Wireless communication methods and communication devices
By introducing MAC PDU identifiers at the MAC layer and using the encryption and integrity protection algorithms of the PDCP layer, the problem that the traditional PDCP layer cannot protect MAC CE is solved, and encryption and integrity protection of MAC SDU and MAC CE are achieved, thereby improving communication security.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2026-03-26
AI Technical Summary
Traditional security protection mechanisms at the PDCP layer cannot effectively protect MAC CE, leading to security risks and user privacy leaks during communication. This is especially true when the capabilities of devices such as AIoT are limited, making it impossible to effectively encrypt and protect the integrity of MAC SDU and MAC CE.
A MAC PDU identifier is introduced at the MAC layer to encrypt and/or protect the integrity of MAC sub-PDUs within the MAC PDU. By introducing the MAC PDU identifier, the encryption and integrity protection algorithms of the PDCP layer are used to protect the MAC sub-PDUs.
It reduces the possibility of user privacy leaks and improves the security of communication processes, especially in situations where the capabilities of devices such as AIoT are limited, ensuring the security of MAC SDU and MAC CE.
Smart Images

Figure CN2024120387_26032026_PF_FP_ABST
Abstract
Description
Method and communication device for wireless communication TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, and more particularly, to a method and a communication device for wireless communication. BACKGROUND
[0002] A conventional security protection mechanism is to encrypt and / or integrity protect user plane data packets and control plane data packets of a packet data convergence protocol (PDCP) layer respectively based on a core network derived key and other related parameters at the PDCP layer. However, this security protection mechanism performed at the PDCP layer has certain limitations and may cause security risks.
[0003] SUMMARY
[0004] The present application provides a method and a communication device for wireless communication. Each aspect of the present application is described below.
[0005] In a first aspect, a method for wireless communication is provided, comprising: sending, by a first device, a medium access control (MAC) protocol data unit (PDU) to a second device, the MAC PDU carrying a MAC PDU identifier, the MAC PDU identifier being used for encryption and / or integrity protection of MAC sub-PDUs in the MAC PDU at a MAC layer.
[0006] In a second aspect, a method for wireless communication is provided, comprising: receiving, by a second device, a MAC PDU sent by a first device, the MAC PDU carrying a MAC PDU identifier, the MAC PDU identifier being used for encryption and / or integrity protection of MAC sub-PDUs in the MAC PDU at a MAC layer.
[0007] In a third aspect, a communication device is provided, the communication device being a first device, comprising: a sending unit configured to send a MAC PDU to a second device, the MAC PDU carrying a MAC PDU identifier, the MAC PDU identifier being used for encryption and / or integrity protection of MAC sub-PDUs in the MAC PDU at a MAC layer.
[0008] In a fourth aspect, a communication device is provided, the communication device being a second device, comprising: a receiving unit configured to receive a MAC PDU sent by a first device, the MAC PDU carrying a MAC PDU identifier, the MAC PDU identifier being used for encryption and / or integrity protection of MAC sub-PDUs in the MAC PDU at a MAC layer.
[0009] In a fifth aspect, a communication device is provided, which includes a processor, a memory, and a communication interface. The memory is configured to store one or more computer programs. The processor is configured to invoke the computer programs in the memory, so that the communication device performs some or all of the steps in the methods of the various aspects described above.
[0010] In a sixth aspect, a communication system is provided, which includes the first device and / or the second device described above. In another possible design, the system can further include other devices interacting with the first device or the second device in the solutions provided by the embodiments.
[0011] In a seventh aspect, a computer-readable storage medium is provided, which stores a computer program. The computer program causes a communication device to perform some or all of the steps in the methods of the various aspects described above.
[0012] In an eighth aspect, a computer program product is provided, which includes a non-transitory computer-readable storage medium storing a computer program. The computer program is operable to cause a communication device to perform some or all of the steps in the methods of the various aspects described above. In some implementations, the computer program product can be a software installation package.
[0013] In a ninth aspect, a chip is provided, which includes a memory and a processor. The processor can invoke and run a computer program from the memory, to implement some or all of the steps described in the methods of the various aspects described above.
[0014] In the embodiments of the present application, a MAC PDU identifier can be introduced to implement the encryption and / or integrity protection process for MAC sub-PDUs at the MAC layer. Compared with the conventional scheme, which can only encrypt and integrity protect at the PDCP layer, the encryption and / or integrity protection for MAC sub-PDUs can be implemented, and the possibility of user privacy leakage can be reduced. BRIEF DESCRIPTION OF DRAWINGS
[0015] FIG. 1 is a wireless communication system 100 to which the embodiments of the present application are applied.
[0016] FIG. 2 is a schematic diagram of integrity protection and encryption for PDCP PDUs at the PDCP layer.
[0017] FIG. 3 is a schematic flowchart of an integrity protection process at the PDCP layer.
[0018] FIG. 4 is a schematic flowchart of an encryption operation process at the PDCP layer.
[0019] FIG. 5A and FIG. 5B are schematic diagrams of a format of a MAC PDU, to which embodiments of the present application are applicable.
[0020] FIG. 6A and FIG. 6B are schematic diagrams of a MAC subheader, to which embodiments of the present application are applicable.
[0021] FIG. 7 is a schematic flowchart of a method of wireless communication according to an embodiment of the present application.
[0022] FIG. 8 is a schematic diagram of a MAC PDU carrying a MAC PDU identifier according to an embodiment of the present application.
[0023] FIG. 9 is a schematic diagram of a MAC PDU carrying a MAC PDU identifier according to another embodiment of the present application.
[0024] FIG. 10A and FIG. 10B are schematic diagrams of a MAC PDU carrying indication information according to an embodiment of the present application.
[0025] FIG. 11 is a schematic diagram of integrity protection and ciphering of a MAC subPDU at a MAC layer according to an embodiment of the present application.
[0026] FIG. 12 is a schematic diagram of integrity protection according to an embodiment of the present application.
[0027] FIG. 13 is a schematic diagram of a MAC PDU after integrity protection according to an embodiment of the present application.
[0028] FIG. 14 is a schematic diagram of integrity protection according to an embodiment of the present application.
[0029] FIG. 15 is a schematic diagram of a MAC PDU after integrity protection according to an embodiment of the present application.
[0030] FIG. 16 is a schematic diagram of integrity protection according to an embodiment of the present application.
[0031] FIG. 17 is a schematic diagram of a MAC PDU after integrity protection and ciphering according to an embodiment of the present application.
[0032] FIG. 18 is a schematic diagram of ciphering according to an embodiment of the present application.
[0033] FIG. 19 is a schematic diagram of integrity protection according to an embodiment of the present application.
[0034] FIG. 20 is a schematic diagram of a MAC PDU after integrity protection and ciphering according to an embodiment of the present application.
[0035] FIG. 21 is a schematic diagram of ciphering according to an embodiment of the present application.
[0036] FIG. 22 is a schematic diagram of a communication device according to an embodiment of the present application.
[0037] FIG. 23 is a schematic diagram of a communication device according to an embodiment of the present application.
[0038] FIG. 24 is a schematic structural diagram of a communication apparatus according to an embodiment of the present application. DETAILED DESCRIPTION
[0039] The technical solutions in the present application will be described below with reference to the accompanying drawings.
[0040] FIG. 1 is a wireless communication system 100 to which embodiments of the present application are applied. The wireless communication system 100 can include a network device 110 and a terminal device 120. The network device 110 can be a device that communicates with the terminal device 120. The network device 110 can provide communication coverage for a specific geographic area and can communicate with the terminal device 120 located in the coverage area.
[0041] FIG. 1 exemplarily shows one network device and two terminals. Optionally, the wireless communication system 100 can include multiple network devices and each network device can include other numbers of terminal devices within its coverage, which is not limited in the embodiments of the present application.
[0042] Optionally, the wireless communication system 100 can further include a network controller, a mobile management entity, and other network entities, which are not limited in the embodiments of the present application.
[0043] It should be understood that the technical solutions of the embodiments of the present application can be applied to various communication systems, such as a 5th generation (5G) system or new radio (NR), a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD), and the like. The technical solutions provided by the present application can also be applied to future communication systems, such as a 6th generation mobile communication system, a satellite communication system, and the like.
[0044] The terminal device in the embodiments of the present application can also be referred to as a user equipment (UE), an access terminal, a user unit, a user station, a mobile station, a mobile station (MS), a mobile terminal (MT), a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent or a user apparatus. The terminal device in the embodiments of the present application can refer to a device that provides voice and / or data connectivity for a user, and can be used to connect people, things and machines, for example, handheld devices with wireless connection functions, vehicle-mounted devices, etc. The terminal device in the embodiments of the present application can be a mobile phone, a tablet computer (Pad), a notebook computer, a palm computer, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. Optionally, the UE can be used to act as a base station. For example, the UE can act as a scheduling entity, which provides a sidelink signal between UEs in V2X or D2D, etc. For example, a cellular phone and a car communicate with each other using a sidelink signal. The cellular phone and the smart home device communicate with each other without relaying the communication signal through the base station.
[0045] The network device in the embodiments of the present application can be a device for communicating with a terminal device, which can also be referred to as an access network device or a radio access network device, such as a network device, which can be a base station. The network device in the embodiments of the present application can refer to a radio access network (RAN) node (or device) that accesses a terminal device to a wireless network. The base station can broadly cover various names in the following or be replaced by the following names, such as: Node B (NodeB), evolved Node B (eNB), next generation Node B (gNB), relay station, transmitting and receiving point (TRP), transmitting point (TP), master station MeNB, auxiliary station SeNB, multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The base station can be a macro base station, a micro base station, a relay node, a donor node or the like, or a combination thereof. The base station can also refer to a communication module, modem or chip for being arranged in the foregoing device or apparatus. The base station can also be a mobile switching center and a device that undertakes the function of a base station in device-to-device (D2D), vehicle-to-everything (V2X), machine-to-machine (M2M) communication, network side device in 6G network, device that undertakes the function of a base station in future communication system, etc. The base station can support networks of the same or different access technologies. The embodiments of the present application do not limit the specific technology and specific device form adopted by the network device.
[0046] The base station can be fixed or mobile. For example, a helicopter or a drone can be configured to act as a mobile base station, and one or more cells can move according to the location of the mobile base station. In other examples, a helicopter or a drone can be configured to act as a device that communicates with another base station.
