Transmission method, communication device, communication system, and storage medium
By introducing protection parameters into the MAC PDU to encrypt and protect the integrity of the MAC CE, the security risks caused by the lack of protection of the MAC CE are resolved, the security and reliability of the MAC CE are improved, and the normal operation of terminal services and data security are ensured.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- BEIJING XIAOMI MOBILE SOFTWARE CO LTD
- Filing Date
- 2024-10-29
- Publication Date
- 2026-05-07
AI Technical Summary
In existing technologies, MAC CE does not provide encryption and integrity protection, which poses security risks and may lead to abnormal terminal operations or leakage of private data.
Introducing protection parameters, including counter values and protection tags, into the MAC PDU provides encryption and integrity protection for the MAC CE, ensuring the security and reliability of the MAC CE.
It improves the security and reliability of MAC CE, prevents tampering and attacks, and ensures the normal operation of terminal services and the security of private data.
Smart Images

Figure CN2024128302_07052026_PF_FP_ABST
Abstract
Description
Transmission methods, communication equipment, communication systems and storage media Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to a transmission method, communication device, communication system and storage medium. Background Technology
[0002] The relevant protocols propose to encrypt and protect the integrity of Radio Resource Control (RRC) messages in order to prevent the content transmitted through RRC messages from being attacked.
[0003] Summary of the Invention
[0004] This disclosure provides a transmission method, communication device, communication system, and storage medium.
[0005] A first aspect of this disclosure provides a transmission method, which is executed by a communication device, and the method includes:
[0006] Sending or receiving a Media Access Control (MAC) Protocol Data Unit (PDU) containing protection parameters, wherein the protection parameters are obtained by protecting the MAC CE in the MAC PDU, and the protection parameters are one or more of the following: a count value, a protection tag.
[0007] A second aspect of this disclosure provides a communication device, which includes:
[0008] A transceiver module is used to send or receive a Media Access Control (MAC) Packet Data Unit (PDU) containing protection parameters, wherein the protection parameters are obtained after protecting the MAC CE in the MAC PDU, and the protection parameters are one or more of the following: a count value, a protection tag.
[0009] A third aspect of this disclosure provides a communication device, which includes one or more processors;
[0010] The processor is used to execute the method described in the first aspect above.
[0011] A communication system, including communication equipment, for performing the method as described in the first aspect above.
[0012] A fourth aspect of this disclosure provides a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in the first aspect above.
[0013] A sixth aspect of this disclosure provides a computer program product including a computer program that, when executed by a processor, implements the method described in the first aspect above.
[0014] The scheme proposed in this disclosure involves a communication device sending or receiving a Media Access Control (MAC) Protocol Data Unit (PDU) containing protection parameters. These protection parameters are obtained by protecting the MAC CE (MAC Component Exchange) within the MAC PDU, and may include one or more of the following: a counter value, a protection tag. This approach mitigates the problem of MAC CE tampering or attack to a certain extent, improving the security and reliability of the MAC CE and providing conditions for enhancing the performance of the communication system. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in the embodiments or background art of this disclosure, the accompanying drawings used in the embodiments or background art of this disclosure will be described below.
[0016] Figure 1 is a schematic diagram of the architecture of a communication system provided in an embodiment of this disclosure;
[0017] Figure 2A is an interactive schematic diagram of a transmission method provided in an embodiment of this disclosure;
[0018] Figures 2B-2N are schematic diagrams of the MAC PDU structure provided in the embodiments of this disclosure;
[0019] [Correction 15.11.2024 according to Rule 91] Figure 3A is an interactive schematic diagram of a transmission method provided by an embodiment of this disclosure;
[0020] [Correction 15.11.2024 according to Rule 91] Figure 3B is a schematic diagram of the structure of a communication device provided in an embodiment of this disclosure;
[0021] Figure 4A is a schematic diagram of the structure of a communication device provided in an embodiment of this disclosure;
[0022] Figure 4B is a schematic diagram of the structure of a chip provided in an embodiment of this disclosure. Detailed Implementation
[0023] This disclosure presents a transmission method, a communication device, a communication system, and a storage medium.
[0024] In a first aspect, embodiments of this disclosure propose a transmission method, the method comprising: sending or receiving a Media Access Control (MAC) Protocol Data Unit (PDU) containing protection parameters, wherein the protection parameters are obtained by performing protection processing on the MAC CE in the MAC PDU, and the protection parameters are one or more of the following: a count value, a protection tag.
[0025] In the above embodiments, the communication device sends or receives a Media Access Control (MAC) Protocol Data Unit (PDU) containing protection parameters. These protection parameters are obtained by protecting the MAC CE (MAC Component Exchange) within the MAC PDU, and may include one or more of the following: a counter value, a protection tag. This, to a certain extent, avoids the problem of MAC CE being tampered with or attacked, improves the security and reliability of the MAC CE, and provides conditions for improving the performance of the communication system.
[0026] In conjunction with some embodiments of the first aspect, in some embodiments, the above-described protection processing of the MAC CE in the MAC PDU includes one or more of the following:
[0027] Encrypt and protect the MAC CE in the MAC PDU;
[0028] Perform integrity protection processing on the MAC CE in the MAC PDU.
[0029] In the above embodiments, the communication device can perform encryption protection and / or integrity protection on the MAC PDU, thereby ensuring the privacy and / or integrity of the MAC PDU and further improving the security and reliability of MAC layer transmission.
[0030] In conjunction with some embodiments of the first aspect, in some embodiments, the above-mentioned protection parameters are located after all MAC sub-PDUs in the MAC PDU.
[0031] In conjunction with some embodiments of the first aspect, in some embodiments, the above-mentioned protection parameters are located before all MAC sub-PDUs in the MAC PDU.
[0032] In the above embodiments, the communication device can place the protection parameters before or after the MAC PDU, thereby ensuring that both parties transmitting the MAC PDU have a consistent understanding of the location of the protection parameters, and improving the efficiency and accuracy of the receiver in parsing the MAC PDU.
[0033] In conjunction with some embodiments of the first aspect, in some embodiments, for the uplink MAC CE, the protection parameter is located before the MAC sub-PDU containing the padding information in the MAC PDU.
[0034] In the above embodiments, the terminal can place the protection parameters before the MAC subPDU containing padding in the uplink MAC PDU, thereby ensuring that the network device's understanding of the location of the protection parameters in the uplink MAC PDU is consistent with that of the terminal, providing conditions and basis for improving the network device's parsing efficiency and speed of the uplink MAC PDU.
[0035] In conjunction with some embodiments of the first aspect, in some embodiments, for a downlink MAC CE, the protection parameter is located before all MAC sub-PDUs containing MAC SDUs in the MAC PDU.
[0036] In the above embodiments, the network can place the protection parameters before all MAC subPDUs containing MAC SDUs in the downlink MAC PDU, thereby ensuring that the terminal's understanding of the location of the protection parameters in the downlink MAC PDU is consistent with that of the network device, providing conditions and basis for improving the terminal's parsing efficiency and speed of the downlink MAC PDU.
[0037] In conjunction with some embodiments of the first aspect, in some embodiments, the aforementioned protection parameters are not carried by the MAC CE, and each MAC CE in the MAC PDU contains indication information for indicating whether the MAC CE is the last MAC CE.
[0038] In the above embodiments, when the protection parameters are not carried by the MAC CE, by including an indication message in each MAC indicating whether it is the last MAC CE, the receiving party of the MAC PDU is provided with the means to obtain the protection parameters more accurately and quickly.
