Information verification method and related apparatus
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2025-09-05
- Publication Date
- 2026-08-06
Smart Images

Figure CN2025119512_06082026_PF_FP_ABST
Abstract
Description
Information verification methods and related devices
[0001] This application claims priority to Chinese Patent Application No. 202411257267.9, filed on September 6, 2024, entitled "Information Verification Method and Related Apparatus", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of communications, and more particularly to an information verification method and related apparatus. Background Technology
[0003] In mobile communication systems, network devices periodically broadcast system messages to provide user equipment (UE) with necessary network access parameters and public information. However, these system messages are broadcast in plaintext, lacking security protection.
[0004] One security verification method is as follows: the network device uses its private key to digitally sign the system message and broadcasts the system message with the digital signature. The UE decrypts the received system message using the network device's public key. When the digital signature obtained after decryption matches the digest of the system message, the security verification is passed, and the UE can further use the information provided by the system message.
[0005] However, performing security verification using the above methods may lead to a decrease in the communication quality of the UE. Summary of the Invention
[0006] This application provides an information verification method and related apparatus to improve the communication quality of terminal devices accessing the network.
[0007] In a first aspect, embodiments of this application provide a multi-carrier communication method applied to the terminal side, such as a terminal device or a communication module in the terminal device, or a circuit or chip in the terminal device responsible for communication functions. Taking the application of this method to a terminal device as an example, the method includes: receiving at least one first system message; and verifying at least one first system message when entering a mode with security protection.
[0008] When entering a security-protected mode, the at least one first system message is verified, which enables the embodiments of this application to support the absence of digital signature information in the first system message, thereby saving bandwidth resources for network device broadcasting and improving the communication quality of terminal devices.
[0009] In some implementations, the method also includes:
[0010] Record the first information, which is used to indicate at least one first system message.
[0011] By recording the first information, the terminal device can locally store information indicating at least one first system message for subsequent verification.
[0012] In some implementations, there are security protection modes, including entering a secure mode from the radio resource control (RRC) connection state.
[0013] Specifically, when entering a security protection mode, verifying at least one first system message includes: receiving second information in the security mode, the second information being used to indicate at least one second system message; and verifying at least one first system message based on the first information and the second information.
[0014] When a terminal device in RRC connection state enters secure mode, it can securely receive second information indicating at least one second system message, which facilitates the verification of at least one first system message based on the first and second information.
[0015] In some implementations, the first information includes at least one first system message, and the second information includes at least one second system message or digital signature information of at least one second system message; or, the first information includes verification information of at least one first system message, and the second information includes verification information of at least one second system message or digital signature information of verification information of at least one second system message.
[0016] When the type of information included in the second information is the same as the type of information included in the first information, it is beneficial to improve the efficiency of information verification by the terminal device. When the type of information included in the second information is a digital signature of the type of information included in the first information, it is beneficial to improve the security of information verification by the terminal device.
[0017] In some implementations, there are security protection modes, including entering a secure mode from the RRC connection state.
[0018] Specifically, when entering a security-protected mode, verifying at least one first system message includes: in the security mode, sending third information, which is used to indicate at least one first system message.
[0019] When a terminal device in RRC connection mode enters secure mode, it can securely send third information to the network device to indicate at least one first system message.
[0020] In some implementations, the first information includes at least one first system message, and the third information includes at least one first system message or digital signature information of at least one first system message; or, the first information includes verification information of at least one first system message, and the third information includes verification information of at least one first system message or digital signature information of verification information of at least one first system message.
[0021] In some implementations, security protection modes include random access procedures implemented by RRC inactive states.
[0022] Specifically, when entering a mode with security protection, at least one first system message is verified, including: during the random access process implemented by the RRC inactive state, receiving message 4, which is used to indicate at least one second system message; and verifying at least one first system message based on the first information and message 4.
[0023] During the random access process in the RRC inactive state, at least one second system message is indicated by message 4. This allows for the early verification of at least one first system message even when security protection is in place and security mode is not activated. This improves the efficiency of information verification and enhances the user experience.
[0024] In some implementations, the first information includes at least one first system message, and message 4 includes at least one second system message or digital signature information of at least one second system message; or, the first information includes verification information of at least one first system message, and message 4 includes verification information of at least one second system message or digital signature information of verification information of at least one second system message.
[0025] When the information type included in message 4 is the same as the information type included in the first message, it is beneficial to improve the efficiency of information verification by the terminal device. When the information type included in message 4 is a digital signature of the information type included in the first message, it is beneficial to improve the security of information verification by the terminal device.
[0026] In some implementations, the security protection mode includes a random access process implemented by the RRC inactive state.
[0027] Specifically, when entering a mode with security protection, at least one first system message is verified, including: during the random access process implemented by the RRC inactive state, message 5 is sent, which is used to indicate at least one first system message.
[0028] During the process of implementing random access in the RRC inactive state, information indicating at least one first system message can be securely sent to the network device via message 5.
[0029] In some implementations, the first information includes at least one first system message, and message 5 includes at least one first system message or digital signature information of at least one first system message; or, the first information includes verification information of at least one first system message, and message 5 includes verification information of at least one first system message or digital signature information of verification information of at least one first system message.
[0030] In some implementations, the method also includes:
[0031] Receive a fourth message, which is used to indicate that at least one first system message is recorded.
[0032] Based on the fourth information, the terminal device can record at least one first system message from the received system messages, which helps to avoid recording the remaining system messages and thus saves storage resources.
[0033] In some implementations, the fourth message is carried in any of the following: a system message, a non-access stratum (NAS) message, or an RRC release message.
[0034] By including the fourth piece of information in the above information, it is possible to avoid sending the fourth piece of information independently, which helps to save downlink overhead.
[0035] Secondly, embodiments of this application provide an information verification method applied to the network side, such as a network device or a component (e.g., a chip, a chip system, etc.) in the network device, or it can also be a logic module or software that can realize all or part of the functions of the network device. Taking the application of this method to a network device as an example, the method includes: obtaining at least one second system message; and verifying at least one second system message when entering a mode with security protection.
[0036] In some implementations, the method also includes:
[0037] Record the fifth piece of information, which is used to indicate at least one second system message.
[0038] By recording the fifth piece of information, network devices can locally store information indicating at least one second system message for subsequent verification.
[0039] In some implementations, there are security protection modes, including entering a secure mode from the RRC connection state.
[0040] Specifically, when entering a security-protected mode, verifying at least one second system message includes: in the security mode, sending second information, which is used to indicate at least one second system message.
[0041] In some implementations, the fifth information includes at least one second system message, and the second information includes at least one second system message or digital signature information of at least one second system message; or, the fifth information includes verification information of at least one fifth system message, and the second information includes verification information of at least one second system message or digital signature information of verification information of at least one second system message.
[0042] In some implementations, there are security protection modes, including entering a secure mode from the RRC connection state;
[0043] Specifically, when entering a security-protected mode, verifying at least one second system message includes: receiving third information in the security mode, the third information being used to indicate at least one first system message; and verifying at least one second system message based on the third information and the fifth information.
[0044] In some implementations, the fifth information includes at least one second system message, and the third information includes at least one first system message or digital signature information of at least one first system message; or, the fifth information includes verification information of at least one second system message, and the third information includes verification information of at least one first system message or digital signature information of verification information of at least one first system message.
[0045] In some implementations, security protection modes include random access procedures implemented by RRC inactive states.
[0046] Specifically, when entering a mode with security protection, at least one second system message is verified, including: during the random access process implemented by the RRC inactive state, message 4 is sent, which is used to indicate at least one second system message.
[0047] In some implementations, the fifth information includes at least one second system message, and message 4 includes at least one second system message or digital signature information of at least one second system message; or, the fifth information includes verification information of at least one second system message, and message 4 includes verification information of at least one second system message or digital signature information of verification information of at least one second system message.
[0048] In some implementations, security protection modes include the process of random access being implemented in an inactive RRC state;
[0049] Specifically, when entering a mode with security protection, at least one first system message is verified, including: during the random access process implemented by the RRC inactive state, message 5 is received, which is used to indicate at least one first system message.
[0050] In some implementations, the fifth information includes at least one second system message, and message 5 includes at least one first system message or digital signature information of at least one first system message; or, the fifth information includes verification information of at least one second system message, and message 5 includes verification information of at least one first system message or digital signature information of verification information of at least one first system message.
[0051] In some implementations, the method also includes:
[0052] Send a sixth message, which is used to instruct the recording of at least one first system message.
[0053] In some implementations, the sixth piece of information is carried in a system message or an RRC release message.
[0054] Thirdly, embodiments of this application provide an information verification device, including modules or units for implementing the methods of the first aspect and any possible implementation of the first aspect, or including modules for implementing the methods of the second aspect and any possible implementation of the second aspect. Each module or unit can implement its corresponding function by executing a computer program.
[0055] For example, the information verification device in the third aspect is a terminal device or a component configured in a terminal device, such as a chip, chip system, processor, etc.; or, the information verification device in the third aspect is a network device or a component configured in a network device, such as a chip, chip system, processor, etc.
[0056] Fourthly, embodiments of this application provide an information verification device, including a processor, which is configured to execute the information verification method in the first aspect and any possible implementation of the first aspect, or to execute the communication method in the second aspect and any possible implementation of the second aspect.
[0057] Optionally, the information verification device includes a memory for storing instructions and data. The memory is coupled to a processor, and when the processor executes the instructions stored in the memory, it can implement the methods described in the above aspects.
[0058] Optionally, the information verification device includes a communication interface for communicating with other communication devices. For example, the communication interface may be a transceiver, circuit, bus, module, pin, or other type of communication interface.
