Communication method and device

By assembling and protecting only the MAC sub-units that require security protection at the MAC layer, the problem of insufficient security in MAC layer transmission is solved, security operation overhead is reduced, and transmission efficiency is improved.

WO2026065315A1PCT designated stage Publication Date: 2026-04-02GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-29
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

In existing 3GPP technologies, the MAC layer lacks security protection mechanisms, resulting in insufficient security for MAC sub-unit transmissions and excessive security protection overhead.

Method used

During MAC layer transmission, only MAC sub-units that require security protection are assembled and protected to generate secure MAC PDUs, thus avoiding security operations on MAC sub-units that do not require protection.

Benefits of technology

It achieves security assurance for the MAC subunit, while reducing unnecessary security computation overhead and improving transmission efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024122526_02042026_PF_FP_ABST
    Figure CN2024122526_02042026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a communication method and device. The method comprises: transmitting a first medium access control layer (MAC) protocol data unit (PDU) under security protection, the first MAC PDU consisting of one or more first MAC subunits requiring security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Communication method and device TECHNICAL FIELD

[0001] The present application relates to the field of communication, and more particularly, to a communication method and device. BACKGROUND

[0002] In the existing 3GPP technology, encryption and integrity protection are mainly performed at the NAS (Non-Access Stratum) and PDCP (Packet Data Convergence Protocol) layers. In the related art, no corresponding security protection mechanism is provided for the MAC (Medium Access Control) layer. However, with the development of technology, there is a demand for the MAC layer to also support security protection of a part of the data to be transmitted. Therefore, how to ensure the security of the MAC subunit transmitted by the MAC layer and at the same time avoid as much as possible the waste of the overhead caused by security operation has become a problem to be solved.

[0003] SUMMARY

[0004] Embodiments of the present application provide a communication method and device.

[0005] Embodiments of the present application provide a communication method performed by a first device, comprising:

[0006] transmitting a first medium access control layer (MAC) protocol data unit (PDU) that is security protected, wherein the first MAC PDU is composed of one or more first MAC subunits that need security protection.

[0007] Embodiments of the present application provide a first device, comprising:

[0008] a first communication unit configured to transmit a first medium access control layer (MAC) protocol data unit (PDU) that is security protected, wherein the first MAC PDU is composed of one or more first MAC subunits that need security protection.

[0009] Embodiments of the present application provide a first device, comprising a transceiver, a processor and a memory. The memory is configured to store a computer program, the transceiver is configured to communicate with other devices, and the processor is configured to invoke and run the computer program stored in the memory, so that the first terminal performs the above method.

[0010] Embodiments of the present application provide a chip for implementing the above method.

[0011] Specifically, the chip comprises a processor configured to invoke and run a computer program from a memory, so that a device installed with the chip performs the above method.

[0012] An embodiment of the present application provides a computer readable storage medium for storing a computer program, which, when executed by a device, causes the device to perform the method described above.

[0013] An embodiment of the present application provides a computer program product comprising computer program instructions, which cause a computer to perform the method described above.

[0014] An embodiment of the present application provides a computer program, which, when executed on a computer, causes the computer to perform the method described above.

[0015] By using the above scheme, the first device can assemble one or more MAC subunits that need security protection, and transmit the security-protected MAC PDU. In this way, since whether the MAC subunit needs security protection is considered, as many MAC subunits as possible that need security protection can be assembled in the MAC PDU and security-protected, so that the security of the MAC subunit transmitted in the MAC PDU can be ensured, and the problem of waste of security operation overhead caused by assembling MAC subunits that do not need security protection in the security-protected MAC PDU can be reduced or avoided as much as possible. BRIEF DESCRIPTION OF DRAWINGS

[0016] FIG. 1 is a schematic diagram of an application scenario according to an embodiment of the present application.

[0017] FIG. 2 is a schematic flowchart of a communication method according to an embodiment of the present application.

[0018] FIG. 3 is a schematic diagram of a scenario of composition of a downlink MAC PDU according to an embodiment of the present application.

[0019] FIG. 4 is a schematic diagram of a scenario of composition of an uplink MAC PDU according to an embodiment of the present application.

[0020] FIG. 5 is a schematic diagram of a scenario of assembling a MAC PDU from to-be-transmitted data according to an embodiment of the present application.

[0021] FIG. 6 is a schematic flowchart of processing at a terminal side according to an embodiment of the present application.

[0022] FIG. 7 is a schematic block diagram of a first device according to an embodiment of the present application.

[0023] FIG. 8 is a schematic block diagram of a communication device according to an embodiment of the present application.

[0024] FIG. 9 is a schematic block diagram of a chip according to an embodiment of the present application.

[0025] FIG. 10 is a schematic block diagram of a communication system according to an embodiment of the present application. DETAILED DESCRIPTION

[0026] The technical solutions of the embodiments of the present application can be applied to various communication systems, for example: LTE (Long Term Evolution), LTE-A (Long Term Evolution-Advanced), NR (New Radio), evolution of NR, WLAN (Wireless Local Area Network), WiFi (Wireless Fidelity), or other communication systems, etc.

[0027] The embodiments of the present application describe various embodiments in combination with network devices and terminals. The terminals can be mobile or fixed, and can also be referred to as mobile stations, user units, etc. The terminals can be stations in WLAN, and can be smart terminals, wireless modems, notebook computers, tablet computers, etc. In the embodiments of the present application, the terminals can be VR (Virtual Reality) terminals / AR (Augmented Reality) terminals, industrial control terminals, unmanned terminals, remote medical terminals, smart grid terminals, transportation safety terminals, smart city terminals, or wireless terminals of smart homes, etc. As an example but not limitation, in the embodiments of the present application, the terminals can also be wearable devices.

[0028] In the embodiments of the present application, the network device can be a device for communicating with the terminal. The network device can be an access point in WLAN, an evolved base station in LTE, or a relay station, or a vehicle-mounted device, a wearable device, and a network device in an NR network (gNB, the next Generation Node B), or a network device in a future evolved PLMN (Public Land Mobile Network), or a network device in a non-ground network, etc. As an example but not limitation, in the embodiments of the present application, the network device can have mobile characteristics, for example, the network device can be a mobile device.

[0029] In order to facilitate understanding of the technical solutions of the embodiments of the present application, the related technologies of the embodiments of the present application are described below. The following related technologies can be combined with the technical solutions of the embodiments of the present application in any way, and all belong to the protection scope of the embodiments of the present application.

[0030] FIG. 1 illustrates a communication system 100. The communication system includes a network device 110 and a terminal 120. In a possible implementation, the communication system 100 can include a plurality of network devices 110, and each network device 110 can include a plurality of terminals 120 within its coverage, which are not limited in the embodiments of the present application. In a possible implementation, the communication system 100 can further include a mobility management entity, an access and mobility management function, and other network entities, which are not limited in the embodiments of the present application. The network device can include an access network device and a core network device. That is, the communication system can include a plurality of core networks for communicating with the access network device. The access network device can be a base station of an LTE, LTE-A, or NR system. For example, the communication system shown in FIG. 1 can include network devices and terminals with communication functions, and can further include other devices in the communication system, such as a network controller, a mobility management entity, and other network entities, which are not limited in the embodiments of the present application.

[0031] FIG. 2 is a schematic flowchart of a communication method performed by a first device according to an embodiment of the present application. The method includes at least part of the following.

[0032] S210, a first media access control (MAC) protocol data unit (PDU) is transmitted, where the first MAC PDU is composed of one or more first MAC subunits that need security protection.

[0033] The security protection can include integrity protection and / or confidentiality protection. The confidentiality protection can also be referred to as encryption protection, which is not repeated in the following.

[0034] The first MAC PDU can be composed of one or more MAC subunits, or the first MAC PDU is assembled from one or more MAC subunits.

[0035] Any MAC subunit can also be referred to as a MAC subPDU.

[0036] Any MAC subunit can include at least one of the following: a subheader (or sub-packet header) corresponding to the MAC subunit (which can be denoted as a MAC subheader) and a payload of the MAC subunit.

[0037] The subheader corresponding to the MAC subunit can carry at least part of the indication fields of R (Reserved bit), L (Length indicator), F (Format indicator), and LCID (Logical Channel Identifier). The LCID can indicate the types of different MAC CEs or MAC SDUs. For example, a certain type of MAC CE corresponds to a specific LCID value. For example, the LCID value of a downlink TAC (Timing Advanced Command) MAC CE is 62. The LCID values corresponding to other types of MAC CEs or MAC SDUs are not limited or enumerated here.

[0038] The load of a MAC subunit can include data carried by the MAC subunit or data to be transmitted by the MAC subunit, and the type of the load of any MAC subunit can include one of a MAC service data unit (SDU), a MAC control element (CE), and padding bits. The MAC CE can be a fixed-size MAC CE or a variable-size MAC CE.

[0039] When the load of a MAC subunit is a MAC CE, the MAC CE can be a fixed-size MAC CE or a variable-size MAC CE. If a MAC subunit includes a fixed-size MAC CE, the subheader corresponding to the MAC subunit can include only R and LCID. If a MAC subunit includes a variable-size MAC CE, the subheader corresponding to the MAC subunit can include R, F, LCID, and L.

[0040] For example, a MAC sub-PDU can have the following composition cases: case 1, only the subheader corresponding to the MAC subunit; case 2, the subheader corresponding to the MAC subunit and the corresponding MAC SDU; case 3, the subheader corresponding to the MAC subunit and the corresponding MAC CE; case 4, the subheader corresponding to the MAC subunit and padding bits; and case 5, only padding bits.

[0041] The first device can be a terminal or an access network device. If the first device is a terminal, the first MAC PDU is an uplink MAC PDU sent by the terminal to the access network device. If the first device is an access network device, the first MAC PDU is a downlink MAC PDU sent by the access network device to the terminal.

[0042] The MAC sub-PDU containing the MAC CE is placed before the MAC sub-PDU containing the MAC SDU, and the MAC sub-PDU containing the MAC SDU is placed before the padding bit (or the MAC sub-PDU containing the padding bit) in the downlink MAC PDU. The composition of the downlink MAC PDU is exemplarily illustrated in combination with FIG. 3: the first MAC sub-PDU in the downlink MAC PDU contains the subheader and the corresponding fixed-size MAC CE1, and the second MAC sub-PDU contains the subheader and the corresponding variable-size MAC CE2; one or more MAC sub-PDUs containing the MAC SDU are assembled after the MAC sub-PDU containing the MAC CE2 in the downlink MAC PDU, and any one of the MAC sub-PDUs can contain the subheader and the MAC SDU; and the MAC sub-PDU containing the padding bit is assembled at the end of the downlink MAC PDU.

