Wireless communication method and communication device
By introducing a first parameter and a second identifier at the MAC layer, the MAC sub-PDU in the MAC PDU is encrypted and its integrity is protected. This solves the problem that the traditional PDCP layer protection mechanism cannot protect the MAC CE, improves the security of the wireless communication system, and reduces the risk of user privacy leakage.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2026-03-26
AI Technical Summary
Traditional security protection mechanisms at the PDCP layer cannot effectively protect MAC CE, leading to security risks and user privacy leaks during communication, especially in wireless communication systems where sensitive information of MAC CE is vulnerable to attack.
A first parameter and a second identifier are introduced at the MAC layer to encrypt and/or protect the integrity of the MAC sub-PDU in the MAC PDU. The first identifier is used to identify the MAC PDU, and the second identifier is used to identify the MAC sub-PDU. This is similar to the encryption and integrity protection mechanism of the PDCP layer to protect the MAC sub-PDU.
By providing encryption and integrity protection at the MAC layer, the possibility of user privacy leaks is reduced, and the security of communication systems is improved, especially the protection of MAC CE in wireless communication systems.
Smart Images

Figure CN2024120388_26032026_PF_FP_ABST
Abstract
Description
Method and communication device for wireless communication TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, and more particularly, to a method and a communication device for wireless communication. BACKGROUND
[0002] The conventional security protection mechanism is to perform encryption and / or integrity protection on user plane data packets and control plane data packets of a packet data convergence protocol (PDCP) layer respectively based on a core network derived key and other related parameters at the PDCP layer. However, this security protection mechanism performed at the PDCP layer has certain limitations and may cause security risks.
[0003] SUMMARY
[0004] The present application provides a method and a communication device for wireless communication. Each aspect of the present application is described below.
[0005] In a first aspect, a method for wireless communication is provided, comprising: sending, by a first device, a first medium access control (MAC) protocol data unit (PDU) to a second device, the first MAC PDU carrying a first parameter, the first parameter being used for encryption and / or integrity protection of a MAC sub-PDU in the first MAC PDU at a MAC layer, wherein the first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying the MAC sub-PDU in the first MAC PDU.
[0006] In a second aspect, a method for wireless communication is provided, comprising: receiving, by a second device, a first MAC PDU sent by a first device, the first MAC PDU carrying a first parameter, the first parameter being used for decryption and / or integrity protection of a MAC sub-PDU in the first MAC PDU at a MAC layer, wherein the first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying the MAC sub-PDU in the first MAC PDU.
[0007] In a third aspect, a communication device is provided, the communication device being a first device, comprising: a sending unit configured to send a first MAC PDU to a second device, the first MAC PDU carrying a first parameter, the first parameter being used for ciphering and / or integrity protection of a MAC sub-PDU in the first MAC PDU at a MAC layer, wherein the first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying the MAC sub-PDU in the first MAC PDU.
[0008] In a fourth aspect, a communication device is provided, the communication device being a second device, comprising: a receiving unit configured to receive a first MAC PDU sent by a first device, the first MAC PDU carrying a first parameter, the first parameter being used for deciphering and / or integrity protection of a MAC sub-PDU in the first MAC PDU at a MAC layer, wherein the first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying the MAC sub-PDU in the first MAC PDU.
[0009] In a fifth aspect, a communication device is provided, comprising a processor, a memory and a communication interface, the memory being configured to store one or more computer programs, and the processor being configured to invoke the computer programs in the memory, so that the communication device performs some or all of the steps in the methods of the various aspects described above.
[0010] In a sixth aspect, an embodiment of the present application provides a communication system, which comprises the first device and / or the second device described above. In another possible design, the system can further comprise other devices interacting with the first device or the second device in the solutions provided by the embodiments of the present application.
[0011] In a seventh aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the computer program causes a communication device to perform some or all of the steps in the methods of the various aspects described above.
[0012] In an eighth aspect, an embodiment of the present application provides a computer program product, which comprises a non-transitory computer readable storage medium storing a computer program, and the computer program is operable to cause a communication device to perform some or all of the steps in the methods of the various aspects described above. In some implementations, the computer program product can be a software installation package.
[0013] In a ninth aspect, an embodiment of the present application provides a chip, which comprises a memory and a processor. The processor can call and run a computer program from the memory to implement part or all of the steps described in the method of each of the above aspects.
[0014] In the embodiments of the present application, the first parameter can be introduced to implement the encryption and / or integrity protection process for the MAC sub-PDU at the MAC layer. Compared with the conventional scheme in which only encryption and integrity protection can be performed at the PDCP layer, the encryption and / or integrity protection for the MAC sub-PDU can be implemented, and the possibility of user privacy leakage can be reduced. BRIEF DESCRIPTION OF DRAWINGS
[0015] FIG. 1 is a wireless communication system 100 to which embodiments of the present application are applied.
[0016] FIG. 2 is a schematic diagram of integrity protection and encryption for a PDCP PDU at a PDCP layer.
[0017] FIG. 3 is a schematic flowchart of an integrity protection process of a PDCP layer.
[0018] FIG. 4 is a schematic flowchart of an encryption operation process of a PDCP layer.
[0019] FIGS. 5A and 5B are schematic diagrams of a format of a MAC PDU to which embodiments of the present application are applied.
[0020] FIGS. 6A and 6B are schematic diagrams of a MAC subheader to which embodiments of the present application are applied.
[0021] FIG. 7 is a schematic flowchart of a method of wireless communication according to an embodiment of the present application.
[0022] FIG. 8 is a schematic diagram of a first MAC PDU carrying a first identifier according to an embodiment of the present application.
[0023] FIG. 9 is a schematic diagram of a first MAC PDU carrying a first identifier according to another embodiment of the present application.
[0024] FIGS. 10A and 10B are schematic diagrams of a first MAC PDU carrying a second identifier according to an embodiment of the present application.
[0025] FIG. 11 is a schematic diagram of a first MAC PDU carrying first indication information according to an embodiment of the present application.
[0026] FIG. 12 is a schematic diagram of a first MAC PDU carrying second indication information according to an embodiment of the present application.
[0027] FIG. 13 is a schematic diagram of integrity protection and encryption for a MAC sub-PDU at a MAC layer according to an embodiment of the present application.
[0028] FIG. 14 is a schematic diagram of integrity protection in an embodiment of the present application.
[0029] FIG. 15 is a schematic diagram of encryption operation in an embodiment of the present application.
[0030] FIG. 16 is a schematic diagram of integrity protection in another embodiment of the present application.
[0031] FIG. 17 is a schematic diagram of encryption in another embodiment of the present application.
[0032] FIG. 18 is a schematic diagram of integrity protection in an embodiment of the present application.
[0033] FIG. 19 is a schematic diagram of encryption in an embodiment of the present application.
[0034] FIG. 20 is a schematic diagram of a communication device in an embodiment of the present application.
[0035] FIG. 21 is a schematic diagram of a communication device in an embodiment of the present application.
[0036] FIG. 22 is a schematic structural diagram of a communication device in an embodiment of the present application. DETAILED DESCRIPTION
[0037] The technical solutions in the present application will be described below with reference to the accompanying drawings.
[0038] FIG. 1 is a wireless communication system 100 to which embodiments of the present application are applied. The wireless communication system 100 can include a network device 110 and a terminal device 120. The network device 110 can be a device that communicates with the terminal device 120. The network device 110 can provide communication coverage for a specific geographic area and can communicate with the terminal device 120 located in the coverage area.
[0039] FIG. 1 exemplarily shows one network device and two terminals. Optionally, the wireless communication system 100 can include multiple network devices and each network device can include other number of terminal devices within its coverage, which is not limited in the embodiments of the present application.
[0040] Optionally, the wireless communication system 100 can further include a network controller, a mobile management entity, and other network entities, which are not limited in the embodiments of the present application.
[0041] It should be understood that the technical solutions of the embodiments of the present application can be applied to various communication systems, for example: a 5th generation (5G) system or new radio (NR), a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD), and the like. The technical solutions provided in the present application can also be applied to future communication systems, such as a 6th generation mobile communication system, a satellite communication system, and the like.
[0042] The terminal device in the embodiments of the present application can also be referred to as a user equipment (UE), an access terminal, a user unit, a user station, a mobile station, a mobile station (MS), a mobile terminal (MT), a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user apparatus. The terminal device in the embodiments of the present application can refer to a device that provides voice and / or data connectivity for a user, and can be used to connect people, things, and machines, such as handheld devices with wireless connection functions, vehicle-mounted devices, and the like. The terminal device in the embodiments of the present application can be a mobile phone, a tablet computer (Pad), a notebook computer, a palm computer, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, and the like. Optionally, the UE can be used to act as a base station. For example, the UE can act as a scheduling entity, which provides a sidelink signal between UEs in V2X or D2D, and the like. For example, a cellular phone and a car communicate with each other using a sidelink signal. The cellular phone and the smart home device communicate with each other without relaying the communication signal through the base station.
[0043] The network device in the embodiments of the present application can be a device for communicating with a terminal device, which can also be referred to as an access network device or a radio access network device, such as a network device, which can be a base station. The network device in the embodiments of the present application can refer to a radio access network (RAN) node (or device) that accesses a terminal device to a wireless network. The base station can broadly cover various names in the following or be replaced by the following names, such as: Node B (NodeB), evolved Node B (eNB), next generation Node B (gNB), relay station, transmitting and receiving point (TRP), transmitting point (TP), master station MeNB, auxiliary station SeNB, multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The base station can be a macro base station, a micro base station, a relay node, a donor node or the like, or a combination thereof. The base station can also refer to a communication module, modem or chip for being disposed in the foregoing devices or apparatuses. The base station can also be a mobile switching center and a device that undertakes a base station function in device-to-device (D2D), vehicle-to-everything (V2X), machine-to-machine (M2M) communication, a network side device in a 6G network, a device that undertakes a base station function in a future communication system, etc. The base station can support networks of the same or different access technologies. The embodiments of the present application do not limit the specific technology and specific device form adopted by the network device.
[0044] The base station can be fixed or mobile. For example, a helicopter or a drone can be configured to act as a mobile base station, and one or more cells can move according to the location of the mobile base station. In other examples, a helicopter or a drone can be configured to act as a device that communicates with another base station.
[0045] In some deployments, the network device in the embodiments of the present application can refer to a CU or a DU, or the network device includes a CU and a DU. The gNB can also include an AAU.
[0046] The network device and the terminal device can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can also be deployed on water surface; can also be deployed on aircraft, balloons and satellites in the air. The scene where the network device and the terminal device are located in the embodiments of the present application is not limited.
[0047] It should be understood that all or part of the functions of the communication device in the present application can also be implemented by software functions running on hardware, or by virtualized functions instantiated on a platform (such as a cloud platform).
[0048] PDCP security mechanism
[0049] In some scenarios, the confidentiality / integrity protection of the user plane (UP) data and the RRC message between the terminal device and the network device (for example, 5G-RAN) can be provided by the PDCP protocol layer.
[0050] In some implementations, the PDCP layer encryption integrity protection mechanism can be understood as the PDCP layer being responsible for performing encryption and integrity protection operations. For a PDCP PDU, integrity protection can be performed first and then encryption. Generally, integrity protection and encryption are paired. For the integrity protection process, the sending end first performs integrity protection calculation, and the receiving end performs corresponding integrity protection verification. For the encryption / decryption process, the sending end performs encryption processing, and the receiving end performs decryption processing.
[0051] Figure 2 shows a schematic diagram of integrity protection and ciphering for PDCP PDU at PDCP layer. Referring to Figure 2, integrity protection is applied to PDCP header and PDCP data part (also referred to as user plane data packet), and a verification value (e.g., message authorization code for integrity (MAC-I)) is obtained after integrity protection, which is used for integrity verification at the receiving end. Currently, integrity protection is applied to PDCP data PDU of signaling radio bearer (SRB), and whether integrity protection is applied to PDCP data PDU transmitted in data radio bearer (DRB) depends on whether integrity protection function is configured for DRB. In addition, integrity protection is not applied to PDCP control PDU.
[0052] Figure 3 shows a flow of integrity protection at PDCP layer. Referring to Figure 3, the sending end can input the following parameters to the integrity protection algorithm: key (Key), count value (COUNT), message (MESSAGE), direction (DIRECTION), bearer identifier (BEARER ID), and then the integrity protection algorithm can generate MAC-I based on the above input parameters. Correspondingly, the receiving end verifies whether integrity protection is successful based on MAC-I using the integrity protection algorithm.