[0047] In some deployments, the network device in the embodiments of the present application can refer to a CU or a DU, or the network device includes a CU and a DU. The gNB can also include an AAU.
[0048] The network device and the terminal device can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can also be deployed on water surface; and can also be deployed on airplanes, balloons and satellites in the air. The scenarios in which the network device and the terminal device are located are not limited in the embodiments of the present application.
[0049] It should be understood that all or part of the functions of the communication device in the present application can also be implemented by software functions running on hardware, or by virtualized functions instantiated on a platform (such as a cloud platform).
[0050] PDCP security mechanism
[0051] In some scenarios, the confidentiality / integrity protection of the user plane (UP) data and the RRC message between the terminal device and the network device (for example, 5G-RAN) can be provided by the PDCP protocol layer.
[0052] In some implementations, the PDCP layer encryption integrity protection mechanism can be understood as the PDCP layer being responsible for performing encryption and integrity protection operations. For a PDCP PDU, integrity protection can be performed first and then encryption. Generally, integrity protection and encryption are paired, and for the integrity protection process, the sending end first performs integrity protection calculation, and the receiving end performs corresponding integrity protection verification. For the encryption / decryption process, the sending end performs encryption processing, and the receiving end performs decryption processing.
[0053] FIG. 2 shows a schematic diagram of integrity protection and encryption of PDCP PDU at the PDCP layer. Referring to FIG. 2, the integrity protection is for the PDCP header and the PDCP data part (also referred to as the user plane data packet), and after the integrity protection of this part of content, a verification value (for example, a message authentication code for integrity (MAC-I)) is obtained for integrity verification at the receiving end. At present, integrity protection is applicable to PDCP data PDU (PDCP data PDU) of a signaling radio bearer (SRB), and whether it is applicable to PDCP data PDU transmitted in a data radio bearer (DRB) depends on whether the DRB is configured with an integrity protection function. In addition, integrity protection is not applicable to PDCP control PDU (PDCP control PDU).
[0054] FIG. 3 illustrates a flow of integrity protection of PDCP layer. Referring to FIG. 3, the transmitter can input the following parameters to the integrity protection algorithm: Key, COUNT, MESSAGE, DIRECTION, BEARER ID, and then the integrity protection algorithm can generate a MAC-I based on the above input parameters. Accordingly, the receiver uses the integrity protection algorithm to verify whether the integrity protection is successful based on the MAC-I.
[0055] For example, the integrity protection algorithm can use a 128-bit integrity algorithm for 5G (NIA) algorithm (e.g., Snow 3G, AES, ZUC), wherein the input of the NIA algorithm includes the following parameters: message “Message”, 128-bit key “Kupint / KRRCint” as KEY, 5-bit bearer identification “BEARER ID”, 1-bit transmission direction “DIRECTION”, 32-bit COUNT. Of course, in the embodiments of the present application, the integrity protection algorithm can use a 256-bit NIA.
[0056] In some implementations, the encryption operation is applied to the data part of the PDCP data PDU and the verification value (e.g., MAC-I) of the integrity protection, continuing to refer to FIG. 2. The encryption operation is not applied to the PDCP header and the service data adaptation protocol (SDAP) header in the data part of the PDCP. In addition, the encryption operation is also not applied to the PDCP control PDU.
[0057] FIG. 4 illustrates a flow of encryption operation of PDCP layer. Referring to FIG. 4, the transmitter can input the following parameters to the encryption algorithm: Key, COUNT, DIRECTION, BEARER ID and LENGTH to generate a key stream (also referred to as key stream block). Then, the generated key stream is operated with the encrypted text (also referred to as plain text block) to obtain the cipher text (also referred to as cipher text block). Accordingly, the receiver performs inverse operation to decrypt the cipher text.
[0058] For example, the encryption operation can employ a 128-bit encryption algorithm for 5G (NEA) (e.g., Snow 3G, AES, ZUC), wherein the input of the NEA algorithm includes the following parameters: a 128-bit key "Kupint / KRRCint" as KEY, a 5-bit bearer identifier "BEARER ID", a 1-bit direction "DIRECTION", a length LENGTH, and a 32-bit count value "COUNT". Of course, in the embodiments of the present application, the integrity protection algorithm can employ a 256-bit NEA.
[0059] Security principle
[0060] In some scenarios, the following security principles can be followed in the process of encryption / integrity protection at the PDCP layer: global uniqueness, flexible variability, and non-repeatability.
[0061] In some implementations, global uniqueness can mean that the same initialization vector (IV) should not be used when using the same encryption key, otherwise some or even all security will be lost, i.e., each generated key stream needs to be different from any other key stream generated using the same algorithm and the same key. Therefore, a unique input is needed to generate each key stream, which can include the following information: a message counter maintained by the PDCP entity, a unique ID of each radio bearer, and a direction bit (different for uplink and downlink).
[0062] In some implementations, the encryption algorithm / integrity protection algorithm can be collectively referred to as a security algorithm, and accordingly, flexible variability can mean that, except for the key, other parameters (e.g., COUNT, bearer identifier, etc.) of the input security algorithm can be filled into the IV (e.g., the IV is 128 bits in ZUK), and in addition, the length of the input security algorithm parameter can be flexibly variable.
[0063] In some implementations, non-repeatability can mean that a security operation (e.g., encryption operation / integrity protection operation) cannot be repeated, i.e., if the PDCP layer has performed a security operation on certain data, the MAC layer does not need to repeat the security operation on the data, and vice versa.
[0064] Format of MAC PDU
[0065] FIGS. 5A and 5B are schematic diagrams of the format of the MAC PDU applicable to the embodiments of the present application. The MAC PDU format shown in FIG. 5A is applicable to downlink transmission. The MAC PDU format shown in FIG. 5B is applicable to uplink transmission.
[0066] In FIG. 5A and FIG. 5B, a MAC PDU can include one or more MAC subPDUs. The MAC subPDUs can be classified into four types. In the first type of MAC subPDU, the MAC subPDU can only include a MAC subheader. In the second type of MAC subPDU, the MAC subPDU can include a MAC subheader and a MAC service data unit (SDU) corresponding to the MAC subheader. In the third type of MAC subPDU, the MAC subPDU can include a MAC subheader and a MAC control element (CE) corresponding to the MAC subheader. In the fourth type of MAC subPDU, the MAC subPDU can include a MAC subheader and padding information.
[0067] Continuing to refer to FIG. 5A and FIG. 5B, the MAC subPDUs carrying MAC CEs are usually adjacent in a MAC PDU. In the MAC PDU shown in FIG. 5A, the MAC subPDUs carrying MAC CEs are located before the MAC subPDUs carrying MAC SDUs. In addition, if the MAC PDU includes a MAC subPDU carrying padding information, the MAC subPDUs carrying MAC SDUs are located before the MAC subPDU carrying padding information. In the MAC PDU shown in FIG. 5B, the MAC subPDUs carrying MAC CEs are located after the MAC subPDUs carrying MAC SDUs. If the MAC PDU includes a MAC subPDU carrying padding information, the MAC subPDUs carrying MAC CEs are located before the MAC subPDU carrying padding information.
[0068] In some implementations, the format of a MAC subheader can be as follows. For a MAC subPDU including a MAC CE of a fixed size and a MAC subPDU including padding information, the corresponding MAC subheader can only include two indication fields: a reserved (denoted as “R”) field and a logical channel identification (LCID) field, as shown in FIG. 6A. For other types of MAC subPDUs (e.g., a MAC subPDU carrying a MAC CE of a variable size), the MAC subheader of the MAC subPDU can include an R field, an F field, an LCID field, and an L field, as shown in FIG. 6B. The value of the LCID in the LCID field can indicate different types of MAC CEs, that is, different types of MAC CEs can correspond to a specific LCID value. For example, the LCID value corresponding to a MAC CE for carrying a downlink timing advanced command (TAC) is 62.
[0069] MAC CE security threats
[0070] With the development of technology, various types of MAC CEs are introduced in communication systems. Related security researchers have found that there are more and more attacks on unprotected MAC CEs. In some scenarios, attackers can tamper with sensitive information delivered in MAC CEs, causing the communication process to fail. For example, attackers can tamper with the network coordination control (NCC) in lower-layer triggered mobility (LTM), which can cause handover failure. In other scenarios, attackers can steal non-sensitive information delivered in MAC CEs and further extract more information in combination with security algorithms, bringing security threats.
[0071] In some scenarios, MAC CEs that deliver sensitive information can be referred to as security-sensitive MAC CEs. Currently, security-sensitive MAC CEs can include downlink LTM MAC CEs, downlink TAC MAC CEs, downlink secondary cell (SCell) activation MAC CEs, downlink SCell deactivation MAC CEs, downlink transmission configuration indication (TCI) state indication MAC CEs, and the like. For downlink LTM MAC CEs, the cell information and / or NCC information carried in this type of MAC CE is security-sensitive information. For downlink TAC MAC CEs, the uplink timing advanced (TA) adjustment information carried in this type of MAC CE is security-sensitive information, and the location of the terminal device can be derived through this information. For downlink SCell activation / deactivation MAC CEs, the indication information of the SCell carried in this type of MAC CE is security-sensitive information, and by tampering with this information, the terminal device can generate additional power consumption. For downlink TCI state indication MAC CEs, the TCI state indication carried in this type of MAC CE is security-sensitive information, and by tampering with this information, the beam information corresponding to the data transmission and reception of the terminal device can be affected, affecting the data transmission and reception performance.
[0072] It should be noted that the above only lists some common MAC CEs that may have security risks, and the embodiments of the present application are not limited thereto. For uplink transmission, considering that some key information in future communication systems may be carried on the physical uplink control channel (PUCCH) or the radio resource control (RRC) and transmitted by uplink MAC CEs, such as carrying ACK / NACK in the PUCCH by MAC CEs, or reporting some user assistance information (UAI) in the RRC, etc., these designs will make the uplink MAC CEs also need some security protection mechanism, therefore, the encryption and / or integrity protection mechanism involved in the embodiments of the present application can also be applicable to such MAC CEs.