[0043] The MAC sub-PDU containing the MAC CE is placed after the MAC sub-PDU containing the MAC SDU, and the MAC sub-PDU containing the MAC CE is placed before the padding bit (or the MAC sub-PDU containing the padding bit) in the uplink MAC PDU. The composition of the uplink MAC PDU is exemplarily illustrated in combination with FIG. 4: one or more MAC sub-PDUs containing the MAC SDU are assembled at the front of the uplink MAC PDU, and any one of the MAC sub-PDUs can contain the subheader and the MAC SDU; the MAC sub-PDU containing the subheader and the fixed-size MAC CE3 and the MAC sub-PDU containing the subheader and the variable-size MAC CE4 are assembled after the one or more MAC sub-PDUs containing the MAC SDU; and the MAC sub-PDU containing the padding bit is assembled at the end of the uplink MAC PDU.

[0044] In addition, as shown in FIG. 3 and FIG. 4, the subheader in the downlink MAC PDU or the MAC sub-PDU containing the MAC CE or the MAC SDU in the downlink MAC PDU can carry at least part of R, L, F, and LCID.

[0045] In some possible implementation manners, the first device generates one or more first MAC sub-units before transmitting the first MAC PDU requiring security protection.

[0046] In an embodiment, the processing of the first device can further include: generating the one or more first MAC sub-units based on at least part of the one or more data to be transmitted requiring security protection.

[0047] The generating the one or more first MAC sub-elements based on at least part of the one or more to-be-transmitted data requiring security protection can comprise: in a case that the one or more to-be-transmitted data requiring security protection is included in the current overall to-be-transmitted data, generating the one or more first MAC sub-elements based on at least part of the one or more to-be-transmitted data requiring security protection.

[0048] For example, in a case that the one or more to-be-transmitted data requiring security protection is included in the current overall to-be-transmitted data, the first device can generate the one or more first MAC sub-elements based on at least part of the one or more to-be-transmitted data requiring security protection, which can comprise: the MAC layer of the first device obtaining the overall to-be-transmitted data, which can comprise at least one of the following: the one or more to-be-transmitted data requiring security protection, the one or more to-be-transmitted data not requiring security protection; the MAC layer of the first device determining whether the one or more to-be-transmitted data requiring security protection is included in the overall to-be-transmitted data; and if the one or more to-be-transmitted data requiring security protection is included, the MAC layer of the first device generating the one or more first MAC sub-elements based on at least part of the one or more to-be-transmitted data requiring security protection.

[0049] Here, the to-be-transmitted data can comprise one of the following: to-be-transmitted data of a logical channel, a MAC control element (CE, Control Element). The MAC CE can be generated by the MAC layer. The to-be-transmitted data of any logical channel is to-be-transmitted data from the logical channel, which can be transmitted from the upper layer to the MAC layer. The logical channel can also be replaced by a radio bearer (RB, Radio Bearer), or a data radio bearer (DRB, Data Radio Bearer), and in some possible examples, the logical channel can also be replaced by an SRB.

[0050] The determination manner of whether the to-be-transmitted data needs security protection is not limited in the embodiment. For example, if the to-be-transmitted data is a MAC CE, and the MAC CE is used to carry sensitive information or sensitive data, the MAC CE can be a MAC CE that needs security protection. The sensitive information can be configured according to actual conditions, such as at least one of a next hop chaining counter (NCC), a terminal ID, a timing advance (TA) amount, and the like. Here, all possible types of sensitive information are not limited or enumerated.

[0051] In addition, the processing of the first device can further include: in the case that the one or more to-be-transmitted data that needs security protection is not included in the current all to-be-transmitted data, generating the one or more fifth MAC subunits based on at least part of the one or more to-be-transmitted data that does not need security protection, and assembling and transmitting the first MAC PDU based on the one or more fifth MAC subunits. The specific processing manner of generating the one or more fifth MAC subunits based on at least part of the one or more to-be-transmitted data that does not need security protection, and assembling and transmitting the first MAC PDU based on the one or more fifth MAC subunits can be the same as the related protocol, and is not described herein.

[0052] In an embodiment, the processing of the first device can further include: in the case that the priority of the one or more to-be-transmitted data that needs security protection is not lower than the one or more to-be-transmitted data that does not need security protection, generating the one or more first MAC subunits based on at least part of the one or more to-be-transmitted data that needs security protection.

[0053] In the case that any one of the to-be-transmitted data is a MAC CE, the MAC CE can have a priority (which can be referred to as the priority of the MAC CE), and the priority of the MAC CE can be determined by the MAC layer, and the determination manner is not limited in the embodiment. In the case that any one of the to-be-transmitted data is to-be-transmitted data of a logical channel, the logical channel (or RB or DRB) has a corresponding priority (which can be referred to as the priority of the logical channel), and the priority of the logical channel can be configured by an upper layer (such as an RRC (Radio Resource Control) layer), and the specific configuration manner is not limited in the embodiment. It should be pointed out that the priority of the MAC CE is higher than the priority of the logical channel.

[0054] Further, the one or more to-be-transmitted data that need security protection can include to-be-transmitted data of one or more logical channels that need security protection, and / or one or more MAC CEs that need security protection; similarly, the one or more to-be-transmitted data that do not need security protection can include to-be-transmitted data of one or more logical channels that do not need security protection, and / or one or more MAC CEs that do not need security protection.

[0055] The priority of the one or more to-be-transmitted data that need security protection is not lower than the one or more to-be-transmitted data that do not need security protection, which can be determined in the case that any one of the following conditions is met:

[0056] The first condition is that the one or more to-be-transmitted data that need security protection only include one or more MAC CEs that need security protection, and the one or more to-be-transmitted data that do not need security protection only include to-be-transmitted data of one or more logical channels that do not need security protection.

[0057] The second condition is that the one or more to-be-transmitted data that need security protection only include one or more MAC CEs that need security protection, the one or more to-be-transmitted data that do not need security protection include one or more MAC CEs that do not need security protection, and the priority of the one or more MAC CEs that need security protection is not lower than the priority of the MAC CE that does not need security protection. The one or more to-be-transmitted data that do not need security protection can only include one or more MAC CEs that do not need security protection; or the one or more to-be-transmitted data that do not need security protection include one or more MAC CEs that do not need security protection and to-be-transmitted data of one or more logical channels that do not need security protection.

[0058] The third condition is that the one or more to-be-transmitted data requiring security protection includes to-be-transmitted data of one or more logical channels requiring security protection, the one or more to-be-transmitted data not requiring security protection only includes to-be-transmitted data of one or more logical channels not requiring security protection, and the priority of the one or more logical channels requiring security protection is not lower than the priority of the logical channel not requiring security protection. The one or more to-be-transmitted data requiring security protection can only include to-be-transmitted data of the one or more logical channels requiring security protection, or the one or more to-be-transmitted data requiring security protection includes one or more MAC CEs requiring security protection and to-be-transmitted data of one or more logical channels requiring security protection. For example, when the priority of the one or more to-be-transmitted data requiring security protection is not lower than the priority of the one or more to-be-transmitted data not requiring security protection, the processing of generating the one or more first MAC subunits based on at least part of the one or more to-be-transmitted data requiring security protection can be that the MAC layer of the first device obtains all to-be-transmitted data, which can include at least one of the one or more to-be-transmitted data requiring security protection and the one or more to-be-transmitted data not requiring security protection; the MAC layer of the first device determines whether the all to-be-transmitted data includes the one or more to-be-transmitted data requiring security protection; if the all to-be-transmitted data includes the one or more to-be-transmitted data requiring security protection, the MAC layer of the first device determines whether the priority of the one or more to-be-transmitted data requiring security protection is not lower than the priority of the one or more to-be-transmitted data not requiring security protection; and when the priority of the one or more to-be-transmitted data requiring security protection is not lower than the priority of the one or more to-be-transmitted data not requiring security protection, the processing of generating the one or more first MAC subunits based on at least part of the one or more to-be-transmitted data requiring security protection.

[0059] In addition, the processing of the first device can further include: if the one or more to-be-transmitted data requiring security protection are not included in the current overall to-be-transmitted data or if the priorities of the one or more to-be-transmitted data requiring security protection are all lower than those of the one or more to-be-transmitted data not requiring security protection, generating the one or more fifth MAC subunits based on at least part of the one or more to-be-transmitted data not requiring security protection, and assembling and transmitting the first MAC PDU based on the one or more fifth MAC subunits. In this case, if the first device has the one or more to-be-transmitted data requiring security protection this time and the priorities are lower than those of the to-be-transmitted data not requiring security protection, the first device does not transmit all the to-be-transmitted data requiring security protection when assembling the first MAC PDU this time, but leaves all the to-be-transmitted data requiring security protection generated this time for corresponding processing when assembling the MAC PDU next time. The related processing when assembling the MAC PDU next time should be the same as the processing mode adopted when assembling the first MAC PDU, and thus is not described herein.

[0060] In an embodiment, the one or more to-be-transmitted data requiring security protection include at least one of the following: one or more second to-be-transmitted data requiring security protection generated currently, and one or more third to-be-transmitted data requiring security protection remaining in assembling a second MAC PDU, wherein the transmission time of the second MAC PDU is earlier than that of the first MAC PDU.

[0061] The one or more second to-be-transmitted data requiring security protection generated currently can include to-be-transmitted data from a logical channel currently acquired by the MAC layer of the first device, and / or a MAC CE currently generated by the MAC layer of the first device.

[0062] The second MAC PDU can be a MAC PDU transmitted in a second resource, and the time domain range occupied by the second resource is earlier than a first resource used for transmitting the first MAC PDU.

[0063] The reason why the one or more third to-be-transmitted data requiring security protection remain in assembling the second MAC PDU can be as follows:

[0064] In one case, the second MAC PDU is a MAC PDU requiring security protection, and the data amount of the to-be-transmitted data requiring security protection (including all to-be-transmitted data from a logical channel and / or a MAC CE) is greater than the second resource when assembling the second MAC PDU, so that part of the one or more third to-be-transmitted data requiring security protection remains.

[0065] In another case, the second MAC PDU is a MAC PDU without security protection, the second MAC PDU is composed of one or more third MAC sub-units without security protection, and the priority of the one or more third to-be-transmitted data is lower than the one or more third MAC sub-units.

[0066] That is, the priority of the third to-be-transmitted data requiring security protection when assembling the second MAC PDU is lower than the to-be-transmitted data without security protection when assembling the second MAC PDU, so that when assembling the second MAC PDU, one or more third MAC sub-units without security protection are generated based on the to-be-transmitted data without security protection, and the second MAC PDU without security protection is transmitted, and all the third to-be-transmitted data requiring security protection generated when assembling the second MAC PDU is not transmitted, and the part of all the third to-be-transmitted data requiring security protection can be used as the to-be-transmitted data requiring security protection when assembling the first MAC PDU.

[0067] Here, the priority of the third to-be-transmitted data requiring security protection when assembling the second MAC PDU is lower than the to-be-transmitted data without security protection when assembling the second MAC PDU, which can be determined in any one of the following conditions:

[0068] The fourth condition is that the one or more third to-be-transmitted data requiring security protection when assembling the second MAC PDU only includes to-be-transmitted data of one or more logical channels requiring security protection, and the one or more to-be-transmitted data without security protection when assembling the second MAC PDU only includes one or more MAC CEs without security protection.