[0059] For example, the information verification device provided in the fourth aspect is a chip or chip system, or it can be a terminal device or network device.
[0060] Fifthly, embodiments of this application provide a computer-readable storage medium including a computer program that, when run on a computer, causes the computer to implement the methods of the first or second aspect and any possible implementation of the first or second aspect.
[0061] In a sixth aspect, embodiments of this application provide a computer program product, which includes a computer program (also referred to as code or instructions) that, when run, causes a computer to perform the methods of the first or second aspect and any possible implementation thereof.
[0062] In a seventh aspect, embodiments of this application provide an information verification system, including the aforementioned terminal device and network device. The terminal device can be used to implement the methods in the first aspect and any possible implementation of the first aspect, and the network device can be used to implement the methods in the second aspect and any possible implementation of the second aspect.
[0063] The third to seventh aspects of this application correspond to the technical solutions of the first or second aspects of this application. The beneficial effects achieved by each aspect and the corresponding feasible implementation are similar, and will not be described again. Attached Figure Description
[0064] Figure 1 is a schematic diagram of the architecture of the communication system used in the embodiments of this application;
[0065] Figure 2 is a schematic diagram of the access network equipment used in the embodiments of this application;
[0066] Figure 3 is a schematic diagram of a certificate-based signature mechanism;
[0067] Figure 4 is a flowchart illustrating an information verification method provided in an embodiment of this application;
[0068] Figure 5 is a flowchart illustrating an information verification method provided in another embodiment of this application;
[0069] Figure 6 is a flowchart illustrating an information verification method provided in another embodiment of this application;
[0070] Figure 7 is a flowchart illustrating an information verification method provided in another embodiment of this application;
[0071] Figure 8 is a flowchart illustrating an information verification method provided in another embodiment of this application;
[0072] Figure 9 is a flowchart illustrating an information verification method provided in an embodiment of this application;
[0073] Figure 10 is a flowchart illustrating an information verification method provided in an embodiment of this application;
[0074] Figure 11 is a flowchart illustrating an information verification method provided in another embodiment of this application;
[0075] Figure 12 is a flowchart illustrating an information verification method provided in another embodiment of this application;
[0076] Figure 13 is a schematic diagram of the structure of an information verification device provided in an embodiment of this application;
[0077] Figure 14 is a schematic diagram of the structure of an information verification device provided in another embodiment of this application. Detailed Implementation
[0078] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0079] It should be understood that in this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates an "or" relationship between the preceding and following related objects, but does not exclude the possibility of indicating an "and" relationship; the specific meaning can be understood in context. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c; a and b; a and c; b and c; or a and b and c. Here, a, b, and c can be single or multiple.
[0080] In this application, the use of prefixes such as "first" and "second" is merely for the purpose of distinguishing and describing different things belonging to the same category, and does not constrain the order, size, or quantity of things. For example, "first parameter" and "second parameter" are simply different parameters, and there is no temporal or quantitative relationship between them.
[0081] This application will present various aspects, embodiments, or features relating to systems that may include multiple devices, components, modules, etc. It should be understood and appreciated that individual systems may include additional devices, components, modules, etc., and / or may not include all the devices, components, modules, etc. discussed in conjunction with the accompanying drawings. Furthermore, combinations of these approaches are also possible.
[0082] Furthermore, in the embodiments of this application, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design scheme described as an "example" in this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of the term "example" is intended to present concepts in a concrete manner. In the embodiments of this application, "of," "corresponding, relevant," and "corresponding" may sometimes be used interchangeably, and it should be noted that their intended meanings are consistent unless their distinction is emphasized.
[0083] Figure 1 is a schematic diagram of the architecture of the communication system applied in the embodiments of this application. Figure 1 shows a schematic diagram of a possible, non-limiting system architecture. As shown in Figure 1, the communication system includes a radio access network (RAN) 100 and a core network (CN) 200. RAN 100 includes at least one RAN node (110a and 110b in Figure 1, collectively referred to as 110) and at least one terminal device (120a-120j in Figure 1, collectively referred to as 120). RAN 100 may also include other RAN nodes, such as wireless relay devices and / or wireless backhaul devices (not shown in Figure 1). Terminal device 120 is wirelessly connected to RAN node 110. RAN node 110 is wirelessly or wired connected to core network 200. The core network device in core network 200 and RAN node 110 in RAN 100 may be different physical devices, or they may be the same physical device integrating core network logical functions and radio access network logical functions.
[0084] RAN 100 can be a cellular system related to the 3rd Generation Partnership Project (3GPP), such as 4G, 5G mobile communication systems, or future-oriented evolution systems (such as 6G mobile communication systems). RAN 100 can also be an open RAN (O-RAN or ORAN), a cloud radio access network (CRAN), or a virtualized RAN (vRAN). RAN 100 can also be a communication system that integrates two or more of the above systems.
[0085] RAN node 110, sometimes also referred to as access network equipment, RAN entity, or access node, is part of the communication system used to help terminal devices achieve wireless access. Multiple RAN nodes 110 in communication system 1000 can be of the same type or different types. In some scenarios, the roles of RAN node 110 and terminal device 120 are relative. For example, network element 120i in Figure 1 can be a helicopter or drone, which can be configured as a mobile base station. For terminal devices 120j accessing RAN 100 through network element 120i, network element 120i is a base station; but for base station 110a, network element 120i is a terminal device. RAN node 110 and terminal device 120 are sometimes both referred to as communication devices. For example, network elements 110a and 110b in Figure 1 can be understood as communication devices with base station functions, and network elements 120a-120j can be understood as communication devices with terminal functions.
[0086] In one possible scenario, a RAN node can be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next-generation NodeB (gNB), or a base station in a future mobile communication system. A RAN node can be a macro base station (as shown in Figure 1, 110a), a micro base station or indoor station (as shown in Figure 1, 110b), a relay node or donor node, or a radio controller in a CRAN scenario. Optionally, a RAN node can also be a server, wearable device, vehicle, or in-vehicle equipment. For example, the access network equipment in vehicle-to-everything (V2X) technology can be a roadside unit (RSU).
[0087] In another possible scenario, multiple RAN nodes collaborate to assist the terminal in achieving wireless access, with different RAN nodes each implementing some of the base station's functions. For example, RAN nodes can be central units (CUs), distributed units (DUs), CU-control planes (CU-CPs), CU-user planes (CU-UPs), or radio units (RUs). CUs and DUs can be separate entities or included in the same network element, such as a baseband unit (BBU). RUs can be included in radio frequency equipment or radio frequency units, such as remote radio units (RRUs), active antenna units (AAUs), or remote radio heads (RRHs).
[0088] In different systems, CU (or CU-CP and CU-UP), DU, or RU may have different names, but those skilled in the art will understand their meaning. For example, in an ORAN system, CU can also be called an open-CU (open-CU, O-CU), DU can also be called an open-DU (open-DU, O-DU), CU-CP can also be called an open-CU-CP (open-CU-CP, O-CU-CP), CU-UP can also be called an open-CU-UP (open-CU-UP, O-CU-UP), and RU can also be called an open-RU (open-RU, O-RU). For ease of description, this application uses CU, CU-CP, CU-UP, DU, and RU as examples. Any of the units among CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented through software modules, hardware modules, or a combination of software and hardware modules.
[0089] Terminal devices can also be called terminals, user equipment (UE), mobile stations, mobile terminals, etc. They can be widely used in various scenarios, such as device-to-device (D2D), vehicle-to-everything (V2X) communication, machine-type communication (MTC), the Internet of Things (IoT), virtual reality, augmented reality, industrial control, autonomous driving, telemedicine, smart grids, smart furniture, smart offices, smart wearables, smart transportation, and smart cities. Terminals can be mobile phones, tablets, computers with wireless transceiver capabilities, wearable devices, vehicles, drones, helicopters, airplanes, ships, robots, robotic arms, smart home devices, etc.
[0090] Base stations and terminals can be fixed or mobile. They can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; they can also be deployed on water; and they can be deployed on aircraft, balloons, and satellites. The embodiments of this application do not limit the application scenarios of the base stations and terminals.
[0091] The roles of base stations and terminals can be relative. For example, the helicopter or drone 120i in Figure 1 can be configured as a mobile base station. For terminals 120j that access the wireless access network 100 through 120i, terminal 120i is a base station; however, for base station 110a, 120i is a terminal, meaning that 110a and 120i communicate via a wireless air interface protocol. Of course, 110a and 120i can also communicate via a base station-to-base station interface protocol. In this case, relative to 110a, 120i is also a base station. Therefore, both base stations and terminals can be collectively referred to as communication devices. 110a and 110b in Figure 1 can be called communication devices with base station functions, and 120a-120j in Figure 1 can be called communication devices with terminal functions.
[0092] Communication between base stations and terminals, between base stations, and between terminals can be conducted using licensed spectrum, unlicensed spectrum, or both simultaneously. Communication can be conducted using spectrum below 6 GHz, spectrum above 6 GHz, or both simultaneously. The embodiments of this application do not limit the spectrum resources used for wireless communication.
[0093] In the embodiments of this application, the functions of the base station can be executed by modules (such as chips) within the base station, or by a control subsystem that includes base station functions. This control subsystem, including base station functions, can be a control center in the aforementioned application scenarios such as smart grids, industrial control, intelligent transportation, and smart cities. Similarly, the functions of the terminal can be executed by modules (such as chips or modems) within the terminal, or by a device that includes terminal functions.
[0094] Figure 2 is a schematic diagram of the access network device used in the embodiments of this application. As shown in Figure 2, the access network device includes one or more CUs, one or more DUs, and one or more RUs. For clarity, only one CU, DU, and RU are shown in Figure 2. The CU is used to connect to the core network and one or more DUs. Optionally, the CU may have some of the functions of the core network. The CU may include CU-CP and CU-UP.
