU) or a MAC control element (CE) within a MAC subPDU. A MAC subPDU can reside within a MAC PDU. A MAC subPDU includes a MAC SDU or a MAC CE. A MAC subPDU may also include other information. For example, the header of a MAC subPDU may include a Reversed (R) field, a Formulation (F) field, a Logical Channel Identifier (LCID) field, and a Length subheader (L subheader) field.
[0103] In this application, the first interval can be preset, agreed upon by protocol, or configured by the access network device; this application does not limit this. The first interval can be implemented in various ways; several examples are given below.
[0104] In the first implementation method, the first interval is a time range, such as between time T1 and time T2. Time T1 and time T2 can be preset, agreed upon by the protocol, or configured by the access network device. Time T1 and time T2 can be an absolute time or a relative time. For example, time T1 and time T2 can be represented by frames and subframes.
[0105] In the second implementation method, the first interval is the interval between two messages, for example, the first interval is from the start of the first message to the end of the second message. The first and second messages can be preset, protocol-defined, or configured by the access network device. For example, the first message is message A or message 3 in the random access process, and the second message is an RRC recovery complete message; another example is that the first message is message A or message 3 in the random access process, and the second message is a message after the safe mode is started, such as an RRC reconfiguration complete message. Message 3 is the third message in the four-step random access process, for example, when the terminal device is in an RRC inactive state. Message 3 can be an RRC recovery request message, used to request the restoration of the RRC connection. Message A is the first message in the two-step random access process.
[0106] In the third implementation method, the first interval is the interval for transmitting N Layer 2 messages, where N is an integer greater than 0. N can be preset, agreed upon by the protocol, or configured by the access network device. For example, the first Layer 2 message among the N Layer 2 messages can be message A or message 3 in the random access process.
[0107] The above are just examples. There may be other implementations for the first interval, which will not be elaborated here.
[0108] In one implementation, the access network device may further send second information. Correspondingly, the terminal device receives the second information from the access network device; the second information indicates recording the received and / or sent Layer 2 messages, or the second information indicates determining the log records of the received and / or sent Layer 2 messages. Upon receiving the second information, the terminal device can record the LCID in the received and / or sent Layer 2 messages according to the second information, and / or record the received and / or sent Layer 2 messages, wherein "record" can also be replaced by descriptions such as "save". Alternatively, the terminal device can determine the log records according to the second information, and the log records may include the LCID in the received and / or sent Layer 2 messages, and / or the received and / or sent Layer 2 messages.
[0109] In one implementation, the second information may indicate the log recording of Layer 2 messages received and / or sent during the RRC inactive state or RRC idle state. Accordingly, the terminal device records the LCID of the Layer 2 messages received and / or sent during the RRC inactive state or RRC idle state, and / or records the Layer 2 messages received and / or sent during the RRC inactive state or RRC idle state. In this implementation, at least one Layer 2 message is a message received and / or sent by the terminal device during random access, or a message received and / or sent by the access network device during random access.
[0110] The second information can be carried through system information, such as being located in the SIB. Alternatively, it can be carried through an RRC release message. When the terminal device is released to the RRC inactive or RRC idle state, the access network device sends an RRC release message including the second information.
[0111] Optionally, the second information may also indicate the first interval. For example, the second information may indicate that the start message of the first interval is message A or message 3, and the second information may indicate that the end message of the first interval is an RRC recovery completion message. The second information may also indicate that at least one Layer 2 message is an uplink message, i.e., a message sent by the terminal device. Furthermore, the second information may indicate the time range of the first interval, such as indicating at least two of the start time, duration, and end time of the first interval.
[0112] For example, the second information indicates that the starting message of the first interval is message A or message 3, and the message data is 2. The second information may also indicate that at least one Layer 2 message is a downlink message, that is, a message received by the terminal device.
[0113] In one implementation, the access network device may further send third information. Correspondingly, the terminal device receives third information from the access network device; the third information indicates a list of RAN-based notification areas (RNAs) or a list of cells, where the RNA list includes at least one RNA and the cell list includes at least one cell. The area corresponding to the RNA list or cell list is a cell that supports the verification of Layer 2 messages. Based on the third information, the terminal device can determine that a cell in the area corresponding to the RNA list or cell list supports the verification of Layer 2 messages. Once the terminal device determines that the current cell is located in the RNA list or cell list, it can proceed to step 601.
[0114] In one implementation, the access network device can also send a fourth message. Correspondingly, the terminal device receives the fourth message from the access network device; the fourth message indicates whether the first cell supports authentication of Layer 2 messages. The terminal device receives the fourth message in the first cell, and based on the fourth message, it can determine that the first cell supports authentication of Layer 2 messages, and then proceed to step 601.
[0115] Step 602: The terminal device sends the first information to the access network device.
[0116] Correspondingly, the access network device receives the first information from the terminal device.
[0117] The first information is used to protect the integrity of at least one Layer 2 message within the first interval, and the first information is determined based on at least one Layer 2 message within the first interval.
[0118] This application does not limit how the first information is determined based on at least one Layer 2 message. In one implementation, the first information indicates at least one of the following:
[0119] At least one LCID, at least one LCID is an LCID included in at least one Layer 2 message, at least one Layer 2 message corresponds one-to-one with at least one LCID, and one of the at least one Layer 2 messages includes one of the at least one LCID;
[0120] At least one or more Layer 2 messages in at least one Layer 2 message;
[0121] The first value is determined based on at least one LCID and / or at least one Layer 2 message.