[0039] In conjunction with some embodiments of the first aspect, in some embodiments, all the first MAC CEs that need to be protected in the above-mentioned MAC PDU are adjacent, and the protection parameters are located before or after all the first MAC CEs.
[0040] In the above embodiments, by placing all the first MAC CEs that need protection together and placing the protection parameters adjacent to these MAC CEs, conditions are provided for the receiving end to obtain the information carried by the first MAC CEs more quickly and accurately.
[0041] In conjunction with some embodiments of the first aspect, in some embodiments, the sub-headers of all second MAC CEs in the above-mentioned MAC PDU are adjacent, the packet bodies of all second MAC CEs are adjacent, and the position of the protection parameter satisfies any one of the following:
[0042] Located between the headers of all second MAC CEs and the bodies of all second MAC CEs;
[0043] Located after the body of all second MAC CEs;
[0044] Located before the sub-packet header of all second MAC CEs;
[0045] The protection parameters are located before the sub-packet headers of all second MAC CEs and after the MAC sub-PDUs containing padding information.
[0046] In the above embodiments, by placing all the second MAC CE headers and bodies together and associating the protection parameters with the headers or bodies of the second MAC CEs, conditions are provided for the receiving end to obtain the information carried by the second MAC CEs more quickly and accurately.
[0047] In conjunction with some embodiments of the first aspect, in some embodiments, the aforementioned second MAC CE is a MAC CE that requires protection processing.
[0048] In conjunction with some embodiments of the first aspect, in some embodiments, the aforementioned protection parameters are located in a MAC sub-header of the MAC PDU, and a MAG sub-header is located before the MAC CE in the MAC PDU that needs to be protected.
[0049] In the above embodiments, by placing the protection parameters in a specific sub-packet header of the MAC PDU, the efficiency and speed at which the receiver obtains the protection parameters are further improved.
[0050] In conjunction with some embodiments of the first aspect, in some embodiments, the above-mentioned protection parameters further include one or more of the following:
[0051] Length, wherein the length is used to indicate the total length of the MAC CE that needs to be protected;
[0052] The logical channel identifier (LCID) corresponding to a MAC sub-packet header.
[0053] In the above embodiments, the protection parameters also include length and / or LCID, thereby providing conditions for further improving the speed and accuracy of the receiver in determining the protection parameters and / or obtaining the information carried by the MAC CE.
[0054] Secondly, embodiments of this disclosure provide a communication device, the communication device comprising:
[0055] A transceiver module is used to send or receive a Media Access Control (MAC) Packet Data Unit (PDU) containing protection parameters, wherein the protection parameters are obtained after protecting the MAC CE in the MAC PDU, and the protection parameters are one or more of the following: a count value, a protection tag.
[0056] In conjunction with some embodiments of the second aspect, in some embodiments, the communication device further includes a processing module for performing one or more of the following: performing encryption protection processing on the MAC CE in the MAC PDU;
[0057] Integrity protection processing is performed on the MAC CE in the MAC PDU.
[0058] In conjunction with some embodiments of the second aspect, in some embodiments, the above-mentioned protection parameters are located after all MAC sub-PDUs in the MAC PDU.
[0059] In conjunction with some embodiments of the second aspect, in some embodiments, the above-mentioned protection parameters are located before all MAC sub-PDUs in the MAC PDU.
[0060] In conjunction with some embodiments of the second aspect, in some embodiments, for an uplink MAC CE, the protection parameter is located before the MAC sub-PDU containing the padding information in the MAC PDU.
[0061] In conjunction with some embodiments of the second aspect, in some embodiments, for a downlink MAC CE, the protection parameter is located before all MAC sub-PDUs containing MAC SDUs in the MAC PDU.
[0062] In conjunction with some embodiments of the second aspect, in some embodiments, the aforementioned protection parameters are not carried by the MAC CE, and each MAC CE in the MAC PDU contains indication information for indicating whether the MAC CE is the last MAC CE.
[0063] In conjunction with some embodiments of the second aspect, in some embodiments, all the first MAC CEs that require protection processing in the above-mentioned MAC PDU are adjacent, and the protection parameter is located before or after all the first MAC CEs.
[0064] In conjunction with some embodiments of the second aspect, in some embodiments, the sub-headers of all second MAC CEs in the above-mentioned MAC PDU are adjacent, the bodies of all second MAC CEs are adjacent, and the position of the protection parameter satisfies any one of the following:
[0065] Located between the headers of all second MAC CEs and the bodies of all second MAC CEs;
[0066] Located after the body of all second MAC CEs;
[0067] Located before the sub-packet headers of all second MAC CEs;
[0068] The protection parameters are located before the sub-packet headers of all second MAC CEs and after the MAC sub-PDUs containing padding information.
[0069] In conjunction with some embodiments of the second aspect, in some embodiments, the aforementioned second MAC CE is a MAC CE that requires protection processing.
[0070] In conjunction with some embodiments of the second aspect, in some embodiments, the aforementioned protection parameters are located in a MAC sub-header of the MAC PDU, and the MAG sub-header is located before the MAC CE in the MAC PDU that needs to be protected.
[0071] In conjunction with some embodiments of the second aspect, in some embodiments, the above-mentioned protection parameters further include one or more of the following:
[0072] Length, wherein the length is used to indicate the total length of the MAC CE that needs to be protected;
[0073] The logical channel identifier (LCID) corresponding to a MAC sub-packet header.
[0074] Thirdly, embodiments of this disclosure provide a communication device, which includes one or more processors; wherein the communication device is used to execute the first aspect and optional implementations of the first aspect.
[0075] Fourthly, embodiments of this disclosure provide a communication system comprising: a terminal and a network device; wherein the terminal and the network device are configured to perform the methods described in the first aspect and optional implementations thereof.
[0076] Fifthly, embodiments of this disclosure provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the method described in the first aspect and its optional implementations.
[0077] In a sixth aspect, embodiments of this disclosure provide a program product that, when executed by a communication device, causes the communication device to perform the method as described in the first aspect and its optional implementations.
[0078] In a seventh aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the methods described in the first aspect and optional implementations of the first aspect.
[0079] Eighthly, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the methods described according to the first aspect and optional implementations thereof.
[0080] It is understood that the aforementioned terminals, network devices, access network devices, core network devices, communication devices, communication systems, storage media, program products, computer programs, chips, or chip systems are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.
[0081] This disclosure provides a transmission method, a communication device, a communication system, and a storage medium. In some embodiments, the terms "transmission method" and "information processing method," "communication method," etc., can be used interchangeably; the terms "message transmission device" and "information processing device," "communication device," etc., can be used interchangeably; and the terms "message transmission system" and "information processing system," "communication system," etc., can be used interchangeably.
[0082] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.
[0083] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0084] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.
[0085] In this disclosure, unless otherwise stated, elements expressed in the singular form, such as "a," "an," "the," "the," "the aforementioned," "the," "this," etc., can mean "one and only one," or "one or more," "at least one," etc. For example, when using articles such as "a," "an," "the," etc. in translation, the noun following the article can be understood as either a singular or a plural expression.
[0086] In the embodiments disclosed herein, "multiple" refers to two or more.
[0087] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.
[0088] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of B); in some embodiments, B (execute B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.
[0089] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.
[0090] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.
[0091] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.
[0092] In some embodiments, the terms “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “if…”, “if…”, etc., can be used interchangeably.
[0093] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.
[0094] In some embodiments, the apparatus and device may be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. In some cases, they may also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "body", etc.