[0073] At present, several common security attacks include: TA attack, carrier aggregation attack, and channel status information reference signal (CSI-RS) attack. For the TA attack, the attacker can determine the distance from the terminal device to the network device according to the TA information in the MAC CE, to accurately locate the position of the terminal device. For the carrier aggregation attack, a malicious cell activates the MAC CE to force the terminal device to consume more energy (based on the CA energy consumption measurement, when an additional cell is activated, the average current of the terminal device increases by 79%). For the CSI-RS attack, the attacker can attack the MAC CE for indicating the activation or deactivation of the channel status information (CSI) report transmitted through the physical uplink control channel (PUCCH) to obtain the CSI{Bi, RSRP} in the PUCCH, causing the position of the terminal device to be exposed.
[0074] In addition, in some scenarios, such as ambient internet of things (AIoT), due to limited device capability, there can be no radio resource control (RRC), PDCP, radio link control (RLC), and other access stratum (AS) layers, i.e., the highest AS layer is the MAC layer, and AIoT data can be carried and transmitted at the MAC layer. In this case, the MAC layer data part (i.e., MAC SDU) needs to be secured.
[0075] As introduced above, the conventional security protection mechanism is to encrypt and / or integrity protect the user plane data packets and control plane data packets of the PDCP layer based on the core network derived key and other related parameters at the PDCP layer. However, this security protection mechanism executed at the PDCP layer has certain limitations and may cause security risks. For example, with the development of technology, multiple types of MAC CEs are introduced, and the security protection mechanism executed at the PDCP layer cannot protect the MAC subPDUs carrying the MAC CEs, which may lead to user privacy leakage. For another example, in some scenarios (such as AIoT), due to limited device capability, there can be no RRC, PDCP, RLC, and other AS layers, i.e., the highest AS layer is the MAC layer, and AIoT data can be carried and transmitted at the MAC layer. In this case, the security protection mechanism executed at the PDCP layer cannot be used to protect the MAC subPDUs carrying the MAC SDUs, which may lead to user privacy leakage.
[0076] Therefore, the applicant proposes to encrypt and / or integrity protect the MAC subPDUs in the MAC PDU at the MAC layer, wherein the MAC subPDUs can include the MAC subPDUs for carrying the MAC SDUs or the MAC subPDUs for carrying the MAC CEs, and the related introduction can be referred to FIGS. 5A and 5B shown above.
[0077] In some implementations, the security protection mechanism at the MAC layer can continue to use the encryption and / or integrity protection mechanism of the PDCP to achieve the encryption and / or integrity protection of the MAC subPDUs. As introduced above, the parameters required in the process of encryption and / or integrity protection at the PDCP layer include the COUNT value and the Bearer ID. However, these two parameters cannot be obtained at the MAC layer, resulting in the inability to continue to use the encryption and / or integrity protection algorithm of the PDCP at the MAC layer.
[0078] Therefore, the applicant proposes that in the encryption and / or integrity protection process for the MAC CE in the MAC PDU at the MAC layer, a MAC PDU identifier for identifying the MAC PDU can be introduced to help implement the encryption and / or integrity protection for the MAC CE and reduce the possibility of user privacy leakage. The MAC PDU identifier is used for the encryption and / or integrity protection of the MAC sub-PDU in the MAC PDU at the MAC layer. For example, the MAC PDU identifier is an input parameter of an algorithm for implementing the encryption and / or integrity protection. In other words, the MAC PDU identifier is an input parameter of an encryption algorithm and / or an integrity protection algorithm used for the encryption and / or integrity protection of the MAC sub-PDU in the MAC PDU at the MAC layer. The method for wireless communication of the embodiment of the present application is described below in conjunction with the schematic flowchart of the method shown in FIG. 7. The method shown in FIG. 7 includes step S710.
[0079] In step S710, the first device sends a MAC PDU to the second device, and the MAC PDU carries the MAC PDU identifier described above.
[0080] In some implementations, the first device can be a terminal device, and correspondingly, the second device can be a network device, that is, corresponding to the uplink transmission scenario. Alternatively, the first device can be a network device, and correspondingly, the second device can be a terminal device, that is, corresponding to the downlink transmission scenario. That is, the scheme of the embodiment of the present application can be applicable to the uplink transmission process and the downlink transmission process, and the difference between the two is that the arrangement manner of the MAC sub-PDU in the MAC PDU is different (for details, see the description above in conjunction with FIGS. 5A and 5B).
[0081] In some implementations, the MAC PDU identifier is used for the encryption and / or integrity protection of the MAC sub-PDU in the MAC PDU at the MAC layer, and the MAC sub-PDU in the MAC PDU can be all the MAC sub-PDU in the MAC PDU, which helps to simplify the complexity of the encryption and / or integrity protection of the MAC PDU. Of course, in the embodiment of the present application, the MAC sub-PDU in the MAC PDU can be part of the MAC sub-PDU in the MAC PDU. Hereinafter, the MAC sub-PDU in the MAC PDU is taken as an example of all the MAC sub-PDU in the MAC PDU.
[0082] In some implementations, the MAC CE carried by the MAC sub-PDU in the MAC PDU can be a security-sensitive MAC CE, for details, see the description above. Of course, in the embodiment of the present application, the MAC CE in the MAC PDU can also include other types of MAC CEs.
[0083] In some embodiments, the encryption and / or integrity protection cases in a MAC PDU can be divided into two cases. It is assumed that the MAC PDU contains N MAC subPDUs carrying MAC CEs or MAC SDUs, where N is a positive integer greater than or equal to 0.
[0084] Case 1: N = 0, that is, there is no MAC subPDU carrying MAC CEs or MAC SDUs in the MAC PDU, and all the MAC subPDUs in the MAC PDU are used to carry padding information. In this case, no encryption and / or integrity protection operation can be performed on the MAC subPDUs in the MAC PDU.
[0085] Case 2: N ≠ 0, that is, the MAC subPDUs in the MAC PDU carry MAC CEs or MAC SDUs. In this case, encryption and / or integrity protection operation can be performed on all the MAC subPDUs in the MAC PDU.
[0086] Hereinafter, the MAC PDU identifier in the embodiments of the present application is introduced. In some embodiments, the MAC PDU identifier is used to identify a MAC PDU. For example, the MAC PDU identifier is used to uniquely identify a MAC PDU. Therefore, the MAC PDU identifier is also referred to as a "global MAC PDU identifier (Global MAC PDU ID)".
[0087] In the embodiments of the present application, by introducing the MAC PDU identifier at the MAC layer, similar to the bearer identifier used by the PDCP layer encryption / integrity protection, it is helpful to continue using the encryption and / or integrity protection algorithm used by the PDCP layer at the MAC layer, so as to realize the encryption and / or integrity protection process for the MAC subPDU.
[0088] For example, the MAC PDU identifier can include one or more of the following: an index of the MAC PDU, a COUNT value corresponding to the MAC PDU. Therefore, the MAC PDU identifier (MAC PDU ID) is also referred to as the MAC PDU index (MAC PDU Index) or the COUNT value.
[0089] The MAC PDU identifier in the embodiments of the present application is introduced above, and hereinafter the bearer mode of the MAC PDU identifier in the embodiments of the present application is introduced. In some embodiments, the MAC PDU identifier is carried in a first field, and the first field is located before other fields in the MAC PDU, and the other fields are fields in the MAC PDU other than the first field, which is helpful for the receiving end to obtain the MAC PDU identifier as early as possible.
[0090] In some implementations, the first field can be located in a MAC PDU header of the MAC PDU.
[0091] For example, referring to FIG. 8, the MAC PDU includes a MAC PDU identifier and N MAC subPDUs: MAC subPDU 1, MAC subPDU 2, …, MAC subPDU N, where N is an integer greater than 1, and the N MAC subPDUs are all integrity protected and / or encrypted at the MAC layer. Accordingly, the first field carrying the MAC PDU identifier in the MAC PDU is earlier than the fields carrying the N MAC subPDUs.
[0092] In some other implementations, the MAC PDU identifier is carried in the first field, and the first field is located in a first MAC subheader of the MAC PDU, or in other words, the first field is located in a MAC subheader of a first MAC subPDU of the MAC PDU, where the first MAC subPDU can be understood as a MAC subPDU that is transmitted earliest among the MAC subPDUs included in the MAC PDU.
[0093] For example, referring to FIG. 9, the MAC PDU includes a MAC PDU identifier and N MAC subPDUs: MAC subPDU 1, MAC subPDU 2, …, MAC subPDU N, where N is an integer greater than 1, and the N MAC subPDUs are all integrity protected and / or encrypted at the MAC layer. Accordingly, the first field carrying the MAC PDU identifier in the MAC PDU can be located in a MAC subheader corresponding to the MAC subPDU 1.
[0094] As introduced above, the MAC PDU identifier can be carried in the MAC PDU and transmitted to the second device. However, for a MAC PDU that is not encrypted and / or integrity protected (for example, the case 1 introduced above), the MAC PDU of this type usually does not carry the MAC PDU identifier. Therefore, in order to facilitate the second device to distinguish between the two different MAC PDUs, the first device can send indication information to the second device to indicate whether the MAC PDU identifier is carried in the MAC PDU, or in other words, the indication information is used to indicate whether the MAC subPDUs in the MAC PDU are encrypted and / or integrity protected.
[0095] That is, the above method further includes: the first device sends indication information to the second device, and the indication information is used to indicate whether the MAC subPDUs in the MAC PDU are encrypted and / or integrity protected.
[0096] In some embodiments, the indication information can be carried in the MAC PDU. Of course, in the embodiments of the present application, the indication information can be sent separately before the MAC PDU. Taking the indication information carried in the MAC PDU as an example, in some embodiments, the indication information is carried in a second field, which is located before a field carrying the MAC PDU identifier in the MAC PDU.
[0097] For example, referring to FIG. 10A, the MAC PDU includes the indication information, the MAC PDU identifier, and N MAC subPDUs: MAC subPDU1, MAC subPDU2, …, MAC subPDU N, where N is an integer greater than 1, and the N MAC subPDUs are all integrity protected and / or ciphered at the MAC layer. Accordingly, the first field carrying the MAC PDU identifier is earlier than the fields carrying the N MAC subPDUs in the MAC PDU, and the second field is earlier than the first field in the MAC PDU.