[0122] For example, the first value may be a hash value determined based on at least one LCID; or, the first value may be the sum of at least one LCID corresponding to at least one Layer 2 message; or, the first value may be a hash value determined based on at least one Layer 2 message; or, the first value may be a hash value determined based on at least one LCID and at least one Layer 2 message; or, the first value may be a cyclic redundancy check (CRC) value determined based on at least one LCID; or, the first value may be a cyclic redundancy check (CRC) value determined based on at least one Layer 2 message. This application does not limit the method for determining the hash value and CRC value; the terminal device and the access network device may pre-agree on the method for determining the hash value and CRC value, and use the same method to determine the hash value and CRC value respectively. This is only an example of using hash value and CRC value; other verification methods can also be used to generate the first value, such as the first value being a message authentication code for integrity (MAC-I) determined based on at least one LCID and / or at least one Layer 2 message.
[0123] The above are just examples. There may be other ways to implement the first information, which will not be elaborated here.
[0124] In this application, the first information is located within the third message, which is an encrypted and / or integrity-protected message. For example, if the terminal device is in an RRC inactive state, the third message is an RRC resumecomplete message; the first Layer 2 message in at least one Layer 2 message can be message A or message 3. As another example, if the terminal device is in an RRC idle state, the third message is a message following the activation of secure mode, such as an RRC reconfiguration complete message; the first Layer 2 message in at least one Layer 2 message can be message A or message 3.
[0125] Step 603: The access network device performs integrity verification on at least one Layer 2 message based on the first information.
[0126] This application does not limit how the access network device performs integrity verification on at least one Layer 2 message. In one possible implementation, the access network device receives and / or sends at least one Layer 2 message in a first interval and determines verification information based on the at least one Layer 2 message. The method by which the access network device determines the verification information is the same as the method by which the terminal device determines the first information. If the verification information and the first information are the same, the integrity verification of at least one Layer 2 message passes, indicating that the at least one Layer 2 message received and / or sent by the terminal device in the first interval is the same as the at least one Layer 2 message received and / or sent by the access network device in the first interval, and the at least one Layer 2 message transmitted in the first interval has not been tampered with. If the verification information and the first information are different, the integrity verification of at least one Layer 2 message fails, indicating that the at least one Layer 2 message received and / or sent by the terminal device in the first interval is different from the at least one Layer 2 message received and / or sent by the access network device in the first interval, and the at least one Layer 2 message transmitted in the first interval may have been tampered with; in this case, the at least one Layer 2 message may be an invalid message.
[0127] For example, the first information indicates a first value. For instance, the first value is a hash value determined based on at least one LCID corresponding to at least one Layer 2 message. The access network device receives and / or sends at least one Layer 2 message in the first interval. The access network device determines the verification information as a hash value based on at least one LCID corresponding to the at least one Layer 2 message. If the hash value is the same as the first value, the integrity verification of the at least one Layer 2 message passes; if the hash value is different from the first value, the integrity verification of the at least one Layer 2 message fails.
[0128] For example, the first value is the sum of at least one LCID corresponding to at least one Layer 2 message. The verification information determined by the access network device is the sum of at least one LCID corresponding to at least one Layer 2 message. If the sum of at least one LCID determined by the access network device is the same as the first value, the integrity verification of at least one Layer 2 message passes; if the sum of at least one LCID determined by the access network device is different from the first value, the integrity verification of at least one Layer 2 message fails.
[0129] For example, the first value is a hash value determined based on at least one Layer 2 message. The verification information determined by the access network device is the hash value determined based on at least one Layer 2 message. If the hash value determined by the access network device is the same as the first value, the integrity verification of at least one Layer 2 message passes; if the hash value determined by the access network device is different from the first value, the integrity verification of at least one Layer 2 message fails.
[0130] For example, the first value is a hash value determined based on at least one LCID and at least one Layer 2 message. The verification information determined by the access network device is the hash value determined based on at least one LCID and at least one Layer 2 message. If the hash value determined by the access network device is the same as the first value, the integrity verification of at least one Layer 2 message passes; if the hash value determined by the access network device is different from the first value, the integrity verification of at least one Layer 2 message fails.
[0131] For example, the first value is a CRC value determined based on at least one LCID. The verification information determined by the access network device is a CRC value determined based on at least one LCID. If the CRC value determined by the access network device is the same as the first value, then the integrity verification of at least one Layer 2 message passes; if the CRC value determined by the access network device is different from the first value, then the integrity verification of at least one Layer 2 message fails.
[0132] For example, the first value is the CRC value determined based on the at least one Layer 2 message. The verification information determined by the access network device is the CRC value determined based on the at least one Layer 2 message. If the CRC value determined by the access network device is the same as the first value, the integrity verification of the at least one Layer 2 message passes; if the CRC value determined by the access network device is different from the first value, the integrity verification of the at least one Layer 2 message fails.
[0133] In another implementation, the access network device can compare the first information with at least one Layer 2 message received and / or sent by the access network device in the first interval to determine whether the integrity check has passed.
[0134] For example, the first information indicates at least one LCID corresponding to at least one Layer 2 message. If the at least one LCID corresponding to at least one Layer 2 message received and / or sent by the access network device in the first interval is the same as the at least one LCID indicated by the first information, then the integrity verification of at least one Layer 2 message passes; if the at least one LCID corresponding to at least one Layer 2 message received and / or sent by the access network device in the first interval is different from the at least one LCID indicated by the first information, then the integrity verification of at least one Layer 2 message fails. Here, "integrity verification passed" can also mean "integrity verification successful"; "integrity verification failed" can also mean "integrity verification failed."