[0069] The fifth condition is that the one or more third to-be-transmitted data requiring security protection when assembling the second MAC PDU only includes one or more MAC CEs requiring security protection, the one or more to-be-transmitted data not requiring security protection when assembling the second MAC PDU includes one or more MAC CEs not requiring security protection, and the priority of at least one MAC CE requiring security protection is lower than that of the MAC CE not requiring security protection. Wherein, the one or more to-be-transmitted data not requiring security protection when assembling the second MAC PDU can only include one or more MAC CEs not requiring security protection; or, the one or more to-be-transmitted data not requiring security protection when assembling the second MAC PDU includes one or more MAC CEs not requiring security protection and to-be-transmitted data of one or more logical channels not requiring security protection. For example, as long as the priority of any one of all MAC CEs requiring security protection is lower than that of any one of the MAC CEs not requiring security protection, it can be determined that the priority of at least one MAC CE requiring security protection is lower than that of the MAC CE not requiring security protection.

[0070] The sixth condition is that the one or more third to-be-transmitted data requiring security protection when assembling the second MAC PDU includes to-be-transmitted data of one or more logical channels requiring security protection, the one or more to-be-transmitted data not requiring security protection when assembling the second MAC PDU only includes to-be-transmitted data of one or more logical channels not requiring security protection, and the priority of at least one logical channel requiring security protection is lower than that of the logical channel not requiring security protection. Wherein, the one or more third to-be-transmitted data requiring security protection when assembling the second MAC PDU can only include to-be-transmitted data of one or more logical channels requiring security protection; or, the one or more to-be-transmitted data requiring security protection when assembling the second MAC PDU can include one or more MAC CEs requiring security protection and to-be-transmitted data of one or more logical channels requiring security protection. For example, as long as the priority of any one of all logical channels requiring security protection is lower than that of any one of the logical channels not requiring security protection, it can be determined that the priority of at least one logical channel requiring security protection is lower than that of the logical channel not requiring security protection.

[0071] In some embodiments, the one or more first MAC subunits are generated based on at least part of the one or more to-be-transmitted data requiring security protection. There can be two possible embodiments. In one embodiment, the data amount of the one or more to-be-transmitted data requiring security protection is greater than the first resource. Then, the one or more first MAC subunits can be generated based on only part of the one or more to-be-transmitted data requiring security protection. In another embodiment, the data amount of the one or more to-be-transmitted data requiring security protection is not greater than the first resource. Then, the one or more first MAC subunits can be generated based on all of the one or more to-be-transmitted data requiring security protection.

[0072] In one embodiment, the data amount of the one or more to-be-transmitted data requiring security protection is greater than the first resource. Then, the one or more first MAC subunits are generated based on only part of the one or more to-be-transmitted data requiring security protection.

[0073] The one or more first MAC subunits are generated based on at least part of the one or more to-be-transmitted data requiring security protection. In one embodiment, the one or more first MAC subunits are generated based on one or more first to-be-transmitted data when the data amount of the one or more to-be-transmitted data requiring security protection is greater than the first resource. The one or more first to-be-transmitted data are part of the one or more to-be-transmitted data requiring security protection selected based on the priority and the first resource.

[0074] The first resource is the transmission resource of the first device for transmitting the first MAC PDU.

[0075] The data amount of the one or more to-be-transmitted data requiring security protection refers to the sum of the data amount of each to-be-transmitted data in the one or more to-be-transmitted data requiring security protection. The data amount of the one or more to-be-transmitted data requiring security protection being greater than the first resource means that the sum of the data amount of each to-be-transmitted data in the one or more to-be-transmitted data requiring security protection is greater than the size of the first resource.

[0076] That is, if the data amount of the one or more to-be-transmitted data requiring security protection is greater than the size of the first resource, it means that the transmission resource obtained this time cannot transmit all of the to-be-transmitted data requiring security protection at one time. Therefore, the first device generates the one or more first MAC subunits based on part of the one or more to-be-transmitted data requiring security protection, which is referred to as the first to-be-transmitted data.

[0077] The generating of the one or more first MAC subunits based on the one or more first to-be-transmitted data can be cyclically performed, wherein any one cycle of the processing can include: selecting the first to-be-transmitted data from the currently remaining one or more to-be-transmitted data that need security protection based on a priority; generating one or more first MAC subunits based on the first to-be-transmitted data selected this time; determining whether there is remaining resource in the first resource, and in the case that there is remaining resource in the first resource, performing the next cycle of the processing; and in the case that there is no remaining resource in the first resource, obtaining all the first MAC subunits and ending the processing.

[0078] In the case that the current cycle of the processing is the first cycle of the processing, the currently remaining one or more to-be-transmitted data that need security protection can be all the to-be-transmitted data that need security protection. In the case that the current cycle of the processing is not the first cycle of the processing, the currently remaining one or more to-be-transmitted data that need security protection can be, in addition to the one or more first to-be-transmitted data selected in all the cycles of the processing before the current cycle of the processing, the remaining one or more to-be-transmitted data that need security protection.

[0079] In one case, the currently remaining one or more to-be-transmitted data that need security protection only include the currently remaining one or more MAC CEs; or, the currently remaining one or more to-be-transmitted data that need security protection include the to-be-transmitted data of the currently remaining one or more logical channels that need security protection and the currently remaining one or more MAC CEs. In this case, the selecting of the first to-be-transmitted data from the currently remaining one or more to-be-transmitted data that need security protection based on the priority can be: selecting the MAC CE with the highest priority from the currently remaining one or more MAC CEs as the first to-be-transmitted data selected this time.

[0080] In one case, the currently remaining one or more to-be-transmitted data that need security protection only include the to-be-transmitted data of the currently remaining one or more logical channels that need security protection. In this case, the selecting of the first to-be-transmitted data from the currently remaining one or more to-be-transmitted data that need security protection based on the priority can be: selecting the logical channel with the highest current priority from the currently remaining one or more logical channels that need security protection, and taking the to-be-transmitted data of the logical channel with the highest current priority as the first to-be-transmitted data selected this time.

[0081] Based on the first selected data to be transmitted, one or more first MAC subunits are generated, which can include one of the following: in the case of the first selected data to be transmitted being data to be transmitted of a logical channel, one or more first MAC SDUs are generated based on the data to be transmitted of the logical channel, and a corresponding subheader is encapsulated for each of the one or more first MAC SDUs to obtain the one or more first MAC subunits; in the case of the first selected data to be transmitted being a first MAC CE, a corresponding subheader is encapsulated for the first MAC CE to obtain the first MAC subunit.

[0082] Optionally, the manner of determining whether the first resource has remaining resources can be: calculating a total data amount of all the first MAC subunits that have been generated, determining whether the total data amount is less than the first resource, and if so, determining that the first resource has remaining resources, otherwise, determining that the first resource does not have remaining resources.

[0083] Optionally, the manner of determining whether the first resource has remaining resources can be: calculating a total data amount of all the first MAC subunits that have been generated, calculating a first value by subtracting the total data amount from the first resource, determining whether the first value is equal to zero, and if not, determining that the first resource has remaining resources and taking the first value as the size of the remaining resources, otherwise, determining that the first resource does not have remaining resources.

[0084] Optionally, the manner of determining whether the first resource has remaining resources can be: calculating a total data amount of all the first selected data to be transmitted, determining whether the total data amount is less than the first resource, and if so, determining that the first resource has remaining resources, otherwise, determining that the first resource does not have remaining resources.

[0085] Optionally, the manner of determining whether the first resource has remaining resources can be: calculating a total data amount of all the first selected data to be transmitted, calculating a first value by subtracting the total data amount from the first resource, determining whether the first value is equal to zero, and if not, determining that the first resource has remaining resources and taking the first value as the size of the remaining resources, otherwise, determining that the first resource does not have remaining resources.

[0086] It should be noted that, since the data amount of the one or more to-be-transmitted data requiring security protection is greater than the size of the first resource, after the one or more first MAC subunits are generated by using the embodiment, there will still be remaining to-be-transmitted data requiring security protection in the one or more to-be-transmitted data requiring security protection. In this case, the remaining to-be-transmitted data requiring security protection can be left for processing when assembling a MAC PDU next time. The MAC PDU assembled next time refers to a MAC PDU transmitted on a next resource (such as a third resource occupying a time domain range later than the first resource). The way of assembling the MAC PDU next time can be the same as the related processing of the first MAC PDU, and no repeated description is made.

[0087] In an embodiment, the data amount of the one or more to-be-transmitted data requiring security protection is not greater than the first resource, and the one or more first MAC subunits can be generated based on all the to-be-transmitted data in the one or more to-be-transmitted data requiring security protection.

[0088] Generating the one or more first MAC subunits based on at least part of the one or more to-be-transmitted data requiring security protection can include: generating the one or more first MAC subunits based on the one or more to-be-transmitted data requiring security protection, in a case where the data amount of the one or more to-be-transmitted data requiring security protection is not greater than the first resource.

[0089] That is, if the data amount of the one or more to-be-transmitted data requiring security protection is not greater than the size of the first resource, it means that the transmission resource obtained this time can transmit all the to-be-transmitted data requiring security protection at one time. Therefore, the first device generates the one or more first MAC subunits based on all the to-be-transmitted data in the one or more to-be-transmitted data requiring security protection.

[0090] The processing of generating the one or more first MAC subunits based on the one or more to-be-transmitted data requiring security protection can be performed in a loop, wherein any one loop processing can include: selecting, as to-be-transmitted data selected this time, to-be-transmitted data requiring security protection with the highest priority from the currently remaining to-be-transmitted data requiring security protection based on the priority; generating one or more first MAC subunits based on the to-be-transmitted data selected this time; determining whether there is a priority of remaining to-be-transmitted data requiring security protection, and performing next loop processing in a case where there is a priority of remaining to-be-transmitted data requiring security protection; and obtaining all the first MAC subunits and ending the processing in a case where there is no priority of remaining to-be-transmitted data requiring security protection.

[0091] The related description of the one or more to-be-transmitted data that currently remain to be security protected is the same as the foregoing embodiments, and will not be repeated. The manner of selecting the to-be-transmitted data that currently has the highest priority and needs to be security protected is similar to the manner of selecting the first to-be-transmitted data in the foregoing embodiments, and will not be repeated.

[0092] Based on the selected to-be-transmitted data, one or more first MAC subunits are generated, which can include one of the following: in a case where the selected to-be-transmitted data is to-be-transmitted data of a logical channel, one or more first MAC SDUs are generated based on the to-be-transmitted data of the logical channel, a corresponding subheader is encapsulated for each of the one or more first MAC SDUs, and one or more first MAC subunits are obtained; in a case where the selected to-be-transmitted data is a first MAC CE, a corresponding subheader is encapsulated for the first MAC CE, and a first MAC subunit is obtained.

[0093] It should be noted that, since the data amount of the one or more to-be-transmitted data that needs to be security protected is not greater than the size of the first resource, after the one or more first MAC subunits are generated by using the embodiment, the first resource can still have remaining resources. The size of the remaining resources can be equal to the size of the first resource minus the data amount of the current all first MAC subunits; or the size of the remaining resources can be equal to the size of the first resource minus the data amount of all to-be-transmitted data that needs to be security protected.

