Wireless communication methods and communication devices

By introducing an identifier at the MAC layer to achieve integrity protection of the MAC CE, the problem that the traditional PDCP layer protection mechanism cannot protect the MAC CE is solved, thus improving communication security and reducing the risk of user privacy leakage.

WO2026060711A1PCT designated stage Publication Date: 2026-03-26GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-23
Publication Date
2026-03-26

AI Technical Summary

Technical Problem

Traditional security protection mechanisms at the PDCP layer cannot effectively protect MAC CE, leading to security risks during communication. In particular, sensitive information of MAC CE is easily tampered with or stolen, resulting in the leakage of user privacy.

Method used

A first parameter and/or a second identifier are introduced at the MAC layer to achieve integrity protection of the MAC CE in the MAC PDU. These identifiers are used to carry out the integrity protection algorithm of the PDCP layer at the MAC layer to ensure the integrity of the MAC CE.

Benefits of technology

By protecting the integrity of MAC CE at the MAC layer, the possibility of user privacy leakage is reduced, the security of the communication process is improved, and sensitive information is prevented from being tampered with or stolen.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024120436_26032026_PF_FP_ABST
    Figure CN2024120436_26032026_PF_FP_ABST
Patent Text Reader

Abstract

Provided are wireless communication methods and communication devices. A method comprises: a first device sends to a second device a first media access control (MAC) protocol data unit (PDU), the first MAC PDU carrying a first parameter, and the first parameter being used for performing integrity protection on a MAC CE in the first MAC PDU at a MAC layer. The first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying a MAC sub-PDU where the MAC CE is located. In the embodiments of the present application, the first parameter may be introduced, so as to implement an integrity protection process for the MAC CE at the MAC layer. Compared with conventional solutions in which encryption and integrity protection can only be performed at a PDCP layer, the present application helps to implement integrity protection for MAC CEs and reduces the possibility of user privacy leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Method and communication device for wireless communication TECHNICAL FIELD

[0001] The present application relates to the field of communication technology, and more particularly, to a method and a communication device for wireless communication. BACKGROUND

[0002] A conventional security protection mechanism is to perform integrity protection on user plane data packets and control plane data packets of a packet data convergence protocol (PDCP) layer respectively based on a core network derived key and other related parameters at the PDCP layer. However, this security protection mechanism performed at the PDCP layer has certain limitations and may cause security risks.

[0003] SUMMARY

[0004] The present application provides a method and a communication device for wireless communication. Each aspect of the present application is described below.

[0005] In a first aspect, a method for wireless communication is provided, comprising: sending, by a first device, a first medium access control (MAC) protocol data unit (PDU) to a second device, the first MAC PDU carrying a first parameter, the first parameter being used for integrity protection of a MAC control element (CE) in the first MAC PDU at a MAC layer, wherein the first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying a MAC sub-PDU in which the MAC CE is located.

[0006] In a second aspect, a method for wireless communication is provided, comprising: receiving, by a second device, a first MAC PDU sent by a first device, the first MAC PDU carrying a first parameter, the first parameter being used for integrity protection of a MAC CE in the first MAC PDU at a MAC layer, wherein the first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying a MAC sub-PDU in which the MAC CE is located.

[0007] In a third aspect, a communication device is provided, the communication device being a first device, comprising: a sending unit configured to send a first MAC PDU to a second device, the first MAC PDU carrying a first parameter, the first parameter being used for integrity protection of a MAC CE in the first MAC PDU at a MAC layer, wherein the first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying a MAC sub-PDU in which the MAC CE is located.

[0008] In a fourth aspect, a communication device is provided, the communication device being a second device, comprising: a receiving unit, configured to receive a first MAC PDU sent by a first device, the first MAC PDU carrying a first parameter, the first parameter being used for integrity protection of a MAC CE in the first MAC PDU at a MAC layer, wherein the first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying a MAC sub-PDU in which the MAC CE is located.

[0009] In a fifth aspect, a communication device is provided, comprising a processor, a memory and a communication interface, the memory being configured to store one or more computer programs, and the processor being configured to invoke the computer programs in the memory, so that the communication device performs some or all of the steps in the methods in the various aspects described above.

[0010] In a sixth aspect, a communication system is provided, comprising the first device and / or the second device described above. In another possible design, the system can further comprise other devices interacting with the first device or the second device in the solutions provided by the embodiments of the present application.

[0011] In a seventh aspect, a computer-readable storage medium is provided, which stores a computer program, and the computer program causes a communication device to perform some or all of the steps in the methods in the various aspects described above.

[0012] In an eighth aspect, a computer program product is provided, which comprises a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to cause a communication device to perform some or all of the steps in the methods in the various aspects described above. In some implementations, the computer program product can be a software installation package.

[0013] In a ninth aspect, a chip is provided, which comprises a memory and a processor, and the processor can invoke and run a computer program from the memory, to implement some or all of the steps described in the methods in the various aspects described above.

[0014] In the embodiments of the present application, the first parameter can be introduced to implement the integrity protection process for the MAC CE at the MAC layer. Compared with the conventional scheme in which encryption and integrity protection can only be performed at the PDCP layer, the integrity protection for the MAC CE can be implemented, and the possibility of user privacy leakage can be reduced. BRIEF DESCRIPTION OF DRAWINGS

[0015] FIG. 1 is a wireless communication system 100 to which embodiments of the present application are applied.

[0016] FIG. 2 is a schematic diagram of integrity protection and ciphering of PDCP PDUs at a PDCP layer.

[0017] FIG. 3 is a schematic flowchart of an integrity protection procedure of a PDCP layer.

[0018] FIG. 4 is a schematic flowchart of a ciphering procedure of a PDCP layer.

[0019] FIGS. 5A and 5B are schematic diagrams of formats of MAC PDUs to which embodiments of the present application are applied.

[0020] FIGS. 6A and 6B are schematic diagrams of MAC subheaders to which embodiments of the present application are applied.

[0021] FIG. 7 is a schematic flowchart of a method of wireless communication according to an embodiment of the present application.

[0022] FIG. 8 is a schematic diagram of a first MAC PDU carrying a first identity according to an embodiment of the present application.

[0023] FIG. 9 is a schematic diagram of a first MAC PDU carrying a first identity according to another embodiment of the present application.

[0024] FIGS. 10A and 10B are schematic diagrams of a first MAC PDU carrying a second identity according to an embodiment of the present application.

[0025] FIG. 11 is a schematic diagram of a first MAC PDU carrying first indication information according to an embodiment of the present application.

[0026] FIG. 12 is a schematic diagram of a first MAC PDU carrying second indication information according to an embodiment of the present application.

[0027] FIG. 13 is a schematic diagram of integrity protection of MAC subPDUs at a MAC layer according to an embodiment of the present application.

[0028] FIG. 14 is a schematic diagram of integrity protection according to an embodiment of the present application.

[0029] FIG. 15 is a schematic diagram of integrity protection according to another embodiment of the present application.

[0030] FIG. 16 is a schematic diagram of integrity protection of a plurality of MAC subPDUs as a whole at a MAC layer according to an embodiment of the present application.

[0031] FIG. 17 is a schematic diagram of integrity protection according to an embodiment of the present application.

[0032] FIG. 18 is a schematic diagram of a communication device according to an embodiment of the present application.

[0033] FIG. 19 is a schematic diagram of a communication device according to an embodiment of the present application.

[0034] FIG. 20 is a schematic structural diagram of a communication device according to an embodiment of the present application. DETAILED DESCRIPTION

[0035] The technical solutions in the present application will be described below with reference to the accompanying drawings.

[0036] FIG. 1 is a wireless communication system 100 to which embodiments of the present application are applied. The wireless communication system 100 can include a network device 110 and a terminal device 120. The network device 110 can be a device that communicates with the terminal device 120. The network device 110 can provide communication coverage for a specific geographic area and can communicate with the terminal device 120 located in the coverage area.

[0037] FIG. 1 exemplarily shows one network device and two terminals. Optionally, the wireless communication system 100 can include multiple network devices and each network device can include other numbers of terminal devices within its coverage, which is not limited in the embodiments of the present application.

[0038] Optionally, the wireless communication system 100 can further include a network controller, a mobile management entity, and other network entities, which are not limited in the embodiments of the present application.

[0039] It should be understood that the technical solutions in the embodiments of the present application can be applied to various communication systems, such as a 5th generation (5G) system or new radio (NR), a long term evolution (LTE) system, an LTE frequency division duplex (FDD) system, an LTE time division duplex (TDD), and the like. The technical solutions provided in the present application can also be applied to future communication systems, such as a 6th generation mobile communication system, a satellite communication system, and the like.

[0040] The terminal device in the embodiments of the present application can also be referred to as a user equipment (UE), an access terminal, a user unit, a user station, a mobile station, a mobile station (MS), a mobile terminal (MT), a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent or a user apparatus. The terminal device in the embodiments of the present application can refer to a device that provides voice and / or data connectivity for a user, and can be used to connect people, things and machines, for example, handheld devices with wireless connection functions, vehicle-mounted devices, etc. The terminal device in the embodiments of the present application can be a mobile phone, a tablet computer (Pad), a notebook computer, a palm computer, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, etc. Optionally, the UE can be used to act as a base station. For example, the UE can act as a scheduling entity, which provides a sidelink signal between UEs in V2X or D2D, etc. For example, a cellular phone and a car communicate with each other using a sidelink signal. The cellular phone and the smart home device communicate with each other without relaying the communication signal through the base station.

[0041] The network device in the embodiments of the present application can be a device for communicating with a terminal device, which can also be referred to as an access network device or a radio access network device, such as a network device, which can be a base station. The network device in the embodiments of the present application can refer to a radio access network (RAN) node (or device) that accesses a terminal device to a wireless network. The base station can broadly cover various names in the following or be replaced by the following names, such as: Node B (NodeB), evolved Node B (eNB), next generation Node B (gNB), relay station, transmitting and receiving point (TRP), transmitting point (TP), master station MeNB, auxiliary station SeNB, multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The base station can be a macro base station, a micro base station, a relay node, a donor node or the like, or a combination thereof. The base station can also refer to a communication module, modem or chip for being arranged in the foregoing device or apparatus. The base station can also be a mobile switching center and a device that undertakes the function of a base station in device-to-device (D2D), vehicle-to-everything (V2X), machine-to-machine (M2M) communication, network side device in 6G network, device that undertakes the function of a base station in future communication system, etc. The base station can support networks of the same or different access technologies. The embodiments of the present application do not limit the specific technology and specific device form adopted by the network device.

[0042] The base station can be fixed or mobile. For example, a helicopter or a drone can be configured to act as a mobile base station, and one or more cells can move according to the location of the mobile base station. In other examples, a helicopter or a drone can be configured to act as a device that communicates with another base station.