[0095] The CU and DU can be configured according to the protocol layer functions of the wireless network they implement: for example, the CU can be configured to implement the functions of the Packet Data Convergence Protocol (PDCP) layer and above (such as the Radio Resource Control (RRC) layer and / or the Service Data Adaptation Protocol (SDAP) layer); the DU can be configured to implement the functions of the protocol layers below the PDCP layer (such as the Radio Link Control (RLC) layer, the Medium Access Control (MAC) layer, and / or the Physical (PHY) layer). Alternatively, the CU can be configured to implement the functions of the protocol layers above the PDCP layer (such as the RRC and / or SDAP layers), and the DU can be configured to implement the functions of the protocol layers below the PDCP layer (such as the RLC, MAC, and / or PHY layers).
[0096] When a CU includes CU-CP and CU-UP, CU-CP is used to implement the control plane functions of the CU, and CU-UP is used to implement the user plane functions of the CU. For example, when a CU is configured to implement the functions of the PDCP layer, RRC layer, and SDAP layer, CU-CP is used to implement the RRC layer functions and the control plane functions of the PDCP layer, and CU-UP is used to implement the SDAP layer functions and the user plane functions of the PDCP layer.
[0097] The CU-CP can interact with network elements in the core network used to implement control plane functions. These network elements can be access and mobility function (AMF) network elements, such as the AMF network element in a 5G system. The AMF network element is responsible for mobility management in the mobile network, such as terminal device location updates, terminal device registration with the network, and terminal device handover.
[0098] CU-UP can interact with network elements in the core network used to implement user plane functions. These network elements, such as the user plane function (UPF) network elements in a 5G system, are responsible for forwarding and receiving data in terminal devices.
[0099] The above CU and DU configurations are merely examples; the functions of the CU and DU can be configured as needed. For instance, the CU or DU can be configured to have more protocol layer functions, or only some protocol layer processing functions. For example, some RLC layer functions and protocol layer functions above the RLC layer can be placed in the CU, while the remaining RLC layer functions and protocol layer functions below the RLC layer can be placed in the DU. Furthermore, the functions of the CU or DU can be divided according to service type or other system requirements, such as by latency. Functions that require low latency can be placed in the DU, while functions that do not require low latency can be placed in the CU.
[0100] DU and RU can cooperate to implement the functions of the PHY layer. A DU can be connected to one or more RUs. The functions of DU and RU can be configured in various ways depending on the design. For example, a DU can be configured to implement baseband functions, and an RU can be configured to implement mid-RF functions. Another example is that a DU can be configured to implement higher-level functions in the PHY layer, and an RU can be configured to implement lower-level functions in the PHY layer, or to implement both lower-level and RF functions. Higher-level functions in the physical layer can include a portion of the physical layer's functions that are closer to the MAC layer, while lower-level functions in the physical layer can include another portion of the physical layer's functions that are closer to the mid-RF side.
[0101] To better understand the embodiments of this application, the technologies and terms involved in this application are briefly explained below.
[0102] I. Private Key and Public Key
[0103] In asymmetric encryption (also known as public-key encryption), encryption can be performed using a private key and a public key. The private key and public key can be used together to form a key pair for secure data transmission and authentication.
[0104] In asymmetric encryption algorithms, the private key is used to decrypt data or create digital signatures. The private key is kept secret, typically known only to its holder, and must be securely protected to prevent unauthorized access. The public key, paired with the private key, is used to encrypt data or verify digital signatures. The public key is public and can be securely distributed to any entity that needs to communicate with it.
[0105] II. Digital Signature
[0106] Digital signatures are a cryptographic technique used to verify the integrity and authenticity of digital documents or data. When using digital signatures, the sender uses their private key to encrypt the data or its hash value, obtaining a digital signature, which is then sent to the recipient along with the original data. Upon receiving the data, the recipient uses the sender's public key to decrypt the digital signature, obtaining a hash value. This hash value is then used to perform a hash operation on the original data to obtain another hash value. Comparing these two hash values, if they match, it indicates that the data has not been tampered with during transmission, thus verifying the data's integrity and authenticity.
[0107] III. System Messages
[0108] In wireless communication networks, system messages are crucial information broadcast by network devices to all terminal devices. These messages contain basic network configurations, operating parameters, and other necessary information that terminal devices require to correctly access and operate the network. For example, in 5G New Radio (NR) systems, system messages are subdivided into three main categories: minimum system information (MSI), remaining minimum system information (RMSI), and other system information (OSI). MSI is the most basic set of information necessary for terminal devices to access the network, primarily including the master information block (MIB) and system information block (SIB). RMSI mainly includes SIB1, which provides relatively static system-level parameters to maintain network connectivity and assists in network handover and reselection. OSI encompasses more system information, from SIB2 to SIB9, which conveys more detailed parameters related to network functions and services.
[0109] In the communication system shown in Figure 1, before accessing the network, terminal devices need to receive system messages from network devices to obtain initial access information. The network devices periodically broadcast these system messages in plaintext on the downlink, meaning they have no security protection. Therefore, important information within these system messages may be subject to tampering or forgery. For example, SIB19 in the system message includes auxiliary information for non-terrestrial networks (NTN). Attackers can tamper with ephemeris information, service times, and other information in SIB19, causing idle terminal devices to be unable to access the NTN network, and degrading the transmission quality of connected terminal devices within the NTN network.
[0110] Figure 3 illustrates a certificate-based signature mechanism. As shown in Figure 3, after verification at a Certificate Authority (CA), a network device can obtain a digital certificate, which includes the network device's public key. To protect system message security, the network device digests the system message, obtains its hash value, and encrypts the hash value using its private key to obtain the digital signature information of the system message hash value.
[0111] When a network device broadcasts a system message, it also broadcasts its digital certificate and the digital signature information of the system message's hash value. Upon receiving the system message and its hash value, the terminal device decrypts the digital signature using the network device's public key, obtaining a hash value. The terminal device then digests the received system message, obtaining another hash value. The terminal device compares the decrypted hash value with the digest hash value. If the two hash values match, it indicates that the system message has not been tampered with during transmission, and the security verification is successful. After successful security verification, the terminal device can obtain initial access information based on the system message to enable subsequent access.
[0112] However, in the above security verification methods, the network device sends digital signature information along with system messages. It should be understood that broadcasting digital signature information requires additional bandwidth resources from the network device. Considering that the downlink resources of the network device are limited, synchronously broadcasting digital signature information will reduce the downlink coverage area of the network device, making it difficult for terminal devices at the edge of the coverage area to receive system messages, resulting in a decline in the communication quality of the terminal devices.
[0113] To address the aforementioned technical problems, embodiments of this application provide an information verification method and related apparatus to improve the communication quality of terminal devices.
[0114] The embodiments of this application enable terminal devices or network devices to perform integrity verification on system messages received by the terminal devices when entering a security protection mode. This helps network devices save downlink resources when broadcasting system messages, thereby improving the communication quality of the terminal devices and enhancing the user's service experience.
[0115] In the embodiments described below, the interaction between a terminal device and a network device is used as an example. It should be understood that the terminal device described above can be replaced by components configured in the terminal device (such as chips, chip systems, processors, etc.), or logical modules or software capable of implementing all or part of the functions of the terminal device; the network device described above can also be replaced by components configured in the network device (such as chips, chip systems, processors, etc.), or logical modules or software capable of implementing all or part of the functions of the network device.
[0116] Figure 4 is a flowchart illustrating an information verification method according to an embodiment of this application. Exemplarily, as shown in Figure 4, the information verification method may include steps S401 to S403.
[0117] S401, the network device sends at least one second system message to the terminal device.
[0118] As an example, a network device can send system messages via broadcast, where the broadcast system message includes at least one second system message, such as MIB, SIB1, or other system messages. In some implementations, the network device can also send system messages via in-path messages; however, this application does not limit the method by which the network device sends system messages.
[0119] It is understandable that when a network device sends at least one second system message to a terminal device, it means that the network device has at least one second system message pre-configured internally, and the network device can obtain at least one second system message from the pre-configured system messages. When a network device broadcasts multiple second system messages, these multiple second system messages can be understood as a set of second system messages.
[0120] In some implementations, the network device may record information indicating at least one second system message while sending at least one second system message for later use. In this embodiment, "record" means that the device stores or caches the relevant information locally.
[0121] S402, the terminal device receives at least one first system message.
[0122] In this step, the terminal device receives system messages broadcast by the network device. Considering that system messages may be tampered with or forged during transmission, the terminal device can acquire at least one first system message. If the terminal device acquires multiple first system messages, these multiple first system messages can be understood as a set of first system messages.
[0123] In some implementations, the terminal device may record information used to indicate at least one of the first system messages for later use.
[0124] S403, when entering a mode with security protection, the terminal device verifies at least one first system message, or the network device verifies at least one second system message.
[0125] It should be noted that in the system architecture shown in Figure 1, the RRC state can be used to describe the connection status between the terminal device and the network device. Among them, the RRC idle state (RRC_IDLE) is a sleep state of the terminal device. When the terminal device and the network device are in the RRC idle state, the terminal device is within the coverage area of the network device. At this time, the terminal device does not maintain an RRC connection with the network device, but the terminal device continuously detects paging messages from the core network in order to receive downlink data or signaling.
[0126] RRC connected state (RRC_CONNECTED) is the state after the terminal device and the network device establish an RRC connection. When the terminal device and the network device are in the RRC connected state, the terminal device can transmit data and receive network services.