[0094] In some possible implementation manners, the processing of the first device can further include: assembling the first MAC PDU based on the one or more first MAC subunits; and performing security protection on the first MAC PDU to obtain the security-protected first MAC PDU.

[0095] In some embodiments, in a case where the data amount of the one or more to-be-transmitted data that needs to be security protected is greater than the first resource, the one or more first MAC subunits generated can occupy the entire first resource. In this case, the first MAC PDU can be directly assembled based on the one or more first MAC subunits. Correspondingly, the transmission of the security-protected first MAC PDU includes: transmitting the security-protected first MAC PDU through the first resource.

[0096] The security protection on the first MAC PDU to obtain the security-protected first MAC PDU includes: performing security protection on the one or more first MAC subunits in the first MAC PDU to obtain the security-protected first MAC PDU.

[0097] The security protection on the one or more first MAC subunits in the first MAC PDU can include one of the following: integrity protection on each of the one or more first MAC subunits in the first MAC PDU to obtain an integrity-protected first MAC PDU; integrity protection and confidentiality protection on each of the one or more first MAC subunits in the first MAC PDU to obtain a first MAC PDU protected by integrity and confidentiality.

[0098] In an embodiment, the integrity protection on each of the one or more first MAC subunits in the first MAC PDU to obtain an integrity-protected first MAC PDU can include: performing integrity calculation on each of the first MAC subunits included in the first MAC PDU based on a MAC integrity key to obtain an integrity check code corresponding to the first MAC PDU, and adding the integrity check code corresponding to the first MAC PDU in the first MAC PDU to obtain the integrity-protected first MAC PDU.

[0099] The integrity calculation on each of the first MAC subunits included in the first MAC PDU based on a MAC integrity key to obtain an integrity check code corresponding to the first MAC PDU can be: integrity calculation on the payloads of all the first MAC subunits included in the first MAC PDU based on the MAC integrity key to obtain the integrity check code corresponding to the first MAC PDU; or integrity calculation on the subheaders and the payloads of all the first MAC subunits included in the first MAC PDU based on the MAC integrity key to obtain the integrity check code corresponding to the first MAC PDU.

[0100] In this example, the first MAC PDU can finally carry the content including each of the first MAC subunits and the integrity check code, and in addition, the first MAC PDU can further include a header of the first MAC PDU. The integrity check code can be placed at or carried in the last of the first MAC PDU, or the integrity check code can also be placed at or carried in the header of the first MAC PDU.

[0101] The MAC integrity key can be denoted as K MACint The MAC integrity key can be alternatively referred to as a MAC integrity protection key, a MAC integrity protection key, a MAC layer integrity key, a MAC layer integrity protection key, or any one of the other names. Here, all possible names of the MAC integrity key are not limited. In addition, the meaning of the integrity key, the integrity protection key, and the integrity protection key appearing in the following text is the same, and no repeated explanation is made.

[0102] The derivation manner of the MAC integrity key is not limited in the embodiment. The MAC integrity algorithm (or referred to as a MAC layer integrity protection algorithm, or a MAC layer integrity protection algorithm) used for calculating the integrity check code and the determination manner thereof are not limited in the embodiment.

[0103] In an embodiment, the integrity protection and the confidentiality protection are performed on each first MAC subunit in the first MAC PDU to obtain the first MAC PDU after the integrity protection and the confidentiality protection, which can include: performing integrity calculation on each first MAC subunit included in the first MAC PDU based on the MAC integrity key to obtain the integrity check code corresponding to the first MAC PDU, adding the integrity check code corresponding to the first MAC PDU in the first MAC PDU to obtain the first MAC PDU after the integrity protection; and performing encryption calculation on the first MAC PDU after the integrity protection based on the MAC confidentiality key to obtain the first MAC PDU after the integrity protection and the confidentiality protection.

[0104] The encryption calculation on the first MAC PDU after the integrity protection based on the MAC confidentiality key to obtain the first MAC PDU after the integrity protection and the confidentiality protection can be: performing encryption on the subheader and the payload of all first MAC subunits included in the first MAC PDU after the integrity protection based on the MAC confidentiality key to obtain the ciphertext data, and adding the ciphertext data to the first MAC PDU to obtain the first MAC PDU after the integrity protection and the confidentiality protection.

[0105] The addition of the ciphertext data to the first MAC PDU can be that the ciphertext data is directly added to the first MAC PDU as the content carried by the first MAC PDU. That is, the first MAC PDU can not carry the subheader and the payload of each first MAC subunit, but is replaced by carrying the ciphertext data.

[0106] Optionally, the encryption on the subheader and the payload of all first MAC subunits included in the first MAC PDU after the integrity protection based on the MAC confidentiality key to obtain the ciphertext data. In this case, the integrity check code is not encrypted, and therefore the content that the first MAC PDU finally carries can include the ciphertext data and the integrity check code; in addition, the first MAC PDU can also include the header of the first MAC PDU. The integrity check code can be placed or carried after the ciphertext data at the end of the first MAC PDU, or the integrity check code can be placed or carried in the header of the first MAC PDU.

[0107] Optionally, the sub-headers and payloads of all the first MAC subunits contained in the first MAC PDU for integrity protection are encrypted based on the MAC confidentiality key to obtain ciphertext data, which can be that the integrity check code, the sub-headers and the payloads of all the first MAC subunits contained in the first MAC PDU for integrity protection are encrypted based on the MAC confidentiality key to obtain ciphertext data. In this case, the integrity check code is also encrypted, so the first MAC PDU can finally carry content including the ciphertext data; in addition, the first MAC PDU can also include the header of the first MAC PDU.

[0108] The MAC confidentiality key can be represented as K MACenc The MAC confidentiality key can also be alternatively referred to as any one of a MAC (or MAC layer) confidentiality protection key, a MAC (or MAC layer) encryption key, a MAC (or MAC layer) decryption key, a MAC layer confidentiality key, and the like, which are not limited or enumerated herein. In addition, the confidentiality key, the encryption key, and the decryption key appearing below have the same meaning and are not repeated.

[0109] The derivation manner of the MAC confidentiality key is not limited in the embodiment. The MAC confidentiality algorithm (or referred to as a MAC layer confidentiality protection algorithm or a MAC layer encryption algorithm) used to calculate the ciphertext data and the determination manner thereof are also not limited in the embodiment.

[0110] In the above various embodiments, the first MAC PDU can occupy all the first resources, so after assembling or generating the first MAC PDU for security protection, the first MAC PDU for security protection can be directly transmitted through the first resources.

[0111] In some embodiments, the first resources have remaining resources. The first resources having remaining resources means that after assembling all the first MAC subunits that need to be protected, the first resources still have remaining resources. For example, if the data amount of one or more data to be transmitted that need security protection is not greater than the first resources, after assembling all the first MAC subunits that need to be protected, the first resources can still have remaining resources.

[0112] In an embodiment, the assembling the first MAC PDU based on the one or more first MAC subunits comprises: assembling the first MAC PDU based on the one or more first MAC subunits and padding bits in the case that the first resources have remaining resources. Correspondingly, the transmitting the first MAC PDU for security protection comprises: transmitting the first MAC PDU for security protection through the first resources.

[0113] Optionally, the security protection on the one or more first MAC subunits in the first MAC PDU comprises integrity protection on each of the one or more first MAC subunits in the first MAC PDU, to obtain an integrity-protected first MAC PDU. The specific processing is the same as the foregoing embodiments, and thus no further description is given.

[0114] In this case, the first MAC PDU can finally carry the content including each first MAC subunit, the integrity check code, the padding bit, and in addition, the first MAC PDU can further include the header of the first MAC PDU. The integrity check code can be placed or carried after all the first MAC subunits in the first MAC PDU and before the padding bit, or the integrity check code can be placed or carried after all the first MAC subunits and the padding bit in the first MAC PDU, or the integrity check code can also be placed or carried in the header of the first MAC PDU.

[0115] Optionally, the security protection on the one or more first MAC subunits in the first MAC PDU comprises integrity protection and confidentiality protection on each of the one or more first MAC subunits in the first MAC PDU, to obtain a first MAC PDU that is integrity-protected and confidentiality-protected. The specific processing is the same as the foregoing embodiments, and thus no further description is given.

[0116] In one case, the MAC confidentiality key is used to encrypt the subheader and the payload of the first MAC subunit contained in the integrity-protected first MAC PDU, to obtain ciphertext data.

[0117] In this case, the integrity check code is not encrypted, and thus the first MAC PDU can finally carry the content including the ciphertext data, the integrity check code, and the padding bit; in addition, the first MAC PDU can further include the header of the first MAC PDU. The integrity check code can be placed or carried after the ciphertext data in the first MAC PDU and before the padding bit, or the integrity check code can be placed or carried after the ciphertext data and the padding bit in the first MAC PDU, or the integrity check code can also be placed or carried in the header of the first MAC PDU.

[0118] In another case, the MAC confidentiality key is used to encrypt the integrity check code, the subheader, and the payload of the first MAC subunit contained in the integrity-protected first MAC PDU, to obtain ciphertext data.

[0119] In this case, the integrity check code is also encrypted, and therefore the first MAC PDU can finally carry content including cipher data and padding bits; in addition, the first MAC PDU can also include a header of the first MAC PDU.

[0120] In the above embodiment, the size of the padding bits is not limited, for example, the size of the padding bits can be such that the padding bits can fill the remaining resources of the first resources.

[0121] In the above embodiment, the first MAC PDU can occupy all the first resources, and therefore after assembling or generating the security-protected first MAC PDU, the security-protected first MAC PDU can be directly transmitted through the first resources.

[0122] In one embodiment, the assembling the first MAC PDU based on the one or more first MAC subunits includes: in a case where there is remaining resources in the first resources, generating one or more fourth MAC subunits based on the remaining resources and one or more data to be transmitted which do not need security protection; and assembling the first MAC PDU based on the one or more first MAC subunits and the one or more fourth MAC subunits. Correspondingly, the transmitting the security-protected first MAC PDU includes: transmitting the security-protected first MAC PDU through the first resources.

[0123] For example, based on the remaining resources and the one or more to-be-transmitted data without security protection, one or more fourth MAC subunits are generated, which can be cyclically executed, wherein any one cycle processing can include: selecting, based on the priority, the one to-be-transmitted data without security protection with the highest priority from the currently remaining one or more to-be-transmitted data without security protection as the fourth to-be-transmitted data selected this time; generating one or more fourth MAC subunits based on the fourth to-be-transmitted data selected this time; judging whether there are remaining resources, and if there are, performing the next cycle processing; and if there are not, obtaining all fourth MAC subunits and ending the processing. Here, in the case of the current cycle processing being the first cycle processing, the currently remaining one or more to-be-transmitted data without security protection can be all to-be-transmitted data without security protection; in the case of the current cycle processing not being the first cycle processing, the currently remaining one or more to-be-transmitted data without security protection can be, in addition to the one or more fourth to-be-transmitted data selected in all cycle processing before the current cycle processing, the remaining one or more to-be-transmitted data without security protection. Wherein, the related processing of selecting the one to-be-transmitted data without security protection with the highest priority is similar to the processing of selecting the one to-be-transmitted data with the highest priority in the foregoing embodiments, and the difference is only that the current example is replaced by selecting one to-be-transmitted data from to-be-transmitted data without security protection, and therefore no repeated description is made.