[0053] For example, the integrity protection algorithm can use 128-bit integrity algorithm for 5G (NIA) algorithm (e.g., Snow 3G, AES, ZUC), wherein the input of the NIA algorithm includes the following parameters: message "Message", 128-bit key "Kupint / KRRCint" as KEY, 5-bit bearer identifier "BEARER ID", 1-bit transmission direction "DIRECTION", and 32-bit count value "COUNT". Of course, in the embodiments of the present application, the integrity protection algorithm can use 256-bit NIA.
[0054] In some implementations, the ciphering operation is applied to the data part of the PDCP data PDU and the verification value of the integrity protection (e.g., MAC-I), with reference to FIG. 2 continuing. The ciphering operation is not applied to the PDCP header and the service data adaptation protocol (SDAP) header in the data part of the PDCP. In addition, the ciphering operation is also not applied to the PDCP control PDU.
[0055] FIG. 4 illustrates a flow of the ciphering operation of the PDCP layer. With reference to FIG. 4, the transmitter can input the following parameters to the ciphering algorithm: a key (KEY), a count value (COUNT), a direction (DIRECTION), a bearer identification (BEARER ID), and a length (LENGTH) to generate a key stream (also referred to as a key stream block). Then, the cipher text (also referred to as a cipher text block) is obtained by operating the generated key stream with the text to be encrypted (also referred to as a plain text block). Accordingly, the receiver performs the inverse operation to decrypt the cipher text.
[0056] For example, the ciphering operation can employ a 128-bit encryption algorithm for 5G (NEA) (e.g., Snow 3G, AES, ZUC), in which the input of the NEA algorithm includes the following parameters: a 128-bit key "Kupint / KRRCint" as the KEY, a 5-bit bearer identification "BEARER ID", a 1-bit direction "DIRECTION", a length LENGTH, and a 32-bit count value "COUNT". Of course, in the embodiments of the present application, the integrity protection algorithm can employ a 256-bit NEA.
[0057] Security Principles
[0058] In some scenarios, the following security principles can be followed in the process of ciphering / integrity protection at the PDCP layer: global uniqueness, flexible variability, and non-repeatability.
[0059] In some implementations, global uniqueness can refer to the same initialization vector (IV) should not be used when using the same encryption with the same key, otherwise some or even all security will be lost, i.e., each generated key stream needs to be different from any other key stream generated using the same algorithm and the same key. Therefore, a unique input is needed to generate each key stream, which can include the following information: a message counter maintained by the PDCP entity, a unique ID of the respective radio bearer, and a direction bit (different for uplink and downlink).
[0060] In some implementations, the encryption algorithm / integrity protection algorithm can be collectively referred to as a security algorithm, and accordingly, the flexible variability can refer to parameters other than the key (e.g., COUNT, bearer identification, etc.) input into the security algorithm, which can be filled into the IV (e.g., the IV in ZUK is 128 bits), and in addition, the length of the parameters input into the security algorithm can be flexibly varied.
[0061] In some implementations, non-repeatability can refer to the fact that a security operation (e.g., an encryption operation / integrity protection operation) cannot be repeated, i.e., if the PDCP layer performs a security operation on certain data, the MAC layer does not need to repeat the security operation on the data, and vice versa.
[0062] Format of MAC PDU
[0063] FIGS. 5A and 5B are schematic diagrams of the format of a MAC PDU to which embodiments of the present application are applicable. The MAC PDU format shown in FIG. 5A is applicable to downlink transmission. The MAC PDU format shown in FIG. 5B is applicable to uplink transmission.
[0064] In FIGS. 5A and 5B, the MAC PDU can include one or more MAC subPDUs. Among them, the MAC subPDU can be divided into four types: in the first type of MAC subPDU, the MAC subPDU can only include a MAC subheader. In the second type of MAC subPDU, the MAC subPDU can include a MAC subheader and a MAC service data unit (SDU) corresponding to the MAC subheader. In the third type of MAC subPDU, the MAC subPDU can include a MAC subheader and a MAC control element (CE) corresponding to the MAC subheader. In the fourth type of MAC subPDU, the MAC subPDU can include a MAC subheader and padding information.
[0065] Continuing to refer to FIG. 5A and FIG. 5B, the MAC subPDU carrying the MAC CE is usually adjacent to the MAC subPDU carrying the MAC SDU. In the MAC PDU shown in FIG. 5A, the MAC subPDU carrying the MAC CE is located before the MAC subPDU carrying the MAC SDU. In addition, if the MAC PDU contains a MAC subPDU carrying padding information, the MAC subPDU carrying the MAC SDU is located before the MAC subPDU carrying the padding information. In the MAC PDU shown in FIG. 5B, the MAC subPDU carrying the MAC CE is located after the MAC subPDU carrying the MAC SDU. If the MAC PDU contains a MAC subPDU carrying padding information, the MAC subPDU carrying the MAC CE is located before the MAC subPDU carrying the padding information.
[0066] In some implementations, the format of the MAC subheader is as follows: for the MAC subPDU containing a MAC CE of fixed size, and the MAC subPDU containing padding information, the corresponding MAC subheader can only contain two indication fields: a reserved (denoted as “R”) field and a logical channel identification (LCID) field, as shown in FIG. 6A. For other types of MAC subPDU (e.g., the MAC subPDU carrying a MAC CE of variable size), the MAC subheader thereof can contain an R field, an F field, an LCID field, and an L field, as shown in FIG. 6B. The value of the LCID in the LCID field can indicate different types of MAC CEs, that is, different types of MAC CEs can correspond to a specific LCID value. For example, the LCID value corresponding to the MAC CE used to carry a downlink timing advanced command (TAC) is 62.
[0067] MAC CE security threats
[0068] With the development of technology, various types of MAC CEs have been introduced in communication systems. Related security researchers have found that attacks on unprotected MAC CEs are increasing. In some scenarios, attackers can tamper with sensitive information delivered in MAC CEs, causing communication processes to fail. For example, attackers can tamper with the network coordination control (NCC) in lower-layer triggered mobility (LTM), which can cause handover failure. In other scenarios, attackers can steal non-sensitive information delivered in MAC CEs and further extract more information by combining security algorithms, posing a security threat.
[0069] In some scenarios, the MAC CE carrying sensitive information can be referred to as a security-sensitive MAC CE. Currently, the security-sensitive MAC CE can include a downlink LTM MAC CE, a downlink TAC MAC CE, a downlink secondary cell (SCell) activation MAC CE, a downlink SCell deactivation MAC CE, a downlink transmission configuration indication (TCI) state indication MAC CE, and the like. For the downlink LTM MAC CE, the cell information and / or NCC information carried in this type of MAC CE is security-sensitive information. For the downlink TAC MAC CE, the uplink timing advance (TA) adjustment information carried in this type of MAC CE is security-sensitive information, and the location of the terminal device can be derived through the information. For the downlink SCell activation / deactivation MAC CE, the indication information of the SCell carried in this type of MAC CE is security-sensitive information, and tampering with the information can cause the terminal device to generate additional power consumption. For the downlink TCI state indication MAC CE, the TCI state indication carried in this type of MAC CE is security-sensitive information, and tampering with the information can affect the beam information corresponding to the data transmission and reception of the terminal device, affecting the data transmission and reception performance.
[0070] It should be noted that the above only lists some common MAC CEs that may have security risks, and the embodiments of the present application are not limited thereto. For uplink transmission, since it is considered that some key information in future communication systems may be carried on the physical uplink control channel (PUCCH) or the radio resource control (RRC) and transmitted by uplink MAC CE, such as carrying ACK / NACK in PUCCH or UE assistance information (UAI) reporting in RRC, etc., these designs will make the uplink MAC CE also need some security protection mechanism, therefore, the encryption and / or integrity protection mechanism involved in the embodiments of the present application can also be applicable to such MAC CEs.
[0071] Currently, several common security attacks include: TA attack, carrier aggregation attack, and channel status information reference signal (CSI-RS) attack. For the TA attack, an attacker can determine the distance from the terminal device to the network device according to the TA information in the MAC CE, to accurately locate the position of the terminal device. For the carrier aggregation attack, a malicious cell activates the MAC CE to force the terminal device to consume more energy (based on CA energy consumption measurement, when an additional cell is activated, the average current of the terminal device increases by 79%). For the CSI-RS attack, an attacker can attack the MAC CE for indicating activation or deactivation of channel status information (CSI) reporting through a physical uplink control channel (PUCCH) transmission to obtain the CSI{Bi, RSRP} in the PUCCH, causing the position of the terminal device to be exposed.
[0072] As introduced before, the traditional security protection mechanism is to encrypt and / or integrity protect the user plane data packets and control plane data packets of the PDCP layer respectively based on the core network derived key and other related parameters at the PDCP layer. However, this security protection mechanism executed at the PDCP layer has certain limitations and may cause security risks. For example, with the development of technology, multiple types of MAC CEs are introduced, at this time, the security protection mechanism executed at the PDCP layer cannot protect the MAC sub-PDUs carrying the MAC CEs, which may lead to user privacy leakage. For another example, in some scenarios (e.g., ambient internet of things (AIoT)), due to the limited device capability, there can be no radio resource control (RRC), PDCP, radio link control (RLC), and other access stratum (AS) layers, i.e., the highest layer of AS is the MAC layer, at this time, the AIoT data can be carried and transmitted at the MAC layer. In this case, the security protection mechanism executed at the PDCP layer cannot continue to protect the MAC sub-PDUs carrying the MAC SDUs, which may lead to user privacy leakage.
[0073] Therefore, the applicant proposes that encryption and / or integrity protection can be performed for MAC sub-PDUs in a MAC PDU at a MAC layer, wherein the MAC sub-PDUs can include MAC sub-PDUs for carrying MAC SDUs or MAC sub-PDUs for carrying MAC CEs, which can be referred to the above description of FIG. 5A and FIG. 5B.
[0074] In some implementations, the security protection mechanism at the MAC layer can continue to use the encryption and / or integrity protection mechanism of the PDCP to implement encryption and / or integrity protection for the MAC sub-PDUs. As described above, the parameters required in the process of encryption and / or integrity protection at the PDCP layer include a COUNT value and a Bearer ID. However, these two parameters cannot be obtained at the MAC layer, resulting in the inability to continue to use the encryption and / or integrity protection algorithm of the PDCP at the MAC layer.
[0075] Therefore, the applicant proposes that in the process of encryption and / or integrity protection for MAC sub-PDUs at the MAC layer, a first parameter can be introduced, which is helpful to implement encryption and / or integrity protection for MAC sub-PDUs and reduce the possibility of user privacy leakage. The first parameter is used for encryption and / or integrity protection for MAC sub-PDUs in a first MAC PDU at the MAC layer. For example, the first parameter is an input parameter of an algorithm for implementing the above encryption and / or integrity protection function, or in other words, the first parameter is an input parameter of an encryption algorithm and / or an integrity protection algorithm used for encryption and / or integrity protection for MAC sub-PDUs in the first MAC PDU at the MAC layer. The method of wireless communication of the embodiment of the application is described below in conjunction with the schematic flowchart of the method shown in FIG. 7. The method shown in FIG. 7 includes step S710.
[0076] In step S710, the first device sends a first MAC PDU to the second device, and the first MAC PDU carries the above-mentioned first parameter.
[0077] In some implementations, the first device can be a terminal device, and correspondingly, the second device can be a network device, i.e., corresponding to an uplink transmission scenario. Alternatively, the first device can be a network device, and correspondingly, the second device can be a terminal device, i.e., corresponding to a downlink transmission scenario. That is, the scheme of the embodiment of the application can be applied to the uplink transmission process and the downlink transmission process, and the difference between the two is that the arrangement of the MAC sub-PDUs in the first MAC PDU is different (which can be referred to the above description in conjunction with FIG. 5A and FIG. 5B).
[0078] As described above, the first parameter is used for ciphering and / or integrity protection of MAC subPDUs in the first MAC PDU at the MAC layer, and the MAC subPDUs can be used to carry MAC SDUs or MAC CEs. In some implementations, the first parameter is used for ciphering and / or integrity protection of MAC subPDUs carrying MAC CEs in the first MAC PDU at the MAC layer, where the MAC subPDUs carrying MAC CEs in the first MAC PDU can be all the MAC subPDUs carrying MAC CEs in the first MAC PDU, or part of the MAC subPDUs carrying MAC CEs in the first MAC PDU. Of course, in the embodiments of the present application, the first parameter is used for ciphering and / or integrity protection of MAC subPDUs carrying MAC SDUs in the first MAC PDU at the MAC layer.