[0098] In some other embodiments, the indication information can be carried in the first MAC subheader of the MAC PDU, or in other words, the second field is located in the MAC subheader of the first MAC subPDU of the MAC PDU, where the first MAC subPDU can be understood as the MAC subPDU transmitted earliest among the MAC subPDUs included in the MAC PDU.
[0099] For example, referring to FIG. 10B, the MAC PDU includes the indication information, the MAC PDU identifier, and N MAC subPDUs: MAC subPDU1, MAC subPDU2, …, MAC subPDU N, where N is an integer greater than 1, and the N MAC subPDUs are all integrity protected and / or ciphered at the MAC layer. Accordingly, the MAC PDU identifier and the indication information can be carried in the MAC subheader corresponding to the MAC subPDU1.
[0100] It should be noted that the above describes the carrying manners of the indication information and the MAC PDU identifier in the embodiments of the present application by taking FIG. 10A and FIG. 10B as examples. Of course, in the embodiments of the present application, the MAC PDU identifier can be carried in the MAC subheader as shown in FIG. 9, and the indication information can be carried in the field other than the MAC subheader as shown in FIG. 10A. Or, the MAC PDU identifier can be carried in the field other than the MAC subheader as shown in FIG. 8, and the indication information can be carried in the MAC subheader as shown in FIG. 10B.
[0101] In addition, it should be noted that, in the embodiments of the present application, the MAC PDU can not carry the indication information, at this time, if the second device receives the MAC PDU identifier in the MAC PDU, it can be determined that the MAC PDU is a MAC PDU that has been integrity protected and / or encrypted. That is, the function of the MAC PDU identifier can be used to replace the indication information, so as to reduce the overhead of transmitting the MAC PDU.
[0102] The MAC PDU identifier and the indication information in the embodiments of the present application are introduced above. The encryption and / or integrity protection of the MAC PDU in the embodiments of the present application are introduced below.
[0103] In some implementations, the integrity protection of the MAC sub-PDU in the MAC PDU includes the integrity protection of the MAC CE or the MAC SDU carried in the MAC sub-PDU, and the MAC sub-header corresponding to the MAC sub-PDU, as shown in FIG. 11. Of course, in the embodiments of the present application, the integrity protection of the MAC sub-PDU in the MAC PDU includes the integrity protection of the MAC CE or the MAC SDU carried in the MAC sub-PDU, the MAC PDU identifier, and the MAC sub-header corresponding to the MAC sub-PDU.
[0104] In some implementations, the MAC PDU includes a verification value for verifying the integrity of the MAC sub-PDU, and the encryption of the MAC sub-PDU in the MAC PDU can include the encryption of the MAC sub-PDU and the verification value, as shown in FIG. 11.
[0105] In the embodiments of the present application, according to the granularity of the encryption and / or integrity protection of the MAC PDU, there are various implementations, wherein the granularity of the encryption and / or integrity protection of the MAC PDU includes performing separately for the MAC sub-PDU, and performing for multiple MAC sub-PDUs as a whole.
[0106] For example, the MAC sub-PDU in the MAC PDU is encrypted separately. For another example, the MAC sub-PDU in the MAC PDU is integrity protected separately. For another example, the multiple MAC sub-PDUs in the MAC PDU are encrypted together. For another example, the multiple MAC sub-PDUs in the MAC PDU are integrity protected together. The different granularity encryption and integrity protection schemes introduced above can be used in combination with each other, or can be used alone. In order to facilitate understanding, the implementation mode 1 and the implementation mode 2 are taken as examples for introduction below.
[0107] Implementation mode 1, the MAC sub-PDU in the MAC PDU is encrypted and / or integrity protected separately. That is, the MAC PDU can be encrypted and / or integrity protected with the MAC sub-PDU as the granularity.
[0108] For example, the MAC sub-PDUs are separately encrypted in the MAC PDU. For another example, the MAC sub-PDUs are separately integrity protected in the MAC PDU. For yet another example, the MAC sub-PDUs are separately encrypted and integrity protected in the MAC PDU.
[0109] In some implementations, the MAC PDU includes a third field for carrying a verification value for verifying the integrity of the MAC sub-PDUs, the third field being located after and adjacent to the MAC sub-PDUs in the MAC PDU, which will be described below in connection with FIG. 13.
[0110] In some implementations, the parameter for integrity protection further includes a first parameter (also referred to as “message “Message””), which is determined based on the MAC sub-PDUs, the field carrying the MAC PDU identifier, and the MAC sub-headers corresponding to the MAC sub-PDUs. Of course, in the embodiments of the present application, if the MAC PDU identifier is carried in the MAC sub-headers corresponding to the MAC sub-PDUs, it can be understood that the first parameter can be determined based on the MAC sub-PDUs and the MAC sub-headers.
[0111] In some implementations, the parameter for encryption further includes a second parameter (also referred to as “length “LENGTH””), which is determined based on the length of the MAC sub-PDUs and the length of the verification value for verifying the integrity of the MAC sub-PDUs, such as MAC-I.
[0112] For ease of understanding, the following describes the scheme for separately integrity protecting the MAC sub-PDUs in the embodiments of the present application in connection with the following example 1.
[0113] Example 1: Assuming that the MAC PDU is as shown in FIG. 8, where N = 5, the MAC PDU includes the MAC sub-PDUs for carrying MAC CE1-MAC CE5: MAC sub-PDU1-MAC sub-PDU5, and the MAC PDU identifier is located before the five MAC sub-PDUs. The following describes the scheme for separately integrity protecting all the MAC sub-PDUs in the MAC PDU in the embodiments of the present application.
[0114] FIG. 12 is a schematic diagram of integrity protection in the embodiments of the present application. Referring to FIG. 12, for the sending end, the MAC sub-PDU1-MAC sub-PDU5 can be separately integrity protected, and the following describes the integrity protection of the MAC sub-PDU1 by way of example, it being understood that the scheme for integrity protecting the other MAC sub-PDUs is similar.
[0115] Correspondingly, the parameters inputting the integrity protection algorithm in the process of integrity protection of the MAC sub-PDU 1 include the following four kinds:
[0116] The key "Key", which is generated by a key derivation manner similar to the traditional manner, is a key for integrity protection of the MAC CE;
[0117] The message "MESSAGE" includes the MAC sub-header in the MAC sub-PDU 1 and the MAC CE.
[0118] The direction "DIRECTION" is used to indicate the direction of the transmission of the MAC PDU is downlink. For example, if the value of the parameter is a first value, it indicates that the direction of the MAC PDU is downlink. Conversely, if the value of the parameter is a second value, it indicates that the direction of the MAC PDU is downlink. Wherein, the first value and the second value are different, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.
[0119] The MAC PDU identification (MAC PDU ID) is similar to the bearer identification "BEARER ID" used in the PDCP layer integrity protection process, and is used to distinguish different MAC PDUs.
[0120] Correspondingly, referring to FIG. 12, the above parameters are input into the integrity protection algorithm for calculation, and the MAC-I corresponding to the MAC sub-PDU 1 can be obtained. The MAC-I is placed after the MAC sub-PDU 1 in the MAC PDU, and the integrity protection is sequentially performed on other MAC sub-PDUs. The obtained MAC PDU is shown in FIG. 13.
[0121] In addition, continuing to refer to FIG. 12, for the receiving end, after receiving the MAC PDU, the above parameters can be input into the integrity protection algorithm to verify the integrity of the MAC sub-PDU 1 to the MAC sub-PDU 5.
[0122] It should be noted that in the embodiment of the present application, the LCID carried in the MAC sub-header of the MAC sub-PDU can be used as an input parameter, which is input into the integrity protection algorithm, and helps to reduce the adjustment of the bit of the input parameter of the traditional integrity protection algorithm. Of course, in the embodiment of the present application, the LCID carried in the MAC sub-header of the MAC sub-PDU can also not be used as an independent input parameter.
[0123] Implementation mode 2, multiple MAC PDUs are encrypted and / or integrity protected in the MAC PDU. That is, the MAC PDU can be encrypted and / or integrity protected in multiple MAC sub-PDUs as a granularity.
[0124] In some embodiments, the MAC PDU includes a third field for carrying a verification value for verifying the integrity of the plurality of MAC sub-PDUs, the third field being located after the plurality of MAC sub-PDUs and adjacent to the last MAC sub-PDU in the plurality of MAC sub-PDUs in the MAC PDU. This is further described below in connection with FIG. 15.
[0125] In some embodiments, the parameters for integrity protection further include a first parameter (also referred to as "MESSAGE"), which is determined based on the MAC CE or the MAC SDU in the plurality of MAC sub-PDUs, the field for carrying the MAC PDU identifier, and the plurality of MAC sub-headers corresponding to the plurality of MAC sub-PDUs. Of course, in the embodiments of the present application, if the MAC PDU identifier is carried in the MAC sub-headers corresponding to the plurality of MAC sub-PDUs, it can be understood that the first parameter can be determined based on the MAC CE or the MAC SDU in the plurality of MAC sub-PDUs and the MAC sub-headers.
[0126] In some embodiments, the parameters for encryption further include a second parameter (also referred to as "LENGTH"), which is determined based on the total length of the plurality of MAC sub-PDUs and the total length of the verification values corresponding to the plurality of MAC sub-PDUs, the verification values being used for verifying the integrity of the plurality of MAC sub-PDUs, for example, the verification values can be the MAC-I described above.
[0127] For ease of understanding, the following describes the scheme of integrity protection of the entire MAC sub-PDUs in the MAC PDU in the embodiments of the present application in connection with the following scenario of Example 2.
[0128] Example 2: Assuming that the MAC PDU is as shown in FIG. 8, where N = 5, the MAC PDU includes the MAC sub-PDUs for carrying the MAC CE1-MAC CE5: MAC sub-PDU1-MAC sub-PDU5, and the MAC PDU identifier is located before the five MAC sub-PDUs. The following describes the scheme of integrity protection of the entire MAC sub-PDUs in the MAC PDU in the embodiments of the present application.
