Key generation method and device

By generating MAC keys, the lack of security protection at the MAC layer is solved, thus ensuring the security of MAC layer messages.

WO2026065317A1PCT designated stage Publication Date: 2026-04-02GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-29
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

In existing 3GPP technologies, the MAC layer lacks security protection mechanisms, resulting in insufficient message security.

Method used

By generating MAC keys, messages at the MAC layer can be securely protected or verified, thus compensating for the lack of security mechanisms at the MAC layer.

Benefits of technology

It ensures the security of messages transmitted at the MAC layer, providing protection for integrity and confidentiality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024122531_02042026_PF_FP_ABST
    Figure CN2024122531_02042026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a key generation method and device. The method comprises: generating at least one media access control (MAC) key on the basis of at least one security key.
Need to check novelty before this filing date? Find Prior Art

Description

Key generation method and device TECHNICAL FIELD

[0001] The present application relates to the field of communication, and more particularly, to a key generation method and device. BACKGROUND

[0002] In the existing 3GPP technology, encryption and integrity protection are mainly performed at the NAS (Non-Access Stratum) and PDCP (Packet Data Convergence Protocol) layers. However, in the related art, no corresponding security protection mechanism is provided for the MAC (Medium Access Control) layer, and therefore, how to make up for the lack of the corresponding security protection mechanism of the MAC layer to ensure the security of the MAC layer messages becomes a problem to be solved.

[0003] SUMMARY

[0004] Embodiments of the present application provide a key generation method and device.

[0005] Embodiments of the present application provide a key generation method performed by a first device, comprising:

[0006] generating at least one MAC key based on at least one security key.

[0007] Embodiments of the present application provide a first device, comprising:

[0008] a first processing unit configured to generate at least one MAC key based on at least one security key.

[0009] By adopting the above scheme, the MAC key can be generated by the device in the communication network, and thus the MAC layer messages received or transmitted by the device can be securely protected or checked by the MAC key, thereby making up for the lack of the MAC layer security mechanism and ensuring the security of the MAC layer transmission messages. BRIEF DESCRIPTION OF DRAWINGS

[0010] FIG. 1 is a schematic diagram of an application scenario according to an embodiment of the present application.

[0011] FIG. 2 is a schematic flowchart of a key generation method according to an embodiment of the present application.

[0012] FIG. 3 is a schematic diagram of a scenario of deriving a MAC integrity key according to an embodiment of the present application.

[0013] FIG. 4 is a schematic diagram of a scenario of deriving a MAC confidentiality key according to an embodiment of the present application.

[0014] FIG. 5 is a schematic flow chart of the processing of an access network device and a terminal in an AS SMC procedure according to an embodiment of the present application.

[0015] FIG. 6 is a schematic diagram of a scenario of calculating a first integrity check code according to an embodiment of the present application.

[0016] FIGS. 7-9 are schematic diagrams of various scenarios of calculating a second integrity check code according to an embodiment of the present application.

[0017] FIGS. 10-12 are schematic diagrams of various scenarios of calculating second cipher data according to an embodiment of the present application.

[0018] FIG. 13 is a schematic block diagram of a first device according to an embodiment of the present application. DETAILED DESCRIPTION

[0019] The technical solutions of the embodiments of the present application can be applied to various communication systems, for example, LTE (Long Term Evolution), LTE-A (Long Term Evolution-Advanced), NR (New Radio), evolution of NR, WLAN (Wireless Local Area Network), WiFi (Wireless Fidelity), or other communication systems, etc.

[0020] The embodiments of the present application describe various embodiments in combination with network devices and terminals. The terminals can be mobile or fixed, and can also be referred to as mobile stations, user units, etc. The terminals can be stations in WLAN, and can be smart terminals, wireless modems, notebook computers, tablet computers, etc. In the embodiments of the present application, the terminals can be VR (Virtual Reality) terminals / AR (Augmented Reality) terminals, industrial control terminals, unmanned driving terminals, remote medical terminals, smart grid terminals, transportation safety terminals, smart city terminals, or wireless terminals of smart homes, etc. As an example but not limitation, in the embodiments of the present application, the terminals can also be wearable devices.

[0021] In the embodiments of the present application, the network device can be a device for communicating with the terminal, and can be an access point in a WLAN, an evolved base station in LTE, or a relay station, or a vehicle-mounted device, a wearable device, a network device in an NR network (gNB, the next Generation Node B), or a network device in a future evolved PLMN (Public Land Mobile Network) or a network device in a non-ground network, etc. By way of example but not limitation, in the embodiments of the present application, the network device can have a mobile characteristic, for example, the network device can be a mobile device.

[0022] In order to facilitate understanding of the technical solutions of the embodiments of the present application, the related technologies of the embodiments of the present application are described as follows, and the following related technologies can be combined with the technical solutions of the embodiments of the present application in any manner, which all belong to the protection scope of the embodiments of the present application.

[0023] FIG. 1 exemplarily shows a communication system 100. The communication system includes a network device 110 and a terminal 120. In a possible implementation, the communication system 100 can include a plurality of network devices 110, and each network device 110 can include a plurality of terminals 120 within its coverage, which is not limited in the embodiments of the present application. In a possible implementation, the communication system 100 can further include a mobility management entity, an access and mobility management function, and other network entities, which are not limited in the embodiments of the present application. The network device can include an access network device and a core network device. That is, the communication system can further include a plurality of core networks for communicating with the access network device. The access network device can be a base station of an LTE, LTE-A, or NR system. Taking the communication system shown in FIG. 1 as an example, the communication device can include a network device and a terminal having a communication function, and the communication device can further include other devices in the communication system, such as a network controller, a mobility management entity, and other network entities, which are not limited in the embodiments of the present application.

[0024] FIG. 2 is a schematic flowchart of a key generation method performed by a first device according to an embodiment of the present application. The method includes at least part of the following contents.

[0025] S210, generating at least one MAC key based on the at least one security key.

[0026] Here, the at least one MAC key is shared or commonly owned by the first device and the second device, and the at least one MAC key can be used to secure MAC layer messages or information transmitted between the first device and the second device. The security can include integrity protection and / or confidentiality protection, which can also be referred to as encryption protection, and is not repeated below.

[0027] Optionally, the first device is a terminal, and the second device is an access network device. Optionally, the first device is an access network device, and the second device is a terminal.

[0028] In some possible implementation manners, the at least one MAC key includes at least one of a MAC integrity key and a MAC confidentiality key.

[0029] The MAC key can be referred to as a MAC layer key, or a MAC (or MAC layer) security key, and the like, and all possible names of the MAC key are not limited herein.

[0030] The MAC integrity key can be denoted as K MACint The MAC integrity key can be used to perform integrity protection and / or integrity verification on MAC layer messages or information transmitted between the first device and the second device. The MAC integrity key can also be referred to as a MAC integrity protection key, a MAC integrity protection key, a MAC layer integrity key, a MAC layer integrity protection key, and the like, and all possible names of the MAC integrity key are not limited herein. In addition, the integrity key, the integrity protection key, and the integrity protection key appearing below have the same meaning, and are not repeated below.

[0031] On the first device side, the MAC integrity key can be used to perform integrity protection on MAC layer messages or information sent by the first device to the second device, and / or perform integrity verification on MAC layer messages or information received by the first device from the second device. On the second device side, the MAC integrity key can be used to perform integrity protection on MAC layer messages or information sent by the second device to the first device, and / or perform integrity verification on MAC layer messages or information received by the second device from the first device.

[0032] The MAC confidentiality key can be denoted as K MACencThe MAC confidentiality key can be used to encrypt and / or decrypt MAC layer messages or information transmitted between the first device and the second device. The MAC confidentiality key can also be referred to as any one of a MAC (or MAC layer) confidentiality protection key, a MAC (or MAC layer) encryption key, a MAC (or MAC layer) decryption key, a MAC layer confidentiality key, and the like, which are not limited or exhaustive herein. In addition, the confidentiality key, the encryption key, and the decryption key have the same meaning and are not repeated below.

[0033] On the first device side, the MAC confidentiality key can be used to encrypt MAC layer messages or information sent by the first device to the second device, and / or to decrypt MAC layer messages or information received by the first device from the second device. On the second device side, the MAC confidentiality key can be used to encrypt MAC layer messages or information sent by the second device to the first device, and / or to decrypt MAC layer messages or information received by the second device from the first device.

[0034] The at least one security key can include an access stratum (AS) key shared or commonly owned by the first device and the second device. Specifically, the at least one security key includes at least one of the following: K gNB , an AS distributed unit (DU) key, an AS control plane key, and an AS user plane key. The AS control plane key includes at least one of an AS control plane integrity key and an AS control plane confidentiality key. The AS user plane key includes at least one of an AS user plane integrity key and an AS user plane confidentiality key. The AS DU key can be a derived key based on K gNB . The AS DU key can include at least one of an AS DU integrity key and an AS DU confidentiality key.

[0035] K gNB may be an initial K gNB , or a K gNB derived vertically based on a next hop (NH) key (i.e., K NG -RAN). The initial K gNB corresponds to a next hop chaining counter (NCC) equal to 0.

[0036] The AS control plane key can be an RRC (Radio Resource Control) layer key, which can be K RRCThe AS control plane integrity key can be an RRC layer integrity key, which can be K RRCint The AS control plane confidentiality key can be an RRC layer confidentiality key, which can be K RRCenc It should be noted that, in the following description, K RRC may refer to K RRCint and / or K RRCenc , and the following description will not be repeated.

[0037] The AS user plane key can be K UP The AS user plane integrity key can be K UPint The user plane confidentiality key can be K UPenc It should be noted that, in the following description, K UP may refer to K UPint and / or K UPenc , and the following description will not be repeated.

[0038] The ASDU key can be K DU The ASDU integrity key can be K DUint The ASDU confidentiality key can be K DUenc It should be noted that, in the following description, K DU may refer to K DUint and / or K DUenc , and the following description will not be repeated.

[0039] It should be noted that, in addition to any one or more of the above keys, the at least one security key can also include other types of keys, such as at least one of Kmn, Ksn, NH, etc., wherein Kmn is an initial AS key of a master node in a dual connection scenario, and Ksn is an initial AS key of a secondary node in a dual connection scenario. As long as the key is shared or commonly owned by the AS layer between the first device and the second device, it can be a security key, and the key or key type that the security key can include is not limited or exhausted here.

[0040] The MAC layer key is a new AS key between the first device and the second device (i.e., the access network device and the terminal), and therefore, the at least one MAC layer key can be derived based on K gNB (or Ksn, or Kmn, or NH), and / or derived based on K UP , K RRC , K DU , and / or directly use K UP , K RRC , KDU .

[0041] In an embodiment, the generating the at least one MAC key based on the at least one security key comprises at least one of: deriving the MAC integrity key based on a first security key and a first input parameter, wherein the first security key is one of the at least one security key, and the first input parameter comprises at least one of: an identity of a MAC integrity algorithm, a type of the MAC integrity algorithm; deriving the MAC confidentiality key based on a second security key and a second input parameter, wherein the second security key is one of the at least one security key, and the second input parameter comprises at least one of: an identity of a MAC confidentiality algorithm, a type of the MAC confidentiality algorithm.

[0042] It should be noted that the first device and the second device derive the at least one MAC key in the same way, and thus the following description of deriving the MAC integrity key and the MAC confidentiality key is applicable to both the first device and the second device, and no repeated description is made.

[0043] The first security key can be any one of the at least one security key, for example, the first security key can be KgNB, or Ksn, or an AS user plane integrity key, or an AS control plane integrity key, or an ASDU integrity key.

[0044] Optionally, the first input parameter can comprise at least one of an identity of a MAC integrity algorithm and a type of the MAC integrity algorithm.

[0045] The MAC integrity algorithm can be a MAC integrity algorithm that is by default of both the first device and the second device, or that is specified by a protocol, or that is negotiated by both the first device and the second device, or that is configured by the first device to the second device, or that is configured by the second device to the first device. As long as the same MAC integrity algorithm is used by both the first device and the second device, it is within the protection scope of the embodiment. The MAC integrity algorithm can also be referred to as a MAC layer integrity protection algorithm, or a MAC layer integrity protection algorithm, and the like. The MAC integrity algorithm can comprise at least one of an algorithm for calculating a MAC layer integrity check code and an algorithm for calculating a MAC layer integrity key.

[0046] The identity of the MAC integrity algorithm can be represented by an ID of 4 bits (bits), or can also be represented by a longer or shorter ID, which is not limited in the embodiment. The identity of the MAC integrity algorithm can be by default of both the first device and the second device, or specified by a protocol. As long as the same identity of the MAC integrity algorithm is used by both the first device and the second device, it is within the protection scope of the embodiment.