[0079] It should be noted that if the first parameter is used for ciphering and / or integrity protection of part of the MAC subPDUs carrying MAC CEs in the first MAC PDU at the MAC layer, where the part of the MAC subPDUs can be the MAC subPDUs carrying security-sensitive MAC CEs, which can be referred to the above description.
[0080] Taking the first parameter used for ciphering and / or integrity protection of the MAC subPDUs carrying MAC CEs as an example, the ciphering and / or integrity protection of the first MAC PDU can be divided into three cases. It is assumed that the first MAC PDU contains N MAC subPDUs carrying MAC CEs, and x of the N MAC subPDUs carrying MAC CEs need to be ciphered and / or integrity protected.
[0081] Case 1: N = 0, that is, there is no MAC subPDU carrying MAC CEs in the first MAC PDU, and all the MAC subPDUs in the first MAC PDU are used to carry MAC SDUs and / or padding information. In this case, ciphering and / or integrity protection operation can not be performed on the MAC subPDUs in the first MAC PDU.
[0082] Case 2: N > 0 and x < N, that is, part of the MAC subPDUs in the first MAC PDU carry MAC CEs. In this case, ciphering and / or integrity protection operation can be performed on the part of the MAC subPDUs carrying MAC CEs.
[0083] Case 3: N > 0 and x = N, that is, all the MAC subPDUs in the first MAC PDU carry MAC CEs. In this case, ciphering and / or integrity protection operation can be performed on all the MAC subPDUs.
[0084] In some implementations, the first parameter comprises a first identifier and / or a second identifier. The first identifier and the second identifier in the embodiments of the present application are introduced as follows.
[0085] The first identifier is used to identify the first MAC PDU.
[0086] In the embodiments of the present application, by introducing the first identifier at the MAC layer, similar to the bearer identifier used by the PDCP layer encryption / integrity protection, it is helpful to continue using the encryption and / or integrity protection algorithm used by the PDCP layer at the MAC layer to implement the encryption and / or integrity protection process for the MAC sub-PDU.
[0087] For example, the first identifier can comprise one or more of the following: an identifier of the first MAC PDU, an index of the first MAC PDU, a COUNT value corresponding to the first MAC PDU. Therefore, the first identifier is also called a MAC PDU identifier (MAC PDU ID), a MAC PDU index (MAC PDU Index) or a COUNT value.
[0088] The first identifier in the embodiments of the present application is introduced above, and the bearer mode of the first identifier in the embodiments of the present application is introduced as follows. In some implementations, the first identifier is carried in a first field, and the first field is located before other fields in the first MAC PDU, and the other fields are fields in the first MAC PDU other than the first field, which is helpful for the receiving end to obtain the first identifier as soon as possible. For example, the first field can be located in the MAC PDU header of the first MAC PDU.
[0089] For example, referring to FIG. 8, the first MAC PDU comprises the first identifier and N MAC sub-PDUs: MAC sub-PDU1, MAC sub-PDU2, …, MAC sub-PDU N, wherein N is an integer greater than 1, and the MAC sub-PDU2 in the N MAC sub-PDUs is a MAC sub-PDU that has been integrity protected and / or encrypted at the MAC layer. Accordingly, the first field carrying the first identifier in the first MAC PDU is earlier than the field carrying the N MAC sub-PDUs.
[0090] In other implementations, the first identifier is carried in a first field, and the first field is located in the first MAC sub-header of the first MAC PDU, or in other words, the first field is located in the MAC sub-header of the first MAC sub-PDU of the first MAC PDU, wherein the first MAC sub-PDU can be understood as the earliest transmitted MAC sub-PDU among the MAC sub-PDUs contained in the first MAC PDU.
[0091] For example, referring to FIG. 9, the first MAC PDU includes a first identifier and N MAC subPDUs: MAC subPDU1, MAC subPDU2, …, MAC subPDU N, where N is an integer greater than 1, and the MAC subPDU2 in the N MAC subPDUs is a MAC subPDU that is integrity protected and / or ciphered at the MAC layer. Accordingly, the first field carrying the first identifier in the first MAC PDU can be located in the MAC subheader corresponding to the MAC subPDU1.
[0092] The second identifier is used to identify the MAC subPDU in the first MAC PDU.
[0093] In the embodiments of the present application, by introducing the second identifier at the MAC layer, similar to the COUNT used by the PDCP layer for ciphering / integrity protection, it is helpful to use the ciphering and / or integrity protection algorithm of the PDCP at the MAC layer to implement the ciphering and / or integrity protection process for the MAC subPDU.
[0094] In the embodiments of the present application, the implementation of the second identifier is not limited. In some implementations, the second identifier can include one or more of the following: an identifier of the MAC subPDU, an index of the MAC subPDU, and a COUNT value corresponding to the MAC subPDU. Therefore, the second identifier is also referred to as a MAC subPDU identifier (MAC subPDU ID), a MAC subPDU index (MAC subPDU Index), or a COUNT value. Of course, in the embodiments of the present application, different types of MAC CEs correspond to different LCIDs, and therefore, the LCID can be reused as the second identifier, that is, the second identifier can be the LCID contained in the MAC subheader of the MAC subPDU, which helps to reduce the overhead required for transmitting the second identifier.
[0095] In the embodiments of the present application, the type of the second identifier is not limited. In some implementations, the second identifier is used to distinguish the MAC subPDU in all MAC PDUs to be transmitted, and at this time, the second identifier can be understood as a global identifier, which is used to uniquely identify the MAC subPDU in all MAC PDUs. Therefore, in the embodiments of the present application, the second identifier can also be referred to as a “MAC subPDU global identifier (MAC subPDU Global ID)”. In other implementations, the second identifier is used to distinguish the MAC subPDU in the first MAC PDU, and at this time, the second identifier can be understood as a local identifier.
[0096] The implementation of the second identifier in the embodiments of the present application is introduced above, and the bearing mode of the second identifier in the embodiments of the present application is introduced below. In some implementations, the second identifier is carried in a second field, and the second field is located in the MAC subheader corresponding to the MAC subPDU.
[0097] In some implementations, the second identifier can occupy a new field in the MAC subheader. For example, referring to FIG. 10A, assuming that the second identifier is a global identifier of the MAC subPDU2, the first MAC PDU includes N MAC subPDUs: MAC subPDU1, MAC subPDU2, …, MAC subPDU N, where N is an integer greater than 1, and the MAC subPDU2 in the N MAC subPDUs is a MAC subPDU that is integrity protected at the MAC layer, the MAC subPDU2 is used to carry the MAC CE, and the verification value used to verify the integrity of the MAC subPDU2 is MAC-I. Accordingly, the first field carrying the second identifier in the first MAC PDU can be located in the MAC subheader corresponding to the MAC subPDU2, that is, the MAC subheader includes the R field, the LCID field, and the field for carrying the second identifier.
[0098] In other implementations, if the second identifier is an LCID, the second identifier can occupy the LCID field in the MAC subheader. That is, the field for carrying the second identifier can reuse a known field in the MAC subheader. For example, referring to FIG. 10B, assuming that the second identifier is the LCID corresponding to the MAC subPDU2, the first MAC PDU includes N MAC subPDUs: MAC subPDU1, MAC subPDU2, …, MAC subPDU N, where N is an integer greater than 1, and the MAC subPDU2 in the N MAC subPDUs is a MAC subPDU that is integrity protected at the MAC layer, the MAC subPDU2 is used to carry the MAC CE, and the verification value used to verify the integrity of the MAC subPDU2 is MAC-I. Accordingly, the first field carrying the second identifier in the first MAC PDU can correspond to the LCID field in the MAC subheader corresponding to the MAC subPDU2, that is, the MAC subheader includes the R field and the LCID field.
[0099] In some scenarios, the implementation of the first parameter can be different for the two cases of the second identifier being a global identifier or a local identifier. In some implementations, if the second identifier is a local identifier, that is, used to distinguish the MAC subPDUs in the first MAC PDU, the first parameter can include the first identifier and the second identifier, that is, the first identifier uniquely identifies the MAC subPDU together with the second identifier. At this time, using the first identifier and the second identifier to encrypt and / or integrity protect the MAC subPDU helps to make the encrypted and / or integrity protected MAC subPDU globally unique, so as to improve the security of the MAC subPDU.
[0100] Taking the second identifier as a local identifier as an example, the second identifier can be the LCID introduced in the foregoing. Of course, in embodiments of the present application, the second identifier can also be other implementation forms.
[0101] In some other implementation modes, if the second identifier is a global identifier, i.e., used to distinguish MAC subPDUs in all MAC PDUs to be transmitted, the first parameter only includes the second identifier. That is to say, the second identifier itself can uniquely identify the MAC subPDU. At this time, using the second identifier to encrypt and / or integrity protect the MAC subPDU helps to make the encrypted and / or integrity protected MAC subPDU satisfy global uniqueness, so as to improve the security of the MAC subPDU. In addition, in embodiments of the present application, the second identifier can be used to uniquely identify the MAC subPDU, which helps to reduce the overhead required for transmitting the first parameter.
[0102] For example, the transmitted MAC subPDUs can be sequentially numbered, and correspondingly, the number of the MAC subPDU is the second identifier. Assuming that the MAC PDU sent by the first device to the second device includes MAC PDU1 and MAC PDU2, and correspondingly, the MAC subPDUs included in the MAC PDU1 are MAC subPDU1-MAC subPDU i, and the MAC subPDUs included in the MAC PDU2 are MAC subPDU i+1-MAC subPDU N, where i is a positive integer greater than or equal to 1 and less than N. Correspondingly, the sending order of the MAC subPDUs in the MAC PDU1 and the MAC PDU2 from early to late (or from front to back) is MAC subPDU1, MAC subPDU2, …, MAC subPDU N, and correspondingly, the second identifier of the MAC subPDU1 is 1, the second identifier of the MAC subPDU2 is 2, and the second identifier of the MAC subPDU N is N.
[0103] In some other implementation modes, only one MAC PDU can contain a MAC CE in a certain period of time, and when the next MAC PDU carrying the MAC CE needs to be transmitted, the key has been updated, and the generated keystream is naturally different, which conforms to the security principle. At this time, the first parameter only includes the second identifier, and does not include the first identifier. For example, in the LTM scenario, only one MAC PDU can contain a MAC CE in a certain period of time, so there is no need to identify the identifier of the MAC PDU (i.e., the first identifier), and when the next LTM MAC CE appears, the key can have been updated, and the generated keystream is naturally different, which conforms to the security principle. At this time, the first parameter can only include the second identifier.
[0104] In some implementations, the first indication information can be carried in the first MAC PDU. Of course, in the embodiments of the present application, the first indication information can be sent separately before the first MAC PDU. Taking the first indication information being carried in the first MAC PDU as an example, in some implementations, the first indication information is carried in a third field, and the third field is located before the field carrying the first identifier in the first MAC PDU.
[0105] As introduced before, the first identifier can be carried in the first MAC PDU and sent to the second device. However, for the MAC PDU without encryption and / or integrity protection, the first identifier is usually not carried in this type of MAC PDU. Therefore, in order to facilitate the second device to distinguish the two different MAC PDUs, the first device can send the first indication information to the second device to indicate whether the first identifier is carried in the first MAC PDU, or in other words, the first indication information is used to indicate whether the first MAC PDU is encrypted and / or integrity protected.
[0106] That is to say, the above method further includes: the first device sends the first indication information to the second device, and the first indication information is used to indicate whether the first identifier is carried in the first MAC PDU.
[0107] In some implementations, the first indication information can be carried in the first MAC PDU. Of course, in the embodiments of the present application, the first indication information can be sent separately before the first MAC PDU. Taking the first indication information being carried in the first MAC PDU as an example, in some implementations, the first indication information is carried in a third field, and the third field is located before the field carrying the first identifier in the first MAC PDU.
[0108] For example, referring to FIG. 11, the first MAC PDU includes the first indication information, the first identifier, and N MAC sub-PDUs: MAC sub-PDU1, MAC sub-PDU2, …, MAC sub-PDUN, where N is an integer greater than 1, and the MAC sub-PDU2 in the N MAC sub-PDUs is the MAC sub-PDU which is integrity protected and / or encrypted at the MAC layer. Accordingly, the first field carrying the first identifier in the first MAC PDU is earlier than the field carrying the N MAC sub-PDUs, and the third field is earlier than the first field in the first MAC PDU.