[0127] RRC inactive state (RRC_INACTIVE) is a state between RRC idle state and RRC connected state. When the terminal device and the network device are in RRC inactive state, the terminal device retains some connection information with the network device, while also retaining the connection with the core network.
[0128] In this step, when the initial connection state between the terminal device and the network device is different, the timing at which the terminal device enters the security protection mode during the network access process will also be different.
[0129] In one example, if the initial connection state between the terminal device and the network device is in RRC idle state, the terminal device needs to establish a connection with the network device through random access, transitioning from RRC idle state to RRC connected state. While the terminal device and network device are in RRC connected state, the network device can send a security mode activation command to the terminal device. In security mode, communication between the terminal device and network device will use a security key, performing operations including data encryption and air interface integrity protection. All security processing between the terminal device and network device is performed at the PDCP layer. Therefore, when the terminal device and network device transition from RRC idle state to RRC connected state and activate security mode, it is equivalent to the terminal device and network device entering a mode with security protection; that is, a mode with security protection includes transitioning from RRC connected state to security mode.
[0130] In another example, when the initial connection state between the terminal device and the network device is in the RRC inactive state, the terminal device establishes a connection with the network device through random access, transitioning from the RRC idle state to the RRC connected state. As described above regarding the RRC inactive state, the terminal device in the RRC inactive state retains its connection to the core network, and its context information (such as security keys and identity identifiers) is preserved in both the network device and the core network. When the terminal device in the RRC inactive state initiates random access, it can activate the preserved security context to enhance the security of subsequent communication. Therefore, when the terminal device in the RRC inactive state initiates random access, it is equivalent to the terminal device and the network device entering a mode with security protection; that is, a mode with security protection includes the process of random access implemented in the RRC inactive state.
[0131] Understandably, the terminal device obtains initial access information by receiving at least one first system message, thereby correctly accessing and operating the network. In this step, whether the terminal device sends at least one first system message or the network device sends at least one second system message, the essence is to verify whether the at least one first system message and the at least one second system message are the same system message, thereby reducing the possibility of problems such as the system messages broadcast by the network device being tampered with or forged.
[0132] For example, when a terminal device verifies at least one first system message, it may send information indicating at least one first system message to a network device. The network device verifies whether the at least one first system message received by the terminal device and the at least one second system message sent by the network device are the same based on the recorded information indicating at least one second system message and the information indicating at least one first system message.
[0133] Alternatively, the network device sends information to the terminal device to indicate at least one second system message, and the terminal device verifies whether the at least one first system message and the at least one second system message are the same based on the recorded information indicating at least one first system message and the information indicating at least one second system message.
[0134] Similarly, when a network device verifies at least one second system message, it can send information indicating at least one second system message to a terminal device. The terminal device then verifies whether the at least one first system message received by the terminal device is the same as the at least one second system message sent by the network device, based on the recorded information indicating at least one first system message and the recorded information indicating at least one second system message. Alternatively, the terminal device sends information indicating at least one first system message to the network device, and the network device verifies whether the at least one first system message and the at least one second system message are the same, based on the recorded information indicating at least one second system message and the recorded information indicating at least one first system message.
[0135] Understandably, if at least one first system message and at least one second system message are identical, the verification passes, indicating that the system message broadcast by the network device has not been tampered with or forged. Otherwise, the system message broadcast by the network device may have been tampered with or forged, and if a terminal device accesses the network based on this system message, it may affect network security, leading the network device to release the connection with the terminal device.
[0136] In this embodiment, by verifying whether at least one second system message sent by the network device and at least one first system message sent by the terminal device are the same when entering a security protection mode, security verification can be achieved while saving bandwidth resources of the network device, which is beneficial to improving the communication quality of the terminal device and enhancing the user experience.
[0137] As can be seen from the embodiment shown in Figure 4, the initial connection state between the terminal device and the network device is different, and the timing when the terminal device enters the security protection mode during the network access process is also different. The information verification method provided in this application embodiment will be further explained below in conjunction with the specific RRC state.
[0138] Figure 5 is a flowchart illustrating an information verification method provided in another embodiment of this application. As an example, the initial connection state between the terminal device and the network device in Figure 5 is the RRC idle state. As shown in Figure 5, the information verification method may include steps S501 to 503.
[0139] S501, the network device sends at least one second system message to the terminal device.
[0140] This step is consistent with step S401 in the embodiment shown in Figure 4.
[0141] It is understandable that when a network device sends at least one second system message to a terminal device, it means that the network device has at least one second system message pre-configured internally, and the network device can obtain at least one second system message. In some implementations, such as optional step S501-1, the network device can record fifth information while sending at least one second system message. The fifth information is used to indicate the above at least one second system message.
[0142] As one possible implementation, the fifth piece of information may include at least one second system message or verification information of at least one second system message. For example, the verification information of at least one second system message may be the hash value of at least one second system message or the cyclic redundancy check (CRC) value of at least one second system message.
[0143] For example, a network device takes at least one second system message as the input parameter of a hash function. The hash algorithm can transform the at least one second system message into a fixed-length output, which is the hash value of the at least one second system message.
[0144] It should be noted that when a network device sends multiple second system messages, the fifth information may include the verification information of multiple second system messages. When the verification information is a hash value, the hash value of multiple second system messages can be understood as the hash value of each second system message in the multiple second system messages. The above multiple hash values can be arranged in a certain order to form a hash value sequence.
[0145] S502, the terminal device receives at least one first system message.
[0146] This step is consistent with step S402 in the embodiment shown in Figure 4.
[0147] In some implementations, such as optional step S502-1, the terminal device may record first information, which is used to indicate at least one of the above first system messages. As one possible implementation, the first information may include at least one of the above first system messages or verification information of at least one first system message.
[0148] For example, the verification information of at least one first system message can be the hash value or CRC value of at least one first system message. Specifically, the terminal device uses at least one first system message as input parameters to a hash function, and a hash algorithm can convert it into the hash value of at least one first system message.
[0149] As can be seen from the above, when a terminal device receives multiple first system messages, the first information may include the verification information of multiple first system messages. When the verification information is a hash value, the hash value of multiple first system messages can be understood as the hash value of each first system message in the multiple first system messages. The above multiple hash values can be arranged in a certain order to form a hash value sequence.
[0150] It should be understood that when a terminal device needs to record at least one first system message, the terminal device can agree through a protocol to record information indicating at least one first system message. As one possible implementation, as shown in optional step S500, the terminal device can receive fourth information, which is used to indicate the recording of at least one first system message. Step S500 can be performed before step S501 or before step S502. The terminal device begins recording at least one first system message after receiving the fourth information; this embodiment does not limit this.
[0151] The fourth piece of information can be sent as a separate indication from the network device to the terminal device. In some implementations, the fourth piece of information can also be carried in a system message. For example, when broadcasting a system message, the network device can carry the above-mentioned fourth piece of information in the system message, and use the system message to indicate the recording of at least one first system message.
[0152] As another possible implementation, when the fourth information is carried in a non-access stratum (NAS) message, the access and mobility management function (AMF) network element in the core network can send the NAS message to the terminal device, and the NAS message can be used to indicate the recording of at least one first system message.
[0153] It should be noted that, compared to the real-time verification method for synchronous broadcast system messages and their digital signature information, the information verification method proposed in this application embodiment verifies at least one first system message after entering a security protection mode, which is equivalent to a post-verification method. Verifying system messages received by the terminal device through post-verification is predicated on the terminal device supporting post-verification, and this step requires the network device or core network to know that the terminal device supports the aforementioned post-verification method.
[0154] In some implementations, the terminal device can also send capability information to the AMF network element. The capability information is used to indicate that the terminal device supports the post-verification method. When the AMF network element learns that the terminal device supports the post-verification method, it instructs the terminal device to record at least one first system message through the aforementioned NAS message.
[0155] S503, when entering a security protection mode, the terminal device verifies at least one first system message, or the network device verifies at least one second system message.
[0156] As described above, when the initial connection state between the terminal device and the network device is in RRC idle state, the terminal device establishes a connection with the network device through random access, transitioning from RRC idle state to RRC connected state. After the network device initiates secure mode, it is equivalent to the terminal device and network device entering a mode with security protection.
[0157] In some implementations, such as optional step S503-1, in a secure mode, the network device sends second information to the terminal device, the second information indicating at least one second system message. Accordingly, the terminal device receives the second information from the network device.
[0158] It should be noted that the network device may record fifth information used to indicate at least one second system message. In some implementations, if the fifth information includes at least one second system message, then the second information includes at least one second system message or digital signature information of at least one second system message. Alternatively, if the fifth information includes verification information of at least one fifth system message, then the second information includes verification information of at least one second system message or digital signature information of verification information of at least one second system message.
[0159] It is understandable that when a network device records the fifth piece of information, the network device obtains the second piece of information based on the locally stored fifth piece of information. Therefore, the content of the second piece of information can be the same as the content of the fifth piece of information, or the content of the second piece of information can be digital signature information obtained by encrypting the content of the fifth piece of information. For example, in secure mode, the second piece of information can be carried in an RRC reconfiguration message.
[0160] When performing step S503-1, as shown in optional step S503-2, the terminal device verifies at least one first system message based on first information and second information. The first information indicates at least one first system message, and the second information indicates at least one second system message. The terminal device verifies at least one first system message based on these two pieces of information, which essentially involves verifying whether at least one first system message and at least one second system message are the same based on their indicated content.
[0161] In some implementations, the first information includes at least one first system message, and the second information includes at least one second system message or digital signature information of at least one second system message. Alternatively, the first information includes verification information of at least one first system message, and the second information includes verification information of at least one second system message or digital signature information of verification information of at least one second system message.