[0124] It should be pointed out that the above is only an exemplary description, and in actual processing, based on the remaining resources and the one or more to-be-transmitted data without security protection, one or more fourth MAC subunits can also be generated by using other processing modes, and the present embodiment is not limited or exhaustive.

[0125] After assembling the first MAC PDU based on the one or more first MAC subunits and the one or more fourth MAC subunits, the first MAC PDU can be subjected to security protection to obtain the first MAC PDU with security protection.

[0126] In an example, the first MAC PDU with security protection can be obtained by subjecting the one or more first MAC subunits in the first MAC PDU to security protection. That is, in the current example, only all first MAC subunits in the first MAC PDU are subjected to security protection, and the fourth MAC subunit is not subjected to security protection.

[0127] Optionally, the one or more first MAC subunits in the first MAC PDU are security protected to obtain a security-protected first MAC PDU. The security-protected first MAC PDU can include: all first MAC subunits contained in the first MAC PDU are integrity protected to obtain an integrity-protected first MAC PDU. The specific processing of integrity protecting all first MAC subunits contained in the first MAC PDU to obtain an integrity-protected first MAC PDU is the same as the foregoing embodiments, and will not be described herein.

[0128] The final content that the first MAC PDU can carry can include each first MAC subunit, an integrity check code, each fourth MAC subunit, and in addition, the first MAC PDU can further include a header of the first MAC PDU. All first MAC subunits can be placed before all fourth MAC subunits; the integrity check code can be placed or carried after all first MAC subunits and before all fourth MAC subunits in the first MAC PDU, or the integrity check code can be placed or carried in the header of the first MAC PDU.

[0129] Optionally, the one or more first MAC subunits in the first MAC PDU are security protected to obtain a security-protected first MAC PDU. The security-protected first MAC PDU can include: all first MAC subunits contained in the first MAC PDU are integrity and confidentiality protected to obtain a first MAC PDU that is integrity and confidentiality protected. The specific processing of integrity and confidentiality protecting all first MAC subunits contained in the first MAC PDU to obtain a first MAC PDU that is integrity and confidentiality protected is the same as the foregoing embodiments, and will not be described herein.

[0130] In one case, the subheader and payload of all first MAC subunits contained in the integrity-protected first MAC PDU are encrypted based on a MAC confidentiality key to obtain ciphertext data.

[0131] In this case, the integrity check code is not encrypted, and therefore the final content that the first MAC PDU can carry can include ciphertext data, an integrity check code, and each fourth MAC subunit; in addition, the first MAC PDU can further include a header of the first MAC PDU. The ciphertext data can be placed before all fourth MAC subunits; the integrity check code can be placed or carried after the ciphertext data and before all fourth MAC subunits in the first MAC PDU, or the integrity check code can be placed or carried in the header of the first MAC PDU.

[0132] In another case, the integrity check code contained in the first MAC PDU, the sub-headers and the payloads of all the first MAC sub-units are encrypted based on the MAC confidentiality key to obtain cipher data.

[0133] In this case, the integrity check code is also encrypted, and therefore the first MAC PDU can finally carry content including the cipher data and each fourth MAC sub-unit; in addition, the first MAC PDU can also include the header of the first MAC PDU. The cipher data can be placed before all the fourth MAC sub-units.

[0134] In an example, the security protection of the first MAC PDU to obtain the security-protected first MAC PDU can include: performing security protection on the one or more first MAC sub-units and the one or more fourth MAC sub-units in the first MAC PDU to obtain the security-protected first MAC PDU. That is, in this example, security protection is performed on all the MAC sub-units contained in the first MAC PDU.

[0135] The security protection of the one or more first MAC sub-units and the one or more fourth MAC sub-units in the first MAC PDU to obtain the security-protected first MAC PDU can include one of the following: performing integrity protection on each first MAC sub-unit in the first MAC PDU and each fourth MAC sub-unit in the one or more fourth MAC sub-units to obtain the integrity-protected first MAC PDU; performing integrity protection and confidentiality protection on each first MAC sub-unit in the first MAC PDU and each fourth MAC sub-unit to obtain the first MAC PDU after integrity protection and confidentiality protection.

[0136] In a case, the integrity protection of each first MAC sub-unit in the first MAC PDU and each fourth MAC sub-unit in the one or more fourth MAC sub-units to obtain the integrity-protected first MAC PDU can be: performing integrity calculation on each first MAC sub-unit and each fourth MAC sub-unit contained in the first MAC PDU based on the MAC integrity key to obtain the integrity check code corresponding to the first MAC PDU, adding the integrity check code corresponding to the first MAC PDU in the first MAC PDU to obtain the integrity-protected first MAC PDU.

[0137] The related description about calculating the integrity check code is similar to the foregoing embodiment, and the difference is that in the present case, the integrity check code is calculated based on all the first MAC subunits and all the fourth MAC subunits, and thus the repeated description is omitted.

[0138] The content that the first MAC PDU finally can carry can include each first MAC subunit, the integrity check code, each fourth MAC subunit, and in addition, the first MAC PDU can further include the header of the first MAC PDU. Among them, all the first MAC subunits can be placed before all the fourth MAC subunits; the integrity check code can be placed or carried after all the first MAC subunits and all the fourth MAC subunits in the first MAC PDU, or the integrity check code can be placed or carried in the header of the first MAC PDU.

[0139] In one case, the first MAC PDU after integrity protection and confidentiality protection can be obtained by performing integrity protection and confidentiality protection on each first MAC subunit and each fourth MAC subunit in the first MAC PDU. Specifically, the integrity check code corresponding to the first MAC PDU can be calculated based on the MAC integrity key by performing integrity calculation on each first MAC subunit and each fourth MAC subunit included in the first MAC PDU, and then the integrity check code corresponding to the first MAC PDU is added to the first MAC PDU to obtain the first MAC PDU after integrity protection. Then, the first MAC PDU after integrity protection is encrypted based on the MAC confidentiality key to obtain the first MAC PDU after integrity protection and confidentiality protection.

[0140] The related description about calculating the integrity check code is similar to the foregoing embodiment, and the difference is that in the present case, the integrity check code is calculated based on all the first MAC subunits and all the fourth MAC subunits, and thus the repeated description is omitted.

[0141] The first MAC PDU after integrity protection and confidentiality protection can be obtained by performing encryption calculation on the first MAC PDU after integrity protection based on the MAC confidentiality key. Specifically, the ciphertext data can be obtained by performing encryption on the subheader and the payload of all the first MAC subunits and all the fourth MAC subunits included in the first MAC PDU after integrity protection based on the MAC confidentiality key, and then the ciphertext data is added to the first MAC PDU to obtain the first MAC PDU after integrity protection and confidentiality protection.

[0142] For example, the processing of calculating the cipher text data only needs to encrypt the sub-headers and payloads of all the first MAC sub-elements and the sub-headers and payloads of all the fourth MAC sub-elements included in the first MAC PDU for integrity protection based on the MAC confidentiality key, to obtain the cipher text data. The relevant description about calculating the cipher text data is similar to the foregoing embodiments, and the difference is that in the present case, the cipher text data is calculated based on all the first MAC sub-elements and all the fourth MAC sub-elements, and thus the description is not repeated.

[0143] That is, the integrity check code is not encrypted, and thus the content that the first MAC PDU finally carries can include the cipher text data and the integrity check code. In addition, the first MAC PDU can also include the header of the first MAC PDU. The integrity check code can be placed or carried after the cipher text data in the first MAC PDU, or the integrity check code can be placed or carried in the header of the first MAC PDU.

[0144] For example, the processing of calculating the cipher text data needs to encrypt the integrity check code, the sub-headers and payloads of all the first MAC sub-elements, and the sub-headers and payloads of all the fourth MAC sub-elements included in the first MAC PDU for integrity protection based on the MAC confidentiality key, to obtain the cipher text data.

[0145] That is, the integrity check code is also encrypted, and thus the content that the first MAC PDU finally carries can include the cipher text data. In addition, the first MAC PDU can also include the header of the first MAC PDU.

[0146] In the foregoing embodiments, the first MAC PDU can occupy all the first resources, and thus after the first MAC PDU for security protection is assembled or generated, the first MAC PDU for security protection can be directly transmitted through the first resources.

[0147] In an embodiment, the assembling the first MAC PDU based on the one or more first MAC sub-elements includes: assembling the first MAC PDU based on the one or more first MAC sub-elements in the case that there is remaining resource in the first resources.

[0148] Correspondingly, the security protection of the first MAC PDU to obtain the first MAC PDU for security protection includes: security protection of the one or more first MAC sub-elements in the first MAC PDU to obtain the first MAC PDU for security protection.

[0149] The transmitting the first MAC PDU for security protection includes: transmitting the first MAC PDU for security protection through the first resources.

[0150] In this embodiment, the first MAC PDU is securely protected to obtain a securely protected first MAC PDU, including securely protecting the one or more first MAC subunits in the first MAC PDU to obtain the securely protected first MAC PDU.

[0151] In one case, securely protecting the one or more first MAC subunits in the first MAC PDU to obtain the securely protected first MAC PDU includes integrity protecting each first MAC subunit in the one or more first MAC subunits in the first MAC PDU to obtain an integrity protected first MAC PDU. Here, the processing of calculating the integrity check code is also only performed on each first MAC subunit, and the specific calculation manner is the same as that in the foregoing embodiment, which will not be described herein.

[0152] In this case, the first MAC PDU can finally carry content including each first MAC subunit and the integrity check code, and in addition, the first MAC PDU can also include a header of the first MAC PDU. The integrity check code can be placed or carried at the end of the first MAC PDU, or the integrity check code can also be placed or carried at the header of the first MAC PDU.

[0153] In one case, securely protecting the one or more first MAC subunits in the first MAC PDU to obtain the securely protected first MAC PDU includes integrity protecting and confidentiality protecting each first MAC subunit in the first MAC PDU to obtain a first MAC PDU that is integrity protected and confidentiality protected.

[0154] If the integrity check code is not encrypted, only the subheader and the payload of all the first MAC subunits included in the integrity protected first MAC PDU are encrypted based on the MAC confidentiality key to obtain ciphertext data; the first MAC PDU can finally carry content including the ciphertext data and the integrity check code; in addition, the first MAC PDU can also include a header of the first MAC PDU. The integrity check code can be placed or carried at the end of the first MAC PDU, i.e., after the ciphertext data, or the integrity check code can also be placed or carried at the header of the first MAC PDU.

[0155] If the integrity check code is encrypted, that is, the integrity check code contained in the first MAC PDU for integrity protection, the sub-headers and payloads of all first MAC sub-units are encrypted based on the MAC confidentiality key to obtain ciphertext data; the final content that the first MAC PDU can carry can include the ciphertext data; in addition, the first MAC PDU can also include the header of the first MAC PDU.