[0135] For example, if the first information indicates at least one Layer 2 message, and the access network device receives and / or sends at least one Layer 2 message in the first interval that is the same as the at least one Layer 2 message indicated by the first information, then the integrity check of the at least one Layer 2 message passes; if the access network device receives and / or sends at least one Layer 2 message in the first interval that is not the same as the at least one Layer 2 message indicated by the first information, then the integrity check of the at least one Layer 2 message fails.
[0136] The above are just examples. When the first information indicates other information, the implementation of integrity verification for at least one Layer 2 message can be deduced by analogy and will not be elaborated further.
[0137] In one implementation, if at least one Layer 2 message integrity protection check fails based on first information, the RRC connection with the terminal device can be released. Optionally, the access network device can also indicate a reason value for releasing the RRC connection, which can indicate that the RRC connection is released due to the check failure.
[0138] Optionally, in this application, the access network device can also send fifth information to the terminal device; correspondingly, the terminal device receives the fifth information. In one implementation, at least one Layer 2 message is an uplink message within the first interval, that is, at least one Layer 2 message is a message sent by the terminal device within the first interval. Then, the fifth information can be determined based on M downlink Layer 2 messages within the first interval. The fifth information is used to perform integrity protection on the M downlink Layer 2 messages within the first interval, where M is an integer greater than 0.
[0139] For example, the fifth message indicates at least one of the following:
[0140] M downlink layer 2 messages correspond to M LCIDs, one downlink layer 2 message includes one LCID, M downlink layer 2 messages correspond one-to-one with M LCIDs, and one downlink layer 2 message in the M downlink layer 2 messages includes one LCID in the M LCIDs;
[0141] One or more downlink 2 messages from M downlink layer 2 messages;
[0142] The second value is determined based on the M LCIDs and / or M downlink layer 2 messages corresponding to the M downlink layer 2 messages.
[0143] For example, the second value is a hash value determined based on M LCIDs; or, the second value is the sum of M LCIDs; or, the second value is a hash value determined based on M downlink layer 2 messages; or, the second value is a hash value determined based on M LCIDs and M downlink layer 2 messages; or, the second value is a CRC value determined based on M LCIDs; or, the second value is a CRC value determined based on M downlink layer 2 messages. This application does not limit the method for determining the hash value and CRC value; the terminal device and the access network device can pre-agree on the method for determining the hash value and CRC value, and use the same method to determine the hash value and CRC value respectively.
[0144] In another implementation, at least one Layer 2 message is a downlink message within the first interval, that is, at least one Layer 2 message is a message received by the terminal device within the first interval (i.e., a message sent by the access network device). Then, the fifth information can be determined based on the M uplink Layer 2 messages within the first interval. The fifth information is used to perform integrity protection on the M uplink Layer 2 messages within the first interval.
[0145] For example, the fifth message indicates at least one of the following:
[0146] M uplink layer 2 messages correspond to M LCIDs, and there is a one-to-one correspondence between the M uplink layer 2 messages and the M LCIDs. One uplink layer 2 message in the M uplink layer 2 messages includes one LCID in the M LCIDs.
[0147] One or more uplink layer 2 messages from M uplink layer 2 messages;
[0148] The third value is determined based on the M LCIDs and / or M uplink layer 2 messages corresponding to the M uplink layer 2 messages.
[0149] For example, the third value is a hash value determined based on M LCIDs; or, the third value is the sum of M LCIDs; or, the third value is a hash value determined based on M uplink layer 2 messages; or, the third value is a hash value determined based on M LCIDs and M uplink layer 2 messages; or, the third value is a CRC value determined based on M LCIDs; or, the third value is a CRC value determined based on M uplink layer 2 messages.
[0150] In this application, the fifth message is located within the fourth message, which is an encrypted and / or integrity-protected message. For example, if the terminal device is in an RRC inactive state, the fourth message is an RRC establishment message. As another example, if the terminal device is in an RRC idle state, the fourth message is a message sent after safe mode is started, such as an RRC reconfiguration message.
[0151] In this application, the order in which the fifth message and the first message are sent is not limited. The fifth message may be sent before the first message or after the first message. This application does not limit this.
[0152] The terminal device performs integrity verification on M downlink layer 2 messages or M uplink layer 2 messages based on the fifth information.
[0153] For example, the fifth information indicates M LCIDs corresponding to M uplink Layer 2 messages. If the M LCIDs corresponding to the M uplink Layer 2 messages received by the terminal device in the first interval are the same as the M LCIDs indicated by the fifth information, then the integrity check of the M uplink Layer 2 messages passes; if the M LCIDs corresponding to the M uplink Layer 2 messages received by the terminal device in the first interval are different from the M LCIDs indicated by the fifth information, then the integrity check of the M uplink Layer 2 messages fails. Here, "integrity check passed" can also mean "integrity check successful"; "integrity check failed" can also mean "integrity check failed."
[0154] For example, if the fifth information indicates M downlink layer 2 messages, and the M downlink layer 2 messages received by the terminal device in the first interval are the same as the M downlink layer 2 messages indicated by the fifth information, then the integrity check of the M downlink layer 2 messages passes; if the M downlink layer 2 messages received by the terminal device in the first interval are not the same as the M downlink layer 2 messages indicated by the fifth information, then the integrity check of the M downlink layer 2 messages fails.