[0095] In some embodiments, "network" can be interpreted as devices included in the network, such as access network devices, core network devices, etc.
[0096] In some embodiments, "access network device (AN device)" may also be referred to as "radio access network device (RAN device)," "base station (BS)," "radio base station," or "fixed station." In some embodiments, it may also be understood as "node," "access point," "transmission point (TP)," "reception point (RP)," "transmission / reception point (TRP)," "panel," "antenna panel," "antenna array," "cell," "macro cell," "small cell," "femto cell," "pico cell," "sector," "cell group," "serving cell," "carrier," "component carrier," or "bandwidth part (BWP)."
[0097] In some embodiments, "terminal" or "terminal device" may be referred to as "user equipment (UE)," "user terminal," "Narrow Band-Internet of Things (NB-IoT) device," "mobile station (MS)," "mobile terminal (MT)," "subscriber station," "mobile unit," "subscriber unit," "wireless unit," "remote unit," "mobile device," "wireless device," "wireless communication device," "remote device," "mobile subscriber station," "access terminal," "mobile terminal," "wireless terminal," "remote terminal," "handset," "user agent," "mobile client," "client," etc.
[0098] In some embodiments, access network devices, core network devices, or network devices can be replaced by terminals. For example, embodiments of this disclosure can also be applied to structures where communication between access network devices, core network devices, or network devices and terminals is replaced by communication between multiple terminals (e.g., device-to-device (D2D), vehicle-to-everything (V2X), etc.). In this case, the structure can also be configured such that the terminal has all or part of the functions of the access network device. Furthermore, terms such as "uplink" and "downlink" can be replaced with terms corresponding to communication between terminals (e.g., "sidelink"). For example, uplink channel, downlink channel, etc., can be replaced with sidelink channel, and uplink link, downlink, etc., can be replaced with sidelink link.
[0099] In some embodiments, the terminal may be replaced by an access network device, a core network device, or a network device. In this case, the access network device, core network device, or network device may also be configured to have all or some of the functions of the terminal.
[0100] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.
[0101] In some embodiments, data, information, etc., may be obtained with the user's consent.
[0102] Figure 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.
[0103] As shown in Figure 1, the communication system 100 includes a terminal 101 and a network device 102.
[0104] In some embodiments, terminal 101 includes, but is not limited to, at least one of the following: mobile phone, wearable device, Internet of Things device, car with communication function, smart car, tablet computer, computer with wireless transceiver function, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal device in industrial control, wireless terminal device in self-driving, wireless terminal device in remote medical surgery, wireless terminal device in smart grid, wireless terminal device in transportation safety, wireless terminal device in smart city, and wireless terminal device in smart home.
[0105] In some embodiments, network device 102 may include at least one of access network device and core network device.
[0106] In some embodiments, the access network device is, for example, a node or device that connects a terminal to a wireless network. The access network device may include, but is not limited to, at least one of the following in a 5G communication system: evolved Node B (eNB), next-generation eNB (ng-eNB), next-generation Node B (gNB), node B (NB), home node B (HNB), home evolved node B (HeNB), radio backhaul device, radio network controller (RNC), base station controller (BSC), base transceiver station (BTS), base band unit (BBU), mobile switching center, base station in a 6G communication system, open RAN, cloud RAN, base station in other communication systems, and access node in a Wi-Fi system.
[0107] In some embodiments, the technical solutions of this disclosure can be applied to the Open RAN architecture. In this case, the interfaces between or within access network devices involved in the embodiments of this disclosure can be transformed into internal interfaces of Open RAN. The processes and information interactions between these internal interfaces can be implemented by software or programs.
[0108] In some embodiments, the access network device may be composed of a central unit (CU) and a distributed unit (DU). The CU may also be called a control unit. The CU-DU structure can separate the protocol layer of the access network device. Some of the protocol layer functions are centrally controlled by the CU, while the remaining part or all of the protocol layer functions are distributed in the DU and centrally controlled by the CU. However, this is not the only possibility.
[0109] In some embodiments, a core network device may be a single device comprising one or more network elements, or it may be multiple devices or a group of devices, each comprising all or part of the aforementioned one or more network elements. Network elements may be virtual or physical. The core network may include, for example, at least one of an Evolved Protocol Core (EPC), a 5G Core Network (5GCN), or a Next Generation Core (NGC).
[0110] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.
[0111] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1 are illustrative. The communication system may include all or some of the main bodies in FIG1, or may include other main bodies outside of FIG1. The number and form of each main body are arbitrary. Each main body may be physical or virtual. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.
[0112] The embodiments disclosed herein can be applied to Long Term Evolution (LTE), LTE-Advanced (LTE-A), LTE-Beyond (LTE-B), SUPER 3G, IMT-Advanced, 4th generation mobile communication system (4G), 5th generation mobile communication system (5G), 5G new radio (NR), Future Radio Access (FRA), New-Radio Access Technology (RAT), New Radio (NR), New radio access (NX), Future generation radio access (FX), Global System for Mobile communications (GSM), CDMA2000, Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20, Ultra-Wideband (UWB), Bluetooth (a registered trademark), Public Land Mobile Network (PLMN) networks, Device-to-Device (D2D) systems, Machine-to-Machine (M2M) systems, Internet of Things (IoT) systems, Vehicle-to-Everything (V2X) systems, systems utilizing other transmission methods, and next-generation systems built upon them, etc. Furthermore, multiple systems can be combined (e.g., a combination of LTE or LTE-A with 5G).
[0113] The relevant protocols propose to encrypt and protect the integrity of Radio Resource Control (RRC) messages in order to prevent the content transmitted through RRC messages from being attacked.
[0114] Optionally, RRC messages can be classified into P-type RRC messages, AI-type RRC messages, and AC-type RRC messages according to the protection strategy.
[0115] Among them, P-class RRC messages are messages that can be sent (unprotected) before AS security is activated; A–I-class RRC messages are messages that can be sent without integrity protection after the Access Stratum (AS) security is activated; and A–C-class RRC messages are messages that can be sent without encryption after the AS security is activated.
[0116] Currently, the Media Access Control (MAC) layer control element (CE) is not encrypted or protected for integrity. As a type of control signaling, the MAC CE may pose security risks if not encrypted and protected for integrity.
[0117] For example, if the MAC CE of the L1 / L2 Triggered Mobility (LTM) cell switch command received by the terminal is tampered with, the terminal may switch to an illegal cell, thereby affecting the execution of terminal services.
[0118] Alternatively, if the terminal receives the attacked GNSS measurement command MAC CE, it will retune to the GNSS frequency to measure GNSS, thereby affecting the terminal's normal communication.
[0119] Alternatively, the terminal's private data may be tampered with. For example, if the terminal's report of the remaining validity period of the Global Navigation Satellite System (GNSS) data to the network device is altered, it may lead to the early or delayed release of the RRC. Or, if the terminal's private Timing Advance (TA) Command MAC CE is obtained by a third party, that third party can identify the terminal's location range relative to the network device, and so on.
[0120] This disclosure proposes a method for protecting MAC CEs. Communication devices can receive or send MAC Protocol Data Units (PDUs) containing protection parameters, thereby improving the security and integrity of MAC PDU transmission and providing conditions for preventing the leakage of terminal private data and improving the service quality of the terminal.
[0121] The transmission method and apparatus provided in this disclosure will now be described in detail with reference to the accompanying drawings.