[0129] FIG. 14 is a schematic diagram of integrity protection in the embodiments of the present application. Referring to FIG. 14, for the sending end, the MAC PDU identifier, the MAC sub-headers in the MAC sub-PDU1-MAC sub-PDU5, and the MAC CE can be integrity protected together, where the parameters for inputting the integrity protection algorithm in the process of integrity protection include the following four kinds:
[0130] a key "Key" generated by a key derivation manner similar to a conventional manner, which is a protection key for integrity of the MAC CE;
[0131] a message "MESSAGE" including a MAC PDU identifier, MAC sub-headers in the MAC sub-PDUs 1-5, and the MAC CE.
[0132] It should be noted that if the MAC PDU includes a MAC PDU header, the message further includes the MAC PDU header.
[0133] a direction "DIRECTION" used to indicate a direction of the MAC PDU is downlink. For example, if a value of the parameter is a first value, it indicates that the direction of the MAC PDU is downlink. Conversely, if the value of the parameter is a second value, it indicates that the direction of the MAC PDU is downlink. The first value and the second value are different, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.
[0134] a MAC PDU identifier (MAC PDU ID) used to distinguish different MAC PDUs, similar to a bearer identifier "BEARER ID" used in a PDCP layer integrity protection process.
[0135] Correspondingly, referring to FIG. 14, the parameters are input into an integrity protection algorithm for calculation, and the MAC-I corresponding to the MAC sub-PDUs 1-5 is obtained, and the MAC-I is placed after the MAC sub-PDUs 1-5 in the MAC PDU, as shown in FIG. 15.
[0136] In addition, referring to FIG. 14, for the receiving end, after receiving the MAC PDU, the parameters can be input into the integrity protection algorithm to verify the integrity of the MAC PDU identifier and the MAC sub-PDUs 1-5.
[0137] The above describes the scheme of integrity protection of the MAC sub-PDUs and the multiple MAC sub-PDUs as a whole in the embodiments of the present application. In some scenarios, the above scheme of integrity protection can be combined with the scheme of encryption of the MAC sub-PDUs and the multiple MAC sub-PDUs as a whole. The following describes examples 3 and 4, where example 3 is used to describe encryption and integrity protection of the multiple MAC sub-PDUs as a whole, and example 4 is used to describe encryption of the multiple MAC sub-PDUs as a whole and integrity protection of the MAC sub-PDUs.
[0138] Example 3: assuming that the MAC PDU is as shown in FIG. 8, wherein N=5, the MAC PDU includes MAC sub-PDUs: MAC sub-PDU1~MAC sub-PDU5 for carrying MAC CE1~MAC CE5, and the MAC PDU identifier is located before the 5 MAC sub-PDUs. The following introduces the scheme for integrity protection of all the MAC sub-PDUs in the MAC PDU together in the embodiments of the present application.
[0139] FIG. 16 is a schematic diagram of integrity protection in the embodiments of the present application. Referring to FIG. 16, for the sending end, the MAC PDU identifier, the MAC sub-headers in the MAC sub-PDUs 1~5 and the MAC CEs can be integrity protected together, wherein the parameters for inputting the integrity protection algorithm in the process of integrity protection include the following 4 kinds:
[0140] the key "Key", which is generated by a key derivation manner similar to the conventional manner, to be a key for integrity protection of the MAC CEs.
[0141] the message "MESSAGE", which includes the MAC PDU identifier, the MAC sub-headers in the MAC sub-PDUs 1~5 and the MAC CEs.
[0142] the direction "DIRECTION", which is used to indicate the direction of transmitting the MAC PDU as downlink. For example, if the value of the parameter is a first value, it indicates that the direction of the MAC PDU is downlink. Conversely, if the value of the parameter is a second value, it indicates that the direction of the MAC PDU is downlink. The first value and the second value are different, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.
[0143] the MAC PDU identifier (MAC PDU ID), which is similar to the bearer identifier "BEARER ID" used in the PDCP layer integrity protection process, and is used to distinguish different MAC PDUs.
[0144] Correspondingly, referring to FIG. 16, the above parameters are input into the integrity protection algorithm for calculation, and the MAC-I corresponding to the MAC sub-PDUs 1~5 can be obtained, and the MAC-I is placed after the MAC sub-PDUs 1~5 in the MAC PDU, as shown in FIG. 17.
[0145] In addition, referring to FIG. 16, for the receiving end, after receiving the MAC PDU, the above parameters can be input into the integrity protection algorithm to verify the integrity of the MAC PDU identifier, the MAC sub-PDUs 1~5.
[0146] Figure 18 is a schematic diagram of encryption in the embodiment of the present application. Referring to Figure 18, for the sending end, the MAC sub-headers in the MAC sub-PDUs 1-5 and the MAC CEs can be encrypted together, wherein the parameters input into the encryption algorithm in the encryption process include the following four parameters:
[0147] A key "Key", which is generated by a key derivation method similar to the conventional method, is a protection key for the integrity of the MAC CEs.
[0148] A direction "DIRECTION", which is used to indicate the direction of the transmission of the MAC PDU is downlink. For example, if the value of the parameter is a first value, it indicates that the direction of the MAC PDU is downlink. Conversely, if the value of the parameter is a second value, it indicates that the direction of the MAC PDU is downlink. The first value and the second value are different, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.
[0149] A MAC PDU identification (MAC PDU ID), which is similar to the bearer identification "BEARER ID" used in the PDCP layer integrity protection process, is used to distinguish different MAC PDUs.
[0150] A length "LENGTH", which is similar to the parameter "LENGTH" used in the PDCP layer encryption process, indicates the length of the information to be encrypted, which is determined based on the lengths of the MAC sub-PDUs 1-5 and the lengths of the corresponding verification values of the MAC sub-PDUs 1-5. The introduction of the parameter makes the length of the generated key stream consistent with the length of the plaintext.
[0151] Correspondingly, referring to Figure 18, the above parameters are input into the encryption algorithm for calculation, and the key stream block corresponding to the MAC sub-PDUs can be obtained. Then, the plaintext block can be encrypted by using the key stream block to obtain the ciphertext block. In addition, referring to Figure 18, for the receiving end, the MAC PDU can be decrypted by using the inverse operation after receiving the MAC PDU.
[0152] Example 4: Assuming that the MAC PDU is as shown in Figure 8, wherein N=5, the MAC PDU includes the MAC sub-PDUs 1-5 for carrying the MAC CEs 1-5, and the MAC PDU identification is located before the five MAC sub-PDUs. The following describes the scheme for integrity protection of all the MAC sub-PDUs in the MAC PDU in the embodiment of the present application.
[0153] Figure 19 is a schematic diagram of integrity protection in the embodiments of the present application. Referring to Figure 19, for the sending end, MAC sub-PDUs 1-5 can be integrity protected respectively. Hereinafter, the integrity protection of MAC sub-PDU 1 is taken as an example for description, and it should be understood that the integrity protection of other MAC sub-PDUs is similar to that of MAC sub-PDU 1.
[0154] Correspondingly, the parameters input into the integrity protection algorithm in the integrity protection of MAC sub-PDU 1 include the following four kinds:
[0155] A key "Key" is generated by a key derivation method similar to the conventional method, and is used as a key for integrity protection of the MAC CE.
[0156] A message "MESSAGE" includes the MAC sub-header in the MAC sub-PDU 1 and the MAC CE.
[0157] A direction "DIRECTION" is used to indicate the direction of the transmission of the MAC PDU, which is downlink. For example, if the value of the parameter is a first value, it indicates that the direction of the MAC PDU is downlink. Conversely, if the value of the parameter is a second value, it indicates that the direction of the MAC PDU is downlink. The first value and the second value are different, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.
[0158] A MAC PDU identifier (MAC PDU ID) is used to distinguish different MAC PDUs, similar to the bearer identifier "BEARER ID" used in the PDCP layer integrity protection process.
[0159] Correspondingly, referring to Figure 19, the above parameters are input into the integrity protection algorithm for calculation, and the MAC-I corresponding to the MAC sub-PDU 1 is obtained. The MAC-I is placed after the MAC sub-PDU 1 in the MAC PDU. The integrity protection is performed on other MAC sub-PDUs in turn, and the obtained MAC PDU is shown in Figure 20.
[0160] In addition, referring to Figure 19, for the receiving end, after receiving the MAC PDU, the above parameters can be input into the integrity protection algorithm to verify the integrity of the MAC sub-PDUs 1-5.
[0161] Figure 21 is a schematic diagram of encryption in the embodiments of the present application. Referring to Figure 21, for the sending end, the MAC sub-headers in the MAC sub-PDUs 1-5 and the MAC CE can be encrypted together. The parameters input into the encryption algorithm in the encryption process include the following four kinds:
[0162] Key, which is generated by a key derivation manner similar to a conventional manner, is a key for integrity protection of the MAC CE.
[0163] DIRECTION, which is used to indicate that the direction of the MAC PDU is downlink. For example, if the parameter takes a first value, it indicates that the direction of the MAC PDU is downlink. Conversely, if the parameter takes a second value, it indicates that the direction of the MAC PDU is downlink. The first value and the second value are different, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.
[0164] MAC PDU ID, which is similar to the BEARER ID used in the PDCP layer integrity protection process, is used to distinguish different MAC PDUs.
[0165] LENGTH, which is similar to the parameter LENGTH used in the PDCP layer encryption process, indicates the length of the information to be encrypted, which is determined based on the lengths of the MAC subPDUs 1-5 and the lengths of the verification values corresponding to the MAC subPDUs 1-5. The introduction of this parameter makes the length of the generated keystream consistent with the length of the plaintext.
[0166] Correspondingly, referring to FIG. 21, the above parameters are input into the encryption algorithm for calculation, and the keystream block corresponding to the MAC subPDU can be obtained. Then, the plaintext block can be encrypted by using the keystream block to obtain the ciphertext block. In addition, referring to FIG. 21, for the receiving end, after receiving the MAC PDU, the MAC PDU can be decrypted by using the inverse operation.
[0167] It should be noted that examples 1-4 are introduced by taking the MAC PDU shown in FIG. 8 as an example. In the embodiments of the present application, the above encryption and / or integrity protection scheme is also applicable to the MAC PDU shown in FIG. 9. The encryption and / or integrity protection process is similar to the above introduction, and the difference lies in that if the MAC PDU ID is carried in the MAC header of the first MAC subPDU, for the first parameter (also referred to as "message") used for integrity protection, the first parameter is determined based on the MAC subPDUs carrying the MAC CE in the MAC PDU except the MAC subheader of the first MAC subPDU and the MAC subheader corresponding to the MAC subPDU carrying the MAC CE.