[0047] For example, the identity of the MAC integrity algorithm can be any one of the following integrity algorithm IDs: 00002, 00012, 00102, 00112. Here, the subscript "2" is used to represent binary; "00002" is used to represent NIA0, i.e., Null Integrity Protection algorithm; "00012" is used to represent 128-NIA1, i.e., 128-bit SNOW 3G based algorithm; "00102" is used to represent 128-NIA2, i.e., 128-bit AES based algorithm; and "00112" is used to represent 128-NIA3, i.e., 128-bit ZUC based algorithm. Here, 128-NIA2 can specifically be a CMAC (Cipher-based Message Authentication Code) mode based on 128-bit AES. The above is only an exemplary illustration, and in actual processing, the MAC integrity algorithm can include but is not limited to the above several algorithms, and the MAC integrity algorithm is not limited to calculating a 128-bit MAC integrity key, but can also be calculating a longer or shorter MAC integrity key, such as the MAC integrity algorithm can also be used to calculate a 256-bit MAC integrity key, and the like, which are not limited or enumerated here.

[0048] The value of the type of the MAC integrity algorithm (or simply referred to as the type of the MAC layer integrity algorithm) can be a default value or a protocol specified value for both the first device and the second device, such as the value of the type of the MAC integrity algorithm can be 0x00 or 0x07 (inclusive) to 0xf0 (inclusive) and values therebetween. The present embodiment does not limit or enumerate the value of the type of the MAC integrity algorithm used by the first device and the second device, as long as the same type of MAC integrity algorithm is used by both the first device and the second device, it is within the protection scope of the present embodiment.

[0049] It should be pointed out that the type of the algorithm can be replaced by any one of the algorithm type distinguisher, algorithm distinguisher, algorithm algorithm identifier, and the like, which will not be repeated in the following description.

[0050] Optionally, the first input parameter can comprise at least one of the following: the identity of the MAC integrity algorithm, the type of the MAC integrity algorithm, the length of the identity of the MAC integrity algorithm, the length of the type of the MAC integrity algorithm, the first fixed value, in addition to the identity of the MAC integrity algorithm, the type of the MAC integrity algorithm.

[0051] The first fixed value can be a default value or a value specified by a protocol between the first device and the second device, and can be 0x69.

[0052] Optionally, the first input parameter can comprise at least one of the following: the identity of the first device, the identity of the second device, the cell identity, the random number, the input parameter used for deriving other AS keys, in addition to the identity of the MAC integrity algorithm, the type of the MAC integrity algorithm, the length of the identity of the MAC integrity algorithm, the length of the type of the MAC integrity algorithm, the first fixed value.

[0053] The random number can also be a freshness value or a key-related count value (or simply a count value), and the like. The random number can be generated by the first device and the second device in a default manner or in a manner specified by a protocol, or the random number can be generated by the first device and configured to the second device, or the random number can be generated by the second device and configured to the first device.

[0054] The other AS key can be any AS key derived based on K gNB The other AS key can be any AS key derived based on K

[0055] In a preferred example, the first input parameter can comprise the identity of the MAC integrity algorithm, the type of the MAC integrity algorithm, the length of the identity of the MAC integrity algorithm, the length of the type of the MAC integrity algorithm, and the first fixed value.

[0056] The MAC integrity key can be derived based on the first security key and the first input parameter, which can be calculated by using a first calculation manner on the first security key and the first input parameter. The first calculation manner can be configured according to actual conditions, for example, the first calculation manner can include at least one of a key derivation function (KDF), a first authentication function, a second authentication function, a third key generation function (for example, which can be represented as f3), a fourth key generation function (for example, which can be represented as f4), a fifth key generation function (for example, which can be represented as f5), a hash algorithm, an advanced encryption standard (AES), SNOW 3G (Snow Third Generation), ZUC (ZU Chongzhi), an exclusive or calculation, a direct connection calculation, an algorithm for calculating a MAC layer integrity key, and the like.

[0057] For example, the MAC integrity key can be calculated by using the first calculation manner on the first security key and the first input parameter to obtain an initial MAC integrity key, and the initial MAC integrity key is truncated to obtain the MAC integrity key.

[0058] The length of the initial MAC integrity key can be the same as that of the first security key, for example, both can be 256 bits. The length of the MAC integrity key can be less than that of the initial MAC integrity key, for example, the length of the MAC integrity key can be 128 bits.

[0059] It should be pointed out that this is only an example, and in some possible examples, the initial MAC integrity key can not be truncated, but the initial MAC integrity key can be directly used as the MAC integrity key, that is, the length of the MAC integrity key can also be 256 bits. Here, all possible cases are not limited or exhausted.

[0060] In combination with FIG. 3, the derivation of the MAC integrity key based on the first security key and the first input parameter is exemplarily explained by taking the first security key as KgNB and the first calculation manner as KDF. When deriving the MAC integrity key, a string (for example, which can be represented as S) is formed by using the first input parameter, and an initial MAC layer integrity key (for example, which is represented as K in FIG. 3) is calculated by using KDF on KgNB (the length can be 256 bits) and the first input parameter. MACint, which can be 256 bits in length, and then truncating the initial MAC layer integrity key (Trunc) to obtain the MAC layer integrity key (i.e., K MACint ). The first input parameter can include the following:

[0061] - FC (i.e., a first fixed value) = 0x69;

[0062] - P0 = algorithm type distinguisher (e.g., the type of MAC integrity algorithm is 0x08) ;

[0063] - L0 = length of algorithm type distinguisher (e.g., the length of the type of MAC integrity algorithm can be 0x00 or 0x01) ;

[0064] - P1 = algorithm identity (e.g., the ID of the MAC integrity algorithm, such as 00102) ;

[0065] - L1 = length of algorithm identity (e.g., the length of the ID of the MAC integrity algorithm, such as 0x00 or 0x01, etc.).

[0066] The second security key can be any one of the at least one security key, for example, the second security key can be KgNB, or Ksn, or an AS user plane confidentiality key, or an AS control plane confidentiality key, or an ASDU confidentiality key.

[0067] The second security key can be the same as or different from the first security key. For example, the first security key and the second security key can be the same, such as both being KgNB or Ksn. For example, the first security key and the second security key can be different, such as the first security key being KgNB or Ksn, and the second security key being an AS user plane confidentiality key, or an AS control plane confidentiality key, or an ASDU confidentiality key. It should be understood that this is only an example, and in actual processing, the specific key or key type of the first security key and the second security key can include but is not limited to the above possibilities, and the present embodiment does not limit or exhaustively enumerate.

[0068] Optionally, the second input parameter can include at least one of an identification of a MAC confidentiality algorithm and a type of a MAC confidentiality algorithm.

[0069] The MAC confidentiality algorithm can be default, or protocol specified, or negotiated by the first device and the second device, or configured by the first device to the second device, or configured by the second device to the first device. As long as the same MAC confidentiality algorithm is used by the first device and the second device, it is within the protection scope of the embodiment. The MAC confidentiality algorithm can also be referred to as a MAC layer confidentiality algorithm, or a MAC layer encryption algorithm, etc. The MAC confidentiality algorithm can include an algorithm for MAC layer encryption and / or decryption, and / or an algorithm for calculating a MAC layer confidentiality key, etc., and preferably, the MAC confidentiality algorithm can include an algorithm for MAC layer encryption and / or decryption.

[0070] The type of the MAC confidentiality algorithm can be an algorithm type distinguisher of the MAC confidentiality key.

[0071] The identity of the MAC confidentiality algorithm can be represented by a 4-bit ID, or can also be represented by a longer or shorter ID, which is not limited in the embodiment. The identity of the MAC confidentiality algorithm can be default, or protocol specified, by the first device and the second device. As long as the same identity of the MAC confidentiality algorithm is used by the first device and the second device, it is within the protection scope of the embodiment.

[0072] For example, the identity of the MAC confidentiality algorithm can be any one of the following confidentiality algorithm or encryption algorithm IDs: 00002, 00012, 00102, 00112. Among them, "00002" is used to represent NEA0, i.e. Null ciphering algorithm; "00012" is used to represent 128-NEA1, i.e. 128-bit SNOW 3G based algorithm; "00102" is used to represent 128-NEA2, i.e. 128-bit AES based algorithm; "00112" is used to represent 128-NEA3, i.e. 128-bit ZUC based algorithm. Here, 128-NEA2 can be specifically a CTR (Counter) mode based on 128-bit AES. The above is only an exemplary description, and in actual processing, the MAC confidentiality algorithm can include but is not limited to the above several algorithms, and the MAC confidentiality algorithm is not limited to calculating a 128-bit MAC confidentiality key, but can also be calculating a longer or shorter MAC confidentiality key, such as the MAC confidentiality algorithm can also be used to calculate a 256-bit MAC confidentiality key, etc., which is not limited or exhaustive here.

[0073] The value of the type of the MAC confidentiality algorithm (or simply referred to as the type of the MAC layer confidentiality algorithm) is different from the value of the type of the MAC integrity algorithm (or simply referred to as the type of the MAC layer integrity algorithm). The value of the type of the MAC confidentiality algorithm can be a default value or a value specified by a protocol between the first device and the second device. For example, the value of the type of the MAC confidentiality algorithm can be 0x00, or 0x07 (inclusive) to 0xf0 (inclusive), and a value therebetween. The present embodiment does not limit or exhaustively list the value of the type of the MAC confidentiality algorithm used by the first device and the second device, as long as the first device and the second device use the same type of MAC confidentiality algorithm.

[0074] For example, the value of the algorithm type discriminator is shown in Table 1.

[0075] Table 1

[0076] Optionally, in addition to including at least one of the identifier of the MAC confidentiality algorithm and the type of the MAC confidentiality algorithm, the second input parameter can also include at least one of the length of the identifier of the MAC confidentiality algorithm, the length of the type of the MAC confidentiality algorithm, and a second fixed value.

[0077] The specific value of the second fixed value can be a default value or a value specified by a protocol between the first device and the second device. The second fixed value can be the same as or different from the first fixed value, which is not limited in the present embodiment.

[0078] Optionally, in addition to including at least one of the identifier of the MAC confidentiality algorithm, the type of the MAC confidentiality algorithm, the length of the identifier of the MAC confidentiality algorithm, the length of the type of the MAC confidentiality algorithm, and the second fixed value, the second input parameter can also include at least one of the identifier of the first device, the identifier of the second device, the cell identifier, the random number, and an input parameter used for deriving other AS keys.

[0079] In a preferred example, the second input parameter can include the identifier of the MAC confidentiality algorithm, the type of the MAC confidentiality algorithm, the length of the identifier of the MAC confidentiality algorithm, the length of the type of the MAC confidentiality algorithm, and the second fixed value.

[0080] The MAC confidentiality key can be derived based on the second security key and the second input parameter, which can be calculated by using a second calculation manner on the second security key and the second input parameter to obtain the MAC confidentiality key. The second calculation manner can be configured according to actual conditions, and the second calculation manner can be the same as or different from the first calculation manner. For example, the second calculation manner can include at least one of the following: KDF, the first authentication function, the second authentication function, the third key generation function, the fourth key generation function, the fifth key generation function, a hash algorithm, AES, SNOW 3G, ZUC, exclusive or calculation, direct connection calculation, an algorithm for calculating a MAC confidentiality key, and the like.

[0081] For example, the MAC confidentiality key can be calculated by using the second calculation manner on the second security key and the second input parameter to obtain an initial MAC confidentiality key, and the initial MAC confidentiality key is truncated to obtain the MAC confidentiality key. The length of the initial MAC confidentiality key can be the same as the second security key, for example, both can be 256 bits. The length of the MAC confidentiality key can be less than that of the initial MAC confidentiality key, for example, the length of the MAC confidentiality key can be 128 bits. It should be pointed out that this is only an example, and in some possible examples, the initial MAC confidentiality key can not be truncated, but the initial MAC confidentiality key can be directly used as the MAC confidentiality key, that is, the length of the MAC confidentiality key can also be 256 bits. Here, all possible cases are not limited or exhausted.

[0082] In combination with FIG. 4, the derivation of the MAC confidentiality key is exemplarily described by taking the second security key KgNB and the second calculation manner KDF as an example: a string (for example, which can be represented as S) is formed by using the second input parameter, and an initial MAC layer confidentiality key (for example, which is represented as K MACenc in FIG. 4) is calculated by using KDF on KgNB (the length can be 256 bits) and the second input parameter, and then the initial MAC confidentiality key is truncated (Trunc) to obtain a MAC layer integrity key (that is, K MACenc in FIG. 4 is exemplarily described). The second input parameter can include the following contents: an identifier of the MAC confidentiality algorithm, a type of the MAC confidentiality algorithm, a length of the identifier of the MAC confidentiality algorithm, a length of the type of the MAC confidentiality algorithm, and a second fixed value.

[0083] Optionally, on the first device and the second device, the MAC integrity key and the MAC confidentiality key can be derived by using the above manners respectively.

[0084] Optionally, the first device and the second device can only derive the MAC integrity key or the MAC confidentiality key.

[0085] For example, if the first device and the second device only need to perform integrity protection on the MAC layer message or information, the first device and the second device can only derive the MAC integrity key; or if the first device and the second device only need to perform encryption protection on the MAC layer message or information, the first device and the second device can only derive the MAC confidentiality key.