[0122] Figure 2A is a flowchart illustrating a transmission method according to an embodiment of the present disclosure. As shown in Figure 2A, the transmission method in this embodiment is executed by a communication device, which can be a terminal or a network device. The embodiment shown in Figure 2A uses a communication device as a terminal as an example for illustration. The method includes:
[0123] Step S2101: Perform protection processing on the MAC CE by placing the protection parameters in the MAC PDU.
[0124] In some embodiments, the MAC CE in the MAC PDU is protected, including by encrypting the MAC CE in the MAC PDU.
[0125] In some embodiments, the MAC CE is encrypted. This can be done by encrypting the MAC CE based on information such as a key, resulting in an encrypted MAC CE. By encrypting the MAC CE, it is possible to prevent third parties from illegally obtaining the information contained in the MAC CE, thus avoiding the leakage of private information.
[0126] In some embodiments, the MAC CE in the MAC PDU is protected, including integrity protection of the MAC CE in the MAC PDU.
[0127] In some embodiments, integrity protection processing is performed on the MAC CE. This includes performing integrity calculations on the MAC CE based on integrity protection input parameters, such as keys and counter values, to generate a protection tag. The protection tag and the MAC CE are then sent together to the peer (e.g., a terminal or network device). Upon receiving the MAC CE, the peer can perform integrity calculations on the received MAC CE using the same logic as the sender (e.g., network device or terminal) to obtain a new protection tag. If the protection tag obtained by the peer is the same as the received protection tag, it can be determined that the MAC CE has not been tampered with. This ensures the reliability and security of the received MAC CE and avoids service anomalies caused by the receiving end responding to information contained in a tampered MAC CE.
[0128] In some embodiments, the terminal can perform protection processing on the uplink (UL) MAC CE and place the protection parameters in the uplink MAC PDU.
[0129] In some embodiments, the network device may perform protection processing on the downlink (UL) MAC CE and place the protection parameters in the downlink MAC PDU.
[0130] In some embodiments, the protection parameters are obtained after protecting the MAC CE in the MAC PDU, and the protection parameters are one or more of the following: count value, protection tag.
[0131] In some embodiments, the MAC PDU may contain only a single count value. For example, if only the MAC CE is encrypted, the MAC PDU may only include the count value corresponding to the encryption protection. Alternatively, if only the MAC CE is protected by integrity, the MAC PDU may only include the count value corresponding to the integrity protection. Or, if both encryption and integrity protection are applied to the MAC CE, but the count value corresponding to the encryption protection is the same as the count value corresponding to the integrity protection, the MAC PDU may also contain only a single count value.
[0132] In some embodiments, the MAC PDU may contain two count values. For example, if the MAC CE is subjected to both encryption protection and integrity protection, then the MAC PDU may include a count value corresponding to encryption protection and a count value corresponding to integrity protection.
[0133] In some embodiments, the protection label may be obtained after integrity protection processing of the MAC CE.
[0134] In some embodiments, terms such as “protection tag”, “message authentication code-integrity (MAC-I)”, “message integrity verification identifier”, “message integrity authentication code”, “information integrity verification identifier”, and “information integrity authentication code” can all indicate auxiliary information used to verify the integrity of a message (or information). In some scenarios, the above terms can be used interchangeably.
[0135] In some embodiments, the protection parameters are carried by the MAC CE, or not by the MAC CE.
[0136] In some embodiments, if the protection parameters are carried by a MAC CE and there are multiple protection parameters, the multiple protection parameters can be carried by a single MAC CE, or different protection parameters can be carried by different MAC CEs.
[0137] In some embodiments, the protection parameters corresponding to encryption protection are carried by one MAC CE, and the protection parameters corresponding to integrity protection are carried by another MAC CE.
[0138] In some embodiments, the protection parameters include, for example, a COUNT value and MAC-I, with the COUNT value preceding MAC-I. Alternatively, the COUNT value may follow MAC-I; this disclosure does not limit this.
[0139] In some embodiments, Figure 2B is a schematic diagram of an uplink MAC PDU structure according to an embodiment of the present disclosure. Figure 2C is a schematic diagram of a downlink MAC PDU structure according to an embodiment of the present disclosure. As shown in Figures 2B and 2C, the protection parameters are located after all MAC sub-PDUs in the MAC PDU.
[0140] In some embodiments, terms such as "located in all MAC subPDUs", "located at the end of the MAC PDU", and "located at the end of the MAC PDU" can be used interchangeably in certain scenarios.
[0141] As shown in Figures 2B and 2C, a MAC PDU includes multiple MAC subPDUs, such as a MAC subPDU containing (including) a MAC service data unit (SDU), a MAC subPDU including a MAC CE, and a MAC subPDU containing padding information. Protection parameters such as the COUNT value and MAC-I can be located after all MAC subPDUs.
[0142] In some embodiments, Figure 2D is a schematic diagram of an uplink MAC PDU structure according to an embodiment of the present disclosure. Figure 2E is a schematic diagram of a downlink MAC PDU structure according to an embodiment of the present disclosure. As shown in Figures 2D or 2E, the COUNT value and MAC-I can be located in the last two MAC subPDUs of the MAC PDU, respectively.
[0143] In some embodiments, as shown in FIG2C, the MAC subPDU including COUNT may be located before the MAC subPDU including MAC-I.
[0144] In some embodiments, the MAC subPDU including COUNT may be located after the MAC subPDU including MAC-I.
[0145] In some embodiments, the terms “carrying,” “containing,” “bearing,” “including,” etc., can be used interchangeably.
[0146] In some embodiments, Figure 2F is a schematic diagram of an uplink MAC PDU structure according to an embodiment of the present disclosure. Figure 2G is a schematic diagram of a downlink MAC PDU structure according to an embodiment of the present disclosure. As shown in Figures 2F or 2G, the protection parameters are located before all MAC sub-PDUs in the MAC PDU. The meaning and description of each part in the MAC PDU shown in Figures 2E and 2G can be referred to the detailed description of Figures 2B and 2C above, and will not be repeated here.
[0147] In some embodiments, Figure 2H is a schematic diagram of an uplink MAC PDU structure according to an embodiment of this disclosure. As shown in Figure 2H, for the uplink MAC CE, the protection parameter is located before the MAC sub-PDU containing padding information in the MAC PDU.
[0148] In some embodiments, the protection parameters include a COUNT value and a MAC-I, and the COUNT value and MAC-I are carried by MAC CEs, as shown in Figure 2E. The COUNT value can be placed before all MAC subPDUs carrying other MAC CEs and after MAC subPDUs including MAC SDUs; MAC-I is placed after all MAC subPDUs carrying other MAC CEs and before MAC subPDUs including paddings.
[0149] In some embodiments, the COUNT value and MAC-I are carried by MAC CEs respectively. The MAC CEs carrying the COUNT value and MAC-I can be placed before all MAC subPDUs carrying other MAC CEs and after MAC subPDUs including MAC SDUs.
[0150] In some embodiments, the COUNT value and MAC-I can be placed after all MAC subPDUs carrying other MAC CEs and before the MAC subPDUs including padding. In this manner, the COUNT value and MAC-I can use either MAC CEs or non-MAC CEs.
[0151] In some embodiments, all first MAC CEs that require protection processing in the MAC PDU are adjacent, and the protection parameters are located before or after all the first MAC CEs.
[0152] In some embodiments, terms such as "all first MAC CEs requiring protection are adjacent", "all first MAC CEs requiring protection are consecutive in the MAC PDU", and "all first MAC CEs requiring protection are together" can be used interchangeably in some scenarios.