[0156] In the above processing, the processing of calculating the integrity check code and calculating the ciphertext data is also only performed on each first MAC sub-unit, and the specific calculation manner is the same as that of the foregoing embodiments, which will not be described herein.

[0157] After the first MAC PDU for security protection is assembled or generated, the first MAC PDU for security protection can be directly transmitted through the first resource.

[0158] In addition, the method further includes: generating one or more fourth MAC sub-units based on the remaining resources and one or more to-be-transmitted data that do not need security protection; and assembling a third MAC PDU that does not need security protection based on the one or more fourth MAC sub-units. Further, the method can further include: transmitting the third MAC PDU through the remaining resources.

[0159] In the foregoing embodiment, the one or more fourth MAC sub-units are generated based on the remaining resources and one or more to-be-transmitted data that do not need security protection, and the related description is the same as that of the foregoing embodiment, which will not be repeated.

[0160] The related processing of assembling the third MAC PDU that does not need security protection based on the one or more fourth MAC sub-units is the same as that of the related protocol, which will not be described herein.

[0161] After the processing of the present embodiment is adopted, the first MAC PDU for security protection can be finally transmitted on the first resource, and the third MAC PDU that does not need security protection can be transmitted on the remaining resources after the first MAC PDU for security protection.

[0162] In a case that the first device is an access network device, the access network device can employ the communication method provided in this embodiment to perform the packaging and transmission of the downlink MAC PDU, that is, the first MAC PDU is the downlink MAC PDU generated and transmitted by the access network device, and the first resource can be the downlink resource used by the access network device to transmit the downlink MAC PDU this time. Correspondingly, the terminal side can receive the first MAC PDU that is securely protected, and the terminal can perform integrity check on the first MAC PDU using the MAC integrity key, or the terminal can first decrypt the cipher data carried by the first MAC PDU using the MAC confidentiality key, and then perform integrity check on the first MAC PDU using the MAC integrity key. Here, the processing performed by the terminal is not limited or exhausted.

[0163] The following will be exemplarily described taking the first device as a terminal as an example:

[0164] In the related protocol, when assembling the MAC PDU, the data to be transmitted can come from the data of the MAC CE and / or the DRB (i.e., the data of the logical channel to be transmitted). As shown in FIG. 5, the terminal can assemble the MAC PDU based on the data of the MAC CE1, the MAC CE2, the MAC CE3, the DRB1, the data of the DRB2, and the data of the DRB3. It should be noted that FIG. 5 is only an exemplary description, and does not limit the number of MAC CEs and the data of the DRBs included when the terminal assembles the MAC PDU, nor does it limit the number of MAC PDUs finally assembled. For example, the terminal can assemble one MAC PDU based on the MAC CE1, the MAC CE2, and the data of the DRB1, and assemble another MAC PDU based on the MAC CE3, the data of the DRB2, and the data of the DRB3, and so on. Here, all possible cases are not limited or exhausted.

[0165] In the related design of the 6G MAC layer, it is necessary to support the security protection (encryption and / or integrity protection) of some MAC CEs and / or the data (i.e., the to-be-transmitted data of the logical channel) of the DRB. Specifically, when the terminal performs uplink MAC PDU packaging, some MAC CEs have been triggered, and part of the MAC CEs are MAC CEs carrying sensitive information or sensitive data, and according to the related configuration, it can be determined that this part of the MAC CEs is the to-be-transmitted data that needs security protection. In addition, the terminal is also configured with multiple DRBs, and according to different configurations, the data of some DRBs needs to be protected (encrypted and / or integrity protected), and the data of some DRBs does not need to be executed security calculation (encryption and / or integrity protection), that is, there may be part of the data of the DRB that needs security protection, and the way of determining which data of the DRB needs security protection or the specific configuration content is not limited in the embodiment. Still in combination with FIG. 5, it is assumed that MAC CE1 and MAC CE2 in FIG. 5 are MAC CEs carrying sensitive information, and according to the related configuration, it can be determined that MAC CE1 and MAC CE2 are to-be-transmitted data that needs security protection; it is assumed that the data of DRB1 and DRB3 is to-be-transmitted data that needs security protection, and the data of DRB2 is to-be-transmitted data that does not need security protection. It should be pointed out that the SRB (Signalling Radio Bearer, signaling radio bearer) needs to be executed security calculation by default, which is not described in the embodiment, but the embodiment can also be applied to the SRB, only the embodiment does not limit it.

[0166] In the above scenario, if the packet is assembled according to the existing logical channel priority (LCP) mechanism or procedure, it is possible to generate a MAC PDU that contains both MAC subPDUs that need security protection (such as the MAC subPDUs used to carry the following contents shown in Figure 5: MAC CE1, MAC CE2, data of DRB1, data of DRB3) and MAC subPDUs that do not need security protection (such as the MAC subPDUs used to carry the following contents shown in Figure 5: MAC CE3, data of DRB2). For such a MAC PDU, since it contains MAC subPDUs that need security protection, even if some of the MAC subPDUs do not need security protection, the MAC layer security protection mechanism will perform security operations on the entire MAC PDU, and security operations themselves require computational overhead, thus resulting in additional computational overhead. In the extreme case, if a MAC PDU contains only one MAC CE that needs security protection and the other MAC subPDUs do not need encryption protection, the MAC PDU will still be subjected to security computation due to the one MAC CE that needs security protection, which will result in a waste of more computational overhead.

[0167] The LCP mechanism or procedure is a mechanism for the terminal to assemble data to be transmitted from one or more logical channels and one or more MAC CEs. According to the LCP, three parameters are configured for each logical channel by the RRC layer: priority, PBR (priority bit rate), and BSD (bucket size duration); and the MAC determines the order in which each logical channel obtains resources according to the three parameters. The priority determines the order in which the data to be transmitted in the logical channel is scheduled, and the greater the priority, the lower the priority. The PBR determines the size of the resource allocation for each scheduled logical channel; the PBR determines an upper limit of the resources that can be scheduled for each logical channel. In addition to the three parameters configured by the RRC, the MAC entity also maintains a variable Bj for each logical channel, with an initial value of 0, which increases with each TTI, and the amount of each increase is PBR*TTI (Transmission Time Interval), and the upper limit is PBR*BSD.

[0168] The LCP mechanism or procedure specified in the related protocol is as follows: when a terminal obtains an uplink resource grant, the uplink resource grant usually determines the size of the MAC PDU. The terminal will allocate the granted uplink resource to different logical channels according to the specified LCP mechanism or procedure, which mainly consists of the following steps:

[0169] Firstly, for all logical channels with Bj>0, the priority is sorted, and the PBR*TTI resource is allocated to each logical channel in the order from high to low priority. If the PBR of a certain logical channel is set to infinity by RRC, the MAC will allocate sufficient resources to the logical channel to schedule all the data of the logical channel before scheduling other lower priority services.

[0170] Secondly, the MAC layer (or MAC entity) updates the Bj value, and subtracts the total size of the RLC PDU served by the corresponding logical channel from Bj.

[0171] After the first step is performed, if there is still remaining authorized resource, all logical channels are scheduled in the order of priority (regardless of the size of Bj), and each logical channel is either completely scheduled or completely uses up the remaining resource before the next logical channel is served.

[0172] It is worth noting that after the priority is determined, the UE also needs to follow some guidelines specified in the protocol when allocating resources to each logical channel: if an SDU can fill the allocated resources, the SDU should not be cut; if the SDU needs to be cut, the cutting method should maximize the utilization of the allocated resources.

[0173] Further, the related protocol also introduces the Logical Channel Restriction guideline for the LCP mechanism or procedure. The guideline can enable the terminal to determine based on the RRC configuration that some logical channels may not be selected for transmission to a certain characteristic uplink resource (i.e., in the uplink MAC PDU). The Logical Channel Restriction guideline can include that RRC controls the LCP procedure by configuring a mapping restriction for each logical channel, which can include at least one of the following parameters: an allowed (Allowd) subcarrier spacing (SCS, Subcarrier Spacing) list, which is used to set the allowed subcarrier spacing for transmission; a maximum PUSCH (Physical Uplink Shared Channel) duration, which sets the maximum PUSCH duration allowed for transmission;

[0174] configureGrantType1Allowed (configured grant type 1 allowed) is used to set whether configured grant type 1 is available for transmission; allowedServingCells (allowed serving cells) is used to set the cells allowed for transmission. For example, if a logical channel is configured with the parameter allowedSCS-List, when the terminal receives an uplink resource, if the SCS (subcarrier spacing) of the uplink resource does not match the allowedSCS-List configured for the logical channel, the logical channel cannot be selected, and the data of the logical channel cannot be transmitted by the uplink resource.

[0175] For the above scenario, the communication method provided by the embodiment of the present application can improve the LCP process or mechanism at the MAC layer in the uplink scenario, and by using the improved LCP process, the MAC CE and MAC SDU that need to perform security operations can be considered, and these MAC CE and MAC SDU that need security protection are assembled into one MAC PDU, and those MAC CE and MAC SDU that do not need security protection are assembled into another MAC PDU, and the MAC PDU as a whole does not need security protection, thereby saving security calculation overhead as much as possible.

[0176] The communication method provided by the embodiment can be used for terminal side processing as shown in FIG. 6, including the following steps.

[0177] In step 601, the terminal receives configuration information of the network, which can indicate whether the MAC (or MAC layer) of the terminal needs to consider the security protected MAC CE and MAC SDU when performing the LCP process.

[0178] The configuration information can include an on indication or an off indication. That is, the configuration information can enable the terminal to determine whether to use the improved processing manner to process the security protected data to be transmitted. The configuration information can be pre-configured to the terminal by any device on the network side, which can be an access network device or a core network device, and the present example does not limit.

[0179] If the configuration information includes the on indication, the following step 602 is performed, and if the configuration information includes the off indication, the packet assembly and transmission processing of the MAC PDU are still performed according to the provisions of the related protocol, which will not be described here.

[0180] Step 602, the MAC layer of the terminal determines whether there is one or more to-be-transmitted data (i.e., to-be-transmitted MAC CE and / or DRB data that needs security protection) that needs security protection, if not, the existing LCP process is followed for processing, which is not limited here; if so, step 603 is executed.

[0181] Step 603, the MAC layer of the terminal compares the data amount of one or more to-be-transmitted data that needs security protection with the size of the obtained uplink resource (i.e., the first resource in the foregoing embodiment), if the data amount of one or more to-be-transmitted data that needs security protection is greater than the size of the obtained uplink resource, step 604 is executed; otherwise, step 605 is executed.

[0182] Step 604, the MAC layer of the terminal selects part of the to-be-transmitted data (i.e., one or more first to-be-transmitted data in the foregoing embodiment) that needs security protection from one or more to-be-transmitted data based on the LCP process, assembles a first MAC PDU, performs security protection on the first MAC PDU, transmits the security-protected first MAC PDU, and ends the processing.