[0086] For another example, the first device and the second device only derive the MAC integrity key or the MAC confidentiality key as the MAC key (or the MAC layer key), but the first device and the second device can use the MAC key for encryption protection and integrity protection on the MAC layer message or information.

[0087] In an embodiment, the method further includes: updating the at least one MAC key in a case where a first condition is met, wherein the first condition includes at least one of the following: system information update, RRC state change, cell switching, and a number of MAC layer integrity verification failures reaching a preset number.

[0088] Optionally, the terminal can determine that the first condition is met when system information is updated; and the access network device can determine that the first condition is met when system information is updated. If the first device is the terminal, the second device is the target access network device; or if the first device is the target access network device, the second device is the terminal.

[0089] Optionally, the RRC state change refers to a change in the RRC state of the terminal. For example, the terminal can determine that the first condition is met when it is determined that the RRC state of the terminal changes; and the access network device can determine that the first condition is met when the RRC state of the terminal changes. If the first device is the terminal, the second device is the access network device; or if the first device is the access network device, the second device is the terminal.

[0090] Optionally, the cell switching can refer to switching of the terminal from a source cell to a target cell. For example, the terminal can determine that the first condition is met when it is determined that the terminal is switched from the source cell to the target cell; and the access network device can determine that the first condition is met when the terminal is switched from the source cell to the target cell, and the access network device can be a target access network device corresponding to the target cell. If the first device is the terminal, the second device is the target access network device; or if the first device is the target access network device, the second device is the terminal.

[0091] Optionally, the number of times of MAC layer integrity verification failure reaching a preset number refers to that when the number of times of MAC layer integrity verification failure events reaches a certain preset value (or a preset number), a failure report or RRC connection reestablishment can be triggered. The failure report can be carried by RRC or MAC layer signaling; if a MAC layer integrity verification failure triggers a failure report, the generation of a MAC sub-PDU or a MAC PDU containing the MAC sub-PDU is suspended, and further, the network (such as an access network device) can instruct the terminal to update the MAC security key while keeping the terminal in an RRC_CONNECTED (connected) state. The RRC connection reestablishment refers to that when the terminal side MAC layer integrity verification fails, the RRC layer of the terminal is instructed that the MAC layer integrity check fails, and the RRC layer of the terminal triggers a certain RRC connection recovery process, and further, the network (such as an access network device) instructs the terminal to update the MAC security key in the RRC reestablishment process. The preset value (or the preset number) can be configured according to actual conditions, which is not limited here.

[0092] It should be understood that the first device and the second device can determine that the first condition is met in any one of determining system information update, RRC state change, cell switching, and the number of times of integrity verification failure reaching a preset number.

[0093] In this embodiment, generating at least one MAC key can refer to initially generating the at least one MAC key, or can refer to updating the at least one MAC key.

[0094] It should be pointed out that on the side of the first device and the second device, the at least one MAC key is updated when the first condition is met. In the following description of updating the MAC key, the first device and the second device are not distinguished.

[0095] Optionally, in the case of security key update, updating the at least one MAC key can be updating the at least one MAC key based on the updated at least one security key.

[0096] Specifically, the updating of the at least one MAC key based on the updated at least one security key includes at least one of the following: obtaining an updated MAC integrity key based on the updated first security key and a first input parameter; and obtaining an updated MAC confidentiality key based on the updated second security key and a second input parameter.

[0097] The first security key, the second security key, and the related descriptions of each security key are the same as those in the foregoing embodiments, and will not be repeated. The manner of updating the first security key, the manner of updating the second security key, and the manner of updating each security key are not limited in this embodiment. The related descriptions of the first input parameter and the second input parameter are also similar to those in the foregoing embodiments. For example, the first input parameter can include at least one of an identifier of a MAC integrity algorithm, a type of the MAC integrity algorithm, a length of the identifier of the MAC integrity algorithm, a length of the type of the MAC integrity algorithm, and a first fixed value. The second input parameter can include at least one of an identifier of a MAC confidentiality algorithm, a type of the MAC confidentiality algorithm, a length of the identifier of the MAC confidentiality algorithm, a length of the type of the MAC confidentiality algorithm, and a second fixed value.

[0098] For example, the updated first security key and the updated second security key are both updated KgNB. The updated MAC integrity key can be obtained by performing a first calculation manner on the updated first security key and the first input parameter. The updated MAC confidentiality key can be obtained by performing a second calculation manner on the updated second security key and the second input parameter.

[0099] Optionally, in the case where the security key is not updated, the updating of the at least one MAC key can include: obtaining the updated at least one MAC key based on the last derived at least one MAC key and updated parameters. The updated parameters can include at least one of an SN count value, an NH freshness value, and the like.

[0100] Specifically, the obtaining of the updated at least one MAC key based on the last derived at least one MAC key and the updated parameters can include at least one of: obtaining the updated MAC integrity key based on the last derived MAC integrity key and the updated parameters; and obtaining the updated MAC confidentiality key based on the last derived MAC confidentiality key and the updated parameters.

[0101] The last derived MAC integrity key can be a first derived MAC integrity key or a last updated MAC integrity key. The last derived MAC confidentiality key can be a first derived MAC confidentiality key or a last updated MAC confidentiality key.

[0102] The way of calculating the updated MAC integrity key can be configured according to actual conditions, such as at least one of KDF, the first authentication function, the second authentication function, the third key generation function, the fourth key generation function, the fifth key generation function, a hash algorithm, AES, SNOW 3G, ZUC, exclusive or calculation, direct connection calculation, and the like. The way of calculating the updated MAC confidentiality key can be the same as or different from the way of calculating the updated MAC integrity key. The way of calculating the updated MAC confidentiality key can be configured according to actual conditions, such as at least one of KDF, the first authentication function, the second authentication function, the third key generation function, the fourth key generation function, the fifth key generation function, a hash algorithm, AES, SNOW 3G, ZUC, exclusive or calculation, direct connection calculation, and the like.

[0103] In some possible implementation manners, the MAC security algorithm can be default or specified by a protocol on the first device and the second device, where the MAC security algorithm includes at least one of a MAC integrity algorithm and a MAC confidentiality algorithm. For example, the first device and the second device can use the MAC security algorithm used last time by both sides by default. For another example, the first device and the second device can use the MAC security algorithm specified by a protocol.

[0104] In some possible implementation manners, the first device and the second device can negotiate the MAC security algorithm, where the MAC security algorithm includes at least one of a MAC integrity algorithm and a MAC confidentiality algorithm.

[0105] In an embodiment, the first device can be a terminal, and the second device can be an access network device. The processing of the first device further includes receiving first algorithm indication information from the second device, where the first algorithm indication information is used by the first device to determine the MAC security algorithm.

[0106] That is, the access network device sends the first algorithm indication information to the terminal, and the terminal receives the first algorithm indication information from the access network device to determine the MAC security algorithm based on the first algorithm indication information.

[0107] Optionally, the first algorithm indication information can include indication information of the MAC security algorithm. The indication information of the MAC security algorithm can include at least one of a name of a MAC integrity algorithm, a name of a MAC confidentiality algorithm, an identity of a MAC integrity algorithm, an identity of a MAC confidentiality algorithm, a type of a MAC integrity algorithm, a type of a MAC confidentiality algorithm, and the like.

[0108] Optionally, the first algorithm indication information can comprise at least one of the following: indication information of an RRC security algorithm, indication information of a UP (User Plane) security algorithm, in addition to the indication information of the MAC security algorithm. The indication information of the RRC security algorithm can comprise indication information of an RRC integrity algorithm and / or indication information of an RRC encryption algorithm; the indication information of the UP security algorithm can comprise indication information of a UP integrity algorithm and / or indication information of a UP encryption algorithm, which are not limited in the embodiment.

[0109] The first algorithm indication information is carried by a first security mode command (SMC, Security Mode Command) message. Specifically, the first algorithm indication information can be sent by the second device (i.e., the access network device) to the first device (i.e., the terminal) through the first SMC (i.e., the AS SMC) message in the process of establishing access stratum (AS, Access Stratum) security by the first device and the second device establishing an RRC connection (which can be referred to as an AS SMC process or an AS SMC procedure). The AS SMC process is used for RRC, UP, and MAC security algorithm negotiation and RRC security activation.

[0110] The first SMC message can be integrity protected using an RRC integrity key (K RRCint ). Specifically, the processing of the second device can comprise: starting or enabling RRC integrity protection, calculating a fifth integrity check code based on the RRC integrity algorithm and K RRCint , sending the first SMC message carrying the fifth integrity check code and the first algorithm indication information. In addition, the first SMC message can also carry other contents as specified by the related protocol, which are not limited in the embodiment.

[0111] Correspondingly, the processing of the first device can be: receiving the first SMC message from the second device, calculating the fifth integrity check code based on the RRC integrity key and the content of the first SMC message other than the fifth integrity check code; in the case that the fifth integrity check code is the same as the fifth integrity check code, determining that the integrity verification of the first SMC message is successful, and extracting the first algorithm indication information from the first SMC message. The content of the first SMC message other than the fifth integrity check code can comprise the first algorithm indication information and other contents as specified by the related protocol, which are not limited in the embodiment.

[0112] In this embodiment, after the first device obtains the first algorithm indication information, the first device can perform the processing of generating the at least one MAC key based on the at least one security key in the foregoing embodiments, which is not repeated here. In addition, after receiving the first algorithm indication information, the first device can also perform the processing of deriving at least part of the security key (such as K UPint , K UPenc , K RRCint , K RRCenc , etc.), which is not limited here.

[0113] In addition, the processing of the first device can further include: starting RRC integrity protection and RRC downlink message decryption (or referred to as RRC downlink decryption) in the case that the first SMC message integrity verification is successful.

[0114] The processing of the second device can further include: starting or enabling RRC downlink message encryption (or referred to as RRC downlink encryption) after sending the first SMC message to the first device.

[0115] Further, the processing of the first device can further include: sending a first security mode complete message to the second device, and starting RRC uplink message encryption (or referred to as RRC uplink encryption). The first security mode complete message can be integrity protected based on the RRC integrity algorithm and K RRCint . That is, the first security mode complete message can carry a sixth integrity check code. The processing of the second device can further include: receiving the first security mode complete message from the first device, calculating a sixth integrity verification code based on the RRC integrity algorithm and K RRCint , and determining that the integrity check is successful in the case that the sixth integrity check code and the sixth integrity verification code are the same, and starting or enabling RRC uplink message decryption (or referred to as RRC uplink decryption).

[0116] It should be further noted that if the processing of the first device (i.e., the terminal) on the first SMC message is not successful (such as integrity verification failure), the terminal will reply to the second device (i.e., the access network device) with an unprotected security mode failure message. In addition, the AS SMC procedure should be used only during initial context setup between the terminal and the access network device (i.e., initial KgNB is activated when transitioning from RRC_IDLE (RRC idle state) to RRC_CONNECTED (RRC connected state).

[0117] In combination with FIG. 5, taking the first device as a UE, the second device as a gNB, and the first SMC message as an AS SMC as an example, the processing of the access network device and the terminal in the AS SMC procedure is exemplarily described as follows:

[0118] Step 501: The gNB starts RRC integrity protection.

[0119] Step 502, gNB sends AS SMC to UE, wherein AS SMC may carry an integrity algorithm, an encryption algorithm, and a fifth integrity check code. The integrity algorithm may include a MAC integrity algorithm, and the encryption algorithm may include a MAC encryption algorithm.

[0120] Here, the integrity algorithm and encryption algorithm can be content carried in the Security Mode Command IE of AS SMC. For example, the Security Mode Command IE can be represented as follows:

[0121] "SecurityConfiqSMC::= SEQUENCE{

[0122] securityAlgorithmConfig (Security Algorithm Configuration)

[0123]

[0124] }”

[0125] The "SecurityAlgorithmConfig" section contains instructions on the MAC integrity algorithm and / or MAC encryption algorithm configured for this project.

[0126] Step 503: Enable RRC downlink encryption on the gNB.

[0127] Step 504: The UE verifies the integrity of the AS SMC based on the fifth integrity check code. If the integrity verification is successful, RRC integrity protection and RRC downlink decryption are enabled.

[0128] Step 505: The UE sends an AS Security Mode Complete message (i.e., the aforementioned first security mode complete message) to the gNB. This AS Security Mode Complete message can also use the RRC integrity key for integrity protection. That is, this AS Security Mode Complete message can carry a sixth integrity check code. The specific calculation method of the sixth integrity check code is not limited in this embodiment.

[0129] Step 506: Enable RRC uplink encryption for the UE.

[0130] Step 507: gNB enables RRC uplink decryption.

[0131] Here, the execution order of step 503 and step 504 is not limited, as long as both are after step 502 and before step 505. The execution order of step 506 and step 507 is not limited, as long as both are after step 505.

[0132] In an embodiment, the first device can be an access network device, and the second device can be a terminal. The processing of the first device further includes: sending second algorithm indication information to the second device, wherein the second algorithm indication information is used by the second device to determine the MAC security algorithm.