[0153] In some embodiments, MAC CEs requiring integrity protection and / or encryption protection can be placed together, while MAC CEs not requiring integrity protection and / or encryption protection can be placed together. MAC CEs requiring integrity protection and / or encryption protection can be placed before or after the MAC CEs not requiring integrity protection and / or encryption protection. In this case, COUNT and / or MAC-I can be placed immediately before or after all MAC CEs requiring integrity protection and / or encryption protection.
[0154] In some embodiments, Figure 2I is a schematic diagram of a downlink MAC PDU structure according to an embodiment of this disclosure. As shown in Figure 2I, for the downlink MAC CE, the protection parameter is located before all MAC sub-PDUs containing MAC SDUs in the MAC PDU.
[0155] In some embodiments, the COUNT value can be placed before all MAC subPDUs that contain other MAC CEs, and MAC-I can be placed after all MAC subPDUs that contain other MAC CEs and before MAC subPDUs including MAC SDUs.
[0156] In some embodiments, the COUNT value and MAC-I can both be placed after all MAC subPDUs that contain other MAC CEs and before MAC subPDUs including MAC SDUs.
[0157] In some embodiments, the protection parameters are not carried by the MAC CE, and each MAC CE in the MAC PDU contains indication information indicating whether that MAC CE is the last MAC CE.
[0158] In other words, if the COUNT value and MAC-I are not in MAC CE format, then each MAC CE needs to indicate whether it is the last MAC CE. Thus, after receiving the downlink MAC PDU, the terminal can determine whether the MAC CE is the last MAC CE based on the indication in each MAC CE. If it is the last MAC CE, then the position adjacent to that MAC CE can be determined as the protection parameter, ensuring that the terminal can obtain the protection parameter more accurately and quickly, thus improving the efficiency of the terminal in decoding the protection parameter.
[0159] In some embodiments, the sub-headers of all second MAC CEs in the MAC PDU are adjacent, the bodies of all second MAC CEs are adjacent, and the protection parameters are located between the headers of all second MAC CEs and the bodies of all second MAC CEs.
[0160] In some embodiments, the second MAC CE can be any MAC CE in the MAC PDU.
[0161] In some embodiments, the sub-headers of all second MAC CEs in the MAC PDU are adjacent, the bodies of all second MAC CEs are adjacent, and the protection parameters are located after the bodies of all second MAC CEs.
[0162] In some embodiments, Figure 2J is a schematic diagram of a MAC PDU structure shown in an embodiment of this disclosure. In Figure 2J, "MAC CE subheader" is the subheader of the second MAC CE, "MAC CE" is the body of the second MAC CE, and protection parameters such as COUNT and MAC-I are located after all bodies.
[0163] In some embodiments, the sub-headers of all second MAC CEs in the MAC PDU are adjacent, the bodies of all second MAC CEs are adjacent, and the protection parameters are located before the sub-headers of all second MAC CEs.
[0164] In some embodiments, the sub-headers of all second MAC CEs in a MAC PDU are adjacent, the bodies of all second MAC CEs are adjacent, and the protection parameters are located before the sub-headers of all second MAC CEs and after the MAC sub-PDU containing the padding information.
[0165] In some embodiments, the second MAC CE is a MAC CE that requires protection. This subheader-grouping method can be used only for MAC CEs requiring protection (e.g., integrity protection and / or encryption protection), while MAC CEs that do not require protection are still grouped together with their subheaders. MAC CEs requiring protection are uniformly placed before or after MAC CEs that do not require protection. In this case, COUNT and / MAC-I are placed immediately before or after the headers (or bodies) of all MAC CEs requiring protection.
[0166] In some embodiments, the protection parameters are located in a MAC sub-header of the MAC PDU, which is located before the MAC CE in the MAC PDU that needs to be protected.
[0167] In some embodiments, the MAC sub-header containing protection parameters can be a newly defined sub-header.
[0168] In some embodiments, Figures 2K and 2L are schematic diagrams of an uplink MAC PDU structure shown in embodiments of this disclosure. Figures 2M and 2N are schematic diagrams of a downlink MAC PDU structure shown in embodiments of this disclosure.
[0169] In Figures 2K-2N, "MAC subheader for ciphering and integrity protection" refers to the MAC subheader used for encryption and integrity protection. In other words, this subheader can be used to carry protection parameters.
[0170] In some embodiments, the protection parameter also includes a length, wherein the length is used to indicate the total length of the MAC CE that needs to be protected.
[0171] [Correction 15.11.2024 according to Rule 91] In some embodiments, the communication device may determine, based on the length parameter, which MAC CEs require ciphering and intergrity protection, as shown in Figures 2L and 2N, and which MAC CEs do not require protection, as shown in Figures 2L and 2N, "MAC CE doesn't require ciphering and intergrity protection".
[0172] In some embodiments, the protection parameters also include the Logical Channel Identifier (LCID) corresponding to the MAC sub-packet header.
[0173] In some embodiments, the LCID corresponding to a MAC sub-packet header is used to distinguish the MAC sub-packet header, logical channel data, MAC control message, and padding information.
[0174] In some embodiments, the LCID corresponding to a MAC sub-header can be agreed upon by a protocol, or the LCID corresponding to a MAC sub-header can be indicated by the network device. Therefore, after receiving a MAC PDU, if the communication device determines that the LCID corresponding to a certain MAC sub-header is the LCID agreed upon by the protocol or indicated by the network device, it can determine that the MAC sub-header contains protection parameters. Based on these protection parameters, the communication device can perform integrity verification and / or decryption processing on the MAC CE in the MAC PDU, improving the efficiency of the communication device in obtaining protection parameters from the MAC PDU.
[0175] In some embodiments, a MAC CE containing protection parameters can be considered as having only a MAC subheader, or a MAC CE that is to be protected can be considered as the body of the MAC CE.
[0176] In some embodiments, the terminal sends a MAC PDU containing protection parameters to the network device, and the corresponding network device receives the MAC PDU containing protection parameters.
[0177] In some embodiments, the network device sends a MAC PDU containing protection parameters to the terminal, and the corresponding terminal receives the MAC PDU containing protection parameters.
[0178] Step S2102: Send a MACPDU containing protection parameters.
[0179] In some embodiments, the terminal may send an uplink MAC PDU containing protection parameters to the network device.
[0180] In some embodiments, the network device may receive an uplink MAC PDU that includes protection parameters.
[0181] In some embodiments, the network device may send a downlink MAC PDU containing protection parameters to the terminal.
[0182] In some embodiments, the terminal may receive a downlink MAC PDU that includes protection parameters.
[0183] The communication method involved in the embodiments of this disclosure may include at least one of steps S2101 to S2102. For example, step S2101 may be implemented as a standalone embodiment, step S2102 may be implemented as a standalone embodiment, etc., but is not limited thereto.
[0184] In this implementation or embodiment, unless there is contradiction, each step can be independent, arbitrarily combined or exchanged in order, optional methods or optional examples can be arbitrarily combined, and can be arbitrarily combined with any steps of other implementations or other embodiments.
[0185] [Correction 15.11.2024 based on Rule 91] Figure 3A is an interactive schematic diagram of a transmission method according to an embodiment of the present disclosure. As shown in Figure 3A, the transmission method involved in this disclosure is executed by a communication device, which may be a terminal or a network device. The method includes:
[0186] Step S2201: Send or receive a MACPDU containing protection parameters.
[0187] The protection parameters are obtained after protecting the MAC CE in the MAC PDU. The protection parameters are one or more of the following: count value, protection tag.