[0155] For example, the fifth information indicates the second value. The terminal device can determine the fourth value based on M LCIDs and / or M downlink layer 2 messages. The method by which the terminal device determines the fourth value is the same as the method by which the access network device determines the second value. If the third value is the same as the second value, the integrity check of the M downlink layer 2 messages passes; if the third value is different from the second value, the integrity check of the M downlink layer 2 messages fails.
[0156] For example, the fifth information indicates the third value. The terminal device can determine the fifth value based on M LCIDs and / or M uplink 2 messages. The method by which the terminal device determines the fifth value is the same as the method by which the access network device determines the third value. If the fifth value and the third value are the same, the integrity check of the M uplink 2 messages passes; if the fifth value and the third value are different, the integrity check of the M uplink 2 messages fails.
[0157] The above is just an example. When the fifth information indicates other information, the implementation method for integrity verification of M downlink layer 2 messages or M uplink layer 2 messages can be deduced by analogy, and will not be elaborated further.
[0158] In one implementation, if the terminal device fails the integrity protection verification of M downlink Layer 2 messages or M uplink Layer 2 messages based on the fifth information, it can trigger RRC re-establishment. The specific process of RRC re-establishment is not limited in this application and will not be described in detail here.
[0159] By using the above method, first information is determined based on at least one Layer 2 message received and / or sent within the first interval, thereby protecting the integrity of at least one Layer 2 message based on the first information, thus reducing the risk of at least one Layer 2 message being tampered with and improving system security.
[0160] In this application, the access network device may also generate the first information and send it to the terminal device, and the terminal device may perform integrity verification on at least one Layer 2 message based on the first information, as described below.
[0161] Figure 7 shows a flowchart of a communication method provided in an embodiment of this application. The method includes:
[0162] Step 701: The access network device receives and / or sends at least one Layer 2 message within the first interval.
[0163] Correspondingly, the terminal device can also receive and / or send at least one Layer 2 message within the first interval. The at least one Layer 2 message is a message transmitted between the terminal device and the access network device.
[0164] The terminal device may be in an RRC inactive state, an RRC idle state, or an RRC connected state. At least one Layer 2 message may include messages received and / or sent by the terminal device during the random access process; for example, the first Layer 2 message in the at least one Layer 2 message may be a message received and / or sent by the terminal device during the random access process. Other details regarding the at least one Layer 2 message can be found in the description of step 601, and will not be repeated here.
[0165] A Layer 2 message can be a MAC subPDU; or a Layer 2 message can be a MAC SDU or MAC CE in a MAC subPDU. For details, please refer to the description in step 601, which will not be repeated here.
[0166] In this application, the first interval can be preset, agreed upon by protocol, or configured by the access network device; this application does not limit this. The first interval can be implemented in various ways, as described in step 601, and will not be repeated here.
[0167] In one implementation, the access network device may further send second information. Correspondingly, the terminal device receives the second information from the access network device; the second information indicates the recording of received and / or sent Layer 2 messages, or the second information indicates the logging of Layer 2 message reception and / or transmission. Other details regarding the second information can be found in the description of step 601, and will not be repeated here.
[0168] In one implementation, the access network device may also send third information. Correspondingly, the terminal device receives the third information from the access network device; the third information indicates an RNA list or a cell list, where the RNA list includes at least one RNA and the cell list includes at least one cell. Other details regarding the third information can be found in the description of step 601 and will not be repeated here.
[0169] In one implementation, the access network device can also send a fourth message. Correspondingly, the terminal device receives the fourth message from the access network device; the fourth message indicates whether the first cell supports authentication of Layer 2 messages. The terminal device receives the fourth message in the first cell, and based on the fourth message, it can determine that the first cell supports authentication of Layer 2 messages, and then proceed to step 601.
[0170] Step 702: The access network device sends the first information to the terminal device.
[0171] Accordingly, the terminal device receives the first information from the access network device.
[0172] The first information is used to protect the integrity of at least one Layer 2 message within the first interval, and the first information is determined based on at least one Layer 2 message within the first interval.
[0173] This application does not limit how the first information is determined based on at least one Layer 2 message; please refer to the description in step 602, which will not be repeated here.
[0174] In this application, the first information is contained within the third message, which is an encrypted and / or integrity-protected message. The third message can be referred to in step 602 for details, and will not be repeated here.
[0175] Step 703: The terminal device performs integrity verification on at least one Layer 2 message based on the first information.
[0176] This application does not limit how the terminal device performs integrity verification on at least one Layer 2 message. In one possible implementation, the terminal device receives and / or sends at least one Layer 2 message in a first interval and determines verification information based on the at least one Layer 2 message. The method by which the terminal device determines the verification information is the same as the method by which the access network device determines the first information. If the verification information and the first information are the same, the integrity verification of at least one Layer 2 message passes, indicating that the at least one Layer 2 message received and / or sent by the terminal device in the first interval is the same as the at least one Layer 2 message received and / or sent by the access network device in the first interval, and the at least one Layer 2 message transmitted in the first interval has not been tampered with. If the verification information and the first information are different, the integrity verification of at least one Layer 2 message fails, indicating that the at least one Layer 2 message received and / or sent by the terminal device in the first interval is different from the at least one Layer 2 message received and / or sent by the access network device in the first interval, and the at least one Layer 2 message transmitted in the first interval may have been tampered with; in this case, the at least one Layer 2 message may be an invalid message.