[0109] In some implementations, the first indication information can be carried in the first MAC PDU. Of course, in the embodiments of the present application, the first indication information can be sent separately before the first MAC PDU. Taking the first indication information being carried in the first MAC PDU as an example, in some implementations, the first indication information is carried in a third field, and the third field is located before the field carrying the first identifier in the first MAC PDU.
[0110] In the embodiments of the present application, the carrying manner of the first indication information is not limited. For example, the first indication information can be newly defined information, and is carried before the first MAC sub-PDU in the first MAC PDU, wherein the first MAC sub-PDU can be understood as the earliest transmitted MAC sub-PDU among the MAC sub-PDUs contained in the first MAC PDU. For another example, the first indication information can be to change the reserved field "R" in the first MAC sub-PDU into a field "S", and S is used to carry the first indication information.
[0111] As introduced above, the second identifier can be carried in the first MAC PDU and transmitted to the second device. However, for the MAC PDU without encryption and / or integrity protection, the second identifier is generally not carried in this type of MAC PDU. Therefore, in order to facilitate the second device to distinguish the two different MAC PDUs, the first device can send the second indication information to the second device to indicate whether the MAC sub-PDU is encrypted and / or integrity protected, or to indicate all the MAC sub-PDUs in the first MAC PDU that are encrypted and / or integrity protected.
[0112] That is to say, the above method further includes: the first device sends the second indication information to the second device, the second indication information is used to indicate whether the MAC sub-PDU is encrypted and / or integrity protected, or the second indication information is used to indicate all the MAC sub-PDUs in the first MAC PDU that are encrypted and / or integrity protected.
[0113] In the embodiments of the present application, the transmission manner of the second indication information is not limited. In some implementation manners, the second indication information can be carried in the first MAC PDU. Of course, in the embodiments of the present application, the second indication information can also be information transmitted independently.
[0114] In some implementation manners, if the second indication information is used to indicate whether the MAC sub-PDU is encrypted and / or integrity protected, the second indication information is carried in the MAC sub-header corresponding to the MAC sub-PDU. Or in other words, the second indication information carried in the MAC sub-header corresponding to the MAC sub-PDU is used to indicate whether the MAC sub-PDU is encrypted and / or integrity protected.
[0115] In another implementation manner, if the second indication information is used to indicate all the MAC sub-PDUs in the first MAC PDU that are encrypted and / or integrity protected, the second indication information is carried in the third field, and the third field is located before the field carrying the first identifier in the first MAC PDU. Of course, in the embodiments of the present application, if the first indication information is also carried in the third field, the first indication information and the second indication information are carried in one field.
[0116] In the embodiments of the present application, the implementation of the second indication information is not limited. In some implementations, the second indication information can be indicated by a bitmap, where each bit in the bitmap can correspond to one MAC sub-PDU in the first MAC PDU respectively, and the value of each bit is used to indicate whether the corresponding MAC sub-PDU is encrypted and / or integrity protected. In some implementations, if the value of the bit is a first value, it indicates that the corresponding MAC sub-PDU is encrypted and / or integrity protected, and if the value of the bit is a second value, it indicates that the corresponding MAC sub-PDU is not encrypted and / or integrity protected, where the first value is different from the second value, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.
[0117] In some scenarios, if the first MAC PDU is a MAC PDU that is encrypted and / or integrity protected, it is usually necessary to indicate which MAC sub-PDUs in the first MAC PDU are encrypted and / or integrity protected and which are not encrypted and / or integrity protected MAC sub-PDUs in combination with the second indication information. That is, the second indication information and the first identifier can be carried in the first MAC PDU at the same time. At this time, the first indication information can be used to indicate whether the second indication and the first identifier are carried in the first MAC PDU at the same time.
[0118] For example, referring to FIG. 12, it is assumed that the first indication information is also called MAC PDU ID indication, and the first identifier is also called MAC PDU ID. The first MAC PDU includes the MAC PDU ID indication, the MAC PDU ID, the second indication information, and N MAC sub-PDUs, where the N MAC sub-PDUs can include MAC sub-PDU1, MAC sub-PDU2, …, MAC sub-PDU N. The MAC PDU ID indication is used to indicate that the first MAC PDU is encrypted and / or integrity protected. The MAC PDU ID is used to identify the MAC PDU. The second indication information is used to indicate whether the corresponding MAC sub-PDU is encrypted and / or integrity protected by N bits in the bitmap.
[0119] It should be noted that in the embodiments of the present application, the second indication information can be adjacent to the first indication information (for example, MAC PDU indication) (see FIG. 12). This is because the first indication information indicates whether the first MAC PDU includes a MAC subPDU that is integrity protected. At this time, the receiving end does not know which MAC subPDU is integrity protected, and therefore the second indication information can be read immediately to determine which MAC subPDU in the first MAC PDU is integrity protected.
[0120] In the embodiments of the present application, the carrying manner of the first indication information and the second indication information is not limited. For example, the first indication information and the second indication information can be designed as a single MAC subPDU, and at this time, the first indication information can be a special LCID.
[0121] The above introduces the first parameter, the first indication information and the second indication information in the embodiments of the present application. The following introduces the encryption and / or integrity protection of the first MAC PDU in the embodiments of the present application.
[0122] In some implementations, the integrity protection of the MAC subPDU in the first MAC PDU includes integrity protection of the MAC CE or MAC SDU carried in the MAC subPDU and the MAC subheader corresponding to the MAC subPDU, as shown in FIG. 13.
[0123] In other implementations, if the first identifier is carried in the MAC PDU header of the first MAC PDU, the integrity protection of the MAC subPDU in the first MAC PDU includes integrity protection of the MAC PDU header, the MAC CE or MAC SDU carried in the MAC subPDU and the MAC subheader corresponding to the MAC subPDU.
[0124] In some implementations, the first MAC PDU includes a verification value (for example, MAC-I) for verifying the integrity of the MAC subPDU, and the encryption of the MAC subPDU in the first MAC PDU includes encryption of the MAC CE or MAC SDU carried in the MAC subPDU and the verification value, as shown in FIG. 13.
[0125] In the embodiments of the present application, according to different granularity of encryption and / or integrity protection of the first MAC PDU, there are various implementations, wherein the granularity of encryption and / or integrity protection of the first MAC PDU includes encryption and / or integrity protection of the MAC subPDU respectively, and encryption and / or integrity protection of multiple MAC subPDUs as a whole.
[0126] For example, the MAC sub-PDUs are separately encrypted in the first MAC PDU. For another example, the MAC sub-PDUs are separately integrity protected in the first MAC PDU. For another example, the MAC sub-PDUs are separately encrypted and integrity protected in the first MAC PDU. For the convenience of understanding, the following describes the implementation mode 1 and the implementation mode 2.
[0127] In the implementation mode 1, the MAC sub-PDUs are separately encrypted and / or integrity protected in the first MAC PDU. That is, the first MAC PDU can be encrypted and / or integrity protected in the granularity of the MAC sub-PDUs.
[0128] For example, the MAC sub-PDUs are separately encrypted in the first MAC PDU. For another example, the MAC sub-PDUs are separately integrity protected in the first MAC PDU. For another example, the MAC sub-PDUs are separately encrypted and integrity protected in the first MAC PDU.
[0129] In some implementations, the first MAC PDU includes a fourth field for carrying a verification value for verifying the integrity of the MAC sub-PDUs, and the fourth field is located after and adjacent to the MAC sub-PDUs in the first MAC PDU, as shown in FIG. 13.
[0130] In some implementations, the parameter for integrity protection further includes a second parameter (also referred to as “message “Message””), wherein the second parameter is determined based on the MAC CE of the MAC sub-PDU, the field carrying the first identifier, and the MAC sub-header corresponding to the MAC sub-PDU. Of course, in the embodiments of the present application, if the first identifier is carried in the MAC sub-header corresponding to the MAC sub-PDU, it can be understood that the second parameter can be determined based on the MAC sub-PDU and the MAC sub-header.
[0131] In some implementations, the parameter for encryption further includes a third parameter (also referred to as “length “LENGTH””), and the information length indicated by the third parameter that needs to be encrypted is determined based on the length of the MAC sub-PDU and the length of the verification value corresponding to the MAC sub-PDU, wherein the verification value is used to verify the integrity of the MAC sub-PDU, for example, the verification value can be MAC-I.
[0132] For the convenience of understanding, the following describes the scheme for separately encrypting and / or integrity protecting the MAC sub-PDUs in the embodiments of the present application in combination with the following scenarios of example 1 to example 2.
[0133] Example 1: assuming that the first MAC PDU is as shown in FIG. 8, and the MAC subPDU2 which is integrity protected and ciphered is used to carry the MAC CE. Wherein, the first identifier is used to identify the MAC PDU, and the second identifier is the LCID carried in the MAC subheader of the MAC subPDU2. The LCID carried in the MAC subheader is shown in FIG. 10B. The following describes the scheme for ciphering and integrity protecting the MAC subPDU2 in the embodiments of the present application.
[0134] In some implementations, for the sending end, the order of ciphering and integrity protecting the MAC subPDU in the MAC subPDU2 can be to perform integrity protection on the MAC subPDU first, and then to cipher the MAC subPDU. Correspondingly, for the receiving end, the order of deciphering and integrity protection verification on the MAC subPDU in the first MAC PDU can be to decipher the MAC subPDU2 first, and then to perform integrity protection verification on the MAC subPDU2.
[0135] FIG. 14 is a schematic diagram of integrity protection in the embodiments of the present application. Referring to FIG. 14, for the sending end, the MAC subheader and the MAC CE of the MAC subPDU2 can be integrity protected, wherein the parameters input into the integrity protection algorithm in the process of integrity protection include the following five kinds:
[0136] The key "Key" is generated by a key derivation method similar to the conventional method to obtain a key for integrity protection of the MAC CE.
[0137] The second identifier (also referred to as "MAC subPDU ID") is similar to the COUNT used in the PDCP layer integrity protection process, and is used to distinguish different MAC subPDUs in the same MAC PDU. As described above, the second identifier can be the LCID corresponding to the MAC subPDU2.
[0138] The message "MESSAGE" includes the MAC PDU header (a field used to carry the first identifier), the MAC subheader of the MAC subPDU, and the MAC CE carried in the MAC subPDU.
[0139] The direction "DIRECTION" is used to indicate the direction of transmitting the first MAC PDU as downlink. For example, if the value of the parameter is a first value, it indicates that the direction of the first MAC PDU is downlink. Conversely, if the value of the parameter is a second value, it indicates that the direction of the first MAC PDU is downlink. Wherein, the first value and the second value are different, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.
[0140] The first identifier (also referred to as a MAC PDU ID) is similar to a bearer identifier (BEARER ID) used in a PDCP layer integrity protection process, and is used to distinguish different MAC PDUs.
[0141] Correspondingly, referring to FIG. 14, the above parameters are input into an integrity protection algorithm for calculation, and the MAC-I corresponding to the MAC sub-PDU 2 is obtained, and the MAC-I is placed behind the MAC sub-PDU 2 in the first MAC PDU, as shown in FIG. 13.
[0142] In addition, referring to FIG. 14, for the receiving end, after receiving the first MAC PDU, the above parameters can be input into an integrity protection algorithm to verify the integrity of the MAC sub-PDU 2.
[0143] FIG. 15 is a schematic diagram of encryption in an embodiment of the present application. Referring to FIG. 15, for the sending end, the MAC CE in the MAC sub-PDU 2 and the MAC-I corresponding to the MAC sub-PDU 2 can be encrypted, and the parameters input into the encryption algorithm in the encryption process include the following five kinds:
[0144] The key "Key" is generated by a key derivation method similar to a conventional method, and is a key for integrity protection of the MAC CE.
[0145] The second identifier (also referred to as a MAC sub-PDU ID) is similar to a COUNT value used in a PDCP layer integrity protection process, and is used to distinguish different MAC sub-PDUs in the same MAC PDU. As described above, the second identifier can be an LCID corresponding to the MAC sub-PDU 2.
[0146] The direction "DIRECTION" is used to indicate that the direction of transmitting the first MAC PDU is downlink. For example, if the value of the parameter is a first value, it indicates that the direction of the first MAC PDU is downlink. Conversely, if the value of the parameter is a second value, it indicates that the direction of the first MAC PDU is downlink. The first value and the second value are different, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.
[0147] The first identifier (also referred to as a MAC PDU ID) is similar to a bearer identifier (BEARER ID) used in a PDCP layer integrity protection process, and is used to distinguish different MAC PDUs.