[0183] For example, in the scenario shown in FIG. 5, if the data amount of MAC CE1+MAC CE2+DRB1+DBR3 is greater than the size of the uplink resource obtained for this transmission, it means that the uplink resource for this transmission cannot transmit all the to-be-transmitted data that needs security calculation. Therefore, the MAC CE and DRB data that needs security calculation needs to be selected for the first MAC PDU packet assembly by executing step 604. That is, MAC CE3 and DRB2 data cannot be selected for assembly into the first MAC PDU. The assembled first MAC PDU is subjected to security calculation, such as encryption and integrity protection, and then transmitted. The priority order of the to-be-transmitted data (MAC CE or DRB data) can be determined according to the order determined by other configuration parameters of the existing LCP mechanism.

[0184] Step 605, the MAC layer of the terminal assembles a first MAC PDU based on the LCP process for one or more to-be-transmitted data that needs security protection, performs security protection on the first MAC PDU, and transmits the security-protected first MAC PDU.

[0185] For example, in the scenario shown in FIG. 5, if the data amount of MAC CE1+MAC CE2+DRB1+DBR3 is not greater than the size of the uplink resource obtained for this transmission, it means that the uplink resource for this transmission is sufficient to transmit all the to-be-transmitted data that needs security calculation and has remaining resources.

[0186] For these remaining resources, there can be several processing methods as follows:

[0187] Method 1, the remaining resources are filled with padding. In this method, the first MAC PDU is finally transmitted on the uplink resource.

[0188] Method 2, the remaining resources are assembled according to the LCP procedure one or more data to be transmitted that do not need security protection (such as MAC CE that does not need security protection and / or DRB data that does not need security protection), and the first MAC PDU assembled after that is uniformly subjected to security operation, such as encryption and / or integrity protection. In this method, the first MAC PDU is finally transmitted on the uplink resource.

[0189] Method 3, the remaining resources are assembled according to the LCP procedure one or more data to be transmitted that do not need security protection (such as MAC CE that does not need security protection and / or DRB data that does not need security protection), and a separate MAC PDU (i.e. the third MAC PDU in the foregoing embodiment) is obtained after assembly, that is, one or more data to be transmitted that need security protection are assembled into the first MAC PDU, the first MAC PDU is subjected to security protection, and a third MAC PDU is also assembled, and the third MAC PDU does not need to be subjected to security protection. In this method, the first MAC PDU and the third MAC PDU are finally transmitted on the uplink resource.

[0190] In addition, before step 603, there can also be a judgment that whether the priority of one or more data to be transmitted that need security protection is not lower than one or more data to be transmitted that do not need security protection, if not lower, step 603 is executed; otherwise, a first MAC PDU is obtained by packeting based on one or more data to be transmitted that do not need security protection according to the LCP procedure and is transmitted.

[0191] After step 604 is completed, there can also be remaining resources on the uplink resource, and padding or other data to be transmitted that do not need security protection (MAC CE and / or DRB data) can be considered for the remaining resources; in addition, after step 604 is completed, there can be remaining data to be transmitted that need security protection, and this part of data to be transmitted can be processed by using the method of step 604 or step 605 when the uplink resource is obtained next time, and no repeated description is made.

[0192] It should be noted that the above process flow at the terminal side can also be added to the LCP mechanism or process as an improved LCP mechanism or process. That is, the improved LCP mechanism or process can be configured at the terminal side, so that the terminal can perform at least part of the above steps 601-605 processing, such as the terminal side MAC layer can perform at least one of the following processing based on the improved LCP mechanism: determining whether there is one or more data to be transmitted that needs security protection; comparing the data amount of one or more data to be transmitted that needs security protection with the size of the obtained uplink resource; selecting part of the data to be transmitted that needs security protection from one or more data to be transmitted that needs security protection based on the LCP process to assemble the first MAC PDU, and performing security protection on the first MAC PDU, and transmitting the security protected first MAC PDU; assembling the first MAC PDU from one or more data to be transmitted that needs security protection, and performing security protection on the first MAC PDU, and transmitting the security protected first MAC PDU; determining whether the priority of one or more data to be transmitted that needs security protection is not lower than one or more data to be transmitted that does not need security protection, and if it is not lower, comparing the data amount of one or more data to be transmitted that needs security protection with the size of the obtained uplink resource, and the like.

[0193] After the terminal completes the above processing, the access network device side can receive the security protected first MAC PDU, and the access network device can use the MAC integrity key to perform integrity check on the first MAC PDU, or the access network device can first use the MAC confidentiality key to decrypt the cipher data carried by the first MAC PDU, and then use the MAC integrity key to perform integrity check on the first MAC PDU. Here, the processing performed by the access network device is not limited or exhausted.

[0194] By adopting the above scheme, the first device can assemble one or more MAC subunits that need security protection, and transmit the security protected MAC PDU. In this way, since whether the MAC subunit needs security protection is considered, as many MAC subunits as possible that need security protection can be assembled in the MAC PDU and security protected, so that the security of the MAC subunit transmitted in the MAC PDU can be guaranteed, and the problem of waste of security operation overhead caused by assembling MAC subunits that do not need security protection in the security protected MAC PDU can be reduced or avoided as much as possible.

[0195] FIG. 7 is a schematic diagram of the composition structure of the first device according to an embodiment of the present application, which includes:

[0196] The first communication unit 701 is configured to transmit a first media access control (MAC) protocol data unit (PDU) that is security-protected, wherein the first MAC PDU is composed of one or more first MAC sub-units that need security protection.

[0197] As shown in FIG. 7, the first device further includes:

[0198] The first processing unit 702 is configured to generate the one or more first MAC sub-units based on at least part of one or more to-be-transmitted data that need security protection.

[0199] The first processing unit is configured to generate the one or more first MAC sub-units based on at least part of the one or more to-be-transmitted data that need security protection, in a case where a priority of the one or more to-be-transmitted data that need security protection is not lower than a priority of the one or more to-be-transmitted data that do not need security protection.

[0200] The first processing unit is configured to generate the one or more first MAC sub-units based on one or more first to-be-transmitted data, in a case where a data amount of the one or more to-be-transmitted data that need security protection is greater than a first resource, wherein the one or more first to-be-transmitted data are part of the to-be-transmitted data that need security protection and are selected from the one or more to-be-transmitted data that need security protection based on the priority and the first resource.

[0201] The first processing unit is configured to generate the one or more first MAC sub-units based on the one or more to-be-transmitted data that need security protection, in a case where a data amount of the one or more to-be-transmitted data that need security protection is not greater than a first resource.

[0202] The one or more to-be-transmitted data that need security protection include at least one of the following: one or more second to-be-transmitted data that are currently generated and need security protection, and one or more third to-be-transmitted data that need security protection and are remaining to be assembled into a second MAC PDU, wherein a transmission time of the second MAC PDU is earlier than a transmission time of the first MAC PDU.

[0203] The second MAC PDU is a MAC PDU that is not security-protected, wherein the second MAC PDU is composed of one or more third MAC sub-units that do not need security protection, and a priority of the one or more third to-be-transmitted data is lower than a priority of the one or more third MAC sub-units.

[0204] The first processing unit is configured to assemble the first MAC PDU based on the one or more first MAC sub-units, and perform security protection on the first MAC PDU to obtain the security-protected first MAC PDU.

[0205] The first processing unit is configured to, in a case where there is remaining resource in the first resource, assemble the first MAC PDU based on the one or more first MAC subunits and padding bits.

[0206] The first processing unit is configured to, in a case where there is remaining resource in the first resource, generate one or more fourth MAC subunits based on the remaining resource and one or more to-be-transmitted data that do not need security protection, and assemble the first MAC PDU based on the one or more first MAC subunits and the one or more fourth MAC subunits.

[0207] The first processing unit is configured to, in a case where there is remaining resource in the first resource, assemble the first MAC PDU based on the one or more first MAC subunits.

[0208] The first processing unit is configured to generate one or more fourth MAC subunits based on the remaining resource and one or more to-be-transmitted data that do not need security protection, and assemble a third MAC PDU that is not secured based on the one or more fourth MAC subunits.

[0209] The to-be-transmitted data includes one of the following: to-be-transmitted data of a logical channel, a MAC control element (CE).

[0210] The first processing unit is configured to secure the one or more first MAC subunits in the first MAC PDU to obtain the first MAC PDU that is secured.

[0211] The first processing unit is configured to secure the one or more first MAC subunits and the one or more fourth MAC subunits in the first MAC PDU to obtain the first MAC PDU that is secured.

[0212] The first communication unit is configured to transmit the first MAC PDU that is secured through the first resource.

[0213] The first communication unit is configured to transmit the third MAC PDU through the remaining resource.

[0214] The first device is a terminal or an access network device.

[0215] The device of the embodiments of the present application can realize the corresponding functions of each device in the embodiments of the communication method described above. The processes, functions, implementation manners and advantages of each module (sub-module, unit or component, etc.) in the device correspond to the description in the corresponding method embodiments described above, and will not be repeated here. It should be noted that the functions described with respect to each module (sub-module, unit or component, etc.) in the device of the embodiments of the present application can be realized by different modules (sub-modules, units or components, etc.), or by the same module (sub-module, unit or component, etc.).

[0216] FIG. 8 is a schematic structural diagram of a communication device 800 according to the embodiments of the present application. The communication device 800 includes a processor 810, which can call and run a computer program from a memory to enable the communication device 800 to implement the method in the embodiments of the present application. In a possible implementation manner, the communication device 800 can further include a memory 820. The processor 810 can call and run a computer program from the memory 820 to enable the communication device 800 to implement the method in the embodiments of the present application. The memory 820 can be a separate device independent of the processor 810, or can be integrated in the processor 810. In a possible implementation manner, the communication device 800 can further include a transceiver 830, and the processor 810 can control the transceiver 830 to communicate with other devices, specifically, to send information or data to other devices, or to receive information or data sent by other devices. The transceiver 830 can include a transmitter and a receiver. The transceiver 830 can further include an antenna, and the number of antennas can be one or more.

[0217] In a possible implementation manner, the communication device 800 can be the first device of the embodiments of the present application, and the communication device 800 can realize the corresponding processes realized by the first device in each method of the embodiments of the present application. For the sake of brevity, they will not be repeated here.

[0218] FIG. 9 is a schematic structural diagram of a chip 900 according to an embodiment of the present application. The chip 900 includes a processor 910, which can invoke and run a computer program from a memory to implement the method in the embodiments of the present application. In a possible implementation, the chip 900 can further include a memory 920. The processor 910 can invoke and run a computer program from the memory 920 to implement the method performed by the first device in the embodiments of the present application. The memory 920 can be a separate device independent of the processor 910, or can be integrated in the processor 910. In a possible implementation, the chip 900 can further include an input interface 930. The processor 910 can control the input interface 930 to communicate with other devices or chips, and specifically, can acquire information or data sent by other devices or chips. In a possible implementation, the chip 900 can further include an output interface 940. The processor 910 can control the output interface 940 to communicate with other devices or chips, and specifically, can output information or data to other devices or chips.