[0177] In another implementation, the terminal device can compare the first information with at least one Layer 2 message received by the terminal device in the first interval to determine whether the integrity check passes. For example, the first information indicates at least one LCID corresponding to at least one Layer 2 message. If the at least one LCID corresponding to at least one Layer 2 message received and / or sent by the terminal device in the first interval is the same as the at least one LCID indicated by the first information, then the integrity check of at least one Layer 2 message passes; if the at least one LCID corresponding to at least one Layer 2 message received and / or sent by the terminal device in the first interval is different from the at least one LCID indicated by the first information, then the integrity check of at least one Layer 2 message fails.
[0178] For example, the first information indicates at least one Layer 2 message. If the terminal device receives and / or sends at least one Layer 2 message in the first interval that is the same as the at least one Layer 2 message indicated by the first information, then the integrity check of the at least one Layer 2 message passes; if the terminal device receives and / or sends at least one Layer 2 message in the first interval that is not the same as the at least one Layer 2 message indicated by the first information, then the integrity check of the at least one Layer 2 message fails.
[0179] The above is just an example. When the first information indicates other information, the implementation method of performing integrity verification on at least one Layer 2 message can be referred to the description of the access network device performing integrity verification on at least one Layer 2 message based on the first information in step 603, which will not be repeated here.
[0180] In one implementation, if the integrity protection check of at least one Layer 2 message fails based on the first information, an RRC re-establishment can be triggered. The specific process of RRC re-establishment is not limited in this application and will not be described in detail here.
[0181] Optionally, the terminal device may also send the fifth information to the access network device; correspondingly, the access network device receives the fifth information. The fifth information can be referred to in the description of step 603, and will not be repeated here. The access network device can perform integrity verification on M downlink Layer 2 messages or M uplink Layer 2 messages based on the fifth information. The specific verification process can be referred to the preceding description, and will not be repeated here.
[0182] Optionally, if the integrity verification of M downlink Layer 2 messages or M uplink Layer 2 messages fails based on the fifth information, the RRC connection with the terminal device can be released. The access network device can also indicate a reason value for releasing the RRC connection, which can indicate that the RRC connection is released due to the verification failure.
[0183] When this application is applied to an O-RAN architecture, the access network device may include an O-CU and an O-DU. The process executed by the access network device can be executed by the O-CU and the O-DU respectively. An example is given below.
[0184] Figure 8 shows a flowchart of a communication method provided in an embodiment of this application. The method includes:
[0185] Optionally, in step 801: the O-CU sends a second message.
[0186] The specific content of the second information can be found in the description in step 601, and will not be repeated here.
[0187] Step 802: The terminal device receives and / or sends at least one Layer 2 message within the first interval.
[0188] Correspondingly, the O-DU can also receive and / or send at least one Layer 2 message within the first interval.
[0189] Step 803: The terminal device sends the first information to the O-DU.
[0190] Accordingly, the O-DU receives the first information from the terminal device.
[0191] This application does not limit how the first information is determined based on at least one Layer 2 message; please refer to the description in step 602, which will not be repeated here.
[0192] Step 804: O-DU sends the first message to O-CU.
[0193] Correspondingly, the O-CU receives the first information from the O-DU.
[0194] The O-DU can also send at least one Layer 2 message to the O-CU, or the O-DU can also send verification information to the O-CU, the verification information being determined based on at least one Layer 2 message. The method by which the O-DU determines the verification information is the same as the method by which the terminal device determines the first information.
[0195] Step 805: The O-CU performs integrity verification on at least one Layer 2 message based on the first information.
[0196] For the specific verification process, please refer to the previous description, which will not be repeated here.
[0197] Optionally, step 806: O-CU sends the fifth information to the terminal device.
[0198] Step 807: The terminal device performs integrity verification on M downlink layer 2 messages or M uplink layer 2 messages based on the fifth information.
[0199] The specific content of the fifth piece of information can be found in the preceding descriptions and will not be repeated here.
[0200] In the above process, the process executed by O-CU can also be executed by O-CU-CP, and the specific process will not be described in detail.
[0201] It is understood that, in order to implement the functions in the above embodiments, the terminal device or access network device includes hardware structures and / or software modules corresponding to perform each function. Those skilled in the art should readily recognize that, based on the units and method steps of the various examples described in conjunction with the embodiments disclosed in this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.
[0202] The following are schematic diagrams of possible communication devices provided in the embodiments of this application. These communication devices can be used to implement the functions of terminal devices or access network devices in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments.
[0203] As shown in Figure 9, the communication device 900 includes a processing unit 910 and a communication unit 920. The communication device 900 is used to implement the functions of the terminal device or access network device in the various method embodiments shown above.
[0204] When the communication device 900 is used to implement the functions of a terminal device:
[0205] A communication unit for receiving and / or sending at least one Layer 2 message within a first interval;
[0206] The communication unit is used to send first information to the access network device; the first information is used to perform integrity protection on at least one Layer 2 message in the first interval, and the first information is determined based on the at least one Layer 2 message.