[0148] LENGTH, similar to the parameter "LENGTH" used in the PDCP layer encryption process, the length of information to be encrypted indicated by the parameter is determined based on the length of the MAC subPDU and the length of the verification value corresponding to the MAC subPDU. The introduction of the parameter makes the length of the generated key stream consistent with the length of the plaintext.
[0149] Correspondingly, referring to FIG. 15, the above parameters are input into the encryption algorithm for calculation, and the key stream block corresponding to the MAC subPDU 2 can be obtained. Then, the plaintext block can be encrypted by using the key stream block to obtain the ciphertext block. In addition, referring to FIG. 15, for the receiving end, after receiving the first MAC PDU, the MAC subPDU 2 and the verification value corresponding to the MAC subPDU 2 can be decrypted by using the inverse operation.
[0150] Example 2: Assuming that the first MAC PDU is as shown in FIG. 10A, and the MAC subPDU for integrity protection in the first MAC PDU is the MAC subPDU 2, the MAC subPDU 2 is used to carry the MAC CE. The second identifier is the global identifier of the MAC subPDU 2 (also referred to as "MAC subPDU global identifier (MAC subPDU Global ID)"), and the MAC subheader of the MAC subPDU carrying the MAC CE. The following describes the scheme for encrypting and integrity protecting the MAC subPDU 2 in the embodiment of the application.
[0151] In some implementations, for the sending end, the order of encrypting and integrity protecting the MAC subPDU 2 in the first MAC PDU can be to perform integrity protection on the MAC subPDU 2 first, and then encrypt the MAC subPDU 2. Correspondingly, for the receiving end, the order of decrypting and integrity protection verifying the MAC subPDU in the first MAC PDU can be to decrypt the MAC subPDU 2 first, and then perform integrity protection verification on the MAC subPDU 2.
[0152] FIG. 16 is a schematic diagram of integrity protection in the embodiment of the application. Referring to FIG. 16, for the sending end, the MAC subheader of the MAC subPDU carrying the MAC CE and the MAC CE can be integrity protected. The parameters input into the integrity protection algorithm in the process of integrity protection include the following four kinds:
[0153] Key "Key", which is generated by a key derivation method similar to the traditional method, is a key for integrity protection of the MAC CE.
[0154] MAC sub-PDU global identity, similar to the COUNT value used in the PDCP layer integrity protection process and the BEARER ID, used to uniquely identify a MAC sub-PDU.
[0155] Message, including the MAC sub-header of the MAC sub-PDU 2 and the MAC CE carried in the MAC sub-PDU 2.
[0156] Direction, used to indicate the direction of transmitting the first MAC PDU is downlink. For example, if the value of the parameter is a first value, it indicates that the direction of the first MAC PDU is downlink. Conversely, if the value of the parameter is a second value, it indicates that the direction of the first MAC PDU is downlink. Wherein the first value and the second value are different, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.
[0157] Correspondingly, referring to FIG. 16, the above parameters are input into the integrity protection algorithm for calculation, and the MAC-I corresponding to the MAC sub-PDU can be obtained, and the MAC-I is placed after the MAC sub-PDU 2 in the first MAC PDU, as shown in FIG. 13.
[0158] In addition, continuing to refer to FIG. 16, for the receiving end, after receiving the first MAC PDU, the above parameters can be input into the integrity protection algorithm for verification.
[0159] FIG. 17 is a schematic diagram of encryption in the embodiment of the present application. Referring to FIG. 17, for the sending end, the MAC CE carried in the MAC sub-PDU and the MAC-I corresponding to the MAC sub-PDU can be encrypted, wherein the parameters input into the encryption algorithm in the encryption process include the following four kinds:
[0160] Key, which is generated by a key derivation method similar to the traditional method, and is a key for integrity protection of the MAC CE.
[0161] MAC sub-PDU global identity, similar to the COUNT value used in the PDCP layer integrity protection process and the BEARER ID, used to uniquely identify a MAC sub-PDU.
[0162] DIRECTION, used to indicate the direction of the first MAC PDU is downlink. For example, if the parameter takes a first value, it means that the direction of the first MAC PDU is downlink. Conversely, if the parameter takes a second value, it means that the direction of the first MAC PDU is downlink. Wherein the first value and the second value are different, for example, the first value is 1, and the second value is 0. For another example, the first value is 0, and the second value is 1.
[0163] LENGTH, similar to the parameter "LENGTH" used in the PDCP layer encryption process, the length of the information to be encrypted indicated by the parameter is determined based on the length of the MAC sub-PDU and the length of the verification value corresponding to the MAC sub-PDU. The introduction of this parameter makes the length of the generated key stream consistent with the length of the plaintext.
[0164] Correspondingly, referring to FIG. 17, the above parameters are input into the encryption algorithm for calculation, and the key stream block corresponding to the MAC sub-PDU 2 can be obtained. Then, the plaintext block can be encrypted using the key stream block to obtain the ciphertext block. In addition, referring to FIG. 17, for the receiving end, after receiving the first MAC PDU, the MAC sub-PDU 2 can be decrypted using the inverse operation.
[0165] Implementation 2: The first MAC PDU is encrypted for multiple MAC PDUs together. That is, the first MAC PDU can be encrypted in multiple MAC sub-PDU granularity.
[0166] It should be noted that the integrity protection process of the first MAC PDU in the above implementation 2 is not limited. For example, the first MAC PDU is encrypted for multiple MAC sub-PDUs together, and the first MAC PDU is integrity protected for multiple MAC sub-PDUs together. For another example, the first MAC PDU is encrypted for multiple MAC sub-PDUs together, and each of the multiple MAC sub-PDUs is integrity protected separately.
[0167] In some implementations, the parameters for encryption further include a third parameter (also referred to as "LENGTH"). The length of the information to be encrypted indicated by the third parameter is determined based on the total length of the sub-PDUs corresponding to the multiple MAC sub-PDUs and the total length of the verification values corresponding to the multiple MAC sub-PDUs. The verification value is used to verify the integrity of the MAC sub-PDU, for example, the verification value can be the MAC-I introduced above.
[0168] It should be noted that in the embodiments of the present application, if the granularity of encryption and integrity protection for the first MAC PDU is different, the implementation manner of the first parameter can be slightly different. In some implementation manners, if the integrity protection is performed for each MAC sub-PDU in the first MAC PDU, and the encryption is performed for all MAC sub-PDUs in the first MAC PDU together, the first parameter for encryption includes the first identifier, and the first parameter for integrity protection includes the first identifier and the second identifier. This is because the encryption is performed for all MAC sub-PDUs in the first MAC PDU as a whole, and therefore, the second identifier can not be introduced to distinguish each MAC sub-PDU.
[0169] For ease of understanding, the following describes the scheme of performing encryption for all MAC sub-PDUs in the first MAC PDU as a whole in the embodiments of the present application, taking the following line scene of Example 3 as an example.
[0170] Example 3: Assuming that the first MAC PDU is as shown in FIG. 10B, and the integrity protection MAC sub-PDU 2 is used to carry the MAC CE. The first identifier is used to identify the MAC PDU, and the carrying manner thereof is shown in FIG. 8, and the second identifier is used to identify the MAC sub-header of the MAC sub-PDU carrying the MAC CE. The following describes the scheme of performing encryption and integrity protection for the first MAC PDU in the embodiments of the present application.
[0171] In some implementation manners, for the sending end, the order of performing encryption and integrity protection for the MAC sub-PDUs in the first MAC PDU can be that the integrity protection is first performed for the MAC sub-PDU 2, and then the encryption is performed for all MAC sub-PDUs together. Correspondingly, for the receiving end, the order of performing decryption and integrity protection verification for the MAC sub-PDUs in the first MAC PDU can be that the decryption is first performed for all MAC sub-PDUs together, and then the integrity protection verification is performed for the MAC sub-PDU 2.
[0172] FIG. 18 is a schematic diagram of performing integrity protection in the embodiments of the present application. Referring to FIG. 18, for the sending end, the MAC sub-header and the MAC CE of the MAC sub-PDU 2 can be subjected to integrity protection, wherein the parameters input into the integrity protection algorithm in the process of performing integrity protection include the following five kinds:
[0173] The key “Key” is used to generate an integrity protection key for the MAC CE through a key derivation manner similar to the conventional manner.
[0174] The second identifier (also referred to as "MAC sub-PDU ID") is similar to the COUNT value "COUNT" used in the PDCP layer integrity protection process, and is used to distinguish different MAC sub-PDUs in the same MAC PDU.
[0175] The message "MESSAGE" includes a MAC PDU header (a field used to carry the first identifier), a MAC sub-header of the MAC sub-PDU, and a MAC CE carried in the MAC sub-PDU.
[0176] The direction "DIRECTION" is used to indicate the direction of the first MAC PDU, which is downlink. For example, if the value of the parameter is a first value, it indicates that the direction of the first MAC PDU is downlink. Conversely, if the value of the parameter is a second value, it indicates that the direction of the first MAC PDU is downlink. The first value and the second value are different, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.
[0177] The first identifier (also referred to as "MAC PDU ID") is similar to the BEARER ID used in the PDCP layer integrity protection process, and is used to distinguish different MAC PDUs.
[0178] Correspondingly, referring to FIG. 18, the above parameters are input into the integrity protection algorithm for calculation, and the MAC-I corresponding to the MAC sub-PDU 2 can be obtained, and the MAC-I is placed after the MAC sub-PDU 2 in the first MAC PDU, as shown in FIG. 13.
[0179] In addition, continuing to refer to FIG. 18, for the receiving end, after receiving the first MAC PDU, the above parameters can be input into the integrity protection algorithm for verification.
[0180] FIG. 19 is a schematic diagram of encryption in the embodiment of the present application. Referring to FIG. 19, for the sending end, the MAC-I corresponding to the MAC sub-PDU 2 and all the MAC sub-PDUs (i.e., N MAC sub-PDUs) in the first MAC PDU can be encrypted as a whole, and the parameters input into the encryption algorithm in the encryption process include the following four kinds:
[0181] The key "Key" is generated by a key derivation method similar to the traditional method, and is a key for integrity protection of the MAC CE.
[0182] DIRECTION, used to indicate the direction of the first MAC PDU is downlink. For example, if the parameter takes a first value, it means that the direction of the first MAC PDU is downlink. Conversely, if the parameter takes a second value, it means that the direction of the first MAC PDU is downlink. Wherein the first value and the second value are different, for example, the first value is 1, and the second value is 0. For another example, the first value is 0, and the second value is 1.
[0183] The first identifier (also referred to as MAC PDU ID) is similar to the bearer identifier (BEARER ID) used in the PDCP layer integrity protection process, and is used to distinguish different MAC PDUs.
[0184] LENGTH, similar to the parameter LENGTH used in the PDCP layer encryption process, the length of the information to be encrypted indicated by the parameter is determined based on the length of the N MAC sub-PDUs and the length of the verification value corresponding to the MAC sub-PDU2. The introduction of this parameter makes the length of the generated keystream consistent with the length of the plaintext.
[0185] Correspondingly, referring to FIG. 19, the above parameters are input into the encryption algorithm for calculation, and the keystream block corresponding to the MAC sub-PDU can be obtained. Then, the plaintext block can be encrypted using the keystream block to obtain the ciphertext block. In addition, referring to FIG. 19, for the receiving end, after receiving the first MAC PDU, the first MAC PDU can be decrypted using the inverse operation.
[0186] The above describes the method embodiments of the present application in detail in combination with FIGS. 1-19. The following describes the device embodiments of the present application in detail in combination with FIGS. 20-22. It should be understood that the description of the method embodiments corresponds to the description of the device embodiments, and therefore, the parts not described in detail can be referred to the previous method embodiments.
[0187] FIG. 20 is a schematic diagram of a communication device in an embodiment of the present application. The communication device 2000 shown in FIG. 20 is a first device, and the communication device 2000 includes a sending unit 2010.
[0188] The sending unit 2010 is configured to send a first MAC PDU to a second device, the first MAC PDU carrying a first parameter, the first parameter being used for encryption and / or integrity protection of MAC sub-PDUs in the first MAC PDU at the MAC layer, wherein the first parameter includes a first identifier and / or a second identifier, the first identifier being used to identify the first MAC PDU, and the second identifier being used to identify the MAC sub-PDUs in the first MAC PDU.
[0189] In some embodiments, the MAC sub-PDUs in the first MAC PDU include a MAC sub-PDU for carrying a MAC SDU and / or a MAC sub-PDU for carrying a MAC CE.