[0162] When the content of the first information matches the content of the second information, the terminal device can perform verification based on the content of the first information and the content of the second information. For example, if the first information includes at least one first system message, and the second information includes at least one second system message, then both pieces of information include system messages, and the terminal device can directly compare whether the at least one first system message and the at least one second system message are the same. Alternatively, if the second information includes digital signature information of at least one second system message, the terminal device can decrypt it, compare the decrypted at least one system message with at least one first system message, and if they are the same, it can be determined that at least one first system message and at least one second system message are the same.
[0163] Similarly, if the first information includes the hash value of at least one first system message, and the second information includes the hash value of at least one second system message, and both pieces of information include hash values, the terminal device can directly compare whether the hash values in the first and second information are the same. If they are the same, the terminal device can determine that at least one first system message and at least one second system message are the same. Alternatively, if the second information includes digital signature information containing the hash value of at least one second system message, the terminal device can compare the decrypted hash value of at least one second system message with the hash value of at least one first system message. If they are the same, then it is determined that at least one first system message and at least one second system message are the same.
[0164] It should be noted that when the second information includes digital signature information of at least one second system message or digital signature information of verification information of at least one second system message, the number of such digital signature information can be one or more. For example, at least one second system message can correspond to one or more digital signature information. The presence of multiple digital signature information does not affect the terminal device's ability to verify whether the at least one first system message and at least one second system message are the same. Therefore, this application embodiment does not limit the number of digital signature information.
[0165] It is understandable that when the terminal device verifies at least one first system message, if at least one first system message is the same as at least one second system message, the verification is considered successful, and the existing connection between the network device and the terminal device is maintained. In some implementations, if at least one first system message differs from at least one second system message, i.e., the verification fails, as shown in optional step S504-1, the terminal device can send a request message to the network device to request the release of the RRC connection. Accordingly, the network device receives the request message from the terminal device.
[0166] When performing step S504-1, as shown in optional step S504-2, the network device sends an RRC release (RRCRelease) message to the terminal device. Accordingly, the terminal device receives the RRC release message from the network device, releasing the RRC connection with the network device. As a possible implementation, the above RRC release message may also include a "cause" field, which indicates the reason for releasing the RRC connection.
[0167] In some implementations, the terminal device can re-establish the connection after determining that the verification has failed and releasing the RRC connection. This application will not elaborate on this aspect in the embodiments.
[0168] It is understandable that when performing optional steps S503-1 and S503-2 above, it is equivalent to verifying whether at least one first system message and at least one second system message are the same on the terminal device side in a secure mode. In this step, the verification of whether at least one first system message and at least one second system message are the same can also be performed on the network device side.
[0169] As one possible implementation, as shown in optional step S503-3 of Figure 6, in the secure mode, the terminal device sends third information to the network device, the third information indicating at least one first system message. Accordingly, the network device receives the third information from the terminal device.
[0170] In some implementations, the first information includes at least one first system message, and the third information includes at least one first system message or digital signature information of at least one first system message. Alternatively, the first information includes verification information of at least one first system message, and the third information includes verification information of at least one first system message or digital signature information of verification information of at least one first system message.
[0171] Referring to the aforementioned relationship between the fifth and second pieces of information, when the terminal device records the first information, the network device obtains the third information based on the local first information. Therefore, the content included in the third information can be the same as the content included in the first information, or the content included in the third information can be digital signature information obtained by encrypting the content included in the first information. For example, in secure mode, the third information can be carried in the RRC Reconfiguration Complete message.
[0172] When performing step S503-3, as shown in optional step S503-4 in Figure 6, the network device verifies at least one second system message based on the third information and the fifth information. The third information indicates at least one first system message, and the fifth information indicates at least one second system message. The network device verifies at least one second system message based on these two pieces of information, which essentially involves verifying whether at least one first system message and at least one second system message are identical based on their indicated content.
[0173] In some implementations, the fifth information includes at least one second system message, and the third information includes at least one first system message or digital signature information of at least one first system message. Alternatively, the fifth information includes verification information of at least one second system message, and the third information includes verification information of at least one first system message or digital signature information of verification information of at least one first system message.
[0174] Referring to the aforementioned verification of at least one first system message by the terminal device, when the content included in the third information matches the content included in the fifth information, the network device can perform verification based on the content included in the third information and the content included in the fifth information. For example, if the third information includes at least one first system message and the fifth information includes at least one second system message, then both of these pieces of information include system messages, and the terminal device can directly compare whether the at least one first system message and the at least one second system message are the same. Alternatively, if the third information includes the digital signature information of at least one first system message, the terminal device can decrypt it, compare the decrypted at least one system message with at least one first system message, and if they are the same, it can be determined that at least one first system message and at least one second system message are the same.
[0175] Similarly, network devices can directly compare the hash values included in the third and fifth information, or compare the decrypted hash value in the fifth information with the hash value included in the third information, to verify whether at least one first system message is the same as at least one second system message. This will not be elaborated further here.
[0176] Referring to the aforementioned terminal device side verifying at least one first system message, if the third information includes digital signature information of at least one first system message or digital signature information of verification information of at least one first system message, the number of the above digital signature information can be one or more. The embodiments of this application do not limit the number of digital signature information.
[0177] In some implementations, if the verification fails, as shown in optional step S504-2 of Figure 6, the network device can directly send an RRC release message to the terminal device. Accordingly, the terminal device receives the RRC release message from the network device and releases the RRC connection with the network device. The RRC release message may also include a "cause" field, which indicates the reason for releasing the RRC connection.
[0178] Figure 7 is a flowchart illustrating an information verification method provided in another embodiment of this application. As an example, the initial connection state between the terminal device and the network device in Figure 7 is the RRC inactive state. As shown in Figure 7, the information verification method may include steps S701 to S703.
[0179] [Correction 04.02.2026 according to Rule 91] S701, the network device sends at least one second system message to the terminal device.
[0180] This step is consistent with step S501 in the embodiment shown in Figure 5.
[0181] In some implementations, such as optional step S701-1, the network device records fifth information while sending at least one second system message. This fifth information is used to indicate the presence or absence of the aforementioned second system messages. For example, referring to the foregoing embodiments, the fifth information may include at least one second system message or verification information of at least one second system message, which will not be elaborated further here.
[0182] S702, the terminal device receives at least one first system message.
[0183] This step is consistent with step S502 in the embodiment shown in Figure 5.
[0184] In some implementations, such as optional step S702-1, the terminal device may record first information, which is used to indicate at least one of the above first system messages. As an example, the content of the first information can be referred to the foregoing embodiments, and will not be repeated here.
[0185] When a terminal device needs to record at least one first system message, the terminal device can agree through a protocol to record information indicating at least one first system message. In one possible implementation, as shown in optional step S700, the network device can send sixth information to the terminal device, the sixth information being used to indicate the recording of at least one first system message. Step S700 can occur before step S701 or before step S702. The terminal device begins recording at least one first system message after receiving the sixth information; this embodiment does not limit this.
[0186] It is understood that the sixth piece of information can be sent as a separate indication by the network device to the terminal device. In some implementations, the sixth piece of information can also be carried in a system message or an RRC release message. As an example, when the connection state between the terminal device and the network device is in an RRC inactive state, the network device can carry the sixth piece of information in the RRC release message. Exemplarily, the network device can also use the RRC release message to indicate support for the information verification method provided in the embodiments of this application within the RNA-based notification area (RNA) or the RNA-supported cell range.
[0187] As one possible implementation, the terminal device can also receive NAS messages from AMF network elements, which carry fourth information to indicate that at least one first system message is recorded.
[0188] S703, when entering a security protection mode, the terminal device verifies at least one first system message, or the network device verifies at least one second system message.
[0189] As described above, when the initial connection state between the terminal device and the network device is in the RRC inactive state, the terminal device establishes a connection with the network device through random access. The process of achieving random access from the RRC inactive state is equivalent to entering a mode with security protection.
[0190] In some implementations, such as optional step S703-1, during the random access process implemented by the RRC inactive state, the network device may send message 4 (message4, Msg4) to the terminal device. Message 4 is used to indicate at least one second system message. Accordingly, the terminal device receives message 4 from the terminal device.
[0191] It is understandable that, corresponding to the fourth step in the four steps of the random access process for the terminal device, the network device sends message 4 to the terminal device, which is to send an RRC connection establishment success message.
[0192] When the network device records the fifth information, the network device sends message 4 based on the content included in the local fifth information. Therefore, the content included in message 4 can be the same as the content included in the fifth information, or the content included in message 4 can be the digital signature information obtained by encrypting the content included in the fifth information.
[0193] In some implementations, the fifth information includes at least one second system message, and message 4 includes at least one second system message or digital signature information of at least one second system message; or, the fifth information includes verification information of at least one second system message, and message 4 includes verification information of at least one second system message or digital signature information of verification information of at least one second system message.
[0194] When performing step S703-1, as shown in optional step S703-2, the terminal device verifies at least one first system message based on the first information and the aforementioned message 4. Here, the first information indicates at least one first system message, and message 4 indicates at least one second system message. The terminal device's verification of at least one first system message based on the first information and message 4 essentially verifies whether at least one first system message and at least one second system message are identical based on their indicated content.
[0195] In some implementations, the first information includes at least one first system message, and message 4 includes at least one second system message or digital signature information of at least one second system message; or, the first information includes verification information of at least one first system message, and message 4 includes verification information of at least one second system message or digital signature information of verification information of at least one second system message.
[0196] Referring to the embodiment shown in Figure 5, when the content of the first information matches the content of message 4, the terminal device can perform verification based on the content of the first information and the content of message 4. For example, if the first information includes at least one first system message and message 4 includes at least one second system message, the terminal device can directly compare whether the at least one first system message and the at least one second system message are the same. Alternatively, if message 4 includes digital signature information of at least one second system message, the terminal device can decrypt it, compare the decrypted at least one system message with at least one first system message, and if they are the same, it can be determined that at least one first system message and at least one second system message are the same.