[0207] When the communication device 900 is used to implement the functions of an access network device:
[0208] A communication unit is configured to receive and / or transmit at least one Layer 2 message within a first interval; receive first information from a terminal device; the first information is used to perform integrity protection on the at least one Layer 2 message within the first interval, and the first information is determined based on the at least one Layer 2 message;
[0209] A processing unit is configured to perform integrity verification on the at least one Layer 2 message based on the first information.
[0210] When the communication device 900 is used to implement the functions of a terminal device:
[0211] A communication unit is configured to receive first information from an access network device; the first information is used to perform integrity protection on at least one Layer 2 message within a first interval, and the first information is determined based on the at least one Layer 2 message.
[0212] A processing unit is configured to perform integrity verification on the at least one Layer 2 message based on the first information.
[0213] When the communication device 900 is used to implement the functions of an access network device:
[0214] A communication unit for receiving and / or sending at least one Layer 2 message within a first interval;
[0215] The communication unit is used to send first information to the terminal device. The first information is used to perform integrity protection on at least one layer 2 message in the first interval. The first information is determined based on the at least one layer 2 message.
[0216] More detailed descriptions of the processing unit 910 and the communication unit 920 can be obtained directly from the relevant descriptions in the above method embodiments, and will not be repeated here.
[0217] It should be understood that the division of units in the above device is merely a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, all units in the device can be implemented entirely through software calls from processing elements; all units can be implemented entirely in hardware; or some units can be implemented through software calls from processing elements, while others are implemented in hardware. For example, each unit can be a separate processing element, or it can be integrated into a chip within the device. Alternatively, it can be stored as a program in memory, called and executed by a processing element of the device. Moreover, these units can be fully or partially integrated together, or implemented independently. The processing element here can also be called a processor, which can be an integrated circuit with signal processing capabilities. In the implementation process, the operations or units described above can be implemented through integrated logic circuits in the processor element or through software calls from processing elements.
[0218] In one example, a unit in any of the above devices can be one or more integrated circuits configured to implement the methods described above, such as: one or more application-specific integrated circuits (ASICs), or one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs), or a combination of at least two of these forms of integrated circuits. As another example, when a unit in the device can be implemented in the form of a processing element scheduler, the processing element can be a processor, such as a general-purpose central processing unit (CPU), or other processor capable of calling programs. Furthermore, these units can be integrated together to implement a system-on-a-chip (SOC).
[0219] The receiving unit described above is an interface circuit of the device, used to receive signals from other devices. For example, when the device is implemented as a chip, the receiving unit is an interface circuit for the chip to receive signals from other chips or devices. The transmitting unit described above is an interface circuit of the device, used to transmit signals to other devices. For example, when the device is implemented as a chip, the transmitting unit is an interface circuit for the chip to transmit signals to other chips or devices.
[0220] As another possible product form, the terminal device or access network device of this application embodiment can be implemented by a general bus architecture. For ease of explanation, refer to FIG10, which is a schematic diagram of the structure of a communication device 1000 provided in an embodiment of this application. The communication device 1000 includes a processor 1001 and a transceiver 1002. The communication device 1000 can be a terminal device, or a chip or chip system therein; or, the communication device 1000 can be an access network device, or a chip or module therein. FIG10 only shows the main components of the communication device 1000. In addition to the processor 1001 and transceiver 1002, the communication device 1000 may further include a memory 1003 and input / output devices (not shown in the figure).
[0221] Optionally, the processor 1001 is mainly used to process communication protocols and communication data, control the entire communication device, execute software programs, and process the data of the software programs. The memory 1003 is mainly used to store software programs and data. The transceiver 1002 may include radio frequency (RF) circuitry and an antenna. The RF circuitry is mainly used for converting baseband signals to RF signals and processing RF signals. The antenna is mainly used for transmitting and receiving RF signals in the form of electromagnetic waves. Input / output devices, such as touchscreens, displays, and keyboards, are mainly used to receive user input data and output data to the user.
[0222] Optionally, the processor 1001, transceiver 1002, and memory 1003 can be connected via a communication bus.
[0223] When the communication device is powered on, the processor 1001 can read the software program in the memory 1003, interpret and execute the instructions of the software program, and process the data of the software program. When data needs to be transmitted wirelessly, the processor 1001 performs baseband processing on the data to be transmitted and outputs the baseband signal to the radio frequency (RF) circuit. The RF circuit processes the baseband signal and transmits the RF signal outward in the form of electromagnetic waves through the antenna. When data is sent to the communication device, the RF circuit receives the RF signal through the antenna, converts the RF signal into a baseband signal, and outputs the baseband signal to the processor 1001. The processor 1001 converts the baseband signal into data and processes the data.
[0224] In another implementation, the radio frequency circuitry and antenna can be set up independently of the processor that performs baseband processing. For example, in a distributed scenario, the radio frequency circuitry and antenna can be arranged remotely, independent of the communication device.
[0225] In some embodiments, those skilled in the art will recognize that the above-described communication device 900 can take the form of the communication device 1000 shown in FIG10 in terms of hardware implementation.
[0226] As an example, the function / implementation process of the processing unit 910 in FIG9 can be implemented by the processor 1001 in the communication device 1000 shown in FIG10 calling computer execution instructions stored in the memory 1003. The function / implementation process of the communication unit 920 in FIG9 can be implemented by the transceiver 1002 in the communication device 1000 shown in FIG10.
[0227] As another possible product form, the terminal device or access network device in this application may adopt the composition structure shown in FIG11, or include the components shown in FIG11. FIG11 is a schematic diagram of the composition of a communication device 1100 provided in this application.