[0190] In some embodiments, the first identifier is carried in a first field, the first field being located before other fields in the first MAC PDU, the other fields being fields in the first MAC PDU other than the first field.
[0191] In some embodiments, the first identifier is carried in a first field, the first field being located in a first MAC sub-header of the first MAC PDU.
[0192] In some embodiments, the second identifier is carried in a second field, the second field being located in a MAC sub-header corresponding to the MAC sub-PDU.
[0193] In some embodiments, the first identifier includes one or more of: an identifier of the first MAC PDU, an index of the first MAC PDU, a count value corresponding to the first MAC PDU.
[0194] In some embodiments, the second identifier includes one or more of: an LCID corresponding to the MAC sub-PDU; an identifier of the MAC sub-PDU, an index of the MAC sub-PDU, a count value corresponding to the MAC sub-PDU.
[0195] In some embodiments, the second identifier is used to distinguish the MAC sub-PDU among all MAC PDUs to be transmitted; or the second identifier is used to distinguish the MAC sub-PDU in the first MAC PDU.
[0196] In some embodiments, the second identifier is used to distinguish the MAC sub-PDU in the first MAC PDU, and the first parameter includes the first identifier and the second identifier.
[0197] In some embodiments, the second identifier is used to distinguish the MAC sub-PDU among all MAC PDUs to be transmitted, and the first parameter includes only the second identifier.
[0198] In some embodiments, if all MAC sub-PDUs in the first MAC PDU are encrypted and / or integrity protected, the first parameter includes only the first identifier.
[0199] In some embodiments, the sending unit is further configured to send, to the second device, first indication information, the first indication information being used to indicate whether the first identifier is carried in the first MAC PDU.
[0200] In some embodiments, the first indication information is carried in a third field, the third field being located in the first MAC PDU before a field carrying the first identifier.
[0201] In some embodiments, the sending unit is further configured to send, to the second device, second indication information, the second indication information being used to indicate whether the MAC subPDU is encrypted and / or integrity protected, or the second indication information being used to indicate all MAC subPDUs in the first MAC PDU that are encrypted and / or integrity protected.
[0202] In some embodiments, the second indication information is used to indicate whether the MAC subPDU is encrypted and / or integrity protected, the second indication information being carried in a MAC subheader corresponding to the MAC subPDU.
[0203] In some embodiments, the second indication information is used to indicate all MAC subPDUs in the first MAC PDU that are encrypted and / or integrity protected, the second indication information being carried in a third field, the third field being located in the first MAC PDU before a field carrying the first identifier.
[0204] In some embodiments, the integrity protection is performed separately for each MAC subPDU in the first MAC PDU.
[0205] In some embodiments, the first MAC PDU comprises a fourth field used to carry a verification value for verifying the integrity of the MAC subPDU, the fourth field being located in the first MAC PDU after and adjacent to the MAC subPDU.
[0206] In some embodiments, the parameters for the integrity protection further comprise a second parameter, the second parameter being determined based on the MAC subPDU, a field carrying the first identifier, and a MAC subheader corresponding to the MAC subPDU.
[0207] In some embodiments, the encryption is performed separately for each MAC subPDU in the first MAC PDU.
[0208] In some embodiments, the parameters for the encryption further comprise a third parameter, and a length of information required for the encryption indicated by the third parameter is determined based on a length of a sub-PDU corresponding to the MAC sub-PDU and a length of a verification value corresponding to the MAC sub-PDU, the verification value being used for verifying integrity of the MAC sub-PDU.
[0209] In some embodiments, the encryption is performed together for a plurality of MAC sub-PDUs in the first MAC PDU.
[0210] In some embodiments, the parameters for the encryption further comprise a third parameter, and a length of information required for the encryption indicated by the third parameter is determined based on a total length of the plurality of MAC sub-PDUs and a total length of verification values corresponding to the plurality of MAC sub-PDUs, the verification values being used for verifying integrity of corresponding MAC sub-PDUs in the plurality of MAC sub-PDUs.
[0211] In some embodiments, if the integrity protection is performed separately for MAC sub-PDUs in the first MAC PDU, the first parameters for the encryption comprise a first identifier, and the first parameters for the integrity protection comprise the first identifier and the second identifier.
[0212] In some embodiments, the first MAC PDU comprises a verification value used for verifying integrity of the MAC sub-PDUs, and the encryption of the MAC sub-PDUs in the first MAC PDU comprises encryption of the MAC sub-PDUs and the verification value.
[0213] In some embodiments, the first device is a terminal device, and the second device is a network device; or the first device is a network device, and the second device is a terminal device.
[0214] FIG. 21 is a schematic diagram of a communication device according to an embodiment of the present application. The communication device 2100 shown in FIG. 21 is a second device, and the communication device 2100 comprises a receiving unit 2110.
[0215] The receiving unit 2110 is configured to receive a first MAC PDU sent by a first device, the first MAC PDU carrying first parameters, the first parameters being used for decryption and / or integrity protection of MAC sub-PDUs in the first MAC PDU at a MAC layer, wherein the first parameters comprise a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying the MAC sub-PDUs in the first MAC PDU.
[0216] In some embodiments, the MAC sub-PDUs in the first MAC PDU include a MAC sub-PDU for carrying a MAC SDU and / or a MAC sub-PDU for carrying a MAC CE.
[0217] In some embodiments, the first identifier is carried in a first field, the first field being located before other fields in the first MAC PDU, the other fields being fields in the first MAC PDU other than the first field.
[0218] In some embodiments, the first identifier is carried in a first field, the first field being located in a first MAC sub-header of the first MAC PDU.
[0219] In some embodiments, the second identifier is carried in a second field, the second field being located in a MAC sub-header corresponding to the MAC sub-PDU.
[0220] In some embodiments, the first identifier includes one or more of: an identifier of the first MAC PDU, an index of the first MAC PDU, a count value corresponding to the first MAC PDU.
[0221] In some embodiments, the second identifier includes one or more of: an LCID corresponding to the MAC sub-PDU; an identifier of the MAC sub-PDU, an index of the MAC sub-PDU, a count value corresponding to the MAC sub-PDU.
[0222] In some embodiments, the second identifier is used to distinguish the MAC sub-PDU among all MAC PDUs to be transmitted; or the second identifier is used to distinguish the MAC sub-PDU in the first MAC PDU.
[0223] In some embodiments, the second identifier is used to distinguish the MAC sub-PDU in the first MAC PDU, and the first parameter includes the first identifier and the second identifier.
[0224] In some embodiments, the second identifier is used to distinguish the MAC sub-PDU among all MAC PDUs to be transmitted, and the first parameter includes only the second identifier.
[0225] In some embodiments, if all MAC sub-PDUs in the first MAC PDU are encrypted and / or integrity protected, the first parameter includes only the first identifier.
[0226] In some embodiments, the receiving unit is configured to receive first indication information sent by the first device, the first indication information being used to indicate whether the first identifier is carried in the first MAC PDU.
[0227] In some embodiments, the first indication information is carried in a third field, the third field being located before a field carrying the first identifier in the first MAC PDU.
[0228] In some embodiments, the receiving unit is configured to receive second indication information sent by the first device, the second indication information being used to indicate whether the MAC sub-PDU is encrypted and / or integrity protected, or the second indication information being used to indicate all MAC sub-PDUs in the first MAC PDU that are encrypted and / or integrity protected.
[0229] In some embodiments, the second indication information is used to indicate whether the MAC sub-PDU is encrypted and / or integrity protected, and the second indication information is carried in a MAC sub-header corresponding to the MAC sub-PDU.
[0230] In some embodiments, the second indication information is used to indicate all MAC sub-PDUs in the first MAC PDU that are encrypted and / or integrity protected, and the second indication information is carried in a third field, the third field being located before a field carrying the first identifier in the first MAC PDU.
[0231] In some embodiments, the integrity protection is performed separately for each MAC sub-PDU in the first MAC PDU.
[0232] In some embodiments, the first MAC PDU comprises a fourth field used to carry a verification value for verifying the integrity of the MAC sub-PDU, the fourth field being located after and adjacent to the MAC sub-PDU in the first MAC PDU.
[0233] In some embodiments, the parameters for the integrity protection further comprise a second parameter determined based on the MAC sub-PDU, a field carrying the first identifier, and a MAC sub-header corresponding to the MAC sub-PDU.
[0234] In some embodiments, the encryption is performed separately for each MAC sub-PDU in the first MAC PDU.
[0235] In some embodiments, the parameters for the encryption further comprise a third parameter, and a length of information required for the encryption indicated by the third parameter is determined based on a length of a sub-PDU corresponding to the MAC sub-PDU and a length of a verification value corresponding to the MAC sub-PDU, the verification value being used for verifying integrity of the MAC sub-PDU.
[0236] In some embodiments, the encryption is performed together for a plurality of MAC sub-PDUs in the first MAC PDU.
[0237] In some embodiments, the parameters for the encryption further comprise a third parameter, and a length of information required for the encryption indicated by the third parameter is determined based on a total length of the plurality of MAC sub-PDUs and a total length of verification values corresponding to the plurality of MAC sub-PDUs, the verification values being used for verifying integrity of corresponding MAC sub-PDUs in the plurality of MAC sub-PDUs.
[0238] In some embodiments, if the integrity protection is performed separately for MAC sub-PDUs in the first MAC PDU, the first parameter for the encryption comprises a first identifier, and the first parameter for the integrity protection comprises the first identifier and the second identifier.
[0239] In some embodiments, the first MAC PDU comprises a verification value used for verifying integrity of the MAC sub-PDUs, and the encryption of the MAC sub-PDU in the first MAC PDU comprises encryption of the MAC sub-PDU and the verification value.
[0240] In some embodiments, the first device is a terminal device, and the second device is a network device; or the first device is a network device, and the second device is a terminal device.
[0241] In optional embodiments, the sending unit 2010 can be a transceiver 2230. The communication device 2000 can further include a processor 2210 and a memory 2220, as shown in FIG. 22.
[0242] In optional embodiments, the receiving unit 2110 can be a transceiver 2230. The communication device 2100 can further include a processor 2210 and a memory 2220, as shown in FIG. 22.
[0243] FIG. 22 is a schematic structural diagram of a communication apparatus according to an embodiment of the present application. The dashed line in FIG. 22 indicates that the unit or module is optional. The apparatus 2200 can be used to implement the method described in the above method embodiments. The apparatus 2200 can be a chip, a terminal device, or a network device.
[0244] The apparatus 2200 can include one or more processors 2210. The processor 2210 can support the apparatus 2200 to implement the methods described in the foregoing method embodiments. The processor 2210 can be a general processor or a special-purpose processor. For example, the processor can be a central processing unit (CPU). Alternatively, the processor can also be other general processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic, discrete hardware components, etc. The general processor can be a microprocessor or the processor can also be any conventional processor.
[0245] The apparatus 2200 can also include one or more memories 2220. The memory 2220 stores a program that can be executed by the processor 2210, so that the processor 2210 executes the methods described in the foregoing method embodiments. The memory 2220 can be independent of the processor 2210 or integrated in the processor 2210.
[0246] The apparatus 2200 can also include a transceiver 2230. The processor 2210 can communicate with other devices or chips through the transceiver 2230. For example, the processor 2210 can perform data transceiving with other devices or chips through the transceiver 2230.
[0247] The embodiments of the present application also provide a computer readable storage medium for storing a program. The computer readable storage medium can be applied to the terminal or network device provided by the embodiments of the present application, and the program causes the computer to execute the method performed by the terminal or network device in the various embodiments of the present application.
[0248] The embodiments of the present application also provide a computer program product. The computer program product includes a program. The computer program product can be applied to the terminal or network device provided by the embodiments of the present application, and the program causes the computer to execute the method performed by the terminal or network device in the various embodiments of the present application.
[0249] The embodiments of the present application also provide a computer program. The computer program can be applied to the terminal or network device provided by the embodiments of the present application, and the computer program causes the computer to execute the method performed by the terminal or network device in the various embodiments of the present application.
[0250] It should be understood that the terms "system" and "network" can be used interchangeably in this application. In addition, the terms used in this application are only used to explain the specific embodiments of the application, and are not intended to limit the application. The terms "first", "second", "third", and "fourth" and the like in the specification and claims of the application and the drawings are used to distinguish different objects, and are not used to describe a particular order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion.