[0133] That is, the access network device sends second algorithm indication information to the terminal, and the terminal receives the second algorithm indication information from the access network device to determine the MAC security algorithm based on the second algorithm indication information.

[0134] The first device, i.e. the access network device, determines the MAC security algorithm in the following way: based on the locally configured allowed algorithm list and the capability of the second device (i.e. the terminal), the MAC security algorithm is selected.

[0135] Next, the first device is taken as an access network device, and the second device is taken as a terminal for example:

[0136] The access network device (such as gNB or ng-eNB) should be configured and provided with the allowed algorithm list through network management. The allowed algorithm list on the side of the access network device can include an allowed integrity algorithm list and / or an allowed encryption algorithm list. At least one allowed integrity algorithm can be included in the allowed integrity algorithm list, which is sorted according to the priority decided by the operator, and at least one allowed encryption algorithm can be included in the allowed encryption algorithm list, which is sorted according to the priority decided by the operator.

[0137] The capability of the terminal can at least include the security capability of the terminal, which can be used to indicate at least one integrity algorithm and / or at least one encryption algorithm supported by the terminal. The security capability of the terminal can be the 5G security capability of the terminal. The way in which the access network device obtains the capability of the terminal is not limited in this embodiment.

[0138] The access network device can determine the MAC security algorithm in the following manner: determining, based on a priority of at least one allowed integrity algorithm included in a locally configured allowed integrity algorithm list and a 5G security capability of the terminal, an integrity algorithm that is allowed to use and is included in the 5G security capability of the terminal as the MAC integrity algorithm; and determining, based on a priority of at least one allowed encryption algorithm included in a locally configured allowed encryption algorithm list and the 5G security capability of the terminal, an encryption algorithm that is allowed to use and is included in the 5G security capability of the terminal as the MAC encryption algorithm.

[0139] It should be noted that, in addition to determining the MAC security algorithm, the access network device can also determine at least one of a UP security algorithm (such as a UP integrity algorithm and / or a UP encryption algorithm), an RRC security algorithm (such as an RRC integrity algorithm and / or an RRC encryption algorithm), and the like, without limitation or exhaustion.

[0140] Optionally, the second algorithm indication information can include indication information of the MAC security algorithm. Optionally, in addition to the indication information of the MAC security algorithm, the second algorithm indication information can also include at least one of the following: indication information of an RRC security algorithm, indication information of a UP (User Plane) security algorithm.

[0141] The second algorithm indication information is carried by a second SMC message. Specifically, the second algorithm indication information can be sent by the access network device to the terminal through the second SMC (also referred to as AS SMC) message in a process of establishing access layer (AS, Access Stratum) security through an SMC procedure (which can be referred to as an AS SMC procedure) when the access network device establishes an RRC connection with the terminal.

[0142] The second SMC message can be integrity protected using an RRC integrity key. Specifically, the processing of the first device (the access network device) can include: calculating a sixth integrity check code based on the RRC integrity key and the content that needs to be carried by the second SMC message. The content carried by the second SMC message, in addition to the sixth integrity check code, can include the second algorithm indication information and other content as specified by the relevant protocol, which is not limited in the present embodiment. Correspondingly, after receiving the second SMC message, the second device (the terminal) will also first perform integrity checking on the second SMC message, and after the checking is passed, the second algorithm indication information is obtained to determine the MAC security algorithm. The processing manner of the second device for performing integrity checking is similar to the processing of the first device for performing integrity checking in the foregoing embodiments, and thus is not repeated.

[0143] In this embodiment, the processing related to the transmission of the AS SMC message and the AS SMC security mode complete message between the terminal and the access network device is similar to the foregoing embodiments, and thus no repeated description is given.

[0144] In the related protocol, it is stipulated that the data of the AS layer is first subjected to integrity protection and then subjected to encryption. Therefore, the first device can apply integrity protection and verification to the MAC sub-headers corresponding to all uplink / downlink sub-PDUs (subPDU) requiring integrity protection and the data or payload part (i.e., MAC CE and / or MAC SDU) to be transmitted (i.e., the entire MAC sub-PDU corresponding to the MAC CE / MAC SDU requiring security protection) after the integrity protection / verification is activated.

[0145] In some possible embodiments, the first device can perform integrity protection on a MAC PDU sent to the second device as a sending end of the MAC layer message. After deriving the MAC key, the first device can perform the following processing: sending a first MAC PDU (Protocol Data Unit) to the second device, wherein the first MAC PDU carries at least one first sub-PDU that is securely protected based on the MAC key. Here, the sub-PDU refers to a MAC sub-PDU (i.e., MAC subPDU), which will not be repeatedly explained below.

[0146] The first MAC PDU can be any MAC PDU sent by the first device, or can be a MAC PDU sent by the first device and requiring security protection.

[0147] The security protection can include integrity protection and / or confidentiality protection. Here, the confidentiality protection can also be referred to as encryption protection, and both have the same meaning. The integrity protection can also be referred to as perfect protection, and both have the same meaning. The following will not be repeatedly explained.

[0148] In the processing of the security protection of the at least one first sub-PDU of the first MAC PDU, the first device can only perform integrity protection, or can first perform integrity protection and then perform encryption protection.

[0149] In some embodiments, the first device can only perform integrity protection on the first MAC PDU.

[0150] In an embodiment, the first device can uniformly perform integrity protection on all first sub-PDUs carried by the first MAC PDU. The at least one first sub-PDU can refer to all or part of the sub-PDUs constituting the first MAC PDU.

[0151] The first MAC PDU carries a first integrity check code, wherein the first integrity check code is calculated based on a MAC integrity key, a MAC integrity algorithm, first identification information, and at least one of the following: data to be transmitted of each of the at least one first sub-PDU, a subheader corresponding to each of the at least one first sub-PDU, and a header of the first MAC PDU.

[0152] The first integrity check code is carried or assembled in the first MAC PDU at a position of a header of the first MAC PDU or after a last first sub-PDU of the first MAC PDU, and the embodiment does not limit or exhaustively list the position of the first MAC PDU carrying the first integrity check code.

[0153] Any first sub-PDU can be composed of a subheader corresponding to the first sub-PDU and data to be transmitted of the first sub-PDU. In some possible examples, the data to be transmitted of any first sub-PDU can also be referred to as a payload of the first sub-PDU or data (or plaintext data) of the first sub-PDU.

[0154] The type of the data to be transmitted of any first sub-PDU can be any of the following: a MAC service data unit (SDU) and a MAC control element (CE).

[0155] The first identification information includes a first COUNT value, wherein the first COUNT value is carried in the header of the first MAC PDU. The first COUNT can be a same COUNT value used by all first sub-PDUs in the first MAC PDU. It should be noted that the first COUNT value can also be referred to as a first serial number (SN), a first number, a first identification code, or the like, and the embodiment does not limit or exhaustively list all possible alternatives.

[0156] The processing of calculating the first integrity check code by the first device can include: calculating the first integrity check code by using the MAC integrity algorithm, the MAC integrity key, and a third input parameter. The third input parameter can include a message (MESSAGE) and the first COUNT value, and the message can include at least one of the following: data to be transmitted of each first sub-PDU, a subheader corresponding to each first sub-PDU, and a header of the first MAC PDU.

[0157] Optionally, the first count value contained in the third input parameter can be filled according to actual needs to obtain a count value of a specified length, and the specified length can be configured according to actual conditions. For example, the specified length is 32 bits, and the actual length of the first count value is 8 bits. Then, 24 bits of 0 can be filled before the first count value to finally obtain the first count value of 32 bits of the specified length.

[0158] Optionally, the third input parameter can further include other contents. For example, the third input parameter can further include a first transmission direction (DIRECTION), which can be represented by 1 bit to indicate that the transmission direction is uplink or downlink. For example, when the first device is a terminal, the first transmission direction can be uplink; and when the first device is an access network device, the first transmission direction can be downlink.

[0159] The calculation of the first integrity check code is exemplarily described in combination with FIG. 6. The message, the first count value, and the first transmission direction are taken as the third input parameter, and the first integrity check code (MAC-I shown in FIG. 6) is calculated based on a MAC integrity algorithm (such as NIA shown in FIG. 6), a MAC integrity key (K MACint

[0160] In an embodiment, the first device performs integrity protection on at least one first sub-PDU carried by the first MAC PDU respectively. Each of the at least one first sub-PDU carries a second integrity check code corresponding to the each first sub-PDU, and the second integrity check code corresponding to the each first sub-PDU is calculated based on a MAC integrity key, a MAC integrity algorithm, second identification information corresponding to the each first sub-PDU, and at least one of the following: a subheader corresponding to the each first sub-PDU, and data to be transmitted of the each first sub-PDU.

[0161] The second identification information corresponding to the each first sub-PDU includes at least one of the following: a logical channel identifier (LCID) corresponding to the each first sub-PDU, and a second count value corresponding to the each first sub-PDU.

[0162] The LCID corresponding to the each first sub-PDU is carried by a subheader corresponding to the each first sub-PDU; and the second count value corresponding to the each first sub-PDU is carried by the subheader corresponding to the each first sub-PDU or a header of the first MAC PDU.

[0163] ​In this embodiment, the at least one first sub-PDU can be at least one sub-PDU of all sub-PDUs carried by the first MAC PDU that needs integrity protection. Which sub-PDUs in the first MAC PDU need integrity protection can be configured according to actual conditions, or determined based on a pre-configured strategy, or can be determined based on pre-received activation information, which is not limited in this embodiment.

[0164] Taking any one of the at least one first sub-PDU (i.e. at least one sub-PDU that needs integrity protection) as the mthfirst sub-PDU as an example, the second integrity check code corresponding to the mthfirst sub-PDU is calculated based on the MAC integrity key, the MAC integrity algorithm, the second identification information corresponding to the mthfirst sub-PDU, and at least one of the following: the sub-header corresponding to the mthfirst sub-PDU, and the data to be transmitted of the mthfirst sub-PDU, wherein m is an integer greater than or equal to 1.

[0165] The carrying or assembling position of the second integrity check code corresponding to the mthfirst sub-PDU in the mthfirst sub-PDU can be at the end of the mthfirst sub-PDU (i.e. after the data (or plaintext data or data to be transmitted) carried by the mthfirst sub-PDU), or can be in the header corresponding to the mthfirst sub-PDU, etc. This embodiment does not limit or exhaust the carrying or assembling position of the second integrity check code corresponding to the mthfirst sub-PDU.

[0166] The second identification information corresponding to the mthfirst sub-PDU can be used to uniquely identify the mthfirst sub-PDU, or to uniquely identify the mthfirst sub-PDU in the first MAC PDU.

[0167] The LCID corresponding to the mthfirst sub-PDU can be used to indicate that the mthfirst sub-PDU is a specific MAC PDU, and / or corresponds to a specific second count value, and / or corresponds to a specific sub-PDU (or sub-PDU type) in a specific first transmission direction. The length of the LCID can be configured according to actual conditions, such as 5 bits.

[0168] Optionally, the second count value corresponding to the mthfirst sub-PDU is carried by the sub-header corresponding to the mthfirst sub-PDU. In this case, the second count value corresponding to the mthfirst sub-PDU can be globally numbered, that is, different first sub-PDUs in the first MAC PDU correspond to different second count values.

[0169] Optionally, the second count value corresponding to the mthfirst sub-PDU is carried by the header of the first MAC PDU. In this case, all sub-PDUs in the first MAC PDU use the same count value.

[0170] It should be noted that the second count value can also be referred to as a second SN, or a second number, or a second identification code, and the like, and all possible alternatives are not limited or exhausted here.

[0171] In an example, the second identification information corresponding to the mth first sub-PDU can only include the LCID corresponding to the mth first sub-PDU.

[0172] For example, if the mth first sub-PDU only appears in the first MAC PDU, different MAC PDUs and / or different sub-PDUs can not be distinguished, in which case only the LCID corresponding to the mth first sub-PDU can be used to uniquely identify the mth first sub-PDU.

[0173] The first device can calculate the second integrity check code corresponding to the mth first sub-PDU, which can include: using a MAC integrity algorithm, a MAC integrity key, and a fourth input parameter to calculate the second integrity check code corresponding to the mth first sub-PDU. The fourth input parameter can include the mth message (MESSAGE) and the LCID corresponding to the mth first sub-PDU. The mth message can include at least one of the data to be transmitted corresponding to the mth first sub-PDU and the subheader corresponding to the mth first sub-PDU. In addition, the fourth input parameter can also include other contents, such as the first transmission direction (DIRECTION).

[0174] In combination with FIG. 7, the calculation of the second integrity check code corresponding to the mth first sub-PDU is exemplarily illustrated. The mth message, the LCID corresponding to the mth first sub-PDU, and the first transmission direction are taken as the fourth input parameter. Based on the MAC integrity algorithm (such as the MAC integrity algorithm illustrated in FIG. 7, which is NIA), the MAC integrity key (illustrated as K MACint in FIG. 7), and the fourth input parameter, the second integrity check code (such as MAC_m-I shown in FIG. 7) corresponding to the mth first sub-PDU is calculated. The mth message includes the subheader corresponding to the mth first sub-PDU and the data to be transmitted carried by the mth first sub-PDU (such as MAC CE_m).