[0043] In some deployments, the network device in the embodiments of the present application can refer to a CU or a DU, or the network device includes a CU and a DU. The gNB can also include an AAU.

[0044] The network device and the terminal device can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can also be deployed on water surface; can also be deployed on aircraft, balloons and satellites in the air. The scene where the network device and the terminal device are located in the embodiments of the present application is not limited.

[0045] It should be understood that all or part of the functions of the communication device in the present application can also be implemented by software functions running on hardware, or by virtualized functions instantiated on a platform (such as a cloud platform).

[0046] PDCP security mechanism

[0047] In some scenarios, the confidentiality / integrity protection of the user plane (UP) data and the RRC message between the terminal device and the network device (for example, 5G-RAN) can be provided by the PDCP protocol layer.

[0048] In some implementations, the PDCP layer encryption integrity protection mechanism can be understood as the PDCP layer being responsible for performing encryption and integrity protection operations. For a PDCP PDU, integrity protection can be performed first and then encryption. Generally, integrity protection and encryption are paired. For the integrity protection process, the sending end first performs integrity protection calculation, and the receiving end performs corresponding integrity protection verification. For the encryption / decryption process, the sending end performs encryption processing, and the receiving end performs decryption processing.

[0049] Figure 2 shows a schematic diagram of integrity protection and ciphering for PDCP PDU at PDCP layer. Referring to Figure 2, integrity protection is applied to PDCP header and PDCP data part (also referred to as user plane data packet), and a verification value (e.g., message authorization code for integrity (MAC-I)) is obtained after integrity protection, which is used for integrity verification at the receiving end. Currently, integrity protection is applied to PDCP data PDU of signaling radio bearer (SRB), and whether integrity protection is applied to PDCP data PDU transmitted in data radio bearer (DRB) depends on whether integrity protection function is configured for DRB. In addition, integrity protection is not applied to PDCP control PDU.

[0050] Figure 3 shows a flow of integrity protection at PDCP layer. Referring to Figure 3, the sending end can input the following parameters to the integrity protection algorithm: key (Key), count value (COUNT), message (MESSAGE), direction (DIRECTION), bearer identifier (BEARER ID), and then the integrity protection algorithm can generate MAC-I based on the above input parameters. Correspondingly, the receiving end verifies whether integrity protection is successful based on MAC-I using the integrity protection algorithm.

[0051] For example, the integrity protection algorithm can use 128-bit integrity algorithm for 5G (NIA) algorithm (e.g., Snow 3G, AES, ZUC), wherein the input of the NIA algorithm includes the following parameters: message "Message", 128-bit key "Kupint / KRRCint" as KEY, 5-bit bearer identifier "BEARER ID", 1-bit transmission direction "DIRECTION", and 32-bit count value "COUNT". Of course, in the embodiments of the present application, the integrity protection algorithm can use 256-bit NIA.

[0052] In some implementations, the ciphering operation is applied to the data part of the PDCP data PDU and the verification value of the integrity protection (e.g., MAC-I), continuing to refer to FIG. 2. The ciphering operation is not applied to the PDCP header and the service data adaptation protocol (SDAP) header in the data part of the PDCP. In addition, the ciphering operation is also not applied to the PDCP control PDU.

[0053] FIG. 4 illustrates a flow of the ciphering operation of the PDCP layer. Referring to FIG. 4, the transmitter can input the following parameters to the ciphering algorithm: a key (KEY), a count value (COUNT), a direction (DIRECTION), a bearer identification (BEARER ID), and a length (LENGTH) to generate a key stream (also referred to as a key stream block). Then, the cipher text (also referred to as a cipher text block) is obtained by operating the generated key stream with the text to be encrypted (also referred to as a plain text block). Accordingly, the receiver performs the inverse operation to decrypt the cipher text.

[0054] For example, the ciphering operation can employ a 128-bit encryption algorithm for 5G (NEA) (e.g., Snow 3G, AES, ZUC), in which the input of the NEA algorithm includes the following parameters: a 128-bit key "Kupint / KRRCint" as the KEY, a 5-bit bearer identification "BEARER ID", a 1-bit direction "DIRECTION", a length LENGTH, and a 32-bit count value "COUNT". Of course, in the embodiments of the present application, the integrity protection algorithm can employ a 256-bit NEA.

[0055] Security Principles

[0056] In some scenarios, the following security principles can be followed in the process of ciphering / integrity protection at the PDCP layer: global uniqueness, flexible variability, and non-repeatability.

[0057] In some implementations, the global uniqueness can refer to that the same initialization vector (IV) should not be used when using the same encryption algorithm with the same key, otherwise the security of certain or even all will be lost, i.e., each generated key stream needs to be different from any other key stream generated using the same algorithm and the same key. Therefore, a unique input is needed to generate each key stream, which can include the following information: a message counter maintained by the PDCP entity, a unique ID of the respective radio bearer, and a direction bit (different for uplink and downlink).

[0058] In some implementations, the encryption algorithm / integrity protection algorithm can be collectively referred to as a security algorithm, and accordingly, the flexible variability can refer to that, except for the key, other parameters (e.g., COUNT, bearer identification, etc.) input into the security algorithm can be filled into the IV (e.g., the IV in ZUK is 128 bits), and in addition, the length of the parameters input into the security algorithm can be flexibly varied.

[0059] In some implementations, the non-repeatability can refer to that the security operation (e.g., encryption operation / integrity protection operation) cannot be repeated, e.g., the PDCP layer has performed a security operation on certain data, and then the MAC layer does not need to repeatedly perform the security operation on the data, and vice versa.

[0060] Format of MAC PDU

[0061] FIGS. 5A and 5B are schematic diagrams of the format of the MAC PDU applicable to the embodiments of the present application. The MAC PDU format shown in FIG. 5A is applicable to downlink transmission. The MAC PDU format shown in FIG. 5B is applicable to uplink transmission.

[0062] In FIGS. 5A and 5B, the MAC PDU can include one or more MAC subPDUs. The MAC subPDU can be divided into four types: in the first type of MAC subPDU, the MAC subPDU can only include a MAC subheader. In the second type of MAC subPDU, the MAC subPDU can include a MAC subheader and a MAC service data unit (SDU) corresponding to the MAC subheader. In the third type of MAC subPDU, the MAC subPDU can include a MAC subheader and a MAC control element (CE) corresponding to the MAC subheader. In the fourth type of MAC subPDU, the MAC subPDU can include a MAC subheader and padding information.

[0063] Continuing to refer to FIG. 5A and FIG. 5B, the MAC subPDU carrying the MAC CE is usually adjacent to the MAC subPDU carrying the MAC SDU. In the MAC PDU shown in FIG. 5A, the MAC subPDU carrying the MAC CE is located before the MAC subPDU carrying the MAC SDU. In addition, if the MAC PDU contains a MAC subPDU carrying padding information, the MAC subPDU carrying the MAC SDU is located before the MAC subPDU carrying the padding information. In the MAC PDU shown in FIG. 5B, the MAC subPDU carrying the MAC CE is located after the MAC subPDU carrying the MAC SDU. If the MAC PDU contains a MAC subPDU carrying padding information, the MAC subPDU carrying the MAC CE is located before the MAC subPDU carrying the padding information.

[0064] In some implementations, the format of the MAC subheader is as follows: for the MAC subPDU containing a MAC CE of fixed size, and the MAC subPDU containing padding information, the corresponding MAC subheader can only contain two indication fields: a reserved (denoted as “R”) field and a logical channel identification (LCID) field, as shown in FIG. 6A. For other types of MAC subPDU (e.g., the MAC subPDU carrying a MAC CE of variable size), the MAC subheader thereof can contain an R field, an F field, an LCID field, and an L field, as shown in FIG. 6B. The value of the LCID in the LCID field can indicate different types of MAC CEs, that is, different types of MAC CEs can correspond to a specific LCID value. For example, the LCID value corresponding to the MAC CE used to carry a downlink timing advanced command (TAC) is 62.

[0065] MAC CE security threats

[0066] With the development of technology, various types of MAC CEs have been introduced in communication systems. Related security researchers have found that attacks on unprotected MAC CEs are increasing. In some scenarios, attackers can tamper with sensitive information delivered in MAC CEs, causing communication processes to fail. For example, attackers can tamper with the network coordination control (NCC) in lower-layer triggered mobility (LTM), which can cause handover failure. In other scenarios, attackers can steal non-sensitive information delivered in MAC CEs and further extract more information by combining security algorithms, posing a security threat.

[0067] In some scenarios, the MAC CE carrying sensitive information can be referred to as a security-sensitive MAC CE. Currently, the security-sensitive MAC CE can include a downlink LTM MAC CE, a downlink TAC MAC CE, a downlink secondary cell (SCell) activation MAC CE, a downlink SCell deactivation MAC CE, a downlink transmission configuration indication (TCI) state indication MAC CE, and the like. For the downlink LTM MAC CE, the cell information and / or NCC information carried in this type of MAC CE is security-sensitive information. For the downlink TAC MAC CE, the uplink timing advanced (TA) adjustment information carried in this type of MAC CE is security-sensitive information, and the location of the terminal device can be derived through the information. For the downlink SCell activation / deactivation MAC CE, the indication information of the SCell carried in this type of MAC CE is security-sensitive information, and tampering with the information can cause the terminal device to generate additional power consumption. For the downlink TCI state indication MAC CE, the TCI state indication carried in this type of MAC CE is security-sensitive information, and tampering with the information can affect the beam information corresponding to the data transmission and reception of the terminal device, affecting the data transmission and reception performance.

[0068] It should be noted that the above only lists some common MAC CEs that may have security risks, and the embodiments of the present application are not limited thereto. For uplink transmission, since it is considered that some key information in future communication systems may be carried on the physical uplink control channel (PUCCH) or the radio resource control (RRC), such as ACK / NACK in the PUCCH or UE assistance information (UAI) in the RRC, and the like, the uplink MAC CE is used to transmit the information, such as carrying ACK / NACK in the PUCCH or reporting UAI in the RRC, and the like, these designs will make the uplink MAC CE also need some security protection mechanism, therefore, the integrity protection mechanism involved in the embodiments of the present application can also be applied to such MAC CEs.

[0069] Currently, several common security attacks include: TA attack, carrier aggregation attack, and channel status information reference signal (CSI-RS) attack. For the TA attack, an attacker can determine the distance from the terminal device to the network device according to the TA information in the MAC CE, to accurately locate the position of the terminal device. For the carrier aggregation attack, a malicious cell activates the MAC CE to force the terminal device to consume more energy (based on CA energy consumption measurement, when an additional cell is activated, the average current of the terminal device increases by 79%). For the CSI-RS attack, an attacker can attack the MAC CE for indicating the activation or deactivation of the channel status information (CSI) report transmitted through the physical uplink control channel (PUCCH), to obtain the CSI{Bi, RSRP} in the PUCCH, causing the position of the terminal device to be exposed.