[0168] For the second parameter (also referred to as "length" LENGTH") for encryption, the length of information indicated by the second parameter that needs to be encrypted is determined based on the total length of sub-PDUs corresponding to MAC sub-PDUs in the MAC PDU that are used to carry MAC CEs, except for the MAC sub-header of the first MAC sub-PDU, and the total length of verification values corresponding to the MAC sub-PDUs, the verification values being used to verify the integrity of the MAC sub-PDUs, for example, the verification values can be the MAC-I introduced above.
[0169] The method embodiments of the present application are described in detail above in combination with FIG. 1 to FIG. 21, and the device embodiments of the present application are described in detail below in combination with FIG. 22 to FIG. 24. It should be understood that the description of the method embodiments and the description of the device embodiments correspond to each other, and therefore, the parts not described in detail can be referred to the foregoing method embodiments.
[0170] FIG. 22 is a schematic diagram of a communication device in an embodiment of the present application. The communication device 2200 shown in FIG. 22 is a first device, and the communication device 2200 includes a sending unit 2210.
[0171] The sending unit 2210 is configured to send a MAC PDU to a second device, the MAC PDU carrying a MAC PDU identifier, the MAC PDU identifier being used for encryption and / or integrity protection of MAC sub-PDUs in the MAC PDU at a MAC layer.
[0172] In some implementations, the MAC sub-PDUs in the MAC PDU that are encrypted and / or integrity protected include all the MAC sub-PDUs in the MAC PDU; and / or the MAC sub-PDUs in the MAC PDU are used to carry MAC control elements (CEs) or MAC service data units (SDUs).
[0173] In some implementations, the MAC PDU identifier is carried in a first field, the first field being located in the MAC PDU before other fields, the other fields being fields in the MAC PDU except for the first field.
[0174] In some implementations, the MAC PDU identifier is carried in a first field, the first field being located in the first MAC sub-header of the MAC PDU.
[0175] In some implementations, the MAC PDU identifier includes one or more of the following: an index of the MAC PDU, a value of a counter corresponding to the MAC PDU.
[0176] In some embodiments, the sending unit is further configured to send indication information to the second device, the indication information being used to indicate whether encryption and / or integrity protection is performed on the MAC sub-PDUs in the MAC PDU.
[0177] In some embodiments, the indication information is carried in a second field, the second field being located before a field carrying the MAC PDU identifier in the MAC PDU.
[0178] In some embodiments, each of the MAC sub-PDUs is encrypted and / or integrity protected separately in the MAC PDU.
[0179] In some embodiments, the MAC PDU comprises a third field used to carry a verification value used to verify the integrity of the MAC sub-PDUs, the third field being located after the MAC sub-PDUs and adjacent to the last MAC sub-PDU in the MAC PDU.
[0180] In some embodiments, the parameters used for the integrity protection further comprise a first parameter determined based on the MAC CEs or MAC SDUs carried in each of the MAC sub-PDUs, the field carrying the MAC PDU identifier, and the MAC sub-headers corresponding to each of the MAC sub-PDUs.
[0181] In some embodiments, the parameters used for the encryption further comprise a second parameter, a length of information required to be encrypted indicated by the second parameter being determined based on a length of each of the MAC sub-PDUs and a length of a verification value used to verify the integrity of each of the MAC sub-PDUs.
[0182] In some embodiments, the plurality of MAC sub-PDUs are encrypted and / or integrity protected together in the MAC PDU.
[0183] In some embodiments, the MAC PDU comprises a third field used to carry a verification value used to verify the integrity of the plurality of MAC sub-PDUs, the third field being located after the plurality of MAC sub-PDUs and adjacent to the last MAC sub-PDU in the MAC PDU.
[0184] In some embodiments, the parameters used for the integrity protection further comprise a first parameter determined based on the plurality of MAC sub-PDUs, the field carrying the MAC PDU identifier, and the plurality of MAC sub-headers corresponding to the plurality of MAC sub-PDUs.
[0185] In some embodiments, the parameters for the encryption further include a second parameter, and a length of information indicated by the second parameter that needs to be encrypted is determined based on a total length of the plurality of MAC subPDUs and a total length of verification values corresponding to the plurality of MAC subPDUs, the verification values being used to verify integrity of the plurality of MAC subPDUs.
[0186] In some embodiments, the integrity protection of the MAC subPDUs in the MAC PDU includes integrity protection of a MAC CE or a MAC SDU carried in the MAC subPDUs, a field carrying the MAC PDU identifier, and a MAC subheader corresponding to the MAC subPDUs.
[0187] In some embodiments, the MAC PDU includes a verification value used to verify integrity of the MAC subPDUs, and the encryption of the MAC subPDUs in the MAC PDU includes encryption of the MAC subPDUs and the verification value.
[0188] In some embodiments, the first device is a terminal device, and the second device is a network device; or the first device is a network device, and the second device is a terminal device.
[0189] FIG. 23 is a schematic diagram of a communication device according to an embodiment of the present application. The communication device 2300 shown in FIG. 23 is a second device, and the communication device 2300 includes a receiving unit 2310.
[0190] The receiving unit 2310 is configured to receive a MAC PDU sent by a first device, the MAC PDU carrying a MAC PDU identifier, the MAC PDU identifier being used for encryption and / or integrity protection of MAC subPDUs in the MAC PDU at a MAC layer.
[0191] In some embodiments, the MAC subPDUs encrypted and / or integrity protected in the MAC PDU include all MAC subPDUs in the MAC PDU; and / or the MAC subPDUs in the MAC PDU are used to carry MAC control elements (CEs) or MAC service data units (SDUs).
[0192] In some embodiments, the MAC PDU identifier is carried in a first field, the first field being located before other fields in the MAC PDU, the other fields being fields in the MAC PDU other than the first field.
[0193] In some embodiments, the MAC PDU identifier is carried in a first field, the first field being located in a first MAC subheader of the MAC PDU.
[0194] In some embodiments, the MAC PDU identifier comprises one or more of: an index of the MAC PDU, a value of a counter corresponding to the MAC PDU.
[0195] In some embodiments, the receiving unit is further configured to receive indication information sent by the first device, the indication information being used to indicate whether encryption and / or integrity protection is performed on a MAC sub-PDU in the MAC PDU.
[0196] In some embodiments, the indication information is carried in a second field, the second field being located in the MAC PDU before a field carrying the MAC PDU identifier.
[0197] In some embodiments, each MAC sub-PDU in the MAC PDU is encrypted and / or integrity protected separately.
[0198] In some embodiments, the MAC PDU comprises a third field, the third field being used to carry a verification value used to verify integrity of the MAC sub-PDUs, the third field being located in the MAC PDU after the MAC sub-PDUs and adjacent to a last MAC sub-PDU in the MAC sub-PDUs.
[0199] In some embodiments, the parameters used for the integrity protection further comprise a first parameter, the first parameter being determined based on the each MAC sub-PDU, the field carrying the MAC PDU identifier, and a MAC sub-header corresponding to the each MAC sub-PDU.
[0200] In some embodiments, the parameters used for the encryption further comprise a second parameter, a length of information required to be encrypted indicated by the second parameter being determined based on a length of the each MAC sub-PDU and a length of a verification value used to verify integrity of the each MAC sub-PDU.
[0201] In some embodiments, a plurality of MAC sub-PDUs in the MAC PDU are encrypted and / or integrity protected together.
[0202] In some embodiments, the MAC PDU comprises a third field, the third field being used to carry a verification value used to verify integrity of the plurality of MAC sub-PDUs, the third field being located in the MAC PDU after the plurality of MAC sub-PDUs and adjacent to a last MAC sub-PDU in the plurality of MAC sub-PDUs.
[0203] In some embodiments, the parameter for the integrity protection further comprises a first parameter, which is determined based on the MAC CE or the MAC SDU carried in the plurality of MAC subPDUs, the field carrying the identification of the MAC PDU, and the plurality of MAC subheaders corresponding to the plurality of MAC subPDUs.
[0204] In some embodiments, the parameter for the encryption further comprises a second parameter, which indicates the length of information that needs to be encrypted, and is determined based on the total length of the plurality of MAC subPDUs, and the total length of the verification values corresponding to the plurality of MAC subPDUs, the verification values being used to verify the integrity of the plurality of MAC subPDUs.
[0205] In some embodiments, the integrity protection of the MAC subPDUs in the MAC PDU comprises integrity protection of the MAC CE or the MAC SDU carried in the MAC subPDUs, the field carrying the identification of the MAC PDU, and the MAC subheader corresponding to the MAC subPDU.
[0206] In some embodiments, the MAC PDU comprises verification values used to verify the integrity of the MAC subPDUs, and the encryption of the MAC subPDUs in the MAC PDU comprises encryption of the MAC subPDUs and the verification values.
[0207] In some embodiments, the first device is a terminal device, and the second device is a network device; or the first device is a network device, and the second device is a terminal device.
[0208] In optional embodiments, the sending unit 2210 can be a transceiver 2430. The communication device 2200 can further include a processor 2410 and a memory 2420, as shown in FIG. 24.
[0209] In optional embodiments, the receiving unit 2310 can be a transceiver 2430. The communication device 2300 can further include a processor 2410 and a memory 2420, as shown in FIG. 24.
[0210] FIG. 24 is a schematic structural diagram of a communication apparatus according to an embodiment of the present application. The dashed line in FIG. 24 indicates that the unit or module is optional. The apparatus 2400 can be used to implement the method described in the above method embodiments. The apparatus 2400 can be a chip, a terminal device, or a network device.
[0211] The apparatus 2400 can include one or more processors 2410. The processor 2410 can support the apparatus 2400 to implement the methods described in the foregoing method embodiments. The processor 2410 can be a general processor or a special-purpose processor. For example, the processor can be a central processing unit (CPU). Alternatively, the processor can also be other general processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic, discrete hardware components, etc. The general processor can be a microprocessor or the processor can also be any conventional processor.
[0212] The apparatus 2400 can also include one or more memories 2420. The memory 2420 stores a program that can be executed by the processor 2410, so that the processor 2410 performs the methods described in the foregoing method embodiments. The memory 2420 can be independent of the processor 2410 or integrated in the processor 2410.