[0175] In an example, the second identification information corresponding to the mth first sub-PDU can only include the second count value corresponding to the mth first sub-PDU. In this case, the second count value corresponding to the mth first sub-PDU is a global number, that is, different sub-PDUs in the first MAC PDU correspond to different second count values, so only the second count value corresponding to the mth first sub-PDU can be used to uniquely identify the mth first sub-PDU.

[0176] The first device calculates the second integrity check code corresponding to the mth first sub-PDU in a manner similar to the foregoing examples, except that the fourth input parameter includes the second count value corresponding to the mth first sub-PDU instead of the LCID, and thus no further description is provided.

[0177] In combination with FIG. 8, the calculation of the second integrity check code corresponding to the mth first sub-PDU is described by way of example. The mth message, the second count value corresponding to the mth first sub-PDU, and the first transmission direction are taken as the fourth input parameter, and the second integrity check code corresponding to the mth first sub-PDU is calculated based on a MAC integrity algorithm (such as NIA in FIG. 8), a MAC integrity key (illustrated as K MACint MACint

[0178] In one example, the second identification information corresponding to the mth first sub-PDU includes the second count value corresponding to the mth first sub-PDU and the LCID corresponding to the mth first sub-PDU.

[0179] In this case, the second count value corresponding to the mth first sub-PDU can be a global number, that is, different sub-PDUs in the first MAC PDU correspond to different second count values. Alternatively, the second count value corresponding to the mth first sub-PDU can be the same count value used by all sub-PDUs in the first MAC PDU.

[0180] The first device calculates the second integrity check code corresponding to the mth first sub-PDU in a manner similar to the foregoing examples, except that the fourth input parameter can include the second count value corresponding to the mth first sub-PDU and the LCID corresponding to the mth first sub-PDU, and thus no further description is provided.

[0181] In combination with FIG. 9, the calculation of the second integrity check code corresponding to the mth first sub-PDU is described by way of example. The mth message, the second count value corresponding to the mth first sub-PDU, the LCID corresponding to the mth first sub-PDU, and the first transmission direction are taken as the fourth input parameter, and the second integrity check code corresponding to the mth first sub-PDU is calculated based on a MAC integrity algorithm (such as NIA in FIG. 9), a MAC integrity key (illustrated as K MACint MACint

[0182] It should be noted that the above is only an exemplary description of calculating the second integrity check code corresponding to the mth first sub-PDU. In actual processing, the manner of calculating the second integrity check code corresponding to each first sub-PDU is the same as the manner of calculating the second integrity check code corresponding to the mth first sub-PDU, and thus is not described one by one.

[0183] In the embodiment in which the first device only performs integrity protection on the first MAC PDU, in the first MAC PDU, each of the at least one first sub-PDU carries the data to be transmitted of the first sub-PDU (or the load (such as a MAC CE or a MAC SDU) of the first sub-PDU), that is, each first sub-PDU can directly carry the data (or plaintext data) that needs to be carried by the first sub-PDU.

[0184] In some embodiments, the first device can perform confidentiality protection (or encryption protection) on the first MAC PDU after performing integrity protection on the first MAC PDU.

[0185] That is, when the MAC layer activates the encryption protection, the encryption protection is applied to all sub-PDUs that need to be encrypted in the uplink / downlink. The entire content of each sub-PDU can be encrypted, or the data to be transmitted or the load (that is, a MAC CE or a MAC SDU) of each sub-PDU can be encrypted.

[0186] It should be further noted that the embodiment in which the first device only performs protection:

[0187] After the first device generates the first integrity check code based on the integrity protection algorithm, the first integrity check code can be placed at the end of the entire first MAC PDU (or at the header of the first MAC PDU), and the integrity protection process ends. When the second device is the receiving end of the first MAC PDU, the second device will perform integrity check on the first MAC PDU. For example, the second device will use the same algorithm and parameters as the first device to calculate the first integrity check code and compare it with the received first integrity check code. If they are the same, the integrity check passes, otherwise the integrity check fails. In this case, the second device will discard the first MAC PDU.

[0188] Alternatively, after the first device generates the second integrity check code (such as MAC-I) corresponding to each first sub-PDU based on the integrity protection algorithm, the second integrity check code can be placed at the end of the first sub-PDU, and the integrity protection process ends. When the second device is the receiving end of the first MAC PDU, the second device will perform integrity check on each first sub-PDU, for example, the second device will calculate the second integrity check code (such as X-MAC) of each first sub-PDU using the same algorithm and parameters as the first device, and compare the X-MAC with the received MAC-I. If they are the same, the integrity check is passed, otherwise the integrity check fails. In addition, in the case of integrity check failure of a certain first MAC sub-unit, the second device can discard the first MAC sub-unit.

[0189] In an embodiment, the first device can uniformly perform confidentiality protection (or encryption protection) on each first sub-PDU that needs confidentiality protection. In this embodiment, the first MAC PDU carries first cipher text data, wherein the first cipher text data is encrypted based on a MAC confidentiality key, a MAC confidentiality algorithm, and the first identification information on at least one of the following: the to-be-transmitted data of each first sub-PDU that needs confidentiality protection, the sub-header corresponding to each first sub-PDU that needs confidentiality protection, the second integrity check code corresponding to each first sub-PDU that needs confidentiality protection, and the first integrity check code.

[0190] The first sub-PDU that needs confidentiality protection can refer to part or all of the first sub-PDUs that constitute the first MAC PDU.

[0191] The processing of the first device to calculate the first cipher text data can include: using the MAC confidentiality algorithm, the MAC confidentiality key, and the fifth input parameter to calculate a first keystream, and performing XOR calculation on the first keystream and the to-be-encrypted data to obtain the first cipher text data, wherein the to-be-encrypted data can include at least one of the following: the to-be-transmitted data of each first sub-PDU that needs confidentiality protection, the sub-header corresponding to each first sub-PDU that needs confidentiality protection, the second integrity check code corresponding to each first sub-PDU that needs confidentiality protection, and the first integrity check code.

[0192] The fifth input parameter can include a message length (Message Length) and a first count value; the message refers to the to-be-encrypted data. Alternatively, the first count value included in the fifth input parameter can be padded according to actual needs to obtain a count value of a specified length, and the specified length and the way of processing the count value of the specified length are the same as in the foregoing embodiments, and will not be repeated here.

[0193] In addition, the fifth input parameter can also include a first transmission direction.

[0194] In one case, if the first device uniformly performs integrity protection and encryption protection on all first sub-PDUs carried by the first MAC PDU. In this case, the data to be encrypted when the first device calculates the first cipher text data can include at least one of the following: data to be transmitted of each first sub-PDU requiring confidentiality protection, a subheader corresponding to each first sub-PDU requiring confidentiality protection, and a first integrity check code.

[0195] For example, the data to be encrypted can include: data to be transmitted of each first sub-PDU requiring confidentiality protection, a subheader corresponding to each first sub-PDU requiring confidentiality protection, and the first integrity check code; and the first sub-PDUs requiring confidentiality protection are all first sub-PDUs performing integrity protection. The first MAC PDU can carry a header of the first MAC PDU and the first cipher text data.

[0196] For example, the data to be encrypted can include: data to be transmitted of each first sub-PDU requiring confidentiality protection, a subheader corresponding to each first sub-PDU requiring confidentiality protection; and the first sub-PDUs requiring confidentiality protection are all first sub-PDUs performing integrity protection. Correspondingly, the first MAC PDU can carry a header of the first MAC PDU, the first cipher text data, and the first integrity check code.

[0197] In this case, the first integrity check code is calculated in the same way as in the foregoing embodiments, and details are not repeated.

[0198] In one case, if the first device uniformly performs integrity protection and encryption protection on all first sub-PDUs carried by the first MAC PDU. In this case, the data to be encrypted when the first device calculates the first cipher text data can include at least one of the following: data to be transmitted of each first sub-PDU requiring confidentiality protection, a subheader corresponding to each first sub-PDU requiring confidentiality protection, and a first integrity check code.

[0199] For example, the data to be encrypted can include: data to be transmitted of each first sub-PDU requiring confidentiality protection, a subheader corresponding to each first sub-PDU requiring confidentiality protection, and the first integrity check code; and the first sub-PDUs requiring confidentiality protection are all first sub-PDUs performing integrity protection. The first MAC PDU can carry a header of the first MAC PDU and the first cipher text data.

[0200] In an embodiment, each of the first sub-PDUs requiring confidentiality protection carries second cipher data corresponding to the first sub-PDU, wherein the second cipher data corresponding to each of the first sub-PDUs requiring confidentiality protection is obtained by encrypting at least one of the following based on a MAC confidentiality key, a MAC confidentiality algorithm, and second identification information corresponding to the first sub-PDU: data to be transmitted of the first sub-PDU, a subheader corresponding to the first sub-PDU, and a second integrity check code corresponding to the first sub-PDU.

[0201] In the embodiment, the first sub-PDUs requiring confidentiality protection can be part or all of the first sub-PDUs protected by integrity in the first MAC PDU. For example, the first MAC PDU contains 10 first sub-PDUs protected by integrity, which are referred to as 10 first sub-PDUs protected by integrity (perfect protection first sub-PDUs). The 10 perfect protection first sub-PDUs can be all encrypted, that is, the final first MAC PDU carries 10 first sub-PDUs protected by integrity and encrypted; or, of the 10 perfect protection first sub-PDUs, only 8 require encryption protection, and the other 2 do not require encryption, that is, the final first MAC PDU carries 8 first sub-PDUs protected by integrity and encrypted and 2 first sub-PDUs protected by integrity only. It should be understood that this is only an example and does not limit the number of perfect protection and / or encrypted first sub-PDUs contained in the first MAC PDU. In addition, which sub-PDUs in the first MAC PDU require confidentiality protection can be configured according to actual conditions, or determined based on a preconfigured strategy, or can be determined based on pre-received activation information, which is not limited in the embodiment. It should be pointed out that the confidentiality protection can be alternatively referred to as encryption protection, which is not repeated below.

[0202] Taking the mth first sub-PDU as an example of any first sub-PDU requiring confidentiality protection, the second cipher data corresponding to the mth first sub-PDU is obtained by encrypting at least one of the following based on a MAC confidentiality key, a MAC confidentiality algorithm, and second identification information corresponding to the mth first sub-PDU: data to be transmitted of the mth first sub-PDU, a subheader corresponding to the mth first sub-PDU, and a second integrity check code corresponding to the mth first sub-PDU.

[0203] In an example, the second identification information corresponding to the mth first sub-PDU can only include an LCID corresponding to the mth first sub-PDU.

[0204] The processing of the first device for calculating the second ciphertext data corresponding to the mth first sub-PDU can include: using the MAC confidentiality algorithm, the MAC confidentiality key and the sixth input parameter, calculating a second keystream, and performing XOR calculation on the second keystream and the mth to-be-encrypted data to obtain the second ciphertext data corresponding to the first sub-PDU, wherein the mth to-be-encrypted data can include at least one of the to-be-transmitted data of the mth first sub-PDU, the sub-header corresponding to the mth first sub-PDU, and the second integrity verification code corresponding to the mth first sub-PDU. The sixth input parameter can include the mth message length and the LCID corresponding to the mth first sub-PDU. The mth message has the same meaning as the mth to-be-encrypted data, which will not be repeated below. In addition, the sixth input parameter can further include the first transmission direction.

[0205] Taking FIG. 10 as an example, the processing of calculating the second ciphertext data corresponding to the mth first sub-PDU can be: taking the LCID corresponding to the mth first sub-PDU, the first transmission direction and the mth message length as the sixth input parameter, calculating a second keystream based on the MAC confidentiality key (illustrated as K MACenc in FIG. 10) and the MAC confidentiality algorithm (denoted as NEA in FIG. 10) on the sixth input parameter, and performing XOR calculation on the second keystream and the mth message to obtain the second ciphertext data corresponding to the mth first sub-PDU.

[0206] In an example, the second identification information corresponding to the mth first sub-PDU can only include the second count value corresponding to the mth first sub-PDU. In this case, the second count value corresponding to the mth first sub-PDU is globally numbered.

[0207] The processing of the first device for calculating the second ciphertext data corresponding to the mth first sub-PDU is similar to the foregoing examples, and the only difference is that the second count value corresponding to the mth first sub-PDU is included in the sixth input parameter instead of the LCID, and thus will not be repeated.

[0208] Taking FIG. 11 as an example, the processing of calculating the second ciphertext data corresponding to the mth first sub-PDU can be: taking the second count value corresponding to the mth first sub-PDU, the first transmission direction and the mth message length as the sixth input parameter, calculating a second keystream based on the MAC confidentiality key (illustrated as K MACenc in FIG. 11) and the MAC confidentiality algorithm (denoted as NEA in FIG. 11) on the sixth input parameter, and performing XOR calculation on the second keystream and the mth message to obtain the second ciphertext data corresponding to the mth first sub-PDU.