[0070] As introduced before, the traditional security protection mechanism is to perform integrity protection on the user plane data packets and control plane data packets of the PDCP layer respectively based on the core network derived key and other related parameters. However, this security protection mechanism executed at the PDCP layer has certain limitations and may cause security risks. For example, with the development of technology, multiple types of MAC CEs are introduced, at this time, the security protection mechanism executed at the PDCP layer cannot protect the MAC sub-PDUs carrying the MAC CEs, which may cause user privacy leakage.

[0071] Therefore, the applicant proposes that the MAC CEs in the MAC PDUs can be subjected to integrity protection at the MAC layer. In some scenarios, the integrity protection of the MAC CEs in the MAC PDUs can be understood as the integrity protection of the MAC sub-PDUs in the MAC PDUs for carrying the MAC CEs. In some implementation manners, the security protection mechanism at the MAC layer can follow the integrity protection mechanism of the PDCP to implement the integrity protection of the MAC sub-PDUs. As introduced before, the parameters required in the process of integrity protection at the PDCP layer include the count value “COUNT” and the bearer identifier “Bearer ID”. However, these two parameters cannot be obtained at the MAC layer, which causes the integrity protection algorithm of the PDCP cannot be continued at the MAC layer.

[0072] Therefore, the applicant proposes that a first parameter can be introduced in the integrity protection process of the MAC CE at the MAC layer, which is helpful to realize the integrity protection of the MAC CE and reduce the possibility of user privacy leakage. The first parameter is used for integrity protection of the MAC CE in the first MAC PDU at the MAC layer. For example, the first parameter is an input parameter of an algorithm for realizing the integrity protection function, or in other words, the first parameter is an input parameter of an integrity protection algorithm used for integrity protection of the MAC CE in the first MAC PDU at the MAC layer. The method of wireless communication of the embodiment of the application is introduced below in conjunction with the schematic flowchart of the method shown in FIG. 7. The method shown in FIG. 7 includes step S710.

[0073] In step S710, the first device sends the first MAC PDU to the second device, and the first MAC PDU carries the first parameter.

[0074] In some implementations, the first device can be a terminal device, and correspondingly, the second device can be a network device, that is, corresponding to the uplink transmission scenario. Alternatively, the first device can be a network device, and correspondingly, the second device can be a terminal device, that is, corresponding to the downlink transmission scenario. That is, the scheme of the embodiment of the application can be applicable to the uplink transmission process and the downlink transmission process, and the difference between the two is that the arrangement manner of the MAC sub-PDUs in the first MAC PDU is different (for details, see the introduction above in conjunction with FIGS. 5A and 5B).

[0075] As described above, the first parameter is used for integrity protection of the MAC sub-PDU carrying the MAC CE in the first MAC PDU at the MAC layer. In some implementations, the MAC sub-PDU subjected to integrity protection can be all the MAC sub-PDUs carrying the MAC CE in the first MAC PDU, or part of the MAC sub-PDUs carrying the MAC CE in the first MAC PDU.

[0076] It should be noted that if the first parameter is used for integrity protection of part of the MAC sub-PDUs carrying the MAC CE in the first MAC PDU at the MAC layer, the part of the MAC sub-PDUs can be the MAC sub-PDUs carrying the security-sensitive MAC CE. For details of the security-sensitive MAC CE, see the introduction above.

[0077] In some implementations, the integrity protection situation in the first MAC PDU can be divided into three categories. It is assumed that the first MAC PDU contains N MAC sub-PDUs carrying the MAC CE, and x of the N MAC sub-PDUs carrying the MAC CE need to be subjected to integrity protection.

[0078] Case 1: N = 0, that is, no MAC subPDU in the first MAC PDU carries a MAC CE, and all the MAC subPDUs in the first MAC PDU are used to carry a MAC SDU and / or padding information. In this case, the integrity protection operation can not be performed on the MAC subPDUs in the first MAC PDU.

[0079] Case 2: N > 0 and x < N, that is, part of the MAC subPDUs in the first MAC PDU carries a MAC CE. In this case, the integrity protection operation can be performed on the part of the MAC subPDUs carrying the MAC CE.

[0080] Case 3: N > 0 and x = N, that is, all the MAC subPDUs in the first MAC PDU carries a MAC CE. In this case, the integrity protection operation can be performed on all the MAC subPDUs.

[0081] In some implementations, the first parameter includes a first identifier and / or a second identifier. The first identifier and the second identifier in the embodiments of the present application are introduced below.

[0082] The first identifier is used to identify the first MAC PDU.

[0083] In the embodiments of the present application, by introducing the first identifier at the MAC layer, similar to the carrying identifier used by the PDCP layer integrity protection, it is helpful to continue using the integrity protection algorithm used by the PDCP layer at the MAC layer to implement the integrity protection process for the MAC CE.

[0084] For example, the first identifier can include one or more of the following: an identifier of the first MAC PDU, an index of the first MAC PDU, and a COUNT value corresponding to the first MAC PDU. Therefore, the first identifier is also called a MAC PDU identifier (MAC PDU ID), a MAC PDU index (MAC PDU Index), or a COUNT value.

[0085] The first identifier in the embodiments of the present application is introduced above, and the carrying manner of the first identifier in the embodiments of the present application is introduced below. In some implementations, the first identifier is carried in a first field, and the first field is located before other fields in the first MAC PDU, and the other fields are fields in the first MAC PDU other than the first field, which is helpful for the receiving end to obtain the first identifier as soon as possible. For example, the first field can be located in the MAC PDU header of the first MAC PDU.

[0086] For example, referring to FIG. 8, the first MAC PDU includes the first identifier and N MAC subPDUs: MAC subPDU1, MAC subPDU2, …, MAC subPDU N, where N is an integer greater than 1, and the MAC subPDU2 in the N MAC subPDUs is a MAC subPDU that is integrity protected at the MAC layer. Accordingly, the first field carrying the first identifier in the first MAC PDU is earlier than the fields carrying the N MAC subPDUs.

[0087] In some implementations, the first identifier is carried in a first field, and the first field is located in a first MAC subheader of the first MAC PDU, or in other words, the first field is located in a MAC subheader of a first MAC subPDU of the first MAC PDU, where the first MAC subPDU can be understood as the earliest transmitted MAC subPDU among the MAC subPDUs included in the first MAC PDU.

[0088] For example, referring to FIG. 9, the first MAC PDU includes the first identifier and N MAC subPDUs: MAC subPDU1, MAC subPDU2, …, MAC subPDU N, where N is an integer greater than 1, and the MAC subPDU2 in the N MAC subPDUs is a MAC subPDU that is integrity protected at the MAC layer. Accordingly, the first field carrying the first identifier in the first MAC PDU can be located in the MAC subheader corresponding to the MAC subPDU1.

[0089] The second identifier is used to identify the MAC subPDU in which the MAC CE is located in the first MAC PDU.

[0090] In the embodiments of the present application, by introducing the second identifier at the MAC layer, similar to the COUNT used by the PDCP layer integrity protection, it is helpful to use the PDCP integrity protection algorithm at the MAC layer to implement the integrity protection process for the MAC CE.

[0091] In the embodiments of the present application, the implementation of the second identifier is not limited. In some implementations, the second identifier can include one or more of the following: an identifier of the MAC subPDU, an index of the MAC subPDU, and a COUNT value corresponding to the MAC subPDU. Therefore, the second identifier is also referred to as the MAC subPDU identifier (MAC subPDU ID), the MAC subPDU index (MAC subPDU Index), or the COUNT value. Of course, in the embodiments of the present application, different types of MAC CEs correspond to different LCIDs, and therefore, the LCID can be reused as the second identifier, that is, the second identifier can be the LCID included in the MAC subheader of the MAC subPDU, which helps to reduce the overhead required to transmit the second identifier.

[0092] In the embodiments of the present application, the type of the second identifier is not limited. In some implementations, the second identifier is used to distinguish the MAC subPDU in all the MAC PDUs to be transmitted, and in this case, the second identifier can be understood as a global identifier, which is used to uniquely identify the MAC subPDU in all the MAC PDUs. Therefore, in the embodiments of the present application, the second identifier can also be referred to as a "MAC subPDU global identifier". In other implementations, the second identifier is used to distinguish the MAC subPDU in the first MAC PDU, and in this case, the second identifier can be understood as a local identifier.

[0093] The implementation of the second identifier in the embodiments of the present application is introduced above, and the carrying manner of the second identifier in the embodiments of the present application is introduced below. In some implementations, the second identifier is carried in a second field, and the second field is located in the MAC subheader corresponding to the MAC subPDU.

[0094] In some implementations, the second identifier can occupy a new field in the MAC subheader. For example, referring to FIG. 10A, it is assumed that the second identifier is the global identifier of the MAC subPDU2, and the first MAC PDU includes N MAC subPDUs: MAC subPDU1, MAC subPDU2,..., MAC subPDU N, where N is an integer greater than 1, and the MAC subPDU2 in the N MAC subPDUs is a MAC subPDU that is integrity protected at the MAC layer, and the MAC subPDU2 is used to carry the MAC CE, and the verification value used to verify the integrity of the MAC subPDU2 is MAC-I. Correspondingly, the first field carrying the second identifier in the first MAC PDU can be located in the MAC subheader corresponding to the MAC subPDU2, that is, the MAC subheader includes the R field, the LCID field and the field used to carry the second identifier.

[0095] In some implementations, if the second identifier is LCID, it can occupy the LCID field in the MAC subheader. That is, the field used to carry the second identifier can reuse a known field in the MAC subheader. For example, referring to Figure 10B, assuming the second identifier is the LCID corresponding to MAC sub-PDU2, the first MAC PDU includes N MAC sub-PDUs: MAC sub-PDU1, MAC sub-PDU2, ..., MAC sub-PDU N, where N is an integer greater than 1, and MAC sub-PDU2 among the N MAC sub-PDUs is the MAC sub-PDU with integrity protection at the MAC layer. MAC sub-PDU2 is used to carry the MAC CE, and the verification value used to verify the integrity of MAC sub-PDU2 is MAC-I. Accordingly, the first field carrying the second identifier in the first MAC PDU can correspond to the LCID field in the MAC subheader corresponding to MAC sub-PDU2; that is, the MAC subheader includes the R field and the LCID field.