[0251] In embodiments of the present application, the term "indicate" can be direct indication or indirect indication, or can represent an associated relationship. For example, A indicates B, which can mean that B can be obtained by A; or A indirectly indicates B, for example, A indicates C, and B can be obtained by C; or A and B have an associated relationship.
[0252] In embodiments of the present application, "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.
[0253] In embodiments of the present application, the term "corresponding" can represent a direct or indirect corresponding relationship between the two, or can represent an associated relationship between the two, or can represent an indication and being indicated, configuration and being configured, and the like.
[0254] In embodiments of the present application, "predefined" or "preconfigured" can be realized by pre-saving corresponding codes, tables or other information that can be used to indicate related information in devices (such as terminal devices and network devices), and the specific implementation manner of the present application is not limited. For example, predefinition can refer to definition in a protocol.
[0255] In embodiments of the present application, the "protocol" can refer to a standard protocol in the field of communication, which can include LTE protocol, NR protocol and related protocols applied to future communication systems, and the present application is not limited thereto.
[0256] In embodiments of the present application, the term "and / or" is only used to describe the association relationship between the associated objects, which means that there can be three relationships, for example, A and / or B, which means that there are three cases of A alone, A and B together, and B alone. In addition, the character " / " in this paper generally represents an "or" relationship between the front and rear associated objects.
[0257] In various embodiments of the present application, the size of the serial number of the above processes does not mean the order of execution, and the execution order of the processes should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0258] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the division of the above-described device embodiments is only a logical function division, and there can be another division manner for actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, or between the different components, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0259] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.
[0260] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically, or two or more units can be integrated into one unit.
[0261] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be read by a computer or a data storage device such as a server, data center and the like integrated with one or more available media sets. The available media can be magnetic media (for example, floppy disk, hard disk, magnetic tape), optical media (for example, digital video disc (DVD)) or semiconductor media (for example, solid state disk (SSD)) and the like.
[0262] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method of wireless communication, comprising: Comprising: A first device sends a first medium access control (MAC) protocol data unit (PDU) to a second device, the first MAC PDU carrying a first parameter, the first parameter being used for encryption and / or integrity protection of a MAC sub-PDU in the first MAC PDU at a MAC layer, wherein the first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying the MAC sub-PDU in the first MAC PDU.
2. The method of claim 1, wherein, The MAC sub-PDU in the first MAC PDU comprises a MAC sub-PDU for carrying a MAC SDU and / or a MAC sub-PDU for carrying a MAC CE.
3. The method of claim 1 or 2, wherein, The first identifier is carried in a first field, the first field being located before other fields in the first MAC PDU, the other fields being fields in the first MAC PDU other than the first field.
4. The method of claim 1 or 2, wherein, The first identifier is carried in a first field, the first field being located in a first MAC sub-header of the first MAC PDU.
5. The method of any one of claims 1-4, wherein, The second identifier is carried in a second field, the second field being located in a MAC sub-header corresponding to the MAC sub-PDU.
6. The method of any one of claims 1-5, wherein, The first identifier comprises one or more of: an identity of the first MAC PDU, an index of the first MAC PDU, a count value corresponding to the first MAC PDU.
7. The method of any one of claims 1-6, wherein, The second identifier comprises one or more of: a logical channel identifier (LCID) corresponding to the MAC sub-PDU; an identity of the MAC sub-PDU, an index of the MAC sub-PDU, a count value corresponding to the MAC sub-PDU.
8. The method of any one of claims 1-7, wherein, The second identifier is used for distinguishing the MAC sub-PDU among all MAC PDUs to be transmitted; or the second identifier is used for distinguishing the MAC sub-PDU in the first MAC PDU.
9. The method of claim 8, wherein, The second identifier is used for distinguishing the MAC sub-PDU in the first MAC PDU, and the first parameter comprises the first identifier and the second identifier.
10. The method of claim 8, wherein, The second identifier is used for distinguishing the MAC sub-PDU among all MAC PDUs to be transmitted, and the first parameter comprises only the second identifier.
11. The method of any one of claims 1-7, wherein, The first parameter comprises only the first identifier if all MAC sub-PDUs in the first MAC PDU are encrypted and / or integrity protected.
12. The method of any one of claims 1-11, wherein, The method further comprises: The first device sends first indication information to the second device, the first indication information being used for indicating whether the first identifier is carried in the first MAC PDU.
13. The method of claim 12, wherein, The first indication information is carried in a third field, the third field being located before a field carrying the first identifier in the first MAC PDU.
14. The method of any one of claims 1-13, wherein, The method further comprises: The first device sends second indication information to the second device, the second indication information being used for indicating whether the MAC sub-PDU is encrypted and / or integrity protected, or The second indication information is used for indicating all MAC subPDUs in the first MAC PDU which are encrypted and / or integrity protected.
15. The method of claim 14, wherein, The second indication information is used for indicating whether the MAC subPDU is encrypted and / or integrity protected, and the second indication information is carried in a MAC subheader corresponding to the MAC subPDU.
16. The method of claim 14, wherein, The second indication information is used for indicating all MAC subPDUs in the first MAC PDU which are encrypted and / or integrity protected, and the second indication information is carried in a third field which is located before a field carrying the first identifier in the first MAC PDU.
17. The method of any one of claims 1-16, wherein, The integrity protection is performed on the MAC subPDUs respectively in the first MAC PDU.
18. The method of claim 17, wherein, The first MAC PDU comprises a fourth field used for carrying a verification value used for verifying the integrity of the MAC subPDUs, and the fourth field is located after and adjacent to the MAC subPDUs in the first MAC PDU.
19. The method of claim 17 or 18, wherein, The parameter used for the integrity protection further comprises a second parameter determined based on the MAC subPDU, the field carrying the first identifier and a MAC subheader corresponding to the MAC subPDU.
20. The method of any one of claims 1-19, wherein, The encryption is performed on the MAC subPDUs respectively in the first MAC PDU.
21. The method of claim 20, wherein, The parameter used for the encryption further comprises a third parameter, and a length of information required to be encrypted indicated by the third parameter is determined based on a length of a subPDU corresponding to the MAC subPDU and a length of a verification value used for verifying the integrity of the MAC subPDU.
22. The method of any one of claims 1-19, wherein, The encryption is performed on the MAC subPDUs together in the first MAC PDU.
23. The method of claim 22, wherein, The parameter used for the encryption further comprises a third parameter, and a length of information required to be encrypted indicated by the third parameter is determined based on a total length of the MAC subPDUs and a total length of verification values corresponding to the MAC subPDUs, the verification values being used for verifying the integrity of the corresponding MAC subPDU in the MAC subPDUs.
24. The method of claim 22 or 23, wherein, If the integrity protection is performed on the MAC subPDUs respectively in the first MAC PDU, the first parameter used for the encryption comprises a first identifier, and the first parameter used for the integrity protection comprises the first identifier and a second identifier.
25. The method of any one of claims 1-24, wherein, The first MAC PDU comprises a verification value used for verifying the integrity of the MAC subPDUs, and the encryption on the MAC subPDU in the first MAC PDU comprises encryption on the MAC subPDU and the verification value.
26. The method of any one of claims 1-25, wherein, The first device is a terminal device, and the second device is a network device; or The first device is a network device, and the second device is a terminal device.
27. A method of wireless communication, the method comprising: Comprise: The second device receives the first MAC PDU sent by the first device, the first MAC PDU carrying a first parameter, the first parameter being used for decrypting and / or integrity protecting a MAC sub-PDU in the first MAC PDU at a MAC layer, The first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying the MAC sub-PDU in the first MAC PDU.
28. The method of claim 27, wherein, The MAC sub-PDU in the first MAC PDU comprises a MAC sub-PDU for carrying a MAC SDU and / or a MAC sub-PDU for carrying a MAC CE.
29. The method of claim 27 or 28, wherein, The first identifier is carried in a first field, the first field being located before other fields in the first MAC PDU, the other fields being fields in the first MAC PDU other than the first field.
30. The method of claim 27 or 28, wherein, The first identifier is carried in a first field, the first field being located in a first MAC sub-header of the first MAC PDU.
31. The method of any one of claims 27-30, wherein, The second identifier is carried in a second field, the second field being located in a MAC sub-header corresponding to the MAC sub-PDU.
32. The method of any one of claims 27-31, wherein, The first identifier comprises one or more of the following: an identifier of the first MAC PDU, an index of the first MAC PDU, and a count value corresponding to the first MAC PDU.
33. The method of any one of claims 27-32, wherein, The second identifier comprises one or more of the following: an LCID corresponding to the MAC sub-PDU, an identifier of the MAC sub-PDU, an index of the MAC sub-PDU, and a count value corresponding to the MAC sub-PDU.
34. The method of any one of claims 27-33, wherein, The second identifier is used for distinguishing the MAC sub-PDU in all MAC PDUs to be transmitted; or the second identifier is used for distinguishing the MAC sub-PDU in the first MAC PDU.
35. The method of claim 34, wherein, The second identifier is used for distinguishing the MAC sub-PDU in the first MAC PDU, and the first parameter comprises the first identifier and the second identifier.
36. The method of claim 34, wherein, The second identifier is used for distinguishing the MAC sub-PDU in all MAC PDUs to be transmitted, and the first parameter comprises only the second identifier.
37. The method of any one of claims 27-33, wherein, If all MAC sub-PDUs in the first MAC PDU are encrypted and / or integrity protected, the first parameter comprises only the first identifier.
38. The method of any one of claims 27-37, wherein, The method further comprises: The second device receives first indication information sent by the first device, the first indication information being used for indicating whether the first identifier is carried in the first MAC PDU.
39. The method of claim 38, wherein, The first indication information is carried in a third field, the third field being located before a field carrying the first identifier in the first MAC PDU.
40. The method of any one of claims 27-39, wherein, The method further comprises: The second device receives second indication information sent by the first device, the second indication information being used for indicating whether the MAC sub-PDU is encrypted and / or integrity protected, or The second indication information is used for indicating all MAC sub-PDUs in the first MAC PDU that are encrypted and / or integrity protected.
41. The method of claim 40, wherein, The second indication information is used for indicating whether the MAC sub-PDU is encrypted and / or integrity protected, and the second indication information is carried in a MAC sub-header corresponding to the MAC sub-PDU.
42. The method of claim 40, wherein, The second indication information is used for indicating all MAC sub-PDUs in the first MAC PDU which are encrypted and / or integrity protected, and the second indication information is carried in a third field which is located before a field carrying the first identifier in the first MAC PDU.
43. The method of any one of claims 27-42, wherein, The integrity protection is performed on the MAC sub-PDUs in the first MAC PDU respectively.
44. The method of claim 43, wherein, The first MAC PDU comprises a fourth field used for carrying a verification value used for verifying the integrity of the MAC sub-PDUs, and the fourth field is located after and adjacent to the MAC sub-PDUs in the first MAC PDU.
45. The method of claim 43 or 44, wherein, The parameter used for the integrity protection further comprises a second parameter determined based on the MAC sub-PDU, the field carrying the first identifier and a MAC sub-header corresponding to the MAC sub-PDU.
46. The method of any one of claims 27-45, wherein, The encryption is performed on the MAC sub-PDUs in the first MAC PDU respectively.
47. The method of claim 46, wherein, The parameter used for the encryption further comprises a third parameter, and a length of information required to be encrypted indicated by the third parameter is determined based on a length of a sub-PDU corresponding to the MAC sub-PDU and a length of a verification value corresponding to the MAC sub-PDU, the verification value being used for verifying the integrity of the MAC sub-PDU.
48. The method of any one of claims 27-45, wherein, The encryption is performed on the MAC sub-PDUs in the first MAC PDU together.
49. The method of claim 48, wherein, The parameter used for the encryption further comprises a third parameter, and a length of information required to be encrypted indicated by the third parameter is determined based on a total length of the MAC sub-PDUs and a total length of verification values corresponding to the MAC sub-PDUs, the verification values being used for verifying the integrity of corresponding MAC sub-PDUs in the MAC sub-PDUs.
50. The method of claim 48 or 49, wherein, If the integrity protection is performed on the MAC sub-PDUs in the first MAC PDU respectively, the first parameter used for the encryption comprises a first identifier, and the first parameter used for the integrity protection comprises the first identifier and a second identifier.
51. The method of any one of claims 27-50, wherein, The first MAC PDU comprises a verification value used for verifying the integrity of the MAC sub-PDUs, and the encryption on the MAC sub-PDUs in the first MAC PDU comprises encryption on the MAC sub-PDUs and the verification value.