[0209] In an example, the second identification information corresponding to the mth first sub-PDU can include the second count value corresponding to the mth first sub-PDU and the LCID corresponding to the mth first sub-PDU.

[0210] In this case, the second count value corresponding to the mth first sub-PDU can be a global number. Alternatively, the second count value corresponding to the mth first sub-PDU can be the same count value used by all sub-PDUs in the first MAC PDU.

[0211] The first device calculates the second cipher data corresponding to the mth first sub-PDU in a similar manner as the foregoing examples, except that the sixth input parameter can include the second count value corresponding to the first sub-PDU and the LCID corresponding to the first sub-PDU, and thus will not be described in detail.

[0212] In combination with FIG. 12, the process of calculating the second cipher data corresponding to the mth first sub-PDU can be to take the second count value corresponding to the mth first sub-PDU, the LCID corresponding to the mth first sub-PDU, the first transmission direction, and the length of the mth message as the sixth input parameter, to calculate a second keystream based on the MAC confidentiality key (denoted as K MACenc in FIG. 12) and the MAC confidentiality algorithm (denoted as NEA in FIG. 12) on the sixth input parameter, and to calculate the second cipher data corresponding to the mth first sub-PDU by performing XOR operation between the second keystream and the mth message.

[0213] It should be noted that the foregoing is only an exemplary description of calculating the second cipher data corresponding to the mth first sub-PDU, and in actual processing, the manner of calculating the second cipher data corresponding to each first sub-PDU carried by the first MAC PDU that needs to be encrypted and protected is the same as the manner of calculating the second cipher data corresponding to the mth first sub-PDU, and thus will not be described in detail.

[0214] In one case, the first device performs unified integrity protection on all first sub-PDUs carried by the first MAC PDU, and separately encrypts at least one first sub-PDU that needs to be encrypted and protected.

[0215] In this case, the data to be encrypted when calculating the second cipher data corresponding to each first sub-PDU requiring encryption protection can include at least one of the following: the data to be transmitted of each first sub-PDU requiring encryption protection, and the sub-header corresponding to each first sub-PDU requiring encryption protection. Correspondingly, the first MAC PDU can carry the header of the first MAC PDU, the second cipher data corresponding to each first sub-PDU requiring encryption protection, and the first integrity check code; or the first MAC PDU can carry the header of the first MAC PDU, the sub-header corresponding to each first sub-PDU requiring encryption protection, the second cipher data corresponding to each first sub-PDU requiring encryption protection, and the first integrity check code. In addition, the first MAC PDU can also include the sub-header and the data to be transmitted of at least one sub-PDU not requiring encryption. In this case, the first integrity check code is calculated in the same way as in the foregoing embodiments, and thus will not be described again.

[0216] In one case, the first device performs integrity protection on each first sub-PDU requiring integrity protection carried by the first MAC PDU respectively, and performs encryption on each first sub-PDU requiring encryption protection.

[0217] In this case, the data to be encrypted when calculating the second cipher data corresponding to each first sub-PDU requiring encryption protection can include at least one of the following: the data to be transmitted of each first sub-PDU requiring encryption protection, the sub-header corresponding to each first sub-PDU requiring encryption protection, and the second integrity check code corresponding to each first sub-PDU requiring encryption protection.

[0218] For example, the mth first sub-PDU is first subjected to integrity protection and then subjected to encryption protection.

[0219] The data to be encrypted when calculating the second cipher data corresponding to the mth first sub-PDU can include the data to be transmitted of the mth first sub-PDU, the sub-header corresponding to the mth first sub-PDU, and the second integrity check code corresponding to the mth first sub-PDU. The mth first sub-PDU in the first MAC PDU can finally carry the second cipher data corresponding to the mth first sub-PDU.

[0220] Alternatively, the data to be encrypted when calculating the second cipher data corresponding to the mth first sub-PDU can include the data to be transmitted of the mth first sub-PDU and the sub-header corresponding to the mth first sub-PDU. The mth first sub-PDU in the first MAC PDU can finally carry the second cipher data corresponding to the mth first sub-PDU and the second integrity check code corresponding to the mth first sub-PDU.

[0221] Alternatively, the data to be encrypted when calculating the second cipher-text data corresponding to the mth first sub-PDU can include the data to be transmitted of the mth first sub-PDU. The mth first sub-PDU in the first MAC PDU can finally carry the sub-header corresponding to the mth first sub-PDU, the second cipher-text data corresponding to the mth first sub-PDU, and the second integrity check code corresponding to the mth first sub-PDU.

[0222] In some possible embodiments, the first device can be a receiving end of a MAC layer message, and processing of the first device can include: receiving a second MAC PDU from a second device, wherein the second MAC PDU carries at least one second sub-PDU that is securely protected based on the MAC key.

[0223] The secure protection can include integrity protection and / or encryption (confidentiality) protection.

[0224] The second MAC PDU can be any MAC PDU received by the first device from the second device. The second device can perform integrity protection and / or encryption protection on the second MAC PDU in a manner similar to the manner in which the first device performs integrity protection and / or encryption protection on the first MAC PDU, except that the MAC PDU generated and sent by the second device is referred to as the second MAC PDU, and the sub-PDU securely protected by the second MAC PDU is referred to as the second sub-PDU, because the first device and the second device are different execution subjects, and thus no repeated description is provided.

[0225] Because the second device can only perform integrity protection, or can first perform integrity protection and then perform encryption protection, in the secure protection of the at least one second sub-PDU of the second MAC PDU, the first device can only perform integrity check on the second sub-PDU carried by the second MAC PDU, or the first device can first perform decryption and then perform integrity check on the second sub-PDU carried by the second MAC PDU.

[0226] In some embodiments, the second device only performs integrity protection on the second sub-PDU in the second MAC PDU, and accordingly, the first device can only perform integrity check on the second sub-PDU in the second MAC PDU.

[0227] In an embodiment, the second device uniformly performs integrity protection on all second sub-PDUs carried by the second MAC PDU, and accordingly, the first device uniformly performs integrity check on all second sub-PDUs in the second MAC PDU. The at least one second sub-PDU can be all or part of the sub-PDUs carried by the second MAC PDU.

[0228] The second MAC PDU carries a third integrity check code; processing performed by the first device after receiving the second MAC PDU can include: calculating a third integrity verification code based on the MAC integrity key, the MAC integrity algorithm, the third identification information, and at least one of the following: data carried by each of the at least one second sub-PDU, the subheader corresponding to each of the at least one second sub-PDU, and the header of the second MAC PDU; verifying the integrity of the second MAC PDU based on the third integrity verification code and the third integrity check code.

[0229] The timing at which the first device derives the MAC integrity key can be after receiving the second MAC PDU, or can be after receiving the MAC security algorithm, or can be after determining the MAC security algorithm, and the present embodiment does not limit the same.

[0230] The location of the third integrity check code in the second MAC PDU can be in the header of the second MAC PDU, or after the last second sub-PDU of the second MAC PDU, and the present embodiment does not limit or exhaust the same.

[0231] Any one of the second sub-PDUs can be composed of the subheader corresponding to the second sub-PDU (or sub-packet header) and data carried by the second sub-PDU. The data carried by any one of the second sub-PDUs can also be referred to as the payload of the second sub-PDU, and the type thereof can be any one of the following: MAC SDU, MAC CE.

[0232] The third identification information includes a third count value, wherein the third count value is carried by the header of the second MAC PDU. The third count value can be the same count value used by all of the second sub-PDUs in the second MAC PDU.

[0233] The processing performed by the first device to calculate the third integrity verification code can include: using the MAC integrity algorithm, the MAC integrity key, and a seventh input parameter to calculate the third integrity check code. The seventh input parameter can include a message (MESSAGE) and a third count value; the message can include at least one of the following: data carried by each of the second sub-PDUs, the subheader corresponding to each of the second sub-PDUs, and the header of the first MAC PDU.

[0234] Optionally, the third count value included in the seventh input parameter can be filled according to actual needs to obtain a count value of a specified length, and the specified length and the filling manner are the same as those of the foregoing embodiments, and thus will not be described herein.

[0235] Optionally, the seventh input parameter can further include other contents, such as the seventh input parameter can further include a second transmission direction (DIRECTION), which can adopt 1 bit to represent the transmission direction as uplink or downlink. For example, when the first device is a terminal, the second transmission direction can be downlink; when the second device is an access network device, the second transmission direction can be uplink.

[0236] Based on the third integrity verification code and the third integrity check code, verifying the integrity of the second MAC PDU can include at least one of the following: in the case of the third integrity verification code and the third integrity check code being the same, verifying the integrity of the second MAC PDU successfully; in the case of the third integrity verification code and the third integrity check code being different, verifying the integrity of the second MAC PDU fails. Further, in the case of verifying the integrity of the second MAC PDU fails, the first device will discard the second MAC PDU.

[0237] In an embodiment, the second device performs integrity protection on at least one second sub-PDU carried by the second MAC PDU respectively. Each of the at least one second sub-PDU carries a fourth integrity check code corresponding to each second sub-PDU, and the processing of the first device after receiving the second MAC PDU can include: based on the MAC integrity key, the MAC integrity algorithm, the fourth identification information corresponding to each second sub-PDU and at least one of the following: the sub-header corresponding to each second sub-PDU, the data carried by each second sub-PDU, calculating the fourth integrity verification code corresponding to each second sub-PDU; based on the fourth integrity verification code and the fourth integrity check code, verifying the integrity of each second sub-PDU.

[0238] The fourth identification information corresponding to each second sub-PDU includes at least one of the following: the LCID corresponding to each second sub-PDU, and the fourth count value corresponding to each second sub-PDU.

[0239] The LCID corresponding to each second sub-PDU is carried by the sub-header corresponding to each second sub-PDU; and the fourth count value corresponding to each second sub-PDU is carried by the sub-header corresponding to each second sub-PDU or the header of the second MAC PDU.

[0240] For example, the n-th second sub-PDU of any one of the at least one second sub-PDU, the fourth integrity verification code corresponding to the n-th second sub-PDU is calculated based on the MAC integrity key, the MAC integrity algorithm, the fourth identification information corresponding to the n-th second sub-PDU, and at least one of the following: the sub-header corresponding to the n-th second sub-PDU, and the data carried by the n-th second sub-PDU, where n is an integer greater than or equal to 1.

[0241] Based on the fourth integrity verification code and the fourth integrity check code, the integrity of each second sub-PDU is verified, which can include at least one of the following: in the case that the fourth integrity verification code corresponding to the n-th second sub-PDU is the same as the fourth integrity check code corresponding to the n-th second sub-PDU, the integrity of the n-th second sub-PDU is verified successfully; in the case that the fourth integrity verification code corresponding to the n-th second sub-PDU is different from the fourth integrity check code corresponding to the n-th second sub-PDU, the integrity of the n-th second sub-PDU is verified unsuccessfully. Further, in the case that the n-th second MAC sub-unit integrity check fails, the first device can discard the n-th second MAC sub-unit.

[0242] The position of the fourth integrity check code corresponding to the n-th second sub-PDU in the n-th second sub-PDU can be at the end of the n-th second sub-PDU (such as after the data carried by the n-th second sub-PDU), or can be in the header corresponding to the n-th second sub-PDU, and the like. The present embodiment does not limit or exhaust the carrying or assembling position of the fourth integrity check code corresponding to the n-th second sub-PDU.

[0243] The fourth identification information corresponding to the n-th second sub-PDU can be used to uniquely identify the n-th second sub-PDU.

[0244] The related description of the LCID corresponding to the n-th second sub-PDU is similar to the foregoing embodiments, and is not described herein.

[0245] Optionally, the fourth count value corresponding to the n-th second sub-PDU is carried by the sub-header corresponding to the n-th second sub-PDU. In this case, the fourth count value corresponding to the n-th second sub-PDU can be a global number.

[0246] Optionally, the fourth count value corresponding to the n-th second sub-PDU is carried by the header of the second MAC PDU. In this case, all sub-PDUs in the second MAC PDU use the same count value.

[0247] It should be pointed out that the fourth count value can also be referred to as a fourth SN, or a fourth number, or a fourth identification code, and the like. Here, all possible replacement cases are not limited or exhausted.

[0248] In an example, the fourth identification information corresponding to the nth second sub-PDU can only include the LCID corresponding to the nth second sub-PDU.

[0249] The processing that the first device calculates the fourth integrity verification code corresponding to the nth second sub-PDU can include: calculating the fourth integrity verification code corresponding to the nth second sub-PDU by using a MAC integrity algorithm, a MAC integrity key, and an eighth input parameter. The eighth input parameter can include the nth message (MESSAGE) and the LCID corresponding to the nth second sub-PDU. The nth message can include at least one of the data carried by the nth second sub-PDU and the subheader corresponding to the nth second sub-PDU. In addition, the eighth input parameter can also include other contents, such as the second transmission direction.