[0096] In some scenarios, the implementation of the first parameter can differ depending on whether the second identifier is a global identifier or a local identifier. In some implementations, if the second identifier is a local identifier, i.e., used to distinguish MAC sub-PDUs within the first MAC PDU, then the first parameter can include both the first and second identifiers. That is, the first and second identifiers together uniquely identify the MAC sub-PDU carrying the MAC CE. In this case, using both the first and second identifiers for integrity protection of the MAC CE helps ensure that the protected MAC CE satisfies global uniqueness, thereby improving the security of the MAC CE.

[0097] Taking the second identifier as a local identifier as an example, the second identifier can be the LCID described above. Of course, in the embodiments of this application, the second identifier can also be other implementations.

[0098] In other implementations, if the second identifier is a global identifier, used to distinguish MAC sub-PDUs among all MAC PDUs to be transmitted, then the first parameter only includes the second identifier. That is, the second identifier itself can uniquely identify the MAC sub-PDU carrying the MAC CE. In this case, using the second identifier to protect the integrity of the MAC sub-PDU helps ensure that the integrity-protected MAC sub-PDU satisfies global uniqueness, thereby improving the security of the MAC CE. Furthermore, in this embodiment, using only the second identifier to uniquely identify the MAC sub-PDU helps reduce the overhead required to transmit the first parameter.

[0099] For example, the transmitted MAC sub-PDUs can be sequentially numbered, and correspondingly, the number of the MAC sub-PDU is the second identifier. Assuming that the MAC PDU sent by the first device to the second device includes MAC PDU1 and MAC PDU2, and correspondingly, the MAC sub-PDUs included in the MAC PDU1 are MAC sub-PDU1-MAC sub-PDUi, and the MAC sub-PDUs included in the MAC PDU2 are MAC sub-PDUi+1-MAC sub-PDU N, where i is a positive integer greater than or equal to 1 and less than N. Correspondingly, the sending order of the MAC sub-PDUs in the MAC PDU1 and the MAC PDU2 from early to late (or from front to back) is MAC sub-PDU1, MAC sub-PDU2, …, MAC sub-PDU N, and correspondingly, the second identifier of the MAC sub-PDU1 is 1, the second identifier of the MAC sub-PDU2 is 2, and the second identifier of the MAC sub-PDU N is N.

[0100] In some other implementations, only one MAC PDU contains a MAC CE in a certain period of time, and when the next MAC PDU carrying the MAC CE needs to be transmitted, the key has been updated, and the generated key stream is naturally different, which meets the security principle. At this time, the first parameter only includes the second identifier, and does not include the first identifier. For example, in the LTM scenario, only one MAC PDU contains a MAC CE in a certain period of time, so it is not necessary to identify the identifier (i.e., the first identifier) of the MAC PDU, and when the next LTM MAC CE appears, the key may have been updated, and the generated key stream is naturally different, which meets the security principle. At this time, the first parameter can only include the second identifier.

[0101] In some other implementations, if all the MAC sub-PDUs in the first MAC PDU are integrity protected, at this time, it is not necessary to distinguish which MAC sub-PDUs in the first MAC PDU are integrity protected and which MAC sub-PDUs are not integrity protected, and therefore, the first parameter can only include the first identifier.

[0102] As introduced in the foregoing, the first identifier can be carried in the first MAC PDU and sent to the second device. However, for the MAC PDU that is not integrity protected, the first identifier is usually not carried in this type of MAC PDU. Therefore, in order to facilitate the second device to distinguish between the two different MAC PDUs, the first device can send first indication information to the second device to indicate whether the first identifier is carried in the first MAC PDU, or in other words, the first indication information is used to indicate whether the MAC CE in the first MAC PDU is integrity protected, or in other words, the first indication information is used to indicate whether the first MAC PDU contains the MAC sub-PDU that is integrity protected.

[0103] That is, the method further includes: the first device sending first indication information to the second device, the first indication information being used to indicate whether the first identifier is carried in the first MAC PDU, and / or the first indication information being used to indicate whether the MAC sub-PDU subjected to integrity protection is included in the first MAC PDU.

[0104] In some implementations, the first indication information can be carried in the first MAC PDU. Of course, in the embodiment of the present application, the first indication information can be sent separately before the first MAC PDU, instead of being carried in the first MAC PDU. Taking the case that the first indication information is carried in the first MAC PDU as an example, in some implementations, the first indication information is carried in a third field, which is located before the field carrying the first identifier in the first MAC PDU.

[0105] For example, referring to FIG. 11, the first MAC PDU includes the first indication information, the first identifier, and N MAC sub-PDUs: MAC sub-PDU1, MAC sub-PDU2, …, MAC sub-PDU N, where N is an integer greater than 1, and the MAC sub-PDU2 in the N MAC sub-PDUs is the MAC sub-PDU subjected to integrity protection at the MAC layer. Accordingly, the first field carrying the first identifier in the first MAC PDU is earlier than the field carrying the N MAC sub-PDUs, and the third field is earlier than the first field in the first MAC PDU.

[0106] In some other implementations, the first indication information can be carried in the first MAC sub-header of the first MAC PDU, or in other words, the third field is located in the MAC sub-header of the first MAC sub-PDU of the first MAC PDU, where the first MAC sub-PDU can be understood as the MAC sub-PDU transmitted earliest among the MAC sub-PDUs included in the first MAC PDU.

[0107] In the embodiment of the present application, the carrying manner of the first indication information is not limited. For example, the first indication information can be newly defined information and carried before the first MAC sub-PDU in the first MAC PDU, where the first MAC sub-PDU can be understood as the MAC sub-PDU transmitted earliest among the MAC sub-PDUs included in the first MAC PDU. For another example, the first indication information can be obtained by changing the reserved field “R” in the first MAC sub-PDU into a field “S”, and the S is used to carry the first indication information.

[0108] In addition, in the embodiment of the present application, the first indication information can occupy 1 bit, which helps to reduce the overhead of transmitting the first indication information. For example, the 1 bit of the first indication information takes a first value, which indicates that the MAC CE in the first MAC PDU is integrity protected. For another example, the 1 bit of the first indication information takes a second value, which indicates that the MAC CE in the first MAC PDU is not integrity protected. The first value is different from the second value, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.

[0109] As introduced above, the second identifier can be carried in the first MAC PDU and sent to the second device. However, for the MAC CE which is not integrity protected, the second identifier is usually not carried in the MAC PDU of this type. Therefore, in order to facilitate the second device to distinguish the two different MAC PDUs, the first device can send the second indication information to the second device to indicate whether the MAC CE is integrity protected or to indicate all the MAC CEs which are integrity protected in the first MAC PDU.

[0110] That is to say, the above method further includes that the first device sends the second indication information to the second device, the second indication information is used to indicate whether the MAC CE is integrity protected or the second indication information is used to indicate all the MAC CEs which are integrity protected in the first MAC PDU.

[0111] In the embodiment of the present application, the transmission mode of the second indication information is not limited. In some implementation manners, the second indication information can be carried in the first MAC PDU. Of course, in the embodiment of the present application, the second indication information can also be information which is independently transmitted.

[0112] In some implementation manners, if the second indication information is used to indicate whether the MAC CE is integrity protected, the second indication information is carried in the MAC subheader of the MAC subPDU corresponding to the MAC CE. Or, the second indication information carried in the MAC subheader corresponding to the MAC subPDU carrying the MAC CE is used to indicate whether the MAC CE is integrity protected.

[0113] In another implementation manner, if the second indication information is used to indicate all the MAC subPDUs which are integrity protected in the first MAC PDU, the second indication information is carried in the third field, and the third field is located before the field carrying the first identifier in the first MAC PDU. Of course, in the embodiment of the present application, if the first indication information is also carried in the third field, the first indication information and the second indication information are carried in one field.

[0114] In the embodiments of the present application, the implementation manner of the second indication information is not limited. In some implementation manners, the second indication information can be indicated by a bitmap, where each bit in the bitmap can correspond to one MAC CE in the first MAC PDU respectively, and the value of each bit is used to indicate whether the corresponding MAC CE is subjected to integrity protection. In some implementation manners, if the value of the bit is a first value, it indicates that the corresponding MAC CE is subjected to integrity protection, and if the value of the bit is a second value, it indicates that the corresponding MAC CE is not subjected to integrity protection, where the first value is different from the second value, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.

[0115] In some scenarios, if the first MAC PDU is a MAC PDU subjected to integrity protection, it is usually necessary to indicate which MAC CEs in the first MAC PDU are subjected to integrity protection and which are not subjected to integrity protection in combination with the second indication information. That is to say, the second indication information and the first identifier can be carried in the first MAC PDU at the same time. At this time, the first indication information can be used to indicate whether the second indication and the first identifier are carried in the first MAC PDU at the same time.

[0116] For example, referring to FIG. 12, it is assumed that the first indication information is also referred to as a MAC PDU ID indication, and the first identifier is also referred to as a MAC PDU ID. The first MAC PDU includes a MAC PDU ID indication, second indication information, a MAC PDU ID and N MAC subPDUs, where the N MAC subPDUs can include a MAC subPDU1, a MAC subPDU2, …, a MAC subPDU N. The MAC PDU ID indication is used to indicate that the first MAC PDU is subjected to integrity protection. The MAC PDU ID is used to identify the MAC PDU. The second indication information is used to indicate whether the corresponding MAC CE is subjected to integrity protection by N bits in the bitmap.

[0117] It should be noted that in the embodiments of the present application, the second indication information can be adjacent to the first indication information (continue to refer to FIG. 12). This is because the first indication information indicates whether there is a MAC subPDU subjected to integrity protection in the first MAC PDU, at this time, the receiving end does not know which MAC subPDU is subjected to integrity protection, and therefore the second indication information can be read immediately to determine which MAC subPDU in the first MAC PDU is subjected to integrity protection.

[0118] In the embodiments of the present application, the carrying manners of the first indication information and the second indication information are not limited. For example, the first indication information and the second indication information can be designed as a single MAC sub-PDU, and at this time, the first indication information can be a special LCID.

[0119] The first parameter, the first indication information and the second indication information in the embodiments of the present application are introduced above. The integrity protection of the first MAC PDU in the embodiments of the present application is introduced below.

[0120] In some implementations, the integrity protection of the MAC CE in the first MAC PDU includes the integrity protection of the MAC sub-PDU carrying the MAC CE and the MAC sub-header corresponding to the MAC sub-PDU, as shown in FIG. 13. Therefore, the integrity protection of the MAC CE in the first MAC PDU can be replaced by the integrity protection of the MAC sub-PDU where the MAC CE is located.

[0121] In other implementations, if the first identifier is carried in the MAC PDU header of the first MAC PDU, the integrity protection of the MAC sub-PDU in the first MAC PDU includes the integrity protection of the MAC PDU header, the MAC CE carried in the MAC sub-PDU and the MAC sub-header corresponding to the MAC sub-PDU.