52. The method of any one of claims 27-51, wherein, The first device is a terminal device, and the second device is a network device; or The first device is a network device, and the second device is a terminal device.
53. A communications device, characterized by The communication device is a first device, comprising: a sending unit configured to send a first MAC PDU to a second device, the first MAC PDU carrying a first parameter used for encrypting and / or integrity protecting MAC sub-PDUs in the first MAC PDU at a MAC layer, The first parameter includes a first identifier and / or a second identifier, the first identifier is used to identify the first MAC PDU, and the second identifier is used to identify a MAC sub-PDU in the first MAC PDU.
54. The communications device of claim 53, wherein, The MAC sub-PDU in the first MAC PDU includes a MAC sub-PDU used to carry a MAC SDU and / or a MAC sub-PDU used to carry a MAC CE.
55. The communication device of claim 53 or 54, wherein, The first identifier is carried in a first field, and the first field is located before other fields in the first MAC PDU, the other fields being fields in the first MAC PDU other than the first field.
56. The communication device of claim 53 or 54, wherein, The first identifier is carried in a first field, and the first field is located in a first MAC sub-header of the first MAC PDU.
57. The communication device of any of claims 53-56, wherein, The second identifier is carried in a second field, and the second field is located in a MAC sub-header corresponding to the MAC sub-PDU.
58. The communication device of any of claims 53-57, wherein, The first identifier includes one or more of the following: an identifier of the first MAC PDU, an index of the first MAC PDU, and a count value corresponding to the first MAC PDU.
59. The communication device of any of claims 53-58, wherein, The second identifier includes one or more of the following: an LCID corresponding to the MAC sub-PDU, an identifier of the MAC sub-PDU, an index of the MAC sub-PDU, and a count value corresponding to the MAC sub-PDU.
60. The communication device of any of claims 53-59, wherein, The second identifier is used to distinguish the MAC sub-PDU in all MAC PDUs to be transmitted; or the second identifier is used to distinguish the MAC sub-PDU in the first MAC PDU.
61. The communications device of claim 60, wherein, The second identifier is used to distinguish the MAC sub-PDU in the first MAC PDU, and the first parameter includes the first identifier and the second identifier.
62. The communications device of claim 60, wherein, The second identifier is used to distinguish the MAC sub-PDU in all MAC PDUs to be transmitted, and the first parameter includes only the second identifier.
63. The communication device of any of claims 53-59, wherein, If all MAC sub-PDUs in the first MAC PDU are encrypted and / or integrity protected, the first parameter includes only the first identifier.
64. The communication device of any of claims 53-63, wherein, The sending unit is further configured to: send first indication information to the second device, the first indication information being used to indicate whether the first identifier is carried in the first MAC PDU.
65. The communications device of claim 64, wherein, The first indication information is carried in a third field, and the third field is located before a field carrying the first identifier in the first MAC PDU.
66. The communication device of any of claims 53-65, wherein, The sending unit is further configured to: send second indication information to the second device, the second indication information being used to indicate whether the MAC sub-PDU is encrypted and / or integrity protected, or The second indication information is used to indicate all MAC sub-PDUs in the first MAC PDU that are encrypted and / or integrity protected.
67. The communications device of claim 66 wherein, The second indication information is used to indicate whether the MAC sub-PDU is encrypted and / or integrity protected, and the second indication information is carried in a MAC sub-header corresponding to the MAC sub-PDU.
68. The communications device of claim 66 wherein, The second indication information is used for indicating all MAC sub-PDUs in the first MAC PDU which are encrypted and / or integrity protected, and is carried in a third field which is located before a field carrying the first identifier in the first MAC PDU.
69. The communication device of any of claims 53-68, wherein, The integrity protection is performed on the MAC sub-PDUs in the first MAC PDU respectively.
70. The communications device of claim 69, wherein, The first MAC PDU comprises a fourth field used for carrying a verification value for verifying the integrity of the MAC sub-PDUs, and the fourth field is located after and adjacent to the MAC sub-PDUs in the first MAC PDU.
71. The communication device of claim 69 or 70, wherein, The parameter used for the integrity protection further comprises a second parameter determined based on the MAC sub-PDUs, the field carrying the first identifier and a MAC sub-header corresponding to the MAC sub-PDUs.
72. The communication device of any of claims 53-71, wherein, The encryption is performed on the MAC sub-PDUs in the first MAC PDU respectively.
73. The communications device of claim 72, wherein The parameter used for the encryption further comprises a third parameter, and a length of information required to be encrypted indicated by the third parameter is determined based on a length of a sub-PDU corresponding to the MAC sub-PDU and a length of a verification value corresponding to the MAC sub-PDU, the verification value being used for verifying the integrity of the MAC sub-PDU.
74. The communication device of any of claims 53-71, wherein, The encryption is performed on the MAC sub-PDUs in the first MAC PDU together.
75. The communications device of claim 74 wherein, The parameter used for the encryption further comprises a third parameter, and a length of information required to be encrypted indicated by the third parameter is determined based on a total length of the MAC sub-PDUs and a total length of verification values corresponding to the MAC sub-PDUs, the verification values being used for verifying the integrity of corresponding MAC sub-PDUs in the MAC sub-PDUs.
76. The communication device of claim 74 or 75, wherein, If the integrity protection is performed on the MAC sub-PDUs in the first MAC PDU respectively, the first parameter used for the encryption comprises a first identifier, and the first parameter used for the integrity protection comprises the first identifier and the second identifier.
77. The communication device of any of claims 53-76, wherein, The first MAC PDU comprises a verification value used for verifying the integrity of the MAC sub-PDUs, and the encryption on the MAC sub-PDUs in the first MAC PDU comprises encryption on the MAC sub-PDUs and the verification value.
78. The communication device of any of claims 53-77, wherein, The first device is a terminal device, and the second device is a network device; or The first device is a network device, and the second device is a terminal device.
79. A communications device, characterized by The communication device is a second device, comprising: a receiving unit configured to receive a first MAC PDU sent by a first device, the first MAC PDU carrying a first parameter, the first parameter being used for decryption and / or integrity protection on MAC sub-PDUs in the first MAC PDU at a MAC layer, The first parameter includes a first identifier and / or a second identifier, the first identifier is used to identify the first MAC PDU, and the second identifier is used to identify a MAC sub-PDU in the first MAC PDU.
80. The communications device of claim 79 wherein, The MAC sub-PDU in the first MAC PDU includes a MAC sub-PDU used to carry a MAC SDU and / or a MAC sub-PDU used to carry a MAC CE.
81. The communication device of claim 79 or 80, wherein, The first identifier is carried in a first field, and the first field is located before other fields in the first MAC PDU, the other fields being fields in the first MAC PDU other than the first field.
82. The communication device of claim 79 or 80, wherein, The first identifier is carried in a first field, and the first field is located in a first MAC sub-header of the first MAC PDU.
83. The communication device of any of claims 79-82, wherein, The second identifier is carried in a second field, and the second field is located in a MAC sub-header corresponding to the MAC sub-PDU.
84. The communication device of any of claims 79-83, wherein, The first identifier includes one or more of the following: an identifier of the first MAC PDU, an index of the first MAC PDU, and a count value corresponding to the first MAC PDU.
85. The communication device of any of claims 79-84, wherein, The second identifier includes one or more of the following: an LCID corresponding to the MAC sub-PDU, an identifier of the MAC sub-PDU, an index of the MAC sub-PDU, and a count value corresponding to the MAC sub-PDU.
86. The communication device of any of claims 79-85, wherein, The second identifier is used to distinguish the MAC sub-PDU in all MAC PDUs to be transmitted; or the second identifier is used to distinguish the MAC sub-PDU in the first MAC PDU.
87. The communications device of claim 86 wherein, The second identifier is used to distinguish the MAC sub-PDU in the first MAC PDU, and the first parameter includes the first identifier and the second identifier.
88. The communications device of claim 86 wherein, The second identifier is used to distinguish the MAC sub-PDU in all MAC PDUs to be transmitted, and the first parameter includes only the second identifier.
89. The communication device of any of claims 79-85, wherein, If all MAC sub-PDUs in the first MAC PDU are encrypted and / or integrity protected, the first parameter includes only the first identifier.
90. The communication device of any of claims 79-89, wherein, The receiving unit is configured to: receive first indication information sent by the first device, the first indication information being used to indicate whether the first identifier is carried in the first MAC PDU.
91. The communications device of claim 90, wherein, The first indication information is carried in a third field, and the third field is located before a field carrying the first identifier in the first MAC PDU.
92. The communication device of any of claims 79-91, wherein, The receiving unit is configured to: receive second indication information sent by the first device, the second indication information being used to indicate whether the MAC sub-PDU is encrypted and / or integrity protected, or The second indication information is used to indicate all MAC sub-PDUs in the first MAC PDU that are encrypted and / or integrity protected.
93. The communications device of claim 92, wherein, The second indication information is used to indicate whether the MAC sub-PDU is encrypted and / or integrity protected, and the second indication information is carried in a MAC sub-header corresponding to the MAC sub-PDU.
94. The communications device of claim 92, wherein, The second indication information is used for indicating all MAC sub-PDUs in the first MAC PDU which are encrypted and / or integrity protected, and the second indication information is carried in a third field which is located before a field carrying the first identifier in the first MAC PDU.
95. The communication device of any of claims 79-94, wherein, The integrity protection is performed on the MAC sub-PDUs respectively in the first MAC PDU.
96. The communications device of claim 95, wherein, The first MAC PDU comprises a fourth field used for carrying a verification value used for verifying the integrity of the MAC sub-PDUs, and the fourth field is located after and adjacent to the MAC sub-PDUs in the first MAC PDU.
97. The communication device of claim 95 or 96, wherein, The parameter used for the integrity protection further comprises a second parameter determined based on the MAC sub-PDUs, the field carrying the first identifier and a MAC sub-header corresponding to the MAC sub-PDUs.
98. The communication device of any of claims 79-97, wherein, The encryption is performed on the MAC sub-PDUs respectively in the first MAC PDU.
99. The communications device of claim 98 wherein, The parameter used for the encryption further comprises a third parameter, and a length of information required to be encrypted indicated by the third parameter is determined based on a length of a sub-PDU corresponding to the MAC sub-PDU and a length of a verification value corresponding to the MAC sub-PDU, the verification value being used for verifying the integrity of the MAC sub-PDU.
100. The communication device of any of claims 79-97, wherein, The encryption is performed on the MAC sub-PDUs together in the first MAC PDU.
101. The communications device of claim 100, wherein, The parameter used for the encryption further comprises a third parameter, and a length of information required to be encrypted indicated by the third parameter is determined based on a total length of the MAC sub-PDUs and a total length of verification values corresponding to the MAC sub-PDUs, the verification values being used for verifying the integrity of corresponding MAC sub-PDUs in the MAC sub-PDUs.
102. The communication device of claim 100 or 101, wherein, If the integrity protection is performed on the MAC sub-PDUs respectively in the first MAC PDU, the first parameter used for the encryption comprises a first identifier, and the first parameter used for the integrity protection comprises the first identifier and the second identifier.
103. The communication device of any of claims 79-102, wherein, The first MAC PDU comprises a verification value used for verifying the integrity of the MAC sub-PDUs, and the encryption on the MAC sub-PDUs in the first MAC PDU comprises encryption on the MAC sub-PDUs and the verification value.
104. The communication device of any of claims 79-103, wherein, The first device is a terminal device, and the second device is a network device; or The first device is a network device, and the second device is a terminal device.
105. A communications device, characterized by A communication device comprising a transceiver, a memory and a processor, the memory being used for storing a program, the processor being used for invoking the program in the memory and controlling the transceiver to receive or send a signal, so that the communication device performs the method in any one of claims 1-52.
106. An apparatus, comprising: A processor is used for invoking a program from a memory, so that the apparatus performs the method in any one of claims 1-52.
107. A chip, comprising: including a processor to call a program from a memory to cause a device in which the chip is installed to perform the method of any of claims 1-52.
108. A computer readable storage medium, characterized in that, having a program stored thereon, the program causing a computer to perform the method of any of claims 1-52.
109. A computer program product, characterized in that, including a program that causes a computer to perform the method of any of claims 1-52.
110. A computer program characterised in that, The computer program causes a computer to perform the method of any of claims 1-52. The computer program causes a computer to perform the method of any of claims 1-52.
Citation Information
Patent Citations
Communication method and device
CN115696319A
Method and device for applying security technique to mobility mac ce based on l1 / l2 in mobile communication system
WO2024150986A1