[0250] In an example, the fourth identification information corresponding to the nth second sub-PDU can only include the fourth count value. In this case, the fourth count value is globally numbered. The processing that the first device calculates the fourth integrity verification code corresponding to the nth second sub-PDU is similar to the foregoing example, and the difference is only that the eighth input parameter can include the fourth count value corresponding to the nth second sub-PDU instead of the LCID, and thus no further description is given. Optionally, the fourth count value included in the eighth input parameter can be filled according to actual requirements to obtain a count value of a specified length.

[0251] In an example, the fourth identification information corresponding to the nth second sub-PDU can include the fourth count value and the LCID. In this case, the fourth count value can be globally numbered, or the fourth count value can be the same count value used by all sub-PDUs in the second MAC PDU. The processing that the first device calculates the fourth integrity verification code corresponding to the nth second sub-PDU is similar to the foregoing example, and the difference is only that the eighth input parameter can include the fourth count value and the LCID corresponding to the nth second sub-PDU, and thus no further description is given.

[0252] It should be noted that the above is only an exemplary description of the calculation of the fourth integrity verification code corresponding to the nth second sub-PDU and the verification of the integrity of the nth second sub-PDU. In actual processing, the way of calculating the fourth integrity verification code corresponding to each second sub-PDU and verifying the integrity of each second sub-PDU is the same as that of the nth second sub-PDU, and thus no further description is given.

[0253] In the embodiment in which the second device only performs integrity protection on the second MAC PDU, in the second MAC PDU, each second sub-PDU of the at least one second sub-PDU carries the data of the second sub-PDU, that is, each second sub-PDU can directly carry the data (or plaintext data) that needs to be carried by the second sub-PDU.

[0254] In some embodiments, the second device can perform confidentiality protection (or encryption protection) on the second MAC PDU after performing integrity protection on the second MAC PDU. Accordingly, the first device needs to first decrypt the confidentiality-protected second sub-PDUs in the second MAC PDU and then perform integrity check.

[0255] In an embodiment, the second device can uniformly perform confidentiality protection (or encryption protection) on each of the second sub-PDUs that need confidentiality protection. In this embodiment, the second MAC PDU carries third cipher data, and the processing performed by the first device after receiving the second MAC PDU further includes: decrypting the third cipher data based on the MAC confidentiality key, the MAC confidentiality algorithm, and the third identification information to obtain at least one of the following: the data carried by each of the confidentiality-protected second sub-PDUs, the sub-header corresponding to each of the confidentiality-protected second sub-PDUs, the third integrity check code, and the fourth integrity check code corresponding to each of the confidentiality-protected second sub-PDUs.

[0256] The timing at which the first device derives the MAC confidentiality key can be after receiving the second MAC PDU, or after receiving the MAC security algorithm, or after determining the MAC security algorithm, which is not limited in this embodiment.

[0257] The confidentiality-protected second sub-PDUs can refer to some or all of the second sub-PDUs carried by the second MAC PDU.

[0258] The decryption processing performed by the first device can include: using the MAC confidentiality algorithm, the MAC confidentiality key, and the ninth input parameter to calculate a third keystream, and performing XOR calculation on the third keystream and the third cipher data to obtain at least one of the following: the data carried by each of the confidentiality-protected second sub-PDUs, the sub-header corresponding to each of the confidentiality-protected second sub-PDUs, the third integrity check code, and the fourth integrity check code corresponding to each of the confidentiality-protected second sub-PDUs.

[0259] The ninth input parameter can include the length of the third cipher data and the third count value. Alternatively, the third count value included in the ninth input parameter can be padded to obtain a count value of a specified length according to actual needs. The specified length and the way of obtaining the count value of the specified length are the same as those in the foregoing embodiments, and are not repeated here. In addition, the ninth input parameter can further include the second transmission direction.

[0260] In one case, the second device performs integrity protection and encryption protection on all the second sub-PDUs carried by the second MAC PDU. In this case, the first device can obtain at least one of the following after decryption: data of each second sub-PDU, a sub-header corresponding to each second sub-PDU, and a third integrity check code corresponding to each second sub-PDU.

[0261] In one case, the second device performs integrity protection on each second sub-PDU carried by the second MAC PDU and performs encryption protection on all the second sub-PDUs carried by the second MAC PDU. The first device can obtain at least one of the following after decryption: data of each second sub-PDU, a sub-header corresponding to each second sub-PDU, and a fourth integrity check code corresponding to each second sub-PDU.

[0262] In one embodiment, the second device can perform confidentiality protection (or encryption protection) on each second sub-PDU that needs confidentiality protection. In this embodiment, each second sub-PDU that is confidentiality protected among the at least one second sub-PDU carries fourth cipher data corresponding to the second sub-PDU that is confidentiality protected. After the first device receives the second MAC PDU, the method further includes: decrypting, based on a MAC confidentiality key, a MAC confidentiality algorithm, and fourth identification information corresponding to each second sub-PDU that is confidentiality protected, the fourth cipher data corresponding to each second sub-PDU that is confidentiality protected, to obtain at least one of the following: data carried by each second sub-PDU that is confidentiality protected, a sub-header corresponding to each second sub-PDU that is confidentiality protected, and a fourth integrity check code corresponding to each second sub-PDU that is confidentiality protected.

[0263] In this embodiment, each second sub-PDU that is confidentiality protected refers to part or all of all second sub-PDUs that are integrity protected in the second MAC PDU.

[0264] Taking the second sub-PDU that is encrypted protected among the at least one second sub-PDU as the nth second sub-PDU as an example, the processing of the first device after decryption can include: decrypting, based on a MAC confidentiality key, a MAC confidentiality algorithm, and fourth identification information corresponding to the nth second sub-PDU, fourth cipher data corresponding to the nth second sub-PDU, to obtain at least one of the following: data carried by the nth second sub-PDU, a sub-header corresponding to the nth second sub-PDU, and a fourth integrity check code corresponding to the nth second sub-PDU.

[0265] In one example, the fourth identification information corresponding to the nth second sub-PDU can only include an LCID.

[0266] The processing of the first device decrypting can include: using the MAC confidentiality algorithm, the MAC confidentiality key and the tenth input parameter, calculating a fourth key stream, performing XOR calculation on the fourth key stream and the fourth ciphertext data corresponding to the nth second sub-PDU, and obtaining at least one of the following: data carried by the nth second sub-PDU, a subheader corresponding to the nth second sub-PDU, and a fourth integrity verification code corresponding to the nth second sub-PDU. The tenth input parameter can include the length of the fourth ciphertext data corresponding to the nth second sub-PDU and the LCID corresponding to the nth second sub-PDU. In addition, the tenth input parameter can further include the second transmission direction.

[0267] In an example, the fourth identification information corresponding to the nth second sub-PDU includes only the fourth count value. In this case, the second count value is globally numbered. The processing of the first device decrypting is similar to the foregoing example, and the difference is that in the present example, the tenth input parameter can include the fourth count value corresponding to the nth second sub-PDU but does not include the LCID corresponding to the nth second sub-PDU, and thus no repeated description is made.

[0268] In an example, the fourth identification information corresponding to the nth second sub-PDU includes the fourth count value and the LCID. The processing of the first device decrypting is similar to the foregoing example, and the difference is that in the present example, the tenth input parameter can include the fourth count value and the LCID corresponding to the nth second sub-PDU, and thus no repeated description is made.

[0269] It should be noted that the above is only an exemplary description of the decryption processing of the fourth ciphertext data corresponding to the nth second sub-PDU, and in actual processing, the manner of the fourth ciphertext data corresponding to each second sub-PDU carried by the second MAC PDU is the same as that of the nth second sub-PDU, and thus no detailed description is made.

[0270] In a case, the second device performs unified integrity protection on all second sub-PDUs carried by the second MAC PDU and respectively encrypts at least one second sub-PDU that needs to be encrypted.

[0271] In this case, the first device can obtain at least one of the following after decryption: data carried by each second sub-PDU that is encrypted, and a subheader corresponding to each second sub-PDU that is encrypted. Further, the first device can perform integrity verification based on the third integrity verification code carried by the second MAC PDU after completing decryption, which is not repeated here.

[0272] In a case, the second device respectively performs integrity protection on each second sub-PDU that needs integrity protection and respectively encrypts each second sub-PDU that needs encryption.

[0273] In this case, the first device can obtain at least one of the following after decryption: the data carried by each of the second sub-PDUs that are encrypted, the sub-header corresponding to each of the second sub-PDUs that are encrypted, and the fourth integrity verification code corresponding to each of the second sub-PDUs that are encrypted. Further, the first device can perform integrity verification based on the fourth integrity verification code corresponding to each of the second sub-PDUs carried by the second MAC PDU after completing decryption, which will not be repeated here.

[0274] By using the above scheme, a MAC key can be generated by a device in a communication network, so that the MAC key can be used to securely protect or verify a MAC layer message received or transmitted by the device, thereby making up for the lack of a MAC layer security mechanism and ensuring the security of a MAC layer message. Further, the above scheme can enhance the existing AS security mode negotiation, and can implement negotiation of a MAC security algorithm in a device in a communication network, thereby making up for the lack of a MAC layer security negotiation mechanism.

[0275] FIG. 13 is a schematic diagram of a constituent structure of a first device according to an embodiment of the present application, including:

[0276] The first processing unit 1301 is configured to generate at least one MAC key based on at least one security key.

[0277] The at least one MAC key includes at least one of a MAC integrity key and a MAC confidentiality key.

[0278] The first processing unit is configured to perform at least one of the following: derive the MAC integrity key based on a first security key and a first input parameter, wherein the first security key is one of the at least one security key, and the first input parameter includes at least one of an identifier of a MAC integrity algorithm and a type of the MAC integrity algorithm; and derive the MAC confidentiality key based on a second security key and a second input parameter, wherein the second security key is one of the at least one security key, and the second input parameter includes at least one of an identifier of a MAC confidentiality algorithm and a type of the MAC confidentiality algorithm.

[0279] The at least one security key includes at least one of a K gNB AS distributed unit (DU) key, an AS control plane key, and an AS user plane key, wherein the AS control plane key includes at least one of an AS control plane integrity key and an AS control plane confidentiality key, the AS user plane key includes at least one of an AS user plane integrity key and an AS user plane confidentiality key, and the AS DU key includes at least one of an AS DU integrity key and an AS DU confidentiality key.

[0280] The first processing unit is configured to update at least one MAC key when a first condition is met, wherein the first condition comprises at least one of the following: system information update, RRC state change, cell change, and a number of MAC layer integrity verification failures reaching a preset number.

[0281] As shown in FIG. 13, the first device further includes a first communication unit 1302 configured to send a first MAC protocol data unit (PDU) to the second device, wherein the first MAC PDU carries at least one first sub-PDU which is securely protected based on the MAC key.

[0282] The first MAC PDU carries a first integrity check code, wherein the first integrity check code is calculated based on a MAC integrity key, a MAC integrity algorithm, first identification information, and at least one of the following: data to be transmitted in each of the at least one first sub-PDU, a subheader corresponding to each of the at least one first sub-PDU, and a header of the first MAC PDU.

[0283] Each of the at least one first sub-PDU carries a second integrity check code corresponding to the each of the at least one first sub-PDU, wherein the second integrity check code corresponding to the each of the at least one first sub-PDU is calculated based on a MAC integrity key, a MAC integrity algorithm, second identification information corresponding to the each of the at least one first sub-PDU, and at least one of the following: a subheader corresponding to the each of the at least one first sub-PDU, and data to be transmitted in the each of the at least one first sub-PDU.

[0284] The first MAC PDU carries first cipher data, wherein the first cipher data is encrypted based on a MAC confidentiality key, a MAC confidentiality algorithm, and first identification information, and at least one of the following: data to be transmitted in each of the at least one first sub-PDU which needs confidentiality protection, a subheader corresponding to the each of the at least one first sub-PDU which needs confidentiality protection, a second integrity check code corresponding to the each of the at least one first sub-PDU which needs confidentiality protection, and the first integrity check code.

[0285] Each of the at least one first sub-PDU requiring confidentiality protection carries second ciphertext data corresponding to the each of the first sub-PDU requiring confidentiality protection, wherein the second ciphertext data corresponding to the each of the first sub-PDU requiring confidentiality protection is encrypted based on a MAC confidentiality key, a MAC confidentiality algorithm, second identification information corresponding to the each of the first sub-PDU requiring confidentiality protection, at least one of the following: data of the each of the first sub-PDU requiring confidentiality protection, a sub-header corresponding to the each of the first sub-PDU requiring confidentiality protection, a second integrity check code corresponding to the each of the first sub-PDU requiring confidentiality protection.

[0286] The first identification information comprises a first count value, wherein the first count value is carried by a header of the first MAC PDU.

[0287] The second identification information corresponding to the each of the first sub-PDU comprises at least one of the following: a logical channel identifier LCID corresponding to the each of the first sub-PDU, a second count value corresponding to the each of the first sub-PDU.