[0122] In the embodiments of the present application, according to the granularity of the integrity protection of the first MAC PDU, there are various implementations, wherein the granularity of the integrity protection of the first MAC PDU includes the integrity protection of the MAC sub-PDU respectively and the integrity protection of the plurality of MAC sub-PDUs as a whole. The implementation mode 1 and the implementation mode 2 are taken as examples for introduction below.

[0123] In the implementation mode 1, the integrity protection of the MAC sub-PDU is performed respectively in the first MAC PDU. That is, the integrity protection of the first MAC PDU can be performed with the MAC sub-PDU as the granularity.

[0124] In some implementations, the first MAC PDU includes a fourth field for carrying a verification value for verifying the integrity of the MAC sub-PDU, and the fourth field is located after the MAC sub-PDU and adjacent to the MAC sub-PDU in the first MAC PDU, as shown in FIG. 13.

[0125] In some implementations, the parameters for integrity protection further include a second parameter (also referred to as "message "Message"") determined based on the MAC CE of the MAC sub-PDU, the field carrying the first identifier, and the MAC sub-header corresponding to the MAC sub-PDU. Of course, in the embodiments of the present application, if the first identifier is carried in the MAC sub-header corresponding to the MAC sub-PDU, it can be understood that the second parameter can be determined based on the MAC CE of the MAC sub-PDU and the MAC sub-header of the MAC sub-PDU.

[0126] To facilitate understanding, the following describes the scheme for integrity protection of the MAC sub-PDU in the embodiments of the present application in conjunction with the following scenarios of Examples 1-2.

[0127] Example 1: Assuming that the first MAC PDU is as shown in FIG. 8, and the MAC sub-PDU 2 for carrying the MAC CE is subjected to integrity protection. The first identifier is used to identify the MAC PDU, and the second identifier is the LCID carried in the MAC sub-header of the MAC sub-PDU 2. The LCID carried in the MAC sub-header is shown in FIG. 10B. The following describes the scheme for integrity protection of the MAC sub-PDU 2 in the embodiments of the present application.

[0128] FIG. 14 is a schematic diagram of integrity protection in the embodiments of the present application. Referring to FIG. 14, for the sending end, the MAC sub-header of the MAC sub-PDU 2 and the MAC CE can be subjected to integrity protection. The parameters input into the integrity protection algorithm in the process of integrity protection include the following five kinds:

[0129] The key "Key" is generated by a key derivation method similar to the conventional method to obtain a key for integrity protection of the MAC CE, also referred to as "Key-MAC_CE-Integrity";

[0130] The second identifier (also referred to as "MAC sub-PDU ID") is similar to the COUNT value used in the PDCP layer integrity protection process, and is used to distinguish different MAC sub-PDUs in the same MAC PDU. As described above, the second identifier can be the LCID corresponding to the MAC sub-PDU 2;

[0131] The message "MESSAGE" includes the MAC PDU header (a field carrying the first identifier), the MAC sub-header of the MAC sub-PDU, and the MAC CE carried in the MAC sub-PDU.

[0132] DIRECTION, used to indicate the direction of the first MAC PDU is downlink. For example, if the parameter takes a first value, it means that the direction of the first MAC PDU is downlink. Conversely, if the parameter takes a second value, it means that the direction of the first MAC PDU is downlink. Wherein the first value and the second value are different, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.

[0133] The first identifier (also referred to as MAC PDU ID) is similar to the bearer identifier (BEARER ID) used in the PDCP layer integrity protection process, and is used to distinguish different MAC PDUs.

[0134] Correspondingly, referring to FIG. 14, the above parameters are input into the integrity protection algorithm for calculation, and the MAC-I corresponding to the MAC subPDU2 can be obtained, and the MAC-I is placed behind the MAC subPDU2 in the first MAC PDU, as shown in FIG. 13.

[0135] In addition, continuing to refer to FIG. 14, for the receiving end, after receiving the first MAC PDU, the above parameters can be input into the integrity protection algorithm to verify the integrity of the MAC subPDU2.

[0136] Example 2: Assuming that the first MAC PDU is as shown in FIG. 10A, and the MAC subPDU for integrity protection in the first MAC PDU is the MAC subPDU2, which is used to carry the MAC CE. Wherein the second identifier is the global identifier of the MAC subPDU2 (also referred to as MAC subPDU global identifier (MAC subPDU Global ID)), and is carried in the MAC subheader of the MAC subPDU carrying the MAC CE. The following describes the scheme for integrity protection of the MAC subPDU2 in the embodiment of the application.

[0137] FIG. 15 is a schematic diagram of integrity protection in the embodiment of the application. Referring to FIG. 15, for the sending end, the MAC subheader of the MAC subPDU carrying the MAC CE and the MAC CE can be integrity protected, wherein the parameters input into the integrity protection algorithm in the process of integrity protection include the following four kinds:

[0138] The key (Key) is generated by a key derivation method similar to the traditional method, and is a key for integrity protection of the MAC CE.

[0139] The MAC subPDU global identifier is similar to the COUNT value and the BEARER ID used in the PDCP layer integrity protection process, and is used to uniquely identify a MAC subPDU.

[0140] The message "MESSAGE" includes a MAC subheader of the MAC subPDU2 and a MAC CE carried in the MAC subPDU2.

[0141] The direction "DIRECTION" is used to indicate the direction of the first MAC PDU is downlink. For example, if the parameter takes a first value, it indicates that the direction of the first MAC PDU is downlink. Conversely, if the parameter takes a second value, it indicates that the direction of the first MAC PDU is downlink. Wherein the first value and the second value are different, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.

[0142] Correspondingly, referring to FIG. 15, the above parameters are input into the integrity protection algorithm for calculation, and the MAC-I corresponding to the MAC subPDU can be obtained. The MAC-I is placed after the MAC subPDU2 in the first MAC PDU, as shown in FIG. 13.

[0143] In addition, continuing to refer to FIG. 15, for the receiving end, after receiving the first MAC PDU, the above parameters can be input into the integrity protection algorithm for verification.

[0144] Implementation 2: The integrity protection is performed on the first MAC PDU for multiple MAC PDUs. That is, the integrity protection can be performed on the first MAC PDU with multiple MAC subPDUs as the granularity.

[0145] In some implementations, the first MAC PDU includes a fourth field for carrying a verification value (e.g., MAC-I) for verifying the integrity of the multiple MAC CEs, and the fourth field is located after the multiple MAC CEs and adjacent to the last MAC CE in the multiple MAC CEs in the first MAC PDU.

[0146] For example, referring to FIG. 16, it is assumed that the first MAC PDU includes N MAC subPDUs: MAC subPDU1, MAC subPDU2, …, MAC subPDU N, wherein N is an integer greater than 1, and the N MAC subPDUs are all integrity protected at the MAC layer. Correspondingly, the fourth field for carrying the verification value can be located after the MAC subPDU N.

[0147] In some embodiments, the parameters for integrity protection further include a second parameter (also referred to as "message "Message"") determined based on the plurality of MAC CEs, the field carrying the first identifier, and the plurality of MAC sub-headers corresponding to the plurality of MAC CEs. Of course, in the embodiments of the present application, if the first identifier is carried in the MAC sub-header corresponding to the first MAC sub-PDU, it can be understood that the second parameter can be determined based on the MAC sub-PDU and the MAC sub-header.

[0148] For ease of understanding, the following describes the scheme of integrity protection of all MAC sub-PDUs in the first MAC PDU as a whole in the embodiments of the present application in combination with the following scenario of Example 3.

[0149] Example 3: Assuming that the first MAC PDU is as shown in FIG. 8, the MAC sub-PDUs in the first MAC PDU are all used to carry MAC CEs, and the MAC sub-PDUs in the first MAC PDU are all integrity protected. Among them, the first identifier is used to identify the MAC PDU, and the second identifier is the LCID carried in the MAC sub-header of each MAC sub-PDU. The LCID carried in the MAC sub-header is shown in FIG. 10B. The following describes the scheme of integrity protection of the MAC sub-PDU 2 in the embodiments of the present application.

[0150] FIG. 17 is a schematic diagram of integrity protection in the embodiments of the present application. Referring to FIG. 17, for the sending end, the MAC sub-headers of all MAC sub-PDUs and the MAC CEs can be integrity protected, wherein the parameters input into the integrity protection algorithm in the process of integrity protection include the following 5 kinds:

[0151] The key "Key" is generated by a key derivation method similar to the traditional method to obtain a key for integrity protection of the MAC CEs.

[0152] The second identifier (also referred to as "MAC sub-PDU ID") is similar to the COUNT value used in the PDCP layer integrity protection process, and is used to distinguish different MAC sub-PDUs in the same MAC PDU. As described above, the second identifier can be the LCID corresponding to each MAC sub-PDU.

[0153] The message "MESSAGE" includes the MAC PDU header (a field carrying the first identifier), the MAC sub-headers of all MAC sub-PDUs in the first MAC PDU, and the MAC CEs carried in the MAC sub-PDUs and the MAC PDU header (carrying the field of the first identifier).

[0154] DIRECTION, used to indicate the direction of the first MAC PDU is downlink. For example, if the parameter takes a first value, it means that the direction of the first MAC PDU is downlink. Conversely, if the parameter takes a second value, it means that the direction of the first MAC PDU is downlink. Wherein the first value and the second value are different, for example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1.

[0155] The first identifier (also referred to as MAC PDU ID) is similar to the bearer identifier (BEARER ID) used in the PDCP layer integrity protection process, and is used to distinguish different MAC PDUs.

[0156] Correspondingly, referring to FIG. 17, the above parameters are input into the integrity protection algorithm for calculation, and the MAC-I corresponding to all MAC sub-PDUs in the first MAC PDU can be obtained. The MAC-I is placed after the last MAC sub-PDU in the first MAC PDU, as shown in FIG. 16.

[0157] In addition, continuing to refer to FIG. 17, for the receiving end, after receiving the first MAC PDU, the above parameters can be input into the integrity protection algorithm to verify the integrity of the MAC sub-PDU 2.

[0158] The above describes the method embodiments of the present application in combination with FIGS. 1-17, and the following describes the device embodiments of the present application in combination with FIGS. 18-20. It should be understood that the description of the method embodiments corresponds to the description of the device embodiments, and therefore, the parts not described in detail can be referred to the foregoing method embodiments.

[0159] FIG. 18 is a schematic diagram of a communication device according to an embodiment of the present application. The communication device 1800 shown in FIG. 18 is a first device, and the communication device 1800 includes a sending unit 1810.

[0160] The sending unit 1810 is configured to send a first MAC PDU to a second device, the first MAC PDU carrying a first parameter, the first parameter being used for integrity protection of a MAC CE in the first MAC PDU at a MAC layer, wherein the first parameter includes a first identifier and / or a second identifier, the first identifier being used to identify the first MAC PDU, and the second identifier being used to identify a MAC sub-PDU in which the MAC CE is located.