[0228] As shown in Figure 11, the communication device 1100 includes at least one processor 1101. Optionally, the communication device also includes a communication interface 1102.
[0229] When the relevant program instructions are executed in the at least one processor 1101, the communication device 1100 can implement the methods and any possible designs provided in any of the foregoing embodiments. Alternatively, the processor 1101 can implement the methods and any possible designs provided in any of the foregoing embodiments through logic circuits or executable code instructions.
[0230] The communication interface 1102 can be used to receive program instructions and transmit them to the processor, or the communication interface 1102 can be used for communication interaction between the communication device 1100 and other communication devices, such as exchanging control signaling and / or service data. For example, the communication interface 1102 can be used to receive signals from other devices besides the communication device 1100 and transmit them to the processor 1101, or to send signals from the processor 1101 to other communication devices besides the communication device 1100.
[0231] Optionally, the communication interface 1102 can be a code and / or data read / write interface circuit, or the communication interface 1102 can be a signal transmission interface circuit between a communication processor and a transceiver, or a chip pin.
[0232] Optionally, the communication device 1100 may further include at least one memory 1103, which can be used to store the required program instructions and / or data. It should be noted that the memory 1103 may exist independently of the processor 1101 or may be integrated with the processor 1101. The memory 1103 may be located within or outside the communication device 1100, without limitation.
[0233] Optionally, the communication device 1100 may further include a power supply circuit 1104, which can be used to power the processor 1101. The power supply circuit 1104 may be located in the same chip as the processor 1101, or in a separate chip outside the chip containing the processor 1101.
[0234] Optionally, the communication device 1100 may also include a bus, through which the various parts of the communication device 1100 can be interconnected.
[0235] In some embodiments, those skilled in the art will recognize that the communication device 900 shown in FIG9 can take the form of the communication device 1100 shown in FIG11 in terms of hardware implementation.
[0236] As an example, the function / implementation process of the processing unit 910 in FIG9 can be implemented by the processor 1101 in the communication device 1100 shown in FIG11 calling the computer execution instructions stored in the memory 1103. The function / implementation process of the communication unit 920 in FIG9 can be implemented by the communication interface 1102 in the communication device 1100 shown in FIG11.
[0237] It should be noted that the structure shown in Figure 11 does not constitute a specific limitation on the terminal device or access network device. For example, in other embodiments of this application, the terminal device or access network device may include more or fewer components than shown in the figure, or combine some components, or split some components, or have different component arrangements. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0238] When the aforementioned communication device is a chip applied to a terminal, the terminal chip implements the functions of the terminal in the above method embodiments. The terminal chip receives information from other modules (such as radio frequency modules or antennas) in the terminal, which is information sent to the terminal by the base station; or, the terminal chip sends information to other modules (such as radio frequency modules or antennas) in the terminal, which is information sent to the base station by the terminal.
[0239] When the aforementioned communication device is a module applied to a base station, the base station module implements the functions of the base station in the above method embodiments. The base station module receives information from other modules (such as radio frequency modules or antennas) in the base station, information sent by the terminal to the base station; or, the base station module sends information to other modules (such as radio frequency modules or antennas) in the base station, information sent by the base station to the terminal. Here, the base station module can be the baseband chip of the base station, or a DU (Digital Unit) or other modules. The DU can be a DU under an Open Radio Access Network (O-RAN) architecture.
[0240] It is understood that the processor in the embodiments of this application may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor may be a microprocessor or any conventional processor.
[0241] The method steps in the embodiments of this application can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can reside in an ASIC. Alternatively, the ASIC can reside in a base station or terminal. Of course, the processor and storage medium can also exist as discrete components in the base station or terminal.
[0242] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are performed entirely or partially. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user equipment, or other programmable device. The computer program or instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; it can also be an optical medium, such as a digital video optical disc; or it can be a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both types of storage media.
[0243] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0244] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, optical storage, etc.) containing computer-usable program code.
[0245] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.
[0246] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.
[0247] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A communication method, characterized in that, include: Receive and / or send at least one Layer 2 message within the first interval; Send the first message to the access network device; The first information is used to protect the integrity of at least one Layer 2 message within the first interval, and the first information is determined based on the at least one Layer 2 message.
2. The method according to claim 1, characterized in that, The method further includes: Receive second information from the access network device; the second information indicates the recording of received and / or transmitted Layer 2 messages.
3. The method according to claim 2, characterized in that, The second information also indicates the first interval.
4. The method according to any one of claims 1 to 3, characterized in that, The first interval is a time range; Alternatively, the first interval is the interval from the start of the first message to the end of the second message; Alternatively, the first interval can be an interval for the transmission of N layer 2 messages, where N is an integer greater than 0.
5. The method according to any one of claims 1 to 4, characterized in that, The first information is determined based on the at least one Layer 2 message, including: The first information indicates at least one of the following: At least one logical channel identifier (LCID), wherein the at least one LCID is the LCID included in the at least one Layer 2 message; The at least one Layer 2 message; A first value is determined based on the at least one LCID and / or the at least one Layer 2 message.
6. The method according to claim 5, characterized in that, The first value is a hash value determined based on the at least one LCID; Alternatively, the first value may be the sum of the at least one LCID; Alternatively, the first value may be a hash value determined based on the at least one Layer 2 message; Alternatively, the first value may be a hash value determined based on the at least one LCID and the at least one Layer 2 message; Alternatively, the first value may be a cyclic redundancy check value determined based on the at least one LCID; Alternatively, the first value may be a cyclic redundancy check value determined based on the at least one layer 2 message.