[0188] In the above embodiments, the communication device sends or receives a Media Access Control (MAC) Protocol Data Unit (PDU) containing protection parameters. These protection parameters are obtained by protecting the MAC CE (MAC Component Exchange) within the MAC PDU, and may include one or more of the following: a counter value, a protection tag. This, to a certain extent, avoids the problem of MAC CE being tampered with or attacked, improves the security and reliability of the MAC CE, and provides conditions for improving the performance of the communication system.
[0189] In some embodiments, the above-described protection processing of the MAC CE in the MAC PDU includes one or more of the following:
[0190] Encrypt and protect the MAC CE in the MAC PDU;
[0191] Perform integrity protection processing on the MAC CE in the MAC PDU.
[0192] In the above embodiments, the communication device can perform encryption protection and / or integrity protection on the MAC PDU, thereby ensuring the privacy and / or integrity of the MAC PDU and further improving the security and reliability of MAC layer transmission.
[0193] In some embodiments, the protection parameters described above are located after all MAC sub-PDUs in the MAC PDU.
[0194] In some embodiments, the protection parameters described above are located before all MAC sub-PDUs in the MAC PDU.
[0195] In the above embodiments, the communication device can place the protection parameters before or after the MAC PDU, thereby ensuring that both parties transmitting the MAC PDU have a consistent understanding of the location of the protection parameters, and improving the efficiency and accuracy of the receiver in parsing the MAC PDU.
[0196] In some embodiments, for an uplink MAC CE, the protection parameter is located before the MAC sub-PDU containing the padding information in the MAC PDU.
[0197] In the above embodiments, the terminal can place the protection parameters before the MAC subPDU containing padding in the uplink MAC PDU, thereby ensuring that the network device's understanding of the location of the protection parameters in the uplink MAC PDU is consistent with that of the terminal, providing conditions and basis for improving the network device's parsing efficiency and speed of the uplink MAC PDU.
[0198] In some embodiments, for a downlink MAC CE, the protection parameter is located before all MAC sub-PDUs containing MAC SDUs in the MAC PDU.
[0199] In the above embodiments, the network can place the protection parameters before all MAC subPDUs containing MAC SDUs in the downlink MAC PDU, thereby ensuring that the terminal's understanding of the location of the protection parameters in the downlink MAC PDU is consistent with that of the network device, providing conditions and basis for improving the terminal's parsing efficiency and speed of the downlink MAC PDU.
[0200] In some embodiments, the protection parameters described above are not carried by the MAC CE, but each MAC CE in the MAC PDU contains indication information indicating whether the MAC CE is the last MAC CE.
[0201] In the above embodiments, when the protection parameters are not carried by the MAC CE, by including an indication message in each MAC indicating whether it is the last MAC CE, the receiving party of the MAC PDU is provided with the means to obtain the protection parameters more accurately and quickly.
[0202] In some embodiments, all the first MAC CEs that require protection processing in the above-described MAC PDU are adjacent, and the protection parameters are located before or after all the first MAC CEs.
[0203] In the above embodiments, by placing all the first MAC CEs that need protection together and placing the protection parameters adjacent to these MAC CEs, conditions are provided for the receiving end to obtain the information carried by the first MAC CEs more quickly and accurately.
[0204] In some embodiments, the sub-headers of all second MAC CEs in the above MAC PDU are adjacent, the bodies of all second MAC CEs are adjacent, and the positions of the protection parameters satisfy any of the following:
[0205] Located between the headers of all second MAC CEs and the bodies of all second MAC CEs;
[0206] Located after the body of all second MAC CEs;
[0207] Located before the sub-packet header of all second MAC CEs;
[0208] The protection parameters are located before the sub-packet headers of all second MAC CEs and after the MAC sub-PDUs containing padding information.
[0209] In the above embodiments, by placing all the second MAC CE headers and bodies together and associating the protection parameters with the headers or bodies of the second MAC CEs, conditions are provided for the receiving end to obtain the information carried by the second MAC CEs more quickly and accurately.
[0210] In some embodiments, the second MAC CE described above is a MAC CE that requires protection processing.
[0211] In some embodiments, the protection parameters are located in a MAC sub-header of the MAC PDU, and a MAG sub-header is located before the MAC CE that needs to be protected in the MAC PDU.
[0212] In the above embodiments, by placing the protection parameters in a specific sub-packet header of the MAC PDU, the efficiency and speed at which the receiver obtains the protection parameters are further improved.
[0213] In some embodiments, the above protection parameters further include one or more of the following:
[0214] Length, wherein the length is used to indicate the total length of the MAC CE that needs to be protected;
[0215] The logical channel identifier (LCID) corresponding to a MAC sub-packet header.
[0216] The transmission method provided in this disclosure will be further described below with reference to the following embodiments.
[0217] When a communication device performs encryption and / or integrity protection on the MAC CE, it includes a COUNT value in the MAC PDU, as well as MAC-I (if integrity protection is performed).
[0218] Alternatively, for uplink (UL) MAC PDUs, the following methods are available:
[0219] Method 1: Place the COUNT value and MAC-I at the end of the MAC PDU. As shown in Figures 2B and 2D.
[0220] As shown in 2B, COUNT and MAC-I are placed at the end of the MAC PDU. The order of COUNT and MAC-I is not important, and COUNT and MAC-I do not have to be MAC CE.
[0221] In one embodiment, as shown in Figure 2D, COUNT and MAC-I can be MAC CE.
[0222] Method 2: Place the COUNT value and MAC-I at the beginning of the MAC PDU.
[0223] As shown in 2D, COUNT and MAC-I are placed at the very beginning of the MAC PDU. The order of COUNT and MAC-I is not important.
[0224] Method 3: Place the COUNT value and MAC-I before the MAC padding subPDU, as shown in Figure 2F.
[0225] In one embodiment, the COUNT value and MAC-I are carried using a MAC CE, or not using a MAC CE, but simply the COUNT value and MAC-I. They can reside in a single MAC CE, or use different MAC CEs respectively.
[0226] One approach is to place the COUNT value before all other MAC CEs and after the MAC subPDUs, including MAC SDUs; and to place the MAC-I value after all other MAC CEs and before the MAC subPDUs, including padding. This approach is primarily suitable when the COUNT value and MAC-I value are carried using MAC CEs.
[0227] Another approach is to place the COUNT value and MAC-I before all other MAC CEs and after the MAC subPDUs, including MAC SDUs. This approach is primarily suitable when the COUNT value and MAC-I are carried by the MAC CE.
[0228] Another approach is to place the COUNT value and MAC-I after all other MAC CEs and before the MAC subPDU, including padding. With this approach, the COUNT value and MAC-I can use either MAC CEs or non-MAC CEs.
[0229] For method three, MAC CEs that require protection can be grouped together, and those that do not require protection can be grouped together. MAC CEs requiring protection can be placed before or after those that do not require protection. In this case, COUNT and / MAC-I are placed immediately before or after all MAC CEs requiring protection.
[0230] Method 4: Place all MAC CE subheaders together, and all MAC CE bodies together. Place COUNT and / MAC-I between the MAC CE subheader and the MAC CE body, or after all MAC CE bodies (as shown in Figure 2H), or before the MAC CE subheader, after the MAC subPDU including padding, etc.