[0161] In some implementations, the first identifier is carried in a first field, and the first field is located before other fields in the first MAC PDU, the other fields being fields in the first MAC PDU other than the first field.

[0162] In some embodiments, the first identifier is carried in a first field, and the first field is located in a first MAC subheader of the first MAC PDU.

[0163] In some embodiments, the second identifier is carried in a second field, and the second field is located in a MAC subheader corresponding to the MAC subPDU.

[0164] In some embodiments, the first identifier comprises one or more of: an identifier of the first MAC PDU, an index of the first MAC PDU, a count value corresponding to the first MAC PDU.

[0165] In some embodiments, the second identifier comprises one or more of: an LCID corresponding to the MAC CE; an identifier of the MAC subPDU, an index of the MAC subPDU, a count value corresponding to the MAC subPDU.

[0166] In some embodiments, the second identifier is used to distinguish the MAC subPDU from all MAC PDUs to be transmitted; or the second identifier is used to distinguish the MAC subPDU in the first MAC PDU.

[0167] In some embodiments, the second identifier is used to distinguish the MAC subPDU in the first MAC PDU, and the first parameter comprises the first identifier and the second identifier.

[0168] In some embodiments, the second identifier is used to distinguish the MAC subPDU from all MAC PDUs to be transmitted, and the first parameter comprises only the second identifier.

[0169] In some embodiments, if all MAC CEs in the first MAC PDU are integrity protected, the first parameter comprises only the first identifier.

[0170] In some embodiments, the sending unit is further configured to send first indication information to the second device, the first indication information being used to indicate whether the first identifier is carried in the first MAC PDU, and / or the first indication information being used to indicate whether a MAC subPDU that is integrity protected is included in the first MAC PDU.

[0171] In some embodiments, the first indication information is carried in a third field, and the third field is located before the field carrying the first identifier in the first MAC PDU.

[0172] In some embodiments, the sending unit is further configured to send second indication information to the second device, the second indication information being used to indicate whether the MAC CE is integrity protected, or the second indication information being used to indicate all MAC CEs in the first MAC PDU that are integrity protected.

[0173] In some embodiments, the second indication information is used to indicate whether the MAC CE is integrity protected, and the second indication information is carried in a MAC subheader of the MAC subPDU.

[0174] In some embodiments, the second indication information is used to indicate all MAC CEs in the first MAC PDU that are integrity protected, and the second indication information is carried in a third field, the third field being located before a field carrying the first identifier in the first MAC PDU.

[0175] In some embodiments, each MAC CE in the first MAC PDU is integrity protected separately.

[0176] In some embodiments, the first MAC PDU includes a fourth field used to carry a verification value for verifying integrity of the MAC CE, the fourth field being located after and adjacent to the MAC CE in the first MAC PDU.

[0177] In some embodiments, the parameters for the integrity protection further include a second parameter determined based on the each MAC CE, the field carrying the first identifier, and a MAC subheader corresponding to the each MAC CE.

[0178] In some embodiments, multiple MAC CEs in the first MAC PDU are integrity protected together.

[0179] In some embodiments, the first MAC PDU includes a fourth field used to carry a verification value for verifying integrity of the multiple MAC CEs, the fourth field being located after and adjacent to a last MAC CE of the multiple MAC CEs in the first MAC PDU.

[0180] In some embodiments, the parameters for the integrity protection further include a second parameter determined based on the multiple MAC CEs, the field carrying the first identifier, and multiple MAC subheaders corresponding to the multiple MAC CEs.

[0181] In some embodiments, the integrity protection on the MAC CE in the first MAC PDU comprises integrity protection on the MAC CE and a MAC subheader corresponding to the MAC CE.

[0182] In some embodiments, the first device is a terminal device, and the second device is a network device; or the first device is a network device, and the second device is a terminal device.

[0183] FIG. 19 is a schematic diagram of a communication device according to an embodiment of the present application. The communication device 1900 shown in FIG. 19 is a second device, and the communication device 1900 comprises a receiving unit 1910.

[0184] The receiving unit 1910 is configured to receive a first MAC PDU sent by a first device, the first MAC PDU carrying a first parameter, the first parameter being used for integrity protection on a MAC CE in the first MAC PDU at a MAC layer, wherein the first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying a MAC sub-PDU in which the MAC CE is located.

[0185] In some embodiments, the first identifier is carried in a first field, and the first field is located before other fields in the first MAC PDU, the other fields being fields in the first MAC PDU other than the first field.

[0186] In some embodiments, the first identifier is carried in a first field, and the first field is located in a first MAC subheader of the first MAC PDU.

[0187] In some embodiments, the second identifier is carried in a second field, and the second field is located in a MAC subheader corresponding to the MAC sub-PDU.

[0188] In some embodiments, the first identifier comprises one or more of the following: an identifier of the first MAC PDU, an index of the first MAC PDU, and a count value corresponding to the first MAC PDU.

[0189] In some embodiments, the second identifier comprises one or more of the following: an LCID corresponding to the MAC CE, an identifier of the MAC sub-PDU, an index of the MAC sub-PDU, and a count value corresponding to the MAC sub-PDU.

[0190] In some embodiments, the second identifier is used to distinguish the MAC subPDU in all MAC PDUs to be transmitted; or the second identifier is used to distinguish the MAC subPDU in the first MAC PDU.

[0191] In some embodiments, the second identifier is used to distinguish the MAC subPDU in the first MAC PDU, and the first parameter includes the first identifier and the second identifier.

[0192] In some embodiments, the second identifier is used to distinguish the MAC subPDU in all MAC PDUs to be transmitted, and the first parameter only includes the second identifier.

[0193] In some embodiments, if all MAC CEs in the first MAC PDU are integrity protected, the first parameter only includes the first identifier.

[0194] In some embodiments, the receiving unit is configured to receive first indication information sent by the first device, the first indication information being used to indicate whether the first identifier is carried in the first MAC PDU, and / or the first indication information being used to indicate whether a MAC subPDU that is integrity protected is included in the first MAC PDU.

[0195] In some embodiments, the first indication information is carried in a third field, and the third field is located before a field carrying the first identifier in the first MAC PDU.

[0196] In some embodiments, the receiving unit is configured to receive second indication information sent by the first device, the second indication information being used to indicate whether the MAC CE is integrity protected, or the second indication information being used to indicate all MAC CEs that are integrity protected in the first MAC PDU.

[0197] In some embodiments, the second indication information is used to indicate whether the MAC CE is integrity protected, and the second indication information is carried in a MAC subheader of the MAC subPDU.

[0198] In some embodiments, the second indication information is used to indicate all MAC CEs that are integrity protected in the first MAC PDU, and the second indication information is carried in a third field, and the third field is located before a field carrying the first identifier in the first MAC PDU.

[0199] In some embodiments, each MAC CE in the first MAC PDU is integrity protected separately.

[0200] In some implementations, the first MAC PDU includes a fourth field for carrying a verification value for verifying the integrity of the MAC CEs, the fourth field being located in the first MAC PDU after the MAC CEs and adjacent to a last MAC CE of the MAC CEs.

[0201] In some implementations, the parameters for the integrity protection further include a second parameter determined based on the each MAC CE, the field carrying the first identity, and a MAC subheader corresponding to the each MAC CE.

[0202] In some implementations, the integrity protection is performed together for multiple MAC CEs in the first MAC PDU.

[0203] In some implementations, the first MAC PDU includes a fourth field for carrying a verification value for verifying the integrity of the multiple MAC CEs, the fourth field being located in the first MAC PDU after the multiple MAC CEs and adjacent to a last MAC CE of the multiple MAC CEs.

[0204] In some implementations, the parameters for the integrity protection further include a second parameter determined based on the multiple MAC CEs, the field carrying the first identity, and multiple MAC subheaders corresponding to the multiple MAC CEs.

[0205] In some implementations, the integrity protection of the MAC CEs in the first MAC PDU includes integrity protection of the MAC CEs and MAC subheaders corresponding to the MAC CEs.

[0206] In some implementations, the first device is a terminal device and the second device is a network device, or the first device is a network device and the second device is a terminal device.

[0207] In optional embodiments, the sending unit 1810 can be a transceiver 2030. The communication device 1800 can further include a processor 2010 and a memory 2020, as shown in FIG. 20.

[0208] In optional embodiments, the receiving unit 1910 can be a transceiver 2030. The communication device 1900 can further include a processor 2010 and a memory 2020, as shown in FIG. 20.

[0209] Fig. 20 is a schematic structural diagram of a communication apparatus according to an embodiment of the present application. The dashed line in Fig. 20 indicates that the unit or module is optional. The apparatus 2000 can be used to implement the method described in the above method embodiments. The apparatus 2000 can be a chip, a terminal device, or a network device.

[0210] The apparatus 2000 can include one or more processors 2010. The processor 2010 can support the apparatus 2000 to implement the method described in the above method embodiments. The processor 2010 can be a general processor or a dedicated processor. For example, the processor can be a central processing unit (CPU). Alternatively, the processor can also be other general processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic, discrete hardware components, etc. The general processor can be a microprocessor or the processor can also be any conventional processor.

[0211] The apparatus 2000 can also include one or more memories 2020. The memory 2020 stores a program, which can be executed by the processor 2010, so that the processor 2010 performs the method described in the above method embodiments. The memory 2020 can be independent of the processor 2010 or integrated in the processor 2010.

[0212] The apparatus 2000 can also include a transceiver 2030. The processor 2010 can communicate with other devices or chips through the transceiver 2030. For example, the processor 2010 can perform data transmission and reception with other devices or chips through the transceiver 2030.

[0213] The embodiments of the present application also provide a computer readable storage medium for storing a program. The computer readable storage medium can be applied to the terminal or network device provided by the embodiments of the present application, and the program causes the computer to execute the method performed by the terminal or network device in the various embodiments of the present application.

[0214] The embodiments of the present application also provide a computer program product. The computer program product includes a program. The computer program product can be applied to the terminal or network device provided by the embodiments of the present application, and the program causes the computer to execute the method performed by the terminal or network device in the various embodiments of the present application.

[0215] The embodiments of the present application further provide a computer program. The computer program can be applied to the terminal or the network device provided by the embodiments of the present application, and the computer program enables a computer to execute the method performed by the terminal or the network device in the embodiments of the present application.

[0216] It should be understood that the terms "system" and "network" can be used interchangeably in the present application. In addition, the terms used in the present application are only used to explain the specific embodiments of the present application, and are not intended to limit the present application. The terms "first", "second", "third", and "fourth" and the like in the specification and claims of the present application and the drawings are used to distinguish different objects, and are not used to describe a particular order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion.