[0288] The LCID corresponding to the each of the first sub-PDU is carried by a sub-header corresponding to the each of the first sub-PDU; and the second count value corresponding to the each of the first sub-PDU is carried by the sub-header corresponding to the each of the first sub-PDU or the header of the first MAC PDU.

[0289] The first communication unit is configured to receive a second MAC PDU from a second device, wherein the second MAC PDU carries at least one second sub-PDU which is securely protected based on the MAC key.

[0290] The second MAC PDU carries third ciphertext data, and the first processing unit is configured to decrypt the third ciphertext data based on a MAC confidentiality key, a MAC confidentiality algorithm, and third identification information, to obtain at least one of the following: data carried by each of the at least one second sub-PDU requiring confidentiality protection, a sub-header corresponding to the each of the second sub-PDU requiring confidentiality protection, a third integrity check code, and a fourth integrity check code corresponding to the each of the second sub-PDU requiring confidentiality protection.

[0291] Each of the at least one second sub-PDU carrying the confidentiality protection carries corresponding fourth cipher-text data, and the first processing unit is configured to decrypt the corresponding fourth cipher-text data of each of the at least one second sub-PDU based on the MAC confidentiality key, the MAC confidentiality algorithm, and corresponding fourth identification information of each of the at least one second sub-PDU, to obtain at least one of the following: data carried by each of the at least one second sub-PDU carrying the confidentiality protection, a sub-header corresponding to each of the at least one second sub-PDU carrying the confidentiality protection, and a fourth integrity check code corresponding to each of the at least one second sub-PDU carrying the confidentiality protection.

[0292] The second MAC PDU carries a third integrity check code, and the first processing unit is configured to calculate a third integrity verification code based on the MAC integrity key, the MAC integrity algorithm, the third identification information, and at least one of the following: data carried by each of the at least one second sub-PDU, a sub-header corresponding to each of the at least one second sub-PDU, and a header of the second MAC PDU, and verify integrity of the second MAC PDU based on the third integrity verification code and the third integrity check code.

[0293] Each of the at least one second sub-PDU carrying the confidentiality protection carries corresponding fourth integrity check code, and the first processing unit is configured to calculate a fourth integrity verification code corresponding to each of the at least one second sub-PDU based on the MAC integrity key, the MAC integrity algorithm, and corresponding fourth identification information of each of the at least one second sub-PDU, and verify integrity of each of the at least one second sub-PDU based on the fourth integrity verification code and the corresponding fourth integrity check code.

[0294] The third identification information includes a third count value, and the third count value is carried by the header of the second MAC PDU.

[0295] The corresponding fourth identification information of each of the at least one second sub-PDU includes at least one of the following: a LCID corresponding to each of the at least one second sub-PDU, and a fourth count value corresponding to each of the at least one second sub-PDU.

[0296] The LCID corresponding to each of the at least one second sub-PDU is carried by a sub-header corresponding to each of the at least one second sub-PDU, and the fourth count value corresponding to each of the at least one second sub-PDU is carried by the sub-header corresponding to each of the at least one second sub-PDU or the header of the second MAC PDU.

[0297] The first communication unit is configured to receive first algorithm indication information from the second device, wherein the first algorithm indication information is used by the first device to determine the MAC security algorithm.

[0298] The first communication unit is configured to send second algorithm indication information to the second device, wherein the second algorithm indication information is used by the second device to determine the MAC security algorithm.

[0299] The MAC security algorithm comprises at least one of the following: a MAC integrity algorithm, a MAC confidentiality algorithm.

[0300] The first device is a terminal. The second device is an access network device. The first device is an access network device. The second device is a terminal.

[0301] The device of the embodiments of the present application can realize the corresponding functions of each device in the key generation method embodiments. The processes, functions, implementation manners and advantages of each module (submodule, unit or component, etc.) in the device can be referred to the corresponding description in the method embodiments, which will not be described here. It should be noted that the functions described with respect to each module (submodule, unit or component, etc.) in the device of the embodiments of the present application can be realized by different modules (submodules, units or components, etc.), or by the same module (submodule, unit or component, etc.).

[0302] It should be understood that the size of the serial number of each process in various embodiments of the present application does not mean the order of execution. The execution order of each process should be determined according to its function and inherent logic. Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here. The above is only a specific implementation of the present application, and the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A key generation method performed by a first device, comprising: generating at least one media access control (MAC) key based on at least one security key.

2. The method of claim 1, wherein, The at least one MAC key comprises at least one of: a MAC integrity key, a MAC confidentiality key.

3. The method of claim 2, wherein, The generating the at least one MAC key based on the at least one security key comprises at least one of: deriving the MAC integrity key based on a first security key and a first input parameter, wherein the first security key is one of the at least one security key, and the first input parameter comprises at least one of: an identity of a MAC integrity algorithm, a type of the MAC integrity algorithm; deriving the MAC confidentiality key based on a second security key and a second input parameter, wherein the second security key is one of the at least one security key, and the second input parameter comprises at least one of: an identity of a MAC confidentiality algorithm, a type of the MAC confidentiality algorithm.

4. The method according to any one of claims 1 to 3, wherein, The at least one security key comprises at least one of: K gNB , an AS distributed unit (DU) key, an AS control plane key, an AS user plane key, wherein the AS control plane key comprises at least one of: an AS control plane integrity key, an AS control plane confidentiality key, the AS user plane key comprises at least one of: an AS user plane integrity key, an AS user plane confidentiality key, and the AS DU key comprises at least one of: an AS DU integrity key, an AS DU confidentiality key. 5.The method of any one of claims 1-4, further comprising: updating the at least one MAC key in a case that a first condition is met, wherein the first condition comprises at least one of: a system information update, a RRC state change, a cell change, a number of MAC layer integrity verification failures reaching a preset number. 6.The method of any one of claims 1-5, further comprising: sending a first MAC protocol data unit (PDU) to a second device, wherein the first MAC PDU carries at least one first sub-PDU which is securely protected based on the MAC key.

7. The method of claim 6, wherein, The first MAC PDU carries a first integrity check code, wherein the first integrity check code is calculated based on the MAC integrity key, a MAC integrity algorithm, first identification information, and at least one of: data to be transmitted in each of the at least one first sub-PDU, a sub-header corresponding to each of the at least one first sub-PDU, a header of the first MAC PDU.

8. The method of claim 6, wherein, Each of the at least one first sub-PDU carries a second integrity check code corresponding to each of the at least one first sub-PDU, wherein the second integrity check code corresponding to each of the at least one first sub-PDU is calculated based on the MAC integrity key, a MAC integrity algorithm, second identification information corresponding to each of the at least one first sub-PDU, and at least one of: a sub-header corresponding to each of the at least one first sub-PDU, data to be transmitted in each of the at least one first sub-PDU.

9. The method according to any one of claims 6-8, wherein, The first MAC PDU carries first cipher data, wherein the first cipher data is encrypted based on the MAC confidentiality key, a MAC confidentiality algorithm, first identification information, and at least one of: data to be transmitted in each of the at least one first sub-PDU which needs confidentiality protection, a sub-header corresponding to each of the at least one first sub-PDU which needs confidentiality protection, a second integrity check code corresponding to each of the at least one first sub-PDU which needs confidentiality protection, the first integrity check code.

10. The method according to any one of claims 6-8, wherein, Each of the at least one first sub-PDU requiring confidentiality protection carries second cipher-text data corresponding to the each of the first sub-PDU requiring confidentiality protection, wherein the second cipher-text data corresponding to the each of the first sub-PDU requiring confidentiality protection is encrypted based on a MAC confidentiality key, a MAC confidentiality algorithm, and second identification information corresponding to the each of the first sub-PDU requiring confidentiality protection, at least one of the following: data of the each of the first sub-PDU requiring confidentiality protection, a sub-header corresponding to the each of the first sub-PDU requiring confidentiality protection, and a second integrity check code corresponding to the each of the first sub-PDU requiring confidentiality protection.

11. The method of claim 7 or 9, wherein, The first identification information comprises a first count value, wherein the first count value is carried by a header of the first MAC PDU.

12. The method of claim 8 or 10, wherein, The second identification information corresponding to the each of the first sub-PDU comprises at least one of the following: a logical channel identifier LCID corresponding to the each of the first sub-PDU, and a second count value corresponding to the each of the first sub-PDU.

13. The method of claim 12, wherein, The LCID corresponding to the each of the first sub-PDU is carried by a sub-header corresponding to the each of the first sub-PDU, and the second count value corresponding to the each of the first sub-PDU is carried by the sub-header corresponding to the each of the first sub-PDU or the header of the first MAC PDU.

14. The method of any of claims 1-13, further comprising: receiving a second MAC PDU from a second device, wherein the second MAC PDU carries at least one second sub-PDU that is securely protected based on the MAC key.

15. The method of claim 14, wherein, The second MAC PDU carries third cipher-text data, and the method further comprises: decrypting the third cipher-text data based on a MAC confidentiality key, a MAC confidentiality algorithm, and third identification information, to obtain at least one of the following: data carried by each of the at least one second sub-PDU requiring confidentiality protection, a sub-header corresponding to each of the at least one second sub-PDU requiring confidentiality protection, a third integrity check code, and a fourth integrity check code corresponding to each of the at least one second sub-PDU requiring confidentiality protection.

16. The method of claim 14, wherein, Each of the at least one second sub-PDU requiring confidentiality protection carries fourth cipher-text data corresponding to the each of the second sub-PDU requiring confidentiality protection, and the method further comprises: decrypting the fourth cipher-text data corresponding to the each of the second sub-PDU requiring confidentiality protection based on a MAC confidentiality key, a MAC confidentiality algorithm, and fourth identification information corresponding to the each of the second sub-PDU requiring confidentiality protection, to obtain at least one of the following: data carried by the each of the second sub-PDU requiring confidentiality protection, a sub-header corresponding to the each of the second sub-PDU requiring confidentiality protection, and a fourth integrity check code corresponding to the each of the second sub-PDU requiring confidentiality protection.

17. The method of any one of claims 14-16, wherein, The second MAC PDU carries a third integrity check code, and the method further comprises: a third integrity verification code is calculated based on the MAC integrity key, a MAC integrity algorithm, third identification information, and at least one of the following: data carried by each of the at least one second sub-PDU, a subheader corresponding to the each of the at least one second sub-PDU, and a header of the second MAC PDU; the integrity of the second MAC PDU is verified based on the third integrity verification code and the third integrity check code.

18. The method of any one of claims 14-16, wherein, each of the at least one second sub-PDU carries a fourth integrity check code corresponding to the each of the at least one second sub-PDU, and the method further comprises: a fourth integrity verification code corresponding to the each of the at least one second sub-PDU is calculated based on the MAC integrity key, a MAC integrity algorithm, fourth identification information corresponding to the each of the at least one second sub-PDU, and at least one of the following: a subheader corresponding to the each of the at least one second sub-PDU, and data carried by the each of the at least one second sub-PDU; the integrity of the each of the at least one second sub-PDU is verified based on the fourth integrity verification code and the fourth integrity check code.

19. The method of claim 15 or 17, wherein, the third identification information comprises a third count value, wherein the third count value is carried by the header of the second MAC PDU.

20. The method of claim 16 or 18, wherein, the fourth identification information corresponding to the each of the at least one second sub-PDU comprises at least one of the following: an LCID corresponding to the each of the at least one second sub-PDU, and a fourth count value corresponding to the each of the at least one second sub-PDU.

21. The method of claim 20, wherein, the LCID corresponding to the each of the at least one second sub-PDU is carried by a subheader corresponding to the each of the at least one second sub-PDU; and the fourth count value corresponding to the each of the at least one second sub-PDU is carried by the subheader corresponding to the each of the at least one second sub-PDU, or the header of the second MAC PDU.

22. The method of any of claims 1-21, further comprising: receiving first algorithm indication information from the second device, wherein the first algorithm indication information is used by the first device to determine a MAC security algorithm.

23. The method of any of claims 1-21, further comprising: sending second algorithm indication information to the second device, wherein the second algorithm indication information is used by the second device to determine a MAC security algorithm.

24. The method of claim 22 or 23, wherein, the MAC security algorithm comprises at least one of the following: a MAC integrity algorithm, and a MAC confidentiality algorithm.

25. The method of any one of claims 1-22, wherein, the first device is a terminal.

26. The method of any one of claims 6-22, 25, wherein, the second device is an access network device.

27. The method of any one of claims 1-21, 23, wherein, the first device is an access network device.

28. The method of any one of claims 6-21, 23, 27, wherein, the second device is a terminal.

29. A first device, comprising: a first processing unit configured to generate at least one media access control (MAC) key based on at least one security key.

Citation Information

Patent Citations

  • Medium access control security

    CN113273236A

  • PSK (Pre-shared Key) updating method and device

    CN113972998A

  • Wireless network access method and device, equipment and storage medium

    CN115550921A

  • Secured account provisioning and payments for NFC-enabled devices

    US20190147440A1