[0213] The apparatus 2400 can also include a transceiver 2430. The processor 2410 can communicate with other devices or chips through the transceiver 2430. For example, the processor 2410 can perform data transceiving with other devices or chips through the transceiver 2430.
[0214] The embodiments of the present application also provide a computer readable storage medium for storing a program. The computer readable storage medium can be applied to the terminal or network device provided by the embodiments of the present application, and the program causes the computer to execute the method performed by the terminal or network device in the various embodiments of the present application.
[0215] The embodiments of the present application also provide a computer program product. The computer program product includes a program. The computer program product can be applied to the terminal or network device provided by the embodiments of the present application, and the program causes the computer to execute the method performed by the terminal or network device in the various embodiments of the present application.
[0216] The embodiments of the present application also provide a computer program. The computer program can be applied to the terminal or network device provided by the embodiments of the present application, and the computer program causes the computer to execute the method performed by the terminal or network device in the various embodiments of the present application.
[0217] It should be understood that the terms "system" and "network" can be used interchangeably in this application. In addition, the terms used in this application are only used to explain the specific embodiments of the application, and are not intended to limit the application. The terms "first", "second", "third", and "fourth" and the like in the specification and claims of the application and the drawings are used to distinguish different objects, and are not used to describe a particular order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion.
[0218] In embodiments of the present application, the term "indicate" can be direct indication or indirect indication, or can represent an associated relationship. For example, A indicates B, which can mean that B can be obtained directly through A; or A indirectly indicates B, for example, A indicates C, and B can be obtained through C; or A and B have an associated relationship.
[0219] In embodiments of the present application, "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.
[0220] In embodiments of the present application, the term "corresponding" can represent a direct or indirect corresponding relationship between the two, or can represent an associated relationship between the two, or can represent an indication and being indicated, configuration and being configured, and the like.
[0221] In embodiments of the present application, "predefined" or "preconfigured" can be achieved by pre-saving corresponding codes, tables or other information that can be used to indicate related information in devices (such as terminal devices and network devices), and the specific implementation of the present application is not limited. For example, predefinition can refer to definition in a protocol.
[0222] In embodiments of the present application, the "protocol" can refer to a standard protocol in the field of communication, which can include LTE protocol, NR protocol and related protocols applied to future communication systems, and the present application is not limited.
[0223] In embodiments of the present application, the term "and / or" is only used to describe the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can mean that A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in this paper generally represents an "or" relationship between the front and rear associated objects.
[0224] In various embodiments of the present application, the size of the serial number of the above processes does not mean the order of execution, and the execution order of the processes should be determined by its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0225] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the division of the above-described device embodiments is only a logical function division, and there can be another division manner for actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, or between the different components, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0226] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.
[0227] In addition, each functional unit in the various embodiments of the present application can be integrated into a processing unit, or each unit can exist physically, or two or more units can be integrated into one unit.
[0228] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be read by a computer or a data storage device such as a server, data center and the like integrated with one or more available media sets. The available media can be magnetic media (for example, floppy disk, hard disk, magnetic tape), optical media (for example, digital video disc (DVD)) or semiconductor media (for example, solid state disk (SSD)) and the like.
[0229] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method of wireless communication, comprising: Comprising: A first device sends a media access control, MAC, protocol data unit, PDU, to a second device, the MAC PDU carrying a MAC PDU identity, the MAC PDU identity being used for ciphering and / or integrity protection of MAC subPDUs in the MAC PDU at a MAC layer.
2. The method of claim 1, wherein, The MAC subPDUs ciphered and / or integrity protected in the MAC PDU comprise all MAC subPDUs in the MAC PDU; And / or The MAC subPDUs in the MAC PDU are used to carry MAC control elements, CEs, or MAC service data units, SDUs.
3. The method of claim 1 or 2, wherein, The MAC PDU identity is carried in a first field, the first field being located in the MAC PDU before other fields, the other fields being fields in the MAC PDU other than the first field.
4. The method of claim 1 or 2, wherein, The MAC PDU identity is carried in a first field, the first field being located in a first MAC subheader of the MAC PDU.
5. The method of any one of claims 1-4, wherein, The MAC PDU identity comprises one or more of: an index of the MAC PDU, a value of a counter corresponding to the MAC PDU.
6. The method of any one of claims 1-5, wherein, The method further comprises: The first device sends indication information to the second device, the indication information being used to indicate whether ciphering and / or integrity protection is applied to MAC subPDUs in the MAC PDU.
7. The method of claim 6, wherein, The indication information is carried in a second field, the second field being located in the MAC PDU before a field carrying the MAC PDU identity.
8. The method of any one of claims 1-7, wherein, Ciphering and / or integrity protection is applied to each MAC subPDU in the MAC PDU separately.
9. The method of claim 8, wherein, The MAC PDU comprises a third field, the third field being used to carry a verification value used to verify integrity of the MAC subPDUs, the third field being located in the MAC PDU after the MAC subPDUs and adjacent to a last MAC subPDU of the MAC subPDUs.
10. The method of claim 8 or 9, wherein, The parameters used for the integrity protection further comprise a first parameter, the first parameter being determined based on a MAC CE or a MAC SDU carried in each of the MAC subPDUs, a field carrying the MAC PDU identity, and a MAC subheader corresponding to each of the MAC subPDUs.
11. The method of any one of claims 8-10, wherein, The parameters used for the ciphering further comprise a second parameter, a length of information required to be ciphered indicated by the second parameter being determined based on a length of each of the MAC subPDUs, and a length of a verification value used to verify integrity of each of the MAC subPDUs.
12. The method of any one of claims 1-7, wherein, Ciphering and / or integrity protection is applied to a plurality of MAC subPDUs in the MAC PDU together.
13. The method of claim 12, wherein, The MAC PDU comprises a third field, the third field being used to carry a verification value used to verify integrity of the plurality of MAC subPDUs, the third field being located in the MAC PDU after the plurality of MAC subPDUs and adjacent to a last MAC subPDU of the plurality of MAC subPDUs.
14. The method of claim 12 or 13, wherein, The parameters for the integrity protection further include a first parameter, which is determined based on a MAC CE or a MAC SDU carried in the plurality of MAC subPDUs, a field carrying the MAC PDU identifier, and a plurality of MAC subheaders corresponding to the plurality of MAC subPDUs.
15. The method of any one of claims 12-14, wherein, The parameters for the encryption further include a second parameter, which is determined based on a total length of the plurality of MAC subPDUs and a total length of verification values corresponding to the plurality of MAC subPDUs, the verification values being used for verifying the integrity of the plurality of MAC subPDUs.
16. The method of any one of claims 1-15, wherein, The integrity protection of the MAC subPDUs in the MAC PDU includes integrity protection of a MAC CE or a MAC SDU carried in the MAC subPDUs, a field carrying the MAC PDU identifier, and a MAC subheader corresponding to the MAC subPDU.
17. The method of any one of claims 1-16, wherein, The MAC PDU includes verification values used for verifying the integrity of the MAC subPDUs, and the encryption of the MAC subPDUs in the MAC PDU includes encryption of the MAC subPDUs and the verification values.
18. The method of any one of claims 1-17, wherein, The first device is a terminal device, and the second device is a network device; or The first device is a network device, and the second device is a terminal device.
19. A method of wireless communication, comprising: The method comprises: The second device receives a MAC PDU sent by the first device, the MAC PDU carrying a MAC PDU identifier, the MAC PDU identifier being used for encryption and / or integrity protection of MAC subPDUs in the MAC PDU at a MAC layer.
20. The method of claim 19, wherein, The MAC subPDUs in the MAC PDU that are encrypted and / or integrity protected include all the MAC subPDUs in the MAC PDU. The MAC subPDUs in the MAC PDU are used for carrying a MAC control element (CE) or a MAC service data unit (SDU). The MAC PDU identifier is carried in a first field, the first field being located before other fields in the MAC PDU, the other fields being fields in the MAC PDU other than the first field.
21. The method of claim 19 or 20, wherein, The MAC PDU identifier is carried in a first field, the first field being located in a first MAC subheader of the MAC PDU.
22. The method of claim 19 or 20, wherein, The MAC PDU identifier includes one or more of the following: an index of the MAC PDU, a value of a counter corresponding to the MAC PDU.
23. The method of any one of claims 19-22, wherein, The method further comprises:
24. The method of any one of claims 19-23, wherein, The second device receives indication information sent by the first device, the indication information being used for indicating whether encryption and / or integrity protection is performed on the MAC subPDUs in the MAC PDU. The indication information is carried in a second field, the second field being located before a field carrying the MAC PDU identifier in the MAC PDU.
25. The method of claim 24, wherein, Encryption and / or integrity protection is performed on each of the MAC subPDUs in the MAC PDU respectively.
26. The method of any one of claims 19-25, wherein, 27. The method of claim 26, wherein, The MAC PDU comprises a third field for carrying a verification value for verifying the integrity of the MAC sub-PDUs, the third field being located after the MAC sub-PDUs and adjacent to the last MAC sub-PDU in the MAC PDU.
28. The method of claim 26 or 27, wherein, The parameters for the integrity protection further comprise a first parameter determined based on the MAC CEs or MAC SDUs carried in the MAC sub-PDUs, the field carrying the MAC PDU identifier, and the MAC sub-headers corresponding to the MAC sub-PDUs.
29. The method of any one of claims 26-28, wherein, The parameters for the encryption further comprise a second parameter, the length of information required to be encrypted indicated by the second parameter being determined based on the length of each MAC sub-PDU and the length of the verification value for verifying the integrity of each MAC sub-PDU.
30. The method of any one of claims 19-25, wherein, The MAC sub-PDUs in the MAC PDU are encrypted and / or integrity protected together.
31. The method of claim 30, wherein, The MAC PDU comprises a third field for carrying a verification value for verifying the integrity of the MAC sub-PDUs, the third field being located after the MAC sub-PDUs and adjacent to the last MAC sub-PDU in the MAC PDU.
32. The method of claim 30 or 31, wherein, The parameters for the integrity protection further comprise a first parameter determined based on the MAC CEs or MAC SDUs carried in the MAC sub-PDUs, the field carrying the MAC PDU identifier, and the MAC sub-headers corresponding to the MAC sub-PDUs.