[0217] In the embodiments of the present application, the "indication" mentioned can be direct indication, or indirect indication, or can be an indication of an associated relationship. For example, A indicates B, which can mean that B can be obtained by A; or A indirectly indicates B, for example, A indicates C, and B can be obtained by C; or A and B have an associated relationship.

[0218] In the embodiments of the present application, "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.

[0219] In the embodiments of the present application, the term "corresponding" can mean a direct or indirect corresponding relationship between the two, or can mean an associated relationship between the two, or can mean an indication and being indicated, configuration and being configured, and the like.

[0220] In the embodiments of the present application, "predefined" or "preconfigured" can be implemented by pre-saving corresponding codes, tables or other information that can be used to indicate related information in devices (for example, including terminal devices and network devices), and the present application does not limit the specific implementation manner. For example, predefinition can mean definition in a protocol.

[0221] In the embodiments of the present application, the "protocol" can refer to a standard protocol in the communication field, for example, can include an LTE protocol, an NR protocol, and a related protocol applied to a future communication system, and the present application does not limit this.

[0222] The term "and / or" used in the embodiments of the present application only describes an association relationship of associated objects, which means that there can be three relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in this document generally represents an "or" relationship between the front and rear associated objects.

[0223] In various embodiments of the present application, the size of the sequence number of the above processes does not mean the order of execution, and the execution order of the processes should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0224] In several embodiments provided by the present application, it should be understood that the disclosed system, device and method can be implemented by other ways. For example, the device embodiments described above are only schematic, and for example, the division of the units is only a logical function division, and there can be another division way in actual implementation, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed coupling or direct coupling or communication connection between each other can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.

[0225] The units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. According to actual needs, part or all of the units can be selected to achieve the purpose of the embodiments of the present application.

[0226] In addition, each functional unit in the various embodiments of the present application can be integrated into a processing unit, or each unit can exist physically independently, or two or more units can be integrated into one unit.

[0227] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be read by a computer or a data storage device such as a server, data center and the like integrated with one or more available media sets. The available media can be magnetic media (for example, floppy disk, hard disk, magnetic tape), optical media (for example, digital video disc (DVD)) or semiconductor media (for example, solid state disk (SSD)) and the like.

[0228] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method of wireless communication, comprising: Comprising: A first device sends a first medium access control (MAC) protocol data unit (PDU) to a second device, the first MAC PDU carrying a first parameter, the first parameter being used for integrity protection of a MAC CE in the first MAC PDU at a MAC layer, wherein the first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying a MAC sub-PDU where the MAC CE is located.

2. The method of claim 1, wherein, The first identifier is carried in a first field, the first field being located before other fields in the first MAC PDU, the other fields being fields in the first MAC PDU other than the first field.

3. The method of claim 1, wherein, The first identifier is carried in a first field, the first field being located in a first MAC sub-header of the first MAC PDU.

4. The method according to any one of claims 1 to 3, characterized in that, The second identifier is carried in a second field, the second field being located in a MAC sub-header corresponding to the MAC sub-PDU.

5. The method of any one of claims 1-4, wherein, The first identifier comprises one or more of: an identity of the first MAC PDU, an index of the first MAC PDU, a count value corresponding to the first MAC PDU.

6. The method of any one of claims 1-5, wherein, The second identifier comprises one or more of: an LCID corresponding to the MAC CE; an identity of the MAC sub-PDU, an index of the MAC sub-PDU, a count value corresponding to the MAC sub-PDU.

7. The method of any one of claims 1-6, wherein, The second identifier is used for distinguishing the MAC sub-PDU among all MAC PDUs to be transmitted; or the second identifier is used for distinguishing the MAC sub-PDU in the first MAC PDU.

8. The method of claim 7, wherein, The second identifier is used for distinguishing the MAC sub-PDU in the first MAC PDU, and the first parameter comprises the first identifier and the second identifier.

9. The method of claim 7, wherein, The second identifier is used for distinguishing the MAC sub-PDU among all MAC PDUs to be transmitted, and the first parameter comprises only the second identifier.

10. The method of any one of claims 1-6, wherein, If all MAC CEs in the first MAC PDU are integrity protected, the first parameter comprises only the first identifier.

11. The method of any one of claims 1-10, wherein, The method further comprises: The first device sends first indication information to the second device, the first indication information being used for indicating whether the first identifier is carried in the first MAC PDU, and / or The first indication information is used for indicating whether a MAC sub-PDU that is integrity protected is included in the first MAC PDU.

12. The method of claim 11, wherein, The first indication information is carried in a third field, the third field being located before a field carrying the first identifier in the first MAC PDU.

13. The method of any one of claims 1-12, wherein, The method further comprises: The first device sends second indication information to the second device, the second indication information being used for indicating whether the MAC CE is integrity protected, or The second indication information is used for indicating all MAC CEs that are integrity protected in the first MAC PDU.

14. The method of claim 13, wherein, The second indication information is used for indicating whether the MAC CE is integrity protected, and the second indication information is carried in a MAC subheader of the MAC subPDU.

15. The method of claim 13, wherein, The second indication information is used for indicating all MAC CEs in the first MAC PDU that are integrity protected, and the second indication information is carried in a third field, which is located before a field carrying the first identifier in the first MAC PDU.

16. The method of any one of claims 1-15, wherein, Each MAC CE in the first MAC PDU is integrity protected separately.

17. The method of claim 16, wherein, The first MAC PDU includes a fourth field used for carrying a verification value for verifying integrity of the MAC CE, and the fourth field is located after and adjacent to the MAC CE in the first MAC PDU.

18. The method of claim 16 or 17, wherein, The parameters for the integrity protection further include a second parameter determined based on the each MAC CE, the field carrying the first identifier, and a MAC subheader corresponding to the each MAC CE.

19. The method of any one of claims 1-15, wherein, Multiple MAC CEs in the first MAC PDU are integrity protected together.

20. The method of claim 19, wherein, The first MAC PDU includes a fourth field used for carrying a verification value for verifying integrity of the multiple MAC CEs, and the fourth field is located after and adjacent to a last MAC CE of the multiple MAC CEs in the first MAC PDU.

21. The method of claim 19 or 20, wherein, The parameters for the integrity protection further include a second parameter determined based on the multiple MAC CEs, the field carrying the first identifier, and multiple MAC subheaders corresponding to the multiple MAC CEs.

22. The method of any one of claims 1-21, wherein, Integrity protecting the MAC CEs in the first MAC PDU includes integrity protecting the MAC CEs and MAC subheaders corresponding to the MAC CEs.

23. The method of any one of claims 1-22, wherein, The first device is a terminal device, and the second device is a network device; or The first device is a network device, and the second device is a terminal device.

24. A method of wireless communication, comprising: Comprise: The second device receives a first MAC PDU sent by the first device, the first MAC PDU carrying a first parameter used for integrity protecting MAC CEs in the first MAC PDU at a MAC layer, The first parameter includes a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying a MAC subPDU in which the MAC CEs are located.

25. The method of claim 24, wherein, The first identifier is carried in a first field, and the first field is located before other fields in the first MAC PDU, the other fields being fields in the first MAC PDU other than the first field.

26. The method of claim 24, wherein, The first identifier is carried in a first field, and the first field is located in a first MAC subheader of the first MAC PDU.

27. The method of any one of claims 24-26, wherein, The second identifier is carried in a second field, and the second field is located in a MAC subheader corresponding to the MAC subPDU.

28. The method of any one of claims 24-27, wherein, The first identifier includes one or more of the following: an identifier of the first MAC PDU, an index of the first MAC PDU, and a count value corresponding to the first MAC PDU.

29. The method of any one of claims 24-28, wherein, The second identifier includes one or more of the following: an LCID corresponding to the MAC CE, an identifier of the MAC subPDU, an index of the MAC subPDU, and a count value corresponding to the MAC subPDU.

30. The method of any one of claims 24-29, wherein, The second identifier is used to distinguish the MAC subPDU from all MAC PDUs to be transmitted; or the second identifier is used to distinguish the MAC subPDU in the first MAC PDU.

31. The method of claim 30, wherein, The second identifier is used to distinguish the MAC subPDU in the first MAC PDU, and the first parameter includes the first identifier and the second identifier.

32. The method of claim 30, wherein, The second identifier is used to distinguish the MAC subPDU from all MAC PDUs to be transmitted, and the first parameter only includes the second identifier.

33. The method of any one of claims 24-29, wherein, If all MAC CEs in the first MAC PDU are integrity protected, the first parameter only includes the first identifier.

34. The method of any one of claims 24-33, wherein, The method further includes: The second device receives first indication information sent by the first device, and the first indication information is used to indicate whether the first identifier is carried in the first MAC PDU, and / or The first indication information is used to indicate whether a MAC subPDU that is integrity protected is included in the first MAC PDU.

35. The method of claim 34, wherein, The first indication information is carried in a third field, and the third field is located before a field carrying the first identifier in the first MAC PDU.

36. The method of any one of claims 24-35, wherein, The method further includes: The second device receives second indication information sent by the first device, and the second indication information is used to indicate whether the MAC CE is integrity protected, or The second indication information is used to indicate all MAC CEs that are integrity protected in the first MAC PDU.

37. The method of claim 36, wherein, The second indication information is used to indicate whether the MAC CE is integrity protected, and the second indication information is carried in a MAC subheader of the MAC subPDU.

38. The method of claim 36, wherein, The second indication information is used to indicate all MAC CEs that are integrity protected in the first MAC PDU, and the second indication information is carried in a third field, and the third field is located before a field carrying the first identifier in the first MAC PDU.

39. The method of any one of claims 24-38, wherein, Each MAC CE in the first MAC PDU is integrity protected separately.

40. The method of claim 39, wherein, The first MAC PDU includes a fourth field used to carry a verification value for verifying the integrity of the MAC CE, and the fourth field is located after and adjacent to the MAC CE in the first MAC PDU.

41. The method of claim 39 or 40, wherein, The parameters for the integrity protection further include a second parameter determined based on the each MAC CE, the field carrying the first identifier, and a MAC subheader corresponding to the each MAC CE.

42. The method of any one of claims 24-38, wherein, The integrity protection is performed on the multiple MAC CEs together in the first MAC PDU.

43. The method of claim 42, wherein, The first MAC PDU includes a fourth field for carrying a verification value for verifying the integrity of the multiple MAC CEs, the fourth field being located after the multiple MAC CEs and adjacent to a last MAC CE of the multiple MAC CEs in the first MAC PDU.

44. The method of claim 42 or 43, wherein, The parameters for the integrity protection further include a second parameter determined based on the multiple MAC CEs, the field carrying the first identifier, and multiple MAC subheaders corresponding to the multiple MAC CEs.