[0197] Similarly, if the first information includes the hash value of at least one first system message, the terminal device can perform verification based on the hash value of at least one second system message included in message 4 or the digital signature information of that hash value, which will not be elaborated here.
[0198] In the case where message 4 includes digital signature information of at least one second system message or digital signature information of verification information of at least one second system message, the number of such digital signature information can be one or more. This application embodiment does not limit the number of digital signature information.
[0199] In some implementations, when at least one first system message differs from at least one second system message, i.e., when the verification fails, as shown in optional step S704-1, the terminal device can send a request message to the network device to request the release of the RRC connection. Accordingly, the network device receives the request message from the terminal device.
[0200] When performing step S704-1, as shown in optional step S704-2, the network device sends an RRC release message to the terminal device. Accordingly, the terminal device receives the RRC release message from the network device and releases the RRC connection with the network device. As a possible implementation, the RRC release message may also include a "cause" field, which indicates the reason for releasing the RRC connection.
[0201] In some implementations, the terminal device can re-establish the connection after determining that the verification has failed and releasing the RRC connection. This application will not elaborate on this aspect in the embodiments.
[0202] Referring to the embodiment shown in Figure 5, when performing optional steps S703-1 and S703-2, it is equivalent to the terminal device verifying whether at least one first system message and at least one second system message are the same during the random access process in the RRC inactive state. Alternatively, this verification can also be performed on the network device side.
[0203] As one possible implementation, as shown in optional step S703-3 of Figure 8, during the random access process in the RRC inactive state, the terminal device sends message 5 (Msg5) to the network device. Message 5 is used to indicate at least one first system message. Accordingly, the network device receives message 5 from the terminal device.
[0204] It is understandable that, corresponding to the network device sending message 4 to the terminal device in the random access procedure, the terminal device sends message 5 to the network device, that is, sends the RRC connection establishment complete (RRCConnectionSetupComplete) message.
[0205] Referring to the connection between the second information and message 4, when the terminal device records the first information, the terminal device sends message 5 based on the content included in the local first information. Therefore, the content included in message 5 can be the same as the content included in the first information, or the content included in message 5 can be the digital signature information obtained by encrypting the content included in the first information.
[0206] For example, the first information includes at least one first system message, and message 5 includes at least one first system message or digital signature information of at least one first system message. Alternatively, the first information includes verification information of at least one first system message, and message 5 includes verification information of at least one first system message or digital signature information of verification information of at least one first system message.
[0207] When performing step S703-3, as shown in optional step S703-4 in Figure 8, the network device verifies at least one second system message based on the fifth information and message 5. Here, message 5 indicates at least one first system message, and the fifth information indicates at least one second system message. The network device verifies at least one second system message based on message 5 and the fifth information, which essentially involves verifying whether at least one first system message and at least one second system message are the same based on their indicated content.
[0208] In some implementations, the fifth information includes at least one second system message, and message 5 includes at least one first system message or digital signature information of at least one first system message. Alternatively, the fifth information includes verification information of at least one second system message, and message 5 includes verification information of at least one first system message or digital signature information of verification information of at least one first system message.
[0209] Referring to the foregoing embodiments, when the content of message 5 matches the content of the fifth information, the network device can perform verification based on the content of message 5 and the content of the fifth information. For example, if message 5 includes at least one first system message and the fifth information includes at least one second system message, the terminal device can directly compare whether the at least one first system message and the at least one second system message are the same. Alternatively, if message 5 includes digital signature information of at least one first system message, the terminal device can decrypt it, compare the decrypted at least one system message with the at least one first system message, and if they are the same, it can be determined that the at least one first system message and the at least one second system message are the same.
[0210] Similarly, if the fifth message includes the hash value of at least one second system message, the terminal device can perform verification based on the hash value of at least one first system message included in message 5 or the digital signature information of that hash value, which will not be elaborated here.
[0211] In the case where message 5 includes digital signature information of at least one first system message or digital signature information of verification information of at least one first system message, the number of the above digital signature information can be one or more. This application embodiment does not limit the number of digital signature information.
[0212] In some implementations, if the verification fails, as shown in optional step S704-2 of Figure 8, the network device can directly send an RRC release message to the terminal device. Accordingly, the terminal device receives the RRC release message from the network device and releases the RRC connection with the network device. The RRC release message may also include a "cause" field, which indicates the reason for releasing the RRC connection.
[0213] In the embodiments shown in Figures 5 to 8 above, a single RAN node is used as the network device for description. The information verification method provided in the embodiments of this application will be further described below using ORAN as the network device.
[0214] Figure 9 is a flowchart illustrating an information verification method according to an embodiment of this application. For example, the initial connection state between the terminal device and the network device in Figure 9 is the RRC idle state. As shown in Figure 9, the information verification method may include steps S901-903.
[0215] S901, O-DU sends at least one second system message to the terminal device.
[0216] In the foregoing embodiments, the network device sends at least one second system message to the terminal device. Taking ORAN as an example, the O-DU in ORAN sends at least one second system message to the terminal device.
[0217] In some implementations, such as optional step S901-1, the O-DU can record fifth information while sending at least one second system message. This fifth information indicates the presence or absence of the aforementioned second system message. Referring to the foregoing embodiments, the fifth information may include at least one second system message or verification information of at least one second system message. The verification information of the at least one second system message may be a hash value or CRC value of the at least one second system message, which will not be elaborated further here.
[0218] Accordingly, as shown in optional step S901-2, the O-DU sends the aforementioned fifth information to the O-CU, and the O-CU receives the fifth information from the O-DU. As an example, the O-CU-CP in the O-CU can receive the fifth information, and for the ORAN, the O-CU can obtain at least one second system message through the fifth information.
[0219] S902, the terminal device receives at least one first system message.
[0220] This step is consistent with step S502 in the embodiment shown in Figure 5.
[0221] Referring to the foregoing embodiments, in some implementations, such as optional step S902-1, the terminal device may record first information, which is used to indicate at least one first system message. Referring to the foregoing embodiments, the first information may include at least one first system message or verification information of at least one first system message, wherein the verification information of at least one first system message may be the hash value or CRC value of at least one first system message, which will not be elaborated here.
[0222] When a terminal device needs to record at least one first system message, the terminal device can agree through a protocol to record information indicating at least one first system message. In one possible implementation, as shown in optional step S900, the terminal device can receive fourth information, which is used to indicate the recording of at least one first system message. Step S900 can occur before step S901 or before step S902. The terminal device begins recording at least one first system message after receiving the fourth information; this embodiment does not limit this.
[0223] The fourth message can be sent directly from the O-CU to the terminal device as a separate instruction. Alternatively, the O-CU can send the fourth message to the O-DU, and the O-DU can forward the fourth message to the terminal device after receiving it.
[0224] In some implementations, the O-DU can also send fourth information to the terminal device. For example, the fourth information can be carried in a system message, and the O-DU sends the fourth information to the terminal device through the system message.
[0225] As another possible implementation, when the fourth information is carried in the NAS message, the AMF network element in the core network can send the NAS message to the terminal device, and the NAS message can be used to indicate the recording of at least one first system message.
[0226] S903, when entering a mode with security protection, the terminal device verifies at least one first system message, or the ORAN verifies at least one second system message.
[0227] In the embodiment shown in Figure 9, after the ORAN initiates the security mode, it is equivalent to the terminal device and the ORAN entering a mode with security protection.
[0228] In some implementations, as shown in optional step S903-1, in the secure mode, the O-CU in the ORAN sends second information to the terminal device, the second information indicating at least one second system message. Accordingly, the terminal device receives the second information from the O-CU.
[0229] As an example, referring to the foregoing embodiments, the fifth information includes at least one second system message, and the second information includes at least one second system message or digital signature information of at least one second system message. Alternatively, if the fifth information includes the hash value of at least one fifth system message, then the second information includes the hash value of at least one second system message or digital signature information of the hash value of at least one second system message.
[0230] When performing step S903-1, as shown in optional step S903-2, the terminal device verifies at least one first system message based on the first information and the second information. The specific verification method can be found in the embodiment shown in Figure 5, and will not be repeated here. If the verification fails, as shown in optional step S904-1, the terminal device can send a request message to the O-DU in the ORAN, which requests the release of the RRC connection. Accordingly, the O-DU receives the request message from the terminal device.
[0231] If step S904-1 is executed, as shown in optional step S904-2, the O-DU sends an RRC release message to the terminal device. Accordingly, the terminal device receives the RRC release message from the O-DU and releases the RRC connection with the ORAN. As a possible implementation, the above RRC release message may also include a "cause" field, which indicates the reason for releasing the RRC connection.
[0232] In some implementations, the terminal device can re-establish the connection after determining that the verification has failed and releasing the RRC connection. This application will not elaborate on this aspect in the embodiments.
[0233] When performing optional steps S903-1 and S903-2 above, it is equivalent to verifying whether at least one first system message and at least one second system message are the same on the terminal device side in a secure mode. Alternatively, this verification can also be performed on the ORAN side.
[0234] In some implementations, as shown in optional steps S903-3 of Figure 10, in the secure mode, the terminal device sends third information to the ORAN, the third information indicating at least one first system message. Accordingly, the ORAN receives the third information from the terminal device; exemplarily, the O-CU in the ORAN receives the third information from the terminal device.
[0235] Referring to the foregoing embodiments, the first information may include at least one first system message, and the third information may include at least one first system message or digital signature information of at least one first system message. Alternatively, the first information may include verification information of at least one first system message, and the third information may include verification information of at least one first system message or digital signature information of verification information of at least one first system message.