[0231] For method four, this subheader grouping method can be used only for MAC CEs that require protection (integrity protection and / or encryption protection), while the subheader and packet body can still be grouped together for MAC CEs that do not require protection. MAC CEs requiring protection should be placed before or after MAC CEs that do not require protection. In this case, COUNT and / MAC-I should be placed immediately before or after the subheaders (or packets) of all MAC CEs that require protection.
[0232] Method 5: For MAC CEs that require protection processing (integrity protection processing and / or encryption protection processing), add a MAC subheader in front of these MAC CEs to carry protection parameters, as shown in Figure 2J.
[0233] Optionally, this subheader includes a COUNT value, MAC-I, LCID, and a length field. The LCID in the subheader is a unique identifier specifically assigned to this subheader. The length field represents the total length of all MAC CEs that require protection following the subheader. Other unprotected MAC CEs can be placed before or after the MAC CEs requiring protection, as shown in Figure 2L. This MAC CE can be considered as having only a MAC subheader, or the MAC CE to be protected can be considered as its body.
[0234] For downlink (DL) MAC PDUs, there are several methods:
[0235] Method 1: Place the COUNT value and MAC-I at the end of the MAC PDU.
[0236] As shown in Figure 2C: COUNT and MAC-I are placed at the end of the MAC PDU. The order of COUNT and MAC-I is not important.
[0237] In one embodiment, COUNT and MAC-I can be MAC CE, as shown in Figure 2E.
[0238] Method 2: Place the COUNT value and MAC-I at the beginning of the MAC PDU.
[0239] As shown in Figure 2G: COUNT and MAC-I are placed at the very beginning of the MAC PDU. The order of COUNT and MAC-I is not important.
[0240] In one embodiment, COUNT and MAC-I can be MAC CE, or they can be COUNT value and MAC-I directly, but not MAC CE.
[0241] Method 3: Place the COUNT value and MAC-I before all MAC subPDUs, including MAC SDUs, as shown in Figure 2I.
[0242] Optionally, the COUNT value and MAC-I are carried using a MAC CE, which can be located in one MAC CE or use different MAC CEs respectively.
[0243] One approach is to place the COUNT value before all MAC subPDUs that contain other MAC CEs, and the MAC-I value after all MAC subPDUs that contain other MAC CEs, and before MAC subPDUs including MAC SDUs.
[0244] Another approach is to place the COUNT value and MAC-I after all MAC subPDUs that contain other MAC CEs, and before MAC subPDUs including MAC SDUs.
[0245] In some embodiments, for Method 3, if the COUNT value and MAC-I are not in MAC CE format, then it is necessary to indicate in each MAC CE whether the MAC CE is the last MAC CE.
[0246] In some embodiments, for method three, MAC CEs that require protection (integrity protection and / or encryption protection) can be placed together, while MAC CEs that do not require protection can be placed together. MAC CEs that require protection can be placed before or after the MAC CEs that do not require protection. In this case, COUNT and / or MAC-I are placed immediately before or after all MAC CEs that require protection.
[0247] Method 4: Place all MAC CE subheaders together, and all MAC CE bodies together. Place COUNT and MAC-I after the MAC CE body as shown in Figure 2J, or between the MAC CE subheader and the MAC CE body, or before the MAC CE subheader.
[0248] For method four, this subheader grouping method can be used only for MAC CEs that require protection (encryption protection and / or integrity protection), while MAC CEs that do not require protection can still use the subheader and packet body grouping method. MAC CEs requiring protection should be placed before or after MAC CEs that do not require protection. In this case, COUNT and / MAC-I should be placed immediately before or after all MAC CEs that require protection.
[0249] Method 5: For MAC CEs that require protection processing (encryption protection processing and / or integrity protection processing), add a MAC subheader before the MAC PDU. This MAC subheader is used to carry protection parameters, as shown in Figure 2M.
[0250] Optionally, the subheader may contain a COUNT value, MAC-I, LCID, and a length field. The LCID in the subheader is a unique identifier specifically assigned to that subheader. The length field represents the total length of all MAC CEs that require protection following the subheader. Other unprotected MAC CEs can be placed before or after the MAC CEs that require protection, as shown in Figure 2N. This MAC CE can be considered as having only a MAC subheader, or the MAC CE requiring protection can be considered as its body.
[0251] This disclosure also provides an apparatus for implementing any of the above methods. For example, an apparatus is provided that includes units or modules for implementing the steps performed by the terminal in any of the above methods. Alternatively, another apparatus is provided that includes units or modules for implementing the steps performed by a network device (e.g., an access network device, a core network functional node, a core network device, etc.) in any of the above methods.
[0252] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.
[0253] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).
[0254] [Correction 15.11.2024 based on Rule 91] Figure 3B is a schematic diagram of the structure of a communication device proposed in an embodiment of this disclosure. As shown in Figure 3B, the communication device 3100 may include at least one of a transceiver module 3101, a processing module 3102, etc. In some embodiments, the transceiver module is used to send or receive a Media Access Control (MAC) Protocol Data Unit (PDU) containing protection parameters, wherein the protection parameters are obtained after protecting the MAC CE in the MAC PDU, and the protection parameters are one or more of the following: a count value, a protection tag.
[0255] In some embodiments, the above-described processing module is configured to perform one or more of the following:
[0256] Encrypt and protect the MAC CE in the MAC PDU;
[0257] Perform integrity protection processing on the MAC CE in the MAC PDU.
[0258] In some embodiments, the above protection parameters are located after all MAC sub-PDUs in the MAC PDU.
[0259] In some embodiments, the aforementioned protection parameters are located before all MAC sub-PDUs in the MAC PDU.
[0260] In some embodiments, for the uplink MAC CE, the protection parameters are located before the MAC sub-PDU containing the padding information in the MAC PDU.
[0261] In some embodiments, for a downlink MAC CE, the protection parameter is located before all MAC sub-PDUs containing MAC SDUs in the MAC PDU.
[0262] In some embodiments, the protection parameters described above are not carried by the MAC CE, but each MAC CE in the MAC PDU contains indication information indicating whether that MAC CE is the last MAC CE.
[0263] In some embodiments, all the first MAC CEs that need to be protected in the above-mentioned MAC PDU are adjacent, and the protection parameters are located before or after all the first MAC CEs.
[0264] In some embodiments, the sub-headers of all second MAC CEs in the above MAC PDU are adjacent, the bodies of all second MAC CEs are adjacent, and the positions of the protection parameters satisfy any of the following:
[0265] Located between the headers of all second MAC CEs and the bodies of all second MAC CEs;
[0266] Located after the body of all second MAC CEs;
[0267] Located before the sub-packet header of all second MAC CEs;
[0268] The protection parameters are located before the sub-packet headers of all second MAC CEs and after the MAC sub-PDUs containing padding information.
[0269] In some embodiments, the second MAC CE described above is a MAC CE that requires protection processing.
[0270] In some embodiments, the protection parameters are located in a MAC sub-header of the MAC PDU, and a MAG sub-header is located before the MAC CE that needs to be protected in the MAC PDU.
[0271] In some embodiments, the protection parameters also include one or more of the following:
[0272] Length, where length indicates the total length of the MAC CE that needs to be protected;
[0273] The logical channel identifier (LCID) corresponding to a MAC sub-packet header.
[0274] Optionally, the transceiver module described above is used to perform at least one of the communication steps such as sending and / or receiving performed by the terminal in any of the above methods, which will not be elaborated here.
[0275] Optionally, the above processing module is used to perform at least one of the other steps executed by the terminal in any of the above methods, which will not be elaborated here.