33. The method of any one of claims 30-32, wherein, The parameters for the encryption further comprise a second parameter, the length of information required to be encrypted indicated by the second parameter being determined based on the length of each MAC sub-PDU and the length of the verification value for verifying the integrity of each MAC sub-PDU.
34. The method of any one of claims 19-33, wherein, The integrity protection of the MAC sub-PDUs in the MAC PDU comprises integrity protection of the MAC CEs or MAC SDUs carried in the MAC sub-PDUs, the field carrying the MAC PDU identifier, and the MAC sub-headers corresponding to the MAC CEs.
35. The method of any one of claims 19-34, wherein, The MAC PDU comprises a verification value for verifying the integrity of the MAC CEs, and the encryption of the MAC sub-PDUs in the MAC PDU comprises encryption of the MAC sub-PDUs and the verification value.
36. The method of any one of claims 19-35, wherein, The first device is a terminal device, and the second device is a network device; or The first device is a network device, and the second device is a terminal device.
37. A communications device, characterized by The communication device is a first device, comprising: a sending unit configured to send a MAC PDU to a second device, the MAC PDU carrying a MAC PDU identifier, the MAC PDU identifier being used for encryption and / or integrity protection of MAC sub-PDUs in the MAC PDU at a MAC layer.
38. The communications device of claim 37, wherein, The MAC sub-PDUs encrypted and / or integrity protected in the MAC PDU include all the MAC sub-PDUs in the MAC PDU. And / or The MAC sub-PDUs in the MAC PDU are used to carry MAC control elements (CEs) or MAC service data units (SDUs).
39. The communication device of claim 37 or 38, wherein, The MAC PDU identifier is carried in a first field, which is located before other fields in the MAC PDU, the other fields being fields in the MAC PDU other than the first field.
40. The communication device of claim 37 or 38, wherein, The MAC PDU identifier is carried in a first field, which is located in a first MAC sub-header of the MAC PDU.
41. The communication device of any one of claims 37-40, wherein, The MAC PDU identifier includes one or more of the following: an index of the MAC PDU, a value of a counter corresponding to the MAC PDU.
42. The communication device of any one of claims 37-41, wherein, The sending unit is further configured to: send, to the second device, indication information indicating whether encryption and / or integrity protection is performed on the MAC sub-PDUs in the MAC PDU.
43. The communications device of claim 42, wherein, The indication information is carried in a second field, which is located before a field carrying the MAC PDU identifier in the MAC PDU.
44. The communication device of any one of claims 37-41, wherein, Each of the MAC sub-PDUs in the MAC PDU is encrypted and / or integrity protected separately.
45. The communications device of claim 44, wherein, The MAC PDU includes a third field for carrying a verification value for verifying the integrity of the MAC sub-PDUs, the third field being located after the MAC sub-PDUs and adjacent to a last MAC sub-PDU of the MAC sub-PDUs in the MAC PDU.
46. The communication device of claim 44 or 45, wherein, The parameters for the integrity protection further include a first parameter determined based on the MAC CEs or MAC SDUs carried in the MAC sub-PDUs, the field carrying the MAC PDU identifier, and MAC sub-headers corresponding to the MAC sub-PDUs.
47. The communication device of any one of claims 44-46, wherein, The parameters for the encryption further include a second parameter, a length of information indicated by the second parameter to be encrypted being determined based on lengths of the MAC sub-PDUs and lengths of verification values corresponding to the MAC sub-PDUs, the verification values being used to verify the integrity of the MAC sub-PDUs.
48. The communication device of any one of claims 37-43, wherein, The MAC PDU includes a third field for carrying a verification value for verifying the integrity of the MAC sub-PDUs, the third field being located after the MAC sub-PDUs and adjacent to a last MAC sub-PDU of the MAC sub-PDUs in the MAC PDU.
49. The communications device of claim 48, wherein, The parameters for the integrity protection further include a first parameter determined based on the MAC CEs or MAC SDUs carried in the MAC sub-PDUs, the field carrying the MAC PDU identifier, and MAC sub-headers corresponding to the MAC sub-PDUs.
50. The communication device of claim 48 or 49, wherein, 51. The communication device of any of claims 48-50, wherein, The parameter for the encryption further comprises a second parameter, a length of information required to be encrypted indicated by the second parameter is determined based on a total length of the plurality of MAC subPDUs and a total length of verification values corresponding to the plurality of MAC subPDUs, the verification values being used for verifying integrity of the plurality of MAC subPDUs.
52. The communication device of any of claims 37-51, wherein, The integrity protection of the MAC subPDUs in the MAC PDU comprises integrity protection of a MAC CE or a MAC SDU carried in the MAC subPDU, a field carrying the MAC PDU identifier and a MAC subheader corresponding to the MAC subPDU.
53. The communication device of any of claims 37-52, wherein, The MAC PDU comprises a verification value used for verifying integrity of the MAC subPDUs, and the encryption of the MAC subPDUs in the MAC PDU comprises encryption of the MAC subPDUs and the verification value.
54. The communication device of any of claims 37-53, wherein, The first device is a terminal device, and the second device is a network device; or The first device is a network device, and the second device is a terminal device.
55. A communications device, characterized by The communication device is a second device, comprising: a receiving unit configured to receive a MAC PDU sent by a first device, the MAC PDU carrying a MAC PDU identifier, the MAC PDU identifier being used for encryption and / or integrity protection of MAC subPDUs in the MAC PDU at a MAC layer.
56. The communications device of claim 55, wherein, The MAC CEs encrypted and / or integrity protected in the MAC PDU comprise all the MAC subPDUs in the MAC PDU; and / or The MAC subPDUs in the MAC PDU are used for carrying MAC control elements (CEs) or MAC service data units (SDUs).
57. The communication device of claim 55 or 56, wherein, The MAC PDU identifier is carried in a first field, the first field being located before other fields in the MAC PDU, the other fields being fields in the MAC PDU other than the first field.
58. The communication device of claim 55 or 56, wherein, The MAC PDU identifier is carried in a first field, the first field being located in a first MAC subheader of the MAC PDU.
59. The communication device of any of claims 55-58, wherein, The MAC PDU identifier comprises one or more of the following: an index of the MAC PDU, a value of a counter corresponding to the MAC PDU.
60. The communication device of any of claims 55-59, wherein, The receiving unit is further configured to: receive indication information sent by the first device, the indication information being used for indicating whether encryption and / or integrity protection is performed on the MAC subPDUs in the MAC PDU.
61. The communications device of claim 60, wherein, The indication information is carried in a second field, the second field being located before a field carrying the MAC PDU identifier in the MAC PDU.
62. The communication device of any of claims 55-61, wherein, Encryption and / or integrity protection is performed on each of the MAC subPDUs in the MAC PDU respectively.
63. The communications device of claim 62, wherein, The MAC PDU comprises a third field used for carrying a verification value used for verifying integrity of the MAC subPDUs, the third field being located after the MAC subPDUs and adjacent to the MAC CEs in the MAC PDU.
64. The communication device of claim 62 or 63, wherein, The parameter for the integrity protection further comprises a first parameter determined based on the MAC CEs or MAC SDUs carried in the MAC subPDUs, the field carrying the MAC PDU identity, and the MAC subheaders corresponding to the MAC subPDUs.
65. The communication device of any of claims 62-64, wherein, The parameter for the encryption further comprises a second parameter, a length of information required to be encrypted indicated by the second parameter is determined based on a length of the MAC subPDUs, and a length of verification values corresponding to the MAC subPDUs, the verification values being used to verify the integrity of the MAC subPDUs.
66. The communication device of any of claims 55-61, wherein, The MAC CEs are encrypted and / or integrity protected together in the MAC PDU.
67. The communications device of claim 66 wherein, The MAC PDU comprises a third field for carrying verification values used to verify the integrity of the MAC subPDUs, the third field being located after the MAC subPDUs and adjacent to a last MAC subPDU in the MAC PDU.
68. The communication device of claim 66 or 67, wherein, The parameter for the integrity protection further comprises a first parameter determined based on the MAC CEs or MAC SDUs carried in the MAC subPDUs, the field carrying the MAC PDU identity, and the MAC subheaders corresponding to the MAC subPDUs.
69. The communication device of any of claims 66-68, wherein, The parameter for the encryption further comprises a second parameter, a length of information required to be encrypted indicated by the second parameter is determined based on a length of the MAC subPDUs, and a length of verification values corresponding to the MAC subPDUs, the verification values being used to verify the integrity of the MAC subPDUs.
70. The communication device of any of claims 55-69, wherein, The integrity protection of the MAC subPDUs in the MAC PDU comprises integrity protection of the MAC subPDUs, the field carrying the MAC PDU identity, and the MAC subheaders corresponding to the MAC subPDUs.
71. The communication device of any of claims 55-70, wherein, The MAC PDU comprises verification values used to verify the integrity of the MAC subPDUs, and the encryption of the MAC subPDUs in the MAC PDU comprises encryption of the MAC subPDUs and the verification values.
72. The communication device of any of claims 55-71, wherein, The first device is a terminal device, and the second device is a network device; or The first device is a network device, and the second device is a terminal device.
73. A communications device, characterized by A communication device comprising a transceiver, a memory, and a processor, the memory being configured to store a program, the processor being configured to invoke the program in the memory and control the transceiver to receive or send a signal, so that the communication device performs the method in any one of claims 1-36.
74. An apparatus comprising: A device comprising a processor configured to invoke a program from a memory, so that the device performs the method in any one of claims 1-36.
75. A chip, comprising: A chip comprising a processor configured to invoke a program from a memory, so that a device installed with the chip performs the method in any one of claims 1-36.
76. A computer-readable storage medium, comprising, A computer program product having a program stored thereon, the program causing a computer to perform the method in any one of claims 1-36.
77. A computer program product, characterized in that, comprising a program causing a computer to perform the method of any one of claims 1-36.
78. A computer program, characterized in that, The computer program causes a computer to perform the method of any one of claims 1-36.
Citation Information
Patent Citations
Medium access control security
CN113273236A
Communication method and device
CN115696319A
Communication method and device
CN115884173A
Initial security activation for medium access control layer
WO2023175378A1