45. The method of any one of claims 24-44, wherein, The integrity protection on the MAC CEs in the first MAC PDU includes integrity protection on the MAC CEs and MAC subheaders corresponding to the MAC CEs.

46. The method of any one of claims 24-45, wherein, The first device is a terminal device, and the second device is a network device; or The first device is a network device, and the second device is a terminal device.

47. A communications device, characterized by The communication device is a first device, including: a sending unit configured to send a first MAC PDU to a second device, the first MAC PDU carrying a first parameter, the first parameter being used for integrity protection on MAC CEs in the first MAC PDU at a MAC layer, wherein the first parameter includes a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying a MAC subPDU in which the MAC CEs are located.

48. The communications device of claim 47 wherein, The first identifier is carried in a first field, the first field being located before other fields in the first MAC PDU, the other fields being fields in the first MAC PDU other than the first field.

49. The communications device of claim 47, wherein, The first identifier is carried in a first field, the first field being located in a first MAC subheader of the first MAC PDU.

50. The communication device of any of claims 47-49, wherein, The second identifier is carried in a second field, the second field being located in a MAC subheader corresponding to the MAC subPDU.

51. The communication device of any of claims 47-50, wherein, The first identifier includes one or more of the following: an identifier of the first MAC PDU, an index of the first MAC PDU, and a count value corresponding to the first MAC PDU.

52. The communication device of any one of claims 47-51, wherein, The second identifier includes one or more of the following: an LCID corresponding to the MAC CEs, an identifier of the MAC subPDU, an index of the MAC subPDU, and a count value corresponding to the MAC subPDU.

53. The communication device of any of claims 47-52, wherein, The second identifier is used for distinguishing the MAC subPDU from all MAC PDUs to be transmitted; or the second identifier is used for distinguishing the MAC subPDU in the first MAC PDU.

54. The communications device of claim 53, wherein, The second identifier is used to distinguish the MAC sub-PDU in the first MAC PDU, and the first parameter includes the first identifier and the second identifier.

55. The communications device of claim 53, wherein, The second identifier is used to distinguish the MAC sub-PDU in all MAC PDUs to be transmitted, and the first parameter only includes the second identifier.

56. The communication device of any one of claims 47-52, wherein, If all MAC CEs in the first MAC PDU are integrity protected, the first parameter only includes the first identifier.

57. The communication device of any of claims 47-56, wherein, The sending unit is further configured to: send first indication information to the second device, the first indication information being used to indicate whether the first identifier is carried in the first MAC PDU, and / or the first indication information is used to indicate whether the MAC sub-PDU that is integrity protected is included in the first MAC PDU.

58. The communications device of claim 57 wherein, The first indication information is carried in a third field, and the third field is located before a field carrying the first identifier in the first MAC PDU.

59. The communication device of any of claims 47-58, wherein, The sending unit is further configured to: send second indication information to the second device, the second indication information being used to indicate whether the MAC CE is integrity protected, or the second indication information is used to indicate all MAC CEs that are integrity protected in the first MAC PDU.

60. The communications device of claim 59 wherein, The second indication information is used to indicate whether the MAC CE is integrity protected, and the second indication information is carried in a MAC sub-header of the MAC sub-PDU.

61. The communications device of claim 59, wherein, The second indication information is used to indicate all MAC CEs that are integrity protected in the first MAC PDU, and the second indication information is carried in a third field, and the third field is located before a field carrying the first identifier in the first MAC PDU.

62. The communication device of any of claims 47-61, wherein, Each MAC CE in the first MAC PDU is integrity protected respectively.

63. The communications device of claim 62, wherein, The first MAC PDU includes a fourth field, the fourth field being used to carry a verification value for verifying the integrity of the MAC CE, and the fourth field is located after the MAC CE and adjacent to the MAC CE in the first MAC PDU.

64. The communication device of claim 62 or 63, wherein, The parameter for the integrity protection further includes a second parameter, the second parameter being determined based on the first identifier, a field carrying each MAC CE, and a MAC sub-header corresponding to each MAC CE.

65. The communication device of any of claims 47-61, wherein, Multiple MAC CEs in the first MAC PDU are integrity protected together.

66. The communications device of claim 65, wherein, The first MAC PDU includes a fourth field, the fourth field being used to carry a verification value for verifying the integrity of the multiple MAC CEs, and the fourth field is located after the multiple MAC CEs and adjacent to a last MAC CE in the multiple MAC CEs in the first MAC PDU.

67. The communication device of claim 65 or 66, wherein, The parameter for the integrity protection further includes a second parameter, the second parameter being determined based on the first identifier, a field carrying the multiple MAC CEs, and multiple MAC sub-headers corresponding to the multiple MAC CEs.

68. The communication device of any of claims 47-67, wherein, The integrity protection on the MAC CE in the first MAC PDU comprises integrity protection on the MAC CE and a MAC subheader corresponding to the MAC CE.

69. The communication device of any of claims 47-68, wherein, The first device is a terminal device, and the second device is a network device; or The first device is a network device, and the second device is a terminal device.

70. A communications device, characterized by The communication device is a second device, comprising: a receiving unit, configured to receive a first MAC PDU sent by a first device, the first MAC PDU carrying a first parameter, the first parameter being used for integrity protection on a MAC CE in the first MAC PDU at a MAC layer, wherein the first parameter comprises a first identifier and / or a second identifier, the first identifier being used for identifying the first MAC PDU, and the second identifier being used for identifying a MAC subPDU in which the MAC CE is located.

71. The communications device of claim 70 wherein, The first identifier is carried in a first field, and the first field is located before other fields in the first MAC PDU, the other fields being fields in the first MAC PDU other than the first field.

72. The communications device of claim 70, wherein The first identifier is carried in a first field, and the first field is located in a first MAC subheader of the first MAC PDU.

73. The communication device of any of claims 70-72, wherein, The second identifier is carried in a second field, and the second field is located in a MAC subheader corresponding to the MAC subPDU.

74. The communication device of any of claims 70-73, wherein, The first identifier comprises one or more of the following: an identifier of the first MAC PDU, an index of the first MAC PDU, and a count value corresponding to the first MAC PDU.

75. The communication device of any of claims 70-74, wherein, The second identifier comprises one or more of the following: an LCID corresponding to the MAC CE, an identifier of the MAC subPDU, an index of the MAC subPDU, and a count value corresponding to the MAC subPDU.

76. The communication device of any of claims 70-75, wherein, The second identifier is used for distinguishing the MAC subPDU from all MAC PDUs to be transmitted; or the second identifier is used for distinguishing the MAC subPDU in the first MAC PDU.

77. The communications device of claim 76 wherein, The second identifier is used for distinguishing the MAC subPDU in the first MAC PDU, and the first parameter comprises the first identifier and the second identifier.

78. The communications device of claim 76 wherein, The second identifier is used for distinguishing the MAC subPDU from all MAC PDUs to be transmitted, and the first parameter comprises only the second identifier.

79. The communication device of any of claims 70-75, wherein, If all MAC CEs in the first MAC PDU are integrity protected, the first parameter comprises only the first identifier.

80. The communication device of any of claims 70-79, wherein, The receiving unit is configured to: receive first indication information sent by the first device, the first indication information being used for indicating whether the first identifier is carried in the first MAC PDU, and / or the first indication information is used for indicating whether a MAC subPDU that is integrity protected is included in the first MAC PDU.

81. The communications device of claim 80 wherein, The first indication information is carried in a third field, and the third field is located before a field carrying the first identifier in the first MAC PDU.

82. The communication device of any of claims 70-81, wherein, The receiving unit is configured to: receiving second indication information sent by the first device, the second indication information being used to indicate whether the MAC CE is integrity protected, or the second indication information being used to indicate all MAC CEs in the first MAC PDU that are integrity protected.

83. The communications device of claim 82 wherein, the second indication information being used to indicate whether the MAC CE is integrity protected, the second indication information being carried in a MAC subheader of the MAC subPDU.

84. The communications device of claim 82, wherein the second indication information being used to indicate all MAC CEs in the first MAC PDU that are integrity protected, the second indication information being carried in a third field, the third field being located before a field carrying the first identifier in the first MAC PDU.

85. The communication device of any of claims 70-84, wherein, each MAC CE in the first MAC PDU is integrity protected separately.

86. The communications device of claim 85 wherein, the first MAC PDU includes a fourth field used to carry a verification value for verifying integrity of the MAC CE, the fourth field being located after and adjacent to the MAC CE in the first MAC PDU.

87. The communication device of claim 85 or 86, wherein, the parameters for the integrity protection further include a second parameter determined based on the first identifier, the field carrying the first identifier, and a MAC subheader corresponding to each MAC CE.

88. The communication device of any of claims 70-85, wherein, a plurality of MAC CEs in the first MAC PDU are integrity protected together.

89. The communication device of claim 88 wherein, the first MAC PDU includes a fourth field used to carry a verification value for verifying integrity of the plurality of MAC CEs, the fourth field being located after and adjacent to a last MAC CE in the plurality of MAC CEs in the first MAC PDU.

90. The communication device of claim 88 or 89, wherein, the parameters for the integrity protection further include a second parameter determined based on the first identifier, the field carrying the first identifier, and a plurality of MAC subheaders corresponding to the plurality of MAC CEs.

91. The communication device of any of claims 70-90, wherein, integrity protecting the MAC CE in the first MAC PDU includes integrity protecting the MAC CE and a MAC subheader corresponding to the MAC CE.

92. The communication device of any of claims 70-91, wherein, the first device is a terminal device, and the second device is a network device; or the first device is a network device, and the second device is a terminal device.

93. A communications device, characterized by a communication device including a transceiver, a memory, and a processor, the memory being used to store a program, the processor being used to invoke the program in the memory and control the transceiver to receive or send a signal, so that the communication device performs the method in any one of claims 1-46.

94. An apparatus comprising: a processor used to invoke a program from a memory, so that the apparatus performs the method in any one of claims 1-46.

95. A chip, comprising: a processor used to invoke a program from a memory, so that the apparatus performs the method in any one of claims 1-46.

96. A computer-readable storage medium, characterized in that, a computer program product, having a program stored thereon, the program causing a computer to perform the method in any one of claims 1-46.

97. A computer program product, characterized in that, comprising a program causing a computer to perform the method of any one of claims 1-46.

98. A computer program, characterized in that, The computer program causes a computer to perform the method of any one of claims 1-46.

Citation Information

Patent Citations

  • Communication method and device

    CN115696319A

  • Message transmission method, device and equipment

    CN118368616A

  • Initial security activation for medium access control layer

    WO2023175378A1

  • Devices and methods of communication

    WO2024152308A1