[0276] Figure 4A is a schematic diagram of the structure of the communication device 4100 proposed in an embodiment of this disclosure. The communication device 4100 can be a network device (e.g., access network device, core network device, etc.), a terminal (e.g., user equipment, etc.), a chip, chip system, or processor that supports the network device in implementing any of the above methods, or a chip, chip system, or processor that supports the terminal in implementing any of the above methods. The communication device 4100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.
[0277] As shown in Figure 4A, the communication device 4100 includes one or more processors 4101. The processor 4101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. The communication device 4100 is used to execute any of the above methods.
[0278] In some embodiments, the communication device 4100 further includes one or more memories 4102 for storing instructions. Optionally, all or part of the memories 4102 may also be located outside the communication device 4100.
[0279] In some embodiments, the communication device 4100 further includes one or more transceivers 4103. When the communication device 4100 includes one or more transceivers 4103, the transceivers 4103 perform at least one of the communication steps such as sending and / or receiving in the above method, and the processor 4101 performs at least one of the other steps.
[0280] In some embodiments, a transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, etc., may be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., may be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., may be used interchangeably.
[0281] In some embodiments, the communication device 4100 may include one or more interface circuits 4104. Optionally, the interface circuit 4104 is connected to the memory 4102, and the interface circuit 4104 can be used to receive signals from the memory 4102 or other devices, and can be used to send signals to the memory 4102 or other devices. For example, the interface circuit 4104 can read instructions stored in the memory 4102 and send the instructions to the processor 4101.
[0282] The communication device 4100 described in the above embodiments may be a network device or a terminal, but the scope of the communication device 4100 described in this disclosure is not limited thereto, and the structure of the communication device 4100 may not be limited by FIG4A. The communication device may be a standalone device or may be part of a larger device. For example, the communication device may be: (1) a standalone integrated circuit IC, or chip, or chip system or subsystem; (2) a collection of one or more ICs, optionally, the IC collection may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.
[0283] Figure 4B is a schematic diagram of the structure of chip 4200 according to an embodiment of this disclosure. For cases where the communication device 4100 can be a chip or a chip system, please refer to the schematic diagram of chip 4200 shown in Figure 4B, but it is not limited thereto.
[0284] Chip 4200 includes one or more processors 4201, which are used to perform any of the above methods.
[0285] In some embodiments, chip 4200 further includes one or more interface circuits 4202. Optionally, the interface circuit 4202 is connected to memory 4203, and the interface circuit 4202 can be used to receive signals from memory 4203 or other devices, and the interface circuit 4202 can be used to send signals to memory 4203 or other devices. For example, the interface circuit 4202 can read instructions stored in memory 4203 and send the instructions to processor 4201.
[0286] In some embodiments, the interface circuit 4202 performs at least one of the communication steps such as sending and / or receiving in the above method, and the processor 4201 performs at least one of the other steps.
[0287] In some embodiments, the terms interface circuit, interface, transceiver pin, transceiver, etc., can be used interchangeably.
[0288] In some embodiments, chip 4200 further includes one or more memories 4203 for storing instructions. Optionally, all or part of the memories 4203 may be located outside of chip 4200.
[0289] This disclosure also proposes a storage medium storing instructions that, when executed on the communication device 4100, cause the communication device 4100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.
[0290] This disclosure also provides a program product that, when executed by the communication device 4100, causes the communication device 4100 to perform any of the above methods. Optionally, the program product is a computer program product.
[0291] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.
[0292] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer programs. When the computer program is loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this disclosure are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer program can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program can be transferred from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., high-density digital video discs (DVDs)), or semiconductor media (e.g., solid-state disks (SSDs)).
[0293] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.
[0294] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0295] The above description is merely a specific embodiment of this disclosure, but the scope of protection of this disclosure is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this disclosure should be included within the scope of protection of this disclosure. Therefore, the scope of protection of this disclosure should be determined by the scope of the claims.
Claims
1. A transmission method, characterized in that, include: Sending or receiving a Media Access Control (MAC) Protocol Data Unit (PDU) containing protection parameters, wherein the protection parameters are obtained by protecting the MAC CE in the MAC PDU, and the protection parameters are one or more of the following: a count value, a protection tag.
2. The method as described in claim 1, characterized in that, The protection process for the MAC CE in the MAC PDU includes one or more of the following: The MAC CE in the MAC PDU is encrypted and protected. Integrity protection processing is performed on the MAC CE in the MAC PDU.
3. The method as described in claim 1 or 2, characterized in that, The protection parameters are located after all MAC sub-PDUs in the MAC PDU.
4. The method as described in claim 1 or 2, characterized in that, The protection parameters are located before all MAC sub-PDUs in the MAC PDU.
5. The method as described in claim 1 or 2, characterized in that, For an uplink MAC CE, the protection parameter is located before the MAC sub-PDU containing the padding information in the MAC PDU.
6. The method as described in claim 1 or 2, characterized in that, For downlink MAC CE, the protection parameter is located before all MAC sub-PDUs containing MAC SDUs in the MAC PDU.
7. The method as described in claim 6, characterized in that, The protection parameters are not carried by the MAC CE, and each MAC CE in the MAC PDU contains indication information indicating whether the MAC CE is the last MAC CE.
8. The method as described in any one of claims 5-7, characterized in that, In the MAC PDU, all first MAC CEs that require protection are adjacent to each other, and the protection parameter is located before or after all the first MAC CEs.
9. The method as described in claim 1 or 2, characterized in that, All second MAC CEs in the MAC PDU have adjacent sub-headers and adjacent packet bodies, and the position of the protection parameter satisfies any of the following: Located between the headers of all second MAC CEs and the bodies of all second MAC CEs; Located after the body of all second MAC CEs; Located before the sub-packet headers of all second MAC CEs; The protection parameters are located before the sub-packet headers of all second MAC CEs and after the MAC sub-PDUs containing padding information.
10. The method as described in claim 9, characterized in that, The second MAC CE is the MAC CE that needs to be protected.
11. The method as described in claim 1 or 2, characterized in that, The protection parameters are located in a MAC sub-header of the MAC PDU, and the MAG sub-header is located before the MAC CE that needs to be protected in the MAC PDU.
12. The method as described in claim 11, characterized in that, The protection parameters also include one or more of the following: Length, wherein the length is used to indicate the total length of the MAC CE that needs to be protected; The logical channel identifier (LCID) corresponding to a MAC sub-packet header.
13. A communication device, characterized in that, The communication device includes: A transceiver module is used to send or receive a Media Access Control (MAC) Packet Data Unit (PDU) containing protection parameters, wherein the protection parameters are obtained after protecting the MAC CE in the MAC PDU, and the protection parameters are one or more of the following: a count value, a protection tag.
14. A communication device, characterized in that, include: One or more processors; The processor is used to execute the transmission method according to any one of claims 1-12.
15. A communication system, characterized in that, It includes a terminal and a network device, wherein the terminal and the network device are respectively used to perform the transmission as described in any one of claims 1-12.
16. A storage medium storing instructions, characterized in that, When the instruction is executed on the communication device, the communication device performs the transmission method as described in any one of claims 1-12.
17. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the transmission method according to any one of claims 1-12.
Citation Information
Patent Citations
Communication method and device
CN115696319A
Method and apparatus for enhancing security of MAC layer entity in next generation mobile communication system
CN116762378A
Message transmission method, device and equipment
CN118368616A
NR security enhancements
CN118402208A
Method and device for applying security technique to mobility mac ce based on l1 / l2 in mobile communication system
WO2024150986A1