[0236] When performing step S903-3, as shown in optional step S903-4 in Figure 9, the O-CU verifies at least one second system message based on the third information and the fifth information. The specific verification method can be referred to the embodiment shown in Figure 6, which will not be repeated here.
[0237] If the verification fails, ORAN can directly send an RRC release message to the terminal device. As shown in optional step S904-2, the O-CU sends an RRC release message to the O-DU, and the O-DU forwards the RRC release message to the terminal device. Accordingly, the terminal device receives the RRC release message from ORAN and releases the RRC connection with ORAN. The RRC release message may also include a "cause" field, which indicates the reason for releasing the RRC connection.
[0238] Figure 11 is a flowchart illustrating an information verification method according to another embodiment of this application. For example, the initial connection state between the terminal device and the network device in Figure 11 is an RRC inactive state. As shown in Figure 11, the information verification method may include steps S1101 to S1103.
[0239] S1101, O-DU sends at least one second system message to the terminal device.
[0240] This step is consistent with step S901 in the embodiment shown in Figure 9.
[0241] In some implementations, referring to the embodiment shown in FIG9, as shown in optional step S1101-1, the O-DU may record fifth information while sending at least one second system message. The fifth information is used to indicate the above at least one second system message. Accordingly, as shown in optional step S1101-2, the O-DU sends the above fifth information to the O-CU, and the O-CU receives the fifth information from the O-DU.
[0242] S1102, the terminal device receives at least one first system message.
[0243] This step is consistent with step S902 in the embodiment shown in Figure 9.
[0244] Referring to the foregoing embodiments, in some implementations, such as optional step S1102-1, the terminal device may record first information, which is used to indicate at least one of the above first system messages.
[0245] When a terminal device needs to record at least one first system message, the terminal device can agree through a protocol to record information indicating at least one first system message. In one possible implementation, as shown in optional step S1100, the O-CU can send sixth information to the terminal device, which is used to indicate the recording of at least one first system message. Step S1100 can occur before step S1101 or before step S1102. The terminal device begins recording at least one first system message after receiving the sixth information; this embodiment does not limit this.
[0246] The sixth message can be sent as a separate instruction from the O-CU to the terminal device. Alternatively, the O-CU can send the sixth message to the O-DU, and the O-DU can forward the sixth message to the terminal device upon receiving it.
[0247] In some implementations, the sixth piece of information can also be carried in system messages or RRC release messages. As an example, when the connection state between the terminal device and the ORAN is in an RRC inactive state, the O-DU in the ORAN can carry the aforementioned sixth piece of information in the RRC release message. Exemplarily, the ORAN can also use the RRC release message to indicate support for the information verification method provided in the embodiments of this application within the RNA-based notification area (RNA) or the RNA-supported cell range.
[0248] As one possible implementation, the terminal device can also receive NAS messages from AMF network elements, which carry fourth information to indicate that at least one first system message is recorded.
[0249] S1103, when entering a security protection mode, the terminal device verifies at least one first system message, or the network device verifies at least one second system message.
[0250] In the embodiment shown in Figure 11, when the initial connection state between the terminal device and ORAN is in the RRC inactive state, the terminal device establishes a connection with ORAN through random access. The process of random access from the RRC inactive state is equivalent to entering a mode with security protection.
[0251] In some implementations, such as optional step S1103-1, during the random access process implemented by the RRC inactive state, the O-CU in the ORAN can send message 4 to the terminal device. Message 4 is used to indicate at least one second system message. Accordingly, the terminal device receives message 4 from the terminal device.
[0252] When performing step S1103-1, as shown in optional step S703-2, the terminal device verifies at least one first system message based on the first information and the above message 4. The specific verification method can be referred to the embodiment shown in Figure 7, which will not be repeated here.
[0253] In some implementations, if the verification fails, as shown in optional step S1104-1, the terminal device can send a request message to the O-DU in the ORAN, which requests the release of the RRC connection. Accordingly, the O-DU receives the request message from the terminal device.
[0254] If step S1104-1 is executed, as shown in optional step S1104-2, the O-DU sends an RRC release message to the terminal device. Accordingly, the terminal device receives the RRC release message from the O-DU and releases the RRC connection with the ORAN. As a possible implementation, the RRC release message may also include a "cause" field, which indicates the reason for releasing the RRC connection.
[0255] In some implementations, the terminal device can re-establish the connection after determining that the verification has failed and releasing the RRC connection. This application will not elaborate on this aspect in the embodiments.
[0256] When performing optional steps S1103-1 and S1103-2 above, it is equivalent to the terminal device verifying whether at least one first system message and at least one second system message are the same during the random access process in the RRC inactive state. Alternatively, this verification can also be performed on the ORAN side.
[0257] In some implementations, as shown in optional steps S1103-3 of Figure 12, during the random access process in the RRC inactive state, the terminal device sends message 5 to the O-CU in the ORAN. Message 5 indicates at least one first system message. Accordingly, the O-CU receives message 5 from the terminal device.
[0258] When performing step S1103-3, as shown in optional step S1103-4 in Figure 12, the O-CU verifies at least one second system message based on the fifth information and message 5. The specific verification method can be referred to the embodiment shown in Figure 8, which will not be repeated here.
[0259] In some implementations, if the verification fails, ORAN can directly send an RRC release message to the terminal device. As shown in optional step S1104-2, the O-CU sends an RRC release message to the O-DU, and the O-DU forwards the RRC release message to the terminal device. Accordingly, the terminal device receives the RRC release message from ORAN and releases the RRC connection with ORAN. The RRC release message may also include a "cause" field, which indicates the reason for releasing the RRC connection.
[0260] It should be noted that the information verification method provided in this application embodiment is equivalent to a post-verification method. This post-verification form is beneficial for security verification of system messages with low latency requirements. For example, if the first system message or the second system message includes system messages other than MIB, SIB1 to SIB5, the information verification method provided in this application embodiment is applicable.
[0261] Figures 13 and 14 are schematic diagrams of possible information verification devices provided in embodiments of this application. These information verification devices can be used to implement the functions of the terminal device or network device in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments. In the embodiments of this application, the information verification device can be the terminal device or network device in the method embodiments shown in Figures 4 to 12, or it can be a component (such as a chip, chip system, processor, etc.) configured in the terminal device or network device, or it can be a logic module or software capable of implementing some or all of the functions of the terminal device or network device.
[0262] Figure 13 is a schematic diagram of the structure of an information verification device provided in an embodiment of this application. As shown in Figure 13, the information verification device 1300 includes a processing module 1310 and a transceiver module 1320.
[0263] The transceiver module 1320 can implement corresponding communication functions and can also be referred to as an input / output interface or communication unit. The processing module 1310 can be used to perform processing operations. It should be understood that if the device 1300 is a component configured in a network device or terminal device, such as a chip, the transceiver module 1320 can be an input / output interface.
[0264] Optionally, the transceiver module 1320 may include a sending module and a receiving module. The sending module is used to perform the sending operations of the network device or terminal device in Figures 4 to 12, and the receiving module is used to perform the receiving operations of the network device or terminal device in Figures 4 to 12.
[0265] It should be understood that when the device 1300 is a component configured in a network device or terminal device, such as a chip, the transmitting module can be an output interface, and the transmitting operation involved in the embodiments of this application can be performed by the output interface; the receiving module can be an input interface, and the receiving operation involved in the embodiments of this application can be performed by the input interface.
[0266] Optionally, the device 1300 may further include a storage module for storing instructions and / or data, and the processing module 1310 may read the instructions and / or data from the storage module to enable the device to implement the method embodiments shown in Figures 4 to 12.
[0267] In one possible design, the device 1300 can be used to implement the functions of the terminal device in the method embodiments shown in Figures 4 to 12. Alternatively, the device 1300 can include a unit for implementing any function or operation of the terminal device in the method embodiments shown in Figures 4 to 12. This unit can be implemented wholly or partially by software, hardware, firmware, or any combination thereof.
[0268] When device 1300 is used to implement the functions of the terminal device in the method embodiments shown in Figures 4 to 12, transceiver module 1320 (specifically, a receiving module) can be used to execute step S501 in Figure 5 to receive at least one system information, and can also be used to execute step S503-1 in Figure 5 to receive second information from the network device, the second information being used to indicate at least one second system message; processing module 1310 can be used to execute step S503-2 in Figure 5 to verify at least one first system message according to the first information and the second information; transceiver module 1320 (specifically, a sending module) can also be used to execute step S503-3 in Figure 6 to send third information to the network device, the third information being used to indicate at least one first system message.
[0269] In another possible design, the device 1300 can be used to implement the functions of the network device in the method embodiments shown in Figures 4 to 12. Alternatively, the device 1300 can include a unit for implementing any function or operation of the network device in the method embodiments shown in Figures 4 to 12. This unit can be implemented in whole or in part by software, hardware, firmware, or any combination thereof.
[0270] [Correction 04.02.2026 based on Rule 91] When device 1300 is used to implement the function of the network device in the method embodiments shown in Figures 4 to 12, transceiver module 1320 (specifically, a sending module) can be used to execute step S501 in Figure 5 to send at least one second system message; processing module 1310 can be used to execute steps S503-4 in Figure 6 to verify at least one second system message according to third information and fifth information; transceiver module 1320 (specifically, a receiving module) can be used to execute step S503-3 in Figure 6 to receive third information from the terminal device, the third information being used to indicate at least one first system message.
[0271] A more detailed description of the above-mentioned processing module 1310 and transceiver module 1320 can be obtained directly from the relevant descriptions in the method embodiments shown in Figures 4 to 12, and will not be repeated here.