[0219] In a possible implementation, the chip can be applied to the first device in the embodiments of the present application, and the chip can implement the corresponding procedures implemented by the first device in the various methods of the embodiments of the present application. For brevity, details are not repeated here. It should be understood that the chip mentioned in the embodiments of the present application can also be referred to as a system-on-chip, a system chip, a chip system or a system-on-chip, etc. The processor mentioned above can be a general-purpose processor, a digital signal processor (DSP), a field programmable gate array (FPGA), an application specific integrated circuit (ASIC) or other programmable logic device, a transistor logic device, a discrete hardware component, etc. Among them, the general-purpose processor mentioned above can be a microprocessor or any conventional processor, etc. The memory mentioned above can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically EPROM (EEPROM) or a flash memory. The volatile memory can be a random access memory (RAM). It should be understood that the above memory is exemplary but not a limiting description, for example, the memory in the embodiments of the present application can also be a static RAM (SRAM), a dynamic RAM (DRAM), a synchronous DRAM (SDRAM), a double data rate SDRAM (DDR SDRAM), an enhanced SDRAM (ESDRAM), a synch link DRAM (SLDRAM) and a direct memory bus random access memory (Direct Rambus RAM, DR RAM) and the like. That is, the memory in the embodiments of the present application is intended to include but not limited to these and any other suitable types of memory.

[0220] FIG. 10 is a schematic block diagram of a communication system 1000 according to an embodiment of the present application. The communication system 1000 includes a first device 1010. The first device 1010 can be configured to implement corresponding functions of the first device in the methods described above.

[0221] In the above embodiments, the whole or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, the whole or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the whole or part of the processes or functions according to the embodiments of the present application are produced. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website site, computer, server or data center to another website site, computer, server or data center through wired (for example, coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wireless (for example, infrared, wireless, microwave, etc.) manner. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media. The available medium can be a magnetic medium (for example, floppy disk, hard disk, magnetic tape), an optical medium (for example, DVD), or a semiconductor medium (for example, Solid State Disk (SSD)) and the like.

[0222] It should be understood that the magnitude of the sequence number of each process in various embodiments of the present application does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic. It can be clearly understood by those skilled in the art that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here. The above is only a specific implementation of the present application, and the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method of communication performed by a first device, comprising: transmitting a first medium access control (MAC) protocol data unit (PDU) with security protection, wherein the first MAC PDU is composed of one or more first MAC subPDUs that require security protection.

2. The method of claim 1, wherein, The method further comprises: generating the one or more first MAC subPDUs based on at least part of one or more data to be transmitted that require security protection.

3. The method of claim 1, wherein, The method further comprises: generating the one or more first MAC subPDUs based on at least part of one or more data to be transmitted that require security protection, in a case that a priority of the one or more data to be transmitted that require security protection is not lower than one or more data to be transmitted that do not require security protection.

4. The method of claim 2 or 3, wherein, The generating the one or more first MAC subPDUs based on at least part of one or more data to be transmitted that require security protection comprises: generating the one or more first MAC subPDUs based on one or more first data to be transmitted, in a case that an amount of data of the one or more data to be transmitted that require security protection is greater than a first resource, wherein the one or more first data to be transmitted are part of the one or more data to be transmitted that require security protection selected based on priority and the first resource.

5. The method of claim 2 or 3, wherein, The generating the one or more first MAC subPDUs based on at least part of one or more data to be transmitted that require security protection comprises: generating the one or more first MAC subPDUs based on the one or more data to be transmitted that require security protection, in a case that an amount of data of the one or more data to be transmitted that require security protection is not greater than a first resource.

6. The method according to any one of claims 2-5, wherein, The one or more data to be transmitted that require security protection comprise at least one of: one or more second data to be transmitted that require security protection currently generated, one or more third data to be transmitted that require security protection remaining for assembling a second MAC PDU, wherein a transmission time of the second MAC PDU is earlier than the first MAC PDU.

7. The method of claim 6, wherein, The second MAC PDU is a MAC PDU without security protection, the second MAC PDU is composed of one or more third MAC subPDUs that do not require security protection, and a priority of the one or more third data to be transmitted is lower than the one or more third MAC subPDUs.

8. The method of any one of claims 1-7, wherein, The method further comprises: assembling the first MAC PDU based on the one or more first MAC subPDUs; performing security protection on the first MAC PDU to obtain the first MAC PDU with security protection.

9. The method of claim 8, wherein, The assembling the first MAC PDU based on the one or more first MAC subPDUs comprises: assembling the first MAC PDU based on the one or more first MAC subPDUs and padding bits, in a case that there is remaining resource in the first resource.

10. The method of claim 8, wherein, The assembling the first MAC PDU based on the one or more first MAC subPDUs comprises: generate one or more fourth MAC subunits based on the remaining resources and one or more to-be-transmitted data which do not need security protection; assemble the first MAC PDU based on the one or more first MAC subunits and the one or more fourth MAC subunits.

11. The method of claim 8, wherein, The assembling the first MAC PDU based on the one or more first MAC subunits comprises: assemble the first MAC PDU based on the one or more first MAC subunits in the case that there are remaining resources in the first resources.

12. The method of claim 11, wherein, The method further comprises: generate one or more fourth MAC subunits based on the remaining resources and one or more to-be-transmitted data which do not need security protection; assemble a third MAC PDU which is not protected by security based on the one or more fourth MAC subunits.

13. The method of any one of claims 2-7, 10-12, wherein, The to-be-transmitted data comprises one of the following: to-be-transmitted data of a logical channel, a MAC control element CE.

14. The method of any one of claims 8-11, wherein, The security protection of the first MAC PDU to obtain the first MAC PDU protected by security comprises: security protection of the one or more first MAC subunits in the first MAC PDU to obtain the first MAC PDU protected by security. The security protection of the first MAC PDU to obtain the first MAC PDU protected by security comprises:

15. The method of claim 10, wherein, security protection of the one or more first MAC subunits and the one or more fourth MAC subunits in the first MAC PDU to obtain the first MAC PDU protected by security. The transmission of the first MAC PDU protected by security comprises:

16. The method of any one of claims 1-15, wherein, transmit the first MAC PDU protected by security through the first resources. The method further comprises:

17. The method of claim 12, wherein, transmit the third MAC PDU through the remaining resources. The first device is a terminal or an access network device.

18. The method of any one of claims 1-17, wherein, 19. A first device comprising: a first communication unit configured to transmit a first medium access control layer (MAC) protocol data unit (PDU) protected by security, wherein the first MAC PDU is composed of one or more first MAC subunits which need security protection.

20. The first device of claim 19, further comprising: a first processing unit configured to generate the one or more first MAC subunits based on at least part of one or more to-be-transmitted data which need security protection. The first processing unit is configured to generate the one or more first MAC subunits based on at least part of one or more to-be-transmitted data which need security protection in the case that a priority of the one or more to-be-transmitted data which need security protection is not lower than that of one or more to-be-transmitted data which do not need security protection.

21. The first device of claim 19, wherein, ​ 22. The first device of claim 20 or 21, wherein, The first processing unit is configured to generate the one or more first MAC subunits based on the one or more first to-be-transmitted data in a case where the data volume of the one or more to-be-transmitted data requiring security protection is greater than the first resource, wherein the one or more first to-be-transmitted data are part of the to-be-transmitted data selected from the one or more to-be-transmitted data requiring security protection based on priorities and the first resource.

23. The first device of claim 20 or 21, wherein, The first processing unit is configured to generate the one or more first MAC subunits based on the one or more to-be-transmitted data requiring security protection in a case where the data volume of the one or more to-be-transmitted data requiring security protection is not greater than the first resource.

24. The first device of any of claims 20-23, wherein, The one or more to-be-transmitted data requiring security protection include at least one of the following: one or more second to-be-transmitted data requiring security protection currently generated, and one or more third to-be-transmitted data requiring security protection remaining in assembling a second MAC PDU, wherein a transmission time of the second MAC PDU is earlier than that of the first MAC PDU.

25. The first device of claim 24, wherein, The second MAC PDU is a MAC PDU without security protection, and the second MAC PDU is composed of one or more third MAC subunits without security protection, and the priorities of the one or more third to-be-transmitted data are lower than those of the one or more third MAC subunits.

26. The first device of any of claims 19-25, wherein, The first processing unit is configured to assemble the first MAC PDU based on the one or more first MAC subunits, and perform security protection on the first MAC PDU to obtain the first MAC PDU with security protection.

27. The first device of claim 26, wherein, The first processing unit is configured to assemble the first MAC PDU based on the one or more first MAC subunits and padding bits in a case where there is remaining resource in the first resource.

28. The first device of claim 26, wherein, The first processing unit is configured to generate one or more fourth MAC subunits based on the remaining resource and one or more to-be-transmitted data without security protection in a case where there is remaining resource in the first resource. The first processing unit is configured to assemble the first MAC PDU based on the one or more first MAC subunits and the one or more fourth MAC subunits.

29. The first device of claim 26, wherein, The first processing unit is configured to assemble the first MAC PDU based on the one or more first MAC subunits in a case where there is remaining resource in the first resource.

30. The first device of claim 29, wherein, The first processing unit is configured to generate one or more fourth MAC subunits based on the remaining resource and one or more to-be-transmitted data without security protection. The first processing unit is configured to assemble a third MAC PDU without security protection based on the one or more fourth MAC subunits.

31. The first device of any of claims 20-25, 28-30, wherein, The to-be-transmitted data includes one of the following: to-be-transmitted data of a logical channel, and a MAC control element (CE).

32. The first device of any of claims 26-29, wherein, The first processing unit is configured to perform security protection on the one or more first MAC subunits in the first MAC PDU to obtain the first MAC PDU with security protection.

33. The first device of claim 28, wherein, The first processing unit is configured to perform security protection on the one or more first MAC subunits and the one or more fourth MAC subunits in the first MAC PDU, to obtain a security-protected first MAC PDU.

34. The first device of any of claims 19-33, wherein, The first communication unit is configured to transmit the security-protected first MAC PDU through a first resource.

35. The first device of claim 30, wherein, The first communication unit is configured to transmit the third MAC PDU through the remaining resource.

36. The first device of any one of claims 19-35, wherein, The first device is a terminal or an access network device.

37. A first device comprising: A transceiver configured to communicate with other devices, a processor, and a memory configured to store a computer program, wherein the processor is configured to invoke and run the computer program stored in the memory, so that the first device performs the method according to any one of claims 1 to 18.

38. A chip comprising: A processor configured to invoke and run a computer program from a memory, so that a device installed with the chip performs the method according to any one of claims 1 to 18. 39.A computer readable storage medium configured to store a computer program, which, when executed by a device, causes the device to perform the method according to any one of claims 1 to 18. 40.A computer program product comprising computer program instructions configured to cause a computer to perform the method according to any one of claims 1 to 18. 41.A computer program configured to cause a computer to perform the method according to any one of claims 1 to 18.

Citation Information

Patent Citations

  • Message transmission method, device and equipment

    CN118368616A

  • NR security enhancements

    CN118402208A

  • Medium access control security

    US20200236537A1

  • Method and apparatus for enhancing security of mac layer entity in next-generation mobile communication system

    US20220240094A1

  • Layer-2 security enhancements

    US20240244424A1