7. The method according to any one of claims 1 to 6, characterized in that, The first information is located in the third message, which is an encrypted and / or integrity-protected message.
8. The method according to claim 7, characterized in that, The third message is the Radio Resource Control recovery complete (RRCresumecomplete) message. Alternatively, the third message may be a message sent after safe mode is started.
9. A communication method, characterized in that, include: Receive and / or send at least one Layer 2 message within the first interval; Receive the first information from the terminal device; The first information is used to protect the integrity of at least one Layer 2 message within the first interval, and the first information is determined based on the at least one Layer 2 message; Integrity verification is performed on the at least one Layer 2 message based on the first information.
10. The method according to claim 9, characterized in that, The method further includes: Send a second message; the second message indicates the recording of received and / or sent Layer 2 messages.
11. The method according to claim 10, characterized in that, The second information also indicates the first interval.
12. The method according to any one of claims 9 to 11, characterized in that, The first interval is a time range; Alternatively, the first interval is the interval from the start of the first message to the end of the second message; Alternatively, the first interval can be an interval for the transmission of N layer 2 messages, where N is an integer greater than 0.
13. The method according to any one of claims 9 to 12, characterized in that, The first information is determined based on the at least one Layer 2 message, including: The first information indicates at least one of the following: At least one logical channel identifier (LCID), wherein the at least one LCID is the LCID included in the at least one Layer 2 message; The at least one Layer 2 message; A first value is determined based on the at least one LCID and / or the at least one Layer 2 message.
14. The method according to claim 13, characterized in that, The first value is a hash value determined based on the at least one LCID; Alternatively, the first value may be the sum of the at least one LCID; Alternatively, the first value may be a hash value determined based on the at least one Layer 2 message; Alternatively, the first value may be a hash value determined based on the at least one LCID and the at least one Layer 2 message; Alternatively, the first value may be a cyclic redundancy check value determined based on the at least one LCID; Alternatively, the first value may be a cyclic redundancy check value determined based on the at least one layer 2 message.
15. The method according to any one of claims 9 to 14, characterized in that, The first information is located in the third message, which is an encrypted and / or integrity-protected message.
16. The method according to claim 15, characterized in that, The third message is the Radio Resource Control recovery complete (RRCresumecomplete) message. Alternatively, the third message may be a message sent after safe mode is started.
17. The method according to any one of claims 9 to 16, characterized in that, The method further includes: If the integrity protection check of at least one Layer 2 message fails based on the first information, the method also includes: Release the Radio Resource Control (RRC) connection with the terminal device.
18. A communication method, characterized in that, include: Receive the first information from the access network device; The first information is used to protect the integrity of at least one Layer 2 message within the first interval, and the first information is determined based on the at least one Layer 2 message; Integrity verification is performed on the at least one Layer 2 message based on the first information.
19. A communication method, characterized in that, include: Receive and / or send at least one Layer 2 message within the first interval; Send first information to the terminal device. The first information is used to protect the integrity of at least one Layer 2 message in the first interval. The first information is determined based on the at least one Layer 2 message.
20. A communication device, characterized in that, include: A communication unit for receiving and / or sending at least one Layer 2 message within a first interval; The communication unit is used to send first information to the access network device; The first information is used to protect the integrity of at least one Layer 2 message within the first interval, and the first information is determined based on the at least one Layer 2 message.
21. A communication device, characterized in that, include: A communication unit for receiving and / or sending at least one Layer 2 message within a first interval; Receive the first information from the terminal device; The first information is used to protect the integrity of at least one Layer 2 message within the first interval, and the first information is determined based on the at least one Layer 2 message; A processing unit is configured to perform integrity verification on the at least one Layer 2 message based on the first information.
22. A communication device, characterized in that, include: The communication unit is used to receive first information from the access network equipment; The first information is used to protect the integrity of at least one Layer 2 message within the first interval, and the first information is determined based on the at least one Layer 2 message; A processing unit is configured to perform integrity verification on the at least one Layer 2 message based on the first information.
23. A communication device, characterized in that, include: A communication unit for receiving and / or sending at least one Layer 2 message within a first interval; The communication unit is used to send first information to the terminal device. The first information is used to perform integrity protection on at least one layer 2 message in the first interval. The first information is determined based on the at least one layer 2 message.
24. A communication device, characterized in that, Includes a processor; the processor is configured to execute a computer program or instructions that cause the communication device to implement the method described in any one of claims 1 to 19.
25. A computer-readable storage medium, characterized in that, The computer contains a computer program or instructions that, when executed on a computer, cause the computer to perform the method as described in any one of claims 1 to 19.
26. A chip, characterized in that, The chip includes a processor coupled to a memory for executing a computer program or instructions stored in the memory, such that the chip implements the method of any one of claims 1 to 19.
27. A computer program product, characterized in that, When the computer reads and executes the computer program product, the method described in any one of claims 1 to 19 is performed.
Citation Information
Patent Citations
Security information updating method and access network equipment
CN109803257A
Layer 2 security enhancements
CN116171641A
Encryption method and device based on channel secret key
CN116866900A
Method and apparatus for enhancing security of mac layer entity in next-generation mobile communication system
US20220240094A1
Distributed unit node, user equipment, and methods in a wireless communications network
US20230388790A1