[0272] It should be noted that the transceiver module can also be called a transceiver unit, transceiver, transceiver machine, or transceiver device, etc. The processing module can also be called a processor, processing board, processing unit, or processing device, etc. Optionally, the transceiver module is used to perform the sending and receiving operations on the terminal device or network device side in the above method. The device in the communication module used to implement the receiving function can be considered as the receiving module, and the device in the communication module used to implement the sending function can be considered as the sending module; that is, the transceiver module includes both a receiving module and a sending module.
[0273] In another possible design, the aforementioned transceiver module and / or processing module can be implemented using virtual modules. For example, the processing module can be implemented using software functional modules or virtual devices, and the transceiver module can also be implemented using software functional modules or virtual devices. In another possible design, the processing module or transceiver module can also be implemented using physical devices. For example, if the device is implemented using a chip / chip circuit, the transceiver module can be an input / output circuit and / or a communication interface, performing input operations (corresponding to the aforementioned receiving operation) and output operations (corresponding to the aforementioned sending operation); the processing module is an integrated processor, microprocessor, or integrated circuit.
[0274] It should be understood that the module division in the embodiments of this application is illustrative and only represents a logical functional division. In actual implementation, there may be other division methods. Furthermore, the functional modules in the various embodiments of this application can be integrated into a single processor, exist as separate physical entities, or be integrated into a single module. The integrated modules described above can be implemented in hardware or as software functional modules.
[0275] Figure 14 is a schematic diagram of the structure of an information verification device provided in another embodiment of this application. The device 1400 shown in Figure 14 can be used to perform any of the methods described above that are executed by the information verification device.
[0276] As shown in Figure 14, the device 1400 of this embodiment includes: a memory 1401, a processor 1402, a communication interface 1403, and a bus 1404. The memory 1401, the processor 1402, and the communication interface 1403 are interconnected via the bus 1404.
[0277] The memory 1401 may be a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1401 may store a program, and when the program stored in the memory 1401 is executed by the processor 1402, the processor 1402 performs any of the aforementioned methods.
[0278] The processor 1402 may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit, or one or more integrated circuits for executing relevant programs.
[0279] The processor 1402 can also be an integrated circuit chip with signal processing capabilities. In implementation, the various related steps in the embodiments of this application can be completed by the integrated logic circuitry in the hardware of the processor 1402 or by software instructions.
[0280] The processor 1402 described above can also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor, etc.
[0281] The steps of the method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory 1401. Processor 1402 reads information from memory 1401 and, in conjunction with its hardware, completes the functions required by the units included in the device of this application.
[0282] The communication interface 1403 can use, but is not limited to, transceivers to enable communication between the device 1400 and other devices or apparatuses.
[0283] Bus 1404 may include a pathway for transmitting information between various components of device 1400 (e.g., memory 1401, processor 1402, communication interface 1403).
[0284] This application also provides a computer-readable storage medium storing computer instructions, which, when executed by a processor, implement the steps of the methods described above.
[0285] This application also provides a computer program product, including computer instructions that, when executed by a processor, implement the various steps in the methods described above.
[0286] This application also provides an information verification system, which includes the aforementioned terminal device and network device.
[0287] It should be noted that the modules or components shown in the above embodiments can be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more microprocessors, or one or more field-programmable gate arrays (FPGAs). Furthermore, when a module is implemented by a processing element calling program code, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor capable of calling program code, such as a controller. Additionally, these modules can be integrated together and implemented as a System-on-a-Chip (SoC).
[0288] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, software modules, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).
[0289] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the disclosure herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and intent of this application are indicated by the following claims.
[0290] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. An information verification method, characterized in that, The method includes: Receive at least one first system message; When entering a security-protected mode, the at least one first system message is verified.
2. The method according to claim 1, characterized in that, The method further includes: Record first information, which is used to indicate the at least one first system message.
3. The method according to claim 2, characterized in that, The security protection mode includes entering a secure mode from the Radio Resource Control (RRC) connection state; Wherein, the verification of at least one first system message when entering a security protection mode includes: In the security mode, a second message is received, which indicates at least one second system message; The at least one first system message is verified based on the first information and the second information.
4. The method according to claim 3, characterized in that, The first information includes at least one first system message, and the second information includes at least one second system message or the digital signature information of the at least one second system message; or, The first information includes verification information of the at least one first system message, and the second information includes verification information of the at least one second system message or digital signature information of the verification information of the at least one second system message.
5. The method according to claim 2, characterized in that, The security protection mode includes entering the security mode from the RRC connection state; Wherein, the verification of at least one first system message when entering a security protection mode includes: In the security mode, a third message is sent, which is used to indicate the at least one first system message.
6. The method according to claim 5, characterized in that, The first information includes at least one first system message, and the third information includes the at least one first system message or the digital signature information of the at least one first system message; or, The first information includes verification information of the at least one first system message, and the third information includes verification information of the at least one first system message or digital signature information of the verification information of the at least one first system message.
7. The method according to claim 2, characterized in that, The security-protected mode includes a process of random access implemented by RRC inactive state; Wherein, the verification of at least one first system message when entering a security protection mode includes: During the process of random access implemented by RRC inactive state, message 4 is received, which is used to indicate at least one second system message; The at least one first system message is verified based on the first information and the message 4.
8. The method according to claim 7, characterized in that, The first information includes at least one first system message, and message 4 includes at least one second system message or the digital signature information of at least one second system message; or, The first information includes verification information of at least one first system message, and message 4 includes verification information of at least one second system message or digital signature information of the verification information of at least one second system message.
9. The method according to claim 2, characterized in that, The security-protected mode includes a process of random access implemented by RRC inactive state; Wherein, the verification of at least one first system message when entering a security protection mode includes: During the process of random access achieved by the RRC inactive state, message 5 is sent, which is used to indicate at least one first system message.
10. The method according to claim 9, characterized in that, The first information includes at least one first system message, and message 5 includes the at least one first system message or the digital signature information of the at least one first system message; or, The first information includes verification information of the at least one first system message, and the message 5 includes the verification information of the at least one first system message or the digital signature information of the verification information of the at least one first system message.
11. The method according to any one of claims 1 to 10, characterized in that, The method further includes: Receive a fourth message, which is used to instruct the recording of the at least one first system message.
12. The method according to claim 11, characterized in that, The fourth information is carried in any of the following: system message, non-access stratum (NAS) message, or RRC release message.
13. An information verification method, characterized in that, The method includes: Obtain at least one second system message; When entering a security-protected mode, the at least one second system message is verified.
14. The method according to claim 13, characterized in that, The method further includes: Record a fifth piece of information, which is used to indicate the at least one second system message.
15. The method according to claim 14, characterized in that, The security protection mode includes entering the security mode from the RRC connection state; The step of verifying at least one second system message when entering a security-protected mode includes: In the security mode, a second message is sent, which is used to indicate the at least one second system message.
16. The method according to claim 15, characterized in that, The fifth piece of information includes at least one second system message, wherein the second information includes the at least one second system message or the digital signature information of the at least one second system message; or... The fifth information includes verification information of the at least one fifth system message, and the second information includes verification information of the at least one second system message or digital signature information of the verification information of the at least one second system message.
17. The method according to claim 14, characterized in that, The security protection mode includes entering the security mode from the RRC connection state; Wherein, the verification of the at least one second system message when entering a security protection mode includes: In the security mode, a third message is received, which is used to indicate the at least one first system message; The at least one second system message is verified based on the third and fifth information.
18. The method according to claim 17, characterized in that, The fifth information includes the at least one second system message, and the third information includes the at least one first system message or the digital signature information of the at least one first system message; or... The fifth information includes verification information of the at least one second system message, and the third information includes verification information of the at least one first system message or digital signature information of the verification information of the at least one first system message.
19. The method according to claim 14, characterized in that, The security-protected mode includes a process of random access implemented by RRC inactive state; Wherein, the verification of the at least one second system message when entering a security protection mode includes: During the process of random access achieved by RRC inactive state, message 4 is sent, which is used to indicate the at least one second system message.
20. The method according to claim 19, characterized in that, The fifth piece of information includes at least one second system message, and message 4 includes the at least one second system message or the digital signature information of the at least one second system message; or... The fifth information includes verification information of the at least one second system message, and message 4 includes verification information of the at least one second system message or digital signature information of the verification information of the at least one second system message.
21. The method according to claim 14, characterized in that, The security-protected mode includes a process of random access implemented by RRC inactive state; Wherein, the verification of the at least one second system message when entering a security protection mode includes: During the process of random access implemented by RRC inactive state, message 5 is received, which is used to indicate at least one first system message.
22. The method according to claim 21, characterized in that, The fifth piece of information includes at least one second system message, wherein message 5 includes at least one first system message or the digital signature information of at least one first system message; or... The fifth information includes verification information of at least one second system message, and message 5 includes verification information of at least one first system message or digital signature information of the verification information of at least one first system message.
23. The method according to any one of claims 13 to 22, characterized in that, The method further includes: Send a sixth message, which is used to instruct the recording of at least one first system message.
24. The method according to claim 23, characterized in that, The sixth piece of information is carried in a system message or an RRC release message.
25. An information verification device, characterized in that, The information verification device includes a module for implementing the information verification method as described in any one of claims 1 to 12, or includes a module for implementing the information verification method as described in any one of claims 13 to 24.
26. An information verification device, characterized in that, include: Processor and memory; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the information verification device to perform the information verification method as claimed in any one of claims 1 to 12, or any one of claims 13 to 24.
27. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the information verification method as claimed in any one of claims 1 to 12, or any one of claims 13 to 24.
28. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the information verification method as claimed in any one of claims 1 to 12, or any one of claims 13 to 24.